[
https://issues.apache.org/jira/browse/KNOX-3425?focusedWorklogId=1038319&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1038319
]
ASF GitHub Bot logged work on KNOX-3425:
----------------------------------------
Author: ASF GitHub Bot
Created on: 27/Aug/26 15:00
Start Date: 27/Aug/26 15:00
Worklog Time Spent: 10m
Work Description: handavid opened a new pull request, #1359:
URL: https://github.com/apache/knox/pull/1359
[KNOX-3425](https://issues.apache.org/jira/browse/KNOX-3425) - LDAP Proxy
disallows anonymous binds to remote backends
## What changes were proposed in this pull request?
The LdapProxyBackend.authenticate method will now return false if either the
given DN or password is empty to prevent unauthorized and anonymous binds.
The UserSearchInterceptor is also updated to not call the backend if the DN
or password is empty.
Cherry-picks #1358 to v3.0.0
## How was this patch tested?
Unit tests added.
Manual tests performed using ldapsearch to attempt anonymous bind that
previously succeeded
```
ldapsearch -v -x -H ldap://localhost:3890 -b 'ou=people,DC=proxy,DC=com'
'(uid=guest*)' '*'
```
## Integration Tests
integration tests were run locally
## UI changes
no UI changes
Issue Time Tracking
-------------------
Worklog Id: (was: 1038319)
Time Spent: 50m (was: 40m)
> Ldap Proxy may allow anonymous bind
> -----------------------------------
>
> Key: KNOX-3425
> URL: https://issues.apache.org/jira/browse/KNOX-3425
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Affects Versions: 3.0.0
> Reporter: David Han
> Assignee: David Han
> Priority: Major
> Fix For: 3.0.0, 3.1.0
>
> Time Spent: 50m
> Remaining Estimate: 0h
>
> The UserSearchInterceptor is configured before the AuthenticationInterceptor.
> The search implementation swallows exceptions with the intention to allow
> partial results from multiple backends. The bug is that this exception
> handling behavior also swallows exceptions raised by the authentication
> interceptor.
> I think that the behavior should be changed to raise any exceptions rather
> than swallowing. Swallowing exceptions also makes it unclear if there were
> any configuration problems connecting to a remote backend.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)