rbac.h revision 1.3 1 1.1 christos /* $NetBSD: rbac.h,v 1.3 2025/09/05 21:16:18 christos Exp $ */
2 1.1 christos
3 1.1 christos /* rbac.h - */
4 1.1 christos /* $OpenLDAP$ */
5 1.1 christos /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
6 1.1 christos *
7 1.3 christos * Copyright 1999-2024 The OpenLDAP Foundation.
8 1.1 christos * All rights reserved.
9 1.1 christos *
10 1.1 christos * Redistribution and use in source and binary forms, with or without
11 1.1 christos * modification, are permitted only as authorized by the OpenLDAP
12 1.1 christos * Public License.
13 1.1 christos *
14 1.1 christos * A copy of this license is available in the file LICENSE in the
15 1.1 christos * top-level directory of the distribution or, alternatively, at
16 1.1 christos * <http://www.OpenLDAP.org/license.html>.
17 1.1 christos */
18 1.1 christos /* ACKNOWLEDGEMENTS:
19 1.1 christos *
20 1.1 christos */
21 1.1 christos
22 1.1 christos #ifndef RBAC_H
23 1.1 christos #define RBAC_H
24 1.1 christos
25 1.1 christos LDAP_BEGIN_DECL
26 1.1 christos
27 1.1 christos #include "ldap_rbac.h"
28 1.1 christos
29 1.1 christos #define USE_NEW_THREAD_CONTEXT 1
30 1.1 christos #define RBAC_BUFLEN 1024
31 1.1 christos
32 1.1 christos /* tenant initialization op */
33 1.1 christos #define INIT_AUDIT_CONTAINER 0x01
34 1.1 christos #define INIT_SESSION_CONTAINER 0x02
35 1.1 christos
36 1.1 christos typedef struct rbac_ad {
37 1.1 christos int type;
38 1.1 christos struct berval attr;
39 1.1 christos AttributeDescription **ad;
40 1.1 christos } rbac_ad_t;
41 1.1 christos
42 1.1 christos /* RBAC AttributeDescriptions */
43 1.1 christos struct slap_rbac_internal_schema {
44 1.1 christos /* slapd schema */
45 1.1 christos AttributeDescription *ad_uid;
46 1.1 christos
47 1.1 christos /* RBAC tenant */
48 1.1 christos AttributeDescription *ad_tenant_id;
49 1.1 christos
50 1.1 christos /* RBAC sessions */
51 1.1 christos AttributeDescription *ad_session_id;
52 1.1 christos AttributeDescription *ad_session_user_dn;
53 1.1 christos AttributeDescription *ad_session_roles;
54 1.1 christos AttributeDescription *ad_session_role_constraints;
55 1.1 christos
56 1.1 christos /* RBAC session permissions */
57 1.1 christos AttributeDescription *ad_permission_opname;
58 1.1 christos AttributeDescription *ad_permission_objname;
59 1.1 christos AttributeDescription *ad_permission_rolename;
60 1.1 christos
61 1.1 christos /* RBAC audit */
62 1.1 christos AttributeDescription *ad_audit_op; /* rbac op: create_session */
63 1.1 christos AttributeDescription *ad_audit_id;
64 1.1 christos AttributeDescription *ad_audit_roles;
65 1.1 christos AttributeDescription *ad_audit_requested_roles;
66 1.1 christos AttributeDescription *ad_audit_timestamp;
67 1.1 christos AttributeDescription *ad_audit_resources;
68 1.1 christos AttributeDescription *ad_audit_objects;
69 1.1 christos AttributeDescription *ad_audit_operations; /* resource ops */
70 1.1 christos AttributeDescription *ad_audit_result;
71 1.1 christos AttributeDescription *ad_audit_properties;
72 1.1 christos AttributeDescription *ad_audit_messages;
73 1.1 christos
74 1.1 christos /* RBAC session attributes */
75 1.1 christos AttributeName *session_attrs;
76 1.1 christos };
77 1.1 christos
78 1.1 christos extern struct slap_rbac_internal_schema slap_rbac_schema;
79 1.1 christos
80 1.1 christos /* attributes in tenant repository */
