forked from mystiq/dex
4d970d5fc4
Authentication is performed by binding to the configured LDAP server using the user supplied credentials. Successfull bind equals authenticated user. Optionally the connector can be configured to search before authentication. The entryDN found will be used to bind to the LDAP server. This feature must be enabled to get supplementary information from the directory (ID, Name, Email). This feature can also be used to limit access to the service. Example use case: Allow your users to log in with e-mail address instead of the identification string in your DNs (typically username). To make re-use of HTTP form handling code from the Local connector possible: - Implemented IdentityProvider interface - Moved the re-used functions to login_local.go Fixes #119
97 lines
2.4 KiB
Go
97 lines
2.4 KiB
Go
package connector
|
|
|
|
import (
|
|
"fmt"
|
|
"html/template"
|
|
"net/http"
|
|
"net/url"
|
|
|
|
phttp "github.com/coreos/dex/pkg/http"
|
|
"github.com/coreos/dex/pkg/log"
|
|
"github.com/coreos/go-oidc/oauth2"
|
|
"github.com/coreos/go-oidc/oidc"
|
|
)
|
|
|
|
func redirectPostError(w http.ResponseWriter, errorURL url.URL, q url.Values) {
|
|
redirectURL := phttp.MergeQuery(errorURL, q)
|
|
w.Header().Set("Location", redirectURL.String())
|
|
w.WriteHeader(http.StatusSeeOther)
|
|
}
|
|
|
|
func handleLoginFunc(lf oidc.LoginFunc, tpl *template.Template, idp IdentityProvider, localErrorPath string, errorURL url.URL) http.HandlerFunc {
|
|
handleGET := func(w http.ResponseWriter, r *http.Request, errMsg string) {
|
|
q := r.URL.Query()
|
|
sessionKey := q.Get("session_key")
|
|
|
|
p := &Page{PostURL: r.URL.String(), Name: "Local", SessionKey: sessionKey}
|
|
if errMsg != "" {
|
|
p.Error = true
|
|
p.Message = errMsg
|
|
}
|
|
|
|
if err := tpl.Execute(w, p); err != nil {
|
|
phttp.WriteError(w, http.StatusInternalServerError, err.Error())
|
|
}
|
|
}
|
|
|
|
handlePOST := func(w http.ResponseWriter, r *http.Request) {
|
|
if err := r.ParseForm(); err != nil {
|
|
msg := fmt.Sprintf("unable to parse form from body: %v", err)
|
|
phttp.WriteError(w, http.StatusBadRequest, msg)
|
|
return
|
|
}
|
|
|
|
userid := r.PostForm.Get("userid")
|
|
if userid == "" {
|
|
handleGET(w, r, "missing email address")
|
|
return
|
|
}
|
|
|
|
password := r.PostForm.Get("password")
|
|
if password == "" {
|
|
handleGET(w, r, "missing password")
|
|
return
|
|
}
|
|
|
|
ident, err := idp.Identity(userid, password)
|
|
log.Errorf("IDENTITY: err: %v", err)
|
|
|
|
if ident == nil || err != nil {
|
|
handleGET(w, r, "invalid login")
|
|
return
|
|
}
|
|
|
|
q := r.URL.Query()
|
|
sessionKey := r.FormValue("session_key")
|
|
if sessionKey == "" {
|
|
q.Set("error", oauth2.ErrorInvalidRequest)
|
|
q.Set("error_description", "missing session_key")
|
|
redirectPostError(w, errorURL, q)
|
|
return
|
|
}
|
|
|
|
redirectURL, err := lf(*ident, sessionKey)
|
|
if err != nil {
|
|
log.Errorf("Unable to log in %#v: %v", *ident, err)
|
|
q.Set("error", oauth2.ErrorAccessDenied)
|
|
q.Set("error_description", "login failed")
|
|
redirectPostError(w, errorURL, q)
|
|
return
|
|
}
|
|
|
|
w.Header().Set("Location", redirectURL)
|
|
w.WriteHeader(http.StatusFound)
|
|
}
|
|
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
|
switch r.Method {
|
|
case "POST":
|
|
handlePOST(w, r)
|
|
case "GET":
|
|
handleGET(w, r, "")
|
|
default:
|
|
w.Header().Set("Allow", "GET, POST")
|
|
phttp.WriteError(w, http.StatusMethodNotAllowed, "GET and POST only acceptable methods")
|
|
}
|
|
}
|
|
}
|