Completed
Pull Request — rbac (#446)
by Simon
04:22
created
smarty-plugins/modifier.date.php 1 patch
Indentation   +11 added lines, -11 removed lines patch added patch discarded remove patch
@@ -16,16 +16,16 @@
 block discarded – undo
16 16
  */
17 17
 function smarty_modifier_date($input)
18 18
 {
19
-    if (gettype($input) === 'object'
20
-        && (get_class($input) === DateTime::class || get_class($input) === DateTimeImmutable::class)
21
-    ) {
22
-        /** @var $date DateTime|DateTimeImmutable */
23
-        $date = $input;
24
-        $dateString = $date->format('Y-m-d H:i:s');
19
+	if (gettype($input) === 'object'
20
+		&& (get_class($input) === DateTime::class || get_class($input) === DateTimeImmutable::class)
21
+	) {
22
+		/** @var $date DateTime|DateTimeImmutable */
23
+		$date = $input;
24
+		$dateString = $date->format('Y-m-d H:i:s');
25 25
 
26
-        return $dateString;
27
-    }
28
-    else {
29
-        return $input;
30
-    }
26
+		return $dateString;
27
+	}
28
+	else {
29
+		return $input;
30
+	}
31 31
 }
32 32
\ No newline at end of file
Please login to merge, or discard this patch.
includes/Helpers/SearchHelpers/LogSearchHelper.php 1 patch
Indentation   +73 added lines, -73 removed lines patch added patch discarded remove patch
@@ -13,87 +13,87 @@
 block discarded – undo
13 13
 
14 14
 class LogSearchHelper extends SearchHelperBase
15 15
 {
16
-    /**
17
-     * LogSearchHelper constructor.
18
-     *
19
-     * @param PdoDatabase $database
20
-     */
21
-    protected function __construct(PdoDatabase $database)
22
-    {
23
-        parent::__construct($database, 'log', Log::class, 'timestamp DESC');
24
-    }
16
+	/**
17
+	 * LogSearchHelper constructor.
18
+	 *
19
+	 * @param PdoDatabase $database
20
+	 */
21
+	protected function __construct(PdoDatabase $database)
22
+	{
23
+		parent::__construct($database, 'log', Log::class, 'timestamp DESC');
24
+	}
25 25
 
26
-    /**
27
-     * Initiates a search for requests
28
-     *
29
-     * @param PdoDatabase $database
30
-     *
31
-     * @return LogSearchHelper
32
-     */
33
-    public static function get(PdoDatabase $database)
34
-    {
35
-        $helper = new LogSearchHelper($database);
26
+	/**
27
+	 * Initiates a search for requests
28
+	 *
29
+	 * @param PdoDatabase $database
30
+	 *
31
+	 * @return LogSearchHelper
32
+	 */
33
+	public static function get(PdoDatabase $database)
34
+	{
35
+		$helper = new LogSearchHelper($database);
36 36
 
37
-        return $helper;
38
-    }
37
+		return $helper;
38
+	}
39 39
 
40
-    /**
41
-     * Filters the results by user
42
-     *
43
-     * @param int $userId
44
-     *
45
-     * @return $this
46
-     */
47
-    public function byUser($userId)
48
-    {
49
-        $this->whereClause .= ' AND user = ?';
50
-        $this->parameterList[] = $userId;
40
+	/**
41
+	 * Filters the results by user
42
+	 *
43
+	 * @param int $userId
44
+	 *
45
+	 * @return $this
46
+	 */
47
+	public function byUser($userId)
48
+	{
49
+		$this->whereClause .= ' AND user = ?';
50
+		$this->parameterList[] = $userId;
51 51
 
52
-        return $this;
53
-    }
52
+		return $this;
53
+	}
54 54
 
55
-    /**
56
-     * Filters the results by log action
57
-     *
58
-     * @param string $action
59
-     *
60
-     * @return $this
61
-     */
62
-    public function byAction($action)
63
-    {
64
-        $this->whereClause .= ' AND action = ?';
65
-        $this->parameterList[] = $action;
55
+	/**
56
+	 * Filters the results by log action
57
+	 *
58
+	 * @param string $action
59
+	 *
60
+	 * @return $this
61
+	 */
62
+	public function byAction($action)
63
+	{
64
+		$this->whereClause .= ' AND action = ?';
65
+		$this->parameterList[] = $action;
66 66
 
67
-        return $this;
68
-    }
67
+		return $this;
68
+	}
69 69
 
70
-    /**
71
-     * Filters the results by object type
72
-     *
73
-     * @param string $objectType
74
-     *
75
-     * @return $this
76
-     */
77
-    public function byObjectType($objectType)
78
-    {
79
-        $this->whereClause .= ' AND objecttype = ?';
80
-        $this->parameterList[] = $objectType;
70
+	/**
71
+	 * Filters the results by object type
72
+	 *
73
+	 * @param string $objectType
74
+	 *
75
+	 * @return $this
76
+	 */
77
+	public function byObjectType($objectType)
78
+	{
79
+		$this->whereClause .= ' AND objecttype = ?';
80
+		$this->parameterList[] = $objectType;
81 81
 
82
-        return $this;
83
-    }
82
+		return $this;
83
+	}
84 84
 
85
-    /**
86
-     * Filters the results by object type
87
-     *
88
-     * @param integer $objectId
89
-     *
90
-     * @return $this
91
-     */
92
-    public function byObjectId($objectId)
93
-    {
94
-        $this->whereClause .= ' AND objectid = ?';
95
-        $this->parameterList[] = $objectId;
85
+	/**
86
+	 * Filters the results by object type
87
+	 *
88
+	 * @param integer $objectId
89
+	 *
90
+	 * @return $this
91
+	 */
92
+	public function byObjectId($objectId)
93
+	{
94
+		$this->whereClause .= ' AND objectid = ?';
95
+		$this->parameterList[] = $objectId;
96 96
 
97
-        return $this;
98
-    }
97
+		return $this;
98
+	}
99 99
 }
100 100
\ No newline at end of file
Please login to merge, or discard this patch.
includes/Tasks/PageBase.php 3 patches
Indentation   +337 added lines, -337 removed lines patch added patch discarded remove patch
@@ -20,341 +20,341 @@
 block discarded – undo
20 20
 
