PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / trunk
Advanced Access Manager – Access Governance for WordPress vtrunk
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / application / Service / Policies.php
advanced-access-manager / application / Service Last commit date
Shortcode 5 months ago AccessDeniedRedirect.php 1 year ago AdminToolbar.php 1 year ago ApiRoute.php 1 year ago BackendMenu.php 1 year ago BaseTrait.php 1 year ago Capability.php 1 year ago Content.php 5 months ago Core.php 9 months ago Hooks.php 1 year ago Identity.php 3 months ago Jwt.php 3 months ago LoginRedirect.php 1 year ago LogoutRedirect.php 3 months ago Metaboxes.php 1 year ago NotFoundRedirect.php 1 year ago Policies.php 1 year ago SecureLogin.php 1 year ago SecurityAudit.php 1 year ago Shortcodes.php 5 months ago Urls.php 1 year ago Welcome.php 1 year ago Widgets.php 1 year ago
Policies.php
233 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * JSON Access Policy service
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Service_Policies
17 {
18 use AAM_Service_BaseTrait;
19
20 /**
21 * Constructor
22 *
23 * @return void
24 * @access protected
25 *
26 * @version 7.0.4
27 */
28 protected function __construct()
29 {
30 // Register RESTful API
31 AAM_Restful_Policies::bootstrap();
32
33 add_action('init', function() {
34 $this->initialize_hooks();
35 }, PHP_INT_MAX);
36 }
37
38 /**
39 * Get a boilerplate policy
40 *
41 * @return string
42 * @access public
43 *
44 * @version 7.0.0
45 */
46 public function get_boilerplate_policy()
47 {
48 return json_encode(json_decode('{
49 "Statement": [
50 {
51 "Effect": "deny",
52 "Resource": [],
53 "Action": []
54 }
55 ],
56 "Param": [
57 {
58 "Key": "SomeParam",
59 "Value": "some-value"
60 }
61 ]
62 }'), JSON_PRETTY_PRINT);
63 }
64
65 /**
66 * Initialize hooks
67 *
68 * @return void
69 * @access protected
70 *
71 * @version 7.0.4
72 */
73 protected function initialize_hooks()
74 {
75 if (is_admin()) {
76 // Hook that initialize the AAM UI part of the service
77 add_action('aam_initialize_ui_action', function () {
78 AAM_Backend_Feature_Main_Policy::register();
79 });
80
81 // Register custom access control metabox
82 add_action('add_meta_boxes', function() {
83 $this->_add_meta_boxes();
84 });
85
86 // Access policy save
87 add_filter('wp_insert_post_data', function($data) {
88 return $this->_wp_insert_post_data($data);
89 });
90 }
91
92 // Override role list permissions
93 add_filter('aam_rest_role_output_filter', function($result, $role) {
94 $context = AAM::api()->misc->get($_GET, 'context');
95
96 if ($context === 'policy_assignee') {
97 $policy_id = AAM::api()->misc->get($_GET, 'policy_id');
98 $is_attached = AAM::api()->policies('role:' . $role->slug)->is_attached(
99 intval($policy_id)
100 );
101
102 $result['is_attached'] = $is_attached;
103
104 if (array_key_exists('permissions', $result)) {
105 $result['permissions'] = [ 'toggle_role_policy' ];
106 }
107 }
108
109 return $result;
110 }, 10, 2);
111
112 // Override user list RESTful output
113 add_filter('aam_rest_user_output_filter', function($result, $user) {
114 $context = AAM::api()->misc->get($_GET, 'context');
115
116 if ($context === 'policy_assignee') {
117 $policy_id = AAM::api()->misc->get($_GET, 'policy_id');
118 $is_attached = AAM::api()->policies('user:' . $user->ID)->is_attached(
119 intval($policy_id)
120 );
121
122 $result['is_attached'] = $is_attached;
123
124 if (array_key_exists('permissions', $result)) {
125 $result['permissions'] = [ 'toggle_user_policy' ];
126 }
127 }
128
129 return $result;
130 }, 10, 2);
131 }
132
133 /**
134 * Register UI metaboxes for the Access Policy edit screen
135 *
136 * @global WP_Post $post
137 *
138 * @return void
139 * @access private
140 *
141 * @version 7.0.0
142 */
143 private function _add_meta_boxes()
144 {
145 global $post;
146
147 if (is_a($post, 'WP_Post')
148 && ($post->post_type === AAM_Framework_Service_Policies::CPT)
149 ) {
150 add_meta_box(
151 AAM_Framework_Service_Policies::CPT,
152 __('Access Policy Document', 'advanced-access-manager'),
153 function() {
154 echo AAM_Backend_View::get_instance()->render_policy_metabox();
155 },
156 AAM_Framework_Service_Policies::CPT,
157 'normal',
158 'high'
159 );
160
161 // Parent policy metabox
162 add_meta_box(
163 AAM_Framework_Service_Policies::CPT . '_parent',
164 __('Parent Policy', 'advanced-access-manager'),
165 function() {
166 echo AAM_Backend_View::get_instance()->render_policy_parent_metabox();
167 },
168 AAM_Framework_Service_Policies::CPT,
169 'side',
170 'low'
171 );
172
173 // Only display the assignee when policy is published
174 if ($post->post_status === 'publish') {
175 add_meta_box(
176 'aam-policy-assignee',
177 __('Access Policy Assignee', 'advanced-access-manager'),
178 function() {
179 echo AAM_Backend_View::get_instance()->renderPolicyPrincipalMetabox();
180 },
181 AAM_Framework_Service_Policies::CPT,
182 'side'
183 );
184 }
185 }
186 }
187
188 /**
189 * Hook into policy submission and filter its content
190 *
191 * @param array $data
192 *
193 * @return array
194 * @access private
195 *
196 * @version 7.0.0
197 */
198 private function _wp_insert_post_data($data)
199 {
200 if (isset($data['post_type'])
201 && ($data['post_type'] === AAM_Framework_Service_Policies::CPT)
202 ) {
203 $content = AAM::api()->misc->get($_POST, 'aam-policy');
204
205 if (empty($content)) {
206 if (empty($data['post_content'])) {
207 $content = $this->get_boilerplate_policy();
208 } else {
209 $content = $data['post_content'];
210 }
211 }
212
213 // Removing any slashes
214 $content = htmlspecialchars_decode(stripslashes($content));
215
216 // Reformat the policy content
217 $json = json_decode($content);
218
219 if (!empty($json)) {
220 $content = wp_json_encode($json, JSON_PRETTY_PRINT);
221 }
222
223 if (!empty($content)) { // Edit form was submitted
224 $content = addslashes($content);
225 }
226
227 $data['post_content'] = $content;
228 }
229
230 return $data;
231 }
232
233 }