PluginProbe
User Access Manager / 1.1.1
User Access Manager v1.1.1
2.3.20 2.3.19 2.3.18 2.3.17 2.3.16 2.3.15 2.3.14 2.3.13 trunk 0.6 0.6.1 0.6.2 0.7 0.7 Beta 0.7.0.1 0.8 0.8.0.1 0.8.0.2 0.9 0.9.1 0.9.1.1 0.9.1.2 0.9.1.3 0.9.1.4 1.0 All 136 releases
← All changes | class/UamAccessHandler.class.php +268 -155 1.0 → 1.1.1 View file →
@@ -27,17 +27,24 @@
27 27
28 28 class UamAccessHandler
29 29 {
30 30 protected $userAccessManager = null;
31 - protected $postUserGroups = array();
32 - protected $categoryUserGroups = array();
33 - protected $userUserGroups = array();
34 - protected $postAccess = array();
35 - protected $categroyAccess = array();
31 + protected $objectUserGroups = array();
32 + protected $objectAccess = array();
36 33 protected $userGroups = array(
37 34 'filtered' => array(),
38 35 'noneFiltered' => array(),
39 36 );
37 + protected $plObjects = array();
38 + protected $objectTypes = array(
39 + 'post',
40 + 'page',
41 + 'attachment',
42 + 'category',
43 + 'user',
44 + 'role'
45 + );
46 + protected $allObjectTypes = null;
40 47
41 48 /**
42 49 * The consturctor
43 50 *
@@ -44,9 +51,9 @@
44 51 * @param object &$userAccessManager The user access manager object.
45 52 *
46 53 * @return null
47 54 */
48 - function __construct(&$userAccessManager)
55 + public function __construct(&$userAccessManager)
49 56 {
50 57 $this->userAccessManager = $userAccessManager;
51 58 }
52 59
@@ -54,14 +61,86 @@
54 61 * Returns the user access manager object.
55 62 *
56 63 * @return object
57 64 */
58 - function &getUserAccessManager()
65 + public function &getUserAccessManager()
59 66 {
60 67 return $this->userAccessManager;
61 68 }
62 69
63 70 /**
71 + * Returns the predfined object types.
72 + *
73 + * @return array();
74 + */
75 + public function getObjectTypes()
76 + {
77 + return $this->objectTypes;
78 + }
79 +
80 + /**
81 + * Returns all objects types.
82 + *
83 + * @return array
84 + */
85 + public function getAllObjectTypes()
86 + {
87 + if (isset($this->allObjectTypes)) {
88 + return $this->allObjectTypes;
89 + }
90 +
91 + $plObjects = $this->getPlObjects();
92 +
93 + $this->allObjectTypes = array_merge(
94 + $this->objectTypes,
95 + array_keys($plObjects)
96 + );
97 +
98 + return $this->allObjectTypes;
99 + }
100 +
101 + /**
102 + * Magic method getter.
103 + *
104 + * @param string $name The name of the function
105 + * @param array $arguments The arguments for the function
106 + *
107 + * @return mixed
108 + */
109 + public function __call($name, $arguments)
110 + {
111 + echo $name;
112 + exit;
113 +
114 + $uam = $this->getUserAccessManager();
115 +
116 + $action = '';
117 +
118 + if ($uam->startsWith($name, 'getUserGroupsFor')) {
119 + $prefix = 'getUserGroupsFor';
120 + } elseif ($uam->startsWith($name, 'checkAccessFor')) {
121 + $prefix = 'checkAccessFor';
122 + }
123 +
124 + $objectType = str_replace($prefix, '', $name);
125 + $objectType = strtolower($objectType);
126 +
127 + $objectId = $arguments[0];
128 +
129 + if ($prefix == 'getUserGroupsFor') {
130 + return $this->getUserGroupsForObject(
131 + $objectType,
132 + $objectId
133 + );
134 + } elseif ($prefix == 'checkAccessFor') {
135 + return $this->checkObjectAccess(
136 + $objectType,
137 + $objectId
138 + );
139 + }
140 + }
141 +
142 + /**
64 143 * Filter the user groups of an object if authors_can_add_posts_to_groups
65 144 * option is enabled
66 145 *
67 146 * @param array $userGroups The user groups.
