ACL.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407
  1. <?php
  2. Lib::loadClass('Core_AclHelper');
  3. class ACL {
  4. public static $REF_TABLE_VERSION = 1;
  5. /**
  6. * Ids List of Proces Init for given tabel (skip filters)
  7. */
  8. public static function getTableProcesInitIds($idTable) {
  9. $procesInitList = self::getTableProcesInitList($idTable);
  10. return array_keys($procesInitList);
  11. }
  12. /**
  13. * List of Proces Init for given table (skip filters)
  14. */
  15. public static function getTableProcesInitList($idTable) {
  16. $tableProcesInitList = array();
  17. $sqlIdProcesListSql = <<<SQL
  18. select tpv.`ID_PROCES`
  19. from `CRM_PROCES_idx_TABLE_TO_PROCES_VIEW` tpv
  20. where tpv.`ID_TABLE`='{$idTable}'
  21. SQL;
  22. $fetchTableProcesInitListSql = <<<SQL
  23. -- time ~0.07 -- no goto and return
  24. select p.`ID`, p.`DESC`
  25. from `CRM_PROCES` p
  26. where p.`ID` in(
  27. select i.`idx_PROCES_INIT_ID`
  28. from `CRM_PROCES_idx` i
  29. where i.`ID_PROCES` in({$sqlIdProcesListSql})
  30. )
  31. and p.`TYPE`='PROCES_INIT'
  32. order by p.`SORT_PRIO`
  33. SQL;
  34. /*
  35. SELECT p.`ID` , p.`DESC`
  36. FROM `CRM_PROCES` p
  37. WHERE p.`ID`
  38. IN (
  39. SELECT i.`idx_PROCES_INIT_ID`
  40. FROM `CRM_PROCES_idx` i
  41. WHERE i.`ID_PROCES`
  42. IN (
  43. SELECT tpv.`ID_PROCES`
  44. FROM `CRM_PROCES_idx_TABLE_TO_PROCES_VIEW` tpv
  45. WHERE tpv.`ID_TABLE` = '13051'
  46. )
  47. )
  48. AND p.`TYPE` = 'PROCES_INIT'
  49. order by p.`SORT_PRIO`
  50. */
  51. $fetchTableProcesInitListSql = <<<SQL
  52. -- time ~0.15s
  53. select p.`ID`, p.`DESC`
  54. from `CRM_PROCES` p
  55. where p.`ID` in(
  56. select i.`idx_PROCES_INIT_ID`
  57. from `CRM_PROCES_idx` i
  58. where i.`ID_PROCES` in({$sqlIdProcesListSql})
  59. union
  60. select ig.`idx_PROCES_INIT_ID`
  61. from `CRM_PROCES_idx` i
  62. join `CRM_PROCES_idx` ig on(ig.`ID_PROCES`=i.`idx_PROCES_WITH_GROUPS_ID`)
  63. where i.`ID_PROCES` in({$sqlIdProcesListSql})
  64. )
  65. and p.`TYPE`='PROCES_INIT'
  66. order by p.`SORT_PRIO`
  67. SQL;
  68. $fetchTableProcesInitListSql = <<<SQL
  69. -- time ~0.14
  70. select p.`ID`, p.`DESC`
  71. from `CRM_PROCES` p
  72. where p.`ID` in(
  73. select i.`idx_PROCES_INIT_ID`
  74. from `CRM_PROCES_idx` i
  75. where i.`ID_PROCES` in({$sqlIdProcesListSql})
  76. or i.`ID_PROCES` in(
  77. select ig.`idx_PROCES_WITH_GROUPS_ID`
  78. from `CRM_PROCES_idx` ig
  79. where ig.`ID_PROCES` in({$sqlIdProcesListSql})
  80. )
  81. )
  82. and p.`TYPE`='PROCES_INIT'
  83. order by p.`SORT_PRIO`
  84. SQL;
  85. //echo'<pre>$fetchTableProcesInitListSql('.$idTable.') ';print_r($fetchTableProcesInitListSql);echo'</pre>';
  86. $tableProcesInitList = array();
  87. $db = DB::getDB();
  88. $res = $db->query($fetchTableProcesInitListSql);
  89. while ($r = $db->fetch($res)) {
  90. $tableProcesInitList[$r->ID] = $r->DESC;
  91. }
  92. return $tableProcesInitList;
  93. }
  94. public static function getProcesInitMapTreeOnlyIds($ids) {
  95. $mapTree = array();
  96. $map = self::getProcesInitMapOnlyIds($ids);
  97. foreach ($map as $r) {
  98. if ('PROCES_INIT' == $r->TYPE) {
  99. $mapTree[$r->ID_PROCES] = array();
  100. }
  101. }
  102. foreach ($map as $r) {
  103. if ('GOTO_AND_RETURN' == $r->TYPE) {
  104. $mapTree[$r->idx_MAIN_PROCES_INIT_ID][$r->ID_PROCES] = array();
  105. }
  106. }
  107. foreach ($map as $r) {
  108. if ('GOTO_AND_RETURN_LVL2' == $r->TYPE) {
  109. $mapTree[$r->idx_MAIN_PROCES_INIT_ID][$r->idx_GOTO_LVL2_INIT_ID][$r->ID_PROCES] = true;
  110. }
  111. }
  112. return $mapTree;
  113. }
  114. public static function getProcesInitMapOnlyIds($ids) {
  115. $map = array();
  116. $sqlIds = V::filter($ids, array('V', 'filterPositiveInteger'));
  117. $sqlIds = implode(',', $sqlIds);
  118. if (empty($sqlIds)) return $map;
  119. $sql = <<<SQL
  120. select i.`ID_PROCES`
  121. , i.`PARENT_ID`
  122. , i.`TYPE`
  123. , i.`idx_PROCES_INIT_ID`
  124. , i.`idx_MAIN_PROCES_INIT_ID`
  125. , i.`idx_PROCES_WITH_GROUPS_ID`
  126. , IF(i.`TYPE`='GOTO_AND_RETURN_LVL2'
  127. , (select ig.`idx_PROCES_INIT_ID`
  128. from `CRM_PROCES_idx` ig
  129. where ig.`ID_PROCES`=i.`PARENT_ID`
  130. limit 1)
  131. , 0
  132. ) as idx_GOTO_LVL2_INIT_ID
  133. from `CRM_PROCES_idx` i
  134. where i.`ID_PROCES` in({$sqlIds})
  135. and i.`idx_MAIN_PROCES_INIT_ID` in({$sqlIds})
  136. SQL;
  137. DBG::_('DBG_MAP', '1', "MAP SQL", $sql, __CLASS__, __FUNCTION__, __LINE__);
  138. $db = DB::getDB();
  139. $res = $db->query($sql);
  140. while ($r = $db->fetch($res)) {
  141. $map[] = $r;
  142. }
  143. //DBG::table("MAP", $map, __CLASS__, __FUNCTION__, __LINE__);
  144. return $map;
  145. }
  146. public static function canGroupViewProces($idGroup, $idProcesInit) {
  147. $isAllowed = false;
  148. $idProcesInit = (int)$idProcesInit;
  149. if (!$idProcesInit) return false;
  150. $checkProcesAccessSql = <<<SQL
  151. select count(*) as cnt
  152. from `CRM_PROCES_idx_GROUP_to_INIT_VIEW` giv
  153. where giv.`ID_GROUP` = '{$idGroup}'
  154. and giv.`ID_PROCES_INIT` = '{$idProcesInit}'
  155. SQL;
  156. $db = DB::getDB();
  157. $res = $db->query($checkProcesAccessSql);
  158. if ($r = $db->fetch($res)) {
  159. if ($r->cnt > 0) {
  160. $isAllowed = true;
  161. }
  162. }
  163. return $isAllowed;
  164. }
  165. public static function getStorageByNamespace($namespace, $forceTblAclInit = false) {
  166. Lib::loadClass('Core_AclHelper');
  167. Lib::loadClass('SchemaFactory');
  168. $ns = Core_AclHelper::parseNamespaceUrl($namespace);
  169. DBG::log($ns, 'array', "parseNamespaceUrl({$namespace})");
  170. if ('default_db' == $ns['prefix']) {
  171. $acl = User::getAcl()->getObjectAcl($ns['prefix'], $ns['name']);
  172. } else if ('objects' == $ns['prefix']) {
  173. $acl = SchemaFactory::loadDefaultObject($ns['name']);
  174. } else if ('default_objects' == $ns['prefix']) {
  175. $acl = SchemaFactory::loadDefaultObject($ns['name']);
  176. } else if ('default_db__x3A__' == substr($ns['prefix'], 0, 17)) {
  177. $rootTableName = strtolower(substr($ns['prefix'], 17));
  178. $acl = SchemaFactory::loadTableObject($rootTableName, $ns['name']);
  179. } else {
  180. throw new HttpException("Not Implemented", 501);
  181. }
  182. $acl->init($forceTblAclInit);
  183. return $acl;
  184. }
  185. public static function getAclByNamespace($namespace, $forceTblAclInit = false) {
  186. return Core_AclHelper::getAclByNamespace($namespace, $forceTblAclInit);
  187. }
  188. public static function parseNamespaceUrl($namespace) {// returns assoc array: [ 'name', 'url', 'prefix', 'sourceName' ]
  189. return Core_AclHelper::parseNamespaceUrl($namespace);
  190. }
  191. public static function getRefTable($rootObjectNamespace, $childName) { // CRM_REF_CONFIG
  192. static $cacheRefTables = array();
  193. $cacheKey = "{$rootObjectNamespace}/{$childName}";
  194. if (array_key_exists($cacheKey, $cacheRefTables)) return $cacheRefTables[$cacheKey];
  195. $rootAcl = self::getAclByNamespace($rootObjectNamespace);
  196. $childXsdType = $rootAcl->getXsdFieldType($childName);
  197. if ('ref_uri:' !== substr($childXsdType, 0, 8)) throw new Exception("Expected ref type for field '{$childName}' in object '{$rootObjectNamespace}'");
  198. $childNamespace = substr($childXsdType, 8);
  199. $childAcl = self::getAclByNamespace($childNamespace);
  200. $refInfo = [];// define $refInfo = [ ID, A_STATUS, VERSION ]
  201. try {// check that ref config table exists
  202. $sqlRootTableNs = DB::getPDO()->quote($rootObjectNamespace, PDO::PARAM_STR);
  203. $sqlChildName = DB::getPDO()->quote($childName, PDO::PARAM_STR);
  204. $sqlChildNamespace = DB::getPDO()->quote($childNamespace, PDO::PARAM_STR);
  205. $refInfo = DB::getPDO()->fetchFirst("
  206. select c.ID, c.A_STATUS, c.VERSION
  207. from `CRM_REF_CONFIG` c
  208. where c.ROOT_OBJECT_NS = {$sqlRootTableNs}
  209. and c.CHILD_NAME = {$sqlChildName}
  210. and c.CHILD_NS = {$sqlChildNamespace}
  211. ");
  212. } catch (Exception $e) {
  213. DB::getPDO()->exec("
  214. CREATE TABLE `CRM_REF_CONFIG` (
  215. `ID` INT NOT NULL AUTO_INCREMENT
  216. , `ROOT_OBJECT_NS` VARCHAR(255) NOT NULL
  217. , `CHILD_NAME` VARCHAR(255) NOT NULL
  218. , `CHILD_NS` VARCHAR(255) NOT NULL
  219. , `A_STATUS` enum('WAITING', 'NORMAL', 'DELETED') NOT NULL DEFAULT 'WAITING'
  220. , `VERSION` int(11) NOT NULL DEFAULT 0
  221. , `A_LAST_ACTION_DATE` timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
  222. , PRIMARY KEY (`ID`)
  223. ) ENGINE = MyISAM DEFAULT CHARSET=latin2;
  224. ");
  225. }
  226. if (empty($refInfo)) {
  227. $refInfo = [ 'ID' => 0, 'A_STATUS' => 'WAITING', 'VERSION' => 0 ];
  228. $refInfo['ID'] = DB::getPDO()->insert("CRM_REF_CONFIG", [
  229. 'ROOT_OBJECT_NS' => $rootObjectNamespace,
  230. 'CHILD_NAME' => $childName,
  231. 'CHILD_NS' => $childNamespace
  232. ]);
  233. }
  234. if (!$refInfo['ID']) throw new Exception("Ref table not found in ref config table for field '{$childName}' in object '{$rootObjectNamespace}'");
  235. $refTableName = "CRM__#REF_TABLE__{$refInfo['ID']}";
  236. if ('WAITING' == $refInfo['A_STATUS']) {
  237. DB::getPDO()->exec("
  238. CREATE TABLE IF NOT EXISTS `{$refTableName}` (
  239. `PRIMARY_KEY` int(11) NOT NULL
  240. , `REMOTE_PRIMARY_KEY` int(11) NOT NULL
  241. , `REMOTE_TYPENAME` varchar(255) NOT NULL DEFAULT ''
