feat(ldap): AD connection prefill + group/OU import filter UI
New-config form now defaults to the CTL Active Directory connection values (balios.ctl.local:3268, dc=ctl,dc=local, AD person filter, down-level bind-DN hint) with the password left blank; editing an existing config still shows its real saved values. Adds a group/OU import filter section: discover AD groups/OUs via GET /ldap/groups, toggle selection or add DNs manually, persist via PATCH /ldap/config. Empty selection keeps today's "import everyone under base DN" behavior. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -23,10 +23,17 @@ interface LdapConfig {
|
|||||||
searchFilter: string;
|
searchFilter: string;
|
||||||
syncIntervalMin: number;
|
syncIntervalMin: number;
|
||||||
isActive: boolean;
|
isActive: boolean;
|
||||||
|
groupFilterDns: string[];
|
||||||
lastSyncAt: string | null;
|
lastSyncAt: string | null;
|
||||||
fieldMappings: FieldMapping[];
|
fieldMappings: FieldMapping[];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface LdapDirectoryEntry {
|
||||||
|
dn: string;
|
||||||
|
name: string;
|
||||||
|
type: 'group' | 'ou';
|
||||||
|
}
|
||||||
|
|
||||||
interface SyncResult {
|
interface SyncResult {
|
||||||
created: number;
|
created: number;
|
||||||
updated: number;
|
updated: number;
|
||||||
@@ -53,13 +60,18 @@ export default function AdminLdapPage() {
|
|||||||
const [syncResult, setSyncResult] = useState<SyncResult | null>(null);
|
const [syncResult, setSyncResult] = useState<SyncResult | null>(null);
|
||||||
const [syncing, setSyncing] = useState(false);
|
const [syncing, setSyncing] = useState(false);
|
||||||
|
|
||||||
// Form state for connection settings
|
// Form state for connection settings.
|
||||||
|
// Defaults are pre-filled with the known-good CTL Active Directory
|
||||||
|
// connection values (sourced from the working XWiki LDAP config) so a
|
||||||
|
// brand-new setup only needs the service-account password. fetchConfig()
|
||||||
|
// below overwrites these with the real saved values whenever a config
|
||||||
|
// already exists.
|
||||||
const [formData, setFormData] = useState({
|
const [formData, setFormData] = useState({
|
||||||
serverUrl: '',
|
serverUrl: 'ldap://balios.ctl.local:3268',
|
||||||
baseDn: '',
|
baseDn: 'dc=ctl,dc=local',
|
||||||
bindDn: '',
|
bindDn: '',
|
||||||
bindPassword: '',
|
bindPassword: '',
|
||||||
searchFilter: '(objectClass=person)',
|
searchFilter: '(&(objectClass=user)(objectCategory=person))',
|
||||||
syncIntervalMin: 60,
|
syncIntervalMin: 60,
|
||||||
isActive: true,
|
isActive: true,
|
||||||
});
|
});
|
||||||
@@ -68,6 +80,13 @@ export default function AdminLdapPage() {
|
|||||||
const [newMapping, setNewMapping] = useState({ ldapField: '', tesseraField: '' });
|
const [newMapping, setNewMapping] = useState({ ldapField: '', tesseraField: '' });
|
||||||
const [showMappingForm, setShowMappingForm] = useState(false);
|
const [showMappingForm, setShowMappingForm] = useState(false);
|
||||||
|
|
||||||
|
// Group/OU import filter (selective sync)
|
||||||
|
const [groupFilterDns, setGroupFilterDns] = useState<string[]>([]);
|
||||||
|
const [discovered, setDiscovered] = useState<LdapDirectoryEntry[] | null>(null);
|
||||||
|
const [discovering, setDiscovering] = useState(false);
|
||||||
|
const [manualDn, setManualDn] = useState('');
|
||||||
|
const [savingFilter, setSavingFilter] = useState(false);
|
||||||
|
|
||||||
const hasAccess =
|
const hasAccess =
|
||||||
currentUser?.role === 'ADMIN' || currentUser?.role === 'SUPER_ADMIN';
|
