3 +--------------------------------------------------------------------+
4 | CiviCRM version 4.4 |
5 +--------------------------------------------------------------------+
6 | Copyright CiviCRM LLC (c) 2004-2013 |
7 +--------------------------------------------------------------------+
8 | This file is a part of CiviCRM. |
10 | CiviCRM is free software; you can copy, modify, and distribute it |
11 | under the terms of the GNU Affero General Public License |
12 | Version 3, 19 November 2007 and the CiviCRM Licensing Exception. |
14 | CiviCRM is distributed in the hope that it will be useful, but |
15 | WITHOUT ANY WARRANTY; without even the implied warranty of |
16 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
17 | See the GNU Affero General Public License for more details. |
19 | You should have received a copy of the GNU Affero General Public |
20 | License and the CiviCRM Licensing Exception along |
21 | with this program; if not, contact CiviCRM LLC |
22 | at info[AT]civicrm[DOT]org. If you have questions about the |
23 | GNU Affero General Public License or the licensing of CiviCRM, |
24 | see the CiviCRM license FAQ at http://civicrm.org/licensing |
25 +--------------------------------------------------------------------+
31 * @copyright CiviCRM LLC (c) 2004-2013
38 * The various type of permissions
50 * given a permission string, check for access requirements
52 * @param string $str the permission to check
53 * @param int $contactID the contactID for whom the check is made
55 * @return boolean true if yes, else false
59 static function check($str, $contactID = NULL) {
60 if ($contactID == NULL) {
61 $session = CRM_Core_Session
::singleton();
62 $contactID = $session->get('userID');
70 return CRM_ACL_BAO_ACL
::check($str, $contactID);
74 * Get the permissioned where clause for the user
76 * @param int $type the type of permission needed
77 * @param array $tables (reference ) add the tables that are needed for the select clause
78 * @param array $whereTables (reference ) add the tables that are needed for the where clause
79 * @param int $contactID the contactID for whom the check is made
80 * @param bool $onlyDeleted whether to include only deleted contacts
81 * @param bool $skipDeleteClause don't add delete clause if this is true,
82 * this means it is handled by generating query
84 * @return string the group where clause for this user
87 public static function whereClause($type,
92 $skipDeleteClause = FALSE
94 // the default value which is valid for rhe final AND
95 $deleteClause = ' ( 1 ) ';
96 if (!$skipDeleteClause) {
97 if (CRM_Core_Permission
::check('access deleted contacts') and $onlyDeleted) {
98 $deleteClause = '(contact_a.is_deleted)';
102 $deleteClause = '(contact_a.is_deleted = 0)';
106 // first see if the contact has edit / view all contacts
107 if (CRM_Core_Permission
::check('edit all contacts') ||
108 ($type == self
::VIEW
&&
109 CRM_Core_Permission
::check('view all contacts')
112 return $skipDeleteClause ?
' ( 1 ) ' : $deleteClause;
115 if ($contactID == NULL) {
116 $session = CRM_Core_Session
::singleton();
117 $contactID = $session->get('userID');
125 return implode(' AND ',
127 CRM_ACL_BAO_ACL
::whereClause($type,
138 * get all the groups the user has access to for the given operation
140 * @param int $type the type of permission needed
141 * @param int $contactID the contactID for whom the check is made
143 * @return array the ids of the groups for which the user has permissions
146 public static function group(
149 $tableName = 'civicrm_saved_search',
151 $includedGroups = NULL
153 if ($contactID == NULL) {
154 $session = CRM_Core_Session
::singleton();
155 $contactID = $session->get('userID');
163 return CRM_ACL_BAO_ACL
::group($type, $contactID, $tableName, $allGroups, $includedGroups);
167 * check if the user has access to this group for operation $type
169 * @param int $type the type of permission needed
170 * @param int $contactID the contactID for whom the check is made
172 * @return array the ids of the groups for which the user has permissions
175 public static function groupPermission(
179 $tableName = 'civicrm_saved_search',
181 $includedGroups = NULL
183 static $cache = array();
186 $session = CRM_Core_Session
::singleton();
188 if ($session->get('userID')) {
189 $contactID = $session->get('userID');
193 $key = "{$tableName}_{$type}_{$contactID}";
194 if (array_key_exists($key, $cache)) {
195 $groups = &$cache[$key];
198 $groups = self
::group($type, $contactID, $tableName, $allGroups, $includedGroups);
199 $cache[$key] = $groups;
202 return in_array($groupID, $groups) ?
TRUE : FALSE;