From 567b10a49a1b33729288a9092d80033328f0e8c3 Mon Sep 17 00:00:00 2001 From: Joshua Rogers Date: Sat, 13 Sep 2025 12:02:58 +0000 Subject: [PATCH] ext_ldap_group_acl: Require base dn and user search filter (#2167) Make ext_ldap_group_acl require -B (user base DN) and -F (user search filter) so the helper finds the user before checking group membership. Fix LDAP referrals handling and make %v always expand to the requested group name. Improve logging and errors, and include release notes for the breaking flag requirements. --- doc/release-notes/release-8.sgml.in | 11 ++++++++++ .../external/LDAP_group/ext_ldap_group_acl.cc | 21 ++++++++++--------- 2 files changed, 22 insertions(+), 10 deletions(-) diff --git a/doc/release-notes/release-8.sgml.in b/doc/release-notes/release-8.sgml.in index 2c7a44edd1..a521cf4f8d 100644 --- a/doc/release-notes/release-8.sgml.in +++ b/doc/release-notes/release-8.sgml.in @@ -46,6 +46,17 @@ The Squid-@SQUID_RELEASE@ change history can be