diff --git a/nodejs/routes/index.js b/nodejs/routes/index.js index 7ad0453..8149e38 100755 --- a/nodejs/routes/index.js +++ b/nodejs/routes/index.js @@ -82,6 +82,34 @@ router.get('/oauth-clients', function(req, res, next) { res.render('oauth_clients', {...values, issuer, discoveryUrl: `${issuer}/.well-known/openid-configuration`}); }); +// Everything a 3rd-party app or the ldap-client host script needs to bind +// this directory, derived from the running config + request host rather than +// hardcoded in a doc -- so it's always right for *this* deployment. +router.get('/ldap-info', function(req, res, next) { + const issuer = ((conf.oauth && conf.oauth.issuer) || `${req.protocol}://${req.get('host')}`).replace(/\/$/, ''); + const ldapHost = issuer.replace(/^https?:\/\//, '').replace(/:\d+$/, ''); + + const userBase = (conf.ldap && conf.ldap.userBase) || 'ou=people,dc=example,dc=com'; + const groupBase = (conf.ldap && conf.ldap.groupBase) || 'ou=groups,dc=example,dc=com'; + // The base DN isn't stored as its own config value -- derive it by + // stripping the leading "ou=...," off userBase (ou=people,dc=example,dc=com + // -> dc=example,dc=com). + const baseDn = userBase.replace(/^ou=[^,]+,/i, ''); + + res.render('ldap_info', { + ...values, + ldapHost, + ldapsUrl: `ldaps://${ldapHost}:636`, + baseDn, + userBase, + groupBase, + userFilter: (conf.ldap && conf.ldap.userFilter) || '(objectClass=posixAccount)', + userNameAttribute: (conf.ldap && conf.ldap.userNameAttribute) || 'uid', + exampleBindDn: `cn=ldapclient,${userBase}`, + ssoUrl: issuer, + }); +}); + // API Tokens is now a section on the Profile page (own profile only). router.get('/api-tokens', (req, res) => res.redirect(301, '/')); diff --git a/nodejs/views/ldap_info.ejs b/nodejs/views/ldap_info.ejs new file mode 100644 index 0000000..e3536fd --- /dev/null +++ b/nodejs/views/ldap_info.ejs @@ -0,0 +1,155 @@ +<%- include('top') %> + + + +

LDAP Info

+

+ Everything a 3rd-party app or host needs to bind this directory, filled in + for <%= ssoUrl %>. +

+ +
+
+
+
+ Connection details +
+
+

+ For a single app's own "LDAP authentication" settings — see + Connecting a 3rd-party app or container + for a field-by-field walkthrough (Gitea, generic Docker LDAP_* env vars, …). +

+
+
LDAPS URL
+
+
+ + +
+
+ +
Base DN
+
+
+ + +
+
+ +
User search base
+
+
+ + +
+
+ +
Group search base
+
+
+ + +
+
+ +
User filter
+
+
+ + +
+
+ +
Username attribute
+
+
+ + +
+
+ +
Example bind DN
+
+
+ + +
+ + A read-only bind account — create it as a plain user via + Users (don't put it in app_sso_admin + or any other privileged group). + +
+
+
+
+
+ +
+
+
+ Set up a Linux host (ldap-client) +
+
+

+ For full host login, SSH keys, and sudo via LDAP (not just one app) — + clone theta42/ldap-client + and run this on the host. Fill in the bind account's password and, + if you want this host's access/sudo groups auto-registered, an + API token from your Profile. +

+
+ +
+ +
+
+
+
+ + + +<%- include('bottom') %> diff --git a/nodejs/views/top.ejs b/nodejs/views/top.ejs index c57e68c..b912922 100755 --- a/nodejs/views/top.ejs +++ b/nodejs/views/top.ejs @@ -56,6 +56,12 @@ OAuth Apps +