diff --git a/mozilla/webtools/bugzilla/Bugzilla/Auth/LDAP.pm b/mozilla/webtools/bugzilla/Bugzilla/Auth/LDAP.pm index 179b5a2c588..c34c3698fe3 100644 --- a/mozilla/webtools/bugzilla/Bugzilla/Auth/LDAP.pm +++ b/mozilla/webtools/bugzilla/Bugzilla/Auth/LDAP.pm @@ -84,7 +84,7 @@ sub authenticate { # We've got our anonymous bind; let's look up this user. $mesg = $LDAPconn->search( base => Param("LDAPBaseDN"), scope => "sub", - filter => Param("LDAPuidattribute") . "=$username", + filter => '(&(' . Param("LDAPuidattribute") . "=$username)" . Param("LDAPfilter") . ')', attrs => ['dn'], ); return (AUTH_LOGINFAILED, undef, "lookup_failure") @@ -102,7 +102,7 @@ sub authenticate { # mail attribute for this user. $mesg = $LDAPconn->search( base => Param("LDAPBaseDN"), scope => "sub", - filter => Param("LDAPuidattribute") . "=$username", + filter => '(&(' . Param("LDAPuidattribute") . "=$username)" . Param("LDAPfilter") . ')', ); my $user_entry = $mesg->shift_entry if !$mesg->code && $mesg->count; if(!$user_entry || !$user_entry->exists(Param("LDAPmailattribute"))) { diff --git a/mozilla/webtools/bugzilla/defparams.pl b/mozilla/webtools/bugzilla/defparams.pl index 15232ad4696..e2dcf753372 100644 --- a/mozilla/webtools/bugzilla/defparams.pl +++ b/mozilla/webtools/bugzilla/defparams.pl @@ -388,6 +388,14 @@ sub check_loginmethod { default => 'mail' }, + { + name => 'LDAPfilter', + desc => 'LDAP filter to AND with the LDAPuidattribute for ' . + 'filtering the list of valid users.', + type => 't', + default => '', + }, + { name => 'loginmethod', desc => 'The type of login authentication to use: