permission.inc
15.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
<?php
/**
* Class Permission
*
* Contains static functions used to determine whether the current user:
* o has permission to perform certain actions
* o has a certain role
* o is assigned to a certain group
* o has read/write access for a specific folder/directory
*
* @author Rob Cherry, Jam Warehouse (Pty) Ltd, South Africa
* @date 14 January 2003
* @package lib.roles
*/
class Permission {
/**
* Checks if the current user has write permission for a specific document.
* To have document write permission the user must satisfy ONE of the following conditions:
* o have write permission for the folder in which the document resides
* o be assigned a role which has write permission for the document
*
* @param $iDocumentID Primary key of document to check
*
* @return boolean true if the current user has document write permission, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasDocumentWritePermission($iDocumentID) {
global $default;
$oDocument = & Document::get($iDocumentID);
if ($oDocument == null) {
$default->log->info("Failed to retrieve document with ID $iDocumentID from database");
return false;
}
if (Permission::userHasFolderWritePermission($oDocument->getFolderID()) ||
Permission::userHasWriteRoleForDocument($iDocumentID)) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_doc_write . "id " . $iDocumentID;
return false;
}
/**
* Checks if the current user has read permission for a specific document.
* To have document read permission the folder must be public or the user must satisfy ONE of the following conditions:
* o have write permission for the document
* o have read permission for the folder in which the document resides
* o be assigned a role which has read permission for the document
*
* @param $iDocumentID Primary key of document to check
*
* @return boolean true if the current user has document read permission, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasDocumentReadPermission($iDocumentID) {
global $default;
$oDocument = & Document::get($iDocumentID);
if ($oDocument == null) {
$default->log->info("Failed to retrieve document with ID $iDocumentID from database");
return false;
}
if (Permission::userHasDocumentWritePermission($iDocumentID) ||
Permission::userHasReadRoleForDocument($iDocumentID) ||
Permission::userHasFolderReadPermission($oDocument->getFolderID())) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_doc_read . "id " . $iDocumentID;
return false;
}
/**
* Checks if the current user has write permission for a specific folder
* To have write permission on a folder the user must satisfy ONE of the following conditions:
* o be in the system administrator group
* o be in the unit administrator group for the unit to which the folder belongs
* o belong to a group that has write access to the folder
* o be assigned a role that has write access to the folder
*
* @param $iFolderID Primary key of folder to check
*
* @return boolean true if the user has folder write permission, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasFolderWritePermission($iFolderID) {
global $lang_err_user_folder_write;
if (Permission::userHasGroupWritePermissionForFolder($iFolderID) ||
Permission::userIsSystemAdministrator() ||
Permission::userIsUnitAdministratorForFolder($iFolderID)) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_folder_write . "id " . $iFolderID;
return false;
}
/**
* Checks if the current user has read permission for a specific folder
* To have read permission on a folder, the folder must be public or the user must satisfy ONE of the following conditions
* o have write permission for the folder
* o belong to a group that has read access to the folder
* o be assigned a role that has read permission for the folder
*
* @param $iFolderID Primary key of folder to check
*
* @return boolean true if the user has folder write permission, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasFolderReadPermission($iFolderID) {
global $lang_err_user_folder_write;
if (Permission::folderIsPublic($iFolderID) ||
Permission::userHasFolderWritePermission($iFolderID) ||
Permission::userHasGroupReadPermissionForFolder($iFolderID)) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_folder_write . "id " . $iFolderID;
return false;
}
/**
* Checks if a folder is public
*
* @param $iFolderID Primary key of folder to check
*
* @return boolean true if the folder is public, false otherwise and set $_SESSION["errorMessage"]
*/
function folderIsPublic($iFolderID) {
global $default, $lang_err_folder_not_public;
$sql = $default->db;
$sql->query("SELECT * FROM " . $default->owl_folders_table . " WHERE id = " . $iFolderID . " AND is_public = 1");
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_folder_not_public . "id " . $iFolderID;
return false;
}
/**
* Checks if the current user has write permission through group membership for a particular folder
*
* @param $iFolderID Primary key of folder to check
*
* @return boolean true if the user has folder write permission, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasGroupWritePermissionForFolder($iFolderID) {
global $default, $lang_err_user_folder_write;
$oFolder = Folder::get($iFolderID);
if ($oFolder == null) {
$default->log->info("Failed to retrieve folder with ID $iFolderID from database");
return false;
}
$sql = $default->db;
$sql->query("SELECT GFL.folder_id " .
"FROM groups_folders_link AS GFL INNER JOIN users_groups_link AS UGL ON GFL.group_id = UGL.group_id " .
"WHERE UGL.user_id = " . $_SESSION["userID"] . " " .
"AND GFL.can_write = 1 " .
"AND GFL.folder_id IN (" . (strlen($oFolder->getParentFolderIDs()) > 0 ? $oFolder->getParentFolderIDs() . ",$iFolderID" : $iFolderID) . ")");
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_folder_write;
return false;
}
/**
* Generate a string to be used in a where clause
* that consists of a list of id that are a folders
* parent Used this because user has read/write permission for a folder if s/he
* has read/write permission for the folder's parent (have to recurse up
* entire hierarchy)
*
* @param int Primary key of folder to start at
*
*/
function generateParentFolderString($iFolderID) {
$sFolderIDString = $iFolderID;
//$iParentFolderID = $iFolderID;
//recurse up the hierarchy, building the string as we go
$iParentFolderID = Folder::getParentFolderID($iFolderID);
while ($iParentFolderID != 0) {
$sFolderIDString .= ", " . $iParentFolderID;
$iFolderID = $iParentFolderID;
$iParentFolderID = Folder::getParentFolderID($iFolderID);
}
return $sFolderIDString;
}
/**
* Checks if the current user has read permission through group membership for a particular folder
*
* @param $iFolderID Primary key of folder to check
*
* @return boolean true if the user has folder write permission, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasGroupReadPermissionForFolder($iFolderID) {
global $default, $lang_err_user_folder_read;
$sql = $default->db;
$oFolder = Folder::get($iFolderID);
if ($oFolder == null) {
$default->log->info("Failed to retrieve folder with ID $iFolderID from database");
return false;
}
//$sql->query("SELECT * FROM " . $default->owl_groups_folders_table = "groups_folders_link" . " WHERE folder_id = " . $iFolderID . " AND user_id = " . $_SESSION["userID"] . " AND can_read = 1");
$sql->query("SELECT GFL.folder_id " .
"FROM groups_folders_link AS GFL INNER JOIN users_groups_link AS UGL ON GFL.group_id = UGL.group_id " .
"WHERE UGL.user_id = " . $_SESSION["userID"] . " " .
"AND GFL.can_read = 1 " .
"AND GFL.folder_id IN (" . (strlen($oFolder->getParentFolderIDs()) > 0 ? $oFolder->getParentFolderIDs() . ",$iFolderID" : $iFolderID) . ")");
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_folder_read;
return false;
}
/**
* Checks if the current user is in the specified group using the group id
*
* @param $iGroupID Primary key of group to check
*
* @return boolean true if the user is in the group, false otherwise and sets $_SESSION["errorMessage"]
*/
function userIsInGroupID($iGroupID) {
global $default, $lang_err_user_group;
$sql = $default->db;
$sql->query("SELECT id FROM " . $default->owl_groups_users_table . " WHERE id = " . $iGroupID . " AND user_id = " . $_SESSION["userID"]);
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_group . "group id = " . $iGroupID;
return false;
}
/**
* Checks if the current user is in the specified group using the group name
*
* @param $sGroupName Name of group to check
*
* @return boolean true if the user is in the group, false otherwise and sets $_SESSION["errorMessage"]
*/
function userIsInGroupName($sGroupName) {
global $default, $lang_err_user_group;
$sql = $default->db;
$sql->query("SELECT GULT.id FROM " . $default->owl_users_groups_table . " AS GULT INNER JOIN " . $default->owl_groups_table . " AS G ON GULT.group_id = G.ID WHERE G.name = '" . $sGroupName . "' AND user_id = " . $_SESSION["userID"]);
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_group . "group name " . $sGroupName;
return false;
}
/**
* Check is the user is assigned a specific role that has write permission for a folder
*
* @param $iFolderID Primary key of folder to check
*
* @return boolean true is the user has the role assigned, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasWriteRoleForDocument($iDocumentID) {
global $default, $lang_err_user_role;
$sql = $default->db;
$sql->query("SELECT * FROM $default->owl_folders_user_roles_table AS FURL INNER JOIN $default->owl_groups_folders_approval_table AS GFAL ON FURL.group_folder_approval_id = GFAL.id " .
"INNER JOIN $default->owl_roles_table AS R ON GFAL.role_id = R.id " .
"WHERE user_id = " . $_SESSION["userID"] . " " .
"AND FURL.document_id = $iDocumentID " .
"AND R.can_write = 1 " .
"AND R.active = 1");
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_role;
return false;
}
/**
* Check is the user is assigned a specific role that has read permission for a folder
*
* @param $iFolderID Primary key of folder to check
*
* @return boolean true is the user has the role assigned, false otherwise and set $_SESSION["errorMessage"]
*/
function userHasReadRoleForDocument($iDocumentID) {
global $default, $lang_err_user_role;
$sql = $default->db;
$sql->query("SELECT * FROM $default->owl_folders_user_roles_table AS FURL INNER JOIN $default->owl_groups_folders_approval_table AS GFAL ON FURL.group_folder_approval_id = GFAL.id " .
