429function restrictedArea(
User $user, $features,
$object = 0, $tableandshare =
'', $feature2 =
'', $dbt_keyfield =
'fk_soc', $dbt_select =
'rowid', $isdraft = 0, $mode = 0)
439 if ($objectid ==
"-1") {
443 $objectid = preg_replace(
'/[^0-9\.\,]/',
'', (
string) $objectid);
452 $parentfortableentity =
'';
456 $originalfeatures = $features;
457 if ($features ==
'agenda') {
458 $tableandshare =
'actioncomm&societe';
459 $feature2 =
'myactions|allactions';
462 if ($features ==
'bank') {
463 $features =
'banque';
465 if ($features ==
'facturerec') {
466 $features =
'facture';
468 if ($features ==
'supplier_invoicerec') {
469 $features =
'fournisseur';
470 $feature2 =
'facture';
472 if ($features ==
'mo') {
475 if ($features ==
'member') {
476 $features =
'adherent';
478 if ($features ==
'subscription') {
479 $features =
'adherent';
480 $feature2 =
'cotisation';
481 $tableandshare =
'subscription&adherent';
482 $parentfortableentity =
'fk_adherent@adherent';
484 if ($features ==
'website' && is_object(
$object) &&
$object->element ==
'websitepage') {
485 $parentfortableentity =
'fk_website@website';
487 if ($features ==
'project') {
488 $features =
'projet';
490 if ($features ==
'product') {
491 $features =
'produit';
493 if ($features ==
'productbatch') {
494 $features =
'produit';
496 if ($features ==
'tax') {
497 $feature2 =
'charges';
499 if ($features ==
'workstation') {
500 $feature2 =
'workstation';
502 if ($features ==
'fournisseur') {
503 $features =
'fournisseur';
504 if (is_object(
$object) &&
$object->element ==
'invoice_supplier') {
505 $feature2 =
'facture';
506 } elseif (is_object(
$object) &&
$object->element ==
'order_supplier') {
507 $feature2 =
'commande';
510 if ($features ==
'payment_sc') {
511 $tableandshare =
'paiementcharge';
512 $parentfortableentity =
'fk_charge@chargesociales';
517 if (in_array($features, [
'commandedet',
'propaldet',
'facturedet',
'supplier_proposaldet',
'evaluationdet',
'skilldet',
'deliverydet',
'contratdet'])) {
518 $features = substr($features, 0, -3);
519 } elseif (in_array($features, [
'stocktransferline',
'inventoryline',
'bomline',
'expensereport_det',
'facture_fourn_det'])) {
520 $features = substr($features, 0, -4);
521 } elseif ($features ==
'commandefournisseurdispatch') {
522 $features =
'commandefournisseur';
523 } elseif ($features ==
'invoice_supplier_det_rec') {
524 $features =
'invoice_supplier_rec';
526 if ($features ==
'evaluation') {
528 $feature2 =
'evaluation';
542 $parameters = array(
'features' => $features,
'originalfeatures' => $originalfeatures,
'objectid' => $objectid,
'dbt_select' => $dbt_select,
'idtype' => $dbt_select,
'isdraft' => $isdraft);
543 if (!empty($hookmanager)) {
544 $reshook = $hookmanager->executeHooks(
'restrictedArea', $parameters);
546 if (isset($hookmanager->resArray[
'result'])) {
547 if ($hookmanager->resArray[
'result'] == 0) {
561 $featuresarray = array($features);
562 if (preg_match(
'/&/', $features)) {
563 $featuresarray = explode(
"&", $features);
564 } elseif (preg_match(
'/\|/', $features)) {
565 $featuresarray = explode(
"|", $features);
569 if (!empty($feature2)) {
570 $feature2 = explode(
"|", $feature2);
578 foreach ($featuresarray as $feature) {
579 $featureforlistofmodule = $feature;
580 if ($featureforlistofmodule ==
'produit') {
581 $featureforlistofmodule =
'product';
583 if ($featureforlistofmodule ==
'supplier_proposal') {
584 $featureforlistofmodule =
'supplierproposal';
586 if (!empty($user->socid) &&
getDolGlobalString(
'MAIN_MODULES_FOR_EXTERNAL') && !in_array($featureforlistofmodule, $listofmodules)) {
592 if ($feature ==
'societe' && (empty($feature2) || !in_array(
'contact', $feature2))) {
593 if (!$user->hasRight(
'societe',
'lire') && !$user->hasRight(
'fournisseur',
'lire')) {
597 } elseif (($feature ==
'societe' && (!empty($feature2) && in_array(
'contact', $feature2))) || $feature ==
'contact') {
598 if (!$user->hasRight(
'societe',
'contact',
'lire')) {
602 } elseif ($feature ==
'produit|service') {
603 if (!$user->hasRight(
'produit',
'lire') && !$user->hasRight(
'service',
'lire')) {
607 } elseif ($feature ==
'prelevement') {
608 if (!$user->hasRight(
'prelevement',
'bons',
'lire')) {
612 } elseif ($feature ==
'cheque') {
613 if (!$user->hasRight(
'banque',
'cheque')) {
617 } elseif ($feature ==
'projet') {
618 if (!$user->hasRight(
'projet',
'lire') && !$user->hasRight(
'projet',
'all',
'lire')) {
622 } elseif ($feature ==
'payment') {
623 if (!$user->hasRight(
'facture',
'lire')) {
627 } elseif ($feature ==
'payment_supplier') {
628 if (!$user->hasRight(
'fournisseur',
'facture',
'lire')) {
632 } elseif ($feature ==
'payment_sc') {
633 if (!$user->hasRight(
'tax',
'charges',
'lire')) {
637 } elseif (!empty($feature2)) {
639 foreach ($feature2 as $subfeature) {
640 if ($subfeature ==
'user' && $user->id == $objectid) {
643 if ($subfeature ==
'fiscalyear' && $user->hasRight(
'accounting',
'fiscalyear',
'write')) {
648 if (!empty($subfeature) && !$user->hasRight($feature, $subfeature,
'lire') && !$user->hasRight($feature, $subfeature,
'read')) {
650 } elseif (empty($subfeature) && !$user->hasRight($feature,
'lire') && !$user->hasRight($feature,
'read')) {
661 } elseif (!empty($feature) && ($feature !=
'user' && $feature !=
'usergroup')) {
662 if (!$user->hasRight($feature,
'lire')
663 && !$user->hasRight($feature,
'read')
664 && !$user->hasRight($feature,
'run')) {
672 if (preg_match(
'/\|/', $features) && $nbko < count($featuresarray)) {
688 $wemustcheckpermissionforcreate = (
GETPOST(
'sendit',
'alpha') ||
GETPOST(
'linkit',
'alpha') || in_array(
GETPOST(
'action',
'aZ09'), array(
'create',
'update',
'set',
'upload',
'add_element_resource',
'confirm_deletebank',
'confirm_delete_linked_resource')) ||
GETPOST(
'roworder',
'alpha', 2));
689 $wemustcheckpermissionfordeletedraft = ((
GETPOST(
"action",
"aZ09") ==
'confirm_delete' &&
GETPOST(
"confirm",
"aZ09") ==
'yes') ||
GETPOST(
"action",
"aZ09") ==
'delete');
691 if ($wemustcheckpermissionforcreate || $wemustcheckpermissionfordeletedraft) {
692 foreach ($featuresarray as $feature) {
693 if ($feature ==
'contact') {
694 if (!$user->hasRight(
'societe',
'contact',
'creer')) {
698 } elseif ($feature ==
'produit|service') {
699 if (!$user->hasRight(
'produit',
'creer') && !$user->hasRight(
'service',
'creer')) {
703 } elseif ($feature ==
'prelevement') {
704 if (!$user->hasRight(
'prelevement',
'bons',
'creer')) {
708 } elseif ($feature ==
'commande_fournisseur') {
709 if (!$user->hasRight(
'fournisseur',
'commande',
'creer') || !$user->hasRight(
'supplier_order',
'creer')) {
713 } elseif ($feature ==
'banque') {
714 if (!$user->hasRight(
'banque',
'modifier')) {
718 } elseif ($feature ==
'cheque') {
719 if (!$user->hasRight(
'banque',
'cheque')) {
723 } elseif ($feature ==
'import') {
724 if (!$user->hasRight(
'import',
'run')) {
728 } elseif ($feature ==
'ecm') {
729 if (!$user->hasRight(
'ecm',
'upload')) {
733 } elseif ($feature ==
'modulebuilder') {
734 if (!$user->hasRight(
'modulebuilder',
'run')) {
738 } elseif (!empty($feature2)) {
739 foreach ($feature2 as $subfeature) {
740 if ($subfeature ==
'user' && $user->id == $objectid && $user->hasRight(
'user',
'self',
'creer')) {
743 if ($subfeature ==
'user' && $user->id == $objectid && $user->hasRight(
'user',
'self',
'password')) {
746 if ($subfeature ==
'user' && $user->id != $objectid && $user->hasRight(
'user',
'user',
'password')) {
750 if (!$user->hasRight($feature, $subfeature,
'creer')
751 && !$user->hasRight($feature, $subfeature,
'write')
752 && !$user->hasRight($feature, $subfeature,
'create')) {
761 } elseif (!empty($feature)) {
763 if (!$user->hasRight($feature,
'creer')
764 && !$user->hasRight($feature,
'write')
765 && !$user->hasRight($feature,
'create')) {
773 if (preg_match(
'/\|/', $features) && $nbko < count($featuresarray)) {
777 if ($wemustcheckpermissionforcreate && !$createok) {
789 if (
GETPOST(
'action',
'aZ09') ==
'confirm_create_user' &&
GETPOST(
"confirm",
'aZ09') ==
'yes') {
790 if (!$user->hasRight(
'user',
'user',
'creer')) {
794 if (!$createuserok) {
807 if ((
GETPOST(
"action",
"aZ09") ==
'confirm_delete' &&
GETPOST(
"confirm",
"aZ09") ==
'yes') ||
GETPOST(
"action",
"aZ09") ==
'delete') {
808 foreach ($featuresarray as $feature) {
809 if ($feature ==
'bookmark') {
810 if (!$user->hasRight(
'bookmark',
'supprimer')) {
811 if ($user->id !=
$object->fk_user || !$user->hasRight(
'bookmark',
'creer')) {
815 } elseif ($feature ==
'contact') {
816 if (!$user->hasRight(
'societe',
'contact',
'supprimer')) {
819 } elseif ($feature ==
'produit|service') {
820 if (!$user->hasRight(
'produit',
'supprimer') && !$user->hasRight(
'service',
'supprimer')) {
823 } elseif ($feature ==
'commande_fournisseur') {
824 if (!$user->hasRight(
'fournisseur',
'commande',
'supprimer')) {
827 } elseif ($feature ==
'payment_supplier') {
828 if (!$user->hasRight(
'fournisseur',
'facture',
'creer')) {
831 } elseif ($feature ==
'payment') {
832 if (!$user->hasRight(
'facture',
'paiement')) {
835 } elseif ($feature ==
'payment_sc') {
836 if (!$user->hasRight(
'tax',
'charges',
'creer')) {
839 } elseif ($feature ==
'banque') {
840 if (!$user->hasRight(
'banque',
'modifier')) {
843 } elseif ($feature ==
'cheque') {
844 if (!$user->hasRight(
'banque',
'cheque')) {
847 } elseif ($feature ==
'ecm') {
848 if (!$user->hasRight(
'ecm',
'upload')) {
851 } elseif ($feature ==
'ftp') {
852 if (!$user->hasRight(
'ftp',
'write')) {
855 } elseif ($feature ==
'salaries') {
856 if (!$user->hasRight(
'salaries',
'delete')) {
859 } elseif ($feature ==
'adherent') {
