25require_once DOL_DOCUMENT_ROOT .
'/core/lib/functions.lib.php';
26require_once DOL_DOCUMENT_ROOT.
'/modulebuilder/class/RightsSyncCommand.class.php';
27require_once DOL_DOCUMENT_ROOT.
'/modulebuilder/class/SyncReport.class.php';
28require_once DOL_DOCUMENT_ROOT.
'/modulebuilder/class/PermissionsBlock.class.php';
54 private const CRUD_LABELS = array(
55 'read' =>
'Read %s object of %s',
56 'write' =>
'Create/Update %s object of %s',
57 'delete' =>
'Delete %s object of %s',
61 private const INDEX_LABEL = 1;
64 private const INDEX_OBJECT = 4;
67 private const INDEX_CRUD = 5;
79 }
catch (\RuntimeException $e) {
80 dol_syslog(
'DescriptorRightsSyncService::sync '.$e->getMessage(), LOG_WARNING);
81 return new SyncReport(0, 0, array($e->getMessage()));
84 $conflicts = array_merge(
85 $block->detectTextConflicts(),
86 $block->detectRightsShapeConflicts($cmd->permissions)
88 if (!empty($conflicts)) {
90 'DescriptorRightsSyncService::sync refused to rewrite '.$cmd->descriptorFile.
': '
91 .implode(
'; ', array_slice($conflicts, 0, 3)),
97 $warnings = $block->detectRightsShapeWarnings($cmd->permissions);
101 }
catch (\InvalidArgumentException $e) {
102 dol_syslog(
'DescriptorRightsSyncService::sync '.$e->getMessage(), LOG_WARNING);
103 return new SyncReport(0, 0, array($e->getMessage()), $warnings);
105 if ($permissions ===
null) {
106 return new SyncReport(0, 1, array(), $warnings);
111 $producedConflicts = $block->detectRightsShapeConflicts($permissions);
112 if (!empty($producedConflicts)) {
114 'DescriptorRightsSyncService::sync refused to write an unusable right into '.$cmd->descriptorFile.
': '
115 .implode(
'; ', array_slice($producedConflicts, 0, 3)),
118 return new SyncReport(0, 0, $producedConflicts, $warnings);
121 $newBlock = $block->render($permissions);
122 if ($block->write($newBlock) < 0) {
123 return new SyncReport(0, 0, array(
'Failed to write the permissions section of '.$cmd->descriptorFile), $warnings);
126 return new SyncReport(substr_count($newBlock,
"\n"), 0, array(), $warnings);
138 $permissions = array_values($cmd->permissions);
140 if ($cmd->scope === RightsSyncCommand::SCOPE_OBJECT) {
141 if ($cmd->actionType === RightsSyncCommand::ACTION_ADD) {
142 return $this->
addObjectRights($permissions, $cmd->module, $cmd->objectName);
147 if ($cmd->actionType === RightsSyncCommand::ACTION_ADD) {
148 return $this->
addRight($permissions, $cmd->objectName, (
string) $cmd->rightLabel, (
string) $cmd->rightCrud);
151 $key = (int) $cmd->rightKey;
152 if (!array_key_exists($key, $permissions)) {
153 throw new \InvalidArgumentException(
'No permission found at index '.$key.
' of the descriptor rights array');
156 if ($cmd->actionType === RightsSyncCommand::ACTION_UPDATE) {
158 $permissions[$key] = array(
159 self::INDEX_LABEL => (
string) $cmd->rightLabel,
161 self::INDEX_CRUD => (
string) $cmd->rightCrud,
166 unset($permissions[$key]);
167 return array_values($permissions);
181 foreach ($permissions as $right) {
182 if (isset($right[self::INDEX_OBJECT]) &&
dol_strtolower((
string) $right[self::INDEX_OBJECT]) === $target) {
187 foreach (self::CRUD_LABELS as $crud => $template) {
188 $permissions[] = array(
190 self::INDEX_OBJECT => $target,
191 self::INDEX_CRUD => $crud,
211 return array_values(array_filter(
217 static function ($right) use ($target) {
218 return !isset($right[self::INDEX_OBJECT]) ||
dol_strtolower((
string) $right[self::INDEX_OBJECT]) !== $target;
233 private function addRight(array $permissions,
string $objectName,
string $label,
string $crud): array
236 foreach ($permissions as $right) {
237 if (isset($right[self::INDEX_OBJECT], $right[self::INDEX_CRUD])
238 &&
dol_strtolower((
string) $right[self::INDEX_OBJECT]) === $target
239 && (
string) $right[self::INDEX_CRUD] === $crud) {
240 throw new \InvalidArgumentException(
'Permission "'.$crud.
'" is already declared for object "'.$objectName.
'"');
244 $permissions[] = array(
245 self::INDEX_LABEL => $label,
246 self::INDEX_OBJECT => $target,
247 self::INDEX_CRUD => $crud,
Syncs rights straight into the mod<Module>.class.php descriptor file.
sync(RightsSyncCommand $cmd)
Apply one sync command to a module descriptor.
addRight(array $permissions, string $objectName, string $label, string $crud)
Append one right, refusing a crud code the object already declares.
applyCommand(RightsSyncCommand $cmd)
Produce the rights array the descriptor should now declare.
removeObjectRights(array $permissions, string $objectName)
Drop every right attached to an object.
addObjectRights(array $permissions, string $module, string $objectName)
Append the three CRUD rights of a freshly generated object.
static fromFile(string $file)
Read a descriptor and locate its permissions block.
Immutable request describing one permissions sync to perform on a module descriptor.
Immutable outcome of a permissions sync run.
if(! $sortfield) if(! $sortorder) $module
dol_ucfirst($string, $encoding="UTF-8")
Convert first character of the first word of a string to upper.
dol_strtolower($string, $encoding="UTF-8")
Convert a string to lower.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
Keeps the permissions section of a module descriptor in sync with ModuleBuilder actions.
sync(RightsSyncCommand $cmd)
Apply one sync command to a module descriptor.