mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-02 19:39:49 +02:00
Use SecurityProtocol to replace UseSSL in LDAP config
Initially proposed by #2376 and fixes #3068 as well.
This commit is contained in:
1 parent
326c982660
commit
401bf944ef
15 files changed
+228
-67
No files matched your search
@@ -3,7 +3,7 @@ Gogs - Go Git Service [
|

|
||||||
|
|
||||||
##### Current tip version: 0.9.36 (see [Releases](https://github.com/gogits/gogs/releases) for binary versions)
|
##### Current tip version: 0.9.37 (see [Releases](https://github.com/gogits/gogs/releases) for binary versions)
|
||||||
|
|
||||||
| Web | UI | Preview |
|
| Web | UI | Preview |
|
||||||
|:-------------:|:-------:|:-------:|
|
|:-------------:|:-------:|:-------:|
|
||||||
|
|||||||
@@ -919,6 +919,7 @@ auths.enabled = Enabled
|
|||||||
auths.updated = Updated
|
auths.updated = Updated
|
||||||
auths.auth_type = Authentication Type
|
auths.auth_type = Authentication Type
|
||||||
auths.auth_name = Authentication Name
|
auths.auth_name = Authentication Name
|
||||||
|
auths.security_protocol = Security Protocol
|
||||||
auths.domain = Domain
|
auths.domain = Domain
|
||||||
auths.host = Host
|
auths.host = Host
|
||||||
auths.port = Port
|
auths.port = Port
|
||||||
|
|||||||
Generated
+1
-1
@@ -6,7 +6,7 @@ imports:
|
|||||||
subpackages:
|
subpackages:
|
||||||
- memcache
|
- memcache
|
||||||
- name: github.com/codegangsta/cli
|
- name: github.com/codegangsta/cli
|
||||||
version: e5bef42c62aa7d25aba4880dc02b7624f01e9e19
|
version: 1efa31f08b9333f1bd4882d61f9d668a70cd902e
|
||||||
- name: github.com/go-macaron/binding
|
- name: github.com/go-macaron/binding
|
||||||
version: bd00823a7e9aa00cb3b1738fde244573ba7cce2c
|
version: bd00823a7e9aa00cb3b1738fde244573ba7cce2c
|
||||||
- name: github.com/go-macaron/cache
|
- name: github.com/go-macaron/cache
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ import (
|
|||||||
"github.com/gogits/gogs/modules/setting"
|
"github.com/gogits/gogs/modules/setting"
|
||||||
)
|
)
|
||||||
|
|
||||||
const APP_VER = "0.9.36.0704"
|
const APP_VER = "0.9.37.0708"
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
runtime.GOMAXPROCS(runtime.NumCPU())
|
runtime.GOMAXPROCS(runtime.NumCPU())
|
||||||
|
|||||||
+22
-6
@@ -23,6 +23,11 @@ import (
|
|||||||
"github.com/gogits/gogs/modules/log"
|
"github.com/gogits/gogs/modules/log"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
var (
|
||||||
|
ErrAuthenticationAlreadyExist = errors.New("Authentication already exist")
|
||||||
|
ErrAuthenticationUserUsed = errors.New("Authentication has been used by some users")
|
||||||
|
)
|
||||||
|
|
||||||
type LoginType int
|
type LoginType int
|
||||||
|
|
||||||
// Note: new type must be added at the end of list to maintain compatibility.
|
// Note: new type must be added at the end of list to maintain compatibility.
|
||||||
@@ -35,11 +40,6 @@ const (
|
|||||||
LOGIN_DLDAP // 5
|
LOGIN_DLDAP // 5
|
||||||
)
|
)
|
||||||
|
|
||||||
var (
|
|
||||||
ErrAuthenticationAlreadyExist = errors.New("Authentication already exist")
|
|
||||||
ErrAuthenticationUserUsed = errors.New("Authentication has been used by some users")
|
|
||||||
)
|
|
||||||
|
|
||||||
var LoginNames = map[LoginType]string{
|
var LoginNames = map[LoginType]string{
|
||||||
LOGIN_LDAP: "LDAP (via BindDN)",
|
LOGIN_LDAP: "LDAP (via BindDN)",
|
||||||
LOGIN_DLDAP: "LDAP (simple auth)", // Via direct bind
|
LOGIN_DLDAP: "LDAP (simple auth)", // Via direct bind
|
||||||
@@ -47,6 +47,12 @@ var LoginNames = map[LoginType]string{
|
|||||||
LOGIN_PAM: "PAM",
|
LOGIN_PAM: "PAM",
|
||||||
}
|
}
|
||||||
|
|
||||||
|
var SecurityProtocolNames = map[ldap.SecurityProtocol]string{
|
||||||
|
ldap.SECURITY_PROTOCOL_UNENCRYPTED: "Unencrypted",
|
||||||
|
ldap.SECURITY_PROTOCOL_LDAPS: "LDAPS",
|
||||||
|
ldap.SECURITY_PROTOCOL_START_TLS: "StartTLS",
|
||||||
|
}
|
||||||
|
|
||||||
// Ensure structs implemented interface.
|
// Ensure structs implemented interface.
|
||||||
var (
|
var (
|
||||||
_ core.Conversion = &LDAPConfig{}
|
_ core.Conversion = &LDAPConfig{}
|
||||||
@@ -66,6 +72,10 @@ func (cfg *LDAPConfig) ToDB() ([]byte, error) {
|
|||||||
return json.Marshal(cfg)
|
return json.Marshal(cfg)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (cfg *LDAPConfig) SecurityProtocolName() string {
|
||||||
|
return SecurityProtocolNames[cfg.SecurityProtocol]
|
||||||
|
}
|
||||||
|
|
||||||
type SMTPConfig struct {
|
type SMTPConfig struct {
|
||||||
Auth string
|
Auth string
|
||||||
Host string
|
Host string
|
||||||
@@ -173,10 +183,16 @@ func (source *LoginSource) IsPAM() bool {
|
|||||||
return source.Type == LOGIN_PAM
|
return source.Type == LOGIN_PAM
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (source *LoginSource) HasTLS() bool {
|
||||||
|
return ((source.IsLDAP() || source.IsDLDAP()) &&
|
||||||
|
source.LDAP().SecurityProtocol > ldap.SECURITY_PROTOCOL_UNENCRYPTED) ||
|
||||||
|
source.IsSMTP()
|
||||||
|
}
|
||||||
|
|
||||||
func (source *LoginSource) UseTLS() bool {
|
func (source *LoginSource) UseTLS() bool {
|
||||||
switch source.Type {
|
switch source.Type {
|
||||||
case LOGIN_LDAP, LOGIN_DLDAP:
|
case LOGIN_LDAP, LOGIN_DLDAP:
|
||||||
return source.LDAP().UseSSL
|
return source.LDAP().SecurityProtocol != ldap.SECURITY_PROTOCOL_UNENCRYPTED
|
||||||
