1 /* dyngroup.c - Demonstration of overlay code */
3 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
5 * Copyright 2003-2007 The OpenLDAP Foundation.
6 * Copyright 2003 by Howard Chu.
9 * Redistribution and use in source and binary forms, with or without
10 * modification, are permitted only as authorized by the OpenLDAP
13 * A copy of this license is available in the file LICENSE in the
14 * top-level directory of the distribution or, alternatively, at
15 * <http://www.OpenLDAP.org/license.html>.
18 * This work was initially developed by Howard Chu for inclusion in
24 #ifdef SLAPD_OVER_DYNGROUP
28 #include <ac/string.h>
29 #include <ac/socket.h>
33 /* This overlay extends the Compare operation to detect members of a
34 * dynamic group. It has no effect on any other operations. It must
35 * be configured with a pair of attributes to trigger on, e.g.
36 * attrpair member memberURL
37 * will cause compares on "member" to trigger a compare on "memberURL".
40 typedef struct adpair {
41 struct adpair *ap_next;
42 AttributeDescription *ap_mem;
43 AttributeDescription *ap_uri;
47 dyngroup_response( Operation *op, SlapReply *rs )
49 slap_overinst *on = (slap_overinst *) op->o_bd->bd_info;
50 adpair *ap = on->on_bi.bi_private;
52 /* If we've been configured and the current response is
53 * what we're looking for...
55 if ( ap && op->o_tag == LDAP_REQ_COMPARE &&
56 rs->sr_err == LDAP_NO_SUCH_ATTRIBUTE ) {
58 for (;ap;ap=ap->ap_next) {
59 if ( op->oq_compare.rs_ava->aa_desc == ap->ap_mem ) {
60 /* This compare is for one of the attributes we're
61 * interested in. We'll use slapd's existing dyngroup
62 * evaluator to get the answer we want.
64 int cache = op->o_do_not_cache;
66 op->o_do_not_cache = 1;
67 rs->sr_err = backend_group( op, NULL, &op->o_req_ndn,
68 &op->oq_compare.rs_ava->aa_value, NULL, ap->ap_uri );
69 op->o_do_not_cache = cache;
70 switch ( rs->sr_err ) {
72 rs->sr_err = LDAP_COMPARE_TRUE;
75 case LDAP_NO_SUCH_OBJECT:
76 rs->sr_err = LDAP_COMPARE_FALSE;
83 /* Default is to just fall through to the normal processing */
84 return SLAP_CB_CONTINUE;
87 static int dyngroup_config(
95 slap_overinst *on = (slap_overinst *) be->bd_info;
96 adpair ap = { NULL, NULL, NULL }, *a2;
98 if ( strcasecmp( argv[0], "attrpair" ) == 0 ) {
101 Debug( LDAP_DEBUG_ANY, "%s: line %d: "
102 "attribute description missing in "
103 "\"attrpair <member-attribute> <URL-attribute>\" line.\n",
107 if ( slap_str2ad( argv[1], &ap.ap_mem, &text ) ) {
108 Debug( LDAP_DEBUG_ANY, "%s: line %d: "
109 "attribute description unknown \"attrpair\" line: %s.\n",
110 fname, lineno, text );
113 if ( slap_str2ad( argv[2], &ap.ap_uri, &text ) ) {
114 Debug( LDAP_DEBUG_ANY, "%s: line %d: "
115 "attribute description unknown \"attrpair\" line: %s.\n",
116 fname, lineno, text );
119 /* The on->on_bi.bi_private pointer can be used for
120 * anything this instance of the overlay needs.
123 a2 = ch_malloc( sizeof(adpair) );
124 a2->ap_next = on->on_bi.bi_private;
125 a2->ap_mem = ap.ap_mem;
126 a2->ap_uri = ap.ap_uri;
127 on->on_bi.bi_private = a2;
129 return SLAP_CONF_UNKNOWN;
139 slap_overinst *on = (slap_overinst *) be->bd_info;
142 for ( ap = on->on_bi.bi_private; ap; ap = a2 ) {
149 static slap_overinst dyngroup;
151 /* This overlay is set up for dynamic loading via moduleload. For static
152 * configuration, you'll need to arrange for the slap_overinst to be
153 * initialized and registered by some other function inside slapd.
156 int dyngroup_initialize() {
157 dyngroup.on_bi.bi_type = "dyngroup";
158 dyngroup.on_bi.bi_db_config = dyngroup_config;
159 dyngroup.on_bi.bi_db_close = dyngroup_close;
160 dyngroup.on_response = dyngroup_response;
162 return overlay_register( &dyngroup );
165 #if SLAPD_OVER_DYNGROUP == SLAPD_MOD_DYNAMIC
167 init_module( int argc, char *argv[] )
169 return dyngroup_initialize();
173 #endif /* defined(SLAPD_OVER_DYNGROUP) */