Commit 9c24f20b authored by Jean-Philippe Metivier's avatar Jean-Philippe Metivier
Browse files

Protection à l'aide des gardes et des privilièges

parent 76dd9a17
Loading
Loading
Loading
Loading
Loading
+13 −2
Changes for module/Application/config/others/admin.config.php: 13 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -6,7 +6,7 @@ use Application\Provider\Privilege\UtilisateurPrivileges;
use UnicaenAuth\Guard\PrivilegeController;
use Zend\Mvc\Router\Http\Literal;
use Zend\Mvc\Router\Http\Segment;

use UnicaenAuth\Provider\Privilege\Privileges;
return [
    'bjyauthorize'    => [
        'guards' => [
@@ -22,9 +22,20 @@ return [
                    'controller' => 'Application\Controller\Role',
                    'action'     => [
                        'index',
                    ],
                    'privileges' => [
                        Privileges::DROIT_PRIVILEGE_VISUALISATION,
                        Privileges::DROIT_PRIVILEGE_EDITION,
                    ],
                ],
                [
                    'controller' => 'Application\Controller\Role',
                    'action'     => [
                        'modifier',
                    ],
                    'privileges' => UtilisateurPrivileges::UTILISATEUR_ATTRIBUTION_ROLE,
                    'privileges' => [
                        Privileges::DROIT_PRIVILEGE_EDITION,
                    ],
                ],
                [
                    'controller' => 'UnicaenApp\Controller\Application',
+33 −5
Changes for module/Application/view/application/role/index.phtml: 33 added lines, 5 removed lines.
Original line number Diff line number Diff line
<?php
    use Application\Entity\Db\Role;
    use Application\Entity\Db\Privilege;
    use UnicaenAuth\Provider\Privilege\Privileges;


    $canVisualiser = $this->isAllowed(Privileges::getResourceId(Privileges::DROIT_PRIVILEGE_VISUALISATION));
    $canModifier = $this->isAllowed(Privileges::getResourceId(Privileges::DROIT_PRIVILEGE_EDITION));

//    var_dump($canVisualiser);
//    var_dump($canModifier);

/**
 * //Provenant du controleur
@@ -14,6 +22,7 @@
?>



<?php $this->headTitle($this->translate("Rôles/Privilèges")) ?>
<h1 class="page-header first"><?php echo $this->translate("Rôles/Privilèges") ?>

@@ -23,25 +32,36 @@
        <?php echo $this->partial('partial/form-filtrage') ?>
    </div>

    <div class="pull-right">
        Structure
        <select>
            <option value = "AAA"> <span class="ur"> Ma petite UR</span></option>
            <option value = "BBB"> <span class="ed"> Ma petite ED</span></option>
            <option value = "EEE"> <span class="etab"> Mon Univ</span></option>
        </select>
    </div>

<?php

echo "<p>";
echo "<table id='mytable' class='mytable table-bordered'>";
echo "<tr><th></th>";
echo "<thead>";
echo "<tr class='ttt'><th></th>";

foreach($roles as $role) {
    echo generateTableHeaderRole($role, $etablissements);
}
echo "</tr>";

echo "</thead>";
echo "<tbody>";

$previous_categorie = null;
foreach($privileges as $privilege) {
    if ($previous_categorie !== $privilege->getCategorie()) {
        echo "<tr><th colspan='1000' class='categorie'>".$privilege->getCategorie()->getLibelle()."</th></tr>";
        echo "<tr class='ttt'><th colspan='1000' class='categorie'>".$privilege->getCategorie()->getLibelle()."</th></tr>";
        $previous_categorie = $privilege->getCategorie();
    }
    echo "<tr>";
    echo "<tr class='ttt'>";
    echo "<th class='privilege'> {$privilege->getLibelle()} </th>";
    foreach($roles as $role) {

@@ -62,12 +82,21 @@ foreach($privileges as $privilege) {
    }
    echo "</tr>";
}
echo "</tbody>";
echo "</table>";
echo "</p>";
?>

<script>
    $(document).ready(function() {
        $("td").click(function() {

            var canModifier =  Boolean(<?php echo $canModifier; ?>);
            if (!canModifier) {
                alert("Vous n'êtes pas autorisé à modifier les privilèges associés à un rôle.");
                return;
            }

            var id = $(this).attr("id");
            var splits = id.split("_");
            var role = splits[1];
@@ -221,5 +250,4 @@ echo "</table>";
    td.droit :hover {
        cursor:pointer;
    }

</style>
 No newline at end of file
+6 −6
Changes for module/Application/view/application/role/partial/form-filtrage.phtml: 6 added lines, 6 removed lines.
Original line number Diff line number Diff line
@@ -44,14 +44,14 @@ echo $this->filterPanel([
            ['value' => '',                             'label' => $this->translate(" - ") ],
            ['value' => $v = "droit",                   'label' => $this->translate("Droit") ],
            ['value' => $v = "import",                  'label' => $this->translate("Import") ],
            ['value' => $v = "these",                  'label' => $this->translate("these") ],
            ['value' => $v = "utilisateur",                  'label' => $this->translate("utilisateur") ],
            ['value' => $v = "doctorant",                  'label' => $this->translate("doctorant") ],
            ['value' => $v = "these",                   'label' => $this->translate("These") ],
            ['value' => $v = "utilisateur",             'label' => $this->translate("Utilisateur") ],
            ['value' => $v = "doctorant",               'label' => $this->translate("Doctorant") ],
            ['value' => $v = "ecole-doctorale",         'label' => $this->translate("École doctorale") ],
            ['value' => $v = "unite-recherche",         'label' => $this->translate("Unité de recherche") ],
            ['value' => $v = "etablissement",                    'label' => $this->translate("Établissement") ],
            ['value' => $v = "validation",                    'label' => $this->translate("validation") ],
            ['value' => $v = "fichier-divers",                    'label' => $this->translate("fichier-divers") ],
//            ['value' => $v = "etablissement",           'label' => $this->translate("Établissement") ],
            ['value' => $v = "validation",              'label' => $this->translate("Validation") ],
            ['value' => $v = "fichier-divers",          'label' => $this->translate("Fichier") ],
            ['value' => $v = "faq",                     'label' => $this->translate("FAQ") ],

        ],