|
4 | 4 | from distutils.util import strtobool |
5 | 5 | import os.path |
6 | 6 | import tempfile |
| 7 | +import ldap |
| 8 | + |
| 9 | +from django_auth_ldap.config import LDAPSearch, GroupOfNamesType |
7 | 10 |
|
8 | 11 | # A boolean that turns on/off debug mode. |
9 | 12 | # https://docs.djangoproject.com/en/1.9/ref/settings/#debug |
|
106 | 109 | ) |
107 | 110 |
|
108 | 111 | AUTHENTICATION_BACKENDS = ( |
| 112 | + "django_auth_ldap.backend.LDAPBackend", |
109 | 113 | "django.contrib.auth.backends.ModelBackend", |
110 | 114 | "guardian.backends.ObjectPermissionBackend", |
111 | 115 | ) |
|
339 | 343 | } |
340 | 344 |
|
341 | 345 | APP_URL_REGEX = '[a-z0-9-]+' |
| 346 | + |
| 347 | +# LDAP settings taken from environment variables. |
| 348 | +LDAP_ENDPOINT = os.environ.get('LDAP_ENDPOINT', '') |
| 349 | +LDAP_BIND_DN = os.environ.get('LDAP_BIND_DN', '') |
| 350 | +LDAP_BIND_PASSWORD = os.environ.get('LDAP_BIND_PASSWORD', '') |
| 351 | +LDAP_USER_BASEDN = os.environ.get('LDAP_USER_BASEDN', '') |
| 352 | +LDAP_USER_FILTER = os.environ.get('LDAP_USER_FILTER', 'username') |
| 353 | +LDAP_GROUP_BASEDN = os.environ.get('LDAP_GROUP_BASEDN', '') |
| 354 | +LDAP_GROUP_FILTER = os.environ.get('LDAP_GROUP_FILTER', '') |
| 355 | + |
| 356 | +# Django LDAP backend configuration. |
| 357 | +# See https://pythonhosted.org/django-auth-ldap/reference.html |
| 358 | +# for variables' details. |
| 359 | +# In order to debug LDAP configuration it is possible to enable |
| 360 | +# verbose logging from auth-ldap plugin: |
| 361 | +# https://pythonhosted.org/django-auth-ldap/logging.html |
| 362 | + |
| 363 | +AUTH_LDAP_SERVER_URI = LDAP_ENDPOINT |
| 364 | +AUTH_LDAP_BIND_DN = LDAP_BIND_DN |
| 365 | +AUTH_LDAP_BIND_PASSWORD = LDAP_BIND_PASSWORD |
| 366 | +AUTH_LDAP_USER_SEARCH = LDAPSearch( |
| 367 | + base_dn=LDAP_USER_BASEDN, |
| 368 | + scope=ldap.SCOPE_SUBTREE, |
| 369 | + filterstr="(%s=%%(user)s)" % LDAP_USER_FILTER |
| 370 | +) |
| 371 | +AUTH_LDAP_GROUP_SEARCH = LDAPSearch( |
| 372 | + base_dn=LDAP_GROUP_BASEDN, |
| 373 | + scope=ldap.SCOPE_SUBTREE, |
| 374 | + filterstr="(%s)" % LDAP_GROUP_FILTER |
| 375 | +) |
| 376 | +AUTH_LDAP_GROUP_TYPE = GroupOfNamesType() |
| 377 | +AUTH_LDAP_USER_ATTR_MAP = { |
| 378 | + "first_name": "givenName", |
| 379 | + "last_name": "sn", |
| 380 | + "email": "mail", |
| 381 | + "username": LDAP_USER_FILTER, |
| 382 | +} |
| 383 | +AUTH_LDAP_GLOBAL_OPTIONS = { |
| 384 | + ldap.OPT_X_TLS_REQUIRE_CERT: False, |
| 385 | + ldap.OPT_REFERRALS: False |
| 386 | +} |
| 387 | +AUTH_LDAP_ALWAYS_UPDATE_USER = True |
| 388 | +AUTH_LDAP_MIRROR_GROUPS = True |
| 389 | +AUTH_LDAP_FIND_GROUP_PERMS = True |
| 390 | +AUTH_LDAP_CACHE_GROUPS = False |
0 commit comments