feat(16-04): rebuild GroupFormModal to three states without AD binding

- Remove AD radio-selection block, discovery effect/state, and the
  two-step create-then-PATCH-bind flow from GroupFormModal.tsx (D-07):
  a local group can no longer be bound to an AD group from this dialog.
- Add locked name field with provenance hint + AD-DN read-only line and
  an editable internalName field for imported groups (D-03/D-04); create
  state gets a hint linking to the LDAP import area.
- Visible save-error line (never a silent catch{}) that distinguishes a
  409 name collision from a generic failure; dialog stays open, inputs
  are preserved.
- Add Group.internalName to the page.tsx interface now (Rule 3 — the
  modal cannot typecheck without it; Task 2 adds the display-cell usage).
- Add seven new admin.groups i18n keys to de.json/en.json (orphaned
  ldapBind.* keys removed in Task 3).
This commit is contained in:
2026-08-06 16:28:07 +02:00
parent 5a687a9d01
commit 30affbbc7e
4 changed files with 85 additions and 169 deletions
+7
View File
@@ -402,7 +402,14 @@
"actions": "Actions",
"membersButton": "Members",
"saveError": "Could not save group. Please try again.",
"saveErrorNameTaken": "This name is already taken.",
"deleteError": "Could not delete group. Please try again.",
"nameLockedHint": "Taken from the AD group. Updated automatically on the next sync.",
"adDnLabel": "AD DN: {ldapDn}",
"internalName": "Internal Name",
"internalNameHint": "Never changed by the sync. If left empty, the interface shows the AD name instead.",
"createLdapHint": "AD groups are imported in the LDAP area, not created here.",
"goToLdap": "Go to LDAP area",
"ldapBind": {
"hint": "Choose an AD group from the list to sync membership automatically.",
"bound": "Bound to: {ldapDn}",