handavid opened a new pull request, #1428: URL: https://github.com/apache/knox/pull/1428
[KNOX-3485](https://issues.apache.org/jira/browse/KNOX-3485) - Roles lookup replaces group entries with role entries ## What changes were proposed in this pull request? Adds an explicit flag to enabled DN mapping in the LDAP Proxy. This fixes a consistency issue where attributes are mapped to the Proxy base DN by the entry DNs were not. The code was fixed so that either the entry DN and attribute DNs are all mapped or none mapped. The LDAPRolesLookupInterceptor is modified to differentiate between group and user entries. If the entry is a group entry, then the entry dn is replaced with the role dn. ## How was this patch tested? Added unit and integration tests ## Integration Tests Adds new workflow test with knox configured to use role lookup. A new docker-compose.role-lookup.yml file is added to run the tests under the new configuration. The roles.json file is used for file-based role lookup so no external server is needed. The workflow test copies the test_knox_ldap_proxy_search.py tests and replaces the expected values from role lookup. The tests are also run with the bypass control. docker compose -f ./.github/workflows/compose/docker-compose.yml -f ./.github/workflows/compose/docker-compose.roles-lookup.yml up --exit-code-from tests tests ## UI changes No UI changes -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
