- Moved _checkPermissions from FHC_Controller to PermissionLib (now is public and it's renamed checkPermissions)

- Added include of PermissionLib in APIv1_Controller
- Added method _isAllowed to APIv1_Controller to call checkPermissions from PermissionLib
- Now the APIv1_Controller constructor requires an array of permissions as parameter
This commit is contained in:
Paolo
2018-03-20 13:00:35 +01:00
parent 15c4c1af24
commit 1f2450cf17
3 changed files with 122 additions and 100 deletions
+21 -3
View File
@@ -7,13 +7,31 @@ class APIv1_Controller extends REST_Controller
/**
* Standard constructor for all the RESTful resources
*/
public function __construct()
public function __construct($requiredPermissions)
{
parent::__construct();
// Loads return messages
$this->load->helper('message');
// Loads permission lib
$this->load->library('PermissionLib');
log_message('debug', 'Called API: '.$_SERVER['PHP_SELF'].'?'.$_SERVER['QUERY_STRING']);
$this->_isAllowed($requiredPermissions);
}
/**
* Checks if the caller is allowed to access to this content with the given permissions
* If it is not allowed will set the HTTP header with code 401
* Wrapper for _checkPermissions
*/
private function _isAllowed($requiredPermissions)
{
if (!$this->permissionlib->checkPermissions($requiredPermissions, $this->router->method))
{
$this->response(error('You are not allowed to access to this content'), REST_Controller::HTTP_UNAUTHORIZED);
}
}
}