Completed
Push — master ( 37f317...606373 )
by Chris
01:34
created

HasPermissions::scopePermission()   A

Complexity

Conditions 4
Paths 1

Size

Total Lines 27

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 4
nc 1
nop 2
dl 0
loc 27
rs 9.488
c 0
b 0
f 0
1
<?php
2
3
namespace Spatie\Permission\Traits;
4
5
use Spatie\Permission\Guard;
6
use Illuminate\Support\Collection;
7
use Illuminate\Database\Eloquent\Builder;
8
use Spatie\Permission\PermissionRegistrar;
9
use Spatie\Permission\Contracts\Permission;
10
use Spatie\Permission\Exceptions\GuardDoesNotMatch;
11
use Illuminate\Database\Eloquent\Relations\MorphToMany;
12
use Spatie\Permission\Exceptions\PermissionDoesNotExist;
13
14
trait HasPermissions
15
{
16
    private $permissionClass;
17
18
    public static function bootHasPermissions()
19
    {
20
        static::deleting(function ($model) {
21
            if (method_exists($model, 'isForceDeleting') && ! $model->isForceDeleting()) {
22
                return;
23
            }
24
25
            $model->permissions()->detach();
26
        });
27
    }
28
29
    public function getPermissionClass()
30
    {
31
        if (! isset($this->permissionClass)) {
32
            $this->permissionClass = app(PermissionRegistrar::class)->getPermissionClass();
33
        }
34
35
        return $this->permissionClass;
36
    }
37
38
    /**
39
     * A model may have multiple direct permissions.
40
     */
41
    public function permissions(): MorphToMany
42
    {
43
        return $this->morphToMany(
0 ignored issues
show
Bug introduced by
It seems like morphToMany() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
44
            config('permission.models.permission'),
45
            'model',
46
            config('permission.table_names.model_has_permissions'),
47
            config('permission.column_names.model_morph_key'),
48
            'permission_id'
49
        );
50
    }
51
52
    /**
53
     * Scope the model query to certain permissions only.
54
     *
55
     * @param \Illuminate\Database\Eloquent\Builder $query
56
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
57
     *
58
     * @return \Illuminate\Database\Eloquent\Builder
59
     */
60
    public function scopePermission(Builder $query, $permissions): Builder
61
    {
62
        $permissions = $this->convertToPermissionModels($permissions);
63
64
        $rolesWithPermissions = array_unique(array_reduce($permissions, function ($result, $permission) {
65
            return array_merge($result, $permission->roles->all());
66
        }, []));
67
68
        return $query->where(function ($query) use ($permissions, $rolesWithPermissions) {
69
            $query->whereHas('permissions', function ($query) use ($permissions) {
70
                $query->where(function ($query) use ($permissions) {
71
                    foreach ($permissions as $permission) {
72
                        $query->orWhere(config('permission.table_names.permissions').'.id', $permission->id);
73
                    }
74
                });
75
            });
76
            if (count($rolesWithPermissions) > 0) {
77
                $query->orWhereHas('roles', function ($query) use ($rolesWithPermissions) {
78
                    $query->where(function ($query) use ($rolesWithPermissions) {
79
                        foreach ($rolesWithPermissions as $role) {
80
                            $query->orWhere(config('permission.table_names.roles').'.id', $role->id);
81
                        }
82
                    });
83
                });
84
            }
85
        });
86
    }
87
88
    /**
89
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
90
     *
91
     * @return array
92
     */
93
    protected function convertToPermissionModels($permissions): array
94
    {
95
        if ($permissions instanceof Collection) {
96
            $permissions = $permissions->all();
97
        }
98
99
        $permissions = array_wrap($permissions);
100
101
        return array_map(function ($permission) {
102
            if ($permission instanceof Permission) {
103
                return $permission;
104
            }
105
106
            return $this->getPermissionClass()->findByName($permission, $this->getDefaultGuardName());
107
        }, $permissions);
108
    }
109
110
    /**
111
     * Determine if the model may perform the given permission.
112
     *
113
     * @param string|int|\Spatie\Permission\Contracts\Permission $permission
114
     * @param string|null $guardName
115
     *
116
     * @return bool
117
     */
118
    public function hasPermissionTo($permission, $guardName = null): bool
119
    {
120
        $permissionClass = $this->getPermissionClass();
121
122
        if (is_string($permission)) {
123
            $permission = $permissionClass->findByName(
124
                $permission,
125
                $guardName ?? $this->getDefaultGuardName()
126
            );
127
        }
128
129
        if (is_int($permission)) {
130
            $permission = $permissionClass->findById(
131
                $permission,
132
                $guardName ?? $this->getDefaultGuardName()
133
            );
134
        }
135
136
        if (! $permission instanceof Permission) {
137
            throw new PermissionDoesNotExist;
138
        }
139
140
        return $this->hasDirectPermission($permission) || $this->hasPermissionViaRole($permission);
141
    }
142
143
    /**
144
     * Determine if the model has any of the given permissions.
145
     *
146
     * @param array ...$permissions
147
     *
148
     * @return bool
149
     */
150 View Code Duplication
    public function hasAnyPermission(...$permissions): bool
0 ignored issues
show
Duplication introduced by
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
151
    {
152
        if (is_array($permissions[0])) {
153
            $permissions = $permissions[0];
154
        }
155
156
        foreach ($permissions as $permission) {
157
            if ($this->hasPermissionTo($permission)) {
158
                return true;
159
            }
160
        }
161
162
        return false;
163
    }
164
165
    /**
166
     * Determine if the model has all of the given permissions.
167
     *
168
     * @param array ...$permissions
169
     *
170
     * @return bool
171
     */
172 View Code Duplication
    public function hasAllPermissions(...$permissions): bool
0 ignored issues
show
Duplication introduced by
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
173
    {
174
        if (is_array($permissions[0])) {
175
            $permissions = $permissions[0];
176
        }
177
178
        foreach ($permissions as $permission) {
179
            if (! $this->hasPermissionTo($permission)) {
180
                return false;
181
            }
182
        }
183
184
        return true;
185
    }
186
187
    /**
188
     * Determine if the model has, via roles, the given permission.
189
     *
190
     * @param \Spatie\Permission\Contracts\Permission $permission
191
     *
192
     * @return bool
193
     */
194
    protected function hasPermissionViaRole(Permission $permission): bool
195
    {
196
        return $this->hasRole($permission->roles);
0 ignored issues
show
Bug introduced by
Accessing roles on the interface Spatie\Permission\Contracts\Permission suggest that you code against a concrete implementation. How about adding an instanceof check?

