3 +--------------------------------------------------------------------+
4 | Copyright CiviCRM LLC. All rights reserved. |
6 | This work is published under the GNU AGPLv3 license with some |
7 | permitted exceptions and without any warranty. For full license |
8 | and copyright information, see https://civicrm.org/licensing |
9 +--------------------------------------------------------------------+
15 * @copyright CiviCRM LLC https://civicrm.org/licensing
20 * The various type of permissions.
32 * Given a permission string, check for access requirements
35 * The permission to check.
36 * @param int|null $contactID
37 * The contactID for whom the check is made.
40 * true if yes, else false
44 public static function check($str, $contactID = NULL) {
45 \CRM_Core_Error
::deprecatedWarning(__CLASS__
. '::' . __FUNCTION__
. ' is deprecated.');
46 if ($contactID == NULL) {
47 $contactID = CRM_Core_Session
::getLoggedInContactID();
55 return CRM_ACL_BAO_ACL
::check($str, $contactID);
59 * Get the permissioned where clause for the user.
62 * The type of permission needed.
63 * @param array $tables
64 * (reference ) add the tables that are needed for the select clause.
65 * @param array $whereTables
66 * (reference ) add the tables that are needed for the where clause.
67 * @param int|null $contactID
68 * The contactID for whom the check is made.
69 * @param bool $onlyDeleted
70 * Whether to include only deleted contacts.
71 * @param bool $skipDeleteClause
72 * Don't add delete clause if this is true,.
73 * this means it is handled by generating query
74 * @param bool $skipOwnContactClause
75 * Do not add 'OR contact_id = $userID' to the where clause.
76 * This is a hideously inefficient query and should be avoided
80 * the group where clause for this user
82 public static function whereClause(
88 $skipDeleteClause = FALSE,
89 $skipOwnContactClause = FALSE
91 // the default value which is valid for the final AND
92 $deleteClause = ' ( 1 ) ';
93 if (!$skipDeleteClause) {
94 if (CRM_Core_Permission
::check('access deleted contacts')) {
96 $deleteClause = '(contact_a.is_deleted)';
100 // Exclude deleted contacts due to permissions
101 $deleteClause = '(contact_a.is_deleted = 0)';
106 $contactID = CRM_Core_Session
::getLoggedInContactID();
108 $contactID = (int) $contactID;
110 // first see if the contact has edit / view all permission
111 if (CRM_Core_Permission
::check('edit all contacts', $contactID) ||
112 ($type == self
::VIEW
&& CRM_Core_Permission
::check('view all contacts', $contactID))
114 return $deleteClause;
117 $whereClause = CRM_ACL_BAO_ACL
::whereClause($type,
122 $where = implode(' AND ', [$whereClause, $deleteClause]);
124 // Add permission on self if we really hate our server or have hardly any contacts.
125 if (!$skipOwnContactClause && $contactID && (CRM_Core_Permission
::check('edit my contact') ||
126 $type == self
::VIEW
&& CRM_Core_Permission
::check('view my contact'))
128 $where = "(contact_a.id = $contactID OR ($where))";
134 * Get all the groups the user has access to for the given operation.
137 * The type of permission needed.
138 * @param int|null $contactID
139 * The contactID for whom the check is made.
141 * @param string $tableName
142 * @param array|null $allGroups
143 * @param array|null $includedGroups
146 * the ids of the groups for which the user has permissions
148 public static function group(
151 $tableName = 'civicrm_saved_search',
153 $includedGroups = NULL
155 if ($contactID == NULL) {
156 $contactID = CRM_Core_Session
::getLoggedInContactID();
159 return CRM_ACL_BAO_ACL
::group($type, (int) $contactID, $tableName, $allGroups, $includedGroups);
163 * Check if the user has access to this group for operation $type
166 * The type of permission needed.
167 * @param int $groupID
168 * @param int|null $contactID
169 * The contactID for whom the check is made.
170 * @param string $tableName
171 * @param array|null $allGroups
172 * @param array|null $includedGroups
176 public static function groupPermission(
180 $tableName = 'civicrm_saved_search',
182 $includedGroups = NULL
185 if (!isset(Civi
::$statics[__CLASS__
]) ||
!isset(Civi
::$statics[__CLASS__
]['group_permission'])) {
186 Civi
::$statics[__CLASS__
]['group_permission'] = [];
190 $contactID = CRM_Core_Session
::getLoggedInContactID();
193 $key = "{$tableName}_{$type}_{$contactID}";
194 if (!array_key_exists($key, Civi
::$statics[__CLASS__
]['group_permission'])) {
195 Civi
::$statics[__CLASS__
]['group_permission'][$key] = self
::group($type, $contactID, $tableName, $allGroups, $includedGroups);
198 return in_array($groupID, Civi
::$statics[__CLASS__
]['group_permission'][$key]);