]> git.sur5r.net Git - openldap/blobdiff - libraries/librewrite/ldapmap.c
Merge remote branch 'origin/mdb.master'
[openldap] / libraries / librewrite / ldapmap.c
index 16db729a0decef05c4ae5c93ffdec26d1d901bcc..6041b2e80f2729fda27933b7e5c1df710eb0d1de 100644 (file)
@@ -1,51 +1,54 @@
-/******************************************************************************
+/* $OpenLDAP$ */
+/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
  *
- * Copyright (C) 2000 Pierangelo Masarati, <ando@sys-net.it>
+ * Copyright 2000-2011 The OpenLDAP Foundation.
  * All rights reserved.
  *
- * Permission is granted to anyone to use this software for any purpose
- * on any computer system, and to alter it and redistribute it, subject
- * to the following restrictions:
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted only as authorized by the OpenLDAP
+ * Public License.
  *
- * 1. The author is not responsible for the consequences of use of this
- * software, no matter how awful, even if they arise from flaws in it.
- *
- * 2. The origin of this software must not be misrepresented, either by
- * explicit claim or by omission.  Since few users ever read sources,
- * credits should appear in the documentation.
- *
- * 3. Altered versions must be plainly marked as such, and must not be
- * misrepresented as being the original software.  Since few users
- * ever read sources, credits should appear in the documentation.
- * 
- * 4. This notice may not be removed or altered.
- *
- ******************************************************************************/
+ * A copy of this license is available in the file LICENSE in the
+ * top-level directory of the distribution or, alternatively, at
+ * <http://www.OpenLDAP.org/license.html>.
+ */
+/* ACKNOWLEDGEMENT:
+ * This work was initially developed by Pierangelo Masarati for
+ * inclusion in OpenLDAP Software.
+ */
 
 #include <portable.h>
 
+#define LDAP_DEPRECATED 1
 #include "rewrite-int.h"
 #include "rewrite-map.h"
 
+typedef enum {
+       MAP_LDAP_UNKNOWN,
+       MAP_LDAP_EVERYTIME,
+       MAP_LDAP_NOW,
+       MAP_LDAP_LATER
+} bindwhen_t;
+
 /*
  * LDAP map data structure
  */
 struct ldap_map_data {
-       char                           *url;
-       LDAPURLDesc                    *lud;
-       int                             attrsonly;
-       char                           *binddn;
-       char                           *bindpw;
+       char                           *lm_url;
+       LDAPURLDesc                    *lm_lud;
+       int                             lm_version;
+       char                           *lm_binddn;
+       struct berval                   lm_cred;
+
+       bindwhen_t                      lm_when;
 
-#define MAP_LDAP_EVERYTIME             0x00
-#define MAP_LDAP_NOW                   0x01
-#define MAP_LDAP_LATER                 0x02
-       int                             when;
+       LDAP                           *lm_ld;
 
-       LDAP                           *ld;
+       int                             lm_wantdn;
+       char                            *lm_attrs[ 2 ];
 
 #ifdef USE_REWRITE_LDAP_PVT_THREADS
-       ldap_pvt_thread_mutex_t         mutex;
+       ldap_pvt_thread_mutex_t         lm_mutex;
 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
 };
 
@@ -56,32 +59,34 @@ map_ldap_free(
 {
        assert( data != NULL );
 
-       if ( data->url != NULL ) {
-               free( data->url );
+       if ( data->lm_url != NULL ) {
+               free( data->lm_url );
        }
 
-       if ( data->lud != NULL ) {
-               ldap_free_urldesc( data->lud );
+       if ( data->lm_lud != NULL ) {
+               ldap_free_urldesc( data->lm_lud );
        }
 
-       if ( data->binddn != NULL ) {
-               free( data->binddn );
+       if ( data->lm_binddn != NULL ) {
+               free( data->lm_binddn );
        }
 
-       if ( data->bindpw != NULL ) {
-               free( data->bindpw );
+       if ( data->lm_cred.bv_val != NULL ) {
+               memset( data->lm_cred.bv_val, 0, data->lm_cred.bv_len );
+               free( data->lm_cred.bv_val );
+               data->lm_cred.bv_val = NULL;
+               data->lm_cred.bv_len = 0;
        }
 
-       if ( data->when != MAP_LDAP_EVERYTIME && data->ld != NULL ) {
-               ldap_unbind_s( data->ld );
+       if ( data->lm_when != MAP_LDAP_EVERYTIME && data->lm_ld != NULL ) {
+               ldap_unbind_ext( data->lm_ld, NULL, NULL );
        }
 
        free( data );
 }
 
-void *
+static void *
 map_ldap_parse(
-               struct rewrite_info *info,
                const char *fname,
                int lineno,
                int argc,
@@ -89,9 +94,8 @@ map_ldap_parse(
 )
 {
        struct ldap_map_data *data;
-       char *p;
+       char *p, *uri;
 
-       assert( info != NULL );
        assert( fname != NULL );
        assert( argv != NULL );
 
@@ -108,13 +112,18 @@ map_ldap_parse(
                return NULL;
        }
 
-       data->url = strdup( argv[ 0 ] );
-       if ( data->url == NULL ) {
+       uri = argv[ 0 ];
+       if ( strncasecmp( uri, "uri=", STRLENOF( "uri=" ) ) == 0 ) {
+               uri += STRLENOF( "uri=" );
+       }
+
+       data->lm_url = strdup( uri );
+       if ( data->lm_url == NULL ) {
                map_ldap_free( data );
                return NULL;
        }
        
-       if ( ldap_url_parse( argv[ 0 ], &data->lud ) != REWRITE_SUCCESS ) {
+       if ( ldap_url_parse( uri, &data->lm_lud ) != REWRITE_SUCCESS ) {
                Debug( LDAP_DEBUG_ANY,
                                "[%s:%d] illegal URI '%s'\n",
                                fname, lineno, argv[ 0 ] );
@@ -122,19 +131,48 @@ map_ldap_parse(
                return NULL;
        }
 
-       p = strchr( data->url, '/' );
+       /* trim everything after [host][:port] */
+       p = strchr( data->lm_url, '/' );
        assert( p[ 1 ] == '/' );
        if ( ( p = strchr( p + 2, '/' ) ) != NULL ) {
                p[ 0 ] = '\0';
        }
 
-       if ( strcasecmp( data->lud->lud_attrs[ 0 ], "dn" ) == 0 ) {
-               data->attrsonly = 1;
+       if ( data->lm_lud->lud_attrs == NULL ) {
+               data->lm_attrs[ 0 ] = LDAP_NO_ATTRS;
+               data->lm_wantdn = 1;
+
+       } else {
+               if ( data->lm_lud->lud_attrs[ 1 ] != NULL ) {
+                       Debug( LDAP_DEBUG_ANY,
+                               "[%s:%d] only one attribute allowed in URI\n",
+                               fname, lineno, 0 );
+                       map_ldap_free( data );
+                       return NULL;
+               }
+
+               if ( strcasecmp( data->lm_lud->lud_attrs[ 0 ], "dn" ) == 0
+                       || strcasecmp( data->lm_lud->lud_attrs[ 0 ], "entryDN" ) == 0 )
+               {
+                       ldap_memfree( data->lm_lud->lud_attrs[ 0 ] );
+                       ldap_memfree( data->lm_lud->lud_attrs );
+                       data->lm_lud->lud_attrs = NULL;
+                       data->lm_attrs[ 0 ] = LDAP_NO_ATTRS;
+                       data->lm_wantdn = 1;
+
+               } else {
+                       data->lm_attrs[ 0 ] = data->lm_lud->lud_attrs[ 0 ];
+               }
        }
-             
+
+       data->lm_attrs[ 1 ] = NULL;
+
+       /* safe defaults */
+       data->lm_version = LDAP_VERSION3;
+
        for ( argc--, argv++; argc > 0; argc--, argv++ ) {
-               if ( strncasecmp( argv[ 0 ], "binddn=", 7 ) == 0 ) {
-                       char *p = argv[ 0 ] + 7;
+               if ( strncasecmp( argv[ 0 ], "binddn=", STRLENOF( "binddn=" ) ) == 0 ) {
+                       char *p = argv[ 0 ] + STRLENOF( "binddn=" );
                        int l;
 
                        if ( p[ 0 ] == '\"' || p [ 0 ] == '\'' ) {
@@ -148,64 +186,106 @@ map_ldap_parse(
                                l = strlen( p );
                        }
                        
-                       data->binddn = strdup( p );                     
-                       if ( data->binddn == NULL ) {
+                       data->lm_binddn = strdup( p );                  
+                       if ( data->lm_binddn == NULL ) {
                                map_ldap_free( data );
                                return NULL;
                        }
 
-                       if ( data->binddn[ l ] == '\"' 
-                                       || data->binddn[ l ] == '\'' ) {
-                               data->binddn[ l ] = '\0';
+                       if ( data->lm_binddn[ l ] == '\"' 
+                                       || data->lm_binddn[ l ] == '\'' ) {
+                               data->lm_binddn[ l ] = '\0';
+                       }
+
+                       /* deprecated */
+               } else if ( strncasecmp( argv[ 0 ], "bindpw=", STRLENOF( "bindpw=" ) ) == 0 ) {
+                       ber_str2bv( argv[ 0 ] + STRLENOF( "bindpw=" ), 0, 1, &data->lm_cred );
+                       if ( data->lm_cred.bv_val == NULL ) {
+                               map_ldap_free( data );
+                               return NULL;
                        }
-               } else if ( strncasecmp( argv[ 0 ], "bindpw=", 7 ) == 0 ) {
-                       data->bindpw = strdup( argv[ 2 ] + 7 );
-                       if ( data->bindpw == NULL ) {
+
+               } else if ( strncasecmp( argv[ 0 ], "credentials=", STRLENOF( "credentials=" ) ) == 0 ) {
+                       ber_str2bv( argv[ 0 ] + STRLENOF( "credentials=" ), 0, 1, &data->lm_cred );
+                       if ( data->lm_cred.bv_val == NULL ) {
                                map_ldap_free( data );
                                return NULL;
                        }
-               } else if ( strncasecmp( argv[ 0 ], "bindwhen=", 9 ) == 0 ) {
-                       char *p = argv[ 0 ] + 9;
+
+               } else if ( strncasecmp( argv[ 0 ], "bindwhen=", STRLENOF( "bindwhen=" ) ) == 0 ) {
+                       char *p = argv[ 0 ] + STRLENOF( "bindwhen=" );
 
                        if ( strcasecmp( p, "now" ) == 0 ) {
                                int rc;
                                
-                               data->when = MAP_LDAP_NOW;
+                               data->lm_when = MAP_LDAP_NOW;
                                
                                /*
                                 * Init LDAP handler ...
                                 */
-                               rc = ldap_initialize( &data->ld, data->url );
+                               rc = ldap_initialize( &data->lm_ld, data->lm_url );
                                if ( rc != LDAP_SUCCESS ) {
                                        map_ldap_free( data );
                                        return NULL;
                                }
 
+                               ldap_set_option( data->lm_ld,
+                                       LDAP_OPT_PROTOCOL_VERSION,
+                                       (void *)&data->lm_version );
+
 #ifdef USE_REWRITE_LDAP_PVT_THREADS
-                               ldap_pvt_thread_mutex_init( &data->mutex );
+                               ldap_pvt_thread_mutex_init( &data->lm_mutex );
 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
 
                        } else if ( strcasecmp( p, "later" ) == 0 ) {
-                               data->when = MAP_LDAP_LATER;
+                               data->lm_when = MAP_LDAP_LATER;
 
 #ifdef USE_REWRITE_LDAP_PVT_THREADS
-                               ldap_pvt_thread_mutex_init( &data->mutex );
+                               ldap_pvt_thread_mutex_init( &data->lm_mutex );
 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
 
