Skip to content
Open
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 64 additions & 1 deletion src/administrator/includes/rbacl.php
Original file line number Diff line number Diff line change
Expand Up @@ -129,7 +129,9 @@ public static function check($userId, $client, $action, $contentId = null)
$userModel = self::model("user");
$contentRoleId = $userModel->getAssociatedContentRole($userId, $client, $contentId);

if (in_array($contentRoleId, $allowedRoles))
$rolesAllowed = array_intersect($contentRoleId, $allowedRoles);
Comment thread
sanjivani1812 marked this conversation as resolved.

if (!empty($rolesAllowed))
{
return true;
}
Expand Down Expand Up @@ -199,4 +201,65 @@ public static function getRoleByUser($userId, $client = '', $clientContentIid =

return $roles;
}

/**
* Method to Get roles of users again to selected agency.
Comment thread
sanjivani1812 marked this conversation as resolved.
Outdated
*
* @param integer $contentId agency id
* @param integer $userId user id
* @param integer $roleId selected role id
*
* @return mixed
*
* @since 1.6
Comment thread
sanjivani1812 marked this conversation as resolved.
Outdated
*/
public function getAuthorizedActions($contentId = null, $userId = null, $roleId = null)
Comment thread
sanjivani1812 marked this conversation as resolved.
Outdated
{
if ($contentId == null)
Comment thread
sanjivani1812 marked this conversation as resolved.
Outdated
{
$input = JFactory::getApplication()->input;
$contentId = $input->get('aid', '0', 'INT');
}

if ($userId == null)
{
$userId = JFactory::getUser()->id;
}

// Get subusers actions mapp
$userRoleId = self::getRoleByUser($userId, 'com_multiagency', 0);

if (empty($userRoleId))
{
$userRoleId = self::getRoleByUser($userId, 'com_multiagency', $contentId);
}

if (!empty($userRoleId))
{
$db = JFactory::getDBO();
$subInQuery = $db->getQuery(true);
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sanjivani1812 Move the DB operations in the model

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@thite-amol - getRoleByUser function having DB operation so I put there. Can please suggest a model name.

$subInQuery->select('action_id')
->from($db->quoteName('#__tjsu_role_action_map'))
->where($db->quoteName('role_id') . 'IN(' . implode(',', $userRoleId) . ')');
$db->setQuery($subInQuery);

$roleActions = $db->loadColumn();

if ($roleActions && !empty($contentId) && !empty($userRoleId))
Comment thread
sanjivani1812 marked this conversation as resolved.
Outdated
{
$query = $db->getQuery(true);
$query->select('m.role_id,r.name, count( m.action_id) as actionCount, (select count(aa.action_id)
FROM #__tjsu_role_action_map aa WHERE aa.role_id = m.role_id) as roleCount');
$query->from($db->quoteName('#__tjsu_role_action_map', 'm'));
$query->join('INNER', $db->quoteName('#__tjsu_actions', 'a') . ' ON (' . $db->quoteName('a.id') . ' = ' . $db->quoteName('m.action_id') . ')');
Comment thread
sanjivani1812 marked this conversation as resolved.
$query->join('INNER', $db->quoteName('#__tjsu_roles', 'r') . ' ON (' . $db->quoteName('r.id') . ' = ' . $db->quoteName('m.role_id') . ')');
$query->where($db->quoteName('m.action_id') . ' IN (' . implode(',', $roleActions) . ')');
$query->group($db->quoteName('m.role_id'));
$query->having('roleCount <= actionCount');
$db->setQuery($query);

return $roles = $db->loadAssocList();
Comment thread
sanjivani1812 marked this conversation as resolved.
Outdated
}
}
}
}
11 changes: 8 additions & 3 deletions src/administrator/models/user.php
Original file line number Diff line number Diff line change
Expand Up @@ -106,7 +106,7 @@ protected function loadFormData()
*
* @since __DEPLOY_VERSION__
*/
public function getAssociatedContentRole($userId, $client, $contentId)
public function getAssociatedContentRole($userId, $client, $contentId = null)
{
$db = Factory::getDbo();
$query = $db->getQuery(true);
Expand All @@ -115,9 +115,14 @@ public function getAssociatedContentRole($userId, $client, $contentId)
$query->from($db->quoteName('#__tjsu_users'));
$query->where($db->quoteName('user_id') . " = " . (int) $userId);
$query->where($db->quoteName('client') . " = " . $db->q($client));
$query->where($db->quoteName('client_id') . " = " . (int) $contentId);

if (!is_null($contentId))
Comment thread
sanjivani1812 marked this conversation as resolved.
{
$query->where($db->quoteName('client_id') . " = " . $db->quote($contentId));
}

$db->setQuery($query);

return $db->loadResult();
return $db->loadColumn();
Comment thread
sanjivani1812 marked this conversation as resolved.
}
}