From 4f8aeb1cdf6131fed9984b1635b71e29eb669834 Mon Sep 17 00:00:00 2001 From: Paul Holden Date: Mon, 28 Feb 2022 14:23:25 +0000 Subject: [PATCH] MDL-64770 tool_uploaduser: validate unique field values in upload. If a custom user profile field is set to be unique, then we should ensure that is respected in the entirety of the uploaded data. --- admin/tool/uploaduser/classes/preview.php | 5 ++++- admin/tool/uploaduser/locallib.php | 18 +++++++++++++++++- 2 files changed, 21 insertions(+), 2 deletions(-) diff --git a/admin/tool/uploaduser/classes/preview.php b/admin/tool/uploaduser/classes/preview.php index a59302430b0..53bc8936947 100644 --- a/admin/tool/uploaduser/classes/preview.php +++ b/admin/tool/uploaduser/classes/preview.php @@ -89,6 +89,9 @@ class preview extends \html_table { protected function read_data() { global $DB, $CFG; + // Track whether values for profile fields defined as unique have already been used. + $profilefieldvalues = []; + $data = array(); $this->cir->init(); $linenum = 1; // Column header is first line. @@ -135,7 +138,7 @@ class preview extends \html_table { } // Check if rowcols have custom profile field with correct data and update error state. - $this->noerror = uu_check_custom_profile_data($rowcols) && $this->noerror; + $this->noerror = uu_check_custom_profile_data($rowcols, $profilefieldvalues) && $this->noerror; $rowcols['status'] = implode('
', $rowcols['status']); $data[] = $rowcols; } diff --git a/admin/tool/uploaduser/locallib.php b/admin/tool/uploaduser/locallib.php index 88f020c2041..d79960b32b5 100644 --- a/admin/tool/uploaduser/locallib.php +++ b/admin/tool/uploaduser/locallib.php @@ -440,9 +440,10 @@ function uu_pre_process_custom_profile_data($data) { * Currently checking for custom profile field or type menu * * @param array $data user profile data + * @param array $profilefieldvalues Used to track previous profile field values to ensure uniqueness is observed * @return bool true if no error else false */ -function uu_check_custom_profile_data(&$data) { +function uu_check_custom_profile_data(&$data, array &$profilefieldvalues = []) { global $CFG; require_once($CFG->dirroot.'/user/profile/lib.php'); @@ -466,6 +467,16 @@ function uu_check_custom_profile_data(&$data) { $data['status'][] = get_string('invaliduserfield', 'error', $shortname); $noerror = false; } + + // Ensure unique field value doesn't already exist in supplied data. + $formfieldunique = $formfield->is_unique() && ($value !== '' || $formfield->is_required()); + if ($formfieldunique && array_key_exists($shortname, $profilefieldvalues) && + (array_search($value, $profilefieldvalues[$shortname]) !== false)) { + + $data['status'][] = get_string('valuealreadyused') . " ({$key})"; + $noerror = false; + } + // Check for duplicate value. if (method_exists($formfield, 'edit_validate_field') ) { $testuser = new stdClass(); @@ -477,6 +488,11 @@ function uu_check_custom_profile_data(&$data) { $noerror = false; } } + + // Record value of unique field, so it can be compared for duplicates. + if ($formfieldunique) { + $profilefieldvalues[$shortname][] = $value; + } } } }