improved ldap_auth.py, thanks Kory
This commit is contained in:
@@ -1 +1 @@
|
|||||||
Version 2.00.0 (2012-07-11 09:17:27) dev
|
Version 2.00.0 (2012-07-11 18:10:46) dev
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# -*- coding: utf-8 -*-
|
# -*- coding: utf-8 -*-
|
||||||
#
|
#
|
||||||
# last tinkered with by korylprince at gmail.com on 2012-04-5
|
# last tinkered with by korylprince at gmail.com on 2012-07-11
|
||||||
#
|
#
|
||||||
|
|
||||||
import sys
|
import sys
|
||||||
@@ -171,6 +171,9 @@ def ldap_auth( server = 'ldap', port = None,
|
|||||||
manage_groups = manage_groups,
|
manage_groups = manage_groups,
|
||||||
allowed_groups = allowed_groups,
|
allowed_groups = allowed_groups,
|
||||||
db = db):
|
db = db):
|
||||||
|
if password == '':
|
||||||
|
logger.warning('blank password not allowed')
|
||||||
|
return False
|
||||||
logger.debug('mode: [%s] manage_user: [%s] custom_scope: [%s] manage_groups: [%s]' % (
|
logger.debug('mode: [%s] manage_user: [%s] custom_scope: [%s] manage_groups: [%s]' % (
|
||||||
str(mode), str(manage_user), str(custom_scope), str(manage_groups)))
|
str(mode), str(manage_user), str(custom_scope), str(manage_groups)))
|
||||||
if manage_user:
|
if manage_user:
|
||||||
@@ -419,9 +422,9 @@ def ldap_auth( server = 'ldap', port = None,
|
|||||||
password = None,
|
password = None,
|
||||||
allowed_groups = allowed_groups
|
allowed_groups = allowed_groups
|
||||||
):
|
):
|
||||||
'''
|
"""
|
||||||
Figure out if the username is a member of an allowed group in ldap or not
|
Figure out if the username is a member of an allowed group in ldap or not
|
||||||
'''
|
"""
|
||||||
#
|
#
|
||||||
# Get all group name where the user is in actually in ldap
|
# Get all group name where the user is in actually in ldap
|
||||||
# #########################################################
|
# #########################################################
|
||||||
@@ -441,13 +444,13 @@ def ldap_auth( server = 'ldap', port = None,
|
|||||||
password = None,
|
password = None,
|
||||||
db = db,
|
db = db,
|
||||||
):
|
):
|
||||||
'''
|
"""
|
||||||
Manage user groups
|
Manage user groups
|
||||||
|
|
||||||
Get all user's group from ldap and refresh the already stored
|
Get all user's group from ldap and refresh the already stored
|
||||||
ones in web2py's application database or create new groups
|
ones in web2py's application database or create new groups
|
||||||
according to ldap.
|
according to ldap.
|
||||||
'''
|
"""
|
||||||
logger.info('[%s] Manage user groups' % str(username))
|
logger.info('[%s] Manage user groups' % str(username))
|
||||||
try:
|
try:
|
||||||
#
|
#
|
||||||
@@ -525,9 +528,9 @@ def ldap_auth( server = 'ldap', port = None,
|
|||||||
cert_path = cert_path,
|
cert_path = cert_path,
|
||||||
cert_file = cert_file
|
cert_file = cert_file
|
||||||
):
|
):
|
||||||
'''
|
"""
|
||||||
Inicialize ldap connection
|
Inicialize ldap connection
|
||||||
'''
|
"""
|
||||||
logger.info('[%s] Inicialize ldap connection' % str(ldap_server))
|
logger.info('[%s] Inicialize ldap connection' % str(ldap_server))
|
||||||
if secure:
|
if secure:
|
||||||
if not ldap_port:
|
if not ldap_port:
|
||||||
@@ -556,9 +559,9 @@ def ldap_auth( server = 'ldap', port = None,
|
|||||||
group_filterstr = group_filterstr,
|
group_filterstr = group_filterstr,
|
||||||
ldap_mode = mode
|
ldap_mode = mode
|
||||||
):
|
):
|
||||||
'''
|
"""
|
||||||
Get all group names from ldap where the user is in
|
Get all group names from ldap where the user is in
|
||||||
'''
|
"""
|
||||||
logger.info('[%s] Get user groups from ldap' % str(username))
|
logger.info('[%s] Get user groups from ldap' % str(username))
|
||||||
#
|
#
|
||||||
# Get all group name where the user is in actually in ldap
|
# Get all group name where the user is in actually in ldap
|
||||||
|
|||||||
Reference in New Issue
Block a user