From 81bc6cd81b347f178a1a2b85e33b7101d1241c41 Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Mon, 05 Oct 2026 12:38:31 +0000
Subject: [PATCH] [#1155] Make the rest2ldap bind templates and HTTP Basic credentials work as documented (#1165)
---
opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java | 30 ++++++++++++++++++++++++++++++
1 files changed, 30 insertions(+), 0 deletions(-)
diff --git a/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java b/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java
index 92770cf..d57b54a 100644
--- a/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java
+++ b/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java
@@ -12,6 +12,7 @@
* information: "Portions copyright [year] [name of copyright owner]".
*
* Copyright 2016 ForgeRock AS.
+ * Portions Copyright 2026 3A Systems, LLC.
*/
package org.forgerock.opendj.rest2ldap.authz;
@@ -25,8 +26,12 @@
import org.forgerock.http.protocol.Response;
import org.forgerock.http.protocol.Status;
import org.forgerock.i18n.LocalizableMessage;
+import org.forgerock.i18n.LocalizedIllegalArgumentException;
import org.forgerock.json.resource.ResourceException;
+import org.forgerock.opendj.ldap.DN;
import org.forgerock.opendj.ldap.LdapException;
+import org.forgerock.opendj.ldap.ResultCode;
+import org.forgerock.opendj.ldap.schema.Schema;
import org.forgerock.util.AsyncFunction;
import org.forgerock.util.promise.NeverThrowsException;
import org.forgerock.util.promise.Promise;
@@ -55,6 +60,31 @@
return new AccessTokenException(message.toString(), cause);
}
+ /**
+ * Returns the DN which a bind DN template designates for a user name.
+ *
+ * @param dnTemplate
+ * The template, with {@code %s} in place of the user name. A template which is just {@code %s} takes the
+ * user name as the DN; otherwise the user name is escaped as an attribute value.
+ * @param schema
+ * The schema used to parse the DN.
+ * @param username
+ * The user name.
+ * @return The DN.
+ * @throws LdapException
+ * With {@link ResultCode#INVALID_CREDENTIALS} if the result is not a valid DN.
+ */
+ static DN formatBindDn(final String dnTemplate, final Schema schema, final String username)
+ throws LdapException {
+ try {
+ return "%s".equals(dnTemplate)
+ ? DN.valueOf(username, schema)
+ : DN.format(dnTemplate, schema, username);
+ } catch (final LocalizedIllegalArgumentException e) {
+ throw LdapException.newLdapException(ResultCode.INVALID_CREDENTIALS, e.getMessageObject(), e);
+ }
+ }
+
static Runnable close(final AtomicReference<? extends Closeable> holder) {
return new Runnable() {
@Override
--
Gitblit v1.10.0