acl_and_auth.go 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "strconv"
  6. "strings"
  7. "time"
  8. )
  9. func List_acl(func_type string) []string {
  10. if func_type == "user_document" {
  11. return []string{
  12. "",
  13. "user",
  14. "all",
  15. }
  16. } else {
  17. return []string{
  18. "",
  19. "all",
  20. "user",
  21. "admin",
  22. "owner",
  23. "50_edit",
  24. "email",
  25. "ban",
  26. "before",
  27. "30_day",
  28. "90_day",
  29. "ban_admin",
  30. "not_all",
  31. "up_to_level_3",
  32. "up_to_level_10",
  33. "30_day_50_edit",
  34. }
  35. }
  36. }
  37. func Get_user_auth(db *sql.DB, ip string) string {
  38. if !IP_or_user(ip) {
  39. var auth string
  40. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  41. if err != nil {
  42. log.Fatal(err)
  43. }
  44. defer stmt.Close()
  45. err = stmt.QueryRow(ip).Scan(&auth)
  46. if err != nil {
  47. if err == sql.ErrNoRows {
  48. auth = "user"
  49. } else {
  50. log.Fatal(err)
  51. }
  52. }
  53. if auth != "user" && auth != "ban" {
  54. return auth
  55. } else {
  56. return ""
  57. }
  58. }
  59. return ""
  60. }
  61. func Get_auth_group_info(db *sql.DB, auth string) map[string]bool {
  62. stmt, err := db.Prepare(DB_change("select name from alist where name = ?"))
  63. if err != nil {
  64. log.Fatal(err)
  65. }
  66. defer stmt.Close()
  67. rows, err := stmt.Query(auth)
  68. if err != nil {
  69. log.Fatal(err)
  70. }
  71. defer rows.Close()
  72. data_list := map[string]bool{}
  73. for rows.Next() {
  74. var name string
  75. err := rows.Scan(&name)
  76. if err != nil {
  77. log.Fatal(err)
  78. }
  79. data_list[name] = true
  80. }
  81. return Check_auth(data_list)
  82. }
  83. func Check_auth(auth_info map[string]bool) map[string]bool {
  84. if _, ok := auth_info["owner"]; ok {
  85. auth_info["admin"] = true
  86. }
  87. admin_auth := []string{"ban", "toron", "check", "acl", "hidel", "give", "bbs"}
  88. if _, ok := auth_info["admin"]; ok {
  89. for _, v := range admin_auth {
  90. auth_info[v] = true
  91. }
  92. }
  93. check := false
  94. for _, v := range admin_auth {
  95. if _, ok := auth_info[v]; ok {
  96. check = true
  97. break
  98. }
  99. }
  100. if check {
  101. auth_info["admin_default_feature"] = true
  102. }
  103. admin_default_feature := []string{"user_name_bold", "multiple_upload", "slow_edit_pass", "edit_bottom_compulsion_pass"}
  104. if _, ok := auth_info["admin_default_feature"]; ok {
  105. for _, v := range admin_default_feature {
  106. auth_info[v] = true
  107. }
  108. auth_info["user"] = true
  109. }
  110. return auth_info
  111. }
  112. func Check_acl(db *sql.DB, name string, topic_number string, tool string, ip string) bool {
  113. auth_name := Get_user_auth(db, ip)
  114. auth_info := Get_auth_group_info(db, auth_name)
  115. ip_or_user := IP_or_user(ip)
  116. level := "0"
  117. if !ip_or_user {
  118. level = Get_level(db, ip)[0]
  119. }
  120. level_int, _ := strconv.Atoi(level)
  121. get_ban := ""
  122. if tool == "document_edit_request" {
  123. get_ban = Get_user_ban(db, ip, "edit_request")[0]
  124. } else {
  125. get_ban = Get_user_ban(db, ip, "")[0]
  126. }
  127. if tool == "" && name != "" {
  128. if !Check_acl(db, name, "", "render", ip) {
  129. return false
  130. }
  131. if strings.HasPrefix(name, "user:") {
  132. user_page_str := name[5:]
  133. if slash_index := strings.Index(user_page_str, "/"); slash_index != -1 {
  134. user_page_str = user_page_str[:slash_index]
  135. }
  136. if auth_info["acl"] {
  137. return true
  138. }
  139. if get_ban == "true" {
  140. return false
  141. }
  142. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  143. if err != nil {
  144. log.Fatal(err)
  145. }
  146. defer stmt.Close()
  147. var acl_data string
  148. err = stmt.QueryRow(name).Scan(&acl_data)
  149. if err != nil {
  150. if err == sql.ErrNoRows {
  151. acl_data = ""
  152. } else {
  153. log.Fatal(err)
  154. }
  155. }
  156. if acl_data == "all" {
  157. return true
  158. } else if acl_data == "user" {
  159. if !ip_or_user {
  160. return true
  161. }
  162. } else if ip == user_page_str {
  163. if !ip_or_user {
  164. return true
  165. }
  166. }
  167. return false
  168. }
  169. }
  170. if Arr_in_str([]string{"document_edit", "document_edit_request", "document_move", "document_delete"}, tool) {
  171. if !Check_acl(db, name, topic_number, "", ip) {
  172. return false
  173. }
  174. } else if Arr_in_str([]string{"bbs_edit", "bbs_comment"}, tool) {
  175. if !Check_acl(db, name, topic_number, "bbs_view", ip) {
  176. return false
  177. }
  178. }
  179. if tool == "topic" {
  180. if name == "" {
  181. stmt, err := db.Prepare(DB_change("select title from rd where code = ?"))
  182. if err != nil {
  183. log.Fatal(err)
  184. }
  185. defer stmt.Close()
  186. err = stmt.QueryRow(topic_number).Scan(&name)
  187. if err != nil {
  188. if err == sql.ErrNoRows {
  189. name = "test"
  190. } else {
  191. log.Fatal(err)
  192. }
  193. }
  194. }
  195. }
  196. end_number := 1
  197. for for_a := 0; for_a < end_number; for_a++ {
  198. acl_data := ""
  199. acl_pass_auth := ""
  200. if tool == "" {
  201. acl_pass_auth = "acl"
  202. if for_a == 0 {
  203. end_number += 1
  204. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  205. if err != nil {
  206. log.Fatal(err)
  207. }
  208. defer stmt.Close()
  209. err = stmt.QueryRow(name).Scan(&acl_data)
  210. if err != nil {
  211. if err == sql.ErrNoRows {
  212. acl_data = ""
  213. } else {
  214. log.Fatal(err)
  215. }
  216. }
  217. } else {
  218. err := db.QueryRow(DB_change("select data from other where name = 'edit'")).Scan(&acl_data)
  219. if err != nil {
  220. if err == sql.ErrNoRows {
  221. acl_data = ""
  222. } else {
  223. log.Fatal(err)
  224. }
  225. }
  226. }
  227. } else if tool == "document_move" {
  228. acl_pass_auth = "acl"
  229. if for_a == 0 {
  230. end_number += 1
  231. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_move_acl'"))
  232. if err != nil {
  233. log.Fatal(err)
  234. }
  235. defer stmt.Close()
  236. err = stmt.QueryRow(name).Scan(&acl_data)
  237. if err != nil {
  238. if err == sql.ErrNoRows {
  239. acl_data = ""
  240. } else {
  241. log.Fatal(err)
  242. }
  243. }
  244. } else {
  245. err := db.QueryRow(DB_change("select data from other where name = 'document_move_acl'")).Scan(&acl_data)
  246. if err != nil {
  247. if err == sql.ErrNoRows {
  248. acl_data = ""
  249. } else {
  250. log.Fatal(err)
  251. }
  252. }
  253. }
  254. } else if tool == "document_edit" {
  255. acl_pass_auth = "acl"
  256. if for_a == 0 {
  257. end_number += 1
  258. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_acl'"))
  259. if err != nil {
  260. log.Fatal(err)
  261. }
  262. defer stmt.Close()
  263. err = stmt.QueryRow(name).Scan(&acl_data)
  264. if err != nil {
  265. if err == sql.ErrNoRows {
  266. acl_data = ""
  267. } else {
  268. log.Fatal(err)
  269. }
  270. }
  271. } else {
  272. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_acl'")).Scan(&acl_data)
  273. if err != nil {
  274. if err == sql.ErrNoRows {
  275. acl_data = ""
  276. } else {
  277. log.Fatal(err)
  278. }
  279. }
  280. }
  281. } else if tool == "document_edit" {
  282. acl_pass_auth = "acl"
  283. if for_a == 0 {
  284. end_number += 1
  285. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_delete_acl'"))
  286. if err != nil {
  287. log.Fatal(err)
  288. }
  289. defer stmt.Close()
  290. err = stmt.QueryRow(name).Scan(&acl_data)
  291. if err != nil {
  292. if err == sql.ErrNoRows {
  293. acl_data = ""
  294. } else {
  295. log.Fatal(err)
  296. }
  297. }
  298. } else {
  299. err := db.QueryRow(DB_change("select data from other where name = 'document_delete_acl'")).Scan(&acl_data)
  300. if err != nil {
  301. if err == sql.ErrNoRows {
  302. acl_data = ""
  303. } else {
  304. log.Fatal(err)
  305. }
  306. }
  307. }
  308. } else if tool == "topic" {
  309. acl_pass_auth = "topic"
  310. if for_a == 0 {
  311. end_number += 1
  312. stmt, err := db.Prepare(DB_change("select acl from rd where code = ?"))
