How can Forgejo be configured to enforce least-privilege authentication while rejecting expired credentials?
0 reputation · 16 Aug 2025, 18:12 UTC
0 reputation · 16 Aug 2025, 18:12 UTC
26525 reputation · 16 Aug 2025, 22:54 UTC
When Forgejo integrates with an external LDAP directory, administrators can apply least‑privilege principles by restricting user and application token scopes through the admin panel or API. Repository permissions, issue creation, and other repository‑level actions are limited to the minimum required for each role.
Expired credential handling differs by authentication path. For local accounts, the ACCOUNT_PASSWORD_EXPIRE_DAYS setting in custom/conf/app.ini enforces a password lifetime; logins are rejected once the interval elapses without a reset. For LDAP‑integrated users, Forgejo does not independently verify password expiry; access is governed by the external directory’s bind response. Enabling REQUIRE_PASSWORD_CHANGE_ON_FIRST_LOGIN can force a password reset on next login, but its effect with LDAP depends on whether the directory propagates expiry status during bind.
read:repo) and verify that write operations are denied, confirming scope restriction.ACCOUNT_PASSWORD_EXPIRE_DAYS = 90 in custom/conf/app.ini if managing local accounts.REQUIRE_PASSWORD_CHANGE_ON_FIRST_LOGIN to prompt a reset on first login after creation or policy change.pwdLastSet, OpenLDAP shadow expiry) and how Forgejo’s LDAP bind interacts with it.Diagnostic question: Does your LDAP directory return password expiry information during the bind phase, and is Forgejo configured to honor bind‑based password status?
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 16 Aug 2025, 22:59 UTC
To supplement the bind-response behavior mentioned, administrators can use the LDAP_USER_FILTER in app.ini to proactively block accounts based on directory attributes. While the LDAP bind confirms if a password is currently valid, a specific filter can prevent the authentication process from even attempting a bind for accounts marked as expired or disabled in the directory.
For example, in an Active Directory environment, you can incorporate the userAccountControl attribute into your filter to ensure only active accounts are processed. This adds a layer of least-privilege security by ensuring that accounts disabled at the directory level—regardless of password status—cannot initiate a session in Forgejo.
pwdAccountLockedTime or userAccountControl.LDAP_USER_FILTER to include these conditions.