Uh oh!
There was an error while loading. Please reload this page.
[enhance](auth)Add a configuration to prohibit accessing LDAP with an empty password - #54099
Closed
zddr wants to merge 1 commit into
Closed
[enhance](auth)Add a configuration to prohibit accessing LDAP with an empty password#54099zddr wants to merge 1 commit into
zddr wants to merge 1 commit into
Conversation
hello-stephen
commented
Jul 30, 2025
Contributor
Thank you for your contribution to Apache Doris. Please clearly describe your PR:
|
zddr
commented
Jul 30, 2025
ContributorAuthor
run buildall |
doris-robot
commented
Jul 30, 2025
TPC-H: Total hot run time: 33998 ms |
doris-robot
commented
Jul 30, 2025
TPC-DS: Total hot run time: 171557 ms |
doris-robot
commented
Jul 30, 2025
ClickBench: Total hot run time: 33.57 s |
zddr
commented
Jul 31, 2025
ContributorAuthor
run nonConcurrent |
zddr
marked this pull request as draft
July 31, 2025 03:08
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What problem does this PR solve?
When LDAP is enabled with null bind, an empty password will automatically convert to an anonymous user login. This scenario is judged as a correct password, and since the username used actually exists, the corresponding user can also be correctly found through the LDAP account. As a result, it becomes possible to log in to any LDAP account with an empty password.
resolve:
add ldap config: ldap_allow_empty_password,default is true,
when set it to false,use empty password login will failed
Issue Number: close #xxx
Related PR: #xxx
Problem Summary:
Add a configuration to prohibit accessing LDAP with an empty password
Release note
Add a configuration to prohibit accessing LDAP with an empty password
Check List (For Author)
Test
Behavior changed:
Does this need documentation?
Check List (For Reviewer who merge this PR)