pub struct LdapAuthPlugin {
base_dn: String,
ldap_uri: String,
uid: String,
use_tls: bool,
tls_verify: bool,
realm: Template,
timeout: Duration,
}Expand description
Authenticates HTTP Basic credentials against an LDAP server via simple bind.
Fields§
§base_dn: StringBase DN the bind DN is built under (e.g. ou=users,dc=example,dc=org).
ldap_uri: StringLDAP server URI (ldap://host:389 or ldaps://host:636).
uid: StringRDN attribute for the bind DN (APISIX uid, default cn).
use_tls: boolWhen true, negotiate StartTLS on the connection.
tls_verify: boolWhen false, TLS certificate verification is disabled.
realm: TemplateRealm advertised in the WWW-Authenticate challenge. Supports
{{namespace.path}} references (no legacy $var interpolation —
realm never supported it, so this sweep must not start).
timeout: DurationWhole-operation deadline for the connect + bind.
Implementations§
Source§impl LdapAuthPlugin
impl LdapAuthPlugin
Sourcepub fn from_config(
config: &HashMap<String, Value>,
_resources: &Arc<PluginResources>,
) -> Result<Self, String>
pub fn from_config( config: &HashMap<String, Value>, _resources: &Arc<PluginResources>, ) -> Result<Self, String>
Builds the plugin from node config.
Accepted keys:
base_dn(string, required): base DN the bind DN is built under.ldap_uri(string, required): LDAP server URI, e.g.ldap://ldap.example.org:389.uid(string, default"cn"): RDN attribute prefixing the username in the bind DN.use_tls(bool, defaultfalse): negotiate StartTLS after connecting.tls_verify(bool, defaultfalse): verify the server certificate.realm(string, default"ldap"): realm in the challenge header; supports{{namespace.path}}references.timeout_ms(u64, default10000): connect + bind deadline.
type: ldap-auth
config:
base_dn: ou=users,dc=example,dc=org
ldap_uri: ldap://ldap.example.org:389
uid: cn
use_tls: false
tls_verify: falseSourcefn reject(
&self,
ctx: Context,
message: &str,
) -> Result<PluginOutput, PluginExecutionError>
fn reject( &self, ctx: Context, message: &str, ) -> Result<PluginOutput, PluginExecutionError>
Builds the 401 rejection carrying the WWW-Authenticate: Basic
challenge and exits on the node’s denied port. Reserved for
deliberate credential rejections — a missing/malformed header, empty
credentials, or a bind the server actively refused.
Sourcefn infra_error(
&self,
ctx: Context,
message: String,
) -> Result<PluginOutput, PluginExecutionError>
fn infra_error( &self, ctx: Context, message: String, ) -> Result<PluginOutput, PluginExecutionError>
Builds a genuine infrastructure-failure Err (LDAP unreachable, or the
connect+bind operation timed out) — unlike reject, this exits
through the error port because the node could not do its job, not
because a presented credential was deliberately refused. The prepared
response is the shared 502 provider_error shape: no Basic
challenge, so a browser does not re-prompt for a password that was
never checked.
Trait Implementations§
Source§impl Plugin for LdapAuthPlugin
impl Plugin for LdapAuthPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Source§fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
Source§fn reads_response_body(&self) -> bool
fn reads_response_body(&self) -> bool
context.response.body. Read moreSource§fn cache_target(&self) -> Option<CacheTarget>
fn cache_target(&self) -> Option<CacheTarget>
proxy-cache half. Read moreAuto Trait Implementations§
impl Freeze for LdapAuthPlugin
impl RefUnwindSafe for LdapAuthPlugin
impl Send for LdapAuthPlugin
impl Sync for LdapAuthPlugin
impl Unpin for LdapAuthPlugin
impl UnsafeUnpin for LdapAuthPlugin
impl UnwindSafe for LdapAuthPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more