00001 <?php
00002
00003
00004
00005
00006
00007
00008
00009
00010
00011
00012
00013
00014
00015
00016
00017
00018
00019
00020
00021
00022
00023
00024
00025
00026
00027
00028
00029
00030
00031
00032
00033
00034
00035 class Mage_Api_Model_Mysql4_Acl extends Mage_Core_Model_Mysql4_Abstract
00036 {
00037
00038
00039
00040
00041
00042 protected function _construct()
00043 {
00044 $this->_init('api/role', 'role_id');
00045 }
00046
00047
00048
00049
00050
00051
00052
00053 function loadAcl()
00054 {
00055 $acl = Mage::getModel('api/acl');
00056
00057 Mage::getSingleton('api/config')->loadAclResources($acl);
00058
00059 $roleTable = Mage::getSingleton('core/resource')->getTableName('api/role');
00060 $rolesArr = $this->_getReadAdapter()->fetchAll(
00061 $this->_getReadAdapter()->select()
00062 ->from($this->getTable('role'))
00063 ->order('tree_level')
00064 );
00065 $this->loadRoles($acl, $rolesArr);
00066
00067 $rulesArr = $this->_getReadAdapter()->fetchAll(
00068 $this->_getReadAdapter()->select()
00069 ->from(array('r'=>$this->getTable('rule')))
00070 ->joinLeft(
00071 array('a'=>$this->getTable('assert')),
00072 'a.assert_id=r.assert_id',
00073 array('assert_type', 'assert_data')
00074 ));
00075 $this->loadRules($acl, $rulesArr);
00076 return $acl;
00077 }
00078
00079
00080
00081
00082
00083
00084
00085
00086 function loadRoles(Mage_Api_Model_Acl $acl, array $rolesArr)
00087 {
00088 foreach ($rolesArr as $role) {
00089 $parent = $role['parent_id']>0 ? Mage_Api_Model_Acl::ROLE_TYPE_GROUP.$role['parent_id'] : null;
00090 switch ($role['role_type']) {
00091 case Mage_Api_Model_Acl::ROLE_TYPE_GROUP:
00092 $roleId = $role['role_type'].$role['role_id'];
00093 $acl->addRole(Mage::getModel('api/acl_role_group', $roleId), $parent);
00094 break;
00095
00096 case Mage_Api_Model_Acl::ROLE_TYPE_USER:
00097 $roleId = $role['role_type'].$role['user_id'];
00098 if (!$acl->hasRole($roleId)) {
00099 $acl->addRole(Mage::getModel('api/acl_role_user', $roleId), $parent);
00100 } else {
00101 $acl->addRoleParent($roleId, $parent);
00102 }
00103 break;
00104 }
00105 }
00106
00107 return $this;
00108 }
00109
00110
00111
00112
00113
00114
00115
00116
00117 function loadRules(Mage_Api_Model_Acl $acl, array $rulesArr)
00118 {
00119 foreach ($rulesArr as $rule) {
00120 $role = $rule['role_type'].$rule['role_id'];
00121 $resource = $rule['resource_id'];
00122 $privileges = !empty($rule['privileges']) ? explode(',', $rule['privileges']) : null;
00123
00124 $assert = null;
00125 if (0!=$rule['assert_id']) {
00126 $assertClass = Mage::getSingleton('api/config')->getAclAssert($rule['assert_type'])->getClassName();
00127 $assert = new $assertClass(unserialize($rule['assert_data']));
00128 }
00129 try {
00130 if ( $rule['permission'] == 'allow' ) {
00131 $acl->allow($role, $resource, $privileges, $assert);
00132 } else if ( $rule['permission'] == 'deny' ) {
00133 $acl->deny($role, $resource, $privileges, $assert);
00134 }
00135 } catch (Exception $e) {
00136
00137
00138
00139
00140
00141
00142
00143
00144 }
00145
00146
00147
00148
00149
00150
00151
00152
00153
00154
00155
00156 }
00157 return $this;
00158 }
00159
00160 }