-(* COCANWIKI scripts.
+(* COCANWIKI - a wiki written in Objective CAML.
* Written by Richard W.M. Jones <rich@merjis.com>.
* Copyright (C) 2004 Merjis Ltd.
- * $Id: cocanwiki.ml,v 1.4 2004/09/07 16:19:43 rich Exp $
+ * $Id: cocanwiki.ml,v 1.7 2004/09/17 15:24:54 rich Exp $
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ *
+ * You should have received a copy of the GNU General Public License
+ * along with this program; see the file COPYING. If not, write to
+ * the Free Software Foundation, Inc., 59 Temple Place - Suite 330,
+ * Boston, MA 02111-1307, USA.
*)
open Apache
* who can use the script. For example:
* register_script ~restrict:[CanEdit ; CanManageUsers] run
*)
-type permissions_t = CanEdit | CanManageUsers
+type permissions_t = CanEdit | CanManageUsers | CanManageContacts
(* The "user object". *)
type user_t = Anonymous (* Not logged in. *)
let can_edit edit_anon = test_permission edit_anon CanEdit
let can_manage_users = test_permission false CanManageUsers
+let can_manage_contacts = test_permission false CanManageContacts
+
+(* The "host object". *)
+type host_t = { hostname : string;
+ edit_anon : bool; }
(* Our wrapper around the standard [register_script] function.
*
failwith ("Hostname ``" ^ hostname ^ "'' not found in " ^
"the hosts/hostnames tables in the database.") in
+ (* Create the host object. *)
+ let host = { hostname = hostname; edit_anon = edit_anon; } in
+
(* Look for the user's cookie, and determine from this the user
* object.
*)
let sth =
dbh#prepare_cached
- "select u.id, u.name, u.can_edit, u.can_manage_users
+ "select u.id, u.name, u.can_edit, u.can_manage_users,
+ u.can_manage_contacts
from usercookies uc, users u
where uc.cookie = ? and uc.userid = u.id and u.hostid = ?" in
sth#execute [`String cookie; `Int hostid];
(match sth#fetch1 () with
[ `Int userid; `String name;
- `Bool can_edit; `Bool can_manage_users ] ->
+ `Bool can_edit; `Bool can_manage_users;
+ `Bool can_manage_contacts ] ->
let perms =
(if can_edit then [ CanEdit ] else []) @
- (if can_manage_users then [ CanManageUsers ] else []) in
+ (if can_manage_users then [ CanManageUsers ] else []) @
+ (if can_manage_contacts then [ CanManageContacts ] else [])
+ in
User (userid, name, perms)
| _ -> assert false)
with
if permitted then (
(* Call the actual CGI script. *)
try
- run r q dbh (hostid, hostname, edit_anon) user
+ run r q dbh hostid host user
with
CgiExit -> ()
) else