You are here

class ServerForm in Lightweight Directory Access Protocol (LDAP) 8.3

Same name and namespace in other branches
  1. 8.4 ldap_servers/src/Form/ServerForm.php \Drupal\ldap_servers\Form\ServerForm

Class ServerForm.

@package Drupal\ldap_servers\Form


Expanded class hierarchy of ServerForm


ldap_servers/src/Form/ServerForm.php, line 14


View source
class ServerForm extends EntityForm {

   * The server entity.
   * @var \Drupal\ldap_servers\Entity\Server
  protected $entity;

   * {@inheritdoc}
  public function form(array $form, FormStateInterface $form_state) {
    $form = parent::form($form, $form_state);

    /** @var \Drupal\ldap_servers\Entity\Server $server */
    $server = $this->entity;
    $form['server'] = [
      '#type' => 'fieldset',
      '#title' => $this
      '#open' => TRUE,
    $form['server']['label'] = [
      '#type' => 'textfield',
      '#title' => $this
      '#maxlength' => 255,
      '#default_value' => $server
      '#description' => $this
        ->t("Choose a unique <strong><em>name</em></strong> for this server configuration."),
      '#required' => TRUE,
    $form['server']['id'] = [
      '#type' => 'machine_name',
      '#default_value' => $server
      '#machine_name' => [
        'exists' => '\\Drupal\\ldap_servers\\Entity\\Server::load',
      '#disabled' => !$server

    /* You will need additional form elements for your custom properties. */
    $form['server']['status'] = [
      '#title' => $this
      '#type' => 'checkbox',
      '#default_value' => $server
      '#description' => $this
        ->t('Disable in order to keep configuration without having it active.'),
    $form['server']['type'] = [
      '#title' => $this
        ->t('LDAP Server type'),
      '#type' => 'select',
      '#options' => [
        'default' => 'Default LDAP',
        'ad' => 'Active Directory',
        'novell_edir' => 'Novell',
        'openldap' => 'Open LDAP',
        'opendir' => 'Apple Open Directory',
      '#default_value' => $server
      '#description' => $this
        ->t("This field is informative. It's purpose is to assist with default values and give validation warnings."),
    $form['server']['address'] = [
      '#type' => 'textfield',
      '#title' => $this
        ->t('Server address'),
      '#maxlength' => 255,
      '#default_value' => $server
      '#description' => $this
        ->t('The domain name or IP address of your LDAP Server such as "".<br> For SSL use the form ldaps://DOMAIN such as \\ldaps://"'),
      '#required' => TRUE,
    $form['server']['port'] = [
      '#type' => 'number',
      '#title' => $this
        ->t('Server port'),
      '#min' => 1,
      '#max' => 65535,
      '#default_value' => $server
        ->get('port') ? $server
        ->get('port') : 389,
      '#description' => $this
        ->t("The TCP/IP port on the above server which accepts LDAP connections. Must be an integer."),
      '#required' => TRUE,
    $form['server']['timeout'] = [
      '#type' => 'number',
      '#title' => $this
        ->t('Network timeout'),
      '#min' => -1,
      '#max' => 999,
      '#default_value' => $server
        ->get('timeout') ? $server
        ->get('timeout') : 10,
      '#description' => $this
        ->t("How long to wait for a response from the LDAP server in seconds."),
      '#required' => TRUE,
    $form['server']['tls'] = [
      '#title' => $this
        ->t('Use Start-TLS'),
      '#type' => 'checkbox',
      '#default_value' => $server
      '#description' => $this
        ->t("Secure the connection between the Drupal and the LDAP servers using TLS.<br> <em>Note: To use START-TLS, you must set the LDAP Port to 389.</em>"),
    $form['bind'] = [
      '#type' => 'fieldset',
      '#title' => $this
    $form['bind']['bind_method'] = [
      '#default_value' => $server
        ->get('bind_method') ? $server
        ->get('bind_method') : 'service_account',
      '#type' => 'radios',
      '#title' => $this
        ->t('Binding Method for Searches'),
      '#options' => [
        'service_account' => $this
          ->t('Service Account Bind: Use credentials in the Service Account field below to bind to LDAP <br> <div class="description">This option is usually a best practice.<br> This is also required for provisioning LDAP accounts and groups.<br> For security reasons, this pair should belong to an  LDAP account with stripped down permissions.</div>'),
        'user' => $this
          ->t('Bind with Users Credentials: Use user\'s entered credentials to bind to LDAP<br> <div class="description">This is only useful for modules that execute during user logon such as LDAP Authentication and LDAP Authorization.<br> This option is not a best practice in most cases.<br> The user\'s dn must be of the form "cn=[username],[base dn]" for this option to work.</div>'),
        'anon_user' => $this
          ->t('Anonymous Bind for search, then Bind with Users Credentials<br> <div class="description">Searches for user dn then uses user\'s entered credentials to bind to LDAP.<br/> This is only useful for modules that work during user logon such as LDAP Authentication and LDAP Authorization. <br>
        The user\'s dn must be discovered by an anonymous search for this option to work.</div>'),
        'anon' => $this
          ->t('Anonymous Bind: Use no credentials to bind to LDAP server<br/> <div class="description">This option will not work on most LDAPS connections.</div>'),
    $form['bind']['binddn'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#title' => $this
        ->t('DN for non-anonymous search'),
      '#size' => 80,
      '#maxlength' => 512,
      '#states' => [
        'visible' => [
          ':input[name=bind_method]' => [
            'value' => strval('service_account'),
        'required' => [
          ':input[name=bind_method]' => [
            'value' => strval('service_account'),
    $form['bind']['bindpw'] = [
      '#type' => 'password',
      '#title' => $this
        ->t('Password for non-anonymous search'),
      '#size' => 80,
      '#states' => [
        'visible' => [
          ':input[name=bind_method]' => [
            'value' => strval('service_account'),
        'required' => [
          ':input[name=bind_method]' => [
            'value' => strval('service_account'),
    if ($server
      ->get('bindpw')) {
      $form['bind']['bindpw']['#attributes'] = [
        'value' => '****',
    $form['users'] = [
