cb_acl.c 3.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697
  1. /** BEGIN COPYRIGHT BLOCK
  2. * This Program is free software; you can redistribute it and/or modify it under
  3. * the terms of the GNU General Public License as published by the Free Software
  4. * Foundation; version 2 of the License.
  5. *
  6. * This Program is distributed in the hope that it will be useful, but WITHOUT
  7. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  8. * FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
  9. *
  10. * You should have received a copy of the GNU General Public License along with
  11. * this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
  12. * Place, Suite 330, Boston, MA 02111-1307 USA.
  13. *
  14. * In addition, as a special exception, Red Hat, Inc. gives You the additional
  15. * right to link the code of this Program with code not covered under the GNU
  16. * General Public License ("Non-GPL Code") and to distribute linked combinations
  17. * including the two, subject to the limitations in this paragraph. Non-GPL Code
  18. * permitted under this exception must only link to the code of this Program
  19. * through those well defined interfaces identified in the file named EXCEPTION
  20. * found in the source code files (the "Approved Interfaces"). The files of
  21. * Non-GPL Code may instantiate templates or use macros or inline functions from
  22. * the Approved Interfaces without causing the resulting work to be covered by
  23. * the GNU General Public License. Only Red Hat, Inc. may make changes or
  24. * additions to the list of Approved Interfaces. You must obey the GNU General
  25. * Public License in all respects for all of the Program code and other code used
  26. * in conjunction with the Program except the Non-GPL Code covered by this
  27. * exception. If you modify this file, you may extend this exception to your
  28. * version of the file, but you are not obligated to do so. If you do not wish to
  29. * provide this exception without modification, you must delete this exception
  30. * statement from your version and license this file solely under the GPL without
  31. * exception.
  32. *
  33. *
  34. * Copyright (C) 2001 Sun Microsystems, Inc. Used by permission.
  35. * Copyright (C) 2005 Red Hat, Inc.
  36. * All rights reserved.
  37. * END COPYRIGHT BLOCK **/
  38. #ifdef HAVE_CONFIG_H
  39. # include <config.h>
  40. #endif
  41. #include "cb.h"
  42. /*
  43. ** generic function to send back results
  44. ** Turn off acl eval on front-end when needed
  45. */
  46. void cb_set_acl_policy(Slapi_PBlock *pb) {
  47. Slapi_Backend *be;
  48. cb_backend_instance *cb;
  49. int noacl;
  50. slapi_pblock_get( pb, SLAPI_BACKEND, &be );
  51. cb = cb_get_instance(be);
  52. /* disable acl checking if the local_acl flag is not set
  53. or if the associated backend is disabled */
  54. noacl=!(cb->local_acl) || cb->associated_be_is_disabled;
  55. if (noacl) {
  56. slapi_pblock_set(pb, SLAPI_PLUGIN_DB_NO_ACL, &noacl);
  57. } else {
  58. /* Be very conservative about acl evaluation */
  59. slapi_pblock_set(pb, SLAPI_PLUGIN_DB_NO_ACL, &noacl);
  60. }
  61. }
  62. int cb_access_allowed(
  63. Slapi_PBlock *pb,
  64. Slapi_Entry *e, /* The Slapi_Entry */
  65. char *attr, /* Attribute of the entry */
  66. struct berval *val, /* value of attr. NOT USED */
  67. int access, /* access rights */
  68. char **errbuf
  69. )
  70. {
  71. switch (access) {
  72. case SLAPI_ACL_ADD:
  73. case SLAPI_ACL_DELETE:
  74. case SLAPI_ACL_COMPARE:
  75. case SLAPI_ACL_WRITE:
  76. case SLAPI_ACL_PROXY:
  77. /* Keep in mind some entries are NOT */
  78. /* available for acl evaluation */
  79. return slapi_access_allowed(pb,e,attr,val,access);
  80. default:
  81. return LDAP_INSUFFICIENT_ACCESS;
  82. }
  83. }