added some capabilities

This commit is contained in:
toyomoyo
2006-08-30 08:43:17 +00:00
parent 849bbccfbb
commit 81e956b964
25 changed files with 59 additions and 75 deletions
+8 -11
View File
@@ -60,9 +60,11 @@
if (!isloggedin() or isguest()) {
redirect('view.php?d='.$data->id);
}
$context = get_context_instance(CONTEXT_MODULE, $cm->id);
/// If it's hidden then it's don't show anything. :)
if (empty($cm->visible) and !isteacher($course->id)) {
if (empty($cm->visible) and !has_capability('moodle/course:viewhiddenactivities', $context)) {
$strdatabases = get_string("modulenameplural", "data");
$navigation = "<a href=\"index.php?id=$course->id\">$strdatabases</a> ->";
print_header_simple(format_string($data->name), "",
@@ -71,19 +73,14 @@
}
/// Can't use this if there are no fields
if (isteacher($course->id)) {
if (has_capability('mod/data:managetemplates', $context)) {
if (!record_exists('data_fields','dataid',$data->id)) { // Brand new database!
redirect($CFG->wwwroot.'/mod/data/field.php?d='.$data->id); // Redirect to field entry
}
}
/// Check access for participants
if ((!isteacher($course->id)) && $data->participants == DATA_TEACHERS_ONLY) {
error (get_string('noaccess','data'));
}
if ($rid) { // So do you have access?
if (!(isteacher($course->id) or data_isowner($rid)) or !confirm_sesskey() ) {
if (!(has_capability('mod/data:manageentries', $context) or data_isowner($rid)) or !confirm_sesskey() ) {
error(get_string('noaccess','data'));
}
}
@@ -138,7 +135,7 @@
/// All student edits are marked unapproved by default
$record = get_record('data_records','id',$rid);
if ($data->approval == 1 || isteacher($course->id)) {
if ($data->approval == 1 || has_capability('mod/data:approve', $context)) {
$record->approved = 1;
} else {
$record->approved = 0;
@@ -171,7 +168,7 @@
/// Check if maximum number of entry as specified by this database is reached
/// Of course, you can't be stopped if you are an editting teacher! =)
if (data_atmaxentries($data) and !isteacheredit($course->id)){
if (data_atmaxentries($data) and !has_capability('mod/data:manageentries',$context)){
notify (get_string('atmaxentry','data'));
print_footer($course);
exit;
@@ -281,7 +278,7 @@
/// Upload records section. Only for teachers and the admin.
if (isteacher($course->id)) {
if (has_capability('mod/data:manageentries',$context)) {
if ($import) {
print_simple_box_start('center','80%');
print_heading(get_string('uploadrecords', 'data'), '', 3);
-7
View File
@@ -67,13 +67,6 @@
$context = get_context_instance(CONTEXT_MODULE, $cm->id);
require_capability('mod/data:managetemplates', $context);
if (!isteacheredit($course->id)){
error(get_string('noaccess','data'));
}
/************************************
* Data Processing *
+1 -1
View File
@@ -1,4 +1,4 @@
<?php
<?php
///////////////////////////////////////////////////////////////////////////
// //
// NOTICE OF COPYRIGHT //
+2 -2
View File
@@ -56,7 +56,7 @@ if ($rid) {
require_course_login($course, true, $cm);
/// If it's hidden then it's don't show anything. :)
if (empty($cm->visible) and !isteacher($course->id)) {
if (empty($cm->visible) and !has_capability('moodle/course:viewhiddenactivities',get_context_instance(CONTEXT_MODULE, $cm->id))) {
$strdatabases = get_string("modulenameplural", "data");
$navigation = "<a href=\"index.php?id=$course->id\">$strdatabases</a> ->";
print_header_simple(format_string($data->name), "",
@@ -65,7 +65,7 @@ if (empty($cm->visible) and !isteacher($course->id)) {
}
/// If we have an empty Database then redirect because this page is useless without data
if (isteacher($course->id)) {
if (has_capability('mod/data:managetemplates', $context)) {
if (!record_exists('data_fields','dataid',$data->id)) { // Brand new database!
redirect($CFG->wwwroot.'/mod/data/field.php?d='.$data->id); // Redirect to field entry
}
+2 -9
View File
@@ -66,18 +66,11 @@
}
}
///checking for participants
// needs fixing?
