Match an LDIF re-import on the entry's dn

Reported again by the submitter's colleague at LINET after #223 was
closed: duplicate checking was implemented for vCard and never for LDIF,
so re-importing an address book still leaves a second copy of everything.
That was deliberate at the time -- the matching key was an open question
I did not want to answer alone -- but the answer had already been given
on #174 and I closed the issue without acting on it.

The answer, in the submitter's words: an attribute that *can* change is
fine, because it will not have changed between two imports minutes apart.
An import is not a sync. That makes the `dn` usable -- it is the only
identity the file carries, and Mozilla's schema defines no UID -- and it
needs no guessing at all, unlike the name-plus-email fallback I had been
weighing.

So `uidFromDn` derives a namespaced, stable uid from the distinguished
name, normalised for the case and spacing two exports of one directory
differ in. A card the book already holds under that uid is updated rather
than duplicated, merged the way the vCard import merges: what the file
carries wins, what it does not mention is left alone. Reported as created
and updated, which is the pair that was asked for.

Three things worth knowing:

Matching is per address book, so two customer directories that each hold
a `cn=John Smith` stay two people as long as they are filed separately.
Imported into one book they would merge, which is the one way this can be
wrong and the reason the escape hatch is worth naming.

The look-alike count stays, and now means something narrower: entries
that `dn` matching could not catch -- one whose `dn` moved between
exports, and anything imported before there was a `dn` to match on. Those
are still only counted, never merged.

A file holding two entries under one `dn` is malformed, since a directory
cannot, and now becomes one card instead of two sharing an identity.

FEATURES gains the re-import behaviour for both formats; it documented
neither.
This commit is contained in:
2026-09-04 07:50:49 -07:00
parent 1f8c12e29e
commit b4248a6661
9 changed files with 330 additions and 53 deletions
+43 -1
View File
@@ -1,5 +1,5 @@
import { describe, expect, it } from "vitest";
import { parseLdif } from "@/lib/ldif";
import { parseLdif, uidFromDn } from "@/lib/ldif";
/** The example from issue #174, as SOGo exports it -- lowercased attribute names and all. */
const SOGO = `dn: cn=Jane Doe
@@ -103,3 +103,45 @@ describe("parseLdif", () => {
expect(r!.attrs.sn).toEqual(["Y"]);
});
});
describe("an identity for an entry, from its distinguished name", () => {
it("gives the same dn the same identity, which is the whole point", () => {
expect(uidFromDn("cn=Jane Doe,ou=People")).toBe(uidFromDn("cn=Jane Doe,ou=People"));
});
it("gives two entries two identities", () => {
expect(uidFromDn("cn=Jane Doe")).not.toBe(uidFromDn("cn=Alan Turing"));
});
it("ignores the case and spacing two exports of one directory differ in", () => {
// LDAP matches attribute types without regard to case, and exporters lay
// a dn out differently. Neither is a different person.
const canonical = uidFromDn("cn=Jane Doe,ou=People");
expect(uidFromDn("CN=Jane Doe,OU=People")).toBe(canonical);
expect(uidFromDn("cn = Jane Doe , ou = People")).toBe(canonical);
expect(uidFromDn(" cn=Jane Doe,ou=People ")).toBe(canonical);
});
it("does not run together words inside a value", () => {
expect(uidFromDn("cn=Jane Doe")).not.toBe(uidFromDn("cn=JaneDoe"));
});
it("says so plainly that it came from an LDIF entry", () => {
// It becomes the card's uid, where a vCard's own UID also lives. The
// namespace is what keeps one from being read as the other.
expect(uidFromDn("cn=Jane Doe")).toMatch(/^urn:x-ihasmail:ldif:/);
});
it("survives a dn a URI would otherwise choke on", () => {
const uid = uidFromDn("cn=Ünter Straße \\+ Söhne,ou=Übersicht")!;
expect(uid.startsWith("urn:x-ihasmail:ldif:")).toBe(true);
expect(uid).not.toMatch(/[\s?#]/);
});
it("has nothing to offer for an entry with no dn", () => {
// Such an entry gets an identity of its own instead, and duplicates on
// re-import as everything did before there was a dn to match on.
expect(uidFromDn("")).toBeNull();
expect(uidFromDn(" ")).toBeNull();
});
});