#!/usr/share/ucs-test/runner bash
# shellcheck shell=bash
## desc: "Create two nested groups on ucs-side and unnest them in sync-mode .This will fail on w2k and w2k3. Can't consider that in the test, as I can't distinguish between w2k3 and w2k8 yet."
## exposure: dangerous
## packages:
## - univention-ad-connector
## bugs:
##  - 18680
## tags:
##  - groupsync
##  - skip_admember

# shellcheck source=../../lib/base.sh
. "$TESTLIBPATH/base.sh" || exit 137
# shellcheck source=../../lib/udm.sh
. "$TESTLIBPATH/udm.sh" || exit 137
# shellcheck source=../../lib/random.sh
. "$TESTLIBPATH/random.sh" || exit 137 

. "adconnector.sh" || exit 137
test -n "$connector_ad_ldap_host" || exit 137


INNER_GROUP="$(random_chars)"
OUTER_GROUP="$(random_chars)"

SYNCMODE="$(ad_get_sync_mode)"
ad_set_sync_mode "sync"

ad_group_create "$INNER_GROUP" || fail_test 110
ad_group_create "$OUTER_GROUP" || fail_test 110

ad_append_to_attribute "CN=$OUTER_GROUP,CN=groups,$(ad_get_base)" \
	"member" "CN=$INNER_GROUP,CN=groups,$(ad_get_base)" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

ad_exists "CN=$OUTER_GROUP,CN=groups,$(ad_get_base)"; fail_bool 0 110
ad_exists "CN=$INNER_GROUP,CN=groups,$(ad_get_base)"; fail_bool 0 110

UDM_groups_group_name="$INNER_GROUP"
udm_exists "groups/group"; fail_bool 0 110
UDM_groups_group_name="$OUTER_GROUP"
udm_exists "groups/group"; fail_bool 0 110

UDM_groups_group_name="$OUTER_GROUP"
udm_verify_multi_value_udm_attribute_contains "nestedGroup" \
	"cn=$INNER_GROUP,cn=groups,$ldap_base" "groups/group"; fail_bool 0 110
UDM_groups_group_name="$INNER_GROUP"
udm_verify_multi_value_udm_attribute_contains "memberOf" \
	"cn=$OUTER_GROUP,cn=groups,$ldap_base" "groups/group"; fail_bool 0 110

ad_verify_multi_value_attribute_contains "CN=$OUTER_GROUP,CN=groups,$(ad_get_base)" \
	"member" "CN=$INNER_GROUP,CN=groups,$(ad_get_base)"; fail_bool 0 110
ad_verify_multi_value_attribute_contains "CN=$INNER_GROUP,CN=groups,$(ad_get_base)" \
	"memberOf" "CN=$OUTER_GROUP,CN=groups,$(ad_get_base)"; fail_bool 0 110

ad_remove_from_attribute "CN=$OUTER_GROUP,CN=groups,$(ad_get_base)" \
	"member" "CN=$INNER_GROUP,CN=groups,$(ad_get_base)" || fail_test 110
ad_wait_for_synchronization; fail_bool 0 110

UDM_groups_group_name="$OUTER_GROUP"
udm_verify_multi_value_udm_attribute_contains "nestedGroup" \
	"cn=$INNER_GROUP,cn=groups,$ldap_base" "groups/group"; fail_bool 1 121 "See #18680"
UDM_groups_group_name="$INNER_GROUP"
udm_verify_multi_value_udm_attribute_contains "memberOf" \
	"cn=$OUTER_GROUP,cn=groups,$ldap_base" "groups/group"; fail_bool 1 121 "See #18680"

ad_verify_multi_value_attribute_contains "CN=$OUTER_GROUP,CN=groups,$(ad_get_base)" \
	"member" "CN=$INNER_GROUP,CN=groups,$(ad_get_base)"; fail_bool 1 110
ad_verify_multi_value_attribute_contains "CN=$INNER_GROUP,CN=groups,$(ad_get_base)" \
	"memberOf" "CN=$OUTER_GROUP,CN=groups,$(ad_get_base)"; fail_bool 1 110

section "Clean up"

UDM_groups_group_name="$INNER_GROUP"
udm_remove "groups/group" || fail_test 110
UDM_groups_group_name="$OUTER_GROUP"
udm_remove "groups/group" || fail_test 110 

ad_set_sync_mode "$SYNCMODE"

exit "$RETVAL"