/*
if ((!isteacher($course->id)) && $data->participants == DATA_TEACHERS_ONLY) {
error ('students are not allowed to participate in this activity');
}
if ($rid){ //editting a record, do you have access to edit this?
if (!isteacher($course->id) or !data_isowner($rid) or !confirm_sesskey()){
if (!has_capability('mod/data:manageentries', $context) or !data_isowner($rid) or !confirm_sesskey()){
error (get_string('noaccess','data'));
}
}*/
}
/// Print the page header
+1 -1
View File
@@ -74,7 +74,7 @@
}
$currentgroup = get_current_group($course->id);
if ($currentgroup and isteacheredit($course->id)) {
if ($currentgroup and has_capability('mod/data:manageentries', $context)) {
$group = get_record("groups", "id", $currentgroup);
$groupname = " ($group->name)";
} else {
+1 -2
View File
@@ -557,7 +557,6 @@ function data_add_record($data, $groupid=0){
$record->groupid = $groupid;
$record->timecreated = $record->timemodified = time();
if (has_capability('mod/data:approve', $context)) {
//if (isteacher($data->course)) {
$record->approved = 1;
} else {
$record->approved = 0;
@@ -857,7 +856,7 @@ function data_print_template($template, $records, $data, $search='',$page=0, $re
foreach ($fieldrecords as $fieldrecord) {
$fields[]= data_get_field($fieldrecord, $data);
}
$isteacher = isteacher($data->course);
$isteacher = has_capability('mod/data:managetemplates', $context);
}
if (empty($records)) {
+1 -4
View File
@@ -42,10 +42,7 @@ if ($id) {
require_login($course->id);
if (!isteacher($course->id)) {
error('Must be a teacher to Import Database');
}
require_capability('mod/data:managetemplates', get_context_instance(CONTEXT_MODULE, $cm->id))
/* get the list of standard presets found in /mod/data/preset */
$presets = array();
+1 -1
View File
@@ -40,7 +40,7 @@
echo "<th><a href=\"report.php?id=$id&amp;sort=firstname\">$strname</a>";
echo "<th width=\"100%\"><a href=\"report.php?id=$id&amp;sort=rating\">$strrating</a>";
foreach ($ratings as $rating) {
if (isteacher($data->course)) {
if (has_capability('mod/data:manageentries', $context)) {
echo '<tr class="forumpostheadertopic">';
} else {
echo '<tr class="forumpostheader">';
+2 -2
View File
@@ -504,7 +504,7 @@ function glossary_get_entries_search($concept, $courseid) {
//Check if the user is a teacher
$bypassteacher = 1; //This means NO (by default)
if (isteacher($courseid)) {
if (has_capability('mod/glossary:manageentries', get_context_instance(CONTEXT_COURSE, $courseid))) {
$bypassteacher = 0; //This means YES
}
@@ -947,7 +947,7 @@ function glossary_search($course, $searchterms, $extended = 0, $glossary = NULL)
$glos = $glossary->id;
}
if (!isteacher($glossary->course)) {
if (!has_capability('mod/glossary:manageentries', get_context_instance(CONTEXT_COURSE, $glossary->course))) {
$glossarymodule = get_record("modules", "name", "glossary");
$onlyvisible = " AND g.id = cm.instance AND cm.visible = 1 AND cm.module = $glossarymodule->id";
$onlyvisibletable = ", {$CFG->prefix}course_modules cm";
+1 -1
View File
@@ -18,7 +18,7 @@
if (!$cm = get_coursemodule_from_instance("glossary", $glossary->id)) {
error("Could not determine which course module this belonged to!");
}
if (!$cm->visible and !isteacher($cm->course)) {
if (!$cm->visible and !has_capability('moodle/course:viewhiddenactivities', get_context_instance(CONTEXT_MODULE, $cm->id))) {
redirect($CFG->wwwroot.'/course/view.php?id='.$cm->course, get_string('activityiscurrentlyhidden'));
}
$entry->cmid = $cm->id;
+2 -2
View File
@@ -119,7 +119,7 @@
$navigation = "<a href=\"../../course/view.php?id=$course->id\">$course->shortname</a> ->";
require_login($course->id);
}
if (!$cm->visible and !isteacher($course->id)) {
if (!$cm->visible and !has_capability('moodle/course:viewhiddenactivities', $context)) {
print_header();
notice(get_string("activityiscurrentlyhidden"));
}
@@ -252,7 +252,7 @@
/// the "Print" icon
$printicon = '';
if ( $isuserframe and $mode != 'search') {
if (isteacher($course->id) or $glossary->allowprintview) {
