From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 71C8A1FF0AD for ; Sun, 04 Oct 2026 18:04:03 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 62C3C2168F; Sun, 04 Oct 2026 18:03:47 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1791129819; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding:in-reply-to:references; bh=8eQvlCXt/e3eLDx3q+ZtgGFfKORww9FvoUZHm4GNcRQ=; b=w28xeBrVUaKWNuUkvWREU+NYUG8LMZPLGptJ4S99l2UsFubdET8haINzkpkM0WOBctAYOj lXtVG7n9+DNnWVlOBCwj50qn3QpcXlcqtN8ha++bLGZPplraJNlIEyABPTzAWZFzqCKsy4 6mLC2Mzncbh+uoB+W/n3ABxcQfzzHYaAZ2+xbuuEp7/SUXIYRgzmhMHeiyH0ddOv+T/hHv 2uMrBBr3eKyBAToE+XFQ9kId1CYa32HPxD578NVZSfJ+3y5qilybbB0qXNtw3sSnRHU/r5 rEDTkJUyuiMHao0eECc4/Nx6PgaF3w3i9YprvafGLcfvFIkP6Cqs4o05nAf8TQ== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH manager 1/2] fix #7649: ui: active directory realm: expose user attribute name option Date: Sun, 4 Oct 2026 16:03:34 +0000 Message-ID: <20261004160335.6-2-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261004160335.6-1-me@dualfroz.com> References: <20261004160335.6-1-me@dualfroz.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.170 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: NY5BMFM43DVXJUQYQEPVIYLDEJQDSHUD X-Message-ID-Hash: NY5BMFM43DVXJUQYQEPVIYLDEJQDSHUD X-MailFrom: me@dualfroz.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: AD realms support the 'user_attr' option, which sets the attribute used as username when syncing users, but it can only be set via the CLI. It is needed for logging in with the user principal name, if that does not end with the AD domain: with 'userPrincipalName' as attribute, the users are synced with their full user principal name, which is then used as is to bind to the server on login. Add a field for it, like the LDAP realm has, with the 'sAMAccountName' default as empty text. Signed-off-by: Michal Fox --- Tested in the browser with the realm edit window and mocked API calls: on create, the new field is only sent if set; on edit, a 'user_attr' set via the CLI is shown, kept when saving, and deleted when the field is cleared. Without the patch, there is no field, and the value can only be changed via the CLI. That the attribute is only used by the sync and the login binds with the given name as is, if it contains an '@', is from reading PVE::Auth::AD; the reporter confirmed that UPN logins work with it. www/manager6/dc/AuthEditAD.js | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/www/manager6/dc/AuthEditAD.js b/www/manager6/dc/AuthEditAD.js index ec5e7808..530b1a67 100644 --- a/www/manager6/dc/AuthEditAD.js +++ b/www/manager6/dc/AuthEditAD.js @@ -17,6 +17,13 @@ Ext.define('PVE.panel.ADInputPanel', { emptyText: 'company.net', allowBlank: false, }, + { + xtype: 'proxmoxtextfield', + name: 'user_attr', + fieldLabel: gettext('User Attribute Name'), + emptyText: Proxmox.Utils.defaultText + ' (sAMAccountName)', + deleteEmpty: !me.isCreate, + }, { xtype: 'proxmoxcheckbox', fieldLabel: gettext('Case-Sensitive'), -- 2.43.0