New module 'Role Delegation'
This commit is contained in:
parent
8ce30b8e63
commit
8e3e8a7d9f
7 changed files with 770 additions and 0 deletions
6
sites/all/modules/role_delegation/CHANGELOG.txt
Normal file
6
sites/all/modules/role_delegation/CHANGELOG.txt
Normal file
|
@ -0,0 +1,6 @@
|
|||
$Id: CHANGELOG.txt,v 1.1.2.3 2010/12/09 18:25:31 andrewschulman Exp $
|
||||
|
||||
Role Delegation 6.x-1.4, 2010-12-09
|
||||
-----------------------------------
|
||||
#170543 by Andrew Schulman: Rename or delete 'assign role' permissions when roles are renamed or deleted.
|
||||
#797452 by AlexisWilke, teliseo: Roles were not being shown in their usual location.
|
274
sites/all/modules/role_delegation/LICENSE.txt
Normal file
274
sites/all/modules/role_delegation/LICENSE.txt
Normal file
|
@ -0,0 +1,274 @@
|
|||
GNU GENERAL PUBLIC LICENSE
|
||||
|
||||
Version 2, June 1991
|
||||
|
||||
Copyright (C) 1989, 1991 Free Software Foundation, Inc. 675 Mass Ave,
|
||||
Cambridge, MA 02139, USA. Everyone is permitted to copy and distribute
|
||||
verbatim copies of this license document, but changing it is not allowed.
|
||||
|
||||
Preamble
|
||||
|
||||
The licenses for most software are designed to take away your freedom to
|
||||
share and change it. By contrast, the GNU General Public License is
|
||||
intended to guarantee your freedom to share and change free software--to
|
||||
make sure the software is free for all its users. This General Public License
|
||||
applies to most of the Free Software Foundation's software and to any other
|
||||
program whose authors commit to using it. (Some other Free Software
|
||||
Foundation software is covered by the GNU Library General Public License
|
||||
instead.) You can apply it to your programs, too.
|
||||
|
||||
When we speak of free software, we are referring to freedom, not price. Our
|
||||
General Public Licenses are designed to make sure that you have the
|
||||
freedom to distribute copies of free software (and charge for this service if
|
||||
you wish), that you receive source code or can get it if you want it, that you
|
||||
can change the software or use pieces of it in new free programs; and that
|
||||
you know you can do these things.
|
||||
|
||||
To protect your rights, we need to make restrictions that forbid anyone to
|
||||
deny you these rights or to ask you to surrender the rights. These restrictions
|
||||
translate to certain responsibilities for you if you distribute copies of the
|
||||
software, or if you modify it.
|
||||
|
||||
For example, if you distribute copies of such a program, whether gratis or for
|
||||
a fee, you must give the recipients all the rights that you have. You must make
|
||||
sure that they, too, receive or can get the source code. And you must show
|
||||
them these terms so they know their rights.
|
||||
|
||||
We protect your rights with two steps: (1) copyright the software, and (2)
|
||||
offer you this license which gives you legal permission to copy, distribute
|
||||
and/or modify the software.
|
||||
|
||||
Also, for each author's protection and ours, we want to make certain that
|
||||
everyone understands that there is no warranty for this free software. If the
|
||||
software is modified by someone else and passed on, we want its recipients
|
||||
to know that what they have is not the original, so that any problems
|
||||
introduced by others will not reflect on the original authors' reputations.
|
||||
|
||||
Finally, any free program is threatened constantly by software patents. We
|
||||
wish to avoid the danger that redistributors of a free program will individually
|
||||
obtain patent licenses, in effect making the program proprietary. To prevent
|
||||
this, we have made it clear that any patent must be licensed for everyone's
|
||||
free use or not licensed at all.
|
||||
|
||||
The precise terms and conditions for copying, distribution and modification
|
||||
follow.
|
||||
|
||||
GNU GENERAL PUBLIC LICENSE
|
||||
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND
|
||||
MODIFICATION
|
||||
|
||||
0. This License applies to any program or other work which contains a notice
|
||||
placed by the copyright holder saying it may be distributed under the terms
|
||||
of this General Public License. The "Program", below, refers to any such
|
||||
program or work, and a "work based on the Program" means either the
|
||||
Program or any derivative work under copyright law: that is to say, a work
|
||||
containing the Program or a portion of it, either verbatim or with
|
||||
modifications and/or translated into another language. (Hereinafter, translation
|
||||
is included without limitation in the term "modification".) Each licensee is
|
||||
addressed as "you".
