ldap.c 142 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986
  1. /*
  2. +----------------------------------------------------------------------+
  3. | PHP Version 7 |
  4. +----------------------------------------------------------------------+
  5. | Copyright (c) 1997-2018 The PHP Group |
  6. +----------------------------------------------------------------------+
  7. | This source file is subject to version 3.01 of the PHP license, |
  8. | that is bundled with this package in the file LICENSE, and is |
  9. | available through the world-wide-web at the following url: |
  10. | http://www.php.net/license/3_01.txt |
  11. | If you did not receive a copy of the PHP license and are unable to |
  12. | obtain it through the world-wide-web, please send a note to |
  13. | license@php.net so we can mail you a copy immediately. |
  14. +----------------------------------------------------------------------+
  15. | Authors: Amitay Isaacs <amitay@w-o-i.com> |
  16. | Eric Warnke <ericw@albany.edu> |
  17. | Rasmus Lerdorf <rasmus@php.net> |
  18. | Gerrit Thomson <334647@swin.edu.au> |
  19. | Jani Taskinen <sniper@iki.fi> |
  20. | Stig Venaas <venaas@uninett.no> |
  21. | Doug Goldstein <cardoe@cardoe.com> |
  22. | Côme Chilliet <mcmic@php.net> |
  23. | PHP 4.0 updates: Zeev Suraski <zeev@php.net> |
  24. +----------------------------------------------------------------------+
  25. */
  26. #define IS_EXT_MODULE
  27. #ifdef HAVE_CONFIG_H
  28. #include "config.h"
  29. #endif
  30. #include "php.h"
  31. #include "php_ini.h"
  32. #include <stddef.h>
  33. #include "ext/standard/dl.h"
  34. #include "php_ldap.h"
  35. #ifdef PHP_WIN32
  36. #include <string.h>
  37. #include "config.w32.h"
  38. #if HAVE_NSLDAP
  39. #include <winsock2.h>
  40. #endif
  41. #define strdup _strdup
  42. #undef WINDOWS
  43. #undef strcasecmp
  44. #undef strncasecmp
  45. #define WINSOCK 1
  46. #define __STDC__ 1
  47. #endif
  48. #include "ext/standard/php_string.h"
  49. #include "ext/standard/info.h"
  50. #ifdef HAVE_LDAP_SASL_H
  51. #include <sasl.h>
  52. #elif defined(HAVE_LDAP_SASL_SASL_H)
  53. #include <sasl/sasl.h>
  54. #endif
  55. #define PHP_LDAP_ESCAPE_FILTER 0x01
  56. #define PHP_LDAP_ESCAPE_DN 0x02
  57. #if defined(LDAP_CONTROL_PAGEDRESULTS) && !defined(HAVE_LDAP_CONTROL_FIND)
  58. LDAPControl *ldap_control_find( const char *oid, LDAPControl **ctrls, LDAPControl ***nextctrlp)
  59. {
  60. assert(nextctrlp == NULL);
  61. return ldap_find_control(oid, ctrls);
  62. }
  63. #endif
  64. #if !defined(LDAP_API_FEATURE_X_OPENLDAP)
  65. void ldap_memvfree(void **v)
  66. {
  67. ldap_value_free((char **)v);
  68. }
  69. #endif
  70. typedef struct {
  71. LDAP *link;
  72. #if defined(LDAP_API_FEATURE_X_OPENLDAP) && defined(HAVE_3ARG_SETREBINDPROC)
  73. zval rebindproc;
  74. #endif
  75. } ldap_linkdata;
  76. typedef struct {
  77. LDAPMessage *data;
  78. BerElement *ber;
  79. zval res;
  80. } ldap_resultentry;
  81. ZEND_DECLARE_MODULE_GLOBALS(ldap)
  82. static PHP_GINIT_FUNCTION(ldap);
  83. static int le_link, le_result, le_result_entry;
  84. #ifdef COMPILE_DL_LDAP
  85. ZEND_GET_MODULE(ldap)
  86. #endif
  87. static void _close_ldap_link(zend_resource *rsrc) /* {{{ */
  88. {
  89. ldap_linkdata *ld = (ldap_linkdata *)rsrc->ptr;
  90. ldap_unbind_ext(ld->link, NULL, NULL);
  91. #if defined(LDAP_API_FEATURE_X_OPENLDAP) && defined(HAVE_3ARG_SETREBINDPROC)
  92. zval_ptr_dtor(&ld->rebindproc);
  93. #endif
  94. efree(ld);
  95. LDAPG(num_links)--;
  96. }
  97. /* }}} */
  98. static void _free_ldap_result(zend_resource *rsrc) /* {{{ */
  99. {
  100. LDAPMessage *result = (LDAPMessage *)rsrc->ptr;
  101. ldap_msgfree(result);
  102. }
  103. /* }}} */
  104. static void _free_ldap_result_entry(zend_resource *rsrc) /* {{{ */
  105. {
  106. ldap_resultentry *entry = (ldap_resultentry *)rsrc->ptr;
  107. if (entry->ber != NULL) {
  108. ber_free(entry->ber, 0);
  109. entry->ber = NULL;
  110. }
  111. zval_ptr_dtor(&entry->res);
  112. efree(entry);
  113. }
  114. /* }}} */
  115. /* {{{ Parse controls from and to arrays */
  116. static void _php_ldap_control_to_array(LDAP *ld, LDAPControl* ctrl, zval* array, int request)
  117. {
  118. array_init(array);
  119. add_assoc_string(array, "oid", ctrl->ldctl_oid);
  120. if (request) {
  121. /* iscritical field only makes sense in request controls (which may be obtained by ldap_get_option) */
  122. add_assoc_bool(array, "iscritical", (ctrl->ldctl_iscritical != 0));
  123. }
  124. /* If it is a known oid, parse to values */
  125. if (strcmp(ctrl->ldctl_oid, LDAP_CONTROL_PASSWORDPOLICYRESPONSE) == 0) {
  126. int expire = 0, grace = 0, rc;
  127. LDAPPasswordPolicyError pperr;
  128. zval value;
  129. rc = ldap_parse_passwordpolicy_control(ld, ctrl, &expire, &grace, &pperr);
  130. if ( rc == LDAP_SUCCESS ) {
  131. array_init(&value);
  132. add_assoc_long(&value, "expire", expire);
  133. add_assoc_long(&value, "grace", grace);
  134. if ( pperr != PP_noError ) {
  135. add_assoc_long(&value, "error", pperr);
  136. }
  137. add_assoc_zval(array, "value", &value);
  138. } else {
  139. add_assoc_null(array, "value");
  140. }
  141. } else if (strcmp(ctrl->ldctl_oid, LDAP_CONTROL_PAGEDRESULTS) == 0) {
  142. int lestimated, rc;
  143. struct berval lcookie = { 0L, NULL };
  144. zval value;
  145. if (ctrl->ldctl_value.bv_len) {
  146. /* ldap_parse_pageresponse_control() allocates lcookie.bv_val */
  147. rc = ldap_parse_pageresponse_control(ld, ctrl, &lestimated, &lcookie);
  148. } else {
  149. /* ldap_parse_pageresponse_control will crash if value is empty */
  150. rc = -1;
  151. }
  152. if ( rc == LDAP_SUCCESS ) {
  153. array_init(&value);
  154. add_assoc_long(&value, "size", lestimated);
  155. add_assoc_stringl(&value, "cookie", lcookie.bv_val, lcookie.bv_len);
  156. add_assoc_zval(array, "value", &value);
  157. } else {
  158. add_assoc_null(array, "value");
  159. }
  160. if (lcookie.bv_val) {
  161. ldap_memfree(lcookie.bv_val);
  162. }
  163. } else if ((strcmp(ctrl->ldctl_oid, LDAP_CONTROL_PRE_READ) == 0) || (strcmp(ctrl->ldctl_oid, LDAP_CONTROL_POST_READ) == 0)) {
  164. BerElement *ber;
  165. struct berval bv;
  166. ber = ber_init(&ctrl->ldctl_value);
  167. if (ber == NULL) {
  168. add_assoc_null(array, "value");
  169. } else if (ber_scanf(ber, "{m{" /*}}*/, &bv) == LBER_ERROR) {
  170. add_assoc_null(array, "value");
  171. } else {
  172. zval value;
  173. array_init(&value);
  174. add_assoc_stringl(&value, "dn", bv.bv_val, bv.bv_len);
  175. while (ber_scanf(ber, "{m" /*}*/, &bv) != LBER_ERROR) {
  176. int i;
  177. BerVarray vals = NULL;
  178. zval tmp;
  179. if (ber_scanf(ber, "[W]", &vals) == LBER_ERROR || vals == NULL)
  180. {
  181. break;
  182. }
  183. array_init(&tmp);
  184. for (i = 0; vals[i].bv_val != NULL; i++) {
  185. add_next_index_stringl(&tmp, vals[i].bv_val, vals[i].bv_len);
  186. }
  187. add_assoc_zval(&value, bv.bv_val, &tmp);
  188. ber_bvarray_free(vals);
  189. }
  190. add_assoc_zval(array, "value", &value);
  191. }
  192. if (ber != NULL) {
  193. ber_free(ber, 1);
  194. }
  195. } else if (strcmp(ctrl->ldctl_oid, LDAP_CONTROL_SORTRESPONSE) == 0) {
  196. zval value;
  197. int errcode, rc;
  198. char* attribute;
  199. if (ctrl->ldctl_value.bv_len) {
  200. rc = ldap_parse_sortresponse_control(ld, ctrl, &errcode, &attribute);
  201. } else {
  202. rc = -1;
  203. }
  204. if ( rc == LDAP_SUCCESS ) {
  205. array_init(&value);
  206. add_assoc_long(&value, "errcode", errcode);
  207. if (attribute) {
  208. add_assoc_string(&value, "attribute", attribute);
  209. ldap_memfree(attribute);
  210. }
  211. add_assoc_zval(array, "value", &value);
  212. } else {
  213. add_assoc_null(array, "value");
  214. }
  215. } else if (strcmp(ctrl->ldctl_oid, LDAP_CONTROL_VLVRESPONSE) == 0) {
  216. int target, count, errcode, rc;
  217. struct berval *context;
  218. zval value;
  219. if (ctrl->ldctl_value.bv_len) {
  220. rc = ldap_parse_vlvresponse_control(ld, ctrl, &target, &count, &context, &errcode);
  221. } else {
  222. rc = -1;
  223. }
  224. if ( rc == LDAP_SUCCESS ) {
  225. array_init(&value);
  226. add_assoc_long(&value, "target", target);
  227. add_assoc_long(&value, "count", count);
  228. add_assoc_long(&value, "errcode", errcode);
  229. if ( context && (context->bv_len >= 0) ) {
  230. add_assoc_stringl(&value, "context", context->bv_val, context->bv_len);
  231. }
  232. add_assoc_zval(array, "value", &value);
  233. } else {
  234. add_assoc_null(array, "value");
  235. }
  236. ber_bvfree(context);
  237. } else {
  238. if (ctrl->ldctl_value.bv_len) {
  239. add_assoc_stringl(array, "value", ctrl->ldctl_value.bv_val, ctrl->ldctl_value.bv_len);
  240. } else {
  241. add_assoc_null(array, "value");
  242. }
  243. }
  244. }
  245. static int _php_ldap_control_from_array(LDAP *ld, LDAPControl** ctrl, zval* array)
  246. {
  247. zval* val;
  248. zend_string *control_oid;
  249. int control_iscritical = 0, rc = LDAP_SUCCESS;
  250. char** ldap_attrs = NULL;
  251. LDAPSortKey** sort_keys = NULL;
  252. zend_string *tmpstring = NULL, **tmpstrings1 = NULL, **tmpstrings2 = NULL;
  253. size_t num_tmpstrings1 = 0, num_tmpstrings2 = 0;
  254. if ((val = zend_hash_str_find(Z_ARRVAL_P(array), "oid", sizeof("oid") - 1)) == NULL) {
  255. php_error_docref(NULL, E_WARNING, "Control must have an oid key");
  256. return -1;
  257. }
  258. control_oid = zval_get_string(val);
  259. if (EG(exception)) {
  260. return -1;
  261. }
  262. if ((val = zend_hash_str_find(Z_ARRVAL_P(array), "iscritical", sizeof("iscritical") - 1)) != NULL) {
  263. control_iscritical = zend_is_true(val);
  264. } else {
  265. control_iscritical = 0;
  266. }
  267. BerElement *ber = NULL;
  268. struct berval control_value = { 0L, NULL };
  269. int control_value_alloc = 0;
  270. if ((val = zend_hash_str_find(Z_ARRVAL_P(array), "value", sizeof("value") - 1)) != NULL) {
  271. if (Z_TYPE_P(val) != IS_ARRAY) {
  272. tmpstring = zval_get_string(val);
  273. if (EG(exception)) {
  274. rc = -1;
  275. goto failure;
  276. }
  277. control_value.bv_val = ZSTR_VAL(tmpstring);
  278. control_value.bv_len = ZSTR_LEN(tmpstring);
  279. } else if (strcmp(ZSTR_VAL(control_oid), LDAP_CONTROL_PAGEDRESULTS) == 0) {
  280. zval* tmp;
  281. int pagesize = 1;
  282. struct berval cookie = { 0L, NULL };
  283. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "size", sizeof("size") - 1)) != NULL) {
  284. pagesize = zval_get_long(tmp);
  285. }
  286. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "cookie", sizeof("cookie") - 1)) != NULL) {
  287. tmpstring = zval_get_string(tmp);
  288. if (EG(exception)) {
  289. rc = -1;
  290. goto failure;
  291. }
  292. cookie.bv_val = ZSTR_VAL(tmpstring);
  293. cookie.bv_len = ZSTR_LEN(tmpstring);
  294. }
  295. /* ldap_create_page_control_value() allocates memory for control_value.bv_val */
  296. control_value_alloc = 1;
  297. rc = ldap_create_page_control_value(ld, pagesize, &cookie, &control_value);
  298. if (rc != LDAP_SUCCESS) {
  299. php_error_docref(NULL, E_WARNING, "Failed to create paged result control value: %s (%d)", ldap_err2string(rc), rc);
  300. }
  301. } else if (strcmp(ZSTR_VAL(control_oid), LDAP_CONTROL_ASSERT) == 0) {
  302. zval* tmp;
  303. zend_string* assert;
  304. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "filter", sizeof("filter") - 1)) == NULL) {
  305. rc = -1;
  306. php_error_docref(NULL, E_WARNING, "Filter missing from assert control value array");
  307. } else {
  308. assert = zval_get_string(tmp);
  309. if (EG(exception)) {
  310. rc = -1;
  311. goto failure;
  312. }
  313. /* ldap_create_assertion_control_value does not reset ld_errno, we need to do it ourselves
  314. See http://www.openldap.org/its/index.cgi/Incoming?id=8674 */
  315. int success = LDAP_SUCCESS;
  316. ldap_set_option(ld, LDAP_OPT_RESULT_CODE, &success);
  317. /* ldap_create_assertion_control_value() allocates memory for control_value.bv_val */
  318. control_value_alloc = 1;
  319. rc = ldap_create_assertion_control_value(ld, ZSTR_VAL(assert), &control_value);
  320. if (rc != LDAP_SUCCESS) {
  321. php_error_docref(NULL, E_WARNING, "Failed to create assert control value: %s (%d)", ldap_err2string(rc), rc);
  322. }
  323. zend_string_release(assert);
  324. }
  325. } else if (strcmp(ZSTR_VAL(control_oid), LDAP_CONTROL_VALUESRETURNFILTER) == 0) {
  326. zval* tmp;
  327. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "filter", sizeof("filter") - 1)) == NULL) {
  328. rc = -1;
  329. php_error_docref(NULL, E_WARNING, "Filter missing from control value array");
  330. } else {
  331. ber = ber_alloc_t(LBER_USE_DER);
  332. if (ber == NULL) {
  333. rc = -1;
  334. php_error_docref(NULL, E_WARNING, "Failed to allocate control value");
  335. } else {
  336. tmpstring = zval_get_string(tmp);
  337. if (EG(exception)) {
  338. rc = -1;
  339. goto failure;
  340. }
  341. if (ldap_put_vrFilter(ber, ZSTR_VAL(tmpstring)) == -1) {
  342. rc = -1;
  343. php_error_docref(NULL, E_WARNING, "Failed to create control value: Bad ValuesReturnFilter: %s", ZSTR_VAL(tmpstring));
  344. } else if (ber_flatten2(ber, &control_value, control_value_alloc) == -1) {
  345. rc = -1;
  346. }
  347. }
  348. }
  349. } else if ((strcmp(ZSTR_VAL(control_oid), LDAP_CONTROL_PRE_READ) == 0) || (strcmp(ZSTR_VAL(control_oid), LDAP_CONTROL_POST_READ) == 0)) {
  350. zval* tmp;
  351. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "attrs", sizeof("attrs") - 1)) == NULL) {
  352. rc = -1;
  353. php_error_docref(NULL, E_WARNING, "Attributes list missing from control value array");
  354. } else {
  355. ber = ber_alloc_t(LBER_USE_DER);
  356. if (ber == NULL) {
  357. rc = -1;
  358. php_error_docref(NULL, E_WARNING, "Failed to allocate control value");
  359. } else {
  360. int num_attribs, i;
  361. zval* attr;
  362. num_attribs = zend_hash_num_elements(Z_ARRVAL_P(tmp));
  363. ldap_attrs = safe_emalloc((num_attribs+1), sizeof(char *), 0);
  364. tmpstrings1 = safe_emalloc(num_attribs, sizeof(zend_string*), 0);
  365. num_tmpstrings1 = 0;
  366. for (i = 0; i<num_attribs; i++) {
  367. if ((attr = zend_hash_index_find(Z_ARRVAL_P(tmp), i)) == NULL) {
  368. rc = -1;
  369. php_error_docref(NULL, E_WARNING, "Failed to encode attribute list");
  370. goto failure;
  371. }
  372. tmpstrings1[num_tmpstrings1] = zval_get_string(attr);
  373. if (EG(exception)) {
  374. rc = -1;
  375. goto failure;
  376. }
  377. ldap_attrs[i] = ZSTR_VAL(tmpstrings1[num_tmpstrings1]);
  378. ++num_tmpstrings1;
  379. }
  380. ldap_attrs[num_attribs] = NULL;
  381. ber_init2( ber, NULL, LBER_USE_DER );
  382. if (ber_printf(ber, "{v}", ldap_attrs) == -1) {
  383. rc = -1;
  384. php_error_docref(NULL, E_WARNING, "Failed to encode attribute list");
  385. } else {
  386. int err;
  387. err = ber_flatten2(ber, &control_value, control_value_alloc);
  388. if (err < 0) {
  389. rc = -1;
  390. php_error_docref(NULL, E_WARNING, "Failed to encode control value (%d)", err);
  391. }
  392. }
  393. }
  394. }
  395. } else if (strcmp(ZSTR_VAL(control_oid), LDAP_CONTROL_SORTREQUEST) == 0) {
  396. int num_keys, i;
  397. zval *sortkey, *tmp;
  398. num_keys = zend_hash_num_elements(Z_ARRVAL_P(val));
  399. sort_keys = safe_emalloc((num_keys+1), sizeof(LDAPSortKey*), 0);
  400. tmpstrings1 = safe_emalloc(num_keys, sizeof(zend_string*), 0);
  401. tmpstrings2 = safe_emalloc(num_keys, sizeof(zend_string*), 0);
  402. num_tmpstrings1 = 0;
  403. num_tmpstrings2 = 0;
  404. for (i = 0; i<num_keys; i++) {
  405. if ((sortkey = zend_hash_index_find(Z_ARRVAL_P(val), i)) == NULL) {
  406. rc = -1;
  407. php_error_docref(NULL, E_WARNING, "Failed to encode sort keys list");
  408. goto failure;
  409. }
  410. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(sortkey), "attr", sizeof("attr") - 1)) == NULL) {
  411. rc = -1;
  412. php_error_docref(NULL, E_WARNING, "Sort key list missing field");
  413. goto failure;
  414. }
  415. sort_keys[i] = emalloc(sizeof(LDAPSortKey));
  416. tmpstrings1[num_tmpstrings1] = zval_get_string(tmp);
  417. if (EG(exception)) {
  418. rc = -1;
  419. goto failure;
  420. }
  421. sort_keys[i]->attributeType = ZSTR_VAL(tmpstrings1[num_tmpstrings1]);
  422. ++num_tmpstrings1;
  423. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(sortkey), "oid", sizeof("oid") - 1)) != NULL) {
  424. tmpstrings2[num_tmpstrings2] = zval_get_string(tmp);
  425. if (EG(exception)) {
  426. rc = -1;
  427. goto failure;
  428. }
  429. sort_keys[i]->orderingRule = ZSTR_VAL(tmpstrings2[num_tmpstrings2]);
  430. ++num_tmpstrings2;
  431. } else {
  432. sort_keys[i]->orderingRule = NULL;
  433. }
  434. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(sortkey), "reverse", sizeof("reverse") - 1)) != NULL) {
  435. sort_keys[i]->reverseOrder = zend_is_true(tmp);
  436. } else {
  437. sort_keys[i]->reverseOrder = 0;
  438. }
  439. }
  440. sort_keys[num_keys] = NULL;
  441. /* ldap_create_sort_control_value() allocates memory for control_value.bv_val */
  442. control_value_alloc = 1;
  443. rc = ldap_create_sort_control_value(ld, sort_keys, &control_value);
  444. if (rc != LDAP_SUCCESS) {
  445. php_error_docref(NULL, E_WARNING, "Failed to create sort control value: %s (%d)", ldap_err2string(rc), rc);
  446. }
  447. } else if (strcmp(ZSTR_VAL(control_oid), LDAP_CONTROL_VLVREQUEST) == 0) {
  448. zval* tmp;
  449. LDAPVLVInfo vlvInfo;
  450. struct berval attrValue;
  451. struct berval context;
  452. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "before", sizeof("before") - 1)) != NULL) {
  453. vlvInfo.ldvlv_before_count = zval_get_long(tmp);
  454. } else {
  455. rc = -1;
  456. php_error_docref(NULL, E_WARNING, "Before key missing from array value for VLV control");
  457. goto failure;
  458. }
  459. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "after", sizeof("after") - 1)) != NULL) {
  460. vlvInfo.ldvlv_after_count = zval_get_long(tmp);
  461. } else {
  462. rc = -1;
  463. php_error_docref(NULL, E_WARNING, "After key missing from array value for VLV control");
  464. goto failure;
  465. }
  466. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "attrvalue", sizeof("attrvalue") - 1)) != NULL) {
  467. tmpstring = zval_get_string(tmp);
  468. if (EG(exception)) {
  469. rc = -1;
  470. goto failure;
  471. }
  472. attrValue.bv_val = ZSTR_VAL(tmpstring);
  473. attrValue.bv_len = ZSTR_LEN(tmpstring);
  474. vlvInfo.ldvlv_attrvalue = &attrValue;
  475. } else if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "offset", sizeof("offset") - 1)) != NULL) {
  476. vlvInfo.ldvlv_attrvalue = NULL;
  477. vlvInfo.ldvlv_offset = zval_get_long(tmp);
  478. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "count", sizeof("count") - 1)) != NULL) {
  479. vlvInfo.ldvlv_count = zval_get_long(tmp);
  480. } else {
  481. rc = -1;
  482. php_error_docref(NULL, E_WARNING, "Count key missing from array value for VLV control");
  483. goto failure;
  484. }
  485. } else {
  486. rc = -1;
  487. php_error_docref(NULL, E_WARNING, "Missing either attrvalue or offset key from array value for VLV control");
  488. goto failure;
  489. }
  490. if ((tmp = zend_hash_str_find(Z_ARRVAL_P(val), "context", sizeof("context") - 1)) != NULL) {
  491. tmpstring = zval_get_string(tmp);
  492. if (EG(exception)) {
  493. rc = -1;
  494. goto failure;
  495. }
  496. context.bv_val = ZSTR_VAL(tmpstring);
  497. context.bv_len = ZSTR_LEN(tmpstring);
  498. vlvInfo.ldvlv_context = &context;
  499. } else {
  500. vlvInfo.ldvlv_context = NULL;
  501. }
  502. /* ldap_create_vlv_control_value() allocates memory for control_value.bv_val */
  503. control_value_alloc = 1;
  504. rc = ldap_create_vlv_control_value(ld, &vlvInfo, &control_value);
  505. if (rc != LDAP_SUCCESS) {
  506. php_error_docref(NULL, E_WARNING, "Failed to create VLV control value: %s (%d)", ldap_err2string(rc), rc);
  507. }
  508. } else {
  509. php_error_docref(NULL, E_WARNING, "Control OID %s does not expect an array as value", ZSTR_VAL(control_oid));
  510. rc = -1;
  511. }
  512. }
  513. if (rc == LDAP_SUCCESS) {
  514. rc = ldap_control_create(ZSTR_VAL(control_oid), control_iscritical, &control_value, 1, ctrl);
  515. }
  516. failure:
  517. zend_string_release(control_oid);
  518. if (tmpstring != NULL) {
  519. zend_string_release(tmpstring);
  520. }
  521. if (tmpstrings1 != NULL) {
  522. int i;
  523. for (i = 0; i < num_tmpstrings1; ++i) {
  524. zend_string_release(tmpstrings1[i]);
  525. }
  526. efree(tmpstrings1);
  527. }
  528. if (tmpstrings2 != NULL) {
  529. int i;
  530. for (i = 0; i < num_tmpstrings2; ++i) {
  531. zend_string_release(tmpstrings2[i]);
  532. }
  533. efree(tmpstrings2);
  534. }
  535. if (control_value.bv_val != NULL && control_value_alloc != 0) {
  536. ber_memfree(control_value.bv_val);
  537. }
  538. if (ber != NULL) {
  539. ber_free(ber, 1);
  540. }
  541. if (ldap_attrs != NULL) {
  542. efree(ldap_attrs);
  543. }
  544. if (sort_keys != NULL) {
  545. LDAPSortKey** sortp = sort_keys;
  546. while (*sortp) {
  547. efree(*sortp);
  548. sortp++;
  549. }
  550. efree(sort_keys);
  551. sort_keys = NULL;
  552. }
  553. if (rc == LDAP_SUCCESS) {
  554. return LDAP_SUCCESS;
  555. }
  556. /* Failed */
  557. *ctrl = NULL;
  558. return -1;
  559. }
  560. static void _php_ldap_controls_to_array(LDAP *ld, LDAPControl** ctrls, zval* array, int request)
  561. {
  562. zval tmp1;
  563. LDAPControl **ctrlp;
  564. array_init(array);
  565. if (ctrls == NULL) {
  566. return;
  567. }
  568. ctrlp = ctrls;
  569. while (*ctrlp != NULL) {
  570. _php_ldap_control_to_array(ld, *ctrlp, &tmp1, request);
  571. add_assoc_zval(array, (*ctrlp)->ldctl_oid, &tmp1);
  572. ctrlp++;
  573. }
  574. ldap_controls_free(ctrls);
  575. }
  576. static LDAPControl** _php_ldap_controls_from_array(LDAP *ld, zval* array)
  577. {
  578. int ncontrols;
  579. LDAPControl** ctrlp, **ctrls = NULL;
  580. zval* ctrlarray;
  581. int error = 0;
  582. ncontrols = zend_hash_num_elements(Z_ARRVAL_P(array));
  583. ctrls = safe_emalloc((1 + ncontrols), sizeof(*ctrls), 0);
  584. *ctrls = NULL;
  585. ctrlp = ctrls;
  586. ZEND_HASH_FOREACH_VAL(Z_ARRVAL_P(array), ctrlarray) {
  587. if (Z_TYPE_P(ctrlarray) != IS_ARRAY) {
  588. php_error_docref(NULL, E_WARNING, "The array value must contain only arrays, where each array is a control");
  589. error = 1;
  590. break;
  591. }
  592. if (_php_ldap_control_from_array(ld, ctrlp, ctrlarray) == LDAP_SUCCESS) {
  593. ++ctrlp;
  594. } else {
  595. error = 1;
  596. break;
  597. }
  598. *ctrlp = NULL;
  599. } ZEND_HASH_FOREACH_END();
  600. if (error) {
  601. ctrlp = ctrls;
  602. while (*ctrlp) {
  603. ldap_control_free(*ctrlp);
  604. ctrlp++;
  605. }
  606. efree(ctrls);
  607. ctrls = NULL;
  608. }
  609. return ctrls;
  610. }
  611. static void _php_ldap_controls_free (LDAPControl*** ctrls)
  612. {
  613. LDAPControl **ctrlp;
  614. if (*ctrls) {
  615. ctrlp = *ctrls;
  616. while (*ctrlp) {
  617. ldap_control_free(*ctrlp);
  618. ctrlp++;
  619. }
  620. efree(*ctrls);
  621. *ctrls = NULL;
  622. }
  623. }
  624. /* }}} */
  625. /* {{{ PHP_INI_BEGIN
  626. */
  627. PHP_INI_BEGIN()
  628. STD_PHP_INI_ENTRY_EX("ldap.max_links", "-1", PHP_INI_SYSTEM, OnUpdateLong, max_links, zend_ldap_globals, ldap_globals, display_link_numbers)
  629. PHP_INI_END()
  630. /* }}} */
  631. /* {{{ PHP_GINIT_FUNCTION
  632. */
  633. static PHP_GINIT_FUNCTION(ldap)
  634. {
  635. ldap_globals->num_links = 0;
  636. }
  637. /* }}} */
  638. /* {{{ PHP_MINIT_FUNCTION
  639. */
  640. PHP_MINIT_FUNCTION(ldap)
  641. {
  642. REGISTER_INI_ENTRIES();
  643. /* Constants to be used with deref-parameter in php_ldap_do_search() */
  644. REGISTER_LONG_CONSTANT("LDAP_DEREF_NEVER", LDAP_DEREF_NEVER, CONST_PERSISTENT | CONST_CS);
  645. REGISTER_LONG_CONSTANT("LDAP_DEREF_SEARCHING", LDAP_DEREF_SEARCHING, CONST_PERSISTENT | CONST_CS);
  646. REGISTER_LONG_CONSTANT("LDAP_DEREF_FINDING", LDAP_DEREF_FINDING, CONST_PERSISTENT | CONST_CS);
  647. REGISTER_LONG_CONSTANT("LDAP_DEREF_ALWAYS", LDAP_DEREF_ALWAYS, CONST_PERSISTENT | CONST_CS);
  648. /* Constants to be used with ldap_modify_batch() */
  649. REGISTER_LONG_CONSTANT("LDAP_MODIFY_BATCH_ADD", LDAP_MODIFY_BATCH_ADD, CONST_PERSISTENT | CONST_CS);
  650. REGISTER_LONG_CONSTANT("LDAP_MODIFY_BATCH_REMOVE", LDAP_MODIFY_BATCH_REMOVE, CONST_PERSISTENT | CONST_CS);
  651. REGISTER_LONG_CONSTANT("LDAP_MODIFY_BATCH_REMOVE_ALL", LDAP_MODIFY_BATCH_REMOVE_ALL, CONST_PERSISTENT | CONST_CS);
  652. REGISTER_LONG_CONSTANT("LDAP_MODIFY_BATCH_REPLACE", LDAP_MODIFY_BATCH_REPLACE, CONST_PERSISTENT | CONST_CS);
  653. REGISTER_STRING_CONSTANT("LDAP_MODIFY_BATCH_ATTRIB", LDAP_MODIFY_BATCH_ATTRIB, CONST_PERSISTENT | CONST_CS);
  654. REGISTER_STRING_CONSTANT("LDAP_MODIFY_BATCH_MODTYPE", LDAP_MODIFY_BATCH_MODTYPE, CONST_PERSISTENT | CONST_CS);
  655. REGISTER_STRING_CONSTANT("LDAP_MODIFY_BATCH_VALUES", LDAP_MODIFY_BATCH_VALUES, CONST_PERSISTENT | CONST_CS);
  656. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP
  657. /* LDAP options */
  658. REGISTER_LONG_CONSTANT("LDAP_OPT_DEREF", LDAP_OPT_DEREF, CONST_PERSISTENT | CONST_CS);
  659. REGISTER_LONG_CONSTANT("LDAP_OPT_SIZELIMIT", LDAP_OPT_SIZELIMIT, CONST_PERSISTENT | CONST_CS);
  660. REGISTER_LONG_CONSTANT("LDAP_OPT_TIMELIMIT", LDAP_OPT_TIMELIMIT, CONST_PERSISTENT | CONST_CS);
  661. #ifdef LDAP_OPT_NETWORK_TIMEOUT
  662. REGISTER_LONG_CONSTANT("LDAP_OPT_NETWORK_TIMEOUT", LDAP_OPT_NETWORK_TIMEOUT, CONST_PERSISTENT | CONST_CS);
  663. #elif defined (LDAP_X_OPT_CONNECT_TIMEOUT)
  664. REGISTER_LONG_CONSTANT("LDAP_OPT_NETWORK_TIMEOUT", LDAP_X_OPT_CONNECT_TIMEOUT, CONST_PERSISTENT | CONST_CS);
  665. #endif
  666. #ifdef LDAP_OPT_TIMEOUT
  667. REGISTER_LONG_CONSTANT("LDAP_OPT_TIMEOUT", LDAP_OPT_TIMEOUT, CONST_PERSISTENT | CONST_CS);
  668. #endif
  669. REGISTER_LONG_CONSTANT("LDAP_OPT_PROTOCOL_VERSION", LDAP_OPT_PROTOCOL_VERSION, CONST_PERSISTENT | CONST_CS);
  670. REGISTER_LONG_CONSTANT("LDAP_OPT_ERROR_NUMBER", LDAP_OPT_ERROR_NUMBER, CONST_PERSISTENT | CONST_CS);
  671. REGISTER_LONG_CONSTANT("LDAP_OPT_REFERRALS", LDAP_OPT_REFERRALS, CONST_PERSISTENT | CONST_CS);
  672. #ifdef LDAP_OPT_RESTART
  673. REGISTER_LONG_CONSTANT("LDAP_OPT_RESTART", LDAP_OPT_RESTART, CONST_PERSISTENT | CONST_CS);
  674. #endif
  675. #ifdef LDAP_OPT_HOST_NAME
  676. REGISTER_LONG_CONSTANT("LDAP_OPT_HOST_NAME", LDAP_OPT_HOST_NAME, CONST_PERSISTENT | CONST_CS);
  677. #endif
  678. REGISTER_LONG_CONSTANT("LDAP_OPT_ERROR_STRING", LDAP_OPT_ERROR_STRING, CONST_PERSISTENT | CONST_CS);
  679. #ifdef LDAP_OPT_MATCHED_DN
  680. REGISTER_LONG_CONSTANT("LDAP_OPT_MATCHED_DN", LDAP_OPT_MATCHED_DN, CONST_PERSISTENT | CONST_CS);
  681. #endif
  682. REGISTER_LONG_CONSTANT("LDAP_OPT_SERVER_CONTROLS", LDAP_OPT_SERVER_CONTROLS, CONST_PERSISTENT | CONST_CS);
  683. REGISTER_LONG_CONSTANT("LDAP_OPT_CLIENT_CONTROLS", LDAP_OPT_CLIENT_CONTROLS, CONST_PERSISTENT | CONST_CS);
  684. #endif
  685. #ifdef LDAP_OPT_DEBUG_LEVEL
  686. REGISTER_LONG_CONSTANT("LDAP_OPT_DEBUG_LEVEL", LDAP_OPT_DEBUG_LEVEL, CONST_PERSISTENT | CONST_CS);
  687. #endif
  688. #ifdef LDAP_OPT_DIAGNOSTIC_MESSAGE
  689. REGISTER_LONG_CONSTANT("LDAP_OPT_DIAGNOSTIC_MESSAGE", LDAP_OPT_DIAGNOSTIC_MESSAGE, CONST_PERSISTENT | CONST_CS);
  690. #endif
  691. #ifdef HAVE_LDAP_SASL
  692. REGISTER_LONG_CONSTANT("LDAP_OPT_X_SASL_MECH", LDAP_OPT_X_SASL_MECH, CONST_PERSISTENT | CONST_CS);
  693. REGISTER_LONG_CONSTANT("LDAP_OPT_X_SASL_REALM", LDAP_OPT_X_SASL_REALM, CONST_PERSISTENT | CONST_CS);
  694. REGISTER_LONG_CONSTANT("LDAP_OPT_X_SASL_AUTHCID", LDAP_OPT_X_SASL_AUTHCID, CONST_PERSISTENT | CONST_CS);
  695. REGISTER_LONG_CONSTANT("LDAP_OPT_X_SASL_AUTHZID", LDAP_OPT_X_SASL_AUTHZID, CONST_PERSISTENT | CONST_CS);
  696. #endif
  697. #ifdef LDAP_OPT_X_SASL_NOCANON
  698. REGISTER_LONG_CONSTANT("LDAP_OPT_X_SASL_NOCANON", LDAP_OPT_X_SASL_NOCANON, CONST_PERSISTENT | CONST_CS);
  699. #endif
  700. #ifdef LDAP_OPT_X_SASL_USERNAME
  701. REGISTER_LONG_CONSTANT("LDAP_OPT_X_SASL_USERNAME", LDAP_OPT_X_SASL_USERNAME, CONST_PERSISTENT | CONST_CS);
  702. #endif
  703. #ifdef ORALDAP
  704. REGISTER_LONG_CONSTANT("GSLC_SSL_NO_AUTH", GSLC_SSL_NO_AUTH, CONST_PERSISTENT | CONST_CS);
  705. REGISTER_LONG_CONSTANT("GSLC_SSL_ONEWAY_AUTH", GSLC_SSL_ONEWAY_AUTH, CONST_PERSISTENT | CONST_CS);
  706. REGISTER_LONG_CONSTANT("GSLC_SSL_TWOWAY_AUTH", GSLC_SSL_TWOWAY_AUTH, CONST_PERSISTENT | CONST_CS);
  707. #endif
  708. #if (LDAP_API_VERSION > 2000)
  709. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_REQUIRE_CERT", LDAP_OPT_X_TLS_REQUIRE_CERT, CONST_PERSISTENT | CONST_CS);
  710. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_NEVER", LDAP_OPT_X_TLS_NEVER, CONST_PERSISTENT | CONST_CS);
  711. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_HARD", LDAP_OPT_X_TLS_HARD, CONST_PERSISTENT | CONST_CS);
  712. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_DEMAND", LDAP_OPT_X_TLS_DEMAND, CONST_PERSISTENT | CONST_CS);
  713. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_ALLOW", LDAP_OPT_X_TLS_ALLOW, CONST_PERSISTENT | CONST_CS);
  714. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_TRY", LDAP_OPT_X_TLS_TRY, CONST_PERSISTENT | CONST_CS);
  715. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CACERTDIR", LDAP_OPT_X_TLS_CACERTDIR, CONST_PERSISTENT | CONST_CS);
  716. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CACERTFILE", LDAP_OPT_X_TLS_CACERTFILE, CONST_PERSISTENT | CONST_CS);
  717. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CERTFILE", LDAP_OPT_X_TLS_CERTFILE, CONST_PERSISTENT | CONST_CS);
  718. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CIPHER_SUITE", LDAP_OPT_X_TLS_CIPHER_SUITE, CONST_PERSISTENT | CONST_CS);
  719. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_KEYFILE", LDAP_OPT_X_TLS_KEYFILE, CONST_PERSISTENT | CONST_CS);
  720. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_RANDOM_FILE", LDAP_OPT_X_TLS_RANDOM_FILE, CONST_PERSISTENT | CONST_CS);
  721. #endif
  722. #ifdef LDAP_OPT_X_TLS_CRLCHECK
  723. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CRLCHECK", LDAP_OPT_X_TLS_CRLCHECK, CONST_PERSISTENT | CONST_CS);
  724. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CRL_NONE", LDAP_OPT_X_TLS_CRL_NONE, CONST_PERSISTENT | CONST_CS);
  725. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CRL_PEER", LDAP_OPT_X_TLS_CRL_PEER, CONST_PERSISTENT | CONST_CS);
  726. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CRL_ALL", LDAP_OPT_X_TLS_CRL_ALL, CONST_PERSISTENT | CONST_CS);
  727. #endif
  728. #ifdef LDAP_OPT_X_TLS_DHFILE
  729. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_DHFILE", LDAP_OPT_X_TLS_DHFILE, CONST_PERSISTENT | CONST_CS);
  730. #endif
  731. #ifdef LDAP_OPT_X_TLS_CRLFILE
  732. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_CRLFILE", LDAP_OPT_X_TLS_CRLFILE, CONST_PERSISTENT | CONST_CS);
  733. #endif
  734. #ifdef LDAP_OPT_X_TLS_PROTOCOL_MIN
  735. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_PROTOCOL_MIN", LDAP_OPT_X_TLS_PROTOCOL_MIN, CONST_PERSISTENT | CONST_CS);
  736. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_PROTOCOL_SSL2", LDAP_OPT_X_TLS_PROTOCOL_SSL2, CONST_PERSISTENT | CONST_CS);
  737. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_PROTOCOL_SSL3", LDAP_OPT_X_TLS_PROTOCOL_SSL3, CONST_PERSISTENT | CONST_CS);
  738. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_PROTOCOL_TLS1_0", LDAP_OPT_X_TLS_PROTOCOL_TLS1_0, CONST_PERSISTENT | CONST_CS);
  739. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_PROTOCOL_TLS1_1", LDAP_OPT_X_TLS_PROTOCOL_TLS1_1, CONST_PERSISTENT | CONST_CS);
  740. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_PROTOCOL_TLS1_2", LDAP_OPT_X_TLS_PROTOCOL_TLS1_2, CONST_PERSISTENT | CONST_CS);
  741. #endif
  742. #ifdef LDAP_OPT_X_TLS_PACKAGE
  743. REGISTER_LONG_CONSTANT("LDAP_OPT_X_TLS_PACKAGE", LDAP_OPT_X_TLS_PACKAGE, CONST_PERSISTENT | CONST_CS);
  744. #endif
  745. #ifdef LDAP_OPT_X_KEEPALIVE_IDLE
  746. REGISTER_LONG_CONSTANT("LDAP_OPT_X_KEEPALIVE_IDLE", LDAP_OPT_X_KEEPALIVE_IDLE, CONST_PERSISTENT | CONST_CS);
  747. REGISTER_LONG_CONSTANT("LDAP_OPT_X_KEEPALIVE_PROBES", LDAP_OPT_X_KEEPALIVE_PROBES, CONST_PERSISTENT | CONST_CS);
  748. REGISTER_LONG_CONSTANT("LDAP_OPT_X_KEEPALIVE_INTERVAL", LDAP_OPT_X_KEEPALIVE_INTERVAL, CONST_PERSISTENT | CONST_CS);
  749. #endif
  750. REGISTER_LONG_CONSTANT("LDAP_ESCAPE_FILTER", PHP_LDAP_ESCAPE_FILTER, CONST_PERSISTENT | CONST_CS);
  751. REGISTER_LONG_CONSTANT("LDAP_ESCAPE_DN", PHP_LDAP_ESCAPE_DN, CONST_PERSISTENT | CONST_CS);
  752. #ifdef HAVE_LDAP_EXTENDED_OPERATION_S
  753. REGISTER_STRING_CONSTANT("LDAP_EXOP_START_TLS", LDAP_EXOP_START_TLS, CONST_PERSISTENT | CONST_CS);
  754. REGISTER_STRING_CONSTANT("LDAP_EXOP_MODIFY_PASSWD", LDAP_EXOP_MODIFY_PASSWD, CONST_PERSISTENT | CONST_CS);
  755. REGISTER_STRING_CONSTANT("LDAP_EXOP_REFRESH", LDAP_EXOP_REFRESH, CONST_PERSISTENT | CONST_CS);
  756. REGISTER_STRING_CONSTANT("LDAP_EXOP_WHO_AM_I", LDAP_EXOP_WHO_AM_I, CONST_PERSISTENT | CONST_CS);
  757. REGISTER_STRING_CONSTANT("LDAP_EXOP_TURN", LDAP_EXOP_TURN, CONST_PERSISTENT | CONST_CS);
  758. #endif
  759. /* LDAP Controls */
  760. /* standard track controls */
  761. #ifdef LDAP_CONTROL_MANAGEDSAIT
  762. /* RFC 3296 */
  763. REGISTER_STRING_CONSTANT("LDAP_CONTROL_MANAGEDSAIT", LDAP_CONTROL_MANAGEDSAIT, CONST_PERSISTENT | CONST_CS);
  764. #endif
  765. #ifdef LDAP_CONTROL_PROXY_AUTHZ
  766. /* RFC 4370 */
  767. REGISTER_STRING_CONSTANT("LDAP_CONTROL_PROXY_AUTHZ", LDAP_CONTROL_PROXY_AUTHZ, CONST_PERSISTENT | CONST_CS);
  768. #endif
  769. #ifdef LDAP_CONTROL_SUBENTRIES
  770. /* RFC 3672 */
  771. REGISTER_STRING_CONSTANT("LDAP_CONTROL_SUBENTRIES", LDAP_CONTROL_SUBENTRIES, CONST_PERSISTENT | CONST_CS);
  772. #endif
  773. #ifdef LDAP_CONTROL_VALUESRETURNFILTER
  774. /* RFC 3876 */
  775. REGISTER_STRING_CONSTANT("LDAP_CONTROL_VALUESRETURNFILTER", LDAP_CONTROL_VALUESRETURNFILTER, CONST_PERSISTENT | CONST_CS);
  776. #endif
  777. #ifdef LDAP_CONTROL_ASSERT
  778. /* RFC 4528 */
  779. REGISTER_STRING_CONSTANT("LDAP_CONTROL_ASSERT", LDAP_CONTROL_ASSERT, CONST_PERSISTENT | CONST_CS);
  780. /* RFC 4527 */
  781. REGISTER_STRING_CONSTANT("LDAP_CONTROL_PRE_READ", LDAP_CONTROL_PRE_READ, CONST_PERSISTENT | CONST_CS);
  782. REGISTER_STRING_CONSTANT("LDAP_CONTROL_POST_READ", LDAP_CONTROL_POST_READ, CONST_PERSISTENT | CONST_CS);
  783. #endif
  784. #ifdef LDAP_CONTROL_SORTREQUEST
  785. /* RFC 2891 */
  786. REGISTER_STRING_CONSTANT("LDAP_CONTROL_SORTREQUEST", LDAP_CONTROL_SORTREQUEST, CONST_PERSISTENT | CONST_CS);
  787. REGISTER_STRING_CONSTANT("LDAP_CONTROL_SORTRESPONSE", LDAP_CONTROL_SORTRESPONSE, CONST_PERSISTENT | CONST_CS);
  788. #endif
  789. /* non-standard track controls */
  790. #ifdef LDAP_CONTROL_PAGEDRESULTS
  791. /* RFC 2696 */
  792. REGISTER_STRING_CONSTANT("LDAP_CONTROL_PAGEDRESULTS", LDAP_CONTROL_PAGEDRESULTS, CONST_PERSISTENT | CONST_CS);
  793. #endif
  794. #ifdef LDAP_CONTROL_AUTHZID_REQUEST
  795. /* RFC 3829 */
  796. REGISTER_STRING_CONSTANT("LDAP_CONTROL_AUTHZID_REQUEST", LDAP_CONTROL_AUTHZID_REQUEST, CONST_PERSISTENT | CONST_CS);
  797. REGISTER_STRING_CONSTANT("LDAP_CONTROL_AUTHZID_RESPONSE", LDAP_CONTROL_AUTHZID_RESPONSE, CONST_PERSISTENT | CONST_CS);
  798. #endif
  799. #ifdef LDAP_CONTROL_SYNC
  800. /* LDAP Content Synchronization Operation -- RFC 4533 */
  801. REGISTER_STRING_CONSTANT("LDAP_CONTROL_SYNC", LDAP_CONTROL_SYNC, CONST_PERSISTENT | CONST_CS);
  802. REGISTER_STRING_CONSTANT("LDAP_CONTROL_SYNC_STATE", LDAP_CONTROL_SYNC_STATE, CONST_PERSISTENT | CONST_CS);
  803. REGISTER_STRING_CONSTANT("LDAP_CONTROL_SYNC_DONE", LDAP_CONTROL_SYNC_DONE, CONST_PERSISTENT | CONST_CS);
  804. #endif
  805. #ifdef LDAP_CONTROL_DONTUSECOPY
  806. /* LDAP Don't Use Copy Control (RFC 6171) */
  807. REGISTER_STRING_CONSTANT("LDAP_CONTROL_DONTUSECOPY", LDAP_CONTROL_DONTUSECOPY, CONST_PERSISTENT | CONST_CS);
  808. #endif
  809. #ifdef LDAP_CONTROL_PASSWORDPOLICYREQUEST
  810. /* Password policy Controls */
  811. REGISTER_STRING_CONSTANT("LDAP_CONTROL_PASSWORDPOLICYREQUEST", LDAP_CONTROL_PASSWORDPOLICYREQUEST, CONST_PERSISTENT | CONST_CS);
  812. REGISTER_STRING_CONSTANT("LDAP_CONTROL_PASSWORDPOLICYRESPONSE", LDAP_CONTROL_PASSWORDPOLICYRESPONSE, CONST_PERSISTENT | CONST_CS);
  813. #endif
  814. #ifdef LDAP_CONTROL_X_INCREMENTAL_VALUES
  815. /* MS Active Directory controls */
  816. REGISTER_STRING_CONSTANT("LDAP_CONTROL_X_INCREMENTAL_VALUES", LDAP_CONTROL_X_INCREMENTAL_VALUES, CONST_PERSISTENT | CONST_CS);
  817. REGISTER_STRING_CONSTANT("LDAP_CONTROL_X_DOMAIN_SCOPE", LDAP_CONTROL_X_DOMAIN_SCOPE, CONST_PERSISTENT | CONST_CS);
  818. REGISTER_STRING_CONSTANT("LDAP_CONTROL_X_PERMISSIVE_MODIFY", LDAP_CONTROL_X_PERMISSIVE_MODIFY, CONST_PERSISTENT | CONST_CS);
  819. REGISTER_STRING_CONSTANT("LDAP_CONTROL_X_SEARCH_OPTIONS", LDAP_CONTROL_X_SEARCH_OPTIONS, CONST_PERSISTENT | CONST_CS);
  820. REGISTER_STRING_CONSTANT("LDAP_CONTROL_X_TREE_DELETE", LDAP_CONTROL_X_TREE_DELETE, CONST_PERSISTENT | CONST_CS);
  821. REGISTER_STRING_CONSTANT("LDAP_CONTROL_X_EXTENDED_DN", LDAP_CONTROL_X_EXTENDED_DN, CONST_PERSISTENT | CONST_CS);
  822. #endif
  823. #ifdef LDAP_CONTROL_VLVREQUEST
  824. /* LDAP VLV */
  825. REGISTER_STRING_CONSTANT("LDAP_CONTROL_VLVREQUEST", LDAP_CONTROL_VLVREQUEST, CONST_PERSISTENT | CONST_CS);
  826. REGISTER_STRING_CONSTANT("LDAP_CONTROL_VLVRESPONSE", LDAP_CONTROL_VLVRESPONSE, CONST_PERSISTENT | CONST_CS);
  827. #endif
  828. le_link = zend_register_list_destructors_ex(_close_ldap_link, NULL, "ldap link", module_number);
  829. le_result = zend_register_list_destructors_ex(_free_ldap_result, NULL, "ldap result", module_number);
  830. le_result_entry = zend_register_list_destructors_ex(_free_ldap_result_entry, NULL, "ldap result entry", module_number);
  831. ldap_module_entry.type = type;
  832. return SUCCESS;
  833. }
  834. /* }}} */
  835. /* {{{ PHP_MSHUTDOWN_FUNCTION
  836. */
  837. PHP_MSHUTDOWN_FUNCTION(ldap)
  838. {
  839. UNREGISTER_INI_ENTRIES();
  840. return SUCCESS;
  841. }
  842. /* }}} */
  843. /* {{{ PHP_MINFO_FUNCTION
  844. */
  845. PHP_MINFO_FUNCTION(ldap)
  846. {
  847. char tmp[32];
  848. #if HAVE_NSLDAP
  849. LDAPVersion ver;
  850. double SDKVersion;
  851. #endif
  852. php_info_print_table_start();
  853. php_info_print_table_row(2, "LDAP Support", "enabled");
  854. if (LDAPG(max_links) == -1) {
  855. snprintf(tmp, 31, ZEND_LONG_FMT "/unlimited", LDAPG(num_links));
  856. } else {
  857. snprintf(tmp, 31, ZEND_LONG_FMT "/" ZEND_LONG_FMT, LDAPG(num_links), LDAPG(max_links));
  858. }
  859. php_info_print_table_row(2, "Total Links", tmp);
  860. #ifdef LDAP_API_VERSION
  861. snprintf(tmp, 31, "%d", LDAP_API_VERSION);
  862. php_info_print_table_row(2, "API Version", tmp);
  863. #endif
  864. #ifdef LDAP_VENDOR_NAME
  865. php_info_print_table_row(2, "Vendor Name", LDAP_VENDOR_NAME);
  866. #endif
  867. #ifdef LDAP_VENDOR_VERSION
  868. snprintf(tmp, 31, "%d", LDAP_VENDOR_VERSION);
  869. php_info_print_table_row(2, "Vendor Version", tmp);
  870. #endif
  871. #if HAVE_NSLDAP
  872. SDKVersion = ldap_version(&ver);
  873. snprintf(tmp, 31, "%F", SDKVersion/100.0);
  874. php_info_print_table_row(2, "SDK Version", tmp);
  875. snprintf(tmp, 31, "%F", ver.protocol_version/100.0);
  876. php_info_print_table_row(2, "Highest LDAP Protocol Supported", tmp);
  877. snprintf(tmp, 31, "%F", ver.SSL_version/100.0);
  878. php_info_print_table_row(2, "SSL Level Supported", tmp);
  879. if (ver.security_level != LDAP_SECURITY_NONE) {
  880. snprintf(tmp, 31, "%d", ver.security_level);
  881. } else {
  882. strcpy(tmp, "SSL not enabled");
  883. }
  884. php_info_print_table_row(2, "Level of Encryption", tmp);
  885. #endif
  886. #ifdef HAVE_LDAP_SASL
  887. php_info_print_table_row(2, "SASL Support", "Enabled");
  888. #endif
  889. php_info_print_table_end();
  890. DISPLAY_INI_ENTRIES();
  891. }
  892. /* }}} */
  893. /* {{{ proto resource ldap_connect([string host [, int port [, string wallet [, string wallet_passwd [, int authmode]]]]])
  894. Connect to an LDAP server */
  895. PHP_FUNCTION(ldap_connect)
  896. {
  897. char *host = NULL;
  898. size_t hostlen = 0;
  899. zend_long port = LDAP_PORT;
  900. #ifdef HAVE_ORALDAP
  901. char *wallet = NULL, *walletpasswd = NULL;
  902. size_t walletlen = 0, walletpasswdlen = 0;
  903. zend_long authmode = GSLC_SSL_NO_AUTH;
  904. int ssl=0;
  905. #endif
  906. ldap_linkdata *ld;
  907. LDAP *ldap = NULL;
  908. #ifdef HAVE_ORALDAP
  909. if (ZEND_NUM_ARGS() == 3 || ZEND_NUM_ARGS() == 4) {
  910. WRONG_PARAM_COUNT;
  911. }
  912. if (zend_parse_parameters(ZEND_NUM_ARGS(), "|slssl", &host, &hostlen, &port, &wallet, &walletlen, &walletpasswd, &walletpasswdlen, &authmode) != SUCCESS) {
  913. RETURN_FALSE;
  914. }
  915. if (ZEND_NUM_ARGS() == 5) {
  916. ssl = 1;
  917. }
  918. #else
  919. if (zend_parse_parameters(ZEND_NUM_ARGS(), "|sl", &host, &hostlen, &port) != SUCCESS) {
  920. RETURN_FALSE;
  921. }
  922. #endif
  923. if (LDAPG(max_links) != -1 && LDAPG(num_links) >= LDAPG(max_links)) {
  924. php_error_docref(NULL, E_WARNING, "Too many open links (" ZEND_LONG_FMT ")", LDAPG(num_links));
  925. RETURN_FALSE;
  926. }
  927. ld = ecalloc(1, sizeof(ldap_linkdata));
  928. {
  929. int rc = LDAP_SUCCESS;
  930. char *url = host;
  931. if (url && !ldap_is_ldap_url(url)) {
  932. size_t urllen = hostlen + sizeof( "ldap://:65535" );
  933. if (port <= 0 || port > 65535) {
  934. efree(ld);
  935. php_error_docref(NULL, E_WARNING, "invalid port number: " ZEND_LONG_FMT, port);
  936. RETURN_FALSE;
  937. }
  938. url = emalloc(urllen);
  939. snprintf( url, urllen, "ldap://%s:" ZEND_LONG_FMT, host, port );
  940. }
  941. #ifdef LDAP_API_FEATURE_X_OPENLDAP
  942. /* ldap_init() is deprecated, use ldap_initialize() instead.
  943. */
  944. rc = ldap_initialize(&ldap, url);
  945. #else /* ! LDAP_API_FEATURE_X_OPENLDAP */
  946. /* ldap_init does not support URLs.
  947. * We must try the original host and port information.
  948. */
  949. ldap = ldap_init(host, port);
  950. if (ldap == NULL) {
  951. efree(ld);
  952. php_error_docref(NULL, E_WARNING, "Could not create session handle");
  953. RETURN_FALSE;
  954. }
  955. #endif /* ! LDAP_API_FEATURE_X_OPENLDAP */
  956. if (url != host) {
  957. efree(url);
  958. }
  959. if (rc != LDAP_SUCCESS) {
  960. efree(ld);
  961. php_error_docref(NULL, E_WARNING, "Could not create session handle: %s", ldap_err2string(rc));
  962. RETURN_FALSE;
  963. }
  964. }
  965. if (ldap == NULL) {
  966. efree(ld);
  967. RETURN_FALSE;
  968. } else {
  969. #ifdef HAVE_ORALDAP
  970. if (ssl) {
  971. if (ldap_init_SSL(&ldap->ld_sb, wallet, walletpasswd, authmode)) {
  972. efree(ld);
  973. php_error_docref(NULL, E_WARNING, "SSL init failed");
  974. RETURN_FALSE;
  975. }
  976. }
  977. #endif
  978. LDAPG(num_links)++;
  979. ld->link = ldap;
  980. RETURN_RES(zend_register_resource(ld, le_link));
  981. }
  982. }
  983. /* }}} */
  984. /* {{{ _get_lderrno
  985. */
  986. static int _get_lderrno(LDAP *ldap)
  987. {
  988. #if !HAVE_NSLDAP
  989. #if LDAP_API_VERSION > 2000 || HAVE_ORALDAP
  990. int lderr;
  991. /* New versions of OpenLDAP do it this way */
  992. ldap_get_option(ldap, LDAP_OPT_ERROR_NUMBER, &lderr);
  993. return lderr;
  994. #else
  995. return ldap->ld_errno;
  996. #endif
  997. #else
  998. return ldap_get_lderrno(ldap, NULL, NULL);
  999. #endif
  1000. }
  1001. /* }}} */
  1002. /* {{{ _set_lderrno
  1003. */
  1004. static void _set_lderrno(LDAP *ldap, int lderr)
  1005. {
  1006. #if !HAVE_NSLDAP
  1007. #if LDAP_API_VERSION > 2000 || HAVE_ORALDAP
  1008. /* New versions of OpenLDAP do it this way */
  1009. ldap_set_option(ldap, LDAP_OPT_ERROR_NUMBER, &lderr);
  1010. #else
  1011. ldap->ld_errno = lderr;
  1012. #endif
  1013. #else
  1014. ldap_set_lderrno(ldap, lderr, NULL, NULL);
  1015. #endif
  1016. }
  1017. /* }}} */
  1018. /* {{{ proto bool ldap_bind(resource link [, string dn [, string password]])
  1019. Bind to LDAP directory */
  1020. PHP_FUNCTION(ldap_bind)
  1021. {
  1022. zval *link;
  1023. char *ldap_bind_dn = NULL, *ldap_bind_pw = NULL;
  1024. size_t ldap_bind_dnlen, ldap_bind_pwlen;
  1025. ldap_linkdata *ld;
  1026. int rc;
  1027. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r|ss", &link, &ldap_bind_dn, &ldap_bind_dnlen, &ldap_bind_pw, &ldap_bind_pwlen) != SUCCESS) {
  1028. RETURN_FALSE;
  1029. }
  1030. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1031. RETURN_FALSE;
  1032. }
  1033. if (ldap_bind_dn != NULL && memchr(ldap_bind_dn, '\0', ldap_bind_dnlen) != NULL) {
  1034. _set_lderrno(ld->link, LDAP_INVALID_CREDENTIALS);
  1035. php_error_docref(NULL, E_WARNING, "DN contains a null byte");
  1036. RETURN_FALSE;
  1037. }
  1038. if (ldap_bind_pw != NULL && memchr(ldap_bind_pw, '\0', ldap_bind_pwlen) != NULL) {
  1039. _set_lderrno(ld->link, LDAP_INVALID_CREDENTIALS);
  1040. php_error_docref(NULL, E_WARNING, "Password contains a null byte");
  1041. RETURN_FALSE;
  1042. }
  1043. {
  1044. #ifdef LDAP_API_FEATURE_X_OPENLDAP
  1045. /* ldap_simple_bind_s() is deprecated, use ldap_sasl_bind_s() instead.
  1046. */
  1047. struct berval cred;
  1048. cred.bv_val = ldap_bind_pw;
  1049. cred.bv_len = ldap_bind_pw ? ldap_bind_pwlen : 0;
  1050. rc = ldap_sasl_bind_s(ld->link, ldap_bind_dn, LDAP_SASL_SIMPLE, &cred,
  1051. NULL, NULL, /* no controls right now */
  1052. NULL); /* we don't care about the server's credentials */
  1053. #else /* ! LDAP_API_FEATURE_X_OPENLDAP */
  1054. rc = ldap_simple_bind_s(ld->link, ldap_bind_dn, ldap_bind_pw);
  1055. #endif /* ! LDAP_API_FEATURE_X_OPENLDAP */
  1056. }
  1057. if ( rc != LDAP_SUCCESS) {
  1058. php_error_docref(NULL, E_WARNING, "Unable to bind to server: %s", ldap_err2string(rc));
  1059. RETURN_FALSE;
  1060. } else {
  1061. RETURN_TRUE;
  1062. }
  1063. }
  1064. /* }}} */
  1065. /* {{{ proto resource ldap_bind_ext(resource link [, string dn [, string password [, serverctrls]]])
  1066. Bind to LDAP directory */
  1067. PHP_FUNCTION(ldap_bind_ext)
  1068. {
  1069. zval *serverctrls = NULL;
  1070. zval *link;
  1071. char *ldap_bind_dn = NULL, *ldap_bind_pw = NULL;
  1072. size_t ldap_bind_dnlen, ldap_bind_pwlen;
  1073. ldap_linkdata *ld;
  1074. LDAPControl **lserverctrls = NULL;
  1075. LDAPMessage *ldap_res;
  1076. int rc;
  1077. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r|ssa", &link, &ldap_bind_dn, &ldap_bind_dnlen, &ldap_bind_pw, &ldap_bind_pwlen, &serverctrls) != SUCCESS) {
  1078. RETURN_FALSE;
  1079. }
  1080. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1081. RETURN_FALSE;
  1082. }
  1083. if (ldap_bind_dn != NULL && memchr(ldap_bind_dn, '\0', ldap_bind_dnlen) != NULL) {
  1084. _set_lderrno(ld->link, LDAP_INVALID_CREDENTIALS);
  1085. php_error_docref(NULL, E_WARNING, "DN contains a null byte");
  1086. RETURN_FALSE;
  1087. }
  1088. if (ldap_bind_pw != NULL && memchr(ldap_bind_pw, '\0', ldap_bind_pwlen) != NULL) {
  1089. _set_lderrno(ld->link, LDAP_INVALID_CREDENTIALS);
  1090. php_error_docref(NULL, E_WARNING, "Password contains a null byte");
  1091. RETURN_FALSE;
  1092. }
  1093. if (serverctrls) {
  1094. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  1095. if (lserverctrls == NULL) {
  1096. RETVAL_FALSE;
  1097. goto cleanup;
  1098. }
  1099. }
  1100. {
  1101. /* ldap_simple_bind() is deprecated, use ldap_sasl_bind() instead */
  1102. struct berval cred;
  1103. int msgid;
  1104. cred.bv_val = ldap_bind_pw;
  1105. cred.bv_len = ldap_bind_pw ? ldap_bind_pwlen : 0;
  1106. /* asynchronous call */
  1107. rc = ldap_sasl_bind(ld->link, ldap_bind_dn, LDAP_SASL_SIMPLE, &cred,
  1108. lserverctrls, NULL, &msgid);
  1109. if (rc != LDAP_SUCCESS ) {
  1110. php_error_docref(NULL, E_WARNING, "Unable to bind to server: %s (%d)", ldap_err2string(rc), rc);
  1111. RETVAL_FALSE;
  1112. goto cleanup;
  1113. }
  1114. rc = ldap_result(ld->link, msgid, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  1115. if (rc == -1) {
  1116. php_error_docref(NULL, E_WARNING, "Bind operation failed");
  1117. RETVAL_FALSE;
  1118. goto cleanup;
  1119. }
  1120. /* return a PHP control object */
  1121. RETVAL_RES(zend_register_resource(ldap_res, le_result));
  1122. }
  1123. cleanup:
  1124. if (lserverctrls) {
  1125. _php_ldap_controls_free(&lserverctrls);
  1126. }
  1127. return;
  1128. }
  1129. /* }}} */
  1130. #ifdef HAVE_LDAP_SASL
  1131. typedef struct {
  1132. char *mech;
  1133. char *realm;
  1134. char *authcid;
  1135. char *passwd;
  1136. char *authzid;
  1137. } php_ldap_bictx;
  1138. /* {{{ _php_sasl_setdefs
  1139. */
  1140. static php_ldap_bictx *_php_sasl_setdefs(LDAP *ld, char *sasl_mech, char *sasl_realm, char *sasl_authc_id, char *passwd, char *sasl_authz_id)
  1141. {
  1142. php_ldap_bictx *ctx;
  1143. ctx = ber_memalloc(sizeof(php_ldap_bictx));
  1144. ctx->mech = (sasl_mech) ? ber_strdup(sasl_mech) : NULL;
  1145. ctx->realm = (sasl_realm) ? ber_strdup(sasl_realm) : NULL;
  1146. ctx->authcid = (sasl_authc_id) ? ber_strdup(sasl_authc_id) : NULL;
  1147. ctx->passwd = (passwd) ? ber_strdup(passwd) : NULL;
  1148. ctx->authzid = (sasl_authz_id) ? ber_strdup(sasl_authz_id) : NULL;
  1149. if (ctx->mech == NULL) {
  1150. ldap_get_option(ld, LDAP_OPT_X_SASL_MECH, &ctx->mech);
  1151. }
  1152. if (ctx->realm == NULL) {
  1153. ldap_get_option(ld, LDAP_OPT_X_SASL_REALM, &ctx->realm);
  1154. }
  1155. if (ctx->authcid == NULL) {
  1156. ldap_get_option(ld, LDAP_OPT_X_SASL_AUTHCID, &ctx->authcid);
  1157. }
  1158. if (ctx->authzid == NULL) {
  1159. ldap_get_option(ld, LDAP_OPT_X_SASL_AUTHZID, &ctx->authzid);
  1160. }
  1161. return ctx;
  1162. }
  1163. /* }}} */
  1164. /* {{{ _php_sasl_freedefs
  1165. */
  1166. static void _php_sasl_freedefs(php_ldap_bictx *ctx)
  1167. {
  1168. if (ctx->mech) ber_memfree(ctx->mech);
  1169. if (ctx->realm) ber_memfree(ctx->realm);
  1170. if (ctx->authcid) ber_memfree(ctx->authcid);
  1171. if (ctx->passwd) ber_memfree(ctx->passwd);
  1172. if (ctx->authzid) ber_memfree(ctx->authzid);
  1173. ber_memfree(ctx);
  1174. }
  1175. /* }}} */
  1176. /* {{{ _php_sasl_interact
  1177. Internal interact function for SASL */
  1178. static int _php_sasl_interact(LDAP *ld, unsigned flags, void *defaults, void *in)
  1179. {
  1180. sasl_interact_t *interact = in;
  1181. const char *p;
  1182. php_ldap_bictx *ctx = defaults;
  1183. for (;interact->id != SASL_CB_LIST_END;interact++) {
  1184. p = NULL;
  1185. switch(interact->id) {
  1186. case SASL_CB_GETREALM:
  1187. p = ctx->realm;
  1188. break;
  1189. case SASL_CB_AUTHNAME:
  1190. p = ctx->authcid;
  1191. break;
  1192. case SASL_CB_USER:
  1193. p = ctx->authzid;
  1194. break;
  1195. case SASL_CB_PASS:
  1196. p = ctx->passwd;
  1197. break;
  1198. }
  1199. if (p) {
  1200. interact->result = p;
  1201. interact->len = strlen(interact->result);
  1202. }
  1203. }
  1204. return LDAP_SUCCESS;
  1205. }
  1206. /* }}} */
  1207. /* {{{ proto bool ldap_sasl_bind(resource link [, string binddn [, string password [, string sasl_mech [, string sasl_realm [, string sasl_authc_id [, string sasl_authz_id [, string props]]]]]]])
  1208. Bind to LDAP directory using SASL */
  1209. PHP_FUNCTION(ldap_sasl_bind)
  1210. {
  1211. zval *link;
  1212. ldap_linkdata *ld;
  1213. char *binddn = NULL;
  1214. char *passwd = NULL;
  1215. char *sasl_mech = NULL;
  1216. char *sasl_realm = NULL;
  1217. char *sasl_authz_id = NULL;
  1218. char *sasl_authc_id = NULL;
  1219. char *props = NULL;
  1220. size_t rc, dn_len, passwd_len, mech_len, realm_len, authc_id_len, authz_id_len, props_len;
  1221. php_ldap_bictx *ctx;
  1222. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r|sssssss", &link, &binddn, &dn_len, &passwd, &passwd_len, &sasl_mech, &mech_len, &sasl_realm, &realm_len, &sasl_authc_id, &authc_id_len, &sasl_authz_id, &authz_id_len, &props, &props_len) != SUCCESS) {
  1223. RETURN_FALSE;
  1224. }
  1225. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1226. RETURN_FALSE;
  1227. }
  1228. ctx = _php_sasl_setdefs(ld->link, sasl_mech, sasl_realm, sasl_authc_id, passwd, sasl_authz_id);
  1229. if (props) {
  1230. ldap_set_option(ld->link, LDAP_OPT_X_SASL_SECPROPS, props);
  1231. }
  1232. rc = ldap_sasl_interactive_bind_s(ld->link, binddn, ctx->mech, NULL, NULL, LDAP_SASL_QUIET, _php_sasl_interact, ctx);
  1233. if (rc != LDAP_SUCCESS) {
  1234. php_error_docref(NULL, E_WARNING, "Unable to bind to server: %s", ldap_err2string(rc));
  1235. RETVAL_FALSE;
  1236. } else {
  1237. RETVAL_TRUE;
  1238. }
  1239. _php_sasl_freedefs(ctx);
  1240. }
  1241. /* }}} */
  1242. #endif /* HAVE_LDAP_SASL */
  1243. /* {{{ proto bool ldap_unbind(resource link)
  1244. Unbind from LDAP directory */
  1245. PHP_FUNCTION(ldap_unbind)
  1246. {
  1247. zval *link;
  1248. ldap_linkdata *ld;
  1249. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r", &link) != SUCCESS) {
  1250. RETURN_FALSE;
  1251. }
  1252. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1253. RETURN_FALSE;
  1254. }
  1255. zend_list_close(Z_RES_P(link));
  1256. RETURN_TRUE;
  1257. }
  1258. /* }}} */
  1259. /* {{{ php_set_opts
  1260. */
  1261. static void php_set_opts(LDAP *ldap, int sizelimit, int timelimit, int deref, int *old_sizelimit, int *old_timelimit, int *old_deref)
  1262. {
  1263. /* sizelimit */
  1264. if (sizelimit > -1) {
  1265. #if (LDAP_API_VERSION >= 2004) || HAVE_NSLDAP || HAVE_ORALDAP
  1266. ldap_get_option(ldap, LDAP_OPT_SIZELIMIT, old_sizelimit);
  1267. ldap_set_option(ldap, LDAP_OPT_SIZELIMIT, &sizelimit);
  1268. #else
  1269. *old_sizelimit = ldap->ld_sizelimit;
  1270. ldap->ld_sizelimit = sizelimit;
  1271. #endif
  1272. }
  1273. /* timelimit */
  1274. if (timelimit > -1) {
  1275. #if (LDAP_API_VERSION >= 2004) || HAVE_NSLDAP || HAVE_ORALDAP
  1276. ldap_get_option(ldap, LDAP_OPT_TIMELIMIT, old_timelimit);
  1277. ldap_set_option(ldap, LDAP_OPT_TIMELIMIT, &timelimit);
  1278. #else
  1279. *old_timelimit = ldap->ld_timelimit;
  1280. ldap->ld_timelimit = timelimit;
  1281. #endif
  1282. }
  1283. /* deref */
  1284. if (deref > -1) {
  1285. #if (LDAP_API_VERSION >= 2004) || HAVE_NSLDAP || HAVE_ORALDAP
  1286. ldap_get_option(ldap, LDAP_OPT_DEREF, old_deref);
  1287. ldap_set_option(ldap, LDAP_OPT_DEREF, &deref);
  1288. #else
  1289. *old_deref = ldap->ld_deref;
  1290. ldap->ld_deref = deref;
  1291. #endif
  1292. }
  1293. }
  1294. /* }}} */
  1295. /* {{{ php_ldap_do_search
  1296. */
  1297. static void php_ldap_do_search(INTERNAL_FUNCTION_PARAMETERS, int scope)
  1298. {
  1299. zval *link, *base_dn, *filter, *attrs = NULL, *attr, *serverctrls = NULL;
  1300. zend_long attrsonly, sizelimit, timelimit, deref;
  1301. zend_string *ldap_filter = NULL, *ldap_base_dn = NULL;
  1302. char **ldap_attrs = NULL;
  1303. ldap_linkdata *ld = NULL;
  1304. LDAPMessage *ldap_res = NULL;
  1305. LDAPControl **lserverctrls = NULL;
  1306. int ldap_attrsonly = 0, ldap_sizelimit = -1, ldap_timelimit = -1, ldap_deref = -1;
  1307. int old_ldap_sizelimit = -1, old_ldap_timelimit = -1, old_ldap_deref = -1;
  1308. int num_attribs = 0, ret = 1, i, errno, argcount = ZEND_NUM_ARGS();
  1309. if (zend_parse_parameters(argcount, "zzz|alllla/", &link, &base_dn, &filter, &attrs, &attrsonly,
  1310. &sizelimit, &timelimit, &deref, &serverctrls) == FAILURE) {
  1311. return;
  1312. }
  1313. /* Reverse -> fall through */
  1314. switch (argcount) {
  1315. case 9:
  1316. case 8:
  1317. ldap_deref = deref;
  1318. case 7:
  1319. ldap_timelimit = timelimit;
  1320. case 6:
  1321. ldap_sizelimit = sizelimit;
  1322. case 5:
  1323. ldap_attrsonly = attrsonly;
  1324. case 4:
  1325. num_attribs = zend_hash_num_elements(Z_ARRVAL_P(attrs));
  1326. ldap_attrs = safe_emalloc((num_attribs+1), sizeof(char *), 0);
  1327. for (i = 0; i<num_attribs; i++) {
  1328. if ((attr = zend_hash_index_find(Z_ARRVAL_P(attrs), i)) == NULL) {
  1329. php_error_docref(NULL, E_WARNING, "Array initialization wrong");
  1330. ret = 0;
  1331. goto cleanup;
  1332. }
  1333. convert_to_string(attr);
  1334. if (EG(exception)) {
  1335. ret = 0;
  1336. goto cleanup;
  1337. }
  1338. ldap_attrs[i] = Z_STRVAL_P(attr);
  1339. }
  1340. ldap_attrs[num_attribs] = NULL;
  1341. default:
  1342. break;
  1343. }
  1344. /* parallel search? */
  1345. if (Z_TYPE_P(link) == IS_ARRAY) {
  1346. int i, nlinks, nbases, nfilters, *rcs;
  1347. ldap_linkdata **lds;
  1348. zval *entry, resource;
  1349. nlinks = zend_hash_num_elements(Z_ARRVAL_P(link));
  1350. if (nlinks == 0) {
  1351. php_error_docref(NULL, E_WARNING, "No links in link array");
  1352. ret = 0;
  1353. goto cleanup;
  1354. }
  1355. if (Z_TYPE_P(base_dn) == IS_ARRAY) {
  1356. nbases = zend_hash_num_elements(Z_ARRVAL_P(base_dn));
  1357. if (nbases != nlinks) {
  1358. php_error_docref(NULL, E_WARNING, "Base must either be a string, or an array with the same number of elements as the links array");
  1359. ret = 0;
  1360. goto cleanup;
  1361. }
  1362. zend_hash_internal_pointer_reset(Z_ARRVAL_P(base_dn));
  1363. } else {
  1364. nbases = 0; /* this means string, not array */
  1365. ldap_base_dn = zval_get_string(base_dn);
  1366. if (EG(exception)) {
  1367. ret = 0;
  1368. goto cleanup;
  1369. }
  1370. }
  1371. if (Z_TYPE_P(filter) == IS_ARRAY) {
  1372. nfilters = zend_hash_num_elements(Z_ARRVAL_P(filter));
  1373. if (nfilters != nlinks) {
  1374. php_error_docref(NULL, E_WARNING, "Filter must either be a string, or an array with the same number of elements as the links array");
  1375. ret = 0;
  1376. goto cleanup;
  1377. }
  1378. zend_hash_internal_pointer_reset(Z_ARRVAL_P(filter));
  1379. } else {
  1380. nfilters = 0; /* this means string, not array */
  1381. ldap_filter = zval_get_string(filter);
  1382. if (EG(exception)) {
  1383. ret = 0;
  1384. goto cleanup;
  1385. }
  1386. }
  1387. lds = safe_emalloc(nlinks, sizeof(ldap_linkdata), 0);
  1388. rcs = safe_emalloc(nlinks, sizeof(*rcs), 0);
  1389. zend_hash_internal_pointer_reset(Z_ARRVAL_P(link));
  1390. for (i=0; i<nlinks; i++) {
  1391. entry = zend_hash_get_current_data(Z_ARRVAL_P(link));
  1392. ld = (ldap_linkdata *) zend_fetch_resource_ex(entry, "ldap link", le_link);
  1393. if (ld == NULL) {
  1394. ret = 0;
  1395. goto cleanup_parallel;
  1396. }
  1397. if (nbases != 0) { /* base_dn an array? */
  1398. entry = zend_hash_get_current_data(Z_ARRVAL_P(base_dn));
  1399. zend_hash_move_forward(Z_ARRVAL_P(base_dn));
  1400. ldap_base_dn = zval_get_string(entry);
  1401. if (EG(exception)) {
  1402. ret = 0;
  1403. goto cleanup_parallel;
  1404. }
  1405. }
  1406. if (nfilters != 0) { /* filter an array? */
  1407. entry = zend_hash_get_current_data(Z_ARRVAL_P(filter));
  1408. zend_hash_move_forward(Z_ARRVAL_P(filter));
  1409. ldap_filter = zval_get_string(entry);
  1410. if (EG(exception)) {
  1411. ret = 0;
  1412. goto cleanup_parallel;
  1413. }
  1414. }
  1415. if (argcount > 8) {
  1416. /* We have to parse controls again for each link as they use it */
  1417. _php_ldap_controls_free(&lserverctrls);
  1418. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  1419. if (lserverctrls == NULL) {
  1420. rcs[i] = -1;
  1421. continue;
  1422. }
  1423. }
  1424. php_set_opts(ld->link, ldap_sizelimit, ldap_timelimit, ldap_deref, &old_ldap_sizelimit, &old_ldap_timelimit, &old_ldap_deref);
  1425. /* Run the actual search */
  1426. ldap_search_ext(ld->link, ZSTR_VAL(ldap_base_dn), scope, ZSTR_VAL(ldap_filter), ldap_attrs, ldap_attrsonly, lserverctrls, NULL, NULL, ldap_sizelimit, &rcs[i]);
  1427. lds[i] = ld;
  1428. zend_hash_move_forward(Z_ARRVAL_P(link));
  1429. }
  1430. array_init(return_value);
  1431. /* Collect results from the searches */
  1432. for (i=0; i<nlinks; i++) {
  1433. if (rcs[i] != -1) {
  1434. rcs[i] = ldap_result(lds[i]->link, LDAP_RES_ANY, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  1435. }
  1436. if (rcs[i] != -1) {
  1437. ZVAL_RES(&resource, zend_register_resource(ldap_res, le_result));
  1438. add_next_index_zval(return_value, &resource);
  1439. } else {
  1440. add_next_index_bool(return_value, 0);
  1441. }
  1442. }
  1443. cleanup_parallel:
  1444. efree(lds);
  1445. efree(rcs);
  1446. } else {
  1447. ldap_filter = zval_get_string(filter);
  1448. if (EG(exception)) {
  1449. ret = 0;
  1450. goto cleanup;
  1451. }
  1452. ldap_base_dn = zval_get_string(base_dn);
  1453. if (EG(exception)) {
  1454. ret = 0;
  1455. goto cleanup;
  1456. }
  1457. ld = (ldap_linkdata *) zend_fetch_resource_ex(link, "ldap link", le_link);
  1458. if (ld == NULL) {
  1459. ret = 0;
  1460. goto cleanup;
  1461. }
  1462. if (argcount > 8) {
  1463. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  1464. if (lserverctrls == NULL) {
  1465. ret = 0;
  1466. goto cleanup;
  1467. }
  1468. }
  1469. php_set_opts(ld->link, ldap_sizelimit, ldap_timelimit, ldap_deref, &old_ldap_sizelimit, &old_ldap_timelimit, &old_ldap_deref);
  1470. /* Run the actual search */
  1471. errno = ldap_search_ext_s(ld->link, ZSTR_VAL(ldap_base_dn), scope, ZSTR_VAL(ldap_filter), ldap_attrs, ldap_attrsonly, lserverctrls, NULL, NULL, ldap_sizelimit, &ldap_res);
  1472. if (errno != LDAP_SUCCESS
  1473. && errno != LDAP_SIZELIMIT_EXCEEDED
  1474. #ifdef LDAP_ADMINLIMIT_EXCEEDED
  1475. && errno != LDAP_ADMINLIMIT_EXCEEDED
  1476. #endif
  1477. #ifdef LDAP_REFERRAL
  1478. && errno != LDAP_REFERRAL
  1479. #endif
  1480. ) {
  1481. /* ldap_res should be freed regardless of return value of ldap_search_ext_s()
  1482. * see: https://linux.die.net/man/3/ldap_search_ext_s */
  1483. if (ldap_res != NULL) {
  1484. ldap_msgfree(ldap_res);
  1485. }
  1486. php_error_docref(NULL, E_WARNING, "Search: %s", ldap_err2string(errno));
  1487. ret = 0;
  1488. } else {
  1489. if (errno == LDAP_SIZELIMIT_EXCEEDED) {
  1490. php_error_docref(NULL, E_WARNING, "Partial search results returned: Sizelimit exceeded");
  1491. }
  1492. #ifdef LDAP_ADMINLIMIT_EXCEEDED
  1493. else if (errno == LDAP_ADMINLIMIT_EXCEEDED) {
  1494. php_error_docref(NULL, E_WARNING, "Partial search results returned: Adminlimit exceeded");
  1495. }
  1496. #endif
  1497. RETVAL_RES(zend_register_resource(ldap_res, le_result));
  1498. }
  1499. }
  1500. cleanup:
  1501. if (ld) {
  1502. /* Restoring previous options */
  1503. php_set_opts(ld->link, old_ldap_sizelimit, old_ldap_timelimit, old_ldap_deref, &ldap_sizelimit, &ldap_timelimit, &ldap_deref);
  1504. }
  1505. if (ldap_filter) {
  1506. zend_string_release(ldap_filter);
  1507. }
  1508. if (ldap_base_dn) {
  1509. zend_string_release(ldap_base_dn);
  1510. }
  1511. if (ldap_attrs != NULL) {
  1512. efree(ldap_attrs);
  1513. }
  1514. if (!ret) {
  1515. RETVAL_BOOL(ret);
  1516. }
  1517. if (lserverctrls) {
  1518. _php_ldap_controls_free(&lserverctrls);
  1519. }
  1520. }
  1521. /* }}} */
  1522. /* {{{ proto resource ldap_read(resource|array link, string base_dn, string filter [, array attrs [, int attrsonly [, int sizelimit [, int timelimit [, int deref [, array servercontrols]]]]]])
  1523. Read an entry */
  1524. PHP_FUNCTION(ldap_read)
  1525. {
  1526. php_ldap_do_search(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_SCOPE_BASE);
  1527. }
  1528. /* }}} */
  1529. /* {{{ proto resource ldap_list(resource|array link, string base_dn, string filter [, array attrs [, int attrsonly [, int sizelimit [, int timelimit [, int deref [, array servercontrols]]]]]])
  1530. Single-level search */
  1531. PHP_FUNCTION(ldap_list)
  1532. {
  1533. php_ldap_do_search(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_SCOPE_ONELEVEL);
  1534. }
  1535. /* }}} */
  1536. /* {{{ proto resource ldap_search(resource|array link, string base_dn, string filter [, array attrs [, int attrsonly [, int sizelimit [, int timelimit [, int deref [, array servercontrols]]]]]])
  1537. Search LDAP tree under base_dn */
  1538. PHP_FUNCTION(ldap_search)
  1539. {
  1540. php_ldap_do_search(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_SCOPE_SUBTREE);
  1541. }
  1542. /* }}} */
  1543. /* {{{ proto bool ldap_free_result(resource result)
  1544. Free result memory */
  1545. PHP_FUNCTION(ldap_free_result)
  1546. {
  1547. zval *result;
  1548. LDAPMessage *ldap_result;
  1549. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r", &result) != SUCCESS) {
  1550. return;
  1551. }
  1552. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  1553. RETURN_FALSE;
  1554. }
  1555. zend_list_close(Z_RES_P(result)); /* Delete list entry */
  1556. RETVAL_TRUE;
  1557. }
  1558. /* }}} */
  1559. /* {{{ proto int ldap_count_entries(resource link, resource result)
  1560. Count the number of entries in a search result */
  1561. PHP_FUNCTION(ldap_count_entries)
  1562. {
  1563. zval *link, *result;
  1564. ldap_linkdata *ld;
  1565. LDAPMessage *ldap_result;
  1566. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result) != SUCCESS) {
  1567. return;
  1568. }
  1569. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1570. RETURN_FALSE;
  1571. }
  1572. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  1573. RETURN_FALSE;
  1574. }
  1575. RETURN_LONG(ldap_count_entries(ld->link, ldap_result));
  1576. }
  1577. /* }}} */
  1578. /* {{{ proto resource ldap_first_entry(resource link, resource result)
  1579. Return first result id */
  1580. PHP_FUNCTION(ldap_first_entry)
  1581. {
  1582. zval *link, *result;
  1583. ldap_linkdata *ld;
  1584. ldap_resultentry *resultentry;
  1585. LDAPMessage *ldap_result, *entry;
  1586. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result) != SUCCESS) {
  1587. return;
  1588. }
  1589. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1590. RETURN_FALSE;
  1591. }
  1592. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  1593. RETURN_FALSE;
  1594. }
  1595. if ((entry = ldap_first_entry(ld->link, ldap_result)) == NULL) {
  1596. RETVAL_FALSE;
  1597. } else {
  1598. resultentry = emalloc(sizeof(ldap_resultentry));
  1599. RETVAL_RES(zend_register_resource(resultentry, le_result_entry));
  1600. ZVAL_COPY(&resultentry->res, result);
  1601. resultentry->data = entry;
  1602. resultentry->ber = NULL;
  1603. }
  1604. }
  1605. /* }}} */
  1606. /* {{{ proto resource ldap_next_entry(resource link, resource result_entry)
  1607. Get next result entry */
  1608. PHP_FUNCTION(ldap_next_entry)
  1609. {
  1610. zval *link, *result_entry;
  1611. ldap_linkdata *ld;
  1612. ldap_resultentry *resultentry, *resultentry_next;
  1613. LDAPMessage *entry_next;
  1614. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result_entry) != SUCCESS) {
  1615. return;
  1616. }
  1617. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1618. RETURN_FALSE;
  1619. }
  1620. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  1621. RETURN_FALSE;
  1622. }
  1623. if ((entry_next = ldap_next_entry(ld->link, resultentry->data)) == NULL) {
  1624. RETVAL_FALSE;
  1625. } else {
  1626. resultentry_next = emalloc(sizeof(ldap_resultentry));
  1627. RETVAL_RES(zend_register_resource(resultentry_next, le_result_entry));
  1628. ZVAL_COPY(&resultentry_next->res, &resultentry->res);
  1629. resultentry_next->data = entry_next;
  1630. resultentry_next->ber = NULL;
  1631. }
  1632. }
  1633. /* }}} */
  1634. /* {{{ proto array ldap_get_entries(resource link, resource result)
  1635. Get all result entries */
  1636. PHP_FUNCTION(ldap_get_entries)
  1637. {
  1638. zval *link, *result;
  1639. LDAPMessage *ldap_result, *ldap_result_entry;
  1640. zval tmp1, tmp2;
  1641. ldap_linkdata *ld;
  1642. LDAP *ldap;
  1643. int num_entries, num_attrib, num_values, i;
  1644. BerElement *ber;
  1645. char *attribute;
  1646. size_t attr_len;
  1647. struct berval **ldap_value;
  1648. char *dn;
  1649. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result) != SUCCESS) {
  1650. return;
  1651. }
  1652. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1653. RETURN_FALSE;
  1654. }
  1655. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  1656. RETURN_FALSE;
  1657. }
  1658. ldap = ld->link;
  1659. num_entries = ldap_count_entries(ldap, ldap_result);
  1660. array_init(return_value);
  1661. add_assoc_long(return_value, "count", num_entries);
  1662. if (num_entries == 0) {
  1663. return;
  1664. }
  1665. ldap_result_entry = ldap_first_entry(ldap, ldap_result);
  1666. if (ldap_result_entry == NULL) {
  1667. zend_array_destroy(Z_ARR_P(return_value));
  1668. RETURN_FALSE;
  1669. }
  1670. num_entries = 0;
  1671. while (ldap_result_entry != NULL) {
  1672. array_init(&tmp1);
  1673. num_attrib = 0;
  1674. attribute = ldap_first_attribute(ldap, ldap_result_entry, &ber);
  1675. while (attribute != NULL) {
  1676. ldap_value = ldap_get_values_len(ldap, ldap_result_entry, attribute);
  1677. num_values = ldap_count_values_len(ldap_value);
  1678. array_init(&tmp2);
  1679. add_assoc_long(&tmp2, "count", num_values);
  1680. for (i = 0; i < num_values; i++) {
  1681. add_index_stringl(&tmp2, i, ldap_value[i]->bv_val, ldap_value[i]->bv_len);
  1682. }
  1683. ldap_value_free_len(ldap_value);
  1684. attr_len = strlen(attribute);
  1685. zend_hash_str_update(Z_ARRVAL(tmp1), php_strtolower(attribute, attr_len), attr_len, &tmp2);
  1686. add_index_string(&tmp1, num_attrib, attribute);
  1687. num_attrib++;
  1688. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1689. ldap_memfree(attribute);
  1690. #endif
  1691. attribute = ldap_next_attribute(ldap, ldap_result_entry, ber);
  1692. }
  1693. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1694. if (ber != NULL) {
  1695. ber_free(ber, 0);
  1696. }
  1697. #endif
  1698. add_assoc_long(&tmp1, "count", num_attrib);
  1699. dn = ldap_get_dn(ldap, ldap_result_entry);
  1700. if (dn) {
  1701. add_assoc_string(&tmp1, "dn", dn);
  1702. } else {
  1703. add_assoc_null(&tmp1, "dn");
  1704. }
  1705. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1706. ldap_memfree(dn);
  1707. #else
  1708. free(dn);
  1709. #endif
  1710. zend_hash_index_update(Z_ARRVAL_P(return_value), num_entries, &tmp1);
  1711. num_entries++;
  1712. ldap_result_entry = ldap_next_entry(ldap, ldap_result_entry);
  1713. }
  1714. add_assoc_long(return_value, "count", num_entries);
  1715. }
  1716. /* }}} */
  1717. /* {{{ proto string ldap_first_attribute(resource link, resource result_entry)
  1718. Return first attribute */
  1719. PHP_FUNCTION(ldap_first_attribute)
  1720. {
  1721. zval *link, *result_entry;
  1722. ldap_linkdata *ld;
  1723. ldap_resultentry *resultentry;
  1724. char *attribute;
  1725. zend_long dummy_ber;
  1726. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr|l", &link, &result_entry, &dummy_ber) != SUCCESS) {
  1727. return;
  1728. }
  1729. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1730. RETURN_FALSE;
  1731. }
  1732. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  1733. RETURN_FALSE;
  1734. }
  1735. if ((attribute = ldap_first_attribute(ld->link, resultentry->data, &resultentry->ber)) == NULL) {
  1736. RETURN_FALSE;
  1737. } else {
  1738. RETVAL_STRING(attribute);
  1739. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1740. ldap_memfree(attribute);
  1741. #endif
  1742. }
  1743. }
  1744. /* }}} */
  1745. /* {{{ proto string ldap_next_attribute(resource link, resource result_entry)
  1746. Get the next attribute in result */
  1747. PHP_FUNCTION(ldap_next_attribute)
  1748. {
  1749. zval *link, *result_entry;
  1750. ldap_linkdata *ld;
  1751. ldap_resultentry *resultentry;
  1752. char *attribute;
  1753. zend_long dummy_ber;
  1754. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr|l", &link, &result_entry, &dummy_ber) != SUCCESS) {
  1755. return;
  1756. }
  1757. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1758. RETURN_FALSE;
  1759. }
  1760. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  1761. RETURN_FALSE;
  1762. }
  1763. if (resultentry->ber == NULL) {
  1764. php_error_docref(NULL, E_WARNING, "called before calling ldap_first_attribute() or no attributes found in result entry");
  1765. RETURN_FALSE;
  1766. }
  1767. if ((attribute = ldap_next_attribute(ld->link, resultentry->data, resultentry->ber)) == NULL) {
  1768. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1769. if (resultentry->ber != NULL) {
  1770. ber_free(resultentry->ber, 0);
  1771. resultentry->ber = NULL;
  1772. }
  1773. #endif
  1774. RETURN_FALSE;
  1775. } else {
  1776. RETVAL_STRING(attribute);
  1777. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1778. ldap_memfree(attribute);
  1779. #endif
  1780. }
  1781. }
  1782. /* }}} */
  1783. /* {{{ proto array ldap_get_attributes(resource link, resource result_entry)
  1784. Get attributes from a search result entry */
  1785. PHP_FUNCTION(ldap_get_attributes)
  1786. {
  1787. zval *link, *result_entry;
  1788. zval tmp;
  1789. ldap_linkdata *ld;
  1790. ldap_resultentry *resultentry;
  1791. char *attribute;
  1792. struct berval **ldap_value;
  1793. int i, num_values, num_attrib;
  1794. BerElement *ber;
  1795. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result_entry) != SUCCESS) {
  1796. return;
  1797. }
  1798. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1799. RETURN_FALSE;
  1800. }
  1801. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  1802. RETURN_FALSE;
  1803. }
  1804. array_init(return_value);
  1805. num_attrib = 0;
  1806. attribute = ldap_first_attribute(ld->link, resultentry->data, &ber);
  1807. while (attribute != NULL) {
  1808. ldap_value = ldap_get_values_len(ld->link, resultentry->data, attribute);
  1809. num_values = ldap_count_values_len(ldap_value);
  1810. array_init(&tmp);
  1811. add_assoc_long(&tmp, "count", num_values);
  1812. for (i = 0; i < num_values; i++) {
  1813. add_index_stringl(&tmp, i, ldap_value[i]->bv_val, ldap_value[i]->bv_len);
  1814. }
  1815. ldap_value_free_len(ldap_value);
  1816. zend_hash_str_update(Z_ARRVAL_P(return_value), attribute, strlen(attribute), &tmp);
  1817. add_index_string(return_value, num_attrib, attribute);
  1818. num_attrib++;
  1819. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1820. ldap_memfree(attribute);
  1821. #endif
  1822. attribute = ldap_next_attribute(ld->link, resultentry->data, ber);
  1823. }
  1824. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1825. if (ber != NULL) {
  1826. ber_free(ber, 0);
  1827. }
  1828. #endif
  1829. add_assoc_long(return_value, "count", num_attrib);
  1830. }
  1831. /* }}} */
  1832. /* {{{ proto array ldap_get_values_len(resource link, resource result_entry, string attribute)
  1833. Get all values with lengths from a result entry */
  1834. PHP_FUNCTION(ldap_get_values_len)
  1835. {
  1836. zval *link, *result_entry;
  1837. ldap_linkdata *ld;
  1838. ldap_resultentry *resultentry;
  1839. char *attr;
  1840. struct berval **ldap_value_len;
  1841. int i, num_values;
  1842. size_t attr_len;
  1843. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rrs", &link, &result_entry, &attr, &attr_len) != SUCCESS) {
  1844. return;
  1845. }
  1846. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1847. RETURN_FALSE;
  1848. }
  1849. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  1850. RETURN_FALSE;
  1851. }
  1852. if ((ldap_value_len = ldap_get_values_len(ld->link, resultentry->data, attr)) == NULL) {
  1853. php_error_docref(NULL, E_WARNING, "Cannot get the value(s) of attribute %s", ldap_err2string(_get_lderrno(ld->link)));
  1854. RETURN_FALSE;
  1855. }
  1856. num_values = ldap_count_values_len(ldap_value_len);
  1857. array_init(return_value);
  1858. for (i=0; i<num_values; i++) {
  1859. add_next_index_stringl(return_value, ldap_value_len[i]->bv_val, ldap_value_len[i]->bv_len);
  1860. }
  1861. add_assoc_long(return_value, "count", num_values);
  1862. ldap_value_free_len(ldap_value_len);
  1863. }
  1864. /* }}} */
  1865. /* {{{ proto string ldap_get_dn(resource link, resource result_entry)
  1866. Get the DN of a result entry */
  1867. PHP_FUNCTION(ldap_get_dn)
  1868. {
  1869. zval *link, *result_entry;
  1870. ldap_linkdata *ld;
  1871. ldap_resultentry *resultentry;
  1872. char *text;
  1873. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result_entry) != SUCCESS) {
  1874. return;
  1875. }
  1876. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1877. RETURN_FALSE;
  1878. }
  1879. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  1880. RETURN_FALSE;
  1881. }
  1882. text = ldap_get_dn(ld->link, resultentry->data);
  1883. if (text != NULL) {
  1884. RETVAL_STRING(text);
  1885. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1886. ldap_memfree(text);
  1887. #else
  1888. free(text);
  1889. #endif
  1890. } else {
  1891. RETURN_FALSE;
  1892. }
  1893. }
  1894. /* }}} */
  1895. /* {{{ proto array ldap_explode_dn(string dn, int with_attrib)
  1896. Splits DN into its component parts */
  1897. PHP_FUNCTION(ldap_explode_dn)
  1898. {
  1899. zend_long with_attrib;
  1900. char *dn, **ldap_value;
  1901. int i, count;
  1902. size_t dn_len;
  1903. if (zend_parse_parameters(ZEND_NUM_ARGS(), "sl", &dn, &dn_len, &with_attrib) != SUCCESS) {
  1904. return;
  1905. }
  1906. if (!(ldap_value = ldap_explode_dn(dn, with_attrib))) {
  1907. /* Invalid parameters were passed to ldap_explode_dn */
  1908. RETURN_FALSE;
  1909. }
  1910. i=0;
  1911. while (ldap_value[i] != NULL) i++;
  1912. count = i;
  1913. array_init(return_value);
  1914. add_assoc_long(return_value, "count", count);
  1915. for (i = 0; i<count; i++) {
  1916. add_index_string(return_value, i, ldap_value[i]);
  1917. }
  1918. ldap_memvfree((void **)ldap_value);
  1919. }
  1920. /* }}} */
  1921. /* {{{ proto string ldap_dn2ufn(string dn)
  1922. Convert DN to User Friendly Naming format */
  1923. PHP_FUNCTION(ldap_dn2ufn)
  1924. {
  1925. char *dn, *ufn;
  1926. size_t dn_len;
  1927. if (zend_parse_parameters(ZEND_NUM_ARGS(), "s", &dn, &dn_len) != SUCCESS) {
  1928. return;
  1929. }
  1930. ufn = ldap_dn2ufn(dn);
  1931. if (ufn != NULL) {
  1932. RETVAL_STRING(ufn);
  1933. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP || WINDOWS
  1934. ldap_memfree(ufn);
  1935. #endif
  1936. } else {
  1937. RETURN_FALSE;
  1938. }
  1939. }
  1940. /* }}} */
  1941. /* added to fix use of ldap_modify_add for doing an ldap_add, gerrit thomson. */
  1942. #define PHP_LD_FULL_ADD 0xff
  1943. /* {{{ php_ldap_do_modify
  1944. */
  1945. static void php_ldap_do_modify(INTERNAL_FUNCTION_PARAMETERS, int oper, int ext)
  1946. {
  1947. zval *serverctrls = NULL;
  1948. zval *link, *entry, *value, *ivalue;
  1949. ldap_linkdata *ld;
  1950. char *dn;
  1951. LDAPMod **ldap_mods;
  1952. LDAPControl **lserverctrls = NULL;
  1953. LDAPMessage *ldap_res;
  1954. int i, j, num_attribs, num_values, msgid;
  1955. size_t dn_len;
  1956. int *num_berval;
  1957. zend_string *attribute;
  1958. zend_ulong index;
  1959. int is_full_add=0; /* flag for full add operation so ldap_mod_add can be put back into oper, gerrit THomson */
  1960. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rsa/|a", &link, &dn, &dn_len, &entry, &serverctrls) != SUCCESS) {
  1961. return;
  1962. }
  1963. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  1964. RETURN_FALSE;
  1965. }
  1966. num_attribs = zend_hash_num_elements(Z_ARRVAL_P(entry));
  1967. ldap_mods = safe_emalloc((num_attribs+1), sizeof(LDAPMod *), 0);
  1968. num_berval = safe_emalloc(num_attribs, sizeof(int), 0);
  1969. zend_hash_internal_pointer_reset(Z_ARRVAL_P(entry));
  1970. /* added by gerrit thomson to fix ldap_add using ldap_mod_add */
  1971. if (oper == PHP_LD_FULL_ADD) {
  1972. oper = LDAP_MOD_ADD;
  1973. is_full_add = 1;
  1974. }
  1975. /* end additional , gerrit thomson */
  1976. for (i = 0; i < num_attribs; i++) {
  1977. ldap_mods[i] = emalloc(sizeof(LDAPMod));
  1978. ldap_mods[i]->mod_op = oper | LDAP_MOD_BVALUES;
  1979. ldap_mods[i]->mod_type = NULL;
  1980. if (zend_hash_get_current_key(Z_ARRVAL_P(entry), &attribute, &index) == HASH_KEY_IS_STRING) {
  1981. ldap_mods[i]->mod_type = estrndup(ZSTR_VAL(attribute), ZSTR_LEN(attribute));
  1982. } else {
  1983. php_error_docref(NULL, E_WARNING, "Unknown attribute in the data");
  1984. /* Free allocated memory */
  1985. while (i >= 0) {
  1986. if (ldap_mods[i]->mod_type) {
  1987. efree(ldap_mods[i]->mod_type);
  1988. }
  1989. efree(ldap_mods[i]);
  1990. i--;
  1991. }
  1992. efree(num_berval);
  1993. efree(ldap_mods);
  1994. RETURN_FALSE;
  1995. }
  1996. value = zend_hash_get_current_data(Z_ARRVAL_P(entry));
  1997. ZVAL_DEREF(value);
  1998. if (Z_TYPE_P(value) != IS_ARRAY) {
  1999. num_values = 1;
  2000. } else {
  2001. SEPARATE_ARRAY(value);
  2002. num_values = zend_hash_num_elements(Z_ARRVAL_P(value));
  2003. }
  2004. num_berval[i] = num_values;
  2005. ldap_mods[i]->mod_bvalues = safe_emalloc((num_values + 1), sizeof(struct berval *), 0);
  2006. /* allow for arrays with one element, no allowance for arrays with none but probably not required, gerrit thomson. */
  2007. if ((num_values == 1) && (Z_TYPE_P(value) != IS_ARRAY)) {
  2008. convert_to_string(value);
  2009. if (EG(exception)) {
  2010. RETVAL_FALSE;
  2011. goto cleanup;
  2012. }
  2013. ldap_mods[i]->mod_bvalues[0] = (struct berval *) emalloc (sizeof(struct berval));
  2014. ldap_mods[i]->mod_bvalues[0]->bv_val = Z_STRVAL_P(value);
  2015. ldap_mods[i]->mod_bvalues[0]->bv_len = Z_STRLEN_P(value);
  2016. } else {
  2017. for (j = 0; j < num_values; j++) {
  2018. if ((ivalue = zend_hash_index_find(Z_ARRVAL_P(value), j)) == NULL) {
  2019. php_error_docref(NULL, E_WARNING, "Value array must have consecutive indices 0, 1, ...");
  2020. num_berval[i] = j;
  2021. num_attribs = i + 1;
  2022. RETVAL_FALSE;
  2023. goto cleanup;
  2024. }
  2025. convert_to_string(ivalue);
  2026. if (EG(exception)) {
  2027. RETVAL_FALSE;
  2028. goto cleanup;
  2029. }
  2030. ldap_mods[i]->mod_bvalues[j] = (struct berval *) emalloc (sizeof(struct berval));
  2031. ldap_mods[i]->mod_bvalues[j]->bv_val = Z_STRVAL_P(ivalue);
  2032. ldap_mods[i]->mod_bvalues[j]->bv_len = Z_STRLEN_P(ivalue);
  2033. }
  2034. }
  2035. ldap_mods[i]->mod_bvalues[num_values] = NULL;
  2036. zend_hash_move_forward(Z_ARRVAL_P(entry));
  2037. }
  2038. ldap_mods[num_attribs] = NULL;
  2039. if (serverctrls) {
  2040. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  2041. if (lserverctrls == NULL) {
  2042. RETVAL_FALSE;
  2043. goto cleanup;
  2044. }
  2045. }
  2046. /* check flag to see if do_mod was called to perform full add , gerrit thomson */
  2047. if (is_full_add == 1) {
  2048. if (ext) {
  2049. i = ldap_add_ext(ld->link, dn, ldap_mods, lserverctrls, NULL, &msgid);
  2050. } else {
  2051. i = ldap_add_ext_s(ld->link, dn, ldap_mods, lserverctrls, NULL);
  2052. }
  2053. if (i != LDAP_SUCCESS) {
  2054. php_error_docref(NULL, E_WARNING, "Add: %s", ldap_err2string(i));
  2055. RETVAL_FALSE;
  2056. } else if (ext) {
  2057. i = ldap_result(ld->link, msgid, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  2058. if (i == -1) {
  2059. php_error_docref(NULL, E_WARNING, "Add operation failed");
  2060. RETVAL_FALSE;
  2061. goto cleanup;
  2062. }
  2063. /* return a PHP control object */
  2064. RETVAL_RES(zend_register_resource(ldap_res, le_result));
  2065. } else RETVAL_TRUE;
  2066. } else {
  2067. if (ext) {
  2068. i = ldap_modify_ext(ld->link, dn, ldap_mods, lserverctrls, NULL, &msgid);
  2069. } else {
  2070. i = ldap_modify_ext_s(ld->link, dn, ldap_mods, lserverctrls, NULL);
  2071. }
  2072. if (i != LDAP_SUCCESS) {
  2073. php_error_docref(NULL, E_WARNING, "Modify: %s", ldap_err2string(i));
  2074. RETVAL_FALSE;
  2075. } else if (ext) {
  2076. i = ldap_result(ld->link, msgid, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  2077. if (i == -1) {
  2078. php_error_docref(NULL, E_WARNING, "Modify operation failed");
  2079. RETVAL_FALSE;
  2080. goto cleanup;
  2081. }
