253da91ba9
- GroupsService.update() rejects `name` with BadRequestException when the loaded group carries a set ldapObjectGuid (imported groups) — a real backend invariant, not a UI-only disable - internalName is settable/clearable on any group; empty/whitespace-only values normalize to null instead of an empty display name - listForTenant() now projects internalName alongside name - UpdateGroupDto drops ldapDn (D-07: no more codepath binds a local group to AD via this route) and gains internalName?: string | null - 9 new test cases in groups.service.spec.ts (name lock, internalName set/clear/idempotent/local-group/unicode, listForTenant projection); stale ldapDn update() test removed (behavior intentionally deleted)