DBA Data[Home] [Help]
Skip to content

PACKAGE BODY: APPS.FND_LDAP_USER

Source


1 package body fnd_ldap_user as
2 /* $Header: AFSCOLUB.pls 120.71 2012/04/12 20:13:54 ctilley ship $ */
3 --
4 -------------------------------------------------------------------------------
5 -- Start of Package Globals
6 
7   G_CREATE             constant  pls_integer := 1;
8   G_UPDATE             constant  pls_integer := 2;
9   G_MODULE_SOURCE  constant varchar2(80) := 'fnd.plsql.oid.fnd_ldap_user.';
10   G_OID_USER_EXISTS constant pls_integer := 2;
11 
12 -- End of Package Globals
13 --
14 -------------------------------------------------------------------------------
15 
16 function delete_user_nodes(p_ldap_session in dbms_ldap.session, p_orclguid in fnd_user.user_guid%type) return pls_integer;
17 function delete_user_subscription(p_ldap_session in dbms_ldap.session, guid raw) return pls_integer;
18 function delete_uniquemember(p_ldap_session in dbms_ldap.session, p_orclguid in fnd_user.user_guid%type) return pls_integer;
19 procedure ProcessLoadedLpadUserRecord (p_ldap_user  IN OUT nocopy fnd_ldap_user.ldap_user_type ,realmDN in varchar2 ,dn_z in varchar2 );
20 --function CanSync ( p_user_id in pls_integer, p_user_name in varchar2 ) return boolean;
21 function get_user_guid(p_ldap_session in dbms_ldap.session, p_user_name in varchar2, dn out nocopy varchar2) return raw ;
22 function isValueOf( u ldap_user_type, fld in varchar2, val in varchar2 ) return boolean;
23 function get_user_guid( p_user_name in varchar2) return raw ;
24 function CanUpdate( attr in varchar2 , user_name in varchar2 , realm in varchar2,x_user_creation in boolean default FALSE) return boolean;
25 function CanPopulate( attr in varchar2 , user_name in varchar2 , realm in varchar2) return boolean;
26 -- Bug 9271995 : internal signature
27 procedure update_user(p_user_guid in raw,
28                      p_user_name in varchar2,
29                      p_password in varchar2 default null,
30                      p_start_date in date default null,
31                      p_end_date in date default null,
32                      p_description in varchar2 default null,
33                      p_email_address in varchar2 default null,
34                      p_fax in varchar2 default null,
35                      p_expire_password in pls_integer,
36                      x_password out nocopy varchar2,
37                      x_result out nocopy pls_integer,
38 		     x_user_creation in boolean default FALSE ) ;
39 
40 --
41 -- Type to hold preferences
42 TYPE update_record IS record (
43   att varchar2(200),
44   op  varchar2(10),
45   val varchar2(4000)
46 );
47 
48 TYPE update_list IS table OF update_record INDEX BY pls_integer;
49 
50 PROCEDURE ProcessUpdateRec(ldap in dbms_ldap.session, dn in varchar2, upd in update_list);
51 
52 --
53 -- LOCAL EXCEPTIONS
54  CANNOT_CREATE_EXCEPTION EXCEPTION;
55 
56  duplicate_dn_EXCEPTION EXCEPTION;
57  duplicate_username_EXCEPTION EXCEPTION;
58  link_create_failed_EXCEPTION EXCEPTION;
59 
60 
61    cache_user_name   varchar2(200) := null;
62    cache_nna         varchar2(200) := null;
63    cache_default_nna varchar2(200) := null;
64 
65 --
66 -------------------------------------------------------------------------------
67 --- REMOVED
68 -- function add_uniquemember(p_ldap_user in fnd_ldap_util.ldap_user_type) return pls_integer is
69 -- translate_ldap_error: Internal
70 -- Will attempt to translate the sqlerrms from an dbms_ldap operation into a FND message
71 
72 -------------------------------------------------------------------------------
73 function translate_ldap_error( errm in varchar2) return varchar2
74 is
75 begin
76 
77  if (instr(errm,':9000')>0 ) then return 'FND_SSO_PASSWORD_EXPIRED'; end if;
78  if (instr(errm,':9001')>0 ) then return 'FND_SSO_LOCKED'; end if;
79  if (instr(errm,':9002')>0 ) then return 'FND_SSO_PASSWORD_EXPIRED'; end if;
80  if (instr(errm,':9003')>0 ) then return 'FND_SSO_PASSWORD_POLICY_ERR'; end if;
81  if (instr(errm,':9004')>0 ) then return 'FND_SSO_PASSWORD_POLICY_ERR'; end if;
82  if (instr(errm,':9005')>0 ) then return 'FND_SSO_PASSWORD_POLICY_ERR'; end if;
83  if (instr(errm,':9006')>0 ) then return 'FND_SSO_PASSWORD_POLICY_ERR'; end if;
84  if (instr(errm,':9007')>0 ) then return 'FND_SSO_PASSWORD_POLICY_ERR'; end if;
85  if (instr(errm,':9008')>0 ) then return 'FND_SSO_UNEXP_ERROR'; end if;
86  if (instr(errm,':9009')>0 ) then return 'FND_SSO_UNEXP_ERROR'; end if;
87  if (instr(errm,':9010')>0 ) then return 'FND_SSO_UNEXP_ERROR'; end if;
88  if (instr(errm,':9011')>0 ) then return 'FND_SSO_CL_IP_LOCK'; end if;
89  if (instr(errm,':9050')>0 ) then return 'FND_SSO_USER_DISABLED'; end if;
90  if (instr(errm,':9051')>0 ) then return 'FND_SSO_LOCKED'; end if;
91  if (instr(errm,':9052')>0 ) then return 'FND_SSO_USER_DISABLED'; end if;
92  if (instr(errm,':9053')>0 ) then return 'FND_SSO_USER_DISABLED'; end if;
93  return 'FND_SSO_UNEXP_ERROR';
94 
95 
96 end translate_ldap_error;
97 
98 --
99 -------------------------------------------------------------------------------
100 PROCEDURE delete_user(ldapSession in dbms_ldap.session, p_user_guid in  fnd_user.user_guid%type ,
101                      x_result out nocopy pls_integer,
102                      p_forced in boolean default false) is
103 
104 
105   l_module_source   varchar2(256) := G_MODULE_SOURCE || 'delete_user: ';
106   l_orclappname       varchar2(256);
107   l_user_name          varchar2(256);
108   subsNode            varchar2(1000);
109   --ldapSession         dbms_ldap.session;
110   l_message dbms_ldap.message := null;
111   l_entry dbms_ldap.message := null;
112   l_attrs dbms_ldap.string_collection;
113   l_attrs_vals dbms_ldap.string_collection;
114   l_isenabled         varchar2(100);
115   l_creatorname       varchar2(1000);
116   searchNodes dbms_ldap.string_collection;
117   l_filter varchar2(256);-- := 'cn=' || p_user_name; Commented out by scheruku to use orclguid instead
118   l_base varchar2(1000);
119   l_guid raw(256);
120   l_fnd_op pls_integer;
121   l_oid_op pls_integer;
122   sso_registration_failure exception;
123 --  l_apps_user_key_type fnd_oid_util.apps_user_key_type;
124   l_orclguid fnd_user.user_guid%type;
125 begin
126 
127   -- initializing
128   l_module_source := G_MODULE_SOURCE || 'delete_user: ';
129   x_result := fnd_ldap_util.G_SUCCESS;
130 
131   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
132   then
133     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
134   end if;
135 
136 --scheruku :: Added logic to get orclguid from fnd_user
137 -- l_apps_user_key_type := fnd_oid_util.get_fnd_user(p_user_name => p_user_name);
138 -- l_orclguid := l_apps_user_key_type.user_guid;
139    l_orclguid :=  p_user_guid;
140 
141  if(l_orclguid IS NULL)
142  then
143   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
144   then
145     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,
146              'NULL guid in FND_USER');
147   end if;
148     x_result := fnd_ldap_util.G_FAILURE;
149  else
150   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
151   then
152     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,
153              'FND_USER GUID::'||l_orclguid);
154   end if;
155   l_filter := 'orclguid='||l_orclguid;
156   --ldapSession := fnd_ldap_util.get_oid_session;
157   --searchNodes := fnd_ldap_util.get_search_nodes;
158   l_base := ''; -- don't need any more for guid search
159   l_attrs(0) := 'orclisenabled';
160   l_attrs(1) := 'creatorsname';
161   l_attrs(2) := 'orclguid';
162 
163     -- search and delete the user only if the creator is the current apps instance and if the user is disabled.
164 
165    --for i in 0..searchNodes.count-1 loop
166       --l_base := searchNodes(i);
167       x_result := dbms_ldap.search_s(ld => ldapSession, base => l_base,
168       scope => dbms_ldap.SCOPE_SUBTREE, filter => l_filter, attrs => l_attrs, attronly => 0, res => l_message);
169       if (x_result is not NULL) then
170 
171         l_entry := dbms_ldap.first_entry(ldapSession, l_message);
172         if l_entry is not null then
173 
174           -- get the first entry
175           l_entry := dbms_ldap.first_entry(ldapSession, l_message);
176 
177           l_attrs_vals := dbms_ldap.get_values(ldapSession, l_entry, 'creatorsname');
178           l_creatorname := l_attrs_vals(0);
179           l_attrs_vals := dbms_ldap.get_values(ldapSession, l_entry, 'orclisenabled');
180           if l_attrs_vals is not NULL and l_attrs_vals.count > 0 then
181             l_isenabled := l_attrs_vals(0);
182           end if;
183           l_attrs_vals := dbms_ldap.get_values(ldapSession, l_entry, 'orclguid');
184           l_guid := l_attrs_vals(0);
185 
186           if (p_forced OR (upper(l_creatorname) = upper(fnd_ldap_util.get_orclappname)
187               and l_isenabled is not NULL
188               and (upper(l_isenabled) = 'INACTIVE' or upper(l_isenabled) = 'DISABLED')
189                 ) ) then
190             x_result := delete_user_subscription(ldapSession, l_guid);
191 --            x_result := delete_uniquemember(ldapSession, p_user_name);
192 --            x_result := delete_user_nodes(ldapSession, p_user_name);
193 
194 --scheruku: Calling the APIS which use the GUID instead
195             x_result := delete_uniquemember(ldapSession, l_orclguid);
196             x_result := delete_user_nodes(ldapSession, l_orclguid);
197 
198 
199           --end if;
200         --end if;
201       --end if;
202    --end loop;
203    --x_result := fnd_ldap_util.unbind(ldapSession);
204 
205           ELSE
206 
207                 if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
208                 then
209                   if (upper(l_creatorname) = upper(fnd_ldap_util.get_orclappname)) THEN
210                          fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'NOT DELETED BECAUSE  was created  by '||l_creatorname);
211                    END IF;
212 
213                   if NOT (l_isenabled is not NULL and (upper(l_isenabled) = 'INACTIVE' or upper(l_isenabled) = 'DISABLED'))
214                     THEN
215                          fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'NOT DELETED BECAUSE  is still enabled '||l_isenabled);
216                    END IF;
217                 end if;
218           end if;
219         end if;
220       end if;
221 
222    if (x_result = dbms_ldap.SUCCESS) then
223         x_result := fnd_ldap_util.G_SUCCESS;
224    end if;
225   end if;-- fnd_user guid null check if block ends here
226 
227   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
228   then
229     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'End');
230   end if;
231 
232 exception
233   when others then
234     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
235     then
236       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
237     end if;
238     x_result := fnd_ldap_util.G_FAILURE;
239 
240 end delete_user;
241 
242 procedure delete_user(p_user_guid in  fnd_user.user_guid%type ,
243                      x_result out nocopy pls_integer,
244                      p_forced in boolean ) is
245 
246 ldapSession  dbms_ldap.session;
247 dummy pls_integer;
248 BEGIN
249   ldapSession := fnd_ldap_util.c_get_oid_session(dummy);
250   delete_user(ldapSession,p_user_guid,x_result,p_forced);
251   fnd_ldap_util.c_unbind(ldapSession,dummy);
252 end delete_user;
253 procedure delete_user(p_user_guid in  fnd_user.user_guid%type ,
254                      x_result out nocopy pls_integer ) is
255 
256 ldapSession  dbms_ldap.session;
257 dummy pls_integer;
258 BEGIN
259 
260   delete_user(p_user_guid,x_result,false);
261 
262 end delete_user;
263 
264 
265 --
266 
267 -------------------------------------------------------------------------------
268 --** INTERNAL SIGNATURE
269 -- The external siganture can only call change_password for updates
270 -- Only from this package we can call change_password for creation phase
271 --
272 procedure change_password(p_user_guid in raw,
273                           p_user_name in varchar2,
274                           p_new_pwd in varchar2,
275                           p_expire_password in pls_integer,
276                           x_password out nocopy varchar2,
277                           x_result out nocopy pls_integer,
278                           p_user_creation in boolean default FALSE ) is
279   no_such_user_exp    exception;
280   PRAGMA EXCEPTION_INIT (no_such_user_exp, -20001);
281   l_module_source   varchar2(256):= G_MODULE_SOURCE || 'change_password: ';
282 
283 BEGIN
284    if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
285       then
286         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin - call update user');
287    end if;
288 
289    update_user(p_user_guid =>p_user_guid,
290                      p_user_name=>p_user_name,
291                      p_password => p_new_pwd,
292                      p_expire_password =>p_expire_password,
293                      x_password=>x_password,
294                      x_result => x_result,
295 		     x_user_creation=>p_user_creation);
296 
297   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
298       then
299       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
300   end if;
301 
302  exception
303     when no_such_user_exp then
304       fnd_message.set_name ('FND', 'FND_SSO_USER_NOT_FOUND');
305       if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
306       then
307         fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
308       end if;
309       x_result := fnd_ldap_util.G_FAILURE;
310     when others then
311       fnd_message.set_name ('FND', 'FND_SSO_UNEXP_ERROR');
312       if (fnd_log.LEVEL_EXCEPTION>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
313       then
314         fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
315       end if;
316     --x_result := fnd_ldap_util.G_FAILURE;
317     -- bug 4573677
318     raise;
319 
320 end change_password;
321 procedure change_password(p_user_guid in raw,
322                           p_user_name in varchar2,
323                           p_new_pwd in varchar2,
324                           p_expire_password in pls_integer,
325                           x_password out nocopy varchar2,
326                           x_result out nocopy pls_integer ) is
327 BEGIN
328    change_password(p_user_guid,p_user_name,p_new_pwd,p_expire_password,x_password,x_result,FALSE);
329 END change_password;
330 --
331 -------------------------------------------------------------------------------
332 function user_exists_by_guid( guid in raw ) return pls_integer
333 is
334   dn varchar2(2000);
335   result pls_integer;
336 
337 begin
338 
342      else
339       dn := fnd_ldap_util.get_dn_for_guid(guid);
340      if (dn is not null) then
341          result := FND_LDAP_UTIL.G_SUCCESS;
343          result := FND_LDAP_UTIL.G_FAILURE;
344      end if;
345      return result;
346 
347   EXCEPTION WHEN OTHERS THEN
348       IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
349          fnd_log.string(fnd_log.LEVEL_EXCEPTION, G_MODULE_SOURCE || 'user_exists_by_guid:', sqlerrm);
350      END IF;
351      raise;
352 
353 end user_exists_by_guid;
354 
355 -------------------------------------------------------------------------------
356 procedure change_user_name(p_user_guid in raw,
357                           p_old_user_name in varchar2,
358                           p_new_user_name in varchar2,
359                           x_result out nocopy pls_integer) is
360   l_module_source VARCHAR2(256);
361   l_user_id fnd_user.user_id%type;
362   l_to_synch BOOLEAN;
363   ldap dbms_ldap.session;
364   flag pls_integer;
365   user_rec FND_LDAP_USER.ldap_user_type;
366   invalid_new_user_exp EXCEPTION;
367   no_such_user_exp     EXCEPTION;
368   dn VARCHAR2(4000);
369   val varchar2(4000);
370   nna varchar2(200);
371   handle pls_integer;
372   upd update_list;
373   target dbms_ldap.string_collection;
374   fld VARCHAR2(200);
375   i pls_integer;
376   ma dbms_ldap.mod_array;
377   found boolean;
378   PRAGMA EXCEPTION_INIT (no_such_user_exp, -20001);
379   x_fnd pls_integer;
380   x_oid pls_integer;
381 
382 begin
383   l_module_source             := G_MODULE_SOURCE || 'change_user_name: ';
384   IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
385     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'Begin');
386   END IF;
387   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
388     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'guid:'||p_user_guid||' old='||p_old_user_name||' new='||p_new_user_name);
389   END IF;
390   -- Check the obivious: No change (ignore case)
391   IF (upper(p_old_user_name)     =upper(p_new_user_name))THEN
392     IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
393       fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END-> SAME NAMES, no changes!');
394     END IF;
395     x_result:=fnd_ldap_util.G_SUCCESS;
396     RETURN;
397   END IF;
398   -- look for the user_id.