|
||||
|
||||
Activities other than copying, distribution and modification are not covered
|
||||
by this License; they are outside its scope. The act of running the Program is
|
||||
not restricted, and the output from the Program is covered only if its contents
|
||||
constitute a work based on the Program (independent of having been made
|
||||
by running the Program). Whether that is true depends on what the Program
|
||||
does.
|
||||
|
||||
1. You may copy and distribute verbatim copies of the Program's source
|
||||
code as you receive it, in any medium, provided that you conspicuously and
|
||||
appropriately publish on each copy an appropriate copyright notice and
|
||||
disclaimer of warranty; keep intact all the notices that refer to this License
|
||||
and to the absence of any warranty; and give any other recipients of the
|
||||
Program a copy of this License along with the Program.
|
||||
|
||||
You may charge a fee for the physical act of transferring a copy, and you
|
||||
may at your option offer warranty protection in exchange for a fee.
|
||||
|
||||
2. You may modify your copy or copies of the Program or any portion of it,
|
||||
thus forming a work based on the Program, and copy and distribute such
|
||||
modifications or work under the terms of Section 1 above, provided that you
|
||||
also meet all of these conditions:
|
||||
|
||||
a) You must cause the modified files to carry prominent notices stating that
|
||||
you changed the files and the date of any change.
|
||||
|
||||
b) You must cause any work that you distribute or publish, that in whole or in
|
||||
part contains or is derived from the Program or any part thereof, to be
|
||||
licensed as a whole at no charge to all third parties under the terms of this
|
||||
License.
|
||||
|
||||
c) If the modified program normally reads commands interactively when run,
|
||||
you must cause it, when started running for such interactive use in the most
|
||||
ordinary way, to print or display an announcement including an appropriate
|
||||
copyright notice and a notice that there is no warranty (or else, saying that
|
||||
you provide a warranty) and that users may redistribute the program under
|
||||
these conditions, and telling the user how to view a copy of this License.
|
||||
(Exception: if the Program itself is interactive but does not normally print such
|
||||
an announcement, your work based on the Program is not required to print
|
||||
an announcement.)
|
||||
|
||||
These requirements apply to the modified work as a whole. If identifiable
|
||||
sections of that work are not derived from the Program, and can be
|
||||
reasonably considered independent and separate works in themselves, then
|
||||
this License, and its terms, do not apply to those sections when you distribute
|
||||
them as separate works. But when you distribute the same sections as part
|
||||
of a whole which is a work based on the Program, the distribution of the
|
||||
whole must be on the terms of this License, whose permissions for other
|
||||
licensees extend to the entire whole, and thus to each and every part
|
||||
regardless of who wrote it.
|
||||
|
||||
Thus, it is not the intent of this section to claim rights or contest your rights to
|
||||
work written entirely by you; rather, the intent is to exercise the right to
|
||||
control the distribution of derivative or collective works based on the
|
||||
Program.
|
||||
|
||||
In addition, mere aggregation of another work not based on the Program
|
||||
with the Program (or with a work based on the Program) on a volume of a
|
||||
storage or distribution medium does not bring the other work under the scope
|
||||
of this License.
|
||||
|
||||
3. You may copy and distribute the Program (or a work based on it, under
|
||||
Section 2) in object code or executable form under the terms of Sections 1
|
||||
and 2 above provided that you also do one of the following:
|
||||
|
||||
a) Accompany it with the complete corresponding machine-readable source
|
||||
code, which must be distributed under the terms of Sections 1 and 2 above
|
||||
on a medium customarily used for software interchange; or,
|
||||
|
||||
b) Accompany it with a written offer, valid for at least three years, to give
|
||||
any third party, for a charge no more than your cost of physically performing
|
||||
source distribution, a complete machine-readable copy of the corresponding
|
||||
source code, to be distributed under the terms of Sections 1 and 2 above on
|
||||
a medium customarily used for software interchange; or,
|
||||
|
||||
c) Accompany it with the information you received as to the offer to distribute
|
||||
corresponding source code. (This alternative is allowed only for
|
||||
noncommercial distribution and only if you received the program in object
|
||||
code or executable form with such an offer, in accord with Subsection b
|
||||
above.)
|
||||
|
||||
The source code for a work means the preferred form of the work for
|
||||
making modifications to it. For an executable work, complete source code
|
||||
means all the source code for all modules it contains, plus any associated
|
||||
interface definition files, plus the scripts used to control compilation and
|
||||
installation of the executable. However, as a special exception, the source
|
||||
code distributed need not include anything that is normally distributed (in
|
||||
either source or binary form) with the major components (compiler, kernel,
|
||||
and so on) of the operating system on which the executable runs, unless that
|
||||
component itself accompanies the executable.
