feat(16-04): rebuild GroupFormModal to three states without AD binding

- Remove AD radio-selection block, discovery effect/state, and the
  two-step create-then-PATCH-bind flow from GroupFormModal.tsx (D-07):
  a local group can no longer be bound to an AD group from this dialog.
- Add locked name field with provenance hint + AD-DN read-only line and
  an editable internalName field for imported groups (D-03/D-04); create
  state gets a hint linking to the LDAP import area.
- Visible save-error line (never a silent catch{}) that distinguishes a
  409 name collision from a generic failure; dialog stays open, inputs
  are preserved.
- Add Group.internalName to the page.tsx interface now (Rule 3 — the
  modal cannot typecheck without it; Task 2 adds the display-cell usage).
- Add seven new admin.groups i18n keys to de.json/en.json (orphaned
  ldapBind.* keys removed in Task 3).
This commit is contained in:
2026-08-06 16:28:07 +02:00
parent 5a687a9d01
commit 30affbbc7e
4 changed files with 85 additions and 169 deletions
@@ -14,6 +14,7 @@ export interface Group {
tenantId: string;
name: string;
ldapDn: string | null;
internalName: string | null;
isDefault: boolean;
createdAt: string;
updatedAt: string;