You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 

293 regels
14 KiB

  1. """
  2. """
  3. # Created on 2016.08.31
  4. #
  5. # Author: Giovanni Cannata
  6. #
  7. # Copyright 2013 - 2018 Giovanni Cannata
  8. #
  9. # This file is part of ldap3.
  10. #
  11. # ldap3 is free software: you can redistribute it and/or modify
  12. # it under the terms of the GNU Lesser General Public License as published
  13. # by the Free Software Foundation, either version 3 of the License, or
  14. # (at your option) any later version.
  15. #
  16. # ldap3 is distributed in the hope that it will be useful,
  17. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  18. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  19. # GNU Lesser General Public License for more details.
  20. #
  21. # You should have received a copy of the GNU Lesser General Public License
  22. # along with ldap3 in the COPYING and COPYING.LESSER files.
  23. # If not, see <http://www.gnu.org/licenses/>.
  24. from sys import stdin, getdefaultencoding
  25. from .. import ALL_ATTRIBUTES, ALL_OPERATIONAL_ATTRIBUTES, NO_ATTRIBUTES, SEQUENCE_TYPES
  26. from ..core.exceptions import LDAPConfigurationParameterError
  27. # checks
  28. _CLASSES_EXCLUDED_FROM_CHECK = ['subschema']
  29. _ATTRIBUTES_EXCLUDED_FROM_CHECK = [ALL_ATTRIBUTES,
  30. ALL_OPERATIONAL_ATTRIBUTES,
  31. NO_ATTRIBUTES,
  32. 'ldapSyntaxes',
  33. 'matchingRules',
  34. 'matchingRuleUse',
  35. 'dITContentRules',
  36. 'dITStructureRules',
  37. 'nameForms',
  38. 'altServer',
  39. 'namingContexts',
  40. 'supportedControl',
  41. 'supportedExtension',
  42. 'supportedFeatures',
  43. 'supportedCapabilities',
  44. 'supportedLdapVersion',
  45. 'supportedSASLMechanisms',
  46. 'vendorName',
  47. 'vendorVersion',
  48. 'subschemaSubentry',
  49. 'ACL']
  50. _UTF8_ENCODED_SYNTAXES = ['1.2.840.113556.1.4.904', # DN String [MICROSOFT]
  51. '1.2.840.113556.1.4.1362', # String (Case) [MICROSOFT]
  52. '1.3.6.1.4.1.1466.115.121.1.12', # DN String [RFC4517]
  53. '1.3.6.1.4.1.1466.115.121.1.15', # Directory String [RFC4517]
  54. '1.3.6.1.4.1.1466.115.121.1.41', # Postal Address) [RFC4517]
  55. '1.3.6.1.4.1.1466.115.121.1.58', # Substring Assertion [RFC4517]
  56. '2.16.840.1.113719.1.1.5.1.6', # Case Ignore List [NOVELL]
  57. '2.16.840.1.113719.1.1.5.1.14', # Tagged String [NOVELL]
  58. '2.16.840.1.113719.1.1.5.1.15', # Tagged Name and String [NOVELL]
  59. '2.16.840.1.113719.1.1.5.1.23', # Tagged Name [NOVELL]
  60. '2.16.840.1.113719.1.1.5.1.25'] # Typed Name [NOVELL]
  61. _UTF8_ENCODED_TYPES = []
  62. _ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF = ['msds-memberOfTransitive', 'msds-memberTransitive', 'entryDN']
  63. _IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF = ['instanceType', 'nTSecurityDescriptor', 'objectCategory']
  64. _CASE_INSENSITIVE_ATTRIBUTE_NAMES = True
  65. _CASE_INSENSITIVE_SCHEMA_NAMES = True
  66. # abstraction layer
  67. _ABSTRACTION_OPERATIONAL_ATTRIBUTE_PREFIX = 'OA_'
  68. # communication
  69. _POOLING_LOOP_TIMEOUT = 10 # number of seconds to wait before restarting a cycle to find an active server in the pool
  70. _RESPONSE_SLEEPTIME = 0.05 # seconds to wait while waiting for a response in asynchronous strategies
  71. _RESPONSE_WAITING_TIMEOUT = 3 # waiting timeout for receiving a response in asynchronous strategies
  72. _SOCKET_SIZE = 4096 # socket byte size
  73. _CHECK_AVAILABILITY_TIMEOUT = 2.5 # default timeout for socket connect when checking availability