|
||||
|
||||
If distribution of executable or object code is made by offering access to
|
||||
copy from a designated place, then offering equivalent access to copy the
|
||||
source code from the same place counts as distribution of the source code,
|
||||
even though third parties are not compelled to copy the source along with the
|
||||
object code.
|
||||
|
||||
4. You may not copy, modify, sublicense, or distribute the Program except as
|
||||
expressly provided under this License. Any attempt otherwise to copy,
|
||||
modify, sublicense or distribute the Program is void, and will automatically
|
||||
terminate your rights under this License. However, parties who have received
|
||||
copies, or rights, from you under this License will not have their licenses
|
||||
terminated so long as such parties remain in full compliance.
|
||||
|
||||
5. You are not required to accept this License, since you have not signed it.
|
||||
However, nothing else grants you permission to modify or distribute the
|
||||
Program or its derivative works. These actions are prohibited by law if you
|
||||
do not accept this License. Therefore, by modifying or distributing the
|
||||
Program (or any work based on the Program), you indicate your acceptance
|
||||
of this License to do so, and all its terms and conditions for copying,
|
||||
distributing or modifying the Program or works based on it.
|
||||
|
||||
6. Each time you redistribute the Program (or any work based on the
|
||||
Program), the recipient automatically receives a license from the original
|
||||
licensor to copy, distribute or modify the Program subject to these terms and
|
||||
conditions. You may not impose any further restrictions on the recipients'
|
||||
exercise of the rights granted herein. You are not responsible for enforcing
|
||||
compliance by third parties to this License.
|
||||
|
||||
7. If, as a consequence of a court judgment or allegation of patent
|
||||
infringement or for any other reason (not limited to patent issues), conditions
|
||||
are imposed on you (whether by court order, agreement or otherwise) that
|
||||
contradict the conditions of this License, they do not excuse you from the
|
||||
conditions of this License. If you cannot distribute so as to satisfy
|
||||
simultaneously your obligations under this License and any other pertinent
|
||||
obligations, then as a consequence you may not distribute the Program at all.
|
||||
For example, if a patent license would not permit royalty-free redistribution
|
||||
of the Program by all those who receive copies directly or indirectly through
|
||||
you, then the only way you could satisfy both it and this License would be to
|
||||
refrain entirely from distribution of the Program.
|
||||
|
||||
If any portion of this section is held invalid or unenforceable under any
|
||||
particular circumstance, the balance of the section is intended to apply and
|
||||
the section as a whole is intended to apply in other circumstances.
|
||||
|
||||
It is not the purpose of this section to induce you to infringe any patents or
|
||||
other property right claims or to contest validity of any such claims; this
|
||||
section has the sole purpose of protecting the integrity of the free software
|
||||
distribution system, which is implemented by public license practices. Many
|
||||
people have made generous contributions to the wide range of software
|
||||
distributed through that system in reliance on consistent application of that
|
||||
system; it is up to the author/donor to decide if he or she is willing to
|
||||
distribute software through any other system and a licensee cannot impose
|
||||
that choice.
|
||||
|
||||
This section is intended to make thoroughly clear what is believed to be a
|
||||
consequence of the rest of this License.
|
||||
|
||||
8. If the distribution and/or use of the Program is restricted in certain
|
||||
countries either by patents or by copyrighted interfaces, the original copyright
|
||||
holder who places the Program under this License may add an explicit
|
||||
geographical distribution limitation excluding those countries, so that
|
||||
distribution is permitted only in or among countries not thus excluded. In such
|
||||
case, this License incorporates the limitation as if written in the body of this
|
||||
License.
|
||||
|
||||
9. The Free Software Foundation may publish revised and/or new versions
|
||||
of the General Public License from time to time. Such new versions will be
|
||||
similar in spirit to the present version, but may differ in detail to address new
|
||||
problems or concerns.
|
||||
|
||||
Each version is given a distinguishing version number. If the Program specifies
|
||||
a version number of this License which applies to it and "any later version",
|
||||
you have the option of following the terms and conditions either of that
|
||||
version or of any later version published by the Free Software Foundation. If
|
||||
the Program does not specify a version number of this License, you may
|
||||
choose any version ever published by the Free Software Foundation.
|
||||
|
||||
10. If you wish to incorporate parts of the Program into other free programs
|
||||
whose distribution conditions are different, write to the author to ask for
|
||||
permission. For software which is copyrighted by the Free Software
|
||||
Foundation, write to the Free Software Foundation; we sometimes make
|
||||
exceptions for this. Our decision will be guided by the two goals of
|
||||
preserving the free status of all derivatives of our free software and of
|
||||
promoting the sharing and reuse of software generally.
|
||||
|
||||
NO WARRANTY
|
||||
|
||||
11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE,
|
||||
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT
|
||||
PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE
|
||||
STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
|
||||
OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT
|
||||
WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED,
|
||||
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
|
||||
OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND
|
||||
PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE
|
||||
PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL
|
||||
NECESSARY SERVICING, REPAIR OR CORRECTION.
|
||||
|
||||
12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR
|
||||
AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR
|
||||
ANY OTHER PARTY WHO MAY MODIFY AND/OR
|
||||
REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE
|
||||
LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL,
|
||||
SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES
|
||||
ARISING OUT OF THE USE OR INABILITY TO USE THE
|
||||
PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA
|
||||
OR DATA BEING RENDERED INACCURATE OR LOSSES
|
||||
SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE
|
||||
PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN
|
||||
IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF
|
||||
THE POSSIBILITY OF SUCH DAMAGES.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
39
sites/all/modules/role_delegation/README.txt
Normal file
39
sites/all/modules/role_delegation/README.txt
Normal file
|
@ -0,0 +1,39 @@
|
|||
$Id: README.txt,v 1.8 2009/06/29 15:29:12 davidlesieur Exp $
|
||||
|
||||
README file for the Role Delegation Drupal module.
|
||||
|
||||
|
||||
Description
|
||||
***********
|
||||
|
||||
This module allows site administrators to grant some roles the authority to
|
||||
assign selected roles to users, without them needing the 'administer
|
||||
permissions' permission.
|
||||
|
||||
For each role, Role Delegation provides a new 'assign <ROLE> role' permission to
|
||||
allow the assignment of that role.
|
||||
|
||||
The module also adds an 'assign all roles' permission. Enabling this permission
|
||||
for a role is a convenient way to allow the assignment of any other role without
|
||||
having to check all the 'assign <ROLE> role' permissions in the Permissions
|
||||
page.
|
||||
|
||||
If an administrator has the 'administer users' permission, a role assignment
|
||||
widget gets displayed in the account creation or editing form. Otherwise, if he
|
||||
has at least the 'access user profiles' permission, the module adds its own
|
||||
'Roles' tab to the user profile so that roles can be assigned.
|
||||
|
||||
|
||||
Installation
|
||||
************
|
||||
|
||||
1. Extract the 'role_delegation' module directory, including all its
|
||||
subdirectories, into your Drupal modules directory.
|
||||
|
||||
2. Go to the Administer > Site building > Modules page, and enable the module.
|
||||
|
||||
3. Go to the Administer > User management > Permissions and scroll down to
|
||||
the role_delegation group of permissions. Each role now has a corresponding
|
||||
'assign <ROLE> role' permission. Grant this permission to roles that shall have
|
||||
the power to assign role ROLE to users.
|
||||
|
12
sites/all/modules/role_delegation/role_delegation.info
Normal file
12
sites/all/modules/role_delegation/role_delegation.info
Normal file
|
@ -0,0 +1,12 @@
|
|||
; $Id: role_delegation.info,v 1.2 2008/06/12 04:00:35 davidlesieur Exp $
|
||||
name = "Role Delegation"
|
||||
description = "Allows site administrators to grant some roles the authority to assign selected roles to users."
|
||||
core = "6.x"
|
||||
|
||||
|
||||
; Information added by drupal.org packaging script on 2010-12-09
|
||||
version = "6.x-1.4"
|
||||
core = "6.x"
|
||||
project = "role_delegation"
|
||||
datestamp = "1291919534"
|
||||
|
37
sites/all/modules/role_delegation/role_delegation.install
Normal file
37
sites/all/modules/role_delegation/role_delegation.install
Normal file
|
@ -0,0 +1,37 @@
|
|||
<?php
|
||||
// $Id: role_delegation.install,v 1.1.2.1 2009/12/31 06:27:45 davidlesieur Exp $
|
||||
|
||||
/**
|
||||
* Update permission names to allow non-English characters.
|
||||
* See http://drupal.org/node/510054.
|
||||
*/
|
||||
function role_delegation_update_6000() {
|
||||
$ret = array();
|
||||
$role_results = db_query('SELECT name FROM {role}');
|
||||
while ($role = db_fetch_object($role_results)) {
|
||||
// Check whether the assign role permission name has changed.
|
||||
if (preg_match('/[^a-zA-Z0-9 \\-_]/', $role->name)) {
|
||||
$old_role_name = preg_replace('/[^a-zA-Z0-9 \\-_]/', '', $role->name);
|
||||
$old_perm = "assign $old_role_name role";
|
||||
$new_perm = "assign {$role->name} role";
|
||||
|
||||
// Update permissions with the new name.
