#!/usr/share/ucs-test/runner bash 
# shellcheck shell=bash
## desc: "Move an AD-user in sync-mode"
## exposure: dangerous
## packages:
## - univention-s4-connector


# shellcheck source=../../lib/base.sh
. "$TESTLIBPATH/base.sh" || exit 137
# shellcheck source=../../lib/udm.sh
. "$TESTLIBPATH/udm.sh" || exit 137
# shellcheck source=../../lib/random.sh
. "$TESTLIBPATH/random.sh" || exit 137


. "s4connector.sh" || exit 137
test -n "$connector_s4_ldap_host" || exit 137
connector_running_on_this_host || exit 137

UDM_users_user_username="$(random_chars)"
UDM_groups_group_name="$(random_chars)"
AD_USER_DN="CN=$UDM_users_user_username,CN=Users,$(ad_get_base)"
UDM_USER_DN="uid=$UDM_users_user_username,cn=users,$ldap_base"
AD_GROUP_DN="CN=$UDM_groups_group_name,CN=groups,$(ad_get_base)"
UDM_GROUP_DN="cn=$UDM_groups_group_name,cn=groups,$ldap_base"
CONTAINER_NAME="$(random_chars)"
AD_CONTAINER_USER_DN="CN=$UDM_users_user_username,CN=$CONTAINER_NAME,$(ad_get_base)"
UDM_CONTAINER_USER_DN="uid=$UDM_users_user_username,cn=$CONTAINER_NAME,$ldap_base"
AD_CONTAINER_GROUP_DN="CN=$UDM_groups_group_name,CN=$CONTAINER_NAME,$(ad_get_base)"
UDM_CONTAINER_GROUP_DN="cn=$UDM_groups_group_name,cn=$CONTAINER_NAME,$ldap_base"

SYNCMODE="$(ad_get_sync_mode)"

ad_set_sync_mode "sync"

section "Create new container"

ad_container_create "$CONTAINER_NAME" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

section "Create user and group"

ad_createuser "$UDM_users_user_username" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110
ad_group_create "$UDM_groups_group_name" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110
ad_append_to_attribute "$AD_GROUP_DN" "member" "$AD_USER_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

udm_exists "users/user"; fail_bool 0 110
ad_exists "$AD_USER_DN"; fail_bool 0 110

udm_verify_multi_value_udm_attribute_contains_ignore_case "users" \
	"$UDM_USER_DN" "groups/group"; fail_bool 0 110
udm_verify_multi_value_udm_attribute_contains_ignore_case "groups" \
	"$UDM_GROUP_DN" "users/user"; fail_bool 0 110
ad_verify_multi_value_attribute_contains "$AD_GROUP_DN" "member" "$AD_USER_DN"; fail_bool 0 110
ad_verify_multi_value_attribute_contains "$AD_USER_DN" "memberOf" "$AD_GROUP_DN"; fail_bool 0 110

section "Move user and group"

ad_move "$AD_USER_DN" "$AD_CONTAINER_USER_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110
ad_move "$AD_GROUP_DN" "$AD_CONTAINER_GROUP_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

udm_exists "users/user"; fail_bool 1 110
udm_exists "users/user" "" "" "cn=$CONTAINER_NAME,$ldap_base"; fail_bool 0 110
udm_exists "groups/group"; fail_bool 1 110
udm_exists "groups/group" "" "" "cn=$CONTAINER_NAME,$ldap_base"; fail_bool 0 110
ad_exists "$AD_USER_DN"; fail_bool 1 110
ad_exists "$AD_CONTAINER_USER_DN"; fail_bool 0 110
ad_exists "$AD_GROUP_DN"; fail_bool 1 110
ad_exists "$AD_CONTAINER_GROUP_DN"; fail_bool 0 110

udm_verify_multi_value_udm_attribute_contains_ignore_case "users" \
	"$UDM_CONTAINER_USER_DN" "groups/group"; fail_bool 0 110
udm_verify_multi_value_udm_attribute_contains_ignore_case "groups" \
	"$UDM_CONTAINER_GROUP_DN" "users/user"; fail_bool 0 110
ad_verify_multi_value_attribute_contains "$AD_CONTAINER_GROUP_DN" \
	"member" "$AD_CONTAINER_USER_DN"; fail_bool 0 110
ad_verify_multi_value_attribute_contains "$AD_CONTAINER_USER_DN" \
	"memberOf" "$AD_CONTAINER_GROUP_DN"; fail_bool 0 110

section "Clean up"

ad_delete "$AD_CONTAINER_USER_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110
ad_delete "$AD_CONTAINER_GROUP_DN" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "$AD_CONTAINER_USER_DN"; fail_bool 1 110
udm_exists "users/user" "" "" "cn=$CONTAINER_NAME,$ldap_base"; fail_bool 1 110
ad_exists "$AD_CONTAINER_GROUP_DN"; fail_bool 1 110
udm_exists "users/user" "" "" "cn=$CONTAINER_NAME,$ldap_base"; fail_bool 1 110

ad_delete "CN=$CONTAINER_NAME,$(ad_get_base)" || fail_test 110

ad_set_sync_mode "$SYNCMODE"

exit "$RETVAL"
