]> git.sur5r.net Git - openldap/commit
saslAuthzTo/From stuff
authorPierangelo Masarati <ando@openldap.org>
Sat, 13 Dec 2003 23:02:59 +0000 (23:02 +0000)
committerPierangelo Masarati <ando@openldap.org>
Sat, 13 Dec 2003 23:02:59 +0000 (23:02 +0000)
commit4602c935f7e9a1ffc2d9b4602e90590d8f665432
treebd715266ea76b38f09304ec00f7dfa7167f29d0a
parent0d8613c27458d7940ab0bfbbc115a8ccf7c4e14b
saslAuthzTo/From stuff

when comparing IDs to saslAuthzTo/From values, the saslAuthzTo
saslAuthzFrom values can take different forms:

dn[.<style>]:<pattern>

<style> ::=  exact ; exact match
children ; children of <pattern> match
subtree ; <pattern> or children of <pattern> match
regex ; <pattern> is regcomp() & regexec()
if no <style>, then exact is assumed

u[.<mech>][/<realm>]:<user>

when parsing a proxyAuthz value, only exact DN is allowed,
and no <mech> can be specified.  <user> cannot contain ':'
and <mech> cannot contain '/'.
servers/slapd/controls.c
servers/slapd/proto-slap.h
servers/slapd/sasl.c
servers/slapd/saslauthz.c
servers/slapd/tools/mimic.c