Addict
Get a full Active Directory REST API in 30 seconds
Addict is a drop-in REST API microservice for Active Directory and LDAP implementations. Just like that.
Doing this:
npm i addict-api -g addict --url ldaps://[address] --user [user]@[domain] --pass [pass]
Gives you a web server with REST endpoints to add, remove, move, disable, enable, unlock or list Users, Groups and Organizational Units. It includes result caching by default and flexible filters for querying, sorting, pagination and column selection.
There's interactive API docs at /api
:
No, it's not Slate.
These docs let you add arguments, try the requests and see the results.
Made with <3 by dthree.
API
# Users GET /userPOST /userGET /user/:userGET /user/:user/existsGET /user/:user/member-of/:groupPOST /user/:user/authenticatePUT /user/:user/passwordPUT /user/:user/password-never-expiresPUT /user/:user/password-expiresPUT /user/:user/enablePUT /user/:user/disablePUT /user/:user/movePUT /user/:user/unlockDELET /user/:user # Groups GET /groupPOST /groupGET /group/:groupGET /group/:group/existsPOST /group/:group/user/:userDELETE /group/:group/user/:userDELETE /group/:group # Organizational Units GET /ouPOST /ouGET /ou/:ouGET /ou/:ou/existsDELETE /ou/:ou # Other GET /otherGET /allGET /find/:filterGET /status # Monitoring GET /status
Want more? Just ask.
Filters
Fields
Choose which fields to include in the results:
GET /user?_fields=description,cn
Filter
Filter any field with fieldName=value
.
GET /group?cn=Guests
We've got operators as well:
GET /user?userAccountControl_gte=500
Operators
=
: Equals_ne=
: Not equals_lt=
: Less than_gt=
: Greater than_gte=
: Greater than or equal to_lte=
: Less than or equal to_like=
: Like (fuzzy search)
Sort
GET /ou?_sort=whenCreated,dn&_order=desc,asc
Paginate
GET /user?_page=6&limit=10
Slice
Add _start
and _end
or _limit
:
GET /user?_start=20&_limit=40
Full Text Search
GET /group?_q=addict
The Nitty Gritty
Passing Secrets
You can pass the AD details at runtime:
addict --url ldaps://[address] --user [user]@[domain] --pass [pass]
As environmental variables:
export ADDICT_URL=ldaps://[address]export ADDICT_USER=[user]@[domain]export ADDICT_PASS=[pass]
Or in ./config.json
:
git clone https://github.com/dthree/addict.gitcd addictvim ./config.json
Authentication
This service defaults to no authentication. I can't and won't try to guess your flavor.
Addict uses express
. The file ./middleware.js
at the root of the directory exposes the app so you can add middleware hooks for auth logic.
LDAP vs LDAPS
If you connect to Active Directory over plain LDAP, it will refuse certain write operations including adding a user and changing a password. To make things even better, Windows Server doesn't support LDAPS out of the box. You're going to have to set up the Domain Controller as a cert authority by installing the Active Directory Certificate Services
Role.
Here's a good tutorial on that.
License
MIT