Commit Graph

717 Commits

Author SHA1 Message Date
schalli 00de6a6f9c fix(16): WR-03 do not delete a bound group merely unobserved under a narrower base DN
syncBoundGroupsForTenant()'s existence sweep only searched the configured
base DNs, so an AD group MOVED to an OU outside that subtree (still
present in the directory) was indistinguishable from a genuine
disappearance and got deleted along with its memberships/module grants —
a silent access loss from a non-destructive AD operation, and a bigger
blast radius than D-05 ("group genuinely gone") was accepted for.

Before concluding disappearance, a second (objectGUID=...) sweep now runs
against each base DN's own domain root (skipped when a base DN already IS
its domain root — the common case, nothing wider to search). A hit there
is reported as an error line and the group is left untouched; only when
the wide sweep also finds nothing is deletion (SC-4/D-05/D-06) actually
established — mirroring the existing conservative stance already taken
for a legacy binding whose DN no longer resolves. Deleting on uncertainty
was the failure mode; this closes it without widening it.
2026-08-06 17:00:54 +02:00
schalli 2779d42e6c fix(16): WR-04 normalize the rename-vs-unchanged comparison
syncBoundGroupsForTenant() compared cn/dn for byte equality, so any
casing difference AD returns between two runs (e.g. after a
domain-controller switch) would look like a rename and re-write
name/ldapDn every single sync — violating the 'sync twice over an
unchanged AD state = no-op' idempotency guarantee. The comparison used
to DECIDE 'is this a rename' is now case-insensitive; the value written
on an actual rename is still stored byte-for-byte as the directory
reports it, per D-03.
2026-08-06 16:58:29 +02:00
schalli 19717954d6 fix(16): WR-02 discriminate P2002 target in group rename branch
syncBoundGroupsForTenant()'s rename write updates name and ldapDn in one
call, so a P2002 there can come from either @@unique([tenantId, name])
or @@unique([tenantId, ldapDn]). The catch previously reported every
P2002 as a name collision unconditionally; it now inspects
err.meta.target the same way importGroupsByDn() already does for its
own create() call, so a non-name unique violation is no longer
mislabelled and sent the admin down the wrong troubleshooting path.
2026-08-06 16:57:34 +02:00
schalli dd59bf592f fix(16): WR-01 name lock in GroupsService.update() also checks ldapDn
A legacy binding from plan 15-06 has ldapDn set but ldapObjectGuid stays
null until the first syncBoundGroupsForTenant() run backfills it. Until
then, GroupsService.update() let a direct PATCH rename through even
though GroupFormModal.tsx already treats the same group as AD-bound
(isImported = ldapDn != null) — the D-03 name lock was only a UI
convention for that window, not the backend invariant the 16-02 summary
claimed.
2026-08-06 16:56:30 +02:00
schalli 7464d32625 docs(16-05): complete Sync-Bericht-und-Freigabe-Matrix plan (Phase 16 done, PERM-02) 2026-08-06 16:41:29 +02:00
schalli a0c5e470c3 docs(16-05): add plan summary, close PERM-02, log open verification items
- 16-05-SUMMARY.md documents the two-task plan (sync-report wiring,
  grants-matrix internal-name fallback).
- PERM-02 marked complete in REQUIREMENTS.md: all five Phase-16 success
  criteria are code-complete across plans 16-01..16-03; this plan
  delivered the last missing visibility layer (D-05/D-06) and the
  third D-04 display site.
- WINDOWS.md #6: this plan's own manual browser walkthrough (sync
  report three-line render, amber default-marker line, grants-matrix
  two-name search) not executed — no browser tool in this session.
2026-08-06 16:40:43 +02:00
schalli fac152af74 feat(16-05): show internal-name fallback in grants matrix column headers (D-04)
- Local Group interface gains internalName?: string | null — GET
  /module-grants/matrix already returns the field (no select on the
  groups query), only the frontend type was missing it.
- Column header text and title tooltip now use internalName ?? name
  (nullish, not truthy) — same fallback pattern as admin/groups and
  UserAccessModal. No layout change: same truncate-with-tooltip cell.
- Search filter now matches both the display name and the stored AD
  name, so neither the internal nor the original AD name search goes
  empty after the header text changed.
2026-08-06 16:38:04 +02:00
schalli f66546df7e feat(16-05): wire full sync report + visible sync-request error (D-06, D-21)
- SyncResult interface grows additively: groupMembershipsAdded/Removed
  (D-21 backend gap, existed since Phase 15 but never wired into the
  frontend) plus groupsAdopted/Renamed/Deleted and defaultMarkerMoved
  (Plan 16-03).
- New syncRequestError state: a failed sync request (network error or
  !res.ok) now renders a visible text-sm text-destructive line instead
  of silently reporting a three-zero result as a successful no-op.
- Sync report container gains three new lines: group-membership counts,
  AD-group counts (always visible, even at zero), and a conditional
  amber "default marker reassigned" line shown only when
  defaultMarkerMoved > 0.
- Four new i18n keys under admin.ldap.sync in de.json/en.json.
2026-08-06 16:37:07 +02:00
schalli 184a3a1174 docs(16-04): complete Gruppen-Dialog-Umbau plan 2026-08-06 16:33:59 +02:00
schalli 63f6ba852e docs(16-04): append self-check result to summary 2026-08-06 16:33:19 +02:00
schalli 6b33bb0b2f docs(16-04): add plan summary
Documents the GroupFormModal three-state rebuild (D-03/D-04/D-07), the
groups-list internalName fallback, and the ldapBind i18n cleanup for
Phase 16 Plan 4.
2026-08-06 16:33:01 +02:00
schalli e900b43d57 test(16-04): remove orphaned ldapBind i18n keys, add D-07 regression tests
Delete the admin.groups.ldapBind.* subtree (hint/bound/unbind/
searchPlaceholder/discoverError/noResults) from de.json and en.json —
fully orphaned since GroupFormModal.tsx no longer has an AD-binding
codepath. admin.groups.ldapBinding (column header) and every other
admin.groups.* key are untouched; key sets stay in parity across both
languages.

Test file's translation stub loses the same dead ldapBind block and
gains the seven Task 1 keys. Two new cases lock down D-07: opening the
create dialog issues no /ldap/groups request, and editing an imported
group renders a disabled name input plus the internal-name field
instead of any AD-search UI.
2026-08-06 16:30:49 +02:00
schalli 6802b48cd8 feat(16-04): show internalName with AD-name fallback in groups list
Name column renders group.internalName ?? group.name (nullish, not
truthiness, since the backend already normalizes blank values to null)
inside a span carrying title={group.name} so the AD name stays
discoverable on hover once an internal name is set. Badge column is
untouched — it remains the sole imported-vs-local marker per D-07.

Adds two component-test cases covering the fallback and its title
attribute (D-04).
2026-08-06 16:29:15 +02:00
schalli 30affbbc7e feat(16-04): rebuild GroupFormModal to three states without AD binding
- Remove AD radio-selection block, discovery effect/state, and the
  two-step create-then-PATCH-bind flow from GroupFormModal.tsx (D-07):
  a local group can no longer be bound to an AD group from this dialog.
- Add locked name field with provenance hint + AD-DN read-only line and
  an editable internalName field for imported groups (D-03/D-04); create
  state gets a hint linking to the LDAP import area.
- Visible save-error line (never a silent catch{}) that distinguishes a
  409 name collision from a generic failure; dialog stays open, inputs
  are preserved.
- Add Group.internalName to the page.tsx interface now (Rule 3 — the
  modal cannot typecheck without it; Task 2 adds the display-cell usage).
- Add seven new admin.groups i18n keys to de.json/en.json (orphaned
  ldapBind.* keys removed in Task 3).
2026-08-06 16:28:07 +02:00
schalli 5a687a9d01 docs(16-03): complete Gruppen-Rekonziliation plan 2026-08-06 16:24:25 +02:00
schalli 68aca81f71 feat(16-03): wire group reconciliation before membership sync (5a)
- syncUsersForTenant() now calls syncBoundGroupsForTenant() (5a) BEFORE
  syncGroupMembershipsForTenant() (5b) — the central correctness ordering
  of Phase 16 (RESEARCH.md Pitfall 1): a rename detected in the same run
  must be written back before the memberOf filter is built, or the
  membership sync would misreport a rename as a membership wipeout
- Add observable ordering test (call-order spies), a no-op-guard test, and
  a regression test proving a memberOf search never uses the stale
  pre-rename DN
- Update the D-21 membership-sync test fixtures to resolve step 5a as a
  deterministic no-op (DN-derived identity GUID), since the wiring now
  runs 5a ahead of every syncUsersForTenant() call those tests exercise

A1 (objectGUID survives an AD rename) and A2 (binary filter escape syntax)
remain unverified against a real directory — no reachable AD in this
sandbox. Documented as an outstanding live verification in the plan
SUMMARY, not silently skipped.
