| @@ -28,12 +28,13 @@ | ||
| 28 | 28 | class UserAccessManager |
| 29 | 29 | { |
| 30 | 30 | var $atAdminPanel = false; |
| 31 | 31 | protected $adminOptionsName = "uamAdminOptions"; |
| 32 | - protected $uamVersion = 1.0; | |
| 33 | - protected $uamDbVersion = 1.1; | |
| 32 | + protected $uamVersion = 1.1; | |
| 33 | + protected $uamDbVersion = 1.2; | |
| 34 | 34 | protected $adminOptions; |
| 35 | 35 | protected $accessHandler = null; |
| 36 | + protected $postUrls = array(); | |
| 36 | 37 | |
| 37 | 38 | /** |
| 38 | 39 | * Consturctor |
| 39 | 40 | * |
| @@ -38,11 +39,11 @@ | ||
| 38 | 39 | * Consturctor |
| 39 | 40 | * |
| 40 | 41 | * @return null |
| 41 | 42 | */ |
| 42 | - function __construct() | |
| 43 | + public function __construct() | |
| 43 | 44 | { |
| 44 | - | |
| 45 | + do_action('uam_init', $this); | |
| 45 | 46 | } |
| 46 | 47 | |
| 47 | 48 | /** |
| 48 | 49 | * Creates the needed tables at the database |
| @@ -48,33 +49,24 @@ | ||
| 48 | 49 | * Creates the needed tables at the database |
| 49 | 50 | * |
| 50 | 51 | * @return null; |
| 51 | 52 | */ |
| 52 | - function install() | |
| 53 | - { | |
| 53 | + public function install() | |
| 54 | + { | |
| 54 | 55 | global $wpdb; |
| 55 | 56 | $uamDbVersion = $this->uamDbVersion; |
| 56 | 57 | |
| 57 | 58 | include_once ABSPATH . 'wp-admin/includes/upgrade.php'; |
| 58 | - $charset_collate = ''; | |
| 59 | + | |
| 60 | + $charsetCollate = $this->_getCharset(); | |
| 59 | 61 | |
| 60 | - if (version_compare(mysql_get_server_info(), '4.1.0', '>=')) { | |
| 61 | - if (!empty($wpdb->charset)) { | |
| 62 | - $charset_collate = "DEFAULT CHARACTER SET $wpdb->charset"; | |
| 63 | - } | |
| 64 | - | |
| 65 | - if (!empty($wpdb->collate)) { | |
| 66 | - $charset_collate.= " COLLATE $wpdb->collate"; | |
| 67 | - } | |
| 68 | - } | |
| 69 | - | |
| 70 | 62 | $dbUserGroup = $wpdb->get_var( |
| 71 | 63 | "SHOW TABLES |
| 72 | - LIKE '" . DB_ACCESSGROUP . "'" | |
| 64 | + LIKE '".DB_ACCESSGROUP."'" | |
| 73 | 65 | ); |
| 74 | 66 | |
| 75 | 67 | if ($dbUserGroup != DB_ACCESSGROUP) { |
| 76 | - $sql = "CREATE TABLE " . DB_ACCESSGROUP . " ( | |
| 68 | + $sql = "CREATE TABLE ".DB_ACCESSGROUP." ( | |
| 77 | 69 | ID int(11) NOT NULL auto_increment, |
| 78 | 70 | groupname tinytext NOT NULL, |
| 79 | 71 | groupdesc text NOT NULL, |
| 80 | 72 | read_access tinytext NOT NULL, |
| @@ -80,77 +72,47 @@ | ||
| 80 | 72 | read_access tinytext NOT NULL, |
| 81 | 73 | write_access tinytext NOT NULL, |
| 82 | 74 | ip_range mediumtext NULL, |
| 83 | 75 | PRIMARY KEY (ID) |
| 84 | - ) $charset_collate;"; | |
| 76 | + ) $charsetCollate;"; | |
| 85 | 77 | dbDelta($sql); |
| 86 | 78 | } |
| 87 | - | |
| 88 | - $dbUserGroupToPost = $wpdb->get_var( | |
| 79 | + | |
| 80 | + $dbUserGroupToObject = $wpdb->get_var( | |
| 89 | 81 | "SHOW TABLES |
| 90 | - LIKE '" . DB_ACCESSGROUP_TO_POST . "'" | |
| 82 | + LIKE '".DB_ACCESSGROUP_TO_OBJECT."'" | |
| 91 | 83 | ); |
| 92 | 84 | |
| 93 | - if ($dbUserGroupToPost != DB_ACCESSGROUP_TO_POST) { | |
| 94 | - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_POST . " ( | |
| 95 | - post_id int(11) NOT NULL, | |
| 85 | + if ($dbUserGroupToObject != DB_ACCESSGROUP_TO_OBJECT) { | |
| 86 | + $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_OBJECT . " ( | |
| 87 | + object_id VARCHAR(11) NOT NULL, | |
| 88 | + object_type varchar(255) NOT NULL, | |
| 96 | 89 | group_id int(11) NOT NULL, |
| 97 | - PRIMARY KEY (post_id,group_id) | |
| 98 | - ) $charset_collate;"; | |
| 90 | + PRIMARY KEY (object_id,object_type,group_id) | |
| 91 | + ) $charsetCollate;"; | |
| 99 | 92 | dbDelta($sql); |
| 100 | 93 | } |
| 101 | 94 | |
| 102 | - $dbUserGroupToUser = $wpdb->get_var( | |
| 103 | - "SHOW TABLES | |
| 104 | - LIKE '" . DB_ACCESSGROUP_TO_USER . "'" | |
| 105 | - ); | |
| 106 | - | |
| 107 | - if ($dbUserGroupToUser != DB_ACCESSGROUP_TO_USER) { | |
| 108 | - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_USER . " ( | |
| 109 | - user_id int(11) NOT NULL, | |
| 110 | - group_id int(11) NOT NULL, | |
| 111 | - PRIMARY KEY (user_id,group_id) | |
| 112 | - ) $charset_collate;"; | |
| 113 | - dbDelta($sql); | |
| 114 | - } | |
| 115 | - | |
| 116 | - $dbUserGroupToCategory = $wpdb->get_var( | |
| 117 | - "SHOW TABLES | |
| 118 | - LIKE '" . DB_ACCESSGROUP_TO_CATEGORY . "'" | |
| 119 | - ); | |
| 120 | - | |
| 121 | - if ($dbUserGroupToCategory != DB_ACCESSGROUP_TO_CATEGORY) { | |
| 122 | - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_CATEGORY . " ( | |
| 123 | - category_id int(11) NOT NULL, | |
| 124 | - group_id int(11) NOT NULL, | |
| 125 | - PRIMARY KEY (category_id,group_id) | |
| 126 | - ) $charset_collate;"; | |
| 127 | - dbDelta($sql); | |
| 128 | - } | |
| 129 | - | |
| 130 | - $dbUserGroupToRole = $wpdb->get_var( | |
| 131 | - "SHOW TABLES | |
| 132 | - LIKE '" . DB_ACCESSGROUP_TO_ROLE . "'" | |
| 133 | - ); | |
| 134 | - | |
| 135 | - if ($dbUserGroupToRole != DB_ACCESSGROUP_TO_ROLE) { | |
| 136 | - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_ROLE . " ( | |
| 137 | - role_name varchar(255) NOT NULL, | |
| 138 | - group_id int(11) NOT NULL, | |
| 139 | - PRIMARY KEY (role_name,group_id) | |
| 140 | - ) $charset_collate;"; | |
| 141 | - dbDelta($sql); | |
| 142 | - } | |
| 143 | - | |
| 144 | - add_option("uam_db_version", $uamDbVersion); | |
| 95 | + add_option("uam_db_version", $this->uamDbVersion); | |
| 145 | 96 | } |
| 146 | 97 | |
| 147 | 98 | /** |
| 148 | - * Updates the database if an old version was installed. | |
| 99 | + * Checks if a database update is necessary. | |
| 149 | 100 | * |
| 101 | + * @return boolean | |
| 102 | + */ | |
| 103 | + public function isDatabaseUpdateNecessary() | |
| 104 | + { | |
| 105 | + $currentDbVersion = get_option("uam_db_version"); | |
| 106 | + return version_compare($currentDbVersion, $this->uamDbVersion, '<'); | |
| 107 | + } | |
| 108 | + | |
| 109 | + /** | |
| 110 | + * Updates the user access manager if an old version was installed. | |
| 111 | + * | |
| 150 | 112 | * @return null; |
| 151 | 113 | */ |
| 152 | - function update() | |
| 114 | + public function update() | |
| 153 | 115 | { |
| 154 | 116 | global $wpdb; |
| 155 | 117 | $currentDbVersion = get_option("uam_db_version"); |
| 156 | 118 | |
| @@ -158,12 +120,10 @@ | ||
| 158 | 120 | $this->install(); |
| 159 | 121 | } |
| 160 | 122 | |
| 161 | 123 | if (!get_option('uam_version') |
| 162 | - || get_option('uam_version') < $this->uamVersion | |
| 124 | + || get_option('uam_version') < 1.0 | |
| 163 | 125 | ) { |
| 164 | - update_option('uam_version', $this->uamVersion); | |
| 165 | - | |
| 166 | 126 | delete_option('allow_comments_locked'); |
| 167 | 127 | } |
| 168 | 128 | |
| 169 | 129 | $dbUserGroup = $wpdb->get_var( |
| @@ -170,15 +130,13 @@ | ||
| 170 | 130 | "SHOW TABLES |
| 171 | 131 | LIKE '" . DB_ACCESSGROUP . "'" |
| 172 | 132 | ); |
| 173 | 133 | |
| 174 | - if ($currentDbVersion != $this->uamDbVersion) { | |
| 134 | + if ($currentDbVersion < $this->uamDbVersion) { | |
| 175 | 135 | if ($currentDbVersion == 1.0) { |
| 176 | - | |
| 177 | - | |
| 178 | 136 | if ($dbUserGroup == DB_ACCESSGROUP) { |
| 179 | 137 | $wpdb->query( |
| 180 | - "ALTER TABLE " . DB_ACCESSGROUP . " | |
| 138 | + "ALTER TABLE ".DB_ACCESSGROUP." | |
| 181 | 139 | ADD read_access TINYTEXT NOT NULL DEFAULT '', |
| 182 | 140 | ADD write_access TINYTEXT NOT NULL DEFAULT '', |
| 183 | 141 | ADD ip_range MEDIUMTEXT NULL DEFAULT ''" |
| 184 | 142 | ); |
| @@ -183,31 +141,98 @@ | ||
| 183 | 141 | ADD ip_range MEDIUMTEXT NULL DEFAULT ''" |
| 184 | 142 | ); |
| 185 | 143 | |
| 186 | 144 | $wpdb->query( |
| 187 | - "UPDATE " . DB_ACCESSGROUP . " | |
| 145 | + "UPDATE ".DB_ACCESSGROUP." | |
| 188 | 146 | SET read_access = 'group', |
| 189 | 147 | write_access = 'group'" |
| 190 | 148 | ); |
| 191 | 149 | |
| 192 | - update_option('uam_db_version', $this->uamDbVersion); | |
| 150 | + $dbIpRange = $wpdb->get_var( | |
| 151 | + "SHOW columns | |
| 152 | + FROM ".DB_ACCESSGROUP." | |
| 153 | + LIKE 'ip_range'" | |
| 154 | + ); | |
| 155 | + | |
| 156 | + if ($dbIpRange != 'ip_range') { | |
| 157 | + $wpdb->query( | |
| 158 | + "ALTER TABLE ".DB_ACCESSGROUP." | |
| 159 | + ADD ip_range MEDIUMTEXT NULL DEFAULT ''" | |
| 160 | + ); | |
| 161 | + } | |
| 193 | 162 | } |
| 194 | - } | |
| 195 | - } | |
| 196 | - | |
| 197 | - if ($dbUserGroup == DB_ACCESSGROUP) { | |
| 198 | - $dbIpRange = $wpdb->get_var( | |
| 199 | - "SHOW columns | |
| 200 | - FROM " . DB_ACCESSGROUP . " | |
| 201 | - LIKE 'ip_range'" | |
| 202 | - ); | |
| 163 | + | |
| 164 | + $currentDbVersion = 1.1; | |
| 165 | + } | |
| 203 | 166 | |
| 204 | - if ($dbIpRange != 'ip_range') { | |
| 167 | + if ($currentDbVersion == 1.1) { | |
| 168 | + define('DB_ACCESSGROUP_TO_POST', $wpdb->prefix . 'uam_accessgroup_to_post'); | |
| 169 | + define('DB_ACCESSGROUP_TO_USER', $wpdb->prefix . 'uam_accessgroup_to_user'); | |
| 170 | + define('DB_ACCESSGROUP_TO_CATEGORY', $wpdb->prefix . 'uam_accessgroup_to_category'); | |
| 171 | + define('DB_ACCESSGROUP_TO_ROLE', $wpdb->prefix . 'uam_accessgroup_to_role'); | |
| 172 | + | |
| 173 | + $charsetCollate = $this->_getCharset(); | |
| 174 | + | |
| 205 | 175 | $wpdb->query( |
| 206 | - "ALTER TABLE " . DB_ACCESSGROUP . " | |
| 207 | - ADD ip_range MEDIUMTEXT NULL DEFAULT ''" | |
| 176 | + "ALTER TABLE 'wp_uam_accessgroup_to_object' | |
| 177 | + CHANGE 'object_id' 'object_id' VARCHAR(11) | |
| 178 | + $charsetCollate;" | |
| 208 | 179 | ); |
| 180 | + | |
| 181 | + $objectTypes = $this->getAccessHandler()->getObjectTypes(); | |
| 182 | + | |
| 183 | + foreach ($objectTypes as $objectType) { | |
| 184 | + $addition = ''; | |
| 185 | + | |
| 186 | + if ($objectType == 'post' | |
| 187 | + || $objectType == 'page' | |
| 188 | + || $objectType == 'attachment' | |
| 189 | + ) { | |
| 190 | + $dbIdName = 'post_id'; | |
| 191 | + $database = DB_ACCESSGROUP_TO_POST.', '.$wpdb->posts; | |
| 192 | + $addition = " WHERE post_id = ID | |
| 193 | + AND post_type = '".$objectType."'"; | |
