* feat: introduce tls parameters in config to allow startTLS
* feat: pass tls config for startTLS to ldap server
* build: update libs to use newer ldap
* feat: allow tls config for startTLS
* feat: introduce new prometheus monitor object
* feat: add LDAPMonitorWatcher as a potential replacement for v0 Collector
* feat: pass monitor object as dependency and instrument core operations
* feat: instantiate monitor in main
* ci: exclude mock files
* ci: generate mocks before running tests and go vet
* ci: make vet command keep going in case of errors
reason is due to the following happening in the GetStats method of the ldap.Stats struct
```
internal/monitoring/mock_interfaces.go:92:13: assignment copies lock value to ret0: (github.com/nmcclain/ldap.Stats, bool) contains github.com/nmcclain/ldap.Stats contains sync.Mutex
internal/monitoring/mock_interfaces.go:93:9: return copies lock value: github.com/nmcclain/ldap.Stats contains sync.Mutex
internal/monitoring/ldap_test.go:23:56: call of mockLDAPServer.EXPECT().GetStats().MinTimes(1).Return copies lock value: github.com/nmcclain/ldap.Stats contains sync.Mutex
```
* deps: move to use go.uber.org/mock/gomock
* fix: update and upgrade libraries
side note:
* using commit to trigger release-please workflow in light of recent changes regarding branch strategy
* ci: introduce dependabot
* build: make build vars optional and passable via env
* build: use . for BUILD_FILES var to allow buildvcs flag
* build: create mkbindir, build and sha256 targets
* build: reuse build target for each platform specific compilation
* Ensure same go version for main and plugins
* chore: release 2.3.0
Release-As: 2.3.0
* release-please
* Fix(plugins)!: Rename the groups table to ldapgroups (#326)
The groups table name is a reserved keyword in mysql and requires that
the table name be escaped with backticks in order to use the groups
name. Other databases such as postgres do not support the use of the
backticks in the query statements. This change renames the groups table
to ldapgroups in oder to avoid this problem altogether.
This does have a dependency on the backend sql plugins to alter the
schema to match the new name.
Signed-off-by: Billy Olsen <billy.olsen@gmail.com>
Co-authored-by: Chris F Ravenscroft <chris@voilaweb.com>
* chore: update docker sqlite with ldapgroups (#338)
* feat: Update migration code to support table names (#339)
* chore(dev): release 2.3.0 (#337)
---------
Signed-off-by: Billy Olsen <billy.olsen@gmail.com>
Co-authored-by: shipperizer <alexcabb@gmail.com>
Co-authored-by: Billy Olsen <wolsen@users.noreply.github.com>
* Plugin: Unix PAM Authentication (#263)
* Add plugin using pam authentication
Adds an additional plugin which us authenticating against
the PAM unix backend and exposing users and groups local
to the machine glauth is running on.
This can be used to expose local users for authentication
in other services which support ldap only.
* plugins: pam: Rewrite Bind() to use ldapopshelper
Modernizes the implementation of Bind() to make use of the helper
functions provided by LDAPOpsHelper.
In order to support custom authentication the existing config.User
has received an additional PassAppCustom property which allows to
specify a custom authentication callback for a user.
In case of the PAM backend this will be used to authenticate against
the local PAM database.
* plugins: pam: Rewrite Search() to use ldapopshelper
Modernizes the implementation of Search() to make use of the helper
functions provided by LDAPOpsHelper.
* plugins: pam: Capability through group membership
Adds a configuration option which decides if a user gets the search
capability or not based on the group memberships of a user.
* plugins: pam: Apply formatting
Runs gofmt and go get on all changes done earlier
* plugins: pam: Address feedback from CodeClimate
- reduce code similarity
- document new exports
- address casing of variables and functions
- reduce complexity of FindPosixGroups()
- reduce complexity of FindPosixAccounts()
- fix else branch in ldapopshelper
Co-authored-by: Marius Zwicker <marius.zwicker@mlba-team.de>
* Updated README for pam plugin
* Updated README for pam plugin
Co-authored-by: Marius Zwicker <marius@mlba-team.de>
Co-authored-by: Marius Zwicker <marius.zwicker@mlba-team.de>