3 * XML password backend for samba
4 * Copyright (C) Jelmer Vernooij 2002
5 * Some parts based on the libxml gjobread example by Daniel Veillard
7 * This program is free software; you can redistribute it and/or modify it under
8 * the terms of the GNU General Public License as published by the Free
9 * Software Foundation; either version 2 of the License, or (at your option)
12 * This program is distributed in the hope that it will be useful, but WITHOUT
13 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
14 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
17 * You should have received a copy of the GNU General Public License along with
18 * this program; if not, write to the Free Software Foundation, Inc., 675
19 * Mass Ave, Cambridge, MA 02139, USA.
23 * - Support stdin input by using '-'
24 * - Be faster. Don't rewrite the whole file when adding a user, but store it in the memory and save it when exiting. Requires changes to samba source.
25 * - Gives the ability to read/write to standard input/output
31 #define XML_URL "http://www.samba.org/ns"
35 #include <libxml/xmlmemory.h>
36 #include <libxml/parser.h>
38 static int xmlsam_debug_level = DBGC_ALL;
41 #define DBGC_CLASS xmlsam_debug_level
43 PDB_MODULE_VERSIONING_MAGIC
45 static char * iota(int a) {
48 snprintf(tmp, 9, "%d", a);
52 BOOL parsePass(xmlDocPtr doc, xmlNsPtr ns, xmlNodePtr cur, SAM_ACCOUNT * u)
56 cur = cur->xmlChildrenNode;
58 if (strcmp(cur->name, "crypt"))
59 DEBUG(0, ("Unknown element %s\n", cur->name));
61 if (!strcmp(xmlGetProp(cur, "type"), "nt")
63 pdb_gethexpwd(xmlNodeListGetString
64 (doc, cur->xmlChildrenNode, 1), temp))
65 pdb_set_nt_passwd(u, temp, PDB_SET);
66 else if (!strcmp(xmlGetProp(cur, "type"), "lanman")
68 pdb_gethexpwd(xmlNodeListGetString
69 (doc, cur->xmlChildrenNode, 1), temp))
70 pdb_set_lanman_passwd(u, temp, PDB_SET);
73 ("Unknown crypt type: %s\n",
74 xmlGetProp(cur, "type")));
81 BOOL parseUser(xmlDocPtr doc, xmlNsPtr ns, xmlNodePtr cur, SAM_ACCOUNT * u)
86 tmp = xmlGetProp(cur, "sid");
88 string_to_sid(&sid, tmp);
89 pdb_set_user_sid(u, &sid, PDB_SET);
91 tmp = xmlGetProp(cur, "uid");
93 pdb_set_uid(u, atol(tmp), PDB_SET);
94 pdb_set_username(u, xmlGetProp(cur, "name"), PDB_SET);
95 /* We don't care what the top level element name is */
96 cur = cur->xmlChildrenNode;
98 if ((!strcmp(cur->name, "group")) && (cur->ns == ns)) {
99 tmp = xmlGetProp(cur, "gid");
101 pdb_set_gid(u, atol(tmp), PDB_SET);
102 tmp = xmlGetProp(cur, "sid");
104 string_to_sid(&sid, tmp);
105 pdb_set_group_sid(u, &sid, PDB_SET);
109 else if ((!strcmp(cur->name, "domain")) && (cur->ns == ns))
111 xmlNodeListGetString(doc, cur->xmlChildrenNode,
114 else if (!strcmp(cur->name, "fullname") && cur->ns == ns)
116 xmlNodeListGetString(doc,
117 cur->xmlChildrenNode,
120 else if (!strcmp(cur->name, "nt_username") && cur->ns == ns)
121 pdb_set_nt_username(u,
122 xmlNodeListGetString(doc,
123 cur->xmlChildrenNode,
126 else if (!strcmp(cur->name, "logon_script") && cur->ns == ns)
127 pdb_set_logon_script(u,
128 xmlNodeListGetString(doc,
129 cur->xmlChildrenNode,
132 else if (!strcmp(cur->name, "profile_path") && cur->ns == ns)
133 pdb_set_profile_path(u,
134 xmlNodeListGetString(doc,
135 cur->xmlChildrenNode,
138 else if (!strcmp(cur->name, "logon_time") && cur->ns == ns)
139 pdb_set_logon_time(u,
140 atol(xmlNodeListGetString
141 (doc, cur->xmlChildrenNode, 1)), PDB_SET);
143 else if (!strcmp(cur->name, "logoff_time") && cur->ns == ns)
144 pdb_set_logoff_time(u,
145 atol(xmlNodeListGetString
146 (doc, cur->xmlChildrenNode, 1)),
149 else if (!strcmp(cur->name, "kickoff_time") && cur->ns == ns)
150 pdb_set_kickoff_time(u,
151 atol(xmlNodeListGetString
152 (doc, cur->xmlChildrenNode, 1)),
155 else if (!strcmp(cur->name, "logon_divs") && cur->ns == ns)
156 pdb_set_logon_divs(u,
157 atol(xmlNodeListGetString
158 (doc, cur->xmlChildrenNode, 1)), PDB_SET);
160 else if (!strcmp(cur->name, "hours_len") && cur->ns == ns)
162 atol(xmlNodeListGetString
163 (doc, cur->xmlChildrenNode, 1)), PDB_SET);
165 else if (!strcmp(cur->name, "unknown_3") && cur->ns == ns)
167 atol(xmlNodeListGetString
168 (doc, cur->xmlChildrenNode, 1)), PDB_SET);
170 else if (!strcmp(cur->name, "unknown_5") && cur->ns == ns)
172 atol(xmlNodeListGetString
173 (doc, cur->xmlChildrenNode, 1)), PDB_SET);
175 else if (!strcmp(cur->name, "unknown_6") && cur->ns == ns)
177 atol(xmlNodeListGetString
178 (doc, cur->xmlChildrenNode, 1)), PDB_SET);
180 else if (!strcmp(cur->name, "homedir") && cur->ns == ns)
182 xmlNodeListGetString(doc, cur->xmlChildrenNode,
185 else if (!strcmp(cur->name, "unknown_str") && cur->ns == ns)
186 pdb_set_unknown_str(u,
187 xmlNodeListGetString(doc,
188 cur->xmlChildrenNode,
191 else if (!strcmp(cur->name, "dir_drive") && cur->ns == ns)
193 xmlNodeListGetString(doc,
194 cur->xmlChildrenNode,
197 else if (!strcmp(cur->name, "munged_dial") && cur->ns == ns)
198 pdb_set_munged_dial(u,
199 xmlNodeListGetString(doc,
200 cur->xmlChildrenNode,
203 else if (!strcmp(cur->name, "acct_desc") && cur->ns == ns)
205 xmlNodeListGetString(doc,
206 cur->xmlChildrenNode,
209 else if (!strcmp(cur->name, "acct_ctrl") && cur->ns == ns)
211 atol(xmlNodeListGetString
212 (doc, cur->xmlChildrenNode, 1)), PDB_SET);
214 else if (!strcmp(cur->name, "workstations") && cur->ns == ns)
215 pdb_set_workstations(u,
216 xmlNodeListGetString(doc,
217 cur->xmlChildrenNode,
220 else if ((!strcmp(cur->name, "password")) && (cur->ns == ns)) {
221 tmp = xmlGetProp(cur, "last_set");
223 pdb_set_pass_last_set_time(u, atol(tmp), PDB_SET);
224 tmp = xmlGetProp(cur, "must_change");
226 pdb_set_pass_must_change_time(u, atol(tmp), PDB_SET);
227 tmp = xmlGetProp(cur, "can_change");
229 pdb_set_pass_can_change_time(u, atol(tmp), PDB_SET);
230 parsePass(doc, ns, cur, u);
234 DEBUG(0, ("Unknown element %s\n", cur->name));
241 typedef struct pdb_xml {
250 xmlNodePtr parseSambaXMLFile(struct pdb_xml *data)
254 data->doc = xmlParseFile(data->location);
255 if (data->doc == NULL)
258 cur = xmlDocGetRootElement(data->doc);
260 DEBUG(0, ("empty document\n"));
261 xmlFreeDoc(data->doc);
264 data->ns = xmlSearchNsByHref(data->doc, cur, XML_URL);
267 ("document of the wrong type, samba user namespace not found\n"));
268 xmlFreeDoc(data->doc);
271 if (strcmp(cur->name, "samba")) {
272 DEBUG(0, ("document of the wrong type, root node != samba"));
273 xmlFreeDoc(data->doc);
277 cur = cur->xmlChildrenNode;
278 while (cur && xmlIsBlankNode(cur)) {
283 if ((strcmp(cur->name, "users")) || (cur->ns != data->ns)) {
284 DEBUG(0, ("document of the wrong type, was '%s', users expected",
286 DEBUG(0, ("xmlDocDump follows\n"));
287 xmlDocDump(stderr, data->doc);
288 DEBUG(0, ("xmlDocDump finished\n"));
289 xmlFreeDoc(data->doc);
293 cur = cur->xmlChildrenNode;
297 static NTSTATUS xmlsam_setsampwent(struct pdb_methods *methods, BOOL update)
302 DEBUG(0, ("Invalid methods\n"));
303 return NT_STATUS_INVALID_PARAMETER;
305 data = (pdb_xml *) methods->private_data;
307 DEBUG(0, ("Invalid pdb_xml_data\n"));
308 return NT_STATUS_INVALID_PARAMETER;
310 data->pwent = parseSambaXMLFile(data);
312 return NT_STATUS_UNSUCCESSFUL;
317 /***************************************************************
318 End enumeration of the passwd list.
319 ****************************************************************/
321 static void xmlsam_endsampwent(struct pdb_methods *methods)
326 DEBUG(0, ("Invalid methods\n"));
330 data = (pdb_xml *) methods->private_data;
333 DEBUG(0, ("Invalid pdb_xml_data\n"));
337 xmlFreeDoc(data->doc);
342 /*****************************************************************
343 Get one SAM_ACCOUNT from the list (next in line)
344 *****************************************************************/
346 static NTSTATUS xmlsam_getsampwent(struct pdb_methods *methods, SAM_ACCOUNT * user)
351 DEBUG(0, ("Invalid methods\n"));
352 return NT_STATUS_INVALID_PARAMETER;
354 data = (pdb_xml *) methods->private_data;
357 DEBUG(0, ("Invalid pdb_xml_data\n"));
358 return NT_STATUS_INVALID_PARAMETER;
361 while (data->pwent) {
362 if ((!strcmp(data->pwent->name, "user")) &&
363 (data->pwent->ns == data->ns)) {
365 parseUser(data->doc, data->ns, data->pwent, user);
366 data->pwent = data->pwent->next;
369 data->pwent = data->pwent->next;
371 return NT_STATUS_UNSUCCESSFUL;
374 /***************************************************************************
375 Adds an existing SAM_ACCOUNT
376 ****************************************************************************/
378 static NTSTATUS xmlsam_add_sam_account(struct pdb_methods *methods, SAM_ACCOUNT * u)
382 xmlNodePtr cur, user, pass, root;
385 DEBUG(10, ("xmlsam_add_sam_account called!\n"));
388 DEBUG(0, ("Invalid methods\n"));
389 return NT_STATUS_INVALID_PARAMETER;
392 data = (pdb_xml *) methods->private_data;
394 DEBUG(0, ("Invalid pdb_xml_data\n"));
395 return NT_STATUS_INVALID_PARAMETER;
398 /* Create a new document if we can't open the current one */
399 if (!parseSambaXMLFile(data)) {
400 DEBUG(0, ("Can't load current XML file, creating a new one\n"));
401 data->doc = xmlNewDoc(XML_DEFAULT_VERSION);
402 root = xmlNewDocNode(data->doc, NULL, "samba", NULL);
403 cur = xmlDocSetRootElement(data->doc, root);
404 data->ns = xmlNewNs(root, XML_URL, "samba");
405 data->users = xmlNewChild(root, data->ns, "users", NULL);
408 user = xmlNewChild(data->users, data->ns, "user", NULL);
409 xmlNewProp(user, "sid",
410 sid_to_string(sid_str, pdb_get_user_sid(u)));
411 if (pdb_get_init_flags(u, PDB_UID) != PDB_DEFAULT)
412 xmlNewProp(user, "uid", iota(pdb_get_uid(u)));
414 if (pdb_get_username(u) && strcmp(pdb_get_username(u), ""))
415 xmlNewProp(user, "name", pdb_get_username(u));
417 cur = xmlNewChild(user, data->ns, "group", NULL);
419 xmlNewProp(cur, "sid",
420 sid_to_string(sid_str, pdb_get_group_sid(u)));
421 if (pdb_get_init_flags(u, PDB_GID) != PDB_DEFAULT)
422 xmlNewProp(cur, "gid", iota(pdb_get_gid(u)));
424 if (pdb_get_init_flags(u, PDB_LOGONTIME) != PDB_DEFAULT)
425 xmlNewChild(user, data->ns, "login_time",
426 iota(pdb_get_logon_time(u)));
428 if (pdb_get_init_flags(u, PDB_LOGOFFTIME) != PDB_DEFAULT)
429 xmlNewChild(user, data->ns, "logoff_time",
430 iota(pdb_get_logoff_time(u)));
432 if (pdb_get_init_flags(u, PDB_KICKOFFTIME) != PDB_DEFAULT)
433 xmlNewChild(user, data->ns, "kickoff_time",
434 iota(pdb_get_kickoff_time(u)));
436 if (pdb_get_domain(u) && strcmp(pdb_get_domain(u), ""))
437 xmlNewChild(user, data->ns, "domain", pdb_get_domain(u));
439 if (pdb_get_nt_username(u) && strcmp(pdb_get_nt_username(u), ""))
440 xmlNewChild(user, data->ns, "nt_username", pdb_get_nt_username(u));
442 if (pdb_get_fullname(u) && strcmp(pdb_get_fullname(u), ""))
443 xmlNewChild(user, data->ns, "fullname", pdb_get_fullname(u));
445 if (pdb_get_homedir(u) && strcmp(pdb_get_homedir(u), ""))
446 xmlNewChild(user, data->ns, "homedir", pdb_get_homedir(u));
448 if (pdb_get_dir_drive(u) && strcmp(pdb_get_dir_drive(u), ""))
449 xmlNewChild(user, data->ns, "dir_drive", pdb_get_dir_drive(u));
451 if (pdb_get_logon_script(u) && strcmp(pdb_get_logon_script(u), ""))
452 xmlNewChild(user, data->ns, "logon_script",
453 pdb_get_logon_script(u));
455 if (pdb_get_profile_path(u) && strcmp(pdb_get_profile_path(u), ""))
456 xmlNewChild(user, data->ns, "profile_path",
457 pdb_get_profile_path(u));
459 if (pdb_get_acct_desc(u) && strcmp(pdb_get_acct_desc(u), ""))
460 xmlNewChild(user, data->ns, "acct_desc", pdb_get_acct_desc(u));
462 if (pdb_get_workstations(u) && strcmp(pdb_get_workstations(u), ""))
463 xmlNewChild(user, data->ns, "workstations",
464 pdb_get_workstations(u));
466 if (pdb_get_unknown_str(u) && strcmp(pdb_get_unknown_str(u), ""))
467 xmlNewChild(user, data->ns, "unknown_str", pdb_get_unknown_str(u));
469 if (pdb_get_munged_dial(u) && strcmp(pdb_get_munged_dial(u), ""))
470 xmlNewChild(user, data->ns, "munged_dial", pdb_get_munged_dial(u));
474 pass = xmlNewChild(user, data->ns, "password", NULL);
475 if (pdb_get_pass_last_set_time(u))
476 xmlNewProp(pass, "last_set", iota(pdb_get_pass_last_set_time(u)));
477 if (pdb_get_init_flags(u, PDB_CANCHANGETIME) != PDB_DEFAULT)
478 xmlNewProp(pass, "can_change",
479 iota(pdb_get_pass_can_change_time(u)));
481 if (pdb_get_init_flags(u, PDB_MUSTCHANGETIME) != PDB_DEFAULT)
482 xmlNewProp(pass, "must_change",
483 iota(pdb_get_pass_must_change_time(u)));
486 if (pdb_get_lanman_passwd(u)) {
487 pdb_sethexpwd(temp, pdb_get_lanman_passwd(u),
488 pdb_get_acct_ctrl(u));
489 cur = xmlNewChild(pass, data->ns, "crypt", temp);
490 xmlNewProp(cur, "type", "lanman");
493 if (pdb_get_nt_passwd(u)) {
494 pdb_sethexpwd(temp, pdb_get_nt_passwd(u), pdb_get_acct_ctrl(u));
495 cur = xmlNewChild(pass, data->ns, "crypt", temp);
496 xmlNewProp(cur, "type", "nt");
499 xmlNewChild(user, data->ns, "acct_ctrl", iota(pdb_get_acct_ctrl(u)));
500 xmlNewChild(user, data->ns, "unknown_3", iota(pdb_get_unknown_3(u)));
502 if (pdb_get_logon_divs(u))
503 xmlNewChild(user, data->ns, "logon_divs",
504 iota(pdb_get_logon_divs(u)));
506 if (pdb_get_hours_len(u))
507 xmlNewChild(user, data->ns, "hours_len",
508 iota(pdb_get_hours_len(u)));
510 xmlNewChild(user, data->ns, "unknown_5", iota(pdb_get_unknown_5(u)));
511 xmlNewChild(user, data->ns, "unknown_6", iota(pdb_get_unknown_6(u)));
512 xmlSaveFile(data->location, data->doc);
517 NTSTATUS pdb_init(PDB_CONTEXT * pdb_context, PDB_METHODS ** pdb_method,
518 const char *location)
523 xmlsam_debug_level = debug_add_class("xmlsam");
524 if (xmlsam_debug_level == -1) {
525 xmlsam_debug_level = DBGC_ALL;
526 DEBUG(0, ("xmlsam: Couldn't register custom debugging class!\n"));
530 DEBUG(0, ("invalid pdb_methods specified\n"));
531 return NT_STATUS_UNSUCCESSFUL;
535 (nt_status = make_pdb_methods(pdb_context->mem_ctx, pdb_method))) {
539 (*pdb_method)->name = "xmlsam";
541 (*pdb_method)->setsampwent = xmlsam_setsampwent;
542 (*pdb_method)->endsampwent = xmlsam_endsampwent;
543 (*pdb_method)->getsampwent = xmlsam_getsampwent;
544 (*pdb_method)->add_sam_account = xmlsam_add_sam_account;
545 (*pdb_method)->getsampwnam = NULL;
546 (*pdb_method)->getsampwsid = NULL;
547 (*pdb_method)->update_sam_account = NULL;
548 (*pdb_method)->delete_sam_account = NULL;
549 (*pdb_method)->getgrsid = NULL;
550 (*pdb_method)->getgrgid = NULL;
551 (*pdb_method)->getgrnam = NULL;
552 (*pdb_method)->add_group_mapping_entry = NULL;
553 (*pdb_method)->update_group_mapping_entry = NULL;
554 (*pdb_method)->delete_group_mapping_entry = NULL;
555 (*pdb_method)->enum_group_mapping = NULL;
557 data = talloc(pdb_context->mem_ctx, sizeof(pdb_xml));
559 (location ? talloc_strdup(pdb_context->mem_ctx, location) : "-");
562 (*pdb_method)->private_data = data;
564 LIBXML_TEST_VERSION xmlKeepBlanksDefault(0);