index 3ec7f68a78cbdc30ac2f759c583c1255827163de..9c01f5489e6881b34ab391bb936b8bf2cd7c40de 100644 (file)
var $subClassName = "faiScriptEntry";
/* Attributes to initialise for each subObject */
- var $subAttributes = array("cn","description","FAIpriority","FAIscript");
+ var $subAttributes = array("cn","description","FAIpriority");
+ var $sub_Load_Later = array("FAIscript");
var $sub64coded = array();
+ var $subBinary = array("FAIscript");
/* Specific attributes */
var $cn = ""; // The class name for this object
var $dialog = NULL; // a dialog, e.g. new disk dialog
var $SubObjects = array(); // All leafobjects of this object
+ var $FAIstate ="";
+
+ var $view_logged = FALSE;
+ var $ui;
+
function faiScript ($config, $dn= NULL)
{
/* Load Attributes */
* First read SubObjects from ldap ... and then the partition definitions for the SubObjects.
*/
if($dn != "new"){
+
$this->dn =$dn;
+ /* Get FAIstate
+ */
+ if(isset($this->attrs['FAIstate'][0])){
+ $this->FAIstate = $this->attrs['FAIstate'][0];
+ }
+
/* Read all leaf objects of this object (For FAIscript this would be FAIscriptEntry)
*/
$ldap = $this->config->get_ldap_link();
$ldap->cd ($this->dn);
- $ldap->search("(&(objectClass=FAIclass)(objectClass=".$this->subClass."))",$this->subAttributes);
+
+ $attrs_to_search = $this->subAttributes;
+ $attrs_to_search[] = "FAIstate";
+ $ldap->search("(&(objectClass=FAIclass)(objectClass=".$this->subClass."))",$attrs_to_search);
while($object = $ldap->fetch()){
- /* Set status for save management */
-
- foreach($this->subAttributes as $attrs){
- if(!isset($object[$attrs][0])){
- $this->SubObjects[$object['cn'][0]][$attrs]="";
- }else{
- $this->SubObjects[$object['cn'][0]][$attrs]=$object[$attrs][0];
+
+ /* Skip objects, that are tagged as removed */
+ if(isset($object['FAIstate'][0])){
+ if(preg_match("/removed$/",$object['FAIstate'][0])){
+ continue;
}
}
-
- foreach($this->sub64coded as $codeIt){
- $this->SubObjects[$object['cn'][0]][$codeIt]=(base64_decode($this->SubObjects[$object['cn'][0]][$codeIt]));
+
+ /* Set status for save management */
+ $objects = array();
+ $objects['status'] = "FreshLoaded";
+ $objects['dn'] = $object['dn'];
+ $objects = $this->get_object_attributes($objects,$this->subAttributes);
+ $this->SubObjects[$objects['cn']] = $objects;
+ }
+
+ }
+ $this->ui = get_userinfo();
+ }
+
+
+ /* Reload some attributes */
+ function get_object_attributes($object,$attributes)
+ {
+ $ldap = $this->config->get_ldap_link();
+ $ldap->cd($this->config->current['BASE']);
+ $ldap->cat($object['dn'],$attributes);
+ $tmp = $ldap->fetch();
+
+ foreach($attributes as $attrs){
+ if(isset($tmp[$attrs][0])){
+ $var = $tmp[$attrs][0];
+
+ /* Check if we must decode some attributes */
+ if(in_array_ics($attrs,$this->sub64coded)){
+ $var = base64_decode($var);
}
- foreach($this->subAttributes as $attrs){
- $this->SubObjects[$object['cn'][0]][$attrs]=addslashes($this->SubObjects[$object['cn'][0]][$attrs]);
+ /* check if this is a binary entry */
+ if(in_array_ics($attrs,$this->subBinary)){
+ $var = $ldap->get_attribute($object['dn'], $attrs,$r_array=0);
}
- $this->SubObjects[$object['cn'][0]]['FAIscript'] = addslashes ($this->readBinary("FAIscript",$object['dn']));
-
- $this->SubObjects[$object['cn'][0]]['status'] = "edited";
- $this->SubObjects[$object['cn'][0]]['dn'] = $object['dn'];
+ /* Fix slashes */
+ $var = addslashes($var);
+ $object[$attrs] = $var;
+ }
+ }
+ return($object);
+ }
+
+
+ /* Return a valid dn to fetch acls. Because 'new' will not work. */
