PluginProbe
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler / 1.7.0
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler v1.7.0
1.7.0 1.6.6 1.6.5 1.6.4 1.6.3 1.6.2 1.6.1 1.6.0 1.5.4 1.5.5 1.5.3 1.5.2 1.5.1 1.5.0 1.4.2 1.4.1 1.4.0 1.3.28 1.3.27 1.3.26 1.3.25 1.3.23 1.3.22 1.3.21 1.3.20 All 50 releases
fluent-cart / app / Services / Permission / PermissionManager.php

PermissionManager.php in FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler 1.7.0, at app/Services/Permission/PermissionManager.php

313 lines 11.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace FluentCart\App\Services\Permission;
4
5 use FluentCart\App\App;
6 use FluentCart\App\Helpers\Helper;
7 use FluentCart\Framework\Support\Arr;
8 use FluentCart\App\Models\User;
9
10 class PermissionManager
11 {
12
13 static $metaKey = '_fluent_cart_admin_role';
14 public const ADMIN_CAP = 'fluent_cart_admin';
15
16 public static function getAllRoles(): array
17 {
18
19 $allRoles = [
20 'super_admin' => [
21 'title' => __('Super Admin', 'fluent-cart'),
22 'descriptions' => __('With All Permissions', 'fluent-cart'),
23 'permissions' => array_keys(self::getAllPermissions())
24 ],
25 'manager' => [
26 'title' => __('Manager', 'fluent-cart'),
27 'descriptions' => __('With All Permissions Except Sensitive Settings', 'fluent-cart'),
28 'permissions' => [
29 'store/settings',
30 'products/view',
31 'products/create',
32 'products/edit',
33 'products/delete',
34 'customers/view',
35 'customers/manage',
36 'customers/export',
37 'customers/delete',
38 'orders/view',
39 'orders/manage_statuses',
40 'orders/can_refund',
41 'orders/manage',
42 'orders/export',
43 'orders/delete',
44 'subscriptions/view',
45 'subscriptions/manage',
46 'subscriptions/export',
47 'subscriptions/delete',
48 'licenses/view',
49 'licenses/manage',
50 'licenses/export',
51 'licenses/delete',
52 'coupons/view',
53 'coupons/manage',
54 'coupons/delete',
55 'reports/view',
56 'reports/export',
57 'integrations/view',
58 'integrations/manage',
59 'integrations/delete',
60 'reviews/manage'
61 ]
62 ],
63 'worker' => [
64 'title' => __('Worker', 'fluent-cart'),
65 'descriptions' => __('View Access for products, customers, coupons, integretions. Manage Access for Order Statuses', 'fluent-cart'),
66 'permissions' => [
67 'products/view',
68 'customers/view',
69 'orders/view',
70 'orders/manage_statuses',
71 'subscriptions/view',
72 'licenses/view',
73 'coupons/view',
74 'coupons/manage',
75 'integrations/view'
76 ]
77 ],
78 'accountant' => [
79 'title' => __('Accountant', 'fluent-cart'),
80 'descriptions' => __('View Access for products, customers, orders, subscriptions, licenses, coupons, reports and integrations', 'fluent-cart'),
81 'permissions' => [
82 'orders/view',
83 'orders/export',
84 'reports/view',
85 'reports/export',
86 'products/view',
87 'customers/view',
88 'customers/export',
89 'subscriptions/view',
90 'subscriptions/export',
91 'licenses/view',
92 'licenses/export',
93 'coupons/view',
94 'integrations/view'
95 ]
96 ]
97 ];
98
99 return apply_filters('fluent_cart/permission/all_roles', $allRoles, []);
100 }
101
102 public static function getUserPermissions($userId = false)
103 {
104 if ($userId === false) {
105 $userId = get_current_user_id();
106 }
107
108 $user = get_user_by('ID', $userId);
109
110 if (user_can($user, 'manage_options')) {
111 $allPermissions = array_keys(self::getAllPermissions());
112 $allPermissions[] = 'is_super_admin';
113
114 return $allPermissions;
115 }
116
117 if (!App::isProActive()) {
118 return [];
119 }
120
121 $currentRole = get_user_meta($userId, static::$metaKey, true);
122
123
124 if (empty($currentRole)) {
125 return [];
126 }
127
128 $allRoles = self::getAllRoles();
129
130 $permissions = Arr::get($allRoles, $currentRole . '.permissions', []);
131
132 return $permissions;
133 }
134
135 public static function hasPermission($permissions, $userId = false): bool
136 {
137 if ($userId === false) {
138 $userId = get_current_user_id();
139 }
140
141
142 if (!$userId) {
143 return false;
144 }
145
146 $userPermissions = self::getUserPermissions($userId);
147 $permissions = (array)$permissions;
148
149 return array_intersect($userPermissions, $permissions) || in_array('super_admin', $userPermissions);
150 }
151
152 public static function hasAnyPermission(array $permissions, $userId = false): bool
153 {
154 if ($userId === false) {
155 $userId = get_current_user_id();
156 }
157
158
159 if (!$userId) {
160 return false;
161 }
162
163 $userPermissions = self::getUserPermissions($userId);
164
165 return !empty(array_intersect($userPermissions, $permissions)) || in_array('is_super_admin', $userPermissions);
166 }
167
168
169 public static function getShopRole($userId)
170 {
171 $user = get_user_by('ID', $userId);
172
173 if (user_can($user, 'manage_options')) {
174 return 'super_admin';
175 }
176
177 $currentRole = get_user_meta($userId, static::$metaKey, true);
178
179 if (empty($currentRole)) {
180 return false;
181 }
182
183 return $currentRole;
184 }
185
186 public static function getAllPermissions(): array
187 {
188 return [
189 'store/settings' => __('Store Settings', 'fluent-cart'),
190 'store/sensitive' => __('Sensitive Settings', 'fluent-cart'),
191 'products/view' => __('View Products', 'fluent-cart'),
192 'products/create' => __('Create Products', 'fluent-cart'),
193 'products/edit' => __('Edit Products', 'fluent-cart'),
194 'products/delete' => __('Delete Products', 'fluent-cart'),
195 'customers/view' => __('View Customers', 'fluent-cart'),
196 'customers/manage' => __('Manage Customers', 'fluent-cart'),
197 'customers/export' => __('Export Customers', 'fluent-cart'),
198 'customers/delete' => __('Delete Customers', 'fluent-cart'),
199 'orders/view' => __('View Orders', 'fluent-cart'),
200 'orders/create' => __('Create Orders', 'fluent-cart'),
201 'orders/manage_statuses' => __('Manage Order Statuses', 'fluent-cart'),
202 'orders/manage' => __('Manage Orders', 'fluent-cart'),
203 'orders/can_refund' => __('Can Refund Orders', 'fluent-cart'),
204 'orders/export' => __('Export Orders', 'fluent-cart'),
205 'orders/delete' => __('Delete Orders', 'fluent-cart'),
206 'subscriptions/view' => __('View Subscriptions', 'fluent-cart'),
207 'subscriptions/manage' => __('Manage Subscriptions', 'fluent-cart'),
208 'subscriptions/export' => __('Export Subscriptions', 'fluent-cart'),
209 'subscriptions/delete' => __('Delete Subscriptions', 'fluent-cart'),
210 'licenses/view' => __('View Licenses', 'fluent-cart'),
211 'licenses/manage' => __('Manage Licenses', 'fluent-cart'),
212 'licenses/export' => __('Export Licenses', 'fluent-cart'),
213 'licenses/delete' => __('Delete Licenses', 'fluent-cart'),
214 'coupons/view' => __('View Coupons', 'fluent-cart'),
215 'coupons/manage' => __('Manage Coupons', 'fluent-cart'),
216 'coupons/delete' => __('Delete Coupons', 'fluent-cart'),
217 'reports/view' => __('View Reports', 'fluent-cart'),
218 'reports/export' => __('Export Reports', 'fluent-cart'),
219 'integrations/view' => __('View Integrations', 'fluent-cart'),
220 'integrations/manage' => __('Manage Integrations', 'fluent-cart'),
221 'integrations/delete' => __('Delete Integrations', 'fluent-cart'),
222 'labels/view' => __('View Labels', 'fluent-cart'),
223 'labels/manage' => __('Manage Labels', 'fluent-cart'),
224 'labels/delete' => __('Delete Labels', 'fluent-cart'),
225 'reviews/manage' => __('Manage Reviews', 'fluent-cart'),
226 'dashboard_stats/view' => __('View Dashboard Stats', 'fluent-cart')
227 ];
228 }
229
230 /**
231 * Get all users that have a FluentCart admin role assigned
232 *
233 * @return array
234 */
235 public static function getUsersWithShopRole(): array
236 {
237 $users = User::query()
238 ->select(['users.*', 'usermeta.meta_value as shop_role'])
239 ->join('usermeta', function ($join) {
240 $join->on('users.ID', '=', 'usermeta.user_id')
241 ->where('usermeta.meta_key', '=', static::$metaKey)
242 ->whereNotNull('usermeta.meta_value')//->where('usermeta.meta_value', '!=', '')
243 ;
244 })
245 ->get();
246
247 // get all roles
248 $allRoles = self::getAllRoles();
249
250 if ($users->isEmpty()) {
251 return [];
252 }
253
254 return $users->map(function ($user) use ($allRoles) {
255 // Check if the shop_role exists in allRoles
256 $role = $allRoles[$user->shop_role] ?? [];
257
258 return [
259 'id' => (int)$user->ID,
260 'email' => $user->user_email,
261 'display_name' => $user->display_name,
262 'username' => $user->user_login,
263 'shop_role' => $user->shop_role,
264 'description' => $role['descriptions'] ?? '',
265 'registered_at' => $user->user_registered,
266 'role_permissions' => self::getUserPermissions($user->ID)
267 ];
268 })->toArray();
269 }
270
271 public static function attachRole($userId, $role)
272 {
273 $wpUser = get_user_by('ID', $userId);
274
275 if (!$wpUser) {
276 return new \WP_Error('user_not_found', __('User not found', 'fluent-cart'));
277 }
278 if (user_can($wpUser, 'manage_options')) {
279 return new \WP_Error('super_admin', __('The user already has all the accesses as part of Administrator Role', 'fluent-cart'));
280 }
281 // Assign the capability directly to the user
282 if (!$wpUser->has_cap(static::ADMIN_CAP)) {
283 $wpUser->add_cap(static::ADMIN_CAP);
284 }
285
286 return update_user_meta($userId, static::$metaKey, $role);
287 }
288
289 public static function detachRole($userId, $role)
290 {
291 $wpUser = get_user_by('ID', $userId);
292
293 if (!$wpUser) {
294 return new \WP_Error('user_not_found', __('User not found', 'fluent-cart'));
295 }
296 if (user_can($wpUser, 'manage_options')) {
297 return new \WP_Error('super_admin', __('The user already has all the accesses as part of Administrator Role', 'fluent-cart'));
298 }
299
300 if (!$wpUser->has_cap(static::ADMIN_CAP)) {
301 $wpUser->remove_cap(static::ADMIN_CAP);
302 }
303
304 return delete_user_meta($userId, static::$metaKey);
305 }
306
307 public static function userCan($permission): bool
308 {
309 $currentUser = Helper::getCurrentUser();
310 return $currentUser && $currentUser->userCan($permission);
311 }
312 }
313