a5c500dbb3
CreateLdapConfigDto's optional fields (searchFilter, syncIntervalMin, isActive, groupFilterDns) had class-field default initializers. NestJS's ValidationPipe instantiates DTOs via plainToInstance, which applies those defaults even when the field is absent from the request body -- so any partial PATCH not including a given field silently reset it to the hardcoded default instead of leaving it untouched. Caught by testing the new groupFilterDns-only PATCH: saving the group filter alone reset searchFilter back to "(objectClass=person)", clobbering the configured Active Directory filter. The service layer already has its own `?? default` fallback for create, so the DTO initializers were redundant and unsafe. Removing them makes updateConfig's existing "only set if dto.field !== undefined" pattern behave correctly for every optional field, not just the ones sent together in one request. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>