00001 <?php
00002
00003
00004
00005
00006
00007
00008
00009
00010
00011
00012
00013
00014
00015
00016
00017
00018
00019
00020
00021
00022
00023
00024
00025
00026
00027
00028
00029
00030
00031
00032
00033
00034
00035 class Mage_Admin_Model_Mysql4_Acl
00036 {
00037 const ACL_ALL_RULES = 'all';
00038
00039
00040
00041
00042
00043
00044 protected $_read;
00045
00046
00047
00048
00049
00050
00051 protected $_write;
00052
00053
00054
00055
00056
00057 function __construct()
00058 {
00059 $this->_read = Mage::getSingleton('core/resource')->getConnection('admin_read');
00060 $this->_write = Mage::getSingleton('core/resource')->getConnection('admin_write');
00061 }
00062
00063
00064
00065
00066
00067
00068
00069 function loadAcl()
00070 {
00071 $acl = Mage::getModel('admin/acl');
00072
00073 Mage::getSingleton('admin/config')->loadAclResources($acl);
00074
00075 $roleTable = Mage::getSingleton('core/resource')->getTableName('admin/role');
00076 $rolesArr = $this->_read->fetchAll("select * from $roleTable order by tree_level");
00077 $this->loadRoles($acl, $rolesArr);
00078
00079 $ruleTable = Mage::getSingleton('core/resource')->getTableName('admin/rule');
00080 $assertTable = Mage::getSingleton('core/resource')->getTableName('admin/assert');
00081 $rulesArr = $this->_read->fetchAll("select r.*, a.assert_type, a.assert_data
00082 from $ruleTable r left join $assertTable a on a.assert_id=r.assert_id");
00083 $this->loadRules($acl, $rulesArr);
00084
00085 return $acl;
00086 }
00087
00088
00089
00090
00091
00092
00093
00094
00095 function loadRoles(Mage_Admin_Model_Acl $acl, array $rolesArr)
00096 {
00097 foreach ($rolesArr as $role) {
00098 $parent = $role['parent_id']>0 ? Mage_Admin_Model_Acl::ROLE_TYPE_GROUP.$role['parent_id'] : null;
00099 switch ($role['role_type']) {
00100 case Mage_Admin_Model_Acl::ROLE_TYPE_GROUP:
00101 $roleId = $role['role_type'].$role['role_id'];
00102 $acl->addRole(Mage::getModel('admin/acl_role_group', $roleId), $parent);
00103 break;
00104
00105 case Mage_Admin_Model_Acl::ROLE_TYPE_USER:
00106 $roleId = $role['role_type'].$role['user_id'];
00107 if (!$acl->hasRole($roleId)) {
00108 $acl->addRole(Mage::getModel('admin/acl_role_user', $roleId), $parent);
00109 } else {
00110 $acl->addRoleParent($roleId, $parent);
00111 }
00112 break;
00113 }
00114 }
00115
00116 return $this;
00117 }
00118
00119
00120
00121
00122
00123
00124
00125
00126 function loadRules(Mage_Admin_Model_Acl $acl, array $rulesArr)
00127 {
00128 foreach ($rulesArr as $rule) {
00129 $role = $rule['role_type'].$rule['role_id'];
00130 $resource = $rule['resource_id'];
00131 $privileges = !empty($rule['privileges']) ? explode(',', $rule['privileges']) : null;
00132
00133 $assert = null;
00134 if (0!=$rule['assert_id']) {
00135 $assertClass = Mage::getSingleton('admin/config')->getAclAssert($rule['assert_type'])->getClassName();
00136 $assert = new $assertClass(unserialize($rule['assert_data']));
00137 }
00138 try {
00139 if ( $rule['permission'] == 'allow' ) {
00140 if ($resource === self::ACL_ALL_RULES) {
00141 $acl->allow($role, null, $privileges, $assert);
00142 }
00143 $acl->allow($role, $resource, $privileges, $assert);
00144 } else if ( $rule['permission'] == 'deny' ) {
00145 $acl->deny($role, $resource, $privileges, $assert);
00146 }
00147 } catch (Exception $e) {
00148
00149
00150
00151
00152
00153
00154
00155
00156 }
00157
00158
00159
00160
00161
00162
00163
00164
00165
00166
00167
00168 }
00169 return $this;
00170 }
00171
00172 }