81 1.1 christos struct slap_rbac_tenant_schema {
82 1.1 christos /* user role assignments, role constraints, and user constraint */
83 1.1 christos AttributeDescription *ad_role;
84 1.1 christos AttributeDescription *ad_role_constraint;
85 1.1 christos AttributeDescription *ad_user_constraint;
86 1.1 christos AttributeDescription *ad_uid;
87 1.1 christos
88 1.1 christos /* session permission */
89 1.1 christos AttributeDescription *ad_permission_users;
90 1.1 christos AttributeDescription *ad_permission_roles;
91 1.1 christos AttributeDescription *ad_permission_objname;
92 1.1 christos AttributeDescription *ad_permission_opname;
93 1.1 christos
94 1.1 christos /* the list of attributes when doing searches in the jts repo */
95 1.1 christos AttributeName *user_attrs;
96 1.1 christos AttributeName *perm_attrs; /* attrs to retrieve for check access */
97 1.1 christos AttributeName *session_perm_attrs; /* attrs for session permissions */
98 1.1 christos
99 1.1 christos /* the corresponding list of attribute description mapping */
100 1.1 christos rbac_ad_t *user_ads;
101 1.1 christos rbac_ad_t *permission_ads;
102 1.1 christos rbac_ad_t *session_permissions_ads;
103 1.1 christos };
104 1.1 christos
105 1.1 christos extern struct slap_rbac_tenant_schema slap_rbac_jts_schema;
106 1.1 christos
107 1.1 christos /* types of RBAC requests */
108 1.1 christos typedef struct rbac_request {
109 1.1 christos int req_type;
110 1.1 christos struct berval sessid;
111 1.1 christos struct berval tenantid;
112 1.1 christos
113 1.1 christos /* session creation */
114 1.1 christos struct berval uid;
115 1.1 christos struct berval authtok;
116 1.1 christos BerVarray roles;
117 1.1 christos struct berval role;
118 1.1 christos
119 1.1 christos /* check access */
120 1.1 christos struct berval opname;
121 1.1 christos struct berval objname;
122 1.1 christos struct berval objid;
123 1.1 christos } rbac_req_t;
124 1.1 christos
125 1.1 christos typedef struct rbac_constraint {
126 1.1 christos struct berval name; /* user name or role name */
127 1.1 christos int allowed_inactivity; /* secs */
128 1.1 christos int begin_time; /* secs */
129 1.1 christos int end_time; /* secs */
130 1.1 christos lutil_timet begin_date;
131 1.1 christos lutil_timet end_date;
132 1.1 christos lutil_timet begin_lock_date;
133 1.1 christos lutil_timet end_lock_date;
134 1.1 christos int day_mask;
135 1.1 christos struct rbac_constraint *next;
136 1.1 christos } rbac_constraint_t;
137 1.1 christos
138 1.1 christos /* holds RBAC info */
139 1.1 christos typedef struct tenant_info {
140 1.1 christos struct berval tid; /* tenant id */
141 1.1 christos struct berval admin;
142 1.1 christos struct berval pwd;
143 1.1 christos struct berval users_basedn;
144 1.1 christos struct berval roles_basedn;
145 1.1 christos struct berval audit_basedn;
146 1.1 christos struct berval permissions_basedn;
147 1.1 christos struct berval sessions_basedn;
148 1.1 christos struct berval session_admin;
149 1.1 christos struct berval session_admin_pwd;
150 1.1 christos struct slap_rbac_tenant_schema *schema;
151 1.1 christos } tenant_info_t;
152 1.1 christos
153 1.1 christos typedef struct rbac_tenant {
154 1.1 christos tenant_info_t tenant_info;
155 1.1 christos struct rbac_tenant *next;
156 1.1 christos } rbac_tenant_t;
157 1.1 christos
158 1.1 christos /* for RBAC callback */
