entityManager = $entityManager; $this->user = $user; $this->crypt = $crypt; $this->acl = $acl; $this->config = $config; } protected function processAccessCheck(string $userId): void { if (!$this->user->isAdmin()) { if ($this->user->getId() !== $userId) { throw new Forbidden(); } } } public function read(string $userId): PreferencesEntity { $this->processAccessCheck($userId); /** @var ?PreferencesEntity $entity */ $entity = $this->entityManager->getEntity('Preferences', $userId); /** @var ?User $user */ $user = $this->entityManager->getEntity('User', $userId); if (!$entity || !$user) { throw new NotFound(); } $entity->set('smtpEmailAddress', $user->get('emailAddress')); $entity->set('name', $user->get('name')); $entity->set('isPortalUser', $user->isPortal()); $entity->clear('smtpPassword'); $fobiddenAttributeList = $this->acl ->getScopeForbiddenAttributeList('Preferences', Table::ACTION_READ); foreach ($fobiddenAttributeList as $attribute) { $entity->clear($attribute); } return $entity; } public function update(string $userId, stdClass $data): PreferencesEntity { $this->processAccessCheck($userId); if ($this->acl->getLevel('Preferences', Table::ACTION_EDIT) === Table::LEVEL_NO) { throw new Forbidden(); } $fobiddenAttributeList = $this->acl ->getScopeForbiddenAttributeList('Preferences', Table::ACTION_EDIT); foreach ($fobiddenAttributeList as $attribute) { unset($data->$attribute); } if (property_exists($data, 'smtpPassword')) { $data->smtpPassword = $this->crypt->encrypt($data->smtpPassword); } $user = $this->entityManager->getEntity('User', $userId); /** @var ?PreferencesEntity */ $entity = $this->entityManager->getEntity('Preferences', $userId); if (!$entity || !$user) { throw new NotFound(); } $entity->set($data); $this->entityManager->saveEntity($entity); $entity->set('smtpEmailAddress', $user->get('emailAddress')); $entity->set('name', $user->get('name')); $entity->clear('smtpPassword'); return $entity; } public function resetToDefaults(string $userId): void { $this->processAccessCheck($userId); $result = $this->getRepository()->resetToDefaults($userId); if (!$result) { throw new NotFound(); } } public function resetDashboard(string $userId): stdClass { $this->processAccessCheck($userId); if ($this->acl->getLevel('Preferences', Table::ACTION_EDIT) === Table::LEVEL_NO) { throw new Forbidden(); } /** @var ?User $user */ $user = $this->entityManager->getEntity('User', $userId); $preferences = $this->entityManager->getEntity('Preferences', $userId); if (!$user) { throw new NotFound(); } if (!$preferences) { throw new NotFound(); } if ($user->isPortal()) { throw new Forbidden(); } $forbiddenAttributeList = $this->acl ->getScopeForbiddenAttributeList('Preferences', Table::ACTION_EDIT); if (in_array('dashboardLayout', $forbiddenAttributeList)) { throw new Forbidden(); } $dashboardLayout = $this->config->get('dashboardLayout'); $dashletsOptions = $this->config->get('dashletsOptions'); $preferences->set([ 'dashboardLayout' => $dashboardLayout, 'dashletsOptions' => $dashletsOptions, ]); $this->entityManager->saveEntity($preferences); return (object) [ 'dashboardLayout' => $preferences->get('dashboardLayout'), 'dashletsOptions' => $preferences->get('dashletsOptions'), ]; } private function getRepository(): Repository { /** @var Repository */ return $this->entityManager->getRepository(PreferencesEntity::ENTITY_TYPE); } }