modules.permission_ids is NULL for module 8 ("Szerviz kategoriak") on every
environment, and PHP 8.1 deprecates passing null to explode(). The notice was
only visible on prod because its index.php still has the stock
error_reporting(-1), whereas dev was previously changed to
E_ALL & ~E_DEPRECATED & ~E_WARNING & ~E_NOTICE.
- Skip rows whose permission_ids is null or empty. Behaviour-preserving:
explode(',', null) returned array(''), which matched no permission id, so
such modules were already excluded. Verified by simulating old vs new
against the real module rows across six permission-id values including 0,
'1' and 'admin' - identical results.
- Return early when the slug matches no permission, rather than dereferencing
null on the next line.
Does not address the wider issue that prod runs ENVIRONMENT='development'
with display_errors=1, so any notice is rendered to real visitors.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
272 lines
6.8 KiB
PHP
Executable File
272 lines
6.8 KiB
PHP
Executable File
<?php
|
|
class Module_model extends CI_Model {
|
|
|
|
function __construct(){
|
|
parent::__construct();
|
|
}
|
|
|
|
public function getAllModule(){
|
|
$this->load->database();
|
|
$query = $this->db->query('SELECT * FROM modules ORDER BY module_name ASC');
|
|
return $query->result();
|
|
}
|
|
|
|
public function getModuleById($module_id){
|
|
$this->load->database();
|
|
$query = $this->db->query('SELECT * FROM modules WHERE module_id = ? LIMIT 1', array($module_id));
|
|
return $query->result()[0];
|
|
}
|
|
|
|
public function getModuleBySlug($module_slug){
|
|
$this->load->database();
|
|
$query = $this->db->query('SELECT * FROM modules WHERE module_slug = ? LIMIT 1', array($module_slug));
|
|
return $query->result()[0];
|
|
}
|
|
|
|
public function getUserModules($userId){
|
|
$this->load->database();
|
|
$this->load->model('User_model');
|
|
|
|
$currentUser = $this->User_model->getUserById($userId);
|
|
|
|
$query = $this->db->query('SELECT * FROM modules');
|
|
$all_module = $query->result();
|
|
$activeModules = array();
|
|
$activeModuleIds = array();
|
|
|
|
foreach($all_module as $moduleItem){
|
|
|
|
//check groupmodules
|
|
$moduleGroupIds = unserialize($moduleItem->permission_group_ids);
|
|
$moduleUserIds = unserialize($moduleItem->permission_ids);
|
|
|
|
if(!empty($moduleItem->permission_ids)){
|
|
}
|
|
|
|
//check group ids
|
|
if(is_array($moduleGroupIds)){
|
|
if(in_array($currentUser->permission_id, $moduleGroupIds)){
|
|
if(!in_array($moduleItem->module_id, $activeModuleIds)){
|
|
|
|
$activeModules[] = $moduleItem;
|
|
$activeModuleIds[] = $moduleItem->module_id;
|
|
|
|
|
|
}
|
|
|
|
}
|
|
}
|
|
|
|
//check user_ids
|
|
|
|
if(is_array($moduleUserIds)){
|
|
if(in_array($currentUser->user_id, $moduleUserIds)){
|
|
|
|
if(!in_array($moduleItem->module_id, $activeModuleIds)){
|
|
$activeModules[] = $moduleItem;
|
|
$activeModuleIds[] = $moduleItem->module_id;
|
|
}
|
|
|
|
}
|
|
}
|
|
}
|
|
return $activeModules;
|
|
}
|
|
|
|
|
|
public function is_module_available($module_id, $userId){
|
|
$this->load->database();
|
|
$this->load->model('User_model');
|
|
|
|
$currentModule = $this->getModuleById($module_id);
|
|
$currentUser = $this->User_model->getUserById($userId);
|
|
$moduleGroupIds = unserialize($currentModule->permission_group_ids);
|
|
$moduleUserIds = unserialize($currentModule->permission_ids);
|
|
$moduleIsOk = 0;
|
|
|
|
//if($currentUser->permission_slug == 'admin' && $module_id != '5'){
|
|
if($currentUser->permission_slug == 'admin'){
|
|
$moduleIsOk = 1;
|
|
}
|
|
|
|
//check groupmodules
|
|
if(is_array($moduleGroupIds)){
|
|
if(in_array($currentUser->permission_id, $moduleGroupIds)){
|
|
$moduleIsOk = 1;
|
|
}
|
|
}
|
|
|
|
//check user_ids
|
|
if(is_array($moduleUserIds)){
|
|
if(in_array($currentUser->user_id, $moduleUserIds)){
|
|
$moduleIsOk = 1;
|
|
}
|
|
}
|
|
|
|
if($moduleIsOk){
|
|
return 1;
|
|
}
|
|
else{
|
|
return 0;
|
|
}
|
|
|
|
}
|
|
|
|
public function is_userId_available_in_module($module_id, $userId){
|
|
$this->load->database();
|
|
$this->load->model('User_model');
|
|
|
|
$currentModule = $this->getModuleById($module_id);
|
|
$userIds = unserialize($currentModule->permission_ids);
|
|
|
|
|
|
if(is_array($userIds)){
|
|
if(in_array($userId, $userIds)){
|
|
return 1;
|
|
}
|
|
}
|
|
}
|
|
|
|
public function is_groupId_available_in_module($module_id, $groupId){
|
|
$this->load->database();
|
|
$this->load->model('User_model');
|
|
|
|
$currentModule = $this->getModuleById($module_id);
|
|
$moduleGroupIds = unserialize($currentModule->permission_group_ids);
|
|
|
|
if(is_array($moduleGroupIds)){
|
|
if(in_array($groupId, $moduleGroupIds)){
|
|
return 1;
|
|
}
|
|
}
|
|
}
|
|
|
|
|
|
public function updateModule($fieldName, $module_id, $moduleUserArray){
|
|
$this->load->database();
|
|
|
|
$allowedFields = array('permission_group_ids', 'permission_ids');
|
|
if (!in_array($fieldName, $allowedFields)) return;
|
|
|
|
if(!empty($moduleUserArray)){
|
|
$this->db->where('module_id', $module_id);
|
|
$this->db->update('modules', array($fieldName => serialize($moduleUserArray)));
|
|
}
|
|
else{
|
|
$this->db->where('module_id', $module_id);
|
|
$this->db->update('modules', array($fieldName => ''));
|
|
}
|
|
}
|
|
|
|
|
|
public function getModulesByPermissionSlug($permissionSlug){
|
|
$this->load->database();
|
|
$this->load->model('Module_model');
|
|
$selectedPermission = $this->Module_model->getPermissionBySlug($permissionSlug);
|
|
|
|
// An unknown slug yields no permission at all; without this the line below
|
|
// dereferences null. No permission means no modules.
|
|
if(!$selectedPermission){
|
|
return array();
|
|
}
|
|
|
|
$query = $this->db->query('SELECT * FROM modules;');
|
|
$results = $query->result();
|
|
$resultArray = array();
|
|
foreach($results as $resultItem){
|
|
// modules.permission_ids is NULL for at least one row (module 8,
|
|
// 'Szerviz kategoriak') on every environment. Passing null to explode()
|
|
// is deprecated in PHP 8.1 and emits a notice. A module with no
|
|
// permissions is visible to nobody, so skipping it keeps the previous
|
|
// behaviour - explode(',', null) returned array('') which matched nothing.
|
|
if($resultItem->permission_ids === null || $resultItem->permission_ids === ''){
|
|
continue;
|
|
}
|
|
|
|
$permissionIdsArray = explode(',', $resultItem->permission_ids);
|
|
if(in_array($selectedPermission->permission_id, $permissionIdsArray)){
|
|
$resultArray[] = $resultItem;
|
|
}
|
|
}
|
|
return $resultArray;
|
|
}
|
|
|
|
public function getPermissionBySlug($permissionSlug){
|
|
$this->load->database();
|
|
|
|
$query = $this->db->query('SELECT * FROM permissions WHERE permission_slug = ?', array($permissionSlug));
|
|
if($query->num_rows() == 1){
|
|
return $query->result()[0];
|
|
}
|
|
else{
|
|
return 0;
|
|
}
|
|
}
|
|
|
|
public function user_can_access_this_module($moduleSlug, $userId){
|
|
$this->load->database();
|
|
$this->load->model('User_model');
|
|
$selectedUser = $this->User_model->getUserById($userId);
|
|
|
|
$query = $this->db->query('SELECT * FROM modules WHERE module_slug = ? LIMIT 1', array($moduleSlug));
|
|
|
|
if($query->num_rows() == 1){
|
|
$result = $query->result()[0];
|
|
$permissionArray = explode(',', $result->permission_ids);
|
|
if(in_array($selectedUser->permission_id, $permissionArray)){
|
|
return 1;
|
|
}
|
|
else{
|
|
return 0;
|
|
}
|
|
|
|
}
|
|
else{
|
|
return 0;
|
|
}
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
?>
|