2007-07-19 10:40:05 +00:00
|
|
|
<?php
|
2008-02-25 02:10:37 +00:00
|
|
|
/**
|
|
|
|
* Security section of the CMS
|
|
|
|
* @package cms
|
|
|
|
* @subpackage security
|
|
|
|
*/
|
2007-08-31 00:31:49 +00:00
|
|
|
class SecurityAdmin extends LeftAndMain implements PermissionProvider {
|
2008-10-07 23:27:07 +00:00
|
|
|
|
2008-11-02 21:27:55 +00:00
|
|
|
static $url_segment = 'security';
|
|
|
|
|
|
|
|
static $url_rule = '/$Action/$ID/$OtherID';
|
|
|
|
|
|
|
|
static $menu_title = 'Security';
|
|
|
|
|
2008-10-07 23:27:07 +00:00
|
|
|
static $tree_class = 'Group';
|
|
|
|
|
|
|
|
static $subitem_class = 'Member';
|
2008-02-25 02:10:37 +00:00
|
|
|
|
|
|
|
static $allowed_actions = array(
|
|
|
|
'addmember',
|
|
|
|
'autocomplete',
|
|
|
|
'removememberfromgroup',
|
|
|
|
'savemember',
|
2008-08-09 03:54:55 +00:00
|
|
|
'AddRecordForm',
|
2009-02-03 03:46:15 +00:00
|
|
|
'MemberForm',
|
2009-11-21 03:16:38 +00:00
|
|
|
'EditForm',
|
2008-02-25 02:10:37 +00:00
|
|
|
);
|
2007-07-19 10:40:05 +00:00
|
|
|
|
2009-11-21 05:24:43 +00:00
|
|
|
/**
|
|
|
|
* @var Array
|
|
|
|
*/
|
|
|
|
static $hidden_permissions = array();
|
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
public function init() {
|
|
|
|
parent::init();
|
|
|
|
|
2009-11-21 03:20:17 +00:00
|
|
|
Requirements::javascript(CMS_DIR . '/javascript/SecurityAdmin.js');
|
|
|
|
Requirements::javascript(CMS_DIR . '/javascript/SecurityAdmin.Tree.js');
|
|
|
|
|
|
|
|
CMSBatchActionHandler::register('delete', 'SecurityAdmin_DeleteBatchAction', 'Group');
|
|
|
|
}
|
|
|
|
|
|
|
|
function getEditForm($id = null) {
|
|
|
|
$form = parent::getEditForm($id);
|
|
|
|
$form->Actions()->insertBefore(
|
|
|
|
new FormAction('addmember',_t('SecurityAdmin.ADDMEMBER','Add Member')),
|
|
|
|
'action_save'
|
|
|
|
);
|
2009-04-29 01:44:28 +00:00
|
|
|
|
2009-11-21 05:24:43 +00:00
|
|
|
// Filter permissions
|
|
|
|
$permissionField = $form->Fields()->dataFieldByName('Permissions');
|
|
|
|
if($permissionField) $permissionField->setHiddenPermissions(self::$hidden_permissions);
|
|
|
|
|
2009-11-21 03:20:17 +00:00
|
|
|
return $form;
|
2007-07-19 10:40:05 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
public function AddRecordForm() {
|
2008-08-10 21:41:10 +00:00
|
|
|
$m = Object::create('MemberTableField',
|
2007-07-19 10:40:05 +00:00
|
|
|
$this,
|
2007-09-14 19:40:56 +00:00
|
|
|
"Members",
|
2007-07-19 10:40:05 +00:00
|
|
|
$this->currentPageID()
|
|
|
|
);
|
|
|
|
return $m->AddRecordForm();
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Ajax autocompletion
|
|
|
|
*/
|
|
|
|
public function autocomplete() {
|
|
|
|
$fieldName = $this->urlParams['ID'];
|
|
|
|
$fieldVal = $_REQUEST[$fieldName];
|
2008-02-25 02:10:37 +00:00
|
|
|
$result = '';
|
2009-07-17 02:23:57 +00:00
|
|
|
|
2008-12-04 22:38:58 +00:00
|
|
|
// Make sure we only autocomplete on keys that actually exist, and that we don't autocomplete on password
|
2009-07-17 02:23:57 +00:00
|
|
|
if(!singleton($this->stat('subitem_class'))->hasDatabaseField($fieldName) || $fieldName == 'Password') return;
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2008-12-04 22:38:58 +00:00
|
|
|
$matches = DataObject::get($this->stat('subitem_class'),"\"$fieldName\" LIKE '" . Convert::raw2sql($fieldVal) . "%'");
|
2007-07-19 10:40:05 +00:00
|
|
|
if($matches) {
|
|
|
|
$result .= "<ul>";
|
|
|
|
foreach($matches as $match) {
|
2009-02-03 23:34:14 +00:00
|
|
|
if(!$match->canView()) continue;
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
$data = $match->FirstName;
|
|
|
|
$data .= ",$match->Surname";
|
|
|
|
$data .= ",$match->Email";
|
|
|
|
$result .= "<li>" . $match->$fieldName . "<span class=\"informal\">($match->FirstName $match->Surname, $match->Email)</span><span class=\"informal data\">$data</span></li>";
|
|
|
|
}
|
|
|
|
$result .= "</ul>";
|
|
|
|
return $result;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public function MemberForm() {
|
|
|
|
$id = $_REQUEST['ID'] ? $_REQUEST['ID'] : Session::get('currentMember');
|
2009-02-03 02:50:25 +00:00
|
|
|
if($id) return $this->getMemberForm($id);
|
2007-07-19 10:40:05 +00:00
|
|
|
}
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
public function getMemberForm($id) {
|
2009-02-03 02:50:25 +00:00
|
|
|
if($id && $id != 'new') $record = DataObject::get_by_id('Member', (int) $id);
|
2007-07-19 10:40:05 +00:00
|
|
|
if($record || $id == 'new') {
|
|
|
|
$fields = new FieldSet(
|
|
|
|
new HiddenField('MemberListBaseGroup', '', $this->currentPageID() )
|
|
|
|
);
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2009-02-03 02:50:25 +00:00
|
|
|
if($extraFields = $record->getCMSFields()) {
|
|
|
|
foreach($extraFields as $extra) {
|
2007-07-19 10:40:05 +00:00
|
|
|
$fields->push( $extra );
|
2009-02-03 02:50:25 +00:00
|
|
|
}
|
|
|
|
}
|
2007-07-19 10:40:05 +00:00
|
|
|
|
2009-02-03 02:50:25 +00:00
|
|
|
$fields->push($idField = new HiddenField('ID'));
|
|
|
|
$fields->push($groupIDField = new HiddenField('GroupID'));
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
$actions = new FieldSet();
|
2009-02-03 02:50:25 +00:00
|
|
|
$actions->push(new FormAction('savemember', _t('SecurityAdmin.SAVE')));
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2009-02-03 02:50:25 +00:00
|
|
|
$form = new Form($this, 'MemberForm', $fields, $actions);
|
2007-07-19 10:40:05 +00:00
|
|
|
if($record) $form->loadDataFrom($record);
|
|
|
|
|
|
|
|
$idField->setValue($id);
|
|
|
|
$groupIDField->setValue($this->currentPageID());
|
2009-02-03 23:34:14 +00:00
|
|
|
|
|
|
|
if($record && !$record->canEdit()) {
|
|
|
|
$readonlyFields = $form->Fields()->makeReadonly();
|
|
|
|
$form->setFields($readonlyFields);
|
|
|
|
}
|
2007-07-19 10:40:05 +00:00
|
|
|
|
|
|
|
return $form;
|
|
|
|
}
|
|
|
|
}
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
function savemember() {
|
|
|
|
$data = $_REQUEST;
|
|
|
|
$className = $this->stat('subitem_class');
|
|
|
|
|
|
|
|
$id = $_REQUEST['ID'];
|
|
|
|
if($id == 'new') $id = null;
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
if($id) {
|
2009-03-17 22:20:03 +00:00
|
|
|
$record = DataObject::get_by_id($className, $id);
|
2009-02-03 23:34:14 +00:00
|
|
|
if($record && !$record->canEdit()) return Security::permissionFailure($this);
|
2007-07-19 10:40:05 +00:00
|
|
|
} else {
|
2009-02-03 23:34:14 +00:00
|
|
|
if(!singleton($this->stat('subitem_class'))->canCreate()) return Security::permissionFailure($this);
|
2007-07-19 10:40:05 +00:00
|
|
|
$record = new $className();
|
|
|
|
}
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
$record->update($data);
|
|
|
|
$record->ID = $id;
|
|
|
|
$record->write();
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
$record->Groups()->add($data['GroupID']);
|
|
|
|
|
|
|
|
FormResponse::add("reloadMemberTableField();");
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
return FormResponse::respond();
|
|
|
|
}
|
|
|
|
|
|
|
|
function addmember($className=null) {
|
|
|
|
$data = $_REQUEST;
|
|
|
|
unset($data['ID']);
|
2009-02-03 02:50:25 +00:00
|
|
|
if($className == null) $className = $this->stat('subitem_class');
|
|
|
|
|
2009-02-03 23:34:14 +00:00
|
|
|
if(!singleton($this->stat('subitem_class'))->canCreate()) return Security::permissionFailure($this);
|
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
$record = new $className();
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
$record->update($data);
|
|
|
|
$record->write();
|
2009-02-03 02:50:25 +00:00
|
|
|
|
2009-03-17 22:20:03 +00:00
|
|
|
if($data['GroupID']) $record->Groups()->add((int)$data['GroupID']);
|
2007-07-19 10:40:05 +00:00
|
|
|
|
|
|
|
FormResponse::add("reloadMemberTableField();");
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
return FormResponse::respond();
|
|
|
|
}
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
public function removememberfromgroup() {
|
|
|
|
$groupID = $this->urlParams['ID'];
|
|
|
|
$memberID = $this->urlParams['OtherID'];
|
|
|
|
if(is_numeric($groupID) && is_numeric($memberID)) {
|
2009-02-03 02:50:25 +00:00
|
|
|
$member = DataObject::get_by_id('Member', (int) $memberID);
|
2009-04-29 01:44:28 +00:00
|
|
|
|
2009-02-03 23:34:14 +00:00
|
|
|
if(!$member->canDelete()) return Security::permissionFailure($this);
|
2009-04-29 01:44:28 +00:00
|
|
|
|
2009-03-17 22:20:03 +00:00
|
|
|
$member->Groups()->remove((int)$groupID);
|
2009-04-29 01:44:28 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
FormResponse::add("reloadMemberTableField();");
|
|
|
|
} else {
|
|
|
|
user_error("SecurityAdmin::removememberfromgroup: Bad parameters: Group=$groupID, Member=$memberID", E_USER_ERROR);
|
|
|
|
}
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
return FormResponse::respond();
|
|
|
|
}
|
2009-11-21 03:16:38 +00:00
|
|
|
|
2009-11-21 03:21:03 +00:00
|
|
|
function getSiteTreeFor($className, $rootID = null, $childrenMethod = null, $filterFunction = null, $minNodeCount = 30) {
|
|
|
|
if (!$childrenMethod) $childrenMethod = 'stageChildren';
|
|
|
|
return parent::getSiteTreeFor($className, $rootID, $childrenMethod, $filterFunction, $minNodeCount);
|
|
|
|
}
|
|
|
|
|
2009-11-21 03:21:00 +00:00
|
|
|
function getCMSTreeTitle() {
|
|
|
|
return _t('SecurityAdmin.SGROUPS', 'Security Groups');
|
2007-07-19 10:40:05 +00:00
|
|
|
}
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-07-19 10:40:05 +00:00
|
|
|
public function EditedMember() {
|
2009-02-03 02:50:25 +00:00
|
|
|
if(Session::get('currentMember')) return DataObject::get_by_id('Member', (int) Session::get('currentMember'));
|
2007-07-19 10:40:05 +00:00
|
|
|
}
|
2007-09-14 19:40:56 +00:00
|
|
|
|
2007-08-31 00:31:49 +00:00
|
|
|
function providePermissions() {
|
|
|
|
return array(
|
2009-10-29 00:55:20 +00:00
|
|
|
'EDIT_PERMISSIONS' => array(
|
|
|
|
