feat(ldap): per-user exclude/denylist filter for sync
Add a per-username denylist so individual accounts (service accounts like administrator, krbtgt, guest, ldap$) can be excluded from LDAP sync, independent of the group/OU include-filter which only scopes the search. - schema: LdapConfig.userExcludeList String[] (+ migration) - sync: skip excluded usernames (case-insensitive) before recording the DN, so an already-imported user added to the list gets deactivated next sync - DTO / config service / controller / scheduler: thread userExcludeList through - web: exclude-list admin UI section (add/remove/save) + de/en translations - tests: 3 specs covering empty list, case-insensitive skip, deactivation Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -325,6 +325,15 @@
|
||||
"selected": "Ausgewaehlt",
|
||||
"emptyMeansAll": "Keine Auswahl - importiert alle Benutzer unter der Basis-DN.",
|
||||
"save": "Filter speichern"
|
||||
},
|
||||
"userExclude": {
|
||||
"title": "Benutzer ausschliessen (Denylist)",
|
||||
"description": "Einzelne Benutzernamen, die nie importiert werden - z. B. Dienstkonten wie administrator, krbtgt, guest oder ldap$. Wirkt zusaetzlich zum Gruppen-/OU-Filter.",
|
||||
"username": "Benutzername",
|
||||
"add": "Hinzufuegen",
|
||||
"excluded": "Ausgeschlossen",
|
||||
"empty": "Keine ausgeschlossen - alle gefundenen Benutzer werden importiert.",
|
||||
"save": "Ausschlussliste speichern"
|
||||
}
|
||||
}
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user