399   -- this procedure asumes that name was already changed on FND_USER (not commit maybe)
400   BEGIN
401      SELECT user_id
402        INTO l_user_id
403        FROM FND_USER
404       WHERE user_guid=p_user_guid
405     AND user_name    =p_old_user_name;
406   EXCEPTION
407   WHEN NO_DATA_FOUND THEN
408     IF (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
409       fnd_log.string(fnd_log.LEVEL_UNEXPECTED , l_module_source, 'Cannot locate user_name[new]='||p_new_user_name||' guid='|| p_user_guid||':'||sqlerrm);
410     END IF;
411     x_result:=fnd_ldap_util.G_FAILURE;
412     RETURN;
413   END;
414   /** to do - what if there are multiple linked users ? **/
415 	if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
416   then
417     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'USER id:: '||l_user_id);
418   end if;
419   l_to_synch := CanSync(l_user_id,p_old_user_name);
420   IF (l_to_synch) THEN
421     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
422       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'SYNC user '||p_new_user_name);
423     END IF;
424     ldap := fnd_ldap_util.c_get_oid_session(flag);
425     IF FND_LDAP_UTIL.loadLdapRecord( ldap, user_rec.user_data, dn , p_user_guid, fnd_ldap_util.G_GUID_KEY) THEN
426       user_rec.dn                 :=dn;
427       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
428         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Updating dn:'||dn);
429       END IF;
430       ProcessLoadedLpadUserRecord(user_rec,NULL,dn);
431       nna := user_rec.NickName_ATT_NAME;
432 
433       FND_SSO_REGISTRATION.is_operation_allowed (
434          p_direction => FND_LDAP_WRAPPER.G_EBIZ_TO_OID,
435          p_entity => FND_LDAP_WRAPPER.G_IDENTITY,
436          p_operation => FND_LDAP_WRAPPER.G_MODIFY,
437          p_attribute => nna,
438          x_fnd_user => x_fnd,
439          x_oid => x_oid,
440          p_user_name => user_rec.user_name,
441          p_realm_dn => user_rec.realmDN);
442 
443       if (x_oid = FND_LDAP_WRAPPER.G_SUCCESS ) THEN
444           i := user_rec.user_data(nna).first;
445           found := false;
446           target.delete;
447           IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
448             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Verifiying that Nickname atrribute does contain  username in '||nna);
449           END IF;
450 
451           while i is not null loop
452               if  (user_rec.user_data(nna)(i)=p_old_user_name) THEN
453                   found := true;
454                   target(target.count) := p_new_user_name;
455                   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
456                       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'It does');
457                   END IF;
458 
459               ELSE
460                   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
461                       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'may need to keep '||user_rec.user_data(nna)(i));
462                   END IF;
463 
464                  target(target.count) := user_rec.user_data(nna)(i);
465               END IF;
466               i:= user_rec.user_data(nna).next(i);
467           end loop;
468           IF found THEN
472              ma := dbms_ldap.create_mod_array(num=> 1);
469                   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
470                       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Updating LDAP ');
471                   END IF;
473              dbms_ldap.populate_mod_array(modptr => ma,
474                      mod_op => DBMS_LDAP.MOD_REPLACE,
475                      mod_type => nna,
476                      modval => target);
477              x_result:= dbms_ldap.modify_s(ldap,user_rec.dn, ma);
478             if (x_result = dbms_ldap.SUCCESS) then
479                        x_result := fnd_ldap_util.G_SUCCESS;
480                   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
481                       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Updating succedd ');
482                   END IF;
483             end if;
484             dbms_ldap.free_mod_array(modptr => ma);
485         ELSE
486           IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
487             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Cannot update nickname attribute');
488           END IF;
489         END IF;
490       ELSE
491 
492               IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
493                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'NickName att does not contain username, no changes ');
494               END IF;
495       END IF;
496     ELSE
497       IF (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
498         fnd_log.string(fnd_log.LEVEL_UNEXPECTED , l_module_source, 'Cannot locate user_name[new]='||p_new_user_name||' guid='|| p_user_guid||':'||sqlerrm);
499       END IF;
500       raise no_such_user_exp;
501     END IF;
502     fnd_ldap_util.c_unbind(ldap,flag);
503   ELSE
504     x_result                    := fnd_ldap_util.G_SUCCESS;
505     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
506       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User is a local user or Synch profile is disabled.');
507     END IF;
508   END IF;
509 
510 
511 
512   IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
513     IF (x_result               = fnd_ldap_util.G_SUCCESS ) THEN
514       fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'End-> fnd_ldap_util.G_SUCCESS ');
515     ELSE
516       fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'End-> fnd_ldap_util.G_FAIL ');
517     END IF;
518   END IF;
519 
520 
521 
522 exception
523   when invalid_new_user_exp then
524       fnd_ldap_util.c_unbind(ldap,flag);
525       fnd_message.set_name ('FND', 'FND_SSO_INVALID_NEW_USER_NAME');
526       if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
527       then
528           fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
529       end if;
530       x_result := fnd_ldap_util.G_FAILURE;
531   when no_such_user_exp then
532       fnd_ldap_util.c_unbind(ldap,flag);
533       fnd_message.set_name ('FND', 'FND_SSO_USER_NOT_FOUND');
534       if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
535       then
536         fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
537       end if;
538       x_result := fnd_ldap_util.G_FAILURE;
539   when others then
540       fnd_message.set_name ('FND', 'FND_SSO_UNEXP_ERROR');
541       if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
542       then
543         fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
544       end if;
545       x_result := fnd_ldap_util.G_FAILURE;
546 end change_user_name;
547 --
548 -------------------------------------------------------------------------------
549 --
550 -- 1) Fills an usertype fnd_ldap_util.ldap_user_type and call create_user(fnd_ldap_util.ldap_user_type)
551 --    if it returns failure put a FND_SSO_USER_EXIST on the errors tack
552 --
553 -- 2) Retreive its guid
554 -- 3) Loook at the APPS_SSO_LOCAL_LOGIN ( user=-1 level, which may or may not be site)
555 --      If its SSO set the FND_USER password to external
556 -- Any EXCEPTION will be logged and passed up
557 
558 
559 FUNCTION create_ldap_user (
560     p_ldap_session IN dbms_ldap.session,
561     p_ldap_user    IN OUT nocopy ldap_user_type)
562   RETURN pls_integer
563 IS
564   l_module_source VARCHAR2(256);
565   retval pls_integer;
566   ldap_result pls_integer;
567   modArray dbms_ldap.mod_array;
568   atName VARCHAR2(4000);
569   atVal  VARCHAR2(4000);
570   handler pls_integer;
571   myid INTEGER;
572   l_dn VARCHAR2(4000);
573   list1 dbms_ldap.string_collection;
574   n pls_integer;
575   i pls_integer;
576   some_data boolean := false;
577 BEGIN
578   l_module_source := G_MODULE_SOURCE || 'create_ldap_user: ';
579   retval := fnd_ldap_util.G_FAILURE;
580 
581   IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
582     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'Begin');
583 
584     -- LOG THE ATTEMPTED CHANGES
585     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
586       BEGIN
587         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'username:'||p_ldap_user.user_name||'  DN :'||l_dn);
588         myid:= sys_context('USERENV', 'SESSIONID');
589         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Attempt to create LDAP user ['||p_ldap_user.user_name||'] ['||myid||']');
590         IF firstValue(p_ldap_user, atname, atval, handler) THEN
591           WHILE (atName IS NOT NULL)
592           LOOP
593             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, '['||myid||'] '||atName||':'||atVal);
594             IF (NOT NextValue(p_ldap_user,atName,atVal,handler) )THEN
598           END LOOP;
595               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, '['||myid||'] END ');
596               atName:=NULL;
597             END IF;
599         END IF;
600       EXCEPTION WHEN OTHERS THEN
601         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Error during log operation '||sqlerrm);
602       END;
603     END IF;
604   END IF;
605 
606   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
607     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Populate modarray : count='|| p_ldap_user.user_data.count);
608   END IF;
609 
610   -- Now we need to figure out the DN and the realm
611   FND_OID_PLUG.completeforcreate(p_ldap_session,p_ldap_user);
612 
613 
614   FND_OID_PLUG.fixupLDAPUser(p_ldap_user,FND_OID_PLUG.G_CREATE_USER);
615 
616   modArray := dbms_ldap.create_mod_array(num=> p_ldap_user.user_data.count);
617   atName := p_ldap_user.user_data.first ;
618 
619   WHILE atName IS NOT NULL
620   LOOP
621             -- Login current data
622         IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
623             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, '  adding '|| atName);
624             FOR i IN p_ldap_user.user_data(atName).first .. p_ldap_user.user_data(atName).last
625             LOOP
626                 IF (p_ldap_user.user_data(atName).exists(i) ) THEN
627                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, '        '||p_ldap_user.user_data(atName)(i) );
628                 ELSE
629                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, '        missing element '||i );
630                 END IF;
631             END LOOP;
632         END IF;
633 
634         list1.delete();
635         n:=0;
636         i:=p_ldap_user.user_data(atName).first;
637 
638         if lower(atName)='objectclass' or
639          CanPopulate(atName,p_ldap_user.user_name,p_ldap_user.realmDN) THEN
640             LOOP
641               list1(n):= p_ldap_user.user_data(atName)(i);
642               n := n+1;
643               i := p_ldap_user.user_data(atName).next(i);
644               EXIT WHEN i IS NULL;
645             END LOOP;
646             dbms_ldap.populate_mod_array(modptr => modArray, mod_op => DBMS_LDAP.MOD_ADD, mod_type => atName, modval => list1);
647             some_data := true;
648         ELSE
649           IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
650              fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Populate modarray : count='|| p_ldap_user.user_data.count);
651           END IF;
652         END IF;
653         atName := p_ldap_user.user_data.next(atName);
654   END LOOP;
655 
656   if (some_data) THEN
657        ldap_result := dbms_ldap.add_s(ld => p_ldap_session, entrydn => p_ldap_user.dn , modptr =>modArray);
658   ELSE
659        IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
660           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'add_s no data to load');
661        END IF;
662   END IF;
663   dbms_ldap.free_mod_array(modArray);
664   IF ldap_result = dbms_ldap.SUCCESS THEN
665 
666        retval := fnd_ldap_util.G_SUCCESS;
667        IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
668           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'created user:' || p_ldap_user.user_name);
669        END IF;
670 
671         -- get the guid
672        p_ldap_user.user_guid := FND_LDAP_UTIL.get_guid_for_dn(p_ldap_session,p_ldap_user.dn );
673        IF (p_ldap_user.user_guid IS NULL) THEN
674           IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
675                 fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Unoticed falure to create created DN [' || p_ldap_user.dn||']');
676           END IF;
677           retval:= fnd_ldap_util.G_FAILURE;
678        ELSE
679           retval := fnd_ldap_util.G_SUCCESS;
680           IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
681             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'new user:' || p_ldap_user.user_name || ' dn:' || p_ldap_user.dn );
682             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'new user:' || p_ldap_user.user_name || ' guid:' || p_ldap_user.user_guid );
683           END IF;
684        END IF;
685       ELSE
686         retval := fnd_ldap_util.G_FAILURE;
687         IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
688           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Falied to create ['||p_ldap_user.dn||'] user:'||p_ldap_user.user_name);
689         END IF;
690 
691   END IF;
692   IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
693     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END->'||retval);
694   END IF;
695   RETURN retval;
696 
697 
698 exception
699   when others then
700     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
701     then
702       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
703     end if;
704   raise;
705 
706 END create_ldap_user;
707 --
708 -------------------------------------------------------------------------------
709 /*
710   get_ACCOUNT_dn: returns where to store subscription information at OiD.
711                 Now is simple, in the future may change for multiples realms.
712 */
713 function get_ACCOUNT_dn(p_guid in raw) return varchar2 is
714 begin
715    return 'cn=ACCOUNTS,cn=subscription_data,cn=subscriptions,' || fnd_ldap_util.get_orclappname;
716 end get_ACCOUNT_dn;
717 --
718 -------------------------------------------------------------------------------
719 function create_user_subscription(ldapSession in dbms_ldap.session, p_user_dn in varchar2 , p_guid in raw)
720 return pls_integer is
721 
725 --userDN varchar2(4000):= p_user_dn;
722 l_module_source   varchar2(256);
723 subsNode varchar2(4000);
724 acctNode varchar2(4000);
726 result pls_integer;
727 retval pls_integer;
728 --ldapSession dbms_ldap.session;
729 modArray  dbms_ldap.mod_array;
730 modmultivalues dbms_ldap.string_collection;
731 i number;
732 flag pls_integer;
733 err varchar2(1000);  --bug 8618800
734 begin
735   l_module_source := G_MODULE_SOURCE || 'create_user_subscription: ';
736   -- set default value to failure. change to success when user created successfully
737   retval := fnd_ldap_util.G_FAILURE;
738   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
739   then
740     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin guid='||p_guid);
741   end if;
742 
743   -- ldapSession := fnd_ldap_util.c_get_oid_session(flag);
744 
745   -- userDN := fnd_ldap_util.get_dn_for_guid(p_guid);
746 
747   acctNode := get_ACCOUNT_dn(p_guid);
748 --  num_attributes := process_attributes(p_ldap_user, x_atts => l_atts,
749   --                                       x_att_values => l_att_values);
750 
751   modArray := dbms_ldap.create_mod_array(num => 2);
752 
753   modmultivalues(0) := 'orclServiceSubscriptionDetail';
754   dbms_ldap.populate_mod_array(modptr => modArray, mod_op => dbms_ldap.mod_add, mod_type => 'objectclass', modval => modmultivalues);
755 
756   modmultivalues(0) := p_user_dn;
757   dbms_ldap.populate_mod_array(modptr => modArray, mod_op => dbms_ldap.mod_add, mod_type => 'seeAlso', modval => modmultivalues);
758 
759   subsNode := 'orclOwnerGUID=' || p_guid|| ',' || acctNode;
760   retval := dbms_ldap.add_s(ld => ldapSession, entrydn => subsNode, modptr => modArray);
761 
762   if (retval = dbms_ldap.SUCCESS) then
763     --retval := add_uniquemember(p_ldap_user);
764     fnd_ldap_util.add_attribute_M(ldapSession,acctNode,'uniqueMember',p_user_dn);
765     retval:= fnd_ldap_util.G_SUCCESS;
766   else
767      if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
768      then
769        fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Failed! retval='||retval||' subsNode:'||subsNode);
770      end if;
771   end if;
772 
773   dbms_ldap.free_mod_array(modptr => modArray);
774   --fnd_ldap_util.c_unbind(ldapSession,flag);
775 
776   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
777   then
778     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
779   end if;
780 
781   return retval;
782 
783 exception
784 when others then
785     err := sqlerrm;  --bug 8618800
786 
787     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
788     then
789        fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
790     end if;
791   -- Bug 8618800 if already exists continue
792     if (instr(err,'Already exists. Object already exists') > 0) then
793     	if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)	 then
794             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User already subscribed');
795         end if;
796  	retval :=  fnd_ldap_util.G_SUCCESS;
797 	return retval;
798     else
799        if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)	 then
800            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Failed! retval='||retval||' subsNode:'||subsNode);
801        end if;
802        raise;
803     end if;
804 
805 
806 end create_user_subscription;
807 --
808 -------------------------------------------------------------------------------
809 procedure decode_dates(p_user_name in varchar2, p_start_date in date, p_end_date in date, x_orclisEnabled out nocopy varchar2, x_user_id out nocopy fnd_user.user_id%type) is
810 
811   -- bug 12925276 : to_date(null) is returned instead of null to indicate that current return type is date and hence make decode() function correctly.
812   -- Also see base bug 13654885 and bug 1124610
813   cursor fnd_dates is
814     select user_id, decode(p_start_date, fnd_user_pkg.null_date, to_date(null),
815                                 null, start_date,
816                                 p_start_date) l_start_date,
817            decode(p_end_date, fnd_user_pkg.null_date, to_date(null),
818                                 null, end_date,
819                                 p_end_date) l_end_date
820            from fnd_user
821            where user_name = p_user_name;
822 
823   l_rec             fnd_dates%rowtype;
824   l_found           boolean;
825   l_user_id fnd_user.user_id%type;
826   l_start_date date;
827   l_end_date date;
828   l_module_source   varchar2(256);
829   no_such_user_exp  exception;
830 
831 begin
832   l_module_source := G_MODULE_SOURCE || 'decode_dates: ';
833   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
834   then
835     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
836   end if;
837 
838   open fnd_dates;
839   fetch fnd_dates into l_rec;
840   l_found := fnd_dates%found;
841   close fnd_dates;
842 
843   if (not l_found)
844   then
845     raise no_such_user_exp;
846   end if;
847 
848 
849 -- Fetching the user_id also in order to fetch user level profiles after call to this procedure.
850    x_user_id := l_rec.user_id;
851 
852    if ((l_rec.l_start_date is not null and l_rec.l_start_date > sysdate)
853     or
854       (l_rec.l_end_date is not null and l_rec.l_end_date <= sysdate))
855   then
856        if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
857        then
858           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User is disabled');
859        end if;
860        x_orclisEnabled := fnd_oid_util.G_DISABLED;
861 
862   else
866   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
863     x_orclisEnabled := fnd_oid_util.G_ENABLED;
864   end if;
865 
867   then
868     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
869   end if;
870 
871 exception
872 when others then
873   if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
874   then
875     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
876   end if;
877   raise_application_error(-20001, 'FND_SSO_USER_NOT_FOUND');
878 
879 end decode_dates;
880 --
881 -------------------------------------------------------------------------------
882 --
883 --Added by scheruku for Nickname changes
884 -------------------------------------------------------------------------------
885 function delete_user_nodes(p_ldap_session in dbms_ldap.session,
886                      p_orclguid in fnd_user.user_guid%type) return pls_integer is
887 
888 l_module_source   varchar2(256);
889 usersNode varchar2(1000);
890 usersNodes dbms_ldap.string_collection;
891 l_result pls_integer;
892 
893 begin
894   l_module_source := G_MODULE_SOURCE || 'delete_user_nodes: ';
895   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
896   then
897     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
898   end if;
899 
900 
901 
902   usersNode := fnd_ldap_util.get_dn_for_guid(p_orclguid => p_orclguid);
903 
904   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
905    then
906      fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'DN for user with GUID::'
907          ||p_orclguid||' DN::'||usersNode);
908    end if;
909 
910   l_result := dbms_ldap.delete_s(ld => p_ldap_session, entrydn => usersNode);
911 
912   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
913   then
914     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
915   end if;
916   return l_result;
917 
918   EXCEPTION WHEN OTHERS THEN
919       IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
920          fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
921      END IF;
922      raise;
923 
924 end delete_user_nodes;
925 --
926 ------------------------------------------------------------------------------
927 function delete_user_subscription(p_ldap_session in dbms_ldap.session, guid in raw)
928 return pls_integer is
929 
930 l_module_source   varchar2(256);
931 subsNode varchar2(1000);
932 l_user_guid raw(256) := guid;
933 l_attrs dbms_ldap.string_collection;
934 l_message dbms_ldap.message := null;
935 l_result pls_integer;
936 l_entry dbms_ldap.message := null;
937 
938 begin
939   l_module_source := G_MODULE_SOURCE || 'delete_user_subscription ';
940   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
941   then
942     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
943   end if;
944 
945   -- delete subcriptions with orclOwnerGUID
946   subsNode := 'cn=ACCOUNTS,cn=subscription_data,cn=subscriptions,' || fnd_ldap_util.get_orclappname;
947   l_result := dbms_ldap.search_s(ld => p_ldap_session, base => subsNode,
948     scope => dbms_ldap.SCOPE_SUBTREE, filter => 'orclOwnerGUID=' || l_user_guid, attrs => l_attrs, attronly => 0, res => l_message);
949   if (l_result is not NULL) then
950         l_entry := dbms_ldap.first_entry(p_ldap_session, l_message);
951         if l_entry is not null then
952            l_result := dbms_ldap.delete_s(ld => p_ldap_session, entrydn => 'orclOwnerGUID=' || l_user_guid||','||subsNode);
953         end if;
954   end if;
955 
956   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
957   then
958     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
959   end if;
960   return l_result;
961 
962   EXCEPTION WHEN OTHERS THEN
963       IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
964          fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
965      END IF;
966      raise;
967 
968 end delete_user_subscription;
969 --
970 -------------------------------------------------------------------------------
971 function delete_uniquemember(p_ldap_session in dbms_ldap.session,
972                       p_orclguid in fnd_user.user_guid%type) return pls_integer is
973 
974 l_module_source   varchar2(256);
975 subsNode varchar2(1000);
976 usersNode varchar2(1000);
977 usersNodes dbms_ldap.string_collection;
978 result pls_integer;
979 retval pls_integer;
980 modArray  dbms_ldap.mod_array;
981 modmultivalues dbms_ldap.string_collection;
982 i number;
983 
984 begin
985   l_module_source := G_MODULE_SOURCE || 'delete_uniquemember: ';
986   -- set default value to failure. change to success when added successfully
987   retval := fnd_ldap_util.G_FAILURE;
988   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
989   then
990     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
991   end if;
992 
993   subsNode := 'cn=ACCOUNTS,cn=subscription_data,cn=subscriptions,' || fnd_ldap_util.get_orclappname;
994 
995   modArray := dbms_ldap.create_mod_array(num => 1);
996 
997   modmultivalues(0) := fnd_ldap_util.get_dn_for_guid(p_orclguid);
998 
999   dbms_ldap.populate_mod_array(modptr => modArray, mod_op => dbms_ldap.mod_delete, mod_type => 'uniquemember', modval => modmultivalues);
1000 
1001   retval := dbms_ldap.modify_s(ld => p_ldap_Session, entrydn => subsNode, modptr => modArray);
1002 
1003 
1004   if (retval = dbms_ldap.SUCCESS) then
1005     retval := fnd_ldap_util.G_SUCCESS;
1006   end if;
1007 
1008   dbms_ldap.free_mod_array(modptr => modArray);
1009 
1013   end if;
1010   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1011   then
1012     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
1014 
1015   return retval;
1016 
1017 exception
1018 when others then
1019   if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1020   then
1021     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1022   end if;
1023      raise;
1024 
1025 end delete_uniquemember;
1026 --
1027 -------------------------------------------------------------------------------
1028 procedure disable_user(p_user_guid in raw,
1029                        p_user_name in varchar2,
1030                        x_result out nocopy pls_integer) is
1031 
1032   usertype fnd_ldap_util.ldap_user_type;
1033   l_module_source   varchar2(256);
1034   no_such_user_exp    exception;
1035   l_user_id fnd_user.user_id%type;
1036   l_local_login         varchar2(30);
1037   l_allow_sync          varchar2(1);
1038   l_profile_defined     boolean;
1039   l_to_synch boolean;
1040   x_password pls_integer;
1041 
1042   PRAGMA EXCEPTION_INIT (no_such_user_exp, -20001);
1043 
1044 begin
1045   l_module_source := G_MODULE_SOURCE || 'disable_user: ';
1046 
1047   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1048   then
1049     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
1050   end if;
1051   -- there is no need to do something more specific
1052   -- Note that this only update sOID with DISABLE
1053   update_user(p_user_guid =>p_user_guid,p_user_name =>p_user_name,
1054                      p_end_date =>sysdate-100,
1055                      p_expire_password => 0,x_password => x_password,x_result => x_result , x_user_creation=>FALSE);
1056 
1057   if x_result <> fnd_ldap_util.G_SUCCESS then
1058     raise no_such_user_exp;
1059   end if;
1060 exception
1061   when no_such_user_exp then
1062     fnd_message.set_name ('FND', 'FND_SSO_USER_NOT_FOUND');
1063     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1064     then
1065       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1066     end if;
1067     x_result := fnd_ldap_util.G_FAILURE;
1068   when others then
1069     fnd_message.set_name ('FND', 'FND_SSO_UNEXP_ERROR');
1070     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1071     then
1072       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1073     end if;
1074     x_result := fnd_ldap_util.G_FAILURE;
1075 
1076 end disable_user;
1077 --
1078 --
1079 --  Return the first GUID found for this username
1080 --     also return in n the number of entryes found
1081 --
1082 --
1083 
1084 FUNCTION get_user_guid_and_count
1085   (
1086     p_user_name IN VARCHAR2,
1087     n OUT nocopy pls_integer)
1088   RETURN VARCHAR2
1089 IS
1090   l_module_source VARCHAR2(256);
1091   orclguid        VARCHAR2(1000);
1092 BEGIN
1093   l_module_source             := G_MODULE_SOURCE || 'get_user_guid_and_count: ';
1094   IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
1095     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'Begin p_username='||p_user_name);
1096   END IF;
1097   orclguid    := get_user_guid(p_user_name);
1098   IF orclguid IS NULL THEN
1099     n         :=0;
1100   ELSE
1101     n:=1;
1102   END IF;
1103   IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
1104     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, '  END orclguid='||orclguid||' n='||n);
1105   END IF;
1106   RETURN orclguid;
1107 EXCEPTION
1108 WHEN OTHERS THEN
1109   IF (fnd_log.LEVEL_EXCEPTION>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
1110     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'EXCEPTION:'||sqlerrm);
1111   END IF;
1112   raise;
1113 END get_user_guid_and_count;
1114 
1115 -----------------------------------------
1116 --
1117 -------------------------------------------------------------------------------
1118 function get_user_guid(p_ldap_session in dbms_ldap.session, p_user_name in varchar2, dn out nocopy varchar2)
1119 return raw is
1120 
1121 l_module_source   varchar2(256);
1122 result pls_integer;
1123 l_user_guid raw(256);
1124 l_message dbms_ldap.message := null;
1125 l_entry dbms_ldap.message := null;
1126 l_attrs dbms_ldap.string_collection;
1127 searchBase varchar2(1000);
1128 searchFilter varchar2(1000);
1129 orclguid varchar2(1000);
1130 ldapSession dbms_ldap.session;
1131 dummy dbms_ldap.session;
1132 
1133 realmList dbms_ldap.string_collection;
1134 ridx pls_integer;
1135 sbase dbms_ldap.string_collection;
1136 begin
1137   l_module_source := G_MODULE_SOURCE || 'get_user_guid: ';
1138 --  retval := fnd_ldap_util.G_FAILURE;
1139   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1140   then
1141     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
1142   end if;
1143 
1144   ldapSession := p_ldap_session;
1145   l_attrs(0) := 'orclguid';
1146   realmList := fnd_oid_plug.getRealmList();
1147   for r in realmList.first .. realmList.last loop
1148     if (orclguid is null ) THEN
1149       ridx := fnd_sso_registration.find_realm_index(realmList(r));
1150       sbase := fnd_sso_registration.getrealmsearchbaselist(ridx);
1151       searchFilter := fnd_sso_registration.get_realm_attribute(ridx,'orclcommonnicknameattribute')
1152                   ||'='||p_user_name ;
1153 
1154       for s in sbase.first .. sbase.last loop
1155                  if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1156                   then
1157                     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'realm:'||r||' base:'||sbase(s)||' filter:'||searchFilter);
1158                   end if;
1162                   filter => searchFilter,
1159              result := dbms_ldap.search_s(ld => ldapSession,
1160                   base => sbase(s),
1161                   scope => dbms_ldap.SCOPE_SUBTREE,
1163                   attrs => l_attrs, attronly => 0,
1164                   res => l_message);
1165              l_entry := dbms_ldap.first_entry(ldapSession, l_message);
1166              if (l_entry is not null) then
1167                         l_attrs := dbms_ldap.get_values(ldapSession, l_entry, 'orclguid');
1168                         dn := dbms_ldap.get_dn(ldapSession,l_entry);
1169                         orclguid := l_attrs(0);
1170                         if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1171                           then
1172                               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'FOUND under base='||sbase(s)||
1173                                ' dn:'|| dn ||' guid='||orclguid);
1174                         end if;
1175              END IF;
1176       end loop;
1177     END IF;
1178   end loop;
1179 
1180 
1181   l_user_guid := orclguid;
1182 
1183   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1184   then
1185     if (l_user_guid is not null) then
1186        fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'GUID found = ' || l_user_guid);
1187     ELSE
1188        fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User '||p_user_name||' not found');
1189     END IF;
1190   end if;
1191 
1192   --result := fnd_ldap_util.unbind(ldapSession);
1193 
1194   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1195   then
1196     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
1197   end if;
1198   return l_user_guid;
1199 
1200 exception
1201   when others then
1202     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1203     then
1204       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1205      -- print stack just for 7306960
1206   	--result:= -99;
1207         --dummy := fnd_ldap_util.c_get_oid_session(result);
1208     end if;
1209     raise;
1210 
1211 end get_user_guid;
1212 
1213 function get_user_guid(p_ldap_session in dbms_ldap.session, p_user_name in varchar2)
1214 return raw is
1215 dn varchar2(4000);
1216 begin
1217    return get_user_guid(p_ldap_session,p_user_name,dn);
1218 end;
1219 
1220 function get_user_guid( p_user_name in varchar2)
1221 return raw is
1222   l_ldap dbms_ldap.session;
1223 ret fnd_user.user_guid%type;
1224 dummy pls_integer;
1225 BEGIN
1226   l_ldap := fnd_ldap_util.c_get_oid_session(dummy);
1227   ret := get_user_guid(l_ldap,p_user_name);
1228   fnd_ldap_util.C_unbind(l_ldap,dummy);
1229   return ret;
1230 EXCEPTION
1231 WHEN OTHERS THEN
1232   fnd_ldap_util.c_unbind(l_ldap,dummy);
1233   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
1234     fnd_log.string(fnd_log.LEVEL_EXCEPTION, G_MODULE_SOURCE || 'get_user_guid: ', sqlerrm);
1235   END IF;
1236   raise;
1237 END get_user_guid;
1238 --
1239 ----------------------------------------
1240 
1241 
1242 
1243 --
1244 -------------------------------------------------------------------------------
1245 
1246 --
1247 -------------------------------------------------------------------------------
1248 procedure link_user(p_user_name in varchar2,
1249                     x_user_guid out nocopy raw,
1250                     x_password out nocopy varchar2,
1251                     x_result out nocopy pls_integer) is
1252 
1253 l_module_source   varchar2(256);
1254 l_user_exists pls_integer;
1255 l_result pls_integer;
1256 l_orclguid fnd_user.user_guid%type;
1257 l_local_login varchar2(100);
1258 l_profile_defined boolean;
1259 l_nickname varchar2(256);
1260 
1261 begin
1262   l_module_source := G_MODULE_SOURCE || 'link_user: ';
1263   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1264   then
1265     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
1266   end if;
1267 
1268 
1269    l_orclguid := get_user_guid(p_user_name);
1270   -- only proceed if user exists
1271 
1272   if (l_orclguid is not null ) then
1273 
1274 
1275     fnd_oid_util.add_user_to_OID_sub_list(p_orclguid => l_orclguid, x_result => l_result);
1276 
1277     x_result := l_result;
1278 
1279     if (l_result = fnd_ldap_util.G_SUCCESS) then
1280       x_user_guid := l_orclguid;
1281 
1282       fnd_profile.get_specific(
1283         name_z      => 'APPS_SSO_LOCAL_LOGIN',
1284         user_id_z => -1,
1285         val_z      => l_local_login,
1286         defined_z    => l_profile_defined);
1287 
1288       if (l_local_login = 'SSO') then
1289         x_password := fnd_web_sec.EXTERNAL_PWD;
1290       end if;
1291 
1292     end if;
1293 
1294   -- user does not exist in OID
1295   else
1296     fnd_message.set_name('FND', 'FND_SSO_USER_NOT_FOUND');
1297     x_result := fnd_ldap_util.G_FAILURE;
1298   end if;
1299 
1300   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1301   then
1302     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
1303   end if;
1304 
1305 exception
1306 when others then
1307   if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1308   then
1309     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1310   end if;
1311   raise;
1312 
1313 end link_user;
1314 --
1315 -------------------------------------------------------------------------------
1316 function process_attributes(p_ldap_user in fnd_ldap_util.ldap_user_type,
1317                             p_operation_type in pls_integer default G_CREATE,
1321 
1318                             x_atts out nocopy dbms_ldap.string_collection,
1319                             x_att_values out nocopy dbms_ldap.string_collection)
1320                             return number is
1322 l_module_source   varchar2(256);
1323 num_attributes     number;
1324 
1325 begin
1326   l_module_source := G_MODULE_SOURCE || 'process_attributes: ';
1327   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1328   then
1329     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
1330   end if;
1331 
1332   num_attributes := 0;
1333 
1334   if (p_ldap_user.sn is not null) then
1335     x_atts(num_attributes) := 'sn';
1336     x_att_values(num_attributes) := p_ldap_user.sn;
1337     num_attributes := num_attributes + 1;
1338   end if;
1339   if (p_ldap_user.cn is not null) then
1340     x_atts(num_attributes) := 'cn';
1341     x_att_values(num_attributes) := p_ldap_user.cn;
1342     num_attributes := num_attributes + 1;
1343   end if;
1344   if (p_ldap_user.uid is not null) then
1345     x_atts(num_attributes) := 'uid';
1346     x_att_values(num_attributes) := p_ldap_user.uid;
1347     num_attributes := num_attributes + 1;
1348   end if;
1349   if (p_ldap_user.userPassword is not null) then
1350     x_atts(num_attributes) := 'userPassword';
1351     x_att_values(num_attributes) := p_ldap_user.userPassword;
1352     num_attributes := num_attributes + 1;
1353   end if;
1354   if (p_ldap_user.telephoneNumber is not null) then
1355     x_atts(num_attributes) := 'telephoneNumber';
1356     x_att_values(num_attributes) := p_ldap_user.telephoneNumber;
1357     num_attributes := num_attributes + 1;
1358   end if;
1359   if (p_ldap_user.street is not null) then
1360     x_atts(num_attributes) := 'street';
1361     x_att_values(num_attributes) := p_ldap_user.street;
1362     num_attributes := num_attributes + 1;
1363   end if;
1364   if (p_ldap_user.postalCode is not null) then
1365     x_atts(num_attributes) := 'postalCode';
1366     x_att_values(num_attributes) := p_ldap_user.postalCode;
1367     num_attributes := num_attributes + 1;
1368   end if;
1369   if (p_ldap_user.physicalDeliveryOfficeName is not null) then
1370     x_atts(num_attributes) := 'physicalDeliveryOfficeName';
1371     x_att_values(num_attributes) := p_ldap_user.physicalDeliveryOfficeName;
1372     num_attributes := num_attributes + 1;
1373   end if;
1374   if (p_ldap_user.st is not null) then
1375     x_atts(num_attributes) := 'st';
1376     x_att_values(num_attributes) := p_ldap_user.st;
1377     num_attributes := num_attributes + 1;
1378   end if;
1379   if (p_ldap_user.l is not null) then
1380     x_atts(num_attributes) := 'l';
1381     x_att_values(num_attributes) := p_ldap_user.l;
1382     num_attributes := num_attributes + 1;
1383   end if;
1384   if (p_ldap_user.displayName is not null) then
1385     x_atts(num_attributes) := 'displayName';
1386     x_att_values(num_attributes) := p_ldap_user.displayName;
1387     num_attributes := num_attributes + 1;
1388   end if;
1389   if (p_ldap_user.givenName is not null) then
1390     x_atts(num_attributes) := 'givenName';
1391     x_att_values(num_attributes) := p_ldap_user.givenName;
1392     num_attributes := num_attributes + 1;
1393   end if;
1394   if (p_ldap_user.homePhone is not null) then
1395     x_atts(num_attributes) := 'homePhone';
1396     x_att_values(num_attributes) := p_ldap_user.homePhone;
1397     num_attributes := num_attributes + 1;
1398   end if;
1399   if (p_ldap_user.mail is not null) then
1400     x_atts(num_attributes) := 'mail';
1401     x_att_values(num_attributes) := p_ldap_user.mail;
1402     num_attributes := num_attributes + 1;
1403   end if;
1404   if (p_ldap_user.c is not null) then
1405     x_atts(num_attributes) := 'c';
1406     x_att_values(num_attributes) := p_ldap_user.c;
1407     num_attributes := num_attributes + 1;
1408   end if;
1409   if (p_ldap_user.facsimileTelephoneNumber is not null) then
1410     x_atts(num_attributes) := 'facsimileTelephoneNumber';
1411     x_att_values(num_attributes) := p_ldap_user.facsimileTelephoneNumber;
1412     num_attributes := num_attributes + 1;
1413   end if;
1414   if (p_ldap_user.description is not null) then
1415     x_atts(num_attributes) := 'description';
1416     x_att_values(num_attributes) := p_ldap_user.description;
1417     num_attributes := num_attributes + 1;
1418   end if;
1419   if (p_ldap_user.orclisEnabled is not null) then
1420     x_atts(num_attributes) := 'orclisEnabled';
1421     x_att_values(num_attributes) := p_ldap_user.orclisEnabled;
1422     num_attributes := num_attributes + 1;
1423   end if;
1424   if (p_ldap_user.orclActiveStartDate is not null) then
1425     x_atts(num_attributes) := 'orclActiveStartDate';
1426     x_att_values(num_attributes) := p_ldap_user.orclActiveStartDate;
1427     num_attributes := num_attributes + 1;
1428   end if;
1429   if (p_ldap_user.orclActiveEndDate is not null) then
1430     x_atts(num_attributes) := 'orclActiveEndDate';
1431     x_att_values(num_attributes) := p_ldap_user.orclActiveEndDate;
1432     num_attributes := num_attributes + 1;
1433   end if;
1434 
1435   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1436   then
1437     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
1438   end if;
1439 
1440   return num_attributes;
1441 
1442 exception
1443 when others then
1444   if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1445   then
1446     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1447   end if;
1448   raise;
1449 
1450 end process_attributes;
1451 --
1452 -------------------------------------------------------------------------------
1453 procedure unlink_user(p_user_guid in fnd_user.user_guid%type,
1454                       p_user_name in varchar2,
1455                       x_result out nocopy pls_integer) is
1459   from fnd_user
1456 
1457 cursor linked_users is
1458   select user_name
1460   where user_guid = p_user_guid
1461   and user_name <> p_user_name;
1462 
1463 l_rec             linked_users%rowtype;
1464 l_found           boolean;
1465 l_module_source   varchar2(256);
1466 l_local_login varchar2(100);
1467 l_profile_defined boolean;
