Method, system and device for synchronizing address book and medium
By monitoring the address book changes of the collaborative office platform through the synchronization server, obtaining and comparing the address book difference information of the LDAP server, and performing synchronous updates, the problems of low synchronization efficiency and poor consistency between the LDAP server and the collaborative office platform are solved, and efficient and accurate address book synchronization is achieved.
Patent Information
- Application Number
- CN202510409191.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-02
AI Technical Summary
In the prior art, the address book synchronization between the LDAP server and the collaborative office platform is inefficient, error-prone, and it is difficult to ensure the real-time and consistency of data.
By monitoring the address book changes of the collaborative office platform through the synchronous server, obtaining and comparing the address book difference information of the LDAP server, and performing synchronous updates, using protocol conversion middleware to solve the protocol incompatibility problem, combining the token bucket algorithm to control the request rate, using hash value comparison to accelerate the difference identification, and optimizing the LDAP query performance.
It realizes automatic synchronization between the collaborative office platform and the LDAP server address book, improves synchronization rate and accuracy, and ensures data consistency and real-timeness.
Smart Images

Figure CN120263892A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and particularly to a method, a system, a device and a medium for synchronizing an address book. Background Art
[0002] By synchronizing the address book of an LDAP (Lightweight Directory Access Protocol) server with the address book of a collaborative office platform (such as Feishu, WeCom, DingTalk, etc.), unified user management and identity authentication can be achieved. In related technologies, it is usually relied on manual addition or modification of departments and users one by one in the collaborative office platform to synchronize the internal organizational structure of an enterprise and the address book of the collaborative office platform. However, this method is inefficient, error-prone and difficult to ensure the real-time nature and consistency of data. Therefore, there is an urgent need for an efficient and accurate method for synchronizing an address book to solve the above problems. Summary of the Invention
[0003] In view of the above problems, the present invention is proposed to provide a method, a system, a device and a medium for synchronizing an address book that can overcome the above problems or at least partially solve the above problems.
[0004] To achieve the above object and other related objects, the present invention provides a method for synchronizing an address book, which is applied to a synchronization server. The synchronization server is respectively connected to an LDAP server and a collaborative office platform. The method includes:
[0005] When it is monitored that a first address book of a collaborative office platform has changed, obtain the first address book from the collaborative office platform, and obtain a second address book from the LDAP server, and compare the user information in the first address book with the user information in the second address book to determine the address book difference information between the first address book and the second address book;
[0006] Synchronously update the second address book according to the address book difference information, so that the first address book is consistent with the second address book.
[0007] Optionally, before the step of obtaining the first address book from the collaborative office platform and obtaining the second address book from the LDAP server when it is monitored that the first address book of the collaborative office platform has changed, the method further includes:
[0008] Establish an SSL / TLS connection with the LDAP server by using the pre-configured connection parameters in the synchronization server, and authenticate the LDAP server.
[0009] Optionally, after the step of establishing an SSL / TLS connection with the LDAP server by using the pre-configured connection parameters in the synchronization server and authenticating the LDAP server, the following steps are further included:
[0010] Set up a scheduled task to periodically poll and query the second address book of the LDAP server to obtain a query result;
[0011] Extract the user attributes of the query result and convert them into data in serialized format;
[0012] Compare the data in serialized format with the historical data of the second address book cached in the synchronization server to obtain the user difference information of the second address book.
[0013] Optionally, before the step of, when it is monitored that the first address book of the collaborative office platform has changed, obtaining the first address book from the collaborative office platform and obtaining the second address book from the LDAP server, the following steps are further included:
[0014] Register and log in to the open platform of the collaborative work platform, and create an address book API on the open platform to obtain the identifier and secret key of the address book API;
[0015] Apply for the permission of the address book API, configure the application data permission of the address book API, and set the whitelist of the address book API;
[0016] Use the identifier and secret key to call the address book API.
[0017] Optionally, the comparing the user information in the first address book with the user information in the second address book to determine the address book difference information between the first address book and the second address book includes:
[0018] Perform hash processing on the user attributes of each user in the first address book to generate the first hash value of each user in the first address book; and perform hash processing on the user attributes of each user in the second address book to generate the second hash value of each user in the second address book;
[0019] Compare the first hash value with the second hash value to determine the address book difference information between the first address book and the second address book.
[0020] Optionally, after the step of synchronously updating the second address book according to the address book difference information to make the first address book and the second address book consistent, the following steps are further included:
[0021] When the step of synchronously updating the second address book according to the address book difference information fails, after waiting for a preset time, the step of synchronously updating the second address book according to the address book difference information is executed again. When the number of failures reaches the preset number, the failure information is recorded, and the address book difference information is saved.
[0022] Optionally, after the step of synchronously updating the second address book according to the address book difference information to make the first address book consistent with the second address book, the following steps are further included:
[0023] Generate a synchronization log for synchronously updating the second address book according to the address book difference information, and use a change log to record the synchronization log of each synchronization update operation.
[0024] In a second aspect, the present invention further provides a system for synchronizing an address book, which is applied to a synchronization server. The synchronization server is respectively connected to an LDAP server and a collaborative office platform. The system includes:
[0025] A comparison module, configured to, when it is monitored that the first address book of the collaborative office platform changes, obtain the first address book from the collaborative office platform, obtain the second address book from the LDAP server, compare the user information in the first address book with the user information in the second address book, and determine the address book difference information between the first address book and the second address book;
[0026] A synchronization module, configured to synchronously update the second address book according to the address book difference information to make the first address book consistent with the second address book.
