

$sql = <<<QUERY
SELECT entry.target, entry.principal, mr.authority, entry.policy, entry.data
FROM
(SELECT mug.role, acl.authority, acl.target, acl.principal, acl.policy, p.data FROM {$accessTable} acl
LEFT JOIN {$policyTable} p ON p.id = acl.policy
JOIN {$memberTable} mug ON acl.principal_class = 'modUserGroup'
AND (acl.context_key = :context OR acl.context_key IS NULL OR acl.context_key = '')
AND mug.member = :principal
AND mug.user_group = acl.principal
) entry
JOIN {$memberRoleTable} mr ON mr.id = entry.role
AND mr.authority <= entry.authority
GROUP BY entry.target, entry.principal, entry.authority, entry.policy
$sql = "SELECT acl.target, acl.principal, mr.authority, acl.policy, p.data FROM {$accessTable} acl " .
"LEFT JOIN {$policyTable} p ON p.id = acl.policy " .
"JOIN {$memberTable} mug ON acl.principal_class = 'modUserGroup' " .
"AND mug.member = :principal " .
"AND mug.user_group = acl.principal " .
"JOIN {$memberRoleTable} mr ON mr.id = mug.role " .
"AND mr.authority <= acl.authority " .
"GROUP BY acl.target, acl.principal, acl.authority, acl.policy";
(SELECT mug.role, acl.authority, acl.target, acl.principal, acl.policy, p.data FROM {$accessTable} acl
LEFT JOIN {$policyTable} p ON p.id = acl.policy
JOIN {$memberTable} mug ON acl.principal_class = 'modUserGroup'
AND (acl.context_key = :context OR acl.context_key IS NULL OR acl.context_key = '')
AND mug.member = :principal
AND mug.user_group = acl.principal
) entry
/**
* Loads the principal attributes that define a modUser security profile.
*
* {@inheritdoc}
*
* @todo Remove the legacy docgroup support.
*/
function loadAttributes($target, $context = '', $reload = false) {
$context = !empty($context) ? $context : $this->xpdo->context->get('key');
if ($this->_attributes === null || $reload) {
$this->_attributes = array();
if (isset($_SESSION["modx.user.{$this->id}.attributes"])) {
if ($reload) {
unset($_SESSION["modx.user.{$this->id}.attributes"]);
} else {
$this->_attributes = $_SESSION["modx.user.{$this->id}.attributes"];
}
}
}
if (!isset($this->_attributes[$context])) $this->_attributes[$context] = array();
if (!isset($this->_attributes[$context][$target])) {
$accessTable = $this->xpdo->getTableName($target);
$policyTable = $this->xpdo->getTableName('modAccessPolicy');
$memberTable = $this->xpdo->getTableName('modUserGroupMember');
$memberRoleTable = $this->xpdo->getTableName('modUserGroupRole');
if ($this->get('id') > 0) {
switch ($target) {
case 'modAccessResourceGroup' :
$legacyDocGroups = array();
#Here was modified.
$sql = <<<QUERY
SELECT entry.target, entry.principal, mr.authority, entry.policy, entry.data
FROM
(SELECT mug.role, acl.authority, acl.target, acl.principal, acl.policy, p.data FROM {$accessTable} acl
LEFT JOIN {$policyTable} p ON p.id = acl.policy
JOIN {$memberTable} mug ON acl.principal_class = 'modUserGroup'
AND (acl.context_key = :context OR acl.context_key IS NULL OR acl.context_key = '')
AND mug.member = :principal
AND mug.user_group = acl.principal
) entry
JOIN {$memberRoleTable} mr ON mr.id = entry.role
AND mr.authority <= entry.authority
GROUP BY entry.target, entry.principal, entry.authority, entry.policy
QUERY;
$bindings = array(
':principal' => $this->get('id'),
':context' => $context
);
$query = new xPDOCriteria($this->xpdo, $sql, $bindings);
if ($query->stmt && $query->stmt->execute()) {
while ($row = $query->stmt->fetch(PDO_FETCH_ASSOC)) {
$this->_attributes[$context][$target][$row['target']][] = array(
'principal' => $row['principal'],
'authority' => $row['authority'],
'policy' => $row['data'] ? xPDO :: fromJSON($row['data'], true) : array(),
);
$legacyDocGroups[$row['target']]= $row['target'];
}
}
$_SESSION[$context . 'Docgroups']= array_values($legacyDocGroups);
break;
case 'modAccessContext' :
#Here was modified.
$sql = <<<QUERY
SELECT entry.target, entry.principal, mr.authority, entry.policy, entry.data
FROM
(SELECT mug.role, acl.authority, acl.target, acl.principal, acl.policy, p.data FROM {$accessTable} acl
LEFT JOIN {$policyTable} p ON p.id = acl.policy
JOIN {$memberTable} mug ON acl.principal_class = 'modUserGroup'
AND mug.member = :principal
AND mug.user_group = acl.principal
) entry
JOIN {$memberRoleTable} mr ON mr.id = entry.role
AND mr.authority <= entry.authority
GROUP BY entry.target, entry.principal, entry.authority, entry.policy
QUERY;
$bindings = array(
':principal' => $this->get('id')
);
$query = new xPDOCriteria($this->xpdo, $sql, $bindings);
if ($query->stmt && $query->stmt->execute()) {
while ($row = $query->stmt->fetch(PDO_FETCH_ASSOC)) {
$this->_attributes[$context][$target][$row['target']][] = array(
'principal' => $row['principal'],
'authority' => $row['authority'],
'policy' => $row['data'] ? xPDO :: fromJSON($row['data'], true) : array(),
);
}
}
break;
case 'modAccessElement' :
#Here was modified.
$sql = <<<QUERY
SELECT entry.target, entry.principal, mr.authority, entry.policy, entry.data
FROM
(SELECT mug.role, acl.authority, acl.target, acl.principal, acl.policy, p.data FROM {$accessTable} acl
LEFT JOIN {$policyTable} p ON p.id = acl.policy
JOIN {$memberTable} mug ON acl.principal_class = 'modUserGroup'
AND (acl.context_key = :context OR acl.context_key IS NULL OR acl.context_key = '')
AND mug.member = :principal
AND mug.user_group = acl.principal
) entry
JOIN {$memberRoleTable} mr ON mr.id = entry.role
AND mr.authority <= entry.authority
GROUP BY entry.target, entry.principal, entry.authority, entry.policy
QUERY;
$bindings = array(
':principal' => $this->get('id'),
':context' => $context
);
$query = new xPDOCriteria($this->xpdo, $sql, $bindings);
if ($query->stmt && $query->stmt->execute()) {
while ($row = $query->stmt->fetch(PDO_FETCH_ASSOC)) {
$this->_attributes[$context][$target][$row['target']][] = array(
'principal' => $row['principal'],
'authority' => $row['authority'],
'policy' => $row['data'] ? xPDO :: fromJSON($row['data'], true) : array(),
);
}
}
break;
default :
break;
}
} else {
switch ($target) {
case 'modAccessResourceGroup' :
$legacyDocGroups = array();
#I did not touch here.
$sql = "SELECT acl.target, acl.principal, 0 AS authority, acl.policy, p.data FROM {$accessTable} acl " .
"LEFT JOIN {$policyTable} p ON p.id = acl.policy " .
"WHERE acl.principal_class = 'modUserGroup' " .
"AND acl.principal = 0 " .
"AND (acl.context_key = :context OR acl.context_key IS NULL OR acl.context_key = '') " .
"GROUP BY acl.target, acl.principal, acl.authority, acl.policy";
$bindings = array(
':context' => $context
);
$query = new xPDOCriteria($this->xpdo, $sql, $bindings);
if ($query->stmt && $query->stmt->execute()) {
while ($row = $query->stmt->fetch(PDO_FETCH_ASSOC)) {
$this->_attributes[$context][$target][$row['target']][] = array(
'principal' => 0,
'authority' => $row['authority'],
'policy' => $row['data'] ? xPDO :: fromJSON($row['data'], true) : array(),
);
$legacyDocGroups[$row['target']]= $row['target'];
}
}
$_SESSION[$context . 'Docgroups']= array_values($legacyDocGroups);
break;
case 'modAccessContext' :
#I did not touch here.
$sql = "SELECT acl.target, acl.principal, 0 AS authority, acl.policy, p.data FROM {$accessTable} acl " .
"LEFT JOIN {$policyTable} p ON p.id = acl.policy " .
"WHERE acl.principal_class = 'modUserGroup' " .
"AND acl.principal = 0 " .
"GROUP BY acl.target, acl.principal, acl.authority, acl.policy";
$query = new xPDOCriteria($this->xpdo, $sql);
if ($query->stmt && $query->stmt->execute()) {
while ($row = $query->stmt->fetch(PDO_FETCH_ASSOC)) {
$this->_attributes[$context][$target][$row['target']][] = array(
'principal' => 0,
'authority' => $row['authority'],
'policy' => $row['data'] ? xPDO :: fromJSON($row['data'], true) : array(),
);
}
}
break;
case 'modAccessElement' :
#I did not touch here.
$sql = "SELECT acl.target, acl.principal, 0 AS authority, acl.policy, p.data FROM {$accessTable} acl " .
"LEFT JOIN {$policyTable} p ON p.id = acl.policy " .
"WHERE acl.principal_class = 'modUserGroup' " .
"AND acl.principal = 0 " .
"AND (acl.context_key = :context OR acl.context_key IS NULL OR acl.context_key = '') " .
"GROUP BY acl.target, acl.principal, acl.authority, acl.policy";
$bindings = array(
':context' => $context
);
$query = new xPDOCriteria($this->xpdo, $sql, $bindings);
if ($query->stmt && $query->stmt->execute()) {
while ($row = $query->stmt->fetch(PDO_FETCH_ASSOC)) {
$this->_attributes[$context][$target][$row['target']][] = array(
'principal' => 0,
'authority' => $row['authority'],
'policy' => $row['data'] ? xPDO :: fromJSON($row['data'], true) : array(),
);
}
}
break;
default :
break;
}
}
if (!isset($this->_attributes[$context][$target])) {
$this->_attributes[$context][$target] = array();
}
$_SESSION["modx.user.{$this->id}.attributes"] = $this->_attributes;
}
}
# Example MySQL config file for small systems. # # This is for a system with little memory (<= 64M) where MySQL is only used # from time to time and it's important that the mysqld daemon # doesn't use much resources. # # You can copy this file to # /etc/my.cnf to set global options, # mysql-data-dir/my.cnf to set server-specific options (in this # installation this directory is /var/mysql/5.1/data) or # ~/.my.cnf to set user-specific options. # # In this file, you can use all long options that a program supports. # If you want to know which options a program supports, run the program # with the "--help" option. # The following options will be passed to all MySQL clients [client] #password = your_password port = 3306 socket = /tmp/mysql.sock default-character-set = ujis # Here follows entries for some specific programs # The MySQL server [mysqld] port = 3306 socket = /tmp/mysql.sock skip-locking key_buffer = 16K max_allowed_packet = 1M table_cache = 4 sort_buffer_size = 64K read_buffer_size = 256K read_rnd_buffer_size = 256K net_buffer_length = 2K thread_stack = 64K default-character-set = ujis # Don't listen on a TCP/IP port at all. This can be a security enhancement, # if all processes that need to connect to mysqld run on the same host. # All interaction with mysqld must be made via Unix sockets or named pipes. # Note that using this option without enabling named pipes on Windows # (using the "enable-named-pipe" option) will render mysqld useless! # #skip-networking server-id = 1 # Uncomment the following if you want to log updates #log-bin=mysql-bin # binary logging format - mixed recommended #binlog_format=mixed # Uncomment the following if you are using InnoDB tables #innodb_data_home_dir = /var/mysql/5.1/data/ #innodb_data_file_path = ibdata1:10M:autoextend #innodb_log_group_home_dir = /var/mysql/5.1/data/ #innodb_log_arch_dir = /var/mysql/5.1/data/ # You can set .._buffer_pool_size up to 50 - 80 % # of RAM but beware of setting memory usage too high #innodb_buffer_pool_size = 16M #innodb_additional_mem_pool_size = 2M # Set .._log_file_size to 25 % of buffer pool size #innodb_log_file_size = 5M #innodb_log_buffer_size = 8M #innodb_flush_log_at_trx_commit = 1 #innodb_lock_wait_timeout = 50 [mysqldump] quick max_allowed_packet = 16M default-character-set = ujis [mysql] no-auto-rehash # Remove the next comment character if you are not familiar with SQL #safe-updates [isamchk] key_buffer = 8M sort_buffer_size = 8M [myisamchk] key_buffer = 8M sort_buffer_size = 8M [mysqlhotcopy] interactive-timeout
[client] port=3306 socket=/tmp/mysql.sock [mysqld] port=3306 socket=/tmp/mysql.sock set-variable = key_buffer_size=16M set-variable = max_allowed_packet=1M [mysqldump] quick