LT-103: Authenticate via LDAP

This commit is contained in:
Aysel Afsar committed 2016-03-22 15:43:06 -04:00
1 parent beaa0d4e65
commit 3c60a6dda1
11 files changed
+559 -34

No files matched your search

@@ -16,27 +16,47 @@
<h1 id="signInPageTitle" class="title-auth">Sign In.</h1>
<p id="signInPageMessage" class="subtitle-auth" style="{{getSignInMessageColor}}">{{{getSignInMessage}}}</p>
<form>
<div class="input-symbol">
<input id="signInPageEmailInput" type="text" name="email" placeholder="Your Email" style="{{getEmailValidationStyling}}" />
<i class="fa fa-envelope-o" title="Your Email"></i>
</div>
{{#if isLDAPSet}}
<form>
<div class="input-symbol">
<input id="signInLDAPUsernameInput" type="text" name="email" placeholder="Username" style="{{getEmailValidationStyling}}" />
<i class="fa fa-envelope-o" title="Your Email"></i>
</div>
<br><br>
<div class="input-symbol">
<input id="signInLDAPPasswordInput" type="password" name="password" placeholder="Password" style={{getPasswordValidationStyling}} />
<span class="fa fa-lock" title="Password"></span>
</div>
</form>
<br><br>
<button id="signInLDAPToAppButton" class="btn-primary btn-main btn-large" style="{{getButtonColor}}">{{getButtonText}}</button>
{{else}}
<form>
<div class="input-symbol">
<input id="signInPageEmailInput" type="text" name="email" placeholder="Your Email" style="{{getEmailValidationStyling}}" />
<i class="fa fa-envelope-o" title="Your Email"></i>
</div>
<br><br>
<div class="input-symbol">
<input id="signInPagePasswordInput" type="password" name="password" placeholder="Password" style={{getPasswordValidationStyling}} />
<span class="fa fa-lock" title="Password"></span>
</div>
</form>
<br><br>
<button id="signInToAppButton" class="btn-primary btn-main btn-large disabledButton" disabled style="{{getButtonColor}}">{{getButtonText}}</button>
{{/if}}
<br><br>
<button id="needAnAccountButton" class="btn-gray btn-main btn-large">Need an account?</button>
<div class="input-symbol">
<input id="signInPagePasswordInput" type="password" name="password" placeholder="Password" style={{getPasswordValidationStyling}} />
<span class="fa fa-lock" title="Password"></span>
</div>
</form>
<br><br>
<button id="forgotPasswordButton" class="btn-gray btn-main btn-large">Forgot password?</button>
<br><br>
<button id="signInToAppButton" class="btn-primary btn-main btn-large disabledButton" disabled style="{{getButtonColor}}">{{getButtonText}}</button>
<br><br>
<button id="needAnAccountButton" class="btn-gray btn-main btn-large">Need an account?</button>
<br><br>
<button id="forgotPasswordButton" class="btn-gray btn-main btn-large">Forgot password?</button>
{{/if}}
</div>
@@ -64,6 +64,10 @@ Template.entrySignIn.helpers({
} else {
return "border: 1px solid gray";
}
},
isLDAPSet: function() {
return Session.get('isLDAPSet');
}
});
@@ -134,6 +138,11 @@ Template.entrySignIn.events({
if(event.keyCode == 13) {
$("#signInToAppButton").click();
}
},
'click #signInLDAPToAppButton': function(e, template) {
var username = template.$("#signInLDAPUsernameInput").val();
var password = template.$("#signInLDAPPasswordInput").val();
ActiveEntry.loginWithLDAP(username, password);
}
});
+54 -10
View File
@@ -32,14 +32,8 @@ if (Meteor.isClient) {
passwordExpirationDays: 90,
inactivityPeriodDays: 180
}
});
}
// requireRegexValidation toggles regex
// reqiureStrongPasswords toggles zxcvbn
if (Meteor.isClient) {
ActiveEntry.errorMessages = new ReactiveDict('errorMessages');
ActiveEntry.errorMessages.set('signInError', false);