[0027] In a third aspect, the present invention provides an electronic device, which includes: a memory and a processor; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory so that the electronic device executes the steps of the method for synchronizing an address book as described above.
[0028] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by an electronic device, the steps of the method for synchronizing an address book as described above are implemented.
[0029] One or more of the above technical solutions provided by the present invention may have the following advantages or at least achieve the following technical effects:
[0030] The method, system, device and medium for synchronizing address books of the present invention. When it is monitored that the first address book of the collaborative office platform changes, by comparing the first address book of the collaborative work platform with the second address book of the LDAP server and synchronously updating the obtained address book difference information to the second address book, the automatic synchronization of the first address book in the collaborative office platform and the second address book in the LDAP server is realized, further improving the synchronization rate and accuracy. Brief Description of the Drawings
[0031] Figure 1 It shows a schematic flowchart of the method for synchronizing address books in an embodiment of the present invention;
[0032] Figure 2 It shows a schematic diagram of the functional modules of the system for synchronizing address books in an embodiment of the present invention;
[0033] Figure 3 It shows a schematic diagram of an electronic device in an embodiment of the present invention. Detailed Embodiments
[0034] The following uses specific specific examples to illustrate the embodiments of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0035] It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner. Therefore, only the components related to the present invention are shown in the diagrams, rather than being drawn according to the number, shape and size of the components in actual implementation. The type, quantity and proportion of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0036] In the following description, a large number of details are explored to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.
[0037] In the specification, claims, and the above-mentioned accompanying drawings of the embodiments of the present disclosure, terms such as "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so as to implement the embodiments of the present disclosure described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.
[0038] Unless otherwise specified, the term "plurality" means two or more.
[0039] In the embodiments of the present disclosure, the character " / " indicates that the objects before and after are in an "or" relationship. For example, A / B means: A or B.
[0040] The term "and / or" is an associative relationship describing an object, indicating that there can be three relationships. For example, A and / or B means: A or B, or, A and B these three relationships.
[0041] For the sake of easy understanding, the following first explains the relevant nouns or terms used in the embodiments of the present invention:
[0042] <1>. LDAP (Lightweight Directory Access Protocol), a directory service protocol based on the X.500 standard, is used to access and maintain distributed directory information services.
[0043] <2>. SSL / TLS (Secure Sockets Layer / Transport Layer Security) is a security protocol used to provide encryption, authentication, and data integrity in network communication.
[0044] <3>. API (Application Programming Interface) is an interface that allows different software programs to interact with each other.
[0045] <4>. go-ldap, a library for operating LDAP servers in the Go language, which provides a set of functions and structures, enabling developers to easily interact with LDAP servers and perform operations such as querying, adding, modifying, and deleting.
[0046] <5>. Web hook is a mechanism that allows an application to send real-time notifications to another application when a specific event occurs. For example, when a specific event (such as creating, deleting, or modifying a user, etc.) occurs in application A, application A will automatically trigger a Webhook.
[0047] <6>, RESTful (Representational State Transfer-full), an architectural style based on the HTTP protocol, is used to design network applications. It makes the system more modular, scalable, and easy to maintain through principles such as unified interfaces, stateless interactions, resource orientation, and hypermedia links.
[0048] <7>, SCIM (System for Cross-domain Identity Management), is an open standard aimed at simplifying the management of users and groups, especially in multi-tenant or cross-organizational environments. SCIM provides a standardized method for managing identity information (such as users, groups, etc.), enabling efficient synchronization and management of identity data between different systems.
[0049] <8>, Node.js, is an open-source, cross-platform JavaScript runtime environment based on the Chrome V8 engine that allows developers to run JavaScript on the server side. It is designed specifically for high-performance, high-concurrency network applications and uses an event-driven, non-blocking I / O model to efficiently handle a large number of concurrent connections.
[0050] <9>, Apache Camel, is an open-source integration framework used to simplify the development of message passing and integration between applications. It allows developers to define routing and mediation rules through simple Java DSL (Domain-Specific Language) or XML configurations, thereby achieving data exchange and business process orchestration between different systems.
[0051] <10>, Nginx+Lua, is a technology that enhances the functionality of Nginx by embedding Lua scripts into it without relying on external applications.
[0052] <11>, Dedicated DN (Dedicated DN), a name that uniquely identifies an entry in a directory in LDAP.
[0053] <12>, VLV index (Virtual List View Index), is a technology used to optimize the query performance of LDAP servers. By virtualizing the entries in the directory into an ordered list and using an indexing mechanism to quickly locate and retrieve entries.
[0054] <13>, Range query, is a technology for requesting data fragments from a server, allowing the client to obtain resources or data in segments.
[0055] <14>, Rabbit MQ is an open-source message broker that supports multiple messaging patterns, including point-to-point, publish / subscribe, and request / response. It is suitable for task queues, microservice communication, and event-driven architectures.
[0056] <15>, Kafka is a distributed stream processing platform mainly used for building real-time data pipelines and streaming applications. It is suitable for log aggregation, real-time analysis, event sourcing, and Internet of Things data processing.
[0057] <16>, ELK (Elasticsearch, Logstash, Kibana) is a log analysis and visualization platform composed of Elasticsearch, Logstash, and Kibana, which is widely used for collecting, processing, storing, and visualizing log data.
