This is an automated email from the ASF dual-hosted git repository.

smolnar82 pushed a commit to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git

commit 8d4d81dbe73b7d0c1e7a4a9de4091a97222447f2
Author: Sandor Molnar <[email protected]>
AuthorDate: Tue Jun 16 11:17:30 2026 +0200

    KNOX-3351: Resolve LDAP roles for users with no groups (#1266)
    
    (cherry picked from commit 9812cec2eb01889456e48db2aa9005ddc2fc1912)
---
 .../knox/gateway/service/auth/AbstractAuthResource.java     | 13 ++++++-------
 1 file changed, 6 insertions(+), 7 deletions(-)

diff --git 
a/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java
 
b/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java
index b87dfe685..3f91decd4 100644
--- 
a/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java
+++ 
b/gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java
@@ -105,9 +105,9 @@ public abstract class AbstractAuthResource {
     final Set<String> matchingGroupNames = subject == null ? 
Collections.emptySet()
             : SubjectUtils.getGroupPrincipals(subject).stream().filter(group 
-> groupFilterPattern.matcher(group.getName()).matches()).map(group -> 
group.getName())
             .collect(Collectors.toSet());
-    if (!matchingGroupNames.isEmpty()) {
-      final Collection<String> roles = lookupRoles(primaryPrincipalName, 
matchingGroupNames);
-      final List<String> groupStrings = GroupUtils.getGroupStrings(roles == 
null ? matchingGroupNames : roles, groupHeaderLengthLimit, 
groupHeaderSizeLimit);
+    final Collection<String> roles = lookupRoles(primaryPrincipalName, 
matchingGroupNames);
+    if (!matchingGroupNames.isEmpty() || !roles.isEmpty()) {
+      final List<String> groupStrings = 
GroupUtils.getGroupStrings(roles.isEmpty() ? matchingGroupNames : roles, 
groupHeaderLengthLimit, groupHeaderSizeLimit);
       for (int i = 0; i < groupStrings.size(); i++) {
         getResponse().addHeader(String.format(Locale.ROOT, 
ACTOR_GROUPS_HEADER_FORMAT, authHeaderActorGroupsPrefix, i + 1), 
groupStrings.get(i));
       }
@@ -116,17 +116,16 @@ public abstract class AbstractAuthResource {
   }
 
   private Collection<String> lookupRoles(String userName, Collection<String> 
groups) {
+    Collection<String> roles = null;
       try {
         if (ldapRolesLookupService != null && 
ldapRolesLookupService.enabled()) {
-          return ldapRolesLookupService.lookupRoles(userName, groups);
-        } else {
-          return null;
+          roles = ldapRolesLookupService.lookupRoles(userName, groups);
         }
       } catch (Exception e) {
         // Couldn't lookup roles: log and return null so that the API will 
return the groups
         LOG.ldapRolesLookupFailed(userName, e);
-        return null;
       }
+      return roles == null ? Collections.emptySet() : roles;
   }
 
 }

Reply via email to