codekingpro/portable-devtools
114k
1"""
2"""
3
4# Created on 2015.11.27
5#
6# Author: Giovanni Cannata
7#
8# Copyright 2015 - 2020 Giovanni Cannata
9#
10# This file is part of ldap3.
11#
12# ldap3 is free software: you can redistribute it and/or modify
13# it under the terms of the GNU Lesser General Public License as published
14# by the Free Software Foundation, either version 3 of the License, or
15# (at your option) any later version.
16#
17# ldap3 is distributed in the hope that it will be useful,
18# but WITHOUT ANY WARRANTY; without even the implied warranty of
19# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20# GNU Lesser General Public License for more details.
21#
22# You should have received a copy of the GNU Lesser General Public License
23# along with ldap3 in the COPYING and COPYING.LESSER files.
24# If not, see <http://www.gnu.org/licenses/>.
25
26
27from ... import MODIFY_REPLACE, MODIFY_DELETE, MODIFY_ADD
28from ...utils.log import log, log_enabled, PROTOCOL
29from ...core.results import RESULT_SUCCESS
30from ...utils.dn import safe_dn
31from ...utils.conv import to_unicode
32
33
34def ad_modify_password(connection, user_dn, new_password, old_password, controls=None):
35 # old password must be None to reset password with sufficient privileges
36 if connection.check_names:
37 user_dn = safe_dn(user_dn)
38 if str is bytes: # python2, converts to unicode
39 new_password = to_unicode(new_password)
40 if old_password:
41 old_password = to_unicode(old_password)
42
43 encoded_new_password = ('"%s"' % new_password).encode('utf-16-le')
44
45 if old_password: # normal users must specify old and new password
46 encoded_old_password = ('"%s"' % old_password).encode('utf-16-le')
47 result = connection.modify(user_dn,
48 {'unicodePwd': [(MODIFY_DELETE, [encoded_old_password]),
49 (MODIFY_ADD, [encoded_new_password])]},
50 controls)
51 else: # admin users can reset password without sending the old one
52 result = connection.modify(user_dn,
53 {'unicodePwd': [(MODIFY_REPLACE, [encoded_new_password])]},
54 controls)
55
56 if not connection.strategy.sync:
57 _, result = connection.get_response(result)
58 else:
59 if connection.strategy.thread_safe:
60 _, result, _, _ = result
61 else:
62 result = connection.result
63
64 # change successful, returns True
65 if result['result'] == RESULT_SUCCESS:
66 return True
67
68 # change was not successful, raises exception if raise_exception = True in connection or returns the operation result, error code is in result['result']
69 if connection.raise_exceptions:
70 from ...core.exceptions import LDAPOperationResult
71 if log_enabled(PROTOCOL):
72 log(PROTOCOL, 'operation result <%s> for <%s>', result, connection)
73 raise LDAPOperationResult(result=result['result'], description=result['description'], dn=result['dn'], message=result['message'], response_type=result['type'])
74
75 return False
76 