fix(16): WR-01 name lock in GroupsService.update() also checks ldapDn

A legacy binding from plan 15-06 has ldapDn set but ldapObjectGuid stays
null until the first syncBoundGroupsForTenant() run backfills it. Until
then, GroupsService.update() let a direct PATCH rename through even
though GroupFormModal.tsx already treats the same group as AD-bound
(isImported = ldapDn != null) — the D-03 name lock was only a UI
convention for that window, not the backend invariant the 16-02 summary
claimed.
This commit is contained in:
2026-08-06 16:56:30 +02:00
parent 7464d32625
commit dd59bf592f
2 changed files with 33 additions and 5 deletions
+11 -5
View File
@@ -107,10 +107,16 @@ export class GroupsService {
* setzen.
*
* Namenssperre (D-03/D-07): trägt die geladene Gruppe einen gesetzten
* ldapObjectGuid, ist sie aus dem Verzeichnis importiert — ein `name`
* im Request wird dann mit BadRequestException abgelehnt, BEVOR die
* Leerstring-Prüfung läuft. Das ist eine Backend-Invariante, kein UI-
* Feld-Disable: ein direkter API-Aufruf kommt an ihr nicht vorbei.
* ldapObjectGuid ODER ldapDn, ist sie aus dem Verzeichnis importiert —
* ein `name` im Request wird dann mit BadRequestException abgelehnt,
* BEVOR die Leerstring-Prüfung läuft. Das ldapDn-Kriterium deckt eine
* Alt-Bindung aus Plan 15-06 ab, die den neuen Rekonziliations-Schritt
* (syncBoundGroupsForTenant, Legacy-Backfill) noch nicht durchlaufen hat
* und deshalb noch keinen ldapObjectGuid trägt — ohne diese zweite
* Bedingung wäre die Sperre bis zum ersten Sync-Lauf nur eine
* UI-Konvention (WR-01, 16-REVIEW.md). Das ist eine Backend-Invariante,
* kein UI-Feld-Disable: ein direkter API-Aufruf kommt an ihr nicht
* vorbei.
*
* internalName (D-04) läuft unabhängig von dieser Sperre — jede Gruppe,
* importiert oder lokal, darf ihn setzen. undefined lässt die Spalte
@@ -132,7 +138,7 @@ export class GroupsService {
} = {};
if (data.name !== undefined) {
if (existing.ldapObjectGuid) {
if (existing.ldapObjectGuid || existing.ldapDn) {
throw new BadRequestException(
'Der Name einer aus dem Verzeichnis übernommenen Gruppe wird dort gepflegt und kann hier nicht geändert werden',
);