feat(ldap): add groupFilterDns column for selective import filter
Persists per-tenant AD group/OU DNs to restrict which directory entries get synced. Empty array (default) preserves current behavior — import everyone under base DN. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,2 @@
|
|||||||
|
-- AlterTable
|
||||||
|
ALTER TABLE "LdapConfig" ADD COLUMN IF NOT EXISTS "groupFilterDns" TEXT[] NOT NULL DEFAULT ARRAY[]::TEXT[];
|
||||||
@@ -69,6 +69,7 @@ model LdapConfig {
|
|||||||
searchFilter String @default("(objectClass=person)")
|
searchFilter String @default("(objectClass=person)")
|
||||||
syncIntervalMin Int @default(60)
|
syncIntervalMin Int @default(60)
|
||||||
isActive Boolean @default(true)
|
isActive Boolean @default(true)
|
||||||
|
groupFilterDns String[] @default([])
|
||||||
lastSyncAt DateTime?
|
lastSyncAt DateTime?
|
||||||
createdAt DateTime @default(now())
|
createdAt DateTime @default(now())
|
||||||
updatedAt DateTime @updatedAt
|
updatedAt DateTime @updatedAt
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { PartialType } from '@nestjs/mapped-types';
|
import { PartialType } from '@nestjs/mapped-types';
|
||||||
import {
|
import {
|
||||||
|
IsArray,
|
||||||
IsBoolean,
|
IsBoolean,
|
||||||
IsInt,
|
IsInt,
|
||||||
IsNotEmpty,
|
IsNotEmpty,
|
||||||
@@ -40,6 +41,11 @@ export class CreateLdapConfigDto {
|
|||||||
@IsBoolean()
|
@IsBoolean()
|
||||||
@IsOptional()
|
@IsOptional()
|
||||||
isActive?: boolean = true;
|
isActive?: boolean = true;
|
||||||
|
|
||||||
|
@IsArray()
|
||||||
|
@IsString({ each: true })
|
||||||
|
@IsOptional()
|
||||||
|
groupFilterDns?: string[] = [];
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -39,6 +39,7 @@ export class LdapConfigService {
|
|||||||
searchFilter: dto.searchFilter ?? '(objectClass=person)',
|
searchFilter: dto.searchFilter ?? '(objectClass=person)',
|
||||||
syncIntervalMin: dto.syncIntervalMin ?? 60,
|
syncIntervalMin: dto.syncIntervalMin ?? 60,
|
||||||
isActive: dto.isActive ?? true,
|
isActive: dto.isActive ?? true,
|
||||||
|
groupFilterDns: dto.groupFilterDns ?? [],
|
||||||
fieldMappings: {
|
fieldMappings: {
|
||||||
create: [
|
create: [
|
||||||
{
|
{
|
||||||
@@ -79,6 +80,9 @@ export class LdapConfigService {
|
|||||||
syncIntervalMin: dto.syncIntervalMin,
|
syncIntervalMin: dto.syncIntervalMin,
|
||||||
}),
|
}),
|
||||||
...(dto.isActive !== undefined && { isActive: dto.isActive }),
|
...(dto.isActive !== undefined && { isActive: dto.isActive }),
|
||||||
|
...(dto.groupFilterDns !== undefined && {
|
||||||
|
groupFilterDns: dto.groupFilterDns,
|
||||||
|
}),
|
||||||
},
|
},
|
||||||
include: { fieldMappings: true },
|
include: { fieldMappings: true },
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user