* Mac M1 Support
* Augmented root DSS and schema discovery based on content of schema directory
* LDAP workaround where req. attribute gets injected in response now works with combined filters
* SubSchema query can return a minimal set, freeipa or openldap's schemas
This commit actually covers a few items. In future commits, I will keep features distinct. This is only happening this time around due to how long it took to merge this branch.
Covered:
- Database plugins (at this time: SQLite, MySQL, Postgres)
- Backends acting as middleware: added the [[Backends]] configuration directive while retaining backward compatibility with [Backend]
- Schema introspection (root DSE query with base scope)
- When proxying, insert queried attribute back in upstream response, if absent, so that the LDAP library does not filter out all entries
- When chaining backends, any backend can be used to inject OTP value in password, before reaching a non-OTP-aware backend (currently guarded by a True statement in case we find an issue (I did thoroughly test but you never know))
- Handling of special "1.1" attributes filter meaning "I do not want attributes" (RFC 4511, 4.5.1.8)
- Support for "want types only" queries, even when proxying
* Ensure config watcher also works in kubernetes
When using configmaps in kubernetes, the file is a symlink, and then
file-watcher is not opdated with a write event. Instead it receives a
CHMOD and a REMOVE event.
This change adds two things
1) Removal of the current wacther and adding of a new watcher for the
same path
2) The do-reload conditional is updated to also include the remove
event.
* Align write and removed conditionals
Fix#141.
With this change, a github action is added that builds a multiarch docker image on every commit, supporting x86_64, aarch64 and arm/v7.
When the action is triggered on a release or tag, it also uploads the versioned image to github container image registry.
Co-authored-by: Jörn Friedrich Dreyer <jfd@butonic.de>
* Pulling in latest changes and fixes for 1.1.1 (#56)
* Adding a few test dockerfiles
* Continued work on docker builds
* Basic example of docker build and run works - see build.sh for now
* Continuing to work on docker build
* Removing testing from build script, since it belongs later in process
* Implementing dumb init
* Docker build fully switched to alpine
* Setting up alpine build
* Cleaning up dockerfile
* Cleaning up repo in prep for merge
* Updating permissions for clean merge
* Removing old ansible cruft, as per #12
* Removing binaries (since we now build)
* Updating sample config to use new fields now available
* Testing travis
* another travis test
* Still working on travis builds
* Fix missing amazon packages
* Merge in Travis config feature branch (#26)
* Adding version string
* Fixing and cleaning up docker build
* Adding image hashing and verification to 'make all'
* Testing build
* Running gofmt to fix build
* Testing switching travis to make
* Testing build again
* Merging in Fixes from travis-build feature branch (#33)
This includes an integration test which runs glauth and compares ldapsearch snapshot output stored in the repo compared to the snapshot output of the glauth.
Additionally, removing old versions of go, and adding windows and linuxar builds (but not tests) to the makefile, and consequently, the travis build.
While the mac, linux-arm, and windows binaries are not able to be run in travis, they are able to be at least compiled.
* Remove needless comment from integration test
* Adding 'is-process-running' check before integration tests run, to clearly note if the program crashes on run
* Switching from 1 sec to 2 sec timeout for integration test
* Adding back config file to fix build. Previous commit intended to see if build failed (and it did)
* Add support for including groups in groups (#23)
* Add support for including groups in groups
* Pulling in Makefile structure to allow easier testing and builds
* Forgot to remove spare test
* Add Version Info at Buildtime (#39)
Adds the build info to the binary at buildtime via buildtime variables. This is shown by `./glauth --version`.
Example output for a non-release:
```
GLauth
Non-release build from branch feature/buildversion
Build time: 20180531_181011Z
Commit: 07ba631c2fd0050f375655ad7c44f862e0e6640c
```
And example of a built release:
```
GLauth v2.3.4
Build time: 20180601_041330Z
Commit: 931d666262b96bab8a5c760be42d7facec7a2d74
```
* Fixing Broken Docker Build (#41)
Forgot to include go-bindata run in Dockerfile.
* Removing leftover TODO from merge
* Testing releases
* Testing releases
* Testing releases
* Adjusting logging
* Add new group tests to integration tests
* add cleanup to test process
* Add documentation about otherGroups, which was a previously undocumented field.
