mirror of
https://github.com/nabbar/golib.git
synced 2025-12-24 11:51:02 +08:00
Global Repos / Workflow - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - UPDATE workflow: split old workflow into multiple files - UPDATE .gitignore: added cluster.old.tar.gz and build artifacts - UPDATE .golangci.yml: enhanced linter rules and disabled deprecated linters [archive] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - FIX extract: recursive decompression for nested archives (e.g., .tar.gz handling) - FIX extract: ZIP archive support now properly uses ReaderAt interface with seek reset - ADD extract: proper symlink and hard link handling in archives - UPDATE tar/writer: improved error handling and file mode preservation - UPDATE zip/writer: enhanced validation and error messages - UPDATE compress/interface: added support for additional compression formats - UPDATE helper/compressor: fixed typo in error handling [artifact] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE artifact: improved error handling and context management - UPDATE client/interface: enhanced API with better type safety and context propagation - UPDATE client/model: refactored for better maintainability - UPDATE github: removed unused error codes, improved model validation - UPDATE gitlab: enhanced API pagination and error handling - UPDATE jfrog: improved artifactory API compatibility - UPDATE s3aws: enhanced S3 bucket operations and error messages [atomic] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE cast: improved type conversion with better error handling - UPDATE interface: enhanced atomic operations with generics support - UPDATE synmap: fixed race conditions in concurrent access patterns - UPDATE value: improved atomic value operations with better memory ordering [aws] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE bucket: enhanced ACL and CORS configuration with validation - UPDATE configAws/models: improved credential handling and region configuration - UPDATE configCustom/interface: added support for custom endpoints - UPDATE http/request: improved retry logic and timeout handling - UPDATE interface: enhanced AWS client with context propagation - UPDATE model: refactored for AWS SDK v2 compatibility - UPDATE multipart/interface: improved chunk handling for large uploads - UPDATE pusher: optimized hash calculation and upload progress tracking - UPDATE resolver: enhanced endpoint resolution with custom DNS - DELETE test files: removed bucket_test.go, group_test.go, object_test.go, policy_test.go, role_test.go, user_test.go [cache] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - ADD context: context-aware cache lifecycle management - UPDATE interface: complete rewrite with Go generics for type-safe key-value operations - ADD item package: generic cache item with expiration tracking (interface and model) - UPDATE model: refactored to use generics (Cache[K comparable, V any]) - REFACTOR: split item.go into modelAny.go for better code organization [certificates] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE auth/encode: improved PEM encoding with better error messages - UPDATE auth/interface: enhanced authentication certificate handling - UPDATE ca: improved CA certificate generation and validation - UPDATE certs: enhanced certificate configuration with SAN support - UPDATE cipher: improved cipher suite selection and validation - UPDATE curves: enhanced elliptic curve handling with additional curves - ADD deprecated.go: marked deprecated TLS versions and cipher suites - UPDATE interface: enhanced certificate interface with context support - UPDATE model: improved certificate model with better validation - UPDATE rootca: enhanced root CA pool management - UPDATE tlsversion: added TLS 1.3 support with proper validation - UPDATE tools: improved certificate utility functions [cobra] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE completion: improved shell completion generation (bash, zsh, fish, powershell) - UPDATE configure: enhanced configuration file handling - UPDATE printError: improved error formatting with color support - UPDATE interface: enhanced cobra interface with context support - UPDATE model: improved cobra model with better validation [config] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE components: improved component lifecycle management - UPDATE const/const: improved constant definitions - UPDATE context: enhanced context handling with better propagation - UPDATE errors: improved error definitions - UPDATE events: enhanced event management - UPDATE manage: improved configuration management with validation - UPDATE model: refactored config model - UPDATE shell: enhanced shell integration for interactive configuration - UPDATE types: improved component and componentList types [console] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - ADD buff.go: BuffPrintf function for colored output to io.Writer (moved from ioutils/multiplexer) - DELETE color.go: removed legacy color file (consolidated functionality) - UPDATE error: improved error definitions with better messages - ADD interface: console interface for abstraction - ADD model: console model for state management - UPDATE padding: enhanced string padding with Unicode support - UPDATE prompt: improved interactive prompt handling [context] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - DELETE config.go: removed deprecated configuration (replaced by Config[T] interface) - UPDATE context: improved context handling with better cancellation support - UPDATE gin/interface: enhanced Gin context integration with type safety - ADD helper: context helper functions for common operations - ADD interface: generic Config[T comparable] interface for type-safe context storage - ADD map: MapManage[T] interface for concurrent-safe map operations - ADD model: thread-safe context model implementation with sync.Map [database] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE gorm/config: improved database configuration - UPDATE gorm/driver: enhanced database driver with better connection pooling - UPDATE gorm/driver_darwin: macOS-specific database optimizations - UPDATE gorm/interface: improved GORM interface with context support - UPDATE gorm/model: refactored model for better maintainability - UPDATE gorm/monitor: enhanced monitoring for database connections - UPDATE kvtypes: improved types for key-value store (compare, driver, item, table) [duration] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE big: enhanced big.Duration for large time spans with arithmetic operations - UPDATE encode: improved marshaling for JSON, YAML, TOML, Text, CBOR - UPDATE format: enhanced human-readable formatting (ns, μs, ms, s, m, h, d, w) - UPDATE interface: improved duration interface with arithmetic methods - UPDATE model: refactored Duration type - UPDATE operation: enhanced arithmetic operations (Add, Sub, Mul, Div) - UPDATE parse: improved parsing with multiple format support - UPDATE truncate: enhanced truncation for rounding durations [encoding] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE aes: improved AES encryption with reader/writer interfaces - UPDATE hexa: enhanced hexadecimal encoding with better error handling - UPDATE mux: improved multiplexer/demultiplexer for stream handling - UPDATE randRead: enhanced random data generation - UPDATE sha256 package: SHA-256 hashing with reader/writer interfaces [errors] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - ADD pool package: thread-safe error pool for collecting multiple errors with concurrent access - UPDATE code: improved error code definition and lookup - UPDATE errors: enhanced error creation with better stack trace - UPDATE interface: improved error interface with more methods - UPDATE mode: enhanced error mode handling (production vs development) - UPDATE return: improved error return handling with context - UPDATE trace: enhanced error tracing with file and line information [file] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE bandwidth: improved bandwidth tracking with concurrency tests - UPDATE perm: enhanced file permission handling with Unix/Windows support - UPDATE perm/encode: improved marshaling for JSON, YAML, TOML - UPDATE perm/format: enhanced permission formatting (e.g., "rwxr-xr-x") - UPDATE perm/parse: improved parsing of permission strings and octal values - UPDATE progress: enhanced progress tracking for file I/O operations - UPDATE progress/io*: improved reader, writer, seeker, closer interfaces with progress callbacks [ftpclient] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE config: improved FTP configuration with TLS support - UPDATE errors: enhanced error definitions - UPDATE interface: improved FTP client interface - UPDATE model: refactored FTP client model [httpcli] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE cli: improved HTTP client with retry logic and timeout handling - UPDATE dns-mapper: enhanced DNS mapping for custom resolution - UPDATE dns-mapper/config: improved DNS mapper configuration - UPDATE dns-mapper/errors: enhanced error handling - UPDATE dns-mapper/interface: improved DNS mapper interface - UPDATE dns-mapper/transport: enhanced HTTP transport with DNS override - UPDATE errors: improved error definitions - UPDATE options: enhanced client options with context support [httpserver] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE config: improved server configuration with TLS and middleware support - UPDATE handler: enhanced request handler with better error handling - UPDATE interface: improved server interface with context support and monitoring integration - UPDATE model: refactored server model with better validation - UPDATE monitor: enhanced monitoring integration with status tracking - UPDATE pool: improved server pool management (config, interface, list, model) - UPDATE run: enhanced server runtime with graceful shutdown - UPDATE server: improved core server implementation with better lifecycle - ADD testhelpers/certs.go: certificate generation utilities for testing - UPDATE types: improved const, fields, and handler types [ioutils] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE bufferReadCloser: improved buffered reader/writer with closer - UPDATE fileDescriptor: enhanced file descriptor limit management (platform-specific for Linux/macOS/Windows) - UPDATE ioprogress: improved progress tracking for I/O operations - UPDATE iowrapper: enhanced I/O wrapper with custom interfaces - UPDATE mapCloser: improved map of closers for resource management - UPDATE maxstdio: enhanced C implementation for max stdio file descriptor retrieval - DELETE multiplexer/model.go: removed legacy multiplexer (functionality moved to console/buff.go and retro/) - UPDATE nopwritecloser: improved no-op write closer - UPDATE tools: enhanced I/O utility functions [ldap] - UPDATE ldap: improved LDAP client with better connection handling and search operations [logger] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE config: improved default values, file options, and syslog configuration - UPDATE entry/interface: enhanced log entry with context support - UPDATE fields: improved field handling with JSON cloning - UPDATE gorm/interface: enhanced GORM logger with trace ID support - UPDATE hashicorp/interface: improved HashiCorp logger integration - FIX hookfile/system: use os.OpenRoot for secure file operations (prevents path traversal) - FIX hookfile/system: fixed import path from libsrv "golib/server" to "golib/runner" - ADD hookfile: IsRunning() method to track file hook state - UPDATE hookstderr/interface: enhanced stderr hook with better buffering - UPDATE hookstdout/interface: enhanced stdout hook with better buffering - UPDATE hooksyslog: improved syslog integration with channel and priority handling - ADD hookwriter package: generic io.Writer hook for custom output destinations - UPDATE interface: enhanced logger interface with context propagation - UPDATE level: improved log level handling and comparison - UPDATE log: enhanced logging with better formatting - UPDATE manage: improved logger lifecycle management - UPDATE model: refactored logger model for better maintainability [mail] - UPDATE sender: improved mail sender with better MIME handling - UPDATE interface: enhanced interface with monitoring support - UPDATE monitor: added monitoring integration for mail operations [monitor] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - ADD status package: new subpackage for status management with Status type (KO, Warn, OK) - ADD status/encode: marshaling support for JSON, YAML, TOML, Text, CBOR - ADD status/format: human-readable status formatting - ADD status/interface: Status type with Parse and String methods - UPDATE encode: improved encoding with better error handling - UPDATE error: enhanced error definitions - UPDATE info: improved system info collection (CPU, mem, disk, network) - UPDATE interface: enhanced monitor interface with status support and better component integration - UPDATE metrics: improved metrics collection and export - UPDATE middleware: enhanced monitoring middleware for HTTP - UPDATE pool/interface: enhanced pool interface with better monitoring integration - UPDATE pool/metrics: improved metrics collection in pool - UPDATE pool/model: refactored pool model for better