feat(02-04): LdapModule with sync service, config service, scheduler, and controller

- LdapService uses ldapts for DIRECTORY SYNC ONLY (anti-pattern avoidance)
- LdapConfigService creates default field mappings per D-16 (displayName, mail, sAMAccountName)
- Custom field mappings can be added/removed per D-17
- Per-tenant LDAP config per D-18
- syncUsersForTenant deactivates users removed from LDAP per D-15
- LdapSyncScheduler sets tenant context explicitly per Pitfall 2
- Manual sync endpoint POST /ldap/sync per D-14
- Auto-sync cron checks syncIntervalMin per D-14
- Test connection endpoint for LDAP config validation
- OpenLDAP + phpLDAPadmin added to docker-compose.dev.yml
- LDAP search filter sanitization per T-02-16
- bindPassword never returned in API responses per T-02-17
This commit is contained in:
2026-06-19 08:38:07 +02:00
parent ac617f4fe5
commit f928cd7713
10 changed files with 874 additions and 0 deletions
+21
View File
@@ -0,0 +1,21 @@
import { Module } from '@nestjs/common';
import { ScheduleModule } from '@nestjs/schedule';
import { UserModule } from '../user/user.module';
import { LdapConfigService } from './ldap-config.service';
import { LdapSyncScheduler } from './ldap-sync.scheduler';
import { LdapController } from './ldap.controller';
import { LdapService } from './ldap.service';
/**
* LDAP Module - Directory sync for user import (AUTH-06).
*
* Provides per-tenant LDAP configuration (D-18), manual sync (D-14),
* auto-sync scheduler (D-14), and configurable field mapping (D-16/D-17).
*/
@Module({
imports: [ScheduleModule.forRoot(), UserModule],
controllers: [LdapController],
providers: [LdapService, LdapConfigService, LdapSyncScheduler],
exports: [LdapService],
})
export class LdapModule {}