diff --git a/src/lib/ldap/client.ts b/src/lib/ldap/client.ts index c47b362..d85c23e 100644 --- a/src/lib/ldap/client.ts +++ b/src/lib/ldap/client.ts @@ -45,7 +45,15 @@ function search( ): Promise<{ dn: string; attributes: Record }[]> { return new Promise((resolve, reject) => { const results: { dn: string; attributes: Record }[] = []; - client.search(baseDn, { filter, scope: "sub" }, (err, res) => { + // Paged (RFC 2696) rather than one unbounded response: a directory-wide + // browse on a real AD domain can return ~1000 entries, and ldapjs's + // single-response handling for a batch that size was observed to drop + // the connection (" closed") even though a plain `ldapsearch` with + // the identical filter completes cleanly — so the fix is on our client's + // response handling, not the query itself. ldapjs runs the multi-page + // RFC 2696 round-trips internally; callers still just see one continuous + // stream of `searchEntry` events followed by a single `end`. + client.search(baseDn, { filter, scope: "sub", paged: { pageSize: 200 } }, (err, res) => { if (err) { reject(err); return;