860 if (!$user->hasRight(
'adherent',
'supprimer')) {
863 } elseif ($feature ==
'paymentbybanktransfer') {
864 if (!$user->hasRight(
'paymentbybanktransfer',
'create')) {
867 } elseif ($feature ==
'prelevement') {
868 if (!$user->hasRight(
'prelevement',
'bons',
'creer')) {
871 } elseif (!empty($feature2)) {
872 foreach ($feature2 as $subfeature) {
873 if (!$user->hasRight($feature, $subfeature,
'supprimer') && !$user->hasRight($feature, $subfeature,
'delete')) {
880 } elseif (!empty($feature)) {
882 if (!$user->hasRight($feature,
'supprimer')
883 && !$user->hasRight($feature,
'delete')
884 && !$user->hasRight($feature,
'run')) {
891 if (preg_match(
'/\|/', $features) && $nbko < count($featuresarray)) {
895 if (!$deleteok && !($isdraft && $createok)) {
907 if (!empty($objectid) && $objectid > 0) {
909 $params = array(
'objectid' => $objectid,
'features' => implode(
',', $featuresarray),
'features2' => $feature2);
940function checkUserAccessToObject($user, array $featuresarray,
$object = 0, $tableandshare =
'', $feature2 =
'', $dbt_keyfield =
'', $dbt_select =
'rowid', $parenttableforentity =
'')
949 $objectid = preg_replace(
'/[^0-9\.\,]/',
'', $objectid);
956 $params = explode(
'&', $tableandshare);
957 $dbtablename = (!empty($params[0]) ? $params[0] :
'');
958 $sharedelement = (!empty($params[1]) ? $params[1] : $dbtablename);
960 foreach ($featuresarray as $feature) {
966 if ($feature ==
'societe' && !empty($feature2) && is_array($feature2) && in_array(
'contact', $feature2)) {
967 $feature =
'contact';
970 if ($feature ==
'member') {
971 $feature =
'adherent';
973 if ($feature ==
'category') {
974 $feature =
'categorie';
976 if ($feature ==
'project') {
979 if ($feature ==
'projet' && !empty($feature2) && is_array($feature2) && !empty(array_intersect(array(
'project_task',
'projet_task'), $feature2))) {
980 $feature =
'project_task';
982 if ($feature ==
'task' || $feature ==
'projet_task') {
983 $feature =
'project_task';
984 $dbtablename =
'projet_task';
986 if ($feature ==
'eventorganization') {
988 $dbtablename =
'actioncomm';
990 if ($feature ==
'payment_sc' && empty($parenttableforentity)) {
992 $parenttableforentity =
'';
993 $dbtablename =
"chargesociales";
994 $feature =
"chargesociales";
995 $objectid =
$object->fk_charge;
998 $checkonentitydone = 0;
1001 $check = array(
'adherent',
'banque',
'bom',
'don',
'mrp',
'user',
'usergroup',
'payment',
'payment_supplier',
'payment_sc',
'product',
'produit',
'service',
'produit|service',
'categorie',
'resource',
'expensereport',
'holiday',
'salaries',
'website',
'recruitment',
'chargesociales',
'knowledgemanagement',
'stock');
1002 $checksoc = array(
'societe');
1003 $checkparentsoc = array(
'agenda',
'contact',
'contrat');
1004 $checkproject = array(
'projet',
'project');
1005 $checktask = array(
'projet_task',
'project_task');
1006 $checkhierarchy = array(
'expensereport',
'holiday',
'hrm');
1007 $checkuser = array(
'bookmark');
1008 $nocheck = array(
'barcode');
1013 if (empty($dbtablename)) {
1014 $dbtablename = $feature;
1015 $sharedelement = (!empty($params[1]) ? $params[1] : $dbtablename);
1019 if ($dbt_select !=
'rowid' && $dbt_select !=
'id') {
1020 $objectid =
"'".$objectid.
