FLAT
CouperSevenval TechnologiesDocker ImageGithub
master
master
  • Changelog
  • FLAT
  • Administration
    • Configuration
    • Docker
    • Logging
  • Cookbook
    • Using the Built-in Mocking
    • Performing Additional Checks on JWT Access Tokens
    • Logging Custom Fields
    • Using Environment Variables
    • Handling Errors with an Error Flow
    • File Serving
    • Forwarding a Request to an Upstream API
    • Extracting Common Initialization Flow Tasks
    • Encoding and Decoding JWT
    • Passing Header Fields to the Client
    • How can I pass an arbitrary header field to an upstream system?
    • Performing Additional Checks on JWT Access Tokens
    • Proxying requests to Upstream APIs
    • Increasing the Request Timeout
    • How can I see what the client requested?
    • Using Swagger UI for API Documentation
    • Testing API Requests
    • Testing with Backend Requests
    • Testing Templates
    • Sending POST Requests
    • Processing Upstream Responses
    • Protecting Access using JWT Tokens
  • Reference
    • Configuration
    • Debugging
    • flat CLI
    • Flow
    • Variables
    • OpenAPI / Swagger Integration
    • OpenAPI
      • CORS - Cross-Origin Resource Sharing
    • OpenAPI
      • Differences from Swagger
    • OpenAPI
      • Mocking
    • OpenAPI
      • Routing
    • OpenAPI
      • Security
    • OpenAPI
      • Upstream APIs
    • OpenAPI
      • Validation
    • Flow Actions
      • assert Action
      • auth Action
      • backend-flow Action
      • copy Action
      • debug Action
      • dump Action
      • echo Action
      • error Action
      • eval Action
      • log Action
      • nameshave Action
      • pass-body Action
      • proxy-request Action
      • regex Action
      • request Action
      • requests Action
      • serve Action
      • set-config Action
      • set-env Action
      • set-response-headers Action
      • set-status Action
      • sub-flow Action
      • template Action
      • test-request Action
      • xslt Action
    • Functions
      • apply-codecs()
      • array-reverse()
      • array()
      • base64-decode()
      • base64-encode()
      • body()
      • calc-signature()
      • capitalize-first()
      • content()
      • decrypt-xml()
      • decrypt()
      • encrypt()
      • ends-with()
      • file-exists()
      • fit-document()
      • fit-log()
      • fit-serialize()
      • get-log()
      • has-class()
      • html-parse()
      • join()
      • json-doc()
      • json-parse()
      • json-stringify()
      • json-to-csv()
      • json-to-xml()
      • jwt-decode()
      • jwt-encode()
      • ldap-lookup()
      • ldap-query()
      • lookup()
      • matches()
      • md5()
      • replace()
      • sort()
      • split()
      • tolower()
      • toupper()
      • trim()
      • unixtime()
      • urldecode(), url-decode()
      • urlencode(), url-encode()
      • uuid3() and uuid4()
      • verify-signature()
      • verify-xmldsig()
      • xml-parse()
      • xml-to-json()
    • Templating
      • {{,}}
      • Comment {{// …}}
      • Dot {{.}}
      • Conditional `{{if <condition>}} … {{elseif <condition> }} … {{else}} … {{end}}
      • loop
      • ?? Operator
      • Object XML Notation (OXN)
      • Pair Producer {{: …}}
      • Placeholder
      • Template Variables
      • with
    • Testing
  • Tutorial
Powered by GitBook
On this page
  • Parameters
  • Example

Was this helpful?

  1. Reference
  2. Functions

ldap-query()

Previousldap-lookup()Nextlookup()

Last updated 4 years ago

Was this helpful?

OXN-node-set ldap-query(string url, string rdn, string rdnPassword, string base_dn, string search, string attributes)

The ldap-query() function connects to an LDAP server with the given url, rdn and rdnPassword. It then performs a query by the given search. An JSON array is returned with objects containing dn and additional attributes given by attributes of all the entities that were found. If no entities match the query, an empty node-set is returned.

Parameters

  • url The ldap URL (string)

  • rdn The (relative) distinguished name of the connecting user (string)

  • rdnPassword The password of the connecting user (string)

  • base_dn The base distinguished name for the directory, used for the search (string)

  • search The filter for searching entities (string)

  • attributes A comma-separated list of attributes to return (string)

Example

In the following example, FLAT connects to the LDAP server with the DN given in the rdn and rdnPassword POST parameters. The given filter is used to search for an entry of a person which is a member of a group Users and sAMAccountName containing doe. In addition to the (default) dn, the sAMAccountName, displayName and mail from the found entries are included in the results.

<flow>
  <eval out="$search">concat("(&amp;(objectClass=person)(memberOf=CN=Users,ou=People,dc=example,dc=com)(sAMAccountName=*doe*))")</eval>
  <eval out="$attributes">"sAMAccountName,displayName,mail"</eval>
  <eval out="$ldap_url">"ldap://ad.example.com"</eval>

  <eval out="$ldap">ldap-lookup($ldap_url, $request/post/rdn, $request/post/rdnPassword, "dc=example,dc=com", $search, $attributes)</eval>
  <error if="not($ldap)">
  {
    "status": 403,
    "message": "ldap-lookup() failed"
  }
  </error>
</flow>

The result is

[
  {
    "dn": "cn=John Doe,ou=People,dc=example,dc=com",
    "sAMAccountName": "john.doe",
    "displayName": "John Doe",
    "mail": "john.doe@example.com"
  },
  {
    "dn": "cn=Joseph Adoell,ou=People,dc=example,dc=com",
    "sAMAccountName": "joseph.adoell",
    "displayName": "Joseph Adoell",
    "mail": "joseph.adoell@example.com"
  }
]
OXN