Skip to content

Conversation

smayya337
Copy link
Member

Proposed changes

  • Create TJHSSTLDAPBackend, a new LDAP backend that authenticates against FreeIPA
  • Remove PamAuthenticationBackend in favor of TJHSSTLDAPBackend
  • Make TJHSSTLDAPBackend higher priority than MasterPasswordAuthenticationBackend in order to allow for auto-creation in all scenarios

Brief description of rationale

This will further streamline the account creation process by removing the need to create Ion accounts separately from FreeIPA accounts.

Please look over/test this carefully for security holes -- the whole thing was written by Claude Code as an experiment.

@smayya337 smayya337 requested a review from a team as a code owner August 8, 2025 18:19
@smayya337 smayya337 changed the title feat: add authentication with LDAP feat(auth): add authentication with LDAP Aug 8, 2025
@smayya337
Copy link
Member Author

linting and testing are a conspiracy by Big GitHub Actions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant