From f407e64115f77f389039bd0b7ea8e639ff2ad134 Mon Sep 17 00:00:00 2001 From: Stavros Date: Mon, 28 Sep 2026 19:27:57 +0300 Subject: [PATCH 1/3] fix: rebind to ldap svc account after pw check fail --- internal/service/auth_service.go | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/internal/service/auth_service.go b/internal/service/auth_service.go index cfa971e4..9e16cfff 100644 --- a/internal/service/auth_service.go +++ b/internal/service/auth_service.go @@ -208,10 +208,14 @@ func (auth *AuthService) CheckUserPassword(search model.UserSearch, password str return fmt.Errorf("failed to bind to ldap user: %w", err) } - err = auth.ldap.BindService(true) - if err != nil { - return fmt.Errorf("failed to bind to ldap service account: %w", err) - } + defer func() { + if err != nil { + bindErr := auth.ldap.BindService(true) + if bindErr != nil { + err = fmt.Errorf("failed to rebind to ldap service account: %w, original error: %w", bindErr, err) + } + } + }() return nil } From 018ce6c7e572276e4d1ffe8cc95d7faee1b12d43 Mon Sep 17 00:00:00 2001 From: Stavros Date: Mon, 28 Sep 2026 19:41:02 +0300 Subject: [PATCH 2/3] fix: rabbit comments --- internal/service/auth_service.go | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/internal/service/auth_service.go b/internal/service/auth_service.go index 9e16cfff..c5b1f0d3 100644 --- a/internal/service/auth_service.go +++ b/internal/service/auth_service.go @@ -203,10 +203,7 @@ func (auth *AuthService) CheckUserPassword(search model.UserSearch, password str return bcrypt.CompareHashAndPassword([]byte(user.Password), []byte(password)) case model.UserLDAP: if auth.ldap != nil { - err := auth.ldap.Bind(search.Username, password) - if err != nil { - return fmt.Errorf("failed to bind to ldap user: %w", err) - } + var err error defer func() { if err != nil { @@ -217,6 +214,11 @@ func (auth *AuthService) CheckUserPassword(search model.UserSearch, password str } }() + err = auth.ldap.Bind(search.Username, password) + if err != nil { + return fmt.Errorf("failed to bind to ldap user: %w", err) + } + return nil } default: From 2be70babaf00e61b1a5395e6e33abb883f757417 Mon Sep 17 00:00:00 2001 From: Stavros Date: Thu, 1 Oct 2026 14:38:24 +0300 Subject: [PATCH 3/3] fix: always rebind to svc account --- internal/service/auth_service.go | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/internal/service/auth_service.go b/internal/service/auth_service.go index c5b1f0d3..2c7b05a2 100644 --- a/internal/service/auth_service.go +++ b/internal/service/auth_service.go @@ -193,7 +193,7 @@ func (auth *AuthService) SearchUser(username string) (*model.UserSearch, error) return nil, ErrUserNotFound } -func (auth *AuthService) CheckUserPassword(search model.UserSearch, password string) error { +func (auth *AuthService) CheckUserPassword(search model.UserSearch, password string) (err error) { switch search.Type { case model.UserLocal: user := auth.GetLocalUser(search.Username) @@ -203,14 +203,14 @@ func (auth *AuthService) CheckUserPassword(search model.UserSearch, password str return bcrypt.CompareHashAndPassword([]byte(user.Password), []byte(password)) case model.UserLDAP: if auth.ldap != nil { - var err error - defer func() { - if err != nil { - bindErr := auth.ldap.BindService(true) - if bindErr != nil { + bindErr := auth.ldap.BindService(true) + if bindErr != nil { + if err != nil { err = fmt.Errorf("failed to rebind to ldap service account: %w, original error: %w", bindErr, err) + return } + err = fmt.Errorf("failed to rebind to ldap service account: %w", bindErr) } }()