Files
NodeBB/src/privileges/categories.js

422 lines
12 KiB
JavaScript
Raw Normal View History

'use strict';
var async = require('async');
var _ = require('underscore');
var helpers = require('./helpers');
module.exports = function(privileges) {
privileges.categories = {};
privileges.categories.list = function(cid, callback) {
2015-09-15 19:21:24 -04:00
// Method used in admin/category controller to show all users/groups with privs in that given cid
2016-08-27 01:52:08 +03:00
var plugins = require('../plugins');
var groups = require('../groups');
var user = require('../user');
2015-09-15 19:21:24 -04:00
var privilegeLabels = [
{name: 'Find Category'},
{name: 'Access Category'},
{name: 'Access Topics'},
2015-09-15 19:21:24 -04:00
{name: 'Create Topics'},
{name: 'Reply to Topics'},
{name: 'Edit Posts'},
{name: 'Delete Posts'},
{name: 'Delete Topics'},
2016-07-12 19:58:59 +03:00
{name: 'Upload Images'},
{name: 'Upload Files'},
2015-09-16 08:35:40 -04:00
{name: 'Purge'},
2015-09-15 19:21:24 -04:00
{name: 'Moderate'}
];
async.parallel({
labels: function(next) {
async.parallel({
2015-09-15 19:21:24 -04:00
users: async.apply(plugins.fireHook, 'filter:privileges.list_human', privilegeLabels),
groups: async.apply(plugins.fireHook, 'filter:privileges.groups.list_human', privilegeLabels)
}, next);
},
users: function(next) {
2016-06-08 11:52:55 +03:00
var userPrivileges;
async.waterfall([
async.apply(plugins.fireHook, 'filter:privileges.list', privileges.userPrivilegeList),
2016-06-08 11:44:15 +03:00
function(_privs, next) {
2016-06-08 11:52:55 +03:00
userPrivileges = _privs;
groups.getMembersOfGroups(userPrivileges.map(function(privilege) {
return 'cid:' + cid + ':privileges:' + privilege;
2015-09-15 19:21:24 -04:00
}), next);
},
function(memberSets, next) {
2015-09-15 19:21:24 -04:00
memberSets = memberSets.map(function(set) {
return set.map(function(uid) {
return parseInt(uid, 10);
});
2015-09-15 19:21:24 -04:00
});
var members = _.unique(_.flatten(memberSets));
2015-09-25 17:38:58 -04:00
user.getUsersFields(members, ['picture', 'username'], function(err, memberData) {
2015-09-15 19:21:24 -04:00
if (err) {
return next(err);
}
memberData.forEach(function(member) {
member.privileges = {};
2016-06-08 11:52:55 +03:00
for(var x=0,numPrivs=userPrivileges.length;x<numPrivs;x++) {
member.privileges[userPrivileges[x]] = memberSets[x].indexOf(parseInt(member.uid, 10)) !== -1;
}
});
next(null, memberData);
});
}
], next);
},
groups: function(next) {
2016-06-08 11:52:55 +03:00
var groupPrivileges;
async.waterfall([
async.apply(plugins.fireHook, 'filter:privileges.groups.list', privileges.groupPrivilegeList),
2016-06-08 11:44:15 +03:00
function(_privs, next) {
2016-06-08 11:52:55 +03:00
groupPrivileges = _privs;
groups.getMembersOfGroups(groupPrivileges.map(function(privilege) {
return 'cid:' + cid + ':privileges:' + privilege;
}), next);
},
function(memberSets, next) {
2015-09-15 19:21:24 -04:00
var uniqueGroups = _.unique(_.flatten(memberSets));
2015-08-06 16:25:36 -04:00
groups.getGroups('groups:createtime', 0, -1, function(err, groupNames) {
if (err) {
return next(err);
}
2015-09-15 19:21:24 -04:00
groupNames = groupNames.filter(function(groupName) {
return groupName.indexOf(':privileges:') === -1 && uniqueGroups.indexOf(groupName) !== -1;
});
groupNames = groups.getEphemeralGroups().concat(groupNames);
2015-10-26 22:28:30 -04:00
var registeredUsersIndex = groupNames.indexOf('registered-users');
if (registeredUsersIndex !== -1) {
groupNames.splice(0, 0, groupNames.splice(registeredUsersIndex, 1)[0]);
} else {
groupNames = ['registered-users'].concat(groupNames);
}
2015-09-15 19:21:24 -04:00
var adminIndex = groupNames.indexOf('administrators');
if (adminIndex !== -1) {
groupNames.splice(adminIndex, 1);
}
var memberPrivs;
var memberData = groupNames.map(function(member) {
memberPrivs = {};
2016-06-08 11:52:55 +03:00
for(var x=0,numPrivs=groupPrivileges.length;x<numPrivs;x++) {
memberPrivs[groupPrivileges[x]] = memberSets[x].indexOf(member) !== -1;
}
2015-09-15 19:21:24 -04:00
return {
name: member,
privileges: memberPrivs,
};
});
next(null, memberData);
});
},
function(memberData, next) {
// Grab privacy info for the groups as well
async.map(memberData, function(member, next) {
groups.isPrivate(member.name, function(err, isPrivate) {
if (err) {
return next(err);
}
member.isPrivate = isPrivate;
next(null, member);
});
}, next);
}
], next);
}
}, function(err, payload) {
if (err) {
return callback(err);
}
// This is a hack because I can't do {labels.users.length} to echo the count in templates.js
payload.columnCount = payload.labels.users.length + 2;
callback(null, payload);
});
};
2014-05-15 20:49:47 -04:00
privileges.categories.get = function(cid, uid, callback) {
2016-08-27 01:52:08 +03:00
var user = require('../user');
2014-05-15 20:49:47 -04:00
async.parallel({
'topics:create': function(next) {
helpers.isUserAllowedTo('topics:create', uid, [cid], next);
2014-05-15 20:49:47 -04:00
},
'topics:read': function(next) {
helpers.isUserAllowedTo('topics:read', uid, [cid], next);
},
2014-05-15 20:49:47 -04:00
read: function(next) {
helpers.isUserAllowedTo('read', uid, [cid], next);
2014-05-15 20:49:47 -04:00
},
isAdministrator: function(next) {
user.isAdministrator(uid, next);
},
isModerator: function(next) {
user.isModerator(uid, cid, next);
}
}, function(err, results) {
2014-10-19 17:11:05 -04:00
if (err) {
2014-05-15 20:49:47 -04:00
return callback(err);
}
2014-10-19 17:11:05 -04:00
var isAdminOrMod = results.isAdministrator || results.isModerator;
2016-08-27 01:52:08 +03:00
var plugins = require('../plugins');
plugins.fireHook('filter:privileges.categories.get', {
cid: cid,
uid: uid,
'topics:create': results['topics:create'][0] || isAdminOrMod,
'topics:read': results['topics:read'][0] || isAdminOrMod,
2014-10-19 17:11:05 -04:00
editable: isAdminOrMod,
view_deleted: isAdminOrMod,
2015-10-20 19:07:24 -04:00
read: results.read[0] || isAdminOrMod,
isAdminOrMod: isAdminOrMod
}, callback);
2014-05-15 20:49:47 -04:00
});
};
2015-09-15 18:21:17 -04:00
privileges.categories.isAdminOrMod = function(cid, uid, callback) {
if (!parseInt(uid, 10)) {
return callback(null, false);
}
2016-08-27 01:52:08 +03:00
var user = require('../user');
2015-09-15 18:21:17 -04:00
helpers.some([
function (next) {
user.isModerator(uid, cid, next);
},
function (next) {
user.isAdministrator(uid, next);
}
], callback);
};
2015-09-16 08:35:40 -04:00
privileges.categories.isUserAllowedTo = function(privilege, cid, uid, callback) {
if (!cid) {
return callback(null, false);
}
helpers.isUserAllowedTo(privilege, uid, [cid], function(err, results) {
callback(err, Array.isArray(results) && results.length ? results[0] : false);
});
};
privileges.categories.can = function(privilege, cid, uid, callback) {
2015-02-24 13:02:58 -05:00
