cmdbobject.class.inc.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543
  1. <?php
  2. // Copyright (C) 2010 Combodo SARL
  3. //
  4. // This program is free software; you can redistribute it and/or modify
  5. // it under the terms of the GNU General Public License as published by
  6. // the Free Software Foundation; version 3 of the License.
  7. //
  8. // This program is distributed in the hope that it will be useful,
  9. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  11. // GNU General Public License for more details.
  12. //
  13. // You should have received a copy of the GNU General Public License
  14. // along with this program; if not, write to the Free Software
  15. // Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  16. /**
  17. * Class cmdbObject
  18. *
  19. * @author Erwan Taloc <erwan.taloc@combodo.com>
  20. * @author Romain Quetiez <romain.quetiez@combodo.com>
  21. * @author Denis Flaven <denis.flaven@combodo.com>
  22. * @license http://www.opensource.org/licenses/gpl-3.0.html LGPL
  23. */
  24. /**
  25. * cmdbObjectClass
  26. * the file to include, then the core is yours
  27. *
  28. * @package iTopORM
  29. */
  30. require_once('coreexception.class.inc.php');
  31. require_once('config.class.inc.php');
  32. require_once('log.class.inc.php');
  33. require_once('kpi.class.inc.php');
  34. require_once('dict.class.inc.php');
  35. require_once('attributedef.class.inc.php');
  36. require_once('filterdef.class.inc.php');
  37. require_once('stimulus.class.inc.php');
  38. require_once('valuesetdef.class.inc.php');
  39. require_once('MyHelpers.class.inc.php');
  40. require_once('expression.class.inc.php');
  41. require_once('cmdbsource.class.inc.php');
  42. require_once('sqlquery.class.inc.php');
  43. require_once('oql/oqlquery.class.inc.php');
  44. require_once('oql/oqlexception.class.inc.php');
  45. require_once('oql/oql-parser.php');
  46. require_once('oql/oql-lexer.php');
  47. require_once('oql/oqlinterpreter.class.inc.php');
  48. require_once('dbobject.class.php');
  49. require_once('dbobjectsearch.class.php');
  50. require_once('dbobjectset.class.php');
  51. require_once('backgroundprocess.inc.php');
  52. require_once('asynctask.class.inc.php');
  53. require_once('dbproperty.class.inc.php');
  54. // db change tracking data model
  55. require_once('cmdbchange.class.inc.php');
  56. require_once('cmdbchangeop.class.inc.php');
  57. // customization data model
  58. // Romain: temporary moved into application.inc.php (see explanations there)
  59. //require_once('trigger.class.inc.php');
  60. //require_once('action.class.inc.php');
  61. // application log
  62. // Romain: temporary moved into application.inc.php (see explanations there)
  63. //require_once('event.class.inc.php');
  64. require_once('templatestring.class.inc.php');
  65. require_once('csvparser.class.inc.php');
  66. require_once('bulkchange.class.inc.php');
  67. /**
  68. * A persistent object, which changes are accurately recorded
  69. *
  70. * @package iTopORM
  71. */
  72. abstract class CMDBObject extends DBObject
  73. {
  74. protected $m_datCreated;
  75. protected $m_datUpdated;
  76. // Note: this value is static, but that could be changed because it is sometimes a real issue (see update of interfaces / connected_to
  77. protected static $m_oCurrChange = null;
  78. protected static $m_sInfo = null; // null => the information is built in a standard way
  79. /**
  80. * Specify another change (this is mainly for backward compatibility)
  81. */
  82. public static function SetCurrentChange(CMDBChange $oChange)
  83. {
  84. self::$m_oCurrChange = $oChange;
  85. }
  86. //
  87. // Todo: simplify the APIs and do not pass the current change as an argument anymore
  88. // SetTrackInfo to be invoked in very few cases (UI.php, CSV import, Data synchro)
  89. // SetCurrentChange is an alternative to SetTrackInfo (csv ?)
  90. // GetCurrentChange to be called ONCE (!) by CMDBChangeOp::OnInsert ($this->Set('change', ..GetCurrentChange())
  91. // GetCurrentChange to create a default change if not already done in the current context
  92. //
  93. /**
  94. * Get a change record (create it if not existing)
  95. */
  96. public static function GetCurrentChange($bAutoCreate = true)
  97. {
  98. if ($bAutoCreate && is_null(self::$m_oCurrChange))
  99. {
  100. self::CreateChange();
  101. }
  102. return self::$m_oCurrChange;
  103. }
  104. /**
  105. * Override the additional information (defaulting to user name)
  106. * A call to this verb should replace every occurence of
  107. * $oMyChange = MetaModel::NewObject("CMDBChange");
  108. * $oMyChange->Set("date", time());
  109. * $oMyChange->Set("userinfo", 'this is done by ... for ...');
  110. * $iChangeId = $oMyChange->DBInsert();
  111. */
  112. public static function SetTrackInfo($sInfo)
  113. {
  114. self::$m_sInfo = $sInfo;
  115. }
  116. /**
  117. * Get the additional information (defaulting to user name)
  118. */
  119. protected static function GetTrackInfo()
  120. {
  121. if (is_null(self::$m_sInfo))
  122. {
  123. return CMDBChange::GetCurrentUserName();
  124. }
  125. else
  126. {
  127. return self::$m_sInfo;
  128. }
  129. }
  130. /**
  131. * Create a standard change record (done here 99% of the time, and nearly once per page)
  132. */
  133. protected static function CreateChange()
  134. {
  135. self::$m_oCurrChange = MetaModel::NewObject("CMDBChange");
  136. self::$m_oCurrChange->Set("date", time());
  137. self::$m_oCurrChange->Set("userinfo", self::GetTrackInfo());
  138. self::$m_oCurrChange->DBInsert();
  139. }
  140. protected function RecordObjCreation()
  141. {
  142. parent::RecordObjCreation();
  143. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpCreate");
  144. $oMyChangeOp->Set("objclass", get_class($this));
  145. $oMyChangeOp->Set("objkey", $this->GetKey());
  146. $iId = $oMyChangeOp->DBInsertNoReload();
  147. }
  148. protected function RecordObjDeletion($objkey)
  149. {
  150. parent::RecordObjDeletion($objkey);
  151. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpDelete");
  152. $oMyChangeOp->Set("objclass", MetaModel::GetRootClass(get_class($this)));
  153. $oMyChangeOp->Set("objkey", $objkey);
  154. $oMyChangeOp->Set("fclass", get_class($this));
  155. $oMyChangeOp->Set("fname", $this->GetRawName());
  156. $iId = $oMyChangeOp->DBInsertNoReload();
  157. }
  158. protected function RecordAttChanges(array $aValues, array $aOrigValues)
  159. {
  160. parent::RecordAttChanges($aValues, $aOrigValues);
  161. // $aValues is an array of $sAttCode => $value
  162. //
  163. foreach ($aValues as $sAttCode=> $value)
  164. {
  165. $oAttDef = MetaModel::GetAttributeDef(get_class($this), $sAttCode);
  166. if ($oAttDef->IsExternalField()) continue; // #@# temporary
  167. if ($oAttDef->IsLinkSet()) continue; // #@# temporary
  168. if (array_key_exists($sAttCode, $aOrigValues))
  169. {
  170. $original = $aOrigValues[$sAttCode];
  171. }
  172. else
  173. {
  174. $original = null;
  175. }
  176. if ($oAttDef instanceOf AttributeOneWayPassword)
  177. {
  178. // One Way encrypted passwords' history is stored -one way- encrypted
  179. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeOneWayPassword");
  180. $oMyChangeOp->Set("objclass", get_class($this));
  181. $oMyChangeOp->Set("objkey", $this->GetKey());
  182. $oMyChangeOp->Set("attcode", $sAttCode);
  183. if (is_null($original))
  184. {
