Skip to content

Commit b763213

Browse files
authored
fix: rebind to ldap svc account after pw check fail (#1165)
1 parent cd8d03f commit b763213

1 file changed

Lines changed: 13 additions & 7 deletions

File tree

‎internal/service/auth_service.go‎

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -193,7 +193,7 @@ func (auth *AuthService) SearchUser(username string) (*model.UserSearch, error)
193193
return nil, ErrUserNotFound
194194
}
195195

196-
func (auth *AuthService) CheckUserPassword(search model.UserSearch, password string) error {
196+
func (auth *AuthService) CheckUserPassword(search model.UserSearch, password string) (err error) {
197197
switch search.Type {
198198
case model.UserLocal:
199199
user := auth.GetLocalUser(search.Username)
@@ -203,14 +203,20 @@ func (auth *AuthService) CheckUserPassword(search model.UserSearch, password str
203203
return bcrypt.CompareHashAndPassword([]byte(user.Password), []byte(password))
204204
case model.UserLDAP:
205205
if auth.ldap != nil {
206-
err := auth.ldap.Bind(search.Username, password)
207-
if err != nil {
208-
return fmt.Errorf("failed to bind to ldap user: %w", err)
209-
}
206+
defer func() {
207+
bindErr := auth.ldap.BindService(true)
208+
if bindErr != nil {
209+
if err != nil {
210+
err = fmt.Errorf("failed to rebind to ldap service account: %w, original error: %w", bindErr, err)
211+
return
212+
}
213+
err = fmt.Errorf("failed to rebind to ldap service account: %w", bindErr)
214+
}
215+
}()
210216

211-
err = auth.ldap.BindService(true)
217+
err = auth.ldap.Bind(search.Username, password)
212218
if err != nil {
213-
return fmt.Errorf("failed to bind to ldap service account: %w", err)
219+
return fmt.Errorf("failed to bind to ldap user: %w", err)
214220
}
215221

216222
return nil

0 commit comments

Comments
 (0)