1468 l_ldap_session dbms_ldap.session :=null;
1469 l_user_exists pls_integer;
1470 dn varchar2(2000);
1471 dummy pls_integer;
1472 
1473 begin
1474   l_module_source := G_MODULE_SOURCE || 'unlink_user: ';
1475   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1476   then
1477     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
1478   end if;
1479 
1480   open linked_users;
1481   fetch linked_users into l_rec;
1482   l_found := linked_users%found;
1483   close linked_users;
1484 
1485   -- no other user linked
1486   if (not l_found)
1487   then
1488 
1489   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1490   then
1491     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'No other FND users linked to this OID User');
1492   end if;
1493     l_user_exists :=   user_exists_by_guid( p_user_guid);
1494 
1495     if (l_user_exists = fnd_ldap_util.G_SUCCESS) then
1496 
1497       l_ldap_session := fnd_ldap_util.c_get_oid_session(dummy);
1498 
1499       x_result := delete_user_subscription(l_ldap_session, p_user_guid);
1500       x_result := delete_uniquemember(l_ldap_session, p_user_guid);
1501 
1502     -- user does not exist in OID
1503     else
1504       fnd_message.set_name('FND', 'FND_SSO_USER_NOT_FOUND');
1505       x_result := fnd_ldap_util.G_FAILURE;
1506     end if;
1507 
1508   -- other users linked
1509   else
1510 
1511     if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1512     then
1513       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Other FND users linked to this OID User');
1514     end if;
1515 
1516     x_result := fnd_ldap_util.G_FAILURE;
1517     fnd_message.set_name ('FND', 'FND_SSO_USER_MULT_LINKED');
1518 
1519   end if;
1520   if ( l_ldap_session is not null) then
1521      fnd_ldap_util.c_unbind(l_ldap_session,dummy);
1522   end if ;
1523   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1524   then
1525     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
1526   end if;
1527 
1528 exception
1529 when others then
1530    fnd_ldap_util.c_unbind(l_ldap_session,dummy);
1531   if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1532   then
1533     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1534   end if;
1535         raise;
1536 
1537 end unlink_user;
1538 --
1539 -------------------------------------------------------------------------------
1540 
1541 -- INTERNAL SIGNATURE
1542 --  x_user_creation can only be true when is called from this package
1543 -- calling public signature only permits x_user_creation=false
1544 --
1545 procedure update_user(p_user_guid in raw,
1546                      p_user_name in varchar2,
1547                      p_password in varchar2 default null,
1548                      p_start_date in date default null,
1549                      p_end_date in date default null,
1550                      p_description in varchar2 default null,
1551                      p_email_address in varchar2 default null,
1552                      p_fax in varchar2 default null,
1553                      p_expire_password in pls_integer,
1554                      x_password out nocopy varchar2,
1555                      x_result out nocopy pls_integer,
1556 		     x_user_creation in boolean default FALSE ) is
1557 
1558 
1559   l_orclisEnabled varchar2(256);
1560  -- usertype fnd_ldap_util.ldap_user_type;
1561   ldap_user fnd_ldap_user.ldap_user_type;
1562   l_module_source   varchar2(256);
1563   no_such_user_exp    exception;
1564   l_nickname varchar2(256);
1565 
1566   l_user_id fnd_user.user_id%type;
1567   l_local_login         varchar2(30);
1568   l_allow_sync          varchar2(1);
1569   l_profile_defined     boolean;
1570   l_to_synch boolean;
1571 
1572   l_guid FND_USER.user_guid%type:= p_user_guid;
1573   ldap dbms_ldap.session;
1574   flag pls_integer;
1575   dn varchar2(4000);
1576   realm varchar2(4000);
1577     upd update_list;
1578     i pls_integer;
1579     x_name_change pls_integer;
1580     ldap_result pls_integer;
1581     l_use_proxy pls_integer := 0;
1582  PRAGMA EXCEPTION_INIT (no_such_user_exp, -20001);
1583 
1584 begin
1585 
1586   l_module_source := G_MODULE_SOURCE || 'update_user[proc]: ';
1587 
1588   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1589   then
1590     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'Begin');
1591   end if;
1592 
1593 
1594    -- figure out the user_id
1595    BEGIN
1596       select user_id into l_user_id from fnd_user
1597       where user_name=p_user_name and user_guid=p_user_guid;
1598       if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1599         then
1600           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'user_id:'||l_user_id);
1601       end if;
1602 
1603       l_to_synch := CanSync(l_user_id,p_user_name);
1604 
1605       if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1606       then
1607           if (l_to_synch) then
1608               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' Can synch');
1609            else
1610            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' NOT synch username:'
1611                    ||p_user_name||' userid:'||l_user_id||'  userGuid:'||p_user_guid);
1612            end if;
1616         -- THIS IS UNEXPECTED !!
1613        END IF;
1614       EXCEPTION WHEN NO_DATA_FOUND THEN
1615         l_to_synch:= true;
1617       if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1618       then
1619        fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Sinc, No ebzlinked user found:'||p_user_name||' guid:'||p_user_guid);
1620      end if;
1621    END;
1622 
1623 
1624   if (l_to_synch) then
1625        if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1626        then
1627            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' synch');
1628        end if;
1629 
1630        l_use_proxy := 0;
1631 
1632        IF (p_password is not null) THEN
1633 
1634            if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
1635                fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'Password is not null');
1636            end if;
1637 
1638            if (p_expire_password is not null and p_expire_password <> fnd_ldap_util.G_TRUE) THEN
1639 
1640                if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
1641                    fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'So far password will not be expired - proxy as user');
1642                end if;
1643 
1644                l_use_proxy :=2;
1645                --  Bug 9271995
1646 	       --    During user_creation  if password is not in IDENTITY_ADD
1647 	       --             expiration will be forced disregarding what was requested
1648 	       IF (x_user_creation AND  not canPopulate('userpassword',ldap_user.user_name, ldap_user.realmDN) )THEN
1649 	       		-- always expire the password
1650                   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
1651                       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Forcing password expiration - not in IDENTITY_ADD');
1652                   end if;
1653                        l_use_proxy :=1;
1654 	       END IF;
1655            else
1656              if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
1657                  fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'Password should be expired - p_expire_password: '||to_char(p_expire_password));
1658              end if;
1659 
1660                l_use_proxy :=1;
1661            end if;
1662         ELSE
1663            if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
1664                fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'Password is null');
1665            end if;
1666 
1667           l_use_proxy := 1;
1668         END IF;
1669         if ( l_use_proxy=2) then
1670              if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1671              then
1672                     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Getting a proxied connection to avoid password forced change: NEW LDAP connection required');
1673              end if;
1674             fnd_ldap_util.proxy_as_user(p_orclguid => p_user_guid,x_ldap_session => ldap);
1675         else
1676            ldap := FND_LDAP_UTIL.c_get_oid_session(flag);
1677            l_use_proxy :=1;
1678         end if;
1679 
1680        l_guid := p_user_guid;
1681        IF  FND_LDAP_UTIL.loadLdapRecord( ldap , ldap_user.user_data,dn,l_guid,FND_LDAP_UTIL.G_GUID_KEY)
1682        THEN
1683                ldap_user.dn                 :=dn;
1684                IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
1685                         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Updating dn:'||dn);
1686                END IF;
1687                ProcessLoadedLpadUserRecord(ldap_user,NULL,dn);
1688 
1689 	       --Bug 13329571
1690 	       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
1691 			fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Calling FIXUP:'||dn);
1692 	       END IF;
1693 	       FND_OID_PLUG.fixupLDAPUser(ldap_user,FND_OID_PLUG.G_UPDATE_USER);
1694 
1695                --  Bug 9271995
1696                --       x_user_creation=TRUE we always update the password
1697                --       x_user_creation=FALSE we check IDENTITY_MODIFY provisioning profile
1698 	       --
1699                IF (p_password is not null and
1700 		       (
1701 			      x_user_creation  -- we set the password anyway, although it will be expired
1702 			      OR canUpdate('userpassword',ldap_user.user_name, ldap_user.realmDN,x_user_creation)
1703 		       )
1704 		   ) THEN
1705                         i:= upd.count;
1706                         upd(i).att := 'userpassword';
1707                         upd(i).val := p_password;
1708                         upd(i).op := DBMS_LDAP.MOD_REPLACE;
1709                END IF;
1710                IF (p_description is not null and NOT isValueOf(ldap_user,'description',p_description)
1711                      and  canUpdate('description',ldap_user.user_name, ldap_user.realmDN,x_user_creation) ) THEN
1712                         i:= upd.count;
1713                         upd(i).att := 'description';
1714                         upd(i).val := p_description;
1715                         upd(i).op := DBMS_LDAP.MOD_REPLACE;
1716                END IF;
1717 
1718                IF (p_email_address is not null and NOT isValueOf(ldap_user,'mail',p_email_address)
1719                    and  canUpdate('mail',ldap_user.user_name, ldap_user.realmDN,x_user_creation) ) THEN
1720                         i:= upd.count;
1721                         upd(i).att := 'mail';
1722                         upd(i).val := p_email_address;
1723                         upd(i).op := DBMS_LDAP.MOD_REPLACE;
1724                END IF;
1725                IF (p_fax is not null and NOT isValueOf(ldap_user,'facsimileTelephoneNumber',p_fax)
1726                      and canUpdate('facsimileTelephoneNumber',ldap_user.user_name, ldap_user.realmDN,x_user_creation)
1727                   ) THEN
1728                         i:= upd.count;
1732                END IF;
1729                         upd(i).att := 'facsimileTelephoneNumber';
1730                         upd(i).val := p_fax;
1731                         upd(i).op := DBMS_LDAP.MOD_REPLACE;
1733                 decode_dates(p_user_name, p_start_date, p_end_date,
1734                              x_orclisEnabled => l_orclisEnabled,
1735                              x_user_id => l_user_id);
1736                IF (l_orclIsEnabled is not null and NOT isValueOf(ldap_user,'orclIsEnabled',l_orclIsEnabled)
1737                        and  canUpdate('orclisenabled',ldap_user.user_name, ldap_user.realmDN)
1738                        and l_orclIsEnabled = fnd_oid_util.G_ENABLED) THEN
1739                         i:= upd.count;
1740                         upd(i).att := 'orclIsEnabled';
1741                         upd(i).val := l_orclIsEnabled;
1742                         upd(i).op := DBMS_LDAP.MOD_REPLACE;
1743                END IF;
1744                if (upd.count>0) THEN
1745                    ProcessUpdateRec(ldap,ldap_user.dn,upd);
1746                END IF;
1747                x_result :=   fnd_ldap_util.G_SUCCESS;
1748 /*
1749    CANNOT CHANGE USERNAME
1750       Unless the old is known, and that is not possible because already was changed on FND_USER...
1751                IF (x_result=FND_LDAP_UTIl.G_SUCCESS AND p_user_name is not null and isValueOf(ldap_user,ldap_user.nickname_att_name,   p_user_name) ) THEN
1752                    change_user_name(p_user_guid,ldap_user.user_name,p_user_name,x_name_change);
1753                    x_result :=x_name_change;
1754                END IF;
1755                */
1756         ELSE
1757             if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1758             then
1759                 fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'USER  '||ldap_user.user_name||' has an invalid guid:'||p_user_guid);
1760             end if;
1761             raise no_such_user_exp;
1762         END IF;
1763         if ( l_use_proxy=2 ) then
1764                  ldap_result  := fnd_ldap_util.unbind(ldap);
1765         elsif l_use_proxy=1 then
1766              FND_LDAP_UTIL.c_unbind(ldap,flag);
1767         end if;
1768         l_use_proxy:=0;
1769 
1770 --        ldap:=null;
1771 
1772   else
1773     x_result := fnd_ldap_util.G_SUCCESS;
1774     if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1775     then
1776       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,
1777                  'User is a local user or synch is disabled for this user.');
1778     end if;
1779   end if;
1780 
1781   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1782   then
1783     if ( x_result = fnd_ldap_util.G_SUCCESS) THEN
1784     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'End->SUCCESS');
1785     ELSE
1786         fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'End->FAIL');
1787      END IF;
1788   end if;
1789 
1790   if x_result <> fnd_ldap_util.G_SUCCESS then
1791     raise no_such_user_exp;
1792   else
1793     fnd_profile.get_specific(
1794       name_z      => 'APPS_SSO_LOCAL_LOGIN',
1795       user_id_z => l_user_id,
1796       val_z      => l_local_login,
1797       defined_z    => l_profile_defined);
1798 
1799     if (l_local_login = 'SSO') then
1800       x_password := fnd_web_sec.EXTERNAL_PWD;
1801     end if;
1802   end if;
1803 
1804 exception
1805   when no_such_user_exp then
1806           if ( l_use_proxy=2 ) then
1807                  ldap_result  := fnd_ldap_util.unbind(ldap);
1808         elsif l_use_proxy=1 then
1809              FND_LDAP_UTIL.c_unbind(ldap,flag);
1810         end if;
1811         l_use_proxy:=0;
1812     fnd_message.set_name ('FND', 'FND_SSO_USER_NOT_FOUND');
1813     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1814     then
1815       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1816     end if;
1817     x_result := fnd_ldap_util.G_FAILURE;
1818   when others then
1819         if ( l_use_proxy=2 ) then
1820                  ldap_result  := fnd_ldap_util.unbind(ldap);
1821         elsif l_use_proxy=1 then
1822              FND_LDAP_UTIL.c_unbind(ldap,flag);
1823         end if;
1824         l_use_proxy:=0;
1825 
1826     fnd_message.set_name ('FND', 'FND_SSO_UNEXP_ERROR');
1827     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1828     then
1829       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1830     end if;
1831 --  x_result := fnd_ldap_util.G_FAILURE;
1832     raise;
1833 
1834 end update_user;
1835 
1836 --
1837 -----------------------------------
1838 -- PUBLIC SIGNATURE
1839 --
1840 procedure update_user(p_user_guid in raw,
1841                      p_user_name in varchar2,
1842                      p_password in varchar2 default null,
1843                      p_start_date in date default null,
1844                      p_end_date in date default null,
1845                      p_description in varchar2 default null,
1846                      p_email_address in varchar2 default null,
1847                      p_fax in varchar2 default null,
1848                      p_expire_password in pls_integer,
1849                      x_password out nocopy varchar2,
1850                      x_result out nocopy pls_integer ) is
1851 BEGIN
1852    update_user(p_user_guid,p_user_name,p_password,p_start_date,p_end_date,p_description,p_email_address,p_fax,p_expire_password,x_password,x_result,FALSE);
1853 END update_user;
1854 --
1855 -------------------------------------------------------------------------------
1856 PROCEDURE ConverToNew(n in out nocopy fnd_ldap_user.ldap_user_type,
1857                       o in out nocopy fnd_ldap_util.ldap_user_type )
1858 IS
1859 BEGIN
1860 
1861      o.object_name := n.user_name;
1862 
1863 
1864 
1868      o.userPassword :=getAttribute(n,'userPassword');
1865      o.uid :=getAttribute(n,'uid');
1866      o.sn :=getAttribute(n,'sn');
1867      o.cn :=getAttribute(n,'cn');
1869      o.telephoneNumber :=getAttribute(n,'telephoneNumber');
1870      o.street :=getAttribute(n,'street');
1871      o.postalCode :=getAttribute(n,'postalCode');
1872      o.physicalDeliveryOfficeName :=getAttribute(n,'physicalDeliveryOfficeName');
1873      o.st :=getAttribute(n,'st');
1874      o.l :=getAttribute(n,'l');
1875      o.displayName :=getAttribute(n,'displayName');
1876      o.givenName :=getAttribute(n,'givenName');
1877      o.homePhone :=getAttribute(n,'homePhone');
1878      o.mail :=getAttribute(n,'mail');
1879      o.c :=getAttribute(n,'c');
1880      o.facsimileTelephoneNumber :=getAttribute(n,'facsimileTelephoneNumber');
1881      o.description :=getAttribute(n,'description');
1882      o.orclisEnabled :=getAttribute(n,'orclisEnabled');
1883      o.orclActiveStartDate :=getAttribute(n,'orclActiveStartDate');
1884      o.orclActiveEndDate :=getAttribute(n,'orclActiveEndDate');
1885      o.orclGUID :=n.user_guid;
1886 
1887      if o.uid is null then o.uid:=n.user_name; END IF;
1888      if o.sn is null then o.sn:=n.user_name; END IF;
1889      if o.cn is null then o.cn:=n.user_name; END IF;
1890 
1891 END ConverToNew;
1892 
1893 -------------------------------------------------------------------------------
1894 function update_user_nodes(p_ldap_session in dbms_ldap.session, p_mod_array in dbms_ldap.mod_array, p_orclguid in raw)
1895 return pls_integer is
1896 
1897 l_module_source   varchar2(256);
1898 usersNode varchar2(1000);
1899 retval pls_integer;
1900 l_message varchar2(200);
1901 
1902 begin
1903   l_module_source := G_MODULE_SOURCE || 'update_user_nodes: ';
1904   -- set default value to failure. change to success when user created successfully
1905   retval := fnd_ldap_util.G_FAILURE;
1906   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1907   then
1908     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
1909   end if;
1910 
1911   usersNode := fnd_ldap_util.get_dn_for_guid(p_orclguid, p_ldap_session);
1912 --  dbms_ldap.use_exception := true;
1913 
1914   retval := dbms_ldap.modify_s(ld => p_ldap_session, entrydn => usersNode, modptr => p_mod_array);
1915 
1916   if (retval = dbms_ldap.SUCCESS) then
1917     retval := fnd_ldap_util.G_SUCCESS;
1918   end if;
1919 
1920   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1921   then
1922     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
1923   end if;
1924   return retval;
1925 
1926 exception
1927   -- bug 4573677
1928   when dbms_ldap.general_error then
1929     l_message := translate_ldap_error(sqlerrm);
1930     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1931     then
1932       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'error '||l_message||':'||sqlerrm);
1933     end if;
1934     fnd_message.set_name('FND',l_message);
1935     if (l_message='FND_SSO_PASSWORD_POLICY_ERR')
1936     then
1937        fnd_message.set_token('SQLMSG',sqlerrm);
1938     elsif  (l_message='FND_SSO_UNEXP_ERROR') then
1939               fnd_message.set_token('SQLMSG',sqlerrm);
1940     end if;
1941     return fnd_ldap_util.G_FAILURE;
1942   when others then
1943     if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1944     then
1945       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
1946     end if;
1947     raise;
1948 
1949 end update_user_nodes;
1950 
1951 function user_exists(p_user_name in varchar2)
1952 return pls_integer is
1953 ldap dbms_ldap.session;
1954   ret pls_integer;
1955   ret2 pls_integer;
1956   flag pls_integer;
1957 begin
1958     ldap := fnd_ldap_util.c_get_oid_session(flag);
1959     ret := user_exists(ldap,p_user_name);
1960    fnd_ldap_util.c_unbind(ldap,flag);
1961     return ret;
1962 EXCEPTION
1963 WHEN OTHERS THEN
1964   fnd_ldap_util.c_unbind(ldap,flag);
1965   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
1966     fnd_log.string(fnd_log.LEVEL_EXCEPTION, G_MODULE_SOURCE || 'user_exists: ', sqlerrm);
1967   END IF;
1968   raise;
1969 end user_exists;
1970 --
1971 -------------------------------------------------------------------------------
1972 function user_exists(ldap in dbms_ldap.session,p_user_name in varchar2)
1973 return pls_integer is
1974 
1975 l_module_source   varchar2(256);
1976 --result pls_integer;
1977   retval pls_integer;
1978 --l_nickname varchar2(256);
1979 
1980 
1981   guid raw(16);
1982 
1983 begin
1984   l_module_source := G_MODULE_SOURCE || 'user_exists: ';
1985   retval := fnd_ldap_util.G_FAILURE;
1986   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
1987   then
1988     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
1989   end if;
1990 
1991   guid := get_user_guid(p_user_name);
1992   if (guid is not null ) then
1993        retval := fnd_ldap_util.G_SUCCESS;
1994   else
1995        retval  :=fnd_ldap_util.G_FAILURE;
1996    end if;
1997 
1998 
1999   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2000   then
2001     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'retval=' || retval);
2002   end if;
2003 
2004   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2005   then
2006     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
2007   end if;
2008 
2009   return retval;
2010 
2011 exception
2012 when others then
2013   if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2014   then
2015     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
2016   end if;
2017   raise;
2021 -------------------------------------------------------------------------------
2018 
2019 end user_exists;
2020 --
2022 -- REMOVED
2023 -- function user_exists_with_filter(p_attr_name in varchar2, p_attr_value in varchar2) return pls_integer is
2024 
2025 --
2026 -------------------------------------------------------------------------------
2027 /**
2028 * FUNCTION comparePassword: Internal
2029 *   Returns true if the password is the same as the stored at OiD for the given DN
2030 * If Not, or any exceptions occurs, returns false
2031 *   It can be used repeteadly since this comparision does not count as failed attempts.
2032 *     Parameters:
2033 *               ldapSession: OiD connection to use
2034 *		user_dn: user DN
2035 *		p_password: password
2036 **/
2037 
2038 function comparePassword(ldapSession in dbms_ldap.session, user_dn in varchar2 , p_password in varchar2) return boolean is
2039 l_result pls_integer;
2040 result boolean;
2041 l_module_source   varchar2(256);
2042 begin
2043   l_module_source := G_MODULE_SOURCE || 'comparePassword: ';
2044  if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2045   then
2046     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'BEGIN DN:'||user_dn);
2047   end if;
2048   l_result :=  dbms_ldap.compare_s(ld => ldapSession, dn => user_dn, attr => 'userpassword', value => p_password);
2049   result :=  l_result= dbms_ldap.COMPARE_TRUE;
2050  if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2051   then
2052     if (result)  then
2053        fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END: Yes');
2054     else
2055        fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END: NO');
2056 
2057     end if;
2058   end if;
2059 
2060   return result;
2061   exception when others then
2062      if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2063     then
2064       fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'Exception: '||sqlcode||' - '||sqlerrm);
2065     end if;
2066     return false;
2067 
2068 end comparePassword;
2069 --
2070 -------------------------------------------------------------------------------
2071 function validate_login(p_user_name in varchar2, p_password in varchar2) return pls_integer is
2072 
2073 l_module_source   varchar2(256);
2074 l_host            varchar2(256);
2075 l_port            varchar2(256);
2076 
2077 result            pls_integer;
2078 retval            pls_integer;
2079 l_user_guid       raw(256);
2080 l_user_name       fnd_user.user_name%type;
2081 l_enabled         boolean;
2082 l_ldap_attr_list  ldap_attr_list;
2083 ldapSession       dbms_ldap.session;
2084 l_retval          pls_integer;
2085 user_dn           varchar2(4000);
2086 l_ldap_auth       varchar2(256);
2087 l_db_wlt_url      varchar2(256);
2088 l_db_wlt_pwd      varchar2(256);
2089 l_message         varchar2(2000);
2090 
2091 begin
2092   l_module_source := G_MODULE_SOURCE || 'validate_login: ';
2093 
2094   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2095   then
2096     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'Begin');
2097   end if;
2098 
2099 
2100   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2101   then
2102     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Username: '||p_user_name);
2103   end if;
2104 
2105   if (p_user_name is null or p_password is null ) then
2106      fnd_message.set_name('FND','FND_SSO_USER_PASSWD_EMPTY');
2107       if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2108       then
2109         fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'END: refusing to validate empty username and/or password');
2110       end if;
2111       return fnd_ldap_util.G_FAILURE;
2112   end if;
2113 
2114   -- Find the DN of the linked guid
2115   begin
2116       select user_guid into l_user_guid from fnd_user where user_name=p_user_name;
2117       if (l_user_guid is null ) then
2118           if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2119           then
2120             fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'END: Null guid in FND_USER for: '||p_user_name);
2121           end if;
2122           fnd_message.set_name('FND','FND_SSO_NOT_LINKED');
2123           return fnd_ldap_util.G_FAILURE;
2124       end if;
2125       exception when no_data_found then
2126           if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2127           then
2128             fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END: user not found');
2129           end if;
2130           fnd_message.set_name('FND','FND_SSO_LOGIN_FAILED'); -- do no disclusre the real causeL
2131           return fnd_ldap_util.G_FAILURE;
2132        when others then
2133           if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2134           then
2135             fnd_log.string(fnd_log.LEVEL_UNEXPECTED ,l_module_source, 'END with exception: '||sqlcode||'-'||sqlerrm);
2136           end if;
2137           fnd_message.set_name('FND','FND-9914'); -- unexpected error
2138          return fnd_ldap_util.G_FAILURE;
2139   end;
2140 
2141   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2142   then
2143     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'GUID:'||l_user_guid);
2144   end if;
2145 
2146 
2147  -- Obtain the user DN using the GUID
2148    begin
2149     user_dn := fnd_Ldap_util.get_dn_for_guid(l_user_guid); -- may raise no data found for invalid guids
2150    exception when no_data_found then
2151           if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2152           then
2153             fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'Guid['||l_user_guid||'] for '||p_user_name||' is not a valid guid');
2154           end if;
2158 
2155           fnd_message.set_name('FND','FND_SSO_USER_NOT_FOUND'); -- Carefull, this is INVALID GUID message, wrong acronym though
2156           return fnd_ldap_util.G_FAILURE;
2157    end;
2159   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2160   then
2161     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'DN:'||user_dn);
2162   end if;
2163 
2164 
2165 
2166   l_host := fnd_preference.get(FND_LDAP_UTIL.G_INTERNAL, FND_LDAP_UTIL.G_LDAP_SYNCH, FND_LDAP_UTIL.G_HOST);
2167   l_port := fnd_preference.get(FND_LDAP_UTIL.G_INTERNAL, FND_LDAP_UTIL.G_LDAP_SYNCH, FND_LDAP_UTIL.G_PORT);
2168 
2169   if (l_host is null or l_port is null) then
2170           if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2171           then
2172             fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'Invalid OiD Setup: host:'||l_host||' port:'||l_port);
2173           end if;
2174 
2175       fnd_message.set_name('FND','FND-9903'); -- OID setup is incomplete
2176       return fnd_ldap_util.G_FAILURE;
2177   end if;
2178 
2179     l_ldap_auth := fnd_preference.get(FND_LDAP_UTIL.G_INTERNAL, FND_LDAP_UTIL.G_LDAP_SYNCH, FND_LDAP_UTIL.G_DBLDAPAUTHLEVEL);
2180 
2181     if (l_ldap_auth>0) then
2182            l_db_wlt_url := fnd_preference.get(FND_LDAP_UTIL.G_INTERNAL, FND_LDAP_UTIL.G_LDAP_SYNCH, FND_LDAP_UTIL.G_DBWALLETDIR);
2183            l_db_wlt_pwd := fnd_preference.eget(FND_LDAP_UTIL.G_INTERNAL, FND_LDAP_UTIL.G_LDAP_SYNCH, FND_LDAP_UTIL.G_DBWALLETPASS, FND_LDAP_UTIL.G_LDAP_PWD);
2184            if (l_db_wlt_url is null or l_db_wlt_pwd is null) then
2185                if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2186                then
2187                 fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'Invalid Wallet Setup: authLEvel:'
2188                                   ||l_ldap_auth||' url:'||l_db_wlt_url||' pwd:'||l_db_wlt_url);
2189                end if;
2190 
2191                fnd_message.set_name('FND','FND-9903'); -- OID setup is incomplete
2192                return fnd_ldap_util.G_FAILURE;
2193            end if;
2194     else
2195           if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2196           then
2197             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'WARNING: NON-SSL connection to OiD, check that the Net is secure');
2198           end if;
2199     end if;
2200 
2201    dbms_ldap.use_exception := TRUE;
2202 
2203   begin
2204     begin
2205        ldapSession := DBMS_LDAP.init(l_host, l_port);
2206        exception when dbms_ldap.init_failed then
2207             if (fnd_log.LEVEL_UNEXPECTED>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2208             then
2209               fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'Cannot contact OID (init failed) at '||l_host||':'||l_port||':'||sqlcode||'-'||sqlerrm);
2210             end if;
2211             fnd_message.set_name('FND','FND_SSO_SYSTEM_NOT_AVAIL');
2212             return fnd_ldap_util.G_FAILURE;
2213           when others then
2214              raise;
2215     end;
2216 
2217     if (l_ldap_auth>0) then
2218 
2219       begin
2220           l_retval := dbms_ldap.open_ssl(ldapSession, 'file:'||l_db_wlt_url, l_db_wlt_pwd, l_ldap_auth);
2221       exception when others then
2222             if (fnd_log.LEVEL_UNEXPECTED>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2223             then
2224               fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source,' Cannot establish SSL channel to OiD: '||sqlcode||'-'||sqlerrm);
2225             end if;
2226 
2227         fnd_message.set_name('FND','FND_SSO_INV_AUTH_MODE'); -- Invalid SSL authcode... it is enouggh description
2228         return fnd_ldap_util.G_FAILURE;
2229       end;
2230 
2231       if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2232       then
2233             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Excellent!! Using SSL to contact OiD');
2234       end if;
2235     end if;
2236 
2237 
2238     l_retval := dbms_ldap.simple_bind_s(ldapSession, user_dn , p_password);
2239 
2240     -- we do analyze in extense the possible DBMS_LDAP exceptions to return accurate messages
2241 
2242 
2243    exception
2244     when dbms_ldap.general_error then
2245         -- here comes the explanation
2246         l_message := sqlerrm;
2247         -- first we check if the password is real,
2248 
2249         if (instr(l_message,':9000:')>0 )then
2250            fnd_message.set_name('FND','FND_SSO_PASSWORD_EXPIRED'); --Your account is locked
2251             if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2252             then
2253               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OiD account password expired ');
2254             end if;
2255         elsif (instr(l_message,':9001:')>0 )then
2256            fnd_message.set_name('FND','FND_SSO_LOCKED'); --Your account is locked
2257             if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2258             then
2259               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OiD account locked');
2260             end if;
2261 
2262         else
2263            if (comparePassword(ldapSession, user_dn , p_password) )then
2264               if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2265               then
2266                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OiD password match but ..');
2267               end if;
2268               if (instr(l_message,':9050:')>0) then
2269                  if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2270                  then
2271                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OiD account is disabled');
2272                  end if;
2273                 fnd_message.set_name('FND','FND_SSO_USER_DISABLED'); --Your account is disabled
2274               elsif (instr(l_message,':9053:')>0) then
2278                  end if;
2275                 if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2276                  then
2277                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OiD account is not active: today is out of [start,end] dates ');
2279                 fnd_message.set_name('FND','FND_SSO_NOT_ACTIVE'); --Your account not active. Either past end_date or future start_date
2280               else  --unknown reason
2281                   if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2282                   then
2283                      fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'cannot bind because:'||l_message);
2284                   end if;
2285                   -- maybe is not the reason, but it is enough for return , I guess
2286                   fnd_message.set_name('FND','FND_APPL_LOGIN_FAILED'); -- invalid username password
2287               end if;
2288 
2289            else
2290               if (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2291               then
2292                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OiD password did not match');
2293               end if;
2294                -- maybe is not the reason, but it is enough for return , I guess
2295                fnd_message.set_name('FND','FND_APPL_LOGIN_FAILED'); -- invalid username password
2296            end if;
2297         end if;
2298          if (fnd_log.LEVEL_PROCEDURE>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2299          then
2300               fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END: bind error: '||l_message);
2301           end if;
2302         return fnd_ldap_util.G_FAILURE;
2303     when others then
2304          if (fnd_log.LEVEL_UNEXPECTED>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2305          then
2306               fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'END: unexpected'||l_message);
2307           end if;
2308           return fnd_ldap_util.G_FAILURE;
2309    end;
2310 
2311 
2312    l_retval:= dbms_ldap.unbind_s(ldapSession);
2313     if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2314       then
2315          fnd_log.string(fnd_log.LEVEL_PROCEDURE , l_module_source, 'END: Valid Username/password');
2316     end if;
2317       return fnd_ldap_util.G_SUCCESS;
2318 
2319   exception when others then
2320          if (fnd_log.LEVEL_UNEXPECTED>= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2321          then
2322               fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'END: unexpected '||sqlcode||' - '||sqlerrm);
2323           end if;
2324            fnd_message.set_name('FND','FND-9914'); -- unexpected error
2325           return fnd_ldap_util.G_FAILURE;
2326 end validate_login;
2327 
2328 
2329 function get_user_name_from_data( dn in varchar2, data in FND_LDAP_UTIL.ldap_record_values )
2330   return varchar2 is
2331   l_realm_idx pls_integer;
2332   nna varchar2(2000);
2333   ret varchar2(4000);
2334 BEGIN
2335     ret := null;
2336     l_realm_idx := FND_SSO_REGISTRATION.getUserRealmIndex(dn);
2337     if (l_realm_idx >=0 ) THEN
2338            nna:=fnd_sso_registration.get_realm_attribute(l_realm_idx, 'orclcommonnameattribute');
2339            if (data.exists(nna)) THEN
2340                ret := data(nna)(0);
2341             end if;
2342     END IF;
2343     return ret;
2344 END get_user_name_from_data;
2345 
2346 function get_username_from_guid(p_guid in fnd_user.user_guid%type)
2347     return varchar2
2348 is
2349   ldapSession dbms_ldap.session;
2350   flag pls_integer;
2351   ret varchar2(4000);
2352   l_dn varchar2(4000);
2353   l_user_data FND_LDAP_UTIL.ldap_record_type;
2354   l_realm_idx pls_integer;
2355     nna varchar2(2000);
2356 
2357 BEGIN
2358     ldapSession := fnd_ldap_util.c_get_oid_session(flag);
2359 
2360     l_dn := FND_LDAP_UTIL.get_dn_for_guid(p_guid);
2361     l_realm_idx := FND_SSO_REGISTRATION.getUserRealmIndex(l_dn);
2362     ret:= null;
2363     if (l_realm_idx >=0 ) THEN
2364            nna:=fnd_sso_registration.get_realm_attribute(l_realm_idx, 'orclcommonnicknameattribute');
2365           if ( FND_LDAP_UTIL.LoadLdapRecord(ldapsession, l_user_data ,p_guid,FND_LDAP_UTIL.G_GUID_KEY)) THEN
2366              if (l_user_data.data.exists(nna)) THEN
2367                ret := l_user_data.data(nna)(0);
2368               end if;
2369           end if;
2370     END IF;
2371 
2372     fnd_ldap_util.c_unbind(ldapSession,flag);
2373     return ret;
2374 
2375   EXCEPTION WHEN OTHERS THEN
2376         fnd_ldap_util.c_unbind(ldapSession,flag);
2377          if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2378         then
2379            fnd_log.string(fnd_log.LEVEL_EXCEPTION, G_MODULE_SOURCE||'.get_username_from_guid: ', sqlerrm);
2380         end if;
2381         raise;
2382 
2383 END;
2384 
2385 --
2386 -- Search either by user_name or dn
2387 -- Fills the record with relevant information
2388 ---
2389 ---   FUTURE: it is possible to cache , seems that the user is looked up several times in some flows.