@@ -76,11 +155,13 @@
76 155 && !$this->checkUserAccess()
77 156 && $this->getUserAccessManager()->atAdminPanel
78 157 ) {
79 158 global $current_user;
159 + //Force user infos
160 + wp_get_current_user();
80 161
81 162 $userGroupsForUser
82 - = $this->getUserGroupsForUser($current_user->ID);
163 + = $this->getUserGroupsForObject('user', $current_user->ID);
83 164
84 165 foreach ($userGroups as $key => $uamUserGroup) {
85 166 if (!array_key_exists($uamUserGroup->getId(), $userGroupsForUser)) {
86 167 unset($userGroups[$key]);
@@ -99,9 +180,9 @@
99 180 * @param boolean $filter Filter the groups.
100 181 *
101 182 * @return array|object
102 183 */
103 - function getUserGroups($userGroupId = null, $filter = true)
184 + public function getUserGroups($userGroupId = null, $filter = true)
104 185 {
105 186 if ($filter) {
106 187 $filterAttr = 'filtered';
107 188 } else {
@@ -107,13 +188,13 @@
107 188 } else {
108 189 $filterAttr = 'noneFiltered';
109 190 }
110 191
111 - if ($userGroupId == null
192 + if ($userGroupId === null
112 193 && $this->userGroups[$filterAttr] != array()
113 194 ) {
114 195 return $this->userGroups[$filterAttr];
115 - } elseif ($userGroupId != null
196 + } elseif ($userGroupId !== null
116 197 && $this->userGroups[$filterAttr] != array()
117 198 ) {
118 199 if (isset($this->userGroups[$filterAttr][$userGroupId])) {
119 200 return $this->userGroups[$filterAttr][$userGroupId];
@@ -162,12 +243,13 @@
162 243 * @param object $userGroup The user group which we want to add.
163 244 *
164 245 * @return null
165 246 */
166 - function addUserGroup($userGroup)
247 + public function addUserGroup($userGroup)
167 248 {
168 249 $this->getUserGroups();
169 - $this->userGroups[$userGroup->getId()] = $userGroup;
250 + $this->userGroups['noneFiltered'][$userGroup->getId()] = $userGroup;
251 + $this->userGroups['filtered'] = array();
170 252 }
171 253
172 254 /**
173 255 * Deletes a user group.
@@ -175,13 +257,14 @@
175 257 * @param integer $userGroupId The user group id which we want to delete.
176 258 *
177 259 * @return null
178 260 */
179 - function deleteUserGroup($userGroupId)
261 + public function deleteUserGroup($userGroupId)
180 262 {
181 263 if ($this->getUserGroups($userGroupId) != null) {
182 264 $this->getUserGroups($userGroupId)->delete();
183 - unset($this->userGroups[$userGroupId]);
265 + unset($this->userGroups['noneFiltered'][$userGroupId]);
266 + $this->userGroups['filtered'] = array();
184 267 }
185 268 }
186 269
187 270 /**
@@ -186,30 +269,59 @@
186 269
187 270 /**
188 271 * Returns the user groups for the given object.
189 272 *
190 - * @param integer $objectId The id of the object.
191 - * @param string $type The type for what we want the groups.
192 - * @param boolean $filter Filter the groups.
273 + * @param string $objectType The object type.
274 + * @param integer $objectId The id of the object.
275 + * @param boolean $filter Filter the groups.
