AccessGroupStorageAcl.php 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158
  1. <?php
  2. Lib::loadClass('Core_AclBase');
  3. Lib::loadClass('User');
  4. Lib::loadClass('UsersHelper');
  5. Lib::loadClass('ParseOgcFilter');
  6. Lib::loadClass('SqlQueryWhereBuilder');
  7. class Schema_AccessGroupStorageAcl extends Core_AclBase {// Read only class
  8. public function getNamespace() { return 'default_objects/' . $this->getName(); }
  9. public function getSourceName() { return 'default_objects'; }
  10. public function init($force = false) {}
  11. public function isInitialized() { return true; }
  12. public function getName() { return 'AccessGroup'; }
  13. public function getRootTableName() { return 'CRM_LISTA_ZASOBOW'; }
  14. public function getFieldListByIdZasob() { return $this->getRealFieldListByIdZasob(); }
  15. public function getVisibleFieldListByIdZasob() { return $this->getRealFieldListByIdZasob(); }
  16. public function getVirtualFieldListByIdZasob() { return array(); }
  17. public function getRealFieldListByIdZasob($force = false) {
  18. $cols[100000] = 'id';// CRM_LISTA_ZASOBOW.ID
  19. $cols[100001] = 'name';// CRM_LISTA_ZASOBOW.DESC
  20. $cols[100002] = 'uid';// Ldap.uid -> value stored in fields: A_ADM_COMPANY, A_CLASSIFIED
  21. return $cols;
  22. }
  23. public function getFields() {
  24. $fields = array();
  25. $fields[100000] = ['name'=>'id', 'perms'=>'R', 'opis'=>'', 'label'=>'', 'sort_prio'=>100];
  26. $fields[100001] = ['name'=>'name', 'perms'=>'R', 'opis'=>'', 'label'=>'', 'sort_prio'=>101];
  27. $fields[100002] = ['name'=>'uid', 'perms'=>'R', 'opis'=>'', 'label'=>'', 'sort_prio'=>102];
  28. return $fields;
  29. }
  30. public function getFieldType($fieldName) { return null; }
  31. // TODO: replace legacy functions: isAllowed, hasFieldPerm, getFieldIdByName
  32. public function canCreateField($fieldName) { return false; }
  33. public function canReadField($fieldName) { return true; }
  34. public function canReadObjectField($fieldName, $record) {return true; }
  35. public function canWriteField($fieldName) { return false; }
  36. public function canWriteObjectField($fieldName, $record) { return false; }
  37. public function getTotal($params = array()) {
  38. return count($this->getItems($params));
  39. }
  40. public function getItem($primaryKey) {
  41. $items = $this->getItems(['primaryKey'=>$primaryKey]);
  42. return (!empty($items[$primaryKey])) ? $items[$primaryKey] : null;
  43. }
  44. public function getItems($params = array()) {
  45. $DBG = V::get('DBG_DS', 0, $_GET, 'int');
  46. if($DBG>2){echo'<pre>';}
  47. if($DBG>2){echo 'C.'.get_class($this).' L.' . __LINE__ . " getItems \$params:";print_r($params);echo "\n";}
  48. $items = array();
  49. // TODO: fetch groups connectes with current user
  50. {
  51. $userLdapGroups = UsersHelper::getLDAPGroupByUserName(User::getLogin());
  52. if($DBG>4){echo 'C.'.get_class($this).' L.' . __LINE__ . " getItems \$userLdapGroups:";print_r($userLdapGroups);echo "\n";}
  53. if (empty($userLdapGroups)) throw new Exception("User groups not found", 404);
  54. foreach ($userLdapGroups as $vLdapGroup) {
  55. $allowGroup = false;
  56. if ('workgroup' == $vLdapGroup->cn) {
  57. $items[0] = ['id'=>'0', 'name'=>$vLdapGroup->name, 'uid'=>$vLdapGroup->cn];
  58. } else {
  59. $cnTest = str_replace('-', '_', $vLdapGroup->cn);
  60. $cnTest = explode('_', $cnTest);
  61. $idZasob = $cnTest[0];
  62. if (!is_numeric($idZasob)) {
  63. if($DBG>2){echo 'C.'.get_class($this).' L.' . __LINE__ . " getItems - skip cn - missing id zasob \$vLdapGroup->cn:";print_r($vLdapGroup->cn);echo "\n";}
  64. continue;
  65. }
  66. $items[$idZasob] = ['id'=>$idZasob, 'name'=>$vLdapGroup->name, 'uid'=>$vLdapGroup->cn];
  67. }
  68. }
  69. }
  70. if ($pk = V::get('primaryKey', '', $params, 'int')) {// [primaryKey] => 2948
  71. if (!array_key_exists($pk, $items)) return array();
  72. $items = array($pk => $items[$pk]);
  73. }
  74. if (!empty($params['ogc:Filter'])) {
  75. $parser = new ParseOgcFilter();
  76. $parser->loadOgcFilter($params['ogc:Filter']);
  77. $queryWhereBuilder = $parser->convertToSqlQueryWhereBuilder();
  78. DBG::_('DBG_DS', '>2', "ogc:Filter \$queryWhereBuilder", $queryWhereBuilder, __CLASS__, __FUNCTION__, __LINE__);
  79. if($DBG>2){echo 'C.'.get_class($this).' L.' . __LINE__ . " getItems \$items:";print_r($items);echo "\n";}
  80. $items = array_filter($items, array($queryWhereBuilder, 'filterRawArray'));
  81. }
  82. $filterId = trim(V::get('f_id', '', $params));
  83. if (strlen($filterId)) {// allow '0'
  84. $queryWhereBuilder = new SqlQueryWhereBuilder();
  85. if (is_numeric($filterId)) {
  86. $queryWhereBuilder->addComparisonFieldToValue('id', '=', $filterId);
  87. } else if (false !== strpos($filterId, '%') && is_numeric(trim($filterId, '%'))) {
  88. $queryWhereBuilder->addComparisonFieldToValue('id', 'like', $filterId);
  89. } else if ('>=' == substr($filterId, 0, 2) && is_numeric(substr($filterId, 2))) {
  90. $queryWhereBuilder->addComparisonFieldToValue('id', 'GreaterThenOrEqualTo', substr($filterId, 2));
  91. } else if ('<=' == substr($filterId, 0, 2) && is_numeric(substr($filterId, 2))) {
  92. $queryWhereBuilder->addComparisonFieldToValue('id', 'LessThenOrEqualTo', substr($filterId, 2));
  93. } else if ('>' == substr($filterId, 0, 1) && is_numeric(substr($filterId, 1))) {
  94. $queryWhereBuilder->addComparisonFieldToValue('id', 'GreaterThen', substr($filterId, 1));
  95. } else if ('<' == substr($filterId, 0, 1) && is_numeric(substr($filterId, 1))) {
  96. $queryWhereBuilder->addComparisonFieldToValue('id', 'LessThen', substr($filterId, 1));
  97. } else if ('=' == substr($filterId, 0, 1) && is_numeric(substr($filterId, 1))) {
  98. $queryWhereBuilder->addComparisonFieldToValue('id', '=', substr($filterId, 1));
  99. } else {
  100. $filterId = null;// TODO: BUG uniimplemented comparison sign
  101. }
  102. if ($filterId) $items = array_filter($items, array($queryWhereBuilder, 'filterRawArray'));
  103. }
  104. foreach (['name', 'uid'] as $fieldName) {
  105. $filterValue = trim(V::get("f_{$fieldName}", '', $params));
  106. if (strlen($filterValue)) {// allow '0'
  107. $queryWhereBuilder = new SqlQueryWhereBuilder();
  108. if (!is_scalar($filterValue)) {
  109. } else if ('=' == substr($filterValue, 0, 1)) {
  110. $queryWhereBuilder->addComparisonFieldToValue($fieldName, '=', substr($filterValue, 1));
  111. } else {
  112. if ('%' != substr($filterValue, 0, 1)) $filterValue = "%{$filterValue}";
  113. if ('%' != substr($filterValue, -1)) $filterValue = "{$filterValue}%";
  114. $queryWhereBuilder->addComparisonFieldToValue($fieldName, 'like', $filterValue);
  115. }
  116. $items = array_filter($items, array($queryWhereBuilder, 'filterRawArray'));
  117. }
  118. }
  119. $orderBy = strtolower(V::get('order_by', 'id', $params));
  120. $orderDir = strtolower(V::get('order_dir', 'desc', $params));
  121. if (!in_array($orderBy, ['id', 'name', 'uid'])) throw new HttpException("Bad Request - wrong or missing order by", 400);
  122. if (!in_array($orderDir, ['desc', 'asc'])) throw new HttpException("Bad Request - wrong or missing order dir", 400);
  123. uasort($items, function ($a, $b) use ($orderBy, $orderDir) {
  124. if ('desc' == $orderDir) {
  125. return (V::geti($orderBy, '', $a) > V::geti($orderBy, '', $b)) ? -1 : 1;
  126. } else if ('asc' == $orderDir) {
  127. return (V::geti($orderBy, '', $a) > V::geti($orderBy, '', $b)) ? 1 : -1;
  128. }
  129. return 0;
  130. });
  131. if($DBG>2){echo 'C.'.get_class($this).' L.' . __LINE__ . " getItems \$items:";print_r($items);echo "\n";}
  132. return $items;
  133. }
  134. public function addItem($itemTodo) { throw new Exception("Insert not allowed"); }
  135. public function updateItem($itemPatch) { throw new Exception("Update not allowed"); }
  136. public function getGeomFieldType($fieldName) { return null; }
  137. public function getPrimaryKeyField() { return 'id'; }
  138. public function getID() { return 0; }
  139. public function getAttributesFromZasoby() { return array(); }
  140. public function isEnumerationField($fieldName) { return false; }
  141. public function getEnumerations($fieldName) { return null; }
  142. public function getXsdFieldType($fieldName) {
  143. if ('id' == $fieldName) return 'xsd:string';
  144. if ('name' == $fieldName) return 'xsd:string';
  145. if ('uid' == $fieldName) return 'xsd:string';
  146. }
  147. public function isGeomField($fldName) { return false; }
  148. }