If you access a property on an interface, you most likely code against a concrete implementation of the interface.

Available Fixes

  1. Adding an additional type check:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeInterface $object) {
        if ($object instanceof SomeClass) {
            $a = $object->a;
        }
    }
    
  2. Changing the type hint:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeClass $object) {
        $a = $object->a;
    }
    
Loading history...
Bug introduced by
It seems like hasRole() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
197
    }
198
199
    /**
200
     * Determine if the model has the given permission.
201
     *
202
     * @param string|int|\Spatie\Permission\Contracts\Permission $permission
203
     *
204
     * @return bool
205
     */
206
    public function hasDirectPermission($permission): bool
207
    {
208
        $permissionClass = $this->getPermissionClass();
209
210
        if (is_string($permission)) {
211
            $permission = $permissionClass->findByName($permission, $this->getDefaultGuardName());
212
            if (! $permission) {
213
                return false;
214
            }
215
        }
216
217
        if (is_int($permission)) {
218
            $permission = $permissionClass->findById($permission, $this->getDefaultGuardName());
219
            if (! $permission) {
220
                return false;
221
            }
222
        }
223
224
        if (! $permission instanceof Permission) {
225
            return false;
226
        }
227
228
        return $this->permissions->contains('id', $permission->id);
0 ignored issues
show
Bug introduced by
The property permissions does not exist. Did you maybe forget to declare it?

In PHP it is possible to write to properties without declaring them. For example, the following is perfectly valid PHP code:

class MyClass { }

$x = new MyClass();
$x->foo = true;

Generally, it is a good practice to explictly declare properties to avoid accidental typos and provide IDE auto-completion:

class MyClass {
    public $foo;
}

$x = new MyClass();
$x->foo = true;
Loading history...
Bug introduced by
Accessing id on the interface Spatie\Permission\Contracts\Permission suggest that you code against a concrete implementation. How about adding an instanceof check?

If you access a property on an interface, you most likely code against a concrete implementation of the interface.

Available Fixes

  1. Adding an additional type check:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeInterface $object) {
        if ($object instanceof SomeClass) {
            $a = $object->a;
        }
    }
    
  2. Changing the type hint:

    interface SomeInterface { }
    class SomeClass implements SomeInterface {
        public $a;
    }
    
    function someFunction(SomeClass $object) {
        $a = $object->a;
    }
    
Loading history...
229
    }
230
231
    /**
232
     * Return all the permissions the model has via roles.
233
     */
234
    public function getPermissionsViaRoles(): Collection
235
    {
236
        return $this->load('roles', 'roles.permissions')
0 ignored issues
show
Bug introduced by
It seems like load() must be provided by classes using this trait. How about adding it as abstract method to this trait?