maintainability - UPDATE pool/pool: enhanced pool implementation with better lifecycle - UPDATE server: enhanced server monitoring with status tracking - UPDATE types/monitor: improved monitor type definitions [nats] - UPDATE client: improved NATS client with better subscription handling - UPDATE config: enhanced NATS configuration with cluster support - UPDATE monitor: added monitoring integration for NATS operations - UPDATE server: improved NATS server integration with monitoring [network] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE bytes: improved byte size handling for network operations - UPDATE number: enhanced number utilities for network data - UPDATE protocol/encode: improved protocol encoding - ADD protocol/format: protocol formatting utilities - UPDATE protocol/interface: enhanced protocol interface - UPDATE protocol/model: refactored protocol model [password] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE password: improved password utilities with strength validation and secure generation [pidcontroller] - UPDATE interface: improved PID controller interface - UPDATE model: enhanced PID controller model with better tuning parameters [pprof] - UPDATE tools: improved pprof utilities for profiling integration [prometheus] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE bloom/bloom: improved bloom filter with better concurrency handling - UPDATE bloom/collection: enhanced bloom filter collection operations - UPDATE interface: enhanced prometheus interface with better type safety - UPDATE metrics/interface: enhanced metrics interface with better registration - UPDATE metrics/model: refactored metrics model for better maintainability - UPDATE model: refactored prometheus model with better validation - UPDATE pool: enhanced metric pool with concurrent access - UPDATE pool/interface: enhanced pool interface - UPDATE pool/model: refactored pool model - UPDATE route: improved routing for metric endpoints - UPDATE types: enhanced type definitions for metrics - UPDATE webmetrics: improved existing metrics (requestBody, requestIPTotal, requestLatency, requestSlow, requestTotal, requestURITotal, responseBody) - ADD webmetrics/activeConnections: gauge for tracking concurrent HTTP connections - ADD webmetrics/requestErrors: counter for HTTP request errors - ADD webmetrics/responseSizeByEndpoint: histogram for response size distribution by endpoint - ADD webmetrics/statusCodeTotal: counter for HTTP status codes [request] - UPDATE interface: enhanced request interface with better type safety - UPDATE model: refactored request model for better maintainability - UPDATE options: improved request options with better validation - UPDATE url: enhanced URL handling with better parsing [retro] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE encoding: improved encoding utilities with better format support - UPDATE format: enhanced formatting functions for retro compatibility - UPDATE model: refactored retro model with better validation - UPDATE utils: improved utility functions for version handling - UPDATE version: enhanced version utilities for retro compatibility [router] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE auth/interface: enhanced authentication interface with better validation - UPDATE auth/model: improved authentication model - UPDATE authheader/interface: enhanced authentication header interface - UPDATE default: improved default router configuration - UPDATE error: enhanced error definitions for router - UPDATE header/config: improved header configuration - UPDATE header/interface: enhanced header interface - UPDATE header/model: refactored header model - UPDATE interface: improved router interface with better type safety - UPDATE middleware: improved router middleware with better error handling - UPDATE model: refactored router model for better maintainability - UPDATE router: enhanced core router implementation - UPDATE tools: enhanced router utilities for route registration [runner] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE package: move package for lifecycle management of long-running services (moved from server/runner) - ADD interface: Runner interface with Start, Stop, Restart, IsRunning, and Uptime methods - ADD startStop package: service lifecycle with blocking start and graceful stop (interface, model, comprehensive tests) - ADD ticker package: periodic task execution at regular intervals (interface, model, comprehensive tests) - ADD tests: concurrency, construction, errors, lifecycle, and uptime tests for both startStop and ticker - ADD tools: RecoveryCaller for panic recovery in goroutines [semaphore] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - FIX bar/bar: Dec method now properly decrements (was calling Inc64, now calls Dec64 with negative value) - UPDATE bar: improved progress bar with better MPB integration - UPDATE bar/context: enhanced context handling for cancellation - UPDATE bar/interface: added methods for Total() and better progress tracking - UPDATE bar/model: improved model with atomic operations - UPDATE bar tests: enhanced bar_operations_test, edge_cases_test, integration_test, and semaphore_test - UPDATE context: enhanced context propagation - UPDATE interface: improved semaphore interface with weighted operations - UPDATE model: refactored model for better thread safety - UPDATE progress: enhanced progress tracking with multiple bars - UPDATE sem/interface: added IsRunning() method for state tracking - UPDATE sem/ulimit: improved ulimit handling for file descriptors - UPDATE sem/weighted: enhanced weighted semaphore operations - UPDATE types: improved type definitions for bar, progress, and semaphore [server] - REFACTOR: moved runner subpackage to root-level runner package - DELETE: empty package after moved runner subpackage [shell] - UPDATE goprompt: improved interactive prompt handling with better input validation [size] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - ADD arithmetic.go: NEW file with arithmetic operations (Add, Sub, Mul, Div with overflow detection) - UPDATE encode: improved marshaling for JSON, YAML, TOML, Text, CBOR - UPDATE format: enhanced human-readable formatting (B, KB, MB, GB, TB, PB, EB) - UPDATE interface: added arithmetic methods (Mul, MulErr, Div, DivErr, Add, AddErr, Sub, SubErr) - UPDATE model: refactored Size type with better validation - UPDATE parse: improved parsing with unit detection (IEC and SI standards) [smtp] - UPDATE client: improved SMTP client with better error handling - UPDATE config: enhanced configuration with validation - UPDATE config/error: improved error definitions - UPDATE config/interface: enhanced