-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathldap.go
More file actions
94 lines (75 loc) · 1.74 KB
/
ldap.go
File metadata and controls
94 lines (75 loc) · 1.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
/*
* Auth : acer
* Desc : ldap
* Time : 2020/7/10 9:58
*/
package services
import (
"fmt"
"bfimpl/services/log"
"github.com/go-ldap/ldap"
)
type LDAPConfig struct {
Addr string
BindUserName string
BindPassword string
SearchDN string
}
type LDAPService struct {
Conn *ldap.Conn
Config LDAPConfig
}
func NewLDAPService(config LDAPConfig) (*LDAPService, error) {
conn, err := ldap.Dial("tcp", config.Addr)
if err != nil {
return nil, err
}
err = conn.Bind(config.BindUserName, config.BindPassword)
if err != nil {
return nil, err
}
return &LDAPService{Conn: conn, Config: config}, nil
}
func LdapService() *LDAPService {
config := LDAPConfig{
Addr: "172.16.9.230:389",
BindUserName: "CN=测试,OU=BF-IT,OU=BF-Users,DC=broadfun,DC=cn",
BindPassword: "123456q@",
SearchDN: "OU=BF-Users,DC=broadfun,DC=cn",
}
s, err := NewLDAPService(config)
if err != nil {
log.GLogger.Error(err.Error())
return nil
}
return s
}
// Login 登录
func (l *LDAPService) Login(userName, password string) (bool, error) {
defer l.Conn.Close()
searchRequest := ldap.NewSearchRequest(
l.Config.SearchDN,
ldap.ScopeWholeSubtree, ldap.NeverDerefAliases, 0, 0, false,
fmt.Sprintf("(&(objectClass=organizationalPerson)(sAMAccountName=%s))", userName),
[]string{"dn"},
nil,
)
sr, err := l.Conn.Search(searchRequest)
if err != nil {
return false, err
}
if len(sr.Entries) != 1 {
return false, fmt.Errorf("user does not exist or too many entries return")
}
userDN := sr.Entries[0].DN
fmt.Println(userDN)
err = l.Conn.Bind(userDN, password)
if err != nil {
return false, err
}
//err = l.Conn.Bind(l.Config.BindUserName, l.Config.BindPassword)
//if err != nil {
// return false, nil
//}
return true, nil
}