diff --git a/.editorconfig b/.editorconfig index ce35108..2b173c9 100644 --- a/.editorconfig +++ b/.editorconfig @@ -1,5 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product # # EditorConfig Configuration file, for more details see: # https://EditorConfig.org @@ -12,7 +14,7 @@ root = true -[*] # For All Files +[*] # Unix-style newlines with a newline ending every file end_of_line = lf insert_final_newline = true diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml index cf37dd3..678cf25 100644 --- a/.github/workflows/pre-commit.yml +++ b/.github/workflows/pre-commit.yml @@ -1,5 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product name: pre-commit on: @@ -21,8 +23,8 @@ jobs: name: linting runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 - - uses: actions/setup-python@v6 + - uses: actions/checkout@v7 + - uses: actions/setup-python@v7 with: python-version: '3.13' - uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd #v3.0.1 diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index dab1e65..971dea2 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -1,5 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product name: tests on: @@ -29,6 +31,7 @@ jobs: - ["3.12", "py312"] - ["3.13", "py313"] - ["3.14", "py314"] + - ["3.15", "py315"] - ["3.11", "docs"] - ["3.11", "coverage"] @@ -36,7 +39,7 @@ jobs: if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name name: ${{ matrix.config[1] }} steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 with: persist-credentials: false - name: Install additional dependencies @@ -45,8 +48,8 @@ jobs: sudo apt update sudo apt install -y ldap-utils slapd libldap2-dev libsasl2-dev - name: Install uv + caching - # astral/setup-uv@7.1.3 - uses: astral-sh/setup-uv@5a7eac68fb9809dea845d802897dc5c723910fa3 + # astral/setup-uv@10.0.1 + uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d with: enable-cache: true cache-dependency-glob: | @@ -55,14 +58,71 @@ jobs: python-version: ${{ matrix.config[0] }} github-token: ${{ secrets.GITHUB_TOKEN }} - name: Test - if: ${{ !startsWith(runner.os, 'Mac') }} run: uvx --with tox-uv tox -e ${{ matrix.config[1] }} - - name: Test (macOS) - if: ${{ startsWith(runner.os, 'Mac') }} - run: uvx --with tox-uv tox -e ${{ matrix.config[1] }}-universal2 - name: Coverage if: matrix.config[1] == 'coverage' run: | uvx coveralls --service=github env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + + - name: Build package artifacts + if: > + matrix.os[0] == 'ubuntu' + && matrix.config[1] == 'py314' + run: | + rm -f dist/* + pip install -U packaging "setuptools >= 78.1.1,< 82" wheel twine + python setup.py sdist + python setup.py bdist_wheel + + - name: Upload package wheel + if: > + matrix.os[0] == 'ubuntu' + && matrix.config[1] == 'py314' + uses: actions/upload-artifact@v7 + with: + name: Products.LDAPUserFolder.whl + path: dist/*whl + + - name: Upload package source distribution + if: > + matrix.os[0] == 'ubuntu' + && matrix.config[1] == 'py314' + uses: actions/upload-artifact@v7 + with: + name: Products.LDAPUserFolder.tar.gz + path: dist/*gz + + publish: + name: Publish to PyPI + runs-on: ubuntu-latest + # Only publish on tag pushes + if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags') + # Wait for build jobs to complete + needs: [build] + environment: + name: pypi + url: https://pypi.org/p/Products.LDAPUserFolder + permissions: + contents: read + id-token: write # Mandatory for trusted publishing + + steps: + - name: Download package artifacts + uses: actions/download-artifact@v8 + with: + path: dist/ + pattern: '*' + merge-multiple: true + + - name: Display structure of downloaded files + run: | + ls -lR dist/ + + - name: Publish to PyPI + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 + with: + skip-existing: true + packages-dir: dist/ + verbose: true diff --git a/.gitignore b/.gitignore index ce7f677..fe457bd 100644 --- a/.gitignore +++ b/.gitignore @@ -1,5 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product *.dll *.egg-info/ *.profraw @@ -28,5 +30,6 @@ lib64 log/ parts/ pyvenv.cfg +share/ testing.log var/ diff --git a/.meta.toml b/.meta.toml index 46e6302..51a2a75 100644 --- a/.meta.toml +++ b/.meta.toml @@ -1,16 +1,19 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product [meta] template = "zope-product" -commit-id = "9fcd3d67" +commit-id = "1f2c8437" [python] with-windows = false with-pypy = false -with-future-python = false +with-future-python = true with-docs = true with-sphinx-doctests = false with-macos = false +with-free-threaded-python = false [tox] use-flake8 = true @@ -51,3 +54,6 @@ build-extra = [ " - libldap2-dev", " - libsasl2-dev", ] + +[pypi] +trusted-publishing = true diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index cdeaf6c..3b76d68 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,9 +1,20 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product minimum_pre_commit_version: '3.6' repos: + - repo: https://github.com/pre-commit/pre-commit-hooks + rev: v6.0.0 + hooks: + - id: check-case-conflict + - id: check-merge-conflict + - id: check-toml + - id: check-yaml + - id: end-of-file-fixer + - id: trailing-whitespace - repo: https://github.com/pycqa/isort - rev: "7.0.0" + rev: "8.0.1" hooks: - id: isort - repo: https://github.com/hhatto/autopep8 @@ -12,7 +23,7 @@ repos: - id: autopep8 args: [--in-place, --aggressive, --aggressive] - repo: https://github.com/asottile/pyupgrade - rev: v3.21.0 + rev: v3.21.2 hooks: - id: pyupgrade args: [--py310-plus] @@ -20,9 +31,14 @@ repos: rev: 0.4.3 hooks: - id: teyit + language_version: python3.13 - repo: https://github.com/PyCQA/flake8 rev: "7.3.0" hooks: - id: flake8 additional_dependencies: - flake8-debugger == 4.1.2 + - repo: https://github.com/sphinx-contrib/sphinx-lint + rev: v1.0.2 + hooks: + - id: sphinx-lint diff --git a/.readthedocs.yaml b/.readthedocs.yaml index 047163d..7696b89 100644 --- a/.readthedocs.yaml +++ b/.readthedocs.yaml @@ -1,5 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product # Read the Docs configuration file # See https://docs.readthedocs.io/en/stable/config-file/v2.html for details diff --git a/CHANGES.rst b/CHANGES.rst index 6524b11..eb63100 100644 --- a/CHANGES.rst +++ b/CHANGES.rst @@ -6,6 +6,7 @@ releases, see the file `HISTORY.txt` in this folder. 6.2 (unreleased) ---------------- +- Add support for Python 3.15. 6.1 (2025-11-19) @@ -108,8 +109,8 @@ releases, see the file `HISTORY.txt` in this folder. - moved documentation to Sphinx -- sanitized buildout test script generation to always use the - ``exportimport`` extra and always test the `GenericSetup` +- sanitized buildout test script generation to always use the + ``exportimport`` extra and always test the `GenericSetup` export/import support - Add ``tox`` configuration to support automated testing @@ -125,7 +126,7 @@ releases, see the file `HISTORY.txt` in this folder. - ensure bind passwords used for the LDAP delegate and the user folder do not get out of sync -- Refactor some definitions in the utils module to make them easier +- Refactor some definitions in the utils module to make them easier to override (Patch by Godefroid Chapelle) - Fixed a missing string conversion in getGroupedUsers (Patch by @@ -134,14 +135,14 @@ releases, see the file `HISTORY.txt` in this folder. - Fix python-ldap error when receiving sets instead of lists for attributes to search on (Patch by Godefroid Chapelle) -- When comparing a login value to login values found on the LDAP +- When comparing a login value to login values found on the LDAP server strip the login value first. This follows OpenLDAP behavior - which considers values as matches even with trailing or leading + which considers values as matches even with trailing or leading spaces in the value query filter. (https://bugs.launchpad.net/bugs/1060080) -- LDAPDelegate: When using a user from the Zope security machinery - for the purpose of finding a suitable bind DN and password for +- LDAPDelegate: When using a user from the Zope security machinery + for the purpose of finding a suitable bind DN and password for connecting to a LDAP server, discard it when it's not been created as the result of a real login and thus has an invalid password (https://bugs.launchpad.net/bugs/1060112) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index bbf4194..fbc1bd1 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -1,6 +1,8 @@ # Contributing to dataflake projects diff --git a/HISTORY.txt b/HISTORY.txt index 341c689..7353cd4 100644 --- a/HISTORY.txt +++ b/HISTORY.txt @@ -21,32 +21,32 @@ folder. 2.26 (2013-06-04) ----------------- -- Fix python-ldap error when receiving sets instead of lists for +- Fix python-ldap error when receiving sets instead of lists for attributes to search on (Patch by Godefroid Chapelle) - Some cleanups found by pyflakes ((Patch by Godefroid Chapelle) 2.25 (2013-06-03) ----------------- -- Refactor some definitions in the utils module to make them easier +- Refactor some definitions in the utils module to make them easier to override (Patch by Godefroid Chapelle) -- Fixed a missing string conversion in getGroupedUsers (Patch by +- Fixed a missing string conversion in getGroupedUsers (Patch by Godefroid Chapelle) 2.24 (2012-10-18) ----------------- -- When comparing a login value to login values found on the LDAP +- When comparing a login value to login values found on the LDAP server strip the login value first. This follows OpenLDAP behavior - which considers values as matches even with trailing or leading + which considers values as matches even with trailing or leading spaces in the value query filter. (https://bugs.launchpad.net/bugs/1060080) -- LDAPDelegate: When using a user from the Zope security machinery - for the purpose of finding a suitable bind DN and password for +- LDAPDelegate: When using a user from the Zope security machinery + for the purpose of finding a suitable bind DN and password for connecting to a LDAP server, discard it when it's not been created as the result of a real login and thus has an invalid password (https://bugs.launchpad.net/bugs/1060112) -- use a known set of component versions (versions.txt from Zope +- use a known set of component versions (versions.txt from Zope 2.3.18) to avoid having to micromanage dependency versions - moved change log entries for version 2.18 and older from CHANGES.txt to HISTORY.txt @@ -56,24 +56,24 @@ folder. 