Blame view

framework/security/PermissionRoleCode.php 1.27 KB
0084d336   Administrator   Importers CRUD
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
  <?php
  /**
   * A PermissionRoleCode represents a single permission code assigned to a {@link PermissionRole}.
   * 
   * @package framework
   * @subpackage security
   *
   * @property string Code
   *
   * @property int RoleID
   *
   * @method PermissionRole Role()
   */
  class PermissionRoleCode extends DataObject {
  	private static $db = array(
  		"Code" => "Varchar",
  	);
  	
  	private static $has_one = array(
  		"Role" => "PermissionRole",
  	);
  
  	protected function validate() {
  		$result = parent::validate();
  
  		// Check that new code doesn't increase privileges, unless an admin is editing.
  		$privilegedCodes = Config::inst()->get('Permission', 'privileged_permissions');
  		if(
  			$this->Code
  			&& in_array($this->Code, $privilegedCodes)
  			&& !Permission::check('ADMIN')
  		) {
  			$result->error(sprintf(
  				_t(
  					'PermissionRoleCode.PermsError',
  					'Can\'t assign code "%s" with privileged permissions (requires ADMIN access)'
  				),
  				$this->Code
  			));
  		}
  
  		return $result;
  	}
  
  	public function canCreate($member = null) {
  		return Permission::check('APPLY_ROLES', 'any', $member);
  	}
  
  	public function canEdit($member = null) {
  		return Permission::check('APPLY_ROLES', 'any', $member);
  	}
  
  	public function canDelete($member = null) {
  		return Permission::check('APPLY_ROLES', 'any', $member);
  	}
  }