if (!cid) {
return callback(null, false);
}
2016-08-26 19:13:05 +03:00
var categories = require('../categories');
2016-08-27 01:52:08 +03:00
var user = require('../user');
categories.getCategoryField(cid, 'disabled', function(err, disabled) {
if (err) {
return callback(err);
}
if (parseInt(disabled, 10) === 1) {
return callback(null, false);
}
helpers.some([
function(next) {
helpers.isUserAllowedTo(privilege, uid, [cid], function(err, results) {
next(err, Array.isArray(results) && results.length ? results[0] : false);
});
},
function(next) {
user.isModerator(uid, cid, next);
},
function(next) {
user.isAdministrator(uid, next);
}
], callback);
});
};
privileges.categories.filterCids = function(privilege, cids, uid, callback) {
2014-11-09 00:33:26 -05:00
if (!Array.isArray(cids) || !cids.length) {
return callback(null, []);
}
cids = cids.filter(function(cid, index, array) {
return array.indexOf(cid) === index;
});
2016-04-29 20:35:49 +03:00
privileges.categories.getBase(privilege, cids, uid, function(err, results) {
if (err) {
return callback(err);
}
cids = cids.filter(function(cid, index) {
return !results.categories[index].disabled &&
(results.allowedTo[index] || results.isAdmin || results.isModerators[index]);
});
callback(null, cids.filter(Boolean));
});
};
privileges.categories.getBase = function(privilege, cids, uid, callback) {
2016-08-26 19:13:05 +03:00
var categories = require('../categories');
2016-08-27 01:52:08 +03:00
var user = require('../user');
async.parallel({
2015-02-25 14:17:30 -05:00
categories: function(next) {
2015-09-25 17:38:58 -04:00
categories.getCategoriesFields(cids, ['disabled'], next);
2015-02-25 14:17:30 -05:00
},
allowedTo: function(next) {
helpers.isUserAllowedTo(privilege, uid, cids, next);
},
isModerators: function(next) {
user.isModerator(uid, cids, next);
},
isAdmin: function(next) {
user.isAdministrator(uid, next);
}
2016-04-29 20:35:49 +03:00
}, callback);
};
privileges.categories.filterUids = function(privilege, cid, uids, callback) {
if (!uids.length) {
return callback(null, []);
}
uids = uids.filter(function(uid, index, array) {
return array.indexOf(uid) === index;
});
2016-08-27 01:52:08 +03:00
var user = require('../user');
async.parallel({
allowedTo: function(next) {
helpers.isUsersAllowedTo(privilege, uids, cid, next);
},
isModerators: function(next) {
user.isModerator(uids, cid, next);
},
isAdmin: function(next) {
user.isAdministrator(uids, next);
}
}, function(err, results) {
if (err) {
return callback(err);
}
uids = uids.filter(function(uid, index) {
return results.allowedTo[index] || results.isModerators[index] || results.isAdmin[index];
});
callback(null, uids);
});
};
privileges.categories.give = function(privileges, cid, groupName, callback) {
2016-08-27 01:52:08 +03:00
var groups = require('../groups');
2015-09-27 15:21:23 -04:00
giveOrRescind(groups.join, privileges, cid, groupName, callback);
};
2015-01-16 17:03:05 -05:00
privileges.categories.rescind = function(privileges, cid, groupName, callback) {
2016-08-27 01:52:08 +03:00
var groups = require('../groups');
2015-09-27 15:21:23 -04:00
giveOrRescind(groups.leave, privileges, cid, groupName, callback);
2015-09-27 15:02:04 -04:00
};
function giveOrRescind(method, privileges, cid, groupName, callback) {
2015-01-16 17:03:05 -05:00
async.each(privileges, function(privilege, next) {
2015-09-27 15:02:04 -04:00
