3 * Copyright 1998-2000 The OpenLDAP Foundation, All Rights Reserved.
4 * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
7 * Copyright (c) 1996 Regents of the University of Michigan.
10 * LIBLDAP url.c -- LDAP URL (RFC 2255) related routines
12 * LDAP URLs look like this:
13 * ldap[is]://host:port[/[dn[?[attributes][?[scope][?[filter][?exts]]]]]]
16 * attributes is a comma separated list
17 * scope is one of these three strings: base one sub (default=base)
18 * filter is an string-represented filter as in RFC 2254
20 * e.g., ldap://host:port/dc=com?o,cn?base?o=openldap?extension
22 * We also tolerate URLs that look like: <ldapurl> and <URL:ldapurl>
29 #include <ac/stdlib.h>
31 #include <ac/socket.h>
32 #include <ac/string.h>
39 static const char* skip_url_prefix LDAP_P((
42 const char **scheme ));
44 int ldap_pvt_url_scheme2proto( const char *scheme )
48 if( scheme == NULL ) {
52 if( strcmp("ldap", scheme) == 0 ) {
53 return LDAP_PROTO_TCP;
56 if( strcmp("ldapi", scheme) == 0 ) {
57 return LDAP_PROTO_IPC;
60 if( strcmp("ldaps", scheme) == 0 ) {
61 return LDAP_PROTO_TCP;
67 int ldap_pvt_url_scheme2tls( const char *scheme )
71 if( scheme == NULL ) {
75 return strcmp("ldaps", scheme) == 0;
79 ldap_is_ldap_url( LDAP_CONST char *url )
88 if( skip_url_prefix( url, &enclosed, &scheme ) == NULL ) {
96 ldap_is_ldaps_url( LDAP_CONST char *url )
105 if( skip_url_prefix( url, &enclosed, &scheme ) == NULL ) {
109 return strcmp(scheme, "ldaps") == 0;
113 ldap_is_ldapi_url( LDAP_CONST char *url )
122 if( skip_url_prefix( url, &enclosed, &scheme ) == NULL ) {
126 return strcmp(scheme, "ldapi") == 0;
133 const char **scheme )
136 * return non-zero if this looks like a LDAP URL; zero if not
137 * if non-zero returned, *urlp will be moved past "ldap://" part of URL
147 /* skip leading '<' (if any) */
155 /* skip leading "URL:" (if any) */
156 if ( strncasecmp( p, LDAP_URL_URLCOLON, LDAP_URL_URLCOLON_LEN ) == 0 ) {
157 p += LDAP_URL_URLCOLON_LEN;
160 /* check for "ldap://" prefix */
161 if ( strncasecmp( p, LDAP_URL_PREFIX, LDAP_URL_PREFIX_LEN ) == 0 ) {
162 /* skip over "ldap://" prefix and return success */
163 p += LDAP_URL_PREFIX_LEN;
168 /* check for "ldaps://" prefix */
169 if ( strncasecmp( p, LDAPS_URL_PREFIX, LDAPS_URL_PREFIX_LEN ) == 0 ) {
170 /* skip over "ldaps://" prefix and return success */
171 p += LDAPS_URL_PREFIX_LEN;
176 /* check for "ldapi://" prefix */
177 if ( strncasecmp( p, LDAPI_URL_PREFIX, LDAPI_URL_PREFIX_LEN ) == 0 ) {
178 /* skip over "ldapi://" prefix and return success */
179 p += LDAPI_URL_PREFIX_LEN;
188 static int str2scope( const char *p )
190 if ( strcasecmp( p, "one" ) == 0 ) {
191 return LDAP_SCOPE_ONELEVEL;
193 } else if ( strcasecmp( p, "onetree" ) == 0 ) {
194 return LDAP_SCOPE_ONELEVEL;
196 } else if ( strcasecmp( p, "base" ) == 0 ) {
197 return LDAP_SCOPE_BASE;
199 } else if ( strcasecmp( p, "sub" ) == 0 ) {
200 return LDAP_SCOPE_SUBTREE;
202 } else if ( strcasecmp( p, "subtree" ) == 0 ) {
203 return LDAP_SCOPE_SUBTREE;
211 ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
214 * Pick apart the pieces of an LDAP URL.
220 const char *scheme = NULL;
224 if( url_in == NULL || ludpp == NULL ) {
225 return LDAP_URL_ERR_PARAM;
228 #ifndef LDAP_INT_IN_KERNEL
229 /* Global options may not be created yet
230 * We can't test if the global options are initialized
231 * because a call to LDAP_INT_GLOBAL_OPT() will try to allocate
232 * the options and cause infinite recursion
234 Debug( LDAP_DEBUG_TRACE, "ldap_url_parse_ext(%s)\n", url_in, 0, 0 );
237 *ludpp = NULL; /* pessimistic */
239 url_tmp = skip_url_prefix( url_in, &enclosed, &scheme );
241 if ( url_tmp == NULL ) {
242 return LDAP_URL_ERR_BADSCHEME;
247 /* make working copy of the remainder of the URL */
248 url = LDAP_STRDUP( url_tmp );
250 return LDAP_URL_ERR_MEM;
254 p = &url[strlen(url)-1];
258 return LDAP_URL_ERR_BADENCLOSURE;
264 /* allocate return struct */
265 ludp = (LDAPURLDesc *)LDAP_CALLOC( 1, sizeof( LDAPURLDesc ));
267 if ( ludp == NULL ) {
269 return LDAP_URL_ERR_MEM;
272 ludp->lud_next = NULL;
273 ludp->lud_host = NULL;
274 ludp->lud_port = LDAP_PORT;
276 ludp->lud_attrs = NULL;
277 ludp->lud_filter = NULL;
278 ludp->lud_scope = LDAP_SCOPE_DEFAULT;
279 ludp->lud_filter = NULL;
280 ludp->lud_exts = NULL;
282 ludp->lud_scheme = LDAP_STRDUP( scheme );
284 if ( ludp->lud_scheme == NULL ) {
286 ldap_free_urldesc( ludp );
287 return LDAP_URL_ERR_MEM;
290 if( strcasecmp( ludp->lud_scheme, "ldaps" ) == 0 ) {
291 ludp->lud_port = LDAPS_PORT;
294 /* scan forward for '/' that marks end of hostport and begin. of dn */
295 p = strchr( url, '/' );
298 /* terminate hostport; point to start of dn */
302 /* IPv6 syntax with [ip address]:port */
304 r = strchr( url, ']' );
307 ldap_free_urldesc( ludp );
308 return LDAP_URL_ERR_BADURL;
311 q = strchr( r, ':' );
313 q = strchr( url, ':' );
318 ldap_pvt_hex_unescape( q );
322 ldap_free_urldesc( ludp );
323 return LDAP_URL_ERR_BADURL;
326 ludp->lud_port = atoi( q );
329 ldap_pvt_hex_unescape( url );
331 /* If [ip address]:port syntax, url is [ip and we skip the [ */
332 ludp->lud_host = LDAP_STRDUP( url + ( *url == '[' ) );
334 if( ludp->lud_host == NULL ) {
336 ldap_free_urldesc( ludp );
337 return LDAP_URL_ERR_MEM;
341 * Kludge. ldap://111.222.333.444:389??cn=abc,o=company
343 * On early Novell releases, search references/referrals were returned
344 * in this format, i.e., the dn was kind of in the scope position,
345 * but the required slash is missing. The whole thing is illegal syntax,
346 * but we need to account for it. Fortunately it can't be confused with
349 if( (p == NULL) && (q != NULL) && ((q = strchr( q, '?')) != NULL)) {
351 /* ? immediately followed by question */
356 ldap_pvt_hex_unescape( q );
357 ludp->lud_dn = LDAP_STRDUP( q );
359 ludp->lud_dn = LDAP_STRDUP( "" );
362 if( ludp->lud_dn == NULL ) {
364 ldap_free_urldesc( ludp );
365 return LDAP_URL_ERR_MEM;
373 return LDAP_URL_SUCCESS;
376 /* scan forward for '?' that may marks end of dn */
377 q = strchr( p, '?' );
380 /* terminate dn part */
386 ldap_pvt_hex_unescape( p );
387 ludp->lud_dn = LDAP_STRDUP( p );
389 ludp->lud_dn = LDAP_STRDUP( "" );
392 if( ludp->lud_dn == NULL ) {
394 ldap_free_urldesc( ludp );
395 return LDAP_URL_ERR_MEM;
402 return LDAP_URL_SUCCESS;
405 /* scan forward for '?' that may marks end of attributes */
407 q = strchr( p, '?' );
410 /* terminate attributes part */
415 /* parse attributes */
416 ldap_pvt_hex_unescape( p );
417 ludp->lud_attrs = ldap_str2charray( p, "," );
419 if( ludp->lud_attrs == NULL ) {
421 ldap_free_urldesc( ludp );
422 return LDAP_URL_ERR_BADATTRS;
430 return LDAP_URL_SUCCESS;
433 /* scan forward for '?' that may marks end of scope */
435 q = strchr( p, '?' );
438 /* terminate the scope part */
443 /* parse the scope */
444 ldap_pvt_hex_unescape( p );
445 ludp->lud_scope = str2scope( p );
447 if( ludp->lud_scope == -1 ) {
449 ldap_free_urldesc( ludp );
450 return LDAP_URL_ERR_BADSCOPE;
458 return LDAP_URL_SUCCESS;
461 /* scan forward for '?' that may marks end of filter */
463 q = strchr( p, '?' );
466 /* terminate the filter part */
471 /* parse the filter */
472 ldap_pvt_hex_unescape( p );
477 ldap_free_urldesc( ludp );
478 return LDAP_URL_ERR_BADFILTER;
481 LDAP_FREE( ludp->lud_filter );
482 ludp->lud_filter = LDAP_STRDUP( p );
484 if( ludp->lud_filter == NULL ) {
486 ldap_free_urldesc( ludp );
487 return LDAP_URL_ERR_MEM;
495 return LDAP_URL_SUCCESS;
498 /* scan forward for '?' that may marks end of extensions */
500 q = strchr( p, '?' );
505 ldap_free_urldesc( ludp );
506 return LDAP_URL_ERR_BADURL;
509 /* parse the extensions */
510 ludp->lud_exts = ldap_str2charray( p, "," );
512 if( ludp->lud_exts == NULL ) {
514 ldap_free_urldesc( ludp );
515 return LDAP_URL_ERR_BADEXTS;
518 for( i=0; ludp->lud_exts[i] != NULL; i++ ) {
519 ldap_pvt_hex_unescape( ludp->lud_exts[i] );
521 if( *ludp->lud_exts[i] == '!' ) {
522 /* count the number of critical extensions */
523 ludp->lud_crit_exts++;
528 /* must have 1 or more */
530 ldap_free_urldesc( ludp );
531 return LDAP_URL_ERR_BADEXTS;
537 return LDAP_URL_SUCCESS;
541 ldap_url_parse( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
543 int rc = ldap_url_parse_ext( url_in, ludpp );
545 if( rc != LDAP_URL_SUCCESS ) {
549 if ((*ludpp)->lud_scope == LDAP_SCOPE_DEFAULT) {
550 (*ludpp)->lud_scope = LDAP_SCOPE_BASE;
553 if ((*ludpp)->lud_host != NULL && *(*ludpp)->lud_host == '\0') {
554 LDAP_FREE( (*ludpp)->lud_host );
555 (*ludpp)->lud_host = NULL;
562 ldap_url_dup ( LDAPURLDesc *ludp )
566 if ( ludp == NULL ) {
570 dest = LDAP_MALLOC( sizeof(LDAPURLDesc) );
575 dest->lud_scheme = NULL;
576 dest->lud_host = NULL;
578 dest->lud_filter = NULL;
579 dest->lud_attrs = NULL;
580 dest->lud_exts = NULL;
581 dest->lud_next = NULL;
583 if ( ludp->lud_scheme != NULL ) {
584 dest->lud_scheme = LDAP_STRDUP( ludp->lud_scheme );
585 if (dest->lud_scheme == NULL) {
586 ldap_free_urldesc(dest);
591 if ( ludp->lud_host != NULL ) {
592 dest->lud_host = LDAP_STRDUP( ludp->lud_host );
593 if (dest->lud_host == NULL) {
594 ldap_free_urldesc(dest);
599 if ( ludp->lud_dn != NULL ) {
600 dest->lud_dn = LDAP_STRDUP( ludp->lud_dn );
601 if (dest->lud_dn == NULL) {
602 ldap_free_urldesc(dest);
607 if ( ludp->lud_filter != NULL ) {
608 dest->lud_filter = LDAP_STRDUP( ludp->lud_filter );
609 if (dest->lud_filter == NULL) {
610 ldap_free_urldesc(dest);
615 if ( ludp->lud_attrs != NULL ) {
616 dest->lud_attrs = ldap_charray_dup( ludp->lud_attrs );
617 if (dest->lud_attrs == NULL) {
618 ldap_free_urldesc(dest);
623 if ( ludp->lud_exts != NULL ) {
624 dest->lud_exts = ldap_charray_dup( ludp->lud_exts );
625 if (dest->lud_exts == NULL) {
626 ldap_free_urldesc(dest);
635 ldap_url_duplist (LDAPURLDesc *ludlist)
637 LDAPURLDesc *dest, *tail, *ludp, *newludp;
641 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
642 newludp = ldap_url_dup(ludp);
643 if (newludp == NULL) {
644 ldap_free_urllist(dest);
650 tail->lud_next = newludp;
657 ldap_url_parselist (LDAPURLDesc **ludlist, const char *url )
666 return LDAP_PARAM_ERROR;
668 urls = ldap_str2charray((char *)url, ", ");
670 return LDAP_NO_MEMORY;
672 /* count the URLs... */
673 for (i = 0; urls[i] != NULL; i++) ;
674 /* ...and put them in the "stack" backward */
676 rc = ldap_url_parse( urls[i], &ludp );
678 ldap_charray_free(urls);
679 ldap_free_urllist(*ludlist);
683 ludp->lud_next = *ludlist;
686 ldap_charray_free(urls);
692 LDAPURLDesc **ludlist,
703 return LDAP_PARAM_ERROR;
705 specs = ldap_str2charray((char *)hosts, ", ");
707 return LDAP_NO_MEMORY;
709 /* count the URLs... */
710 for (i = 0; specs[i] != NULL; i++) /* EMPTY */;
712 /* ...and put them in the "stack" backward */
714 ludp = LDAP_CALLOC( 1, sizeof(LDAPURLDesc) );
716 ldap_charray_free(specs);
717 ldap_free_urllist(*ludlist);
719 return LDAP_NO_MEMORY;
721 ludp->lud_port = port;
722 ludp->lud_host = specs[i];
724 p = strchr(ludp->lud_host, ':');
726 /* more than one :, IPv6 address */
727 if ( strchr(p+1, ':') != NULL ) {
728 /* allow [address] and [address]:port */
729 if ( *ludp->lud_host == '[' ) {
730 p = LDAP_STRDUP(ludp->lud_host+1);
731 /* copied, make sure we free source later */
732 specs[i] = ludp->lud_host;
734 p = strchr( ludp->lud_host, ']' );
736 return LDAP_PARAM_ERROR;
740 return LDAP_PARAM_ERROR;
749 ldap_pvt_hex_unescape(p);
750 ludp->lud_port = atoi(p);
753 ldap_pvt_hex_unescape(ludp->lud_host);
754 ludp->lud_scheme = LDAP_STRDUP("ldap");
755 ludp->lud_next = *ludlist;
759 /* this should be an array of NULLs now */
760 /* except entries starting with [ */
761 ldap_charray_free(specs);
766 ldap_url_list2hosts (LDAPURLDesc *ludlist)
770 char *s, *p, buf[32]; /* big enough to hold a long decimal # (overkill) */
775 /* figure out how big the string is */
776 size = 1; /* nul-term */
777 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
778 size += strlen(ludp->lud_host) + 1; /* host and space */
779 if (strchr(ludp->lud_host, ':')) /* will add [ ] below */
781 if (ludp->lud_port != 0)
782 size += sprintf(buf, ":%d", ludp->lud_port);
784 s = LDAP_MALLOC(size);
789 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
790 if (strchr(ludp->lud_host, ':')) {
791 p += sprintf(p, "[%s]", ludp->lud_host);
793 strcpy(p, ludp->lud_host);
794 p += strlen(ludp->lud_host);
796 if (ludp->lud_port != 0)
797 p += sprintf(p, ":%d", ludp->lud_port);
801 p--; /* nuke that extra space */
808 LDAPURLDesc *ludlist )
812 char *s, *p, buf[32]; /* big enough to hold a long decimal # (overkill) */
817 /* figure out how big the string is */
818 size = 1; /* nul-term */
819 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
820 size += strlen(ludp->lud_scheme) + strlen(ludp->lud_host);
821 if (strchr(ludp->lud_host, ':')) /* will add [ ] below */
823 size += sizeof(":/// ");
825 if (ludp->lud_port != 0) {
826 size += sprintf(buf, ":%d", ludp->lud_port);
830 s = LDAP_MALLOC(size);
836 for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
838 strchr(ludp->lud_host, ':') ? "%s://[%s]" : "%s://%s",
839 ludp->lud_scheme, ludp->lud_host);
840 if (ludp->lud_port != 0)
841 p += sprintf(p, ":%d", ludp->lud_port);
846 p--; /* nuke that extra space */
852 ldap_free_urllist( LDAPURLDesc *ludlist )
854 LDAPURLDesc *ludp, *next;
856 for (ludp = ludlist; ludp != NULL; ludp = next) {
857 next = ludp->lud_next;
858 ldap_free_urldesc(ludp);
863 ldap_free_urldesc( LDAPURLDesc *ludp )
865 if ( ludp == NULL ) {
869 if ( ludp->lud_scheme != NULL ) {
870 LDAP_FREE( ludp->lud_scheme );
873 if ( ludp->lud_host != NULL ) {
874 LDAP_FREE( ludp->lud_host );
877 if ( ludp->lud_dn != NULL ) {
878 LDAP_FREE( ludp->lud_dn );
881 if ( ludp->lud_filter != NULL ) {
882 LDAP_FREE( ludp->lud_filter);
885 if ( ludp->lud_attrs != NULL ) {
886 LDAP_VFREE( ludp->lud_attrs );
889 if ( ludp->lud_exts != NULL ) {
890 LDAP_VFREE( ludp->lud_exts );
899 ldap_url_search( LDAP *ld, LDAP_CONST char *url, int attrsonly )
906 assert( ld != NULL );
907 assert( LDAP_VALID( ld ) );
909 if ( ldap_url_parse( url, &ludp ) != 0 ) {
910 ld->ld_errno = LDAP_PARAM_ERROR;
914 if( ludp->lud_crit_exts ) {
915 /* we don't support any extension (yet) */
916 ld->ld_errno = LDAP_NOT_SUPPORTED;
920 ber = ldap_build_search_req( ld, ludp->lud_dn, ludp->lud_scope,
921 ludp->lud_filter, ludp->lud_attrs, attrsonly, NULL, NULL,
927 bind.ri_request = LDAP_REQ_SEARCH;
928 bind.ri_msgid = ld->ld_msgid;
929 bind.ri_url = (char *)url;
930 err = ldap_send_server_request(
931 ld, ber, ld->ld_msgid, NULL,
935 ldap_free_urldesc( ludp );
941 ldap_url_search_st( LDAP *ld, LDAP_CONST char *url, int attrsonly,
942 struct timeval *timeout, LDAPMessage **res )
946 if (( msgid = ldap_url_search( ld, url, attrsonly )) == -1 ) {
947 return( ld->ld_errno );
950 if ( ldap_result( ld, msgid, 1, timeout, res ) == -1 ) {
951 return( ld->ld_errno );
954 if ( ld->ld_errno == LDAP_TIMEOUT ) {
955 (void) ldap_abandon( ld, msgid );
956 ld->ld_errno = LDAP_TIMEOUT;
957 return( ld->ld_errno );
960 return( ldap_result2error( ld, *res, 0 ));
966 LDAP *ld, LDAP_CONST char *url, int attrsonly, LDAPMessage **res )
970 if (( msgid = ldap_url_search( ld, url, attrsonly )) == -1 ) {
971 return( ld->ld_errno );
974 if ( ldap_result( ld, msgid, 1, (struct timeval *)NULL, res ) == -1 ) {
975 return( ld->ld_errno );
978 return( ldap_result2error( ld, *res, 0 ));
983 ldap_pvt_hex_unescape( char *s )
986 * Remove URL hex escapes from s... done in place. The basic concept for
987 * this routine is borrowed from the WWW library HTUnEscape() routine.
991 for ( p = s; *s != '\0'; ++s ) {
993 if ( *++s != '\0' ) {
994 *p = ldap_pvt_unhex( *s ) << 4;
996 if ( *++s != '\0' ) {
997 *p++ += ldap_pvt_unhex( *s );
1009 ldap_pvt_unhex( int c )
1011 return( c >= '0' && c <= '9' ? c - '0'
1012 : c >= 'A' && c <= 'F' ? c - 'A' + 10