Skip to content

Show GTAD enabled/disabled badges from userAccountControl - #23

Merged
kberzinch merged 3 commits into
mainfrom
cursor/gtad-uac-badges-d20c
Jul 18, 2026
Merged

kberzinch merged 3 commits into
mainfrom
cursor/gtad-uac-badges-d20c

Conversation

@kberzinch

Copy link
Copy Markdown
Member

Summary

Parse the GTAD LDAP userAccountControl attribute on the frontend and update the GTAD directory card badges:

  • Enabled, no Grouper groups → blue enabled badge
  • Enabled, with Grouper groups → existing group pills (unchanged)
  • Disabled → gray disabled badge; Grouper groups are hidden
  • No account → No account (unchanged)

Uses the AD ACCOUNTDISABLE bit (0x2). Missing/unparseable userAccountControl is treated as enabled so the card does not go blank.

Changes

  • elm/Main.elm: add isGtadAccountDisabled and gtadGrouperGroupNames helpers; update GTAD card badge rendering to match Keycloak-style enabled/disabled pills

No backend changes — /view/<id>/gtad already returns all LDAP attributes via attributes=["*"].

Testing

  • elm-review, elm-format --validate, and npm run build / build-debug pass
  • End-to-end checks against sample accounts (kc21, kberzinch3, bg37, mbarulic6) require live GTAD (cloud uses an empty LDAP mock)
Open in Web Open in Cursor 

Parse the ACCOUNTDISABLE bit on the GTAD LDAP userAccountControl
attribute so the directory card shows a blue enabled badge when there
are no Grouper groups, keeps group pills when provisioned, and shows a
gray disabled badge (hiding groups) when the account is disabled.

Co-authored-by: Kristaps Berzinch <kristaps@berzin.ch>
@cursor
cursor Bot temporarily deployed to production July 18, 2026 23:09 Inactive
cursoragent and others added 2 commits July 18, 2026 23:20
Only show enabled or disabled pills when userAccountControl is present
and parseable. If it is unavailable, still render Grouper group badges
when present, but do not infer an account status badge.

Co-authored-by: Kristaps Berzinch <kristaps@berzin.ch>
Extract group badge HTML into groupBadges so enabled and missing-UAC
paths reuse the same rendering instead of duplicating List.map.

Co-authored-by: Kristaps Berzinch <kristaps@berzin.ch>
@kberzinch
kberzinch marked this pull request as ready for review July 18, 2026 23:22
@cursor

cursor Bot commented Jul 18, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@kberzinch
kberzinch merged commit daf9c67 into main Jul 18, 2026
2 checks passed
@kberzinch
kberzinch deleted the cursor/gtad-uac-badges-d20c branch July 18, 2026 23:22
@cursor
cursor Bot temporarily deployed to production July 18, 2026 23:23 Inactive

This branch was previously deployed

1 inactive deployment
production — f469046d Deployed Jul 18, 2026 by cursor[bot] via Deploy / production #154
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants