mirror of
https://github.com/Terranom674/Piwigo_Bratonien_Tools.git
synced 2026-09-19 21:04:33 +00:00
Fix private album owner access on permissions form
This commit is contained in:
59
main.inc.php
59
main.inc.php
@@ -1,7 +1,7 @@
|
||||
<?php
|
||||
/*
|
||||
Plugin Name: Bratonien Tools
|
||||
Version: 0.13.1
|
||||
Version: 0.13.2
|
||||
Description: Erweiterbare Administrationswerkzeuge fuer die Bratonien-Piwigo-Installation.
|
||||
Plugin URI: https://github.com/Terranom674/Piwigo_Bratonien_Tools
|
||||
Author: Bratonien
|
||||
@@ -25,10 +25,67 @@ add_event_handler('get_admin_plugin_menu_links', 'bratonien_tools_admin_menu');
|
||||
add_event_handler('get_derivative_url', 'bratonien_tools_filter_derivative_url', EVENT_HANDLER_PRIORITY_NEUTRAL, 4);
|
||||
add_event_handler('loc_end_element_set_global', 'bratonien_tools_batch_titles_register_action');
|
||||
add_event_handler('element_set_global_action', 'bratonien_tools_batch_titles_apply', EVENT_HANDLER_PRIORITY_NEUTRAL, 2);
|
||||
add_event_handler('init', 'bratonien_tools_prepare_private_album_permissions', EVENT_HANDLER_PRIORITY_NEUTRAL - 20);
|
||||
add_event_handler('init', 'bratonien_tools_preserve_private_album_access', EVENT_HANDLER_PRIORITY_NEUTRAL - 10);
|
||||
add_event_handler('init', 'bratonien_tools_album_shares_init');
|
||||
add_event_handler('delete_categories', 'bratonien_tools_album_shares_on_delete_categories');
|
||||
|
||||
/**
|
||||
* Piwigo's per-album permissions form rewrites the complete direct-user
|
||||
* permission list when an album is saved as private. Add the acting user to
|
||||
* that submitted list on the public -> private transition so Piwigo itself
|
||||
* persists the permission together with the other selected users.
|
||||
*/
|
||||
function bratonien_tools_prepare_private_album_permissions()
|
||||
{
|
||||
global $user;
|
||||
|
||||
if (
|
||||
!defined('IN_ADMIN')
|
||||
|| $_SERVER['REQUEST_METHOD'] !== 'POST'
|
||||
|| empty($user['id'])
|
||||
|| (string)($_POST['status'] ?? '') !== 'private'
|
||||
)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
$page = (string)($_GET['page'] ?? '');
|
||||
if (!preg_match('/^album-(\d+)-permissions$/', $page, $matches))
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
$category_id = (int)$matches[1];
|
||||
if ($category_id < 1)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
$result = pwg_query('SELECT status FROM '.CATEGORIES_TABLE.' WHERE id = '.$category_id.' LIMIT 1');
|
||||
if (!pwg_db_num_rows($result))
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
$category = pwg_db_fetch_assoc($result);
|
||||
if ($category['status'] !== 'public')
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
$users = isset($_POST['users']) && is_array($_POST['users']) ? $_POST['users'] : array();
|
||||
$current_user_id = (int)$user['id'];
|
||||
$normalized_user_ids = array_map('intval', $users);
|
||||
|
||||
if (!in_array($current_user_id, $normalized_user_ids, true))
|
||||
{
|
||||
$users[] = $current_user_id;
|
||||
}
|
||||
|
||||
$_POST['users'] = $users;
|
||||
}
|
||||
|
||||
function bratonien_tools_admin_menu($menu)
|
||||
{
|
||||
$menu[] = array(
|
||||
|
||||
Reference in New Issue
Block a user