1   /**
2    * Copyright (c) 2000-2009 Liferay, Inc. All rights reserved.
3    *
4    *
5    *
6    *
7    * The contents of this file are subject to the terms of the Liferay Enterprise
8    * Subscription License ("License"). You may not use this file except in
9    * compliance with the License. You can obtain a copy of the License by
10   * contacting Liferay, Inc. See the License for the specific language governing
11   * permissions and limitations under the License, including but not limited to
12   * distribution rights of the Software.
13   *
14   * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
15   * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16   * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
17   * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
18   * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
19   * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
20   * SOFTWARE.
21   */
22  
23  package com.liferay.portlet.shopping.service.permission;
24  
25  import com.liferay.portal.PortalException;
26  import com.liferay.portal.SystemException;
27  import com.liferay.portal.security.auth.PrincipalException;
28  import com.liferay.portal.security.permission.ActionKeys;
29  import com.liferay.portal.security.permission.PermissionChecker;
30  import com.liferay.portlet.shopping.model.ShoppingOrder;
31  import com.liferay.portlet.shopping.service.ShoppingOrderLocalServiceUtil;
32  
33  /**
34   * <a href="ShoppingOrderPermission.java.html"><b><i>View Source</i></b></a>
35   *
36   * @author Brian Wing Shun Chan
37   */
38  public class ShoppingOrderPermission {
39  
40      public static void check(
41              PermissionChecker permissionChecker, long groupId, long orderId,
42              String actionId)
43          throws PortalException, SystemException {
44  
45          if (!contains(permissionChecker, groupId, orderId, actionId)) {
46              throw new PrincipalException();
47          }
48      }
49  
50      public static void check(
51              PermissionChecker permissionChecker, long groupId,
52              ShoppingOrder order, String actionId)
53          throws PortalException {
54  
55          if (!contains(permissionChecker, groupId, order, actionId)) {
56              throw new PrincipalException();
57          }
58      }
59  
60      public static boolean contains(
61              PermissionChecker permissionChecker, long groupId, long orderId,
62              String actionId)
63          throws PortalException, SystemException {
64  
65          ShoppingOrder order =
66              ShoppingOrderLocalServiceUtil.getOrder(orderId);
67  
68          return contains(permissionChecker, groupId, order, actionId);
69      }
70  
71      public static boolean contains(
72          PermissionChecker permissionChecker, long groupId, ShoppingOrder order,
73          String actionId) {
74  
75          if (ShoppingPermission.contains(
76                  permissionChecker, groupId, ActionKeys.MANAGE_ORDERS)) {
77  
78              return true;
79          }
80          else {
81              if (permissionChecker.hasOwnerPermission(
82                      order.getCompanyId(), ShoppingOrder.class.getName(),
83                      order.getOrderId(), order.getUserId(), actionId)) {
84  
85                  return true;
86              }
87  
88              return permissionChecker.hasPermission(
89                  order.getGroupId(), ShoppingOrder.class.getName(),
90                  order.getOrderId(), actionId);
91          }
92      }
93  
94  }