Version 3.0.5

This commit is contained in:
Neo committed 2025-12-19 00:31:03 -08:00
1 parent 19b38c7c74
commit 1d4720f3e2
3755 files changed
+508378 -664541

No files matched your search

@@ -0,0 +1,30 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Define the default groups section
* Last Updated: $Date: 2009-07-28 20:26:37 -0400 (Tue, 28 Jul 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @since 20th February 2002
* @version $Rev: 4948 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
/**
* Very simply returns the default section if one is not
* passed in the URL
*/
$DEFAULT_SECTION = 'groups';
@@ -0,0 +1,877 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Group management
* Last Updated: $Date: 2009-11-25 05:46:35 -0500 (Wed, 25 Nov 2009) $
*
* @author $Author: matt $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5468 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_groups_groups extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
//-----------------------------------------
// Load skin
//-----------------------------------------
$this->html = $this->registry->output->loadTemplate('cp_skin_groups');
//-----------------------------------------
// Set up stuff
//-----------------------------------------
$this->form_code = $this->html->form_code = 'module=groups&amp;section=groups';
$this->form_code_js = $this->html->form_code_js = 'module=groups&section=groups';
//-----------------------------------------
// Load lang
//-----------------------------------------
ipsRegistry::getClass('class_localization')->loadLanguageFile( array( 'admin_groups' ) );
///----------------------------------------
// What to do...
//-----------------------------------------
switch( $this->request['do'] )
{
case 'doadd':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_add' );
$this->_saveGroup('add');
break;
case 'add':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_add' );
$this->_groupForm('add');
break;
case 'edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit' );
$this->_groupForm('edit');
break;
case 'doedit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit' );
$this->_saveGroup('edit');
break;
case 'delete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete' );
$this->_deleteForm();
break;
case 'dodelete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete' );
$this->_doDelete();
break;
case 'master_xml_export':
$this->masterXMLExport();
break;
case 'groups_overview':
default:
$this->_mainScreen();
break;
}
//-----------------------------------------
// Pass to CP output hander
//-----------------------------------------
$this->registry->getClass('output')->html_main .= $this->registry->getClass('output')->global_template->global_frame_wrapper();
$this->registry->getClass('output')->sendOutput();
}
/**
* List the groups
*
* @access private
* @return void [Outputs to screen]
*/
private function _mainScreen()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$g_array = array();
$content = "";
$form = array();
$rows = array();
//-----------------------------------------
// Page details
//-----------------------------------------
$this->registry->output->extra_nav[] = array( $this->form_code, $this->lang->words['g_nav'] );
//-----------------------------------------
// Get groups
//-----------------------------------------
$this->DB->build( array( 'select' => 'g_id, g_access_cp, g_is_supmod, g_title, prefix, suffix',
'from' => 'groups',
'order' => 'g_title' ) );
$o = $this->DB->execute();
while ( $row = $this->DB->fetch( $o ) )
{
$_extra = ( $this->request['showSecondary'] ) ? ' OR mgroup_others LIKE \'%,' . intval($row['g_id']) . ',%\'' : '';
/* As much as I hate nested queries, this is actually quicker especially when you add in the LIKE check.*/
$count = $this->DB->buildAndFetch( array( 'select' => 'COUNT(*) as count',
'from' => 'members',
'where' => 'member_group_id=' . intval($row['g_id']) . $_extra ) );
$row['count'] = $count['count'];
$rows[ $row['g_id'] ] = $row;
}
foreach( $rows as $row )
{
//-----------------------------------------
// Set up basics
//-----------------------------------------
$row['_can_delete'] = ( $row['g_id'] > 4 ) ? 1 : 0;
$row['_can_acp'] = ( $row['g_access_cp'] == 1 ) ? 1 : 0;
$row['_can_supmod'] = ( $row['g_is_supmod'] == 1 ) ? 1 : 0;
//-----------------------------------------
// Add
//-----------------------------------------
$content .= $this->html->groupsOverviewRow( $row );
//-----------------------------------------
// Add to array
//-----------------------------------------
$g_array[] = array( $row['g_id'], $row['g_title'] );
}
//-----------------------------------------
// And output
//-----------------------------------------
$this->registry->output->html .= $this->html->groupsOverviewWrapper( $content, $g_array );
}
/**
* Exports the groups to a master XML file for distribution
*
* @access public
* @return void [Outputs to screen]
*/
public function masterXMLExport()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$entry = array();
$skip = IPSLib::fetchNonDefaultGroupFields();
//-----------------------------------------
// Get XML class
//-----------------------------------------
require_once( IPS_KERNEL_PATH . 'class_xml.php' );
$xml = new class_xml();
$xml->doc_type = IPS_DOC_CHAR_SET;
$xml->xml_set_root( 'export', array( 'exported' => time() ) );
//-----------------------------------------
// Set group
//-----------------------------------------
$xml->xml_add_group( 'group' );
//-----------------------------------------
// Grab our default 6 groups
//-----------------------------------------
$this->DB->build( array( 'select' => '*',
'from' => 'groups',
'order' => 'g_id ASC',
'limit' => array( 0, 6 )
) );
$this->DB->execute();
while ( $r = $this->DB->fetch() )
{
$content = array();
$r['g_icon'] = '';
//-----------------------------------------
// Sort the fields...
//-----------------------------------------
foreach( $r as $k => $v )
{
if ( ! in_array( $k, $skip ) )
{
$content[] = $xml->xml_build_simple_tag( $k, $v );
}
}
$entry[] = $xml->xml_build_entry( 'row', $content );
}
$xml->xml_add_entry_to_group( 'group', $entry );
$xml->xml_format_document();
//-----------------------------------------
// Print to browser
//-----------------------------------------
$this->registry->output->showDownload( $xml->xml_document, 'groups.xml', '', 0 );
}
/**
* Form to delete a group
*
* @access private
* @return void [Outputs to screen]
*/
private function _deleteForm()
{
$group_id = intval($this->request['id']);
$group = $this->caches['group_cache'][ $group_id ];
if ( !$group_id )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1120 );
}
if ( $group_id < 6 )
{
$this->registry->output->showError( $this->lang->words['g_preset'], 1121 );
}
if( $group['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete_admin' );
}
//-----------------------------------------
// How many users will we be moving?
//-----------------------------------------
$black_adder = $this->DB->buildAndFetch( array( 'select' => 'COUNT(*) as users', 'from' => 'members', 'where' => "member_group_id=" . $group_id ) );
$extra_group = $this->DB->buildAndFetch( array( 'select' => 'COUNT(*) as users', 'from' => 'members', 'where' => "mgroup_others LIKE '%,". $group_id .",%'" ) );
$black_adder['users'] = $black_adder['users'] > 0 ? $black_adder['users'] : 0;
$extra_group['users'] = $extra_group['users'] > 1 ? $extra_group['users'] : 0;
$this->registry->output->html .= $this->html->groupDelete( $group, $black_adder['users'], $extra_group['users'] );
}
/**
* Delete the group
*
* @access private
* @return void [Outputs to screen]
*/
private function _doDelete()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$this->request['id'] = intval($this->request['id'] );
$this->request['to_id'] = intval($this->request['to_id'] );
//-----------------------------------------
// Auth check...
//-----------------------------------------
ipsRegistry::getClass('adminFunctions')->checkSecurityKey( $this->request['secure_key'] );
//-----------------------------------------
// Check
//-----------------------------------------
if ( ! $this->request['id'] )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1122 );
}
if ( $this->request['id'] < 6 )
{
$this->registry->output->showError( $this->lang->words['g_preset'], 1124 );
}
if ( ! $this->request['to_id'] )
{
$this->registry->output->showError( $this->lang->words['g_mecries'], 1123 );
}
//-----------------------------------------
// Check to make sure that the relevant groups exist.
//-----------------------------------------
$original = $this->caches['group_cache'][ $this->request['id'] ];
$move_to = $this->caches['group_cache'][ $this->request['to_id'] ];
if( !count($original) )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1125 );
}
if( !count($move_to) )
{
$this->registry->output->showError( $this->lang->words['g_mecries'], 1126 );
}
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( $original['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete_admin' );
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'member_move_admin1', 'members', 'members' );
}
else if( $move_to['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'member_move_admin2', 'members', 'members' );
}
//-----------------------------------------
// Move and delete
//-----------------------------------------
$this->DB->update( 'members', array( 'member_group_id' => $this->request['to_id'] ), 'member_group_id=' . $this->request['id'] );
$this->DB->delete( 'groups', "g_id=" . $this->request['id'] );
$this->DB->delete( 'admin_permission_rows', "row_id_type='group' AND row_id=" . $this->request['id'] );
//-----------------------------------------
// Can't promote to non-existent group
//-----------------------------------------
foreach( $this->cache->getCache('group_cache') as $row )
{
$promotion = explode( '&', $row['g_promotion'] );
if( $promotion[0] == $this->request['id'] )
{
$this->DB->update( 'groups', array( 'g_promotion' => '-1&-1' ), 'g_id=' . $row['g_id'] );
}
}
//-----------------------------------------
// Remove from moderators table
//-----------------------------------------
$this->DB->delete( 'moderators', "is_group=1 AND group_id=" . $this->request['id'] );
//-----------------------------------------
// Remove as a secondary group
//-----------------------------------------
$this->DB->build( array(
'select' => 'member_group_id, mgroup_others, member_id',
'from' => 'members',
'where' => "mgroup_others LIKE '%," . $this->request['id'] . ",%'"
) );
$exg = $this->DB->execute();
while( $others = $this->DB->fetch($exg) )
{
$extra = array();
$extra = explode( ",", IPSText::cleanPermString( $others['mgroup_others'] ) );
$to_insert = array();
if( count( $extra ) )
{
foreach( $extra as $mgroup_other )
{
if( $mgroup_other != $this->request['id'] )
{
if( $mgroup_other != "" )
{
$to_insert[] = $mgroup_other;
}
}
}
if( count( $to_insert ) )
{
$new_others = ',' . implode( ',', $to_insert ) . ',';
}
else
{
$new_others = "";
}
$this->DB->update( 'members', array( 'mgroup_others' => $new_others ), 'member_id=' . $others['member_id'] );
}
}
//-----------------------------------------
// Rebuild caches
//-----------------------------------------
$this->rebuildGroupCache();
$this->cache->rebuildCache( 'moderators', 'forums' );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['g_removedlog'], $original['g_title'] ) );
$this->registry->output->global_message = $this->lang->words['g_removed'];
$this->_mainScreen();
}
/**
* Save the group [add/edit]
*
* @access private
* @param string 'add' or 'edit'
* @return void [Outputs to screen]
*/
private function _saveGroup( $type='edit' )
{
//-----------------------------------------
// INIT
//-----------------------------------------
$group_id = intval($this->request['id']);
$oldGroup = $this->caches['group_cache'][ $group_id ];
//-----------------------------------------
// Auth check...
//-----------------------------------------
ipsRegistry::getClass('adminFunctions')->checkSecurityKey( $this->request['secure_key'] );
//-----------------------------------------
// Check...
//-----------------------------------------
if ( ! $this->request['g_title'] )
{
$this->registry->output->showError( $this->lang->words['g_title_error'], 1127 );
}
if( intval($this->request['g_max_mass_pm']) > 500 )
{
$this->registry->output->showError( $this->lang->words['g_mass_pm_too_large'], 1127 );
}
#MSSQL needs a check on this
if ( IPSText::mbstrlen( $this->request['g_title'] ) > 32 )
{
$this->registry->output->showError( $this->lang->words['g_title_error'], 1127 );
}
if ( $type == 'edit' )
{
if ( !$group_id )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1128 );
}
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( $this->caches['group_cache'][ $group_id ]['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit_admin' );
}
}
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( ( $type == 'add' OR !$this->caches['group_cache'][ $group_id ]['g_access_cp'] ) AND $this->request['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_add_admin' );
}
//-----------------------------------------
// Sort out the perm mask id things
//-----------------------------------------
$new_perm_set_id = 0;
if( $this->request['g_new_perm_set'] )
{
$this->DB->insert( 'forum_perms', array( 'perm_name' => $this->request['g_new_perm_set'] ) );
$new_perm_set_id = $this->DB->getInsertId();
}
else
{
if ( !is_array( $this->request['permid'] ) )
{
$this->registry->output->showError( $this->lang->words['g_oneperm'], 1129 );
}
}
$this->lang->loadLanguageFile( array( 'admin_permissions' ), 'members' );
//-----------------------------------------
// Some other generic fields
//-----------------------------------------
$promotion_a = '-1'; // id
$promotion_b = '-1'; // posts
if ( $this->request['g_promotion_id'] AND $this->request['g_promotion_id'] > 0 )
{
$promotion_a = $this->request['g_promotion_id'];
$promotion_b = $this->request['g_promotion_posts'];
}
if ( $this->request['g_attach_per_post'] and $this->request['g_attach_max'] > 0 )
{
if ( $this->request['g_attach_per_post'] > $this->request['g_attach_max'] )
{
$this->registry->output->global_message = $this->lang->words['g_pergreater'];
$this->_groupForm('edit');
return;
}
}
$this->request[ 'p_max'] = str_replace( ":", "", $this->request['p_max'] );
$this->request[ 'p_width'] = str_replace( ":", "", $this->request['p_width'] );
$this->request[ 'p_height'] = str_replace( ":", "", $this->request['p_height'] );
$sig_limits = array(
$this->request['use_signatures'],
$this->request['max_images'],
$this->request['max_dims_x'],
$this->request['max_dims_y'],
$this->request['max_urls'],
$this->request['max_lines'],
);
//-----------------------------------------
// Set the db array
//-----------------------------------------
$db_string = array(
'g_view_board' => intval($this->request['g_view_board']),
'g_mem_info' => intval($this->request['g_mem_info']),
'g_can_add_friends' => intval($this->request['g_can_add_friends']),
'g_use_search' => intval($this->request['g_use_search']),
'g_email_friend' => intval($this->request['g_email_friend']),
'g_invite_friend' => $this->request['g_invite_friend'] ? intval( $this->request['g_invite_friend'] ) : 0,
'g_edit_profile' => intval($this->request['g_edit_profile']),
'g_use_pm' => intval($this->request['g_use_pm']),
'g_pm_perday' => intval($this->request['g_pm_perday']),
'g_is_supmod' => intval($this->request['g_is_supmod']),
'g_access_cp' => intval($this->request['g_access_cp']),
'g_title' => trim($this->request['g_title']),
'g_access_offline' => intval($this->request['g_access_offline']),
'g_dname_changes' => intval($this->request['g_dname_changes']),
'g_dname_date' => intval($this->request['g_dname_date']),
'prefix' => trim( IPSText::safeslashes( $_POST['prefix'] ) ),
'suffix' => trim( IPSText::safeslashes( $_POST['suffix'] ) ),
'g_hide_from_list' => intval($this->request['g_hide_from_list']),
