Sandor Molnar created KNOX-3389:
-----------------------------------
Summary: Embedded LDAP getUserGroups drops roles-lookup roles that
have no backing group
Key: KNOX-3389
URL: https://issues.apache.org/jira/browse/KNOX-3389
Project: Apache Knox
Issue Type: Bug
Components: Server
Affects Versions: 3.0.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.0.0
When the embedded Knox LDAP server has the roles lookup interceptor enabled,
resolved roles are written to the user entry as memberOf values. If the user
has no existing groups (so there is no template group DN to build a full DN
from), {{LDAPRolesLookupInterceptor.addRoleAttribute}} stores each role as a
bare RDN, e.g. {{memberOf: cn=platform:awc-admin-sam}}, with no trailing DN
components.
{{KnoxLDAPServerManager.getUserGroups}} then fails to return these as groups.
It extracts the CN by taking the substring between {{cn=}} and the first comma,
but a bare RDN has no comma {{(indexOf(',') returns -1)}}, so the value is
silently skipped and the roles never surface as groups.
*Repro:* embedded LDAP pointed at a demo backend whose LDIF defines users but
no groups, with {{rolesLookup}} in {{gateway.ldap.interceptor.names}}.
Authenticate a user (e.g. {{sam}}) whose roles resolve to
{{platform:awc-admin-sam}} and {{ml-workspace-abc:viewer-sam}}. Knox resolves
the roles and writes them to {{memberOf}} as {{cn=<role>}}, but
{{getUserGroups("sam")}} returns an empty list.
*Fix:* when the roles lookup interceptor is active, handle bare-RDN
{{memberOf}} values by taking everything after {{cn=}}. Full DNs continue to be
parsed as before, and a no-comma value without the interceptor is still skipped
as unexpected data.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)