2015-09-08 05:15:39 +08:00
|
|
|
<?php
|
|
|
|
|
|
|
|
class LdapContactsSuggestions implements \RainLoop\Providers\Suggestions\ISuggestions
|
|
|
|
{
|
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-23 16:14:42 +08:00
|
|
|
private $sLdapUri = 'ldap://localhost:389';
|
2015-09-08 05:15:39 +08:00
|
|
|
|
2021-08-22 16:48:33 +08:00
|
|
|
/**
|
|
|
|
* @var bool
|
|
|
|
*/
|
|
|
|
private $bUseStartTLS = True;
|
|
|
|
|
2015-09-08 05:15:39 +08:00
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 18:01:43 +08:00
|
|
|
private $sBindDn = null;
|
2015-09-08 05:15:39 +08:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 18:01:43 +08:00
|
|
|
private $sBindPassword = null;
|
2015-09-08 05:15:39 +08:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 18:54:02 +08:00
|
|
|
private $sBaseDn = 'ou=People,dc=example,dc=com';
|
2015-09-08 05:15:39 +08:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 19:32:20 +08:00
|
|
|
private $sObjectClasses = 'inetOrgPerson';
|
2015-09-08 05:15:39 +08:00
|
|
|
|
2018-06-07 06:02:43 +08:00
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 19:10:40 +08:00
|
|
|
private $sUidAttributes = 'uid';
|
2018-06-07 06:02:43 +08:00
|
|
|
|
2015-09-08 05:15:39 +08:00
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 19:10:40 +08:00
|
|
|
private $sNameAttributes = 'displayName,cn,givenName,sn';
|
2015-09-08 05:15:39 +08:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 19:10:40 +08:00
|
|
|
private $sEmailAttributes = 'mailAddress,mail,mailAlternateAddress,mailAlias';
|
2015-09-08 05:15:39 +08:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @var \MailSo\Log\Logger
|
|
|
|
*/
|
|
|
|
private $oLogger = null;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @var string
|
|
|
|
*/
|
2021-08-22 18:54:02 +08:00
|
|
|
private $sAllowedEmails = '*';
|
2015-09-08 05:15:39 +08:00
|
|
|
|
|
|
|
/**
|
2021-08-22 18:17:05 +08:00
|
|
|
* @param string $sLdapUri
|
2021-08-22 16:48:33 +08:00
|
|
|
* @param bool $bUseStartTLS
|
2021-08-22 18:01:43 +08:00
|
|
|
* @param string $sBindDn
|
|
|
|
* @param string $sBindPassword
|
|
|
|
* @param string $sBaseDn
|
2021-08-22 19:32:20 +08:00
|
|
|
* @param string $sObjectClasses
|
2021-08-22 19:10:40 +08:00
|
|
|
* @param string $sNameAttributes
|
|
|
|
* @param string $sEmailAttributes
|
|
|
|
* @param string $sUidAttributes
|
2021-08-22 06:42:38 +08:00
|
|
|
* @param string $sAllowedEmails
|
2015-09-08 05:15:39 +08:00
|
|
|
*
|
|
|
|
* @return \LdapContactsSuggestions
|
|
|
|
*/
|
2021-08-22 19:32:20 +08:00
|
|
|
public function SetConfig($sLdapUri, $bUseStartTLS, $sBindDn, $sBindPassword, $sBaseDn, $sObjectClasses, $sUidAttributes, $sNameAttributes, $sEmailAttributes, $sAllowedEmails)
|
2015-09-08 05:15:39 +08:00
|
|
|
{
|
2021-08-22 18:17:05 +08:00
|
|
|
$this->sLdapUri = $sLdapUri;
|
2021-08-22 16:48:33 +08:00
|
|
|
$this->bUseStartTLS = $bUseStartTLS;
|
2021-08-22 18:01:43 +08:00
|
|
|
if (0 < \strlen($sBindDn))
|
2018-11-30 20:54:28 +08:00
|
|
|
{
|
2021-08-22 18:01:43 +08:00
|
|
|
$this->sBindDn = $sBindDn;
|
|
|
|
$this->sBindPassword = $sBindPassword;
|
2018-11-30 20:54:28 +08:00
|
|
|
}
|
2021-08-22 18:01:43 +08:00
|
|
|
$this->sBaseDn = $sBaseDn;
|