"INNER JOIN $default->owl_roles_table AS R ON GFAL.role_id = R.id " .
"WHERE user_id = " . $_SESSION["userID"] . " " .
"AND FURL.document_id = $iDocumentID " .
"AND R.can_read = 1");
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_user_role;
return false;
}
/**
* Checks if a given role exists using the role primary key
*
* @param $iRoleID Primary key of role to check for
*
* @return boolean true if role exists, false otherwise and set $_SESSION["errorMessage"]
*/
function roleIDExists($iRoleID) {
global $default, $lang_err_role_not_exist;
$sql = $default->db;
$sql->query("SELECT id FROM " . $default->owl_roles_table . " WHERE id = " . $iRoleID);
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_role_not_exist . $sRoleName;
return false;
}
/**
* Checks if a given role exists using the role name
*
* @param $sRoleName Name of role to check for
*
* @return boolean true if role exists, false otherwise and set $_SESSION["errorMessage"]
*/
function roleNameExists($sRoleName) {
global $default, $lang_err_role_not_exist;
$sql = $default->db;
$sql->query("SELECT id FROM " . $default->owl_roles_table . " WHERE name = '" . $sRoleName . "'");
if ($sql->next_record()) {
return true;
}
$_SESSION["errorMessage"] = $lang_err_role_not_exist . $sRoleName;
return false;
}
/**
* Get the primary key for a role
*
* @param $sRoleName Name of role to get primary key for
*
* @return ID if role exists, false otherwise and set $_SESSION["errorMessage"]
*/
function getRoleID($sRoleName) {
global $default, $lang_err_database;
if (roleExists($sRoleName)) {
$sql = $default->db;
$sql->query("SELECT id FROM " . $default->owl_roles_table . " WHERE name = '" . $sRoleName . "'");
$sql->next_record();
return $sql->f("id");
}
$_SESSION["errorMessage"] = $lang_err_database;
return false;
}
/**
* Check if the current user is a system administrator
*
* @return boolean true is user is system administrator, false otherwise and set $_SESSION["errorMessage"]
*
*/
function userIsSystemAdministrator($iUserID = "") {
global $default, $lang_err_database;
if ($iUserID == "") {
$iUserID = $_SESSION["userID"];
}
$sql = $default->db;
$sql->query("SELECT UGL.group_id " .
"FROM $default->owl_users_groups_table AS UGL INNER JOIN $default->owl_groups_table AS GL ON UGL.group_id = GL.id " .
"WHERE UGL.user_id = $iUserID " .
"AND is_sys_admin = 1");
return $sql->next_record();
}
/**
* Checks if the current user is a unit administrator
*
* @return boolean true if the user is the unit administrator for the unit to which the folder belongs, false otherwise
*/
function userIsUnitAdministrator($iUserID = "") {
global $default;
if ($iUserID == "") {
$iUserID = $_SESSION["userID"];
}
$sql = $default->db;
$sql->query("SELECT UGL.group_id " .
"FROM $default->owl_users_groups_table AS UGL INNER JOIN $default->owl_groups_units_table AS GUL ON GUL.group_id = UGL.group_id " .
"INNER JOIN $default->owl_groups_table AS GL ON GL.id = UGL.group_id " .
"WHERE UGL.user_id = $iUserID " .
"AND GL.is_unit_admin = 1");
return $sql->next_record();
}
/**
* Checks if the current user is a unit administrator
*
* @return boolean true if the user is the unit administrator for the unit to which the folder belongs, false otherwise
*/
function userIsUnitAdministratorForFolder($iFolderID) {
global $default;
$sql = $default->db;
$sql->query("SELECT UGL.group_id " .
"FROM $default->owl_users_groups_table AS UGL INNER JOIN $default->owl_groups_units_table AS GUL ON GUL.group_id = UGL.group_id " .
"INNER JOIN $default->owl_groups_table AS GL ON GL.id = UGL.group_id " .
"INNER JOIN $default->owl_groups_folders_table AS GFL ON GFL.group_id = UGL.group_id " .
"WHERE UGL.user_id = " . $_SESSION["userID"] . " " .
"AND GL.is_unit_admin = 1 " .
"AND GFL.folder_id = $iFolderID");
return $sql->next_record();
}
/**
* Checks if the current user is a guest user
*
* @return boolean true if the user is in the Anonymous group, else false
*/
function userIsGuest($iUserID = "") {
global $default;
if ($iUserID == "") {
$iUserID = $_SESSION["userID"];
}
$sql = $default->db;
// you're a guest user if you're in the Anonymous group
$sql->query("SELECT UGL.group_id
FROM $default->owl_users_groups_table AS UGL INNER JOIN $default->owl_groups_table AS GL ON GL.id = UGL.group_id
WHERE GL.name = 'Anonymous'
AND UGL.user_id = $iUserID");
return $sql->next_record();
}
}
?>