2390 
2391 FUNCTION SearchUser (ldap in out nocopy dbms_ldap.session ,
2392     p_ldap_user IN OUT nocopy fnd_ldap_user.ldap_user_type ,
2393     username_z in varchar2 default null,
2394     dn_z in varchar2 default null)  return boolean
2395 IS
2396 
2397  guid varchar2(4000);
2398  realmDN varchar2(4000);
2399  dn varchar2(4000);
2400  l_module_source varchar2(256);
2401 BEGIN
2402   l_module_source := G_MODULE_SOURCE || 'SearchUser: ';
2403 
2404   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2405   then
2406     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'Begin');
2407   end if;
2408 
2409   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2410   then
2414 
2411     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' isername:'||username_z||' dn:'||dn_z);
2412   end if;
2413 
2415   if (dn_z is null and username_z is null) THEN
2416     if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2417     then
2418       fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END-> false ,Must suply either dn or username ');
2419     end if;
2420 
2421     return false;
2422   END IF;
2423 
2424   IF (dn_z is not null) THEN
2425 
2426      iF (username_z is not null) THEN
2427         if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2428         then
2429          fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END-> false , choose  dn or username, do not use both ');
2430         end if;
2431          raise TOO_MANY_ROWS  ;
2432      END IF;
2433 
2434 
2435      realmDN := FND_OID_PLUG.get_realm_from_user_dn(ldap,dn_z);
2436 
2437      if (realmDN is not null ) THEN
2438          if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2439           then
2440             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' Realm->:'||realmDN);
2441           end if;
2442             IF FND_LDAP_UTIL.loadldaprecord(ldap,p_ldap_user.user_data,p_ldap_user.dn,dn_z,FND_LDAP_UTIL.G_DN_KEY) THEN
2443               if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2444                then
2445                  fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' Complete the record ' );
2446                end if;
2447                ProcessLoadedLpadUserRecord(p_ldap_user,realmDN,dn_z);
2448 
2449               if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2450               then
2451                fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END-> true ');
2452               end if;
2453                return true; -- loaded from dn_z
2454            ELSE
2455               return false;
2456            END IF;
2457       ELSE
2458          if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2459           then
2460             fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, ' END-> Dn does not belong to any realm');
2461           end if;
2462         return false; -- no a valid user dn
2463       END IF;
2464   ELSE
2465       if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2466      then
2467         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' lookup by username');
2468      end if;
2469      guid := get_user_guid(ldap,username_z,dn);
2470      if (guid is not null) THEN
2471         if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2472         then
2473           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, ' Found guid:'||guid);
2474          end if;
2475          IF FND_LDAP_UTIL.loadldaprecord(ldap,p_ldap_user.user_data,p_ldap_user.dn,dn,FND_LDAP_UTIL.G_DN_KEY) THEN
2476                ProcessLoadedLpadUserRecord(p_ldap_user,realmDN,dn);
2477               if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2478               then
2479                 fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, ' END-> FOUND');
2480               end if;
2481 
2482                return true; -- loaded from username search
2483            ELSE
2484               if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2485               then
2486                 fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, ' END-> FAIL');
2487               end if;
2488 
2489               return false;
2490         END IF;
2491      else
2492                if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2493               then
2494                 fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, ' END-> NOT FOUND');
2495               end if;
2496 
2497       return null;
2498      END IF;
2499   END IF;
2500 
2501 
2502   EXCEPTION WHEN OTHERS THEN
2503          if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2504         then
2505            fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source , sqlerrm);
2506         end if;
2507         raise;
2508 
2509 
2510 END SearchUser;
2511 
2512 FUNCTION getEmptyLU return ldap_user_type
2513 IS
2514     ret ldap_user_type;
2515 BEGIN
2516    ret.user_name :=null;
2517    return ret;
2518 END getEmptyLU;
2519 
2520 
2521 --
2522 -- Wrapper to suply an ldapSession
2523 ---
2524 FUNCTION SearchUser (  username_z in varchar2,
2525     p_ldap_user IN OUT nocopy fnd_ldap_user.ldap_user_type)  return boolean
2526 IS
2527 ret boolean;
2528 ldapSession dbms_ldap.session;
2529 flag pls_integer;
2530 l_module varchar2(200) := G_MODULE_SOURCE||'.SearchUser[public]';
2531 BEGIN
2532     ldapSession := fnd_ldap_util.c_get_oid_session(flag);
2533     ret:= false;
2534     ret := SearchUser(ldapSession, p_ldap_user , username_z);
2535 
2536     fnd_ldap_util.c_unbind(ldapSession,flag);
2537     return ret;
2538 
2539   EXCEPTION WHEN OTHERS THEN
2540         fnd_ldap_util.c_unbind(ldapSession,flag);
2541          if (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2542         then
2543            fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module, sqlerrm);
2544         end if;
2545         raise;
2546 END SearchUser;
2547 
2548 FUNCTION new_Ldap_user( user_name in FND_USER.USER_NAME%TYPE) return ldap_user_type
2549 is
2550   ret ldap_user_type := getEmptyLU();
2551 BEGIN
2552   ret.user_name := user_name;
2553   select user_id,user_name,user_guid into ret.user_id,ret.user_name, ret.user_guid
2554     from FND_USER WHERE
2555     FND_USER.USER_NAME= ret.user_name;
2556   return ret;
2557   EXCEPTION WHEN NO_DATA_FOUND then
2558      ret.user_id:=null;
2562 
2559      ret.user_guid:=null;
2560      return ret;
2561 END new_Ldap_user; -- user_name
2563 PROCEDURE TrimPermited(
2564     p_entity pls_integer,
2565     p_operation pls_integer,
2566     l_user IN OUT nocopy fnd_ldap_user.ldap_user_type)
2567 IS
2568  attr varchar2(200);
2569  l_attr varchar2(200);
2570  x_oid pls_integer;
2571  x_fnd pls_integer;
2572  l_module_source varchar2(200) := G_MODULE_SOURCE||'.TrimPermited';
2573 
2574 BEGIN
2575   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2576   then
2577         fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'Begin:'|| p_entity||' '|| p_operation);
2578   end if;
2579   attr := l_user.user_data.first;
2580   WHILE attr is not null LOOP
2581       l_attr := attr;
2582     if (p_operation = FND_LDAP_WRAPPER.G_ADD and attr='userpassword') THEN
2583         null;
2584         --BUG 9271995:" do not trim password during creation
2585     ELSE
2586     FND_SSO_REGISTRATION.is_operation_allowed(FND_LDAP_WRAPPER.G_EBIZ_TO_OID,
2587          p_entity,p_operation,
2588           l_attr,x_fnd,x_oid,l_user.user_name,l_user.realmDN);
2589        if (x_oid <> FND_LDAP_WRAPPER.G_SUCCESS) THEN
2590             if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)then
2591               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Discard '||attr);
2592             end if;
2593             l_user.user_data.delete(attr);
2594        END IF;
2595       END IF;
2596       attr := l_user.user_data.next(attr);
2597   END LOOP;
2598   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
2599   then
2600         fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END');
2601   end if;
2602 
2603 END TrimPermited;
2604 
2605 FUNCTION pvt_create_user
2606   (p_ldap_user IN OUT nocopy fnd_ldap_user.ldap_user_type)
2607   RETURN pls_integer
2608 IS
2609   l_module_source VARCHAR2(256);
2610   retval pls_integer;
2611   result pls_integer;
2612   ldapSession dbms_ldap.session;
2613   flag pls_integer;
2614   l_userDN          VARCHAR2(4000);
2615   l_user_guid       VARCHAR2(4000);
2616   l_oid_username    VARCHAR2(4000);
2617   l_counter         INTEGER;
2618   l_guid            VARCHAR2(100);
2619   l_link            VARCHAR2(10);
2620   l_profile_defined BOOLEAN;
2621   l_user_exists     BOOLEAN;
2622   l_dn_exists       BOOLEAN;
2623   l_username_exists BOOLEAN;
2624   l_rollback_ldap   BOOLEAN;
2625   l_uname varchar2(4000);
2626   l_dn varchar2(4000);
2627   v varchar2(4000);
2628   l_multi_sso  varchar2(10) := 'Y';
2629   l_user_linked varchar2(1) := 'N';
2630   l_session_flag boolean := false;
2631 BEGIN
2632   l_module_source := G_MODULE_SOURCE || 'pvt_create_user: ';
2633   -- set default value to failure. change to success when user created successfully
2634   retval                      := fnd_ldap_util.G_FAILURE;
2635   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2636     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
2637   END IF;
2638   ldapSession := fnd_ldap_util.c_get_oid_session(flag);
2639 
2640   l_session_flag := true;  /* fix for bug 8271359 */
2641 
2642   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
2643       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'l_session_flag = true ' );
2644   end if;
2645 
2646   l_uname := p_ldap_user.user_name;
2647   IF SearchUser(ldapSession,p_ldap_user, username_z => l_uname) THEN
2648     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2649       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User exists , checkin APPS_SSO_LINK_SAME_NAMES');
2650     END IF;
2651 
2652     -- Bug 8618800
2653     -- Link same names should only apply if the LDAP user is not already linked to an EBS user on this instance
2654     -- and APPS_SSO_ALLOW_MULTIPLE_ACCOUNTS is Disabled.  Get Site level only.
2655     fnd_profile.get_specific(name_z => 'APPS_SSO_ALLOW_MULTIPLE_ACCOUNTS',
2656                             USER_ID_Z          =>  -1,
2657                             RESPONSIBILITY_ID_Z => -1,
2658                             APPLICATION_ID_Z    => -1,
2659                             ORG_ID_Z            => -1,
2660                             val_z => l_multi_sso,
2661                             defined_z => l_profile_defined);
2662 
2663     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2664         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Checking APPS_SSO_ALLOW_MULTIPLE_ACCOUNTS '||l_multi_sso);
2665     END IF;
2666 
2667     FND_SSO_REGISTRATION.get_user_or_site_profile(
2668              profile_name=>'APPS_SSO_LINK_SAME_NAMES' ,
2669              user_name_z => p_ldap_user.user_name ,
2670              val_z =>l_link,
2671              defined_z => l_profile_defined );
2672 
2673     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2674         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Checking APPS_SSO_LINK_SAME_NAMES '||l_link);
2675     END IF;
2676 
2677     -- Get guid of LDAP User.
2678     l_user_guid := get_user_guid(ldapSession,l_uname,l_dn);
2679 
2680      if (l_user_guid is not null) then
2681         IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2682             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User guid found...check if already linked to an EBS user');
2683         END IF;
2684 
2685         begin
2686            select 'Y' into l_user_linked from fnd_user
2687            where user_guid = l_user_guid
2688            and rownum = 1;
2689 
2690           IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2691               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Is this OID user already linked? '||l_user_linked);
2692           END IF;
2693 
2697             END IF;
2694         exception when no_data_found then
2695             IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2696                 fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'This OID is not linked ');
2698             null;
2699         end;
2700      end if;
2701 
2702     IF (l_multi_sso = 'N' and l_user_linked = 'Y') then
2703          if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2704              fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source,
2705                    'STOP - Allow Multiple accounts is disabled and this LDAP user is already linked to an EBS user(s)');
2706          end if;
2707         raise link_create_failed_EXCEPTION;
2708     END IF;
2709 
2710     IF (l_link = 'Y') THEN
2711       if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2712         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User exists but APPS_SSO_LINK_SAME_NAMES is Enabled, adding user to subscription list');
2713       end if;
2714 
2715       retval := create_user_subscription(ldapSession, p_ldap_user.dn , p_ldap_user.user_guid);
2716 
2717       IF (retval <> fnd_ldap_util.G_SUCCESS) THEN
2718         if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2719           fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source,
2720                    'Failed to create subscription for create_user("'||p_ldap_user.user_name
2721                      ||'"), user existed and  (APPS_SSO_LINK_SAME_NAMES=Enabled)');
2722         end if;
2723         raise link_create_failed_EXCEPTION;
2724 
2725       ELSE
2726           if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2727              fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Subscription created at OiD');
2728           end if;
2729 
2730        -- Bug 8661715 Potential ldap leak
2731         if (l_session_flag = true) then
2732             if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)  then
2733                 fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'LDAP SESSION closing ' );
2734             end if;
2735             fnd_ldap_util.c_unbind(ldapSession,flag);
2736             l_session_flag := false;
2737         end if;
2738         -- Bug 8618800 - User already exists and Link Same Names is enabled - simply link the users
2739         -- return retval;
2740 
2741          -- Bug 13692093: Return new status since the LDAP user already exists the password should not be updated.
