/
sharedraft.plugin.php
154 lines (126 loc) · 3.04 KB
/
sharedraft.plugin.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
<?php
class ShareDraftPlugin extends Plugin
{
/**
* Gets the secret key for a post
**/
public function get_secret_key( $post )
{
$key = md5($post->slug . Options::get('guid'));
return $key;
}
/**
* Gets the sharing URL for a post
**/
public function get_share_url( $post )
{
$key = $this->get_secret_key( $post );
$url = $post->permalink . '?sharedraft=' . $key;
return $url;
}
/**
* Checks if the proper credential has been supplied to access the current post
**/
private function is_authorized( $post = null, $deny = false )
{
$auth = Controller::get_var( 'sharedraft' );
// if there's no auth key, deny authorization automatically
if( $auth == null )
{
return false;
}
ACL::clear_caches(); // sadly, caching can't be used with Hisa
// if someone has an auth token but should be denied, mess them up
if( $deny == true )
{
// Utils::redirect( Site::get_url() );
exit;
return false;
}
// we assume the authorization is fine until actually testing the post
if( $post != null )
{
if( $auth != $this->get_secret_key( $post ) )
{
return false;
}
}
return true;
}
/**
* A helper function to prevent access with Hisa
**/
public function deny_access()
{
$this->is_authorized( null, true );
}
/**
* Update the where filters for querying a post if the sharedraft key is set
*
* @param array $filters The array of pre-existing filters
* @return array The modified array, if the key is set
*/
public function filter_template_where_filters( $filters)
{
if( $this->is_authorized() )
{
unset( $filters['status'] );
// Utils::debug( $filters, $filters['status'] );
}
return $filters;
}
/**
* Give users access to the token if they passed along the proper key
**/
public function filter_user_token_access( $accesses, $user_id, $token_id )
{
// Utils::debug( $accesses, $user_id, $token_id );
if( $this->is_authorized() )
{
$bitmask = ACL::get_bitmask( 0 );
$bitmask->read = true;
$accesses[0] = $bitmask->value;
}
return $accesses;
}
/**
* Run the actual check of the post authorization here, in the template header
**/
public function action_template_header( $theme )
{
if( $theme->posts instanceof Posts )
{
// if someone is trying to sneak into multiple posts, kill their attempt
$this->deny_access();
return;
}
elseif( $theme->post instanceof Post )
{
if( !$this->is_authorized( $theme->post ) )
{
$this->deny_access();
}
return;
}
else
{
return;
}
// if( !$this->is_authorized( $theme->post ) )
}
/**
* Update the publish form to display the draft link
*
* @param FormUI $form The publishing form
* @param Post $post The post displayed in the form
*/
function action_form_publish($form, $post)
{
if( $post->slug != '' ) {
$url = $this->get_share_url( $post );
$share_url = $form->settings->append( 'text', 'share_url', 'null:null', _t( 'Share URL', 'hisa' ), 'tabcontrol_text' );
$share_url->value = $url;
}
}
}
?>