Files
ldap-auth-service/lib/patch-ldap-dn.js
2026-08-20 14:34:28 +05:00

44 lines
1.5 KiB
JavaScript

'use strict';
// Workaround for ldapjs 3.x / @ldapjs/dn: its escapeValue hex-escapes every
// non-ASCII UTF-8 byte in DN values (\d0\a2...). Active Directory's LDAP add
// parser decodes those hex escapes as Latin-1 characters, so Cyrillic DNs get
// double-encoded (mojibake) on the server and group membership lookups fail
// with LDAP 32. Keep non-ASCII characters raw so writeString sends real UTF-8.
// Must be loaded BEFORE ldapjs/@ldapjs/dn are required.
//
// eslint-disable-next-line global-require
const modulePath = require.resolve('@ldapjs/dn/lib/utils/escape-value');
// eslint-disable-next-line global-require
require(modulePath); // ensure it is in the require cache
require.cache[modulePath].exports = function escapeValue(value) {
if (typeof value !== 'string') {
throw new Error('value must be a string');
}
let result = '';
for (let i = 0; i < value.length; i += 1) {
const c = value.charCodeAt(i);
if (c === 0x5c) {
result += '\\\\';
continue;
}
if (c === 0x2c || c === 0x2b || c === 0x22 || c === 0x3c || c === 0x3e || c === 0x3b || c === 0x3d) {
result += '\\' + value[i];
continue;
}
if (c <= 31) {
result += '\\' + c.toString(16).padStart(2, '0');
continue;
}
if ((i === 0 || i === value.length - 1) && c === 0x20) {
result += '\\20';
continue;
}
if (i === 0 && c === 0x23) {
result += '\\23';
continue;
}
result += value[i];
}
return result;
};