2.23 (2012-04-23) ----------------- -- Add ``setuptools-git`` to ``setup_requires`` to prevent missing +- Add ``setuptools-git`` to ``setup_requires`` to prevent missing files in the egg release - versions 2.22 and 2.21 will not build due to a missing ``VERSION.txt``. 2.22 (2012-04-23) ----------------- -- factored some tests into separate modules to increase +- factored some tests into separate modules to increase maintainability - Moved all documentary text files into the egg root 2.21 (2012-04-21) ----------------- -- Make sure to raise OverflowError if no users can be found +- Make sure to raise OverflowError if no users can be found when calling ``getUserNames`` (https://bugs.launchpad.net/bugs/972408) -- switch to using the standalone ``dataflake.fakeldap`` package +- switch to using the standalone ``dataflake.fakeldap`` package for unit tests @@ -89,11 +89,11 @@ folder. 2.19 (2011-01-10) ----------------- -- Add attribute name to the negative_cache_key so requests - for same value but different attribute do not poison the +- Add attribute name to the negative_cache_key so requests + for same value but different attribute do not poison the cache. (https://bugs.launchpad.net/bugs/695821) -- The changed base classes in Zope 2.13 did not define +- The changed base classes in Zope 2.13 did not define isPrincipiaFolderish, so the user folder would no longer show up in the left hand navigation pane in the ZMI. (https://bugs.launchpad.net/bugs/693315) @@ -102,25 +102,25 @@ folder. string and unicode to use basestring. (https://bugs.launchpad.net/bugs/700071) - Fixed an export/import test error so all tests run again. -- The Manager DN Password value on the ``Configure`` tab in the - ZMI showed up in clear text when viewing the HTML source for +- The Manager DN Password value on the ``Configure`` tab in the + ZMI showed up in clear text when viewing the HTML source for the rendered page. (https://bugs.launchpad.net/bugs/664976) 2.18 (2010-07-29) ----------------- -- Added a new flag ``purge`` to the ``ldap-servers`` and - ``ldap-schema`` export/import XML elements for finer-grained - control over value purging for those two settings if the +- Added a new flag ``purge`` to the ``ldap-servers`` and + ``ldap-schema`` export/import XML elements for finer-grained + control over value purging for those two settings if the global purge flag is not set. (https://bugs.launchpad.net/bugs/586970) -- The export/import code did not handle server definitions +- The export/import code did not handle server definitions using the ``ldapi`` protocol correctly. (part of https://bugs.launchpad.net/bugs/586970) -- When adding a new server definition, the comparison to avoid - duplicate server definitions was faulty. Furthermore, operations - and connection timeout values were disregarded for duplicate +- When adding a new server definition, the comparison to avoid + duplicate server definitions was faulty. Furthermore, operations + and connection timeout values were disregarded for duplicate server definitions. (https://bugs.launchpad.net/bugs/586967) @@ -135,7 +135,7 @@ folder. 2.16 (2010-04-15) ----------------- -- depend on dataflake.ldapconnection so tests run without +- depend on dataflake.ldapconnection so tests run without any hassle. - Use sha hexdigests instead of digests to build cache keys, digest values can contain non-ASCII characters. @@ -143,7 +143,7 @@ folder. 2.15 (2010-04-12) ----------------- -- Changed import/export test code to be compatible with +- Changed import/export test code to be compatible with GenericSetup 1.5 - No longer force-inject the "fakeldap" module into the module namespace sys.modules as "ldap" for testing @@ -151,20 +151,20 @@ folder. 2.14 (2009-12-22) ----------------- -- Updated compatibility with CMF 2.1 and the upcoming +- Updated compatibility with CMF 2.1 and the upcoming dataflake.ldapconnection 1.0 -- Potential Bug: Avoid cache hash clashes by recomputing the hash +- Potential Bug: Avoid cache hash clashes by recomputing the hash when the admin clears the caches in the ZMI (http://www.dataflake.org/tracker/issue_00629) -- Bug: _lookupuserbyattr created its own user search filter and +- Bug: _lookupuserbyattr created its own user search filter and did not take the _extra_user_filter attribute into account (http://www.dataflake.org/tracker/issue_00640) 2.13 (2009-05-02) ----------------- -- Factoring: Removed the SSHA module in favor of using Zope's - AccessControl.AuthEncoding module to handle password creation for +- Factoring: Removed the SSHA module in favor of using Zope's + AccessControl.AuthEncoding module to handle password creation for most types of encryption. - Bug: Binary attribute handling in manage_addUser was broken. Only the first character in the binary attribute's value would be stored. @@ -175,7 +175,7 @@ folder. LDAPUserFolder. When installing the LDAPUserFolder via Buildout, make sure to specify the extra name "exportimport" to automatically pull the GenericSetup dependency: Products.LDAPUserFolder[exportimport] -- Factoring: GenericSetup profile registration and CMF skin folder +- Factoring: GenericSetup profile registration and CMF skin folder registration now moved from code to ZCML. Renamed profile "default" to "cmfldap", that's a more descriptive name. The minimum CMF version required for installing the CMF integration is now 2.1.0, which @@ -189,9 +189,9 @@ folder. breaks if the DN contains commas in any value. Patch by Russell Sim. This also required cleaning up one test that used an invalid DN format. (http://www.dataflake.org/tracker/issue_00623) -- Factoring: For testing, use the fakeldap module from the +- Factoring: For testing, use the fakeldap module from the dataflake.ldapconnection package instead of maintaining a copy here. -- Factoring: Refactored unit tests to use ZopeTestCase and ZopeLite instead +- Factoring: Refactored unit tests to use ZopeTestCase and ZopeLite instead of hand-rolling ZODB connections etc. - Bug: Added explicit CMFDefault dependency for the CMF-related functions by adding an extras_require in setup.py. @@ -203,7 +203,7 @@ folder. 2.11 (2008-08-01) ----------------- - Feature: The site administrator may now set an arbitrary LDAP search - filter expression that will be applied to all user searches in + filter expression that will be applied to all user searches in addition to the default filters. Only those user records matching both the default filter and this arbitrary filter expression will be returned. CAUTION: The filter expression must conform to standard LDAP @@ -212,10 +212,10 @@ folder. - Factoring: Move the LDAP server configuration off the Configure tab in the ZMI to its own LDAP Servers tab to avoid overcrowding the configuration view even more. -- Bug: The unit tests for the LDAPMemberDataTool and the +- Bug: The unit tests for the LDAPMemberDataTool and the LDAPMembershipTool did not run due to a faulty import. -- Bug: The ZMI Caches tab erroneously suggested that a cached user's - last access time would be recorded and/or updated. This was not the case, +- Bug: The ZMI Caches tab erroneously suggested that a cached user's + last access time would be recorded and/or updated. This was not the case, it is recorded at user object creation and then never updated. The Caches tab will now reflect the creation time. Since the API to set or query the last access time was not used anywhere it has been removed. @@ -225,12 +225,12 @@ folder. 2.10 (2008-07-21) ----------------- -- Bug: Recreating the internal cache hash key inside - LDAPUserFolder.__setstate__ can lead to values differring from one thread - to the next, leading to unnecessary extra LDAP lookups for values already +- Bug: Recreating the internal cache hash key inside + LDAPUserFolder.__setstate__ can lead to values differring from one thread + to the next, leading to unnecessary extra LDAP lookups for values already cached under the original key. (http://www.dataflake.org/tracker/issue_00608 by Stefan Loidl) -- Factoring: LDAPUserFolder.__setstate__: Removed old backwards-compatibility +- Factoring: LDAPUserFolder.__setstate__: Removed old backwards-compatibility gyrations. - Bug: FakeLDAP could not handle BASE-scoped searches - Bug: LDAPUserFolder.searchUsers mishandled searches on DN by not passing @@ -239,21 +239,21 @@ folder. 2.9 (2008-06-04) ---------------- -- Bug: LDAPUserFolder.getUserByAttr: The negative login cache used for +- Bug: LDAPUserFolder.getUserByAttr: The negative login cache used for preventing repeated LDAP requests when a user enters wrong - creadentials was keyed on user login alone. This would prevent - subsequent logins with the correct password. Thanks to Tarek + creadentials was keyed on user login alone. This would prevent + subsequent logins with the correct password. Thanks to Tarek Ziade for test and patch and Gilles Lenfant for filing the issue. (http://www.dataflake.org/tracker/issue_00605) -- Refactoring: test suite: Rearrange imports to prevent error messages when +- Refactoring: test suite: Rearrange imports to prevent error messages when the CMF is not present. - Bug: LDAPDelegate.search: Improve searches on binary attributes such as - objectGUID by introducing a method argument that prevents + objectGUID by introducing a method argument that prevents UTF*-conversion of the filter expression passed in. (http://www.dataflake.org/tracker/issue_00576 by Wichert Akkerman) -- Feature: Improve binary attribute handlng by introducing a binary flag +- Feature: Improve binary attribute handlng by introducing a binary flag for LDAP schema items that is consulted when inserting/modifying an - attribute flagged that way. Introduce a hardcoded list of + attribute flagged that way. Introduce a hardcoded list of binary attributes to no convert from UTF-8 when searching. (http://www.dataflake.org/tracker/issue_00598 Dragos Chirila) - Bug: LDAPUserFolder.getUserByAttr: made login attribute and uid attribute @@ -282,25 +282,25 @@ NOTE: In order to use the LDAP-based CMF membership components scripts and templates with their CMF 2.1.0 counterparts - Bug: LDAPMemberDataTool: The "Member Properties" ZMI tab was broken due to a typo in the ZPT code. -- Bug: LDAPMemberDataTool: Adjusted wrapUser to match the changed +- Bug: LDAPMemberDataTool: Adjusted wrapUser to match the changed behavior in CMF 2.1.0 and up. -- Bug: LDAPMembershipTool/LDAPMemberDataTool: Since the core CMF tools +- Bug: LDAPMembershipTool/LDAPMemberDataTool: Since the core CMF tools no longer support the IActionProvider interface the tests to prove the LDAP-based versions support these interfaces have been removed. -- Bug: The functional test rig setup has been changed to avoid +- Bug: The functional test rig setup has been changed to avoid DeprecationWarning-Messages from GenericSetup 1.3 and up. -- Bug: LDAPUserFolder.searchGroups: Make the code more defensive for +- Bug: LDAPUserFolder.searchGroups: Make the code more defensive for situations where a search would return groups without members, suggested by Nick Davis. (http://www.dataflake.org/tracker/issue_00584) -- Feature: Added negative caching for users to avoid querying the LDAP +- Feature: Added negative caching for users to avoid querying the LDAP server again and again for invalid logins. Patch provided by Wichert Akkerman. (http://www.dataflake.org/tracker/issue_00572) - Feature: added a group/membership mapping for group type "univentionGroup" (http://www.dataflake.org/tracker/issue_00569) -- Documentation: Noted the danger of trying to install the CMFLDAP +- Documentation: Noted the danger of trying to install the CMFLDAP extensions into a Plone site: Just don't do it, you will suffer! @@ -319,7 +319,7 @@ NOTE: In order to use the LDAP-based CMF membership components key whenever Zope is restarted. (http://www.dataflake.org/tracker/issue_00535) - LDAPDelegate._connect: We now check to see if a new requested - connection is known to our configuration by checking the + connection is known to our configuration by checking the connection string against the saved server information in order to prevent reusing connections instantiated while handling ldap.REFERRAL exceptions, spotted by Riccardo Lemmi. @@ -346,7 +346,7 @@ NOTE: In order to use the LDAP-based CMF membership components **NOTE**: The python-ldap requirement is now version 2.0.6 or higher -- Fixed a broken security declaration for searchGroups and a +- Fixed a broken security declaration for searchGroups and a left-over form tag in the Users tab (thanks to Klaus Barthelmann) - LDAPDelegate.modify would attempt to modify a LDAP record even if the list of modifications was empty. This is now logged without @@ -361,7 +361,7 @@ NOTE: In order to use the LDAP-based CMF membership components - Group deletion for groups with non-ASCII and non-UTF8 characters was broken, discovered by Eric Brun (http://www.dataflake.org/tracker/issue_00527) -- Unforeseen software combinations, such as CMF < 1.6 in combination +- Unforeseen software combinations, such as CMF < 1.6 in combination with GenericSetup could prevent Zope from starting up because the LDAPUserFolder initialization module would throw an error. @@ -370,7 +370,7 @@ NOTE: In order to use the LDAP-based CMF membership components ---------------- - Sidnei da Silva took the time to root out any use of mutable variables in method argument lists. -- Completely refactored the way searches are handled by the +- Completely refactored the way searches are handled by the FakeLDAP testing fixture. The new code uses intelligent parsing to make sense of a query and apply it in a generic way instead of trying to sniff a filter to guess where the query came from @@ -400,13 +400,13 @@ NOTE: In order to use the LDAP-based CMF membership components - In ActiveDirectory, it is possible to have records (specifically internal system accounts) that have the correct objectClasses to qualify as user records, but they lack the attribute designated as - the chosen UID attribute. Thanks to Wichert Akkerman, these are now + the chosen UID attribute. Thanks to Wichert Akkerman, these are now disregarded. (http://www.dataflake.org/tracker/issue_00484) - Make sure objectGUID, when set on the LDAPUser as a property, gets treated specially (discovered by Wichert Akkerman in the course of clarifying http://www.dataflake.org/tracker/issue_00480) - The SimpleLog.zLOGLogger log method ignored the ``args`` parameter - (http://www.dataflake.org/tracker/issue_00474, thanks go to + (http://www.dataflake.org/tracker/issue_00474, thanks go to Mark Hammond) - Repaired warings appearing in Zope 2.8.5 due to a couple typos in security declarations. @@ -433,7 +433,7 @@ NOTE: In order to use the LDAP-based CMF membership components - The LDAPUserFolder factory method and the initialization code were massively simplified. A lot of duplicated code was removed. When adding a LDAPUserFolder, there is no longer a separate Add view. - The user folder will be created straight away and the admin will + The user folder will be created straight away and the admin will be redirected to the Configure tab of the new instance. **Note**: If you have code that programmatically instantiates LDAPUserFolder instances then you must change it. See @@ -449,11 +449,11 @@ NOTE: In order to use the LDAP-based CMF membership components - A bug had crept into the logging subsystem that could cause spurious error messages. (http://www.dataflake.org/tracker/issue_00462) -- The user records found via the Users tab search were not +- The user records found via the Users tab search were not consistent with the users that can actually log in because the search on the Users tab did not filter out records that do not match the user object classes as defined on the Configure tab. - (http://www.dataflake.org/tracker/issue_00260 and + (http://www.dataflake.org/tracker/issue_00260 and http://www.dataflake.org/tracker/issue_00445) @@ -473,13 +473,13 @@ NOTE: In order to use the LDAP-based CMF membership components - Before returning a new connection in the internal LDAPDelegate connection methods the Manage DSA IT control was enabled. This was the result of misunderstanding the control - it really is - only needed to directly access and manipulate a referral or + only needed to directly access and manipulate a referral or alias entry without having the server send you to the referred or aliased server. - The old behavior of mapping every LDAP group name a user is member - of to a Zope role of the same name can now be reactivated using + of to a Zope role of the same name can now be reactivated using a new configuration option named "Group mapping" on the - Configuration tab. Many thanks to Dirk Bergstrom for a set of + Configuration tab. Many thanks to Dirk Bergstrom for a set of patches and unit tests. (http://www.dataflake.org/tracker/issue_00459) @@ -498,11 +498,11 @@ NOTE: In order to use the LDAP-based CMF membership components (http://www.dataflake.org/tracker/issue_00446 by Pierre-Julien Grizel) - An earlier special-casing applied by Chris McDonough to - correctly handle AD objectGUID values has been applied in a + correctly handle AD objectGUID values has been applied in a second place, in the findUser method (patch by Mark Hammond). - Deleting a user record would be short-circuited if the user record itself was not in the DIT anymore, e.g. because someone - manipulated the DIT without the user folder knowing about it. + manipulated the DIT without the user folder knowing about it. This prevented cleanups for group memberships to be performed. (http://www.dataflake.org/tracker/issue_00439 by Hans-Juergen Sell) @@ -512,13 +512,13 @@ NOTE: In order to use the LDAP-based CMF membership components getUserNames now also raises a OverflowError if no results have been returned in order to show a simple text input widget on the local role management view instead of the multiple choice select - box. (http://www.dataflake.org/tracker/issue_00442 by Andrew - Veitch and http://www.dataflake.org/tracker/issue_00441 by + box. (http://www.dataflake.org/tracker/issue_00442 by Andrew + Veitch and http://www.dataflake.org/tracker/issue_00441 by Hans-Juergen Sell) - Added the new logging machinery to the LDAPDelegate class which improves lower-level LDAP problem discovery. - Moved away from the current way of logging to a purely zLOG-based - mechanism. This will make sure that all logging for Zope is in + mechanism. This will make sure that all logging for Zope is in one and the same place and that more information can be passed along to the logging mechanism, such as tracebacks. (http://www.dataflake.org/tracker/issue_00438 by Mark Hammond) @@ -528,7 +528,7 @@ NOTE: In order to use the LDAP-based CMF membership components subclassing LDAPDelegate and overriding implementation details has become easier. (http://www.dataflake.org/tracker/issue_00438 by Mark Hammond) -- Added a registry for delegate implementations so that other +- Added a registry for delegate implementations so that other delegate classes can register themselves with this registry and become available to the LDAPUserFolder during instantiation. @@ -576,7 +576,7 @@ NOTE: In order to use the LDAP-based CMF membership components the LDAP server through a file socket. Please see the README for additional notes on LDAP over IPC. - + 2.5beta1 (2004-11-20) --------------------- - The setting for groups storage was not carried over from the Add @@ -608,7 +608,7 @@ NOTE: In order to use the LDAP-based CMF membership components a request several attempts at connecting to the LDAP server are made. The time it takes for the LDAPUserFolder to return control to Zope will be the sum of the connection attempts - multiplied by the chosen Timeout value. + multiplied by the chosen Timeout value. 