smolnar82 opened a new pull request, #1318:
URL: https://github.com/apache/knox/pull/1318

   [KNOX-3389](https://issues.apache.org/jira/browse/KNOX-3389) - Embedded LDAP 
getUserGroups drops roles-lookup roles that have no backing group
   
   ## What changes were proposed in this pull request?
   
   When the roles lookup interceptor is enabled on the embedded LDAP server, 
resolved roles are stored on the user entry as `memberOf` values. If the user 
has no existing groups, there is no template group DN available, so 
`LDAPRolesLookupInterceptor.addRoleAttribute` stores each role as a bare RDN 
(`cn=<role>`) with no trailing DN components.
   
   `KnoxLDAPServerManager.getUserGroups` extracted the group name as the 
substring between `cn=` and the first comma. 
   For a bare RDN there is no comma, so`indexOf(',')` returned `-1` and the 
value was silently dropped, thus the resolved roles never surfaced as groups.
   
   This PR makes `getUserGroups` handle the bare-RDN case by taking everything 
after `cn=`, gated on `hasRolesLookupInterceptor` so the behavior only relaxes 
for the path that actually produces bare RDNs:
   
   - Full DN (`cn=role,ou=groups,dc=...`): unchanged, extract between `cn=` and 
the first comma.
   - Bare RDN (`cn=role`): only when the roles lookup interceptor is active, 
take everything after `cn=`.
   - No-comma value without the interceptor: still skipped as 
unexpected/malformed data.
   
   ## How was this patch tested?
   
   Added two unit tests to `KnoxLDAPServerManagerTest` that start the embedded 
server, seed a user via the admin session, and call `getUserGroups` directly:
   - `testGetUserGroupsResolvesBareRdnRolesWhenRolesLookupActive` - user with 
`memberOf: cn=platform:awc-admin-sam` and `cn=ml-workspace-abc:viewer-sam`, 
interceptor flag on: both roles resolve as groups (reproduces the reported 
scenario).
   - `testGetUserGroupsIgnoresBareRdnWhenRolesLookupInactive` - a full-DN group 
plus a bare RDN, interceptor flag off: only the full-DN group resolves, proving 
the lenient parse is scoped to the roles-lookup case.
   
   Manually tested as well (using the same setup as described in the JIRA). 
After my changes applied, I could see the resolved groups:
   ```
   ~ $ curl -iku sam:sam-password 
http://localhost:8443/gateway/sandbox/auth/api/v1/pre
   HTTP/1.1 200 OK
   Date: Wed, 22 Jul 2026 11:10:35 GMT
   Set-Cookie: KNOXSESSIONID=node01qag1cyt0x3sat9xtybpnjtlb0.node0; 
Path=/gateway/sandbox; Secure; HttpOnly
   Expires: Thu, 01 Jan 1970 00:00:00 GMT
   Set-Cookie: rememberMe=deleteMe; Path=/gateway/sandbox; Max-Age=0; 
Expires=Tue, 21-Jul-2026 11:10:35 GMT; SameSite=lax
   x-knox-username: sam
   x-knox-roles: ml-workspace-abc:viewer-sam,platform:awc-admin-sam
   Content-Length: 0
   ```
   
   ## Integration Tests
   N/A
   
   ## UI changes
   N/A


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to