codekingpro/portable-devtools
114k
1"""
2"""
3
4# Created on 2016.04.17
5#
6# Author: Giovanni Cannata
7#
8# Copyright 2016 - 2020 Giovanni Cannata
9#
10# This file is part of ldap3.
11#
12# ldap3 is free software: you can redistribute it and/or modify
13# it under the terms of the GNU Lesser General Public License as published
14# by the Free Software Foundation, either version 3 of the License, or
15# (at your option) any later version.
16#
17# ldap3 is distributed in the hope that it will be useful,
18# but WITHOUT ANY WARRANTY; without even the implied warranty of
19# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20# GNU Lesser General Public License for more details.
21#
22# You should have received a copy of the GNU Lesser General Public License
23# along with ldap3 in the COPYING and COPYING.LESSER files.
24# If not, see <http://www.gnu.org/licenses/>.
25from ...core.exceptions import LDAPInvalidDnError
26from ... import SEQUENCE_TYPES, MODIFY_DELETE, BASE, DEREF_NEVER
27from ...utils.dn import safe_dn
28
29
30def edir_remove_members_from_groups(connection,
31 members_dn,
32 groups_dn,
33 fix,
34 transaction):
35 """
36 :param connection: a bound Connection object
37 :param members_dn: the list of members to remove from groups
38 :param groups_dn: the list of groups where members are to be removed
39 :param fix: checks for inconsistences in the users-groups relation and fixes them
40 :param transaction: activates an LDAP transaction
41 :return: a boolean where True means that the operation was successful and False means an error has happened
42 Removes users-groups relations following the eDirectory rules: groups are removed from securityEquals and groupMembership
43 attributes in the member object while members are removed from member and equivalentToMe attributes in the group object.
44 Raises LDAPInvalidDnError if members or groups are not found in the DIT.
45
46 """
47 if not isinstance(members_dn, SEQUENCE_TYPES):
48 members_dn = [members_dn]
49
50 if not isinstance(groups_dn, SEQUENCE_TYPES):
51 groups_dn = [groups_dn]
52
53 if connection.check_names: # builds new lists with sanitized dn
54 safe_members_dn = []
55 safe_groups_dn = []
56 for member_dn in members_dn:
57 safe_members_dn.append(safe_dn(member_dn))
58 for group_dn in groups_dn:
59 safe_groups_dn.append(safe_dn(group_dn))
60
61 members_dn = safe_members_dn
62 groups_dn = safe_groups_dn
63
64 transaction_control = None
65 error = False
66
67 if transaction:
68 transaction_control = connection.extend.novell.start_transaction()
69
70 if not error:
71 for member in members_dn:
72 if fix: # checks for existance of member and for already assigned groups
73 result = connection.search(member, '(objectclass=*)', BASE, dereference_aliases=DEREF_NEVER, attributes=['securityEquals', 'groupMembership'])
74
75 if not connection.strategy.sync:
76 response, result = connection.get_response(result)
77 else:
78 if connection.strategy.thread_safe:
79 _, result, response, _ = result
80 else:
81 response = connection.response
82 result = connection.result
83
84 if not result['description'] == 'success':
85 raise LDAPInvalidDnError(member + ' not found')
86
87 existing_security_equals = response[0]['attributes']['securityEquals'] if 'securityEquals' in response[0]['attributes'] else []
88 existing_group_membership = response[0]['attributes']['groupMembership'] if 'groupMembership' in response[0]['attributes'] else []
89 else:
90 existing_security_equals = groups_dn
91 existing_group_membership = groups_dn
92 existing_security_equals = [element.lower() for element in existing_security_equals]
93 existing_group_membership = [element.lower() for element in existing_group_membership]
94
95 changes = dict()
96 security_equals_to_remove = [element for element in groups_dn if element.lower() in existing_security_equals]
97 group_membership_to_remove = [element for element in groups_dn if element.lower() in existing_group_membership]
98 if security_equals_to_remove:
99 changes['securityEquals'] = (MODIFY_DELETE, security_equals_to_remove)
100 if group_membership_to_remove:
101 changes['groupMembership'] = (MODIFY_DELETE, group_membership_to_remove)
102 if changes:
103 result = connection.modify(member, changes, controls=[transaction_control] if transaction else None)
104 if not connection.strategy.sync:
105 _, result = connection.get_response(result)
106 else:
107 if connection.strategy.thread_safe:
108 _, result, _, _ = result
109 else:
110 result = connection.result
111 if result['description'] != 'success':
112 error = True
113 break
114
115 if not error:
116 for group in groups_dn:
117 if fix: # checks for existance of group and for already assigned members
118 result = connection.search(group, '(objectclass=*)', BASE, dereference_aliases=DEREF_NEVER, attributes=['member', 'equivalentToMe'])
119
120 if not connection.strategy.sync:
121 response, result = connection.get_response(result)
122 else:
123 if connection.strategy.thread_safe:
124 _, result, response, _ = result
125 else:
126 response = connection.response
127 result = connection.result
128
129 if not result['description'] == 'success':
130 raise LDAPInvalidDnError(group + ' not found')
131
132 existing_members = response[0]['attributes']['member'] if 'member' in response[0]['attributes'] else []
133 existing_equivalent_to_me = response[0]['attributes']['equivalentToMe'] if 'equivalentToMe' in response[0]['attributes'] else []
134 else:
135 existing_members = members_dn
136 existing_equivalent_to_me = members_dn
137
138 existing_members = [element.lower() for element in existing_members]
139 existing_equivalent_to_me = [element.lower() for element in existing_equivalent_to_me]
140
141 changes = dict()
142 member_to_remove = [element for element in members_dn if element.lower() in existing_members]
143 equivalent_to_me_to_remove = [element for element in members_dn if element.lower() in existing_equivalent_to_me]
144 if member_to_remove:
145 changes['member'] = (MODIFY_DELETE, member_to_remove)
146 if equivalent_to_me_to_remove:
147 changes['equivalentToMe'] = (MODIFY_DELETE, equivalent_to_me_to_remove)
148 if changes:
149 result = connection.modify(group, changes, controls=[transaction_control] if transaction else None)
150 if not connection.strategy.sync:
151 _, result = connection.get_response(result)
152 else:
153 if connection.strategy.thread_safe:
154 _, result, _, _ = result
155 else:
156 result = connection.result
157 if result['description'] != 'success':
158 error = True
159 break
160
161 if transaction:
162 if error: # aborts transaction in case of error in the modify operations
163 result = connection.extend.novell.end_transaction(commit=False, controls=[transaction_control])
164 else:
165 result = connection.extend.novell.end_transaction(commit=True, controls=[transaction_control])
166
167 if result['description'] != 'success':
168 error = True
169
170 return not error # return True if no error is raised in the LDAP operations
171 