Bug #80820 [Com]: Using ldap_exop_passwd with ppolicy control do not update $ldap resource
| From: | clement dot oudot at worteks dot com | Date: | Tue, 02 Mar 2021 23:01:50 +0000 |
| Subject: | Bug #80820 [Com]: Using ldap_exop_passwd with ppolicy control do not update $ldap resource | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-232482@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80820&edit=1
ID: 80820
Comment by: clement dot oudot at worteks dot com
Reported by: clement dot oudot at worteks dot com
Summary: Using ldap_exop_passwd with ppolicy control do not
update $ldap resource
Status: Open
Type: Bug
Package: LDAP related
Operating System: Linux
PHP Version: 7.4.15
Block user comment: N
Private report: N
New Comment:
Forgot to give the exact PHP version:
$ php -v
PHP 7.4.3 (cli) (built: Oct 6 2020 15:47:56) ( NTS )
Copyright (c) The PHP Group
Zend Engine v3.4.0, Copyright (c) Zend Technologies
with Zend OPcache v7.4.3, Copyright (c), by Zend Technologies
Previous Comments:
------------------------------------------------------------------------
[2021-03-02 23:00:19] clement dot oudot at worteks dot com
Description:
------------
I tried to use ldap_exop_passwd with password policy (see my code in test script)
With this code, the $ldap resource is not updated, so error_code is still the previous one. There is
no issue if not ctrls reference is passed at latest argument.
Test script:
---------------
$ctrls = array();
$exop_passwd = ldap_exop_passwd($ldap, $dn, $oldpassword, $password, $ctrls);
$error_code = ldap_errno($ldap);
$error_msg = ldap_error($ldap);
error_log("TEST $error_code / $error_msg / $exop_passwd");
if (!$exop_passwd) {
if (isset($ctrls[LDAP_CONTROL_PASSWORDPOLICYRESPONSE])) {
$value = $ctrls[LDAP_CONTROL_PASSWORDPOLICYRESPONSE]['value'];
if (isset($value['error'])) {
$ppolicy_error_code = $value['error'];
error_log("LDAP - Ppolicy error code: $ppolicy_error_code");
}
}
}
Expected result:
----------------
We should have in $error_code the value "19" when password is refused by LDAP directory
when it is too short
Actual result:
--------------
Here is the current log:
[Tue Mar 02 23:47:30.736095 2021] [php7:warn] [pid 14066] [client 127.0.0.1:48158] PHP Warning:
ldap_exop_passwd(): Passwd modify extended operation failed: Password fails quality checking policy
(19) in /usr/local/ssp/lib/functions.inc.php on line 457, referer: http://ssp.example.com/index.php?action=change
[Tue Mar 02 23:47:30.736195 2021] [php7:notice] [pid 14066] [client 127.0.0.1:48158] TEST 0 /
Success / , referer: http://ssp.example.com/index.php?action=change
[Tue Mar 02 23:47:30.736228 2021] [php7:notice] [pid 14066] [client 127.0.0.1:48158] LDAP - Ppolicy
error code: 6, referer: http://ssp.example.com/index.php?action=change
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80820&edit=1