PluginProbe
User Access Manager / 1.2.2
User Access Manager v1.2.2
2.3.20 2.3.19 2.3.18 2.3.17 2.3.16 2.3.15 2.3.14 2.3.13 trunk 0.6 0.6.1 0.6.2 0.7 0.7 Beta 0.7.0.1 0.8 0.8.0.1 0.8.0.2 0.9 0.9.1 0.9.1.1 0.9.1.2 0.9.1.3 0.9.1.4 1.0 All 136 releases
← All changes | class/UserAccessManager.class.php +1138 -534 1.0 → 1.2.2 View file →
@@ -26,14 +26,69 @@
26 26 */
27 27
28 28 class UserAccessManager
29 29 {
30 - var $atAdminPanel = false;
30 + protected $atAdminPanel = false;
31 31 protected $adminOptionsName = "uamAdminOptions";
32 - protected $uamVersion = 1.0;
33 - protected $uamDbVersion = 1.1;
32 + protected $uamVersion = "1.2";
33 + protected $uamDbVersion = "1.1";
34 34 protected $adminOptions;
35 35 protected $accessHandler = null;
36 + protected $postUrls = array();
37 + protected $mimeTypes = array(
38 + 'txt' => 'text/plain',
39 + 'htm' => 'text/html',
40 + 'html' => 'text/html',
41 + 'php' => 'text/html',
42 + 'css' => 'text/css',
43 + 'js' => 'application/javascript',
44 + 'json' => 'application/json',
45 + 'xml' => 'application/xml',
46 + 'swf' => 'application/x-shockwave-flash',
47 + 'flv' => 'video/x-flv',
48 +
49 + // images
50 + 'png' => 'image/png',
51 + 'jpe' => 'image/jpeg',
52 + 'jpeg' => 'image/jpeg',
53 + 'jpg' => 'image/jpeg',
54 + 'gif' => 'image/gif',
55 + 'bmp' => 'image/bmp',
56 + 'ico' => 'image/vnd.microsoft.icon',
57 + 'tiff' => 'image/tiff',
58 + 'tif' => 'image/tiff',
59 + 'svg' => 'image/svg+xml',
60 + 'svgz' => 'image/svg+xml',
61 +
62 + // archives
63 + 'zip' => 'application/zip',
64 + 'rar' => 'application/x-rar-compressed',
65 + 'exe' => 'application/x-msdownload',
66 + 'msi' => 'application/x-msdownload',
67 + 'cab' => 'application/vnd.ms-cab-compressed',
68 +
69 + // audio/video
70 + 'mp3' => 'audio/mpeg',
71 + 'qt' => 'video/quicktime',
72 + 'mov' => 'video/quicktime',
73 +
74 + // adobe
75 + 'pdf' => 'application/pdf',
76 + 'psd' => 'image/vnd.adobe.photoshop',
77 + 'ai' => 'application/postscript',
78 + 'eps' => 'application/postscript',
79 + 'ps' => 'application/postscript',
80 +
81 + // ms office
82 + 'doc' => 'application/msword',
83 + 'rtf' => 'application/rtf',
84 + 'xls' => 'application/vnd.ms-excel',
85 + 'ppt' => 'application/vnd.ms-powerpoint',
86 +
87 + // open office
88 + 'odt' => 'application/vnd.oasis.opendocument.text',
89 + 'ods' => 'application/vnd.oasis.opendocument.spreadsheet',
90 + );
36 91
37 92 /**
38 93 * Consturctor
39 94 *
@@ -38,119 +93,186 @@
38 93 * Consturctor
39 94 *
40 95 * @return null
41 96 */
42 - function __construct()
97 + public function __construct()
43 98 {
44 -
99 + do_action('uam_init', $this);
45 100 }
46 101
47 102 /**
48 - * Creates the needed tables at the database
103 + * Returns all blogs of the network
49 104 *
105 + * @return array()
106 + */
107 + private function _getBlogIds()
108 + {
109 + global $wpdb;
110 +
111 + if (is_multisite()) {
112 + $blogIds = $wpdb->get_col(
113 + "SELECT blog_id
114 + FROM $wpdb->blogs"
115 + );
116 +
117 + return $blogIds;
118 + }
119 +
120 + return array();
121 + }
122 +
123 + /**
124 + * Installs the user access manager.
125 + *
50 126 * @return null;
51 127 */
52 - function install()
53 - {
128 + public function install()
129 + {
54 130 global $wpdb;
131 + $blogIds = $this->_getBlogIds();
132 +
133 + if ($blogIds !== array()
134 + && isset($_GET['networkwide'])
135 + && ($_GET['networkwide'] == 1)
136 + ) {
137 + $currentBlog = $wpdb->blogid;
138 +
139 + foreach ($blogIds as $blogId) {
140 + switch_to_blog($blogId);
141 + $this->_installUam();
142 + }
143 +
144 + switch_to_blog($currentBlog);
145 +
146 + return;
147 + }
148 +
149 + $this->_installUam();
150 + }
151 +
152 + /**
153 + * Creates the needed tables at the database and adds the options
154 + *
155 + * @return null;
156 + */
157 + private function _installUam()
158 + {
159 + global $wpdb;
55 160 $uamDbVersion = $this->uamDbVersion;
56 161
57 - include_once ABSPATH . 'wp-admin/includes/upgrade.php';
58 - $charset_collate = '';
162 + include_once ABSPATH.'wp-admin/includes/upgrade.php';
163 +
164 + $charsetCollate = $this->_getCharset();
59 165
60 - if (version_compare(mysql_get_server_info(), '4.1.0', '>=')) {
61 - if (!empty($wpdb->charset)) {
62 - $charset_collate = "DEFAULT CHARACTER SET $wpdb->charset";
63 - }
64 -
65 - if (!empty($wpdb->collate)) {
66 - $charset_collate.= " COLLATE $wpdb->collate";
67 - }
68 - }
166 + $dbAccessGroup = $wpdb->prefix.'uam_accessgroups';
167 + $dbAccessGroupToObject = $wpdb->prefix.'uam_accessgroup_to_object';
69 168
70 169 $dbUserGroup = $wpdb->get_var(
71 170 "SHOW TABLES
72 - LIKE '" . DB_ACCESSGROUP . "'"
171 + LIKE '".$dbAccessGroup."'"
73 172 );
74 173
75 - if ($dbUserGroup != DB_ACCESSGROUP) {
76 - $sql = "CREATE TABLE " . DB_ACCESSGROUP . " (
77 - ID int(11) NOT NULL auto_increment,
78 - groupname tinytext NOT NULL,
79 - groupdesc text NOT NULL,
80 - read_access tinytext NOT NULL,
81 - write_access tinytext NOT NULL,
82 - ip_range mediumtext NULL,
83 - PRIMARY KEY (ID)
84 - ) $charset_collate;";
85 - dbDelta($sql);
174 + if ($dbUserGroup != $dbAccessGroup) {
175 + dbDelta(
176 + "CREATE TABLE ".$dbAccessGroup." (
177 + ID int(11) NOT NULL auto_increment,
178 + groupname tinytext NOT NULL,
179 + groupdesc text NOT NULL,
180 + read_access tinytext NOT NULL,
181 + write_access tinytext NOT NULL,
182 + ip_range mediumtext NULL,
183 + PRIMARY KEY (ID)
184 + ) $charsetCollate;"
185 + );
86 186 }
87 -
88 - $dbUserGroupToPost = $wpdb->get_var(
187 +
188 + $dbUserGroupToObject = $wpdb->get_var(
89 189 "SHOW TABLES
90 - LIKE '" . DB_ACCESSGROUP_TO_POST . "'"
190 + LIKE '".$dbAccessGroupToObject."'"
91 191 );
92 192
93 - if ($dbUserGroupToPost != DB_ACCESSGROUP_TO_POST) {
94 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_POST . " (
95 - post_id int(11) NOT NULL,
96 - group_id int(11) NOT NULL,
97 - PRIMARY KEY (post_id,group_id)
98 - ) $charset_collate;";
99 - dbDelta($sql);
193 + if ($dbUserGroupToObject != $dbAccessGroupToObject) {
194 + dbDelta(
195 + "CREATE TABLE " . $dbAccessGroupToObject . " (
196 + object_id VARCHAR(11) NOT NULL,
197 + object_type varchar(255) NOT NULL,
198 + group_id int(11) NOT NULL,
199 + PRIMARY KEY (object_id,object_type,group_id)
200 + ) $charsetCollate;"
201 + );
100 202 }
101 203
102 - $dbUserGroupToUser = $wpdb->get_var(
103 - "SHOW TABLES
104 - LIKE '" . DB_ACCESSGROUP_TO_USER . "'"
105 - );
106 -
107 - if ($dbUserGroupToUser != DB_ACCESSGROUP_TO_USER) {
108 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_USER . " (
109 - user_id int(11) NOT NULL,
110 - group_id int(11) NOT NULL,
111 - PRIMARY KEY (user_id,group_id)
112 - ) $charset_collate;";
113 - dbDelta($sql);
204 + add_option("uam_db_version", $this->uamDbVersion);
205 + }
206 +
207 + /**
208 + * Checks if a database update is necessary.
209 + *
210 + * @return boolean
211 + */
212 + public function isDatabaseUpdateNecessary()
213 + {
214 + global $wpdb;
215 + $blogIds = $this->_getBlogIds();
216 +
217 + if ($blogIds !== array()
218 + && is_super_admin()
219 + ) {
220 + $currentBlog = $wpdb->blogid;
221 +
222 + foreach ($blogIds as $blogId) {
223 + switch_to_blog($blogId);
224 + $currentDbVersion = get_option("uam_db_version");
225 +
226 + if (version_compare($currentDbVersion, $this->uamDbVersion, '<')) {
227 + switch_to_blog($currentBlog);
228 + return true;
229 + }
230 + }
231 +
232 + switch_to_blog($currentBlog);
114 233 }
115 234
116 - $dbUserGroupToCategory = $wpdb->get_var(
117 - "SHOW TABLES
118 - LIKE '" . DB_ACCESSGROUP_TO_CATEGORY . "'"
119 - );
235 + $currentDbVersion = get_option("uam_db_version");
236 + return version_compare($currentDbVersion, $this->uamDbVersion, '<');
237 + }
238 +
239 + /**
240 + * Updates the user access manager if an old version was installed.
241 + *
242 + * @param boolean $networkWide If true update network wide
243 + *
244 + * @return null;
245 + */
246 + public function update($networkWide)
247 + {
248 + global $wpdb;
249 + $blogIds = $this->_getBlogIds();
250 +
251 + if ($blogIds !== array()
252 + && $networkWide
253 + ) {
254 + $currentBlog = $wpdb->blogid;
255 +
256 + foreach ($blogIds as $blogId) {
257 + switch_to_blog($blogId);
258 + $this->_installUam();
259 + }
260 +
261 + switch_to_blog($currentBlog);
262 +
263 + return;
264 + }
120 265
121 - if ($dbUserGroupToCategory != DB_ACCESSGROUP_TO_CATEGORY) {
122 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_CATEGORY . " (
123 - category_id int(11) NOT NULL,
124 - group_id int(11) NOT NULL,
125 - PRIMARY KEY (category_id,group_id)
126 - ) $charset_collate;";
127 - dbDelta($sql);
128 - }
129 -
130 - $dbUserGroupToRole = $wpdb->get_var(
131 - "SHOW TABLES
132 - LIKE '" . DB_ACCESSGROUP_TO_ROLE . "'"
133 - );
134 -
135 - if ($dbUserGroupToRole != DB_ACCESSGROUP_TO_ROLE) {
136 - $sql = "CREATE TABLE " . DB_ACCESSGROUP_TO_ROLE . " (
137 - role_name varchar(255) NOT NULL,
138 - group_id int(11) NOT NULL,
139 - PRIMARY KEY (role_name,group_id)
140 - ) $charset_collate;";
141 - dbDelta($sql);
142 - }
143 -
144 - add_option("uam_db_version", $uamDbVersion);
266 + $this->_updateUam();
145 267 }
146 268
147 269 /**
148 - * Updates the database if an old version was installed.
270 + * Updates the user access manager if an old version was installed.
149 271 *
150 272 * @return null;
151 273 */
152 - function update()
274 + private function _updateUam()
153 275 {
154 276 global $wpdb;
155 277 $currentDbVersion = get_option("uam_db_version");
156 278
@@ -158,27 +280,25 @@
158 280 $this->install();
159 281 }
160 282
161 283 if (!get_option('uam_version')
162 - || get_option('uam_version') < $this->uamVersion
284 + || version_compare(get_option('uam_version'), "1.0") === -1
163 285 ) {
164 - update_option('uam_version', $this->uamVersion);
165 -
166 286 delete_option('allow_comments_locked');
167 287 }
168 288
289 + $dbAccessGroup = $wpdb->prefix.'uam_accessgroups';
290 +
169 291 $dbUserGroup = $wpdb->get_var(
170 292 "SHOW TABLES
171 - LIKE '" . DB_ACCESSGROUP . "'"
293 + LIKE '".$dbAccessGroup."'"
172 294 );
173 295
174 - if ($currentDbVersion != $this->uamDbVersion) {
175 - if ($currentDbVersion == 1.0) {
176 -
177 -
178 - if ($dbUserGroup == DB_ACCESSGROUP) {
296 + if (version_compare($currentDbVersion, $this->uamDbVersion) === -1) {
297 + if (version_compare($currentDbVersion, "1.0") === 0) {
298 + if ($dbUserGroup == $dbAccessGroup) {
179 299 $wpdb->query(
180 - "ALTER TABLE " . DB_ACCESSGROUP . "
300 + "ALTER TABLE ".$dbAccessGroup."
181 301 ADD read_access TINYTEXT NOT NULL DEFAULT '',
182 302 ADD write_access TINYTEXT NOT NULL DEFAULT '',
183 303 ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
184 304 );
@@ -183,33 +303,100 @@
183 303 ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
184 304 );
185 305
186 306 $wpdb->query(
187 - "UPDATE " . DB_ACCESSGROUP . "
307 + "UPDATE ".$dbAccessGroup."
188 308 SET read_access = 'group',
189 309 write_access = 'group'"
190 310 );
191 311
192 - update_option('uam_db_version', $this->uamDbVersion);
312 + $dbIpRange = $wpdb->get_var(
313 + "SHOW columns
314 + FROM ".$dbAccessGroup."
315 + LIKE 'ip_range'"
316 + );
317 +
318 + if ($dbIpRange != 'ip_range') {
319 + $wpdb->query(
320 + "ALTER TABLE ".$dbAccessGroup."
321 + ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
322 + );
323 + }
193 324 }
194 - }
195 - }
196 -
197 - if ($dbUserGroup == DB_ACCESSGROUP) {
198 - $dbIpRange = $wpdb->get_var(
199 - "SHOW columns
200 - FROM " . DB_ACCESSGROUP . "
201 - LIKE 'ip_range'"
202 - );
325 +
326 + $currentDbVersion = "1.1";
327 + }
203 328
204 - if ($dbIpRange != 'ip_range') {
329 + if (version_compare($currentDbVersion, "1.1") === 0) {
330 + $dbAccessGroupToObject = $wpdb->prefix.'uam_accessgroup_to_object';
331 + $dbAccessgroupToPost = $wpdb->prefix.'uam_accessgroup_to_post';
332 + $dbAccessgroupToUser = $wpdb->prefix.'uam_accessgroup_to_user';
333 + $dbAccessgroupToCategory = $wpdb->prefix.'uam_accessgroup_to_category';
334 + $dbAccessgroupToRole = $wpdb->prefix.'uam_accessgroup_to_role';
335 +
336 + $charsetCollate = $this->_getCharset();
337 +
205 338 $wpdb->query(
206 - "ALTER TABLE " . DB_ACCESSGROUP . "
207 - ADD ip_range MEDIUMTEXT NULL DEFAULT ''"
339 + "ALTER TABLE 'wp_uam_accessgroup_to_object'
340 + CHANGE 'object_id' 'object_id' VARCHAR(11)
341 + $charsetCollate;"
208 342 );
343 +
344 + $objectTypes = $this->getAccessHandler()->getObjectTypes();
345 +
346 + foreach ($objectTypes as $objectType) {
347 + $addition = '';
348 +
349 + $postableTypes = $this->getAccessHandler()->getPostableTypes();
350 +
351 + if (in_array($objectType, $postableTypes)) {
352 + $dbIdName = 'post_id';
353 + $database = $dbAccessgroupToPost.', '.$wpdb->posts;
354 + $addition = " WHERE post_id = ID
355 + AND post_type = '".$objectType."'";
356 + } elseif ($objectType == 'category') {
357 + $dbIdName = 'category_id';
358 + $database = $dbAccessgroupToCategory;
359 + } elseif ($objectType == 'user') {
360 + $dbIdName = 'user_id';
361 + $database = $dbAccessgroupToUser;
362 + } elseif ($objectType == 'role') {
363 + $dbIdName = 'role_name';
364 + $database = $dbAccessgroupToRole;
365 + }
366 +
367 + $sql = "SELECT ".$dbIdName." as id, group_id as groupId
368 + FROM ".$database.$addition;
369 +
370 + $dbObjects = $wpdb->get_results($sql);
371 +
372 + foreach ($dbObjects as $dbObject) {
373 + $sql = "INSERT INTO ".$dbAccessGroupToObject." (
374 + group_id,
375 + object_id,
376 + object_type
377 + )
378 + VALUES(
379 + '".$dbObject->groupId."',
380 + '".$dbObject->id."',
381 + '".$objectType."'
382 + )";
383 +
384 + $wpdb->query($sql);
385 + }
386 + }
387 +
388 + $wpdb->query(
389 + "DROP TABLE ".$dbAccessgroupToPost.",
390 + ".$dbAccessgroupToUser.",
391 + ".$dbAccessgroupToCategory.",
392 + ".$dbAccessgroupToRole
393 + );
209 394 }
395 +
396 + update_option('uam_db_version', $this->uamDbVersion);
210 397 }
211 - }
398 + }
212 399
213 400 /**
214 401 * Clean up wordpress if the plugin will be uninstalled.
215 402 *
@@ -214,17 +401,14 @@
214 401 * Clean up wordpress if the plugin will be uninstalled.
215 402 *
216 403 * @return null
217 404 */
218 - function uninstall()
405 + public function uninstall()
219 406 {
220 407 global $wpdb;
221 408 $wpdb->query(
222 - "DROP TABLE " . DB_ACCESSGROUP . ",
223 - " . DB_ACCESSGROUP_TO_POST . ",
224 - " . DB_ACCESSGROUP_TO_USER . ",
225 - " . DB_ACCESSGROUP_TO_CATEGORY . ",
226 - " . DB_ACCESSGROUP_TO_ROLE
409 + "DROP TABLE ".DB_ACCESSGROUP.",
410 + ".DB_ACCESSGROUP_TO_OBJECT
227 411 );
228 412
229 413 delete_option($this->adminOptionsName);
230 414 delete_option('uam_version');
@@ -232,13 +416,35 @@
232 416 $this->deleteHtaccessFiles();
233 417 }
234 418
235 419 /**
420 + * Returns the database charset.
421 + *
422 + * @return string
423 + */
424 + private function _getCharset()
425 + {
426 + $charsetCollate = '';
427 +
428 + if (version_compare(mysql_get_server_info(), '4.1.0', '>=')) {
429 + if (!empty($wpdb->charset)) {
430 + $charsetCollate = "DEFAULT CHARACTER SET $wpdb->charset";
431 + }
432 +
433 + if (!empty($wpdb->collate)) {
434 + $charsetCollate.= " COLLATE $wpdb->collate";
435 + }
436 + }
437 +
438 + return $charsetCollate;
439 + }
440 +
441 + /**
236 442 * Remove the htaccess file if the plugin is deactivated.
237 443 *
238 444 * @return null
239 445 */
240 - function deactivate()
446 + public function deactivate()
241 447 {
242 448 $this->deleteHtaccessFiles();
243 449 }
244 450
@@ -244,21 +450,29 @@
244 450
245 451 /**
246 452 * Creates a htaccess file.
247 453 *
454 + * @param string $dir The destination directory.
455 + * @param string $objectType The object type.
456 + *
248 457 * @return null.
249 458 */
250 - function createHtaccess()
459 + public function createHtaccess($dir = null, $objectType = null)
251 460 {
252 - // Make .htaccess file to protect data
253 - // get url
254 -
255 - $wud = wp_upload_dir();
256 - if (empty($wud['error'])) {
257 - $dir = $wud['basedir'] . "/";
258 - $permaStruc = get_option('permalink_structure');
461 + if ($dir === null) {
462 + $wud = wp_upload_dir();
259 463
260 - if (empty($permaStruc)) {
464 + if (empty($wud['error'])) {
465 + $dir = $wud['basedir'] . "/";
466 + }
467 + }
468 +
469 + if ($objectType === null) {
470 + $objectType = 'attachment';
471 + }
472 +
473 + if ($dir !== null) {
474 + if (!$this->isPermalinksActive()) {
261 475 $areaname = "WP-Files";
262 476 $uamOptions = $this->getAdminOptions();
263 477
264 478 if ($uamOptions['lock_file_types'] == 'selected') {
@@ -301,14 +515,15 @@
301 515 $htaccessTxt = "<IfModule mod_rewrite.c>\n";
302 516 $htaccessTxt .= "RewriteEngine On\n";
303 517 $htaccessTxt .= "RewriteBase ".$homeRoot."\n";
304 518 $htaccessTxt .= "RewriteRule ^index\.php$ - [L]\n";
305 - $htaccessTxt .= "RewriteRule (.*) ".$homeRoot."index.php?getfile=$1 [L]\n";
519 + $htaccessTxt .= "RewriteRule (.*) ";
520 + $htaccessTxt .= $homeRoot."index.php?uamfiletype=".$objectType."&uamgetfile=$1 [L]\n";
306 521 $htaccessTxt .= "</IfModule>\n";
307 522 }
308 523
309 524 // save files
310 - $htaccess = fopen($dir . ".htaccess", "w");
525 + $htaccess = fopen($dir.".htaccess", "w");
311 526 fwrite($htaccess, $htaccessTxt);
312 527 fclose($htaccess);
313 528 }
314 529 }
@@ -316,88 +531,51 @@
316 531 /**
317 532 * Creates a htpasswd file.
318 533 *
319 534 * @param boolean $createNew Force to create new file.
535 + * @param string $dir The destination directory.
320 536 *
321 537 * @return null
322 538 */
323 - function createHtpasswd($createNew = false)
539 + public function createHtpasswd($createNew = false, $dir = null)
324 540 {
541 + if (!function_exists('get_userdata')) {
542 + include_once ABSPATH.'wp-includes/pluggable.php';
543 + }
544 +
325 545 global $current_user;
546 + //Force user infos
547 + wp_get_current_user();
548 +
326 549 $uamOptions = $this->getAdminOptions();
327 550
328 551 // get url
329 - $wud = wp_upload_dir();
330 - if (empty($wud['error'])) {
331 - $url = $wud['basedir'] . "/";
552 + if ($dir === null) {
553 + $wud = wp_upload_dir();
554 +
555 + if (empty($wud['error'])) {
556 + $dir = $wud['basedir'] . "/";
557 + }
558 + }
559 +
560 + if ($dir !== null) {
332 561 $curUserdata = get_userdata($current_user->ID);
333 - $user = $curUserdata->user_login;
334 562
335 - if (!file_exists($url . ".htpasswd") || $createNew) {
563 + if (!file_exists($dir.".htpasswd") || $createNew) {
336 564 if ($uamOptions['file_pass_type'] == 'random') {
337 - // create password
338 - $array = array();
339 - $length = 10;
340 - $capitals = true;
341 - $specialSigns = false;
342 - if ($length < 8) {
343 - $length = mt_rand(8, 20);
344 - }
345 -
346 - // numbers
347 - for ($i = 48; $i < 58; $i++) {
348 - $array[] = chr($i);
349 - }
350 -
351 - // small
352 - for ($i = 97; $i < 122; $i++) {
353 - $array[] = chr($i);
354 - }
355 -
356 - // capitals
357 - if ($capitals) {
358 - for ($i = 65; $i < 90; $i++) {
359 - $array[] = chr($i);
360 - }
361 - }
362 -
363 - // specialchar:
364 - if ($specialSigns) {
365 - for ($i = 33; $i < 47; $i++) {
366 - $array[] = chr($i);
367 - }
368 -
369 - for ($i = 59; $i < 64; $i++) {
370 - $array[] = chr($i);
371 - }
372 -
373 - for ($i = 91; $i < 96; $i++) {
374 - $array[] = chr($i);
375 - }
376 -
377 - for ($i = 123; $i < 126; $i++) {
378 - $array[] = chr($i);
379 - }
380 - }
381 -
382 - mt_srand((double)microtime() * 1000000);
383 - $password = '';
384 -
385 - for ($i = 1; $i <= $length; $i++) {
386 - $rnd = mt_rand(0, count($array) - 1);
387 - $password.= $array[$rnd];
388 - $password = md5($password);
389 - }
565 + $password = md5($this->getRandomPassword());
390 566 } elseif ($uamOptions['file_pass_type'] == 'admin') {
391 567 $password = $curUserdata->user_pass;
392 568 }
569 +
570 + $user = $curUserdata->user_login;
393 571
394 572 // make .htpasswd
395 - $htpasswd_txt = "$user:" . $password . "\n";
396 -
573 + $htpasswdTxt = "$user:" . $password . "\n";
574 +
397 575 // save file
398 - $htpasswd = fopen($url . ".htpasswd", "w");
399 - fwrite($htpasswd, $htpasswd_txt);
576 + $htpasswd = fopen($dir.".htpasswd", "w");
577 + fwrite($htpasswd, $htpasswdTxt);
400 578 fclose($htpasswd);
401 579 }
402 580 }
403 581 }
@@ -404,32 +582,102 @@
404 582
405 583 /**
406 584 * Deletes the htaccess files.
407 585 *
586 + * @param string $dir The destination directory.
587 + *
408 588 * @return null
409 589 */
410 - function deleteHtaccessFiles()
590 + public function deleteHtaccessFiles($dir = null)
411 591 {
412 - $wud = wp_upload_dir();
413 - if (empty($wud['error'])) {
414 - $url = $wud['basedir'] . "/";
592 + if ($dir === null) {
593 + $wud = wp_upload_dir();
415 594
416 - if (file_exists($url.".htaccess")) {
417 - unlink($url.".htaccess");
595 + if (empty($wud['error'])) {
596 + $dir = $wud['basedir'] . "/";
418 597 }
598 + }
599 +
600 + if ($dir !== null) {
601 + if (file_exists($dir.".htaccess")) {
602 + unlink($dir.".htaccess");
603 + }
419 604
420 - if (file_exists($url.".htpasswd")) {
421 - unlink($url.".htpasswd");
605 + if (file_exists($dir.".htpasswd")) {
606 + unlink($dir.".htpasswd");
422 607 }
423 608 }
424 609 }
425 610
426 611 /**
612 + * Generates and retruns a randmom password.
613 + *
614 + * @return string
615 + */
616 + public function getRandomPassword()
617 + {
618 + //create password
619 + $array = array();
620 + $length = 16;
621 + $capitals = true;
622 + $specialSigns = false;
623 + if ($length < 8) {
624 + $length = mt_rand(8, 20);
625 + }
626 +
627 + // numbers
628 + for ($i = 48; $i < 58; $i++) {
629 + $array[] = chr($i);
630 + }
631 +
632 + // small
633 + for ($i = 97; $i < 122; $i++) {
634 + $array[] = chr($i);
635 + }
636 +
637 + // capitals
638 + if ($capitals) {
639 + for ($i = 65; $i < 90; $i++) {
640 + $array[] = chr($i);
641 + }
642 + }
643 +
644 + // specialchar:
645 + if ($specialSigns) {
646 + for ($i = 33; $i < 47; $i++) {
647 + $array[] = chr($i);
648 + }
649 +
650 + for ($i = 59; $i < 64; $i++) {
651 + $array[] = chr($i);
652 + }
653 +
654 + for ($i = 91; $i < 96; $i++) {
655 + $array[] = chr($i);
656 + }
657 +
658 + for ($i = 123; $i < 126; $i++) {
659 + $array[] = chr($i);
660 + }
661 + }
662 +
663 + mt_srand((double)microtime() * 1000000);
664 + $password = '';
665 +
666 + for ($i = 1; $i <= $length; $i++) {
667 + $rnd = mt_rand(0, count($array) - 1);
668 + $password.= $array[$rnd];
669 + }
670 +
671 + return $password;
672 + }
673 +
674 + /**
427 675 * Returns the current settings
428 676 *
429 677 * @return array
430 678 */
431 - function getAdminOptions()
679 + public function getAdminOptions()
432 680 {
433 681 if (empty($this->adminOptions)) {
434 682 $uamAdminOptions = array(
435 683 'hide_post_title' => 'false',
@@ -495,14 +743,15 @@
495 743
496 744 /**
497 745 * Retruns the content of the excecuded php file.
498 746 *
499 - * @param string $fileName The file name
500 - * @param integer $id The id if needed.
747 + * @param string $fileName The file name
748 + * @param integer $objectId The id if needed.
749 + * @param string $objectType The object type if needed.
501 750 *
502 751 * @return string
503 752 */
504 - function getIncludeContents($fileName, $id = null)
753 + public function getIncludeContents($fileName, $objectId = null, $objectType = null)
505 754 {
506 755 if (is_file($fileName)) {
507 756 ob_start();
508 757 include $fileName;
@@ -519,19 +768,67 @@
519 768 * Returns the access handler object.
520 769 *
521 770 * @return object
522 771 */
523 - function &getAccessHandler()
772 + public function &getAccessHandler()
524 773 {
525 774 if ($this->accessHandler == null) {
526 - $this->accessHandler = new UamAccessHandler(&$this);
775 + $this->accessHandler = new UamAccessHandler($this);
527 776 }
528 777
529 778 return $this->accessHandler;
530 779 }
531 780
781 + /**
782 + * Returns the current version of the user access manager.
783 + *
784 + * @return string
785 + */
786 + public function getVersion()
787 + {
788 + return $this->uamVersion;
789 + }
532 790
791 + /**
792 + * Returns true if a user is at the admin panel.
793 + *
794 + * @return boolean
795 + */
796 + public function atAdminPanel()
797 + {
798 + return $this->atAdminPanel;
799 + }
800 +
801 + /**
802 + * Sets the atAdminPanel var to true.
803 + *
804 + * @return null
805 + */
806 + public function setAtAdminPanel()
807 + {
808 + $this->atAdminPanel = true;
809 + }
810 +
811 +
533 812 /*
813 + * Helper functions.
814 + */
815 +
816 + /**
817 + * Checks if a string starts with the given needle.
818 + *
819 + * @param string $haystack The haystack.
820 + * @param string $needle The needle
821 + *
822 + * @return boolean
823 + */
824 + public function startsWith($haystack, $needle)
825 + {
826 + return strpos($haystack, $needle) === 0;
827 + }
828 +
829 +
830 + /*
534 831 * Functions for the admin panel content.
535 832 */
536 833
537 834 /**
@@ -538,9 +835,9 @@
538 835 * The function for the wp_print_styles action.
539 836 *
540 837 * @return null
541 838 */
542 - function addStyles()
839 + public function addStyles()
543 840 {
544 841 wp_enqueue_style(
545 842 'UserAccessManagerAdmin',
546 843 UAM_URLPATH . "css/uamAdmin.css",
@@ -562,9 +859,9 @@
562 859 * The function for the wp_print_scripts action.
563 860 *
564 861 * @return null
565 862 */
566 - function addScripts()
863 + public function addScripts()
567 864 {
568 865 wp_enqueue_script(
569 866 'UserAccessManagerJQueryTools',
570 867 UAM_URLPATH . 'js/jquery.tools.min.js',
@@ -581,9 +878,9 @@
581 878 * Prints the admin page
582 879 *
583 880 * @return null
584 881 */
585 - function printAdminPage()
882 + public function printAdminPage()
586 883 {
587 884 if (isset($_GET['page'])) {
588 885 $curAdminPage = $_GET['page'];
589 886 }
@@ -603,9 +900,9 @@
603 900 * Shows the error if the user has no rights to edit the content
604 901 *
605 902 * @return null
606 903 */
607 - function noRightsToEditContent()
904 + public function noRightsToEditContent()
608 905 {
609 906 $noRights = false;
610 907
611 908 if (isset($_GET['post'])
@@ -610,10 +907,14 @@
610 907
611 908 if (isset($_GET['post'])
612 909 && is_numeric($_GET['post'])
613 910 ) {
614 - $noRights
615 - = !$this->getAccessHandler()->checkAccess($_GET['post']);
911 + $post = get_post($_GET['post']);
912 +
913 + $noRights = !$this->getAccessHandler()->checkObjectAccess(
914 + $post->post_type,
915 + $post->ID
916 + );
616 917 }
617 918
618 919 if (isset($_GET['attachment_id'])
619 920 && is_numeric($_GET['attachment_id'])
@@ -618,10 +919,14 @@
618 919 if (isset($_GET['attachment_id'])
619 920 && is_numeric($_GET['attachment_id'])
620 921 && !$noRights
621 922 ) {
622 - $noRights
623 - = !$this->getAccessHandler()->checkAccess($_GET['attachment_id']);
923 + $post = get_post($_GET['attachment_id']);
924 +
925 + $noRights = !$this->getAccessHandler()->checkObjectAccess(
926 + $post->post_type,
927 + $post->ID
928 + );
624 929 }
625 930
626 931 if (isset($_GET['tag_ID'])
627 932 && is_numeric($_GET['tag_ID'])
@@ -626,14 +931,16 @@
626 931 if (isset($_GET['tag_ID'])
627 932 && is_numeric($_GET['tag_ID'])
628 933 && !$noRights
629 934 ) {
630 - $noRights
631 - = !$this->getAccessHandler()->checkCategoryAccess($_GET['tag_ID']);
935 + $noRights = !$this->getAccessHandler()->checkObjectAccess(
936 + 'category',
937 + $_GET['tag_ID']
938 + );
632 939 }
633 940
634 941 if ($noRights) {
635 - wp_die(TXT_NO_RIGHTS);
942 + wp_die(TXT_UAM_NO_RIGHTS);
636 943 }
637 944 }
638 945
639 946 /**
@@ -641,13 +948,13 @@
641 948 * Removes widgets to which a user should not have access.
