mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
98 lines
4.3 KiB
XML
98 lines
4.3 KiB
XML
<?xml version="1.0"?>
|
|
<auth>
|
|
<!--<authenticator>
|
|
<type>ldap</type>
|
|
-->
|
|
<!-- Replacement fields: instances of {email}, {username} and {password}
|
|
are replaced with the corresponding user's values inside the
|
|
<filter>, <server>, <ldap-options>, <search-fields>,
|
|
<search-filter>, <search-base>, <search-user> and <search-password>
|
|
elements. -->
|
|
<!-- Filter users for which this authenticator applies. This is a Python
|
|
expression which is evaluated after field replacement. -->
|
|
<!-- <filter>'{email}'.endswith('@example.com')</filter>
|
|
<options>
|
|
-->
|
|
<!-- Whether to allow user registration. Possible values are True,
|
|
False and Challenge (i.e. allow registration in case of
|
|
successful authentication). Default is True. -->
|
|
<!-- <allow-register>False</allow-register>
|
|
-->
|
|
<!-- Whether Galaxy should automatically register users when they
|
|
first login. Default is False. -->
|
|
<!-- <auto-register>True</auto-register>
|
|
-->
|
|
<!-- Whether users are allowed to change their password. Default is
|
|
False. -->
|
|
<!-- <allow-password-change>False</allow-password-change>
|
|
-->
|
|
|
|
<!-- LDAP-specific options -->
|
|
<!-- <server>ldap://dc1.example.com</server>
|
|
-->
|
|
<!-- Additional options for the LDAP connection. The syntax is:
|
|
option1=value1,option2=value2,...
|
|
Options and values should match those from the python-ldap
|
|
documentation.
|
|
The following example allows connecting to ldaps:// (SSL/TLS)
|
|
when self-signed certificates are used -->
|
|
<!-- <ldap-options>OPT_X_TLS_REQUIRE_CERT=OPT_X_TLS_ALLOW</ldap-options>
|
|
-->
|
|
<!-- Whether to allow login with username instead of email. Default
|
|
is False. -->
|
|
<!-- <login-use-username>False</login-use-username>
|
|
-->
|
|
<!-- Whether to continue with the following authenticators if LDAP
|
|
fails. Default is False. -->
|
|
<!-- <continue-on-failure>False</continue-on-failure>
|
|
-->
|
|
<!-- If search-fields is not specified, all other search-* elements
|
|
are ignored.
|
|
If search-user is not specified, Galaxy will bind anonymously
|
|
to the LDAP server for search. -->
|
|
<!-- For Active Directory: -->
|
|
<!-- <search-fields>sAMAccountName,mail</search-fields>
|
|
<search-filter>(&(objectClass=user)(mail={email}))</search-filter>
|
|
<search-base>dc=dc1,dc=example,dc=com</search-base>
|
|
<search-user>jsmith@dc1.example.com</search-user>
|
|
<search-password>mysecret</search-password>
|
|
-->
|
|
<!-- For OpenLDAP: -->
|
|
<!-- <search-fields>uid,mail</search-fields>
|
|
<search-filter>(|(mail={email})(uid={username}))</search-filter>
|
|
<search-base>ou=People,dc=example,dc=com</search-base>
|
|
<search-user>cn=jsmith,ou=People,dc=domain,dc=com</search-user>
|
|
<search-password>mysecret</search-password>
|
|
-->
|
|
|
|
<!-- Replacement fields: instances of {email}, {username},
|
|
{password}, {dn} plus all fields defined in <search-fields> are
|
|
replaced with the corresponding user's values inside the
|
|
<bind-user>, <bind-password>, <auto-register-username> and
|
|
<auto-register-email> elements. -->
|
|
<!-- For Active Directory: -->
|
|
<!-- <bind-user>{sAMAccountName}@dc1.example.com</bind-user>
|
|
<bind-password>{password}</bind-password>
|
|
<auto-register-username>{sAMAccountName}</auto-register-username>
|
|
<auto-register-email>{mail}</auto-register-email>
|
|
-->
|
|
<!-- For OpenLDAP: -->
|
|
<!-- <bind-user>{dn}</bind-user>
|
|
<bind-password>{password}</bind-password>
|
|
<auto-register-username>{uid}</auto-register-username>
|
|
<auto-register-email>{mail}</auto-register-email>
|
|
-->
|
|
<!-- </options>
|
|
</authenticator>
|
|
-->
|
|
|
|
<authenticator>
|
|
<type>localdb</type>
|
|
<options>
|
|
<!-- Whether users are allowed to change their password. Default is
|
|
False. -->
|
|
<allow-password-change>true</allow-password-change>
|
|
</options>
|
|
</authenticator>
|
|
</auth>
|