MDL-50714 mod_forum: Correct use of movedicussions cap when posting

The ability to view the group dropdown was too closely related to the
movediscussions capability when posting, or editing a forum post.

The movedicussions capability should only be considered for some parts of
this logic. Users should be able to select the group to post to when
writing message, as long as they have access to that group.
This commit is contained in:
Andrew Nicols
2015-08-21 08:22:24 +08:00
parent ef176837dc
commit 7603f1589c
2 changed files with 58 additions and 24 deletions
+35 -13
View File
@@ -159,24 +159,46 @@ class mod_forum_post_form extends moodleform {
$mform->setConstants(array('timestart'=> 0, 'timeend'=>0));
}
if ($groupmode = groups_get_activity_groupmode($cm, $course)) { // hack alert
if ($groupmode = groups_get_activity_groupmode($cm, $course)) {
$groupdata = groups_get_activity_allowed_groups($cm);
$groupcount = count($groupdata);
$groupinfo = array();
$modulecontext = context_module::instance($cm->id);
// Check whether the user has access to all groups in this forum from the accessallgroups cap.
if ($groupmode == VISIBLEGROUPS || has_capability('moodle/site:accessallgroups', $modulecontext)) {
// Only allow posting to all groups if the user has access to all groups.
$groupinfo = array('0' => get_string('allparticipants'));
$groupinfo = array();
foreach ($groupdata as $groupid => $group) {
// Check whether this user can post in this group.
// We must make this check because all groups are returned for a visible grouped activity.
if (forum_user_can_post_discussion($forum, $groupid, null, $cm, $modcontext)) {
// Build the data for the groupinfo select.
$groupinfo[$groupid] = $group->name;
} else {
unset($groupdata[$groupid]);
}
}
$groupcount = count($groupinfo);
// Check whether this user can post to all groups.
// Posts to the 'All participants' group go to all groups, not to each group in a list.
// It makes sense to allow this, even if there currently aren't any groups because there may be in the future.
if (forum_user_can_post_discussion($forum, -1, null, $cm, $modcontext)) {
// Note: We must reverse in this manner because array_unshift renumbers the array.
$groupinfo = array_reverse($groupinfo, true );
$groupinfo[-1] = get_string('allparticipants');
$groupinfo = array_reverse($groupinfo, true );
$groupcount++;
}
$contextcheck = has_capability('mod/forum:movediscussions', $modulecontext) && empty($post->parent) && $groupcount > 1;
if ($contextcheck) {
foreach ($groupdata as $grouptemp) {
$groupinfo[$grouptemp->id] = $grouptemp->name;
}
// Determine whether the user can select a group from the dropdown. The dropdown is available for several reasons.
// 1) This is a new post (not an edit), and there are at least two groups to choose from.
$canselectgroupfornew = empty($post->edit) && $groupcount > 1;
// 2) This is editing of an existing post and the user is allowed to movediscussions.
// We allow this because the post may have been moved from another forum where groups are not available.
// We show this even if no groups are available as groups *may* have been available but now are not.
$canselectgroupformove = $groupcount && !empty($post->edit) && has_capability('mod/forum:movediscussions', $modcontext);
// Important: You can *only* change the group for a top level post. Never any reply.
$canselectgroup = empty($post->parent) && ($canselectgroupfornew || $canselectgroupformove);
if ($canselectgroup) {
$mform->addElement('select','groupinfo', get_string('group'), $groupinfo);
$mform->setDefault('groupinfo', $post->groupid);
$mform->setType('groupinfo', PARAM_INT);
+23 -11
View File
@@ -693,8 +693,6 @@ if ($mform_post->is_cancelled()) {
// WARNING: the $fromform->message array has been overwritten, do not use it anymore!
$fromform->messagetrust = trusttext_trusted($modcontext);
$contextcheck = isset($fromform->groupinfo) && has_capability('mod/forum:movediscussions', $modcontext);
if ($fromform->edit) { // Updating a post
unset($fromform->groupid);
$fromform->id = $fromform->edit;
@@ -718,10 +716,15 @@ if ($mform_post->is_cancelled()) {
}
// If the user has access to all groups and they are changing the group, then update the post.
if ($contextcheck) {
if (isset($fromform->groupinfo) && has_capability('mod/forum:movediscussions', $modcontext)) {
if (empty($fromform->groupinfo)) {
$fromform->groupinfo = -1;
}
if (!forum_user_can_post_discussion($forum, $fromform->groupinfo, null, $cm, $modcontext)) {
print_error('cannotupdatepost', 'forum');
}
$DB->set_field('forum_discussions' ,'groupid' , $fromform->groupinfo, array('firstpost' => $fromform->id));
}
@@ -849,19 +852,27 @@ if ($mform_post->is_cancelled()) {
exit;
} else { // Adding a new discussion.
// The location to redirect to after successfully posting.
$redirectto = new moodle_url('view.php', array('f' => $fromform->forum));
// Before we add this we must check that the user will not exceed the blocking threshold.
forum_check_blocking_threshold($thresholdwarning);
if (isset($fromform->groupinfo)) {
// Use the value provided in the dropdown group selection.
$fromform->groupid = $fromform->groupinfo;
// Ensure that we redirect back to the group selected.
$redirectto->param('group', $fromform->groupid);
} else if (!isset($fromform->groupid) || empty($fromform->groupid)) {
// There was not value set in the hidden form element.
// Use the value for all participants instead.
$fromform->groupid = -1;
}
if (!forum_user_can_post_discussion($forum, $fromform->groupid, -1, $cm, $modcontext)) {
print_error('cannotcreatediscussion', 'forum');
}
// If the user has access all groups capability let them choose the group.
if ($contextcheck) {
$fromform->groupid = $fromform->groupinfo;
}
if (empty($fromform->groupid)) {
$fromform->groupid = -1;
}
$fromform->mailnow = empty($fromform->mailnow) ? 0 : 1;
@@ -913,7 +924,8 @@ if ($mform_post->is_cancelled()) {
$completion->update_state($cm,COMPLETION_COMPLETE);
}
redirect(forum_go_back_to("view.php?f=$fromform->forum"), $message.$subscribemessage, $timemessage);
// Redirect back to the discussion.
redirect(forum_go_back_to($redirectto->out()), $message . $subscribemessage, $timemessage);
} else {
print_error("couldnotadd", "forum", $errordestination);