feat(auth): LDAP login — authenticate imported users against the directory
LDAP-imported users have no local passwordHash, and validateUser only checked the local password, so they could never log in. Now a passwordless user with an ldapDn is authenticated by binding as their OWN DN with the entered password against the tenant's active LDAP config (reusing the ldaps TLS-skip option). Empty passwords are rejected before binding to avoid AD's unauthenticated-bind bypass. Local-password users are unchanged. LdapService.verifyUserCredentials added; LdapModule now exports LdapConfigService; AuthModule imports LdapModule (no circular dep). 8 new specs (bind success/fail, empty-password guard, login via bind, wrong pw, no config, no ldapDn, inactive). API 226 green, tsc clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -16,6 +16,6 @@ import { LdapService } from './ldap.service';
|
||||
imports: [ScheduleModule.forRoot(), UserModule],
|
||||
controllers: [LdapController],
|
||||
providers: [LdapService, LdapConfigService, LdapSyncScheduler],
|
||||
exports: [LdapService],
|
||||
exports: [LdapService, LdapConfigService],
|
||||
})
|
||||
export class LdapModule {}
|
||||
|
||||
@@ -308,3 +308,44 @@ describe('LdapService.testConnection — TLS verification opt-out (ldaps)', () =
|
||||
expect(opts.tlsOptions).toBeUndefined();
|
||||
});
|
||||
});
|
||||
|
||||
describe('LdapService.verifyUserCredentials — LDAP login bind', () => {
|
||||
let service: LdapService;
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
mockUnbind.mockResolvedValue(undefined);
|
||||
service = new LdapService({} as any, {} as any);
|
||||
});
|
||||
|
||||
it('returns true when the user bind succeeds', async () => {
|
||||
mockBind.mockResolvedValue(undefined);
|
||||
const ok = await service.verifyUserCredentials(
|
||||
{ serverUrl: 'ldaps://ad:636', tlsRejectUnauthorized: false },
|
||||
'CN=alice,DC=x',
|
||||
'correct-pw',
|
||||
);
|
||||
expect(ok).toBe(true);
|
||||
expect(mockBind).toHaveBeenCalledWith('CN=alice,DC=x', 'correct-pw');
|
||||
});
|
||||
|
||||
it('returns false when the user bind fails (wrong password)', async () => {
|
||||
mockBind.mockRejectedValue(new Error('invalid credentials'));
|
||||
const ok = await service.verifyUserCredentials(
|
||||
{ serverUrl: 'ldaps://ad:636' },
|
||||
'CN=alice,DC=x',
|
||||
'wrong-pw',
|
||||
);
|
||||
expect(ok).toBe(false);
|
||||
});
|
||||
|
||||
it('rejects an empty password WITHOUT binding (no anonymous-bind bypass)', async () => {
|
||||
const ok = await service.verifyUserCredentials(
|
||||
{ serverUrl: 'ldaps://ad:636' },
|
||||
'CN=alice,DC=x',
|
||||
'',
|
||||
);
|
||||
expect(ok).toBe(false);
|
||||
expect(mockBind).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -152,6 +152,41 @@ export class LdapService {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Authenticate a user for LOGIN by binding as their OWN DN with the password
|
||||
* they entered (distinct from the service-account bind used for sync/search).
|
||||
* Returns true only on a successful authenticated bind.
|
||||
*
|
||||
* SECURITY: an empty password is rejected up front — many AD servers treat a
|
||||
* bind with a DN and empty password as an unauthenticated/anonymous bind that
|
||||
* "succeeds", which would let anyone log in as any LDAP user. Never allow it.
|
||||
*/
|
||||
async verifyUserCredentials(
|
||||
config: { serverUrl: string; tlsRejectUnauthorized?: boolean | null },
|
||||
userDn: string,
|
||||
password: string,
|
||||
): Promise<boolean> {
|
||||
if (!userDn || !password) {
|
||||
return false;
|
||||
}
|
||||
|
||||
const client = new Client(
|
||||
this.buildClientOptions(config.serverUrl, config.tlsRejectUnauthorized),
|
||||
);
|
||||
try {
|
||||
await client.bind(userDn, password);
|
||||
return true;
|
||||
} catch {
|
||||
return false;
|
||||
} finally {
|
||||
try {
|
||||
await client.unbind();
|
||||
} catch {
|
||||
// Ignore unbind errors
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Discover groups and organizational units under the configured base DN.
|
||||
* Used by the admin UI to build a selective import filter (groupFilterDns).
|
||||
|
||||
Reference in New Issue
Block a user