diff --git a/api/config/settings/common.py b/api/config/settings/common.py index 7b391b5522cb70db16a8ac0e046daa3d4a6f1ed0..e5ac5a34404a62423cf8e7b57a1ae366b1894506 100644 --- a/api/config/settings/common.py +++ b/api/config/settings/common.py @@ -460,6 +460,9 @@ if AUTH_LDAP_ENABLED: "%(user)s" ) AUTH_LDAP_START_TLS = env.bool("LDAP_START_TLS", default=False) + AUTH_LDAP_BIND_AS_AUTHENTICATING_USER = env( + "AUTH_LDAP_BIND_AS_AUTHENTICATING_USER", default=False + ) DEFAULT_USER_ATTR_MAP = [ "first_name:givenName", diff --git a/docs/installation/ldap.rst b/docs/installation/ldap.rst index a30bb5e6bd6ebf6c657ebcdc1a9a4b92afa2ab31..dc5582f7dde4463ee9bfabad2345cac092d8c9c2 100644 --- a/docs/installation/ldap.rst +++ b/docs/installation/ldap.rst @@ -31,6 +31,7 @@ Basic features: * ``LDAP_START_TLS``: Set to ``True`` to enable LDAP StartTLS support. Default: ``False``. * ``LDAP_ROOT_DN``: The LDAP search root DN, e.g. ``dc=my,dc=domain,dc=com``; supports multiple entries in a space-delimited list, e.g. ``dc=users,dc=domain,dc=com dc=admins,dc=domain,dc=com``. * ``LDAP_USER_ATTR_MAP``: A mapping of Django user attributes to LDAP values, e.g. ``first_name:givenName, last_name:sn, username:cn, email:mail``. Default: ``first_name:givenName, last_name:sn, username:cn, email:mail``. +* ``AUTH_LDAP_BIND_AS_AUTHENTICATING_USER``: Controls whether direct binding is used. Default: ``False``. Group features: