GroupPrincipalBackend.php 8.1 KB


  1. <?php
  2. /**
  3. * @copyright Copyright (c) 2016, ownCloud, Inc.
  4. * @copyright Copyright (c) 2018, Georg Ehrke
  5. *
  6. * @author Roeland Jago Douma <roeland@famdouma.nl>
  7. * @author Thomas Müller <thomas.mueller@tmit.eu>
  8. * @author Georg Ehrke <oc.list@georgehrke.com>
  9. *
  10. * @license AGPL-3.0
  11. *
  12. * This code is free software: you can redistribute it and/or modify
  13. * it under the terms of the GNU Affero General Public License, version 3,
  14. * as published by the Free Software Foundation.
  15. *
  16. * This program is distributed in the hope that it will be useful,
  17. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  18. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  19. * GNU Affero General Public License for more details.
  20. *
  21. * You should have received a copy of the GNU Affero General Public License, version 3,
  22. * along with this program. If not, see <http://www.gnu.org/licenses/>
  23. *
  24. */
  25. namespace OCA\DAV\DAV;
  26. use OCP\IGroup;
  27. use OCP\IGroupManager;
  28. use OCP\IUserSession;
  29. use OCP\Share\IManager as IShareManager;
  30. use OCP\IUser;
  31. use Sabre\DAV\Exception;
  32. use \Sabre\DAV\PropPatch;
  33. use Sabre\DAVACL\PrincipalBackend\BackendInterface;
  34. class GroupPrincipalBackend implements BackendInterface {
  35. const PRINCIPAL_PREFIX = 'principals/groups';
  36. /** @var IGroupManager */
  37. private $groupManager;
  38. /** @var IUserSession */
  39. private $userSession;
  40. /** @var IShareManager */
  41. private $shareManager;
  42. /**
  43. * @param IGroupManager $IGroupManager
  44. * @param IUserSession $userSession
  45. * @param IShareManager $shareManager
  46. */
  47. public function __construct(IGroupManager $IGroupManager,
  48. IUserSession $userSession,
  49. IShareManager $shareManager) {
  50. $this->groupManager = $IGroupManager;
  51. $this->userSession = $userSession;
  52. $this->shareManager = $shareManager;
  53. }
  54. /**
  55. * Returns a list of principals based on a prefix.
  56. *
  57. * This prefix will often contain something like 'principals'. You are only
  58. * expected to return principals that are in this base path.
  59. *
  60. * You are expected to return at least a 'uri' for every user, you can
  61. * return any additional properties if you wish so. Common properties are:
  62. * {DAV:}displayname
  63. *
  64. * @param string $prefixPath
  65. * @return string[]
  66. */
  67. public function getPrincipalsByPrefix($prefixPath) {
  68. $principals = [];
  69. if ($prefixPath === self::PRINCIPAL_PREFIX) {
  70. foreach($this->groupManager->search('') as $user) {
  71. $principals[] = $this->groupToPrincipal($user);
  72. }
  73. }
  74. return $principals;
  75. }
  76. /**
  77. * Returns a specific principal, specified by it's path.
  78. * The returned structure should be the exact same as from
  79. * getPrincipalsByPrefix.
  80. *
  81. * @param string $path
  82. * @return array
  83. */
  84. public function getPrincipalByPath($path) {
  85. $elements = explode('/', $path, 3);
  86. if ($elements[0] !== 'principals') {
  87. return null;
  88. }
  89. if ($elements[1] !== 'groups') {
  90. return null;
  91. }
  92. $name = urldecode($elements[2]);
  93. $group = $this->groupManager->get($name);
  94. if (!is_null($group)) {
  95. return $this->groupToPrincipal($group);
  96. }
  97. return null;
  98. }
  99. /**
  100. * Returns the list of members for a group-principal
  101. *
  102. * @param string $principal
  103. * @return string[]
  104. * @throws Exception
  105. */
  106. public function getGroupMemberSet($principal) {
  107. $elements = explode('/', $principal);
  108. if ($elements[0] !== 'principals') {
  109. return [];
  110. }
  111. if ($elements[1] !== 'groups') {
  112. return [];
  113. }
  114. $name = $elements[2];
  115. $group = $this->groupManager->get($name);
  116. if (is_null($group)) {
  117. return [];
  118. }
  119. return array_map(function($user) {
  120. return $this->userToPrincipal($user);
  121. }, $group->getUsers());
  122. }
  123. /**
  124. * Returns the list of groups a principal is a member of
  125. *
  126. * @param string $principal
  127. * @return array
  128. * @throws Exception
  129. */
  130. public function getGroupMembership($principal) {
  131. return [];
  132. }
  133. /**
  134. * Updates the list of group members for a group principal.
  135. *
  136. * The principals should be passed as a list of uri's.
  137. *
  138. * @param string $principal
  139. * @param string[] $members
  140. * @throws Exception
  141. */
  142. public function setGroupMemberSet($principal, array $members) {
  143. throw new Exception('Setting members of the group is not supported yet');
  144. }
  145. /**
  146. * @param string $path
  147. * @param PropPatch $propPatch
  148. * @return int
  149. */
  150. function updatePrincipal($path, PropPatch $propPatch) {
  151. return 0;
  152. }
  153. /**
  154. * @param string $prefixPath
  155. * @param array $searchProperties
  156. * @param string $test
  157. * @return array
  158. */
  159. function searchPrincipals($prefixPath, array $searchProperties, $test = 'allof') {
  160. $results = [];
  161. if (\count($searchProperties) === 0) {
  162. return [];
  163. }
  164. if ($prefixPath !== self::PRINCIPAL_PREFIX) {
  165. return [];
  166. }
  167. // If sharing is disabled, return the empty array
  168. $shareAPIEnabled = $this->shareManager->shareApiEnabled();
  169. if (!$shareAPIEnabled) {
  170. return [];
  171. }
  172. // If sharing is restricted to group members only,
  173. // return only members that have groups in common
  174. $restrictGroups = false;
  175. if ($this->shareManager->shareWithGroupMembersOnly()) {
  176. $user = $this->userSession->getUser();
  177. if (!$user) {
  178. return [];
  179. }
  180. $restrictGroups = $this->groupManager->getUserGroupIds($user);
  181. }
  182. foreach ($searchProperties as $prop => $value) {
  183. switch ($prop) {
  184. case '{DAV:}displayname':
  185. $groups = $this->groupManager->search($value);
  186. $results[] = array_reduce($groups, function(array $carry, IGroup $group) use ($restrictGroups) {
  187. $gid = $group->getGID();
  188. // is sharing restricted to groups only?
  189. if ($restrictGroups !== false) {
  190. if (!\in_array($gid, $restrictGroups, true)) {
  191. return $carry;
  192. }
  193. }
  194. $carry[] = self::PRINCIPAL_PREFIX . '/' . $gid;
  195. return $carry;
  196. }, []);
  197. break;
  198. case '{urn:ietf:params:xml:ns:caldav}calendar-user-address-set':
  199. // If you add support for more search properties that qualify as a user-address,
  200. // please also add them to the array below
  201. $results[] = $this->searchPrincipals(self::PRINCIPAL_PREFIX, [
  202. ], 'anyof');
  203. break;
  204. default:
  205. $results[] = [];
  206. break;
  207. }
  208. }
  209. // results is an array of arrays, so this is not the first search result
  210. // but the results of the first searchProperty
  211. if (count($results) === 1) {
  212. return $results[0];
  213. }
  214. switch ($test) {
  215. case 'anyof':
  216. return array_values(array_unique(array_merge(...$results)));
  217. case 'allof':
  218. default:
  219. return array_values(array_intersect(...$results));
  220. }
  221. }
  222. /**
  223. * @param string $uri
  224. * @param string $principalPrefix
  225. * @return string
  226. */
  227. function findByUri($uri, $principalPrefix) {
  228. // If sharing is disabled, return the empty array
  229. $shareAPIEnabled = $this->shareManager->shareApiEnabled();
  230. if (!$shareAPIEnabled) {
  231. return null;
  232. }
  233. // If sharing is restricted to group members only,
  234. // return only members that have groups in common
  235. $restrictGroups = false;
  236. if ($this->shareManager->shareWithGroupMembersOnly()) {
  237. $user = $this->userSession->getUser();
  238. if (!$user) {
  239. return null;
  240. }
  241. $restrictGroups = $this->groupManager->getUserGroupIds($user);
  242. }
  243. if (strpos($uri, 'principal:principals/groups/') === 0) {
  244. $name = urlencode(substr($uri, 28));
  245. if ($restrictGroups !== false && !\in_array($name, $restrictGroups, true)) {
  246. return null;
  247. }
  248. return substr($uri, 10);
  249. }
  250. return null;
  251. }
  252. /**
  253. * @param IGroup $group
  254. * @return array
  255. */
  256. protected function groupToPrincipal($group) {
  257. $groupId = $group->getGID();
  258. // getDisplayName returns UID if none
  259. $displayName = $group->getDisplayName();
  260. return [
  261. 'uri' => 'principals/groups/' . urlencode($groupId),
  262. '{DAV:}displayname' => $displayName,
  263. '{urn:ietf:params:xml:ns:caldav}calendar-user-type' => 'GROUP',
  264. ];
  265. }
  266. /**
  267. * @param IUser $user
  268. * @return array
  269. */
  270. protected function userToPrincipal($user) {
  271. $userId = $user->getUID();
  272. // getDisplayName returns UID if none
  273. $displayName = $user->getDisplayName();
  274. $principal = [
  275. 'uri' => 'principals/users/' . $userId,
  276. '{DAV:}displayname' => $displayName,
  277. '{urn:ietf:params:xml:ns:caldav}calendar-user-type' => 'INDIVIDUAL',
  278. ];
  279. $email = $user->getEMailAddress();
  280. if (!empty($email)) {
  281. $principal['{http://sabredav.org/ns}email-address'] = $email;
  282. }
  283. return $principal;
  284. }
  285. }