feat: implement LDAP auth fallback in authenticate_user
This commit is contained in:
@@ -21,22 +21,41 @@ def get_user(db: Session, username: str) -> Optional[User]:
|
||||
return db.query(User).filter(User.username == username).first()
|
||||
|
||||
|
||||
def upsert_ldap_user(db: Session, attrs: dict) -> User:
|
||||
"""Create or update a User from LDAP attribute dict, commit and return."""
|
||||
from app.modules.auth.ldap import _upsert_from_attrs
|
||||
_upsert_from_attrs(db, attrs)
|
||||
db.commit()
|
||||
return get_user(db, attrs["username"])
|
||||
|
||||
|
||||
def authenticate_user(
|
||||
db: Session, username: str, password: str, ldap_enabled: bool
|
||||
) -> Optional[User]:
|
||||
user = get_user(db, username)
|
||||
if user is None or not user.is_active:
|
||||
|
||||
# Explicitly deactivated users are always blocked
|
||||
if user is not None and not user.is_active:
|
||||
return None
|
||||
|
||||
local_ok = user.pw_hash is not None and verify_password(password, user.pw_hash)
|
||||
if local_ok:
|
||||
# Local auth
|
||||
if user is not None and user.pw_hash is not None:
|
||||
if verify_password(password, user.pw_hash):
|
||||
_touch_last_login(db, user)
|
||||
return user
|
||||
|
||||
# LDAP auth
|
||||
if ldap_enabled:
|
||||
from app.core.config import get_settings
|
||||
from app.modules.auth.ldap import ldap_authenticate
|
||||
s = get_settings()
|
||||
attrs = ldap_authenticate(username, password, s.LDAP_SERVER, s.LDAP_DOMAIN)
|
||||
if attrs is None:
|
||||
return None
|
||||
user = upsert_ldap_user(db, attrs)
|
||||
_touch_last_login(db, user)
|
||||
return user
|
||||
|
||||
if ldap_enabled:
|
||||
# LDAP auth implemented in Part 2
|
||||
pass
|
||||
|
||||
return None
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user