1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
1 |
# IVLE - Informatics Virtual Learning Environment
|
2 |
# Copyright (C) 2007-2008 The University of Melbourne
|
|
3 |
#
|
|
4 |
# This program is free software; you can redistribute it and/or modify
|
|
5 |
# it under the terms of the GNU General Public License as published by
|
|
6 |
# the Free Software Foundation; either version 2 of the License, or
|
|
7 |
# (at your option) any later version.
|
|
8 |
#
|
|
9 |
# This program is distributed in the hope that it will be useful,
|
|
10 |
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
11 |
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
12 |
# GNU General Public License for more details.
|
|
13 |
#
|
|
14 |
# You should have received a copy of the GNU General Public License
|
|
15 |
# along with this program; if not, write to the Free Software
|
|
16 |
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
|
17 |
||
18 |
# Module: LDAP Authenticate
|
|
19 |
# Author: Matt Giuca
|
|
20 |
# Date: 21/2/2008
|
|
21 |
||
22 |
# Pluggable authentication module for LDAP servers.
|
|
23 |
# This will read the ldap_url and ldap_format_string config variables.
|
|
24 |
# This module is NOT active implicitly - it must be specified in the
|
|
25 |
# "auth_modules" config string.
|
|
26 |
# However, setup.py should configure it in auth_modules by default.
|
|
27 |
||
28 |
import ldap |
|
29 |
||
1080.1.12
by me at id
ivle.auth.autherror: Remove, moving AuthError into ivle.auth itself. |
30 |
from ivle.auth import AuthError |
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
31 |
import ivle.conf |
32 |
||
1080.1.14
by me at id
ivle.auth.* now uses Storm, and not ivle.(db|user). This changes the interface |
33 |
def auth(store, login, password, user): |
1079
by William Grant
Merge setup-refactor branch. This completely breaks existing installations; |
34 |
"""
|
35 |
A plugin auth function, as described above.
|
|
36 |
This one authenticates against an LDAP server.
|
|
37 |
Returns user if successful. Raises AuthError if unsuccessful.
|
|
38 |
Also raises AuthError if the LDAP server had an unexpected error.
|
|
39 |
"""
|
|
40 |
try: |
|
41 |
l = ldap.initialize(ivle.conf.ldap_url) |
|
42 |
# ldap_format_string contains a "%s" to put the login name
|
|
43 |
l.simple_bind_s(ivle.conf.ldap_format_string % login, password) |
|
44 |
except ldap.INVALID_CREDENTIALS: |
|
45 |
raise AuthError() |
|
46 |
except Exception, msg: |
|
47 |
raise AuthError("Internal error (LDAP auth): %s" % repr(msg)) |
|
48 |
# Got here - Must have successfully authenticated with LDAP
|
|
49 |
return user |
|
50 |