Commit baccac37 authored by Simon M. Haller-Seeber's avatar Simon M. Haller-Seeber
Browse files

fix external email registration, Admin. Working solution.

parent 13b76926
Loading
Loading
Loading
Loading
+12 −9
Changes for README.md: 12 added lines, 9 removed lines.
Original line number Diff line number Diff line
@@ -34,12 +34,6 @@ db.users.find({email:"EMAIL"}).pretty()
db.users.update({email : OLDEMAIL},{$set: { email : NEWEMAIL}});
```

## Coming soon

- Option that Admins can invite non LDAP User



## Configuration

### Domain Configuration
@@ -74,15 +68,24 @@ LDAP_BINDDN: ou=someunit,ou=people,dc=DOMAIN,dc=TLS
# By default tries to bind directly with the ldap user - this user has to be in the LDAP GROUP
# you have to set a group filter a minimal groupfilter would be: '(objectClass=person)'
LDAP_GROUP_FILTER: '(memberof=GROUPNAME,ou=groups,dc=DOMAIN,dc=TLD)'
LDAP_CONTACTS: 'true'

# If user is in ADMIN_GROUP on user creation (first login) isAdmin is set to true. 
# Admin Users can invite external (non ldap) users. This feature makes only sense 
# when ALLOW_EMAIL_LOGIN is set to 'true'. Additionally adminsy can send 
# system wide messages.
#LDAP_ADMIN_GROUP_FILTER: '(memberof=cn=ADMINGROUPNAME,ou=groups,dc=DOMAIN,dc=TLD)'
ALLOW_EMAIL_LOGIN: 'false'

# All users in the LDAP_GROUP_FILTER are loaded from the ldap server into contacts.
LDAP_CONTACTS: 'false'
```

### LDAP Contacts 

If you enable this, then all users in GROUPNAME are loaded from the ldap server into the contacts. 
If you enable this, then all users in LDAP_GROUP_FILTER are loaded from the ldap server into the contacts. 
At the moment this happens every time you click on "Share" within a project.
The user search happens without bind - so if your LDAP needs a bind you can adapt this in the 
function `getLdapContacts()` in ContactsController.js (lines 82 - 107) 
function `getLdapContacts()` in ContactsController.js (lines 92) 
if you want to enable this function set:
```
LDAP_CONTACTS: 'true'
+10 −2
Changes for docker-compose.yml: 10 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -48,9 +48,17 @@ services:
            LDAP_BINDDN: ou=someunit,ou=people,dc=DOMAIN,dc=TLS
            # By default tries to bind directly with the ldap user - this user has to be in the LDAP GROUP
            LDAP_GROUP_FILTER: '(memberof=cn=GROUPNAME,ou=groups,dc=DOMAIN,dc=TLD)'
            #LDAP_GROUP_FILTER: '(memberof=GROUPNAME,ou=groups,dc=DOMAIN,dc=TLD)'
            # if user is in ADMIN_GROUP on user creation (first login) isAdmin is set to true.

            # If user is in ADMIN_GROUP on user creation (first login) isAdmin is set to true. 
            # Admin Users can invite external (non ldap) users. This feature makes only sense 
            # when ALLOW_EMAIL_LOGIN is set to 'true'. Additionally adminsy can send 
            # system wide messages.
            #LDAP_ADMIN_GROUP_FILTER: '(memberof=cn=ADMINGROUPNAME,ou=groups,dc=DOMAIN,dc=TLD)'
            ALLOW_EMAIL_LOGIN: 'false'

            # All users in the LDAP_GROUP_FILTER are loaded from the ldap server into contacts.
            # This LDAP search happens without bind. If you want this and your LDAP needs a bind you can 
            # adapt this in the function getLdapContacts() in ContactsController.js (lines 82 - 107)
            LDAP_CONTACTS: 'false'

            # Same property, unfortunately with different names in
+10 −9
Changes for ldap-overleaf-sl/Dockerfile: 10 added lines, 9 removed lines.
Original line number Diff line number Diff line
@@ -14,16 +14,19 @@ RUN npm install ldapts
# overwrite some files
COPY sharelatex/AuthenticationManager.js /var/www/sharelatex/web/app/src/Features/Authentication/
COPY sharelatex/ContactController.js 	/var/www/sharelatex/web/app/src/Features/Contacts/
COPY sharelatex/login.pug /var/www/sharelatex/web/app/views/user/login.pug
COPY sharelatex/settings.pug /var/www/sharelatex/web/app/views/user/settings.pug
COPY sharelatex/navbar.pug /var/www/sharelatex/web/app/views/layout/navbar.pug 
COPY sharelatex/share.pug /var/www/sharelatex/web/app/views/project/editor/share.pug
COPY sharelatex/login.pug 		/var/www/sharelatex/web/app/views/user/
COPY sharelatex/settings.pug 		/var/www/sharelatex/web/app/views/user/
COPY sharelatex/navbar.pug 		/var/www/sharelatex/web/app/views/layout/
COPY sharelatex/share.pug 		/var/www/sharelatex/web/app/views/project/editor/

# Non LDAP User Reegistration for Admins
COPY sharelatex/admin-index.pug 	/var/www/sharelatex/web/app/views/admin/index.pug
RUN rm  /var/www/sharelatex/web/app/views/admin/register.pug

### To remove comments entirly (bug https://github.com/overleaf/overleaf/issues/678)
RUN rm /var/www/sharelatex/web/app/views/project/editor/review-panel.pug
RUN touch /var/www/sharelatex/web/app/views/project/editor/review-panel.pug


### Nginx and Certificates
# enable https via letsencrypt
RUN  rm /etc/nginx/sites-enabled/sharelatex.conf
@@ -34,8 +37,6 @@ RUN wget https://raw.githubusercontent.com/certbot/certbot/master/certbot-nginx/
RUN wget https://raw.githubusercontent.com/certbot/certbot/master/certbot/certbot/ssl-dhparams.pem -O /etc/nginx/ssl-dhparams.pem 

# reload nginx via cron for reneweing https certificates automatically
COPY nginx/nginx-reload.cron  /etc/cron.d/nginx-cron
RUN chmod 0744 /etc/cron.d/nginx-cron
RUN touch /var/log/cron.log
RUN crontab /etc/cron.d/nginx-cron
COPY nginx/nginx-reload.sh  /etc/cron.weekly/
RUN chmod 0744 /etc/cron.weekly/nginx-reload.sh
+0 −4
Changes for ldap-overleaf-sl/nginx/nginx-reload.cron: 0 added lines, 4 removed lines.
Original line number Diff line number Diff line
* 2 * * * root /etc/init.d/nginx reload 
#* * * * * root sleep 10; echo "Nginx relaoded" >> /var/log/cron.log 2>&1
# Reload Nginx to reload the certificates (2am)
+3 −0
Changes for ldap-overleaf-sl/nginx/nginx-reload.sh: 3 added lines, 0 removed lines.
Original line number Diff line number Diff line
#!/bin/bash

/etc/init.d/nginx reload 
Loading