Difference between revisions of "Extension:SimpleSecurity2.1.php"
(allow wildcard for user/groups too) |
|||
Line 11: | Line 11: | ||
} else $t = $title; | } else $t = $title; | ||
− | # Extract security information from article | + | # Extract security information for this action from this article |
$security = ''; | $security = ''; | ||
$text = new Article(Title::newFromText($t)); | $text = new Article(Title::newFromText($t)); | ||
Line 22: | Line 22: | ||
} | } | ||
− | # | + | # Validate extracted security against this user/groups |
− | if ($security) { | + | $security = preg_split("/\\s*,\\s*/",$security); |
+ | if (count($security) && !in_array('*',$security)) { | ||
$groups[] = ucwords($wgUser->mName); | $groups[] = ucwords($wgUser->mName); | ||
− | |||
if (count(array_intersect($groups,$security))==0) { | if (count(array_intersect($groups,$security))==0) { | ||
$action = 'view'; | $action = 'view'; |
Revision as of 07:36, 27 November 2006
<?
- Security
$groups = $wgUser->getGroups(); if (!in_array('sysop',$groups)&&!in_array('directors',$groups)) {
# Handle moves and submits $a = $action == 'submit' ? 'edit' : $action; if ($title=='Special:Movepage' && $action=='submit') { $a = 'move'; $t = $wgRequest->getText('wpOldTitle',$wgRequest->getVal('target')); } else $t = $title;
# Extract security information for this action from this article $security = ; $text = new Article(Title::newFromText($t)); $text = $text->fetchContent(0, false, false); preg_match_all("/\\[{2}\\s*security\\s*:\\s*([^\\]]+?)\\s*\\|\\s*([^\\]]+?)\\s*\\]{2}/i",$text,$matches,PREG_SET_ORDER); foreach ($matches as $m) { $actions = preg_split("/\\s*,\\s*/",$m[1]); if (in_array($a,$actions)) $security = $m[2]; if (in_array('*',$actions) && ($security == )) $security = $m[2]; }
# Validate extracted security against this user/groups $security = preg_split("/\\s*,\\s*/",$security); if (count($security) && !in_array('*',$security)) { $groups[] = ucwords($wgUser->mName); if (count(array_intersect($groups,$security))==0) { $action = 'view'; $title = 'Action not permitted'; } } }
- Remove the security links before wiki-parsing
$wgHooks['ParserBeforeStrip'][] = 'securityRemoveLinks'; function securityRemoveLinks(&$parser, &$text, &$strip_state) { $text = preg_replace("/\\[{2}\\s*security\\s*:[^\\]]+?\\]{2}[\r\n]?/i",,$text); } ?>