+ function acl_base_for_current_object($dn)
+ {
+ if($dn == "new"){
+ if($this->dn == "new"){
+ $dn= "cn=dummy,".$_SESSION['CurrentMainBase'];
+ }else{
+ $dn = $this->dn;
}
}
+ return($dn);
}
+
function execute()
{
+ /* Call parent execute */
+ plugin::execute();
+
+ if($this->is_account && !$this->view_logged){
+ $this->view_logged = TRUE;
+ new log("view","fai/".get_class($this),$this->dn);
+ }
+
/* Fill templating stuff */
$smarty= get_smarty();
$display= "";
/* Add new sub object */
if(isset($_POST['AddSubObject'])){
$this->dialog= new $this->subClassName($this->config,"new");
+ $this->dialog->set_acl_base($this->acl_base);
+ $this->dialog->set_acl_category("fai");
$this->is_dialog=true;
}
- $_SESSION['objectinfo'] = $this->dn;
- /* Edit selected Sub Object */
- if((isset($_POST['EditSubObject']))&&(isset($_POST['SubObject']))){
- $this->dialog= new $this->subClassName($this->config,$this->dn,$this->SubObjects[$_POST['SubObject']]);
- $_SESSION['objectinfo'] = $this->SubObjects[$_POST['SubObject']]['dn'];
- $this->is_dialog=true;
+ if($this->dn != "new"){
+ $_SESSION['objectinfo']= $this->dn;
}
-
- /* Remove Sub object */
- if((isset($_POST['DelSubObject']))&&(isset($_POST['SubObject']))){
- if($this->SubObjects[$_POST['SubObject']]['status'] == "edited"){
- $this->SubObjects[$_POST['SubObject']]['status']= "delete";
- }else{
- unset($this->SubObjects[$_POST['SubObject']]);
+
+ /* Handle posts */
+ $once = true;
+ foreach($_POST as $name => $value){
+
+ /* Edit script posted */
+ if(preg_match("/^editscript_/",$name)&&($once)){
+
+ /* Get posted entry id */
+ $once = false;
+ $entry = preg_replace("/^editscript_/","",$name);
+ $entry = base64_decode(preg_replace("/_.*/","",$entry));
+
+ /* Get object, and load missing entry values */
+ $obj = $this->SubObjects[$entry];
+ if($obj['status'] == "FreshLoaded"){
+ $obj = $this->get_object_attributes($obj,$this->sub_Load_Later);
+ }
+
+ /* Create new dialog and set acl attributes */
+ $this->dialog= new $this->subClassName($this->config,$this->dn,$obj);
+ $this->dialog->set_acl_base($this->acl_base_for_current_object($obj['dn']));
+ $this->dialog->set_acl_category("fai");
+
+ /* Assign some additional dialog informations like headline and parent */
+ $_SESSION['objectinfo'] = $obj['dn'];
+ $this->dialog->parent = &$this;
+ $this->is_dialog=true;
+ }
+
+ /* Delete script requested */
+ if(preg_match("/^deletescript_/",$name)&&($once)){
+
+ /* Parse out posted entry id */
+ $once = false;
+ $entry = preg_replace("/^deletescript_/","",$name);
+ $entry = base64_decode(preg_replace("/_.*/","",$entry));
+
+ /* Check acls, are we allowed to delete an entry */
+ $acl = $this->ui->get_permissions($this->acl_base_for_current_object($this->SubObjects[$entry]['dn']),"fai/faiScriptEntry") ;
+ if(preg_match("/d/",$acl)){
+ $status = $this->SubObjects[$entry]['status'];
+ if($status == "edited" || $status == "FreshLoaded"){
+ $this->SubObjects[$entry]['status']= "delete";
+ }else{
+ unset($this->SubObjects[$entry]);
+ }
+ }
}
}
- /* Save Dialog */
+
+ /* Save the edited entry */
if(isset($_POST['SaveSubObject'])){
+
+ /* Check if there are still errors remaining that must be fixed before saving */
$this->dialog->save_object();
$msgs = $this->dialog->check();
if(count($msgs)>0){
print_red($msg);
}
}else{
+
+ /* Get return object */
$obj = $this->dialog->save();
+
+ /* If we have renamed the script entry, we must remove the old entry */
if(isset($obj['remove'])){
- if($this->SubObjects[$obj['remove']['from']]['status']=="edited"){
