From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 46889921B3 for ; Tue, 28 Mar 2023 16:20:20 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 2FFAC1DD69 for ; Tue, 28 Mar 2023 16:20:20 +0200 (CEST) Received: from proxmox-new.maurer-it.com (proxmox-new.maurer-it.com [94.136.29.106]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS for ; Tue, 28 Mar 2023 16:20:19 +0200 (CEST) Received: from proxmox-new.maurer-it.com (localhost.localdomain [127.0.0.1]) by proxmox-new.maurer-it.com (Proxmox) with ESMTP id CE2EE47206 for ; Tue, 28 Mar 2023 16:20:18 +0200 (CEST) From: Lukas Wagner To: pbs-devel@lists.proxmox.com Date: Tue, 28 Mar 2023 16:20:14 +0200 Message-Id: <20230328142014.727880-1-l.wagner@proxmox.com> X-Mailer: git-send-email 2.30.2 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL -0.165 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Subject: [pbs-devel] [PATCH proxmox-backup] api-types: ldap: add verification regex for LDAP DNs X-BeenThere: pbs-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox Backup Server development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 28 Mar 2023 14:20:20 -0000 Regex was taken from the LDAP implementation in PVE. Signed-off-by: Lukas Wagner --- pbs-api-types/src/ldap.rs | 33 ++++++++++++++++++++++++++++++++- 1 file changed, 32 insertions(+), 1 deletion(-) diff --git a/pbs-api-types/src/ldap.rs b/pbs-api-types/src/ldap.rs index 316b5a65..eabc5249 100644 --- a/pbs-api-types/src/ldap.rs +++ b/pbs-api-types/src/ldap.rs @@ -1,6 +1,8 @@ use serde::{Deserialize, Serialize}; -use proxmox_schema::{api, ApiStringFormat, ApiType, ArraySchema, Schema, StringSchema, Updater}; +use proxmox_schema::{ + api, const_regex, ApiStringFormat, ApiType, ArraySchema, Schema, StringSchema, Updater, +}; use super::{REALM_ID_SCHEMA, SINGLE_LINE_COMMENT_SCHEMA}; @@ -45,6 +47,13 @@ pub enum LdapMode { optional: true, schema: USER_CLASSES_SCHEMA, }, + "base-dn" : { + schema: LDAP_DOMAIN_SCHEMA, + }, + "bind-dn" : { + schema: LDAP_DOMAIN_SCHEMA, + optional: true, + } }, )] #[derive(Serialize, Deserialize, Updater, Clone)] @@ -133,6 +142,28 @@ pub enum RemoveVanished { Properties, } +macro_rules! DOMAIN_PART_REGEX { + () => { + r#"("[^"]+"|[^ ,+"/<>;=#][^,+"/<>;=]*[^ ,+"/<>;=]|[^ ,+"/<>;=#])"# + }; +} + +const_regex! { + pub LDAP_DOMAIN_REGEX = concat!( + r#"\w+="#, + DOMAIN_PART_REGEX!(), + r#"(,\s*\w+="#, + DOMAIN_PART_REGEX!(), + ")*" + ); +} + +pub const LDAP_DOMAIN_FORMAT: ApiStringFormat = ApiStringFormat::Pattern(&LDAP_DOMAIN_REGEX); + +pub const LDAP_DOMAIN_SCHEMA: Schema = StringSchema::new("LDAP Domain") + .format(&LDAP_DOMAIN_FORMAT) + .schema(); + pub const SYNC_DEFAULTS_STRING_SCHEMA: Schema = StringSchema::new("sync defaults options") .format(&ApiStringFormat::PropertyString( &SyncDefaultsOptions::API_SCHEMA, -- 2.30.2