diff --git a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts index 7bcdb2818..cc96cf327 100644 --- a/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts +++ b/backend/src/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-fns.ts @@ -80,7 +80,6 @@ export const ldapPasswordRotationFactory: TRotationFactory< try { await executeWithPotentialGateway( { ...connection, credentials: { ...connection.credentials, ...credentials } }, - gatewayService, gatewayV2Service, async () => {} ); @@ -150,7 +149,6 @@ export const ldapPasswordRotationFactory: TRotationFactory< } : credentials }, - gatewayService, gatewayV2Service, async (client) => { const userDn = await getDN(dn, client); diff --git a/backend/src/services/app-connection/ldap/ldap-connection-fns.ts b/backend/src/services/app-connection/ldap/ldap-connection-fns.ts index 36036f460..eb11e8459 100644 --- a/backend/src/services/app-connection/ldap/ldap-connection-fns.ts +++ b/backend/src/services/app-connection/ldap/ldap-connection-fns.ts @@ -4,7 +4,7 @@ import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service import { TGatewayV2ServiceFactory } from "@app/ee/services/gateway-v2/gateway-v2-service"; import { getConfig } from "@app/lib/config/env"; import { BadRequestError } from "@app/lib/errors"; -import { GatewayProxyProtocol, withGatewayProxy } from "@app/lib/gateway"; +import { GatewayProxyProtocol } from "@app/lib/gateway"; import { withGatewayV2Proxy } from "@app/lib/gateway-v2/gateway-v2"; import { logger } from "@app/lib/logger"; import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator"; @@ -109,7 +109,6 @@ export const getLdapConnectionClient = async ({ export const executeWithPotentialGateway = async ( config: TLdapConnectionConfig, - gatewayService: Pick, gatewayV2Service: Pick, operation: (client: ldap.Client) => Promise ): Promise => { @@ -117,7 +116,7 @@ export const executeWithPotentialGateway = async ( const { protocol, host, port } = parseLdapUrl(credentials.url); const appCfg = getConfig(); - if (gatewayId && gatewayService && gatewayV2Service) { + if (gatewayId && gatewayV2Service) { await blockLocalAndPrivateIpAddresses(credentials.url, true); const platformConnectionDetails = await gatewayV2Service.getPlatformConnectionDetailsByGatewayId({ gatewayId, @@ -162,52 +161,6 @@ export const executeWithPotentialGateway = async ( } ); } - - const relayDetails = await gatewayService.fnGetGatewayClientTlsByGatewayId(gatewayId); - const [relayHost, relayPort] = relayDetails.relayAddress.split(":"); - return withGatewayProxy( - async (proxyPort) => { - const proxyUrl = constructLdapUrl(protocol, "localhost", proxyPort); - const isSSL = protocol === "ldaps"; - - const client = ldap.createClient({ - url: proxyUrl, - timeout: LDAP_TIMEOUT, - connectTimeout: LDAP_TIMEOUT, - tlsOptions: isSSL - ? { - rejectUnauthorized: config.credentials.sslRejectUnauthorized, - ca: config.credentials.sslCertificate ? [config.credentials.sslCertificate] : undefined, - servername: host, - // bypass hostname verification for development - ...(appCfg.isDevelopmentMode ? { checkServerIdentity: () => undefined } : {}) - } - : undefined - }); - - return setupLdapClientHandlers(client, credentials.dn, credentials.password, async (ldapClient) => { - try { - return await operation(ldapClient); - } finally { - ldapClient.destroy(); - } - }); - }, - { - protocol: GatewayProxyProtocol.Tcp, - targetHost: host, - targetPort: port, - relayHost, - relayPort: Number(relayPort), - identityId: relayDetails.identityId, - orgId: relayDetails.orgId, - tlsOptions: { - ca: relayDetails.certChain, - cert: relayDetails.certificate, - key: relayDetails.privateKey.toString() - } - } - ); } // Non-gateway path - calls getLdapConnectionClient which has validation @@ -225,7 +178,7 @@ export const validateLdapConnectionCredentials = async ( gatewayV2Service: Pick ) => { try { - await executeWithPotentialGateway(config, gatewayService, gatewayV2Service, async (client) => { + await executeWithPotentialGateway(config, gatewayV2Service, async (client) => { // this shouldn't occur as handle connection error events in client but here as fallback if (!client.connected) { throw new BadRequestError({ message: "Unable to connect to LDAP server" });