mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-10 03:27:57 +00:00
fix: reject empty passwords in LDAP authentication to prevent unauthenticated binds (#23633)
Per RFC 4513, a Simple Bind with a non-empty DN but empty password is unauthenticated simple authentication. Many LDAP servers (OpenLDAP default, some AD configs) accept these binds, allowing account takeover without valid credentials. Rejects empty and whitespace-only passwords before attempting the LDAP bind.
This commit is contained in:
parent
83024d00bb
commit
b78dabb442
1 changed files with 8 additions and 0 deletions
|
|
@ -323,6 +323,14 @@ async def ldap_auth(
|
|||
detail=ERROR_MESSAGES.ACTION_PROHIBITED,
|
||||
)
|
||||
|
||||
# Reject empty passwords before attempting the LDAP bind.
|
||||
# Per RFC 4513 §5.1.2, a Simple Bind with a non-empty DN but empty
|
||||
# password is "unauthenticated simple authentication" — many LDAP
|
||||
# servers (OpenLDAP default, some AD configs) return success for these,
|
||||
# which would grant access without valid credentials.
|
||||
if not form_data.password or not form_data.password.strip():
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
|
||||
# NOW load LDAP config variables
|
||||
LDAP_SERVER_LABEL = request.app.state.config.LDAP_SERVER_LABEL
|
||||
LDAP_SERVER_HOST = request.app.state.config.LDAP_SERVER_HOST
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue