mirror of
https://github.com/freedombox/FreedomBox.git
synced 2026-04-29 10:10:19 +00:00
61 lines
1.7 KiB
Bash
Executable File
61 lines
1.7 KiB
Bash
Executable File
#!/bin/sh
|
|
#
|
|
# This file is part of Plinth.
|
|
#
|
|
# This program is free software: you can redistribute it and/or modify
|
|
# it under the terms of the GNU Affero General Public License as
|
|
# published by the Free Software Foundation, either version 3 of the
|
|
# License, or (at your option) any later version.
|
|
#
|
|
# This program is distributed in the hope that it will be useful,
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
# GNU Affero General Public License for more details.
|
|
#
|
|
# You should have received a copy of the GNU Affero General Public License
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
#
|
|
|
|
# Must be run as root.
|
|
|
|
username="$1"
|
|
groupname="$2"
|
|
|
|
cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
|
|
dn: cn=$groupname,ou=groups,dc=thisbox
|
|
changetype: modify
|
|
delete: member
|
|
member: uid=$username,ou=users,dc=thisbox
|
|
EOF
|
|
|
|
if [ $? -eq 0 ]; then
|
|
echo "Removed user from group"
|
|
elif [ $? -eq 16 ]; then
|
|
echo "User was not in group"
|
|
exit 1
|
|
elif [ $? -eq 65 ]; then
|
|
# Cannot have empty group, so just delete the group.
|
|
ldapdelete -Y EXTERNAL -H ldapi:/// "cn=$groupname,ou=groups,dc=thisbox"
|
|
|
|
if [ $? -eq 0 ]; then
|
|
echo "User was last member in group, so group was deleted."
|
|
else
|
|
echo "User was last member in group, but could not delete group."
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
if [ "$groupname" == "admin" ]; then
|
|
# update sudo group if needed
|
|
results=$(ldapsearch -Y EXTERNAL -H ldapi:/// -b 'cn=sudo,ou=groups,dc=thisbox' -LLL "(memberUid=$username)")
|
|
|
|
if [ -n "$results" ]; then
|
|
cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
|
|
dn: cn=sudo,ou=groups,dc=thisbox
|
|
changetype: modify
|
|
delete: memberUid
|
|
memberUid: $username
|
|
EOF
|
|
fi
|
|
fi
|