'use strict'; // Workaround for ldapjs 3.x / @ldapjs/dn: its escapeValue hex-escapes every // non-ASCII UTF-8 byte in DN values (\d0\a2...). Active Directory's LDAP add // parser decodes those hex escapes as Latin-1 characters, so Cyrillic DNs get // double-encoded (mojibake) on the server and group membership lookups fail // with LDAP 32. Keep non-ASCII characters raw so writeString sends real UTF-8. // Must be loaded BEFORE ldapjs/@ldapjs/dn are required. // // eslint-disable-next-line global-require const modulePath = require.resolve('@ldapjs/dn/lib/utils/escape-value'); // eslint-disable-next-line global-require require(modulePath); // ensure it is in the require cache require.cache[modulePath].exports = function escapeValue(value) { if (typeof value !== 'string') { throw new Error('value must be a string'); } let result = ''; for (let i = 0; i < value.length; i += 1) { const c = value.charCodeAt(i); if (c === 0x5c) { result += '\\\\'; continue; } if (c === 0x2c || c === 0x2b || c === 0x22 || c === 0x3c || c === 0x3e || c === 0x3b || c === 0x3d) { result += '\\' + value[i]; continue; } if (c <= 31) { result += '\\' + c.toString(16).padStart(2, '0'); continue; } if ((i === 0 || i === value.length - 1) && c === 0x20) { result += '\\20'; continue; } if (i === 0 && c === 0x23) { result += '\\23'; continue; } result += value[i]; } return result; };