Sitelet https://github.com/Free2MoveApp/snipe-it/commit/7b33f95e837f609226c5c1127b99d05b57a4e9c0
Skip to content

Commit 7b33f95

Browse files
authored
Fixes/import permissions mask (grokability#6826)
* Check for empty headers in import * Added import permission * Fixed model path in docblock * Added import gate to default blade * Check if the user is an admin OR idf they have import permissions * Walked back that admin permission Since admins are bound by full company support, it makes less sense to let admins have this permission by default, versus having them specifically designated to the import permission
1 parent 5893e25 commit 7b33f95

7 files changed

Lines changed: 45 additions & 14 deletions

File tree

‎app/Http/Controllers/Api/ImportController.php‎

Lines changed: 5 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ class ImportController extends Controller
2525
*/
2626
public function index()
2727
{
28-
//
28+
$this->authorize('import');
2929
$imports = Import::latest()->get();
3030
return (new ImportsTransformer)->transformImports($imports);
3131

@@ -39,10 +39,8 @@ public function index()
3939
*/
4040
public function store()
4141
{
42-
//
43-
if (!Company::isCurrentUserAuthorized()) {
44-
return redirect()->route('hardware.index')->with('error', trans('general.insufficient_permissions'));
45-
} elseif (!config('app.lock_passwords')) {
42+
$this->authorize('import');
43+
if (!config('app.lock_passwords')) {
4644
$files = Input::file('files');
4745
$path = config('app.private_uploads').'/imports';
4846
$results = [];
@@ -119,7 +117,7 @@ public function store()
119117
*/
120118
public function process(ItemImportRequest $request, $import_id)
121119
{
122-
$this->authorize('create', Asset::class);
120+
$this->authorize('import');
123121
// Run a backup immediately before processing
124122
Artisan::call('backup:run');
125123
$errors = $request->import(Import::find($import_id));
@@ -162,7 +160,7 @@ public function process(ItemImportRequest $request, $import_id)
162160
*/
163161
public function destroy($import_id)
164162
{
165-
$this->authorize('create', Asset::class);
163+
$this->authorize('import');
166164
$import = Import::find($import_id);
167165
try {
168166
unlink(config('app.private_uploads').'/imports/'.$import->file_path);

‎app/Http/Controllers/ImportsController.php‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ class ImportsController extends Controller
1212
{
1313
public function index()
1414
{
15-
$this->authorize('create', Asset::class);
15+
$this->authorize('import');
1616
$imports = Import::latest()->get();
1717
$imports = (new ImportsTransformer)->transformImports($imports);
1818
return view('importer/import')->with('imports', $imports);

‎app/Http/Requests/ItemImportRequest.php‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,20 @@ public function import(Import $import)
4343
$import->save();
4444
$fieldMappings=[];
4545
if ($import->field_map) {
46+
47+
// This checks to make sure the field header has been mapped.
48+
// If it hasn't been, it will throw an array_flip error
49+
foreach ($import->field_map as $field => $fieldValue) {
50+
$errorMessage = null;
51+
52+
if(is_null($fieldValue)){
53+
$errorMessage = 'All import fields must be mapped.';
54+
$this->errorCallback($import, $field, $errorMessage);
55+
56+
return $this->errors;
57+
}
58+
}
59+
4660
// We submit as csv field: column, but the importer is happier if we flip it here.
4761
$fieldMappings = array_change_key_case(array_flip($import->field_map), CASE_LOWER);
4862
// dd($fieldMappings);

‎app/Policies/SnipePermissionsPolicy.php‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ public function index(User $user)
5353
/**
5454
* Determine whether the user can view the accessory.
5555
*
56-
* @param \App\User $user
56+
* @param \App\Models\User $user
5757
* @return mixed
5858
*/
5959
public function view(User $user, $item = null)
@@ -64,7 +64,7 @@ public function view(User $user, $item = null)
6464
/**
6565
* Determine whether the user can create accessories.
6666
*
67-
* @param \App\User $user
67+
* @param \App\Models\User $user
6868
* @return mixed
6969
*/
7070
public function create(User $user)
@@ -75,7 +75,7 @@ public function create(User $user)
7575
/**
7676
* Determine whether the user can update the accessory.
7777
*
78-
* @param \App\User $user
78+
* @param \App\Models\User $user
7979
* @return mixed
8080
*/
8181
public function update(User $user, $item = null)
@@ -86,7 +86,7 @@ public function update(User $user, $item = null)
8686
/**
8787
* Determine whether the user can delete the accessory.
8888
*
89-
* @param \App\User $user
89+
* @param \App\Models\User $user
9090
* @return mixed
9191
*/
9292
public function delete(User $user, $item = null)
@@ -97,11 +97,13 @@ public function delete(User $user, $item = null)
9797
/**
9898
* Determine whether the user can manage the accessory.
9999
*
100-
* @param \App\User $user
100+
* @param \App\Models\User $user
101101
* @return mixed
102102
*/
103103
public function manage(User $user, $item = null)
104104
{
105105
return $user->hasAccess($this->columnName().'.edit');
106106
}
107+
108+
107109
}

‎app/Providers/AuthServiceProvider.php‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,14 @@ public function boot()
113113
});
114114

115115

116+
// Can the user import CSVs?
117+
Gate::define('import', function ($user) {
118+
if ($user->hasAccess('import') ) {
119+
return true;
120+
}
121+
});
122+
123+
116124
# -----------------------------------------
117125
# Reports
118126
# -----------------------------------------

‎config/permissions.php‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,15 @@
2727
)
2828
),
2929

30+
'CSV Import' => array(
31+
array(
32+
'permission' => 'import',
33+
'label' => '',
34+
'note' => 'This will allow users to import even if access to users, assets, etc is denied elsewhere.',
35+
'display' => true,
36+
)
37+
),
38+
3039
'Reports' => array(
3140
array(
3241
'permission' => 'reports.view',

‎resources/views/layouts/default.blade.php‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -520,7 +520,7 @@
520520
</a>
521521
</li>
522522
@endcan
523-
@can('create', \App\Models\Asset::class)
523+
@can('import')
524524
<li{!! (Request::is('import/*') ? ' class="active"' : '') !!}>
525525
<a href="{{ route('imports.index') }}">
526526
<i class="fa fa-cloud-download"></i>

0 commit comments

Comments
 (0)