#!/bin/bash
#
# This file is part of Plinth.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program.  If not, see <http://www.gnu.org/licenses/>.
#

# Must be run as root.

old_username="$1"
new_username="$2"

cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
dn: uid=$old_username,ou=users,dc=thisbox
changetype: modrdn
newrdn: uid=$new_username
deleteoldrdn: 1
EOF

if [ $? -eq 0 ]; then
    echo "Success: user renamed"
else
    echo "Failed: user rename failed"
    exit 1
fi

# update groups
results=$(ldapsearch 2>/dev/null -Y EXTERNAL -H ldapi:/// -b 'ou=groups,dc=thisbox' -LLL "(member=uid=$old_username,ou=users,dc=thisbox)" dn | grep -v '^$')

while read -r line; do
    cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
$line
changetype: modify
add: member
member: uid=$new_username,ou=users,dc=thisbox
EOF

    cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
$line
changetype: modify
delete: member
member: uid=$old_username,ou=users,dc=thisbox
EOF
done <<< "$results"

# update sudo group if needed
results=$(ldapsearch -Y EXTERNAL -H ldapi:/// -b 'cn=sudo,ou=groups,dc=thisbox' -LLL "(memberUid=$old_username)")

if [ -n "$results" ]; then
    cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
dn: cn=sudo,ou=groups,dc=thisbox
changetype: modify
delete: memberUid
memberUid: $old_username
EOF

    cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
dn: cn=sudo,ou=groups,dc=thisbox
changetype: modify
add: memberUid
memberUid: $new_username
EOF
fi