case LOGIN_SMTP:
|
case LOGIN_SMTP:
|
||||||
return source.SMTP().TLS
|
return source.SMTP().TLS
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -59,14 +59,15 @@ type Version struct {
|
|||||||
// If you want to "retire" a migration, remove it from the top of the list and
|
// If you want to "retire" a migration, remove it from the top of the list and
|
||||||
// update _MIN_VER_DB accordingly
|
// update _MIN_VER_DB accordingly
|
||||||
var migrations = []Migration{
|
var migrations = []Migration{
|
||||||
NewMigration("fix locale file load panic", fixLocaleFileLoadPanic), // V4 -> V5:v0.6.0
|
NewMigration("fix locale file load panic", fixLocaleFileLoadPanic), // V4 -> V5:v0.6.0
|
||||||
NewMigration("trim action compare URL prefix", trimCommitActionAppUrlPrefix), // V5 -> V6:v0.6.3
|
NewMigration("trim action compare URL prefix", trimCommitActionAppUrlPrefix), // V5 -> V6:v0.6.3
|
||||||
NewMigration("generate issue-label from issue", issueToIssueLabel), // V6 -> V7:v0.6.4
|
NewMigration("generate issue-label from issue", issueToIssueLabel), // V6 -> V7:v0.6.4
|
||||||
NewMigration("refactor attachment table", attachmentRefactor), // V7 -> V8:v0.6.4
|
NewMigration("refactor attachment table", attachmentRefactor), // V7 -> V8:v0.6.4
|
||||||
NewMigration("rename pull request fields", renamePullRequestFields), // V8 -> V9:v0.6.16
|
NewMigration("rename pull request fields", renamePullRequestFields), // V8 -> V9:v0.6.16
|
||||||
NewMigration("clean up migrate repo info", cleanUpMigrateRepoInfo), // V9 -> V10:v0.6.20
|
NewMigration("clean up migrate repo info", cleanUpMigrateRepoInfo), // V9 -> V10:v0.6.20
|
||||||
NewMigration("generate rands and salt for organizations", generateOrgRandsAndSalt), // V10 -> V11:v0.8.5
|
NewMigration("generate rands and salt for organizations", generateOrgRandsAndSalt), // V10 -> V11:v0.8.5
|
||||||
NewMigration("convert date to unix timestamp", convertDateToUnix), // V11 -> V12:v0.9.2
|
NewMigration("convert date to unix timestamp", convertDateToUnix), // V11 -> V12:v0.9.2
|
||||||
|
NewMigration("convert LDAP UseSSL option to SecurityProtocol", ldapUseSSLToSecurityProtocol), // V12 -> V13:v0.9.37
|
||||||
}
|
}
|
||||||
|
|
||||||
// Migrate database to current version
|
// Migrate database to current version
|
||||||
@@ -580,6 +581,7 @@ type TWebhook struct {
|
|||||||
func (t *TWebhook) TableName() string { return "webhook" }
|
func (t *TWebhook) TableName() string { return "webhook" }
|
||||||
|
|
||||||
func convertDateToUnix(x *xorm.Engine) (err error) {
|
func convertDateToUnix(x *xorm.Engine) (err error) {
|
||||||
|
log.Info("This migration could take up to minutes, please be patient.")
|
||||||
type Bean struct {
|
type Bean struct {
|
||||||
ID int64 `xorm:"pk autoincr"`
|
ID int64 `xorm:"pk autoincr"`
|
||||||
Created time.Time
|
Created time.Time
|
||||||
|
|||||||
@@ -0,0 +1,52 @@
|
|||||||
|
// Copyright 2016 The Gogs Authors. All rights reserved.
|
||||||
|
// Use of this source code is governed by a MIT-style
|
||||||
|
// license that can be found in the LICENSE file.
|
||||||
|
|
||||||
|
package migrations
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/Unknwon/com"
|
||||||
|
"github.com/go-xorm/xorm"
|
||||||
|
)
|
||||||
|
|
||||||
|
func ldapUseSSLToSecurityProtocol(x *xorm.Engine) error {
|
||||||
|
results, err := x.Query("SELECT `id`,`cfg` FROM `login_source` WHERE `type` = 2 OR `type` = 5")
|
||||||
|
if err != nil {
|
||||||
|
if strings.Contains(err.Error(), "no such column") {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
return fmt.Errorf("select LDAP login sources: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
sess := x.NewSession()
|
||||||
|
defer sessionRelease(sess)
|
||||||
|
if err = sess.Begin(); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, result := range results {
|
||||||
|
cfg := map[string]interface{}{}
|
||||||
|
if err = json.Unmarshal(result["cfg"], &cfg); err != nil {
|
||||||
|
return fmt.Errorf("decode JSON config: %v", err)
|
||||||
|
}
|
||||||
|
if com.ToStr(cfg["UseSSL"]) == "true" {
|
||||||
|
cfg["SecurityProtocol"] = 1 // LDAPS
|
||||||
|
}
|
||||||
|
delete(cfg, "UseSSL")
|
||||||
|
|
||||||
|
data, err := json.Marshal(&cfg)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("encode JSON config: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if _, err = sess.Exec("UPDATE `login_source` SET `cfg`=? WHERE `id`=?",
|
||||||
|
string(data), com.StrTo(result["id"]).MustInt64()); err != nil {
|
||||||
|
return fmt.Errorf("update config column: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return sess.Commit()
|
||||||
|
}
|
||||||
@@ -31,6 +31,7 @@ type AuthenticationForm struct {
|
|||||||
SMTPHost string
|
SMTPHost string
|
||||||
SMTPPort int
|
SMTPPort int
|
||||||
AllowedDomains string
|
AllowedDomains string
|
||||||
|
SecurityProtocol int `binding:"Range(0,2)"`
|
||||||
TLS bool
|
TLS bool
|
||||||
SkipVerify bool
|
SkipVerify bool
|
||||||
PAMServiceName string
|
PAMServiceName string
|
||||||
|
|||||||
+48
-25
@@ -16,12 +16,21 @@ import (
|
|||||||
"github.com/gogits/gogs/modules/log"
|
"github.com/gogits/gogs/modules/log"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
type SecurityProtocol int
|
||||||
|
|
||||||
|
// Note: new type must be added at the end of list to maintain compatibility.
