mssql remaps a user only when orphaned; mailu's operator tool no longer re-enables

ALTER USER ... WITH LOGIN runs only when the user's SID is not the
login's, so an already-mapped user is left alone. The provisioner
enables a mailbox through its own method; the password tool an
operator uses keeps changing the password only.
This commit is contained in:
jochen
2026-09-26 01:30:15 +02:00
parent 6fd93afc6c
commit 620b47d309
3 changed files with 22 additions and 6 deletions
+11 -3
View File
@@ -148,9 +148,17 @@ export class MssqlClient {
if (users.length === 0) {
await this.exec(`CREATE USER ${ident(login)} FOR LOGIN ${ident(login)}`, database);
} else {
// Re-point an existing user at the login. A database restored from elsewhere keeps its user
// under the old login's SID, orphaned; this maps it back, and is a no-op when it already is.
await this.exec(`ALTER USER ${ident(login)} WITH LOGIN = ${ident(login)}`, database);
// Re-point an existing user at the login when its SID is not the login's: a database restored
// from elsewhere keeps its user under the old login's SID, orphaned. Only then, so a user that
// is already mapped is left alone.
const orphaned = await this.query(
`SELECT 1 AS ok FROM sys.database_principals WHERE name = ${literal(login)} ` +
`AND (sid IS NULL OR sid <> SUSER_SID(${literal(login)}))`,
database,
);
if (orphaned.length > 0) {
await this.exec(`ALTER USER ${ident(login)} WITH LOGIN = ${ident(login)}`, database);
}
}
await this.exec(`ALTER ROLE db_owner ADD MEMBER ${ident(login)}`, database);
}