  313. if err != nil {
  314. log.Fatal(err)
  315. }
  316. defer stmt.Close()
  317. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  318. if err != nil {
  319. if err == sql.ErrNoRows {
  320. acl_data = ""
  321. } else {
  322. log.Fatal(err)
  323. }
  324. }
  325. } else if for_a == 1 {
  326. end_number += 1
  327. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'dis'"))
  328. if err != nil {
  329. log.Fatal(err)
  330. }
  331. defer stmt.Close()
  332. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  333. if err != nil {
  334. if err == sql.ErrNoRows {
  335. acl_data = ""
  336. } else {
  337. log.Fatal(err)
  338. }
  339. }
  340. } else {
  341. err := db.QueryRow(DB_change("select data from other where name = 'discussion'")).Scan(&acl_data)
  342. if err != nil {
  343. if err == sql.ErrNoRows {
  344. acl_data = ""
  345. } else {
  346. log.Fatal(err)
  347. }
  348. }
  349. }
  350. } else if tool == "topic_view" {
  351. acl_pass_auth = "topic"
  352. stmt, err := db.Prepare(DB_change("select set_data from topic_set where thread_code = ? and set_name = 'thread_view_acl'"))
  353. if err != nil {
  354. log.Fatal(err)
  355. }
  356. defer stmt.Close()
  357. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  358. if err != nil {
  359. if err == sql.ErrNoRows {
  360. acl_data = ""
  361. } else {
  362. log.Fatal(err)
  363. }
  364. }
  365. } else if tool == "upload" {
  366. acl_pass_auth = "multiple_upload"
  367. err := db.QueryRow(DB_change("select data from other where name = 'upload_acl'")).Scan(&acl_data)
  368. if err != nil {
  369. if err == sql.ErrNoRows {
  370. acl_data = ""
  371. } else {
  372. log.Fatal(err)
  373. }
  374. }
  375. } else if tool == "many_upload" {
  376. acl_pass_auth = "multiple_upload"
  377. err := db.QueryRow(DB_change("select data from other where name = 'many_upload_acl'")).Scan(&acl_data)
  378. if err != nil {
  379. if err == sql.ErrNoRows {
  380. acl_data = ""
  381. } else {
  382. log.Fatal(err)
  383. }
  384. }
  385. } else if tool == "vote" {
  386. acl_pass_auth = "owner"
  387. if for_a == 0 {
  388. end_number += 1
  389. if topic_number != "" {
  390. stmt, err := db.Prepare(DB_change("select acl from vote where id = ? and user = ''"))
  391. if err != nil {
  392. log.Fatal(err)
  393. }
  394. defer stmt.Close()
  395. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  396. if err != nil {
  397. if err == sql.ErrNoRows {
  398. acl_data = ""
  399. } else {
  400. log.Fatal(err)
  401. }
  402. }
  403. } else {
  404. continue
  405. }
  406. } else {
  407. err := db.QueryRow(DB_change("select data from other where name = 'vote_acl'")).Scan(&acl_data)
  408. if err != nil {
  409. if err == sql.ErrNoRows {
  410. acl_data = ""
  411. } else {
  412. log.Fatal(err)
  413. }
  414. }
  415. }
  416. } else if tool == "slow_edit" {
  417. acl_pass_auth = "slow_edit_pass"
  418. err := db.QueryRow(DB_change("select data from other where name = 'slow_edit_acl'")).Scan(&acl_data)
  419. if err != nil {
  420. if err == sql.ErrNoRows {
  421. acl_data = ""
  422. } else {
  423. log.Fatal(err)
  424. }
  425. }
  426. } else if tool == "edit_bottom_compulsion" {
  427. acl_pass_auth = "edit_bottom_compulsion_pass"
  428. err := db.QueryRow(DB_change("select data from other where name = 'edit_bottom_compulsion_acl'")).Scan(&acl_data)
  429. if err != nil {
  430. if err == sql.ErrNoRows {
  431. acl_data = ""
  432. } else {
  433. log.Fatal(err)
  434. }
  435. }
  436. } else if tool == "bbs_edit" {
  437. acl_pass_auth = "bbs"
  438. if for_a == 0 {
  439. end_number += 1
  440. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl' and set_id = ?"))
