j3rem1e
2014-03-27 e4b0ae020290abfff26ef8b8f35485d277e4da62
src/main/java/com/gitblit/auth/LdapAuthProvider.java
@@ -294,6 +294,20 @@
      LDAPConnection ldapConnection = getLdapConnection();
      if (ldapConnection != null) {
         try {
            boolean alreadyAuthenticated = false;
            String bindPattern = settings.getString(Keys.realm.ldap.bindpattern, "");
            if (!StringUtils.isEmpty(bindPattern)) {
               try {
                  String bindUser = StringUtils.replace(bindPattern, "${username}", simpleUsername);
                  ldapConnection.bind(bindUser, new String(password));
                  alreadyAuthenticated = true;
               } catch (LDAPException e) {
                  return null;
               }
            }
            // Find the logging in user's DN
            String accountBase = settings.getString(Keys.realm.ldap.accountBase, "");
            String accountPattern = settings.getString(Keys.realm.ldap.accountPattern, "(&(objectClass=person)(sAMAccountName=${username}))");
@@ -304,7 +318,7 @@
               SearchResultEntry loggingInUser = result.getSearchEntries().get(0);
               String loggingInUserDN = loggingInUser.getDN();
               if (isAuthenticated(ldapConnection, loggingInUserDN, new String(password))) {
               if (alreadyAuthenticated || isAuthenticated(ldapConnection, loggingInUserDN, new String(password))) {
                  logger.debug("LDAP authenticated: " + username);
                  UserModel user = null;