-added function to read user attributes from given user dn
This commit is contained in:
parent
1f5a75333e
commit
ffd68b369c
192
lam/lib/ldap.php
192
lam/lib/ldap.php
|
@ -24,99 +24,125 @@ $Id$
|
||||||
// ldap.php provides basic functions to connect to the OpenLDAP server and get lists of users and groups.
|
// ldap.php provides basic functions to connect to the OpenLDAP server and get lists of users and groups.
|
||||||
include_once("../config/config.php");
|
include_once("../config/config.php");
|
||||||
|
|
||||||
|
// class representing local user entry with attributes of ldap user entry
|
||||||
|
include_once("userentry.php");
|
||||||
|
|
||||||
class Ldap{
|
class Ldap{
|
||||||
|
|
||||||
// object of Config to access preferences
|
// object of Config to access preferences
|
||||||
var $conf;
|
var $conf;
|
||||||
|
|
||||||
// server handle
|
// server handle
|
||||||
var $server;
|
var $server;
|
||||||
|
|
||||||
// constructor
|
// constructor
|
||||||
// $config has to be an object of Config (../config/config.php)
|
// $config has to be an object of Config (../config/config.php)
|
||||||
function Ldap($config) {
|
function Ldap($config) {
|
||||||
if (is_object($config)) $this->conf = $config;
|
if (is_object($config)) $this->conf = $config;
|
||||||
else { echo _("Ldap->Ldap failed!"); exit;}
|
else { echo _("Ldap->Ldap failed!"); exit;}
|
||||||
}
|
}
|
||||||
|
|
||||||
// returns an array of strings with the DN entries of all users
|
// returns an array of strings with the DN entries of all users
|
||||||
// $base is optional and specifies the root from where to search for entries
|
// $base is optional and specifies the root from where to search for entries
|
||||||
function getUsers($base = "") {
|
function getUsers($base = "") {
|
||||||
if ($base == "") $base = $this->conf->get_UserSuffix();
|
if ($base == "") $base = $this->conf->get_UserSuffix();
|
||||||
// users have the attribute "posixAccount" or "sambaAccount" and do not end with "$"
|
// users have the attribute "posixAccount" or "sambaAccount" and do not end with "$"
|
||||||
$filter = "(&(|(objectClass=posixAccount) (objectClass=sambaAccount)) (!(uid=*$)))";
|
$filter = "(&(|(objectClass=posixAccount) (objectClass=sambaAccount)) (!(uid=*$)))";
|
||||||
$attrs = array();
|
$attrs = array();
|
||||||
$sr = ldap_search($this->server, $base, $filter, $attrs);
|
$sr = ldap_search($this->server, $base, $filter, $attrs);
|
||||||
$info = ldap_get_entries($this->server, $sr);
|
$info = ldap_get_entries($this->server, $sr);
|
||||||
$ret = array();
|
$ret = array();
|
||||||
for ($i = 0; $i < $info["count"]; $i++) $ret[$i] = $info[$i]["dn"];
|
for ($i = 0; $i < $info["count"]; $i++) $ret[$i] = $info[$i]["dn"];
|
||||||
ldap_free_result($sr);
|
ldap_free_result($sr);
|
||||||
return $ret;
|
return $ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
// returns an array of strings with the DN entries of all groups
|
// returns an array of strings with the DN entries of all groups
|
||||||
// $base is optional and specifies the root from where to search for entries
|
// $base is optional and specifies the root from where to search for entries
|
||||||
function getGroups($base = "") {
|
function getGroups($base = "") {
|
||||||
if ($base == "") $base = $this->conf->get_GroupSuffix();
|
if ($base == "") $base = $this->conf->get_GroupSuffix();
|
||||||
// groups have the attribute "posixGroup"
|
// groups have the attribute "posixGroup"
|
||||||
$filter = "(objectClass=posixGroup)";
|
$filter = "(objectClass=posixGroup)";
|
||||||
$attrs = array();
|
$attrs = array();
|
||||||
$sr = ldap_search($this->server, $base, $filter, $attrs);
|
$sr = ldap_search($this->server, $base, $filter, $attrs);
|
||||||
$info = ldap_get_entries($this->server, $sr);
|
$info = ldap_get_entries($this->server, $sr);
|
||||||
$ret = array();
|
$ret = array();
|
||||||
for ($i = 0; $i < $info["count"]; $i++) $ret[$i] = $info[$i]["dn"];
|
for ($i = 0; $i < $info["count"]; $i++) $ret[$i] = $info[$i]["dn"];
|
||||||
ldap_free_result($sr);
|
ldap_free_result($sr);
|
||||||
return $ret;
|
return $ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
// returns an array of strings with the DN entries of all Samba hosts
|
// returns an array of strings with the DN entries of all Samba hosts
|
||||||
// $base is optional and specifies the root from where to search for entries
|
// $base is optional and specifies the root from where to search for entries
|
||||||
function getMachines($base = "") {
|
function getMachines($base = "") {
|
||||||
if ($base == "") $base = $this->conf->get_HostSuffix();
|
if ($base == "") $base = $this->conf->get_HostSuffix();
|
||||||
// Samba hosts have the attribute "sambaAccount" and end with "$"
|
// Samba hosts have the attribute "sambaAccount" and end with "$"
|
||||||
$filter = "(&(objectClass=sambaAccount) (uid=*$))";
|
$filter = "(&(objectClass=sambaAccount) (uid=*$))";
|
||||||
$attrs = array();
|
$attrs = array();
|
||||||
$sr = ldap_search($this->server, $base, $filter, $attrs);
|
$sr = ldap_search($this->server, $base, $filter, $attrs);
|
||||||
$info = ldap_get_entries($this->server, $sr);
|
$info = ldap_get_entries($this->server, $sr);
|
||||||
$ret = array();
|
$ret = array();
|
||||||
for ($i = 0; $i < $info["count"]; $i++) $ret[$i] = $info[$i]["dn"];
|
for ($i = 0; $i < $info["count"]; $i++) $ret[$i] = $info[$i]["dn"];
|
||||||
ldap_free_result($sr);
|
ldap_free_result($sr);
|
||||||
return $ret;
|
return $ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
// connects to the server using the given username and password
|
// connects to the server using the given username and password
|
||||||
// $base is optional and specifies the root from where to search for entries
|
// $base is optional and specifies the root from where to search for entries
|
||||||
// if connect succeeds the server handle is returned
|
// if connect succeeds the server handle is returned
|
||||||
function connect($user, $passwd) {
|
function connect($user, $passwd) {
|
||||||
// close any prior connection
|
// close any prior connection
|
||||||
@$this->close();
|
@$this->close();
|
||||||
// do not allow anonymous bind
|
// do not allow anonymous bind
|
||||||
if ((!$user)||($user == "")) {
|
if ((!$user)||($user == "")) {
|
||||||
echo _("No username was specified!");
|
echo _("No username was specified!");
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
if ($this->conf->get_SSL() == "True") $this->server = @ldap_connect("ldaps://" . $this->conf->get_Host(), $this->conf->get_Port());
|
if ($this->conf->get_SSL() == "True") $this->server = @ldap_connect("ldaps://" . $this->conf->get_Host(), $this->conf->get_Port());
|
||||||
else $this->server = @ldap_connect("ldap://" . $this->conf->get_Host(), $this->conf->get_Port());
|
else $this->server = @ldap_connect("ldap://" . $this->conf->get_Host(), $this->conf->get_Port());
|
||||||
if ($this->server) {
|
if ($this->server) {
|
||||||
// use LDAPv3
|
// use LDAPv3
|
||||||
ldap_set_option($this->server, LDAP_OPT_PROTOCOL_VERSION, 3);
|
ldap_set_option($this->server, LDAP_OPT_PROTOCOL_VERSION, 3);
|
||||||
$bind = @ldap_bind($this->server, $user, $passwd);
|
$bind = @ldap_bind($this->server, $user, $passwd);
|
||||||
if ($bind) {
|
if ($bind) {
|
||||||
// return server handle
|
// return server handle
|
||||||
return $this->server;
|
return $this->server;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// fills the UserEntry object with attributes from the ldap server with the
|
||||||
|
// given dn of an user entry
|
||||||
|
function getUser ($in_user_dn) {
|
||||||
|
$user = new UserEntry();
|
||||||
|
$attrs = array();
|
||||||
|
$resource = ldap_read ($this->server,
|
||||||
|
$in_user_dn, "(objectClass=*)", $attrs);
|
||||||
|
$entry = ldap_first_entry ($this->server, $resource);
|
||||||
|
|
||||||
|
// attributes which are not multivalued ...
|
||||||
|
$uid = ldap_get_values ($this->server, $entry, "uid");
|
||||||
|
$user->setUid ($uid[0]);
|
||||||
|
$cn = ldap_get_values ($this->server, $entry, "cn");
|
||||||
|
$user->setCn ($cn[0]);
|
||||||
|
$sn = ldap_get_values ($this->server, $entry, "sn");
|
||||||
|
$user->setSn ($sn[0]);
|
||||||
|
$givenName = ldap_get_values ($this->server, $entry, "givenName");
|
||||||
|
$user->setGivenName ($givenName[0]);
|
||||||
|
$homeDirectory = ldap_get_values ($this->server, $entry, "homeDirectory");
|
||||||
|
$user->setHomeDirectory ($homeDirectory[0]);
|
||||||
|
return $user;
|
||||||
|
}
|
||||||
|
|
||||||
// closes connection to server
|
// closes connection to server
|
||||||
function close() {
|
function close() {
|
||||||
ldap_close($this->server);
|
ldap_close($this->server);
|
||||||
}
|
}
|
||||||
|
|
||||||
// returns the LDAP connection handle
|
// returns the LDAP connection handle
|
||||||
function server() {
|
function server() {
|
||||||
return $this->server;
|
return $this->server;
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue