etianen / etianen/django-python3-ldap

Using SID for LDAP_AUTH_USER_LOOKUP_FIELDS

Open
#280 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
428
Forks
122
PR merge metrics
No merged PRs in 30d

Description

So we want to use Active Directory's SID ("objectSID") for our user lookups instead of "username". This is because usernames can change but SID does not. If we use "username" and our sync process runs, if a user's username has change, the sync will fail.

So we updated LDAP_AUTH_USER_LOOKUP_FIELDS to be ("sid",) and it seems to work. However, we had to create a custom auth backend to utilize the "username" field for the authenticate method.

Can the package be updated to accommodate this situation? And are there any unforeseen issues we might run into using our custom solution?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.