| 194 | + } elseif ($objectType == 'category') { | |
| 195 | + $dbIdName = 'category_id'; | |
| 196 | + $database = DB_ACCESSGROUP_TO_CATEGORY; | |
| 197 | + } elseif ($objectType == 'user') { | |
| 198 | + $dbIdName = 'user_id'; | |
| 199 | + $database = DB_ACCESSGROUP_TO_USER; | |
| 200 | + } elseif ($objectType == 'role') { | |
| 201 | + $dbIdName = 'role_name'; | |
| 202 | + $database = DB_ACCESSGROUP_TO_ROLE; | |
| 203 | + } | |
| 204 | + | |
| 205 | + $sql = "SELECT ".$dbIdName." as id, group_id as groupId | |
| 206 | + FROM ".$database.$addition; | |
| 207 | + | |
| 208 | + $dbObjects = $wpdb->get_results($sql); | |
| 209 | + | |
| 210 | + foreach ($dbObjects as $dbObject) { | |
| 211 | + $sql = "INSERT INTO ".DB_ACCESSGROUP_TO_OBJECT." ( | |
| 212 | + group_id, | |
| 213 | + object_id, | |
| 214 | + object_type | |
| 215 | + ) | |
| 216 | + VALUES( | |
| 217 | + '".$dbObject->groupId."', | |
| 218 | + '".$dbObject->id."', | |
| 219 | + '".$objectType."' | |
| 220 | + )"; | |
| 221 | + | |
| 222 | + $wpdb->query($sql); | |
| 223 | + } | |
| 224 | + } | |
| 225 | + | |
| 226 | + $wpdb->query( | |
| 227 | + "DROP TABLE ".DB_ACCESSGROUP_TO_POST.", | |
| 228 | + ".DB_ACCESSGROUP_TO_USER.", | |
| 229 | + ".DB_ACCESSGROUP_TO_CATEGORY.", | |
| 230 | + ".DB_ACCESSGROUP_TO_ROLE | |
| 231 | + ); | |
| 209 | 232 | } |
| 233 | + | |
| 234 | + update_option('uam_db_version', $this->uamDbVersion); | |
| 210 | 235 | } |
| 211 | 236 | } |
| 212 | 237 | |
| 213 | 238 | /** |
| @@ -214,17 +239,14 @@ | ||
| 214 | 239 | * Clean up wordpress if the plugin will be uninstalled. |
| 215 | 240 | * |
| 216 | 241 | * @return null |
| 217 | 242 | */ |
| 218 | - function uninstall() | |
| 243 | + public function uninstall() | |
| 219 | 244 | { |
| 220 | 245 | global $wpdb; |
| 221 | 246 | $wpdb->query( |
| 222 | - "DROP TABLE " . DB_ACCESSGROUP . ", | |
| 223 | - " . DB_ACCESSGROUP_TO_POST . ", | |
| 224 | - " . DB_ACCESSGROUP_TO_USER . ", | |
| 225 | - " . DB_ACCESSGROUP_TO_CATEGORY . ", | |
| 226 | - " . DB_ACCESSGROUP_TO_ROLE | |
| 247 | + "DROP TABLE ".DB_ACCESSGROUP.", | |
| 248 | + ".DB_ACCESSGROUP_TO_OBJECT | |
| 227 | 249 | ); |
| 228 | 250 | |
| 229 | 251 | delete_option($this->adminOptionsName); |
| 230 | 252 | delete_option('uam_version'); |
| @@ -232,13 +254,35 @@ | ||
| 232 | 254 | $this->deleteHtaccessFiles(); |
| 233 | 255 | } |
| 234 | 256 | |
| 235 | 257 | /** |
| 258 | + * Returns the database charset. | |
| 259 | + * | |
| 260 | + * @return string | |
| 261 | + */ | |
| 262 | + private function _getCharset() | |
| 263 | + { | |
| 264 | + $charsetCollate = ''; | |
| 265 | + | |
| 266 | + if (version_compare(mysql_get_server_info(), '4.1.0', '>=')) { | |
| 267 | + if (!empty($wpdb->charset)) { | |
| 268 | + $charsetCollate = "DEFAULT CHARACTER SET $wpdb->charset"; | |
| 269 | + } | |
| 270 | + | |
| 271 | + if (!empty($wpdb->collate)) { | |
| 272 | + $charsetCollate.= " COLLATE $wpdb->collate"; | |
| 273 | + } | |
| 274 | + } | |
| 275 | + | |
| 276 | + return $charsetCollate; | |
| 277 | + } | |
| 278 | + | |
| 279 | + /** | |
| 236 | 280 | * Remove the htaccess file if the plugin is deactivated. |
| 237 | 281 | * |
| 238 | 282 | * @return null |
| 239 | 283 | */ |
| 240 | - function deactivate() | |
| 284 | + public function deactivate() | |
| 241 | 285 | { |
| 242 | 286 | $this->deleteHtaccessFiles(); |
| 243 | 287 | } |
| 244 | 288 | |
| @@ -244,21 +288,29 @@ | ||
| 244 | 288 | |
| 245 | 289 | /** |
| 246 | 290 | * Creates a htaccess file. |
| 247 | 291 | * |
| 292 | + * @param string $dir The destination directory. | |
| 293 | + * @param string $objectType The object type. | |
| 294 | + * | |
| 248 | 295 | * @return null. |
| 249 | 296 | */ |
| 250 | - function createHtaccess() | |
| 297 | + public function createHtaccess($dir = null, $objectType = null) | |
| 251 | 298 | { |
| 252 | - // Make .htaccess file to protect data | |
| 253 | - // get url | |
| 254 | - | |
| 255 | - $wud = wp_upload_dir(); | |
| 256 | - if (empty($wud['error'])) { | |
| 257 | - $dir = $wud['basedir'] . "/"; | |
| 258 | - $permaStruc = get_option('permalink_structure'); | |
| 299 | + if ($dir === null) { | |
| 300 | + $wud = wp_upload_dir(); | |
| 259 | 301 | |
| 260 | - if (empty($permaStruc)) { | |
| 302 | + if (empty($wud['error'])) { | |
| 303 | + $dir = $wud['basedir'] . "/"; | |
| 304 | + } | |
| 305 | + } | |
| 306 | + | |
| 307 | + if ($objectType === null) { | |
| 308 | + $objectType = 'attachment'; | |
| 309 | + } | |
| 310 | + | |
| 311 | + if ($dir !== null) { | |
| 312 | + if (!$this->isPermalinksActive()) { | |
| 261 | 313 | $areaname = "WP-Files"; |
| 262 | 314 | $uamOptions = $this->getAdminOptions(); |
| 263 | 315 | |
| 264 | 316 | if ($uamOptions['lock_file_types'] == 'selected') { |
| @@ -301,14 +353,15 @@ | ||
| 301 | 353 | $htaccessTxt = "<IfModule mod_rewrite.c>\n"; |
| 302 | 354 | $htaccessTxt .= "RewriteEngine On\n"; |
| 303 | 355 | $htaccessTxt .= "RewriteBase ".$homeRoot."\n"; |
| 304 | 356 | $htaccessTxt .= "RewriteRule ^index\.php$ - [L]\n"; |
| 305 | - $htaccessTxt .= "RewriteRule (.*) ".$homeRoot."index.php?getfile=$1 [L]\n"; | |
| 357 | + $htaccessTxt .= "RewriteRule (.*) "; | |
| 358 | + $htaccessTxt .= $homeRoot."index.php?uamfiletype=".$objectType."&uamgetfile=$1 [L]\n"; | |
| 306 | 359 | $htaccessTxt .= "</IfModule>\n"; |
| 307 | 360 | } |
| 308 | 361 | |
| 309 | 362 | // save files |
| 310 | - $htaccess = fopen($dir . ".htaccess", "w"); | |
| 363 | + $htaccess = fopen($dir.".htaccess", "w"); | |
| 311 | 364 | fwrite($htaccess, $htaccessTxt); |
| 312 | 365 | fclose($htaccess); |
| 313 | 366 | } |
| 314 | 367 | } |
| @@ -316,88 +369,45 @@ | ||
| 316 | 369 | /** |
| 317 | 370 | * Creates a htpasswd file. |
| 318 | 371 | * |
| 319 | 372 | * @param boolean $createNew Force to create new file. |
| 373 | + * @param string $dir The destination directory. | |
| 320 | 374 | * |
| 321 | 375 | * @return null |
| 322 | 376 | */ |
| 323 | - function createHtpasswd($createNew = false) | |
| 377 | + public function createHtpasswd($createNew = false, $dir = null) | |
| 324 | 378 | { |
| 325 | 379 | global $current_user; |
| 380 | + | |
| 326 | 381 | $uamOptions = $this->getAdminOptions(); |
| 327 | 382 | |
| 328 | 383 | // get url |
| 329 | - $wud = wp_upload_dir(); | |
| 330 | - if (empty($wud['error'])) { | |
| 331 | - $url = $wud['basedir'] . "/"; | |
| 384 | + if ($dir === null) { | |
| 385 | + $wud = wp_upload_dir(); | |
| 386 | + | |
| 387 | + if (empty($wud['error'])) { | |
| 388 | + $dir = $wud['basedir'] . "/"; | |
| 389 | + } | |
| 390 | + } | |
| 391 | + | |
| 392 | + if ($dir !== null) { | |
| 332 | 393 | $curUserdata = get_userdata($current_user->ID); |
| 333 | - $user = $curUserdata->user_login; | |
| 334 | 394 | |
| 335 | - if (!file_exists($url . ".htpasswd") || $createNew) { | |
| 395 | + if (!file_exists($dir.".htpasswd") || $createNew) { | |
| 336 | 396 | if ($uamOptions['file_pass_type'] == 'random') { |
| 337 | - // create password | |
| 338 | - $array = array(); | |
| 339 | - $length = 10; | |
| 340 | - $capitals = true; | |
| 341 | - $specialSigns = false; | |
| 342 | - if ($length < 8) { | |
| 343 | - $length = mt_rand(8, 20); | |
| 344 | - } | |
| 345 | - | |
| 346 | - // numbers | |
| 347 | - for ($i = 48; $i < 58; $i++) { | |
| 348 | - $array[] = chr($i); | |
| 349 | - } | |
| 350 | - | |
| 351 | - // small | |
| 352 | - for ($i = 97; $i < 122; $i++) { | |
| 353 | - $array[] = chr($i); | |
| 354 | - } | |
| 355 | - | |
| 356 | - // capitals | |
| 357 | - if ($capitals) { | |
| 358 | - for ($i = 65; $i < 90; $i++) { | |
| 359 | - $array[] = chr($i); | |
| 360 | - } | |
| 361 | - } | |
| 362 | - | |
| 363 | - // specialchar: | |
| 364 | - if ($specialSigns) { | |
| 365 | - for ($i = 33; $i < 47; $i++) { | |
| 366 | - $array[] = chr($i); | |
| 367 | - } | |
| 368 | - | |
| 369 | - for ($i = 59; $i < 64; $i++) { | |
| 370 | - $array[] = chr($i); | |
| 371 | - } | |
| 372 | - | |
| 373 | - for ($i = 91; $i < 96; $i++) { | |
| 374 | - $array[] = chr($i); | |
| 375 | - } | |
| 376 | - | |
| 377 | - for ($i = 123; $i < 126; $i++) { | |
| 378 | - $array[] = chr($i); | |
| 379 | - } | |
| 380 | - } | |
| 381 | - | |
| 382 | - mt_srand((double)microtime() * 1000000); | |
| 383 | - $password = ''; | |
| 384 | - | |
| 385 | - for ($i = 1; $i <= $length; $i++) { | |
| 386 | - $rnd = mt_rand(0, count($array) - 1); | |
| 387 | - $password.= $array[$rnd]; | |
| 388 | - $password = md5($password); | |
| 389 | - } | |
| 397 | + $password = md5($this->getRandomPassword()); | |
| 390 | 398 | } elseif ($uamOptions['file_pass_type'] == 'admin') { |
| 391 | 399 | $password = $curUserdata->user_pass; |
| 392 | 400 | } |
| 401 | + | |
| 402 | + $user = $curUserdata->user_login; | |
| 393 | 403 | |
| 394 | 404 | // make .htpasswd |
| 395 | - $htpasswd_txt = "$user:" . $password . "\n"; | |
| 396 | - | |
| 405 | + $htpasswdTxt = "$user:" . $password . "\n"; | |
| 406 | + | |
| 397 | 407 | // save file |
| 398 | - $htpasswd = fopen($url . ".htpasswd", "w"); | |
| 399 | - fwrite($htpasswd, $htpasswd_txt); | |
| 408 | + $htpasswd = fopen($dir.".htpasswd", "w"); | |
| 409 | + fwrite($htpasswd, $htpasswdTxt); | |
| 400 | 410 | fclose($htpasswd); |
| 401 | 411 | } |
| 402 | 412 | } |
| 403 | 413 | } |
| @@ -404,32 +414,102 @@ | ||
| 404 | 414 | |
| 405 | 415 | /** |
| 406 | 416 | * Deletes the htaccess files. |
| 407 | 417 | * |
| 418 | + * @param string $dir The destination directory. | |
| 419 | + * | |
| 408 | 420 | * @return null |
| 409 | 421 | */ |
| 410 | - function deleteHtaccessFiles() | |
| 422 | + public function deleteHtaccessFiles($dir = null) | |
| 411 | 423 | { |
| 412 | - $wud = wp_upload_dir(); | |
| 413 | - if (empty($wud['error'])) { | |
| 414 | - $url = $wud['basedir'] . "/"; | |
| 424 | + if ($dir === null) { | |
| 425 | + $wud = wp_upload_dir(); | |
| 415 | 426 | |
| 416 | - if (file_exists($url.".htaccess")) { | |
| 417 | - unlink($url.".htaccess"); | |
| 427 | + if (empty($wud['error'])) { | |
| 428 | + $dir = $wud['basedir'] . "/"; | |