2742          IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2743              fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OID User already exists - return G_OID_USER_EXISTS');
2744           END IF;
2745 
2746          return G_OID_USER_EXISTS;
2747 
2748       END IF;
2749     ELSE -- AUTOLINK DISABLED
2750       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2751         fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'FAILED: User exists [username='||p_ldap_user.user_name||']');
2752       END IF;
2753       raise duplicate_username_EXCEPTION;
2754     END IF;
2755   ELSE
2756     FND_OID_PLUG.completeForCreate(ldapSession, p_ldap_user);
2757     l_oid_username := p_ldap_user.user_name;
2758     l_dn := p_ldap_user.dn ;
2759     IF SearchUser(ldapSession,p_ldap_user,dn_z => l_dn ) THEN
2760       IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2761         fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'DN collsion, trying to create "'||l_oid_username||'" on dn:' || p_ldap_user.dn );
2762       END IF;
2763       raise duplicate_dn_EXCEPTION;
2764     END IF;
2765   END IF;
2766 
2767   --Time to verify is operation allowed for given attributes
2768   TrimPermited(fnd_ldap_wrapper.G_IDENTITY,fnd_ldap_wrapper.G_ADD,p_ldap_user);
2769 
2770   BEGIN
2771       v := p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME)(0);
2772       EXCEPTION WHEN OTHERS THEN
2773       v := NULL;
2774   END;
2775   if (v is null) THEN
2776       IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2777         fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'NicknameAtrtribute not preosente in the record , Cannot create. Check configuration (prov Profiles)');
2778       END IF;
2779      raise CANNOT_CREATE_EXCEPTION;
2780   END IF;
2781 
2782 
2783   IF NOT ( attributePresent(p_ldap_user,'sn') AND attributePresent(p_ldap_user,'cn')) THEN
2784     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2785       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Not all attrirbutes are present ' || ' cn='||getAttribute(p_ldap_user,'cn') || ' sn='||getAttribute(p_ldap_user,'sn') );
2786     END IF;
2787     IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2788       fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END -> failed');
2789     END IF;
2790      -- Bug 8661715 Potential ldap leak
2791       if (l_session_flag = true) then
2792           if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)  then
2793               fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'LDAP SESSION closing ' );
2794           end if;
2795           l_session_flag := false;
2796           fnd_ldap_util.c_unbind(ldapSession,flag);
2797       end if;
2798      RETURN fnd_ldap_util.G_FAILURE;
2799   END IF;
2800 
2801   setAttribute(p_ldap_user,'objectClass','top',true);
2802   setAttribute(p_ldap_user,'objectClass','inetorgperson',false);
2803   setAttribute(p_ldap_user,'objectClass','orcluserv2',false);
2804 
2805   retval := create_ldap_user(ldapSession, p_ldap_user);
2806 
2807   IF (retval <> fnd_ldap_util.G_SUCCESS) THEN
2808     if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2809         fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, 'User creation failed');
2810     end if;
2811   ELSE
2812     IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2816     IF (retval <> fnd_ldap_util.G_SUCCESS) THEN
2813       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'LDAP user created, now creating susbscriptions');
2814     END IF;
2815     retval := create_user_subscription(ldapSession, p_ldap_user.dn, p_ldap_user.user_guid);
2817       IF (fnd_log.LEVEL_UNEXPECTED>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2818         fnd_log.string(fnd_log.LEVEL_UNEXPECTED ,l_module_source, 'Subscription creation failed for a new user,  removing user');
2819       END IF;
2820       delete_user(ldapSession, p_ldap_user.user_guid,result);
2821       IF (result <>fnd_ldap_util.G_SUCCESS) THEN
2822         if (fnd_log.LEVEL_UNEXPECTED >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2823              fnd_log.string(fnd_log.LEVEL_UNEXPECTED, l_module_source, ' unable to remove user ');
2824         end if;
2825       END IF;
2826       raise link_create_failed_EXCEPTION;
2827     ELSIF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2828       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Subscription creation succeeded');
2829     END IF;
2830 
2831     fnd_ldap_util.c_unbind(ldapSession,flag);
2832     l_session_flag := false;
2833 
2834       if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
2835           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'l_session_flag : = false ' );
2836           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'LDAP SESSION CLOSED NORMALLY : ' );
2837       end if;
2838 
2839     IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2840       IF (retval = fnd_ldap_util.G_SUCCESS) THEN
2841         fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'End ->fnd_ldap_util.G_SUCCESS');
2842       ELSE
2843         fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'End ->fnd_ldap_util.G_FAILURE');
2844       END IF ;
2845     END IF;
2846   END IF;
2847   RETURN retval;
2848 EXCEPTION
2849 
2850 WHEN CANNOT_CREATE_EXCEPTION THEN
2851   if l_session_flag = true then
2852        if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL)  then
2853            fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closing in CANNOT CREATE EXCEPTION BLOCK - START ' );
2854        end if;
2855      fnd_ldap_util.c_unbind(ldapSession,flag);
2856 
2857      if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
2858          fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closed in CANNOT CREATE EXCEPTION BLOCK - END ');
2859      end if;
2860   end if;
2861 
2862   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2863     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'Error creating ldap user "' ||p_ldap_user.user_name||'" ' ||' Incorrect configuration' );
2864   END IF;
2865   fnd_message.set_name ('FND', 'FND-9903');
2866   RETURN fnd_ldap_util.G_FAILURE;
2867 
2868 WHEN duplicate_dn_EXCEPTION THEN
2869   if l_session_flag = true then
2870        if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL)  then
2871            fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closing in Duplicate DN EXCEPTION BLOCK - START ' );
2872        end if;
2873      fnd_ldap_util.c_unbind(ldapSession,flag);
2874 
2875      if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
2876          fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closed in Duplicate DN EXCEPTION BLOCK - END ');
2877      end if;
2878   end if;
2879 
2880   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2881     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'Error creating ldap user "' ||p_ldap_user.user_name||'" ' ||' DN  already exists [DN:'||p_ldap_user.dn ||']' );
2882   END IF;
2883   fnd_message.set_name ('FND', 'FND_SSO_USER_EXISTS');
2884   RETURN fnd_ldap_util.G_FAILURE;
2885 WHEN duplicate_username_EXCEPTION THEN
2886   if l_session_flag = true then
2887        if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL)  then
2888            fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closing in Duplicate Username EXCEPTION BLOCK - START ' );
2889        end if;
2890      fnd_ldap_util.c_unbind(ldapSession,flag);
2891 
2892      if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
2893          fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closed in Duplicate username EXCEPTION BLOCK - END ');
2894      end if;
2895   end if;
2896 
2897   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2898     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'Error creating ldap user "' ||p_ldap_user.user_name||'" ' ||' username  already exists [guid:'||p_ldap_user.user_guid||']' );
2899   END IF;
2900   fnd_message.set_name ('FND', 'FND_SSO_USER_EXISTS');
2901   RETURN fnd_ldap_util.G_FAILURE;
2902 WHEN link_create_failed_EXCEPTION THEN
2903   if l_session_flag = true then
2904        if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL)  then
2905            fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closing in Link create failed EXCEPTION BLOCK - START ' );
2906        end if;
2907      fnd_ldap_util.c_unbind(ldapSession,flag);
2908 
2909      if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
2910          fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closed in Link create failed EXCEPTION BLOCK - END ');
2911      end if;
2912   end if;
2913 
2914   IF (fnd_log.LEVEL_EXCEPTION>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2915     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, 'Error creating sunscriptions for "'||p_ldap_user.user_name||'"  guid:'||p_ldap_user.user_guid );
2916   END IF;
2917   fnd_message.set_name('FND','FND_SSO_LINK_USER_FAILED');
2918   RETURN fnd_ldap_util.G_FAILURE;
2919 WHEN OTHERS THEN
2920   if l_session_flag = true then
2921        if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL)  then
2922            fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closing in WHEN OTHERS EXCEPTION BLOCK - START ' );
2926      if (fnd_log.LEVEL_ERROR >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
2923        end if;
2924      fnd_ldap_util.c_unbind(ldapSession,flag);
2925 
2927          fnd_log.string(fnd_log.LEVEL_ERROR, l_module_source, 'LDAP SESSION closed in WHEN OTHERS EXCEPTION BLOCK - END ');
2928      end if;
2929   end if;
2930 
2931   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2932     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
2933   END IF;
2934   raise;
2935 END pvt_create_user;
2936 
2937 PROCEDURE create_user
2938   (
2939     p_realm in out nocopy varchar2,
2940     p_user_name       IN VARCHAR2,
2941     p_password        IN VARCHAR2,
2942     p_start_date      IN DATE DEFAULT sysdate,
2943     p_end_date        IN DATE DEFAULT NULL,
2944     p_description     IN VARCHAR2 DEFAULT NULL,
2945     p_email_address   IN VARCHAR2 DEFAULT NULL,
2946     p_fax             IN VARCHAR2 DEFAULT NULL,
2947     p_expire_password IN pls_integer,
2948     x_user_guid OUT nocopy raw,
2949     x_password OUT nocopy VARCHAR2,
2950     x_result OUT nocopy pls_integer)
2951 IS
2952 
2953   l_usr fnd_ldap_user.ldap_user_type;
2954   l_module_source VARCHAR2(256) := G_MODULE_SOURCE || 'create_user: ';
2955   l_start_date      VARCHAR2(256);
2956   l_end_date        VARCHAR2(656);
2957   l_local_login     VARCHAR2(100);
2958   l_profile_defined BOOLEAN;
2959   l_nickname        VARCHAR2(256);
2960   l_password        VARCHAR2(256);
2961   l_enabled         VARCHAR2(30);
2962   l_du_result pls_integer;
2963   l_cp_result pls_integer;
2964   user_name fnd_user.user_name%type;
2965   l_disabled_usr boolean;
2966   l_oid_user_exists varchar2(1) := 'N';
2967 
2968 
2969 
2970 BEGIN
2971   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
2972     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
2973   END IF;
2974   if (p_realm is null) THEN
2975       p_realm := FND_OID_PLUG.get_realm_dn(p_user_name=>p_user_name);
2976   END IF;
2977 
2978   l_usr := new_Ldap_user(p_user_name);
2979 
2980   l_usr.realmDN := p_realm;
2981 
2982   l_enabled                := fnd_oid_util.G_ENABLED;
2983   IF ((p_start_date        IS NOT NULL AND p_start_date > sysdate) OR (p_end_date IS NOT NULL AND p_end_date <= sysdate)) THEN
2984     --usertype.orclisEnabled := fnd_oid_util.G_DISABLED;
2985      setAttribute(l_usr,'orclisEnabled',fnd_oid_util.G_DISABLED,true);
2986      l_disabled_usr := true;
2987   ELSE
2988     -- usertype.orclisEnabled := fnd_oid_util.G_ENABLED;
2989      setAttribute(l_usr,'orclisEnabled',fnd_oid_util.G_ENABLED,true);
2990      l_disabled_usr := false;
2991   END IF;
2992 
2993  /* Bug 9271995: Always create the user with the password
2994     By default it will remain expired
2995   IF (p_expire_password = fnd_ldap_util.G_TRUE) THEN
2996     l_password         := p_password;
2997   ELSE
2998     l_password := NULL;
2999   END IF;
3000   */
3001   l_password := p_password;
3002   /* If self service user and pending user, create the user as enabled user first and then change
3003   the flag to disabled after the password has been updated by proxying as that user. This is because
3004   we cannot proxy as a disabled user. */
3005   -- Bug 9398572.
3006   -- IF ( (l_password  IS NULL) AND l_disabled_usr ) THEN
3007   IF ( (p_expire_password = fnd_ldap_util.G_FALSE) AND (l_disabled_usr) ) THEN
3008     l_enabled              := fnd_oid_util.G_DISABLED;
3009     --usertype.orclisEnabled := fnd_oid_util.G_ENABLED;
3010     setAttribute(l_usr,'orclisEnabled',fnd_oid_util.G_ENABLED,true);
3011   END IF;
3012   -- first create user. If self service, then pass in a null password
3013   user_name             := p_user_name;
3014   --l_nickname            := fnd_ldap_util.get_orclcommonnicknameattr(user_name);
3015   l_nickname := FND_SSO_REGISTRATION.get_realm_attribute(p_realm,'orclCommonNickNameAttribute');
3016   -- usertype.uid          := p_user_name;
3017   -- usertype.sn           := p_user_name;
3018   -- usertype.cn           := p_user_name;
3019   -- usertype.userPassword := l_password;
3020   -- usertype.description  := p_description;
3021   setAttribute(l_usr,l_nickname,p_user_name,true);
3022   setAttribute(l_usr,'uid',p_user_name,true);
3023   setAttribute(l_usr,'sn',p_user_name,true);
3024   setAttribute(l_usr,'cn',p_user_name,true);
3025   setAttribute(l_usr,'description',p_description,true);
3026 
3027   -- Passing a null password fails - previously this check was done in
3028   -- process_attributes
3029   /*  Bug 13472484 and 9498047 - commenting out adding the password attribute
3030  *  when creating the user.  We will create the user with no password initially
3031  *  and set the password later in the flow by calling change_password.  This
3032  *  will perform a check as to whether we should change the pwd as the user or
3033  *  admin so that expiration occurs.  This is to resolve issues with pwd
3034  *  history.  Setting this to NULL or a dummy pwd may cause issues with password
3035  *  policies.
3036  */
3037   -- IF (l_password IS NOT NULL) then
3038   --   setAttribute(l_usr,'userPassword',l_password,true);
3039   -- END IF;
3040 
3041   IF (upper(l_nickname)  = fnd_ldap_util.G_MAIL) THEN
3042     --usertype.mail       := p_user_name;
3043     setAttribute(l_usr,'mail',p_user_name,true);
3044   ELSE
3045     --usertype.mail := p_email_address;
3046     setAttribute(l_usr,'mail',p_email_address,true);
3047   END IF;
3048   IF (upper(l_nickname)                = fnd_ldap_util.G_FACSIMILETELEPHONENUMBER) THEN
3049     --usertype.facsimileTelephoneNumber := p_user_name;
3050     setAttribute(l_usr,'facsimileTelephoneNumber',p_user_name,true);
3051   ELSE
3052     --usertype.facsimileTelephoneNumber := p_fax;
3053     setAttribute(l_usr,'facsimileTelephoneNumber',p_fax,true);
3054   END IF;
3055 
3059 
3056   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3057       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Done setting attributes for user creation...now create the user in OID');
3058   END IF;
3060 
3061   x_result      := pvt_create_user(l_usr);
3062 
3063   if (x_result = G_OID_USER_EXISTS) then
3064       if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) then
3065           fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'OID user already exists...set flag and status.  Password related task should be bypassed');
3066       end if;
3067       l_oid_user_exists := 'Y';
3068       x_result :=  fnd_ldap_util.G_SUCCESS;
3069   end if;
3070 
3071 
3072  IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3073      if (x_result = fnd_ldap_util.G_SUCCESS) then
3074          fnd_log.string(fnd_log.LEVEL_STATEMENT,l_module_source,'Successfully created LDAP user');
3075      else
3076          fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'Failed to create LDAP user');
3077      end if;
3078  END IF;
3079 
3080  -- NOTE: This code seems to be a NOOP and may be removed
3081  IF (p_expire_password = fnd_ldap_util.G_TRUE) THEN
3082     l_password         := p_password;
3083   ELSE
3084     l_password := NULL;
3085   END IF;
3086 
3087   -- Bug 13692093: Added check for LINK_EXISTING which is a successful linking of a new FND and existing LDAP user
3088   IF (x_result   = fnd_ldap_util.G_SUCCESS) THEN
3089     -- x_user_guid := get_user_guid(p_user_name);
3090     x_user_guid := l_usr.user_guid;
3091     fnd_profile.get_specific( name_z => 'APPS_SSO_LOCAL_LOGIN', user_id_z => -1, val_z => l_local_login, defined_z => l_profile_defined);
3092     IF (l_local_login = 'SSO') THEN
3093       x_password     := fnd_web_sec.EXTERNAL_PWD;
3094     END IF;
3095     -- if p_expire_password = false then update the user password (and password only)
3096     IF ( (x_result = fnd_ldap_util.G_SUCCESS and l_oid_user_exists = 'N') )THEN
3097       begin
3098          IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3099              fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'User has been created - now set password');
3100          END IF;
3101 
3102              change_password(x_user_guid, p_user_name, p_password, p_expire_password, x_password, l_cp_result,TRUE);
3103 
3104          IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3105              fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'User password has been set');
3106          END IF;
3107 
3108       exception when others then
3109         delete_user(x_user_guid, x_result,true);
3110         raise;
3111       end;
3112       IF (l_enabled = fnd_oid_util.G_DISABLED) THEN
3113          if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3114              fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'Setting user to disabled.');
3115          end if;
3116         disable_user(x_user_guid, p_user_name, l_du_result);
3117       END IF;
3118       IF ( (l_cp_result = fnd_ldap_util.G_FAILURE ) OR (l_du_result = fnd_ldap_util.G_FAILURE) ) THEN
3119         if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3120              fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,'Error occurred - delete user');
3121         end if;
3122 
3123         delete_user(x_user_guid, x_result);
3124       ELSE
3125         x_result := fnd_ldap_util.G_SUCCESS;
3126       END IF;
3127     END IF;
3128   ELSE
3129     fnd_message.set_name ('FND', 'FND_SSO_USER_EXISTS');
3130   END IF;
3131   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3132     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'End');
3133   END IF;
3134 EXCEPTION
3135 WHEN OTHERS THEN
3136   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3137     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
3138   END IF;
3139   raise;
3140 END create_user;
3141 
3142 
3143 
3144 FUNCTION getNickNameAttr( username_z in varchar2) return varchar2
3145 IS
3146 realm varchar2(4000);
3147 user_rec ldap_user_type;
3148 idx pls_integer;
3149 l_module_source varchar2(256);
3150 BEGIN
3151   l_module_source:=  G_MODULE_SOURCE ||'getNickNameAttr';
3152   IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3153     fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, sqlerrm);
3154   END IF;
3155 
3156   if (username_z is null) THEN
3157     IF (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3158       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'No user given: use default');
3159     END IF;
3160      if (cache_default_nna is null) THEN
3161          cache_default_nna:= fnd_sso_registration.get_realm_attribute(
3162                          FND_SSO_REGISTRATION.getdefaultrealm,'orclCommonNickNameAttribute');
3163          IF (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3164            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Caching:'||cache_default_nna);
3165          END IF;
3166      END IF;
3167     IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3168       fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END->'||cache_default_nna||' From cache');
3169     END IF;
3170      return cache_default_nna;
3171   END IF;
3172 
3173 
3174   if (cache_user_name is not null) THEN
3175       if (cache_user_name = username_z) THEN
3176          IF (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3177            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Asking again for '||cache_user_name||'?');
3178          END IF;
3179          IF (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3180            fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source, 'END->'||cache_default_nna||' USER From cache');
3181          END IF;
3185            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'different user, not cached');
3182          return cache_nna;
3183       ELSE
3184          IF (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3186          END IF;
3187           cache_user_name:= null;
3188       END IF;
3189   END IF;
3190   -- ok, no options but search
3191 
3192   IF (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3193            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Need to locate the user at LDAP');
3194   END IF;
3195   IF (SearchUser(username_z=>username_z,p_ldap_user=>user_rec)) THEN
3196 
3197      IF (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3198            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User FOUND');
