2020-08-22 22:26:06 +10:00
|
|
|
<?php
|
|
|
|
|
2020-08-23 12:30:18 +10:00
|
|
|
namespace App\Classes\LDAP;
|
2020-08-22 22:26:06 +10:00
|
|
|
|
2023-01-28 23:07:39 +11:00
|
|
|
use Carbon\Carbon;
|
2020-09-21 22:20:59 +10:00
|
|
|
use Exception;
|
2023-02-19 16:35:07 +11:00
|
|
|
use Illuminate\Support\Collection;
|
2020-09-19 00:08:00 +10:00
|
|
|
use Illuminate\Support\Facades\Cache;
|
2023-01-28 23:07:39 +11:00
|
|
|
use Illuminate\Support\Facades\Config;
|
2023-04-13 21:01:15 +10:00
|
|
|
use Illuminate\Support\Facades\Cookie;
|
2023-02-14 21:38:42 +11:00
|
|
|
use Illuminate\Support\Facades\Log;
|
2023-04-13 21:01:15 +10:00
|
|
|
use Illuminate\Support\Facades\Session;
|
2023-02-19 16:35:07 +11:00
|
|
|
use LdapRecord\LdapRecordException;
|
|
|
|
use LdapRecord\Models\Model;
|
|
|
|
use LdapRecord\Query\Collection as LDAPCollection;
|
|
|
|
use LdapRecord\Query\ObjectNotFoundException;
|
2020-09-21 22:20:59 +10:00
|
|
|
|
2023-02-14 21:38:42 +11:00
|
|
|
use App\Classes\LDAP\Schema\{AttributeType,Base,LDAPSyntax,MatchingRule,MatchingRuleUse,ObjectClass};
|
|
|
|
use App\Exceptions\InvalidUsage;
|
2020-09-21 22:20:59 +10:00
|
|
|
use App\Ldap\Entry;
|
|
|
|
|
2023-04-02 22:08:43 +10:00
|
|
|
final class Server
|
2020-08-22 22:26:06 +10:00
|
|
|
{
|
2025-01-13 22:03:47 +11:00
|
|
|
// Connection information used for these object and children
|
|
|
|
private ?string $connection;
|
|
|
|
|
2023-02-14 21:38:42 +11:00
|
|
|
// This servers schema objectclasses
|
2023-02-19 16:35:07 +11:00
|
|
|
private Collection $attributetypes;
|
|
|
|
private Collection $ldapsyntaxes;
|
|
|
|
private Collection $matchingrules;
|
|
|
|
private Collection $matchingruleuse;
|
|
|
|
private Collection $objectclasses;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2025-01-13 22:03:47 +11:00
|
|
|
/* ObjectClass Types */
|
|
|
|
public const OC_STRUCTURAL = 0x01;
|
|
|
|
public const OC_ABSTRACT = 0x02;
|
|
|
|
public const OC_AUXILIARY = 0x03;
|
|
|
|
|
|
|
|
public function __construct(string $connection=NULL)
|
|
|
|
{
|
|
|
|
$this->connection = $connection;
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
public function __get(string $key): mixed
|
|
|
|
{
|
2025-01-13 22:03:47 +11:00
|
|
|
return match($key) {
|
|
|
|
'attributetypes' => $this->attributetypes,
|
|
|
|
'connection' => $this->connection,
|
|
|
|
'ldapsyntaxes' => $this->ldapsyntaxes,
|
|
|
|
'matchingrules' => $this->matchingrules,
|
|
|
|
'objectclasses' => $this->objectclasses,
|
|
|
|
default => throw new Exception('Unknown key:' . $key),
|
|
|
|
};
|
2023-02-19 00:32:46 +11:00
|
|
|
}
|
|
|
|
|
2023-02-19 16:35:07 +11:00
|
|
|
/* STATIC METHODS */
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Gets the root DN of the specified LDAPServer, or throws an exception if it
|
|
|
|
* can't find it.
|
|
|
|
*
|
|
|
|
* @param null $connection Return a collection of baseDNs
|
|
|
|
* @param bool $objects Return a collection of Entry Models
|
|
|
|
* @return Collection
|
|
|
|
* @throws ObjectNotFoundException
|
|
|
|
* @testedin GetBaseDNTest::testBaseDNExists();
|
2023-04-02 22:08:43 +10:00
|
|
|
* @todo Need to allow for the scenario if the baseDN is not readable by ACLs
|
2023-02-19 16:35:07 +11:00
|
|
|
*/
|
2025-01-13 22:03:47 +11:00
|
|
|
public static function baseDNs(string $connection='default',bool $objects=TRUE): Collection
|
2023-02-19 16:35:07 +11:00
|
|
|
{
|
2025-01-13 22:03:47 +11:00
|
|
|
$cachetime = Carbon::now()
|
|
|
|
->addSeconds(Config::get('ldap.cache.time'));
|
2023-02-19 16:35:07 +11:00
|
|
|
|
|
|
|
try {
|
|
|
|
$base = self::rootDSE($connection,$cachetime);
|
|
|
|
|
2023-04-13 21:01:15 +10:00
|
|
|
/**
|
|
|
|
* LDAP Error Codes:
|
|
|
|
* https://ldap.com/ldap-result-code-reference/
|
|
|
|
* + success 0
|
|
|
|
* + operationsError 1
|
|
|
|
* + protocolError 2
|
|
|
|
* + timeLimitExceeded 3
|
|
|
|
* + sizeLimitExceeded 4
|
|
|
|
* + compareFalse 5
|
|
|
|
* + compareTrue 6
|
|
|
|
* + authMethodNotSupported 7
|
|
|
|
* + strongerAuthRequired 8
|
|
|
|
* + referral 10
|
|
|
|
* + adminLimitExceeded 11
|
|
|
|
* + unavailableCriticalExtension 12
|
|
|
|
* + confidentialityRequired 13
|
|
|
|
* + saslBindInProgress 14
|
|
|
|
* + noSuchAttribute 16
|
|
|
|
* + undefinedAttributeType 17
|
|
|
|
* + inappropriateMatching 18
|
|
|
|
* + constraintViolation 19
|
|
|
|
* + attributeOrValueExists 20
|
|
|
|
* + invalidAttributeSyntax 21
|
|
|
|
* + noSuchObject 32
|
|
|
|
* + aliasProblem 33
|
|
|
|
* + invalidDNSyntax 34
|
|
|
|
* + isLeaf 35
|
|
|
|
* + aliasDereferencingProblem 36
|
|
|
|
* + inappropriateAuthentication 48
|
|
|
|
* + invalidCredentials 49
|
|
|
|
* + insufficientAccessRights 50
|
|
|
|
* + busy 51
|
|
|
|
* + unavailable 52
|
|
|
|
* + unwillingToPerform 53
|
|
|
|
* + loopDetect 54
|
|
|
|
* + sortControlMissing 60
|
|
|
|
* + offsetRangeError 61
|
|
|
|
* + namingViolation 64
|
|
|
|
* + objectClassViolation 65
|
|
|
|
* + notAllowedOnNonLeaf 66
|
|
|
|
* + notAllowedOnRDN 67
|
|
|
|
* + entryAlreadyExists 68
|
|
|
|
* + objectClassModsProhibited 69
|
|
|
|
* + resultsTooLarge 70
|
|
|
|
* + affectsMultipleDSAs 71
|
|
|
|
* + virtualListViewError or controlError 76
|
|
|
|
* + other 80
|
|
|
|
* + serverDown 81
|
|
|
|
* + localError 82
|
|
|
|
* + encodingError 83
|
|
|
|
* + decodingError 84
|
|
|
|
* + timeout 85
|
|
|
|
* + authUnknown 86
|
|
|
|
* + filterError 87
|
|
|
|
* + userCanceled 88
|
|
|
|
* + paramError 89
|
|
|
|
* + noMemory 90
|
|
|
|
* + connectError 91
|
|
|
|
* + notSupported 92
|
|
|
|
* + controlNotFound 93
|
|
|
|
* + noResultsReturned 94
|
|
|
|
* + moreResultsToReturn 95
|
|
|
|
* + clientLoop 96
|
|
|
|
* + referralLimitExceeded 97
|
|
|
|
* + invalidResponse 100
|
|
|
|
* + ambiguousResponse 101
|
|
|
|
* + tlsNotSupported 112
|
|
|
|
* + intermediateResponse 113
|
|
|
|
* + unknownType 114
|
|
|
|
* + canceled 118
|
|
|
|
* + noSuchOperation 119
|
|
|
|
* + tooLate 120
|
|
|
|
* + cannotCancel 121
|
|
|
|
* + assertionFailed 122
|
|
|
|
* + authorizationDenied 123
|
|
|
|
* + e-syncRefreshRequired 4096
|
|
|
|
* + noOperation 16654
|
|
|
|
*
|
|
|
|
* LDAP Tag Codes:
|
|
|
|
* + A client bind operation 97
|
|
|
|
* + The entry for which you were searching 100
|
|
|
|
* + The result from a search operation 101
|
|
|
|
* + The result from a modify operation 103
|
|
|
|
* + The result from an add operation 105
|
|
|
|
* + The result from a delete operation 107
|
|
|
|
* + The result from a modify DN operation 109
|
|
|
|
* + The result from a compare operation 111
|
|
|
|
* + A search reference when the entry you perform your search on holds a referral to the entry you require.
|
|
|
|
* + Search references are expressed in terms of a referral.
|
|
|
|
* 115
|
|
|
|
* + A result from an extended operation 120
|
|
|
|
*/
|
|
|
|
// If we cannot get to our LDAP server we'll head straight to the error page
|
2023-02-19 16:35:07 +11:00
|
|
|
} catch (LdapRecordException $e) {
|
2025-01-13 22:03:47 +11:00
|
|
|
switch ($e->getDetailedError()?->getErrorCode()) {
|
2023-02-19 16:35:07 +11:00
|
|
|
case 49:
|
2023-04-13 21:01:15 +10:00
|
|
|
// Since we failed authentication, we should delete our auth cookie
|
|
|
|
if (Cookie::has('password_encrypt')) {
|
|
|
|
Log::alert('Clearing user credentials and logging out');
|
|
|
|
|
|
|
|
Cookie::queue(Cookie::forget('password_encrypt'));
|
|
|
|
Cookie::queue(Cookie::forget('username_encrypt'));
|
|
|
|
|
|
|
|
Session::invalidate();
|
|
|
|
}
|
|
|
|
|
2023-02-19 16:35:07 +11:00
|
|
|
abort(401,$e->getDetailedError()->getErrorMessage());
|
|
|
|
|
|
|
|
default:
|
2025-01-13 22:03:47 +11:00
|
|
|
abort(597,$e->getDetailedError()?->getErrorMessage() ?: $e->getMessage());
|
2023-02-19 16:35:07 +11:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (! $objects)
|
|
|
|
return collect($base->namingcontexts);
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @note While we are caching our baseDNs, it seems if we have more than 1,
|
|
|
|
* our caching doesnt generate a hit on a subsequent call to this function (before the cache expires).
|
|
|
|
* IE: If we have 5 baseDNs, it takes 5 calls to this function to case them all.
|
|
|
|
* @todo Possibly a bug wtih ldaprecord, so need to investigate
|
|
|
|
*/
|
|
|
|
$result = collect();
|
2025-01-13 22:03:47 +11:00
|
|
|
foreach ($base->namingcontexts as $dn)
|
2023-02-19 16:35:07 +11:00
|
|
|
$result->push((new Entry)->cache($cachetime)->findOrFail($dn));
|
|
|
|
|
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Obtain the rootDSE for the server, that gives us server information
|
|
|
|
*
|
|
|
|
* @param null $connection
|
|
|
|
* @return Entry|null
|
|
|
|
* @throws ObjectNotFoundException
|
|
|
|
* @testedin TranslateOidTest::testRootDSE();
|
|
|
|
*/
|
2025-01-13 22:03:47 +11:00
|
|
|
public static function rootDSE(string $connection=NULL,Carbon $cachetime=NULL): ?Model
|
2023-02-19 16:35:07 +11:00
|
|
|
{
|
|
|
|
$e = new Entry;
|
|
|
|
|
|
|
|
return Entry::on($connection ?? $e->getConnectionName())
|
|
|
|
->cache($cachetime)
|
|
|
|
->in(NULL)
|
|
|
|
->read()
|
|
|
|
->select(['+'])
|
|
|
|
->whereHas('objectclass')
|
|
|
|
->firstOrFail();
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Get the Schema DN
|
|
|
|
*
|
|
|
|
* @param $connection
|
|
|
|
* @return string
|
|
|
|
* @throws ObjectNotFoundException
|
|
|
|
*/
|
2025-01-13 22:03:47 +11:00
|
|
|
public static function schemaDN(string $connection=NULL): string
|
2023-02-19 16:35:07 +11:00
|
|
|
{
|
|
|
|
$cachetime = Carbon::now()->addSeconds(Config::get('ldap.cache.time'));
|
|
|
|
|
|
|
|
return collect(self::rootDSE($connection,$cachetime)->subschemasubentry)->first();
|
|
|
|
}
|
|
|
|
|
2020-09-19 00:08:00 +10:00
|
|
|
/**
|
2023-02-14 21:38:42 +11:00
|
|
|
* Query the server for a DN and return its children and if those children have children.
|
2020-09-19 00:08:00 +10:00
|
|
|
*
|
|
|
|
* @param string $dn
|
2023-02-19 16:35:07 +11:00
|
|
|
* @return LDAPCollection|NULL
|
2020-09-19 00:08:00 +10:00
|
|
|
*/
|
2023-02-19 16:35:07 +11:00
|
|
|
public function children(string $dn): ?LDAPCollection
|
2020-09-19 00:08:00 +10:00
|
|
|
{
|
2020-09-21 22:20:59 +10:00
|
|
|
return ($x=(new Entry)
|
2025-01-13 22:03:47 +11:00
|
|
|
->on($this->connection)
|
2023-01-28 23:07:39 +11:00
|
|
|
->cache(Carbon::now()->addSeconds(Config::get('ldap.cache.time')))
|
2020-09-21 22:20:59 +10:00
|
|
|
->select(['*','hassubordinates'])
|
|
|
|
->setDn($dn)
|
2024-01-08 12:28:11 +11:00
|
|
|
->list()
|
2020-09-21 22:20:59 +10:00
|
|
|
->get()) ? $x : NULL;
|
2020-09-19 00:08:00 +10:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Fetch a DN from the server
|
|
|
|
*
|
|
|
|
* @param string $dn
|
|
|
|
* @param array $attrs
|
2023-02-14 21:38:42 +11:00
|
|
|
* @return Entry|null
|
2020-08-22 22:26:06 +10:00
|
|
|
*/
|
2020-09-21 22:20:59 +10:00
|
|
|
public function fetch(string $dn,array $attrs=['*','+']): ?Entry
|
2020-08-22 22:26:06 +10:00
|
|
|
{
|
2020-09-21 22:20:59 +10:00
|
|
|
return ($x=(new Entry)
|
2025-01-13 22:03:47 +11:00
|
|
|
->on($this->connection)
|
2023-01-28 23:07:39 +11:00
|
|
|
->cache(Carbon::now()->addSeconds(Config::get('ldap.cache.time')))
|
2020-09-21 22:20:59 +10:00
|
|
|
->select($attrs)
|
|
|
|
->find($dn)) ? $x : NULL;
|
2020-08-22 22:26:06 +10:00
|
|
|
}
|
2020-08-31 21:41:45 +10:00
|
|
|
|
2023-02-14 21:38:42 +11:00
|
|
|
/**
|
|
|
|
* This function determines if the specified attribute is contained in the force_may list
|
|
|
|
* as configured in config.php.
|
|
|
|
*
|
|
|
|
* @return boolean True if the specified attribute is configured to be force as a may attribute
|
|
|
|
*/
|
|
|
|
public function isForceMay($attr_name): bool
|
|
|
|
{
|
|
|
|
return in_array($attr_name,config('pla.force_may',[]));
|
|
|
|
}
|
|
|
|
|
2023-03-27 16:19:37 +11:00
|
|
|
/**
|
|
|
|
* Does this server support RFC3666 language tags
|
|
|
|
* OID: 1.3.6.1.4.1.4203.1.5.4
|
|
|
|
*
|
|
|
|
* @return bool
|
|
|
|
* @throws ObjectNotFoundException
|
|
|
|
*/
|
|
|
|
public function isLanguageTags(): bool
|
|
|
|
{
|
|
|
|
return in_array('1.3.6.1.4.1.4203.1.5.4',$this->rootDSE()->supportedfeatures);
|
|
|
|
}
|
|
|
|
|
2023-02-14 21:38:42 +11:00
|
|
|
/**
|
|
|
|
* Return the server's schema
|
|
|
|
*
|
|
|
|
* @param string $item Schema Item to Fetch
|
|
|
|
* @param string|null $key
|
2023-02-19 16:35:07 +11:00
|
|
|
* @return Collection|Base|NULL
|
2023-02-14 21:38:42 +11:00
|
|
|
* @throws InvalidUsage
|
|
|
|
*/
|
2025-01-13 22:03:47 +11:00
|
|
|
public function schema(string $item,string $key=NULL): Collection|LDAPSyntax|Base|NULL
|
2023-02-14 21:38:42 +11:00
|
|
|
{
|
|
|
|
// Ensure our item to fetch is lower case
|
|
|
|
$item = strtolower($item);
|
|
|
|
if ($key)
|
|
|
|
$key = strtolower($key);
|
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
$result = Cache::remember('schema'.$item,config('ldap.cache.time'),function() use ($item) {
|
|
|
|
// First pass if we have already retrieved the schema item
|
|
|
|
switch ($item) {
|
|
|
|
case 'attributetypes':
|
|
|
|
if (isset($this->attributetypes))
|
|
|
|
return $this->attributetypes;
|
|
|
|
else
|
|
|
|
$this->attributetypes = collect();
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
break;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
case 'ldapsyntaxes':
|
|
|
|
if (isset($this->ldapsyntaxes))
|
|
|
|
return $this->ldapsyntaxes;
|
|
|
|
else
|
|
|
|
$this->ldapsyntaxes = collect();
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
break;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
case 'matchingrules':
|
|
|
|
if (isset($this->matchingrules))
|
|
|
|
return $this->matchingrules;
|
|
|
|
else
|
|
|
|
$this->matchingrules = collect();
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
break;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
/*
|
|
|
|
case 'matchingruleuse':
|
|
|
|
if (isset($this->matchingruleuse))
|
|
|
|
return is_null($key) ? $this->matchingruleuse : $this->matchingruleuse->get($key);
|
|
|
|
else
|
|
|
|
$this->matchingruleuse = collect();
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
break;
|
|
|
|
*/
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
case 'objectclasses':
|
|
|
|
if (isset($this->objectclasses))
|
|
|
|
return $this->objectclasses;
|
|
|
|
else
|
|
|
|
$this->objectclasses = collect();
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
break;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2025-01-13 22:03:47 +11:00
|
|
|
// This error message is not localized as only developers should ever see it
|
2023-02-19 00:32:46 +11:00
|
|
|
default:
|
|
|
|
throw new InvalidUsage('Invalid request to fetch schema: '.$item);
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
// Try to get the schema DN from the specified entry.
|
2025-01-13 22:03:47 +11:00
|
|
|
$schema_dn = $this->schemaDN('default');
|
2023-02-19 16:35:07 +11:00
|
|
|
$schema = $this->fetch($schema_dn);
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
switch ($item) {
|
|
|
|
case 'attributetypes':
|
|
|
|
Log::debug('Attribute Types');
|
|
|
|
// build the array of attribueTypes
|
|
|
|
//$syntaxes = $this->SchemaSyntaxes($dn);
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
foreach ($schema->{$item} as $line) {
|
|
|
|
if (is_null($line) || ! strlen($line))
|
|
|
|
continue;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
$o = new AttributeType($line);
|
|
|
|
$this->attributetypes->put($o->name_lc,$o);
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
/*
|
|
|
|
if (isset($syntaxes[$attr->getSyntaxOID()])) {
|
|
|
|
$syntax = $syntaxes[$attr->getSyntaxOID()];
|
|
|
|
$attr->setType($syntax->getDescription());
|
|
|
|
}
|
|
|
|
$this->attributetypes[$attr->getName()] = $attr;
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* bug 856832: create an entry in the $attrs_oid array too. This
|
|
|
|
* will be a ref to the $attrs entry for maintenance and performance
|
|
|
|
* reasons
|
|
|
|
*/
|
|
|
|
//$attrs_oid[$attr->getOID()] = &$attrs[$attr->getName()];
|
2023-02-14 21:38:42 +11:00
|
|
|
}
|
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
// go back and add data from aliased attributeTypes
|
|
|
|
foreach ($this->attributetypes as $o) {
|
|
|
|
/* foreach of the attribute's aliases, create a new entry in the attrs array
|
|
|
|
* with its name set to the alias name, and all other data copied.*/
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
if ($o->aliases->count()) {
|
|
|
|
Log::debug(sprintf('\ Attribute [%s] has the following aliases [%s]',$o->name,$o->aliases->join(',')));
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
foreach ($o->aliases as $alias) {
|
|
|
|
$new_attr = clone $o;
|
|
|
|
$new_attr->setName($alias);
|
|
|
|
$new_attr->addAlias($o->name);
|
|
|
|
$new_attr->removeAlias($alias);
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
$this->attributetypes->put(strtolower($alias),$new_attr);
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
// Now go through and reference the parent/child relationships
|
|
|
|
foreach ($this->attributetypes as $o)
|
|
|
|
if ($o->sup_attribute) {
|
|
|
|
$parent = strtolower($o->sup_attribute);
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
if ($this->attributetypes->has($parent) !== FALSE)
|
|
|
|
$this->attributetypes[$parent]->addChild($o->name);
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
// go through any children and add details if the child doesnt have them (ie, cn inherits name)
|
|
|
|
// @todo This doesnt traverse children properly, so children of children may not get the settings they should
|
|
|
|
foreach ($this->attributetypes as $parent) {
|
|
|
|
foreach ($parent->children as $child) {
|
|
|
|
$child = strtolower($child);
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
/* only overwrite the child's SINGLE-VALUE property if the parent has it set, and the child doesnt
|
|
|
|
* (note: All LDAP attributes default to multi-value if not explicitly set SINGLE-VALUE) */
|
|
|
|
if (! is_null($parent->is_single_value) && is_null($this->attributetypes[$child]->is_single_value))
|
|
|
|
$this->attributetypes[$child]->setIsSingleValue($parent->is_single_value);
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
}
|
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
// Add the used in and required_by values.
|
|
|
|
foreach ($this->schema('objectclasses') as $object_class) {
|
|
|
|
$must_attrs = $object_class->getMustAttrNames();
|
|
|
|
$may_attrs = $object_class->getMayAttrNames();
|
|
|
|
$oclass_attrs = $must_attrs->merge($may_attrs)->unique();
|
|
|
|
|
|
|
|
// Add Used In.
|
|
|
|
foreach ($oclass_attrs as $attr_name)
|
|
|
|
if ($this->attributetypes->has(strtolower($attr_name)))
|
|
|
|
$this->attributetypes[strtolower($attr_name)]->addUsedInObjectClass($object_class->name);
|
|
|
|
|
|
|
|
// Add Required By.
|
|
|
|
foreach ($must_attrs as $attr_name)
|
|
|
|
if ($this->attributetypes->has(strtolower($attr_name)))
|
|
|
|
$this->attributetypes[strtolower($attr_name)]->addRequiredByObjectClass($object_class->name);
|
|
|
|
|
|
|
|
// Force May
|
|
|
|
foreach ($object_class->getForceMayAttrs() as $attr_name)
|
|
|
|
if ($this->attributetypes->has(strtolower($attr_name->name)))
|
|
|
|
$this->attributetypes[strtolower($attr_name->name)]->setForceMay();
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
return $this->attributetypes;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
case 'ldapsyntaxes':
|
|
|
|
Log::debug('LDAP Syntaxes');
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
foreach ($schema->{$item} as $line) {
|
|
|
|
if (is_null($line) || ! strlen($line))
|
|
|
|
continue;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
$o = new LDAPSyntax($line);
|
|
|
|
$this->ldapsyntaxes->put(strtolower($o->oid),$o);
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
return $this->ldapsyntaxes;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
case 'matchingrules':
|
|
|
|
Log::debug('Matching Rules');
|
|
|
|
$this->matchingruleuse = collect();
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
foreach ($schema->{$item} as $line) {
|
2023-02-14 21:38:42 +11:00
|
|
|
if (is_null($line) || ! strlen($line))
|
|
|
|
continue;
|
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
$o = new MatchingRule($line);
|
|
|
|
$this->matchingrules->put($o->name_lc,$o);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* For each MatchingRuleUse entry, add the attributes who use it to the
|
|
|
|
* MatchingRule in the $rules array.
|
|
|
|
*/
|
|
|
|
if ($schema->matchingruleuse) {
|
|
|
|
foreach ($schema->matchingruleuse as $line) {
|
|
|
|
if (is_null($line) || ! strlen($line))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
$o = new MatchingRuleUse($line);
|
|
|
|
$this->matchingruleuse->put($o->name_lc,$o);
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
if ($this->matchingrules->has($o->name_lc) !== FALSE)
|
|
|
|
$this->matchingrules[$o->name_lc]->setUsedByAttrs($o->getUsedByAttrs());
|
|
|
|
}
|
|
|
|
|
|
|
|
} else {
|
|
|
|
/* No MatchingRuleUse entry in the subschema, so brute-forcing
|
|
|
|
* the reverse-map for the "$rule->getUsedByAttrs()" data.*/
|
|
|
|
foreach ($this->schema('attributetypes') as $attr) {
|
|
|
|
$rule_key = strtolower($attr->getEquality());
|
|
|
|
|
|
|
|
if ($this->matchingrules->has($rule_key) !== FALSE)
|
|
|
|
$this->matchingrules[$rule_key]->addUsedByAttr($attr->name);
|
|
|
|
}
|
2023-02-14 21:38:42 +11:00
|
|
|
}
|
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
return $this->matchingrules;
|
|
|
|
|
|
|
|
case 'objectclasses':
|
|
|
|
Log::debug('Object Classes');
|
|
|
|
|
|
|
|
foreach ($schema->{$item} as $line) {
|
|
|
|
if (is_null($line) || ! strlen($line))
|
|
|
|
continue;
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
$o = new ObjectClass($line,$this);
|
|
|
|
$this->objectclasses->put($o->name_lc,$o);
|
2023-02-14 21:38:42 +11:00
|
|
|
}
|
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
// Now go through and reference the parent/child relationships
|
|
|
|
foreach ($this->objectclasses as $o)
|
|
|
|
foreach ($o->getSupClasses() as $parent) {
|
|
|
|
$parent = strtolower($parent);
|
2025-01-13 22:03:47 +11:00
|
|
|
|
|
|
|
if (! $this->objectclasses->contains($parent))
|
2023-02-19 00:32:46 +11:00
|
|
|
$this->objectclasses[$parent]->addChildObjectClass($o->name);
|
|
|
|
}
|
|
|
|
|
|
|
|
return $this->objectclasses;
|
2025-01-13 22:03:47 +11:00
|
|
|
|
|
|
|
// Shouldnt get here
|
|
|
|
default:
|
|
|
|
throw new InvalidUsage('Invalid request to fetch schema: '.$item);
|
2023-02-19 00:32:46 +11:00
|
|
|
}
|
|
|
|
});
|
2023-02-14 21:38:42 +11:00
|
|
|
|
2023-02-19 00:32:46 +11:00
|
|
|
return is_null($key) ? $result : $result->get($key);
|
2023-02-14 21:38:42 +11:00
|
|
|
}
|
|
|
|
|
2023-03-27 16:19:37 +11:00
|
|
|
/**
|
|
|
|
* Given an OID, return the ldapsyntax for the OID
|
|
|
|
*
|
|
|
|
* @param string $oid
|
|
|
|
* @return LDAPSyntax|null
|
|
|
|
* @throws InvalidUsage
|
|
|
|
*/
|
2023-02-14 21:38:42 +11:00
|
|
|
public function schemaSyntaxName(string $oid): ?LDAPSyntax
|
|
|
|
{
|
|
|
|
return $this->schema('ldapsyntaxes',$oid);
|
|
|
|
}
|
|
|
|
}
|