interface with context support - UPDATE config/model: refactored model for better maintainability - UPDATE interface: improved SMTP interface with monitoring support - UPDATE monitor: added monitoring integration for SMTP operations - DELETE network/network.go: removed legacy network handling (consolidated into client) - UPDATE tlsmode/tls: enhanced TLS mode handling (None, TLS, StartTLS) - UPDATE types/interface: improved type interface [socket] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - ADD client/interface_darwin: macOS-specific socket client options - UPDATE client/interface_linux: platform-specific socket options for Linux - UPDATE client/interface_other: platform-specific socket options for other platforms - UPDATE client/tcp/error: improved TCP client error handling - UPDATE client/tcp/interface: enhanced TCP client interface - UPDATE client/tcp/model: improved TCP client model - UPDATE client/udp/error: improved UDP client error handling - UPDATE client/udp/interface: enhanced UDP client interface - UPDATE client/udp/model: improved UDP client model - UPDATE client/unix/error: improved Unix socket client error handling - UPDATE client/unix/ignore: enhanced ignore functionality - UPDATE client/unix/interface: enhanced Unix socket client interface - UPDATE client/unix/model: improved Unix socket client model - UPDATE client/unixgram/error: improved Unix datagram client error handling - UPDATE client/unixgram/ignore: enhanced ignore functionality - UPDATE client/unixgram/interface: enhanced Unix datagram client interface - UPDATE client/unixgram/model: improved Unix datagram client model - UPDATE config/client: improved client configuration - UPDATE config/server: improved server configuration - DELETE delim: moved legacy delimiter to I/O package - UPDATE interface: improved socket interface - UPDATE io: enhanced I/O operations - DELETE multi: moved legacy multi to I/O package - ADD server/interface_darwin: macOS-specific socket server options - UPDATE server/interface_linux: platform-specific server options for Linux - UPDATE server/interface_other: platform-specific server options for other platforms - UPDATE server/tcp/error: improved TCP server error handling - UPDATE server/tcp/interface: enhanced TCP server interface - UPDATE server/tcp/listener: improved TCP server listener - UPDATE server/tcp/model: improved TCP server model - UPDATE server/udp/error: improved UDP server error handling - UPDATE server/udp/interface: enhanced UDP server interface - UPDATE server/udp/listener: improved UDP server listener - UPDATE server/udp/model: improved UDP server model - UPDATE server/unix/error: improved Unix socket server error handling - UPDATE server/unix/ignore: enhanced ignore functionality - UPDATE server/unix/interface: enhanced Unix socket server interface - UPDATE server/unix/listener: improved Unix socket server listener - UPDATE server/unix/model: improved Unix socket server model - UPDATE server/unixgram/error: improved Unix datagram server error handling - UPDATE server/unixgram/ignore: enhanced ignore functionality - UPDATE server/unixgram/interface: enhanced Unix datagram server interface - UPDATE server/unixgram/listener: improved Unix datagram server listener - UPDATE server/unixgram/model: improved Unix datagram server model [static] - UPDATE interface: improved static interface with monitoring support - UPDATE model: refactored static model - UPDATE monitor: added monitoring integration for static file operations [status] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE cache: improved status cache with better synchronization - UPDATE config: improved status configuration - UPDATE control/encode: improved control encoding - UPDATE control/interface: enhanced control interface with status tracking - UPDATE control/model: refactored control model - UPDATE encode: improved status encoding - UPDATE error: enhanced error definitions for status - UPDATE info: improved status info handling - UPDATE interface: enhanced status interface - UPDATE listmandatory/interface: improved list mandatory interface - UPDATE listmandatory/model: refactored list mandatory model - UPDATE mandatory/interface: enhanced mandatory interface - UPDATE mandatory/model: refactored mandatory model - UPDATE model: refactored status model - UPDATE pool: improved status pool - UPDATE route: enhanced status route handling [test] - DELETE: all manual tests are or will be replaced by proper automated test suites in respective packages [version] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE error: improved error definitions for version - UPDATE license: enhanced license handling - UPDATE version: improved version utilities [viper] - ADD/UPDATE documentation: comprehensive documentation with monitoring patterns - ADD/UPDATE tests: enhanced benchmark, config, encoding, example, integration, lifecycle, metrics, security, transitions - UPDATE interface: enhanced viper interface with context support - UPDATE model: refactored viper model for better maintainability
739 lines
18 KiB
Go
739 lines
18 KiB
Go
/*
|
|
* MIT License
|
|
*
|
|
* Copyright (c) 2019 Nicolas JUHEL
|
|
*
|
|
* Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
* of this software and associated documentation files (the "Software"), to deal
|
|
* in the Software without restriction, including without limitation the rights
|
|
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
* copies of the Software, and to permit persons to whom the Software is
|
|
* furnished to do so, subject to the following conditions:
|
|
*
|
|
* The above copyright notice and this permission notice shall be included in all
|
|
* copies or substantial portions of the Software.
|
|
*
|
|
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
* SOFTWARE.
|
|
*
|
|
*/
|
|
|
|
package ldap
|
|
|
|
import (
|
|
"context"
|
|
"crypto/tls"
|
|
"fmt"
|
|
"net"
|
|
"slices"
|
|
"strings"
|
|
|
|
"github.com/go-ldap/ldap/v3"
|
|
libcrt "github.com/nabbar/golib/certificates"
|
|
libctx "github.com/nabbar/golib/context"
|
|
liberr "github.com/nabbar/golib/errors"
|
|
liblog "github.com/nabbar/golib/logger"
|
|
logent "github.com/nabbar/golib/logger/entry"
|
|
loglvl "github.com/nabbar/golib/logger/level"
|
|
)
|
|
|
|
type FuncLogger liblog.FuncLog
|
|
|
|
// HelperLDAP struct use to manage connection to server and request it.
|
|
type HelperLDAP struct {
|
|
Attributes []string
|
|
conn *ldap.Conn
|
|
config *Config
|
|
tlsConfig *tls.Config
|
|
tlsMode TLSMode
|
|
bindDN string
|
|
bindPass string
|
|
ctx context.Context
|
|
log liblog.FuncLog
|
|
}
|
|
|
|
// NewLDAP build a new LDAP helper based on config struct given.