159 1.1 christos typedef struct rbac_callback_info {
160 1.1 christos tenant_info_t *tenantp;
161 1.1 christos void *private;
162 1.1 christos } rbac_callback_info_t;
163 1.1 christos
164 1.1 christos /* RBAC user */
165 1.1 christos typedef struct rbac_user {
166 1.1 christos struct berval tenantid;
167 1.1 christos struct berval uid;
168 1.1 christos struct berval dn;
169 1.1 christos struct berval constraints;
170 1.1 christos struct berval password;
171 1.1 christos struct berval msg;
172 1.1 christos int authz; /* flag for bind (pwd policy) info */
173 1.1 christos BerVarray roles;
174 1.1 christos BerVarray role_constraints;
175 1.1 christos #if 0 /* additional parameters from Fortress */
176 1.1 christos private String userId;
177 1.1 christos @XmlElement(nillable = true)
178 1.1 christos private char[] password;
179 1.1 christos @XmlElement(nillable = true)
180 1.1 christos private char[] newPassword;
181 1.1 christos private String internalId;
182 1.1 christos @XmlElement(nillable = true)
183 1.1 christos private List<UserRole> roles;
184 1.1 christos @XmlElement(nillable = true)
185 1.1 christos private List<UserAdminRole> adminRoles;
186 1.1 christos private String pwPolicy;
187 1.1 christos private String cn;
188 1.1 christos private String sn;
189 1.1 christos private String dn;
190 1.1 christos private String ou;
191 1.1 christos private String description;
192 1.1 christos private String beginTime;
193 1.1 christos private String endTime;
194 1.1 christos private String beginDate;
195 1.1 christos private String endDate;
196 1.1 christos private String beginLockDate;
197 1.1 christos private String endLockDate;
198 1.1 christos private String dayMask;
199 1.1 christos private String name;
200 1.1 christos private int timeout;
201 1.1 christos private boolean reset;
202 1.1 christos private boolean locked;
203 1.1 christos private Boolean system;
204 1.1 christos @XmlElement(nillable = true)
205 1.1 christos private Props props = new Props();
206 1.1 christos @XmlElement(nillable = true)
207 1.1 christos private Address address;
208 1.1 christos @XmlElement(nillable = true)
209 1.1 christos private List<String> phones;
210 1.1 christos @XmlElement(nillable = true)
211 1.1 christos private List<String> mobiles;
212 1.1 christos @XmlElement(nillable = true)
213 1.1 christos private List<String> emails;
214 1.1 christos #endif /* 0 */
215 1.1 christos } rbac_user_t;
216 1.1 christos
217 1.1 christos enum {
218 1.1 christos RBAC_NONE = 0,
219 1.1 christos RBAC_TENANT,
220 1.1 christos RBAC_TENANT_ID,
221 1.1 christos RBAC_USERS_BASE_DN,
222 1.1 christos RBAC_ROLES_BASE_DN,
223 1.1 christos RBAC_PERMISSIONS_BASE_DN,
224 1.1 christos RBAC_ADMIN_DN,
225 1.1 christos RBAC_ADMIN_PWD,
226 1.1 christos RBAC_SESSIONS_BASE_DN,
227 1.1 christos RBAC_SESSION_ADMIN_DN,
228 1.1 christos RBAC_SESSION_ADMIN_PWD,
229 1.1 christos RBAC_ROLE_ASSIGNMENT,
230 1.1 christos RBAC_ROLE_CONSTRAINTS,
231 1.1 christos RBAC_USER_CONSTRAINTS,
232 1.1 christos RBAC_UID,
233 1.1 christos RBAC_USERS,
234 1.1 christos RBAC_ROLES,
235 1.1 christos RBAC_OBJ_NAME,
236 1.1 christos RBAC_OP_NAME,
237 1.1 christos RBAC_ROLE_NAME,
238 1.1 christos RBAC_SESSION_ID,
239 1.1 christos RBAC_USER_DN,
240 1.1 christos RBAC_AUDIT_ROLES,
241 1.1 christos RBAC_AUDIT_RESOURCES,
242 1.1 christos RBAC_AUDIT_RESULT,
243 1.1 christos RBAC_AUDIT_TIMESTAMP,
