mirror of
https://github.com/Vateron-Media/XC_VM.git
synced 2026-10-03 12:02:29 +02:00
Administrator groups can be limited to a list of advanced permissions (add_user, settings, database, …). None of it was applied: - PageAuthorization::checkPermissions() and checkResellerPermissions(), called without a page (every controller's requirePermission()), took the page from SCRIPT_FILENAME. Under the front controller that is always Public/index.php, so the page checked was "index", which no rule names: every page opened for every administrator and reseller. - post.php saves all 63 admin forms and checked the page "post", also unnamed. A restricted administrator could save anything — settings, servers, or their own user with member_group_id=1, becoming a full admin. The page now comes from AdminHelpers::getPageName() (the route's PAGE_NAME). post.php holds each action to the rule of the page it saves, through checkPostAction(): add vs edit is decided by the form's `edit` field instead of ?id=, mass_delete_* map to mass_delete, TMDb category import to categories. The Enigma2 device page had no rule at all and now has the MAG one (add_e2 / edit_e2). The administrator's own profile and module settings stay open, as before. Full administrators (group 1, or a group with no advanced list) are unaffected. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA
51 lines
2.4 KiB
PHP
51 lines
2.4 KiB
PHP
<?php
|
|
|
|
use PHPUnit\Framework\TestCase;
|
|
use XcVm\Core\Auth\PageAuthorization;
|
|
|
|
/**
|
|
* post.php saves every admin form (63 actions). It used to check the page
|
|
* "post", which no rule names, so a restricted administrator — an admin group
|
|
* with a list of advanced permissions — could save anything, their own group
|
|
* included. checkPostAction() applies the rule of the page each action saves.
|
|
*/
|
|
final class PageAuthorizationPostActionTest extends TestCase {
|
|
|
|
protected function setUp(): void {
|
|
// A restricted administrator: may manage and edit lines, nothing else.
|
|
$GLOBALS['rUserInfo'] = ['id' => 9, 'member_group_id' => 5];
|
|
$GLOBALS['rPermissions'] = ['is_admin' => 1, 'advanced' => ['users', 'edit_user']];
|
|
$GLOBALS['db'] = new stdClass();
|
|
}
|
|
|
|
protected function tearDown(): void {
|
|
unset($GLOBALS['rUserInfo'], $GLOBALS['rPermissions'], $GLOBALS['db']);
|
|
}
|
|
|
|
public function testRestrictedAdminIsHeldToThePageRules(): void {
|
|
$this->assertTrue(PageAuthorization::checkPostAction('line', true), 'edit a line (edit_user)');
|
|
$this->assertFalse(PageAuthorization::checkPostAction('line', false), 'add a line (add_user)');
|
|
$this->assertFalse(PageAuthorization::checkPostAction('user', true), 'edit a panel user, e.g. their own group');
|
|
$this->assertFalse(PageAuthorization::checkPostAction('settings', false));
|
|
$this->assertFalse(PageAuthorization::checkPostAction('quick_tools', false));
|
|
$this->assertFalse(PageAuthorization::checkPostAction('mass_delete_lines', false), 'mass delete');
|
|
$this->assertFalse(PageAuthorization::checkPostAction('enigma', false), 'add an Enigma2 device');
|
|
$this->assertFalse(PageAuthorization::checkPostAction('import_tmdb_categories', false));
|
|
$this->assertTrue(PageAuthorization::checkPostAction('edit_profile', false), 'own profile');
|
|
}
|
|
|
|
public function testFullAdministratorKeepsEverything(): void {
|
|
$GLOBALS['rUserInfo']['member_group_id'] = 1;
|
|
foreach (['line', 'user', 'settings', 'quick_tools', 'mass_delete_lines', 'enigma', 'stream', 'server'] as $rAction) {
|
|
$this->assertTrue(PageAuthorization::checkPostAction($rAction, false), $rAction);
|
|
$this->assertTrue(PageAuthorization::checkPostAction($rAction, true), $rAction . ' (edit)');
|
|
}
|
|
}
|
|
|
|
public function testEnigmaPageFollowsTheMagRules(): void {
|
|
$GLOBALS['rPermissions']['advanced'] = ['edit_e2'];
|
|
$this->assertTrue(PageAuthorization::checkPermissions('enigma', true));
|
|
$this->assertFalse(PageAuthorization::checkPermissions('enigma', false));
|
|
}
|
|
}
|