Forum Discussion
Sending APM AD Query groups as a header
Hi,
Such piece of code should work (HTTP_REQUEST_RELEASE is valid, too) and, taking for granted the group membership piece of data does not violate HTTP RFC (syntax, size, ...), I'd suggest we try we removing the directive "clientside".
Otherwise, the perRequest policies come with the "HTTP Headers" agents that should do just that!
- buulamJan 19, 2023
Admin
Hi SteveD1979 did you have any feedback after this reply from Scot_JC ?
- SteveD1979Feb 15, 2023
Cirrostratus
No i still don't have this working. Sorry I had other projects going on. This is my irule right now and it will send all of the member of in CN=, DN=, DN= format. The header is just too long. I'm trying to figure out a way to split it with an irule or if i have to create a custom variable in the VPE and call that.
when ACCESS_ACL_ALLOWED {
HTTP::header replace USERID [ACCESS::session data get session.logon.last.username]
HTTP::header replace GROUPS [ACCESS::session data get session.ad.last.attr.memberOf]
}- Leslie_HubertusFeb 17, 2023Ret. Employee
Not sure if this is more in Lucas_Thompson's wheelhouse, or JRahm, or Kai_Wilke, but tagging them all just in case.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com