2.4 (2004-07-31) @@ -622,7 +622,7 @@ NOTE: In order to use the LDAP-based CMF membership components **IMPORTANT NOTE**: This version of the LDAPUserFolder does away with the old behavior of implicitly mapping LDAP groups to Zope roles. Any Zope roles that get conferred - are governed by the "LDAP group to Zope role" + are governed by the "LDAP group to Zope role" form on the "Groups" tab. If you relied on this behavior please create the appropriate mappings in your instance. @@ -636,7 +636,7 @@ future Zope releases. part of the Configure tab. - Added MD5 to the list of available default password encryption methods -- Refactored caching using a new simple cache class contributed +- Refactored caching using a new simple cache class contributed by Chris McDonough. - getAttributeOfAllUsers method removed in favor of a more general getAttributesOfAllObjects method on LDAPUserFolder @@ -669,7 +669,7 @@ future Zope releases. enabled. To go back to the old behavior the old log code is still in place, but must be enabled by hand in the python code. This represents a reversed decision on JTracker issue 247. -- Refactored the Groups tab in the Zope Management Interface +- Refactored the Groups tab in the Zope Management Interface (ZMI) to be less cluttered and be clearer about the difference between group records in LDAP versus roles in Zope. - LDAPDelegate's search method now ignores nonstandard internal @@ -689,14 +689,14 @@ future Zope releases. LDAPUserFolder are dependent on the "LDAP group to Zope role" mapping that can be manipulated on the "Groups" tab in the ZMI. The existing behavior of adding the roles specified as "Default - user roles" on the "Configure" tab to all authenticated users - remains the same. This change means that the administrator now has + user roles" on the "Configure" tab to all authenticated users + remains the same. This change means that the administrator now has *full control* over what roles a user can have. 2.4beta2 (2004-04-14) --------------------- -From this version on the LDAPUserFolder product will drop +From this version on the LDAPUserFolder product will drop compatibility with Python 2.1. You should use Python 2.2.3 with Zope 2.6.x or Python 2.3.3 with Zope 2.7.x @@ -762,7 +762,7 @@ existing LDAPUserFolder and LDAPUserSatellite instances! permission (JTracker issue 355 by Florent Guillaume). - Add shortcut in getUser to immediately return None is the passed name is empty or None. -- If it is available I am now using the ReconnectLDAPObject for +- If it is available I am now using the ReconnectLDAPObject for LDAP connections since it promises to hide temporary connection problems and long connection timeouts. This could potentially fix JTracker issue 324 by P.-J Grizel. @@ -781,7 +781,7 @@ existing LDAPUserFolder and LDAPUserSatellite instances! number of trips back to the LDAP server should be reduced. - The list of user IDs generated by calls to getUserList is no longer a thread-level variable but globally shared, - meaning this potentially expensive search operation will be + meaning this potentially expensive search operation will be performed less often. - These changes were also applied to the LDAPUserSatellite log, user to role mapping and expiration mappings. @@ -790,7 +790,7 @@ existing LDAPUserFolder and LDAPUserSatellite instances! 2.3 (2003-12-18) ---------------- - Noticed that sometimes "empty" authentication credentials lead - to unnecessary lookups for non-existing users. Relaxed a + to unnecessary lookups for non-existing users. Relaxed a specific authentication check so this is prevented. - The unicode changes had possible disabling consequences for group-to-role mappings defined on the Groups tab. Thanks go @@ -801,18 +801,18 @@ existing LDAPUserFolder and LDAPUserSatellite instances! --------------------- - Fixed a couple buglets found by Florent Guillaume (JTracker issue 333). -- Florent also noticed code that would trigger unnecessary +- Florent also noticed code that would trigger unnecessary MODRDN calls when a user record was updated. This extra call did not damage the record, it was just unnecessary work (issue 334). - Dieter Maurer provided the explanation for a recursion error - in the __getattr__ method on the LDAPUser object that a + in the __getattr__ method on the LDAPUser object that a few people had run into (JTracker issue 338 by Michael Crawford). - The getGroupedUsers method was not working if the groups are stored in the user folder itself (JTracker issue 342, thanks Florent Guillaume again). -- Spurred by Helge Tesdal and Nate Aune I spent a little more +- Spurred by Helge Tesdal and Nate Aune I spent a little more time on the unicode-ability. Now a user that has non-ASCII characters not just in arbitrary attributes but also in attributes that form part of the full DN are processed @@ -823,11 +823,11 @@ existing LDAPUserFolder and LDAPUserSatellite instances! 2.3beta2 (2003-11-02) --------------------- - Cut down on the number of LDAP lookups in cases where the - user lookup happens "anonymously", meaning not as part of a + user lookup happens "anonymously", meaning not as part of a normal authenticated request but from the Zope security machinery for things like ownership-related security checks. Thanks to Kyler Laird for bringing this one up. -- All user lookups are now limited to those object classed +- All user lookups are now limited to those object classed defined in the "User object classes" configuration setting on the "Configure" tab. Previously the lookup policy was much more lenient and accepted every record where the login @@ -836,7 +836,7 @@ existing LDAPUserFolder and LDAPUserSatellite instances! WITH THE OBJECT CLASSES SETTING AND USAGE!*** Due to the possible breakage I had been sitting on Tracker issue 294, filed by Andy Dustman, for quite a while before - going with it. Thanks for keeping the pressure on - it is + going with it. Thanks for keeping the pressure on - it is "the right thing" to do. - The "Users" tab will now show a little more information on the user record detail view by default, namely the DN and @@ -857,18 +857,18 @@ existing LDAPUserFolder and LDAPUserSatellite instances! - Cleaned up LDAP filter strings used by the product to have surrounding parentheses. - Enable correct handling of DN elements that contain bad - characters, such as backslash-escaped commas (Bug report + characters, such as backslash-escaped commas (Bug report by Stephen Kirby) 2.2 (2003-08-08) ---------------- - User attributes can now be declared "multi-valued" in the - LDAP Schema, thereby ensuring that all values for that + LDAP Schema, thereby ensuring that all values for that attribute are stored on the user object (Feature request by Jean Jordaan, JTracker issue 294). - While investigating JTracker issue 309 ("problem changing password") - it became apparent that previous fixes to correctly use mapped + it became apparent that previous fixes to correctly use mapped attributes during user creation were flawed. Also, _expireUser is now more resilient against receiving invalid user information. @@ -881,19 +881,19 @@ existing LDAPUserFolder and LDAPUserSatellite instances! all newer servers should be able to handle that. - Removed non-existent "_expire" call from the interfaces file for the LDAPUser class (JTracker issue 303 filed by Jean Jordaan) -- Added "clear" password encryption scheme to the choices +- Added "clear" password encryption scheme to the choices available when adding a new LDAPUserFolder (JTracker issue 295, thanks to Andy Dustman) - Added some (obviously missing) logging calls. Thanks to Jean Jordaan for telling me about it (JTracker issue 300). Also, added a missing message return from the LDAPDelegate modify method. -- Revamped group handling a little bit so that the +- Revamped group handling a little bit so that the GROUP_MEMBER_MAP mapping in the utils module is the central place where permissible groups and their member types are stored. Fixed issue 289 by Eric Brun which was suffering from a related problem at the same time. -- If a new user is created and the form fields are not named +- If a new user is created and the form fields are not named after the real LDAP attribute names but with mapped names as specified on the LDAP schema tab the correct reverse translation will now be done (JTracker issue 301, thanks to @@ -920,13 +920,13 @@ existing LDAPUserFolder and LDAPUserSatellite instances! visible on the "Configure" tab. (JTracker issue 284 by Dirk Datzert) - Started a separate README for those hapless users who are stuck - on Active Directory with input from Philipp Kutter (JTracker + on Active Directory with input from Philipp Kutter (JTracker issue 280), see README.ActiveDirectory.txt -- If roles were stored locally and a user with locally stored +- If roles were