user->isAdmin()) { if ($this->user->getId() != $userId) { throw new Forbidden(); } } } public function deleteActionDelete(Request $request): StdClass { $params = $request->getRouteParams(); $userId = $params['id']; if (empty($userId)) { throw new BadRequest(); } $this->handleUserAccess($userId); $result = $this->entityManager ->getRepository('Preferences') ->resetToDefaults($userId); if (!$result) { throw new NotFound(); } return $result; } public function putActionUpdate(Request $request): StdClass { $params = $request->getRouteParams(); $data = $request->getParsedBody(); $userId = $params['id']; $this->handleUserAccess($userId); if ($this->acl->getLevel('Preferences', 'edit') === 'no') { throw new Forbidden(); } foreach ($this->acl->getScopeForbiddenAttributeList('Preferences', 'edit') as $attribute) { unset($data->$attribute); } if (property_exists($data, 'smtpPassword')) { $data->smtpPassword = $this->crypt->encrypt($data->smtpPassword); } $user = $this->entityManager->getEntity('User', $userId); $entity = $this->entityManager->getEntity('Preferences', $userId); if ($entity && $user) { $entity->set($data); $this->entityManager->saveEntity($entity); $entity->set('smtpEmailAddress', $user->get('emailAddress')); $entity->set('name', $user->get('name')); $entity->clear('smtpPassword'); return $entity->getValueMap(); } throw new Error(); } public function getActionRead(Request $request): StdClass { $params = $request->getRouteParams(); $userId = $params['id']; $this->handleUserAccess($userId); $entity = $this->entityManager->getEntity('Preferences', $userId); $user = $this->entityManager->getEntity('User', $userId); if (!$entity || !$user) { throw new NotFound(); } $entity->set('smtpEmailAddress', $user->get('emailAddress')); $entity->set('name', $user->get('name')); $entity->set('isPortalUser', $user->isPortal()); $entity->clear('smtpPassword'); foreach ($this->acl->getScopeForbiddenAttributeList('Preferences', 'read') as $attribute) { $entity->clear($attribute); } return $entity->getValueMap(); } public function postActionResetDashboard(Request $request): StdClass { $data = $request->getParsedBody(); if (empty($data->id)) { throw new BadRequest(); } $userId = $data->id; $this->handleUserAccess($userId); $user = $this->entityManager->getEntity('User', $userId); $preferences = $this->entityManager->getEntity('Preferences', $userId); if (!$user) { throw new NotFound(); } if (!$preferences) { throw new NotFound(); } if ($user->isPortal()) { throw new Forbidden(); } if ($this->acl->getLevel('Preferences', 'edit') === 'no') { throw new Forbidden(); } $forbiddenAttributeList = $this->acl->getScopeForbiddenAttributeList('Preferences', 'edit'); if (in_array('dashboardLayout', $forbiddenAttributeList)) { throw new Forbidden(); } $dashboardLayout = $this->config->get('dashboardLayout'); $dashletsOptions = $this->config->get('dashletsOptions'); $preferences->set([ 'dashboardLayout' => $dashboardLayout, 'dashletsOptions' => $dashletsOptions, ]); $this->entityManager->saveEntity($preferences); return (object) [ 'dashboardLayout' => $preferences->get('dashboardLayout'), 'dashletsOptions' => $preferences->get('dashletsOptions'), ]; } }