| Conditions | 12 | 
| Paths | 25 | 
| Total Lines | 78 | 
| Lines | 0 | 
| Ratio | 0 % | 
| Changes | 0 | ||
Small methods make your code easier to understand, in particular if combined with a good name. Besides, if your method is small, finding a good name is usually much easier.
For example, if you find yourself adding comments to a method's body, this is usually a good sign to extract the commented part to a new method, and use the comment as a starting point when coming up with a good name for this new method.
Commonly applied refactorings include:
If many parameters/temporary variables are present:
| 1 | <?php | ||
| 148 | public function canUser($module, $function, ValueObject $object, array $targets = []) | ||
| 149 |     { | ||
| 150 | $permissionSets = $this->hasAccess($module, $function); | ||
| 151 |         if ($permissionSets === false || $permissionSets === true) { | ||
| 152 | return $permissionSets; | ||
| 153 | } | ||
| 154 | |||
| 155 |         if (empty($targets)) { | ||
| 156 | $targets = null; | ||
| 157 | } | ||
| 158 | |||
| 159 | $currentUserRef = $this->getCurrentUserReference(); | ||
| 160 |         foreach ($permissionSets as $permissionSet) { | ||
| 161 | /** | ||
| 162 | * First deal with Role limitation if any. | ||
| 163 | * | ||
| 164 | * Here we accept ACCESS_GRANTED and ACCESS_ABSTAIN, the latter in cases where $object and $targets | ||
| 165 | * are not supported by limitation. | ||
| 166 | * | ||
| 167 | * @var \eZ\Publish\API\Repository\Values\User\Limitation[] | ||
| 168 | */ | ||
| 169 |             if ($permissionSet['limitation'] instanceof Limitation) { | ||
| 170 | $type = $this->limitationService->getLimitationType($permissionSet['limitation']->getIdentifier()); | ||
| 171 | $accessVote = $type->evaluate($permissionSet['limitation'], $currentUserRef, $object, $targets); | ||
| 172 |                 if ($accessVote === LimitationType::ACCESS_DENIED) { | ||
| 173 | continue; | ||
| 174 | } | ||
| 175 | } | ||
| 176 | |||
| 177 | /** | ||
| 178 | * Loop over all policies. | ||
| 179 | * | ||
| 180 | * These are already filtered by hasAccess and given hasAccess did not return boolean | ||
| 181 | * there must be some, so only return true if one of them says yes. | ||
| 182 | * | ||
| 183 | * @var \eZ\Publish\API\Repository\Values\User\Policy | ||
| 184 | */ | ||
| 185 |             foreach ($permissionSet['policies'] as $policy) { | ||
| 186 | $limitations = $policy->getLimitations(); | ||
| 187 | |||
| 188 | /* | ||
| 189 | * Return true if policy gives full access (aka no limitations) | ||
| 190 | */ | ||
| 191 |                 if ($limitations === '*') { | ||
| 192 | return true; | ||
| 193 | } | ||
| 194 | |||
| 195 | /* | ||
| 196 | * Loop over limitations, all must return ACCESS_GRANTED for policy to pass. | ||
| 197 | * If limitations was empty array this means same as '*' | ||
| 198 | */ | ||
| 199 | $limitationsPass = true; | ||
| 200 |                 foreach ($limitations as $limitation) { | ||
| 201 | $type = $this->limitationService->getLimitationType($limitation->getIdentifier()); | ||
| 202 | $accessVote = $type->evaluate($limitation, $currentUserRef, $object, $targets); | ||
| 203 | /* | ||
| 204 | * For policy limitation atm only support ACCESS_GRANTED | ||
| 205 | * | ||
| 206 | * Reasoning: Right now, use of a policy limitation not valid for a policy is per definition a | ||
| 207 | * BadState. To reach this you would have to configure the "policyMap" wrongly, like using | ||
| 208 | * Node (Location) limitation on state/assign. So in this case Role Limitations will return | ||
| 209 | * ACCESS_ABSTAIN (== no access here), and other limitations will throw InvalidArgument above, | ||
| 210 | * both cases forcing dev to investigate to find miss configuration. This might be relaxed in | ||
| 211 | * the future if valid use cases for ACCESS_ABSTAIN on policy limitations becomes known. | ||
| 212 | */ | ||
| 213 |                     if ($accessVote !== LimitationType::ACCESS_GRANTED) { | ||
| 214 | $limitationsPass = false; | ||
| 215 | break; // Break to next policy, all limitations must pass | ||
| 216 | } | ||
| 217 | } | ||
| 218 |                 if ($limitationsPass) { | ||
| 219 | return true; | ||
| 220 | } | ||
| 221 | } | ||
| 222 | } | ||
| 223 | |||
| 224 | return false; // None of the limitation sets wanted to let you in, sorry! | ||
| 225 | } | ||
| 226 | |||
| 267 | 
If a method or function can return multiple different values and unless you are sure that you only can receive a single value in this context, we recommend to add an additional type check:
If this a common case that PHP Analyzer should handle natively, please let us know by opening an issue.