'g_perm_id' => $new_perm_set_id ? $new_perm_set_id : implode( ",", $this->request['permid'] ),
'g_icon' => trim( IPSText::safeslashes( $_POST['g_icon'] ) ),
'g_attach_max' => $this->request['g_attach_max'],
'g_avatar_upload' => intval($this->request['g_avatar_upload']),
'g_max_messages' => intval($this->request['g_max_messages']),
'g_max_mass_pm' => intval($this->request['g_max_mass_pm']),
'g_pm_flood_mins' => intval($this->request['g_pm_flood_mins']),
'g_search_flood' => intval($this->request['g_search_flood']),
'g_promotion' => $promotion_a . '&' . $promotion_b,
'g_photo_max_vars' => $this->request['p_max'].':'.$this->request['p_width'].':'.$this->request['p_height'],
'g_dohtml' => intval($this->request['g_dohtml']),
'g_email_limit' => intval($this->request['join_limit']).':'.intval($this->request['join_flood']),
'g_bypass_badwords' => intval($this->request['g_bypass_badwords']),
'g_can_msg_attach' => intval($this->request['g_can_msg_attach']),
'g_attach_per_post' => intval($this->request['g_attach_per_post']),
'g_rep_max_positive' => intval( $this->request['g_rep_max_positive'] ),
'g_rep_max_negative' => intval( $this->request['g_rep_max_negative'] ),
'g_signature_limits' => implode( ':', $sig_limits ),
'g_hide_online_list' => intval( $this->request['g_hide_online_list'] ),
'g_displayname_unit' => intval( $this->request['g_displayname_unit'] ),
'g_sig_unit' => intval( $this->request['g_sig_unit'] ),
'g_bitoptions' => IPSBWOPtions::freeze( $this->request, 'groups', 'global' ), # Saves all BW options for all apps
);
//-----------------------------------------
// Ok? Load interface and child classes
//-----------------------------------------
IPSLib::loadInterface( 'admin/group_form.php' );
foreach( ipsRegistry::$applications as $app_dir => $app_data )
{
if ( ! IPSLib::appIsInstalled( $app_dir ) )
{
continue;
}
if ( file_exists( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' ) )
{
require_once( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' );
$_class = 'admin_group_form__' . $app_dir;
$_object = new $_class( $this->registry );
$remote = $_object->getForSave();
$db_string = array_merge( $remote, $db_string );
}
}
$this->DB->force_data_type = array( 'g_title' => 'string' );
//-----------------------------------------
// Editing...do an update
//-----------------------------------------
if ($type == 'edit')
{
$this->DB->update( 'groups', $db_string, 'g_id=' . $group_id );
//-----------------------------------------
// Update moderator table too
//-----------------------------------------
$this->DB->update( 'moderators', array( 'group_name' => $db_string['g_title'] ), 'group_id=' . $group_id );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['g_editedlog'], $db_string['g_title'] ) );
$this->registry->output->global_message = $this->lang->words['g_edited'];
}
else
{
$this->DB->insert( 'groups', $db_string );
$group_id = $this->DB->getInsertId();
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['g_addedlog'], $db_string['g_title'] ) );
$this->registry->output->global_message = $this->lang->words['g_added'];
}
$this->rebuildGroupCache();
if( $new_perm_set_id )
{
$from = '';
if( ( $type == 'edit' AND $db_string['g_access_cp'] AND !$oldGroup['g_access_cp'] ) OR ( $type == 'add' AND $db_string['g_access_cp'] ) )
{
//-----------------------------------------
// Do they already have restrictions?
//-----------------------------------------
$test = $this->DB->buildAndFetch( array( 'select' => 'row_id', 'from' => 'admin_permission_rows', 'where' => "row_id_type='group' AND row_id=" . $group_id ) );
if( !$test['row_id'] )
{
$from = '&amp;_from=group-' . $group_id;
}
}
$this->registry->output->doneScreen( $this->lang->words['per_saved'], $this->lang->words['per_manage'], 'module=groups&amp;section=permissions&amp;do=edit_set_form' . $from . '&amp;id=' . $new_perm_set_id, 'redirect' );
return;
}
else
{
if( ( $type == 'edit' AND $db_string['g_access_cp'] AND !$oldGroup['g_access_cp'] ) OR ( $type == 'add' AND $db_string['g_access_cp'] ) )
{
//-----------------------------------------
// Do they already have restrictions?
//-----------------------------------------
$test = $this->DB->buildAndFetch( array( 'select' => 'row_id', 'from' => 'admin_permission_rows', 'where' => "row_id_type='group' AND row_id=" . $group_id ) );
if( !$test['row_id'] )
{
$this->registry->output->html .= $this->html->groupAdminConfirm( $group_id );
}
}
$this->_mainScreen();
}
}
/**
* Rebuilds the group cache
*
* @access public
* @return void
*/
public function rebuildGroupCache()
{
$cache = array();
$this->DB->build( array( 'select' => '*',
'from' => 'groups',
'order' => 'g_title ASC' ) );
$this->DB->execute();
while ( $i = $this->DB->fetch() )
{
$cache[ $i['g_id'] ] = IPSLib::unpackGroup( $i );
}
$this->cache->setCache( 'group_cache', $cache, array( 'array' => 1 ) );
}
/**
* Show the add/edit group form
*
* @access private
* @param string 'add' or 'edit'
* @return void [Outputs to screen]
*/
private function _groupForm( $type='edit' )
{
//-----------------------------------------
// Grab group data and start us off
//-----------------------------------------
if ($type == 'edit')
{
if ($this->request['id'] == "")
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 11210 );
}
$group = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'groups', 'where' => "g_id=" . intval($this->request['id']) ) );
$group = IPSLib::unpackGroup( $group );
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( $group['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit_admin' );
}
}
else
{
$group = array();
if( $this->request['id'] )
{
$group = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'groups', 'where' => "g_id=" . intval($this->request['id']) ) );
$group = IPSLib::unpackGroup( $group );
}
$group['g_title'] = 'New Group';
}
//-----------------------------------------
// Grab permission masks
//-----------------------------------------
$perm_masks = array();
$this->DB->build( array( 'select' => '*', 'from' => 'forum_perms' ) );
$this->DB->execute();
while ( $r = $this->DB->fetch() )
{
$perm_masks[] = array( $r['perm_id'], $r['perm_name'] );
}
//-----------------------------------------
// Ok? Load interface and child classes
//-----------------------------------------
$blocks = array( 'tabs' => array(), 'area' => array() );
IPSLib::loadInterface( 'admin/group_form.php' );
$tabsUsed = 2;
$firsttab = false;
foreach( ipsRegistry::$applications as $app_dir => $app_data )
{
if ( ! IPSLib::appIsInstalled( $app_dir ) )
{
continue;
}
if ( file_exists( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' ) )
{
require_once( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' );
$_class = 'admin_group_form__' . $app_dir;
if ( class_exists( $_class ) )
{
$_object = new $_class( $this->registry );
$data = $_object->getDisplayContent( $group, $tabsUsed );
$blocks['area'][ $app_dir ] = $data['content'];
$blocks['tabs'][ $app_dir ] = $data['tabs'];
$tabsUsed = $data['tabsUsed'] ? ( $tabsUsed + $data['tabsUsed'] ) : ( $tabsUsed + 1 );
if ( $this->request['_initTab'] == $app_dir )
{
$firsttab = $tabsUsed;
}
}
}
}
//-----------------------------------------
// And output to form
//-----------------------------------------
$this->registry->output->html .= $this->html->groupsForm( $type, $group, $perm_masks, $blocks, $firsttab );
}
}
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,639 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Permissions management
* Last Updated: $Date: 2009-10-19 06:55:42 -0400 (Mon, 19 Oct 2009) $
*
* @author $Author: matt $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5240 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_groups_permissions extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
/* Load Skin and Lang */
$this->html = $this->registry->output->loadTemplate('cp_skin_permissions');
$this->registry->class_localization->loadLanguageFile( array( 'admin_permissions' ) );
/* URL Bits */
$this->form_code = $this->html->form_code = 'module=groups&amp;section=permissions&amp;';
$this->form_code_js = $this->html->form_code_js = 'module=groups&section=permissions&';
/* What to do */
switch( $this->request['do'] )
{
case 'delete_set':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_delete' );
$this->_doDeleteSet();
break;
case 'do_create_set':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_doCreatePermissionSet();
break;
case 'do_edit_set':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_permissionSaveForm();
break;
case 'edit_set_form':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_permissionSetForm();
break;
case 'view_perm_users':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'permmasks_view' );
$this->permissionSetUsers();
break;
case 'remove_mask':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'permmasks_delete' );
$this->removePermissionSet();
break;
case 'overview':
default:
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_mainScreen();
break;
}
/* Output */
$this->registry->getClass('output')->html_main .= $this->registry->getClass('output')->global_template->global_frame_wrapper();
$this->registry->getClass('output')->sendOutput();
}
/**
* Removes permission set(s) from a user
*
* @access public
* @return void
**/
public function removePermissionSet()
{
/* INI */
$member_id = intval( $this->request['id'] );
$perm_id = $this->request['pid'];
if( ! $member_id )
{
$this->registry->output->showError( $this->lang->words['per_memid'], 11338 );
}
/* Get the member */
$this->DB->build( array( 'select' => 'member_id, members_display_name, org_perm_id', 'from' => 'members', 'where' => "member_id={$member_id}" ) );
$this->DB->execute();
if( ! $mem = $this->DB->fetch() )
{
$this->registry->output->showError( $this->lang->words['per_memid'], 11339 );
}
/* Remove all permission sets */
if( $perm_id == 'all' )
{
$this->DB->update( 'members', array( 'org_perm_id' => 0 ), "member_id={$member_id}" );
}
/* Remove specific permission set */
else
{
/* Make Safe */
$perm_id = intval( $perm_id );
/* Get an array of permission ids */
$pid_array = explode( ",", IPSText::cleanPermString( $mem['org_perm_id'] ) );
/* If there's only one, then we can just remove it */
if( count( $pid_array ) < 2 )
{
$this->DB->update( 'members', array( 'org_perm_id' => 0 ), "member_id={$member_id}" );
}
else
{
/* Remove the specified element */
unset( $pid_array[ array_search( $perm_id, $pid_array ) ] );
/* Update the database */
$this->DB->update( 'members', array( 'org_perm_id' => implode( ",", $pid_array ) ), "member_id={$member_id}" );
}
}
/* Output */
$this->registry->output->html .= $this->html->permissionSetRemoveDone( $mem['members_display_name'] );
$this->registry->output->printPopupWindow();
}
/**
* Show users that are assigned the specified permission set
*
* @access public
* @return void
**/
public function permissionSetUsers()
{
/* Check ID */
$perm_id = intval( $this->request['id'] );
if( ! $perm_id )
{
$this->registry->output->showError( $this->lang->words['per_setid'], 11340 );
}
/* Query the permission set */
$this->DB->build( array( 'select' => '*', 'from' => 'forum_perms', 'where' => "perm_id={$perm_id}" ) );
$this->DB->execute();
if ( ! $perms = $this->DB->fetch() )
{
$this->registry->output->showError( $this->lang->words['per_setid'], 11341 );
}
/* Query the users who have this set */
$this->DB->build( array(
'select' => 'member_id, members_display_name, email, posts, org_perm_id',
'from' => 'members',
'where' => "(org_perm_id IS NOT NULL AND org_perm_id != '')",
'order' => 'name'
) );
$outer = $this->DB->execute();
/* Loop through the users */
$rows = array();
while( $r = $this->DB->fetch( $outer ) )
{
/* Arrayize the perm ids */
$exp_pid = explode( ",", IPSText::cleanPermString( $r['org_perm_id'] ) );
/* Loop through the ids */
foreach( $exp_pid as $pid )
{
/* Is the perm id we are looking for? */
if( $pid == $perm_id )
{
/* What other sets is this member using? */
if( count( $exp_pid ) > 1 )
{
/* INI the extra field */
$extra = "<em style='color:red'>";
/* Query the set names */
$this->DB->build( array(
'select' => '*',
'from' => 'forum_perms',
'where' => "perm_id IN (" . IPSText::cleanPermString( $r['org_perm_id'] ) . ") AND perm_id <> {$perm_id}"
) );
$this->DB->execute();
/* Add each set to the extra field */
while( $mr = $this->DB->fetch() )
{
$extra .= $mr['perm_name'].",";
}
/* Finish the extra field */
$extra = rtrim( $extra, ',' );
$extra .= "</em>";
}
/* No other sets in use */
else
{
$extra = "";
}
/* Add to array */
$r['_extra'] = $extra;
$rows[] = $r;
}
}
}
/* Output */
$this->registry->output->html .= $this->html->permissionSetUsers( $perm_id, $perms['perm_name'], $rows );
$this->registry->output->printPopupWindow();
}
/**
* Deletes a permission set
*
* @access private
* @return void [Outputs to screen]
*/
private function _doDeleteSet()
{
/* INIT */
$id = $this->request['id'];
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Loop through applications */
$where = array();
foreach( $this->registry->getApplications() as $app )
{
/* Check to see if there is a permission map */
$_file = IPSLib::getAppDir( $app['app_directory'] ) . '/extensions/coreExtensions.php';
if( file_exists( $_file ) )
{
/* Get the permission mappings */
require_once( $_file );
/* Check for a config array */
if( isset( $_PERM_CONFIG ) && is_array( $_PERM_CONFIG ) && count( $_PERM_CONFIG ) )
{
/* Loop through the types */
foreach( $_PERM_CONFIG as $perm_type )