'name' => _t('SecurityAdmin.EDITPERMISSIONS', 'Manage permissions for groups'),
|
2009-10-30 01:43:34 +00:00
|
|
|
'category' => _t('Permissions.PERMISSIONS_CATEGORY', 'Roles and access permissions'),
|
|
|
|
'help' => _t('SecurityAdmin.EDITPERMISSIONS_HELP', 'Ability to edit Permissions and IP Addresses for a group. Requires "Access to Security".'),
|
2009-10-29 00:55:20 +00:00
|
|
|
'sort' => 0
|
2009-10-29 21:36:13 +00:00
|
|
|
),
|
|
|
|
'APPLY_ROLES' => array(
|
|
|
|
'name' => _t('SecurityAdmin.APPLY_ROLES', 'Apply roles to groups'),
|
2009-10-30 01:43:34 +00:00
|
|
|
'category' => _t('Permissions.PERMISSIONS_CATEGORY', 'Roles and access permissions'),
|
|
|
|
'help' => _t('SecurityAdmin.APPLY_ROLES_HELP', 'Ability to edit the roles assigned to a group. Requires "Access to Security.".'),
|
2009-10-29 21:36:13 +00:00
|
|
|
'sort' => 0
|
2009-10-29 00:55:20 +00:00
|
|
|
)
|
2007-08-31 00:31:49 +00:00
|
|
|
);
|
|
|
|
}
|
2009-11-21 02:01:21 +00:00
|
|
|
|
|
|
|
/**
|
2009-11-21 05:24:43 +00:00
|
|
|
* The permissions represented in the $codes will not appearing in the form
|
|
|
|
* containing {@link PermissionCheckboxSetField} so as not to be checked / unchecked.
|
|
|
|
*
|
|
|
|
* @param $codes String|Array
|
2009-11-21 02:01:21 +00:00
|
|
|
*/
|
2009-11-21 05:24:43 +00:00
|
|
|
static function add_hidden_permission($codes){
|
|
|
|
if(is_string($codes)) $codes = array($codes);
|
2009-12-16 05:54:23 +00:00
|
|
|
self::$hidden_permissions = array_merge(self::$hidden_permissions, $codes);
|
2009-11-21 05:24:43 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @param $codes String|Array
|
|
|
|
*/
|
|
|
|
static function remove_hidden_permission($codes){
|
|
|
|
if(is_string($codes)) $codes = array($codes);
|
|
|
|
self::$hidden_permissions = array_diff(self::$hidden_permissions, $codes);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @return Array
|
|
|
|
*/
|
|
|
|
static function get_hidden_permissions(){
|
|
|
|
return self::$hidden_permissions;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Clear all permissions previously hidden with {@link add_hidden_permission}
|
|
|
|
*/
|
|
|
|
static function clear_hidden_permissions(){
|
|
|
|
self::$hidden_permissions = array();
|
2009-11-21 02:01:21 +00:00
|
|
|
}
|
2007-07-19 10:40:05 +00:00
|
|
|
}
|
|
|
|
|
2009-11-21 03:20:17 +00:00
|
|
|
/**
|
|
|
|
* Delete multiple {@link Group} records. Usually used through the {@link SecurityAdmin} interface.
|
|
|
|
*
|
|
|
|
* @package cms
|
|
|
|
* @subpackage batchactions
|
|
|
|
*/
|
|
|
|
class SecurityAdmin_DeleteBatchAction extends CMSBatchAction {
|
|
|
|
function getActionTitle() {
|
|
|
|
return _t('AssetAdmin_DeleteBatchAction.TITLE', 'Delete groups');
|
|
|
|
}
|
|
|
|
|
|
|
|
function run(DataObjectSet $records) {
|
|
|
|
$status = array(
|
|
|
|
'modified'=>array(),
|
|
|
|
'deleted'=>array()
|
|
|
|
);
|
|
|
|
|
|
|
|
foreach($records as $record) {
|
|
|
|
// TODO Provide better feedback if permission was denied
|
|
|
|
if(!$record->canDelete()) continue;
|
|
|
|
|
|
|
|
$id = $record->ID;
|
|
|
|
$record->delete();
|
|
|
|
$status['deleted'][$id] = array();
|
|
|
|
$record->destroy();
|
|
|
|
unset($record);
|
|
|
|
}
|
|
|
|
|
|
|
|
return Convert::raw2json($status);
|
|
|
|
}
|
|
|
|
}
|
2009-02-03 03:46:15 +00:00
|
|
|
?>
|