+
+ /* Get old entry values */
+ $old_stat = $this->SubObjects[$obj['remove']['from']]['status'];
+
+ /* Depending on status, set new status */
+ if($old_stat == "edited" || $old_stat == "FreshLoaded"){
$this->SubObjects[$obj['remove']['from']]['status'] = "delete";
}elseif($this->SubObjects[$obj['remove']['from']]['status']=="new"){
unset($this->SubObjects[$obj['remove']['from']]);
}
+
+ /* Append the new entry */
$obj['status'] = "new";
$this->SubObjects[$obj['remove']['to']] = $obj;
unset($this->SubObjects[$obj['remove']['to']]['remove']);
}else{
+
+ /* Set new status and append the entry */
+ if($obj['status'] == "FreshLoaded"){
+ $obj['status'] = "edited";
+ }
$this->SubObjects[$obj['cn']]=$obj;
}
$this->is_dialog=false;
unset($this->dialog);
$this->dialog=NULL;
+
}
}
+ /* Sort entries */
+ $tmp = $keys = array();
+ foreach($this->SubObjects as $key => $entry){
+ $keys[$key]=$key;
+ }
+ natcasesort($keys);
+ foreach($keys as $key){
+ $tmp[$key]=$this->SubObjects[$key];
+ }
+ $this->SubObjects = $tmp;
+
/* Cancel Dialog */
if(isset($_POST['CancelSubObject'])){
$this->is_dialog=false;
return($display);
}
- $smarty->assign("SubObjects",$this->getList());
- $smarty->assign("SubObjectKeys",array_flip($this->getList()));
-
+ /* Divlist added 23.02.2006
+ Containing FAIscripts
+ */
+ $divlist = new divSelectBox("FAIscripts");
+ $divlist->setHeight(400);
+ foreach($this->getList(true) as $key => $name){
+
+ $dn= $this->acl_base_for_current_object($name['dn']);
+ $acl = $this->ui->get_permissions($dn,"fai/faiScriptEntry") ;
+ $act = "";
+
+ /* Hide delete icon if this object is freezed */
+ if($this->FAIstate == "freeze"){
+ $act .= "<input type='image' src='images/edit.png' name='editscript_%s' title='"._("edit")."' alt='"._("edit")."'>";
+ }else{
+ $act .= "<input type='image' src='images/edit.png' name='editscript_%s' title='"._("edit")."' alt='"._("edit")."'>";
+ if(preg_match("/d/",$acl)){
+ $act .="<input type='image' src='images/edittrash.png' name='deletescript_%s' title='"._("delete")."' alt='"._("delete")."'>";
+ }
+ }
+
+ /* Check acls for download icon */
+ $s_acl = $this->ui->get_permissions($dn,"fai/faiScriptEntry","FAIscript") ;
+ if(($this->SubObjects[$key]['status'] == "new") || ($this->SubObjects[$key]['dn'] == "new") || !preg_match("/r/",$s_acl)){
+ $down = "";
+ }else{
+ $down = "<a href='getFAIscript.php?id=".base64_encode($name['dn'])."' >
+ <img src='images/save.png' alt='"._("Download")."' title='"._("Download")."' border=0>
+ </a>";
+ }
+
+ /* Check if we are allowed to view this object */
+ $s_acl = $this->ui->get_permissions($dn,"fai/faiScriptEntry","cn") ;
+ if(preg_match("/r/",$s_acl)){
+ $divlist->AddEntry(array( array("string"=>$name['name']),
+ array("string"=>$down , "attach" => "style='width:20px;'"),
+ array("string"=>str_replace("%s",base64_encode($key),$act),
+ "attach"=>"style='border-right: 0px;width:50px;text-align:right;'")));
+ }
+ }
+ $smarty->assign("Entry_divlist",$divlist->DrawList());
+
+
/* Magic quotes GPC, escapes every ' " \, to solve some security risks
- * If we post the escaped strings they will be escaped again
- */
+ * If we post the escaped strings they will be escaped again
+ */
foreach($this->attributes as $attrs){
if(get_magic_quotes_gpc()){
$smarty->assign($attrs,stripslashes($this->$attrs));
}
}
+ $dn = $this->acl_base_for_current_object($this->dn);
+ $smarty->assign("sub_object_is_addable",
+ preg_match("/c/",$this->ui->get_permissions($dn,"fai/faiScriptEntry")) &&
+ !preg_match("/freeze/",$this->FAIstate));
+
+ $tmp = $this->plInfo();
+ foreach($tmp['plProvidedAcls'] as $name => $translated){
+ $smarty->assign($name."ACL",$this->getacl($name));
+ }
+
$display.= $smarty->fetch(get_template_path('faiScript.tpl', TRUE));
return($display);
}
/* Generate listbox friendly SubObject list
- */
- function getList(){
+ */
+ function getList($use_dns=false){
$a_return=array();
foreach($this->SubObjects as $obj){
if($obj['status'] != "delete"){
- if((isset($obj['description']))&&(!empty($obj['description']))){
- $a_return[$obj['cn']]= $obj['cn']." [".$obj['description']."]";
+ if($use_dns){
+ if((isset($obj['description']))&&(!empty($obj['description']))){
+ $a_return[$obj['cn']]['name']= $obj['cn']." [".stripslashes($obj['description'])."]";
+ }else{
+ $a_return[$obj['cn']]['name']= $obj['cn'];
+ }
+ $a_return[$obj['cn']]['dn']= $obj['dn'];
}else{
- $a_return[$obj['cn']]= $obj['cn'];
+ if((isset($obj['description']))&&(!empty($obj['description']))){
+ $a_return[$obj['cn']]= $obj['cn']." [".stripslashes($obj['description'])."]";
+ }else{
+ $a_return[$obj['cn']]= $obj['cn'];
+ }
}
}
}
*/
function remove_from_parent()
{
- $ldap = $this->config->get_ldap_link();
- $ldap->cd ($this->dn);
- $ldap->rmdir_recursive($this->dn);
- $this->handle_post_events("remove");
+ if($this->acl_is_removeable()){
+ $ldap = $this->config->get_ldap_link();
+ $ldap->cd ($this->dn);
+
+ $use_dn = preg_replace("/".normalizePreg(get_release_dn($this->dn))."/i", $_SESSION['faifilter']['branch'], $this->dn);
+ if($_SESSION['faifilter']['branch'] == "main"){
+ $use_dn = $this->dn;
+ }
+
+ new log("remove","fai/".get_class($this),$use_dn,$this->attributes);
+
+ prepare_to_save_FAI_object($use_dn,array(),true);
+
+ foreach($this->SubObjects as $name => $obj){
+ $use_dn = preg_replace("/".normalizePreg(get_release_dn($this->dn))."/i", $_SESSION['faifilter']['branch'], $obj['dn']);
+ if($_SESSION['faifilter']['branch'] == "main"){
+ $use_dn = $obj['dn'];
+ }
+ prepare_to_save_FAI_object($use_dn,array(),true);
+ }
+ $this->handle_post_events("remove");
+ }
}
*/
function save_object()
{
- if(isset($_POST['FAIscript_posted'])){
+ if((isset($_POST['FAIscript_posted'])) && ($this->FAIstate != "freeze")){
plugin::save_object();
foreach($this->attributes as $attrs){
if(isset($_POST[$attrs])){
/* Check supplied data */
function check()
{
- $message= array();
+ /* Call common method to give check the hook */
+ $message= plugin::check();
+
return ($message);
}
function save()
{
plugin::save();
-
+
$ldap = $this->config->get_ldap_link();
-
- $ldap->cat($this->dn);
- if($ldap->count()!=0){
- /* Write FAIscript to ldap*/
- $ldap->cd($this->dn);
- $ldap->modify($this->attrs);
+
+ prepare_to_save_FAI_object($this->dn,$this->attrs);
+ show_ldap_error($ldap->get_error(), sprintf(_("Creating of FAI/script with dn '%s' failed."),$this->dn));
+
+ if($this->initially_was_account){
+ new log("modify","fai/".get_class($this),$this->dn,$this->attributes);
}else{
- /* Write FAIscript to ldap*/
- $ldap->cd($this->config->current['BASE']);
- $ldap->create_missing_trees(preg_replace('/^[^,]+,/', '', $this->dn));
- $ldap->cd($this->dn);
- $ldap->add($this->attrs);
+ new log("create","fai/".get_class($this),$this->dn,$this->attributes);
}
- show_ldap_error($ldap->get_error());
-
+
+ /* Do object tagging */
+ $this->handle_object_tagging();
+
/* Prepare FAIscriptEntry to write it to ldap
* First sort array.
* Because we must delete old entries first.
