chore(deps): move every ZB.MOM.WW pin to the newest published version
Auth 0.1.5 -> 0.2.0, Health 0.2.0 -> 0.3.0, Secrets/.Abstractions/.Ui 0.6.1 -> 0.6.2. Theme, GalaxyRepository, Audit, Configuration, Telemetry and Telemetry.Serilog were already at the newest version on the feed. Checked against the shared-lib source rather than the version numbers, because these packages are versioned as a family and a bump is not by itself evidence that the package changed: - Auth 0.2.0 is the only one carrying content for us: LDAP backup-DC failover (FallbackServers, endpoint walk with sticky preference, boot-time entry validation). Purely additive; the default is empty, which leaves single-endpoint behaviour unchanged. - Health 0.3.0 carries a breaking change, but every line of it is in ZB.MOM.WW.Health.Akka, which we do not reference. No commit touched the core ZB.MOM.WW.Health package between 0.2.0 and 0.3.0. - Secrets 0.6.2 is a message-only change: one validator string literal gains mounted-volume guidance. SecretsStorePathRules is untouched. The four non-csproj files are not a separate feature. Configuration/ LdapOptions is a deliberate shadow of the shared type and carries an explicit warning to mirror any new upstream field, because AddZbLdapAuth binds the whole MxGateway:Ldap section onto the shared options. So FallbackServers is live on our config surface the moment the package lands, and without the mirror an operator could configure a backup DC that works but is invisible on the dashboard's Settings page. The Settings row renders "none" when empty, since that is the answer someone who believes a backup DC is configured actually needs. Entry syntax is deliberately NOT re-validated here: the shared validator already fails the boot on a malformed entry and owns the (internal) parser, so a second copy would drift. Note both validators skip entirely when Ldap:Enabled is false. Verified the binder is non-strict (ErrorOnUnknownConfiguration is unused anywhere in the tree), so the upgrade could not break startup on a newly-recognised key either way. Build 0 warnings / 0 errors; gateway suite 892/892, unchanged. The live LDAP tests are opt-in and were not run, so the failover path itself is covered only by the shared library's own tests.
This commit is contained in:
@@ -68,4 +68,19 @@ public sealed class LdapOptions
|
||||
|
||||
/// <summary>Gets the LDAP attribute name for group membership.</summary>
|
||||
public string GroupAttribute { get; init; } = "memberOf";
|
||||
|
||||
/// <summary>
|
||||
/// Gets the ordered fallback LDAP endpoints (<c>"host"</c> or <c>"host:port"</c>) the shared
|
||||
/// provider walks when the primary fails with a system-side error. Empty (the default) leaves
|
||||
/// single-endpoint behaviour unchanged. Mirrors
|
||||
/// <see cref="ZB.MOM.WW.Auth.Abstractions.Ldap.LdapOptions.FallbackServers"/>, added in
|
||||
/// ZB.MOM.WW.Auth 0.2.0.
|
||||
/// <para>
|
||||
/// Carried here only so the effective-config display does not hide a configured backup DC —
|
||||
/// nothing on the gateway side reads it. Entry syntax is validated at boot by the shared
|
||||
/// <c>LdapOptionsValidator</c>, which owns the (internal) parser; re-validating here would
|
||||
/// mean a second, drifting copy of that grammar.
|
||||
/// </para>
|
||||
/// </summary>
|
||||
public IReadOnlyList<string> FallbackServers { get; init; } = [];
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user