smolnar82 opened a new pull request, #1431:
URL: https://github.com/apache/knox/pull/1431

   [KNOX-3490](https://issues.apache.org/jira/browse/KNOX-3490) - Fix LDAP 
roles lookup using the wrong username when the client omits the uid attribute
   
   ## What changes were proposed in this pull request?
   `LDAPRolesLookupInterceptor` derived the roles-lookup identity from entry 
*attributes* (`uid`, `cn`). Because the entry is trimmed to the attributes the 
client requested, a client that omits `uid` (e.g. Hadoop `LdapGroupsMapping`) 
left only `cn`, so the lookup was keyed on a display name and returned the 
wrong roles. The username is now taken from the entry's DN (always present), 
falling back to attributes for non-uid-based DNs.
   
   ## How was this patch tested?
   - New unit tests in `LDAPRolesLookupInterceptorTest` covering the 
trimmed-uid case and the non-uid-DN fallback.
   - `mvn -pl gateway-server test -Dtest=LDAPRolesLookupInterceptorTest` → 7/7 
pass.
   - Manually verified on a running cluster by hot-patching the gateway jar: 
the local-cluster path now resolves the correct roles.
   
   ## Integration Tests
   No integration test added — this is an internal interceptor fix covered by 
unit tests.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to