Module: OpenDirectoryUtils::CommandsUserCreateRemove

Includes:
CleanCheck, CommandsBase
Included in:
Connection
Defined in:
lib/open_directory_utils/commands_user_create_remove.rb

Overview

Instance Method Summary collapse

Methods included from CommandsBase

#build_dscl_command, #build_dseditgroup_command, #build_pwpolicy_command, #dscl, #dseditgroup, #pwpolicy

Methods included from CleanCheck

#assert, #check_critical_attribute, #group_record_name_alternatives, #tidy_attribs, #user_record_name_alternatives

Instance Method Details

#user_add_to_group(attribs, dir_info) ⇒ Object



312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 312

def user_add_to_group(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:group_membership]
  attribs[:value] = attribs[:value] || attribs[:groupmembership]
  attribs[:value] = attribs[:value] || attribs[:group_name]
  attribs[:value] = attribs[:value] || attribs[:groupname]
  attribs[:value] = attribs[:value] || attribs[:gid]

  check_critical_attribute( attribs, :record_name, :username )
  check_critical_attribute( attribs, :value, :groupname )
  attribs    = tidy_attribs(attribs)
  command    = { operation: 'edit', action: 'add', type: 'user'}
  user_attrs  = attribs.merge(command)

  dseditgroup( user_attrs, dir_info )
end

#user_append_email(attribs, dir_info) ⇒ Object



204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 204

def user_append_email(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs['apple-user-mailattribute']
  attribs[:value] = attribs[:value] || attribs[:apple_user_mailattribute]
  attribs[:value] = attribs[:value] || attribs[:e_mail_attribute]
  attribs[:value] = attribs[:value] || attribs[:mail_attribute]
  attribs[:value] = attribs[:value] || attribs[:email]
  attribs[:value] = attribs[:value] || attribs[:mail]

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :email )
  attribs    = tidy_attribs(attribs)

  answer     = []

  # command    = {action: 'append', scope: 'Users', attribute: 'mail'}
  # user_attrs = attribs.merge(command)
  # answer    << dscl( user_attrs, dir_info )

  command    = {action: 'append', scope: 'Users', attribute: 'email'}
  user_attrs = attribs.merge(command)
  answer    << dscl( user_attrs, dir_info )

  return answer
end

#user_create(attribs, dir_info) ⇒ Object



403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 403

def user_create(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  check_critical_attribute( attribs, :record_name )
  # attribs           = tidy_attribs(attribs).dup
  attribs           = tidy_attribs(attribs)

  answer            = []
  attribs[:value]   = nil
  answer           << user_create_min(attribs, dir_info)
  if attribs[:first_name] or attribs[:firstname] or attribs[:given_name] or
                      attribs[:givenname]
    attribs[:value] = nil
    answer         << user_set_first_name(attribs, dir_info)
  end
  # skip email if non-sent
  if attribs[:email] or attribs[:mail] or attribs[:apple_user_mailattribute]
    attribs[:value] = nil
    answer         << user_set_email(attribs, dir_info)
  end
  # TODO add to groups without error - if group present
  # "<main> attribute status: eDSSchemaError\n" +
  # "<dscl_cmd> DS Error: -14142 (eDSSchemaError)"]
  # # enroll in a group membership if info present
  if attribs[:group_name] or attribs[:groupname] or attribs[:gid] or
                    attribs[:group_membership] or attribs[:groupmembership]
    attribs[:value] = nil
    answer         << user_add_to_group(attribs, dir_info)
  end

  return answer.flatten
end

#user_create_min(attribs, dir_info) ⇒ Object



364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 364

def user_create_min(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  check_critical_attribute( attribs, :record_name )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', value: nil, attribute: nil}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )

  answer          = []
  attribs[:value] = nil
  answer         << dscl( user_attrs, dir_info )
  attribs[:value] = nil
  answer         << user_set_password(attribs, dir_info)
  attribs[:value] = nil
  answer         << user_set_shell(attribs, dir_info)
  attribs[:value] = nil
  answer         << user_set_last_name(attribs, dir_info)
  attribs[:value] = nil
  answer         << user_set_real_name(attribs, dir_info)
  attribs[:value] = nil
  answer         << user_set_unique_id(attribs, dir_info)
  attribs[:value] = nil
  answer         << user_set_primary_group_id(attribs, dir_info)
  attribs[:value] = nil
  answer         << user_set_nfs_home_directory(attribs, dir_info)
  attribs[:value] = nil
  answer         << (attribs, dir_info)      if
                    attribs[:enable]&.eql? 'true' or attribs[:enable]&.eql? true
  answer         << (attribs, dir_info) unless
                    attribs[:enable]&.eql? 'true' or attribs[:enable]&.eql? true
  return answer
end

#user_delete(attribs, dir_info) ⇒ Object



438
439
440
441
442
443
444
445
446
447
448
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 438

def user_delete(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  check_critical_attribute( attribs, :record_name )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'delete', scope: 'Users', value: nil, attribute: nil}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_disable_login(attribs, dir_info) ⇒ Object

/usr/bin/pwpolicy -a diradmin -p A-B1g-S3cret -u $shortname_USERNAME -setpolicy “isDisabled=1”



301
302
303
304
305
306
307
308
309
310
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 301

def (attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  check_critical_attribute( attribs, :record_name )
  attribs    = tidy_attribs(attribs)

  command = {attribute: 'disableuser', value: nil}
  params  = command.merge(attribs)
  pwpolicy(params, dir_info)
end

#user_enable_login(attribs, dir_info) ⇒ Object

/usr/bin/pwpolicy -a diradmin -p A-B1g-S3cret -u $shortname_USERNAME -setpolicy “isDisabled=0”



290
291
292
293
294
295
296
297
298
299
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 290

def (attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  check_critical_attribute( attribs, :record_name )
  attribs    = tidy_attribs(attribs)

  command = {attribute: 'enableuser', value: nil}
  params  = command.merge(attribs)
  pwpolicy(params, dir_info)
end

#user_exists?(attribs, dir_info) ⇒ Boolean

get all usernames – dscl . -list /Users get all user details – dscl . -readall /Users

Returns:

  • (Boolean)


38
39
40
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 38

def user_exists?(attribs, dir_info)
  user_get_info(attribs, dir_info)
end

#user_get_info(attribs, dir_info) ⇒ Object Also known as: user_info

GET INFO

get user record – dscl . -read /Users/<username> get user value – dscl . -read /Users/<username> <key> search od user – dscl . -search /Users RealName “Andrew Garrett” return as xml – dscl -plist . -search /Users RealName “Andrew Garrett”



23
24
25
26
27
28
29
30
31
32
33
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 23

def user_get_info(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  check_critical_attribute( attribs, :record_name )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'read', scope: 'Users', attribute: nil, value: nil}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_get_policy(attribs, dir_info) ⇒ Object Also known as: user_login_enabled?

/usr/bin/pwpolicy -a diradmin -p A-B1g-S3cret -u $shortname_USERNAME -getpolicy



349
350
351
352
353
354
355
356
357
358
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 349

def user_get_policy(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  check_critical_attribute( attribs, :record_name )
  attribs    = tidy_attribs(attribs)

  command = {attribute: 'getpolicy', value: nil}
  params  = command.merge(attribs)
  pwpolicy(params, dir_info)
end

#user_password_verified?(attribs, dir_info) ⇒ Boolean Also known as: user_password_ok?