|
||||||
|
const (
|
||||||
|
SECURITY_PROTOCOL_UNENCRYPTED SecurityProtocol = iota
|
||||||
|
SECURITY_PROTOCOL_LDAPS
|
||||||
|
SECURITY_PROTOCOL_START_TLS
|
||||||
|
)
|
||||||
|
|
||||||
// Basic LDAP authentication service
|
// Basic LDAP authentication service
|
||||||
type Source struct {
|
type Source struct {
|
||||||
Name string // canonical name (ie. corporate.ad)
|
Name string // canonical name (ie. corporate.ad)
|
||||||
Host string // LDAP host
|
Host string // LDAP host
|
||||||
Port int // port number
|
Port int // port number
|
||||||
UseSSL bool // Use SSL
|
SecurityProtocol SecurityProtocol
|
||||||
SkipVerify bool
|
SkipVerify bool
|
||||||
BindDN string // DN to bind with
|
BindDN string // DN to bind with
|
||||||
BindPassword string // Bind DN password
|
BindPassword string // Bind DN password
|
||||||
@@ -102,9 +111,46 @@ func (ls *Source) findUserDN(l *ldap.Conn, name string) (string, bool) {
|
|||||||
return userDN, true
|
return userDN, true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func dial(ls *Source) (*ldap.Conn, error) {
|
||||||
|
log.Trace("Dialing LDAP with security protocol (%v) without verifying: %v", ls.SecurityProtocol, ls.SkipVerify)
|
||||||
|
|
||||||
|
tlsCfg := &tls.Config{
|
||||||
|
ServerName: ls.Host,
|
||||||
|
InsecureSkipVerify: ls.SkipVerify,
|
||||||
|
}
|
||||||
|
if ls.SecurityProtocol == SECURITY_PROTOCOL_LDAPS {
|
||||||
|
return ldap.DialTLS("tcp", fmt.Sprintf("%s:%d", ls.Host, ls.Port), tlsCfg)
|
||||||
|
}
|
||||||
|
|
||||||
|
conn, err := ldap.Dial("tcp", fmt.Sprintf("%s:%d", ls.Host, ls.Port))
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("Dial: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if ls.SecurityProtocol == SECURITY_PROTOCOL_START_TLS {
|
||||||
|
if err = conn.StartTLS(tlsCfg); err != nil {
|
||||||
|
conn.Close()
|
||||||
|
return nil, fmt.Errorf("StartTLS: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return conn, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func bindUser(l *ldap.Conn, userDN, passwd string) error {
|
||||||
|
log.Trace("Binding with userDN: %s", userDN)
|
||||||
|
err := l.Bind(userDN, passwd)
|
||||||
|
if err != nil {
|
||||||
|
log.Debug("LDAP auth. failed for %s, reason: %v", userDN, err)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
log.Trace("Bound successfully with userDN: %s", userDN)
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
// searchEntry : search an LDAP source if an entry (name, passwd) is valid and in the specific filter
|
// searchEntry : search an LDAP source if an entry (name, passwd) is valid and in the specific filter
|
||||||
func (ls *Source) SearchEntry(name, passwd string, directBind bool) (string, string, string, string, bool, bool) {
|
func (ls *Source) SearchEntry(name, passwd string, directBind bool) (string, string, string, string, bool, bool) {
|
||||||
l, err := ldapDial(ls)
|
l, err := dial(ls)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Error(4, "LDAP Connect error, %s:%v", ls.Host, err)
|
log.Error(4, "LDAP Connect error, %s:%v", ls.Host, err)
|
||||||
ls.Enabled = false
|
ls.Enabled = false
|
||||||
@@ -197,26 +243,3 @@ func (ls *Source) SearchEntry(name, passwd string, directBind bool) (string, str
|
|||||||
|
|
||||||
return username_attr, name_attr, sn_attr, mail_attr, admin_attr, true
|
return username_attr, name_attr, sn_attr, mail_attr, admin_attr, true
|
||||||
}
|
}
|
||||||
|
|
||||||
func bindUser(l *ldap.Conn, userDN, passwd string) error {
|
|
||||||
log.Trace("Binding with userDN: %s", userDN)
|
|
||||||
err := l.Bind(userDN, passwd)
|
|
||||||
if err != nil {
|
|
||||||
log.Debug("LDAP auth. failed for %s, reason: %v", userDN, err)
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
log.Trace("Bound successfully with userDN: %s", userDN)
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
func ldapDial(ls *Source) (*ldap.Conn, error) {
|
|
||||||
if ls.UseSSL {
|
|
||||||
log.Debug("Using TLS for LDAP without verifying: %v", ls.SkipVerify)
|
|
||||||
return ldap.DialTLS("tcp", fmt.Sprintf("%s:%d", ls.Host, ls.Port), &tls.Config{
|
|
||||||
ServerName: ls.Host,
|
|
||||||
InsecureSkipVerify: ls.SkipVerify,
|
|
||||||
})
|
|
||||||
} else {
|
|
||||||
return ldap.Dial("tcp", fmt.Sprintf("%s:%d", ls.Host, ls.Port))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -4346,7 +4346,7 @@ func confLocaleLocale_deDeIni() (*asset, error) {
|
|||||||
return a, nil
|
