01: /**
02: * Copyright (c) 2000-2008 Liferay, Inc. All rights reserved.
03: *
04: * Permission is hereby granted, free of charge, to any person obtaining a copy
05: * of this software and associated documentation files (the "Software"), to deal
06: * in the Software without restriction, including without limitation the rights
07: * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
08: * copies of the Software, and to permit persons to whom the Software is
09: * furnished to do so, subject to the following conditions:
10: *
11: * The above copyright notice and this permission notice shall be included in
12: * all copies or substantial portions of the Software.
13: *
14: * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
15: * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16: * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
17: * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
18: * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
19: * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
20: * SOFTWARE.
21: */package com.liferay.portal.service.permission;
22:
23: import com.liferay.portal.PortalException;
24: import com.liferay.portal.SystemException;
25: import com.liferay.portal.kernel.security.permission.ActionKeys;
26: import com.liferay.portal.kernel.security.permission.PermissionChecker;
27: import com.liferay.portal.model.Group;
28: import com.liferay.portal.model.Organization;
29: import com.liferay.portal.security.auth.PrincipalException;
30: import com.liferay.portal.service.GroupLocalServiceUtil;
31: import com.liferay.portal.service.OrganizationLocalServiceUtil;
32:
33: import java.util.List;
34:
35: /**
36: * <a href="GroupPermissionImpl.java.html"><b><i>View Source</i></b></a>
37: *
38: * @author Brian Wing Shun Chan
39: *
40: */
41: public class GroupPermissionImpl implements GroupPermission {
42:
43: public void check(PermissionChecker permissionChecker,
44: long groupId, String actionId) throws PortalException,
45: SystemException {
46:
47: if (!contains(permissionChecker, groupId, actionId)) {
48: throw new PrincipalException();
49: }
50: }
51:
52: public boolean contains(PermissionChecker permissionChecker,
53: long groupId, String actionId) throws PortalException,
54: SystemException {
55:
56: if (actionId.equals(ActionKeys.MANAGE_LAYOUTS)) {
57: Group group = GroupLocalServiceUtil.getGroup(groupId);
58:
59: if (group.isOrganization()) {
60: long organizationId = group.getClassPK();
61:
62: return OrganizationPermissionUtil.contains(
63: permissionChecker, organizationId, actionId);
64: } else if (group.isUser()) {
65:
66: // An individual user would never reach this block because he
67: // would be an administrator of his own layouts. However, a user
68: // who manages a set of organizations may be modifying pages of
69: // a user he manages.
70:
71: long userId = group.getClassPK();
72:
73: List organizations = OrganizationLocalServiceUtil
74: .getUserOrganizations(userId);
75:
76: for (int i = 0; i < organizations.size(); i++) {
77: Organization organization = (Organization) organizations
78: .get(i);
79:
80: if (OrganizationPermissionUtil.contains(
81: permissionChecker, organization
82: .getOrganizationId(),
83: ActionKeys.MANAGE_USERS)) {
84:
85: return true;
86: }
87: }
88: }
89: }
90:
91: // Group id must be set so that users can modify their personal pages
92:
93: return permissionChecker.hasPermission(groupId, Group.class
94: .getName(), groupId, actionId);
95: }
96:
97: }
|