UsersController.php 6.25 KB
<?php
namespace App\Controller;

use App\Controller\AppController;
use Cake\Event\Event;
use Cake\ORM\TableRegistry;

/**
 * Users Controller
 *
 * @property \App\Model\Table\UsersTable $Users
 */
class UsersController extends AppController
{
	// "l'" utilisateur (et non pas "le utilisateur")
	protected function getArticle() {
		return "L'";
	}
	
	
	/**
	 * @param $user
	 *
	 * Give authorization for users
	 *
	 * @return boolean
	 */
	public function isAuthorized($user)
	{
		$configuration = TableRegistry::get('Configurations')->find()->where(['id =' => 1])->first();
		$role = $this->Users->find()->where(['username' => $user[$configuration->authentificationType_ldap][0]])->first()['role'];
		 
		$action = $this->request->params['action'];
		 
    	// Super-Admin peut accéder à chaque action
    	if($role == 'Super Administrateur') return true;
		
		//Pour tout le monde
		if (in_array($action, ['index', 'view', 'getLdapLogin', 'getLdapEmail'])) return true;
		 
		 
		// Par défaut refuser
		return false;
	}
	
	
	public function beforeFilter(Event $event)
	{
		parent::beforeFilter($event);
		$this->LdapAuth->allow(['logout']);
	}
	
	public function login()
	{
		if ($this->request->is('post')) {

			$user = $this->LdapAuth->connection();
			
			if ($user != FALSE) {
				$this->LdapAuth->setUser($user);	

				return $this->redirect($this->LdapAuth->redirectUrl());
			}
			$this->Flash->error(__('Login ou mot de passe invalide, réessayez'));
		}
	}
	
	public function logout()
	{
		return $this->redirect($this->LdapAuth->logout());
	}
	
	
    /**
     * Index method
     *
     * @return \Cake\Network\Response|null
     */
    public function index()
    {
        $this->paginate = [
            'contain' => ['GroupesMetiers']
        ];
        $users = $this->paginate($this->Users);

        $this->set(compact('users'));
        $this->set('_serialize', ['users']);
    }

    /**
     * View method
     *
     * @param string|null $id User id.
     * @return \Cake\Network\Response|null
     * @throws \Cake\Datasource\Exception\RecordNotFoundException When record not found.
     */
    public function view($id = null)
    {
        $user = $this->Users->get($id, [
            'contain' => ['GroupesMetiers']
        ]);

        $this->set('user', $user);
        $this->set('_serialize', ['user']);
    }

    /**
     * Add method
     *
     * @return \Cake\Network\Response|void Redirects on successful add, renders view otherwise.
     */
    public function add()
    {
        $user = $this->Users->newEntity();
        if ($this->request->is('post')) {
            $user = $this->Users->patchEntity($user, $this->request->data);
            if ($this->Users->save($user)) {
                $this->Flash->success(__('L\'utilisateur a bien été ajouté.'));
                return $this->redirect(['action' => 'view', $user->id]);
            } else {
                $this->Flash->error(__('L\utilisateur n\'a pas pu être ajouté.'));
            }
        }
        $groupesMetiers = $this->Users->GroupesMetiers->find('list', [ 'keyField' => 'id', 'valueField' => 'nom']);
       
        $utilisateurs = TableRegistry::get('LdapConnections')->getListUsers();
        
        $this->set(compact('user', 'groupesMetiers', 'utilisateurs'));
        $this->set('_serialize', ['user']);
    }

    /**
     * Edit method
     *
     * @param string|null $id User id.
     * @return \Cake\Network\Response|void Redirects on successful edit, renders view otherwise.
     * @throws \Cake\Network\Exception\NotFoundException When record not found.
     */
    public function edit($id = null)
    {
        $user = $this->Users->get($id, [
            'contain' => []
        ]);
        if ($this->request->is(['patch', 'post', 'put'])) {
            $user = $this->Users->patchEntity($user, $this->request->data);
            if ($this->Users->save($user)) {
                $this->Flash->success(__('L\utilisateur a bien été édité.'));
                return $this->redirect(['action' => 'view', $id]);
            } else {
                $this->Flash->error(__('L\utilisateur n\'a pas pu être édité.'));
            }
        }
        $groupesMetiers = $this->Users->GroupesMetiers->find('list', [ 'keyField' => 'id', 'valueField' => 'nom']);
        
        $this->set(compact('user', 'groupesMetiers'));
        $this->set('_serialize', ['user']);
    }

    /**
     * Delete method
     *
     * @param string|null $id User id.
     * @return \Cake\Network\Response|null Redirects to index.
     * @throws \Cake\Datasource\Exception\RecordNotFoundException When record not found.
     */
    public function delete($id = null)
    {
        $this->request->allowMethod(['post', 'delete']);
        $user = $this->Users->get($id);
        if ($this->Users->delete($user)) {
            $this->Flash->success(__('L\utilisateur a bien été supprimé.'));
        } else {
            $this->Flash->error(__('L\utilisateur n\'a pas pu être supprimé.'));
        }
        return $this->redirect(['action' => 'index']);
    }
    
    
    // called from Javascript (Ajax)
    public function getLdapLogin($userName) {

    	$ldapConnection = TableRegistry::get('LdapConnections');
    	$u = $ldapConnection->getAllLdapUsers();
    	
    	for($i = 0; $i < $ldapConnection->getNbUsers(); $i++) {
    		
    	    if (!empty($u[$i][$this->request->session()->read('authType')][0])) {
    			if ($userName == $u[$i]['givenname'][0].' '.$u[$i]['sn'][0]) {
    				$this->set ( 'login', $u[$i][$this->request->session()->read('authType')][0] );
    			}
    		}
    	}

    	$this->viewBuilder()->layout = 'ajax';
    }
    
    // called from Javascript (Ajax)
    public function getLdapEmail($userName) {
    	$ldapConnection = TableRegistry::get('LdapConnections');
    	$u = $ldapConnection->getAllLdapUsers();

        for($i = 0; $i < $ldapConnection->getNbUsers(); $i++) {

            if (!empty($u[$i][$this->request->session()->read('authType')][0])) {

    			if ($userName == $u[$i]['givenname'][0].' '.$u[$i]['sn'][0]) {
    				if (isset($u[$i]['mail'][0]) && filter_var($u[$i]['mail'][0], FILTER_VALIDATE_EMAIL)) {
    					$this->set ('email', $u[$i]['mail'][0] );
    				} else {
    					$this->set ('email', ' ');
    				}
    			}
    		}
    				

    	}
    
    	$this->viewBuilder()->layout = 'ajax';
    }
    
    
}