Browse project docs

Server API

Use the source-backed ldapjs-community server API to listen for LDAP traffic and route protocol operations.

On this page

ldapjs-community retains the ldapjs v2 server API. This page summarizes the verified public shape; use the upstream server reference for exhaustive request and response fields.

Link to Create and listenCreate and listen

javascript
const ldap = require('ldapjs')

const server = ldap.createServer()

server.on('error', (err) => {
  console.error('LDAP server error:', err)
})

server.listen(1389, '127.0.0.1', () => {
  console.log(`LDAP server listening at ${server.url}`)
})

createServer accepts an options object. The upstream reference documents a compatible logger and PEM-encoded certificate and key values for TLS server mode.

The server exposes url after listening, a writable maxConnections limit, getConnections(callback), and close(callback). Register close, clientError, and error listeners when the application needs lifecycle or failure reporting.

Link to Route operationsRoute operations

Server routes follow an operation(base, ...handlers) pattern. Handlers receive req, res, and next, and can be chained like middleware.

Handlers may be passed individually or in arrays. server.use(...handlers) installs middleware that runs before mounted routes. Call next() to continue the chain or pass an LDAP error to stop it and return the corresponding result.

RoutePurpose
server.bind(base, handlers...)Handle bind requests.
server.add(base, handlers...)Handle entry creation.
server.search(base, handlers...)Stream search entries and completion.
server.modify(base, handlers...)Apply requested changes.
server.del(base, handlers...)Handle entry deletion.
server.compare(base, handlers...)Compare an attribute value.
server.modifyDN(base, handlers...)Rename or move an entry.
server.exop(oid, handlers...)Handle an extended operation.
server.unbind(handlers...)Override unbind cleanup.

Link to Bind routeBind route

javascript
server.bind('dc=example,dc=com', (req, res, next) => {
  if (req.dn.toString() !== process.env.LDAP_BIND_DN ||
      req.credentials !== process.env.LDAP_PASSWORD) {
    return next(new ldap.InvalidCredentialsError())
  }

  res.end()
  return next()
})

The upstream API currently documents LDAP v3 and simple authentication for BindRequest.

Link to Search routeSearch route

javascript
server.search('dc=example,dc=com', (req, res, next) => {
  const entry = {
    dn: 'cn=service,dc=example,dc=com',
    attributes: {
      objectClass: ['person'],
      cn: ['service'],
      sn: ['account']
    }
  }

  if (req.filter.matches(entry.attributes)) res.send(entry)
  res.end()
  return next()
})

Common request fields include dn, controls, connection, and logId. req.connection.ldap.bindDN identifies the bound DN for that connection. Search requests additionally expose baseObject through the dn getter, plus scope, derefAliases, sizeLimit, timeLimit, typesOnly, filter, and attributes.

Link to ResponsesResponses

Every response has end(). With no argument it returns LDAP success, except compare responses, where res.end(true) and res.end(false) report compare true or false. Search routes can call res.send(entry) repeatedly before res.end().

Link to Errors and connection failuresErrors and connection failures

Pass LDAP errors to next, for example next(new ldap.InsufficientAccessRightsError()). This stops the remaining handler chain and fills the LDAP result fields. Register clientError for malformed client traffic or request-handling failures and error for listener failures. See the Error API for the error model.

Link to Complete referenceComplete reference