  2082. /* return a PHP control object */
  2083. RETVAL_RES(zend_register_resource(ldap_res, le_result));
  2084. } else RETVAL_TRUE;
  2085. }
  2086. cleanup:
  2087. for (i = 0; i < num_attribs; i++) {
  2088. efree(ldap_mods[i]->mod_type);
  2089. for (j = 0; j < num_berval[i]; j++) {
  2090. efree(ldap_mods[i]->mod_bvalues[j]);
  2091. }
  2092. efree(ldap_mods[i]->mod_bvalues);
  2093. efree(ldap_mods[i]);
  2094. }
  2095. efree(num_berval);
  2096. efree(ldap_mods);
  2097. if (lserverctrls) {
  2098. _php_ldap_controls_free(&lserverctrls);
  2099. }
  2100. return;
  2101. }
  2102. /* }}} */
  2103. /* {{{ proto bool ldap_add(resource link, string dn, array entry [, array servercontrols])
  2104. Add entries to LDAP directory */
  2105. PHP_FUNCTION(ldap_add)
  2106. {
  2107. /* use a newly define parameter into the do_modify so ldap_mod_add can be used the way it is supposed to be used , Gerrit THomson */
  2108. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, PHP_LD_FULL_ADD, 0);
  2109. }
  2110. /* }}} */
  2111. /* {{{ proto resource ldap_add_ext(resource link, string dn, array entry [, array servercontrols])
  2112. Add entries to LDAP directory */
  2113. PHP_FUNCTION(ldap_add_ext)
  2114. {
  2115. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, PHP_LD_FULL_ADD, 1);
  2116. }
  2117. /* }}} */
  2118. /* three functions for attribute base modifications, gerrit Thomson */
  2119. /* {{{ proto bool ldap_mod_replace(resource link, string dn, array entry [, array servercontrols])
  2120. Replace attribute values with new ones */
  2121. PHP_FUNCTION(ldap_mod_replace)
  2122. {
  2123. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_MOD_REPLACE, 0);
  2124. }
  2125. /* }}} */
  2126. /* {{{ proto resource ldap_mod_replace_ext(resource link, string dn, array entry [, array servercontrols])
  2127. Replace attribute values with new ones */
  2128. PHP_FUNCTION(ldap_mod_replace_ext)
  2129. {
  2130. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_MOD_REPLACE, 1);
  2131. }
  2132. /* }}} */
  2133. /* {{{ proto bool ldap_mod_add(resource link, string dn, array entry [, array servercontrols])
  2134. Add attribute values to current */
  2135. PHP_FUNCTION(ldap_mod_add)
  2136. {
  2137. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_MOD_ADD, 0);
  2138. }
  2139. /* }}} */
  2140. /* {{{ proto resource ldap_mod_add(resource link, string dn, array entry [, array servercontrols])
  2141. Add attribute values to current */
  2142. PHP_FUNCTION(ldap_mod_add_ext)
  2143. {
  2144. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_MOD_ADD, 1);
  2145. }
  2146. /* }}} */
  2147. /* {{{ proto bool ldap_mod_del(resource link, string dn, array entry [, array servercontrols])
  2148. Delete attribute values */
  2149. PHP_FUNCTION(ldap_mod_del)
  2150. {
  2151. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_MOD_DELETE, 0);
  2152. }
  2153. /* }}} */
  2154. /* {{{ proto resource ldap_mod_del_ext(resource link, string dn, array entry [, array servercontrols])
  2155. Delete attribute values */
  2156. PHP_FUNCTION(ldap_mod_del_ext)
  2157. {
  2158. php_ldap_do_modify(INTERNAL_FUNCTION_PARAM_PASSTHRU, LDAP_MOD_DELETE, 1);
  2159. }
  2160. /* }}} */
  2161. /* {{{ php_ldap_do_delete
  2162. */
  2163. static void php_ldap_do_delete(INTERNAL_FUNCTION_PARAMETERS, int ext)
  2164. {
  2165. zval *serverctrls = NULL;
  2166. zval *link;
  2167. ldap_linkdata *ld;
  2168. LDAPControl **lserverctrls = NULL;
  2169. LDAPMessage *ldap_res;
  2170. char *dn;
  2171. int rc, msgid;
  2172. size_t dn_len;
  2173. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rs|a", &link, &dn, &dn_len, &serverctrls) != SUCCESS) {
  2174. return;
  2175. }
  2176. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  2177. RETURN_FALSE;
  2178. }
  2179. if (serverctrls) {
  2180. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  2181. if (lserverctrls == NULL) {
  2182. RETVAL_FALSE;
  2183. goto cleanup;
  2184. }
  2185. }
  2186. if (ext) {
  2187. rc = ldap_delete_ext(ld->link, dn, lserverctrls, NULL, &msgid);
  2188. } else {
  2189. rc = ldap_delete_ext_s(ld->link, dn, lserverctrls, NULL);
  2190. }
  2191. if (rc != LDAP_SUCCESS) {
  2192. php_error_docref(NULL, E_WARNING, "Delete: %s", ldap_err2string(rc));
  2193. RETVAL_FALSE;
  2194. goto cleanup;
  2195. } else if (ext) {
  2196. rc = ldap_result(ld->link, msgid, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  2197. if (rc == -1) {
  2198. php_error_docref(NULL, E_WARNING, "Delete operation failed");
  2199. RETVAL_FALSE;
  2200. goto cleanup;
  2201. }
  2202. /* return a PHP control object */
  2203. RETVAL_RES(zend_register_resource(ldap_res, le_result));
  2204. } else {
  2205. RETVAL_TRUE;
  2206. }
  2207. cleanup:
  2208. if (lserverctrls) {
  2209. _php_ldap_controls_free(&lserverctrls);
  2210. }
  2211. return;
  2212. }
  2213. /* }}} */
  2214. /* {{{ proto bool ldap_delete(resource link, string dn [, array servercontrols])
  2215. Delete an entry from a directory */
  2216. PHP_FUNCTION(ldap_delete)
  2217. {
  2218. php_ldap_do_delete(INTERNAL_FUNCTION_PARAM_PASSTHRU, 0);
  2219. }
  2220. /* }}} */
  2221. /* {{{ proto resource ldap_delete_ext(resource link, string dn [, array servercontrols])
  2222. Delete an entry from a directory */
  2223. PHP_FUNCTION(ldap_delete_ext)
  2224. {
  2225. php_ldap_do_delete(INTERNAL_FUNCTION_PARAM_PASSTHRU, 1);
  2226. }
  2227. /* }}} */
  2228. /* {{{ _ldap_str_equal_to_const
  2229. */
  2230. static size_t _ldap_str_equal_to_const(const char *str, size_t str_len, const char *cstr)
  2231. {
  2232. size_t i;
  2233. if (strlen(cstr) != str_len)
  2234. return 0;
  2235. for (i = 0; i < str_len; ++i) {
  2236. if (str[i] != cstr[i]) {
  2237. return 0;
  2238. }
  2239. }
  2240. return 1;
  2241. }
  2242. /* }}} */
  2243. /* {{{ _ldap_strlen_max
  2244. */
  2245. static size_t _ldap_strlen_max(const char *str, size_t max_len)
  2246. {
  2247. size_t i;
  2248. for (i = 0; i < max_len; ++i) {
  2249. if (str[i] == '\0') {
  2250. return i;
  2251. }
  2252. }
  2253. return max_len;
  2254. }
  2255. /* }}} */
  2256. /* {{{ _ldap_hash_fetch
  2257. */
  2258. static void _ldap_hash_fetch(zval *hashTbl, const char *key, zval **out)
  2259. {
  2260. *out = zend_hash_str_find(Z_ARRVAL_P(hashTbl), key, strlen(key));
  2261. }
  2262. /* }}} */
  2263. /* {{{ proto bool ldap_modify_batch(resource link, string dn, array modifs [, array servercontrols])
  2264. Perform multiple modifications as part of one operation */
  2265. PHP_FUNCTION(ldap_modify_batch)
  2266. {
  2267. zval *serverctrls = NULL;
  2268. ldap_linkdata *ld;
  2269. zval *link, *mods, *mod, *modinfo;
  2270. zend_string *modval;
  2271. zval *attrib, *modtype, *vals;
  2272. zval *fetched;
  2273. char *dn;
  2274. size_t dn_len;
  2275. int i, j, k;
  2276. int num_mods, num_modprops, num_modvals;
  2277. LDAPMod **ldap_mods;
  2278. LDAPControl **lserverctrls = NULL;
  2279. uint32_t oper;
  2280. /*
  2281. $mods = array(
  2282. array(
  2283. "attrib" => "unicodePwd",
  2284. "modtype" => LDAP_MODIFY_BATCH_REMOVE,
  2285. "values" => array($oldpw)
  2286. ),
  2287. array(
  2288. "attrib" => "unicodePwd",
  2289. "modtype" => LDAP_MODIFY_BATCH_ADD,
  2290. "values" => array($newpw)
  2291. ),
  2292. array(
  2293. "attrib" => "userPrincipalName",
  2294. "modtype" => LDAP_MODIFY_BATCH_REPLACE,
  2295. "values" => array("janitor@corp.contoso.com")
  2296. ),
  2297. array(
  2298. "attrib" => "userCert",
  2299. "modtype" => LDAP_MODIFY_BATCH_REMOVE_ALL
  2300. )
  2301. );
  2302. */
  2303. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rsa/|a", &link, &dn, &dn_len, &mods, &serverctrls) != SUCCESS) {
  2304. return;
  2305. }
  2306. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  2307. RETURN_FALSE;
  2308. }
  2309. /* perform validation */
  2310. {
  2311. zend_string *modkey;
  2312. zend_long modtype;
  2313. /* to store the wrongly-typed keys */
  2314. zend_ulong tmpUlong;
  2315. /* make sure the DN contains no NUL bytes */
  2316. if (_ldap_strlen_max(dn, dn_len) != dn_len) {
  2317. php_error_docref(NULL, E_WARNING, "DN must not contain NUL bytes");
  2318. RETURN_FALSE;
  2319. }
  2320. /* make sure the top level is a normal array */
  2321. zend_hash_internal_pointer_reset(Z_ARRVAL_P(mods));
  2322. if (zend_hash_get_current_key_type(Z_ARRVAL_P(mods)) != HASH_KEY_IS_LONG) {
  2323. php_error_docref(NULL, E_WARNING, "Modifications array must not be string-indexed");
  2324. RETURN_FALSE;
  2325. }
  2326. num_mods = zend_hash_num_elements(Z_ARRVAL_P(mods));
  2327. for (i = 0; i < num_mods; i++) {
  2328. /* is the numbering consecutive? */
  2329. if ((fetched = zend_hash_index_find(Z_ARRVAL_P(mods), i)) == NULL) {
  2330. php_error_docref(NULL, E_WARNING, "Modifications array must have consecutive indices 0, 1, ...");
  2331. RETURN_FALSE;
  2332. }
  2333. mod = fetched;
  2334. /* is it an array? */
  2335. if (Z_TYPE_P(mod) != IS_ARRAY) {
  2336. php_error_docref(NULL, E_WARNING, "Each entry of modifications array must be an array itself");
  2337. RETURN_FALSE;
  2338. }
  2339. SEPARATE_ARRAY(mod);
  2340. /* for the modification hashtable... */
  2341. zend_hash_internal_pointer_reset(Z_ARRVAL_P(mod));
  2342. num_modprops = zend_hash_num_elements(Z_ARRVAL_P(mod));
  2343. for (j = 0; j < num_modprops; j++) {
  2344. /* are the keys strings? */
  2345. if (zend_hash_get_current_key(Z_ARRVAL_P(mod), &modkey, &tmpUlong) != HASH_KEY_IS_STRING) {
  2346. php_error_docref(NULL, E_WARNING, "Each entry of modifications array must be string-indexed");
  2347. RETURN_FALSE;
  2348. }
  2349. /* is this a valid entry? */
  2350. if (
  2351. !_ldap_str_equal_to_const(ZSTR_VAL(modkey), ZSTR_LEN(modkey), LDAP_MODIFY_BATCH_ATTRIB) &&
  2352. !_ldap_str_equal_to_const(ZSTR_VAL(modkey), ZSTR_LEN(modkey), LDAP_MODIFY_BATCH_MODTYPE) &&
  2353. !_ldap_str_equal_to_const(ZSTR_VAL(modkey), ZSTR_LEN(modkey), LDAP_MODIFY_BATCH_VALUES)
  2354. ) {
  2355. php_error_docref(NULL, E_WARNING, "The only allowed keys in entries of the modifications array are '" LDAP_MODIFY_BATCH_ATTRIB "', '" LDAP_MODIFY_BATCH_MODTYPE "' and '" LDAP_MODIFY_BATCH_VALUES "'");
  2356. RETURN_FALSE;
  2357. }
  2358. fetched = zend_hash_get_current_data(Z_ARRVAL_P(mod));
  2359. modinfo = fetched;
  2360. /* does the value type match the key? */
  2361. if (_ldap_str_equal_to_const(ZSTR_VAL(modkey), ZSTR_LEN(modkey), LDAP_MODIFY_BATCH_ATTRIB)) {
  2362. if (Z_TYPE_P(modinfo) != IS_STRING) {
  2363. php_error_docref(NULL, E_WARNING, "A '" LDAP_MODIFY_BATCH_ATTRIB "' value must be a string");
  2364. RETURN_FALSE;
  2365. }
  2366. if (Z_STRLEN_P(modinfo) != _ldap_strlen_max(Z_STRVAL_P(modinfo), Z_STRLEN_P(modinfo))) {
  2367. php_error_docref(NULL, E_WARNING, "A '" LDAP_MODIFY_BATCH_ATTRIB "' value must not contain NUL bytes");
  2368. RETURN_FALSE;
  2369. }
  2370. }
  2371. else if (_ldap_str_equal_to_const(ZSTR_VAL(modkey), ZSTR_LEN(modkey), LDAP_MODIFY_BATCH_MODTYPE)) {
  2372. if (Z_TYPE_P(modinfo) != IS_LONG) {
  2373. php_error_docref(NULL, E_WARNING, "A '" LDAP_MODIFY_BATCH_MODTYPE "' value must be a long");
  2374. RETURN_FALSE;
  2375. }
  2376. /* is the value in range? */
  2377. modtype = Z_LVAL_P(modinfo);
  2378. if (
  2379. modtype != LDAP_MODIFY_BATCH_ADD &&
  2380. modtype != LDAP_MODIFY_BATCH_REMOVE &&
  2381. modtype != LDAP_MODIFY_BATCH_REPLACE &&
  2382. modtype != LDAP_MODIFY_BATCH_REMOVE_ALL
  2383. ) {
  2384. php_error_docref(NULL, E_WARNING, "The '" LDAP_MODIFY_BATCH_MODTYPE "' value must match one of the LDAP_MODIFY_BATCH_* constants");
  2385. RETURN_FALSE;
  2386. }
  2387. /* if it's REMOVE_ALL, there must not be a values array; otherwise, there must */
  2388. if (modtype == LDAP_MODIFY_BATCH_REMOVE_ALL) {
  2389. if (zend_hash_str_exists(Z_ARRVAL_P(mod), LDAP_MODIFY_BATCH_VALUES, strlen(LDAP_MODIFY_BATCH_VALUES))) {
  2390. php_error_docref(NULL, E_WARNING, "If '" LDAP_MODIFY_BATCH_MODTYPE "' is LDAP_MODIFY_BATCH_REMOVE_ALL, a '" LDAP_MODIFY_BATCH_VALUES "' array must not be provided");
  2391. RETURN_FALSE;
  2392. }
  2393. }
  2394. else {
  2395. if (!zend_hash_str_exists(Z_ARRVAL_P(mod), LDAP_MODIFY_BATCH_VALUES, strlen(LDAP_MODIFY_BATCH_VALUES))) {
  2396. php_error_docref(NULL, E_WARNING, "If '" LDAP_MODIFY_BATCH_MODTYPE "' is not LDAP_MODIFY_BATCH_REMOVE_ALL, a '" LDAP_MODIFY_BATCH_VALUES "' array must be provided");
  2397. RETURN_FALSE;
  2398. }
  2399. }
  2400. }
  2401. else if (_ldap_str_equal_to_const(ZSTR_VAL(modkey), ZSTR_LEN(modkey), LDAP_MODIFY_BATCH_VALUES)) {
  2402. if (Z_TYPE_P(modinfo) != IS_ARRAY) {
  2403. php_error_docref(NULL, E_WARNING, "A '" LDAP_MODIFY_BATCH_VALUES "' value must be an array");
  2404. RETURN_FALSE;
  2405. }
  2406. SEPARATE_ARRAY(modinfo);
  2407. /* is the array not empty? */
  2408. zend_hash_internal_pointer_reset(Z_ARRVAL_P(modinfo));
  2409. num_modvals = zend_hash_num_elements(Z_ARRVAL_P(modinfo));
  2410. if (num_modvals == 0) {
  2411. php_error_docref(NULL, E_WARNING, "A '" LDAP_MODIFY_BATCH_VALUES "' array must have at least one element");
  2412. RETURN_FALSE;
  2413. }
  2414. /* are its keys integers? */
  2415. if (zend_hash_get_current_key_type(Z_ARRVAL_P(modinfo)) != HASH_KEY_IS_LONG) {
  2416. php_error_docref(NULL, E_WARNING, "A '" LDAP_MODIFY_BATCH_VALUES "' array must not be string-indexed");
  2417. RETURN_FALSE;
  2418. }
  2419. /* are the keys consecutive? */
  2420. for (k = 0; k < num_modvals; k++) {
  2421. if ((fetched = zend_hash_index_find(Z_ARRVAL_P(modinfo), k)) == NULL) {
  2422. php_error_docref(NULL, E_WARNING, "A '" LDAP_MODIFY_BATCH_VALUES "' array must have consecutive indices 0, 1, ...");
  2423. RETURN_FALSE;
  2424. }
  2425. }
  2426. }
  2427. zend_hash_move_forward(Z_ARRVAL_P(mod));
  2428. }
  2429. }
  2430. }
  2431. /* validation was successful */
  2432. /* allocate array of modifications */
  2433. ldap_mods = safe_emalloc((num_mods+1), sizeof(LDAPMod *), 0);
  2434. /* for each modification */
  2435. for (i = 0; i < num_mods; i++) {
  2436. /* allocate the modification struct */
  2437. ldap_mods[i] = safe_emalloc(1, sizeof(LDAPMod), 0);
  2438. /* fetch the relevant data */
  2439. fetched = zend_hash_index_find(Z_ARRVAL_P(mods), i);
  2440. mod = fetched;
  2441. _ldap_hash_fetch(mod, LDAP_MODIFY_BATCH_ATTRIB, &attrib);
  2442. _ldap_hash_fetch(mod, LDAP_MODIFY_BATCH_MODTYPE, &modtype);
  2443. _ldap_hash_fetch(mod, LDAP_MODIFY_BATCH_VALUES, &vals);
  2444. /* map the modification type */
  2445. switch (Z_LVAL_P(modtype)) {
  2446. case LDAP_MODIFY_BATCH_ADD:
  2447. oper = LDAP_MOD_ADD;
  2448. break;
  2449. case LDAP_MODIFY_BATCH_REMOVE:
  2450. case LDAP_MODIFY_BATCH_REMOVE_ALL:
  2451. oper = LDAP_MOD_DELETE;
  2452. break;
  2453. case LDAP_MODIFY_BATCH_REPLACE:
  2454. oper = LDAP_MOD_REPLACE;
  2455. break;
  2456. default:
  2457. zend_throw_error(NULL, "Unknown and uncaught modification type.");
  2458. RETVAL_FALSE;
  2459. efree(ldap_mods[i]);
  2460. num_mods = i;
  2461. goto cleanup;
  2462. }
  2463. /* fill in the basic info */
  2464. ldap_mods[i]->mod_op = oper | LDAP_MOD_BVALUES;
  2465. ldap_mods[i]->mod_type = estrndup(Z_STRVAL_P(attrib), Z_STRLEN_P(attrib));
  2466. if (Z_LVAL_P(modtype) == LDAP_MODIFY_BATCH_REMOVE_ALL) {
  2467. /* no values */
  2468. ldap_mods[i]->mod_bvalues = NULL;
  2469. }
  2470. else {
  2471. /* allocate space for the values as part of this modification */
  2472. num_modvals = zend_hash_num_elements(Z_ARRVAL_P(vals));
  2473. ldap_mods[i]->mod_bvalues = safe_emalloc((num_modvals+1), sizeof(struct berval *), 0);
  2474. /* for each value */
  2475. for (j = 0; j < num_modvals; j++) {
  2476. /* fetch it */
  2477. fetched = zend_hash_index_find(Z_ARRVAL_P(vals), j);
  2478. modval = zval_get_string(fetched);
  2479. if (EG(exception)) {
  2480. RETVAL_FALSE;
  2481. ldap_mods[i]->mod_bvalues[j] = NULL;
  2482. num_mods = i + 1;
  2483. goto cleanup;
  2484. }
  2485. /* allocate the data struct */
  2486. ldap_mods[i]->mod_bvalues[j] = safe_emalloc(1, sizeof(struct berval), 0);
  2487. /* fill it */
  2488. ldap_mods[i]->mod_bvalues[j]->bv_len = ZSTR_LEN(modval);
  2489. ldap_mods[i]->mod_bvalues[j]->bv_val = estrndup(ZSTR_VAL(modval), ZSTR_LEN(modval));
  2490. zend_string_release(modval);
  2491. }
  2492. /* NULL-terminate values */
  2493. ldap_mods[i]->mod_bvalues[num_modvals] = NULL;
  2494. }
  2495. }
  2496. /* NULL-terminate modifications */
  2497. ldap_mods[num_mods] = NULL;
  2498. if (serverctrls) {
  2499. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  2500. if (lserverctrls == NULL) {
  2501. RETVAL_FALSE;
  2502. goto cleanup;
  2503. }
  2504. }
  2505. /* perform (finally) */
  2506. if ((i = ldap_modify_ext_s(ld->link, dn, ldap_mods, lserverctrls, NULL)) != LDAP_SUCCESS) {
  2507. php_error_docref(NULL, E_WARNING, "Batch Modify: %s", ldap_err2string(i));
  2508. RETVAL_FALSE;
  2509. } else RETVAL_TRUE;
  2510. /* clean up */
  2511. cleanup: {
  2512. for (i = 0; i < num_mods; i++) {
  2513. /* attribute */
  2514. efree(ldap_mods[i]->mod_type);
  2515. if (ldap_mods[i]->mod_bvalues != NULL) {
  2516. /* each BER value */
  2517. for (j = 0; ldap_mods[i]->mod_bvalues[j] != NULL; j++) {
  2518. /* free the data bytes */
  2519. efree(ldap_mods[i]->mod_bvalues[j]->bv_val);
  2520. /* free the bvalue struct */
  2521. efree(ldap_mods[i]->mod_bvalues[j]);
  2522. }
  2523. /* the BER value array */
  2524. efree(ldap_mods[i]->mod_bvalues);
  2525. }
  2526. /* the modification */
  2527. efree(ldap_mods[i]);
  2528. }
  2529. /* the modifications array */
  2530. efree(ldap_mods);
  2531. if (lserverctrls) {
  2532. _php_ldap_controls_free(&lserverctrls);
  2533. }
  2534. }
  2535. }
  2536. /* }}} */
  2537. /* {{{ proto int ldap_errno(resource link)
  2538. Get the current ldap error number */
  2539. PHP_FUNCTION(ldap_errno)
  2540. {
  2541. zval *link;
  2542. ldap_linkdata *ld;
  2543. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r", &link) != SUCCESS) {
  2544. return;
  2545. }
  2546. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  2547. RETURN_FALSE;
  2548. }
  2549. RETURN_LONG(_get_lderrno(ld->link));
  2550. }
  2551. /* }}} */
  2552. /* {{{ proto string ldap_err2str(int errno)
  2553. Convert error number to error string */
  2554. PHP_FUNCTION(ldap_err2str)
  2555. {
  2556. zend_long perrno;
  2557. if (zend_parse_parameters(ZEND_NUM_ARGS(), "l", &perrno) != SUCCESS) {
  2558. return;
  2559. }
  2560. RETURN_STRING(ldap_err2string(perrno));
  2561. }
  2562. /* }}} */
  2563. /* {{{ proto string ldap_error(resource link)
  2564. Get the current ldap error string */
  2565. PHP_FUNCTION(ldap_error)
  2566. {
  2567. zval *link;
  2568. ldap_linkdata *ld;
  2569. int ld_errno;
  2570. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r", &link) != SUCCESS) {
  2571. return;
  2572. }
  2573. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  2574. RETURN_FALSE;
  2575. }
  2576. ld_errno = _get_lderrno(ld->link);
  2577. RETURN_STRING(ldap_err2string(ld_errno));
  2578. }
  2579. /* }}} */
  2580. /* {{{ proto bool ldap_compare(resource link, string dn, string attr, string value)
  2581. Determine if an entry has a specific value for one of its attributes */
  2582. PHP_FUNCTION(ldap_compare)
  2583. {
  2584. zval *serverctrls = NULL;
  2585. zval *link;
  2586. char *dn, *attr, *value;
  2587. size_t dn_len, attr_len, value_len;
  2588. ldap_linkdata *ld;
  2589. LDAPControl **lserverctrls = NULL;
  2590. int errno;
  2591. struct berval lvalue;
  2592. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rsss|a", &link, &dn, &dn_len, &attr, &attr_len, &value, &value_len, &serverctrls) != SUCCESS) {
  2593. return;
  2594. }
  2595. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  2596. RETURN_FALSE;
  2597. }
  2598. if (serverctrls) {
  2599. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  2600. if (lserverctrls == NULL) {
  2601. RETVAL_FALSE;
  2602. goto cleanup;
  2603. }
  2604. }
  2605. lvalue.bv_val = value;
  2606. lvalue.bv_len = value_len;
  2607. errno = ldap_compare_ext_s(ld->link, dn, attr, &lvalue, lserverctrls, NULL);
  2608. switch (errno) {
  2609. case LDAP_COMPARE_TRUE:
  2610. RETVAL_TRUE;
  2611. break;
  2612. case LDAP_COMPARE_FALSE:
  2613. RETVAL_FALSE;
  2614. break;
  2615. default:
  2616. php_error_docref(NULL, E_WARNING, "Compare: %s", ldap_err2string(errno));
  2617. RETVAL_LONG(-1);
  2618. }
  2619. cleanup:
  2620. if (lserverctrls) {
  2621. _php_ldap_controls_free(&lserverctrls);
  2622. }
  2623. return;
  2624. }
  2625. /* }}} */
  2626. /* {{{ proto bool ldap_sort(resource link, resource result, string sortfilter)
  2627. Sort LDAP result entries */
  2628. PHP_FUNCTION(ldap_sort)
  2629. {
  2630. zval *link, *result;
  2631. ldap_linkdata *ld;
  2632. char *sortfilter;
  2633. size_t sflen;
  2634. zend_resource *le;
  2635. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rrs", &link, &result, &sortfilter, &sflen) != SUCCESS) {
  2636. RETURN_FALSE;
