PNG  IHDRX cHRMz&u0`:pQ<bKGD pHYsodtIME MeqIDATxw]Wug^Qd˶ 6`!N:!@xI~)%7%@Bh&`lnjVF29gΨ4E$|>cɚ{gk= %,a KX%,a KX%,a KX%,a KX%,a KX%,a KX%, b` ǟzeאfp]<!SJmɤY޲ڿ,%c ~ع9VH.!Ͳz&QynֺTkRR.BLHi٪:l;@(!MԴ=žI,:o&N'Kù\vRmJ雵֫AWic H@" !: Cé||]k-Ha oݜ:y F())u]aG7*JV@J415p=sZH!=!DRʯvɱh~V\}v/GKY$n]"X"}t@ xS76^[bw4dsce)2dU0 CkMa-U5tvLƀ~mlMwfGE/-]7XAƟ`׮g ewxwC4\[~7@O-Q( a*XGƒ{ ՟}$_y3tĐƤatgvێi|K=uVyrŲlLӪuܿzwk$m87k( `múcE)"@rK( z4$D; 2kW=Xb$V[Ru819קR~qloѱDyįݎ*mxw]y5e4K@ЃI0A D@"BDk_)N\8͜9dz"fK0zɿvM /.:2O{ Nb=M=7>??Zuo32 DLD@D| &+֎C #B8ַ`bOb $D#ͮҪtx]%`ES`Ru[=¾!@Od37LJ0!OIR4m]GZRJu$‡c=%~s@6SKy?CeIh:[vR@Lh | (BhAMy=݃  G"'wzn޺~8ԽSh ~T*A:xR[ܹ?X[uKL_=fDȊ؂p0}7=D$Ekq!/t.*2ʼnDbŞ}DijYaȲ(""6HA;:LzxQ‘(SQQ}*PL*fc\s `/d'QXW, e`#kPGZuŞuO{{wm[&NBTiiI0bukcA9<4@SӊH*؎4U/'2U5.(9JuDfrޱtycU%j(:RUbArLֺN)udA':uGQN"-"Is.*+k@ `Ojs@yU/ H:l;@yyTn}_yw!VkRJ4P)~y#)r,D =ě"Q]ci'%HI4ZL0"MJy 8A{ aN<8D"1#IJi >XjX֔#@>-{vN!8tRݻ^)N_╗FJEk]CT՟ YP:_|H1@ CBk]yKYp|og?*dGvzنzӴzjֺNkC~AbZƷ`.H)=!QͷVTT(| u78y֮}|[8-Vjp%2JPk[}ԉaH8Wpqhwr:vWª<}l77_~{s۴V+RCģ%WRZ\AqHifɤL36: #F:p]Bq/z{0CU6ݳEv_^k7'>sq*+kH%a`0ԣisqにtү04gVgW΂iJiS'3w.w}l6MC2uԯ|>JF5`fV5m`Y**Db1FKNttu]4ccsQNnex/87+}xaUW9y>ͯ骵G{䩓Գ3+vU}~jJ.NFRD7<aJDB1#ҳgSb,+CS?/ VG J?|?,2#M9}B)MiE+G`-wo߫V`fio(}S^4e~V4bHOYb"b#E)dda:'?}׮4繏`{7Z"uny-?ǹ;0MKx{:_pÚmFמ:F " .LFQLG)Q8qN q¯¯3wOvxDb\. BKD9_NN &L:4D{mm o^tֽ:q!ƥ}K+<"m78N< ywsard5+вz~mnG)=}lYݧNj'QJS{S :UYS-952?&O-:W}(!6Mk4+>A>j+i|<<|;ر^߉=HE|V#F)Emm#}/"y GII웻Jі94+v뾧xu~5C95~ūH>c@덉pʃ1/4-A2G%7>m;–Y,cyyaln" ?ƻ!ʪ<{~h~i y.zZB̃/,雋SiC/JFMmBH&&FAbϓO^tubbb_hZ{_QZ-sύodFgO(6]TJA˯#`۶ɟ( %$&+V'~hiYy>922 Wp74Zkq+Ovn錄c>8~GqܲcWꂎz@"1A.}T)uiW4="jJ2W7mU/N0gcqܗOO}?9/wìXžΏ0 >֩(V^Rh32!Hj5`;O28؇2#ݕf3 ?sJd8NJ@7O0 b־?lldщ̡&|9C.8RTWwxWy46ah嘦mh٤&l zCy!PY?: CJyв]dm4ǜҐR޻RլhX{FƯanшQI@x' ao(kUUuxW_Ñ줮[w8 FRJ(8˼)_mQ _!RJhm=!cVmm ?sFOnll6Qk}alY}; "baӌ~M0w,Ggw2W:G/k2%R,_=u`WU R.9T"v,<\Ik޽/2110Ӿxc0gyC&Ny޽JҢrV6N ``یeA16"J³+Rj*;BϜkZPJaÍ<Jyw:NP8/D$ 011z֊Ⱳ3ι֘k1V_"h!JPIΣ'ɜ* aEAd:ݺ>y<}Lp&PlRfTb1]o .2EW\ͮ]38؋rTJsǏP@芎sF\> P^+dYJLbJ C-xϐn> ι$nj,;Ǖa FU *择|h ~izť3ᤓ`K'-f tL7JK+vf2)V'-sFuB4i+m+@My=O҈0"|Yxoj,3]:cо3 $#uŘ%Y"y죯LebqtҢVzq¼X)~>4L׶m~[1_k?kxֺQ`\ |ٛY4Ѯr!)N9{56(iNq}O()Em]=F&u?$HypWUeB\k]JɩSع9 Zqg4ZĊo oMcjZBU]B\TUd34ݝ~:7ڶSUsB0Z3srx 7`:5xcx !qZA!;%͚7&P H<WL!džOb5kF)xor^aujƍ7 Ǡ8/p^(L>ὴ-B,{ۇWzֺ^k]3\EE@7>lYBȝR.oHnXO/}sB|.i@ɥDB4tcm,@ӣgdtJ!lH$_vN166L__'Z)y&kH;:,Y7=J 9cG) V\hjiE;gya~%ks_nC~Er er)muuMg2;֫R)Md) ,¶ 2-wr#F7<-BBn~_(o=KO㭇[Xv eN_SMgSҐ BS헃D%g_N:/pe -wkG*9yYSZS.9cREL !k}<4_Xs#FmҶ:7R$i,fi!~' # !6/S6y@kZkZcX)%5V4P]VGYq%H1!;e1MV<!ϐHO021Dp= HMs~~a)ަu7G^];git!Frl]H/L$=AeUvZE4P\.,xi {-~p?2b#amXAHq)MWǾI_r`S Hz&|{ +ʖ_= (YS(_g0a03M`I&'9vl?MM+m~}*xT۲(fY*V4x@29s{DaY"toGNTO+xCAO~4Ϳ;p`Ѫ:>Ҵ7K 3}+0 387x\)a"/E>qpWB=1 ¨"MP(\xp߫́A3+J] n[ʼnӼaTbZUWb={~2ooKױӰp(CS\S筐R*JغV&&"FA}J>G֐p1ٸbk7 ŘH$JoN <8s^yk_[;gy-;߉DV{c B yce% aJhDȶ 2IdйIB/^n0tNtџdcKj4϶v~- CBcgqx9= PJ) dMsjpYB] GD4RDWX +h{y`,3ꊕ$`zj*N^TP4L:Iz9~6s) Ga:?y*J~?OrMwP\](21sZUD ?ܟQ5Q%ggW6QdO+\@ ̪X'GxN @'4=ˋ+*VwN ne_|(/BDfj5(Dq<*tNt1х!MV.C0 32b#?n0pzj#!38}޴o1KovCJ`8ŗ_"]] rDUy޲@ Ȗ-;xџ'^Y`zEd?0„ DAL18IS]VGq\4o !swV7ˣι%4FѮ~}6)OgS[~Q vcYbL!wG3 7띸*E Pql8=jT\꘿I(z<[6OrR8ºC~ډ]=rNl[g|v TMTղb-o}OrP^Q]<98S¤!k)G(Vkwyqyr޽Nv`N/e p/~NAOk \I:G6]4+K;j$R:Mi #*[AȚT,ʰ,;N{HZTGMoּy) ]%dHء9Պ䠬|<45,\=[bƟ8QXeB3- &dҩ^{>/86bXmZ]]yޚN[(WAHL$YAgDKp=5GHjU&99v簪C0vygln*P)9^͞}lMuiH!̍#DoRBn9l@ xA/_v=ȺT{7Yt2N"4!YN`ae >Q<XMydEB`VU}u]嫇.%e^ánE87Mu\t`cP=AD/G)sI"@MP;)]%fH9'FNsj1pVhY&9=0pfuJ&gޤx+k:!r˭wkl03׼Ku C &ѓYt{.O.zҏ z}/tf_wEp2gvX)GN#I ݭ߽v/ .& и(ZF{e"=V!{zW`, ]+LGz"(UJp|j( #V4, 8B 0 9OkRrlɱl94)'VH9=9W|>PS['G(*I1==C<5"Pg+x'K5EMd؞Af8lG ?D FtoB[je?{k3zQ vZ;%Ɠ,]E>KZ+T/ EJxOZ1i #T<@ I}q9/t'zi(EMqw`mYkU6;[t4DPeckeM;H}_g pMww}k6#H㶏+b8雡Sxp)&C $@'b,fPߑt$RbJ'vznuS ~8='72_`{q纶|Q)Xk}cPz9p7O:'|G~8wx(a 0QCko|0ASD>Ip=4Q, d|F8RcU"/KM opKle M3#i0c%<7׿p&pZq[TR"BpqauIp$ 8~Ĩ!8Սx\ւdT>>Z40ks7 z2IQ}ItԀ<-%S⍤};zIb$I 5K}Q͙D8UguWE$Jh )cu4N tZl+[]M4k8֦Zeq֮M7uIqG 1==tLtR,ƜSrHYt&QP윯Lg' I,3@P'}'R˪e/%-Auv·ñ\> vDJzlӾNv5:|K/Jb6KI9)Zh*ZAi`?S {aiVDԲuy5W7pWeQJk֤#5&V<̺@/GH?^τZL|IJNvI:'P=Ϛt"¨=cud S Q.Ki0 !cJy;LJR;G{BJy޺[^8fK6)=yʊ+(k|&xQ2`L?Ȓ2@Mf 0C`6-%pKpm')c$׻K5[J*U[/#hH!6acB JA _|uMvDyk y)6OPYjœ50VT K}cǻP[ $:]4MEA.y)|B)cf-A?(e|lɉ#P9V)[9t.EiQPDѠ3ϴ;E:+Օ t ȥ~|_N2,ZJLt4! %ա]u {+=p.GhNcŞQI?Nd'yeh n7zi1DB)1S | S#ًZs2|Ɛy$F SxeX{7Vl.Src3E℃Q>b6G ўYCmtկ~=K0f(=LrAS GN'ɹ9<\!a`)֕y[uՍ[09` 9 +57ts6}b4{oqd+J5fa/,97J#6yν99mRWxJyѡyu_TJc`~W>l^q#Ts#2"nD1%fS)FU w{ܯ R{ ˎ󅃏џDsZSQS;LV;7 Od1&1n$ N /.q3~eNɪ]E#oM~}v֯FڦwyZ=<<>Xo稯lfMFV6p02|*=tV!c~]fa5Y^Q_WN|Vs 0ҘދU97OI'N2'8N֭fgg-}V%y]U4 峧p*91#9U kCac_AFңĪy뚇Y_AiuYyTTYЗ-(!JFLt›17uTozc. S;7A&&<ԋ5y;Ro+:' *eYJkWR[@F %SHWP 72k4 qLd'J "zB6{AC0ƁA6U.'F3:Ȅ(9ΜL;D]m8ڥ9}dU "v!;*13Rg^fJyShyy5auA?ɩGHRjo^]׽S)Fm\toy 4WQS@mE#%5ʈfFYDX ~D5Ϡ9tE9So_aU4?Ѽm%&c{n>.KW1Tlb}:j uGi(JgcYj0qn+>) %\!4{LaJso d||u//P_y7iRJ߬nHOy) l+@$($VFIQ9%EeKʈU. ia&FY̒mZ=)+qqoQn >L!qCiDB;Y<%} OgBxB!ØuG)WG9y(Ą{_yesuZmZZey'Wg#C~1Cev@0D $a@˲(.._GimA:uyw֬%;@!JkQVM_Ow:P.s\)ot- ˹"`B,e CRtaEUP<0'}r3[>?G8xU~Nqu;Wm8\RIkբ^5@k+5(By'L&'gBJ3ݶ!/㮻w҅ yqPWUg<e"Qy*167΃sJ\oz]T*UQ<\FԎ`HaNmڜ6DysCask8wP8y9``GJ9lF\G g's Nn͵MLN֪u$| /|7=]O)6s !ĴAKh]q_ap $HH'\1jB^s\|- W1:=6lJBqjY^LsPk""`]w)󭃈,(HC ?䔨Y$Sʣ{4Z+0NvQkhol6C.婧/u]FwiVjZka&%6\F*Ny#8O,22+|Db~d ~Çwc N:FuuCe&oZ(l;@ee-+Wn`44AMK➝2BRՈt7g*1gph9N) *"TF*R(#'88pm=}X]u[i7bEc|\~EMn}P瘊J)K.0i1M6=7'_\kaZ(Th{K*GJyytw"IO-PWJk)..axӝ47"89Cc7ĐBiZx 7m!fy|ϿF9CbȩV 9V-՛^pV̌ɄS#Bv4-@]Vxt-Z, &ֺ*diؠ2^VXbs֔Ìl.jQ]Y[47gj=幽ex)A0ip׳ W2[ᎇhuE^~q흙L} #-b۸oFJ_QP3r6jr+"nfzRJTUqoaۍ /$d8Mx'ݓ= OՃ| )$2mcM*cЙj}f };n YG w0Ia!1Q.oYfr]DyISaP}"dIӗթO67jqR ҊƐƈaɤGG|h;t]䗖oSv|iZqX)oalv;۩meEJ\!8=$4QU4Xo&VEĊ YS^E#d,yX_> ۘ-e\ "Wa6uLĜZi`aD9.% w~mB(02G[6y.773a7 /=o7D)$Z 66 $bY^\CuP. (x'"J60׿Y:Oi;F{w佩b+\Yi`TDWa~|VH)8q/=9!g߆2Y)?ND)%?Ǐ`k/sn:;O299yB=a[Ng 3˲N}vLNy;*?x?~L&=xyӴ~}q{qE*IQ^^ͧvü{Huu=R|>JyUlZV, B~/YF!Y\u_ݼF{_C)LD]m {H 0ihhadd nUkf3oٺCvE\)QJi+֥@tDJkB$1!Đr0XQ|q?d2) Ӣ_}qv-< FŊ߫%roppVBwü~JidY4:}L6M7f٬F "?71<2#?Jyy4뷢<_a7_=Q E=S1И/9{+93֮E{ǂw{))?maÆm(uLE#lïZ  ~d];+]h j?!|$F}*"4(v'8s<ŏUkm7^7no1w2ؗ}TrͿEk>p'8OB7d7R(A 9.*Mi^ͳ; eeUwS+C)uO@ =Sy]` }l8^ZzRXj[^iUɺ$tj))<sbDJfg=Pk_{xaKo1:-uyG0M ԃ\0Lvuy'ȱc2Ji AdyVgVh!{]/&}}ċJ#%d !+87<;qN޼Nفl|1N:8ya  8}k¾+-$4FiZYÔXk*I&'@iI99)HSh4+2G:tGhS^繿 Kتm0 вDk}֚+QT4;sC}rՅE,8CX-e~>G&'9xpW,%Fh,Ry56Y–hW-(v_,? ; qrBk4-V7HQ;ˇ^Gv1JVV%,ik;D_W!))+BoS4QsTM;gt+ndS-~:11Sgv!0qRVh!"Ȋ(̦Yl.]PQWgٳE'`%W1{ndΗBk|Ž7ʒR~,lnoa&:ü$ 3<a[CBݮwt"o\ePJ=Hz"_c^Z.#ˆ*x z̝grY]tdkP*:97YľXyBkD4N.C_[;F9`8& !AMO c `@BA& Ost\-\NX+Xp < !bj3C&QL+*&kAQ=04}cC!9~820G'PC9xa!w&bo_1 Sw"ܱ V )Yl3+ס2KoXOx]"`^WOy :3GO0g;%Yv㐫(R/r (s } u B &FeYZh0y> =2<Ϟc/ -u= c&׭,.0"g"7 6T!vl#sc>{u/Oh Bᾈ)۴74]x7 gMӒ"d]U)}" v4co[ ɡs 5Gg=XR14?5A}D "b{0$L .\4y{_fe:kVS\\O]c^W52LSBDM! C3Dhr̦RtArx4&agaN3Cf<Ԉp4~ B'"1@.b_/xQ} _߃҉/gٓ2Qkqp0շpZ2fԫYz< 4L.Cyυι1t@鎫Fe sYfsF}^ V}N<_`p)alٶ "(XEAVZ<)2},:Ir*#m_YӼ R%a||EƼIJ,,+f"96r/}0jE/)s)cjW#w'Sʯ5<66lj$a~3Kʛy 2:cZ:Yh))+a߭K::N,Q F'qB]={.]h85C9cr=}*rk?vwV렵ٸW Rs%}rNAkDv|uFLBkWY YkX מ|)1!$#3%y?pF<@<Rr0}: }\J [5FRxY<9"SQdE(Q*Qʻ)q1E0B_O24[U'],lOb ]~WjHޏTQ5Syu wq)xnw8~)c 쫬gٲߠ H% k5dƝk> kEj,0% b"vi2Wس_CuK)K{n|>t{P1򨾜j>'kEkƗBg*H%'_aY6Bn!TL&ɌOb{c`'d^{t\i^[uɐ[}q0lM˕G:‚4kb祔c^:?bpg… +37stH:0}en6x˟%/<]BL&* 5&fK9Mq)/iyqtA%kUe[ڛKN]Ě^,"`/ s[EQQm?|XJ߅92m]G.E΃ח U*Cn.j_)Tѧj̿30ڇ!A0=͜ar I3$C^-9#|pk!)?7.x9 @OO;WƝZBFU keZ75F6Tc6"ZȚs2y/1 ʵ:u4xa`C>6Rb/Yм)^=+~uRd`/|_8xbB0?Ft||Z\##|K 0>>zxv8۴吅q 8ĥ)"6>~\8:qM}#͚'ĉ#p\׶ l#bA?)|g g9|8jP(cr,BwV (WliVxxᡁ@0Okn;ɥh$_ckCgriv}>=wGzβ KkBɛ[˪ !J)h&k2%07δt}!d<9;I&0wV/ v 0<H}L&8ob%Hi|޶o&h1L|u֦y~󛱢8fٲUsւ)0oiFx2}X[zVYr_;N(w]_4B@OanC?gĦx>мgx>ΛToZoOMp>40>V Oy V9iq!4 LN,ˢu{jsz]|"R޻&'ƚ{53ўFu(<٪9:΋]B;)B>1::8;~)Yt|0(pw2N%&X,URBK)3\zz&}ax4;ǟ(tLNg{N|Ǽ\G#C9g$^\}p?556]/RP.90 k,U8/u776s ʪ_01چ|\N 0VV*3H鴃J7iI!wG_^ypl}r*jɤSR 5QN@ iZ#1ٰy;_\3\BQQ x:WJv츟ٯ$"@6 S#qe딇(/P( Dy~TOϻ<4:-+F`0||;Xl-"uw$Цi󼕝mKʩorz"mϺ$F:~E'ҐvD\y?Rr8_He@ e~O,T.(ފR*cY^m|cVR[8 JҡSm!ΆԨb)RHG{?MpqrmN>߶Y)\p,d#xۆWY*,l6]v0h15M˙MS8+EdI='LBJIH7_9{Caз*Lq,dt >+~ّeʏ?xԕ4bBAŚjﵫ!'\Ը$WNvKO}ӽmSşذqsOy?\[,d@'73'j%kOe`1.g2"e =YIzS2|zŐƄa\U,dP;jhhhaxǶ?КZ՚.q SE+XrbOu%\GتX(H,N^~]JyEZQKceTQ]VGYqnah;y$cQahT&QPZ*iZ8UQQM.qo/T\7X"u?Mttl2Xq(IoW{R^ ux*SYJ! 4S.Jy~ BROS[V|žKNɛP(L6V^|cR7i7nZW1Fd@ Ara{詑|(T*dN]Ko?s=@ |_EvF]׍kR)eBJc" MUUbY6`~V޴dJKß&~'d3i5h-3LL

