PluginProbe
User Access Manager / 1.1.1
User Access Manager v1.1.1
2.3.20 2.3.19 2.3.18 2.3.17 2.3.16 2.3.15 2.3.14 2.3.13 trunk 0.6 0.6.1 0.6.2 0.7 0.7 Beta 0.7.0.1 0.8 0.8.0.1 0.8.0.2 0.9 0.9.1 0.9.1.1 0.9.1.2 0.9.1.3 0.9.1.4 1.0 All 136 releases
← All changes | class/UserAccessManager.class.php +839 -460 1.0 → 1.1.1 View file →
@@ -28,12 +28,13 @@
28 28 class UserAccessManager
29 29 {
30 30 var $atAdminPanel = false;
31 31 protected $adminOptionsName = "uamAdminOptions";
32 - protected $uamVersion = 1.0;
33 - protected $uamDbVersion = 1.1;
32 + protected $uamVersion = 1.1;
33 + protected $uamDbVersion = 1.2;
34 34 protected $adminOptions;
35 35 protected $accessHandler = null;
36 + protected $postUrls = array();
36 37
37 38 /**
38 39 * Consturctor
39 40 *
@@ -38,11 +39,11 @@
38 39 * Consturctor
39 40 *
40 41 * @return null
41 42 */
42 - function __construct()
43 + public function __construct()
43 44 {
44 -
45 + do_action('uam_init', $this);
45 46 }
46 47
47 48 /**
48 49 * Creates the needed tables at the database
@@ -48,33 +49,24 @@
48 49 * Creates the needed tables at the database
49 50 *
50 51 * @return null;
51 52 */
52 - function install()
53 - {
53 + public function install()
54 + {
54 55 global $wpdb;
55 56 $uamDbVersion = $this->uamDbVersion;
56 57
57 58 include_once ABSPATH . 'wp-admin/includes/upgrade.php';
58 - $charset_collate = '';
59 +
60 + $charsetCollate = $this->_getCharset();
59 61
60 - if (version_compare(mysql_get_server_info(), '4.1.0', '>=')) {
61 - if (!empty($wpdb->charset)) {
62 - $charset_collate = "DEFAULT CHARACTER SET $wpdb->charset";
63 - }
64 -
65 - if (!empty($wpdb->collate)) {
66 - $charset_collate.= " COLLATE $wpdb->collate";
67 - }
68 - }
69 -
70 62 $dbUserGroup = $wpdb->get_var(
71 63 "SHOW TABLES
72 - LIKE '" . DB_ACCESSGROUP . "'"
64 + LIKE '".DB_ACCESSGROUP."'"
73 65 );
74 66
75 67 if ($dbUserGroup != DB_ACCESSGROUP) {
76 - $sql = "CREATE TABLE " . DB_ACCESSGROUP . " (
68 + $sql = "CREATE TABLE ".DB_ACCESSGROUP." (
77 69 ID int(11) NOT NULL auto_increment,
78 70 groupname tinytext NOT NULL,
79 71 groupdesc text NOT NULL,
80 72 read_access tinytext NOT NULL,
@@ -80,77 +72,47 @@
80 72 read_access tinytext NOT NULL,
81 73 write_access tinytext NOT NULL,
82 74 ip_range mediumtext NULL,
83 75 PRIMARY KEY (ID)
84 - ) $charset_collate;";
76 + ) $charsetCollate;";
85 77 dbDelta($sql);
86 78 }
87 -
88 - $dbUserGroupToPost = $wpdb->get_var(
79 +
80 + $dbUserGroupToObject = $wpdb->get_var(
89 81 "SHOW TABLES
90 - LIKE '" . DB_ACCESSGROUP_TO_POST . "'"
82 + LIKE '".DB_ACCESSGROUP_TO_OBJECT."'"
91 83 );
92 84
93 - if ($dbUserGroupToPost != DB_ACCESSGROUP_TO_POST) {
94 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_POST . " (
95 - post_id int(11) NOT NULL,
85 + if ($dbUserGroupToObject != DB_ACCESSGROUP_TO_OBJECT) {
86 + $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_OBJECT . " (
87 + object_id VARCHAR(11) NOT NULL,
88 + object_type varchar(255) NOT NULL,
96 89 group_id int(11) NOT NULL,
97 - PRIMARY KEY (post_id,group_id)
98 - ) $charset_collate;";
90 + PRIMARY KEY (object_id,object_type,group_id)
91 + ) $charsetCollate;";
99 92 dbDelta($sql);
100 93 }
101 94
102 - $dbUserGroupToUser = $wpdb->get_var(
103 - "SHOW TABLES
104 - LIKE '" . DB_ACCESSGROUP_TO_USER . "'"
105 - );
106 -
107 - if ($dbUserGroupToUser != DB_ACCESSGROUP_TO_USER) {
108 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_USER . " (
109 - user_id int(11) NOT NULL,
110 - group_id int(11) NOT NULL,
111 - PRIMARY KEY (user_id,group_id)
112 - ) $charset_collate;";
113 - dbDelta($sql);
114 - }
115 -
116 - $dbUserGroupToCategory = $wpdb->get_var(
117 - "SHOW TABLES
118 - LIKE '" . DB_ACCESSGROUP_TO_CATEGORY . "'"
119 - );
120 -
121 - if ($dbUserGroupToCategory != DB_ACCESSGROUP_TO_CATEGORY) {
122 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_CATEGORY . " (
123 - category_id int(11) NOT NULL,
124 - group_id int(11) NOT NULL,
125 - PRIMARY KEY (category_id,group_id)
126 - ) $charset_collate;";
127 - dbDelta($sql);
128 - }
129 -
130 - $dbUserGroupToRole = $wpdb->get_var(
131 - "SHOW TABLES
132 - LIKE '" . DB_ACCESSGROUP_TO_ROLE . "'"
133 - );
134 -
135 - if ($dbUserGroupToRole != DB_ACCESSGROUP_TO_ROLE) {
136 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_ROLE . " (
137 - role_name varchar(255) NOT NULL,
138 - group_id int(11) NOT NULL,
139 - PRIMARY KEY (role_name,group_id)
140 - ) $charset_collate;";
141 - dbDelta($sql);
142 - }
143 -
144 - add_option("uam_db_version", $uamDbVersion);
95 + add_option("uam_db_version", $this->uamDbVersion);
145 96 }
146 97
147 98 /**
148 - * Updates the database if an old version was installed.
99 + * Checks if a database update is necessary.
149 100 *
101 + * @return boolean
102 + */
103 + public function isDatabaseUpdateNecessary()
104 + {
105 + $currentDbVersion = get_option("uam_db_version");
106 + return version_compare($currentDbVersion, $this->uamDbVersion, '<');
107 + }
108 +
109 + /**
110 + * Updates the user access manager if an old version was installed.
111 + *
150 112 * @return null;
151 113 */
152 - function update()
114 + public function update()
153 115 {
154 116 global $wpdb;
155 117 $currentDbVersion = get_option("uam_db_version");
156 118
@@ -158,12 +120,10 @@
158 120 $this->install();
159 121 }
160 122
161 123 if (!get_option('uam_version')
162 - || get_option('uam_version') < $this->uamVersion
124 + || get_option('uam_version') < 1.0
163 125 ) {
164 - update_option('uam_version', $this->uamVersion);
165 -
166 126 delete_option('allow_comments_locked');
167 127 }
168 128
169 129 $dbUserGroup = $wpdb->get_var(
@@ -170,15 +130,13 @@
170 130 "SHOW TABLES
171 131 LIKE '" . DB_ACCESSGROUP . "'"
172 132 );
173 133
174 - if ($currentDbVersion != $this->uamDbVersion) {
134 + if ($currentDbVersion < $this->uamDbVersion) {
175 135 if ($currentDbVersion == 1.0) {
176 -
177 -
178 136 if ($dbUserGroup == DB_ACCESSGROUP) {
179 137 $wpdb->query(
180 - "ALTER TABLE " . DB_ACCESSGROUP . "
138 + "ALTER TABLE ".DB_ACCESSGROUP."
181 139 ADD read_access TINYTEXT NOT NULL DEFAULT '',
182 140 ADD write_access TINYTEXT NOT NULL DEFAULT '',
183 141 ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
184 142 );
@@ -183,31 +141,98 @@
183 141 ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
184 142 );
185 143
186 144 $wpdb->query(
187 - "UPDATE " . DB_ACCESSGROUP . "
145 + "UPDATE ".DB_ACCESSGROUP."
188 146 SET read_access = 'group',
189 147 write_access = 'group'"
190 148 );
191 149
192 - update_option('uam_db_version', $this->uamDbVersion);
150 + $dbIpRange = $wpdb->get_var(
151 + "SHOW columns
152 + FROM ".DB_ACCESSGROUP."
153 + LIKE 'ip_range'"
154 + );
155 +
156 + if ($dbIpRange != 'ip_range') {
157 + $wpdb->query(
158 + "ALTER TABLE ".DB_ACCESSGROUP."
