Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
removeMembersFromGroups.py171 linesDownload Raw Back to novell
1"""
2"""
3
4# Created on 2016.04.17
5#
6# Author: Giovanni Cannata
7#
8# Copyright 2016 - 2020 Giovanni Cannata
9#
10# This file is part of ldap3.
11#
12# ldap3 is free software: you can redistribute it and/or modify
13# it under the terms of the GNU Lesser General Public License as published
14# by the Free Software Foundation, either version 3 of the License, or
15# (at your option) any later version.
16#
17# ldap3 is distributed in the hope that it will be useful,
18# but WITHOUT ANY WARRANTY; without even the implied warranty of
19# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
20# GNU Lesser General Public License for more details.
21#
22# You should have received a copy of the GNU Lesser General Public License
23# along with ldap3 in the COPYING and COPYING.LESSER files.
24# If not, see <http://www.gnu.org/licenses/>.
25from ...core.exceptions import LDAPInvalidDnError
26from ... import SEQUENCE_TYPES, MODIFY_DELETE, BASE, DEREF_NEVER
27from ...utils.dn import safe_dn
28
29
30def edir_remove_members_from_groups(connection,
31                                    members_dn,
32                                    groups_dn,
33                                    fix,
34                                    transaction):
35    """
36    :param connection: a bound Connection object
37    :param members_dn: the list of members to remove from groups
38    :param groups_dn: the list of groups where members are to be removed
39    :param fix: checks for inconsistences in the users-groups relation and fixes them
40    :param transaction: activates an LDAP transaction
41    :return: a boolean where True means that the operation was successful and False means an error has happened
42    Removes users-groups relations following the eDirectory rules: groups are removed from securityEquals and groupMembership
43    attributes in the member object while members are removed from member and equivalentToMe attributes in the group object.
44    Raises LDAPInvalidDnError if members or groups are not found in the DIT.
45
46    """
47    if not isinstance(members_dn, SEQUENCE_TYPES):
48        members_dn = [members_dn]
49
50    if not isinstance(groups_dn, SEQUENCE_TYPES):
51        groups_dn = [groups_dn]
52
53    if connection.check_names:  # builds new lists with sanitized dn
54        safe_members_dn = []
55        safe_groups_dn = []
56        for member_dn in members_dn:
57            safe_members_dn.append(safe_dn(member_dn))
58        for group_dn in groups_dn:
59            safe_groups_dn.append(safe_dn(group_dn))
60
61        members_dn = safe_members_dn
62        groups_dn = safe_groups_dn
63
64    transaction_control = None
65    error = False
66
67    if transaction:
68        transaction_control = connection.extend.novell.start_transaction()
69
70    if not error:
71        for member in members_dn:
72            if fix:  # checks for existance of member and for already assigned groups
73                result = connection.search(member, '(objectclass=*)', BASE, dereference_aliases=DEREF_NEVER, attributes=['securityEquals', 'groupMembership'])
74
75                if not connection.strategy.sync:
76                    response, result = connection.get_response(result)
77                else:
78                    if connection.strategy.thread_safe:
79                        _, result, response, _ = result
80                    else:
81                        response = connection.response
82                        result = connection.result
83
84                if not result['description'] == 'success':
85                    raise LDAPInvalidDnError(member + ' not found')
86
87                existing_security_equals = response[0]['attributes']['securityEquals'] if 'securityEquals' in response[0]['attributes'] else []
88                existing_group_membership = response[0]['attributes']['groupMembership'] if 'groupMembership' in response[0]['attributes'] else []
89            else:
90                existing_security_equals = groups_dn
91                existing_group_membership = groups_dn
92            existing_security_equals = [element.lower() for element in existing_security_equals]
93            existing_group_membership = [element.lower() for element in existing_group_membership]
94
95            changes = dict()
96            security_equals_to_remove = [element for element in groups_dn if element.lower() in existing_security_equals]
97            group_membership_to_remove = [element for element in groups_dn if element.lower() in existing_group_membership]
98            if security_equals_to_remove:
99                changes['securityEquals'] = (MODIFY_DELETE, security_equals_to_remove)
100            if group_membership_to_remove:
101                changes['groupMembership'] = (MODIFY_DELETE, group_membership_to_remove)
102            if changes:
103                result = connection.modify(member, changes, controls=[transaction_control] if transaction else None)
104                if not connection.strategy.sync:
105                    _, result = connection.get_response(result)
106                else:
107                    if connection.strategy.thread_safe:
108                        _, result, _, _ = result
109                    else:
110                        result = connection.result
111                if result['description'] != 'success':
112                    error = True
113                    break
114
115    if not error:
116        for group in groups_dn:
117            if fix:  # checks for existance of group and for already assigned members
118                result = connection.search(group, '(objectclass=*)', BASE, dereference_aliases=DEREF_NEVER, attributes=['member', 'equivalentToMe'])
119
120                if not connection.strategy.sync:
121                    response, result = connection.get_response(result)
122                else:
123                    if connection.strategy.thread_safe:
124                        _, result, response, _ = result
125                    else:
126                        response = connection.response
127                        result = connection.result
128
129                if not result['description'] == 'success':
130                    raise LDAPInvalidDnError(group + ' not found')
131
132                existing_members = response[0]['attributes']['member'] if 'member' in response[0]['attributes'] else []
133                existing_equivalent_to_me = response[0]['attributes']['equivalentToMe'] if 'equivalentToMe' in response[0]['attributes'] else []
134            else:
135                existing_members = members_dn
136                existing_equivalent_to_me = members_dn
137
138            existing_members = [element.lower() for element in existing_members]
139            existing_equivalent_to_me = [element.lower() for element in existing_equivalent_to_me]
140
141            changes = dict()
142            member_to_remove = [element for element in members_dn if element.lower() in existing_members]
143            equivalent_to_me_to_remove = [element for element in members_dn if element.lower() in existing_equivalent_to_me]
144            if member_to_remove:
145                changes['member'] = (MODIFY_DELETE, member_to_remove)
146            if equivalent_to_me_to_remove:
147                changes['equivalentToMe'] = (MODIFY_DELETE, equivalent_to_me_to_remove)
148            if changes:
149                result = connection.modify(group, changes, controls=[transaction_control] if transaction else None)
150                if not connection.strategy.sync:
151                    _, result = connection.get_response(result)
152                else:
153                    if connection.strategy.thread_safe:
154                        _, result, _, _ = result
155                    else:
156                        result = connection.result
157                if result['description'] != 'success':
158                    error = True
159                    break
160
161    if transaction:
162        if error:  # aborts transaction in case of error in the modify operations
163            result = connection.extend.novell.end_transaction(commit=False, controls=[transaction_control])
164        else:
165            result = connection.extend.novell.end_transaction(commit=True, controls=[transaction_control])
166
167        if result['description'] != 'success':
168            error = True
169
170    return not error  # return True if no error is raised in the LDAP operations
171 
codekingpro/portable-devtools · Team Ai