|
|
func NewLDAP(ctx context.Context, cnf *Config, attributes []string) (*HelperLDAP, liberr.Error) {
|
|
if cnf == nil {
|
|
return nil, ErrorParamEmpty.Error(nil)
|
|
}
|
|
|
|
return &HelperLDAP{
|
|
Attributes: attributes,
|
|
//nolint #staticcheck
|
|
tlsConfig: libcrt.GetTLSConfig(cnf.Uri),
|
|
tlsMode: _TLSModeInit,
|
|
config: cnf.Clone(),
|
|
ctx: libctx.IsolateParent(ctx),
|
|
}, nil
|
|
}
|
|
|
|
func (lc *HelperLDAP) Clone() *HelperLDAP {
|
|
var att = make([]string, 0)
|
|
copy(att, lc.Attributes)
|
|
|
|
return &HelperLDAP{
|
|
Attributes: att,
|
|
conn: nil,
|
|
config: lc.config.Clone(),
|
|
tlsConfig: lc.tlsConfig.Clone(),
|
|
tlsMode: lc.tlsMode,
|
|
bindDN: lc.bindDN,
|
|
bindPass: lc.bindPass,
|
|
ctx: lc.ctx,
|
|
log: lc.log,
|
|
}
|
|
}
|
|
|
|
// SetLogger is used to specify the logger to be used for debug messgae
|
|
func (lc *HelperLDAP) SetLogger(fct liblog.FuncLog) {
|
|
lc.log = fct
|
|
}
|
|
|
|
func (lc *HelperLDAP) getLogDefault() liblog.Logger {
|
|
return liblog.New(lc.ctx)
|
|
}
|
|
|
|
func (lc *HelperLDAP) getLogEntry(lvl loglvl.Level, msg string, args ...interface{}) logent.Entry {
|
|
var log liblog.Logger
|
|
if lc.log == nil {
|
|
log = lc.getLogDefault()
|
|
lc.log = func() liblog.Logger {
|
|
return log
|
|
}
|
|
}
|
|
|
|
if l := lc.log(); l != nil {
|
|
log = l
|
|
}
|
|
|
|
if log == nil {
|
|
return logent.New(lvl)
|
|
}
|
|
|
|
return log.Entry(lvl, msg, args...).FieldAdd("ldap.host", lc.config.ServerAddr(lc.tlsMode == TLSModeTLS)).FieldAdd("ldap.tlsMode", lc.tlsMode.String())
|
|
}
|
|
|
|
func (lc *HelperLDAP) getLogEntryErr(lvlKO loglvl.Level, err error, msg string, args ...interface{}) logent.Entry {
|
|
var log liblog.Logger
|
|
if lc.log == nil {
|
|
log = lc.getLogDefault()
|
|
lc.log = func() liblog.Logger {
|
|
return log
|
|
}
|
|
}
|
|
|
|
if l := lc.log(); l != nil {
|
|
log = l
|
|
}
|
|
|
|
if log == nil {
|
|
return logent.New(lvlKO).ErrorAdd(true, err)
|
|
}
|
|
|
|
return log.Entry(lvlKO, msg, args...).FieldAdd("ldap.host", lc.config.ServerAddr(lc.tlsMode == TLSModeTLS)).ErrorAdd(true, err)
|
|
}
|
|
|
|
// SetCredentials used to defined the BindDN and password for connection.
|
|
func (lc *HelperLDAP) SetCredentials(user, pass string) {
|
|
lc.bindDN = user
|
|
lc.bindPass = pass
|
|
}
|
|
|
|
func (lc *HelperLDAP) GetTLSMode() TLSMode {
|
|
if lc.tlsMode == TLSModeTLS || lc.tlsMode == TLSModeStarttls {
|
|
if lc.tlsConfig == nil {
|
|
return TLSModeNone
|
|
}
|
|
}
|
|
|
|
return lc.tlsMode
|
|
}
|
|
|
|
// ForceTLSMode used to force tls mode and defined tls condition.
|
|
func (lc *HelperLDAP) ForceTLSMode(tlsMode TLSMode, tlsConfig *tls.Config) {
|
|
if tlsConfig != nil {
|
|
lc.tlsConfig = tlsConfig
|
|
} else {
|
|
lc.tlsConfig = &tls.Config{
|
|
MinVersion: tls.VersionTLS12,
|
|
MaxVersion: tls.VersionTLS13,
|
|
}
|
|
}
|
|
|
|
switch tlsMode {
|
|
case TLSModeTLS:
|
|
lc.tlsMode = TLSModeTLS
|
|
case TLSModeStarttls:
|
|
lc.tlsMode = TLSModeStarttls
|
|
case TLSModeNone:
|
|
lc.tlsConfig = nil
|
|
lc.tlsMode = TLSModeNone
|
|
case _TLSModeInit:
|
|
lc.tlsMode = _TLSModeInit
|
|
}
|
|
}
|
|
|
|
func (lc *HelperLDAP) dialTLS() (*ldap.Conn, liberr.Error) {
|
|
d := net.Dialer{}
|
|
adr := lc.config.ServerAddr(true)
|
|
|
|
if len(adr) < 3 {
|
|
return nil, ErrorLDAPServerTLS.Error(fmt.Errorf("invalid port for LDAPS"))
|
|
}
|
|
|
|
c, err := d.DialContext(lc.ctx, "tcp", adr)
|
|
|
|
if err != nil {
|
|
if c != nil {
|
|
_ = c.Close()
|
|
}
|
|
|
|
return nil, ErrorLDAPServerTLS.Error(err)
|
|
}
|
|
|
|
c = tls.Client(c, lc.tlsConfig) // nolint
|
|
|
|
l := ldap.NewConn(c, true)
|
|
if l == nil {
|
|
return nil, ErrorLDAPServerTLS.Error(ErrorLDAPServerConnection.Error(nil))
|
|
}
|
|
|
|
l.Start()
|
|
|
|
if l.IsClosing() {
|
|
return nil, ErrorLDAPServerTLS.Error(ErrorLDAPServerDialClosing.Error(nil))
|
|
}
|
|
|
|
if _, tlsOk := l.TLSConnectionState(); !tlsOk {
|
|
return nil, ErrorLDAPServerTLS.Error(nil)
|
|
}
|
|
|
|
return l, nil
|
|
}
|
|
|
|
func (lc *HelperLDAP) dial() (*ldap.Conn, liberr.Error) {
|
|
d := net.Dialer{}
|
|
adr := lc.config.ServerAddr(false)
|
|
|
|
if len(adr) < 3 {
|
|
return nil, ErrorLDAPServerTLS.Error(fmt.Errorf("invalid port for LDAP / LDAP+STARTLS"))
