spring-projects / spring-projects/spring-security
SEC-2766: When username contains backslash, an extra backslash is added.
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
david.wybourn (Migrated from SEC-2766) said:
When using ldap authentication for login purposes, any username containing a backslash has another backslash added in front.
example\username
becomes
example\username
I've confirmed using wireshark that this is the case, and by using ldapsearch I can confirm that the credentials work when there is just a single backslash.
The issue appears to ldap related, using in memory authentication does not cause the extra backslash character to be added. Hence the issue does not rely with the form itself.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at the LDAP authentication path in Spring Security and compare its username handling with the in-memory authentication path described in the issue. Reproduce a login using a username containing a backslash, then verify with ldapsearch or captured LDAP traffic that the credential contains only one backslash.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100