From a05133f39dba0fd16c1f557bbd5e7d78b461bb1f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=BChn?= Date: Fri, 28 Aug 2026 11:28:56 +0200 Subject: [PATCH] Fix AD user creation: userAccountControl must be string for ldapts --- backend/ldapOperations.js | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/backend/ldapOperations.js b/backend/ldapOperations.js index a7faac3..943fff2 100644 --- a/backend/ldapOperations.js +++ b/backend/ldapOperations.js @@ -178,7 +178,8 @@ async function createADUser({ ou, vorname, nachname, email, username, password, sAMAccountName = sAMAccountName.substring(0, 20); // userAccountControl: 514 = NORMAL_ACCOUNT + ACCOUNTDISABLE - const userAccountControl = 514; + // ldapts requires attribute values as strings (numbers cause "The string argument must be of type string" error) + const userAccountControl = '514'; const effectiveDisplayName = displayName || (nachname + ', ' + vorname); const entry = { @@ -254,13 +255,14 @@ async function createADUser({ ou, vorname, nachname, email, username, password, console.log('[LDAP] Passwort gesetzt für:', dn); // Step 3: Enable the account (userAccountControl: 512 = NORMAL_ACCOUNT, enabled) + // ldapts requires attribute values as strings try { await client.modify(dn, [ new Change({ operation: 'replace', modification: new Attribute({ type: 'userAccountControl', - values: [512], + values: ['512'], }), }), ]);