docs: close the LDAP bind password backlog item
Notes what was deliberately left out: extracting and renaming the crypto service out of calendar/ touches five modules and belongs in its own change, so the existing provider is reused as-is and the naming smell is recorded in LdapModule instead. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
+8
@@ -1,5 +1,13 @@
|
||||
---
|
||||
created: 2026-08-11
|
||||
resolved: 2026-08-11
|
||||
resolution: |
|
||||
Behoben in Commit 4f687ea. Spalte heisst jetzt encryptedBindPassword,
|
||||
Verschluesselung ueber den bestehenden CalendarCryptoService, Entschluesselung
|
||||
zentral in getConfig()/getAllActiveConfigs(), Bootstrap-Backfill fuer
|
||||
Altbestand, 9 neue Tests. Punkt 1 der Loesung (Dienst aus calendar/
|
||||
herausheben und umbenennen) bewusst NICHT mitgemacht — beruehrt fuenf Module
|
||||
und gehoert in eine eigene Aenderung; im LdapModule als Notiz vermerkt.
|
||||
title: LDAP-Bind-Passwort liegt im Klartext in der DB, obwohl der Verschluesselungsdienst schon existiert
|
||||
area: ldap
|
||||
severity: major
|
||||
Reference in New Issue
Block a user