  185. $original = '';
  186. }
  187. $oMyChangeOp->Set("prev_pwd", $original);
  188. $iId = $oMyChangeOp->DBInsertNoReload();
  189. }
  190. elseif ($oAttDef instanceOf AttributeEncryptedString)
  191. {
  192. // Encrypted string history is stored encrypted
  193. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeEncrypted");
  194. $oMyChangeOp->Set("objclass", get_class($this));
  195. $oMyChangeOp->Set("objkey", $this->GetKey());
  196. $oMyChangeOp->Set("attcode", $sAttCode);
  197. if (is_null($original))
  198. {
  199. $original = '';
  200. }
  201. $oMyChangeOp->Set("prevstring", $original);
  202. $iId = $oMyChangeOp->DBInsertNoReload();
  203. }
  204. elseif ($oAttDef instanceOf AttributeBlob)
  205. {
  206. // Data blobs
  207. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeBlob");
  208. $oMyChangeOp->Set("objclass", get_class($this));
  209. $oMyChangeOp->Set("objkey", $this->GetKey());
  210. $oMyChangeOp->Set("attcode", $sAttCode);
  211. if (is_null($original))
  212. {
  213. $original = new ormDocument();
  214. }
  215. $oMyChangeOp->Set("prevdata", $original);
  216. $iId = $oMyChangeOp->DBInsertNoReload();
  217. }
  218. elseif ($oAttDef instanceOf AttributeStopWatch)
  219. {
  220. // Stop watches - record changes for sub items only (they are visible, the rest is not visible)
  221. //
  222. if (is_null($original))
  223. {
  224. $original = new OrmStopWatch();
  225. }
  226. foreach ($oAttDef->ListSubItems() as $sSubItemAttCode => $oSubItemAttDef)
  227. {
  228. $item_value = $oSubItemAttDef->GetValue($value);
  229. $item_original = $oSubItemAttDef->GetValue($original);
  230. if ($item_value != $item_original)
  231. {
  232. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  233. $oMyChangeOp->Set("objclass", get_class($this));
  234. $oMyChangeOp->Set("objkey", $this->GetKey());
  235. $oMyChangeOp->Set("attcode", $sSubItemAttCode);
  236. $oMyChangeOp->Set("oldvalue", $item_original);
  237. $oMyChangeOp->Set("newvalue", $item_value);
  238. $iId = $oMyChangeOp->DBInsertNoReload();
  239. }
  240. }
  241. }
  242. elseif ($oAttDef instanceOf AttributeCaseLog)
  243. {
  244. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeCaseLog");
  245. $oMyChangeOp->Set("objclass", get_class($this));
  246. $oMyChangeOp->Set("objkey", $this->GetKey());
  247. $oMyChangeOp->Set("attcode", $sAttCode);
  248. $oMyChangeOp->Set("lastentry", $value->GetLatestEntryIndex());
  249. $iId = $oMyChangeOp->DBInsertNoReload();
  250. }
  251. elseif ($oAttDef instanceOf AttributeText)
  252. {
  253. // Data blobs
  254. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeText");
  255. $oMyChangeOp->Set("objclass", get_class($this));
  256. $oMyChangeOp->Set("objkey", $this->GetKey());
  257. $oMyChangeOp->Set("attcode", $sAttCode);
  258. if (!is_null($original) && ($original instanceof ormCaseLog))
  259. {
  260. $original = $original->GetText();
  261. }
  262. $oMyChangeOp->Set("prevdata", $original);
  263. $iId = $oMyChangeOp->DBInsertNoReload();
  264. }
  265. else
  266. {
  267. // Scalars
  268. //
  269. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  270. $oMyChangeOp->Set("objclass", get_class($this));
  271. $oMyChangeOp->Set("objkey", $this->GetKey());
  272. $oMyChangeOp->Set("attcode", $sAttCode);
  273. $oMyChangeOp->Set("oldvalue", $original);
  274. $oMyChangeOp->Set("newvalue", $value);
  275. $iId = $oMyChangeOp->DBInsertNoReload();
  276. }
  277. }
  278. }
  279. /**
  280. * Helper to ultimately check user rights before writing (Insert, Update or Delete)
