【问题标题】:can bind successfully to the ldap server, but needs to know how to find user w/i AD可以成功绑定到 ldap 服务器,但需要知道如何使用 AD 找到用户
【发布时间】:2010-03-20 04:55:44
【问题描述】:

我创建一个登录表单来绑定到 ldap 服务器,如果成功,它会创建一个会话(用户的用户名存储在其中),然后我转到另一个具有 session_start() 的页面;而且效果很好。

我现在想做的是添加代码来测试该用户是否是特定组的成员。

所以理论上,这就是我想做的事情

if(username session is valid) {
  search ldap for user -> get list of groups user is member of

  foreach(group they are member of) {
    switch(group) {
      case STAFF:
      print 'they are member of staff group';
      $access = true;
      break;

      default:
      print 'not a member of STAFF group';
      $access = false;
      break;
    }

    if(group == STAFF) {
     break;
    }

   }

   if($access == TRUE) {
    // you have access to the content on this page
   } else {
    // you do not have access to this page
   }
}

如何进行不带绑定的 ldap_search?我不想在每个页面上一直询问他们的密码,而且我无法通过会话传递他们的密码。

感谢任何帮助。

【问题讨论】:

    标签: php authentication session active-directory ldap


    【解决方案1】:

    最佳实践是使用这样的库来完成必要的部分。

    http://sourceforge.net/projects/classldap/

    http://sourceforge.net/projects/adldap/

    【讨论】:

    • 我已经在使用adldap了,但是在使用user_groups()之前我需要先绑定它,而且我不想一直要求用户登录他们去的每个页面,我是传递会话,不能通过会话传递密码。
    猜你喜欢
    • 1970-01-01
    • 2014-09-22
    • 1970-01-01
    • 2019-11-25
    • 2011-04-21
    • 2023-03-13
    • 1970-01-01
    • 2010-12-20
    • 1970-01-01
    相关资源
    最近更新 更多