@@ -48,6 +42,15 @@ if (Meteor.isClient) {
// Change password warning message according to whether zxcvbn is turned on
Session.set('passwordWarning', 'Password must have at least 8 characters. It must contain at least 1 uppercase, 1 lowercase, 1 number and 1 special character.');
Meteor.call('isLDAPSet', function(error, isSet) {
Session.set('isLDAPSet', isSet);
});
}
if (Meteor.isServer) {
LDAP_DEFAULTS.url = Meteor.settings.ldap && Meteor.settings.ldap.url;
LDAP_DEFAULTS.port = Meteor.settings.ldap && Meteor.settings.ldap.port;
}
ActiveEntry.configure = function (configObject) {
@@ -128,6 +131,7 @@ ActiveEntry.signIn = function (emailValue, passwordValue){
ActiveEntry.verifyPassword(passwordValue);
ActiveEntry.verifyEmail(emailValue);
// TODO: Find a solution nested calling
var ActiveEntryConfig = Session.get('Photonic.ActiveEntry');
var failedAttemptsLimit = ActiveEntryConfig && ActiveEntryConfig.passwordOptions && ActiveEntryConfig.passwordOptions.failedAttemptsLimit || 5;
@@ -217,6 +221,44 @@ ActiveEntry.signIn = function (emailValue, passwordValue){
};
ActiveEntry.loginWithLDAP = function(username, password) {
if (!username || !password) {
return;
}
Meteor.loginWithLDAP(username, password, {
// The dn value depends on what you want to search/auth against
// The structure will depend on how your ldap server
// is configured or structured.
dn: "uid=" + username + ",ou=users,ou=system",
// The search value is optional. Set it if your search does not
// work with the bind dn.
searchResultsProfileMap: [
{
resultKey: 'cn',
profileProperty: 'fullName'
},
{
resultKey: 'mail',
profileProperty: 'email'
}
]
}, function(error) {
if (error) {
ActiveEntry.errorMessages.set('signInError', error.errorType+" ["+error.error+"]");
return;
}
ActiveEntry.errorMessages.set('signInError', null);
// Update last login time
Meteor.call("updateLastLoginDate");
var ActiveEntryConfig = Session.get('Photonic.ActiveEntry');
Router.go(ActiveEntryConfig.signIn.destination);
});
};
ActiveEntry.signUp = function (emailValue, passwordValue, confirmPassword, fullName){
ActiveEntry.verifyEmail(emailValue);
ActiveEntry.verifyPassword(passwordValue);
@@ -235,14 +277,16 @@ ActiveEntry.signUp = function (emailValue, passwordValue, confirmPassword, fullN
return;
}
// Capitalize first letter of every word in fullName
var capitalizedFullName = fullName.replace(/[^\s]+/g, function(str){
return str.substr(0,1).toUpperCase()+str.substr(1).toLowerCase();
});
Accounts.createUser({
email: emailValue,
password: passwordValue,
profile: {
fullName: fullName
},
testCase: {
createdAt: new Date()
fullName: capitalizedFullName
}
}, function (error, result) {
if (error) {
+4 -4
View File
@@ -15,7 +15,7 @@ Package.onUse(function (api) {
'clinical:router@2.0.17',
'grove:less@0.1.1',
'session',
'reactive-dict',
'reactive-dict'
//'codetheweb:zxcvbn'
], ['client']);
@@ -25,7 +25,8 @@ Package.onUse(function (api) {
]);
api.use([
'zuuk:stale-session@1.0.8'
'zuuk:stale-session@1.0.8',
'typ:accounts-ldap'
], ['client', 'server']);
api.addFiles([
@@ -60,8 +61,7 @@ Package.onUse(function (api) {
'components/changePassword/changePassword.html',
'components/changePassword/changePassword.js',
'components/changePassword/changePassword.less',
'components/changePassword/changePassword.less'
], ['client']);
+8
View File
@@ -147,6 +147,14 @@ Meteor.methods({
return true;
}
return false;
},
isLDAPSet: function() {
if (LDAP_DEFAULTS.url && LDAP_DEFAULTS.port) {
return true;
}
return false;
}