2017-02-08 00:43:00 +00:00
|
|
|
<?php
|
|
|
|
|
2022-02-16 04:08:28 +00:00
|
|
|
namespace Code\Lib;
|
2017-02-08 00:43:00 +00:00
|
|
|
|
2022-02-16 04:08:28 +00:00
|
|
|
use Code\Access\PermissionRoles;
|
|
|
|
use Code\Access\Permissions;
|
|
|
|
use Code\Lib\Channel;
|
|
|
|
use Code\Extend\Hook;
|
2017-12-23 13:42:23 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @brief Permission Categories. Permission rules for various classes of connections.
|
|
|
|
*
|
|
|
|
* Connection permissions answer the question "Can Joe view my photos?"
|
|
|
|
*
|
|
|
|
* Some permissions may be inherited from the channel's "privacy settings"
|
2022-02-16 04:08:28 +00:00
|
|
|
* (@ref ::Code::Access::PermissionLimits "PermissionLimits") "Who can view my
|
2017-12-23 13:42:23 +00:00
|
|
|
* photos (at all)?" which have higher priority than individual connection settings.
|
|
|
|
* We evaluate permission limits first, and then fall through to connection
|
|
|
|
* permissions if the permission limits didn't already make a definitive decision.
|
|
|
|
*
|
|
|
|
* After PermissionLimits and connection permissions are evaluated, individual
|
2022-02-16 04:08:28 +00:00
|
|
|
* content ACLs are evaluated (@ref ::Code::Access::AccessList "AccessList").
|
2017-12-23 13:42:23 +00:00
|
|
|
* These answer the question "Can Joe view *this* album/photo?".
|
|
|
|
*/
|
2019-05-07 05:22:58 +00:00
|
|
|
|
2021-12-03 03:01:39 +00:00
|
|
|
class Permcat
|
|
|
|
{
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @var array
|
|
|
|
*/
|
|
|
|
private $permcats = [];
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @brief Permcat constructor.
|
|
|
|
*
|
|
|
|
* @param int $channel_id
|
|
|
|
*/
|
2022-02-05 22:07:10 +00:00
|
|
|
public function __construct($channel_id, $abook_id = 0)
|
2021-12-03 03:01:39 +00:00
|
|
|
{
|
|
|
|
|
|
|
|
$perms = [];
|
|
|
|
|
|
|
|
// first check role perms for a perms_connect setting
|
|
|
|
|
|
|
|
$role = get_pconfig($channel_id, 'system', 'permissions_role');
|
|
|
|
if ($role) {
|
|
|
|
$x = PermissionRoles::role_perms($role);
|
|
|
|
if ($x['perms_connect']) {
|
|
|
|
$perms = Permissions::FilledPerms($x['perms_connect']);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// if no role perms it may be a custom role, see if there any autoperms
|
|
|
|
|
|
|
|
if (! $perms) {
|
2022-01-22 10:04:36 +00:00
|
|
|
$perms = Permissions::FilledAutoperms($channel_id);
|
2021-12-03 03:01:39 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// if no autoperms it may be a custom role with manual perms
|
|
|
|
|
|
|
|
if (! $perms) {
|
2022-01-25 01:26:12 +00:00
|
|
|
$c = Channel::from_id($channel_id);
|
2021-12-03 03:01:39 +00:00
|
|
|
if ($c) {
|
2022-01-22 10:04:36 +00:00
|
|
|
$perms = Permissions::FilledPerms(explode(',',get_abconfig($channel_id, $c['channel_hash'], 'system', 'my_perms', EMPTY_STR)));
|
2021-12-03 03:01:39 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// nothing was found - create a filled permission array where all permissions are 0
|
|
|
|
|
|
|
|
if (! $perms) {
|
|
|
|
$perms = Permissions::FilledPerms([]);
|
|
|
|
}
|
|
|
|
|
|
|
|
$this->permcats[] = [
|
|
|
|
'name' => 'default',
|
|
|
|
'localname' => t('default', 'permcat'),
|
|
|
|
'perms' => Permissions::Operms($perms),
|
|
|
|
'system' => 1
|
|
|
|
];
|
|
|
|
|
|
|
|
|
2022-02-05 22:07:10 +00:00
|
|
|
$p = $this->load_permcats($channel_id, $abook_id);
|
2021-12-03 03:01:39 +00:00
|
|
|
if ($p) {
|
|
|
|
for ($x = 0; $x < count($p); $x++) {
|
|
|
|
$this->permcats[] = [
|
|
|
|
'name' => $p[$x][0],
|
|
|
|
'localname' => $p[$x][1],
|
|
|
|
'perms' => Permissions::Operms(Permissions::FilledPerms($p[$x][2])),
|
|
|
|
'system' => intval($p[$x][3])
|
|
|
|
];
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-02-05 22:07:10 +00:00
|
|
|
public function match($current) {
|
|
|
|
if ($current) {
|
|
|
|
$perms = Permissions::FilledPerms($current);
|
|
|
|
$operms = Permissions::Operms($perms);
|
|
|
|
}
|
|
|
|
|
|
|
|
if ($this->permcats && $operms) {
|
|
|
|
foreach($this->permcats as $permcat) {
|
|
|
|
$pp = $permcat['perms'];
|
|
|
|
$matching = 0;
|
|
|
|
foreach ($pp as $rp) {
|
|
|
|
foreach ($operms as $op) {
|
|
|
|
if ($rp['name'] === $op['name'] && intval($rp['value']) === intval($op['value'])) {
|
|
|
|
$matching ++;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if ($matching === count($pp)) {
|
|
|
|
return $permcat['name'];
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return 'custom';
|
|
|
|
}
|
|
|
|
|
2021-12-03 03:01:39 +00:00
|
|
|
/**
|
|
|
|
* @brief Return array with permcats.
|
|
|
|
*
|
|
|
|
* @return array
|
|
|
|
*/
|
|
|
|
public function listing()
|
|
|
|
{
|
|
|
|
return $this->permcats;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @brief
|
|
|
|
*
|
|
|
|
* @param string $name
|
|
|
|
* @return array
|
|
|
|
* * \e array with permcats
|
|
|
|
* * \e bool \b error if $name not found in permcats true
|
|
|
|
*/
|
|
|
|
public function fetch($name)
|
|
|
|
{
|
|
|
|
if ($name && $this->permcats) {
|
|
|
|
foreach ($this->permcats as $permcat) {
|
|
|
|
if (strcasecmp($permcat['name'], $name) === 0) {
|
|
|
|
return $permcat;
|
|
|
|
}
|
|
|
|
}
|
2022-02-05 22:07:10 +00:00
|
|
|
}
|
2021-12-03 03:01:39 +00:00
|
|
|
return ['error' => true];
|
|
|
|
}
|
|
|
|
|
2022-02-05 22:07:10 +00:00
|
|
|
public function load_permcats($uid, $abook_id = 0)
|
2021-12-03 03:01:39 +00:00
|
|
|
{
|
|
|
|
|
|
|
|
$permcats = [
|
|
|
|
[ 'follower', t('follower', 'permcat'),
|
|
|
|
[ 'view_stream','view_profile','view_contacts','view_storage','view_pages','view_wiki',
|
|
|
|
'post_like' ], 1
|
|
|
|
],
|
|
|
|
[ 'contributor', t('contributor', 'permcat'),
|
|
|
|
[ 'view_stream','view_profile','view_contacts','view_storage','view_pages','view_wiki',
|
|
|
|
'post_wall','post_comments','write_wiki','post_like','tag_deliver','chat' ], 1
|
|
|
|
],
|
|
|
|
[ 'publisher', t('publisher', 'permcat'),
|
|
|
|
[ 'view_stream','view_profile','view_contacts','view_storage','view_pages',
|
|
|
|
'write_storage','post_wall','write_pages','write_wiki','post_comments','post_like','tag_deliver',
|
|
|
|
'chat', 'republish' ], 1
|
|
|
|
]
|
|
|
|
];
|
|
|
|
|
|
|
|
if ($uid) {
|
|
|
|
$x = q(
|
|
|
|
"select * from pconfig where uid = %d and cat = 'permcat'",
|
|
|
|
intval($uid)
|
|
|
|
);
|
|
|
|
if ($x) {
|
|
|
|
foreach ($x as $xv) {
|
2022-01-22 10:04:36 +00:00
|
|
|
$value = unserialise($xv['v']);
|
2021-12-03 03:01:39 +00:00
|
|
|
$permcats[] = [ $xv['k'], $xv['k'], $value, 0 ];
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-02-05 22:07:10 +00:00
|
|
|
if ($abook_id) {
|
|
|
|
$r = q("select * from abook left join xchan on abook_xchan = xchan_hash where abook_id = %d and abook_channel = %d",
|
|
|
|
intval($abook_id),
|
|
|
|
intval($uid)
|
|
|
|
);
|
|
|
|
if ($r) {
|
|
|
|
$my_perms = explode(',', get_abconfig($uid, $r[0]['xchan_hash'], 'system', 'my_perms', EMPTY_STR));
|
|
|
|
$permcats[] = [ 'custom', t('custom'), $my_perms, 1];
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
2021-12-03 03:01:39 +00:00
|
|
|
/**
|
|
|
|
* @hooks permcats
|
|
|
|
* * \e array
|
|
|
|
*/
|
2022-02-12 08:50:48 +00:00
|
|
|
Hook::call('permcats', $permcats);
|
2021-12-03 03:01:39 +00:00
|
|
|
|
|
|
|
return $permcats;
|
|
|
|
}
|
|
|
|
|
|
|
|
public static function find_permcat($arr, $name)
|
|
|
|
{
|
2022-08-26 22:37:04 +00:00
|
|
|
if ($arr && $name) {
|
|
|
|
foreach ($arr as $p) {
|
|
|
|
if ($p['name'] == $name) {
|
|
|
|
return $p['value'];
|
|
|
|
}
|
2021-12-03 03:01:39 +00:00
|
|
|
}
|
|
|
|
}
|
2022-08-26 22:37:04 +00:00
|
|
|
return false;
|
2021-12-03 03:01:39 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
public static function update($channel_id, $name, $permarr)
|
|
|
|
{
|
|
|
|
PConfig::Set($channel_id, 'permcat', $name, $permarr);
|
|
|
|
}
|
|
|
|
|
|
|
|
public static function delete($channel_id, $name)
|
|
|
|
{
|
|
|
|
PConfig::Delete($channel_id, 'permcat', $name);
|
|
|
|
}
|
|
|
|
}
|