/usr/bin/dscl /LDAPv3/127.0.0.1 -auth #shortname “#passwd”

Returns:

  • (Boolean)


272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 272

def user_password_verified?(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:password]
  attribs[:value] = attribs[:value] || attribs[:passwd]

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :password )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'auth', scope: 'Users'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_remove_from_group(attribs, dir_info) ⇒ Object



330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 330

def user_remove_from_group(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:group_membership]
  attribs[:value] = attribs[:value] || attribs[:groupmembership]
  attribs[:value] = attribs[:value] || attribs[:group_name]
  attribs[:value] = attribs[:value] || attribs[:groupname]
  attribs[:value] = attribs[:value] || attribs[:gid]

  check_critical_attribute( attribs, :record_name, :username )
  check_critical_attribute( attribs, :value, :groupname )
  attribs    = tidy_attribs(attribs)
  command    = { operation: 'edit', action: 'delete', type: 'user'}
  user_attrs  = attribs.merge(command)

  dseditgroup( user_attrs, dir_info )
end

#user_set_first_email(attribs, dir_info) ⇒ Object Also known as: user_set_email

/usr/bin/dscl -u diradmin -P A-B1g-S3cret /LDAPv3/127.0.0.1 -create /Users/$shortname_USERNAME mail “$VALUE” /usr/bin/dscl -u diradmin -P A-B1g-S3cret /LDAPv3/127.0.0.1 -create /Users/$shortname_USERNAME email “$VALUE” /usr/bin/dscl -u diradmin -P A-B1g-S3cret /LDAPv3/127.0.0.1 -create /Users/$shortname_USERNAME apple-user-mailattribute “$VALUE”



174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 174

def user_set_first_email(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs['apple-user-mailattribute']
  attribs[:value] = attribs[:value] || attribs[:apple_user_mailattribute]
  attribs[:value] = attribs[:value] || attribs[:email]
  attribs[:value] = attribs[:value] || attribs[:mail]

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :email )
  attribs    = tidy_attribs(attribs)

  answer     = []

  command    = {action: 'create', scope: 'Users', attribute: 'MailAttribute'}
  user_attrs = attribs.merge(command)
  answer    << dscl( user_attrs, dir_info )

  command    = {action: 'create', scope: 'Users', attribute: 'EMailAddress'}
  user_attrs = attribs.merge(command)
  answer    << dscl( user_attrs, dir_info )

  # command    = {action: 'create', scope: 'Users', attribute: 'apple-user-mailattribute'}
  # user_attrs = attribs.merge(command)
  # answer    << dscl( user_attrs, dir_info )

  return answer
end

#user_set_first_name(attribs, dir_info) ⇒ Object

/usr/bin/dscl -u diradmin -P A-B1g-S3cret /LDAPv3/127.0.0.1 -create /Users/$shortname_USERNAME FirstName “$VALUE”



70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 70

def user_set_first_name(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:given_name]
  attribs[:value] = attribs[:value] || attribs[:givenname]
  attribs[:value] = attribs[:value] || attribs[:first_name]
  attribs[:value] = attribs[:value] || attribs[:firstname]

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :first_name )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', attribute: 'FirstName'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_set_last_name(attribs, dir_info) ⇒ Object

/usr/bin/dscl -u diradmin -P A-B1g-S3cret /LDAPv3/127.0.0.1 -create /Users/$shortname_USERNAME LastName “$VALUE”



89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 89

def user_set_last_name(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:sn]
  attribs[:value] = attribs[:value] || attribs[:surname]
  attribs[:value] = attribs[:value] || attribs[:lastname]
  attribs[:value] = attribs[:value] || attribs[:last_name]
  attribs[:value] = attribs[:value] || attribs[:real_name]
  attribs[:value] = attribs[:value] || attribs[:realname]
  attribs[:value] = attribs[:value] || attribs[:short_name]
  attribs[:value] = attribs[:value] || attribs[:shortname]
  attribs[:value] = attribs[:value] || attribs[:user_name]
  attribs[:value] = attribs[:value] || attribs[:username]
  attribs[:value] = attribs[:value] || attribs[:uid]

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :last_name )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', attribute: 'LastName'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_set_nfs_home_directory(attribs, dir_info) ⇒ Object

/usr/bin/dscl -u diradmin -P A-B1g-S3cret /LDAPv3/127.0.0.1 -create /Users/someuser NFSHomeDirectory /Users/someuser



