grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026. -------------------------------------------------------------------------- */ /** @file * @brief */ if (!defined('GLPI_ROOT')) { die("Sorry. You can't access this file directly"); } /// Rule collection class for Rights management class RuleRightCollection extends RuleCollection { // From RuleCollection public $stop_on_first_match = false; static $rightname = 'rule_ldap'; public $orderby = "name"; public $menu_option = 'right'; // Specific ones /// Array containing results : entity + right public $rules_entity_rights = array(); /// Array containing results : only entity public $rules_entity = array(); /// Array containing results : only right public $rules_rights = array(); function getTitle() { return __('Authorizations assignment rules'); } /** * @see RuleCollection::cleanTestOutputCriterias() */ function cleanTestOutputCriterias(array $output) { if (isset($output["_rule_process"])) { unset($output["_rule_process"]); } return $output; } /** * @see RuleCollection::showTestResults() */ function showTestResults($rule, array $output, $global_result) { $actions = $rule->getActions(); echo "" . __('Rule results') . ""; echo ""; echo "".__('Validation')."". "".Dropdown::getYesNo($global_result).""; if (isset($output["_ldap_rules"]["rules_entities"])) { echo ""; echo "".__('Entities assignment').""; foreach ($output["_ldap_rules"]["rules_entities"] as $entities) { foreach ($entities as $entity) { $this->displayActionByName("entity", $entity[0]); if (isset($entity[1])) { $this->displayActionByName("recursive", $entity[1]); } } } } if (isset($output["_ldap_rules"]["rules_rights"])) { echo ""; echo "".__('Rights assignment').""; foreach ($output["_ldap_rules"]["rules_rights"] as $val) { $this->displayActionByName("profile", $val[0]); } } if (isset($output["_ldap_rules"]["rules_entities_rights"])) { echo ""; echo "".__('Rights and entities assignment').""; foreach ($output["_ldap_rules"]["rules_entities_rights"] as $val) { if (is_array($val[0])) { foreach ($val[0] as $tmp) { $this->displayActionByName("entity", $tmp); } } else { $this->displayActionByName("entity", $val[0]); } if (isset($val[1])) { $this->displayActionByName("profile", $val[1]); } if (isset($val[2])) { $this->displayActionByName("is_recursive",$val[2]); } } } if (isset($output["_ldap_rules"])) { unset($output["_ldap_rules"]); } foreach ($output as $criteria => $value) { if (isset($actions[$criteria])) { // ignore _* fields if (isset($actions[$criteria]['action_type'])) { $actiontype = $actions[$criteria]['action_type']; } else { $actiontype =''; } echo ""; echo "".$actions[$criteria]["name"].""; echo "".$rule->getActionValue($criteria, $actiontype, $value); echo "\n"; } } echo ""; } /** * Display action using its name * * @param $name action name * @param $value default value **/ function displayActionByName($name, $value) { echo ""; switch ($name) { case "entity" : echo "".__('Entity')." \n"; echo "".Dropdown::getDropdownName("glpi_entities", $value).""; break; case "profile" : echo ""._n('Profile', 'Profiles', Session::getPluralNumber())." \n"; echo "".Dropdown::getDropdownName("glpi_profiles", $value).""; break; case "is_recursive" : echo "".__('Recursive')." \n"; echo "".Dropdown::getYesNo($value).""; break; } echo ""; } /** * Get all the fields needed to perform the rule * * @see RuleCollection::getFieldsToLookFor() **/ function getFieldsToLookFor() { global $DB; $params = array(); $sql = "SELECT DISTINCT `value` FROM `glpi_rules`, `glpi_rulecriterias`, `glpi_rulerightparameters` WHERE `glpi_rules`.`sub_type` = 'RuleRight' AND `glpi_rulecriterias`.`rules_id` = `glpi_rules`.`id` AND `glpi_rulecriterias`.`criteria` = `glpi_rulerightparameters`.`value`"; $result = $DB->query($sql); while ($param = $DB->fetch_assoc($result)) { //Dn is alwsays retreived from ldap : don't need to ask for it ! if ($param["value"] != "dn") { $params[] = Toolbox::strtolower($param["value"]); } } return $params; } /** * Get the attributes needed for processing the rules * * @see RuleCollection::prepareInputDataForProcess() * * @param $input input datas * @param $params extra parameters given * * @return an array of attributes **/ function prepareInputDataForProcess($input, $params) { $rule_parameters = array(); //LDAP type method if ($params["type"] == "LDAP") { //Get all the field to retrieve to be able to process rule matching $rule_fields = $this->getFieldsToLookFor(); //Get all the datas we need from ldap to process the rules $sz = @ldap_read($params["connection"], $params["userdn"], "objectClass=*", $rule_fields); $rule_input = AuthLDAP::get_entries_clean($params["connection"], $sz); if (count($rule_input)) { if (isset($input)) { $groups = $input; } else { $groups = array(); } $rule_input = $rule_input[0]; //Get all the ldap fields $fields = $this->getFieldsForQuery(); foreach ($fields as $field) { switch(Toolbox::strtoupper($field)) { case "LOGIN" : $rule_parameters["LOGIN"] = $params["login"]; break; case "MAIL_EMAIL" : $rule_parameters["MAIL_EMAIL"] = $params["mail_email"]; break; case "LDAP_SERVER" : $rule_parameters["LDAP_SERVER"] = $params["ldap_server"]; break; case "GROUPS" : foreach ($groups as $group) { $rule_parameters["GROUPS"][] = $group; } break; default : if (isset($rule_input[$field])) { if (!is_array($rule_input[$field])) { $rule_parameters[$field] = $rule_input[$field]; } else { if (count($rule_input[$field])) { foreach ($rule_input[$field] as $key => $val) { if ($key !== 'count') { $rule_parameters[$field][] = $val; } } } } } } } return $rule_parameters; } return $rule_input; } else if ($params["type"] == "SSO") { $rule_parameters["MAIL_EMAIL"] = $params["email"]; $rule_parameters["LOGIN"] = $params["login"]; return $rule_parameters; } //IMAP/POP login method $rule_parameters["MAIL_SERVER"] = $params["mail_server"]; $rule_parameters["MAIL_EMAIL"] = $params["email"]; $rule_parameters["LOGIN"] = $params["login"]; return $rule_parameters; } /** * Get the list of fields to be retreived to process rules **/ function getFieldsForQuery() { $rule = new RuleRight(); $criterias = $rule->getCriterias(); $fields = array(); foreach ($criterias as $criteria) { if (!is_array($criteria)) { continue; } if (isset($criteria['virtual']) && $criteria['virtual']) { $fields[] = $criteria['id']; } else { $fields[] = $criteria['field']; } } return $fields; } }