PageRenderTime 43ms CodeModel.GetById 18ms RepoModel.GetById 0ms app.codeStats 0ms

/public/phpmyadmin/libraries/server_user_groups.lib.php

https://gitlab.com/qbarbosa/klindev
PHP | 359 lines | 273 code | 27 blank | 59 comment | 39 complexity | a5beb182f25fcd385307abd5cf79455a MD5 | raw file
  1. <?php
  2. /* vim: set expandtab sw=4 ts=4 sts=4: */
  3. /**
  4. * set of functions for user group handling
  5. *
  6. * @package PhpMyAdmin
  7. */
  8. if (! defined('PHPMYADMIN')) {
  9. exit;
  10. }
  11. /**
  12. * Return HTML to list the users belonging to a given user group
  13. *
  14. * @param string $userGroup user group name
  15. *
  16. * @return string HTML to list the users belonging to a given user group
  17. */
  18. function PMA_getHtmlForListingUsersofAGroup($userGroup)
  19. {
  20. $html_output = '<h2>'
  21. . sprintf(__('Users of \'%s\' user group'), htmlspecialchars($userGroup))
  22. . '</h2>';
  23. $cfgRelation = PMA_getRelationsParam();
  24. $usersTable = PMA_Util::backquote($cfgRelation['db'])
  25. . "." . PMA_Util::backquote($cfgRelation['users']);
  26. $sql_query = "SELECT `username` FROM " . $usersTable
  27. . " WHERE `usergroup`='" . PMA_Util::sqlAddSlashes($userGroup) . "'";
  28. $result = PMA_queryAsControlUser($sql_query, false);
  29. if ($result) {
  30. if ($GLOBALS['dbi']->numRows($result) == 0) {
  31. $html_output .= '<p>'
  32. . __('No users were found belonging to this user group.')
  33. . '</p>';
  34. } else {
  35. $html_output .= '<table>'
  36. . '<thead><tr><th>#</th><th>' . __('User') . '</th></tr></thead>'
  37. . '<tbody>';
  38. $i = 0;
  39. while ($row = $GLOBALS['dbi']->fetchRow($result)) {
  40. $i++;
  41. $html_output .= '<tr>'
  42. . '<td>' . $i . ' </td>'
  43. . '<td>' . htmlspecialchars($row[0]) . '</td>'
  44. . '</tr>';
  45. }
  46. $html_output .= '</tbody>'
  47. . '</table>';
  48. }
  49. }
  50. $GLOBALS['dbi']->freeResult($result);
  51. return $html_output;
  52. }
  53. /**
  54. * Returns HTML for the 'user groups' table
  55. *
  56. * @return string HTML for the 'user groups' table
  57. */
  58. function PMA_getHtmlForUserGroupsTable()
  59. {
  60. $html_output = '<h2>' . __('User groups') . '</h2>';
  61. $cfgRelation = PMA_getRelationsParam();
  62. $groupTable = PMA_Util::backquote($cfgRelation['db'])
  63. . "." . PMA_Util::backquote($cfgRelation['usergroups']);
  64. $sql_query = "SELECT * FROM " . $groupTable . " ORDER BY `usergroup` ASC";
  65. $result = PMA_queryAsControlUser($sql_query, false);
  66. if ($result && $GLOBALS['dbi']->numRows($result)) {
  67. $html_output .= '<form name="userGroupsForm" id="userGroupsForm"'
  68. . ' action="server_privileges.php" method="post">';
  69. $html_output .= PMA_URL_getHiddenInputs();
  70. $html_output .= '<table id="userGroupsTable">';
  71. $html_output .= '<thead><tr>';
  72. $html_output .= '<th style="white-space: nowrap">'
  73. . __('User group') . '</th>';
  74. $html_output .= '<th>' . __('Server level tabs') . '</th>';
  75. $html_output .= '<th>' . __('Database level tabs') . '</th>';
  76. $html_output .= '<th>' . __('Table level tabs') . '</th>';
  77. $html_output .= '<th>' . __('Action') . '</th>';
  78. $html_output .= '</tr></thead>';
  79. $html_output .= '<tbody>';
  80. $odd = true;
  81. $userGroups = array();
  82. while ($row = $GLOBALS['dbi']->fetchAssoc($result)) {
  83. $groupName = $row['usergroup'];
  84. if (! isset($userGroups[$groupName])) {
  85. $userGroups[$groupName] = array();
  86. }
  87. $userGroups[$groupName][$row['tab']] = $row['allowed'];
  88. }
  89. foreach ($userGroups as $groupName => $tabs) {
  90. $html_output .= '<tr class="' . ($odd ? 'odd' : 'even') . '">';
  91. $html_output .= '<td>' . htmlspecialchars($groupName) . '</td>';
  92. $html_output .= '<td>' . _getAllowedTabNames($tabs, 'server') . '</td>';
  93. $html_output .= '<td>' . _getAllowedTabNames($tabs, 'db') . '</td>';
  94. $html_output .= '<td>' . _getAllowedTabNames($tabs, 'table') . '</td>';
  95. $html_output .= '<td>';
  96. $html_output .= '<a class="" href="server_user_groups.php'
  97. . PMA_URL_getCommon(
  98. array(
  99. 'viewUsers' => 1, 'userGroup' => $groupName
  100. )
  101. )
  102. . '">'
  103. . PMA_Util::getIcon('b_usrlist.png', __('View users')) . '</a>';
  104. $html_output .= '&nbsp;&nbsp;';
  105. $html_output .= '<a class="" href="server_user_groups.php'
  106. . PMA_URL_getCommon(
  107. array(
  108. 'editUserGroup' => 1, 'userGroup' => $groupName
  109. )
  110. )
  111. . '">'
  112. . PMA_Util::getIcon('b_edit.png', __('Edit')) . '</a>';
  113. $html_output .= '&nbsp;&nbsp;';
  114. $html_output .= '<a class="deleteUserGroup ajax"'
  115. . ' href="server_user_groups.php'
  116. . PMA_URL_getCommon(
  117. array(
  118. 'deleteUserGroup' => 1, 'userGroup' => $groupName
  119. )
  120. )
  121. . '">'
  122. . PMA_Util::getIcon('b_drop.png', __('Delete')) . '</a>';
  123. $html_output .= '</td>';
  124. $html_output .= '</tr>';
  125. $odd = ! $odd;
  126. }
  127. $html_output .= '</tbody>';
  128. $html_output .= '</table>';
  129. $html_output .= '</form>';
  130. }
  131. $GLOBALS['dbi']->freeResult($result);
  132. $html_output .= '<fieldset id="fieldset_add_user_group">';
  133. $html_output .= '<a href="server_user_groups.php'
  134. . PMA_URL_getCommon(array('addUserGroup' => 1)) . '">'
  135. . PMA_Util::getIcon('b_usradd.png')
  136. . __('Add user group') . '</a>';
  137. $html_output .= '</fieldset>';
  138. return $html_output;
  139. }
  140. /**
  141. * Returns the list of allowed menu tab names
  142. * based on a data row from usergroup table.
