Additional settings
warnung
This setting is intended for specific cases where standard LDAP filters are not sufficient. Filtering with regular expressions on large data sets may reduce performance.
LDAP_GROUP_ADDITIONAL_FILTER allows additional filtering of LDAP groups using a regular expression. Key details:
- Scope — the regular expression is applied to the final result of the LDAP group loading process.
- What is filtered — the regular expression is applied only to the final group name (for example,
secops), not to the full DN string (CN=secops,OU=Groups...). - Syntax — standard PHP regular expressions (PCRE) are used.
- Delimiters — the pattern must be wrapped with delimiter characters (for example,
#). The opening and closing delimiter must match. - Enabling — set the filter value in
LDAP_GROUP_ADDITIONAL_FILTERin theconfig.envconfiguration file.
Examples
Exact match:
- shell
LDAP_GROUP_ADDITIONAL_FILTER=#^secops$#
Filtering by prefix:
- shell
LDAP_GROUP_ADDITIONAL_FILTER=#^prod-.*#
Case-insensitive filter:
- shell
LDAP_GROUP_ADDITIONAL_FILTER=#^admin$#i