{"kind": "hook", "major": "18", "item": {"slug": "ldap_password_hook", "name": "ldap_password_hook", "name_zh": "ldap_password_hook", "category": "Authentication and connections", "summary": "hook type for password manglers", "aliases": [], "versions": {"16": {"facts": [{"label": "Interface type", "value": "auth_password_hook_typ"}, {"label": "Header", "value": "src/include/libpq/auth.h"}, {"label": "Subsystem", "value": "Authentication and connections"}, {"label": "Initial value", "value": "dummy_ldap_password_mutator"}], "related": [], "release": {"ref": "REL_16_STABLE", "label": "16", "major": "16", "channel": "stable", "revision": "dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa/src/include/libpq/auth.h#L32", "path": "src/include/libpq/auth.h", "label": "Interface declaration", "sha256": "66c65b1a4254066bc368b56219742d0b3f21b8cad1c4cdf5bac5508414c94cd5"}, {"url": "https://github.com/postgres/postgres/blob/dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa/src/backend/libpq/auth.c#L157", "path": "src/backend/libpq/auth.c", "label": "Core definition", "sha256": "6803da2f479c149bec539985f611a83df73716f2b79838f0c972959a2bf2ec65"}, {"url": "https://github.com/postgres/postgres/blob/dcc37b7099a9f3cf2c75167d8dc92e75f96bc1fa/src/backend/libpq/auth.c#L2529", "path": "src/backend/libpq/auth.c", "label": "Call sites", "sha256": "6803da2f479c149bec539985f611a83df73716f2b79838f0c972959a2bf2ec65"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/libpq/auth.c:2529"]}, {"code": "\t\t/*\n\t\t * Bind with a pre-defined username/password (if available) for\n\t\t * searching. If none is specified, this turns into an anonymous bind.\n\t\t */\n\t\tr = ldap_simple_bind_s(ldap,\n\t\t\t\t\t\t\t   port->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\t   port->hba->ldapbindpasswd ? ldap_password_hook(port->hba->ldapbindpasswd) : \"\");\n\t\tif (r != LDAP_SUCCESS)\n\t\t{\n\t\t\tereport(LOG,\n\t\t\t\t\t(errmsg(\"could not perform initial LDAP bind for ldapbinddn \\\"%s\\\" on server \\\"%s\\\": %s\",\n\t\t\t\t\t\t\tport->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\tserver_name,\n\t\t\t\t\t\t\tldap_err2string(r)),\n\t\t\t\t\t errdetail_for_ldap(ldap)));", "title": "Core call context: src/backend/libpq/auth.c:2523\u20132537", "paragraphs": []}], "signature": "typedef char *(*auth_password_hook_typ) (char *input);\nextern PGDLLIMPORT auth_password_hook_typ ldap_password_hook;", "description": ["hook type for password manglers"]}, "17": {"facts": [{"label": "Interface type", "value": "auth_password_hook_typ"}, {"label": "Header", "value": "src/include/libpq/auth.h"}, {"label": "Subsystem", "value": "Authentication and connections"}, {"label": "Initial value", "value": "dummy_ldap_password_mutator"}], "related": [], "release": {"ref": "REL_17_STABLE", "label": "17", "major": "17", "channel": "stable", "revision": "163288afd32a448244c8df75b3c33181aadd7f20"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/163288afd32a448244c8df75b3c33181aadd7f20/src/include/libpq/auth.h#L32", "path": "src/include/libpq/auth.h", "label": "Interface declaration", "sha256": "a0066453dfde98129af96e8258339d958b4a400b967049ca7a9422adc7d8b8bf"}, {"url": "https://github.com/postgres/postgres/blob/163288afd32a448244c8df75b3c33181aadd7f20/src/backend/libpq/auth.c#L155", "path": "src/backend/libpq/auth.c", "label": "Core definition", "sha256": "3257a7b822764268e1ac47c0002959c56d203d17b008538ecb179b48c6c64e0b"}, {"url": "https://github.com/postgres/postgres/blob/163288afd32a448244c8df75b3c33181aadd7f20/src/backend/libpq/auth.c#L2538", "path": "src/backend/libpq/auth.c", "label": "Call sites", "sha256": "3257a7b822764268e1ac47c0002959c56d203d17b008538ecb179b48c6c64e0b"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/libpq/auth.c:2538"]}, {"code": "\t\t/*\n\t\t * Bind with a pre-defined username/password (if available) for\n\t\t * searching. If none is specified, this turns into an anonymous bind.