access_login_allowed: Remove primary group check

This check is now performed within g_check_user_in_group()
This commit is contained in:
matt335672
2023-10-05 12:25:40 +01:00
parent cf677da22c
commit 5837deae04
-26
View File
@@ -40,7 +40,6 @@
int
access_login_allowed(const struct config_security *cfg_sec, const char *user)
{
int gid;
int ok;
if ((0 == g_strncmp(user, "root", 5)) && (0 == cfg_sec->allow_root))
@@ -56,18 +55,6 @@ access_login_allowed(const struct config_security *cfg_sec, const char *user)
return 1;
}
if (0 != g_getuser_info_by_name(user, 0, &gid, 0, 0, 0))
{
LOG(LOG_LEVEL_ERROR, "Cannot read user info! - login denied");
return 0;
}
if (cfg_sec->ts_users == gid)
{
LOG(LOG_LEVEL_DEBUG, "ts_users is user's primary group");
return 1;
}
if (0 != g_check_user_in_group(user, cfg_sec->ts_users, &ok))
{
LOG(LOG_LEVEL_ERROR, "Cannot read group info! - login denied");
@@ -89,7 +76,6 @@ int
access_login_mng_allowed(const struct config_security *cfg_sec,
const char *user)
{
int gid;
int ok;
if ((0 == g_strncmp(user, "root", 5)) && (0 == cfg_sec->allow_root))
@@ -106,18 +92,6 @@ access_login_mng_allowed(const struct config_security *cfg_sec,
return 1;
}
if (0 != g_getuser_info_by_name(user, 0, &gid, 0, 0, 0))
{
LOG(LOG_LEVEL_ERROR, "[MNG] Cannot read user info! - login denied");
return 0;
}
if (cfg_sec->ts_admins == gid)
{
LOG(LOG_LEVEL_INFO, "[MNG] ts_users is user's primary group");
return 1;
}
if (0 != g_check_user_in_group(user, cfg_sec->ts_admins, &ok))
{
LOG(LOG_LEVEL_ERROR, "[MNG] Cannot read group info! - login denied");