acl_and_auth.go 22 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "strconv"
  6. "strings"
  7. "time"
  8. )
  9. func List_acl(func_type string) []string {
  10. if func_type == "user_document" {
  11. return []string{
  12. "",
  13. "user",
  14. "all",
  15. }
  16. } else {
  17. return []string{
  18. "",
  19. "all",
  20. "user",
  21. "admin",
  22. "owner",
  23. "50_edit",
  24. "email",
  25. "ban",
  26. "before",
  27. "30_day",
  28. "90_day",
  29. "ban_admin",
  30. "not_all",
  31. "up_to_level_3",
  32. "up_to_level_10",
  33. "30_day_50_edit",
  34. }
  35. }
  36. }
  37. func Do_insert_auth_history(db *sql.DB, ip string, what string) {
  38. var log_off string
  39. err := db.QueryRow(DB_change("select data from other where name = 'auth_history_off'")).Scan(&log_off)
  40. if err != nil {
  41. if err == sql.ErrNoRows {
  42. log_off = ""
  43. } else {
  44. log.Fatal(err)
  45. }
  46. }
  47. if log_off == "" {
  48. stmt, err := db.Prepare(DB_change("insert into re_admin (who, what, time) values (?, ?, ?)"))
  49. if err != nil {
  50. log.Fatal(err)
  51. }
  52. defer stmt.Close()
  53. time := Get_time()
  54. _, err = stmt.Exec(ip, what, time)
  55. if err != nil {
  56. log.Fatal(err)
  57. }
  58. }
  59. }
  60. func Get_user_auth(db *sql.DB, ip string) string {
  61. if !IP_or_user(ip) {
  62. var auth string
  63. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  64. if err != nil {
  65. log.Fatal(err)
  66. }
  67. defer stmt.Close()
  68. err = stmt.QueryRow(ip).Scan(&auth)
  69. if err != nil {
  70. if err == sql.ErrNoRows {
  71. auth = "user"
  72. } else {
  73. log.Fatal(err)
  74. }
  75. }
  76. if auth != "user" && auth != "ban" {
  77. return auth
  78. } else {
  79. return ""
  80. }
  81. }
  82. return ""
  83. }
  84. func Get_auth_group_info(db *sql.DB, auth string) map[string]bool {
  85. stmt, err := db.Prepare(DB_change("select acl from alist where name = ?"))
  86. if err != nil {
  87. log.Fatal(err)
  88. }
  89. defer stmt.Close()
  90. rows, err := stmt.Query(auth)
  91. if err != nil {
  92. log.Fatal(err)
  93. }
  94. defer rows.Close()
  95. data_list := map[string]bool{}
  96. for rows.Next() {
  97. var name string
  98. err := rows.Scan(&name)
  99. if err != nil {
  100. log.Fatal(err)
  101. }
  102. data_list[name] = true
  103. }
  104. return Check_auth(data_list)
  105. }
  106. func Check_auth(auth_info map[string]bool) map[string]bool {
  107. if _, ok := auth_info["owner"]; ok {
  108. auth_info["admin"] = true
  109. }
  110. admin_auth := []string{"ban", "toron", "check", "acl", "hidel", "give", "bbs"}
  111. if _, ok := auth_info["admin"]; ok {
  112. for _, v := range admin_auth {
  113. auth_info[v] = true
  114. }
  115. }
  116. check := false
  117. for _, v := range admin_auth {
  118. if _, ok := auth_info[v]; ok {
  119. check = true
  120. break
  121. }
  122. }
  123. if check {
