smolnar82 opened a new pull request, #1318: URL: https://github.com/apache/knox/pull/1318
[KNOX-3389](https://issues.apache.org/jira/browse/KNOX-3389) - Embedded LDAP getUserGroups drops roles-lookup roles that have no backing group ## What changes were proposed in this pull request? When the roles lookup interceptor is enabled on the embedded LDAP server, resolved roles are stored on the user entry as `memberOf` values. If the user has no existing groups, there is no template group DN available, so `LDAPRolesLookupInterceptor.addRoleAttribute` stores each role as a bare RDN (`cn=<role>`) with no trailing DN components. `KnoxLDAPServerManager.getUserGroups` extracted the group name as the substring between `cn=` and the first comma. For a bare RDN there is no comma, so`indexOf(',')` returned `-1` and the value was silently dropped, thus the resolved roles never surfaced as groups. This PR makes `getUserGroups` handle the bare-RDN case by taking everything after `cn=`, gated on `hasRolesLookupInterceptor` so the behavior only relaxes for the path that actually produces bare RDNs: - Full DN (`cn=role,ou=groups,dc=...`): unchanged, extract between `cn=` and the first comma. - Bare RDN (`cn=role`): only when the roles lookup interceptor is active, take everything after `cn=`. - No-comma value without the interceptor: still skipped as unexpected/malformed data. ## How was this patch tested? Added two unit tests to `KnoxLDAPServerManagerTest` that start the embedded server, seed a user via the admin session, and call `getUserGroups` directly: - `testGetUserGroupsResolvesBareRdnRolesWhenRolesLookupActive` - user with `memberOf: cn=platform:awc-admin-sam` and `cn=ml-workspace-abc:viewer-sam`, interceptor flag on: both roles resolve as groups (reproduces the reported scenario). - `testGetUserGroupsIgnoresBareRdnWhenRolesLookupInactive` - a full-DN group plus a bare RDN, interceptor flag off: only the full-DN group resolves, proving the lenient parse is scoped to the roles-lookup case. Manually tested as well (using the same setup as described in the JIRA). After my changes applied, I could see the resolved groups: ``` ~ $ curl -iku sam:sam-password http://localhost:8443/gateway/sandbox/auth/api/v1/pre HTTP/1.1 200 OK Date: Wed, 22 Jul 2026 11:10:35 GMT Set-Cookie: KNOXSESSIONID=node01qag1cyt0x3sat9xtybpnjtlb0.node0; Path=/gateway/sandbox; Secure; HttpOnly Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: rememberMe=deleteMe; Path=/gateway/sandbox; Max-Age=0; Expires=Tue, 21-Jul-2026 11:10:35 GMT; SameSite=lax x-knox-username: sam x-knox-roles: ml-workspace-abc:viewer-sam,platform:awc-admin-sam Content-Length: 0 ``` ## Integration Tests N/A ## UI changes N/A -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
