mirror of
https://github.com/projectsend/projectsend.git
synced 2026-09-17 17:15:08 +00:00
6e47d76ba6
Client file sharing, rebuilt from the ground up: a private area per client, resumable uploads, folders, groups and categories, sharing with expiry dates and download limits, comments, file versions, an activity log, a REST API, and sixteen languages. This repository begins here. ProjectSend 2 was developed privately, and that development history is not published — the previous generation remains available, with its own history, at projectsend/legacy. Free software under the GNU General Public License v2, or (at your option) any later version.
41 lines
1.0 KiB
PHP
41 lines
1.0 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Modules\Identity\Ldap;
|
|
|
|
/**
|
|
* How the connection to the directory is protected.
|
|
*
|
|
* One field with three values rather than a pair of booleans, and
|
|
* deliberately no "don't verify the certificate" escape hatch — that
|
|
* setting is the most-abused option in every LDAP integration and turns
|
|
* "encrypted" into "encrypted to whoever answered". A corporate
|
|
* self-signed CA is the real need behind it, and LdapSettings answers that
|
|
* with a CA certificate path instead.
|
|
*/
|
|
enum LdapEncryption: string
|
|
{
|
|
case None = 'none';
|
|
case Ssl = 'ssl';
|
|
case Tls = 'tls';
|
|
|
|
public function label(): string
|
|
{
|
|
return match ($this) {
|
|
self::None => 'None (unencrypted)',
|
|
self::Ssl => 'LDAPS (implicit TLS)',
|
|
self::Tls => 'StartTLS',
|
|
};
|
|
}
|
|
|
|
/** The port this scheme conventionally listens on. */
|
|
public function defaultPort(): int
|
|
{
|
|
return match ($this) {
|
|
self::Ssl => 636,
|
|
default => 389,
|
|
};
|
|
}
|
|
}
|