  2637. }
  2638. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  2639. RETURN_FALSE;
  2640. }
  2641. le = Z_RES_P(result);
  2642. if (le->type != le_result) {
  2643. php_error_docref(NULL, E_WARNING, "Supplied resource is not a valid ldap result resource");
  2644. RETURN_FALSE;
  2645. }
  2646. if (ldap_sort_entries(ld->link, (LDAPMessage **) &le->ptr, sflen ? sortfilter : NULL, strcmp) != LDAP_SUCCESS) {
  2647. php_error_docref(NULL, E_WARNING, "%s", ldap_err2string(errno));
  2648. RETURN_FALSE;
  2649. }
  2650. RETURN_TRUE;
  2651. }
  2652. /* }}} */
  2653. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP
  2654. /* {{{ proto bool ldap_get_option(resource link, int option, mixed retval)
  2655. Get the current value of various session-wide parameters */
  2656. PHP_FUNCTION(ldap_get_option)
  2657. {
  2658. zval *link, *retval;
  2659. ldap_linkdata *ld;
  2660. zend_long option;
  2661. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rlz/", &link, &option, &retval) != SUCCESS) {
  2662. return;
  2663. }
  2664. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  2665. RETURN_FALSE;
  2666. }
  2667. switch (option) {
  2668. /* options with int value */
  2669. case LDAP_OPT_DEREF:
  2670. case LDAP_OPT_SIZELIMIT:
  2671. case LDAP_OPT_TIMELIMIT:
  2672. case LDAP_OPT_PROTOCOL_VERSION:
  2673. case LDAP_OPT_ERROR_NUMBER:
  2674. case LDAP_OPT_REFERRALS:
  2675. #ifdef LDAP_OPT_RESTART
  2676. case LDAP_OPT_RESTART:
  2677. #endif
  2678. #ifdef LDAP_OPT_X_SASL_NOCANON
  2679. case LDAP_OPT_X_SASL_NOCANON:
  2680. #endif
  2681. #ifdef LDAP_OPT_X_TLS_REQUIRE_CERT
  2682. case LDAP_OPT_X_TLS_REQUIRE_CERT:
  2683. #endif
  2684. #ifdef LDAP_OPT_X_TLS_CRLCHECK
  2685. case LDAP_OPT_X_TLS_CRLCHECK:
  2686. #endif
  2687. #ifdef LDAP_OPT_X_TLS_PROTOCOL_MIN
  2688. case LDAP_OPT_X_TLS_PROTOCOL_MIN:
  2689. #endif
  2690. #ifdef LDAP_OPT_X_KEEPALIVE_IDLE
  2691. case LDAP_OPT_X_KEEPALIVE_IDLE:
  2692. case LDAP_OPT_X_KEEPALIVE_PROBES:
  2693. case LDAP_OPT_X_KEEPALIVE_INTERVAL:
  2694. #endif
  2695. {
  2696. int val;
  2697. if (ldap_get_option(ld->link, option, &val)) {
  2698. RETURN_FALSE;
  2699. }
  2700. zval_ptr_dtor(retval);
  2701. ZVAL_LONG(retval, val);
  2702. } break;
  2703. #ifdef LDAP_OPT_NETWORK_TIMEOUT
  2704. case LDAP_OPT_NETWORK_TIMEOUT:
  2705. {
  2706. struct timeval *timeout = NULL;
  2707. if (ldap_get_option(ld->link, LDAP_OPT_NETWORK_TIMEOUT, (void *) &timeout)) {
  2708. if (timeout) {
  2709. ldap_memfree(timeout);
  2710. }
  2711. RETURN_FALSE;
  2712. }
  2713. if (!timeout) {
  2714. RETURN_FALSE;
  2715. }
  2716. zval_ptr_dtor(retval);
  2717. ZVAL_LONG(retval, timeout->tv_sec);
  2718. ldap_memfree(timeout);
  2719. } break;
  2720. #elif defined(LDAP_X_OPT_CONNECT_TIMEOUT)
  2721. case LDAP_X_OPT_CONNECT_TIMEOUT:
  2722. {
  2723. int timeout;
  2724. if (ldap_get_option(ld->link, LDAP_X_OPT_CONNECT_TIMEOUT, &timeout)) {
  2725. RETURN_FALSE;
  2726. }
  2727. zval_ptr_dtor(retval);
  2728. ZVAL_LONG(retval, (timeout / 1000));
  2729. } break;
  2730. #endif
  2731. #ifdef LDAP_OPT_TIMEOUT
  2732. case LDAP_OPT_TIMEOUT:
  2733. {
  2734. struct timeval *timeout = NULL;
  2735. if (ldap_get_option(ld->link, LDAP_OPT_TIMEOUT, (void *) &timeout)) {
  2736. if (timeout) {
  2737. ldap_memfree(timeout);
  2738. }
  2739. RETURN_FALSE;
  2740. }
  2741. if (!timeout) {
  2742. RETURN_FALSE;
  2743. }
  2744. zval_ptr_dtor(retval);
  2745. ZVAL_LONG(retval, timeout->tv_sec);
  2746. ldap_memfree(timeout);
  2747. } break;
  2748. #endif
  2749. /* options with string value */
  2750. case LDAP_OPT_ERROR_STRING:
  2751. #ifdef LDAP_OPT_HOST_NAME
  2752. case LDAP_OPT_HOST_NAME:
  2753. #endif
  2754. #ifdef HAVE_LDAP_SASL
  2755. case LDAP_OPT_X_SASL_MECH:
  2756. case LDAP_OPT_X_SASL_REALM:
  2757. case LDAP_OPT_X_SASL_AUTHCID:
  2758. case LDAP_OPT_X_SASL_AUTHZID:
  2759. #endif
  2760. #ifdef LDAP_OPT_X_SASL_USERNAME
  2761. case LDAP_OPT_X_SASL_USERNAME:
  2762. #endif
  2763. #if (LDAP_API_VERSION > 2000)
  2764. case LDAP_OPT_X_TLS_CACERTDIR:
  2765. case LDAP_OPT_X_TLS_CACERTFILE:
  2766. case LDAP_OPT_X_TLS_CERTFILE:
  2767. case LDAP_OPT_X_TLS_CIPHER_SUITE:
  2768. case LDAP_OPT_X_TLS_KEYFILE:
  2769. case LDAP_OPT_X_TLS_RANDOM_FILE:
  2770. #endif
  2771. #ifdef LDAP_OPT_X_TLS_PACKAGE
  2772. case LDAP_OPT_X_TLS_PACKAGE:
  2773. #endif
  2774. #ifdef LDAP_OPT_X_TLS_CRLFILE
  2775. case LDAP_OPT_X_TLS_CRLFILE:
  2776. #endif
  2777. #ifdef LDAP_OPT_X_TLS_DHFILE
  2778. case LDAP_OPT_X_TLS_DHFILE:
  2779. #endif
  2780. #ifdef LDAP_OPT_MATCHED_DN
  2781. case LDAP_OPT_MATCHED_DN:
  2782. #endif
  2783. {
  2784. char *val = NULL;
  2785. if (ldap_get_option(ld->link, option, &val) || val == NULL || *val == '\0') {
  2786. if (val) {
  2787. ldap_memfree(val);
  2788. }
  2789. RETURN_FALSE;
  2790. }
  2791. zval_ptr_dtor(retval);
  2792. ZVAL_STRING(retval, val);
  2793. ldap_memfree(val);
  2794. } break;
  2795. case LDAP_OPT_SERVER_CONTROLS:
  2796. case LDAP_OPT_CLIENT_CONTROLS:
  2797. {
  2798. LDAPControl **ctrls = NULL;
  2799. if (ldap_get_option(ld->link, option, &ctrls) || ctrls == NULL) {
  2800. if (ctrls) {
  2801. ldap_memfree(ctrls);
  2802. }
  2803. RETURN_FALSE;
  2804. }
  2805. zval_ptr_dtor(retval);
  2806. _php_ldap_controls_to_array(ld->link, ctrls, retval, 1);
  2807. } break;
  2808. /* options not implemented
  2809. case LDAP_OPT_API_INFO:
  2810. case LDAP_OPT_API_FEATURE_INFO:
  2811. */
  2812. default:
  2813. RETURN_FALSE;
  2814. }
  2815. RETURN_TRUE;
  2816. }
  2817. /* }}} */
  2818. /* {{{ proto bool ldap_set_option(resource link, int option, mixed newval)
  2819. Set the value of various session-wide parameters */
  2820. PHP_FUNCTION(ldap_set_option)
  2821. {
  2822. zval *link, *newval;
  2823. ldap_linkdata *ld;
  2824. LDAP *ldap;
  2825. zend_long option;
  2826. if (zend_parse_parameters(ZEND_NUM_ARGS(), "zlz", &link, &option, &newval) != SUCCESS) {
  2827. return;
  2828. }
  2829. if (Z_TYPE_P(link) == IS_NULL) {
  2830. ldap = NULL;
  2831. } else {
  2832. if ((ld = (ldap_linkdata *)zend_fetch_resource_ex(link, "ldap link", le_link)) == NULL) {
  2833. RETURN_FALSE;
  2834. }
  2835. ldap = ld->link;
  2836. }
  2837. switch (option) {
  2838. /* options with int value */
  2839. case LDAP_OPT_DEREF:
  2840. case LDAP_OPT_SIZELIMIT:
  2841. case LDAP_OPT_TIMELIMIT:
  2842. case LDAP_OPT_PROTOCOL_VERSION:
  2843. case LDAP_OPT_ERROR_NUMBER:
  2844. #ifdef LDAP_OPT_DEBUG_LEVEL
  2845. case LDAP_OPT_DEBUG_LEVEL:
  2846. #endif
  2847. #ifdef LDAP_OPT_X_TLS_REQUIRE_CERT
  2848. case LDAP_OPT_X_TLS_REQUIRE_CERT:
  2849. #endif
  2850. #ifdef LDAP_OPT_X_TLS_CRLCHECK
  2851. case LDAP_OPT_X_TLS_CRLCHECK:
  2852. #endif
  2853. #ifdef LDAP_OPT_X_TLS_PROTOCOL_MIN
  2854. case LDAP_OPT_X_TLS_PROTOCOL_MIN:
  2855. #endif
  2856. #ifdef LDAP_OPT_X_KEEPALIVE_IDLE
  2857. case LDAP_OPT_X_KEEPALIVE_IDLE:
  2858. case LDAP_OPT_X_KEEPALIVE_PROBES:
  2859. case LDAP_OPT_X_KEEPALIVE_INTERVAL:
  2860. #endif
  2861. {
  2862. int val;
  2863. convert_to_long_ex(newval);
  2864. if (ZEND_LONG_EXCEEDS_INT(Z_LVAL_P(newval))) {
  2865. php_error_docref(NULL, E_WARNING, "Option value is too big");
  2866. RETURN_FALSE;
  2867. }
  2868. val = (int)Z_LVAL_P(newval);
  2869. if (ldap_set_option(ldap, option, &val)) {
  2870. RETURN_FALSE;
  2871. }
  2872. } break;
  2873. #ifdef LDAP_OPT_NETWORK_TIMEOUT
  2874. case LDAP_OPT_NETWORK_TIMEOUT:
  2875. {
  2876. struct timeval timeout;
  2877. convert_to_long_ex(newval);
  2878. timeout.tv_sec = Z_LVAL_P(newval);
  2879. timeout.tv_usec = 0;
  2880. if (ldap_set_option(ldap, LDAP_OPT_NETWORK_TIMEOUT, (void *) &timeout)) {
  2881. RETURN_FALSE;
  2882. }
  2883. } break;
  2884. #elif defined(LDAP_X_OPT_CONNECT_TIMEOUT)
  2885. case LDAP_X_OPT_CONNECT_TIMEOUT:
  2886. {
  2887. int timeout;
  2888. convert_to_long_ex(newval);
  2889. timeout = 1000 * Z_LVAL_P(newval); /* Convert to milliseconds */
  2890. if (ldap_set_option(ldap, LDAP_X_OPT_CONNECT_TIMEOUT, &timeout)) {
  2891. RETURN_FALSE;
  2892. }
  2893. } break;
  2894. #endif
  2895. #ifdef LDAP_OPT_TIMEOUT
  2896. case LDAP_OPT_TIMEOUT:
  2897. {
  2898. struct timeval timeout;
  2899. convert_to_long_ex(newval);
  2900. timeout.tv_sec = Z_LVAL_P(newval);
  2901. timeout.tv_usec = 0;
  2902. if (ldap_set_option(ldap, LDAP_OPT_TIMEOUT, (void *) &timeout)) {
  2903. RETURN_FALSE;
  2904. }
  2905. } break;
  2906. #endif
  2907. /* options with string value */
  2908. case LDAP_OPT_ERROR_STRING:
  2909. #ifdef LDAP_OPT_HOST_NAME
  2910. case LDAP_OPT_HOST_NAME:
  2911. #endif
  2912. #ifdef HAVE_LDAP_SASL
  2913. case LDAP_OPT_X_SASL_MECH:
  2914. case LDAP_OPT_X_SASL_REALM:
  2915. case LDAP_OPT_X_SASL_AUTHCID:
  2916. case LDAP_OPT_X_SASL_AUTHZID:
  2917. #endif
  2918. #if (LDAP_API_VERSION > 2000)
  2919. case LDAP_OPT_X_TLS_CACERTDIR:
  2920. case LDAP_OPT_X_TLS_CACERTFILE:
  2921. case LDAP_OPT_X_TLS_CERTFILE:
  2922. case LDAP_OPT_X_TLS_CIPHER_SUITE:
  2923. case LDAP_OPT_X_TLS_KEYFILE:
  2924. case LDAP_OPT_X_TLS_RANDOM_FILE:
  2925. #endif
  2926. #ifdef LDAP_OPT_X_TLS_CRLFILE
  2927. case LDAP_OPT_X_TLS_CRLFILE:
  2928. #endif
  2929. #ifdef LDAP_OPT_X_TLS_DHFILE
  2930. case LDAP_OPT_X_TLS_DHFILE:
  2931. #endif
  2932. #ifdef LDAP_OPT_MATCHED_DN
  2933. case LDAP_OPT_MATCHED_DN:
  2934. #endif
  2935. {
  2936. zend_string *val;
  2937. val = zval_get_string(newval);
  2938. if (EG(exception)) {
  2939. RETURN_FALSE;
  2940. }
  2941. if (ldap_set_option(ldap, option, ZSTR_VAL(val))) {
  2942. zend_string_release(val);
  2943. RETURN_FALSE;
  2944. }
  2945. zend_string_release(val);
  2946. } break;
  2947. /* options with boolean value */
  2948. case LDAP_OPT_REFERRALS:
  2949. #ifdef LDAP_OPT_RESTART
  2950. case LDAP_OPT_RESTART:
  2951. #endif
  2952. #ifdef LDAP_OPT_X_SASL_NOCANON
  2953. case LDAP_OPT_X_SASL_NOCANON:
  2954. #endif
  2955. {
  2956. void *val;
  2957. val = zend_is_true(newval) ? LDAP_OPT_ON : LDAP_OPT_OFF;
  2958. if (ldap_set_option(ldap, option, val)) {
  2959. RETURN_FALSE;
  2960. }
  2961. } break;
  2962. /* options with control list value */
  2963. case LDAP_OPT_SERVER_CONTROLS:
  2964. case LDAP_OPT_CLIENT_CONTROLS:
  2965. {
  2966. LDAPControl **ctrls;
  2967. int rc;
  2968. if (Z_TYPE_P(newval) != IS_ARRAY) {
  2969. php_error_docref(NULL, E_WARNING, "Expected array value for this option");
  2970. RETURN_FALSE;
  2971. }
  2972. ctrls = _php_ldap_controls_from_array(ldap, newval);
  2973. if (ctrls == NULL) {
  2974. RETURN_FALSE;
  2975. } else {
  2976. rc = ldap_set_option(ldap, option, ctrls);
  2977. _php_ldap_controls_free(&ctrls);
  2978. if (rc != LDAP_SUCCESS) {
  2979. RETURN_FALSE;
  2980. }
  2981. }
  2982. } break;
  2983. default:
  2984. RETURN_FALSE;
  2985. }
  2986. RETURN_TRUE;
  2987. }
  2988. /* }}} */
  2989. #ifdef HAVE_LDAP_PARSE_RESULT
  2990. /* {{{ proto bool ldap_parse_result(resource link, resource result, int &errcode [, string &matcheddn [, string &errmsg [, array &referrals [, array &controls]]]])
  2991. Extract information from result */
  2992. PHP_FUNCTION(ldap_parse_result)
  2993. {
  2994. zval *link, *result, *errcode, *matcheddn, *errmsg, *referrals, *serverctrls;
  2995. ldap_linkdata *ld;
  2996. LDAPMessage *ldap_result;
  2997. LDAPControl **lserverctrls = NULL;
  2998. char **lreferrals, **refp;
  2999. char *lmatcheddn, *lerrmsg;
  3000. int rc, lerrcode, myargcount = ZEND_NUM_ARGS();
  3001. if (zend_parse_parameters(myargcount, "rrz/|z/z/z/z/", &link, &result, &errcode, &matcheddn, &errmsg, &referrals, &serverctrls) != SUCCESS) {
  3002. return;
  3003. }
  3004. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3005. RETURN_FALSE;
  3006. }
  3007. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  3008. RETURN_FALSE;
  3009. }
  3010. rc = ldap_parse_result(ld->link, ldap_result, &lerrcode,
  3011. myargcount > 3 ? &lmatcheddn : NULL,
  3012. myargcount > 4 ? &lerrmsg : NULL,
  3013. myargcount > 5 ? &lreferrals : NULL,
  3014. myargcount > 6 ? &lserverctrls : NULL,
  3015. 0);
  3016. if (rc != LDAP_SUCCESS) {
  3017. php_error_docref(NULL, E_WARNING, "Unable to parse result: %s", ldap_err2string(rc));
  3018. RETURN_FALSE;
  3019. }
  3020. zval_ptr_dtor(errcode);
  3021. ZVAL_LONG(errcode, lerrcode);
  3022. /* Reverse -> fall through */
  3023. switch (myargcount) {
  3024. case 7:
  3025. zval_ptr_dtor(serverctrls);
  3026. _php_ldap_controls_to_array(ld->link, lserverctrls, serverctrls, 0);
  3027. case 6:
  3028. zval_ptr_dtor(referrals);
  3029. array_init(referrals);
  3030. if (lreferrals != NULL) {
  3031. refp = lreferrals;
  3032. while (*refp) {
  3033. add_next_index_string(referrals, *refp);
  3034. refp++;
  3035. }
  3036. ldap_memvfree((void**)lreferrals);
  3037. }
  3038. case 5:
  3039. zval_ptr_dtor(errmsg);
  3040. if (lerrmsg == NULL) {
  3041. ZVAL_EMPTY_STRING(errmsg);
  3042. } else {
  3043. ZVAL_STRING(errmsg, lerrmsg);
  3044. ldap_memfree(lerrmsg);
  3045. }
  3046. case 4:
  3047. zval_ptr_dtor(matcheddn);
  3048. if (lmatcheddn == NULL) {
  3049. ZVAL_EMPTY_STRING(matcheddn);
  3050. } else {
  3051. ZVAL_STRING(matcheddn, lmatcheddn);
  3052. ldap_memfree(lmatcheddn);
  3053. }
  3054. }
  3055. RETURN_TRUE;
  3056. }
  3057. /* }}} */
  3058. #endif
  3059. /* {{{ Extended operation response parsing, Pierangelo Masarati */
  3060. #ifdef HAVE_LDAP_PARSE_EXTENDED_RESULT
  3061. /* {{{ proto bool ldap_parse_exop(resource link, resource result [, string retdata [, string retoid]])
  3062. Extract information from extended operation result */
  3063. PHP_FUNCTION(ldap_parse_exop)
  3064. {
  3065. zval *link, *result, *retdata, *retoid;
  3066. ldap_linkdata *ld;
  3067. LDAPMessage *ldap_result;
  3068. char *lretoid;
  3069. struct berval *lretdata;
  3070. int rc, myargcount = ZEND_NUM_ARGS();
  3071. if (zend_parse_parameters(myargcount, "rr|z/z/", &link, &result, &retdata, &retoid) != SUCCESS) {
  3072. WRONG_PARAM_COUNT;
  3073. }
  3074. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3075. RETURN_FALSE;
  3076. }
  3077. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  3078. RETURN_FALSE;
  3079. }
  3080. rc = ldap_parse_extended_result(ld->link, ldap_result,
  3081. myargcount > 3 ? &lretoid: NULL,
  3082. myargcount > 2 ? &lretdata: NULL,
  3083. 0);
  3084. if (rc != LDAP_SUCCESS) {
  3085. php_error_docref(NULL, E_WARNING, "Unable to parse extended operation result: %s", ldap_err2string(rc));
  3086. RETURN_FALSE;
  3087. }
  3088. /* Reverse -> fall through */
  3089. switch (myargcount) {
  3090. case 4:
  3091. zval_ptr_dtor(retoid);
  3092. if (lretoid == NULL) {
  3093. ZVAL_EMPTY_STRING(retoid);
  3094. } else {
  3095. ZVAL_STRING(retoid, lretoid);
  3096. ldap_memfree(lretoid);
  3097. }
  3098. case 3:
  3099. /* use arg #3 as the data returned by the server */
  3100. zval_ptr_dtor(retdata);
  3101. if (lretdata == NULL) {
  3102. ZVAL_EMPTY_STRING(retdata);
  3103. } else {
  3104. ZVAL_STRINGL(retdata, lretdata->bv_val, lretdata->bv_len);
  3105. ldap_memfree(lretdata->bv_val);
  3106. ldap_memfree(lretdata);
  3107. }
  3108. }
  3109. RETURN_TRUE;
  3110. }
  3111. /* }}} */
  3112. #endif
  3113. /* }}} */
  3114. /* {{{ proto resource ldap_first_reference(resource link, resource result)
  3115. Return first reference */
  3116. PHP_FUNCTION(ldap_first_reference)
  3117. {
  3118. zval *link, *result;
  3119. ldap_linkdata *ld;
  3120. ldap_resultentry *resultentry;
  3121. LDAPMessage *ldap_result, *entry;
  3122. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result) != SUCCESS) {
  3123. return;
  3124. }
  3125. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3126. RETURN_FALSE;
  3127. }
  3128. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  3129. RETURN_FALSE;
  3130. }
  3131. if ((entry = ldap_first_reference(ld->link, ldap_result)) == NULL) {
  3132. RETVAL_FALSE;
  3133. } else {
  3134. resultentry = emalloc(sizeof(ldap_resultentry));
  3135. RETVAL_RES(zend_register_resource(resultentry, le_result_entry));
  3136. ZVAL_COPY(&resultentry->res, result);
  3137. resultentry->data = entry;
  3138. resultentry->ber = NULL;
  3139. }
  3140. }
  3141. /* }}} */
  3142. /* {{{ proto resource ldap_next_reference(resource link, resource reference_entry)
  3143. Get next reference */
  3144. PHP_FUNCTION(ldap_next_reference)
  3145. {
  3146. zval *link, *result_entry;
  3147. ldap_linkdata *ld;
  3148. ldap_resultentry *resultentry, *resultentry_next;
  3149. LDAPMessage *entry_next;
  3150. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rr", &link, &result_entry) != SUCCESS) {
  3151. return;
  3152. }
  3153. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3154. RETURN_FALSE;
  3155. }
  3156. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  3157. RETURN_FALSE;
  3158. }
  3159. if ((entry_next = ldap_next_reference(ld->link, resultentry->data)) == NULL) {
  3160. RETVAL_FALSE;
  3161. } else {
  3162. resultentry_next = emalloc(sizeof(ldap_resultentry));
  3163. RETVAL_RES(zend_register_resource(resultentry_next, le_result_entry));
  3164. ZVAL_COPY(&resultentry_next->res, &resultentry->res);
  3165. resultentry_next->data = entry_next;
  3166. resultentry_next->ber = NULL;
  3167. }
  3168. }
  3169. /* }}} */
  3170. #ifdef HAVE_LDAP_PARSE_REFERENCE
  3171. /* {{{ proto bool ldap_parse_reference(resource link, resource reference_entry, array referrals)
  3172. Extract information from reference entry */
  3173. PHP_FUNCTION(ldap_parse_reference)
  3174. {
  3175. zval *link, *result_entry, *referrals;
  3176. ldap_linkdata *ld;
  3177. ldap_resultentry *resultentry;
  3178. char **lreferrals, **refp;
  3179. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rrz/", &link, &result_entry, &referrals) != SUCCESS) {
  3180. return;
  3181. }
  3182. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3183. RETURN_FALSE;
  3184. }
  3185. if ((resultentry = (ldap_resultentry *)zend_fetch_resource(Z_RES_P(result_entry), "ldap result entry", le_result_entry)) == NULL) {
  3186. RETURN_FALSE;
  3187. }
  3188. if (ldap_parse_reference(ld->link, resultentry->data, &lreferrals, NULL /* &serverctrls */, 0) != LDAP_SUCCESS) {
  3189. RETURN_FALSE;
  3190. }
  3191. zval_ptr_dtor(referrals);
  3192. array_init(referrals);
  3193. if (lreferrals != NULL) {
  3194. refp = lreferrals;
  3195. while (*refp) {
  3196. add_next_index_string(referrals, *refp);
  3197. refp++;
  3198. }
  3199. ldap_memvfree((void**)lreferrals);
  3200. }
  3201. RETURN_TRUE;
  3202. }
  3203. /* }}} */
  3204. #endif
  3205. /* {{{ php_ldap_do_rename
  3206. */
  3207. static void php_ldap_do_rename(INTERNAL_FUNCTION_PARAMETERS, int ext)
  3208. {
  3209. zval *serverctrls = NULL;
  3210. zval *link;
  3211. ldap_linkdata *ld;
  3212. LDAPControl **lserverctrls = NULL;
  3213. LDAPMessage *ldap_res;
  3214. int rc, msgid;
  3215. char *dn, *newrdn, *newparent;
  3216. size_t dn_len, newrdn_len, newparent_len;
  3217. zend_bool deleteoldrdn;
  3218. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rsssb|a", &link, &dn, &dn_len, &newrdn, &newrdn_len, &newparent, &newparent_len, &deleteoldrdn, &serverctrls) != SUCCESS) {
  3219. return;
  3220. }
  3221. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3222. RETURN_FALSE;
  3223. }
  3224. if (newparent_len == 0) {
  3225. newparent = NULL;
  3226. }
  3227. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP
  3228. if (serverctrls) {
  3229. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  3230. if (lserverctrls == NULL) {
  3231. RETVAL_FALSE;
  3232. goto cleanup;
  3233. }
  3234. }
  3235. if (ext) {
  3236. rc = ldap_rename(ld->link, dn, newrdn, newparent, deleteoldrdn, lserverctrls, NULL, &msgid);
  3237. } else {
  3238. rc = ldap_rename_s(ld->link, dn, newrdn, newparent, deleteoldrdn, lserverctrls, NULL);
  3239. }
  3240. #else
  3241. if (newparent_len != 0) {
  3242. php_error_docref(NULL, E_WARNING, "You are using old LDAP API, newparent must be the empty string, can only modify RDN");
  3243. RETURN_FALSE;
  3244. }
  3245. if (serverctrls) {
  3246. php_error_docref(NULL, E_WARNING, "You are using old LDAP API, controls are not supported");
  3247. RETURN_FALSE;
  3248. }
  3249. if (ext) {
  3250. php_error_docref(NULL, E_WARNING, "You are using old LDAP API, ldap_rename_ext is not supported");
  3251. RETURN_FALSE;
  3252. }
  3253. /* could support old APIs but need check for ldap_modrdn2()/ldap_modrdn() */
  3254. rc = ldap_modrdn2_s(ld->link, dn, newrdn, deleteoldrdn);
  3255. #endif
  3256. if (rc != LDAP_SUCCESS) {
  3257. RETVAL_FALSE;
  3258. } else if (ext) {
  3259. rc = ldap_result(ld->link, msgid, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  3260. if (rc == -1) {
  3261. php_error_docref(NULL, E_WARNING, "Rename operation failed");
  3262. RETVAL_FALSE;
  3263. goto cleanup;
  3264. }
  3265. /* return a PHP control object */
  3266. RETVAL_RES(zend_register_resource(ldap_res, le_result));
  3267. } else {
  3268. RETVAL_TRUE;
  3269. }
  3270. cleanup:
  3271. if (lserverctrls) {