stored locally and a user with locally stored roles had all roles removed that user would still show up in - the user listing, even if the user record itself was removed + the user listing, even if the user record itself was removed from LDAP. Now removal of all roles will clean the internal - roles storage mechanism correctly. Thanks go to Hans-Juergen + roles storage mechanism correctly. Thanks go to Hans-Juergen Sell for letting me know. - When a user logs in the application will no longer construct the user object with the name typed in by the user but will @@ -937,20 +937,20 @@ existing LDAPUserFolder and LDAPUserSatellite instances! - Domain restrictions put on the emergency/init-users were not respected, thanks to Dirk Datzert for pointing that out in JTracker issue 283. -- Broke the Caches tab if and when the anonymous cache +- Broke the Caches tab if and when the anonymous cache contained any users, the display for anonymous cache users was calling a non-existing method. (JTracker issue 281, my thanks go to Ronan Amicel) -- Logic error in getGroups corrected that could lead to binding +- Logic error in getGroups corrected that could lead to binding with an invalid user/password pair. Now the decision what to bind as is left completely up to the LDAPDelegate itself. - Added workaround for changed behavior of ldap.explode_dn which will blow up now if the passed-in DN does not contain at least one key=value pair. -- Removed superfluous argument to manage_setUserProperty +- Removed superfluous argument to manage_setUserProperty (Tracker issue 270 by Dirk Datzert) - Fixed manage_setUserProperty errors that crept in during - the last great code reorganization and also added a unit + the last great code reorganization and also added a unit test to exercise this method. (Tracker issue 269, thanks to Dirk Datzert again for pointing that out) @@ -1055,12 +1055,12 @@ No significant changes between 2.1 beta3 and 2.1 changed in the utils module, whereas before it was hardcoded to be "Latin-1" in all places. - The getUserDetails method API was extended to allow passing - in a sequence of desired attributes. This is helpful when + in a sequence of desired attributes. This is helpful when certain attributes (e.g. binary pictures) are not needed and - would unnecessarily slow down the request. This feature + would unnecessarily slow down the request. This feature suggested by Artur Zaprzala. - The module reorganization broke the decoding of UTF-8 values - which meant non-ASCII characters appeared as garbage + which meant non-ASCII characters appeared as garbage characters. Artur Zaprzala posted a set of patches in Tracker issue 198 to fix the issue and simplify/improve the unicode handling in general. @@ -1070,27 +1070,27 @@ No significant changes between 2.1 beta3 and 2.1 --------------------- Version 2.0 represents a major code base refactoring. The main goals were code simplification, cruft removal and improving -maintainability for me. While this meant putting the axe to +maintainability for me. While this meant putting the axe to some features it also enabled me to implement some other functionality that would have been much harder to do using the old code. -- ZBabel support has been discontinued. - I have received very little (meaning No) feedback on it and - even before it was offered only very few people requested it. - I myself did not have an environment set up where I could - maintain the translation dictionaries, mainly because the way - they are updated is (in my opionion) a huge PITA. I got tired of - lugging code along that got more stale with every update I did - to the main cod. Since I have been on a simplification spree for +- ZBabel support has been discontinued. + I have received very little (meaning No) feedback on it and + even before it was offered only very few people requested it. + I myself did not have an environment set up where I could + maintain the translation dictionaries, mainly because the way + they are updated is (in my opionion) a huge PITA. I got tired of + lugging code along that got more stale with every update I did + to the main cod. Since I have been on a simplification spree for version 2.0 it was one of the first items to go. My apologies to Dirk Datzert who performed the most of the ZBabel integration work last year. - Cookie support is no longer built into the product. If you need cookie-based authentication I recommend installing the - CookieCrumbler product alongside the LDAPUserFolder. It performs + CookieCrumbler product alongside the LDAPUserFolder. It performs all functionalities of the built-in cookie support. See - http://www.zope.org/Members/hathawsh/CookieCrumbler for + http://www.zope.org/Members/hathawsh/CookieCrumbler for information and download. - You can now specify multiple LDAP servers to be used by the LDAPUserFolder. Servers are used in a failover fashion. If the @@ -1098,22 +1098,22 @@ old code. This assumes that the LDAP data structure on both servers is identical, e.g. the users search base is the same. - The LDAPUserSatellite can now be used in recursive fashion. This - means it can go out and consult all LDAPUserSatellites in its + means it can go out and consult all LDAPUserSatellites in its acquisition path and have them make any role manipulations before doing its own work, thereby getting a cumulative effect. Please - use caution with this feature because it is potentially very + use caution with this feature because it is potentially very expensive. 1.6 (unknown) ------------- -That's it, folks... this is the end of the 1.x line of -LDAPUserFolders. The new version, LDAPUserFolder 2.x, +That's it, folks... this is the end of the 1.x line of +LDAPUserFolders. The new version, LDAPUserFolder 2.x, is out by now and I encourage everyone to give it a try. It has many added features and, above all, a refactored code base that makes it easier for me to maintain and improve. -From this point on no new features will be added to the +From this point on no new features will be added to the 1.x series, and only urgent bug fixes. All development will concentrate on the 2.x series. @@ -1128,7 +1128,7 @@ concentrate on the 2.x series. 1.6beta2 (unknown) ------------------ - A brand new object can now be instantiated after upgrading - to this version. It's called "LDAPUserSatellite" and is + to this version. It's called "LDAPUserSatellite" and is used to manipulate roles for a user based on the context the user is in if a LDAPUserSatellite is around. Roles can be manipulated by applying a mapping from @@ -1136,15 +1136,15 @@ concentrate on the 2.x series. a group record lookup in an additional groups search path on your LDAP server. The LDAPUserSatellite does not directly change global roles - on the user object like the LDAPRoleTwiddler and + on the user object like the LDAPRoleTwiddler and LDAPRoleExtender did, it uses internal Zope security mechanisms to compute roles based on context. - This new object replaces both the LDAPRoleTwiddler and + This new object replaces both the LDAPRoleTwiddler and the LDAPRoleExtender, which are hereby deprecated. Thanks go to Dirk Datzert who did some extensive testing and helped me hunt down a lot of bugs. - Better logging for using cached users -- Caches ZMI tab more informative by presenting both +- Caches ZMI tab more informative by presenting both authenticated and anonymous cache contents - Update some outdated help files for the LDAPUserFolder @@ -1159,28 +1159,28 @@ concentrate on the 2.x series. record, suggested by Michael Stroeder. - Logging and caching are factored out into instance-level objects -- The security model has seen a complete change to make - it simpler and to respect access controls placed on the +- The security model has seen a complete change to make + it simpler and to respect access controls placed on the LDAP server itself more: - providing a Manager DN and password is optional - if a Manager DN has been provided in the configuration - then that DN will be used to bind for every single + then that DN will be used to bind for every single LDAP operation - if no Manager DN has been provided then the current user's DN will be used for binding. - if no Manager DN has been provided and a user who - authenticated against another user folder is + authenticated against another user folder is attempting to perform LDAP operations it will be performed with an anonymous bind. - This all implies that if you want to make changes in LDAP that - require specific rights you must either log in as a user with - those specific rights or use the less security-conscious - workaround of providing a Manager DN in the LDAPUserFolder - configuration. - If you attempt to make changes with a Manager user - authenticated against another user folder you might not be able + This all implies that if you want to make changes in LDAP that + require specific rights you must either log in as a user with + those specific rights or use the less security-conscious + workaround of providing a Manager DN in the LDAPUserFolder + configuration. + If you attempt to make changes with a Manager user + authenticated against another user folder you might not be able to, which might be a source of confusion for some Zope admins. - Catch ldap.PARTIAL_RESULTS after issuing a search request to the server, something the Micro$haft "Active Directory" @@ -1197,12 +1197,12 @@ concentrate on the 2.x series. display semicolon-separated values for all multi-valued attributes when you view the record. - A misconfigured Users base DN setting is now less likely to - lead to complete blowups upon trying to connect to the + lead to complete blowups upon trying to connect to the LDAP server so that access to the container will