#!/usr/share/ucs-test/runner bash 
## desc: "Check whether the Container-Ignore-Subtree is respected on ad-side in read-mode"
## exposure: dangerous
## packages:
## - univention-s4-connector


. "$TESTLIBPATH/base.sh" || exit 137
. "$TESTLIBPATH/udm.sh" || exit 137
. "$TESTLIBPATH/random.sh" || exit 137


. "s4connector.sh" || exit 137
test -n "$connector_s4_ldap_host" || exit 137
connector_running_on_this_host || exit 137

CONTAINER1="$(random_chars)"
CONTAINER2="$(random_chars)"

SYNCMODE="$(ad_get_sync_mode)"
ad_set_sync_mode "sync"

UDM_container_cn_name="$CONTAINER1"
AD_CONTAINER_DN="CN=$UDM_container_cn_name,$(ad_get_base)"
ad_container_create "$CONTAINER1" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

udm_exists "container/cn"; fail_bool 0 110
ad_exists "$AD_CONTAINER_DN"; fail_bool 0 110

section "Modify Container-Ignore-Subtree"

invoke-rc.d univention-s4-connector stop

MAIN_FILE="/usr/share/pyshared/univention/s4connector/s4/main.py"
cp -f "$MAIN_FILE" "$MAIN_FILE".ucs-test-backup
sed -i "s/import mapping/import mapping\nmapping.s4_mapping ['container'].ignore_subtree = mapping.s4_mapping ['container'].ignore_subtree + ['cn=$CONTAINER1,$ldap_base']/" "$MAIN_FILE"

ad_set_sync_mode "read"
invoke-rc.d univention-s4-connector start

section "Create container"
UDM_container_cn_name="$CONTAINER2"
AD_CONTAINER_DN="CN=$UDM_container_cn_name,CN=$CONTAINER1,$(ad_get_base)"

ad_container_create "$CONTAINER2" "" "CN=$CONTAINER1,$(ad_get_base)" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_CONTAINER_DN"; fail_bool 0 110
udm_exists  "container/cn" "" "" "cn=$CONTAINER1,$ldap_base"; fail_bool 1 110

section "Clean up"

ad_delete "$AD_CONTAINER_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_CONTAINER_DN"; fail_bool 1 110
udm_exists  "container/cn" "" "" "cn=$CONTAINER1,$ldap_base"; fail_bool 1 110

invoke-rc.d univention-s4-connector stop
mv -f "$MAIN_FILE".ucs-test-backup "$MAIN_FILE"
ad_set_sync_mode "sync"
invoke-rc.d univention-s4-connector start

UDM_container_cn_name="$CONTAINER1"
AD_CONTAINER_DN="CN=$UDM_container_cn_name,$(ad_get_base)"
ad_delete "$AD_CONTAINER_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_CONTAINER_DN"; fail_bool 1 110
udm_exists  "container/cn"; fail_bool 1 110

ad_set_sync_mode "$SYNCMODE"

exit "$RETVAL"
