Enrich AD users from SGU profile metadata
This commit is contained in:
@@ -24,6 +24,20 @@
|
||||
- Client private keys are non-exportable and reside in `LocalMachine\My`.
|
||||
- The NTLM validator rejects non-HTTPS redirects, URI user information, and hosts
|
||||
outside its explicit redirect allow-list.
|
||||
- Profile enrichment reads only allow-listed HTTPS pages and caps the response
|
||||
body at 512 KiB by default. Portal cookies are request-scoped and held only in
|
||||
memory.
|
||||
|
||||
## Profile minimization
|
||||
|
||||
- Administrative enrichment reads only employee number, display name,
|
||||
employee type/status, email, job title, and department from known element IDs.
|
||||
- Incident details, calendars, photographs, manager names, and manager positions
|
||||
are deliberately ignored.
|
||||
- The employee number must match the authenticated `AD` key before metadata is
|
||||
synchronized.
|
||||
- If SGU changes its HTML, authentication and exact-password synchronization
|
||||
continue without enrichment; existing AD metadata is not erased.
|
||||
|
||||
Lab self-signed certificates are appropriate only for the isolated VM network.
|
||||
Use an enterprise CA with revocation checking in production.
|
||||
|
||||
Reference in New Issue
Block a user