a1cf05404ca2664582137e65a6616077bec3ac7e
LDAP-imported users have no local passwordHash, and validateUser only checked the local password, so they could never log in. Now a passwordless user with an ldapDn is authenticated by binding as their OWN DN with the entered password against the tenant's active LDAP config (reusing the ldaps TLS-skip option). Empty passwords are rejected before binding to avoid AD's unauthenticated-bind bypass. Local-password users are unchanged. LdapService.verifyUserCredentials added; LdapModule now exports LdapConfigService; AuthModule imports LdapModule (no circular dep). 8 new specs (bind success/fail, empty-password guard, login via bind, wrong pw, no config, no ldapDn, inactive). API 226 green, tsc clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Description
Tessera - Modulare Workflow-Automatisierung und Tool-Integration
Releases
15
Tessera 1.9.2
Latest
Languages
TypeScript
90.7%
JavaScript
5.4%
Rust
1.4%
HTML
1%
Shell
0.6%
Other
0.8%