Completed
Pull Request — master (#922)
by Chris
113:52 queued 66:29
created

HasPermissions::getGuardNames()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 4

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 1
nc 1
nop 0
dl 0
loc 4
rs 10
c 0
b 0
f 0
1
<?php
2
3
namespace Spatie\Permission\Traits;
4
5
use Spatie\Permission\Guard;
6
use Illuminate\Support\Collection;
7
use Illuminate\Database\Eloquent\Builder;
8
use Spatie\Permission\PermissionRegistrar;
9
use Spatie\Permission\Contracts\Permission;
10
use Spatie\Permission\Exceptions\GuardDoesNotMatch;
11
use Illuminate\Database\Eloquent\Relations\MorphToMany;
12
use Spatie\Permission\Exceptions\PermissionDoesNotExist;
13
14
trait HasPermissions
15
{
16
    private $permissionClass;
17
18
    public static function bootHasPermissions()
19
    {
20
        static::deleting(function ($model) {
21
            if (method_exists($model, 'isForceDeleting') && ! $model->isForceDeleting()) {
22
                return;
23
            }
24
25
            $model->permissions()->detach();
26
        });
27
    }
28
29
    public function getPermissionClass()
30
    {
31
        if (! isset($this->permissionClass)) {
32
            $this->permissionClass = app(PermissionRegistrar::class)->getPermissionClass();
33
        }
34
35
        return $this->permissionClass;
36
    }
37
38
    /**
39
     * A model may have multiple direct permissions.
40
     */
41
    public function permissions(): MorphToMany
42
    {
43
        return $this->morphToMany(
0 ignored issues
show
Bug introduced by
It seems like morphToMany() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
44
            config('permission.models.permission'),
45
            'model',
46
            config('permission.table_names.model_has_permissions'),
47
            config('permission.column_names.model_morph_key'),
48
            'permission_id'
49
        );
50
    }
51
52
    /**
53
     * Scope the model query to certain permissions only.
54
     *
55
     * @param \Illuminate\Database\Eloquent\Builder $query
56
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
57
     *
58
     * @return \Illuminate\Database\Eloquent\Builder
59
     */
60
    public function scopePermission(Builder $query, $permissions): Builder
61
    {
62
        $permissions = $this->convertToPermissionModels($permissions);
63
64
        $rolesWithPermissions = array_unique(array_reduce($permissions, function ($result, $permission) {
65
            return array_merge($result, $permission->roles->all());
66
        }, []));
67
68
        return $query->where(function ($query) use ($permissions, $rolesWithPermissions) {
69
            $query->whereHas('permissions', function ($query) use ($permissions) {
70
                $query->where(function ($query) use ($permissions) {
71
                    foreach ($permissions as $permission) {
72
                        $query->orWhere(config('permission.table_names.permissions').'.id', $permission->id);
73
                    }
74
                });
75
            });
76
            if (count($rolesWithPermissions) > 0) {
77
                $query->orWhereHas('roles', function ($query) use ($rolesWithPermissions) {
78
                    $query->where(function ($query) use ($rolesWithPermissions) {
79
                        foreach ($rolesWithPermissions as $role) {
80
                            $query->orWhere(config('permission.table_names.roles').'.id', $role->id);
81
                        }
82
                    });
83
                });
84
            }
85
        });
86
    }
87
88
    /**
89
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
90
     *
91
     * @return array
92
     */
93
    protected function convertToPermissionModels($permissions): array
94
    {
95
        if ($permissions instanceof Collection) {
96
            $permissions = $permissions->all();
97
        }
98
99
        $permissions = array_wrap($permissions);
100
101
        return array_map(function ($permission) {
102
            if ($permission instanceof Permission) {
103
                return $permission;
104
            }
105
106
            return $this->getPermissionClass()->findByName($permission, $this->getDefaultGuardName());
107
        }, $permissions);
108
    }
109
110
    /**
111
     * Determine if the model may perform the given permission.
112
     *
113
     * @param string|int|\Spatie\Permission\Contracts\Permission $permission
114
     * @param string|null $guardName
115
     *
116
     * @return bool
117
     */
118
    public function hasPermissionTo($permission, $guardName = null): bool
119
    {
120
        $permissionClass = $this->getPermissionClass();
121
122
        if (is_string($permission)) {
123
            $permission = $permissionClass->findByName(
124
                $permission,
125
                $guardName ?? $this->getDefaultGuardName()
126
            );
127
        }
128
129
        if (is_int($permission)) {
130
            $permission = $permissionClass->findById(
131
                $permission,
132
                $guardName ?? $this->getDefaultGuardName()
133
            );
134
        }
135
136
        if (! $permission instanceof Permission) {
137
            throw new PermissionDoesNotExist;
138
        }
139
140
        return $this->hasDirectPermission($permission) || $this->hasPermissionViaRole($permission);
141
    }
142
143
    /**
144
     * An alias to hasPermissionTo(), but avoids throwing an exception.
145
     *
146
     * @param string|int|\Spatie\Permission\Contracts\Permission $permission
147
     * @param string|null $guardName
148
     *
149
     * @return bool
150
     */
151
    public function checkPermissionTo($permission, $guardName = null): bool
152
    {
153
        try {
154
            return $this->hasPermissionTo($permission, $guardName);
155
        } catch (PermissionDoesNotExist $e) {
156
            return false;
157
        }
158
    }
159
160
    /**
161
     * Determine if the model has any of the given permissions.
162
     *
163
     * @param array ...$permissions
164
     *
165
     * @return bool
166
     */
167 View Code Duplication
    public function hasAnyPermission(...$permissions): bool
0 ignored issues
show
Duplication introduced by
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
168
    {
169
        if (is_array($permissions[0])) {
170
            $permissions = $permissions[0];
171
        }
172
173
        foreach ($permissions as $permission) {
174
            if ($this->checkPermissionTo($permission)) {
175
                return true;
176
            }
177
        }
178
179
        return false;
180
    }
181
182
    /**
183
     * Determine if the model has all of the given permissions.
184
     *
185
     * @param array ...$permissions
186
     *
187
     * @return bool
188
     */
189 View Code Duplication
    public function hasAllPermissions(...$permissions): bool
0 ignored issues
show
Duplication introduced by
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
190
    {
191
        if (is_array($permissions[0])) {
192
            $permissions = $permissions[0];
193
        }
194
195
        foreach ($permissions as $permission) {
196
            if (! $this->hasPermissionTo($permission)) {
197
                return false;
198
            }
199
        }
200
201
        return true;
202
    }
203
204
    /**
205
     * Determine if the model has, via roles, the given permission.
206
     *
207
     * @param \Spatie\Permission\Contracts\Permission $permission
208
     *
209
     * @return bool
210
     */
211
    protected function hasPermissionViaRole(Permission $permission): bool
212
    {
213
        return $this->hasRole($permission->roles);
0 ignored issues
show
Bug introduced by
Accessing roles on the interface Spatie\Permission\Contracts\Permission suggest that you code against a concrete implementation. How about adding an instanceof check?