2021-08-22 19:32:20 +08:00
|
|
|
$this->sObjectClasses = $sObjectClasses;
|
2021-08-22 19:10:40 +08:00
|
|
|
$this->sUidAttributes = $sUidAttributes;
|
|
|
|
$this->sNameAttributes = $sNameAttributes;
|
|
|
|
$this->sEmailAttributes = $sEmailAttributes;
|
2015-09-08 05:15:39 +08:00
|
|
|
$this->sAllowedEmails = $sAllowedEmails;
|
|
|
|
|
|
|
|
return $this;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param \RainLoop\Model\Account $oAccount
|
|
|
|
* @param string $sQuery
|
|
|
|
* @param int $iLimit = 20
|
|
|
|
*
|
|
|
|
* @return array
|
|
|
|
*/
|
2020-08-31 00:04:54 +08:00
|
|
|
public function Process(RainLoop\Model\Account $oAccount, string $sQuery, int $iLimit = 20): array
|
2015-09-08 05:15:39 +08:00
|
|
|
{
|
|
|
|
$sQuery = \trim($sQuery);
|
|
|
|
|
|
|
|
if (2 > \strlen($sQuery))
|
|
|
|
{
|
|
|
|
return array();
|
|
|
|
}
|
|
|
|
else if (!$oAccount || !\RainLoop\Plugins\Helper::ValidateWildcardValues($oAccount->Email(), $this->sAllowedEmails))
|
|
|
|
{
|
|
|
|
return array();
|
|
|
|
}
|
|
|
|
|
|
|
|
$aResult = $this->ldapSearch($oAccount, $sQuery);
|
|
|
|
|
|
|
|
$aResult = \RainLoop\Utils::RemoveSuggestionDuplicates($aResult);
|
|
|
|
if ($iLimit < \count($aResult))
|
|
|
|
{
|
|
|
|
$aResult = \array_slice($aResult, 0, $iLimit);
|
|
|
|
}
|
|
|
|
|
|
|
|
return $aResult;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param array $aLdapItem
|
2021-08-22 19:10:40 +08:00
|
|
|
* @param array $aEmailAttributes
|
|
|
|
* @param array $aNameAttributes
|
|
|
|
* @param array $aUidAttributes
|
2015-09-08 05:15:39 +08:00
|
|
|
*
|
|
|
|
* @return array
|
|
|
|
*/
|
2021-08-22 19:10:40 +08:00
|
|
|
private function findNameAndEmail($aLdapItem, $aEmailAttributes, $aNameAttributes, $aUidAttributes)
|
2015-09-08 05:15:39 +08:00
|
|
|
{
|
2018-06-07 06:02:43 +08:00
|
|
|
$sEmail = $sName = $sUid = '';
|
2015-09-08 05:15:39 +08:00
|
|
|
if ($aLdapItem)
|
|
|
|
{
|
2021-08-22 19:10:40 +08:00
|
|
|
foreach ($aEmailAttributes as $sField)
|
2015-09-08 05:15:39 +08:00
|
|
|
{
|
2021-08-22 17:03:56 +08:00
|
|
|
$sField = \strtolower($sField);
|
2015-09-08 05:15:39 +08:00
|
|
|
if (!empty($aLdapItem[$sField][0]))
|
|
|
|
{
|
|
|
|
$sEmail = \trim($aLdapItem[$sField][0]);
|
|
|
|
if (!empty($sEmail))
|
|
|
|
{
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-08-22 19:10:40 +08:00
|
|
|
foreach ($aNameAttributes as $sField)
|
2015-09-08 05:15:39 +08:00
|
|
|
{
|
2021-08-22 17:03:56 +08:00
|
|
|
$sField = \strtolower($sField);
|
2015-09-08 05:15:39 +08:00
|
|
|
if (!empty($aLdapItem[$sField][0]))
|
|
|
|
{
|
|
|
|
$sName = \trim($aLdapItem[$sField][0]);
|
|
|
|
if (!empty($sName))
|
|
|
|
{
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2018-06-07 06:02:43 +08:00
|
|
|
|
2021-08-22 19:10:40 +08:00
|
|
|
foreach ($aUidAttributes as $sField)
|
2018-06-07 06:02:43 +08:00
|
|
|
{
|
2021-08-22 17:03:56 +08:00
|
|
|
$sField = \strtolower($sField);
|
2018-06-07 06:02:43 +08:00
|
|
|
if (!empty($aLdapItem[$sField][0]))
|
|
|
|
{
|
|
|
|
$sUid = \trim($aLdapItem[$sField][0]);
|
|
|
|
if (!empty($sUid))
|
|
|
|
{
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2015-09-08 05:15:39 +08:00
|
|
|
}
|
|
|
|
|
2018-06-07 06:02:43 +08:00
|
|
|
