3 * Copyright 1998-2002 The OpenLDAP Foundation, All Rights Reserved.
4 * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
7 * Copyright (c) 1996 Regents of the University of Michigan.
10 * LIBLDAP url.c -- LDAP URL (RFC 2255) related routines
12 * LDAP URLs look like this:
13 * ldap[is]://host:port[/[dn[?[attributes][?[scope][?[filter][?exts]]]]]]
16 * attributes is a comma separated list
17 * scope is one of these three strings: base one sub (default=base)
18 * filter is an string-represented filter as in RFC 2254
20 * e.g., ldap://host:port/dc=com?o,cn?base?(o=openldap)?extension
22 * We also tolerate URLs that look like: <ldapurl> and <URL:ldapurl>
29 #include <ac/stdlib.h>
31 #include <ac/socket.h>
32 #include <ac/string.h>
39 static const char* skip_url_prefix LDAP_P((
42 const char **scheme ));
44 int ldap_pvt_url_scheme2proto( const char *scheme )
48 if( scheme == NULL ) {
52 if( strcmp("ldap", scheme) == 0 ) {
53 return LDAP_PROTO_TCP;
56 if( strcmp("ldapi", scheme) == 0 ) {
57 return LDAP_PROTO_IPC;
60 if( strcmp("ldaps", scheme) == 0 ) {
61 return LDAP_PROTO_TCP;
63 #ifdef LDAP_CONNECTIONLESS
64 if( strcmp("cldap", scheme) == 0 ) {
65 return LDAP_PROTO_UDP;
73 ldap_pvt_url_scheme2tls( const char *scheme )
77 if( scheme == NULL ) {
81 return strcmp("ldaps", scheme) == 0;
85 ldap_is_ldap_url( LDAP_CONST char *url )
94 if( skip_url_prefix( url, &enclosed, &scheme ) == NULL ) {
102 ldap_is_ldaps_url( LDAP_CONST char *url )
111 if( skip_url_prefix( url, &enclosed, &scheme ) == NULL ) {
115 return strcmp(scheme, "ldaps") == 0;
119 ldap_is_ldapi_url( LDAP_CONST char *url )
128 if( skip_url_prefix( url, &enclosed, &scheme ) == NULL ) {
132 return strcmp(scheme, "ldapi") == 0;
135 #ifdef LDAP_CONNECTIONLESS
137 ldap_is_ldapc_url( LDAP_CONST char *url )
146 if( skip_url_prefix( url, &enclosed, &scheme ) == NULL ) {
150 return strcmp(scheme, "cldap") == 0;
158 const char **scheme )
161 * return non-zero if this looks like a LDAP URL; zero if not
162 * if non-zero returned, *urlp will be moved past "ldap://" part of URL
172 /* skip leading '<' (if any) */
180 /* skip leading "URL:" (if any) */
181 if ( strncasecmp( p, LDAP_URL_URLCOLON, LDAP_URL_URLCOLON_LEN ) == 0 ) {
182 p += LDAP_URL_URLCOLON_LEN;
185 /* check for "ldap://" prefix */
186 if ( strncasecmp( p, LDAP_URL_PREFIX, LDAP_URL_PREFIX_LEN ) == 0 ) {
187 /* skip over "ldap://" prefix and return success */
188 p += LDAP_URL_PREFIX_LEN;
193 /* check for "ldaps://" prefix */
194 if ( strncasecmp( p, LDAPS_URL_PREFIX, LDAPS_URL_PREFIX_LEN ) == 0 ) {
195 /* skip over "ldaps://" prefix and return success */
196 p += LDAPS_URL_PREFIX_LEN;
201 /* check for "ldapi://" prefix */
202 if ( strncasecmp( p, LDAPI_URL_PREFIX, LDAPI_URL_PREFIX_LEN ) == 0 ) {
203 /* skip over "ldapi://" prefix and return success */
204 p += LDAPI_URL_PREFIX_LEN;
209 #ifdef LDAP_CONNECTIONLESS
210 /* check for "cldap://" prefix */
211 if ( strncasecmp( p, LDAPC_URL_PREFIX, LDAPC_URL_PREFIX_LEN ) == 0 ) {
212 /* skip over "cldap://" prefix and return success */
213 p += LDAPC_URL_PREFIX_LEN;
223 static int str2scope( const char *p )
225 if ( strcasecmp( p, "one" ) == 0 ) {
226 return LDAP_SCOPE_ONELEVEL;
228 } else if ( strcasecmp( p, "onetree" ) == 0 ) {
229 return LDAP_SCOPE_ONELEVEL;
231 } else if ( strcasecmp( p, "base" ) == 0 ) {
232 return LDAP_SCOPE_BASE;
234 } else if ( strcasecmp( p, "sub" ) == 0 ) {
235 return LDAP_SCOPE_SUBTREE;
237 } else if ( strcasecmp( p, "subtree" ) == 0 ) {
238 return LDAP_SCOPE_SUBTREE;
244 static int hex_escape( char *buf, const char *s, int list )
248 static const char hex[] = "0123456789ABCDEF";
250 if( s == NULL ) return 0;
252 for( pos=0,i=0; s[i]; i++ ) {
278 escape = s[i] < 0x20 || 0x1f >= s[i];
283 buf[pos++] = hex[ (s[i] >> 4) & 0x0f ];
284 buf[pos++] = hex[ s[i] & 0x0f ];
294 static int hex_escape_args( char *buf, char **s )
299 if( s == NULL ) return 0;
302 for( i=0; s[i] != NULL; i++ ) {
306 pos += hex_escape( &buf[pos], s[i], 1 );
312 char * ldap_url_desc2str( LDAPURLDesc *u )
319 if( u == NULL ) return NULL;
322 for( i=0; u->lud_exts[i]; i++ ) {
323 len += strlen( u->lud_exts[i] ) + 1;
328 if( u->lud_filter ) {
329 len += strlen( u->lud_filter );
332 if ( len ) len++; /* ? */
334 switch( u->lud_scope ) {
335 case LDAP_SCOPE_ONELEVEL:
336 case LDAP_SCOPE_SUBTREE:
337 case LDAP_SCOPE_BASE:
338 len += sizeof("base");
343 if ( len ) len++; /* ? */
347 for( i=0; u->lud_attrs[i]; i++ ) {
348 len += strlen( u->lud_attrs[i] ) + 1;
351 } else if ( len ) len++; /* ? */
354 len += strlen( u->lud_dn ) + 1;
363 len+=strlen( u->lud_host );
366 len += strlen( u->lud_scheme ) + sizeof("://");
368 /* allocate enough to hex escape everything -- overkill */
369 s = LDAP_MALLOC( 3*len );
371 if( s == NULL ) return NULL;
374 sprintf( s, "%s://%s:%d%n", u->lud_scheme,
375 u->lud_host, u->lud_port, &sofar );
377 sprintf( s, "%s://%s%n", u->lud_scheme,
378 u->lud_host, &sofar );
381 if( sep < 1 ) goto done;
384 sofar += hex_escape( &s[sofar], u->lud_dn, 0 );
386 if( sep < 2 ) goto done;
389 sofar += hex_escape_args( &s[sofar], u->lud_attrs );
391 if( sep < 3 ) goto done;
394 switch( u->lud_scope ) {
395 case LDAP_SCOPE_BASE:
396 strcpy( &s[sofar], "base" );
397 sofar += sizeof("base") - 1;
399 case LDAP_SCOPE_ONELEVEL:
400 strcpy( &s[sofar], "one" );
401 sofar += sizeof("one") - 1;
403 case LDAP_SCOPE_SUBTREE:
404 strcpy( &s[sofar], "sub" );
405 sofar += sizeof("sub") - 1;
409 if( sep < 4 ) goto done;
412 sofar += hex_escape( &s[sofar], u->lud_filter, 0 );
414 if( sep < 5 ) goto done;
417 sofar += hex_escape_args( &s[sofar], u->lud_exts );
425 ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
428 * Pick apart the pieces of an LDAP URL.
434 const char *scheme = NULL;
438 if( url_in == NULL || ludpp == NULL ) {
439 return LDAP_URL_ERR_PARAM;
442 #ifndef LDAP_INT_IN_KERNEL
443 /* Global options may not be created yet
444 * We can't test if the global options are initialized
445 * because a call to LDAP_INT_GLOBAL_OPT() will try to allocate
446 * the options and cause infinite recursion
448 Debug( LDAP_DEBUG_TRACE, "ldap_url_parse_ext(%s)\n", url_in, 0, 0 );
451 *ludpp = NULL; /* pessimistic */
453 url_tmp = skip_url_prefix( url_in, &enclosed, &scheme );
455 if ( url_tmp == NULL ) {
456 return LDAP_URL_ERR_BADSCHEME;
461 /* make working copy of the remainder of the URL */
462 url = LDAP_STRDUP( url_tmp );
464 return LDAP_URL_ERR_MEM;
468 p = &url[strlen(url)-1];
472 return LDAP_URL_ERR_BADENCLOSURE;
478 /* allocate return struct */
479 ludp = (LDAPURLDesc *)LDAP_CALLOC( 1, sizeof( LDAPURLDesc ));
481 if ( ludp == NULL ) {
483 return LDAP_URL_ERR_MEM;
486 ludp->lud_next = NULL;
487 ludp->lud_host = NULL;
490 ludp->lud_attrs = NULL;
491 ludp->lud_filter = NULL;
492 ludp->lud_scope = LDAP_SCOPE_DEFAULT;
493 ludp->lud_filter = NULL;
494 ludp->lud_exts = NULL;
496 ludp->lud_scheme = LDAP_STRDUP( scheme );
498 if ( ludp->lud_scheme == NULL ) {
500 ldap_free_urldesc( ludp );
501 return LDAP_URL_ERR_MEM;
504 /* scan forward for '/' that marks end of hostport and begin. of dn */
505 p = strchr( url, '/' );
508 /* terminate hostport; point to start of dn */
512 /* IPv6 syntax with [ip address]:port */
514 r = strchr( url, ']' );
517 ldap_free_urldesc( ludp );
518 return LDAP_URL_ERR_BADURL;
521 q = strchr( r, ':' );
523 q = strchr( url, ':' );
528 ldap_pvt_hex_unescape( q );
532 ldap_free_urldesc( ludp );
533 return LDAP_URL_ERR_BADURL;
536 ludp->lud_port = atoi( q );
539 ldap_pvt_hex_unescape( url );
541 /* If [ip address]:port syntax, url is [ip and we skip the [ */
542 ludp->lud_host = LDAP_STRDUP( url + ( *url == '[' ) );
544 if( ludp->lud_host == NULL ) {
546 ldap_free_urldesc( ludp );
547 return LDAP_URL_ERR_MEM;
551 * Kludge. ldap://111.222.333.444:389??cn=abc,o=company
553 * On early Novell releases, search references/referrals were returned
554 * in this format, i.e., the dn was kind of in the scope position,
555 * but the required slash is missing. The whole thing is illegal syntax,
556 * but we need to account for it. Fortunately it can't be confused with
559 if( (p == NULL) && (q != NULL) && ((q = strchr( q, '?')) != NULL)) {
561 /* ? immediately followed by question */
566 ldap_pvt_hex_unescape( q );
567 ludp->lud_dn = LDAP_STRDUP( q );
569 ludp->lud_dn = LDAP_STRDUP( "" );
572 if( ludp->lud_dn == NULL ) {
574 ldap_free_urldesc( ludp );
575 return LDAP_URL_ERR_MEM;
583 return LDAP_URL_SUCCESS;
586 /* scan forward for '?' that may marks end of dn */
587 q = strchr( p, '?' );
590 /* terminate dn part */
596 ldap_pvt_hex_unescape( p );
597 ludp->lud_dn = LDAP_STRDUP( p );
599 ludp->lud_dn = LDAP_STRDUP( "" );
602 if( ludp->lud_dn == NULL ) {
604 ldap_free_urldesc( ludp );
605 return LDAP_URL_ERR_MEM;
612 return LDAP_URL_SUCCESS;
615 /* scan forward for '?' that may marks end of attributes */
617 q = strchr( p, '?' );
620 /* terminate attributes part */
625 /* parse attributes */
626 ldap_pvt_hex_unescape( p );
627 ludp->lud_attrs = ldap_str2charray( p, "," );
629 if( ludp->lud_attrs == NULL ) {
631 ldap_free_urldesc( ludp );
632 return LDAP_URL_ERR_BADATTRS;
640 return LDAP_URL_SUCCESS;
643 /* scan forward for '?' that may marks end of scope */
645 q = strchr( p, '?' );
648 /* terminate the scope part */
653 /* parse the scope */
654 ldap_pvt_hex_unescape( p );
655 ludp->lud_scope = str2scope( p );
657 if( ludp->lud_scope == -1 ) {
659 ldap_free_urldesc( ludp );
660 return LDAP_URL_ERR_BADSCOPE;
668 return LDAP_URL_SUCCESS;
671 /* scan forward for '?' that may marks end of filter */
673 q = strchr( p, '?' );
676 /* terminate the filter part */
681 /* parse the filter */
682 ldap_pvt_hex_unescape( p );
687 ldap_free_urldesc( ludp );
688 return LDAP_URL_ERR_BADFILTER;
691 LDAP_FREE( ludp->lud_filter );
692 ludp->lud_filter = LDAP_STRDUP( p );
694 if( ludp->lud_filter == NULL ) {
696 ldap_free_urldesc( ludp );
697 return LDAP_URL_ERR_MEM;
705 return LDAP_URL_SUCCESS;
708 /* scan forward for '?' that may marks end of extensions */
710 q = strchr( p, '?' );
715 ldap_free_urldesc( ludp );
716 return LDAP_URL_ERR_BADURL;
719 /* parse the extensions */
720 ludp->lud_exts = ldap_str2charray( p, "," );
722 if( ludp->lud_exts == NULL ) {
724 ldap_free_urldesc( ludp );
725 return LDAP_URL_ERR_BADEXTS;
728 for( i=0; ludp->lud_exts[i] != NULL; i++ ) {
729 ldap_pvt_hex_unescape( ludp->lud_exts[i] );
731 if( *ludp->lud_exts[i] == '!' ) {
732 /* count the number of critical extensions */
733 ludp->lud_crit_exts++;
738 /* must have 1 or more */
740 ldap_free_urldesc( ludp );
741 return LDAP_URL_ERR_BADEXTS;
747 return LDAP_URL_SUCCESS;
751 ldap_url_parse( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
753 int rc = ldap_url_parse_ext( url_in, ludpp );
755 if( rc != LDAP_URL_SUCCESS ) {
759 if ((*ludpp)->lud_scope == LDAP_SCOPE_DEFAULT) {
760 (*ludpp)->lud_scope = LDAP_SCOPE_BASE;
763 if ((*ludpp)->lud_host != NULL && *(*ludpp)->lud_host == '\0') {
764 LDAP_FREE( (*ludpp)->lud_host );
765 (*ludpp)->lud_host = NULL;
768 if ((*ludpp)->lud_port == 0) {
769 if( strcmp((*ludpp)->lud_scheme, "ldap") == 0 ) {
770 (*ludpp)->lud_port = LDAP_PORT;
771 #ifdef LDAP_CONNECTIONLESS
772 } else if( strcmp((*ludpp)->lud_scheme, "cldap") == 0 ) {
773 (*ludpp)->lud_port = LDAP_PORT;
775 } else if( strcmp((*ludpp)->lud_scheme, "ldaps") == 0 ) {
776 (*ludpp)->lud_port = LDAPS_PORT;
784 ldap_url_dup ( LDAPURLDesc *ludp )
788 if ( ludp == NULL ) {
792 dest = LDAP_MALLOC( sizeof(LDAPURLDesc) );
797 dest->lud_scheme = NULL;