  74. _RESET_AVAILABILITY_TIMEOUT = 5 # default timeout for resetting the availability status when checking candidate addresses
  75. _RESTARTABLE_SLEEPTIME = 2 # time to wait in a restartable strategy before retrying the request
  76. _RESTARTABLE_TRIES = 30 # number of times to retry in a restartable strategy before giving up. Set to True for unlimited retries
  77. _REUSABLE_THREADED_POOL_SIZE = 5
  78. _REUSABLE_THREADED_LIFETIME = 3600 # 1 hour
  79. _DEFAULT_THREADED_POOL_NAME = 'REUSABLE_DEFAULT_POOL'
  80. _ADDRESS_INFO_REFRESH_TIME = 300 # seconds to wait before refreshing address info from dns
  81. _ADDITIONAL_SERVER_ENCODINGS = ['latin-1', 'koi8-r'] # some broken LDAP implementation may have different encoding than those expected by RFCs
  82. _ADDITIONAL_CLIENT_ENCODINGS = ['utf-8']
  83. _IGNORE_MALFORMED_SCHEMA = False # some flaky LDAP servers returns malformed schema. If True no expection is raised and schema is thrown away
  84. _DEFAULT_SERVER_ENCODING = 'utf-8' # should always be utf-8
  85. if stdin and hasattr(stdin, 'encoding') and stdin.encoding:
  86. _DEFAULT_CLIENT_ENCODING = stdin.encoding
  87. elif getdefaultencoding():
  88. _DEFAULT_CLIENT_ENCODING = getdefaultencoding()
  89. else:
  90. _DEFAULT_CLIENT_ENCODING = 'utf-8'
  91. PARAMETERS = ['CASE_INSENSITIVE_ATTRIBUTE_NAMES',
  92. 'CASE_INSENSITIVE_SCHEMA_NAMES',
  93. 'ABSTRACTION_OPERATIONAL_ATTRIBUTE_PREFIX',
  94. 'POOLING_LOOP_TIMEOUT',
  95. 'RESPONSE_SLEEPTIME',
  96. 'RESPONSE_WAITING_TIMEOUT',
  97. 'SOCKET_SIZE',
  98. 'CHECK_AVAILABILITY_TIMEOUT',
  99. 'RESTARTABLE_SLEEPTIME',
  100. 'RESTARTABLE_TRIES',
  101. 'REUSABLE_THREADED_POOL_SIZE',
  102. 'REUSABLE_THREADED_LIFETIME',
  103. 'DEFAULT_THREADED_POOL_NAME',
  104. 'ADDRESS_INFO_REFRESH_TIME',
  105. 'RESET_AVAILABILITY_TIMEOUT',
  106. 'DEFAULT_CLIENT_ENCODING',
  107. 'DEFAULT_SERVER_ENCODING',
  108. 'CLASSES_EXCLUDED_FROM_CHECK',
  109. 'ATTRIBUTES_EXCLUDED_FROM_CHECK',
  110. 'UTF8_ENCODED_SYNTAXES',
  111. 'UTF8_ENCODED_TYPES',
  112. 'ADDITIONAL_SERVER_ENCODINGS',
  113. 'ADDITIONAL_CLIENT_ENCODINGS',
  114. 'IGNORE_MALFORMED_SCHEMA',
  115. 'ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF',
  116. 'IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF'
  117. ]
  118. def get_config_parameter(parameter):
  119. if parameter == 'CASE_INSENSITIVE_ATTRIBUTE_NAMES': # Boolean
  120. return _CASE_INSENSITIVE_ATTRIBUTE_NAMES
  121. elif parameter == 'CASE_INSENSITIVE_SCHEMA_NAMES': # Boolean
  122. return _CASE_INSENSITIVE_SCHEMA_NAMES
  123. elif parameter == 'ABSTRACTION_OPERATIONAL_ATTRIBUTE_PREFIX': # String
  124. return _ABSTRACTION_OPERATIONAL_ATTRIBUTE_PREFIX
  125. elif parameter == 'POOLING_LOOP_TIMEOUT': # Integer
  126. return _POOLING_LOOP_TIMEOUT
  127. elif parameter == 'RESPONSE_SLEEPTIME': # Integer
  128. return _RESPONSE_SLEEPTIME
  129. elif parameter == 'RESPONSE_WAITING_TIMEOUT': # Integer
  130. return _RESPONSE_WAITING_TIMEOUT
  131. elif parameter == 'SOCKET_SIZE': # Integer
  132. return _SOCKET_SIZE
  133. elif parameter == 'CHECK_AVAILABILITY_TIMEOUT': # Integer
  134. return _CHECK_AVAILABILITY_TIMEOUT
  135. elif parameter == 'RESTARTABLE_SLEEPTIME': # Integer
  136. return _RESTARTABLE_SLEEPTIME
  137. elif parameter == 'RESTARTABLE_TRIES': # Integer
  138. return _RESTARTABLE_TRIES
  139. elif parameter == 'REUSABLE_THREADED_POOL_SIZE': # Integer
  140. return _REUSABLE_THREADED_POOL_SIZE