3199      END IF;
3200      cache_user_name := username_z;
3201      idx := FND_SSO_REGISTRATION.getuserrealmindex(user_rec.dn);
3202      cache_nna := Fnd_sso_registration.get_realm_attribute(
3203                          idx ,'orclCommonNickNameAttribute');
3204      IF (fnd_log.LEVEL_PROCEDURE>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3205            fnd_log.string(fnd_log.LEVEL_PROCEDURE ,l_module_source, 'END->'||cache_nna);
3206      END IF;
3207       return cache_nna;
3208   ELSE
3209      IF (fnd_log.LEVEL_STATEMENT>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3210            fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'User NOT FOUND, using default');
3211      END IF;
3212      IF (fnd_log.LEVEL_PROCEDURE>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3213            fnd_log.string(fnd_log.LEVEL_PROCEDURE ,l_module_source, 'END->'||cache_default_nna);
3214      END IF;
3215 
3216      return cache_default_nna; -- do not  cache it, maybe it is about to change
3217   END IF;
3218 EXCEPTION
3219 WHEN OTHERS THEN
3220   IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3221     fnd_log.string(fnd_log.LEVEL_EXCEPTION, l_module_source, sqlerrm);
3222   END IF;
3223   raise;
3224 
3225 END getNickNameAttr;
3226 
3227 
3228 --
3229 --
3230 -------------------------------------------------------------------------------
3231 /*
3232 
3233 
3234  API FOR LDAP_RECORD HANDLING
3235 
3236 */
3237 
3238 
3239 FUNCTION locateIdx ( col in out nocopy DBMS_LDAP.STRING_COLLECTION , val in  varchar ) return pls_integer
3240 is
3241   i pls_integer;
3242 BEGIN
3243   if (col is null or val is null ) then
3244      return null;
3245   end if;
3246   i:= col.first;
3247   while i is not null loop
3248       if (VAL = col(i) ) then
3249             return i;
3250       END IF;
3251       i := col.next(i);
3252   END LOOP;
3253   return null;
3254 END locateIdx;
3255 
3256 PROCEDURE setAttribute( usr in out nocopy ldap_user_type,
3257        attName in varchar2,
3258        attVal in  varchar2,
3259        replaceIt in boolean default false )
3260 IS
3261   old_idx pls_integer;
3262   lista DBMS_LDAP.STRING_COLLECTION ;
3263   l_name varchar2(4000) := lower(attName);
3264 BEGIN
3265   if (replaceIt) then
3266         usr.user_data.delete(l_name);
3267   END IF;
3268   if (NOT usr.user_data.exists(l_name)  ) then
3269       usr.user_data(l_name)(0) := attVal;
3270   ELSE
3271      -- the attribute exists
3272      old_idx := locateIdx(usr.user_data(l_name),attVal);
3273 
3274      if (old_idx is null) THEN
3275        -- the value is not duplicated
3276        usr.user_data(l_name)(usr.user_data(l_name).count+1):= attVal;
3277      end if;
3278    END IF;
3279 END setAttribute;
3280 
3281 PROCEDURE deleteAttribute( usr in out nocopy ldap_user_type,
3282        attName in varchar2,
3283        attVal in varchar2 )
3284 IS
3285  i pls_integer ;
3286   l_name varchar2(4000) := lower(attName);
3287 
3288 BEGIN
3289    i := locateIdx( usr.user_data(l_name), attVal);
3290    while i is not null LOOP
3291            usr.user_data(attName).delete(i);
3292            -- make sure we don't left duplicates
3293            i := locateIdx( usr.user_data(l_name), attVal);
3294     end LOOP;
3295 END deleteAttribute;
3296 
3297 
3298 PROCEDURE deleteAttribute( usr in out nocopy ldap_user_type,
3299        attName in  varchar2)
3300 is
3301   l_name varchar2(4000) := lower(attName);
3302 
3303 BEGIN
3304   if (usr.user_data(l_name) is not null ) THEN
3305      usr.user_data(l_name).delete;
3306      usr.user_data.delete(l_name);
3307   END IF;
3308 END deleteAttribute;
3309 
3310 FUNCTION getAttribute( usr in out nocopy ldap_user_type,
3311        attName in varchar2,
3312        attValIdx in pls_integer default 0 ) return varchar2
3313 is
3314 BEGIN
3315    return usr.user_data(lower(attName))(attValIdx);
3316    EXCEPTION WHEN OTHERS THEN
3317       return null;
3318 END getAttribute;
3319 
3320 
3321 
3322 
3323 
3324 FUNCTION firstValue(usr in out nocopy ldap_user_type,
3325        attName in out nocopy varchar2,
3326        attValue in out nocopy varchar2,
3327        handle in out nocopy pls_integer ) return boolean -- false when record is empty
3328 IS
3329 BEGIN
3330   attName := null;
3331   attValue := null;
3332   handle := null;
3333   attName := usr.user_data.first;
3334   if (attName is not null) THEN
3335      handle := usr.user_data(attName).first;
3336   ELSE
3337      handle := -1;
3338      return false;
3339   END IF ;
3340   -- skip empty lists
3341   WHILE handle is null LOOP
3342     attName := usr.user_data.next(attName);
3343     if (attName is not null) THEN
3344          handle := usr.user_data(attName).first;
3345     ELSE
3346        handle := -1;
3347        return false;
3348     END IF;
3352   END IF;
3349   END LOOP;
3350   if  (handle is not null) THEN
3351       attValue := usr.user_data(attName)(handle);
3353   return handle is not null;
3354   EXCEPTION when others then
3355      handle:= -1;
3356      return false;
3357 END firstValue;
3358 
3359 FUNCTION nextValue(usr in out nocopy ldap_user_type,
3360        attName in out nocopy varchar2,
3361        attValue in out nocopy varchar2,
3362        handle in out nocopy pls_integer ) return boolean -- true if returned fields contains data
3363 is
3364 BEGIN
3365   if (handle = -1 or handle is null ) THEN
3366      attName := null;
3367      attValue :=null;
3368      handle := -1;
3369      return false;
3370   end if;
3371   handle := usr.user_data(attName).next(handle);
3372   WHILE handle is null LOOP
3373       attName := usr.user_data.next(attName);
3374       if (attName is null) then
3375            handle := -1;
3376            attValue := null;
3377            return false;
3378       END IF;
3379       handle := usr.user_data(attName).first;
3380   END LOOP;
3381   if (handle is not null) THEN
3382      attValue := usr.user_data(attName)(handle);
3383      return true;
3384   else
3385      return false;
3386   end if;
3387 
3388 END nextValue;
3389 
3390 FUNCTION attributePresent( usr in out nocopy ldap_user_type,
3391        attName in varchar2) return boolean
3392   is
3393   l_name varchar2(4000):= lower(attName);
3394 BEGIN
3395  return usr.user_data.exists(l_name) and  usr.user_data(l_name).exists(0);
3396 
3397 END attributePresent;
3398 
3399 function CanSync ( p_user_id in pls_integer, p_user_name in varchar2 ) return boolean
3400 is
3401   l_local_login         varchar2(30);
3402   l_profile_defined     boolean;
3403   l_to_synch boolean := false;
3404     l_allow_sync          varchar2(1);
3405    l_user_id FND_USER.user_ID%TYPE := p_user_id;
3406    l_user_name FND_USER.user_name%TYPE := p_user_name;
3407   l_module_source varchar2(200) := G_MODULE_SOURCE || 'CanSync:['||p_user_id||']';
3408 BEGIN
3409   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)then
3410        fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source,'BEGIN '||p_user_name||' userid:'||p_user_id);
3411   end if;
3412   if (l_user_id is null and l_user_name is null) THEN
3413     if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)then
3414               fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source,'END->False, try it manually ');
3415    end if;
3416     return false;
3417   ELSIF (l_user_id is null) THEN
3418      BEGIN
3419         select user_id into l_user_id from FND_USER where user_name =l_user_name;
3420         EXCEPTION WHEN OTHERS THEN
3421             if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)then
3422                 fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source,'END->False, user not found ');
3423             end if;
3424             return false;
3425      END;
3426   ELSIF (l_user_name is null) THEN
3427      BEGIN
3428         select user_name  into l_user_name from FND_USER where user_id =l_user_id;
3429         EXCEPTION WHEN OTHERS THEN
3430            if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)then
3431                  fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source,'END->False, user not found ');
3432            end if;
3433            return false;
3434      END;
3435 
3436   ELSE
3437      null;
3438   END IF;
3439   fnd_profile.get_specific(
3440     name_z       => 'APPS_SSO_LOCAL_LOGIN',
3441     user_id_z    => l_user_id,
3442     val_z        => l_local_login,
3443     defined_z    => l_profile_defined);
3444 
3445      if (not l_profile_defined or l_local_login = fnd_oid_util.G_LOCAL)
3446      then
3447         if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
3448         then
3449             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,
3450                     'value of APPS_SSO_LOCAL_LOGIN::  '|| l_local_login);
3451             fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,
3452                     'Local user dont sych '|| l_user_name);
3453         end if;
3454              l_to_synch := FALSE;
3455      else
3456         fnd_profile.get_specific(name_z => 'APPS_SSO_LDAP_SYNC',
3457                   user_id_z => l_user_id,
3458                   val_z => l_allow_sync,
3459                   defined_z => l_profile_defined);
3460 
3461         if (not l_profile_defined or l_allow_sync = fnd_oid_util.G_N)
3462         then
3463              if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
3464              then
3465                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,
3466                        'value of APPS_SSO_LDAP_SYNC  '|| l_allow_sync);
3467                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source,
3468                        'Synch profile is disabled for user ...dont sych '|| l_user_name);
3469              end if;
3470              l_to_synch := FALSE;
3471        else
3472              l_to_synch := TRUE;
3473         end if;
3474   end if;
3475   if (fnd_log.LEVEL_PROCEDURE >= fnd_log.G_CURRENT_RUNTIME_LEVEL)then
3476         if (l_to_synch) THEN
3477              fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source,'END->True' );
3478         ELSE
3479               fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module_source,'END->False' );
3480         END IF;
3481   end if;
3482 
3483   return l_to_synch;
3484 
3485 
3486   EXCEPTION WHEN OTHERS THEN
3487       IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3488          fnd_log.string(fnd_log.LEVEL_EXCEPTION,  l_module_source , sqlerrm);
3489      END IF;
3490      raise;
3491 
3492 END CanSync;
3493 
3497 i pls_integer;
3494 -------------------------------------------------------------------------------
3495 PROCEDURE ProcessUpdateRec(ldap in dbms_ldap.session, dn in varchar2, upd in update_list)
3496 IS
3498 ma dbms_ldap.mod_array := null;
3499 l dbms_ldap.string_collection;
3500 m varchar2(100);
3501 l_module_source varchar2(400);
3502 BEGIN
3503   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
3504   then
3505     l_module_source := G_MODULE_SOURCE || 'ProcessUpdateRec: ';
3506     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'Begin');
3507   end if;
3508 
3509   ma := dbms_ldap.create_mod_array(num=> upd.count);
3510   i:= upd.first;
3511   while i is not null LOOP
3512       l.delete;
3513       l(0) := upd(i).val;
3514 
3515 
3516      dbms_ldap.populate_mod_array(modptr => ma,
3517                  mod_op =>upd(i).op,
3518                  mod_type => upd(i).att,
3519                  modval => l);
3520       i:=upd.next(i);
3521   END LOOP;
3522   i := dbms_ldap.modify_s(ldap,dn,ma);
3523 
3524   if (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL)
3525   then
3526     fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module_source, 'END');
3527   end if;
3528 
3529 
3530   EXCEPTION WHEN OTHERS THEN
3531      if (ma is not null) then
3532          dbms_ldap.free_Mod_array(ma);
3533      END IF;
3534     IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3535          fnd_log.string(fnd_log.LEVEL_EXCEPTION,  l_module_source , sqlerrm);
3536      END IF;
3537      raise;
3538 END ProcessUpdateRec;
3539 
3540 FUNCTION isValueOf( u ldap_user_type, fld in varchar2, val in varchar2 ) return boolean
3541 IS
3542 i pls_integer;
3543 n varchar2(200) := lower(fld);
3544 l dbms_ldap.string_collection;
3545 BEGIN
3546   if val is null THEN
3547      return false;
3548   END IF;
3549   IF u.user_data.exists(n) THEN
3550       L:= u.user_data(n);
3551       i:= l.first;
3552       while i is not null loop
3553           if (l(i) = val) THEN
3554               return true;
3555           END IF;
3556           i:= l.next(i);
3557       end loop;
3558   END IF;
3559   return false;
3560 END isValueOf;
3561 
3562 PROCEDURE ProcessLoadedLpadUserRecord (p_ldap_user  IN OUT nocopy fnd_ldap_user.ldap_user_type ,
3563     realmDN in varchar2 ,
3564     dn_z in varchar2 )
3565     IS
3566     realm pls_integer;
3567     exp1 dbms_ldap.string_collection;
3568     i pls_integer;
3569     l_module varchar2(4000):= G_MODULE_SOURCE || 'ProcessLoadedLpadUserRecord: ';
3570     shortest varchar2(4000);
3571     l_v varchar2(4000);
3572 BEGIN
3573 
3574    IF (fnd_log.LEVEL_PROCEDURE>= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3575                   fnd_log.string(fnd_log.LEVEL_PROCEDURE, l_module, 'BEGIN');
3576    END IF;
3577    IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3578                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'in realm:'||realmDN||' dn:'||dn_z);
3579    END IF;
3580    if ( p_ldap_user.user_data.exists('orclguid') and p_ldap_user.user_data('orclguid').count>0 ) THEN
3581         p_ldap_user.user_guid := p_ldap_user.user_data('orclguid')(0);
3582       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3583                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'guid(from record):'||p_ldap_user.user_guid );
3584       END IF;
3585     else
3586        p_ldap_user.user_guid:=null;
3587       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3588                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'NULL Guid (?)');
3589       END IF;
3590 
3591     END IF;
3592 
3593    p_ldap_user.dn := dn_z;  -- no validation
3594 
3595       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3596                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'dn(parameter):'||dn_z);
3597       END IF;
3598 
3599    realm := FND_SSO_REGISTRATION.getUserRealmIndex(p_ldap_user.dn);
3600       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3601                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'realmIdx(from dn)'||realm);
3602       END IF;
3603 
3604    p_ldap_user.NickName_ATT_NAME := lower(FND_SSO_REGISTRATION.get_realm_attribute(realm,'orclcommonnicknameattribute'));
3605       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3606                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'NickNameAttribute(realm)'||p_ldap_user.NickName_ATT_NAME );
3607       END IF;
3608 
3609    p_ldap_user.realmDN := FND_SSO_REGISTRATION.find_realm(realm);
3610       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3611                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'realmDN(resolving):'|| p_ldap_user.realmDN );
3612       END IF;
3613 
3614    exp1 := dbms_ldap.explode_dn(lower(dn_z),0);
3615    i :=  instr(exp1(0),'=');
3616    p_ldap_user.RDN_ATT_NAME:= substr(exp1(0),0,i-1) ;
3617    p_ldap_user.RDN_VALUE :=  substr(exp1(0),i+1) ;
3618    p_ldap_user.parent_DN := '';
3619    for i in 1 .. exp1.last -- skip the first
3620    LOOP
3621       p_ldap_user.parent_DN := p_ldap_user.parent_DN || ',' || exp1(i);
3622     END LOOP;
3623       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3624                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'parentDN(from parameter dn)'||p_ldap_user.parent_DN);
3625       END IF;
3626    -- The username calculation:: Can by tricky
3627    -- case 0: No value
3628    IF ( p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME).count=0) THEN
3629        p_ldap_user.user_name := null;
3630       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3631                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'nna has no value: username=NULL');
3635        p_ldap_user.user_name := p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME)(0);
3632       END IF;
3633    -- case 1: only one value in the nickanme attribute
3634    ELSIF ( p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME).count=1) THEN
3636       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3637                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, 'user_name(unique nna in record):'||p_ldap_user.user_name);
3638       END IF;
3639    ELSE
3640     -- case 2: several values, let's lookup on FND_USER to see if there is a match
3641      i := p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME).first;
3642      p_ldap_user.user_id:= null;
3643       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3644                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, ' several nna , lookinf for a best match');
3645       END IF;
3646      shortest := null;
3647      p_ldap_user.user_name :=null;
3648      while i is not null loop
3649         l_v:=p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME)(i);
3650 
3651 
3652         BEGIN
3653             IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3654                    fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, '  testing nna:'||l_v);
3655             END IF;
3656 
3657             select user_id into p_ldap_user.user_id from fnd_user where
3658                    user_name=l_v and user_guid=p_ldap_user.user_guid;
3659 
3660             IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3661                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, ' there it is user_uid:'||p_ldap_user.user_id);
3662             END IF;
3663             if (p_ldap_user.user_name is null) THEN
3664                   p_ldap_user.user_name := l_v;
3665                   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3666                       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, ' tyring with '||l_v);
3667                   END IF;
3668             ELSIF (length(p_ldap_user.user_name)>length(l_v)) THEN
3669                   p_ldap_user.user_name:= l_v;
3670                   IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3671                       fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, ' Better with shorter : '||l_v);
3672                   END IF;
3673             END IF;
3674 
3675             i:= p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME).next(i);
3676 
3677             --- multilink will be a disaster if a user with serveral nna matches several Ebz users
3678           EXCEPTION WHEN NO_DATA_FOUND THEN
3679                     i:= p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME).next(i);
3680 
3681         END;
3682      end loop;
3683      if (p_ldap_user.user_name is null) THEN
3684       IF (fnd_log.LEVEL_STATEMENT >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3685                   fnd_log.string(fnd_log.LEVEL_STATEMENT, l_module, '  bad luck, using the first one then '||p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME)(0));
3686       END IF;
3687 
3688        p_ldap_user.user_name := p_ldap_user.user_data(p_ldap_user.NickName_ATT_NAME)(0);
3689      END IF;
3690    END IF;
3691 
3692   EXCEPTION WHEN OTHERS THEN
3693      IF (fnd_log.LEVEL_EXCEPTION >= fnd_log.G_CURRENT_RUNTIME_LEVEL) THEN
3694          fnd_log.string(fnd_log.LEVEL_EXCEPTION,  l_module , sqlerrm);
3695      END IF;
3696      raise;
3697 
3698 END ProcessLoadedLpadUserRecord;
3699 
3700 
3701 function CanPopulate( attr in varchar2 , user_name in varchar2 , realm in varchar2) return boolean
3702 IS
3703     x_fnd pls_integer;
3704     x_oid pls_integer;
3705     vAttr varchar2(200) := attr;
3706 BEGIN
3707 
3708     FND_SSO_REGISTRATION.is_operation_allowed (
3709                   p_direction => FND_LDAP_WRAPPER.G_EBIZ_TO_OID,
3710                   p_entity => FND_LDAP_WRAPPER.G_IDENTITY,
3711                   p_operation => FND_LDAP_WRAPPER.G_ADD,
3712                   p_attribute => vAttr,
3713                   x_fnd_user => x_fnd,
3714                   x_oid => x_oid,
3715                   p_user_name => user_name,
3716                   p_realm_dn => realm);
3717     return x_oid=FND_LDAP_WRAPPER.G_SUCCESS;
3718 
3719 END CanPopulate;
3720 
3721 function CanUpdate( attr in varchar2 , user_name in varchar2 , realm in varchar2, x_user_creation in boolean default FALSE ) return boolean
3722 IS
3723    x_fnd pls_integer;
3724    x_oid pls_integer;
3725    vAttr varchar2(200) := attr;
3726 BEGIN
3727    IF (x_user_creation) THEN
3728 	return CanPopulate(attr,user_name,realm);
3729    ELSE
3730    FND_SSO_REGISTRATION.is_operation_allowed (
3731                   p_direction => FND_LDAP_WRAPPER.G_EBIZ_TO_OID,
3732                   p_entity => FND_LDAP_WRAPPER.G_IDENTITY,
3733                   p_operation => FND_LDAP_WRAPPER.G_MODIFY,
3734                   p_attribute => vAttr,
3735                   x_fnd_user => x_fnd,
3736                   x_oid => x_oid,
3737                   p_user_name => user_name,
3738                   p_realm_dn => realm);
3739    return x_oid=FND_LDAP_WRAPPER.G_SUCCESS;
3740     END IF;
3741 
3742 END CanUpdate;
3743 
3744 
3745 end fnd_ldap_user;