]> git.sur5r.net Git - openldap/blob - servers/slapd/back-monitor/compare.c
New access_allowed()
[openldap] / servers / slapd / back-monitor / compare.c
1 /* compare.c - monitor backend compare routine */
2 /* $OpenLDAP$ */
3 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
4  *
5  * Copyright 2001-2009 The OpenLDAP Foundation.
6  * Portions Copyright 2001-2003 Pierangelo Masarati.
7  * All rights reserved.
8  *
9  * Redistribution and use in source and binary forms, with or without
10  * modification, are permitted only as authorized by the OpenLDAP
11  * Public License.
12  *
13  * A copy of this license is available in file LICENSE in the
14  * top-level directory of the distribution or, alternatively, at
15  * <http://www.OpenLDAP.org/license.html>.
16  */
17 /* ACKNOWLEDGEMENTS:
18  * This work was initially developed by Pierangelo Masarati for inclusion
19  * in OpenLDAP Software.
20  */
21
22 #include "portable.h"
23
24 #include <stdio.h>
25
26 #include <slap.h>
27 #include "back-monitor.h"
28
29 int
30 monitor_back_compare( Operation *op, SlapReply *rs )
31 {
32         monitor_info_t  *mi = ( monitor_info_t * ) op->o_bd->be_private;
33         Entry           *e, *matched = NULL;
34         Attribute       *a;
35         int             rc;
36         AclCheck        ak;
37
38         ak.ak_state = NULL;
39
40         /* get entry with reader lock */
41         monitor_cache_dn2entry( op, rs, &op->o_req_ndn, &e, &matched );
42         if ( e == NULL ) {
43                 rs->sr_err = LDAP_NO_SUCH_OBJECT;
44                 if ( matched ) {
45                         ak.ak_e = matched;
46                         ak.ak_desc = slap_schema.si_ad_entry;
47                         ak.ak_val = NULL;
48                         ak.ak_access = ACL_DISCLOSE;
49                         if ( !access_allowed( op, &ak ))
50                         {
51                                 /* do nothing */ ;
52                         } else {
53                                 rs->sr_matched = matched->e_dn;
54                         }
55                 }
56                 send_ldap_result( op, rs );
57                 if ( matched ) {
58                         monitor_cache_release( mi, matched );
59                         rs->sr_matched = NULL;
60                 }
61
62                 return rs->sr_err;
63         }
64
65         ak.ak_e = e;
66         ak.ak_desc = op->oq_compare.rs_ava->aa_desc;
67         ak.ak_val = &op->oq_compare.rs_ava->aa_value;
68         ak.ak_access = ACL_COMPARE;
69         rs->sr_err = access_allowed( op, &ak );
70         if ( !rs->sr_err ) {
71                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
72                 goto return_results;
73         }
74
75         rs->sr_err = LDAP_NO_SUCH_ATTRIBUTE;
76
77         for ( a = attrs_find( e->e_attrs, op->oq_compare.rs_ava->aa_desc );
78                         a != NULL;
79                         a = attrs_find( a->a_next, op->oq_compare.rs_ava->aa_desc )) {
80                 rs->sr_err = LDAP_COMPARE_FALSE;
81
82                 if ( attr_valfind( a,
83                         SLAP_MR_ATTRIBUTE_VALUE_NORMALIZED_MATCH |
84                                 SLAP_MR_ASSERTED_VALUE_NORMALIZED_MATCH,
85                         &op->oq_compare.rs_ava->aa_value, NULL,
86                         op->o_tmpmemctx ) == 0 )
87                 {
88                         rs->sr_err = LDAP_COMPARE_TRUE;
89                         break;
90                 }
91         }
92
93 return_results:;
94         rc = rs->sr_err;
95         switch ( rc ) {
96         case LDAP_COMPARE_FALSE:
97         case LDAP_COMPARE_TRUE:
98                 rc = LDAP_SUCCESS;
99                 break;
100
101         case LDAP_NO_SUCH_ATTRIBUTE:
102                 break;
103
104         default:
105                 ak.ak_desc = slap_schema.si_ad_entry;
106                 ak.ak_val = NULL;
107                 ak.ak_access = ACL_DISCLOSE;
108                 if ( !access_allowed( op, &ak ))
109                 {
110                         rs->sr_err = LDAP_NO_SUCH_OBJECT;
111                 }
112                 break;
113         }
114                 
115         send_ldap_result( op, rs );
116         rs->sr_err = rc;
117
118         monitor_cache_release( mi, e );
119
120         return rs->sr_err;
121 }
122