handavid opened a new pull request, #1435:
URL: https://github.com/apache/knox/pull/1435

   [KNOX-3496](https://issues.apache.org/jira/browse/KNOX-3496) - LDAP Proxy 
requests memberOf attribute from backend
   
   ## What changes were proposed in this pull request?
   
   The LdapProxyBackend now explicity requests the memberOf attribute from the 
backend if the useMemberOf flag is set.
   
   ## How was this patch tested?
   
   Manual requests were run against and OKTA LDAP server to verify the 
behavior. This showed that the OKTA LDAP server would include the `memberOf` 
attribute if requested in addition to '*'
   ```
   ldapsearch -v -x -H ldaps://<okta-ldap-server>:636  -D '<user>' -w 
<password> -b 'ou=users,<base dn>' -s sub '(uid=*)' '*' memberOf
   ```
   The output was then compared to the output through the LDAP proxy
   ```
   ldapsearch -v -x -H ldaps://<ldap-proxy-server>:636  -D '<user>' -w 
<password> -b 'ou=people,<proxy base dn>' -s sub '(uid=*)' '*'
   ```
   Unit tests were added to validate that the `memberOf` attribute is added to 
the backend request when the `useMemberOf` flag is set.
   
   (Please explain how this patch was tested. For instance: running automated 
unit/integration tests, manual tests. Please write down your test steps as 
detailed as possible)
   
   ## Integration Tests
   no integration tests were added as these would require running an okta ldap 
server
   
   ## UI changes
   no UI changes


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to