feat(ldap): AD connection prefill + group/OU import filter UI
New-config form now defaults to the CTL Active Directory connection values (balios.ctl.local:3268, dc=ctl,dc=local, AD person filter, down-level bind-DN hint) with the password left blank; editing an existing config still shows its real saved values. Adds a group/OU import filter section: discover AD groups/OUs via GET /ldap/groups, toggle selection or add DNs manually, persist via PATCH /ldap/config. Empty selection keeps today's "import everyone under base DN" behavior. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -23,10 +23,17 @@ interface LdapConfig {
|
||||
searchFilter: string;
|
||||
syncIntervalMin: number;
|
||||
isActive: boolean;
|
||||
groupFilterDns: string[];
|
||||
lastSyncAt: string | null;
|
||||
fieldMappings: FieldMapping[];
|
||||
}
|
||||
|
||||
interface LdapDirectoryEntry {
|
||||
dn: string;
|
||||
name: string;
|
||||
type: 'group' | 'ou';
|
||||
}
|
||||
|
||||
interface SyncResult {
|
||||
created: number;
|
||||
updated: number;
|
||||
@@ -53,13 +60,18 @@ export default function AdminLdapPage() {
|
||||
const [syncResult, setSyncResult] = useState<SyncResult | null>(null);
|
||||
const [syncing, setSyncing] = useState(false);
|
||||
|
||||
// Form state for connection settings
|
||||
// Form state for connection settings.
|
||||
// Defaults are pre-filled with the known-good CTL Active Directory
|
||||
// connection values (sourced from the working XWiki LDAP config) so a
|
||||
// brand-new setup only needs the service-account password. fetchConfig()
|
||||
// below overwrites these with the real saved values whenever a config
|
||||
// already exists.
|
||||
const [formData, setFormData] = useState({
|
||||
serverUrl: '',
|
||||
baseDn: '',
|
||||
serverUrl: 'ldap://balios.ctl.local:3268',
|
||||
baseDn: 'dc=ctl,dc=local',
|
||||
bindDn: '',
|
||||
bindPassword: '',
|
||||
searchFilter: '(objectClass=person)',
|
||||
searchFilter: '(&(objectClass=user)(objectCategory=person))',
|
||||
syncIntervalMin: 60,
|
||||
isActive: true,
|
||||
});
|
||||
@@ -68,6 +80,13 @@ export default function AdminLdapPage() {
|
||||
const [newMapping, setNewMapping] = useState({ ldapField: '', tesseraField: '' });
|
||||
const [showMappingForm, setShowMappingForm] = useState(false);
|
||||
|
||||
// Group/OU import filter (selective sync)
|
||||
const [groupFilterDns, setGroupFilterDns] = useState<string[]>([]);
|
||||
const [discovered, setDiscovered] = useState<LdapDirectoryEntry[] | null>(null);
|
||||
const [discovering, setDiscovering] = useState(false);
|
||||
const [manualDn, setManualDn] = useState('');
|
||||
const [savingFilter, setSavingFilter] = useState(false);
|
||||
|
||||
const hasAccess =
|
||||
currentUser?.role === 'ADMIN' || currentUser?.role === 'SUPER_ADMIN';
|
||||
|
||||
@@ -89,6 +108,7 @@ export default function AdminLdapPage() {
|
||||
syncIntervalMin: data.syncIntervalMin ?? 60,
|
||||
isActive: data.isActive ?? true,
|
||||
});
|
||||
setGroupFilterDns(data.groupFilterDns ?? []);
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
@@ -208,6 +228,59 @@ export default function AdminLdapPage() {
|
||||
}
|
||||
};
|
||||
|
||||
