diff --git a/application/Espo/Controllers/Preferences.php b/application/Espo/Controllers/Preferences.php index 5e1a1d4829..c7128bcf1e 100644 --- a/application/Espo/Controllers/Preferences.php +++ b/application/Espo/Controllers/Preferences.php @@ -29,183 +29,79 @@ namespace Espo\Controllers; -use Espo\Core\Exceptions\Error; -use Espo\Core\Exceptions\Forbidden; -use Espo\Core\Exceptions\BadRequest; -use Espo\Core\Exceptions\NotFound; - use Espo\Core\{ - Controllers\Base, + Exceptions\BadRequest, Api\Request, - Di, }; +use Espo\Services\Preferences as Service; + use StdClass; -class Preferences extends Base implements - - Di\EntityManagerAware, - Di\CryptAware +class Preferences { - use Di\EntityManagerSetter; - use Di\CryptSetter; + private $service; - protected $entityManager; - - protected $crypt; - - protected function handleUserAccess(string $userId): void + public function __construct(Service $service) { - if (!$this->user->isAdmin()) { - if ($this->user->getId() != $userId) { - throw new Forbidden(); - } - } - } - - public function deleteActionDelete(Request $request): StdClass - { - $params = $request->getRouteParams(); - - $userId = $params['id']; - - if (empty($userId)) { - throw new BadRequest(); - } - - $this->handleUserAccess($userId); - - $result = $this->entityManager - ->getRepository('Preferences') - ->resetToDefaults($userId); - - if (!$result) { - throw new NotFound(); - } - - return $result; - } - - public function putActionUpdate(Request $request): StdClass - { - $params = $request->getRouteParams(); - - $data = $request->getParsedBody(); - - $userId = $params['id']; - - $this->handleUserAccess($userId); - - if ($this->acl->getLevel('Preferences', 'edit') === 'no') { - throw new Forbidden(); - } - - foreach ($this->acl->getScopeForbiddenAttributeList('Preferences', 'edit') as $attribute) { - unset($data->$attribute); - } - - if (property_exists($data, 'smtpPassword')) { - $data->smtpPassword = $this->crypt->encrypt($data->smtpPassword); - } - - $user = $this->entityManager->getEntity('User', $userId); - - $entity = $this->entityManager->getEntity('Preferences', $userId); - - if ($entity && $user) { - $entity->set($data); - - $this->entityManager->saveEntity($entity); - - $entity->set('smtpEmailAddress', $user->get('emailAddress')); - $entity->set('name', $user->get('name')); - - $entity->clear('smtpPassword'); - - return $entity->getValueMap(); - } - - throw new Error(); + $this->service = $service; } public function getActionRead(Request $request): StdClass { - $params = $request->getRouteParams(); + $userId = $request->getRouteParam('id'); - $userId = $params['id']; - - $this->handleUserAccess($userId); - - $entity = $this->entityManager->getEntity('Preferences', $userId); - $user = $this->entityManager->getEntity('User', $userId); - - if (!$entity || !$user) { - throw new NotFound(); + if (!$userId) { + throw new BadRequest(); } - $entity->set('smtpEmailAddress', $user->get('emailAddress')); - $entity->set('name', $user->get('name')); - $entity->set('isPortalUser', $user->isPortal()); + return $this->service->read($userId)->getValueMap(); + } - $entity->clear('smtpPassword'); + public function deleteActionDelete(Request $request): StdClass + { + $userId = $request->getRouteParam('id'); - foreach ($this->acl->getScopeForbiddenAttributeList('Preferences', 'read') as $attribute) { - $entity->clear($attribute); + if (!$userId) { + throw new BadRequest(); } - return $entity->getValueMap(); + $this->service->resetToDefaults($userId); + + return $this->service + ->read($userId) + ->getValueMap(); + } + + public function putActionUpdate(Request $request): StdClass + { + $userId = $request->getRouteParam('id'); + + if (!$userId) { + throw new BadRequest(); + } + + $data = $request->getParsedBody(); + + if (!$userId) { + throw new BadRequest(); + } + + return $this->service + ->update($userId, $data) + ->getValueMap(); } public function postActionResetDashboard(Request $request): StdClass { $data = $request->getParsedBody(); - if (empty($data->id)) { + $userId = $data->id ?? null; + + if (!$userId) { throw new BadRequest(); } - $userId = $data->id; - - $this->handleUserAccess($userId); - - $user = $this->entityManager->getEntity('User', $userId); - $preferences = $this->entityManager->getEntity('Preferences', $userId); - - if (!$user) { - throw new NotFound(); - } - - if (!