SuiteCRM-Core/public/legacy/Api/V8/Helper/ModuleAccessChecker.php
2026-07-29 12:57:50 +01:00

69 lines
2.5 KiB
PHP

<?php
/**
* SuiteCRM is a customer relationship management program developed by SuiteCRM Ltd.
* Copyright (C) 2026 SuiteCRM Ltd.
*
* This program is free software; you can redistribute it and/or modify it under
* the terms of the GNU Affero General Public License version 3 as published by the
* Free Software Foundation with the addition of the following permission added
* to Section 15 as permitted in Section 7(a): FOR ANY PART OF THE COVERED WORK
* IN WHICH THE COPYRIGHT IS OWNED BY SUITECRM, SUITECRM DISCLAIMS THE
* WARRANTY OF NON INFRINGEMENT OF THIRD PARTY RIGHTS.
*
* This program is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
* FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more
* details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*
* In accordance with Section 7(b) of the GNU Affero General Public License
* version 3, these Appropriate Legal Notices must retain the display of the
* "Supercharged by SuiteCRM" logo. If the display of the logos is not reasonably
* feasible for technical reasons, the Appropriate Legal Notices must display
* the words "Supercharged by SuiteCRM".
*/
namespace Api\V8\Helper;
use ACLController;
use SuiteCRM\Exception\NotAllowedException;
/**
* Class ModuleAccessChecker
* @package Api\V8\Helper
*/
#[\AllowDynamicProperties]
class ModuleAccessChecker
{
/**
* @param string $module
* @throws NotAllowedException
*/
public function checkAccess(string $module): void
{
global $current_user, $adminOnlyList;
// not in $moduleList, so the tab check below would reject it for everyone; row/field-level
// enforcement happens in ModuleService instead
if ($module === 'Users' || $module === 'Employees') {
return;
}
if (!empty($adminOnlyList[$module])) {
if (!$current_user->isAdmin()) {
throw new NotAllowedException('The API user does not have access to this module.');
}
return;
}
$modules = query_module_access_list($current_user);
ACLController::filterModuleList($modules, false);
if (!in_array($module, $modules, true)) {
throw new NotAllowedException('The API user does not have access to this module.');
}
}
}