Merge pull request #32 from theta42/fix/load-theta42-schema-in-image
Load the theta42 (dateOfBirth) schema in the all-in-one image
This commit is contained in:
@@ -68,6 +68,13 @@ COPY tos.md /tos.md
|
|||||||
COPY docker-entrypoint.sh /usr/local/bin/
|
COPY docker-entrypoint.sh /usr/local/bin/
|
||||||
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
|
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
|
||||||
|
|
||||||
|
# theta42 custom schema (dateOfBirth + theta42Person). The app adds
|
||||||
|
# objectClass theta42Person when a user has a dateOfBirth, so the directory
|
||||||
|
# must know it or user create/update fails with LDAP 0x15. Mirrors the
|
||||||
|
# cn=config LDIF ops/ldap-setup.sh loads on bare metal, in .schema form so
|
||||||
|
# docker-entrypoint.sh can `include` it in the static slapd.conf.
|
||||||
|
COPY ops/schema/theta42.schema /etc/openldap/schema/theta42.schema
|
||||||
|
|
||||||
# Expose ports
|
# Expose ports
|
||||||
# 3001: SSO Manager web interface (HTTP — terminate TLS at the front proxy)
|
# 3001: SSO Manager web interface (HTTP — terminate TLS at the front proxy)
|
||||||
# 389: LDAP (plain + StartTLS) — used internally by the app; map to host only
|
# 389: LDAP (plain + StartTLS) — used internally by the app; map to host only
|
||||||
|
|||||||
@@ -78,6 +78,7 @@ include /etc/openldap/schema/core.schema
|
|||||||
include /etc/openldap/schema/cosine.schema
|
include /etc/openldap/schema/cosine.schema
|
||||||
include /etc/openldap/schema/inetorgperson.schema
|
include /etc/openldap/schema/inetorgperson.schema
|
||||||
include /etc/openldap/schema/nis.schema
|
include /etc/openldap/schema/nis.schema
|
||||||
|
include /etc/openldap/schema/theta42.schema
|
||||||
|
|
||||||
# Module loading (pw-sha2 provides {SSHA512} used by the app for user passwords;
|
# Module loading (pw-sha2 provides {SSHA512} used by the app for user passwords;
|
||||||
# ppolicy/memberof/refint are the overlays the app depends on). On OpenLDAP 2.5+
|
# ppolicy/memberof/refint are the overlays the app depends on). On OpenLDAP 2.5+
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# theta42 custom schema — dateOfBirth (ISO 8601 YYYY-MM-DD) + the theta42Person
|
||||||
|
# auxiliary objectClass that carries it.
|
||||||
|
#
|
||||||
|
# This mirrors the cn=config LDIF that ops/ldap-setup.sh section 5 loads on
|
||||||
|
# bare-metal deployments, in slapd.conf .schema form so the all-in-one Docker
|
||||||
|
# image (which uses a static slapd.conf) can `include` it. The app
|
||||||
|
# (nodejs/models/user_ldap.js) adds objectClass theta42Person when a user has a
|
||||||
|
# dateOfBirth, so the directory must know this objectClass or user
|
||||||
|
# create/update fails with LDAP 0x15 (objectClass: value invalid per syntax).
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.99999.1.1
|
||||||
|
NAME 'dateOfBirth'
|
||||||
|
DESC 'Date of birth in ISO 8601 format YYYY-MM-DD'
|
||||||
|
EQUALITY caseExactMatch
|
||||||
|
SUBSTR caseExactSubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.15
|
||||||
|
SINGLE-VALUE )
|
||||||
|
|
||||||
|
objectclass ( 1.3.6.1.4.1.99999.2.1
|
||||||
|
NAME 'theta42Person'
|
||||||
|
DESC 'Theta42 SSO extended person attributes'
|
||||||
|
AUXILIARY
|
||||||
|
MAY ( dateOfBirth ) )
|
||||||
Reference in New Issue
Block a user