[0058] <17>, Loki is a log aggregation system developed by Grafana Labs, designed specifically for large-scale log data.
[0059] Next, the technical solutions in the embodiments of the present invention will be described in detail with reference to the accompanying drawings in the embodiments of the present invention.
[0060] Please refer to Figure 1 , an embodiment of the present invention provides a method for synchronizing an address book, which is applied to a synchronization server. The synchronization server is respectively connected to an LDAP server and a collaborative office platform. The method may include the following steps S10 to S20:
[0061] Step S10, when it is monitored that the first address book of the collaborative office platform has changed, obtain the first address book from the collaborative office platform, obtain the second address book from the LDAP server, and compare the user information in the first address book with the user information in the second address book to determine the address book difference information between the first address book and the second address book.
[0062] Among them, the synchronization server is used to connect to the collaborative work platform and the LDAP server to synchronize the address books of the LDAP server and the collaborative work platform. It can directly read the address book of the LDAP server using the LDAP protocol (such as connecting to the LDAP server using the go-ldap library, querying and obtaining user and department information in the LDAP server, such as name, email, mobile phone number, etc.), or obtain the address book stored and managed by the LDAP server based on a protocol conversion middleware; and the synchronization server can call the address book API of the collaborative work platform to obtain the address book stored and managed by the collaborative work platform.
[0063] The first address book is used to represent the address book (i.e., the enterprise organizational structure) centrally stored and managed in the collaborative office platform, which includes enterprise department information, enterprise personnel (i.e., users) information, etc.
[0064] A user can represent a member within an enterprise. The user resources in the address book include basic information such as a unique identifier (ID), name, phone number, and email, and also include information such as the department to which the user belongs and custom fields.
[0065] A department is used to represent a certain node on the enterprise organizational structure tree. Within a department, users can be added as department members, and new departments can also be added to establish a parent-child hierarchical relationship.
[0066] The second address book is used to represent the address book managed and stored in the LDAP server.
[0067] The address book difference information is used to represent the address book differences obtained by comparing the first address book and the second address book; it can include the creation, modification (such as phone number, email, department, etc.), and deletion of departments and users.
[0068] As an example, when the first address book includes Employee A (Sales Department), Employee B (Technical Department), Employee C (Marketing Department), and the second address book includes Employee A (Sales Department), Employee B (Technical Department), Employee C (Sales Department), comparing the first address book and the second address book, it is found that the department of Employee C in the first address book has changed.
[0069] As another example, when the first address book includes Employee A, Employee B, Employee D, and the second address book includes Employee A, Employee B, Employee C, comparing the first address book and the second address book, it is found that Employee D is newly added and Employee C is deleted in the first address book.
[0070] In a specific implementation, when the first address book of the collaborative work platform changes, the collaborative work platform can receive the first address book change event (such as employee onboarding, employee departure, employee information modification, etc.) pushed by the collaborative office platform through the Webhook configured by the address book API of the collaborative work platform. The synchronization server can request to call the address book API of the collaborative work platform to obtain the first address book, and the synchronization server can request the LDAP server to obtain the second address book; then compare the user information in the first address book with the user information in the second address book to obtain the address book difference information between the first address book and the second address book.
[0071] Preferably, considering that LDAP is based on the directory service protocol (tree query), while the collaborative office platform usually uses RESTful API or SCIM interface, protocol incompatibility will cause difficulties in data interaction. In addition, there are restrictions on the collaborative office platform API (such as call frequency, paging size, etc.), and it is necessary to adapt to the interface specifications of different platforms (for example, the number of pages of Feishu is different from that of DingTalk).
[0072] In view of this, the embodiments of the present invention convert LDAP operations into HTTP requests based on a protocol conversion middleware, or reverse-resolve API responses into LDAP entries to overcome the data interaction difficulties caused by protocol incompatibility. And, in response to the problem of frequency control restrictions on the collaborative office platform API, the embodiments of the present invention control the request rate through the token bucket algorithm and combine the exponential backoff mechanism to handle the frequency limit problem.
[0073] Exemplarily, converting LDAP operations into HTTP requests based on a protocol conversion middleware, or reverse-resolving API responses into LDAP entries, the process may include:
[0074] First, deploy a protocol conversion middleware that can support both LDAP protocol and HTTP protocol, and configure the mapping rules between LDAP operations and HTTP requests in the protocol conversion middleware. The protocol conversion middleware has the ability to parse and generate data of both protocols. For example, it can be a Node.js custom middleware, an Apache Camel middleware, an Nginx+Lua middleware, etc. The mapping rules between LDAP operations and HTTP requests, for example, clarify which request method of HTTP (such as GET) the LDAP query operation corresponds to, which attributes of LDAP are mapped to the parameters in the HTTP request, etc., and how the API response data corresponds to each field of the LDAP entry, etc.
[0075] Second, in response to an LDAP operation request, the protocol conversion middleware captures the request and converts the LDAP operation information into the corresponding HTTP request format according to the pre-configured mapping rules and sends it to the target system. Among them, the target system is, for example, a Web application, etc., aiming to achieve the conversion of LDAP operations to HTTP requests and solve the interaction problem between the LDAP system and the system that only supports the HTTP protocol.