  141. elif parameter == 'REUSABLE_THREADED_LIFETIME': # Integer
  142. return _REUSABLE_THREADED_LIFETIME
  143. elif parameter == 'DEFAULT_THREADED_POOL_NAME': # String
  144. return _DEFAULT_THREADED_POOL_NAME
  145. elif parameter == 'ADDRESS_INFO_REFRESH_TIME': # Integer
  146. return _ADDRESS_INFO_REFRESH_TIME
  147. elif parameter == 'RESET_AVAILABILITY_TIMEOUT': # Integer
  148. return _RESET_AVAILABILITY_TIMEOUT
  149. elif parameter in ['DEFAULT_CLIENT_ENCODING', 'DEFAULT_ENCODING']: # String - DEFAULT_ENCODING for backward compatibility
  150. return _DEFAULT_CLIENT_ENCODING
  151. elif parameter == 'DEFAULT_SERVER_ENCODING': # String
  152. return _DEFAULT_SERVER_ENCODING
  153. elif parameter == 'CLASSES_EXCLUDED_FROM_CHECK': # Sequence
  154. if isinstance(_CLASSES_EXCLUDED_FROM_CHECK, SEQUENCE_TYPES):
  155. return _CLASSES_EXCLUDED_FROM_CHECK
  156. else:
  157. return [_CLASSES_EXCLUDED_FROM_CHECK]
  158. elif parameter == 'ATTRIBUTES_EXCLUDED_FROM_CHECK': # Sequence
  159. if isinstance(_ATTRIBUTES_EXCLUDED_FROM_CHECK, SEQUENCE_TYPES):
  160. return _ATTRIBUTES_EXCLUDED_FROM_CHECK
  161. else:
  162. return [_ATTRIBUTES_EXCLUDED_FROM_CHECK]
  163. elif parameter == 'UTF8_ENCODED_SYNTAXES': # Sequence
  164. if isinstance(_UTF8_ENCODED_SYNTAXES, SEQUENCE_TYPES):
  165. return _UTF8_ENCODED_SYNTAXES
  166. else:
  167. return [_UTF8_ENCODED_SYNTAXES]
  168. elif parameter == 'UTF8_ENCODED_TYPES': # Sequence
  169. if isinstance(_UTF8_ENCODED_TYPES, SEQUENCE_TYPES):
  170. return _UTF8_ENCODED_TYPES
  171. else:
  172. return [_UTF8_ENCODED_TYPES]
  173. elif parameter in ['ADDITIONAL_SERVER_ENCODINGS', 'ADDITIONAL_ENCODINGS']: # Sequence - ADDITIONAL_ENCODINGS for backward compatibility
  174. if isinstance(_ADDITIONAL_SERVER_ENCODINGS, SEQUENCE_TYPES):
  175. return _ADDITIONAL_SERVER_ENCODINGS
  176. else:
  177. return [_ADDITIONAL_SERVER_ENCODINGS]
  178. elif parameter in ['ADDITIONAL_CLIENT_ENCODINGS']: # Sequence
  179. if isinstance(_ADDITIONAL_CLIENT_ENCODINGS, SEQUENCE_TYPES):
  180. return _ADDITIONAL_CLIENT_ENCODINGS
  181. else:
  182. return [_ADDITIONAL_CLIENT_ENCODINGS]
  183. elif parameter == 'IGNORE_MALFORMED_SCHEMA': # Boolean
  184. return _IGNORE_MALFORMED_SCHEMA
  185. elif parameter == 'ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF': # Sequence
  186. if isinstance(_ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF, SEQUENCE_TYPES):
  187. return _ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF
  188. else:
  189. return [_ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF]
  190. elif parameter == 'IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF': # Sequence
  191. if isinstance(_IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF, SEQUENCE_TYPES):
  192. return _IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF
  193. else:
  194. return [_IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF]
  195. raise LDAPConfigurationParameterError('configuration parameter %s not valid' % parameter)
  196. def set_config_parameter(parameter, value):
  197. if parameter == 'CASE_INSENSITIVE_ATTRIBUTE_NAMES':
  198. global _CASE_INSENSITIVE_ATTRIBUTE_NAMES
  199. _CASE_INSENSITIVE_ATTRIBUTE_NAMES = value
  200. elif parameter == 'CASE_INSENSITIVE_SCHEMA_NAMES':
  201. global _CASE_INSENSITIVE_SCHEMA_NAMES
  202. _CASE_INSENSITIVE_SCHEMA_NAMES = value
  203. elif parameter == 'ABSTRACTION_OPERATIONAL_ATTRIBUTE_PREFIX':
  204. global _ABSTRACTION_OPERATIONAL_ATTRIBUTE_PREFIX
