cmdbobject.class.inc.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581
  1. <?php
  2. // Copyright (C) 2010-2012 Combodo SARL
  3. //
  4. // This file is part of iTop.
  5. //
  6. // iTop is free software; you can redistribute it and/or modify
  7. // it under the terms of the GNU Affero General Public License as published by
  8. // the Free Software Foundation, either version 3 of the License, or
  9. // (at your option) any later version.
  10. //
  11. // iTop is distributed in the hope that it will be useful,
  12. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  14. // GNU Affero General Public License for more details.
  15. //
  16. // You should have received a copy of the GNU Affero General Public License
  17. // along with iTop. If not, see <http://www.gnu.org/licenses/>
  18. /**
  19. * Class cmdbObject
  20. *
  21. * @copyright Copyright (C) 2010-2012 Combodo SARL
  22. * @license http://opensource.org/licenses/AGPL-3.0
  23. */
  24. /**
  25. * cmdbObjectClass
  26. * the file to include, then the core is yours
  27. *
  28. * @package iTopORM
  29. */
  30. require_once('coreexception.class.inc.php');
  31. require_once('config.class.inc.php');
  32. require_once('log.class.inc.php');
  33. require_once('kpi.class.inc.php');
  34. require_once('dict.class.inc.php');
  35. require_once('attributedef.class.inc.php');
  36. require_once('filterdef.class.inc.php');
  37. require_once('stimulus.class.inc.php');
  38. require_once('valuesetdef.class.inc.php');
  39. require_once('MyHelpers.class.inc.php');
  40. require_once('expression.class.inc.php');
  41. require_once('cmdbsource.class.inc.php');
  42. require_once('sqlquery.class.inc.php');
  43. require_once('oql/oqlquery.class.inc.php');
  44. require_once('oql/oqlexception.class.inc.php');
  45. require_once('oql/oql-parser.php');
  46. require_once('oql/oql-lexer.php');
  47. require_once('oql/oqlinterpreter.class.inc.php');
  48. require_once('dbobject.class.php');
  49. require_once('dbobjectsearch.class.php');
  50. require_once('dbobjectset.class.php');
  51. require_once('backgroundprocess.inc.php');
  52. require_once('asynctask.class.inc.php');
  53. require_once('dbproperty.class.inc.php');
  54. // db change tracking data model
  55. require_once('cmdbchange.class.inc.php');
  56. require_once('cmdbchangeop.class.inc.php');
  57. // customization data model
  58. // Romain: temporary moved into application.inc.php (see explanations there)
  59. //require_once('trigger.class.inc.php');
  60. //require_once('action.class.inc.php');
  61. // application log
  62. // Romain: temporary moved into application.inc.php (see explanations there)
  63. //require_once('event.class.inc.php');
  64. require_once('templatestring.class.inc.php');
  65. require_once('csvparser.class.inc.php');
  66. require_once('bulkchange.class.inc.php');
  67. /**
  68. * A persistent object, which changes are accurately recorded
  69. *
  70. * @package iTopORM
  71. */
  72. abstract class CMDBObject extends DBObject
  73. {
  74. protected $m_datCreated;
  75. protected $m_datUpdated;
  76. // Note: this value is static, but that could be changed because it is sometimes a real issue (see update of interfaces / connected_to
  77. protected static $m_oCurrChange = null;
  78. protected static $m_sInfo = null; // null => the information is built in a standard way
  79. /**
  80. * Specify another change (this is mainly for backward compatibility)
  81. */
  82. public static function SetCurrentChange(CMDBChange $oChange)
  83. {
  84. self::$m_oCurrChange = $oChange;
  85. }
  86. //
  87. // Todo: simplify the APIs and do not pass the current change as an argument anymore
  88. // SetTrackInfo to be invoked in very few cases (UI.php, CSV import, Data synchro)
  89. // SetCurrentChange is an alternative to SetTrackInfo (csv ?)
  90. // GetCurrentChange to be called ONCE (!) by CMDBChangeOp::OnInsert ($this->Set('change', ..GetCurrentChange())
  91. // GetCurrentChange to create a default change if not already done in the current context
  92. //
  93. /**
  94. * Get a change record (create it if not existing)
  95. */
  96. public static function GetCurrentChange($bAutoCreate = true)
  97. {
  98. if ($bAutoCreate && is_null(self::$m_oCurrChange))
  99. {
  100. self::CreateChange();
  101. }
  102. return self::$m_oCurrChange;
  103. }
  104. /**
  105. * Override the additional information (defaulting to user name)
  106. * A call to this verb should replace every occurence of
  107. * $oMyChange = MetaModel::NewObject("CMDBChange");
  108. * $oMyChange->Set("date", time());
  109. * $oMyChange->Set("userinfo", 'this is done by ... for ...');
  110. * $iChangeId = $oMyChange->DBInsert();
  111. */
  112. public static function SetTrackInfo($sInfo)
  113. {
  114. self::$m_sInfo = $sInfo;
  115. }
  116. /**
  117. * Get the additional information (defaulting to user name)
  118. */
  119. protected static function GetTrackInfo()
  120. {
  121. if (is_null(self::$m_sInfo))
  122. {
  123. return CMDBChange::GetCurrentUserName();
  124. }
  125. else
  126. {
  127. return self::$m_sInfo;
  128. }
  129. }
  130. /**
  131. * Create a standard change record (done here 99% of the time, and nearly once per page)
  132. */
  133. protected static function CreateChange()
  134. {
  135. self::$m_oCurrChange = MetaModel::NewObject("CMDBChange");
  136. self::$m_oCurrChange->Set("date", time());
  137. self::$m_oCurrChange->Set("userinfo", self::GetTrackInfo());
  138. self::$m_oCurrChange->DBInsert();
  139. }
  140. protected function RecordObjCreation()
  141. {
  142. parent::RecordObjCreation();
  143. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpCreate");
  144. $oMyChangeOp->Set("objclass", get_class($this));
  145. $oMyChangeOp->Set("objkey", $this->GetKey());
  146. $iId = $oMyChangeOp->DBInsertNoReload();
  147. }
  148. protected function RecordObjDeletion($objkey)
  149. {
  150. parent::RecordObjDeletion($objkey);
  151. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpDelete");
  152. $oMyChangeOp->Set("objclass", MetaModel::GetRootClass(get_class($this)));
  153. $oMyChangeOp->Set("objkey", $objkey);
  154. $oMyChangeOp->Set("fclass", get_class($this));
  155. $oMyChangeOp->Set("fname", $this->GetRawName());
  156. $iId = $oMyChangeOp->DBInsertNoReload();
  157. }
  158. protected function RecordAttChanges(array $aValues, array $aOrigValues)
  159. {
  160. parent::RecordAttChanges($aValues, $aOrigValues);
  161. // $aValues is an array of $sAttCode => $value
  162. //
  163. foreach ($aValues as $sAttCode=> $value)
  164. {
  165. $oAttDef = MetaModel::GetAttributeDef(get_class($this), $sAttCode);
  166. if ($oAttDef->IsExternalField()) continue; // #@# temporary
  167. if ($oAttDef->IsLinkSet()) continue; // #@# temporary
  168. if (array_key_exists($sAttCode, $aOrigValues))
  169. {
  170. $original = $aOrigValues[$sAttCode];
  171. }
  172. else
  173. {
  174. $original = null;
  175. }
  176. if ($oAttDef instanceOf AttributeOneWayPassword)
  177. {
  178. // One Way encrypted passwords' history is stored -one way- encrypted
  179. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeOneWayPassword");
  180. $oMyChangeOp->Set("objclass", get_class($this));
  181. $oMyChangeOp->Set("objkey", $this->GetKey());
  182. $oMyChangeOp->Set("attcode", $sAttCode);
  183. if (is_null($original))
  184. {
  185. $original = '';
  186. }
  187. $oMyChangeOp->Set("prev_pwd", $original);
  188. $iId = $oMyChangeOp->DBInsertNoReload();
  189. }
  190. elseif ($oAttDef instanceOf AttributeEncryptedString)
  191. {
  192. // Encrypted string history is stored encrypted
  193. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeEncrypted");
  194. $oMyChangeOp->Set("objclass", get_class($this));
  195. $oMyChangeOp->Set("objkey", $this->GetKey());
  196. $oMyChangeOp->Set("attcode", $sAttCode);
  197. if (is_null($original))
  198. {
  199. $original = '';
  200. }
  201. $oMyChangeOp->Set("prevstring", $original);
  202. $iId = $oMyChangeOp->DBInsertNoReload();
  203. }
  204. elseif ($oAttDef instanceOf AttributeBlob)
  205. {
  206. // Data blobs
  207. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeBlob");
  208. $oMyChangeOp->Set("objclass", get_class($this));
  209. $oMyChangeOp->Set("objkey", $this->GetKey());
  210. $oMyChangeOp->Set("attcode", $sAttCode);
  211. if (is_null($original))
  212. {
  213. $original = new ormDocument();
  214. }
  215. $oMyChangeOp->Set("prevdata", $original);
  216. $iId = $oMyChangeOp->DBInsertNoReload();
  217. }
  218. elseif ($oAttDef instanceOf AttributeStopWatch)
  219. {
  220. // Stop watches - record changes for sub items only (they are visible, the rest is not visible)
  221. //
  222. if (is_null($original))
  223. {
  224. $original = new OrmStopWatch();
  225. }
  226. foreach ($oAttDef->ListSubItems() as $sSubItemAttCode => $oSubItemAttDef)
  227. {
  228. $item_value = $oSubItemAttDef->GetValue($value);
  229. $item_original = $oSubItemAttDef->GetValue($original);
  230. if ($item_value != $item_original)
  231. {
  232. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  233. $oMyChangeOp->Set("objclass", get_class($this));
  234. $oMyChangeOp->Set("objkey", $this->GetKey());
  235. $oMyChangeOp->Set("attcode", $sSubItemAttCode);
  236. $oMyChangeOp->Set("oldvalue", $item_original);
  237. $oMyChangeOp->Set("newvalue", $item_value);
  238. $iId = $oMyChangeOp->DBInsertNoReload();
  239. }
  240. }
  241. }
  242. elseif ($oAttDef instanceOf AttributeCaseLog)
  243. {
  244. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeCaseLog");
  245. $oMyChangeOp->Set("objclass", get_class($this));
  246. $oMyChangeOp->Set("objkey", $this->GetKey());
  247. $oMyChangeOp->Set("attcode", $sAttCode);
  248. $oMyChangeOp->Set("lastentry", $value->GetLatestEntryIndex());
  249. $iId = $oMyChangeOp->DBInsertNoReload();
  250. }
  251. elseif ($oAttDef instanceOf AttributeLongText)
  252. {
  253. // Data blobs
  254. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeLongText");
  255. $oMyChangeOp->Set("objclass", get_class($this));
  256. $oMyChangeOp->Set("objkey", $this->GetKey());
  257. $oMyChangeOp->Set("attcode", $sAttCode);
  258. if (!is_null($original) && ($original instanceof ormCaseLog))
  259. {
  260. $original = $original->GetText();
  261. }
  262. $oMyChangeOp->Set("prevdata", $original);
  263. $iId = $oMyChangeOp->DBInsertNoReload();
  264. }
  265. elseif ($oAttDef instanceOf AttributeText)
  266. {
  267. // Data blobs
  268. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeText");
  269. $oMyChangeOp->Set("objclass", get_class($this));
  270. $oMyChangeOp->Set("objkey", $this->GetKey());
  271. $oMyChangeOp->Set("attcode", $sAttCode);
  272. if (!is_null($original) && ($original instanceof ormCaseLog))
  273. {
  274. $original = $original->GetText();
  275. }
  276. $oMyChangeOp->Set("prevdata", $original);
  277. $iId = $oMyChangeOp->DBInsertNoReload();
  278. }
  279. elseif ($oAttDef instanceOf AttributeBoolean)
  280. {
  281. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  282. $oMyChangeOp->Set("objclass", get_class($this));
  283. $oMyChangeOp->Set("objkey", $this->GetKey());
  284. $oMyChangeOp->Set("attcode", $sAttCode);
  285. $oMyChangeOp->Set("oldvalue", $original ? 1 : 0);
  286. $oMyChangeOp->Set("newvalue", $value ? 1 : 0);
  287. $iId = $oMyChangeOp->DBInsertNoReload();
  288. }
  289. elseif ($oAttDef instanceOf AttributeHierarchicalKey)
  290. {
  291. // Hierarchical keys
  292. //
  293. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  294. $oMyChangeOp->Set("objclass", get_class($this));
  295. $oMyChangeOp->Set("objkey", $this->GetKey());
  296. $oMyChangeOp->Set("attcode", $sAttCode);
  297. $oMyChangeOp->Set("oldvalue", $original);
  298. $oMyChangeOp->Set("newvalue", $value[$sAttCode]);
  299. $iId = $oMyChangeOp->DBInsertNoReload();
  300. }
  301. else
  302. {
  303. // Scalars
  304. //
  305. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  306. $oMyChangeOp->Set("objclass", get_class($this));
  307. $oMyChangeOp->Set("objkey", $this->GetKey());
  308. $oMyChangeOp->Set("attcode", $sAttCode);
  309. $oMyChangeOp->Set("oldvalue", $original);
  310. $oMyChangeOp->Set("newvalue", $value);
  311. $iId = $oMyChangeOp->DBInsertNoReload();
  312. }
  313. }
  314. }
  315. /**
  316. * Helper to ultimately check user rights before writing (Insert, Update or Delete)
  317. * The check should never fail, because the UI should prevent from such a usage
  318. * Anyhow, if the user has found a workaround... the security gets enforced here
  319. */
  320. protected function CheckUserRights($bSkipStrongSecurity, $iActionCode)
  321. {
  322. if (is_null($bSkipStrongSecurity))
  323. {
  324. // This is temporary
  325. // We have implemented this safety net right before releasing iTop 1.0
  326. // and we decided that it was too risky to activate it
  327. // Anyhow, users willing to have a very strong security could set
  328. // skip_strong_security = 0, in the config file
  329. $bSkipStrongSecurity = MetaModel::GetConfig()->Get('skip_strong_security');
  330. }
  331. if (!$bSkipStrongSecurity)
  332. {
  333. $sClass = get_class($this);
  334. $oSet = DBObjectSet::FromObject($this);
  335. if (!UserRights::IsActionAllowed($sClass, $iActionCode, $oSet))
  336. {
  337. // Intrusion detected
  338. throw new SecurityException('You are not allowed to modify objects of class: '.$sClass);
  339. }
  340. }
  341. }
  342. public function DBInsert()
  343. {
  344. return $this->DBInsertTracked_Internal();
  345. }
  346. public function DBInsertTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  347. {
  348. self::SetCurrentChange($oChange);
  349. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  350. $ret = $this->DBInsertTracked_Internal();
  351. return $ret;
  352. }
  353. public function DBInsertTrackedNoReload(CMDBChange $oChange, $bSkipStrongSecurity = null)
  354. {
  355. self::SetCurrentChange($oChange);
  356. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  357. $ret = $this->DBInsertTracked_Internal(true);
  358. return $ret;
  359. }
  360. protected function DBInsertTracked_Internal($bDoNotReload = false)
  361. {
  362. if ($bDoNotReload)
  363. {
  364. $ret = parent::DBInsertNoReload();
  365. }
  366. else
  367. {
  368. $ret = parent::DBInsert();
  369. }
  370. return $ret;
  371. }
  372. public function DBClone($newKey = null)
  373. {
  374. return $this->DBCloneTracked_Internal();
  375. }
  376. public function DBCloneTracked(CMDBChange $oChange, $newKey = null)
  377. {
  378. self::SetCurrentChange($oChange);
  379. $this->DBCloneTracked_Internal($newKey);
  380. }
  381. protected function DBCloneTracked_Internal($newKey = null)
  382. {
  383. $newKey = parent::DBClone($newKey);
  384. $oClone = MetaModel::GetObject(get_class($this), $newKey);
  385. return $newKey;
  386. }
  387. public function DBUpdate()
  388. {
  389. // Copy the changes list before the update (the list should be reset afterwards)
  390. $aChanges = $this->ListChanges();
  391. if (count($aChanges) == 0)
  392. {
  393. return;
  394. }
  395. $ret = parent::DBUpdate();
  396. return $ret;
  397. }
  398. public function DBUpdateTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  399. {
  400. self::SetCurrentChange($oChange);
  401. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  402. $this->DBUpdate();
  403. }
  404. public function DBDelete(&$oDeletionPlan = null)
  405. {
  406. return $this->DBDeleteTracked_Internal($oDeletionPlan);
  407. }
