[-] BO : #PSTEST-931 : fix bug in AdminAccess

This commit is contained in:
lLefevre
2012-03-06 16:46:54 +00:00
parent c124fb2a0a
commit fd317ae249
3 changed files with 36 additions and 39 deletions
@@ -48,7 +48,7 @@
var tabnumber = tout[4]; var tabnumber = tout[4];
var table = 'table#table_'+id_profile; var table = 'table#table_'+id_profile;
perfect_access_js_gestion(this, perm, id_tab, tabsize, tabnumber, table); perfect_access_js_gestion(this, perm, id_tab, tabsize, tabnumber, table, '{$id_tab_access}');
$.ajax({ $.ajax({
url: "{$link->getAdminLink('AdminAccess')}", url: "{$link->getAdminLink('AdminAccess')}",
@@ -62,7 +62,7 @@
submitAddAccess: '1', submitAddAccess: '1',
action: 'updateAccess', action: 'updateAccess',
ajax: '1', ajax: '1',
token: '{getAdminToken tab='AdminAccess'}', token: '{getAdminToken tab='AdminAccess'}'
}, },
success : function(res,textStatus,jqXHR) success : function(res,textStatus,jqXHR)
{ {
@@ -86,7 +86,7 @@
var id_module = tout[0]; var id_module = tout[0];
var perm = tout[1]; var perm = tout[1];
var id_profile = tout[2]; var id_profile = tout[2];
var enabled = $(this).is(':checked')? 1 : 0; var enabled = $(this).is(':checked') ? 1 : 0;
var table = 'table#table_module_'+id_profile; var table = 'table#table_module_'+id_profile;
if (id_module == -1) if (id_module == -1)
@@ -110,7 +110,7 @@
changeModuleAccess: '1', changeModuleAccess: '1',
action: 'updateModuleAccess', action: 'updateModuleAccess',
ajax: '1', ajax: '1',
token: '{getAdminToken tab='AdminAccess'}', token: '{getAdminToken tab='AdminAccess'}'
}, },
success : function(res,textStatus,jqXHR) success : function(res,textStatus,jqXHR)
{ {
+28 -31
View File
@@ -27,9 +27,12 @@
class AdminAccessControllerCore extends AdminController class AdminAccessControllerCore extends AdminController
{ {
/* Black list of id_tab that do not have access */ /* @var array : Black list of id_tab that do not have access */
public $accesses_black_list = array(); public $accesses_black_list = array();
/* @var int : id tab of controller AdminAccess */
public $id_tab_access;
public function __construct() public function __construct()
{ {
$this->table = 'access'; $this->table = 'access';
@@ -40,6 +43,9 @@ class AdminAccessControllerCore extends AdminController
// Blacklist AdminLogin // Blacklist AdminLogin
$this->accesses_black_list[] = Tab::getIdFromClassName('AdminLogin'); $this->accesses_black_list[] = Tab::getIdFromClassName('AdminLogin');
// Get id tab of controller AdminAccess
$this->id_tab_access = (int)Db::getInstance()->getValue('SELECT `id_tab` FROM `'._DB_PREFIX_.'tab` WHERE `class_name` = "AdminAccess"');
parent::__construct(); parent::__construct();
} }
@@ -100,7 +106,8 @@ class AdminAccessControllerCore extends AdminController
'access_edit' => $this->tabAccess['edit'], 'access_edit' => $this->tabAccess['edit'],
'perms' => array('view', 'add', 'edit', 'delete'), 'perms' => array('view', 'add', 'edit', 'delete'),
'modules' => $modules, 'modules' => $modules,
'link' => $this->context->link 'link' => $this->context->link,
'id_tab_access' => (int)$this->id_tab_access
); );
return parent::renderForm(); return parent::renderForm();
@@ -143,41 +150,37 @@ class AdminAccessControllerCore extends AdminController
$enabled = (int)Tools::getValue('enabled'); $enabled = (int)Tools::getValue('enabled');
$id_tab = (int)Tools::getValue('id_tab'); $id_tab = (int)Tools::getValue('id_tab');
$id_profile = (int)Tools::getValue('id_profile'); $id_profile = (int)Tools::getValue('id_profile');
$res = true;
if ($id_tab == -1 && $perm == 'all' && $enabled == 0) if ($id_tab == -1 && $perm == 'all' && $enabled == 0)
$res &= Db::getInstance()->execute(' $sql = '
UPDATE `'._DB_PREFIX_.'access` UPDATE `'._DB_PREFIX_.'access`
SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.' SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.'
WHERE `id_profile` = '.(int)$id_profile.' AND `id_tab` != 31 WHERE `id_profile` = '.(int)$id_profile.' AND `id_tab` != '.(int)$this->id_tab_access;
');
else if ($id_tab == -1 && $perm == 'all') else if ($id_tab == -1 && $perm == 'all')
$res &= Db::getInstance()->execute(' $sql = '
UPDATE `'._DB_PREFIX_.'access` UPDATE `'._DB_PREFIX_.'access`
SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.' SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.'
WHERE `id_profile` = '.(int)$id_profile WHERE `id_profile` = '.(int)$id_profile;
);
else if ($id_tab == -1) else if ($id_tab == -1)
$res &= Db::getInstance()->execute(' $sql = '
UPDATE `'._DB_PREFIX_.'access` UPDATE `'._DB_PREFIX_.'access`
SET `'.bqSQL($perm).'` = '.(int)$enabled.' SET `'.bqSQL($perm).'` = '.(int)$enabled.'
WHERE `id_profile` = '.(int)$id_profile WHERE `id_profile` = '.(int)$id_profile;
);
else if ($perm == 'all') else if ($perm == 'all')
$res &= Db::getInstance()->execute(' $sql = '
UPDATE `'._DB_PREFIX_.'access` UPDATE `'._DB_PREFIX_.'access`
SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.' SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.'
WHERE `id_tab` = '.(int)$id_tab.' WHERE `id_tab` = '.(int)$id_tab.'
AND `id_profile` = '.(int)$id_profile AND `id_profile` = '.(int)$id_profile;
);
else else
$res &= Db::getInstance()->execute(' $sql = '
UPDATE `'._DB_PREFIX_.'access` UPDATE `'._DB_PREFIX_.'access`
SET `'.bqSQL($perm).'` = '.(int)$enabled.' SET `'.bqSQL($perm).'` = '.(int)$enabled.'
WHERE `id_tab` = '.(int)$id_tab.' WHERE `id_tab` = '.(int)$id_tab.'
AND `id_profile` = '.(int)$id_profile AND `id_profile` = '.(int)$id_profile;
);
$res = $res?'ok':'error'; $res = Db::getInstance()->execute($sql) ? 'ok' : 'error';
die($res); die($res);
} }
} }
@@ -194,30 +197,24 @@ class AdminAccessControllerCore extends AdminController
$enabled = (int)Tools::getValue('enabled'); $enabled = (int)Tools::getValue('enabled');
$id_module = (int)Tools::getValue('id_module'); $id_module = (int)Tools::getValue('id_module');
$id_profile = (int)Tools::getValue('id_profile'); $id_profile = (int)Tools::getValue('id_profile');
$res = true;
if (!in_array($perm, array('view', 'configure'))) if (!in_array($perm, array('view', 'configure')))
throw new PrestaShopException('permission not exists'); throw new PrestaShopException('permission not exists');
if ($id_module == -1) if ($id_module == -1)
{ $sql = '
$res &= Db::getInstance()->execute('
UPDATE `'._DB_PREFIX_.'module_access` UPDATE `'._DB_PREFIX_.'module_access`
SET `'.bqSQL($perm).'` = '.(int)$enabled.' SET `'.bqSQL($perm).'` = '.(int)$enabled.'
WHERE `id_profile` = '.(int)$id_profile WHERE `id_profile` = '.(int)$id_profile;
);
}
else else
{ $sql = '
$res &= Db::getInstance()->execute('
UPDATE `'._DB_PREFIX_.'module_access` UPDATE `'._DB_PREFIX_.'module_access`
SET `'.bqSQL($perm).'` = '.(int)$enabled.' SET `'.bqSQL($perm).'` = '.(int)$enabled.'
WHERE `id_module` = '.(int)$id_module.' WHERE `id_module` = '.(int)$id_module.'
AND `id_profile` = '.(int)$id_profile AND `id_profile` = '.(int)$id_profile;
);
} $res = Db::getInstance()->execute($sql) ? 'ok' : 'error';
$res = $res?'ok':'error';
die($res); die($res);
} }
} }
+3 -3
View File
@@ -87,7 +87,7 @@ function check_for_all_accesses(tabsize, tabnumber)
} }
} }
function perfect_access_js_gestion(src, action, id_tab, tabsize, tabnumber, table) function perfect_access_js_gestion(src, action, id_tab, tabsize, tabnumber, table, id_tab_access)
{ {
if (id_tab == '-1' && action == 'all') if (id_tab == '-1' && action == 'all')
{ {
@@ -96,14 +96,14 @@ function perfect_access_js_gestion(src, action, id_tab, tabsize, tabnumber, tabl
$(table+' .delete').attr('checked', src.checked); $(table+' .delete').attr('checked', src.checked);
$(table+' .view').attr('checked', src.checked); $(table+' .view').attr('checked', src.checked);
$(table+' .all').attr('checked', src.checked); $(table+' .all').attr('checked', src.checked);
$(table+' .31').attr('checked', "checked"); $(table+' .'+id_tab_access).attr('checked', "checked");
} }
else if (action == 'all') else if (action == 'all')
$(table+' .'+id_tab).attr('checked', src.checked); $(table+' .'+id_tab).attr('checked', src.checked);
else if (id_tab == '-1') else if (id_tab == '-1')
{ {
$(table+' .'+action).attr('checked', src.checked); $(table+' .'+action).attr('checked', src.checked);
$(table+' #'+action+'31').attr('checked', "checked"); $(table+' #'+action+id_tab_access).attr('checked', "checked");
} }
check_for_all_accesses(tabsize, tabnumber); check_for_all_accesses(tabsize, tabnumber);
} }