Skip to content

Commit d414d91

Browse files
committed
created unityperms.php
1 parent bf2e212 commit d414d91

4 files changed

Lines changed: 420 additions & 68 deletions

File tree

‎resources/lib/UnityPerms.php‎

Lines changed: 123 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,123 @@
1+
<?php
2+
3+
namespace UnityWebPortal\lib;
4+
5+
class UnityPerms
6+
{
7+
private $SQL;
8+
private $USER;
9+
10+
public function __construct($SQL, $USER)
11+
{
12+
$this->SQL = $SQL;
13+
$this->USER = $USER;
14+
}
15+
16+
public function checkApproveUser($uid, $operated_on, $group)
17+
{
18+
if (!$this->USER->isInGroup($uid, $group)) {
19+
return false;
20+
}
21+
22+
$role = $this->SQL->getRole($uid, $group);
23+
24+
if ($this->SQL->hasPermission($role, 'unity.admin') || $this->SQL->hasPermission($role, 'unity.admin_no_grant')) {
25+
return true;
26+
}
27+
28+
if (!$this->SQL->hasPermission($role, 'unity.approve_user')) {
29+
return false;
30+
}
31+
32+
$operated_on_role = $this->SQL->getRole($operated_on, $group);
33+
34+
if ($this->SQL->getPriority($operated_on_role) >= $this->SQL->getPriority($role)) {
35+
return false;
36+
}
37+
38+
return true;
39+
}
40+
41+
public function checkDenyUser($uid, $operated_on, $group)
42+
{
43+
if (!$this->USER->isInGroup($uid, $group)) {
44+
return false;
45+
}
46+
47+
$role = $this->SQL->getRole($uid, $group);
48+
49+
if ($this->SQL->hasPermission($role, 'unity.admin') || $this->SQL->hasPermission($role, 'unity.admin_no_grant')) {
50+
return true;
51+
}
52+
53+
if (!$this->SQL->hasPermission($role, 'unity.deny_user')) {
54+
return false;
55+
}
56+
57+
$operated_on_role = $this->SQL->getRole($operated_on, $group);
58+
59+
if ($this->SQL->getPriority($operated_on_role) >= $this->SQL->getPriority($role)) {
60+
return false;
61+
}
62+
63+
return true;
64+
}
65+
66+
public function checkGrantRole($uid, $group, $role)
67+
{
68+
if (!$this->USER->isInGroup($uid, $group)) {
69+
return false;
70+
}
71+
72+
if (!$this->SQL->roleAvailableInGroup($uid, $group, $role)) {
73+
return false;
74+
}
75+
76+
$user_role = $this->SQL->getRole($uid, $group);
77+
78+
if ($this->SQL->hasPermission($user_role, 'unity.admin') || $this->SQL->hasPermission($user_role, 'unity.admin_no_grant')) {
79+
return true;
80+
}
81+
82+
if (!$this->SQL->hasPermission($user_role, 'unity.grant_role')) {
83+
return false;
84+
}
85+
86+
$role_to_grant = $this->SQL->getRole($role, $group);
87+
88+
if ($this->SQL->getPriority($role_to_grant) >= $this->SQL->getPriority($user_role)) {
89+
return false;
90+
}
91+
92+
return true;
93+
}
94+
95+
public function checkRevokeRole($uid, $group, $role)
96+
{
97+
if (!$this->USER->isInGroup($uid, $group)) {
98+
return false;
99+
}
100+
101+
if (!$this->SQL->roleAvailableInGroup($uid, $group, $role)) {
102+
return false;
103+
}
104+
105+
$user_role = $this->SQL->getRole($uid, $group);
106+
107+
if ($this->SQL->hasPermission($user_role, 'unity.admin') || $this->SQL->hasPermission($user_role, 'unity.admin_no_grant')) {
108+
return true;
109+
}
110+
111+
if (!$this->SQL->hasPermission($user_role, 'unity.revoke_role')) {
112+
return false;
113+
}
114+
115+
$role_to_revoke = $this->SQL->getRole($role, $group);
116+
117+
if ($this->SQL->getPriority($role_to_revoke) >= $this->SQL->getPriority($user_role)) {
118+
return false;
119+
}
120+
121+
return true;
122+
}
123+
}

‎resources/lib/UnitySQL.php‎

Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,12 @@ class UnitySQL
1414
private const TABLE_AUDIT_LOG = "audit_log";
1515
private const TABLE_ACCOUNT_DELETION_REQUESTS = "account_deletion_requests";
1616
private const TABLE_SITEVARS = "sitevars";
17+
private const TABLE_GROUP_ROLES = "groupRoles";
18+
private const TABLE_GROUP_TYPES = "groupTypes";
19+
private const TABLE_GROUP_ROLE_ASSIGNMENTS = "groupRoleAssignments";
20+
private const TABLE_GROUP_REQUESTS = "groupRequests";
21+
private const TABLE_GROUP_JOIN_REQUESTS = "groupJoinRequests";
22+
1723

1824
private const REQUEST_ADMIN = "admin";
1925

@@ -299,4 +305,70 @@ public function updateSiteVar($name, $value)
299305

300306
$stmt->execute();
301307
}
308+
309+
public function getRole($uid, $group)
310+
{
311+
$stmt = $this->conn->prepare(
312+
"SELECT * FROM " . self::TABLE_GROUP_ROLE_ASSIGNMENTS . " WHERE user=:uid AND `group`=:group"
313+
);
314+
$stmt->bindParam(":uid", $uid);
315+
$stmt->bindParam(":group", $group);
316+
317+
$stmt->execute();
318+
319+
return $stmt->fetchAll()[0]['role'];
320+
}
321+
322+
public function hasPermission($role, $perm)
323+
{
324+
$stmt = $this->conn->prepare(
325+
"SELECT * FROM " . self::TABLE_GROUP_ROLES . " WHERE slug=:role"
326+
);
327+
$stmt->bindParam(":role", $role);
328+
329+
$stmt->execute();
330+
331+
$row = $stmt->fetchAll()[0];
332+
$perms = explode(",", $row['perms']);
333+
return in_array($perm, $perms);
334+
}
335+
336+
public function getPriority($role)
337+
{
338+
$stmt = $this->conn->prepare(
339+
"SELECT * FROM " . self::TABLE_GROUP_ROLES . " WHERE slug=:role"
340+
);
341+
$stmt->bindParam(":role", $role);
342+
343+
$stmt->execute();
344+
345+
$row = $stmt->fetchAll()[0];
346+
return $row['priority'];
347+
}
348+
349+
public function roleAvailableInGroup($uid, $group, $role)
350+
{
351+
$stmt = $this->conn->prepare(
352+
"SELECT * FROM " . self::TABLE_GROUP_ROLE_ASSIGNMENTS . " WHERE user=:uid AND `group`=:group"
353+
);
354+
$stmt->bindParam(":uid", $uid);
355+
$stmt->bindParam(":group", $group);
356+
357+
$stmt->execute();
358+
$row = $stmt->fetchAll()[0];
359+
360+
$group_slug = $row['group'];
361+
362+
$stmt = $this->conn->prepare(
363+
"SELECT * FROM " . self::TABLE_GROUP_TYPES . " WHERE slug=:slug"
364+
);
365+
366+
$stmt->bindParam(":slug", $group_slug);
367+
$stmt->execute();
368+
369+
$row = $stmt->fetchAll()[0];
370+
$roles = explode(",", $row['roles']);
371+
372+
return in_array($role, $roles);
373+
}
302374
}

‎resources/lib/UnityUser.php‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -671,4 +671,22 @@ public function hasRequestedAccountDeletion()
671671
{
672672
return $this->SQL->accDeletionRequestExists($this->getUID());
673673
}
674+
675+
/**
676+
* Checks whether a user is in a group or not
677+
*/
678+
679+
public function isInGroup($uid, $group)
680+
{
681+
$group = new UnityGroup(
682+
$group,
683+
$this->LDAP,
684+
$this->SQL,
685+
$this->MAILER,
686+
$this->REDIS,
687+
$this->WEBHOOK
688+
);
689+
690+
return in_array($uid, $group->getGroupMemberUIDs());
691+
}
674692
}

0 commit comments

Comments
 (0)