permissions.php 8.96 KB
Newer Older
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
<?php

// This file is part of Moodle - http://moodle.org/
//
// Moodle is free software: you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// Moodle is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License
// along with Moodle.  If not, see <http://www.gnu.org/licenses/>.

/**
 * This script serves draft files of current user
 *
 * @package    moodlecore
 * @subpackage role
 * @copyright  2009 Petr Skoda (skodak) info@skodak.org
 * @license    http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
 */

require('../../config.php');
require_once("$CFG->dirroot/$CFG->admin/roles/lib.php");
require_once("permissions_forms.php");

$contextid  = required_param('contextid',PARAM_INT);

$roleid     = optional_param('roleid', 0, PARAM_INT);
$capability = optional_param('capability', false, PARAM_CAPABILITY);
$confirm    = optional_param('confirm', 0, PARAM_BOOL);
$prevent    = optional_param('prevent', 0, PARAM_BOOL);
$allow      = optional_param('allow', 0, PARAM_BOOL);
$unprohibit = optional_param('unprohibit', 0, PARAM_BOOL);
$prohibit   = optional_param('prohibit', 0, PARAM_BOOL);

list($context, $course, $cm) = get_context_info_array($contextid);

43
$url = new moodle_url('/admin/roles/permissions.php', array('contextid' => $contextid));
44

45
if (!$course) {
46
    if ($context->contextlevel == CONTEXT_USER) {
47
48
49
50
        $course = $DB->get_record('course', array('id'=>optional_param('courseid', SITEID, PARAM_INT)), '*', MUST_EXIST);
        $user = $DB->get_record('user', array('id'=>$context->instanceid), '*', MUST_EXIST);
        $url->param('courseid', $course->id);
        $url->param('userid', $user->id);
51
52
53
54
55
    } else {
        $course = $SITE;
    }
}

Petr Skoda's avatar
Petr Skoda committed
56
57
58
// security first
require_login($course, false, $cm);
require_capability('moodle/role:review', $context);
59
60
$PAGE->set_url($url);
$PAGE->set_context($context);
61
$courseid = $course->id;
62
$isfrontpage = ($course->id == SITEID);
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77


// These are needed early because of tabs.php
$assignableroles = get_assignable_roles($context, ROLENAME_BOTH);
list($overridableroles, $overridecounts, $nameswithcounts) = get_overridable_roles($context, ROLENAME_BOTH, true);
if ($capability) {
    $capability = $DB->get_record('capabilities', array('name'=>$capability), '*', MUST_EXIST);
}

$allowoverrides     = has_capability('moodle/role:override', $context);
$allowsafeoverrides = has_capability('moodle/role:safeoverride', $context);

$contextname = print_context_name($context);
$title = get_string('permissionsincontext', 'role', $contextname);
$straction = get_string('permissions', 'role'); // Used by tabs.php
78
79
$tabfile = $CFG->dirroot.'/'.$CFG->admin.'/roles/tabs.php';
$currenttab = 'permissions';
80

81
82
83
84
85
86
87
$PAGE->set_pagelayout('admin');
$PAGE->set_title($title);
switch ($context->contextlevel) {
    case CONTEXT_SYSTEM:
        print_error('cannotoverridebaserole', 'error');
        break;
    case CONTEXT_USER:
88
        $tabfile = null;
89
90
91
        if ($isfrontpage) {
            $fullname = fullname($user, has_capability('moodle/site:viewfullnames', $context));
            $PAGE->set_heading($fullname);
92
        } else {
93
            $PAGE->set_heading($course->fullname);
94
        }
95
96
97
98
99
100
101
102
        $showroles = 1;
        break;
    case CONTEXT_COURSECAT:
        $PAGE->set_heading("$SITE->fullname: ".get_string("categories"));
        break;
    case CONTEXT_COURSE:
        if ($isfrontpage) {
            admin_externalpage_setup('frontpageroles', '', array(), $PAGE->url);
103
        } else {
104
            $PAGE->set_heading($course->fullname);
105
        }
106
107
108
109
110
111
112
113
        break;
    case CONTEXT_MODULE:
        $PAGE->set_heading(print_context_name($context, false));
        $PAGE->set_cacheable(false);
        break;
    case CONTEXT_BLOCK:
        $PAGE->set_heading($PAGE->course->fullname);
        break;
114
115
}

116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
// handle confirmations and actions
// We have a capability and overrides are allowed or safe overrides are allowed and this is safe
if ($capability && ($allowoverrides || ($allowsafeoverrides && is_safe_capability($capability)))) {
    // If we already know the the role ID, it is overrideable, and we are setting prevent or unprohibit
    if (isset($overridableroles[$roleid]) && ($prevent || $unprohibit)) {
        // We are preventing
        if ($prevent) {
            if ($confirm && data_submitted() && confirm_sesskey()) {
                role_change_permission($roleid, $context, $capability->name, CAP_PREVENT);
                redirect($PAGE->url);