244 1.1 christos RBAC_AUDIT_PROPERTIES,
245 1.1 christos RBAC_AUDIT_OP,
246 1.1 christos RBAC_AUDIT_ID,
247 1.1 christos RBAC_AUDIT_REQUESTED_ROLES,
248 1.1 christos RBAC_AUDIT_OBJS,
249 1.1 christos RBAC_AUDIT_OPS,
250 1.1 christos RBAC_AUDIT_MSGS,
251 1.1 christos RBAC_LAST
252 1.1 christos };
253 1.1 christos
254 1.1 christos enum {
255 1.1 christos RBAC_DEFAULT_TENANT_ID = RBAC_LAST,
256 1.1 christos RBAC_DEFAULT_USERS_BASE_DN,
257 1.1 christos RBAC_DEFAULT_PERMISSIONS_BASE_DN,
258 1.1 christos RBAC_DEFAULT_ROLES_BASE_DN,
259 1.1 christos RBAC_DEFAULT_SESSIONS_BASE_DN,
260 1.1 christos RBAC_DEFAULT_AUDIT_BASE_DN
261 1.1 christos };
262 1.1 christos
263 1.1 christos typedef struct rbac_user_idlist {
264 1.1 christos char *user_id;
265 1.1 christos struct rbac_user_idlist *next;
266 1.1 christos } rbac_user_idlist_t;
267 1.1 christos
268 1.1 christos /* RBAC sessions */
269 1.1 christos #define RBAC_SESSION_RDN_EQ "rbacSessid="
270 1.1 christos #define RBAC_AUDIT_RDN_EQ "rbacAuditId="
271 1.1 christos
272 1.1 christos typedef struct rbac_session {
273 1.1 christos rbac_user_t *user;
274 1.1 christos struct berval tenantid;
275 1.1 christos struct berval sessid;
276 1.1 christos struct berval uid;
277 1.1 christos struct berval userdn;
278 1.1 christos char uuidbuf[ LDAP_LUTIL_UUIDSTR_BUFSIZE ];
279 1.1 christos struct berval sessdn;
280 1.1 christos long last_access;
281 1.1 christos int timeout;
282 1.1 christos int warning_id;
283 1.1 christos int error_id;
284 1.1 christos int grace_logins;
285 1.1 christos int expiration_secs;
286 1.1 christos int is_authenticated; /* boolean */
287 1.1 christos struct berval message;
288 1.1 christos BerVarray roles;
289 1.1 christos BerVarray role_constraints;
290 1.1 christos } rbac_session_t;
291 1.1 christos
292 1.1 christos /* RBAC roles */
293 1.1 christos typedef struct rbac_role {
294 1.1 christos char *name;
295 1.1 christos char *description;
296 1.1 christos struct rbac_role *parent;
297 1.1 christos struct rbac_role *next;
298 1.1 christos } rbac_role_t;
299 1.1 christos
300 1.1 christos typedef struct rbac_role_list {
301 1.1 christos char *name;
302 1.1 christos struct rbac_role_list *next;
303 1.1 christos } rbac_role_list_t;
304 1.1 christos
305 1.1 christos /* RBAC permissions */
306 1.1 christos typedef struct rbac_permission {
307 1.1 christos struct berval dn;
308 1.1 christos int admin; /* boolean */
309 1.1 christos struct berval internalId;
310 1.1 christos BerVarray opName;
311 1.1 christos BerVarray objName;
312 1.1 christos struct berval objectId;
313 1.1 christos struct berval abstractName;
314 1.1 christos struct berval type;
315 1.1 christos BerVarray roles;
316 1.1 christos BerVarray uids;
317 1.1 christos struct rbac_permission *next;
318 1.1 christos } rbac_permission_t;
319 1.1 christos
320 1.1 christos /* RBAC Audit */
321 1.1 christos typedef enum {
322 1.1 christos CreateSession = 0,
323 1.1 christos CheckAccess,
324 1.1 christos AddActiveRole,
325 1.1 christos DropActiveRole,
326 1.1 christos SessionPermissions,
327 1.1 christos DeleteSession,
328 1.1 christos SessionRoles
329 1.1 christos } audit_op_t;
330 1.1 christos
331 1.1 christos /* function prototypes */
332 1.1 christos
333 1.1 christos int rbac_initialize_repository( void );
334 1.1 christos int rbac_initialize_tenants( BackendDB *be, ConfigReply *cr );