|
|
}
|
|
|
|
c, err := d.DialContext(lc.ctx, "tcp", adr)
|
|
|
|
if err != nil {
|
|
if c != nil {
|
|
_ = c.Close()
|
|
}
|
|
|
|
return nil, ErrorLDAPServerDial.Error(err)
|
|
}
|
|
|
|
l := ldap.NewConn(c, false)
|
|
if l == nil {
|
|
return nil, ErrorLDAPServerDial.Error(ErrorLDAPServerConnection.Error(nil))
|
|
}
|
|
|
|
l.Start()
|
|
|
|
if l.IsClosing() {
|
|
return nil, ErrorLDAPServerDial.Error(ErrorLDAPServerDialClosing.Error(nil))
|
|
}
|
|
|
|
return l, nil
|
|
}
|
|
|
|
func (lc *HelperLDAP) starttls(l *ldap.Conn) liberr.Error {
|
|
err := l.StartTLS(lc.tlsConfig)
|
|
|
|
if err != nil {
|
|
return ErrorLDAPServerStartTLS.Error(err)
|
|
}
|
|
|
|
if _, tlsOk := l.TLSConnectionState(); !tlsOk {
|
|
return ErrorLDAPServerStartTLS.Error(nil)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
func (lc *HelperLDAP) tryConnect() (TLSMode, liberr.Error) {
|
|
if lc == nil {
|
|
return TLSModeNone, ErrorParamEmpty.Error(nil)
|
|
}
|
|
|
|
var (
|
|
l *ldap.Conn
|
|
err liberr.Error
|
|
)
|
|
|
|
defer func() {
|
|
if l != nil {
|
|
_ = l.Close()
|
|
}
|
|
}()
|
|
|
|
if lc.config.Portldaps != 0 {
|
|
l, err = lc.dialTLS()
|
|
|
|
lc.getLogEntryErr(loglvl.DebugLevel, err, "connecting ldap with tls mode '%s'", TLSModeTLS.String()).Check(loglvl.DebugLevel)
|
|
|
|
if err == nil {
|
|
return TLSModeTLS, nil
|
|
}
|
|
}
|
|
|
|
if lc.config.PortLdap == 0 {
|
|
return _TLSModeInit, ErrorLDAPServerConfig.Error(nil)
|
|
}
|
|
|
|
l, err = lc.dial()
|
|
lc.getLogEntryErr(loglvl.DebugLevel, err, "connecting ldap with tls mode '%s'", TLSModeNone.String()).Check(loglvl.DebugLevel)
|
|
|
|
if err != nil {
|
|
return _TLSModeInit, err
|
|
}
|
|
|
|
err = lc.starttls(l)
|
|
lc.getLogEntryErr(loglvl.DebugLevel, err, "connecting ldap with tls mode '%s'", TLSModeStarttls.String()).Check(loglvl.DebugLevel)
|
|
|
|
if err == nil {
|
|
return TLSModeStarttls, nil
|
|
}
|
|
|
|
return TLSModeNone, nil
|
|
}
|
|
|
|
func (lc *HelperLDAP) connect() liberr.Error {
|
|
if lc == nil || lc.ctx == nil {
|
|
return ErrorLDAPContext.Error(ErrorParamEmpty.Error(nil))
|
|
}
|
|
|
|
if err := lc.ctx.Err(); err != nil {
|
|
return ErrorLDAPContext.Error(err)
|
|
}
|
|
|
|
if lc.conn == nil {
|
|
var (
|
|
l *ldap.Conn
|
|
err liberr.Error
|
|
)
|
|
|
|
if lc.tlsMode == _TLSModeInit {
|
|
m, e := lc.tryConnect()
|
|
|
|
if e != nil {
|
|
return e
|
|
}
|
|
|
|
lc.tlsMode = m
|
|
}
|
|
|
|
if lc.tlsMode == TLSModeTLS {
|
|
l, err = lc.dialTLS()
|
|
if err != nil {
|
|
if l != nil {
|
|
_ = l.Close()
|
|
}
|
|
return err
|
|
}
|
|
}
|
|
|
|
if lc.tlsMode == TLSModeNone || lc.tlsMode == TLSModeStarttls {
|
|
l, err = lc.dial()
|
|
if err != nil {
|
|
if l != nil {
|
|
_ = l.Close()
|
|
}
|
|
return err
|
|
}
|
|
}
|
|
|
|
if lc.tlsMode == TLSModeStarttls {
|
|
err = lc.starttls(l)
|
|
if err != nil {
|
|
if l != nil {
|
|
_ = l.Close()
|
|
}
|
|
return err
|
|
}
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap connected").Log()
|
|
lc.conn = l
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// Check used to check if connection success (without any bind).
|
|
func (lc *HelperLDAP) Check() liberr.Error {
|
|
if lc == nil {
|
|
return ErrorParamEmpty.Error(nil)
|
|
}
|
|
|
|
if lc.conn == nil {
|
|
defer func() {
|
|
if lc.conn != nil {
|
|
_ = lc.conn.Close()
|
|
lc.conn = nil
|
|
}
|
|
}()
|
|
}
|
|
|
|
if err := lc.connect(); err != nil {
|
|
lc.Close()
|
|
return err
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// Close used to close connection object.
|
|
func (lc *HelperLDAP) Close() {
|
|
if lc == nil {
|
|
return
|
|
}
|
|
|
|
if lc.conn != nil {
|
|
_ = lc.conn.Close()
|
|
lc.conn = nil
|
|
}
|
|
}
|
|
|
|
// AuthUser used to test bind given user uid and password.
|
|
func (lc *HelperLDAP) AuthUser(username, password string) liberr.Error {
|
|
if lc == nil {
|
|
return ErrorParamEmpty.Error(nil)
|
|
}
|
|
|
|
if err := lc.connect(); err != nil {
|
|
return err
|
|
}
|
|
|
|
if username == "" || password == "" {
|
|
return ErrorParamEmpty.Error(nil)
|
|
}
|
|
|
|
err := lc.conn.Bind(username, password)
|
|
|
|
return ErrorLDAPBind.IfError(err)
|
|
}
|
|
|
|
// Connect used to connect and bind to server.
