a1cf05404c
LDAP-imported users have no local passwordHash, and validateUser only checked the local password, so they could never log in. Now a passwordless user with an ldapDn is authenticated by binding as their OWN DN with the entered password against the tenant's active LDAP config (reusing the ldaps TLS-skip option). Empty passwords are rejected before binding to avoid AD's unauthenticated-bind bypass. Local-password users are unchanged. LdapService.verifyUserCredentials added; LdapModule now exports LdapConfigService; AuthModule imports LdapModule (no circular dep). 8 new specs (bind success/fail, empty-password guard, login via bind, wrong pw, no config, no ldapDn, inactive). API 226 green, tsc clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
30 lines
957 B
TypeScript
30 lines
957 B
TypeScript
import { Module } from '@nestjs/common';
|
|
import { ConfigService } from '@nestjs/config';
|
|
import { JwtModule } from '@nestjs/jwt';
|
|
import { PassportModule } from '@nestjs/passport';
|
|
import { LdapModule } from '../ldap/ldap.module';
|
|
import { MailModule } from '../mail/mail.module';
|
|
import { AuthController } from './auth.controller';
|
|
import { AuthService } from './auth.service';
|
|
import { JwtStrategy } from './strategies/jwt.strategy';
|
|
import { LocalStrategy } from './strategies/local.strategy';
|
|
|
|
@Module({
|
|
imports: [
|
|
PassportModule,
|
|
JwtModule.registerAsync({
|
|
useFactory: (configService: ConfigService) => ({
|
|
secret: configService.get<string>('JWT_SECRET'),
|
|
signOptions: { expiresIn: '30d' },
|
|
}),
|
|
inject: [ConfigService],
|
|
}),
|
|
MailModule,
|
|
LdapModule,
|
|
],
|
|
controllers: [AuthController],
|
|
providers: [AuthService, LocalStrategy, JwtStrategy],
|
|
exports: [AuthService],
|
|
})
|
|
export class AuthModule {}
|