\n\t\t */\n\t\tr = ldap_simple_bind_s(ldap,\n\t\t\t\t\t\t\t   port->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\t   port->hba->ldapbindpasswd ? ldap_password_hook(port->hba->ldapbindpasswd) : \"\");\n\t\tif (r != LDAP_SUCCESS)\n\t\t{\n\t\t\tereport(LOG,\n\t\t\t\t\t(errmsg(\"could not perform initial LDAP bind for ldapbinddn \\\"%s\\\" on server \\\"%s\\\": %s\",\n\t\t\t\t\t\t\tport->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\tserver_name,\n\t\t\t\t\t\t\tldap_err2string(r)),\n\t\t\t\t\t errdetail_for_ldap(ldap)));", "title": "Core call context: src/backend/libpq/auth.c:2532\u20132546", "paragraphs": []}], "signature": "typedef char *(*auth_password_hook_typ) (char *input);\nextern PGDLLIMPORT auth_password_hook_typ ldap_password_hook;", "description": ["hook type for password manglers"]}, "18": {"facts": [{"label": "Interface type", "value": "auth_password_hook_typ"}, {"label": "Header", "value": "src/include/libpq/auth.h"}, {"label": "Subsystem", "value": "Authentication and connections"}, {"label": "Initial value", "value": "dummy_ldap_password_mutator"}], "related": [], "release": {"ref": "REL_18_STABLE", "label": "18", "major": "18", "channel": "stable", "revision": "753057e340da8f22e57c9a409ea7a235fd6a46bd"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/include/libpq/auth.h#L49", "path": "src/include/libpq/auth.h", "label": "Interface declaration", "sha256": "976773a9612d289da53c43129ef0438a57904cdd19ffa2ca3d6d2b00104ec241"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/libpq/auth.c#L156", "path": "src/backend/libpq/auth.c", "label": "Core definition", "sha256": "94252cb1e2c49b0ddb15f6596d0abf8056c84493de07cc81439da4c5b07018f1"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/libpq/auth.c#L2536", "path": "src/backend/libpq/auth.c", "label": "Call sites", "sha256": "94252cb1e2c49b0ddb15f6596d0abf8056c84493de07cc81439da4c5b07018f1"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/libpq/auth.c:2536"]}, {"code": "\t\t/*\n\t\t * Bind with a pre-defined username/password (if available) for\n\t\t * searching. If none is specified, this turns into an anonymous bind.\n\t\t */\n\t\tr = ldap_simple_bind_s(ldap,\n\t\t\t\t\t\t\t   port->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\t   port->hba->ldapbindpasswd ? ldap_password_hook(port->hba->ldapbindpasswd) : \"\");\n\t\tif (r != LDAP_SUCCESS)\n\t\t{\n\t\t\tereport(LOG,\n\t\t\t\t\t(errmsg(\"could not perform initial LDAP bind for ldapbinddn \\\"%s\\\" on server \\\"%s\\\": %s\",\n\t\t\t\t\t\t\tport->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\tserver_name,\n\t\t\t\t\t\t\tldap_err2string(r)),\n\t\t\t\t\t errdetail_for_ldap(ldap)));", "title": "Core call context: src/backend/libpq/auth.c:2530\u20132544", "paragraphs": []}], "signature": "typedef char *(*auth_password_hook_typ) (char *input);\nextern PGDLLIMPORT auth_password_hook_typ ldap_password_hook;", "description": ["hook type for password manglers"]}, "19": {"facts": [{"label": "Interface type", "value": "auth_password_hook_typ"}, {"label": "Header", "value": "src/include/libpq/auth.h"}, {"label": "Subsystem", "value": "Authentication and connections"}, {"label": "Initial value", "value": "dummy_ldap_password_mutator"}], "related": [], "release": {"ref": "REL_19_BETA4", "label": "19 Beta 