From 67405dde9ba213331dab1fc46cb18c485070fd5b Mon Sep 17 00:00:00 2001
From: matthew_swift <matthew_swift@localhost>
Date: Fri, 05 Jun 2009 09:04:50 +0000
Subject: [PATCH] svn merge -r5333:5417 https://opends.dev.java.net/svn/opends/branches/b2.0

---
 opends/src/server/org/opends/server/workflowelement/localbackend/LocalBackendAddOperation.java |   27 ++++++++++++++++++++-------
 1 files changed, 20 insertions(+), 7 deletions(-)

diff --git a/opends/src/server/org/opends/server/workflowelement/localbackend/LocalBackendAddOperation.java b/opends/src/server/org/opends/server/workflowelement/localbackend/LocalBackendAddOperation.java
index bb0ace1..118297f 100644
--- a/opends/src/server/org/opends/server/workflowelement/localbackend/LocalBackendAddOperation.java
+++ b/opends/src/server/org/opends/server/workflowelement/localbackend/LocalBackendAddOperation.java
@@ -1464,14 +1464,26 @@
 
         if (oid.equals(OID_LDAP_ASSERTION))
         {
+          // RFC 4528 mandates support for Add operation basically
+          // suggesting an asertion on self. As daft as it may be
+          // we gonna have to support this for RFC compliance.
           LDAPAssertionRequestControl assertControl =
             getRequestControl(LDAPAssertionRequestControl.DECODER);
 
           try
           {
-            // FIXME -- We need to determine whether the current user has
-            //          permission to make this determination.
             SearchFilter filter = assertControl.getSearchFilter();
+
+            // Check if the current user has permission to make
+            // this determination.
+            if (!AccessControlConfigManager.getInstance().
+              getAccessControlHandler().isAllowed(this, entry, filter))
+            {
+              throw new DirectoryException(
+                ResultCode.INSUFFICIENT_ACCESS_RIGHTS,
+                ERR_CONTROL_INSUFFICIENT_ACCESS_RIGHTS.get(oid));
+            }
+
             if (! filter.matchesEntry(entry))
             {
               throw new DirectoryException(ResultCode.ASSERTION_FAILED,
@@ -1620,12 +1632,13 @@
       }
     }
 
-    // FIXME -- Check access controls on the entry to see if it should
-    //          be returned or if any attributes need to be stripped
-    //          out..
-    SearchResultEntry searchEntry = new SearchResultEntry(addedEntry);
+    // Check access controls on the entry and strip out
+    // any not allowed attributes.
+    SearchResultEntry searchEntry =
+      AccessControlConfigManager.getInstance().
+      getAccessControlHandler().filterEntry(this, addedEntry);
     LDAPPostReadResponseControl responseControl =
-         new LDAPPostReadResponseControl(searchEntry);
+      new LDAPPostReadResponseControl(searchEntry);
     addResponseControl(responseControl);
   }
 }

--
Gitblit v1.10.0