[0076] Finally, when the target system returns an API response after processing an HTTP request, the protocol conversion middleware receives the response and, according to the pre-configured mapping rules, parses the data in the API response and converts it into the LDAP entry format. In this way, even if the response returned by the target system is in HTTP format, it can be correctly converted into an entry that the LDAP system can recognize and process, thus completing the entire data interaction process and overcoming the data interaction difficulties caused by protocol incompatibility.
[0077] Exemplarily, controlling the request rate through the token bucket algorithm and combining the exponential backoff mechanism to handle the frequency limiting problem, the process may include:
[0078] First, tokens are put into the token bucket at a fixed rate. When there is a request, only the request that obtains a token will be processed. For example, it can be set to put 10 tokens into the bucket per second, and each request consumes 1 token, so that the request rate can be limited within 10 requests per second.
[0079] Second, when a request is rejected due to rate limiting (such as the frequency of the synchronous server request to call the address book API of the collaborative work platform to obtain the first address book exceeds the limit, or the frequency of the request to call the address book API of the collaborative work platform to synchronously update the first address book exceeds the limit), the exponential backoff mechanism is triggered for retry. After each request is rejected, the waiting time increases exponentially before the next attempt. For example, the first retry waits for 1 second, the second waits for 2 seconds, the third waits for 4 seconds, and so on, until success or the maximum retry count (or maximum waiting time) is reached. This strategy can effectively reduce the pressure on the address book API of the collaborative work platform by dynamically adjusting the retry interval time and avoid being further rate limited due to frequent requests.
[0080] Step S20, synchronously update the second address book according to the address book difference information, so that the first address book is consistent with the second address book.
[0081] In a specific implementation, after obtaining the address book difference information between the first address book and the second address book, according to the address book difference information, the synchronization server can request to synchronously update the second address book of the LDAP server to synchronize the address book of the LDAP server with the address book of the collaborative office platform. Thus, when it is monitored that the first address book of the collaborative office platform changes, by comparing the first address book of the collaborative office platform with the second address book of the LDAP server and synchronously updating the obtained address book difference information to the second address book, the automatic synchronization of the first address book in the collaborative office platform and the second address book in the LDAP server is realized, further improving the synchronization rate and accuracy.
[0082] As an example, when the first address book includes Employee A (Sales Department), Employee B (Technical Department), and Employee C (Marketing Department), and the second address book includes Employee A (Sales Department), Employee B (Technical Department), and Employee C (Sales Department), comparing the first address book and the second address book reveals that the department of Employee C in the first address book has changed. The department information of Employee C in the second address book can be modified (for example, changing the Sales Department of Employee C in the second address book to the Marketing Department), so as to ensure that the updated second address book is the same as the first address book.
[0083] As another example, when the first address book includes Employee A, Employee B, and Employee D, and the second address book includes Employee A, Employee B, and Employee C, comparing the first address book and the second address book reveals that Employee D is newly added and Employee C is deleted in the first address book. Further, Employee C in the second address book can be deleted, and Employee D can be added to the second address book, so as to ensure that the updated second address book is the same as the first address book.
[0084] Further, in an embodiment, before step S10, the method may further include step A10:
[0085] Step A10: Establish an SSL / TLS connection with the LDAP server using the pre-configured connection parameters in the synchronization server, and authenticate the LDAP server.
[0086] Among them, the connection parameters are used to represent the necessary configuration information for establishing and managing the communication between the synchronization server and the LDAP server. Such as server address, port number, dedicated DN (unique identifier), encryption method (SSL / TLS encryption), etc.
[0087] In this embodiment, before synchronizing the address book, it is also necessary to establish a communication connection between the LDAP server and the synchronization server. For example, use the LDAP library of the Go language (such as the go-ldap library) to connect to the LDAP server, and then the department and user information in the LDAP server can be queried; the connection parameters of the LDAP server can be pre-configured and managed in the synchronization server, such as the network address, port number, dedicated DN, and encryption method of the LDAP server, and then an SSL / TLS connection with the LDAP server is established using the pre-configured connection parameters; then, the LDAP server is authenticated using the Bind method (such as simple binding, anonymous binding), that is, the synchronization server can verify the user identity through the binding operation. After completing the authentication, the synchronization server can obtain the address book data in the LDAP server according to its permissions; thus, by successfully establishing the connection between the LDAP server and the synchronization server, a foundation is laid for subsequent address book synchronization.
[0088] As an example, in the Simple Bind method, authentication is performed by providing the user's dedicated DN (unique identifier) and password. The synchronization server can send a Bind request containing the DN and password to the LDAP server; the LDAP server checks the existence of the dedicated DN and verifies whether the password is correct; if the verification is successful, the LDAP server returns a success response; if it fails, an error message is returned.
[0089] As another example, in the anonymous bind method, the synchronization server does not provide any identity information (i.e., no username and password) when binding, allowing access to the publicly available part of the data in the LDAP server. The synchronization server sends a bind request to the LDAP server, where the dedicated DN and password fields are empty; after receiving the bind request, the LDAP server checks whether anonymous access is allowed. If the LDAP server is configured to allow anonymous binding, the request is accepted and a success response is returned; otherwise, the request is rejected and an error message is returned.
[0090] Preferably, in the embodiments of the present application, considering that the LDAP query performance degrades (such as deep paging query with page Size = 1000 causing timeouts) when synchronizing tens of thousands of users, the embodiments of the present application solve this problem through VLV / Range query optimization paging mechanism, data chunk parallel processing, caching, and asynchronous preloading.