335 1.1 christos
336 1.1 christos /* RBAC tenant information */
337 1.1 christos tenant_info_t *rbac_tid2tenant( struct berval *tid );
338 1.1 christos
339 1.1 christos rbac_req_t *rbac_alloc_req( int type );
340 1.1 christos void rbac_free_req( rbac_req_t *reqp );
341 1.1 christos
342 1.1 christos rbac_user_t *rbac_read_user( Operation *op, rbac_req_t *rabc_reqp );
343 1.1 christos int rbac_authenticate_user( Operation *op, rbac_user_t *user );
344 1.1 christos int rbac_user_temporal_constraint( rbac_user_t *userp );
345 1.1 christos void rbac_free_user( rbac_user_t *user );
346 1.1 christos
347 1.1 christos rbac_session_t *rbac_alloc_session( void );
348 1.1 christos int rbac_is_valid_session_id( struct berval *sessid );
349 1.1 christos rbac_session_t *rbac_session_byid( Operation *op, rbac_req_t *reqp );
350 1.1 christos int rbac_is_session_owner( rbac_session_t *sessp, rbac_req_t *reqp );
351 1.1 christos int rbac_register_session( Operation *op, SlapReply *rs, rbac_session_t *sess );
352 1.1 christos int rbac_int_delete_session( Operation *op, rbac_session_t *sessp );
353 1.1 christos int rbac_session_add_role(
354 1.1 christos Operation *op,
355 1.1 christos rbac_session_t *sessp,
356 1.1 christos rbac_req_t *reqp );
357 1.1 christos int rbac_session_drop_role(
358 1.1 christos Operation *op,
359 1.1 christos rbac_session_t *sessp,
360 1.1 christos rbac_req_t *reqp );
361 1.1 christos int rbac_int_session_permissions(
362 1.1 christos Operation *op,
363 1.1 christos SlapReply *rs,
364 1.1 christos rbac_req_t *reqp,
365 1.1 christos rbac_session_t *sessp );
366 1.1 christos int activate_session_roles(
367 1.1 christos rbac_session_t *sessp,
368 1.1 christos rbac_req_t *reqp,
369 1.1 christos rbac_user_t *userp );
370 1.1 christos void rbac_free_session( rbac_session_t *sessp );
371 1.1 christos
372 1.1 christos rbac_constraint_t *rbac_user_role_constraints( BerVarray values );
373 1.1 christos rbac_constraint_t *rbac_role2constraint(
374 1.1 christos struct berval *role,
375 1.1 christos rbac_constraint_t *role_constraints );
376 1.1 christos rbac_constraint_t *rbac_bv2constraint( struct berval *bv );
377 1.1 christos int rbac_check_time_constraint( rbac_constraint_t *cp );
378 1.1 christos void rbac_free_constraint( rbac_constraint_t *cp );
379 1.1 christos void rbac_free_constraints( rbac_constraint_t *constraints );
380 1.1 christos
381 1.1 christos rbac_permission_t *rbac_read_permission( Operation *op, rbac_req_t *rbac_reqp );
382 1.1 christos int rbac_check_session_permission(
383 1.1 christos rbac_session_t *sessp,
384 1.1 christos rbac_permission_t *permp,
385 1.1 christos rbac_constraint_t *role_constraints );
386 1.1 christos void rbac_free_permission( rbac_permission_t *permp );
387 1.1 christos
388 1.1 christos /* audit functions */
389 1.1 christos void rbac_audit(
390 1.1 christos Operation *op,
391 1.1 christos audit_op_t rbac_op,
392 1.1 christos rbac_session_t *sessp,
393 1.1 christos rbac_req_t *reqp,
394 1.1 christos int result,
395 1.1 christos char *msg );
396 1.1 christos
397 1.1 christos /* acl functions */
398 1.1 christos int rbac_create_session_acl_check( struct berval *sessid, rbac_user_t *userp );
399 1.1 christos
400 1.1 christos void rbac_to_lower( struct berval *bv );
401 1.1 christos
402 1.1 christos LDAP_END_DECL
403 1.1 christos
404 1.1 christos #endif /* RBAC_H */
405