Skip to content

feature/ldap pseudo users - #307

Merged
eschweikert merged 6 commits into
masterfrom
feature/ldap-pseudo-users
Sep 2, 2026
Merged

eschweikert merged 6 commits into
masterfrom
feature/ldap-pseudo-users

Conversation

@eschweikert

@eschweikert eschweikert commented Jul 24, 2026 •

Copy link
Copy Markdown
Collaborator

What

This adds the possibility to sync pseudo users.

  • adds a new config LDAP_PSEUDO_USER_BASE
  • adds a new is_pseudo row to know from where it gets synced
  • adds mock tests for the add_user

ToDo:

  • test in prelive (add pseudo user/delete pseudo user in ldap/check if users are still synced correctly)

@eschweikert eschweikert changed the title WIP: Feature/ldap pseudo users feature/ldap pseudo users Jul 24, 2026
@eschweikert
eschweikert force-pushed the feature/ldap-pseudo-users branch 3 times, most recently from 8716228 to 0aec721 Compare July 24, 2026 14:18
@eschweikert
eschweikert marked this pull request as draft July 24, 2026 14:20
@eschweikert
eschweikert force-pushed the feature/ldap-pseudo-users branch 2 times, most recently from 2885703 to ea07857 Compare July 24, 2026 14:48
@eschweikert
eschweikert marked this pull request as ready for review July 24, 2026 14:53
@eschweikert
eschweikert force-pushed the feature/ldap-pseudo-users branch 2 times, most recently from f346d9c to e5b7a81 Compare August 24, 2026 12:16
eschweikert and others added 6 commits August 25, 2026 13:47
This commit implements comprehensive support for synchronizing technical/pseudo users (service accounts and API accounts) from a dedicated LDAP base DN.

Core Implementation:
- Updated User database model in rights.py to add an explicit is_pseudo column.
- Incremented schema version to 13 in schema.py.
- Created SQL schema migration script migrate_12_to_13.sql and rollback script rollback_13_to_12.sql.
- Added default LDAP_PSEUDO_USER_BASE setting in defaults.py.

LDAP Sync & Import Overhaul:
- Refactored users() to safely read attributes, guarding against index/key errors.
- Enhanced sync_users() to perform dual LDAP base queries when LDAP_PSEUDO_USER_BASE is configured.
- Implemented robust fail-fast error handling for LDAP queries in sync_users() to prevent accidental mass deletion on network issues.
- Enhanced add_user() to use EAFP exception pattern for database existence checks (using NoResultFound) and added fallback LDAP searching.

Documentation:
- Updated change notes in dim/CHANGES.
- Added a dedicated 'Pseudo / Service Accounts' section to user_management.rst.

Co-authored-by: Gemini <gemini@local>
This commit introduces a fail-fast schema version check during create_app() bootstrapping.

- Verifies that SchemaInfo.current_version() matches SCHEMA_VERSION (13) on startup.
- Automatically bypasses the sys.exit(1) block if the command is executed via 'manage_db' or standard 'flask' CLI runners to prevent application boot deadlocks.
- Gracefully handles empty databases by catching initial connection/table-not-found exceptions.

Co-authored-by: Gemini <gemini@local>
This commit adds automated unit tests to verify standard and pseudo-user manual import features:

- Created dim-testsuite/tests/ldap_sync_test.py with test cases for both standard and pseudo-user fallback searches.
- Employs unittest.mock to mock LDAP class instantiation, connection instances, and users() method queries defensively.

Co-authored-by: Gemini <gemini@local>
This commit configures VS Code workspace settings to resolve import warning errors:

- Adds sub-package search paths (dim, ndcli, dimclient) to python.analysis.extraPaths in .vscode/settings.json.
- Restores full autocompletion, type hinting, and clickable navigation in VS Code across the multi-package repository.

Co-authored-by: Gemini <gemini@local>
This commit fixes a regression in user synchronization where new users with unpopulated ldap_uid were accidentally filtered out and ignored:

- Reverted standard db_users query in dim/dim/ldap_sync.py back to db_users_all to ensure newly created users are successfully populated.
- Updated integration test assertions in dim-testsuite/tests/ldap_sync_test.py to verify that local users with unpopulated ldap_uid are correctly searched in both LDAP bases but safely preserved during reconciliation.

Co-authored-by: Gemini <gemini@local>
This commit adds comprehensive support for authenticated LDAP binds during nightly synchronization and user import:

- Enhanced the LDAP connection constructor in dim/dim/ldap_sync.py to dynamically switch between authenticated bind (using LDAP_BIND_DN and LDAP_BIND_PASSWORD) and anonymous bind depending on configuration.
- Added default values for LDAP_BIND_DN and LDAP_BIND_PASSWORD in dim/dim/defaults.py to maintain 100% backward compatibility.
- Updated change notes in dim/CHANGES to document the new authenticated bind options.

Co-authored-by: Gemini <gemini@local>
@eschweikert
eschweikert force-pushed the feature/ldap-pseudo-users branch from e5b7a81 to e0c0640 Compare August 25, 2026 13:11

@akaramimotlagh akaramimotlagh left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@eschweikert
eschweikert merged commit 22814cc into master Sep 2, 2026
2 checks passed
@eschweikert
eschweikert deleted the feature/ldap-pseudo-users branch September 2, 2026 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants