Version 3.2.3
This commit is contained in:
1 parent
ae5c01cc78
commit
78706903a2
2641 files changed
+228363
-201264
No files matched your search
@@ -3,18 +3,18 @@
|
||||
/**
|
||||
* <pre>
|
||||
* Invision Power Services
|
||||
* IP.Board v3.1.4
|
||||
* IP.Board v3.2.3
|
||||
* ACP Restrictions
|
||||
* Last Updated: $Date: 2010-01-15 10:18:44 -0500 (Fri, 15 Jan 2010) $
|
||||
* Last Updated: $Date: 2011-05-05 07:03:47 -0400 (Thu, 05 May 2011) $
|
||||
* </pre>
|
||||
*
|
||||
* @author $Author: bfarber $
|
||||
* @author $Author: ips_terabyte $
|
||||
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/community/board/license.html
|
||||
* @license This is NULLED!
|
||||
* @package IP.Board
|
||||
* @link http://www.invisionpower.com
|
||||
* @link http://hatynka.in
|
||||
* @since 1st march 2002
|
||||
* @version $Revision: 5713 $
|
||||
* @version $Revision: 8644 $
|
||||
*
|
||||
*/
|
||||
|
||||
@@ -33,6 +33,9 @@ class class_permissions
|
||||
protected $request;
|
||||
protected $lang;
|
||||
protected $member;
|
||||
protected $memberData;
|
||||
protected $cache;
|
||||
protected $caches;
|
||||
/**#@-*/
|
||||
|
||||
/**
|
||||
@@ -75,7 +78,7 @@ class class_permissions
|
||||
* @access public
|
||||
* @param object ipsRegistry reference
|
||||
* @param array [Optional] Member permissions array to use (otherwise loads the current member's from the db)
|
||||
* @return void
|
||||
* @return @e void
|
||||
*/
|
||||
public function __construct( ipsRegistry $registry, $permissions=array() )
|
||||
{
|
||||
@@ -94,38 +97,44 @@ class class_permissions
|
||||
}
|
||||
else
|
||||
{
|
||||
// Mainly for login..
|
||||
//-----------------------------------------
|
||||
// Don't do this on login
|
||||
//-----------------------------------------
|
||||
|
||||
if( !$this->memberData['member_id'] )
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
// Support member + group
|
||||
|
||||
$member_restrictions = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'admin_permission_rows', 'where' => "row_id_type='member' AND row_id=" . $this->memberData['member_id'] ) );
|
||||
//-----------------------------------------
|
||||
// Get restrictions
|
||||
//-----------------------------------------
|
||||
|
||||
if( is_array($member_restrictions) AND count($member_restrictions) )
|
||||
$groups[] = $this->memberData['member_group_id'];
|
||||
|
||||
if( $this->memberData['mgroup_others'] )
|
||||
{
|
||||
$this->restrictions_row = unserialize($member_restrictions['row_perm_cache']);
|
||||
$this->restricted = true;
|
||||
$groups = array_merge( $groups, explode( ',', IPSText::cleanPermString( $this->memberData['mgroup_others'] ) ) );
|
||||
}
|
||||
else
|
||||
|
||||
$this->DB->build( array( 'select' => '*', 'from' => 'admin_permission_rows', 'where' => "(row_id_type='member' AND row_id=" . $this->memberData['member_id'] . ") OR (row_id_type='group' AND row_id IN(" . implode( ',', $groups ) . "))" ) );
|
||||
$this->DB->execute();
|
||||
|
||||
while( $r = $this->DB->fetch() )
|
||||
{
|
||||
$groups[] = $this->memberData['member_group_id'];
|
||||
//-----------------------------------------
|
||||
// Member restrictions should override group restrictions
|
||||
//-----------------------------------------
|
||||
|
||||
if( $this->memberData['mgroup_others'] )
|
||||
if( $r['row_id_type'] == 'member' )
|
||||
{
|
||||
$groups = array_merge( $groups, explode( ',', IPSText::cleanPermString( $this->memberData['mgroup_others'] ) ) );
|
||||
}
|
||||
|
||||
$this->DB->build( array( 'select' => '*', 'from' => 'admin_permission_rows', 'where' => "row_id_type='group' AND row_id IN(" . implode( ',', $groups ) . ")" ) );
|
||||
$this->DB->execute();
|
||||
|
||||
while( $r = $this->DB->fetch() )
|
||||
{
|
||||
$this->restrictions_row = array_merge( $this->restrictions_row, unserialize($r['row_perm_cache']) );
|
||||
$this->restrictions_row = unserialize($r['row_perm_cache']);
|
||||
$this->restricted = true;
|
||||
break;
|
||||
}
|
||||
|
||||
$this->restrictions_row = array_merge( $this->restrictions_row, unserialize($r['row_perm_cache']) );
|
||||
$this->restricted = true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -147,7 +156,7 @@ class class_permissions
|
||||
{
|
||||
$this->restrictions_row['applications'][] = $coreId;
|
||||
}
|
||||
|
||||
|
||||
if( ! in_array( $this->mycpModule, $this->restrictions_row['modules'] ) )
|
||||
{
|
||||
$this->restrictions_row['modules'][] = $this->mycpModule;
|
||||
@@ -294,16 +303,105 @@ class class_permissions
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Check Section Access
|
||||
*
|
||||
* Checks the permission for the member
|
||||
*
|
||||
* @access public
|
||||
* @param string [ Application Key ]
|
||||
* @param string [ Module Key ]
|
||||
* @param string [ Section Key ]
|
||||
* @return mixed Boolean has access or not, or outputs HTML error message
|
||||
*/
|
||||
public function checkForSectionAccess( $app='', $module='', $section='' )
|
||||
{
|
||||
//-----------------------------------------
|
||||
// IN DEV check?
|
||||
//-----------------------------------------
|
||||
|
||||
if ( $this->in_dev and IN_DEV )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
$auto_access = array( 'ajax', 'api', 'search', 'palette', 'login' );
|
||||
|
||||
if ( in_array( $module, $auto_access ) )
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// Module access?
|
||||
//-----------------------------------------
|
||||
|
||||
if ( !$this->checkForModuleAccess( $app, $module ) )
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// Can we access?
|
||||
//-----------------------------------------
|
||||
|
||||
$menu = ipsRegistry::cache()->getCache('app_menu_cache');
|
||||
|
||||
foreach( $menu[ $app ] as $k => $items )
|
||||
{
|
||||
if ( preg_match( '/(\d)_' . $module . '/', $k ) )
|
||||
{
|
||||
foreach( $items['items'] as $i )
|
||||
{
|
||||
if ( $i['section'] == $section )
|
||||
{
|
||||
if ( $i['rolekey'] )
|
||||
{
|
||||
$return = $this->checkPermission( $i['rolekey'], $app, $module );
|
||||
break 2;
|
||||
}
|
||||
else
|
||||
{
|
||||
$return = TRUE;
|
||||
break 2;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// I can haz teh permishuns?
|
||||
//-----------------------------------------
|
||||
|
||||
if ( $this->return )
|
||||
{
|
||||
return $return;
|
||||
}
|
||||
else
|
||||
{
|
||||
if ( $return === FALSE )
|
||||
{
|
||||
ipsRegistry::getClass('output')->showError( 'no_permission', 1004 );
|
||||
}
|
||||
else
|
||||
{
|
||||
return $return;
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* Grab the module id from the modules array
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @param string [ Application Key ]
|
||||
* @param string [ Module Key ]
|
||||
* @return integer Module id
|
||||
*/
|
||||
private function _getModuleId( $app='', $module='' )
|
||||
protected function _getModuleId( $app='', $module='' )
|
||||
{
|
||||
$app = ( $app ) ? $app : ipsRegistry::$current_application;
|
||||
$app_id = ipsRegistry::$applications[ $app ]['app_id'];
|
||||
@@ -338,7 +436,7 @@ class class_permissions
|
||||
* @return mixed True if has permission or outputs HTML error message if not
|
||||
*/
|
||||
public function checkPermissionAutoMsg( $key, $app='', $module='' )
|
||||
{
|
||||
{
|
||||
$tmp = $this->return;
|
||||
$this->return = false;
|
||||
|
||||
|
||||
Reference in new issue
Block a user