feat(ldap): support anonymous bind (no bind DN/password required)
bindDn and bindPassword are now optional on LdapConfig (nullable
migration) and throughout the DTOs/service/client -- an admin can
leave both blank to connect to directories that permit anonymous
read access. LdapService.bind() falls back to an RFC 4513 anonymous
bind (empty DN + empty password) whenever either field is missing,
shared across testConnection, listGroups, and syncUsersForTenant.
Frontend: removed the required attribute from Bind-DN/Bind-Passwort,
added a placeholder hint ("leer = anonymous bind"), and the
"Verbindung testen" button now only needs a Server-URL to enable
(not bindDn+bindPassword). Config responses now return bindPassword
as null (not a misleading "********") when no password is set.
Verified locally: submitted only a Server-URL with both bind fields
empty and confirmed the request reached the anonymous-bind code path
(DNS failure for the unreachable test host, not a validation error).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -350,9 +350,8 @@ export default function AdminLdapPage() {
|
||||
type="text"
|
||||
value={formData.bindDn}
|
||||
onChange={(e) => setFormData({ ...formData, bindDn: e.target.value })}
|
||||
placeholder="cn=admin,dc=example,dc=com"
|
||||
placeholder="cn=admin,dc=example,dc=com (leer = anonymous bind)"
|
||||
className="flex h-10 w-full rounded-md border border-input bg-background px-3 py-2 text-sm"
|
||||
required
|
||||
/>
|
||||
</div>
|
||||
<div className="space-y-2">
|
||||
@@ -363,9 +362,8 @@ export default function AdminLdapPage() {
|
||||
type="password"
|
||||
value={formData.bindPassword}
|
||||
onChange={(e) => setFormData({ ...formData, bindPassword: e.target.value })}
|
||||
placeholder={config ? '********' : ''}
|
||||
placeholder={config?.bindPassword ? '********' : ''}
|
||||
className="flex h-10 w-full rounded-md border border-input bg-background px-3 py-2 text-sm"
|
||||
required={!config}
|
||||
/>
|
||||
</div>
|
||||
</div>
|
||||
@@ -392,10 +390,7 @@ export default function AdminLdapPage() {
|
||||
<button
|
||||
type="button"
|
||||
onClick={handleTestConnection}
|
||||
disabled={
|
||||
!config &&
|
||||
!(formData.serverUrl && formData.bindDn && formData.bindPassword)
|
||||
}
|
||||
disabled={!config && !formData.serverUrl}
|
||||
className="rounded-md border border-border px-4 py-2 text-sm font-medium text-foreground hover:bg-muted transition-colors disabled:opacity-50"
|
||||
>
|
||||
{t('testConnection')}
|
||||
|
||||
Reference in New Issue
Block a user