Skip to content

Commit

Permalink
Add LDAP support to /api/session
Browse files Browse the repository at this point in the history
  • Loading branch information
dzaporozhets committed Jul 16, 2013
1 parent a6cfb54 commit 559e83d
Show file tree
Hide file tree
Showing 3 changed files with 24 additions and 21 deletions.
17 changes: 9 additions & 8 deletions lib/api/session.rb
Original file line number Diff line number Diff line change
Expand Up @@ -3,18 +3,19 @@ module API
class Session < Grape::API
# Login to get token
#
# Parameters:
# login (*required) - user login
# email (*required) - user email
# password (required) - user password
#
# Example Request:
# POST /session
post "/session" do
resource = User.find_for_database_authentication(email: params[:email])

return unauthorized! unless resource
auth = Gitlab::Auth.new
user = auth.find(params[:email] || params[:login], params[:password])

if resource.valid_password?(params[:password])
present resource, with: Entities::UserLogin
else
unauthorized!
end
return unauthorized! unless user
present user, with: Entities::UserLogin
end
end
end
13 changes: 13 additions & 0 deletions lib/gitlab/auth.rb
Original file line number Diff line number Diff line change
@@ -1,5 +1,18 @@
module Gitlab
class Auth
def find(login, password)
user = User.find_by_email(login) || User.find_by_username(login)

if user.nil? || user.ldap_user?
# Second chance - try LDAP authentication
return nil unless ldap_conf.enabled

ldap_auth(login, password)
else
user if user.valid_password?(password)
end
end

def find_for_ldap_auth(auth, signed_in_resource = nil)
uid = auth.info.uid
provider = auth.provider
Expand Down
15 changes: 2 additions & 13 deletions lib/gitlab/backend/grack_auth.rb
Original file line number Diff line number Diff line change
Expand Up @@ -64,19 +64,8 @@ def authorized_git_request?
end

def authenticate_user(login, password)
user = User.find_by_email(login) || User.find_by_username(login)

# If the provided login was not a known email or username
# then user is nil
if user.nil? || user.ldap_user?
# Second chance - try LDAP authentication
return nil unless ldap_conf.enabled

auth = Gitlab::Auth.new
auth.ldap_auth(login, password)
else
return user if user.valid_password?(password)
end
auth = Gitlab::Auth.new
auth.find(login, password)
end

def authorize_request(service)
Expand Down

0 comments on commit 559e83d

Please sign in to comment.