goauthentik/authentik

Nested user attributes not exposed as valid LDAP attributes in LDAP Outpost

オープン

#16,954 opened on 2025/09/23

 (2 件のコメント) (0 件のリアクション) (0 人の担当者)Python (319 件のフォーク)batch import
bugbug/confirmedgood first issue

Repository metrics

Stars
 (4,050 個のスター)
PR merge metrics
 (PR metrics pending)

説明

Describe the bug When exposing custom attributes via the LDAP outpost, nested attributes are not returned as individual LDAP attributes. Instead, they appear in a serialized map format that does not seem to comply with LDAP.

To Reproduce Steps to reproduce the behavior:

  1. Configure a user in Authentik with a custom attribute containing nested values, e.g. settings.locale = en.
  2. Query the user via the LDAP outpost using ldapsearch.
  3. Inspect the LDAP response.

See that the attribute is returned as a serialized map string rather than as a proper multi-valued LDAP attribute.

Expected behavior I would expect the LDAP outpost to flatten or map the nested attribute into standard LDAP attributes, for example:

settingsLocale: en

or

settings.locale: en

instead of:

settings: map[locale:en]

Version and Deployment (please complete the following information):

  • authentik version: 2025.8.3
  • Deployment: Docker

Additional context Add any other context about the problem here.

コントリビューターガイド