Add an admin-only LDAP configuration UI with an enable toggle and full sign-in integration. Backend: - ldapSettings model + migration (single-row config) - GET/PUT/test routes under /ldap (admin-gated; bind password masked) - shared ldapClient with RFC 4515 filter escaping and empty-password guard - signin tries local auth first, then LDAP when enabled (find-or-create local user) so the bootstrap admin is never locked out Frontend: - LDAP settings page (Switch + form + test connection) under /admin/ldap - AdminNav tabs between user management and LDAP - ldapControl util, types, and Ldap i18n namespace for all 6 locales Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
62 lines
1.3 KiB
JavaScript
62 lines
1.3 KiB
JavaScript
export async function up(queryInterface, Sequelize) {
|
|
await queryInterface.createTable('ldapSettings', {
|
|
id: {
|
|
type: Sequelize.INTEGER,
|
|
primaryKey: true,
|
|
autoIncrement: true,
|
|
},
|
|
enabled: {
|
|
type: Sequelize.BOOLEAN,
|
|
allowNull: false,
|
|
defaultValue: false,
|
|
},
|
|
url: {
|
|
type: Sequelize.STRING,
|
|
allowNull: false,
|
|
defaultValue: '',
|
|
},
|
|
bindDn: {
|
|
type: Sequelize.STRING,
|
|
allowNull: false,
|
|
defaultValue: '',
|
|
},
|
|
bindCredentials: {
|
|
type: Sequelize.STRING,
|
|
allowNull: false,
|
|
defaultValue: '',
|
|
},
|
|
searchBase: {
|
|
type: Sequelize.STRING,
|
|
allowNull: false,
|
|
defaultValue: '',
|
|
},
|
|
searchFilter: {
|
|
type: Sequelize.STRING,
|
|
allowNull: false,
|
|
defaultValue: '(mail={{username}})',
|
|
},
|
|
emailAttribute: {
|
|
type: Sequelize.STRING,
|
|
allowNull: false,
|
|
defaultValue: 'mail',
|
|
},
|
|
usernameAttribute: {
|
|
type: Sequelize.STRING,
|
|
allowNull: false,
|
|
defaultValue: 'cn',
|
|
},
|
|
createdAt: {
|
|
type: Sequelize.DATE,
|
|
allowNull: false,
|
|
},
|
|
updatedAt: {
|
|
type: Sequelize.DATE,
|
|
allowNull: false,
|
|
},
|
|
});
|
|
}
|
|
|
|
export async function down(queryInterface) {
|
|
await queryInterface.dropTable('ldapSettings');
|
|
}
|