Classify SGU accounts into AD role groups
This commit is contained in:
@@ -109,6 +109,12 @@ public sealed class ActiveDirectorySynchronizer(
|
||||
user.CommitChanges();
|
||||
}
|
||||
|
||||
// Role membership is part of account provisioning, not optional
|
||||
// enrichment. Do it before changing the password so a missing or
|
||||
// inaccessible authorization group cannot leave a newly usable
|
||||
// account without its required classification.
|
||||
EnsureRoleGroupMembership(user, identity);
|
||||
|
||||
// The exact institutional password received by the broker is passed to AD.
|
||||
// It is not derived, transformed, written to disk, or included in logs.
|
||||
user.Invoke("SetPassword", [password]);
|
||||
@@ -195,6 +201,33 @@ public sealed class ActiveDirectorySynchronizer(
|
||||
}
|
||||
}
|
||||
|
||||
private void EnsureRoleGroupMembership(DirectoryEntry user, UserIdentity identity)
|
||||
{
|
||||
user.RefreshCache(["distinguishedName"]);
|
||||
string? userDn = Convert.ToString(user.Properties["distinguishedName"].Value);
|
||||
if (string.IsNullOrWhiteSpace(userDn))
|
||||
{
|
||||
throw new InvalidOperationException($"Active Directory did not return a distinguished name for {identity.UserName}.");
|
||||
}
|
||||
|
||||
string groupDn = options.GetGroupDn(identity.Role);
|
||||
using DirectoryEntry group = Bind(groupDn);
|
||||
_ = group.NativeObject;
|
||||
if (group.Properties["member"].Contains(userDn))
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
group.Properties["member"].Add(userDn);
|
||||
group.CommitChanges();
|
||||
logger.LogInformation(
|
||||
BrokerEventIds.DirectoryRoleGroupMembershipAdded,
|
||||
"Added {InstitutionalUser} with role {Role} to Active Directory security group {GroupDn}.",
|
||||
identity.UserName,
|
||||
identity.Role,
|
||||
groupDn);
|
||||
}
|
||||
|
||||
private void TryEnsureRemoteDesktopGroupMembership(DirectoryEntry user, string institutionalUser)
|
||||
{
|
||||
if (string.IsNullOrWhiteSpace(options.RemoteDesktopGroupDn))
|
||||
|
||||
Reference in New Issue
Block a user