|
||||
$perm_results = db_query('SELECT * FROM {permission}');
|
||||
while ($perm_row = db_fetch_object($perm_results)) {
|
||||
$perms = explode(', ', $perm_row->perm);
|
||||
$changed = FALSE;
|
||||
foreach ($perms as $key => $perm) {
|
||||
if ($perm == $old_perm) {
|
||||
$perms[$key] = $new_perm;
|
||||
$changed = TRUE;
|
||||
}
|
||||
}
|
||||
if ($changed) {
|
||||
$perms = db_escape_string(implode(', ', $perms));
|
||||
$ret[] = update_sql("UPDATE {permission} SET perm = '$perms' WHERE pid = {$perm_row->pid}");
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return $ret;
|
||||
}
|
345
sites/all/modules/role_delegation/role_delegation.module
Normal file
345
sites/all/modules/role_delegation/role_delegation.module
Normal file
|
@ -0,0 +1,345 @@
|
|||
<?php
|
||||
// $Id: role_delegation.module,v 1.14.2.7 2010/12/09 18:25:31 andrewschulman Exp $
|
||||
|
||||
/**
|
||||
* @file
|
||||
*
|
||||
* This module allows site administrators to grant some roles the authority to
|
||||
* assign selected roles to users, without them needing the 'administer access
|
||||
* control' permission.
|
||||
*
|
||||
* It provides its own tab in the user profile so that roles can be assigned
|
||||
* without needing access to the user edit form.
|
||||
*/
|
||||
|
||||
/**
|
||||
* Implementation of hook_help().
|
||||
*/
|
||||
function role_delegation_help($section) {
|
||||
switch ($section) {
|
||||
case 'admin/help#role_delegation':
|
||||
return '<p>'. t('This module allows site administrators to grant some roles the authority to assign selected roles to users, without them needing the <em>administer permissions</em> permission.') .'</p><p>'. t('It provides its own tab in the user profile so that roles can be assigned without needing access to the user edit form.') .'</p>';
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of hook_perm().
|
||||
*/
|
||||
function role_delegation_perm() {
|
||||
$roles = _role_delegation_roles();
|
||||
$perms = array('assign all roles');
|
||||
foreach ($roles as $role) {
|
||||
$perms[] = _role_delegation_make_perm($role);
|
||||
}
|
||||
return $perms;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of hook_menu().
|
||||
*/
|
||||
function role_delegation_menu() {
|
||||
global $user;
|
||||
$items = array();
|
||||
|
||||
$items['user/%user/roles'] = array(
|
||||
'title' => 'Roles',
|
||||
'page callback' => 'drupal_get_form',
|
||||
'page arguments' => array('role_delegation_roles_form', 1),
|
||||
'access callback' => 'role_delegation_access',
|
||||
'type' => MENU_LOCAL_TASK,
|
||||
);
|
||||
return $items;
|
||||
}
|
||||
|
||||
/**
|
||||
* Provides a form for assigning roles to the current user.
|
||||
*/
|
||||
function role_delegation_roles_form(&$form_state, $account) {
|
||||
$form['roles'] = array(
|
||||
'#type' => 'fieldset',
|
||||
'#title' => t('Roles'),
|
||||
'#tree' => TRUE,
|
||||
);
|
||||
// Provide a separate checkbox for each role but hide those the user has no authority over.
|
||||
$roles = _role_delegation_roles();
|
||||
$roles_preserve = array('authenticated user');
|
||||
foreach ($roles as $rid => $role) {
|
||||
if (!(user_access('assign all roles') || user_access(_role_delegation_make_perm($role)) || user_access('administer permissions'))) {
|
||||
// Hide roles the user can't assign.
|
||||
$form['roles'][$rid] = array(
|
||||
'#type' => 'value',
|
||||
'#value' => isset($account->roles[$rid]),
|
||||
);
|
||||
if (isset($account->roles[$rid])) {
|
||||
$roles_preserve[] = $role;
|
||||
}
|
||||
}
|
||||
else {
|
||||
$form['roles'][$rid] = array(
|
||||
'#type' => 'checkbox',
|
||||
'#title' => check_plain($role),
|
||||
'#default_value' => isset($account->roles[$rid]),
|
||||
);
|
||||
}
|
||||
}
|
||||
$form['roles']['#description'] = t('The user receives the combined permissions of the %roles role(s), and all roles selected here. ', array('%roles' => implode(', ', $roles_preserve)));
|
||||
$form['account'] = array(
|
||||
'#type' => 'value',
|
||||
'#value' => $account,
|
||||
);
|
||||
$form['submit'] = array(
|
||||
'#type' => 'submit',
|
||||
'#value' => t('Submit'),
|
||||
);
|
||||
|
||||
drupal_set_title(check_plain($account->name));
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Saves the roles assigned to the account given in the form.
|
||||
*/
|
||||
function role_delegation_roles_form_submit($form, &$form_state) {
|
||||
if (is_array($form_state['values']['roles']) && isset($form_state['values']['account']->uid)) {
|
||||
$account = user_load(array('uid' => (int)$form_state['values']['account']->uid));
|
||||
$myroles = array();
|
||||
$rolenames = user_roles(TRUE);
|
||||
foreach (array_keys(array_filter($form_state['values']['roles'])) as $rid) {
|
||||
$myroles[$rid] = $rolenames[$rid];
|
||||
}
|
||||
user_save($account, array('roles' => $myroles));
|
||||
|
||||
// Delete the user's menu cache.
|
||||
cache_clear_all($form_state['values']['account']->uid .':', 'cache_menu', TRUE);
|
||||
|
||||
drupal_set_message(t('The roles have been updated.'));
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Access callback for menu hook.
|
||||
*/
|
||||
function role_delegation_access() {
|
||||
// Check access to user profile page.
|
||||
if (!user_access('access user profiles')) {
|
||||
return FALSE;
|
||||
}
|
||||
// Check if they can edit users. In that case, the Roles tab is not needed.
|
||||
if (user_access('administer users')) {
|
||||
return FALSE;
|
||||
}
|
||||
// Check access to role assignment page.
|
||||
if (user_access('administer permissions')) {
|
||||
return TRUE;
|
||||
}
|
||||
$perms = role_delegation_perm();
|
||||
foreach ($perms as $perm) {
|
||||
if (user_access($perm)) {
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns all existing roles, except anonymous and authenticated user.
|
||||
*/
|
||||
function _role_delegation_roles() {
|
||||
$roles = user_roles(TRUE);
|
||||
unset($roles[DRUPAL_AUTHENTICATED_RID]);
|
||||
return $roles;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns the delegation permission for a role.
|
||||
*/
|
||||
function _role_delegation_make_perm($role) {
|
||||
return "assign $role role";
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Implementation of hook_form_FORM_ID_alter() for user_admin_role().
|
||||
*/
|
||||
function role_delegation_form_user_admin_role_alter(&$form, $form_state)
|
||||
{
|
||||
// Put our submit function in line ahead of user_admin_role_submit(),
|
||||
// so that it can make use of the old role name before it's changed to the new.
|
||||
array_unshift($form['#submit'], 'role_delegation_form_user_admin_role_submit');
|
||||
}
|
||||
|
||||
/**
|
||||
* Submit function for the user_admin_role form:
|
||||
* When a role is renamed or deleted, rename or delete the permission
|
||||
* to assign that role.
|
||||
*/
|
||||
function role_delegation_form_user_admin_role_submit($form, &$form_state) {
|
||||
$op = $form_state['values']['op'];
|
||||
if ($op != t('Save role') && $op != t('Delete role')) {
|
||||
return;
|
||||
}
|
||||
$rid = $form_state['values']['rid'];
|
||||
$oldrole = db_result(db_query('SELECT name FROM {role} WHERE rid = %d', $rid));
|
||||
$newrole = $form_state['values']['name'];
|
||||
if ($op == t('Save role') && $oldrole == $newrole) {
|
||||
return;
|
||||
}
|
||||
// Role is being renamed or deleted.
|
||||
// Loop through permission lists for all roles, renaming or deleting the
|
||||
// 'assign' permission for this role.
|
||||
$oldperm = _role_delegation_make_perm($oldrole);
|
||||
$result = db_query('SELECT * FROM {permission}');
|
||||
while ($row = db_fetch_object($result)) {
|
||||
$perms = explode(', ', $row->perm);
|
||||
for ($i = 0; $i < count($perms); ++$i) {
|
||||
if ($perms[$i] == $oldperm) {
|
||||
switch ($op) {
|
||||
case t('Save role'):
|
||||
$perms[$i] = _role_delegation_make_perm($newrole);
|
||||
break;
|
||||
case t('Delete role'):
|
||||
unset($perms[$i]);
|
||||
break;
|
||||
}
|
||||
if (count($perms)) {
|
||||
db_query("UPDATE {permission} SET perm = '%s' WHERE pid = %d",
|
||||
implode(', ', $perms), $row->pid);
|
||||
} else {
|
||||
db_query("DELETE FROM {permission} WHERE pid = %d", $row->pid);
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of hook_user().
|
||||
*/
|
||||
function role_delegation_user($op, &$edit, &$account, $category = NULL) {
|
||||
if ($op == 'register' || ($op == 'form' && $category == 'account')) {
|
||||
// Only alter user form when user can't assign permissions without Role Delegation.
|
||||
if (!user_access('administer permissions')) {
|
||||
// Split up roles based on whether they can be delegated or not.
|
||||
$current_roles = isset($account->roles) ? $account->roles : array();
|
||||
$rids_default = array();
|
||||
$rids_preserve = array(DRUPAL_AUTHENTICATED_RID => DRUPAL_AUTHENTICATED_RID);
|
||||
$roles_preserve = array('authenticated user');
|
||||
$roles_options = array();
|
||||
$roles = _role_delegation_roles();
|
||||
foreach ($roles as $rid => $role) {
|
||||
if (user_access('assign all roles') || user_access(_role_delegation_make_perm($role))) {
|
||||
if (array_key_exists($rid, $current_roles)) {
|
||||
$rids_default[] = $rid;
|
||||
}
|
||||
$roles_options[$rid] = $role;
|
||||
}
|
||||
else {
|
||||
if (array_key_exists($rid, $current_roles)) {
|
||||
$rids_preserve[$rid] = $rid;
|
||||
$roles_preserve[] = $role;
|
||||
}
|
||||
}
|
||||
}
|
||||
if (empty($roles_options)) {
|
||||
// No role can be assigned.
|
||||
return;
|
||||
}
|
||||
// Generate the form items.
|
||||
$form['roles_preserve'] = array(
|
||||
'#type' => 'value',
|
||||
'#value' => $rids_preserve,
|
||||
);
|
||||
$roles_assign = array(
|
||||
'#type' => 'checkboxes',
|
||||
'#title' => t('Roles'),
|
||||
'#description' => t('The user receives the combined permissions of the %roles role(s), and all roles selected here. ', array('%roles' => implode(', ', $roles_preserve))),
|
||||
'#options' => $roles_options,
|
||||
'#default_value' => $rids_default,
|
||||
'#weight' => 10,
|
||||
);
|
||||
if ($op == 'register') {
|
||||
// Since the user module does array_merge() instead of array_merge_recursive() (see bug http://drupal.org/node/227690),
|
||||
// we must move this under 'account' later at role_delegation_form_user_register_alter()
|
||||
$form['roles_assign'] = $roles_assign;
|
||||
}
|
||||
else {
|
||||
$form['account']['roles_assign'] = $roles_assign;
|
||||
}
|
||||
return $form;
|
||||
}
|
||||
}
|
||||
elseif (isset($edit['roles_assign']) && ($op == 'insert' || $op == 'submit')) {
|
||||
$edit['roles'] = $edit['roles_preserve'] + array_filter($edit['roles_assign']);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of hook_form_FORM_ID_alter() for user_register().
|
||||
*/
|
||||
function role_delegation_form_user_register_alter(&$form, $form_state) {
|
||||
// Move our field where it belongs
|
||||
if (isset($form['roles_assign'])) {
|
||||
$form['account']['roles_assign'] = $form['roles_assign'];
|
||||
unset($form['roles_assign']);
|
||||
$form['account']['notify']['#weight'] = 11;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of hook_user_operations().
|
||||
*/
|
||||
function role_delegation_user_operations($form_state = array()) {
|
||||
// Only provide role add/remove operations when user can't assign permissions
|
||||
// without Role Delegation.
|
||||
if (user_access('administer permissions')) {
|
||||
return;
|
||||
}
|
||||
|
||||
// Provide add/remove operations for delegated roles.
|
||||
$roles = _role_delegation_roles();
|
||||
$add_roles = array();
|
||||
$remove_roles = array();
|
||||
foreach ($roles as $rid => $role) {
|
||||
if (user_access('assign all roles') || user_access(_role_delegation_make_perm($role))) {
|
||||
// Use different operation names than those from user_user_operations(),
|
||||
// to keep user_user_operations() from emitting a warning about the
|
||||
// permissions.
|
||||
$add_roles['role_delegation_add_role-' . $rid] = $role;
|
||||
$remove_roles['role_delegation_remove_role-' . $rid] = $role;
|
||||
}
|
||||
}
|
||||
if (!count($add_roles)) {
|
||||
return;
|
||||
}
|
||||
$operations = array(
|
||||
t('Add a role to the selected users') => array(
|
||||
'label' => $add_roles,
|
||||
),
|
||||
t('Remove a role from the selected users') => array(
|
||||
'label' => $remove_roles,
|
||||
),
|
||||
);
|
||||
|
||||
// If the form has been posted, insert the proper data for role editing if necessary.
|
||||
if (!empty($form_state['submitted'])) {
|
||||
$operation_rid = explode('-', $form_state['values']['operation']);
|
||||
$operation = $operation_rid[0];
|
||||
if ($operation == 'role_delegation_add_role' || $operation == 'role_delegation_remove_role') {
|
||||
$rid = $operation_rid[1];
|
||||
if ($add_roles['role_delegation_add_role-' . $rid]) {
|
||||
$operations[$form_state['values']['operation']] = array(
|
||||
'callback' => 'user_multiple_role_edit',
|
||||
'callback arguments' => array(str_replace('role_delegation_', '', $operation), $rid),
|
||||
);
|
||||
}
|
||||
else {
|
||||
watchdog('security', 'Detected malicious attempt to alter protected user fields.', array(), WATCHDOG_WARNING);
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return $operations;
|
||||
}
|
57
sites/all/modules/role_delegation/translations/fr.po
Normal file
57
sites/all/modules/role_delegation/translations/fr.po
Normal file
|
@ -0,0 +1,57 @@
|
|||
# $Id: fr.po,v 1.1 2009/05/13 17:37:59 davidlesieur Exp $
|
||||
#
|
||||
# LANGUAGE translation of Drupal (general)
|
||||
# Copyright YEAR NAME <EMAIL@ADDRESS>
|
||||
# Generated from files:
|
||||
# role_delegation.module,v 1.9 2009/03/03 01:42:29 davidlesieur
|
||||
# role_delegation.info,v 1.2 2008/06/12 04:00:35 davidlesieur
|
||||
#
|
||||
msgid ""
|
||||
msgstr ""
|
||||
"Project-Id-Version: role_delegation\n"
|
||||
"POT-Creation-Date: 2009-05-13 18:35+0200\n"
|
||||
"PO-Revision-Date: 2009-05-13 18:50+0100\n"
|
||||
"Last-Translator: TheRec <anonymous@anonymous.net>\n"
|
||||
"Language-Team: NONE <EMAIL@ADDRESS>\n"
|
||||
"MIME-Version: 1.0\n"
|
||||
"Content-Type: text/plain; charset=utf-8\n"
|
||||
"Content-Transfer-Encoding: 8bit\n"
|
||||
"Plural-Forms: nplurals=2; plural=(n > 1) \n"
|
||||
"X-Poedit-Language: French\n"
|
||||
|
||||
#: role_delegation.module:21
|
||||
msgid "This module allows site administrators to grant some roles the authority to assign selected roles to users, without them needing the <em>administer permissions</em> permission."
|
||||
msgstr "Ce module permet aux administrateurs du site d'attribuer aux rôles l'autorité d'assigner des rôles définis aux utilisateurs, sans qu'ils ne nécessitent la droit d'accès <em>administrer les droits d'accès</em>."
|
||||
|
||||
#: role_delegation.module:21
|
||||
msgid "It provides its own tab in the user profile so that roles can be assigned without needing access to the user edit form."
|
||||
msgstr "Il met à disposition son propre onglet dans le profil utilisateur afin que ces rôles puissent être assignés sans requérir d'accéder au formulaire d'édition de l'utilisateur."
|
||||
|
||||
#: role_delegation.module:45;61
|
||||
msgid "Roles"
|
||||
msgstr "Rôles"
|
||||
|
||||
#: role_delegation.module:62
|
||||
msgid "The user receives the combined permissions of the authenticated user role, and all roles selected here."
|
||||
msgstr "L'utilisateur reçoit les permissions combinées du rôle d'utilisateur identifié et celles de tous les rôles sélectionnés ici."
|
||||
|
||||
#: role_delegation.module:89
|
||||
msgid "Submit"
|
||||
msgstr "Soumettre"
|
||||
|
||||
#: role_delegation.module:112
|
||||
msgid "The roles have been updated."
|
||||
msgstr "Les rôles ont été mis à jour."
|
||||
|
||||
#: role_delegation.module:30
|
||||
msgid "assign all roles"
|
||||
msgstr "assigner tous les rôles"
|
||||
|
||||
#: role_delegation.info:0
|
||||
msgid "Role Delegation"
|
||||
msgstr "Role Delegation"
|
||||
|
||||
#: role_delegation.info:0
|
||||
msgid "Allows site administrators to grant some roles the authority to assign selected roles to users."
|
||||
msgstr "Permet aux administrateurs du site d'attribuer aux rôles l'autorité d'assigner des rôles définis aux utilisateurs."
|
||||
|
Reference in a new issue