798 dest->lud_host = NULL;
800 dest->lud_filter = NULL;
801 dest->lud_attrs = NULL;
802 dest->lud_exts = NULL;
803 dest->lud_next = NULL;
805 if ( ludp->lud_scheme != NULL ) {
806 dest->lud_scheme = LDAP_STRDUP( ludp->lud_scheme );
807 if (dest->lud_scheme == NULL) {
808 ldap_free_urldesc(dest);
813 if ( ludp->lud_host != NULL ) {
814 dest->lud_host = LDAP_STRDUP( ludp->lud_host );
815 if (dest->lud_host == NULL) {
816 ldap_free_urldesc(dest);
821 if ( ludp->lud_dn != NULL ) {
822 dest->lud_dn = LDAP_STRDUP( ludp->lud_dn );
823 if (dest->lud_dn == NULL) {
824 ldap_free_urldesc(dest);
829 if ( ludp->lud_filter != NULL ) {
830 dest->lud_filter = LDAP_STRDUP( ludp->lud_filter );
831 if (dest->lud_filter == NULL) {
832 ldap_free_urldesc(dest);
837 if ( ludp->lud_attrs != NULL ) {
838 dest->lud_attrs = ldap_charray_dup( ludp->lud_attrs );
839 if (dest->lud_attrs == NULL) {
840 ldap_free_urldesc(dest);
845 if ( ludp->lud_exts != NULL ) {
846 dest->lud_exts = ldap_charray_dup( ludp->lud_exts );
847 if (dest->lud_exts == NULL) {
848 ldap_free_urldesc(dest);
857 ldap_url_duplist (LDAPURLDesc *ludlist)
859 LDAPURLDesc *dest, *tail, *ludp, *newludp;
863 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
864 newludp = ldap_url_dup(ludp);
865 if (newludp == NULL) {
866 ldap_free_urllist(dest);
872 tail->lud_next = newludp;
879 ldap_url_parselist (LDAPURLDesc **ludlist, const char *url )
888 return LDAP_PARAM_ERROR;
890 urls = ldap_str2charray((char *)url, ", ");
892 return LDAP_NO_MEMORY;
894 /* count the URLs... */
895 for (i = 0; urls[i] != NULL; i++) ;
896 /* ...and put them in the "stack" backward */
898 rc = ldap_url_parse( urls[i], &ludp );
900 ldap_charray_free(urls);
901 ldap_free_urllist(*ludlist);
905 ludp->lud_next = *ludlist;
908 ldap_charray_free(urls);
914 LDAPURLDesc **ludlist,
925 return LDAP_PARAM_ERROR;
927 specs = ldap_str2charray((char *)hosts, ", ");
929 return LDAP_NO_MEMORY;
931 /* count the URLs... */
932 for (i = 0; specs[i] != NULL; i++) /* EMPTY */;
934 /* ...and put them in the "stack" backward */
936 ludp = LDAP_CALLOC( 1, sizeof(LDAPURLDesc) );
938 ldap_charray_free(specs);
939 ldap_free_urllist(*ludlist);
941 return LDAP_NO_MEMORY;
943 ludp->lud_port = port;
944 ludp->lud_host = specs[i];
946 p = strchr(ludp->lud_host, ':');
948 /* more than one :, IPv6 address */
949 if ( strchr(p+1, ':') != NULL ) {
950 /* allow [address] and [address]:port */
951 if ( *ludp->lud_host == '[' ) {
952 p = LDAP_STRDUP(ludp->lud_host+1);
953 /* copied, make sure we free source later */
954 specs[i] = ludp->lud_host;
956 p = strchr( ludp->lud_host, ']' );
958 return LDAP_PARAM_ERROR;
962 return LDAP_PARAM_ERROR;
971 ldap_pvt_hex_unescape(p);
972 ludp->lud_port = atoi(p);
975 ldap_pvt_hex_unescape(ludp->lud_host);
976 ludp->lud_scheme = LDAP_STRDUP("ldap");
977 ludp->lud_next = *ludlist;
981 /* this should be an array of NULLs now */
