-
Notifications
You must be signed in to change notification settings - Fork 230
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add support for managing idoverrideusers in ipagroup. #487
Add support for managing idoverrideusers in ipagroup. #487
Conversation
Correct me if this is wrong, but from what I can tell there's no way to add ID overrides entries using Ansible anyway? |
@DazAh no, until this PR is merged. |
Just to be clear from what I can tell your PR only includes adding a pre existing id user override to a group. Pretty sure adding a user override in the first place is missing which is unfortunate. |
34ed2ea
to
99693ca
Compare
99693ca
to
a27e53f
Compare
a27e53f
to
17a20ba
Compare
da2e1d8
to
09172cc
Compare
09172cc
to
cdcd713
Compare
"group_add_member: group1: Unknown option: idoverrideuser" - The option was added with IPA 4.9.0. |
cdcd713
to
af056ed
Compare
@t-woerner actually, the changes go back to IPA 4.8.7. I updated the code and tests to reflect this. |
The group CLI option `idoverrideusers` was not supported by ansible-freeipa, and this patch adds support to it. Tests require an AD trust, and a user `aduser@ad.ipa.test` to exist, or the user name must be provided (variable, CLI) through `test_ad_user`. A new test playbook was added: tests/group/test_group_idoverrideuser.yml
af056ed
to
099eb96
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changes and test coverage are LGTM.
The CLI option
idoverrideusers
was not supported by ansible-freeipa,and this patch adds support to it.
Tests require an AD trust, and a usere
aduser@ad.ipa.test
to exist.A new test was added: