// NOTE: entryACI are NOT considered in adds (it would be a security breech)
addPerscriptiveAciTuples( invocation.getProxy(), tuples, normName, subentryAttrs );
addSubentryAciTuples( invocation.getProxy(), tuples, normName, subentryAttrs );
// check if entry scope permission is granted
DirectoryPartitionNexusProxy proxy = invocation.getProxy();
engine.checkPermission( proxy, userGroups, user.getJndiName(), user.getAuthenticationLevel(),
normName, null, null, ADD_PERMS, tuples, subentryAttrs );
// now we must check if attribute type and value scope permission is granted
NamingEnumeration attributeList = entry.getAll();