{
$where[] = " app='{$app['app_directory']}' AND perm_type='" . strtolower( $perm_type ) . "' ";
}
}
}
}
/* Query Permission Rows */
$this->DB->build( array( 'select' => '*', 'from' => 'permission_index', 'where' => implode( ' OR ', $where ) ) );
$outer = $this->DB->execute();
while( $r = $this->DB->fetch( $outer ) )
{
foreach( array( 'perm_view', 'perm_2', 'perm_3', 'perm_4', 'perm_5', 'perm_6', 'perm_7' ) as $p )
{
if( $r[$p] != '*' )
{
$_perm_arr = explode( ',', IPSText::cleanPermString( $r[$p] ) );
if( in_array( $id, $_perm_arr ) )
{
unset( $_perm_arr[ array_search( $id, $_perm_arr ) ] );
}
$r[$p] = ',' . implode( ',', $_perm_arr ) . ',';
}
}
$update = $r;
unset( $update['perm_id'] );
/* Update */
$this->DB->update( 'permission_index', $update, "perm_id={$r['perm_id']}" );
}
/* Delete */
$this->DB->delete( 'forum_perms', "perm_id=$id" );
/* Done */
$this->registry->output->doneScreen( $this->lang->words['per_removed'], $this->lang->words['per_manage'], $this->form_code, 'redirect' );
}
/**
* Creates a nwe permission set
*
* @access private
* @return void [Outputs to screen]
*/
private function _doCreatePermissionSet()
{
/* INIT */
$set_name = $this->request['new_perm_name'];
$base_on = $this->request['new_perm_copy'];
if( ! $set_name )
{
$this->registry->output->global_message = $this->words['err_specify_set_name'];
$this->_mainScreen();
return;
}
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Loop through applications */
$where = array();
foreach( $this->registry->getApplications() as $app )
{
/* Check to see if there is a permission map */
$_file = IPSLib::getAppDir( $app['app_directory'] ) . '/extensions/coreExtensions.php';
if( file_exists( $_file ) )
{
/* Get the permission mappings */
require_once( $_file );
/* Check for a config array */
if( isset( $_PERM_CONFIG ) && is_array( $_PERM_CONFIG ) && count( $_PERM_CONFIG ) )
{
/* Loop through the types */
foreach( $_PERM_CONFIG as $perm_type )
{
$where[] = " app='{$app['app_directory']}' AND perm_type='" . strtolower( $perm_type ) . "' ";
}
}
}
}
/* Create the set */
$this->DB->insert( 'forum_perms', array( 'perm_name' => $set_name ) );
$new_set_id = $this->DB->getInsertId();
/* Query Permission Rows */
$this->DB->build( array( 'select' => '*', 'from' => 'permission_index', 'where' => implode( ' OR ', $where ) ) );
$outer = $this->DB->execute();
while( $r = $this->DB->fetch( $outer ) )
{
$perm_id = $r['perm_id'];
foreach( array( 'perm_view', 'perm_2', 'perm_3', 'perm_4', 'perm_5', 'perm_6', 'perm_7' ) as $p )
{
if( $r[$p] != '*' )
{
if( in_array( $base_on, explode( ',', IPSText::cleanPermString( $r[$p] ) ) ) )
{
$r[$p] .= $new_set_id . ',';
}
}
}
/* Unset main ID */
unset( $r['perm_id'] );
/* Update */
$this->DB->update( 'permission_index', $r, "perm_id=" . $perm_id );
}
/* Done */
$this->registry->output->doneScreen( $this->lang->words['per_saved'], $this->lang->words['per_manage'], $this->form_code . 'do=edit_set_form&amp;id=' . $new_set_id, 'redirect' );
}
/**
* Saves the global permission set form
*
* @access private
* @return void [Outputs to screen]
*/
private function _permissionSaveForm()
{
/* ID */
$id = intval( $this->request['id'] );
$matricies = array();
/* Query Set Name */
$set_data = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'forum_perms', 'where' => "perm_id={$id}" ) );
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Save */
$perm_obj->saveItemPermMatrix( $this->request['perms'], $id, $this->request['apps'] );
if( $this->request['perm_name'] != $set_data['perm_name'] )
{
$this->DB->update( 'forum_perms', array( 'perm_name' => $this->request['perm_name'] ), "perm_id={$id}" );
}
/* Done */
$this->registry->output->doneScreen( $this->lang->words['per_saved'], $this->lang->words['per_manage'], $this->form_code . '&amp;_from=' . $this->request['_from'], 'redirect' );
}
/**
* Form for modifying a permission set
*
* @access private
* @return void [Outputs to screen]
*/
private function _permissionSetForm()
{
/* ID */
$id = intval( $this->request['id'] );
$matricies = array();
$apps = array();
/* Query Set Name */
$set_data = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'forum_perms', 'where' => "perm_id={$id}" ) );
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Loop through applications */
foreach( $this->registry->getApplications() as $app )
{
/* Check to see if there is a permission map */
$_file = IPSLib::getAppDir( $app['app_directory'] ) . '/extensions/coreExtensions.php';
if( file_exists( $_file ) )
{
/* Get the permission mappings */
require_once( $_file );
/* Check for a config array */
if( isset( $_PERM_CONFIG ) && is_array( $_PERM_CONFIG ) && count( $_PERM_CONFIG ) )
{
