feat(auth): LDAP login — authenticate imported users against the directory
Tessera CI/CD / Lint & Type Check (push) Successful in 47s
Tessera CI/CD / Tests (push) Successful in 47s
Tessera CI/CD / Build & Publish Images (push) Successful in 2m21s

LDAP-imported users have no local passwordHash, and validateUser only checked
the local password, so they could never log in. Now a passwordless user with
an ldapDn is authenticated by binding as their OWN DN with the entered
password against the tenant's active LDAP config (reusing the ldaps TLS-skip
option). Empty passwords are rejected before binding to avoid AD's
unauthenticated-bind bypass. Local-password users are unchanged.

LdapService.verifyUserCredentials added; LdapModule now exports
LdapConfigService; AuthModule imports LdapModule (no circular dep). 8 new
specs (bind success/fail, empty-password guard, login via bind, wrong pw, no
config, no ldapDn, inactive). API 226 green, tsc clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-22 14:51:23 +02:00
parent af9e968c6f
commit a1cf05404c
6 changed files with 220 additions and 3 deletions
+41
View File
@@ -308,3 +308,44 @@ describe('LdapService.testConnection — TLS verification opt-out (ldaps)', () =
expect(opts.tlsOptions).toBeUndefined();
});
});
describe('LdapService.verifyUserCredentials — LDAP login bind', () => {
let service: LdapService;
beforeEach(() => {
vi.clearAllMocks();
mockUnbind.mockResolvedValue(undefined);
service = new LdapService({} as any, {} as any);
});
it('returns true when the user bind succeeds', async () => {
mockBind.mockResolvedValue(undefined);
const ok = await service.verifyUserCredentials(
{ serverUrl: 'ldaps://ad:636', tlsRejectUnauthorized: false },
'CN=alice,DC=x',
'correct-pw',
);
expect(ok).toBe(true);
expect(mockBind).toHaveBeenCalledWith('CN=alice,DC=x', 'correct-pw');
});
it('returns false when the user bind fails (wrong password)', async () => {
mockBind.mockRejectedValue(new Error('invalid credentials'));
const ok = await service.verifyUserCredentials(
{ serverUrl: 'ldaps://ad:636' },
'CN=alice,DC=x',
'wrong-pw',
);
expect(ok).toBe(false);
});
it('rejects an empty password WITHOUT binding (no anonymous-bind bypass)', async () => {
const ok = await service.verifyUserCredentials(
{ serverUrl: 'ldaps://ad:636' },
'CN=alice,DC=x',
'',
);
expect(ok).toBe(false);
expect(mockBind).not.toHaveBeenCalled();
});
});