const handleDiscoverGroups = async () => {
|
||||
setDiscovering(true);
|
||||
try {
|
||||
const res = await fetch(`${API_URL}/ldap/groups`, {
|
||||
credentials: 'include',
|
||||
});
|
||||
if (res.ok) {
|
||||
const data = await res.json();
|
||||
setDiscovered(data);
|
||||
}
|
||||
} catch {
|
||||
// silently fail
|
||||
} finally {
|
||||
setDiscovering(false);
|
||||
}
|
||||
};
|
||||
|
||||
const toggleGroupFilterDn = (dn: string) => {
|
||||
setGroupFilterDns((prev) =>
|
||||
prev.includes(dn) ? prev.filter((d) => d !== dn) : [...prev, dn],
|
||||
);
|
||||
};
|
||||
|
||||
const handleAddManualDn = () => {
|
||||
const dn = manualDn.trim();
|
||||
if (!dn || groupFilterDns.includes(dn)) return;
|
||||
setGroupFilterDns((prev) => [...prev, dn]);
|
||||
setManualDn('');
|
||||
};
|
||||
|
||||
const handleRemoveGroupFilterDn = (dn: string) => {
|
||||
setGroupFilterDns((prev) => prev.filter((d) => d !== dn));
|
||||
};
|
||||
|
||||
const handleSaveGroupFilter = async () => {
|
||||
setSavingFilter(true);
|
||||
try {
|
||||
const res = await fetch(`${API_URL}/ldap/config`, {
|
||||
method: 'PATCH',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
credentials: 'include',
|
||||
body: JSON.stringify({ groupFilterDns }),
|
||||
});
|
||||
if (res.ok) {
|
||||
await fetchConfig();
|
||||
}
|
||||
} catch {
|
||||
// silently fail
|
||||
} finally {
|
||||
setSavingFilter(false);
|
||||
}
|
||||
};
|
||||
|
||||
if (!hasAccess) {
|
||||
return (
|
||||
<div className="flex items-center justify-center min-h-[60vh]">
|
||||
@@ -269,10 +342,11 @@ export default function AdminLdapPage() {
|
||||
type="text"
|
||||
value={formData.bindDn}
|
||||
onChange={(e) => setFormData({ ...formData, bindDn: e.target.value })}
|
||||
placeholder="cn=admin,dc=example,dc=com"
|
||||
placeholder="ctl\serviceaccount"
|
||||
className="flex h-10 w-full rounded-md border border-input bg-background px-3 py-2 text-sm"
|
||||
required
|
||||
/>
|
||||
<p className="text-xs text-muted-foreground">{t('bindDnHint')}</p>
|
||||
</div>
|
||||
<div className="space-y-2">
|
||||
<label className="text-sm font-medium text-foreground">
|
||||
@@ -455,6 +529,115 @@ export default function AdminLdapPage() {
|
||||
</section>
|
||||
)}
|
||||
|
||||
{/* Section 2.5: Group/OU import filter (selective sync) */}
|
||||
{config && (
|
||||
<section className="rounded-lg border border-border p-6">
|
||||
<h2 className="text-lg font-semibold text-foreground mb-2">
|
||||
{t('groupFilter.title')}
|
||||
</h2>
|
||||
<p className="text-sm text-muted-foreground mb-4">
|
||||
{t('groupFilter.description')}
|
||||
</p>
|
||||
|
||||
<div className="flex items-center gap-3 mb-4">
|
||||
<button
|
||||
type="button"
|
||||
onClick={handleDiscoverGroups}
|
||||
disabled={discovering}
|
||||
className="rounded-md border border-border px-4 py-2 text-sm font-medium text-foreground hover:bg-muted transition-colors disabled:opacity-50"
|
||||
>
|
||||
{discovering ? tCommon('loading') : t('groupFilter.discover')}
|
||||
</button>
|
||||
</div>
|
||||
|
||||
{discovered && discovered.length > 0 && (
|
||||
<div className="mb-4 max-h-64 overflow-y-auto rounded-md border border-border divide-y divide-border">
|
