auth.login_ex¶
Authenticate using one of a variety of mechanisms.
The mechanism is selected by the mechanism field of the request, and the set of supported mechanisms will be expanded in future releases.
Warning
Mechanisms with a _PLAIN suffix involve passing plain-text passwords or
password-equivalent strings and should not be used over untrusted or insecure
transport.
The response_type of the result indicates the outcome of the current authentication step and whether further action is required to complete authentication:
SUCCESS– authentication completed and a session was established.OTP_REQUIRED– the account requires a one-time password; the client must continue authentication by submitting the token via theOTP_TOKENmechanism.AUTH_ERR– generic authentication failure corresponding toPAM_AUTH_ERRandPAM_USER_UNKNOWNfrom libpam. Returned when the account does not exist or the credential is incorrect.EXPIRED– the supplied credential is expired and not suitable for authentication.REDIRECT– authentication must be performed on a different server.
A JSON-RPC error response (code -32001, Method call error) is returned instead of a result in the following cases:
a multistep challenge-response mechanism is in progress and the supplied
mechanismdoes not match the expected next step (errnoEBUSY)the
OTP_TOKENmechanism is used without a preceding step having requested it (errnoEINVAL)the current authenticator assurance level prohibits the supplied mechanism (errno
EOPNOTSUPP)
No Additional Items
Tuple Validation
Parameter 1: login_data
login_data
AuthApiKeyPlain
Type: objectNo Additional Properties
Mechanism
Type: constSpecific value:
"API_KEY_PLAIN"
Username
Type: stringApi Key
Type: stringAuthCommonOptions
Type: object Default: {"user_info": true}No Additional Properties
User Info
Type: boolean Default: trueAuthPasswordPlain
Type: objectNo Additional Properties
Mechanism
Type: constSpecific value:
"PASSWORD_PLAIN"
Username
Type: stringPassword
Type: stringAuthCommonOptions
Type: object Default: {"user_info": true}No Additional Properties
User Info
Type: boolean Default: trueAuthTokenPlain
Type: objectNo Additional Properties
Mechanism
Type: constSpecific value:
"TOKEN_PLAIN"
Token
Type: stringAuthCommonOptions
Type: object Default: {"user_info": true}No Additional Properties
User Info
Type: boolean Default: trueAuthOTPToken
Type: objectNo Additional Properties
Mechanism
Type: constSpecific value:
"OTP_TOKEN"
Otp Token
Type: stringAuthCommonOptions
Type: object Default: {"user_info": true}No Additional Properties
User Info
Type: boolean Default: trueResult
AuthRespSuccess
Type: objectNo Additional Properties
Response Type
Type: constSpecific value:
"SUCCESS"
AuthUserInfo
Type: objectNo Additional Properties
Pw Name
Type: stringname of the user
Pw Gecos
Type: stringfull username or comment field
Pw Dir
Type: stringuser home directory
Pw Shell
Type: stringuser command line interpreter
Pw Uid
Type: integernumerical user id of the user
Pw Gid
Type: integernumerical group id for the user's primary group
Grouplist
optional list of group ids for groups of which this account is a member. If get_groups is not specified, this value will be null.
No Additional Items
Each item of this array must be:
Sid
optional SID value for the account that is present if sid_info is specified in payload.
Source
Type: enum (of string)the source for the user account.
Must be one of:
- "LOCAL"
- "ACTIVEDIRECTORY"
- "LDAP"
Local
Type: booleanboolean value indicating whether the account is local to TrueNAS or provided by a directory service.
Attributes
Type: objectTwo Factor Config
Type: objectPrivilege
Type: objectAccount Attributes
Type: array of stringNo Additional Items
Each item of this array must be:
Authenticator
Type: enum (of string)Must be one of:
- "LEVEL_1"
- "LEVEL_2"
AuthRespAuthErr
Type: objectNo Additional Properties
Response Type
Type: constSpecific value:
"AUTH_ERR"
AuthRespExpired
Type: objectNo Additional Properties
Response Type
Type: constSpecific value:
"EXPIRED"
AuthRespOTPRequired
Type: objectNo Additional Properties
Response Type
Type: constSpecific value:
"OTP_REQUIRED"
Username
Type: stringAuthRespAuthRedirect
Type: objectNo Additional Properties
Response Type
Type: constSpecific value:
"REDIRECT"
Urls
Type: array of stringNo Additional Items
Each item of this array must be:
Required roles: