1 /******************************************************************************
3 * Copyright (C) 2000 Pierangelo Masarati, <ando@sys-net.it>
6 * Permission is granted to anyone to use this software for any purpose
7 * on any computer system, and to alter it and redistribute it, subject
8 * to the following restrictions:
10 * 1. The author is not responsible for the consequences of use of this
11 * software, no matter how awful, even if they arise from flaws in it.
13 * 2. The origin of this software must not be misrepresented, either by
14 * explicit claim or by omission. Since few users ever read sources,
15 * credits should appear in the documentation.
17 * 3. Altered versions must be plainly marked as such, and must not be
18 * misrepresented as being the original software. Since few users
19 * ever read sources, credits should appear in the documentation.
21 * 4. This notice may not be removed or altered.
23 ******************************************************************************/
31 #include "rewrite-int.h"
32 #include "rewrite-map.h"
37 #ifdef USE_REWRITE_LDAP_PVT_THREADS
38 ldap_pvt_thread_mutex_t xpasswd_mutex;
39 static int xpasswd_mutex_init = 0;
40 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
44 * NOTE: these are old-fashion maps; new maps will be parsed on separate
45 * config lines, and referred by name.
49 struct rewrite_info *info,
54 struct rewrite_map *map;
56 assert( info != NULL );
58 assert( currpos != NULL );
60 Debug( LDAP_DEBUG_ARGS, "rewrite_xmap_parse: %s\n%s%s",
65 map = calloc( sizeof( struct rewrite_map ), 1 );
67 Debug( LDAP_DEBUG_ANY, "rewrite_xmap_parse:"
68 " calloc failed\n%s%s%s", "", "", "" );
73 * Experimental passwd map:
74 * replaces the uid with the matching gecos from /etc/passwd file
76 if ( strncasecmp(s, "xpasswd", 7 ) == 0 ) {
77 map->lm_type = REWRITE_MAP_XPWDMAP;
78 map->lm_name = strdup( "xpasswd" );
80 assert( s[7] == '}' );
83 #ifdef USE_REWRITE_LDAP_PVT_THREADS
84 if ( !xpasswd_mutex_init ) {
85 xpasswd_mutex_init = 1;
86 if ( ldap_pvt_thread_mutex_init( &xpasswd_mutex ) ) {
91 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
93 /* Don't really care if fails */
97 * Experimental file map:
98 * looks up key in a `key value' ascii file
100 } else if ( strncasecmp(s, "xfile", 5 ) == 0 ) {
106 map->lm_type = REWRITE_MAP_XFILEMAP;
108 if ( s[ c ] != '(' ) {
113 /* Must start with '/' for security concerns */
115 if ( s[ c ] != '/' ) {
120 for ( p = s + c; p[ 0 ] != '\0' && p[ 0 ] != ')'; p++ );
121 if ( p[ 0 ] != ')' ) {
127 filename = calloc( sizeof( char ), l + 1 );
128 AC_MEMCPY( filename, s + c, l );
129 filename[ l ] = '\0';
131 map->lm_args = ( void * )fopen( filename, "r" );
134 if ( map->lm_args == NULL ) {
141 #ifdef USE_REWRITE_LDAP_PVT_THREADS
142 if ( ldap_pvt_thread_mutex_init( &map->lm_mutex ) ) {
143 fclose( ( FILE * )map->lm_args );
147 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
152 * Experimental ldap map:
153 * looks up key on the fly (not implemented!)
155 } else if ( strncasecmp(s, "xldap", 5 ) == 0 ) {
162 if ( s[ c ] != '(' ) {
168 p = strchr( s, '}' );
178 * Add two bytes for urlencoding of '%s'
181 url = calloc( sizeof( char ), l + 3 );
182 AC_MEMCPY( url, s + c, l );
186 * Urlencodes the '%s' for ldap_url_parse
188 p = strchr( url, '%' );
190 AC_MEMCPY( p + 3, p + 1, strlen( p + 1 ) + 1 );
195 rc = ldap_url_parse( url, &lud );
198 if ( rc != LDAP_SUCCESS ) {
202 assert( lud != NULL );
204 map->lm_args = ( void * )lud;
205 map->lm_type = REWRITE_MAP_XLDAPMAP;
207 #ifdef USE_REWRITE_LDAP_PVT_THREADS
208 if ( ldap_pvt_thread_mutex_init( &map->lm_mutex ) ) {
209 ldap_free_urldesc( lud );
213 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
225 struct rewrite_info *info,
230 struct rewrite_map *map = NULL;
231 struct rewrite_subst *subst = NULL;
232 char *s, *begin = NULL, *end;
236 assert( info != NULL );
237 assert( string != NULL );
238 assert( currpos != NULL );
243 * Go to the end of the map invocation (the right closing brace)
245 for ( p = string, cnt = 1; p[ 0 ] != '\0' && cnt > 0; p++ ) {
246 if ( p[ 0 ] == REWRITE_SUBMATCH_ESCAPE ) {
248 * '%' marks the beginning of a new map
250 if ( p[ 1 ] == '{' ) {
253 * '%' followed by a digit may mark the beginning
256 } else if ( isdigit( (unsigned char) p[ 1 ] ) && p[ 2 ] == '{' ) {
260 if ( p[ 1 ] != '\0' )
262 } else if ( p[ 0 ] == '}' ) {
272 * Copy the map invocation
275 s = calloc( sizeof( char ), l + 1 );
276 AC_MEMCPY( s, string, l );
280 * Isolate the map name (except for variable deref)
283 case REWRITE_OPERATOR_VARIABLE_GET:
284 case REWRITE_OPERATOR_PARAM_GET:
287 begin = strchr( s, '(' );
288 if ( begin == NULL ) {
298 * Check for special map types
302 case REWRITE_OPERATOR_SUBCONTEXT:
303 case REWRITE_OPERATOR_COMMAND:
304 case REWRITE_OPERATOR_VARIABLE_SET:
305 case REWRITE_OPERATOR_VARIABLE_GET:
306 case REWRITE_OPERATOR_PARAM_GET:
312 * Variable set and get may be repeated to indicate session-wide
313 * instead of operation-wide variables
316 case REWRITE_OPERATOR_VARIABLE_SET:
317 case REWRITE_OPERATOR_VARIABLE_GET:
323 * Variable get token can be appended to variable set to mean store
326 if ( p[ 0 ] == REWRITE_OPERATOR_VARIABLE_GET ) {
331 * Check the syntax of the variable name
333 if ( !isalpha( (unsigned char) p[ 0 ] ) ) {
337 for ( p++; p[ 0 ] != '\0'; p++ ) {
338 if ( !isalnum( (unsigned char) p[ 0 ] ) ) {
345 * Isolate the argument of the map (except for variable deref)
348 case REWRITE_OPERATOR_VARIABLE_GET:
349 case REWRITE_OPERATOR_PARAM_GET:
352 end = strrchr( begin, ')' );
360 * Compile the substitution pattern of the map argument
362 subst = rewrite_subst_compile( info, begin );
363 if ( subst == NULL ) {
373 map = calloc( sizeof( struct rewrite_map ), 1 );
375 if ( subst != NULL ) {
382 #ifdef USE_REWRITE_LDAP_PVT_THREADS
383 if ( ldap_pvt_thread_mutex_init( &map->lm_mutex ) ) {
384 if ( subst != NULL ) {
391 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
394 * No subst for variable deref
397 case REWRITE_OPERATOR_VARIABLE_GET:
398 case REWRITE_OPERATOR_PARAM_GET:
401 map->lm_subst = subst;
406 * Parses special map types
413 case REWRITE_OPERATOR_SUBCONTEXT: /* '>' */
416 * Fetch the rewrite context
417 * it MUST have been defined previously
419 map->lm_type = REWRITE_MAP_SUBCONTEXT;
420 map->lm_name = strdup( s + 1 );
421 map->lm_data = rewrite_context_find( info, s + 1 );
422 if ( map->lm_data == NULL ) {
432 case REWRITE_OPERATOR_COMMAND: /* '|' */
440 case REWRITE_OPERATOR_VARIABLE_SET: /* '&' */
441 if ( s[ 1 ] == REWRITE_OPERATOR_VARIABLE_SET ) {
442 if ( s[ 2 ] == REWRITE_OPERATOR_VARIABLE_GET ) {
443 map->lm_type = REWRITE_MAP_SETW_SESN_VAR;
444 map->lm_name = strdup( s + 3 );
446 map->lm_type = REWRITE_MAP_SET_SESN_VAR;
447 map->lm_name = strdup( s + 2 );
450 if ( s[ 1 ] == REWRITE_OPERATOR_VARIABLE_GET ) {
451 map->lm_type = REWRITE_MAP_SETW_OP_VAR;
452 map->lm_name = strdup( s + 2 );
454 map->lm_type = REWRITE_MAP_SET_OP_VAR;
455 map->lm_name = strdup( s + 1 );
461 * Variable dereference
463 case REWRITE_OPERATOR_VARIABLE_GET: /* '*' */
464 if ( s[ 1 ] == REWRITE_OPERATOR_VARIABLE_GET ) {
465 map->lm_type = REWRITE_MAP_GET_SESN_VAR;
466 map->lm_name = strdup( s + 2 );
468 map->lm_type = REWRITE_MAP_GET_OP_VAR;
469 map->lm_name = strdup( s + 1 );
476 case REWRITE_OPERATOR_PARAM_GET: /* '$' */
477 map->lm_type = REWRITE_MAP_GET_PARAM;
478 map->lm_name = strdup( s + 1 );
485 map->lm_type = REWRITE_MAP_BUILTIN;
486 map->lm_name = strdup( s );
487 map->lm_data = rewrite_builtin_map_find( info, s );
488 if ( map->lm_data == NULL ) {
500 * Map key -> value resolution
501 * NOTE: these are old-fashion maps; new maps will be parsed on separate
502 * config lines, and referred by name.
506 struct rewrite_info *info,
507 struct rewrite_op *op,
508 struct rewrite_map *map,
513 int rc = REWRITE_SUCCESS;
515 assert( info != NULL );
516 assert( op != NULL );
517 assert( map != NULL );
518 assert( key != NULL );
519 assert( val != NULL );
524 switch ( map->lm_type ) {
526 case REWRITE_MAP_XPWDMAP: {
529 #ifdef USE_REWRITE_LDAP_PVT_THREADS
530 ldap_pvt_thread_mutex_lock( &xpasswd_mutex );
531 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
533 pwd = getpwnam( key->bv_val );
536 #ifdef USE_REWRITE_LDAP_PVT_THREADS
537 ldap_pvt_thread_mutex_unlock( &xpasswd_mutex );
538 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
540 rc = REWRITE_NO_SUCH_OBJECT;
544 if ( pwd->pw_gecos != NULL && pwd->pw_gecos[0] != '\0' ) {
545 int l = strlen( pwd->pw_gecos );
547 val->bv_val = strdup( pwd->pw_gecos );
548 if ( val->bv_val == NULL ) {
550 #ifdef USE_REWRITE_LDAP_PVT_THREADS
551 ldap_pvt_thread_mutex_unlock( &xpasswd_mutex );
552 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
559 val->bv_val = strdup( key->bv_val );
560 val->bv_len = key->bv_len;
563 #ifdef USE_REWRITE_LDAP_PVT_THREADS
564 ldap_pvt_thread_mutex_unlock( &xpasswd_mutex );
565 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
569 #endif /* HAVE_GETPWNAM*/
571 case REWRITE_MAP_XFILEMAP: {
574 if ( map->lm_args == NULL ) {
579 #ifdef USE_REWRITE_LDAP_PVT_THREADS
580 ldap_pvt_thread_mutex_lock( &map->lm_mutex );
581 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
583 rewind( ( FILE * )map->lm_args );
585 while ( fgets( buf, sizeof( buf ), ( FILE * )map->lm_args ) ) {
589 blen = strlen( buf );
590 if ( buf[ blen - 1 ] == '\n' ) {
591 buf[ blen - 1 ] = '\0';
594 p = strtok( buf, " " );
596 #ifdef USE_REWRITE_LDAP_PVT_THREADS
597 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
598 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