21 21
 abstract class PageBase extends TaskBase implements IRoutedTask
22 22
 {
23
-    use TemplateOutput;
24
-    /** @var string Smarty template to display */
25
-    protected $template = "base.tpl";
26
-    /** @var string HTML title. Currently unused. */
27
-    protected $htmlTitle;
28
-    /** @var bool Determines if the page is a redirect or not */
29
-    protected $isRedirecting = false;
30
-    /** @var array Queue of headers to be sent on successful completion */
31
-    protected $headerQueue = array();
32
-    /** @var string The name of the route to use, as determined by the request router. */
33
-    private $routeName = null;
34
-    /** @var TokenManager */
35
-    protected $tokenManager;
36
-    /** @var string[] Extra CSS files to include */
37
-    private $extraCss = array();
38
-    /** @var string[] Extra JS files to include */
39
-    private $extraJs = array();
40
-
41
-    /**
42
-     * Sets the route the request will take. Only should be called from the request router or barrier test.
43
-     *
44
-     * @param string $routeName        The name of the route
45
-     * @param bool   $skipCallableTest Don't use this unless you know what you're doing, and what the implications are.
46
-     *
47
-     * @throws Exception
48
-     * @category Security-Critical
49
-     */
50
-    final public function setRoute($routeName, $skipCallableTest = false)
51
-    {
52
-        // Test the new route is callable before adopting it.
53
-        if (!$skipCallableTest && !is_callable(array($this, $routeName))) {
54
-            throw new Exception("Proposed route '$routeName' is not callable.");
55
-        }
56
-
57
-        // Adopt the new route
58
-        $this->routeName = $routeName;
59
-    }
60
-
61
-    /**
62
-     * Gets the name of the route that has been passed from the request router.
63
-     * @return string
64
-     */
65
-    final public function getRouteName()
66
-    {
67
-        return $this->routeName;
68
-    }
69
-
70
-    /**
71
-     * Performs generic page setup actions
72
-     */
73
-    final protected function setupPage()
74
-    {
75
-        $this->setUpSmarty();
76
-
77
-        $siteNoticeText = SiteNotice::get($this->getDatabase());
78
-
79
-        $this->assign('siteNoticeText', $siteNoticeText);
80
-
81
-        $currentUser = User::getCurrent($this->getDatabase());
82
-        $this->assign('currentUser', $currentUser);
83
-        $this->assign('loggedIn', (!$currentUser->isCommunityUser()));
84
-    }
85
-
86
-    /**
87
-     * Runs the page logic as routed by the RequestRouter
88
-     *
89
-     * Only should be called after a security barrier! That means only from execute().
90
-     */
91
-    final protected function runPage()
92
-    {
93
-        $database = $this->getDatabase();
94
-
95
-        // initialise a database transaction
96
-        if (!$database->beginTransaction()) {
97
-            throw new Exception('Failed to start transaction on primary database.');
98
-        }
99
-
100
-        try {
101
-            // run the page code
102
-            $this->{$this->getRouteName()}();
103
-
104
-            $database->commit();
105
-        }
106
-        catch (ApplicationLogicException $ex) {
107
-            // it's an application logic exception, so nothing went seriously wrong with the site. We can use the
108
-            // standard templating system for this.
109
-
110
-            // Firstly, let's undo anything that happened to the database.
111
-            $database->rollBack();
112
-
113
-            // Reset smarty
114
-            $this->setUpSmarty();
115
-
116
-            // Set the template
117
-            $this->setTemplate('exception/application-logic.tpl');
118
-            $this->assign('message', $ex->getMessage());
119
-
120
-            // Force this back to false
121
-            $this->isRedirecting = false;
122
-            $this->headerQueue = array();
123
-        }
124
-        catch (OptimisticLockFailedException $ex) {
125
-            // it's an optimistic lock failure exception, so nothing went seriously wrong with the site. We can use the
126
-            // standard templating system for this.
127
-
128
-            // Firstly, let's undo anything that happened to the database.
129
-            $database->rollBack();
130
-
131
-            // Reset smarty
132
-            $this->setUpSmarty();
133
-
134
-            // Set the template
135
-            $this->setTemplate('exception/optimistic-lock-failure.tpl');
136
-            $this->assign('message', $ex->getMessage());
137
-
138
-            // Force this back to false
139
-            $this->isRedirecting = false;
140
-            $this->headerQueue = array();
141
-        }
142
-        finally {
143
-            // Catch any hanging on transactions
144
-            if ($database->hasActiveTransaction()) {
145
-                $database->rollBack();
146
-            }
147
-        }
148
-
149
-        // run any finalisation code needed before we send the output to the browser.
150
-        $this->finalisePage();
151
-
152
-        // Send the headers
153
-        $this->sendResponseHeaders();
154
-
155
-        // Check we have a template to use!
156
-        if ($this->template !== null) {
157
-            $content = $this->fetchTemplate($this->template);
158
-            ob_clean();
159
-            print($content);
160
-            ob_flush();
161
-
162
-            return;
163
-        }
164
-    }
165
-
166
-    /**
167
-     * Performs final tasks needed before rendering the page.
168
-     */
169
-    protected function finalisePage()
170
-    {
171
-        if ($this->isRedirecting) {
172
-            $this->template = null;
173
-
174
-            return;
175
-        }
176
-
177
-        $this->assign('extraCss', $this->extraCss);
178
-        $this->assign('extraJs', $this->extraJs);
179
-
180
-        // If we're actually displaying content, we want to add the session alerts here!
181
-        $this->assign('alerts', SessionAlert::getAlerts());
182
-        SessionAlert::clearAlerts();
183
-
184
-        $this->assign('htmlTitle', $this->htmlTitle);
185
-    }
186
-
187
-    /**
188
-     * @return TokenManager
189
-     */
190
-    public function getTokenManager()
191
-    {
192
-        return $this->tokenManager;
193
-    }
194
-
195
-    /**
196
-     * @param TokenManager $tokenManager
197
-     */
198
-    public function setTokenManager($tokenManager)
199
-    {
200
-        $this->tokenManager = $tokenManager;
201
-    }
202
-
203
-    /**
204
-     * Sends the redirect headers to perform a GET at the destination page.
205
-     *
206
-     * Also nullifies the set template so Smarty does not render it.
207
-     *
208
-     * @param string      $page   The page to redirect requests to (as used in the UR)
209
-     * @param null|string $action The action to use on the page.
210
-     * @param null|array  $parameters
211
-     * @param null|string $script The script (relative to index.php) to redirect to
212
-     */
213
-    final protected function redirect($page = '', $action = null, $parameters = null, $script = null)
214
-    {
215
-        $currentScriptName = WebRequest::scriptName();
216
-
217
-        // Are we changing script?
218
-        if ($script === null || substr($currentScriptName, -1 * count($script)) === $script) {
219
-            $targetScriptName = $currentScriptName;
220
-        }
221
-        else {
222
-            $targetScriptName = $this->getSiteConfiguration()->getBaseUrl() . '/' . $script;
223
-        }
224
-
225
-        $pathInfo = array($targetScriptName);
226
-
227
-        $pathInfo[1] = $page;
228
-
229
-        if ($action !== null) {
230
-            $pathInfo[2] = $action;
231
-        }
232
-
233
-        $url = implode('/', $pathInfo);
234
-
235
-        if (is_array($parameters) && count($parameters) > 0) {
236
-            $url .= '?' . http_build_query($parameters);
237
-        }
238
-
239
-        $this->redirectUrl($url);
240
-    }
241
-
242
-    /**
243
-     * Sends the redirect headers to perform a GET at the new address.
244
-     *
245
-     * Also nullifies the set template so Smarty does not render it.
246
-     *
247
-     * @param string $path URL to redirect to
248
-     */
249
-    final protected function redirectUrl($path)
250
-    {
251
-        // 303 See Other = re-request at new address with a GET.
252
-        $this->headerQueue[] = 'HTTP/1.1 303 See Other';
253
-        $this->headerQueue[] = "Location: $path";
254
-
255
-        $this->setTemplate(null);
256
-        $this->isRedirecting = true;
257
-    }
258
-
259
-    /**
260
-     * Sets the name of the template this page should display.
261
-     *
262
-     * @param string $name
263
-     *
264
-     * @throws Exception
265
-     */
266
-    final protected function setTemplate($name)
267
-    {
268
-        if ($this->isRedirecting) {
269
-            throw new Exception('This page has been set as a redirect, no template can be displayed!');
270
-        }
271
-
272
-        $this->template = $name;
273
-    }
274
-
275
-    /**
276
-     * Adds an extra CSS file to to the page
277
-     *
278
-     * @param string $path The path (relative to the application root) of the file
279
-     */
280
-    final protected function addCss($path) {
281
-        if(in_array($path, $this->extraCss)){
282
-            // nothing to do
283
-            return;
284
-        }
285
-
286
-        $this->extraCss[] = $path;
287
-    }
288
-
289
-    /**
290
-     * Adds an extra JS file to to the page
291
-     *
292
-     * @param string $path The path (relative to the application root) of the file
293
-     */
294
-    final protected function addJs($path){
295
-        if(in_array($path, $this->extraJs)){
296
-            // nothing to do
297
-            return;
298
-        }
299
-
300
-        $this->extraJs[] = $path;
301
-    }
302
-
303
-    /**
304
-     * Main function for this page, when no specific actions are called.
305
-     * @return void
306
-     */
307
-    abstract protected function main();
308
-
309
-    /**
310
-     * @param string $title
311
-     */
312
-    final protected function setHtmlTitle($title)
313
-    {
314
-        $this->htmlTitle = $title;
315
-    }
316
-
317
-    public function execute()
318
-    {
319
-        if ($this->getRouteName() === null) {
320
-            throw new Exception('Request is unrouted.');
321
-        }
322
-
323
-        if ($this->getSiteConfiguration() === null) {
324
-            throw new Exception('Page has no configuration!');
325
-        }
326
-
327
-        $this->setupPage();
328
-
329
-        $this->runPage();
330
-    }
331
-
332
-    public function assignCSRFToken()
333
-    {
334
-        $token = $this->tokenManager->getNewToken();
335
-        $this->assign('csrfTokenData', $token->getTokenData());
336
-    }
337
-
338
-    public function validateCSRFToken()
339
-    {
340
-        if (!$this->tokenManager->validateToken(WebRequest::postString('csrfTokenData'))) {
341
-            throw new ApplicationLogicException('Form token is not valid, please reload and try again');
342
-        }
343
-    }
344
-
345
-    protected function sendResponseHeaders()
346
-    {
347
-        if (headers_sent()) {
348
-            throw new ApplicationLogicException          ('Headers have already been sent! This is likely a bug in the application.');
349
-        }
350
-
351
-        foreach ($this->headerQueue as $item) {
352
-            if (mb_strpos($item, "\r") !== false || mb_strpos($item, "\n") !== false) {
353
-                // Oops. We're not allowed to do this.
354
-                throw new Exception('Unable to split header');
355
-            }
356
-
357
-            header($item);
358
-        }
359
-    }
23
+	use TemplateOutput;
24
+	/** @var string Smarty template to display */
25
+	protected $template = "base.tpl";
26
+	/** @var string HTML title. Currently unused. */
27
+	protected $htmlTitle;
28
+	/** @var bool Determines if the page is a redirect or not */
29
+	protected $isRedirecting = false;
30
+	/** @var array Queue of headers to be sent on successful completion */
31
+	protected $headerQueue = array();
32
+	/** @var string The name of the route to use, as determined by the request router. */
33
+	private $routeName = null;
34
+	/** @var TokenManager */
35
+	protected $tokenManager;
36
+	/** @var string[] Extra CSS files to include */
37
+	private $extraCss = array();
38
+	/** @var string[] Extra JS files to include */
39
+	private $extraJs = array();
40
+
41
+	/**
42
+	 * Sets the route the request will take. Only should be called from the request router or barrier test.
43
+	 *
44
+	 * @param string $routeName        The name of the route
45
+	 * @param bool   $skipCallableTest Don't use this unless you know what you're doing, and what the implications are.
46
+	 *
47
+	 * @throws Exception
48
+	 * @category Security-Critical
49
+	 */
50
+	final public function setRoute($routeName, $skipCallableTest = false)
51
+	{
52
+		// Test the new route is callable before adopting it.
53
+		if (!$skipCallableTest && !is_callable(array($this, $routeName))) {
54
+			throw new Exception("Proposed route '$routeName' is not callable.");
55
+		}
56
+
57
+		// Adopt the new route
58
+		$this->routeName = $routeName;
59
+	}
60
+
61
+	/**
62
+	 * Gets the name of the route that has been passed from the request router.
63
+	 * @return string
64
+	 */
65
+	final public function getRouteName()
66
+	{
67
+		return $this->routeName;
68
+	}
69
+
70
+	/**
71
+	 * Performs generic page setup actions
72
+	 */
73
+	final protected function setupPage()
74
+	{
75
+		$this->setUpSmarty();
76
+
77
+		$siteNoticeText = SiteNotice::get($this->getDatabase());
78
+
79
+		$this->assign('siteNoticeText', $siteNoticeText);
80
+
81
+		$currentUser = User::getCurrent($this->getDatabase());
82
+		$this->assign('currentUser', $currentUser);
83
+		$this->assign('loggedIn', (!$currentUser->isCommunityUser()));
84
+	}
85
+
86
+	/**
87
+	 * Runs the page logic as routed by the RequestRouter
88
+	 *
89
+	 * Only should be called after a security barrier! That means only from execute().
90
+	 */
91
+	final protected function runPage()
92
+	{
93
+		$database = $this->getDatabase();
94
+
95
+		// initialise a database transaction
96
+		if (!$database->beginTransaction()) {
97
+			throw new Exception('Failed to start transaction on primary database.');
98
+		}
99
+
100
+		try {
101
+			// run the page code
102
+			$this->{$this->getRouteName()}();
103
+
104
+			$database->commit();
105
+		}
106
+		catch (ApplicationLogicException $ex) {
107
+			// it's an application logic exception, so nothing went seriously wrong with the site. We can use the
108
+			// standard templating system for this.
109
+
110
+			// Firstly, let's undo anything that happened to the database.
111
+			$database->rollBack();
112
+
113
+			// Reset smarty
114
+			$this->setUpSmarty();
115
+
116
+			// Set the template
117
+			$this->setTemplate('exception/application-logic.tpl');
118
+			$this->assign('message', $ex->getMessage());
119
+
120
+			// Force this back to false
121
+			$this->isRedirecting = false;
122
+			$this->headerQueue = array();
123
+		}
124
+		catch (OptimisticLockFailedException $ex) {
125
+			// it's an optimistic lock failure exception, so nothing went seriously wrong with the site. We can use the
126
+			// standard templating system for this.
127
+
128
+			// Firstly, let's undo anything that happened to the database.
129
+			$database->rollBack();
130
+
131
+			// Reset smarty
132
+			$this->setUpSmarty();
133
+
134
+			// Set the template
135
+			$this->setTemplate('exception/optimistic-lock-failure.tpl');
136
+			$this->assign('message', $ex->getMessage());
137
+
138
+			// Force this back to false
139
+			$this->isRedirecting = false;
140
+			$this->headerQueue = array();
141
+		}
142
+		finally {
143
+			// Catch any hanging on transactions
144
+			if ($database->hasActiveTransaction()) {
145
+				$database->rollBack();
146
+			}
147
+		}
148
+
149
+		// run any finalisation code needed before we send the output to the browser.
150
+		$this->finalisePage();
151
+
152
+		// Send the headers
153
+		$this->sendResponseHeaders();
154
+
155
+		// Check we have a template to use!
156
+		if ($this->template !== null) {
157
+			$content = $this->fetchTemplate($this->template);
158
+			ob_clean();
159
+			print($content);
160
+			ob_flush();
161
+
162
+			return;
163
+		}
164
+	}
165
+
166
+	/**
167
+	 * Performs final tasks needed before rendering the page.
168
+	 */
169
+	protected function finalisePage()
170
+	{
171
+		if ($this->isRedirecting) {
172
+			$this->template = null;
173
+
174
+			return;
175
+		}
176
+
177
+		$this->assign('extraCss', $this->extraCss);
178
+		$this->assign('extraJs', $this->extraJs);
179
+
180
+		// If we're actually displaying content, we want to add the session alerts here!
181
+		$this->assign('alerts', SessionAlert::getAlerts());
182
+		SessionAlert::clearAlerts();
183
+
184
+		$this->assign('htmlTitle', $this->htmlTitle);
185
+	}
186
+
187
+	/**
188
+	 * @return TokenManager
189
+	 */
190
+	public function getTokenManager()
191
+	{
192
+		return $this->tokenManager;
193
+	}
194
+
195
+	/**
196
+	 * @param TokenManager $tokenManager
197
+	 */
198
+	public function setTokenManager($tokenManager)
199
+	{
200
+		$this->tokenManager = $tokenManager;
201
+	}
202
+
203
+	/**
204
+	 * Sends the redirect headers to perform a GET at the destination page.
205
+	 *
206
+	 * Also nullifies the set template so Smarty does not render it.
207
+	 *
208
+	 * @param string      $page   The page to redirect requests to (as used in the UR)
209
+	 * @param null|string $action The action to use on the page.
210
+	 * @param null|array  $parameters
211
+	 * @param null|string $script The script (relative to index.php) to redirect to
212
+	 */
213
+	final protected function redirect($page = '', $action = null, $parameters = null, $script = null)
214
+	{
215
+		$currentScriptName = WebRequest::scriptName();
216
+
217
+		// Are we changing script?
218
+		if ($script === null || substr($currentScriptName, -1 * count($script)) === $script) {
219
+			$targetScriptName = $currentScriptName;
220
+		}
221
+		else {
222
+			$targetScriptName = $this->getSiteConfiguration()->getBaseUrl() . '/' . $script;
223
+		}
224
+
225
+		$pathInfo = array($targetScriptName);
226
+
227
+		$pathInfo[1] = $page;
228
+
229
+		if ($action !== null) {
230
+			$pathInfo[2] = $action;
231
+		}
232
+
233
+		$url = implode('/', $pathInfo);
234
+
235
+		if (is_array($parameters) && count($parameters) > 0) {
236
+			$url .= '?' . http_build_query($parameters);
237
+		}
238
+
239
+		$this->redirectUrl($url);
240
+	}
241
+
242
+	/**
243
+	 * Sends the redirect headers to perform a GET at the new address.
244
+	 *
245
+	 * Also nullifies the set template so Smarty does not render it.
246
+	 *
247
+	 * @param string $path URL to redirect to
248
+	 */
249
+	final protected function redirectUrl($path)
250
+	{
251
+		// 303 See Other = re-request at new address with a GET.
252
+		$this->headerQueue[] = 'HTTP/1.1 303 See Other';
253
+		$this->headerQueue[] = "Location: $path";
254
+
255
+		$this->setTemplate(null);
256
+		$this->isRedirecting = true;
257
+	}
258
+
259
+	/**
260
+	 * Sets the name of the template this page should display.
261
+	 *
262
+	 * @param string $name
263
+	 *
264
+	 * @throws Exception
265
+	 */
266
+	final protected function setTemplate($name)
267
+	{
268
+		if ($this->isRedirecting) {
269
+			throw new Exception('This page has been set as a redirect, no template can be displayed!');
270
+		}
271
+
272
+		$this->template = $name;
273
+	}
274
+
275
+	/**
276
+	 * Adds an extra CSS file to to the page
277
+	 *
278
+	 * @param string $path The path (relative to the application root) of the file
279
+	 */
280
+	final protected function addCss($path) {
281
+		if(in_array($path, $this->extraCss)){
282
+			// nothing to do
283
+			return;
284
+		}
285
+
286
+		$this->extraCss[] = $path;
287
+	}
288
+
289
+	/**
290
+	 * Adds an extra JS file to to the page
291
+	 *
292
+	 * @param string $path The path (relative to the application root) of the file
293
+	 */
294
+	final protected function addJs($path){
295
+		if(in_array($path, $this->extraJs)){
296
+			// nothing to do
297
+			return;
298
+		}
299
+
300
+		$this->extraJs[] = $path;
301
+	}
302
+
303
+	/**
304
+	 * Main function for this page, when no specific actions are called.
305
+	 * @return void
306
+	 */
307
+	abstract protected function main();
308
+
309
+	/**
310
+	 * @param string $title
311
+	 */
312
+	final protected function setHtmlTitle($title)
313
+	{
314
+		$this->htmlTitle = $title;
315
+	}
316
+
317
+	public function execute()
318
+	{
319
+		if ($this->getRouteName() === null) {
320
+			throw new Exception('Request is unrouted.');
321
+		}
322
+
323
+		if ($this->getSiteConfiguration() === null) {
324
+			throw new Exception('Page has no configuration!');
325
+		}
326
+
327
+		$this->setupPage();
328
+
329
+		$this->runPage();
330
+	}
331
+
332
+	public function assignCSRFToken()
333
+	{
334
+		$token = $this->tokenManager->getNewToken();
335
+		$this->assign('csrfTokenData', $token->getTokenData());
336
+	}
337
+
338
+	public function validateCSRFToken()
339
+	{
340
+		if (!$this->tokenManager->validateToken(WebRequest::postString('csrfTokenData'))) {
341
+			throw new ApplicationLogicException('Form token is not valid, please reload and try again');
342
+		}
343
+	}
344
+
345
+	protected function sendResponseHeaders()
346
+	{
347
+		if (headers_sent()) {
348
+			throw new ApplicationLogicException          ('Headers have already been sent! This is likely a bug in the application.');
349
+		}
350
+
351
+		foreach ($this->headerQueue as $item) {
352
+			if (mb_strpos($item, "\r") !== false || mb_strpos($item, "\n") !== false) {
353
+				// Oops. We're not allowed to do this.
354
+				throw new Exception('Unable to split header');
355
+			}
356
+
357
+			header($item);
358
+		}
359
+	}
360 360
 }
Please login to merge, or discard this patch.
Spacing   +6 added lines, -6 removed lines patch added patch discarded remove patch
@@ -219,7 +219,7 @@  discard block
 block discarded – undo
219 219
             $targetScriptName = $currentScriptName;
220 220
         }
221 221
         else {
222
-            $targetScriptName = $this->getSiteConfiguration()->getBaseUrl() . '/' . $script;
222
+            $targetScriptName = $this->getSiteConfiguration()->getBaseUrl().'/'.$script;
223 223
         }
224 224
 
225 225
         $pathInfo = array($targetScriptName);
@@ -233,7 +233,7 @@  discard block
 block discarded – undo
233 233
         $url = implode('/', $pathInfo);
234 234
 
235 235
         if (is_array($parameters) && count($parameters) > 0) {
236
-            $url .= '?' . http_build_query($parameters);
236
+            $url .= '?'.http_build_query($parameters);
237 237
         }
238 238
 
239 239
         $this->redirectUrl($url);
@@ -278,7 +278,7 @@  discard block
 block discarded – undo
278 278
      * @param string $path The path (relative to the application root) of the file
279 279
      */
280 280
     final protected function addCss($path) {
281
-        if(in_array($path, $this->extraCss)){
281
+        if (in_array($path, $this->extraCss)) {
282 282
             // nothing to do
283 283
             return;
284 284
         }
@@ -291,8 +291,8 @@  discard block
 block discarded – undo
291 291
      *
292 292
      * @param string $path The path (relative to the application root) of the file
293 293
      */
294
-    final protected function addJs($path){
295
-        if(in_array($path, $this->extraJs)){
294
+    final protected function addJs($path) {
295
+        if (in_array($path, $this->extraJs)) {
296 296
             // nothing to do
297 297
             return;
298 298
         }
@@ -345,7 +345,7 @@  discard block
 block discarded – undo
345 345
     protected function sendResponseHeaders()
346 346
     {
347 347
         if (headers_sent()) {
348
-            throw new ApplicationLogicException          ('Headers have already been sent! This is likely a bug in the application.');
348
+            throw new ApplicationLogicException('Headers have already been sent! This is likely a bug in the application.');
349 349
         }
350 350
 
351 351
         foreach ($this->headerQueue as $item) {
Please login to merge, or discard this patch.
Braces   +6 added lines, -4 removed lines patch added patch discarded remove patch
@@ -277,8 +277,9 @@  discard block
 block discarded – undo
277 277
      *
278 278
      * @param string $path The path (relative to the application root) of the file
279 279
      */
280
-    final protected function addCss($path) {
281
-        if(in_array($path, $this->extraCss)){
280
+    final protected function addCss($path)
281
+    {
282
+        if(in_array($path, $this->extraCss)) {
282 283
             // nothing to do
283 284
             return;
284 285
         }
@@ -291,8 +292,9 @@  discard block
 block discarded – undo
291 292
      *
292 293
      * @param string $path The path (relative to the application root) of the file
293 294
      */
294
-    final protected function addJs($path){
295
-        if(in_array($path, $this->extraJs)){
295
+    final protected function addJs($path)
296
+    {
297
+        if(in_array($path, $this->extraJs)) {
296 298
             // nothing to do
297 299
             return;
298 300
         }
Please login to merge, or discard this patch.
includes/IdentificationVerifier.php 3 patches
Indentation   +157 added lines, -157 removed lines patch added patch discarded remove patch
@@ -26,131 +26,131 @@  discard block
 block discarded – undo
26 26
  */
27 27
 class IdentificationVerifier
28 28
 {
29
-    /**
30
-     * This field is an array of parameters, in key => value format, that should be appended to the Meta Wikimedia
31
-     * Web Service Endpoint URL to query if a user is listed on the Identification Noticeboard.  Note that URL encoding
32
-     * of these values is *not* necessary; this is done automatically.
33
-     *
34
-     * @var string[]
35
-     * @category Security-Critical
36
-     */
37
-    private static $apiQueryParameters = array(
38
-        'action'   => 'query',
39
-        'format'   => 'json',
40
-        'prop'     => 'links',
41
-        'titles'   => 'Access to nonpublic information policy/Noticeboard',
42
-        // Username of the user to be checked, with User: prefix, goes here!  Set in isIdentifiedOnWiki()
43
-        'pltitles' => '',
44
-    );
45
-    /** @var HttpHelper */
46
-    private $httpHelper;
47
-    /** @var SiteConfiguration */
48
-    private $siteConfiguration;
49
-    /** @var PdoDatabase */
50
-    private $dbObject;
51
-
52
-    /**
53
-     * IdentificationVerifier constructor.
54
-     *
55
-     * @param HttpHelper        $httpHelper
56
-     * @param SiteConfiguration $siteConfiguration
57
-     * @param PdoDatabase       $dbObject
58
-     */
59
-    public function __construct(HttpHelper $httpHelper, SiteConfiguration $siteConfiguration, PdoDatabase $dbObject)
60
-    {
61
-        $this->httpHelper = $httpHelper;
62
-        $this->siteConfiguration = $siteConfiguration;
63
-        $this->dbObject = $dbObject;
64
-    }
65
-
66
-    /**
67
-     * Checks if the given user is identified to the Wikimedia Foundation.
68
-     *
69
-     * @param string $onWikiName The Wikipedia username of the user
70
-     *
71
-     * @return bool
72
-     * @category Security-Critical
73
-     */
74
-    public function isUserIdentified($onWikiName)
75
-    {
76
-        if ($this->checkIdentificationCache($onWikiName)) {
77
-            return true;
78
-        }
79
-        else {
80
-            if ($this->isIdentifiedOnWiki($onWikiName)) {
81
-                $this->cacheIdentificationStatus($onWikiName);
82
-
83
-                return true;
84
-            }
85
-            else {
86
-                return false;
87
-            }
88
-        }
89
-    }
90
-
91
-    /**
92
-     * Checks if the given user has a valid entry in the idcache table.
93
-     *
94
-     * @param string $onWikiName The Wikipedia username of the user
95
-     *
96
-     * @return bool
97
-     * @category Security-Critical
98
-     */
99
-    private function checkIdentificationCache($onWikiName)
100
-    {
101
-        $interval = $this->siteConfiguration->getIdentificationCacheExpiry();
102
-
103
-        $query = <<<SQL
29
+	/**
30
+	 * This field is an array of parameters, in key => value format, that should be appended to the Meta Wikimedia
31
+	 * Web Service Endpoint URL to query if a user is listed on the Identification Noticeboard.  Note that URL encoding
32
+	 * of these values is *not* necessary; this is done automatically.
33
+	 *
34
+	 * @var string[]
35
+	 * @category Security-Critical
36
+	 */
37
+	private static $apiQueryParameters = array(
38
+		'action'   => 'query',
39
+		'format'   => 'json',
40
+		'prop'     => 'links',
41
+		'titles'   => 'Access to nonpublic information policy/Noticeboard',
42
+		// Username of the user to be checked, with User: prefix, goes here!  Set in isIdentifiedOnWiki()
43
+		'pltitles' => '',
44
+	);
45
+	/** @var HttpHelper */
46
+	private $httpHelper;
47
+	/** @var SiteConfiguration */
48
+	private $siteConfiguration;
49
+	/** @var PdoDatabase */
50
+	private $dbObject;
51
+
52
+	/**
53
+	 * IdentificationVerifier constructor.
54
+	 *
55
+	 * @param HttpHelper        $httpHelper
56
+	 * @param SiteConfiguration $siteConfiguration
57
+	 * @param PdoDatabase       $dbObject
58
+	 */
59
+	public function __construct(HttpHelper $httpHelper, SiteConfiguration $siteConfiguration, PdoDatabase $dbObject)
60
+	{
61
+		$this->httpHelper = $httpHelper;
62
+		$this->siteConfiguration = $siteConfiguration;
63
+		$this->dbObject = $dbObject;
64
+	}
65
+
66
+	/**
67
+	 * Checks if the given user is identified to the Wikimedia Foundation.
68
+	 *
69
+	 * @param string $onWikiName The Wikipedia username of the user
70
+	 *
71
+	 * @return bool
72
+	 * @category Security-Critical
73
+	 */
74
+	public function isUserIdentified($onWikiName)
75
+	{
76
+		if ($this->checkIdentificationCache($onWikiName)) {
77
+			return true;
78
+		}
79
+		else {
80
+			if ($this->isIdentifiedOnWiki($onWikiName)) {
81
+				$this->cacheIdentificationStatus($onWikiName);
82
+
83
+				return true;
84
+			}
85
+			else {
86
+				return false;
87
+			}
88
+		}
89
+	}
90
+
91
+	/**
92
+	 * Checks if the given user has a valid entry in the idcache table.
93
+	 *
94
+	 * @param string $onWikiName The Wikipedia username of the user
95
+	 *
96
+	 * @return bool
97
+	 * @category Security-Critical
98
+	 */
99
+	private function checkIdentificationCache($onWikiName)
100
+	{
101
+		$interval = $this->siteConfiguration->getIdentificationCacheExpiry();
102
+
103
+		$query = <<<SQL
104 104
 			SELECT COUNT(`id`)
105 105
 			FROM `idcache`
106 106
 			WHERE `onwikiusername` = :onwikiname
107 107
 				AND DATE_ADD(`checktime`, INTERVAL {$interval}) >= NOW();
108 108
 SQL;
109
-        $stmt = $this->dbObject->prepare($query);
110
-        $stmt->bindValue(':onwikiname', $onWikiName, PDO::PARAM_STR);
111
-        $stmt->execute();
112
-
113
-        // Guaranteed by the query to only return a single row with a single column
114
-        $results = $stmt->fetch(PDO::FETCH_NUM);
115
-
116
-        // I don't expect this to ever be a value other than 0 or 1 since the `onwikiusername` column is declared as a
117
-        // unique key - but meh.
118
-        return $results[0] != 0;
119
-    }
120
-
121
-    /**
122
-     * Does pretty much exactly what it says on the label - this method will clear all expired idcache entries from the
123
-     * idcache table.  Meant to be called periodically by a maintenance script.
124
-     *
125
-     * @param SiteConfiguration $siteConfiguration
126
-     * @param PdoDatabase       $dbObject
127
-     *
128
-     * @return void
129
-     */
130
-    public static function clearExpiredCacheEntries(SiteConfiguration $siteConfiguration, PdoDatabase $dbObject)
131
-    {
132
-        $interval = $siteConfiguration->getIdentificationCacheExpiry();
133
-
134
-        $query = <<<SQL
109
+		$stmt = $this->dbObject->prepare($query);
110
+		$stmt->bindValue(':onwikiname', $onWikiName, PDO::PARAM_STR);
111
+		$stmt->execute();
112
+
113
+		// Guaranteed by the query to only return a single row with a single column
114
+		$results = $stmt->fetch(PDO::FETCH_NUM);
115
+
116
+		// I don't expect this to ever be a value other than 0 or 1 since the `onwikiusername` column is declared as a
117
+		// unique key - but meh.
118
+		return $results[0] != 0;
119
+	}
120
+
121
+	/**
122
+	 * Does pretty much exactly what it says on the label - this method will clear all expired idcache entries from the
123
+	 * idcache table.  Meant to be called periodically by a maintenance script.
124
+	 *
125
+	 * @param SiteConfiguration $siteConfiguration
126
+	 * @param PdoDatabase       $dbObject
127
+	 *
128
+	 * @return void
129
+	 */
130
+	public static function clearExpiredCacheEntries(SiteConfiguration $siteConfiguration, PdoDatabase $dbObject)
131
+	{
132
+		$interval = $siteConfiguration->getIdentificationCacheExpiry();
133
+
134
+		$query = <<<SQL
135 135
 			DELETE FROM `idcache`
136 136
 			WHERE DATE_ADD(`checktime`, INTERVAL {$interval}) < NOW();
137 137
 SQL;
138
-        $dbObject->prepare($query)->execute();
139
-    }
140
-
141
-    /**
142
-     * This method will add an entry to the idcache that the given Wikipedia user has been verified as identified.  This
143
-     * is so we don't have to hit the API every single time we check.  The cache entry is valid for as long as specified
144
-     * in the ACC configuration (validity enforced by checkIdentificationCache() and clearExpiredCacheEntries()).
145
-     *
146
-     * @param string $onWikiName The Wikipedia username of the user
147
-     *
148
-     * @return void
149
-     * @category Security-Critical
150
-     */
151
-    private function cacheIdentificationStatus($onWikiName)
152
-    {
153
-        $query = <<<SQL
138
+		$dbObject->prepare($query)->execute();
139
+	}
140
+
141
+	/**
142
+	 * This method will add an entry to the idcache that the given Wikipedia user has been verified as identified.  This
143
+	 * is so we don't have to hit the API every single time we check.  The cache entry is valid for as long as specified
144
+	 * in the ACC configuration (validity enforced by checkIdentificationCache() and clearExpiredCacheEntries()).
145
+	 *
146
+	 * @param string $onWikiName The Wikipedia username of the user
147
+	 *
148
+	 * @return void
149
+	 * @category Security-Critical
150
+	 */
151
+	private function cacheIdentificationStatus($onWikiName)
152
+	{
153
+		$query = <<<SQL
154 154
 			INSERT INTO `idcache`
155 155
 				(`onwikiusername`)
156 156
 			VALUES
@@ -159,44 +159,44 @@  discard block
 block discarded – undo
159 159
 				`onwikiusername` = VALUES(`onwikiusername`),
160 160
 				`checktime` = CURRENT_TIMESTAMP;
161 161
 SQL;
162
-        $stmt = $this->dbObject->prepare($query);
163
-        $stmt->bindValue(':onwikiname', $onWikiName, PDO::PARAM_STR);
164
-        $stmt->execute();
165
-    }
166
-
167
-    /**
168
-     * Queries the Wikimedia API to determine if the specified user is listed on the identification noticeboard.
169
-     *
170
-     * @param string $onWikiName The Wikipedia username of the user
171
-     *
172
-     * @return bool
173
-     * @throws EnvironmentException
174
-     * @category Security-Critical
175
-     */
176
-    private function isIdentifiedOnWiki($onWikiName)
177
-    {
178
-        $strings = new StringFunctions();
179
-
180
-        // First character of Wikipedia usernames is always capitalized.
181
-        $onWikiName = $strings->ucfirst($onWikiName);
182
-
183
-        $parameters = self::$apiQueryParameters;
184
-        $parameters['pltitles'] = "User:" . $onWikiName;
185
-
186
-        try {
187
-            $endpoint = $this->siteConfiguration->getMetaWikimediaWebServiceEndpoint();
188
-            $response = $this->httpHelper->get($endpoint, $parameters);
189
-            $response = json_decode($response, true);
190
-        } catch (CurlException $ex) {
191
-            // failed getting identification status, so throw a nicer error.
192
-            $m = 'Could not contact metawiki API to determine user\' identification status. '
193
-                . 'This is probably a transient error, so please try again.';
194
-
195
-            throw new EnvironmentException($m, 0, $ex);
196
-        }
197
-
198
-        $page = @array_pop($response['query']['pages']);
199
-
200
-        return @$page['links'][0]['title'] === "User:" . $onWikiName;
201
-    }
162
+		$stmt = $this->dbObject->prepare($query);
163
+		$stmt->bindValue(':onwikiname', $onWikiName, PDO::PARAM_STR);
164
+		$stmt->execute();
165
+	}
166
+
167
+	/**
168
+	 * Queries the Wikimedia API to determine if the specified user is listed on the identification noticeboard.
169
+	 *
170
+	 * @param string $onWikiName The Wikipedia username of the user
171
+	 *
172
+	 * @return bool
173
+	 * @throws EnvironmentException
174
+	 * @category Security-Critical
175
+	 */
176
+	private function isIdentifiedOnWiki($onWikiName)
177
+	{
178
+		$strings = new StringFunctions();
179
+
180
+		// First character of Wikipedia usernames is always capitalized.
181
+		$onWikiName = $strings->ucfirst($onWikiName);
182
+
183
+		$parameters = self::$apiQueryParameters;
184
+		$parameters['pltitles'] = "User:" . $onWikiName;
185
+
186
+		try {
187
+			$endpoint = $this->siteConfiguration->getMetaWikimediaWebServiceEndpoint();
188
+			$response = $this->httpHelper->get($endpoint, $parameters);
189
+			$response = json_decode($response, true);
190
+		} catch (CurlException $ex) {
191
+			// failed getting identification status, so throw a nicer error.
192
+			$m = 'Could not contact metawiki API to determine user\' identification status. '
193
+				. 'This is probably a transient error, so please try again.';
194
+
195
+			throw new EnvironmentException($m, 0, $ex);
196
+		}
197
+
198
+		$page = @array_pop($response['query']['pages']);
199
+
200
+		return @$page['links'][0]['title'] === "User:" . $onWikiName;
201
+	}
202 202
 }
Please login to merge, or discard this patch.
Braces   +2 added lines, -1 removed lines patch added patch discarded remove patch
@@ -187,7 +187,8 @@
 block discarded – undo
187 187
             $endpoint = $this->siteConfiguration->getMetaWikimediaWebServiceEndpoint();
188 188
             $response = $this->httpHelper->get($endpoint, $parameters);
189 189
             $response = json_decode($response, true);
190
-        } catch (CurlException $ex) {
190
+        }
191
+        catch (CurlException $ex) {
191 192
             // failed getting identification status, so throw a nicer error.
192 193
             $m = 'Could not contact metawiki API to determine user\' identification status. '
193 194
                 . 'This is probably a transient error, so please try again.';
Please login to merge, or discard this patch.
Spacing   +2 added lines, -2 removed lines patch added patch discarded remove patch
@@ -181,7 +181,7 @@  discard block
 block discarded – undo
181 181
         $onWikiName = $strings->ucfirst($onWikiName);
182 182
 
