1 /* denyop.c - Denies operations */
2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
4 * Copyright 2004 The OpenLDAP Foundation.
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted only as authorized by the OpenLDAP
11 * A copy of this license is available in the file LICENSE in the
12 * top-level directory of the distribution or, alternatively, at
13 * <http://www.OpenLDAP.org/license.html>.
16 * This work was initially developed by Pierangelo Masarati for inclusion in
22 #ifdef SLAPD_OVER_DENYOP
26 #include <ac/string.h>
27 #include <ac/socket.h>
31 /* This overlay provides a quick'n'easy way to deny selected operations
32 * for a database whose backend implements the operations. It is intended
33 * to be less expensive than ACLs because its evaluation occurs before
34 * any backend specific operation is actually even initiated.
49 typedef struct denyop_info {
50 int do_op[denyop_unbind + 1];
54 denyop_func( Operation *op, SlapReply *rs )
56 slap_overinst *on = (slap_overinst *) op->o_bd->bd_info;
57 denyop_info *oi = (denyop_info *)on->on_bi.bi_private;
62 deny = oi->do_op[denyop_bind];
66 deny = oi->do_op[denyop_add];
70 deny = oi->do_op[denyop_delete];
74 deny = oi->do_op[denyop_modrdn];
78 deny = oi->do_op[denyop_modify];
81 case LDAP_REQ_COMPARE:
82 deny = oi->do_op[denyop_compare];
86 deny = oi->do_op[denyop_search];
89 case LDAP_REQ_EXTENDED:
90 deny = oi->do_op[denyop_extended];
94 deny = oi->do_op[denyop_unbind];
99 return SLAP_CB_CONTINUE;
102 op->o_bd->bd_info = (BackendInfo *)on->on_info;
103 send_ldap_error( op, rs, LDAP_UNWILLING_TO_PERFORM,
104 "operation not allowed within namingContext" );
114 slap_overinst *on = (slap_overinst *) be->bd_info;
117 oi = (denyop_info *)ch_malloc(sizeof(denyop_info));
118 memset(oi, 0, sizeof(denyop_info));
119 on->on_bi.bi_private = oi;
133 slap_overinst *on = (slap_overinst *) be->bd_info;
134 denyop_info *oi = (denyop_info *)on->on_bi.bi_private;
136 if ( strcasecmp( argv[0], "denyop" ) == 0 ) {
140 Debug( LDAP_DEBUG_ANY, "%s: line %d: "
141 "operation list missing in "
142 "\"denyop <op-list>\" line.\n",
147 /* The on->on_bi.bi_private pointer can be used for
148 * anything this instance of the overlay needs.
153 char *next = strchr( op, ',' );
160 if ( strcmp( op, "add" ) == 0 ) {
161 oi->do_op[denyop_add] = 1;
163 } else if ( strcmp( op, "bind" ) == 0 ) {
164 oi->do_op[denyop_bind] = 1;
166 } else if ( strcmp( op, "compare" ) == 0 ) {
167 oi->do_op[denyop_compare] = 1;
169 } else if ( strcmp( op, "delete" ) == 0 ) {
170 oi->do_op[denyop_delete] = 1;
172 } else if ( strcmp( op, "extended" ) == 0 ) {
173 oi->do_op[denyop_extended] = 1;
175 } else if ( strcmp( op, "modify" ) == 0 ) {
176 oi->do_op[denyop_modify] = 1;
178 } else if ( strcmp( op, "modrdn" ) == 0 ) {
179 oi->do_op[denyop_modrdn] = 1;
181 } else if ( strcmp( op, "search" ) == 0 ) {
182 oi->do_op[denyop_search] = 1;
184 } else if ( strcmp( op, "unbind" ) == 0 ) {
185 oi->do_op[denyop_unbind] = 1;
188 Debug( LDAP_DEBUG_ANY, "%s: line %d: "
189 "unknown operation \"%s\" at "
190 "\"denyop <op-list>\" line.\n",
199 return SLAP_CONF_UNKNOWN;
209 slap_overinst *on = (slap_overinst *) be->bd_info;
210 denyop_info *oi = (denyop_info *)on->on_bi.bi_private;
219 /* This overlay is set up for dynamic loading via moduleload. For static
220 * configuration, you'll need to arrange for the slap_overinst to be
221 * initialized and registered by some other function inside slapd.
224 static slap_overinst denyop;
229 memset( &denyop, 0, sizeof( slap_overinst ) );
230 denyop.on_bi.bi_type = "denyop";
231 denyop.on_bi.bi_db_init = denyop_over_init;
232 denyop.on_bi.bi_db_config = denyop_config;
233 denyop.on_bi.bi_db_destroy = denyop_destroy;
235 denyop.on_bi.bi_op_bind = denyop_func;
236 denyop.on_bi.bi_op_search = denyop_func;
237 denyop.on_bi.bi_op_compare = denyop_func;
238 denyop.on_bi.bi_op_modify = denyop_func;
239 denyop.on_bi.bi_op_modrdn = denyop_func;
240 denyop.on_bi.bi_op_add = denyop_func;
241 denyop.on_bi.bi_op_delete = denyop_func;
242 denyop.on_bi.bi_extended = denyop_func;
243 denyop.on_bi.bi_op_unbind = denyop_func;
245 denyop.on_response = NULL /* denyop_response */ ;
247 return overlay_register( &denyop );
250 #if SLAPD_OVER_DENYOP == SLAPD_MOD_DYNAMIC
252 init_module( int argc, char *argv[] )
254 return denyop_init();
256 #endif /* SLAPD_OVER_DENYOP == SLAPD_MOD_DYNAMIC */
258 #endif /* defined(SLAPD_OVER_DENYOP) */