Commit 102a36dc authored by Thomas Hamel's avatar Thomas Hamel
Browse files

Ajout de AutorisationInscriptionAssertion

parent 0e8e4ac1
Loading
Loading
Loading
Loading
+57 −0
Changes for doc/release-notes/8.x.0/01_saisie_these.sql: 57 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -653,3 +653,60 @@ from PROFIL_TO_ROLE p2r
         join PROFIL_PRIVILEGE pp on pp.PROFIL_ID = pr.id
where not exists (select * from role_privilege where role_id = p2r.role_id and privilege_id = pp.privilege_id)
;

--
-- Nouvelle catégorie de privilèges : AutorisationInscription.
--
INSERT INTO CATEGORIE_PRIVILEGE (ID, CODE, LIBELLE, ORDRE)
SELECT nextval('categorie_privilege_id_seq'), 'autorisation-inscription', 'Autorisation d''inscription', 11020
    WHERE NOT EXISTS (SELECT 1
                  FROM CATEGORIE_PRIVILEGE
                  WHERE CODE = 'autorisation-inscription');

insert into PRIVILEGE(ID, CATEGORIE_ID, CODE, LIBELLE, ORDRE)
with d(ordre, code, lib) as (select 1,
                                    'ajouter',
                                    'Ajouter (ou non) une autorisation d''inscription sur l''année suivante')
select nextval('privilege_id_seq'), cp.id, d.code, d.lib, d.ordre
from d
         join CATEGORIE_PRIVILEGE cp on cp.CODE = 'autorisation-inscription'
WHERE NOT EXISTS (SELECT 1
                  FROM PRIVILEGE p
                  WHERE p.CODE = d.code);

-- Ajout du privilège pour le responsable d'ED/Admin tech pour ajouter une autorisation d'inscription
INSERT INTO PROFIL_PRIVILEGE (PRIVILEGE_ID, PROFIL_ID)
with data(categ, priv) as (select 'autorisation-inscription', 'ajouter')
select p.id as PRIVILEGE_ID, profil.id as PROFIL_ID
from data
         join PROFIL on profil.ROLE_ID in (
                                           'RESP_ED',
                                           'ADMIN_TECH'
    )
         join CATEGORIE_PRIVILEGE cp on cp.CODE = data.categ
         join PRIVILEGE p on p.CATEGORIE_ID = cp.id and p.code = data.priv
where not exists (select * from PROFIL_PRIVILEGE where PRIVILEGE_ID = p.id and PROFIL_ID = profil.id);

insert into ROLE_PRIVILEGE (ROLE_ID, PRIVILEGE_ID)
select p2r.ROLE_ID, pp.PRIVILEGE_ID
from PROFIL_TO_ROLE p2r
         join profil pr on pr.id = p2r.PROFIL_ID
         join PROFIL_PRIVILEGE pp on pp.PROFIL_ID = pr.id
where not exists (select * from role_privilege where role_id = p2r.role_id and privilege_id = pp.privilege_id)
;

-- Suppression du privilège pour le RESP_ED de supprimer un rapport CSI
DELETE
from role_privilege
where privilege_id in (select id from privilege where code LIKE 'supprimer-sien' and categorie_id in (select id from categorie_privilege where code LIKE 'rapport-csi'))
  and role_id in (select id from role where code LIKE 'RESP_ED');

delete from profil_privilege pp1
where exists (
    select *
    from profil_privilege pp
             join profil on pp.profil_id = profil.id and role_id in ('RESP_ED')
             join privilege p on pp.privilege_id = p.id
    where p.code in ('supprimer-sien') and categorie_id in (select id from categorie_privilege where code LIKE 'rapport-csi')
      and pp.profil_id = pp1.profil_id and pp.privilege_id = pp1.privilege_id
);
 No newline at end of file
+10 −27
Changes for module/Application/config/others/autorisation-inscription.config.php: 10 added lines, 27 removed lines.
Original line number Diff line number Diff line
@@ -2,11 +2,13 @@

namespace Application;

use Application\Assertion\AutorisationInscription\AutorisationInscriptionAssertion;
use Application\Assertion\AutorisationInscription\AutorisationInscriptionAssertionFactory;
use Application\Controller\AutorisationInscriptionController;
use Application\Controller\Factory\AutorisationInscriptionControllerFactory;
use Application\Form\AutorisationInscriptionForm;
use Application\Form\Factory\AutorisationInscriptionFormFactory;
use Application\Provider\Privilege\RapportPrivileges;
use Application\Provider\Privilege\AutorisationInscriptionPrivileges;
use Application\Service\AutorisationInscription\AutorisationInscriptionService;
use Application\Service\AutorisationInscription\AutorisationInscriptionServiceFactory;
use UnicaenAuth\Guard\PrivilegeController;
@@ -24,28 +26,10 @@ return [
                'allow' => [
                    [
                        'privileges' => [
                            RapportPrivileges::RAPPORT_CSI_LISTER_TOUT,
                            RapportPrivileges::RAPPORT_CSI_LISTER_SIEN,
                            RapportPrivileges::RAPPORT_CSI_TELEVERSER_TOUT,
                            RapportPrivileges::RAPPORT_CSI_TELEVERSER_SIEN,
                            RapportPrivileges::RAPPORT_CSI_SUPPRIMER_SIEN,
                            RapportPrivileges::RAPPORT_CSI_SUPPRIMER_TOUT,
                            RapportPrivileges::RAPPORT_CSI_RECHERCHER_SIEN,
                            RapportPrivileges::RAPPORT_CSI_TELECHARGER_TOUT,
                            RapportPrivileges::RAPPORT_CSI_TELECHARGER_SIEN,

                            RapportPrivileges::RAPPORT_MIPARCOURS_LISTER_TOUT,
                            RapportPrivileges::RAPPORT_MIPARCOURS_LISTER_SIEN,
                            RapportPrivileges::RAPPORT_MIPARCOURS_TELEVERSER_TOUT,
                            RapportPrivileges::RAPPORT_MIPARCOURS_TELEVERSER_SIEN,
                            RapportPrivileges::RAPPORT_MIPARCOURS_SUPPRIMER_SIEN,
                            RapportPrivileges::RAPPORT_MIPARCOURS_SUPPRIMER_TOUT,
                            RapportPrivileges::RAPPORT_MIPARCOURS_RECHERCHER_SIEN,
                            RapportPrivileges::RAPPORT_MIPARCOURS_TELECHARGER_TOUT,
                            RapportPrivileges::RAPPORT_MIPARCOURS_TELECHARGER_SIEN,
                            AutorisationInscriptionPrivileges::AUTORISATION_INSCRIPTION_AJOUTER,
                        ],
                        'resources'  => ['Rapport'],
                        'assertion' => 'Assertion\\Rapport', /** @see RapportAssertion */
                        'resources'  => ['AutorisationInscription'],
                        'assertion' => AutorisationInscriptionAssertion::class,
                    ],
                ],
            ],
@@ -55,14 +39,12 @@ return [
                [
                    'controller' => AutorisationInscriptionController::class,
                    'action'     => [
                        'autoriser-inscription', // à modifier ensuite,
                        'ajouter'
                    ],
                    'privileges' => [
                        RapportPrivileges::RAPPORT_CSI_LISTER_TOUT,
                        RapportPrivileges::RAPPORT_CSI_LISTER_SIEN,
                        AutorisationInscriptionPrivileges::AUTORISATION_INSCRIPTION_AJOUTER,
                    ],
                    'assertion' => 'Assertion\\Rapport',
                    'assertion' => AutorisationInscriptionAssertion::class,
                ],
            ],
        ],
@@ -99,7 +81,8 @@ return [

    'service_manager' => [
        'factories' => [
            AutorisationInscriptionService::class => AutorisationInscriptionServiceFactory::class
            AutorisationInscriptionService::class => AutorisationInscriptionServiceFactory::class,
            AutorisationInscriptionAssertion::class => AutorisationInscriptionAssertionFactory::class
        ],
    ],
    'controllers' => [
+143 −0
Changes for module/Application/src/Application/Assertion/AutorisationInscription/AutorisationInscriptionAssertion.php: 143 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

namespace Application\Assertion\AutorisationInscription;

use Application\Assertion\AbstractAssertion;
use Application\Assertion\Exception\FailedAssertionException;
use Application\Assertion\ThrowsFailedAssertionExceptionTrait;
use Application\Entity\AnneeUniv;
use Application\Entity\Db\AutorisationInscription;
use Application\Entity\Db\Rapport;
use Application\Provider\Privilege\AutorisationInscriptionPrivileges;
use Application\Service\AutorisationInscription\AutorisationInscriptionServiceAwareTrait;
use Application\Service\Rapport\RapportServiceAwareTrait;
use Application\Service\UserContextServiceAwareInterface;
use Application\Service\UserContextServiceAwareTrait;
use Laminas\Permissions\Acl\Resource\ResourceInterface;
use These\Entity\Db\These;
use These\Entity\Db\TheseAnneeUniv;
use UnicaenApp\Service\MessageCollectorAwareInterface;
use UnicaenApp\Service\MessageCollectorAwareTrait;

class AutorisationInscriptionAssertion extends AbstractAssertion implements UserContextServiceAwareInterface, MessageCollectorAwareInterface
{
    use ThrowsFailedAssertionExceptionTrait;
    use MessageCollectorAwareTrait;
    use UserContextServiceAwareTrait;
    use AutorisationInscriptionServiceAwareTrait;
    use RapportServiceAwareTrait;

    private ?AutorisationInscription $autorisationInscription = null;
    private ?Rapport $rapport = null;

    /**
     * @param array $page
     * @return bool
     */
    public function __invoke(array $page): bool
    {
        return $this->assertPage($page);
    }

    /**
     * @param array $page
     * @return bool
     */
    private function assertPage(array $page): bool
    {
        return true;
    }

    /**
     * @param string $controller
     * @param string $action
     * @param string $privilege
     * @return boolean
     */
    protected function assertController($controller, $action = null, $privilege = null): bool
    {
        if (!parent::assertController($controller, $action, $privilege)) {
            return false;
        }

        $this->getRequestedAutorisationInscription();
        $these = $this->rapport?->getThese();
        try {
            if ($action == 'ajouter') {
                if ($this->autorisationInscription === null) {
                    if ($roleEcoleDoctorale = $this->userContextService->getSelectedRoleEcoleDoctorale()) {
                        $this->assertTrue(
                            $these->getEcoleDoctorale()->getStructure()->getId() === $roleEcoleDoctorale->getStructure()->getId(),
                            "La thèse n'est pas rattachée à l'ED " . $roleEcoleDoctorale->getStructure()->getCode()
                        );
                    }
                    return $this->canAjouterAutorisationInscription($these);
                }
            }
        } catch (FailedAssertionException $e) {
            if ($e->getMessage()) {
                $this->getServiceMessageCollector()->addMessage($e->getMessage(), __CLASS__);
            }
            return false;
        }

        return true;
    }

    /**
     * @param AutorisationInscription $entity
     * @param string $privilege
     * @return boolean
     */
    protected function assertEntity(ResourceInterface $entity, $privilege = null): bool
    {
        if (!parent::assertEntity($entity, $privilege)) {
            return false;
        }

        $this->autorisationInscription = $entity;

        try {
            switch ($privilege) {
                case AutorisationInscriptionPrivileges::AUTORISATION_INSCRIPTION_AJOUTER:
                    if($this->autorisationInscription->getId()) return false;
                    $this->rapport = $this->autorisationInscription->getRapport();
                    $these = $this->rapport?->getThese();
                    if ($roleEcoleDoctorale = $this->userContextService->getSelectedRoleEcoleDoctorale()) {
                        $this->assertTrue(
                            $these->getEcoleDoctorale()->getStructure()->getId() === $roleEcoleDoctorale->getStructure()->getId(),
                            "La thèse n'est pas rattachée à l'ED " . $roleEcoleDoctorale->getStructure()->getCode()
                        );
                    }
                    return $this->canAjouterAutorisationInscription($these);
            }

