mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
Users can authenticate against an LDAP/AD server with configurable server URL, bind DN, search base, and user filter. Supports StartTLS and LDAPS — plaintext is not allowed. Both Active Directory (memberOf) and POSIX groups (memberUid) are mapped to BamBuddy groups on each login. Auto-provisioning creates local accounts on first LDAP login. Local admin accounts remain as fallback when LDAP is unreachable. Password management is disabled for LDAP users.