cmdbobject.class.inc.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582
  1. <?php
  2. // Copyright (C) 2010-2012 Combodo SARL
  3. //
  4. // This file is part of iTop.
  5. //
  6. // iTop is free software; you can redistribute it and/or modify
  7. // it under the terms of the GNU Affero General Public License as published by
  8. // the Free Software Foundation, either version 3 of the License, or
  9. // (at your option) any later version.
  10. //
  11. // iTop is distributed in the hope that it will be useful,
  12. // but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  14. // GNU Affero General Public License for more details.
  15. //
  16. // You should have received a copy of the GNU Affero General Public License
  17. // along with iTop. If not, see <http://www.gnu.org/licenses/>
  18. /**
  19. * Class cmdbObject
  20. *
  21. * @copyright Copyright (C) 2010-2012 Combodo SARL
  22. * @license http://opensource.org/licenses/AGPL-3.0
  23. */
  24. /**
  25. * cmdbObjectClass
  26. * the file to include, then the core is yours
  27. *
  28. * @package iTopORM
  29. */
  30. require_once('coreexception.class.inc.php');
  31. require_once('config.class.inc.php');
  32. require_once('log.class.inc.php');
  33. require_once('kpi.class.inc.php');
  34. require_once('dict.class.inc.php');
  35. require_once('attributedef.class.inc.php');
  36. require_once('filterdef.class.inc.php');
  37. require_once('stimulus.class.inc.php');
  38. require_once('valuesetdef.class.inc.php');
  39. require_once('MyHelpers.class.inc.php');
  40. require_once('expression.class.inc.php');
  41. require_once('cmdbsource.class.inc.php');
  42. require_once('sqlquery.class.inc.php');
  43. require_once('oql/oqlquery.class.inc.php');
  44. require_once('oql/oqlexception.class.inc.php');
  45. require_once('oql/oql-parser.php');
  46. require_once('oql/oql-lexer.php');
  47. require_once('oql/oqlinterpreter.class.inc.php');
  48. require_once('dbobject.class.php');
  49. require_once('dbobjectsearch.class.php');
  50. require_once('dbobjectset.class.php');
  51. require_once('backgroundprocess.inc.php');
  52. require_once('asynctask.class.inc.php');
  53. require_once('dbproperty.class.inc.php');
  54. // db change tracking data model
  55. require_once('cmdbchange.class.inc.php');
  56. require_once('cmdbchangeop.class.inc.php');
  57. // customization data model
  58. // Romain: temporary moved into application.inc.php (see explanations there)
  59. //require_once('trigger.class.inc.php');
  60. //require_once('action.class.inc.php');
  61. // application log
  62. // Romain: temporary moved into application.inc.php (see explanations there)
  63. //require_once('event.class.inc.php');
  64. require_once('templatestring.class.inc.php');
  65. require_once('csvparser.class.inc.php');
  66. require_once('bulkchange.class.inc.php');
  67. /**
  68. * A persistent object, which changes are accurately recorded
  69. *
  70. * @package iTopORM
  71. */
  72. abstract class CMDBObject extends DBObject
  73. {
  74. protected $m_datCreated;
  75. protected $m_datUpdated;
  76. // Note: this value is static, but that could be changed because it is sometimes a real issue (see update of interfaces / connected_to
  77. protected static $m_oCurrChange = null;
  78. protected static $m_sInfo = null; // null => the information is built in a standard way
  79. /**
  80. * Specify another change (this is mainly for backward compatibility)
  81. */
  82. public static function SetCurrentChange(CMDBChange $oChange)
  83. {
  84. self::$m_oCurrChange = $oChange;
  85. }
  86. //
  87. // Todo: simplify the APIs and do not pass the current change as an argument anymore
  88. // SetTrackInfo to be invoked in very few cases (UI.php, CSV import, Data synchro)
  89. // SetCurrentChange is an alternative to SetTrackInfo (csv ?)
  90. // GetCurrentChange to be called ONCE (!) by CMDBChangeOp::OnInsert ($this->Set('change', ..GetCurrentChange())
  91. // GetCurrentChange to create a default change if not already done in the current context
  92. //
  93. /**
  94. * Get a change record (create it if not existing)
  95. */
  96. public static function GetCurrentChange($bAutoCreate = true)
  97. {
  98. if ($bAutoCreate && is_null(self::$m_oCurrChange))
  99. {
  100. self::CreateChange();
  101. }
  102. return self::$m_oCurrChange;
  103. }
  104. /**
  105. * Override the additional information (defaulting to user name)
  106. * A call to this verb should replace every occurence of
  107. * $oMyChange = MetaModel::NewObject("CMDBChange");
  108. * $oMyChange->Set("date", time());
  109. * $oMyChange->Set("userinfo", 'this is done by ... for ...');
  110. * $iChangeId = $oMyChange->DBInsert();
  111. */
  112. public static function SetTrackInfo($sInfo)
  113. {
  114. self::$m_sInfo = $sInfo;
  115. }
  116. /**
  117. * Get the additional information (defaulting to user name)
  118. */
  119. protected static function GetTrackInfo()
  120. {
  121. if (is_null(self::$m_sInfo))
  122. {
  123. return CMDBChange::GetCurrentUserName();
  124. }
  125. else
  126. {
  127. return self::$m_sInfo;
  128. }
  129. }
  130. /**
  131. * Create a standard change record (done here 99% of the time, and nearly once per page)
  132. */
  133. protected static function CreateChange()
  134. {
  135. self::$m_oCurrChange = MetaModel::NewObject("CMDBChange");
  136. self::$m_oCurrChange->Set("date", time());
  137. self::$m_oCurrChange->Set("userinfo", self::GetTrackInfo());
  138. self::$m_oCurrChange->DBInsert();
  139. }
  140. protected function RecordObjCreation()
  141. {
  142. parent::RecordObjCreation();
  143. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpCreate");
  144. $oMyChangeOp->Set("objclass", get_class($this));
  145. $oMyChangeOp->Set("objkey", $this->GetKey());
  146. $iId = $oMyChangeOp->DBInsertNoReload();
  147. }
  148. protected function RecordObjDeletion($objkey)
  149. {
  150. parent::RecordObjDeletion($objkey);
  151. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpDelete");
  152. $oMyChangeOp->Set("objclass", MetaModel::GetRootClass(get_class($this)));
  153. $oMyChangeOp->Set("objkey", $objkey);
  154. $oMyChangeOp->Set("fclass", get_class($this));
  155. $oMyChangeOp->Set("fname", substr($this->GetRawName(), 0, 255)); // Protect against very long friendly names
  156. $iId = $oMyChangeOp->DBInsertNoReload();
  157. }
  158. protected function RecordAttChanges(array $aValues, array $aOrigValues)
  159. {
  160. parent::RecordAttChanges($aValues, $aOrigValues);
  161. // $aValues is an array of $sAttCode => $value
  162. //
  163. foreach ($aValues as $sAttCode=> $value)
  164. {
  165. $oAttDef = MetaModel::GetAttributeDef(get_class($this), $sAttCode);
  166. if ($oAttDef->IsExternalField()) continue;
  167. if ($oAttDef->IsLinkSet()) continue;
  168. if ($oAttDef->GetTrackingLevel() == TRACKING_NONE) continue;
  169. if (array_key_exists($sAttCode, $aOrigValues))
  170. {
  171. $original = $aOrigValues[$sAttCode];
  172. }
  173. else
  174. {
  175. $original = null;
  176. }
  177. if ($oAttDef instanceOf AttributeOneWayPassword)
  178. {
  179. // One Way encrypted passwords' history is stored -one way- encrypted
  180. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeOneWayPassword");
  181. $oMyChangeOp->Set("objclass", get_class($this));
  182. $oMyChangeOp->Set("objkey", $this->GetKey());
  183. $oMyChangeOp->Set("attcode", $sAttCode);
  184. if (is_null($original))
  185. {
  186. $original = '';
  187. }
  188. $oMyChangeOp->Set("prev_pwd", $original);
  189. $iId = $oMyChangeOp->DBInsertNoReload();
  190. }
  191. elseif ($oAttDef instanceOf AttributeEncryptedString)
  192. {
  193. // Encrypted string history is stored encrypted
  194. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeEncrypted");
  195. $oMyChangeOp->Set("objclass", get_class($this));
  196. $oMyChangeOp->Set("objkey", $this->GetKey());
  197. $oMyChangeOp->Set("attcode", $sAttCode);
  198. if (is_null($original))
  199. {
  200. $original = '';
  201. }
  202. $oMyChangeOp->Set("prevstring", $original);
  203. $iId = $oMyChangeOp->DBInsertNoReload();
  204. }
  205. elseif ($oAttDef instanceOf AttributeBlob)
  206. {
  207. // Data blobs
  208. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeBlob");
  209. $oMyChangeOp->Set("objclass", get_class($this));
  210. $oMyChangeOp->Set("objkey", $this->GetKey());
  211. $oMyChangeOp->Set("attcode", $sAttCode);
  212. if (is_null($original))
  213. {
  214. $original = new ormDocument();
  215. }
  216. $oMyChangeOp->Set("prevdata", $original);
  217. $iId = $oMyChangeOp->DBInsertNoReload();
  218. }
  219. elseif ($oAttDef instanceOf AttributeStopWatch)
  220. {
  221. // Stop watches - record changes for sub items only (they are visible, the rest is not visible)
  222. //
  223. if (is_null($original))
  224. {
  225. $original = new OrmStopWatch();
  226. }
  227. foreach ($oAttDef->ListSubItems() as $sSubItemAttCode => $oSubItemAttDef)
  228. {
  229. $item_value = $oSubItemAttDef->GetValue($value);
  230. $item_original = $oSubItemAttDef->GetValue($original);
  231. if ($item_value != $item_original)
  232. {
  233. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  234. $oMyChangeOp->Set("objclass", get_class($this));
  235. $oMyChangeOp->Set("objkey", $this->GetKey());
  236. $oMyChangeOp->Set("attcode", $sSubItemAttCode);
  237. $oMyChangeOp->Set("oldvalue", $item_original);
  238. $oMyChangeOp->Set("newvalue", $item_value);
  239. $iId = $oMyChangeOp->DBInsertNoReload();
  240. }
  241. }
  242. }
  243. elseif ($oAttDef instanceOf AttributeCaseLog)
  244. {
  245. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeCaseLog");
  246. $oMyChangeOp->Set("objclass", get_class($this));
  247. $oMyChangeOp->Set("objkey", $this->GetKey());
  248. $oMyChangeOp->Set("attcode", $sAttCode);
  249. $oMyChangeOp->Set("lastentry", $value->GetLatestEntryIndex());
  250. $iId = $oMyChangeOp->DBInsertNoReload();
  251. }
  252. elseif ($oAttDef instanceOf AttributeLongText)
  253. {
  254. // Data blobs
  255. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeLongText");
  256. $oMyChangeOp->Set("objclass", get_class($this));
  257. $oMyChangeOp->Set("objkey", $this->GetKey());
  258. $oMyChangeOp->Set("attcode", $sAttCode);
  259. if (!is_null($original) && ($original instanceof ormCaseLog))
  260. {
  261. $original = $original->GetText();
  262. }
  263. $oMyChangeOp->Set("prevdata", $original);
  264. $iId = $oMyChangeOp->DBInsertNoReload();
  265. }
  266. elseif ($oAttDef instanceOf AttributeText)
  267. {
  268. // Data blobs
  269. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeText");
  270. $oMyChangeOp->Set("objclass", get_class($this));
  271. $oMyChangeOp->Set("objkey", $this->GetKey());
  272. $oMyChangeOp->Set("attcode", $sAttCode);
  273. if (!is_null($original) && ($original instanceof ormCaseLog))
  274. {
  275. $original = $original->GetText();
  276. }
  277. $oMyChangeOp->Set("prevdata", $original);
  278. $iId = $oMyChangeOp->DBInsertNoReload();
  279. }
  280. elseif ($oAttDef instanceOf AttributeBoolean)
  281. {
  282. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  283. $oMyChangeOp->Set("objclass", get_class($this));
  284. $oMyChangeOp->Set("objkey", $this->GetKey());
  285. $oMyChangeOp->Set("attcode", $sAttCode);
  286. $oMyChangeOp->Set("oldvalue", $original ? 1 : 0);
  287. $oMyChangeOp->Set("newvalue", $value ? 1 : 0);
  288. $iId = $oMyChangeOp->DBInsertNoReload();
  289. }
  290. elseif ($oAttDef instanceOf AttributeHierarchicalKey)
  291. {
  292. // Hierarchical keys
  293. //
  294. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  295. $oMyChangeOp->Set("objclass", get_class($this));
  296. $oMyChangeOp->Set("objkey", $this->GetKey());
