From 3aba0d9aa64e821aa6fa9e77d037544c64dc74b4 Mon Sep 17 00:00:00 2001 From: Lukas Wagner Date: Tue, 28 Mar 2023 16:20:14 +0200 Subject: [PATCH] api-types: ldap: add verification regex for LDAP DNs Regex was taken from the LDAP implementation in PVE. Signed-off-by: Lukas Wagner --- pbs-api-types/src/ldap.rs | 33 ++++++++++++++++++++++++++++++++- 1 file changed, 32 insertions(+), 1 deletion(-) diff --git a/pbs-api-types/src/ldap.rs b/pbs-api-types/src/ldap.rs index 316b5a65..eabc5249 100644 --- a/pbs-api-types/src/ldap.rs +++ b/pbs-api-types/src/ldap.rs @@ -1,6 +1,8 @@ use serde::{Deserialize, Serialize}; -use proxmox_schema::{api, ApiStringFormat, ApiType, ArraySchema, Schema, StringSchema, Updater}; +use proxmox_schema::{ + api, const_regex, ApiStringFormat, ApiType, ArraySchema, Schema, StringSchema, Updater, +}; use super::{REALM_ID_SCHEMA, SINGLE_LINE_COMMENT_SCHEMA}; @@ -45,6 +47,13 @@ pub enum LdapMode { optional: true, schema: USER_CLASSES_SCHEMA, }, + "base-dn" : { + schema: LDAP_DOMAIN_SCHEMA, + }, + "bind-dn" : { + schema: LDAP_DOMAIN_SCHEMA, + optional: true, + } }, )] #[derive(Serialize, Deserialize, Updater, Clone)] @@ -133,6 +142,28 @@ pub enum RemoveVanished { Properties, } +macro_rules! DOMAIN_PART_REGEX { + () => { + r#"("[^"]+"|[^ ,+"/<>;=#][^,+"/<>;=]*[^ ,+"/<>;=]|[^ ,+"/<>;=#])"# + }; +} + +const_regex! { + pub LDAP_DOMAIN_REGEX = concat!( + r#"\w+="#, + DOMAIN_PART_REGEX!(), + r#"(,\s*\w+="#, + DOMAIN_PART_REGEX!(), + ")*" + ); +} + +pub const LDAP_DOMAIN_FORMAT: ApiStringFormat = ApiStringFormat::Pattern(&LDAP_DOMAIN_REGEX); + +pub const LDAP_DOMAIN_SCHEMA: Schema = StringSchema::new("LDAP Domain") + .format(&LDAP_DOMAIN_FORMAT) + .schema(); + pub const SYNC_DEFAULTS_STRING_SCHEMA: Schema = StringSchema::new("sync defaults options") .format(&ApiStringFormat::PropertyString( &SyncDefaultsOptions::API_SCHEMA,