return a, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var _confLocaleLocale_enUsIni = []byte("\x1f\x8b\x08\x00\x00\x09\x6e\x88\x00\xff\xac\xbd\xeb\x72\xdc\x48\xae\x27\xfe\x9d\x4f\xc1\xf6\x84\xc3\x76\x84\x54\x1d\xdd\x7d\xfe\xff\xdd\xe8\x68\x77\xaf\x2c\xb5\x2f\xe7\x58\x96\x8e\x24\xf7\xec\xac\xc3\xc1\x66\x15\xa9\x2a\x8e\xab\xc8\x1a\x92\x25\x59\x33\x31\x6f\xb0\x0f\xb0\xcf\xb7\x4f\xb2\xc0\x0f\x40\x5e\x48\x96\x64\xf7\x1c\x7f\xb0\x58\x99\xc8\x1b\x12\x89\x04\x90\x48\x64\xbe\xdd\x66\x45\xd9\x2d\xd2\xe7\xe9\x51\xba\xcd\xab\x7a\x5d\x76\x5d\xda\x95\xeb\xeb\xc3\x55\xd3\xf5\x65\x91\xbe\xaa\x7a\xfa\xdd\xde\x54\x8b\x32\x49\x56\xcd\xa6\x24\xd0\xd7\xf4\x27\x29\xf2\x6e\x35\x6f\xf2\xb6\xa0\x84\x13\xfb\x4e\xca\xcf\xdb\x75\xd3\x32\xd0\xaf\xf2\x95\xac\xca\xf5\x96\xcb\xd0\x9f\xa4\xab\x96\x75\x56\xd5\xf4\xf3\x92\xbe\xd2\x37\xb5\xa4\x34\xbb\xde\x92\xce\x76\xbd\xa4\xed\xb6\x96\xf4\x7e\x9b\xb4\xe5\xb2\xa2\xde\xb4\x94\x74\xa1\x9f\xc9\x6d\x39\xef\xaa\x9e\x5b\xfa\xb3\x7c\x25\x37\x65\xdb\x55\x0d\xd7\xfe\x9b\x7c\x25\xdb\x7c\xc9\x00\xe7\xf4\x27\xe9\xcb\xcd\x76\x9d\xa3\xc0\x95\x7e\x26\xeb\xbc\x5e\xee\x04\xe6\xad\x7e\x26\x8b\xb6\xa4\xac\xac\x2e\x6f\x29\xf5\x18\x3f\x66\xb3\x59\xb2\x23\x24\x64\xdb\xb6\xb9\xae\xd6\x65\x96\xd7\x45\xb6\x91\x61\xbe\xa7\xf4\x54\xd3\x53\x4a\x4f\x39\x1d\x43\x28\x0b\x1a\x6a\x96\x77\x3a\x0e\xc2\x25\x8d\x3c\xef\x12\x54\x55\xe7\x1b\x2b\xcd\x9f\x49\xb9\xc9\xab\x35\x63\x8d\xff\x52\xbf\xbb\xee\xb6\x01\x6a\xcf\xf5\x93\x70\x90\xf5\x77\xdb\x12\x28\x38\xbc\xa2\xaf\x64\x91\x6f\xfb\xc5\x2a\xe7\x6e\xca\x57\x42\x40\xdb\x86\x70\xd1\xb4\x77\x80\xb3\x1f\x49\xd3\x2e\xf3\xba\xfa\x7b\xde\x0b\x7e\xce\x82\x9f\xc9\xa6\x6a\xdb\x86\x51\x7b\x8a\x8f\x84\x46\x9e\x71\x3d\x94\xf2\x8e\x90\x10\xd4\xc2\x39\x9b\x6a\xd9\x0a\x16\x39\xf3\x14\xbf\xb8\x16\xc9\xd3\x9a\x24\xcb\xd5\x76\xdd\xb4\x9f\x34\xf5\x25\x7f\x0e\xaa\xa4\xce\x69\x6e\xdc\xaf\xbc\xa6\xf9\xd0\xdc\x53\xfc\x88\x00\xba\x24\x2f\x36\x84\xe1\x6d\x5e\x97\x8c\xba\x23\xfe\x45\xf8\xa2\x5f\x49\xbe\x58\x34\xbb\xba\xcf\xba\xb2\xef\xab\x7a\xc9\x73\x70\x24\x49\xe9\xa5\x26\x25\x41\x9e\x4b\xbb\x6b\x76\x6e\x96\x29\xfd\x2f\xf4\x33\x3d\x97\x9f\x92\x17\x14\x42\xa6\x2b\x49\x4d\xf6\xd5\x4d\xd5\x57\xa5\x34\x66\x3f\x92\xed\x6e\xbd\x26\x7c\xfe\x6d\x57\x76\x3d\x67\x9d\xd3\x6f\xc2\x80\xfc\x4e\xaa\xae\xdb\xa1\xc4\x1b\x7c\x24\x34\xa9\xf5\x02\xc3\x39\xc6\x47\x92\x7c\xa8\xea\xae\xcf\xd7\xeb\x8f\x89\x7e\x30\xb0\x7c\x09\x9e\xfa\xaa\x47\x67\x35\x31\xbd\xec\xcb\x6d\xc7\x88\x4e\x5f\x56\x6d\xd7\x1f\xf6\x15\x91\xda\xc5\xae\x4e\x8a\x66\xf1\x89\x88\x98\x17\x24\x96\xd2\x9b\xeb\x94\xc6\xf4\x84\xc8\xb8\xdd\xd5\x35\x8d\x22\x7d\xd5\xd0\xc8\xa8\x99\xaa\x28\xd3\x13\x40\x1f\xa4\xdb\x75\x99\x77\x04\x52\xe6\x45\xfa\x53\x9e\xf6\x79\xbb\x2c\xfb\xe7\x8f\xb2\x39\x2d\x9e\x4f\x8f\xd2\x55\x5b\x5e\x3f\x7f\xf4\xb8\x7b\xf4\xf3\xab\x1d\x15\x5b\x57\x75\xd9\xfd\xf4\x6d\xfe\x73\xba\xc8\x29\x87\xc6\x7a\x97\xce\xcb\x6b\x5e\x2b\xd4\x56\x4a\x44\x5a\x2f\x79\x9d\xdc\xf5\x2b\x6e\x90\x26\x8c\x3e\xba\x94\x17\xea\x37\x09\x63\x89\x16\x72\x56\xcc\x8d\x29\xa1\x43\x48\x6e\x09\x4b\xa7\x77\x97\xff\xf9\xf6\x20\x3d\x27\xce\xb4\x6c\x4b\x7c\xd3\x7f\x54\xe2\x87\x94\x46\x7b\x55\x9d\xbc\x98\x25\x54\xd6\x10\x72\x92\xf7\xf9\x9c\xfb\xee\x26\x89\x33\x65\x0d\xb9\x3c\xac\x24\xe6\x75\xe0\x6b\x5d\x8f\xd5\xa9\x2b\x73\x72\x1d\x52\x1d\xba\x78\x5d\x1d\xef\x78\x05\x53\xba\xc3\xec\xb9\xe0\x8c\xaa\x4a\xdf\xbc\x7b\x77\x76\xf2\x22\x2d\xeb\x25\x61\x26\xbd\xad\xfa\x55\xba\xeb\xaf\xff\x7b\xb6\x2c\xeb\xb2\xcd\xd7\xd9\xa2\x62\xa4\xb4\x44\x57\x29\x61\x49\x86\x38\x4b\xba\x6e\x4d\x0c\xa6\xe0\x56\x2e\x2f\xdf\xa6\xa7\xf4\x49\x9d\xa1\xb2\xdc\x91\x7e\x95\x74\x7f\x5b\x33\xa2\x5c\x83\x57\xab\x32\x05\xcd\x02\xa8\xb9\x1e\xe2\x25\x2d\xb4\xaf\xb3\xf4\xa7\x79\xfb\x73\xd0\xbf\x7c\xde\x35\xeb\x5d\xaf\x25\x6f\x57\x65\x8d\x89\x22\x52\x6a\x7b\xe2\x56\xc6\xfb\x67\x49\xd9\xb6\x19\xf1\xcd\xfe\x8e\xa7\x47\xfb\xb2\xaf\x15\xa9\x8c\x48\xb9\x6e\x7a\x9a\xfe\x14\xe5\xa4\x8a\xaa\xbe\xc9\xd7\x55\x41\x93\xe4\x11\x19\x97\x45\x62\xd1\xd0\x7c\x73\x69\xa2\xe8\xe6\x16\x28\xa2\x05\x46\x6c\x3d\x7d\x34\x7b\x04\x3e\xfb\xe8\xf0\xd1\x2c\xa9\x9b\x4c\x98\x00\x73\xe4\xa2\xea\xf2\x39\x71\x67\xd9\x2d\x5a\x63\x76\x7f\x61\xba\x93\xae\x28\x44\x1a\x41\xf0\x9c\xf0\x0e\x04\xc6\xcf\x44\x99\x13\x9b\x06\x2f\x51\x2e\x12\x8e\xdd\x58\x8e\xa3\x0b\xe1\x3a\x2e\x61\x34\xe6\xc4\x26\xda\xa8\xf2\x68\xbb\x5d\x57\x0b\x69\xfa\x95\xe4\x79\x02\xe5\xfd\x58\x91\x12\xc2\x81\xc0\x2c\x2f\x20\x33\xea\x35\x73\xa5\x34\x62\xef\x28\xbf\x2a\x69\xc5\xad\x76\x4b\xd9\x93\xd6\xcd\xae\xf8\x06\x9b\x83\xcd\x9c\x67\xc1\xe9\x45\x43\x1d\x06\x55\x39\x00\xdf\xc4\x11\x31\x14\x16\x01\xda\x72\xd3\xf4\x8c\x38\x2d\xc6\x6c\xee\xb6\xa2\x4c\x1a\x69\x97\xdf\xd0\xe6\xd6\x37\xb2\x94\x0b\x5a\xaa\x0b\xae\x78\x96\x10\x5b\xc9\x74\x39\x11\xff\x91\x25\x65\x69\x31\xed\x02\x6a\xb3\xa3\x55\xb8\xa2\xca\x18\xf1\x2c\x87\x50\x95\x53\xfd\xc4\x90\xa8\x1e\x70\x07\x5a\xf1\x0d\xed\x99\x3c\xd1\x27\xf8\xd0\xdf\x61\xfd\xd4\xab\xfc\xfa\x9a\x7a\xd5\xd1\x6a\x7a\x9d\x2e\xd6\x0d\x2d\xc5\xf7\x17\x6f\x3b\x5e\x68\xab\x6c\xdb\xb4\x90\x3f\x28\xeb\x9c\x3e\x5d\x5a\x80\x68\x86\xa8\x77\x9b\x39\xfd\xba\x5d\x55\x8b\x95\xa0\x9d\x4b\xf0\xfa\xa0\x54\x6a\x62\xd7\xd1\x14\x1e\xa4\xb4\xb4\x68\x04\x8Line truncated
|
