Passed
Push — master ( b9cd2f...6ed2ee )
by Jan
03:56
created

UserVoter::supports()   A

Complexity

Conditions 2
Paths 2

Size

Total Lines 12
Code Lines 6

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 2
eloc 6
nc 2
nop 2
dl 0
loc 12
rs 10
c 0
b 0
f 0
1
<?php
2
/**
3
 *
4
 * part-db version 0.1
5
 * Copyright (C) 2005 Christoph Lechner
6
 * http://www.cl-projects.de/
7
 *
8
 * part-db version 0.2+
9
 * Copyright (C) 2009 K. Jacobs and others (see authors.php)
10
 * http://code.google.com/p/part-db/
11
 *
12
 * Part-DB Version 0.4+
13
 * Copyright (C) 2016 - 2019 Jan Böhmer
14
 * https://github.com/jbtronics
15
 *
16
 * This program is free software; you can redistribute it and/or
17
 * modify it under the terms of the GNU General Public License
18
 * as published by the Free Software Foundation; either version 2
19
 * of the License, or (at your option) any later version.
20
 *
21
 * This program is distributed in the hope that it will be useful,
22
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
23
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
24
 * GNU General Public License for more details.
25
 *
26
 * You should have received a copy of the GNU General Public License
27
 * along with this program; if not, write to the Free Software
28
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA
29
 *
30
 */
31
32
namespace App\Security\Voter;
33
34
35
use App\Entity\User;
36
37
class UserVoter extends ExtendedVoter
38
{
39
40
    /**
41
     * Determines if the attribute and subject are supported by this voter.
42
     *
43
     * @param string $attribute An attribute
44
     * @param mixed $subject The subject to secure, e.g. an object the user wants to access or any other PHP type
45
     *
46
     * @return bool True if the attribute and subject are supported, false otherwise
47
     */
48
    protected function supports($attribute, $subject)
49
    {
50
        if($subject instanceof User)
51
        {
52
            return in_array($attribute, array_merge(
53
                $this->resolver->listOperationsForPermission('users'),
54
                $this->resolver->listOperationsForPermission('self')),
55
            false
56
            );
57
        }
58
59
        return false;
60
    }
61
62
    /**
63
     * Similar to voteOnAttribute, but checking for the anonymous user is already done.
64
     * The current user (or the anonymous user) is passed by $user.
65
     * @param $attribute
66
     * @param $subject
67
     * @param User $user
68
     * @return bool
69
     */
70
    protected function voteOnUser($attribute, $subject, User $user): bool
71
    {
72
        if($subject instanceof User)
73
        {
74
            //Check if the checked user is the user itself
75
            if($subject->getID() === $user->getID() &&
76
                $this->resolver->isValidOperation('self', $attribute)) {
77
                //Then we also need to check the self permission
78
                $tmp = $this->resolver->inherit($user, 'self', $attribute) ?? false;
79
                //But if the self value is not allowed then use just the user value:
80
                if($tmp)
81
                    return $tmp;
82
            }
83
            //Else just check users permission:
84
            return $this->resolver->inherit($user, 'users', $attribute) ?? false;
85
        }
86
87
        return false;
88
    }
89
90
91
}