4", "major": "19", "channel": "preview", "revision": "b73d13c32c834a2c8e1c60cb92f79530376cedf1"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/b73d13c32c834a2c8e1c60cb92f79530376cedf1/src/include/libpq/auth.h#L49", "path": "src/include/libpq/auth.h", "label": "Interface declaration", "sha256": "8d296fc93077825992c59353c99cf4e3cb27407349c9e150a3ea90b2e36a2db2"}, {"url": "https://github.com/postgres/postgres/blob/b73d13c32c834a2c8e1c60cb92f79530376cedf1/src/backend/libpq/auth.c#L159", "path": "src/backend/libpq/auth.c", "label": "Core definition", "sha256": "d3ab30f5024f21b3ba60959b760898f8d84ba0a90498c3cde8c24fbb8b6ea734"}, {"url": "https://github.com/postgres/postgres/blob/b73d13c32c834a2c8e1c60cb92f79530376cedf1/src/backend/libpq/auth.c#L2583", "path": "src/backend/libpq/auth.c", "label": "Call sites", "sha256": "d3ab30f5024f21b3ba60959b760898f8d84ba0a90498c3cde8c24fbb8b6ea734"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/libpq/auth.c:2583"]}, {"code": "\t\t/*\n\t\t * Bind with a pre-defined username/password (if available) for\n\t\t * searching. If none is specified, this turns into an anonymous bind.\n\t\t */\n\t\tr = ldap_simple_bind_s(ldap,\n\t\t\t\t\t\t\t   port->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\t   port->hba->ldapbindpasswd ? ldap_password_hook(port->hba->ldapbindpasswd) : \"\");\n\t\tif (r != LDAP_SUCCESS)\n\t\t{\n\t\t\tereport(LOG,\n\t\t\t\t\t(errmsg(\"could not perform initial LDAP bind for ldapbinddn \\\"%s\\\" on server \\\"%s\\\": %s\",\n\t\t\t\t\t\t\tport->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\tserver_name,\n\t\t\t\t\t\t\tldap_err2string(r)),\n\t\t\t\t\t errdetail_for_ldap(ldap)));", "title": "Core call context: src/backend/libpq/auth.c:2577\u20132591", "paragraphs": []}], "signature": "typedef char *(*auth_password_hook_typ) (char *input);\nextern PGDLLIMPORT auth_password_hook_typ ldap_password_hook;", "description": ["hook type for password manglers"]}, "20": {"facts": [{"label": "Interface type", "value": "auth_password_hook_typ"}, {"label": "Header", "value": "src/include/libpq/auth.h"}, {"label": "Subsystem", "value": "Authentication and connections"}, {"label": "Initial value", "value": "dummy_ldap_password_mutator"}], "related": [], "release": {"ref": "master", "label": "20 devel", "major": "20", "channel": "devel", "revision": "2c10c2ce4d7bcd57543a49ab402af02a39724e0a"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/2c10c2ce4d7bcd57543a49ab402af02a39724e0a/src/include/libpq/auth.h#L49", "path": "src/include/libpq/auth.h", "label": "Interface declaration", "sha256": "8d296fc93077825992c59353c99cf4e3cb27407349c9e150a3ea90b2e36a2db2"}, {"url": "https://github.com/postgres/postgres/blob/2c10c2ce4d7bcd57543a49ab402af02a39724e0a/src/backend/libpq/auth.c#L159", "path": "src/backend/libpq/auth.c", "label": "Core definition", "sha256": "d3ab30f5024f21b3ba60959b760898f8d84ba0a90498c3cde8c24fbb8b6ea734"}, {"url": "https://github.com/postgres/postgres/blob/2c10c2ce4d7bcd57543a49ab402af02a39724e0a/src/backend/libpq/auth.c#L2583", "path": "src/backend/libpq/auth.c", "label": "Call sites", "sha256": "d3ab30f5024f21b3ba60959b760898f8d84ba0a90498c3cde8c24fbb8b6ea734"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/libpq/auth.c:2583"]}, {"code": "\t\t/*\n\t\t * Bind with a pre-defined username/password (if available) for\n\t\t * searching. If none is specified, this turns into an anonymous bind.