sasl-regexp proper behavior?

I recently had bad data in my directory (oops) that had would return 2 results to the sasl-regexp query for what bind DN to map a user to.

Other than this being a shot myself in the foot scenario, I'm curious about:

What is the current behavior when this happens? Would the entity get assigned the first DN returned?

What should the correct behavior be? From the literature, sasl-regexp should be a 1-1 mapping. So in a case like this when two results are returned, should the entity be mapped to a DN at all? Or would it be better to return an error?