[0091] First, create a VLV index in the LDAP server (such as Open LDAP) to allow the client to directly locate data chunks through offsets and ranges, or optimize the paging mechanism through Range queries. In this way, traversing all entries can be avoided, the traversal overhead during deep paging can be reduced, and the query time is optimized from linear growth to constant time. VLV query is an efficient paging query method that avoids performance problems caused by too large an offset in traditional paging queries through the virtual list method. Range query reduces the amount of data queried by specifying the query range, thereby improving query efficiency. Both of these query methods can effectively solve the problem of degraded LDAP query performance, especially during deep paging queries, which can significantly reduce the query time.
[0092] Second, according to the memory and processing capabilities of the LDAP server, the data to be synchronized is divided into multiple small data chunks; multi-threading or multi-process technology is used to process the divided data chunks in parallel. In this way, the computing resources of the LDAP server can be fully utilized, the data processing speed can be increased, and the synchronization time can be reduced.
[0093] Finally, for frequently queried data, use a caching mechanism to store it in memory to reduce the number of queries to the LDAP server. At the same time, through asynchronous preloading, preload the data that may be needed in advance when the LDAP server is idle. In this way, the response speed of the LDAP server can be further improved, and the user waiting time can be reduced.
[0094] Further, in one embodiment, after step S20, the method may further include step S30:
[0095] Step S30, when the step of synchronously updating the second address book according to the address book difference information fails, after waiting for a preset time, execute again the step of synchronously updating the second address book according to the address book difference information. When the number of failures reaches the preset number, record the failure information and save the address book difference information.
[0096] Wherein, the preset time is used to represent the waiting time preset according to the reason for the failure of the synchronous update.
[0097] The preset number is used to represent the preset number of retry times (for example, the preset number of retry times is 3 times).
[0098] In this embodiment, when no response from the LDAP server is received within a certain period of time, it can be determined that the step of synchronously updating the second address book according to the address book difference information fails (such as network interruption or service failure of the LDAP server); this synchronous update task can be stored in the message queue of the synchronous server (such as storing the failed synchronous update task in the Rabbit MQ or Kafka queue of the synchronous server), and after an interval of time, execute again the step of synchronously updating the second address book according to the address book difference information; and when it is detected that the number of failures of the synchronous update operation exceeds the preset number, trigger a manual warning (such as through a robot or email notification of the collaborative work platform), and then the failed synchronous update operation (i.e., the synchronous update failure information) can be recorded in the log (including information such as the failure reason and timestamp), and the address book difference information of this synchronous update operation can be saved. Thus, by setting a retry policy, the stability and reliability of the synchronous server are improved, and at the same time, data loss caused by synchronous failures is reduced, effectively handling the problem of synchronous update failures.
[0099] Further, in one embodiment, after step S20, the method may further include S40:
[0100] Step S40, generate a synchronization log for synchronously updating the second address book according to the address book difference information, and use a change log to record the synchronization log of each synchronous update operation.
[0101] Among them, the synchronization log is used to represent a file or data set that records various information during the process of the synchronization server performing synchronization update operations; it includes but is not limited to: basic information, status information, and data information. It uses a structured format (such as JSON) and contains the operation type, user ID, and error details.
[0102] Basic information: It can include a timestamp, operation type (such as incremental synchronization), synchronization source and target (such as synchronizing from the first address book to the second address book).
[0103] Status information: It can include the synchronization status (success, failure, in progress, etc.), error code and description (such as when the synchronization fails, record the specific error code and detailed error description).
[0104] Data information: It can include the amount of synchronized data (such as how many employee information and department information are synchronized), data change details (for incremental synchronization, it will record which data has changed, such as which departments or users are newly added, modified, or deleted).
[0105] In this embodiment, after each execution of the step of synchronously updating the second address book according to the address book difference information, a corresponding synchronization log is generated, and then the change log is used to record the synchronization log of each synchronization update operation; thus, by reasonably recording, storing, and managing the synchronization log, it is convenient for log analysis solutions such as ELK or Loki analysis.
[0106] In this embodiment, when it is monitored that the first address book of the collaborative office platform has changed, by comparing the first address book of the collaborative work platform with the second address book of the LDAP server, and synchronously updating the obtained address book difference information to the second address book, the automatic synchronization of the first address book in the collaborative office platform and the second address book in the LDAP server is realized, further improving the synchronization rate and accuracy.
[0107] Based on the foregoing embodiment, a second embodiment of the method for synchronizing address books according to the present invention is proposed. In this embodiment, after step A10, the method may further include the following steps A20 to A40:
[0108] Step A20, set a timed task to periodically poll and query the second address book of the LDAP server to obtain a query result.
[0109] Among them, the timed task is used to represent a task that periodically initiates a query for the latest second address book of the LDAP server by the synchronization server, and it will be automatically executed at a specific time interval or specific time point (such as once every 5 minutes).
[0110] Query result, which is used to represent the user attributes (such as user ID, email, department, etc.) of the latest second address book obtained from the LDAP server after executing the scheduled task.
[0111] In a specific implementation, after successfully establishing a connection between the LDAP server and the synchronization server, the LDAP server can be periodically polled by setting a scheduled task. For example, an LDAP query statement can be used to specify the search base (Base DN) and filtering conditions, so as to regularly obtain the latest second address book from the LDAP server, obtain a list of users that meet the requirements (such as returning user attributes, such as email, mobile phone number, etc.), that is, the query result.