method('cid:' + cid + ':privileges:groups:' + privilege, groupName, next);
2015-01-16 17:03:05 -05:00
}, callback);
2015-09-27 15:02:04 -04:00
}
2015-01-16 17:03:05 -05:00
2014-05-15 20:49:47 -04:00
privileges.categories.canMoveAllTopics = function(currentCid, targetCid, uid, callback) {
2016-08-27 01:52:08 +03:00
var user = require('../user');
2014-05-15 20:49:47 -04:00
async.parallel({
isAdministrator: function(next) {
user.isAdministrator(uid, next);
},
moderatorOfCurrent: function(next) {
user.isModerator(uid, currentCid, next);
},
moderatorOfTarget: function(next) {
user.isModerator(uid, targetCid, next);
}
}, function(err, results) {
if (err) {
return callback(err);
}
callback(null, results.isAdministrator || (results.moderatorOfCurrent && results.moderatorOfTarget));
});
};
privileges.categories.userPrivileges = function(cid, uid, callback) {
2016-08-27 01:52:08 +03:00
var user = require('../user');
var groups = require('../groups');
2014-05-15 20:49:47 -04:00
async.parallel({
find: async.apply(groups.isMember, uid, 'cid:' + cid + ':privileges:find'),
2014-05-15 20:49:47 -04:00
read: function(next) {
groups.isMember(uid, 'cid:' + cid + ':privileges:read', next);
2014-05-15 20:49:47 -04:00
},
'topics:create': function(next) {
groups.isMember(uid, 'cid:' + cid + ':privileges:topics:create', next);
2014-05-15 20:49:47 -04:00
},
'topics:read': function(next) {
groups.isMember(uid, 'cid:' + cid + ':privileges:topics:read', next);
},
2014-05-15 20:49:47 -04:00
'topics:reply': function(next) {
groups.isMember(uid, 'cid:' + cid + ':privileges:topics:reply', next);
2014-05-15 20:49:47 -04:00
},
2016-08-09 09:50:49 -05:00
'posts:edit': function(next) {
groups.isMember(uid, 'cid:' + cid + ':privileges:posts:edit', next);
},
2016-08-09 09:50:49 -05:00
'posts:delete': function(next) {
groups.isMember(uid, 'cid:' + cid + ':privileges:posts:delete', next);
},
'topics:delete': function(next) {
groups.isMember(uid, 'cid:' + cid + ':privileges:topics:delete', next);
},
2014-05-15 20:49:47 -04:00
mods: function(next) {
user.isModerator(uid, cid, next);
}
}, callback);
};
privileges.categories.groupPrivileges = function(cid, groupName, callback) {
2016-08-27 01:52:08 +03:00
var groups = require('../groups');
2014-05-15 20:49:47 -04:00
async.parallel({
'groups:find': async.apply(groups.isMember, groupName, 'cid:' + cid + ':privileges:groups:find'),
2014-05-15 20:49:47 -04:00
'groups:read': function(next) {
groups.isMember(groupName, 'cid:' + cid + ':privileges:groups:read', next);
2014-05-15 20:49:47 -04:00
},
'groups:topics:create': function(next) {
groups.isMember(groupName, 'cid:' + cid + ':privileges:groups:topics:create', next);
2014-05-15 20:49:47 -04:00
},
'groups:topics:reply': function(next) {
groups.isMember(groupName, 'cid:' + cid + ':privileges:groups:topics:reply', next);
},
2016-08-09 09:50:49 -05:00
'groups:posts:edit': function(next) {
groups.isMember(groupName, 'cid:' + cid + ':privileges:groups:posts:edit', next);
},
2016-08-09 09:50:49 -05:00
'groups:posts:delete': function(next) {
groups.isMember(groupName, 'cid:' + cid + ':privileges:groups:posts:delete', next);
},
'groups:topics:delete': function(next) {
groups.isMember(groupName, 'cid:' + cid + ':privileges:groups:topics:delete', next);
},
'groups:topics:read': function(next) {
groups.isMember(groupName, 'cid:' + cid + ':privileges:groups:topics:read', next);
2014-05-15 20:49:47 -04:00
}
}, callback);
};
};