3 ms·
paperless-ngx is successor of paperless and paperless-ng. Around that time I moved to https://teedy.io https://teedy.io which is also opensource https://github.
by pratio 2y ago
paperless-ngx is successor of paperless and paperless-ng. Around that time I moved to https://teedy.io https://teedy.io which is also opensource https://github.com/sismics/docs https://github.com/sismics/docs and also support ldap.
I've been itching to give paperless-ngx a shot because I just love it but ldap hasn't yet ended up in the docs but the pull request was merged https://github.com/paperless-ngx/paperless-ngx/pull/5190 https://github.com/paperless-ngx/paperless-ngx/pull/5190.
Regardless, I just love how this project just keeps coming back to life
- candiddevmike 2y agoAs someone who is adding SSO to B2C apps, are you an LDAP or nothing kind of person or would you consider things with OIDC/OAuth integration too? LDAP is such a pain in the ass to integrate with, and it seems like most things are going OIDC these days.
- pratio 2y agoAbsolutely, would love OIDC/OAuth. I use https://goauthentik.io/ https://goauthentik.io/. Teedy supports only LDAP so that's what I'm using right now.
- candiddevmike 2y agoNice, thank you. Ive been busy adding OIDC client support to a household management app (https://homechart.app https://homechart.app) and I'm now adding support for making it an OIDC provider too. In theory, you'd already have accounts for all of your household members (ideally with TOTP or WebAuthn), so it should be a good identity provider. I've been avoiding LDAP like the plague. I think MS is moving away from self-hosted AD, and LDAP really loses its luster for most folks when the self hosted options are something like OpenLDAP.
- pratio 2y agoSo, https://goauthentik.io/ https://goauthentik.io/ actually supports totp with ldap as well. https://docs.goauthentik.io/docs/providers/ldap#binding--bind-modes https://docs.goauthentik.io/docs/providers/ldap#binding--bin... And the parent makes a good point that OIDC/OAuth does not give group membership.
- vetinari 2y agoOIDC is not really a replacement for LDAP. SAML2 could be, but OIDC in itself has no concept like group membership. Kerberos, yes, but LDAP no. What are your pain points integrating with LDAP? It is pretty simple.
- candiddevmike 2y agoOIDC _can_ have group memberships if the provider/client support it via claims. LDAP is a pain because you have to expose/support a lot of knobs for integration (bind vs anonymous, secure vs unsecure, group format, root DNs, etc.). OIDC is (in theory) a lot simpler for the most part as the bare minimum is discovery URL, client ID, and client secret.
- bigfatkitten 2y agoAnd LDAP is a nonstarter for passwordless auth.