var _confLocaleLocale_enUsIni = []byte("\x1f\x8b\x08\x00\x00\x09\x6e\x88\x00\xff\xac\xbd\xeb\x72\xdc\x48\xae\x27\xfe\x9d\x4f\xc1\xf6\x84\xc3\x76\x84\x54\x1d\xdd\x7d\xfe\xff\xdd\xe8\x68\x77\xaf\x2c\xb5\x2f\xe7\x58\x96\x8e\x24\xf7\xec\xac\xc3\xc1\x66\x15\xa9\x2a\x8e\xab\xc8\x1a\x92\x25\x59\x33\x31\x6f\xb0\x0f\xb0\xcf\xb7\x4f\xb2\xc0\x0f\x40\x5e\x48\x96\x64\xf7\x1c\x7f\xb0\x58\x99\xc8\x1b\x12\x89\x04\x90\x48\x64\xbe\xdd\x66\x45\xd9\x2d\xd2\xe7\xe9\x51\xba\xcd\xab\x7a\x5d\x76\x5d\xda\x95\xeb\xeb\xc3\x55\xd3\xf5\x65\x91\xbe\xaa\x7a\xfa\xdd\xde\x54\x8b\x32\x49\x56\xcd\xa6\x24\xd0\xd7\xf4\x27\x29\xf2\x6e\x35\x6f\xf2\xb6\xa0\x84\x13\xfb\x4e\xca\xcf\xdb\x75\xd3\x32\xd0\xaf\xf2\x95\xac\xca\xf5\x96\xcb\xd0\x9f\xa4\xab\x96\x75\x56\xd5\xf4\xf3\x92\xbe\xd2\x37\xb5\xa4\x34\xbb\xde\x92\xce\x76\xbd\xa4\xed\xb6\x96\xf4\x7e\x9b\xb4\xe5\xb2\xa2\xde\xb4\x94\x74\xa1\x9f\xc9\x6d\x39\xef\xaa\x9e\x5b\xfa\xb3\x7c\x25\x37\x65\xdb\x55\x0d\xd7\xfe\x9b\x7c\x25\xdb\x7c\xc9\x00\xe7\xf4\x27\xe9\xcb\xcd\x76\x9d\xa3\xc0\x95\x7e\x26\xeb\xbc\x5e\xee\x04\xe6\xad\x7e\x26\x8b\xb6\xa4\xac\xac\x2e\x6f\x29\xf5\x18\x3f\x66\xb3\x59\xb2\x23\x24\x64\xdb\xb6\xb9\xae\xd6\x65\x96\xd7\x45\xb6\x91\x61\xbe\xa7\xf4\x54\xd3\x53\x4a\x4f\x39\x1d\x43\x28\x0b\x1a\x6a\x96\x77\x3a\x0e\xc2\x25\x8d\x3c\xef\x12\x54\x55\xe7\x1b\x2b\xcd\x9f\x49\xb9\xc9\xab\x35\x63\x8d\xff\x52\xbf\xbb\xee\xb6\x01\x6a\xcf\xf5\x93\x70\x90\xf5\x77\xdb\x12\x28\x38\xbc\xa2\xaf\x64\x91\x6f\xfb\xc5\x2a\xe7\x6e\xca\x57\x42\x40\xdb\x86\x70\xd1\xb4\x77\x80\xb3\x1f\x49\xd3\x2e\xf3\xba\xfa\x7b\xde\x0b\x7e\xce\x82\x9f\xc9\xa6\x6a\xdb\x86\x51\x7b\x8a\x8f\x84\x46\x9e\x71\x3d\x94\xf2\x8e\x90\x10\xd4\xc2\x39\x9b\x6a\xd9\x0a\x16\x39\xf3\x14\xbf\xb8\x16\xc9\xd3\x9a\x24\xcb\xd5\x76\xdd\xb4\x9f\x34\xf5\x25\x7f\x0e\xaa\xa4\xce\x69\x6e\xdc\xaf\xbc\xa6\xf9\xd0\xdc\x53\xfc\x88\x00\xba\x24\x2f\x36\x84\xe1\x6d\x5e\x97\x8c\xba\x23\xfe\x45\xf8\xa2\x5f\x49\xbe\x58\x34\xbb\xba\xcf\xba\xb2\xef\xab\x7a\xc9\x73\x70\x24\x49\xe9\xa5\x26\x25\x41\x9e\x4b\xbb\x6b\x76\x6e\x96\x29\xfd\x2f\xf4\x33\x3d\x97\x9f\x92\x17\x14\x42\xa6\x2b\x49\x4d\xf6\xd5\x4d\xd5\x57\xa5\x34\x66\x3f\x92\xed\x6e\xbd\x26\x7c\xfe\x6d\x57\x76\x3d\x67\x9d\xd3\x6f\xc2\x80\xfc\x4e\xaa\xae\xdb\xa1\xc4\x1b\x7c\x24\x34\xa9\xf5\x02\xc3\x39\xc6\x47\x92\x7c\xa8\xea\xae\xcf\xd7\xeb\x8f\x89\x7e\x30\xb0\x7c\x09\x9e\xfa\xaa\x47\x67\x35\x31\xbd\xec\xcb\x6d\xc7\x88\x4e\x5f\x56\x6d\xd7\x1f\xf6\x15\x91\xda\xc5\xae\x4e\x8a\x66\xf1\x89\x88\x98\x17\x24\x96\xd2\x9b\xeb\x94\xc6\xf4\x84\xc8\xb8\xdd\xd5\x35\x8d\x22\x7d\xd5\xd0\xc8\xa8\x99\xaa\x28\xd3\x13\x40\x1f\xa4\xdb\x75\x99\x77\x04\x52\xe6\x45\xfa\x53\x9e\xf6\x79\xbb\x2c\xfb\xe7\x8f\xb2\x39\x2d\x9e\x4f\x8f\xd2\x55\x5b\x5e\x3f\x7f\xf4\xb8\x7b\xf4\xf3\xab\x1d\x15\x5b\x57\x75\xd9\xfd\xf4\x6d\xfe\x73\xba\xc8\x29\x87\xc6\x7a\x97\xce\xcb\x6b\x5e\x2b\xd4\x56\x4a\x44\x5a\x2f\x79\x9d\xdc\xf5\x2b\x6e\x90\x26\x8c\x3e\xba\x94\x17\xea\x37\x09\x63\x89\x16\x72\x56\xcc\x8d\x29\xa1\x43\x48\x6e\x09\x4b\xa7\x77\x97\xff\xf9\xf6\x20\x3d\x27\xce\xb4\x6c\x4b\x7c\xd3\x7f\x54\xe2\x87\x94\x46\x7b\x55\x9d\xbc\x98\x25\x54\xd6\x10\x72\x92\xf7\xf9\x9c\xfb\xee\x26\x89\x33\x65\x0d\xb9\x3c\xac\x24\xe6\x75\xe0\x6b\x5d\x8f\xd5\xa9\x2b\x73\x72\x1d\x52\x1d\xba\x78\x5d\x1d\xef\x78\x05\x53\xba\xc3\xec\xb9\xe0\x8c\xaa\x4a\xdf\xbc\x7b\x77\x76\xf2\x22\x2d\xeb\x25\x61\x26\xbd\xad\xfa\x55\xba\xeb\xaf\xff\x7b\xb6\x2c\xeb\xb2\xcd\xd7\xd9\xa2\x62\xa4\xb4\x44\x57\x29\x61\x49\x86\x38\x4b\xba\x6e\x4d\x0c\xa6\xe0\x56\x2e\x2f\xdf\xa6\xa7\xf4\x49\x9d\xa1\xb2\xdc\x91\x7e\x95\x74\x7f\x5b\x33\xa2\x5c\x83\x57\xab\x32\x05\xcd\x02\xa8\xb9\x1e\xe2\x25\x2d\xb4\xaf\xb3\xf4\xa7\x79\xfb\x73\xd0\xbf\x7c\xde\x35\xeb\x5d\xaf\x25\x6f\x57\x65\x8d\x89\x22\x52\x6a\x7b\xe2\x56\xc6\xfb\x67\x49\xd9\xb6\x19\xf1\xcd\xfe\x8e\xa7\x47\xfb\xb2\xaf\x15\xa9\x8c\x48\xb9\x6e\x7a\x9a\xfe\x14\xe5\xa4\x8a\xaa\xbe\xc9\xd7\x55\x41\x93\xe4\x11\x19\x97\x45\x62\xd1\xd0\x7c\x73\x69\xa2\xe8\xe6\x16\x28\xa2\x05\x46\x6c\x3d\x7d\x34\x7b\x04\x3e\xfb\xe8\xf0\xd1\x2c\xa9\x9b\x4c\x98\x00\x73\xe4\xa2\xea\xf2\x39\x71\x67\xd9\x2d\x5a\x63\x76\x7f\x61\xba\x93\xae\x28\x44\x1a\x41\xf0\x9c\xf0\x0e\x04\xc6\xcf\x44\x99\x13\x9b\x06\x2f\x51\x2e\x12\x8e\xdd\x58\x8e\xa3\x0b\xe1\x3a\x2e\x61\x34\xe6\xc4\x26\xda\xa8\xf2\x68\xbb\x5d\x57\x0b\x69\xfa\x95\xe4\x79\x02\xe5\xfd\x58\x91\x12\xc2\x81\xc0\x2c\x2f\x20\x33\xea\x35\x73\xa5\x34\x62\xef\x28\xbf\x2a\x69\xc5\xad\x76\x4b\xd9\x93\xd6\xcd\xae\xf8\x06\x9b\x83\xcd\x9c\x67\xc1\xe9\x45\x43\x1d\x06\x55\x39\x00\xdf\xc4\x11\x31\x14\x16\x01\xda\x72\xd3\xf4\x8c\x38\x2d\xc6\x6c\xee\xb6\xa2\x4c\x1a\x69\x97\xdf\xd0\xe6\xd6\x37\xb2\x94\x0b\x5a\xaa\x0b\xae\x78\x96\x10\x5b\xc9\x74\x39\x11\xff\x91\x25\x65\x69\x31\xed\x02\x6a\xb3\xa3\x55\xb8\xa2\xca\x18\xf1\x2c\x87\x50\x95\x53\xfd\xc4\x90\xa8\x1e\x70\x07\x5a\xf1\x0d\xed\x99\x3c\xd1\x27\xf8\xd0\xdf\x61\xfd\xd4\xab\xfc\xfa\x9a\x7a\xd5\xd1\x6a\x7a\x9d\x2e\xd6\x0d\x2d\xc5\xf7\x17\x6f\x3b\x5e\x68\xab\x6c\xdb\xb4\x90\x3f\x28\xeb\x9c\x3e\x5d\x5a\x80\x68\x86\xa8\x77\x9b\x39\xfd\xba\x5d\x55\x8b\x95\xa0\x9d\x4b\xf0\xfa\xa0\x54\x6a\x62\xd7\xd1\x14\x1e\xa4\xb4\xb4\x68\x04\x8Line truncated
|
||||||
|
|
||||||
func confLocaleLocale_enUsIniBytes() ([]byte, error) {
|
func confLocaleLocale_enUsIniBytes() ([]byte, error) {
|
||||||
return bindataRead(
|
return bindataRead(
|
||||||
@@ -4361,7 +4361,7 @@ func confLocaleLocale_enUsIni() (*asset, error) {
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
info := bindataFileInfo{name: "conf/locale/locale_en-US.ini", size: 51370, mode: os.FileMode(420), modTime: time.Unix(1467213086, 0)}
|
info := bindataFileInfo{name: "conf/locale/locale_en-US.ini", size: 51414, mode: os.FileMode(420), modTime: time.Unix(1467844155, 0)}
|
||||||
a := &asset{bytes: bytes, info: info}
|
a := &asset{bytes: bytes, info: info}
|
||||||
return a, nil
|
