In Confluence we have always used LDAP authentication, but used Confluence's internal groups for authorization. Due to organizational reasons, we have two LDAP directories defined; most users exist in one of those directories, the others in the other. When using OSUser.xsml in version 3.2, this setup worked fine: we had both directories defined in osuser.xml (along with the internal Confluence authenticator), and when a user was created in Confluence, they were not associated with any particular directory; they were sert up internally, and when logging in would be authenticated against the directories in turn. If the first LDAP directory did not have that user the second one would be tried, and would work.
However, after upgrading to Confluence 4.3.5, using multiple directories no longer works, since now each user appears to be associated with a particular directory (the first one in the directory order). This means that if a user that exists only in the second defined LDAP directory gets added, they cannot login, since their user profile assumes they belong to the first one. In looking at the user profile, it appears that the directory field is not editable.
Is there some alternative way to associate a user with a specific directory on creation or later, or is this a setup that only worked using OSUser?