642 949 *
643 950 * @return null
644 951 */
645 - function setupAdminDashboard()
952 + public function setupAdminDashboard()
646 953 {
647 954 global $wp_meta_boxes;
648 955
649 - if (!$this->getAccessHandler()->checkUserAccess()) {
956 + if (!$this->getAccessHandler()->checkUserAccess('manage_user_groups')) {
650 957 unset($wp_meta_boxes['dashboard']['normal']['core']['dashboard_recent_comments']);
651 958 }
652 959 }
653 960
@@ -655,14 +962,70 @@
655 962 * The function for the update_option_permalink_structure action.
656 963 *
657 964 * @return null
658 965 */
659 - function updatePermalink()
966 + public function updatePermalink()
660 967 {
661 968 $this->createHtaccess();
969 + $this->createHtpasswd();
662 970 }
663 971
972 +
973 + /*
974 + * Meta functions
975 + */
976 +
664 977 /**
978 + * Saves the object data to the database.
979 + *
980 + * @param string $objectType The object type.
981 + * @param integer $objectId The id of the object.
982 + * @param array $userGroups The new usergroups for the object.
983 + *
984 + * @return null
985 + */
986 + private function _saveObjectData($objectType, $objectId, $userGroups = null)
987 + {
988 + $uamAccessHandler = &$this->getAccessHandler();
989 + $uamOptions = $this->getAdminOptions();
990 +
991 + if (isset($_POST['uam_update_groups'])
992 + && ($uamAccessHandler->checkUserAccess('manage_user_groups')
993 + || $uamOptions['authors_can_add_posts_to_groups'] == 'true')
994 + ) {
995 + $userGroupsForObject = $uamAccessHandler->getUserGroupsForObject(
996 + $objectType,
997 + $objectId
998 + );
999 +
1000 + foreach ($userGroupsForObject as $uamUserGroup) {
1001 + $uamUserGroup->removeObject($objectType, $objectId);
1002 + $uamUserGroup->save();
1003 + }
1004 +
1005 + if ($userGroups === null
1006 + && isset($_POST['uam_usergroups'])
1007 + ) {
1008 + $userGroups = $_POST['uam_usergroups'];
1009 + }
1010 +
1011 + if ($userGroups !== null) {
1012 + foreach ($userGroups as $userGroupId) {
1013 + $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId);
1014 +
1015 + $uamUserGroup->addObject($objectType, $objectId);
1016 + $uamUserGroup->save();
1017 + }
1018 + }
1019 + }
1020 + }
1021 +
1022 +
1023 + /*
1024 + * Functions for the post actions.
1025 + */
1026 +
1027 + /**
665 1028 * The function for the manage_posts_columns and
666 1029 * the manage_pages_columns filter.
667 1030 *
668 1031 * @param array $defaults The table headers.
@@ -668,11 +1031,11 @@
668 1031 * @param array $defaults The table headers.
669 1032 *
670 1033 * @return array
671 1034 */
672 - function addPostColumnsHeader($defaults)
1035 + public function addPostColumnsHeader($defaults)
673 1036 {
674 - $defaults['uam_access'] = __('Access');
1037 + $defaults['uam_access'] = __('Access', 'user-access-manager');
675 1038 return $defaults;
676 1039 }
677 1040
678 1041 /**
@@ -682,12 +1045,18 @@
682 1045 * @param integer $id The id.
683 1046 *
684 1047 * @return String
685 1048 */
686 - function addPostColumn($columnName, $id)
1049 + public function addPostColumn($columnName, $id)
687 1050 {
688 1051 if ($columnName == 'uam_access') {
689 - echo $this->getIncludeContents(UAM_REALPATH.'tpl/postColumn.php', $id);
1052 + $post = get_post($id);
1053 +
1054 + echo $this->getIncludeContents(
1055 + UAM_REALPATH.'tpl/objectColumn.php',
1056 + $post->ID,
1057 + $post->post_type
1058 + );
690 1059 }
691 1060 }
692 1061
693 1062 /**
@@ -696,10 +1065,12 @@
696 1065 * @param object $post The post.
697 1066 *
698 1067 * @return null;
699 1068 */
700 - function editPostContent($post)
1069 + public function editPostContent($post)
701 1070 {
1071 + $objectId = $post->ID;
1072 +
702 1073 include UAM_REALPATH.'tpl/postEditForm.php';
703 1074 }
704 1075
705 1076 /**
@@ -708,57 +1079,26 @@
708 1079 * @param mixed $postParam The post id or a array of a post.
709 1080 *
710 1081 * @return null
711 1082 */
712 - function savePostData($postParam)
1083 + public function savePostData($postParam)
713 1084 {
714 - $uamAccessHandler = &$this->getAccessHandler();
715 - $uamOptions = $this->getAdminOptions();
1085 + if (is_array($postParam)) {
1086 + $post = get_post($postParam['ID']);
1087 + } else {
1088 + $post = get_post($postParam);
1089 + }
716 1090
717 - if ($uamAccessHandler->checkUserAccess()
718 - || $uamOptions['authors_can_add_posts_to_groups'] == 'true'
719 - ) {
720 - if (is_array($postParam)) {
721 - $post = get_post($postParam['ID']);
722 - } else {
723 - $post = get_post($postParam);
724 - }
725 -
726 - if ($post->post_type == 'revision') {
727 - $postId = $post->post_parent;
728 - $post = get_post($postId);
729 - } else {
730 - $postId = $post->ID;
731 - }
732 -
733 - if ($post->post_type == 'post') {
734 - $postType = 'Post';
735 - } elseif ($post->post_type == 'page') {
736 - $postType = 'Page';
737 - } elseif ($post->post_type == 'attachment') {
738 - $postType = 'File';
739 - }
740 -
741 - $userGroupsForPost = $uamAccessHandler->getUserGroupsForPost($postId);
742 -
743 - foreach ($userGroupsForPost as $uamUserGroup) {
744 - $uamUserGroup->{'remove'.$postType}($postId);
745 - $uamUserGroup->save();
746 - }
747 -
748 - if (isset($_POST['usergroups'])) {
749 - $userGroups = $_POST['usergroups'];
750 - }
751 -
752 - if (isset($userGroups)) {
753 - foreach ($userGroups as $userGroupId) {
754 - $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId);
755 -
756 - $uamUserGroup->{'add'.$postType}($postId);
757 - $uamUserGroup->save();
758 - }
759 - }
1091 + $postId = $post->ID;
1092 + $postType = $post->post_type;
1093 +
1094 + if ($postType == 'revision') {
1095 + $postId = $post->post_parent;
1096 + $parentPost = get_post($postId);
1097 + $postType = $parentPost->post_type;
760 1098 }
1099 +
1100 + $this->_saveObjectData($postType, $postId);
761 1101 }
762 1102
763 1103 /**
764 1104 * The function for the attachment_fields_to_save filter.
@@ -768,9 +1108,9 @@
768 1108 * @param object $attachment The attachment id.
769 1109 *
770 1110 * @return object
771 1111 */
772 - function saveAttachmentData($attachment)
1112 + public function saveAttachmentData($attachment)
773 1113 {
774 1114 $this->savePostData($attachment['ID']);
775 1115
776 1116 return $attachment;
@@ -782,15 +1122,17 @@
782 1122 * @param integer $postId The post id.
783 1123 *
784 1124 * @return null
785 1125 */
786 - function removePostData($postId)
1126 + public function removePostData($postId)
787 1127 {
788 1128 global $wpdb;
1129 + $post = get_post($postId);
789 1130
790 1131 $wpdb->query(
791 - "DELETE FROM " . DB_ACCESSGROUP_TO_POST . "
792 - WHERE post_id = ".$postId
1132 + "DELETE FROM " . DB_ACCESSGROUP_TO_OBJECT . "
1133 + WHERE object_id = '".$postId."'
1134 + AND object_type = '".$post->post_type."'"
793 1135 );
794 1136 }
795 1137
796 1138 /**
@@ -800,21 +1142,29 @@
800 1142 * @param object $post The post.
801 1143 *
802 1144 * @return string
803 1145 */
804 - function showMediaFile($meta = '', $post = null)
805 - {
1146 + public function showMediaFile($meta = '', $post = null)
1147 + {
806 1148 $content = $meta;
807 1149 $content .= '</td></tr><tr>';
808 1150 $content .= '<th class="label">';
809 - $content .= '<label>'.TXT_SET_UP_USERGROUPS.'</label>';
1151 + $content .= '<label>'.TXT_UAM_SET_UP_USERGROUPS.'</label>';
810 1152 $content .= '</th>';
811 1153 $content .= '<td class="field">';
812 - $content .= $this->getIncludeContents(UAM_REALPATH.'tpl/postEditForm.php');
1154 + $content .= $this->getIncludeContents(
1155 + UAM_REALPATH.'tpl/postEditForm.php',
1156 + $post->ID
1157 + );
813 1158
814 1159 return $content;
815 1160 }
816 1161
1162 +
1163 + /*
1164 + * Functions for the user actions.
1165 + */
1166 +
817 1167 /**
818 1168 * The function for the manage_users_columns filter.
819 1169 *
820 1170 * @param array $defaults The table headers.
@@ -820,9 +1170,9 @@
820 1170 * @param array $defaults The table headers.
821 1171 *
822 1172 * @return array
823 1173 */
824 - function addUserColumnsHeader($defaults)
1174 + public function addUserColumnsHeader($defaults)
825 1175 {
826 1176 $defaults['uam_access'] = __('uam user groups');
827 1177 return $defaults;
828 1178 }
@@ -835,14 +1185,15 @@
835 1185 * @param integer $id The id.
836 1186 *
837 1187 * @return String
838 1188 */
839 - function addUserColumn($empty, $columnName, $id)
1189 + public function addUserColumn($empty, $columnName, $id)
840 1190 {
841 1191 if ($columnName == 'uam_access') {
842 1192 return $this->getIncludeContents(
843 1193 UAM_REALPATH.'tpl/userColumn.php',
844 - $id
1194 + $id,
1195 + 'user'
845 1196 );
846 1197 }
847 1198 }
848 1199
@@ -850,9 +1201,9 @@
850 1201 * The function for the edit_user_profile action.
851 1202 *
852 1203 * @return null
853 1204 */
854 - function showUserProfile()
1205 + public function showUserProfile()
855 1206 {
856 1207 echo $this->getIncludeContents(UAM_REALPATH.'tpl/userProfileEditForm.php');
857 1208 }
858 1209
@@ -862,37 +1213,11 @@
862 1213 * @param integer $userId The user id.
863 1214 *
864 1215 * @return null
865 1216 */
866 - function saveUserData($userId)
1217 + public function saveUserData($userId)
867 1218 {
868 - $uamAccessHandler = &$this->getAccessHandler();
869 -
870 - if ($uamAccessHandler->checkUserAccess()) {
871 - if ($uamAccessHandler->checkUserAccess()) {
872 - $userGroupsForPost
873 - = $uamAccessHandler->getUserGroupsForUser($userId);
874 -
875 - foreach ($userGroupsForPost as $uamUserGroup) {
876 - $uamUserGroup->removeUser($userId);
877 - $uamUserGroup->save();
878 - }
879 -
880 - if (isset($_POST['usergroups'])) {
881 - $userGroups = $_POST['usergroups'];
882 - }
883 -
884 - if (isset($userGroups)) {
885 - foreach ($userGroups as $userGroupId) {
886 - $uamUserGroup
887 - = $uamAccessHandler->getUserGroups($userGroupId);
888 -
889 - $uamUserGroup->addUser($userId);
890 - $uamUserGroup->save();
891 - }
892 - }
893 - }
894 - }
1219 + $this->_saveObjectData('user', $userId);
895 1220 }
896 1221
897 1222 /**
898 1223 * The function for the delete_user action.
