feat(ldap): opt-in skip TLS verification for ldaps (internal CA)
Add a per-tenant "Skip TLS certificate verification" toggle to the LDAP admin page so admins can connect to an AD whose ldaps:// certificate is signed by an internal/self-signed CA (Node error: "unable to verify the first certificate"). When enabled, ldapts is given tlsOptions.rejectUnauthorized=false; the flag is ignored for plain ldap:// (no TLS). Defaults to full verification. New Boolean column LdapConfig.tlsRejectUnauthorized (@default(true)) + migration; wired through DTOs, config service, all Client creations (test/groups/user-search/import/sync) and the test-connection endpoint. UI checkbox with an insecure-network warning (de/en). 3 new service specs; API 218 green, web 131 green, both apps tsc clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -133,6 +133,9 @@ export class LdapController {
|
||||
const serverUrl = dto.serverUrl || config?.serverUrl;
|
||||
const bindDn = dto.bindDn || config?.bindDn;
|
||||
const bindPassword = dto.bindPassword || config?.bindPassword;
|
||||
// Explicit form value wins; otherwise fall back to the saved config.
|
||||
const tlsRejectUnauthorized =
|
||||
dto.tlsRejectUnauthorized ?? config?.tlsRejectUnauthorized;
|
||||
|
||||
if (!serverUrl) {
|
||||
throw new BadRequestException(
|
||||
@@ -140,7 +143,12 @@ export class LdapController {
|
||||
);
|
||||
}
|
||||
|
||||
return this.ldapService.testConnection({ serverUrl, bindDn, bindPassword });
|
||||
return this.ldapService.testConnection({
|
||||
serverUrl,
|
||||
bindDn,
|
||||
bindPassword,
|
||||
tlsRejectUnauthorized,
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -165,6 +173,7 @@ export class LdapController {
|
||||
baseDn: config.baseDn,
|
||||
bindDn: config.bindDn,
|
||||
bindPassword: config.bindPassword,
|
||||
tlsRejectUnauthorized: config.tlsRejectUnauthorized,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -191,6 +200,7 @@ export class LdapController {
|
||||
baseDn: config.baseDn,
|
||||
bindDn: config.bindDn,
|
||||
bindPassword: config.bindPassword,
|
||||
tlsRejectUnauthorized: config.tlsRejectUnauthorized,
|
||||
},
|
||||
tenantId,
|
||||
q ?? '',
|
||||
@@ -223,6 +233,7 @@ export class LdapController {
|
||||
baseDn: config.baseDn,
|
||||
bindDn: config.bindDn,
|
||||
bindPassword: config.bindPassword,
|
||||
tlsRejectUnauthorized: config.tlsRejectUnauthorized,
|
||||
searchFilter: config.searchFilter,
|
||||
groupFilterDns: config.groupFilterDns,
|
||||
userExcludeList: config.userExcludeList,
|
||||
@@ -258,6 +269,7 @@ export class LdapController {
|
||||
baseDn: config.baseDn,
|
||||
bindDn: config.bindDn,
|
||||
bindPassword: config.bindPassword,
|
||||
tlsRejectUnauthorized: config.tlsRejectUnauthorized,
|
||||
searchFilter: config.searchFilter,
|
||||
groupFilterDns: config.groupFilterDns,
|
||||
userExcludeList: config.userExcludeList,
|
||||
|
||||
Reference in New Issue
Block a user