Extension:LDAPSyncAll

From mediawiki.org
Jump to navigation Jump to search
MediaWiki Stakeholders' Group Logo.svg This extension is maintained by a member of the MediaWiki Stakeholders' Group .
MWStake LDAPStack Icon.svg This extension is part of the LDAP Stack and requires the LDAPProvider extension to be installed first.

This extension provides a mechanism to synchronize users in the database and users in active directory.

MediaWiki extensions manual
OOjs UI icon advanced.svg
LDAPSyncAll
Release status: stable
MWStake LDAPStack Icon.svg
Description Used to synchronize users
Author(s) Cindy Cicalese, Mark A. Hershberger, Robert Vogel
Latest version 1.0.0
Compatibility policy Snapshots releases along with MediaWiki. Master is not backwards compatible.
MediaWiki 1.31+
MediaWiki 1.36 Not formally tested
MediaWiki 1.34 Not formally tested
MediaWiki 1.32 Not formally tested
License GNU General Public License 2.0 or later
Download
  • $LDAPSyncAllBlockExecutorUsername
  • $LDAPSyncAllExcludedUsernames
  • $LDAPSyncAllExcludedGroups
Translate the LDAPSyncAll extension if it is available at translatewiki.net

Check usage and version matrix.

Issues Open tasks · Report a bug
  • If a user is in LDAP, but not in the database => the user is added to the database
  • If a user is in the database, but not in LDAP => the user account will be disabled in the database

Installation[edit]

Execute within MediaWiki root or add mediawiki/ldap-sync-all to the composer.json file of your projectː

composer require hallowelt/ldapsyncall dev-REL1_31

Activation[edit]

Add the following line to your LocalSettings.phpː

wfLoadExtension( 'LDAPSyncAll' );

Usage[edit]

The extension provides a maintenance script that you can simply run from your console php maintenance/SyncLDAPUsers.php. In addition, there is a RunJobsTriggerHandler that runs once a day.

Configuration[edit]

You need to add the following line in your LocalSettings.php. Don't forget to change "Admin" to the username who has admin permissions. This user disables accounts that are not in LDAP.

$GLOBALS['LDAPSyncAllBlockExecutorUsername'] = 'Admin';

You can specify usernames and usergroups that you want to exclude from disabling, for example:

$GLOBALS['LDAPSyncAllExcludedUsernames'] = [ 'Bob', 'Emily' ];

$GLOBALS['LDAPSyncAllExcludedGroups'] = [ 'bot', 'editor' ];
LDAP Stack Extensions are targeted/qualified for MediaWiki LTS releases only.
However, this table helps to determine which extension-releases to use across all recent versions.

MediaWiki Release Recommended Extension Version Test Status Latest Test Date
1.31 (LTS) LDAPxxx_REL1_31 Tested, Recommended March 2020
1.32 LDAPxxx_REL1_31 Not Tested -
1.33 LDAPxxx_REL1_31 Tested March 2020
1.34 LDAPxxx_REL1_31 Tested March 2020
1.35 (LTS Planned) LDAPxxx_master Tested March 2020