                        } else if ( strcasecmp( p, "everytime" ) == 0 ) {
-                               data->when = MAP_LDAP_EVERYTIME;
+                               data->lm_when = MAP_LDAP_EVERYTIME;
                        } else {
                                /* ignore ... */
                        }
+
+               } else if ( strncasecmp( argv[ 0 ], "version=", STRLENOF( "version=" ) ) == 0 ) {
+                       if ( lutil_atoi( &data->lm_version, argv[ 0 ] + STRLENOF( "version=" ) ) ) {
+                               map_ldap_free( data );
+                               return NULL;
+                       }
+
+                       switch ( data->lm_version ) {
+                       case LDAP_VERSION2:
+                       case LDAP_VERSION3:
+                               break;
+
+                       default:
+                               Debug( LDAP_DEBUG_ANY,
+                                       "[%s:%d] unknown version %s\n",
+                                       fname, lineno, p );
+                               map_ldap_free( data );
+                               return NULL;
+                       }
+
+               } else {
+                       Debug( LDAP_DEBUG_ANY,
+                               "[%s:%d] unknown option %s (ignored)\n",
+                               fname, lineno, argv[0] );
                }
        }
 
+       if ( data->lm_when == MAP_LDAP_UNKNOWN ) {
+               data->lm_when = MAP_LDAP_EVERYTIME;
+       }
+
        return ( void * )data;
 }
 
-int
+static int
 map_ldap_apply(
-               struct rewrite_builtin_map *map,
+               void *private,
                const char *filter,
                struct berval *val
 
@@ -213,36 +293,36 @@ map_ldap_apply(
 {
        LDAP *ld;
        LDAPMessage *res = NULL, *entry;
-       char **values;
        int rc;
-       struct ldap_map_data *data = ( struct ldap_map_data * )map->lb_private;
-       LDAPURLDesc *lud = data->lud;
+       struct ldap_map_data *data = private;
+       LDAPURLDesc *lud = data->lm_lud;
        
-       int first_try = 1;
+       int first_try = 1, set_version = 0;
 
-       assert( map != NULL );
-       assert( map->lb_type == REWRITE_BUILTIN_MAP_LDAP );
-       assert( map->lb_private != NULL );
+       assert( private != NULL );
        assert( filter != NULL );
        assert( val != NULL );
 
        val->bv_val = NULL;
        val->bv_len = 0;
 
-       if ( data->when == MAP_LDAP_EVERYTIME ) {
-               rc = ldap_initialize( &ld, data->url );
+       if ( data->lm_when == MAP_LDAP_EVERYTIME ) {
+               rc = ldap_initialize( &ld, data->lm_url );
+               set_version = 1;
+
        } else {
 #ifdef USE_REWRITE_LDAP_PVT_THREADS
-               ldap_pvt_thread_mutex_lock( &data->mutex );
+               ldap_pvt_thread_mutex_lock( &data->lm_mutex );
 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
 
                rc = LDAP_SUCCESS;
 
-               if ( data->when == MAP_LDAP_LATER && data->ld == NULL ) {
-                       rc = ldap_initialize( &data->ld, data->url );
+               if ( data->lm_when == MAP_LDAP_LATER && data->lm_ld == NULL ) {
+                       rc = ldap_initialize( &data->lm_ld, data->lm_url );
+                       set_version = 1;
                }
                
-               ld = data->ld;
+               ld = data->lm_ld;
        }
 
        if ( rc != LDAP_SUCCESS ) {
@@ -250,32 +330,44 @@ map_ldap_apply(
                goto rc_return;
        }
 
-do_bind:
-       if ( data->binddn != NULL ) {
-               rc = ldap_simple_bind_s( ld, data->binddn, data->bindpw );
+do_bind:;
+       if ( set_version ) {
+               ldap_set_option( ld, LDAP_OPT_PROTOCOL_VERSION,
+                       (void *)&data->lm_version );
+               set_version = 0;
+       }
+
+       if ( data->lm_binddn != NULL ) {
+               rc = ldap_sasl_bind_s( ld, data->lm_binddn,
+                       LDAP_SASL_SIMPLE, &data->lm_cred,
+                       NULL, NULL, NULL );
                if ( rc == LDAP_SERVER_DOWN && first_try ) {
                        first_try = 0;
-                       if ( ldap_initialize( &ld, data->url ) != LDAP_SUCCESS ) {
+                       if ( ldap_initialize( &ld, data->lm_url ) != LDAP_SUCCESS ) {
                                rc = REWRITE_ERR;
                                goto rc_return;
                        }
+                       set_version = 1;
                        goto do_bind;
+
                } else if ( rc != REWRITE_SUCCESS ) {
                        rc = REWRITE_ERR;
                        goto rc_return;
                }
        }
 
-       rc = ldap_search_s( ld, lud->lud_dn, lud->lud_scope, ( char * )filter,
-                       lud->lud_attrs, data->attrsonly, &res );
+       rc = ldap_search_ext_s( ld, lud->lud_dn, lud->lud_scope, ( char * )filter,
+                       data->lm_attrs, 0, NULL, NULL, NULL, 1, &res );
        if ( rc == LDAP_SERVER_DOWN && first_try ) {
                first_try = 0;
-                if ( ldap_initialize( &ld, data->url ) != LDAP_SUCCESS ) {
+                if ( ldap_initialize( &ld, data->lm_url ) != LDAP_SUCCESS ) {
                        rc = REWRITE_ERR;
                        goto rc_return;
                }
+               set_version = 1;
                goto do_bind;
-       } else if ( rc != REWRITE_SUCCESS ) {
+
+       } else if ( rc != LDAP_SUCCESS ) {
                rc = REWRITE_ERR;
                goto rc_return;
        }
@@ -289,23 +381,31 @@ do_bind:
        entry = ldap_first_entry( ld, res );
        assert( entry != NULL );
 
-       if ( data->attrsonly == 1 ) {
+       if ( data->lm_wantdn == 1 ) {
                /*
                 * dn is newly allocated, so there's no need to strdup it
                 */
                val->bv_val = ldap_get_dn( ld, entry );
+               val->bv_len = strlen( val->bv_val );
+
        } else {
-               values = ldap_get_values( ld, entry, lud->lud_attrs[ 0 ] );
-               if ( values == NULL || values[ 0 ] == NULL ) {
-                       if ( values != NULL ) {
-                               ldap_value_free( values );
+               struct berval **values;
+
+               values = ldap_get_values_len( ld, entry, data->lm_attrs[ 0 ] );
+               if ( values != NULL ) {
+                       if ( values[ 0 ] != NULL && values[ 0 ]->bv_val != NULL ) {
+#if 0
+                               /* NOTE: in principle, multiple values
+                                * should not be acceptable according
+                                * to the current API; ignore by now */
+                               if ( values[ 1 ] != NULL ) {
+                                       /* error */                             
+                               }
+#endif
+                               ber_dupbv( val, values[ 0 ] );
                        }
-                       ldap_msgfree( res );
-                       rc = REWRITE_ERR;
-                       goto rc_return;
+                       ldap_value_free_len( values );
                }
-               val->bv_val = strdup( values[ 0 ] );
-               ldap_value_free( values );
        }
        
        ldap_msgfree( res );
@@ -314,20 +414,41 @@ do_bind:
                rc = REWRITE_ERR;
                goto rc_return;
        }
-       val->bv_len = strlen( val->bv_val );
 
-rc_return:
-       if ( data->when == MAP_LDAP_EVERYTIME ) {
+rc_return:;
+       if ( data->lm_when == MAP_LDAP_EVERYTIME ) {
                if ( ld != NULL ) {
-                       ldap_unbind_s( ld );
+                       ldap_unbind_ext( ld, NULL, NULL );
                }
+
        } else {
-               data->ld = ld;
+               data->lm_ld = ld;
 #ifdef USE_REWRITE_LDAP_PVT_THREADS
-               ldap_pvt_thread_mutex_unlock( &data->mutex );
+               ldap_pvt_thread_mutex_unlock( &data->lm_mutex );
 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
        }
        
        return rc;
 }
 
+static int
+map_ldap_destroy(
+               void *private
+)
+{
+       struct ldap_map_data *data = private;
+
+       assert( private != NULL );
+       
+       map_ldap_free( data );
+
+       return 0;
+}
+
+const rewrite_mapper rewrite_ldap_mapper = {
+       "ldap",
+       map_ldap_parse,
+       map_ldap_apply,
+       map_ldap_destroy
+};
+