From 81bc6cd81b347f178a1a2b85e33b7101d1241c41 Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Mon, 05 Oct 2026 12:38:31 +0000
Subject: [PATCH] [#1155] Make the rest2ldap bind templates and HTTP Basic credentials work as documented (#1165)

---
 opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java |   30 ++++++++++++++++++++++++++++++
 1 files changed, 30 insertions(+), 0 deletions(-)

diff --git a/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java b/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java
index 92770cf..d57b54a 100644
--- a/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java
+++ b/opendj-rest2ldap/src/main/java/org/forgerock/opendj/rest2ldap/authz/Utils.java
@@ -12,6 +12,7 @@
  * information: "Portions copyright [year] [name of copyright owner]".
  *
  * Copyright 2016 ForgeRock AS.
+ * Portions Copyright 2026 3A Systems, LLC.
  */
 package org.forgerock.opendj.rest2ldap.authz;
 
@@ -25,8 +26,12 @@
 import org.forgerock.http.protocol.Response;
 import org.forgerock.http.protocol.Status;
 import org.forgerock.i18n.LocalizableMessage;
+import org.forgerock.i18n.LocalizedIllegalArgumentException;
 import org.forgerock.json.resource.ResourceException;
+import org.forgerock.opendj.ldap.DN;
 import org.forgerock.opendj.ldap.LdapException;
+import org.forgerock.opendj.ldap.ResultCode;
+import org.forgerock.opendj.ldap.schema.Schema;
 import org.forgerock.util.AsyncFunction;
 import org.forgerock.util.promise.NeverThrowsException;
 import org.forgerock.util.promise.Promise;
@@ -55,6 +60,31 @@
         return new AccessTokenException(message.toString(), cause);
     }
 
+    /**
+     * Returns the DN which a bind DN template designates for a user name.
+     *
+     * @param dnTemplate
+     *         The template, with {@code %s} in place of the user name. A template which is just {@code %s} takes the
+     *         user name as the DN; otherwise the user name is escaped as an attribute value.
+     * @param schema
+     *         The schema used to parse the DN.
+     * @param username
+     *         The user name.
+     * @return The DN.
+     * @throws LdapException
+     *         With {@link ResultCode#INVALID_CREDENTIALS} if the result is not a valid DN.
+     */
+    static DN formatBindDn(final String dnTemplate, final Schema schema, final String username)
+            throws LdapException {
+        try {
+            return "%s".equals(dnTemplate)
+                    ? DN.valueOf(username, schema)
+                    : DN.format(dnTemplate, schema, username);
+        } catch (final LocalizedIllegalArgumentException e) {
+            throw LdapException.newLdapException(ResultCode.INVALID_CREDENTIALS, e.getMessageObject(), e);
+        }
+    }
+
     static Runnable close(final AtomicReference<? extends Closeable> holder) {
         return new Runnable() {
             @Override

--
Gitblit v1.10.0