#!/usr/share/ucs-test/runner bash
## desc: "Check whether the Container-Ignore-Subtree is respected on ucs-side in read-mode"
## exposure: dangerous
## packages:
## - univention-ad-connector

. "$TESTLIBPATH/base.sh" || exit 137
. "$TESTLIBPATH/udm.sh" || exit 137
. "$TESTLIBPATH/random.sh" || exit 137 

. "adconnector.sh" || exit 137
test -n "$connector_ad_ldap_host" || exit 137


CONTAINER1="$(random_chars)"
CONTAINER2="$(random_chars)"

SYNCMODE="$(ad_get_sync_mode)"
ad_set_sync_mode "sync"

UDM_container_cn_name="$CONTAINER1"
AD_CONTAINER_DN="CN=$UDM_container_cn_name,$(ad_get_base)"
udm_create "container/cn" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

udm_exists "container/cn"; fail_bool 0 110
ad_exists "$AD_CONTAINER_DN"; fail_bool 0 110

section "Modify Container-Ignore-Subtree"

invoke-rc.d univention-ad-connector stop

MAIN_FILE="/usr/share/pyshared/univention/connector/ad/main.py"
cp -f "$MAIN_FILE" "$MAIN_FILE".ucs-test-backup
sed -i "s/import mapping/import mapping\nmapping.ad_mapping ['container'].ignore_subtree = mapping.ad_mapping ['container'].ignore_subtree + ['cn=$CONTAINER1,$ldap_base']/" "$MAIN_FILE"

ad_set_sync_mode "read"
invoke-rc.d univention-ad-connector start

section "Create container"
UDM_container_cn_name="$CONTAINER2"
AD_CONTAINER_DN="CN=$UDM_container_cn_name,CN=$CONTAINER1,$(ad_get_base)"

udm_create "container/cn" "" "" "cn=$CONTAINER1,$ldap_base" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

udm_exists  "container/cn" "" "" "cn=$CONTAINER1,$ldap_base"; fail_bool 0 110
ad_exists "$AD_CONTAINER_DN"; fail_bool 1 110

section "Clean up"

udm_remove "container/cn" "" "" "cn=$CONTAINER1,$ldap_base" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_CONTAINER_DN"; fail_bool 1 110
udm_exists  "container/cn" "" "" "cn=$CONTAINER1,$ldap_base"; fail_bool 1 110

invoke-rc.d univention-ad-connector stop
mv -f "$MAIN_FILE".ucs-test-backup "$MAIN_FILE"
ad_set_sync_mode "sync"
invoke-rc.d univention-ad-connector start

UDM_container_cn_name="$CONTAINER1"
AD_CONTAINER_DN="CN=$UDM_container_cn_name,$(ad_get_base)"
udm_remove "container/cn" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_CONTAINER_DN"; fail_bool 1 110
udm_exists  "container/cn"; fail_bool 1 110

ad_set_sync_mode "$SYNCMODE"

exit "$RETVAL"
