1 /* chain.c - chain LDAP operations */
3 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
5 * Copyright 2003 The OpenLDAP Foundation.
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted only as authorized by the OpenLDAP
12 * A copy of this license is available in the file LICENSE in the
13 * top-level directory of the distribution or, alternatively, at
14 * <http://www.OpenLDAP.org/license.html>.
17 * This work was initially developed by the Howard Chu for inclusion
18 * in OpenLDAP Software.
20 /* This is an altered version */
22 * Copyright 2003, Howard Chu, All rights reserved. <hyc@highlandsun.com>
24 * Permission is granted to anyone to use this software for any purpose
25 * on any computer system, and to alter it and redistribute it, subject
26 * to the following restrictions:
28 * 1. The author is not responsible for the consequences of use of this
29 * software, no matter how awful, even if they arise from flaws in it.
31 * 2. The origin of this software must not be misrepresented, either by
32 * explicit claim or by omission. Since few users ever read sources,
33 * credits should appear in the documentation.
35 * 3. Altered versions must be plainly marked as such, and must not be
36 * misrepresented as being the original software. Since few users
37 * ever read sources, credits should appear in the documentation.
39 * 4. This notice may not be removed or altered.
46 #include <ac/string.h>
47 #include <ac/socket.h>
50 #include "back-ldap.h"
53 ldap_chain_response( Operation *op, SlapReply *rs )
55 slap_overinst *on = (slap_overinst *) op->o_bd->bd_info;
56 void *private = op->o_bd->be_private;
57 slap_callback *sc = op->o_callback;
58 LDAPControl **prev = op->o_ctrls;
59 LDAPControl **ctrls = NULL, authz;
61 int cache = op->o_do_not_cache;
64 struct berval ndn = op->o_ndn;
66 if ( rs->sr_err != LDAP_REFERRAL )
67 return SLAP_CB_CONTINUE;
69 /* currently we assume only one referral destination.
70 * we'll have to parse this in the future.
75 op->o_bd->be_private = on->on_bi.bi_private;
76 op->o_callback = NULL;
78 /* Chaining is performed by a privileged user on behalf
79 * of a normal user, using the ProxyAuthz control. However,
80 * Binds are done separately, on an anonymous session.
82 if ( op->o_tag != LDAP_REQ_BIND ) {
83 for (i=0; prev && prev[i]; i++);
86 /* Add an extra NULL slot */
89 ctrls = op->o_tmpalloc((i+1)*sizeof(LDAPControl *),
91 for (i=0; i <nctrls; i++)
93 ctrls[nctrls] = &authz;
94 ctrls[nctrls+1] = NULL;
95 authz.ldctl_oid = LDAP_CONTROL_PROXY_AUTHZ;
96 authz.ldctl_iscritical = 1;
97 authz.ldctl_value = op->o_dn;
98 if ( op->o_dn.bv_len ) {
99 authzid = op->o_tmpalloc( op->o_dn.bv_len+4,
101 strcpy(authzid, "dn: ");
102 strcpy(authzid+4, op->o_dn.bv_val);
103 authz.ldctl_value.bv_len = op->o_dn.bv_len + 4;
104 authz.ldctl_value.bv_val = authzid;
107 op->o_ndn = op->o_bd->be_rootndn;
110 switch( op->o_tag ) {
111 case LDAP_REQ_BIND: {
112 struct berval rndn = op->o_req_ndn;
113 Connection *conn = op->o_conn;
114 op->o_req_ndn = slap_empty_bv;
116 rc = ldap_back_bind( op, rs );
117 op->o_req_ndn = rndn;
122 rc = ldap_back_add( op, rs );
124 case LDAP_REQ_DELETE:
125 rc = ldap_back_delete( op, rs );
127 case LDAP_REQ_MODRDN:
128 rc = ldap_back_modrdn( op, rs );
130 case LDAP_REQ_MODIFY:
131 rc = ldap_back_modify( op, rs );
133 case LDAP_REQ_COMPARE:
134 rc = ldap_back_compare( op, rs );
136 case LDAP_REQ_SEARCH:
137 rc = ldap_back_search( op, rs );
139 case LDAP_REQ_EXTENDED:
140 rc = ldap_back_extended( op, rs );
143 rc = SLAP_CB_CONTINUE;
146 op->o_do_not_cache = cache;
148 op->o_bd->be_private = private;
151 if ( ctrls ) op->o_tmpfree( ctrls, op->o_tmpmemctx );
152 if ( authzid ) op->o_tmpfree( authzid, op->o_tmpmemctx );
158 static int ldap_chain_config(
166 slap_overinst *on = (slap_overinst *) be->bd_info;
167 void *private = be->be_private;
170 be->be_private = on->on_bi.bi_private;
171 rc = ldap_back_db_config( be, fname, lineno, argc, argv );
172 be->be_private = private;
176 static int ldap_chain_init(
180 slap_overinst *on = (slap_overinst *) be->bd_info;
181 void *private = be->be_private;
184 be->be_private = NULL;
185 rc = ldap_back_db_init( be );
186 on->on_bi.bi_private = be->be_private;
187 be->be_private = private;
191 static int ldap_chain_destroy(
195 slap_overinst *on = (slap_overinst *) be->bd_info;
196 void *private = be->be_private;
199 be->be_private = on->on_bi.bi_private;
200 rc = ldap_back_db_destroy( be );
201 on->on_bi.bi_private = be->be_private;
202 be->be_private = private;
206 static slap_overinst ldapchain;
208 int ldap_chain_setup()
210 ldapchain.on_bi.bi_type = "chain";
211 ldapchain.on_bi.bi_db_init = ldap_chain_init;
212 ldapchain.on_bi.bi_db_config = ldap_chain_config;
213 ldapchain.on_bi.bi_db_destroy = ldap_chain_destroy;
214 ldapchain.on_response = ldap_chain_response;
216 return overlay_register( &ldapchain );