"'";
1023 if (in_array($feature, $check) && $objectid > 0) {
1024 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1025 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1026 if (($feature ==
'user' || $feature ==
'usergroup') && isModEnabled(
'multicompany')) {
1028 if (
$conf->entity == 1 && $user->admin && !$user->entity) {
1029 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1030 $sql .=
" AND dbt.entity IS NOT NULL";
1032 $sql .=
",".MAIN_DB_PREFIX.
"usergroup_user as ug";
1033 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1034 $sql .=
" AND ((ug.fk_user = dbt.rowid";
1035 $sql .=
" AND ug.entity IN (".getEntity(
'usergroup').
"))";
1036 $sql .=
" OR dbt.entity = 0)";
1039 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1040 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1044 if ($parenttableforentity && preg_match(
'/(.*)@(.*)/', $parenttableforentity, $reg)) {
1045 $sql .=
", ".MAIN_DB_PREFIX.$reg[2].
" as dbtp";
1046 $sql .=
" WHERE dbt.".$reg[1].
" = dbtp.rowid AND dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1047 $sql .=
" AND dbtp.entity IN (".getEntity($sharedelement, 1).
")";
1049 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1050 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1053 $checkonentitydone = 1;
1055 if (in_array($feature, $checksoc) && $objectid > 0) {
1057 if ($user->socid > 0) {
1058 if ($user->socid != $objectid) {
1061 } elseif (isModEnabled(
'societe') && !$user->hasRight(
'societe',
'lire') && !$user->hasRight(
'societe',
'client',
'voir')) {
1062 dol_syslog(
"security.lib.php::checkUserAccessToObject Deny access due: (isModEnabled('societe') && !user->hasRight('societe', 'lire') && !user->hasRight('societe', 'client', 'voir'))", LOG_DEBUG);
1064 } elseif (isModEnabled(
"societe") && ($user->hasRight(
'societe',
'lire') && !$user->hasRight(
'societe',
'client',
'voir'))) {
1066 $sql =
"SELECT COUNT(sc.fk_soc) as nb";
1067 $sql .=
" FROM (".MAIN_DB_PREFIX.
"societe_commerciaux as sc";
1068 $sql .=
", ".MAIN_DB_PREFIX.
"societe as s)";
1069 $sql .=
" WHERE sc.fk_soc IN (".$db->sanitize($objectid, 1).
")";
1070 $sql .=
" AND (sc.fk_user = ".((int) $user->id);
1072 $userschilds = $user->getAllChildIds();
1073 if (!empty($userschilds)) $sql .=
" OR sc.fk_user IN (".$db->sanitize(implode(
',', $userschilds)).
")";
1076 $sql .=
" AND sc.fk_soc = s.rowid";
1077 $sql .=
" AND s.entity IN (".getEntity($sharedelement, 1).
")";
1078 } elseif (isModEnabled(
'multicompany')) {
1080 $sql =
"SELECT COUNT(s.rowid) as nb";
1081 $sql .=
" FROM ".MAIN_DB_PREFIX.
"societe as s";
1082 $sql .=
" WHERE s.rowid IN (".$db->sanitize($objectid, 1).
")";
1083 $sql .=
" AND s.entity IN (".getEntity($sharedelement, 1).
")";
1086 $checkonentitydone = 1;
1088 if (in_array($feature, $checkparentsoc) && $objectid > 0) {
1090 if ($user->socid > 0) {
1091 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1092 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1093 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1094 $sql .=
" AND dbt.fk_soc = ".((int) $user->socid);
1095 } elseif (isModEnabled(
"societe") && ($user->hasRight(
'societe',
'lire') && !$user->hasRight(
'societe',
'client',
'voir'))) {
1097 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1098 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1099 $sql .=
" LEFT JOIN ".MAIN_DB_PREFIX.
"societe_commerciaux as sc ON dbt.fk_soc = sc.fk_soc AND sc.fk_user = ".((int) $user->id);
1100 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1101 $sql .=
" AND (dbt.fk_soc IS NULL OR sc.fk_soc IS NOT NULL)";
1102 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1103 } elseif (isModEnabled(
'multicompany')) {
1105 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1106 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1107 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1108 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1111 $checkonentitydone = 1;
1113 if (in_array($feature, $checkproject) && $objectid > 0) {
1114 if (isModEnabled(
'project') && !$user->hasRight(
'projet',
'all',
'lire')) {
1115 $projectid = $objectid;
1117 include_once DOL_DOCUMENT_ROOT.
'/projet/class/project.class.php';
1118 $projectstatic =
new Project($db);
1119 $tmps = $projectstatic->getProjectsAuthorizedForUser($user, 0, 1, 0);
1121 $tmparray = explode(
',', $tmps);
1122 if (!in_array($projectid, $tmparray)) {
1126 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1127 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1128 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1129 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1131 $checkonentitydone = 1;
1133 if (in_array($feature, $checktask) && (
int) $objectid > 0) {
1134 if (isModEnabled(
'project') && !$user->hasRight(
'projet',
'all',
'lire')) {
1135 $task =
new Task($db);
1136 $task->fetch((
int) $objectid);
1137 $projectid = $task->fk_project;
1139 include_once DOL_DOCUMENT_ROOT.
'/projet/class/project.class.php';
1140 $projectstatic =
new Project($db);
1141 $tmps = $projectstatic->getProjectsAuthorizedForUser($user, 0, 1, 0);
1143 $tmparray = explode(
',', $tmps);
1144 if (!in_array($projectid, $tmparray)) {
1148 $sharedelement =
'project';
1149 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1150 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1151 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1152 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1155 $checkonentitydone = 1;
1159 if (!$checkonentitydone && !in_array($feature, $nocheck) && $objectid > 0) {
1161 if ($user->socid > 0) {
1162 if (empty($dbt_keyfield)) {
1163 dol_print_error(
null,
'Param dbt_keyfield is required but not defined');
1165 $sql =
"SELECT COUNT(dbt.".$dbt_keyfield.
") as nb";
1166 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1167 $sql .=
" WHERE dbt.rowid IN (".$db->sanitize($objectid, 1).
")";
1168 $sql .=
" AND dbt.".$dbt_keyfield.
" = ".((int) $user->socid);
1169 } elseif (isModEnabled(
"societe") && !$user->hasRight(
'societe',
'client',
'voir')) {
1171 if ($feature !=
'ticket') {
1172 if (empty($dbt_keyfield)) {
1173 dol_print_error(
null,
'Param dbt_keyfield is required but not defined');
1175 $sql =
"SELECT COUNT(sc.fk_soc) as nb";
1176 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1177 $sql .=
", ".MAIN_DB_PREFIX.
"societe_commerciaux as sc";
1178 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1179 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1180 $sql .=
" AND sc.fk_soc = dbt.".$dbt_keyfield;
1181 $sql .=
" AND (sc.fk_user = ".((int) $user->id);
1183 $userschilds = $user->getAllChildIds();
1184 if (!empty($userschilds)) $sql .=
" OR sc.fk_user IN (".$db->sanitize(implode(
',', $userschilds)).
")";
1189 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1190 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1191 $sql .=
" LEFT JOIN ".MAIN_DB_PREFIX.
"societe_commerciaux as sc ON sc.fk_soc = dbt.".$dbt_keyfield.
" AND sc.fk_user = ".((int) $user->id);
1192 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1193 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1194 $sql .=
" AND (sc.fk_user = ".((int) $user->id).
