feat(ldap): support anonymous bind (no bind DN/password required)
bindDn and bindPassword are now optional on LdapConfig (nullable
migration) and throughout the DTOs/service/client -- an admin can
leave both blank to connect to directories that permit anonymous
read access. LdapService.bind() falls back to an RFC 4513 anonymous
bind (empty DN + empty password) whenever either field is missing,
shared across testConnection, listGroups, and syncUsersForTenant.
Frontend: removed the required attribute from Bind-DN/Bind-Passwort,
added a placeholder hint ("leer = anonymous bind"), and the
"Verbindung testen" button now only needs a Server-URL to enable
(not bindDn+bindPassword). Config responses now return bindPassword
as null (not a misleading "********") when no password is set.
Verified locally: submitted only a Server-URL with both bind fields
empty and confirmed the request reached the anonymous-bind code path
(DNS failure for the unreachable test host, not a validation error).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -64,8 +64,8 @@ model LdapConfig {
|
||||
tenant Tenant @relation(fields: [tenantId], references: [id])
|
||||
serverUrl String
|
||||
baseDn String
|
||||
bindDn String
|
||||
bindPassword String
|
||||
bindDn String?
|
||||
bindPassword String?
|
||||
searchFilter String @default("(objectClass=person)")
|
||||
syncIntervalMin Int @default(60)
|
||||
isActive Boolean @default(true)
|
||||
|
||||
Reference in New Issue
Block a user