$preferences) { - throw new NotFound(); - } - - if ($user->isPortal()) { - throw new Forbidden(); - } - - if ($this->acl->getLevel('Preferences', 'edit') === 'no') { - throw new Forbidden(); - } - - $forbiddenAttributeList = $this->acl->getScopeForbiddenAttributeList('Preferences', 'edit'); - - if (in_array('dashboardLayout', $forbiddenAttributeList)) { - throw new Forbidden(); - } - - $dashboardLayout = $this->config->get('dashboardLayout'); - $dashletsOptions = $this->config->get('dashletsOptions'); - - $preferences->set([ - 'dashboardLayout' => $dashboardLayout, - 'dashletsOptions' => $dashletsOptions, - ]); - - $this->entityManager->saveEntity($preferences); - - return (object) [ - 'dashboardLayout' => $preferences->get('dashboardLayout'), - 'dashletsOptions' => $preferences->get('dashletsOptions'), - ]; + return $this->service->resetDashboard($userId); } } diff --git a/application/Espo/Services/Preferences.php b/application/Espo/Services/Preferences.php new file mode 100644 index 0000000000..7e258ba3e1 --- /dev/null +++ b/application/Espo/Services/Preferences.php @@ -0,0 +1,210 @@ +entityManager = $entityManager; + $this->user = $user; + $this->crypt = $crypt; + $this->acl = $acl; + $this->config = $config; + } + + protected function processAccessCheck(string $userId): void + { + if (!$this->user->isAdmin()) { + if ($this->user->getId() !== $userId) { + throw new Forbidden(); + } + } + } + + public function read(string $userId): PreferencesEntity + { + $this->processAccessCheck($userId); + + $entity = $this->entityManager->getEntity('Preferences', $userId); + $user = $this->entityManager->getEntity('User', $userId); + + if (!$entity || !$user) { + throw new NotFound(); + } + + $entity->set('smtpEmailAddress', $user->get('emailAddress')); + $entity->set('name', $user->get('name')); + $entity->set('isPortalUser', $user->isPortal()); + + $entity->clear('smtpPassword'); + + $fobiddenAttributeList = $this->acl + ->getScopeForbiddenAttributeList('Preferences', Table::ACTION_READ); + + foreach ($fobiddenAttributeList as $attribute) { + $entity->clear($attribute); + } + + return $entity; + } + + public function update(string $userId, StdClass $data): PreferencesEntity + { + $this->processAccessCheck($userId); + + if ($this->acl->getLevel('Preferences', Table::ACTION_EDIT) === Table::LEVEL_NO) { + throw new Forbidden(); + } + + $fobiddenAttributeList = $this->acl + ->getScopeForbiddenAttributeList('Preferences', Table::ACTION_EDIT); + + foreach ($fobiddenAttributeList as $attribute) { + unset($data->$attribute); + } + + if (property_exists($data, 'smtpPassword')) { + $data->smtpPassword = $this->crypt->encrypt($data->smtpPassword); + } + + $user = $this->entityManager->getEntity('User', $userId); + + $entity = $this->entityManager->getEntity('Preferences', $userId); + + if (!$entity || !$user) { + throw new NotFound(); + } + + $entity->set($data); + + $this->entityManager->saveEntity($entity); + + $entity->set('smtpEmailAddress', $user->get('emailAddress')); + $entity->set('name', $user->get('name')); + + $entity->clear('smtpPassword'); + + return $entity; + } + + public function resetToDefaults(string $userId): void + { + $this->processAccessCheck($userId); + + $result = $this->entityManager + ->getRepository('Preferences') + ->resetToDefaults($userId); + + if (!$result) { + throw new NotFound(); + } + } + + public function resetDashboard(string $userId): StdClass + { + $this->processAccessCheck($userId); + + if ($this->acl->getLevel('Preferences', Table::ACTION_EDIT) === Table::LEVEL_NO) { + throw new Forbidden(); + } + + $user = $this->entityManager->getEntity('User', $userId); + + $preferences = $this->entityManager->getEntity('Preferences', $userId); + + if (!$user) { + throw new NotFound(); + } + + if (!$preferences) { + throw new NotFound(); + } + + if ($user->isPortal()) { + throw new Forbidden(); + } + + $forbiddenAttributeList = $this->acl + ->getScopeForbiddenAttributeList('Preferences', Table::ACTION_EDIT); + + if (in_array('dashboardLayout', $forbiddenAttributeList)) { + throw new Forbidden(); + } + + $dashboardLayout = $this->config->get('dashboardLayout'); + $dashletsOptions = $this->config->get('dashletsOptions'); + + $preferences->set([ + 'dashboardLayout' => $dashboardLayout, + 'dashletsOptions' => $dashletsOptions, + ]); + + $this->entityManager->saveEntity($preferences); + + return (object) [ + 'dashboardLayout' => $preferences->get('dashboardLayout'), + 'dashletsOptions' => $preferences->get('dashletsOptions'), + ]; + } +}