]> git.sur5r.net Git - openldap/blobdiff - servers/slapd/search.c
Extend value_match to extract an asserted value from a full value
[openldap] / servers / slapd / search.c
index 0112a4515df66d4eb4f8c1c1f8f82ef5f6b3ee42..63379e60b6a5d1c97ecc97773712fc02c779960f 100644 (file)
@@ -27,7 +27,7 @@
 
 int
 do_search(
-    Connection *conn,  /* where to send results                       */
+    Connection *conn,  /* where to send results */
     Operation  *op     /* info about the op to which we're responding */
 ) {
        int             i;
@@ -164,7 +164,7 @@ do_search(
                goto return_results;
        } 
 
-       rc = 0;
+       rc = LDAP_SUCCESS;
 
 #ifdef NEW_LOGGING
        LDAP_LOG(( "operation", LDAP_LEVEL_ARGS,
@@ -192,55 +192,44 @@ do_search(
        Debug( LDAP_DEBUG_ARGS, "\n", 0, 0, 0 );
 #endif
 
-
        Statslog( LDAP_DEBUG_STATS,
            "conn=%ld op=%d SRCH base=\"%s\" scope=%d filter=\"%s\"\n",
            op->o_connid, op->o_opid, base, scope, fstr );
 
        manageDSAit = get_manageDSAit( op );
 
-       if( scope != LDAP_SCOPE_BASE && nbase[0] == '\0' &&
-               default_search_nbase != NULL )
-       {
-               ch_free( base );
-               ch_free( nbase );
-               base = ch_strdup( default_search_base );
-               nbase = ch_strdup( default_search_nbase );
-       }
-
-       /* Select backend */
-       be = select_backend( nbase, manageDSAit );
-
-       /* check restrictions */
-       rc = backend_check_restrictions( be, conn, op, NULL, &text ) ;
-       if( rc != LDAP_SUCCESS ) {
-               send_ldap_result( conn, op, rc,
-                       NULL, text, NULL, NULL );
-               goto return_results;
-       }
-
        if ( scope == LDAP_SCOPE_BASE ) {
                Entry *entry = NULL;
 
                if ( strcasecmp( nbase, LDAP_ROOT_DSE ) == 0 ) {
-                       rc = root_dse_info( conn, &entry, &text );
-               }
-
-#if defined( SLAPD_MONITOR_DN )
-               else if ( strcasecmp( nbase, SLAPD_MONITOR_DN ) == 0 ) {
-                       rc = monitor_info( &entry, &text );
-               }
+#ifdef LDAP_CONNECTIONLESS
+                       /* Ignore LDAPv2 CLDAP DSE queries */
+                       if (op->o_protocol==LDAP_VERSION2 && conn->c_is_udp) {
+                               goto return_results;
+                       }
 #endif
+                       /* check restrictions */
+                       rc = backend_check_restrictions( NULL, conn, op, NULL, &text ) ;
+                       if( rc != LDAP_SUCCESS ) {
+                               send_ldap_result( conn, op, rc,
+                                       NULL, text, NULL, NULL );
+                               goto return_results;
+                       }
 
-#if defined( SLAPD_CONFIG_DN )
-               else if ( strcasecmp( nbase, SLAPD_CONFIG_DN ) == 0 ) {
-                       rc = config_info( &entry, &text );
+                       rc = root_dse_info( conn, &entry, &text );
                }
-#endif
 
 #if defined( SLAPD_SCHEMA_DN )
                else if ( strcasecmp( nbase, SLAPD_SCHEMA_DN ) == 0 ) {
-                       rc= schema_info( &entry, &text );
+                       /* check restrictions */
+                       rc = backend_check_restrictions( NULL, conn, op, NULL, &text ) ;
+                       if( rc != LDAP_SUCCESS ) {
+                               send_ldap_result( conn, op, rc,
+                                       NULL, text, NULL, NULL );
+                               goto return_results;
+                       }
+
+                       rc = schema_info( &entry, &text );
                }
 #endif
 
@@ -266,14 +255,33 @@ do_search(
                }
        }
 
-       if ( be == NULL ) {
-               /* no backend, return a referral (or noSuchObject) */
+       if( nbase[0] == '\0' && default_search_nbase != NULL ) {
+               ch_free( base );
+               ch_free( nbase );
+               base = ch_strdup( default_search_base );
+               nbase = ch_strdup( default_search_nbase );
+       }
+
+       /*
+        * We could be serving multiple database backends.  Select the
+        * appropriate one, or send a referral to our "referral server"
+        * if we don't hold it.
+        */
+       if ( (be = select_backend( nbase, manageDSAit )) == NULL ) {
                send_ldap_result( conn, op, rc = LDAP_REFERRAL,
                        NULL, NULL, default_referral, NULL );
 
                goto return_results;
        }
 
+       /* check restrictions */
+       rc = backend_check_restrictions( be, conn, op, NULL, &text ) ;
+       if( rc != LDAP_SUCCESS ) {
+               send_ldap_result( conn, op, rc,
+                       NULL, text, NULL, NULL );
+               goto return_results;
+       }
+
        /* check for referrals */
        rc = backend_check_referrals( be, conn, op, base, nbase );
        if ( rc != LDAP_SUCCESS ) {