2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
4 * Copyright 2000-2005 The OpenLDAP Foundation.
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted only as authorized by the OpenLDAP
11 * A copy of this license is available in the file LICENSE in the
12 * top-level directory of the distribution or, alternatively, at
13 * <http://www.OpenLDAP.org/license.html>.
16 * This work was initially developed by Pierangelo Masarati for
17 * inclusion in OpenLDAP Software.
28 #define LDAP_DEPRECATED 1
29 #include "rewrite-int.h"
30 #include "rewrite-map.h"
35 #ifdef USE_REWRITE_LDAP_PVT_THREADS
36 ldap_pvt_thread_mutex_t xpasswd_mutex;
37 static int xpasswd_mutex_init = 0;
38 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
42 * NOTE: these are old-fashion maps; new maps will be parsed on separate
43 * config lines, and referred by name.
47 struct rewrite_info *info,
52 struct rewrite_map *map;
54 assert( info != NULL );
56 assert( currpos != NULL );
58 Debug( LDAP_DEBUG_ARGS, "rewrite_xmap_parse: %s\n%s%s",
63 map = calloc( sizeof( struct rewrite_map ), 1 );
65 Debug( LDAP_DEBUG_ANY, "rewrite_xmap_parse:"
66 " calloc failed\n%s%s%s", "", "", "" );
71 * Experimental passwd map:
72 * replaces the uid with the matching gecos from /etc/passwd file
74 if ( strncasecmp(s, "xpasswd", 7 ) == 0 ) {
75 map->lm_type = REWRITE_MAP_XPWDMAP;
76 map->lm_name = strdup( "xpasswd" );
78 assert( s[7] == '}' );
81 #ifdef USE_REWRITE_LDAP_PVT_THREADS
82 if ( !xpasswd_mutex_init ) {
83 if ( ldap_pvt_thread_mutex_init( &xpasswd_mutex ) ) {
89 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
91 /* Don't really care if fails */
95 * Experimental file map:
96 * looks up key in a `key value' ascii file
98 } else if ( strncasecmp( s, "xfile", 5 ) == 0 ) {
104 map->lm_type = REWRITE_MAP_XFILEMAP;
106 if ( s[ c ] != '(' ) {
111 /* Must start with '/' for security concerns */
113 if ( s[ c ] != '/' ) {
118 for ( p = s + c; p[ 0 ] != '\0' && p[ 0 ] != ')'; p++ );
119 if ( p[ 0 ] != ')' ) {
125 filename = calloc( sizeof( char ), l + 1 );
126 AC_MEMCPY( filename, s + c, l );
127 filename[ l ] = '\0';
129 map->lm_args = ( void * )fopen( filename, "r" );
132 if ( map->lm_args == NULL ) {
139 #ifdef USE_REWRITE_LDAP_PVT_THREADS
140 if ( ldap_pvt_thread_mutex_init( &map->lm_mutex ) ) {
141 fclose( ( FILE * )map->lm_args );
145 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
150 * Experimental ldap map:
151 * looks up key on the fly (not implemented!)
153 } else if ( strncasecmp(s, "xldap", 5 ) == 0 ) {
160 if ( s[ c ] != '(' ) {
166 p = strchr( s, '}' );
176 * Add two bytes for urlencoding of '%s'
179 url = calloc( sizeof( char ), l + 3 );
180 AC_MEMCPY( url, s + c, l );
184 * Urlencodes the '%s' for ldap_url_parse
186 p = strchr( url, '%' );
188 AC_MEMCPY( p + 3, p + 1, strlen( p + 1 ) + 1 );
193 rc = ldap_url_parse( url, &lud );
196 if ( rc != LDAP_SUCCESS ) {
200 assert( lud != NULL );
202 map->lm_args = ( void * )lud;
203 map->lm_type = REWRITE_MAP_XLDAPMAP;
205 #ifdef USE_REWRITE_LDAP_PVT_THREADS
206 if ( ldap_pvt_thread_mutex_init( &map->lm_mutex ) ) {
207 ldap_free_urldesc( lud );
211 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
222 * Map key -> value resolution
223 * NOTE: these are old-fashion maps; new maps will be parsed on separate
224 * config lines, and referred by name.
