Re: some thoughts about accessing smb shares

Stephan Lauffer <[email protected]> Fri, 24 Feb 2012 14:42:06 +0100
Newsgroups gmane.comp.horde.gollem
Message-ID <[email protected]>
Hi Jan, hello others!

Am 24.02.2012 11:32, schrieb Jan Schneider:
>
> Zitat von Stephan Lauffer <[email protected]>:
>
>> Hello!
>>
>> Thank you for gollem! :)
>>
>> Ok... I think about mounting the so called homeDirectory of a windows
>> user account into the filemanager, into gollem.
>>
>> Since we have a lot of different servers, paths it is not possible to
>> get this working with static informations in backends.local.php.
>>
>> Right now I would like to ask a directory (via) ldap for this path. I
>> think this would match for the most cases.
>>
>> My question is: Do you like this idea? What different ideas do you have?
>>
>> (and yes I'd like to code this feature if there is a goog chance to
>> become this upstream afterwards).
>
> That sounds far too specific to be integrated upstream, but nothing
> speaks against implementing this locally in your configuration file
>

Thank you for your fast response!

Ok... I think nearly every windows domain user has a homedirectory but 
as you explained: It may be to specific for the most horde installations 
and so (poorly for mee) it will not go upstream.

My question now is: Could you please be so kind and take a short look at 
my patch?

Since I am new to the horde world I am realy not sure if the place and 
way how I patched it is done well. :-/

My idea right now is...:

[1] changes on gollem/config/backends.local.php

Three new params for the smb backend: shareLdapURI (and optional 
shareLdapDN, shareLdapPW for non anonymous binds) to query the Microsoft 
ADS (or other ldap servers). The format of shareLdapURI is very close to 
the well known one from Apache called AuthLDAPURL.

example:

	'shareLdapURI' => 
'ldap://123.123.123.123/?ou=users,dc=my,dc=foobar,dc=com?samAccountname?homeDirectory',
	'shareLdapDN' => 'cn=foo bar,dc=my,dc=foobar,dc=com',
	'shareLdapPW' => 'MySecret',

So we search for homeDirectory where samAccountname=horde-use in the 
search base "ou=users,dc=my,dc=foobar,dc=com" at our domain controller 
123.123.123.123.

So if there is a defined shareLdapURI in our backend config than...

[2] changes on pear/php/Horde/Vfs/Smb.php

Test if there is a homeDirectory path found in the DS. If not, fall back 
to the already known "share" params.

Now... I don't know if this is a good place to things like this in 
Smb.php. And... maybe I had to take an horde specific ldap class...? How 
should I handle errors or warnings?

It would be very helpfully for my to know what you think...

Thank you!

(may I should ask my question on the devel list...?)

-- 
Freundliche Gruesse,
Stephan Lauffer

[ University of Education Freiburg - Germany ]
[ http://www.ph-freiburg.de/zik/             ]
[ Fon/ Fax: +49 761 682 -559/ -486           ]

-- 
Gollem mailing list
Frequently Asked Questions: http://horde.org/faq/
To unsubscribe, mail: [email protected]
Smb.php-shareLdapURI.patch (text/plain, 2 KB)
--- pear/php/Horde/Vfs/Smb-orig.php	2012-02-24 14:03:17.000000000 +0100
+++ pear/php/Horde/Vfs/Smb.php	2012-02-24 14:25:51.000000000 +0100
@@ -626,3 +626,51 @@
     {
-        list($share) = $this->_escapeShellCommand($this->_params['share']);
+	$share = NULL;
+
+	if (isset($this->_params['shareLdapURI'])) {
+
+		# Test if param shareLdapURI is set.
+		# If true query LDAP server for the share to mount.
+		# If shareLdapURI is unset we will take the data from 'share'
+
+		$ldap_share_path = mb_split("\?", $this->_params['shareLdapURI']);
+
+		$ds = @ldap_connect($ldap_share_path[0]);
+		if (!$ds)  {
+			throw new Horde_Vfs_Exception("LDAP connection error");
+		}
+
+		if (isset($this->_params['shareLdapDN']) && isset($this->_params['shareLdapPW'])) {
+			$lb = @ldap_bind( 	$ds,	
+						$this->_params['shareLdapDN'],
+						$this->_params['shareLdapPW']);
+		} else {
+			$lb = @ldap_bind($ds);
+		}	
+
+		if (!$lb) {
+			throw new Horde_Vfs_Exception(ldap_error($ds));
+		}
+
+		$justthese = array($ldap_share_path[3]);
+		$sr = ldap_list(	$ds,
+					$ldap_share_path[1],
+					$ldap_share_path[2] . "=" . $this->_params['username'],
+					$justthese);
+		$result = ldap_get_entries($ds, $sr);
+	
+		if ($ds) @ldap_unbind($ds);
+
+		if ($result['count']==1) {
+			$share = $result[0][$ldap_share_path[3]][0];
+			$splitarr = preg_split('/\\\/',$share);
+
+			$fullpath = '//'.implode('/',array_slice($splitarr,2,2));
+			$path = implode('/',array_slice($splitarr,4));
+		}
+	}
+	if (!isset($share)) { 
+		list($share) = $this->_escapeShellCommand($this->_params['share']);
+		$fullpath = '//' . $this->_params['hostspec'] . '/' . $share;
+	}
+	
         putenv('PASSWD=' . $this->_params['password']);
@@ -630,5 +678,6 @@
         $fullcmd = $this->_params['smbclient'] .
-            ' "//' . $this->_params['hostspec'] . '/' . $share . '"' .
+            ' "' . $fullpath . '"' .
             ' "-p' . $this->_params['port'] . '"' .
             ' "-U' . $this->_params['username'] . '"' .
+            ' "-W' . $this->_params['domain'] . '"' .
             ' -D "' . $path . '" ' .
smime.p7s (application/pkcs7-signature, 4.8 KB) - not displayed