Search filters can be supplied as strings or constructed filter objects. Construct filter objects when values come from users or another untrusted source so the library performs the wire encoding instead of interpolating LDAP filter syntax.
For filter grammar and escaping, use LDAP filter syntax and LDAP filter escaping rules.
Link to Parse a filterParse a filter
const ldap = require('ldapjs')
const filter = ldap.parseFilter('(&(objectClass=person)(mail=*@example.com))')
console.log(filter.type)
console.log(filter.toString())
parseFilter(value) throws when the string is not valid filter syntax. Compound filters expose their child filters as a tree.
Link to Construct a filterConstruct a filter
const filter = new ldap.AndFilter({
filters: [
new ldap.EqualityFilter({
attribute: 'objectClass',
value: 'person'
}),
new ldap.EqualityFilter({
attribute: 'uid',
value: process.env.LDAP_USERNAME
})
]
})
client.search(process.env.LDAP_BASE_DN, {
scope: 'sub',
filter
}, callback)
Link to Exported filter classesExported filter classes
| Class | Purpose |
|---|---|
EqualityFilter | Match one exact attribute value. |
PresenceFilter | Require an attribute to be present. |
SubstringFilter | Match initial, intermediate, or final substrings. |
GreaterThanEqualsFilter | Apply greater-than-or-equal matching. |
LessThanEqualsFilter | Apply less-than-or-equal matching. |
ApproximateFilter | Represent approximate matching. |
AndFilter | Require every child filter to match. |
OrFilter | Require at least one child filter to match. |
NotFilter | Negate one child filter. |
ExtensibleFilter | Encode or parse an LDAPv3 extensible-match filter. |
Standard filter objects expose matches(entry) for in-memory server routing. Attribute values are strings unless the application adds its own schema-aware conversion.
Extensible matching
The current implementation can parse and encode ExtensibleFilter values for clients, but it does not implement server-side extensible matching. Do not rely on matches() for that filter type.