feat(auth): LDAP login — authenticate imported users against the directory
LDAP-imported users have no local passwordHash, and validateUser only checked the local password, so they could never log in. Now a passwordless user with an ldapDn is authenticated by binding as their OWN DN with the entered password against the tenant's active LDAP config (reusing the ldaps TLS-skip option). Empty passwords are rejected before binding to avoid AD's unauthenticated-bind bypass. Local-password users are unchanged. LdapService.verifyUserCredentials added; LdapModule now exports LdapConfigService; AuthModule imports LdapModule (no circular dep). 8 new specs (bind success/fail, empty-password guard, login via bind, wrong pw, no config, no ldapDn, inactive). API 226 green, tsc clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,109 @@
|
||||
import { beforeEach, describe, expect, it, vi } from 'vitest';
|
||||
import { AuthService } from './auth.service';
|
||||
|
||||
/**
|
||||
* validateUser — LDAP login path (AUTH-06 follow-up): users imported from LDAP
|
||||
* have no local passwordHash and must be authenticated by binding as their own
|
||||
* DN against the tenant's directory. These tests cover that branch; the local
|
||||
* password path (argon2) is unchanged and exercised elsewhere.
|
||||
*/
|
||||
describe('AuthService.validateUser — LDAP login', () => {
|
||||
let service: AuthService;
|
||||
let prisma: any;
|
||||
let ldapService: any;
|
||||
let ldapConfigService: any;
|
||||
|
||||
const ldapUser = {
|
||||
id: 'u1',
|
||||
tenantId: 't1',
|
||||
username: 'alice',
|
||||
passwordHash: null,
|
||||
ldapDn: 'CN=alice,OU=Users,DC=ctl,DC=local',
|
||||
isActive: true,
|
||||
};
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
prisma = {
|
||||
user: {
|
||||
findUnique: vi.fn().mockResolvedValue(ldapUser),
|
||||
update: vi.fn().mockResolvedValue({}),
|
||||
},
|
||||
};
|
||||
ldapService = { verifyUserCredentials: vi.fn() };
|
||||
ldapConfigService = {
|
||||
getConfig: vi.fn().mockResolvedValue({
|
||||
serverUrl: 'ldaps://balios.ctl.local:636',
|
||||
isActive: true,
|
||||
tlsRejectUnauthorized: false,
|
||||
}),
|
||||
};
|
||||
service = new AuthService(
|
||||
prisma,
|
||||
{} as any,
|
||||
{} as any,
|
||||
{} as any,
|
||||
ldapService,
|
||||
ldapConfigService,
|
||||
);
|
||||
});
|
||||
|
||||
it('authenticates an LDAP user via a successful directory bind', async () => {
|
||||
ldapService.verifyUserCredentials.mockResolvedValue(true);
|
||||
|
||||
const result = await service.validateUser('Alice', 'ad-password');
|
||||
|
||||
expect(result).toEqual(ldapUser);
|
||||
expect(ldapService.verifyUserCredentials).toHaveBeenCalledWith(
|
||||
{
|
||||
serverUrl: 'ldaps://balios.ctl.local:636',
|
||||
tlsRejectUnauthorized: false,
|
||||
},
|
||||
ldapUser.ldapDn,
|
||||
'ad-password',
|
||||
);
|
||||
expect(prisma.user.update).toHaveBeenCalledWith({
|
||||
where: { id: 'u1' },
|
||||
data: { lastLoginAt: expect.any(Date) },
|
||||
});
|
||||
});
|
||||
|
||||
it('rejects an LDAP user when the directory bind fails', async () => {
|
||||
ldapService.verifyUserCredentials.mockResolvedValue(false);
|
||||
|
||||
const result = await service.validateUser('alice', 'wrong');
|
||||
|
||||
expect(result).toBeNull();
|
||||
expect(prisma.user.update).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it('rejects an LDAP user when no active LDAP config exists', async () => {
|
||||
ldapConfigService.getConfig.mockResolvedValue(null);
|
||||
|
||||
const result = await service.validateUser('alice', 'pw');
|
||||
|
||||
expect(result).toBeNull();
|
||||
expect(ldapService.verifyUserCredentials).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it('rejects a passwordless user that has no ldapDn (never binds)', async () => {
|
||||
prisma.user.findUnique.mockResolvedValue({
|
||||
...ldapUser,
|
||||
ldapDn: null,
|
||||
});
|
||||
|
||||
const result = await service.validateUser('alice', 'pw');
|
||||
|
||||
expect(result).toBeNull();
|
||||
expect(ldapService.verifyUserCredentials).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it('rejects an inactive LDAP user before any bind', async () => {
|
||||
prisma.user.findUnique.mockResolvedValue({ ...ldapUser, isActive: false });
|
||||
|
||||
const result = await service.validateUser('alice', 'pw');
|
||||
|
||||
expect(result).toBeNull();
|
||||
expect(ldapService.verifyUserCredentials).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user