Commit 5317fdeb authored by Laurent Lecluse's avatar Laurent Lecluse
Browse files

canView pour sécuriser l'accès aux fiches à terme

parent 18d13e4e
Loading
Loading
Loading
Loading
Loading
+12 −7
Changes for front/Intervenant/Recherche.vue: 12 added lines, 7 removed lines.
Original line number Diff line number Diff line
@@ -23,7 +23,7 @@
    <table v-if="intervenants.length > 0" class="table table-bordered table-hover">
        <thead>
        <tr>
            <th style="width:90px"></th>
            <th v-if="canView" style="width:90px"></th>
            <th>Civilité</th>
            <th>Nom</th>
            <th>Prenom</th>
@@ -36,14 +36,14 @@
        <tbody>
        <tr v-for="(intervenant,code) in intervenants" :class="{'bg-danger': intervenant.destruction!==null}"
            :title="(intervenant.destruction!==null) ? 'Fiche historisé' : ''">
            <td style="">
            <td v-if="intervenant.canView">
                <a :href="urlFiche(intervenant['code'])"><i class="fas fa-eye"></i> Fiche</a>
            </td>
            <td>{{ intervenant['civilite'] }}</td>
            <td>{{ intervenant['nom'] }}</td>
            <td>{{ intervenant['prenom'] }}</td>
            <td>{{ intervenant['structure'] }}</td>
            <td>{{ intervenant['statut'] }}</td>
            <td>{{ intervenant.civilite }}</td>
            <td>{{ intervenant.nom }}</td>
            <td>{{ intervenant.prenom }}</td>
            <td>{{ intervenant.structure }}</td>
            <td>{{ intervenant.statut }}</td>
            <td>
                <u-date :value="intervenant['date-naissance']"/>
            </td>
@@ -87,6 +87,7 @@ export default {
        return {
            searchTerm: '',
            noResult: 0,
            canView: false,
            intervenants: [],
            checkedTypes: ['vacataire', 'permanent', 'etudiant'],
        };
@@ -129,7 +130,11 @@ export default {
                        let datas = response.data;
                        let datasFiltered = [];

                        this.canView = false;
                        for (const intervenant in datas) {
                            if (datas[intervenant].canView) {
                                this.canView = true;
                            }
                            if (datas[intervenant].typeIntervenantCode == 'E' && this.checkedTypes.includes('vacataire')) {
                                datasFiltered.push(datas[intervenant]);
                                continue;
+3 −2
Changes for module/Intervenant/src/Processus/IntervenantProcessus.php: 3 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -4,6 +4,7 @@ namespace Intervenant\Processus;

use Application\Processus\AbstractProcessus;
use Intervenant\Entity\Db\Intervenant;
use Unicaen\Framework\Application\Application;


/**
@@ -34,8 +35,8 @@ class IntervenantProcessus extends AbstractProcessus
    public function recherche(): RechercheProcessus
    {
        if (!$this->recherche) {
            $this->recherche = new RechercheProcessus;
            $this->recherche->setEntityManager($this->getEntityManager());
            // @todo utiliser l'injection de dépendances...
            $this->recherche = Application::getInstance()->container()->get(RechercheProcessus::class);
        }

        return $this->recherche;
+19 −6
Changes for module/Intervenant/src/Processus/RechercheProcessus.php: 19 added lines, 6 removed lines.
Original line number Diff line number Diff line
@@ -3,14 +3,14 @@
namespace Intervenant\Processus;


use Application\Service\Traits\ContextServiceAwareTrait;
use UnicaenApp\Service\EntityManagerAwareTrait;
use Application\Provider\Privileges;
use Application\Service\ContextService;
use Doctrine\ORM\EntityManager;
use Unicaen\Framework\Authorize\Authorize;
use UnicaenApp\Util;

class RechercheProcessus
{
    use EntityManagerAwareTrait;
    use ContextServiceAwareTrait;

    /**
     * @var bool
@@ -19,6 +19,16 @@ class RechercheProcessus



    public function __construct(
        private readonly EntityManager  $entityManager,
        private readonly ContextService $context,
        private readonly Authorize      $authorize
    )
    {
    }



    /**
     * @param string  $critere
     * @param integer $limit
@@ -40,7 +50,7 @@ class RechercheProcessus
    {
        if (strlen($critere) < 2) return [];

        $anneeId = (int)$this->getServiceContext()->getAnnee()->getId();
        $anneeId = (int)$this->context->getAnnee()->getId();
        $critere = self::reduce($critere);

        $criteres = explode('_', $critere);
@@ -76,11 +86,12 @@ class RechercheProcessus
        $intervenants = [];


        $stmt = $this->getEntityManager()->getConnection()->executeQuery($sql);
        $stmt = $this->entityManager->getConnection()->executeQuery($sql);
        while ($r = $stmt->fetch()) {
            $k = $this->makeKey($r, $key);
            if (!isset($intervenants[$k])) {
                $intervenants[$k] = [
                    'canView'                => $this->authorize->isAllowedPrivilege(Privileges::INTERVENANT_FICHE),
                    'civilite'               => $r['CIVILITE'],
                    'nom'                    => $r['NOM_USUEL'],
                    'prenom'                 => $r['PRENOM'],
@@ -230,6 +241,8 @@ class RechercheProcessus
        return $this->rechercheGenerique($critere, $limit, $key, true);
    }



    /**
     * @param string $str      Chaine à nettoyer
     * @param string $encoding Encodage en sortie