228 struct rewrite_info *info,
229 struct rewrite_op *op,
230 struct rewrite_map *map,
235 int rc = REWRITE_SUCCESS;
237 assert( info != NULL );
238 assert( op != NULL );
239 assert( map != NULL );
240 assert( key != NULL );
241 assert( val != NULL );
246 switch ( map->lm_type ) {
248 case REWRITE_MAP_XPWDMAP: {
251 #ifdef USE_REWRITE_LDAP_PVT_THREADS
252 ldap_pvt_thread_mutex_lock( &xpasswd_mutex );
253 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
255 pwd = getpwnam( key->bv_val );
258 #ifdef USE_REWRITE_LDAP_PVT_THREADS
259 ldap_pvt_thread_mutex_unlock( &xpasswd_mutex );
260 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
262 rc = REWRITE_NO_SUCH_OBJECT;
267 if ( pwd->pw_gecos != NULL && pwd->pw_gecos[0] != '\0' ) {
268 int l = strlen( pwd->pw_gecos );
270 val->bv_val = strdup( pwd->pw_gecos );
271 if ( val->bv_val == NULL ) {
273 #ifdef USE_REWRITE_LDAP_PVT_THREADS
274 ldap_pvt_thread_mutex_unlock( &xpasswd_mutex );
275 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
282 #endif /* HAVE_PW_GECOS */
284 val->bv_val = strdup( key->bv_val );
285 val->bv_len = key->bv_len;
288 #ifdef USE_REWRITE_LDAP_PVT_THREADS
289 ldap_pvt_thread_mutex_unlock( &xpasswd_mutex );
290 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
294 #endif /* HAVE_GETPWNAM*/
296 case REWRITE_MAP_XFILEMAP: {
299 if ( map->lm_args == NULL ) {
304 #ifdef USE_REWRITE_LDAP_PVT_THREADS
305 ldap_pvt_thread_mutex_lock( &map->lm_mutex );
306 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
308 rewind( ( FILE * )map->lm_args );
310 while ( fgets( buf, sizeof( buf ), ( FILE * )map->lm_args ) ) {
314 blen = strlen( buf );
315 if ( buf[ blen - 1 ] == '\n' ) {
316 buf[ blen - 1 ] = '\0';
319 p = strtok( buf, " " );
321 #ifdef USE_REWRITE_LDAP_PVT_THREADS
322 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
323 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
327 if ( strcasecmp( p, key->bv_val ) == 0
328 && ( p = strtok( NULL, "" ) ) ) {
329 val->bv_val = strdup( p );
330 if ( val->bv_val == NULL ) {
334 val->bv_len = strlen( p );
336 #ifdef USE_REWRITE_LDAP_PVT_THREADS
337 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
338 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
344 #ifdef USE_REWRITE_LDAP_PVT_THREADS
345 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
346 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
353 case REWRITE_MAP_XLDAPMAP: {
356 LDAPMessage *res = NULL, *entry;
357 LDAPURLDesc *lud = ( LDAPURLDesc * )map->lm_args;
361 assert( lud != NULL );
364 * No mutex because there is no write on the map data
367 ld = ldap_init( lud->lud_host, lud->lud_port );
373 snprintf( filter, sizeof( filter ), lud->lud_filter,
376 if ( strcasecmp( lud->lud_attrs[ 0 ], "dn" ) == 0 ) {
379 rc = ldap_search_s( ld, lud->lud_dn, lud->lud_scope,
380 filter, lud->lud_attrs, attrsonly, &res );
381 if ( rc != LDAP_SUCCESS ) {
387 if ( ldap_count_entries( ld, res ) != 1 ) {
393 entry = ldap_first_entry( ld, res );
394 if ( entry == NULL ) {
400 if ( attrsonly == 1 ) {
401 val->bv_val = ldap_get_dn( ld, entry );
402 if ( val->bv_val == NULL ) {
409 values = ldap_get_values( ld, entry,
411 if ( values == NULL ) {
417 val->bv_val = strdup( values[ 0 ] );
418 ldap_value_free( values );
420 val->bv_len = strlen( val->bv_val );
425 rc = REWRITE_SUCCESS;
434 rewrite_xmap_destroy(
435 struct rewrite_map **pmap
438 struct rewrite_map *map;
445 switch ( map->lm_type ) {
446 case REWRITE_MAP_XPWDMAP:
447 #ifdef USE_REWRITE_LDAP_PVT_THREADS
448 --xpasswd_mutex_init;
449 if ( !xpasswd_mutex_init ) {
450 ldap_pvt_thread_mutex_destroy( &xpasswd_mutex );
452 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
456 case REWRITE_MAP_XFILEMAP:
457 #ifdef USE_REWRITE_LDAP_PVT_THREADS
458 ldap_pvt_thread_mutex_lock( &map->lm_mutex );
459 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
461 if ( map->lm_args ) {
462 fclose( ( FILE * )map->lm_args );
466 #ifdef USE_REWRITE_LDAP_PVT_THREADS
467 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
468 ldap_pvt_thread_mutex_destroy( &map->lm_mutex );
469 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
472 case REWRITE_MAP_XLDAPMAP:
473 #ifdef USE_REWRITE_LDAP_PVT_THREADS
474 ldap_pvt_thread_mutex_lock( &map->lm_mutex );
475 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
477 if ( map->lm_args ) {
478 ldap_free_urldesc( ( LDAPURLDesc * )map->lm_args );
482 #ifdef USE_REWRITE_LDAP_PVT_THREADS
483 ldap_pvt_thread_mutex_unlock( &map->lm_mutex );
484 ldap_pvt_thread_mutex_destroy( &map->lm_mutex );
485 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
493 free( map->lm_name );