spring-projects / spring-projects/spring-security
SEC-1963: ActiveDirectoryLdapAuthenticationProvider: flag binary attributes
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
Mark Rigby-Jones (Migrated from SEC-1963) said:
JNDI is not able to correctly detect binary attributes in Active Directory, leading to some attributes (such as the SID and GUID) to be incorrectly transferred in text mode, leading to corruption for certain values. A fix for this is to add an additional item to the environment in bindAsUser(...):
env.put("java.naming.ldap.attributes.binary", "objectGUID objectSid");
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Locate the bindAsUser(...) entry point in the Spring Security source and inspect how its JNDI environment is assembled. Verify the Active Directory binary-attribute handling for objectGUID and objectSid, then check the relevant existing authentication coverage; done means those values are not transferred in text mode or corrupted.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, backend
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 48/100