codekingpro/portable-devtools
114k
1/*-------------------------------------------------------------------------2 *3 * hba.h4 * Interface to hba.c5 *6 *7 * src/include/libpq/hba.h8 *9 *-------------------------------------------------------------------------10 */11#ifndef HBA_H12#define HBA_H13 14#include "libpq/pqcomm.h" /* pgrminclude ignore */ /* needed for NetBSD */15#include "nodes/pg_list.h"16#include "regex/regex.h"17 18 19/*20 * The following enum represents the authentication methods that21 * are supported by PostgreSQL.22 *23 * Note: keep this in sync with the UserAuthName array in hba.c.24 */25typedef enum UserAuth26{27 uaReject,28 uaImplicitReject, /* Not a user-visible option */29 uaTrust,30 uaIdent,31 uaPassword,32 uaMD5,33 uaSCRAM,34 uaGSS,35 uaSSPI,36 uaPAM,37 uaBSD,38 uaLDAP,39 uaCert,40 uaRADIUS,41 uaPeer42#define USER_AUTH_LAST uaPeer /* Must be last value of this enum */43} UserAuth;44 45/*46 * Data structures representing pg_hba.conf entries47 */48 49typedef enum IPCompareMethod50{51 ipCmpMask,52 ipCmpSameHost,53 ipCmpSameNet,54 ipCmpAll55} IPCompareMethod;56 57typedef enum ConnType58{59 ctLocal,60 ctHost,61 ctHostSSL,62 ctHostNoSSL,63 ctHostGSS,64 ctHostNoGSS,65} ConnType;66 67typedef enum ClientCertMode68{69 clientCertOff,70 clientCertCA,71 clientCertFull72} ClientCertMode;73 74typedef enum ClientCertName75{76 clientCertCN,77 clientCertDN78} ClientCertName;79 80/*81 * A single string token lexed from an authentication configuration file82 * (pg_ident.conf or pg_hba.conf), together with whether the token has83 * been quoted. If "string" begins with a slash, it may optionally84 * contain a regular expression (currently used for pg_ident.conf when85 * building IdentLines and for pg_hba.conf when building HbaLines).86 */87typedef struct AuthToken88{89 char *string;90 bool quoted;91 regex_t *regex;92} AuthToken;93 94typedef struct HbaLine95{96 char *sourcefile;97 int linenumber;98 char *rawline;99 ConnType conntype;100 List *databases;101 List *roles;102 struct sockaddr_storage addr;103 int addrlen; /* zero if we don't have a valid addr */104 struct sockaddr_storage mask;105 int masklen; /* zero if we don't have a valid mask */106 IPCompareMethod ip_cmp_method;107 char *hostname;108 UserAuth auth_method;109 char *usermap;110 char *pamservice;111 bool pam_use_hostname;112 bool ldaptls;113 char *ldapscheme;114 char *ldapserver;115 int ldapport;116 char *ldapbinddn;117 char *ldapbindpasswd;118 char *ldapsearchattribute;119 char *ldapsearchfilter;120 char *ldapbasedn;121 int ldapscope;122 char *ldapprefix;123 char *ldapsuffix;124 ClientCertMode clientcert;125 ClientCertName clientcertname;126 char *krb_realm;127 bool include_realm;128 bool compat_realm;129 bool upn_username;130 List *radiusservers;131 char *radiusservers_s;132 List *radiussecrets;133 char *radiussecrets_s;134 List *radiusidentifiers;135 char *radiusidentifiers_s;136 List *radiusports;137 char *radiusports_s;138} HbaLine;139 140typedef struct IdentLine141{142 int linenumber;143 144 char *usermap;145 AuthToken *system_user;146 AuthToken *pg_user;147} IdentLine;148 149/*150 * TokenizedAuthLine represents one line lexed from an authentication151 * configuration file. Each item in the "fields" list is a sub-list of152 * AuthTokens. We don't emit a TokenizedAuthLine for empty or all-comment153 * lines, so "fields" is never NIL (nor are any of its sub-lists).154 *155 * Exception: if an error occurs during tokenization, we might have156 * fields == NIL, in which case err_msg != NULL.157 */158typedef struct TokenizedAuthLine159{160 List *fields; /* List of lists of AuthTokens */161 char *file_name; /* File name of origin */162 int line_num; /* Line number */163 char *raw_line; /* Raw line text */164 char *err_msg; /* Error message if any */165} TokenizedAuthLine;166 167/* kluge to avoid including libpq/libpq-be.h here */168typedef struct Port hbaPort;169 170extern bool load_hba(void);171extern bool load_ident(void);172extern const char *hba_authname(UserAuth auth_method);173extern void hba_getauthmethod(hbaPort *port);174extern int check_usermap(const char *usermap_name,175 const char *pg_user, const char *system_user,176 bool case_insensitive);177extern HbaLine *parse_hba_line(TokenizedAuthLine *tok_line, int elevel);178extern IdentLine *parse_ident_line(TokenizedAuthLine *tok_line, int elevel);179extern bool pg_isblank(const char c);180extern FILE *open_auth_file(const char *filename, int elevel, int depth,181 char **err_msg);182extern void free_auth_file(FILE *file, int depth);183extern void tokenize_auth_file(const char *filename, FILE *file,184 List **tok_lines, int elevel, int depth);185 186#endif /* HBA_H */187 