2015-07-12 15:01:42 -04:00
|
|
|
<?php
|
|
|
|
|
2015-09-10 14:31:09 -04:00
|
|
|
namespace BookStack\Http\Controllers;
|
2015-07-12 15:01:42 -04:00
|
|
|
|
2016-02-27 14:24:42 -05:00
|
|
|
use BookStack\Ownable;
|
2015-08-29 10:03:42 -04:00
|
|
|
use HttpRequestException;
|
2015-07-12 15:01:42 -04:00
|
|
|
use Illuminate\Foundation\Bus\DispatchesJobs;
|
2015-08-29 10:03:42 -04:00
|
|
|
use Illuminate\Http\Exception\HttpResponseException;
|
2015-07-12 15:01:42 -04:00
|
|
|
use Illuminate\Routing\Controller as BaseController;
|
|
|
|
use Illuminate\Foundation\Validation\ValidatesRequests;
|
2015-08-24 16:10:04 -04:00
|
|
|
use Illuminate\Support\Facades\Auth;
|
2015-08-29 10:03:42 -04:00
|
|
|
use Illuminate\Support\Facades\Session;
|
2015-09-10 14:31:09 -04:00
|
|
|
use BookStack\User;
|
2015-07-12 15:01:42 -04:00
|
|
|
|
|
|
|
abstract class Controller extends BaseController
|
|
|
|
{
|
|
|
|
use DispatchesJobs, ValidatesRequests;
|
2015-08-24 16:10:04 -04:00
|
|
|
|
2015-08-29 10:03:42 -04:00
|
|
|
/**
|
|
|
|
* @var User static
|
|
|
|
*/
|
|
|
|
protected $currentUser;
|
|
|
|
/**
|
|
|
|
* @var bool
|
|
|
|
*/
|
|
|
|
protected $signedIn;
|
|
|
|
|
2015-08-24 16:10:04 -04:00
|
|
|
/**
|
|
|
|
* Controller constructor.
|
|
|
|
*/
|
|
|
|
public function __construct()
|
|
|
|
{
|
2016-09-17 13:22:04 -04:00
|
|
|
$this->middleware(function ($request, $next) {
|
2015-09-05 12:42:05 -04:00
|
|
|
|
2016-09-17 13:22:04 -04:00
|
|
|
// Get a user instance for the current user
|
|
|
|
$user = auth()->user();
|
|
|
|
if (!$user) $user = User::getDefault();
|
2015-09-05 12:42:05 -04:00
|
|
|
|
2016-09-17 13:22:04 -04:00
|
|
|
// Share variables with views
|
|
|
|
view()->share('signedIn', auth()->check());
|
|
|
|
view()->share('currentUser', $user);
|
|
|
|
|
|
|
|
// Share variables with controllers
|
|
|
|
$this->currentUser = $user;
|
|
|
|
$this->signedIn = auth()->check();
|
|
|
|
|
|
|
|
return $next($request);
|
|
|
|
});
|
2015-08-29 10:03:42 -04:00
|
|
|
}
|
|
|
|
|
2015-12-31 12:57:34 -05:00
|
|
|
/**
|
|
|
|
* Stops the application and shows a permission error if
|
|
|
|
* the application is in demo mode.
|
|
|
|
*/
|
|
|
|
protected function preventAccessForDemoUsers()
|
|
|
|
{
|
2016-01-09 14:23:35 -05:00
|
|
|
if (config('app.env') === 'demo') $this->showPermissionError();
|
2015-12-31 12:57:34 -05:00
|
|
|
}
|
|
|
|
|
2015-12-05 09:41:51 -05:00
|
|
|
/**
|
|
|
|
* Adds the page title into the view.
|
|
|
|
* @param $title
|
|
|
|
*/
|
|
|
|
public function setPageTitle($title)
|
|
|
|
{
|
|
|
|
view()->share('pageTitle', $title);
|
|
|
|
}
|
|
|
|
|
2015-12-31 12:57:34 -05:00
|
|
|
/**
|
2016-02-27 14:24:42 -05:00
|
|
|
* On a permission error redirect to home and display.
|
2015-12-31 12:57:34 -05:00
|
|
|
* the error as a notification.
|
|
|
|
*/
|
|
|
|
protected function showPermissionError()
|
|
|
|
{
|
|
|
|
Session::flash('error', trans('errors.permission'));
|
2016-02-29 15:31:21 -05:00
|
|
|
$response = request()->wantsJson() ? response()->json(['error' => trans('errors.permissionJson')], 403) : redirect('/');
|
2016-02-27 15:52:46 -05:00
|
|
|
throw new HttpResponseException($response);
|
2015-12-31 12:57:34 -05:00
|
|
|
}
|
|
|
|
|
2015-08-29 10:03:42 -04:00
|
|
|
/**
|
|
|
|
* Checks for a permission.
|
2016-02-27 14:24:42 -05:00
|
|
|
* @param string $permissionName
|
2015-08-29 10:03:42 -04:00
|
|
|
* @return bool|\Illuminate\Http\RedirectResponse
|
|
|
|
*/
|
|
|
|
protected function checkPermission($permissionName)
|
|
|
|
{
|
|
|
|
if (!$this->currentUser || !$this->currentUser->can($permissionName)) {
|
2015-12-31 12:57:34 -05:00
|
|
|
$this->showPermissionError();
|
2015-08-29 10:03:42 -04:00
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2016-02-27 14:24:42 -05:00
|
|
|
/**
|
|
|
|
* Check the current user's permissions against an ownable item.
|
|
|
|
* @param $permission
|
|
|
|
* @param Ownable $ownable
|
|
|
|
* @return bool
|
|
|
|
*/
|
|
|
|
protected function checkOwnablePermission($permission, Ownable $ownable)
|
|
|
|
{
|
2016-02-29 15:31:21 -05:00
|
|
|
if (userCan($permission, $ownable)) return true;
|
|
|
|
return $this->showPermissionError();
|
2016-02-27 14:24:42 -05:00
|
|
|
}
|
|
|
|
|
2015-12-31 12:57:34 -05:00
|
|
|
/**
|
|
|
|
* Check if a user has a permission or bypass if the callback is true.
|
|
|
|
* @param $permissionName
|
|
|
|
* @param $callback
|
|
|
|
* @return bool
|
|
|
|
*/
|
2015-08-29 10:03:42 -04:00
|
|
|
protected function checkPermissionOr($permissionName, $callback)
|
|
|
|
{
|
|
|
|
$callbackResult = $callback();
|
|
|
|
if ($callbackResult === false) $this->checkPermission($permissionName);
|
|
|
|
return true;
|
2015-08-24 16:10:04 -04:00
|
|
|
}
|
|
|
|
|
2016-05-07 09:29:43 -04:00
|
|
|
/**
|
|
|
|
* Send back a json error message.
|
|
|
|
* @param string $messageText
|
|
|
|
* @param int $statusCode
|
|
|
|
* @return mixed
|
|
|
|
*/
|
|
|
|
protected function jsonError($messageText = "", $statusCode = 500)
|
|
|
|
{
|
|
|
|
return response()->json(['message' => $messageText], $statusCode);
|
|
|
|
}
|
|
|
|
|
2015-07-12 15:01:42 -04:00
|
|
|
}
|