1 | |
|
2 | |
|
3 | |
|
4 | |
|
5 | |
|
6 | |
|
7 | |
|
8 | |
|
9 | |
|
10 | |
|
11 | |
|
12 | |
|
13 | |
|
14 | |
|
15 | |
|
16 | |
package org.kuali.rice.kns.document.authorization; |
17 | |
|
18 | |
import java.util.HashMap; |
19 | |
import java.util.HashSet; |
20 | |
import java.util.Map; |
21 | |
import java.util.Set; |
22 | |
|
23 | |
import org.kuali.rice.kim.bo.Person; |
24 | |
import org.kuali.rice.kim.bo.impl.KimAttributes; |
25 | |
import org.kuali.rice.kim.bo.types.dto.AttributeSet; |
26 | |
import org.kuali.rice.kim.util.KimCommonUtils; |
27 | |
import org.kuali.rice.kim.util.KimConstants; |
28 | |
import org.kuali.rice.kns.bo.BusinessObject; |
29 | |
import org.kuali.rice.kns.document.MaintenanceDocument; |
30 | |
import org.kuali.rice.kns.service.KNSServiceLocator; |
31 | |
import org.kuali.rice.kns.service.MaintenanceDocumentDictionaryService; |
32 | |
import org.kuali.rice.kns.util.KNSConstants; |
33 | |
|
34 | 0 | public class MaintenanceDocumentAuthorizerBase extends DocumentAuthorizerBase |
35 | |
implements MaintenanceDocumentAuthorizer { |
36 | |
|
37 | |
|
38 | |
|
39 | |
transient protected static MaintenanceDocumentDictionaryService maintenanceDocumentDictionaryService; |
40 | |
|
41 | |
@SuppressWarnings("unchecked") |
42 | |
public final boolean canCreate(Class boClass, Person user) { |
43 | 0 | AttributeSet permissionDetails = new AttributeSet(); |
44 | 0 | permissionDetails.put(KimAttributes.DOCUMENT_TYPE_NAME, |
45 | |
getMaintenanceDocumentDictionaryService().getDocumentTypeName( |
46 | |
boClass)); |
47 | 0 | permissionDetails.put(KNSConstants.MAINTENANCE_ACTN, |
48 | |
KNSConstants.MAINTENANCE_NEW_ACTION); |
49 | 0 | return !permissionExistsByTemplate(KNSConstants.KNS_NAMESPACE, |
50 | |
KimConstants.PermissionTemplateNames.CREATE_MAINTAIN_RECORDS, |
51 | |
permissionDetails) |
52 | |
|| getIdentityManagementService() |
53 | |
.isAuthorizedByTemplateName( |
54 | |
user.getPrincipalId(), |
55 | |
KNSConstants.KNS_NAMESPACE, |
56 | |
KimConstants.PermissionTemplateNames.CREATE_MAINTAIN_RECORDS, |
57 | |
permissionDetails, new AttributeSet()); |
58 | |
} |
59 | |
|
60 | |
@SuppressWarnings("unchecked") |
61 | |
public final boolean canMaintain(BusinessObject businessObject, Person user) { |
62 | 0 | Map<String, String> permissionDetails = new HashMap<String, String>(2); |
63 | 0 | permissionDetails.put(KimAttributes.DOCUMENT_TYPE_NAME, |
64 | |
getMaintenanceDocumentDictionaryService().getDocumentTypeName( |
65 | |
businessObject.getClass())); |
66 | 0 | permissionDetails.put(KNSConstants.MAINTENANCE_ACTN, |
67 | |
KNSConstants.MAINTENANCE_EDIT_ACTION); |
68 | 0 | return !permissionExistsByTemplate(KNSConstants.KNS_NAMESPACE, |
69 | |
KimConstants.PermissionTemplateNames.CREATE_MAINTAIN_RECORDS, |
70 | |
permissionDetails) |
71 | |
|| isAuthorizedByTemplate( |
72 | |
businessObject, |
73 | |
KNSConstants.KNS_NAMESPACE, |
74 | |
KimConstants.PermissionTemplateNames.CREATE_MAINTAIN_RECORDS, |
75 | |
user.getPrincipalId(), permissionDetails, null); |
76 | |
} |
77 | |
|
78 | |
public final boolean canCreateOrMaintain( |
79 | |
MaintenanceDocument maintenanceDocument, Person user) { |
80 | 0 | return !permissionExistsByTemplate(maintenanceDocument, |
81 | |
KNSConstants.KNS_NAMESPACE, |
82 | |
KimConstants.PermissionTemplateNames.CREATE_MAINTAIN_RECORDS) |
83 | |
|| isAuthorizedByTemplate( |
84 | |
maintenanceDocument, |
85 | |
KNSConstants.KNS_NAMESPACE, |
86 | |
KimConstants.PermissionTemplateNames.CREATE_MAINTAIN_RECORDS, |
87 | |
user.getPrincipalId()); |
88 | |
} |
89 | |
|
90 | |
public Set<String> getSecurePotentiallyHiddenSectionIds() { |
91 | 0 | return new HashSet<String>(); |
92 | |
} |
93 | |
|
94 | |
public Set<String> getSecurePotentiallyReadOnlySectionIds() { |
95 | 0 | return new HashSet<String>(); |
96 | |
} |
97 | |
|
98 | |
@SuppressWarnings("unchecked") |
99 | |
@Override |
100 | |
protected void addRoleQualification(BusinessObject businessObject, Map<String, String> attributes) { |
101 | 0 | super.addRoleQualification(businessObject, attributes); |
102 | 0 | if (businessObject instanceof MaintenanceDocument) { |
103 | 0 | MaintenanceDocument maintDoc = (MaintenanceDocument)businessObject; |
104 | 0 | if ( maintDoc.getNewMaintainableObject() != null ) { |
105 | 0 | attributes.putAll(KimCommonUtils.getNamespaceAndComponentSimpleName(maintDoc.getNewMaintainableObject().getBoClass())); |
106 | |
} |
107 | |
} |
108 | 0 | } |
109 | |
|
110 | |
@SuppressWarnings("unchecked") |
111 | |
@Override |
112 | |
protected void addPermissionDetails(BusinessObject businessObject, Map<String, String> attributes) { |
113 | 0 | super.addPermissionDetails(businessObject, attributes); |
114 | 0 | if (businessObject instanceof MaintenanceDocument) { |
115 | 0 | MaintenanceDocument maintDoc = (MaintenanceDocument)businessObject; |
116 | 0 | if ( maintDoc.getNewMaintainableObject() != null ) { |
117 | 0 | attributes.putAll(KimCommonUtils.getNamespaceAndComponentSimpleName(maintDoc.getNewMaintainableObject().getBoClass())); |
118 | 0 | attributes.put(KNSConstants.MAINTENANCE_ACTN,maintDoc.getNewMaintainableObject().getMaintenanceAction()); |
119 | |
} |
120 | |
} |
121 | 0 | } |
122 | |
|
123 | |
protected final MaintenanceDocumentDictionaryService getMaintenanceDocumentDictionaryService() { |
124 | 0 | if (maintenanceDocumentDictionaryService == null) { |
125 | 0 | maintenanceDocumentDictionaryService = KNSServiceLocator |
126 | |
.getMaintenanceDocumentDictionaryService(); |
127 | |
} |
128 | 0 | return maintenanceDocumentDictionaryService; |
129 | |
} |
130 | |
|
131 | |
} |