smolnar82 opened a new pull request, #1431: URL: https://github.com/apache/knox/pull/1431
[KNOX-3490](https://issues.apache.org/jira/browse/KNOX-3490) - Fix LDAP roles lookup using the wrong username when the client omits the uid attribute ## What changes were proposed in this pull request? `LDAPRolesLookupInterceptor` derived the roles-lookup identity from entry *attributes* (`uid`, `cn`). Because the entry is trimmed to the attributes the client requested, a client that omits `uid` (e.g. Hadoop `LdapGroupsMapping`) left only `cn`, so the lookup was keyed on a display name and returned the wrong roles. The username is now taken from the entry's DN (always present), falling back to attributes for non-uid-based DNs. ## How was this patch tested? - New unit tests in `LDAPRolesLookupInterceptorTest` covering the trimmed-uid case and the non-uid-DN fallback. - `mvn -pl gateway-server test -Dtest=LDAPRolesLookupInterceptorTest` → 7/7 pass. - Manually verified on a running cluster by hot-patching the gateway jar: the local-cluster path now resolves the correct roles. ## Integration Tests No integration test added — this is an internal interceptor fix covered by unit tests. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