return a, nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -612,6 +612,13 @@ function initAdmin() {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function onSecurityProtocolChange() {
|
||||||
|
if ($('#security_protocol').val() > 0) {
|
||||||
|
$('.has-tls').show();
|
||||||
|
} else {
|
||||||
|
$('.has-tls').hide();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// New authentication
|
// New authentication
|
||||||
if ($('.admin.new.authentication').length > 0) {
|
if ($('.admin.new.authentication').length > 0) {
|
||||||
@@ -620,6 +627,7 @@ function initAdmin() {
|
|||||||
$('.dldap').hide();
|
$('.dldap').hide();
|
||||||
$('.smtp').hide();
|
$('.smtp').hide();
|
||||||
$('.pam').hide();
|
$('.pam').hide();
|
||||||
|
$('.has-tls').hide();
|
||||||
|
|
||||||
var auth_type = $(this).val();
|
var auth_type = $(this).val();
|
||||||
switch (auth_type) {
|
switch (auth_type) {
|
||||||
@@ -628,6 +636,7 @@ function initAdmin() {
|
|||||||
break;
|
break;
|
||||||
case '3': // SMTP
|
case '3': // SMTP
|
||||||
$('.smtp').show();
|
$('.smtp').show();
|
||||||
|
$('.has-tls').show();
|
||||||
break;
|
break;
|
||||||
case '4': // PAM
|
case '4': // PAM
|
||||||
$('.pam').show();
|
$('.pam').show();
|
||||||
@@ -636,7 +645,19 @@ function initAdmin() {
|
|||||||
$('.dldap').show();
|
$('.dldap').show();
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (auth_type == '2' || auth_type == '5') {
|
||||||
|
onSecurityProtocolChange()
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
$('#security_protocol').change(onSecurityProtocolChange)
|
||||||
|
}
|
||||||
|
// Edit authentication
|
||||||
|
if ($('.admin.edit.authentication').length > 0) {
|
||||||
|
var auth_type = $('#auth_type').val();
|
||||||
|
if (auth_type == '2' || auth_type == '5') {
|
||||||
|
$('#security_protocol').change(onSecurityProtocolChange);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Notice
|
// Notice
|
||||||
|
|||||||
+35
-16
@@ -41,17 +41,24 @@ func Authentications(ctx *context.Context) {
|
|||||||
ctx.HTML(200, AUTHS)
|
ctx.HTML(200, AUTHS)
|
||||||
}
|
}
|
||||||
|
|
||||||
type AuthSource struct {
|
type dropdownItem struct {
|
||||||
Name string
|
Name string
|
||||||
Type models.LoginType
|
Type interface{}
|
||||||
}
|
}
|
||||||
|
|
||||||
var authSources = []AuthSource{
|
var (
|
||||||
{models.LoginNames[models.LOGIN_LDAP], models.LOGIN_LDAP},
|
authSources = []dropdownItem{
|
||||||
{models.LoginNames[models.LOGIN_DLDAP], models.LOGIN_DLDAP},
|
{models.LoginNames[models.LOGIN_LDAP], models.LOGIN_LDAP},
|
||||||
{models.LoginNames[models.LOGIN_SMTP], models.LOGIN_SMTP},
|
{models.LoginNames[models.LOGIN_DLDAP], models.LOGIN_DLDAP},
|
||||||
{models.LoginNames[models.LOGIN_PAM], models.LOGIN_PAM},
|
{models.LoginNames[models.LOGIN_SMTP], models.LOGIN_SMTP},
|
||||||
}
|
{models.LoginNames[models.LOGIN_PAM], models.LOGIN_PAM},
|
||||||
|
}
|
||||||
|
securityProtocols = []dropdownItem{
|
||||||
|
{models.SecurityProtocolNames[ldap.SECURITY_PROTOCOL_UNENCRYPTED], ldap.SECURITY_PROTOCOL_UNENCRYPTED},
|
||||||
|
{models.SecurityProtocolNames[ldap.SECURITY_PROTOCOL_LDAPS], ldap.SECURITY_PROTOCOL_LDAPS},
|
||||||
|
{models.SecurityProtocolNames[ldap.SECURITY_PROTOCOL_START_TLS], ldap.SECURITY_PROTOCOL_START_TLS},
|
||||||
|
}
|
||||||
|
)
|
||||||
|
|
||||||
func NewAuthSource(ctx *context.Context) {
|
func NewAuthSource(ctx *context.Context) {
|
||||||
ctx.Data["Title"] = ctx.Tr("admin.auths.new")
|
ctx.Data["Title"] = ctx.Tr("admin.auths.new")
|
||||||
@@ -59,10 +66,12 @@ func NewAuthSource(ctx *context.Context) {
|
|||||||
ctx.Data["PageIsAdminAuthentications"] = true
|
ctx.Data["PageIsAdminAuthentications"] = true
|
||||||
|
|
||||||
ctx.Data["type"] = models.LOGIN_LDAP
|
ctx.Data["type"] = models.LOGIN_LDAP
|
||||||
ctx.Data["CurTypeName"] = models.LoginNames[models.LOGIN_LDAP]
|
ctx.Data["CurrentTypeName"] = models.LoginNames[models.LOGIN_LDAP]
|
||||||
|
ctx.Data["CurrentSecurityProtocol"] = models.SecurityProtocolNames[ldap.SECURITY_PROTOCOL_UNENCRYPTED]
|
||||||
ctx.Data["smtp_auth"] = "PLAIN"
|
ctx.Data["smtp_auth"] = "PLAIN"
|
||||||
ctx.Data["is_active"] = true
|
ctx.Data["is_active"] = true
|
||||||
ctx.Data["AuthSources"] = authSources
|
ctx.Data["AuthSources"] = authSources
|
||||||
|
ctx.Data["SecurityProtocols"] = securityProtocols
|
||||||
ctx.Data["SMTPAuths"] = models.SMTPAuths
|
ctx.Data["SMTPAuths"] = models.SMTPAuths
|
||||||
ctx.HTML(200, AUTH_NEW)
|
ctx.HTML(200, AUTH_NEW)
|
||||||
}
|
}
|
||||||
@@ -73,7 +82,7 @@ func parseLDAPConfig(form auth.AuthenticationForm) *models.LDAPConfig {
|
|||||||
Name: form.Name,
|
Name: form.Name,
|
||||||
Host: form.Host,
|
Host: form.Host,
|
||||||
Port: form.Port,
|
Port: form.Port,
|
||||||
UseSSL: form.TLS,
|
SecurityProtocol: ldap.SecurityProtocol(form.SecurityProtocol),
|
||||||
SkipVerify: form.SkipVerify,
|
SkipVerify: form.SkipVerify,
|
||||||
BindDN: form.BindDN,
|
BindDN: form.BindDN,
|
||||||
UserDN: form.UserDN,
|
UserDN: form.UserDN,
|
||||||
@@ -107,21 +116,21 @@ func NewAuthSourcePost(ctx *context.Context, form auth.AuthenticationForm) {
|
|||||||
ctx.Data["PageIsAdmin"] = true
|
