handavid opened a new pull request, #1428:
URL: https://github.com/apache/knox/pull/1428

   [KNOX-3485](https://issues.apache.org/jira/browse/KNOX-3485) - Roles lookup 
replaces group entries with role entries
   
   ## What changes were proposed in this pull request?
   
   Adds an explicit flag to enabled DN mapping in the LDAP Proxy. This fixes a 
consistency issue where attributes are mapped to the Proxy base DN by the entry 
DNs were not. The code was fixed so that either the entry DN and attribute DNs 
are all mapped or none mapped.
   
   The LDAPRolesLookupInterceptor is modified to differentiate between group 
and user entries. If the entry is a group entry, then the entry dn is replaced 
with the role dn.
   
   ## How was this patch tested?
   
   Added unit and integration tests
   
   ## Integration Tests
   
   Adds new workflow test with knox configured to use role lookup. A new 
docker-compose.role-lookup.yml file is added to run the tests under the new 
configuration. The roles.json file is used for file-based role lookup so no 
external server is needed. The workflow test copies the 
test_knox_ldap_proxy_search.py tests and replaces the expected values from role 
lookup. The tests are also run with the bypass control.
   docker compose -f ./.github/workflows/compose/docker-compose.yml -f 
./.github/workflows/compose/docker-compose.roles-lookup.yml up --exit-code-from 
tests tests
   
   ## UI changes
   No UI changes
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to