99e613e Web UI: allow users from trusted Active Directory forest manage IPA

1 file Authored by abbra 3 years ago, Committed by rcritten 3 years ago,
    Web UI: allow users from trusted Active Directory forest manage IPA
    
    Extend Web UI logic to decide whether default Web UI view should have a
    full menu or should be confined to a self-service interface. Standard
    logic in FreeIPA Web UI is to combine two facts:
    
     * for IPA users membership in `admins` group is used to indicate full
       menu should be shown
    
     * for AD users the fact that ID override object is presented by IPA
       `whoami` command is used to confine to a self-service interface
    
    With the change to allow user ID overrides from a default trust view to
    be members of groups and roles, we can unify the administrative
    privileges checks for both IPA and AD users.
    
    Fixed: https://pagure.io/freeipa/issue/8335
    Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
    Reviewed-By: Rob Crittenden <rcritten@redhat.com>
    Reviewed-By: Rob Crittenden <rcritten@redhat.com>