feat(ldap): per-user exclude/denylist filter for sync
Tessera CI/CD / Lint & Type Check (push) Successful in 43s
Tessera CI/CD / Tests (push) Successful in 43s
Tessera CI/CD / Build & Publish Images (push) Successful in 1m46s

Add a per-username denylist so individual accounts (service accounts like
administrator, krbtgt, guest, ldap$) can be excluded from LDAP sync,
independent of the group/OU include-filter which only scopes the search.

- schema: LdapConfig.userExcludeList String[] (+ migration)
- sync: skip excluded usernames (case-insensitive) before recording the DN,
  so an already-imported user added to the list gets deactivated next sync
- DTO / config service / controller / scheduler: thread userExcludeList through
- web: exclude-list admin UI section (add/remove/save) + de/en translations
- tests: 3 specs covering empty list, case-insensitive skip, deactivation

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-14 09:34:01 +02:00
parent ef3e41769e
commit 9d1323fe97
11 changed files with 283 additions and 1 deletions
+4
View File
@@ -40,6 +40,7 @@ export class LdapConfigService {
syncIntervalMin: dto.syncIntervalMin ?? 60,
isActive: dto.isActive ?? true,
groupFilterDns: dto.groupFilterDns ?? [],
userExcludeList: dto.userExcludeList ?? [],
fieldMappings: {
create: [
{
@@ -83,6 +84,9 @@ export class LdapConfigService {
...(dto.groupFilterDns !== undefined && {
groupFilterDns: dto.groupFilterDns,
}),
...(dto.userExcludeList !== undefined && {
userExcludeList: dto.userExcludeList,
}),
},
include: { fieldMappings: true },
});