  205. _ABSTRACTION_OPERATIONAL_ATTRIBUTE_PREFIX = value
  206. elif parameter == 'POOLING_LOOP_TIMEOUT':
  207. global _POOLING_LOOP_TIMEOUT
  208. _POOLING_LOOP_TIMEOUT = value
  209. elif parameter == 'RESPONSE_SLEEPTIME':
  210. global _RESPONSE_SLEEPTIME
  211. _RESPONSE_SLEEPTIME = value
  212. elif parameter == 'RESPONSE_WAITING_TIMEOUT':
  213. global _RESPONSE_WAITING_TIMEOUT
  214. _RESPONSE_WAITING_TIMEOUT = value
  215. elif parameter == 'SOCKET_SIZE':
  216. global _SOCKET_SIZE
  217. _SOCKET_SIZE = value
  218. elif parameter == 'CHECK_AVAILABILITY_TIMEOUT':
  219. global _CHECK_AVAILABILITY_TIMEOUT
  220. _CHECK_AVAILABILITY_TIMEOUT = value
  221. elif parameter == 'RESTARTABLE_SLEEPTIME':
  222. global _RESTARTABLE_SLEEPTIME
  223. _RESTARTABLE_SLEEPTIME = value
  224. elif parameter == 'RESTARTABLE_TRIES':
  225. global _RESTARTABLE_TRIES
  226. _RESTARTABLE_TRIES = value
  227. elif parameter == 'REUSABLE_THREADED_POOL_SIZE':
  228. global _REUSABLE_THREADED_POOL_SIZE
  229. _REUSABLE_THREADED_POOL_SIZE = value
  230. elif parameter == 'REUSABLE_THREADED_LIFETIME':
  231. global _REUSABLE_THREADED_LIFETIME
  232. _REUSABLE_THREADED_LIFETIME = value
  233. elif parameter == 'DEFAULT_THREADED_POOL_NAME':
  234. global _DEFAULT_THREADED_POOL_NAME
  235. _DEFAULT_THREADED_POOL_NAME = value
  236. elif parameter == 'ADDRESS_INFO_REFRESH_TIME':
  237. global _ADDRESS_INFO_REFRESH_TIME
  238. _ADDRESS_INFO_REFRESH_TIME = value
  239. elif parameter == 'RESET_AVAILABILITY_TIMEOUT':
  240. global _RESET_AVAILABILITY_TIMEOUT
  241. _RESET_AVAILABILITY_TIMEOUT = value
  242. elif parameter in ['DEFAULT_CLIENT_ENCODING', 'DEFAULT_ENCODING']:
  243. global _DEFAULT_CLIENT_ENCODING
  244. _DEFAULT_CLIENT_ENCODING = value
  245. elif parameter == 'DEFAULT_SERVER_ENCODING':
  246. global _DEFAULT_SERVER_ENCODING
  247. _DEFAULT_SERVER_ENCODING = value
  248. elif parameter == 'CLASSES_EXCLUDED_FROM_CHECK':
  249. global _CLASSES_EXCLUDED_FROM_CHECK
  250. _CLASSES_EXCLUDED_FROM_CHECK = value
  251. elif parameter == 'ATTRIBUTES_EXCLUDED_FROM_CHECK':
  252. global _ATTRIBUTES_EXCLUDED_FROM_CHECK
  253. _ATTRIBUTES_EXCLUDED_FROM_CHECK = value
  254. elif parameter == 'UTF8_ENCODED_SYNTAXES':
  255. global _UTF8_ENCODED_SYNTAXES
  256. _UTF8_ENCODED_SYNTAXES = value
  257. elif parameter == 'UTF8_ENCODED_TYPES':
  258. global _UTF8_ENCODED_TYPES
  259. _UTF8_ENCODED_TYPES = value
  260. elif parameter in ['ADDITIONAL_SERVER_ENCODINGS', 'ADDITIONAL_ENCODINGS']:
  261. global _ADDITIONAL_SERVER_ENCODINGS
  262. _ADDITIONAL_SERVER_ENCODINGS = value if isinstance(value, SEQUENCE_TYPES) else [value]
  263. elif parameter in ['ADDITIONAL_CLIENT_ENCODINGS']:
  264. global _ADDITIONAL_CLIENT_ENCODINGS
  265. _ADDITIONAL_CLIENT_ENCODINGS = value if isinstance(value, SEQUENCE_TYPES) else [value]
  266. elif parameter == 'IGNORE_MALFORMED_SCHEMA':
  267. global _IGNORE_MALFORMED_SCHEMA
  268. _IGNORE_MALFORMED_SCHEMA = value
  269. elif parameter == 'ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF':
  270. global _ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF
  271. _ATTRIBUTES_EXCLUDED_FROM_OBJECT_DEF = value
  272. elif parameter == 'IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF':
  273. global _IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF
  274. _IGNORED_MANDATORY_ATTRIBUTES_IN_OBJECT_DEF = value
  275. else:
  276. raise LDAPConfigurationParameterError('unable to set configuration parameter %s' % parameter)