      '#type' => 'fieldset',
      '#title' => $this
    $form['users']['basedn'] = [
      '#default_value' => $server
      '#type' => 'textarea',
      '#cols' => 50,
      '#rows' => 6,
      '#title' => $this
        ->t('Base DNs for LDAP users, groups, and other entries.'),
      '#description' => '<div>' . $this
        ->t('DNs that have  relevant entries, e.g. <code>ou=campus accounts,dc=ad,dc=uiuc,dc=edu</code>.<br> Keep in mind that every additional basedn likely doubles the number of queries. <br> Place the more heavily used one first and consider using one higher base DN rather than 2 or more lower base DNs.<br> Enter one per line in case if you need more than one.') . '</div>',
    $form['users']['user_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('AuthName attribute'),
      '#description' => $this
        ->t("The attribute that holds the user's login name. (eg. <code>cn</code> for eDir or <code>sAMAccountName</code> for Active Directory)."),
    $form['users']['account_name_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('AccountName attribute'),
      '#description' => $this
        ->t('The attribute that holds the unique account name. Defaults to the same as the AuthName attribute.'),
    $form['users']['mail_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('Email attribute'),
      '#description' => $this
        ->t("The attribute that holds the user's email address. (eg. <code>mail</code>). Leave empty if no such attribute exists"),
    $form['users']['mail_template'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('Email template'),
      '#description' => $this
        ->t("If no attribute contains the user's email address, but it can be derived from other attributes, enter an email \"template\" here.<br> Templates should have the user's attribute name in form such as [cn], [uin], etc. such as <code>[cn]</code>.<br> See also the <a href=\"\"> documentation on LDAP tokens</a>."),
    $form['users']['picture_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('Thumbnail attribute'),
      '#description' => $this
        ->t("The attribute that holds the user's thumnail image. (e.g. <code>thumbnailPhoto</code>). Leave empty if no such attribute exists"),
    $form['users']['unique_persistent_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('Persistent and Unique User ID Attribute'),
      '#description' => $this
        ->t("Login attributes are not always persistent (e.g. change in last name or email).<br> Most setups should set this attribute to avoid creation of duplicate accounts or other issues.<br> In cases where DN does not change, enter 'dn' here. If no such attribute exists, leave this blank."),
    $form['users']['unique_persistent_attr_binary'] = [
      '#default_value' => $server
      '#type' => 'checkbox',
      '#title' => $this
        ->t('Does the <em>Persistent and Unique User ID Attribute</em> hold a binary value?'),
      '#description' => $this
        ->t("You need to set this if you are using a binary attribute such as objectSid in ActiveDirectory for the PUID.<br> If you don't want this consider switching to another attribute, such as samaccountname."),
    $form['users']['user_dn_expression'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 80,
      '#title' => $this
        ->t('Expression for user DN. Required when "Bind with Users Credentials" method selected.'),
      '#description' => $this
        ->t('%username and %basedn are valid tokens in the expression.<br> Typically it will be: <code>cn=%username,%basedn</code> which might evaluate to <code>cn=jdoe,ou=campus accounts,dc=ad,dc=mycampus,dc=edu</code>'),
    $form['users']['testing_drupal_username'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('Testing Drupal Username'),
      '#description' => $this
        ->t("This is optional and used for testing this server's configuration against an actual username<br>The user need not exist in Drupal and testing will not affect the user's LDAP or Drupal Account."),
    $form['users']['testing_drupal_user_dn'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 120,
      '#title' => $this
        ->t('DN of testing username'),
      '#description' => $this
        ->t("This is optional and used for testing this server's configuration against an actual username, e.g. cn=hpotter,ou=people,dc=hogwarts,dc=edu.<br> The user need not exist in Drupal and testing will not affect the user's LDAP or Drupal Account."),
    $form['groups'] = [
      '#type' => 'fieldset',
      '#title' => $this
    $form['groups']['grp_unused'] = [
      '#default_value' => $server
      '#type' => 'checkbox',
      '#title' => $this
        ->t('Groups are not relevant to this Drupal site. This is generally true if LDAP Groups and LDAP Authorization are not in use.'),
      '#disabled' => FALSE,
    $form['groups']['grp_nested'] = [
      '#default_value' => $server
      '#type' => 'checkbox',
      '#title' => $this
        ->t('Nested groups are used in my LDAP'),
      '#disabled' => FALSE,
      '#description' => $this
        ->t('If a user is a member of group A and group A is a member of group B, user should be considered to be in group A and B.<br> If your LDAP has nested groups, but you want to ignore nesting, leave this unchecked.'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['grp_memb_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t("LDAP Group Entry Attribute Holding User's DN, CN, etc."),
      '#description' => $this
        ->t('e.g uniquemember, memberUid'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['derive_group'] = [
      '#type' => 'fieldset',
      '#title' => $this
        ->t('Derive from group'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['derive_group']['grp_object_cat'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('Name of Group Object Class'),
      '#description' => $this
        ->t('e.g. groupOfNames, groupOfUniqueNames, group.'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['derive_group']['grp_memb_attr_match_user_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('User attribute held in "LDAP Group Entry Attribute Holding..."'),
      '#description' => $this
        ->t('This is almost always "dn" (which technically isn\'t an attribute). Sometimes its "cn".'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['attribute'] = [
      '#type' => 'fieldset',
      '#title' => $this
        ->t('Derive from user attribute'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['attribute']['grp_user_memb_attr_exists'] = [
      '#default_value' => $server
      '#type' => 'checkbox',
      '#title' => $this
        ->t('A user LDAP attribute such as <code>memberOf</code> exists that contains a list of their groups.'),
      '#description' => $this
        ->t('Active Directory and openLdap with memberOf overlay fit this model. <br> Using this ignores "derive from group"'),
      '#disabled' => FALSE,
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['attribute']['grp_user_memb_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t('Attribute in User Entry Containing Groups'),
      '#description' => $this
        ->t('e.g. memberOf <em>(case sensitive)</em>.'),
      '#states' => [
        'enabled' => [
          ':input[name=grp_user_memb_attr_exists]' => [
            'checked' => TRUE,
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['deriveDN'] = [
      '#type' => 'fieldset',
      '#title' => $this
        ->t('Derive from DN'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['deriveDN']['grp_derive_from_dn'] = [
      '#default_value' => $server
      '#type' => 'checkbox',
      '#title' => $this
        ->t("Groups are derived from user's LDAP entry DN."),
      '#description' => $this
        ->t('This group definition has very limited functionality and most modules will not take this into account.  LDAP Authorization will.'),
      '#disabled' => FALSE,
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['deriveDN']['grp_derive_from_dn_attr'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 30,
      '#title' => $this
        ->t("Attribute of the user's LDAP entry DN which contains the group"),
      '#description' => $this
        ->t('e.g. ou'),
      '#states' => [
        'enabled' => [
          ':input[name=grp_derive_from_dn]' => [
            'checked' => TRUE,
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['grp_test_grp_dn'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 120,
      '#title' => $this
        ->t('Testing LDAP Group DN'),
      '#description' => $this
        ->t('This is optional and can be useful for debugging and validating forms.'),
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['groups']['grp_test_grp_dn_writeable'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 120,
      '#title' => $this
        ->t('Testing LDAP Group DN that is writable.'),
      '#description' => $this
        ->t("<strong>WARNING:</strong> the test script for the server will create, delete, and add members to this group! <br> This is optional and can be useful for debugging and validating forms."),
      '#placeholder' => $this
      '#states' => [
        'visible' => [
          ':input[name=grp_unused]' => [
            'checked' => FALSE,
    $form['pagination'] = [
      '#type' => 'fieldset',
      '#title' => $this
    $form['pagination']['search_pagination'] = [
      '#default_value' => $server
      '#type' => 'checkbox',
      '#title' => $this
        ->t('Use LDAP Pagination.'),
    $form['pagination']['search_page_size'] = [
      '#default_value' => $server
      '#type' => 'textfield',
      '#size' => 10,
      '#title' => $this
        ->t('Pagination size limit.'),
      '#description' => $this
        ->t('This should be equal to or smaller than the max number of entries returned at a time by your LDAP server. 1000 is a good guess when unsure. Other modules such as LDAP Query or LDAP Feeds will be allowed to set a smaller page size, but not a larger one.'),
      '#states' => [
        'visible' => [
          ':input[name="search_pagination"]' => [
            'checked' => TRUE,
    return $form;

   * {@inheritdoc}
  public function save(array $form, FormStateInterface $form_state) {
    if ($form_state
      ->getValue('bind_method') != 'service_account') {
        ->set('binddn', NULL);
        ->set('bindpw', NULL);
    else {
      if ($form_state
        ->getValue('bindpw') != '****') {
          ->set('bindpw', $form_state
      else {

        // Fetch existing password since the placeholder is present.
        $oldConfiguration = Server::load($this->entity
        if ($oldConfiguration && $oldConfiguration
          ->get('bindpw')) {
            ->set('bindpw', $oldConfiguration
    $fields = [
    foreach ($fields as $field) {
        ->set($field, mb_strtolower(trim($this->entity
    $status = $this->entity
    switch ($status) {
      case SAVED_NEW:
          ->t('Created the %label Server.', [
          '%label' => $this->entity
          ->t('Saved the %label Server.', [
          '%label' => $this->entity



Namesort descending Modifiers Type Description Overrides
DependencySerializationTrait::$_entityStorages protected property An array of entity type IDs keyed by the property name of their storages.
DependencySerializationTrait::$_serviceIds protected property An array of service IDs keyed by property name used for serialization.
DependencySerializationTrait::__sleep public function 1
DependencySerializationTrait::__wakeup public function 2
EntityForm::$entityTypeManager protected property The entity type manager. 3
EntityForm::$moduleHandler protected property The module handler service.
EntityForm::$operation protected property The name of the current operation.
EntityForm::$privateEntityManager private property The entity manager.
EntityForm::actions protected function Returns an array of supported actions for the current entity form. 29
EntityForm::actionsElement protected function Returns the action form element for the current entity form.
EntityForm::afterBuild public function Form element #after_build callback: Updates the entity with submitted data.
EntityForm::buildEntity public function Builds an updated entity object based upon the submitted form values. Overrides EntityFormInterface::buildEntity 2
EntityForm::buildForm public function Form constructor. Overrides FormInterface::buildForm 10
EntityForm::copyFormValuesToEntity protected function Copies top-level form values to entity properties 7
EntityForm::getBaseFormId public function Returns a string identifying the base form. Overrides BaseFormIdInterface::getBaseFormId 5
EntityForm::getEntity public function Gets the form entity. Overrides EntityFormInterface::getEntity
EntityForm::getEntityFromRouteMatch public function Determines which entity will be used by this form from a RouteMatch object. Overrides EntityFormInterface::getEntityFromRouteMatch 1
EntityForm::getFormId public function Returns a unique string identifying the form. Overrides FormInterface::getFormId 10
EntityForm::getOperation public function Gets the operation identifying the form. Overrides EntityFormInterface::getOperation
EntityForm::init protected function Initialize the form state and the entity before the first form build. 3
EntityForm::prepareEntity protected function Prepares the entity object before the form is built first. 3
EntityForm::prepareInvokeAll protected function Invokes the specified prepare hook variant.
EntityForm::processForm public function Process callback: assigns weights and hides extra fields.
EntityForm::setEntity public function Sets the form entity. Overrides EntityFormInterface::setEntity
EntityForm::setEntityManager public function Sets the entity manager for this form. Overrides EntityFormInterface::setEntityManager
EntityForm::setEntityTypeManager public function Sets the entity type manager for this form. Overrides EntityFormInterface::setEntityTypeManager
EntityForm::setModuleHandler public function Sets the module handler for this form. Overrides EntityFormInterface::setModuleHandler
EntityForm::setOperation public function Sets the operation for this form. Overrides EntityFormInterface::setOperation
EntityForm::submitForm public function This is the default entity object builder function. It is called before any other submit handler to build the new entity object to be used by the following submit handlers. At this point of the form workflow the entity is validated and the form state… Overrides FormInterface::submitForm 17
EntityForm::__get public function
EntityForm::__set public function
FormBase::$configFactory protected property The config factory. 1
FormBase::$requestStack protected property The request stack. 1
FormBase::$routeMatch protected property The route match.
FormBase::config protected function Retrieves a configuration object.
FormBase::configFactory protected function Gets the config factory for this form. 1
FormBase::container private function Returns the service container.
FormBase::create public static function Instantiates a new instance of this class. Overrides ContainerInjectionInterface::create 87
FormBase::currentUser protected function Gets the current user.
FormBase::getRequest protected function Gets the request object.
FormBase::getRouteMatch protected function Gets the route match.
FormBase::logger protected function Gets the logger for a specific channel.
FormBase::redirect protected function Returns a redirect response object for the specified route. Overrides UrlGeneratorTrait::redirect
FormBase::resetConfigFactory public function Resets the configuration factory.
FormBase::setConfigFactory public function Sets the config factory for this form.
FormBase::setRequestStack public function Sets the request stack object to use.
FormBase::validateForm public function Form validation handler. Overrides FormInterface::validateForm 62
LinkGeneratorTrait::$linkGenerator protected property The link generator. 1
LinkGeneratorTrait::getLinkGenerator Deprecated protected function Returns the link generator.
LinkGeneratorTrait::l Deprecated protected function Renders a link to a route given a route name and its parameters.
LinkGeneratorTrait::setLinkGenerator Deprecated public function Sets the link generator service.
LoggerChannelTrait::$loggerFactory protected property The logger channel factory service.
LoggerChannelTrait::getLogger protected function Gets the logger for a specific channel.
LoggerChannelTrait::setLoggerFactory public function Injects the logger channel factory.
MessengerTrait::$messenger protected property The messenger. 29
MessengerTrait::messenger public function Gets the messenger. 29
MessengerTrait::setMessenger public function Sets the messenger.
RedirectDestinationTrait::$redirectDestination protected property The redirect destination service. 1
RedirectDestinationTrait::getDestinationArray protected function Prepares a 'destination' URL query parameter for use with \Drupal\Core\Url.
RedirectDestinationTrait::getRedirectDestination protected function Returns the redirect destination service.
RedirectDestinationTrait::setRedirectDestination public function Sets the redirect destination service.
ServerForm::$entity protected property The server entity. Overrides EntityForm::$entity
ServerForm::form public function Gets the actual form array to be built. Overrides EntityForm::form
ServerForm::save public function Form submission handler for the 'save' action. Overrides EntityForm::save
StringTranslationTrait::$stringTranslation protected property The string translation service. 1
StringTranslationTrait::formatPlural protected function Formats a string containing a count of items.
StringTranslationTrait::getNumberOfPlurals protected function Returns the number of plurals supported by a given language.
StringTranslationTrait::getStringTranslation protected function Gets the string translation service.
StringTranslationTrait::setStringTranslation public function Sets the string translation service to use. 2
StringTranslationTrait::t protected function Translates a string to the current language or to a given language.
UrlGeneratorTrait::$urlGenerator protected property The url generator.
UrlGeneratorTrait::getUrlGenerator Deprecated protected function Returns the URL generator service.
UrlGeneratorTrait::setUrlGenerator Deprecated public function Sets the URL generator service.
UrlGeneratorTrait::url Deprecated protected function Generates a URL or path for a specific route based on the given parameters.