I am doing tests to restrict access to repositories thanks to an LDAP filter per repository.
Is the LDAP filter adds a restriction to the access by built-in groups or does the application applies a logical OR to evaluate if a user can access to a repository ?
I have troubles to test myself as my account has admin permissions and I have no access to test accounts in ActiveDirectory.
Documentation is out-of-date: available fields and snapshots no longer match with 2.7.x and 2.8.x versions
https://confluence.atlassian.com/display/FISHEYE027/Permissions
https://confluence.atlassian.com/display/FISHEYE/Permissions
By the way, documentation only explains how to fill in forms... but not what consequence it has on the security permission (logical AND or OR). Documentation should be improved so that it describes what happens in permissions checking according to different options in defaults or per repository settings.