Try a directory before anything signs in through it #95

Merged
jcoffey-dev merged 1 commits from feature/directory-test into main 2026-09-28 21:51:56 +00:00
Owner

POST /api/directory/test, for the console's guided directory setup (settings-reorg, first wave). It lets an admin test a real person against a saved directory before any domain is switched to it.

Request: {"directoryId": "…", "address": "[email protected]", "password": "…"} (password optional).

The answer says:

  • opened: whether the server could build the directory, with the build error if not;
  • lookup: what a recipient lookup of the address finds: an account (email, aliases, groups, name), a group, or none; or the error;
  • signIn: whether the password signs in. A wrong password (wrongPassword: true) is told apart from an unreachable or misconfigured directory (error);
  • oidc: for OIDC directories, the discovered issuer and JWKS URI. They take no passwords (DIR-29) and have no lookup (DIR-10).

It calls the directory itself, below the sign-in path:

  • a test never creates or updates an account (DIR-14);
  • it never counts toward the sign-in ban;
  • it ignores which domains use the directory (DIR-6);
  • nothing is cached (DIR-32);
  • a password hash a directory hands back is never returned.

Access: server-level administrators with sysDirectoryUpdate, like Explain's /api/explain route.

Checked against the test suite's OpenLDAP container (stalwart-test-openldap) and fixture directory:

  • lookup of [email protected] finds the account with alias, group and name;
  • the right password signs in; a wrong one gives wrongPassword;
  • an unknown address gives found: none;
  • an unknown directory id and missing parameters give clear errors;
  • a directory at a dead port answers at once with "Connection refused" for both lookup and sign-in.

Also: cargo check, clippy on jmap/http, and the fork checks are clean. No integration test in the suite yet. The directory suites need the same containers, and I'd rather add one alongside DIR tests 12–17 when those land.

`POST /api/directory/test`, for the console's guided directory setup (settings-reorg, first wave). It lets an admin test a real person against a saved directory before any domain is switched to it. Request: `{"directoryId": "…", "address": "[email protected]", "password": "…"}` (password optional). The answer says: - **opened:** whether the server could build the directory, with the build error if not; - **lookup:** what a recipient lookup of the address finds: an account (email, aliases, groups, name), a group, or none; or the error; - **signIn:** whether the password signs in. A wrong password (`wrongPassword: true`) is told apart from an unreachable or misconfigured directory (`error`); - **oidc:** for OIDC directories, the discovered issuer and JWKS URI. They take no passwords (DIR-29) and have no lookup (DIR-10). It calls the directory itself, below the sign-in path: - a test never creates or updates an account (DIR-14); - it never counts toward the sign-in ban; - it ignores which domains use the directory (DIR-6); - nothing is cached (DIR-32); - a password hash a directory hands back is never returned. Access: server-level administrators with `sysDirectoryUpdate`, like Explain's `/api/explain` route. **Checked** against the test suite's OpenLDAP container (`stalwart-test-openldap`) and fixture directory: - lookup of [email protected] finds the account with alias, group and name; - the right password signs in; a wrong one gives `wrongPassword`; - an unknown address gives `found: none`; - an unknown directory id and missing parameters give clear errors; - a directory at a dead port answers at once with "Connection refused" for both lookup and sign-in. Also: `cargo check`, clippy on jmap/http, and the fork checks are clean. No integration test in the suite yet. The directory suites need the same containers, and I'd rather add one alongside DIR tests 12–17 when those land.
jcoffey-dev added 1 commit 2026-09-28 19:45:00 +00:00
Try a directory before anything signs in through it
ci / fork-checks (pull_request) Successful in 59s
ci / build (pull_request) Successful in 4m5s
ac3a63973d
POST /api/directory/test takes a saved directory's id, an address and
optionally a password, and answers whether the directory opened, what a
recipient lookup of the address finds (account or group, with its
aliases, groups and name), and whether the password signs in. A wrong
password is told apart from a directory that can't be reached or is set
up wrong.

It calls the directory itself, below the sign-in path: a test never
creates or updates an account, never counts toward the sign-in ban and
doesn't depend on which domains use the directory. A password hash a
directory returns is never sent back. OIDC directories report their
discovered issuer; they take no passwords.

For server-level administrators with directory update permission. The
console's guided directory setup uses it to test a real person before
any domain is switched over.
jcoffey-dev merged commit afffa0fc96 into main 2026-09-28 21:51:56 +00:00
jcoffey-dev deleted branch feature/directory-test 2026-09-28 21:51:56 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#95