1 /* acl.c - routines to parse and check acl's */
6 #include <sys/socket.h>
7 #include <netinet/in.h>
16 extern Attribute *attr_find();
17 extern char *re_comp();
18 extern struct acl *global_acl;
19 extern int global_default_access;
20 extern char *access2str();
21 extern char *dn_normalize_case();
23 int acl_access_allowed();
25 struct acl *acl_get_applicable();
27 static int regex_matches();
29 extern pthread_mutex_t regex_mutex;
32 * access_allowed - check whether dn is allowed the requested access
33 * to entry e, attribute attr, value val. if val is null, access to
34 * the whole attribute is assumed (all values). this routine finds
35 * the applicable acl and calls acl_access_allowed() to make the
38 * returns 0 access NOT allowed
61 a = acl_get_applicable( be, op, e, attr );
62 rc = acl_access_allowed( a, be, conn, e, val, op, access );
68 * acl_get_applicable - return the acl applicable to entry e, attribute
69 * attr. the acl returned is suitable for use in subsequent calls to
70 * acl_access_allowed().
85 Debug( LDAP_DEBUG_ACL, "=> acl_get: entry (%s) attr (%s)\n", e->e_dn,
88 if ( be_isroot( be, op->o_dn ) ) {
89 Debug( LDAP_DEBUG_ACL,
90 "<= acl_get: no acl applicable to database root\n", 0, 0,
95 /* check for a backend-specific acl that matches the entry */
96 for ( i = 1, a = be->be_acl; a != NULL; a = a->acl_next, i++ ) {
97 if ( a->acl_dnpat != NULL ) {
98 edn = dn_normalize_case( strdup( e->e_dn ) );
99 if ( ! regex_matches( a->acl_dnpat, edn ) ) {
105 if ( a->acl_filter != NULL ) {
106 if ( test_filter( NULL, NULL, NULL, e, a->acl_filter )
111 if ( attr == NULL || a->acl_attrs == NULL ||
112 charray_inlist( a->acl_attrs, attr ) ) {
113 Debug( LDAP_DEBUG_ACL, "<= acl_get: backend acl #%d\n",
119 /* check for a global acl that matches the entry */
120 for ( i = 1, a = global_acl; a != NULL; a = a->acl_next, i++ ) {
121 if ( a->acl_dnpat != NULL ) {
122 edn = dn_normalize_case( strdup( e->e_dn ) );
123 if ( ! regex_matches( a->acl_dnpat, edn ) ) {
129 if ( a->acl_filter != NULL ) {
130 if ( test_filter( NULL, NULL, NULL, e, a->acl_filter )
135 if ( attr == NULL || a->acl_attrs == NULL || charray_inlist(
136 a->acl_attrs, attr ) ) {
137 Debug( LDAP_DEBUG_ACL, "<= acl_get: global acl #%d\n",
142 Debug( LDAP_DEBUG_ACL, "<= acl_get: no match\n", 0, 0, 0 );
148 * acl_access_allowed - check whether the given acl allows dn the
149 * requested access to entry e, attribute attr, value val. if val
150 * is null, access to the whole attribute is assumed (all values).
152 * returns 0 access NOT allowed
174 Debug( LDAP_DEBUG_ACL, "=> acl: %s access to value \"%s\" by \"%s\"\n",
175 access2str( access ), val ? val->bv_val : "any", op->o_dn ?
178 if ( be_isroot( be, op->o_dn ) ) {
179 Debug( LDAP_DEBUG_ACL, "<= acl: granted to database root\n",
184 default_access = be->be_dfltaccess ? be->be_dfltaccess :
185 global_default_access;
187 Debug( LDAP_DEBUG_ACL,
188 "<= acl: %s by default (no matching to)\n",
189 default_access >= access ? "granted" : "denied", 0, 0 );
190 return( default_access >= access );
194 if ( op->o_dn != NULL ) {
195 odn = dn_normalize_case( strdup( op->o_dn ) );
197 bv.bv_len = strlen( odn );
199 for ( i = 1, b = a->acl_access; b != NULL; b = b->a_next, i++ ) {
200 if ( b->a_dnpat != NULL ) {
202 * if access applies to the entry itself, and the
203 * user is bound as somebody in the same namespace as
204 * the entry, OR the given dn matches the dn pattern
206 if ( strcasecmp( b->a_dnpat, "self" ) == 0 && op->o_dn
207 != NULL && *(op->o_dn) && e->e_dn != NULL ) {
208 edn = dn_normalize_case( strdup( e->e_dn ) );
209 if ( strcasecmp( edn, op->o_dn ) == 0 ) {
211 if ( odn ) free( odn );
212 Debug( LDAP_DEBUG_ACL,
213 "<= acl: matched by clause #%d access %s\n",
214 i, (b->a_access & ~ACL_SELF) >=
215 access ? "granted" : "denied", 0 );
217 return( (b->a_access & ~ACL_SELF)
222 if ( regex_matches( b->a_dnpat, odn ) ) {
223 if ( odn ) free( odn );
224 Debug( LDAP_DEBUG_ACL,
225 "<= acl: matched by clause #%d access %s\n",
226 i, (b->a_access & ~ACL_SELF) >= access ?