        } catch (FailedAssertionException $e) {
            if ($e->getMessage()) {
                $this->getServiceMessageCollector()->addMessage($e->getMessage(), __CLASS__);
            }
            return false;
        }
        return true;
    }

    private function canAjouterAutorisationInscription(These $these): bool
    {
        $anneesInscriptionThese = array_map(function(TheseAnneeUniv $anneeUniv) {
            return $anneeUniv->getPremiereAnnee();
        },  $these->getAnneesUnivInscription()->toArray());
        $derniereAnneeUnivInscription = AnneeUniv::fromPremiereAnnee(max($anneesInscriptionThese));
        return $derniereAnneeUnivInscription === $this->rapport->getAnneeUniv();
    }

    private function getRequestedAutorisationInscription(): ?AutorisationInscription
    {
        $autorisationInscription = null;
        if (($routeMatch = $this->getRouteMatch()) && $id = $routeMatch->getParam('rapport')) {
            $autorisationInscription = $this->autorisationInscriptionService->getRepository()->findOneBy(["rapport" => $id]);
            $this->rapport = $this->rapportService->getRepository()->find($id);
        }

        return $autorisationInscription;
    }
}
 No newline at end of file
+50 −0
Changes for module/Application/src/Application/Assertion/AutorisationInscription/AutorisationInscriptionAssertionFactory.php: 50 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

namespace Application\Assertion\AutorisationInscription;

use Application\Assertion\AbstractAssertion;
use Application\Service\AutorisationInscription\AutorisationInscriptionService;
use Application\Service\Rapport\RapportService;
use Individu\Service\IndividuService;
use Psr\Container\ContainerExceptionInterface;
use Psr\Container\ContainerInterface;
use Psr\Container\NotFoundExceptionInterface;

class AutorisationInscriptionAssertionFactory
{
    /**
     * @throws ContainerExceptionInterface
     * @throws NotFoundExceptionInterface
     */
    public function __invoke(ContainerInterface $container): AutorisationInscriptionAssertion
    {
        $userContext = $container->get('UnicaenAuth\Service\UserContext');
        $autorisationInscriptionService = $container->get(AutorisationInscriptionService::class);
        $rapportService = $container->get(RapportService::class);
        $messageCollector = $container->get('MessageCollector');

        /** @var  $assertion */
        $assertion = new AutorisationInscriptionAssertion();
        $assertion->setUserContextService($userContext);
        $assertion->setAutorisationInscriptionService($autorisationInscriptionService);
        $assertion->setRapportService($rapportService);
        $assertion->setServiceMessageCollector($messageCollector);

        $this->injectCommons($assertion, $container);

        return $assertion;
    }

    /**
     * @throws NotFoundExceptionInterface
     * @throws ContainerExceptionInterface
     */
    protected function injectCommons(AbstractAssertion $assertion, ContainerInterface $container)
    {
        $authorizeService = $container->get('BjyAuthorize\Service\Authorize');
        $mvcEvent = $container->get('Application')->getMvcEvent();

        $assertion->setServiceAuthorize($authorizeService);
        $assertion->setMvcEvent($mvcEvent);
    }
}
 No newline at end of file
+10 −0
Changes for module/Application/src/Application/Provider/Privilege/AutorisationInscriptionPrivileges.php: 10 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

namespace Application\Provider\Privilege;

use UnicaenAuth\Provider\Privilege\Privileges;

class AutorisationInscriptionPrivileges extends Privileges
{
    const AUTORISATION_INSCRIPTION_AJOUTER = 'autorisation-inscription-ajouter';
}
Loading