  124. auth_info["admin_default_feature"] = true
  125. }
  126. admin_default_feature := []string{"treat_as_admin", "user_name_bold", "multiple_upload", "slow_edit_pass", "edit_bottom_compulsion_pass"}
  127. if _, ok := auth_info["admin_default_feature"]; ok {
  128. for _, v := range admin_default_feature {
  129. auth_info[v] = true
  130. }
  131. auth_info["user"] = true
  132. }
  133. return auth_info
  134. }
  135. func Check_acl(db *sql.DB, name string, topic_number string, tool string, ip string) bool {
  136. auth_name := Get_user_auth(db, ip)
  137. auth_info := Get_auth_group_info(db, auth_name)
  138. ip_or_user := IP_or_user(ip)
  139. level := "0"
  140. if !ip_or_user {
  141. level = Get_level(db, ip)[0]
  142. }
  143. level_int, _ := strconv.Atoi(level)
  144. get_ban := ""
  145. ban_type := ""
  146. if tool == "document_edit_request" {
  147. temp_arr := Get_user_ban(db, ip, "edit_request")
  148. get_ban = temp_arr[0]
  149. ban_type = temp_arr[1]
  150. } else {
  151. temp_arr := Get_user_ban(db, ip, "")
  152. get_ban = temp_arr[0]
  153. ban_type = temp_arr[1]
  154. }
  155. if ban_type != "" {
  156. ban_type_len := len(ban_type)
  157. if ban_type_len == 1 {
  158. ban_type = string(ban_type[0])
  159. } else if ban_type_len == 2 {
  160. ban_type = string(ban_type[1])
  161. }
  162. }
  163. if tool == "" && name != "" {
  164. if !Check_acl(db, name, "", "render", ip) {
  165. return false
  166. }
  167. if strings.HasPrefix(name, "user:") {
  168. user_page_str := name[5:]
  169. if slash_index := strings.Index(user_page_str, "/"); slash_index != -1 {
  170. user_page_str = user_page_str[:slash_index]
  171. }
  172. if auth_info["acl"] {
  173. return true
  174. }
  175. if get_ban == "true" {
  176. return false
  177. }
  178. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  179. if err != nil {
  180. log.Fatal(err)
  181. }
  182. defer stmt.Close()
  183. var acl_data string
  184. err = stmt.QueryRow(name).Scan(&acl_data)
  185. if err != nil {
  186. if err == sql.ErrNoRows {
  187. acl_data = ""
  188. } else {
  189. log.Fatal(err)
  190. }
  191. }
  192. if acl_data == "all" {
  193. return true
  194. } else if acl_data == "user" {
  195. if !ip_or_user {
  196. return true
  197. }
  198. } else if ip == user_page_str {
  199. if !ip_or_user {
  200. return true
  201. }
  202. }
  203. return false
  204. }
  205. }
  206. if Arr_in_str([]string{"document_edit", "document_edit_request", "document_move", "document_delete"}, tool) {
  207. if !Check_acl(db, name, topic_number, "", ip) {
  208. return false
  209. }
  210. } else if Arr_in_str([]string{"bbs_edit", "bbs_comment"}, tool) {
  211. if !Check_acl(db, name, topic_number, "bbs_view", ip) {
  212. return false
  213. }
  214. }
  215. if tool == "topic" {
  216. if name == "" {
  217. stmt, err := db.Prepare(DB_change("select title from rd where code = ?"))
  218. if err != nil {
  219. log.Fatal(err)
  220. }
  221. defer stmt.Close()
  222. err = stmt.QueryRow(topic_number).Scan(&name)
  223. if err != nil {
  224. if err == sql.ErrNoRows {
  225. name = "test"
  226. } else {
  227. log.Fatal(err)
  228. }
  229. }
  230. }
  231. }
  232. end_number := 1
  233. for for_a := 0; for_a < end_number; for_a++ {
  234. acl_data := ""
  235. acl_pass_auth := ""
  236. if tool == "" {
  237. acl_pass_auth = "acl"
  238. if for_a == 0 {
  239. end_number += 1
  240. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  241. if err != nil {
  242. log.Fatal(err)
  243. }
  244. defer stmt.Close()
  245. err = stmt.QueryRow(name).Scan(&acl_data)
  246. if err != nil {
  247. if err == sql.ErrNoRows {
  248. acl_data = ""
  249. } else {
  250. log.Fatal(err)
  251. }
  252. }
  253. } else {
  254. err := db.QueryRow(DB_change("select data from other where name = 'edit'")).Scan(&acl_data)
  255. if err != nil {
  256. if err == sql.ErrNoRows {
  257. acl_data = ""
  258. } else {
  259. log.Fatal(err)
  260. }
  261. }
  262. }
  263. } else if tool == "document_move" {
  264. acl_pass_auth = "acl"
  265. if for_a == 0 {
  266. end_number += 1
  267. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_move_acl'"))
  268. if err != nil {
  269. log.Fatal(err)
  270. }
  271. defer stmt.Close()
  272. err = stmt.QueryRow(name).Scan(&acl_data)
  273. if err != nil {
  274. if err == sql.ErrNoRows {
  275. acl_data = ""
  276. } else {
  277. log.Fatal(err)
  278. }
  279. }
  280. } else {
  281. err := db.QueryRow(DB_change("select data from other where name = 'document_move_acl'")).Scan(&acl_data)
  282. if err != nil {
  283. if err == sql.ErrNoRows {
  284. acl_data = ""
  285. } else {
  286. log.Fatal(err)
  287. }
  288. }
  289. }
  290. } else if tool == "document_edit" {
  291. acl_pass_auth = "acl"
  292. if for_a == 0 {
  293. end_number += 1
  294. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_acl'"))
  295. if err != nil {
  296. log.Fatal(err)
  297. }
  298. defer stmt.Close()
  299. err = stmt.QueryRow(name).Scan(&acl_data)
  300. if err != nil {
  301. if err == sql.ErrNoRows {
  302. acl_data = ""
  303. } else {
  304. log.Fatal(err)
  305. }
  306. }
  307. } else {
  308. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_acl'")).Scan(&acl_data)
  309. if err != nil {
  310. if err == sql.ErrNoRows {
  311. acl_data = ""
  312. } else {
  313. log.Fatal(err)
  314. }
  315. }
  316. }
  317. } else if tool == "document_edit" {
  318. acl_pass_auth = "acl"
  319. if for_a == 0 {
  320. end_number += 1
  321. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_delete_acl'"))
  322. if err != nil {
  323. log.Fatal(err)
  324. }
  325. defer stmt.Close()
  326. err = stmt.QueryRow(name).Scan(&acl_data)
  327. if err != nil {
  328. if err == sql.ErrNoRows {
  329. acl_data = ""
  330. } else {
  331. log.Fatal(err)
  332. }
  333. }
  334. } else {
  335. err := db.QueryRow(DB_change("select data from other where name = 'document_delete_acl'")).Scan(&acl_data)
  336. if err != nil {
  337. if err == sql.ErrNoRows {
  338. acl_data = ""
  339. } else {
  340. log.Fatal(err)
  341. }
  342. }
  343. }
  344. } else if tool == "topic" {
  345. acl_pass_auth = "topic"
  346. if for_a == 0 {
  347. end_number += 1
  348. stmt, err := db.Prepare(DB_change("select acl from rd where code = ?"))
  349. if err != nil {
  350. log.Fatal(err)
  351. }
  352. defer stmt.Close()
  353. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  354. if err != nil {
  355. if err == sql.ErrNoRows {
  356. acl_data = ""
  357. } else {
  358. log.Fatal(err)
  359. }
  360. }
  361. } else if for_a == 1 {
  362. end_number += 1
  363. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'dis'"))
  364. if err != nil {
  365. log.Fatal(err)
  366. }
  367. defer stmt.Close()
  368. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  369. if err != nil {
  370. if err == sql.ErrNoRows {
  371. acl_data = ""
  372. } else {
  373. log.Fatal(err)
  374. }
  375. }
  376. } else {
  377. err := db.QueryRow(DB_change("select data from other where name = 'discussion'")).Scan(&acl_data)
  378. if err != nil {
  379. if err == sql.ErrNoRows {
  380. acl_data = ""
  381. } else {
  382. log.Fatal(err)
  383. }
  384. }
  385. }
  386. } else if tool == "topic_view" {
  387. acl_pass_auth = "topic"
  388. stmt, err := db.Prepare(DB_change("select set_data from topic_set where thread_code = ? and set_name = 'thread_view_acl'"))
  389. if err != nil {
  390. log.Fatal(err)
  391. }
  392. defer stmt.Close()
  393. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  394. if err != nil {
  395. if err == sql.ErrNoRows {
  396. acl_data = ""
  397. } else {
  398. log.Fatal(err)
  399. }
  400. }
  401. } else if tool == "upload" {
  402. acl_pass_auth = "multiple_upload"
  403. err := db.QueryRow(DB_change("select data from other where name = 'upload_acl'")).Scan(&acl_data)
  404. if err != nil {
  405. if err == sql.ErrNoRows {
  406. acl_data = ""
  407. } else {
  408. log.Fatal(err)
  409. }
  410. }
  411. } else if tool == "many_upload" {
  412. acl_pass_auth = "multiple_upload"
  413. err := db.QueryRow(DB_change("select data from other where name = 'many_upload_acl'")).Scan(&acl_data)
  414. if err != nil {
  415. if err == sql.ErrNoRows {
  416. acl_data = ""
  417. } else {
  418. log.Fatal(err)
  419. }
  420. }
  421. } else if tool == "vote" {
  422. acl_pass_auth = "owner"
  423. if for_a == 0 {
  424. end_number += 1
  425. if topic_number != "" {
  426. stmt, err := db.Prepare(DB_change("select acl from vote where id = ? and user = ''"))
  427. if err != nil {
  428. log.Fatal(err)
  429. }
  430. defer stmt.Close()
  431. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  432. if err != nil {
  433. if err == sql.ErrNoRows {
  434. acl_data = ""
  435. } else {
  436. log.Fatal(err)
  437. }
  438. }
  439. } else {
  440. continue
  441. }
  442. } else {
  443. err := db.QueryRow(DB_change("select data from other where name = 'vote_acl'")).Scan(&acl_data)
  444. if err != nil {
  445. if err == sql.ErrNoRows {
  446. acl_data = ""
  447. } else {
  448. log.Fatal(err)
  449. }
  450. }
  451. }
  452. } else if tool == "slow_edit" {
  453. acl_pass_auth = "slow_edit_pass"
  454. err := db.QueryRow(DB_change("select data from other where name = 'slow_edit_acl'")).Scan(&acl_data)
  455. if err != nil {
  456. if err == sql.ErrNoRows {
  457. acl_data = ""
  458. } else {
  459. log.Fatal(err)
  460. }
  461. }
  462. } else if tool == "edit_bottom_compulsion" {
  463. acl_pass_auth = "edit_bottom_compulsion_pass"
  464. err := db.QueryRow(DB_change("select data from other where name = 'edit_bottom_compulsion_acl'")).Scan(&acl_data)
  465. if err != nil {
  466. if err == sql.ErrNoRows {
  467. acl_data = ""
  468. } else {
  469. log.Fatal(err)
  470. }
  471. }
  472. } else if tool == "bbs_edit" {
  473. acl_pass_auth = "bbs"
  474. if for_a == 0 {
  475. end_number += 1
  476. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl' and set_id = ?"))