if (has_capability('mod/glossary:manageentries', $context) or $glossary->allowprintview) {
$printicon = " <a title =\"". get_string("printerfriendly","glossary") . "\" target=\"printview\" href=\"print.php?id=$cm->id&amp;mode=$mode&amp;hook=$hook&amp;sortkey=$sortkey&amp;sortorder=$sortorder&amp;offset=$offset\"><img border=\"0\" src=\"print.gif\" alt=\"\" /></a>";
}
}
+9 -6
View File
@@ -7,7 +7,8 @@
require_once("lib.php");
$id = required_param("id"); // course
$coursecontext = get_context_instance(CONTEXT_COURSE, $id);
if (! $course = get_record("course", "id", $id)) {
error("Course ID is incorrect");
}
@@ -240,7 +241,7 @@
MAX(a.score) AS maxscore
";
$select = "a.hotpot IN ($hotpotids)";
if (isteacher($course->id)) {
if (has_capability('mod/hotpot:viewreport', $coursecontext)) {
// do nothing (=get all users)
} else {
// restrict results to this user only
@@ -298,7 +299,7 @@
array_push($table->head, $title);
array_push($table->align, "center");
}
if (isteacheredit($course->id)) {
if (has_capability('moodle/course:manageactivities', $coursecontext)) {
array_push($table->head, $strupdate);
array_push($table->align, "center");
}
@@ -311,7 +312,7 @@
array_push($table->align,
"left", "left", "center", "left"
);
if (isadmin()) {
if (has_capability('mod/hotpot:grade', $coursecontext)) {
array_push($table->head, $strregrade);
array_push($table->align, "center");
}
@@ -350,9 +351,11 @@
$bestscore = "&nbsp;";
} else {
$cm = get_coursemodule_from_instance('hotpot', $hotpot->id);
// report number of attempts and users
$report = get_string("viewallreports","quiz", $totals[$hotpot->id]->attemptcount);
if (isteacher($course->id)) {
if (has_capability('mod/hotpot:viewreport', get_context_instance(CONTEXT_MODULE, $cm->id))) {
$report .= " (".$totals[$hotpot->id]->usercount." $strusers)";
}
$report = '<a href="report.php?hp='.$hotpot->id.'">'.$report.'</a>';
@@ -377,7 +380,7 @@
array_push($data, $printsection);
}
if (isteacheredit($course->id)) {
if (has_capability('moodle/course:manageactivities', $coursecontext)) {
$updatebutton = ''
. '<form target="'.$CFG->framename.'" method="get" action="'.$CFG->wwwroot.'/course/mod.php">'
. '<input type="hidden" name="update" value="'.$hotpot->coursemodule.'" />'
+3 -2
View File
@@ -707,7 +707,8 @@ function hotpot_get_all_instances_in_course($modulename, $course) {
if ($rawmods = get_records_sql($query)) {
// cache $isteacher setting
$isteacher = isteacher($course->id);
$isteacher = has_capability('mod/hotpot:viewreport', get_context_instance(CONTEXT_MODULE, $course->id));
$explodesection = array();
$order = array();
@@ -1018,7 +1019,7 @@ function hotpot_print_recent_mod_activity($activity, $course, $detail=false) {
$href = "$CFG->wwwroot/mod/hotpot/view.php?hp=$activity->instance";
print '<a href="'.$href.'">'.$activity->name.'</a> - ';
}
if (isteacher($course)) {
if (has_capability('mod/hotpot:viewreport',get_context_instance(CONTEXT_COURSE, $course))) {
// score (with link to attempt details)
$href = "$CFG->wwwroot/mod/hotpot/review.php?hp=$activity->instance&attempt=".$activity->content->attemptid;
print '<a href="'.$href.'">('.hotpot_format_score($activity->content).')</a> ';
+6 -5
View File
@@ -31,13 +31,14 @@
}
}
$context = get_context_instance(CONTEXT_MODULE, $cm->id);
// set homeurl of couse (for error messages)
$course_homeurl = "$CFG->wwwroot/course/view.php?id=$course->id";
require_login($course->id);
// get report mode
if (isteacher($course->id)) {
if (has_capability('mod/hotpot:viewreport',$context)) {
$mode = optional_param("mode", "overview");
} else {
// students have no choice
@@ -48,7 +49,7 @@
$formdata = array(
'mode' => $mode,
'reportcourse' => isadmin() ? optional_param('reportcourse', get_user_preferences('hotpot_reportcourse', 'this')) : 'this',
'reportusers' => isteacher($course->id) ? optional_param('reportusers', get_user_preferences('hotpot_reportusers', 'all')) : 'this',
'reportusers' => has_capability('mod/hotpot:viewreport',$context) ? optional_param('reportusers', get_user_preferences('hotpot_reportusers', 'all')) : 'this',
'reportattempts' => optional_param('reportattempts', get_user_preferences('hotpot_reportattempts', 'all')),
'reportformat' => optional_param('reportformat', 'htm'),
'reportshowlegend' => optional_param('reportshowlegend', get_user_preferences('hotpot_reportshowlegend', '0')),
@@ -67,13 +68,13 @@
// print page header. if required
if ($formdata['reportformat']=='htm') {
hotpot_print_report_heading($course, $cm, $hotpot, $mode);
if (isteacher($course->id)) {
if (has_capability('mod/hotpot:viewreport',$context)) {
hotpot_print_report_selector($course, $hotpot, $formdata);
}
}
// delete selected attempts, if any
if (isteacher($course->id)) {
if (has_capability('mod/hotpot:deleteattempt',$context)) {
$del = optional_param("del", "");
hotpot_delete_selected_attempts($hotpot, $del);
}
@@ -384,7 +385,7 @@ function hotpot_print_report_heading(&$course, &$cm, &$hotpot, &$mode) {
$navigation = "<a href=index.php?id=$course->id>$strmodulenameplural</a> -> ";
$navigation .= "<a href=\"view.php?id=$cm->id\">$hotpot->name</a> -> ";
if (isteacher($course->id)) {
if (has_capability('mod/hotpot:viewreport',$context)) {
if ($mode=='overview' || $mode=='simplestat' || $mode=='fullstat') {
$module = "quiz";
} else {
+1 -1
View File
@@ -53,7 +53,7 @@ class hotpot_report extends hotpot_default_report {
// set align and wrap
$this->set_align_and_wrap($table);
// is link to review allowed?
$allow_review = ($is_html && (isteacher($course->id) || $hotpot->review));
$allow_review = ($is_html && (has_capability('mod/hotpot:viewreport',get_context_instance(CONTEXT_COURSE, $course->id)) || $hotpot->review));
// initialize array of data values
$this->data = array();
// set exercise data values
+1 -1
View File
@@ -26,7 +26,7 @@ class hotpot_report extends hotpot_default_report {
$nobr_start = $is_html ? '<nobr>' : '';
$nobr_end = $is_html ? '</nobr>' : '';
// is review allowed? (do this once here, to save time later)
$allow_review = ($is_html && (isteacher($course->id) || $hotpot->review));
$allow_review = ($is_html && (has_capability('mod/hotpot:viewreport',get_context_instance(CONTEXT_COURSE, $course->id)) || $hotpot->review));
// assume penalties column is NOT required
$show_penalties = false;
// initialize $table
+3 -3
View File
@@ -82,11 +82,11 @@ class hotpot_report extends hotpot_default_report {
}
$attemptnumber = $attempt->attempt;
$starttime = trim(userdate($attempt->timestart, $strtimeformat));
if ($is_html && isset($attempt->score) && (isteacher($course->id) || $hotpot->review)) {
if ($is_html && isset($attempt->score) && (has_capability('mod/hotpot:viewreport',get_context_instance(CONTEXT_COURSE, $course->id)) || $hotpot->review)) {
$attemptnumber = '<a href="review.php?hp='.$hotpot->id.'&attempt='.$attempt->id.'">'.$attemptnumber.'</a>';
$starttime = '<a href="review.php?hp='.$hotpot->id.'&attempt='.$attempt->id.'">'.$starttime.'</a>';
}
if ($is_html && isteacher($course->id)) {
if ($is_html && has_capability('mod/hotpot:viewreport',get_context_instance(CONTEXT_COURSE, $course))) {
$checkbox = '<input type=checkbox name="box'.$attempt->clickreportid.'" value="'.$attempt->clickreportid.'">'.$spacer;
} else {
$checkbox = '';
@@ -111,7 +111,7 @@ class hotpot_report extends hotpot_default_report {
// remove final 'hr' from data rows
array_pop($table->data);
// add the "delete" form to the table
if ($options['reportformat']=='htm' && isteacher($course->id)) {
if ($options['reportformat']=='htm' && has_capability('mod/hotpot:viewreport',get_context_instance(CONTEXT_COURSE, $course->id))) {
$strdeletecheck = get_string('deleteattemptcheck','quiz');
$table->start = $this->deleteform_javascript();
$table->start .= '<form method="post" action="report.php" name="deleteform" onsubmit="'."return deletecheck('".$strdeletecheck."', 'selection')".'">'."\n";
+1 -1
View File
@@ -15,7 +15,7 @@ class hotpot_report extends hotpot_default_report {
$is_html = ($options['reportformat']=='htm');
$blank = ($download ? '' : '&nbsp;');