* Auto fetching bindata during build so it's not needed to be done manually
* Syntax fix
* starting framework for unit tests
* Merging in ongoing progress from Feature/travis build (#44)
Fixes a few minor issues:
#42 - now uses the makefile in the docker build, which means version info is correctly embedded at runtime - also now outputs version data at the top of the log when the container starts
Fixing a simple issue found by go vet. Need to do more work on fixing issues found in go vet.
* Forgot to run 'go fmt'
* Adding codecov for go now that a single test is written
* Testing not quite ready yet, removing from build
* Add Support For 2 Factor Authentication
Merging in feature from @ryskov (PR #24) adding 2FA support during LDAP binds. This is accomplished by concatenating the code to the end of the password.
Also added integration tests for the TOTP method to run in CI. Could not, however, add automated tests for the yubikey, due the physical nature.
* Expose LDAPS ports in Docker container (#49)
Currently, the LDAPS ports are not exposed in the docker container.
* Adding better logging to docker start script
* Add more logging info to docker startup script
* Fix Arm32 Build (#52)
As discussed in issue #51, Arm32 builds were using 368 (intel/amd) arch accidentally, generating linux 32 bit binaries instead of arm 32 bit binaries. This commit fixes this in the Makefile, which will fix both the local builds, as well as the travis CI and release builds.
fixes#52
* Update docker hub image badge to a working one
previous one simply returned 0.
* Removing 3893 - fixes#50
* Fixing readme MD formatting
* Adding travis_retry to fix against intermittent network outages
* Add TLS options for running both with TLS and without on the same time (#27)
* Add TLS options for running both with TLS and without on the same time.
This commit expands on the settings available for using TLS. It puts TLS settings under the [frontend.tls] section and adds a new setting to [frontend] called TLSExclusive (bool).
TLSExclusive specifies whether or not to only run TLS when it is enabled, and is 'true' by default. Setting it to 'false' and having TLS enabled, causes the server to start both a LDAP and LDAPS server,
and therefore requires to seperate 'listen' options (to run on different ports) - the Frontend.Listen and the Frontend.TLS.Listen. If TLSExclusive is set to 'true' and no Frontend.TLS.Listen is specified, it will use the Frontend.Listen.
* Adding PR template and improving integration test tooling
* Updating formatting
* Add get dependencies step to makefile setup
* Add go 1.11
* Add App Password Support (#60)
App passwords can now be used to allow easier OTP use alongside applications which need to bind with a static password. Use the key `passappsha256` and specify an array of password hashes. See the readme and sample configuration file for more information.
Fixes#54
* Adding NCoC as official project code of conduct
We happily accept contributions based on the merit of the contributions.
* Properly handling paramaters in logs - fixes#64
* Adding ldapsearch for healthchecks
* fixed quoting in docker startup script (#77)
Thanks @cxcv cxcv
* Minor tweak of help text
* More durable Dockerfile (#92)
Co-authored-by: Ben Yanke <ben@benyanke.com>
Co-authored-by: Andrea Cervesato <andrea.cervesato@gmail.com>
* Pulling in latest changes and fixes for 1.1.1 (#56)
* Adding a few test dockerfiles
* Continued work on docker builds
* Basic example of docker build and run works - see build.sh for now
* Continuing to work on docker build
* Removing testing from build script, since it belongs later in process
* Implementing dumb init
* Docker build fully switched to alpine
* Setting up alpine build
* Cleaning up dockerfile
* Cleaning up repo in prep for merge
* Updating permissions for clean merge
* Removing old ansible cruft, as per #12
* Removing binaries (since we now build)
* Updating sample config to use new fields now available
* Testing travis
* another travis test
* Still working on travis builds
* Fix missing amazon packages
* Merge in Travis config feature branch (#26)
* Adding version string
* Fixing and cleaning up docker build
* Adding image hashing and verification to 'make all'
* Testing build
* Running gofmt to fix build
* Testing switching travis to make
* Testing build again
* Merging in Fixes from travis-build feature branch (#33)
This includes an integration test which runs glauth and compares ldapsearch snapshot output stored in the repo compared to the snapshot output of the glauth.