always remain - intact and the LDAPUserFolder can be reconfigured or deleted + intact and the LDAPUserFolder can be reconfigured or deleted if needed. - No blowups from getUser if the name passed in is not a string, - just returns None instead now. (Tracker issue 166 filed by + just returns None instead now. (Tracker issue 166 filed by Romain Eliot) @@ -1214,8 +1214,8 @@ concentrate on the 2.x series. (Tracker issue 163, my thanks go to John Hohm who did a lot of the detective work for this one himself) - Using a better search filter in case getGroups is asked - to return all groups available to the LDAPUserFolder. - Improved the doc string for getGroups to clarify its + to return all groups available to the LDAPUserFolder. + Improved the doc string for getGroups to clarify its usage. Michael Stroeder suggested the better search filter. @@ -1223,7 +1223,7 @@ concentrate on the 2.x series. --------------------- - New method getLocalUsers added to allow for retrieving all user DNs and their roles that have roles stored - locally. If user roles are stored locally this method is + locally. If user roles are stored locally this method is now used on the Users ZMI tab to show a list of all users with locally stored roles. This is more or less a convenience so that the admin does not have to search @@ -1231,7 +1231,7 @@ concentrate on the 2.x series. find out about a user's roles. - The implementation for getGroupDetails was incomplete for locally stored groups. It is now fully implemented. -- New method "getGroupedUsers" will return a sequence of +- New method "getGroupedUsers" will return a sequence of user objects for the groups you pass as argument. If no groups are passed then user objects from all groups that are visible to the LDAPUserFolder are returned. @@ -1239,10 +1239,10 @@ concentrate on the 2.x series. by ensuring __getattr__ can now find the DN attribute. Trying to call getUserDN on a unwrapped user object will always raise an error due to the nature of wrapping - and security declarations. __getattr__ does not raise + and security declarations. __getattr__ does not raise this error. - manage_setUserProperty is now more useful by allowing - set set empty properties, which it did not before. + set set empty properties, which it did not before. (Tracker Issue 158, thanks to Sven Thomsen) - The manage_editUser method will no longer blow up if the specific user's RDN attribute is not part of the values @@ -1253,17 +1253,17 @@ concentrate on the 2.x series. 1.5beta2 (2002-07-08) --------------------- - The latest versions of OpenLDAP seem to complain about - the LDAP protocol in use if it is not LDAPv3. Added a + the LDAP protocol in use if it is not LDAPv3. Added a workaround that catches the complaint and explicitly sets the protocol. -- Corrected some faulty default arguments that could have +- Corrected some faulty default arguments that could have caused errors in certain cases. -- The group search scope was mis-applied to a search that +- The group search scope was mis-applied to a search that takes a group DN and returns its objectClass. This would - cause errors if SCOPE_ONELEVEL is the groups search scope + cause errors if SCOPE_ONELEVEL is the groups search scope because that scope does not include the object pointed to - by the group DN. Changed to always use SCOPE_BASE (this - scope searches the current object only) instead (Tracker + by the group DN. Changed to always use SCOPE_BASE (this + scope searches the current object only) instead (Tracker issue 141, thanks go to Philippe May). - A similar bug as the one above afflicted the _lookupuser method. Changed search scope to SCOPE_BASE as well. Derrick @@ -1278,28 +1278,28 @@ concentrate on the 2.x series. - Small fix on add form to ensure form element naming is consistent (Tracker issue 139 by David Riggs). - Instead of adding a workaround for the (faulty) ability - to create and have empty group records on Netscape + to create and have empty group records on Netscape directory server products (which then won't show up on - the LDAPUserFolder "Groups" tab) I have added a paragraph + the LDAPUserFolder "Groups" tab) I have added a paragraph in the README that addresses why it happens and what to do. - A stupid syntax error on my part prevented the "SERVER_DOWN" - exception that was used to determine the freshness of a - reused connection object to ever be caught correctly. Brad + exception that was used to determine the freshness of a + reused connection object to ever be caught correctly. Brad Powell pushed my nose into that and made me fix it. 1.4 (2002-05-17) ---------------- -- All actions performed on the management tabs with the +- All actions performed on the management tabs with the lone exception of the "Custom Forms" tab will now go back to the same tab, with the correct tab highlighted. (Tracker issue 127, thanks to David Riggs) -- Expiring users out of the caches when the record got +- Expiring users out of the caches when the record got changed was not working in all cases. The expiration is now more explicit and involves manipulating the caches - directly instead of changing the expiration time on the + directly instead of changing the expiration time on the user object (Tracker item 128). -- IE on windoze misbehaves when setting a cookie where +- IE on windoze misbehaves when setting a cookie where expiration is set to an empty string. All other browsers (surprise surprise!) behave correctly, but IE will foil any login attempts when using cookie mode. Added a @@ -1308,14 +1308,14 @@ concentrate on the 2.x series. 1.4beta3 (2002-05-08) --------------------- -- The code used to format exceptions in the utils method +- The code used to format exceptions in the utils method was called the wrong way and failed when it was called - to format an exception (Tracker issue 125, thanks to + to format an exception (Tracker issue 125, thanks to David Riggs). -- A juxtaposition in arguments to manage_edit led to - segfaults in some applications (spotted by Tres +- A juxtaposition in arguments to manage_edit led to + segfaults in some applications (spotted by Tres Seaver). -- Logging is extracted into its own module (SimpleLog), +- Logging is extracted into its own module (SimpleLog), thereby making it easier to extend later. @@ -1325,56 +1325,56 @@ concentrate on the 2.x series. insensitive (Tracker # 123 from Jan Idzikowski). - The LDAPUserFolder will now use the LDAP database connection on a more persistent basis. A connection - gets stored away and reused until it breaks or until the - object is ghosted by Zope. This should speed up LDAP + gets stored away and reused until it breaks or until the + object is ghosted by Zope. This should speed up LDAP accesses in many situations. 1.4beta1 (2002-05-06) --------------------- - The unicode verification in utils.py could not deal with - non-ascii characters (Tracker issue 122, thanks to Jan + non-ascii characters (Tracker issue 122, thanks to Jan Idzikowski). - The setting for encryption scheme was never set with the selection from the add form (thanks Dirk Datzert). - The redirection after calling the constructor method has - been changed to use RESPONSE.redirect to get over the - idiosyncrasies of returning something from a self that + been changed to use RESPONSE.redirect to get over the + idiosyncrasies of returning something from a self that is a factory dispatcher and not a container. (thanks to Dirk Datzert) -- Internal cache is no longer case-sensitive (suggested +- Internal cache is no longer case-sensitive (suggested by Dirk Datzert) - The list of available LDAP groups to map to Zope roles - on the Groups tab is now sorted alphabetically (suggestion + on the Groups tab is now sorted alphabetically (suggestion from Dirk Datzert). 1.3 (2002-04-16) ---------------- - Added workaround for the missing "crypt" module problem - that only appears on a so-called OS from Redmond. (Tracker + that only appears on a so-called OS from Redmond. (Tracker issues 119 and 120) -- Simplified package structure somewhat by adding a utils - module that defines methods or constants used in the +- Simplified package structure somewhat by adding a utils + module that defines methods or constants used in the other modules. -- As a step to better unicode handling the LDAPUser now +- As a step to better unicode handling the LDAPUser now stores all attribute strings as unicode strings. 1.3beta1 (2002-04-05) --------------------- -- Small bug in user object caching code that could lead to - duplicate user objects being cached which only differ in +- Small bug in user object caching code that could lead to + duplicate user objects being cached which only differ in capitalization. - Added a couple small improvements and fixes as suggested by Dieter Maurer. - Added workaround for the buggy windoze ldap.pyd that does not have a meaningful __version__ string (Tracker issue 118). -- Added the ability to map a LDAP group name to a Zope role +- Added the ability to map a LDAP group name to a Zope role name. In a nutshell, if LDAP group "Employee" is mapped to - Zope role "Member" then anyone who authenticates through - LDAP and is in LDAP group "Employee" will have "Employee" + Zope role "Member" then anyone who authenticates through + LDAP and is in LDAP group "Employee" will have "Employee" and "Member" in the list of roles for the user. @@ -1385,21 +1385,21 @@ concentrate on the 2.x series. make user password encryption schemes selectable in the LDAPUserFolder configuration. Thanks Dirk! - Added a new configuration toggle to set the use of SSL - for the LDAP server connection. This option will be - ignored and appear greyed-out on the Configure tab if + for the LDAP server connection. This option will be + ignored and appear greyed-out on the Configure tab if the python-ldap module version is lower than 2.0. - The detailed user data view on the Users tab will now - show the full DN for every group that is listed as + show the full DN for every group that is listed as possible roles for a user. This will help everyone who - has roles with the same name defined several times + has roles with the same name defined several times underneath their groups search base (Tracker item 107, thanks go to David Rideau). 1.2beta3 (2002-01-30) --------------------- -- Not only did the importing semantics for the latest - python-ldap modules change, some fundamental method +- Not only did the importing semantics for the latest + python-ldap modules change, some fundamental method signatures changed as well. This fixes the call to ldap.open which led to uncontrollable debugging output on the command line since 1.2beta2 (Tracker @@ -1408,7 +1408,7 @@ concentrate on the 2.x series. 1.2beta2 (2002-01-29) --------------------- - Ensure compatibility with the latest python-ldap releases - which introduced an underdocumented and spurious change + which introduced an underdocumented and spurious change that mandates a different way of importing the ldap module. (Tracker issues 102 and 105) The recommended python-ldap module to use remains @@ -1419,8 +1419,8 @@ concentrate on the 2.x series. 1.2beta1 (2002-01-28) --------------------- - If the authentication information was incorrect, the - _searchResults method would raise the Unauthorized - exception, which would make basic HTTP authentication boxes + _searchResults method would raise the Unauthorized + exception, which would make basic HTTP authentication boxes pop up even in cookie mode. It now returns an empty string and users will get the login page when in cookie mode. Tracker issue 87 - thanks to Eric Brun. @@ -1429,18 +1429,18 @@ concentrate on the 2.x series. form. The line break has been removed. (Tracker issue 103, thanks once again to Florent Guillaume) - A little more extended debug logging in the _lookupuser - method (suggested by Marc-Aurele Darche of IDEALX, Tracker + method (suggested by Marc-Aurele Darche of IDEALX, Tracker issue 101) - The RDN Attribute dropdown in the Configure tab now lists all attributes defined on the LDAP Schema tab. This allows the administrator to select any attribute if the LDAP setup - violates RFC 2377. Suggestion and patch (thanks!) from + violates RFC 2377. Suggestion and patch (thanks!) from Marc-Aurele Darche of IDEALX, Tracker issue 101. 1.1 (2001-12-14) ---------------- -- Exclusively use direct string method invocation as opposed +- Exclusively use direct string method invocation as opposed to using the string module - Mistakenly cached the superuser account upon successful authentication. This would break the "Caches" tab because @@ -1465,11 +1465,11 @@ concentrate on the 2.x series. 1.1beta2 (2001-12-04) --------------------- - The administrator can now choose between reading group - information from the LDAP server or storing it inside + information from the LDAP server or storing it inside the LDAP User Folder itself. This feature has been added in response to Tracker issue 94. Thanks go to Colin Smith for bringing this configuration option to my attention. -- The Users tab in the ZMI would show tracebacks if the +- The Users tab in the ZMI would show tracebacks if the connection to the LDAP server produced an error. Now the real error is shown (Tracker Issue 93) - Some details of the ZBabel transition did not work @@ -1491,33 +1491,33 @@ concentrate on the 2.x series. - Adding of users was broken because of a faulty invocation for translating record attributes into UTF-8 (Tracker issue 83, thanks go to Magnus Heino) -- Changing some attribute names led to the main management - screen bombing out (Tracker Issue 84, thanks go to +- Changing some attribute names led to the main management + screen bombing out (Tracker Issue 84, thanks go to Magnus Heino) - The way in which caches were used in getUser was broken since the last few betas and cache records with a fake passwords were sometimes used in a real validation context. - LDAP User objects now have a __getattr__ that will look into the internal properties dictionary, meaning direct - attribute access is now possible without the need to + attribute access is now possible without the need to use getProperty(). The "Public User Attribute" machinery - has been renamed to explain its new meaning in this + has been renamed to explain its new meaning in this context: It is used to map an attribute name from LDAP to another name that will also appear on the user object. 1.0 beta5 (unknown) ------------------- -- Default roles were no longer applied (Tracker issue 73, +- Default roles were no longer applied (Tracker issue 73, thanks go to Eric Brun) -- Passwords can now contain colon (:) characters. This +- Passwords can now contain colon (:) characters. This would break reading the authentication cookie in cookie mode before (Tracker issue 74, thanks to Eric Brun) - Added logging to cache lookup successes and decided to - simplify getUserById at the same time (Tracker issue + simplify getUserById at the same time (Tracker issue 75, thanks to Eric Brun) - The user ID as seen by zope is now guaranteed to be the - same every time a user logs in, regardless of name + same every time a user logs in, regardless of name capitalization (which LDAP ignores upon searching). Tracker issue 77, thanks go to Eric Brun. @@ -1531,9 +1531,9 @@ concentrate on the 2.x series. 1.0 beta3 (2001-11-07) ---------------------- - Added compatibility with WebDAV and FTP when in cookie mode -- Basic Auth is used as "last resort" when authenticating +- Basic Auth is used as "last resort" when authenticating a user, meaning if you change to cookie mode from basic - auth mode there will be no login screen if you were + auth mode there will be no login screen if you were logged in. - An attempt is made, while in cookie mode, to hand off authentication to the next user folder above if a user @@ -1541,18 +1541,18 @@ concentrate on the 2.x series. above. - The life span of the authentication cookie (if cookie mode is in use) can now be set by the administrator. -- Vast amounts of code were removed by integrating the +- Vast amounts of code were removed by integrating the validate/authenticate/identify machinery better into the machinery provided by the BasicUserFolder base class. 1.0 beta2 (2001-10-15) ---------------------- -**WARNING**: As of this point the product is not API-compatible -with the LDAPUserManager or LDAPLoginAdapter anymore. The API will +**WARNING**: As of this point the product is not API-compatible +with the LDAPUserManager or LDAPLoginAdapter anymore. The API will change even more before the final 1.0-release. -Please experiment but don't use in production unless you really +Please experiment but don't use in production unless you really know what you are doing. - The LDAP User Folder is much more flexible with the groups @@ -1568,7 +1568,7 @@ know what you are doing. - The "LDAP Schema" tab has been completely revamped. The fields for inputting a mapped public name that will show up on the user object to an LDAP attribute has been integrated into the main - display and can be triggered by adding attributes with the + display and can be triggered by adding attributes with the optional "Public name" value filled in. - The "log verbosity" setting has been moved onto the "Log" tab. - The horribly kludgy "getGroupsWithInconsistentRecords" method, @@ -1576,13 +1576,13 @@ know what you are doing. - Any attempt to be backwards-compatible with Python 1.5.x was removed. This product needs Zope 2.4.x, which in turn depends on Python 2.1.x or higher. -- The "Advanced" configuration tab has been removed after +- The "Advanced" configuration tab has been removed after consolidating its functionality into other screens. 1.0 beta1 (2001-10-09) ---------------------- -This product combines the LDAPLoginAdapter and LDAPUserManager +This product combines the LDAPLoginAdapter and LDAPUserManager products into a single package. It is designed to supplant both of them and further development, apart from urgent bug fixes, will be limited to this product. @@ -1593,7 +1593,7 @@ should continue to use the LDAPLoginAdapter/LDAPUserManager combo. This first version is simply a combination of all contents from all classes used in the LDAPLoginAdapter and LDAPUserManager -code. Future plans (probably version 2.0 and up) will include +code. Future plans (probably version 2.0 and up) will include a complete refactoring with class separation of - Storage backend operations @@ -1609,5 +1609,5 @@ Other cleanups in this first cut involve the following: - throwing out of code that tried to fake unicode support for Python versions prior to 1.6 -- Some refactoring of ZMI screens, there will undoubtedly be +- Some refactoring of ZMI screens, there will undoubtedly be more in the future. diff --git a/MANIFEST.in b/MANIFEST.in index 9cdc393..0033b73 100644 --- a/MANIFEST.in +++ b/MANIFEST.in @@ -1,5 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product include *.md include *.rst include *.txt diff --git a/README.rst b/README.rst index 9d745ab..cea2b7e 100644 --- a/README.rst +++ b/README.rst @@ -21,6 +21,6 @@ Products.LDAPUserFolder ========================= -This product is a replacement for a Zope user folder. It does not store its +This product is a replacement for a Zope user folder. It does not store its own user objects but uses an LDAP backend to store user and group/role information. diff --git a/buildout.cfg b/buildout.cfg index 0c66508..84ec39b 100644 --- a/buildout.cfg +++ b/buildout.cfg @@ -2,8 +2,8 @@ extends = https://zopefoundation.github.io/Zope/releases/master/versions.cfg develop = . -parts = - test +parts = + test [test] diff --git a/docs/configuration.rst b/docs/configuration.rst index 9c450d3..9c3292f 100644 --- a/docs/configuration.rst +++ b/docs/configuration.rst @@ -162,7 +162,7 @@ The following settings apply when adding new server connections: operation timeout value can guard against a hanging site by watching how long it takes for a LDAP request to return. - .. note:: + .. note:: Please use this setting with caution and make sure you know how long your LDAP server might take to respond under high load. With this setting a long response @@ -200,15 +200,15 @@ The following values can be defined for an LDAP schema item: to an attribute name of your choosing on the user object. This is useful if you have code that expects certain attributes on the user object, like the Tracker product which expects "email". In this case - you would need an LDAP schema item that carries email addresses and + you would need an LDAP schema item that carries email addresses and map it to "email". - **Multi-valued**: In the underlying libraries, all user record attributes that are returned as part of the LDAP record are sequences of values. - By default, in order to stay compatible with "normal" user folders, + By default, in order to stay compatible with "normal" user folders, Zope user objects do not have sequences as standard user attributes, - so when a LDAPUser object is created only the first value in the - sequence of values for a given attribute is used to populate the + so when a LDAPUser object is created only the first value in the + sequence of values for a given attribute is used to populate the equivalent attribute on the user object. By declaring a schema item to be multi-valued the entire value sequence as delivered by the LDAP server is stored on the user object. diff --git a/docs/glossary.rst b/docs/glossary.rst index 4ac2aea..870cb6f 100644 --- a/docs/glossary.rst +++ b/docs/glossary.rst @@ -12,7 +12,7 @@ Glossary Microsoft. python-ldap - The `python-ldap `_ library is + The `python-ldap `_ library is used to communicate with LDAP servers. Sphinx diff --git a/docs/index.rst b/docs/index.rst index 2096477..d5b54d1 100644 --- a/docs/index.rst +++ b/docs/index.rst @@ -7,7 +7,7 @@ Narrative documentation explaining how to use :mod:`Products.LDAPUserFolder`. .. toctree:: :maxdepth: 2 - + installation configuration faq @@ -21,7 +21,7 @@ Technical documentation for programming interfaces and APIs. .. toctree:: :maxdepth: 2 - + api diff --git a/docs/installation.rst b/docs/installation.rst index 6608453..ba2ae0a 100644 --- a/docs/installation.rst +++ b/docs/installation.rst @@ -12,7 +12,7 @@ is OpenLDAP. Install with ``pip`` -------------------- -.. code:: +.. code:: $ pip install Products.LDAPUserFolder diff --git a/pyproject.toml b/pyproject.toml index 3cff9ea..e745a33 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,9 +1,10 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product - +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product [build-system] requires = [ - "setuptools >= 78.1.1,< 81", + "setuptools >= 78.1.1,< 82", "wheel", ] build-backend = "setuptools.build_meta" @@ -35,6 +36,7 @@ classifiers = [ "Programming Language :: Python :: 3.12", "Programming Language :: Python :: 3.13", "Programming Language :: Python :: 3.14", + "Programming Language :: Python :: 3.15", "Topic :: Internet :: WWW/HTTP :: Site Management", "Topic :: System :: Systems Administration :: Authentication/Directory :: LDAP", ] @@ -81,3 +83,8 @@ exclude_lines = [ [tool.coverage.html] directory = "parts/htmlcov" + +[tool.zest-releaser] +create-wheel = false +extra-message = "" +upload-pypi = false diff --git a/setup.cfg b/setup.cfg index 832c2c6..064af33 100644 --- a/setup.cfg +++ b/setup.cfg @@ -1,6 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product - +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product [flake8] doctests = 1 no-accept-encodings = True diff --git a/src/Products/LDAPUserFolder/dtml/cache.dtml b/src/Products/LDAPUserFolder/dtml/cache.dtml index 5d32f67..aea29ca 100644 --- a/src/Products/LDAPUserFolder/dtml/cache.dtml +++ b/src/Products/LDAPUserFolder/dtml/cache.dtml @@ -6,8 +6,8 @@

- This view shows all available groups exposed by the LDAP server - as well as all non-anonymous logged-in users in the cache + This view shows all available groups exposed by the LDAP server + as well as all non-anonymous logged-in users in the cache at this moment.

@@ -37,7 +37,7 @@
- " />
@@ -53,7 +53,7 @@
- " />
@@ -69,7 +69,7 @@
- " />
diff --git a/src/Products/LDAPUserFolder/dtml/groups.dtml b/src/Products/LDAPUserFolder/dtml/groups.dtml index 5973c73..1afef8d 100644 --- a/src/Products/LDAPUserFolder/dtml/groups.dtml +++ b/src/Products/LDAPUserFolder/dtml/groups.dtml @@ -8,8 +8,8 @@

This view shows all LDAP group records found on the LDAP server - and allows deletion and addition. You can also map LDAP groups - to Zope roles, thereby conferring a Zope role on members of a + and allows deletion and addition. You can also map LDAP groups + to Zope roles, thereby conferring a Zope role on members of a LDAP group.

@@ -37,8 +37,8 @@
- No groups found in LDAP. - Please check the settings "Group base DN" and "Groups search scope" + No groups found in LDAP. + Please check the settings "Group base DN" and "Groups search scope" and make sure your LDAP tree contains suitable group records.
diff --git a/src/Products/LDAPUserFolder/dtml/ldapschema.dtml b/src/Products/LDAPUserFolder/dtml/ldapschema.dtml index b8b803f..ead3e85 100644 --- a/src/Products/LDAPUserFolder/dtml/ldapschema.dtml +++ b/src/Products/LDAPUserFolder/dtml/ldapschema.dtml @@ -7,15 +7,15 @@

- This form is used to input the attributes for user records - as defined by your LDAP schema. + This form is used to input the attributes for user records + as defined by your LDAP schema. The attributes you define here drive all the select boxes that deal with user attributes in the management interface, like the attribute - to search by on the "Search" tab, the attributes you can choose as the + to search by on the "Search" tab, the attributes you can choose as the Login Name on the "Properties" tab or the attributes you can map to special - user object attributes on the "Advanced" tab. - Adding or removing attributes on this page does not affect your LDAP schema - in any way, it will only affect what the LDAPUserFolder knows about your schema. + user object attributes on the "Advanced" tab. + Adding or removing attributes on this page does not affect your LDAP schema + in any way, it will only affect what the LDAPUserFolder knows about your schema.

@@ -54,7 +54,7 @@
-
diff --git a/src/Products/LDAPUserFolder/dtml/properties.dtml b/src/Products/LDAPUserFolder/dtml/properties.dtml index f43c33b..083cad4 100644 --- a/src/Products/LDAPUserFolder/dtml/properties.dtml +++ b/src/Products/LDAPUserFolder/dtml/properties.dtml @@ -7,7 +7,7 @@

- Change the basic properties of your LDAPUserFolder + Change the basic properties of your LDAPUserFolder on this form.

@@ -35,7 +35,7 @@ - + User ID Attribute @@ -69,7 +69,7 @@ - + Users Base DN " /> @@ -82,7 +82,7 @@ - + Group storage @@ -95,7 +95,7 @@   - + Group mapping @@ -109,7 +109,7 @@   - + Groups Base DN " /> @@ -122,7 +122,7 @@ - + Manager DN " /> @@ -145,12 +145,12 @@ Read-only - checked="&dtml-sel;"/> - + User object classes @@ -167,7 +167,7 @@ Danger! See the online help for details. - + User password encryption @@ -180,7 +180,7 @@ - + Default User Roles @@ -191,7 +191,7 @@ - +
@@ -200,4 +200,3 @@
- diff --git a/src/Products/LDAPUserFolder/dtml/users.dtml b/src/Products/LDAPUserFolder/dtml/users.dtml index 0761a8e..3ed518e 100644 --- a/src/Products/LDAPUserFolder/dtml/users.dtml +++ b/src/Products/LDAPUserFolder/dtml/users.dtml @@ -5,7 +5,7 @@
- + @@ -345,14 +345,14 @@ function toggleSelect() {

Add new user

- The user record will be created on the branch you designated - as the users search base on the configuration screen. - The user attributes on this form depend on the list of - attributes you specified under "LDAP user attributes" on the same + The user record will be created on the branch you designated + as the users search base on the configuration screen. + The user attributes on this form depend on the list of + attributes you specified under "LDAP user attributes" on the same configuration screen. - To enter multiple values for attributes designated as multivalue in - the LDAP Schema configuration separate the values with a + To enter multiple values for attributes designated as multivalue in + the LDAP Schema configuration separate the values with a semicolon (;).

diff --git a/tox.ini b/tox.ini index d86805f..4712d8d 100644 --- a/tox.ini +++ b/tox.ini @@ -1,5 +1,7 @@ -# Generated from: -# https://github.com/zopefoundation/meta/tree/master/config/zope-product +# DO NOT EDIT THIS FILE BY HAND. Generated with +# zope.meta (https://zopemeta.readthedocs.io/) from templates in +# https://github.com/dataflake/meta/tree/master/zope-product and +# https://github.com/zopefoundation/meta/tree/master/src/zope/meta/zope-product [tox] minversion = 3.18 envlist = @@ -10,13 +12,14 @@ envlist = py312 py313 py314 + py315 docs coverage [testenv] skip_install = true deps = - setuptools >= 78.1.1,< 81 + setuptools >= 78.1.1,< 82 zc.buildout wheel setenv = @@ -38,12 +41,12 @@ description = ensure that the distribution is ready to release basepython = python3 skip_install = true deps = - setuptools >= 78.1.1,< 81 + setuptools >= 78.1.1,< 82 wheel twine build check-manifest - check-python-versions >= 0.20.0 + check-python-versions >= 0.24.2 wheel commands_pre = commands =