* After deletion, we perform add and modify
*/
$Objects = array();
+
+ /* We do not need to save untouched objects */
+ foreach($this->SubObjects as $name => $obj){
+ if($obj['status'] == "FreshLoaded"){
+ unset($this->SubObjects[$name]);
+ }
+ }
+
foreach($this->SubObjects as $name => $obj){
if($obj['status'] == "delete"){
$Objects[$name] = $obj;
}
$tmp = array();
- foreach($this->subAttributes as $attrs){
+ $attributes = array_merge($this->sub_Load_Later,$this->subAttributes);
+ foreach($attributes as $attrs){
+
if(empty($obj[$attrs])){
$obj[$attrs] = array();
}
$tmp[$attrs] = $obj[$attrs];
}
}
-
+
$tmp['objectClass'] = $this->subClasses;
$sub_dn = "cn=".$obj['cn'].",".$this->dn;
if($obj['status']=="new"){
- $ldap->cat($sub_dn);
+ $ldap->cat($sub_dn,array("objectClass"));
if($ldap->count()){
- $obj['status']="modify";
+ $obj['status']="edited";
}
}
if(empty($tmp['FAIpriority'])){
$tmp['FAIpriority'] ="0";
}
-
+
+ /* Check if gosaAdministrativeUnitTag is required as object class */
+ if($obj['status'] == "edited"){
+ $ldap->cat($sub_dn,array("objectClass"));
+ $attrs = $ldap->fetch();
+ if(isset($attrs['objectClass'])){
+ if(in_array_ics("gosaAdministrativeUnitTag",$attrs['objectClass'])){
+ $tmp['objectClass'][] = "gosaAdministrativeUnitTag";
+ }
+ }
+ }
+
if($obj['status'] == "delete"){
- $ldap->cd($sub_dn);
- $ldap->rmdir_recursive($sub_dn);
+ prepare_to_save_FAI_object($sub_dn,array(),true);
$this->handle_post_events("remove");
}elseif($obj['status'] == "edited"){
- $ldap->cd($sub_dn);
- $ldap->modify($tmp);
+ prepare_to_save_FAI_object($sub_dn,$tmp);
$this->handle_post_events("modify");
}elseif($obj['status']=="new"){
- if($tmp['description']==array()){
- unset($tmp['description']);
- }
- if($tmp['FAIscript']==array()){
- $tmp['FAIscript']=" ";
- }
- $ldap->cd($this->config->current['BASE']);
- $ldap->create_missing_trees(preg_replace('/^[^,]+,/', '', $this->dn));
- $ldap->cd($sub_dn);
- $ldap->add($tmp);
+ prepare_to_save_FAI_object($sub_dn,$tmp);
$this->handle_post_events("add");
}
- show_ldap_error($ldap->get_error());
- }
- }
-
-
- function readBinary($attr,$dn){
- $Data ="";
- $ds= ldap_connect($this->config->current['SERVER']);
- ldap_set_option($ds, LDAP_OPT_PROTOCOL_VERSION, 3);
- if (function_exists("ldap_set_rebind_proc") && isset($this->config->current['RECURSIVE']) && $this->config->current['RECURSIVE'] == "true") {
- ldap_set_option($this->cid, LDAP_OPT_REFERRALS, 1);
- ldap_set_rebind_proc($ds, array(&$this, "rebind"));
- }
-
- if(isset($this->config->current['TLS']) && $this->config->current['TLS'] == "true"){
- ldap_start_tls($ds);
- }
- $r = ldap_bind($ds);
- $sr = @ldap_read($ds, $dn, $attr."=*", array($attr));
-
- if ($sr) {
- $ei=ldap_first_entry($ds, $sr);
- if ($ei) {
- if ($info = ldap_get_values_len($ds, $ei, $attr)){
- $Data= $info[0];
- }
- }
+ $this->handle_object_tagging($sub_dn, $this->gosaUnitTag);
}
-
- /* close conncetion */
- ldap_unbind($ds);
- return($Data);
}
+
-
+ /* Return plugin informations for acl handling */
+ function plInfo()
+ {
+ return (array(
+ "plShortName" => _("Script"),
+ "plDescription" => _("FAI script"),
+ "plSelfModify" => FALSE,
+ "plDepends" => array(),
+ "plPriority" => 18,
+ "plSection" => array("administration"),
+ "plCategory" => array("fai"),
+ "plProvidedAcls" => array(
+ "cn" => _("Name")." ("._("Readonly").")",
+ "description" => _("Description"))
+ ));
+ }
}
// vim:tabstop=2:expandtab:shiftwidth=2:filetype=php:syntax:ruler: