mirror of
https://git.openldap.org/openldap/openldap.git
synced 2025-12-22 23:59:34 -05:00
Now related ITSes need be audited and possibly closed.
Enhancements:
- re-styled code for better readability
- upgraded backend API to reflect recent changes
- LDAP schema is checked when loading SQL/LDAP mapping
- AttributeDescription/ObjectClass pointers used for more efficient
mapping lookup
- bervals used where string length is required often
- atomized write operations by committing at the end of each operation
and defaulting connection closure to rollback
- added LDAP access control to write operations
- fully implemented modrdn (with rdn attrs change, deleteoldrdn,
access check, parent/children check and more)
- added parent access control, children control to delete operation
- added structuralObjectClass operational attribute check and
value return on search
- added hasSubordinate operational attribute on demand
- search limits are appropriately enforced
- function backsql_strcat() has been made more efficient
- concat function has been made configurable by means of a pattern
- added config switches:
- fail_if_no_mapping write operations fail if there is no mapping
- has_ldapinfo_dn_ru overrides autodetect
- concat_pattern a string containing two '?' is used
(note that "?||?" should be more portable
than builtin function "CONCAT(?,?)")
- strcast_func cast of string constants in "SELECT DISTINCT statements (needed by PostgreSQL)
- upper_needs_cast cast the argument of upper when required
(basically when building dn substring queries)
Todo:
- add security checks for SQL statements that can be injected (?)
- re-test with previously supported RDBMs
- replace dn_ru and so with normalized dn (no need for upper() and so
in dn match)
- implement a backsql_normalize() function to replace the upper()
conversion routines
- note that subtree deletion, subtree renaming and so could be easily
implemented (rollback and consistency checks are available :)
- implement "lastmod" and other operational stuff (ldap_entries table ?)
66 lines
1.4 KiB
SQL
66 lines
1.4 KiB
SQL
drop table ldap_oc_mappings;
|
|
create table ldap_oc_mappings
|
|
(
|
|
id integer not null primary key,
|
|
name varchar(64) not null,
|
|
keytbl varchar(64) not null,
|
|
keycol varchar(64) not null,
|
|
create_proc varchar(255),
|
|
create_keyval varchar(255),
|
|
delete_proc varchar(255),
|
|
expect_return integer not null
|
|
);
|
|
|
|
drop table ldap_attr_mappings;
|
|
create table ldap_attr_mappings
|
|
(
|
|
id integer not null primary key,
|
|
oc_map_id integer not null references ldap_oc_mappings(id),
|
|
name varchar(255) not null,
|
|
sel_expr varchar(255) not null,
|
|
sel_expr_u varchar(255),
|
|
from_tbls varchar(255) not null,
|
|
join_where varchar(255),
|
|
add_proc varchar(255),
|
|
delete_proc varchar(255),
|
|
param_order integer not null,
|
|
expect_return integer not null
|
|
);
|
|
|
|
drop table ldap_entries;
|
|
create table ldap_entries
|
|
(
|
|
id integer not null primary key,
|
|
dn varchar(255) not null,
|
|
oc_map_id integer not null references ldap_oc_mappings(id),
|
|
parent int NOT NULL ,
|
|
keyval int NOT NULL
|
|
);
|
|
|
|
alter table ldap_entries add
|
|
constraint unq1_ldap_entries unique
|
|
(
|
|
oc_map_id,
|
|
keyval
|
|
);
|
|
|
|
alter table ldap_entries add
|
|
constraint unq2_ldap_entries unique
|
|
(
|
|
dn
|
|
);
|
|
|
|
drop table ldap_referrals;
|
|
create table ldap_referrals
|
|
(
|
|
entry_id integer not null references ldap_entries(id),
|
|
url varchar(256) not null
|
|
);
|
|
|
|
drop table ldap_entry_objclasses;
|
|
create table ldap_entry_objclasses
|
|
(
|
|
entry_id integer not null references ldap_entries(id),
|
|
oc_name varchar(64)
|
|
);
|
|
|