return array($sEmail, $sName, $sUid);
|
2015-09-08 05:15:39 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param \RainLoop\Model\Account $oAccount
|
|
|
|
* @param string $sQuery
|
|
|
|
*
|
|
|
|
* @return array
|
|
|
|
*/
|
|
|
|
private function ldapSearch($oAccount, $sQuery)
|
|
|
|
{
|
|
|
|
$sSearchEscaped = $this->escape($sQuery);
|
|
|
|
|
|
|
|
$aResult = array();
|
2021-08-22 18:17:05 +08:00
|
|
|
$oCon = @\ldap_connect($this->sLdapUri);
|
2015-09-08 05:15:39 +08:00
|
|
|
if ($oCon)
|
|
|
|
{
|
|
|
|
$this->oLogger->Write('ldap_connect: connected', \MailSo\Log\Enumerations\Type::INFO, 'LDAP');
|
|
|
|
|
|
|
|
@\ldap_set_option($oCon, LDAP_OPT_PROTOCOL_VERSION, 3);
|
|
|
|
|
2021-08-22 16:48:33 +08:00
|
|
|
if ($this->bUseStartTLS && !@\ldap_start_tls($oCon))
|
|
|
|
{
|
|
|
|
$this->logLdapError($oCon, 'ldap_start_tls');
|
|
|
|
return $aResult;
|
|
|
|
}
|
|
|
|
|
2021-08-22 18:01:43 +08:00
|
|
|
if (!@\ldap_bind($oCon, $this->sBindDn, $this->sBindPassword))
|
2015-09-08 05:15:39 +08:00
|
|
|
{
|
2021-08-22 18:01:43 +08:00
|
|
|
if (is_null($this->sBindDn))
|
2019-03-28 06:44:29 +08:00
|
|
|
{
|
2018-11-30 20:54:28 +08:00
|
|
|
$this->logLdapError($oCon, 'ldap_bind (anonymous)');
|
2019-03-28 06:44:29 +08:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2018-11-30 20:54:28 +08:00
|
|
|
$this->logLdapError($oCon, 'ldap_bind');
|
|
|
|
}
|
2019-03-28 06:44:29 +08:00
|
|
|
|
2015-09-08 05:15:39 +08:00
|
|
|
return $aResult;
|
|
|
|
}
|
|
|
|
|
|
|
|
$sDomain = \MailSo\Base\Utils::GetDomainFromEmail($oAccount->Email());
|
2021-08-22 18:01:43 +08:00
|
|
|
$sBaseDn = \strtr($this->sBaseDn, array(
|
2015-09-08 05:15:39 +08:00
|
|
|
'{domain}' => $sDomain,
|
|
|
|
'{domain:dc}' => 'dc='.\strtr($sDomain, array('.' => ',dc=')),
|
|
|
|
'{email}' => $oAccount->Email(),
|
|
|
|
'{email:user}' => \MailSo\Base\Utils::GetAccountNameFromEmail($oAccount->Email()),
|
|
|
|
'{email:domain}' => $sDomain,
|
|
|
|
'{login}' => $oAccount->Login(),
|
|
|
|
'{imap:login}' => $oAccount->Login(),
|
|
|
|
'{imap:host}' => $oAccount->DomainIncHost(),
|
|
|
|
'{imap:port}' => $oAccount->DomainIncPort()
|
|
|
|
));
|
|
|
|
|
2021-08-22 19:32:20 +08:00
|
|
|
$aObjectClasses = empty($this->sObjectClasses) ? array() : \explode(',', $this->sObjectClasses);
|
2021-08-22 19:10:40 +08:00
|
|
|
$aEmails = empty($this->sEmailAttributes) ? array() : \explode(',', $this->sEmailAttributes);
|
|
|
|
$aNames = empty($this->sNameAttributes) ? array() : \explode(',', $this->sNameAttributes);
|
|
|
|
$aUIDs = empty($this->sUidAttributes) ? array() : \explode(',', $this->sUidAttributes);
|
2015-09-08 05:15:39 +08:00
|
|
|
|
2021-08-22 19:32:20 +08:00
|
|
|
$aObjectClasses = \array_map('trim', $aObjectClasses);
|
2015-09-08 05:15:39 +08:00
|
|
|
$aEmails = \array_map('trim', $aEmails);
|
|
|
|
$aNames = \array_map('trim', $aNames);
|
2018-06-07 06:02:43 +08:00
|
|
|
$aUIDs = \array_map('trim', $aUIDs);
|
2015-09-08 05:15:39 +08:00
|
|
|
|
2018-06-07 06:02:43 +08:00
|
|
|
$aFields = \array_merge($aEmails, $aNames, $aUIDs);
|
2015-09-08 05:15:39 +08:00
|
|
|
|
2021-08-22 19:32:20 +08:00
|
|
|
$iObjCount = 0;
|
|
|
|
$sObjFilter = '';
|
|
|
|
foreach ($aObjectClasses as $sItem)
|
|
|
|
{
|
