1 # BEGIN BPS TAGGED BLOCK {{{
5 # This software is Copyright (c) 1996-2015 Best Practical Solutions, LLC
6 # <sales@bestpractical.com>
8 # (Except where explicitly superseded by other copyright notices)
13 # This work is made available to you under the terms of Version 2 of
14 # the GNU General Public License. A copy of that license should have
15 # been provided with this software, but in any event can be snarfed
18 # This work is distributed in the hope that it will be useful, but
19 # WITHOUT ANY WARRANTY; without even the implied warranty of
20 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
21 # General Public License for more details.
23 # You should have received a copy of the GNU General Public License
24 # along with this program; if not, write to the Free Software
25 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
26 # 02110-1301 or visit their web page on the internet at
27 # http://www.gnu.org/licenses/old-licenses/gpl-2.0.html.
30 # CONTRIBUTION SUBMISSION POLICY:
32 # (The following paragraph is not intended to limit the rights granted
33 # to you to modify and distribute this software under the terms of
34 # the GNU General Public License and is only of importance to you if
35 # you choose to contribute your changes and enhancements to the
36 # community by submitting them to Best Practical Solutions, LLC.)
38 # By intentionally submitting any modifications, corrections or
39 # derivatives to this work, or any other work intended for use with
40 # Request Tracker, to Best Practical Solutions, LLC, you confirm that
41 # you are the copyright holder for those contributions and you grant
42 # Best Practical Solutions, LLC a nonexclusive, worldwide, irrevocable,
43 # royalty-free, perpetual, license to use, copy, create derivative
44 # works based on those contributions, and sublicense and distribute
45 # those contributions and any derivatives thereof.
47 # END BPS TAGGED BLOCK }}}
51 RT::ACL - collection of RT ACE objects
56 my $ACL = RT::ACL->new($CurrentUser);
68 use base 'RT::SearchBuilder';
81 Hand out the next ACE that was found
87 =head2 LimitToObject $object
89 Limit the ACL to rights for the object $object. It needs to be an RT::Record class.
97 my $obj_type = ref($obj)||$obj;
98 my $obj_id = eval { $obj->id};
100 my $object_clause = 'possible_objects';
101 $self->_OpenParen($object_clause);
103 SUBCLAUSE => $object_clause,
104 FIELD => 'ObjectType',
106 VALUE => (ref($obj)||$obj),
107 ENTRYAGGREGATOR => 'OR' # That "OR" applies to the separate objects we're searching on, not "Type Or ID"
111 SUBCLAUSE => $object_clause,
115 ENTRYAGGREGATOR => 'AND',
119 $self->_CloseParen($object_clause);
125 =head2 LimitToPrincipal { Type => undef, Id => undef, IncludeGroupMembership => undef }
127 Limit the ACL to the principal with PrincipalId Id and PrincipalType Type
132 if IncludeGroupMembership => 1 is specified, ACEs which apply to the principal due to group membership will be included in the resultset.
137 sub LimitToPrincipal {
139 my %args = ( Type => undef,
141 IncludeGroupMembership => undef,
144 if ( $args{'IncludeGroupMembership'} ) {
145 my $cgm = $self->NewAlias('CachedGroupMembers');
146 $self->Join( ALIAS1 => 'main',
147 FIELD1 => 'PrincipalId',
151 $self->Limit( ALIAS => $cgm,
154 $self->Limit( ALIAS => $cgm,
157 VALUE => $args{'Id'},
158 ENTRYAGGREGATOR => 'OR'
161 if ( defined $args{'Type'} ) {
162 $self->Limit( FIELD => 'PrincipalType',
164 VALUE => $args{'Type'},
165 ENTRYAGGREGATOR => 'OR'
169 # if the principal id points to a user, we really want to point
170 # to their ACL equivalence group. The machinations we're going through
171 # lead me to start to suspect that we really want users and groups
172 # to just be the same table. or _maybe_ that we want an object db.
173 my $princ = RT::Principal->new( RT->SystemUser );
174 $princ->Load( $args{'Id'} );
175 if ( $princ->PrincipalType eq 'User' ) {
176 my $group = RT::Group->new( RT->SystemUser );
177 $group->LoadACLEquivalenceGroup($princ);
178 $args{'Id'} = $group->PrincipalId;
180 $self->Limit( FIELD => 'PrincipalId',
182 VALUE => $args{'Id'},
183 ENTRYAGGREGATOR => 'OR'
195 # Short-circuit having to load up the ->Object
196 return $self->SUPER::AddRecord( $record )
197 if $record->CurrentUser->PrincipalObj->Id == RT->SystemUser->Id;
199 my $obj = $record->Object;
200 return unless $self->CurrentUser->HasRight( Right => 'ShowACL',
202 or $self->CurrentUser->HasRight( Right => 'ModifyACL',
205 return $self->SUPER::AddRecord( $record );
208 # The singular of ACL is ACE.
209 sub _SingularClass { "RT::ACE" }
211 RT::Base->_ImportOverlays();