2021-04-19 23:30:27 +01:00
|
|
|
package ldap
|
|
|
|
|
|
|
|
import (
|
2021-04-26 10:53:06 +01:00
|
|
|
"errors"
|
|
|
|
"fmt"
|
2021-05-08 19:59:31 +01:00
|
|
|
"net/http"
|
2021-04-26 10:53:06 +01:00
|
|
|
"strings"
|
2021-05-08 19:59:31 +01:00
|
|
|
"sync"
|
2021-04-26 10:53:06 +01:00
|
|
|
|
2021-05-04 23:03:19 +01:00
|
|
|
"github.com/go-openapi/strfmt"
|
2021-04-19 23:30:27 +01:00
|
|
|
log "github.com/sirupsen/logrus"
|
2021-04-26 10:53:06 +01:00
|
|
|
"goauthentik.io/outpost/pkg/client/outposts"
|
2021-04-19 23:30:27 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
func (ls *LDAPServer) Refresh() error {
|
2021-04-26 10:53:06 +01:00
|
|
|
outposts, err := ls.ac.Client.Outposts.OutpostsLdapList(outposts.NewOutpostsLdapListParams(), ls.ac.Auth)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if len(outposts.Payload.Results) < 1 {
|
|
|
|
return errors.New("no ldap provider defined")
|
|
|
|
}
|
|
|
|
providers := make([]*ProviderInstance, len(outposts.Payload.Results))
|
|
|
|
for idx, provider := range outposts.Payload.Results {
|
2021-05-07 10:46:26 +01:00
|
|
|
userDN := strings.ToLower(fmt.Sprintf("ou=users,%s", provider.BaseDn))
|
|
|
|
groupDN := strings.ToLower(fmt.Sprintf("ou=groups,%s", provider.BaseDn))
|
2021-04-26 10:53:06 +01:00
|
|
|
providers[idx] = &ProviderInstance{
|
2021-05-04 23:03:19 +01:00
|
|
|
BaseDN: provider.BaseDn,
|
|
|
|
GroupDN: groupDN,
|
|
|
|
UserDN: userDN,
|
|
|
|
appSlug: *provider.ApplicationSlug,
|
|
|
|
flowSlug: *provider.BindFlowSlug,
|
|
|
|
searchAllowedGroups: []*strfmt.UUID{provider.SearchGroup},
|
2021-05-08 19:59:31 +01:00
|
|
|
boundUsersMutex: sync.RWMutex{},
|
|
|
|
boundUsers: make(map[string]UserFlags),
|
2021-05-04 23:03:19 +01:00
|
|
|
s: ls,
|
|
|
|
log: log.WithField("logger", "authentik.outpost.ldap").WithField("provider", provider.Name),
|
2021-04-26 10:53:06 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
ls.providers = providers
|
|
|
|
ls.log.Info("Update providers")
|
2021-04-19 23:30:27 +01:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (ls *LDAPServer) Start() error {
|
2021-04-26 13:46:29 +01:00
|
|
|
listen := "0.0.0.0:3389"
|
2021-04-19 23:30:27 +01:00
|
|
|
log.Debugf("Listening on %s", listen)
|
|
|
|
err := ls.s.ListenAndServe(listen)
|
|
|
|
if err != nil {
|
|
|
|
ls.log.Errorf("LDAP Server Failed: %s", err.Error())
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
2021-05-08 19:59:31 +01:00
|
|
|
|
|
|
|
type transport struct {
|
|
|
|
headers map[string]string
|
|
|
|
}
|
|
|
|
|
|
|
|
func (t *transport) RoundTrip(req *http.Request) (*http.Response, error) {
|
|
|
|
for key, value := range t.headers {
|
|
|
|
req.Header.Add(key, value)
|
|
|
|
}
|
|
|
|
return http.DefaultTransport.RoundTrip(req)
|
|
|
|
}
|
|
|
|
func newTransport(headers map[string]string) *transport {
|
|
|
|
return &transport{headers}
|
|
|
|
}
|