mirror of
https://github.com/Combodo/iTop.git
synced 2026-09-29 21:09:10 +02:00
WIP
This commit is contained in:
File diff suppressed because it is too large
Load Diff
@@ -162,13 +162,14 @@ Opérateurs :<br/>
|
||||
'Core:Context=GUI:Portal' => 'Portal',
|
||||
'Core:Context=GUI:Portal+' => 'GUI:Portal',
|
||||
|
||||
'Core:GetQuota:Error' => 'Erreur lors de la récupération du quota des %1$s',
|
||||
'Core:ConsoleUsers' => 'utilisateurs console',
|
||||
'Core:DisabledUsers' => 'utilisateurs désactivés',
|
||||
'Core:PortalUsers' => 'utilisateurs du portail',
|
||||
'Core:BusinessPartnerUser' => 'utilisateurs partenaires business',
|
||||
'Core:ReadOnlyUsers' => 'utilisateurs en lecture seule',
|
||||
'Core:ApplicationUsers' => 'utilisateurs applicatifs',
|
||||
'Core:GetCountingUsers:Error' => 'Erreur lors du comptage des %1$s',
|
||||
'Core:CountingUsers:ConsoleUsers' => 'utilisateurs console',
|
||||
'Core:CountingUsers:DisabledUsers' => 'utilisateurs désactivés',
|
||||
'Core:CountingUsers:PortalUsers' => 'utilisateurs du portail',
|
||||
'Core:CountingUsers:BusinessPartnerUser' => 'utilisateurs partenaires business',
|
||||
'Core:CountingUsers:ReadOnlyUsers' => 'utilisateurs en lecture seule',
|
||||
'Core:CountingUsers:ApplicationUsers' => 'utilisateurs applicatifs',
|
||||
'Core:CountingUsers:AllUsers' => 'tous les utilisateurs',
|
||||
]);
|
||||
|
||||
//////////////////////////////////////////////////////////////////////
|
||||
|
||||
@@ -20,7 +20,7 @@ use User;
|
||||
use UserRights;
|
||||
|
||||
/**
|
||||
*
|
||||
* @description Repository that aims to count users based on their type
|
||||
*/
|
||||
class ITopUserCountingRepository
|
||||
{
|
||||
@@ -37,7 +37,7 @@ class ITopUserCountingRepository
|
||||
* @throws MySQLException
|
||||
* @throws Exception
|
||||
*/
|
||||
public function GetConsoleUsers(array $aExcludedUsers = [], array $aExcludedProfiles = [], bool $bAllData = true, array $aExcludedFinalClasses = ['UserToken', 'UserRemoteSaaS']): array
|
||||
public function GetConsoleUsers(array $aExcludedUsers = [], array $aExcludedProfiles = ['Portal user'], bool $bAllData = true, array $aExcludedFinalClasses = ['UserToken', 'UserRemoteSaaS']): array
|
||||
{
|
||||
$sExcludedUsers = $this->ArrayToOQLStringParameter($aExcludedUsers);
|
||||
$sExcludedProfiles = $this->ArrayToOQLStringParameter($aExcludedProfiles);
|
||||
@@ -57,66 +57,33 @@ class ITopUserCountingRepository
|
||||
try {
|
||||
$oFilter = $bAllData ? DBObjectSearch::FromOQL_AllData($sOQLUserConsole) : DBObjectSearch::FromOQL($sOQLUserConsole);
|
||||
} catch (Exception $e) {
|
||||
IssueLog::Error('Core:GetConsoleUsersQuota:Error : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetQuota:Error', Dict::S('Core:ConsoleUsers')));
|
||||
IssueLog::Error(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:ConsoleUsers')).' - error details : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:ConsoleUsers')).'.');
|
||||
}
|
||||
|
||||
$aConsoleUsers = $this->GetUsersFromFilter($oFilter);
|
||||
$aPortalUsers = $this->GetPortalUsers();
|
||||
$aReadOnlyUsers = $this->GetReadOnlyUsers();
|
||||
|
||||
return array_diff($aConsoleUsers, $aPortalUsers, $aReadOnlyUsers);
|
||||
}
|
||||
|
||||
private function ArrayToOQLStringParameter(array $aValues): string
|
||||
{
|
||||
$aQuotedValues = [];
|
||||
foreach ($aValues as $value) {
|
||||
$value = trim((string) $value);
|
||||
if ($value === '') {
|
||||
continue;
|
||||
}
|
||||
$aQuotedValues[] = "'".addslashes($value)."'";
|
||||
}
|
||||
|
||||
return empty($aQuotedValues) ? "''" : implode(', ', $aQuotedValues);
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws CoreUnexpectedValue
|
||||
* @throws CoreException
|
||||
* @throws MySQLException
|
||||
*/
|
||||
public function GetUsersFromFilter(DBObjectSearch|DBUnionSearch|null $oFilter, array $aOrderBy = [], array $aArgs = []): array
|
||||
{
|
||||
$aUsers = [];
|
||||
if (is_null($oFilter)) {
|
||||
return $aUsers;
|
||||
}
|
||||
$oSet = new DBObjectSet($oFilter, $aOrderBy, $aArgs);
|
||||
while ($oUser = $oSet->Fetch()) {
|
||||
$aUsers[] = $oUser;
|
||||
}
|
||||
|
||||
return $aUsers;
|
||||
return array_diff($aConsoleUsers, $aReadOnlyUsers);
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws Exception
|
||||
*/
|
||||
public function GetPortalUsers(bool $bAllData = true): array
|
||||
public function GetPortalUsers(bool $bAllData = true, array $aExcludedFinalClasses = ['UserToken', 'UserRemoteSaaS']): array
|
||||
{
|
||||
$sExcludedFinalClasses = $this->ArrayToOQLStringParameter($aExcludedFinalClasses);
|
||||
|
||||
$sOQLPortalUser = "
|
||||
SELECT User AS u
|
||||
JOIN URP_UserProfile AS uup ON uup.userid = u.id
|
||||
JOIN URP_Profiles AS up ON uup.profileid = up.id
|
||||
WHERE up.id = '2' AND u.status != 'disabled' ";
|
||||
WHERE up.id = '2' AND u.status != 'disabled' AND u.finalclass NOT IN ($sExcludedFinalClasses)";
|
||||
|
||||
try {
|
||||
$oFilter = $bAllData ? DBObjectSearch::FromOQL_AllData($sOQLPortalUser) : DBObjectSearch::FromOQL($sOQLPortalUser);
|
||||
} catch (Exception $e) {
|
||||
IssueLog::Error('Core:GetConsoleUsersQuota:Error : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetQuota:Error', Dict::S('Core:ApplicationUsers')));
|
||||
IssueLog::Error(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:PortalUsers')).' - error details : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:PortalUsers')).'.');
|
||||
}
|
||||
|
||||
return $this->GetUsersFromFilter($oFilter);
|
||||
@@ -143,13 +110,43 @@ class ITopUserCountingRepository
|
||||
}
|
||||
}
|
||||
|
||||
// remove portal users
|
||||
$aPortalUsers = $this->GetPortalUsers();
|
||||
$aReadOnlyUsers = array_diff($aReadOnlyUsers, $aPortalUsers);
|
||||
// remove disabled users
|
||||
$aDisabledUsers = $this->GetDisabledUsers();
|
||||
$aUserToken = $this->GetApplicationUsers();
|
||||
return array_diff($aReadOnlyUsers, $aUserToken);
|
||||
}
|
||||
|
||||
return array_diff($aReadOnlyUsers, $aDisabledUsers);
|
||||
/**
|
||||
* @throws Exception
|
||||
*/
|
||||
public function GetDisabledUsers(bool $bAllData = true): array
|
||||
{
|
||||
$sOQLDisabledUser = "
|
||||
SELECT User AS u
|
||||
WHERE u.status = 'disabled'
|
||||
";
|
||||
try {
|
||||
$oFilter = $bAllData ? DBObjectSearch::FromOQL_AllData($sOQLDisabledUser) : DBObjectSearch::FromOQL($sOQLDisabledUser);
|
||||
} catch (Exception $e) {
|
||||
IssueLog::Error(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:DisabledUsers')).' - error details : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:DisabledUsers')).'.');
|
||||
}
|
||||
|
||||
return $this->GetUsersFromFilter($oFilter);
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws Exception
|
||||
*/
|
||||
public function GetApplicationUsers(bool $bAllData = true): array
|
||||
{
|
||||
$sOQLApplicationUser = 'SELECT UserToken';
|
||||
try {
|
||||
$oFilter = $bAllData ? DBObjectSearch::FromOQL_AllData($sOQLApplicationUser) : DBObjectSearch::FromOQL($sOQLApplicationUser);
|
||||
} catch (Exception $e) {
|
||||
IssueLog::Error(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:ApplicationUsers')).' - error details : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:ApplicationUsers')).'.');
|
||||
}
|
||||
|
||||
return $this->GetUsersFromFilter($oFilter);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -162,8 +159,8 @@ class ITopUserCountingRepository
|
||||
try {
|
||||
$oFilter = $bAllData ? DBObjectSearch::FromOQL_AllData($sOqlUser) : DBObjectSearch::FromOQL($sOqlUser);
|
||||
} catch (Exception $e) {
|
||||
IssueLog::Error('combodo-users-quota-slave/GetUsersNotInQuota : '.$e->getMessage(), 'combodo-users-quota');
|
||||
throw new Exception(Dict::S('CombodoUserQuota:Error'));
|
||||
IssueLog::Error(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:AllUsers')).' - error details : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetCountingUsers:Error', Dict::S('Core:CountingUsers:AllUsers')).'.');
|
||||
}
|
||||
|
||||
return $this->GetUsersFromFilter($oFilter);
|
||||
@@ -179,28 +176,11 @@ class ITopUserCountingRepository
|
||||
*/
|
||||
private function IsUserReadOnly(User $oUser, string $sClassCategory): bool
|
||||
{
|
||||
if ($oUser->Get('status') == 'disabled') {
|
||||
return false;
|
||||
}
|
||||
|
||||
// check if user is a portal user
|
||||
$oProfileLinks = $oUser->Get('profile_list');
|
||||
while ($oLink = $oProfileLinks->Fetch()) {
|
||||
$iProfileId = $oLink->Get('profileid');
|
||||
if (!$iProfileId) {
|
||||
continue;
|
||||
}
|
||||
$oProfile = MetaModel::GetObject('URP_Profiles', $iProfileId, false);
|
||||
if ($oProfile && $oProfile->Get('name') === PORTAL_PROFILE_NAME) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
// login (mandatory to compute rights)
|
||||
UserRights::Login($oUser->GetName());
|
||||
|
||||
foreach (MetaModel::GetClasses($sClassCategory) as $sClass) {
|
||||
// no need to check stimuli for now since users can't execute stimulus without UR_ACTION_MODIFY
|
||||
// no need to check stimuli for now since users can't execute any without UR_ACTION_MODIFY
|
||||
if (
|
||||
UserRights::IsActionAllowed($sClass, UR_ACTION_MODIFY, null, $oUser) ||
|
||||
UserRights::IsActionAllowed($sClass, UR_ACTION_BULK_MODIFY, null, $oUser) ||
|
||||
@@ -216,37 +196,36 @@ class ITopUserCountingRepository
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws Exception
|
||||
* @throws CoreUnexpectedValue
|
||||
* @throws CoreException
|
||||
* @throws MySQLException
|
||||
*/
|
||||
public function GetDisabledUsers(bool $bAllData = true): array
|
||||
public function GetUsersFromFilter(DBObjectSearch|DBUnionSearch|null $oFilter, array $aOrderBy = [], array $aArgs = []): array
|
||||
{
|
||||
$sOQLDisabledUser = "
|
||||
SELECT User AS u
|
||||
WHERE u.status = 'disabled'
|
||||
";
|
||||
try {
|
||||
$oFilter = $bAllData ? DBObjectSearch::FromOQL_AllData($sOQLDisabledUser) : DBObjectSearch::FromOQL($sOQLDisabledUser);
|
||||
} catch (Exception $e) {
|
||||
IssueLog::Error('Core:GetDisabledUsersQuota:Error : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetQuota:Error', Dict::S('Core:DisabledUsers')));
|
||||
$aUsers = [];
|
||||
if (is_null($oFilter)) {
|
||||
return $aUsers;
|
||||
}
|
||||
$oSet = new DBObjectSet($oFilter, $aOrderBy, $aArgs);
|
||||
while ($oUser = $oSet->Fetch()) {
|
||||
$aUsers[] = $oUser;
|
||||
}
|
||||
|
||||
return $this->GetUsersFromFilter($oFilter);
|
||||
return $aUsers;
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws Exception
|
||||
*/
|
||||
public function GetApplicationUsers(bool $bAllData = true): array
|
||||
private function ArrayToOQLStringParameter(array $aValues): string
|
||||
{
|
||||
$sOQLApplicationUser = 'SELECT UserToken';
|
||||
try {
|
||||
$oFilter = $bAllData ? DBObjectSearch::FromOQL_AllData($sOQLApplicationUser) : DBObjectSearch::FromOQL($sOQLApplicationUser);
|
||||
} catch (Exception $e) {
|
||||
IssueLog::Error('Core:GetConsoleUsersQuota:Error : '.$e->getMessage());
|
||||
throw new Exception(Dict::Format('Core:GetQuota:Error', Dict::S('Core:ApplicationUsers')));
|
||||
$aQuotedValues = [];
|
||||
foreach ($aValues as $value) {
|
||||
$value = trim((string) $value);
|
||||
if ($value === '') {
|
||||
continue;
|
||||
}
|
||||
$aQuotedValues[] = "'".addslashes($value)."'";
|
||||
}
|
||||
|
||||
return $this->GetUsersFromFilter($oFilter);
|
||||
return empty($aQuotedValues) ? "''" : implode(', ', $aQuotedValues);
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -1466,6 +1466,31 @@ abstract class ItopDataTestCase extends ItopTestCase
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* @description To avoid adding finalclasses parameters to GivenUserInDB
|
||||
* @param string $sPassword
|
||||
* @param array $aProfiles Profile names Example: ['Administrator']
|
||||
