2023-06-18 17:29:49 +00:00
|
|
|
use dotenv::dotenv;
|
2023-06-18 16:19:59 +00:00
|
|
|
use ldap3::{LdapConn, Mod};
|
2023-06-18 17:34:27 +00:00
|
|
|
use skynet_ldap_server::{get_config, Config};
|
|
|
|
use std::env;
|
2023-06-18 16:19:59 +00:00
|
|
|
|
|
|
|
#[async_std::main]
|
|
|
|
async fn main() -> tide::Result<()> {
|
|
|
|
let config = get_config();
|
|
|
|
|
|
|
|
//update_users(&config).await;
|
|
|
|
update_admin(&config).await?;
|
2023-06-18 17:34:27 +00:00
|
|
|
|
2023-06-18 16:19:59 +00:00
|
|
|
Ok(())
|
|
|
|
}
|
|
|
|
|
|
|
|
//async fn update_users(config: &Config) {
|
2023-06-18 17:34:27 +00:00
|
|
|
|
2023-06-18 16:19:59 +00:00
|
|
|
//}
|
2023-06-18 17:34:27 +00:00
|
|
|
fn uid_to_dn(uid: &str) -> String {
|
2023-06-18 16:19:59 +00:00
|
|
|
format!("uid={},ou=users,dc=skynet,dc=ie", uid)
|
|
|
|
}
|
|
|
|
|
2023-06-18 17:34:27 +00:00
|
|
|
async fn update_admin(config: &Config) -> tide::Result<()> {
|
2023-06-18 17:29:49 +00:00
|
|
|
dotenv().ok();
|
2023-06-18 17:34:27 +00:00
|
|
|
|
2023-06-18 17:29:49 +00:00
|
|
|
// read from teh env
|
|
|
|
if let Ok(x) = env::var("USERS_ADMIN") {
|
|
|
|
let users = x.split(',').collect::<Vec<&str>>();
|
2023-06-18 17:34:27 +00:00
|
|
|
|
|
|
|
update_group(config, "skynet-admins", &users, true).await?;
|
2023-06-18 17:29:49 +00:00
|
|
|
// admins automatically get added as users
|
2023-06-18 17:34:27 +00:00
|
|
|
update_group(config, "skynet-users", &users, false).await?;
|
2023-06-18 17:29:49 +00:00
|
|
|
}
|
2023-06-18 16:33:39 +00:00
|
|
|
Ok(())
|
|
|
|
}
|
|
|
|
|
2023-06-18 17:34:27 +00:00
|
|
|
async fn update_group(config: &Config, group: &str, users: &[&str], replace: bool) -> tide::Result<()> {
|
2023-06-18 16:19:59 +00:00
|
|
|
let mut ldap = LdapConn::new(&config.ldap_host)?;
|
|
|
|
|
|
|
|
// use the admin account
|
|
|
|
ldap.simple_bind(&config.ldap_admin, &config.ldap_admin_pw)?.success()?;
|
2023-06-18 16:33:39 +00:00
|
|
|
|
2023-06-18 17:32:52 +00:00
|
|
|
let dn = format!("cn={},ou=groups,dc=skynet,dc=ie", group);
|
2023-06-18 17:34:27 +00:00
|
|
|
let members = users.iter().map(|uid| uid_to_dn(uid)).collect();
|
2023-06-18 16:45:33 +00:00
|
|
|
let mods = if replace {
|
2023-06-18 17:32:52 +00:00
|
|
|
vec![Mod::Replace("member".to_string(), members)]
|
2023-06-18 16:45:33 +00:00
|
|
|
} else {
|
2023-06-18 17:32:52 +00:00
|
|
|
vec![Mod::Add("member".to_string(), members)]
|
2023-06-18 16:45:33 +00:00
|
|
|
};
|
2023-06-18 17:34:27 +00:00
|
|
|
|
2023-06-18 17:32:52 +00:00
|
|
|
if let Err(x) = ldap.modify(&dn, mods) {
|
2023-06-18 16:45:33 +00:00
|
|
|
println!("{:?}", x);
|
|
|
|
}
|
2023-06-18 16:33:39 +00:00
|
|
|
|
2023-06-18 17:32:52 +00:00
|
|
|
let dn_linux = format!("cn={}-linux,ou=groups,dc=skynet,dc=ie", group);
|
2023-06-18 17:34:27 +00:00
|
|
|
let members_linux = users.iter().map(|uid| uid.to_string()).collect();
|
2023-06-18 16:45:33 +00:00
|
|
|
let mods = if replace {
|
2023-06-18 17:32:52 +00:00
|
|
|
vec![Mod::Replace("memberUid".to_string(), members_linux)]
|
2023-06-18 16:45:33 +00:00
|
|
|
} else {
|
2023-06-18 17:32:52 +00:00
|
|
|
vec![Mod::Add("memberUid".to_string(), members_linux)]
|
2023-06-18 16:45:33 +00:00
|
|
|
};
|
2023-06-18 17:34:27 +00:00
|
|
|
if let Err(x) = ldap.modify(&dn_linux, mods) {
|
2023-06-18 16:45:33 +00:00
|
|
|
println!("{:?}", x);
|
|
|
|
};
|
2023-06-18 16:19:59 +00:00
|
|
|
|
2023-06-18 17:32:52 +00:00
|
|
|
// tidy up
|
2023-06-18 16:19:59 +00:00
|
|
|
ldap.unbind()?;
|
2023-06-18 16:33:39 +00:00
|
|
|
|
2023-06-18 16:19:59 +00:00
|
|
|
Ok(())
|
2023-06-18 17:34:27 +00:00
|
|
|
}
|