[
https://issues.apache.org/jira/browse/KNOX-3485?focusedWorklogId=1043834&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1043834
]
ASF GitHub Bot logged work on KNOX-3485:
----------------------------------------
Author: ASF GitHub Bot
Created on: 25/Sep/26 03:02
Start Date: 25/Sep/26 03:02
Worklog Time Spent: 10m
Work Description: handavid opened a new pull request, #1428:
URL: https://github.com/apache/knox/pull/1428
[KNOX-3485](https://issues.apache.org/jira/browse/KNOX-3485) - Roles lookup
replaces group entries with role entries
## What changes were proposed in this pull request?
Adds an explicit flag to enabled DN mapping in the LDAP Proxy. This fixes a
consistency issue where attributes are mapped to the Proxy base DN by the entry
DNs were not. The code was fixed so that either the entry DN and attribute DNs
are all mapped or none mapped.
The LDAPRolesLookupInterceptor is modified to differentiate between group
and user entries. If the entry is a group entry, then the entry dn is replaced
with the role dn.
## How was this patch tested?
Added unit and integration tests
## Integration Tests
Adds new workflow test with knox configured to use role lookup. A new
docker-compose.role-lookup.yml file is added to run the tests under the new
configuration. The roles.json file is used for file-based role lookup so no
external server is needed. The workflow test copies the
test_knox_ldap_proxy_search.py tests and replaces the expected values from role
lookup. The tests are also run with the bypass control.
docker compose -f ./.github/workflows/compose/docker-compose.yml -f
./.github/workflows/compose/docker-compose.roles-lookup.yml up --exit-code-from
tests tests
## UI changes
No UI changes
Issue Time Tracking
-------------------
Worklog Id: (was: 1043834)
Remaining Estimate: 0h
Time Spent: 10m
> LDAP Proxy should apply role mapping to Group entries
> -----------------------------------------------------
>
> Key: KNOX-3485
> URL: https://issues.apache.org/jira/browse/KNOX-3485
> Project: Apache Knox
> Issue Type: Improvement
> Components: Server
> Affects Versions: 3.1.0
> Reporter: David Han
> Assignee: David Han
> Priority: Major
> Fix For: 3.1.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> The LDAPRolesLookupInterceptor only transforms the memberOf attribute in user
> entries. This interceptor should also replace group entries with their
> corresponding mapped role entries.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)