1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16 package org.kuali.hr.time.authorization;
17
18 import org.apache.commons.lang.StringUtils;
19 import org.apache.log4j.Logger;
20 import org.kuali.hr.time.roles.UserRoles;
21 import org.kuali.hr.time.util.TKContext;
22 import org.kuali.hr.time.util.TKUser;
23 import org.kuali.hr.time.util.TkConstants;
24 import org.kuali.rice.krad.bo.BusinessObject;
25
26
27
28
29
30
31
32
33
34
35
36
37 public class DepartmentalRuleAuthorizer extends TkMaintenanceDocumentAuthorizerBase {
38
39 private static final Logger LOG = Logger.getLogger(DepartmentalRuleAuthorizer.class);
40
41 @Override
42 public boolean rolesIndicateGeneralReadAccess() {
43 return getRoles().isSystemAdmin() ||
44 getRoles().isGlobalViewOnly() ||
45 getRoles().getOrgAdminCharts().size() > 0 ||
46 getRoles().getOrgAdminDepartments().size() > 0 ||
47 getRoles().getDepartmentViewOnlyDepartments().size() > 0 ||
48 getRoles().isAnyApproverActive();
49 }
50
51 @Override
52 public boolean rolesIndicateGeneralWriteAccess() {
53 return getRoles().isSystemAdmin() ||
54 getRoles().getOrgAdminCharts().size() > 0 ||
55 getRoles().getOrgAdminDepartments().size() > 0;
56 }
57
58 @Override
59 public boolean rolesIndicateWriteAccess(BusinessObject bo) {
60 return bo instanceof DepartmentalRule && DepartmentalRuleAuthorizer.hasAccessToWrite((DepartmentalRule)bo);
61 }
62
63 @Override
64 public boolean rolesIndicateReadAccess(BusinessObject bo) {
65 return bo instanceof DepartmentalRule && DepartmentalRuleAuthorizer.hasAccessToRead((DepartmentalRule)bo);
66 }
67
68 public static boolean hasAccessToWrite(DepartmentalRule dr) {
69 boolean ret = false;
70 if (TKUser.isSystemAdmin())
71 return true;
72
73 if (dr != null && TKUser.getDepartmentAdminAreas().size() > 0) {
74 String dept = dr.getDept();
75 if (StringUtils.equals(dept, TkConstants.WILDCARD_CHARACTER)) {
76
77 ret = false;
78 } else {
79
80 ret = TKUser.getDepartmentAdminAreas().contains(dr.getDept());
81 }
82 }
83
84 return ret;
85 }
86
87
88
89
90
91
92
93
94
95 public static boolean hasAccessToRead(DepartmentalRule dr) {
96 boolean ret = false;
97 if (TKUser.isSystemAdmin() || TKUser.isGlobalViewOnly())
98 return true;
99
100 if (dr != null) {
101
102
103
104 /
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132