\n\t\t */\n\t\tr = ldap_simple_bind_s(ldap,\n\t\t\t\t\t\t\t   port->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\t   port->hba->ldapbindpasswd ? ldap_password_hook(port->hba->ldapbindpasswd) : \"\");\n\t\tif (r != LDAP_SUCCESS)\n\t\t{\n\t\t\tereport(LOG,\n\t\t\t\t\t(errmsg(\"could not perform initial LDAP bind for ldapbinddn \\\"%s\\\" on server \\\"%s\\\": %s\",\n\t\t\t\t\t\t\tport->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\tserver_name,\n\t\t\t\t\t\t\tldap_err2string(r)),\n\t\t\t\t\t errdetail_for_ldap(ldap)));", "title": "Core call context: src/backend/libpq/auth.c:2577\u20132591", "paragraphs": []}], "signature": "typedef char *(*auth_password_hook_typ) (char *input);\nextern PGDLLIMPORT auth_password_hook_typ ldap_password_hook;", "description": ["hook type for password manglers"]}}, "content_hash": "480366d39b4b4c734bdcd1f51ddba0f75f94b0196e8c480d370aefad6c512c3b", "imported_at": "2026-09-27T09:57:58.828"}, "snapshot": {"facts": [{"label": "Interface type", "value": "auth_password_hook_typ"}, {"label": "Header", "value": "src/include/libpq/auth.h"}, {"label": "Subsystem", "value": "Authentication and connections"}, {"label": "Initial value", "value": "dummy_ldap_password_mutator"}], "related": [], "release": {"ref": "REL_18_STABLE", "label": "18", "major": "18", "channel": "stable", "revision": "753057e340da8f22e57c9a409ea7a235fd6a46bd"}, "sources": [{"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/include/libpq/auth.h#L49", "path": "src/include/libpq/auth.h", "label": "Interface declaration", "sha256": "976773a9612d289da53c43129ef0438a57904cdd19ffa2ca3d6d2b00104ec241"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/libpq/auth.c#L156", "path": "src/backend/libpq/auth.c", "label": "Core definition", "sha256": "94252cb1e2c49b0ddb15f6596d0abf8056c84493de07cc81439da4c5b07018f1"}, {"url": "https://github.com/postgres/postgres/blob/753057e340da8f22e57c9a409ea7a235fd6a46bd/src/backend/libpq/auth.c#L2536", "path": "src/backend/libpq/auth.c", "label": "Call sites", "sha256": "94252cb1e2c49b0ddb15f6596d0abf8056c84493de07cc81439da4c5b07018f1"}], "sections": [{"title": "Call sites", "paragraphs": ["src/backend/libpq/auth.c:2536"]}, {"code": "\t\t/*\n\t\t * Bind with a pre-defined username/password (if available) for\n\t\t * searching. If none is specified, this turns into an anonymous bind.\n\t\t */\n\t\tr = ldap_simple_bind_s(ldap,\n\t\t\t\t\t\t\t   port->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\t   port->hba->ldapbindpasswd ? ldap_password_hook(port->hba->ldapbindpasswd) : \"\");\n\t\tif (r != LDAP_SUCCESS)\n\t\t{\n\t\t\tereport(LOG,\n\t\t\t\t\t(errmsg(\"could not perform initial LDAP bind for ldapbinddn \\\"%s\\\" on server \\\"%s\\\": %s\",\n\t\t\t\t\t\t\tport->hba->ldapbinddn ? port->hba->ldapbinddn : \"\",\n\t\t\t\t\t\t\tserver_name,\n\t\t\t\t\t\t\tldap_err2string(r)),\n\t\t\t\t\t errdetail_for_ldap(ldap)));", "title": "Core call context: src/backend/libpq/auth.c:2530\u20132544", "paragraphs": []}], "signature": "typedef char *(*auth_password_hook_typ) (char *input);\nextern PGDLLIMPORT auth_password_hook_typ ldap_password_hook;", "description": ["hook type for password manglers"]}, "comparison": {"left": "15", "right": "16", "status": "added", "diff": "--- PostgreSQL 15\n+++ PostgreSQL 16\n@@ -1 +1,22 @@\n-Not recorded in this version\n+{\n+  \"facts\": [\n+    {\n+      \"label\": \"Interface type\",\n+      \"value\": \"auth_password_hook_typ\"\n+    },\n+    {\n+      \"label\": \"Header\",\n+      \"value\": \"src/include/libpq/auth.h\"\n+    },\n+    {\n+      \"label\": \"Subsystem\",\n+      \"value\": \"Authentication and connections\"\n+    },\n+    {\n+      \"label\": \"Initial value\",\n+      \"value\": \"dummy_ldap_password_mutator\"\n+    }\n+  ],\n+  \"signature\": \"typedef char *(*auth_password_hook_typ) (char *input);\\nextern PGDLLIMPORT auth_password_hook_typ ldap_password_hook;\",\n+  \"tables\": null\n+}"}}