* @param bool $bReturnLogin
|
||||
*
|
||||
* @return string|int The unique login
|
||||
* @throws \Exception
|
||||
*/
|
||||
protected function GivenTokenUserInDB(array $aProfiles, bool $bReturnLogin = true): string|int
|
||||
{
|
||||
$sLogin = 'demo_test_'.uniqid(__CLASS__, true);
|
||||
|
||||
$aProfileList = array_map(function ($sProfileId) {
|
||||
return 'profileid:'.self::$aURP_Profiles[$sProfileId];
|
||||
}, $aProfiles);
|
||||
|
||||
$iUser = $this->GivenObjectInDB('UserToken', [
|
||||
'login' => $sLogin,
|
||||
'language' => 'EN US',
|
||||
'profile_list' => $aProfileList,
|
||||
]);
|
||||
return $bReturnLogin ? $sLogin : $iUser;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param string $sPassword
|
||||
* @param array $aProfiles Profile names Example: ['Administrator']
|
||||
|
||||
@@ -12,6 +12,10 @@ class ITopUserCountingRepositoryTest extends ItopDataTestCase
|
||||
{
|
||||
parent::setUp();
|
||||
$this->CreateReadOnlyUsers();
|
||||
$this->CreateDisabledUsers();
|
||||
$this->CreatePortalUsers();
|
||||
$this->CreateTokenUsers();
|
||||
$this->CreateConsoleUsers();
|
||||
|
||||
}
|
||||
|
||||
@@ -20,18 +24,48 @@ class ITopUserCountingRepositoryTest extends ItopDataTestCase
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Configuration ReadOnly']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Ticket ReadOnly']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Service Catalog ReadOnly']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Configuration ReadOnly', 'Portal user']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Ticket ReadOnly', 'Portal user']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Service Catalog ReadOnly', 'Portal user']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Configuration ReadOnly', 'Ticket ReadOnly']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Ticket ReadOnly', 'Service Catalog ReadOnly']);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Configuration ReadOnly', 'Ticket ReadOnly', 'Service Catalog ReadOnly']);
|
||||
}
|
||||
|
||||
private function CreateDisabledUser()
|
||||
private function CreateDisabledUsers()
|
||||
{
|
||||
$sUser = $this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Configuration Manager']);
|
||||
// get user by login
|
||||
$oUser = \MetaModel::GetObjectByName('User', $sUser);
|
||||
$iDisabledUser = $this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Configuration Manager'], false);
|
||||
$oUser = \MetaModel::GetObject('User', $iDisabledUser);
|
||||
$oUser->Set('status', 'disabled');
|
||||
$oUser->DBUpdate();
|
||||
|
||||
$iDisabledReadOnlyUser = $this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Ticket ReadOnly'], false);
|
||||
$oUser = \MetaModel::GetObject('User', $iDisabledReadOnlyUser);
|
||||
$oUser->Set('status', 'disabled');
|
||||
$oUser->DBUpdate();
|
||||
}
|
||||
|
||||
private function CreatePortalUsers()
|
||||
{
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Portal user'], false);
|
||||
|
||||
$iDisabledPortalUser = $this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Portal user'], false);
|
||||
$oUser = \MetaModel::GetObject('User', $iDisabledPortalUser);
|
||||
$oUser->Set('status', 'disabled');
|
||||
$oUser->DBUpdate();
|
||||
}
|
||||
|
||||
private function CreateTokenUsers()
|
||||
{
|
||||
$this->GivenTokenUserInDB(['Configuration Manager'], false);
|
||||
$this->GivenTokenUserInDB(['Portal user'], false);
|
||||
$this->GivenTokenUserInDB(['Configuration ReadOnly'], false);
|
||||
}
|
||||
|
||||
private function CreateConsoleUsers()
|
||||
{
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Configuration Manager'], false);
|
||||
$this->GivenUserInDB('qpf_z17H3232*"ré$"é', ['Administrator'], false);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -110,5 +144,4 @@ class ITopUserCountingRepositoryTest extends ItopDataTestCase
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user