Closed mattmoyer closed 3 years ago
We could consider using RFC2255 to put enough data into the URL to make it unique. Note that RFC2255 already defines the sub
query to mean subtree search, although maybe we could just ignore that little detail. :)
I noticed this is somewhat weird for Jumpcloud, since all users have the same
ldaps://ldap.jumpcloud.com/?sub=XYZ
-style URL, and anysub
collisions would be the same across different search bases. Maybe we should encode the search base somehow?Originally posted by @mattmoyer in https://github.com/vmware-tanzu/pinniped/pull/620#r636518757