feat(auth): LDAP login — authenticate imported users against the directory
Tessera CI/CD / Lint & Type Check (push) Successful in 47s
Tessera CI/CD / Tests (push) Successful in 47s
Tessera CI/CD / Build & Publish Images (push) Successful in 2m21s

LDAP-imported users have no local passwordHash, and validateUser only checked
the local password, so they could never log in. Now a passwordless user with
an ldapDn is authenticated by binding as their OWN DN with the entered
password against the tenant's active LDAP config (reusing the ldaps TLS-skip
option). Empty passwords are rejected before binding to avoid AD's
unauthenticated-bind bypass. Local-password users are unchanged.

LdapService.verifyUserCredentials added; LdapModule now exports
LdapConfigService; AuthModule imports LdapModule (no circular dep). 8 new
specs (bind success/fail, empty-password guard, login via bind, wrong pw, no
config, no ldapDn, inactive). API 226 green, tsc clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-22 14:51:23 +02:00
parent af9e968c6f
commit a1cf05404c
6 changed files with 220 additions and 3 deletions
+35
View File
@@ -152,6 +152,41 @@ export class LdapService {
}
}
/**
* Authenticate a user for LOGIN by binding as their OWN DN with the password
* they entered (distinct from the service-account bind used for sync/search).
* Returns true only on a successful authenticated bind.
*
* SECURITY: an empty password is rejected up front — many AD servers treat a
* bind with a DN and empty password as an unauthenticated/anonymous bind that
* "succeeds", which would let anyone log in as any LDAP user. Never allow it.
*/
async verifyUserCredentials(
config: { serverUrl: string; tlsRejectUnauthorized?: boolean | null },
userDn: string,
password: string,
): Promise<boolean> {
if (!userDn || !password) {
return false;
}
const client = new Client(
this.buildClientOptions(config.serverUrl, config.tlsRejectUnauthorized),
);
try {
await client.bind(userDn, password);
return true;
} catch {
return false;
} finally {
try {
await client.unbind();
} catch {
// Ignore unbind errors
}
}
}
/**
* Discover groups and organizational units under the configured base DN.
* Used by the admin UI to build a selective import filter (groupFilterDns).