If you access a property on an interface, you most likely code against a concrete implementation of the interface.

Available Fixes

  1. Adding an additional type check:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeInterface $object) {
        if ($object instanceof SomeClass) {
            $a = $object->a;
        }
    }
    
  2. Changing the type hint:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeClass $object) {
        $a = $object->a;
    }
    
Loading history...
Bug introduced by
It seems like hasRole() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
214
    }
215
216
    /**
217
     * Determine if the model has the given permission.
218
     *
219
     * @param string|int|\Spatie\Permission\Contracts\Permission $permission
220
     *
221
     * @return bool
222
     */
223
    public function hasDirectPermission($permission): bool
224
    {
225
        $permissionClass = $this->getPermissionClass();
226
227
        if (is_string($permission)) {
228
            $permission = $permissionClass->findByName($permission, $this->getDefaultGuardName());
229
            if (! $permission) {
230
                return false;
231
            }
232
        }
233
234
        if (is_int($permission)) {
235
            $permission = $permissionClass->findById($permission, $this->getDefaultGuardName());
236
            if (! $permission) {
237
                return false;
238
            }
239
        }
240
241
        if (! $permission instanceof Permission) {
242
            return false;
243
        }
244
245
        return $this->permissions->contains('id', $permission->id);
0 ignored issues
show
Bug introduced by
The property permissions does not exist. Did you maybe forget to declare it?

In PHP it is possible to write to properties without declaring them. For example, the following is perfectly valid PHP code:

class MyClass { }

$x = new MyClass();
$x->foo = true;

Generally, it is a good practice to explictly declare properties to avoid accidental typos and provide IDE auto-completion:

class MyClass {
    public $foo;
}

$x = new MyClass();
$x->foo = true;
Loading history...
Bug introduced by
Accessing id on the interface Spatie\Permission\Contracts\Permission suggest that you code against a concrete implementation. How about adding an instanceof check?

If you access a property on an interface, you most likely code against a concrete implementation of the interface.

Available Fixes

  1. Adding an additional type check:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeInterface $object) {
        if ($object instanceof SomeClass) {
            $a = $object->a;
        }
    }
    
  2. Changing the type hint:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeClass $object) {
        $a = $object->a;
    }
    
Loading history...
246
    }
247
248
    /**
249
     * Return all the permissions the model has via roles.
250
     */
251
    public function getPermissionsViaRoles(): Collection
252
    {
253
        return $this->load('roles', 'roles.permissions')
0 ignored issues
show
Bug introduced by
It seems like load() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
254
            ->roles->flatMap(function ($role) {
255
                return $role->permissions;
256
            })->sort()->values();
257
    }
258
259
    /**
260
     * Return all the permissions the model has, both directly and via roles.
261
     */
262
    public function getAllPermissions(): Collection
263
    {
264
        $permissions = $this->permissions;
265
266
        if ($this->roles) {
0 ignored issues
show
Bug introduced by
The property roles does not exist. Did you maybe forget to declare it?

