ldapjs-community retains the ldapjs v2 server API. This page summarizes the verified public shape; use the upstream server reference for exhaustive request and response fields.
Link to Create and listenCreate and listen
const ldap = require('ldapjs')
const server = ldap.createServer()
server.on('error', (err) => {
console.error('LDAP server error:', err)
})
server.listen(1389, '127.0.0.1', () => {
console.log(`LDAP server listening at ${server.url}`)
})
createServer accepts an options object. The upstream reference documents a compatible logger and PEM-encoded certificate and key values for TLS server mode.
The server exposes url after listening, a writable maxConnections limit, getConnections(callback), and close(callback). Register close, clientError, and error listeners when the application needs lifecycle or failure reporting.
Link to Route operationsRoute operations
Server routes follow an operation(base, ...handlers) pattern. Handlers receive req, res, and next, and can be chained like middleware.
Handlers may be passed individually or in arrays. server.use(...handlers) installs middleware that runs before mounted routes. Call next() to continue the chain or pass an LDAP error to stop it and return the corresponding result.
| Route | Purpose |
|---|---|
server.bind(base, handlers...) | Handle bind requests. |
server.add(base, handlers...) | Handle entry creation. |
server.search(base, handlers...) | Stream search entries and completion. |
server.modify(base, handlers...) | Apply requested changes. |
server.del(base, handlers...) | Handle entry deletion. |
server.compare(base, handlers...) | Compare an attribute value. |
server.modifyDN(base, handlers...) | Rename or move an entry. |
server.exop(oid, handlers...) | Handle an extended operation. |
server.unbind(handlers...) | Override unbind cleanup. |
Link to Bind routeBind route
server.bind('dc=example,dc=com', (req, res, next) => {
if (req.dn.toString() !== process.env.LDAP_BIND_DN ||
req.credentials !== process.env.LDAP_PASSWORD) {
return next(new ldap.InvalidCredentialsError())
}
res.end()
return next()
})
The upstream API currently documents LDAP v3 and simple authentication for BindRequest.
Link to Search routeSearch route
server.search('dc=example,dc=com', (req, res, next) => {
const entry = {
dn: 'cn=service,dc=example,dc=com',
attributes: {
objectClass: ['person'],
cn: ['service'],
sn: ['account']
}
}
if (req.filter.matches(entry.attributes)) res.send(entry)
res.end()
return next()
})
Common request fields include dn, controls, connection, and logId. req.connection.ldap.bindDN identifies the bound DN for that connection. Search requests additionally expose baseObject through the dn getter, plus scope, derefAliases, sizeLimit, timeLimit, typesOnly, filter, and attributes.
Link to ResponsesResponses
Every response has end(). With no argument it returns LDAP success, except compare responses, where res.end(true) and res.end(false) report compare true or false. Search routes can call res.send(entry) repeatedly before res.end().
Link to Errors and connection failuresErrors and connection failures
Pass LDAP errors to next, for example next(new ldap.InsufficientAccessRightsError()). This stops the remaining handler chain and fills the LDAP result fields. Register clientError for malformed client traffic or request-handling failures and error for listener failures. See the Error API for the error model.