2026-08-06 16:21:10 +02:00
schalli 522293417a feat(16-03): add syncBoundGroupsForTenant reconciliation method
- New private LdapService.syncBoundGroupsForTenant(): rename detection
  (SC-3), disappearance deletion with default-marker handoff before delete
  (SC-4/D-05/D-06), legacy ldapDn-only binding GUID backfill (D-07), and a
  32-hex-char guard before any objectGUID filter interpolation (T-16-01)
- LdapSyncResult grows additively: groupsAdopted, groupsRenamed,
  groupsDeleted, defaultMarkerMoved
- LdapService constructor takes GroupsService; LdapModule imports
  GroupsModule (no cycle)
- 14 new test cases covering the full behavior matrix plus idempotency
2026-08-06 16:15:09 +02:00
schalli da0361df5f docs(16-02): complete backend name-lock/internalName/default-handoff plan 2026-08-06 16:03:54 +02:00
schalli f71e614f7f feat(16-02): display name with fallback in user-detail projections (D-04, UI-SPEC Surface Contract 6)
- ModuleGrantsService.getUserAccess() now selects internalName on the
  membership query's group projection (already present via `include:
  { group: true }` on the grant query)
- Both display points (viaGroups names, membership chips' name field)
  use internalName ?? name; groups[] sorting now runs over the
  displayed name as a result, distinct from GroupsService.listForTenant()
  which still sorts by the raw name column
- 3 new test cases: fallback set/unset, sort-by-displayed-name
- No apps/web/ changes (verified via git diff --name-only)
2026-08-06 16:00:18 +02:00
schalli 253da91ba9 feat(16-02): server-side name lock for imported groups + internalName (D-03/D-04/D-07)
- GroupsService.update() rejects `name` with BadRequestException when the
  loaded group carries a set ldapObjectGuid (imported groups) — a real
  backend invariant, not a UI-only disable
- internalName is settable/clearable on any group; empty/whitespace-only
  values normalize to null instead of an empty display name
- listForTenant() now projects internalName alongside name
- UpdateGroupDto drops ldapDn (D-07: no more codepath binds a local group
  to AD via this route) and gains internalName?: string | null
- 9 new test cases in groups.service.spec.ts (name lock, internalName
  set/clear/idempotent/local-group/unicode, listForTenant projection);
  stale ldapDn update() test removed (behavior intentionally deleted)
2026-08-06 15:58:28 +02:00
schalli 2ef9b8638c feat(16-02): standard group handoff building block (D-06)
- DEFAULT_GROUP_NAME extracted as shared constant between
  ensureDefaultGroup() and the new reassignDefaultBeforeDelete()
- reassignDefaultBeforeDelete(tenantId, groupId) moves the default
  marker deterministically (DEFAULT_GROUP_NAME first, else oldest
  other group by createdAt asc), never deletes, never throws
- 6 test cases covering handoff, fallback ordering, no-other-group,
  non-default no-op, cross-tenant no-op, and P2002 race
2026-08-06 15:55:53 +02:00
schalli 1b19876c32 docs(16-01): complete AD group import tracer plan 2026-08-06 15:49:26 +02:00
schalli b4844557af docs(16-01): add plan summary 2026-08-06 15:45:41 +02:00
schalli 626e29659d feat(16-01): apply Group.internalName/ldapObjectGuid migration to local DB
- Migration 20260806133916_add_group_internal_name_and_object_guid applied
  against the local Postgres container (baselined 24 prior migrations first
  — _prisma_migrations was missing, unrelated to this task's DDL)
- New describe block in migration-sql.spec.ts pins internalName,
  ldapObjectGuid, and the (tenantId, ldapObjectGuid) unique index
- Full API test suite green (40 files, 526 tests)
2026-08-06 15:43:19 +02:00
schalli 3523e43a13 feat(16-01): tracer — select and import AD groups end-to-end
Task 1 checkpoint resolved: approve-both, granted 2026-08-06 by the
project owner (D-04 one-way schema extension: Group.internalName +
Group.ldapObjectGuid, both nullable, one versioned migration).

Adds the Phase 16 tracer slice through every layer:
- Prisma schema: Group.internalName, Group.ldapObjectGuid,
  @@unique([tenantId, ldapObjectGuid]) (Prisma client regenerated;
  the versioned migration itself is Task 3, separately blocking).
- LdapService: listGroups() now reads objectGUID via
  explicitBufferAttributes and flags alreadyImported per tenant;
  new importGroupsByDn() creates a Group per checked DN with
  name/ldapDn/ldapObjectGuid, reject-with-report on name collision
  (P2002 on name -> nameCollisions, P2002 on ldapObjectGuid ->
  skipped), never aborts the batch on one DN's error; new static
  escapeLdapFilterBuffer() for Plan 16-03's later existence sweep.
- DTO/controller: ImportGroupsDto, POST /ldap/groups/import
  (ADMIN/SUPER_ADMIN), listGroups route now tenant-scoped.
- Frontend: new "AD-Gruppen importieren" section in /admin/ldap,
  own discovery/import handlers with a visible error state
  (Owner decision 2026-08-06 — no silent catch{} for these two
  handlers), i18n keys in de.json/en.json.
- Tests: 8 new cases covering the full <behavior> list plus
  listGroups sort order and alreadyImported.

Flagged assumption (RESEARCH.md A1/A2): objectGUID rename-stability
and the binary filter syntax are unverified against a real AD —
this plan only WRITES the GUID, Plan 16-03 reads it back live.
2026-08-06 15:09:35 +02:00
schalli c4a25511f3 docs(16): create phase plan 2026-08-06 14:42:44 +02:00
schalli 3dfa671ec9 docs(16): create phase plan — 5 plans, 4 waves, tracer-first 2026-08-06 14:38:45 +02:00
schalli 5c7d4ad128 docs(16): reassign PERM-02 to phase 16 with import semantics 2026-08-06 14:10:53 +02:00
schalli 1c658a8ed7 docs(16): UI design contract 2026-08-06 13:52:33 +02:00
schalli 092f4f6068 docs(16): UI design contract 2026-08-06 10:34:48 +02:00
schalli c5ce07afab docs(16): add validation strategy 2026-08-05 16:49:26 +02:00
schalli 9a494b1afd docs(16): research AD-Gruppen-Synchronisation phase 2026-08-05 16:48:12 +02:00
schalli fca4e3c3b5 docs(state): record phase 16 context session 2026-08-05 16:26:34 +02:00
schalli 8728716824 docs(16): capture phase context 2026-08-05 16:26:34 +02:00
schalli d502941767 docs: mark DOE URL todo as post-phase-16
Tessera CI/CD / Lint & Type Check (push) Successful in 48s
Tessera CI/CD / Tests (push) Successful in 47s
Tessera CI/CD / Build & Publish Images (push) Successful in 7s
2026-08-05 16:13:15 +02:00
schalli 324d578fe4 docs: diagnose DOE tender URL defect (API uri instead of notice page) 2026-08-05 16:11:44 +02:00
schalli 13ae48f0c1 docs: capture todo - Ausschreibungsportal falsche URL 2026-08-05 16:07:30 +02:00
schalli ff70b4efba docs(quick-260805-fok): Standardgruppe bei Mandanten-Anlage + Startup-Reparatur
Tessera CI/CD / Lint & Type Check (push) Successful in 48s
Tessera CI/CD / Tests (push) Successful in 49s
Tessera CI/CD / Build & Publish Images (push) Successful in 28s
2026-08-05 11:37:43 +02:00
schalli 0d7d8a597e feat(260805-fok): beide Mandanten-Entstehungspfade verdrahten + Startup-Reparatur
- TenantService.create ruft nach prisma.tenant.create ensureDefaultGroup
  auf; Fehler werden protokolliert, nicht propagiert (Muster aus
  UserService.create)
- tenant.module.ts importiert GroupsModule (keine Zirkularitaet, wie
  UserModule bereits vormacht)
- AdminSeedService.onApplicationBootstrap besteht jetzt aus zwei
  sequenziellen await-Schritten: seedAdmin() (bisheriger Rumpf, plus
  ensureDefaultGroup nach dem Tenant-Upsert und VOR user.create), dann
  ensureDefaultGroupsForAllTenants() als abschliessende Reparatur ueber
  ALLE Mandanten — laeuft unabhaengig von seedAdmin()s fruehen
  Rueckkehrpfaden (fehlende ENV / Admin existiert bereits) und ist je
  Mandant sowie insgesamt try/catch-gekapselt, blockiert den API-Start nie
- Reparatur sitzt bewusst NICHT als eigener onApplicationBootstrap-Hook
  in GroupsModule (Ordering-Falle aus tender-scheduler.service.ts)
- tenant.service.spec.ts, admin-seed.service.spec.ts (neu): Reihenfolge,
