]> git.sur5r.net Git - openldap/blob - libraries/librewrite/ldapmap.c
happy new year
[openldap] / libraries / librewrite / ldapmap.c
1 /* $OpenLDAP$ */
2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
3  *
4  * Copyright 2000-2007 The OpenLDAP Foundation.
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted only as authorized by the OpenLDAP
9  * Public License.
10  *
11  * A copy of this license is available in the file LICENSE in the
12  * top-level directory of the distribution or, alternatively, at
13  * <http://www.OpenLDAP.org/license.html>.
14  */
15 /* ACKNOWLEDGEMENT:
16  * This work was initially developed by Pierangelo Masarati for
17  * inclusion in OpenLDAP Software.
18  */
19
20 #include <portable.h>
21
22 #define LDAP_DEPRECATED 1
23 #include "rewrite-int.h"
24 #include "rewrite-map.h"
25
26 typedef enum {
27         MAP_LDAP_UNKNOWN,
28         MAP_LDAP_EVERYTIME,
29         MAP_LDAP_NOW,
30         MAP_LDAP_LATER
31 } bindwhen_t;
32
33 /*
34  * LDAP map data structure
35  */
36 struct ldap_map_data {
37         char                           *lm_url;
38         LDAPURLDesc                    *lm_lud;
39         int                             lm_version;
40         char                           *lm_binddn;
41         struct berval                   lm_cred;
42
43         bindwhen_t                      lm_when;
44
45         LDAP                           *lm_ld;
46
47         int                             lm_wantdn;
48         char                            *lm_attrs[ 2 ];
49
50 #ifdef USE_REWRITE_LDAP_PVT_THREADS
51         ldap_pvt_thread_mutex_t         lm_mutex;
52 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
53 };
54
55 static void
56 map_ldap_free(
57                 struct ldap_map_data *data
58 )
59 {
60         assert( data != NULL );
61
62         if ( data->lm_url != NULL ) {
63                 free( data->lm_url );
64         }
65
66         if ( data->lm_lud != NULL ) {
67                 ldap_free_urldesc( data->lm_lud );
68         }
69
70         if ( data->lm_binddn != NULL ) {
71                 free( data->lm_binddn );
72         }
73
74         if ( data->lm_cred.bv_val != NULL ) {
75                 memset( data->lm_cred.bv_val, 0, data->lm_cred.bv_len );
76                 free( data->lm_cred.bv_val );
77                 data->lm_cred.bv_val = NULL;
78                 data->lm_cred.bv_len = 0;
79         }
80
81         if ( data->lm_when != MAP_LDAP_EVERYTIME && data->lm_ld != NULL ) {
82                 ldap_unbind_ext( data->lm_ld, NULL, NULL );
83         }
84
85         free( data );
86 }
87
88 void *
89 map_ldap_parse(
90                 struct rewrite_info *info,
91                 const char *fname,
92                 int lineno,
93                 int argc,
94                 char **argv
95 )
96 {
97         struct ldap_map_data *data;
98         char *p, *uri;
99
100         assert( info != NULL );
101         assert( fname != NULL );
102         assert( argv != NULL );
103
104         data = calloc( sizeof( struct ldap_map_data ), 1 );
105         if ( data == NULL ) {
106                 return NULL;
107         }
108
109         if ( argc < 1 ) {
110                 Debug( LDAP_DEBUG_ANY,
111                                 "[%s:%d] ldap map needs URI\n%s",
112                                 fname, lineno, "" );
113                 free( data );
114                 return NULL;
115         }
116
117         uri = argv[ 0 ];
118         if ( strncasecmp( uri, "uri=", STRLENOF( "uri=" ) ) == 0 ) {
119                 uri += STRLENOF( "uri=" );
120         }
121
122         data->lm_url = strdup( uri );
123         if ( data->lm_url == NULL ) {
124                 map_ldap_free( data );
125                 return NULL;
126         }
127         
128         if ( ldap_url_parse( uri, &data->lm_lud ) != REWRITE_SUCCESS ) {
129                 Debug( LDAP_DEBUG_ANY,
130                                 "[%s:%d] illegal URI '%s'\n",
131                                 fname, lineno, argv[ 0 ] );
132                 map_ldap_free( data );
133                 return NULL;
134         }
135
136         /* trim everything after [host][:port] */
137         p = strchr( data->lm_url, '/' );
138         assert( p[ 1 ] == '/' );
139         if ( ( p = strchr( p + 2, '/' ) ) != NULL ) {
140                 p[ 0 ] = '\0';
141         }
142
143         if ( data->lm_lud->lud_attrs == NULL ) {
144                 data->lm_attrs[ 0 ] = LDAP_NO_ATTRS;
145                 data->lm_wantdn = 1;
146
147         } else {
148                 if ( data->lm_lud->lud_attrs[ 1 ] != NULL ) {
149                         Debug( LDAP_DEBUG_ANY,
150                                 "[%s:%d] only one attribute allowed in URI\n",
151                                 fname, lineno, 0 );
152                         map_ldap_free( data );
153                         return NULL;
154                 }
155
156                 if ( strcasecmp( data->lm_lud->lud_attrs[ 0 ], "dn" ) == 0
157                         || strcasecmp( data->lm_lud->lud_attrs[ 0 ], "entryDN" ) == 0 )
158                 {
159                         ldap_memfree( data->lm_lud->lud_attrs[ 0 ] );
160                         ldap_memfree( data->lm_lud->lud_attrs );
161                         data->lm_lud->lud_attrs = NULL;
162                         data->lm_attrs[ 0 ] = LDAP_NO_ATTRS;
163                         data->lm_wantdn = 1;
164
165                 } else {
166                         data->lm_attrs[ 0 ] = data->lm_lud->lud_attrs[ 0 ];
167                 }
168         }
169
170         data->lm_attrs[ 1 ] = NULL;
171
172         /* safe defaults */
173         data->lm_version = LDAP_VERSION3;
174
175         for ( argc--, argv++; argc > 0; argc--, argv++ ) {
176                 if ( strncasecmp( argv[ 0 ], "binddn=", STRLENOF( "binddn=" ) ) == 0 ) {
177                         char *p = argv[ 0 ] + STRLENOF( "binddn=" );
178                         int l;
179
180                         if ( p[ 0 ] == '\"' || p [ 0 ] == '\'' ) {
181                                 l = strlen( p ) - 2;
182                                 p++;
183                                 if ( p[ l ] != p[ 0 ] ) {
184                                         map_ldap_free( data );
185                                         return NULL;
186                                 }
187                         } else {
188                                 l = strlen( p );
189                         }
190                         
191                         data->lm_binddn = strdup( p );                  
192                         if ( data->lm_binddn == NULL ) {
193                                 map_ldap_free( data );
194                                 return NULL;
195                         }
196
197                         if ( data->lm_binddn[ l ] == '\"' 
198                                         || data->lm_binddn[ l ] == '\'' ) {
199                                 data->lm_binddn[ l ] = '\0';
200                         }
201
202                         /* deprecated */
203                 } else if ( strncasecmp( argv[ 0 ], "bindpw=", STRLENOF( "bindpw=" ) ) == 0 ) {
204                         ber_str2bv( argv[ 0 ] + STRLENOF( "bindpw=" ), 0, 1, &data->lm_cred );
205                         if ( data->lm_cred.bv_val == NULL ) {
206                                 map_ldap_free( data );
207                                 return NULL;
208                         }
209
210                 } else if ( strncasecmp( argv[ 0 ], "credentials=", STRLENOF( "credentials=" ) ) == 0 ) {
211                         ber_str2bv( argv[ 0 ] + STRLENOF( "credentials=" ), 0, 1, &data->lm_cred );
212                         if ( data->lm_cred.bv_val == NULL ) {
213                                 map_ldap_free( data );
214                                 return NULL;
215                         }
216
217                 } else if ( strncasecmp( argv[ 0 ], "bindwhen=", STRLENOF( "bindwhen=" ) ) == 0 ) {
218                         char *p = argv[ 0 ] + STRLENOF( "bindwhen=" );
219
220                         if ( strcasecmp( p, "now" ) == 0 ) {
221                                 int rc;
222                                 
223                                 data->lm_when = MAP_LDAP_NOW;
224                                 
225                                 /*
226                                  * Init LDAP handler ...
227                                  */
228                                 rc = ldap_initialize( &data->lm_ld, data->lm_url );
229                                 if ( rc != LDAP_SUCCESS ) {
230                                         map_ldap_free( data );
231                                         return NULL;
232                                 }
233
234                                 ldap_set_option( data->lm_ld,
235                                         LDAP_OPT_PROTOCOL_VERSION,
236                                         (void *)&data->lm_version );
237
238 #ifdef USE_REWRITE_LDAP_PVT_THREADS
239                                 ldap_pvt_thread_mutex_init( &data->lm_mutex );
240 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
241
242                         } else if ( strcasecmp( p, "later" ) == 0 ) {
243                                 data->lm_when = MAP_LDAP_LATER;
244
245 #ifdef USE_REWRITE_LDAP_PVT_THREADS
246                                 ldap_pvt_thread_mutex_init( &data->lm_mutex );
247 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
248
249                         } else if ( strcasecmp( p, "everytime" ) == 0 ) {
250                                 data->lm_when = MAP_LDAP_EVERYTIME;
251                         } else {
252                                 /* ignore ... */
253                         }
254
255                 } else if ( strncasecmp( argv[ 0 ], "version=", STRLENOF( "version=" ) ) == 0 ) {
256                         if ( lutil_atoi( &data->lm_version, argv[ 0 ] + STRLENOF( "version=" ) ) ) {
257                                 map_ldap_free( data );
258                                 return NULL;
259                         }
260
261                         switch ( data->lm_version ) {
262                         case LDAP_VERSION2:
263                         case LDAP_VERSION3:
264                                 break;
265
266                         default:
267                                 Debug( LDAP_DEBUG_ANY,
268                                         "[%s:%d] unknown version %s\n",
269                                         fname, lineno, p );
270                                 map_ldap_free( data );
271                                 return NULL;
272                         }
273
274                 } else {
275                         Debug( LDAP_DEBUG_ANY,
276                                 "[%s:%d] unknown option %s (ignored)\n",
277                                 fname, lineno, argv[0] );
278                 }
279         }
280
281         if ( data->lm_when == MAP_LDAP_UNKNOWN ) {
282                 data->lm_when = MAP_LDAP_EVERYTIME;
283         }
284
285         return ( void * )data;
286 }
287
288 int
289 map_ldap_apply(
290                 struct rewrite_builtin_map *map,
291                 const char *filter,
292                 struct berval *val
293
294 )
295 {
296         LDAP *ld;
297         LDAPMessage *res = NULL, *entry;
298         int rc;
299         struct ldap_map_data *data = ( struct ldap_map_data * )map->lb_private;
300         LDAPURLDesc *lud = data->lm_lud;
301         
302         int first_try = 1, set_version = 0;
303
304         assert( map != NULL );
305         assert( map->lb_type == REWRITE_BUILTIN_MAP_LDAP );
306         assert( map->lb_private != NULL );
307         assert( filter != NULL );
308         assert( val != NULL );
309
310         val->bv_val = NULL;
311         val->bv_len = 0;
312
313         if ( data->lm_when == MAP_LDAP_EVERYTIME ) {
314                 rc = ldap_initialize( &ld, data->lm_url );
315                 set_version = 1;
316
317         } else {
318 #ifdef USE_REWRITE_LDAP_PVT_THREADS
319                 ldap_pvt_thread_mutex_lock( &data->lm_mutex );
320 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
321
322                 rc = LDAP_SUCCESS;
323
324                 if ( data->lm_when == MAP_LDAP_LATER && data->lm_ld == NULL ) {
325                         rc = ldap_initialize( &data->lm_ld, data->lm_url );
326                         set_version = 1;
327                 }
328                 
329                 ld = data->lm_ld;
330         }
331
332         if ( rc != LDAP_SUCCESS ) {
333                 rc = REWRITE_ERR;
334                 goto rc_return;
335         }
336
337 do_bind:;
338         if ( set_version ) {
339                 ldap_set_option( ld, LDAP_OPT_PROTOCOL_VERSION,
340                         (void *)&data->lm_version );
341                 set_version = 0;
342         }
343
344         if ( data->lm_binddn != NULL ) {
345                 rc = ldap_sasl_bind_s( ld, data->lm_binddn,
346                         LDAP_SASL_SIMPLE, &data->lm_cred,
347                         NULL, NULL, NULL );
348                 if ( rc == LDAP_SERVER_DOWN && first_try ) {
349                         first_try = 0;
350                         if ( ldap_initialize( &ld, data->lm_url ) != LDAP_SUCCESS ) {
351                                 rc = REWRITE_ERR;
352                                 goto rc_return;
353                         }
354                         set_version = 1;
355                         goto do_bind;
356
357                 } else if ( rc != REWRITE_SUCCESS ) {
358                         rc = REWRITE_ERR;
359                         goto rc_return;
360                 }
361         }
362
363         rc = ldap_search_ext_s( ld, lud->lud_dn, lud->lud_scope, ( char * )filter,
364                         data->lm_attrs, 0, NULL, NULL, NULL, 1, &res );
365         if ( rc == LDAP_SERVER_DOWN && first_try ) {
366                 first_try = 0;
367                 if ( ldap_initialize( &ld, data->lm_url ) != LDAP_SUCCESS ) {
368                         rc = REWRITE_ERR;
369                         goto rc_return;
370                 }
371                 set_version = 1;
372                 goto do_bind;
373
374         } else if ( rc != LDAP_SUCCESS ) {
375                 rc = REWRITE_ERR;
376                 goto rc_return;
377         }
378
379         if ( ldap_count_entries( ld, res ) != 1 ) {
380                 ldap_msgfree( res );
381                 rc = REWRITE_ERR;
382                 goto rc_return;
383         }
384
385         entry = ldap_first_entry( ld, res );
386         assert( entry != NULL );
387
388         if ( data->lm_wantdn == 1 ) {
389                 /*
390                  * dn is newly allocated, so there's no need to strdup it
391                  */
392                 val->bv_val = ldap_get_dn( ld, entry );
393                 val->bv_len = strlen( val->bv_val );
394
395         } else {
396                 struct berval **values;
397
398                 values = ldap_get_values_len( ld, entry, data->lm_attrs[ 0 ] );
399                 if ( values != NULL ) {
400                         if ( values[ 0 ] != NULL && values[ 0 ]->bv_val != NULL ) {
401 #if 0
402                                 /* NOTE: in principle, multiple values
403                                  * should not be acceptable according
404                                  * to the current API; ignore by now */
405                                 if ( values[ 1 ] != NULL ) {
406                                         /* error */                             
407                                 }
408 #endif
409                                 ber_dupbv( val, values[ 0 ] );
410                         }
411                         ldap_value_free_len( values );
412                 }
413         }
414         
415         ldap_msgfree( res );
416
417         if ( val->bv_val == NULL ) {
418                 rc = REWRITE_ERR;
419                 goto rc_return;
420         }
421
422 rc_return:;
423         if ( data->lm_when == MAP_LDAP_EVERYTIME ) {
424                 if ( ld != NULL ) {
425                         ldap_unbind_ext( ld, NULL, NULL );
426                 }
427
428         } else {
429                 data->lm_ld = ld;
430 #ifdef USE_REWRITE_LDAP_PVT_THREADS
431                 ldap_pvt_thread_mutex_unlock( &data->lm_mutex );
432 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
433         }
434         
435         return rc;
436 }
437
438 int
439 map_ldap_destroy(
440                 struct rewrite_builtin_map **pmap
441 )
442 {
443         struct ldap_map_data *data;
444
445         assert( pmap != NULL );
446         assert( *pmap != NULL );
447         
448         data = ( struct ldap_map_data * )(*pmap)->lb_private;
449
450         map_ldap_free( data );
451
452         (*pmap)->lb_private = NULL;
453
454         return 0;
455 }
456