183 183
         $parameters = self::$apiQueryParameters;
184
-        $parameters['pltitles'] = "User:" . $onWikiName;
184
+        $parameters['pltitles'] = "User:".$onWikiName;
185 185
 
186 186
         try {
187 187
             $endpoint = $this->siteConfiguration->getMetaWikimediaWebServiceEndpoint();
@@ -197,6 +197,6 @@  discard block
 block discarded – undo
197 197
 
198 198
         $page = @array_pop($response['query']['pages']);
199 199
 
200
-        return @$page['links'][0]['title'] === "User:" . $onWikiName;
200
+        return @$page['links'][0]['title'] === "User:".$onWikiName;
201 201
     }
202 202
 }
Please login to merge, or discard this patch.
includes/Exceptions/AccessDeniedException.php 3 patches
Unused Use Statements   -2 removed lines patch added patch discarded remove patch
@@ -11,9 +11,7 @@
 block discarded – undo
11 11
 use Waca\DataObjects\Log;
12 12
 use Waca\DataObjects\User;
13 13
 use Waca\Fragments\NavigationMenuAccessControl;
14
-use Waca\Helpers\HttpHelper;
15 14
 use Waca\Helpers\SearchHelpers\LogSearchHelper;
16
-use Waca\IdentificationVerifier;
17 15
 use Waca\PdoDatabase;
18 16
 use Waca\Security\SecurityManager;
19 17
 
Please login to merge, or discard this patch.
Indentation   +85 added lines, -85 removed lines patch added patch discarded remove patch
@@ -26,89 +26,89 @@
 block discarded – undo
26 26
  */
27 27
 class AccessDeniedException extends ReadableException
28 28
 {
29
-    use NavigationMenuAccessControl;
30
-
31
-    /**
32
-     * @var SecurityManager
33
-     */
34
-    private $securityManager;
35
-
36
-    /**
37
-     * AccessDeniedException constructor.
38
-     *
39
-     * @param SecurityManager $securityManager
40
-     */
41
-    public function __construct(SecurityManager $securityManager = null)
42
-    {
43
-        $this->securityManager = $securityManager;
44
-    }
45
-
46
-    public function getReadableError()
47
-    {
48
-        if (!headers_sent()) {
49
-            header("HTTP/1.1 403 Forbidden");
50
-        }
51
-
52
-        $this->setUpSmarty();
53
-
54
-        // uck. We should still be able to access the database in this situation though.
55
-        $database = PdoDatabase::getDatabaseConnection('acc');
56
-        $currentUser = User::getCurrent($database);
57
-        $this->assign('currentUser', $currentUser);
58
-        $this->assign("loggedIn", (!$currentUser->isCommunityUser()));
59
-
60
-        if($this->securityManager !== null) {
61
-            $this->setupNavMenuAccess($currentUser);
62
-        }
63
-
64
-        if ($currentUser->isDeclined()) {
65
-            $this->assign('htmlTitle', 'Account Declined');
66
-            $this->assign('declineReason', $this->getLogEntry('Declined', $currentUser, $database));
67
-
68
-            return $this->fetchTemplate("exception/account-declined.tpl");
69
-        }
70
-
71
-        if ($currentUser->isSuspended()) {
72
-            $this->assign('htmlTitle', 'Account Suspended');
73
-            $this->assign('suspendReason', $this->getLogEntry('Suspended', $currentUser, $database));
74
-
75
-            return $this->fetchTemplate("exception/account-suspended.tpl");
76
-        }
77
-
78
-        if ($currentUser->isNewUser()) {
79
-            $this->assign('htmlTitle', 'Account Pending');
80
-
81
-            return $this->fetchTemplate("exception/account-new.tpl");
82
-        }
83
-
84
-        return $this->fetchTemplate("exception/access-denied.tpl");
85
-    }
86
-
87
-    /**
88
-     * @param string      $action
89
-     * @param User        $user
90
-     * @param PdoDatabase $database
91
-     *
92
-     * @return null|string
93
-     */
94
-    private function getLogEntry($action, User $user, PdoDatabase $database)
95
-    {
96
-        /** @var Log[] $logs */
97
-        $logs = LogSearchHelper::get($database)
98
-            ->byAction($action)
99
-            ->byObjectType('User')
100
-            ->byObjectId($user->getId())
101
-            ->limit(1)
102
-            ->fetch();
103
-
104
-        return $logs[0]->getComment();
105
-    }
106
-
107
-    /**
108
-     * @return SecurityManager
109
-     */
110
-    protected function getSecurityManager()
111
-    {
112
-        return $this->securityManager;
113
-    }
29
+	use NavigationMenuAccessControl;
30
+
31
+	/**
32
+	 * @var SecurityManager
33
+	 */
34
+	private $securityManager;
35
+
36
+	/**
37
+	 * AccessDeniedException constructor.
38
+	 *
39
+	 * @param SecurityManager $securityManager
40
+	 */
41
+	public function __construct(SecurityManager $securityManager = null)
42
+	{
43
+		$this->securityManager = $securityManager;
44
+	}
45
+
46
+	public function getReadableError()
47
+	{
48
+		if (!headers_sent()) {
49
+			header("HTTP/1.1 403 Forbidden");
50
+		}
51
+
52
+		$this->setUpSmarty();
53
+
54
+		// uck. We should still be able to access the database in this situation though.
55
+		$database = PdoDatabase::getDatabaseConnection('acc');
56
+		$currentUser = User::getCurrent($database);
57
+		$this->assign('currentUser', $currentUser);
58
+		$this->assign("loggedIn", (!$currentUser->isCommunityUser()));
59
+
60
+		if($this->securityManager !== null) {
61
+			$this->setupNavMenuAccess($currentUser);
62
+		}
63
+
64
+		if ($currentUser->isDeclined()) {
65
+			$this->assign('htmlTitle', 'Account Declined');
66
+			$this->assign('declineReason', $this->getLogEntry('Declined', $currentUser, $database));
67
+
68
+			return $this->fetchTemplate("exception/account-declined.tpl");
69
+		}
70
+
71
+		if ($currentUser->isSuspended()) {
72
+			$this->assign('htmlTitle', 'Account Suspended');
73
+			$this->assign('suspendReason', $this->getLogEntry('Suspended', $currentUser, $database));
74
+
75
+			return $this->fetchTemplate("exception/account-suspended.tpl");
76
+		}
77
+
78
+		if ($currentUser->isNewUser()) {
79
+			$this->assign('htmlTitle', 'Account Pending');
80
+
81
+			return $this->fetchTemplate("exception/account-new.tpl");
82
+		}
83
+
84
+		return $this->fetchTemplate("exception/access-denied.tpl");
85
+	}
86
+
87
+	/**
88
+	 * @param string      $action
89
+	 * @param User        $user
90
+	 * @param PdoDatabase $database
91
+	 *
92
+	 * @return null|string
93
+	 */
94
+	private function getLogEntry($action, User $user, PdoDatabase $database)
95
+	{
96
+		/** @var Log[] $logs */
97
+		$logs = LogSearchHelper::get($database)
98
+			->byAction($action)
99
+			->byObjectType('User')
100
+			->byObjectId($user->getId())
101
+			->limit(1)
102
+			->fetch();
103
+
104
+		return $logs[0]->getComment();
105
+	}
106
+
107
+	/**
108
+	 * @return SecurityManager
109
+	 */
110
+	protected function getSecurityManager()
111
+	{
112
+		return $this->securityManager;
113
+	}
114 114
 }
115 115
\ No newline at end of file
Please login to merge, or discard this patch.
Spacing   +1 added lines, -1 removed lines patch added patch discarded remove patch
@@ -57,7 +57,7 @@
 block discarded – undo
57 57
         $this->assign('currentUser', $currentUser);
58 58
         $this->assign("loggedIn", (!$currentUser->isCommunityUser()));
59 59
 
60
-        if($this->securityManager !== null) {
60
+        if ($this->securityManager !== null) {
61 61
             $this->setupNavMenuAccess($currentUser);
62 62
         }
63 63
 
Please login to merge, or discard this patch.
includes/Fragments/NavigationMenuAccessControl.php 2 patches
Doc Comments   +5 added lines, -1 removed lines patch added patch discarded remove patch
@@ -24,6 +24,10 @@  discard block
 block discarded – undo
24 24
 
25 25
 trait NavigationMenuAccessControl
26 26
 {
27
+    /**
28
+     * @param string $name
29
+     * @param boolean $value
30
+     */
27 31
     protected abstract function assign($name, $value);
28 32
 
29 33
     /**
@@ -32,7 +36,7 @@  discard block
 block discarded – undo
32 36
     protected abstract function getSecurityManager();
33 37
 
34 38
     /**
35
-     * @param $currentUser
39
+     * @param \Waca\DataObjects\User $currentUser
36 40
      */
37 41
     protected function setupNavMenuAccess($currentUser)
38 42
     {
Please login to merge, or discard this patch.
Indentation   +36 added lines, -36 removed lines patch added patch discarded remove patch
@@ -24,45 +24,45 @@
 block discarded – undo
24 24
 
25 25
 trait NavigationMenuAccessControl
26 26
 {
27
-    protected abstract function assign($name, $value);
27
+	protected abstract function assign($name, $value);
28 28
 
29
-    /**
30
-     * @return SecurityManager
31
-     */
32
-    protected abstract function getSecurityManager();
29
+	/**
30
+	 * @return SecurityManager
31
+	 */
32
+	protected abstract function getSecurityManager();
33 33
 
34
-    /**
35
-     * @param $currentUser
36
-     */
37
-    protected function setupNavMenuAccess($currentUser)
38
-    {
39
-        $this->assign('nav__canRequests', $this->getSecurityManager()
40
-                ->allows(PageMain::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
34
+	/**
35
+	 * @param $currentUser
36
+	 */
37
+	protected function setupNavMenuAccess($currentUser)
38
+	{
39
+		$this->assign('nav__canRequests', $this->getSecurityManager()
40
+				->allows(PageMain::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
41 41
 
42
-        $this->assign('nav__canLogs', $this->getSecurityManager()
43
-                ->allows(PageLog::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
44
-        $this->assign('nav__canUsers', $this->getSecurityManager()
45
-                ->allows(StatsUsers::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
46
-        $this->assign('nav__canSearch', $this->getSecurityManager()
47
-                ->allows(PageSearch::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
48
-        $this->assign('nav__canStats', $this->getSecurityManager()
49
-                ->allows(StatsMain::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
42
+		$this->assign('nav__canLogs', $this->getSecurityManager()
43
+				->allows(PageLog::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
44
+		$this->assign('nav__canUsers', $this->getSecurityManager()
45
+				->allows(StatsUsers::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
46
+		$this->assign('nav__canSearch', $this->getSecurityManager()
47
+				->allows(PageSearch::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
48
+		$this->assign('nav__canStats', $this->getSecurityManager()
49
+				->allows(StatsMain::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
50 50
 
