mentorenwahl/docker/backend/src/backend/ldap.cr
Dominic Grimm 3a19d1d8db
All checks were successful
continuous-integration/drone/pr Build is passing
continuous-integration/drone/push Build is passing
Fixed file license headers
2022-03-07 14:06:02 +01:00

63 lines
1.8 KiB
Crystal

# Mentorenwahl: A fullstack application for assigning mentors to students based on their whishes.
# Copyright (C) 2022 Dominic Grimm
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation, either version 3 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <https://www.gnu.org/licenses/>.
require "ldap"
require "socket"
require "ldap_escape"
require "pool/connection"
require "./ldap/*"
module Backend
# Provides LDAP utility functions
module Ldap
extend self
CLIENT = ConnectionPool.new do
create_client
end
# Creates a new LDAP connection
private def create_client : LDAP::Client
LDAP::Client.new(TCPSocket.new(Backend.config.ldap.host, Backend.config.ldap.port))
end
# Queries the LDAP server for a user
#
# NOTE: Returns raw LDAP data
def raw_user(dn : String) : User::Raw
CLIENT.connection do |client|
client
.authenticate(Backend.config.ldap.bind_dn, Backend.config.ldap.bind_password)
.search(base: dn)
.first
end
end
# Queries the LDAP server for a user
def user(dn : String) : User
User.from_raw(raw_user(dn))
end
# Checks if credentials are valid
def authenticate?(dn : String, password : String) : Bool
!!CLIENT.connection(&.authenticate(dn, password))
rescue LDAP::Client::AuthError
false
end
end
end