Robustheits-Fix: RFC-5321-konforme E-Mail-Local-Parts (keine Rand-Punkte/Doppelpunkte) + sAMAccountName-Fallback bei Nicht-Latin-Namen + Release v11

This commit is contained in:
Kühn
2026-09-17 13:15:27 +02:00
parent 1c28917bb5
commit 4d5ab818e9
6 changed files with 29 additions and 5 deletions

View File

@@ -168,7 +168,8 @@ async function createADUser({ ou, vorname, nachname, email, username, password,
// Build UPN — FIX: Username umlautfrei normalisieren (ä→ae etc.),
// damit kein ungültiger UPN wie müller@... entsteht.
const upnSuffix = LDAP_UPN_SUFFIX || LDAP_BIND_USER.split('@')[1] || LDAP_DOMAIN.toLowerCase() + '.intra';
const userPrincipalName = toSamAccountName(username) + '@' + upnSuffix;
const normalizedUsername = toSamAccountName(username) || 'user' + Date.now().toString(36);
const userPrincipalName = normalizedUsername + '@' + upnSuffix;
// sAMAccountName: max 20 chars
let sAMAccountName = toSamAccountName(username);
@@ -176,6 +177,11 @@ async function createADUser({ ou, vorname, nachname, email, username, password,
sAMAccountName = toSamAccountName(nachname + vorname.charAt(0));
}
sAMAccountName = sAMAccountName.substring(0, 20);
// Fallback: Name nur aus Sonderzeichen → generischer Name (AD lehnt leeren sAMAccountName ab)
if (!sAMAccountName) {
sAMAccountName = ('user' + Date.now().toString(36)).substring(0, 20);
console.warn('[LDAP] sAMAccountName war nach Normalisierung leer — Fallback:', sAMAccountName);
}
// userAccountControl: 514 = NORMAL_ACCOUNT + ACCOUNTDISABLE
// ldapts requires attribute values as strings (numbers cause "The string argument must be of type string" error)