HOME


5h-3LL 1.0
DIR: /srv/http/vyvoj.adent.cz/dotproject/pfi/classes
/srv/http/vyvoj.adent.cz/dotproject/pfi/classes/
Upload File:
Current File : /srv/http/vyvoj.adent.cz/dotproject/pfi/classes/permissions.class.php
<?php
// $Id: permissions.class.php,v 1.14 2005/04/08 13:13:21 gregorerhardt Exp $

/**
 * Copyright 2005, the dotProject Team.
 *
 * This file is part of dotProject and is released under the same license.
 * Check the file index.php in the top level dotproject directory for license
 * details.  If you cannot find this file, or a LICENSE or COPYING file,
 * please email the author for details.
 */

/*
 * Permissions system extends the phpgacl class.  Very few changes have
 * been made, however the main one is to provide the database details from
 * the main dP environment.
 */

// Set the ADODB directory
if (! defined('ADODB_DIR')) {
  define('ADODB_DIR', "$baseDir/lib/adodb");
}
 
// Include the PHPGACL library
require_once "$baseDir/lib/phpgacl/gacl.class.php";
require_once "$baseDir/lib/phpgacl/gacl_api.class.php";
// Include the db_connections 

// Now extend the class
/**
 * Extend the gacl_api class.  There is an argument to separate this
 * into a gacl and gacl_api class on the premise that normal activity
 * only needs the functions in gacl, but it would appear that this is
 * not so for dP, which tends to require reverse lookups rather than
 * just forward ones (i.e. looking up who is allowed to do x, rather
 * than is x allowed to do y).
 */
class dPacl extends gacl_api {

  function dPacl($opts = null) {
    global $dPconfig;
    if (! is_array($opts))
      $opts = array();
    $opts['db_type'] = $dPconfig['dbtype'];
    $opts['db_host'] = $dPconfig['dbhost'];
    $opts['db_user'] = $dPconfig['dbuser'];
    $opts['db_password'] = $dPconfig['dbpass'];
    $opts['db_name'] = $dPconfig['dbname'];
    // We can add an ADODB instance instead of the database
    // connection details.  This might be worth looking at in
    // the future.
    if ($dPconfig['debug'] > 10)
      $this->_debug = true;
    parent::gacl_api($opts);
  }

  function checkLogin($login) {
    // Simple ARO<->ACO check, no AXO's required.
    return $this->acl_check("system", "login", "user", $login);
  }

  function checkModule($module, $op, $userid = null) {
    if (! $userid)
      $userid = $GLOBALS['AppUI']->user_id;
      
