Give privilege to users in TerminalServerAdmins

Revives the currently unused TerminalServerAdmins group.

Users in this group will eventually have special privileges for session
management. Currently, members of this group will be allowed to
list all sessions with the xrdp-sesadmin command.
This commit is contained in:
matt335672
2024-12-20 16:58:24 +00:00
parent dd020e971b
commit 86c7fa63b9
9 changed files with 162 additions and 133 deletions
+13 -4
View File
@@ -271,8 +271,9 @@ login for all users is enabled.
.TP
\fBTerminalServerAdmins\fR=\fIgroup\fR
\fIThis option is currently ignored!\fR Only members of this group can
have session management rights.
Members of this group can use the \fBxrdp-sesadmin\fR command to
administer sessions started by other users. The root user is always
considered to be in this group.
.TP
\fBRestrictOutboundClipboard\fR=\fI[all|none|text|file|image]\fR
@@ -334,8 +335,16 @@ To keep compatibility, the following aliases are also available.
.TP
\fBAlwaysGroupCheck\fR=\fI[true|false]\fR
If set to \fB1\fR, \fBtrue\fR or \fByes\fR, require group membership even
if the group specified in \fBTerminalServerUsers\fR doesn't exist.
If set to \fB1\fR, \fBtrue\fR or \fByes\fR:-
.RS
.HP 3
- For normal logins, require group membership even if the group specified
in \fBTerminalServerUsers\fR doesn't exist.
.HP 3
- An error message may be generated when any user authenticates
if the group specified in \fBTerminalServerAdmins\fR doesn't exist. This is
because the system is unable to check whether the user is an administrator.
.RE
.TP
\fBAllowAlternateShell\fR=\fI[true|false]\fR
+2 -1
View File
@@ -37,7 +37,8 @@ Valid commands are:
.RS 4
.TP
.B list
List active sessions for the current user.
List active sessions for the current user. Members of the
\fBTerminalServerAdmins\fR group can view active sessions for all users.
.TP
.BI kill: sid
Kills the session specified the given \fIsession id\fP.