|
|
func (lc *HelperLDAP) Connect() liberr.Error {
|
|
if lc == nil {
|
|
return ErrorParamEmpty.Error(nil)
|
|
}
|
|
|
|
if err := lc.AuthUser(lc.bindDN, lc.bindPass); err != nil {
|
|
return err
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap bind success").FieldAdd("bind.dn", lc.bindDN).Log()
|
|
return nil
|
|
}
|
|
|
|
func (lc *HelperLDAP) runSearch(filter string, attributes []string) (*ldap.SearchResult, liberr.Error) {
|
|
var (
|
|
err error
|
|
src *ldap.SearchResult
|
|
)
|
|
|
|
if e := lc.Connect(); e != nil {
|
|
return nil, e
|
|
}
|
|
|
|
defer lc.Close()
|
|
|
|
searchRequest := ldap.NewSearchRequest(
|
|
lc.config.Basedn,
|
|
ldap.ScopeWholeSubtree,
|
|
ldap.NeverDerefAliases,
|
|
0, 0, false,
|
|
filter,
|
|
attributes,
|
|
nil,
|
|
)
|
|
|
|
if src, err = lc.conn.Search(searchRequest); err != nil {
|
|
return nil, ErrorLDAPSearch.Error(err)
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap search success").FieldAdd("ldap.filter", filter).FieldAdd("ldap.attributes", attributes).Log()
|
|
return src, nil
|
|
}
|
|
|
|
func (lc *HelperLDAP) getUserName(username string) (string, liberr.Error) {
|
|
username = strings.TrimSpace(username)
|
|
if username == "" {
|
|
if usr := lc.ParseEntries(lc.bindDN); len(usr) == 0 {
|
|
return "", ErrorLDAPInvalidUID.Error(ErrorLDAPInvalidDN.Error(nil))
|
|
} else if _, ok := usr["uid"]; !ok {
|
|
return "", ErrorLDAPInvalidUID.Error(ErrorLDAPAttributeNotFound.Error(nil))
|
|
} else if len(usr["uid"]) < 1 {
|
|
return "", ErrorLDAPInvalidUID.Error(ErrorLDAPAttributeEmpty.Error(nil))
|
|
} else {
|
|
username = usr["uid"][0]
|
|
}
|
|
|
|
username = strings.TrimSpace(username)
|
|
}
|
|
|
|
if username == "" {
|
|
return "", ErrorLDAPInvalidUID.Error(ErrorLDAPAttributeEmpty.Error(nil))
|
|
}
|
|
|
|
return username, nil
|
|
}
|
|
|
|
// UserInfo used to retrieve the information of a given username.
|
|
func (lc *HelperLDAP) UserInfo(username string) (map[string]string, liberr.Error) {
|
|
return lc.UserInfoByField(username, userFieldUid)
|
|
}
|
|
|
|
// UserInfoByField used to retrieve the information of a given username but use a given field to make the search.
|
|
func (lc *HelperLDAP) UserInfoByField(username string, fieldOfUnicValue string) (map[string]string, liberr.Error) {
|
|
var (
|
|
err liberr.Error
|
|
src *ldap.SearchResult
|
|
userRes map[string]string
|
|
)
|
|
|
|
if username, err = lc.getUserName(username); err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
userRes = make(map[string]string)
|
|
attributes := append(lc.Attributes, "cn")
|
|
|
|
src, err = lc.runSearch(fmt.Sprintf(lc.config.FilterUser, fieldOfUnicValue, username), attributes)
|
|
|
|
if err != nil {
|
|
return userRes, err
|
|
}
|
|
|
|
if len(src.Entries) != 1 {
|
|
if len(src.Entries) > 1 {
|
|
return userRes, ErrorLDAPUserNotUniq.Error(nil)
|
|
} else {
|
|
return userRes, ErrorLDAPUserNotFound.Error(nil)
|
|
}
|
|
}
|
|
|
|
for _, attr := range attributes {
|
|
userRes[attr] = src.Entries[0].GetAttributeValue(attr)
|
|
}
|
|
|
|
if _, ok := userRes["DN"]; !ok {
|
|
userRes["DN"] = src.Entries[0].DN
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap user find success").FieldAdd("ldap.user", username).FieldAdd("ldap.map", userRes).Log()
|
|
return userRes, nil
|
|
}
|
|
|
|
// GroupInfo used to retrieve the information of a given group cn.
|
|
func (lc *HelperLDAP) GroupInfo(groupname string) (map[string]interface{}, liberr.Error) {
|
|
return lc.GroupInfoByField(groupname, groupFieldCN)
|
|
}
|
|
|
|
func (lc *HelperLDAP) AttributeFilter(search string, filter string, allAttribute bool, attribute ...string) (map[string]map[string]string, liberr.Error) {
|
|
var (
|
|
err liberr.Error
|
|
src *ldap.SearchResult
|
|
grpInfo = make(map[string]map[string]string, 0)
|
|
)
|
|
|
|
if !slices.Contains(attribute, "cn") {
|
|
attribute = append(append(make([]string, 0, len(attribute)+1), "cn"), attribute...)
|
|
}
|
|
|
|
if len(filter) > 0 && len(search) > 0 {
|
|
src, err = lc.runSearch(fmt.Sprintf("(&(objectClass~=groupOfNames)(%s=%s))", filter, search), attribute)
|
|
} else {
|
|
src, err = lc.runSearch("(&(objectClass~=groupOfNames))", attribute)
|
|
}
|
|
|
|
if err != nil {
|
|
return grpInfo, err
|
|
} else if len(src.Entries) == 0 {
|
|
return nil, ErrorLDAPGroupNotFound.Error(nil)
|
|
}
|
|
|
|
for i := range src.Entries {
|
|
if src.Entries[i] == nil {
|
|
continue
|
|
} else if len(src.Entries[i].Attributes) < 1 {
|
|
continue
|
|
}
|
|
|
|
var g = make(map[string]string, 0)
|
|
|
|
for j := range src.Entries[i].Attributes {
|
|
if src.Entries[i].Attributes[j] == nil {
|
|
continue
|
|
} else if len(src.Entries[i].Attributes[j].Name) < 1 {
|
|
continue
|
|
} else if len(src.Entries[i].Attributes[j].Values) < 1 {
|
|
continue
|
|
} else if slices.Contains(attribute, src.Entries[i].Attributes[j].Name) {
|
|
g[src.Entries[i].Attributes[j].Name] = strings.Join(src.Entries[i].Attributes[j].Values, " ")
|
|
}
|
|
}
|
|
|
|
if len(g) < 1 {
|
|
continue
|
|
} else if allAttribute && len(g) != len(attribute) {
|
|
continue
|
|
}
|
|
|
|
if _, k := g["cn"]; k {
|
|
grpInfo[g["cn"]] = g
|
|
continue
|
|
}
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap group find success").FieldAdd("ldap.group", search).FieldAdd("ldap.attributes", strings.Join(attribute, ",")).FieldAdd("ldap.result.len", len(grpInfo)).Log()
|
|
return grpInfo, nil
|
|
}
|
|
|
|
// GroupInfoByField used to retrieve the information of a given group cn, but use a given field to make the search.
