feat(ldap): group/OU discovery endpoint + selective sync filter
Adds listGroups() to browse AD groups/OUs under base DN, and collectSearchEntries() to restrict syncUsersForTenant to members of selected groups or users under selected OUs. Group DNs are matched via escaped memberOf clauses (RFC 4515); OU DNs become extra search bases. Empty groupFilterDns keeps the original single-base-DN search unchanged. Controller sync endpoint and the sync scheduler both pass groupFilterDns through so manual and scheduled syncs honor it. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -64,6 +64,7 @@ export class LdapSyncScheduler {
|
||||
bindDn: config.bindDn,
|
||||
bindPassword: config.bindPassword,
|
||||
searchFilter: config.searchFilter,
|
||||
groupFilterDns: config.groupFilterDns,
|
||||
fieldMappings: config.fieldMappings,
|
||||
},
|
||||
config.tenantId,
|
||||
|
||||
Reference in New Issue
Block a user