/[virtual-ldap]/bin/ldap-rewrite.pl
This is repository of my old source code which isn't updated any more. Go to git.rot13.org for current projects!
ViewVC logotype

Contents of /bin/ldap-rewrite.pl

Parent Directory Parent Directory | Revision Log Revision Log


Revision 73 - (show annotations)
Tue Feb 23 00:11:35 2010 UTC (14 years, 1 month ago) by dpavlin
File MIME type: text/plain
File size: 5572 byte(s)
fix server socket connection handling, better logging

1 #!/usr/bin/perl
2 # Copyright (c) 2006 Hans Klunder <hans.klunder@bigfoot.com>. All rights reserved.
3 # This program is free software; you can redistribute it and/or
4 # modify it under the same terms as Perl itself.
5
6 # It's modified by Dobrica Pavlinusic <dpavlin@rot13.org> to include following:
7 #
8 # * rewrite LDAP bind request cn: username@domain.com -> uid=username,dc=domain,dc=com
9 # * rewrite search responses:
10 # ** expand key:value pairs from hrEduPersonUniqueNumber into hrEduPersonUniqueNumber_key
11 # ** augment response with yaml/dn.yaml data (for external data import)
12
13 use strict;
14 use warnings;
15
16 use IO::Select;
17 use IO::Socket;
18 use IO::Socket::SSL;
19 use warnings;
20 use Data::Dump qw/dump/;
21 use Convert::ASN1 qw(asn_read);
22 use Net::LDAP::ASN qw(LDAPRequest LDAPResponse);
23 our $VERSION = '0.3';
24 use fields qw(socket target);
25 use YAML qw/LoadFile/;
26
27 my $debug = 0;
28
29 my $config = {
30 yaml_dir => './yaml/',
31 listen => shift @ARGV || 'localhost:1389',
32 upstream_ldap => 'ldap.ffzg.hr',
33 upstream_ssl => 1,
34 overlay_prefix => 'ffzg-',
35 # log_file => 'log/ldap-rewrite.log',
36
37 };
38
39 my $log_fh;
40
41 sub log {
42 return unless $config->{log_file};
43
44 if ( ! $log_fh ) {
45 open($log_fh, '>>', $config->{log_file}) || die "can't open ", $config->{log_file},": $!";
46 print $log_fh "# " . time;
47 }
48 $log_fh->autoflush(1);
49 print $log_fh join("\n", @_),"\n";
50 }
51
52 BEGIN {
53 $SIG{'__WARN__'} = sub { warn @_; main::log(@_); }
54 }
55
56
57 if ( ! -d $config->{yaml_dir} ) {
58 warn "DISABLE ", $config->{yaml_dir}," data overlay";
59 }
60
61 warn "# config = ",dump( $config );
62
63 sub handle {
64 my $clientsocket=shift;
65 my $serversocket=shift;
66
67 # read from client
68 asn_read($clientsocket, my $reqpdu);
69 if ( ! $reqpdu ) {
70 warn "client closed connection\n";
71 return 0;
72 }
73 $reqpdu = log_request($reqpdu);
74
75 # send to server
76 print $serversocket $reqpdu or die "Could not send PDU to server\n ";
77
78 # read from server
79 my $ready;
80 my $sel = IO::Select->new($serversocket);
81 for( $ready = 1 ; $ready ; $ready = $sel->can_read(0)) {
82 asn_read($serversocket, my $respdu);
83 if ( ! $respdu ) {
84 warn "server closed connection\n";
85 return 0;
86 }
87 $respdu = log_response($respdu);
88 # and send the result to the client
89 print $clientsocket $respdu || return 0;
90 }
91
92 return 1;
93 }
94
95
96 sub log_request {
97 my $pdu=shift;
98
99 die "empty pdu" unless $pdu;
100
101 # print '-' x 80,"\n";
102 # print "Request ASN 1:\n";
103 # Convert::ASN1::asn_hexdump(\*STDOUT,$pdu);
104 # print "Request Perl:\n";
105 my $request = $LDAPRequest->decode($pdu);
106 warn "## request = ",dump($request);
107
108 if ( defined $request->{bindRequest} ) {
109 if ( $request->{bindRequest}->{name} =~ m{@} ) {
110 my $old = $request->{bindRequest}->{name};
111 $request->{bindRequest}->{name} =~ s/[@\.]/,dc=/g;
112 $request->{bindRequest}->{name} =~ s/^/uid=/;
113 warn "rewrite bind cn $old -> ", $request->{bindRequest}->{name};
114 Convert::ASN1::asn_hexdump(\*STDOUT,$pdu) if $debug;
115 $pdu = $LDAPRequest->encode($request);
116 Convert::ASN1::asn_hexdump(\*STDOUT,$pdu) if $debug;
117 }
118 }
119
120 return $pdu;
121 }
122
123 sub log_response {
124 my $pdu=shift;
125 die "empty pdu" unless $pdu;
126
127 # print '-' x 80,"\n";
128 # print "Response ASN 1:\n";
129 # Convert::ASN1::asn_hexdump(\*STDOUT,$pdu);
130 # print "Response Perl:\n";
131 my $response = $LDAPResponse->decode($pdu);
132
133 if ( defined $response->{protocolOp}->{searchResEntry} ) {
134 my $uid = $response->{protocolOp}->{searchResEntry}->{objectName};
135 warn "## objectName $uid";
136
137 my @attrs;
138
139 map {
140 if ( $_->{type} eq 'hrEduPersonUniqueNumber' ) {
141 foreach my $val ( @{ $_->{vals} } ) {
142 next if $val !~ m{.+:.+};
143 my ( $n, $v ) = split(/\s*:\s*/, $val );
144 push @attrs, { type => $_->{type} . '_' . $n, vals => [ $v ] };
145 }
146 }
147 } @{ $response->{protocolOp}->{searchResEntry}->{attributes} };
148
149 warn "# ++ attrs ",dump( @attrs );
150
151 push @{ $response->{protocolOp}->{searchResEntry}->{attributes} }, $_ foreach @attrs;
152
153 my $path = $config->{yaml_dir} . "$uid.yaml";
154 if ( -e $path ) {
155 my $data = LoadFile($path);
156 warn "# yaml = ",dump($data);
157
158 foreach my $type ( keys %$data ) {
159
160 my $vals = $data->{$type};
161
162 push @{ $response->{protocolOp}->{searchResEntry}->{attributes} }, {
163 type => $config->{overlay_prefix} . $type,
164 vals => ref($vals) eq 'ARRAY' ? $vals : [ $vals ],
165 };
166 }
167 }
168
169 $pdu = $LDAPResponse->encode($response);
170 }
171
172 warn "## response = ", dump($response);
173
174 return $pdu;
175 }
176
177
178 my $listenersock = IO::Socket::INET->new(
179 Listen => 5,
180 Proto => 'tcp',
181 Reuse => 1,
182 LocalAddr => $config->{listen},
183 ) || die "can't open listen socket: $!";
184
185 our $server_sock;
186
187 sub connect_to_server {
188 my $sock;
189 if ( $config->{upstream_ssl} ) {
190 $sock = IO::Socket::SSL->new( $config->{upstream_ldap} . ':ldaps' );
191 } else {
192 $sock = IO::Socket::INET->new(
193 Proto => 'tcp',
194 PeerAddr => $config->{upstream_ldap},
195 PeerPort => 389,
196 );
197 }
198 die "can't open ", $config->{upstream_ldap}, " $!\n" unless $sock;
199 warn "## connected to ", $sock->peerhost, ":", $sock->peerport, "\n";
200 return $sock;
201 }
202
203 my $sel = IO::Select->new($listenersock);
204 while (my @ready = $sel->can_read) {
205 foreach my $fh (@ready) {
206 if ($fh == $listenersock) {
207 # let's create a new socket
208 my $psock = $listenersock->accept;
209 $sel->add($psock);
210 warn "## add $psock " . time;
211 } else {
212 $server_sock->{$fh} ||= connect_to_server;
213 if ( ! handle($fh,$server_sock->{$fh}) ) {
214 warn "## remove $fh " . time;
215 $sel->remove($server_sock->{$fh});
216 $server_sock->{$fh}->close;
217 delete $server_sock->{$fh};
218 # we have finished with the socket
219 $sel->remove($fh);
220 $fh->close;
221 }
222 }
223 }
224 }
225
226 1;

Properties

Name Value
svn:executable *

  ViewVC Help
Powered by ViewVC 1.1.26