In PHP it is possible to write to properties without declaring them. For example, the following is perfectly valid PHP code:

class MyClass { }

$x = new MyClass();
$x->foo = true;

Generally, it is a good practice to explictly declare properties to avoid accidental typos and provide IDE auto-completion:

class MyClass {
    public $foo;
}

$x = new MyClass();
$x->foo = true;
Loading history...
267
            $permissions = $permissions->merge($this->getPermissionsViaRoles());
268
        }
269
270
        return $permissions->sort()->values();
271
    }
272
273
    /**
274
     * Grant the given permission(s) to a role.
275
     *
276
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
277
     *
278
     * @return $this
279
     */
280 View Code Duplication
    public function givePermissionTo(...$permissions)
0 ignored issues
show
Duplication introduced by
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
281
    {
282
        $permissions = collect($permissions)
283
            ->flatten()
284
            ->map(function ($permission) {
285
                return $this->getStoredPermission($permission);
286
            })
287
            ->filter(function ($permission) {
288
                return $permission instanceof Permission;
289
            })
290
            ->each(function ($permission) {
291
                $this->ensureModelSharesGuard($permission);
292
            })
293
            ->map->id
294
            ->all();
295
296
        $model = $this->getModel();
0 ignored issues
show
Bug introduced by
It seems like getModel() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
297
298
        if ($model->exists) {
299
            $this->permissions()->sync($permissions, false);
300
            $model->load('permissions');
301
        } else {
302
            $class = \get_class($model);
303
304
            $class::saved(
305
                function ($model) use ($permissions) {
306
                    $model->permissions()->sync($permissions, false);
307
                    $model->load('permissions');
308
                });
309
        }
310
311
        $this->forgetCachedPermissions();
312
313
        return $this;
314
    }
315
316
    /**
317
     * Remove all current permissions and set the given ones.
318
     *
319
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
320
     *
321
     * @return $this
322
     */
323
    public function syncPermissions(...$permissions)
324
    {
325
        $this->permissions()->detach();
326
327
        return $this->givePermissionTo($permissions);
328
    }
329
330
    /**
331
     * Revoke the given permission.
332
     *
333
     * @param \Spatie\Permission\Contracts\Permission|\Spatie\Permission\Contracts\Permission[]|string|string[] $permission
334
     *
335
     * @return $this
336
     */
337
    public function revokePermissionTo($permission)
338
    {
339
        $this->permissions()->detach($this->getStoredPermission($permission));
340
341
        $this->forgetCachedPermissions();
342
343
        $this->load('permissions');
0 ignored issues
show
Bug introduced by
It seems like load() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
344
345
        return $this;
346
    }
347
348
    /**
349
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
350
     *
351
     * @return \Spatie\Permission\Contracts\Permission|\Spatie\Permission\Contracts\Permission[]|\Illuminate\Support\Collection
352
     */
353
    protected function getStoredPermission($permissions)
354
    {
355
        $permissionClass = $this->getPermissionClass();
356
357
        if (is_numeric($permissions)) {
358
            return $permissionClass->findById($permissions, $this->getDefaultGuardName());
359
        }
360
361
        if (is_string($permissions)) {
362
            return $permissionClass->findByName($permissions, $this->getDefaultGuardName());
363
        }
364
365
        if (is_array($permissions)) {
366
            return $permissionClass
367
                ->whereIn('name', $permissions)
368
                ->whereIn('guard_name', $this->getGuardNames())
369
                ->get();
370
        }
371
372
        return $permissions;
373
    }
374
375
    /**
376
     * @param \Spatie\Permission\Contracts\Permission|\Spatie\Permission\Contracts\Role $roleOrPermission
377
     *
378
     * @throws \Spatie\Permission\Exceptions\GuardDoesNotMatch
379
     */
380
    protected function ensureModelSharesGuard($roleOrPermission)
381
    {
382
        if (! $this->getGuardNames()->contains($roleOrPermission->guard_name)) {
383
            throw GuardDoesNotMatch::create($roleOrPermission->guard_name, $this->getGuardNames());
384
        }
385
    }
386
387
    protected function getGuardNames(): Collection
388
    {
389
        return Guard::getNames($this);
390
    }
391
392
    protected function getDefaultGuardName(): string
393
    {
394
        return Guard::getDefaultName($this);
395
    }
396
397
    /**
398
     * Forget the cached permissions.
399
     */
400
    public function forgetCachedPermissions()
401
    {
402
        app(PermissionRegistrar::class)->forgetCachedPermissions();
403
    }
404
}
405