51
-        $this->assign('nav__canBan', $this->getSecurityManager()
52
-                ->allows(PageBan::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
53
-        $this->assign('nav__canEmailMgmt', $this->getSecurityManager()
54
-                ->allows(PageEmailManagement::class, RoleConfiguration::MAIN,
55
-                    $currentUser) === SecurityManager::ALLOWED);
56
-        $this->assign('nav__canWelcomeMgmt', $this->getSecurityManager()
57
-                ->allows(PageWelcomeTemplateManagement::class, RoleConfiguration::MAIN,
58
-                    $currentUser) === SecurityManager::ALLOWED);
59
-        $this->assign('nav__canSiteNoticeMgmt', $this->getSecurityManager()
60
-                ->allows(PageSiteNotice::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
61
-        $this->assign('nav__canUserMgmt', $this->getSecurityManager()
62
-                ->allows(PageUserManagement::class, RoleConfiguration::MAIN,
63
-                    $currentUser) === SecurityManager::ALLOWED);
51
+		$this->assign('nav__canBan', $this->getSecurityManager()
52
+				->allows(PageBan::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
53
+		$this->assign('nav__canEmailMgmt', $this->getSecurityManager()
54
+				->allows(PageEmailManagement::class, RoleConfiguration::MAIN,
55
+					$currentUser) === SecurityManager::ALLOWED);
56
+		$this->assign('nav__canWelcomeMgmt', $this->getSecurityManager()
57
+				->allows(PageWelcomeTemplateManagement::class, RoleConfiguration::MAIN,
58
+					$currentUser) === SecurityManager::ALLOWED);
59
+		$this->assign('nav__canSiteNoticeMgmt', $this->getSecurityManager()
60
+				->allows(PageSiteNotice::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
61
+		$this->assign('nav__canUserMgmt', $this->getSecurityManager()
62
+				->allows(PageUserManagement::class, RoleConfiguration::MAIN,
63
+					$currentUser) === SecurityManager::ALLOWED);
64 64
 
65
-        $this->assign('nav__canViewRequest', $this->getSecurityManager()
66
-                ->allows(PageViewRequest::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
67
-    }
65
+		$this->assign('nav__canViewRequest', $this->getSecurityManager()
66
+				->allows(PageViewRequest::class, RoleConfiguration::MAIN, $currentUser) === SecurityManager::ALLOWED);
67
+	}
68 68
 }
69 69
\ No newline at end of file
Please login to merge, or discard this patch.
includes/Pages/Registration/PageRegisterBase.php 2 patches
Doc Comments   +8 added lines, -5 removed lines patch added patch discarded remove patch
@@ -44,6 +44,9 @@  discard block
 block discarded – undo
44 44
         }
45 45
     }
46 46
 
47
+    /**
48
+     * @return string
49
+     */
47 50
     protected abstract function getRegistrationTemplate();
48 51
 
49 52
     protected function isProtectedPage()
@@ -70,12 +73,12 @@  discard block
 block discarded – undo
70 73
     }
71 74
 
72 75
     /**
73
-     * @param $emailAddress
74
-     * @param $password
75
-     * @param $username
76
+     * @param null|string $emailAddress
77
+     * @param null|string $password
78
+     * @param null|string $username
76 79
      * @param $useOAuthSignup
77
-     * @param $confirmationId
78
-     * @param $onwikiUsername
80
+     * @param null|integer $confirmationId
81
+     * @param null|string $onwikiUsername
79 82
      *
80 83
      * @throws ApplicationLogicException
81 84
      */
Please login to merge, or discard this patch.
Indentation   +198 added lines, -198 removed lines patch added patch discarded remove patch
@@ -18,202 +18,202 @@
 block discarded – undo
18 18
 
19 19
 abstract class PageRegisterBase extends InternalPageBase
20 20
 {
21
-    /**
22
-     * Main function for this page, when no specific actions are called.
23
-     */
24
-    protected function main()
25
-    {
26
-        $useOAuthSignup = $this->getSiteConfiguration()->getUseOAuthSignup();
27
-
28
-        // Dual-mode page
29
-        if (WebRequest::wasPosted()) {
30
-            $this->validateCSRFToken();
31
-
32
-            try {
33
-                $this->handlePost($useOAuthSignup);
34
-            }
35
-            catch (ApplicationLogicException $ex) {
36
-                SessionAlert::error($ex->getMessage());
37
-                $this->redirect('register');
38
-            }
39
-        }
40
-        else {
41
-            $this->assignCSRFToken();
42
-            $this->assign("useOAuthSignup", $useOAuthSignup);
43
-            $this->setTemplate($this->getRegistrationTemplate());
44
-        }
45
-    }
46
-
47
-    protected abstract function getRegistrationTemplate();
48
-
49
-    protected function isProtectedPage()
50
-    {
51
-        return false;
52
-    }
53
-
54
-    /**
55
-     * @param string $emailAddress
56
-     *
57
-     * @throws ApplicationLogicException
58
-     */
59
-    protected function validateUniqueEmail($emailAddress)
60
-    {
61
-        $query = 'SELECT COUNT(id) FROM user WHERE email = :email';
62
-        $statement = $this->getDatabase()->prepare($query);
63
-        $statement->execute(array(':email' => $emailAddress));
64
-
65
-        if ($statement->fetchColumn() > 0) {
66
-            throw new ApplicationLogicException('That email address is already in use on this system.');
67
-        }
68
-
69
-        $statement->closeCursor();
70
-    }
71
-
72
-    /**
73
-     * @param $emailAddress
74
-     * @param $password
75
-     * @param $username
76
-     * @param $useOAuthSignup
77
-     * @param $confirmationId
78
-     * @param $onwikiUsername
79
-     *
80
-     * @throws ApplicationLogicException
81
-     */
82
-    protected function validateRequest(
83
-        $emailAddress,
84
-        $password,
85
-        $username,
86
-        $useOAuthSignup,
87
-        $confirmationId,
88
-        $onwikiUsername
89
-    ) {
90
-        if (!WebRequest::postBoolean('guidelines')) {
91
-            throw new ApplicationLogicException('You must read the interface guidelines before your request may be submitted.');
92
-        }
93
-
94
-        $this->validateGeneralInformation($emailAddress, $password, $username);
95
-        $this->validateUniqueEmail($emailAddress);
96
-        $this->validateNonOAuthFields($useOAuthSignup, $confirmationId, $onwikiUsername);
97
-    }
98
-
99
-    /**
100
-     * @param $useOAuthSignup
101
-     * @param $confirmationId
102
-     * @param $onwikiUsername
103
-     *
104
-     * @throws ApplicationLogicException
105
-     */
106
-    protected function validateNonOAuthFields($useOAuthSignup, $confirmationId, $onwikiUsername)
107
-    {
108
-        if (!$useOAuthSignup) {
109
-            if ($confirmationId === null || $confirmationId <= 0) {
110
-                throw new ApplicationLogicException('Please enter the revision id of your confirmation edit.');
111
-            }
112
-
113
-            if ($onwikiUsername === null) {
114
-                throw new ApplicationLogicException('Please specify your on-wiki username.');
115
-            }
116
-        }
117
-    }
118
-
119
-    /**
120
-     * @param $emailAddress
121
-     * @param $password
122
-     * @param $username
123
-     *
124
-     * @throws ApplicationLogicException
125
-     */
126
-    protected function validateGeneralInformation($emailAddress, $password, $username)
127
-    {
128
-        if ($emailAddress === null) {
129
-            throw new ApplicationLogicException('Your email address appears to be invalid!');
130
-        }
131
-
132
-        if ($password !== WebRequest::postString('pass2')) {
133
-            throw new ApplicationLogicException('Your passwords did not match, please try again.');
134
-        }
135
-
136
-        if (User::getByUsername($username, $this->getDatabase()) !== false) {
137
-            throw new ApplicationLogicException('That username is already in use on this system.');
138
-        }
139
-    }
140
-
141
-    /**
142
-     * @param $useOAuthSignup
143
-     *
144
-     * @throws ApplicationLogicException
145
-     * @throws \Exception
146
-     */
147
-    protected function handlePost($useOAuthSignup)
148
-    {
149
-        // Get the data
150
-        $emailAddress = WebRequest::postEmail('email');
151
-        $password = WebRequest::postString('pass');
152
-        $username = WebRequest::postString('name');
153
-
154
-        // Only set if OAuth is disabled
155
-        $confirmationId = WebRequest::postInt('conf_revid');
156
-        $onwikiUsername = WebRequest::postString('wname');
157
-
158
-        // Do some validation
159
-        $this->validateRequest($emailAddress, $password, $username, $useOAuthSignup, $confirmationId,
160
-            $onwikiUsername);
161
-
162
-        $database = $this->getDatabase();
163
-
164
-        $user = new User();
165
-        $user->setDatabase($database);
166
-
167
-        $user->setUsername($username);
168
-        $user->setPassword($password);
169
-        $user->setEmail($emailAddress);
170
-
171
-        if (!$useOAuthSignup) {
172
-            $user->setOnWikiName($onwikiUsername);
173
-            $user->setConfirmationDiff($confirmationId);
174
-        }
175
-
176
-        $user->save();
177
-
178
-        $defaultRole = $this->getDefaultRole();
179
-
180
-        $role = new UserRole();
181
-        $role->setDatabase($database);
182
-        $role->setUser($user->getId());
183
-        $role->setRole($defaultRole);
184
-        $role->save();
185
-
186
-        // Log now to get the signup date.
187
-        Logger::newUser($database, $user);
188
-        Logger::userRolesEdited($database, $user, 'Registration', array($defaultRole), array());
189
-
190
-        if ($useOAuthSignup) {
191
-            $oauthHelper = $this->getOAuthHelper();
192
-
193
-            $requestToken = $oauthHelper->getRequestToken();
194
-            $user->setOAuthRequestToken($requestToken->key);
195
-            $user->setOAuthRequestSecret($requestToken->secret);
196
-            $user->save();
197
-
198
-            WebRequest::setPartialLogin($user);
199
-
200
-            $this->redirectUrl($oauthHelper->getAuthoriseUrl($requestToken->key));
201
-        }
202
-        else {
203
-            // only notify if we're not using the oauth signup.
204
-            $this->getNotificationHelper()->userNew($user);
205
-            WebRequest::setLoggedInUser($user);
206
-            $this->redirect('preferences');
207
-        }
208
-    }
209
-
210
-    protected abstract function getDefaultRole();
211
-
212
-    /**
213
-     * Entry point for registration complete
214
-     */
215
-    protected function done()
216
-    {
217
-        $this->setTemplate('registration/alert-registrationcomplete.tpl');
218
-    }
21
+	/**
22
+	 * Main function for this page, when no specific actions are called.
23
+	 */
24
+	protected function main()
25
+	{
26
+		$useOAuthSignup = $this->getSiteConfiguration()->getUseOAuthSignup();
27
+
28
+		// Dual-mode page
29
+		if (WebRequest::wasPosted()) {
30
+			$this->validateCSRFToken();
31
+
32
+			try {
33
+				$this->handlePost($useOAuthSignup);
34
+			}
35
+			catch (ApplicationLogicException $ex) {
36
+				SessionAlert::error($ex->getMessage());
37
+				$this->redirect('register');
38
+			}
39
+		}
40
+		else {
41
+			$this->assignCSRFToken();
42
+			$this->assign("useOAuthSignup", $useOAuthSignup);
43
+			$this->setTemplate($this->getRegistrationTemplate());
44
+		}
45
+	}
46
+
47
+	protected abstract function getRegistrationTemplate();
48
+
49
+	protected function isProtectedPage()
50
+	{
51
+		return false;
52
+	}
53
+
54
+	/**
55
+	 * @param string $emailAddress
56
+	 *
57
+	 * @throws ApplicationLogicException
58
+	 */
59
+	protected function validateUniqueEmail($emailAddress)
60
+	{
61
+		$query = 'SELECT COUNT(id) FROM user WHERE email = :email';
62
+		$statement = $this->getDatabase()->prepare($query);
63
+		$statement->execute(array(':email' => $emailAddress));
64
+
65
+		if ($statement->fetchColumn() > 0) {
66
+			throw new ApplicationLogicException('That email address is already in use on this system.');
67
+		}
68
+
69
+		$statement->closeCursor();
70
+	}
71
+
72
+	/**
73
+	 * @param $emailAddress
74
+	 * @param $password
75
+	 * @param $username
76
+	 * @param $useOAuthSignup
77
+	 * @param $confirmationId
78
+	 * @param $onwikiUsername
79
+	 *
80
+	 * @throws ApplicationLogicException
81
+	 */
82
+	protected function validateRequest(
83
+		$emailAddress,
84
+		$password,
85
+		$username,
86
+		$useOAuthSignup,
87
+		$confirmationId,
88
+		$onwikiUsername
89
+	) {
90
+		if (!WebRequest::postBoolean('guidelines')) {
91
+			throw new ApplicationLogicException('You must read the interface guidelines before your request may be submitted.');
92
+		}
93
+
94
+		$this->validateGeneralInformation($emailAddress, $password, $username);
95
+		$this->validateUniqueEmail($emailAddress);
96
+		$this->validateNonOAuthFields($useOAuthSignup, $confirmationId, $onwikiUsername);
97
+	}
98
+
99
+	/**
100
+	 * @param $useOAuthSignup
101
+	 * @param $confirmationId
102
+	 * @param $onwikiUsername
103
+	 *
104
+	 * @throws ApplicationLogicException
105
+	 */
106
+	protected function validateNonOAuthFields($useOAuthSignup, $confirmationId, $onwikiUsername)
107
+	{
108
+		if (!$useOAuthSignup) {
109
+			if ($confirmationId === null || $confirmationId <= 0) {
110
+				throw new ApplicationLogicException('Please enter the revision id of your confirmation edit.');
111
+			}
112
+
113
+			if ($onwikiUsername === null) {
114
+				throw new ApplicationLogicException('Please specify your on-wiki username.');
115
+			}
116
+		}
117
+	}
118
+
119
+	/**
120
+	 * @param $emailAddress
121
+	 * @param $password
122
+	 * @param $username
123
+	 *
124
+	 * @throws ApplicationLogicException
125
+	 */
126
+	protected function validateGeneralInformation($emailAddress, $password, $username)
127
+	{
128
+		if ($emailAddress === null) {
129
+			throw new ApplicationLogicException('Your email address appears to be invalid!');
130
+		}
131
+
132
+		if ($password !== WebRequest::postString('pass2')) {
133
+			throw new ApplicationLogicException('Your passwords did not match, please try again.');
134
+		}
135
+
136
+		if (User::getByUsername($username, $this->getDatabase()) !== false) {
137
+			throw new ApplicationLogicException('That username is already in use on this system.');
138
+		}
139
+	}
140
+
141
+	/**
142
+	 * @param $useOAuthSignup
143
+	 *
144
+	 * @throws ApplicationLogicException
145
+	 * @throws \Exception
146
+	 */
147
+	protected function handlePost($useOAuthSignup)
148
+	{
149
+		// Get the data
150
+		$emailAddress = WebRequest::postEmail('email');
151
+		$password = WebRequest::postString('pass');
152
+		$username = WebRequest::postString('name');
153
+
154
+		// Only set if OAuth is disabled
155
+		$confirmationId = WebRequest::postInt('conf_revid');
156
+		$onwikiUsername = WebRequest::postString('wname');
157
+
158
+		// Do some validation
159
+		$this->validateRequest($emailAddress, $password, $username, $useOAuthSignup, $confirmationId,
160
+			$onwikiUsername);
161
+
162
+		$database = $this->getDatabase();
163
+
164
+		$user = new User();
165
+		$user->setDatabase($database);
166
+
167
+		$user->setUsername($username);
168
+		$user->setPassword($password);
169
+		$user->setEmail($emailAddress);
170
+
171
+		if (!$useOAuthSignup) {
172
+			$user->setOnWikiName($onwikiUsername);
173
+			$user->setConfirmationDiff($confirmationId);
174
+		}
175
+
176
+		$user->save();
177
+
178
+		$defaultRole = $this->getDefaultRole();
179
+
180
+		$role = new UserRole();
181
+		$role->setDatabase($database);
182
+		$role->setUser($user->getId());
183
+		$role->setRole($defaultRole);
184
+		$role->save();
185
+
186
+		// Log now to get the signup date.
187
+		Logger::newUser($database, $user);
188
+		Logger::userRolesEdited($database, $user, 'Registration', array($defaultRole), array());
189
+
190
+		if ($useOAuthSignup) {
191
+			$oauthHelper = $this->getOAuthHelper();
192
+
193
+			$requestToken = $oauthHelper->getRequestToken();
194
+			$user->setOAuthRequestToken($requestToken->key);
195
+			$user->setOAuthRequestSecret($requestToken->secret);
196
+			$user->save();
197
+
198
+			WebRequest::setPartialLogin($user);
199
+
200
+			$this->redirectUrl($oauthHelper->getAuthoriseUrl($requestToken->key));
201
+		}
202
+		else {
203
+			// only notify if we're not using the oauth signup.
204
+			$this->getNotificationHelper()->userNew($user);
205
+			WebRequest::setLoggedInUser($user);
206
+			$this->redirect('preferences');
207
+		}
208
+	}
209
+
210
+	protected abstract function getDefaultRole();
211
+
212
+	/**
213
+	 * Entry point for registration complete
214
+	 */
215
+	protected function done()
216
+	{
217
+		$this->setTemplate('registration/alert-registrationcomplete.tpl');
218
+	}
219 219
 }
Please login to merge, or discard this patch.
includes/Security/SecurityManager.php 3 patches
Indentation   +196 added lines, -196 removed lines patch added patch discarded remove patch
@@ -14,200 +14,200 @@
 block discarded – undo
14 14
 
