1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16 package org.kuali.hr.time.authorization;
17
18 import org.apache.commons.lang.StringUtils;
19 import org.apache.log4j.Logger;
20 import org.kuali.hr.time.roles.UserRoles;
21 import org.kuali.hr.time.util.TKContext;
22 import org.kuali.hr.time.util.TkConstants;
23 import org.kuali.rice.krad.bo.BusinessObject;
24
25
26
27
28
29
30
31
32
33
34
35
36 public class DepartmentalRuleAuthorizer extends TkMaintenanceDocumentAuthorizerBase {
37
38 private static final Logger LOG = Logger.getLogger(DepartmentalRuleAuthorizer.class);
39
40 @Override
41 public boolean rolesIndicateGeneralReadAccess() {
42 return getRoles().isSystemAdmin() ||
43 getRoles().isGlobalViewOnly() ||
44 getRoles().getOrgAdminCharts().size() > 0 ||
45 getRoles().getOrgAdminDepartments().size() > 0 ||
46 getRoles().getDepartmentViewOnlyDepartments().size() > 0 ||
47 getRoles().isAnyApproverActive();
48 }
49
50 @Override
51 public boolean rolesIndicateGeneralWriteAccess() {
52 return getRoles().isSystemAdmin() ||
53 getRoles().getOrgAdminCharts().size() > 0 ||
54 getRoles().getOrgAdminDepartments().size() > 0;
55 }
56
57 @Override
58 public boolean rolesIndicateWriteAccess(BusinessObject bo) {
59 return bo instanceof DepartmentalRule && DepartmentalRuleAuthorizer.hasAccessToWrite((DepartmentalRule)bo);
60 }
61
62 @Override
63 public boolean rolesIndicateReadAccess(BusinessObject bo) {
64 return bo instanceof DepartmentalRule && DepartmentalRuleAuthorizer.hasAccessToRead((DepartmentalRule)bo);
65 }
66
67 public static boolean hasAccessToWrite(DepartmentalRule dr) {
68 boolean ret = false;
69 if (TKContext.getUser().isSystemAdmin())
70 return true;
71
72 if (dr != null && TKContext.getUser().getDepartmentAdminAreas().size() > 0) {
73 String dept = dr.getDept();
74 if (StringUtils.equals(dept, TkConstants.WILDCARD_CHARACTER)) {
75
76 ret = false;
77 } else {
78
79 ret = TKContext.getUser().getDepartmentAdminAreas().contains(dr.getDept());
80 }
81 }
82
83 return ret;
84 }
85
86
87
88
89
90
91
92
93
94 public static boolean hasAccessToRead(DepartmentalRule dr) {
95 boolean ret = false;
96 if (TKContext.getUser().isSystemAdmin() || TKContext.getUser().isGlobalViewOnly())
97 return true;
98
99 if (dr != null) {
100
101
102
103 /
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131