136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 136

def user_set_nfs_home_directory(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:home_directory]
  attribs[:value] = attribs[:value] || attribs[:nfs_home_directory]
  attribs[:value] = attribs[:value] || '/Volumes/Macintosh HD/Users/someone'

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :home_directory )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', attribute: 'NFSHomeDirectory'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_set_password(attribs, dir_info) ⇒ Object

/usr/bin/pwpolicy -a diradmin -p “TopSecret” -u username -setpassword “AnotherSecret” /usr/bin/dscl -plist -u diradmin -P #adminpw /LDAPv3/127.0.0.1 -passwd /Users/#shortname “#passwd”



255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 255

def user_set_password(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:password]
  attribs[:value] = attribs[:value] || attribs[:passwd]
  attribs[:value] = attribs[:value] || '*'

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :password )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'passwd', scope: 'Users'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_set_primary_group_id(attribs, dir_info) ⇒ Object

sudo dscl . -create /Users/someuser PrimaryGroupID 80



232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 232

def user_set_primary_group_id(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:groupid]
  attribs[:value] = attribs[:value] || attribs[:group_id]
  attribs[:value] = attribs[:value] || attribs[:gidnumber]
  attribs[:value] = attribs[:value] || attribs[:groupnumber]
  attribs[:value] = attribs[:value] || attribs[:group_number]
  attribs[:value] = attribs[:value] || attribs[:primarygroupid]
  attribs[:value] = attribs[:value] || attribs[:primary_group_id]

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :group_id )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', attribute: 'PrimaryGroupID'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_set_real_name(attribs, dir_info) ⇒ Object

CHANGE OD

/usr/bin/dscl -u diradmin -P A-B1g-S3cret /LDAPv3/127.0.0.1 -create /Users/$USER RealName “$VALUE”



45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 45

def user_set_real_name(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:common_name]
  attribs[:value] = attribs[:value] || attribs[:cn]
  attribs[:value] = attribs[:value] || attribs[:realname]
  attribs[:value] = attribs[:value] || attribs[:real_name]
  attribs[:value] = attribs[:value] || attribs[:fullname]
  attribs[:value] = attribs[:value] || attribs[:full_name]
  if attribs[:last_name] or attribs[:first_name]
    attribs[:value] = attribs[:value] || "#{attribs[:first_name]} #{attribs[:last_name]}"
  end
  attribs[:value] = attribs[:value] || attribs[:record_name]

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :real_name )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', attribute: 'RealName'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_set_shell(attribs, dir_info) ⇒ Object

sudo dscl . -create /Users/someuser UserShell /bin/bash



154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 154

def user_set_shell(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)

  attribs[:value] = attribs[:value] || attribs[:user_shell]
  attribs[:value] = attribs[:value] || attribs[:shell]
  attribs[:value] = attribs[:value] || '/bin/bash'

  check_critical_attribute( attribs, :record_name )
  check_critical_attribute( attribs, :value, :shell )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', attribute: 'UserShell'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end

#user_set_unique_id(attribs, dir_info) ⇒ Object

sudo dscl . -create /Users/someuser UniqueID “1010”



115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
# File 'lib/open_directory_utils/commands_user_create_remove.rb', line 115

def user_set_unique_id(attribs, dir_info)
  attribs = user_record_name_alternatives(attribs)
  check_critical_attribute( attribs, :record_name )

  attribs[:value] = attribs[:value] || attribs[:uniqueid]
  attribs[:value] = attribs[:value] || attribs[:unique_id]
  attribs[:value] = attribs[:value] || attribs[:uid_number]
  attribs[:value] = attribs[:value] || attribs[:uidnumber]
  attribs[:value] = attribs[:value] || attribs[:usernumber]
  attribs[:value] = attribs[:value] || attribs[:user_number]

  check_critical_attribute( attribs, :value, :unique_id )
  attribs    = tidy_attribs(attribs)

  command    = {action: 'create', scope: 'Users', attribute: 'UniqueID'}
  user_attrs = attribs.merge(command)

  dscl( user_attrs, dir_info )
end