New site setting c_ldap_sync_email_addrs to toggle synchronization of email addresses...
[citadel.git] / citadel / ldap.c
index c7d2baf8723035368dd4e2b1da2d773a51d3e073..73e45ba23c2a777ee6072fe155b6a482c207edee 100644 (file)
@@ -30,6 +30,69 @@ int ctdl_require_ldap_version = 3;
 #include <ldap.h>
 
 
+/*
+ * Utility function, supply a search result and get back the fullname (display name, common name, etc) from the first result
+ */
+void derive_fullname_from_ldap_result(char *fullname, int fullname_size, LDAP *ldserver, LDAPMessage *search_result)
+{
+       char **values;
+
+       if (fullname == NULL) return;
+
+       if (CtdlGetConfigInt("c_auth_mode") == AUTHMODE_LDAP_AD) {
+               values = ldap_get_values(ldserver, search_result, "displayName");
+               if (values) {
+                       if (values[0]) {
+                               if (fullname) safestrncpy(fullname, values[0], fullname_size);
+                               syslog(LOG_DEBUG, "ldap: displayName = %s", values[0]);
+                       }
+                       ldap_value_free(values);
+               }
+       }
+       else {
+               values = ldap_get_values(ldserver, search_result, "cn");
+               if (values) {
+                       if (values[0]) {
+                               if (fullname) safestrncpy(fullname, values[0], fullname_size);
+                               syslog(LOG_DEBUG, "ldap: cn = %s", values[0]);
+                       }
+                       ldap_value_free(values);
+               }
+       }
+}
+
+
+/*
+ * Utility function, supply a search result and get back the uid from the first result
+ */
+uid_t derive_uid_from_ldap(LDAP *ldserver, LDAPMessage *entry)
+{
+       char **values;
+       uid_t uid = (-1);
+
+       if (CtdlGetConfigInt("c_auth_mode") == AUTHMODE_LDAP_AD) {
+               values = ldap_get_values(ldserver, entry, "objectGUID");        // AD schema: uid hashed from objectGUID
+               if (values) {
+                       if (values[0]) {
+                               uid = abs(HashLittle(values[0], strlen(values[0])));
+                       }
+                       ldap_value_free(values);
+               }
+       }
+       else {
+               values = ldap_get_values(ldserver, entry, "uidNumber");         // POSIX schema: uid = uidNumber
+               if (values) {
+                       if (values[0]) {
+                               uid = atoi(values[0]);
+                       }
+                       ldap_value_free(values);
+               }
+       }
+
+       return(uid);
+}
+
+
 /*
  * Wrapper function for ldap_initialize() that consistently fills in the correct fields
  */
@@ -51,26 +114,14 @@ int ctdl_ldap_initialize(LDAP **ld) {
 
 
 /*
- * Look up a user in the directory to see if this is an account that can be authenticated
+ * Bind to the LDAP server and return a working handle
  */
-int CtdlTryUserLDAP(char *username,
-               char *found_dn, int found_dn_size,
-               char *fullname, int fullname_size,
-               uid_t *uid, int lookup_based_on_username)
-{
+LDAP *ctdl_ldap_bind(void) {
        LDAP *ldserver = NULL;
        int i;
-       LDAPMessage *search_result = NULL;
-       LDAPMessage *entry = NULL;
-       char searchstring[1024];
-       struct timeval tv;
-       char **values;
-       char *user_dn = NULL;
-
-       if (fullname) safestrncpy(fullname, username, fullname_size);
 
        if (ctdl_ldap_initialize(&ldserver) != LDAP_SUCCESS) {
-               return(errno);
+               return(NULL);
        }
 
        ldap_set_option(ldserver, LDAP_OPT_PROTOCOL_VERSION, &ctdl_require_ldap_version);
@@ -78,32 +129,47 @@ int CtdlTryUserLDAP(char *username,
 
        striplt(CtdlGetConfigStr("c_ldap_bind_dn"));
        striplt(CtdlGetConfigStr("c_ldap_bind_pw"));
-       syslog(LOG_DEBUG, "ldap: bind DN: %s", CtdlGetConfigStr("c_ldap_bind_dn"));
        i = ldap_simple_bind_s(ldserver,
                (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_dn")) ? CtdlGetConfigStr("c_ldap_bind_dn") : NULL),
                (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_pw")) ? CtdlGetConfigStr("c_ldap_bind_pw") : NULL)
        );
        if (i != LDAP_SUCCESS) {
                syslog(LOG_ERR, "ldap: Cannot bind: %s (%d)", ldap_err2string(i), i);
-               return(i);
+               return(NULL);
        }
 
+       return(ldserver);
+}
+
+
+/*
+ * Look up a user in the directory to see if this is an account that can be authenticated
+ */
+int CtdlTryUserLDAP(char *username,
+               char *found_dn, int found_dn_size,
+               char *fullname, int fullname_size,
+               uid_t *uid)
+{
+       LDAP *ldserver = NULL;
+       LDAPMessage *search_result = NULL;
+       LDAPMessage *entry = NULL;
+       char searchstring[1024];
+       struct timeval tv;
+       char *user_dn = NULL;
+
+       ldserver = ctdl_ldap_bind();
+       if (!ldserver) return(-1);
+
+       if (fullname) safestrncpy(fullname, username, fullname_size);
        tv.tv_sec = 10;
        tv.tv_usec = 0;
 
        if (CtdlGetConfigInt("c_auth_mode") == AUTHMODE_LDAP_AD) {
-               if (lookup_based_on_username != 0)
-                       snprintf(searchstring, sizeof(searchstring), "(displayName=%s)",username);
-               else
-                       snprintf(searchstring, sizeof(searchstring), "(sAMAccountName=%s)", username);
+               snprintf(searchstring, sizeof(searchstring), "(sAMAccountName=%s)", username);
        }
        else {
-               if (lookup_based_on_username != 0) {
-                       snprintf(searchstring, sizeof(searchstring), "(cn=%s)",username);
-               }
-               else {
-                       snprintf(searchstring, sizeof(searchstring), "(&(objectclass=posixAccount)(uid=%s))", username);
-               }
+               snprintf(searchstring, sizeof(searchstring), "(&(objectclass=posixAccount)(cn=%s))", username);
+               // snprintf(searchstring, sizeof(searchstring), "(&(objectclass=posixAccount)(uid=%s))", username);
        }
 
        syslog(LOG_DEBUG, "ldap: search: %s", searchstring);
@@ -141,54 +207,8 @@ int CtdlTryUserLDAP(char *username,
                        syslog(LOG_DEBUG, "ldap: dn = %s", user_dn);
                }
 
-               if (CtdlGetConfigInt("c_auth_mode") == AUTHMODE_LDAP_AD) {
-                       values = ldap_get_values(ldserver, search_result, "displayName");
-                       if (values) {
-                               if (values[0]) {
-                                       if (fullname) safestrncpy(fullname, values[0], fullname_size);
-                                       syslog(LOG_DEBUG, "ldap: displayName = %s", values[0]);
-                               }
-                               ldap_value_free(values);
-                       }
-               }
-               else {
-                       values = ldap_get_values(ldserver, search_result, "cn");
-                       if (values) {
-                               if (values[0]) {
-                                       if (fullname) safestrncpy(fullname, values[0], fullname_size);
-                                       syslog(LOG_DEBUG, "ldap: cn = %s", values[0]);
-                               }
-                               ldap_value_free(values);
-                       }
-               }
-               /* If we know the username is the CN/displayName, we already set the uid*/
-               if (lookup_based_on_username==0) {
-                       if (CtdlGetConfigInt("c_auth_mode") == AUTHMODE_LDAP_AD) {
-                               values = ldap_get_values(ldserver, search_result, "objectGUID");
-                               if (values) {
-                                       if (values[0]) {
-                                               if (uid != NULL) {
-                                                       *uid = abs(HashLittle(values[0], strlen(values[0])));
-                                                       syslog(LOG_DEBUG, "ldap: uid hashed from objectGUID = %d", *uid);
-                                               }
-                                       }
-                                       ldap_value_free(values);
-                               }
-                       }
-                       else {
-                               values = ldap_get_values(ldserver, search_result, "uidNumber");
-                               if (values) {
-                                       if (values[0]) {
-                                               syslog(LOG_DEBUG, "ldap: uidNumber = %s", values[0]);
-                                               if (uid != NULL) {
-                                                       *uid = atoi(values[0]);
-                                               }
-                                       }
-                                       ldap_value_free(values);
-                               }
-                       }
-               }
-
+               derive_fullname_from_ldap_result(fullname, fullname_size, ldserver, search_result);
+               *uid = derive_uid_from_ldap(ldserver, search_result);
        }
 
        /* free the results */
@@ -284,7 +304,6 @@ int Ctdl_LDAP_to_vCard(char *ldap_dn, struct vCard *v)
 {
        int changed_something = 0;
        LDAP *ldserver = NULL;
-       int i;
        struct timeval tv;
        LDAPMessage *search_result = NULL;
        LDAPMessage *entry = NULL;
@@ -315,24 +334,8 @@ int Ctdl_LDAP_to_vCard(char *ldap_dn, struct vCard *v)
        if (!ldap_dn) return(0);
        if (!v) return(0);
 
-       if (ctdl_ldap_initialize(&ldserver) != LDAP_SUCCESS) {
-               return(0);
-       }
-
-       ldap_set_option(ldserver, LDAP_OPT_PROTOCOL_VERSION, &ctdl_require_ldap_version);
-       ldap_set_option(ldserver, LDAP_OPT_REFERRALS, (void *)LDAP_OPT_OFF);
-
-       striplt(CtdlGetConfigStr("c_ldap_bind_dn"));
-       striplt(CtdlGetConfigStr("c_ldap_bind_pw"));
-       syslog(LOG_DEBUG, "ldap: bind DN: %s", CtdlGetConfigStr("c_ldap_bind_dn"));
-       i = ldap_simple_bind_s(ldserver,
-               (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_dn")) ? CtdlGetConfigStr("c_ldap_bind_dn") : NULL),
-               (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_pw")) ? CtdlGetConfigStr("c_ldap_bind_pw") : NULL)
-       );
-       if (i != LDAP_SUCCESS) {
-               syslog(LOG_ERR, "ldap: Cannot bind: %s (%d)", ldap_err2string(i), i);
-               return(0);
-       }
+       ldserver = ctdl_ldap_bind();
+       if (!ldserver) return(-1);
 
        tv.tv_sec = 10;
        tv.tv_usec = 0;
@@ -450,7 +453,6 @@ int Ctdl_LDAP_to_vCard(char *ldap_dn, struct vCard *v)
 int extract_email_addresses_from_ldap(char *ldap_dn, char *emailaddrs)
 {
        LDAP *ldserver = NULL;
-       int i;
        struct timeval tv;
        LDAPMessage *search_result = NULL;
        LDAPMessage *entry = NULL;
@@ -460,24 +462,8 @@ int extract_email_addresses_from_ldap(char *ldap_dn, char *emailaddrs)
        if (!ldap_dn) return(1);
        if (!emailaddrs) return(1);
 
-       if (ctdl_ldap_initialize(&ldserver) != LDAP_SUCCESS) {
-               return(2);
-       }
-
-       ldap_set_option(ldserver, LDAP_OPT_PROTOCOL_VERSION, &ctdl_require_ldap_version);
-       ldap_set_option(ldserver, LDAP_OPT_REFERRALS, (void *)LDAP_OPT_OFF);
-
-       striplt(CtdlGetConfigStr("c_ldap_bind_dn"));
-       striplt(CtdlGetConfigStr("c_ldap_bind_pw"));
-       syslog(LOG_DEBUG, "ldap: bind DN: %s", CtdlGetConfigStr("c_ldap_bind_dn"));
-       i = ldap_simple_bind_s(ldserver,
-               (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_dn")) ? CtdlGetConfigStr("c_ldap_bind_dn") : NULL),
-               (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_pw")) ? CtdlGetConfigStr("c_ldap_bind_pw") : NULL)
-       );
-       if (i != LDAP_SUCCESS) {
-               syslog(LOG_ERR, "ldap: Cannot bind: %s (%d)", ldap_err2string(i), i);
-               return(3);
-       }
+       ldserver = ctdl_ldap_bind();
+       if (!ldserver) return(-1);
 
        tv.tv_sec = 10;
        tv.tv_usec = 0;
@@ -513,13 +499,12 @@ int extract_email_addresses_from_ldap(char *ldap_dn, char *emailaddrs)
        entry = ldap_first_entry(ldserver, search_result);
        if (entry) {
                syslog(LOG_DEBUG, "ldap: search got user details");
-               mail=ldap_get_values(ldserver, search_result, "mail");
+               mail = ldap_get_values(ldserver, search_result, "mail");
 
                if (mail) {
                        int q;
                        for (q=0; q<ldap_count_values(mail); ++q) {
                                if (IsDirectory(mail[q], 0)) {
-                                       syslog(LOG_DEBUG, "\035FIXME YES DIRECTORY %s\033[0m", mail[q]);
                                        if ((strlen(emailaddrs) + strlen(mail[q]) + 2) > 512) {
                                                syslog(LOG_ERR, "ldap: can't fit all email addresses into user record");
                                        }
@@ -546,41 +531,23 @@ int extract_email_addresses_from_ldap(char *ldap_dn, char *emailaddrs)
 /*
  * Scan LDAP for users and populate Citadel's user database with everyone
  */
-void CtdlPopulateUsersFromLDAP(void)
+void CtdlSynchronizeUsersFromLDAP(void)
 {
        LDAP *ldserver = NULL;
-       int i;
        LDAPMessage *search_result = NULL;
        LDAPMessage *entry = NULL;
        char *user_dn = NULL;
        char searchstring[1024];
        struct timeval tv;
-       // char **values;
 
        if ((CtdlGetConfigInt("c_auth_mode") != AUTHMODE_LDAP) && (CtdlGetConfigInt("c_auth_mode") != AUTHMODE_LDAP_AD)) {
                return;         // not running LDAP
        }
 
-       syslog(LOG_INFO, "ldap: populating Citadel user database from LDAP");
-
-       if (ctdl_ldap_initialize(&ldserver) != LDAP_SUCCESS) {
-               return;
-       }
+       syslog(LOG_INFO, "ldap: synchronizing Citadel user database from LDAP");
 
-       ldap_set_option(ldserver, LDAP_OPT_PROTOCOL_VERSION, &ctdl_require_ldap_version);
-       ldap_set_option(ldserver, LDAP_OPT_REFERRALS, (void *)LDAP_OPT_OFF);
-
-       striplt(CtdlGetConfigStr("c_ldap_bind_dn"));
-       striplt(CtdlGetConfigStr("c_ldap_bind_pw"));
-       syslog(LOG_DEBUG, "ldap: bind DN: %s", CtdlGetConfigStr("c_ldap_bind_dn"));
-       i = ldap_simple_bind_s(ldserver,
-               (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_dn")) ? CtdlGetConfigStr("c_ldap_bind_dn") : NULL),
-               (!IsEmptyStr(CtdlGetConfigStr("c_ldap_bind_pw")) ? CtdlGetConfigStr("c_ldap_bind_pw") : NULL)
-       );
-       if (i != LDAP_SUCCESS) {
-               syslog(LOG_ERR, "ldap: Cannot bind: %s (%d)", ldap_err2string(i), i);
-               return;
-       }
+       ldserver = ctdl_ldap_bind();
+       if (!ldserver) return;
 
        tv.tv_sec = 10;
        tv.tv_usec = 0;
@@ -622,6 +589,38 @@ void CtdlPopulateUsersFromLDAP(void)
                user_dn = ldap_get_dn(ldserver, entry);
                if (user_dn) {
                        syslog(LOG_DEBUG, "ldap: found %s", user_dn);
+
+                       int fullname_size = 256;
+                       char fullname[256] = { 0 } ;
+                       uid_t uid = (-1);
+                       char new_emailaddrs[512] = { 0 } ;
+
+                       derive_fullname_from_ldap_result(fullname, fullname_size, ldserver, entry);
+                       uid = derive_uid_from_ldap(ldserver, entry);
+                       syslog(LOG_DEBUG, "ldap: display name: <%s> , uid = <%d>", fullname, uid);
+
+                       // now create or update the user
+                       int found_user;
+                       struct ctdluser usbuf;
+
+                       found_user = getuserbyuid(&usbuf, uid);
+                       if (found_user != 0) {
+                               create_user(fullname, CREATE_USER_DO_NOT_BECOME_USER, uid);
+                               found_user = getuserbyuid(&usbuf, uid);
+                               strcpy(fullname, usbuf.fullname);
+                       }
+
+                       if (found_user == 0) {          // user record exists
+                               // now update the account email addresses if necessary
+                               if (CtdlGetConfigInt("c_ldap_sync_email_addrs") > 0) {
+                                       if (extract_email_addresses_from_ldap(user_dn, new_emailaddrs) == 0) {
+                                               if (strcmp(usbuf.emailaddrs, new_emailaddrs)) {                         // update only if changed
+                                                       CtdlSetEmailAddressesForUser(usbuf.fullname, new_emailaddrs);
+                                               }
+                                       }
+                               }
+                       }
+                       ldap_memfree(user_dn);
                }
 
                entry = ldap_next_entry(ldserver, entry);