refactor(quick-260921-m34): Aufgabe 1 - Mandantenbindung entzaubert, 105 unnoetige any-Zusicherungen entfernt

- prisma-tenant.extension.ts: (prisma as any) und die Handannotation an
  $allOperations in forTenant()/forSystem() entfernt; Kopfkommentar
  unveraendert. .then((results: any[]) => ...) auf unknown[] umgestellt.
- 105 Aufrufstellen `const X = forTenant(...) as any` / `forSystem(...) as
  any` von der Zusicherung befreit, Zuweisungsform woertlich erhalten
  (rls-access-inventory.spec.ts bleibt scharf, 30/30 gruen einzeln
  geprueft).
- withTenantTransaction(): Prisma.TransactionClient fuer tx probiert,
  gemessen verworfen - bricht das Testdoppel in
  prisma-tenant.extension.spec.ts (TS2322 auf einem absichtlich
  unvollstaendigen Fake-Objekt). tx bleibt any, mit Begruendung am Typ.
- Gefolge des jetzt getypten Klienten entfernt: any[]-Annotationen und
  .map((x: any) => ...) in groups.service.ts, module-grants.service.ts,
  dkv.service.ts, ldap-config.service.ts, tenders.controller.ts:270.
- Befund (D-03): tender-matching.service.ts:159 trug eine Handannotation
  (match: { tender: unknown }), die den Wert nur deshalb auf unknown
  verengte, um TS7006 unter dem alten any-Klienten zu vermeiden - mit dem
  getypten Klienten war das falsch. Annotation geloescht, kein Ersatz
  durch Zusicherung.
- Zwei any bleiben gezielt in groups.service.ts (u/a in
  ensureDefaultGroup(), gefolge von tx: any) - Begruendung am Code.

noExplicitAny apps/api/src: 288 -> 149 (Schranke 155). type-check 4/4,
lint 5/5 (0 error). apps/api 72/1143 gruen, apps/web 73/531 gruen,
rls-access-inventory.spec.ts 30/30 gruen.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TPPB4ApQxzSU1rwV2Ffj9J
This commit is contained in:
2026-09-21 16:19:16 +02:00
parent 8d845e732e
commit b188946e31
24 changed files with 147 additions and 148 deletions
+9 -9
View File
@@ -68,7 +68,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
*/
async onApplicationBootstrap(): Promise<void> {
try {
const systemPrisma = forSystem(this.prisma) as any;
const systemPrisma = forSystem(this.prisma);
const configs: { id: string; tenantId: string; encryptedBindPassword: string | null }[] =
await systemPrisma.ldapConfig.findMany({
select: { id: true, tenantId: true, encryptedBindPassword: true },
@@ -84,7 +84,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
for (const config of legacy) {
// Schreiben je Altzeile GEBUNDEN an den Mandanten der Zeile — unter
// Systemkontext wuerde die Datenbank das Update abweisen (P2025).
const tenantPrisma = forTenant(this.prisma, config.tenantId) as any;
const tenantPrisma = forTenant(this.prisma, config.tenantId);
await tenantPrisma.ldapConfig.update({
where: { id: config.id },
data: {
@@ -146,7 +146,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
* bewusst ueber alle Mandanten liest.
*/
async getConfig(tenantId: string) {
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const config = await tenantPrisma.ldapConfig.findUnique({
where: { tenantId },
include: { fieldMappings: true },
@@ -166,7 +166,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
* gemessen.
*/
async createConfig(tenantId: string, dto: CreateLdapConfigDto) {
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const created = await tenantPrisma.ldapConfig.create({
data: {
tenantId,
@@ -209,7 +209,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
* Mandantengebunden (WINDOWS #20 Etappe 2, 260909-ipc).
*/
async updateConfig(tenantId: string, dto: UpdateLdapConfigDto) {
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const updated = await tenantPrisma.ldapConfig.update({
where: { tenantId },
data: {
@@ -257,7 +257,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
configId: string,
dto: CreateFieldMappingDto,
) {
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
return tenantPrisma.ldapFieldMapping.create({
data: {
ldapConfigId: configId,
@@ -283,7 +283,7 @@ export class LdapConfigService implements OnApplicationBootstrap {
* Loeschung.
*/
async removeFieldMapping(tenantId: string, mappingId: string) {
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const mapping = await tenantPrisma.ldapFieldMapping.findUnique({
where: { id: mappingId },
});
@@ -319,11 +319,11 @@ export class LdapConfigService implements OnApplicationBootstrap {
* den es dann nicht gibt.
*/
async getAllActiveConfigs() {
const systemPrisma = forSystem(this.prisma) as any;
const systemPrisma = forSystem(this.prisma);
const configs = await systemPrisma.ldapConfig.findMany({
where: { isActive: true },
include: { tenant: true, fieldMappings: true },
});
return configs.map((config: any) => this.withDecryptedPassword(config));
return configs.map((config) => this.withDecryptedPassword(config));
}
}
+8 -8
View File
@@ -298,7 +298,7 @@ export class LdapService {
// Mandantengescopter Lesepfad (WINDOWS #20 Etappe 2, 260909-ipc): die
// "bereits importiert"-Markierung darf nur die Gruppen DIESES Mandanten
// sehen.
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
try {
await this.bind(client, config.bindDn, config.bindPassword);
@@ -471,7 +471,7 @@ export class LdapService {
// Mandantengescopter Identitaets-/Schreibpfad (WINDOWS #20 Etappe 2,
// 260909-ipc). Nicht zu verwechseln mit resolveEmailForWrite() oben, die
// bewusst ungebunden bleibt.
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const existingByDn = await tenantPrisma.user.findFirst({
where: { ldapDn: dn, tenantId },
});
@@ -566,7 +566,7 @@ export class LdapService {
// Mandantengescopter Lesepfad (WINDOWS #20 Etappe 2, 260909-ipc): die
// "bereits importiert"-Markierung darf nur die Konten DIESES Mandanten
// sehen.
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const first = (v: unknown): string =>
Array.isArray(v) ? String(v[0] ?? '') : v != null ? String(v) : '';
@@ -663,7 +663,7 @@ export class LdapService {
);
// Mandantengescopter Dedup-/Schreibpfad (WINDOWS #20 Etappe 2,
// 260909-ipc).
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
try {
await this.bind(client, config.bindDn, config.bindPassword);
@@ -791,7 +791,7 @@ export class LdapService {
);
// Mandantengescopter Schreibpfad (T-16-02): app.current_tenant wird vor
// jedem group.create() gesetzt, RLS ist das zweite Netz.
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
try {
await this.bind(client, config.bindDn, config.bindPassword);
@@ -934,7 +934,7 @@ export class LdapService {
);
// Create tenant-scoped Prisma client per Pitfall 2
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
try {
// 1. Bind with service account (anonymous when not configured)
@@ -1208,7 +1208,7 @@ export class LdapService {
tenantId: string,
result: LdapSyncResult,
): Promise<void> {
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const boundGroups: { id: string; name: string; ldapDn: string | null }[] =
await tenantPrisma.group.findMany({
@@ -1371,7 +1371,7 @@ export class LdapService {
tenantId: string,
result: LdapSyncResult,
): Promise<void> {
const tenantPrisma = forTenant(this.prisma, tenantId) as any;
const tenantPrisma = forTenant(this.prisma, tenantId);
const candidates: {
id: string;