LDAP protocol/host/port configuration by URL; make BASE_DN optional

PHP ldap_connect($host, $port) function signature is deprecated: https://www.php.net/manual/en/function.ldap-connect.php

Querying an AD Global Catalog across an entire forest requires an empty base DN
This commit is contained in:
operateur404
2021-02-04 03:49:50 +01:00
committed by GitHub
parent 08bc8975d8
commit d382e2e4be
4 changed files with 9 additions and 19 deletions

View File

@@ -70,8 +70,8 @@ class Client
* *
* @access public * @access public
* *
* @param string $server LDAP server hostname or IP * @param string $server LDAP server URI (ldap[s]://hostname:port) or hostname (deprecated)
* @param int $port LDAP port * @param int $port LDAP port (deprecated)
* @param bool $tls Start TLS * @param bool $tls Start TLS
* @param bool $verify Skip SSL certificate verification * @param bool $verify Skip SSL certificate verification
* @return Client * @return Client
@@ -88,7 +88,12 @@ class Client
putenv('LDAPTLS_REQCERT=never'); putenv('LDAPTLS_REQCERT=never');
} }
$this->ldap = @ldap_connect($server, $port); if (filter_var($server, FILTER_VALIDATE_URL) !== false) {
$this->ldap = @ldap_connect($server);
}
else {
$this->ldap = @ldap_connect($server, $port);
}
if ($this->ldap === false) { if ($this->ldap === false) {
throw new ConnectionException('Malformed LDAP server hostname or LDAP server port'); throw new ConnectionException('Malformed LDAP server hostname or LDAP server port');

View File

@@ -342,10 +342,6 @@ class User
*/ */
public function getBaseDn() public function getBaseDn()
{ {
if (! LDAP_USER_BASE_DN) {
throw new LogicException('LDAP user base DN empty, check the parameter LDAP_USER_BASE_DN');
}
return LDAP_USER_BASE_DN; return LDAP_USER_BASE_DN;
} }

View File

@@ -102,12 +102,9 @@ define('DB_TIMEOUT', null);
// Enable LDAP authentication (false by default) // Enable LDAP authentication (false by default)
define('LDAP_AUTH', false); define('LDAP_AUTH', false);
// LDAP server hostname // LDAP server protocol, hostname and port URL (ldap[s]://hostname:port)
define('LDAP_SERVER', ''); define('LDAP_SERVER', '');
// LDAP server port (389 by default)
define('LDAP_PORT', 389);
// By default, require certificate to be verified for ldaps:// style URL. Set to false to skip the verification // By default, require certificate to be verified for ldaps:// style URL. Set to false to skip the verification
define('LDAP_SSL_VERIFY', true); define('LDAP_SSL_VERIFY', true);

View File

@@ -785,14 +785,6 @@ class LdapUserTest extends Base
$this->assertEquals(array('is_ldap_user' => 1), $user->getExtraAttributes()); $this->assertEquals(array('is_ldap_user' => 1), $user->getExtraAttributes());
} }
public function testGetBaseDnNotConfigured()
{
$this->expectException('\LogicException');
$user = new User($this->query);
$user->getBaseDn();
}
public function testGetLdapUserPatternNotConfigured() public function testGetLdapUserPatternNotConfigured()
{ {
$this->expectException('\LogicException'); $this->expectException('\LogicException');