mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-10 07:55:39 +02:00
Two related LDAP authentication changes. Fix: POSIX primary group membership was ignored. authenticate_ldap_user only searched for posixGroup entries via memberUid (supplementary groups). A user's primary group — referenced by the gidNumber attribute on the user object matching gidNumber on a posixGroup — was never resolved, so users whose role came from their primary group landed without the expected permissions. The authenticator now runs a second search for posixGroup entries whose gidNumber matches the user's primary gidNumber, then dedupes DNs case-insensitively before passing the list to resolve_group_mapping (LDAP DNs are case-insensitive by spec). New feature: ldap_default_group setting. Settings → Authentication → LDAP → Advanced has a new "Default group" selector. When an LDAP user authenticates but is not listed in any mapped LDAP group, they are assigned to this fallback group instead of being left with no groups (and therefore no permissions). A warning is logged each time the fallback is applied so admins can spot missing group assignments. Empty setting preserves the old behavior. Tests: added 4 mocked authenticate_ldap_user tests covering primary gidNumber lookup, dedupe of overlapping memberUid+primary gid matches, case-insensitive DN dedupe, and the guard when a user entry has no gidNumber attribute. Also extended the existing parse_ldap_config tests to cover the new default_group field. Backend: ldap_service.py (primary group + dedupe + default_group field), schemas/settings.py (schema field), api/routes/auth.py (fallback wiring in _provision_ldap_user / _sync_ldap_user). Frontend: LDAPSettings.tsx default-group dropdown in the Advanced collapsible, api/client.ts type field, new i18n keys in all 7 locales (defaultGroup, defaultGroupNone, defaultGroupHint).