[0112] It should be noted that during the process of the synchronization server (such as the go-ldap library) polling the second address book of the LDAP server, accounts marked as invalid or expired in the LDAP server will be filtered out.
[0113] Step A30, extract the user attributes of the query result and convert them into data in serialized format.
[0114] Among them, the data in serialized format is used to represent the data obtained by converting the user attributes extracted from the query result into a unified data structure (such as JSON or Protobuf).
[0115] In a specific implementation, the query result can be parsed to extract user attributes from the query result; furthermore, the user attributes can be converted into data in a unified serialized format.
[0116] Step A40, compare the data in the serialized format with the historical data of the second address book cached by the synchronization server to obtain the user difference information of the second address book.
[0117] Among them, the historical data of the second address book is used to represent the second address book in a unified data structure (such as JSON or Protobuf) cached by the synchronization server after the last synchronization update operation.
[0118] User difference information is used to represent the department or user information in which the second address book in the LDAP server has changed since the last synchronization operation, that is, the newly added, modified, or deleted department and user information found after comparing the data in the serialized format generated from the latest second address book with the historical data of the second address book.
[0119] In a specific implementation, the serialized format data can be compared with the second address book historical data cached in the synchronization server, and the newly added, modified or deleted departments or users in the second address book of the LDAP server can be marked, so as to obtain the user difference information of the second address book; thus, the user difference information can be used as the input for synchronous update to synchronously update the first address book of the collaborative work platform, so as to ensure that the user and department information in the second address book of the LDAP server is consistent with that in the first address book of the collaborative work platform.
[0120] In this embodiment, by setting a scheduled task to periodically poll and query the second address book of the LDAP server, a query result is obtained; the user attributes of the query result are extracted and converted into data in a serialized format; the data in the serialized format is compared with the historical second address book data in the synchronization server to obtain the user difference information of the second address book. Thus, the latest user and department information is obtained by periodically querying the LDAP server, the first address book of the collaborative work platform is synchronously updated, and the data consistency between the second address book of the LDAP server and the first address book of the collaborative work platform is maintained.
[0121] Based on the foregoing embodiments, a third embodiment of the method for synchronizing the address book according to the present invention is proposed. In this embodiment, before step S10, the method may further include the following steps B10 to B30:
[0122] Step B10, register and log in to the open platform developer background of the collaborative work platform, and create an address book API on the open platform to obtain the identifier and secret key of the address book API.
[0123] Among them, the identifier (app_id) and the secret key (app_secret) are used to represent the unique identifier and secret key of the open platform application and are used to call the API of the open platform.
[0124] In a specific implementation, the open platform of the collaborative work platform can be entered first, a developer account can be registered and the password corresponding to the developer account can be set, and then the developer account and password can be used to log in to the open platform; after logging in to the open platform, the "Create Application" button can be clicked, and then the application name (such as the address book API) and application description can be filled in, and then click to create; after the creation of the address book API is completed, the identifier (app_id) and the secret key (app_secret) of the address book API can be viewed on the application details page.
[0125] Step B20, apply for the permission of the address book API, configure the application data permission of the address book API, and set the whitelist of the address book API.
[0126] Among them, the permission scope of the address book API defines the scope of department and user data that the application can access, and the application cannot access data outside the permission scope.
[0127] The application data permission is used to represent the scope of address book data that the application can obtain when calling the address book API in the application's identity (such as the scope of departments and users that can be accessed). Only departments and users within the data permission scope can the application query or operate on.
[0128] The configuration method of the address book data permission. By default, the address book permission scope is configured to be the same as the available scope of the application; for manual configuration, specific departments or members can be selected and set as the address book permission scope; for the full-member scope, it can be configured as the address book permission for all members within the enterprise.
[0129] As an example, when querying the information of user A by calling the address book API in the application's identity, the application needs to have the data permission for user A.
[0130] As another example, there are three departments A, B, and C in the address book. If an application only has the address book permissions for departments B and C, then the application can only obtain the data of departments B and C in the address book through the interface, and an error indicating no permission will be reported when trying to obtain the data of department A.
[0131] In the specific implementation, enter the (development configuration) permission management page in the developer background of the development platform, and you can select and confirm to enable the API permissions required for this address book API, such as permissions for creating, deleting, and modifying departments and users, reading the department information list, user information, etc.; then in the address book permission scope area, configure the application data permission of the address book API; and in order to improve the security of application access, you can set the IP list that can legally access the address book API of the collaborative work platform through the IP white list function. Requests from IP addresses not in the white list will be rejected and an error prompt message will be returned.
[0132] Step B30, call the address book API by using the application access credential.
[0133] In a specific implementation, the address book API can be called only after the above-mentioned creation of the address book API, application for API permissions, configuration of application data permissions, and setting of the IP whitelist are completed; after logging in to the open platform of the collaborative work platform, the collaborative work platform can be requested to authorize access to the data in the address book API to obtain the authorization code after authorization by the collaborative work platform; furthermore, the app_id, app_secret, and authorization code of the address book API can be used through the OAuth2.0 process to obtain the user_access_token interface; and then the user_access_token (i.e., the access credential returned after authorization is completed) can be used to call the address book API in the user's identity.
[0134] It should be noted that the access token user_access_token is obtained through the POST / authen / v1 / access_token interface, and a token automatic refresh mechanism is set. The obtained user_access_token has a validity period (for example, it should be used within 3 minutes after the authorization code is generated). It is necessary to regularly check the validity period of the user_access_token to ensure that a new token is obtained by refreshing this interface before it expires.