227 "granted" : "denied", 0 );
229 return( (b->a_access & ~ACL_SELF)
234 if ( b->a_addrpat != NULL ) {
235 if ( regex_matches( b->a_addrpat, conn->c_addr ) ) {
236 if ( odn ) free( odn );
237 Debug( LDAP_DEBUG_ACL,
238 "<= acl: matched by clause #%d access %s\n",
239 i, (b->a_access & ~ACL_SELF) >= access ?
240 "granted" : "denied", 0 );
242 return( (b->a_access & ~ACL_SELF) >= access );
245 if ( b->a_domainpat != NULL ) {
246 if ( regex_matches( b->a_domainpat, conn->c_domain ) ) {
247 if ( odn ) free( odn );
248 Debug( LDAP_DEBUG_ACL,
249 "<= acl: matched by clause #%d access %s\n",
250 i, (b->a_access & ~ACL_SELF) >= access ?
251 "granted" : "denied", 0 );
253 return( (b->a_access & ~ACL_SELF) >= access );
256 if ( b->a_dnattr != NULL && op->o_dn != NULL ) {
257 /* see if asker is listed in dnattr */
258 if ( (at = attr_find( e->e_attrs, b->a_dnattr ))
259 != NULL && value_find( at->a_vals, &bv,
260 at->a_syntax, 3 ) == 0 )
262 if ( (b->a_access & ACL_SELF) && (val == NULL
263 || value_cmp( &bv, val, at->a_syntax,
268 if ( odn ) free( odn );
269 Debug( LDAP_DEBUG_ACL,
270 "<= acl: matched by clause #%d access %s\n",
271 i, (b->a_access & ~ACL_SELF) >= access ?
272 "granted" : "denied", 0 );
274 return( (b->a_access & ~ACL_SELF) >= access );
277 /* asker not listed in dnattr - check for self access */
278 if ( ! (b->a_access & ACL_SELF) || val == NULL ||
279 value_cmp( &bv, val, at->a_syntax, 2 ) != 0 ) {
283 if ( odn ) free( odn );
284 Debug( LDAP_DEBUG_ACL,
285 "<= acl: matched by clause #%d (self) access %s\n",
286 i, (b->a_access & ~ACL_SELF) >= access ? "granted"
289 return( (b->a_access & ~ACL_SELF) >= access );
293 if ( odn ) free( odn );
294 Debug( LDAP_DEBUG_ACL, "<= acl: %s by default (no matching by)\n",
295 default_access >= access ? "granted" : "denied", 0, 0 );
297 return( default_access >= access );
301 * acl_check_mods - check access control on the given entry to see if
302 * it allows the given modifications by the user associated with op.
303 * returns LDAP_SUCCESS mods allowed ok
304 * anything else mods not allowed - return is an error
305 * code indicating the problem
320 for ( ; mods != NULL; mods = mods->mod_next ) {
321 if ( strcasecmp( mods->mod_type, "modifiersname" ) == 0 ||
322 strcasecmp( mods->mod_type, "modifytimestamp" ) == 0 ) {
326 a = acl_get_applicable( be, op, e, mods->mod_type );
328 switch ( mods->mod_op & ~LDAP_MOD_BVALUES ) {
329 case LDAP_MOD_REPLACE:
331 if ( mods->mod_bvalues == NULL ) {
334 for ( i = 0; mods->mod_bvalues[i] != NULL; i++ ) {
335 if ( ! acl_access_allowed( a, be, conn, e,
336 mods->mod_bvalues[i], op, ACL_WRITE ) ) {
337 return( LDAP_INSUFFICIENT_ACCESS );
342 case LDAP_MOD_DELETE:
343 if ( mods->mod_bvalues == NULL ) {
344 if ( ! acl_access_allowed( a, be, conn, e,
345 NULL, op, ACL_WRITE ) ) {
346 return( LDAP_INSUFFICIENT_ACCESS );
350 for ( i = 0; mods->mod_bvalues[i] != NULL; i++ ) {
351 if ( ! acl_access_allowed( a, be, conn, e,
352 mods->mod_bvalues[i], op, ACL_WRITE ) ) {
353 return( LDAP_INSUFFICIENT_ACCESS );
360 return( LDAP_SUCCESS );
366 regex_matches( char *pat, char *str )
371 if ( (e = compile( pat, NULL, NULL )) == NULL ) {
372 Debug( LDAP_DEBUG_ANY,
373 "compile( \"%s\", \"%s\") failed\n", pat, str, 0 );
376 rc = step( str ? str : "", e );
385 regex_matches( char *pat, char *str )
390 pthread_mutex_lock( ®ex_mutex );
391 if ( (e = re_comp( pat )) != NULL ) {
392 Debug( LDAP_DEBUG_ANY,
393 "re_comp( \"%s\", \"%s\") failed because (%s)\n", pat, str,
395 pthread_mutex_unlock( ®ex_mutex );
398 rc = re_exec( str ? str : "" );
399 pthread_mutex_unlock( ®ex_mutex );