Skip to content

docs(admin): warn that LDAP gidNumber keeps group membership - #15715

Open
whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-ldap-gidnumber-membership-caveat
Open

whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-ldap-gidnumber-membership-caveat

Conversation

@whoalin1

@whoalin1 whoalin1 commented Oct 6, 2026 •

Copy link
Copy Markdown

Summary

Document the LDAP POSIX primary-group footgun: matching user/group gidNumber (or AD primaryGroupID) keeps the user in the Nextcloud group even after they are removed via the configured membership attribute.

  • Warning on the admin Group Member association field in user_auth_ldap.rst.
  • Clarifies the relation is independent of member / memberUid / uniqueMember.
  • Notes leftover UI/occ membership, that ldapGidNumber is configurable but not in the UI, and that ldap:show-remnants does not clear this secondary relation.

Closes #11148

Test plan

  • Sphinx build of the admin manual succeeds for user_auth_ldap.rst
  • New .. warning:: appears after Group Member association and before Nested groups
  • Mentions gidNumber, independence from assoc attr, AD primaryGroupID, ldapGidNumber, and that show-remnants is unrelated
  • No cleanup / API pages changed

AI disclosure

This PR was drafted with the help of AI coding assistants (Cursor agents / LLM-based tools), including the description. I am responsible for it and happy to rework anything that doesn't fit.

The commits don't carry Assisted-by: trailers yet; I can add them if wanted (that needs a force push).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Admin] LDAP: user's attribute gidNumber is used for group relations

1 participant