Raise LDAP client timeout for the directory-wide import browse
ldapjs's `timeout` option is a single flat deadline for the whole operation (set once when the request is sent, not reset per entry received) — 5s is fine for a bind or a single-match search during login, but the admin "import accounts" browse runs an unbounded (objectClass=person) search across the entire base DN, which can take longer than 5s against a real AD domain and was getting killed mid-stream (surfaced as ldapjs's generic "<id> closed" ConnectionError). Bumped that one call site to 30s; login-path calls keep the tighter 5s deadline. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012o9j9RezxbZVKQMrB7oRLY
This commit is contained in:
1 parent
14fe8c0445
commit
f9128499df
1 file changed
+8
-3
@@ -13,11 +13,16 @@ interface ConnectionSettings {
|
|||||||
useTls: boolean;
|
useTls: boolean;
|
||||||
}
|
}
|
||||||
|
|
||||||
function createLdapClient(settings: ConnectionSettings): ldap.Client {
|
function createLdapClient(settings: ConnectionSettings, timeoutMs = 5_000): ldap.Client {
|
||||||
const protocol = settings.useTls ? "ldaps" : "ldap";
|
const protocol = settings.useTls ? "ldaps" : "ldap";
|
||||||
const client = ldap.createClient({
|
const client = ldap.createClient({
|
||||||
url: `${protocol}://${settings.host}:${settings.port}`,
|
url: `${protocol}://${settings.host}:${settings.port}`,
|
||||||
timeout: 5_000,
|
// ldapjs's `timeout` is a single flat deadline for the whole operation
|
||||||
|
// (set once when the request is sent, not reset per entry received) —
|
||||||
|
// fine for a bind or a single-match search, but a directory-wide
|
||||||
|
// "(objectClass=person)" browse over the whole base DN can easily take
|
||||||
|
// longer than 5s on a real AD domain and gets killed mid-stream.
|
||||||
|
timeout: timeoutMs,
|
||||||
connectTimeout: 5_000,
|
connectTimeout: 5_000,
|
||||||
});
|
});
|
||||||
// A socket-level error (e.g. host unreachable) with no listener would
|
// A socket-level error (e.g. host unreachable) with no listener would
|
||||||
@@ -120,7 +125,7 @@ export async function searchLdapDirectory(): Promise<LdapUserInfo[]> {
|
|||||||
const settings = await getLdapSettings();
|
const settings = await getLdapSettings();
|
||||||
if (!settings) return [];
|
if (!settings) return [];
|
||||||
|
|
||||||
const client = createLdapClient(settings);
|
const client = createLdapClient(settings, 30_000);
|
||||||
try {
|
try {
|
||||||
await bind(client, settings.bindDn, settings.bindPassword);
|
await bind(client, settings.bindDn, settings.bindPassword);
|
||||||
const entries = await search(client, settings.baseDn, settings.listFilter);
|
const entries = await search(client, settings.baseDn, settings.listFilter);
|
||||||
|
|||||||
Reference in new issue
Block a user