  242. , `A_STATUS` enum('WAITING', 'NORMAL', 'DELETED') NOT NULL DEFAULT 'WAITING'
  243. , `TRANACTION_ID` int(11) NOT NULL
  244. , `A_LAST_ACTION_DATE` timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
  245. , KEY `PRIMARY_KEY` (`PRIMARY_KEY`)
  246. , KEY `REMOTE_PRIMARY_KEY` (`REMOTE_PRIMARY_KEY`)
  247. ) ENGINE=MyISAM DEFAULT CHARSET=latin2 COMMENT='{$rootObjectNamespace} #REF $childName ({$childNamespace})';
  248. ");
  249. $refInfo['A_STATUS'] = "NORMAL";
  250. $refInfo['VERSION'] = self::$REF_TABLE_VERSION;
  251. $affected = DB::getPDO()->update("CRM_REF_CONFIG", 'ID', $refInfo['ID'], [
  252. 'A_STATUS' => $refInfo['A_STATUS'],
  253. 'VERSION' => $refInfo['VERSION']
  254. ]);
  255. }
  256. if ($refInfo['VERSION'] < self::$REF_TABLE_VERSION) throw new Exception("TODO: ref table {$refInfo['ID']} require upgrade - field '{$childName}' in object '{$rootObjectNamespace}'");
  257. $cacheRefTables[$cacheKey] = $refTableName;
  258. return $refTableName;
  259. }
  260. public static function getInstanceId($namespace) { // CRM_INSTANCE_CONFIG
  261. $conf = self::getInstanceConfig($namespace);
  262. return $conf['id'];
  263. }
  264. public static function getInstanceConfig($namespace) { // CRM_INSTANCE_CONFIG
  265. try {
  266. $conf = self::fetchInstanceConfig($namespace);
  267. } catch (Exception $e) {
  268. DB::getPDO()->execSql("
  269. create table if not exists `CRM_INSTANCE_CONFIG` (
  270. `id` int(11) not null AUTO_INCREMENT,
  271. `namespace` varchar(255) NOT NULL DEFAULT '',
  272. `rootNamespace` varchar(255) NOT NULL DEFAULT '',
  273. `idInstanceBase` int(11) NOT NULL DEFAULT 0,
  274. `_createdAt` datetime NOT NULL,
  275. UNIQUE KEY `namespace` (`namespace`),
  276. KEY `rootNamespace` (`rootNamespace`),
  277. PRIMARY KEY (`id`)
  278. ) ENGINE=MyISAM DEFAULT CHARSET=latin2
  279. ");
  280. // TODO:?: `_tableInstalled` tinyint(1) not null default 0,
  281. $conf = self::fetchInstanceConfig($namespace);
  282. }
  283. if (!$conf) {
  284. $id = DB::getPDO()->insert("CRM_INSTANCE_CONFIG", [
  285. 'namespace' => $namespace,
  286. 'rootNamespace' => self::getRootNamespace($namespace),
  287. '_createdAt' => 'NOW()',
  288. ]);
  289. $conf = self::fetchInstanceConfig($namespace);
  290. }
  291. if (!$conf) throw new Exception("Instance not found in config table '{$namespace}'");
  292. return $conf;
  293. }
  294. public static function fetchInstanceConfig($namespace) {
  295. return DB::getPDO()->fetchFirst("
  296. select c.*
  297. from `CRM_INSTANCE_CONFIG` c
  298. where c.namespace = '{$namespace}'
  299. ");
  300. }
  301. public static function getRootNamespace($namespace) { // TODO: works only for relative urls! - mv to Acl->getRootNamespace
  302. Lib::loadClass('SchemaFactory');
  303. try {
  304. $objectItem = SchemaFactory::loadDefaultObject('SystemObject')->getItem($namespace);
  305. } catch (Exception $e) {
  306. throw new Exception("Object not installed '{$namespace}'");
  307. }
  308. if (!$objectItem['isStructInstalled']) throw new Exception("Object structure not installed '{$namespace}'");
  309. if ($objectItem['idDatabase'] != DB::getPDO()->getZasobId()) throw new Exception("Only default_db supported"); // TODO: support more Sources
  310. return "default_db/{$objectItem['_rootTableName']}";
  311. }
  312. public static function getNamespaceSiblings($namespace) {
  313. return array_map(function ($row) {
  314. return $row['namespace'];
  315. }, DB::getPDO()->fetchAll("
  316. select s.namespace
  317. from CRM_INSTANCE_CONFIG c
  318. join CRM_INSTANCE_CONFIG s on ( s.rootNamespace = c.rootNamespace and s.namespace != c.rootNamespace )
  319. where c.namespace = :namespace
  320. ", [
  321. 'namespace' => $namespace
  322. ]));
  323. }
  324. public static function getFeatureNamespaces($namespace, $pk) {
  325. $instanceTable = self::getInstanceTable($namespace);
  326. return array_map(function ($row) {
  327. return $row['namespace'];
  328. }, DB::getPDO()->fetchAll("
  329. select c.namespace
  330. from `{$instanceTable}` i
  331. join `CRM_INSTANCE_CONFIG` c on ( c.id = i.idInstance )
  332. where i.pk = :pk
  333. ", [
  334. 'pk' => $pk,
  335. ]));
  336. }
  337. public static function getInstanceTable($namespace) {
  338. $conf = self::getInstanceConfig($namespace);
  339. if (!empty($conf['idInstanceBase'])) return "CRM__#INSTANCE_TABLE__{$conf['idInstanceBase']}";
  340. $rootNs = $conf['rootNamespace'];
  341. $rootConf = self::getInstanceConfig($rootNs);
  342. $instanceTableName = "CRM__#INSTANCE_TABLE__{$rootConf['id']}";
  343. if (!empty($rootConf['idInstance'])) {
  344. $affected = DB::getPDO()->update("CRM_INSTANCE_CONFIG", 'rootNamespace', $rootNs, [
  345. 'idInstanceBase' => $rootConf['id']
  346. ]);
  347. return $instanceTableName;
  348. }
  349. // TODO: fetch primaryKeyType - TODO: store primaryKey and primaryKeyType in SystemObject item
  350. $pkType = 'int';
  351. DB::getPDO()->exec("
  352. CREATE TABLE IF NOT EXISTS `{$instanceTableName}` (
  353. `pk` int(11) NOT NULL COMMENT 'primary key'
  354. , `idInstance` int(11) NOT NULL
  355. , `_createdAt` datetime NOT NULL
  356. , KEY `pk` (`pk`)
  357. , KEY `idInstance` (`idInstance`)
  358. ) ENGINE=MyISAM DEFAULT CHARSET=latin2 COMMENT='{$rootNs} #INSTANCE';
  359. ");
  360. $affected = DB::getPDO()->update("CRM_INSTANCE_CONFIG", 'rootNamespace', $rootNs, [
  361. 'idInstanceBase' => $rootConf['id']
  362. ]);
  363. return $instanceTableName;
  364. }
  365. // @params $from - ( ACL | tableName | namespace | etc... - only ACL)
  366. public static function query($from) {
  367. Lib::loadClass('AclQueryBuilder');
  368. $query = new AclQueryBuilder();
  369. $query->from($from);
  370. return $query;
  371. }
  372. /**
  373. * @param mixed $object - Core_AclBase or string - namespace
  374. * @return Core_AclFields
  375. */
  376. public static function getObjectFields($object) {
  377. // TODO: try to get structure from `CRM_#CACHE_ACL_OBJECT_FIELD`
  378. // if ($object is instance Core_AclBase) {
  379. // if ($object->isStructInstalled) then get structure from `CRM_#CACHE_ACL_OBJECT_FIELD` and put into Core_AclFields
  380. // else get from $object->getFields() and put into Core_AclFields
  381. }
  382. }