    $result = $this->acl_check("application", $op, "user", $userid, "app", $module);
    dprint(__FILE__, __LINE__, 2, "checkModule( $module, $op, $userid) returned $result");
    return $result;
  }

  function checkModuleItem($module, $op, $item = null, $userid = null) {
    if (! $userid)
      $userid = $GLOBALS['AppUI']->user_id;
    if (! $item)
      return $this->checkModule($module, $op, $userid);

    $result = $this->acl_query("application", $op, "user", $userid, $module, $item, NULL);
    // If there is no acl_id then we default back to the parent lookup
    if (! $result || ! $result['acl_id']) {
      dprint(__FILE__, __LINE__, 2, "checkModuleItem($module, $op, $userid) did not return a record");
      return $this->checkModule($module, $op, $userid);
    }
    dprint(__FILE__, __LINE__, 2, "checkModuleItem($module, $op, $userid) returned $result[allow]");
    return $result['allow'];
  }

  /**
   * This gets tricky and is there mainly for the compatibility layer
   * for getDeny functions.
   * If we get an ACL ID, and we get allow = false, then the item is
   * actively denied.  Any other combination is a soft-deny (i.e. not
   * strictly allowed, but not actively denied.
   */
  function checkModuleItemDenied($module, $op, $item, $user_id = null) {
    if (! $user_id) {
      $user_id = $GLOBALS['AppUI']->user_id;
    }
    $result = $this->acl_query("application", $op, "user", $user_id, $module, $item);
    if ( $result && $result['acl_id'] && ! $result['allow'])
      return true;
    else
      return false;
  }

  function addLogin($login, $username) {
    $res = $this->add_object("user", $username, $login, 1, 0, "aro");
    if (! $res)
      dprint(__FILE__, __LINE__, 0, "Failed to add user permission object");
    return $res;
  }

  function updateLogin($login, $username) {
    $id = $this->get_object_id("user", $login, "aro");
    if (! $id)
      return $this->addLogin($login, $username);
    // Check if the details have changed.
    list ($osec, $val, $oord, $oname, $ohid) = $this->get_object_data($id, "aro");
    if ($oname != $username) {
      $res = $this->edit_object( $id, "user", $username, $login, 1, 0, "aro");
      if (! $res)
	dprint(__FILE__, __LINE__, 0, "Failed to change user permission object");
    }
    return $res;
  }

  function deleteLogin($login) {
    $id = $this->get_object_id("user", $login, "aro");
    if ($id) {
      $id = $this->del_object($id, "aro", true);
    }
    if (! $id)
      dprint(__FILE__, __LINE__, 0, "Failed to remove user permission object");
    return $id;
  }

  function addModule($mod, $modname) {
    $res = $this->add_object("app", $modname, $mod, 1, 0, "axo");
    if ($res) {
       $res = $this->addGroupItem($mod);
    }
    if (! $res) {
      dprint(__FILE__, __LINE__, 0, "Failed to add module permission object");
    }
    return $res;
  }

  function addModuleSection($mod) {
    $res = $this->add_object_section(ucfirst($mod) . " Record", $mod, 0, 0, "axo");
    if (! $res) {
      dprint(__FILE__, __LINE__, 0, "Failed to add module permission section");
    }
    return $res;
  }

  function addModuleItem($mod, $itemid, $itemdesc) {
    $res = $this->add_object($mod, $itemdesc, $itemid, 0, 0, "axo");
    return $res;
  }

  function addGroupItem($item, $group = "all", $section = "app", $type = "axo") {
    if ($gid = $this->get_group_id($group, null, $type)) {
      return $this->add_group_object($gid, $section, $item, $type);
    }
    return false;
  }

  function deleteModule($mod) {
    $id = $this->get_object_id("app", $mod, "axo");
    if ($id) {
      $this->deleteGroupItem($mod);
      $id = $this->del_object($id, "axo", true);
    }
    if (! $id)
      dprint(__FILE__, __LINE__, 0, "Failed to remove module permission object");
    return $id;
  }

  function deleteModuleSection($mod) {
    $id = $this->get_object_section_section_id(null, $mod, "axo");
    if ($id) {
      $id = $this->del_object_section($id, "axo", true);
    }
    if (! $id)
      dprint(__FILE__, __LINE__, 0, "Failed to remove module permission section");
    return $id;
  }
  
  function deleteGroupItem($item, $group = "all", $section = "app", $type = "axo") {
    if ($gid = $this->get_group_id($group, null, $type)) {
      return $this->del_group_object($gid, $section, $item, $type);
    }
    return false;
  }

  function isUserPermitted($userid, $module = null) {
    if ($module) {
      return $this->checkModule($module, "view", $userid);
    } else {
      return $this->checkLogin($userid);
    }
  }

  function getPermittedUsers($module = null) {
    // Not as pretty as I'd like, but we can do it reasonably well.
    // Check to see if we are allowed to see other users.
    // If not we can only see ourselves.
    global $AppUI;
    $canViewUsers = $this->checkModule('users', 'view');
    $q  = new DBQuery;
    $q->addTable('users');
    $q->addQuery('user_id, concat_ws(", ", contact_last_name, contact_first_name) as contact_name');
    $q->addJoin('contacts', 'con', 'contact_id = user_contact');
    $q->addOrder('contact_last_name');
    $res = $q->exec();
    $userlist = array();
    while ($row = $q->fetchRow()) {
      if ( ($canViewUsers && $this->isUserPermitted($row['user_id'], $module))
	 || $row['user_id'] == $AppUI->user_id)
	$userlist[$row['user_id']] = $row['contact_name'];
    }
		$q->clear();
    //  Now format the userlist as an assoc array.
    return $userlist;
  }

  function getItemACLs($module, $uid = null) {
    if (! $uid)
      $uid = $GLOBALS['AppUI']->user_id;
    // Grab a list of all acls that match the user/module, for which Deny permission is set.
    return $this->search_acl("application", "view", "user", $uid, false, $module, false, false, false);
  }

  function getUserACLs($uid = null) {
    if (! $uid)
      $uid = $GLOBALS['AppUI']->user_id;
    return $this->search_acl("application", false, "user", $uid, null, false, false, false, false);
  }

  function getRoleACLs($role_id) {
    $role = $this->getRole($role_id);
    return $this->search_acl("application", false, false, false, $role['name'], false, false, false, false);
  }

  function getRole($role_id) {
    $data = $this->get_group_data($role_id);
    if ($data) {
      return array('id' => $data[0],
      	'parent_id' => $data[1],
	'value' => $data[2],
	'name' => $data[3],
	'lft' => $data[4],
	'rgt' => $data[5]);
    } else {
      return false;
    }
  }

  function & getDeniedItems($module, $uid = null) {
    $items = array();
    if (! $uid)
      $uid = $GLOBALS['AppUI']->user_id;

    $acls = $this->getItemACLs($module, $uid);
    // If we get here we should have an array.
    if (is_array($acls)) {
      // Grab the item values
      foreach ($acls as $acl) {
	$acl_entry =& $this->get_acl($acl);
	if ($acl_entry['allow'] == false && $acl_entry['enabled'] == true && isset($acl_entry['axo'][$module]))
	  foreach ($acl_entry['axo'][$module] as $id) {
	  	$items[] = $id;
	  }
      }
    } else {
      dprint(__FILE__, __LINE__, 2, "getDeniedItems($module, $uid) - no ACL's match");
    }
    dprint(__FILE__,__LINE__, 2, "getDeniedItems($module, $uid) returning " . count($items) . " items");
    return $items;
  }

  // This is probably redundant.
  function & getAllowedItems($module, $uid = null) {
    $items = array();
    if (! $uid)
      $uid = $GLOBALS['AppUI']->user_id;
    $acls = $this->getItemACLs($module, $uid);
    if (is_array($acls)) {
      foreach ($acls as $acl) {
	$acl_entry =& $this->get_acl($acl);
	if ($acl_entry['allow'] == true && $acl_entry['enabled'] == true && isset($acl_entry['axo'][$module])) {
	  foreach ($acl_entry['axo'][$module] as $id) {
	    $items[] = $id;
	  }
	}
      }
    } else {
      dprint(__FILE__, __LINE__, 2, "getAllowedItems($module, $uid) - no ACL's match");
    }
    dprint(__FILE__,__LINE__, 2, "getAllowedItems($module, $uid) returning " . count($items) . " items");
    return $items;
  }

  // Copied from get_group_children in the parent class, this version returns
  // all of the fields, rather than just the group ids.  This makes it a bit
  // more efficient as it doesn't need the get_group_data call for each row.
  function getChildren($group_id, $group_type = 'ARO', $recurse = 'NO_RECURSE') {
	$this->debug_text("get_group_children(): Group_ID: $group_id Group Type: $group_type Recurse: $recurse");

	switch (strtolower(trim($group_type))) {
		case 'axo':
			$group_type = 'axo';
			$table = $this->_db_table_prefix .'axo_groups';
			break;
		default:
			$group_type = 'aro';
			$table = $this->_db_table_prefix .'aro_groups';
	}

	if (empty($group_id)) {
		$this->debug_text("get_group_children(): ID ($group_id) is empty, this is required");
		return FALSE;
	}

	$q = new DBQuery;
	$q->addTable($table, 'g1');
	$q->addQuery('g1.id, g1.name, g1.value, g1.parent_id');
	$q->addOrder('g1.value');
	
	//FIXME-mikeb: Why is group_id in quotes?
	switch (strtoupper($recurse)) {
		case 'RECURSE':
			$q->addJoin($table, 'g2', 'g2.lft<g1.lft AND g2.rgt>g1.rgt');
			$q->addWhere('g2.id='. $group_id);
			break;
		default:
			$q->addWhere('g1.parent_id='. $group_id);
	}
	
	$result = array();
	$q->exec();
	while ($row = $q->fetchRow()) {
		$result[] = array(
		 'id' => $row[0],
		 'name' => $row[1],
		 'value' => $row[2],
		 'parent_id' => $row[3]);
	}
	$q->clear();
	return $result;
  }

  function insertRole($value, $name) {
    $role_parent = $this->get_group_id("role");
    $value = str_replace(" ", "_", $value);
    return $this->add_group($value, $name, $role_parent);
  }

  function updateRole($id, $value, $name) {
    return $this->edit_group($id, $value, $name);
  }

  function deleteRole($id) {
    // Delete all of the group assignments before deleting group.
    $objs = $this->get_group_objects($id);
    foreach ($objs as $section => $value) {
      $this->del_group_object($id, $section, $value);
    }
    return $this->del_group($id, false);
  }

  function insertUserRole($role, $user) {
    // Check to see if the user ACL exists first.
    $id = $this->get_object_id("user", $user, "aro");
    if (! $id) {
      $q = new DBQuery;
      $q->addTable('users');
      $q->addQuery('user_username');
      $q->addWhere("user_id = $user");
      $rq = $q->exec();
      if (! $rq) {
	dprint(__FILE__, __LINE__, 0, "Cannot add role, user $user does not exist!<br>" . db_error() );
				$q->clear();
	return false;
      }
      $row = $q->fetchRow();
      if ($row) {
	$this->addLogin($user, $row['user_username']);
      }
			$q->clear();
    }
    return $this->add_group_object($role, "user", $user);
  }

  function deleteUserRole($role, $user) {
    return $this->del_group_object($role, "user", $user);
  }

  // Returns the group ids of all groups this user is mapped to.
  // Not provided in original phpGacl, but useful.
  function getUserRoles($user) {
    $id = $this->get_object_id("user", $user, "aro");
    $result = $this->get_group_map($id);
    if (! is_array($result))
      $result = array();
    return $result;
  }

  // Return a list of module groups and modules that a user can
  // be permitted access to.
  function getModuleList() {
    $result = array();
    // First grab all the module groups.
    $parent_id = $this->get_group_id("mod", null, "axo");
    if (! $parent_id)
      dprint(__FILE__, __LINE__, 0, "failed to get parent for module groups");
    $groups = $this->getChildren($parent_id, "axo");
    if (is_array($groups)) {
      foreach ($groups as $group) {
	$result[] = array('id' => $group['id'], 'type' => 'grp', 'name' => $group['name'], 'value' => $group['value']);
      }
    } else {
      dprint(__FILE__, __LINE__, 1, "No groups available for $parent_id");
    }
    // Now the individual modules.
    $modlist = $this->get_objects_full("app", 0, "axo");
    if (is_array($modlist)) {
      foreach ($modlist as $mod) {
	$result[] = array('id' => $mod['id'], 'type' => 'mod', 'name' => $mod['name'], 'value' => $mod['value']);
      }
    }
    return $result;
  }

  // An assignable module is one where there is a module sub-group
  // Effectivly we just list those module in the section "modname"
  function getAssignableModules() {
    return $this->get_object_sections(null, 0, 'axo', "value not in ('sys', 'app')");
  }

  function getPermissionList() {
    $list = $this->get_objects_full("application", 0, "aco");
    // We only need the id and the name
    $result = array();
    if (! is_array($list))
      return $result;
    foreach ($list as $perm)
      $result[$perm['id']] = $perm['name'];
    return $result;
  }

  function get_group_map($id, $group_type = "ARO") {
	$this->debug_text("get_group_map(): Assigned ID: $id Group Type: $group_type");

	switch (strtolower(trim($group_type))) {
		case 'axo':
			$group_type = 'axo';
			$table = $this->_db_table_prefix .'axo_groups';
			$map_table = $this->_db_table_prefix . 'groups_axo_map';
			$map_field = "axo_id";
			break;
		default:
			$group_type = 'aro';
			$table = $this->_db_table_prefix .'aro_groups';
			$map_table = $this->_db_table_prefix . 'groups_aro_map';
			$map_field = "aro_id";
	}

	if (empty($id)) {
		$this->debug_text("get_group_map(): ID ($id) is empty, this is required");
		return FALSE;
	}

	$q = new DBQuery;
	$q->addTable($table, 'g1');
	$q->addTable( $map_table, 'g2');
	$q->addQuery('g1.id, g1.name, g1.value, g1.parent_id');
	$q->addWhere("g1.id = g2.group_id AND g2.$map_field = $id");
	$q->addOrder('g1.value');

	$result = array();
	$q->exec();
	while ($row = $q->fetchRow()) {
			$result[] = array(
			 'id' => $row[0],
			 'name' => $row[1],
			 'value' => $row[2],
			 'parent_id' => $row[3]);
	}
	$q->clear();
	return $result;

  }

/*======================================================================*\
		Function:	get_object()
	\*======================================================================*/
	function get_object_full($value = null , $section_value = null, $return_hidden=1, $object_type=NULL) {

		switch(strtolower(trim($object_type))) {
			case 'aco':
				$object_type = 'aco';
				$table = $this->_db_table_prefix .'aco';
				break;
			case 'aro':
				$object_type = 'aro';
				$table = $this->_db_table_prefix .'aro';
				break;
			case 'axo':
				$object_type = 'axo';
				$table = $this->_db_table_prefix .'axo';
				break;
			case 'acl':
				$object_type = 'acl';
				$table = $this->_db_table_prefix .'acl';
				break;
			default:
				$this->debug_text('get_object(): Invalid Object Type: '. $object_type);
				return FALSE;
		}

		$this->debug_text("get_object(): Section Value: $section_value Object Type: $object_type");

		$q = new DBQuery;
		$q->addTable($table);
		$q->addQuery('id, section_value, name, value, order_value, hidden');
	
		if (!empty($value)) {
			$q->addWhere('value=' . $this->db->quote($value));

		}

		if (!empty($section_value)) {
			$q->addWhere('section_value='. $this->db->quote($section_value));

		}

		if ($return_hidden==0 AND $object_type != 'acl') {
			$q->addWhere('hidden=0');

		}


		$q->exec();
		$row = $q->fetchRow();
		$q->clear();

		if (!is_array($row)) {
			$this->debug_db('get_object');
			return false;
		}

		// Return Object info.
		return array(
		  'id' => $row[0],
		  'section_value' => $row[1],
		  'name' => $row[2],
		  'value' => $row[3],
		  'order_value' => $row[4],
		  'hidden' => $row[5]
		);
	}

	/*======================================================================*\
		Function:	get_objects ()
		Purpose:	Grabs all Objects in the database, or specific to a section_value
					returns format suitable for add_acl and is_conflicting_acl
	\*======================================================================*/
	function get_objects_full($section_value = NULL, $return_hidden = 1, $object_type = NULL, $limit_clause = NULL) {
		switch (strtolower(trim($object_type))) {
			case 'aco':
				$object_type = 'aco';
				$table = $this->_db_table_prefix .'aco';
				break;
			case 'aro':
				$object_type = 'aro';
				$table = $this->_db_table_prefix .'aro';
				break;
			case 'axo':
				$object_type = 'axo';
				$table = $this->_db_table_prefix .'axo';
				break;
			default:
				$this->debug_text('get_objects(): Invalid Object Type: '. $object_type);
				return FALSE;
		}

		$this->debug_text("get_objects(): Section Value: $section_value Object Type: $object_type");

		$q = new DBQuery;
		$q->addTable($table);
		$q->addQuery('id, section_value, name, value, order_value, hidden');

		if (!empty($section_value)) {
			$q->addWhere('section_value='. $this->db->quote($section_value));
		}

		if ($return_hidden==0) {
			$q->addWhere('hidden=0');
		}

		if (!empty($limit_clause)) {
			$q->addWhere($limit_clause);
		}

		$q->addOrder('order_value');

		/*
		$rs = $q->exec();

		if (!is_object($rs)) {
			$this->debug_db('get_objects');
			return FALSE;
		}
		*/

		$retarr = array();

		$q->exec();
		while ($row = $q->fetchRow()) {
			$retarr[] = array(
			  'id' => $row[0],
			  'section_value' => $row[1],
			  'name' => $row[2],
			  'value' => $row[3],
			  'order_value' => $row[4],
			  'hidden' => $row[5]
			);
		}
		$q->clear();

		// Return objects
		return $retarr;
	}

	function get_object_sections($section_value = NULL, $return_hidden = 1, $object_type = NULL, $limit_clause = NULL) {
		switch (strtolower(trim($object_type))) {
			case 'aco':
				$object_type = 'aco';
				$table = $this->_db_table_prefix .'aco_sections';
				break;
			case 'aro':
				$object_type = 'aro';
				$table = $this->_db_table_prefix .'aro_sections';
				break;
			case 'axo':
				$object_type = 'axo';
				$table = $this->_db_table_prefix .'axo_sections';
				break;
			default:
				$this->debug_text('get_object_sections(): Invalid Object Type: '. $object_type);
				return FALSE;
		}

		$this->debug_text("get_objects(): Section Value: $section_value Object Type: $object_type");

		// $query = 'SELECT id, value, name, order_value, hidden FROM '. $table;
		$q = new DBQuery;
		$q->addTable($table);
		$q->addQuery('id, value, name, order_value, hidden');


		if (!empty($section_value)) {
			$q->addWhere('value='. $this->db->quote($section_value));

		}

		if ($return_hidden==0) {
			$q->addWhere('hidden=0');

		}

		if (!empty($limit_clause)) {
			$q->addWhere($limit_clause);

		}

		$q->addOrder('order_value');

		$rs = $q->exec();

		/*
		if (!is_object($rs)) {
			$this->debug_db('get_object_sections');
			return FALSE;
		}
		*/

		$retarr = array();

		while ($row = $q->fetchRow()) {
			$retarr[] = array(
			  'id' => $row[0],
			  'value' => $row[1],
			  'name' => $row[2],
			  'order_value' => $row[3],
			  'hidden' => $row[4]
			);
		}
		$q->clear();

		// Return objects
		return $retarr;
	}

  /** Called from do_perms_aed, allows us to add a new ACL */
  function addUserPermission() {
    // Need to have a user id, 
    // parse the permissions array
    if (! is_array($_POST['permission_type'])) {
      $this->debug_text("you must select at least one permission");
      return false;
    }
    /*
    echo "<pre>\n";
    var_dump($_POST);
    echo "</pre>\n";
    return true;
    */

    $mod_type = substr($_POST['permission_module'],0,4);
    $mod_id = substr($_POST['permission_module'],4);
    $mod_group = null;
    $mod_mod = null;
    if ($mod_type == 'grp,') {
      $mod_group = array($mod_id);
    } else {
      if (isset($_POST['permission_item']) && $_POST['permission_item']) {
	$mod_mod = array();
	$mod_mod[$_POST['permission_table']][] =  $_POST['permission_item'];
	// check if the item already exists, if not create it.
	// First need to check if the section exists.
	if (! $this->get_object_section_section_id(null, $_POST['permission_table'], 'axo')) {
	  $this->addModuleSection($_POST['permission_table']);
	}
	if (! $this->get_object_id($_POST['permission_table'], $_POST['permission_item'],  'axo')) {
	  $this->addModuleItem($_POST['permission_table'], $_POST['permission_item'], $_POST['permission_name']);
	}
      } else {
	// Get the module information
	$mod_info = $this->get_object_data($mod_id, 'axo');
	$mod_mod = array();
	$mod_mod[$mod_info[0][0]][] = $mod_info[0][1];
      }
    }
    $aro_info = $this->get_object_data($_POST['permission_user'], 'aro');
    $aro_map = array();
    $aro_map[$aro_info[0][0]][] = $aro_info[0][1];
    // Build the permissions info
    $type_map = array();
    foreach ($_POST['permission_type'] as $tid) {
      $type = $this->get_object_data($tid, 'aco');
      foreach ($type as $t) {
	$type_map[$t[0]][] = $t[1];
      }
    }
    return $this->add_acl(
      $type_map,
      $aro_map,
      null,
      $mod_mod,
      $mod_group,
      $_POST['permission_access'],
      1,
      null,
      null,
      "user");
  }

  function addRolePermission() {
    if (! is_array($_POST['permission_type'])) {
      $this->debug_text("you must select at least one permission");
      return false;
    }

    $mod_type = substr($_POST['permission_module'],0,4);
    $mod_id = substr($_POST['permission_module'],4);
    $mod_group = null;
    $mod_mod = null;
    if ($mod_type == 'grp,') {
      $mod_group = array($mod_id);
    } else {
      // Get the module information
      $mod_info = $this->get_object_data($mod_id, 'axo');
      $mod_mod = array();
      $mod_mod[$mod_info[0][0]][] = $mod_info[0][1];
    }
    $aro_map = array($_POST['role_id']);
    // Build the permissions info
    $type_map = array();
    foreach ($_POST['permission_type'] as $tid) {
      $type = $this->get_object_data($tid, 'aco');
      foreach ($type as $t) {
	$type_map[$t[0]][] = $t[1];
      }
    }
    return $this->add_acl(
      $type_map,
      null,
      $aro_map,
      $mod_mod,
      $mod_group,
      $_POST['permission_access'],
      1,
      null,
      null,
      "user");
    if (! is_array($_POST['permission_type'])) {
      $this->debug_text("you must select at least one permission");
      return false;
    }
  }

  // Some function overrides.
  function debug_text($text) {
    $this->_debug_msg = $text;
    dprint(__FILE__, __LINE__, 9, $text);
  }

  function msg() {
    return $this->_debug_msg;
  }

}
?>