GUACAMOLE-234: Merge fixes for LDAP resource leak regressions.

This commit is contained in:
Mike Jumper
2019-08-12 10:15:13 -07:00
committed by GitHub
2 changed files with 17 additions and 28 deletions

View File

@@ -128,10 +128,8 @@ public class LDAPConnectionService {
public LdapNetworkConnection bindAs(Dn userDN, String password)
throws GuacamoleException {
// Obtain appropriately-configured LdapNetworkConnection instance
LdapNetworkConnection ldapConnection = createLDAPConnection();
try {
// Get ldapConnection and try to connect and bind.
try (LdapNetworkConnection ldapConnection = createLDAPConnection()) {
// Connect to LDAP server
ldapConnection.connect();
@@ -140,14 +138,7 @@ public class LDAPConnectionService {
if (confService.getEncryptionMethod() == EncryptionMethod.STARTTLS)
ldapConnection.startTls();
}
catch (LdapException e) {
throw new GuacamoleServerException("Error connecting to LDAP server.", e);
}
// Bind using provided credentials
try {
BindRequest bindRequest = new BindRequestImpl();
bindRequest.setDn(userDN);
bindRequest.setCredentials(password);
@@ -165,7 +156,6 @@ public class LDAPConnectionService {
// Disconnect if an error occurs during bind
catch (LdapException e) {
logger.debug("Unable to bind to LDAP server.", e);
disconnect(ldapConnection);
throw new GuacamoleInvalidCredentialsException(
"Unable to bind to the LDAP server.",
CredentialsInfo.USERNAME_PASSWORD);

View File

@@ -20,6 +20,7 @@
package org.apache.guacamole.auth.ldap;
import com.google.inject.Inject;
import java.io.IOException;
import java.util.ArrayList;
import java.util.Collection;
import java.util.HashMap;
@@ -188,19 +189,17 @@ public class ObjectQueryService {
logger.debug("Searching \"{}\" for objects matching \"{}\".", baseDN, query);
try {
LdapConnectionConfig ldapConnectionConfig = ldapConnection.getConfig();
// Search within subtree of given base DN
SearchRequest request = ldapService.getSearchRequest(baseDN,
query);
SearchCursor results = ldapConnection.search(request);
// Produce list of all entries in the search result, automatically
// following referrals if configured to do so
List<Entry> entries = new ArrayList<>();
try (SearchCursor results = ldapConnection.search(request)) {
while (results.next()) {
if (results.isEntry()) {
@@ -226,7 +225,7 @@ public class ObjectQueryService {
return entries;
}
catch (CursorException | LdapException e) {
catch (CursorException | IOException | LdapException e) {
throw new GuacamoleServerException("Unable to query list of "
+ "objects from LDAP directory.", e);
}