159 + ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
160 + );
161 + }
193 162 }
194 - }
195 - }
196 -
197 - if ($dbUserGroup == DB_ACCESSGROUP) {
198 - $dbIpRange = $wpdb->get_var(
199 - "SHOW columns
200 - FROM " . DB_ACCESSGROUP . "
201 - LIKE 'ip_range'"
202 - );
163 +
164 + $currentDbVersion = 1.1;
165 + }
203 166
204 - if ($dbIpRange != 'ip_range') {
167 + if ($currentDbVersion == 1.1) {
168 + define('DB_ACCESSGROUP_TO_POST', $wpdb->prefix . 'uam_accessgroup_to_post');
169 + define('DB_ACCESSGROUP_TO_USER', $wpdb->prefix . 'uam_accessgroup_to_user');
170 + define('DB_ACCESSGROUP_TO_CATEGORY', $wpdb->prefix . 'uam_accessgroup_to_category');
171 + define('DB_ACCESSGROUP_TO_ROLE', $wpdb->prefix . 'uam_accessgroup_to_role');
172 +
173 + $charsetCollate = $this->_getCharset();
174 +
205 175 $wpdb->query(
206 - "ALTER TABLE " . DB_ACCESSGROUP . "
207 - ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
176 + "ALTER TABLE 'wp_uam_accessgroup_to_object'
177 + CHANGE 'object_id' 'object_id' VARCHAR(11)
178 + $charsetCollate;"
208 179 );
180 +
181 + $objectTypes = $this->getAccessHandler()->getObjectTypes();
182 +
183 + foreach ($objectTypes as $objectType) {
184 + $addition = '';
185 +
186 + if ($objectType == 'post'
187 + || $objectType == 'page'
188 + || $objectType == 'attachment'
189 + ) {
190 + $dbIdName = 'post_id';
191 + $database = DB_ACCESSGROUP_TO_POST.', '.$wpdb->posts;
192 + $addition = " WHERE post_id = ID
193 + AND post_type = '".$objectType."'";
194 + } elseif ($objectType == 'category') {
195 + $dbIdName = 'category_id';
196 + $database = DB_ACCESSGROUP_TO_CATEGORY;
197 + } elseif ($objectType == 'user') {
198 + $dbIdName = 'user_id';
199 + $database = DB_ACCESSGROUP_TO_USER;
200 + } elseif ($objectType == 'role') {
201 + $dbIdName = 'role_name';
202 + $database = DB_ACCESSGROUP_TO_ROLE;
203 + }
204 +
205 + $sql = "SELECT ".$dbIdName." as id, group_id as groupId
206 + FROM ".$database.$addition;
207 +
208 + $dbObjects = $wpdb->get_results($sql);
209 +
210 + foreach ($dbObjects as $dbObject) {
211 + $sql = "INSERT INTO ".DB_ACCESSGROUP_TO_OBJECT." (
212 + group_id,
213 + object_id,
214 + object_type
215 + )
216 + VALUES(
217 + '".$dbObject->groupId."',
218 + '".$dbObject->id."',
219 + '".$objectType."'
220 + )";
221 +
222 + $wpdb->query($sql);
223 + }
224 + }
225 +
226 + $wpdb->query(
227 + "DROP TABLE ".DB_ACCESSGROUP_TO_POST.",
228 + ".DB_ACCESSGROUP_TO_USER.",
229 + ".DB_ACCESSGROUP_TO_CATEGORY.",
230 + ".DB_ACCESSGROUP_TO_ROLE
231 + );
209 232 }
233 +
234 + update_option('uam_db_version', $this->uamDbVersion);
210 235 }
211 236 }
212 237
213 238 /**
@@ -214,17 +239,14 @@
214 239 * Clean up wordpress if the plugin will be uninstalled.
215 240 *
216 241 * @return null
217 242 */
218 - function uninstall()
243 + public function uninstall()
219 244 {
220 245 global $wpdb;
221 246 $wpdb->query(
222 - "DROP TABLE " . DB_ACCESSGROUP . ",
223 - " . DB_ACCESSGROUP_TO_POST . ",
224 - " . DB_ACCESSGROUP_TO_USER . ",
225 - " . DB_ACCESSGROUP_TO_CATEGORY . ",
226 - " . DB_ACCESSGROUP_TO_ROLE
247 + "DROP TABLE ".DB_ACCESSGROUP.",
248 + ".DB_ACCESSGROUP_TO_OBJECT
227 249 );
228 250
229 251 delete_option($this->adminOptionsName);
230 252 delete_option('uam_version');
@@ -232,13 +254,35 @@
232 254 $this->deleteHtaccessFiles();
233 255 }
234 256
235 257 /**
258 + * Returns the database charset.
259 + *
260 + * @return string
261 + */
262 + private function _getCharset()
263 + {
264 + $charsetCollate = '';
265 +
266 + if (version_compare(mysql_get_server_info(), '4.1.0', '>=')) {
267 + if (!empty($wpdb->charset)) {
268 + $charsetCollate = "DEFAULT CHARACTER SET $wpdb->charset";
269 + }
270 +
271 + if (!empty($wpdb->collate)) {
272 + $charsetCollate.= " COLLATE $wpdb->collate";
273 + }
274 + }
275 +
276 + return $charsetCollate;
277 + }
278 +
279 + /**
236 280 * Remove the htaccess file if the plugin is deactivated.
237 281 *
238 282 * @return null
239 283 */
240 - function deactivate()
284 + public function deactivate()
241 285 {
242 286 $this->deleteHtaccessFiles();
243 287 }
244 288
@@ -244,21 +288,29 @@
244 288
245 289 /**
246 290 * Creates a htaccess file.
247 291 *
292 + * @param string $dir The destination directory.
293 + * @param string $objectType The object type.
294 + *
248 295 * @return null.
249 296 */
250 - function createHtaccess()
297 + public function createHtaccess($dir = null, $objectType = null)
251 298 {
252 - // Make .htaccess file to protect data
253 - // get url
254 -
255 - $wud = wp_upload_dir();
256 - if (empty($wud['error'])) {
257 - $dir = $wud['basedir'] . "/";
258 - $permaStruc = get_option('permalink_structure');
299 + if ($dir === null) {
300 + $wud = wp_upload_dir();
259 301
260 - if (empty($permaStruc)) {
302 + if (empty($wud['error'])) {
303 + $dir = $wud['basedir'] . "/";
304 + }
305 + }
306 +
307 + if ($objectType === null) {
308 + $objectType = 'attachment';
309 + }
310 +
311 + if ($dir !== null) {
312 + if (!$this->isPermalinksActive()) {
261 313 $areaname = "WP-Files";
262 314 $uamOptions = $this->getAdminOptions();
263 315
264 316 if ($uamOptions['lock_file_types'] == 'selected') {
@@ -301,14 +353,15 @@
301 353 $htaccessTxt = "<IfModule mod_rewrite.c>\n";
302 354 $htaccessTxt .= "RewriteEngine On\n";
303 355 $htaccessTxt .= "RewriteBase ".$homeRoot."\n";
304 356 $htaccessTxt .= "RewriteRule ^index\.php$ - [L]\n";
305 - $htaccessTxt .= "RewriteRule (.*) ".$homeRoot."index.php?getfile=$1 [L]\n";
357 + $htaccessTxt .= "RewriteRule (.*) ";
358 + $htaccessTxt .= $homeRoot."index.php?uamfiletype=".$objectType."&uamgetfile=$1 [L]\n";
306 359 $htaccessTxt .= "</IfModule>\n";
307 360 }
308 361
309 362 // save files
310 - $htaccess = fopen($dir . ".htaccess", "w");
363 + $htaccess = fopen($dir.".htaccess", "w");
311 364 fwrite($htaccess, $htaccessTxt);
312 365 fclose($htaccess);
313 366 }
314 367 }
@@ -316,88 +369,45 @@
316 369 /**
317 370 * Creates a htpasswd file.
318 371 *
319 372 * @param boolean $createNew Force to create new file.
373 + * @param string $dir The destination directory.
320 374 *
321 375 * @return null
322 376 */
323 - function createHtpasswd($createNew = false)
377 + public function createHtpasswd($createNew = false, $dir = null)
324 378 {
325 379 global $current_user;
380 +
326 381 $uamOptions = $this->getAdminOptions();
327 382
328 383 // get url
329 - $wud = wp_upload_dir();
330 - if (empty($wud['error'])) {
331 - $url = $wud['basedir'] . "/";
384 + if ($dir === null) {
385 + $wud = wp_upload_dir();
386 +
387 + if (empty($wud['error'])) {
388 + $dir = $wud['basedir'] . "/";
389 + }
390 + }
391 +
392 + if ($dir !== null) {
332 393 $curUserdata = get_userdata($current_user->ID);
333 - $user = $curUserdata->user_login;
334 394
335 - if (!file_exists($url . ".htpasswd") || $createNew) {
395 + if (!file_exists($dir.".htpasswd") || $createNew) {
336 396 if ($uamOptions['file_pass_type'] == 'random') {
337 - // create password
338 - $array = array();
339 - $length = 10;
340 - $capitals = true;
341 - $specialSigns = false;
342 - if ($length < 8) {
343 - $length = mt_rand(8, 20);
344 - }
345 -
346 - // numbers
347 - for ($i = 48; $i < 58; $i++) {
348 - $array[] = chr($i);
349 - }
350 -
351 - // small
352 - for ($i = 97; $i < 122; $i++) {
353 - $array[] = chr($i);
354 - }
355 -
356 - // capitals
357 - if ($capitals) {
358 - for ($i = 65; $i < 90; $i++) {
359 - $array[] = chr($i);
360 - }
361 - }
362 -
363 - // specialchar:
364 - if ($specialSigns) {
365 - for ($i = 33; $i < 47; $i++) {
366 - $array[] = chr($i);
367 - }
368 -
369 - for ($i = 59; $i < 64; $i++) {
370 - $array[] = chr($i);
371 - }
372 -
373 - for ($i = 91; $i < 96; $i++) {
374 - $array[] = chr($i);
375 - }
376 -
377 - for ($i = 123; $i < 126; $i++) {
378 - $array[] = chr($i);
379 - }
380 - }
381 -
382 - mt_srand((double)microtime() * 1000000);
383 - $password = '';
384 -
385 - for ($i = 1; $i <= $length; $i++) {
386 - $rnd = mt_rand(0, count($array) - 1);
387 - $password.= $array[$rnd];
388 - $password = md5($password);
389 - }
397 + $password = md5($this->getRandomPassword());
390 398 } elseif ($uamOptions['file_pass_type'] == 'admin') {
391 399 $password = $curUserdata->user_pass;
392 400 }
401 +
402 + $user = $curUserdata->user_login;
393 403
394 404 // make .htpasswd
395 - $htpasswd_txt = "$user:" . $password . "\n";
396 -
405 + $htpasswdTxt = "$user:" . $password . "\n";
406 +
397 407 // save file
398 - $htpasswd = fopen($url . ".htpasswd", "w");
399 - fwrite($htpasswd, $htpasswd_txt);
408 + $htpasswd = fopen($dir.".htpasswd", "w");
409 + fwrite($htpasswd, $htpasswdTxt);
400 410 fclose($htpasswd);
401 411 }
402 412 }
403 413 }
@@ -404,32 +414,102 @@
404 414
405 415 /**
406 416 * Deletes the htaccess files.