" OR sc.fk_user IS NULL)";
1196 } elseif (isModEnabled(
'multicompany') && (!empty(
$object->ismultientitymanaged) || !isset(
$object->ismultientitymanaged))) {
1198 $sql =
"SELECT COUNT(dbt.".$dbt_select.
") as nb";
1199 $sql .=
" FROM ".MAIN_DB_PREFIX.$dbtablename.
" as dbt";
1200 $sql .=
" WHERE dbt.".$dbt_select.
" IN (".$db->sanitize($objectid, 1).
")";
1201 $sql .=
" AND dbt.entity IN (".getEntity($sharedelement, 1).
")";
1206 if ($feature ===
'agenda' && ((
int) $objectid) > 0) {
1208 if ( !$user->hasRight(
'agenda',
'allactions',
'read')) {
1209 require_once DOL_DOCUMENT_ROOT.
'/comm/action/class/actioncomm.class.php';
1211 $action->fetch((
int) $objectid);
1212 if ($action->authorid != $user->id && $action->userownerid != $user->id && !(array_key_exists($user->id, $action->userassigned))) {
1220 if (in_array($feature, $checkhierarchy) && is_object(
$object) && $objectid > 0) {
1221 $childids = $user->getAllChildIds(1);
1223 if ($feature ==
'holiday') {
1224 $useridtocheck =
$object->fk_user;
1225 if (!$user->hasRight(
'holiday',
'readall') && !in_array($useridtocheck, $childids) && !in_array(
$object->fk_validator, $childids)) {
1229 if ($feature ==
'expensereport') {
1230 $useridtocheck =
$object->fk_user_author;
1231 if (!$user->hasRight(
'expensereport',
'readall')) {
1232 if (!in_array($useridtocheck, $childids)) {
1237 if ($feature ==
'hrm' && in_array(
'evaluation', $feature2)) {
1238 $useridtocheck =
$object->fk_user;
1240 if ($user->hasRight(
'hrm',
'evaluation',
'readall')) {
1244 if (!$user->hasRight(
'hrm',
'evaluation',
'read')) {
1249 return in_array($useridtocheck, $childids);
1255 if (in_array($feature, $checkuser) && is_object(
$object) && $objectid > 0) {
1256 $useridtocheck =
$object->fk_user;
1257 if (!empty($useridtocheck) && $useridtocheck > 0 && $useridtocheck != $user->id && empty($user->admin)) {
1263 if ($feature ==
'contact' && in_array($dbtablename, array(
'socpeople',
'contact')) && !empty($objectid)) {
1264 $sqlpriv =
"SELECT COUNT(dbt.rowid) as nb";
1265 $sqlpriv .=
" FROM ".MAIN_DB_PREFIX.
"socpeople as dbt";
1266 $sqlpriv .=
" WHERE dbt.rowid IN (".$db->sanitize($objectid, 1).
")";
1267 $sqlpriv .=
" AND dbt.priv = 1 AND (dbt.fk_user_creat IS NULL OR dbt.fk_user_creat <> ".((int) $user->id).
")";
1268 $resqlpriv = $db->query($sqlpriv);
1272 $objpriv = $db->fetch_object($resqlpriv);
1273 if ($objpriv && $objpriv->nb > 0) {
1279 $resql = $db->query($sql);
1281 $obj = $db->fetch_object($resql);
1282 if (!$obj || $obj->nb < count(explode(
',', $objectid))) {
1286 dol_syslog(
"Bad forged sql in security.lib.php::checkUserAccessToObject", LOG_WARNING);
1292 dol_syslog(
"security.lib.php::checkUserAccessToObject::return True", LOG_DEBUG);
if(!defined( 'NOREQUIREMENU')) if(!empty(GETPOST('seteventmessages', 'alpha'))) if(!function_exists("llxHeader")) top_httphead($contenttype='text/html', $forcenocache=0)
Show HTTP header.