602 if ( strcasecmp( p, key->bv_val ) == 0
603 && ( p = strtok( NULL, "" ) ) ) {
604 val->bv_val = strdup( p );
605 if ( val->bv_val == NULL ) {
609 val->bv_len = strlen( p );
611 #ifdef USE_REWRITE_LDAP_PVT_THREADS
612 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
613 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
619 #ifdef USE_REWRITE_LDAP_PVT_THREADS
620 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
621 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
628 case REWRITE_MAP_XLDAPMAP: {
630 char filter[ LDAP_FILT_MAXSIZ ];
631 LDAPMessage *res = NULL, *entry;
632 LDAPURLDesc *lud = ( LDAPURLDesc * )map->lm_args;
636 assert( lud != NULL );
639 * No mutex because there is no write on the map data
642 ld = ldap_init( lud->lud_host, lud->lud_port );
648 snprintf( filter, sizeof( filter ), lud->lud_filter,
651 if ( strcasecmp( lud->lud_attrs[ 0 ], "dn" ) == 0 ) {
654 rc = ldap_search_s( ld, lud->lud_dn, lud->lud_scope,
655 filter, lud->lud_attrs, attrsonly, &res );
656 if ( rc != LDAP_SUCCESS ) {
662 if ( ldap_count_entries( ld, res ) != 1 ) {
668 entry = ldap_first_entry( ld, res );
669 if ( entry == NULL ) {
675 if ( attrsonly == 1 ) {
676 val->bv_val = ldap_get_dn( ld, entry );
677 if ( val->bv_val == NULL ) {
684 values = ldap_get_values( ld, entry,
686 if ( values == NULL ) {
692 val->bv_val = strdup( values[ 0 ] );
693 ldap_value_free( values );
695 val->bv_len = strlen( val->bv_val );
700 rc = REWRITE_SUCCESS;
709 * Applies the new map type
713 struct rewrite_info *info,
714 struct rewrite_op *op,
715 struct rewrite_map *map,
720 int rc = REWRITE_SUCCESS;
722 assert( info != NULL );
723 assert( op != NULL );
724 assert( map != NULL );
725 assert( key != NULL );
726 assert( val != NULL );
731 switch ( map->lm_type ) {
732 case REWRITE_MAP_SUBCONTEXT:
733 rc = rewrite_context_apply( info, op,
734 ( struct rewrite_context * )map->lm_data,
735 key->bv_val, &val->bv_val );
736 if ( val->bv_val != NULL ) {
737 val->bv_len = strlen( val->bv_val );
741 case REWRITE_MAP_SET_OP_VAR:
742 case REWRITE_MAP_SETW_OP_VAR:
743 rc = rewrite_var_set( &op->lo_vars, map->lm_name,
745 ? REWRITE_SUCCESS : REWRITE_ERR;
746 if ( map->lm_type == REWRITE_MAP_SET_OP_VAR ) {
747 val->bv_val = strdup( "" );
749 val->bv_val = strdup( key->bv_val );
750 val->bv_len = key->bv_len;
754 case REWRITE_MAP_GET_OP_VAR: {
755 struct rewrite_var *var;
757 var = rewrite_var_find( op->lo_vars, map->lm_name );
761 val->bv_val = strdup( var->lv_value.bv_val );
762 val->bv_len = var->lv_value.bv_len;
767 case REWRITE_MAP_SET_SESN_VAR:
768 case REWRITE_MAP_SETW_SESN_VAR:
769 if ( op->lo_cookie == NULL ) {
773 rc = rewrite_session_var_set( info, op->lo_cookie,
774 map->lm_name, key->bv_val );
775 if ( map->lm_type == REWRITE_MAP_SET_SESN_VAR ) {
776 val->bv_val = strdup( "" );
778 val->bv_val = strdup( key->bv_val );
779 val->bv_len = key->bv_len;
783 case REWRITE_MAP_GET_SESN_VAR:
784 rc = rewrite_session_var_get( info, op->lo_cookie,
788 case REWRITE_MAP_GET_PARAM:
789 rc = rewrite_param_get( info, map->lm_name, val );
792 case REWRITE_MAP_BUILTIN: {
793 struct rewrite_builtin_map *bmap = map->lm_data;
794 switch ( bmap->lb_type ) {
795 case REWRITE_BUILTIN_MAP_LDAP:
796 rc = map_ldap_apply( bmap, key->bv_val, val );