Code

Simple style updates
[gosa.git] / include / class_plugin.inc
index 239e89fc5eea63d5f47a4ce629088f543e2da9d2..6cbec1b4eddc6cf2a5559cf6b04e21b406a3c27c 100644 (file)
@@ -222,10 +222,13 @@ class plugin
    */
   function execute()
   {
+    gosa_log("ACL ".get_class($this)." - ".$this->acl_category." - ".$this->acl_base);
+
     /* This one is empty currently. Fabian - please fill in the docu code */
     $_SESSION['current_class_for_help'] = get_class($this);
+
     /* Reset Lock message POST/GET check array, to prevent perg_match errors*/
-    $_SESSION['LOCK_VARS_TO_USE'] =array();
+    $_SESSION['LOCK_VARS_TO_USE'] = $_SESSION['LOCK_VARS_USED'] =array();
   }
 
   /*! \brief execute plugin
@@ -913,7 +916,9 @@ class plugin
     }
     $todo[] = "is_account";
     foreach($todo as $var){
-      $this->$var = $source->$var;
+      if (isset($source->$var)){
+        $this->$var= $source->$var;
+      }
     }
   }
 
@@ -1121,18 +1126,13 @@ class plugin
 
   function remove_snapshot($dn)
   {
-echo "FIXME: remove_snapshot uses old acl's<br>";
-    $ui   = get_userinfo();
-    $acl  = get_permissions ($dn, $ui->subtreeACL);
-    $acl  = get_module_permission($acl, "snapshot", $dn);
-
-    if (chkacl($this->acl, "delete") == ""){
-      $ldap = $this->config->get_ldap_link();
-      $ldap->cd($this->config->current['BASE']);
-      $ldap->rmdir_recursive($dn);
-    }else{
-      print_red (_("You are not allowed to delete this snapshot!"));
-    }
+    $ui       = get_userinfo();
+    $old_dn   = $this->dn; 
+    $this->dn = $dn;
+    $ldap = $this->config->get_ldap_link();
+    $ldap->cd($this->config->current['BASE']);
+    $ldap->rmdir_recursive($dn);
+    $this->dn = $old_dn;
   }
 
 
@@ -1353,7 +1353,8 @@ echo "FIXME: remove_snapshot uses old acl's<br>";
       /* Restore one of the already deleted objects */
       if(preg_match("/^RestoreDeletedSnapShot_/",$name) && $once){
         $once = false;
-        $this->snapDialog = new SnapShotDialog($this->config,$baseSuffixe,$this);
+        $this->snapDialog = new SnapShotDialog($this->config,"",$this);
+        $this->snapDialog->set_snapshot_bases($baseSuffixe);
         $this->snapDialog->display_restore_dialog      = true;
         $this->snapDialog->display_all_removed_objects  = true;
       }
@@ -1465,7 +1466,149 @@ echo "FIXME: remove_snapshot uses old acl's<br>";
     return  $ui->get_permissions($this->acl_base, $this->acl_category.get_class($this), $attribute,$skip_write);
   }
 
