2019-10-23 00:40:14 +02:00
|
|
|
<?php
|
2020-02-09 15:45:36 +01:00
|
|
|
/**
|
|
|
|
* @copyright Copyright (C) 2020, Friendica
|
|
|
|
*
|
|
|
|
* @license GNU AGPL version 3 or any later version
|
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License as
|
|
|
|
* published by the Free Software Foundation, either version 3 of the
|
|
|
|
* License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU Affero General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public License
|
|
|
|
* along with this program. If not, see <https://www.gnu.org/licenses/>.
|
|
|
|
*
|
|
|
|
*/
|
2019-10-23 00:40:14 +02:00
|
|
|
|
|
|
|
namespace Friendica\Util;
|
|
|
|
|
|
|
|
use Friendica\Model\Group;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Util class for ACL formatting
|
|
|
|
*/
|
|
|
|
final class ACLFormatter
|
|
|
|
{
|
|
|
|
/**
|
|
|
|
* Turn user/group ACLs stored as angle bracketed text into arrays
|
|
|
|
*
|
2019-11-05 14:27:22 +01:00
|
|
|
* @param string|null $acl_string A angle-bracketed list of IDs
|
2019-10-23 00:40:14 +02:00
|
|
|
*
|
2019-11-01 15:43:16 +01:00
|
|
|
* @return array The array based on the IDs (empty in case there is no list)
|
2019-10-23 00:40:14 +02:00
|
|
|
*/
|
2019-11-05 14:27:22 +01:00
|
|
|
public function expand(string $acl_string = null)
|
2019-10-23 00:40:14 +02:00
|
|
|
{
|
2019-11-01 15:43:16 +01:00
|
|
|
// In case there is no ID list, return empty array (=> no ACL set)
|
2019-11-05 14:27:22 +01:00
|
|
|
if (!isset($acl_string)) {
|
2019-11-01 15:43:16 +01:00
|
|
|
return [];
|
2019-11-01 14:13:29 +01:00
|
|
|
}
|
|
|
|
|
2019-10-23 00:40:14 +02:00
|
|
|
// turn string array of angle-bracketed elements into numeric array
|
|
|
|
// e.g. "<1><2><3>" => array(1,2,3);
|
2019-11-05 14:27:22 +01:00
|
|
|
preg_match_all('/<(' . Group::FOLLOWERS . '|'. Group::MUTUALS . '|[0-9]+)>/', $acl_string, $matches, PREG_PATTERN_ORDER);
|
2019-10-23 00:40:14 +02:00
|
|
|
|
|
|
|
return $matches[1];
|
|
|
|
}
|
2019-10-23 00:54:34 +02:00
|
|
|
|
2019-11-05 14:27:22 +01:00
|
|
|
/**
|
|
|
|
* Takes an arbitrary ACL string and sanitizes it for storage
|
|
|
|
*
|
|
|
|
* @param string|null $acl_string
|
|
|
|
* @return string
|
|
|
|
*/
|
|
|
|
public function sanitize(string $acl_string = null)
|
|
|
|
{
|
|
|
|
if (empty($acl_string)) {
|
|
|
|
return '';
|
|
|
|
}
|
|
|
|
|
|
|
|
$cleaned_list = trim($acl_string, '<>');
|
|
|
|
|
|
|
|
if (empty($cleaned_list)) {
|
|
|
|
return '';
|
|
|
|
}
|
|
|
|
|
|
|
|
$elements = explode('><', $cleaned_list);
|
|
|
|
|
|
|
|
sort($elements);
|
|
|
|
|
|
|
|
array_walk($elements, [$this, 'sanitizeItem']);
|
|
|
|
|
|
|
|
return implode('', $elements);
|
|
|
|
}
|
|
|
|
|
2019-10-23 00:54:34 +02:00
|
|
|
/**
|
|
|
|
* Wrap ACL elements in angle brackets for storage
|
|
|
|
*
|
|
|
|
* @param string $item The item to sanitise
|
|
|
|
*/
|
2019-11-05 14:27:22 +01:00
|
|
|
private function sanitizeItem(string &$item) {
|
2019-11-01 14:13:29 +01:00
|
|
|
// The item is an ACL int value
|
2019-10-23 00:54:34 +02:00
|
|
|
if (intval($item)) {
|
|
|
|
$item = '<' . intval(Strings::escapeTags(trim($item))) . '>';
|
2019-11-01 14:13:29 +01:00
|
|
|
// The item is a allowed ACL character
|
2019-10-23 00:54:34 +02:00
|
|
|
} elseif (in_array($item, [Group::FOLLOWERS, Group::MUTUALS])) {
|
|
|
|
$item = '<' . $item . '>';
|
2019-11-01 14:13:29 +01:00
|
|
|
// The item is already a ACL string
|
|
|
|
} elseif (preg_match('/<\d+?>/', $item)) {
|
2019-10-29 07:01:50 +01:00
|
|
|
unset($item);
|
2019-11-01 14:13:29 +01:00
|
|
|
// The item is not supported, so remove it (cleanup)
|
|
|
|
} else {
|
|
|
|
$item = '';
|
2019-10-23 00:54:34 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Convert an ACL array to a storable string
|
|
|
|
*
|
|
|
|
* Normally ACL permissions will be an array.
|
|
|
|
* We'll also allow a comma-separated string.
|
|
|
|
*
|
|
|
|
* @param string|array $permissions
|
|
|
|
*
|
|
|
|
* @return string
|
|
|
|
*/
|
2019-10-23 21:38:51 +02:00
|
|
|
function toString($permissions) {
|
2019-10-23 00:54:34 +02:00
|
|
|
$return = '';
|
|
|
|
if (is_array($permissions)) {
|
|
|
|
$item = $permissions;
|
|
|
|
} else {
|
|
|
|
$item = explode(',', $permissions);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (is_array($item)) {
|
2019-11-05 14:27:22 +01:00
|
|
|
array_walk($item, [$this, 'sanitizeItem']);
|
2019-10-23 00:54:34 +02:00
|
|
|
$return = implode('', $item);
|
|
|
|
}
|
|
|
|
return $return;
|
|
|
|
}
|
2019-10-23 00:40:14 +02:00
|
|
|
}
|