| 418 | 429 | } |
| 430 | + } | |
| 431 | + | |
| 432 | + if ($dir !== null) { | |
| 433 | + if (file_exists($dir.".htaccess")) { | |
| 434 | + unlink($dir.".htaccess"); | |
| 435 | + } | |
| 419 | 436 | |
| 420 | - if (file_exists($url.".htpasswd")) { | |
| 421 | - unlink($url.".htpasswd"); | |
| 437 | + if (file_exists($dir.".htpasswd")) { | |
| 438 | + unlink($dir.".htpasswd"); | |
| 422 | 439 | } |
| 423 | 440 | } |
| 424 | 441 | } |
| 425 | 442 | |
| 426 | 443 | /** |
| 444 | + * Generates and retruns a randmom password. | |
| 445 | + * | |
| 446 | + * @return string | |
| 447 | + */ | |
| 448 | + public function getRandomPassword() | |
| 449 | + { | |
| 450 | + //create password | |
| 451 | + $array = array(); | |
| 452 | + $length = 16; | |
| 453 | + $capitals = true; | |
| 454 | + $specialSigns = false; | |
| 455 | + if ($length < 8) { | |
| 456 | + $length = mt_rand(8, 20); | |
| 457 | + } | |
| 458 | + | |
| 459 | + // numbers | |
| 460 | + for ($i = 48; $i < 58; $i++) { | |
| 461 | + $array[] = chr($i); | |
| 462 | + } | |
| 463 | + | |
| 464 | + // small | |
| 465 | + for ($i = 97; $i < 122; $i++) { | |
| 466 | + $array[] = chr($i); | |
| 467 | + } | |
| 468 | + | |
| 469 | + // capitals | |
| 470 | + if ($capitals) { | |
| 471 | + for ($i = 65; $i < 90; $i++) { | |
| 472 | + $array[] = chr($i); | |
| 473 | + } | |
| 474 | + } | |
| 475 | + | |
| 476 | + // specialchar: | |
| 477 | + if ($specialSigns) { | |
| 478 | + for ($i = 33; $i < 47; $i++) { | |
| 479 | + $array[] = chr($i); | |
| 480 | + } | |
| 481 | + | |
| 482 | + for ($i = 59; $i < 64; $i++) { | |
| 483 | + $array[] = chr($i); | |
| 484 | + } | |
| 485 | + | |
| 486 | + for ($i = 91; $i < 96; $i++) { | |
| 487 | + $array[] = chr($i); | |
| 488 | + } | |
| 489 | + | |
| 490 | + for ($i = 123; $i < 126; $i++) { | |
| 491 | + $array[] = chr($i); | |
| 492 | + } | |
| 493 | + } | |
| 494 | + | |
| 495 | + mt_srand((double)microtime() * 1000000); | |
| 496 | + $password = ''; | |
| 497 | + | |
| 498 | + for ($i = 1; $i <= $length; $i++) { | |
| 499 | + $rnd = mt_rand(0, count($array) - 1); | |
| 500 | + $password.= $array[$rnd]; | |
| 501 | + } | |
| 502 | + | |
| 503 | + return $password; | |
| 504 | + } | |
| 505 | + | |
| 506 | + /** | |
| 427 | 507 | * Returns the current settings |
| 428 | 508 | * |
| 429 | 509 | * @return array |
| 430 | 510 | */ |
| 431 | - function getAdminOptions() | |
| 511 | + public function getAdminOptions() | |
| 432 | 512 | { |
| 433 | 513 | if (empty($this->adminOptions)) { |
| 434 | 514 | $uamAdminOptions = array( |
| 435 | 515 | 'hide_post_title' => 'false', |
| @@ -495,14 +575,15 @@ | ||
| 495 | 575 | |
| 496 | 576 | /** |
| 497 | 577 | * Retruns the content of the excecuded php file. |
| 498 | 578 | * |
| 499 | - * @param string $fileName The file name | |
| 500 | - * @param integer $id The id if needed. | |
| 579 | + * @param string $fileName The file name | |
| 580 | + * @param integer $objectId The id if needed. | |
| 581 | + * @param string $objectType The object type if needed. | |
| 501 | 582 | * |
| 502 | 583 | * @return string |
| 503 | 584 | */ |
| 504 | - function getIncludeContents($fileName, $id = null) | |
| 585 | + public function getIncludeContents($fileName, $objectId = null, $objectType = null) | |
| 505 | 586 | { |
| 506 | 587 | if (is_file($fileName)) { |
| 507 | 588 | ob_start(); |
| 508 | 589 | include $fileName; |
| @@ -519,9 +600,9 @@ | ||
| 519 | 600 | * Returns the access handler object. |
| 520 | 601 | * |
| 521 | 602 | * @return object |
| 522 | 603 | */ |
| 523 | - function &getAccessHandler() | |
| 604 | + public function &getAccessHandler() | |
| 524 | 605 | { |
| 525 | 606 | if ($this->accessHandler == null) { |
| 526 | 607 | $this->accessHandler = new UamAccessHandler(&$this); |
| 527 | 608 | } |
| @@ -530,8 +611,26 @@ | ||
| 530 | 611 | } |
| 531 | 612 | |
| 532 | 613 | |
| 533 | 614 | /* |
| 615 | + * Helper functions. | |
| 616 | + */ | |
| 617 | + | |
| 618 | + /** | |
| 619 | + * Checks if a string starts with the given needle. | |
| 620 | + * | |
| 621 | + * @param string $haystack The haystack. | |
| 622 | + * @param string $needle The needle | |
| 623 | + * | |
| 624 | + * @return boolean | |
| 625 | + */ | |
| 626 | + public function startsWith($haystack, $needle) | |
| 627 | + { | |
| 628 | + return strpos($haystack, $needle) === 0; | |
| 629 | + } | |
| 630 | + | |
| 631 | + | |
| 632 | + /* | |
| 534 | 633 | * Functions for the admin panel content. |
| 535 | 634 | */ |
| 536 | 635 | |
| 537 | 636 | /** |
| @@ -538,9 +637,9 @@ | ||
| 538 | 637 | * The function for the wp_print_styles action. |
| 539 | 638 | * |
| 540 | 639 | * @return null |
| 541 | 640 | */ |
| 542 | - function addStyles() | |
| 641 | + public function addStyles() | |
| 543 | 642 | { |
| 544 | 643 | wp_enqueue_style( |
| 545 | 644 | 'UserAccessManagerAdmin', |
| 546 | 645 | UAM_URLPATH . "css/uamAdmin.css", |
| @@ -562,9 +661,9 @@ | ||
| 562 | 661 | * The function for the wp_print_scripts action. |
| 563 | 662 | * |
| 564 | 663 | * @return null |
| 565 | 664 | */ |
| 566 | - function addScripts() | |
| 665 | + public function addScripts() | |
| 567 | 666 | { |
| 568 | 667 | wp_enqueue_script( |
| 569 | 668 | 'UserAccessManagerJQueryTools', |
| 570 | 669 | UAM_URLPATH . 'js/jquery.tools.min.js', |
| @@ -581,9 +680,9 @@ | ||
| 581 | 680 | * Prints the admin page |
| 582 | 681 | * |
| 583 | 682 | * @return null |
| 584 | 683 | */ |
| 585 | - function printAdminPage() | |
| 684 | + public function printAdminPage() | |
| 586 | 685 | { |
| 587 | 686 | if (isset($_GET['page'])) { |
| 588 | 687 | $curAdminPage = $_GET['page']; |
| 589 | 688 | } |
| @@ -603,9 +702,9 @@ | ||
| 603 | 702 | * Shows the error if the user has no rights to edit the content |
| 604 | 703 | * |
| 605 | 704 | * @return null |
| 606 | 705 | */ |
| 607 | - function noRightsToEditContent() | |
| 706 | + public function noRightsToEditContent() | |
| 608 | 707 | { |
| 609 | 708 | $noRights = false; |
| 610 | 709 | |
| 611 | 710 | if (isset($_GET['post']) |
| @@ -610,10 +709,14 @@ | ||
| 610 | 709 | |
| 611 | 710 | if (isset($_GET['post']) |
| 612 | 711 | && is_numeric($_GET['post']) |
| 613 | 712 | ) { |
| 614 | - $noRights | |
| 615 | - = !$this->getAccessHandler()->checkAccess($_GET['post']); | |
| 713 | + $post = get_post($_GET['post']); | |
| 714 | + | |
| 715 | + $noRights = !$this->getAccessHandler()->checkObjectAccess( | |
| 716 | + $post->post_type, | |
| 717 | + $post->ID | |
| 718 | + ); | |
| 616 | 719 | } |
| 617 | 720 | |
| 618 | 721 | if (isset($_GET['attachment_id']) |
| 619 | 722 | && is_numeric($_GET['attachment_id']) |
| @@ -618,10 +721,14 @@ | ||
| 618 | 721 | if (isset($_GET['attachment_id']) |
| 619 | 722 | && is_numeric($_GET['attachment_id']) |
| 620 | 723 | && !$noRights |
| 621 | 724 | ) { |
| 622 | - $noRights | |
| 623 | - = !$this->getAccessHandler()->checkAccess($_GET['attachment_id']); | |
| 725 | + $post = get_post($_GET['attachment_id']); | |
| 726 | + | |
| 727 | + $noRights = !$this->getAccessHandler()->checkObjectAccess( | |
| 728 | + $post->post_type, | |
| 729 | + $post->ID | |
| 730 | + ); | |
| 624 | 731 | } |
| 625 | 732 | |
| 626 | 733 | if (isset($_GET['tag_ID']) |
| 627 | 734 | && is_numeric($_GET['tag_ID']) |
| @@ -626,10 +733,12 @@ | ||
| 626 | 733 | if (isset($_GET['tag_ID']) |
| 627 | 734 | && is_numeric($_GET['tag_ID']) |
| 628 | 735 | && !$noRights |
| 629 | 736 | ) { |
| 630 | - $noRights | |
| 631 | - = !$this->getAccessHandler()->checkCategoryAccess($_GET['tag_ID']); | |
| 737 | + $noRights = !$this->getAccessHandler()->checkObjectAccess( | |
| 738 | + 'category', | |
| 739 | + $_GET['tag_ID'] | |
| 740 | + ); | |
| 632 | 741 | } |
| 633 | 742 | |
| 634 | 743 | if ($noRights) { |
| 635 | 744 | wp_die(TXT_NO_RIGHTS); |
| @@ -641,9 +750,9 @@ | ||
| 641 | 750 | * Removes widgets to which a user should not have access. |
| 642 | 751 | * |
| 643 | 752 | * @return null |
| 644 | 753 | */ |
| 645 | - function setupAdminDashboard() | |
| 754 | + public function setupAdminDashboard() | |
| 646 | 755 | { |
| 647 | 756 | global $wp_meta_boxes; |
| 648 | 757 | |
| 649 | 758 | if (!$this->getAccessHandler()->checkUserAccess()) { |
| @@ -655,14 +764,65 @@ | ||
| 655 | 764 | * The function for the update_option_permalink_structure action. |
| 656 | 765 | * |
| 657 | 766 | * @return null |
| 658 | 767 | */ |
| 659 | - function updatePermalink() | |
| 768 | + public function updatePermalink() | |
| 660 | 769 | { |
| 661 | 770 | $this->createHtaccess(); |
| 771 | + $this->createHtpasswd(); | |
| 662 | 772 | } |
| 663 | 773 | |
| 774 | + /* | |
| 775 | + * Meta functions | |
| 776 | + */ | |
| 777 | + | |
| 664 | 778 | /** |
| 779 | + * Saves the object data to the database. | |
| 780 | + * | |
| 781 | + * @param string $objectType The object type. | |
| 782 | + * @param integer $objectId The id of the object. | |
| 783 | + * | |
| 784 | + * @return null | |
| 785 | + */ | |
| 786 | + private function _saveObjectData($objectType, $objectId) | |
| 787 | + { | |
| 788 | + $uamAccessHandler = &$this->getAccessHandler(); | |
| 789 | + $uamOptions = $this->getAdminOptions(); | |
| 790 | + | |
| 791 | + if (isset($_POST['uam_update_groups']) | |
| 792 | + && ($uamAccessHandler->checkUserAccess() | |
| 793 | + || $uamOptions['authors_can_add_posts_to_groups'] == 'true') | |
| 794 | + ) { | |
| 795 | + $userGroupsForObject = $uamAccessHandler->getUserGroupsForObject( | |
| 796 | + $objectType, | |
| 797 | + $objectId | |
| 798 | + ); | |
| 799 | + | |
| 800 | + foreach ($userGroupsForObject as $uamUserGroup) { | |
| 801 | + $uamUserGroup->removeObject($objectType, $objectId); | |
| 802 | + $uamUserGroup->save(); | |
| 803 | + } | |
| 804 | + | |
| 805 | + if (isset($_POST['uam_usergroups'])) { | |
| 806 | + $userGroups = $_POST['uam_usergroups']; | |
| 807 | + } | |
| 808 | + | |
| 809 | + if (isset($userGroups)) { | |
| 810 | + foreach ($userGroups as $userGroupId) { | |
| 811 | + $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId); | |
