Commit 241da10d authored by Jim Jagielski's avatar Jim Jagielski
Browse files

Fold in approved, 2.1/2.2-like behavior which prevents core

dump when doing LDAP auth even if the check_user_id didn't
succeed.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@239641 13f79535-47bb-0310-9956-ffa450edef68
parent 9018531b
Loading
Loading
Loading
Loading
+5 −0
Changes for CHANGES: 5 added lines, 0 removed lines.
Original line number Diff line number Diff line
                                                         -*- coding: utf-8 -*-
Changes with Apache 2.0.55
  *) Fix core dump if mod_auth_ldap's mod_auth_ldap_auth_checker()
     was called even if mod_auth_ldap_check_user_id() was not
     (or if it didn't succeed) for non-authoritative cases.
     [Jim Jagielski]
  *) Fix cases where the byterange filter would buffer responses
     into memory.  PR 29962.  [Joe Orton]
+0 −7
Changes for STATUS: 0 added lines, 7 removed lines.
Original line number Diff line number Diff line
@@ -201,13 +201,6 @@ PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
        2.0 version: http://people.apache.org/~trawick/179704-20.txt
        +1: trawick, jorton, wrowe

    *) Prevent bad dereferencing of non-existent req struct in
       mod_auth_ldap's mod_auth_ldap_auth_checker() if
       mod_auth_ldap_check_user_id() was never (fully) called.
       Similar behavior to that in 2.1/2.2.
         http://people.apache.org/~jim/mod_auth_ldap-2.0.patch
       +1: jim, minfrin, bnicholes

     *) Add httxt2dbm for creating RewriteMap DBM Files.
        http://svn.apache.org/viewcvs.cgi?rev=209539&view=rev
        +1: pquerna, jorton, trawick
+27 −0
Changes for modules/experimental/mod_auth_ldap.c: 27 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -460,6 +460,26 @@ int mod_auth_ldap_auth_checker(request_rec *r)
        return DECLINED;
    }

    /*
     * It is possible that we've skipped mod_auth_ldap's
     * check_user_id hook, but still get here. In that
     * case, the req request_config struct hasn't been initialized
     * causing problems when we try to use req->dn and/or req->name
     * below. So we simply create one.
     *
     * Unlike 2.2, we don't try to search or populate it.
     */
    if (!req) {
        ap_log_rerror(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, r, 
                      "[%d] auth_ldap authorise: "
                      "no req struct - skipped mod_auth_ldap_check_user_id?",
                      getpid());

        req = (mod_auth_ldap_request_t *)apr_pcalloc(r->pool,
                                                     sizeof(mod_auth_ldap_request_t));
        ap_set_module_config(r->request_config, &auth_ldap_module, req);
    }

    if (sec->host) {
        ldc = util_ldap_connection_find(r, sec->host, sec->port,
                                       sec->binddn, sec->bindpw, sec->deref,
@@ -657,6 +677,13 @@ int mod_auth_ldap_auth_checker(request_rec *r)
            }
        }
        else if (strcmp(w, "ldap-attribute") == 0) {
            if (req->dn == NULL || strlen(req->dn) == 0) {
	        ap_log_rerror(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, r,
                              "[%d] auth_ldap authorise: "
                              "require ldap-attribute: user's DN has not been defined; failing authorisation", 
                              getpid());
                return sec->auth_authoritative? HTTP_UNAUTHORIZED : DECLINED;
            }
            while (t[0]) {
                w = ap_getword(r->pool, &t, '=');
                value = ap_getword_conf(r->pool, &t);