'fieldset', '#title' => t('Synchronizing options'), '#collapsible' => TRUE, '#collapsed' => FALSE, ); $form['sync']['ldapdata_sync'] = array( '#type' => 'radios', '#title' => t('Synchronize LDAP data with Drupal profiles'), '#options' => array(t('When user logs in. (Use when LDAP rarely changes.)'), t('On each page load.'), t('Every time user object loaded in Drupal. (May cause high LDAP traffic.)')), '#default_value' => LDAPDATA_SYNC, '#description' => t('User edition will always synchronize the data despite the selection above.'), ); $form['submit'] = array( '#type' => 'submit', '#value' => t('Save configuration'), ); $form['reset'] = array( '#type' => 'submit', '#value' => t('Reset to defaults'), ); $form['list']['#value'] = ldapdata_admin_list(); return $form; } /** * Submit hook for the settings form. */ function ldapdata_admin_settings_submit($form, &$form_state) { $op = $form_state['clicked_button']['#value']; $values = $form_state['values']; switch ($op) { case t('Save configuration'): variable_set('ldapdata_sync', $values['ldapdata_sync']); drupal_set_message(t('The configuration options have been saved.')); break; case t('Reset to defaults'): variable_del('ldapdata_sync'); drupal_set_message(t('The configuration options have been reset to their default values.')); break; } } /** * Implements the LDAP servers list. * * @return * The HTML table with the servers list. */ function ldapdata_admin_list() { $rows = array(); $result = db_query("SELECT sid, name, status FROM {ldapauth} ORDER BY weight"); while ($row = db_fetch_object($result)) { $rows[] = array( 'data' => array( $row->name, l(t('edit'), 'admin/settings/ldap/ldapdata/edit/'. $row->sid), l(t('reset'), 'admin/settings/ldap/ldapdata/reset/'. $row->sid), ), 'class' => $row->status ? 'menu-enabled' : 'menu-disabled', ); } $header = array( t('Server'), array('data' => t('Operations'), 'colspan' => 2), ); return theme('table', $header, $rows); } /** * Implements the LDAP server edit page. * * @param $form_state * A form state array. * @param $op * An operatin - edit or reset. * @param $sid * A LDAP server ID. * * @return * The form structure. */ function ldapdata_admin_edit(&$form_state, $op, $sid) { if ($op == "reset" && $sid) { $form['sid'] = array( '#type' => 'value', '#value' => $sid, ); return confirm_form( $form, t('Are you sure you want to reset the fields mapping to defaults ?'), 'admin/settings/ldap/ldapdata', t('This action cannot be undone.
'), t('Reset'), t('Cancel') ); } elseif ($op == "edit" && $sid) { $edit = db_fetch_array(db_query("SELECT * FROM {ldapauth} WHERE sid = %d", $sid)); $ldapdata_mappings = $edit['ldapdata_mappings'] ? unserialize($edit['ldapdata_mappings']) : array(); $ldapdata_roattrs = $edit['ldapdata_roattrs'] ? unserialize($edit['ldapdata_roattrs']) : array(); $ldapdata_rwattrs = $edit['ldapdata_rwattrs'] ? unserialize($edit['ldapdata_rwattrs']) : array(); $ldapdata_attrs = $edit['ldapdata_attrs'] ? unserialize($edit['ldapdata_attrs']) : array(); $form['description'] = array( '#value' => t('Configure profile synchronization settings for %server.', array('%server' => $edit['name'])), ); // Attribute mapping. $form['mapping'] = array( '#type' => 'fieldset', '#title' => t('Drupal-LDAP fields mapping'), '#collapsible' => TRUE, '#collapsed' => FALSE, ); $form['mapping']['ldapdata_mapping'] = array( '#type' => 'radios', '#title' => t('Drupal user profile field mapping'), '#default_value' => isset($ldapdata_mappings['access']) ? $ldapdata_mappings['access'] : LDAPDATA_MAP_ATTRIBUTES, '#options' => array( LDAPDATA_MAP_NOTHING => t('No mapping. (Clears any mappings defined below.)'), LDAPDATA_MAP_ATTRIBUTES_READ_ONLY => t('Read only: Drupal user profile fields have LDAP attributes.'), LDAPDATA_MAP_ATTRIBUTES => t('Read/write: Drupal user profile fields have LDAP attributes. LDAP attributes updated upon Drupal profile change.'), ), ); $profile_fields = _ldapdata_retrieve_profile_fields(); $standard_fields = _ldapdata_retrieve_standard_user_fields(); $drupal_fields = $profile_fields + $standard_fields; $form['mapping']['mapping_pre'] = array( '#value' => t('Drupal field | LDAP attribute |