||||
{discovered.map((entry) => (
|
||||
<label
|
||||
key={entry.dn}
|
||||
className="flex items-center gap-3 px-4 py-2 text-sm hover:bg-muted/30 cursor-pointer"
|
||||
>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={groupFilterDns.includes(entry.dn)}
|
||||
onChange={() => toggleGroupFilterDn(entry.dn)}
|
||||
/>
|
||||
<span className="rounded bg-muted px-1.5 py-0.5 text-xs font-medium text-muted-foreground">
|
||||
{entry.type === 'ou' ? t('groupFilter.typeOu') : t('groupFilter.typeGroup')}
|
||||
</span>
|
||||
<span className="font-medium text-foreground">{entry.name}</span>
|
||||
<span className="font-mono text-xs text-muted-foreground truncate">
|
||||
{entry.dn}
|
||||
</span>
|
||||
</label>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
|
||||
{discovered && discovered.length === 0 && (
|
||||
<p className="mb-4 text-sm text-muted-foreground">{t('groupFilter.noneFound')}</p>
|
||||
)}
|
||||
|
||||
<div className="flex items-end gap-3 mb-4">
|
||||
<div className="flex-1 space-y-1">
|
||||
<label className="text-xs font-medium text-muted-foreground">
|
||||
{t('groupFilter.manualDn')}
|
||||
</label>
|
||||
<input
|
||||
type="text"
|
||||
value={manualDn}
|
||||
onChange={(e) => setManualDn(e.target.value)}
|
||||
placeholder="CN=Beispiel,OU=Gruppen,DC=ctl,DC=local"
|
||||
className="flex h-9 w-full rounded-md border border-input bg-background px-3 py-1 text-sm font-mono"
|
||||
/>
|
||||
</div>
|
||||
<button
|
||||
type="button"
|
||||
onClick={handleAddManualDn}
|
||||
className="h-9 rounded-md border border-border px-3 text-xs font-medium text-foreground hover:bg-muted transition-colors"
|
||||
>
|
||||
{t('groupFilter.addDn')}
|
||||
</button>
|
||||
</div>
|
||||
|
||||
<div className="mb-4">
|
||||
<p className="text-xs font-medium text-muted-foreground mb-2">
|
||||
{t('groupFilter.selected')}
|
||||
</p>
|
||||
{groupFilterDns.length === 0 ? (
|
||||
<p className="text-sm text-muted-foreground">{t('groupFilter.emptyMeansAll')}</p>
|
||||
) : (
|
||||
<ul className="space-y-1">
|
||||
{groupFilterDns.map((dn) => (
|
||||
<li
|
||||
key={dn}
|
||||
className="flex items-center justify-between gap-3 rounded-md border border-border px-3 py-1.5 text-sm"
|
||||
>
|
||||
<span className="font-mono text-xs text-foreground truncate">{dn}</span>
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => handleRemoveGroupFilterDn(dn)}
|
||||
className="shrink-0 rounded px-2 py-1 text-xs text-destructive hover:bg-destructive/10 transition-colors"
|
||||
>
|
||||
{t('fieldMapping.remove')}
|
||||
</button>
|
||||
</li>
|
||||
))}
|
||||
</ul>
|
||||
)}
|
||||
</div>
|
||||
|
||||
<button
|
||||
type="button"
|
||||
onClick={handleSaveGroupFilter}
|
||||
disabled={savingFilter}
|
||||
className="rounded-md bg-primary px-4 py-2 text-sm font-medium text-primary-foreground hover:opacity-90 transition-opacity disabled:opacity-50"
|
||||
>
|
||||
{savingFilter ? tCommon('loading') : t('groupFilter.save')}
|
||||
</button>
|
||||
</section>
|
||||
)}
|
||||
|
||||
{/* Section 3: Sync Settings (D-14) */}
|
||||
{config && (
|
||||
<section className="rounded-lg border border-border p-6">
|
||||
|
||||
Reference in New Issue
Block a user