feat(ldap): AD connection prefill + group/OU import filter UI

New-config form now defaults to the CTL Active Directory connection
values (balios.ctl.local:3268, dc=ctl,dc=local, AD person filter,
down-level bind-DN hint) with the password left blank; editing an
existing config still shows its real saved values.

Adds a group/OU import filter section: discover AD groups/OUs via
GET /ldap/groups, toggle selection or add DNs manually, persist via
PATCH /ldap/config. Empty selection keeps today's "import everyone
under base DN" behavior.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-07 09:39:58 +02:00
parent 04fc33fc2a
commit 75b58491e9
3 changed files with 220 additions and 5 deletions
+16
View File
@@ -278,6 +278,22 @@
"noTenants": "No tenants found",
"deleteConfirm": "Are you sure you want to delete this tenant?",
"cannotDeleteActive": "Cannot delete tenants with active users"
},
"ldap": {
"bindDnHint": "AD format: domain\\username (e.g. ctl\\serviceaccount), not DN notation.",
"groupFilter": {
"title": "Import filter (groups/OUs)",
"description": "Restrict sync to selected AD groups or organizational units. With no selection, every user under the base DN is imported.",
"discover": "Discover groups/OUs",
"typeOu": "OU",
"typeGroup": "Group",
"noneFound": "No groups or OUs found.",
"manualDn": "Add DN manually",
"addDn": "Add",
"selected": "Selected",
"emptyMeansAll": "No selection - imports every user under the base DN.",
"save": "Save filter"
}
}
},
"adminModules": {