15 15
 final class SecurityManager
16 16
 {
17
-    const ALLOWED = 1;
18
-    const ERROR_NOT_IDENTIFIED = 2;
19
-    const ERROR_DENIED = 3;
20
-    /** @var IdentificationVerifier */
21
-    private $identificationVerifier;
22
-    /**
23
-     * @var RoleConfiguration
24
-     */
25
-    private $roleConfiguration;
26
-
27
-    /**
28
-     * SecurityManager constructor.
29
-     *
30
-     * @param IdentificationVerifier $identificationVerifier
31
-     * @param RoleConfiguration      $roleConfiguration
32
-     */
33
-    public function __construct(
34
-        IdentificationVerifier $identificationVerifier,
35
-        RoleConfiguration $roleConfiguration
36
-    ) {
37
-        $this->identificationVerifier = $identificationVerifier;
38
-        $this->roleConfiguration = $roleConfiguration;
39
-    }
40
-
41
-    /**
42
-     * Tests if a user is allowed to perform an action.
43
-     *
44
-     * This method should form a hard, deterministic security barrier, and only return true if it is absolutely sure
45
-     * that a user should have access to something.
46
-     *
47
-     * @param string $page
48
-     * @param string $route
49
-     * @param User   $user
50
-     *
51
-     * @return int
52
-     *
53
-     * @category Security-Critical
54
-     */
55
-    public function allows($page, $route, User $user)
56
-    {
57
-        $this->getActiveRoles($user, $activeRoles, $inactiveRoles);
58
-
59
-        $availableRights = $this->flattenRoles($activeRoles);
60
-        $testResult = $this->findResult($availableRights, $page, $route);
61
-
62
-        if ($testResult !== null) {
63
-            // We got a firm result here, so just return it.
64
-            return $testResult;
65
-        }
66
-
67
-        // No firm result yet, so continue testing the inactive roles so we can give a better error.
68
-        $inactiveRights = $this->flattenRoles($inactiveRoles);
69
-        $testResult = $this->findResult($inactiveRights, $page, $route);
70
-
71
-        if ($testResult === self::ALLOWED) {
72
-            // The user is allowed to access this, but their role is inactive.
73
-            return self::ERROR_NOT_IDENTIFIED;
74
-        }
75
-
76
-        // Other options from the secondary test are denied and inconclusive, which at this point defaults to denied.
77
-        return self::ERROR_DENIED;
78
-    }
79
-
80
-    /**
81
-     * @param array  $pseudoRole The role (flattened) to check
82
-     * @param string $page       The page class to check
83
-     * @param string $route      The page route to check
84
-     *
85
-     * @return int|null
86
-     */
87
-    private function findResult($pseudoRole, $page, $route)
88
-    {
89
-        if (isset($pseudoRole[$page])) {
90
-            // check for deny on catch-all route
91
-            if (isset($pseudoRole[$page][RoleConfiguration::ALL])) {
92
-                if ($pseudoRole[$page][RoleConfiguration::ALL] === RoleConfiguration::ACCESS_DENY) {
93
-                    return self::ERROR_DENIED;
94
-                }
95
-            }
96
-
97
-            // check normal route
98
-            if (isset($pseudoRole[$page][$route])) {
99
-                if ($pseudoRole[$page][$route] === RoleConfiguration::ACCESS_DENY) {
100
-                    return self::ERROR_DENIED;
101
-                }
102
-
103
-                if ($pseudoRole[$page][$route] === RoleConfiguration::ACCESS_ALLOW) {
104
-                    return self::ALLOWED;
105
-                }
106
-            }
107
-
108
-            // check for allowed on catch-all route
109
-            if (isset($pseudoRole[$page][RoleConfiguration::ALL])) {
110
-                if ($pseudoRole[$page][RoleConfiguration::ALL] === RoleConfiguration::ACCESS_ALLOW) {
111
-                    return self::ALLOWED;
112
-                }
113
-            }
114
-        }
115
-
116
-        // return indeterminate result
117
-        return null;
118
-    }
119
-
120
-    /**
121
-     * Takes an array of roles and flattens the values to a single set.
122
-     *
123
-     * @param array $activeRoles
124
-     *
125
-     * @return array
126
-     */
127
-    private function flattenRoles($activeRoles)
128
-    {
129
-        $result = array();
130
-
131
-        $roleConfig = $this->roleConfiguration->getApplicableRoles($activeRoles);
132
-
133
-        // Iterate over every page in every role
134
-        foreach ($roleConfig as $role) {
135
-            foreach ($role as $page => $pageRights) {
136
-                // Create holder in result for this page
137
-                if (!isset($result[$page])) {
138
-                    $result[$page] = array();
139
-                }
140
-
141
-                foreach ($pageRights as $action => $permission) {
142
-                    // Deny takes precedence, so if it's set, don't change it.
143
-                    if (isset($result[$page][$action])) {
144
-                        if ($result[$page][$action] === RoleConfiguration::ACCESS_DENY) {
145
-                            continue;
146
-                        }
147
-                    }
148
-
149
-                    if ($permission === RoleConfiguration::ACCESS_DEFAULT) {
150
-                        // Configured to do precisely nothing.
151
-                        continue;
152
-                    }
153
-
154
-                    $result[$page][$action] = $permission;
155
-                }
156
-            }
157
-        }
158
-
159
-        return $result;
160
-    }
161
-
162
-    /**
163
-     * @param User  $user
164
-     * @param array $activeRoles
165
-     * @param array $inactiveRoles
166
-     */
167
-    public function getActiveRoles(User $user, &$activeRoles, &$inactiveRoles)
168
-    {
169
-        // Default to the community user here, because the main user is logged out
170
-        $identified = false;
171
-        $userRoles = array('public');
172
-
173
-        // if we're not the community user, get our real rights.
174
-        if (!$user->isCommunityUser()) {
175
-            // Check the user's status - only active users are allowed the effects of roles
176
-
177
-            $userRoles[] = 'loggedIn';
178
-
179
-            if ($user->isActive()) {
180
-                $ur = UserRole::getForUser($user->getId(), $user->getDatabase());
181
-
182
-                // NOTE: public is still in this array.
183
-                foreach ($ur as $r) {
184
-                    $userRoles[] = $r->getRole();
185
-                }
186
-
187
-                $identified = $user->isIdentified($this->identificationVerifier);
188
-            }
189
-        }
190
-
191
-        $activeRoles = array();
192
-        $inactiveRoles = array();
193
-
194
-        /** @var string $v */
195
-        foreach ($userRoles as $v) {
196
-            if ($this->roleConfiguration->roleNeedsIdentification($v)) {
197
-                if ($identified) {
198
-                    $activeRoles[] = $v;
199
-                }
200
-                else {
201
-                    $inactiveRoles[] = $v;
202
-                }
203
-            }
204
-            else {
205
-                $activeRoles[] = $v;
206
-            }
207
-        }
208
-    }
209
-
210
-    public function getRoleConfiguration(){
211
-        return $this->roleConfiguration;
212
-    }
17
+	const ALLOWED = 1;
18
+	const ERROR_NOT_IDENTIFIED = 2;
19
+	const ERROR_DENIED = 3;
20
+	/** @var IdentificationVerifier */
21
+	private $identificationVerifier;
22
+	/**
23
+	 * @var RoleConfiguration
24
+	 */
25
+	private $roleConfiguration;
26
+
27
+	/**
28
+	 * SecurityManager constructor.
29
+	 *
30
+	 * @param IdentificationVerifier $identificationVerifier
31
+	 * @param RoleConfiguration      $roleConfiguration
32
+	 */
33
+	public function __construct(
34
+		IdentificationVerifier $identificationVerifier,
35
+		RoleConfiguration $roleConfiguration
36
+	) {
37
+		$this->identificationVerifier = $identificationVerifier;
38
+		$this->roleConfiguration = $roleConfiguration;
39
+	}
40
+
41
+	/**
42
+	 * Tests if a user is allowed to perform an action.
43
+	 *
44
+	 * This method should form a hard, deterministic security barrier, and only return true if it is absolutely sure
45
+	 * that a user should have access to something.
46
+	 *
47
+	 * @param string $page
48
+	 * @param string $route
49
+	 * @param User   $user
50
+	 *
51
+	 * @return int
52
+	 *
53
+	 * @category Security-Critical
54
+	 */
55
+	public function allows($page, $route, User $user)
56
+	{
57
+		$this->getActiveRoles($user, $activeRoles, $inactiveRoles);
58
+
59
+		$availableRights = $this->flattenRoles($activeRoles);
60
+		$testResult = $this->findResult($availableRights, $page, $route);
61
+
62
+		if ($testResult !== null) {
63
+			// We got a firm result here, so just return it.
64
+			return $testResult;
65
+		}
66
+
67
+		// No firm result yet, so continue testing the inactive roles so we can give a better error.
68
+		$inactiveRights = $this->flattenRoles($inactiveRoles);
69
+		$testResult = $this->findResult($inactiveRights, $page, $route);
70
+
71
+		if ($testResult === self::ALLOWED) {
72
+			// The user is allowed to access this, but their role is inactive.
73
+			return self::ERROR_NOT_IDENTIFIED;
74
+		}
75
+
76
+		// Other options from the secondary test are denied and inconclusive, which at this point defaults to denied.
77
+		return self::ERROR_DENIED;
78
+	}
79
+
80
+	/**
81
+	 * @param array  $pseudoRole The role (flattened) to check
82
+	 * @param string $page       The page class to check
83
+	 * @param string $route      The page route to check
84
+	 *
85
+	 * @return int|null
86
+	 */
87
+	private function findResult($pseudoRole, $page, $route)
88
+	{
89
+		if (isset($pseudoRole[$page])) {
90
+			// check for deny on catch-all route
91
+			if (isset($pseudoRole[$page][RoleConfiguration::ALL])) {
92
+				if ($pseudoRole[$page][RoleConfiguration::ALL] === RoleConfiguration::ACCESS_DENY) {
93
+					return self::ERROR_DENIED;
94
+				}
95
+			}
96
+
97
+			// check normal route
98
+			if (isset($pseudoRole[$page][$route])) {
99
+				if ($pseudoRole[$page][$route] === RoleConfiguration::ACCESS_DENY) {
100
+					return self::ERROR_DENIED;
101
+				}
102
+
103
+				if ($pseudoRole[$page][$route] === RoleConfiguration::ACCESS_ALLOW) {
104
+					return self::ALLOWED;
105
+				}
106
+			}
107
+
108
+			// check for allowed on catch-all route
109
+			if (isset($pseudoRole[$page][RoleConfiguration::ALL])) {
110
+				if ($pseudoRole[$page][RoleConfiguration::ALL] === RoleConfiguration::ACCESS_ALLOW) {
111
+					return self::ALLOWED;
112
+				}
113
+			}
114
+		}
115
+
116
+		// return indeterminate result
117
+		return null;
118
+	}
119
+
120
+	/**
121
+	 * Takes an array of roles and flattens the values to a single set.
122
+	 *
123
+	 * @param array $activeRoles
124
+	 *
125
+	 * @return array
126
+	 */
127
+	private function flattenRoles($activeRoles)
128
+	{
129
+		$result = array();
130
+
131
+		$roleConfig = $this->roleConfiguration->getApplicableRoles($activeRoles);
132
+
133
+		// Iterate over every page in every role
134
+		foreach ($roleConfig as $role) {
135
+			foreach ($role as $page => $pageRights) {
136
+				// Create holder in result for this page
137
+				if (!isset($result[$page])) {
138
+					$result[$page] = array();
139
+				}
140
+
141
+				foreach ($pageRights as $action => $permission) {
142
+					// Deny takes precedence, so if it's set, don't change it.
143
+					if (isset($result[$page][$action])) {
144
+						if ($result[$page][$action] === RoleConfiguration::ACCESS_DENY) {
145
+							continue;
146
+						}
147
+					}
148
+
149
+					if ($permission === RoleConfiguration::ACCESS_DEFAULT) {
150
+						// Configured to do precisely nothing.
151
+						continue;
152
+					}
153
+
154
+					$result[$page][$action] = $permission;
155
+				}
156
+			}
157
+		}
158
+
159
+		return $result;
160
+	}
161
+
162
+	/**
163
+	 * @param User  $user
164
+	 * @param array $activeRoles
165
+	 * @param array $inactiveRoles
166
+	 */
167
+	public function getActiveRoles(User $user, &$activeRoles, &$inactiveRoles)
168
+	{
169
+		// Default to the community user here, because the main user is logged out
170
+		$identified = false;
171
+		$userRoles = array('public');
172
+
173
+		// if we're not the community user, get our real rights.
174
+		if (!$user->isCommunityUser()) {
175
+			// Check the user's status - only active users are allowed the effects of roles
176
+
177
+			$userRoles[] = 'loggedIn';
178
+
179
+			if ($user->isActive()) {
180
+				$ur = UserRole::getForUser($user->getId(), $user->getDatabase());
181
+
182
+				// NOTE: public is still in this array.
183
+				foreach ($ur as $r) {
184
+					$userRoles[] = $r->getRole();
185
+				}
186
+
187
+				$identified = $user->isIdentified($this->identificationVerifier);
188
+			}
189
+		}
190
+
191
+		$activeRoles = array();
192
+		$inactiveRoles = array();
193
+
194
+		/** @var string $v */
195
+		foreach ($userRoles as $v) {
196
+			if ($this->roleConfiguration->roleNeedsIdentification($v)) {
197
+				if ($identified) {
198
+					$activeRoles[] = $v;
199
+				}
200
+				else {
201
+					$inactiveRoles[] = $v;
202
+				}
203
+			}
204
+			else {
205
+				$activeRoles[] = $v;
206
+			}
207
+		}
208
+	}
209
+
210
+	public function getRoleConfiguration(){
211
+		return $this->roleConfiguration;
212
+	}
213 213
 }
Please login to merge, or discard this patch.
Spacing   +1 added lines, -1 removed lines patch added patch discarded remove patch
@@ -207,7 +207,7 @@
 block discarded – undo
207 207
         }
208 208
     }
209 209
 
210
-    public function getRoleConfiguration(){
210
+    public function getRoleConfiguration() {
211 211
         return $this->roleConfiguration;
212 212
     }
213 213
 }
Please login to merge, or discard this patch.
Braces   +2 added lines, -1 removed lines patch added patch discarded remove patch
@@ -207,7 +207,8 @@
 block discarded – undo
207 207
         }
208 208
     }
209 209
 
210
-    public function getRoleConfiguration(){
210
+    public function getRoleConfiguration()
211
+    {
211 212
         return $this->roleConfiguration;
212 213
     }
213 214
 }
Please login to merge, or discard this patch.
includes/Security/RoleConfiguration.php 1 patch
Indentation   +307 added lines, -307 removed lines patch added patch discarded remove patch
@@ -41,338 +41,338 @@
 block discarded – undo
41 41
 
42 42
 class RoleConfiguration
43 43
 {
44
-    const ACCESS_ALLOW = 1;
45
-    const ACCESS_DENY = -1;
46
-    const ACCESS_DEFAULT = 0;
47
-    const MAIN = 'main';
48
-    const ALL = '*';
49
-    /**
50
-     * A map of roles to rights
51
-     *
52
-     * For example:
53
-     *
54
-     * array(
55
-     *   'myrole' => array(
56
-     *       PageMyPage::class => array(
57
-     *           'edit' => self::ACCESS_ALLOW,
58
-     *           'create' => self::ACCESS_DENY,
59
-     *       )
60
-     *   )
61
-     * )
62
-     *
63
-     * Note that DENY takes precedence over everything else when roles are combined, followed by ALLOW, followed by
64
-     * DEFAULT. Thus, if you have the following ([A]llow, [D]eny, [-] (default)) grants in different roles, this should
65
-     * be the expected result:
66
-     *
67
-     * - (-,-,-) = - (default because nothing to explicitly say allowed or denied equates to a denial)
68
-     * - (A,-,-) = A
69
-     * - (D,-,-) = D
70
-     * - (A,D,-) = D (deny takes precedence over allow)
71
-     * - (A,A,A) = A (repetition has no effect)
72
-     *
73
-     * The public role is special, and is applied to all users automatically. Avoid using deny on this role.
74
-     *
75
-     * @var array
76
-     */
77
-    private $roleConfig = array(
78
-        'public'            => array(
79
-            /*
44
+	const ACCESS_ALLOW = 1;
45
+	const ACCESS_DENY = -1;
46
+	const ACCESS_DEFAULT = 0;
47
+	const MAIN = 'main';
48
+	const ALL = '*';
49
+	/**
50
+	 * A map of roles to rights
51
+	 *
52
+	 * For example:
53
+	 *
54
+	 * array(
55
+	 *   'myrole' => array(
56
+	 *       PageMyPage::class => array(
57
+	 *           'edit' => self::ACCESS_ALLOW,
58
+	 *           'create' => self::ACCESS_DENY,
59
+	 *       )
60
+	 *   )
61
+	 * )
62
+	 *
63
+	 * Note that DENY takes precedence over everything else when roles are combined, followed by ALLOW, followed by
64
+	 * DEFAULT. Thus, if you have the following ([A]llow, [D]eny, [-] (default)) grants in different roles, this should
65
+	 * be the expected result:
66
+	 *
67
+	 * - (-,-,-) = - (default because nothing to explicitly say allowed or denied equates to a denial)
68
+	 * - (A,-,-) = A
69
+	 * - (D,-,-) = D
70
+	 * - (A,D,-) = D (deny takes precedence over allow)
71
+	 * - (A,A,A) = A (repetition has no effect)
72
+	 *
73
+	 * The public role is special, and is applied to all users automatically. Avoid using deny on this role.
74
+	 *
75
+	 * @var array
76
+	 */
77
+	private $roleConfig = array(
78
+		'public'            => array(
79
+			/*
80 80
              * THIS ROLE IS GRANTED TO ALL LOGGED *OUT* USERS IMPLICITLY.
81 81
              *
82 82
              * USERS IN THIS ROLE DO NOT HAVE TO BE IDENTIFIED TO GET THE RIGHTS CONFERRED HERE.
83 83
              * DO NOT ADD ANY SECURITY-SENSITIVE RIGHTS HERE.
84 84
              */
85
-            '_childRoles'    => array(
86
-                'publicStats',
87
-            ),
88
-            PageOAuth::class => array(
89
-                'callback' => self::ACCESS_ALLOW,
90
-            ),
91
-            PageTeam::class  => array(
92
-                self::MAIN => self::ACCESS_ALLOW,
93
-            ),
94
-        ),
95
-        'loggedIn'            => array(
96
-            /*
85
+			'_childRoles'    => array(
86
+				'publicStats',
87
+			),
88
+			PageOAuth::class => array(
89
+				'callback' => self::ACCESS_ALLOW,
90
+			),
91
+			PageTeam::class  => array(
92
+				self::MAIN => self::ACCESS_ALLOW,
93
+			),
94
+		),
95
+		'loggedIn'            => array(
96
+			/*
97 97
              * THIS ROLE IS GRANTED TO ALL LOGGED IN USERS IMPLICITLY.
98 98
              *
99 99
              * USERS IN THIS ROLE DO NOT HAVE TO BE IDENTIFIED TO GET THE RIGHTS CONFERRED HERE.
100 100
              * DO NOT ADD ANY SECURITY-SENSITIVE RIGHTS HERE.
101 101
              */
102
-            '_childRoles'    => array(
103
-                'public',
104
-            ),
105
-            PagePreferences::class               => array(
106
-                self::MAIN       => self::ACCESS_ALLOW,
107
-                'changePassword' => self::ACCESS_ALLOW,
108
-            ),
109
-            PageOAuth::class                     => array(
110
-                'attach' => self::ACCESS_ALLOW,
111
-                'detach' => self::ACCESS_ALLOW,
112
-            ),
113
-        ),
114
-        'user'              => array(
115
-            '_description' => 'A standard tool user.',
116
-            '_editableBy' => array('admin', 'toolRoot'),
117
-            '_childRoles'                        => array(
118
-                'internalStats',
119
-            ),
120
-            PageMain::class                      => array(
121
-                self::MAIN => self::ACCESS_ALLOW,
122
-            ),
123
-            PageBan::class                       => array(
124
-                self::MAIN => self::ACCESS_ALLOW,
125
-            ),
126
-            PageEditComment::class               => array(
127
-                self::MAIN => self::ACCESS_ALLOW,
128
-            ),
129
-            PageEmailManagement::class           => array(
130
-                self::MAIN => self::ACCESS_ALLOW,
131
-                'view'     => self::ACCESS_ALLOW,
132
-            ),
133
-            PageExpandedRequestList::class       => array(
134
-                self::MAIN => self::ACCESS_ALLOW,
135
-            ),
136
-            PageLog::class                       => array(
137
-                self::MAIN => self::ACCESS_ALLOW,
138
-            ),
139
-            PageSearch::class                    => array(
140
-                self::MAIN => self::ACCESS_ALLOW,
141
-            ),
142
-            PageWelcomeTemplateManagement::class => array(
143
-                self::MAIN => self::ACCESS_ALLOW,
144
-                'select'   => self::ACCESS_ALLOW,
145
-                'view'     => self::ACCESS_ALLOW,
146
-            ),
147
-            PageViewRequest::class               => array(
148
-                self::MAIN => self::ACCESS_ALLOW,
149
-            ),
150
-            'RequestData'                        => array(
151
-                'seePrivateDataWhenReserved' => self::ACCESS_ALLOW,
152
-                'seePrivateDataWithHash'     => self::ACCESS_ALLOW,
153
-            ),
154
-            PageCustomClose::class               => array(
155
-                self::MAIN => self::ACCESS_ALLOW,
156
-            ),
157
-            PageComment::class                   => array(
158
-                self::MAIN => self::ACCESS_ALLOW,
159
-            ),
160
-            PageCloseRequest::class              => array(
161
-                self::MAIN => self::ACCESS_ALLOW,
162
-            ),
163
-            PageDeferRequest::class              => array(
164
-                self::MAIN => self::ACCESS_ALLOW,
165
-            ),
166
-            PageDropRequest::class               => array(
167
-                self::MAIN => self::ACCESS_ALLOW,
168
-            ),
169
-            PageReservation::class               => array(
170
-                self::MAIN => self::ACCESS_ALLOW,
171
-            ),
172
-            PageSendToUser::class                => array(
173
-                self::MAIN => self::ACCESS_ALLOW,
174
-            ),
175
-            PageBreakReservation::class          => array(
176
-                self::MAIN => self::ACCESS_ALLOW,
177
-            ),
102
+			'_childRoles'    => array(
103
+				'public',
104
+			),
105
+			PagePreferences::class               => array(
106
+				self::MAIN       => self::ACCESS_ALLOW,
107
+				'changePassword' => self::ACCESS_ALLOW,
108
+			),
109
+			PageOAuth::class                     => array(
110
+				'attach' => self::ACCESS_ALLOW,
111
+				'detach' => self::ACCESS_ALLOW,
112
+			),
113
+		),
114
+		'user'              => array(
115
+			'_description' => 'A standard tool user.',
116
+			'_editableBy' => array('admin', 'toolRoot'),
117
+			'_childRoles'                        => array(
118
+				'internalStats',
119
+			),
120
+			PageMain::class                      => array(
121
+				self::MAIN => self::ACCESS_ALLOW,
122
+			),
123
+			PageBan::class                       => array(
124
+				self::MAIN => self::ACCESS_ALLOW,
125
+			),
126
+			PageEditComment::class               => array(
127
+				self::MAIN => self::ACCESS_ALLOW,
128
+			),
129
+			PageEmailManagement::class           => array(
130
+				self::MAIN => self::ACCESS_ALLOW,
131
+				'view'     => self::ACCESS_ALLOW,
132
+			),
133
+			PageExpandedRequestList::class       => array(
134
+				self::MAIN => self::ACCESS_ALLOW,
135
+			),
136
+			PageLog::class                       => array(
137
+				self::MAIN => self::ACCESS_ALLOW,
138
+			),
139
+			PageSearch::class                    => array(
140
+				self::MAIN => self::ACCESS_ALLOW,
141
+			),
142
+			PageWelcomeTemplateManagement::class => array(
143
+				self::MAIN => self::ACCESS_ALLOW,
144
+				'select'   => self::ACCESS_ALLOW,
145
+				'view'     => self::ACCESS_ALLOW,
146
+			),
147
+			PageViewRequest::class               => array(
148
+				self::MAIN => self::ACCESS_ALLOW,
149
+			),
150
+			'RequestData'                        => array(
151
+				'seePrivateDataWhenReserved' => self::ACCESS_ALLOW,
152
+				'seePrivateDataWithHash'     => self::ACCESS_ALLOW,
153
+			),
154
+			PageCustomClose::class               => array(
155
+				self::MAIN => self::ACCESS_ALLOW,
156
+			),
157
+			PageComment::class                   => array(
158
+				self::MAIN => self::ACCESS_ALLOW,
159
+			),
160
+			PageCloseRequest::class              => array(
161
+				self::MAIN => self::ACCESS_ALLOW,
162
+			),
163
+			PageDeferRequest::class              => array(
164
+				self::MAIN => self::ACCESS_ALLOW,
165
+			),
166
+			PageDropRequest::class               => array(
167
+				self::MAIN => self::ACCESS_ALLOW,
168
+			),
169
+			PageReservation::class               => array(
170
+				self::MAIN => self::ACCESS_ALLOW,
171
+			),
172
+			PageSendToUser::class                => array(
173
+				self::MAIN => self::ACCESS_ALLOW,
174
+			),
175
+			PageBreakReservation::class          => array(
176
+				self::MAIN => self::ACCESS_ALLOW,
177
+			),
178 178
 