  477. if err != nil {
  478. log.Fatal(err)
  479. }
  480. defer stmt.Close()
  481. err = stmt.QueryRow(name).Scan(&acl_data)
  482. if err != nil {
  483. if err == sql.ErrNoRows {
  484. acl_data = ""
  485. } else {
  486. log.Fatal(err)
  487. }
  488. }
  489. } else if for_a == 1 {
  490. end_number += 1
  491. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  492. if err != nil {
  493. log.Fatal(err)
  494. }
  495. defer stmt.Close()
  496. err = stmt.QueryRow(name).Scan(&acl_data)
  497. if err != nil {
  498. if err == sql.ErrNoRows {
  499. acl_data = ""
  500. } else {
  501. log.Fatal(err)
  502. }
  503. }
  504. } else if for_a == 2 {
  505. end_number += 1
  506. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl_all'")).Scan(&acl_data)
  507. if err != nil {
  508. if err == sql.ErrNoRows {
  509. acl_data = ""
  510. } else {
  511. log.Fatal(err)
  512. }
  513. }
  514. } else {
  515. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  516. if err != nil {
  517. if err == sql.ErrNoRows {
  518. acl_data = ""
  519. } else {
  520. log.Fatal(err)
  521. }
  522. }
  523. }
  524. } else if tool == "bbs_comment" {
  525. acl_pass_auth = "bbs"
  526. if for_a == 0 {
  527. end_number += 1
  528. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl' and set_id = ?"))
  529. if err != nil {
  530. log.Fatal(err)
  531. }
  532. defer stmt.Close()
  533. err = stmt.QueryRow(name).Scan(&acl_data)
  534. if err != nil {
  535. if err == sql.ErrNoRows {
  536. acl_data = ""
  537. } else {
  538. log.Fatal(err)
  539. }
  540. }
  541. } else if for_a == 1 {
  542. end_number += 1
  543. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  544. if err != nil {
  545. log.Fatal(err)
  546. }
  547. defer stmt.Close()
  548. err = stmt.QueryRow(name).Scan(&acl_data)
  549. if err != nil {
  550. if err == sql.ErrNoRows {
  551. acl_data = ""
  552. } else {
  553. log.Fatal(err)
  554. }
  555. }
  556. } else if for_a == 2 {
  557. end_number += 1
  558. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl_all'")).Scan(&acl_data)
  559. if err != nil {
  560. if err == sql.ErrNoRows {
  561. acl_data = ""
  562. } else {
  563. log.Fatal(err)
  564. }
  565. }
  566. } else {
  567. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  568. if err != nil {
  569. if err == sql.ErrNoRows {
  570. acl_data = ""
  571. } else {
  572. log.Fatal(err)
  573. }
  574. }
  575. }
  576. } else if tool == "bbs_view" {
  577. acl_pass_auth = "bbs"
  578. if for_a == 0 {
  579. end_number += 1
  580. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl' and set_id = ?"))
  581. if err != nil {
  582. log.Fatal(err)
  583. }
  584. defer stmt.Close()
  585. err = stmt.QueryRow(name).Scan(&acl_data)
  586. if err != nil {
  587. if err == sql.ErrNoRows {
  588. acl_data = ""
  589. } else {
  590. log.Fatal(err)
  591. }
  592. }
  593. } else {
  594. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl_all'")).Scan(&acl_data)
  595. if err != nil {
  596. if err == sql.ErrNoRows {
  597. acl_data = ""
  598. } else {
  599. log.Fatal(err)
  600. }
  601. }
  602. }
  603. } else if tool == "recaptcha" {
  604. acl_pass_auth = "admin_default_feature"
  605. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_pass_acl'")).Scan(&acl_data)
  606. if err != nil {
  607. if err == sql.ErrNoRows {
  608. acl_data = ""
  609. } else {
  610. log.Fatal(err)
  611. }
  612. }
  613. } else if tool == "recaptcha_five_pass" {
  614. acl_pass_auth = "admin_default_feature"
