ldap.go 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370
  1. package ldap
  2. import (
  3. "errors"
  4. "fmt"
  5. "sort"
  6. "strconv"
  7. "gogs.carducci-dante.gov.it/karmen/core/config"
  8. "gogs.carducci-dante.gov.it/karmen/core/orm"
  9. ldap "gopkg.in/ldap.v2"
  10. )
  11. type CompleteNameI interface {
  12. CompleteName() string
  13. }
  14. type Client struct {
  15. Conn *ldap.Conn
  16. Config *config.ConfigT
  17. }
  18. func (c *Client) Close() {
  19. c.Conn.Close()
  20. }
  21. func NewClient(host string, config *config.ConfigT) (*Client, error) {
  22. var err error
  23. client := new(Client)
  24. client.Config = config
  25. client.Conn, err = ldap.Dial("tcp", host)
  26. if err != nil {
  27. return nil, err
  28. }
  29. err = client.Conn.Bind(config.AdminCN(), config.Ldap.AdminPassword)
  30. if err != nil {
  31. return nil, err
  32. }
  33. return client, nil
  34. }
  35. func (c *Client) AddTeacher(teacher *orm.Teacher) error {
  36. mailDir := fmt.Sprintf("%s/%s/", c.Config.Ldap.MailDirBasePath, teacher.Username())
  37. uidNumber, err := c.NextMailUIDNumber()
  38. if err != nil {
  39. return err
  40. }
  41. addRequest := ldap.NewAddRequest(c.TeacherDN(teacher))
  42. addRequest.Attribute("objectClass", []string{
  43. "inetOrgPerson",
  44. "posixAccount",
  45. "PostfixBookMailAccount",
  46. "organizationalPerson",
  47. "extensibleObject",
  48. })
  49. addRequest.Attribute("sn", []string{teacher.Surname})
  50. addRequest.Attribute("uid", []string{teacher.Username()})
  51. addRequest.Attribute("homeDirectory", []string{fmt.Sprintf("/home/users/%s", teacher.Username())})
  52. addRequest.Attribute("givenName", []string{teacher.Surname})
  53. addRequest.Attribute("mail", []string{fmt.Sprintf("%s@%s", teacher.Username(), c.Config.Domain)})
  54. addRequest.Attribute("mailEnabled", []string{"TRUE"})
  55. addRequest.Attribute("mailGidNumber", []string{c.Config.Ldap.MailGIDNumber})
  56. addRequest.Attribute("mailUidNumber", []string{uidNumber})
  57. addRequest.Attribute("uidNumber", []string{uidNumber})
  58. addRequest.Attribute("gidNumber", []string{uidNumber})
  59. addRequest.Attribute("uniqueIdentifier", []string{teacher.Username()})
  60. addRequest.Attribute("mailHomeDirectory", []string{mailDir})
  61. addRequest.Attribute("mailStorageDirectory", []string{"maildir:" + mailDir})
  62. addRequest.Attribute("mailQuota", []string{c.Config.Ldap.MailQuota})
  63. addRequest.Attribute("userPassword", []string{fmt.Sprintf("{SSHA}%s", teacher.SaltPassword(teacher.PlainPassword))})
  64. err = c.Conn.Add(addRequest)
  65. if err != nil {
  66. return err
  67. }
  68. return nil
  69. }
  70. func (c *Client) UpdateTeacher(teacher *orm.Teacher) error {
  71. mailDir := fmt.Sprintf("%s/%s/", c.Config.Ldap.MailDirBasePath, teacher.Username())
  72. modRequest := ldap.NewModifyRequest(c.TeacherDN(teacher))
  73. modRequest.Replace("mail", []string{fmt.Sprintf("%s@%s", teacher.Username(), c.Config.Domain)})
  74. modRequest.Replace("mailHomeDirectory", []string{mailDir})
  75. modRequest.Replace("mailStorageDirectory", []string{"maildir:" + mailDir})
  76. modRequest.Replace("mailEnabled", []string{"TRUE"})
  77. modRequest.Replace("mailGidNumber", []string{c.Config.Ldap.MailGIDNumber})
  78. modRequest.Replace("mailQuota", []string{c.Config.Ldap.MailQuota})
  79. err := c.Conn.Modify(modRequest)
  80. if err != nil {
  81. return err
  82. }
  83. return nil
  84. }
  85. func (c *Client) UpdateTeacherPassword(teacher *orm.Teacher, password string) error {
  86. modRequest := ldap.NewModifyRequest(c.TeacherDN(teacher))
  87. modRequest.Replace("userPassword", []string{fmt.Sprintf("{SSHA}%s", teacher.SaltPassword(password))})
