1   /**
2    * Copyright (c) 2000-2009 Liferay, Inc. All rights reserved.
3    *
4    *
5    *
6    *
7    * The contents of this file are subject to the terms of the Liferay Enterprise
8    * Subscription License ("License"). You may not use this file except in
9    * compliance with the License. You can obtain a copy of the License by
10   * contacting Liferay, Inc. See the License for the specific language governing
11   * permissions and limitations under the License, including but not limited to
12   * distribution rights of the Software.
13   *
14   * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
15   * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16   * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
17   * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
18   * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
19   * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
20   * SOFTWARE.
21   */
22  
23  package com.liferay.portlet.bookmarks.service.permission;
24  
25  import com.liferay.portal.PortalException;
26  import com.liferay.portal.SystemException;
27  import com.liferay.portal.security.auth.PrincipalException;
28  import com.liferay.portal.security.permission.ActionKeys;
29  import com.liferay.portal.security.permission.PermissionChecker;
30  import com.liferay.portal.util.PropsValues;
31  import com.liferay.portlet.bookmarks.model.BookmarksFolder;
32  import com.liferay.portlet.bookmarks.model.impl.BookmarksFolderImpl;
33  import com.liferay.portlet.bookmarks.service.BookmarksFolderLocalServiceUtil;
34  
35  /**
36   * <a href="BookmarksFolderPermission.java.html"><b><i>View Source</i></b></a>
37   *
38   * @author Brian Wing Shun Chan
39   * @author Raymond Augé
40   */
41  public class BookmarksFolderPermission {
42  
43      public static void check(
44              PermissionChecker permissionChecker, long groupId, long folderId,
45              String actionId)
46          throws PortalException, SystemException {
47  
48          if (!contains(permissionChecker, groupId, folderId, actionId)) {
49              throw new PrincipalException();
50          }
51      }
52  
53      public static void check(
54              PermissionChecker permissionChecker, long folderId,
55              String actionId)
56          throws PortalException, SystemException {
57  
58          if (!contains(permissionChecker, folderId, actionId)) {
59              throw new PrincipalException();
60          }
61      }
62  
63      public static void check(
64              PermissionChecker permissionChecker, BookmarksFolder folder,
65              String actionId)
66          throws PortalException, SystemException {
67  
68          if (!contains(permissionChecker, folder, actionId)) {
69              throw new PrincipalException();
70          }
71      }
72  
73      public static boolean contains(
74              PermissionChecker permissionChecker, long groupId, long folderId,
75              String actionId)
76          throws PortalException, SystemException {
77  
78          if (folderId == BookmarksFolderImpl.DEFAULT_PARENT_FOLDER_ID) {
79              return BookmarksPermission.contains(
80                  permissionChecker, groupId, actionId);
81          }
82          else {
83              return contains(permissionChecker, folderId, actionId);
84          }
85      }
86  
87      public static boolean contains(
88              PermissionChecker permissionChecker, long folderId,
89              String actionId)
90          throws PortalException, SystemException {
91  
92          BookmarksFolder folder =
93              BookmarksFolderLocalServiceUtil.getFolder(folderId);
94  
95          return contains(permissionChecker, folder, actionId);
96      }
97  
98      public static boolean contains(
99              PermissionChecker permissionChecker, BookmarksFolder folder,
100             String actionId)
101         throws PortalException, SystemException {
102 
103         if (actionId.equals(ActionKeys.ADD_FOLDER)) {
104             actionId = ActionKeys.ADD_SUBFOLDER;
105         }
106 
107         long folderId = folder.getFolderId();
108 
109         if (actionId.equals(ActionKeys.VIEW)) {
110             while (folderId != BookmarksFolderImpl.DEFAULT_PARENT_FOLDER_ID) {
111                 folder = BookmarksFolderLocalServiceUtil.getFolder(folderId);
112 
113                 folderId = folder.getParentFolderId();
114 
115                 if (!permissionChecker.hasOwnerPermission(
116                         folder.getCompanyId(), BookmarksFolder.class.getName(),
117                         folder.getFolderId(), folder.getUserId(), actionId) &&
118                     !permissionChecker.hasPermission(
119                         folder.getGroupId(), BookmarksFolder.class.getName(),
120                         folder.getFolderId(), actionId)) {
121 
122                     return false;
123                 }
124 
125                 if (!PropsValues.PERMISSIONS_VIEW_DYNAMIC_INHERITANCE) {
126                     break;
127                 }
128             }
129 
130             return true;
131         }
132         else {
133             while (folderId != BookmarksFolderImpl.DEFAULT_PARENT_FOLDER_ID) {
134                 if (permissionChecker.hasOwnerPermission(
135                         folder.getCompanyId(), BookmarksFolder.class.getName(),
136                         folder.getFolderId(), folder.getUserId(), actionId)) {
137 
138                     return true;
139                 }
140 
141                 if (permissionChecker.hasPermission(
142                         folder.getGroupId(), BookmarksFolder.class.getName(),
143                         folder.getFolderId(), actionId)) {
144 
145                     return true;
146                 }
147 
148                 if (actionId.equals(ActionKeys.VIEW)) {
149                     break;
150                 }
151 
152                 folder = BookmarksFolderLocalServiceUtil.getFolder(folderId);
153 
154                 folderId = folder.getParentFolderId();
155             }
156 
157             return false;
158         }
159     }
160 
161 }