This check looks for methods that are used by a trait but not required by it.

To illustrate, let’s look at the following code example

trait Idable {
    public function equalIds(Idable $other) {
        return $this->getId() === $other->getId();
    }
}

The trait Idable provides a method equalsId that in turn relies on the method getId(). If this method does not exist on a class mixing in this trait, the method will fail.

Adding the getId() as an abstract method to the trait will make sure it is available.

Loading history...
237
            ->roles->flatMap(function ($role) {
238
                return $role->permissions;
239
            })->sort()->values();
240
    }
241
242
    /**
243
     * Return all the permissions the model has, both directly and via roles.
244
     */
245
    public function getAllPermissions(): Collection
246
    {
247
        return $this->permissions
248
            ->merge($this->getPermissionsViaRoles())
249
            ->sort()
250
            ->values();
251
    }
252
253
    /**
254
     * Grant the given permission(s) to a role.
255
     *
256
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
257
     *
258
     * @return $this
259
     */
260 View Code Duplication
    public function givePermissionTo(...$permissions)
0 ignored issues
show
Duplication introduced by
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
261
    {
262
        $permissions = collect($permissions)
263
            ->flatten()
264
            ->map(function ($permission) {
265
                return $this->getStoredPermission($permission);
266
            })
267
            ->filter(function ($permission) {
268
                return $permission instanceof Permission;
269
            })
270
            ->each(function ($permission) {
271
                $this->ensureModelSharesGuard($permission);
272
            })
273
            ->map->id
274
            ->all();
275
276
        $this->permissions()->sync($permissions, false);
277
278
        $this->forgetCachedPermissions();
279
280
        return $this;
281
    }
282
283
    /**
284
     * Remove all current permissions and set the given ones.
285
     *
286
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
287
     *
288
     * @return $this
289
     */
290
    public function syncPermissions(...$permissions)
291
    {
292
        $this->permissions()->detach();
293
294
        return $this->givePermissionTo($permissions);
295
    }
296
297
    /**
298
     * Revoke the given permission.
299
     *
300
     * @param \Spatie\Permission\Contracts\Permission|\Spatie\Permission\Contracts\Permission[]|string|string[] $permission
301
     *
302
     * @return $this
303
     */
304
    public function revokePermissionTo($permission)
305
    {
306
        $this->permissions()->detach($this->getStoredPermission($permission));
307
308
        $this->forgetCachedPermissions();
309
310
        return $this;
311
    }
312
313
    /**
314
     * @param string|array|\Spatie\Permission\Contracts\Permission|\Illuminate\Support\Collection $permissions
315
     *
316
     * @return \Spatie\Permission\Contracts\Permission|\Spatie\Permission\Contracts\Permission[]|\Illuminate\Support\Collection
317
     */
318
    protected function getStoredPermission($permissions)
319
    {
320
        $permissionClass = $this->getPermissionClass();
321
322
        if (is_numeric($permissions)) {
323
            return $permissionClass->findById($permissions, $this->getDefaultGuardName());
324
        }
325
326
        if (is_string($permissions)) {
327
            return $permissionClass->findByName($permissions, $this->getDefaultGuardName());
328
        }
329
330
        if (is_array($permissions)) {
331
            return $permissionClass
332
                ->whereIn('name', $permissions)
333
                ->whereIn('guard_name', $this->getGuardNames())
334
                ->get();
335
        }
336
337
        return $permissions;
338
    }
339
340
    /**
341
     * @param \Spatie\Permission\Contracts\Permission|\Spatie\Permission\Contracts\Role $roleOrPermission
342
     *
343
     * @throws \Spatie\Permission\Exceptions\GuardDoesNotMatch
344
     */
345
    protected function ensureModelSharesGuard($roleOrPermission)
346
    {
347
        if (! $this->getGuardNames()->contains($roleOrPermission->guard_name)) {
348
            throw GuardDoesNotMatch::create($roleOrPermission->guard_name, $this->getGuardNames());
349
        }
350
    }
351
352
    protected function getGuardNames(): Collection
353
    {
354
        return Guard::getNames($this);
355
    }
356
357
    protected function getDefaultGuardName(): string
358
    {
359
        return Guard::getDefaultName($this);
360
    }
361
362
    /**
363
     * Forget the cached permissions.
364
     */
365
    public function forgetCachedPermissions()
366
    {
367
        app(PermissionRegistrar::class)->forgetCachedPermissions();
368
    }
369
}
370