Skip to content

[#1160] Allow unescaped '=' in LDAPUtils dnRule attribute values - #1161

Open
nicholascowan wants to merge 1 commit into
OpenIdentityPlatform:masterfrom
nicholascowan:fix/ldaputils-dn-allow-equals-in-values
Open

nicholascowan wants to merge 1 commit into
OpenIdentityPlatform:masterfrom
nicholascowan:fix/ldaputils-dn-allow-equals-in-values

Conversation

@nicholascowan

Copy link
Copy Markdown

Summary

Regression was introduced in #436.

Test plan

  • LDAPUtilsTest / testIsDNWithEqualsInValue passes
  • Existing testIsDN / testIsDNInvalid / testIsDNInvalid2 still pass
  • Import Google Workspace IdP metadata with a real idpid= entity ID succeeds on OpenAM 16

…ttribute values

RFC 4514 permits '=' inside DN attribute values; the dnRule regex added
in OpenIdentityPlatform#436 rejected Google Workspace SAML entity IDs containing idpid=.
@nicholascowan

Copy link
Copy Markdown
Author

@vharseko — could you take a look when you have a chance? This adjusts the `dnRule` regex from #436 so RFC 4514-valid DNs with `=` in attribute values (e.g. Google Workspace `idpid=`) are accepted again. Happy to adjust if you'd prefer a different approach.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

LDAPUtils.newDN rejects DNs with = in the value (Google Workspace SAML entity IDs)

1 participant