docs: document that the domain/base DN is entered once (#37)
The base DN (stack.ldapBaseDn) is the single place the domain is set; the LDAP DNs (bindDN/userBase/groupBase) and oauth.issuer all derive from it and must stay consistent. Drifting them apart (leaving bindDN at dc=example,dc=com while ldapBaseDn is the real domain) makes the SSO bind against a non-existent root DN and every login fails with Invalid Credentials. - secrets.js.example: clarifying comment at ldapBaseDn - DEPLOYMENT.md: "domain entered once as the base DN" note + theta-env setup.env cross-link (merged the two duplicate theta-env blockquotes) - README.md: cross-link to DEPLOYMENT.md from "Server set up" Docs only; no app/secrets-structure change. Co-authored-by: Claude <noreply@anthropic.com>
This commit is contained in:
+4
-1
@@ -52,7 +52,10 @@ module.exports = {
|
||||
// Read by docker-entrypoint.sh (server-side slapd config + validation), the
|
||||
// superproject bootstrap script, and setup.sh. Omit for bare-metal use.
|
||||
stack: {
|
||||
ldapBaseDn: 'dc=example,dc=com', // slapd suffix (also drives seed OUs)
|
||||
ldapBaseDn: 'dc=example,dc=com', // slapd suffix (also drives seed OUs).
|
||||
// The base DN also appears in ldap.bindDN/userBase/groupBase above and
|
||||
// in oauth.issuer — keep them consistent with this value
|
||||
// (cn=admin,<dn>, ou=people,<dn>, ou=groups,<dn>, https://<ssoHost>).
|
||||
ldapDomain: 'example.com', // default cert CN + OAuth issuer host
|
||||
ldapCertCn: '', // cert CN; empty -> defaults to ldapDomain
|
||||
ssoHost: 'sso.example.com', // public SSO hostname (OAuth issuer URL)
|
||||
|
||||
Reference in New Issue
Block a user