LT-103: Authenticate via LDAP
This commit is contained in:
1 parent
beaa0d4e65
commit
3c60a6dda1
11 files changed
+559
-34
No files matched your search
@@ -16,27 +16,47 @@
|
||||
<h1 id="signInPageTitle" class="title-auth">Sign In.</h1>
|
||||
<p id="signInPageMessage" class="subtitle-auth" style="{{getSignInMessageColor}}">{{{getSignInMessage}}}</p>
|
||||
|
||||
<form>
|
||||
<div class="input-symbol">
|
||||
<input id="signInPageEmailInput" type="text" name="email" placeholder="Your Email" style="{{getEmailValidationStyling}}" />
|
||||
<i class="fa fa-envelope-o" title="Your Email"></i>
|
||||
</div>
|
||||
{{#if isLDAPSet}}
|
||||
<form>
|
||||
<div class="input-symbol">
|
||||
<input id="signInLDAPUsernameInput" type="text" name="email" placeholder="Username" style="{{getEmailValidationStyling}}" />
|
||||
<i class="fa fa-envelope-o" title="Your Email"></i>
|
||||
</div>
|
||||
<br><br>
|
||||
|
||||
<div class="input-symbol">
|
||||
<input id="signInLDAPPasswordInput" type="password" name="password" placeholder="Password" style={{getPasswordValidationStyling}} />
|
||||
<span class="fa fa-lock" title="Password"></span>
|
||||
</div>
|
||||
</form>
|
||||
|
||||
<br><br>
|
||||
<button id="signInLDAPToAppButton" class="btn-primary btn-main btn-large" style="{{getButtonColor}}">{{getButtonText}}</button>
|
||||
{{else}}
|
||||
<form>
|
||||
<div class="input-symbol">
|
||||
<input id="signInPageEmailInput" type="text" name="email" placeholder="Your Email" style="{{getEmailValidationStyling}}" />
|
||||
<i class="fa fa-envelope-o" title="Your Email"></i>
|
||||
</div>
|
||||
<br><br>
|
||||
|
||||
<div class="input-symbol">
|
||||
<input id="signInPagePasswordInput" type="password" name="password" placeholder="Password" style={{getPasswordValidationStyling}} />
|
||||
<span class="fa fa-lock" title="Password"></span>
|
||||
</div>
|
||||
</form>
|
||||
|
||||
<br><br>
|
||||
<button id="signInToAppButton" class="btn-primary btn-main btn-large disabledButton" disabled style="{{getButtonColor}}">{{getButtonText}}</button>
|
||||
|
||||
{{/if}}
|
||||
<br><br>
|
||||
<button id="needAnAccountButton" class="btn-gray btn-main btn-large">Need an account?</button>
|
||||
|
||||
<div class="input-symbol">
|
||||
<input id="signInPagePasswordInput" type="password" name="password" placeholder="Password" style={{getPasswordValidationStyling}} />
|
||||
<span class="fa fa-lock" title="Password"></span>
|
||||
</div>
|
||||
</form>
|
||||
<br><br>
|
||||
<button id="forgotPasswordButton" class="btn-gray btn-main btn-large">Forgot password?</button>
|
||||
|
||||
<br><br>
|
||||
<button id="signInToAppButton" class="btn-primary btn-main btn-large disabledButton" disabled style="{{getButtonColor}}">{{getButtonText}}</button>
|
||||
|
||||
<br><br>
|
||||
<button id="needAnAccountButton" class="btn-gray btn-main btn-large">Need an account?</button>
|
||||
|
||||
<br><br>
|
||||
<button id="forgotPasswordButton" class="btn-gray btn-main btn-large">Forgot password?</button>
|
||||
|
||||
{{/if}}
|
||||
</div>
|
||||
|
||||
@@ -64,6 +64,10 @@ Template.entrySignIn.helpers({
|
||||
} else {
|
||||
return "border: 1px solid gray";
|
||||
}
|
||||
},
|
||||
|
||||
isLDAPSet: function() {
|
||||
return Session.get('isLDAPSet');
|
||||
}
|
||||
|
||||
});
|
||||
@@ -134,6 +138,11 @@ Template.entrySignIn.events({
|
||||
if(event.keyCode == 13) {
|
||||
$("#signInToAppButton").click();
|
||||
}
|
||||
},
|
||||
'click #signInLDAPToAppButton': function(e, template) {
|
||||
var username = template.$("#signInLDAPUsernameInput").val();
|
||||
var password = template.$("#signInLDAPPasswordInput").val();
|
||||
ActiveEntry.loginWithLDAP(username, password);
|
||||
}
|
||||
});
|
||||
|
||||
|
||||
@@ -32,14 +32,8 @@ if (Meteor.isClient) {
|
||||
passwordExpirationDays: 90,
|
||||
inactivityPeriodDays: 180
|
||||
}
|
||||
|
||||
});
|
||||
}
|
||||
|
||||
// requireRegexValidation toggles regex
|
||||
// reqiureStrongPasswords toggles zxcvbn
|
||||
|
||||
if (Meteor.isClient) {
|
||||
ActiveEntry.errorMessages = new ReactiveDict('errorMessages');
|
||||
ActiveEntry.errorMessages.set('signInError', false);
|
||||
|
||||
@@ -48,6 +42,15 @@ if (Meteor.isClient) {
|
||||
|
||||
// Change password warning message according to whether zxcvbn is turned on
