From 679c8a7d09e3308857988fd4c8210fd1003af397 Mon Sep 17 00:00:00 2001 From: Girish Ramakrishnan Date: Mon, 19 Sep 2016 13:53:44 -0700 Subject: [PATCH] Fix all usages of ldap.parseFilter Part of #56 --- src/ldap.js | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/src/ldap.js b/src/ldap.js index eb2633c33..a574a810a 100644 --- a/src/ldap.js +++ b/src/ldap.js @@ -127,7 +127,8 @@ function groupSearch(req, res, next) { }; // ensure all filter values are also lowercase - var lowerCaseFilter = ldap.parseFilter(req.filter.toString().toLowerCase()); + var lowerCaseFilter = safe(function () { return ldap.parseFilter(req.filter.toString().toLowerCase()); }, null); + if (!lowerCaseFilter) return next(new ldap.OperationsError(safe.error.toString())); if ((req.dn.equals(dn) || req.dn.parentOf(dn)) && lowerCaseFilter.matches(obj.attributes)) { res.send(obj); @@ -160,7 +161,8 @@ function mailboxSearch(req, res, next) { }; // ensure all filter values are also lowercase - var lowerCaseFilter = ldap.parseFilter(req.filter.toString().toLowerCase()); + var lowerCaseFilter = safe(function () { return ldap.parseFilter(req.filter.toString().toLowerCase()); }, null); + if (!lowerCaseFilter) return next(new ldap.OperationsError(safe.error.toString())); if ((req.dn.equals(dn) || req.dn.parentOf(dn)) && lowerCaseFilter.matches(obj.attributes)) { res.send(obj);