Files
tessera-ctl/.planning/phases/02-authentication-multi-tenancy/02-04-SUMMARY.md
T

1.3 KiB

Plan 02-04: LDAP Integration — Summary

Status: Complete Date: 2026-06-19

What Was Built

Task 1: Backend LDAP Module

  • LdapService using ldapts library for directory sync (NOT as auth — anti-pattern avoidance)
  • LdapConfigService for per-tenant LDAP configuration (D-18)
  • LdapSyncScheduler with configurable auto-sync interval (D-14)
  • Field mapping: configurable with defaults (displayName→Name, mail→Email, sAMAccountName→Username) (D-16)
  • Custom field mapping support (D-17)
  • Deactivation of removed LDAP users (D-15)
  • Manual sync endpoint POST /ldap/sync
  • Prisma schema extended with LdapConfig and LdapFieldMapping models

Task 2: Frontend LDAP Admin UI

  • LDAP settings page at /admin/ldap
  • Connection configuration form (server URL, base DN, bind user, filter)
  • Field mapping editor with default + custom fields
  • Test connection button
  • Manual sync trigger button
  • Sidebar navigation updated with LDAP admin link
  • i18n keys for DE/EN

Commits

  • f928cd7: LdapModule with sync service, config service, scheduler, controller
  • 6e19591: LDAP admin UI with config, mapping editor, sync trigger

Requirements Addressed

  • AUTH-06: Users can be imported from LDAP/AD ✓
  • TNNT-01: LDAP data tenant-isolated via RLS ✓
  • TNNT-02: LDAP config per tenant ✓
  • TNNT-03: Per-request tenant context in LDAP operations ✓