|
|
func (lc *HelperLDAP) GroupInfoByField(groupname string, fieldForUnicValue string) (map[string]interface{}, liberr.Error) {
|
|
var (
|
|
err liberr.Error
|
|
src *ldap.SearchResult
|
|
grpInfo map[string]interface{}
|
|
)
|
|
|
|
src, err = lc.runSearch(fmt.Sprintf(lc.config.FilterGroup, fieldForUnicValue, groupname), []string{})
|
|
if err != nil {
|
|
return grpInfo, err
|
|
}
|
|
|
|
if len(src.Entries) == 0 {
|
|
return nil, ErrorLDAPGroupNotFound.Error(nil)
|
|
}
|
|
|
|
grpInfo = make(map[string]interface{}, len(src.Entries[0].Attributes))
|
|
for _, entry := range src.Entries {
|
|
for _, entryAttribute := range entry.Attributes {
|
|
grpInfo[entryAttribute.Name] = entryAttribute.Values
|
|
}
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap group find success").FieldAdd("ldap.group", groupname).FieldAdd("ldap.map", grpInfo).Log()
|
|
return grpInfo, nil
|
|
}
|
|
|
|
// UserMemberOf returns the group list of a given user.
|
|
func (lc *HelperLDAP) UserMemberOf(username string) ([]string, liberr.Error) {
|
|
var (
|
|
err liberr.Error
|
|
src *ldap.SearchResult
|
|
grp []string
|
|
)
|
|
|
|
if username, err = lc.getUserName(username); err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
grp = make([]string, 0)
|
|
|
|
src, err = lc.runSearch(fmt.Sprintf(lc.config.FilterUser, userFieldUid, username), []string{"memberOf"})
|
|
if err != nil {
|
|
return grp, err
|
|
}
|
|
|
|
for _, entry := range src.Entries {
|
|
for _, mmb := range entry.GetAttributeValues("memberOf") {
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap find user group list building").FieldAdd("ldap.user", username).FieldAdd("ldap.raw.groups", mmb).Log()
|
|
mmo := lc.ParseEntries(mmb)
|
|
grp = append(grp, mmo["cn"]...)
|
|
}
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap user group list success").FieldAdd("ldap.user", username).FieldAdd("ldap.grouplist", grp).Log()
|
|
return grp, nil
|
|
}
|
|
|
|
// UserIsInGroup used to check if a given username is a group member of a list of reference group name.
|
|
func (lc *HelperLDAP) UserIsInGroup(username string, groupname []string) (bool, liberr.Error) {
|
|
var (
|
|
err liberr.Error
|
|
grpMmbr []string
|
|
)
|
|
|
|
if username, err = lc.getUserName(username); err != nil {
|
|
return false, err
|
|
} else if grpMmbr, err = lc.UserMemberOf(username); err != nil {
|
|
return false, err
|
|
}
|
|
|
|
for _, grpSrch := range groupname {
|
|
for _, grpItem := range grpMmbr {
|
|
if strings.EqualFold(grpSrch, grpItem) {
|
|
return true, nil
|
|
}
|
|
}
|
|
}
|
|
|
|
return false, nil
|
|
}
|
|
|
|
// UsersOfGroup used to retrieve the member list of a given group name.
|
|
func (lc *HelperLDAP) UsersOfGroup(groupname string) ([]string, liberr.Error) {
|
|
var (
|
|
err liberr.Error
|
|
src *ldap.SearchResult
|
|
grp []string
|
|
)
|
|
|
|
grp = make([]string, 0)
|
|
|
|
src, err = lc.runSearch(fmt.Sprintf(lc.config.FilterGroup, groupFieldCN, groupname), []string{"member"})
|
|
if err != nil {
|
|
return grp, err
|
|
}
|
|
|
|
for _, entry := range src.Entries {
|
|
for _, mmb := range entry.GetAttributeValues("member") {
|
|
member := lc.ParseEntries(mmb)
|
|
grp = append(grp, member["uid"]...)
|
|
}
|
|
}
|
|
|
|
lc.getLogEntry(loglvl.DebugLevel, "ldap group user list success").FieldAdd("ldap.group", groupname).FieldAdd("ldap.userlist", grp).Log()
|
|
return grp, nil
|
|
}
|
|
|
|
// ParseEntries used to clean attributes of an object class.
|
|
func (lc *HelperLDAP) ParseEntries(entry string) map[string][]string {
|
|
var listEntries = make(map[string][]string)
|
|
|
|
for _, ent := range strings.Split(entry, ",") {
|
|
key := strings.SplitN(ent, "=", 2)
|
|
|
|
if len(key) != 2 || len(key[0]) < 1 || len(key[1]) < 1 {
|
|
continue
|
|
}
|
|
|
|
key[0] = strings.TrimSpace(key[0])
|
|
key[1] = strings.TrimSpace(key[1])
|
|
|
|
if _, ok := listEntries[key[0]]; !ok {
|
|
listEntries[key[0]] = []string{}
|
|
}
|
|
|
|
listEntries[key[0]] = append(listEntries[key[0]], key[1])
|
|
}
|
|
|
|
return listEntries
|
|
}
|