179
-        ),
180
-        'admin'             => array(
181
-            '_description' => 'A tool administrator.',
182
-            '_editableBy' => array('admin', 'toolRoot'),
183
-            '_childRoles'                        => array(
184
-                'user', 'requestAdminTools',
185
-            ),
186
-            PageEmailManagement::class           => array(
187
-                'edit'   => self::ACCESS_ALLOW,
188
-                'create' => self::ACCESS_ALLOW,
189
-            ),
190
-            PageSiteNotice::class                => array(
191
-                self::MAIN => self::ACCESS_ALLOW,
192
-            ),
193
-            PageUserManagement::class            => array(
194
-                self::MAIN  => self::ACCESS_ALLOW,
195
-                'approve'   => self::ACCESS_ALLOW,
196
-                'decline'   => self::ACCESS_ALLOW,
197
-                'rename'    => self::ACCESS_ALLOW,
198
-                'editUser'  => self::ACCESS_ALLOW,
199
-                'suspend'   => self::ACCESS_ALLOW,
200
-                'editRoles' => self::ACCESS_ALLOW,
201
-            ),
202
-            PageWelcomeTemplateManagement::class => array(
203
-                'edit'   => self::ACCESS_ALLOW,
204
-                'delete' => self::ACCESS_ALLOW,
205
-                'add'    => self::ACCESS_ALLOW,
206
-            ),
207
-        ),
208
-        'checkuser'         => array(
209
-            '_description' => 'A user with CheckUser access',
210
-            '_editableBy' => array('checkuser', 'toolRoot'),
211
-            '_childRoles'             => array(
212
-                'user', 'requestAdminTools',
213
-            ),
214
-            PageUserManagement::class => array(
215
-                self::MAIN  => self::ACCESS_ALLOW,
216
-                'suspend'   => self::ACCESS_ALLOW,
217
-                'editRoles' => self::ACCESS_ALLOW,
218
-            ),
219
-            'RequestData'             => array(
220
-                'seeUserAgentData' => self::ACCESS_ALLOW,
221
-            ),
222
-        ),
223
-        'toolRoot'         => array(
224
-            '_description' => 'A user with shell access to the servers running the tool',
225
-            '_editableBy' => array('toolRoot'),
226
-            '_childRoles'             => array(
227
-                'admin', 'checkuser',
228
-            ),
229
-        ),
179
+		),
180
+		'admin'             => array(
181
+			'_description' => 'A tool administrator.',
182
+			'_editableBy' => array('admin', 'toolRoot'),
183
+			'_childRoles'                        => array(
184
+				'user', 'requestAdminTools',
185
+			),
186
+			PageEmailManagement::class           => array(
187
+				'edit'   => self::ACCESS_ALLOW,
188
+				'create' => self::ACCESS_ALLOW,
189
+			),
190
+			PageSiteNotice::class                => array(
191
+				self::MAIN => self::ACCESS_ALLOW,
192
+			),
193
+			PageUserManagement::class            => array(
194
+				self::MAIN  => self::ACCESS_ALLOW,
195
+				'approve'   => self::ACCESS_ALLOW,
196
+				'decline'   => self::ACCESS_ALLOW,
197
+				'rename'    => self::ACCESS_ALLOW,
198
+				'editUser'  => self::ACCESS_ALLOW,
199
+				'suspend'   => self::ACCESS_ALLOW,
200
+				'editRoles' => self::ACCESS_ALLOW,
201
+			),
202
+			PageWelcomeTemplateManagement::class => array(
203
+				'edit'   => self::ACCESS_ALLOW,
204
+				'delete' => self::ACCESS_ALLOW,
205
+				'add'    => self::ACCESS_ALLOW,
206
+			),
207
+		),
208
+		'checkuser'         => array(
209
+			'_description' => 'A user with CheckUser access',
210
+			'_editableBy' => array('checkuser', 'toolRoot'),
211
+			'_childRoles'             => array(
212
+				'user', 'requestAdminTools',
213
+			),
214
+			PageUserManagement::class => array(
215
+				self::MAIN  => self::ACCESS_ALLOW,
216
+				'suspend'   => self::ACCESS_ALLOW,
217
+				'editRoles' => self::ACCESS_ALLOW,
218
+			),
219
+			'RequestData'             => array(
220
+				'seeUserAgentData' => self::ACCESS_ALLOW,
221
+			),
222
+		),
223
+		'toolRoot'         => array(
224
+			'_description' => 'A user with shell access to the servers running the tool',
225
+			'_editableBy' => array('toolRoot'),
226
+			'_childRoles'             => array(
227
+				'admin', 'checkuser',
228
+			),
229
+		),
230 230
 
231
-        // Child roles go below this point
232
-        'publicStats'       => array(
233
-            '_hidden'               => true,
234
-            StatsUsers::class       => array(
235
-                self::MAIN => self::ACCESS_ALLOW,
236
-                'detail'   => self::ACCESS_ALLOW,
237
-            ),
238
-            StatsTopCreators::class => array(
239
-                self::MAIN => self::ACCESS_ALLOW,
240
-            ),
241
-        ),
242
-        'internalStats'     => array(
243
-            '_hidden'                    => true,
244
-            StatsMain::class             => array(
245
-                self::MAIN => self::ACCESS_ALLOW,
246
-            ),
247
-            StatsFastCloses::class       => array(
248
-                self::MAIN => self::ACCESS_ALLOW,
249
-            ),
250
-            StatsInactiveUsers::class    => array(
251
-                self::MAIN => self::ACCESS_ALLOW,
252
-            ),
253
-            StatsMonthlyStats::class     => array(
254
-                self::MAIN => self::ACCESS_ALLOW,
255
-            ),
256
-            StatsReservedRequests::class => array(
257
-                self::MAIN => self::ACCESS_ALLOW,
258
-            ),
259
-            StatsTemplateStats::class    => array(
260
-                self::MAIN => self::ACCESS_ALLOW,
261
-            ),
262
-        ),
263
-        'requestAdminTools' => array(
264
-            '_hidden'                   => true,
265
-            PageBan::class              => array(
266
-                self::MAIN => self::ACCESS_ALLOW,
267
-                'set'      => self::ACCESS_ALLOW,
268
-                'remove'   => self::ACCESS_ALLOW,
269
-            ),
270
-            PageEditComment::class      => array(
271
-                'editOthers' => self::ACCESS_ALLOW,
272
-            ),
273
-            PageBreakReservation::class => array(
274
-                'force' => self::ACCESS_ALLOW,
275
-            ),
276
-            PageCustomClose::class      => array(
277
-                'skipCcMailingList' => self::ACCESS_ALLOW,
278
-            ),
279
-            'RequestData'               => array(
280
-                'reopenOldRequest'      => self::ACCESS_ALLOW,
281
-                'alwaysSeePrivateData'  => self::ACCESS_ALLOW,
282
-                'alwaysSeeHash'         => self::ACCESS_ALLOW,
283
-                'seeRestrictedComments' => self::ACCESS_ALLOW,
284
-            ),
285
-        ),
286
-    );
287
-    /** @var array
288
-     * List of roles which are *exempt* from the identification requirements
289
-     *
290
-     * Think twice about adding roles to this list.
291
-     *
292
-     * @category Security-Critical
293
-     */
294
-    private $identificationExempt = array('public', 'loggedIn');
231
+		// Child roles go below this point
232
+		'publicStats'       => array(
233
+			'_hidden'               => true,
234
+			StatsUsers::class       => array(
235
+				self::MAIN => self::ACCESS_ALLOW,
236
+				'detail'   => self::ACCESS_ALLOW,
237
+			),
238
+			StatsTopCreators::class => array(
239
+				self::MAIN => self::ACCESS_ALLOW,
240
+			),
241
+		),
242
+		'internalStats'     => array(
243
+			'_hidden'                    => true,
244
+			StatsMain::class             => array(
245
+				self::MAIN => self::ACCESS_ALLOW,
246
+			),
247
+			StatsFastCloses::class       => array(
248
+				self::MAIN => self::ACCESS_ALLOW,
249
+			),
250
+			StatsInactiveUsers::class    => array(
251
+				self::MAIN => self::ACCESS_ALLOW,
252
+			),
253
+			StatsMonthlyStats::class     => array(
254
+				self::MAIN => self::ACCESS_ALLOW,
255
+			),
256
+			StatsReservedRequests::class => array(
257
+				self::MAIN => self::ACCESS_ALLOW,
258
+			),
259
+			StatsTemplateStats::class    => array(
260
+				self::MAIN => self::ACCESS_ALLOW,
261
+			),
262
+		),
263
+		'requestAdminTools' => array(
264
+			'_hidden'                   => true,
265
+			PageBan::class              => array(
266
+				self::MAIN => self::ACCESS_ALLOW,
267
+				'set'      => self::ACCESS_ALLOW,
268
+				'remove'   => self::ACCESS_ALLOW,
269
+			),
270
+			PageEditComment::class      => array(
271
+				'editOthers' => self::ACCESS_ALLOW,
272
+			),
273
+			PageBreakReservation::class => array(
274
+				'force' => self::ACCESS_ALLOW,
275
+			),
276
+			PageCustomClose::class      => array(
277
+				'skipCcMailingList' => self::ACCESS_ALLOW,
278
+			),
279
+			'RequestData'               => array(
280
+				'reopenOldRequest'      => self::ACCESS_ALLOW,
281
+				'alwaysSeePrivateData'  => self::ACCESS_ALLOW,
282
+				'alwaysSeeHash'         => self::ACCESS_ALLOW,
283
+				'seeRestrictedComments' => self::ACCESS_ALLOW,
284
+			),
285
+		),
286
+	);
287
+	/** @var array
288
+	 * List of roles which are *exempt* from the identification requirements
289
+	 *
290
+	 * Think twice about adding roles to this list.
291
+	 *
292
+	 * @category Security-Critical
293
+	 */
294
+	private $identificationExempt = array('public', 'loggedIn');
295 295
 
296
-    /**
297
-     * RoleConfiguration constructor.
298
-     *
299
-     * @param array $roleConfig           Set to non-null to override the default configuration.
300
-     * @param array $identificationExempt Set to non-null to override the default configuration.
301
-     */
302
-    public function __construct(array $roleConfig = null, array $identificationExempt = null)
303
-    {
304
-        if ($roleConfig !== null) {
305
-            $this->roleConfig = $roleConfig;
306
-        }
296
+	/**
297
+	 * RoleConfiguration constructor.
298
+	 *
299
+	 * @param array $roleConfig           Set to non-null to override the default configuration.
300
+	 * @param array $identificationExempt Set to non-null to override the default configuration.
301
+	 */
302
+	public function __construct(array $roleConfig = null, array $identificationExempt = null)
303
+	{
304
+		if ($roleConfig !== null) {
305
+			$this->roleConfig = $roleConfig;
306
+		}
307 307
 
308
-        if ($identificationExempt !== null) {
309
-            $this->identificationExempt = $identificationExempt;
310
-        }
311
-    }
308
+		if ($identificationExempt !== null) {
309
+			$this->identificationExempt = $identificationExempt;
310
+		}
311
+	}
312 312
 
313
-    /**
314
-     * @param array $roles The roles to check
315
-     *
316
-     * @return array
317
-     */
318
-    public function getApplicableRoles(array $roles)
319
-    {
320
-        $available = array();
313
+	/**
314
+	 * @param array $roles The roles to check
315
+	 *
316
+	 * @return array
317
+	 */
318
+	public function getApplicableRoles(array $roles)
319
+	{
320
+		$available = array();
321 321
 
322
-        foreach ($roles as $role) {
323
-            if (!isset($this->roleConfig[$role])) {
324
-                // wat
325
-                continue;
326
-            }
322
+		foreach ($roles as $role) {
323
+			if (!isset($this->roleConfig[$role])) {
324
+				// wat
325
+				continue;
326
+			}
327 327
 
328
-            $available[$role] = $this->roleConfig[$role];
328
+			$available[$role] = $this->roleConfig[$role];
329 329
 
330
-            if (isset($available[$role]['_childRoles'])) {
331
-                $childRoles = self::getApplicableRoles($available[$role]['_childRoles']);
332
-                $available = array_merge($available, $childRoles);
330
+			if (isset($available[$role]['_childRoles'])) {
331
+				$childRoles = self::getApplicableRoles($available[$role]['_childRoles']);
332
+				$available = array_merge($available, $childRoles);
333 333
 
334
-                unset($available[$role]['_childRoles']);
335
-            }
334
+				unset($available[$role]['_childRoles']);
335
+			}
336 336
 
337
-            foreach (array('_hidden', '_editableBy', '_description') as $item) {
338
-                if (isset($available[$role][$item])) {
339
-                    unset($available[$role][$item]);
340
-                }
341
-            }
342
-        }
337
+			foreach (array('_hidden', '_editableBy', '_description') as $item) {
338
+				if (isset($available[$role][$item])) {
339
+					unset($available[$role][$item]);
340
+				}
341
+			}
342
+		}
343 343
 
344
-        return $available;
345
-    }
344
+		return $available;
345
+	}
346 346
 
347
-    public function getAvailableRoles()
348
-    {
349
-        $possible = array_diff(array_keys($this->roleConfig), array('public', 'loggedIn'));
347
+	public function getAvailableRoles()
348
+	{
349
+		$possible = array_diff(array_keys($this->roleConfig), array('public', 'loggedIn'));
350 350
 
351
-        $actual = array();
351
+		$actual = array();
352 352
 
353
-        foreach ($possible as $role) {
354
-            if (!isset($this->roleConfig[$role]['_hidden'])) {
355
-                $actual[$role] = array(
356
-                    'description' => $this->roleConfig[$role]['_description'],
357
-                    'editableBy'  => $this->roleConfig[$role]['_editableBy'],
358
-                );
359
-            }
360
-        }
353
+		foreach ($possible as $role) {
354
+			if (!isset($this->roleConfig[$role]['_hidden'])) {
355
+				$actual[$role] = array(
356
+					'description' => $this->roleConfig[$role]['_description'],
357
+					'editableBy'  => $this->roleConfig[$role]['_editableBy'],
358
+				);
359
+			}
360
+		}
361 361
 
362
-        return $actual;
363
-    }
362
+		return $actual;
363
+	}
364 364
 
365
-    /**
366
-     * @param string $role
367
-     *
368
-     * @return bool
369
-     */
370
-    public function roleNeedsIdentification($role)
371
-    {
372
-        if (in_array($role, $this->identificationExempt)) {
373
-            return false;
374
-        }
365
+	/**
366
+	 * @param string $role
367
+	 *
368
+	 * @return bool
369
+	 */
370
+	public function roleNeedsIdentification($role)
371
+	{
372
+		if (in_array($role, $this->identificationExempt)) {
373
+			return false;
374
+		}
375 375
 
376
-        return true;
377
-    }
376
+		return true;
377
+	}
378 378
 }
Please login to merge, or discard this patch.