#!/usr/share/ucs-test/runner bash
## desc: "Check whether the User-Ignore-Subtree is respected on ad-side in write-mode"
## exposure: dangerous
## packages:
## - univention-ad-connector

. "$TESTLIBPATH/base.sh" || exit 137
. "$TESTLIBPATH/udm.sh" || exit 137
. "$TESTLIBPATH/random.sh" || exit 137 

. "adconnector.sh" || exit 137
test -n "$connector_ad_ldap_host" || exit 137


UDM_users_user_username="$(random_chars)"
AD_GROUP_DN="CN=$UDM_groups_group_name,CN=groups,$(ad_get_base)"
UDM_GROUP_DN="cn=$UDM_groups_group_name,cn=groups,$ldap_base"
AD_USER_DN="CN=$UDM_users_user_username,CN=Users,$(ad_get_base)"

SYNCMODE="$(ad_get_sync_mode)"

section "Modify User-Ignore-Subtree"

invoke-rc.d univention-ad-connector stop

MAIN_FILE="/usr/share/pyshared/univention/connector/ad/main.py"
cp -f "$MAIN_FILE" "$MAIN_FILE".ucs-test-backup
sed -i "s/import mapping/import mapping\nmapping.ad_mapping ['user'].ignore_subtree = mapping.ad_mapping ['user'].ignore_subtree + ['cn=users,$ldap_base']/" "$MAIN_FILE"

ad_set_sync_mode "write"
invoke-rc.d univention-ad-connector start

section "Create user"

ad_createuser "$UDM_users_user_username" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_USER_DN"; fail_bool 0 110
udm_exists "users/user"; fail_bool 1 110

section "Clean up"

ad_delete "$AD_USER_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_USER_DN"; fail_bool 1 110
udm_exists "users/user"; fail_bool 1 110

invoke-rc.d univention-ad-connector stop
mv -f "$MAIN_FILE".ucs-test-backup "$MAIN_FILE"
ad_set_sync_mode "$SYNCMODE"
invoke-rc.d univention-ad-connector start

exit "$RETVAL"
