Unverified Commit b1060180 authored by Kevyn Bruyere's avatar Kevyn Bruyere Committed by GitHub

fix: LDAP - avoid reading empty tls cert file (#2980)

parent cfbd3dca
...@@ -18,12 +18,7 @@ module.exports = { ...@@ -18,12 +18,7 @@ module.exports = {
bindCredentials: conf.bindCredentials, bindCredentials: conf.bindCredentials,
searchBase: conf.searchBase, searchBase: conf.searchBase,
searchFilter: conf.searchFilter, searchFilter: conf.searchFilter,
tlsOptions: (conf.tlsEnabled) ? { tlsOptions: getTlsOptions(conf),
rejectUnauthorized: conf.verifyTLSCertificate,
ca: [
fs.readFileSync(conf.tlsCertPath)
]
} : {},
includeRaw: true includeRaw: true
}, },
usernameField: 'email', usernameField: 'email',
...@@ -56,3 +51,25 @@ module.exports = { ...@@ -56,3 +51,25 @@ module.exports = {
)) ))
} }
} }
function getTlsOptions(conf) {
if (!conf.tlsEnabled) {
return {}
}
if (!conf.tlsCertPath) {
return {
rejectUnauthorized: conf.verifyTLSCertificate,
}
}
const caList = []
if (conf.verifyTLSCertificate) {
caList.push(fs.readFileSync(conf.tlsCertPath))
}
return {
rejectUnauthorized: conf.verifyTLSCertificate,
ca: caList
}
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment