MDL-64770 tool_uploaduser: validate unique field values in upload.

If a custom user profile field is set to be unique, then we should
ensure that is respected in the entirety of the uploaded data.
This commit is contained in:
Paul Holden
2022-02-28 14:25:52 +00:00
parent 9cd77c4130
commit 4f8aeb1cdf
2 changed files with 21 additions and 2 deletions
+4 -1
View File
@@ -89,6 +89,9 @@ class preview extends \html_table {
protected function read_data() {
global $DB, $CFG;
// Track whether values for profile fields defined as unique have already been used.
$profilefieldvalues = [];
$data = array();
$this->cir->init();
$linenum = 1; // Column header is first line.
@@ -135,7 +138,7 @@ class preview extends \html_table {
}
// Check if rowcols have custom profile field with correct data and update error state.
$this->noerror = uu_check_custom_profile_data($rowcols) && $this->noerror;
$this->noerror = uu_check_custom_profile_data($rowcols, $profilefieldvalues) && $this->noerror;
$rowcols['status'] = implode('<br />', $rowcols['status']);
$data[] = $rowcols;
}
+17 -1
View File
@@ -440,9 +440,10 @@ function uu_pre_process_custom_profile_data($data) {
* Currently checking for custom profile field or type menu
*
* @param array $data user profile data
* @param array $profilefieldvalues Used to track previous profile field values to ensure uniqueness is observed
* @return bool true if no error else false
*/
function uu_check_custom_profile_data(&$data) {
function uu_check_custom_profile_data(&$data, array &$profilefieldvalues = []) {
global $CFG;
require_once($CFG->dirroot.'/user/profile/lib.php');
@@ -466,6 +467,16 @@ function uu_check_custom_profile_data(&$data) {
$data['status'][] = get_string('invaliduserfield', 'error', $shortname);
$noerror = false;
}
// Ensure unique field value doesn't already exist in supplied data.
$formfieldunique = $formfield->is_unique() && ($value !== '' || $formfield->is_required());
if ($formfieldunique && array_key_exists($shortname, $profilefieldvalues) &&
(array_search($value, $profilefieldvalues[$shortname]) !== false)) {
$data['status'][] = get_string('valuealreadyused') . " ({$key})";
$noerror = false;
}
// Check for duplicate value.
if (method_exists($formfield, 'edit_validate_field') ) {
$testuser = new stdClass();
@@ -477,6 +488,11 @@ function uu_check_custom_profile_data(&$data) {
$noerror = false;
}
}
// Record value of unique field, so it can be compared for duplicates.
if ($formfieldunique) {
$profilefieldvalues[$shortname][] = $value;
}
}
}
}