mirror of
https://github.com/projectsend/projectsend.git
synced 2026-10-07 22:01:21 +00:00
9c43f9cb9a
LDAP sign-in only took an email address. The LDAP settings now have an optional username attribute (cn, uid, sAMAccountName and so on). Once it is set, the login field also takes a username. The service account looks the username up, and the login carries on with the address the directory holds for it, through the same checks, single user bind, provisioning and rate limiting as an email login. Whether the input is an address is decided by the same email rule that accepted every stored address, so an address such as someone@localhost is never taken for a username. The username goes through the query builder, so it is escaped, and it has to match exactly one entry. The directory is client-only, so a username never signs in a staff account. With the attribute left empty, nothing changes. This ports feat/ldap_signin_by_username, which was written against v1 and has no history in common with this codebase.
45 lines
1.6 KiB
PHP
45 lines
1.6 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Modules\Identity\Ldap;
|
|
|
|
/**
|
|
* Talking to a directory server.
|
|
*
|
|
* An interface with one production implementation, so the login flow can
|
|
* be tested without one. That is the whole testing strategy for this
|
|
* feature: everything above the wire — which account types may
|
|
* authenticate, provisioning, rate limiting, the two-factor hand-off — is
|
|
* where the bugs would be, and none of it should need a directory to
|
|
* exercise.
|
|
*/
|
|
interface LdapDirectory
|
|
{
|
|
/**
|
|
* Verify a password against the directory.
|
|
*
|
|
* Returns null for every failure — no such entry, wrong password,
|
|
* server unreachable — because the caller must not be able to tell
|
|
* those apart, and neither must the login form.
|
|
*/
|
|
public function authenticate(string $email, string $password): ?LdapIdentity;
|
|
|
|
/**
|
|
* The address of the one entry whose username attribute matches, found
|
|
* with the service account. No bind as the person, so nothing is
|
|
* verified here: the caller still signs in by that address, through
|
|
* authenticate(). Null for no match, more than one, or any failure.
|
|
*/
|
|
public function emailForUsername(string $username): ?string;
|
|
|
|
/**
|
|
* Exercise the configuration and report which stage failed, for the
|
|
* settings screen's test button. This is the one place that is allowed
|
|
* to be specific about failures: it is behind `edit_settings`, and it
|
|
* is the difference between a working directory and v1's checkbox that
|
|
* silently did nothing.
|
|
*/
|
|
public function probe(?string $email = null, ?string $password = null): LdapProbeResult;
|
|
}
|