index 9ceefc964318b6a2d37c606be882ca94e8ab27cf..2c46e9efcd63f72ca88a5fe53b5824f4845b36e5 100644 (file)
/* get acl's an put them into the userinfo object
attr subtreeACL (userdn:components, userdn:component1#sub1#sub2,component2,...) */
/* get acl's an put them into the userinfo object
attr subtreeACL (userdn:components, userdn:component1#sub1#sub2,component2,...) */
- function userinfo($config, $userdn){
- $this->config= $config;
+ function userinfo(&$config, $userdn){
+ $this->config= &$config;
$ldap= $this->config->get_ldap_link();
$ldap->cat($userdn,array('sn', 'givenName', 'uid', 'gidNumber', 'preferredLanguage', 'gosaUnitTag'));
$attrs= $ldap->fetch();
$ldap= $this->config->get_ldap_link();
$ldap->cat($userdn,array('sn', 'givenName', 'uid', 'gidNumber', 'preferredLanguage', 'gosaUnitTag'));
$attrs= $ldap->fetch();
$this->dn= $userdn;
$this->uid= $attrs['uid'][0];
$this->ip= $_SERVER['REMOTE_ADDR'];
$this->dn= $userdn;
$this->uid= $attrs['uid'][0];
$this->ip= $_SERVER['REMOTE_ADDR'];
+
+ /* Initialize ACL_CACHE */
+ $_SESSION['ACL_CACHE']= array();
+ $this->reset_acl_cache();
}
}
+ public function reset_acl_cache()
+ {
+ /* Initialize ACL_CACHE */
+ $_SESSION['ACL_CACHE']= array();
+ }
+
function loadACL()
{
$this->ACL= array();
$this->groups= array();
$this->result_cache =array();
function loadACL()
{
$this->ACL= array();
$this->groups= array();
$this->result_cache =array();
+ $this->reset_acl_cache();
$ldap= $this->config->get_ldap_link();
$ldap->cd($this->config->current['BASE']);
$ldap= $this->config->get_ldap_link();
$ldap->cd($this->config->current['BASE']);
$aclc[$attrs['dn']]= $ol;
}
$aclc[$attrs['dn']]= $ol;
}
+ /* Resolve roles here.
+ */
+ foreach($aclc as $dn => $data){
+ foreach($data as $prio => $aclc_value) {
+ if($aclc_value['type'] == "role"){
+
+ unset($aclc[$dn][$prio]);
+
+ $ldap->cat($aclc_value['acl'],array("gosaAclTemplate"));
+ $attrs = $ldap->fetch();
+
+ if(isset($attrs['gosaAclTemplate'])){
+ for($i= 0; $i<$attrs['gosaAclTemplate']['count']; $i++){
+ $tmp = @acl::explodeAcl($attrs['gosaAclTemplate'][$i]);
+
+ foreach($tmp as $new_acl){
+ $new_acl['members'] = $aclc_value['members'];
+ $aclc[$dn][] =$new_acl;
+ }
+ }
+ }
+ }
+ }
+ }
+
/* ACL's read, sort for tree depth */
asort($aclp);
/* ACL's read, sort for tree depth */
asort($aclp);
function get_permissions($dn, $object, $attribute= "", $skip_write= FALSE)
{
function get_permissions($dn, $object, $attribute= "", $skip_write= FALSE)
{
+ /* Push cache answer? */
+ if (isset($_SESSION['ACL_CACHE']["$dn+$object+$attribute"])){
+ return ($_SESSION['ACL_CACHE']["$dn+$object+$attribute"]);
+ }
+
$acl= array("r" => "", "w" => "", "c" => "", "d" => "", "m" => "", "a" => "");
/* Build dn array */
$acl= array("r" => "", "w" => "", "c" => "", "d" => "", "m" => "", "a" => "");
/* Build dn array */
$ret= preg_replace('/w/', '', $ret);
}
$ret= preg_replace('/w/', '', $ret);
}
+ $_SESSION['ACL_CACHE']["$dn+$object+$attribute"]= $ret;
return ($ret);
}
return ($ret);
}
function mergeACL($acl, $type, $newACL)
{
function mergeACL($acl, $type, $newACL)
{
- if(preg_match("/w/",$newACL) && !preg_match("/r/",$newACL)){
+ if (strpos($newACL, 'w') !== FALSE && strpos($newACL, 'r') === FALSE){
$newACL .= "r";
}
$newACL .= "r";
}
+
foreach(str_split($newACL) as $char){
/* Ignore invalid characters */
foreach(str_split($newACL) as $char){
/* Ignore invalid characters */
function cleanACL($acl, $reset= FALSE)
{
function cleanACL($acl, $reset= FALSE)
{
- foreach ($acl as $key => $value){
+ foreach ($acl as &$value){
/* Reset removes everything but 'p' */
if ($reset && $value != 'p'){
/* Reset removes everything but 'p' */
if ($reset && $value != 'p'){
- $acl[$key]= "";
+ $value= "";
continue;
}
/* Decrease tree level */
continue;
}
/* Decrease tree level */
- if (preg_match('/^[0-9]+$/', $value)){
- if ($value > 0){
- $acl[$key]= $value - 1;
+ if (is_int($value)){
+ if ($value){
+ $value--;
} else {
} else {
- $acl[$key]= "";
+ $value= "";
}
}
}
}
}
}
$acl = "rwcdm";
$types = "rwcdm";
$acl = "rwcdm";
$types = "rwcdm";
-
if(!is_string($category)){
trigger_error("category must be string");
$acl = "";
if(!is_string($category)){
trigger_error("category must be string");
$acl = "";