Class AdminAccessController
This class contains some helper methods for handling view requests. Be careful always when outputting raw user data to HTML or when handling POST requests because insufficient protection will lead to XSS and CSRF vulnerabilities.
category |
System |
---|---|
package |
AdminHttpViewControllers |
__construct(\HttpContextReaderInterface $httpContextReader, \HttpResponseProcessorInterface $httpResponseProcessor, \ContentViewInterface $defaultContentView)
\HttpContextReaderInterface
\HttpResponseProcessorInterface
\ContentViewInterface
_appendGroupChildrenToGroupsArray(array $children, array &$groupsArray, integer $parentId)
array
array
integer
_callActionMethod(string $actionName) : \HttpControllerResponseInterface
Throws |
|
---|
string
Name of action method to call, without 'action'-Suffix.
\HttpControllerResponseInterface
Response message.
_getAdminById(integer $adminId) : array
integer
array
_getAdminEditsListElementActions() : array
array
_getAdminEditsListItems( $adminId) : array
array
_getAdminsOverviewsListElementActions() : array
array
_getAdminsOverviewsListItems() : array
array
_getAssets() : \AssetCollection
_getGlobalPermissonsOverviewListItems( $roleId) : array
Throws |
|
---|
array
_getPermissionOverviewsGroupCollection() : \AdminAccessGroupCollection
_getPermissionsOverviewsListItems(integer $roleId) : array
Throws |
|
---|
integer
array
_getPostData(string $keyName) : string|null
This method is the object oriented layer for $_POST[$keyName].
string
Expected key of post parameter.
string|null
Either the expected value or null, of not found.
_getPostDataCollection() : \KeyValueCollection
_getQueryParameter(string $keyName) : mixed|null
This method is the object oriented layer for $_GET[$keyName].
string
Expected key of query parameter.
mixed|null
Either the expected value or null, of not found.
_getQueryParametersCollection() : \KeyValueCollection
_getRoleById(integer $roleId) : array
integer
array
_getRolesOverviewsListAction() : array
array
_getRolesOverviewsListItems() : array
array
_getServerData(string $keyName) : string|null
This method is the object oriented layer for $_SERVER[$keyName].
string
Expected key of server parameter.
string|null
Either the expected value or null, of not found.
_grantAllPermissionsForRole( $type, $roleId)
Throws |
|
---|
_render(string $templateFile, array $contentArray) : string
string
Template file to render.
array
Content array which represent the variables of the template.
string
Rendered template.
_returnHttpResponse(string $title = '', string $template = 'overview.html', array $templateData = array(), string $currentSection = '') : \AdminLayoutHttpControllerResponse
string
string
array
string
\AdminLayoutHttpControllerResponse
_updateAssignedRolesForAdmin( $adminId, array $assignedRoles)
array
_updatePermissionsForRole( $type, $roleId, array $grantedGroups)
Throws |
|
---|
array
_updateUnknownPermissionsForRole( $type, $roleId, $value)
_validatePageToken(string $customExceptionMessage = null)
Example: public function proceed(HttpContextInterface $httpContext) { parent::proceed($httpContext); // proceed http context from parent class if($_SERVER['REQUEST_METHOD'] === 'POST') { $this->_validatePageToken(); // CSRF Protection } }
Throws |
|
---|
string
(optional) You can specify a custom exception message.
actionAssignRoles() : \RedirectHttpControllerResponse
actionDefault() : \HttpControllerResponseInterface
Every controller child class requires at least the default action method, which is invoked when the ::_getQueryParameterData('do') value is not separated by a trailing slash.
Every action method have to return an instance which implements the http controller response interface.
\HttpControllerResponseInterface
actionEditAdmin() : \AdminLayoutHttpControllerResponse
actionManageAdmins() : \AdminLayoutHttpControllerResponse
actionManagePermissions() : \AdminLayoutHttpControllerResponse
actionManageRoles() : \AdminLayoutHttpControllerResponse
actionSavePermissions() : \RedirectHttpControllerResponse
getTemplateFile(string $templateFile) : \ExistingFile
Throws |
|
---|
string
The relative path and filename to search for
\ExistingFile
containing absolute file path to the given template file
init()
proceed(\HttpContextInterface $httpContext)
The action method is determined by the http context reader instance and the current request context. Re-implement this method in child classes to enable XSS and CSRF protection on demand.
see | \HttpResponseProcessorInterface::proceed \HttpContextReaderInterface::getActionName |
---|---|
Throws |
|
validateCurrentAdminStatus()
Throws |
|
---|
db : \CI_DB_query_builder
var |
---|
\CI_DB_query_builder
languageTextManager : \LanguageTextManager
var |
---|
\LanguageTextManager
templatePath : string
var |
---|
string
httpContextReader : \HttpContextReaderInterface
httpResponseProcessor : \HttpResponseProcessorInterface
queryParametersArray : array
var |
---|
array
postDataArray : array
var |
---|
array
assets : \AssetCollectionInterface
serverDataArray : array
var |
Server data. |
---|
array