407 417 *
418 + * @param string $dir The destination directory.
419 + *
408 420 * @return null
409 421 */
410 - function deleteHtaccessFiles()
422 + public function deleteHtaccessFiles($dir = null)
411 423 {
412 - $wud = wp_upload_dir();
413 - if (empty($wud['error'])) {
414 - $url = $wud['basedir'] . "/";
424 + if ($dir === null) {
425 + $wud = wp_upload_dir();
415 426
416 - if (file_exists($url.".htaccess")) {
417 - unlink($url.".htaccess");
427 + if (empty($wud['error'])) {
428 + $dir = $wud['basedir'] . "/";
418 429 }
430 + }
431 +
432 + if ($dir !== null) {
433 + if (file_exists($dir.".htaccess")) {
434 + unlink($dir.".htaccess");
435 + }
419 436
420 - if (file_exists($url.".htpasswd")) {
421 - unlink($url.".htpasswd");
437 + if (file_exists($dir.".htpasswd")) {
438 + unlink($dir.".htpasswd");
422 439 }
423 440 }
424 441 }
425 442
426 443 /**
444 + * Generates and retruns a randmom password.
445 + *
446 + * @return string
447 + */
448 + public function getRandomPassword()
449 + {
450 + //create password
451 + $array = array();
452 + $length = 16;
453 + $capitals = true;
454 + $specialSigns = false;
455 + if ($length < 8) {
456 + $length = mt_rand(8, 20);
457 + }
458 +
459 + // numbers
460 + for ($i = 48; $i < 58; $i++) {
461 + $array[] = chr($i);
462 + }
463 +
464 + // small
465 + for ($i = 97; $i < 122; $i++) {
466 + $array[] = chr($i);
467 + }
468 +
469 + // capitals
470 + if ($capitals) {
471 + for ($i = 65; $i < 90; $i++) {
472 + $array[] = chr($i);
473 + }
474 + }
475 +
476 + // specialchar:
477 + if ($specialSigns) {
478 + for ($i = 33; $i < 47; $i++) {
479 + $array[] = chr($i);
480 + }
481 +
482 + for ($i = 59; $i < 64; $i++) {
483 + $array[] = chr($i);
484 + }
485 +
486 + for ($i = 91; $i < 96; $i++) {
487 + $array[] = chr($i);
488 + }
489 +
490 + for ($i = 123; $i < 126; $i++) {
491 + $array[] = chr($i);
492 + }
493 + }
494 +
495 + mt_srand((double)microtime() * 1000000);
496 + $password = '';
497 +
498 + for ($i = 1; $i <= $length; $i++) {
499 + $rnd = mt_rand(0, count($array) - 1);
500 + $password.= $array[$rnd];
501 + }
502 +
503 + return $password;
504 + }
505 +
506 + /**
427 507 * Returns the current settings
428 508 *
429 509 * @return array
430 510 */
431 - function getAdminOptions()
511 + public function getAdminOptions()
432 512 {
433 513 if (empty($this->adminOptions)) {
434 514 $uamAdminOptions = array(
435 515 'hide_post_title' => 'false',
@@ -495,14 +575,15 @@
495 575
496 576 /**
497 577 * Retruns the content of the excecuded php file.
498 578 *
499 - * @param string $fileName The file name
500 - * @param integer $id The id if needed.
579 + * @param string $fileName The file name
580 + * @param integer $objectId The id if needed.
581 + * @param string $objectType The object type if needed.
501 582 *
502 583 * @return string
503 584 */
504 - function getIncludeContents($fileName, $id = null)
585 + public function getIncludeContents($fileName, $objectId = null, $objectType = null)
505 586 {
506 587 if (is_file($fileName)) {
507 588 ob_start();
508 589 include $fileName;
@@ -519,9 +600,9 @@
519 600 * Returns the access handler object.
520 601 *
521 602 * @return object
522 603 */
523 - function &getAccessHandler()
604 + public function &getAccessHandler()
524 605 {
525 606 if ($this->accessHandler == null) {
526 607 $this->accessHandler = new UamAccessHandler(&$this);
527 608 }
@@ -530,8 +611,26 @@
530 611 }
531 612
532 613
533 614 /*
615 + * Helper functions.
616 + */
617 +
618 + /**
619 + * Checks if a string starts with the given needle.
620 + *
621 + * @param string $haystack The haystack.
622 + * @param string $needle The needle
623 + *
624 + * @return boolean
625 + */
626 + public function startsWith($haystack, $needle)
627 + {
628 + return strpos($haystack, $needle) === 0;
629 + }
630 +
631 +
632 + /*
534 633 * Functions for the admin panel content.
535 634 */
536 635
537 636 /**
@@ -538,9 +637,9 @@
538 637 * The function for the wp_print_styles action.
539 638 *
540 639 * @return null
541 640 */
542 - function addStyles()
641 + public function addStyles()
543 642 {
544 643 wp_enqueue_style(
545 644 'UserAccessManagerAdmin',
546 645 UAM_URLPATH . "css/uamAdmin.css",
@@ -562,9 +661,9 @@
562 661 * The function for the wp_print_scripts action.
563 662 *
564 663 * @return null
565 664 */
566 - function addScripts()
665 + public function addScripts()
567 666 {
568 667 wp_enqueue_script(
569 668 'UserAccessManagerJQueryTools',
570 669 UAM_URLPATH . 'js/jquery.tools.min.js',
@@ -581,9 +680,9 @@
581 680 * Prints the admin page
582 681 *
583 682 * @return null
584 683 */
585 - function printAdminPage()
684 + public function printAdminPage()
586 685 {
587 686 if (isset($_GET['page'])) {
588 687 $curAdminPage = $_GET['page'];
589 688 }
@@ -603,9 +702,9 @@
603 702 * Shows the error if the user has no rights to edit the content
604 703 *
605 704 * @return null
606 705 */
607 - function noRightsToEditContent()
706 + public function noRightsToEditContent()
608 707 {
609 708 $noRights = false;
610 709
611 710 if (isset($_GET['post'])
@@ -610,10 +709,14 @@
610 709
611 710 if (isset($_GET['post'])
612 711 && is_numeric($_GET['post'])
613 712 ) {
614 - $noRights
615 - = !$this->getAccessHandler()->checkAccess($_GET['post']);
713 + $post = get_post($_GET['post']);
714 +
715 + $noRights = !$this->getAccessHandler()->checkObjectAccess(
716 + $post->post_type,
717 + $post->ID
718 + );
616 719 }
617 720
618 721 if (isset($_GET['attachment_id'])
619 722 && is_numeric($_GET['attachment_id'])
@@ -618,10 +721,14 @@
618 721 if (isset($_GET['attachment_id'])
619 722 && is_numeric($_GET['attachment_id'])
620 723 && !$noRights
621 724 ) {
622 - $noRights
623 - = !$this->getAccessHandler()->checkAccess($_GET['attachment_id']);
725 + $post = get_post($_GET['attachment_id']);
726 +
727 + $noRights = !$this->getAccessHandler()->checkObjectAccess(
728 + $post->post_type,
729 + $post->ID
730 + );
624 731 }
625 732
626 733 if (isset($_GET['tag_ID'])
627 734 && is_numeric($_GET['tag_ID'])
@@ -626,10 +733,12 @@
626 733 if (isset($_GET['tag_ID'])
627 734 && is_numeric($_GET['tag_ID'])
628 735 && !$noRights
629 736 ) {
630 - $noRights
631 - = !$this->getAccessHandler()->checkCategoryAccess($_GET['tag_ID']);
737 + $noRights = !$this->getAccessHandler()->checkObjectAccess(
738 + 'category',
739 + $_GET['tag_ID']
740 + );
632 741 }
633 742
634 743 if ($noRights) {
635 744 wp_die(TXT_NO_RIGHTS);
@@ -641,9 +750,9 @@
641 750 * Removes widgets to which a user should not have access.
642 751 *
643 752 * @return null
644 753 */
645 - function setupAdminDashboard()
754 + public function setupAdminDashboard()
646 755 {
647 756 global $wp_meta_boxes;
648 757
649 758 if (!$this->getAccessHandler()->checkUserAccess()) {
@@ -655,14 +764,65 @@
655 764 * The function for the update_option_permalink_structure action.
656 765 *
657 766 * @return null
658 767 */
659 - function updatePermalink()
768 + public function updatePermalink()
660 769 {
661 770 $this->createHtaccess();
771 + $this->createHtpasswd();
662 772 }
663 773
774 + /*
775 + * Meta functions
776 + */
777 +
664 778 /**
779 + * Saves the object data to the database.
780 + *
781 + * @param string $objectType The object type.
782 + * @param integer $objectId The id of the object.
783 + *
784 + * @return null
785 + */
786 + private function _saveObjectData($objectType, $objectId)
787 + {
788 + $uamAccessHandler = &$this->getAccessHandler();
789 + $uamOptions = $this->getAdminOptions();
790 +
791 + if (isset($_POST['uam_update_groups'])
792 + && ($uamAccessHandler->checkUserAccess()
793 + || $uamOptions['authors_can_add_posts_to_groups'] == 'true')
794 + ) {
795 + $userGroupsForObject = $uamAccessHandler->getUserGroupsForObject(
796 + $objectType,
797 + $objectId
798 + );
799 +
800 + foreach ($userGroupsForObject as $uamUserGroup) {
801 + $uamUserGroup->removeObject($objectType, $objectId);
802 + $uamUserGroup->save();
803 + }
804 +
805 + if (isset($_POST['uam_usergroups'])) {
806 + $userGroups = $_POST['uam_usergroups'];
807 + }
808 +
809 + if (isset($userGroups)) {
810 + foreach ($userGroups as $userGroupId) {
811 + $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId);
812 +
813 + $uamUserGroup->addObject($objectType, $objectId);
814 + $uamUserGroup->save();
815 + }
816 + }
817 + }
818 + }
819 +
820 + /*
821 + * Functions for the post actions.
822 + */
823 +
824 + /**
665 825 * The function for the manage_posts_columns and
666 826 * the manage_pages_columns filter.
667 827 *
668 828 * @param array $defaults The table headers.
@@ -668,9 +828,9 @@
668 828 * @param array $defaults The table headers.
669 829 *
670 830 * @return array
671 831 */
672 - function addPostColumnsHeader($defaults)
832 + public function addPostColumnsHeader($defaults)
673 833 {
674 834 $defaults['uam_access'] = __('Access');
675 835 return $defaults;
676 836 }
@@ -682,12 +842,18 @@
682 842 * @param integer $id The id.
683 843 *
684 844 * @return String
685 845 */
686 - function addPostColumn($columnName, $id)
846 + public function addPostColumn($columnName, $id)
687 847 {
688 848 if ($columnName == 'uam_access') {
689 - echo $this->getIncludeContents(UAM_REALPATH.'tpl/postColumn.php', $id);
849 + $post = get_post($id);
850 +
851 + echo $this->getIncludeContents(
852 + UAM_REALPATH.'tpl/objectColumn.php',
853 + $post->ID,
854 + $post->post_type
855 + );
690 856 }
691 857 }
692 858
693 859 /**
@@ -696,10 +862,12 @@
696 862 * @param object $post The post.
697 863 *
698 864 * @return null;
699 865 */
700 - function editPostContent($post)
866 + public function editPostContent($post)
701 867 {
868 + $objectId = $post->ID;
869 +
702 870 include UAM_REALPATH.'tpl/postEditForm.php';
703 871 }
704 872
705 873 /**
@@ -708,57 +876,26 @@
708 876 * @param mixed $postParam The post id or a array of a post.
709 877 *
710 878 * @return null
711 879 */
712 - function savePostData($postParam)
713 - {
714 - $uamAccessHandler = &$this->getAccessHandler();
715 - $uamOptions = $this->getAdminOptions();
880 + public function savePostData($postParam)
881 + {
882 + if (is_array($postParam)) {
883 + $post = get_post($postParam['ID']);
884 + } else {
885 + $post = get_post($postParam);
886 + }
887 +
888 + $postId = $post->ID;
889 + $postType = $post->post_type;
716 890
717 - if ($uamAccessHandler->checkUserAccess()
718 - || $uamOptions['authors_can_add_posts_to_groups'] == 'true'
719 - ) {
720 - if (is_array($postParam)) {
721 - $post = get_post($postParam['ID']);
722 - } else {
723 - $post = get_post($postParam);
724 - }
725 -
726 - if ($post->post_type == 'revision') {
727 - $postId = $post->post_parent;
728 - $post = get_post($postId);
729 - } else {
730 - $postId = $post->ID;
731 - }
732 -
733 - if ($post->post_type == 'post') {
734 - $postType = 'Post';
735 - } elseif ($post->post_type == 'page') {
736 - $postType = 'Page';
737 - } elseif ($post->post_type == 'attachment') {
738 - $postType = 'File';
739 - }
740 -
741 - $userGroupsForPost = $uamAccessHandler->getUserGroupsForPost($postId);
742 -
743 - foreach ($userGroupsForPost as $uamUserGroup) {
744 - $uamUserGroup->{'remove'.$postType}($postId);
745 - $uamUserGroup->save();
746 - }
747 -
748 - if (isset($_POST['usergroups'])) {
749 - $userGroups = $_POST['usergroups'];
750 - }
751 -
752 - if (isset($userGroups)) {
753 - foreach ($userGroups as $userGroupId) {
754 - $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId);
755 -
756 - $uamUserGroup->{'add'.$postType}($postId);
757 - $uamUserGroup->save();
758 - }
759 - }
891 + if ($postType == 'revision') {
892 + $postId = $post->post_parent;
893 + $parentPost = get_post($postId);
894 + $postType = $parentPost->post_type;
760 895 }
896 +
897 + $this->_saveObjectData($postType, $postId);
761 898 }
762 899
763 900 /**
764 901 * The function for the attachment_fields_to_save filter.
@@ -768,9 +905,9 @@
768 905 * @param object $attachment The attachment id.
769 906 *
770 907 * @return object
771 908 */
772 - function saveAttachmentData($attachment)
909 + public function saveAttachmentData($attachment)
773 910 {
774 911 $this->savePostData($attachment['ID']);
775 912
776 913 return $attachment;
@@ -782,9 +919,9 @@
782 919 * @param integer $postId The post id.
783 920 *
784 921 * @return null
785 922 */
786 - function removePostData($postId)
923 + public function removePostData($postId)
787 924 {
788 925 global $wpdb;
789 926
790 927 $wpdb->query(
@@ -800,10 +937,10 @@
800 937 * @param object $post The post.
801 938 *
802 939 * @return string
803 940 */
804 - function showMediaFile($meta = '', $post = null)
805 - {
941 + public function showMediaFile($meta = '', $post = null)
942 + {
806 943 $content = $meta;
807 944 $content .= '</td></tr><tr>';
808 945 $content .= '<th class="label">';
809 946 $content .= '<label>'.TXT_SET_UP_USERGROUPS.'</label>';
@@ -808,13 +945,21 @@
808 945 $content .= '<th class="label">';
809 946 $content .= '<label>'.TXT_SET_UP_USERGROUPS.'</label>';
810 947 $content .= '</th>';
811 948 $content .= '<td class="field">';
812 - $content .= $this->getIncludeContents(UAM_REALPATH.'tpl/postEditForm.php');
949 + $content .= $this->getIncludeContents(
950 + UAM_REALPATH.'tpl/postEditForm.php',
951 + $post->ID
952 + );
813 953
814 954 return $content;
815 955 }
816 956
957 +
958 + /*
959 + * Functions for the user actions.
960 + */
961 +
817 962 /**
818 963 * The function for the manage_users_columns filter.
819 964 *
820 965 * @param array $defaults The table headers.
@@ -820,9 +965,9 @@
820 965 * @param array $defaults The table headers.
821 966 *
822 967 * @return array
823 968 */
824 - function addUserColumnsHeader($defaults)
969 + public function addUserColumnsHeader($defaults)
825 970 {
826 971 $defaults['uam_access'] = __('uam user groups');
827 972 return $defaults;
828 973 }
@@ -835,14 +980,15 @@
835 980 * @param integer $id The id.
836 981 *
837 982 * @return String
838 983 */
839 - function addUserColumn($empty, $columnName, $id)
984 + public function addUserColumn($empty, $columnName, $id)
840 985 {
841 986 if ($columnName == 'uam_access') {
842 987 return $this->getIncludeContents(
843 988 UAM_REALPATH.'tpl/userColumn.php',
844 - $id
989 + $id,
990 + 'user'
845 991 );
846 992 }
847 993 }
848 994
@@ -850,9 +996,9 @@
850 996 * The function for the edit_user_profile action.
851 997 *
852 998 * @return null
853 999 */
854 - function showUserProfile()
1000 + public function showUserProfile()
855 1001 {
856 1002 echo $this->getIncludeContents(UAM_REALPATH.'tpl/userProfileEditForm.php');
857 1003 }
858 1004
@@ -862,37 +1008,11 @@
862 1008 * @param integer $userId The user id.
863 1009 *
864 1010 * @return null
865 1011 */
866 - function saveUserData($userId)
1012 + public function saveUserData($userId)
867 1013 {
868 - $uamAccessHandler = &$this->getAccessHandler();
869 -
870 - if ($uamAccessHandler->checkUserAccess()) {
871 - if ($uamAccessHandler->checkUserAccess()) {
872 - $userGroupsForPost
873 - = $uamAccessHandler->getUserGroupsForUser($userId);
874 -
875 - foreach ($userGroupsForPost as $uamUserGroup) {
876 - $uamUserGroup->removeUser($userId);
877 - $uamUserGroup->save();
878 - }
879 -
880 - if (isset($_POST['usergroups'])) {
881 - $userGroups = $_POST['usergroups'];
882 - }
883 -
884 - if (isset($userGroups)) {
885 - foreach ($userGroups as $userGroupId) {
886 - $uamUserGroup
887 - = $uamAccessHandler->getUserGroups($userGroupId);
888 -
889 - $uamUserGroup->addUser($userId);
890 - $uamUserGroup->save();
891 - }
892 - }
893 - }
894 - }
1014 + $this->_saveObjectData('user', $userId);
895 1015 }
896 1016
897 1017 /**
898 1018 * The function for the delete_user action.
@@ -900,9 +1020,9 @@
900 1020 * @param integer $userId The user id.
901 1021 *
902 1022 * @return null
903 1023 */
904 - function removeUserData($userId)
1024 + public function removeUserData($userId)
905 1025 {
906 1026 global $wpdb;
907 1027
908 1028 $wpdb->query(
@@ -910,8 +1030,13 @@
910 1030 WHERE user_id = ".$userId
911 1031 );
912 1032 }
913 1033
1034 +
1035 + /*
1036 + * Functions for the category actions.