| 812 | + | |
| 813 | + $uamUserGroup->addObject($objectType, $objectId); | |
| 814 | + $uamUserGroup->save(); | |
| 815 | + } | |
| 816 | + } | |
| 817 | + } | |
| 818 | + } | |
| 819 | + | |
| 820 | + /* | |
| 821 | + * Functions for the post actions. | |
| 822 | + */ | |
| 823 | + | |
| 824 | + /** | |
| 665 | 825 | * The function for the manage_posts_columns and |
| 666 | 826 | * the manage_pages_columns filter. |
| 667 | 827 | * |
| 668 | 828 | * @param array $defaults The table headers. |
| @@ -668,9 +828,9 @@ | ||
| 668 | 828 | * @param array $defaults The table headers. |
| 669 | 829 | * |
| 670 | 830 | * @return array |
| 671 | 831 | */ |
| 672 | - function addPostColumnsHeader($defaults) | |
| 832 | + public function addPostColumnsHeader($defaults) | |
| 673 | 833 | { |
| 674 | 834 | $defaults['uam_access'] = __('Access'); |
| 675 | 835 | return $defaults; |
| 676 | 836 | } |
| @@ -682,12 +842,18 @@ | ||
| 682 | 842 | * @param integer $id The id. |
| 683 | 843 | * |
| 684 | 844 | * @return String |
| 685 | 845 | */ |
| 686 | - function addPostColumn($columnName, $id) | |
| 846 | + public function addPostColumn($columnName, $id) | |
| 687 | 847 | { |
| 688 | 848 | if ($columnName == 'uam_access') { |
| 689 | - echo $this->getIncludeContents(UAM_REALPATH.'tpl/postColumn.php', $id); | |
| 849 | + $post = get_post($id); | |
| 850 | + | |
| 851 | + echo $this->getIncludeContents( | |
| 852 | + UAM_REALPATH.'tpl/objectColumn.php', | |
| 853 | + $post->ID, | |
| 854 | + $post->post_type | |
| 855 | + ); | |
| 690 | 856 | } |
| 691 | 857 | } |
| 692 | 858 | |
| 693 | 859 | /** |
| @@ -696,10 +862,12 @@ | ||
| 696 | 862 | * @param object $post The post. |
| 697 | 863 | * |
| 698 | 864 | * @return null; |
| 699 | 865 | */ |
| 700 | - function editPostContent($post) | |
| 866 | + public function editPostContent($post) | |
| 701 | 867 | { |
| 868 | + $objectId = $post->ID; | |
| 869 | + | |
| 702 | 870 | include UAM_REALPATH.'tpl/postEditForm.php'; |
| 703 | 871 | } |
| 704 | 872 | |
| 705 | 873 | /** |
| @@ -708,57 +876,26 @@ | ||
| 708 | 876 | * @param mixed $postParam The post id or a array of a post. |
| 709 | 877 | * |
| 710 | 878 | * @return null |
| 711 | 879 | */ |
| 712 | - function savePostData($postParam) | |
| 713 | - { | |
| 714 | - $uamAccessHandler = &$this->getAccessHandler(); | |
| 715 | - $uamOptions = $this->getAdminOptions(); | |
| 880 | + public function savePostData($postParam) | |
| 881 | + { | |
| 882 | + if (is_array($postParam)) { | |
| 883 | + $post = get_post($postParam['ID']); | |
| 884 | + } else { | |
| 885 | + $post = get_post($postParam); | |
| 886 | + } | |
| 887 | + | |
| 888 | + $postId = $post->ID; | |
| 889 | + $postType = $post->post_type; | |
| 716 | 890 | |
| 717 | - if ($uamAccessHandler->checkUserAccess() | |
| 718 | - || $uamOptions['authors_can_add_posts_to_groups'] == 'true' | |
| 719 | - ) { | |
| 720 | - if (is_array($postParam)) { | |
| 721 | - $post = get_post($postParam['ID']); | |
| 722 | - } else { | |
| 723 | - $post = get_post($postParam); | |
| 724 | - } | |
| 725 | - | |
| 726 | - if ($post->post_type == 'revision') { | |
| 727 | - $postId = $post->post_parent; | |
| 728 | - $post = get_post($postId); | |
| 729 | - } else { | |
| 730 | - $postId = $post->ID; | |
| 731 | - } | |
| 732 | - | |
| 733 | - if ($post->post_type == 'post') { | |
| 734 | - $postType = 'Post'; | |
| 735 | - } elseif ($post->post_type == 'page') { | |
| 736 | - $postType = 'Page'; | |
| 737 | - } elseif ($post->post_type == 'attachment') { | |
| 738 | - $postType = 'File'; | |
| 739 | - } | |
| 740 | - | |
| 741 | - $userGroupsForPost = $uamAccessHandler->getUserGroupsForPost($postId); | |
| 742 | - | |
| 743 | - foreach ($userGroupsForPost as $uamUserGroup) { | |
| 744 | - $uamUserGroup->{'remove'.$postType}($postId); | |
| 745 | - $uamUserGroup->save(); | |
| 746 | - } | |
| 747 | - | |
| 748 | - if (isset($_POST['usergroups'])) { | |
| 749 | - $userGroups = $_POST['usergroups']; | |
| 750 | - } | |
| 751 | - | |
| 752 | - if (isset($userGroups)) { | |
| 753 | - foreach ($userGroups as $userGroupId) { | |
| 754 | - $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId); | |
| 755 | - | |
| 756 | - $uamUserGroup->{'add'.$postType}($postId); | |
| 757 | - $uamUserGroup->save(); | |
| 758 | - } | |
| 759 | - } | |
| 891 | + if ($postType == 'revision') { | |
| 892 | + $postId = $post->post_parent; | |
| 893 | + $parentPost = get_post($postId); | |
| 894 | + $postType = $parentPost->post_type; | |
| 760 | 895 | } |
| 896 | + | |
| 897 | + $this->_saveObjectData($postType, $postId); | |
| 761 | 898 | } |
| 762 | 899 | |
| 763 | 900 | /** |
| 764 | 901 | * The function for the attachment_fields_to_save filter. |
| @@ -768,9 +905,9 @@ | ||
| 768 | 905 | * @param object $attachment The attachment id. |
| 769 | 906 | * |
| 770 | 907 | * @return object |
| 771 | 908 | */ |
| 772 | - function saveAttachmentData($attachment) | |
| 909 | + public function saveAttachmentData($attachment) | |
| 773 | 910 | { |
| 774 | 911 | $this->savePostData($attachment['ID']); |
| 775 | 912 | |
| 776 | 913 | return $attachment; |
| @@ -782,9 +919,9 @@ | ||
| 782 | 919 | * @param integer $postId The post id. |
| 783 | 920 | * |
| 784 | 921 | * @return null |
| 785 | 922 | */ |
| 786 | - function removePostData($postId) | |
| 923 | + public function removePostData($postId) | |
| 787 | 924 | { |
| 788 | 925 | global $wpdb; |
| 789 | 926 | |
| 790 | 927 | $wpdb->query( |
| @@ -800,10 +937,10 @@ | ||
| 800 | 937 | * @param object $post The post. |
| 801 | 938 | * |
| 802 | 939 | * @return string |
| 803 | 940 | */ |
| 804 | - function showMediaFile($meta = '', $post = null) | |
| 805 | - { | |
| 941 | + public function showMediaFile($meta = '', $post = null) | |
| 942 | + { | |
| 806 | 943 | $content = $meta; |
| 807 | 944 | $content .= '</td></tr><tr>'; |
| 808 | 945 | $content .= '<th class="label">'; |
| 809 | 946 | $content .= '<label>'.TXT_SET_UP_USERGROUPS.'</label>'; |
| @@ -808,13 +945,21 @@ | ||
| 808 | 945 | $content .= '<th class="label">'; |
| 809 | 946 | $content .= '<label>'.TXT_SET_UP_USERGROUPS.'</label>'; |
| 810 | 947 | $content .= '</th>'; |
| 811 | 948 | $content .= '<td class="field">'; |
| 812 | - $content .= $this->getIncludeContents(UAM_REALPATH.'tpl/postEditForm.php'); | |
| 949 | + $content .= $this->getIncludeContents( | |
| 950 | + UAM_REALPATH.'tpl/postEditForm.php', | |
| 951 | + $post->ID | |
| 952 | + ); | |
| 813 | 953 | |
| 814 | 954 | return $content; |
| 815 | 955 | } |
| 816 | 956 | |
| 957 | + | |
| 958 | + /* | |
| 959 | + * Functions for the user actions. | |
| 960 | + */ | |
| 961 | + | |
| 817 | 962 | /** |
| 818 | 963 | * The function for the manage_users_columns filter. |
| 819 | 964 | * |
| 820 | 965 | * @param array $defaults The table headers. |
| @@ -820,9 +965,9 @@ | ||
| 820 | 965 | * @param array $defaults The table headers. |
| 821 | 966 | * |
| 822 | 967 | * @return array |
| 823 | 968 | */ |
| 824 | - function addUserColumnsHeader($defaults) | |
| 969 | + public function addUserColumnsHeader($defaults) | |
| 825 | 970 | { |
| 826 | 971 | $defaults['uam_access'] = __('uam user groups'); |
| 827 | 972 | return $defaults; |
| 828 | 973 | } |
| @@ -835,14 +980,15 @@ | ||
| 835 | 980 | * @param integer $id The id. |
| 836 | 981 | * |
| 837 | 982 | * @return String |
| 838 | 983 | */ |
| 839 | - function addUserColumn($empty, $columnName, $id) | |
| 984 | + public function addUserColumn($empty, $columnName, $id) | |
| 840 | 985 | { |
| 841 | 986 | if ($columnName == 'uam_access') { |
| 842 | 987 | return $this->getIncludeContents( |
| 843 | 988 | UAM_REALPATH.'tpl/userColumn.php', |
| 844 | - $id | |
| 989 | + $id, | |
| 990 | + 'user' | |
| 845 | 991 | ); |
| 846 | 992 | } |
| 847 | 993 | } |
| 848 | 994 | |
| @@ -850,9 +996,9 @@ | ||
| 850 | 996 | * The function for the edit_user_profile action. |
| 851 | 997 | * |
| 852 | 998 | * @return null |
| 853 | 999 | */ |
| 854 | - function showUserProfile() | |
| 1000 | + public function showUserProfile() | |
| 855 | 1001 | { |
| 856 | 1002 | echo $this->getIncludeContents(UAM_REALPATH.'tpl/userProfileEditForm.php'); |
| 857 | 1003 | } |
| 858 | 1004 | |
| @@ -862,37 +1008,11 @@ | ||
| 862 | 1008 | * @param integer $userId The user id. |
| 863 | 1009 | * |
| 864 | 1010 | * @return null |
| 865 | 1011 | */ |
| 866 | - function saveUserData($userId) | |
| 1012 | + public function saveUserData($userId) | |
| 867 | 1013 | { |
| 868 | - $uamAccessHandler = &$this->getAccessHandler(); | |
| 869 | - | |
| 870 | - if ($uamAccessHandler->checkUserAccess()) { | |
| 871 | - if ($uamAccessHandler->checkUserAccess()) { | |
| 872 | - $userGroupsForPost | |
| 873 | - = $uamAccessHandler->getUserGroupsForUser($userId); | |
| 874 | - | |
| 875 | - foreach ($userGroupsForPost as $uamUserGroup) { | |
| 876 | - $uamUserGroup->removeUser($userId); | |
| 877 | - $uamUserGroup->save(); | |
| 878 | - } | |
| 879 | - | |
| 880 | - if (isset($_POST['usergroups'])) { | |
| 881 | - $userGroups = $_POST['usergroups']; | |
| 882 | - } | |
| 883 | - | |
| 884 | - if (isset($userGroups)) { | |
| 885 | - foreach ($userGroups as $userGroupId) { | |
| 886 | - $uamUserGroup | |
| 887 | - = $uamAccessHandler->getUserGroups($userGroupId); | |
| 888 | - | |
| 889 | - $uamUserGroup->addUser($userId); | |
| 890 | - $uamUserGroup->save(); | |
| 891 | - } | |
| 892 | - } | |
| 893 | - } | |
| 894 | - } | |
| 1014 | + $this->_saveObjectData('user', $userId); | |
| 895 | 1015 | } |
| 896 | 1016 | |
| 897 | 1017 | /** |
| 898 | 1018 | * The function for the delete_user action. |
| @@ -900,9 +1020,9 @@ | ||
| 900 | 1020 | * @param integer $userId The user id. |
| 901 | 1021 | * |
| 902 | 1022 | * @return null |
| 903 | 1023 | */ |
| 904 | - function removeUserData($userId) | |
| 1024 | + public function removeUserData($userId) | |
| 905 | 1025 | { |
| 906 | 1026 | global $wpdb; |
| 907 | 1027 | |
| 908 | 1028 | $wpdb->query( |
| @@ -910,8 +1030,13 @@ | ||
