Commit 6b249c2b authored by Laurent Lecluse's avatar Laurent Lecluse
Browse files

Protection des statuts et simplification des routes pour Intervenant

parent d2e9f580
Loading
Loading
Loading
Loading
+1 −0
Changes for module/Application/config/administration.config.php: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -277,6 +277,7 @@ return [
                        Privileges::ODF_RECONDUCTION_OFFRE,
                        Privileges::STRUCTURES_ADMINISTRATION_VISUALISATION,
                        Privileges::PARAMETRES_PERIODES_VISUALISATION,
                        Privileges::INTERVENANT_STATUT_VISUALISATION,
                    ],
                    'assertion'  => Assertion\GestionAssertion::class,
                ],
+14 −27
Changes for module/Intervenant/config/module.config.php: 14 added lines, 27 removed lines.
Original line number Diff line number Diff line
@@ -3,21 +3,14 @@
namespace Intervenant;

use Application\Provider\Privilege\Privileges;
use Intervenant\Entity\Db\Statut;

return [
    'routes' => [
        'statut' => [
            'options'       => [
            'route'         => '/statut',
                'constraints' => [
                    'statut' => '[0-9]*',
                ],
                'defaults'    => [
                    '__NAMESPACE__' => 'Intervenant\Controller',
                    'controller'    => 'Statut',
            'controller'    => 'Intervenant\Controller\Statut',
            'action'        => 'index',
                ],
            ],
            'may_terminate' => true,
            'child_routes'  => [
                'saisie' => [
@@ -26,44 +19,38 @@ return [
                    'constraints' => [
                        'statut' => '[0-9]*',
                    ],
                    'may_terminate' => true,
                ],
                'delete' => [
                    'options'       => [
                    'route'       => '/delete/:statut',
                    'action'      => 'delete',
                    'constraints' => [
                        'statut' => '[0-9]*',
                    ],
                        'defaults'    => [
                            'action' => 'delete',
                        ],
                    ],
                    'may_terminate' => true,
                ],
                'trier'  => [
                    'options'       => [
                    'route'  => '/trier',
                        'contraints' => [
                        ],
                        'defaults'   => [
                    'action' => 'trier',
                ],
                    ],
                    'may_terminate' => 'true',
                ],
                'clone'  => [
                    'options'       => [
                    'route'       => '/clone/:statut',
                    'action'      => 'clone',
                    'constraints' => [
                        'statut' => '[0-9]*',
                    ],
                        'defaults'    => [
                            'action' => 'clone',
                ],
            ],
                    'may_terminate' => true,
        ],
    ],

    'resources' => [
        'Statut',
    ],

    'rules' => [
        [
            'privileges' => Privileges::INTERVENANT_STATUT_EDITION,
            'resources'  => 'Statut',
            'assertion'  => Assertion\StatutAssertion::class,
        ],
    ],

+53 −0
Changes for module/Intervenant/src/Assertion/StatutAssertion.php: 53 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

namespace Intervenant\Assertion;

use Application\Acl\Role;
use Application\Provider\Privilege\Privileges;
use Intervenant\Entity\Db\Statut;
use UnicaenAuth\Assertion\AbstractAssertion;
use Laminas\Permissions\Acl\Resource\ResourceInterface;


/**
 * Description of StatutAssertion
 *
 * @author Laurent Lécluse <laurent.lecluse at unicaen.fr>
 */
class StatutAssertion extends AbstractAssertion
{

    protected function assertEntity(ResourceInterface $entity = null, $privilege = null)
    {
        $role = $this->getRole();

        // Si le rôle n'est pas renseigné alors on s'en va...
        if (!$role instanceof Role) return false;

        // pareil si le rôle ne possède pas le privilège adéquat
        if ($privilege && !$role->hasPrivilege($privilege)) return false;

        switch (true) {
            case $entity instanceof Statut:
                switch ($privilege) {
                    case Privileges::INTERVENANT_STATUT_EDITION: // Attention à bien avoir généré le fournisseur de privilèges si vous utilisez la gestion des privilèges d'UnicaenAuth
                        return $this->assertStatutEdition($entity);
                }
            break;
        }
    }



    /* Vos autres tests */

    function assertStatutEdition(Statut $statut)
    {
        if ($statut->isAutres() || $statut->isNonAutorise()) {
            return false;
        }

        return true;
    }

}
 No newline at end of file
+32 −0
Changes for module/Intervenant/src/Assertion/StatutAssertionFactory.php: 32 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

namespace Intervenant\Assertion;

use Psr\Container\ContainerInterface;



/**
 * Description of StatutAssertionFactory
 *
 * @author Laurent Lécluse <laurent.lecluse at unicaen.fr>
 */
class StatutAssertionFactory
{

    /**
     * @param ContainerInterface $container
     * @param string             $requestedName
     * @param array|null         $options
     *
     * @return StatutAssertion
     */
    public function __invoke(ContainerInterface $container, $requestedName, $options = null): StatutAssertion
    {
        $assertion = new StatutAssertion;

        /* Injectez vos dépendances ICI */

        return $assertion;
    }
}
 No newline at end of file
+2 −3
Changes for module/Intervenant/src/Controller/StatutController.php: 2 added lines, 3 removed lines.
Original line number Diff line number Diff line
@@ -67,8 +67,7 @@ class StatutController extends AbstractController
            $title = 'Édition d\'un statut d\'intervenant';
        }

        $canEdit = $this->isAllowed(Privileges::getResourceId(Privileges::INTERVENANT_STATUT_EDITION));
        $canEdit = false;
        $canEdit = $this->isAllowed($statut, Privileges::INTERVENANT_STATUT_EDITION);
        if ($canEdit) {
            $form->bindRequestSave($statut, $this->getRequest(), function (Statut $si) {
                try {
@@ -89,7 +88,7 @@ class StatutController extends AbstractController
            $form->readOnly();
        }

        return compact('typesIntervenants', 'statut', 'statuts', 'form', 'title');
        return compact('typesIntervenants', 'canEdit', 'statut', 'statuts', 'form', 'title');
    }


Loading