mirror of
https://codeberg.org/forgejo/forgejo.git
synced 2025-01-12 15:49:28 -05:00
792b4dba2c
* update github.com/blevesearch/bleve v2.0.2 -> v2.0.3 * github.com/denisenkom/go-mssqldb v0.9.0 -> v0.10.0 * github.com/editorconfig/editorconfig-core-go v2.4.1 -> v2.4.2 * github.com/go-chi/cors v1.1.1 -> v1.2.0 * github.com/go-git/go-billy v5.0.0 -> v5.1.0 * github.com/go-git/go-git v5.2.0 -> v5.3.0 * github.com/go-ldap/ldap v3.2.4 -> v3.3.0 * github.com/go-redis/redis v8.6.0 -> v8.8.2 * github.com/go-sql-driver/mysql v1.5.0 -> v1.6.0 * github.com/go-swagger/go-swagger v0.26.1 -> v0.27.0 * github.com/lib/pq v1.9.0 -> v1.10.1 * github.com/mattn/go-sqlite3 v1.14.6 -> v1.14.7 * github.com/go-testfixtures/testfixtures v3.5.0 -> v3.6.0 * github.com/issue9/identicon v1.0.1 -> v1.2.0 * github.com/klauspost/compress v1.11.8 -> v1.12.1 * github.com/mgechev/revive v1.0.3 -> v1.0.6 * github.com/microcosm-cc/bluemonday v1.0.7 -> v1.0.8 * github.com/niklasfasching/go-org v1.4.0 -> v1.5.0 * github.com/olivere/elastic v7.0.22 -> v7.0.24 * github.com/pelletier/go-toml v1.8.1 -> v1.9.0 * github.com/prometheus/client_golang v1.9.0 -> v1.10.0 * github.com/xanzy/go-gitlab v0.44.0 -> v0.48.0 * github.com/yuin/goldmark v1.3.3 -> v1.3.5 * github.com/6543/go-version v1.2.4 -> v1.3.1 * do github.com/lib/pq v1.10.0 -> v1.10.1 again ...
91 lines
2.4 KiB
Go
Vendored
91 lines
2.4 KiB
Go
Vendored
package ldap
|
|
|
|
// This file contains the "Who Am I?" extended operation as specified in rfc 4532
|
|
//
|
|
// https://tools.ietf.org/html/rfc4532
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
|
|
ber "github.com/go-asn1-ber/asn1-ber"
|
|
)
|
|
|
|
type whoAmIRequest bool
|
|
|
|
// WhoAmIResult is returned by the WhoAmI() call
|
|
type WhoAmIResult struct {
|
|
AuthzID string
|
|
}
|
|
|
|
func (r whoAmIRequest) encode() (*ber.Packet, error) {
|
|
request := ber.Encode(ber.ClassApplication, ber.TypeConstructed, ApplicationExtendedRequest, nil, "Who Am I? Extended Operation")
|
|
request.AppendChild(ber.NewString(ber.ClassContext, ber.TypePrimitive, 0, ControlTypeWhoAmI, "Extended Request Name: Who Am I? OID"))
|
|
return request, nil
|
|
}
|
|
|
|
// WhoAmI returns the authzId the server thinks we are, you may pass controls
|
|
// like a Proxied Authorization control
|
|
func (l *Conn) WhoAmI(controls []Control) (*WhoAmIResult, error) {
|
|
packet := ber.Encode(ber.ClassUniversal, ber.TypeConstructed, ber.TagSequence, nil, "LDAP Request")
|
|
packet.AppendChild(ber.NewInteger(ber.ClassUniversal, ber.TypePrimitive, ber.TagInteger, l.nextMessageID(), "MessageID"))
|
|
req := whoAmIRequest(true)
|
|
encodedWhoAmIRequest, err := req.encode()
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
packet.AppendChild(encodedWhoAmIRequest)
|
|
|
|
if len(controls) != 0 {
|
|
packet.AppendChild(encodeControls(controls))
|
|
}
|
|
|
|
l.Debug.PrintPacket(packet)
|
|
|
|
msgCtx, err := l.sendMessage(packet)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
defer l.finishMessage(msgCtx)
|
|
|
|
result := &WhoAmIResult{}
|
|
|
|
l.Debug.Printf("%d: waiting for response", msgCtx.id)
|
|
packetResponse, ok := <-msgCtx.responses
|
|
if !ok {
|
|
return nil, NewError(ErrorNetwork, errors.New("ldap: response channel closed"))
|
|
}
|
|
packet, err = packetResponse.ReadPacket()
|
|
l.Debug.Printf("%d: got response %p", msgCtx.id, packet)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
if packet == nil {
|
|
return nil, NewError(ErrorNetwork, errors.New("ldap: could not retrieve message"))
|
|
}
|
|
|
|
if l.Debug {
|
|
if err := addLDAPDescriptions(packet); err != nil {
|
|
return nil, err
|
|
}
|
|
ber.PrintPacket(packet)
|
|
}
|
|
|
|
if packet.Children[1].Tag == ApplicationExtendedResponse {
|
|
if err := GetLDAPError(packet); err != nil {
|
|
return nil, err
|
|
}
|
|
} else {
|
|
return nil, NewError(ErrorUnexpectedResponse, fmt.Errorf("Unexpected Response: %d", packet.Children[1].Tag))
|
|
}
|
|
|
|
extendedResponse := packet.Children[1]
|
|
for _, child := range extendedResponse.Children {
|
|
if child.Tag == 11 {
|
|
result.AuthzID = ber.DecodeString(child.Data.Bytes())
|
|
}
|
|
}
|
|
|
|
return result, nil
|
|
}
|