| 910 | 1030 | WHERE user_id = ".$userId |
| 911 | 1031 | ); |
| 912 | 1032 | } |
| 913 | 1033 | |
| 1034 | + | |
| 1035 | + /* | |
| 1036 | + * Functions for the category actions. | |
| 1037 | + */ | |
| 1038 | + | |
| 914 | 1039 | /** |
| 915 | 1040 | * The function for the manage_categories_columns filter. |
| 916 | 1041 | * |
| 917 | 1042 | * @param array $defaults The table headers. |
| @@ -917,9 +1042,9 @@ | ||
| 917 | 1042 | * @param array $defaults The table headers. |
| 918 | 1043 | * |
| 919 | 1044 | * @return array |
| 920 | 1045 | */ |
| 921 | - function addCategoryColumnsHeader($defaults) | |
| 1046 | + public function addCategoryColumnsHeader($defaults) | |
| 922 | 1047 | { |
| 923 | 1048 | $defaults['uam_access'] = __('Access'); |
| 924 | 1049 | return $defaults; |
| 925 | 1050 | } |
| @@ -932,14 +1057,15 @@ | ||
| 932 | 1057 | * @param integer $id The id. |
| 933 | 1058 | * |
| 934 | 1059 | * @return String |
| 935 | 1060 | */ |
| 936 | - function addCategoryColumn($empty, $columnName, $id) | |
| 1061 | + public function addCategoryColumn($empty, $columnName, $id) | |
| 937 | 1062 | { |
| 938 | 1063 | if ($columnName == 'uam_access') { |
| 939 | 1064 | return $this->getIncludeContents( |
| 940 | - UAM_REALPATH.'tpl/categoryColumn.php', | |
| 941 | - $id | |
| 1065 | + UAM_REALPATH.'tpl/objectColumn.php', | |
| 1066 | + $id, | |
| 1067 | + 'category' | |
| 942 | 1068 | ); |
| 943 | 1069 | } |
| 944 | 1070 | } |
| 945 | 1071 | |
| @@ -949,9 +1075,9 @@ | ||
| 949 | 1075 | * @param object $category The category. |
| 950 | 1076 | * |
| 951 | 1077 | * @return null |
| 952 | 1078 | */ |
| 953 | - function showCategoryEditForm($category) | |
| 1079 | + public function showCategoryEditForm($category) | |
| 954 | 1080 | { |
| 955 | 1081 | include UAM_REALPATH.'tpl/categoryEditForm.php'; |
| 956 | 1082 | } |
| 957 | 1083 | |
| @@ -961,37 +1087,11 @@ | ||
| 961 | 1087 | * @param integer $categoryId The category id. |
| 962 | 1088 | * |
| 963 | 1089 | * @return null |
| 964 | 1090 | */ |
| 965 | - function saveCategoryData($categoryId) | |
| 1091 | + public function saveCategoryData($categoryId) | |
| 966 | 1092 | { |
| 967 | - $uamAccessHandler = &$this->getAccessHandler(); | |
| 968 | - $uamOptions = $this->getAdminOptions(); | |
| 969 | - | |
| 970 | - if ($uamAccessHandler->checkUserAccess() | |
| 971 | - || $uamOptions['authors_can_add_posts_to_groups'] == 'true' | |
| 972 | - ) { | |
| 973 | - $userGroupsForCategory | |
| 974 | - = $uamAccessHandler->getUserGroupsForCategory($categoryId); | |
| 975 | - | |
| 976 | - foreach ($userGroupsForCategory as $uamUserGroup) { | |
| 977 | - $uamUserGroup->removeCategory($categoryId); | |
| 978 | - $uamUserGroup->save(); | |
| 979 | - } | |
| 980 | - | |
| 981 | - if (isset($_POST['usergroups'])) { | |
| 982 | - $userGroups = $_POST['usergroups']; | |
| 983 | - } | |
| 984 | - | |
| 985 | - if (isset($userGroups)) { | |
| 986 | - foreach ($userGroups as $userGroupId) { | |
| 987 | - $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId); | |
| 988 | - | |
| 989 | - $uamUserGroup->addCategory($categoryId); | |
| 990 | - $uamUserGroup->save(); | |
| 991 | - } | |
| 992 | - } | |
| 993 | - } | |
| 1093 | + $this->_saveObjectData('category', $categoryId); | |
| 994 | 1094 | } |
| 995 | 1095 | |
| 996 | 1096 | /** |
| 997 | 1097 | * The function for the delete_category action. |
| @@ -999,9 +1099,9 @@ | ||
| 999 | 1099 | * @param integer $categoryId The id of the category. |
| 1000 | 1100 | * |
| 1001 | 1101 | * @return null |
| 1002 | 1102 | */ |
| 1003 | - function removeCategoryData($categoryId) | |
| 1103 | + public function removeCategoryData($categoryId) | |
| 1004 | 1104 | { |
| 1005 | 1105 | global $wpdb; |
| 1006 | 1106 | |
| 1007 | 1107 | $wpdb->query( |
| @@ -1008,15 +1108,111 @@ | ||
| 1008 | 1108 | "DELETE FROM " . DB_ACCESSGROUP_TO_CATEGORY . " |
| 1009 | 1109 | WHERE category_id = ".$categoryId |
| 1010 | 1110 | ); |
| 1011 | 1111 | } |
| 1112 | + | |
| 1012 | 1113 | |
| 1114 | + /* | |
| 1115 | + * Functions for the pluggable object actions. | |
| 1116 | + */ | |
| 1013 | 1117 | |
| 1118 | + /** | |
| 1119 | + * The function for the pluggable save action. | |
| 1120 | + * | |
| 1121 | + * @param string $objectType The name of the pluggable object. | |
| 1122 | + * @param integer $objectId The pluggable object id. | |
| 1123 | + * | |
| 1124 | + * @return null | |
| 1125 | + */ | |
| 1126 | + public function savePlObjectData($objectType, $objectId) | |
| 1127 | + { | |
| 1128 | + $this->_saveObjectData($objectType, $objectId); | |
| 1129 | + } | |
| 1130 | + | |
| 1131 | + /** | |
| 1132 | + * The function for the pluggable remove action. | |
| 1133 | + * | |
| 1134 | + * @param string $objectName The name of the pluggable object. | |
| 1135 | + * @param integer $objectId The pluggable object id. | |
| 1136 | + * | |
| 1137 | + * @return null | |
| 1138 | + */ | |
| 1139 | + public function removePlObjectData($objectName, $objectId) | |
| 1140 | + { | |
| 1141 | + global $wpdb; | |
| 1142 | + | |
| 1143 | + $wpdb->query( | |
| 1144 | + "DELETE FROM " . DB_ACCESSGROUP_TO_OBJECT . " | |
| 1145 | + WHERE user_id = ".$userId." | |
| 1146 | + AND object_type = ".$objectName | |
| 1147 | + ); | |
| 1148 | + } | |
| 1149 | + | |
| 1150 | + /** | |
| 1151 | + * Returns the group selection form for pluggable objects. | |
| 1152 | + * | |
| 1153 | + * @param string $objectType The object type. | |
| 1154 | + * @param integer $objectId The id of the object. | |
| 1155 | + * | |
| 1156 | + * @return string; | |
| 1157 | + */ | |
| 1158 | + public function showPlGroupSelectionForm($objectType, $objectId) | |
| 1159 | + { | |
| 1160 | + $fileName = UAM_REALPATH.'tpl/groupSelectionForm.php'; | |
| 1161 | + $uamUserGroups = $this->getAccessHandler()->getUserGroups(); | |
| 1162 | + $userGroupsForObject = $this->getAccessHandler()->getUserGroupsForObject( | |
| 1163 | + $objectType, | |
| 1164 | + $objectId | |
| 1165 | + ); | |
| 1166 | + | |
| 1167 | + if (is_file($fileName)) { | |
| 1168 | + ob_start(); | |
| 1169 | + include $fileName; | |
| 1170 | + $contents = ob_get_contents(); | |
| 1171 | + ob_end_clean(); | |
| 1172 | + | |
| 1173 | + return $contents; | |
| 1174 | + } | |
| 1175 | + | |
| 1176 | + return ''; | |
| 1177 | + } | |
| 1178 | + | |
| 1179 | + /** | |
| 1180 | + * Returns the column for a pluggable object. | |
| 1181 | + * | |
| 1182 | + * @param string $objectType The object type. | |
| 1183 | + * @param integer $objectId The object id. | |
| 1184 | + * | |
| 1185 | + * @return string | |
| 1186 | + */ | |
| 1187 | + public function getPlColumn($objectType, $objectId) | |
| 1188 | + { | |
| 1189 | + return $this->getIncludeContents( | |
| 1190 | + UAM_REALPATH.'tpl/objectColumn.php', | |
| 1191 | + $objectId, | |
| 1192 | + $objectType | |
| 1193 | + ); | |
| 1194 | + } | |
| 1195 | + | |
| 1196 | + | |
| 1014 | 1197 | /* |
| 1015 | 1198 | * Functions for the blog content. |
| 1016 | 1199 | */ |
| 1017 | 1200 | |
| 1018 | 1201 | /** |
| 1202 | + * Manipulates the wordpress query object to filter content. | |
| 1203 | + * | |
| 1204 | + * @param object $wpQuery The wordpress query object. | |
| 1205 | + * | |
| 1206 | + * @return null | |
| 1207 | + */ | |
| 1208 | + public function parseQuery($wpQuery) | |
| 1209 | + { | |
| 1210 | + $wpQuery->query_vars['post__not_in'] | |
| 1211 | + += $this->_getExcludedPosts(); | |
| 1212 | + } | |
| 1213 | + | |
| 1214 | + /** | |
| 1019 | 1215 | * Modifies the content of the post by the given settings. |
| 1020 | 1216 | * |
| 1021 | 1217 | * @param object $post The current post. |
| 1022 | 1218 | * |
| @@ -1037,15 +1233,17 @@ | ||
| 1037 | 1233 | |
| 1038 | 1234 | if ($uamOptions['hide_'.$postType] == 'true' |
| 1039 | 1235 | || $this->atAdminPanel |
| 1040 | 1236 | ) { |
| 1041 | - if ($uamAccessHandler->checkAccess($post->ID)) { | |
| 1042 | - $post->post_title .= $this->adminOutput($post->ID); | |
| 1237 | + if ($uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) { | |
| 1238 | + $post->post_title .= $this->adminOutput($post->post_type, $post->ID); | |
| 1043 | 1239 | |
| 1044 | 1240 | return $post; |
| 1045 | 1241 | } |
| 1046 | 1242 | } else { |
| 1047 | - if (!$uamAccessHandler->checkAccess($post->ID)) { | |
| 1243 | + if (!$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) { | |
| 1244 | + $post->isLocked = true; | |
| 1245 | + | |
| 1048 | 1246 | $uamPostContent = $uamOptions[$postType.'_content']; |
| 1049 | 1247 | $uamPostContent = str_replace( |
| 1050 | 1248 | "[LOGIN_FORM]", |
| 1051 | 1249 | $this->getLoginBarHtml(), |
| @@ -1075,9 +1273,9 @@ | ||
| 1075 | 1273 | |
| 1076 | 1274 | $post->post_content = $uamPostContent; |
| 1077 | 1275 | } |
| 1078 | 1276 | |
| 1079 | - $post->post_title .= $this->adminOutput($post->ID); | |
| 1277 | + $post->post_title .= $this->adminOutput($post->post_type, $post->ID); | |
| 1080 | 1278 | |
| 1081 | 1279 | return $post; |
| 1082 | 1280 | } |
| 1083 | 1281 | |
| @@ -1090,9 +1288,9 @@ | ||
| 1090 | 1288 | * @param arrray $posts The posts. |
| 1091 | 1289 | * |
| 1092 | 1290 | * @return array |
| 1093 | 1291 | */ |
| 1094 | - function showPost($posts = array()) | |
| 1292 | + public function showPost($posts = array()) | |
| 1095 | 1293 | { |
| 1096 | 1294 | $showPosts = array(); |
| 1097 | 1295 | $uamOptions = $this->getAdminOptions(); |
| 1098 | 1296 | |
| @@ -1113,8 +1311,118 @@ | ||
| 1113 | 1311 | return $posts; |
| 1114 | 1312 | } |
| 1115 | 1313 | |
| 1116 | 1314 | /** |
| 1315 | + * Returns the excluded posts. | |
| 1316 | + * | |
| 1317 | + * @return array | |
| 1318 | + */ | |
| 1319 | + private function _getExcludedPosts() | |
| 1320 | + { | |
| 1321 | + $uamAccessHandler = &$this->getAccessHandler(); | |
| 1322 | + | |
| 1323 | + if ($uamAccessHandler->checkUserAccess()) { | |
| 1324 | + return array(); | |
| 1325 | + } | |
| 1326 | + | |
| 1327 | + global $current_user, $wpdb; | |
| 1328 | + //Force user infos | |
| 1329 | + wp_get_current_user(); | |
| 1330 | + | |