currentUser?.role === 'ADMIN' || currentUser?.role === 'SUPER_ADMIN';
|
||||||
|
|
||||||
@@ -89,6 +108,7 @@ export default function AdminLdapPage() {
|
|||||||
syncIntervalMin: data.syncIntervalMin ?? 60,
|
syncIntervalMin: data.syncIntervalMin ?? 60,
|
||||||
isActive: data.isActive ?? true,
|
isActive: data.isActive ?? true,
|
||||||
});
|
});
|
||||||
|
setGroupFilterDns(data.groupFilterDns ?? []);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} catch {
|
} catch {
|
||||||
@@ -208,6 +228,59 @@ export default function AdminLdapPage() {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const handleDiscoverGroups = async () => {
|
||||||
|
setDiscovering(true);
|
||||||
|
try {
|
||||||
|
const res = await fetch(`${API_URL}/ldap/groups`, {
|
||||||
|
credentials: 'include',
|
||||||
|
});
|
||||||
|
if (res.ok) {
|
||||||
|
const data = await res.json();
|
||||||
|
setDiscovered(data);
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// silently fail
|
||||||
|
} finally {
|
||||||
|
setDiscovering(false);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const toggleGroupFilterDn = (dn: string) => {
|
||||||
|
setGroupFilterDns((prev) =>
|
||||||
|
prev.includes(dn) ? prev.filter((d) => d !== dn) : [...prev, dn],
|
||||||
|
);
|
||||||
|
};
|
||||||
|
|
||||||
|
const handleAddManualDn = () => {
|
||||||
|
const dn = manualDn.trim();
|
||||||
|
if (!dn || groupFilterDns.includes(dn)) return;
|
||||||
|
setGroupFilterDns((prev) => [...prev, dn]);
|
||||||
|
setManualDn('');
|
||||||
|
};
|
||||||
|
|
||||||
|
const handleRemoveGroupFilterDn = (dn: string) => {
|
||||||
|
setGroupFilterDns((prev) => prev.filter((d) => d !== dn));
|
||||||
|
};
|
||||||
|
|
||||||
|
const handleSaveGroupFilter = async () => {
|
||||||
|
setSavingFilter(true);
|
||||||
|
try {
|
||||||
|
const res = await fetch(`${API_URL}/ldap/config`, {
|
||||||
|
method: 'PATCH',
|
||||||
|
headers: { 'Content-Type': 'application/json' },
|
||||||
|
credentials: 'include',
|
||||||
|
body: JSON.stringify({ groupFilterDns }),
|
||||||
|
});
|
||||||
|
if (res.ok) {
|
||||||
|
await fetchConfig();
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// silently fail
|
||||||
|
} finally {
|
||||||
|
setSavingFilter(false);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
if (!hasAccess) {
|
if (!hasAccess) {
|
||||||
return (
|
return (
|
||||||
<div className="flex items-center justify-center min-h-[60vh]">
|
<div className="flex items-center justify-center min-h-[60vh]">
|
||||||
@@ -269,10 +342,11 @@ export default function AdminLdapPage() {
|
|||||||
type="text"
|
type="text"
|
||||||
value={formData.bindDn}
|
value={formData.bindDn}
|
||||||
onChange={(e) => setFormData({ ...formData, bindDn: e.target.value })}
|
onChange={(e) => setFormData({ ...formData, bindDn: e.target.value })}
|
||||||
placeholder="cn=admin,dc=example,dc=com"
|
placeholder="ctl\serviceaccount"
|
||||||
className="flex h-10 w-full rounded-md border border-input bg-background px-3 py-2 text-sm"
|
className="flex h-10 w-full rounded-md border border-input bg-background px-3 py-2 text-sm"
|
||||||
required
|
required
|
||||||
/>
|
/>
|
||||||
|
<p className="text-xs text-muted-foreground">{t('bindDnHint')}</p>
|
||||||
</div>
|
</div>
|
||||||
<div className="space-y-2">
|
<div className="space-y-2">
|
||||||
<label className="text-sm font-medium text-foreground">
|
<label className="text-sm font-medium text-foreground">
|
||||||
@@ -455,6 +529,115 @@ export default function AdminLdapPage() {
|
|||||||
</section>
|
</section>
|
||||||
)}
|
)}
|
||||||
|
|
||||||
|
