Fix AD user creation: userAccountControl must be string for ldapts

This commit is contained in:
Kühn
2026-08-28 11:28:56 +02:00
parent 03d20b0e09
commit a05133f39d

View File

@@ -178,7 +178,8 @@ async function createADUser({ ou, vorname, nachname, email, username, password,
sAMAccountName = sAMAccountName.substring(0, 20); sAMAccountName = sAMAccountName.substring(0, 20);
// userAccountControl: 514 = NORMAL_ACCOUNT + ACCOUNTDISABLE // userAccountControl: 514 = NORMAL_ACCOUNT + ACCOUNTDISABLE
const userAccountControl = 514; // ldapts requires attribute values as strings (numbers cause "The string argument must be of type string" error)
const userAccountControl = '514';
const effectiveDisplayName = displayName || (nachname + ', ' + vorname); const effectiveDisplayName = displayName || (nachname + ', ' + vorname);
const entry = { const entry = {
@@ -254,13 +255,14 @@ async function createADUser({ ou, vorname, nachname, email, username, password,
console.log('[LDAP] Passwort gesetzt für:', dn); console.log('[LDAP] Passwort gesetzt für:', dn);
// Step 3: Enable the account (userAccountControl: 512 = NORMAL_ACCOUNT, enabled) // Step 3: Enable the account (userAccountControl: 512 = NORMAL_ACCOUNT, enabled)
// ldapts requires attribute values as strings
try { try {
await client.modify(dn, [ await client.modify(dn, [
new Change({ new Change({
operation: 'replace', operation: 'replace',
modification: new Attribute({ modification: new Attribute({
type: 'userAccountControl', type: 'userAccountControl',
values: [512], values: ['512'],
}), }),
}), }),
]); ]);