  615. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_one_check_five_pass_acl'")).Scan(&acl_data)
  616. if err != nil {
  617. if err == sql.ErrNoRows {
  618. acl_data = ""
  619. } else {
  620. log.Fatal(err)
  621. }
  622. }
  623. } else if tool == "document_edit_request" {
  624. acl_pass_auth = "acl"
  625. if for_a == 0 {
  626. end_number += 1
  627. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_request_acl'"))
  628. if err != nil {
  629. log.Fatal(err)
  630. }
  631. defer stmt.Close()
  632. err = stmt.QueryRow(name).Scan(&acl_data)
  633. if err != nil {
  634. if err == sql.ErrNoRows {
  635. acl_data = ""
  636. } else {
  637. log.Fatal(err)
  638. }
  639. }
  640. } else {
  641. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_request_acl'")).Scan(&acl_data)
  642. if err != nil {
  643. if err == sql.ErrNoRows {
  644. acl_data = ""
  645. } else {
  646. log.Fatal(err)
  647. }
  648. }
  649. }
  650. } else if tool == "document_make_acl" {
  651. acl_pass_auth = "acl"
  652. err := db.QueryRow(DB_change("select data from other where name = 'document_make_acl'")).Scan(&acl_data)
  653. if err != nil {
  654. if err == sql.ErrNoRows {
  655. acl_data = ""
  656. } else {
  657. log.Fatal(err)
  658. }
  659. }
  660. } else {
  661. // tool == "render"
  662. acl_pass_auth = "acl"
  663. if for_a == 0 {
  664. end_number += 1
  665. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'view'"))
  666. if err != nil {
  667. log.Fatal(err)
  668. }
  669. defer stmt.Close()
  670. err = stmt.QueryRow(name).Scan(&acl_data)
  671. if err != nil {
  672. if err == sql.ErrNoRows {
  673. acl_data = ""
  674. } else {
  675. log.Fatal(err)
  676. }
  677. }
  678. } else {
  679. err := db.QueryRow(DB_change("select data from other where name = 'all_view_acl'")).Scan(&acl_data)
  680. if err != nil {
  681. if err == sql.ErrNoRows {
  682. acl_data = ""
  683. } else {
  684. log.Fatal(err)
  685. }
  686. }
  687. }
  688. }
  689. if auth_info[acl_pass_auth] {
  690. return true
  691. } else if ban_type == "4" {
  692. return false
  693. }
  694. if acl_data == "" {
  695. if tool == "recaptcha" {
  696. acl_data = "admin"
  697. } else if tool == "slow_edit" || tool == "edit_bottom_compulsion" {
  698. acl_data = "not_all"
  699. } else {
  700. acl_data = "normal"
  701. }
  702. }
  703. except_ban_tool_list := []string{"render", "topic_view", "bbs_view"}
  704. if acl_data != "normal" {
  705. if !(acl_data == "ban" || acl_data == "ban_admin") || ban_type == "3" {
  706. if !Arr_in_str(except_ban_tool_list, tool) {
  707. if get_ban == "true" {
  708. return false
  709. }
  710. }
  711. }
  712. if acl_data == "all" || acl_data == "ban" {
  713. return true
  714. } else if acl_data == "user" {
  715. if !ip_or_user {
  716. return true
  717. }
  718. } else if acl_data == "admin" {
  719. if auth_info["treat_as_admin"] {
  720. return true
  721. }
  722. } else if acl_data == "50_edit" {
  723. if !ip_or_user {
  724. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  725. if err != nil {
  726. log.Fatal(err)
  727. }
  728. defer stmt.Close()
  729. var count int
  730. err = stmt.QueryRow(ip).Scan(&count)
  731. if err != nil {
  732. if err == sql.ErrNoRows {
  733. count = 0
  734. } else {
  735. log.Fatal(err)
  736. }
  737. }
  738. if count >= 50 {
  739. return true
  740. }
  741. }
  742. } else if acl_data == "before" {
  743. stmt, err := db.Prepare(DB_change("select ip from history where title = ? and ip = ?"))