193 276 *
194 277 * @return array
195 278 */
196 - private function _getUserGroupsForObject($objectId, $type, $filter = true)
279 + public function getUserGroupsForObject($objectType, $objectId, $filter = true)
197 280 {
281 + if (!in_array($objectType, $this->getAllObjectTypes())) {
282 + return;
283 + }
284 +
285 + if ($objectType == 'user') {
286 + $filter = false;
287 + }
288 +
289 + if ($filter) {
290 + $filterAttr = 'filtered';
291 + } else {
292 + $filterAttr = 'noneFiltered';
293 + }
294 +
295 + if (isset($this->objectUserGroups[$objectType][$filterAttr][$objectId])) {
296 + return $this->objectUserGroups[$objectType][$filterAttr][$objectId];
297 + }
298 +
198 299 $objectUserGroups = array();
199 300
200 301 $userGroups = $this->getUserGroups(null, $filter);
302 +
303 + $plObject = false;
304 +
305 + if ($objectType != 'user'
306 + && $objectType != 'post'
307 + && $objectType != 'category'
308 + ) {
309 + $plObject = true;
310 + }
201 311
202 312 if (isset($userGroups)) {
203 313 foreach ($userGroups as $userGroup) {
204 - $objectMembership = $userGroup->{$type.'IsMember'}($objectId, true);
205 -
314 + $objectMembership = $userGroup->objectIsMember(
315 + $objectType,
316 + $objectId,
317 + true
318 + );
319 +
206 320 if ($objectMembership !== false) {
207 - if (isset($objectMembership['byPost'])
208 - || isset($objectMembership['byCategory'])
209 - || isset($objectMembership['byRole'])
210 - ) {
211 - $userGroup->setRecursive[$objectId] = $objectMembership;
321 + if (is_array($objectMembership)) {
322 + $userGroup->setRecursive[$objectType][$objectId]
323 + = $objectMembership;
212 324 }
213 325
214 326 $objectUserGroups[$userGroup->getId()]
215 327 = $userGroup;
@@ -221,99 +333,47 @@
221 333 if ($filter) {
222 334 $objectUserGroups = $this->_filterUserGroups($objectUserGroups);
223 335 }
224 336
225 - return $objectUserGroups;
226 - }
227 -
228 - /**
229 - * Returns the user groups of the given post.
230 - *
231 - * @param integer $postId The id of the post from which we want the groups.
232 - * @param boolean $filter Filter the groups.
233 - *
234 - * @return array
235 - */
236 - function getUserGroupsForPost($postId, $filter = true)
237 - {
238 - if ($filter) {
239 - $filterAttr = 'filtered';
240 - } else {
241 - $filterAttr = 'noneFiltered';
242 - }
337 + $this->objectUserGroups[$objectType][$filterAttr][$objectId]
338 + = $objectUserGroups;
243 339
244 - if (isset($this->postUserGroups[$filterAttr][$postId])) {
245 - return $this->postUserGroups[$filterAttr][$postId];
246 - }
247 -
248 - $this->postUserGroups[$filterAttr][$postId]
249 - = $this->_getUserGroupsForObject($postId, 'post', $filter);
250 -
251 - return $this->postUserGroups[$filterAttr][$postId];
340 + return $this->objectUserGroups[$objectType][$filterAttr][$objectId];
252 341 }
253 342
254 343 /**
255 - * Returns the user groups of the given category.
344 + * Unsets the usergroups for objects.
256 345 *
257 - * @param integer $categoryId The id of the category from which
258 - * we want the groups.
259 - * @param boolean $filter Filter the groups.
260 - *
261 - * @return array
346 + * @return null
262 347 */
263 - function getUserGroupsForCategory($categoryId, $filter = true)
348 + public function unsetUserGroupsForObject()
264 349 {
265 - if ($filter) {
266 - $filterAttr = 'filtered';
267 - } else {
268 - $filterAttr = 'noneFiltered';
269 - }
270 -
271 - if (isset($this->categoryUserGroups[$filterAttr][$categoryId])) {
272 - return $this->categoryUserGroups[$filterAttr][$categoryId];
273 - }
274 -
275 - $this->categoryUserGroups[$filterAttr][$categoryId]
276 - = $this->_getUserGroupsForObject($categoryId, 'category', $filter);
277 -
278 - return $this->categoryUserGroups[$filterAttr][$categoryId];
350 + $this->objectUserGroups = array();
279 351 }
280 352
281 - /**
282 - * Returns the user groups of the given user.
283 - *
284 - * @param integer $userId The id of the user from which we want the groups.
285 - *
286 - * @return array
287 - */
288 - function getUserGroupsForUser($userId)
289 - {
290 - if (isset($this->userUserGroups[$userId])) {
291 - return $this->userUserGroups[$userId];
292 - }
293 -
294 - $this->userUserGroups[$userId]
295 - = $this->_getUserGroupsForObject($userId, 'user', false);
296 -
297 - return $this->userUserGroups[$userId];
298 - }
299 -
300 353 /**
301 354 * Checks if the current_user has access to the given post.
302 355 *
356 + * @param string $objectType The object type which should be checked.
303 357 * @param integer $objectId The id of the object.
304 - * @param array $membership The group membership for the object.
305 - * @param string $type The object type which should be checked.
306 358 *
307 359 * @return boolean
308 360 */
309 - private function _checkAccess($objectId, $membership, $type = null)
361 + public function checkObjectAccess($objectType, $objectId)
310 362 {
311 - global $current_user;
363 + if (!in_array($objectType, $this->getAllObjectTypes())) {
364 + return;
365 + }
312 366
313 - $uamOptions = $this->getUserAccessManager()->getAdminOptions();
367 + if (isset($this->objectAccess[$objectType][$objectId])) {
368 + return $this->objectAccess[$objectType][$objectId];
369 + }
314 370
315 - if ($type == 'post') {
371 + global $current_user;
372 + //Force user infos
373 + wp_get_current_user();
374 +
375 + if ($objectType == 'post') {
316 376 $post = get_post($objectId);
317 377 $authorId = $post->post_author;
318 378 } else {
319 379 $authorId = -1;
@@ -318,14 +378,17 @@
318 378 } else {
319 379 $authorId = -1;
320 380 }
321 381
382 + $uamOptions = $this->getUserAccessManager()->getAdminOptions();
383 + $membership = $this->getUserGroupsForObject($objectType, $objectId, false);
384 +
322 385 if ($membership == array()
323 386 || $this->checkUserAccess()
324 387 || $current_user->ID == $authorId
325 388 && $uamOptions['authors_has_access_to_own'] == 'true'
326 389 ) {
327 - return true;
390 + return $this->objectAccess[$objectType][$objectId] = true;
328 391 }
329 392
330 393 $curIp = explode(".", $_SERVER['REMOTE_ADDR']);
331 394
@@ -330,11 +393,12 @@
330 393 $curIp = explode(".", $_SERVER['REMOTE_ADDR']);
331 394
332 395 foreach ($membership as $key => $userGroup) {
333 396 if ($this->checkUserIp($curIp, $userGroup->getIpRange())
334 - || $userGroup->userIsMember($current_user->ID)
397 + || $userGroup->objectIsMember('user', $current_user->ID)
335 398 ) {
336 - return true;
399 + return $this->objectAccess[$objectType][$objectId] = true;
400 + break;
337 401 }
338 402
339 403 if ($this->getUserAccessManager()->atAdminPanel
340 404 && $userGroup->getWriteAccess() == 'all'
@@ -345,55 +409,18 @@
345 409 }
346 410 }
347 411
348 412 if ($membership == array()) {
349 - return true;
413 + return $this->objectAccess[$objectType][$objectId] = true;
350 414 }
351 415
352 - return false;
416 + return $this->objectAccess[$objectType][$objectId] = false;
353 417 }
354 418
355 - /**
356 - * Checks if the current_user has access to the given post.
357 - *
358 - * @param integer $postId The id of the post which we want to check.
359 - *
360 - * @return boolean
361 - */
362 - function checkAccess($postId)
363 - {
364 - if (isset($this->postAccess[$postId])) {
365 - return $this->postAccess[$postId];
366 - }
367 -
368 - $postMembership = $this->getUserGroupsForPost($postId, false);
369 -
370 - $this->postAccess[$postId]
371 - = $this->_checkAccess($postId, $postMembership, 'post');
372 -
373 - return $this->postAccess[$postId];
374 - }
375 419
376 - /**
377 - * Checks if the current_user has access to the given category.
378 - *
379 - * @param integer $categoryId The id of the category which we want to check.
380 - *
381 - * @return boolean
420 + /*
421 + * Other functions
382 422 */
383 - function checkCategoryAccess($categoryId)
384 - {
385 - if (isset($this->categroyAccess[$categoryId])) {
386 - return $this->categroyAccess[$categoryId];
387 - }
388 -
389 - $categoryMembership = $this->getUserGroupsForCategory($categoryId, false);
390 -
391 - $this->categroyAccess[$categoryId]
392 - = $this->_checkAccess($categoryId, $categoryMembership);
393 -
394 - return $this->categroyAccess[$categoryId];
395 - }
396 423
397 424 /**
398 425 * Checks if the given ip matches with the range.
399 426 *
@@ -401,9 +428,9 @@
401 428 * @param array $ipRanges The ip ranges.
