Plugin author
1 plugin in the catalog · ★ 0 GitHub stars across them · first listed Oct 2, 2026 · General
LDAP / Active Directory password login for the web dashboard. Verifies credentials with an LDAP bind (direct or search-then-bind), never stores passwords, requires ldaps:// or StartTLS, and supports group restriction. Registers the `ldap` dashboard auth provider once dashboard.ldap_auth is configured. Disclosure — dashboard logins are verified by binding to your configured LDAP/AD server with the user's password (TLS with certificate validation required unless allow_insecure is set); sessions are stateless HMAC tokens (12h access / 30d refresh by default) signed with HERMES_DASHBOARD_LDAP_SECRET or a random per-process key, and logout cannot revoke them; group removal and disabled accounts are not re-checked until the refresh token expires; failed logins count toward the directory's account-lockout policy.
← Back to the catalog