AdminObjectAclManipulator.php 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290
  1. <?php
  2. /*
  3. * This file is part of the Sonata project.
  4. *
  5. * (c) Thomas Rabaix <thomas.rabaix@sonata-project.org>
  6. *
  7. * For the full copyright and license information, please view the LICENSE
  8. * file that was distributed with this source code.
  9. */
  10. namespace Sonata\AdminBundle\Util;
  11. use Sonata\AdminBundle\Form\Type\AclMatrixType;
  12. use Symfony\Component\Form\Form;
  13. use Symfony\Component\Form\FormBuilderInterface;
  14. use Symfony\Component\Form\FormFactoryInterface;
  15. use Symfony\Component\Security\Acl\Domain\ObjectIdentity;
  16. use Symfony\Component\Security\Acl\Domain\RoleSecurityIdentity;
  17. use Symfony\Component\Security\Acl\Exception\NoAceFoundException;
  18. use Symfony\Component\Security\Acl\Domain\UserSecurityIdentity;
  19. use Symfony\Component\Security\Core\User\UserInterface;
  20. /**
  21. * A manipulator for updating ACL related to an object.
  22. *
  23. * @author Kévin Dunglas <kevin@les-tilleuls.coop>
  24. * @author Baptiste Meyer <baptiste@les-tilleuls.coop>
  25. */
  26. class AdminObjectAclManipulator
  27. {
  28. const ACL_USERS_FORM_NAME = 'acl_users_form';
  29. const ACL_ROLES_FORM_NAME = 'acl_roles_form';
  30. /**
  31. * @var \Symfony\Component\Form\FormFactoryInterface
  32. */
  33. protected $formFactory;
  34. /**
  35. * @var string
  36. */
  37. protected $maskBuilderClass;
  38. /**
  39. * @param \Symfony\Component\Form\FormFactoryInterface $formFactory
  40. * @param string $maskBuilderClass
  41. */
  42. public function __construct(FormFactoryInterface $formFactory, $maskBuilderClass)
  43. {
  44. $this->formFactory = $formFactory;
  45. $this->maskBuilderClass = $maskBuilderClass;
  46. }
  47. /**
  48. * Gets mask builder class name
  49. *
  50. * @return string
  51. */
  52. public function getMaskBuilderClass()
  53. {
  54. return $this->maskBuilderClass;
  55. }
  56. /**
  57. * Gets the form
  58. *
  59. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  60. * @return \Symfony\Component\Form\Form
  61. *
  62. * @deprecated Deprecated since version 2.4. Use createAclUsersForm() instead.
  63. */
  64. public function createForm(AdminObjectAclData $data)
  65. {
  66. trigger_error('createForm() is deprecated since version 2.4. Use createAclUsersForm() instead.', E_USER_DEPRECATED);
  67. return $this->createAclUsersForm($data);
  68. }
  69. /**
  70. * Gets the ACL users form
  71. *
  72. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  73. * @return \Symfony\Component\Form\Form
  74. */
  75. public function createAclUsersForm(AdminObjectAclData $data)
  76. {
  77. $aclValues = $data->getAclUsers();
  78. $formBuilder = $this->formFactory->createNamedBuilder(self::ACL_USERS_FORM_NAME, 'form');
  79. $form = $this->buildForm($data, $formBuilder, $aclValues);
  80. $data->setAclUsersForm($form);
  81. return $form;
  82. }
  83. /**
  84. * Gets the ACL roles form
  85. *
  86. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  87. * @return \Symfony\Component\Form\Form
  88. */
  89. public function createAclRolesForm(AdminObjectAclData $data)
  90. {
  91. $aclValues = $data->getAclRoles();
  92. $formBuilder = $this->formFactory->createNamedBuilder(self::ACL_ROLES_FORM_NAME, 'form');
  93. $form = $this->buildForm($data, $formBuilder, $aclValues);
  94. $data->setAclRolesForm($form);
  95. return $form;
  96. }
  97. /**
  98. * Updates ACL users
  99. *
  100. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  101. */
  102. public function updateAclUsers(AdminObjectAclData $data)
  103. {
  104. $aclValues = $data->getAclUsers();
  105. $form = $data->getAclUsersForm();
  106. $this->buildAcl($data, $form, $aclValues);
  107. }
  108. /**
  109. * Updates ACL roles
  110. *
  111. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  112. */
  113. public function updateAclRoles(AdminObjectAclData $data)
  114. {
  115. $aclValues = $data->getAclRoles();
  116. $form = $data->getAclRolesForm();
  117. $this->buildAcl($data, $form, $aclValues);
  118. }
  119. /**
  120. * Updates ACl
  121. *
  122. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  123. *
  124. * @deprecated Deprecated since version 2.4. Use updateAclUsers() instead.
