spring-projects / spring-projects/spring-security

SEC-2766: When username contains backslash, an extra backslash is added.

Open
#2,994 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

type: bug type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

david.wybourn (Migrated from SEC-2766) said:

When using ldap authentication for login purposes, any username containing a backslash has another backslash added in front.

example\username
becomes
example\username

I've confirmed using wireshark that this is the case, and by using ldapsearch I can confirm that the credentials work when there is just a single backslash.

The issue appears to ldap related, using in memory authentication does not cause the extra backslash character to be added. Hence the issue does not rely with the form itself.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the LDAP authentication path in Spring Security and compare its username handling with the in-memory authentication path described in the issue. Reproduce a login using a username containing a backslash, then verify with ldapsearch or captured LDAP traffic that the credential contains only one backslash.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authentication, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.