  88. err := c.Conn.Modify(modRequest)
  89. if err != nil {
  90. return err
  91. }
  92. return nil
  93. }
  94. func (c *Client) DeleteTeacher(teacher *orm.Teacher) error {
  95. delRequest := ldap.NewDelRequest(c.TeacherDN(teacher), nil)
  96. err := c.Conn.Del(delRequest)
  97. if err != nil {
  98. return err
  99. }
  100. return nil
  101. }
  102. func (c *Client) DeleteByDN(dn string) error {
  103. delRequest := ldap.NewDelRequest(dn, nil)
  104. err := c.Conn.Del(delRequest)
  105. if err != nil {
  106. return err
  107. }
  108. return nil
  109. }
  110. func (c *Client) AddTeacherToGroup(teacher *orm.Teacher, groupDN string) error {
  111. memberAttr, err := c.memberAttribute(groupDN)
  112. if err != nil {
  113. return err
  114. }
  115. modRequest := ldap.NewModifyRequest(fmt.Sprintf("%s,%s", groupDN, c.GroupsDN()))
  116. switch memberAttr {
  117. case "member":
  118. modRequest.Add(memberAttr, []string{c.personDN(teacher, c.TeachersDN())})
  119. case "memberuid":
  120. modRequest.Add(memberAttr, []string{teacher.Username()})
  121. default:
  122. return errors.New(fmt.Sprintf("Attribute %s is not supported!", memberAttr))
  123. }
  124. err = c.Conn.Modify(modRequest)
  125. if err != nil {
  126. return err
  127. }
  128. return nil
  129. }
  130. func (c *Client) RemoveTeacherFromGroup(teacher *orm.Teacher, groupDN string) error {
  131. memberAttr, err := c.memberAttribute(groupDN)
  132. if err != nil {
  133. return err
  134. }
  135. modRequest := ldap.NewModifyRequest(fmt.Sprintf("%s,%s", groupDN, c.GroupsDN()))
  136. switch memberAttr {
  137. case "member":
  138. modRequest.Delete(memberAttr, []string{c.personDN(teacher, c.TeachersDN())})
  139. case "memberuid":
  140. modRequest.Delete(memberAttr, []string{teacher.Username()})
  141. default:
  142. return errors.New(fmt.Sprintf("Attribute %s is not supported!", memberAttr))
  143. }
  144. err = c.Conn.Modify(modRequest)
  145. if err != nil {
  146. return err
  147. }
  148. return nil
  149. }
  150. func (c *Client) RemoveTeacherFromGroupByMemberValue(memberValue string, groupDN string) error {
  151. memberAttr, err := c.memberAttribute(groupDN)
  152. if err != nil {
  153. return err
  154. }
  155. modRequest := ldap.NewModifyRequest(fmt.Sprintf("%s,%s", groupDN, c.GroupsDN()))
  156. switch memberAttr {
  157. case "member":
  158. modRequest.Delete(memberAttr, []string{memberValue})
  159. case "memberuid":
  160. modRequest.Delete(memberAttr, []string{memberValue})
  161. default:
  162. return errors.New(fmt.Sprintf("Attribute %s is not supported!", memberAttr))
  163. }
  164. err = c.Conn.Modify(modRequest)
  165. if err != nil {
  166. return err
  167. }
  168. return nil
  169. }
  170. func (c *Client) IsTeacherInGroup(teacher *orm.Teacher, groupDN string) (bool, error) {
  171. memberAttr, err := c.memberAttribute(groupDN)
  172. if err != nil {
  173. return false, err
  174. }
  175. var memberValue string
  176. switch memberAttr {
  177. case "member":
  178. memberValue = c.personDN(teacher, c.TeachersDN())
  179. case "memberuid":
  180. memberValue = teacher.Username()
  181. default:
  182. return false, errors.New(fmt.Sprintf("Attribute %s is not supported!", memberAttr))
  183. }
  184. searchRequest := ldap.NewSearchRequest(
  185. fmt.Sprintf("%s,%s", groupDN, c.GroupsDN()),
  186. ldap.ScopeWholeSubtree, ldap.NeverDerefAliases, 0, 0, false,
  187. fmt.Sprintf("(&(%s=%s))", memberAttr, memberValue),
  188. []string{memberAttr},
  189. nil,
  190. )
  191. sr, err := c.Conn.Search(searchRequest)
  192. if err != nil {
  193. return false, err
  194. }
  195. return len(sr.Entries) > 0, nil
  196. }
  197. func (c *Client) GroupMembers(groupDN string) ([]*ldap.Entry, error) {
  198. searchRequest := ldap.NewSearchRequest(
  199. fmt.Sprintf("%s,%s", groupDN, c.GroupsDN()),
  200. ldap.ScopeWholeSubtree, ldap.NeverDerefAliases, 0, 0, false,
  201. "(|(member=*)(memberuid=*))",
  202. []string{"member", "memberuid"},
  203. nil,
  204. )
  205. sr, err := c.Conn.Search(searchRequest)
  206. if err != nil {
  207. return nil, err
  208. }
  209. return sr.Entries, nil
  210. }
  211. func (c *Client) Teachers() ([]*ldap.Entry, error) {
  212. result, err := c.Search(
  213. c.TeachersDN(),
  214. "(&(objectClass=organizationalPerson))",
  215. []string{"dn", "cn"},
  216. )
  217. if err != nil {
  218. return nil, err
  219. }
  220. return result.Entries, nil
  221. }
  222. func (c *Client) Search(base string, filter string, attributes []string) (*ldap.SearchResult, error) {
  223. searchRequest := ldap.NewSearchRequest(
  224. base,
  225. ldap.ScopeWholeSubtree, ldap.NeverDerefAliases, 0, 0, false,
  226. filter,
  227. attributes,
  228. nil,
  229. )
  230. sr, err := c.Conn.Search(searchRequest)
  231. if err != nil {
  232. return nil, err
  233. }
  234. return sr, nil
  235. }
  236. func (c *Client) TeacherExists(teacher *orm.Teacher) (bool, error) {
  237. searchRequest := ldap.NewSearchRequest(
  238. c.TeachersDN(),
  239. ldap.ScopeWholeSubtree, ldap.NeverDerefAliases, 0, 0, false,
  240. fmt.Sprintf("(&(objectClass=organizationalPerson)(cn=%s))", teacher.CompleteName()),
  241. []string{"dn", "cn"},
  242. nil,
  243. )
  244. sr, err := c.Conn.Search(searchRequest)
  245. if err != nil {
  246. return false, err
  247. }
  248. return len(sr.Entries) > 0, nil
  249. }
  250. func (c *Client) TeachersDN() string {
  251. return fmt.Sprintf("%s,%s", c.Config.Ldap.TeachersDN, c.DomainDN())
  252. }
  253. func (c *Client) DomainDN() string {
  254. return c.Config.DomainDN()
  255. }
  256. func (c *Client) TeacherDN(teacher *orm.Teacher) string {
  257. return fmt.Sprintf("cn=%s %s,%s", teacher.Name, teacher.Surname, c.TeachersDN())
  258. }
  259. func (c *Client) GroupsDN() string {
  260. return fmt.Sprintf("%s,%s", c.Config.Ldap.GroupsDN, c.DomainDN())
  261. }
  262. func (c *Client) PeopleDN() string {
  263. return fmt.Sprintf("%s,%s", c.Config.Ldap.PeopleDN, c.DomainDN())
  264. }
  265. func (c *Client) NextMailUIDNumber() (string, error) {
  266. searchRequest := ldap.NewSearchRequest(
  267. c.PeopleDN(),
  268. ldap.ScopeWholeSubtree, ldap.NeverDerefAliases, 0, 0, false,
  269. "(mailUidNumber=*)",
  270. []string{"mailUidNumber"},
  271. nil,
  272. )
  273. sr, err := c.Conn.Search(searchRequest)
  274. if err != nil {
  275. return "0", err
  276. }
  277. if len(sr.Entries) == 0 {
  278. return c.Config.Ldap.FirstUIDNumber, nil
  279. }
  280. var uids []int
  281. for _, e := range sr.Entries {
  282. n, err := strconv.Atoi(e.Attributes[0].Values[0])
  283. uids = append(uids, n)
  284. if err != nil {
  285. return "0", err
  286. }
  287. }
  288. sort.Ints(uids)
  289. nextUid := uids[len(uids)-1] + 1
  290. return strconv.Itoa(nextUid), nil
  291. }
  292. func (c *Client) memberAttribute(groupDN string) (string, error) {
  293. searchRequest := ldap.NewSearchRequest(
  294. fmt.Sprintf("%s,%s", groupDN, c.GroupsDN()),
  295. ldap.ScopeWholeSubtree, ldap.NeverDerefAliases, 0, 0, false,
  296. "(member=*)",
  297. []string{"member"},
  298. nil,
  299. )
  300. sr, err := c.Conn.Search(searchRequest)
  301. if err != nil {
  302. return "", err
  303. }
  304. if len(sr.Entries) > 0 {
  305. return "member", nil
  306. }
  307. return "memberuid", nil
  308. }
  309. func (c *Client) personDN(person CompleteNameI, baseDN string) string {
  310. dn := fmt.Sprintf("cn=%s,%s", person.CompleteName(), baseDN)
  311. return dn
  312. }