cmdbobject.class.inc.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569
  1. <?php
  2. // Copyright (C) 2010-2012 Combodo SARL
  3. //
  4. // This file is part of iTop.
  5. //
  6. // iTop is free software; you can redistribute it and/or modify
  7. // it under the terms of the GNU Affero General Public License as published by
  8. // the Free Software Foundation, either version 3 of the License, or
  9. // (at your option) any later version.
  10. //
  11. // iTop is distributed in the hope that it will be useful,
  12. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  14. // GNU Affero General Public License for more details.
  15. //
  16. // You should have received a copy of the GNU Affero General Public License
  17. // along with iTop. If not, see <http://www.gnu.org/licenses/>
  18. /**
  19. * Class cmdbObject
  20. *
  21. * @copyright Copyright (C) 2010-2012 Combodo SARL
  22. * @license http://opensource.org/licenses/AGPL-3.0
  23. */
  24. /**
  25. * cmdbObjectClass
  26. * the file to include, then the core is yours
  27. *
  28. * @package iTopORM
  29. */
  30. require_once('coreexception.class.inc.php');
  31. require_once('config.class.inc.php');
  32. require_once('log.class.inc.php');
  33. require_once('kpi.class.inc.php');
  34. require_once('dict.class.inc.php');
  35. require_once('attributedef.class.inc.php');
  36. require_once('filterdef.class.inc.php');
  37. require_once('stimulus.class.inc.php');
  38. require_once('valuesetdef.class.inc.php');
  39. require_once('MyHelpers.class.inc.php');
  40. require_once('expression.class.inc.php');
  41. require_once('cmdbsource.class.inc.php');
  42. require_once('sqlquery.class.inc.php');
  43. require_once('oql/oqlquery.class.inc.php');
  44. require_once('oql/oqlexception.class.inc.php');
  45. require_once('oql/oql-parser.php');
  46. require_once('oql/oql-lexer.php');
  47. require_once('oql/oqlinterpreter.class.inc.php');
  48. require_once('dbobject.class.php');
  49. require_once('dbobjectsearch.class.php');
  50. require_once('dbobjectset.class.php');
  51. require_once('backgroundprocess.inc.php');
  52. require_once('asynctask.class.inc.php');
  53. require_once('dbproperty.class.inc.php');
  54. // db change tracking data model
  55. require_once('cmdbchange.class.inc.php');
  56. require_once('cmdbchangeop.class.inc.php');
  57. // customization data model
  58. // Romain: temporary moved into application.inc.php (see explanations there)
  59. //require_once('trigger.class.inc.php');
  60. //require_once('action.class.inc.php');
  61. // application log
  62. // Romain: temporary moved into application.inc.php (see explanations there)
  63. //require_once('event.class.inc.php');
  64. require_once('templatestring.class.inc.php');
  65. require_once('csvparser.class.inc.php');
  66. require_once('bulkchange.class.inc.php');
  67. /**
  68. * A persistent object, which changes are accurately recorded
  69. *
  70. * @package iTopORM
  71. */
  72. abstract class CMDBObject extends DBObject
  73. {
  74. protected $m_datCreated;
  75. protected $m_datUpdated;
  76. // Note: this value is static, but that could be changed because it is sometimes a real issue (see update of interfaces / connected_to
  77. protected static $m_oCurrChange = null;
  78. protected static $m_sInfo = null; // null => the information is built in a standard way
  79. /**
  80. * Specify another change (this is mainly for backward compatibility)
  81. */
  82. public static function SetCurrentChange(CMDBChange $oChange)
  83. {
  84. self::$m_oCurrChange = $oChange;
  85. }
  86. //
  87. // Todo: simplify the APIs and do not pass the current change as an argument anymore
  88. // SetTrackInfo to be invoked in very few cases (UI.php, CSV import, Data synchro)
  89. // SetCurrentChange is an alternative to SetTrackInfo (csv ?)
  90. // GetCurrentChange to be called ONCE (!) by CMDBChangeOp::OnInsert ($this->Set('change', ..GetCurrentChange())
  91. // GetCurrentChange to create a default change if not already done in the current context
  92. //
  93. /**
  94. * Get a change record (create it if not existing)
  95. */
  96. public static function GetCurrentChange($bAutoCreate = true)
  97. {
  98. if ($bAutoCreate && is_null(self::$m_oCurrChange))
  99. {
  100. self::CreateChange();
  101. }
  102. return self::$m_oCurrChange;
  103. }
  104. /**
  105. * Override the additional information (defaulting to user name)
  106. * A call to this verb should replace every occurence of
  107. * $oMyChange = MetaModel::NewObject("CMDBChange");
  108. * $oMyChange->Set("date", time());
  109. * $oMyChange->Set("userinfo", 'this is done by ... for ...');
  110. * $iChangeId = $oMyChange->DBInsert();
  111. */
  112. public static function SetTrackInfo($sInfo)
  113. {
  114. self::$m_sInfo = $sInfo;
  115. }
  116. /**
  117. * Get the additional information (defaulting to user name)
  118. */
  119. protected static function GetTrackInfo()
  120. {
  121. if (is_null(self::$m_sInfo))
  122. {
  123. return CMDBChange::GetCurrentUserName();
  124. }
  125. else
  126. {
  127. return self::$m_sInfo;
  128. }
  129. }
  130. /**
  131. * Create a standard change record (done here 99% of the time, and nearly once per page)
  132. */
  133. protected static function CreateChange()
  134. {
  135. self::$m_oCurrChange = MetaModel::NewObject("CMDBChange");
  136. self::$m_oCurrChange->Set("date", time());
  137. self::$m_oCurrChange->Set("userinfo", self::GetTrackInfo());
  138. self::$m_oCurrChange->DBInsert();
  139. }
  140. protected function RecordObjCreation()
  141. {
  142. parent::RecordObjCreation();
  143. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpCreate");
  144. $oMyChangeOp->Set("objclass", get_class($this));
  145. $oMyChangeOp->Set("objkey", $this->GetKey());
  146. $iId = $oMyChangeOp->DBInsertNoReload();
  147. }
  148. protected function RecordObjDeletion($objkey)
  149. {
  150. parent::RecordObjDeletion($objkey);
  151. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpDelete");
  152. $oMyChangeOp->Set("objclass", MetaModel::GetRootClass(get_class($this)));
  153. $oMyChangeOp->Set("objkey", $objkey);
  154. $oMyChangeOp->Set("fclass", get_class($this));
  155. $oMyChangeOp->Set("fname", $this->GetRawName());
  156. $iId = $oMyChangeOp->DBInsertNoReload();
  157. }
  158. protected function RecordAttChanges(array $aValues, array $aOrigValues)
  159. {
  160. parent::RecordAttChanges($aValues, $aOrigValues);
  161. // $aValues is an array of $sAttCode => $value
  162. //
  163. foreach ($aValues as $sAttCode=> $value)
  164. {
  165. $oAttDef = MetaModel::GetAttributeDef(get_class($this), $sAttCode);
  166. if ($oAttDef->IsExternalField()) continue; // #@# temporary
  167. if ($oAttDef->IsLinkSet()) continue; // #@# temporary
  168. if (array_key_exists($sAttCode, $aOrigValues))
  169. {
  170. $original = $aOrigValues[$sAttCode];
  171. }
  172. else
  173. {
  174. $original = null;
  175. }
  176. if ($oAttDef instanceOf AttributeOneWayPassword)
  177. {
  178. // One Way encrypted passwords' history is stored -one way- encrypted
  179. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeOneWayPassword");
  180. $oMyChangeOp->Set("objclass", get_class($this));
  181. $oMyChangeOp->Set("objkey", $this->GetKey());
  182. $oMyChangeOp->Set("attcode", $sAttCode);
  183. if (is_null($original))
  184. {
  185. $original = '';
  186. }
  187. $oMyChangeOp->Set("prev_pwd", $original);
  188. $iId = $oMyChangeOp->DBInsertNoReload();
  189. }
  190. elseif ($oAttDef instanceOf AttributeEncryptedString)
  191. {
  192. // Encrypted string history is stored encrypted
  193. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeEncrypted");
  194. $oMyChangeOp->Set("objclass", get_class($this));
  195. $oMyChangeOp->Set("objkey", $this->GetKey());
  196. $oMyChangeOp->Set("attcode", $sAttCode);
  197. if (is_null($original))
  198. {
  199. $original = '';
  200. }
  201. $oMyChangeOp->Set("prevstring", $original);
  202. $iId = $oMyChangeOp->DBInsertNoReload();
  203. }
  204. elseif ($oAttDef instanceOf AttributeBlob)
  205. {
  206. // Data blobs
  207. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeBlob");
  208. $oMyChangeOp->Set("objclass", get_class($this));
  209. $oMyChangeOp->Set("objkey", $this->GetKey());
  210. $oMyChangeOp->Set("attcode", $sAttCode);
  211. if (is_null($original))
  212. {
  213. $original = new ormDocument();
  214. }
  215. $oMyChangeOp->Set("prevdata", $original);
  216. $iId = $oMyChangeOp->DBInsertNoReload();
  217. }
  218. elseif ($oAttDef instanceOf AttributeStopWatch)
  219. {
  220. // Stop watches - record changes for sub items only (they are visible, the rest is not visible)
  221. //
  222. if (is_null($original))
  223. {
  224. $original = new OrmStopWatch();
  225. }
  226. foreach ($oAttDef->ListSubItems() as $sSubItemAttCode => $oSubItemAttDef)
  227. {
  228. $item_value = $oSubItemAttDef->GetValue($value);
  229. $item_original = $oSubItemAttDef->GetValue($original);
  230. if ($item_value != $item_original)
  231. {
  232. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  233. $oMyChangeOp->Set("objclass", get_class($this));
  234. $oMyChangeOp->Set("objkey", $this->GetKey());
  235. $oMyChangeOp->Set("attcode", $sSubItemAttCode);
  236. $oMyChangeOp->Set("oldvalue", $item_original);
  237. $oMyChangeOp->Set("newvalue", $item_value);
  238. $iId = $oMyChangeOp->DBInsertNoReload();
  239. }
  240. }
  241. }
  242. elseif ($oAttDef instanceOf AttributeCaseLog)
  243. {
  244. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeCaseLog");
  245. $oMyChangeOp->Set("objclass", get_class($this));
  246. $oMyChangeOp->Set("objkey", $this->GetKey());
  247. $oMyChangeOp->Set("attcode", $sAttCode);
  248. $oMyChangeOp->Set("lastentry", $value->GetLatestEntryIndex());
  249. $iId = $oMyChangeOp->DBInsertNoReload();
  250. }
  251. elseif ($oAttDef instanceOf AttributeLongText)
  252. {
  253. // Data blobs
  254. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeLongText");
  255. $oMyChangeOp->Set("objclass", get_class($this));
  256. $oMyChangeOp->Set("objkey", $this->GetKey());
  257. $oMyChangeOp->Set("attcode", $sAttCode);
  258. if (!is_null($original) && ($original instanceof ormCaseLog))
  259. {
  260. $original = $original->GetText();
  261. }
  262. $oMyChangeOp->Set("prevdata", $original);
  263. $iId = $oMyChangeOp->DBInsertNoReload();
  264. }
  265. elseif ($oAttDef instanceOf AttributeText)
  266. {
  267. // Data blobs
  268. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeText");
  269. $oMyChangeOp->Set("objclass", get_class($this));
  270. $oMyChangeOp->Set("objkey", $this->GetKey());
  271. $oMyChangeOp->Set("attcode", $sAttCode);
  272. if (!is_null($original) && ($original instanceof ormCaseLog))
  273. {
  274. $original = $original->GetText();
  275. }
  276. $oMyChangeOp->Set("prevdata", $original);
  277. $iId = $oMyChangeOp->DBInsertNoReload();
  278. }
  279. elseif ($oAttDef instanceOf AttributeBoolean)
  280. {
  281. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  282. $oMyChangeOp->Set("objclass", get_class($this));
  283. $oMyChangeOp->Set("objkey", $this->GetKey());
  284. $oMyChangeOp->Set("attcode", $sAttCode);
  285. $oMyChangeOp->Set("oldvalue", $original ? 1 : 0);
  286. $oMyChangeOp->Set("newvalue", $value ? 1 : 0);
  287. $iId = $oMyChangeOp->DBInsertNoReload();
  288. }
  289. else
  290. {
  291. // Scalars
  292. //
  293. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  294. $oMyChangeOp->Set("objclass", get_class($this));
  295. $oMyChangeOp->Set("objkey", $this->GetKey());
  296. $oMyChangeOp->Set("attcode", $sAttCode);
  297. $oMyChangeOp->Set("oldvalue", $original);
  298. $oMyChangeOp->Set("newvalue", $value);
  299. $iId = $oMyChangeOp->DBInsertNoReload();
  300. }
  301. }
  302. }
  303. /**
  304. * Helper to ultimately check user rights before writing (Insert, Update or Delete)
  305. * The check should never fail, because the UI should prevent from such a usage
  306. * Anyhow, if the user has found a workaround... the security gets enforced here
  307. */
  308. protected function CheckUserRights($bSkipStrongSecurity, $iActionCode)
  309. {
  310. if (is_null($bSkipStrongSecurity))
  311. {
  312. // This is temporary
  313. // We have implemented this safety net right before releasing iTop 1.0
  314. // and we decided that it was too risky to activate it
  315. // Anyhow, users willing to have a very strong security could set
  316. // skip_strong_security = 0, in the config file
  317. $bSkipStrongSecurity = MetaModel::GetConfig()->Get('skip_strong_security');
  318. }
  319. if (!$bSkipStrongSecurity)
  320. {
  321. $sClass = get_class($this);
  322. $oSet = DBObjectSet::FromObject($this);
  323. if (!UserRights::IsActionAllowed($sClass, $iActionCode, $oSet))
  324. {
  325. // Intrusion detected
  326. throw new SecurityException('You are not allowed to modify objects of class: '.$sClass);
  327. }
  328. }
  329. }
  330. public function DBInsert()
  331. {
  332. return $this->DBInsertTracked_Internal();
  333. }
  334. public function DBInsertTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  335. {
  336. self::SetCurrentChange($oChange);
  337. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  338. $ret = $this->DBInsertTracked_Internal();
  339. return $ret;
  340. }
  341. public function DBInsertTrackedNoReload(CMDBChange $oChange, $bSkipStrongSecurity = null)
  342. {
  343. self::SetCurrentChange($oChange);
  344. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  345. $ret = $this->DBInsertTracked_Internal(true);
  346. return $ret;
  347. }
  348. protected function DBInsertTracked_Internal($bDoNotReload = false)
  349. {
  350. if ($bDoNotReload)
  351. {
  352. $ret = parent::DBInsertNoReload();
  353. }
  354. else
  355. {
  356. $ret = parent::DBInsert();
  357. }
  358. return $ret;
  359. }
  360. public function DBClone($newKey = null)
  361. {
  362. return $this->DBCloneTracked_Internal();
  363. }
  364. public function DBCloneTracked(CMDBChange $oChange, $newKey = null)
  365. {
  366. self::SetCurrentChange($oChange);
  367. $this->DBCloneTracked_Internal($newKey);
  368. }
  369. protected function DBCloneTracked_Internal($newKey = null)
  370. {
  371. $newKey = parent::DBClone($newKey);
  372. $oClone = MetaModel::GetObject(get_class($this), $newKey);
  373. return $newKey;
  374. }
  375. public function DBUpdate()
  376. {
  377. // Copy the changes list before the update (the list should be reset afterwards)
  378. $aChanges = $this->ListChanges();
  379. if (count($aChanges) == 0)
  380. {
  381. return;
  382. }
  383. $ret = parent::DBUpdate();
  384. return $ret;
  385. }
  386. public function DBUpdateTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  387. {
  388. self::SetCurrentChange($oChange);
  389. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  390. $this->DBUpdate();
  391. }
  392. public function DBDelete(&$oDeletionPlan = null)
  393. {
  394. return $this->DBDeleteTracked_Internal($oDeletionPlan);
  395. }
  396. public function DBDeleteTracked(CMDBChange $oChange, $bSkipStrongSecurity = null, &$oDeletionPlan = null)
  397. {
  398. self::SetCurrentChange($oChange);
  399. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_DELETE);
  400. $this->DBDeleteTracked_Internal($oDeletionPlan);
  401. }
  402. protected function DBDeleteTracked_Internal(&$oDeletionPlan = null)
  403. {
  404. $prevkey = $this->GetKey();
  405. $ret = parent::DBDelete($oDeletionPlan);
  406. return $ret;
  407. }
  408. public static function BulkUpdate(DBObjectSearch $oFilter, array $aValues)
  409. {
  410. return $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  411. }
  412. public static function BulkUpdateTracked(CMDBChange $oChange, DBObjectSearch $oFilter, array $aValues)
  413. {
  414. self::SetCurrentChange($oChange);
  415. $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  416. }
  417. protected static function BulkUpdateTracked_Internal(DBObjectSearch $oFilter, array $aValues)
  418. {
  419. // $aValues is an array of $sAttCode => $value
  420. // Get the list of objects to update (and load it before doing the change)
  421. $oObjSet = new CMDBObjectSet($oFilter);
  422. $oObjSet->Load();
  423. // Keep track of the previous values (will be overwritten when the objects are synchronized with the DB)
  424. $aOriginalValues = array();
  425. $oObjSet->Rewind();
  426. while ($oItem = $oObjSet->Fetch())
  427. {
  428. $aOriginalValues[$oItem->GetKey()] = $oItem->m_aOrigValues;
  429. }
  430. // Update in one single efficient query
  431. $ret = parent::BulkUpdate($oFilter, $aValues);
  432. // Record... in many queries !!!
  433. $oObjSet->Rewind();
  434. while ($oItem = $oObjSet->Fetch())
  435. {
  436. $aChangedValues = $oItem->ListChangedValues($aValues);
  437. $oItem->RecordAttChanges($aChangedValues, $aOriginalValues[$oItem->GetKey()]);
  438. }
  439. return $ret;
  440. }
  441. }
  442. /**
  443. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  444. *
  445. * @package iTopORM
  446. */
  447. class CMDBObjectSet extends DBObjectSet
  448. {
  449. // this is the public interface (?)
  450. // I have to define those constructors here... :-(
  451. // just to get the right object class in return.
  452. // I have to think again to those things: maybe it will work fine if a have a constructor define here (?)
  453. static public function FromScratch($sClass)
  454. {
  455. $oFilter = new CMDBSearchFilter($sClass);
  456. $oFilter->AddConditionExpression(new FalseExpression());
  457. $oRetSet = new self($oFilter);
  458. // NOTE: THIS DOES NOT WORK IF m_bLoaded is private in the base class (and you will not get any error message)
  459. $oRetSet->m_bLoaded = true; // no DB load
  460. return $oRetSet;
  461. }
  462. // create an object set ex nihilo
  463. // input = array of objects
  464. static public function FromArray($sClass, $aObjects)
  465. {
  466. $oRetSet = self::FromScratch($sClass);
  467. $oRetSet->AddObjectArray($aObjects, $sClass);
  468. return $oRetSet;
  469. }
  470. static public function FromArrayAssoc($aClasses, $aObjects)
  471. {
  472. // In a perfect world, we should create a complete tree of DBObjectSearch,
  473. // but as we lack most of the information related to the objects,
  474. // let's create one search definition
  475. $sClass = reset($aClasses);
  476. $sAlias = key($aClasses);
  477. $oFilter = new CMDBSearchFilter($sClass, $sAlias);
  478. $oRetSet = new CMDBObjectSet($oFilter);
  479. $oRetSet->m_bLoaded = true; // no DB load
  480. foreach($aObjects as $rowIndex => $aObjectsByClassAlias)
  481. {
  482. $oRetSet->AddObjectExtended($aObjectsByClassAlias);
  483. }
  484. return $oRetSet;
  485. }
  486. }
  487. /**
  488. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  489. *
  490. * @package iTopORM
  491. */
  492. class CMDBSearchFilter extends DBObjectSearch
  493. {
  494. // this is the public interface (?)
  495. }
  496. ?>