[0135] In this embodiment, by registering and logging in to the open platform of the collaborative work platform, creating an address book API on the open platform, obtaining the identifier and secret key of the address book API; applying for the permissions of the address book API, configuring the application data permissions of the address book API, and setting the whitelist of the address book API; using the identifier and secret key to call the address book API; thus realizing the safe and efficient call of the address book API of the collaborative work platform, laying a foundation for subsequent address book synchronization.
[0136] Based on the foregoing embodiment, a fourth embodiment of the method for synchronizing the address book according to the present invention is proposed. In this embodiment, step S10 may further include the following sub-steps S101 to S102:
[0137] Sub-step S101, performing hash processing on the user attributes of each user in the first address book to generate the first hash value of each user in the first address book; and performing hash processing on the user attributes of each user in the second address book to generate the second hash value of each user in the second address book.
[0138] Among them, the user attribute refers to the set of basic information and extended information of the user in the address book, which is used to describe various characteristics of enterprise employees. The basic attributes may include but are not limited to user ID, name, email, mobile phone number, gender, department, etc. The extended information may include but is not limited to job level, sequence, personnel type, custom fields, etc.
[0139] The first hash value, which is used to represent the hash value generated by using the user attributes of each user in the first address book.
[0140] The second hash value, which is used to represent the hash value generated by using the user attributes of each user in the second address book.
[0141] In a specific implementation, the user attributes of each user in the first address book (such as name, email, and mobile phone number, etc.) can be obtained first, and then the user attributes of each user are concatenated, and then a hash algorithm (such as MD5, SHA256, etc.) is used to process the concatenated user attributes to generate the first hash value of each user in the first address book; and the user attributes of each user in the second address book can be obtained, and then the user attributes of each user are concatenated, and then a hash algorithm (such as MD5, SHA256, etc.) is used to process the concatenated user attributes to generate the second hash value of each user in the second address book.
[0142] As an example, the user attributes of user A, such as name, email, and mobile phone number, can be obtained from the first address book; then the name, email, and mobile phone number of user A are concatenated, and then a hash algorithm is used to process the concatenated user attributes to generate the hash value of user A.
[0143] Sub-step S102, comparing the first hash value with the second hash value to determine the address book difference information between the first address book and the second address book.
[0144] In a specific implementation, after obtaining the first hash value of each user in the first address book and the second hash value of each user in the second address book, the first hash value and the second hash value can be compared bit by bit (through an exclusive OR operation). When a difference between the first hash value and the second hash value is detected, the difference between the first hash value and the second hash value (i.e., the address book difference information between the first address book and the second address book) is obtained. If there is a difference between the first hash value and the second hash value, it indicates that there are also differences (inconsistencies) in the department information and / or user information in the first address book and the second address book. If the first hash value and the second hash value are the same, it indicates that neither the first address book nor the second address book has been modified; thus, duplicate data can be quickly identified by comparing the hash values, avoiding duplicate submissions.
[0145] In this embodiment, the user attributes of each user in the first address book are hashed to generate the first hash value of each user in the first address book; and the user attributes of each user in the second address book are hashed to generate the second hash value of each user in the second address book; the first hash value is compared with the second hash value to determine the address book difference information between the first address book and the second address book; thus, by comparing the hash values, it is possible to quickly determine whether the first address book is the same as the second address book, further improving the data security.
[0146] Based on the same inventive concept, in the fifth embodiment of the present invention, there is also provided a system for synchronizing an address book corresponding to the method for synchronizing an address book in the foregoing embodiment. Since the principle of solving problems by the system in the fifth embodiment of the present invention is similar to the method for synchronizing an address book in the foregoing embodiment of the present invention, the implementation of the system can refer to the implementation of the method, and the repeated parts will not be described again.
[0147] Please refer to Figure 2 , the system for synchronizing an address book of the present invention may include:
[0148] An acquisition module 10, configured to, when it is monitored that the first address book of the collaborative office platform changes, obtain the first address book from the collaborative office platform, and obtain the second address book from the LDAP server, and compare the user information in the first address book with the user information in the second address book to determine the address book difference information between the first address book and the second address book;
[0149] A comparison module 20, configured to synchronously update the second address book according to the address book difference information, so that the first address book is consistent with the second address book.
[0150] In addition, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method for synchronizing an address book described above is implemented.
[0151] Figure 3 is a schematic block diagram of an electronic device provided by an embodiment of the present application. As Figure 3 shown, the electronic device includes: at least one processor 401, a memory 402, at least one network interface 403, and a user interface 405. Each component in the electronic device is coupled together through a bus system 404. It can be understood that the bus system 404 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 404 further includes a power bus, a control bus, and a status signal bus. However, for the sake of clear description, in Figure 3 all kinds of buses are labeled as the bus system.
[0152] Among them, the user interface 405 may include a display, a keyboard, a mouse, a trackball, a pointing gun, a key, a button, a touchpad, or a touch screen, etc.
[0153] It can be understood that the memory 402 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM, Static Random Access Memory), synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory). The memory described in the embodiments of the present invention is intended to include but not limited to these and any other suitable categories of memory.