  beide fruehen Rueckkehrpfade, Fehlerisolation je Mandant, Idempotenz
  ueber zwei Bootstrap-Laeufe
2026-08-05 11:30:49 +02:00
schalli 9d1254cd78 feat(260805-fok): GroupsService.ensureDefaultGroup(tenantId)
- Neue Methode ensureDefaultGroup: legt fuer einen Mandanten ohne jede
  Gruppe die Standardgruppe 'Alle Benutzer' (isDefault:true) an, nimmt
  alle Bestandsbenutzer als MANUAL-Mitglieder auf und erzeugt Grants
  fuer alle aktiven Module — derselbe Endzustand wie die drei
  Backfill-INSERTs der Migration 20260804130130
- Waechter prueft ausschliesslich group.count === 0, niemals die
  fehlende isDefault-Markierung (D-13)
- P2002 aus dem partiellen Index Group_one_default_per_tenant wird
  abgefangen und liefert null statt zu werfen (Race-Sicherheit)
- groups.service.spec.ts: Fake erweitert um group.count,
  tenantModuleActivation, moduleGrant.findMany/createMany,
  $transaction mit Callback-Form, plus voller ensureDefaultGroup-Testblock
2026-08-05 11:28:16 +02:00
schalli c2e9f67a7d docs(quick-260805-d0r): Gruppenmitgliedschaften im Benutzer-Detail
Tessera CI/CD / Lint & Type Check (push) Successful in 50s
Tessera CI/CD / Tests (push) Successful in 52s
Tessera CI/CD / Build & Publish Images (push) Successful in 4m5s
2026-08-05 09:44:11 +02:00
schalli 8ce374818c feat(260805-d0r): membership-origin badge on chips (D-19/D-20)
- Reuses admin.groups.members.sourceManual/.sourceLdap -- no new i18n key
- Badge markup copied verbatim from GroupMembersModal.tsx (blue for LDAP,
  neutral gray otherwise), same visual language on both surfaces
2026-08-05 09:37:26 +02:00
schalli 73122b5676 test(260805-d0r): add failing test for MANUAL/LDAP origin badge on chips 2026-08-05 09:36:45 +02:00
schalli f8ff74bd3f feat(260805-d0r): UserAccessModal chips render from data.groups (D-16)
- Chips come from the response's groups (actual GroupMembership rows),
  not the union of row.viaGroups -- closes the reproduced defect where
  revoking a group's last grant hid an otherwise-unchanged membership
- React key is the group id, not the name
- Test file: moved the LDAP/MANUAL badge assertion out of this commit,
  it belongs to Task 2 which reuses admin.groups.members
2026-08-05 09:35:54 +02:00
schalli 771f680034 test(260805-d0r): rewrite modal test fixtures to { groups, modules } shape
- Regression: group without any module grant stays visible as a chip
- New: mixed empty-modules + populated-groups case, LDAP/MANUAL badge case
2026-08-05 09:34:42 +02:00
schalli ecadf69e14 feat(260805-d0r): getUserAccess returns groups from GroupMembership (D-16)
- New groupMembership.findMany query, tenant-scoped via group.tenantId
  (GroupMembership has no own tenantId column)
- Response shape changes from an array to { groups, modules }; modules
  entries stay field-identical to before
- Group without any module grant now stays visible, closing the
  reproduced defect
2026-08-05 09:33:51 +02:00
schalli b6d4e4acb6 test(260805-d0r): add failing tests for groups in getUserAccess
- Regression: user in a group without any module grant stays visible
- Cross-tenant: membership in a foreign tenant's group is excluded
- Origin (MANUAL/LDAP), empty-modules case, stable alpha sort
2026-08-05 09:33:22 +02:00
schalli be1183a61c docs(roadmap): add Phase 16 AD group synchronisation 2026-08-05 08:54:55 +02:00
schalli 8e70f55c8c docs(15): add pattern map from planning
Tessera CI/CD / Lint & Type Check (push) Successful in 42s
Tessera CI/CD / Tests (push) Successful in 50s
Tessera CI/CD / Build & Publish Images (push) Successful in 2m46s
2026-08-04 19:54:13 +02:00
schalli d15475d6d7 docs(15-08): complete Serverseitige Modulsperre und Marketplace-Sperr-Badge plan 2026-08-04 19:53:13 +02:00