remove roles from users when role is deleted (#1640)
This commit is contained in:
@@ -17,6 +17,7 @@ use App\Form\RoleType;
|
|||||||
use App\Model\PermissionSection;
|
use App\Model\PermissionSection;
|
||||||
use App\Repository\RolePermissionRepository;
|
use App\Repository\RolePermissionRepository;
|
||||||
use App\Repository\RoleRepository;
|
use App\Repository\RoleRepository;
|
||||||
|
use App\Repository\UserRepository;
|
||||||
use App\Security\RolePermissionManager;
|
use App\Security\RolePermissionManager;
|
||||||
use App\Security\RoleService;
|
use App\Security\RoleService;
|
||||||
use Sensio\Bundle\FrameworkExtraBundle\Configuration\Security;
|
use Sensio\Bundle\FrameworkExtraBundle\Configuration\Security;
|
||||||
@@ -195,9 +196,16 @@ final class PermissionController extends AbstractController
|
|||||||
* @Route(path="/roles/{id}/delete", name="admin_user_role_delete", methods={"GET", "POST"})
|
* @Route(path="/roles/{id}/delete", name="admin_user_role_delete", methods={"GET", "POST"})
|
||||||
* @Security("is_granted('role_permissions')")
|
* @Security("is_granted('role_permissions')")
|
||||||
*/
|
*/
|
||||||
public function deleteRole(Role $role): Response
|
public function deleteRole(Role $role, UserRepository $userRepository): Response
|
||||||
{
|
{
|
||||||
try {
|
try {
|
||||||
|
// workaround, as roles is still a string array on users table
|
||||||
|
// until this is fixed, the users must be manually updated
|
||||||
|
$users = $userRepository->findUsersWithRole($role->getName());
|
||||||
|
foreach ($users as $user) {
|
||||||
|
$user->removeRole($role->getName());
|
||||||
|
$userRepository->saveUser($user);
|
||||||
|
}
|
||||||
$this->roleRepository->deleteRole($role);
|
$this->roleRepository->deleteRole($role);
|
||||||
$this->flashSuccess('action.delete.success');
|
$this->flashSuccess('action.delete.success');
|
||||||
} catch (\Exception $ex) {
|
} catch (\Exception $ex) {
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
|
|
||||||
namespace App\Repository;
|
namespace App\Repository;
|
||||||
|
|
||||||
|
use App\Entity\Role;
|
||||||
use App\Entity\User;
|
use App\Entity\User;
|
||||||
use App\Repository\Loader\UserLoader;
|
use App\Repository\Loader\UserLoader;
|
||||||
use App\Repository\Paginator\LoaderPaginator;
|
use App\Repository\Paginator\LoaderPaginator;
|
||||||
@@ -170,6 +171,28 @@ class UserRepository extends EntityRepository implements UserLoaderInterface
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param string $role
|
||||||
|
* @return User[]
|
||||||
|
* @internal
|
||||||
|
*/
|
||||||
|
public function findUsersWithRole(string $role): array
|
||||||
|
{
|
||||||
|
if ($role === User::ROLE_USER) {
|
||||||
|
return $this->findAll();
|
||||||
|
}
|
||||||
|
|
||||||
|
$qb = $this->getEntityManager()->createQueryBuilder();
|
||||||
|
|
||||||
|
$qb
|
||||||
|
->select('u')
|
||||||
|
->from(User::class, 'u')
|
||||||
|
->andWhere('u.roles LIKE :role');
|
||||||
|
$qb->setParameter('role', '%' . $role . '%');
|
||||||
|
|
||||||
|
return $qb->getQuery()->getResult();
|
||||||
|
}
|
||||||
|
|
||||||
private function getQueryBuilderForQuery(UserQuery $query): QueryBuilder
|
private function getQueryBuilderForQuery(UserQuery $query): QueryBuilder
|
||||||
{
|
{
|
||||||
$qb = $this->getEntityManager()->createQueryBuilder();
|
$qb = $this->getEntityManager()->createQueryBuilder();
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
|
|
||||||
namespace App\Tests\Controller;
|
namespace App\Tests\Controller;
|
||||||
|
|
||||||
|
use App\DataFixtures\UserFixtures;
|
||||||
use App\Entity\RolePermission;
|
use App\Entity\RolePermission;
|
||||||
use App\Entity\User;
|
use App\Entity\User;
|
||||||
|
|
||||||
@@ -105,6 +106,23 @@ class PermissionControllerTest extends ControllerBaseTest
|
|||||||
$content = $client->getResponse()->getContent();
|
$content = $client->getResponse()->getContent();
|
||||||
self::assertStringContainsString('<th data-field="TEST_ROLE" class="alwaysVisible text-center">', $content);
|
self::assertStringContainsString('<th data-field="TEST_ROLE" class="alwaysVisible text-center">', $content);
|
||||||
|
|
||||||
|
// add user to role
|
||||||
|
$this->request($client, '/profile/' . UserFixtures::USERNAME_USER . '/roles');
|
||||||
|
$form = $client->getCrawler()->filter('form[name=user_roles]')->form();
|
||||||
|
$client->submit($form, [
|
||||||
|
'user_roles[roles]' => [
|
||||||
|
0 => 'ROLE_TEAMLEAD',
|
||||||
|
2 => 'ROLE_SUPER_ADMIN',
|
||||||
|
3 => 'TEST_ROLE'
|
||||||
|
]
|
||||||
|
]);
|
||||||
|
$this->assertIsRedirect($client, $this->createUrl('/profile/' . urlencode(UserFixtures::USERNAME_USER) . '/roles'));
|
||||||
|
$client->followRedirect();
|
||||||
|
$this->assertTrue($client->getResponse()->isSuccessful());
|
||||||
|
|
||||||
|
$user = $this->getUserByName(UserFixtures::USERNAME_USER);
|
||||||
|
$this->assertEquals(['ROLE_TEAMLEAD', 'ROLE_SUPER_ADMIN', 'TEST_ROLE', 'ROLE_USER'], $user->getRoles());
|
||||||
|
|
||||||
$this->request($client, '/admin/permissions/roles/1/delete');
|
$this->request($client, '/admin/permissions/roles/1/delete');
|
||||||
$this->assertIsRedirect($client, $this->createUrl('/admin/permissions'));
|
$this->assertIsRedirect($client, $this->createUrl('/admin/permissions'));
|
||||||
$client->followRedirect();
|
$client->followRedirect();
|
||||||
@@ -112,6 +130,10 @@ class PermissionControllerTest extends ControllerBaseTest
|
|||||||
self::assertHasFlashDeleteSuccess($client);
|
self::assertHasFlashDeleteSuccess($client);
|
||||||
$content = $client->getResponse()->getContent();
|
$content = $client->getResponse()->getContent();
|
||||||
self::assertStringNotContainsString('<th data-field="TEST_ROLE" class="alwaysVisible text-center">', $content);
|
self::assertStringNotContainsString('<th data-field="TEST_ROLE" class="alwaysVisible text-center">', $content);
|
||||||
|
|
||||||
|
// verify that role was removed from user
|
||||||
|
$user = $this->getUserByName(UserFixtures::USERNAME_USER);
|
||||||
|
$this->assertEquals(['ROLE_TEAMLEAD', 'ROLE_SUPER_ADMIN', 'ROLE_USER'], $user->getRoles());
|
||||||
}
|
}
|
||||||
|
|
||||||
public function testSavePermissionIsSecured()
|
public function testSavePermissionIsSecured()
|
||||||
|
|||||||
Reference in New Issue
Block a user