[0154] The memory 402 in the embodiments of the present invention is used to store various categories of data to support the operation of the electronic device 400. Examples of these data include: any executable program for operating on the electronic device 400, such as the operating system 4021 and the application program 4022; the operating system 4021 contains various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application program 4022 can contain various application programs, such as a media player (Media Player), a browser (Browser), etc., for implementing various application services. The method for synchronizing the address book provided in the embodiments of the present invention can be included in the application program 4022.
[0155] The method disclosed in the embodiments of the present invention above can be applied to or implemented by a processor 401. The processor 401 may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above method can be completed by the integrated logic circuit in hardware or instructions in software form in the processor 401. The above-mentioned processor 401 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 401 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor 401 may be a microprocessor or any conventional processor, etc. Combining the steps of the method for synchronizing the address book provided in the embodiments of the present invention can be directly embodied as being executed and completed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, and this storage medium is located in the memory. The processor reads the information in the memory and combines its hardware to complete the steps of the foregoing method.
[0156] In an exemplary embodiment, the electronic device 400 may be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs) for executing the foregoing method.
[0157] In summary, when the present invention monitors that the first address book of the collaborative office platform has changed, by comparing the first address book of the collaborative work platform with the second address book of the LDAP server and synchronously updating the obtained address book difference information to the second address book, it realizes the automatic synchronization of the first address book in the collaborative office platform and the second address book in the LDAP server, further improving the synchronization rate and accuracy.
[0158] The above embodiments are only illustrative of the principles and effects of the present invention and are not used to limit the present invention. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or changes completed by those with ordinary knowledge in the technical field without departing from the spirit and technical idea disclosed by the present invention should still be covered by the claims of the present invention.
Claims
1. A method for synchronizing an address book, characterized in that, Applied to a synchronization server, the synchronization server is respectively connected to an LDAP server and a collaborative office platform, and the method includes: When it is monitored that the first address book of the collaborative office platform has changed, obtain the first address book from the collaborative office platform, obtain the second address book from the LDAP server, and compare the user information in the first address book with the user information in the second address book to determine the address book difference information between the first address book and the second address book; Synchronously update the second address book according to the address book difference information so that the first address book is consistent with the second address book.
2. The method according to claim 1, wherein Before the step of obtaining the first address book from the collaborative office platform and obtaining the second address book from the LDAP server when it is monitored that the first address book of the collaborative office platform has changed, it further includes: Establish an SSL / TLS connection with the LDAP server by using the pre-configured connection parameters in the synchronization server and authenticate the LDAP server.
3. The method according to claim 2, characterized in that, After the step of establishing an SSL / TLS connection with the LDAP server by using the pre-configured connection parameters in the synchronization server and authenticating the LDAP server, it further includes: Set a scheduled task to periodically poll and query the second address book of the LDAP server to obtain a query result; Extract the user attributes of the query result and convert them into data in a serialized format; Compare the data in the serialized format with the historical data of the second address book cached in the synchronization server to obtain the user difference information of the second address book.
4. The method according to claim 1, wherein Before the step of obtaining the first address book from the collaborative office platform and obtaining the second address book from the LDAP server when it is monitored that the first address book of the collaborative office platform has changed, it further includes: Register and log in to the open platform of the collaborative work platform, create an address book API on the open platform, and obtain the identifier and secret key of the address book API; Apply for the permission of the address book API, configure the application data permission of the address book API, and set the white list of the address book API; Call the address book API by using the identifier and the secret key.
5. The method according to claim 1, wherein The comparing the user information in the first address book with the user information in the second address book to determine the address book difference information between the first address book and the second address book includes: Perform a hash process on the user attributes of each user in the first address book to generate a first hash value for each user in the first address book; and perform a hash process on the user attributes of each user in the second address book to generate a second hash value for each user in the second address book; Compare the first hash value with the second hash value to determine the address book difference information between the first address book and the second address book.
6. The method according to claim 1, wherein After the step of synchronously updating the second address book according to the address book difference information so that the first address book is consistent with the second address book, it further includes: When the step of synchronously updating the second address book according to the address book difference information fails, after waiting for a preset time, the step of synchronously updating the second address book according to the address book difference information is executed again, and when the number of failures reaches the preset number, the failure information is recorded, and the address book difference information is saved.
7. The method according to claim 1, wherein After the step of synchronously updating the second address book according to the address book difference information, it further includes: Generating a synchronization log for synchronously updating the second address book according to the address book difference information, and using a change log to record the synchronization log of each synchronization update operation.
8. A system for synchronizing address books, characterized in that, Applied to a synchronization server, the synchronization server is respectively connected to an LDAP server and a collaborative office platform, and the system includes: A comparison module, configured to, when it is monitored that the first address book of the collaborative office platform has changed, obtain the first address book from the collaborative office platform, obtain the second address book from the LDAP server, compare the user information in the first address book with the user information in the second address book, and determine the address book difference information between the first address book and the second address book; A synchronization module, configured to synchronously update the second address book according to the address book difference information, so that the first address book is consistent with the second address book.
9. An electronic device, characterized in that, The electronic device includes: a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the electronic device executes the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, A program is stored on the computer-readable storage medium, and when the program runs, it is used to execute the steps of the method according to any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
Method and system for synchronizing data of enterprise address book and personal address book
CN101989989A
Address book automatic generation and query method, and phone
CN103888412A
Cloud synchronization method of network address book data
CN107528909A
Method and system for quickly docking third-party APP platform, and storage medium
CN111694495A
Optimizing a three tiered synchronization system by pre-fetching and pre-formatting synchronization data
US20060136518A1