  281. * The check should never fail, because the UI should prevent from such a usage
  282. * Anyhow, if the user has found a workaround... the security gets enforced here
  283. */
  284. protected function CheckUserRights($bSkipStrongSecurity, $iActionCode)
  285. {
  286. if (is_null($bSkipStrongSecurity))
  287. {
  288. // This is temporary
  289. // We have implemented this safety net right before releasing iTop 1.0
  290. // and we decided that it was too risky to activate it
  291. // Anyhow, users willing to have a very strong security could set
  292. // skip_strong_security = 0, in the config file
  293. $bSkipStrongSecurity = MetaModel::GetConfig()->Get('skip_strong_security');
  294. }
  295. if (!$bSkipStrongSecurity)
  296. {
  297. $sClass = get_class($this);
  298. $oSet = DBObjectSet::FromObject($this);
  299. if (!UserRights::IsActionAllowed($sClass, $iActionCode, $oSet))
  300. {
  301. // Intrusion detected
  302. throw new SecurityException('You are not allowed to modify objects of class: '.$sClass);
  303. }
  304. }
  305. }
  306. public function DBInsert()
  307. {
  308. return $this->DBInsertTracked_Internal();
  309. }
  310. public function DBInsertTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  311. {
  312. self::SetCurrentChange($oChange);
  313. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  314. $ret = $this->DBInsertTracked_Internal();
  315. return $ret;
  316. }
  317. public function DBInsertTrackedNoReload(CMDBChange $oChange, $bSkipStrongSecurity = null)
  318. {
  319. self::SetCurrentChange($oChange);
  320. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  321. $ret = $this->DBInsertTracked_Internal(true);
  322. return $ret;
  323. }
  324. protected function DBInsertTracked_Internal($bDoNotReload = false)
  325. {
  326. if ($bDoNotReload)
  327. {
  328. $ret = parent::DBInsertNoReload();
  329. }
  330. else
  331. {
  332. $ret = parent::DBInsert();
  333. }
  334. return $ret;
  335. }
  336. public function DBClone($newKey = null)
  337. {
  338. return $this->DBCloneTracked_Internal();
  339. }
  340. public function DBCloneTracked(CMDBChange $oChange, $newKey = null)
  341. {
  342. self::SetCurrentChange($oChange);
  343. $this->DBCloneTracked_Internal($newKey);
  344. }
  345. protected function DBCloneTracked_Internal($newKey = null)
  346. {
  347. $newKey = parent::DBClone($newKey);
  348. $oClone = MetaModel::GetObject(get_class($this), $newKey);
  349. return $newKey;
  350. }
  351. public function DBUpdate()
  352. {
  353. // Copy the changes list before the update (the list should be reset afterwards)
  354. $aChanges = $this->ListChanges();
  355. if (count($aChanges) == 0)
  356. {
  357. return;
  358. }
  359. $ret = parent::DBUpdate();
  360. return $ret;
  361. }
  362. public function DBUpdateTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  363. {
  364. self::SetCurrentChange($oChange);
  365. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  366. $this->DBUpdate();
  367. }
  368. public function DBDelete(&$oDeletionPlan = null)
  369. {
  370. return $this->DBDeleteTracked_Internal($oDeletionPlan);
  371. }
  372. public function DBDeleteTracked(CMDBChange $oChange, $bSkipStrongSecurity = null, &$oDeletionPlan = null)
  373. {
  374. self::SetCurrentChange($oChange);
  375. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_DELETE);
  376. $this->DBDeleteTracked_Internal($oDeletionPlan);
  377. }
  378. protected function DBDeleteTracked_Internal(&$oDeletionPlan = null)
  379. {