@@ -900,18 +1225,24 @@
900 1225 * @param integer $userId The user id.
901 1226 *
902 1227 * @return null
903 1228 */
904 - function removeUserData($userId)
1229 + public function removeUserData($userId)
905 1230 {
906 1231 global $wpdb;
907 1232
908 1233 $wpdb->query(
909 - "DELETE FROM " . DB_ACCESSGROUP_TO_USER . "
910 - WHERE user_id = ".$userId
1234 + "DELETE FROM " . DB_ACCESSGROUP_TO_OBJECT . "
1235 + WHERE object_id = ".$userId."
1236 + AND object_type = 'user'"
911 1237 );
912 1238 }
913 1239
1240 +
1241 + /*
1242 + * Functions for the category actions.
1243 + */
1244 +
914 1245 /**
915 1246 * The function for the manage_categories_columns filter.
916 1247 *
917 1248 * @param array $defaults The table headers.
@@ -917,11 +1248,11 @@
917 1248 * @param array $defaults The table headers.
918 1249 *
919 1250 * @return array
920 1251 */
921 - function addCategoryColumnsHeader($defaults)
1252 + public function addCategoryColumnsHeader($defaults)
922 1253 {
923 - $defaults['uam_access'] = __('Access');
1254 + $defaults['uam_access'] = __('Access', 'user-access-manager');
924 1255 return $defaults;
925 1256 }
926 1257
927 1258 /**
@@ -932,14 +1263,15 @@
932 1263 * @param integer $id The id.
933 1264 *
934 1265 * @return String
935 1266 */
936 - function addCategoryColumn($empty, $columnName, $id)
1267 + public function addCategoryColumn($empty, $columnName, $id)
937 1268 {
938 1269 if ($columnName == 'uam_access') {
939 1270 return $this->getIncludeContents(
940 - UAM_REALPATH.'tpl/categoryColumn.php',
941 - $id
1271 + UAM_REALPATH.'tpl/objectColumn.php',
1272 + $id,
1273 + 'category'
942 1274 );
943 1275 }
944 1276 }
945 1277
@@ -949,9 +1281,9 @@
949 1281 * @param object $category The category.
950 1282 *
951 1283 * @return null
952 1284 */
953 - function showCategoryEditForm($category)
1285 + public function showCategoryEditForm($category)
954 1286 {
955 1287 include UAM_REALPATH.'tpl/categoryEditForm.php';
956 1288 }
957 1289
@@ -961,37 +1293,11 @@
961 1293 * @param integer $categoryId The category id.
962 1294 *
963 1295 * @return null
964 1296 */
965 - function saveCategoryData($categoryId)
1297 + public function saveCategoryData($categoryId)
966 1298 {
967 - $uamAccessHandler = &$this->getAccessHandler();
968 - $uamOptions = $this->getAdminOptions();
969 -
970 - if ($uamAccessHandler->checkUserAccess()
971 - || $uamOptions['authors_can_add_posts_to_groups'] == 'true'
972 - ) {
973 - $userGroupsForCategory
974 - = $uamAccessHandler->getUserGroupsForCategory($categoryId);
975 -
976 - foreach ($userGroupsForCategory as $uamUserGroup) {
977 - $uamUserGroup->removeCategory($categoryId);
978 - $uamUserGroup->save();
979 - }
980 -
981 - if (isset($_POST['usergroups'])) {
982 - $userGroups = $_POST['usergroups'];
983 - }
984 -
985 - if (isset($userGroups)) {
986 - foreach ($userGroups as $userGroupId) {
987 - $uamUserGroup = $uamAccessHandler->getUserGroups($userGroupId);
988 -
989 - $uamUserGroup->addCategory($categoryId);
990 - $uamUserGroup->save();
991 - }
992 - }
993 - }
1299 + $this->_saveObjectData('category', $categoryId);
994 1300 }
995 1301
996 1302 /**
997 1303 * The function for the delete_category action.
@@ -999,24 +1305,135 @@
999 1305 * @param integer $categoryId The id of the category.
1000 1306 *
1001 1307 * @return null
1002 1308 */
1003 - function removeCategoryData($categoryId)
1309 + public function removeCategoryData($categoryId)
1004 1310 {
1311 + //TODO
1005 1312 global $wpdb;
1006 1313
1007 1314 $wpdb->query(
1008 - "DELETE FROM " . DB_ACCESSGROUP_TO_CATEGORY . "
1009 - WHERE category_id = ".$categoryId
1315 + "DELETE FROM " . DB_ACCESSGROUP_TO_OBJECT . "
1316 + WHERE object_id = ".$categoryId."
1317 + AND object_type = 'category'"
1010 1318 );
1011 1319 }
1320 +
1012 1321
1322 + /*
1323 + * Functions for the pluggable object actions.
1324 + */
1013 1325
1326 + /**
1327 + * The function for the pluggable save action.
1328 + *
1329 + * @param string $objectType The name of the pluggable object.
1330 + * @param integer $objectId The pluggable object id.
1331 + * @param array $userGroups The user groups for the object.
1332 + *
1333 + * @return null
1334 + */
1335 + public function savePlObjectData($objectType, $objectId, $userGroups = null)
1336 + {
1337 + $this->_saveObjectData($objectType, $objectId, $userGroups);
1338 + }
1339 +
1340 + /**
1341 + * The function for the pluggable remove action.
1342 + *
1343 + * @param string $objectName The name of the pluggable object.
1344 + * @param integer $objectId The pluggable object id.
1345 + *
1346 + * @return null
1347 + */
1348 + public function removePlObjectData($objectName, $objectId)
1349 + {
1350 + global $wpdb;
1351 +
1352 + $wpdb->query(
1353 + "DELETE FROM " . DB_ACCESSGROUP_TO_OBJECT . "
1354 + WHERE user_id = ".$userId."
1355 + AND object_type = ".$objectName
1356 + );
1357 + }
1358 +
1359 + /**
1360 + * Returns the group selection form for pluggable objects.
1361 + *
1362 + * @param string $objectType The object type.
1363 + * @param integer $objectId The id of the object.
1364 + * @param string $groupsFormName The name of the form which contains the groups.
1365 + *
1366 + * @return string;
1367 + */
1368 + public function showPlGroupSelectionForm($objectType, $objectId, $groupsFormName = null)
1369 + {
1370 + $fileName = UAM_REALPATH.'tpl/groupSelectionForm.php';
1371 + $uamUserGroups = $this->getAccessHandler()->getUserGroups();
1372 + $userGroupsForObject = $this->getAccessHandler()->getUserGroupsForObject(
1373 + $objectType,
1374 + $objectId
1375 + );
1376 +
1377 + if (is_file($fileName)) {
1378 + ob_start();
1379 + include $fileName;
1380 + $contents = ob_get_contents();
1381 + ob_end_clean();
1382 +
1383 + return $contents;
1384 + }
1385 +
1386 + return '';
1387 + }
1388 +
1389 + /**
1390 + * Returns the column for a pluggable object.
1391 + *
1392 + * @param string $objectType The object type.
1393 + * @param integer $objectId The object id.
1394 + *
1395 + * @return string
1396 + */
1397 + public function getPlColumn($objectType, $objectId)
1398 + {
1399 + return $this->getIncludeContents(
1400 + UAM_REALPATH.'tpl/objectColumn.php',
1401 + $objectId,
1402 + $objectType
1403 + );
1404 + }
1405 +
1406 +
1014 1407 /*
1015 1408 * Functions for the blog content.
1016 1409 */
1017 1410
1018 1411 /**
1412 + * Manipulates the wordpress query object to filter content.
1413 + *
1414 + * @param object $wpQuery The wordpress query object.
1415 + *
1416 + * @return null
1417 + */
1418 + public function parseQuery($wpQuery)
1419 + {
1420 + $uamOptions = $this->getAdminOptions();
1421 +
1422 + if ($uamOptions['hide_post'] == 'true') {
1423 + $uamAccessHandler = &$this->getAccessHandler();
1424 + $excludedPosts = $uamAccessHandler->getExcludedPosts();
1425 +
1426 + if (count($excludedPosts) > 0) {
1427 + $wpQuery->query_vars['post__not_in'] = array_merge(
1428 + $wpQuery->query_vars['post__not_in'],
1429 + $excludedPosts
1430 + );
1431 + }
1432 + }
1433 + }
1434 +
1435 + /**
1019 1436 * Modifies the content of the post by the given settings.
1020 1437 *
1021 1438 * @param object $post The current post.
1022 1439 *
@@ -1027,10 +1444,15 @@
1027 1444 $uamOptions = $this->getAdminOptions();
1028 1445 $uamAccessHandler = &$this->getAccessHandler();
1029 1446
1030 1447 $postType = $post->post_type;
1031 -
1032 - if ($postType == 'attachment') {
1448 +
1449 + $postableTypes = $uamAccessHandler->getPostableTypes();
1450 +
1451 + if (in_array($postType, $postableTypes)
1452 + && $postType != 'post'
1453 + && $postType != 'page'
1454 + ) {
1033 1455 $postType = 'post';
1034 1456 } elseif ($postType != 'post' && $postType != 'page') {
1035 1457 return $post;
1036 1458 }
@@ -1035,17 +1457,19 @@
1035 1457 return $post;
1036 1458 }
1037 1459
1038 1460 if ($uamOptions['hide_'.$postType] == 'true'
1039 - || $this->atAdminPanel
1461 + || $this->atAdminPanel()
1040 1462 ) {
1041 - if ($uamAccessHandler->checkAccess($post->ID)) {
1042 - $post->post_title .= $this->adminOutput($post->ID);
1463 + if ($uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1464 + $post->post_title .= $this->adminOutput($post->post_type, $post->ID);
1043 1465
1044 1466 return $post;
1045 1467 }
1046 1468 } else {
1047 - if (!$uamAccessHandler->checkAccess($post->ID)) {
1469 + if (!$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1470 + $post->isLocked = true;
1471 +
1048 1472 $uamPostContent = $uamOptions[$postType.'_content'];
1049 1473 $uamPostContent = str_replace(
1050 1474 "[LOGIN_FORM]",
1051 1475 $this->getLoginBarHtml(),
@@ -1075,9 +1499,9 @@
1075 1499
1076 1500 $post->post_content = $uamPostContent;
1077 1501 }
1078 1502
1079 - $post->post_title .= $this->adminOutput($post->ID);
1503 + $post->post_title .= $this->adminOutput($post->post_type, $post->ID);
1080 1504
1081 1505 return $post;
1082 1506 }
1083 1507
@@ -1090,9 +1514,9 @@
1090 1514 * @param arrray $posts The posts.
1091 1515 *
1092 1516 * @return array
1093 1517 */
1094 - function showPost($posts = array())
1518 + public function showPost($posts = array())
1095 1519 {
1096 1520 $showPosts = array();
1097 1521 $uamOptions = $this->getAdminOptions();
1098 1522
@@ -1099,9 +1523,11 @@
1099 1523 if (!is_feed()
1100 1524 || ($uamOptions['protect_feed'] == 'true' && is_feed())
1101 1525 ) {
1102 1526 foreach ($posts as $post) {
1103 - $post = $this->_getPost($post);
1527 + if ($post !== null) {
1528 + $post = $this->_getPost($post);
1529 + }
1104 1530
1105 1531 if ($post !== null) {
1106 1532 $showPosts[] = $post;
1107 1533 }
@@ -1113,8 +1539,33 @@
1113 1539 return $posts;
1114 1540 }
1115 1541
1116 1542 /**
1543 + * The function for the posts_where_paged filter.
1544 + *
1545 + * @param string $sql The where sql statment.
1546 + *
1547 + * @return string
1548 + */
1549 + public function showPostSql($sql)
1550 + {
1551 + $uamAccessHandler = &$this->getAccessHandler();
1552 + $uamOptions = $this->getAdminOptions();
1553 +
1554 + if ($uamOptions['hide_post'] == 'true') {
1555 + global $wpdb;
1556 + $excludedPosts = $uamAccessHandler->getExcludedPosts();
1557 +
1558 + if (count($excludedPosts) > 0) {
1559 + $excludedPostsStr = implode(",", $excludedPosts);
1560 + $sql .= " AND $wpdb->posts.ID NOT IN($excludedPostsStr) ";
1561 + }
1562 + }
1563 +
1564 + return $sql;
1565 + }
1566 +
1567 + /**
1117 1568 * The function for the wp_get_nav_menu_items filter.
1118 1569 *
1119 1570 * @param array $items The menu item.
1120 1571 *
@@ -1119,9 +1570,9 @@
1119 1570 * @param array $items The menu item.
1120 1571 *
1121 1572 * @return array
1122 1573 */
1123 - function showCustomMenu($items)
1574 + public function showCustomMenu($items)
1124 1575 {
1125 1576 $showItems = array();
1126 1577
1127 1578 foreach ($items as $item) {
@@ -1128,22 +1579,36 @@
1128 1579 if ($item->object == 'post'
1129 1580 || $item->object == 'page'
1130 1581 ) {
1131 1582 $object = get_post($item->object_id);
1132 - $post = $this->_getPost($object);
1583 +
1584 + if ($object !== null) {
1585 + $post = $this->_getPost($object);
1586 + }
1133 1587
1134 1588 if ($post !== null) {
1135 - $item->title = $post->post_title;
1589 + if (isset($post->isLocked)) {
1590 + $item->title = $post->post_title;
1591 + }
1592 +
1593 + $item->title .= $this->adminOutput(
1594 + $item->object,
1595 + $item->object_id
1596 + );
1136 1597
1137 1598 $showItems[] = $item;
1138 1599 }
1139 1600 } elseif ($item->object == 'category') {
1140 1601 $object = get_category($item->object_id);
1141 - $category = $this->_getCategory($object);
1602 + $category = $this->_getTerm('category', $object);
1142 1603
1143 1604 if ($category !== null
1144 1605 && !$category->isEmpty
1145 1606 ) {
1607 + $item->title .= $this->adminOutput(
1608 + $item->object,
1609 + $item->object_id
1610 + );
1146 1611 $showItems[] = $item;
1147 1612 }
1148 1613 } else {
1149 1614 $showItems[] = $item;
@@ -1159,9 +1624,9 @@
1159 1624 * @param array $comments The comments.
1160 1625 *
1161 1626 * @return array
1162 1627 */
1163 - function showComment($comments = array())
1628 + public function showComment($comments = array())
1164 1629 {
1165 1630 $showComments = array();
1166 1631 $uamOptions = $this->getAdminOptions();
1167 1632 $uamAccessHandler = &$this->getAccessHandler();
@@ -1171,15 +1636,15 @@
1171 1636 $postType = $post->post_type;
1172 1637
1173 1638 if ($uamOptions['hide_'.$postType.'_comment'] == 'true'
1174 1639 || $uamOptions['hide_'.$postType] == 'true'
1175 - || $this->atAdminPanel
1640 + || $this->atAdminPanel()
1176 1641 ) {
1177 - if ($uamAccessHandler->checkAccess($post->ID)) {
1642 + if ($uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1178 1643 $showComments[] = $comment;
1179 1644 }
1180 1645 } else {
1181 - if (!$uamAccessHandler->checkAccess($post->ID)) {
1646 + if (!$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)) {
1182 1647 $comment->comment_content
1183 1648 = $uamOptions[$postType.'_comment_content'];
1184 1649 }
1185 1650
@@ -1198,9 +1663,9 @@
1198 1663 * @param array $pages The pages.
1199 1664 *
1200 1665 * @return array
1201 1666 */
1202 - function showPage($pages = array())
1667 + public function showPage($pages = array())
1203 1668 {
1204 1669 $showPages = array();
1205 1670 $uamOptions = $this->getAdminOptions();
1206 1671 $uamAccessHandler = &$this->getAccessHandler();
@@ -1206,16 +1671,19 @@
1206 1671 $uamAccessHandler = &$this->getAccessHandler();
1207 1672
1208 1673 foreach ($pages as $page) {
1209 1674 if ($uamOptions['hide_page'] == 'true'
1210 - || $this->atAdminPanel
1675 + || $this->atAdminPanel()
1211 1676 ) {
1212 - if ($uamAccessHandler->checkAccess($page->ID)) {
1213 - $page->post_title.= $this->adminOutput($page->ID);
1677 + if ($uamAccessHandler->checkObjectAccess($page->post_type, $page->ID)) {
1678 + $page->post_title .= $this->adminOutput(
1679 + $page->post_type,
1680 + $page->ID
1681 + );
1214 1682 $showPages[] = $page;
1215 1683 }
1216 1684 } else {
1217 - if (!$uamAccessHandler->checkAccess($page->ID)) {
1685 + if (!$uamAccessHandler->checkObjectAccess($page->post_type, $page->ID)) {
1218 1686 if ($uamOptions['hide_page_title'] == 'true') {
1219 1687 $page->post_title = $uamOptions['page_title'];
1220 1688 }
1221 1689
@@ -1221,9 +1689,9 @@
1221 1689
1222 1690 $page->post_content = $uamOptions['page_content'];
1223 1691 }
1224 1692
1225 - $page->post_title.= $this->adminOutput($page->ID);
1693 + $page->post_title .= $this->adminOutput($page->post_type, $page->ID);
1226 1694 $showPages[] = $page;
1227 1695 }
1228 1696 }
1229 1697
@@ -1232,66 +1700,90 @@
1232 1700 return $pages;
1233 1701 }
1234 1702
1235 1703 /**
1236 - * Modifies the content of the category by the given settings.
1704 + * Modifies the content of the term by the given settings.
1237 1705 *
1238 - * @param object $category The current category.
1706 + * @param string $termType The type of the term.
1707 + * @param object $term The current term.
1239 1708 *
1240 1709 * @return object
1241 1710 */
1242 - private function _getCategory($category)
1711 + private function _getTerm($termType, $term)
1243 1712 {
1244 1713 $uamOptions = $this->getAdminOptions();
1245 1714 $uamAccessHandler = &$this->getAccessHandler();
1246 1715
1247 - $category->isEmpty = false;
1716 + $term->isEmpty = false;
1248 1717
1249 - if ($uamAccessHandler->checkCategoryAccess($category->term_id)) {
1250 - if ($this->atAdminPanel == false
1718 + $term->name .= $this->adminOutput('term', $term->term_id);
1719 +
1720 + if ($termType == 'post_tag'
1721 + || $termType == 'category'
1722 + && $uamAccessHandler->checkObjectAccess('category', $term->term_id)
1723 + ) {
1724 + if ($this->atAdminPanel() == false
1251 1725 && ($uamOptions['hide_post'] == 'true'
1252 1726 || $uamOptions['hide_page'] == 'true')
1253 1727 ) {
1728 + $termRequest = $term->term_id;
1729 + $termRequestType = $termType;
1730 +
1731 + if ($termType == 'post_tag') {
1732 + $termRequest = $term->slug;
1733 + $termRequestType = 'tag';
1734 + }
1735 +
1254 1736 $args = array(
1255 1737 'numberposts' => - 1,
1256 - 'category' => $category->term_id
1738 + $termRequestType => $termRequest
1257 1739 );
1258 1740
1259 - $categoryPosts = get_posts($args);
1741 + $termPosts = get_posts($args);
1742 + $term->count = count($termPosts);
1260 1743
1261 - if (isset($categoryPosts)) {
1262 - foreach ($categoryPosts as $post) {
1744 + if (isset($termPosts)) {
1745 + foreach ($termPosts as $post) {
1263 1746 if ($uamOptions['hide_'.$post->post_type] == 'true'
1264 - && !$uamAccessHandler->checkAccess($post->ID)
1747 + && !$uamAccessHandler->checkObjectAccess($post->post_type, $post->ID)
1265 1748 ) {
1266 - $category->count--;
1749 + $term->count--;
1267 1750 }
1268 1751 }
1269 1752 }
1270 1753
1271 - if ($category->count <= 0
1754 + //For post_tags
1755 + if ($termType == 'post_tag'
1756 + && $term->count <= 0
1757 + ) {
1758 + return null;
1759 + }
1760 +
1761 + //For categories
1762 + if ($term->count <= 0
1272 1763 && $uamOptions['hide_empty_categories'] == 'true'
1273 - && $category->taxonomy == "category"
1764 + && ($term->taxonomy == "term"
1765 + || $term->taxonomy == "category")
1274 1766 ) {
1275 - $category->isEmpty = true;
1767 + $term->isEmpty = true;
1276 1768 }
1277 1769
1278 1770 if ($uamOptions['lock_recursive'] == 'false') {
1279 - $curCategory = $category;
1771 + $curCategory = $term;
1280 1772
1281 1773 while ($curCategory->parent != 0) {
1282 - $curCategory = get_category($curCategory->parent);
1774 + $curCategory = get_term($curCategory->parent, 'category');
1283 1775
1284 - if ($uamAccessHandler->checkCategoryAccess($curCategory->term_id)) {
1285 - $category->parent = $curCategory->term_id;
1776 + if ($uamAccessHandler->checkObjectAccess('term', $curCategory->term_id)) {
1777 + $term->parent = $curCategory->term_id;
1286 1778 break;
1287 1779 }
1288 1780 }
1289 1781 }
1290 1782
1291 - return $category;
1783 + return $term;
1292 1784 } else {
1293 - return $category;
1785 + return $term;
1294 1786 }
1295 1787 }
1296 1788
1297 1789 return null;
@@ -1299,72 +1791,52 @@
1299 1791
1300 1792 /**
1301 1793 * The function for the get_terms filter.
1302 1794 *
1303 - * @param array $categories The categories.
1304 - * @param array $args The given arguments.
1795 + * @param array $terms The terms.
1796 + * @param array $args The given arguments.
1305 1797 *
1306 1798 * @return array
1307 1799 */
1308 - function showCategory($categories = array(), $args = array())
1309 - {
1800 + public function showTerms($terms = array(), $args = array())
1801 + {
1310 1802 $uamOptions = $this->getAdminOptions();
1311 1803 $uamAccessHandler = &$this->getAccessHandler();
1312 1804
1313 - $showCategories = array();
1805 + $showTerms = array();
1314 1806
1315 1807 $uamOptions = $this->getAdminOptions();
1316 1808
1317 - foreach ($categories as $category) {
1318 - if (!is_object($category)) {
1319 - return $categories;
1809 + foreach ($terms as $term) {
1810 + if (!is_object($term)) {
1811 + return $terms;
1320 1812 }
1321 1813
1322 - $category = $this->_getCategory($category);
1814 + if ($term->taxonomy == 'category') {
1815 + $term = $this->_getTerm('category', $term);
1816 + } elseif ($term->taxonomy == 'post_tag') {
1817 + $term = $this->_getTerm('post_tag', $term);
1818 + }
1323 1819
1324 - if ($category !== null) {
1325 - if (!$category->isEmpty) {
1326 - $showCategories[$category->term_id] = $category;
1820 + if ($term !== null) {
1821 + if (!isset($term->isEmpty)
1822 + || !$term->isEmpty
1823 + ) {
1824 + $showTerms[$term->term_id] = $term;
1327 1825 }
1328 1826 }
1329 1827 }
1330 1828
1331 - foreach ($categories as $key => $category) {
1332 - if (!array_key_exists($category->term_id, $showCategories)) {
1333 - unset($categories[$key]);
1829 + foreach ($terms as $key => $term) {
1830 + if (!array_key_exists($term->term_id, $showTerms)) {
1831 + unset($terms[$key]);
1334 1832 }
1335 1833 }
1336 1834
1337 - return $categories;
1835 + return $terms;
1338 1836 }
1339 1837
1340 1838 /**
1341 - * The function for the get_the_title filter.
