LDAP protocol/host/port configuration by URL; make BASE_DN optional
PHP ldap_connect($host, $port) function signature is deprecated: https://www.php.net/manual/en/function.ldap-connect.php Querying an AD Global Catalog across an entire forest requires an empty base DN
This commit is contained in:
@@ -70,8 +70,8 @@ class Client
|
|||||||
*
|
*
|
||||||
* @access public
|
* @access public
|
||||||
*
|
*
|
||||||
* @param string $server LDAP server hostname or IP
|
* @param string $server LDAP server URI (ldap[s]://hostname:port) or hostname (deprecated)
|
||||||
* @param int $port LDAP port
|
* @param int $port LDAP port (deprecated)
|
||||||
* @param bool $tls Start TLS
|
* @param bool $tls Start TLS
|
||||||
* @param bool $verify Skip SSL certificate verification
|
* @param bool $verify Skip SSL certificate verification
|
||||||
* @return Client
|
* @return Client
|
||||||
@@ -88,7 +88,12 @@ class Client
|
|||||||
putenv('LDAPTLS_REQCERT=never');
|
putenv('LDAPTLS_REQCERT=never');
|
||||||
}
|
}
|
||||||
|
|
||||||
$this->ldap = @ldap_connect($server, $port);
|
if (filter_var($server, FILTER_VALIDATE_URL) !== false) {
|
||||||
|
$this->ldap = @ldap_connect($server);
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
$this->ldap = @ldap_connect($server, $port);
|
||||||
|
}
|
||||||
|
|
||||||
if ($this->ldap === false) {
|
if ($this->ldap === false) {
|
||||||
throw new ConnectionException('Malformed LDAP server hostname or LDAP server port');
|
throw new ConnectionException('Malformed LDAP server hostname or LDAP server port');
|
||||||
|
|||||||
@@ -342,10 +342,6 @@ class User
|
|||||||
*/
|
*/
|
||||||
public function getBaseDn()
|
public function getBaseDn()
|
||||||
{
|
{
|
||||||
if (! LDAP_USER_BASE_DN) {
|
|
||||||
throw new LogicException('LDAP user base DN empty, check the parameter LDAP_USER_BASE_DN');
|
|
||||||
}
|
|
||||||
|
|
||||||
return LDAP_USER_BASE_DN;
|
return LDAP_USER_BASE_DN;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -102,12 +102,9 @@ define('DB_TIMEOUT', null);
|
|||||||
// Enable LDAP authentication (false by default)
|
// Enable LDAP authentication (false by default)
|
||||||
define('LDAP_AUTH', false);
|
define('LDAP_AUTH', false);
|
||||||
|
|
||||||
// LDAP server hostname
|
// LDAP server protocol, hostname and port URL (ldap[s]://hostname:port)
|
||||||
define('LDAP_SERVER', '');
|
define('LDAP_SERVER', '');
|
||||||
|
|
||||||
// LDAP server port (389 by default)
|
|
||||||
define('LDAP_PORT', 389);
|
|
||||||
|
|
||||||
// By default, require certificate to be verified for ldaps:// style URL. Set to false to skip the verification
|
// By default, require certificate to be verified for ldaps:// style URL. Set to false to skip the verification
|
||||||
define('LDAP_SSL_VERIFY', true);
|
define('LDAP_SSL_VERIFY', true);
|
||||||
|
|
||||||
|
|||||||
@@ -785,14 +785,6 @@ class LdapUserTest extends Base
|
|||||||
$this->assertEquals(array('is_ldap_user' => 1), $user->getExtraAttributes());
|
$this->assertEquals(array('is_ldap_user' => 1), $user->getExtraAttributes());
|
||||||
}
|
}
|
||||||
|
|
||||||
public function testGetBaseDnNotConfigured()
|
|
||||||
{
|
|
||||||
$this->expectException('\LogicException');
|
|
||||||
|
|
||||||
$user = new User($this->query);
|
|
||||||
$user->getBaseDn();
|
|
||||||
}
|
|
||||||
|
|
||||||
public function testGetLdapUserPatternNotConfigured()
|
public function testGetLdapUserPatternNotConfigured()
|
||||||
{
|
{
|
||||||
$this->expectException('\LogicException');
|
$this->expectException('\LogicException');
|
||||||
|
|||||||
Reference in New Issue
Block a user