2 # Copyright (c) 2006 Hans Klunder <hans.klunder@bigfoot.com>. All rights reserved.
3 # This program is free software; you can redistribute it and/or
4 # modify it under the same terms as Perl itself.
6 # It's modified by Dobrica Pavlinusic <dpavlin@rot13.org> to include following:
8 # * rewrite LDAP bind request cn: username@domain.com -> uid=username,dc=domain,dc=com
9 # * rewrite search responses:
10 # ** expand key:value pairs from hrEduPersonUniqueNumber into hrEduPersonUniqueNumber_key
11 # ** augment response with yaml/dn.yaml data (for external data import)
20 use Data::Dump qw/dump/;
21 use Convert::ASN1 qw(asn_read);
22 use Net::LDAP::ASN qw(LDAPRequest LDAPResponse);
24 use fields qw(socket target);
25 use YAML qw/LoadFile/;
30 yaml_dir => './yaml/',
31 listen => shift @ARGV || 'localhost:1389',
32 upstream_ldap => 'ldap.ffzg.hr',
34 overlay_prefix => 'ffzg-',
35 # log_file => 'log/ldap-rewrite.log',
42 return unless $config->{log_file};
45 open($log_fh, '>>', $config->{log_file}) || die "can't open ", $config->{log_file},": $!";
46 print $log_fh "# " . time;
48 $log_fh->autoflush(1);
49 print $log_fh join("\n", @_),"\n";
53 $SIG{'__WARN__'} = sub { warn @_; main::log(@_); }
57 if ( ! -d $config->{yaml_dir} ) {
58 warn "DISABLE ", $config->{yaml_dir}," data overlay";
61 warn "# config = ",dump( $config );
64 my $clientsocket=shift;
65 my $serversocket=shift;
68 asn_read($clientsocket, my $reqpdu);
70 warn "WARNING no reqpdu\n";
73 $reqpdu = log_request($reqpdu);
76 print $serversocket $reqpdu or die "Could not send PDU to server\n ";
80 my $sel = IO::Select->new($serversocket);
81 for( $ready = 1 ; $ready ; $ready = $sel->can_read(0)) {
82 asn_read($serversocket, my $respdu) or return 1;
83 $respdu = log_response($respdu);
84 # and send the result to the client
85 print $clientsocket $respdu;
95 # print '-' x 80,"\n";
96 # print "Request ASN 1:\n";
97 # Convert::ASN1::asn_hexdump(\*STDOUT,$pdu);
98 # print "Request Perl:\n";
99 my $request = $LDAPRequest->decode($pdu);
100 warn "## request = ",dump($request);
102 if ( defined $request->{bindRequest} ) {
103 if ( $request->{bindRequest}->{name} =~ m{@} ) {
104 my $old = $request->{bindRequest}->{name};
105 $request->{bindRequest}->{name} =~ s/[@\.]/,dc=/g;
106 $request->{bindRequest}->{name} =~ s/^/uid=/ unless $request->{bindRequest}->{name} =~ m/^uid=/;
107 warn "rewrite bind cn $old -> ", $request->{bindRequest}->{name};
108 Convert::ASN1::asn_hexdump(\*STDOUT,$pdu) if $debug;
109 $pdu = $LDAPRequest->encode($request);
110 Convert::ASN1::asn_hexdump(\*STDOUT,$pdu) if $debug;
120 # print '-' x 80,"\n";
121 # print "Response ASN 1:\n";
122 # Convert::ASN1::asn_hexdump(\*STDOUT,$pdu);
123 # print "Response Perl:\n";
124 my $response = $LDAPResponse->decode($pdu);
126 if ( defined $response->{protocolOp}->{searchResEntry} ) {
127 my $uid = $response->{protocolOp}->{searchResEntry}->{objectName};
128 warn "## objectName $uid";
133 if ( $_->{type} eq 'hrEduPersonUniqueNumber' ) {
134 foreach my $val ( @{ $_->{vals} } ) {
135 next if $val !~ m{.+:.+};
136 my ( $n, $v ) = split(/\s*:\s*/, $val );
137 push @attrs, { type => $_->{type} . '_' . $n, vals => [ $v ] };
140 } @{ $response->{protocolOp}->{searchResEntry}->{attributes} };
142 warn "# ++ attrs ",dump( @attrs );
144 push @{ $response->{protocolOp}->{searchResEntry}->{attributes} }, $_ foreach @attrs;
146 my $path = $config->{yaml_dir} . "$uid.yaml";
148 my $data = LoadFile($path);
149 warn "# yaml = ",dump($data);
151 foreach my $type ( keys %$data ) {
153 my $vals = $data->{$type};
155 push @{ $response->{protocolOp}->{searchResEntry}->{attributes} }, {
156 type => $config->{overlay_prefix} . $type,
157 vals => ref($vals) eq 'ARRAY' ? $vals : [ $vals ],
162 $pdu = $LDAPResponse->encode($response);
165 warn "## response = ", dump($response);
171 my $listenersock = shift;
172 my $targetsock=shift;
174 die "Could not create listener socket: $!\n" unless $listenersock;
175 die "Could not create connection to server: $!\n" unless $targetsock;
177 my $sel = IO::Select->new($listenersock);
179 while (my @ready = $sel->can_read) {
180 foreach my $fh (@ready) {
181 if ($fh == $listenersock) {
182 # let's create a new socket
183 my $psock = $listenersock->accept;
186 my $result = handle($fh,$targetsock);
188 # we have finished with the socket
191 delete $Handlers{*$fh};
199 my $listenersock = IO::Socket::INET->new(
203 LocalAddr => $config->{listen},
204 ) || die "can't open listen socket: $!";
207 my $targetsock = $config->{upstream_ssl}
208 ? IO::Socket::INET->new(
210 PeerAddr => $config->{upstream_ldap},
213 : IO::Socket::SSL->new( $config->{upstream_ldap} . ':ldaps')
214 || die "can't open upstream socket: $!";
216 run_proxy($listenersock,$targetsock);