  297. $oMyChangeOp->Set("attcode", $sAttCode);
  298. $oMyChangeOp->Set("oldvalue", $original);
  299. $oMyChangeOp->Set("newvalue", $value[$sAttCode]);
  300. $iId = $oMyChangeOp->DBInsertNoReload();
  301. }
  302. else
  303. {
  304. // Scalars
  305. //
  306. $oMyChangeOp = MetaModel::NewObject("CMDBChangeOpSetAttributeScalar");
  307. $oMyChangeOp->Set("objclass", get_class($this));
  308. $oMyChangeOp->Set("objkey", $this->GetKey());
  309. $oMyChangeOp->Set("attcode", $sAttCode);
  310. $oMyChangeOp->Set("oldvalue", $original);
  311. $oMyChangeOp->Set("newvalue", $value);
  312. $iId = $oMyChangeOp->DBInsertNoReload();
  313. }
  314. }
  315. }
  316. /**
  317. * Helper to ultimately check user rights before writing (Insert, Update or Delete)
  318. * The check should never fail, because the UI should prevent from such a usage
  319. * Anyhow, if the user has found a workaround... the security gets enforced here
  320. */
  321. protected function CheckUserRights($bSkipStrongSecurity, $iActionCode)
  322. {
  323. if (is_null($bSkipStrongSecurity))
  324. {
  325. // This is temporary
  326. // We have implemented this safety net right before releasing iTop 1.0
  327. // and we decided that it was too risky to activate it
  328. // Anyhow, users willing to have a very strong security could set
  329. // skip_strong_security = 0, in the config file
  330. $bSkipStrongSecurity = MetaModel::GetConfig()->Get('skip_strong_security');
  331. }
  332. if (!$bSkipStrongSecurity)
  333. {
  334. $sClass = get_class($this);
  335. $oSet = DBObjectSet::FromObject($this);
  336. if (!UserRights::IsActionAllowed($sClass, $iActionCode, $oSet))
  337. {
  338. // Intrusion detected
  339. throw new SecurityException('You are not allowed to modify objects of class: '.$sClass);
  340. }
  341. }
  342. }
  343. public function DBInsert()
  344. {
  345. return $this->DBInsertTracked_Internal();
  346. }
  347. public function DBInsertTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  348. {
  349. self::SetCurrentChange($oChange);
  350. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  351. $ret = $this->DBInsertTracked_Internal();
  352. return $ret;
  353. }
  354. public function DBInsertTrackedNoReload(CMDBChange $oChange, $bSkipStrongSecurity = null)
  355. {
  356. self::SetCurrentChange($oChange);
  357. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  358. $ret = $this->DBInsertTracked_Internal(true);
  359. return $ret;
  360. }
  361. protected function DBInsertTracked_Internal($bDoNotReload = false)
  362. {
  363. if ($bDoNotReload)
  364. {
  365. $ret = parent::DBInsertNoReload();
  366. }
  367. else
  368. {
  369. $ret = parent::DBInsert();
  370. }
  371. return $ret;
  372. }
  373. public function DBClone($newKey = null)
  374. {
  375. return $this->DBCloneTracked_Internal();
  376. }
  377. public function DBCloneTracked(CMDBChange $oChange, $newKey = null)
  378. {
  379. self::SetCurrentChange($oChange);
  380. $this->DBCloneTracked_Internal($newKey);
  381. }
  382. protected function DBCloneTracked_Internal($newKey = null)
  383. {
  384. $newKey = parent::DBClone($newKey);
  385. $oClone = MetaModel::GetObject(get_class($this), $newKey);
  386. return $newKey;
  387. }
  388. public function DBUpdate()
  389. {
  390. // Copy the changes list before the update (the list should be reset afterwards)
  391. $aChanges = $this->ListChanges();
  392. if (count($aChanges) == 0)
  393. {
  394. return;
  395. }
  396. $ret = parent::DBUpdate();
  397. return $ret;
  398. }
  399. public function DBUpdateTracked(CMDBChange $oChange, $bSkipStrongSecurity = null)
  400. {
  401. self::SetCurrentChange($oChange);
  402. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_MODIFY);
  403. $this->DBUpdate();
  404. }
  405. public function DBDelete(&$oDeletionPlan = null)
  406. {
  407. return $this->DBDeleteTracked_Internal($oDeletionPlan);
  408. }