  143. *
  144. * @param array $row row of usergroup table
  145. * @param string $level 'server', 'db' or 'table'
  146. *
  147. * @return string comma separated list of allowed menu tab names
  148. */
  149. function _getAllowedTabNames($row, $level)
  150. {
  151. $tabNames = array();
  152. $tabs = PMA_Util::getMenuTabList($level);
  153. foreach ($tabs as $tab => $tabName) {
  154. if (! isset($row[$level . '_' . $tab])
  155. || $row[$level . '_' . $tab] == 'Y'
  156. ) {
  157. $tabNames[] = $tabName;
  158. }
  159. }
  160. return implode(', ', $tabNames);
  161. }
  162. /**
  163. * Deletes a user group
  164. *
  165. * @param string $userGroup user group name
  166. *
  167. * @return void
  168. */
  169. function PMA_deleteUserGroup($userGroup)
  170. {
  171. $cfgRelation = PMA_getRelationsParam();
  172. $userTable = PMA_Util::backquote($cfgRelation['db'])
  173. . "." . PMA_Util::backquote($cfgRelation['users']);
  174. $groupTable = PMA_Util::backquote($cfgRelation['db'])
  175. . "." . PMA_Util::backquote($cfgRelation['usergroups']);
  176. $sql_query = "DELETE FROM " . $userTable
  177. . " WHERE `usergroup`='" . PMA_Util::sqlAddSlashes($userGroup) . "'";
  178. PMA_queryAsControlUser($sql_query, true);
  179. $sql_query = "DELETE FROM " . $groupTable
  180. . " WHERE `usergroup`='" . PMA_Util::sqlAddSlashes($userGroup) . "'";
  181. PMA_queryAsControlUser($sql_query, true);
  182. }
  183. /**
  184. * Returns HTML for add/edit user group dialog
  185. *
  186. * @param string $userGroup name of the user group in case of editing
  187. *
  188. * @return string HTML for add/edit user group dialog
  189. */
  190. function PMA_getHtmlToEditUserGroup($userGroup = null)
  191. {
  192. $html_output = '';
  193. if ($userGroup == null) {
  194. $html_output .= '<h2>' . __('Add user group') . '</h2>';
  195. } else {
  196. $html_output .= '<h2>'
  197. . sprintf(__('Edit user group: \'%s\''), htmlspecialchars($userGroup))
  198. . '</h2>';
  199. }
  200. $html_output .= '<form name="userGroupForm" id="userGroupForm"'
  201. . ' action="server_user_groups.php" method="post">';
  202. $urlParams = array();
  203. if ($userGroup != null) {
  204. $urlParams['userGroup'] = $userGroup;
  205. $urlParams['editUserGroupSubmit'] = '1';
  206. } else {
  207. $urlParams['addUserGroupSubmit'] = '1';
  208. }
  209. $html_output .= PMA_URL_getHiddenInputs($urlParams);
  210. $html_output .= '<fieldset id="fieldset_user_group_rights">';
  211. $html_output .= '<legend>' . __('User group menu assignments')
  212. . '&nbsp;&nbsp;&nbsp;'
  213. . '<input type="checkbox" class="checkall_box" title="Check all">'
  214. . '<label for="addUsersForm_checkall">' . __('Check all') . '</label>'
  215. . '</legend>';
  216. if ($userGroup == null) {
  217. $html_output .= '<label for="userGroup">' . __('Group name:') . '</label>';
  218. $html_output .= '<input type="text" name="userGroup" '
  219. . 'autocomplete="off" required="required" />';
  220. $html_output .= '<div class="clearfloat"></div>';
  221. }
  222. $allowedTabs = array(
  223. 'server' => array(),
  224. 'db' => array(),
  225. 'table' => array()
  226. );
  227. if ($userGroup != null) {
  228. $cfgRelation = PMA_getRelationsParam();
  229. $groupTable = PMA_Util::backquote($cfgRelation['db'])
  230. . "." . PMA_Util::backquote($cfgRelation['usergroups']);
  231. $sql_query = "SELECT * FROM " . $groupTable
  232. . " WHERE `usergroup`='" . PMA_Util::sqlAddSlashes($userGroup) . "'";
  233. $result = PMA_queryAsControlUser($sql_query, false);
  234. if ($result) {
  235. while ($row = $GLOBALS['dbi']->fetchAssoc($result)) {
  236. $key = $row['tab'];
  237. $value = $row['allowed'];
  238. if (substr($key, 0, 7) == 'server_' && $value == 'Y') {
  239. $allowedTabs['server'][] = /*overload*/mb_substr($key, 7);
  240. } elseif (substr($key, 0, 3) == 'db_' && $value == 'Y') {
  241. $allowedTabs['db'][] = /*overload*/mb_substr($key, 3);
  242. } elseif (substr($key, 0, 6) == 'table_'
  243. && $value == 'Y'
  244. ) {
  245. $allowedTabs['table'][] = /*overload*/mb_substr($key, 6);
  246. }
  247. }
  248. }
  249. $GLOBALS['dbi']->freeResult($result);
  250. }
  251. $html_output .= _getTabList(
  252. __('Server-level tabs'), 'server', $allowedTabs['server']
  253. );
  254. $html_output .= _getTabList(
  255. __('Database-level tabs'), 'db', $allowedTabs['db']
  256. );
  257. $html_output .= _getTabList(
  258. __('Table-level tabs'), 'table', $allowedTabs['table']
  259. );
  260. $html_output .= '</fieldset>';
  261. $html_output .= '<fieldset id="fieldset_user_group_rights_footer"'
  262. . ' class="tblFooters">';
  263. $html_output .= '<input type="submit" value="' . __('Go') . '">';
  264. $html_output .= '</fieldset>';
  265. return $html_output;
  266. }
  267. /**
  268. * Returns HTML for checkbox groups to choose
  269. * tabs of 'server', 'db' or 'table' levels.