            } else {
                $a = (object)array('cap'=>get_capability_docs_link($capability)." ($capability->name)", 'role'=>$overridableroles[$roleid], 'context'=>$contextname);
                $message = get_string('confirmroleprevent', 'role', $a);
                $continueurl = new moodle_url($PAGE->url, array('contextid'=>$context->id, 'roleid'=>$roleid, 'capability'=>$capability->name, 'prevent'=>1, 'sesskey'=>sesskey(), 'confirm'=>1));
131
            }
132
133
134
135
136
137
138
139
140
141
        }
        // We are unprohibiting
        if ($unprohibit) {
            if ($confirm && data_submitted() && confirm_sesskey()) {
                role_change_permission($roleid, $context, $capability->name, CAP_INHERIT);
                redirect($PAGE->url);
            } else {
                $a = (object)array('cap'=>get_capability_docs_link($capability)." ($capability->name)", 'role'=>$overridableroles[$roleid], 'context'=>$contextname);
                $message = get_string('confirmroleunprohibit', 'role', $a);
                $continueurl = new moodle_url($PAGE->url, array('contextid'=>$context->id, 'roleid'=>$roleid, 'capability'=>$capability->name, 'unprohibit'=>1, 'sesskey'=>sesskey(), 'confirm'=>1));
142
143
            }
        }
144
145
        // Display and print
        echo $OUTPUT->header();
146
147
148
        if ($tabfile) {
            include($tabfile);
        }
149
150
151
152
        echo $OUTPUT->heading($title);
        echo $OUTPUT->confirm($message, $continueurl, $PAGE->url);
        echo $OUTPUT->footer();
        die;
153
154
    }

155
156
157
158
159
160
161
162
163
164
165
166
167
168
    if ($allow || $prohibit) {
        if ($allow) {
            $mform = new role_allow_form(null, array($context, $capability, $overridableroles));
            if ($mform->is_cancelled()) {
                redirect($PAGE->url);
            } else if ($data = $mform->get_data() and !empty($data->roleid)) {
                $roleid = $data->roleid;
                if (isset($overridableroles[$roleid])) {
                    role_change_permission($roleid, $context, $capability->name, CAP_ALLOW);
                }
                redirect($PAGE->url);
            } else {
                $a = (object)array('cap'=>get_capability_docs_link($capability)." ($capability->name)", 'context'=>$contextname);
                $message = get_string('roleallowinfo', 'role', $a);
169
            }
170
171
172
173
174
175
176
177
178
179
180
181
182
183
        }
        if ($prohibit) {
            $mform = new role_prohibit_form(null, array($context, $capability, $overridableroles));
            if ($mform->is_cancelled()) {
                redirect($PAGE->url);
            } else if ($data = $mform->get_data() and !empty($data->roleid)) {
                $roleid = $data->roleid;
                if (isset($overridableroles[$roleid])) {
                    role_change_permission($roleid, $context, $capability->name, CAP_PROHIBIT);
                }
                redirect($PAGE->url);
            } else {
                $a = (object)array('cap'=>get_capability_docs_link($capability)." ($capability->name)", 'context'=>$contextname);
                $message = get_string('roleprohibitinfo', 'role', $a);
184
185
            }
        }
186
        echo $OUTPUT->header();
187
188
189
        if ($tabfile) {
            include($tabfile);
        }
190
191
192
193
194
        echo $OUTPUT->heading($title);
        echo $OUTPUT->box($message);
        $mform->display();
        echo $OUTPUT->footer();
        die;
195
196
197
198
    }
}

echo $OUTPUT->header();
199
200
201
if ($tabfile) {
    include($tabfile);
}
202
203
204
205
206
207
208
209
210
echo $OUTPUT->heading($title);

$table = new permissions_table($context, $contextname, $allowoverrides, $allowsafeoverrides, $overridableroles);
echo $OUTPUT->box_start('generalbox capbox');
// print link to advanced override page
if ($overridableroles) {
    $overrideurl = new moodle_url('/admin/roles/override.php', array('contextid' => $context->id));
    $select = new single_select($overrideurl, 'roleid', $nameswithcounts);
    $select->label = get_string('advancedoverride', 'role');
211
    echo html_writer::tag('div', $OUTPUT->render($select), array('class'=>'advancedoverride'));
212
213
214
215
216
217
}
$table->display();
echo $OUTPUT->box_end();


if ($context->contextlevel > CONTEXT_USER) {
218
219
220
    echo html_writer::start_tag('div', array('class'=>'backlink'));
    echo html_writer::tag('a', get_string('backto', '', $contextname), array('href'=>get_context_url($context)));
    echo html_writer::end_tag('div');
221
222
223
224
}

echo $OUTPUT->footer($course);