Skip to content

Harden LDAP authentication against empty credentials - #102

Open
AugustoMagalhaes wants to merge 2 commits into
rackslab:mainfrom
AugustoMagalhaes:fix/ldap-unauthenticated-bind
Open

AugustoMagalhaes wants to merge 2 commits into
rackslab:mainfrom
AugustoMagalhaes:fix/ldap-unauthenticated-bind

Conversation

@AugustoMagalhaes

Copy link
Copy Markdown

Summary

LDAPAuthentifier.login() only rejected None credentials and forwarded empty strings to simple_bind_s(). An empty password results in an LDAP unauthenticated bind (RFC 4513 §5.1.2), which some directory servers accept as a successful bind without verifying credentials.

This change validates credentials before any LDAP operation:

  • reject missing or non-string user/password
  • reject blank usernames
  • reject empty passwords (not stripped, so passwords containing spaces keep working)

Tests

Added regression tests ensuring an empty password never reaches simple_bind_s(), and that blank usernames and non-string credentials are rejected before any LDAP operation. Also verified passwords containing spaces are still accepted.

Notes

Reported privately to the maintainer beforehand; opening the PR as requested.

@rezib rezib self-assigned this Oct 3, 2026
@rezib rezib added this to the v1.10.0 milestone Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants