cb_acl.c 3.6 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192
  1. /** BEGIN COPYRIGHT BLOCK
  2. * This Program is free software; you can redistribute it and/or modify it under
  3. * the terms of the GNU General Public License as published by the Free Software
  4. * Foundation; version 2 of the License.
  5. *
  6. * This Program is distributed in the hope that it will be useful, but WITHOUT
  7. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  8. * FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
  9. *
  10. * You should have received a copy of the GNU General Public License along with
  11. * this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
  12. * Place, Suite 330, Boston, MA 02111-1307 USA.
  13. *
  14. * In addition, as a special exception, Red Hat, Inc. gives You the additional
  15. * right to link the code of this Program with code not covered under the GNU
  16. * General Public License ("Non-GPL Code") and to distribute linked combinations
  17. * including the two, subject to the limitations in this paragraph. Non-GPL Code
  18. * permitted under this exception must only link to the code of this Program
  19. * through those well defined interfaces identified in the file named EXCEPTION
  20. * found in the source code files (the "Approved Interfaces"). The files of
  21. * Non-GPL Code may instantiate templates or use macros or inline functions from
  22. * the Approved Interfaces without causing the resulting work to be covered by
  23. * the GNU General Public License. Only Red Hat, Inc. may make changes or
  24. * additions to the list of Approved Interfaces. You must obey the GNU General
  25. * Public License in all respects for all of the Program code and other code used
  26. * in conjunction with the Program except the Non-GPL Code covered by this
  27. * exception. If you modify this file, you may extend this exception to your
  28. * version of the file, but you are not obligated to do so. If you do not wish to
  29. * provide this exception without modification, you must delete this exception
  30. * statement from your version and license this file solely under the GPL without
  31. * exception.
  32. *
  33. *
  34. * Copyright (C) 2001 Sun Microsystems, Inc. Used by permission.
  35. * Copyright (C) 2005 Red Hat, Inc.
  36. * All rights reserved.
  37. * END COPYRIGHT BLOCK **/
  38. #include "cb.h"
  39. /*
  40. ** generic function to send back results
  41. ** Turn off acl eval on front-end when needed
  42. */
  43. void cb_set_acl_policy(Slapi_PBlock *pb) {
  44. Slapi_Backend *be;
  45. cb_backend_instance *cb;
  46. int noacl;
  47. slapi_pblock_get( pb, SLAPI_BACKEND, &be );
  48. cb = cb_get_instance(be);
  49. /* disable acl checking if the local_acl flag is not set
  50. or if the associated backend is disabled */
  51. noacl=!(cb->local_acl) || cb->associated_be_is_disabled;
  52. if (noacl) {
  53. slapi_pblock_set(pb, SLAPI_PLUGIN_DB_NO_ACL, &noacl);
  54. } else {
  55. /* Be very conservative about acl evaluation */
  56. slapi_pblock_set(pb, SLAPI_PLUGIN_DB_NO_ACL, &noacl);
  57. }
  58. }
  59. int cb_access_allowed(
  60. Slapi_PBlock *pb,
  61. Slapi_Entry *e, /* The Slapi_Entry */
  62. char *attr, /* Attribute of the entry */
  63. struct berval *val, /* value of attr. NOT USED */
  64. int access, /* access rights */
  65. char **errbuf
  66. )
  67. {
  68. switch (access) {
  69. case SLAPI_ACL_ADD:
  70. case SLAPI_ACL_DELETE:
  71. case SLAPI_ACL_COMPARE:
  72. case SLAPI_ACL_WRITE:
  73. case SLAPI_ACL_PROXY:
  74. /* Keep in mind some entries are NOT */
  75. /* available for acl evaluation */
  76. return slapi_access_allowed(pb,e,attr,val,access);
  77. default:
  78. return LDAP_INSUFFICIENT_ACCESS;
  79. }
  80. }