Enrich AD users from SGU profile metadata

This commit is contained in:
2026-09-01 07:34:00 -06:00
parent 289a67e371
commit 3d0897316d
16 changed files with 563 additions and 22 deletions
+14
View File
@@ -24,6 +24,20 @@
- Client private keys are non-exportable and reside in `LocalMachine\My`.
- The NTLM validator rejects non-HTTPS redirects, URI user information, and hosts
outside its explicit redirect allow-list.
- Profile enrichment reads only allow-listed HTTPS pages and caps the response
body at 512 KiB by default. Portal cookies are request-scoped and held only in
memory.
## Profile minimization
- Administrative enrichment reads only employee number, display name,
employee type/status, email, job title, and department from known element IDs.
- Incident details, calendars, photographs, manager names, and manager positions
are deliberately ignored.
- The employee number must match the authenticated `AD` key before metadata is
synchronized.
- If SGU changes its HTML, authentication and exact-password synchronization
continue without enrichment; existing AD metadata is not erased.
Lab self-signed certificates are appropriate only for the isolated VM network.
Use an enterprise CA with revocation checking in production.