$no_value = ($download ? '' : '-');
$allow_review = true; // ($options['reportformat']=='htm' && (isteacher($course->id) || $hotpot->review));
$allow_review = true;
// start the table
unset($table);
$table->border = 1;
+5 -3
View File
@@ -29,8 +29,10 @@
if (! $attempt = get_record("hotpot_attempts", "id", $attempt)) {
error("Attempt ID was incorrect");
}
$context = get_context_instance(CONTEXT_MODULE, $cm->id);
require_login($course->id);
if (!isteacher($course->id)) {
if (!has_capability('mod/hotpot:viewreport',$context)) {
if (!$hotpot->review) {
error(get_string("noreview", "quiz"));
}
@@ -58,7 +60,7 @@
print_heading($hotpot->name);
hotpot_print_attempt_summary($hotpot, $attempt);
hotpot_print_review_buttons($course, $hotpot, $attempt);
$action = isteacher($course->id) ? optional_param('action') : '';
$action = has_capability('mod/hotpot:viewreport',$context) ? optional_param('action') : '';
if ($action) {
$xml = get_field('hotpot_details', 'details', 'attempt', $attempt->id);
print '<hr>';
@@ -130,7 +132,7 @@ function hotpot_print_review_buttons(&$course, &$hotpot, &$attempt) {
print "\n".'<table border="0" align="center" cellpadding="2" cellspacing="2" class="generaltable">';
print "\n<tr>\n".'<td align="center">';
print_single_button("report.php?hp=$hotpot->id", NULL, get_string('continue'), 'post');
if (isteacher($course->id) && record_exists('hotpot_details', 'attempt', $attempt->id)) {
if (has_capability('mod/hotpot:viewreport',$context) && record_exists('hotpot_details', 'attempt', $attempt->id)) {
print "</td>\n".'<td align="center">';
print_single_button("review.php?hp=$hotpot->id&attempt=$attempt->id&action=showxmlsource", NULL, get_string('showxmlsource', 'hotpot'), 'post');
print "</td>\n".'<td align="center">';
+1 -1
View File
@@ -9,7 +9,7 @@
$params->course = required_param('course');
$params->reference = required_param('reference');
require_login($params->course);
if (!isteacher($params->course)) {
if (!has_capability('mod/hotpot:viewreport',get_context_instance(CONTEXT_COURSE, $params->course))) {
error("You are not allowed to view this page!");
}
if (isadmin()) {
+3 -1
View File
@@ -32,8 +32,10 @@
if (! $cm = get_coursemodule_from_instance("hotpot", $hotpot->id, $course->id)) {
error("Course Module ID was incorrect");
}
}
require_login($course->id);
$context = get_context_instance(CONTEXT_MODULE, $cm->id);
}
// set nextpage (for error messages)
$nextpage = "$CFG->wwwroot/course/view.php?id=$course->id";
@@ -49,7 +51,7 @@
$loggedinas = '<span class="logininfo">'.user_login_string($course, $USER).'</span>';
$time = time();
$hppassword = optional_param('hppassword');
if (HOTPOT_FIRST_ATTEMPT && !isteacher($course->id)) {
if (HOTPOT_FIRST_ATTEMPT && !has_capability('mod/hotpot:grade', $context)) {
// check this quiz is available to this student
// error message, if quiz is unavailable
$error = '';
+1 -3
View File
@@ -10,9 +10,7 @@
require_login($course->id, false);
if (!isteacher($course->id)) {
error("You can't modify this course!");
}
require_capability('moodle/course:manageactivities', get_context_instance(CONTEXT_COURSE, $course->id));
$streditingasurvey = get_string("editingasurvey", "survey");
$strsurveys = get_string("modulenameplural", "survey");
+1 -4
View File
@@ -17,10 +17,7 @@
}
require_login($course->id, false);
if (!isteacher($course->id)) {
error("Sorry, only teachers can see this.");
}
require_capability('mod/survey:download', get_context_instance(CONTEXT_MODULE, $cm->id)) ;
if (! $survey = get_record("survey", "id", $cm->instance)) {
error("Survey ID was incorrect");
+2 -1
View File
@@ -21,8 +21,9 @@
require_login($course->id, false, $cm);
$groupmode = groupmode($course, $cm); // Groups are being used
$context = get_context_instance(CONTEXT_MODULE, $cm->id);
if (!isteacher($course->id)) {
if (!has_capability('mod/survey:readresponses', $context)) {
if ($type != "student.png" or $sid != $USER->id ) {
error("Sorry, you aren't allowed to see this.");
} else if ($groupmode and !ismember($group)) {