block contexts: MDL-19098 every block should have a context

even non-course and sticky blocks.

The parent context is block_instances.parentcontextid.

The block context should be used for checking permissions directly
related to the block, like moodle/block:view or moodle/site:manageblocks.

However, if the block is displaying information about the current page,
for example the participants block showing who 'here', then it may be
better to use the context of the page where the bloack is appearing -
in other words $this->page->context - to check permissions about the
user's ability to see participants here.

Or, if the block is displaying something stronly related to courses,
for example, a course meny block, the block should probably use the
context for $this->page->course to check permissions.
This commit is contained in:
tjhunt
2009-07-13 08:37:34 +00:00
parent dc203659af
commit e92c286c20
19 changed files with 223 additions and 214 deletions
+12 -5
View File
@@ -407,6 +407,7 @@ class block_manager {
'contextid1' => $context->id,
'contextid2' => $context->id,
'pagetype' => $this->page->pagetype,
'contextblock' => CONTEXT_BLOCK,
);
$sql = "SELECT
bi.id,
@@ -419,7 +420,11 @@ class block_manager {
COALESCE(bp.visible, 1) AS visible,
COALESCE(bp.region, bi.defaultregion) AS region,
COALESCE(bp.weight, bi.defaultweight) AS weight,
bi.configdata
bi.configdata,
ctx.id AS ctxid,
ctx.path AS ctxpath,
ctx.depth AS ctxdepth,
ctx.contextlevel AS ctxlevel
FROM {block_instances} bi
JOIN {block} b ON bi.blockname = b.name
@@ -427,6 +432,8 @@ class block_manager {
AND bp.contextid = :contextid1
AND bp.pagetype = :pagetype
AND bp.subpage = :subpage1
JOIN {context} ctx ON ctx.contextlevel = :contextblock
AND ctx.instanceid = bi.id
WHERE
$contexttest
@@ -444,6 +451,7 @@ class block_manager {
$this->birecordsbyregion = $this->prepare_per_region_arrays();
$unknown = array();
foreach ($blockinstances as $bi) {
$bi = make_context_subobj($bi);
if ($this->is_known_region($bi->region)) {
$this->birecordsbyregion[$bi->region][] = $bi;
} else {
@@ -491,12 +499,11 @@ class block_manager {
$blockinstance->configdata = '';
$blockinstance->id = $DB->insert_record('block_instances', $blockinstance);
if ($this->page->context->contextlevel == CONTEXT_COURSE) {
get_context_instance(CONTEXT_BLOCK, $blockinstance->id);
}
// Ensure the block context is created.
get_context_instance(CONTEXT_BLOCK, $blockinstance->id);
// If the new instance was created, allow it to do additional setup
if($block = block_instance($blockname, $blockinstance)) {
if ($block = block_instance($blockname, $blockinstance)) {
$block->instance_create();
}
}