982 /* except entries starting with [ */
983 ldap_charray_free(specs);
988 ldap_url_list2hosts (LDAPURLDesc *ludlist)
992 char *s, *p, buf[32]; /* big enough to hold a long decimal # (overkill) */
997 /* figure out how big the string is */
998 size = 1; /* nul-term */
999 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
1000 size += strlen(ludp->lud_host) + 1; /* host and space */
1001 if (strchr(ludp->lud_host, ':')) /* will add [ ] below */
1003 if (ludp->lud_port != 0)
1004 size += sprintf(buf, ":%d", ludp->lud_port);
1006 s = LDAP_MALLOC(size);
1011 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
1012 if (strchr(ludp->lud_host, ':')) {
1013 p += sprintf(p, "[%s]", ludp->lud_host);
1015 strcpy(p, ludp->lud_host);
1016 p += strlen(ludp->lud_host);
1018 if (ludp->lud_port != 0)
1019 p += sprintf(p, ":%d", ludp->lud_port);
1023 p--; /* nuke that extra space */
1030 LDAPURLDesc *ludlist )
1034 char *s, *p, buf[32]; /* big enough to hold a long decimal # (overkill) */
1036 if (ludlist == NULL)
1039 /* figure out how big the string is */
1040 size = 1; /* nul-term */
1041 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
1042 size += strlen(ludp->lud_scheme) + strlen(ludp->lud_host);
1043 if (strchr(ludp->lud_host, ':')) /* will add [ ] below */
1045 size += sizeof(":/// ");
1047 if (ludp->lud_port != 0) {
1048 size += sprintf(buf, ":%d", ludp->lud_port);
1052 s = LDAP_MALLOC(size);
1058 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
1060 strchr(ludp->lud_host, ':') ? "%s://[%s]" : "%s://%s",
1061 ludp->lud_scheme, ludp->lud_host);
1062 if (ludp->lud_port != 0)
1063 p += sprintf(p, ":%d", ludp->lud_port);
1068 p--; /* nuke that extra space */
1074 ldap_free_urllist( LDAPURLDesc *ludlist )
1076 LDAPURLDesc *ludp, *next;
1078 for (ludp = ludlist; ludp != NULL; ludp = next) {
1079 next = ludp->lud_next;
1080 ldap_free_urldesc(ludp);
1085 ldap_free_urldesc( LDAPURLDesc *ludp )
1087 if ( ludp == NULL ) {
1091 if ( ludp->lud_scheme != NULL ) {
1092 LDAP_FREE( ludp->lud_scheme );
1095 if ( ludp->lud_host != NULL ) {
1096 LDAP_FREE( ludp->lud_host );
1099 if ( ludp->lud_dn != NULL ) {
1100 LDAP_FREE( ludp->lud_dn );
1103 if ( ludp->lud_filter != NULL ) {
1104 LDAP_FREE( ludp->lud_filter);
1107 if ( ludp->lud_attrs != NULL ) {
1108 LDAP_VFREE( ludp->lud_attrs );
1111 if ( ludp->lud_exts != NULL ) {
1112 LDAP_VFREE( ludp->lud_exts );
1119 ldap_int_unhex( int c )
1121 return( c >= '0' && c <= '9' ? c - '0'
1122 : c >= 'A' && c <= 'F' ? c - 'A' + 10
1127 ldap_pvt_hex_unescape( char *s )
1130 * Remove URL hex escapes from s... done in place. The basic concept for
1131 * this routine is borrowed from the WWW library HTUnEscape() routine.
1135 for ( p = s; *s != '\0'; ++s ) {
1137 if ( *++s != '\0' ) {
1138 *p = ldap_int_unhex( *s ) << 4;
1140 if ( *++s != '\0' ) {
1141 *p++ += ldap_int_unhex( *s );