feat(ldap): opt-in skip TLS verification for ldaps (internal CA)
Add a per-tenant "Skip TLS certificate verification" toggle to the LDAP admin page so admins can connect to an AD whose ldaps:// certificate is signed by an internal/self-signed CA (Node error: "unable to verify the first certificate"). When enabled, ldapts is given tlsOptions.rejectUnauthorized=false; the flag is ignored for plain ldap:// (no TLS). Defaults to full verification. New Boolean column LdapConfig.tlsRejectUnauthorized (@default(true)) + migration; wired through DTOs, config service, all Client creations (test/groups/user-search/import/sync) and the test-connection endpoint. UI checkbox with an insecure-network warning (de/en). 3 new service specs; API 218 green, web 131 green, both apps tsc clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -39,6 +39,7 @@ export class LdapConfigService {
|
||||
searchFilter: dto.searchFilter ?? '(objectClass=person)',
|
||||
syncIntervalMin: dto.syncIntervalMin ?? 60,
|
||||
isActive: dto.isActive ?? true,
|
||||
tlsRejectUnauthorized: dto.tlsRejectUnauthorized ?? true,
|
||||
groupFilterDns: dto.groupFilterDns ?? [],
|
||||
userExcludeList: dto.userExcludeList ?? [],
|
||||
fieldMappings: {
|
||||
@@ -81,6 +82,9 @@ export class LdapConfigService {
|
||||
syncIntervalMin: dto.syncIntervalMin,
|
||||
}),
|
||||
...(dto.isActive !== undefined && { isActive: dto.isActive }),
|
||||
...(dto.tlsRejectUnauthorized !== undefined && {
|
||||
tlsRejectUnauthorized: dto.tlsRejectUnauthorized,
|
||||
}),
|
||||
...(dto.groupFilterDns !== undefined && {
|
||||
groupFilterDns: dto.groupFilterDns,
|
||||
}),
|
||||
|
||||
Reference in New Issue
Block a user