From 3f4deb91789189521d577457bd6da27de8fd75b1 Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Wed, 07 Oct 2026 08:31:10 +0000
Subject: [PATCH] [#1153] Parse the whole DN string, and build or split DN strings through DN instead of string operations (#1171)

---
 opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/UserAttr.java |    6 ++++--
 1 files changed, 4 insertions(+), 2 deletions(-)

diff --git a/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/UserAttr.java b/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/UserAttr.java
index ea1f069..ce18c87 100644
--- a/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/UserAttr.java
+++ b/opendj-server-legacy/src/main/java/org/opends/server/authorization/dseecompat/UserAttr.java
@@ -130,12 +130,14 @@
     public static KeywordBindRule decode(String expression,
                                          EnumBindRuleType type)
     throws AciException {
-        String[] vals=expression.split("#");
-        if(vals.length != 2) {
+        // The attribute name cannot contain an octothorpe, but the value after it can.
+        final int sharpPos = expression.indexOf('#');
+        if (sharpPos < 0 || sharpPos == expression.length() - 1) {
             LocalizableMessage message =
                 WARN_ACI_SYNTAX_INVALID_USERATTR_EXPRESSION.get(expression);
             throw new AciException(message);
         }
+        final String[] vals = { expression.substring(0, sharpPos), expression.substring(sharpPos + 1) };
         UserAttrType userAttrType = UserAttrType.getType(vals[1]);
         switch (userAttrType) {
                 case GROUPDN:

--
Gitblit v1.10.0