Re: [Tiki-devel] Permission inheritance

luciash via TikiWiki-devel <[email protected]>
Newsgroups gmane.comp.cms.tiki.devel
Message-ID <[email protected]>
Lovely! <3

On 03.02.2021 12:42, Jonny Bradley via TikiWiki-devel wrote:
> Hi Mike
>
> Yes, just like that, in fact the workspaces "feature" also uses categories and category permissions (and perspectives), but the fact that each file within a file gallery, or thread within a forum needed to be individually categorised as well made it sort of unusable.
>
> This is for a new project Geoff and i are working on, using http://doc.tiki.org/Templated-Groups and http://doc.tiki.org/Roles with category permissions, and we didn't realise that it still wasn't possible for most object types, only tracker items were done so far, so hence extending the same principle to various others.
>
> I'm hoping once it's working we can create some more documentation and maybe profiles to explain the process, it's taken a lot of guesswork and experimentation (and some code fixes) to get this far... nearly there we hope ;)
>
> So more soon!
>
> jonny
>
>
>
>> On 2 Feb 2021, at 18:55, Michael Finko <[email protected]> wrote:
>>
>> Hi Jonny,
>>
>> It sounds like you are trying to re-create 'Workspaces https://doc.tiki.org/Workspace' with Categories?
>> Though, I most likely do not understand your full use case.
>>
>> br,
>> Mike
>>
>> On Tue, Feb 2, 2021 at 7:53 PM Jonny Bradley via TikiWiki-devel <[email protected]> wrote:
>>> Hi all
>>>
>>> Well that grew into a bit of a monster task!
>>>
>>> Now pushed to trunk/master in https://gitlab.com/tikiwiki/tiki/-/commit/7b963065 - do you think you could take a look over it Victor (and anyone else fearless enough to venture into these areas) please? :)
>>>
>>> I need it in 22.x so am preparing a patch which i'll apply locally to a pre-production tiki so it should get some significant testing there, but if others could check in trunk before i backport for real that would be greatly reassuring!
>>>
>>> Basically, this fixes being able to set up permissions on a category, and be able to set that category on a file gallery, forum, blog or calendar, and the child objects inside them (files, threads, posts and events) will obey the perms set in their parent's category. Basically how it should have been forever, but wasn't ;)
>>>
>>> Many thanks to Victor again for doing the hard bit (several years ago), i just took the same theory used for tracker items and extended it a bit :p
>>>
>>> jonny
>>>
>>>
>>>
>>>
>>>> On 1 Feb 2021, at 14:41, Jonny Bradley via TikiWiki-devel <[email protected]> wrote:
>>>>
>>>> Thanks Victor, nice to hear :)
>>>>
>>>> I have a commit coming but added calendars and calendaritems, and blogs and blog posts to the category factory but need to set up test cases here locally to check i got the sql right...
>>>>
>>>> More soon
>>>>
>>>> jonny
>>>>
>>>>
>>>>
>>>>> On 1 Feb 2021, at 12:02, Victor Emanouilov via TikiWiki-devel <[email protected]> wrote:
>>>>>
>>>>> Hi Jonny,
>>>>>
>>>>> I think I'd have done it the same way! Looks good to me.
>>>>>
>>>>> File gallery->file relation actually works but only on object level (e.g. permission assigned to the file gallery will apply for all files under it and individual file permissions will apply for the files themselves). However, you are right that category factory needs more updates to make it happen - e.g. permission assigned to a file gallery via a category to be enforced for files underneath.
>>>>>
>>>>> Regards,
>>>>> Victor
>>>>>
>>>>> On 1/27/21 2:58 PM, Jonny Bradley via TikiWiki-devel wrote:
>>>>>> Hi Victor
>>>>>>
>>>>>> Thanks for the speedy reply 8)
>>>>>>
>>>>>> So to test i set all forum perms off globally and made a category (reg can see) that has all forum perms apart from tiki_p_admin_forum set for registered, and categorised a forum as "reg can see", and i can see the forum which should have the topics list, but none show up.
>>>>>>
>>>>>> I think i've got it working, but not going to commit it just now (new releases coming this afternoon!) but just in case you have a chance to look over this, here's the new patch (below).
>>>>>>
>>>>>> The main "magic" i was missing i think was the database lookup in CategoryFactory.php which i think i got working eventually.
>>>>>>
>>>>>> If this is all ok i'll commit it to trunk and test more before backporting, but then also i'd like to add files and file galleries support at least, because this has been a major "feature disappointment" since tiki 1.x :p
>>>>>>
>>>>>> Thanks V, catching up gradually! (wow, only 4 yours since https://gitlab.com/tikiwiki/tiki/-/commit/1ed83819 ;)
>>>>>>
>>>>>> jonny
>>>>>> ---
>>>>>>
>>>>>>
>>>>>> Index: lib/core/Perms/ResolverFactory/CategoryFactory.php
>>>>>> IDEA additional info:
>>>>>> Subsystem: com.intellij.openapi.diff.impl.patch.CharsetEP
>>>>>> <+>UTF-8
>>>>>> ===================================================================
>>>>>> diff --git a/lib/core/Perms/ResolverFactory/CategoryFactory.php b/lib/core/Perms/ResolverFactory/CategoryFactory.php
>>>>>> --- a/lib/core/Perms/ResolverFactory/CategoryFactory.php    (revision 5459652a28dd0edae95e16c103920985aa2c9d14)
>>>>>> +++ b/lib/core/Perms/ResolverFactory/CategoryFactory.php    (date 1611751776236)
>>>>>> @@ -88,7 +88,7 @@
>>>>>>              }
>>>>>>              // only trackeritem parents supported for now
>>>>>> -           if ($this->parent && $baseContext['type'] !== 'trackeritem') {
>>>>>> +           if ($this->parent && ! in_array($baseContext['type'], ['trackeritem', 'thread'])) {
>>>>>>                      return $values;
>>>>>>              }
>>>>>> @@ -155,6 +155,15 @@
>>>>>>                              INNER JOIN `tiki_category_objects` co ON co.`catObjectId` = o.`objectId` WHERE " .
>>>>>>                              $db->in('ti.itemId', array_keys($objects), $bindvars) . " ORDER BY co.`catObjectId`, co.`categId`",
>>>>>>                              $bindvars
>>>>>> +                   );
>>>>>> +           } else if ($baseContext['type'] === 'thread' && $this->parent) {
>>>>>> +                   $bindvars = [];
>>>>>> +                   $result = $db->fetchAll(
>>>>>> +                           "SELECT co.`categId`, comm.`threadId` AS itemId FROM `tiki_comments` comm
>>>>>> +                           INNER JOIN `tiki_objects` o ON comm.`object` = o.`itemId` AND o.`type` = 'forum'
>>>>>> +                           INNER JOIN `tiki_category_objects` co ON co.`catObjectId` = o.`objectId` WHERE " .
>>>>>> +                           $db->in('comm.threadId', array_keys($objects), $bindvars) . " ORDER BY co.`catObjectId`, co.`categId`",
>>>>>> +                           $bindvars
>>>>>>                      );
>>>>>>              } else {
>>>>>>                      $bindvars = [$baseContext['type']];
>>>>>> Index: tiki-view_forum_thread.php
>>>>>> IDEA additional info:
>>>>>> Subsystem: com.intellij.openapi.diff.impl.patch.CharsetEP
>>>>>> <+>UTF-8
>>>>>> ===================================================================
>>>>>> diff --git a/tiki-view_forum_thread.php b/tiki-view_forum_thread.php
>>>>>> --- a/tiki-view_forum_thread.php    (revision 5459652a28dd0edae95e16c103920985aa2c9d14)
>>>>>> +++ b/tiki-view_forum_thread.php    (date 1611751776287)
>>>>>> @@ -145,7 +145,7 @@
>>>>>> $commentslib->comment_add_hit($_REQUEST["comments_parentId"]);
>>>>>> $commentslib->mark_comment($user, $forumId, $_REQUEST["comments_parentId"]);
>>>>>> -$tikilib->get_perm_object($_REQUEST['comments_parentId'], 'thread');
>>>>>> +$tikilib->get_perm_object($_REQUEST['comments_parentId'], 'thread', '', true, $forumId);
>>>>>>    if ($user) {
>>>>>>      if ($forum_info["moderator"] == $user) {
>>>>>> Index: lib/tikilib.php
>>>>>> IDEA additional info:
>>>>>> Subsystem: com.intellij.openapi.diff.impl.patch.CharsetEP
>>>>>> <+>UTF-8
>>>>>> ===================================================================
>>>>>> diff --git a/lib/tikilib.php b/lib/tikilib.php
>>>>>> --- a/lib/tikilib.php       (revision 5459652a28dd0edae95e16c103920985aa2c9d14)
>>>>>> +++ b/lib/tikilib.php       (date 1611751776275)
>>>>>> @@ -4054,13 +4054,13 @@
>>>>>>       * @param bool $global
>>>>>>       * @return array|bool
>>>>>>       */
>>>>>> -   function get_perm_object($objectId, $objectType, $info = '', $global = true)
>>>>>> +   function get_perm_object($objectId, $objectType, $info = '', $global = true, $parentId = null)
>>>>>>      {
>>>>>>              global $user;
>>>>>>              $smarty = TikiLib::lib('smarty');
>>>>>>              $userlib = TikiLib::lib('user');
>>>>>> -           $perms = Perms::get([ 'type' => $objectType, 'object' => $objectId ]);
>>>>>> +           $perms = Perms::get([ 'type' => $objectType, 'object' => $objectId, 'parentId' => $parentId ]);
>>>>>>              if (empty($perms->getGroups())) {
>>>>>>                      $perms->setGroups($this->get_user_groups($user));
>>>>>>              }
>>>>>> Index: lib/comments/commentslib.php
>>>>>> IDEA additional info:
>>>>>> Subsystem: com.intellij.openapi.diff.impl.patch.CharsetEP
>>>>>> <+>UTF-8
>>>>>> ===================================================================
>>>>>> diff --git a/lib/comments/commentslib.php b/lib/comments/commentslib.php
>>>>>> --- a/lib/comments/commentslib.php  (revision 5459652a28dd0edae95e16c103920985aa2c9d14)
>>>>>> +++ b/lib/comments/commentslib.php  (date 1611751776224)
>>>>>> @@ -915,7 +915,7 @@
>>>>>>              $query .= $info['query'];
>>>>>>              $ret = $this->fetchAll($query, $info['bindvars'], $max, $offset);
>>>>>> -           $ret = $this->filter_topic_perms($ret);
>>>>>> +           $ret = $this->filter_topic_perms($ret, $forumId);
>>>>>>              foreach ($ret as &$res) {
>>>>>>                      $tid = $res['threadId'];
>>>>>> @@ -954,17 +954,17 @@
>>>>>>              return $this->getOne($query, $info['bindvars']);
>>>>>>      }
>>>>>> -   private function filter_topic_perms($topics) {
>>>>>> +   private function filter_topic_perms($topics, $forumId = null) {
>>>>>>              $topic_ids = array_map(function($row){
>>>>>>                      return $row['parentId'] > 0 ? $row['parentId'] : $row['threadId'];
>>>>>>              }, $topics);
>>>>>>              $topic_ids = array_unique($topic_ids);
>>>>>> -           Perms::bulk(['type' => 'thread'], 'object', $topic_ids);
>>>>>> +           Perms::bulk(['type' => 'thread', 'parentId' => $forumId], 'object', $topic_ids);
>>>>>>              $ret = [];
>>>>>>              foreach ($topics as $row) {
>>>>>>                      $topic_id = $row['parentId'] > 0 ? $row['parentId'] : $row['threadId'];
>>>>>> -                   $perms = Perms::get(['type' => 'thread', 'object' => $topic_id]);
>>>>>> +                   $perms = Perms::get(['type' => 'thread', 'object' => $topic_id, 'parentId' => $forumId]);
>>>>>>                      if ($perms->forum_read) {
>>>>>>                              $ret[] = $row;
>>>>>>                      }
>>>>>>
>>>>>>
>>>>>>
>>>>>>> On 27 Jan 2021, at 09:26, Victor Emanouilov via TikiWiki-devel <[email protected]> wrote:
>>>>>>>
>>>>>>> Hi Jonny,
>>>>>>>
>>>>>>> Does this comment in Perms_ResolverFactory_CategoryFactory help?
>>>>>>>
>>>>>>> * Parent parameter can be passed during initialization to configure
>>>>>>> * Factory to return parent object permissions. Currently only supports
>>>>>>> * TrackerItem parents (i.e. Trackers) category permissions. Parent
>>>>>>> * perissions are retrieved by loading categories for the parent and then
>>>>>>> * checking their permissions.
>>>>>>>
>>>>>>> If you use category permissions, maybe that's why parent->child inheritance does not work in forum context. For now parent->child permission check on category basis is done only for tracker->trackeritem relation. We could extend to forum->thread level but I am not use both of these can be categorized. Can you share a bit more about your use-case - where do you set categories and which categories get permissions?
>>>>>>>
>>>>>>> Regards,
>>>>>>> Victor
>>>>>>>
>>>>>>> On 1/27/21 11:11 AM, Jonny Bradley via TikiWiki-devel wrote:
>>>>>>>> Hi all, almost certainly something for Victor but others may know and/or benefit from sharing :)
>>>>>>>>
>>>>>>>> A couple of Tikis ago you added a "layer" to the Permissions system so that child objects could inherit the permission on their parents, like files in file galleries, and blog posts in blogs etc.
>>>>>>>>
>>>>>>>> We are deploying a tiki for a client that needs category permissions to work on forums, which we assumed they would but it seems not. A user can see how many "topics" (a.k.a. threads) there are in a forum, on tiki-forums.php, but not see the actual posts in tiki-view_forum.php or tiki-view_forum_thread.php.
>>>>>>>>
>>>>>>>> So i worked out the patch below, which gets the relevant parent forumId into the Perms::get function and hoped the Victor Magic would take over and all would be well... but it seems not. And stepping through the code i get lost, as usual, in \Perms_ResolverFactory_ObjectFactory::bulk and so on.
>>>>>>>>
>>>>>>>> What did i miss?
>>>>>>>>
>>>>>>>> Thanks in advance
>>>>>>>>
>>>>>>>> jonny
>>>>>>>> ----
>>>>>> [snip]
>>>>>>
>>>>>> _______________________________________________
>>>>>> TikiWiki-devel mailing list
>>>>>> [email protected]
>>>>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
>>>>>
>>>>> _______________________________________________
>>>>> TikiWiki-devel mailing list
>>>>> [email protected]
>>>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
>>>>>
>>>>
>>>>
>>>> _______________________________________________
>>>> TikiWiki-devel mailing list
>>>> [email protected]
>>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
>>>>
>>>
>>>
>>> _______________________________________________
>>> TikiWiki-devel mailing list
>>> [email protected]
>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
>>> _______________________________________________
>>> TikiWiki-devel mailing list
>>> [email protected]
>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
>
> _______________________________________________
> TikiWiki-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.