Coverage for src/backend/InvenTree/InvenTree/setting/ldap.py: 6%
26 statements
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 17:47 +0000
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-07 17:47 +0000
1"""Configuration of LDAP support for InvenTree."""
3from InvenTree.config import get_boolean_setting, get_setting
6def get_ldap_config(debug: bool = False) -> dict:
7 """Return a dictionary of LDAP configuration settings.
9 The returned settings will be updated into the globals() object,
10 and will be used to configure the LDAP authentication backend.
11 """
12 import django_auth_ldap.config # ty: ignore[unresolved-import]
13 import ldap # ty: ignore[unresolved-import]
15 # get global options from dict and use ldap.OPT_* as keys and values
16 global_options_dict = get_setting(
17 'INVENTREE_LDAP_GLOBAL_OPTIONS',
18 'ldap.global_options',
19 default_value=None,
20 typecast=dict,
21 )
23 global_options = {}
25 for k, v in global_options_dict.items():
26 # keys are always ldap.OPT_* constants
27 k_attr = getattr(ldap, k, None)
28 if not k.startswith('OPT_') or k_attr is None:
29 print(f"[LDAP] ldap.global_options, key '{k}' not found, skipping...")
30 continue
32 # values can also be other strings, e.g. paths
33 v_attr = v
34 if v.startswith('OPT_'):
35 v_attr = getattr(ldap, v, None)
37 if v_attr is None:
38 print(f"[LDAP] ldap.global_options, value key '{v}' not found, skipping...")
39 continue
41 global_options[k_attr] = v_attr
43 if debug:
44 print('[LDAP] ldap.global_options =', global_options)
46 group_type_class = get_setting(
47 'INVENTREE_LDAP_GROUP_TYPE_CLASS',
48 'ldap.group_type_class',
49 'GroupOfUniqueNamesType',
50 str,
51 )
53 group_type_class_args = get_setting(
54 'INVENTREE_LDAP_GROUP_TYPE_CLASS_ARGS', 'ldap.group_type_class_args', [], list
55 )
57 group_type_class_kwargs = get_setting(
58 'INVENTREE_LDAP_GROUP_TYPE_CLASS_KWARGS',
59 'ldap.group_type_class_kwargs',
60 {'name_attr': 'cn'},
61 dict,
62 )
64 group_object_class = get_setting(
65 'INVENTREE_LDAP_GROUP_OBJECT_CLASS',
66 'ldap.group_object_class',
67 'groupOfUniqueNames',
68 str,
69 )
71 ldap_config = {
72 'AUTH_LDAP_GLOBAL_OPTIONS': global_options,
73 'AUTH_LDAP_SERVER_URI': get_setting(
74 'INVENTREE_LDAP_SERVER_URI', 'ldap.server_uri'
75 ),
76 'AUTH_LDAP_START_TLS': get_boolean_setting(
77 'INVENTREE_LDAP_START_TLS', 'ldap.start_tls', False
78 ),
79 'AUTH_LDAP_BIND_DN': get_setting('INVENTREE_LDAP_BIND_DN', 'ldap.bind_dn'),
80 'AUTH_LDAP_BIND_PASSWORD': get_setting(
81 'INVENTREE_LDAP_BIND_PASSWORD', 'ldap.bind_password'
82 ),
83 'AUTH_LDAP_USER_SEARCH': django_auth_ldap.config.LDAPSearch(
84 get_setting('INVENTREE_LDAP_SEARCH_BASE_DN', 'ldap.search_base_dn'),
85 ldap.SCOPE_SUBTREE,
86 str(
87 get_setting(
88 'INVENTREE_LDAP_SEARCH_FILTER_STR',
89 'ldap.search_filter_str',
90 '(uid= %(user)s)',
91 )
92 ),
93 ),
94 'AUTH_LDAP_USER_DN_TEMPLATE': get_setting(
95 'INVENTREE_LDAP_USER_DN_TEMPLATE', 'ldap.user_dn_template'
96 ),
97 'AUTH_LDAP_USER_ATTR_MAP': get_setting(
98 'INVENTREE_LDAP_USER_ATTR_MAP',
99 'ldap.user_attr_map',
100 {'first_name': 'givenName', 'last_name': 'sn', 'email': 'mail'},
101 dict,
102 ),
103 'AUTH_LDAP_ALWAYS_UPDATE_USER': get_boolean_setting(
104 'INVENTREE_LDAP_ALWAYS_UPDATE_USER', 'ldap.always_update_user', True
105 ),
106 'AUTH_LDAP_CACHE_TIMEOUT': get_setting(
107 'INVENTREE_LDAP_CACHE_TIMEOUT', 'ldap.cache_timeout', 3600, int
108 ),
109 'AUTH_LDAP_MIRROR_GROUPS': get_boolean_setting(
110 'INVENTREE_LDAP_MIRROR_GROUPS', 'ldap.mirror_groups', False
111 ),
112 'AUTH_LDAP_GROUP_OBJECT_CLASS': group_object_class,
113 'AUTH_LDAP_GROUP_SEARCH': django_auth_ldap.config.LDAPSearch(
114 get_setting('INVENTREE_LDAP_GROUP_SEARCH', 'ldap.group_search'),
115 ldap.SCOPE_SUBTREE,
116 f'(objectClass={group_object_class})',
117 ),
118 'AUTH_LDAP_GROUP_TYPE_CLASS': group_type_class,
119 'AUTH_LDAP_GROUP_TYPE_CLASS_ARGS': [*group_type_class_args],
120 'AUTH_LDAP_GROUP_TYPE_CLASS_KWARGS': {**group_type_class_kwargs},
121 'AUTH_LDAP_GROUP_TYPE': getattr(django_auth_ldap.config, group_type_class)(
122 *group_type_class_args, **group_type_class_kwargs
123 ),
124 'AUTH_LDAP_REQUIRE_GROUP': get_setting(
125 'INVENTREE_LDAP_REQUIRE_GROUP', 'ldap.require_group'
126 ),
127 'AUTH_LDAP_DENY_GROUP': get_setting(
128 'INVENTREE_LDAP_DENY_GROUP', 'ldap.deny_group'
129 ),
130 'AUTH_LDAP_USER_FLAGS_BY_GROUP': get_setting(
131 'INVENTREE_LDAP_USER_FLAGS_BY_GROUP',
132 'ldap.user_flags_by_group',
133 default_value=None,
134 typecast=dict,
135 ),
136 'AUTH_LDAP_FIND_GROUP_PERMS': True,
137 }
139 return ldap_config