[-] BO : fixed access rights in employee permissions #PSCFV-3157

This commit is contained in:
dMetzger
2012-07-12 07:33:27 +00:00
parent fbdad2e97e
commit 16580ab714
2 changed files with 59 additions and 33 deletions
+2 -4
View File
@@ -2105,9 +2105,9 @@ class AdminControllerCore extends Controller
{ {
if ($obj->id) if ($obj->id)
{ {
$result = Shop::getShopById((int)$obj->id, $this->identifier, $this->table); $result = Shop::getShopById((int)$obj->id, $this->identifier, $this->table);
foreach ($result as $row) foreach ($result as $row)
$this->fields_value['shop'][$row['id_'.$input['type']]][] = $row[$this->identifier]; $this->fields_value['shop'][$row['id_'.$input['type']]][] = $row['id_shop'];
} }
} }
elseif (isset($input['lang']) && $input['lang']) elseif (isset($input['lang']) && $input['lang'])
@@ -2363,10 +2363,8 @@ class AdminControllerCore extends Controller
$assos = array(); $assos = array();
if (Tools::isSubmit('checkBoxShopAsso_'.$table)) if (Tools::isSubmit('checkBoxShopAsso_'.$table))
{
foreach (Tools::getValue('checkBoxShopAsso_'.$table) as $id_shop => $value) foreach (Tools::getValue('checkBoxShopAsso_'.$table) as $id_shop => $value)
$assos[] = (int)$id_shop; $assos[] = (int)$id_shop;
}
else if (Shop::getTotalShops(false) == 1)// if we do not have the checkBox multishop, we can have an admin with only one shop and being in multishop else if (Shop::getTotalShops(false) == 1)// if we do not have the checkBox multishop, we can have an admin with only one shop and being in multishop
$assos[] = (int)Shop::getContextShopID(); $assos[] = (int)Shop::getContextShopID();
return $assos; return $assos;
+57 -29
View File
@@ -35,6 +35,8 @@ class AdminEmployeesControllerCore extends AdminController
/** @var array tabs list*/ /** @var array tabs list*/
protected $tabs_list = array(); protected $tabs_list = array();
protected $restrict_edition = false;
public function __construct() public function __construct()
{ {
@@ -133,6 +135,8 @@ class AdminEmployeesControllerCore extends AdminController
if ($this->context->employee->id == Tools::getValue('id_employee')) if ($this->context->employee->id == Tools::getValue('id_employee'))
{ {
$this->tabAccess['view'] = '1'; $this->tabAccess['view'] = '1';
if (!$this->tabAccess['edit'])
$this->restrict_edition = true;
$this->tabAccess['edit'] = '1'; $this->tabAccess['edit'] = '1';
} }
} }
@@ -235,34 +239,33 @@ class AdminEmployeesControllerCore extends AdminController
'name' => 'bo_theme', 'name' => 'bo_theme',
'options' => array('query' => $this->themes), 'options' => array('query' => $this->themes),
'desc' => $this->l('Back Office theme') 'desc' => $this->l('Back Office theme')
),
array(
'type' => 'radio',
'label' => $this->l('Show screencast at log in:'),
'name' => 'bo_show_screencast',
'desc' => $this->l('Display the welcome video in the Admin panel dashboard at log in'),
'required' => false,
'class' => 't',
'is_bool' => true,
'values' => array(
array(
'id' => 'bo_show_screencast_on',
'value' => 1,
'label' => $this->l('Enabled')
),
array(
'id' => 'bo_show_screencast_off',
'value' => 0,
'label' => $this->l('Disabled')
)
)
) )
) )
); );
if ((int)$this->tabAccess['edit']) if ((int)$this->tabAccess['edit'] && !$this->restrict_edition)
{ {
$this->fields_form['input'][] = array(
'type' => 'radio',
'label' => $this->l('Show screencast at log in:'),
'name' => 'bo_show_screencast',
'required' => false,
'class' => 't',
'is_bool' => true,
'values' => array(
array(
'id' => 'bo_show_screencast_on',
'value' => 1,
'label' => $this->l('Enabled')
),
array(
'id' => 'bo_show_screencast_off',
'value' => 0,
'label' => $this->l('Disabled')
)
),
'desc' => $this->l('Display the welcome video in the Admin panel dashboard at log in')
);
$this->fields_form['input'][] = array( $this->fields_form['input'][] = array(
'type' => 'radio', 'type' => 'radio',
'label' => $this->l('Status:'), 'label' => $this->l('Status:'),
@@ -355,7 +358,6 @@ class AdminEmployeesControllerCore extends AdminController
$this->errors[] = Tools::displayError('This functionality has been disabled.'); $this->errors[] = Tools::displayError('This functionality has been disabled.');
return; return;
} }
/* PrestaShop demo mode*/
if ($this->context->employee->id == Tools::getValue('id_employee')) if ($this->context->employee->id == Tools::getValue('id_employee'))
{ {
@@ -366,8 +368,8 @@ class AdminEmployeesControllerCore extends AdminController
$employee = new Employee(Tools::getValue('id_employee')); $employee = new Employee(Tools::getValue('id_employee'));
if ($employee->isLastAdmin()) if ($employee->isLastAdmin())
{ {
$this->errors[] = Tools::displayError('You cannot disable or delete the last administrator account.'); $this->errors[] = Tools::displayError('You cannot disable or delete the last administrator account.');
return false; return false;
} }
// It is not possible to delete an employee if he manages warehouses // It is not possible to delete an employee if he manages warehouses
@@ -378,11 +380,37 @@ class AdminEmployeesControllerCore extends AdminController
return false; return false;
} }
} }
else if (Tools::isSubmit('submitAddemployee')) elseif (Tools::isSubmit('submitAddemployee'))
{ {
$employee = new Employee((int)Tools::getValue('id_employee')); $employee = new Employee((int)Tools::getValue('id_employee'));
if (!(int)$this->tabAccess['edit'])
// If the employee is editing its own account
if ($this->restrict_edition)
{
$_POST['id_profile'] = $_GET['id_profile'] = $employee->id_profile; $_POST['id_profile'] = $_GET['id_profile'] = $employee->id_profile;
$_POST['active'] = $_GET['active'] = $employee->active;
// Unset set shops
foreach ($_POST as $postkey => $postvalue)
if (strstr($postkey, 'checkBoxShopAsso_'.$this->table) !== false)
unset($_POST[$postkey]);
foreach ($_GET as $postkey => $postvalue)
if (strstr($postkey, 'checkBoxShopAsso_'.$this->table) !== false)
unset($_GET[$postkey]);
// Add current shops associated to the employee
$result = Shop::getShopById((int)$employee->id, $this->identifier, $this->table);
foreach ($result as $row)
{
$key = 'checkBoxShopAsso_'.$this->table;
if (!isset($_POST[$key]))
$_POST[$key] = array();
if (!isset($_GET[$key]))
$_GET[$key] = array();
$_POST[$key][$row['id_shop']] = 1;
$_GET[$key][$row['id_shop']] = 1;
}
}
if ($employee->isLastAdmin()) if ($employee->isLastAdmin())
{ {
@@ -402,7 +430,7 @@ class AdminEmployeesControllerCore extends AdminController
if (!in_array(Tools::getValue('bo_theme'), $this->themes)) if (!in_array(Tools::getValue('bo_theme'), $this->themes))
{ {
$this->errors[] = Tools::displayError('Invalid theme.'); $this->errors[] = Tools::displayError('Invalid theme.');
return false; return false;
} }
$assos = $this->getSelectedAssoShop($this->table); $assos = $this->getSelectedAssoShop($this->table);