215 lines
8.9 KiB
PHP
215 lines
8.9 KiB
PHP
<?php
|
|
|
|
/*
|
|
* AVSDev UF Organisations (https://avsdev.uk)
|
|
*
|
|
* @link https://git.avsdev.uk/avsdev/sprinkle-organisations
|
|
* @license https://git.avsdev.uk/avsdev/sprinkle-organisations/blob/master/LICENSE.md (LGPL-3.0 License)
|
|
*/
|
|
|
|
namespace UserFrosting\Sprinkle\Organisations\Database\Seeds;
|
|
|
|
use UserFrosting\Sprinkle\Account\Database\Models\Permission;
|
|
use UserFrosting\Sprinkle\Account\Database\Models\Role;
|
|
use UserFrosting\Sprinkle\Core\Database\Seeder\BaseSeed;
|
|
use UserFrosting\Sprinkle\Core\Facades\Seeder;
|
|
|
|
/**
|
|
* Seeder for the permissions related to organisations.
|
|
*
|
|
* @author Craig Williams (https://avsdev.uk)
|
|
*/
|
|
class OrganisationPermissions extends BaseSeed
|
|
{
|
|
/**
|
|
* {@inheritdoc}
|
|
*/
|
|
public function run()
|
|
{
|
|
// We require the default roles
|
|
Seeder::execute('DefaultPermissions');
|
|
Seeder::execute('DefaultRoles');
|
|
Seeder::execute('OrganisationRoles');
|
|
|
|
// Get and save permissions
|
|
$permissions = $this->getPermissions();
|
|
$this->savePermissions($permissions);
|
|
|
|
// Add default mappings to permissions
|
|
$this->syncPermissionsRole($permissions);
|
|
}
|
|
|
|
/**
|
|
* @return array Permissions to seed
|
|
*/
|
|
protected function getPermissions()
|
|
{
|
|
return [
|
|
'create_organisation' => new Permission([
|
|
'slug' => 'create_organisation',
|
|
'name' => 'Create organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Create a new organisation.',
|
|
]),
|
|
'register_organisation' => new Permission([
|
|
'slug' => 'register_organisation',
|
|
'name' => 'Register organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Register a new organisation. May optionally require approval.',
|
|
]),
|
|
'view_organisation_field' => new Permission([
|
|
'slug' => 'view_organisation_field',
|
|
'name' => 'View organisation',
|
|
'conditions' => "in(property,['name','slug','description','members'])",
|
|
'description' => 'View certain properties of any organisation.',
|
|
]),
|
|
'view_organisation_field_own' => new Permission([
|
|
'slug' => 'view_organisation_field',
|
|
'name' => 'View own organisation',
|
|
'conditions' => "is_organisation_member(self.id,organisation.id) & in(property,['name','slug','description','members'])",
|
|
'description' => 'View certain properties of own organisation.',
|
|
]),
|
|
'update_organisation_field' => new Permission([
|
|
'slug' => 'update_organisation_field',
|
|
'name' => 'Edit organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Edit basic properties of any organisation.',
|
|
]),
|
|
'approve_organisation' => new Permission([
|
|
'slug' => 'approve_organisation',
|
|
'name' => 'Approve/Reject organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Approve/Reject organisation registation request.',
|
|
]),
|
|
'merge_organisations' => new Permission([
|
|
'slug' => 'merge_organisations',
|
|
'name' => 'Merge two organisations',
|
|
'conditions' => 'always()',
|
|
'description' => 'Merge two organisations together, including all the members.',
|
|
]),
|
|
'leave_organisation' => new Permission([
|
|
'slug' => 'leave_organisation',
|
|
'name' => 'Leave organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Allows members to leave organisations.',
|
|
]),
|
|
'delete_organisation' => new Permission([
|
|
'slug' => 'delete_organisation',
|
|
'name' => 'Delete organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Delete an organisation.',
|
|
]),
|
|
'restore_organisation' => new Permission([
|
|
'slug' => 'restore_organisation',
|
|
'name' => 'Restore organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Restore a deleted organisation.',
|
|
]),
|
|
'permenent_delete_organisation' => new Permission([
|
|
'slug' => 'permenent_delete_organisation',
|
|
'name' => 'Permenently delete organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'Permenently delete an organisation.',
|
|
]),
|
|
'uri_organisation' => new Permission([
|
|
'slug' => 'uri_organisation',
|
|
'name' => 'View organisation',
|
|
'conditions' => 'always()',
|
|
'description' => 'View the organisation page of any organisation.',
|
|
]),
|
|
'uri_organisation_own' => new Permission([
|
|
'slug' => 'uri_organisation',
|
|
'name' => 'View own organisation',
|
|
'conditions' => 'is_organisation_member(self.id,organisation.id)',
|
|
'description' => 'View the organisation page of an organisation you are a member of.',
|
|
]),
|
|
'uri_organisations' => new Permission([
|
|
'slug' => 'uri_organisations',
|
|
'name' => 'Organisation management page',
|
|
'conditions' => 'always()',
|
|
'description' => 'View a page containing a list of organisations.',
|
|
]),
|
|
'uri_deleted_organisations' => new Permission([
|
|
'slug' => 'uri_deleted_organisations',
|
|
'name' => 'Deleted organisation management page',
|
|
'conditions' => 'always()',
|
|
'description' => 'View a page containing a list of deleted organisations.',
|
|
]),
|
|
];
|
|
}
|
|
|
|
|
|
/**
|
|
* Save permissions.
|
|
*
|
|
* @param array $permissions
|
|
*/
|
|
protected function savePermissions(array &$permissions)
|
|
{
|
|
foreach ($permissions as $slug => $permission) {
|
|
|
|
// Trying to find if the permission already exist
|
|
$existingPermission = Permission::where(['slug' => $permission->slug, 'conditions' => $permission->conditions])->first();
|
|
|
|
// Don't save if already exist, use existing permission reference
|
|
// otherwise to re-sync permissions and roles
|
|
if ($existingPermission == null) {
|
|
$permission->save();
|
|
} else {
|
|
$permissions[$slug] = $existingPermission;
|
|
}
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Sync permissions with default roles.
|
|
*
|
|
* @param array $permissions
|
|
*/
|
|
protected function syncPermissionsRole(array $permissions)
|
|
{
|
|
$roleSiteAdmin = Role::where('slug', 'site-admin')->first();
|
|
if ($roleSiteAdmin) {
|
|
$roleSiteAdmin->permissions()->syncWithoutDetaching([
|
|
$permissions['create_organisation']->id,
|
|
$permissions['view_organisation_field']->id,
|
|
$permissions['update_organisation_field']->id,
|
|
$permissions['approve_organisation']->id,
|
|
$permissions['merge_organisations']->id,
|
|
$permissions['delete_organisation']->id,
|
|
$permissions['uri_organisations']->id,
|
|
$permissions['uri_organisation']->id,
|
|
]);
|
|
|
|
}
|
|
|
|
$roleOrgAdmin = Role::where('slug', 'organisations-admin')->first();
|
|
if ($roleOrgAdmin) {
|
|
$roleOrgAdmin->permissions()->syncWithoutDetaching([
|
|
$permissions['create_organisation']->id,
|
|
$permissions['view_organisation_field']->id,
|
|
$permissions['update_organisation_field']->id,
|
|
$permissions['approve_organisation']->id,
|
|
$permissions['merge_organisations']->id,
|
|
$permissions['delete_organisation']->id,
|
|
$permissions['uri_organisations']->id,
|
|
$permissions['uri_organisation']->id,
|
|
$permissions['uri_deleted_organisations']->id,
|
|
$permissions['restore_organisation']->id,
|
|
$permissions['permenent_delete_organisation']->id,
|
|
]);
|
|
}
|
|
|
|
$roleUser = Role::where('slug', 'user')->first();
|
|
if ($roleUser) {
|
|
$roleUser->permissions()->syncWithoutDetaching([
|
|
$permissions['uri_organisations']->id,
|
|
$permissions['uri_organisation_own']->id,
|
|
$permissions['view_organisation_field_own']->id,
|
|
$permissions['leave_organisation']->id,
|
|
$permissions['register_organisation']->id,
|
|
]);
|
|
}
|
|
}
|
|
}
|