https://bugs.openldap.org/show_bug.cgi?id=9773
Issue ID: 9773 Summary: slapo-allowed should also list "operational" attributes Product: OpenLDAP Version: 2.6.0 Hardware: All OS: All Status: UNCONFIRMED Keywords: needs_review Severity: normal Priority: --- Component: contrib Assignee: bugs@openldap.org Reporter: michael@stroeder.com Target Milestone: ---
When using slapo-allowed a client may disable input fields for attributes not listed in 'allowedAttributesEffective'. This helps the user to understand that he/she should not even try to modify the attribute (better UX).
But slapo-allowed never shows operational attributes in allowedAttributesEffective. In most use-cases this is understandable but there are some nice use-cases (e.g. setting pwdPolicySubentry) where it should be possible for the client to display an enabled input field even for operational attributes.
See also: * Discussion in ITS#9671 * https://code.stroeder.com/ldap/web2ldap/issues/24