LDAP request has unreplaced template

Cantor, Scott
Fri Feb 15 14:39:18 EST 2013

On 2/15/13 1:55 PM, "Christopher Bongaarts" <cab at umn.edu> wrote:

>Here's one I've not seen before...
>[15/Feb/2013:11:59:01 -0600] - OPERATION  - INFO  - conn=12888470 op=1
>msgid=2 SEARCH base="o=university of minnesota,c=us" scope=2
>filter="(uid=$requestContext.principalName)" attrs="* isMemberOf "
>Coming in on a connection from one of our Shib IdP servers.  Only seeing
>a handful of these per day.  Is there a code path that can result in this?

I would speculate that it could be a code path in which the identity is
null, but I wasn't sure if that would leave the variable unreplaced or
replaced with an empty string.

-- Scott

