/store/admin/controller/user/user_permission.php

https://github.com/elleeott/WPOC-boilerplate · PHP · 426 lines · 316 code · 110 blank · 0 comment · 65 complexity · c27daa57189dcf5a82f8b3e733cf072a MD5 · raw file

  1. <?php
  2. class ControllerUserUserPermission extends Controller {
  3. private $error = array();
  4. public function index() {
  5. $this->load->language('user/user_group');
  6. $this->document->setTitle($this->language->get('heading_title'));
  7. $this->load->model('user/user_group');
  8. $this->getList();
  9. }
  10. public function insert() {
  11. $this->load->language('user/user_group');
  12. $this->document->setTitle($this->language->get('heading_title'));
  13. $this->load->model('user/user_group');
  14. if (($this->request->server['REQUEST_METHOD'] == 'POST') && $this->validateForm()) {
  15. $this->model_user_user_group->addUserGroup($this->request->post);
  16. $this->session->data['success'] = $this->language->get('text_success');
  17. $url = '';
  18. if (isset($this->request->get['sort'])) {
  19. $url .= '&sort=' . $this->request->get['sort'];
  20. }
  21. if (isset($this->request->get['order'])) {
  22. $url .= '&order=' . $this->request->get['order'];
  23. }
  24. if (isset($this->request->get['page'])) {
  25. $url .= '&page=' . $this->request->get['page'];
  26. }
  27. $this->redirect($this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . $url, 'SSL'));
  28. }
  29. $this->getForm();
  30. }
  31. public function update() {
  32. $this->load->language('user/user_group');
  33. $this->document->setTitle($this->language->get('heading_title'));
  34. $this->load->model('user/user_group');
  35. if (($this->request->server['REQUEST_METHOD'] == 'POST') && $this->validateForm()) {
  36. $this->model_user_user_group->editUserGroup($this->request->get['user_group_id'], $this->request->post);
  37. $this->session->data['success'] = $this->language->get('text_success');
  38. $url = '';
  39. if (isset($this->request->get['sort'])) {
  40. $url .= '&sort=' . $this->request->get['sort'];
  41. }
  42. if (isset($this->request->get['order'])) {
  43. $url .= '&order=' . $this->request->get['order'];
  44. }
  45. if (isset($this->request->get['page'])) {
  46. $url .= '&page=' . $this->request->get['page'];
  47. }
  48. $this->redirect($this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . $url, 'SSL'));
  49. }
  50. $this->getForm();
  51. }
  52. public function delete() {
  53. $this->load->language('user/user_group');
  54. $this->document->setTitle($this->language->get('heading_title'));
  55. $this->load->model('user/user_group');
  56. if (isset($this->request->post['selected']) && $this->validateDelete()) {
  57. foreach ($this->request->post['selected'] as $user_group_id) {
  58. $this->model_user_user_group->deleteUserGroup($user_group_id);
  59. }
  60. $this->session->data['success'] = $this->language->get('text_success');
  61. $url = '';
  62. if (isset($this->request->get['sort'])) {
  63. $url .= '&sort=' . $this->request->get['sort'];
  64. }
  65. if (isset($this->request->get['order'])) {
  66. $url .= '&order=' . $this->request->get['order'];
  67. }
  68. if (isset($this->request->get['page'])) {
  69. $url .= '&page=' . $this->request->get['page'];
  70. }
  71. $this->redirect($this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . $url, 'SSL'));
  72. }
  73. $this->getList();
  74. }
  75. private function getList() {
  76. if (isset($this->request->get['sort'])) {
  77. $sort = $this->request->get['sort'];
  78. } else {
  79. $sort = 'name';
  80. }
  81. if (isset($this->request->get['order'])) {
  82. $order = $this->request->get['order'];
  83. } else {
  84. $order = 'ASC';
  85. }
  86. if (isset($this->request->get['page'])) {
  87. $page = $this->request->get['page'];
  88. } else {
  89. $page = 1;
  90. }
  91. $url = '';
  92. if (isset($this->request->get['sort'])) {
  93. $url .= '&sort=' . $this->request->get['sort'];
  94. }
  95. if (isset($this->request->get['order'])) {
  96. $url .= '&order=' . $this->request->get['order'];
  97. }
  98. if (isset($this->request->get['page'])) {
  99. $url .= '&page=' . $this->request->get['page'];
  100. }
  101. $this->data['breadcrumbs'] = array();
  102. $this->data['breadcrumbs'][] = array(
  103. 'text' => $this->language->get('text_home'),
  104. 'href' => $this->url->link('common/home', 'token=' . $this->session->data['token'], 'SSL'),
  105. 'separator' => false
  106. );
  107. $this->data['breadcrumbs'][] = array(
  108. 'text' => $this->language->get('heading_title'),
  109. 'href' => $this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . $url, 'SSL'),
  110. 'separator' => ' :: '
  111. );
  112. $this->data['insert'] = $this->url->link('user/user_permission/insert', 'token=' . $this->session->data['token'] . $url, 'SSL');
  113. $this->data['delete'] = $this->url->link('user/user_permission/delete', 'token=' . $this->session->data['token'] . $url, 'SSL');
  114. $this->data['user_groups'] = array();
  115. $data = array(
  116. 'sort' => $sort,
  117. 'order' => $order,
  118. 'start' => ($page - 1) * $this->config->get('config_admin_limit'),
  119. 'limit' => $this->config->get('config_admin_limit')
  120. );
  121. $user_group_total = $this->model_user_user_group->getTotalUserGroups();
  122. $results = $this->model_user_user_group->getUserGroups($data);
  123. foreach ($results as $result) {
  124. $action = array();
  125. $action[] = array(
  126. 'text' => $this->language->get('text_edit'),
  127. 'href' => $this->url->link('user/user_permission/update', 'token=' . $this->session->data['token'] . '&user_group_id=' . $result['user_group_id'] . $url, 'SSL')
  128. );
  129. $this->data['user_groups'][] = array(
  130. 'user_group_id' => $result['user_group_id'],
  131. 'name' => $result['name'],
  132. 'selected' => isset($this->request->post['selected']) && in_array($result['user_group_id'], $this->request->post['selected']),
  133. 'action' => $action
  134. );
  135. }
  136. $this->data['heading_title'] = $this->language->get('heading_title');
  137. $this->data['text_no_results'] = $this->language->get('text_no_results');
  138. $this->data['column_name'] = $this->language->get('column_name');
  139. $this->data['column_action'] = $this->language->get('column_action');
  140. $this->data['button_insert'] = $this->language->get('button_insert');
  141. $this->data['button_delete'] = $this->language->get('button_delete');
  142. if (isset($this->error['warning'])) {
  143. $this->data['error_warning'] = $this->error['warning'];
  144. } else {
  145. $this->data['error_warning'] = '';
  146. }
  147. if (isset($this->session->data['success'])) {
  148. $this->data['success'] = $this->session->data['success'];
  149. unset($this->session->data['success']);
  150. } else {
  151. $this->data['success'] = '';
  152. }
  153. $url = '';
  154. if ($order == 'ASC') {
  155. $url .= '&order=DESC';
  156. } else {
  157. $url .= '&order=ASC';
  158. }
  159. if (isset($this->request->get['page'])) {
  160. $url .= '&page=' . $this->request->get['page'];
  161. }
  162. $this->data['sort_name'] = $this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . '&sort=name' . $url, 'SSL');
  163. $url = '';
  164. if (isset($this->request->get['sort'])) {
  165. $url .= '&sort=' . $this->request->get['sort'];
  166. }
  167. if (isset($this->request->get['order'])) {
  168. $url .= '&order=' . $this->request->get['order'];
  169. }
  170. $pagination = new Pagination();
  171. $pagination->total = $user_group_total;
  172. $pagination->page = $page;
  173. $pagination->limit = $this->config->get('config_admin_limit');
  174. $pagination->text = $this->language->get('text_pagination');
  175. $pagination->url = $this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . $url . '&page={page}', 'SSL');
  176. $this->data['pagination'] = $pagination->render();
  177. $this->data['sort'] = $sort;
  178. $this->data['order'] = $order;
  179. $this->template = 'user/user_group_list.tpl';
  180. $this->children = array(
  181. 'common/header',
  182. 'common/footer'
  183. );
  184. $this->response->setOutput($this->render());
  185. }
  186. private function getForm() {
  187. $this->data['heading_title'] = $this->language->get('heading_title');
  188. $this->data['text_select_all'] = $this->language->get('text_select_all');
  189. $this->data['text_unselect_all'] = $this->language->get('text_unselect_all');
  190. $this->data['entry_name'] = $this->language->get('entry_name');
  191. $this->data['entry_access'] = $this->language->get('entry_access');
  192. $this->data['entry_modify'] = $this->language->get('entry_modify');
  193. $this->data['button_save'] = $this->language->get('button_save');
  194. $this->data['button_cancel'] = $this->language->get('button_cancel');
  195. $this->data['tab_general'] = $this->language->get('tab_general');
  196. if (isset($this->error['warning'])) {
  197. $this->data['error_warning'] = $this->error['warning'];
  198. } else {
  199. $this->data['error_warning'] = '';
  200. }
  201. if (isset($this->error['name'])) {
  202. $this->data['error_name'] = $this->error['name'];
  203. } else {
  204. $this->data['error_name'] = '';
  205. }
  206. $url = '';
  207. if (isset($this->request->get['sort'])) {
  208. $url .= '&sort=' . $this->request->get['sort'];
  209. }
  210. if (isset($this->request->get['order'])) {
  211. $url .= '&order=' . $this->request->get['order'];
  212. }
  213. if (isset($this->request->get['page'])) {
  214. $url .= '&page=' . $this->request->get['page'];
  215. }
  216. $this->data['breadcrumbs'] = array();
  217. $this->data['breadcrumbs'][] = array(
  218. 'text' => $this->language->get('text_home'),
  219. 'href' => $this->url->link('common/home', 'token=' . $this->session->data['token'], 'SSL'),
  220. 'separator' => false
  221. );
  222. $this->data['breadcrumbs'][] = array(
  223. 'text' => $this->language->get('heading_title'),
  224. 'href' => $this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . $url, 'SSL'),
  225. 'separator' => ' :: '
  226. );
  227. if (!isset($this->request->get['user_group_id'])) {
  228. $this->data['action'] = $this->url->link('user/user_permission/insert', 'token=' . $this->session->data['token'] . $url, 'SSL');
  229. } else {
  230. $this->data['action'] = $this->url->link('user/user_permission/update', 'token=' . $this->session->data['token'] . '&user_group_id=' . $this->request->get['user_group_id'] . $url, 'SSL');
  231. }
  232. $this->data['cancel'] = $this->url->link('user/user_permission', 'token=' . $this->session->data['token'] . $url, 'SSL');
  233. if (isset($this->request->get['user_group_id']) && $this->request->server['REQUEST_METHOD'] != 'POST') {
  234. $user_group_info = $this->model_user_user_group->getUserGroup($this->request->get['user_group_id']);
  235. }
  236. if (isset($this->request->post['name'])) {
  237. $this->data['name'] = $this->request->post['name'];
  238. } elseif (!empty($user_group_info)) {
  239. $this->data['name'] = $user_group_info['name'];
  240. } else {
  241. $this->data['name'] = '';
  242. }
  243. $ignore = array(
  244. 'common/home',
  245. 'common/startup',
  246. 'common/login',
  247. 'common/logout',
  248. 'common/forgotten',
  249. 'common/reset',
  250. 'error/not_found',
  251. 'error/permission',
  252. 'common/footer',
  253. 'common/header'
  254. );
  255. $this->data['permissions'] = array();
  256. $files = glob(DIR_APPLICATION . 'controller/*/*.php');
  257. foreach ($files as $file) {
  258. $data = explode('/', dirname($file));
  259. $permission = end($data) . '/' . basename($file, '.php');
  260. if (!in_array($permission, $ignore)) {
  261. $this->data['permissions'][] = $permission;
  262. }
  263. }
  264. if (isset($this->request->post['permission'])) {
  265. $this->data['access'] = $this->request->post['permission']['access'];
  266. } elseif (isset($user_group_info['permission']['access'])) {
  267. $this->data['access'] = $user_group_info['permission']['access'];
  268. } else {
  269. $this->data['access'] = array();
  270. }
  271. if (isset($this->request->post['permission'])) {
  272. $this->data['modify'] = $this->request->post['permission']['modify'];
  273. } elseif (isset($user_group_info['permission']['modify'])) {
  274. $this->data['modify'] = $user_group_info['permission']['modify'];
  275. } else {
  276. $this->data['modify'] = array();
  277. }
  278. $this->template = 'user/user_group_form.tpl';
  279. $this->children = array(
  280. 'common/header',
  281. 'common/footer'
  282. );
  283. $this->response->setOutput($this->render());
  284. }
  285. private function validateForm() {
  286. if (!$this->user->hasPermission('modify', 'user/user_permission')) {
  287. $this->error['warning'] = $this->language->get('error_permission');
  288. }
  289. if ((utf8_strlen($this->request->post['name']) < 3) || (utf8_strlen($this->request->post['name']) > 64)) {
  290. $this->error['name'] = $this->language->get('error_name');
  291. }
  292. if (!$this->error) {
  293. return true;
  294. } else {
  295. return false;
  296. }
  297. }
  298. private function validateDelete() {
  299. if (!$this->user->hasPermission('modify', 'user/user_permission')) {
  300. $this->error['warning'] = $this->language->get('error_permission');
  301. }
  302. $this->load->model('user/user');
  303. foreach ($this->request->post['selected'] as $user_group_id) {
  304. $user_total = $this->model_user_user->getTotalUsersByGroupId($user_group_id);
  305. if ($user_total) {
  306. $this->error['warning'] = sprintf($this->language->get('error_user'), $user_total);
  307. }
  308. }
  309. if (!$this->error) {
  310. return true;
  311. } else {
  312. return false;
  313. }
  314. }
  315. }
  316. ?>