67e2fc54c2
Rewire onto the shared @simpleworkjs/oidc-client, /directory-schema, /ldap, and
/app-stack packages (deleting the byte-identical local forks). utils/access.js
now fetches reachable hosts through the shared directory client, which
validates the {results} envelope and treats envelope drift as a failed group
rather than silently returning []. models/user_ldap.js is a thin wrapper over
createLdapClient (loose TLS default preserved). build_info moves to utils/ with
the shared {buildVersion,buildHash,buildYear} shape. Align ldapts ^8.1.8 and
redis ^6.1.0. Lockfile regenerated from the registry (no file:/link:).
Co-Authored-By: Claude <noreply@anthropic.com>
22 lines
983 B
JavaScript
22 lines
983 B
JavaScript
'use strict';
|
|
|
|
// Thin LDAP helpers — the jump host's entire LDAP surface, now backed by the
|
|
// shared @simpleworkjs/ldap package:
|
|
// getUser(uid) -> { dn, uid, sshPublicKeys: [] } or null
|
|
// getGroups(dn) -> [cn, ...] (groupOfNames membership)
|
|
// checkPassword(dn, pw) -> bool (simple bind as the user)
|
|
// addSshKey(dn, keyLine) -> void (idempotent multi-value add)
|
|
//
|
|
// Behavior is unchanged from the previous in-tree implementation: posixAccount
|
|
// user filter, groupOfNames group filter, bind-as-user password check,
|
|
// TypeOrValueExists treated as success on key add, and the same loose TLS
|
|
// default ({ rejectUnauthorized: false } when conf.ldap omits tlsOptions).
|
|
|
|
const conf = require('@simpleworkjs/conf');
|
|
const { createLdapClient } = require('@simpleworkjs/ldap');
|
|
|
|
const ldapConf = conf.ldap || {};
|
|
module.exports = createLdapClient({
|
|
...ldapConf,
|
|
tlsOptions: ldapConf.tlsOptions || { rejectUnauthorized: false },
|
|
}); |