/* Loop through the types */
foreach( $_PERM_CONFIG as $perm_type )
{
/* Check for a class */
$_class = $app['app_directory'] . 'PermMapping' . $perm_type;
if( class_exists( $_class ) )
{
/* Create the object */
$perm_map = new $_class;
/* Make sure the function exists */
if( method_exists( $perm_map, 'getPermItems' ) )
{
$matricies[$app['app_title']] = $perm_obj->adminItemPermMatrix( $perm_map, $perm_map->getPermItems(), $id, $app['app_directory'], $perm_type );
$apps[$app['app_directory']] = $perm_type;
}
}
}
}
}
}
/* Output */
$this->registry->output->html .= $this->html->permissionEditor( $set_data['perm_name'], $matricies, $id, $apps );
}
/**
* List permission masks
*
* @access private
* @return void [Outputs to screen]
*/
private function _mainScreen()
{
/* INIT */
$perms = array();
$mems = array();
$groups = array();
$dlist = "";
$content = "";
/* Get the names for the perm masks w/id */
$this->DB->build( array( 'select' => '*', 'from' => 'forum_perms', 'order' => 'perm_name ASC' ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$perms[ $r['perm_id'] ] = $r['perm_name'];
}
/* Number of users using this mask as an override */
$this->DB->build( array( 'select' => 'COUNT(member_id) as count, org_perm_id',
'from' => 'members',
'where' => "(org_perm_id " . $this->DB->buildIsNull( false ) . " AND org_perm_id != '')",
'group' => 'org_perm_id',
) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
if ( strstr( $r['org_perm_id'] , "," ) )
{
foreach( explode( ",", $r['org_perm_id'] ) as $pid )
{
$mems[ $pid ] = ! isset( $mems[ $pid ] ) ? 0 : $mems[ $pid ];
$mems[ $pid ] += $r['count'];
}
}
else
{
$mems[ $r['org_perm_id'] ] += $r['count'];
}
}
/* Groups using this mask */
$this->DB->build( array( 'select' => 'g_id, g_title, g_perm_id', 'from' => 'groups' ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
if ( strstr( $r['g_perm_id'] , "," ) )
{
foreach( explode( ",", $r['g_perm_id'] ) as $pid )
{
$groups[ $pid ][] = $r['g_title'];
}
}
else
{
$groups[ $r['g_perm_id'] ][] = $r['g_title'];
}
}
/* Build the output data */
$display_groups = array();
foreach( $perms as $id => $name )
{
$groups_used = "";
$mems_used = 0;
$is_active = 0;
$dlist .= "<option value='$id'>$name</option>\n";
if ( isset( $groups[ $id ] ) AND is_array( $groups[ $id ] ) )
{
foreach( $groups[ $id ] as $g_title )
{
$groups_used .= '&middot; ' . $g_title . "<br />";
}
$is_active = 1;
}
else
{
$groups_used = "{$this->lang->words['per_none']}";
}
if ( isset($mems[ $id ]) AND $mems[ $id ] > 0 )
{
$is_active = 1;
}
$r['id'] = $id;
$r['name'] = $name;
$r['isactive'] = $is_active;
$r['groups'] = $groups_used;
$r['mems'] = isset( $mems[ $id ] ) ? intval( $mems[ $id ] ) : 0;
$display_groups[] = $r;
}
/**
* Wow this is convoluted...
*/
if( $this->request['_from'] )
{
$from = explode( '-', $this->request['_from'] );
if( $from[1] )
{
$this->registry->class_localization->loadLanguageFile( array( 'admin_groups' ), 'members' );
$this->registry->output->html .= $this->html->groupAdminConfirm( $from[1] );
}
}
$this->registry->output->html .= $this->html->permissionsSplash( $display_groups, $dlist );
}
}
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,29 @@
<?xml version="1.0" encoding="UTF-8"?>
<menu>
<tabitems>
<item>
<title>Управление группами</title>
<subitems>
<subitem>
<subitemtitle>Управление группами пользователей</subitemtitle>
<subsection>groups</subsection>
<subitemurl>do=groups_overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Маски доступа</title>
<subitems>
<subitem>
<subitemtitle>Управление масками доступа</subitemtitle>
<subsection>permissions</subsection>
<subitemurl>do=overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
</tabitems>
</menu>
@@ -0,0 +1,45 @@
<?xml version="1.0" encoding="UTF-8"?>
<permissions>
<group>
<grouptitle>Управление группами</grouptitle>
<items>
<item>
<key>groups_add</key>
<string>Может добавлять группы?</string>
</item>
<item>
<key>groups_add_admin</key>
<string>Может добавлять АДМИНИСТРАТОРСКИЕ группы?</string>
</item>
<item>
<key>groups_edit</key>
<string>Может редактировать группы?</string>
</item>
<item>
<key>groups_edit_admin</key>
<string>Может редактировать АДМИНИСТРАТОРСКИЕ группы?</string>
</item>
<item>
<key>groups_delete</key>
<string>Может удалять группы?</string>
</item>
<item>
<key>groups_delete_admin</key>
<string>Может удалять АДМИНИСТРАТОРСКИЕ группы?</string>
</item>
</items>
</group>
<group>
<grouptitle>Управление правами</grouptitle>
<items>
<item>
<key>perms_manage</key>
<string>Может добавлять и редактировать маски доступа?</string>
</item>
<item>
<key>perms_delete</key>
<string>Может удалять маски доступа?</string>
</item>
</items>
</group>
</permissions>