Difference between revisions of "Extension:SimpleSecurity2.1.php"

From Organic Design wiki
(allow wildcard for user/groups too)
Line 11: Line 11:
 
} else $t = $title;
 
} else $t = $title;
  
# Extract security information from article
+
# Extract security information for this action from this article
 
$security = '';
 
$security = '';
 
$text = new Article(Title::newFromText($t));
 
$text = new Article(Title::newFromText($t));
Line 22: Line 22:
 
}
 
}
  
# Redirect if permission violated
+
# Validate extracted security against this user/groups
if ($security) {
+
$security = preg_split("/\\s*,\\s*/",$security);
 +
if (count($security) && !in_array('*',$security)) {
 
$groups[] = ucwords($wgUser->mName);
 
$groups[] = ucwords($wgUser->mName);
$security = preg_split("/\\s*,\\s*/",$security);
 
 
if (count(array_intersect($groups,$security))==0) {
 
if (count(array_intersect($groups,$security))==0) {
 
$action = 'view';
 
$action = 'view';

Revision as of 07:36, 27 November 2006

<?

  1. Security

$groups = $wgUser->getGroups(); if (!in_array('sysop',$groups)&&!in_array('directors',$groups)) {

# Handle moves and submits $a = $action == 'submit' ? 'edit' : $action; if ($title=='Special:Movepage' && $action=='submit') { $a = 'move'; $t = $wgRequest->getText('wpOldTitle',$wgRequest->getVal('target')); } else $t = $title;

# Extract security information for this action from this article $security = ; $text = new Article(Title::newFromText($t)); $text = $text->fetchContent(0, false, false); preg_match_all("/\\[{2}\\s*security\\s*:\\s*([^\\]]+?)\\s*\\|\\s*([^\\]]+?)\\s*\\]{2}/i",$text,$matches,PREG_SET_ORDER); foreach ($matches as $m) { $actions = preg_split("/\\s*,\\s*/",$m[1]); if (in_array($a,$actions)) $security = $m[2]; if (in_array('*',$actions) && ($security == )) $security = $m[2]; }

# Validate extracted security against this user/groups $security = preg_split("/\\s*,\\s*/",$security); if (count($security) && !in_array('*',$security)) { $groups[] = ucwords($wgUser->mName); if (count(array_intersect($groups,$security))==0) { $action = 'view'; $title = 'Action not permitted'; } } }

  1. Remove the security links before wiki-parsing

$wgHooks['ParserBeforeStrip'][] = 'securityRemoveLinks'; function securityRemoveLinks(&$parser, &$text, &$strip_state) { $text = preg_replace("/\\[{2}\\s*security\\s*:[^\\]]+?\\]{2}[\r\n]?/i",,$text); } ?>