1 /* $OpenLDAP: pkg/ldap/libraries/librewrite/ldapmap.c,v 1.12.2.4 2008/02/11 23:26:42 kurt Exp $ */
2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
4 * Copyright 2000-2008 The OpenLDAP Foundation.
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted only as authorized by the OpenLDAP
11 * A copy of this license is available in the file LICENSE in the
12 * top-level directory of the distribution or, alternatively, at
13 * <http://www.OpenLDAP.org/license.html>.
16 * This work was initially developed by Pierangelo Masarati for
17 * inclusion in OpenLDAP Software.
22 #define LDAP_DEPRECATED 1
23 #include "rewrite-int.h"
24 #include "rewrite-map.h"
34 * LDAP map data structure
36 struct ldap_map_data
{
41 struct berval lm_cred
;
50 #ifdef USE_REWRITE_LDAP_PVT_THREADS
51 ldap_pvt_thread_mutex_t lm_mutex
;
52 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
57 struct ldap_map_data
*data
60 assert( data
!= NULL
);
62 if ( data
->lm_url
!= NULL
) {
66 if ( data
->lm_lud
!= NULL
) {
67 ldap_free_urldesc( data
->lm_lud
);
70 if ( data
->lm_binddn
!= NULL
) {
71 free( data
->lm_binddn
);
74 if ( data
->lm_cred
.bv_val
!= NULL
) {
75 memset( data
->lm_cred
.bv_val
, 0, data
->lm_cred
.bv_len
);
76 free( data
->lm_cred
.bv_val
);
77 data
->lm_cred
.bv_val
= NULL
;
78 data
->lm_cred
.bv_len
= 0;
81 if ( data
->lm_when
!= MAP_LDAP_EVERYTIME
&& data
->lm_ld
!= NULL
) {
82 ldap_unbind_ext( data
->lm_ld
, NULL
, NULL
);
96 struct ldap_map_data
*data
;
99 assert( fname
!= NULL
);
100 assert( argv
!= NULL
);
102 data
= calloc( sizeof( struct ldap_map_data
), 1 );
103 if ( data
== NULL
) {
108 Debug( LDAP_DEBUG_ANY
,
109 "[%s:%d] ldap map needs URI\n%s",
116 if ( strncasecmp( uri
, "uri=", STRLENOF( "uri=" ) ) == 0 ) {
117 uri
+= STRLENOF( "uri=" );
120 data
->lm_url
= strdup( uri
);
121 if ( data
->lm_url
== NULL
) {
122 map_ldap_free( data
);
126 if ( ldap_url_parse( uri
, &data
->lm_lud
) != REWRITE_SUCCESS
) {
127 Debug( LDAP_DEBUG_ANY
,
128 "[%s:%d] illegal URI '%s'\n",
129 fname
, lineno
, argv
[ 0 ] );
130 map_ldap_free( data
);
134 /* trim everything after [host][:port] */
135 p
= strchr( data
->lm_url
, '/' );
136 assert( p
[ 1 ] == '/' );
137 if ( ( p
= strchr( p
+ 2, '/' ) ) != NULL
) {
141 if ( data
->lm_lud
->lud_attrs
== NULL
) {
142 data
->lm_attrs
[ 0 ] = LDAP_NO_ATTRS
;
146 if ( data
->lm_lud
->lud_attrs
[ 1 ] != NULL
) {
147 Debug( LDAP_DEBUG_ANY
,
148 "[%s:%d] only one attribute allowed in URI\n",
150 map_ldap_free( data
);
154 if ( strcasecmp( data
->lm_lud
->lud_attrs
[ 0 ], "dn" ) == 0
155 || strcasecmp( data
->lm_lud
->lud_attrs
[ 0 ], "entryDN" ) == 0 )
157 ldap_memfree( data
->lm_lud
->lud_attrs
[ 0 ] );
158 ldap_memfree( data
->lm_lud
->lud_attrs
);
159 data
->lm_lud
->lud_attrs
= NULL
;
160 data
->lm_attrs
[ 0 ] = LDAP_NO_ATTRS
;
164 data
->lm_attrs
[ 0 ] = data
->lm_lud
->lud_attrs
[ 0 ];
168 data
->lm_attrs
[ 1 ] = NULL
;
171 data
->lm_version
= LDAP_VERSION3
;
173 for ( argc
--, argv
++; argc
> 0; argc
--, argv
++ ) {
174 if ( strncasecmp( argv
[ 0 ], "binddn=", STRLENOF( "binddn=" ) ) == 0 ) {
175 char *p
= argv
[ 0 ] + STRLENOF( "binddn=" );
178 if ( p
[ 0 ] == '\"' || p
[ 0 ] == '\'' ) {
181 if ( p
[ l
] != p
[ 0 ] ) {
182 map_ldap_free( data
);
189 data
->lm_binddn
= strdup( p
);
190 if ( data
->lm_binddn
== NULL
) {
191 map_ldap_free( data
);
195 if ( data
->lm_binddn
[ l
] == '\"'
196 || data
->lm_binddn
[ l
] == '\'' ) {
197 data
->lm_binddn
[ l
] = '\0';
201 } else if ( strncasecmp( argv
[ 0 ], "bindpw=", STRLENOF( "bindpw=" ) ) == 0 ) {
202 ber_str2bv( argv
[ 0 ] + STRLENOF( "bindpw=" ), 0, 1, &data
->lm_cred
);
203 if ( data
->lm_cred
.bv_val
== NULL
) {
204 map_ldap_free( data
);
208 } else if ( strncasecmp( argv
[ 0 ], "credentials=", STRLENOF( "credentials=" ) ) == 0 ) {
209 ber_str2bv( argv
[ 0 ] + STRLENOF( "credentials=" ), 0, 1, &data
->lm_cred
);
210 if ( data
->lm_cred
.bv_val
== NULL
) {
211 map_ldap_free( data
);
215 } else if ( strncasecmp( argv
[ 0 ], "bindwhen=", STRLENOF( "bindwhen=" ) ) == 0 ) {
216 char *p
= argv
[ 0 ] + STRLENOF( "bindwhen=" );
218 if ( strcasecmp( p
, "now" ) == 0 ) {
221 data
->lm_when
= MAP_LDAP_NOW
;
224 * Init LDAP handler ...
226 rc
= ldap_initialize( &data
->lm_ld
, data
->lm_url
);
227 if ( rc
!= LDAP_SUCCESS
) {
228 map_ldap_free( data
);
232 ldap_set_option( data
->lm_ld
,
233 LDAP_OPT_PROTOCOL_VERSION
,
234 (void *)&data
->lm_version
);
236 #ifdef USE_REWRITE_LDAP_PVT_THREADS
237 ldap_pvt_thread_mutex_init( &data
->lm_mutex
);
238 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
240 } else if ( strcasecmp( p
, "later" ) == 0 ) {
241 data
->lm_when
= MAP_LDAP_LATER
;
243 #ifdef USE_REWRITE_LDAP_PVT_THREADS
244 ldap_pvt_thread_mutex_init( &data
->lm_mutex
);
245 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
247 } else if ( strcasecmp( p
, "everytime" ) == 0 ) {
248 data
->lm_when
= MAP_LDAP_EVERYTIME
;
253 } else if ( strncasecmp( argv
[ 0 ], "version=", STRLENOF( "version=" ) ) == 0 ) {
254 if ( lutil_atoi( &data
->lm_version
, argv
[ 0 ] + STRLENOF( "version=" ) ) ) {
255 map_ldap_free( data
);
259 switch ( data
->lm_version
) {
265 Debug( LDAP_DEBUG_ANY
,
266 "[%s:%d] unknown version %s\n",
268 map_ldap_free( data
);
273 Debug( LDAP_DEBUG_ANY
,
274 "[%s:%d] unknown option %s (ignored)\n",
275 fname
, lineno
, argv
[0] );
279 if ( data
->lm_when
== MAP_LDAP_UNKNOWN
) {
280 data
->lm_when
= MAP_LDAP_EVERYTIME
;
283 return ( void * )data
;
295 LDAPMessage
*res
= NULL
, *entry
;
297 struct ldap_map_data
*data
= private;
298 LDAPURLDesc
*lud
= data
->lm_lud
;
300 int first_try
= 1, set_version
= 0;
302 assert( private != NULL
);
303 assert( filter
!= NULL
);
304 assert( val
!= NULL
);
309 if ( data
->lm_when
== MAP_LDAP_EVERYTIME
) {
310 rc
= ldap_initialize( &ld
, data
->lm_url
);
314 #ifdef USE_REWRITE_LDAP_PVT_THREADS
315 ldap_pvt_thread_mutex_lock( &data
->lm_mutex
);
316 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
320 if ( data
->lm_when
== MAP_LDAP_LATER
&& data
->lm_ld
== NULL
) {
321 rc
= ldap_initialize( &data
->lm_ld
, data
->lm_url
);
328 if ( rc
!= LDAP_SUCCESS
) {
335 ldap_set_option( ld
, LDAP_OPT_PROTOCOL_VERSION
,
336 (void *)&data
->lm_version
);
340 if ( data
->lm_binddn
!= NULL
) {
341 rc
= ldap_sasl_bind_s( ld
, data
->lm_binddn
,
342 LDAP_SASL_SIMPLE
, &data
->lm_cred
,
344 if ( rc
== LDAP_SERVER_DOWN
&& first_try
) {
346 if ( ldap_initialize( &ld
, data
->lm_url
) != LDAP_SUCCESS
) {
353 } else if ( rc
!= REWRITE_SUCCESS
) {
359 rc
= ldap_search_ext_s( ld
, lud
->lud_dn
, lud
->lud_scope
, ( char * )filter
,
360 data
->lm_attrs
, 0, NULL
, NULL
, NULL
, 1, &res
);
361 if ( rc
== LDAP_SERVER_DOWN
&& first_try
) {
363 if ( ldap_initialize( &ld
, data
->lm_url
) != LDAP_SUCCESS
) {
370 } else if ( rc
!= LDAP_SUCCESS
) {
375 if ( ldap_count_entries( ld
, res
) != 1 ) {
381 entry
= ldap_first_entry( ld
, res
);
382 assert( entry
!= NULL
);
384 if ( data
->lm_wantdn
== 1 ) {
386 * dn is newly allocated, so there's no need to strdup it
388 val
->bv_val
= ldap_get_dn( ld
, entry
);
389 val
->bv_len
= strlen( val
->bv_val
);
392 struct berval
**values
;
394 values
= ldap_get_values_len( ld
, entry
, data
->lm_attrs
[ 0 ] );
395 if ( values
!= NULL
) {
396 if ( values
[ 0 ] != NULL
&& values
[ 0 ]->bv_val
!= NULL
) {
398 /* NOTE: in principle, multiple values
399 * should not be acceptable according
400 * to the current API; ignore by now */
401 if ( values
[ 1 ] != NULL
) {
405 ber_dupbv( val
, values
[ 0 ] );
407 ldap_value_free_len( values
);
413 if ( val
->bv_val
== NULL
) {
419 if ( data
->lm_when
== MAP_LDAP_EVERYTIME
) {
421 ldap_unbind_ext( ld
, NULL
, NULL
);
426 #ifdef USE_REWRITE_LDAP_PVT_THREADS
427 ldap_pvt_thread_mutex_unlock( &data
->lm_mutex
);
428 #endif /* USE_REWRITE_LDAP_PVT_THREADS */
439 struct ldap_map_data
*data
= private;
441 assert( private != NULL
);
443 map_ldap_free( data
);
448 const rewrite_mapper rewrite_ldap_mapper
= {