This file is indexed.

/usr/share/perl5/Net/LDAP/Control/ProxyAuth.pm is in libnet-ldap-perl 1:0.6500+dfsg-1.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
# Copyright (c) 2001-2004 Graham Barr <gbarr@pobox.com>. All rights reserved.
# This program is free software; you can redistribute it and/or
# modify it under the same terms as Perl itself.

package Net::LDAP::Control::ProxyAuth;

use Net::LDAP::Control;

our @ISA = qw(Net::LDAP::Control);
our $VERSION = '1.09';

use Net::LDAP::Constant qw(LDAP_CONTROL_PROXYAUTHORIZATION);
use Net::LDAP::ASN qw(proxyAuthValue);
use strict;

sub LDAP_CONTROL_PROXYAUTHORIZATION_OLD { '2.16.840.1.113730.3.4.12'; }

sub init {
  my($self) = @_;

  delete $self->{asn};

  if (defined($self->{proxyDN})) {
    $self->{type} = LDAP_CONTROL_PROXYAUTHORIZATION_OLD;

    $self->{asn} = { proxyDN => $self->{proxyDN} || '' }
      unless (exists $self->{value});
  }
  else {
    $self->{value} = $self->{authzID} || ''
      unless (exists $self->{value});
  }

  # criticality must be set !
  $self->{critical} = 1;

  $self;
}


sub proxyDN {
  my $self = shift;

  if (@_) {
    delete $self->{value};

    $self->{type} = LDAP_CONTROL_PROXYAUTHORIZATION_OLD;
    return $self->{asn}{proxyDN} = shift || '';
  }
  elsif ($self->{type} eq LDAP_CONTROL_PROXYAUTHORIZATION) {
    $self->{error} = 'Illegal query method: use authzID()';
    return undef;
  }
  else {
    $self->{asn} ||= $proxyAuthValue->decode($self->{value});
  }

  $self->{asn}{proxyDN};
}


sub authzID {
  my $self = shift;

  if (@_) {
    delete $self->{value};

    $self->{type} = LDAP_CONTROL_PROXYAUTHORIZATION;
    return $self->{authzID} = shift || '';
  }
  elsif ($self->{type} eq LDAP_CONTROL_PROXYAUTHORIZATION_OLD) {
    $self->{error} = 'Illegal query method: use proxyDN()';
    return undef;
  }
  else {
    $self->{authzID} ||= $self->{value};
  }

  $self->{authzID};
}


sub value {
  my $self = shift;

  unless (exists $self->{value}) {
    $self->{value} = ($self->{type} eq LDAP_CONTROL_PROXYAUTHORIZATION_OLD)
		     ? $proxyAuthValue->encode($self->{asn})
                     : $self->{authzID} || '';
  }

  return $self->{value};
}

# make sure criticality remains TRUE
sub critical {
  1;
}

1;

__END__

=head1 NAME

Net::LDAP::Control::ProxyAuth - LDAPv3 Proxy Authorization control object

=head1 SYNOPSIS

 use Net::LDAP;
 use Net::LDAP::Control::ProxyAuth;

 $ldap = Net::LDAP->new( "ldap.mydomain.eg" );

 $auth = Net::LDAP::Control::ProxyAuth->new( authzID => 'dn:cn=me,ou=people,o=myorg.com' );

 @args = ( base     => "cn=subnets,cn=sites,cn=configuration,$BASE_DN",
	   scope    => "subtree",
	   filter   => "(objectClass=subnet)",
	   callback => \&process_entry, # Call this sub for each entry
	   control  => [ $auth ],
 );

 while (1) {
   # Perform search
   my $mesg = $ldap->search( @args );

   # Only continue on LDAP_SUCCESS
   $mesg->code and last;

 }


=head1 DESCRIPTION

C<Net::LDAP::Control::ProxyAuth> provides an interface for the creation and manipulation
of objects that represent the C<Proxy Authorization Control> as described by RFC 4370.

It allows a client to be bound to an LDAP server with its own identity, but to perform
operations on behalf of another user, the C<authzID>.

With the exception of any extension that causes a change in authentication,
authorization or data confidentiality, a single C<Proxy Authorization Control>
may be included in any search, compare, modify, add, delete, or moddn or
extended operation.

As required by the RFC, the criticality of this control is automatically set to
TRUE in order to protect clients from submitting requests with other identities
that they intend to.


=head1 CONSTRUCTOR ARGUMENTS

In addition to the constructor arguments described in
L<Net::LDAP::Control> the following are provided.

=over 4

=item authzID

The authzID that is required. This is the identity we are requesting operations to use.

=item proxyDN

In early versions of the drafts to RFC 4370, draft-weltman-ldapv3-proxy-XX.txt,
the value in the control and thus the constructor argument was a DN and was called C<proxyDN>.
It served the same purpose as C<authzID> in recent versions of C<proxyAuthorization> control.

=back

B<Please note:>
Unfortunately the OID and the encoding or the C<Proxy Authorization Control>
changed significantly between early versions of draft-weltman-ldapv3-proxy-XX.txt
and the final RFC.
Net::LDAP::Control::ProxyAuth tries to cope with that situation and changes
the OID and encoding used depending on the constructor argument.

With C<proxyDN> as constructor argument the old OID and encoding are used,
while with C<authzID> as constructor argument the new OID and encoding are used.
Using this logic servers supporting either OID can be handled correctly.

=head1 METHODS

As with L<Net::LDAP::Control> each constructor argument
described above is also available as a method on the object which will
return the current value for the attribute if called without an argument,
and set a new value for the attribute if called with an argument.

=head1 SEE ALSO

L<Net::LDAP>,
L<Net::LDAP::Control>,

=head1 AUTHORS

Olivier Dubois, Swift sa/nv based on Net::LDAP::Control::Page from
Graham Barr E<lt>gbarr@pobox.comE<gt>.
Peter Marschall E<lt>peter@adpm.deE<gt> added authzID extensions
based on ideas from Graham Barr E<lt>gbarr@pobox.comE<gt>.

Please report any bugs, or post any suggestions, to the perl-ldap
mailing list E<lt>perl-ldap@perl.orgE<gt>

=head1 COPYRIGHT

Copyright (c) 2001-2004 Graham Barr. All rights reserved. This program is
free software; you can redistribute it and/or modify it under the same
terms as Perl itself.

=cut