807b95e92a
Adds RulesHandler exposing POST /api/v1/rules/{id}/preview and
POST /api/v1/rules/{id}/run. Preview returns the generated LDAP filter,
matched objects, and planned actions. Run triggers an immediate execution
via the Runner using the X-Triggered-By header (defaults to 'api').
Also adds Runner.PreviewRule so the handler can delegate without having to
load the rule, connection, and LDAP client itself.