Additionally, removing old versions of go, and adding windows and linuxar builds (but not tests) to the makefile, and consequently, the travis build.
While the mac, linux-arm, and windows binaries are not able to be run in travis, they are able to be at least compiled.
* Remove needless comment from integration test
* Adding 'is-process-running' check before integration tests run, to clearly note if the program crashes on run
* Switching from 1 sec to 2 sec timeout for integration test
* Adding back config file to fix build. Previous commit intended to see if build failed (and it did)
* Add support for including groups in groups (#23)
* Add support for including groups in groups
* Pulling in Makefile structure to allow easier testing and builds
* Forgot to remove spare test
* Add Version Info at Buildtime (#39)
Adds the build info to the binary at buildtime via buildtime variables. This is shown by `./glauth --version`.
Example output for a non-release:
```
GLauth
Non-release build from branch feature/buildversion
Build time: 20180531_181011Z
Commit: 07ba631c2fd0050f375655ad7c44f862e0e6640c
```
And example of a built release:
```
GLauth v2.3.4
Build time: 20180601_041330Z
Commit: 931d666262b96bab8a5c760be42d7facec7a2d74
```
* Fixing Broken Docker Build (#41)
Forgot to include go-bindata run in Dockerfile.
* Removing leftover TODO from merge
* Testing releases
* Testing releases
* Testing releases
* Adjusting logging
* Add new group tests to integration tests
* add cleanup to test process
* Add documentation about otherGroups, which was a previously undocumented field.
* Auto fetching bindata during build so it's not needed to be done manually
* Syntax fix
* starting framework for unit tests
* Merging in ongoing progress from Feature/travis build (#44)
Fixes a few minor issues:
#42 - now uses the makefile in the docker build, which means version info is correctly embedded at runtime - also now outputs version data at the top of the log when the container starts
Fixing a simple issue found by go vet. Need to do more work on fixing issues found in go vet.
* Forgot to run 'go fmt'
* Adding codecov for go now that a single test is written
* Testing not quite ready yet, removing from build
* Add Support For 2 Factor Authentication
Merging in feature from @ryskov (PR #24) adding 2FA support during LDAP binds. This is accomplished by concatenating the code to the end of the password.
Also added integration tests for the TOTP method to run in CI. Could not, however, add automated tests for the yubikey, due the physical nature.
* Expose LDAPS ports in Docker container (#49)
Currently, the LDAPS ports are not exposed in the docker container.
* Adding better logging to docker start script
* Add more logging info to docker startup script
* Fix Arm32 Build (#52)
As discussed in issue #51, Arm32 builds were using 368 (intel/amd) arch accidentally, generating linux 32 bit binaries instead of arm 32 bit binaries. This commit fixes this in the Makefile, which will fix both the local builds, as well as the travis CI and release builds.
fixes#52
* Update docker hub image badge to a working one
previous one simply returned 0.
* Removing 3893 - fixes#50
* Fixing readme MD formatting
* Adding travis_retry to fix against intermittent network outages
* Add TLS options for running both with TLS and without on the same time (#27)
* Add TLS options for running both with TLS and without on the same time.
This commit expands on the settings available for using TLS. It puts TLS settings under the [frontend.tls] section and adds a new setting to [frontend] called TLSExclusive (bool).
TLSExclusive specifies whether or not to only run TLS when it is enabled, and is 'true' by default. Setting it to 'false' and having TLS enabled, causes the server to start both a LDAP and LDAPS server,
and therefore requires to seperate 'listen' options (to run on different ports) - the Frontend.Listen and the Frontend.TLS.Listen. If TLSExclusive is set to 'true' and no Frontend.TLS.Listen is specified, it will use the Frontend.Listen.
* Adding PR template and improving integration test tooling
* Updating formatting
* Add get dependencies step to makefile setup
* Add go 1.11
* Add App Password Support (#60)
App passwords can now be used to allow easier OTP use alongside applications which need to bind with a static password. Use the key `passappsha256` and specify an array of password hashes. See the readme and sample configuration file for more information.
Fixes#54
* Adding NCoC as official project code of conduct
We happily accept contributions based on the merit of the contributions.
