Files
ldap-auth-service/server.js
2026-08-20 11:50:00 +05:00

117 lines
3.6 KiB
JavaScript

'use strict';
const path = require('path');
const express = require('express');
const config = require('./lib/config');
const ldapClient = require('./lib/ldapClient');
const adminApi = require('./lib/adminApi');
const app = express();
app.use(express.json());
app.use(express.static(path.join(__dirname, 'public')));
function corsHeaders(res) {
res.setHeader('Access-Control-Allow-Origin', '*');
res.setHeader('Access-Control-Allow-Methods', 'GET, POST, PUT, OPTIONS');
res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization');
}
app.use((req, res, next) => {
corsHeaders(res);
if (req.method === 'OPTIONS') return res.sendStatus(204);
next();
});
app.get('/', (req, res) => res.redirect(302, '/auth'));
app.get('/auth', (req, res) => {
res.sendFile(path.join(__dirname, 'public', 'auth.html'));
});
app.get('/admin', (req, res) => {
res.sendFile(path.join(__dirname, 'public', 'admin.html'));
});
app.get('/health', async (req, res) => {
try {
await ldapClient.testConnection();
res.json({ status: 'ok', ldap: 'connected' });
} catch (err) {
res.status(503).json({ status: 'error', error: err.message });
}
});
app.get('/status', (req, res) => {
res.json({
status: 'running',
service: 'LDAP Auth',
ldap_url: config.ldapUrl,
base_dn: config.baseDN,
timestamp: new Date().toISOString()
});
});
app.post('/api/auth', async (req, res) => {
const { username, password } = req.body || {};
const all = req.query.all === '1';
const description = req.query.description === '1';
const groups = req.query.groups === '1';
const modeCount = [all, description, groups].filter(Boolean).length;
if (modeCount > 1) {
return res.status(400).json({ success: false, error: 'Conflicting parameters: use only one of description=1, groups=1, or all=1' });
}
if (!username) {
return res.status(400).json({ success: false, error: 'Username is required' });
}
let mode = 'basic';
if (description) mode = 'description';
else if (groups) mode = 'groups';
else if (all) mode = 'all';
try {
const result = await ldapClient.authenticate(username, password, mode);
res.json(result);
} catch (err) {
res.status(err.status || 401).json({ success: false, error: err.message });
}
});
app.use('/api/admin', adminApi);
app.use((err, req, res, next) => {
const status = err.status || err.statusCode || 500;
if (status >= 500) console.error(err);
res.status(status).json({ success: false, error: status >= 500 ? 'Внутренняя ошибка сервера' : (err.message || 'Некорректный запрос') });
});
async function main() {
console.log('=== LDAP Auth Service Starting ===');
console.log(`LDAP URL: ${config.ldapUrl}`);
console.log(`Base DN: ${config.baseDN}`);
console.log(`Admin: ${config.adminLogin || '(not set)'}`);
console.log(`Port: ${config.port}`);
console.log('==================================');
if (!config.adminLogin || !config.adminPassword) {
console.warn('⚠ ADMIN_LOGIN / ADMIN_PASSWORD not set in .env - admin panel disabled');
} else {
try {
await ldapClient.testConnection();
console.log('✓ LDAP connection test passed');
} catch (err) {
console.warn(`⚠ LDAP connection test failed: ${err.message}`);
}
}
app.listen(config.port, () => {
console.log(`🚀 Server running on http://localhost:${config.port}`);
console.log(`🌐 Web auth: http://localhost:${config.port}/auth`);
console.log(`🛠 Admin panel: http://localhost:${config.port}/admin`);
console.log(`📊 Health: http://localhost:${config.port}/health`);
});
}
main();