LDAP - Get User Attributes node
The LDAP - Get User Attributes node retrieves one or more attributes from a user entry in the LDAP directory.
This node is available in: Authentication, Admin, Self Service, API, Consent, Library, Custom, User Defined
LDAP configuration
Defines the connection protocol used to communicate with the LDAP server.
Option available:
- ldap: Standard (non-secure) connection (port 389).
- ldaps: Secure connection over SSL/TLS (port 636).
- start-tls: Connection starts as a standard LDAP connection (typically on port 389) and is then upgraded to a secure channel using TLS.
Specifies the hostname or IP address of the LDAP server.
Defines the port used to connect to the LDAP server.
Typical values:
- 389 for LDAP
- 636 for LDAPS
Specifies the maximum time (in seconds) to wait for a connection to the LDAP server.
A value of 0 usually means no timeout.
The Distinguished Name (DN) of the administrative user used to perform the LDAP search operation.
The password associated with the admin user DN.
Defines the base context (starting point) in the LDAP directory where the user search will be performed.
Defines the scope of the LDAP search:
- base: Searches only the base DN
- one: Searches one level under the base DN
- sub: Searches the entire subtree under the base DN
Specifies the LDAP search filter used to locate the user.
Example:(uid={{username}})
The filter can include variables to dynamically match user input.
Defines which LDAP attributes should be retrieved after a successful authentication (e.g., uid, samaccountname, mail, cn).
These attributes can be used in subsequent nodes of the flow. Each attribute is entered through the node's repeatable entry list in the UI, or you can reference a {{variable}} that resolves to the collection at runtime.
Save in session
The Save in Session option is used to persist data within the user session.
Session Attribute Mapping section allows mapping attributes to specific values.
Multiple mappings can be defined, they're then stored in the user session at the end of the flow.
Rule are defined as:attribute : value retrieved from the node
Example:username: uid
Attribute Manipulation
It is possible to use a set of basic functions to manipulate attributes, see Attribute Manipulation.
Save in the flow store
Attributes generated or retrieved from the node can be saved into a variable.
They can then be reused by other nodes in the flow by referencing them as {{variable.attribute}}.
To do this you choose attributes that need to be stored in the variable, and in the flow store (All attributes exposed by the node are listed in a multi-select dropdown, allowing the user to choose one or more of them), then a variable name that can be freely defined by the user.
There is also a flag to make the variable available to the frontend.
Default output node
- Success
- User Not Found
- Failure
JSON metadata
{
"name": "ldap_get_attributes",
"active": true,
"bundleName": "default-nodes",
"bundleVersion": "1.0",
"category": "ldap_ad_user_management",
"deprecated": false,
"displayName": [{
"lang": "en",
"value": "LDAP - Get User Attributes"
}, {
"lang": "it",
"value": "LDAP - Get User Attributes"
}
],
"nodeName": "LdapAttributes",
"index": 8,
"inputs": [{
"name": "Input"
}
],
"outputs": [{
"name": "Success",
"level": "success"
}, {
"name": "UserNotFound",
"level": "warning"
}, {
"name": "Failure",
"level": "error"
}
]
}