* Properly handling paramaters in logs - fixes#64
* Adding ldapsearch for healthchecks
* fixed quoting in docker startup script (#77)
Thanks @cxcv cxcv
* Minor tweak of help text
* More durable Dockerfile (#92)
* refactor with latest dev
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de>
* fix modules, update .gitignore
* pass in logger
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de>
Co-authored-by: Ben Yanke <ben@benyanke.com>
Co-authored-by: Andrea Cervesato <andrea.cervesato@gmail.com>
* Add ownCloud 10 backend supporting provisioning api as well as graph api
* Use github.com/DeepDiver1975/msgraph.go/v1.0
* List members in groups when using graph api
* Handle searchBaseDN pointing to a user
* Pulling in latest changes and fixes for 1.1.1 (#56)
* Adding a few test dockerfiles
* Continued work on docker builds
* Basic example of docker build and run works - see build.sh for now
* Continuing to work on docker build
* Removing testing from build script, since it belongs later in process
* Implementing dumb init
* Docker build fully switched to alpine
* Setting up alpine build
* Cleaning up dockerfile
* Cleaning up repo in prep for merge
* Updating permissions for clean merge
* Removing old ansible cruft, as per #12
* Removing binaries (since we now build)
* Updating sample config to use new fields now available
* Testing travis
* another travis test
* Still working on travis builds
* Fix missing amazon packages
* Merge in Travis config feature branch (#26)
* Adding version string
* Fixing and cleaning up docker build
* Adding image hashing and verification to 'make all'
* Testing build
* Running gofmt to fix build
* Testing switching travis to make
* Testing build again
* Merging in Fixes from travis-build feature branch (#33)
This includes an integration test which runs glauth and compares ldapsearch snapshot output stored in the repo compared to the snapshot output of the glauth.
Additionally, removing old versions of go, and adding windows and linuxar builds (but not tests) to the makefile, and consequently, the travis build.
While the mac, linux-arm, and windows binaries are not able to be run in travis, they are able to be at least compiled.
* Remove needless comment from integration test
* Adding 'is-process-running' check before integration tests run, to clearly note if the program crashes on run
* Switching from 1 sec to 2 sec timeout for integration test
* Adding back config file to fix build. Previous commit intended to see if build failed (and it did)
* Add support for including groups in groups (#23)
* Add support for including groups in groups
* Pulling in Makefile structure to allow easier testing and builds
* Forgot to remove spare test
* Add Version Info at Buildtime (#39)
Adds the build info to the binary at buildtime via buildtime variables. This is shown by `./glauth --version`.
Example output for a non-release:
```
GLauth
Non-release build from branch feature/buildversion
Build time: 20180531_181011Z
Commit: 07ba631c2fd0050f375655ad7c44f862e0e6640c
```
And example of a built release:
```
GLauth v2.3.4
Build time: 20180601_041330Z
Commit: 931d666262b96bab8a5c760be42d7facec7a2d74
```
* Fixing Broken Docker Build (#41)
Forgot to include go-bindata run in Dockerfile.
* Removing leftover TODO from merge
* Testing releases
* Testing releases
* Testing releases
* Adjusting logging
* Add new group tests to integration tests
* add cleanup to test process
* Add documentation about otherGroups, which was a previously undocumented field.
* Auto fetching bindata during build so it's not needed to be done manually
* Syntax fix
* starting framework for unit tests
* Merging in ongoing progress from Feature/travis build (#44)
Fixes a few minor issues:
#42 - now uses the makefile in the docker build, which means version info is correctly embedded at runtime - also now outputs version data at the top of the log when the container starts
Fixing a simple issue found by go vet. Need to do more work on fixing issues found in go vet.
* Forgot to run 'go fmt'
* Adding codecov for go now that a single test is written
* Testing not quite ready yet, removing from build
* Add Support For 2 Factor Authentication
Merging in feature from @ryskov (PR #24) adding 2FA support during LDAP binds. This is accomplished by concatenating the code to the end of the password.
Also added integration tests for the TOTP method to run in CI. Could not, however, add automated tests for the yubikey, due the physical nature.
* Expose LDAPS ports in Docker container (#49)
Currently, the LDAPS ports are not exposed in the docker container.
* Adding better logging to docker start script
* Add more logging info to docker startup script
* Fix Arm32 Build (#52)
As discussed in issue #51, Arm32 builds were using 368 (intel/amd) arch accidentally, generating linux 32 bit binaries instead of arm 32 bit binaries. This commit fixes this in the Makefile, which will fix both the local builds, as well as the travis CI and release builds.
fixes#52
* Update docker hub image badge to a working one
previous one simply returned 0.
* Removing 3893 - fixes#50
* Fixing readme MD formatting
* Adding travis_retry to fix against intermittent network outages
* Add TLS options for running both with TLS and without on the same time (#27)
* Add TLS options for running both with TLS and without on the same time.
This commit expands on the settings available for using TLS. It puts TLS settings under the [frontend.tls] section and adds a new setting to [frontend] called TLSExclusive (bool).
TLSExclusive specifies whether or not to only run TLS when it is enabled, and is 'true' by default. Setting it to 'false' and having TLS enabled, causes the server to start both a LDAP and LDAPS server,
and therefore requires to seperate 'listen' options (to run on different ports) - the Frontend.Listen and the Frontend.TLS.Listen. If TLSExclusive is set to 'true' and no Frontend.TLS.Listen is specified, it will use the Frontend.Listen.
* Adding PR template and improving integration test tooling
* Updating formatting
* Add get dependencies step to makefile setup
* Add go 1.11
* Add App Password Support (#60)
App passwords can now be used to allow easier OTP use alongside applications which need to bind with a static password. Use the key `passappsha256` and specify an array of password hashes. See the readme and sample configuration file for more information.
Fixes#54
* Adding NCoC as official project code of conduct
We happily accept contributions based on the merit of the contributions.
* Properly handling paramaters in logs - fixes#64
* Adding ldapsearch for healthchecks
* fixed quoting in docker startup script (#77)
Thanks @cxcv cxcv
* Minor tweak of help text
* More durable Dockerfile (#92)
Co-authored-by: Ben Yanke <ben@benyanke.com>
Co-authored-by: Andrea Cervesato <andrea.cervesato@gmail.com>
* goimports fixups
Adjust imports lists to match that produced by goimports.
Signed-off-by: Icarus Sparry <icarus.sparry@amd.com>
* Fix mutex handling
Mutexes must not be copied after their first use.
Create a global mutex for ldap and pass a pointer to this around.
Fixes#43
Signed-off-by: Icarus Sparry <icarus.sparry@amd.com>
* Add config options for customizing group and nate attribute prefixes and name of ssh-key output
* Rename nameattr and groupattr to respectively nameformat and groupformat
* Messed up setting up default values on merge for ldap and ldaps section
* Fix good-results after 'via LDAP' suffix was removed from gecos and description
* Added uid for good-results aswell
* Revert "Added uid for good-results aswell"
This reverts commit 21b86d257063d6fc00b9152a8b8ff87488e5c37a.
* Adjust tests
* order of cn and uid should be same for both posixaccount and posixgroup to pass tests
* Adding a few test dockerfiles
* Continued work on docker builds
* Basic example of docker build and run works - see build.sh for now
* Continuing to work on docker build
* Removing testing from build script, since it belongs later in process
* Implementing dumb init
* Docker build fully switched to alpine
* Setting up alpine build
* Cleaning up dockerfile
* Cleaning up repo in prep for merge
* Updating permissions for clean merge
* Removing old ansible cruft, as per #12
* Removing binaries (since we now build)
* Updating sample config to use new fields now available
* Testing travis
* another travis test
* Still working on travis builds
* Fix missing amazon packages
* Merge in Travis config feature branch (#26)
* Adding version string
* Fixing and cleaning up docker build
* Adding image hashing and verification to 'make all'
* Testing build
* Running gofmt to fix build
* Testing switching travis to make
* Testing build again
* Merging in Fixes from travis-build feature branch (#33)
This includes an integration test which runs glauth and compares ldapsearch snapshot output stored in the repo compared to the snapshot output of the glauth.
Additionally, removing old versions of go, and adding windows and linuxar builds (but not tests) to the makefile, and consequently, the travis build.
