BookStack/app/Http/Controllers/Controller.php

116 lines
3.2 KiB
PHP
Raw Normal View History

2015-07-12 21:01:42 +02:00
<?php
namespace BookStack\Http\Controllers;
2015-07-12 21:01:42 +02:00
use BookStack\Ownable;
2015-08-29 16:03:42 +02:00
use HttpRequestException;
2015-07-12 21:01:42 +02:00
use Illuminate\Foundation\Bus\DispatchesJobs;
2015-08-29 16:03:42 +02:00
use Illuminate\Http\Exception\HttpResponseException;
2015-07-12 21:01:42 +02:00
use Illuminate\Routing\Controller as BaseController;
use Illuminate\Foundation\Validation\ValidatesRequests;
2015-08-24 22:10:04 +02:00
use Illuminate\Support\Facades\Auth;
2015-08-29 16:03:42 +02:00
use Illuminate\Support\Facades\Session;
use BookStack\User;
2015-07-12 21:01:42 +02:00
abstract class Controller extends BaseController
{
use DispatchesJobs, ValidatesRequests;
2015-08-24 22:10:04 +02:00
2015-08-29 16:03:42 +02:00
/**
* @var User static
*/
protected $currentUser;
/**
* @var bool
*/
protected $signedIn;
2015-08-24 22:10:04 +02:00
/**
* Controller constructor.
*/
public function __construct()
{
2015-08-29 16:03:42 +02:00
// Get a user instance for the current user
$user = auth()->user();
2015-09-05 18:42:05 +02:00
if (!$user) $user = User::getDefault();
2015-08-29 16:03:42 +02:00
// Share variables with views
view()->share('signedIn', auth()->check());
2015-08-29 16:03:42 +02:00
view()->share('currentUser', $user);
2015-09-05 18:42:05 +02:00
2015-08-29 16:03:42 +02:00
// Share variables with controllers
$this->currentUser = $user;
$this->signedIn = auth()->check();
2015-08-29 16:03:42 +02:00
}
/**
* Stops the application and shows a permission error if
* the application is in demo mode.
*/
protected function preventAccessForDemoUsers()
{
if (config('app.env') === 'demo') $this->showPermissionError();
}
/**
* Adds the page title into the view.
* @param $title
*/
public function setPageTitle($title)
{
view()->share('pageTitle', $title);
}
/**
* On a permission error redirect to home and display.
* the error as a notification.
*/
protected function showPermissionError()
{
Session::flash('error', trans('errors.permission'));
$response = request()->wantsJson() ? response()->json(['error' => trans('errors.permissionJson')], 403) : redirect('/', 403);
throw new HttpResponseException($response);
}
2015-08-29 16:03:42 +02:00
/**
* Checks for a permission.
* @param string $permissionName
2015-08-29 16:03:42 +02:00
* @return bool|\Illuminate\Http\RedirectResponse
*/
protected function checkPermission($permissionName)
{
if (!$this->currentUser || !$this->currentUser->can($permissionName)) {
$this->showPermissionError();
2015-08-29 16:03:42 +02:00
}
return true;
}
/**
* Check the current user's permissions against an ownable item.
* @param $permission
* @param Ownable $ownable
* @return bool
*/
protected function checkOwnablePermission($permission, Ownable $ownable)
{
$permissionBaseName = strtolower($permission) . '-';
if (userCan($permissionBaseName . 'all')) return true;
if (userCan($permissionBaseName . 'own') && $ownable->createdBy->id === $this->currentUser->id) return true;
$this->showPermissionError();
}
/**
* Check if a user has a permission or bypass if the callback is true.
* @param $permissionName
* @param $callback
* @return bool
*/
2015-08-29 16:03:42 +02:00
protected function checkPermissionOr($permissionName, $callback)
{
$callbackResult = $callback();
if ($callbackResult === false) $this->checkPermission($permissionName);
return true;
2015-08-24 22:10:04 +02:00
}
2015-07-12 21:01:42 +02:00
}