codekingpro/portable-devtools
114k
1"""2"""3 4# Created on 2016.12.265#6# Author: Giovanni Cannata7#8# Copyright 2016 - 2020 Giovanni Cannata9#10# This file is part of ldap3.11#12# ldap3 is free software: you can redistribute it and/or modify13# it under the terms of the GNU Lesser General Public License as published14# by the Free Software Foundation, either version 3 of the License, or15# (at your option) any later version.16#17# ldap3 is distributed in the hope that it will be useful,18# but WITHOUT ANY WARRANTY; without even the implied warranty of19# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the20# GNU Lesser General Public License for more details.21#22# You should have received a copy of the GNU Lesser General Public License23# along with ldap3 in the COPYING and COPYING.LESSER files.24# If not, see <http://www.gnu.org/licenses/>.25 26from ...core.exceptions import LDAPInvalidDnError, LDAPOperationsErrorResult27from ... import SEQUENCE_TYPES, MODIFY_DELETE, BASE, DEREF_NEVER28from ...utils.dn import safe_dn29 30 31def ad_remove_members_from_groups(connection,32 members_dn,33 groups_dn,34 fix,35 raise_error=False):36 """37 :param connection: a bound Connection object38 :param members_dn: the list of members to remove from groups39 :param groups_dn: the list of groups where members are to be removed40 :param fix: checks for group existence and existing members41 :param raise_error: If the operation fails it raises an error instead of returning False42 :return: a boolean where True means that the operation was successful and False means an error has happened43 Removes users-groups relations following the Activwe Directory rules: users are removed from groups' member attribute44 45 """46 if not isinstance(members_dn, SEQUENCE_TYPES):47 members_dn = [members_dn]48 49 if not isinstance(groups_dn, SEQUENCE_TYPES):50 groups_dn = [groups_dn]51 52 if connection.check_names: # builds new lists with sanitized dn53 members_dn = [safe_dn(member_dn) for member_dn in members_dn]54 groups_dn = [safe_dn(group_dn) for group_dn in groups_dn]55 56 error = False57 58 for group in groups_dn:59 if fix: # checks for existance of group and for already assigned members60 result = connection.search(group, '(objectclass=*)', BASE, dereference_aliases=DEREF_NEVER, attributes=['member'])61 62 if not connection.strategy.sync:63 response, result = connection.get_response(result)64 else:65 if connection.strategy.thread_safe:66 _, result, response, _ = result67 else:68 response = connection.response69 result = connection.result70 71 if not result['description'] == 'success':72 raise LDAPInvalidDnError(group + ' not found')73 74 existing_members = response[0]['attributes']['member'] if 'member' in response[0]['attributes'] else []75 else:76 existing_members = members_dn77 78 existing_members = [element.lower() for element in existing_members]79 changes = dict()80 member_to_remove = [element for element in members_dn if element.lower() in existing_members]81 if member_to_remove:82 changes['member'] = (MODIFY_DELETE, member_to_remove)83 if changes:84 result = connection.modify(group, changes)85 if not connection.strategy.sync:86 _, result = connection.get_response(result)87 else:88 if connection.strategy.thread_safe:89 _, result, _, _ = result90 else:91 result = connection.result92 if result['description'] != 'success':93 error = True94 result_error_params = ['result', 'description', 'dn', 'message']95 if raise_error:96 raise LDAPOperationsErrorResult([(k, v) for k, v in result.items() if k in result_error_params])97 break98 99 return not error100 