{/* Section 2.5: Group/OU import filter (selective sync) */}
|
||||||
|
{config && (
|
||||||
|
<section className="rounded-lg border border-border p-6">
|
||||||
|
<h2 className="text-lg font-semibold text-foreground mb-2">
|
||||||
|
{t('groupFilter.title')}
|
||||||
|
</h2>
|
||||||
|
<p className="text-sm text-muted-foreground mb-4">
|
||||||
|
{t('groupFilter.description')}
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<div className="flex items-center gap-3 mb-4">
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
onClick={handleDiscoverGroups}
|
||||||
|
disabled={discovering}
|
||||||
|
className="rounded-md border border-border px-4 py-2 text-sm font-medium text-foreground hover:bg-muted transition-colors disabled:opacity-50"
|
||||||
|
>
|
||||||
|
{discovering ? tCommon('loading') : t('groupFilter.discover')}
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{discovered && discovered.length > 0 && (
|
||||||
|
<div className="mb-4 max-h-64 overflow-y-auto rounded-md border border-border divide-y divide-border">
|
||||||
|
{discovered.map((entry) => (
|
||||||
|
<label
|
||||||
|
key={entry.dn}
|
||||||
|
className="flex items-center gap-3 px-4 py-2 text-sm hover:bg-muted/30 cursor-pointer"
|
||||||
|
>
|
||||||
|
<input
|
||||||
|
type="checkbox"
|
||||||
|
checked={groupFilterDns.includes(entry.dn)}
|
||||||
|
onChange={() => toggleGroupFilterDn(entry.dn)}
|
||||||
|
/>
|
||||||
|
<span className="rounded bg-muted px-1.5 py-0.5 text-xs font-medium text-muted-foreground">
|
||||||
|
{entry.type === 'ou' ? t('groupFilter.typeOu') : t('groupFilter.typeGroup')}
|
||||||
|
</span>
|
||||||
|
<span className="font-medium text-foreground">{entry.name}</span>
|
||||||
|
<span className="font-mono text-xs text-muted-foreground truncate">
|
||||||
|
{entry.dn}
|
||||||
|
</span>
|
||||||
|
</label>
|
||||||
|
))}
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
|
||||||
|
{discovered && discovered.length === 0 && (
|
||||||
|
<p className="mb-4 text-sm text-muted-foreground">{t('groupFilter.noneFound')}</p>
|
||||||
|
)}
|
||||||
|
|
||||||
|
<div className="flex items-end gap-3 mb-4">
|
||||||
|
<div className="flex-1 space-y-1">
|
||||||
|
<label className="text-xs font-medium text-muted-foreground">
|
||||||
|
{t('groupFilter.manualDn')}
|
||||||
|
</label>
|
||||||
|
<input
|
||||||
|
type="text"
|
||||||
|
value={manualDn}
|
||||||
|
onChange={(e) => setManualDn(e.target.value)}
|
||||||
|
placeholder="CN=Beispiel,OU=Gruppen,DC=ctl,DC=local"
|
||||||
|
className="flex h-9 w-full rounded-md border border-input bg-background px-3 py-1 text-sm font-mono"
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
onClick={handleAddManualDn}
|
||||||
|
className="h-9 rounded-md border border-border px-3 text-xs font-medium text-foreground hover:bg-muted transition-colors"
|
||||||
|
>
|
||||||
|
{t('groupFilter.addDn')}
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-xs font-medium text-muted-foreground mb-2">
|
||||||
|
{t('groupFilter.selected')}
|
||||||
|
</p>
|
||||||
|
{groupFilterDns.length === 0 ? (
|
||||||
|
<p className="text-sm text-muted-foreground">{t('groupFilter.emptyMeansAll')}</p>
|
||||||
|
) : (
|
||||||
|
<ul className="space-y-1">
|
||||||
|
{groupFilterDns.map((dn) => (
|
||||||
|
<li
|
||||||
|
key={dn}
|
||||||
|
className="flex items-center justify-between gap-3 rounded-md border border-border px-3 py-1.5 text-sm"
|
||||||
|
>
|
||||||
|
<span className="font-mono text-xs text-foreground truncate">{dn}</span>
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
onClick={() => handleRemoveGroupFilterDn(dn)}
|
||||||
|
className="shrink-0 rounded px-2 py-1 text-xs text-destructive hover:bg-destructive/10 transition-colors"
|
||||||
|
>
|
||||||
|
{t('fieldMapping.remove')}
|
||||||
|
</button>
|
||||||
|
</li>
|
||||||
|
))}
|
||||||
|
</ul>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
onClick={handleSaveGroupFilter}
|
||||||
|
disabled={savingFilter}
|
||||||
|
className="rounded-md bg-primary px-4 py-2 text-sm font-medium text-primary-foreground hover:opacity-90 transition-opacity disabled:opacity-50"
|
||||||
|
>
|
||||||
|
{savingFilter ? tCommon('loading') : t('groupFilter.save')}
|
||||||
|
</button>
|
||||||
|
</section>
|
||||||
|
)}
|
||||||
|
|
||||||
{/* Section 3: Sync Settings (D-14) */}
|
{/* Section 3: Sync Settings (D-14) */}
|
||||||
{config && (
|
{config && (
|
||||||
<section className="rounded-lg border border-border p-6">
|
<section className="rounded-lg border border-border p-6">
|
||||||
|
|||||||
@@ -278,6 +278,22 @@
|
|||||||
"noTenants": "Keine Mandanten gefunden",
|
"noTenants": "Keine Mandanten gefunden",
|
||||||
"deleteConfirm": "Moechten Sie diesen Mandanten wirklich loeschen?",
|
"deleteConfirm": "Moechten Sie diesen Mandanten wirklich loeschen?",
|
||||||
"cannotDeleteActive": "Mandanten mit aktiven Benutzern koennen nicht geloescht werden"
|
"cannotDeleteActive": "Mandanten mit aktiven Benutzern koennen nicht geloescht werden"
|
||||||
|
},
|
||||||
|
"ldap": {
|
||||||
|
"bindDnHint": "AD-Format: Domaene\\Benutzername (z.B. ctl\\serviceaccount), keine DN-Schreibweise.",
|
||||||
|
"groupFilter": {
|
||||||
|
"title": "Import-Filter (Gruppen/OUs)",
|
||||||
|
"description": "Beschraenkt den Sync auf ausgewaehlte AD-Gruppen oder Organisationseinheiten. Ohne Auswahl werden alle Benutzer unter der Basis-DN importiert.",
|
||||||
|
"discover": "Gruppen/OUs suchen",
|
||||||
|
"typeOu": "OU",
|
||||||
|
"typeGroup": "Gruppe",
|
||||||
|
"noneFound": "Keine Gruppen oder OUs gefunden.",
|
||||||
|
"manualDn": "DN manuell hinzufuegen",
|
||||||
|
"addDn": "Hinzufuegen",
|
||||||
|
"selected": "Ausgewaehlt",
|
||||||
|
"emptyMeansAll": "Keine Auswahl - importiert alle Benutzer unter der Basis-DN.",
|
||||||
|
"save": "Filter speichern"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"adminModules": {
|
"adminModules": {
|
||||||
|
|||||||
@@ -278,6 +278,22 @@
|
|||||||
"noTenants": "No tenants found",
|
"noTenants": "No tenants found",
|
||||||
"deleteConfirm": "Are you sure you want to delete this tenant?",
|
"deleteConfirm": "Are you sure you want to delete this tenant?",
|
||||||
"cannotDeleteActive": "Cannot delete tenants with active users"
|
"cannotDeleteActive": "Cannot delete tenants with active users"
|
||||||
|
},
|
||||||
|
"ldap": {
|
||||||
|
"bindDnHint": "AD format: domain\\username (e.g. ctl\\serviceaccount), not DN notation.",
|
||||||
|
"groupFilter": {
|
||||||
|
"title": "Import filter (groups/OUs)",
|
||||||
|
"description": "Restrict sync to selected AD groups or organizational units. With no selection, every user under the base DN is imported.",
|
||||||
|
"discover": "Discover groups/OUs",
|
||||||
|
"typeOu": "OU",
|
||||||
|
"typeGroup": "Group",
|
||||||
|
"noneFound": "No groups or OUs found.",
|
||||||
|
"manualDn": "Add DN manually",
|
||||||
|
"addDn": "Add",
|
||||||
|
"selected": "Selected",
|
||||||
|
"emptyMeansAll": "No selection - imports every user under the base DN.",
|
||||||
|
"save": "Save filter"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"adminModules": {
|
"adminModules": {
|
||||||
|
|||||||
Reference in New Issue
Block a user