passport.js 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128
  1. const debug = require('debug')('crowi:service:PassportService');
  2. const passport = require('passport');
  3. const LocalStrategy = require('passport-local').Strategy;
  4. const LdapStrategy = require('passport-ldapauth');
  5. /**
  6. * the service class of Passport
  7. */
  8. class PassportService {
  9. // see '/lib/form/login.js'
  10. static get USERNAME_FIELD() { return 'loginForm[username]' }
  11. static get PASSWORD_FIELD() { return 'loginForm[password]' }
  12. constructor(crowi) {
  13. this.crowi = crowi;
  14. }
  15. /**
  16. * setup LocalStrategy
  17. *
  18. * @memberof PassportService
  19. */
  20. setupLocalStrategy() {
  21. debug('setup LocalStrategy');
  22. const User = this.crowi.model('User');
  23. passport.use(new LocalStrategy(
  24. {
  25. usernameField: PassportService.USERNAME_FIELD,
  26. passwordField: PassportService.PASSWORD_FIELD,
  27. },
  28. (username, password, done) => {
  29. // find user
  30. User.findUserByUsernameOrEmail(username, password, (err, user) => {
  31. if (err) { return done(err); }
  32. // check existence and password
  33. if (!user || !user.isPasswordValid(password)) {
  34. return done(null, false, { message: 'Incorrect credentials.' });
  35. }
  36. return done(null, user);
  37. });
  38. }
  39. ));
  40. }
  41. /*
  42. * Asynchronous configuration retrieval
  43. */
  44. // setupLdapStrategy() {
  45. // var getLDAPConfiguration = function(req, callback) {
  46. // var loginForm = req.body.loginForm;
  47. // if (!req.form.isValid) {
  48. // // TODO handle error
  49. // }
  50. // var username = loginForm.username;
  51. // var password = loginForm.password;
  52. // process.nextTick(() => {
  53. // var opts = {
  54. // usernameField: PassportService.USERNAME_FIELD,
  55. // passwordField: PassportService.PASSWORD_FIELD,
  56. // server: {
  57. // url: 'ldaps://pike.weseek.co.jp',
  58. // bindDN: `uid=${username}`,
  59. // bindCredentials: password,
  60. // searchBase: 'ou=people',
  61. // searchFilter: '(uid={{username}})'
  62. // }
  63. // };
  64. // callback(null, opts);
  65. // });
  66. // };
  67. // passport.use(new LdapStrategy(getLDAPConfiguration,
  68. // (user, done) => {
  69. // debug("LDAP authentication has successed");
  70. // return done(null, user);
  71. // }
  72. // ));
  73. // }
  74. setupLdapStrategy() {
  75. passport.use(new LdapStrategy(
  76. {
  77. usernameField: PassportService.USERNAME_FIELD,
  78. passwordField: PassportService.PASSWORD_FIELD,
  79. server: {
  80. url: 'ldaps://localhost',
  81. bindDN: `cn=...,dc=weseek,dc=co,dc=jp`,
  82. bindCredentials: 'secret',
  83. searchBase: 'ou=...,dc=weseek,dc=co,dc=jp',
  84. searchFilter: '(uid={{username}})'
  85. },
  86. },
  87. (user, done) => {
  88. debug("LDAP authentication has succeeded");
  89. return done(null, user);
  90. }
  91. ));
  92. }
  93. /**
  94. * setup serializer and deserializer
  95. *
  96. * @memberof PassportService
  97. */
  98. setupSerializer() {
  99. debug('setup serializer and deserializer');
  100. const User = this.crowi.model('User');
  101. passport.serializeUser(function(user, done) {
  102. done(null, user.id);
  103. });
  104. passport.deserializeUser(function(id, done) {
  105. User.findById(id, function(err, user) {
  106. done(err, user);
  107. });
  108. });
  109. }
  110. }
  111. module.exports = PassportService;