ctx.Data["PageIsAdmin"] = true
|
||||||
ctx.Data["PageIsAdminAuthentications"] = true
|
ctx.Data["PageIsAdminAuthentications"] = true
|
||||||
|
|
||||||
ctx.Data["CurTypeName"] = models.LoginNames[models.LoginType(form.Type)]
|
ctx.Data["CurrentTypeName"] = models.LoginNames[models.LoginType(form.Type)]
|
||||||
|
ctx.Data["CurrentSecurityProtocol"] = models.SecurityProtocolNames[ldap.SecurityProtocol(form.SecurityProtocol)]
|
||||||
ctx.Data["AuthSources"] = authSources
|
ctx.Data["AuthSources"] = authSources
|
||||||
|
ctx.Data["SecurityProtocols"] = securityProtocols
|
||||||
ctx.Data["SMTPAuths"] = models.SMTPAuths
|
ctx.Data["SMTPAuths"] = models.SMTPAuths
|
||||||
|
|
||||||
if ctx.HasError() {
|
hasTLS := false
|
||||||
ctx.HTML(200, AUTH_NEW)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
var config core.Conversion
|
var config core.Conversion
|
||||||
switch models.LoginType(form.Type) {
|
switch models.LoginType(form.Type) {
|
||||||
case models.LOGIN_LDAP, models.LOGIN_DLDAP:
|
case models.LOGIN_LDAP, models.LOGIN_DLDAP:
|
||||||
config = parseLDAPConfig(form)
|
config = parseLDAPConfig(form)
|
||||||
|
hasTLS = ldap.SecurityProtocol(form.SecurityProtocol) > ldap.SECURITY_PROTOCOL_UNENCRYPTED
|
||||||
case models.LOGIN_SMTP:
|
case models.LOGIN_SMTP:
|
||||||
config = parseSMTPConfig(form)
|
config = parseSMTPConfig(form)
|
||||||
|
hasTLS = true
|
||||||
case models.LOGIN_PAM:
|
case models.LOGIN_PAM:
|
||||||
config = &models.PAMConfig{
|
config = &models.PAMConfig{
|
||||||
ServiceName: form.PAMServiceName,
|
ServiceName: form.PAMServiceName,
|
||||||
@@ -130,6 +139,12 @@ func NewAuthSourcePost(ctx *context.Context, form auth.AuthenticationForm) {
|
|||||||
ctx.Error(400)
|
ctx.Error(400)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
ctx.Data["HasTLS"] = hasTLS
|
||||||
|
|
||||||
|
if ctx.HasError() {
|
||||||
|
ctx.HTML(200, AUTH_NEW)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
if err := models.CreateSource(&models.LoginSource{
|
if err := models.CreateSource(&models.LoginSource{
|
||||||
Type: models.LoginType(form.Type),
|
Type: models.LoginType(form.Type),
|
||||||
@@ -152,6 +167,7 @@ func EditAuthSource(ctx *context.Context) {
|
|||||||
ctx.Data["PageIsAdmin"] = true
|
ctx.Data["PageIsAdmin"] = true
|
||||||
ctx.Data["PageIsAdminAuthentications"] = true
|
ctx.Data["PageIsAdminAuthentications"] = true
|
||||||
|
|
||||||
|
ctx.Data["SecurityProtocols"] = securityProtocols
|
||||||
ctx.Data["SMTPAuths"] = models.SMTPAuths
|
ctx.Data["SMTPAuths"] = models.SMTPAuths
|
||||||
|
|
||||||
source, err := models.GetLoginSourceByID(ctx.ParamsInt64(":authid"))
|
source, err := models.GetLoginSourceByID(ctx.ParamsInt64(":authid"))
|
||||||
@@ -160,6 +176,8 @@ func EditAuthSource(ctx *context.Context) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
ctx.Data["Source"] = source
|
ctx.Data["Source"] = source
|
||||||
|
ctx.Data["HasTLS"] = source.HasTLS()
|
||||||
|
|
||||||
ctx.HTML(200, AUTH_EDIT)
|
ctx.HTML(200, AUTH_EDIT)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -176,6 +194,7 @@ func EditAuthSourcePost(ctx *context.Context, form auth.AuthenticationForm) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
ctx.Data["Source"] = source
|
ctx.Data["Source"] = source
|
||||||
|
ctx.Data["HasTLS"] = source.HasTLS()
|
||||||
|
|
||||||
if ctx.HasError() {
|
if ctx.HasError() {
|
||||||
ctx.HTML(200, AUTH_EDIT)
|
ctx.HTML(200, AUTH_EDIT)
|
||||||
|
|||||||
+1
-1
@@ -1 +1 @@
|
|||||||
0.9.36.0704
|
0.9.37.0708
|
||||||
@@ -14,7 +14,7 @@
|
|||||||
<input type="hidden" name="id" value="{{.Source.ID}}">
|
<input type="hidden" name="id" value="{{.Source.ID}}">
|
||||||
<div class="inline field">
|
<div class="inline field">
|
||||||
<label>{{$.i18n.Tr "admin.auths.auth_type"}}</label>
|
<label>{{$.i18n.Tr "admin.auths.auth_type"}}</label>
|
||||||
<input type="hidden" name="type" value="{{.Source.Type}}">
|
<input type="hidden" id="auth_type" name="type" value="{{.Source.Type}}">
|
||||||
<span>{{.Source.TypeName}}</span>
|
<span>{{.Source.TypeName}}</span>
|
||||||
</div>
|
</div>
|
||||||
<div class="required inline field {{if .Err_Name}}error{{end}}">
|
<div class="required inline field {{if .Err_Name}}error{{end}}">
|
||||||
@@ -25,6 +25,19 @@
|
|||||||
<!-- LDAP and DLDAP -->
|
<!-- LDAP and DLDAP -->
|
||||||
{{if or .Source.IsLDAP .Source.IsDLDAP}}
|
{{if or .Source.IsLDAP .Source.IsDLDAP}}
|
||||||
{{ $cfg:=.Source.LDAP }}
|
{{ $cfg:=.Source.LDAP }}
|
||||||
|
<div class="inline required field {{if .Err_SecurityProtocol}}error{{end}}">
|
||||||
|
<label>{{.i18n.Tr "admin.auths.security_protocol"}}</label>
|
||||||
|
<div class="ui selection security-protocol dropdown">
|
||||||
|
<input type="hidden" id="security_protocol" name="security_protocol" value="{{$cfg.SecurityProtocol}}">
|
||||||
|
<div class="text">{{$cfg.SecurityProtocolName}}</div>
|
||||||
|
<i class="dropdown icon"></i>
|
||||||
|
<div class="menu">
|
||||||
|
{{range .SecurityProtocols}}
|
||||||
|
<div class="item" data-value="{{.Type}}">{{.Name}}</div>
|
||||||
|
{{end}}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
<div class="required field">
|
<div class="required field">
|
||||||
<label for="host">{{.i18n.Tr "admin.auths.host"}}</label>
|
<label for="host">{{.i18n.Tr "admin.auths.host"}}</label>
|
||||||
<input id="host" name="host" value="{{$cfg.Host}}" placeholder="e.g. mydomain.com" required>
|
<input id="host" name="host" value="{{$cfg.Host}}" placeholder="e.g. mydomain.com" required>
|
||||||
@@ -129,13 +142,13 @@
|
|||||||
</div>
|
</div>
|
||||||
{{end}}
|
{{end}}
|
||||||
|
|
||||||
<div class="inline field {{if not (or (or .Source.IsLDAP .Source.IsDLDAP) .Source.IsSMTP)}}hide{{end}}">
|
<div class="inline field {{if not .Source.IsSMTP}}hide{{end}}">
|
||||||
<div class="ui checkbox">
|
<div class="ui checkbox">
|
||||||
<label><strong>{{.i18n.Tr "admin.auths.enable_tls"}}</strong></label>
|
<label><strong>{{.i18n.Tr "admin.auths.enable_tls"}}</strong></label>
|
||||||
<input name="tls" type="checkbox" {{if .Source.UseTLS}}checked{{end}}>
|
<input name="tls" type="checkbox" {{if .Source.UseTLS}}checked{{end}}>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div class="inline field {{if not (or (or .Source.IsLDAP .Source.IsDLDAP) .Source.IsSMTP)}}hide{{end}}">
|
<div class="has-tls inline field {{if not .HasTLS}}hide{{end}}">
|
||||||
<div class="ui checkbox">
|
<div class="ui checkbox">
|
||||||
<label><strong>{{.i18n.Tr "admin.auths.skip_tls_verify"}}</strong></label>
|
<label><strong>{{.i18n.Tr "admin.auths.skip_tls_verify"}}</strong></label>
|
||||||
<input name="skip_verify" type="checkbox" {{if .Source.SkipVerify}}checked{{end}}>
|
<input name="skip_verify" type="checkbox" {{if .Source.SkipVerify}}checked{{end}}>
|
||||||
|
|||||||
@@ -16,7 +16,7 @@
|
|||||||
<label>{{.i18n.Tr "admin.auths.auth_type"}}</label>
|
<label>{{.i18n.Tr "admin.auths.auth_type"}}</label>
|
||||||
<div class="ui selection type dropdown">
|
<div class="ui selection type dropdown">
|
||||||
<input type="hidden" id="auth_type" name="type" value="{{.type}}">
|
<input type="hidden" id="auth_type" name="type" value="{{.type}}">
|
||||||
<div class="text">{{.CurTypeName}}</div>
|
<div class="text">{{.CurrentTypeName}}</div>
|
||||||
<i class="dropdown icon"></i>
|
<i class="dropdown icon"></i>
|
||||||
<div class="menu">
|
<div class="menu">
|
||||||
{{range .AuthSources}}
|
{{range .AuthSources}}
|
||||||
@@ -32,6 +32,19 @@
|
|||||||
|
|
||||||
<!-- LDAP and DLDAP -->
|
<!-- LDAP and DLDAP -->
|
||||||
<div class="ldap dldap field {{if not (or (eq .type 2) (eq .type 5))}}hide{{end}}">
|
<div class="ldap dldap field {{if not (or (eq .type 2) (eq .type 5))}}hide{{end}}">
|
||||||
|
<div class="inline required field {{if .Err_SecurityProtocol}}error{{end}}">
|
||||||
|
<label>{{.i18n.Tr "admin.auths.security_protocol"}}</label>
|
||||||
|
<div class="ui selection security-protocol dropdown">
|
||||||
|
<input type="hidden" id="security_protocol" name="security_protocol" value="{{.security_protocol}}">
|
||||||
|
<div class="text">{{.CurrentSecurityProtocol}}</div>
|
||||||
|
<i class="dropdown icon"></i>
|
||||||
|
<div class="menu">
|
||||||
|
{{range .SecurityProtocols}}
|
||||||
|
<div class="item" data-value="{{.Type}}">{{.Name}}</div>
|
||||||
|
{{end}}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
<div class="required field">
|
<div class="required field">
|
||||||
<label for="host">{{.i18n.Tr "admin.auths.host"}}</label>
|
<label for="host">{{.i18n.Tr "admin.auths.host"}}</label>
|
||||||
<input id="host" name="host" value="{{.host}}" placeholder="e.g. mydomain.com">
|
<input id="host" name="host" value="{{.host}}" placeholder="e.g. mydomain.com">
|
||||||
@@ -126,13 +139,13 @@
|
|||||||
<input name="attributes_in_bind" type="checkbox" {{if .attributes_in_bind}}checked{{end}}>
|
<input name="attributes_in_bind" type="checkbox" {{if .attributes_in_bind}}checked{{end}}>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div class="ldap dldap smtp inline field {{if not (or (or (eq .type 2) (eq .type 5)) (eq .type 3))}}hide{{end}}">
|
<div class="smtp inline field {{if not (eq .type 3)}}hide{{end}}">
|
||||||
<div class="ui checkbox">
|
<div class="ui checkbox">
|
||||||
<label><strong>{{.i18n.Tr "admin.auths.enable_tls"}}</strong></label>
|
<label><strong>{{.i18n.Tr "admin.auths.enable_tls"}}</strong></label>
|
||||||
<input name="tls" type="checkbox" {{if .tls}}checked{{end}}>
|
<input name="tls" type="checkbox" {{if .tls}}checked{{end}}>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
<div class="ldap dldap smtp inline field {{if not (or (or (eq .type 2) (eq .type 5)) (eq .type 3))}}hide{{end}}">
|
<div class="has-tls inline field {{if not .HasTLS}}hide{{end}}">
|
||||||
<div class="ui checkbox">
|
<div class="ui checkbox">
|
||||||
<label><strong>{{.i18n.Tr "admin.auths.skip_tls_verify"}}</strong></label>
|
<label><strong>{{.i18n.Tr "admin.auths.skip_tls_verify"}}</strong></label>
|
||||||
<input name="skip_verify" type="checkbox" {{if .skip_verify}}checked{{end}}>
|
<input name="skip_verify" type="checkbox" {{if .skip_verify}}checked{{end}}>
|
||||||
|
|||||||
Reference in new issue
Block a user