402 429 *
403 430 * @return boolean
404 431 */
405 - function checkUserIp($curIp, $ipRanges)
432 + public function checkUserIp($curIp, $ipRanges)
406 433 {
407 434 if (isset($ipRanges)) {
408 435 foreach ($ipRanges as $ipRange) {
409 436 $ipRange = explode("-", $ipRange);
@@ -432,19 +459,20 @@
432 459 return false;
433 460 }
434 461
435 462 /**
436 - * Checks the user access by user level.
463 + * Return the role of the user.
437 464 *
438 - * @return boolean
465 + * @param integer $userId The user id.
466 + *
467 + * @return string|null
439 468 */
440 - function checkUserAccess()
469 + private function _getUserRole($userId)
441 470 {
442 - global $current_user, $wpdb;
443 -
444 - $uamOptions = $this->getUserAccessManager()->getAdminOptions();
445 - $curUserdata = get_userdata($current_user->ID);
446 -
471 + global $wpdb;
472 +
473 + $curUserdata = get_userdata($userId);
474 +
447 475 if (!isset($curUserdata->user_level)) {
448 476 $curUserdata->user_level = null;
449 477 }
450 478
@@ -453,16 +481,53 @@
453 481 } else {
454 482 $capabilities = null;
455 483 }
456 484
457 - $role = is_array($capabilities) ?
458 - array_keys($capabilities) : 'norole';
459 - $role = trim($role[0]);
485 + $role = is_array($capabilities) ?
486 + array_keys($capabilities) : array('norole');
487 +
488 + return trim($role[0]);
489 + }
490 +
491 + /**
492 + * Checks if the user is an admin user
493 + *
494 + * @param integer $userId The user id.
495 + *
496 + * @return boolean
497 + */
498 + public function userIsAdmin($userId)
499 + {
500 + $role = $this->_getUserRole($userId);
460 501
502 + if ($role == 'administrator'
503 + || is_super_admin($userId)
504 + ) {
505 + return true;
506 + }
507 +
508 + return false;
509 + }
510 +
511 + /**
512 + * Checks the user access by user level.
513 + *
514 + * @return boolean
515 + */
516 + public function checkUserAccess()
517 + {
518 + global $current_user;
519 + //Force user infos
520 + wp_get_current_user();
521 +
522 + $uamOptions = $this->getUserAccessManager()->getAdminOptions();
523 +
524 + $role = $this->_getUserRole($current_user->ID);
461 525 $orderedRoles = $this->getRolesOrdered();
462 526
463 527 if ($orderedRoles[$role] >= $orderedRoles[$uamOptions['full_access_role']]
464 528 || $role == 'administrator'
529 + || is_super_admin($current_user->ID)
465 530 ) {
466 531 return true;
467 532 }
468 533
@@ -473,9 +538,9 @@
473 538 * Returns the roles as assoziative array.
474 539 *
475 540 * @return array
476 541 */
477 - function getRolesOrdered()
542 + public function getRolesOrdered()
478 543 {
479 544 $orderedRoles = array(
480 545 'norole' => 0,
481 546 'subscriber' => 1,
@@ -485,6 +550,54 @@
485 550 'administrator' => 5
486 551 );
487 552
488 553 return $orderedRoles;
554 + }
555 +
556 + /**
557 + * Registers object that should be handelt by the user access manager.
558 + *
559 + * @param array $object The object which you want to register.
560 + *
561 + * @return boolean
562 + */
563 + public function registerPlObject($object)
564 + {
565 + if (!isset($object['name'])
566 + || !isset($object['reference'])
567 + || !isset($object['getFull'])
568 + || !isset($object['getFullObjects'])
569 + ) {
570 + return false;
571 + }
572 +
573 + $this->plObjects[$object['name']] = $object;
574 +
575 + return true;
576 + }
577 +
578 + /**
579 + * Returns a registerd pluggable object.
580 + *
581 + * @param string $objectName The name of the object which should be returned.
582 + *
583 + * @return array
584 + */
585 + public function getPlObject($objectName)
586 + {
587 + if (isset($this->plObjects[$objectName])) {
588 + return $this->plObjects[$objectName];
589 + }
590 +
591 + return array();
592 + }
593 +
594 + /**
595 + * Returns all registerd pluggable objects.
596 + *
597 + * @return array
598 + */
599 + public function getPlObjects()
600 + {
601 + return $this->plObjects;
489 602 }
490 603 }