docs: close the LDAP bind password backlog item
Tessera CI/CD / Lint & Type Check (push) Successful in 52s
Tessera CI/CD / Tests (push) Successful in 51s
Tessera CI/CD / Build & Publish Images (push) Successful in 25s

Notes what was deliberately left out: extracting and renaming the crypto
service out of calendar/ touches five modules and belongs in its own change,
so the existing provider is reused as-is and the naming smell is recorded in
LdapModule instead.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-11 14:11:11 +02:00
parent 4f687eaea9
commit e1f799513e
2 changed files with 10 additions and 1 deletions
@@ -1,5 +1,13 @@
---
created: 2026-08-11
resolved: 2026-08-11
resolution: |
Behoben in Commit 4f687ea. Spalte heisst jetzt encryptedBindPassword,
Verschluesselung ueber den bestehenden CalendarCryptoService, Entschluesselung
zentral in getConfig()/getAllActiveConfigs(), Bootstrap-Backfill fuer
Altbestand, 9 neue Tests. Punkt 1 der Loesung (Dienst aus calendar/
herausheben und umbenennen) bewusst NICHT mitgemacht — beruehrt fuenf Module
und gehoert in eine eigene Aenderung; im LdapModule als Notiz vermerkt.
title: LDAP-Bind-Passwort liegt im Klartext in der DB, obwohl der Verschluesselungsdienst schon existiert
area: ldap
severity: major