grthtrhthjhtyjytjytkergtrhtrjytjerhrfh4:24 29/09/2026. -------------------------------------------------------------------------- */ /** @file * @brief */ if (!defined('GLPI_ROOT')) { die("Sorry. You can't access this file directly"); } /** * RuleRight Class * * Rule class for Rights management **/ class RuleRight extends Rule { // From Rule static $rightname = 'rule_ldap'; public $orderby = "name"; public $specific_parameters = true; // Temproray hack for this class in 0.84 static function getTable() { return 'glpi_rules'; } /** * @see Rule::maxActionsCount() **/ function maxActionsCount() { // Unlimited return 4; } /** * @see Rule::showNewRuleForm() **/ function showNewRuleForm($ID) { echo "
"; echo ""; echo "\n"; echo ""; echo "\n"; echo ""; echo "\n"; echo "
" .__('Authorizations assignment rules') . "
".__('Name') . ""; Html::autocompletionTextField($this, "name", array('value' => '', 'size' => 33)); echo ''.__('Description') . ""; Html::autocompletionTextField($this, "description", array('value' => '', 'size' => 33)); echo "".__('Logical operator') . ""; $this->dropdownRulesMatch(); echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; echo "
"._n('Profile', 'Profiles', 1) . ""; Profile::dropdown(); echo "".__('Recursive') . ""; Dropdown::showYesNo("is_recursive",0); echo "
"; Html::closeForm(); } /** * Execute the actions as defined in the rule * * @see Rule::executeActions() * * @param $output the result of the actions * @param $params the parameters * * @return the fields modified **/ function executeActions($output, $params) { global $CFG_GLPI; $entity = ''; $right = ''; $is_recursive = 0; $continue = true; $output_src = $output; if (count($this->actions)) { $entity = array(); foreach ($this->actions as $action) { switch ($action->fields["action_type"]) { case "assign" : switch ($action->fields["field"]) { case "entities_id" : $entity[] = $action->fields["value"]; break; case "profiles_id" : $right = $action->fields["value"]; break; case "is_recursive" : $is_recursive = $action->fields["value"]; break; case "is_active" : $output["is_active"] = $action->fields["value"]; break; case "_ignore_user_import" : $continue = false; $output_src["_stop_import"] = true; break; } // switch (field) break; case "regex_result" : switch ($action->fields["field"]) { case "_affect_entity_by_dn" : case "_affect_entity_by_tag" : case "_affect_entity_by_domain" : case "_affect_entity_by_completename" : foreach ($this->regex_results as $regex_result) { $res = RuleAction::getRegexResultById($action->fields["value"], $regex_result); if ($res != null) { switch ($action->fields["field"]) { case "_affect_entity_by_dn" : $entity_found = Entity::getEntityIDByDN(addslashes($res)); break; case "_affect_entity_by_tag" : $entity_found = Entity::getEntityIDByTag(addslashes($res)); break; case "_affect_entity_by_domain" : $entity_found = Entity::getEntityIDByDomain(addslashes($res)); break; case "_affect_entity_by_completename" : $res = Toolbox::unclean_cross_side_scripting_deep($res); $entity_found = Entity::getEntityIDByCompletename(addslashes($res)); break; default: $entity_found = -1; break; } //If an entity was found if ($entity_found > -1) { $entity[] = $entity_found; } } } if (!count($entity)) { //Not entity assigned : action processing must be stopped for this rule $continue = false; } break; } // switch (field) break; } // switch (action_type) } // foreach (action) } // count (actions) if ($continue) { //Nothing to be returned by the function : //Store in session the entity and/or right if (count($entity)) { if ($right != '') { foreach ($entity as $entID) { $output["_ldap_rules"]["rules_entities_rights"][] = array($entID, $right, $is_recursive); } } else { foreach ($entity as $entID) { $output["_ldap_rules"]["rules_entities"][] = array($entID, $is_recursive); } } } else if ($right != '') { $output["_ldap_rules"]["rules_rights"][] = $right; } return $output; } return $output_src; } function getTitle() { return __('Automatic user assignment'); } /** * @see Rule::getCriterias() **/ function getCriterias() { static $criterias = array(); if (!count($criterias)) { $criterias['common'] = __('Global criteria'); $criterias['LDAP_SERVER']['table'] = 'glpi_authldaps'; $criterias['LDAP_SERVER']['field'] = 'name'; $criterias['LDAP_SERVER']['name'] = __('LDAP directory'); $criterias['LDAP_SERVER']['linkfield'] = ''; $criterias['LDAP_SERVER']['type'] = 'dropdown'; $criterias['LDAP_SERVER']['virtual'] = true; $criterias['LDAP_SERVER']['id'] = 'ldap_server'; $criterias['MAIL_SERVER']['table'] = 'glpi_authmails'; $criterias['MAIL_SERVER']['field'] = 'name'; $criterias['MAIL_SERVER']['name'] = __('Email server'); $criterias['MAIL_SERVER']['linkfield'] = ''; $criterias['MAIL_SERVER']['type'] = 'dropdown'; $criterias['MAIL_SERVER']['virtual'] = true; $criterias['MAIL_SERVER']['id'] = 'mail_server'; $criterias['MAIL_EMAIL']['table'] = ''; $criterias['MAIL_EMAIL']['field'] = ''; $criterias['MAIL_EMAIL']['name'] = _n('Email', 'Emails', 1); $criterias['MAIL_EMAIL']['linkfield'] = ''; $criterias['MAIL_EMAIL']['virtual'] = true; $criterias['MAIL_EMAIL']['id'] = 'mail_email'; $criterias['LOGIN']['table'] = ''; $criterias['LOGIN']['field'] = ''; $criterias['LOGIN']['name'] = __('Login'); $criterias['LOGIN']['linkfield'] = ''; $criterias['LOGIN']['virtual'] = true; $criterias['LOGIN']['id'] = 'login'; $criterias['GROUPS']['table'] = 'glpi_groups'; $criterias['GROUPS']['field'] = 'completename'; $criterias['GROUPS']['name'] = __('Imported group from an LDAP directory'); $criterias['GROUPS']['linkfield'] = ''; $criterias['GROUPS']['type'] = 'dropdown'; $criterias['GROUPS']['virtual'] = true; $criterias['GROUPS']['id'] = 'groups'; //Dynamically add all the ldap criterias to the current list of rule's criterias $this->addSpecificCriteriasToArray($criterias); } return $criterias; } /** * @see Rule::getActions() **/ function getActions() { $actions = array(); $actions['entities_id']['name'] = __('Entity'); $actions['entities_id']['type'] = 'dropdown'; $actions['entities_id']['table'] = 'glpi_entities'; $actions['_affect_entity_by_dn']['name'] = __('Entity based on LDAP information'); $actions['_affect_entity_by_dn']['type'] = 'text'; $actions['_affect_entity_by_dn']['force_actions'] = array('regex_result'); $actions['_affect_entity_by_dn']['duplicatewith'] = 'entities_id'; $actions['_affect_entity_by_tag']['name'] = __('Entity from TAG'); $actions['_affect_entity_by_tag']['type'] = 'text'; $actions['_affect_entity_by_tag']['force_actions'] = array('regex_result'); $actions['_affect_entity_by_tag']['duplicatewith'] = 'entities_id'; $actions['_affect_entity_by_domain']['name'] = __('Entity from mail domain'); $actions['_affect_entity_by_domain']['type'] = 'text'; $actions['_affect_entity_by_domain']['force_actions'] = array('regex_result'); $actions['_affect_entity_by_domain']['duplicatewith'] = 'entities_id'; $actions['_affect_entity_by_completename']['name'] = __('Entity from complete name'); $actions['_affect_entity_by_completename']['type'] = 'text'; $actions['_affect_entity_by_completename']['force_actions'] = array('regex_result'); $actions['_affect_entity_by_completename']['duplicatewith'] = 'entities_id'; $actions['profiles_id']['name'] = _n('Profile', 'Profiles', Session::getPluralNumber()); $actions['profiles_id']['type'] = 'dropdown'; $actions['profiles_id']['table'] = 'glpi_profiles'; $actions['is_recursive']['name'] = __('Recursive'); $actions['is_recursive']['type'] = 'yesno'; $actions['is_recursive']['table'] = ''; $actions['is_active']['name'] = __('Active'); $actions['is_active']['type'] = 'yesno'; $actions['is_active']['table'] = ''; $actions['_ignore_user_import']['name'] = __('To be unaware of import'); $actions['_ignore_user_import']['type'] = 'yesonly'; $actions['_ignore_user_import']['table'] = ''; return $actions; } /** * Get all ldap rules criterias from the DB and add them into the RULES_CRITERIAS * * @param &$criterias **/ function addSpecificCriteriasToArray(&$criterias) { $criterias['ldap'] = __('LDAP criteria'); foreach (getAllDatasFromTable('glpi_rulerightparameters', '', true) as $datas ) { $criterias[$datas["value"]]['name'] = $datas["name"]; $criterias[$datas["value"]]['field'] = $datas["value"]; $criterias[$datas["value"]]['linkfield'] = ''; $criterias[$datas["value"]]['table'] = ''; } } } ?>