Class StoreAccessService
java.lang.Object
org.bgerp.plugin.inventoru.service.StoreAccessService
Which warehouses a user may see and change.
The rule lives here rather than in an action because it is also needed outside of one — the
parameter values of a warehouse are written by the kernel action
/user/parameter,
which knows nothing about warehouses, and the plugin has to enforce access from an event
listener instead.-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic enumOn which warehouses a permission node acts. -
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionaccessibleStoreIds(Connection con, DynActionForm form) static booleanallowed(Connection con, DynActionForm form, String action, StoreAccessService.Scope defaultScope, int storeId) allowed(Connection, DynActionForm, String, Scope, Store)by warehouse ID.static booleanallowed(Connection con, DynActionForm form, String action, StoreAccessService.Scope defaultScope, Store store) Whether a permission node lets the user act on the warehouse, seestoreIds(Connection, DynActionForm, String, StoreAccessService.Scope).static booleancanEditParams(DynActionForm form) static voidcheckAdmin(DynActionForm form) Refuses a change of who reaches a warehouse — its grants and its editing group — to anyone but a warehouse admin.static booleanisAdmin(DynActionForm form) static booleanisEditGroupMember(DynActionForm form, Store store) ownStoreIds(Connection con, DynActionForm form) The warehouses of the user personally, ignoring the admin-tier permission — an admin's "my warehouse" screen has to stay their own, not every warehouse in the system.resolve(Connection con, User user, ConfigMap perm, StoreAccessService.Scope defaultScope) The warehouses the options of a node give a given user, the warehouse admin aside — the rule ofstoreIds(Connection, DynActionForm, String, StoreAccessService.Scope)itself, so that it can be checked as it is.runStoreIds(Connection con, User user) The warehouses a user who is not a warehouse admin runs: those of their editing groups — not the owned or granted ones.static StoreAccessService.Scopescope(DynActionForm form, String action, StoreAccessService.Scope defaultScope) storeIds(Connection con, DynActionForm form, String action, StoreAccessService.Scope defaultScope) The warehouses a permission node lets the user act on.storeIds(Connection con, DynActionForm form, ConfigMap perm, StoreAccessService.Scope defaultScope) storeIds(Connection, DynActionForm, String, Scope)for an already resolved node, e.g.workingStoreIds(Connection con, User user) The warehouses a user works with: owned, granted personally or to one of their groups, or run by their editing group.workStoreIds(Connection con, DynActionForm form, String action) The warehouses a node of WORKING with stock — reserve, return, transfer, the materials of a process — lets the user act on,StoreAccessService.Scope.WORKby default.
-
Field Details
-
PERMISSION_PARAM_UPDATE
Permission to change the parameter values of a warehouse. It gates no action of its own — the values are written by the kernel action/user/parameter:parameterUpdate, whose permission covers every object type at once, so a person allowed to fill in the parameters of their processes was by that alone allowed to rewrite the parameters of a warehouse. Access to the warehouse itself is a separate question, checked on top of this.- See Also:
-
OPTION_STORES
- See Also:
-
OPTION_STORE_TYPES
Option of a permission node: comma-separated store type IDs the node is limited to.- See Also:
-
-
Method Details
-
accessibleStoreIds
- Returns:
nullfor an admin-tier user, meaning every warehouse; otherwise the IDs of the warehouses the user owns, has an activeStoreAccessDAOgrant for — personally or through one of their groups — or may edit through theedit_group_idgroup — possibly an empty set.- Throws:
Exception
-
ownStoreIds
The warehouses of the user personally, ignoring the admin-tier permission — an admin's "my warehouse" screen has to stay their own, not every warehouse in the system.- Returns:
- the IDs, possibly empty.
- Throws:
Exception
-
workingStoreIds
The warehouses a user works with: owned, granted personally or to one of their groups, or run by their editing group. The rule ofownStoreIds(Connection, DynActionForm)for a given user — without the request, so that it can be checked as it is.- Throws:
Exception
-
storeIds
public static Set<Integer> storeIds(Connection con, DynActionForm form, String action, StoreAccessService.Scope defaultScope) throws Exception The warehouses a permission node lets the user act on. Changing a warehouse — its card, parameters, equipment, stock — defaults toStoreAccessService.Scope.RUN, working with it toStoreAccessService.Scope.WORK: the owner of a warehouse and whoever holds a grant to it are its installers. There used to be one measure for both, and an installer holding a storekeeper's permission rewrote the owner of a warehouse he was only granted and deleted it with its stock.- Parameters:
action- the permission node, e.g./user/plugin/inventoru/store:update.defaultScope- the scope when the node carries noOPTION_STORES.- Returns:
null— every warehouse (a warehouse admin, or the optionallwithout types); otherwise the IDs, possibly none — also without the node at all.- Throws:
Exception
-
storeIds
public static Set<Integer> storeIds(Connection con, DynActionForm form, ConfigMap perm, StoreAccessService.Scope defaultScope) throws Exception storeIds(Connection, DynActionForm, String, Scope)for an already resolved node, e.g.form.getPermission()— the node of the called action.- Parameters:
perm- the options of the node,null— the user does not hold it.- Throws:
Exception
-
workStoreIds
public static Set<Integer> workStoreIds(Connection con, DynActionForm form, String action) throws Exception The warehouses a node of WORKING with stock — reserve, return, transfer, the materials of a process — lets the user act on,StoreAccessService.Scope.WORKby default. Unlike a change of a warehouse, a warehouse admin is not widened here: working is personal, and the materials of a process list the admin's own warehouses, not every one in the system — unless the node saysstores=all.- Throws:
Exception
-
resolve
public static Set<Integer> resolve(Connection con, User user, ConfigMap perm, StoreAccessService.Scope defaultScope) throws Exception The warehouses the options of a node give a given user, the warehouse admin aside — the rule ofstoreIds(Connection, DynActionForm, String, StoreAccessService.Scope)itself, so that it can be checked as it is.- Parameters:
perm- the options of the node,null— the user does not hold it: no warehouse.- Returns:
null— every warehouse; otherwise the IDs, possibly none.- Throws:
Exception
-
allowed
public static boolean allowed(Connection con, DynActionForm form, String action, StoreAccessService.Scope defaultScope, Store store) throws Exception Whether a permission node lets the user act on the warehouse, seestoreIds(Connection, DynActionForm, String, StoreAccessService.Scope). A deleted warehouse is in none of the sets, which are built from live rows: for it the rule is read from the row itself, so whoever ran it can open and restore it.- Throws:
Exception
-
allowed
public static boolean allowed(Connection con, DynActionForm form, String action, StoreAccessService.Scope defaultScope, int storeId) throws Exception allowed(Connection, DynActionForm, String, Scope, Store)by warehouse ID.- Throws:
Exception
-
scope
public static StoreAccessService.Scope scope(DynActionForm form, String action, StoreAccessService.Scope defaultScope) - Returns:
- the
StoreAccessService.Scopea permission node is set to, the default when the option is absent;StoreAccessService.Scope.ALLfor a warehouse admin.
-
runStoreIds
The warehouses a user who is not a warehouse admin runs: those of their editing groups — not the owned or granted ones. The rule ofStoreAccessService.Scope.RUNfor a given user.- Throws:
Exception
-
isEditGroupMember
- Returns:
- whether the user is in the editing group of the warehouse — read from the row, so it
holds for a deleted warehouse too, which the sets of
storeIds(Connection, DynActionForm, String, StoreAccessService.Scope)do not list.
-
canEditParams
- Returns:
- whether the user may change parameter values of warehouses at all — the screen shows them read-only otherwise, and the write is refused.
-
checkAdmin
Refuses a change of who reaches a warehouse — its grants and its editing group — to anyone but a warehouse admin. Each of those actions has a permission node of its own, and whoever held just the one for the editing group put their own group in and became the manager of any warehouse, with everythingStoreAccessService.Scope.RUNopens.- Throws:
BGMessageException
-
isAdmin
- Returns:
- whether the user is a warehouse admin, see
checkAdmin(DynActionForm).
-