Coverage for src/backend/InvenTree/InvenTree/setting/ldap.py: 6%

26 statements  

« prev     ^ index     » next       coverage.py v7.15.2, created at 2026-10-07 17:47 +0000

1"""Configuration of LDAP support for InvenTree.""" 

2 

3from InvenTree.config import get_boolean_setting, get_setting 

4 

5 

6def get_ldap_config(debug: bool = False) -> dict: 

7 """Return a dictionary of LDAP configuration settings. 

8 

9 The returned settings will be updated into the globals() object, 

10 and will be used to configure the LDAP authentication backend. 

11 """ 

12 import django_auth_ldap.config # ty: ignore[unresolved-import] 

13 import ldap # ty: ignore[unresolved-import] 

14 

15 # get global options from dict and use ldap.OPT_* as keys and values 

16 global_options_dict = get_setting( 

17 'INVENTREE_LDAP_GLOBAL_OPTIONS', 

18 'ldap.global_options', 

19 default_value=None, 

20 typecast=dict, 

21 ) 

22 

23 global_options = {} 

24 

25 for k, v in global_options_dict.items(): 

26 # keys are always ldap.OPT_* constants 

27 k_attr = getattr(ldap, k, None) 

28 if not k.startswith('OPT_') or k_attr is None: 

29 print(f"[LDAP] ldap.global_options, key '{k}' not found, skipping...") 

30 continue 

31 

32 # values can also be other strings, e.g. paths 

33 v_attr = v 

34 if v.startswith('OPT_'): 

35 v_attr = getattr(ldap, v, None) 

36 

37 if v_attr is None: 

38 print(f"[LDAP] ldap.global_options, value key '{v}' not found, skipping...") 

39 continue 

40 

41 global_options[k_attr] = v_attr 

42 

43 if debug: 

44 print('[LDAP] ldap.global_options =', global_options) 

45 

46 group_type_class = get_setting( 

47 'INVENTREE_LDAP_GROUP_TYPE_CLASS', 

48 'ldap.group_type_class', 

49 'GroupOfUniqueNamesType', 

50 str, 

51 ) 

52 

53 group_type_class_args = get_setting( 

54 'INVENTREE_LDAP_GROUP_TYPE_CLASS_ARGS', 'ldap.group_type_class_args', [], list 

55 ) 

56 

57 group_type_class_kwargs = get_setting( 

58 'INVENTREE_LDAP_GROUP_TYPE_CLASS_KWARGS', 

59 'ldap.group_type_class_kwargs', 

60 {'name_attr': 'cn'}, 

61 dict, 

62 ) 

63 

64 group_object_class = get_setting( 

65 'INVENTREE_LDAP_GROUP_OBJECT_CLASS', 

66 'ldap.group_object_class', 

67 'groupOfUniqueNames', 

68 str, 

69 ) 

70 

71 ldap_config = { 

72 'AUTH_LDAP_GLOBAL_OPTIONS': global_options, 

73 'AUTH_LDAP_SERVER_URI': get_setting( 

74 'INVENTREE_LDAP_SERVER_URI', 'ldap.server_uri' 

75 ), 

76 'AUTH_LDAP_START_TLS': get_boolean_setting( 

77 'INVENTREE_LDAP_START_TLS', 'ldap.start_tls', False 

78 ), 

79 'AUTH_LDAP_BIND_DN': get_setting('INVENTREE_LDAP_BIND_DN', 'ldap.bind_dn'), 

80 'AUTH_LDAP_BIND_PASSWORD': get_setting( 

81 'INVENTREE_LDAP_BIND_PASSWORD', 'ldap.bind_password' 

82 ), 

83 'AUTH_LDAP_USER_SEARCH': django_auth_ldap.config.LDAPSearch( 

84 get_setting('INVENTREE_LDAP_SEARCH_BASE_DN', 'ldap.search_base_dn'), 

85 ldap.SCOPE_SUBTREE, 

86 str( 

87 get_setting( 

88 'INVENTREE_LDAP_SEARCH_FILTER_STR', 

89 'ldap.search_filter_str', 

90 '(uid= %(user)s)', 

91 ) 

92 ), 

93 ), 

94 'AUTH_LDAP_USER_DN_TEMPLATE': get_setting( 

95 'INVENTREE_LDAP_USER_DN_TEMPLATE', 'ldap.user_dn_template' 

96 ), 

97 'AUTH_LDAP_USER_ATTR_MAP': get_setting( 

98 'INVENTREE_LDAP_USER_ATTR_MAP', 

99 'ldap.user_attr_map', 

100 {'first_name': 'givenName', 'last_name': 'sn', 'email': 'mail'}, 

101 dict, 

102 ), 

103 'AUTH_LDAP_ALWAYS_UPDATE_USER': get_boolean_setting( 

104 'INVENTREE_LDAP_ALWAYS_UPDATE_USER', 'ldap.always_update_user', True 

105 ), 

106 'AUTH_LDAP_CACHE_TIMEOUT': get_setting( 

107 'INVENTREE_LDAP_CACHE_TIMEOUT', 'ldap.cache_timeout', 3600, int 

108 ), 

109 'AUTH_LDAP_MIRROR_GROUPS': get_boolean_setting( 

110 'INVENTREE_LDAP_MIRROR_GROUPS', 'ldap.mirror_groups', False 

111 ), 

112 'AUTH_LDAP_GROUP_OBJECT_CLASS': group_object_class, 

113 'AUTH_LDAP_GROUP_SEARCH': django_auth_ldap.config.LDAPSearch( 

114 get_setting('INVENTREE_LDAP_GROUP_SEARCH', 'ldap.group_search'), 

115 ldap.SCOPE_SUBTREE, 

116 f'(objectClass={group_object_class})', 

117 ), 

118 'AUTH_LDAP_GROUP_TYPE_CLASS': group_type_class, 

119 'AUTH_LDAP_GROUP_TYPE_CLASS_ARGS': [*group_type_class_args], 

120 'AUTH_LDAP_GROUP_TYPE_CLASS_KWARGS': {**group_type_class_kwargs}, 

121 'AUTH_LDAP_GROUP_TYPE': getattr(django_auth_ldap.config, group_type_class)( 

122 *group_type_class_args, **group_type_class_kwargs 

123 ), 

124 'AUTH_LDAP_REQUIRE_GROUP': get_setting( 

125 'INVENTREE_LDAP_REQUIRE_GROUP', 'ldap.require_group' 

126 ), 

127 'AUTH_LDAP_DENY_GROUP': get_setting( 

128 'INVENTREE_LDAP_DENY_GROUP', 'ldap.deny_group' 

129 ), 

130 'AUTH_LDAP_USER_FLAGS_BY_GROUP': get_setting( 

131 'INVENTREE_LDAP_USER_FLAGS_BY_GROUP', 

132 'ldap.user_flags_by_group', 

133 default_value=None, 

134 typecast=dict, 

135 ), 

136 'AUTH_LDAP_FIND_GROUP_PERMS': True, 

137 } 

138 

139 return ldap_config