  409. public function DBDeleteTracked(CMDBChange $oChange, $bSkipStrongSecurity = null, &$oDeletionPlan = null)
  410. {
  411. self::SetCurrentChange($oChange);
  412. $this->CheckUserRights($bSkipStrongSecurity, UR_ACTION_DELETE);
  413. $this->DBDeleteTracked_Internal($oDeletionPlan);
  414. }
  415. protected function DBDeleteTracked_Internal(&$oDeletionPlan = null)
  416. {
  417. $prevkey = $this->GetKey();
  418. $ret = parent::DBDelete($oDeletionPlan);
  419. return $ret;
  420. }
  421. public static function BulkUpdate(DBObjectSearch $oFilter, array $aValues)
  422. {
  423. return $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  424. }
  425. public static function BulkUpdateTracked(CMDBChange $oChange, DBObjectSearch $oFilter, array $aValues)
  426. {
  427. self::SetCurrentChange($oChange);
  428. $this->BulkUpdateTracked_Internal($oFilter, $aValues);
  429. }
  430. protected static function BulkUpdateTracked_Internal(DBObjectSearch $oFilter, array $aValues)
  431. {
  432. // $aValues is an array of $sAttCode => $value
  433. // Get the list of objects to update (and load it before doing the change)
  434. $oObjSet = new CMDBObjectSet($oFilter);
  435. $oObjSet->Load();
  436. // Keep track of the previous values (will be overwritten when the objects are synchronized with the DB)
  437. $aOriginalValues = array();
  438. $oObjSet->Rewind();
  439. while ($oItem = $oObjSet->Fetch())
  440. {
  441. $aOriginalValues[$oItem->GetKey()] = $oItem->m_aOrigValues;
  442. }
  443. // Update in one single efficient query
  444. $ret = parent::BulkUpdate($oFilter, $aValues);
  445. // Record... in many queries !!!
  446. $oObjSet->Rewind();
  447. while ($oItem = $oObjSet->Fetch())
  448. {
  449. $aChangedValues = $oItem->ListChangedValues($aValues);
  450. $oItem->RecordAttChanges($aChangedValues, $aOriginalValues[$oItem->GetKey()]);
  451. }
  452. return $ret;
  453. }
  454. }
  455. /**
  456. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  457. *
  458. * @package iTopORM
  459. */
  460. class CMDBObjectSet extends DBObjectSet
  461. {
  462. // this is the public interface (?)
  463. // I have to define those constructors here... :-(
  464. // just to get the right object class in return.
  465. // I have to think again to those things: maybe it will work fine if a have a constructor define here (?)
  466. static public function FromScratch($sClass)
  467. {
  468. $oFilter = new CMDBSearchFilter($sClass);
  469. $oFilter->AddConditionExpression(new FalseExpression());
  470. $oRetSet = new self($oFilter);
  471. // NOTE: THIS DOES NOT WORK IF m_bLoaded is private in the base class (and you will not get any error message)
  472. $oRetSet->m_bLoaded = true; // no DB load
  473. return $oRetSet;
  474. }
  475. // create an object set ex nihilo
  476. // input = array of objects
  477. static public function FromArray($sClass, $aObjects)
  478. {
  479. $oRetSet = self::FromScratch($sClass);
  480. $oRetSet->AddObjectArray($aObjects, $sClass);
  481. return $oRetSet;
  482. }
  483. static public function FromArrayAssoc($aClasses, $aObjects)
  484. {
  485. // In a perfect world, we should create a complete tree of DBObjectSearch,
  486. // but as we lack most of the information related to the objects,
  487. // let's create one search definition
  488. $sClass = reset($aClasses);
  489. $sAlias = key($aClasses);
  490. $oFilter = new CMDBSearchFilter($sClass, $sAlias);
  491. $oRetSet = new CMDBObjectSet($oFilter);
  492. $oRetSet->m_bLoaded = true; // no DB load
  493. foreach($aObjects as $rowIndex => $aObjectsByClassAlias)
  494. {
  495. $oRetSet->AddObjectExtended($aObjectsByClassAlias);
  496. }
  497. return $oRetSet;
  498. }
  499. }
  500. /**
  501. * TODO: investigate how to get rid of this class that was made to workaround some language limitation... or a poor design!
  502. *
  503. * @package iTopORM
  504. */
  505. class CMDBSearchFilter extends DBObjectSearch
  506. {
  507. // this is the public interface (?)
  508. }
  509. ?>