1   /**
2    * Copyright (c) 2000-2009 Liferay, Inc. All rights reserved.
3    *
4    *
5    *
6    *
7    * The contents of this file are subject to the terms of the Liferay Enterprise
8    * Subscription License ("License"). You may not use this file except in
9    * compliance with the License. You can obtain a copy of the License by
10   * contacting Liferay, Inc. See the License for the specific language governing
11   * permissions and limitations under the License, including but not limited to
12   * distribution rights of the Software.
13   *
14   * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
15   * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16   * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
17   * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
18   * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
19   * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
20   * SOFTWARE.
21   */
22  
23  package com.liferay.portlet.shopping.service.permission;
24  
25  import com.liferay.portal.PortalException;
26  import com.liferay.portal.SystemException;
27  import com.liferay.portal.security.auth.PrincipalException;
28  import com.liferay.portal.security.permission.ActionKeys;
29  import com.liferay.portal.security.permission.PermissionChecker;
30  import com.liferay.portal.util.PropsValues;
31  import com.liferay.portlet.shopping.model.ShoppingCategory;
32  import com.liferay.portlet.shopping.model.impl.ShoppingCategoryImpl;
33  import com.liferay.portlet.shopping.service.ShoppingCategoryLocalServiceUtil;
34  
35  /**
36   * <a href="ShoppingCategoryPermission.java.html"><b><i>View Source</i></b></a>
37   *
38   * @author Brian Wing Shun Chan
39   */
40  public class ShoppingCategoryPermission {
41  
42      public static void check(
43              PermissionChecker permissionChecker, long groupId, long categoryId,
44              String actionId)
45          throws PortalException, SystemException {
46  
47          if (!contains(permissionChecker, groupId, categoryId, actionId)) {
48              throw new PrincipalException();
49          }
50      }
51  
52      public static void check(
53              PermissionChecker permissionChecker, long categoryId,
54              String actionId)
55          throws PortalException, SystemException {
56  
57          if (!contains(permissionChecker, categoryId, actionId)) {
58              throw new PrincipalException();
59          }
60      }
61  
62      public static void check(
63              PermissionChecker permissionChecker, ShoppingCategory category,
64              String actionId)
65          throws PortalException, SystemException {
66  
67          if (!contains(permissionChecker, category, actionId)) {
68              throw new PrincipalException();
69          }
70      }
71  
72      public static boolean contains(
73              PermissionChecker permissionChecker, long groupId, long categoryId,
74              String actionId)
75          throws PortalException, SystemException {
76  
77          if (categoryId == ShoppingCategoryImpl.DEFAULT_PARENT_CATEGORY_ID) {
78              return ShoppingPermission.contains(
79                  permissionChecker, groupId, actionId);
80          }
81          else {
82              return contains(permissionChecker, categoryId, actionId);
83          }
84      }
85  
86      public static boolean contains(
87              PermissionChecker permissionChecker, long categoryId,
88              String actionId)
89          throws PortalException, SystemException {
90  
91          ShoppingCategory category =
92              ShoppingCategoryLocalServiceUtil.getCategory(categoryId);
93  
94          return contains(permissionChecker, category, actionId);
95      }
96  
97      public static boolean contains(
98              PermissionChecker permissionChecker, ShoppingCategory category,
99              String actionId)
100         throws PortalException, SystemException {
101 
102         if (actionId.equals(ActionKeys.ADD_CATEGORY)) {
103             actionId = ActionKeys.ADD_SUBCATEGORY;
104         }
105 
106         long categoryId = category.getCategoryId();
107 
108         if (actionId.equals(ActionKeys.VIEW)) {
109             while (categoryId !=
110                         ShoppingCategoryImpl.DEFAULT_PARENT_CATEGORY_ID) {
111 
112                 category = ShoppingCategoryLocalServiceUtil.getCategory(
113                     categoryId);
114 
115                 categoryId = category.getParentCategoryId();
116 
117                 if (!permissionChecker.hasOwnerPermission(
118                         category.getCompanyId(),
119                         ShoppingCategory.class.getName(),
120                         category.getCategoryId(), category.getUserId(),
121                         actionId) &&
122                     !permissionChecker.hasPermission(
123                         category.getGroupId(), ShoppingCategory.class.getName(),
124                         category.getCategoryId(), actionId)) {
125 
126                     return false;
127                 }
128 
129                 if (!PropsValues.PERMISSIONS_VIEW_DYNAMIC_INHERITANCE) {
130                     break;
131                 }
132             }
133 
134             return true;
135         }
136         else {
137             while (categoryId !=
138                         ShoppingCategoryImpl.DEFAULT_PARENT_CATEGORY_ID) {
139 
140                 if (permissionChecker.hasOwnerPermission(
141                         category.getCompanyId(),
142                         ShoppingCategory.class.getName(),
143                         category.getCategoryId(), category.getUserId(),
144                         actionId)) {
145 
146                     return true;
147                 }
148 
149                 if (permissionChecker.hasPermission(
150                         category.getGroupId(), ShoppingCategory.class.getName(),
151                         category.getCategoryId(), actionId)) {
152 
153                     return true;
154                 }
155 
156                 if (actionId.equals(ActionKeys.VIEW)) {
157                     break;
158                 }
159 
160                 category = ShoppingCategoryLocalServiceUtil.getCategory(
161                     categoryId);
162 
163                 categoryId = category.getParentCategoryId();
164             }
165 
166             return false;
167         }
168     }
169 
170 }