1 | <?php |
||
11 | class RelatedObjectVoter implements VoterInterface |
||
12 | { |
||
13 | /** |
||
14 | * @var RoleHierarchyInterface |
||
15 | */ |
||
16 | protected $roleHierarchy; |
||
17 | |||
18 | /** |
||
19 | * @var LoggerInterface |
||
20 | */ |
||
21 | protected $logger; |
||
22 | |||
23 | /** |
||
24 | * @param RoleHierarchyInterface $roleHierarchy |
||
25 | * @param LoggerInterface $logger |
||
26 | */ |
||
27 | public function __construct(RoleHierarchyInterface $roleHierarchy, LoggerInterface $logger) |
||
28 | { |
||
29 | $this->roleHierarchy = $roleHierarchy; |
||
30 | $this->logger = $logger; |
||
31 | } |
||
32 | |||
33 | /** |
||
34 | * @param string $attribute |
||
35 | * @return bool |
||
36 | */ |
||
37 | public function supportsAttribute($attribute) |
||
41 | |||
42 | /** |
||
43 | * @param string $class |
||
44 | * @return bool |
||
45 | */ |
||
46 | public function supportsClass($class) |
||
47 | { |
||
48 | try { |
||
49 | $reflection = new \ReflectionClass($class); |
||
50 | } catch (\Exception $e) { |
||
51 | return false; |
||
52 | } |
||
53 | |||
54 | if ($reflection->implementsInterface('Dominikzogg\EnergyCalculator\Voter\RelatedObjectInterface')) { |
||
55 | return true; |
||
56 | } |
||
57 | |||
58 | return false; |
||
59 | } |
||
60 | |||
61 | /** |
||
62 | * @param TokenInterface $token |
||
63 | * @param null|object $object |
||
64 | * @param array $attributes |
||
65 | * @return int |
||
66 | */ |
||
67 | public function vote(TokenInterface $token, $object, array $attributes) |
||
68 | { |
||
69 | $voterName = $this->getName(); |
||
70 | |||
71 | if (!is_object($object)) { |
||
72 | $this->logger->debug(sprintf('RelatedObjectVoter %s not received an object. Voting to abstain.', $voterName)); |
||
73 | |||
74 | return self::ACCESS_ABSTAIN; |
||
75 | } |
||
76 | |||
77 | $user = $token->getUser(); |
||
78 | if (!$user instanceof UserInterface) { |
||
79 | $this->logger->debug(sprintf('RelatedObjectVoter %s not received an valid user object. Voting to abstain.', $voterName)); |
||
80 | |||
81 | return self::ACCESS_ABSTAIN; |
||
82 | } |
||
83 | |||
84 | if (!$this->supportsClass($object)) { |
||
85 | $objectString = is_object($object) ? get_class($object) : gettype($object); |
||
86 | $this->logger->debug(sprintf('RelatedObjectVoter %s does not support class %s. Voting to abstain.', $voterName, $objectString)); |
||
87 | |||
88 | return self::ACCESS_ABSTAIN; |
||
89 | } |
||
90 | |||
91 | $userRoles = $this->getUserRoles($token); |
||
92 | foreach ($this->getNeededRoles($attributes, $object) as $neededRole) { |
||
93 | if (!in_array($neededRole, $userRoles)) { |
||
94 | $this->logger->debug(sprintf('Needed Role "%s" not found on user. Voting to abstain.', $neededRole)); |
||
95 | |||
96 | return self::ACCESS_ABSTAIN; |
||
97 | } |
||
98 | } |
||
99 | |||
100 | if (true === $this->isRelatedObject($user, $object)) { |
||
101 | $this->logger->debug(sprintf('Object is RelatedObject (%s). Voting to grant access.', $voterName)); |
||
102 | |||
103 | return self::ACCESS_GRANTED; |
||
104 | } |
||
105 | |||
106 | $this->logger->debug(sprintf('Object is not RelatedObject (%s). Voting to abstain.', $voterName)); |
||
107 | |||
108 | return self::ACCESS_ABSTAIN; |
||
109 | } |
||
110 | |||
111 | /** |
||
112 | * @param TokenInterface $token |
||
113 | * @return array |
||
114 | */ |
||
115 | protected function getUserRoles(TokenInterface $token) |
||
116 | { |
||
117 | $roles = array(); |
||
118 | |||
119 | foreach ($this->roleHierarchy->getReachableRoles($token->getRoles()) as $role) { |
||
120 | $roles[] = $role->getRole(); |
||
121 | } |
||
122 | |||
123 | return array_unique($roles); |
||
124 | } |
||
125 | |||
126 | /** |
||
127 | * @param array $attributes |
||
128 | * @param RelatedObjectInterface $object |
||
129 | * @return array |
||
130 | */ |
||
131 | protected function getNeededRoles(array $attributes, RelatedObjectInterface $object) |
||
132 | { |
||
133 | $roles = array(); |
||
134 | $prefix = $this->getNeededRolesPrefix($object); |
||
135 | foreach ($attributes as $attribute) { |
||
136 | $roles[] = $prefix.$attribute; |
||
137 | } |
||
138 | |||
139 | return $roles; |
||
140 | } |
||
141 | |||
142 | /** |
||
143 | * @param RelatedObjectInterface $object |
||
144 | * @return string |
||
145 | */ |
||
146 | protected function getNeededRolesPrefix(RelatedObjectInterface $object) |
||
150 | |||
151 | /** |
||
152 | * @param RelatedObjectInterface $user |
||
153 | * @param RelatedObjectInterface $object |
||
154 | * @return bool |
||
155 | */ |
||
156 | protected function isRelatedObject(RelatedObjectInterface $user, RelatedObjectInterface $object) |
||
168 | |||
169 | /** |
||
170 | * @return string |
||
171 | */ |
||
172 | protected function getName() |
||
173 | { |
||
178 | } |
||
179 |
This check looks from parameters that have been defined for a function or method, but which are not used in the method body.