1037 + */
1038 +
914 1039 /**
915 1040 * The function for the manage_categories_columns filter.
916 1041 *
917 1042 * @param array $defaults The table headers.
@@ -917,9 +1042,9 @@
917 1042 * @param array $defaults The table headers.
918 1043 *
919 1044 * @return array
920 1045 */
921 - function addCategoryColumnsHeader($defaults)
1046 + public function addCategoryColumnsHeader($defaults)
922 1047 {
923 1048 $defaults['uam_access'] = __('Access');
924 1049 return $defaults;
925 1050 }
@@ -932,14 +1057,15 @@
932 1057 * @param integer $id The id.
933 1058 *
934 1059 * @return String
935 1060 */
936 - function addCategoryColumn($empty, $columnName, $id)
1061 + public function addCategoryColumn($empty, $columnName, $id)
937 1062 {
938 1063 if ($columnName == 'uam_access') {
939 1064 return $this->getIncludeContents(
940 - UAM_REALPATH.'tpl/categoryColumn.php',
941 - $id
1065 + UAM_REALPATH.'tpl/objectColumn.php',
1066 + $id,
1067 + 'category'
942 1068 );
943 1069 }
944 1070 }
945 1071
@@ -949,9 +1075,9 @@
949 1075 * @param object $category The category.
950 1076 *
951 1077 * @return null
952 1078 */
953 - function showCategoryEditForm($category)
1079 + public function showCategoryEditForm($category)
954 1080 {
955 1081 include UAM_REALPATH.'tpl/categoryEditForm.php';
956 1082 }
957 1083
@@ -961,37 +1087,11 @@
961 1087 * @param integer $categoryId The category id.
962 1088 *
963 1089 * @return null
964 1090 */
965 - function saveCategoryData($categoryId)
1091 + public function saveCategoryData($categoryId)
966 1092 {
967 - $uamAccessHandler = &$this->getAccessHandler();
968 - $uamOptions = $this->getAdminOptions();
969 -
970 - if ($uamAccessHandler->checkUserAccess()
971 - || $uamOptions['authors_can_add_posts_to_groups'] == 'true'
972 - ) {
973 - $userGroupsForCategory
974 - = $uamAccessHandler->getUserGroupsForCategory($categoryId);
975 -
976 - foreach ($userGroupsForCategory as $uamUserGroup) {
977 - $uamUserGroup->removeCategory($categoryId);
978 - $uamUserGroup->save();
979 - }
980 -
981 - if (isset($_POST['usergroups'])) {
982 - $userGroups = $_POST['usergroups'];
983 - }
984 -
985 - if (isset($userGroups)) {
986 - foreach ($userGroups as $userGroupId) {
987 - $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId);
988 -
989 - $uamUserGroup->addCategory($categoryId);
990 - $uamUserGroup->save();
991 - }
992 - }
993 - }
1093 + $this->_saveObjectData('category', $categoryId);
994 1094 }
995 1095
996 1096 /**
997 1097 * The function for the delete_category action.
@@ -999,9 +1099,9 @@
999 1099 * @param integer $categoryId The id of the category.
1000 1100 *
1001 1101 * @return null
1002 1102 */
1003 - function removeCategoryData($categoryId)
1103 + public function removeCategoryData($categoryId)
1004 1104 {
1005 1105 global $wpdb;
1006 1106
1007 1107 $wpdb->query(
@@ -1008,15 +1108,111 @@
1008 1108 "DELETE FROM " . DB_ACCESSGROUP_TO_CATEGORY . "
1009 1109 WHERE category_id = ".$categoryId
1010 1110 );
1011 1111 }
1112 +
1012 1113
1114 + /*
1115 + * Functions for the pluggable object actions.
1116 + */
1013 1117
1118 + /**
1119 + * The function for the pluggable save action.
1120 + *
1121 + * @param string $objectType The name of the pluggable object.
1122 + * @param integer $objectId The pluggable object id.
1123 + *
1124 + * @return null
1125 + */
1126 + public function savePlObjectData($objectType, $objectId)
1127 + {
1128 + $this->_saveObjectData($objectType, $objectId);
1129 + }
1130 +
1131 + /**
1132 + * The function for the pluggable remove action.
1133 + *
1134 + * @param string $objectName The name of the pluggable object.
1135 + * @param integer $objectId The pluggable object id.
1136 + *
1137 + * @return null
1138 + */
1139 + public function removePlObjectData($objectName, $objectId)
1140 + {
1141 + global $wpdb;
1142 +
1143 + $wpdb->query(
1144 + "DELETE FROM " . DB_ACCESSGROUP_TO_OBJECT . "
1145 + WHERE user_id = ".$userId."
1146 + AND object_type = ".$objectName
1147 + );
1148 + }
1149 +
1150 + /**
1151 + * Returns the group selection form for pluggable objects.
1152 + *
1153 + * @param string $objectType The object type.
1154 + * @param integer $objectId The id of the object.
1155 + *
1156 + * @return string;
1157 + */
1158 + public function showPlGroupSelectionForm($objectType, $objectId)
1159 + {
1160 + $fileName = UAM_REALPATH.'tpl/groupSelectionForm.php';
1161 + $uamUserGroups = $this->getAccessHandler()->getUserGroups();
1162 + $userGroupsForObject = $this->getAccessHandler()->getUserGroupsForObject(
1163 + $objectType,
1164 + $objectId
1165 + );
1166 +
1167 + if (is_file($fileName)) {
1168 + ob_start();
1169 + include $fileName;
1170 + $contents = ob_get_contents();
1171 + ob_end_clean();
1172 +
1173 + return $contents;
1174 + }
1175 +
1176 + return '';
1177 + }
1178 +
1179 + /**
1180 + * Returns the column for a pluggable object.
1181 + *
1182 + * @param string $objectType The object type.
1183 + * @param integer $objectId The object id.
1184 + *
1185 + * @return string
1186 + */
1187 + public function getPlColumn($objectType, $objectId)
1188 + {
1189 + return $this->getIncludeContents(
1190 + UAM_REALPATH.'tpl/objectColumn.php',
1191 + $objectId,
1192 + $objectType
1193 + );
1194 + }
1195 +
1196 +
1014 1197 /*
1015 1198 * Functions for the blog content.
1016 1199 */
1017 1200
1018 1201 /**
1202 + * Manipulates the wordpress query object to filter content.
1203 + *
1204 + * @param object $wpQuery The wordpress query object.
1205 + *
1206 + * @return null
1207 + */
1208 + public function parseQuery($wpQuery)
1209 + {
1210 + $wpQuery->query_vars['post__not_in']
1211 + += $this->_getExcludedPosts();
1212 + }
1213 +
1214 + /**
1019 1215 * Modifies the content of the post by the given settings.
1020 1216 *
1021 1217 * @param object $post The current post.
1022 1218 *
@@ -1037,15 +1233,17 @@
1037 1233
1038 1234 if ($uamOptions['hide_'.$postType] == 'true'
1039 1235 || $this->atAdminPanel
1040 1236 ) {
1041 - if ($uamAccessHandler->checkAccess($post->ID)) {
1042 - $post->post_title .= $this->adminOutput($post->ID);
1237 + if ($uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1238 + $post->post_title .= $this->adminOutput($post->post_type, $post->ID);
1043 1239
1044 1240 return $post;
1045 1241 }
1046 1242 } else {
1047 - if (!$uamAccessHandler->checkAccess($post->ID)) {
1243 + if (!$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1244 + $post->isLocked = true;
1245 +
1048 1246 $uamPostContent = $uamOptions[$postType.'_content'];
1049 1247 $uamPostContent = str_replace(
1050 1248 "[LOGIN_FORM]",
1051 1249 $this->getLoginBarHtml(),
@@ -1075,9 +1273,9 @@
1075 1273
1076 1274 $post->post_content = $uamPostContent;
1077 1275 }
1078 1276
1079 - $post->post_title .= $this->adminOutput($post->ID);
1277 + $post->post_title .= $this->adminOutput($post->post_type, $post->ID);
1080 1278
1081 1279 return $post;
1082 1280 }
1083 1281
@@ -1090,9 +1288,9 @@
1090 1288 * @param arrray $posts The posts.
1091 1289 *
1092 1290 * @return array
1093 1291 */
1094 - function showPost($posts = array())
1292 + public function showPost($posts = array())
1095 1293 {
1096 1294 $showPosts = array();
1097 1295 $uamOptions = $this->getAdminOptions();
1098 1296
@@ -1113,8 +1311,118 @@
1113 1311 return $posts;
1114 1312 }
1115 1313
1116 1314 /**
1315 + * Returns the excluded posts.
1316 + *
1317 + * @return array
1318 + */
1319 + private function _getExcludedPosts()
1320 + {
1321 + $uamAccessHandler = &$this->getAccessHandler();
1322 +
1323 + if ($uamAccessHandler->checkUserAccess()) {
1324 + return array();
1325 + }
1326 +
1327 + global $current_user, $wpdb;
1328 + //Force user infos
1329 + wp_get_current_user();
1330 +
1331 + $userUserGroups = $uamAccessHandler->getUserGroupsForObject(
1332 + 'user',
1333 + $current_user->ID,
1334 + false
1335 + );
1336 +
1337 + $userUserGroupArray = array();
1338 +
1339 + foreach ($userUserGroups as $userUserGroup) {
1340 + $userUserGroupArray[] = $userUserGroup->getId();
1341 + }
1342 +
1343 + if ($userUserGroupArray !== array()) {
1344 + $userUserGroupString = implode(', ', $userUserGroupArray);
1345 + } else {
1346 + $userUserGroupString = 'NULL';
1347 + }
1348 +
1349 + $postSql = "SELECT DISTINCT p.ID
1350 + FROM $wpdb->posts AS p
1351 + INNER JOIN $wpdb->term_relationships AS tr
1352 + ON p.ID = tr.object_id
1353 + INNER JOIN $wpdb->term_taxonomy tt
1354 + ON tr.term_taxonomy_id = tt.term_taxonomy_id
1355 + WHERE tt.taxonomy = 'category'
1356 + AND tt.term_id IN (
1357 + SELECT gc.object_id
1358 + FROM ".DB_ACCESSGROUP_TO_OBJECT." gc
1359 + WHERE gc.object_type = 'category'
1360 + AND gc.object_id NOT IN (
1361 + SELECT igc.object_id
1362 + FROM ".DB_ACCESSGROUP_TO_OBJECT." igc
1363 + WHERE igc.object_type = 'category'
1364 + AND igc.group_id IN (".$userUserGroupString.")
