This is an automated email from the ASF dual-hosted git repository. smolnar82 pushed a commit to branch knox_idf in repository https://gitbox.apache.org/repos/asf/knox.git
commit 8d4d81dbe73b7d0c1e7a4a9de4091a97222447f2 Author: Sandor Molnar <[email protected]> AuthorDate: Tue Jun 16 11:17:30 2026 +0200 KNOX-3351: Resolve LDAP roles for users with no groups (#1266) (cherry picked from commit 9812cec2eb01889456e48db2aa9005ddc2fc1912) --- .../knox/gateway/service/auth/AbstractAuthResource.java | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java b/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java index b87dfe685..3f91decd4 100644 --- a/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java +++ b/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java @@ -105,9 +105,9 @@ public abstract class AbstractAuthResource { final Set<String> matchingGroupNames = subject == null ? Collections.emptySet() : SubjectUtils.getGroupPrincipals(subject).stream().filter(group -> groupFilterPattern.matcher(group.getName()).matches()).map(group -> group.getName()) .collect(Collectors.toSet()); - if (!matchingGroupNames.isEmpty()) { - final Collection<String> roles = lookupRoles(primaryPrincipalName, matchingGroupNames); - final List<String> groupStrings = GroupUtils.getGroupStrings(roles == null ? matchingGroupNames : roles, groupHeaderLengthLimit, groupHeaderSizeLimit); + final Collection<String> roles = lookupRoles(primaryPrincipalName, matchingGroupNames); + if (!matchingGroupNames.isEmpty() || !roles.isEmpty()) { + final List<String> groupStrings = GroupUtils.getGroupStrings(roles.isEmpty() ? matchingGroupNames : roles, groupHeaderLengthLimit, groupHeaderSizeLimit); for (int i = 0; i < groupStrings.size(); i++) { getResponse().addHeader(String.format(Locale.ROOT, ACTOR_GROUPS_HEADER_FORMAT, authHeaderActorGroupsPrefix, i + 1), groupStrings.get(i)); } @@ -116,17 +116,16 @@ public abstract class AbstractAuthResource { } private Collection<String> lookupRoles(String userName, Collection<String> groups) { + Collection<String> roles = null; try { if (ldapRolesLookupService != null && ldapRolesLookupService.enabled()) { - return ldapRolesLookupService.lookupRoles(userName, groups); - } else { - return null; + roles = ldapRolesLookupService.lookupRoles(userName, groups); } } catch (Exception e) { // Couldn't lookup roles: log and return null so that the API will return the groups LOG.ldapRolesLookupFailed(userName, e); - return null; } + return roles == null ? Collections.emptySet() : roles; } }