  744. if err != nil {
  745. log.Fatal(err)
  746. }
  747. defer stmt.Close()
  748. var exist string
  749. err = stmt.QueryRow(name, ip).Scan(&exist)
  750. if err != nil {
  751. if err == sql.ErrNoRows {
  752. exist = ""
  753. } else {
  754. log.Fatal(err)
  755. }
  756. }
  757. if exist != "" {
  758. return true
  759. }
  760. } else if acl_data == "30_day" || acl_data == "90_day" {
  761. if !ip_or_user {
  762. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  763. if err != nil {
  764. log.Fatal(err)
  765. }
  766. defer stmt.Close()
  767. var signup_date string
  768. err = stmt.QueryRow(ip).Scan(&signup_date)
  769. if err != nil {
  770. if err == sql.ErrNoRows {
  771. signup_date = Get_time()
  772. } else {
  773. log.Fatal(err)
  774. }
  775. }
  776. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  777. if acl_data == "30_day" {
  778. time_1 = time_1.AddDate(0, 0, 30)
  779. } else {
  780. time_1 = time_1.AddDate(0, 0, 90)
  781. }
  782. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  783. if time_2.After(time_1) {
  784. return true
  785. }
  786. }
  787. } else if acl_data == "email" {
  788. if !ip_or_user {
  789. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'email'"))
  790. if err != nil {
  791. log.Fatal(err)
  792. }
  793. defer stmt.Close()
  794. var exist string
  795. err = stmt.QueryRow(ip).Scan(&exist)
  796. if err != nil {
  797. if err == sql.ErrNoRows {
  798. exist = ""
  799. } else {
  800. log.Fatal(err)
  801. }
  802. }
  803. if exist != "" {
  804. return true
  805. }
  806. }
  807. } else if acl_data == "owner" {
  808. if auth_info["owner"] {
  809. return true
  810. }
  811. } else if acl_data == "ban_admin" {
  812. if auth_info["treat_as_admin"] || get_ban == "true" {
  813. return true
  814. }
  815. } else if acl_data == "not_all" {
  816. return false
  817. } else if acl_data == "up_to_level_3" || acl_data == "up_to_level_10" {
  818. if acl_data == "up_to_level_3" {
  819. if level_int >= 3 {
  820. return true
  821. }
  822. } else if acl_data == "up_to_level_10" {
  823. if level_int >= 10 {
  824. return true
  825. }
  826. }
  827. } else if acl_data == "30_day_50_edit" {
  828. if !ip_or_user {
  829. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  830. if err != nil {
  831. log.Fatal(err)
  832. }
  833. defer stmt.Close()
  834. var signup_date string
  835. err = stmt.QueryRow(ip).Scan(&signup_date)
  836. if err != nil {
  837. if err == sql.ErrNoRows {
  838. signup_date = Get_time()
  839. } else {
  840. log.Fatal(err)
  841. }
  842. }
  843. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  844. time_1 = time_1.AddDate(0, 0, 30)
  845. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  846. if time_2.After(time_1) {
  847. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  848. if err != nil {
  849. log.Fatal(err)
  850. }
  851. defer stmt.Close()
  852. var count int
  853. err = stmt.QueryRow(ip).Scan(&count)
  854. if err != nil {
  855. if err == sql.ErrNoRows {
  856. count = 0
  857. } else {
  858. log.Fatal(err)
  859. }
  860. }
  861. if count >= 50 {
  862. return true
  863. }
  864. }
  865. }
  866. }
  867. return false
  868. } else if for_a == end_number-1 {
  869. if !Arr_in_str(except_ban_tool_list, tool) {
  870. if get_ban == "true" {
  871. return false
  872. }
  873. }
  874. if tool == "topic" {
  875. stmt, err := db.Prepare(DB_change("select title from rd where code = ? and stop != ''"))
  876. if err != nil {
  877. log.Fatal(err)
  878. }
  879. defer stmt.Close()
  880. var topic_state string
  881. err = stmt.QueryRow(topic_number).Scan(&topic_state)
  882. if err != nil {
  883. if err == sql.ErrNoRows {
  884. topic_state = ""
  885. } else {
  886. log.Fatal(err)
  887. }
  888. }
  889. if topic_state != "" {
  890. if auth_info["topic"] {
  891. return true
  892. } else {
  893. return false
  894. }
  895. } else {
  896. return true
  897. }
  898. } else {
  899. return true
  900. }
  901. }
  902. }
  903. return false
  904. }