+  /* Get all allowed bases to move an object to or to create a new object.
+     Idepartments also contains all base departments which lead to the allowed bases */
+  function get_allowed_bases($category = "")
+  {
+    $ui = get_userinfo();
+    $deps = array();
+
+    /* Set category */ 
+    if(empty($category)){
+      $category = $this->acl_category.get_class($this);
+    }
+
+    /* Is this a new object ? Or just an edited existing object */
+    if(!$this->initially_was_account && $this->is_account){
+      $new = true;
+    }else{
+      $new = false;
+    }
+
+    $cat_bases = $ui->get_module_departments(preg_replace("/\/.*$/","",$category));
+    foreach($this->config->idepartments as $dn => $name){
+      
+      if(!in_array_ics($dn,$cat_bases)){
+        continue;
+      }
+      
+      $acl = $ui->get_permissions($dn,$category);
+      if($new && preg_match("/c/",$acl)){
+        $deps[$dn] = $name;
+      }elseif(!$new && preg_match("/m/",$acl)){
+        $deps[$dn] = $name;
+      }
+    }
+
+    /* Add current base */      
+    if(isset($this->base) && isset($this->config->idepartments[$this->base])){
+      $deps[$this->base] = $this->config->idepartments[$this->base];
+    }else{
+      echo "No default base found. ".$this->base."<br> ";
+    }
+
+    return($deps);
+  }
+
+  /* This function modifies object acls too, if an object is moved.
+   *  $old_dn   specifies the actually used dn
+   *  $new_dn   specifies the destiantion dn
+   */
+  function update_acls($old_dn,$new_dn,$output_changes = FALSE)
+  {
+    global $config;
+
+    /* Check if old_dn is empty. This should never happen */
+    if(empty($old_dn) || empty($new_dn)){
+      trigger_error("Failed to check acl dependencies, wrong dn given.");
+      return;
+    }
+
+    /* Update userinfo if necessary */
+    if($_SESSION['ui']->dn == $old_dn){
+      $_SESSION['ui']->dn = $new_dn;
+      gosa_log(_("Updated current user dn from '".$old_dn."' to '".$new_dn."'"));
+    }
+
+    /* Object was moved, ensure that all acls will be moved too */
+    if($new_dn != $old_dn && $old_dn != "new"){
 
+      /* get_ldap configuration */
+      $update = array();
+      $ldap = $config->get_ldap_link();
+      $ldap->cd ($config->current['BASE']);
+      $ldap->search("(&(objectClass=gosaAcl)(gosaAclEntry=*))",array("cn","gosaAclEntry"));
+      while($attrs = $ldap->fetch()){
+
+        $acls = array();
+
+        /* Walk through acls */
+        for($i = 0 ; $i <  $attrs['gosaAclEntry']['count'] ; $i ++ ){
+
+          /* Reset vars */
+          $found = false;
+
+          /* Get Acl parts */
+          $acl_parts = split(":",$attrs['gosaAclEntry'][$i]);
+
+          /* Get every single member for this acl */  
+          $members = array();  
+          if(preg_match("/,/",$acl_parts[2])){
+            $members = split(",",$acl_parts[2]);
+          }else{
+            $members = array($acl_parts[2]);
+          } 
+      
+          /* Check if member match current dn */
+          foreach($members as $key => $member){
+            $member = base64_decode($member);
+            if($member == $old_dn){
+              $found = true;
+              $members[$key] = base64_encode($new_dn);
+            }
+          } 
+         
+          /* Create new member string */ 
+          $new_members = "";
+          foreach($members as $member){
+            $new_members .= $member.",";
+          }
+          $new_members = preg_replace("/,$/","",$new_members);
+          $acl_parts[2] = $new_members;
+        
+          /* Reconstruckt acl entry */
+          $acl_str  ="";
+          foreach($acl_parts as $t){
+           $acl_str .= $t.":";
+          }
+          $acl_str = preg_replace("/:$/","",$acl_str);
+       }
+
+       /* Acls for this object must be adjusted */
+       if($found){
+
+          if($output_changes){
+            echo "<font color='green'>".
+                  _("Changing ACL dn")."&nbsp;:&nbsp;<br>&nbsp;-"._("from")."&nbsp;<b>&nbsp;".
+                  $old_dn.
+                  "</b><br>&nbsp;-"._("to")."&nbsp;<b>".
+                  $new_dn.
+                  "</b></font><br>";
+          }
+          $update[$attrs['dn']] =array();
+          foreach($acls as $acl){
+            $update[$attrs['dn']]['gosaAclEntry'][] = $acl;
+          }
+        }
+      }
+
+      /* Write updated acls */
+      foreach($update as $dn => $attrs){
+        $ldap->cd($dn);
+        $ldap->modify($attrs);
+      }
+    }
+  }
 }
 // vim:tabstop=2:expandtab:shiftwidth=2:filetype=php:syntax:ruler:
 ?>