PluginProbe
User Access Manager / 2.1.11
User Access Manager v2.1.11
2.3.20 2.3.19 2.3.18 2.3.17 2.3.16 2.3.15 2.3.14 2.3.13 trunk 0.6 0.6.1 0.6.2 0.7 0.7 Beta 0.7.0.1 0.8 0.8.0.1 0.8.0.2 0.9 0.9.1 0.9.1.1 0.9.1.2 0.9.1.3 0.9.1.4 1.0 All 136 releases
← All changes | src/Access/AccessHandler.php +151 -53 2.3.17 → 2.1.11 View file →
@@ -1,65 +1,152 @@
1 1 <?php
2 -
3 -declare(strict_types=1);
4 -
2 +/**
3 + * AccessHandler.php
4 + *
5 + * The AccessHandler class file.
6 + *
7 + * PHP versions 5
8 + *
9 + * @author Alexander Schneider <[email protected]>
10 + * @copyright 2008-2017 Alexander Schneider
11 + * @license http://www.gnu.org/licenses/gpl-2.0.html GNU General Public License, version 2
12 + * @version SVN: $id$
13 + * @link http://wordpress.org/extend/plugins/user-access-manager/
14 + */
5 15 namespace UserAccessManager\Access;
6 16
7 -use Exception;
8 17 use UserAccessManager\Config\MainConfig;
9 18 use UserAccessManager\Database\Database;
10 19 use UserAccessManager\Object\ObjectHandler;
20 +use UserAccessManager\UserGroup\AbstractUserGroup;
11 21 use UserAccessManager\User\UserHandler;
12 -use UserAccessManager\UserGroup\AbstractUserGroup;
13 22 use UserAccessManager\UserGroup\UserGroupHandler;
14 -use UserAccessManager\UserGroup\UserGroupTypeException;
15 23 use UserAccessManager\Wrapper\Wordpress;
16 24
25 +/**
26 + * Class AccessHandler
27 + *
28 + * @package UserAccessManager\AccessHandler
29 + */
17 30 class AccessHandler
18 31 {
19 - private ?array $excludedTerms = null;
20 - private ?array $excludedPosts = null;
21 - private array $objectAccess = [];
22 - private ?array $noneHiddenPostTypes = null;
32 + /**
33 + * @var Wordpress
34 + */
35 + private $wordpress;
23 36
37 + /**
38 + * @var MainConfig
39 + */
40 + private $mainConfig;
41 +
42 + /**
43 + * @var Database
44 + */
45 + private $database;
46 +
47 + /**
48 + * @var ObjectHandler
49 + */
50 + private $objectHandler;
51 +
52 + /**
53 + * @var UserHandler
54 + */
55 + private $userHandler;
56 +
57 + /**
58 + * @var UserGroupHandler
59 + */
60 + private $userGroupHandler;
61 +
62 + /**
63 + * @var null|array
64 + */
65 + private $excludedTerms = null;
66 +
67 + /**
68 + * @var null|array
69 + */
70 + private $excludedPosts = null;
71 +
72 + /**
73 + * @var array
74 + */
75 + private $objectAccess = [];
76 +
77 + /**
78 + * @var null|array
79 + */
80 + private $noneHiddenPostTypes = null;
81 +
82 + /**
83 + * AccessHandler constructor.
84 + *
85 + * @param Wordpress $wordpress
86 + * @param MainConfig $mainConfig
87 + * @param Database $database
88 + * @param ObjectHandler $objectHandler
89 + * @param UserHandler $userHandler
90 + * @param UserGroupHandler $userGroupHandler
91 + */
24 92 public function __construct(
25 - private Wordpress $wordpress,
26 - private MainConfig $mainConfig,
27 - private Database $database,
28 - private ObjectHandler $objectHandler,
29 - private UserHandler $userHandler,
30 - private UserGroupHandler $userGroupHandler
93 + Wordpress $wordpress,
94 + MainConfig $mainConfig,
95 + Database $database,
96 + ObjectHandler $objectHandler,
97 + UserHandler $userHandler,
98 + UserGroupHandler $userGroupHandler
31 99 ) {
100 + $this->wordpress = $wordpress;
101 + $this->mainConfig = $mainConfig;
102 + $this->database = $database;
103 + $this->objectHandler = $objectHandler;
104 + $this->userHandler = $userHandler;
105 + $this->userGroupHandler = $userGroupHandler;
32 106 }
33 107
34 - private function hasAuthorAccess(string $objectType, int|string|null $objectId): bool
108 + /**
109 + * Checks it the user has access because he is the author.
110 + *
111 + * @param string $objectType
112 + * @param string $objectId
113 + *
114 + * @return bool
115 + */
116 + private function hasAuthorAccess($objectType, $objectId)
35 117 {
36 118 if ($this->mainConfig->authorsHasAccessToOwn() === true
37 119 && $this->objectHandler->isPostType($objectType)
38 120 ) {
121 + $currentUser = $this->wordpress->getCurrentUser();
39 122 $post = $this->objectHandler->getPost($objectId);
40 -
41 - if ($post === false) {
42 - return false;
43 - }
44 -
45 - $currentUserId = $this->wordpress->getCurrentUser()->ID;
46 - return $currentUserId !== 0
47 - && $currentUserId === (int) $post->post_author;
123 + return ($post !== false && $currentUser->ID === (int)$post->post_author);
48 124 }
49 125
50 126 return false;
51 127 }
52 128
53 - private function isAdmin(?bool $isAdmin): bool
129 + /**
130 + * Checks if the is admin value is set if not grabs it from the wordpress function.
131 + *
132 + * @param null|bool $isAdmin
133 + *
134 + * @return bool
135 + */
136 + private function isAdmin($isAdmin)
54 137 {
55 138 return ($isAdmin === null) ? $this->wordpress->isAdmin() : $isAdmin;
56 139 }
57 140
58 141 /**
59 - * @throws UserGroupTypeException
142 + * Returns the user user groups filtered by the write access.
143 + *
144 + * @param null|bool $isAdmin If set we force the admin mode.
145 + *
146 + * @return AbstractUserGroup[]
60 147 */
61 - private function getUserUserGroupsForObjectAccess(?bool $isAdmin = null): array
148 + private function getUserUserGroupsForObjectAccess($isAdmin = null)
62 149 {
63 150 $userUserGroups = $this->userGroupHandler->getUserGroupsForUser();
64 151
65 152 if ($this->isAdmin($isAdmin) === true) {
@@ -74,16 +161,22 @@
74 161 return $this->wordpress->applyFilters('uam_get_user_user_groups_for_object_access', $userUserGroups, $isAdmin);
75 162 }
76 163
77 164 /**
78 - * @throws UserGroupTypeException
79 - * @throws Exception
165 + * Checks if the current_user has access to the given post.
166 + *
167 + * @param string $objectType The object type which should be checked.
168 + * @param int $objectId The id of the object.
169 + * @param null|bool $isAdmin If set we force the admin mode.
170 + *
171 + * @return bool
80 172 */
81 - public function checkObjectAccess(?string $objectType, int|string|null $objectId, ?bool $isAdmin = null): bool
173 + public function checkObjectAccess($objectType, $objectId, $isAdmin = null)
82 174 {
83 175 $isAdmin = $this->isAdmin($isAdmin);
176 + $admin = $isAdmin === true ? 'admin' : 'noAdmin';
84 177
85 - if (isset($this->objectAccess[$isAdmin][$objectType][$objectId]) === false) {
178 + if (isset($this->objectAccess[$admin][$objectType][$objectId]) === false) {
86 179 if ($this->objectHandler->isValidObjectType($objectType) === false
87 180 || $this->userHandler->checkUserAccess(UserHandler::MANAGE_USER_GROUPS_CAPABILITY) === true
88 181 || $this->hasAuthorAccess($objectType, $objectId) === true
89 182 ) {
@@ -91,25 +184,25 @@
91 184 } else {
92 185 $membership = $this->userGroupHandler->getUserGroupsForObject($objectType, $objectId);
93 186 $access = $membership === []
94 187 || array_intersect_key($membership, $this->getUserUserGroupsForObjectAccess($isAdmin)) !== [];
95 -
96 - if ($access && $this->wordpress->isUserLoggedIn() && $this->wordpress->isMultiSite()) {
97 - $access = $this->wordpress->isUserMemberOfBlog();
98 - }
99 188 }
100 189
101 - $this->objectAccess[$isAdmin][$objectType][$objectId] = $access;
190 + $this->objectAccess[$admin][$objectType][$objectId] = $access;
102 191 }
103 192
104 - return $this->objectAccess[$isAdmin][$objectType][$objectId];
193 + return $this->objectAccess[$admin][$objectType][$objectId];
105 194 }
106 195
107 196 /**
108 - * @throws UserGroupTypeException
109 - * @throws Exception
197 + * Returns the excluded objects.
