#!/bin/bash
#
# This file is part of Plinth.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program.  If not, see <http://www.gnu.org/licenses/>.
#

# Must be run as root.

username="$1"
groupname="$2"

# check if group already exists
results=$(ldapsearch -Y EXTERNAL -H ldapi:/// -b 'ou=groups,dc=thisbox' -LLL "(cn=$groupname)" cn)

if [ -z "$results" ]; then
    # create group, with user as initial member
    cat <<EOF |ldapadd -Y EXTERNAL -H ldapi:///
dn: cn=$groupname,ou=groups,dc=thisbox
objectClass: groupOfNames
cn: $groupname
member: uid=$username,ou=users,dc=thisbox
EOF
else
    # add user to existing group
    cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
dn: cn=$groupname,ou=groups,dc=thisbox
changetype: modify
add: member
member: uid=$username,ou=users,dc=thisbox
EOF
fi

# For admin users, also need a posixAccount for sudo.
if [ "$groupname" == "admin" ]; then
    # check if sudo group already exists
    results=$(ldapsearch -Y EXTERNAL -H ldapi:/// -b 'ou=groups,dc=thisbox' -LLL "(cn=sudo)" cn)

    if [ -z "$results" ]; then
	# create sudo group
	cat <<EOF |ldapadd -Y EXTERNAL -H ldapi:///
dn: cn=sudo,ou=groups,dc=thisbox
objectClass: posixGroup
cn: sudo
gidNumber: 27
memberUid: $username
EOF
    else
	# add user to sudo group
	cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
dn: cn=sudo,ou=groups,dc=thisbox
changetype: modify
add: memberUid
memberUid: $username
EOF
    fi
fi
