| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | <?php | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-05-18 00:56:55 +08:00
										 |  |  | namespace BookStack\Users\Controllers; | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-25 23:58:03 +08:00
										 |  |  | use BookStack\Exceptions\PermissionsException; | 
					
						
							| 
									
										
										
										
											2023-05-19 03:53:39 +08:00
										 |  |  | use BookStack\Http\Controller; | 
					
						
							| 
									
										
										
										
											2023-05-18 00:56:55 +08:00
										 |  |  | use BookStack\Permissions\PermissionsRepo; | 
					
						
							|  |  |  | use BookStack\Users\Models\Role; | 
					
						
							|  |  |  | use BookStack\Users\Queries\RolesAllPaginatedAndSorted; | 
					
						
							| 
									
										
										
										
											2022-10-30 23:16:06 +08:00
										 |  |  | use BookStack\Util\SimpleListOptions; | 
					
						
							| 
									
										
										
										
											2020-08-04 21:55:01 +08:00
										 |  |  | use Exception; | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  | use Illuminate\Http\Request; | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-11-21 02:53:01 +08:00
										 |  |  | class RoleController extends Controller | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  | { | 
					
						
							| 
									
										
										
										
											2023-07-26 00:59:04 +08:00
										 |  |  |     public function __construct( | 
					
						
							|  |  |  |         protected PermissionsRepo $permissionsRepo | 
					
						
							|  |  |  |     ) { | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Show a listing of the roles in the system. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2022-10-30 03:52:17 +08:00
										 |  |  |     public function index(Request $request) | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         $this->checkPermission('user-roles-manage'); | 
					
						
							| 
									
										
										
										
											2022-10-30 03:52:17 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-30 23:16:06 +08:00
										 |  |  |         $listOptions = SimpleListOptions::fromRequest($request, 'roles')->withSortOptions([ | 
					
						
							|  |  |  |             'display_name' => trans('common.sort_name'), | 
					
						
							|  |  |  |             'users_count' => trans('settings.roles_assigned_users'), | 
					
						
							|  |  |  |             'permissions_count' => trans('settings.roles_permissions_provided'), | 
					
						
							|  |  |  |             'created_at' => trans('common.sort_created_at'), | 
					
						
							|  |  |  |             'updated_at' => trans('common.sort_updated_at'), | 
					
						
							|  |  |  |         ]); | 
					
						
							| 
									
										
										
										
											2022-10-30 03:52:17 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-30 23:16:06 +08:00
										 |  |  |         $roles = (new RolesAllPaginatedAndSorted())->run(20, $listOptions); | 
					
						
							|  |  |  |         $roles->appends($listOptions->getPaginationAppends()); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-04 21:33:24 +08:00
										 |  |  |         $this->setPageTitle(trans('settings.roles')); | 
					
						
							| 
									
										
										
										
											2022-01-06 20:18:11 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-30 03:52:17 +08:00
										 |  |  |         return view('settings.roles.index', [ | 
					
						
							|  |  |  |             'roles'       => $roles, | 
					
						
							| 
									
										
										
										
											2022-10-30 23:16:06 +08:00
										 |  |  |             'listOptions' => $listOptions, | 
					
						
							| 
									
										
										
										
											2022-10-30 03:52:17 +08:00
										 |  |  |         ]); | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     /** | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  |      * Show the form to create a new role. | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |      */ | 
					
						
							| 
									
										
										
										
											2021-12-19 20:27:14 +08:00
										 |  |  |     public function create(Request $request) | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         $this->checkPermission('user-roles-manage'); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-12-19 20:27:14 +08:00
										 |  |  |         /** @var ?Role $role */ | 
					
						
							|  |  |  |         $role = null; | 
					
						
							|  |  |  |         if ($request->has('copy_from')) { | 
					
						
							|  |  |  |             $role = Role::query()->find($request->get('copy_from')); | 
					
						
							|  |  |  |         } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         if ($role) { | 
					
						
							|  |  |  |             $role->display_name .= ' (' . trans('common.copy') . ')'; | 
					
						
							|  |  |  |         } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-04 21:33:24 +08:00
										 |  |  |         $this->setPageTitle(trans('settings.role_create')); | 
					
						
							| 
									
										
										
										
											2022-01-06 20:18:11 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-12-19 20:27:14 +08:00
										 |  |  |         return view('settings.roles.create', ['role' => $role]); | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Store a new role in the system. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-21 02:53:01 +08:00
										 |  |  |     public function store(Request $request) | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         $this->checkPermission('user-roles-manage'); | 
					
						
							| 
									
										
										
										
											2023-02-19 02:36:34 +08:00
										 |  |  |         $data = $this->validate($request, [ | 
					
						
							| 
									
										
										
										
											2021-11-05 08:26:55 +08:00
										 |  |  |             'display_name' => ['required', 'min:3', 'max:180'], | 
					
						
							| 
									
										
										
										
											2021-12-19 20:27:14 +08:00
										 |  |  |             'description'  => ['max:180'], | 
					
						
							| 
									
										
										
										
											2024-06-09 03:33:34 +08:00
										 |  |  |             'external_auth_id' => ['string', 'max:180'], | 
					
						
							| 
									
										
										
										
											2023-02-19 02:36:34 +08:00
										 |  |  |             'permissions'  => ['array'], | 
					
						
							|  |  |  |             'mfa_enforced' => ['string'], | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         ]); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-02-19 02:36:34 +08:00
										 |  |  |         $data['permissions'] = array_keys($data['permissions'] ?? []); | 
					
						
							|  |  |  |         $data['mfa_enforced'] = ($data['mfa_enforced'] ?? 'false') === 'true'; | 
					
						
							|  |  |  |         $this->permissionsRepo->saveNewRole($data); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         return redirect('/settings/roles'); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Show the form for editing a user role. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-21 02:53:01 +08:00
										 |  |  |     public function edit(string $id) | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         $this->checkPermission('user-roles-manage'); | 
					
						
							| 
									
										
										
										
											2016-03-03 06:35:01 +08:00
										 |  |  |         $role = $this->permissionsRepo->getRoleById($id); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-04 21:33:24 +08:00
										 |  |  |         $this->setPageTitle(trans('settings.role_edit')); | 
					
						
							| 
									
										
										
										
											2022-01-06 20:18:11 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-02-04 01:34:15 +08:00
										 |  |  |         return view('settings.roles.edit', ['role' => $role]); | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  |     } | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Updates a user role. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-21 02:53:01 +08:00
										 |  |  |     public function update(Request $request, string $id) | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         $this->checkPermission('user-roles-manage'); | 
					
						
							| 
									
										
										
										
											2023-02-19 02:36:34 +08:00
										 |  |  |         $data = $this->validate($request, [ | 
					
						
							| 
									
										
										
										
											2021-11-05 08:26:55 +08:00
										 |  |  |             'display_name' => ['required', 'min:3', 'max:180'], | 
					
						
							| 
									
										
										
										
											2021-12-19 20:27:14 +08:00
										 |  |  |             'description'  => ['max:180'], | 
					
						
							| 
									
										
										
										
											2024-06-09 03:33:34 +08:00
										 |  |  |             'external_auth_id' => ['string', 'max:180'], | 
					
						
							| 
									
										
										
										
											2023-02-19 02:36:34 +08:00
										 |  |  |             'permissions'  => ['array'], | 
					
						
							|  |  |  |             'mfa_enforced' => ['string'], | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         ]); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-02-20 00:03:50 +08:00
										 |  |  |         $data['permissions'] = array_keys($data['permissions'] ?? []); | 
					
						
							|  |  |  |         $data['mfa_enforced'] = ($data['mfa_enforced'] ?? 'false') === 'true'; | 
					
						
							| 
									
										
										
										
											2023-02-19 02:36:34 +08:00
										 |  |  |         $this->permissionsRepo->updateRole($id, $data); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         return redirect('/settings/roles'); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Show the view to delete a role. | 
					
						
							|  |  |  |      * Offers the chance to migrate users. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-21 02:53:01 +08:00
										 |  |  |     public function showDelete(string $id) | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         $this->checkPermission('user-roles-manage'); | 
					
						
							| 
									
										
										
										
											2016-03-03 06:35:01 +08:00
										 |  |  |         $role = $this->permissionsRepo->getRoleById($id); | 
					
						
							|  |  |  |         $roles = $this->permissionsRepo->getAllRolesExcept($role); | 
					
						
							| 
									
										
										
										
											2016-12-05 00:51:39 +08:00
										 |  |  |         $blankRole = $role->newInstance(['display_name' => trans('settings.role_delete_no_migration')]); | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         $roles->prepend($blankRole); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-01-04 21:33:24 +08:00
										 |  |  |         $this->setPageTitle(trans('settings.role_delete')); | 
					
						
							| 
									
										
										
										
											2022-01-06 20:18:11 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-02-04 01:34:15 +08:00
										 |  |  |         return view('settings.roles.delete', ['role' => $role, 'roles' => $roles]); | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Delete a role from the system, | 
					
						
							|  |  |  |      * Migrate from a previous role if set. | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  |      * | 
					
						
							| 
									
										
										
										
											2020-08-04 21:55:01 +08:00
										 |  |  |      * @throws Exception | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-21 02:53:01 +08:00
										 |  |  |     public function delete(Request $request, string $id) | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         $this->checkPermission('user-roles-manage'); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-03-03 06:35:01 +08:00
										 |  |  |         try { | 
					
						
							| 
									
										
										
										
											2023-03-25 20:07:59 +08:00
										 |  |  |             $migrateRoleId = intval($request->get('migrate_role_id') ?: "0"); | 
					
						
							|  |  |  |             $this->permissionsRepo->deleteRole($id, $migrateRoleId); | 
					
						
							| 
									
										
										
										
											2016-03-03 06:35:01 +08:00
										 |  |  |         } catch (PermissionsException $e) { | 
					
						
							| 
									
										
										
										
											2019-10-05 19:55:01 +08:00
										 |  |  |             $this->showErrorNotification($e->getMessage()); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-12-10 20:37:21 +08:00
										 |  |  |             return redirect("/settings/roles/delete/{$id}"); | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |         } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |         return redirect('/settings/roles'); | 
					
						
							|  |  |  |     } | 
					
						
							| 
									
										
										
										
											2016-02-27 07:44:02 +08:00
										 |  |  | } |