1365 + )
1366 + ) AND p.ID NOT IN (
1367 + SELECT igp.object_id
1368 + FROM ".DB_ACCESSGROUP_TO_OBJECT." igp
1369 + WHERE (igp.object_type = 'post' OR igp.object_type = 'page')
1370 + AND igp.group_id IN (".$userUserGroupString.")
1371 + )
1372 + UNION
1373 + SELECT DISTINCT gp.object_id
1374 + FROM ".DB_ACCESSGROUP_TO_OBJECT." gp
1375 + INNER JOIN $wpdb->term_relationships AS tr
1376 + ON gp.object_id = tr.object_id
1377 + INNER JOIN $wpdb->term_taxonomy tt
1378 + ON tr.term_taxonomy_id = tt.term_taxonomy_id
1379 + WHERE (gp.object_type = 'post' OR gp.object_type = 'page')
1380 + AND gp.object_id NOT IN (
1381 + SELECT igp.object_id
1382 + FROM ".DB_ACCESSGROUP_TO_OBJECT." igp
1383 + WHERE (igp.object_type = 'post' OR igp.object_type = 'page')
1384 + AND igp.group_id IN (".$userUserGroupString.")
1385 + ) AND tt.term_id NOT IN (
1386 + SELECT igc.object_id
1387 + FROM ".DB_ACCESSGROUP_TO_OBJECT." igc
1388 + WHERE igc.object_type = 'category'
1389 + AND igc.group_id IN (".$userUserGroupString.")
1390 + )";
1391 +
1392 + $excludedPosts = $wpdb->get_col($postSql);
1393 +
1394 + return $excludedPosts;
1395 + }
1396 +
1397 + /**
1398 + * The function for the posts_where_paged filter.
1399 + *
1400 + * @param string $sql The where sql statment.
1401 + *
1402 + * @return string
1403 + */
1404 + public function showPostSql($sql)
1405 + {
1406 + $uamAccessHandler = &$this->getAccessHandler();
1407 + $uamOptions = $this->getAdminOptions();
1408 +
1409 + if ($uamOptions['hide_post'] == 'true'
1410 + && !$uamAccessHandler->checkUserAccess()
1411 + ) {
1412 + global $wpdb;
1413 + $excludedPosts = $this->_getExcludedPosts();
1414 +
1415 + if (count($excludedPosts) > 0) {
1416 + $excludedPostsStr = implode(",", $excludedPosts);
1417 + $sql .= " AND $wpdb->posts.ID NOT IN($excludedPostsStr) ";
1418 + }
1419 + }
1420 +
1421 + return $sql;
1422 + }
1423 +
1424 + /**
1117 1425 * The function for the wp_get_nav_menu_items filter.
1118 1426 *
1119 1427 * @param array $items The menu item.
1120 1428 *
@@ -1119,9 +1427,9 @@
1119 1427 * @param array $items The menu item.
1120 1428 *
1121 1429 * @return array
1122 1430 */
1123 - function showCustomMenu($items)
1431 + public function showCustomMenu($items)
1124 1432 {
1125 1433 $showItems = array();
1126 1434
1127 1435 foreach ($items as $item) {
@@ -1131,9 +1439,13 @@
1131 1439 $object = get_post($item->object_id);
1132 1440 $post = $this->_getPost($object);
1133 1441
1134 1442 if ($post !== null) {
1135 - $item->title = $post->post_title;
1443 + if (isset($post->isLocked)) {
1444 + $item->title = $post->post_title;
1445 + }
1446 +
1447 + $item->title .= $this->adminOutput($item->object, $item->object_id);
1136 1448
1137 1449 $showItems[] = $item;
1138 1450 }
1139 1451 } elseif ($item->object == 'category') {
@@ -1142,8 +1454,9 @@
1142 1454
1143 1455 if ($category !== null
1144 1456 && !$category->isEmpty
1145 1457 ) {
1458 + $item->title .= $this->adminOutput($item->object, $item->object_id);
1146 1459 $showItems[] = $item;
1147 1460 }
1148 1461 } else {
1149 1462 $showItems[] = $item;
@@ -1159,9 +1472,9 @@
1159 1472 * @param array $comments The comments.
1160 1473 *
1161 1474 * @return array
1162 1475 */
1163 - function showComment($comments = array())
1476 + public function showComment($comments = array())
1164 1477 {
1165 1478 $showComments = array();
1166 1479 $uamOptions = $this->getAdminOptions();
1167 1480 $uamAccessHandler = &$this->getAccessHandler();
@@ -1173,13 +1486,13 @@
1173 1486 if ($uamOptions['hide_'.$postType.'_comment'] == 'true'
1174 1487 || $uamOptions['hide_'.$postType] == 'true'
1175 1488 || $this->atAdminPanel
1176 1489 ) {
1177 - if ($uamAccessHandler->checkAccess($post->ID)) {
1490 + if ($uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1178 1491 $showComments[] = $comment;
1179 1492 }
1180 1493 } else {
1181 - if (!$uamAccessHandler->checkAccess($post->ID)) {
1494 + if (!$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1182 1495 $comment->comment_content
1183 1496 = $uamOptions[$postType.'_comment_content'];
1184 1497 }
1185 1498
@@ -1198,9 +1511,9 @@
1198 1511 * @param array $pages The pages.
1199 1512 *
1200 1513 * @return array
1201 1514 */
1202 - function showPage($pages = array())
1515 + public function showPage($pages = array())
1203 1516 {
1204 1517 $showPages = array();
1205 1518 $uamOptions = $this->getAdminOptions();
1206 1519 $uamAccessHandler = &$this->getAccessHandler();
@@ -1208,14 +1521,14 @@
1208 1521 foreach ($pages as $page) {
1209 1522 if ($uamOptions['hide_page'] == 'true'
1210 1523 || $this->atAdminPanel
1211 1524 ) {
1212 - if ($uamAccessHandler->checkAccess($page->ID)) {
1213 - $page->post_title.= $this->adminOutput($page->ID);
1525 + if ($uamAccessHandler->checkObjectAccess($page->post_type, $page->ID)) {
1526 + $page->post_title.= $this->adminOutput($page->post_type, $page->ID);
1214 1527 $showPages[] = $page;
1215 1528 }
1216 1529 } else {
1217 - if (!$uamAccessHandler->checkAccess($page->ID)) {
1530 + if (!$uamAccessHandler->checkObjectAccess($page->post_type, $page->ID)) {
1218 1531 if ($uamOptions['hide_page_title'] == 'true') {
1219 1532 $page->post_title = $uamOptions['page_title'];
1220 1533 }
1221 1534
@@ -1221,9 +1534,9 @@
1221 1534
1222 1535 $page->post_content = $uamOptions['page_content'];
1223 1536 }
1224 1537
1225 - $page->post_title.= $this->adminOutput($page->ID);
1538 + $page->post_title .= $this->adminOutput($page->post_type, $page->ID);
1226 1539 $showPages[] = $page;
1227 1540 }
1228 1541 }
1229 1542
@@ -1245,9 +1558,11 @@
1245 1558 $uamAccessHandler = &$this->getAccessHandler();
1246 1559
1247 1560 $category->isEmpty = false;
1248 1561
1249 - if ($uamAccessHandler->checkCategoryAccess($category->term_id)) {
1562 + $category->name .= $this->adminOutput('category', $category->term_id);
1563 +
1564 + if ($uamAccessHandler->checkObjectAccess('category', $category->term_id)) {
1250 1565 if ($this->atAdminPanel == false
1251 1566 && ($uamOptions['hide_post'] == 'true'
1252 1567 || $uamOptions['hide_page'] == 'true')
1253 1568 ) {
@@ -1256,15 +1571,16 @@
1256 1571 'category' => $category->term_id
1257 1572 );
1258 1573
1259 1574 $categoryPosts = get_posts($args);
1575 + $category->count = count($categoryPosts);
1260 1576
1261 1577 if (isset($categoryPosts)) {
1262 1578 foreach ($categoryPosts as $post) {
1263 1579 if ($uamOptions['hide_'.$post->post_type] == 'true'
1264 - && !$uamAccessHandler->checkAccess($post->ID)
1580 + && !$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)
1265 1581 ) {
1266 - $category->count--;
1582 + $category->count--;
1267 1583 }
1268 1584 }
1269 1585 }
1270 1586
@@ -1280,9 +1596,9 @@
1280 1596
1281 1597 while ($curCategory->parent != 0) {
1282 1598 $curCategory = get_category($curCategory->parent);
1283 1599
1284 - if ($uamAccessHandler->checkCategoryAccess($curCategory->term_id)) {
1600 + if ($uamAccessHandler->checkObjectAccess('category', $curCategory->term_id)) {
1285 1601 $category->parent = $curCategory->term_id;
1286 1602 break;
1287 1603 }
1288 1604 }
@@ -1304,9 +1620,9 @@
1304 1620 * @param array $args The given arguments.
1305 1621 *
1306 1622 * @return array
1307 1623 */
1308 - function showCategory($categories = array(), $args = array())
1624 + public function showCategory($categories = array(), $args = array())
1309 1625 {
1310 1626 $uamOptions = $this->getAdminOptions();
1311 1627 $uamAccessHandler = &$this->getAccessHandler();
1312 1628
@@ -1337,34 +1653,8 @@
1337 1653 return $categories;
1338 1654 }
1339 1655
1340 1656 /**
1341 - * The function for the get_the_title filter.
1342 - *
1343 - * @param string $title The title of the post.
1344 - * @param object $postId The post id.
1345 - *
1346 - * @return string
1347 - */
1348 - /*function showTitle($title, $postId = null)
1349 - {
1350 - $uamOptions = $this->getAdminOptions();
1351 - $uamAccessHandler = &$this->getAccessHandler();
1352 -
1353 - $post = get_post($postId);
1354 - $postType = $post->post_type;
1355 -
1356 - if (!$uamAccessHandler->checkAccess($postId)
1357 - && $post != null
1358 - && $uamOptions['hide_'.$postType.'_title'] == 'true'
1359 - ) {
1360 - $title = $uamOptions[$postType.'_title'];
1361 - }
1362 -
1363 - return $title;
1364 - }*/
1365 -
1366 - /**
1367 1657 * The function for the get_previous_post_where and
1368 1658 * the get_next_post_where filter.
1369 1659 *
1370 1660 * @param string $sql The current sql string.
@@ -1370,29 +1660,21 @@
1370 1660 * @param string $sql The current sql string.
1371 1661 *
1372 1662 * @return string
1373 1663 */
1374 - function showNextPreviousPost($sql)
1664 + public function showNextPreviousPost($sql)
1375 1665 {
1666 + $uamAccessHandler = &$this->getAccessHandler();
1376 1667 $uamOptions = $this->getAdminOptions();
1377 1668
1378 - if ($uamOptions['hide_post'] == 'true') {
1379 - $posts = get_posts();
1380 - $uamAccessHandler = &$this->getAccessHandler();
1669 + if ($uamOptions['hide_post'] == 'true'
1670 + && !$uamAccessHandler->checkUserAccess()
1671 + ) {
1672 + $excludedPosts = $this->_getExcludedPosts();
1381 1673
1382 - if (isset($posts)) {
1383 - foreach ($posts as $post) {
1384 - if (!$uamAccessHandler->checkAccess($post->ID)) {
1385 - $excludedPosts[] = $post->ID;
1386 - }
1387 - }
1388 -
1389 - global $wpdb;
1390 -
1391 - if (isset($excludedPosts)) {
1392 - $excludedPostsStr = implode(",", $excludedPosts);
1393 - $sql.= "AND p.ID NOT IN($excludedPostsStr)";
1394 - }
1674 + if (count($excludedPosts) > 0) {
1675 + $excludedPostsStr = implode(",", $excludedPosts);
1676 + $sql.= " AND p.ID NOT IN($excludedPostsStr) ";
1395 1677 }
1396 1678 }
1397 1679
1398 1680 return $sql;
@@ -1400,13 +1682,14 @@
1400 1682
1401 1683 /**
1402 1684 * Returns the admin hint.
1403 1685 *
1404 - * @param integer $postId The post id we want to check.
1686 + * @param string $objectType The object type.
1687 + * @param integer $objectId The object id we want to check.
1405 1688 *
1406 1689 * @return string
1407 1690 */
1408 - function adminOutput($postId)
1691 + public function adminOutput($objectType, $objectId)
1409 1692 {
1410 1693 $output = "";
1411 1694
1412 1695 if (!$this->atAdminPanel) {
@@ -1422,9 +1705,11 @@
1422 1705 }
1423 1706
1424 1707 $uamAccessHandler = &$this->getAccessHandler();
1425 1708
1426 - if (count($uamAccessHandler->getUserGroupsForPost($postId)) > 0) {
1709 + if ($uamAccessHandler->userIsAdmin($current_user->ID)
1710 + && count($uamAccessHandler->getUserGroupsForObject($objectType, $objectId)) > 0
1711 + ) {
1427 1712 $output .= $uamOptions['blog_admin_hint_text'];
1428 1713 }
1429 1714 }
1430 1715 }
@@ -1439,12 +1724,12 @@
1439 1724 * @param integer $postId The id of the post.
1440 1725 *
1441 1726 * @return string
1442 1727 */
1443 - function showGroupMembership($link, $postId)
1728 + public function showGroupMembership($link, $postId)
1444 1729 {
1445 1730 $uamAccessHandler = &$this->getAccessHandler();
1446 - $groups = $uamAccessHandler->getUserGroupsForPost($postId);
1731 + $groups = $uamAccessHandler->getUserGroupsForObject('post', $postId);
1447 1732
1448 1733 if (count($groups) > 0) {
1449 1734 $link .= ' | '.TXT_ASSIGNED_GROUPS.': ';
1450 1735
@@ -1462,9 +1747,9 @@
1462 1747 * Returns the login bar.
1463 1748 *
1464 1749 * @return string
1465 1750 */
1466 - function getLoginBarHtml()
1751 + public function getLoginBarHtml()
1467 1752 {
1468 1753 if (!is_user_logged_in()) {
1469 1754 return $this->getIncludeContents(UAM_REALPATH.'tpl/loginBar.php');
1470 1755 }
@@ -1477,38 +1762,64 @@
1477 1762 * Functions for the redirection and files.
1478 1763 */
1479 1764
1480 1765 /**
1766 + * Returns ture if permalinks are active otherwise false.
1767 + *
1768 + * @return boolean
1769 + */
1770 + public function isPermalinksActive()
1771 + {
1772 + $permaStruc = get_option('permalink_structure');
1773 +
1774 + if (empty($permaStruc)) {
1775 + return false;
1776 + } else {
1777 + return true;
1778 + }
1779 + }
1780 +
1781 + /**
1481 1782 * Redirects to a page or to content.
1783 + *
1784 + * @param string $headers The headers which are given from wordpress.
1785 + * @param object $pageParams The params of the current page.
1482 1786 *
1483 1787 * @return null
1484 1788 */
1485 - function redirect()
1789 + public function redirect($headers, $pageParams)
1486 1790 {
1487 1791 $uamOptions = $this->getAdminOptions();
1488 1792
1489 - if (isset($_GET['getfile'])) {
1490 - $fileUrl = $_GET['getfile'];
1491 - }
1793 + if (isset($_GET['uamgetfile'])
1794 + && isset($_GET['uamfiletype'])
1795 + ) {
1796 + $fileUrl = $_GET['uamgetfile'];
1797 + $fileType = $_GET['uamfiletype'];
1798 + $this->getFile($fileType, $fileUrl);
1799 + } elseif (!$this->atAdminPanel && $uamOptions['redirect'] != 'false') {
1800 + $object = null;
1492 1801
1493 - $emptyId = null;
1494 - $post = get_post($emptyId);
1495 -
1496 - if ($uamOptions['redirect'] != 'false'
1497 - && !$this->getAccessHandler()->checkAccess($post->ID)
1498 - && !$this->atAdminPanel
1499 - && !isset($fileUrl)
1500 - ) {
1501 - $this->redirectUser();
1502 - } elseif (isset($fileUrl)) {
1503 - $permaStruc = get_option('permalink_structure');
1802 + if (isset($pageParams->query_vars['p'])) {
1803 + $object = get_post($pageParams->query_vars['p']);
1804 + $objectType = $object->post_type;
1805 + $objectId = $object->ID;
1806 + } elseif (isset($pageParams->query_vars['page_id'])) {
1807 + $object = get_post($pageParams->query_vars['page_id']);
1808 + $objectType = $object->post_type;
1809 + $objectId = $object->ID;
1810 + } elseif (isset($pageParams->query_vars['cat_id'])) {
1811 + $object = get_category($pageParams->query_vars['cat_id']);
1812 + $objectType = 'category';
1813 + $objectId = $object->term_id;
1814 + }
1504 1815
1505 - if (!empty($permaStruc)) {
1506 - $uploadDir = wp_upload_dir();
1507 - $fileUrl = $uploadDir['baseurl'].'/'.$fileUrl;
1816 + if ($object === null
1817 + ||$object !== null
1818 + && !$this->getAccessHandler()->checkObjectAccess($objectType, $objectId)
1819 + ) {
1820 + $this->redirectUser($object);
1508 1821 }
1509 -
1510 - $this->getFile($fileUrl);
1511 1822 }
1512 1823 }
1513 1824
1514 1825 /**
@@ -1513,11 +1824,13 @@
1513 1824
1514 1825 /**
1515 1826 * Redirects the user to his destination.
1516 1827 *
1828 + * @param object $object The current object we want to access.
1829 + *
1517 1830 * @return null
1518 1831 */
1519 - function redirectUser()
1832 + public function redirectUser($object = null)
1520 1833 {
1521 1834 global $wp_query;
1522 1835
1523 1836 $postToShow = false;
@@ -1522,11 +1835,13 @@
1522 1835
1523 1836 $postToShow = false;
1524 1837 $posts = $wp_query->get_posts();
1525 1838
1526 - if (isset($posts)) {
1839 + if ($object === null
1840 + && isset($posts)
1841 + ) {
1527 1842 foreach ($posts as $post) {
1528 - if ($this->getAccessHandler()->checkAccess($post->ID)) {
1843 + if ($this->getAccessHandler()->checkObjectAccess($post->post_type, $post->ID)) {
1529 1844 $postToShow = true;
1530 1845 break;
1531 1846 }
1532 1847 }
@@ -1533,9 +1848,9 @@
1533 1848 }
1534 1849
1535 1850 if (!$postToShow) {
1536 1851 $uamOptions = $this->getAdminOptions();
1537 -
1852 +
1538 1853 if ($uamOptions['redirect'] == 'blog') {
1539 1854 $url = home_url('/');
1540 1855 } elseif ($uamOptions['redirect'] == 'custom_page') {
1541 1856 $post = get_post($uamOptions['redirect_custom_page']);
@@ -1545,8 +1860,9 @@
1545 1860 }
1546 1861
1547 1862 if ($url != "http://".$_SERVER['HTTP_HOST'].$_SERVER["REQUEST_URI"]) {
1548 1863 wp_redirect($url);
1864 + exit;
1549 1865 }
1550 1866 }
1551 1867 }
1552 1868
@@ -1552,32 +1868,26 @@
1552 1868
1553 1869 /**
1554 1870 * Delivers the content of the requestet file.
1555 1871 *
1556 - * @param string $url The file url.
1872 + * @param string $objectType The type of the requested file.
1873 + * @param string $objectUrl The file url.
1557 1874 *
1558 1875 * @return null
1559 1876 */
1560 - function getFile($url)
1877 + public function getFile($objectType, $objectUrl)
1561 1878 {
1562 - $post = get_post($this->getAttachmentIdByUrl($url));
1879 + $object = $this->_getFileSettingsByType($objectType, $objectUrl);
1563 1880
1564 - if ($post !== null) {
1565 - $file = null;
1566 - } else {
1881 + if ($object === null) {
1567 1882 return null;
1568 1883 }
1569 1884
1570 - if ($post->post_type == 'attachment'
1571 - && $this->getAccessHandler()->checkAccess($post->ID)
1572 - ) {
1573 - $uploadDir = wp_upload_dir();
1574 - $file = $uploadDir['basedir'].'/'.str_replace(
1575 - $uploadDir['baseurl'],
1576 - '',
1577 - $url
1578 - );
1579 - } else if (wp_attachment_is_image($post->ID)) {
1885 + $file = null;
1886 +
1887 + if ($this->getAccessHandler()->checkObjectAccess($object->type, $object->id)) {
1888 + $file = $object->file;
1889 + } elseif ($object->isImage) {
1580 1890 $file = UAM_REALPATH.'gfx/noAccessPic.png';
1581 1891 } else {
1582 1892 wp_die(TXT_NO_RIGHTS);
1583 1893 }
@@ -1584,10 +1894,10 @@
1584 1894
1585 1895 //Deliver content
1586 1896 if (file_exists($file)) {
1587 1897 $fileName = basename($file);
1588 -
1589 - /**
1898 +
1899 + /*
1590 1900 * This only for compatibility
1591 1901 * mime_content_type has been deprecated as the PECL extension Fileinfo
1592 1902 * provides the same functionality (and more) in a much cleaner way.
1593 1903 */
@@ -1592,33 +1902,37 @@
1592 1902 * provides the same functionality (and more) in a much cleaner way.
1593 1903 */
1594 1904 if (function_exists('finfo_open')) {
1595 1905 $finfo = finfo_open(FILEINFO_MIME);
1596 -
1597 - if (!$finfo) {
1598 - wp_die(TXT_FILEINFO_DB_ERROR);
1599 - }
1600 -
1601 - $fileType = finfo_file($finfo, $file);
1906 + $fileMimeType = finfo_file($finfo, $file);
1907 + finfo_close($finfo);
1602 1908 } else {
1603 - $fileType = mime_content_type($file);
1909 + $fileMimeType = mime_content_type($file);
1604 1910 }
1605 1911
1606 1912 header('Content-Description: File Transfer');
1607 - header('Content-Type: '.$fileType);
1608 - header('Content-Length: '.filesize($file));
1609 - header('Content-Transfer-Encoding: binary');
1610 - header('Expires: 0');
1913 + header('Content-Type: '.$fileMimeType);
1611 1914
1612 - if (!wp_attachment_is_image($post->ID)) {
1613 - header('Content-Disposition: attachment; filename='.basename($file));
1915 + if (!$object->isImage) {
1916 + $baseName = str_replace(' ', '_', basename($file));
1917 +
1918 + header('Content-Disposition: attachment; filename="'.$baseName.'"');
1614 1919 }
1920 +
1921 + header('Content-Transfer-Encoding: binary');
1922 + header('Content-Length: '.filesize($file));
1615 1923
1924 + $uamOptions = $this->getAdminOptions();
1925 +
1616 1926 if ($uamOptions['download_type'] == 'fopen'
1617 - && !wp_attachment_is_image($post->ID)
1927 + && !$objectIsImage
1618 1928 ) {
1619 - $fp = fopen($file, 'rb');
1929 + $fp = fopen($file, 'r');
1620 1930
1931 + //TODO find better solution (prevent '\n' / '0A')
1932 + ob_clean();
1933 + flush();
1934 +
1621 1935 while (!feof($fp)) {
1622 1936 set_time_limit(30);
1623 1937 $buffer = fread($fp, 1024);
1624 1938 echo $buffer;
@@ -1636,8 +1950,57 @@
1636 1950 }
1637 1951 }
1638 1952
1639 1953 /**
1954 + * Returns the file object by the given type and url.
1955 + *
1956 + * @param string $objectType The type of the requested file.
1957 + * @param string $objectUrl The file url.
1958 + *
1959 + * @return object|null
1960 + */
1961 + private function _getFileSettingsByType($objectType, $objectUrl)
1962 + {
1963 + $object = null;
1964 +
1965 + if ($objectType == 'attachment') {
1966 + $uploadDir = wp_upload_dir();
1967 +
1968 + if ($this->isPermalinksActive()) {
1969 + $objectUrl = $uploadDir['baseurl'].'/'.$objectUrl;
1970 + }
1971 +
1972 + $post = get_post($this->getPostIdByUrl($objectUrl));
1973 +
1974 + if ($post !== null
1975 + && $post->post_type == 'attachment'
1976 + ) {
1977 + $object->id = $post->ID;
1978 + $object->isImage = wp_attachment_is_image($post->ID);
1979 + $object->type = $objectType;
1980 +
1981 + $object->file = $uploadDir['basedir'].str_replace(
1982 + $uploadDir['baseurl'],
1983 + '',
1984 + $objectUrl
1985 + );
1986 + }
1987 + } else {
1988 + $plObject = $this->getAccessHandler()->getPlObject($objectType);
1989 +
1990 + if (isset($plObject)
1991 + && isset($plObject['getFileObject'])
1992 + ) {
1993 + $object = $plObject['reference']->{$plObject['getFileObject']}(
1994 + $objectUrl
1995 + );
1996 + }
1997 + }
1998 +
1999 + return $object;
2000 + }
2001 +
2002 + /**
1640 2003 * Returns the url for a locked file.
1641 2004 *
1642 2005 * @param string $url The base url.
1643 2006 * @param integer $id The id of the file.
@@ -1643,14 +2006,13 @@
1643 2006 * @param integer $id The id of the file.
1644 2007 *
1645 2008 * @return string
1646 2009 */
1647 - function getFileUrl($url, $id)
2010 + public function getFileUrl($url, $id)
1648 2011 {
1649 2012 $uamOptions = $this->getAdminOptions();
1650 - $permaStruc = get_option('permalink_structure');
1651 2013
1652 - if (empty($permaStruc)
2014 + if (!$this->isPermalinksActive()
1653 2015 && $uamOptions['lock_file'] == 'true'
1654 2016 ) {
1655 2017 $post = &get_post($id);
1656 2018
@@ -1661,12 +2023,12 @@
1661 2023 ",",
1662 2024 $uamOptions['locked_file_types']
1663 2025 );
1664 2026
1665 - if (in_array($type, $fileTypes)
1666 - || $uamOptions['lock_file_types'] == 'all'
2027 + if ($uamOptions['lock_file_types'] == 'all'
2028 + || in_array($type, $fileTypes)
1667 2029 ) {
1668 - $url = home_url('/').'?getfile='.$url;
2030 + $url = home_url('/').'?uamfiletype=attachment&uamgetfile='.$url;
1669 2031 }
1670 2032 }
1671 2033
1672 2034 return $url;
@@ -1678,11 +2040,15 @@
1678 2040 * @param string $url The url of the post(attachment).
1679 2041 *
1680 2042 * @return object The post.
1681 2043 */
1682 - function getAttachmentIdByUrl($url)
2044 + public function getPostIdByUrl($url)
1683 2045 {
1684 - //Filter editstring
2046 + if (isset($this->postUrls[$url])) {
2047 + return $this->postUrls[$url];
2048 + }
2049 +
2050 + //Filter edit string
1685 2051 $newUrl = preg_split("/-e[0-9]*/", $url);
1686 2052
1687 2053 if (count($newUrl) == 2) {
1688 2054 $newUrl = $newUrl[0].$newUrl[1];
@@ -1703,15 +2069,28 @@
1703 2069 $dbPost = $wpdb->get_row(
1704 2070 "SELECT ID
1705 2071 FROM ".$wpdb->prefix."posts
1706 2072 WHERE guid = '" . $newUrl . "'
1707 - LIMIT 1",
1708 - ARRAY_A
2073 + LIMIT 1"
1709 2074 );
1710 2075
1711 2076 if ($dbPost) {
1712 - return $dbPost['ID'];
2077 + return $dbPost->ID;
1713 2078 }
1714 2079
1715 2080 return null;
2081 + }
2082 +
2083 + /**
2084 + * Caches the urls for the post for a later lookup.
2085 + *
2086 + * @param string $url The url of the post.
2087 + * @param object $post The post object.
2088 + *
2089 + * @return null
2090 + */
2091 + public function cachePostLinks($url, $post)
2092 + {
2093 + $this->postUrls[$url] = $post->ID;
2094 + return $url;
1716 2095 }
1717 2096 }