  3272. _php_ldap_controls_free(&lserverctrls);
  3273. }
  3274. return;
  3275. }
  3276. /* }}} */
  3277. /* {{{ proto bool ldap_rename(resource link, string dn, string newrdn, string newparent, bool deleteoldrdn [, array servercontrols])
  3278. Modify the name of an entry */
  3279. PHP_FUNCTION(ldap_rename)
  3280. {
  3281. php_ldap_do_rename(INTERNAL_FUNCTION_PARAM_PASSTHRU, 0);
  3282. }
  3283. /* }}} */
  3284. /* {{{ proto resource ldap_rename_ext(resource link, string dn, string newrdn, string newparent, bool deleteoldrdn [, array servercontrols])
  3285. Modify the name of an entry */
  3286. PHP_FUNCTION(ldap_rename_ext)
  3287. {
  3288. php_ldap_do_rename(INTERNAL_FUNCTION_PARAM_PASSTHRU, 1);
  3289. }
  3290. /* }}} */
  3291. #ifdef HAVE_LDAP_START_TLS_S
  3292. /* {{{ proto bool ldap_start_tls(resource link)
  3293. Start TLS */
  3294. PHP_FUNCTION(ldap_start_tls)
  3295. {
  3296. zval *link;
  3297. ldap_linkdata *ld;
  3298. int rc, protocol = LDAP_VERSION3;
  3299. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r", &link) != SUCCESS) {
  3300. return;
  3301. }
  3302. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3303. RETURN_FALSE;
  3304. }
  3305. if (((rc = ldap_set_option(ld->link, LDAP_OPT_PROTOCOL_VERSION, &protocol)) != LDAP_SUCCESS) ||
  3306. ((rc = ldap_start_tls_s(ld->link, NULL, NULL)) != LDAP_SUCCESS)
  3307. ) {
  3308. php_error_docref(NULL, E_WARNING,"Unable to start TLS: %s", ldap_err2string(rc));
  3309. RETURN_FALSE;
  3310. } else {
  3311. RETURN_TRUE;
  3312. }
  3313. }
  3314. /* }}} */
  3315. #endif
  3316. #endif /* (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP */
  3317. #if defined(LDAP_API_FEATURE_X_OPENLDAP) && defined(HAVE_3ARG_SETREBINDPROC)
  3318. /* {{{ _ldap_rebind_proc()
  3319. */
  3320. int _ldap_rebind_proc(LDAP *ldap, const char *url, ber_tag_t req, ber_int_t msgid, void *params)
  3321. {
  3322. ldap_linkdata *ld;
  3323. int retval;
  3324. zval cb_args[2];
  3325. zval cb_retval;
  3326. zval *cb_link = (zval *) params;
  3327. ld = (ldap_linkdata *) zend_fetch_resource_ex(cb_link, "ldap link", le_link);
  3328. /* link exists and callback set? */
  3329. if (ld == NULL || Z_ISUNDEF(ld->rebindproc)) {
  3330. php_error_docref(NULL, E_WARNING, "Link not found or no callback set");
  3331. return LDAP_OTHER;
  3332. }
  3333. /* callback */
  3334. ZVAL_COPY_VALUE(&cb_args[0], cb_link);
  3335. ZVAL_STRING(&cb_args[1], url);
  3336. if (call_user_function_ex(EG(function_table), NULL, &ld->rebindproc, &cb_retval, 2, cb_args, 0, NULL) == SUCCESS && !Z_ISUNDEF(cb_retval)) {
  3337. retval = zval_get_long(&cb_retval);
  3338. zval_ptr_dtor(&cb_retval);
  3339. } else {
  3340. php_error_docref(NULL, E_WARNING, "rebind_proc PHP callback failed");
  3341. retval = LDAP_OTHER;
  3342. }
  3343. zval_ptr_dtor(&cb_args[1]);
  3344. return retval;
  3345. }
  3346. /* }}} */
  3347. /* {{{ proto bool ldap_set_rebind_proc(resource link, string callback)
  3348. Set a callback function to do re-binds on referral chasing. */
  3349. PHP_FUNCTION(ldap_set_rebind_proc)
  3350. {
  3351. zval *link, *callback;
  3352. ldap_linkdata *ld;
  3353. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rz", &link, &callback) != SUCCESS) {
  3354. RETURN_FALSE;
  3355. }
  3356. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3357. RETURN_FALSE;
  3358. }
  3359. if (Z_TYPE_P(callback) == IS_STRING && Z_STRLEN_P(callback) == 0) {
  3360. /* unregister rebind procedure */
  3361. if (!Z_ISUNDEF(ld->rebindproc)) {
  3362. zval_ptr_dtor(&ld->rebindproc);
  3363. ZVAL_UNDEF(&ld->rebindproc);
  3364. ldap_set_rebind_proc(ld->link, NULL, NULL);
  3365. }
  3366. RETURN_TRUE;
  3367. }
  3368. /* callable? */
  3369. if (!zend_is_callable(callback, 0, NULL)) {
  3370. zend_string *callback_name = zend_get_callable_name(callback);
  3371. php_error_docref(NULL, E_WARNING, "Two arguments expected for '%s' to be a valid callback", ZSTR_VAL(callback_name));
  3372. zend_string_release_ex(callback_name, 0);
  3373. RETURN_FALSE;
  3374. }
  3375. /* register rebind procedure */
  3376. if (Z_ISUNDEF(ld->rebindproc)) {
  3377. ldap_set_rebind_proc(ld->link, _ldap_rebind_proc, (void *) link);
  3378. } else {
  3379. zval_ptr_dtor(&ld->rebindproc);
  3380. }
  3381. ZVAL_COPY(&ld->rebindproc, callback);
  3382. RETURN_TRUE;
  3383. }
  3384. /* }}} */
  3385. #endif
  3386. static zend_string* php_ldap_do_escape(const zend_bool *map, const char *value, size_t valuelen, zend_long flags)
  3387. {
  3388. char hex[] = "0123456789abcdef";
  3389. size_t i, p = 0;
  3390. size_t len = 0;
  3391. zend_string *ret;
  3392. for (i = 0; i < valuelen; i++) {
  3393. len += (map[(unsigned char) value[i]]) ? 3 : 1;
  3394. }
  3395. /* Per RFC 4514, a leading and trailing space must be escaped */
  3396. if ((flags & PHP_LDAP_ESCAPE_DN) && (value[0] == ' ')) {
  3397. len += 2;
  3398. }
  3399. if ((flags & PHP_LDAP_ESCAPE_DN) && ((valuelen > 1) && (value[valuelen - 1] == ' '))) {
  3400. len += 2;
  3401. }
  3402. ret = zend_string_alloc(len, 0);
  3403. for (i = 0; i < valuelen; i++) {
  3404. unsigned char v = (unsigned char) value[i];
  3405. if (map[v] || ((flags & PHP_LDAP_ESCAPE_DN) && ((i == 0) || (i + 1 == valuelen)) && (v == ' '))) {
  3406. ZSTR_VAL(ret)[p++] = '\\';
  3407. ZSTR_VAL(ret)[p++] = hex[v >> 4];
  3408. ZSTR_VAL(ret)[p++] = hex[v & 0x0f];
  3409. } else {
  3410. ZSTR_VAL(ret)[p++] = v;
  3411. }
  3412. }
  3413. ZSTR_VAL(ret)[p] = '\0';
  3414. ZSTR_LEN(ret) = p;
  3415. return ret;
  3416. }
  3417. static void php_ldap_escape_map_set_chars(zend_bool *map, const char *chars, const size_t charslen, char escape)
  3418. {
  3419. size_t i = 0;
  3420. while (i < charslen) {
  3421. map[(unsigned char) chars[i++]] = escape;
  3422. }
  3423. }
  3424. PHP_FUNCTION(ldap_escape)
  3425. {
  3426. char *value, *ignores;
  3427. size_t valuelen = 0, ignoreslen = 0;
  3428. int i;
  3429. zend_long flags = 0;
  3430. zend_bool map[256] = {0}, havecharlist = 0;
  3431. if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|sl", &value, &valuelen, &ignores, &ignoreslen, &flags) != SUCCESS) {
  3432. return;
  3433. }
  3434. if (!valuelen) {
  3435. RETURN_EMPTY_STRING();
  3436. }
  3437. if (flags & PHP_LDAP_ESCAPE_FILTER) {
  3438. havecharlist = 1;
  3439. php_ldap_escape_map_set_chars(map, "\\*()\0", sizeof("\\*()\0") - 1, 1);
  3440. }
  3441. if (flags & PHP_LDAP_ESCAPE_DN) {
  3442. havecharlist = 1;
  3443. php_ldap_escape_map_set_chars(map, "\\,=+<>;\"#\r", sizeof("\\,=+<>;\"#\r") - 1, 1);
  3444. }
  3445. if (!havecharlist) {
  3446. for (i = 0; i < 256; i++) {
  3447. map[i] = 1;
  3448. }
  3449. }
  3450. if (ignoreslen) {
  3451. php_ldap_escape_map_set_chars(map, ignores, ignoreslen, 0);
  3452. }
  3453. RETURN_NEW_STR(php_ldap_do_escape(map, value, valuelen, flags));
  3454. }
  3455. #ifdef STR_TRANSLATION
  3456. /* {{{ php_ldap_do_translate
  3457. */
  3458. static void php_ldap_do_translate(INTERNAL_FUNCTION_PARAMETERS, int way)
  3459. {
  3460. char *value;
  3461. size_t value_len;
  3462. int result;
  3463. if (zend_parse_parameters(ZEND_NUM_ARGS(), "s", &value, &value_len) != SUCCESS) {
  3464. return;
  3465. }
  3466. if (value_len == 0) {
  3467. RETURN_FALSE;
  3468. }
  3469. if (way == 1) {
  3470. result = ldap_8859_to_t61(&value, &value_len, 0);
  3471. } else {
  3472. result = ldap_t61_to_8859(&value, &value_len, 0);
  3473. }
  3474. if (result == LDAP_SUCCESS) {
  3475. RETVAL_STRINGL(value, value_len);
  3476. free(value);
  3477. } else {
  3478. php_error_docref(NULL, E_WARNING, "Conversion from iso-8859-1 to t61 failed: %s", ldap_err2string(result));
  3479. RETVAL_FALSE;
  3480. }
  3481. }
  3482. /* }}} */
  3483. /* {{{ proto string ldap_t61_to_8859(string value)
  3484. Translate t61 characters to 8859 characters */
  3485. PHP_FUNCTION(ldap_t61_to_8859)
  3486. {
  3487. php_ldap_do_translate(INTERNAL_FUNCTION_PARAM_PASSTHRU, 0);
  3488. }
  3489. /* }}} */
  3490. /* {{{ proto string ldap_8859_to_t61(string value)
  3491. Translate 8859 characters to t61 characters */
  3492. PHP_FUNCTION(ldap_8859_to_t61)
  3493. {
  3494. php_ldap_do_translate(INTERNAL_FUNCTION_PARAM_PASSTHRU, 1);
  3495. }
  3496. /* }}} */
  3497. #endif
  3498. #ifdef LDAP_CONTROL_PAGEDRESULTS
  3499. /* {{{ proto mixed ldap_control_paged_result(resource link, int pagesize [, bool iscritical [, string cookie]])
  3500. Inject paged results control*/
  3501. PHP_FUNCTION(ldap_control_paged_result)
  3502. {
  3503. zend_long pagesize;
  3504. zend_bool iscritical;
  3505. zval *link;
  3506. char *cookie = NULL;
  3507. size_t cookie_len = 0;
  3508. struct berval lcookie = { 0L, NULL };
  3509. ldap_linkdata *ld;
  3510. LDAP *ldap;
  3511. BerElement *ber = NULL;
  3512. LDAPControl ctrl, *ctrlsp[2];
  3513. int rc, myargcount = ZEND_NUM_ARGS();
  3514. if (zend_parse_parameters(myargcount, "rl|bs", &link, &pagesize, &iscritical, &cookie, &cookie_len) != SUCCESS) {
  3515. return;
  3516. }
  3517. if (Z_TYPE_P(link) == IS_NULL) {
  3518. ldap = NULL;
  3519. } else {
  3520. if ((ld = (ldap_linkdata *)zend_fetch_resource_ex(link, "ldap link", le_link)) == NULL) {
  3521. RETURN_FALSE;
  3522. }
  3523. ldap = ld->link;
  3524. }
  3525. ber = ber_alloc_t(LBER_USE_DER);
  3526. if (ber == NULL) {
  3527. php_error_docref(NULL, E_WARNING, "Unable to alloc BER encoding resources for paged results control");
  3528. RETURN_FALSE;
  3529. }
  3530. ctrl.ldctl_iscritical = 0;
  3531. switch (myargcount) {
  3532. case 4:
  3533. lcookie.bv_val = cookie;
  3534. lcookie.bv_len = cookie_len;
  3535. /* fallthru */
  3536. case 3:
  3537. ctrl.ldctl_iscritical = (int)iscritical;
  3538. /* fallthru */
  3539. }
  3540. if (ber_printf(ber, "{iO}", (int)pagesize, &lcookie) == LBER_ERROR) {
  3541. php_error_docref(NULL, E_WARNING, "Unable to BER printf paged results control");
  3542. RETVAL_FALSE;
  3543. goto lcpr_error_out;
  3544. }
  3545. rc = ber_flatten2(ber, &ctrl.ldctl_value, 0);
  3546. if (rc == LBER_ERROR) {
  3547. php_error_docref(NULL, E_WARNING, "Unable to BER encode paged results control");
  3548. RETVAL_FALSE;
  3549. goto lcpr_error_out;
  3550. }
  3551. ctrl.ldctl_oid = LDAP_CONTROL_PAGEDRESULTS;
  3552. if (ldap) {
  3553. /* directly set the option */
  3554. ctrlsp[0] = &ctrl;
  3555. ctrlsp[1] = NULL;
  3556. rc = ldap_set_option(ldap, LDAP_OPT_SERVER_CONTROLS, ctrlsp);
  3557. if (rc != LDAP_SUCCESS) {
  3558. php_error_docref(NULL, E_WARNING, "Unable to set paged results control: %s (%d)", ldap_err2string(rc), rc);
  3559. RETVAL_FALSE;
  3560. goto lcpr_error_out;
  3561. }
  3562. RETVAL_TRUE;
  3563. } else {
  3564. /* return a PHP control object */
  3565. array_init(return_value);
  3566. add_assoc_string(return_value, "oid", ctrl.ldctl_oid);
  3567. if (ctrl.ldctl_value.bv_len) {
  3568. add_assoc_stringl(return_value, "value", ctrl.ldctl_value.bv_val, ctrl.ldctl_value.bv_len);
  3569. }
  3570. if (ctrl.ldctl_iscritical) {
  3571. add_assoc_bool(return_value, "iscritical", ctrl.ldctl_iscritical);
  3572. }
  3573. }
  3574. lcpr_error_out:
  3575. if (ber != NULL) {
  3576. ber_free(ber, 1);
  3577. }
  3578. return;
  3579. }
  3580. /* }}} */
  3581. /* {{{ proto bool ldap_control_paged_result_response(resource link, resource result [, string &cookie [, int &estimated]])
  3582. Extract paged results control response */
  3583. PHP_FUNCTION(ldap_control_paged_result_response)
  3584. {
  3585. zval *link, *result, *cookie, *estimated;
  3586. struct berval lcookie;
  3587. int lestimated;
  3588. ldap_linkdata *ld;
  3589. LDAPMessage *ldap_result;
  3590. LDAPControl **lserverctrls, *lctrl;
  3591. BerElement *ber;
  3592. ber_tag_t tag;
  3593. int rc, lerrcode, myargcount = ZEND_NUM_ARGS();
  3594. if (zend_parse_parameters(myargcount, "rr|z/z/", &link, &result, &cookie, &estimated) != SUCCESS) {
  3595. return;
  3596. }
  3597. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3598. RETURN_FALSE;
  3599. }
  3600. if ((ldap_result = (LDAPMessage *)zend_fetch_resource(Z_RES_P(result), "ldap result", le_result)) == NULL) {
  3601. RETURN_FALSE;
  3602. }
  3603. rc = ldap_parse_result(ld->link,
  3604. ldap_result,
  3605. &lerrcode,
  3606. NULL, /* matcheddn */
  3607. NULL, /* errmsg */
  3608. NULL, /* referrals */
  3609. &lserverctrls,
  3610. 0);
  3611. if (rc != LDAP_SUCCESS) {
  3612. php_error_docref(NULL, E_WARNING, "Unable to parse result: %s (%d)", ldap_err2string(rc), rc);
  3613. RETURN_FALSE;
  3614. }
  3615. if (lerrcode != LDAP_SUCCESS) {
  3616. php_error_docref(NULL, E_WARNING, "Result is: %s (%d)", ldap_err2string(lerrcode), lerrcode);
  3617. RETURN_FALSE;
  3618. }
  3619. if (lserverctrls == NULL) {
  3620. php_error_docref(NULL, E_WARNING, "No server controls in result");
  3621. RETURN_FALSE;
  3622. }
  3623. lctrl = ldap_control_find(LDAP_CONTROL_PAGEDRESULTS, lserverctrls, NULL);
  3624. if (lctrl == NULL) {
  3625. ldap_controls_free(lserverctrls);
  3626. php_error_docref(NULL, E_WARNING, "No paged results control response in result");
  3627. RETURN_FALSE;
  3628. }
  3629. ber = ber_init(&lctrl->ldctl_value);
  3630. if (ber == NULL) {
  3631. ldap_controls_free(lserverctrls);
  3632. php_error_docref(NULL, E_WARNING, "Unable to alloc BER decoding resources for paged results control response");
  3633. RETURN_FALSE;
  3634. }
  3635. tag = ber_scanf(ber, "{io}", &lestimated, &lcookie);
  3636. (void)ber_free(ber, 1);
  3637. if (tag == LBER_ERROR) {
  3638. ldap_controls_free(lserverctrls);
  3639. php_error_docref(NULL, E_WARNING, "Unable to decode paged results control response");
  3640. RETURN_FALSE;
  3641. }
  3642. if (lestimated < 0) {
  3643. ldap_controls_free(lserverctrls);
  3644. php_error_docref(NULL, E_WARNING, "Invalid paged results control response value");
  3645. RETURN_FALSE;
  3646. }
  3647. ldap_controls_free(lserverctrls);
  3648. if (myargcount == 4) {
  3649. zval_ptr_dtor(estimated);
  3650. ZVAL_LONG(estimated, lestimated);
  3651. }
  3652. zval_ptr_dtor(cookie);
  3653. if (lcookie.bv_len == 0) {
  3654. ZVAL_EMPTY_STRING(cookie);
  3655. } else {
  3656. ZVAL_STRINGL(cookie, lcookie.bv_val, lcookie.bv_len);
  3657. }
  3658. ldap_memfree(lcookie.bv_val);
  3659. RETURN_TRUE;
  3660. }
  3661. /* }}} */
  3662. #endif
  3663. /* {{{ Extended operations, Pierangelo Masarati */
  3664. #ifdef HAVE_LDAP_EXTENDED_OPERATION_S
  3665. /* {{{ proto resource ldap_exop(resource link, string reqoid [, string reqdata [, array servercontrols [, string &retdata [, string &retoid]]]])
  3666. Extended operation */
  3667. PHP_FUNCTION(ldap_exop)
  3668. {
  3669. zval *serverctrls = NULL;
  3670. zval *link, *retdata = NULL, *retoid = NULL;
  3671. char *lretoid = NULL;
  3672. zend_string *reqoid, *reqdata = NULL;
  3673. struct berval lreqdata, *lretdata = NULL;
  3674. ldap_linkdata *ld;
  3675. LDAPMessage *ldap_res;
  3676. LDAPControl **lserverctrls = NULL;
  3677. int rc, msgid;
  3678. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rS|S!a!z/z/", &link, &reqoid, &reqdata, &serverctrls, &retdata, &retoid) != SUCCESS) {
  3679. return;
  3680. }
  3681. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3682. RETURN_FALSE;
  3683. }
  3684. if (reqdata) {
  3685. lreqdata.bv_val = ZSTR_VAL(reqdata);
  3686. lreqdata.bv_len = ZSTR_LEN(reqdata);
  3687. } else {
  3688. lreqdata.bv_len = 0;
  3689. }
  3690. if (serverctrls) {
  3691. lserverctrls = _php_ldap_controls_from_array(ld->link, serverctrls);
  3692. if (lserverctrls == NULL) {
  3693. RETVAL_FALSE;
  3694. goto cleanup;
  3695. }
  3696. }
  3697. if (retdata) {
  3698. /* synchronous call */
  3699. rc = ldap_extended_operation_s(ld->link, ZSTR_VAL(reqoid),
  3700. lreqdata.bv_len > 0 ? &lreqdata: NULL,
  3701. lserverctrls,
  3702. NULL,
  3703. retoid ? &lretoid : NULL,
  3704. &lretdata );
  3705. if (rc != LDAP_SUCCESS ) {
  3706. php_error_docref(NULL, E_WARNING, "Extended operation %s failed: %s (%d)", ZSTR_VAL(reqoid), ldap_err2string(rc), rc);
  3707. RETVAL_FALSE;
  3708. goto cleanup;
  3709. }
  3710. if (retoid) {
  3711. zval_ptr_dtor(retoid);
  3712. if (lretoid) {
  3713. ZVAL_STRING(retoid, lretoid);
  3714. ldap_memfree(lretoid);
  3715. } else {
  3716. ZVAL_EMPTY_STRING(retoid);
  3717. }
  3718. }
  3719. zval_ptr_dtor(retdata);
  3720. if (lretdata) {
  3721. ZVAL_STRINGL(retdata, lretdata->bv_val, lretdata->bv_len);
  3722. ldap_memfree(lretdata->bv_val);
  3723. ldap_memfree(lretdata);
  3724. } else {
  3725. ZVAL_EMPTY_STRING(retdata);
  3726. }
  3727. RETVAL_TRUE;
  3728. goto cleanup;
  3729. }
  3730. /* asynchronous call */
  3731. rc = ldap_extended_operation(ld->link, ZSTR_VAL(reqoid),
  3732. lreqdata.bv_len > 0 ? &lreqdata: NULL,
  3733. lserverctrls,
  3734. NULL,
  3735. &msgid);
  3736. if (rc != LDAP_SUCCESS ) {
  3737. php_error_docref(NULL, E_WARNING, "Extended operation %s failed: %s (%d)", ZSTR_VAL(reqoid), ldap_err2string(rc), rc);
  3738. RETVAL_FALSE;
  3739. goto cleanup;
  3740. }
  3741. rc = ldap_result(ld->link, msgid, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  3742. if (rc == -1) {
  3743. php_error_docref(NULL, E_WARNING, "Extended operation %s failed", ZSTR_VAL(reqoid));
  3744. RETVAL_FALSE;
  3745. goto cleanup;
  3746. }
  3747. /* return a PHP control object */
  3748. RETVAL_RES(zend_register_resource(ldap_res, le_result));
  3749. cleanup:
  3750. if (lserverctrls) {
  3751. _php_ldap_controls_free(&lserverctrls);
  3752. }
  3753. }
  3754. /* }}} */
  3755. #endif
  3756. #ifdef HAVE_LDAP_PASSWD
  3757. /* {{{ proto bool|string ldap_exop_passwd(resource link [, string user [, string oldpw [, string newpw [, array ctrls]]]])
  3758. Passwd modify extended operation */
  3759. PHP_FUNCTION(ldap_exop_passwd)
  3760. {
  3761. zval *link, *serverctrls;
  3762. struct berval luser = { 0L, NULL };
  3763. struct berval loldpw = { 0L, NULL };
  3764. struct berval lnewpw = { 0L, NULL };
  3765. struct berval lgenpasswd = { 0L, NULL };
  3766. LDAPControl *ctrl, **lserverctrls = NULL, *requestctrls[2] = { NULL, NULL };
  3767. LDAPMessage* ldap_res = NULL;
  3768. ldap_linkdata *ld;
  3769. int rc, myargcount = ZEND_NUM_ARGS(), msgid, err;
  3770. char* errmsg = NULL;
  3771. if (zend_parse_parameters(myargcount, "r|sssz/", &link, &luser.bv_val, &luser.bv_len, &loldpw.bv_val, &loldpw.bv_len, &lnewpw.bv_val, &lnewpw.bv_len, &serverctrls) == FAILURE) {
  3772. return;
  3773. }
  3774. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3775. RETVAL_FALSE;
  3776. goto cleanup;
  3777. }
  3778. switch (myargcount) {
  3779. case 5:
  3780. /* ldap_create_passwordpolicy_control() allocates ctrl */
  3781. if (ldap_create_passwordpolicy_control(ld->link, &ctrl) == LDAP_SUCCESS) {
  3782. requestctrls[0] = ctrl;
  3783. }
  3784. }
  3785. /* asynchronous call to get result and controls */
  3786. rc = ldap_passwd(ld->link, &luser,
  3787. loldpw.bv_len > 0 ? &loldpw : NULL,
  3788. lnewpw.bv_len > 0 ? &lnewpw : NULL,
  3789. requestctrls,
  3790. NULL, &msgid);
  3791. if (requestctrls[0] != NULL) {
  3792. ldap_control_free(requestctrls[0]);
  3793. }
  3794. if (rc != LDAP_SUCCESS ) {
  3795. php_error_docref(NULL, E_WARNING, "Passwd modify extended operation failed: %s (%d)", ldap_err2string(rc), rc);
  3796. RETVAL_FALSE;
  3797. goto cleanup;
  3798. }
  3799. rc = ldap_result(ld->link, msgid, 1 /* LDAP_MSG_ALL */, NULL, &ldap_res);
  3800. if ((rc < 0) || !ldap_res) {
  3801. rc = _get_lderrno(ld->link);
  3802. php_error_docref(NULL, E_WARNING, "Passwd modify extended operation failed: %s (%d)", ldap_err2string(rc), rc);
  3803. RETVAL_FALSE;
  3804. goto cleanup;
  3805. }
  3806. rc = ldap_parse_passwd(ld->link, ldap_res, &lgenpasswd);
  3807. if( rc != LDAP_SUCCESS ) {
  3808. php_error_docref(NULL, E_WARNING, "Passwd modify extended operation failed: %s (%d)", ldap_err2string(rc), rc);
  3809. RETVAL_FALSE;
  3810. goto cleanup;
  3811. }
  3812. rc = ldap_parse_result(ld->link, ldap_res, &err, NULL, &errmsg, NULL, (myargcount > 4 ? &lserverctrls : NULL), 0);
  3813. if( rc != LDAP_SUCCESS ) {
  3814. php_error_docref(NULL, E_WARNING, "Passwd modify extended operation failed: %s (%d)", ldap_err2string(rc), rc);
  3815. RETVAL_FALSE;
  3816. goto cleanup;
  3817. }
  3818. if (myargcount > 4) {
  3819. zval_ptr_dtor(serverctrls);
  3820. _php_ldap_controls_to_array(ld->link, lserverctrls, serverctrls, 0);
  3821. }
  3822. /* return */
  3823. if (lnewpw.bv_len == 0) {
  3824. if (lgenpasswd.bv_len == 0) {
  3825. RETVAL_EMPTY_STRING();
  3826. } else {
  3827. RETVAL_STRINGL(lgenpasswd.bv_val, lgenpasswd.bv_len);
  3828. }
  3829. } else if (err == LDAP_SUCCESS) {
  3830. RETVAL_TRUE;
  3831. } else {
  3832. php_error_docref(NULL, E_WARNING, "Passwd modify extended operation failed: %s (%d)", (errmsg ? errmsg : ldap_err2string(err)), err);
  3833. RETVAL_FALSE;
  3834. }
  3835. cleanup:
  3836. if (lgenpasswd.bv_val != NULL) {
  3837. ldap_memfree(lgenpasswd.bv_val);
  3838. }
  3839. if (ldap_res != NULL) {
  3840. ldap_msgfree(ldap_res);
  3841. }
  3842. if (errmsg != NULL) {
  3843. ldap_memfree(errmsg);
  3844. }
  3845. }
  3846. /* }}} */
  3847. #endif
  3848. #ifdef HAVE_LDAP_WHOAMI_S
  3849. /* {{{ proto bool|string ldap_exop_whoami(resource link)
  3850. Whoami extended operation */
  3851. PHP_FUNCTION(ldap_exop_whoami)
  3852. {
  3853. zval *link;
  3854. struct berval *lauthzid;
  3855. ldap_linkdata *ld;
  3856. int rc;
  3857. if (zend_parse_parameters(ZEND_NUM_ARGS(), "r", &link) == FAILURE) {
  3858. WRONG_PARAM_COUNT;
  3859. }
  3860. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3861. RETURN_FALSE;
  3862. }
  3863. /* synchronous call */
  3864. rc = ldap_whoami_s(ld->link, &lauthzid, NULL, NULL);
  3865. if (rc != LDAP_SUCCESS ) {
  3866. php_error_docref(NULL, E_WARNING, "Whoami extended operation failed: %s (%d)", ldap_err2string(rc), rc);
  3867. RETURN_FALSE;
  3868. }
  3869. if (lauthzid == NULL) {
  3870. RETVAL_EMPTY_STRING();
  3871. } else {
  3872. RETVAL_STRINGL(lauthzid->bv_val, lauthzid->bv_len);
  3873. ldap_memfree(lauthzid->bv_val);
  3874. ldap_memfree(lauthzid);
  3875. }
  3876. }
  3877. /* }}} */
  3878. #endif
  3879. #ifdef HAVE_LDAP_REFRESH_S
  3880. /* {{{ proto bool|int ldap_exop_refresh(resource link , string dn , int ttl)
  3881. DDS refresh extended operation */
  3882. PHP_FUNCTION(ldap_exop_refresh)
  3883. {
  3884. zval *link, *ttl;
  3885. struct berval ldn;
  3886. ber_int_t lttl;
  3887. ber_int_t newttl;
  3888. ldap_linkdata *ld;
  3889. int rc;
  3890. if (zend_parse_parameters(ZEND_NUM_ARGS(), "rsz", &link, &ldn.bv_val, &ldn.bv_len, &ttl) != SUCCESS) {
  3891. WRONG_PARAM_COUNT;
  3892. }
  3893. if ((ld = (ldap_linkdata *)zend_fetch_resource(Z_RES_P(link), "ldap link", le_link)) == NULL) {
  3894. RETURN_FALSE;
  3895. }
  3896. lttl = (ber_int_t)zval_get_long(ttl);
  3897. rc = ldap_refresh_s(ld->link, &ldn, lttl, &newttl, NULL, NULL);
  3898. if (rc != LDAP_SUCCESS ) {
  3899. php_error_docref(NULL, E_WARNING, "Refresh extended operation failed: %s (%d)", ldap_err2string(rc), rc);
  3900. RETURN_FALSE;
  3901. }
  3902. RETURN_LONG(newttl);
  3903. }
  3904. /* }}} */
  3905. #endif
  3906. /* }}} */
  3907. /* {{{ arginfo */
  3908. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_connect, 0, 0, 0)
  3909. ZEND_ARG_INFO(0, hostname)
  3910. ZEND_ARG_INFO(0, port)
  3911. #ifdef HAVE_ORALDAP
  3912. ZEND_ARG_INFO(0, wallet)
  3913. ZEND_ARG_INFO(0, wallet_passwd)
  3914. ZEND_ARG_INFO(0, authmode)
  3915. #endif
  3916. ZEND_END_ARG_INFO()
  3917. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_resource, 0, 0, 1)
  3918. ZEND_ARG_INFO(0, link_identifier)
  3919. ZEND_END_ARG_INFO()
  3920. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_bind, 0, 0, 1)
  3921. ZEND_ARG_INFO(0, link_identifier)
  3922. ZEND_ARG_INFO(0, bind_rdn)
  3923. ZEND_ARG_INFO(0, bind_password)
  3924. ZEND_END_ARG_INFO()
  3925. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_bind_ext, 0, 0, 1)
  3926. ZEND_ARG_INFO(0, link_identifier)
  3927. ZEND_ARG_INFO(0, bind_rdn)
  3928. ZEND_ARG_INFO(0, bind_password)
  3929. ZEND_ARG_INFO(0, servercontrols)
  3930. ZEND_END_ARG_INFO()
  3931. #ifdef HAVE_LDAP_SASL
  3932. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_sasl_bind, 0, 0, 1)
  3933. ZEND_ARG_INFO(0, link)
  3934. ZEND_ARG_INFO(0, binddn)
  3935. ZEND_ARG_INFO(0, password)
  3936. ZEND_ARG_INFO(0, sasl_mech)
  3937. ZEND_ARG_INFO(0, sasl_realm)
  3938. ZEND_ARG_INFO(0, sasl_authz_id)
  3939. ZEND_ARG_INFO(0, props)
  3940. ZEND_END_ARG_INFO()
  3941. #endif
  3942. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_read, 0, 0, 3)
  3943. ZEND_ARG_INFO(0, link_identifier)
  3944. ZEND_ARG_INFO(0, base_dn)
  3945. ZEND_ARG_INFO(0, filter)
  3946. ZEND_ARG_INFO(0, attributes)
  3947. ZEND_ARG_INFO(0, attrsonly)
  3948. ZEND_ARG_INFO(0, sizelimit)
  3949. ZEND_ARG_INFO(0, timelimit)
  3950. ZEND_ARG_INFO(0, deref)
  3951. ZEND_ARG_INFO(0, servercontrols)
  3952. ZEND_END_ARG_INFO()
  3953. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_list, 0, 0, 3)
  3954. ZEND_ARG_INFO(0, link_identifier)
  3955. ZEND_ARG_INFO(0, base_dn)
  3956. ZEND_ARG_INFO(0, filter)
  3957. ZEND_ARG_INFO(0, attributes)
  3958. ZEND_ARG_INFO(0, attrsonly)
  3959. ZEND_ARG_INFO(0, sizelimit)
  3960. ZEND_ARG_INFO(0, timelimit)
  3961. ZEND_ARG_INFO(0, deref)
  3962. ZEND_ARG_INFO(0, servercontrols)
  3963. ZEND_END_ARG_INFO()
  3964. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_search, 0, 0, 3)
  3965. ZEND_ARG_INFO(0, link_identifier)
  3966. ZEND_ARG_INFO(0, base_dn)
  3967. ZEND_ARG_INFO(0, filter)
  3968. ZEND_ARG_INFO(0, attributes)
  3969. ZEND_ARG_INFO(0, attrsonly)
  3970. ZEND_ARG_INFO(0, sizelimit)
  3971. ZEND_ARG_INFO(0, timelimit)
  3972. ZEND_ARG_INFO(0, deref)
  3973. ZEND_ARG_INFO(0, servercontrols)
  3974. ZEND_END_ARG_INFO()
  3975. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_count_entries, 0, 0, 2)
  3976. ZEND_ARG_INFO(0, link_identifier)
  3977. ZEND_ARG_INFO(0, result_identifier)
  3978. ZEND_END_ARG_INFO()
  3979. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_first_entry, 0, 0, 2)
  3980. ZEND_ARG_INFO(0, link_identifier)
  3981. ZEND_ARG_INFO(0, result_identifier)
  3982. ZEND_END_ARG_INFO()
  3983. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_next_entry, 0, 0, 2)
  3984. ZEND_ARG_INFO(0, link_identifier)
  3985. ZEND_ARG_INFO(0, result_identifier)
  3986. ZEND_END_ARG_INFO()
  3987. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_get_entries, 0, 0, 2)
  3988. ZEND_ARG_INFO(0, link_identifier)
  3989. ZEND_ARG_INFO(0, result_identifier)
  3990. ZEND_END_ARG_INFO()
  3991. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_first_attribute, 0, 0, 2)
  3992. ZEND_ARG_INFO(0, link_identifier)
  3993. ZEND_ARG_INFO(0, result_entry_identifier)
  3994. ZEND_END_ARG_INFO()
  3995. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_next_attribute, 0, 0, 2)
  3996. ZEND_ARG_INFO(0, link_identifier)
  3997. ZEND_ARG_INFO(0, result_entry_identifier)
  3998. ZEND_END_ARG_INFO()
  3999. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_get_attributes, 0, 0, 2)
  4000. ZEND_ARG_INFO(0, link_identifier)
  4001. ZEND_ARG_INFO(0, result_entry_identifier)
  4002. ZEND_END_ARG_INFO()
  4003. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_get_values, 0, 0, 3)
  4004. ZEND_ARG_INFO(0, link_identifier)
  4005. ZEND_ARG_INFO(0, result_entry_identifier)
  4006. ZEND_ARG_INFO(0, attribute)
  4007. ZEND_END_ARG_INFO()
  4008. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_get_values_len, 0, 0, 3)
  4009. ZEND_ARG_INFO(0, link_identifier)
  4010. ZEND_ARG_INFO(0, result_entry_identifier)
  4011. ZEND_ARG_INFO(0, attribute)
  4012. ZEND_END_ARG_INFO()
  4013. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_get_dn, 0, 0, 2)
  4014. ZEND_ARG_INFO(0, link_identifier)
  4015. ZEND_ARG_INFO(0, result_entry_identifier)
  4016. ZEND_END_ARG_INFO()
  4017. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_explode_dn, 0, 0, 2)
  4018. ZEND_ARG_INFO(0, dn)
  4019. ZEND_ARG_INFO(0, with_attrib)
  4020. ZEND_END_ARG_INFO()
  4021. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_dn2ufn, 0, 0, 1)
  4022. ZEND_ARG_INFO(0, dn)
  4023. ZEND_END_ARG_INFO()
  4024. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_add, 0, 0, 3)
  4025. ZEND_ARG_INFO(0, link_identifier)
  4026. ZEND_ARG_INFO(0, dn)
  4027. ZEND_ARG_INFO(0, entry)
  4028. ZEND_ARG_INFO(0, servercontrols)
  4029. ZEND_END_ARG_INFO()
  4030. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_add_ext, 0, 0, 3)
  4031. ZEND_ARG_INFO(0, link_identifier)
  4032. ZEND_ARG_INFO(0, dn)
  4033. ZEND_ARG_INFO(0, entry)
  4034. ZEND_ARG_INFO(0, servercontrols)
  4035. ZEND_END_ARG_INFO()
  4036. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_delete, 0, 0, 2)
  4037. ZEND_ARG_INFO(0, link_identifier)
  4038. ZEND_ARG_INFO(0, dn)
  4039. ZEND_ARG_INFO(0, servercontrols)
  4040. ZEND_END_ARG_INFO()
  4041. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_delete_ext, 0, 0, 2)
  4042. ZEND_ARG_INFO(0, link_identifier)
  4043. ZEND_ARG_INFO(0, dn)
  4044. ZEND_ARG_INFO(0, servercontrols)
  4045. ZEND_END_ARG_INFO()
  4046. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_modify, 0, 0, 3)
  4047. ZEND_ARG_INFO(0, link_identifier)
  4048. ZEND_ARG_INFO(0, dn)
  4049. ZEND_ARG_INFO(0, entry)
  4050. ZEND_ARG_INFO(0, servercontrols)
  4051. ZEND_END_ARG_INFO()
  4052. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_modify_batch, 0, 0, 3)
  4053. ZEND_ARG_INFO(0, link_identifier)
  4054. ZEND_ARG_INFO(0, dn)
  4055. ZEND_ARG_ARRAY_INFO(0, modifications_info, 0)
  4056. ZEND_ARG_INFO(0, servercontrols)
  4057. ZEND_END_ARG_INFO()
  4058. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_mod_add, 0, 0, 3)
  4059. ZEND_ARG_INFO(0, link_identifier)
  4060. ZEND_ARG_INFO(0, dn)
  4061. ZEND_ARG_INFO(0, entry)
  4062. ZEND_ARG_INFO(0, servercontrols)
  4063. ZEND_END_ARG_INFO()
  4064. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_mod_add_ext, 0, 0, 3)
  4065. ZEND_ARG_INFO(0, link_identifier)
  4066. ZEND_ARG_INFO(0, dn)
  4067. ZEND_ARG_INFO(0, entry)
  4068. ZEND_ARG_INFO(0, servercontrols)
  4069. ZEND_END_ARG_INFO()
  4070. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_mod_replace, 0, 0, 3)
  4071. ZEND_ARG_INFO(0, link_identifier)
  4072. ZEND_ARG_INFO(0, dn)
  4073. ZEND_ARG_INFO(0, entry)
  4074. ZEND_ARG_INFO(0, servercontrols)
  4075. ZEND_END_ARG_INFO()
  4076. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_mod_replace_ext, 0, 0, 3)
  4077. ZEND_ARG_INFO(0, link_identifier)
  4078. ZEND_ARG_INFO(0, dn)
  4079. ZEND_ARG_INFO(0, entry)
  4080. ZEND_ARG_INFO(0, servercontrols)
  4081. ZEND_END_ARG_INFO()
  4082. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_mod_del, 0, 0, 3)
  4083. ZEND_ARG_INFO(0, link_identifier)
  4084. ZEND_ARG_INFO(0, dn)
  4085. ZEND_ARG_INFO(0, entry)
  4086. ZEND_ARG_INFO(0, servercontrols)
  4087. ZEND_END_ARG_INFO()
  4088. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_mod_del_ext, 0, 0, 3)
  4089. ZEND_ARG_INFO(0, link_identifier)
  4090. ZEND_ARG_INFO(0, dn)
  4091. ZEND_ARG_INFO(0, entry)
  4092. ZEND_ARG_INFO(0, servercontrols)
  4093. ZEND_END_ARG_INFO()
  4094. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_err2str, 0, 0, 1)
  4095. ZEND_ARG_INFO(0, errno)
  4096. ZEND_END_ARG_INFO()
  4097. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_compare, 0, 0, 4)
  4098. ZEND_ARG_INFO(0, link_identifier)
  4099. ZEND_ARG_INFO(0, dn)
  4100. ZEND_ARG_INFO(0, attribute)
  4101. ZEND_ARG_INFO(0, value)
  4102. ZEND_ARG_INFO(0, servercontrols)
  4103. ZEND_END_ARG_INFO()
  4104. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_sort, 0, 0, 3)
  4105. ZEND_ARG_INFO(0, link)
  4106. ZEND_ARG_INFO(0, result)
  4107. ZEND_ARG_INFO(0, sortfilter)
  4108. ZEND_END_ARG_INFO()
  4109. #ifdef LDAP_CONTROL_PAGEDRESULTS
  4110. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_control_paged_result, 0, 0, 2)
  4111. ZEND_ARG_INFO(0, link)
  4112. ZEND_ARG_INFO(0, pagesize)
  4113. ZEND_ARG_INFO(0, iscritical)
  4114. ZEND_ARG_INFO(0, cookie)
  4115. ZEND_END_ARG_INFO();
  4116. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_control_paged_result_response, 0, 0, 2)
  4117. ZEND_ARG_INFO(0, link)
  4118. ZEND_ARG_INFO(0, result)
  4119. ZEND_ARG_INFO(1, cookie)
  4120. ZEND_ARG_INFO(1, estimated)
  4121. ZEND_END_ARG_INFO();
  4122. #endif
  4123. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP
  4124. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_rename, 0, 0, 5)
  4125. ZEND_ARG_INFO(0, link_identifier)
  4126. ZEND_ARG_INFO(0, dn)
  4127. ZEND_ARG_INFO(0, newrdn)
  4128. ZEND_ARG_INFO(0, newparent)
  4129. ZEND_ARG_INFO(0, deleteoldrdn)
  4130. ZEND_ARG_INFO(0, servercontrols)
  4131. ZEND_END_ARG_INFO()
  4132. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_rename_ext, 0, 0, 5)
  4133. ZEND_ARG_INFO(0, link_identifier)
  4134. ZEND_ARG_INFO(0, dn)
  4135. ZEND_ARG_INFO(0, newrdn)
  4136. ZEND_ARG_INFO(0, newparent)
  4137. ZEND_ARG_INFO(0, deleteoldrdn)
  4138. ZEND_ARG_INFO(0, servercontrols)
  4139. ZEND_END_ARG_INFO()
  4140. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_get_option, 0, 0, 3)
  4141. ZEND_ARG_INFO(0, link_identifier)
  4142. ZEND_ARG_INFO(0, option)
  4143. ZEND_ARG_INFO(1, retval)
  4144. ZEND_END_ARG_INFO()
  4145. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_set_option, 0, 0, 3)
  4146. ZEND_ARG_INFO(0, link_identifier)
  4147. ZEND_ARG_INFO(0, option)
  4148. ZEND_ARG_INFO(0, newval)
  4149. ZEND_END_ARG_INFO()
  4150. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_first_reference, 0, 0, 2)
  4151. ZEND_ARG_INFO(0, link)
  4152. ZEND_ARG_INFO(0, result)
  4153. ZEND_END_ARG_INFO()
  4154. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_next_reference, 0, 0, 2)
  4155. ZEND_ARG_INFO(0, link)
  4156. ZEND_ARG_INFO(0, entry)
  4157. ZEND_END_ARG_INFO()
  4158. #ifdef HAVE_LDAP_PARSE_REFERENCE
  4159. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_parse_reference, 0, 0, 3)
  4160. ZEND_ARG_INFO(0, link)
  4161. ZEND_ARG_INFO(0, entry)
  4162. ZEND_ARG_INFO(1, referrals)
  4163. ZEND_END_ARG_INFO()
  4164. #endif
  4165. #ifdef HAVE_LDAP_PARSE_RESULT
  4166. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_parse_result, 0, 0, 3)
  4167. ZEND_ARG_INFO(0, link)
  4168. ZEND_ARG_INFO(0, result)
  4169. ZEND_ARG_INFO(1, errcode)
  4170. ZEND_ARG_INFO(1, matcheddn)
  4171. ZEND_ARG_INFO(1, errmsg)
  4172. ZEND_ARG_INFO(1, referrals)
  4173. ZEND_ARG_INFO(1, serverctrls)
  4174. ZEND_END_ARG_INFO()
  4175. #endif
  4176. #endif
  4177. #if defined(LDAP_API_FEATURE_X_OPENLDAP) && defined(HAVE_3ARG_SETREBINDPROC)
  4178. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_set_rebind_proc, 0, 0, 2)
  4179. ZEND_ARG_INFO(0, link)
  4180. ZEND_ARG_INFO(0, callback)
  4181. ZEND_END_ARG_INFO()
  4182. #endif
  4183. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_escape, 0, 0, 1)
  4184. ZEND_ARG_INFO(0, value)
  4185. ZEND_ARG_INFO(0, ignore)
  4186. ZEND_ARG_INFO(0, flags)
  4187. ZEND_END_ARG_INFO()
  4188. #ifdef STR_TRANSLATION
  4189. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_t61_to_8859, 0, 0, 1)
  4190. ZEND_ARG_INFO(0, value)
  4191. ZEND_END_ARG_INFO()
  4192. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_8859_to_t61, 0, 0, 1)
  4193. ZEND_ARG_INFO(0, value)
  4194. ZEND_END_ARG_INFO()
  4195. #endif
  4196. #ifdef HAVE_LDAP_EXTENDED_OPERATION_S
  4197. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_exop, 0, 0, 2)
  4198. ZEND_ARG_INFO(0, link)
  4199. ZEND_ARG_INFO(0, reqoid)
  4200. ZEND_ARG_INFO(0, reqdata)
  4201. ZEND_ARG_INFO(0, servercontrols)
  4202. ZEND_ARG_INFO(1, retdata)
  4203. ZEND_ARG_INFO(1, retoid)
  4204. ZEND_END_ARG_INFO()
  4205. #endif
  4206. #ifdef HAVE_LDAP_PASSWD
  4207. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_exop_passwd, 0, 0, 1)
  4208. ZEND_ARG_INFO(0, link)
  4209. ZEND_ARG_INFO(0, user)
  4210. ZEND_ARG_INFO(0, oldpw)
  4211. ZEND_ARG_INFO(0, newpw)
  4212. ZEND_ARG_INFO(1, serverctrls)
  4213. ZEND_END_ARG_INFO()
  4214. #endif
  4215. #ifdef HAVE_LDAP_WHOAMI_S
  4216. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_exop_whoami, 0, 0, 1)
  4217. ZEND_ARG_INFO(0, link)
  4218. ZEND_END_ARG_INFO()
  4219. #endif
  4220. #ifdef HAVE_LDAP_REFRESH_S
  4221. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_exop_refresh, 0, 0, 3)
  4222. ZEND_ARG_INFO(0, link)
  4223. ZEND_ARG_INFO(0, dn)
  4224. ZEND_ARG_INFO(0, ttl)
  4225. ZEND_END_ARG_INFO()
  4226. #endif
  4227. #ifdef HAVE_LDAP_PARSE_EXTENDED_RESULT
  4228. ZEND_BEGIN_ARG_INFO_EX(arginfo_ldap_parse_exop, 0, 0, 4)
  4229. ZEND_ARG_INFO(0, link)
  4230. ZEND_ARG_INFO(0, result)
  4231. ZEND_ARG_INFO(1, retdata)
  4232. ZEND_ARG_INFO(1, retoid)
  4233. ZEND_END_ARG_INFO()
  4234. #endif
  4235. /* }}} */
  4236. /*
  4237. This is just a small subset of the functionality provided by the LDAP library. All the
  4238. operations are synchronous. Referrals are not handled automatically.
  4239. */
  4240. /* {{{ ldap_functions[]
  4241. */
  4242. static const zend_function_entry ldap_functions[] = {
  4243. PHP_FE(ldap_connect, arginfo_ldap_connect)
  4244. PHP_FALIAS(ldap_close, ldap_unbind, arginfo_ldap_resource)
  4245. PHP_FE(ldap_bind, arginfo_ldap_bind)
  4246. PHP_FE(ldap_bind_ext, arginfo_ldap_bind_ext)
  4247. #ifdef HAVE_LDAP_SASL
  4248. PHP_FE(ldap_sasl_bind, arginfo_ldap_sasl_bind)
  4249. #endif
  4250. PHP_FE(ldap_unbind, arginfo_ldap_resource)
  4251. PHP_FE(ldap_read, arginfo_ldap_read)
  4252. PHP_FE(ldap_list, arginfo_ldap_list)
  4253. PHP_FE(ldap_search, arginfo_ldap_search)
  4254. PHP_FE(ldap_free_result, arginfo_ldap_resource)
  4255. PHP_FE(ldap_count_entries, arginfo_ldap_count_entries)
  4256. PHP_FE(ldap_first_entry, arginfo_ldap_first_entry)
  4257. PHP_FE(ldap_next_entry, arginfo_ldap_next_entry)
  4258. PHP_FE(ldap_get_entries, arginfo_ldap_get_entries)
  4259. PHP_FE(ldap_first_attribute, arginfo_ldap_first_attribute)
  4260. PHP_FE(ldap_next_attribute, arginfo_ldap_next_attribute)
  4261. PHP_FE(ldap_get_attributes, arginfo_ldap_get_attributes)
  4262. PHP_FALIAS(ldap_get_values, ldap_get_values_len, arginfo_ldap_get_values)
  4263. PHP_FE(ldap_get_values_len, arginfo_ldap_get_values_len)
  4264. PHP_FE(ldap_get_dn, arginfo_ldap_get_dn)
  4265. PHP_FE(ldap_explode_dn, arginfo_ldap_explode_dn)
  4266. PHP_FE(ldap_dn2ufn, arginfo_ldap_dn2ufn)
  4267. PHP_FE(ldap_add, arginfo_ldap_add)
  4268. PHP_FE(ldap_add_ext, arginfo_ldap_add_ext)
  4269. PHP_FE(ldap_delete, arginfo_ldap_delete)
  4270. PHP_FE(ldap_delete_ext, arginfo_ldap_delete_ext)
  4271. PHP_FE(ldap_modify_batch, arginfo_ldap_modify_batch)
  4272. PHP_FALIAS(ldap_modify, ldap_mod_replace, arginfo_ldap_modify)
  4273. /* additional functions for attribute based modifications, Gerrit Thomson */
  4274. PHP_FE(ldap_mod_add, arginfo_ldap_mod_add)
  4275. PHP_FE(ldap_mod_add_ext, arginfo_ldap_mod_add_ext)
  4276. PHP_FE(ldap_mod_replace, arginfo_ldap_mod_replace)
  4277. PHP_FE(ldap_mod_replace_ext, arginfo_ldap_mod_replace_ext)
  4278. PHP_FE(ldap_mod_del, arginfo_ldap_mod_del)
  4279. PHP_FE(ldap_mod_del_ext, arginfo_ldap_mod_del_ext)
  4280. /* end gjt mod */
  4281. PHP_FE(ldap_errno, arginfo_ldap_resource)
  4282. PHP_FE(ldap_err2str, arginfo_ldap_err2str)
  4283. PHP_FE(ldap_error, arginfo_ldap_resource)
  4284. PHP_FE(ldap_compare, arginfo_ldap_compare)
  4285. PHP_DEP_FE(ldap_sort, arginfo_ldap_sort)
  4286. #if (LDAP_API_VERSION > 2000) || HAVE_NSLDAP || HAVE_ORALDAP
  4287. PHP_FE(ldap_rename, arginfo_ldap_rename)
  4288. PHP_FE(ldap_rename_ext, arginfo_ldap_rename_ext)
  4289. PHP_FE(ldap_get_option, arginfo_ldap_get_option)
  4290. PHP_FE(ldap_set_option, arginfo_ldap_set_option)
  4291. PHP_FE(ldap_first_reference, arginfo_ldap_first_reference)
  4292. PHP_FE(ldap_next_reference, arginfo_ldap_next_reference)
  4293. #ifdef HAVE_LDAP_PARSE_REFERENCE
  4294. PHP_FE(ldap_parse_reference, arginfo_ldap_parse_reference)
  4295. #endif
  4296. #ifdef HAVE_LDAP_PARSE_RESULT
  4297. PHP_FE(ldap_parse_result, arginfo_ldap_parse_result)
  4298. #endif
  4299. #ifdef HAVE_LDAP_START_TLS_S
  4300. PHP_FE(ldap_start_tls, arginfo_ldap_resource)
  4301. #endif
  4302. #ifdef HAVE_LDAP_EXTENDED_OPERATION_S
  4303. PHP_FE(ldap_exop, arginfo_ldap_exop)
  4304. #endif
  4305. #ifdef HAVE_LDAP_PASSWD
  4306. PHP_FE(ldap_exop_passwd, arginfo_ldap_exop_passwd)
  4307. #endif
  4308. #ifdef HAVE_LDAP_WHOAMI_S
  4309. PHP_FE(ldap_exop_whoami, arginfo_ldap_exop_whoami)
  4310. #endif
  4311. #ifdef HAVE_LDAP_REFRESH_S
  4312. PHP_FE(ldap_exop_refresh, arginfo_ldap_exop_refresh)
  4313. #endif
  4314. #ifdef HAVE_LDAP_PARSE_EXTENDED_RESULT
  4315. PHP_FE(ldap_parse_exop, arginfo_ldap_parse_exop)
  4316. #endif
  4317. #endif
  4318. #if defined(LDAP_API_FEATURE_X_OPENLDAP) && defined(HAVE_3ARG_SETREBINDPROC)
  4319. PHP_FE(ldap_set_rebind_proc, arginfo_ldap_set_rebind_proc)
  4320. #endif
  4321. PHP_FE(ldap_escape, arginfo_ldap_escape)
  4322. #ifdef STR_TRANSLATION
  4323. PHP_FE(ldap_t61_to_8859, arginfo_ldap_t61_to_8859)
  4324. PHP_FE(ldap_8859_to_t61, arginfo_ldap_8859_to_t61)
  4325. #endif
  4326. #ifdef LDAP_CONTROL_PAGEDRESULTS
  4327. PHP_FE(ldap_control_paged_result, arginfo_ldap_control_paged_result)
  4328. PHP_FE(ldap_control_paged_result_response, arginfo_ldap_control_paged_result_response)
  4329. #endif
  4330. PHP_FE_END
  4331. };
  4332. /* }}} */
  4333. zend_module_entry ldap_module_entry = { /* {{{ */
  4334. STANDARD_MODULE_HEADER,
  4335. "ldap",
  4336. ldap_functions,
  4337. PHP_MINIT(ldap),
  4338. PHP_MSHUTDOWN(ldap),
  4339. NULL,
  4340. NULL,
  4341. PHP_MINFO(ldap),
  4342. PHP_LDAP_VERSION,
  4343. PHP_MODULE_GLOBALS(ldap),
  4344. PHP_GINIT(ldap),
  4345. NULL,
  4346. NULL,
  4347. STANDARD_MODULE_PROPERTIES_EX
  4348. };
  4349. /* }}} */
  4350. /*
  4351. * Local variables:
  4352. * tab-width: 4
  4353. * c-basic-offset: 4
  4354. * End:
  4355. * vim600: sw=4 ts=4 fdm=marker
  4356. * vim<600: sw=4 ts=4
  4357. */