| 1331 | + $userUserGroups = $uamAccessHandler->getUserGroupsForObject( | |
| 1332 | + 'user', | |
| 1333 | + $current_user->ID, | |
| 1334 | + false | |
| 1335 | + ); | |
| 1336 | + | |
| 1337 | + $userUserGroupArray = array(); | |
| 1338 | + | |
| 1339 | + foreach ($userUserGroups as $userUserGroup) { | |
| 1340 | + $userUserGroupArray[] = $userUserGroup->getId(); | |
| 1341 | + } | |
| 1342 | + | |
| 1343 | + if ($userUserGroupArray !== array()) { | |
| 1344 | + $userUserGroupString = implode(', ', $userUserGroupArray); | |
| 1345 | + } else { | |
| 1346 | + $userUserGroupString = 'NULL'; | |
| 1347 | + } | |
| 1348 | + | |
| 1349 | + $postSql = "SELECT DISTINCT p.ID | |
| 1350 | + FROM $wpdb->posts AS p | |
| 1351 | + INNER JOIN $wpdb->term_relationships AS tr | |
| 1352 | + ON p.ID = tr.object_id | |
| 1353 | + INNER JOIN $wpdb->term_taxonomy tt | |
| 1354 | + ON tr.term_taxonomy_id = tt.term_taxonomy_id | |
| 1355 | + WHERE tt.taxonomy = 'category' | |
| 1356 | + AND tt.term_id IN ( | |
| 1357 | + SELECT gc.object_id | |
| 1358 | + FROM ".DB_ACCESSGROUP_TO_OBJECT." gc | |
| 1359 | + WHERE gc.object_type = 'category' | |
| 1360 | + AND gc.object_id NOT IN ( | |
| 1361 | + SELECT igc.object_id | |
| 1362 | + FROM ".DB_ACCESSGROUP_TO_OBJECT." igc | |
| 1363 | + WHERE igc.object_type = 'category' | |
| 1364 | + AND igc.group_id IN (".$userUserGroupString.") | |
| 1365 | + ) | |
| 1366 | + ) AND p.ID NOT IN ( | |
| 1367 | + SELECT igp.object_id | |
| 1368 | + FROM ".DB_ACCESSGROUP_TO_OBJECT." igp | |
| 1369 | + WHERE (igp.object_type = 'post' OR igp.object_type = 'page') | |
| 1370 | + AND igp.group_id IN (".$userUserGroupString.") | |
| 1371 | + ) | |
| 1372 | + UNION | |
| 1373 | + SELECT DISTINCT gp.object_id | |
| 1374 | + FROM ".DB_ACCESSGROUP_TO_OBJECT." gp | |
| 1375 | + INNER JOIN $wpdb->term_relationships AS tr | |
| 1376 | + ON gp.object_id = tr.object_id | |
| 1377 | + INNER JOIN $wpdb->term_taxonomy tt | |
| 1378 | + ON tr.term_taxonomy_id = tt.term_taxonomy_id | |
| 1379 | + WHERE (gp.object_type = 'post' OR gp.object_type = 'page') | |
| 1380 | + AND gp.object_id NOT IN ( | |
| 1381 | + SELECT igp.object_id | |
| 1382 | + FROM ".DB_ACCESSGROUP_TO_OBJECT." igp | |
| 1383 | + WHERE (igp.object_type = 'post' OR igp.object_type = 'page') | |
| 1384 | + AND igp.group_id IN (".$userUserGroupString.") | |
| 1385 | + ) AND tt.term_id NOT IN ( | |
| 1386 | + SELECT igc.object_id | |
| 1387 | + FROM ".DB_ACCESSGROUP_TO_OBJECT." igc | |
| 1388 | + WHERE igc.object_type = 'category' | |
| 1389 | + AND igc.group_id IN (".$userUserGroupString.") | |
| 1390 | + )"; | |
| 1391 | + | |
| 1392 | + $excludedPosts = $wpdb->get_col($postSql); | |
| 1393 | + | |
| 1394 | + return $excludedPosts; | |
| 1395 | + } | |
| 1396 | + | |
| 1397 | + /** | |
| 1398 | + * The function for the posts_where_paged filter. | |
| 1399 | + * | |
| 1400 | + * @param string $sql The where sql statment. | |
| 1401 | + * | |
| 1402 | + * @return string | |
| 1403 | + */ | |
| 1404 | + public function showPostSql($sql) | |
| 1405 | + { | |
| 1406 | + $uamAccessHandler = &$this->getAccessHandler(); | |
| 1407 | + $uamOptions = $this->getAdminOptions(); | |
| 1408 | + | |
| 1409 | + if ($uamOptions['hide_post'] == 'true' | |
| 1410 | + && !$uamAccessHandler->checkUserAccess() | |
| 1411 | + ) { | |
| 1412 | + global $wpdb; | |
| 1413 | + $excludedPosts = $this->_getExcludedPosts(); | |
| 1414 | + | |
| 1415 | + if (count($excludedPosts) > 0) { | |
| 1416 | + $excludedPostsStr = implode(",", $excludedPosts); | |
| 1417 | + $sql .= " AND $wpdb->posts.ID NOT IN($excludedPostsStr) "; | |
| 1418 | + } | |
| 1419 | + } | |
| 1420 | + | |
| 1421 | + return $sql; | |
| 1422 | + } | |
| 1423 | + | |
| 1424 | + /** | |
| 1117 | 1425 | * The function for the wp_get_nav_menu_items filter. |
| 1118 | 1426 | * |
| 1119 | 1427 | * @param array $items The menu item. |
| 1120 | 1428 | * |
| @@ -1119,9 +1427,9 @@ | ||
| 1119 | 1427 | * @param array $items The menu item. |
| 1120 | 1428 | * |
| 1121 | 1429 | * @return array |
| 1122 | 1430 | */ |
| 1123 | - function showCustomMenu($items) | |
| 1431 | + public function showCustomMenu($items) | |
| 1124 | 1432 | { |
| 1125 | 1433 | $showItems = array(); |
| 1126 | 1434 | |
| 1127 | 1435 | foreach ($items as $item) { |
| @@ -1131,9 +1439,13 @@ | ||
| 1131 | 1439 | $object = get_post($item->object_id); |
| 1132 | 1440 | $post = $this->_getPost($object); |
| 1133 | 1441 | |
| 1134 | 1442 | if ($post !== null) { |
| 1135 | - $item->title = $post->post_title; | |
| 1443 | + if (isset($post->isLocked)) { | |
| 1444 | + $item->title = $post->post_title; | |
| 1445 | + } | |
| 1446 | + | |
| 1447 | + $item->title .= $this->adminOutput($item->object, $item->object_id); | |
| 1136 | 1448 | |
| 1137 | 1449 | $showItems[] = $item; |
| 1138 | 1450 | } |
| 1139 | 1451 | } elseif ($item->object == 'category') { |
| @@ -1142,8 +1454,9 @@ | ||
| 1142 | 1454 | |
| 1143 | 1455 | if ($category !== null |
| 1144 | 1456 | && !$category->isEmpty |
| 1145 | 1457 | ) { |
| 1458 | + $item->title .= $this->adminOutput($item->object, $item->object_id); | |
| 1146 | 1459 | $showItems[] = $item; |
| 1147 | 1460 | } |
| 1148 | 1461 | } else { |
| 1149 | 1462 | $showItems[] = $item; |
| @@ -1159,9 +1472,9 @@ | ||
| 1159 | 1472 | * @param array $comments The comments. |
| 1160 | 1473 | * |
| 1161 | 1474 | * @return array |
| 1162 | 1475 | */ |
| 1163 | - function showComment($comments = array()) | |
| 1476 | + public function showComment($comments = array()) | |
| 1164 | 1477 | { |
| 1165 | 1478 | $showComments = array(); |
| 1166 | 1479 | $uamOptions = $this->getAdminOptions(); |
| 1167 | 1480 | $uamAccessHandler = &$this->getAccessHandler(); |
| @@ -1173,13 +1486,13 @@ | ||
| 1173 | 1486 | if ($uamOptions['hide_'.$postType.'_comment'] == 'true' |
| 1174 | 1487 | || $uamOptions['hide_'.$postType] == 'true' |
| 1175 | 1488 | || $this->atAdminPanel |
| 1176 | 1489 | ) { |
| 1177 | - if ($uamAccessHandler->checkAccess($post->ID)) { | |
| 1490 | + if ($uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) { | |
| 1178 | 1491 | $showComments[] = $comment; |
| 1179 | 1492 | } |
| 1180 | 1493 | } else { |
| 1181 | - if (!$uamAccessHandler->checkAccess($post->ID)) { | |
| 1494 | + if (!$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) { | |
| 1182 | 1495 | $comment->comment_content |
| 1183 | 1496 | = $uamOptions[$postType.'_comment_content']; |
| 1184 | 1497 | } |
| 1185 | 1498 | |
| @@ -1198,9 +1511,9 @@ | ||
| 1198 | 1511 | * @param array $pages The pages. |
| 1199 | 1512 | * |
| 1200 | 1513 | * @return array |
| 1201 | 1514 | */ |
| 1202 | - function showPage($pages = array()) | |
| 1515 | + public function showPage($pages = array()) | |
| 1203 | 1516 | { |
| 1204 | 1517 | $showPages = array(); |
| 1205 | 1518 | $uamOptions = $this->getAdminOptions(); |
| 1206 | 1519 | $uamAccessHandler = &$this->getAccessHandler(); |
| @@ -1208,14 +1521,14 @@ | ||
| 1208 | 1521 | foreach ($pages as $page) { |
| 1209 | 1522 | if ($uamOptions['hide_page'] == 'true' |
| 1210 | 1523 | || $this->atAdminPanel |
| 1211 | 1524 | ) { |
| 1212 | - if ($uamAccessHandler->checkAccess($page->ID)) { | |
| 1213 | - $page->post_title.= $this->adminOutput($page->ID); | |
| 1525 | + if ($uamAccessHandler->checkObjectAccess($page->post_type, $page->ID)) { | |
| 1526 | + $page->post_title.= $this->adminOutput($page->post_type, $page->ID); | |
| 1214 | 1527 | $showPages[] = $page; |
| 1215 | 1528 | } |
| 1216 | 1529 | } else { |
| 1217 | - if (!$uamAccessHandler->checkAccess($page->ID)) { | |
| 1530 | + if (!$uamAccessHandler->checkObjectAccess($page->post_type, $page->ID)) { | |
| 1218 | 1531 | if ($uamOptions['hide_page_title'] == 'true') { |
| 1219 | 1532 | $page->post_title = $uamOptions['page_title']; |
| 1220 | 1533 | } |
| 1221 | 1534 | |
| @@ -1221,9 +1534,9 @@ | ||
| 1221 | 1534 | |
| 1222 | 1535 | $page->post_content = $uamOptions['page_content']; |
| 1223 | 1536 | } |
| 1224 | 1537 | |
| 1225 | - $page->post_title.= $this->adminOutput($page->ID); | |
| 1538 | + $page->post_title .= $this->adminOutput($page->post_type, $page->ID); | |
| 1226 | 1539 | $showPages[] = $page; |
| 1227 | 1540 | } |
| 1228 | 1541 | } |
| 1229 | 1542 | |
| @@ -1245,9 +1558,11 @@ | ||
| 1245 | 1558 | $uamAccessHandler = &$this->getAccessHandler(); |
| 1246 | 1559 | |
| 1247 | 1560 | $category->isEmpty = false; |
| 1248 | 1561 | |
| 1249 | - if ($uamAccessHandler->checkCategoryAccess($category->term_id)) { | |
| 1562 | + $category->name .= $this->adminOutput('category', $category->term_id); | |
| 1563 | + | |
| 1564 | + if ($uamAccessHandler->checkObjectAccess('category', $category->term_id)) { | |
| 1250 | 1565 | if ($this->atAdminPanel == false |
| 1251 | 1566 | && ($uamOptions['hide_post'] == 'true' |
| 1252 | 1567 | || $uamOptions['hide_page'] == 'true') |
| 1253 | 1568 | ) { |
| @@ -1256,15 +1571,16 @@ | ||
| 1256 | 1571 | 'category' => $category->term_id |
| 1257 | 1572 | ); |
| 1258 | 1573 | |
| 1259 | 1574 | $categoryPosts = get_posts($args); |
| 1575 | + $category->count = count($categoryPosts); | |
| 1260 | 1576 | |
| 1261 | 1577 | if (isset($categoryPosts)) { |
| 1262 | 1578 | foreach ($categoryPosts as $post) { |
| 1263 | 1579 | if ($uamOptions['hide_'.$post->post_type] == 'true' |
| 1264 | - && !$uamAccessHandler->checkAccess($post->ID) | |
| 1580 | + && !$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID) | |
| 1265 | 1581 | ) { |
| 1266 | - $category->count--; | |
| 1582 | + $category->count--; | |
| 1267 | 1583 | } |
| 1268 | 1584 | } |
| 1269 | 1585 | } |
| 1270 | 1586 | |
| @@ -1280,9 +1596,9 @@ | ||
| 1280 | 1596 | |
| 1281 | 1597 | while ($curCategory->parent != 0) { |
| 1282 | 1598 | $curCategory = get_category($curCategory->parent); |
| 1283 | 1599 | |
| 1284 | - if ($uamAccessHandler->checkCategoryAccess($curCategory->term_id)) { | |
| 1600 | + if ($uamAccessHandler->checkObjectAccess('category', $curCategory->term_id)) { | |
| 1285 | 1601 | $category->parent = $curCategory->term_id; |
| 1286 | 1602 | break; |
| 1287 | 1603 | } |
| 1288 | 1604 | } |
| @@ -1304,9 +1620,9 @@ | ||
| 1304 | 1620 | * @param array $args The given arguments. |
| 1305 | 1621 | * |
| 1306 | 1622 | * @return array |
| 1307 | 1623 | */ |
| 1308 | - function showCategory($categories = array(), $args = array()) | |
| 1624 | + public function showCategory($categories = array(), $args = array()) | |
| 1309 | 1625 | { |
| 1310 | 1626 | $uamOptions = $this->getAdminOptions(); |
| 1311 | 1627 | $uamAccessHandler = &$this->getAccessHandler(); |
| 1312 | 1628 | |
| @@ -1337,34 +1653,8 @@ | ||
| 1337 | 1653 | return $categories; |
| 1338 | 1654 | } |
| 1339 | 1655 | |
| 1340 | 1656 | /** |
| 1341 | - * The function for the get_the_title filter. | |
| 1342 | - * | |
| 1343 | - * @param string $title The title of the post. | |
| 1344 | - * @param object $postId The post id. | |
| 1345 | - * | |
| 1346 | - * @return string | |
| 1347 | - */ | |
| 1348 | - /*function showTitle($title, $postId = null) | |
| 1349 | - { | |
| 1350 | - $uamOptions = $this->getAdminOptions(); | |
| 1351 | - $uamAccessHandler = &$this->getAccessHandler(); | |
| 1352 | - | |
| 1353 | - $post = get_post($postId); | |
| 1354 | - $postType = $post->post_type; | |
| 1355 | - | |
| 1356 | - if (!$uamAccessHandler->checkAccess($postId) | |
| 1357 | - && $post != null | |
| 1358 | - && $uamOptions['hide_'.$postType.'_title'] == 'true' | |
| 1359 | - ) { | |
| 1360 | - $title = $uamOptions[$postType.'_title']; | |
| 1361 | - } | |
| 1362 | - | |
| 1363 | - return $title; | |
| 1364 | - }*/ | |
| 1365 | - | |
| 1366 | - /** | |
| 1367 | 1657 | * The function for the get_previous_post_where and |
| 1368 | 1658 | * the get_next_post_where filter. |
| 1369 | 1659 | * |
| 1370 | 1660 | * @param string $sql The current sql string. |
| @@ -1370,29 +1660,21 @@ | ||
| 1370 | 1660 | * @param string $sql The current sql string. |
| 1371 | 1661 | * |
| 1372 | 1662 | * @return string |
| 1373 | 1663 | */ |
| 1374 | - function showNextPreviousPost($sql) | |
| 1664 | + public function showNextPreviousPost($sql) | |
| 1375 | 1665 | { |
| 1666 | + $uamAccessHandler = &$this->getAccessHandler(); | |
| 1376 | 1667 | $uamOptions = $this->getAdminOptions(); |
| 1377 | 1668 | |
| 1378 | - if ($uamOptions['hide_post'] == 'true') { | |
| 1379 | - $posts = get_posts(); | |
| 1380 | - $uamAccessHandler = &$this->getAccessHandler(); | |
| 1669 | + if ($uamOptions['hide_post'] == 'true' | |
| 1670 | + && !$uamAccessHandler->checkUserAccess() | |
| 1671 | + ) { | |
| 1672 | + $excludedPosts = $this->_getExcludedPosts(); | |
| 1381 | 1673 | |
| 1382 | - if (isset($posts)) { | |
| 1383 | - foreach ($posts as $post) { | |
| 1384 | - if (!$uamAccessHandler->checkAccess($post->ID)) { | |
| 1385 | - $excludedPosts[] = $post->ID; | |
| 1386 | - } | |
| 1387 | - } | |
| 1388 | - | |
| 1389 | - global $wpdb; | |
| 1390 | - | |
| 1391 | - if (isset($excludedPosts)) { | |
| 1392 | - $excludedPostsStr = implode(",", $excludedPosts); | |
| 1393 | - $sql.= "AND p.ID NOT IN($excludedPostsStr)"; | |
| 1394 | - } | |
| 1674 | + if (count($excludedPosts) > 0) { | |
| 1675 | + $excludedPostsStr = implode(",", $excludedPosts); | |
| 1676 | + $sql.= " AND p.ID NOT IN($excludedPostsStr) "; | |
| 1395 | 1677 | } |
| 1396 | 1678 | } |
| 1397 | 1679 | |
| 1398 | 1680 | return $sql; |
| @@ -1400,13 +1682,14 @@ | ||
| 1400 | 1682 | |
| 1401 | 1683 | /** |
| 1402 | 1684 | * Returns the admin hint. |
| 1403 | 1685 | * |
| 1404 | - * @param integer $postId The post id we want to check. | |
| 1686 | + * @param string $objectType The object type. | |
| 1687 | + * @param integer $objectId The object id we want to check. | |
| 1405 | 1688 | * |
| 1406 | 1689 | * @return string |
| 1407 | 1690 | */ |
| 1408 | - function adminOutput($postId) | |
| 1691 | + public function adminOutput($objectType, $objectId) | |
| 1409 | 1692 | { |
| 1410 | 1693 | $output = ""; |
| 1411 | 1694 | |
| 1412 | 1695 | if (!$this->atAdminPanel) { |
| @@ -1422,9 +1705,11 @@ | ||
| 1422 | 1705 | } |
| 1423 | 1706 | |
| 1424 | 1707 | $uamAccessHandler = &$this->getAccessHandler(); |
| 1425 | 1708 | |
| 1426 | - if (count($uamAccessHandler->getUserGroupsForPost($postId)) > 0) { | |
| 1709 | + if ($uamAccessHandler->userIsAdmin($current_user->ID) | |
| 1710 | + && count($uamAccessHandler->getUserGroupsForObject($objectType, $objectId)) > 0 | |
| 1711 | + ) { | |
| 1427 | 1712 | $output .= $uamOptions['blog_admin_hint_text']; |
| 1428 | 1713 | } |
| 1429 | 1714 | } |
| 1430 | 1715 | } |
| @@ -1439,12 +1724,12 @@ | ||
| 1439 | 1724 | * @param integer $postId The id of the post. |
| 1440 | 1725 | * |
| 1441 | 1726 | * @return string |
| 1442 | 1727 | */ |
| 1443 | - function showGroupMembership($link, $postId) | |
| 1728 | + public function showGroupMembership($link, $postId) | |
| 1444 | 1729 | { |
| 1445 | 1730 | $uamAccessHandler = &$this->getAccessHandler(); |
| 1446 | - $groups = $uamAccessHandler->getUserGroupsForPost($postId); | |
| 1731 | + $groups = $uamAccessHandler->getUserGroupsForObject('post', $postId); | |
| 1447 | 1732 | |
| 1448 | 1733 | if (count($groups) > 0) { |
| 1449 | 1734 | $link .= ' | '.TXT_ASSIGNED_GROUPS.': '; |
| 1450 | 1735 | |
| @@ -1462,9 +1747,9 @@ | ||
| 1462 | 1747 | * Returns the login bar. |
| 1463 | 1748 | * |
| 1464 | 1749 | * @return string |
| 1465 | 1750 | */ |
| 1466 | - function getLoginBarHtml() | |
| 1751 | + public function getLoginBarHtml() | |
| 1467 | 1752 | { |
| 1468 | 1753 | if (!is_user_logged_in()) { |
| 1469 | 1754 | return $this->getIncludeContents(UAM_REALPATH.'tpl/loginBar.php'); |
| 1470 | 1755 | } |
| @@ -1477,38 +1762,64 @@ | ||
| 1477 | 1762 | * Functions for the redirection and files. |
| 1478 | 1763 | */ |
| 1479 | 1764 | |
| 1480 | 1765 | /** |
| 1766 | + * Returns ture if permalinks are active otherwise false. | |
| 1767 | + * | |
| 1768 | + * @return boolean | |
| 1769 | + */ | |
| 1770 | + public function isPermalinksActive() | |
| 1771 | + { | |
| 1772 | + $permaStruc = get_option('permalink_structure'); | |
| 1773 | + | |
| 1774 | + if (empty($permaStruc)) { | |
| 1775 | + return false; | |
| 1776 | + } else { | |
| 1777 | + return true; | |
| 1778 | + } | |
| 1779 | + } | |
| 1780 | + | |
| 1781 | + /** | |
| 1481 | 1782 | * Redirects to a page or to content. |
| 1783 | + * | |
| 1784 | + * @param string $headers The headers which are given from wordpress. | |
| 1785 | + * @param object $pageParams The params of the current page. | |
| 1482 | 1786 | * |
| 1483 | 1787 | * @return null |
| 1484 | 1788 | */ |
| 1485 | - function redirect() | |
| 1789 | + public function redirect($headers, $pageParams) | |
| 1486 | 1790 | { |
| 1487 | 1791 | $uamOptions = $this->getAdminOptions(); |
| 1488 | 1792 | |
| 1489 | - if (isset($_GET['getfile'])) { | |
| 1490 | - $fileUrl = $_GET['getfile']; | |
| 1491 | - } | |
| 1793 | + if (isset($_GET['uamgetfile']) | |
| 1794 | + && isset($_GET['uamfiletype']) | |
| 1795 | + ) { | |
| 1796 | + $fileUrl = $_GET['uamgetfile']; | |
| 1797 | + $fileType = $_GET['uamfiletype']; | |
| 1798 | + $this->getFile($fileType, $fileUrl); | |
| 1799 | + } elseif (!$this->atAdminPanel && $uamOptions['redirect'] != 'false') { | |
| 1800 | + $object = null; | |
| 1492 | 1801 | |
| 1493 | - $emptyId = null; | |
| 1494 | - $post = get_post($emptyId); | |
| 1495 | - | |
| 1496 | - if ($uamOptions['redirect'] != 'false' | |
| 1497 | - && !$this->getAccessHandler()->checkAccess($post->ID) | |
| 1498 | - && !$this->atAdminPanel | |
| 1499 | - && !isset($fileUrl) | |
| 1500 | - ) { | |
| 1501 | - $this->redirectUser(); | |
| 1502 | - } elseif (isset($fileUrl)) { | |
| 1503 | - $permaStruc = get_option('permalink_structure'); | |
| 1802 | + if (isset($pageParams->query_vars['p'])) { | |
| 1803 | + $object = get_post($pageParams->query_vars['p']); | |
| 1804 | + $objectType = $object->post_type; | |
| 1805 | + $objectId = $object->ID; | |
| 1806 | + } elseif (isset($pageParams->query_vars['page_id'])) { | |
| 1807 | + $object = get_post($pageParams->query_vars['page_id']); | |
| 1808 | + $objectType = $object->post_type; | |
| 1809 | + $objectId = $object->ID; | |
| 1810 | + } elseif (isset($pageParams->query_vars['cat_id'])) { | |
| 1811 | + $object = get_category($pageParams->query_vars['cat_id']); | |
| 1812 | + $objectType = 'category'; | |
| 1813 | + $objectId = $object->term_id; | |
| 1814 | + } | |
| 1504 | 1815 | |
| 1505 | - if (!empty($permaStruc)) { | |
| 1506 | - $uploadDir = wp_upload_dir(); | |
| 1507 | - $fileUrl = $uploadDir['baseurl'].'/'.$fileUrl; | |
| 1816 | + if ($object === null | |
| 1817 | + ||$object !== null | |
| 1818 | + && !$this->getAccessHandler()->checkObjectAccess($objectType, $objectId) | |
| 1819 | + ) { | |
| 1820 | + $this->redirectUser($object); | |
| 1508 | 1821 | } |
| 1509 | - | |
| 1510 | - $this->getFile($fileUrl); | |
| 1511 | 1822 | } |
| 1512 | 1823 | } |
| 1513 | 1824 | |
| 1514 | 1825 | /** |
| @@ -1513,11 +1824,13 @@ | ||
| 1513 | 1824 | |
| 1514 | 1825 | /** |
| 1515 | 1826 | * Redirects the user to his destination. |
| 1516 | 1827 | * |
| 1828 | + * @param object $object The current object we want to access. | |
| 1829 | + * | |
| 1517 | 1830 | * @return null |
| 1518 | 1831 | */ |
| 1519 | - function redirectUser() | |
| 1832 | + public function redirectUser($object = null) | |
| 1520 | 1833 | { |
| 1521 | 1834 | global $wp_query; |
| 1522 | 1835 | |
| 1523 | 1836 | $postToShow = false; |
| @@ -1522,11 +1835,13 @@ | ||
| 1522 | 1835 | |
| 1523 | 1836 | $postToShow = false; |
| 1524 | 1837 | $posts = $wp_query->get_posts(); |
| 1525 | 1838 | |
| 1526 | - if (isset($posts)) { | |
| 1839 | + if ($object === null | |
| 1840 | + && isset($posts) | |
| 1841 | + ) { | |
| 1527 | 1842 | foreach ($posts as $post) { |
| 1528 | - if ($this->getAccessHandler()->checkAccess($post->ID)) { | |
| 1843 | + if ($this->getAccessHandler()->checkObjectAccess($post->post_type, $post->ID)) { | |
| 1529 | 1844 | $postToShow = true; |
| 1530 | 1845 | break; |
| 1531 | 1846 | } |
| 1532 | 1847 | } |
| @@ -1533,9 +1848,9 @@ | ||
| 1533 | 1848 | } |
| 1534 | 1849 | |
| 1535 | 1850 | if (!$postToShow) { |
| 1536 | 1851 | $uamOptions = $this->getAdminOptions(); |
| 1537 | - | |
| 1852 | + | |
| 1538 | 1853 | if ($uamOptions['redirect'] == 'blog') { |
| 1539 | 1854 | $url = home_url('/'); |
| 1540 | 1855 | } elseif ($uamOptions['redirect'] == 'custom_page') { |
| 1541 | 1856 | $post = get_post($uamOptions['redirect_custom_page']); |
| @@ -1545,8 +1860,9 @@ | ||
| 1545 | 1860 | } |
| 1546 | 1861 | |
| 1547 | 1862 | if ($url != "http://".$_SERVER['HTTP_HOST'].$_SERVER["REQUEST_URI"]) { |
| 1548 | 1863 | wp_redirect($url); |
| 1864 | + exit; | |
| 1549 | 1865 | } |
| 1550 | 1866 | } |
| 1551 | 1867 | } |
| 1552 | 1868 | |
| @@ -1552,32 +1868,26 @@ | ||
| 1552 | 1868 | |
| 1553 | 1869 | /** |
| 1554 | 1870 | * Delivers the content of the requestet file. |
| 1555 | 1871 | * |
| 1556 | - * @param string $url The file url. | |
| 1872 | + * @param string $objectType The type of the requested file. | |
| 1873 | + * @param string $objectUrl The file url. | |
| 1557 | 1874 | * |
| 1558 | 1875 | * @return null |
| 1559 | 1876 | */ |
| 1560 | - function getFile($url) | |
| 1877 | + public function getFile($objectType, $objectUrl) | |
| 1561 | 1878 | { |
| 1562 | - $post = get_post($this->getAttachmentIdByUrl($url)); | |
| 1879 | + $object = $this->_getFileSettingsByType($objectType, $objectUrl); | |
| 1563 | 1880 | |
| 1564 | - if ($post !== null) { | |
| 1565 | - $file = null; | |
| 1566 | - } else { | |
| 1881 | + if ($object === null) { | |
| 1567 | 1882 | return null; |
| 1568 | 1883 | } |
| 1569 | 1884 | |
| 1570 | - if ($post->post_type == 'attachment' | |
| 1571 | - && $this->getAccessHandler()->checkAccess($post->ID) | |
| 1572 | - ) { | |
| 1573 | - $uploadDir = wp_upload_dir(); | |
| 1574 | - $file = $uploadDir['basedir'].'/'.str_replace( | |
| 1575 | - $uploadDir['baseurl'], | |
| 1576 | - '', | |
| 1577 | - $url | |
| 1578 | - ); | |
| 1579 | - } else if (wp_attachment_is_image($post->ID)) { | |
| 1885 | + $file = null; | |
| 1886 | + | |
| 1887 | + if ($this->getAccessHandler()->checkObjectAccess($object->type, $object->id)) { | |
| 1888 | + $file = $object->file; | |
| 1889 | + } elseif ($object->isImage) { | |
| 1580 | 1890 | $file = UAM_REALPATH.'gfx/noAccessPic.png'; |
| 1581 | 1891 | } else { |
| 1582 | 1892 | wp_die(TXT_NO_RIGHTS); |
| 1583 | 1893 | } |
| @@ -1584,10 +1894,10 @@ | ||
| 1584 | 1894 | |
| 1585 | 1895 | //Deliver content |
| 1586 | 1896 | if (file_exists($file)) { |
| 1587 | 1897 | $fileName = basename($file); |
| 1588 | - | |
| 1589 | - /** | |
| 1898 | + | |
| 1899 | + /* | |
| 1590 | 1900 | * This only for compatibility |
| 1591 | 1901 | * mime_content_type has been deprecated as the PECL extension Fileinfo |
| 1592 | 1902 | * provides the same functionality (and more) in a much cleaner way. |
| 1593 | 1903 | */ |
| @@ -1592,33 +1902,37 @@ | ||
| 1592 | 1902 | * provides the same functionality (and more) in a much cleaner way. |
| 1593 | 1903 | */ |
| 1594 | 1904 | if (function_exists('finfo_open')) { |
| 1595 | 1905 | $finfo = finfo_open(FILEINFO_MIME); |
| 1596 | - | |
| 1597 | - if (!$finfo) { | |
| 1598 | - wp_die(TXT_FILEINFO_DB_ERROR); | |
| 1599 | - } | |
| 1600 | - | |
| 1601 | - $fileType = finfo_file($finfo, $file); | |
| 1906 | + $fileMimeType = finfo_file($finfo, $file); | |
| 1907 | + finfo_close($finfo); | |
| 1602 | 1908 | } else { |
| 1603 | - $fileType = mime_content_type($file); | |
| 1909 | + $fileMimeType = mime_content_type($file); | |
| 1604 | 1910 | } |
| 1605 | 1911 | |
| 1606 | 1912 | header('Content-Description: File Transfer'); |
| 1607 | - header('Content-Type: '.$fileType); | |
| 1608 | - header('Content-Length: '.filesize($file)); | |
| 1609 | - header('Content-Transfer-Encoding: binary'); | |
| 1610 | - header('Expires: 0'); | |
| 1913 | + header('Content-Type: '.$fileMimeType); | |
| 1611 | 1914 | |
| 1612 | - if (!wp_attachment_is_image($post->ID)) { | |
| 1613 | - header('Content-Disposition: attachment; filename='.basename($file)); | |
| 1915 | + if (!$object->isImage) { | |
| 1916 | + $baseName = str_replace(' ', '_', basename($file)); | |
| 1917 | + | |
| 1918 | + header('Content-Disposition: attachment; filename="'.$baseName.'"'); | |
| 1614 | 1919 | } |
| 1920 | + | |
| 1921 | + header('Content-Transfer-Encoding: binary'); | |
| 1922 | + header('Content-Length: '.filesize($file)); | |
| 1615 | 1923 | |
| 1924 | + $uamOptions = $this->getAdminOptions(); | |
| 1925 | + | |
| 1616 | 1926 | if ($uamOptions['download_type'] == 'fopen' |
| 1617 | - && !wp_attachment_is_image($post->ID) | |
| 1927 | + && !$objectIsImage | |
| 1618 | 1928 | ) { |
| 1619 | - $fp = fopen($file, 'rb'); | |
| 1929 | + $fp = fopen($file, 'r'); | |
| 1620 | 1930 | |
| 1931 | + //TODO find better solution (prevent '\n' / '0A') | |
| 1932 | + ob_clean(); | |
| 1933 | + flush(); | |
| 1934 | + | |
| 1621 | 1935 | while (!feof($fp)) { |
| 1622 | 1936 | set_time_limit(30); |
| 1623 | 1937 | $buffer = fread($fp, 1024); |
| 1624 | 1938 | echo $buffer; |
| @@ -1636,8 +1950,57 @@ | ||
| 1636 | 1950 | } |
| 1637 | 1951 | } |
| 1638 | 1952 | |
| 1639 | 1953 | /** |
| 1954 | + * Returns the file object by the given type and url. | |
| 1955 | + * | |
| 1956 | + * @param string $objectType The type of the requested file. | |
| 1957 | + * @param string $objectUrl The file url. | |
| 1958 | + * | |
| 1959 | + * @return object|null | |
| 1960 | + */ | |
| 1961 | + private function _getFileSettingsByType($objectType, $objectUrl) | |
| 1962 | + { | |
| 1963 | + $object = null; | |
| 1964 | + | |
| 1965 | + if ($objectType == 'attachment') { | |
| 1966 | + $uploadDir = wp_upload_dir(); | |
| 1967 | + | |
| 1968 | + if ($this->isPermalinksActive()) { | |
| 1969 | + $objectUrl = $uploadDir['baseurl'].'/'.$objectUrl; | |
| 1970 | + } | |
| 1971 | + | |
| 1972 | + $post = get_post($this->getPostIdByUrl($objectUrl)); | |
| 1973 | + | |
| 1974 | + if ($post !== null | |
| 1975 | + && $post->post_type == 'attachment' | |
| 1976 | + ) { | |
| 1977 | + $object->id = $post->ID; | |
| 1978 | + $object->isImage = wp_attachment_is_image($post->ID); | |
| 1979 | + $object->type = $objectType; | |
| 1980 | + | |
| 1981 | + $object->file = $uploadDir['basedir'].str_replace( | |
| 1982 | + $uploadDir['baseurl'], | |
| 1983 | + '', | |
| 1984 | + $objectUrl | |
| 1985 | + ); | |
| 1986 | + } | |
| 1987 | + } else { | |
| 1988 | + $plObject = $this->getAccessHandler()->getPlObject($objectType); | |
| 1989 | + | |
| 1990 | + if (isset($plObject) | |
| 1991 | + && isset($plObject['getFileObject']) | |
| 1992 | + ) { | |
| 1993 | + $object = $plObject['reference']->{$plObject['getFileObject']}( | |
| 1994 | + $objectUrl | |
| 1995 | + ); | |
| 1996 | + } | |
| 1997 | + } | |
| 1998 | + | |
| 1999 | + return $object; | |
| 2000 | + } | |
| 2001 | + | |
| 2002 | + /** | |
| 1640 | 2003 | * Returns the url for a locked file. |
| 1641 | 2004 | * |
| 1642 | 2005 | * @param string $url The base url. |
| 1643 | 2006 | * @param integer $id The id of the file. |
| @@ -1643,14 +2006,13 @@ | ||
| 1643 | 2006 | * @param integer $id The id of the file. |
| 1644 | 2007 | * |
| 1645 | 2008 | * @return string |
| 1646 | 2009 | */ |
| 1647 | - function getFileUrl($url, $id) | |
| 2010 | + public function getFileUrl($url, $id) | |
| 1648 | 2011 | { |
| 1649 | 2012 | $uamOptions = $this->getAdminOptions(); |
| 1650 | - $permaStruc = get_option('permalink_structure'); | |
| 1651 | 2013 | |
| 1652 | - if (empty($permaStruc) | |
| 2014 | + if (!$this->isPermalinksActive() | |
| 1653 | 2015 | && $uamOptions['lock_file'] == 'true' |
| 1654 | 2016 | ) { |
| 1655 | 2017 | $post = &get_post($id); |
| 1656 | 2018 | |
| @@ -1661,12 +2023,12 @@ | ||
| 1661 | 2023 | ",", |
| 1662 | 2024 | $uamOptions['locked_file_types'] |
| 1663 | 2025 | ); |
| 1664 | 2026 | |
| 1665 | - if (in_array($type, $fileTypes) | |
| 1666 | - || $uamOptions['lock_file_types'] == 'all' | |
| 2027 | + if ($uamOptions['lock_file_types'] == 'all' | |
| 2028 | + || in_array($type, $fileTypes) | |
| 1667 | 2029 | ) { |
| 1668 | - $url = home_url('/').'?getfile='.$url; | |
| 2030 | + $url = home_url('/').'?uamfiletype=attachment&uamgetfile='.$url; | |
| 1669 | 2031 | } |
| 1670 | 2032 | } |
| 1671 | 2033 | |
| 1672 | 2034 | return $url; |
| @@ -1678,11 +2040,15 @@ | ||
| 1678 | 2040 | * @param string $url The url of the post(attachment). |
| 1679 | 2041 | * |
| 1680 | 2042 | * @return object The post. |
| 1681 | 2043 | */ |
| 1682 | - function getAttachmentIdByUrl($url) | |
| 2044 | + public function getPostIdByUrl($url) | |
| 1683 | 2045 | { |
| 1684 | - //Filter editstring | |
| 2046 | + if (isset($this->postUrls[$url])) { | |
| 2047 | + return $this->postUrls[$url]; | |
| 2048 | + } | |
| 2049 | + | |
| 2050 | + //Filter edit string | |
| 1685 | 2051 | $newUrl = preg_split("/-e[0-9]*/", $url); |
| 1686 | 2052 | |
| 1687 | 2053 | if (count($newUrl) == 2) { |
| 1688 | 2054 | $newUrl = $newUrl[0].$newUrl[1]; |
| @@ -1703,15 +2069,28 @@ | ||
| 1703 | 2069 | $dbPost = $wpdb->get_row( |
| 1704 | 2070 | "SELECT ID |
| 1705 | 2071 | FROM ".$wpdb->prefix."posts |
| 1706 | 2072 | WHERE guid = '" . $newUrl . "' |
| 1707 | - LIMIT 1", | |
| 1708 | - ARRAY_A | |
| 2073 | + LIMIT 1" | |
| 1709 | 2074 | ); |
| 1710 | 2075 | |
| 1711 | 2076 | if ($dbPost) { |
| 1712 | - return $dbPost['ID']; | |
| 2077 | + return $dbPost->ID; | |
| 1713 | 2078 | } |
| 1714 | 2079 | |
| 1715 | 2080 | return null; |
| 2081 | + } | |
| 2082 | + | |
| 2083 | + /** | |
| 2084 | + * Caches the urls for the post for a later lookup. | |
| 2085 | + * | |
| 2086 | + * @param string $url The url of the post. | |
| 2087 | + * @param object $post The post object. | |
| 2088 | + * | |
| 2089 | + * @return null | |
| 2090 | + */ | |
| 2091 | + public function cachePostLinks($url, $post) | |
| 2092 | + { | |
| 2093 | + $this->postUrls[$url] = $post->ID; | |
| 2094 | + return $url; | |
| 1716 | 2095 | } |
| 1717 | 2096 | } |