  408. public function DBDeleteTracked(CMDBChange $oChange, $bSkipStrongSecurity = null, &$oDeletionPlan = null)
  409. {
  410. self::SetCurrentChange($oChange);
  411. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_DELETE);
  412. $this->DBDeleteTracked_Internal($oDeletionPlan);
  413. }
  414. protected function DBDeleteTracked_Internal(&$oDeletionPlan = null)
  415. {
  416. $prevkey = $this->GetKey();
  417. $ret = parent::DBDelete($oDeletionPlan);
  418. return $ret;
  419. }
  420. public static function BulkUpdate(DBObjectSearch $oFilter, array $aValues)
  421. {
  422. return $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  423. }
  424. public static function BulkUpdateTracked(CMDBChange $oChange, DBObjectSearch $oFilter, array $aValues)
  425. {
  426. self::SetCurrentChange($oChange);
  427. $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  428. }
  429. protected static function BulkUpdateTracked_Internal(DBObjectSearch $oFilter, array $aValues)
  430. {
  431. // $aValues is an array of $sAttCode => $value
  432. // Get the list of objects to update (and load it before doing the change)
  433. $oObjSet = new CMDBObjectSet($oFilter);
  434. $oObjSet->Load();
  435. // Keep track of the previous values (will be overwritten when the objects are synchronized with the DB)
  436. $aOriginalValues = array();
  437. $oObjSet->Rewind();
  438. while ($oItem = $oObjSet->Fetch())
  439. {
  440. $aOriginalValues[$oItem->GetKey()] = $oItem->m_aOrigValues;
  441. }
  442. // Update in one single efficient query
  443. $ret = parent::BulkUpdate($oFilter, $aValues);
  444. // Record... in many queries !!!
  445. $oObjSet->Rewind();
  446. while ($oItem = $oObjSet->Fetch())
  447. {
  448. $aChangedValues = $oItem->ListChangedValues($aValues);
  449. $oItem->RecordAttChanges($aChangedValues, $aOriginalValues[$oItem->GetKey()]);
  450. }
  451. return $ret;
  452. }
  453. }
  454. /**
  455. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  456. *
  457. * @package iTopORM
  458. */
  459. class CMDBObjectSet extends DBObjectSet
  460. {
  461. // this is the public interface (?)
  462. // I have to define those constructors here... :-(
  463. // just to get the right object class in return.
  464. // I have to think again to those things: maybe it will work fine if a have a constructor define here (?)
  465. static public function FromScratch($sClass)
  466. {
  467. $oFilter = new CMDBSearchFilter($sClass);
  468. $oFilter->AddConditionExpression(new FalseExpression());
  469. $oRetSet = new self($oFilter);
  470. // NOTE: THIS DOES NOT WORK IF m_bLoaded is private in the base class (and you will not get any error message)
  471. $oRetSet->m_bLoaded = true; // no DB load
  472. return $oRetSet;
  473. }
  474. // create an object set ex nihilo
  475. // input = array of objects
  476. static public function FromArray($sClass, $aObjects)
  477. {
  478. $oRetSet = self::FromScratch($sClass);
  479. $oRetSet->AddObjectArray($aObjects, $sClass);
  480. return $oRetSet;
  481. }
  482. static public function FromArrayAssoc($aClasses, $aObjects)
  483. {
  484. // In a perfect world, we should create a complete tree of DBObjectSearch,
  485. // but as we lack most of the information related to the objects,
  486. // let's create one search definition
  487. $sClass = reset($aClasses);
  488. $sAlias = key($aClasses);
  489. $oFilter = new CMDBSearchFilter($sClass, $sAlias);
  490. $oRetSet = new CMDBObjectSet($oFilter);
  491. $oRetSet->m_bLoaded = true; // no DB load
  492. foreach($aObjects as $rowIndex => $aObjectsByClassAlias)
  493. {
  494. $oRetSet->AddObjectExtended($aObjectsByClassAlias);
  495. }
  496. return $oRetSet;
  497. }
  498. }
  499. /**
  500. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  501. *
  502. * @package iTopORM
  503. */
  504. class CMDBSearchFilter extends DBObjectSearch
  505. {
  506. // this is the public interface (?)
  507. }
  508. ?>