  380. $prevkey = $this->GetKey();
  381. $ret = parent::DBDelete($oDeletionPlan);
  382. return $ret;
  383. }
  384. public static function BulkUpdate(DBObjectSearch $oFilter, array $aValues)
  385. {
  386. return $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  387. }
  388. public static function BulkUpdateTracked(CMDBChange $oChange, DBObjectSearch $oFilter, array $aValues)
  389. {
  390. self::SetCurrentChange($oChange);
  391. $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  392. }
  393. protected static function BulkUpdateTracked_Internal(DBObjectSearch $oFilter, array $aValues)
  394. {
  395. // $aValues is an array of $sAttCode => $value
  396. // Get the list of objects to update (and load it before doing the change)
  397. $oObjSet = new CMDBObjectSet($oFilter);
  398. $oObjSet->Load();
  399. // Keep track of the previous values (will be overwritten when the objects are synchronized with the DB)
  400. $aOriginalValues = array();
  401. $oObjSet->Rewind();
  402. while ($oItem = $oObjSet->Fetch())
  403. {
  404. $aOriginalValues[$oItem->GetKey()] = $oItem->m_aOrigValues;
  405. }
  406. // Update in one single efficient query
  407. $ret = parent::BulkUpdate($oFilter, $aValues);
  408. // Record... in many queries !!!
  409. $oObjSet->Rewind();
  410. while ($oItem = $oObjSet->Fetch())
  411. {
  412. $aChangedValues = $oItem->ListChangedValues($aValues);
  413. $oItem->RecordAttChanges($aChangedValues, $aOriginalValues[$oItem->GetKey()]);
  414. }
  415. return $ret;
  416. }
  417. }
  418. /**
  419. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  420. *
  421. * @package iTopORM
  422. */
  423. class CMDBObjectSet extends DBObjectSet
  424. {
  425. // this is the public interface (?)
  426. // I have to define those constructors here... :-(
  427. // just to get the right object class in return.
  428. // I have to think again to those things: maybe it will work fine if a have a constructor define here (?)
  429. static public function FromScratch($sClass)
  430. {
  431. $oFilter = new CMDBSearchFilter($sClass);
  432. $oFilter->AddConditionExpression(new FalseExpression());
  433. $oRetSet = new self($oFilter);
  434. // NOTE: THIS DOES NOT WORK IF m_bLoaded is private in the base class (and you will not get any error message)
  435. $oRetSet->m_bLoaded = true; // no DB load
  436. return $oRetSet;
  437. }
  438. // create an object set ex nihilo
  439. // input = array of objects
  440. static public function FromArray($sClass, $aObjects)
  441. {
  442. $oRetSet = self::FromScratch($sClass);
  443. $oRetSet->AddObjectArray($aObjects, $sClass);
  444. return $oRetSet;
  445. }
  446. static public function FromArrayAssoc($aClasses, $aObjects)
  447. {
  448. // In a perfect world, we should create a complete tree of DBObjectSearch,
  449. // but as we lack most of the information related to the objects,
  450. // let's create one search definition
  451. $sClass = reset($aClasses);
  452. $sAlias = key($aClasses);
  453. $oFilter = new CMDBSearchFilter($sClass, $sAlias);
  454. $oRetSet = new CMDBObjectSet($oFilter);
  455. $oRetSet->m_bLoaded = true; // no DB load
  456. foreach($aObjects as $rowIndex => $aObjectsByClassAlias)
  457. {
  458. $oRetSet->AddObjectExtended($aObjectsByClassAlias);
  459. }
  460. return $oRetSet;
  461. }
  462. }
  463. /**
  464. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  465. *
  466. * @package iTopORM
  467. */
  468. class CMDBSearchFilter extends DBObjectSearch
  469. {
  470. // this is the public interface (?)
  471. }
  472. ?>