internal/outpost/ldap: type switching for uidNumber/gidNumber - #24839
Open
tacerus wants to merge 1 commit into
Open
internal/outpost/ldap: type switching for uidNumber/gidNumber#24839tacerus wants to merge 1 commit into
tacerus wants to merge 1 commit into
Conversation
When the uidNumber attribute was set as an integer without an explicit gidNumber, the system would generate a gidNumber instead of mapping the uidNumber. The mapping only worked if uidNumber was set as a string. As uidNumber/gidNumber are commonly integers, avoid the need for faking strings in the user attributes by matching the behavior. This also reduces implementation confusion, as the documentation states The gidNumber attribute of each virtual group is equal to the uidNumber of the user. without imposing any limitations on the data type. Signed-off-by: Georg Pfuetzenreuter <georg.pfuetzenreuter@suse.com>
✅ Deploy Preview for authentik-integrations ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for authentik-storybook ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for authentik-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Contributor
Author
|
CI failure appears not related to my change, but let me know if I missed something. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Details
What does this PR change?
Treat both integer and string uidNumber/gidNumber attribute values equally.
Why is this change needed?
When the uidNumber attribute was set as an integer without an explicit gidNumber, the system would generate a gidNumber instead of mapping the uidNumber. The mapping only worked if uidNumber was set as a string.
As uidNumber/gidNumber are commonly integers, avoid the need for faking strings in the user attributes by matching the behavior.
This also reduces implementation confusion, as the documentation states
without imposing any limitations on the data type.
How was this tested?
Define a user with a custom
uidNumberattribute. Set the attribute to a number: first a string, then an integer one. Observe the result when querying the uidNumber/gidNumber attributes of the user and the users virtual group.Linked issues
Checklist
make all)make docs)