While the mac, linux-arm, and windows binaries are not able to be run in travis, they are able to be at least compiled.
* Remove needless comment from integration test
* Adding 'is-process-running' check before integration tests run, to clearly note if the program crashes on run
* Switching from 1 sec to 2 sec timeout for integration test
* Adding back config file to fix build. Previous commit intended to see if build failed (and it did)
* Add support for including groups in groups (#23)
* Add support for including groups in groups
* Pulling in Makefile structure to allow easier testing and builds
* Forgot to remove spare test
* Add Version Info at Buildtime (#39)
Adds the build info to the binary at buildtime via buildtime variables. This is shown by `./glauth --version`.
Example output for a non-release:
```
GLauth
Non-release build from branch feature/buildversion
Build time: 20180531_181011Z
Commit: 07ba631c2fd0050f375655ad7c44f862e0e6640c
```
And example of a built release:
```
GLauth v2.3.4
Build time: 20180601_041330Z
Commit: 931d666262b96bab8a5c760be42d7facec7a2d74
```
* Fixing Broken Docker Build (#41)
Forgot to include go-bindata run in Dockerfile.
* Removing leftover TODO from merge
* Testing releases
* Testing releases
* Testing releases
* Adjusting logging
* Add new group tests to integration tests
* add cleanup to test process
* Add documentation about otherGroups, which was a previously undocumented field.
* Auto fetching bindata during build so it's not needed to be done manually
* Syntax fix
* starting framework for unit tests
* Merging in ongoing progress from Feature/travis build (#44)
Fixes a few minor issues:
#42 - now uses the makefile in the docker build, which means version info is correctly embedded at runtime - also now outputs version data at the top of the log when the container starts
Fixing a simple issue found by go vet. Need to do more work on fixing issues found in go vet.
* Forgot to run 'go fmt'
* Adding codecov for go now that a single test is written
* Testing not quite ready yet, removing from build
* Add Support For 2 Factor Authentication
Merging in feature from @ryskov (PR #24) adding 2FA support during LDAP binds. This is accomplished by concatenating the code to the end of the password.
Also added integration tests for the TOTP method to run in CI. Could not, however, add automated tests for the yubikey, due the physical nature.
* Expose LDAPS ports in Docker container (#49)
Currently, the LDAPS ports are not exposed in the docker container.
* Adding better logging to docker start script
* Add more logging info to docker startup script
* Fix Arm32 Build (#52)
As discussed in issue #51, Arm32 builds were using 368 (intel/amd) arch accidentally, generating linux 32 bit binaries instead of arm 32 bit binaries. This commit fixes this in the Makefile, which will fix both the local builds, as well as the travis CI and release builds.
fixes#52
* Update docker hub image badge to a working one
previous one simply returned 0.
* Removing 3893 - fixes#50
* Fixing readme MD formatting
* Adding travis_retry to fix against intermittent network outages
* Add TLS options for running both with TLS and without on the same time (#27)
* Add TLS options for running both with TLS and without on the same time.
This commit expands on the settings available for using TLS. It puts TLS settings under the [frontend.tls] section and adds a new setting to [frontend] called TLSExclusive (bool).
TLSExclusive specifies whether or not to only run TLS when it is enabled, and is 'true' by default. Setting it to 'false' and having TLS enabled, causes the server to start both a LDAP and LDAPS server,
and therefore requires to seperate 'listen' options (to run on different ports) - the Frontend.Listen and the Frontend.TLS.Listen. If TLSExclusive is set to 'true' and no Frontend.TLS.Listen is specified, it will use the Frontend.Listen.
* Adding PR template and improving integration test tooling
* Updating formatting
* Add get dependencies step to makefile setup
* Add go 1.11
* Add App Password Support (#60)
App passwords can now be used to allow easier OTP use alongside applications which need to bind with a static password. Use the key `passappsha256` and specify an array of password hashes. See the readme and sample configuration file for more information.
Fixes#54
* Adding NCoC as official project code of conduct
We happily accept contributions based on the merit of the contributions.
* Properly handling paramaters in logs - fixes#64
* Adding ldapsearch for healthchecks