---|---|
"; $form['mapping'][$field_tmp] = array( '#type' => 'textfield', '#default_value' => isset($ldapdata_mappings[$field_tmp]) ? $ldapdata_mappings[$field_tmp] : NULL, '#size' => '20', '#prefix' => $_prefix, '#suffix' => ' | ', ); } $form['mapping']['mapping_post'] = array( '#value' => '
cn|text|textfield|Common Name|64|64
homePage|url|textfield|Other web pages|64|64
'),
);
$fields = $rooptions = $rwoptions = $roattrs = $rwattrs = array();
foreach ($ldapdata_attrs as $attr => $data) {
$fields[$attr] = $data[2];
}
foreach ($fields as $attr => $attr_name) {
$rooptions[$attr] = '';
$rwoptions[$attr] = '';
if (in_array($attr, $ldapdata_roattrs))
$roattrs[] = $attr;
if (in_array($attr, $ldapdata_rwattrs))
$rwattrs[] = $attr;
$form['attributes']['table'][$attr] = array(
'#value' => $attr_name,
);
}
$form['attributes']['ldapdata_roattrs'] = array(
'#type' => 'checkboxes',
'#options' => $rooptions,
'#default_value' => $roattrs,
);
$form['attributes']['ldapdata_rwattrs'] = array(
'#type' => 'checkboxes',
'#options' => $rwoptions,
'#default_value' => $rwattrs,
);
$form['attributes']['header'] = array(
'#type' => 'value',
'#value' => array(
array('data' => t('Attribute name')),
array('data' => t('Readable by user?')),
array('data' => t('Editable by user?')),
)
);
$form['attributes']['ldapdata_filter_php'] = array(
'#type' => 'textarea',
'#title' => t('PHP to filter attributes'),
'#default_value' => $edit['ldapdata_filter_php'],
'#cols' => 25,
'#rows' => 5,
'#description' => t('Enter PHP to filter LDAP attributes. Careful, bad PHP code here will break your site. If left empty, no filtering will be done. If filter is set, then attributes will be only readable. The LDAP atributes array $attributes
is available in the code context. The code should return a filtered $attributes
array as in example bellow:$attributes[\'mail\'][0] = preg_replace(\'/([^@]+@).*/\', \'$1mail.com\', $attributes[\'mail\'][0]);
return $attributes;
'),
);
// Advanced configuration.
$form['advanced'] = array(
'#type' => 'fieldset',
'#title' => t('Advanced configuration'),
'#description' => t('When reading/editing attributes, this module logs on to the LDAP directory using the user\'s DN/pass pair. However, many LDAP setups do not allow their users to edit attributes.
If this is your case, but still you want users to edit their LDAP attributes via Drupal, you should set up an special user on your directory, with special access to edit your users\' attributes. Then this module will use it to log on and edit data.
"Test" tries authentication with the saved DN and password and prints the result.
'), '#collapsible' => TRUE, '#collapsed' => TRUE ); $form['advanced']['ldapdata_binddn'] = array( '#type' => 'textfield', '#title' => t('DN for reading/editing attributes'), '#default_value' => $edit['ldapdata_binddn'], '#size' => 50, '#maxlength' => 255, ); if (!$edit['ldapdata_bindpw']) { $form['advanced']['ldapdata_bindpw'] = array( '#type' => 'password', '#title' => t('Password for reading/editing attributes'), '#size' => 50, '#maxlength' => 255, ); } else { // Given an option to clear the password. $form['advanced']['ldapdata_bindpw_clear'] = array( '#type' => 'checkbox', '#default_value' => FALSE, '#title' => t('Clear current password'), ); } $form['advanced']['test'] = array( '#type' => 'submit', '#value' => t('Test'), ); $form['sid'] = array( '#type' => 'hidden', '#value' => $sid, ); $form['buttons']['submit'] = array( '#type' => 'submit', '#value' => t('Update'), ); return $form; } else { drupal_goto('admin/settings/ldap/ldapdata'); } } /** * Validate hook for the settings form. */ function ldapdata_admin_edit_validate($form, &$form_state) { $op = $form_state['clicked_button']['#value']; $values = $form_state['values']; switch ($op) { case t('Update'): $form_state['ldapdata_attrs'] = array(); $ldapdata_attrs = TRUE; foreach ((trim($values['attributes']['ldapdata_attrs']) ? explode("\n", trim($values['attributes']['ldapdata_attrs'])) : array()) as $line) { if (count($data = explode('|', trim($line))) == 6) $form_state['ldapdata_attrs'] += array(trim(array_shift($data)) => $data); else $ldapdata_attrs = FALSE; } if (!$ldapdata_attrs) form_set_error('attributes][ldapdata_attrs', t('Bad attribute syntax.')); $form_state['ldapdata_mappings'] = array(); $form_state['ldapdata_mappings']['access'] = $values['ldapdata_mapping']; if ($form_state['ldapdata_mappings']['access'] >= 4) { foreach (element_children($values) as $attr) { if (preg_match("/ldap_amap/", $attr) && $values[$attr]) $form_state['ldapdata_mappings'][$attr] = $values[$attr]; } } $form_state['ldapdata_mappings'] = !empty($form_state['ldapdata_mappings']) ? serialize($form_state['ldapdata_mappings']) : ''; $form_state['ldapdata_roattrs'] = isset($values['attributes']['ldapdata_roattrs']) ? array_values(array_intersect($values['attributes']['ldapdata_roattrs'], array_keys($form_state['ldapdata_attrs']))) : array(); $form_state['ldapdata_roattrs'] = !empty($form_state['ldapdata_roattrs']) ? serialize($form_state['ldapdata_roattrs']) : ''; $form_state['ldapdata_rwattrs'] = isset($values['attributes']['ldapdata_rwattrs']) ? array_values(array_intersect($values['attributes']['ldapdata_rwattrs'], array_keys($form_state['ldapdata_attrs']))) : array(); $form_state['ldapdata_rwattrs'] = !empty($form_state['ldapdata_rwattrs']) ? serialize($form_state['ldapdata_rwattrs']) : ''; $form_state['ldapdata_attrs'] = !empty($form_state['ldapdata_attrs']) ? serialize($form_state['ldapdata_attrs']) : ''; $form_state['ldapdata_filter_php'] = trim($values['attributes']['ldapdata_filter_php']); $form_state['ldapdata_rwattrs'] = empty($form_state['ldapdata_filter_php']) ? $form_state['ldapdata_rwattrs'] : ''; break; } } /** * Submit hook for the settings form. */ function ldapdata_admin_edit_submit($form, &$form_state) { $op = $form_state['clicked_button']['#value']; $values = $form_state['values']; switch ($op) { case t('Update'): if (isset($values['ldapdata_bindpw_clear'])) { db_query("UPDATE {ldapauth} SET ldapdata_mappings = '%s', ldapdata_roattrs = '%s', ldapdata_rwattrs = '%s', ldapdata_binddn = '%s', ldapdata_attrs = '%s', ldapdata_filter_php = '%s' WHERE sid = %d", $form_state['ldapdata_mappings'], $form_state['ldapdata_roattrs'], $form_state['ldapdata_rwattrs'], $values['ldapdata_binddn'], $form_state['ldapdata_attrs'], $form_state['ldapdata_filter_php'], $values['sid']); if ($values['ldapdata_bindpw_clear']) { db_query("UPDATE {ldapauth} SET ldapdata_bindpw = '' WHERE sid = %d", $values['sid']); } } else { db_query("UPDATE {ldapauth} SET ldapdata_mappings = '%s', ldapdata_roattrs = '%s', ldapdata_rwattrs = '%s', ldapdata_binddn = '%s', ldapdata_bindpw = '%s', ldapdata_attrs = '%s', ldapdata_filter_php = '%s' WHERE sid = %d", $form_state['ldapdata_mappings'], $form_state['ldapdata_roattrs'], $form_state['ldapdata_rwattrs'], $values['ldapdata_binddn'], $values['ldapdata_bindpw'], $form_state['ldapdata_attrs'], $form_state['ldapdata_filter_php'], $values['sid']); } drupal_set_message(t('The configuration options have been saved.')); $form_state['redirect'] = 'admin/settings/ldap/ldapdata'; break; case t('Reset'): if ($values['confirm'] == 1) { // Settings reset. db_query("UPDATE {ldapauth} SET ldapdata_mappings = '', ldapdata_roattrs = '', ldapdata_rwattrs = '', ldapdata_binddn = '', ldapdata_bindpw = '', ldapdata_attrs = '', ldapdata_filter_php = '' WHERE sid = %d", $values['sid']); drupal_set_message(t('The configuration options have been reset to their default values.')); } $form_state['redirect'] = 'admin/settings/ldap/ldapdata'; break; case t('Test'): global $_ldapdata_ldap; if (isset($values['sid']) && _ldapdata_init($values['sid'])) { // Try to authenticate. $bind_info = _ldapdata_edition($values['sid']); if (!$_ldapdata_ldap->connect($bind_info['dn'], $bind_info['pass'])) { drupal_set_message(t('Authentication with the LDAP server for the dn %dn and saved password failed.', array('%dn' => $bind_info['dn'])), 'error'); } else { drupal_set_message(t('Authentication with the LDAP server for the dn %dn and saved password succeeded.', array('%dn' => $bind_info['dn']))); } } else { drupal_set_message(t('Cannot load server settings. Please save configuration first.'), 'error'); } break; } }