1342 - *
1343 - * @param string $title The title of the post.
1344 - * @param object $postId The post id.
1345 - *
1346 - * @return string
1347 - */
1348 - /*function showTitle($title, $postId = null)
1349 - {
1350 - $uamOptions = $this->getAdminOptions();
1351 - $uamAccessHandler = &$this->getAccessHandler();
1352 -
1353 - $post = get_post($postId);
1354 - $postType = $post->post_type;
1355 -
1356 - if (!$uamAccessHandler->checkAccess($postId)
1357 - && $post != null
1358 - && $uamOptions['hide_'.$postType.'_title'] == 'true'
1359 - ) {
1360 - $title = $uamOptions[$postType.'_title'];
1361 - }
1362 -
1363 - return $title;
1364 - }*/
1365 -
1366 - /**
1367 1839 * The function for the get_previous_post_where and
1368 1840 * the get_next_post_where filter.
1369 1841 *
1370 1842 * @param string $sql The current sql string.
@@ -1370,29 +1842,19 @@
1370 1842 * @param string $sql The current sql string.
1371 1843 *
1372 1844 * @return string
1373 1845 */
1374 - function showNextPreviousPost($sql)
1846 + public function showNextPreviousPost($sql)
1375 1847 {
1848 + $uamAccessHandler = &$this->getAccessHandler();
1376 1849 $uamOptions = $this->getAdminOptions();
1377 1850
1378 1851 if ($uamOptions['hide_post'] == 'true') {
1379 - $posts = get_posts();
1380 - $uamAccessHandler = &$this->getAccessHandler();
1852 + $excludedPosts = $uamAccessHandler->getExcludedPosts();
1381 1853
1382 - if (isset($posts)) {
1383 - foreach ($posts as $post) {
1384 - if (!$uamAccessHandler->checkAccess($post->ID)) {
1385 - $excludedPosts[] = $post->ID;
1386 - }
1387 - }
1388 -
1389 - global $wpdb;
1390 -
1391 - if (isset($excludedPosts)) {
1392 - $excludedPostsStr = implode(",", $excludedPosts);
1393 - $sql.= "AND p.ID NOT IN($excludedPostsStr)";
1394 - }
1854 + if (count($excludedPosts) > 0) {
1855 + $excludedPostsStr = implode(",", $excludedPosts);
1856 + $sql.= " AND p.ID NOT IN($excludedPostsStr) ";
1395 1857 }
1396 1858 }
1397 1859
1398 1860 return $sql;
@@ -1400,17 +1862,18 @@
1400 1862
1401 1863 /**
1402 1864 * Returns the admin hint.
1403 1865 *
1404 - * @param integer $postId The post id we want to check.
1866 + * @param string $objectType The object type.
1867 + * @param integer $objectId The object id we want to check.
1405 1868 *
1406 1869 * @return string
1407 1870 */
1408 - function adminOutput($postId)
1871 + public function adminOutput($objectType, $objectId)
1409 1872 {
1410 1873 $output = "";
1411 1874
1412 - if (!$this->atAdminPanel) {
1875 + if (!$this->atAdminPanel()) {
1413 1876 $uamOptions = $this->getAdminOptions();
1414 1877
1415 1878 if ($uamOptions['blog_admin_hint'] == 'true') {
1416 1879 global $current_user;
@@ -1422,9 +1885,11 @@
1422 1885 }
1423 1886
1424 1887 $uamAccessHandler = &$this->getAccessHandler();
1425 1888
1426 - if (count($uamAccessHandler->getUserGroupsForPost($postId)) > 0) {
1889 + if ($uamAccessHandler->userIsAdmin($current_user->ID)
1890 + && count($uamAccessHandler->getUserGroupsForObject($objectType, $objectId)) > 0
1891 + ) {
1427 1892 $output .= $uamOptions['blog_admin_hint_text'];
1428 1893 }
1429 1894 }
1430 1895 }
@@ -1439,15 +1904,15 @@
1439 1904 * @param integer $postId The id of the post.
1440 1905 *
1441 1906 * @return string
1442 1907 */
1443 - function showGroupMembership($link, $postId)
1908 + public function showGroupMembership($link, $postId)
1444 1909 {
1445 1910 $uamAccessHandler = &$this->getAccessHandler();
1446 - $groups = $uamAccessHandler->getUserGroupsForPost($postId);
1911 + $groups = $uamAccessHandler->getUserGroupsForObject('post', $postId);
1447 1912
1448 1913 if (count($groups) > 0) {
1449 - $link .= ' | '.TXT_ASSIGNED_GROUPS.': ';
1914 + $link .= ' | '.TXT_UAM_ASSIGNED_GROUPS.': ';
1450 1915
1451 1916 foreach ($groups as $group) {
1452 1917 $link .= $group->getGroupName().', ';
1453 1918 }
@@ -1462,9 +1927,9 @@
1462 1927 * Returns the login bar.
1463 1928 *
1464 1929 * @return string
1465 1930 */
1466 - function getLoginBarHtml()
1931 + public function getLoginBarHtml()
1467 1932 {
1468 1933 if (!is_user_logged_in()) {
1469 1934 return $this->getIncludeContents(UAM_REALPATH.'tpl/loginBar.php');
1470 1935 }
@@ -1477,47 +1942,98 @@
1477 1942 * Functions for the redirection and files.
1478 1943 */
1479 1944
1480 1945 /**
1946 + * Returns ture if permalinks are active otherwise false.
1947 + *
1948 + * @return boolean
1949 + */
1950 + public function isPermalinksActive()
1951 + {
1952 + $permaStruc = get_option('permalink_structure');
1953 +
1954 + if (empty($permaStruc)) {
1955 + return false;
1956 + } else {
1957 + return true;
1958 + }
1959 + }
1960 +
1961 + /**
1481 1962 * Redirects to a page or to content.
1963 + *
1964 + * @param string $headers The headers which are given from wordpress.
1965 + * @param object $pageParams The params of the current page.
1482 1966 *
1483 1967 * @return null
1484 1968 */
1485 - function redirect()
1969 + public function redirect($headers, $pageParams)
1486 1970 {
1487 1971 $uamOptions = $this->getAdminOptions();
1488 1972
1489 - if (isset($_GET['getfile'])) {
1490 - $fileUrl = $_GET['getfile'];
1491 - }
1973 + if (isset($_GET['uamgetfile'])
1974 + && isset($_GET['uamfiletype'])
1975 + ) {
1976 + $fileUrl = $_GET['uamgetfile'];
1977 + $fileType = $_GET['uamfiletype'];
1978 + $this->getFile($fileType, $fileUrl);
1979 + } elseif (!$this->atAdminPanel() && $uamOptions['redirect'] != 'false') {
1980 + $object = null;
1492 1981
1493 - $emptyId = null;
1494 - $post = get_post($emptyId);
1495 -
1496 - if ($uamOptions['redirect'] != 'false'
1497 - && !$this->getAccessHandler()->checkAccess($post->ID)
1498 - && !$this->atAdminPanel
1499 - && !isset($fileUrl)
1500 - ) {
1501 - $this->redirectUser();
1502 - } elseif (isset($fileUrl)) {
1503 - $permaStruc = get_option('permalink_structure');
1982 + if (isset($pageParams->query_vars['p'])) {
1983 + $object = get_post($pageParams->query_vars['p']);
1984 + $objectType = $object->post_type;
1985 + $objectId = $object->ID;
1986 + } elseif (isset($pageParams->query_vars['page_id'])) {
1987 + $object = get_post($pageParams->query_vars['page_id']);
1988 + $objectType = $object->post_type;
1989 + $objectId = $object->ID;
1990 + } elseif (isset($pageParams->query_vars['cat_id'])) {
1991 + $object = get_category($pageParams->query_vars['cat_id']);
1992 + $objectType = 'category';
1993 + $objectId = $object->term_id;
1994 + }
1504 1995
1505 - if (!empty($permaStruc)) {
1506 - $uploadDir = wp_upload_dir();
1507 - $fileUrl = $uploadDir['baseurl'].'/'.$fileUrl;
1996 + if ($object === null
1997 + ||$object !== null
1998 + && !$this->getAccessHandler()->checkObjectAccess($objectType, $objectId)
1999 + ) {
2000 + $this->redirectUser($object);
1508 2001 }
1509 -
1510 - $this->getFile($fileUrl);
1511 2002 }
1512 2003 }
1513 2004
1514 2005 /**
2006 + * Returns the current url.
2007 + *
2008 + * @return string
2009 + */
2010 + public function getCurrentUrl()
2011 + {
2012 + if (!isset($_SERVER['REQUEST_URI'])) {
2013 + $serverrequri = $_SERVER['PHP_SELF'];
2014 + } else {
2015 + $serverrequri = $_SERVER['REQUEST_URI'];
2016 + }
2017 +
2018 + $s = empty($_SERVER["HTTPS"]) ? '' : ($_SERVER["HTTPS"] == "on") ? "s" : "";
2019 + $protocolArray = explode("/", strtolower($_SERVER["SERVER_PROTOCOL"]));
2020 + $protocol = $protocolArray[0].$s;
2021 + $port = ($_SERVER["SERVER_PORT"] == "80") ? "" : (":".$_SERVER["SERVER_PORT"]);
2022 +
2023 + $fullUrl = $protocol."://".$_SERVER['SERVER_NAME'].$port.$serverrequri;
2024 +
2025 + return $fullUrl;
2026 + }
2027 +
2028 + /**
1515 2029 * Redirects the user to his destination.
1516 2030 *
2031 + * @param object $object The current object we want to access.
2032 + *
1517 2033 * @return null
1518 2034 */
1519 - function redirectUser()
2035 + public function redirectUser($object = null)
1520 2036 {
1521 2037 global $wp_query;
1522 2038
1523 2039 $postToShow = false;
@@ -1522,11 +2038,13 @@
1522 2038
1523 2039 $postToShow = false;
1524 2040 $posts = $wp_query->get_posts();
1525 2041
1526 - if (isset($posts)) {
2042 + if ($object === null
2043 + && isset($posts)
2044 + ) {
1527 2045 foreach ($posts as $post) {
1528 - if ($this->getAccessHandler()->checkAccess($post->ID)) {
2046 + if ($this->getAccessHandler()->checkObjectAccess($post->post_type, $post->ID)) {
1529 2047 $postToShow = true;
1530 2048 break;
1531 2049 }
1532 2050 }
@@ -1533,9 +2051,9 @@
1533 2051 }
1534 2052
1535 2053 if (!$postToShow) {
1536 2054 $uamOptions = $this->getAdminOptions();
1537 -
2055 +
1538 2056 if ($uamOptions['redirect'] == 'blog') {
1539 2057 $url = home_url('/');
1540 2058 } elseif ($uamOptions['redirect'] == 'custom_page') {
1541 2059 $post = get_post($uamOptions['redirect_custom_page']);
@@ -1542,11 +2060,12 @@
1542 2060 $url = $post->guid;
1543 2061 } elseif ($uamOptions['redirect'] == 'custom_url') {
1544 2062 $url = $uamOptions['redirect_custom_url'];
1545 2063 }
1546 -
1547 - if ($url != "http://".$_SERVER['HTTP_HOST'].$_SERVER["REQUEST_URI"]) {
2064 +
2065 + if ($url != $this->getCurrentUrl()) {
1548 2066 wp_redirect($url);
2067 + exit;
1549 2068 }
1550 2069 }
1551 2070 }
1552 2071
@@ -1552,75 +2071,81 @@
1552 2071
1553 2072 /**
1554 2073 * Delivers the content of the requestet file.
1555 2074 *
1556 - * @param string $url The file url.
2075 + * @param string $objectType The type of the requested file.
2076 + * @param string $objectUrl The file url.
1557 2077 *
1558 2078 * @return null
1559 2079 */
1560 - function getFile($url)
2080 + public function getFile($objectType, $objectUrl)
1561 2081 {
1562 - $post = get_post($this->getAttachmentIdByUrl($url));
2082 + $object = $this->_getFileSettingsByType($objectType, $objectUrl);
1563 2083
1564 - if ($post !== null) {
1565 - $file = null;
1566 - } else {
2084 + if ($object === null) {
1567 2085 return null;
1568 2086 }
1569 2087
1570 - if ($post->post_type == 'attachment'
1571 - && $this->getAccessHandler()->checkAccess($post->ID)
1572 - ) {
1573 - $uploadDir = wp_upload_dir();
1574 - $file = $uploadDir['basedir'].'/'.str_replace(
1575 - $uploadDir['baseurl'],
1576 - '',
1577 - $url
1578 - );
1579 - } else if (wp_attachment_is_image($post->ID)) {
2088 + $file = null;
2089 +
2090 + if ($this->getAccessHandler()->checkObjectAccess($object->type, $object->id)) {
2091 + $file = $object->file;
2092 + } elseif ($object->isImage) {
1580 2093 $file = UAM_REALPATH.'gfx/noAccessPic.png';
1581 2094 } else {
1582 - wp_die(TXT_NO_RIGHTS);
2095 + wp_die(TXT_UAM_NO_RIGHTS);
1583 2096 }
1584 2097
1585 2098 //Deliver content
1586 2099 if (file_exists($file)) {
1587 2100 $fileName = basename($file);
1588 -
1589 - /**
2101 +
2102 + /*
1590 2103 * This only for compatibility
1591 2104 * mime_content_type has been deprecated as the PECL extension Fileinfo
1592 2105 * provides the same functionality (and more) in a much cleaner way.
1593 2106 */
2107 + $ext = strtolower(array_pop(explode('.', $fileName)));
2108 +
1594 2109 if (function_exists('finfo_open')) {
1595 2110 $finfo = finfo_open(FILEINFO_MIME);
1596 -
1597 - if (!$finfo) {
1598 - wp_die(TXT_FILEINFO_DB_ERROR);
1599 - }
1600 -
1601 - $fileType = finfo_file($finfo, $file);
2111 + $fileMimeType = finfo_file($finfo, $file);
2112 + finfo_close($finfo);
2113 + } elseif (function_exists('mime_content_type')) {
2114 + $fileMimeType = mime_content_type($file);
2115 + } elseif (array_key_exists($ext, $this->mimeTypes)) {
2116 + $fileMimeType = $this->mimeTypes[$ext];
1602 2117 } else {
1603 - $fileType = mime_content_type($file);
2118 + $fileMimeType = 'application/octet-stream';
1604 2119 }
1605 2120
1606 2121 header('Content-Description: File Transfer');
1607 - header('Content-Type: '.$fileType);
1608 - header('Content-Length: '.filesize($file));
1609 - header('Content-Transfer-Encoding: binary');
1610 - header('Expires: 0');
2122 + header('Content-Type: '.$fileMimeType);
1611 2123
1612 - if (!wp_attachment_is_image($post->ID)) {
1613 - header('Content-Disposition: attachment; filename='.basename($file));
2124 + if (!$object->isImage) {
2125 + $baseName = str_replace(' ', '_', basename($file));
2126 +
2127 + header('Content-Disposition: attachment; filename="'.$baseName.'"');
1614 2128 }
2129 +
2130 + header('Content-Transfer-Encoding: binary');
2131 + header('Content-Length: '.filesize($file));
1615 2132
2133 + $uamOptions = $this->getAdminOptions();
2134 +
1616 2135 if ($uamOptions['download_type'] == 'fopen'
1617 - && !wp_attachment_is_image($post->ID)
2136 + && !$object->isImage
1618 2137 ) {
1619 - $fp = fopen($file, 'rb');
2138 + $fp = fopen($file, 'r');
1620 2139
2140 + //TODO find better solution (prevent '\n' / '0A')
2141 + ob_clean();
2142 + flush();
2143 +
1621 2144 while (!feof($fp)) {
1622 - set_time_limit(30);
2145 + if (!ini_get('safe_mode')) {
2146 + set_time_limit(30);
2147 + }
1623 2148 $buffer = fread($fp, 1024);
1624 2149 echo $buffer;
1625 2150 }
1626 2151
@@ -1631,13 +2156,74 @@
1631 2156 readfile($file);
1632 2157 exit;
1633 2158 }
1634 2159 } else {
1635 - wp_die(TXT_FILE_NOT_FOUND_ERROR);
2160 + wp_die(TXT_UAM_FILE_NOT_FOUND_ERROR);
1636 2161 }
1637 2162 }
1638 2163
1639 2164 /**
2165 + * Returns the file object by the given type and url.
2166 + *
2167 + * @param string $objectType The type of the requested file.
2168 + * @param string $objectUrl The file url.
2169 + *
2170 + * @return object|null
2171 + */
2172 + private function _getFileSettingsByType($objectType, $objectUrl)
2173 + {
2174 + $object = null;
2175 +
2176 + if ($objectType == 'attachment') {
2177 + $uploadDir = wp_upload_dir();
2178 +
2179 + $multiPath = str_replace(ABSPATH, '/', $uploadDir['basedir']);
2180 + $multiPath = str_replace('/files', $multiPath, $uploadDir['baseurl']);
2181 +
2182 + if ($this->isPermalinksActive()) {
2183 + //TODO Remove if not needed.
2184 + //$objectUrl = $uploadDir['baseurl'].'/'.$objectUrl;
2185 + $objectUrl = $multiPath.'/'.$objectUrl;
2186 + }
2187 +
2188 + $post = get_post($this->getPostIdByUrl($objectUrl));
2189 +
2190 + if ($post !== null
2191 + && $post->post_type == 'attachment'
2192 + ) {
2193 + $object->id = $post->ID;
2194 + $object->isImage = wp_attachment_is_image($post->ID);
2195 + $object->type = $objectType;
2196 +
2197 + //TODO Remove if not needed.
2198 + /*$object->file = $uploadDir['basedir'].str_replace(
2199 + $uploadDir['baseurl'],
2200 + '',
2201 + $objectUrl
2202 + );*/
2203 +
2204 + $object->file = $uploadDir['basedir'].str_replace(
2205 + $multiPath,
2206 + '',
2207 + $objectUrl
2208 + );
2209 + }
2210 + } else {
2211 + $plObject = $this->getAccessHandler()->getPlObject($objectType);
2212 +
2213 + if (isset($plObject)
2214 + && isset($plObject['getFileObject'])
2215 + ) {
2216 + $object = $plObject['reference']->{$plObject['getFileObject']}(
2217 + $objectUrl
2218 + );
2219 + }
2220 + }
2221 +
2222 + return $object;
2223 + }
2224 +
2225 + /**
1640 2226 * Returns the url for a locked file.
1641 2227 *
1642 2228 * @param string $url The base url.
1643 2229 * @param integer $id The id of the file.
@@ -1643,14 +2229,13 @@
1643 2229 * @param integer $id The id of the file.
1644 2230 *
1645 2231 * @return string
1646 2232 */
1647 - function getFileUrl($url, $id)
2233 + public function getFileUrl($url, $id)
1648 2234 {
1649 2235 $uamOptions = $this->getAdminOptions();
1650 - $permaStruc = get_option('permalink_structure');
1651 2236
1652 - if (empty($permaStruc)
2237 + if (!$this->isPermalinksActive()
1653 2238 && $uamOptions['lock_file'] == 'true'
1654 2239 ) {
1655 2240 $post = &get_post($id);
1656 2241
@@ -1661,12 +2246,12 @@
1661 2246 ",",
1662 2247 $uamOptions['locked_file_types']
1663 2248 );
1664 2249
1665 - if (in_array($type, $fileTypes)
1666 - || $uamOptions['lock_file_types'] == 'all'
2250 + if ($uamOptions['lock_file_types'] == 'all'
2251 + || in_array($type, $fileTypes)
1667 2252 ) {
1668 - $url = home_url('/').'?getfile='.$url;
2253 + $url = home_url('/').'?uamfiletype=attachment&uamgetfile='.$url;
1669 2254 }
1670 2255 }
1671 2256
1672 2257 return $url;
@@ -1678,12 +2263,18 @@
1678 2263 * @param string $url The url of the post(attachment).
1679 2264 *
1680 2265 * @return object The post.
1681 2266 */
1682 - function getAttachmentIdByUrl($url)
2267 + public function getPostIdByUrl($url)
1683 2268 {
1684 - //Filter editstring
1685 - $newUrl = preg_split("/-e[0-9]*/", $url);
2269 + if (isset($this->postUrls[$url])) {
2270 + return $this->postUrls[$url];
2271 + }
2272 +
2273 + $this->postUrls[$url] = null;
2274 +
2275 + //Filter edit string
2276 + $newUrl = preg_split("/-e[0-9]{1,}/", $url);
1686 2277
1687 2278 if (count($newUrl) == 2) {
1688 2279 $newUrl = $newUrl[0].$newUrl[1];
1689 2280 } else {
@@ -1690,9 +2281,9 @@
1690 2281 $newUrl = $newUrl[0];
1691 2282 }
1692 2283
1693 2284 //Filter size
1694 - $newUrl = preg_split("/-[0-9]*x[0-9]*/", $newUrl);
2285 + $newUrl = preg_split("/-[0-9]{1,}x[0-9]{1,}/", $newUrl);
1695 2286
1696 2287 if (count($newUrl) == 2) {
1697 2288 $newUrl = $newUrl[0].$newUrl[1];
1698 2289 } else {
@@ -1703,15 +2294,28 @@
1703 2294 $dbPost = $wpdb->get_row(
1704 2295 "SELECT ID
1705 2296 FROM ".$wpdb->prefix."posts
1706 2297 WHERE guid = '" . $newUrl . "'
1707 - LIMIT 1",
1708 - ARRAY_A
2298 + LIMIT 1"
1709 2299 );
1710 2300
1711 2301 if ($dbPost) {
1712 - return $dbPost['ID'];
2302 + $this->postUrls[$url] = $dbPost->ID;
1713 2303 }
1714 2304
1715 - return null;
2305 + return $this->postUrls[$url];
2306 + }
2307 +
2308 + /**
2309 + * Caches the urls for the post for a later lookup.
2310 + *
2311 + * @param string $url The url of the post.
2312 + * @param object $post The post object.
2313 + *
2314 + * @return null
2315 + */
2316 + public function cachePostLinks($url, $post)
2317 + {
2318 + $this->postUrls[$url] = $post->ID;
2319 + return $url;
1716 2320 }
1717 2321 }