1 /* SASL LDAP auxprop implementation
2 * Copyright (C) 2002 Howard Chu, hyc@symas.com
13 #include "plugin_common.h"
17 static char ldapdb[] = "ldapdb";
19 SASL_AUXPROP_PLUG_INIT( ldapdb )
21 typedef struct ldapctx {
22 const char *uri; /* URI of LDAP server */
23 const char *id; /* SASL authcid to bind as */
24 const char *pw; /* password for bind */
25 const char *mech; /* SASL mech */
28 typedef struct gluectx {
30 sasl_server_params_t *lp;
34 static int ldapdb_interact(LDAP *ld, unsigned flags __attribute__((unused)),
35 void *def, void *inter)
37 sasl_interact_t *in = inter;
41 for (;in->id != SASL_CB_LIST_END;in++)
46 case SASL_CB_GETREALM:
47 ldap_get_option(ld, LDAP_OPT_X_SASL_REALM, &p);
49 case SASL_CB_AUTHNAME:
62 in->result = gc->lp->utils->malloc(l+1);
64 return LDAP_NO_MEMORY;
65 strcpy((char *)in->result, p);
72 static void ldapdb_auxprop_lookup(void *glob_context,
73 sasl_server_params_t *sparams,
78 ldapctx *ctx = glob_context;
79 int ret, i, n, *aindx;
80 const struct propval *pr;
82 gluectx gc = { ctx, sparams, NULL };
83 struct berval *dn = NULL, **bvals;
84 LDAPMessage *msg, *res;
85 char **attrs = NULL, *authzid = NULL;
87 if(!ctx || !sparams || !user) return;
89 pr = sparams->utils->prop_get(sparams->propctx);
92 /* count how many attrs to fetch */
93 for(i = 0, n = 0; pr[i].name; i++) {
94 if(pr[i].name[0] == '*' && (flags & SASL_AUXPROP_AUTHZID))
96 if(pr[i].values && !(flags & SASL_AUXPROP_OVERRIDE))
100 /* nothing to do, bail out */
103 /* alloc an array of attr names for search, and index to the props */
104 attrs = sparams->utils->malloc((n+1)*sizeof(char *)*2);
107 aindx = (int *)(attrs + n + 1);
110 for (i=0, n=0; pr[i].name; i++) {
111 if(pr[i].name[0] == '*' && (flags & SASL_AUXPROP_AUTHZID))
113 if(pr[i].values && !(flags & SASL_AUXPROP_OVERRIDE))
115 attrs[n] = (char *)pr[i].name;
116 if (pr[i].name[0] == '*') attrs[n]++;
122 if(ldap_initialize(&ld, ctx->uri)) {
123 sparams->utils->free(attrs);
127 authzid = sparams->utils->malloc(ulen + sizeof("u:"));
128 if (!authzid) goto done;
129 strcpy(authzid, "u:");
130 strcpy(authzid+2, user);
134 ret = ldap_set_option(ld, LDAP_OPT_PROTOCOL_VERSION, &i);
136 ret = ldap_sasl_interactive_bind_s(ld, NULL, ctx->mech, NULL, NULL,
137 LDAP_SASL_QUIET, ldapdb_interact, &gc);
138 if (ret != LDAP_SUCCESS) goto done;
140 ret = ldap_extended_operation_s(ld, LDAP_EXOP_X_WHO_AM_I, NULL, NULL,
142 if (ret != LDAP_SUCCESS || !dn) goto done;
144 if (dn->bv_val && !strncmp(dn->bv_val, "dn:", 3))
145 ret = ldap_search_s(ld, dn->bv_val+3, LDAP_SCOPE_BASE, "(objectclass=*)",
149 if (ret != LDAP_SUCCESS) goto done;
151 for(msg=ldap_first_message(ld, res); msg; msg=ldap_next_message(ld, msg))
153 if (ldap_msgtype(msg) != LDAP_RES_SEARCH_ENTRY) continue;
156 bvals = ldap_get_values_len(ld, msg, attrs[i]);
157 if (!bvals) continue;
158 if (pr[aindx[i]].values)
159 sparams->utils->prop_erase(sparams->propctx, pr[aindx[i]].name);
160 sparams->utils->prop_set(sparams->propctx, pr[aindx[i]].name,
161 bvals[0]->bv_val, bvals[0]->bv_len);
168 if(authzid) sparams->utils->free(authzid);
169 if(attrs) sparams->utils->free(attrs);
170 if(ld) ldap_unbind(ld);
173 static void ldapdb_auxprop_free(void *glob_ctx, const sasl_utils_t *utils)
175 utils->free(glob_ctx);
178 static sasl_auxprop_plug_t ldapdb_auxprop_plugin = {
181 NULL, /* glob_context */
182 ldapdb_auxprop_free, /* auxprop_free */
183 ldapdb_auxprop_lookup, /* auxprop_lookup */
188 int ldapdb_auxprop_plug_init(const sasl_utils_t *utils,
191 sasl_auxprop_plug_t **plug,
192 const char *plugname __attribute__((unused)))
197 if(!out_version || !plug) return SASL_BADPARAM;
199 if(max_version < SASL_AUXPROP_PLUG_VERSION) return SASL_BADVERS;
201 utils->getopt(utils->getopt_context, ldapdb, "ldapdb_uri", &tmp.uri, NULL);
202 if(!tmp.uri) return SASL_BADPARAM;
204 utils->getopt(utils->getopt_context, ldapdb, "ldapdb_id", &tmp.id, NULL);
205 utils->getopt(utils->getopt_context, ldapdb, "ldapdb_pw", &tmp.pw, NULL);
206 utils->getopt(utils->getopt_context, ldapdb, "ldapdb_mech", &tmp.mech, NULL);
207 utils->getopt(utils->getopt_context, ldapdb, "ldapdb_rc", &s, NULL);
208 if(s && setenv("LDAPRC", s, 1)) return SASL_BADPARAM;
210 p = utils->malloc(sizeof(ldapctx));
211 if (!p) return SASL_NOMEM;
213 ldapdb_auxprop_plugin.glob_context = p;
215 *out_version = SASL_AUXPROP_PLUG_VERSION;
217 *plug = &ldapdb_auxprop_plugin;