LdapBrowser.java 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318
  1. /*
  2. * Password Management Servlets (PWM)
  3. * http://www.pwm-project.org
  4. *
  5. * Copyright (c) 2006-2009 Novell, Inc.
  6. * Copyright (c) 2009-2021 The PWM Project
  7. *
  8. * Licensed under the Apache License, Version 2.0 (the "License");
  9. * you may not use this file except in compliance with the License.
  10. * You may obtain a copy of the License at
  11. *
  12. * http://www.apache.org/licenses/LICENSE-2.0
  13. *
  14. * Unless required by applicable law or agreed to in writing, software
  15. * distributed under the License is distributed on an "AS IS" BASIS,
  16. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  17. * See the License for the specific language governing permissions and
  18. * limitations under the License.
  19. */
  20. package password.pwm.ldap;
  21. import com.novell.ldapchai.ChaiEntry;
  22. import com.novell.ldapchai.ChaiEntryFactory;
  23. import com.novell.ldapchai.exception.ChaiOperationException;
  24. import com.novell.ldapchai.exception.ChaiUnavailableException;
  25. import com.novell.ldapchai.provider.ChaiProvider;
  26. import com.novell.ldapchai.provider.ChaiProviderFactory;
  27. import com.novell.ldapchai.provider.DirectoryVendor;
  28. import com.novell.ldapchai.provider.SearchScope;
  29. import com.novell.ldapchai.util.ChaiUtility;
  30. import com.novell.ldapchai.util.SearchHelper;
  31. import lombok.Builder;
  32. import lombok.Value;
  33. import password.pwm.DomainProperty;
  34. import password.pwm.bean.DomainID;
  35. import password.pwm.bean.ProfileID;
  36. import password.pwm.bean.SessionLabel;
  37. import password.pwm.config.AppConfig;
  38. import password.pwm.config.DomainConfig;
  39. import password.pwm.config.profile.LdapProfile;
  40. import password.pwm.config.stored.StoredConfiguration;
  41. import password.pwm.error.ErrorInformation;
  42. import password.pwm.error.PwmError;
  43. import password.pwm.error.PwmUnrecoverableException;
  44. import password.pwm.util.java.CollectorUtil;
  45. import password.pwm.util.java.StringUtil;
  46. import password.pwm.util.logging.PwmLogger;
  47. import java.util.ArrayList;
  48. import java.util.Collections;
  49. import java.util.HashMap;
  50. import java.util.HashSet;
  51. import java.util.LinkedHashMap;
  52. import java.util.List;
  53. import java.util.Map;
  54. import java.util.Set;
  55. import java.util.TreeMap;
  56. import java.util.function.Function;
  57. public class LdapBrowser
  58. {
  59. public static final String PARAM_DN = "dn";
  60. public static final String PARAM_PROFILE = "profile";
  61. private static final String ATTR_SUBORDINATE_COUNT = "subordinateCount";
  62. private static final PwmLogger LOGGER = PwmLogger.forClass( LdapBrowser.class );
  63. private final StoredConfiguration storedConfiguration;
  64. private final SessionLabel sessionLabel;
  65. private final ChaiProviderFactory chaiProviderFactory;
  66. private final Map<ProfileID, ChaiProvider> providerCache = new HashMap<>();
  67. private enum DnType
  68. {
  69. navigable,
  70. selectable,
  71. }
  72. public LdapBrowser(
  73. final SessionLabel sessionLabel,
  74. final ChaiProviderFactory chaiProviderFactory,
  75. final StoredConfiguration storedConfiguration
  76. )
  77. {
  78. this.sessionLabel = sessionLabel;
  79. this.chaiProviderFactory = chaiProviderFactory;
  80. this.storedConfiguration = storedConfiguration;
  81. }
  82. public LdapBrowseResult doBrowse(
  83. final DomainID domainID,
  84. final ProfileID profile,
  85. final String dn
  86. )
  87. throws PwmUnrecoverableException
  88. {
  89. try
  90. {
  91. return doBrowseImpl( domainID, profile, dn );
  92. }
  93. catch ( final ChaiUnavailableException | ChaiOperationException e )
  94. {
  95. throw PwmUnrecoverableException.fromChaiException( e );
  96. }
  97. catch ( final Exception e )
  98. {
  99. throw new PwmUnrecoverableException( new ErrorInformation( PwmError.ERROR_LDAP_DATA_ERROR, e.getMessage() ) );
  100. }
  101. }
  102. public void close( )
  103. {
  104. for ( final ChaiProvider chaiProvider : providerCache.values() )
  105. {
  106. chaiProvider.close();
  107. }
  108. providerCache.clear();
  109. }
  110. private LdapBrowseResult doBrowseImpl(
  111. final DomainID domainID,
  112. final ProfileID profileID,
  113. final String dn
  114. )
  115. throws PwmUnrecoverableException, ChaiUnavailableException, ChaiOperationException
  116. {
  117. final LdapBrowseResult.LdapBrowseResultBuilder result = LdapBrowseResult.builder();
  118. updateBrowseResultChildren( domainID, profileID, dn, result );
  119. result.dn( dn );
  120. result.profileID( profileID );
  121. final DomainConfig domainConfig = AppConfig.forStoredConfig( storedConfiguration ).getDomainConfigs().get( domainID );
  122. if ( domainConfig.getLdapProfiles().size() > 1 )
  123. {
  124. result.profileList( new ArrayList<>( domainConfig.getLdapProfiles().keySet() ) );
  125. }
  126. if ( adRootDNList( domainID, profileID ).contains( dn ) )
  127. {
  128. result.parentDN( "" );
  129. }
  130. else if ( StringUtil.notEmpty( dn ) )
  131. {
  132. final ChaiEntry dnEntry = getChaiProvider( domainID, profileID ).getEntryFactory().newChaiEntry( dn );
  133. final ChaiEntry parentEntry = dnEntry.getParentEntry();
  134. if ( parentEntry == null )
  135. {
  136. result.parentDN( "" );
  137. }
  138. else
  139. {
  140. result.parentDN( parentEntry.getEntryDN() );
  141. }
  142. }
  143. return result.build();
  144. }
  145. private void updateBrowseResultChildren(
  146. final DomainID domainID,
  147. final ProfileID profileID,
  148. final String dn,
  149. final LdapBrowseResult.LdapBrowseResultBuilder result
  150. )
  151. throws ChaiUnavailableException, PwmUnrecoverableException, ChaiOperationException
  152. {
  153. final Map<String, DnType> childDNs = new TreeMap<>( getChildEntries( domainID, profileID, dn ) );
  154. final List<DNInformation> navigableDNs = new ArrayList<>();
  155. final List<DNInformation> selectableDNs = new ArrayList<>();
  156. for ( final Map.Entry<String, DnType> entry : childDNs.entrySet() )
  157. {
  158. final String childDN = entry.getKey();
  159. final DNInformation dnInformation = new DNInformation( rdnNameFromDN( childDN ), childDN );
  160. if ( entry.getValue() == DnType.navigable )
  161. {
  162. navigableDNs.add( dnInformation );
  163. }
  164. else
  165. {
  166. selectableDNs.add( dnInformation );
  167. }
  168. }
  169. result.navigableDNlist( navigableDNs );
  170. result.selectableDNlist( selectableDNs );
  171. result.maxResults( childDNs.size() >= getMaxSizeLimit( domainID, storedConfiguration ) );
  172. }
  173. private ChaiProvider getChaiProvider( final DomainID domainID, final ProfileID profile )
  174. throws PwmUnrecoverableException
  175. {
  176. if ( !providerCache.containsKey( profile ) )
  177. {
  178. final DomainConfig domainConfig = AppConfig.forStoredConfig( storedConfiguration ).getDomainConfigs().get( domainID );
  179. final LdapProfile ldapProfile = domainConfig.getLdapProfiles().get( profile );
  180. final ChaiProvider chaiProvider = LdapOperationsHelper.openProxyChaiProvider( chaiProviderFactory, sessionLabel, ldapProfile, domainConfig, null );
  181. providerCache.put( profile, chaiProvider );
  182. }
  183. return providerCache.get( profile );
  184. }
  185. private static int getMaxSizeLimit(
  186. final DomainID domainID,
  187. final StoredConfiguration storedConfiguration
  188. )
  189. {
  190. final DomainConfig domainConfig = AppConfig.forStoredConfig( storedConfiguration ).getDomainConfigs().get( domainID );
  191. return Integer.parseInt( domainConfig.readDomainProperty( DomainProperty.LDAP_BROWSER_MAX_ENTRIES ) );
  192. }
  193. private Map<String, DnType> getChildEntries(
  194. final DomainID domainID,
  195. final ProfileID profile,
  196. final String dn
  197. )
  198. throws ChaiUnavailableException, PwmUnrecoverableException, ChaiOperationException
  199. {
  200. final ChaiProvider chaiProvider = getChaiProvider( domainID, profile );
  201. if ( StringUtil.isEmpty( dn ) && chaiProvider.getDirectoryVendor() == DirectoryVendor.ACTIVE_DIRECTORY )
  202. {
  203. return Collections.unmodifiableMap( adRootDNList( domainID, profile ).stream().collect( CollectorUtil.toLinkedMap(
  204. Function.identity(),
  205. rootDN -> DnType.navigable
  206. ) ) );
  207. }
  208. final Set<String> results = doLdapSearch( domainID, dn, chaiProvider );
  209. final HashMap<String, DnType> returnMap = new LinkedHashMap<>( results.size() );
  210. for ( final String resultDN : results )
  211. {
  212. final DnType dnType = dnHasSubordinates( resultDN, chaiProvider );
  213. returnMap.put( resultDN, dnType );
  214. }
  215. return Collections.unmodifiableMap( returnMap );
  216. }
  217. private DnType dnHasSubordinates(
  218. final String dn,
  219. final ChaiProvider chaiProvider
  220. )
  221. throws ChaiUnavailableException, ChaiOperationException
  222. {
  223. final ChaiEntry chaiEntry = ChaiEntryFactory.newChaiFactory( chaiProvider ).newChaiEntry( dn );
  224. return chaiEntry.hasChildren()
  225. ? DnType.navigable
  226. : DnType.selectable;
  227. }
  228. private Set<String> doLdapSearch(
  229. final DomainID domainID,
  230. final String dn,
  231. final ChaiProvider chaiProvider
  232. )
  233. throws ChaiUnavailableException, ChaiOperationException
  234. {
  235. final SearchHelper searchHelper = new SearchHelper();
  236. searchHelper.setFilter( SearchHelper.DEFAULT_FILTER );
  237. searchHelper.setAttributes( Collections.emptyList() );
  238. searchHelper.setMaxResults( getMaxSizeLimit( domainID, storedConfiguration ) );
  239. searchHelper.setSearchScope( SearchScope.ONE );
  240. return chaiProvider.search( dn, searchHelper ).keySet();
  241. }
  242. private Set<String> adRootDNList( final DomainID domainID, final ProfileID profile )
  243. throws ChaiUnavailableException, ChaiOperationException, PwmUnrecoverableException
  244. {
  245. final ChaiProvider chaiProvider = getChaiProvider( domainID, profile );
  246. final Set<String> adRootValues = new HashSet<>();
  247. if ( chaiProvider.getDirectoryVendor() == DirectoryVendor.ACTIVE_DIRECTORY )
  248. {
  249. final ChaiEntry chaiEntry = ChaiUtility.getRootDSE( chaiProvider );
  250. adRootValues.addAll( chaiEntry.readMultiStringAttribute( "namingContexts" ) );
  251. }
  252. return adRootValues;
  253. }
  254. private static String rdnNameFromDN( final String dn )
  255. {
  256. int end = dn.indexOf( ',' );
  257. if ( end == -1 )
  258. {
  259. end = dn.length();
  260. }
  261. return dn.substring( 0, end );
  262. }
  263. @Value
  264. @Builder
  265. public static class LdapBrowseResult
  266. {
  267. private String dn;
  268. private ProfileID profileID;
  269. private String parentDN;
  270. private List<ProfileID> profileList;
  271. private boolean maxResults;
  272. private List<DNInformation> navigableDNlist;
  273. private List<DNInformation> selectableDNlist;
  274. }
  275. @Value
  276. public static class DNInformation
  277. {
  278. private final String entryName;
  279. private final String dn;
  280. }
  281. }