pub struct LdapAuthPlugin {
base_dn: String,
ldap_uri: String,
uid: String,
use_tls: bool,
tls_verify: bool,
realm: String,
timeout: Duration,
}Expand description
Authenticates HTTP Basic credentials against an LDAP server via simple bind.
Fields§
§base_dn: StringBase DN the bind DN is built under (e.g. ou=users,dc=example,dc=org).
ldap_uri: StringLDAP server URI (ldap://host:389 or ldaps://host:636).
uid: StringRDN attribute for the bind DN (APISIX uid, default cn).
use_tls: boolWhen true, negotiate StartTLS on the connection.
tls_verify: boolWhen false, TLS certificate verification is disabled.
realm: StringRealm advertised in the WWW-Authenticate challenge.
timeout: DurationWhole-operation deadline for the connect + bind.
Implementations§
Source§impl LdapAuthPlugin
impl LdapAuthPlugin
Sourcepub fn from_config(
config: &HashMap<String, Value>,
_resources: &Arc<PluginResources>,
) -> Result<Self, String>
pub fn from_config( config: &HashMap<String, Value>, _resources: &Arc<PluginResources>, ) -> Result<Self, String>
Builds the plugin from node config.
Accepted keys:
base_dn(string, required): base DN the bind DN is built under.ldap_uri(string, required): LDAP server URI, e.g.ldap://ldap.example.org:389.uid(string, default"cn"): RDN attribute prefixing the username in the bind DN.use_tls(bool, defaultfalse): negotiate StartTLS after connecting.tls_verify(bool, defaultfalse): verify the server certificate.realm(string, default"ldap"): realm in the challenge header.timeout_ms(u64, default10000): connect + bind deadline.
type: ldap-auth
config:
base_dn: ou=users,dc=example,dc=org
ldap_uri: ldap://ldap.example.org:389
uid: cn
use_tls: false
tls_verify: falseSourcefn reject(
&self,
ctx: Context,
message: &str,
) -> Result<PluginOutput, PluginExecutionError>
fn reject( &self, ctx: Context, message: &str, ) -> Result<PluginOutput, PluginExecutionError>
Builds the 401 rejection carrying the WWW-Authenticate: Basic challenge
and routes the context through the node’s error port.
Trait Implementations§
Source§impl Plugin for LdapAuthPlugin
impl Plugin for LdapAuthPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Unique identifier for the plugin type (e.g., “proxy-rewrite”, “upstream”).
Source§fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Executes the plugin logic against the request/response context. Read more
Auto Trait Implementations§
impl Freeze for LdapAuthPlugin
impl RefUnwindSafe for LdapAuthPlugin
impl Send for LdapAuthPlugin
impl Sync for LdapAuthPlugin
impl Unpin for LdapAuthPlugin
impl UnsafeUnpin for LdapAuthPlugin
impl UnwindSafe for LdapAuthPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more