diff --git a/tasks/configure_home_permissions.yml b/tasks/configure_home_permissions.yml index 0343af69633d822597c08c70558e1f63ca6133e4..9eb5167dc083ebd0b2baf8d285ac562aace22ee5 100644 --- a/tasks/configure_home_permissions.yml +++ b/tasks/configure_home_permissions.yml @@ -1,17 +1,15 @@ --- -- name: $HOME-Verzeichnisse von Usern mit gleichen Gruppen schützen - block: - - name: $HOME-Verzeichnisse sammeln - ansible.builtin.find: - file_type: directory - paths: "/home/" - excludes: 'import' - register: ls_out - - name: striktere Berechtigungen für Homeverzeichnisse setzen - ansible.builtin.file: - path: "{{ item.path }}/" - mode: "0700" - loop: - # - "{{ ls_out.files | difference(['import','zih']) }}" - - "{{ ls_out.files }}" - when: item.path not in "import" +- name: assemble a list of all $HOME directories + ansible.builtin.find: + file_type: directory + paths: "/home/" + excludes: 'import' + register: ls_out + +- name: set stricter permissions to protect $HOME directories from access by users with the same group + ansible.builtin.file: + path: "{{ item.path }}/" + mode: "0700" + loop: "{{ ls_out.files }}" + # loop: "{{ ls_out.files | difference(['import','zih']) }}" + when: not "import" in item.path