|
|
|
if (!empty($sItem))
|
|
|
|
{
|
|
|
|
$iObjCount++;
|
|
|
|
$sObjFilter .= '(objectClass='.$sItem.')';
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2015-09-08 05:15:39 +08:00
|
|
|
$aItems = array();
|
|
|
|
$sSubFilter = '';
|
|
|
|
foreach ($aFields as $sItem)
|
|
|
|
{
|
|
|
|
if (!empty($sItem))
|
|
|
|
{
|
|
|
|
$aItems[] = $sItem;
|
|
|
|
$sSubFilter .= '('.$sItem.'=*'.$sSearchEscaped.'*)';
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-08-22 19:32:20 +08:00
|
|
|
$sFilter = '(&';
|
|
|
|
$sFilter .= (1 < $iObjCount ? '(|' : '').$sObjFilter.(1 < $iObjCount ? ')' : '');
|
2015-09-08 05:15:39 +08:00
|
|
|
$sFilter .= (1 < count($aItems) ? '(|' : '').$sSubFilter.(1 < count($aItems) ? ')' : '');
|
|
|
|
$sFilter .= ')';
|
|
|
|
|
2021-08-22 18:01:43 +08:00
|
|
|
$this->oLogger->Write('ldap_search: start: '.$sBaseDn.' / '.$sFilter, \MailSo\Log\Enumerations\Type::INFO, 'LDAP');
|
|
|
|
$oS = @\ldap_search($oCon, $sBaseDn, $sFilter, $aItems, 0, 30, 30);
|
2015-09-08 05:15:39 +08:00
|
|
|
if ($oS)
|
|
|
|
{
|
|
|
|
$aEntries = @\ldap_get_entries($oCon, $oS);
|
|
|
|
if (is_array($aEntries))
|
|
|
|
{
|
|
|
|
if (isset($aEntries['count']))
|
|
|
|
{
|
|
|
|
unset($aEntries['count']);
|
|
|
|
}
|
|
|
|
|
|
|
|
foreach ($aEntries as $aItem)
|
|
|
|
{
|
|
|
|
if ($aItem)
|
|
|
|
{
|
|
|
|
$sName = $sEmail = '';
|
2018-06-07 06:02:43 +08:00
|
|
|
list ($sEmail, $sName) = $this->findNameAndEmail($aItem, $aEmails, $aNames, $aUIDs);
|
2015-09-08 05:15:39 +08:00
|
|
|
if (!empty($sEmail))
|
|
|
|
{
|
|
|
|
$aResult[] = array($sEmail, $sName);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
$this->logLdapError($oCon, 'ldap_get_entries');
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
$this->logLdapError($oCon, 'ldap_search');
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
return $aResult;
|
|
|
|
}
|
|
|
|
|
|
|
|
return $aResult;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param string $sStr
|
|
|
|
*
|
|
|
|
* @return string
|
|
|
|
*/
|
|
|
|
public function escape($sStr)
|
|
|
|
{
|
|
|
|
$aNewChars = array();
|
|
|
|
$aChars = array('\\', '*', '(', ')', \chr(0));
|
|
|
|
|
|
|
|
foreach ($aChars as $iIndex => $sValue)
|
|
|
|
{
|
|
|
|
$aNewChars[$iIndex] = '\\'.\str_pad(\dechex(\ord($sValue)), 2, '0');
|
|
|
|
}
|
|
|
|
|
|
|
|
return \str_replace($aChars, $aNewChars, $sStr);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param mixed $oCon
|
|
|
|
* @param string $sCmd
|
|
|
|
*
|
|
|
|
* @return string
|
|
|
|
*/
|
|
|
|
public function logLdapError($oCon, $sCmd)
|
|
|
|
{
|
|
|
|
if ($this->oLogger)
|
|
|
|
{
|
|
|
|
$sError = $oCon ? @\ldap_error($oCon) : '';
|
|
|
|
$iErrno = $oCon ? @\ldap_errno($oCon) : 0;
|
|
|
|
|
|
|
|
$this->oLogger->Write($sCmd.' error: '.$sError.' ('.$iErrno.')',
|
|
|
|
\MailSo\Log\Enumerations\Type::WARNING, 'LDAP');
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param \MailSo\Log\Logger $oLogger
|
|
|
|
*
|
|
|
|
* @return \LdapContactsSuggestions
|
|
|
|
*/
|
|
|
|
public function SetLogger($oLogger)
|
|
|
|
{
|
|
|
|
if ($oLogger instanceof \MailSo\Log\Logger)
|
|
|
|
{
|
|
|
|
$this->oLogger = $oLogger;
|
|
|
|
}
|
|
|
|
|
|
|
|
return $this;
|
|
|
|
}
|
|
|
|
}
|