|
||||
Session.set('passwordWarning', 'Password must have at least 8 characters. It must contain at least 1 uppercase, 1 lowercase, 1 number and 1 special character.');
|
||||
|
||||
Meteor.call('isLDAPSet', function(error, isSet) {
|
||||
Session.set('isLDAPSet', isSet);
|
||||
});
|
||||
}
|
||||
|
||||
if (Meteor.isServer) {
|
||||
LDAP_DEFAULTS.url = Meteor.settings.ldap && Meteor.settings.ldap.url;
|
||||
LDAP_DEFAULTS.port = Meteor.settings.ldap && Meteor.settings.ldap.port;
|
||||
}
|
||||
|
||||
ActiveEntry.configure = function (configObject) {
|
||||
@@ -128,6 +131,7 @@ ActiveEntry.signIn = function (emailValue, passwordValue){
|
||||
|
||||
ActiveEntry.verifyPassword(passwordValue);
|
||||
ActiveEntry.verifyEmail(emailValue);
|
||||
// TODO: Find a solution nested calling
|
||||
|
||||
var ActiveEntryConfig = Session.get('Photonic.ActiveEntry');
|
||||
var failedAttemptsLimit = ActiveEntryConfig && ActiveEntryConfig.passwordOptions && ActiveEntryConfig.passwordOptions.failedAttemptsLimit || 5;
|
||||
@@ -217,6 +221,44 @@ ActiveEntry.signIn = function (emailValue, passwordValue){
|
||||
|
||||
};
|
||||
|
||||
ActiveEntry.loginWithLDAP = function(username, password) {
|
||||
if (!username || !password) {
|
||||
return;
|
||||
}
|
||||
|
||||
Meteor.loginWithLDAP(username, password, {
|
||||
// The dn value depends on what you want to search/auth against
|
||||
// The structure will depend on how your ldap server
|
||||
// is configured or structured.
|
||||
dn: "uid=" + username + ",ou=users,ou=system",
|
||||
// The search value is optional. Set it if your search does not
|
||||
// work with the bind dn.
|
||||
searchResultsProfileMap: [
|
||||
{
|
||||
resultKey: 'cn',
|
||||
profileProperty: 'fullName'
|
||||
},
|
||||
{
|
||||
resultKey: 'mail',
|
||||
profileProperty: 'email'
|
||||
}
|
||||
]
|
||||
}, function(error) {
|
||||
if (error) {
|
||||
ActiveEntry.errorMessages.set('signInError', error.errorType+" ["+error.error+"]");
|
||||
return;
|
||||
}
|
||||
ActiveEntry.errorMessages.set('signInError', null);
|
||||
|
||||
// Update last login time
|
||||
Meteor.call("updateLastLoginDate");
|
||||
|
||||
var ActiveEntryConfig = Session.get('Photonic.ActiveEntry');
|
||||
Router.go(ActiveEntryConfig.signIn.destination);
|
||||
|
||||
});
|
||||
};
|
||||
|
||||
ActiveEntry.signUp = function (emailValue, passwordValue, confirmPassword, fullName){
|
||||
ActiveEntry.verifyEmail(emailValue);
|
||||
ActiveEntry.verifyPassword(passwordValue);
|
||||
@@ -235,14 +277,16 @@ ActiveEntry.signUp = function (emailValue, passwordValue, confirmPassword, fullN
|
||||
return;
|
||||
}
|
||||
|
||||
// Capitalize first letter of every word in fullName
|
||||
var capitalizedFullName = fullName.replace(/[^\s]+/g, function(str){
|
||||
return str.substr(0,1).toUpperCase()+str.substr(1).toLowerCase();
|
||||
});
|
||||
|
||||
Accounts.createUser({
|
||||
email: emailValue,
|
||||
password: passwordValue,
|
||||
profile: {
|
||||
fullName: fullName
|
||||
},
|
||||
testCase: {
|
||||
createdAt: new Date()
|
||||
fullName: capitalizedFullName
|
||||
}
|
||||
}, function (error, result) {
|
||||
if (error) {
|
||||
|
||||
@@ -15,7 +15,7 @@ Package.onUse(function (api) {
|
||||
'clinical:router@2.0.17',
|
||||
'grove:less@0.1.1',
|
||||
'session',
|
||||
'reactive-dict',
|
||||
'reactive-dict'
|
||||
//'codetheweb:zxcvbn'
|
||||
], ['client']);
|
||||
|
||||
@@ -25,7 +25,8 @@ Package.onUse(function (api) {
|
||||
]);
|
||||
|
||||
api.use([
|
||||
'zuuk:stale-session@1.0.8'
|
||||
'zuuk:stale-session@1.0.8',
|
||||
'typ:accounts-ldap'
|
||||
], ['client', 'server']);
|
||||
|
||||
api.addFiles([
|
||||
@@ -60,8 +61,7 @@ Package.onUse(function (api) {
|
||||
|
||||
'components/changePassword/changePassword.html',
|
||||
'components/changePassword/changePassword.js',
|
||||
'components/changePassword/changePassword.less',
|
||||
|
||||
'components/changePassword/changePassword.less'
|
||||
], ['client']);
|
||||
|
||||
|
||||
|
||||
@@ -147,6 +147,14 @@ Meteor.methods({
|
||||
return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
},
|
||||
|
||||
isLDAPSet: function() {
|
||||
if (LDAP_DEFAULTS.url && LDAP_DEFAULTS.port) {
|
||||
return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user