/* filterentry.c - apply a filter to an entry */
/* $OpenLDAP$ */
/*
- * Copyright 1998-2002 The OpenLDAP Foundation, All Rights Reserved.
+ * Copyright 1998-2003 The OpenLDAP Foundation, All Rights Reserved.
* COPYING RESTRICTIONS APPLY, see COPYRIGHT file
*/
a = attrs_find( a->a_next, mra->ma_desc ) )
{
struct berval *bv;
- for ( bv = a->a_vals; bv->bv_val != NULL; bv++ ) {
+#ifdef SLAP_NVALUES
+ for ( bv = a->a_nvals ? a->a_nvals : a->a_vals;
+ bv->bv_val != NULL; bv++ )
+#else
+ for ( bv = a->a_vals; bv->bv_val != NULL; bv++ )
+#endif
+ {
int ret;
int rc;
const char *text;
- rc = value_match( &ret, a->a_desc, mra->ma_rule,
- SLAP_MR_ASSERTION_SYNTAX_MATCH,
+ rc = value_match( &ret, a->a_desc, mra->ma_rule, 0,
bv, &mra->ma_value, &text );
if( rc != LDAP_SUCCESS ) {
}
/* normalize for equality */
+#ifdef SLAP_NVALUES
+ rc = asserted_value_validate_normalize( a->a_desc, mra->ma_rule,
+ SLAP_MR_EXT|SLAP_MR_VALUE_OF_ASSERTION_SYNTAX,
+ &mra->ma_value, &value, &text );
+#else
rc = value_validate_normalize( a->a_desc,
SLAP_MR_EQUALITY,
&mra->ma_value, &value, &text );
+#endif
if ( rc != LDAP_SUCCESS ) {
continue;
}
}
/* check match */
- for ( bv = a->a_vals; bv->bv_val != NULL; bv++ ) {
+#ifdef SLAP_NVALUES
+ for ( bv = a->a_nvals ? a->a_nvals : a->a_vals;
+ bv->bv_val != NULL; bv++ )
+#else
+ for ( bv = a->a_vals; bv->bv_val != NULL; bv++ )
+#endif
+ {
int ret;
int rc;
- rc = value_match( &ret, a->a_desc, mra->ma_rule,
- SLAP_MR_ASSERTION_SYNTAX_MATCH,
+ rc = value_match( &ret, a->a_desc, mra->ma_rule, 0,
bv, &value, &text );
if( rc != LDAP_SUCCESS ) {
}
/* normalize for equality */
+#ifdef SLAP_NVALUES
+ rc = asserted_value_validate_normalize( ad,
+ mra->ma_rule,
+ SLAP_MR_EXT|SLAP_MR_VALUE_OF_ASSERTION_SYNTAX,
+ &mra->ma_value, &value, &text );
+#else
rc = value_validate_normalize( ad, SLAP_MR_EQUALITY,
&mra->ma_value, &value, &text );
+#endif
if ( rc != LDAP_SUCCESS ) {
continue;
}
}
/* check match */
- rc = value_match( &ret, ad, mra->ma_rule,
- SLAP_MR_ASSERTION_SYNTAX_MATCH,
+ rc = value_match( &ret, ad, mra->ma_rule, 0,
bv, &value, &text );
if( rc != LDAP_SUCCESS ) {
continue;
}
- for ( bv = a->a_vals; bv->bv_val != NULL; bv++ ) {
+#ifdef SLAP_NVALUES
+ for ( bv = a->a_nvals ? a->a_nvals : a->a_vals;
+ bv->bv_val != NULL; bv++ )
+#else
+ for ( bv = a->a_vals; bv->bv_val != NULL; bv++ )
+#endif
+ {
int ret;
int rc;
const char *text;
- rc = value_match( &ret, a->a_desc, mr,
- SLAP_MR_ASSERTION_SYNTAX_MATCH,
+ rc = value_match( &ret, a->a_desc, mr, 0,
bv, &ava->aa_value, &text );
if( rc != LDAP_SUCCESS ) {
}
}
+ if ( ava->aa_desc == slap_schema.si_ad_hasSubordinates
+ && be && be->be_has_subordinates ) {
+ int hasSubordinates;
+ struct berval hs;
+
+ /*
+ * No other match should be allowed ...
+ */
+ assert( type == LDAP_FILTER_EQUALITY );
+
+ if ( (*be->be_has_subordinates)( be, conn, op, e, &hasSubordinates ) ) {
+ return LDAP_OTHER;
+ }
+
+ if ( hasSubordinates == LDAP_COMPARE_TRUE ) {
+ hs.bv_val = "TRUE";
+ hs.bv_len = sizeof( "TRUE" ) - 1;
+
+ } else if ( hasSubordinates == LDAP_COMPARE_FALSE ) {
+ hs.bv_val = "FALSE";
+ hs.bv_len = sizeof( "FALSE" ) - 1;
+
+ } else {
+ return LDAP_OTHER;
+ }
+
+ if ( bvmatch( &ava->aa_value, &hs ) ) {
+ return LDAP_COMPARE_TRUE;
+ }
+
+ return LDAP_COMPARE_FALSE;
+ }
+
return( LDAP_COMPARE_FALSE );
}
AttributeDescription *desc
)
{
+ Attribute *a;
+
if ( !access_allowed( be, conn, op, e, desc, NULL, ACL_SEARCH, NULL ) )
{
return LDAP_INSUFFICIENT_ACCESS;
}
- return attrs_find( e->e_attrs, desc ) != NULL
- ? LDAP_COMPARE_TRUE : LDAP_COMPARE_FALSE;
+ a = attrs_find( e->e_attrs, desc );
+
+ if ( a == NULL && desc == slap_schema.si_ad_hasSubordinates ) {
+
+ /*
+ * XXX: fairly optimistic: if the function is defined,
+ * then PRESENCE must succeed, because hasSubordinate
+ * is boolean-valued; I think we may live with this
+ * simplification by now
+ */
+ if ( be && be->be_has_subordinates ) {
+ return LDAP_COMPARE_TRUE;
+ }
+
+ return LDAP_COMPARE_FALSE;
+ }
+
+ return a != NULL ? LDAP_COMPARE_TRUE : LDAP_COMPARE_FALSE;
}
continue;
}
- for ( bv = a->a_vals; bv->bv_val != NULL; bv++ ) {
+#ifdef SLAP_NVALUES
+ for ( bv = a->a_nvals ? a->a_nvals : a->a_vals;
+ bv->bv_val != NULL; bv++ )
+#else
+ for ( bv = a->a_vals; bv->bv_val != NULL; bv++ )
+#endif
+ {
int ret;
int rc;
const char *text;
- rc = value_match( &ret, a->a_desc, mr,
- SLAP_MR_ASSERTION_SYNTAX_MATCH,
+ rc = value_match( &ret, a->a_desc, mr, 0,
bv, f->f_sub, &text );
if( rc != LDAP_SUCCESS ) {