#!/usr/bin/perl -w

#----------------------------------------------------------------------
# copyright (C) 1999, 2000 e-smith, inc.
#		
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#		
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.	See the
# GNU General Public License for more details.
#		
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307  USA
# 
# Technical support for this program is available from e-smith, inc.
# For details, please visit our web site at www.e-smith.com or
# call us on 1 888 ESMITH 1 (US/Canada toll free) or +1 613 564 8000
#----------------------------------------------------------------------

package esmith;

use strict;
use Errno;
use esmith::config;
use esmith::util;
use esmith::db;
use Net::LDAP;

my %conf;
tie %conf, 'esmith::config';

my %accounts;
tie %accounts, 'esmith::config', '/home/e-smith/accounts';

my $status = db_get_prop(\%conf, 'ldap', 'status');
unless (defined $status && $status eq "enabled" )
{
    warn "Not running action script $0, LDAP service not enabled!\n";
    exit(0);
}

my $event = $ARGV [0];
my $userName = $ARGV [1];

die "Username argument missing." unless defined ($userName);

my ($type, %properties) = db_get(\%accounts, $userName);

if (($type ne 'user') && ($type ne 'group'))
{
    die "Account $userName is not a user or group account; " .
	"update LDAP entry failed.\n";
}

#------------------------------------------------------------
# Update LDAP directory entry. First read LDAP password
#------------------------------------------------------------
my $pw = esmith::util::LdapPassword();

#------------------------------------------------------------
# Update LDAP database entry.
#------------------------------------------------------------
my $base = esmith::util::ldapBase (db_get(\%conf, 'DomainName'));

my $ldap = Net::LDAP->new('localhost')
    or die "$@";

$ldap->bind(
    dn => "cn=root,$base",
    password => $pw
);


my @attrs = ();

if ($type eq 'user')
{
    push @attrs, (objectClass => ['posixaccount','posixgroup']);
    push @attrs, (loginShell  => '/bin/bash');
    
    push @attrs, (uid => $userName);
    push @attrs, (cn => $userName);
 
    push @attrs, (uidNumber =>  $properties{'Uid'});
    push @attrs, (gidNumber =>  $properties{'Gid'});

    my $homedir = "/home/e-smith/" . $userName . "/files";
    push @attrs, (homeDirectory =>  $homedir);

    my $name = $properties{'FirstName'} . " " . $properties{'LastName'};
    if ($name !~ /^\s*$/)
    {
	push @attrs, (Description => $name);
    }

    if ($properties{'FirstName'} !~ /^\s*$/)
    {
	push @attrs, (givenName => $properties{'FirstName'});
    }

    if ($properties{'LastName'} !~ /^\s*$/)
    {
	push @attrs, (sn => $properties{'LastName'});
    }

    my $mail = $userName . "\@" . $conf{'DomainName'};
    if ($mail !~ /^\s*$/)
    {
	push @attrs, (mail => $mail);
    }
    
    if ($properties{'Phone'} !~ /^\s*$/)
    {
	push @attrs, (telephoneNumber => $properties{'Phone'});
    }
    
    if ($properties{'Company'} !~ /^\s*$/)
    {
	push @attrs, (o => $properties{'Company'});
    }
    
    if ($properties{'Dept'} !~ /^\s*$/)
    {
	push @attrs, (ou => $properties{'Dept'});
    }
    
    if ($properties{'City'} !~ /^\s*$/)
    {
	push @attrs, (l => $properties{'City'});
    }
    
    if ($properties{'Street'} !~ /^\s*$/)
    {
	push @attrs, (street => $properties{'Street'});
    }
}
elsif ($type eq 'group')
{
    push @attrs, (objectClass => 'posixgroup');
    push @attrs, (uid => $userName);
    push @attrs, (gidNumber =>  $properties{'Gid'});
    
    my $name = $properties{'Description'};
    if ($name !~ /^\s*$/)
    {
	push @attrs, (cn => $name);
    }

    my $mail = $userName . "\@" . $conf{'DomainName'};
    if ($mail !~ /^\s*$/)
    {
	push @attrs, (mail => $mail);
    }

    if (db_get_prop (\%conf, 'ldap', 'defaultPhoneNumber') !~ /^\s*$/)
    {
        push @attrs, (telephoneNumber =>
	    db_get_prop (\%conf, 'ldap', 'defaultPhoneNumber'));
    }

    if (db_get_prop (\%conf, 'ldap', 'defaultCompany') !~ /^\s*$/)
    {
        push @attrs, (o => db_get_prop (\%conf, 'ldap', 'defaultCompany'));
    }

    if (db_get_prop (\%conf, 'ldap', 'defaultDepartment') !~ /^\s*$/)
    {
        push @attrs, (ou =>
	    db_get_prop (\%conf, 'ldap', 'defaultDepartment'));
    }

    if (db_get_prop (\%conf, 'ldap', 'defaultCity') !~ /^\s*$/)
    {
        push @attrs, (l =>
	    db_get_prop (\%conf, 'ldap', 'defaultCity'));
    }

    if (db_get_prop (\%conf, 'ldap', 'defaultStreet') !~ /^\s*$/)
    {
        push @attrs, (street =>
	    db_get_prop (\%conf, 'ldap', 'defaultStreet'));
    }

    # ---------------------------------------------------
    #   Process group members
    # ---------------------------------------------------
    
    my $gmembers = $properties{'Members'};
    push @attrs, (memberUid => [(split (/,/,$gmembers))]);

}
my $dn = "uid=$userName," .  esmith::util::ldapBase ($conf {'DomainName'});
if (($event eq 'user-create') || ($event eq 'group-create'))
{
    my $result = $ldap->add ($dn, attr => \@attrs);

    $result->code && warn "failed to add entry: ", $result->error ;
}
else
{
    my %attrs = @attrs;
    my $result = $ldap->modify ($dn, replace => \%attrs);
    $result->code && warn "failed to modify entry: ", $result->error ;
   
}

$ldap->unbind;

exit (0);
