Re: Object Class Violation
"Manuel Amador (Rudd-O)" <[email protected]> Wed, 03 Aug 2005 19:30:50 -0500
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Message-ID | <[email protected]> |
Colors are bad usability hints. Maybe the required attribute labels can
be emboldened but that would require gtk2 with pango (<b>my bold
label</b>).
El mar, 02-08-2005 a las 12:49 -0700, Neil Schneider escribi=C3=B3:
> Manuel Amador (Rudd-O) said:
> > No, I don't think this will work, technically, the reason of which
> > being
> > that unneeded object classes sometimes cannot be added because they
> > sometimes require some attributes to be present. And sometimes
> > attributes you want to fill will need an object class not present in
> > your template.
>=20
> GQ solves the problem of required attributes by displaying them in a
> different color. Thus indicating to the user that they need to be
> filled in to prevent an objectclass error. Attributes not part of the
> templated ObjectClass don't appear in the attributes list.
Actually DA should not require *any* (or nearly any) attribute, and
automatically drop unneeded object classes.
>=20
> > Thus you intend to move the responsibility of deciding which object
> > class to go in an object to the user, when DA is actually in a much
> > better position to determine the optimum array of needed object
> > classes.
>=20
> No offense, but this sounds arrogant to me. To my ear this sounds like
> the software is smarter than the administrator at determining what
> objectclasses are required.
No, it's not smarter. It's more efficient, time-wise.
But the actual problem is that DA should simply not require all of that
data that it's requiring now. DA should only require a minimum of
perhaps unix user name, and no password (in which case it should set the
password to disabled or the account ... I don't exactly know what to do
in this corner case). Thus most of the barriers for rapid account entry
are dropped.
> Granted, this is often the case, however
> the assumption is flawed.
>=20
> > This is something that needs to be determined on a case-per-case
> > basis,
> > with an algorithm that detects which object classes are needed, and
> > automatically adjusts the object's OCs as corresponding, just as it is
> > now.
>=20
> How is an algorithm going to make this determiniation?
by checking the attributes of the object you just entered, and adding
the required object classes automatically. This is already done now.
> Does the system
> require both Samba authentication and Unix authentication? In my case
> it does. Is a host attribute required? In my case, none is required.
Check the "grant access to all computers in the network" check box in
the access control wizard stage.
> Every time you try to second guess the administrator, you run into
> these kinds of conflicts. What makes you, or your software, better
> equiped to decide which attributes must be required?
Really, I made that call when it worked fine. Then standards changed,
and I did not have the time and wasn't involved enough to make the
software follow the standards.
>=20
> > Either improve the algorithm (which is very, very simple actually) or
> > find a way to use the host attribute without adding a conflicting
> > object
> > class, which is the real problem AFAIK.
>=20
> Host attribute is unecessary in my enviroment, but you would choose to
> force me to use it.
Again, check the "grant...." checkbox and you'll be fine. That will
make DA drop the account object class.
>=20
--=20
Rudd-O <[email protected]>
http://www.amautacorp.com/staff/Rudd-O/