View source
<?php
namespace Drupal\webform;
use Drupal\Component\Utility\SortArray;
use Drupal\Core\Extension\ModuleHandlerInterface;
use Drupal\Core\Session\AccountInterface;
use Drupal\Core\StringTranslation\StringTranslationTrait;
use Drupal\webform\Access\WebformAccessResult;
class WebformAccessRulesManager implements WebformAccessRulesManagerInterface {
use StringTranslationTrait;
protected $moduleHandler;
public function __construct(ModuleHandlerInterface $module_handler) {
$this->moduleHandler = $module_handler;
}
public function checkWebformAccess($operation, AccountInterface $account, WebformInterface $webform) {
$access_rules = $this
->getAccessRules($webform);
$cache_per_user = $this
->cachePerUser($access_rules);
$condition = $this
->checkAccessRules($operation, $account, $access_rules);
return WebformAccessResult::allowedIf($condition, $webform, $cache_per_user);
}
public function checkWebformSubmissionAccess($operation, AccountInterface $account, WebformSubmissionInterface $webform_submission) {
$webform = $webform_submission
->getWebform();
$access_rules = $this
->getAccessRules($webform);
$cache_per_user = $this
->cachePerUser($access_rules);
if ($this
->checkAccessRules($operation, $account, $access_rules)) {
return WebformAccessResult::allowed($webform_submission, $cache_per_user);
}
if ($webform_submission
->isOwner($account) && isset($access_rules[$operation . '_own']) && $this
->checkAccessRule($access_rules[$operation . '_own'], $account)) {
return WebformAccessResult::allowed($webform_submission, $cache_per_user);
}
if (isset($access_rules[$operation . '_any']) && $this
->checkAccessRule($access_rules[$operation . '_any'], $account)) {
return WebformAccessResult::allowed($webform_submission, $cache_per_user);
}
return WebformAccessResult::neutral($webform_submission, $cache_per_user);
}
public function getDefaultAccessRules() {
$access_rules = [];
foreach ($this
->getAccessRulesInfo() as $access_rule => $info) {
$access_rules[$access_rule] = [
'roles' => $info['roles'],
'users' => $info['users'],
'permissions' => $info['permissions'],
];
}
return $access_rules;
}
public function getAccessRulesInfo() {
$access_rules = $this->moduleHandler
->invokeAll('webform_access_rules');
$this->moduleHandler
->alter('webform_access_rules', $access_rules);
foreach ($access_rules as $access_rule => $info) {
$access_rules[$access_rule] += [
'title' => NULL,
'description' => NULL,
'weight' => 0,
'roles' => [],
'users' => [],
'permissions' => [],
];
}
uasort($access_rules, [
SortArray::class,
'sortByWeightElement',
]);
return $access_rules;
}
public function getAccessRules(WebformInterface $webform) {
return $webform
->getAccessRules() + $this
->getDefaultAccessRules();
}
public function checkAccessRules($operation, AccountInterface $account, array $access_rules) {
if ($this
->checkAccessRule($access_rules['administer'], $account)) {
return TRUE;
}
if (isset($access_rules[$operation]) && $this
->checkAccessRule($access_rules[$operation], $account)) {
return TRUE;
}
return FALSE;
}
protected function checkAccessRule(array $access_rule, AccountInterface $account) {
if (!empty($access_rule['roles']) && array_intersect($access_rule['roles'], $account
->getRoles())) {
return TRUE;
}
elseif (!empty($access_rule['users']) && in_array($account
->id(), $access_rule['users'])) {
return TRUE;
}
elseif (!empty($access_rule['permissions'])) {
foreach ($access_rule['permissions'] as $permission) {
if ($account
->hasPermission($permission)) {
return TRUE;
}
}
}
return FALSE;
}
public function cachePerUser(array $access_rules) {
foreach ($access_rules as $access_rule) {
if (!empty($access_rule['users'])) {
return TRUE;
}
}
return FALSE;
}
}