  125. */
  126. public function updateAcl(AdminObjectAclData $data)
  127. {
  128. trigger_error('updateAcl() is deprecated since version 2.4. Use updateAclUsers() instead.', E_USER_DEPRECATED);
  129. $this->updateAclUsers($data);
  130. }
  131. /**
  132. * Builds ACL
  133. *
  134. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  135. * @param \Symfony\Component\Form\Form $form
  136. * @param \Traversable $aclValues
  137. */
  138. protected function buildAcl(AdminObjectAclData $data, Form $form, \Traversable $aclValues)
  139. {
  140. $masks = $data->getMasks();
  141. $acl = $data->getAcl();
  142. $matrices = $form->getData();
  143. foreach ($aclValues as $aclValue) {
  144. foreach ($matrices as $key => $matrix) {
  145. if ($aclValue instanceof UserInterface) {
  146. if (array_key_exists('user', $matrix) && $aclValue->getUsername() === $matrix['user']) {
  147. $matrices[$key]['acl_value'] = $aclValue;
  148. }
  149. } elseif (array_key_exists('role', $matrix) && $aclValue === $matrix['role']) {
  150. $matrices[$key]['acl_value'] = $aclValue;
  151. }
  152. }
  153. }
  154. foreach ($matrices as $matrix) {
  155. if (!isset($matrix['acl_value'])) {
  156. continue;
  157. }
  158. $securityIdentity = $this->getSecurityIdentity($matrix['acl_value']);
  159. $maskBuilder = new $this->maskBuilderClass();
  160. foreach ($data->getUserPermissions() as $permission) {
  161. if (isset($matrix[$permission]) && $matrix[$permission] === true) {
  162. $maskBuilder->add($permission);
  163. }
  164. }
  165. // Restore OWNER and MASTER permissions
  166. if (!$data->isOwner()) {
  167. foreach ($data->getOwnerPermissions() as $permission) {
  168. if ($acl->isGranted(array($masks[$permission]), array($securityIdentity))) {
  169. $maskBuilder->add($permission);
  170. }
  171. }
  172. }
  173. $mask = $maskBuilder->get();
  174. $index = null;
  175. $ace = null;
  176. foreach ($acl->getObjectAces() as $currentIndex => $currentAce) {
  177. if ($currentAce->getSecurityIdentity()->equals($securityIdentity)) {
  178. $index = $currentIndex;
  179. $ace = $currentAce;
  180. break;
  181. }
  182. }
  183. if ($ace) {
  184. $acl->updateObjectAce($index, $mask);
  185. } else {
  186. $acl->insertObjectAce($securityIdentity, $mask);
  187. }
  188. }
  189. $data->getSecurityHandler()->updateAcl($acl);
  190. }
  191. /**
  192. * Builds the form
  193. *
  194. * @param \Sonata\AdminBundle\Util\AdminObjectAclData $data
  195. * @param \Symfony\Component\Form\FormBuilderInterface $formBuilder
  196. * @param \Traversable $aclValues
  197. * @return \Symfony\Component\Form\Form
  198. */
  199. protected function buildForm(AdminObjectAclData $data, FormBuilderInterface $formBuilder, \Traversable $aclValues)
  200. {
  201. // Retrieve object identity
  202. $objectIdentity = ObjectIdentity::fromDomainObject($data->getObject());
  203. $acl = $data->getSecurityHandler()->getObjectAcl($objectIdentity);
  204. if (!$acl) {
  205. $acl = $data->getSecurityHandler()->createAcl($objectIdentity);
  206. }
  207. $data->setAcl($acl);
  208. $masks = $data->getMasks();
  209. $securityInformation = $data->getSecurityInformation();
  210. foreach ($aclValues as $key => $aclValue) {
  211. $securityIdentity = $this->getSecurityIdentity($aclValue);
  212. $permissions = array();
  213. foreach ($data->getUserPermissions() as $permission) {
  214. try {
  215. $checked = $acl->isGranted(array($masks[$permission]), array($securityIdentity));
  216. } catch (NoAceFoundException $e) {
  217. $checked = false;
  218. }
  219. $attr = array();
  220. if (
  221. self::ACL_ROLES_FORM_NAME === $formBuilder->getName()
  222. && isset($securityInformation[$aclValue])
  223. && array_search($permission, $securityInformation[$aclValue]) !== false
  224. ) {
  225. $attr['disabled'] = 'disabled';
  226. }
  227. $permissions[$permission] = array(
  228. 'required' => false,
  229. 'data' => $checked,
  230. 'disabled' => array_key_exists('disabled', $attr),
  231. 'attr' => $attr,
  232. );
  233. }
  234. $formBuilder->add($key, new AclMatrixType(), array('permissions' => $permissions, 'acl_value' => $aclValue));
  235. }
  236. return $formBuilder->getForm();
  237. }
  238. /**
  239. * Gets a user or a role security identity
  240. *
  241. * @param string|\Symfony\Component\Security\Core\User\UserInterface $aclValue
  242. * @return \Symfony\Component\Security\Acl\Domain\RoleSecurityIdentity|\Symfony\Component\Security\Acl\Domain\UserSecurityIdentity
  243. */
  244. protected function getSecurityIdentity($aclValue)
  245. {
  246. return ($aclValue instanceof UserInterface)
  247. ? UserSecurityIdentity::fromAccount($aclValue)
  248. : new RoleSecurityIdentity($aclValue)
  249. ;
  250. }
  251. }