  270. *
  271. * @param string $title title of the checkbox group
  272. * @param string $level 'server', 'db' or 'table'
  273. * @param array $selected array of selected allowed tabs
  274. *
  275. * @return string HTML for checkbox groups
  276. */
  277. function _getTabList($title, $level, $selected)
  278. {
  279. $tabs = PMA_Util::getMenuTabList($level);
  280. $html_output = '<fieldset>';
  281. $html_output .= '<legend>' . $title . '</legend>';
  282. foreach ($tabs as $tab => $tabName) {
  283. $html_output .= '<div class="item">';
  284. $html_output .= '<input type="checkbox" class="checkall"'
  285. . (in_array($tab, $selected) ? ' checked="checked"' : '')
  286. . ' name="' . $level . '_' . $tab . '" value="Y" />';
  287. $html_output .= '<label for="' . $level . '_' . $tab . '">'
  288. . '<code>' . $tabName . '</code>'
  289. . '</label>';
  290. $html_output .= '</div>';
  291. }
  292. $html_output .= '</fieldset>';
  293. return $html_output;
  294. }
  295. /**
  296. * Add/update a user group with allowed menu tabs.
  297. *
  298. * @param string $userGroup user group name
  299. * @param boolean $new whether this is a new user group
  300. *
  301. * @return void
  302. */
  303. function PMA_editUserGroup($userGroup, $new = false)
  304. {
  305. $tabs = PMA_Util::getMenuTabList();
  306. $cfgRelation = PMA_getRelationsParam();
  307. $groupTable = PMA_Util::backquote($cfgRelation['db'])
  308. . "." . PMA_Util::backquote($cfgRelation['usergroups']);
  309. if (! $new) {
  310. $sql_query = "DELETE FROM " . $groupTable
  311. . " WHERE `usergroup`='" . PMA_Util::sqlAddSlashes($userGroup) . "';";
  312. PMA_queryAsControlUser($sql_query, true);
  313. }
  314. $sql_query = "INSERT INTO " . $groupTable
  315. . "(`usergroup`, `tab`, `allowed`)"
  316. . " VALUES ";
  317. $first = true;
  318. foreach ($tabs as $tabGroupName => $tabGroup) {
  319. foreach ($tabs[$tabGroupName] as $tab => $tabName) {
  320. if (! $first) {
  321. $sql_query .= ", ";
  322. }
  323. $tabName = $tabGroupName . '_' . $tab;
  324. $allowed = isset($_REQUEST[$tabName]) && $_REQUEST[$tabName] == 'Y';
  325. $sql_query .= "('" . $userGroup . "', '" . $tabName . "', '"
  326. . ($allowed ? "Y" : "N") . "')";
  327. $first = false;
  328. }
  329. }
  330. $sql_query .= ";";
  331. PMA_queryAsControlUser($sql_query, true);
  332. }