198 + *
199 + * @param string $type
200 + * @param array $filterTypesMap
201 + *
202 + * @return array
110 203 */
111 - private function getExcludedObjects(string $type, array $filterTypesMap = []): array
204 + private function getExcludedObjects($type, array $filterTypesMap = [])
112 205 {
113 206 $excludedObjects = [];
114 207 $userGroups = $this->userGroupHandler->getFullUserGroups();
115 208
@@ -136,11 +229,13 @@
136 229 return array_combine($objectIds, $objectIds);
137 230 }
138 231
139 232 /**
140 - * @throws UserGroupTypeException
233 + * Returns the excluded terms for a user.
234 + *
235 + * @return array
141 236 */
142 - public function getExcludedTerms(): ?array
237 + public function getExcludedTerms()
143 238 {
144 239 if ($this->userHandler->checkUserAccess(UserHandler::MANAGE_USER_GROUPS_CAPABILITY)) {
145 240 $this->excludedTerms = [];
146 241 }
@@ -151,9 +246,14 @@
151 246
152 247 return $this->excludedTerms;
153 248 }
154 249
155 - private function getNoneHiddenPostTypes(): ?array
250 + /**
251 + * Returns the none hidden post types map.
252 + *
253 + * @return array
254 + */
255 + private function getNoneHiddenPostTypes()
156 256 {
157 257 if ($this->noneHiddenPostTypes === null) {
158 258 $this->noneHiddenPostTypes = [];
159 259
@@ -171,11 +271,13 @@
171 271 return $this->noneHiddenPostTypes;
172 272 }
173 273
174 274 /**
175 - * @throws UserGroupTypeException
275 + * Returns the excluded posts.
276 + *
277 + * @return array
176 278 */
177 - public function getExcludedPosts(): ?array
279 + public function getExcludedPosts()
178 280 {
179 281 if ($this->userHandler->checkUserAccess(UserHandler::MANAGE_USER_GROUPS_CAPABILITY)) {
180 282 $this->excludedPosts = [];
181 283 }
@@ -185,19 +287,15 @@
185 287 $excludedPosts = $this->getExcludedObjects(ObjectHandler::GENERAL_POST_OBJECT_TYPE, $noneHiddenPostTypes);
186 288
187 289 if ($this->mainConfig->authorsHasAccessToOwn() === true) {
188 290 $query = $this->database->prepare(
189 - "SELECT ID FROM {$this->database->getPostsTable()}
291 + "SELECT ID
292 + FROM {$this->database->getPostsTable()}
190 293 WHERE post_author = %d",
191 294 $this->wordpress->getCurrentUser()->ID
192 295 );
193 296
194 - $ownPosts = array_filter(
195 - (array) $this->database->getResults($query),
196 - function ($ownPost) {
197 - return isset($ownPost->ID);
198 - }
199 - );
297 + $ownPosts = (array)$this->database->getResults($query);
200 298 $ownPostIds = [];
201 299
202 300 foreach ($ownPosts as $ownPost) {
203 301 $ownPostIds[$ownPost->ID] = $ownPost->ID;