add group filter support to ldap-check.sh (#11935)
* add group filter support to ldap-check.sh * Update scripts/ldap-check.sh Co-Authored-By: George Goldberg <george@gberg.me>
Этот коммит содержится в:
коммит произвёл
George Goldberg
родитель
0f36649d22
Коммит
85960abb08
@@ -17,8 +17,9 @@ ldapsearch_cmd=ldapsearch
|
|||||||
|
|
||||||
if [[ -z ${1} ]]; then
|
if [[ -z ${1} ]]; then
|
||||||
echo "We could not find a username";
|
echo "We could not find a username";
|
||||||
echo "usage: ./ldap-check.sh [username]"
|
echo "usage: ./ldap-check.sh -u/-g [username/groupname]"
|
||||||
echo "example: ./ldap-check.sh john"
|
echo "example: ./ldap-check.sh -u john"
|
||||||
|
echo "example: ./ldap-check.sh -g admin-staff"
|
||||||
exit 1;
|
exit 1;
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -54,14 +55,35 @@ UserFilter=`cat $config_file | jq -r .LdapSettings.UserFilter`
|
|||||||
EmailAttribute=`cat $config_file | jq -r .LdapSettings.EmailAttribute`
|
EmailAttribute=`cat $config_file | jq -r .LdapSettings.EmailAttribute`
|
||||||
UsernameAttribute=`cat $config_file | jq -r .LdapSettings.UsernameAttribute`
|
UsernameAttribute=`cat $config_file | jq -r .LdapSettings.UsernameAttribute`
|
||||||
IdAttribute=`cat $config_file | jq -r .LdapSettings.IdAttribute`
|
IdAttribute=`cat $config_file | jq -r .LdapSettings.IdAttribute`
|
||||||
|
GroupFilter=`cat $config_file | jq -r .LdapSettings.GroupFilter`
|
||||||
|
GroupIdAttribute=`cat $config_file | jq -r .LdapSettings.GroupIdAttribute`
|
||||||
|
|
||||||
if [[ -z ${UserFilter} ]]; then
|
if [[ -z ${UserFilter} ]]; then
|
||||||
UserFilter="($IdAttribute=$1)"
|
UserFilter="($IdAttribute=$2)"
|
||||||
else
|
else
|
||||||
UserFilter="(&($IdAttribute=$1)$UserFilter)"
|
UserFilter="(&($IdAttribute=$2)$UserFilter)"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if [[ -z ${GroupFilter} ]]; then
|
||||||
|
GroupFilter="($GroupIdAttribute=$2)"
|
||||||
|
else
|
||||||
|
GroupFilter="(&($GroupIdAttribute=$2)$GroupFilter)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ $1 == '-u' ]]; then
|
||||||
|
|
||||||
cmd_to_run="$ldapsearch_cmd -LLL -x -h $LdapServer -p $LdapPort -D \"$BindUsername\" -w \"$BindPassword\" -b \"$BaseDN\" \"$UserFilter\" $IdAttribute $UsernameAttribute $EmailAttribute"
|
cmd_to_run="$ldapsearch_cmd -LLL -x -h $LdapServer -p $LdapPort -D \"$BindUsername\" -w \"$BindPassword\" -b \"$BaseDN\" \"$UserFilter\" $IdAttribute $UsernameAttribute $EmailAttribute"
|
||||||
echo $cmd_to_run
|
echo $cmd_to_run
|
||||||
echo "-------------------------"
|
echo "-------------------------"
|
||||||
eval $cmd_to_run
|
eval $cmd_to_run
|
||||||
|
|
||||||
|
elif [[ $1 == '-g' ]]; then
|
||||||
|
|
||||||
|
cmd_to_run="$ldapsearch_cmd -LLL -x -h $LdapServer -p $LdapPort -D \"$BindUsername\" -w \"$BindPassword\" -b \"$BaseDN\" \"$GroupFilter\""
|
||||||
|
echo $cmd_to_run
|
||||||
|
echo "-------------------------"
|
||||||
|
eval $cmd_to_run
|
||||||
|
|
||||||
|
else
|
||||||
|
echo "User or Group not specified"
|
||||||
|
fi
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user