fix(16): WR-04 normalize the rename-vs-unchanged comparison
syncBoundGroupsForTenant() compared cn/dn for byte equality, so any casing difference AD returns between two runs (e.g. after a domain-controller switch) would look like a rename and re-write name/ldapDn every single sync — violating the 'sync twice over an unchanged AD state = no-op' idempotency guarantee. The comparison used to DECIDE 'is this a rename' is now case-insensitive; the value written on an actual rename is still stored byte-for-byte as the directory reports it, per D-03.
This commit is contained in:
@@ -1627,6 +1627,36 @@ describe('LdapService.syncBoundGroupsForTenant — Rekonziliation gegen das Verz
|
||||
expect(second.groupsRenamed).toBe(0);
|
||||
expect(second.groupsDeleted).toBe(0);
|
||||
});
|
||||
|
||||
it('a hit whose cn/dn differ only in casing from the stored values is NOT a rename — no write, no groupsRenamed increment (WR-04, 16-REVIEW.md)', async () => {
|
||||
// Simulates a domain-controller switch returning different casing for
|
||||
// the same, unchanged AD group between two syncs — Priority Check 7
|
||||
// ("sync twice over an unchanged AD state = no-op") must hold even
|
||||
// then.
|
||||
groups = [
|
||||
{
|
||||
id: 'g1',
|
||||
tenantId: 't1',
|
||||
name: 'Sales',
|
||||
ldapDn: 'CN=Sales,DC=example,DC=com',
|
||||
ldapObjectGuid: guidHex,
|
||||
isDefault: false,
|
||||
},
|
||||
];
|
||||
mockSearch.mockResolvedValue({
|
||||
searchEntries: [{ dn: 'cn=sales,dc=example,dc=com', cn: 'sales' }],
|
||||
});
|
||||
|
||||
const result = makeResult();
|
||||
await run(result);
|
||||
|
||||
expect(prisma.group.update).not.toHaveBeenCalled();
|
||||
expect(result.groupsRenamed).toBe(0);
|
||||
// The stored value is untouched — it is NOT rewritten to the
|
||||
// differently-cased AD response either.
|
||||
expect(groups[0].name).toBe('Sales');
|
||||
expect(groups[0].ldapDn).toBe('CN=Sales,DC=example,DC=com');
|
||||
});
|
||||
});
|
||||
|
||||
describe('LdapService — AD group import (SC-1/SC-2, D-01/D-02)', () => {
|
||||
|
||||
Reference in New Issue
Block a user