From 3f4deb91789189521d577457bd6da27de8fd75b1 Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Wed, 07 Oct 2026 08:31:10 +0000
Subject: [PATCH] [#1153] Parse the whole DN string, and build or split DN strings through DN instead of string operations (#1171)

---
 opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/PatternRDN.java |   14 ++++++++------
 1 files changed, 8 insertions(+), 6 deletions(-)

diff --git a/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/PatternRDN.java b/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/PatternRDN.java
index 3ca7f27..6a4d637 100644
--- a/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/PatternRDN.java
+++ b/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/PatternRDN.java
@@ -21,7 +21,6 @@
 import static org.opends.server.util.CollectionUtils.*;
 
 import java.util.Arrays;
-import java.util.Iterator;
 import java.util.List;
 import java.util.TreeMap;
 
@@ -178,7 +177,7 @@
       return false;
     }
 
-    // Sort the attribute-value pairs by attribute type.
+    // Index the value patterns by attribute type.
     TreeMap<String, List<ByteString>> patternMap = new TreeMap<>();
     for (int i = 0; i < typePatterns.length; i++)
     {
@@ -189,13 +188,16 @@
       }
       patternMap.put(type.getNameOrOID(), valuePatterns.get(i));
     }
+    if (patternMap.size() != rdn.size())
+    {
+      return false;
+    }
 
-    Iterator<String> patternKeyIter = patternMap.keySet().iterator();
+    // An RDN keeps its AVAs in the order of the DN string, so look each one up by its type.
     for (AVA ava : rdn)
     {
-      String rdnKey = ava.getAttributeType().getNameOrOID();
-      if (!rdnKey.equals(patternKeyIter.next())
-          || !matchValuePattern(patternMap.get(rdnKey), ava))
+      List<ByteString> valuePattern = patternMap.get(ava.getAttributeType().getNameOrOID());
+      if (valuePattern == null || !matchValuePattern(valuePattern, ava))
       {
         return false;
       }

--
Gitblit v1.10.0