access_login_allowed: Remove primary group check
This check is now performed within g_check_user_in_group()
This commit is contained in:
@@ -40,7 +40,6 @@
|
||||
int
|
||||
access_login_allowed(const struct config_security *cfg_sec, const char *user)
|
||||
{
|
||||
int gid;
|
||||
int ok;
|
||||
|
||||
if ((0 == g_strncmp(user, "root", 5)) && (0 == cfg_sec->allow_root))
|
||||
@@ -56,18 +55,6 @@ access_login_allowed(const struct config_security *cfg_sec, const char *user)
|
||||
return 1;
|
||||
}
|
||||
|
||||
if (0 != g_getuser_info_by_name(user, 0, &gid, 0, 0, 0))
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR, "Cannot read user info! - login denied");
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (cfg_sec->ts_users == gid)
|
||||
{
|
||||
LOG(LOG_LEVEL_DEBUG, "ts_users is user's primary group");
|
||||
return 1;
|
||||
}
|
||||
|
||||
if (0 != g_check_user_in_group(user, cfg_sec->ts_users, &ok))
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR, "Cannot read group info! - login denied");
|
||||
@@ -89,7 +76,6 @@ int
|
||||
access_login_mng_allowed(const struct config_security *cfg_sec,
|
||||
const char *user)
|
||||
{
|
||||
int gid;
|
||||
int ok;
|
||||
|
||||
if ((0 == g_strncmp(user, "root", 5)) && (0 == cfg_sec->allow_root))
|
||||
@@ -106,18 +92,6 @@ access_login_mng_allowed(const struct config_security *cfg_sec,
|
||||
return 1;
|
||||
}
|
||||
|
||||
if (0 != g_getuser_info_by_name(user, 0, &gid, 0, 0, 0))
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR, "[MNG] Cannot read user info! - login denied");
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (cfg_sec->ts_admins == gid)
|
||||
{
|
||||
LOG(LOG_LEVEL_INFO, "[MNG] ts_users is user's primary group");
|
||||
return 1;
|
||||
}
|
||||
|
||||
if (0 != g_check_user_in_group(user, cfg_sec->ts_admins, &ok))
|
||||
{
|
||||
LOG(LOG_LEVEL_ERROR, "[MNG] Cannot read group info! - login denied");
|
||||
|
||||
Reference in New Issue
Block a user