2009-10-15 22:27:56 +00:00
|
|
|
<?php
|
|
|
|
/**
|
|
|
|
* A PermissionRoleCode represents a single permission code assigned to a {@link PermissionRole}.
|
2010-04-23 01:04:16 +00:00
|
|
|
*
|
2012-04-12 18:02:46 +12:00
|
|
|
* @package framework
|
2010-04-23 01:04:16 +00:00
|
|
|
* @subpackage security
|
2009-10-15 22:27:56 +00:00
|
|
|
*/
|
|
|
|
class PermissionRoleCode extends DataObject {
|
2013-03-21 19:48:54 +01:00
|
|
|
private static $db = array(
|
2009-10-15 22:27:56 +00:00
|
|
|
"Code" => "Varchar",
|
|
|
|
);
|
|
|
|
|
2013-03-21 19:48:54 +01:00
|
|
|
private static $has_one = array(
|
2009-10-15 22:27:56 +00:00
|
|
|
"Role" => "PermissionRole",
|
|
|
|
);
|
2013-08-30 13:59:38 +02:00
|
|
|
|
|
|
|
protected function validate() {
|
|
|
|
$result = parent::validate();
|
|
|
|
|
|
|
|
// Check that new code doesn't increase privileges, unless an admin is editing.
|
|
|
|
$privilegedCodes = Config::inst()->get('Permission', 'privileged_permissions');
|
|
|
|
if(
|
|
|
|
$this->Code
|
|
|
|
&& in_array($this->Code, $privilegedCodes)
|
|
|
|
&& !Permission::check('ADMIN')
|
|
|
|
) {
|
|
|
|
$result->error(sprintf(
|
|
|
|
_t(
|
|
|
|
'PermissionRoleCode.PermsError',
|
|
|
|
'Can\'t assign code "%s" with privileged permissions (requires ADMIN access)'
|
|
|
|
),
|
|
|
|
$this->Code
|
|
|
|
));
|
|
|
|
}
|
|
|
|
|
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
|
|
|
|
public function canCreate($member = null) {
|
|
|
|
return Permission::check('APPLY_ROLES', 'any', $member);
|
|
|
|
}
|
|
|
|
|
|
|
|
public function canEdit($member = null) {
|
|
|
|
return Permission::check('APPLY_ROLES', 'any', $member);
|
|
|
|
}
|
|
|
|
|
|
|
|
public function canDelete($member = null) {
|
|
|
|
return Permission::check('APPLY_ROLES', 'any', $member);
|
|
|
|
}
|
2012-03-24 16:04:52 +13:00
|
|
|
}
|