  441. if err != nil {
  442. log.Fatal(err)
  443. }
  444. defer stmt.Close()
  445. err = stmt.QueryRow(name).Scan(&acl_data)
  446. if err != nil {
  447. if err == sql.ErrNoRows {
  448. acl_data = ""
  449. } else {
  450. log.Fatal(err)
  451. }
  452. }
  453. } else if for_a == 1 {
  454. end_number += 1
  455. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  456. if err != nil {
  457. log.Fatal(err)
  458. }
  459. defer stmt.Close()
  460. err = stmt.QueryRow(name).Scan(&acl_data)
  461. if err != nil {
  462. if err == sql.ErrNoRows {
  463. acl_data = ""
  464. } else {
  465. log.Fatal(err)
  466. }
  467. }
  468. } else if for_a == 2 {
  469. end_number += 1
  470. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl_all'")).Scan(&acl_data)
  471. if err != nil {
  472. if err == sql.ErrNoRows {
  473. acl_data = ""
  474. } else {
  475. log.Fatal(err)
  476. }
  477. }
  478. } else {
  479. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  480. if err != nil {
  481. if err == sql.ErrNoRows {
  482. acl_data = ""
  483. } else {
  484. log.Fatal(err)
  485. }
  486. }
  487. }
  488. } else if tool == "bbs_comment" {
  489. acl_pass_auth = "bbs"
  490. if for_a == 0 {
  491. end_number += 1
  492. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl' and set_id = ?"))
  493. if err != nil {
  494. log.Fatal(err)
  495. }
  496. defer stmt.Close()
  497. err = stmt.QueryRow(name).Scan(&acl_data)
  498. if err != nil {
  499. if err == sql.ErrNoRows {
  500. acl_data = ""
  501. } else {
  502. log.Fatal(err)
  503. }
  504. }
  505. } else if for_a == 1 {
  506. end_number += 1
  507. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  508. if err != nil {
  509. log.Fatal(err)
  510. }
  511. defer stmt.Close()
  512. err = stmt.QueryRow(name).Scan(&acl_data)
  513. if err != nil {
  514. if err == sql.ErrNoRows {
  515. acl_data = ""
  516. } else {
  517. log.Fatal(err)
  518. }
  519. }
  520. } else if for_a == 2 {
  521. end_number += 1
  522. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl_all'")).Scan(&acl_data)
  523. if err != nil {
  524. if err == sql.ErrNoRows {
  525. acl_data = ""
  526. } else {
  527. log.Fatal(err)
  528. }
  529. }
  530. } else {
  531. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  532. if err != nil {
  533. if err == sql.ErrNoRows {
  534. acl_data = ""
  535. } else {
  536. log.Fatal(err)
  537. }
  538. }
  539. }
  540. } else if tool == "bbs_view" {
  541. acl_pass_auth = "bbs"
  542. if for_a == 0 {
  543. end_number += 1
  544. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl' and set_id = ?"))
  545. if err != nil {
  546. log.Fatal(err)
  547. }
  548. defer stmt.Close()
  549. err = stmt.QueryRow(name).Scan(&acl_data)
  550. if err != nil {
  551. if err == sql.ErrNoRows {
  552. acl_data = ""
  553. } else {
  554. log.Fatal(err)
  555. }
  556. }
  557. } else {
  558. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl_all'")).Scan(&acl_data)
  559. if err != nil {
  560. if err == sql.ErrNoRows {
  561. acl_data = ""
  562. } else {
  563. log.Fatal(err)
  564. }
  565. }
  566. }
  567. } else if tool == "recaptcha" {
  568. acl_pass_auth = "admin_default_feature"
  569. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_pass_acl'")).Scan(&acl_data)
  570. if err != nil {
  571. if err == sql.ErrNoRows {
  572. acl_data = ""
  573. } else {
  574. log.Fatal(err)
  575. }
  576. }
  577. } else if tool == "recaptcha_five_pass" {
  578. acl_pass_auth = "admin_default_feature"
  579. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_one_check_five_pass_acl'")).Scan(&acl_data)
  580. if err != nil {
  581. if err == sql.ErrNoRows {
  582. acl_data = ""
  583. } else {
  584. log.Fatal(err)
  585. }
  586. }
  587. } else if tool == "document_edit_request" {
  588. acl_pass_auth = "acl"
  589. if for_a == 0 {
  590. end_number += 1
  591. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_request_acl'"))
  592. if err != nil {
  593. log.Fatal(err)
  594. }
  595. defer stmt.Close()
  596. err = stmt.QueryRow(name).Scan(&acl_data)
  597. if err != nil {
  598. if err == sql.ErrNoRows {
  599. acl_data = ""
  600. } else {
  601. log.Fatal(err)
  602. }
  603. }
  604. } else {
  605. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_request_acl'")).Scan(&acl_data)
  606. if err != nil {
  607. if err == sql.ErrNoRows {
  608. acl_data = ""
  609. } else {
  610. log.Fatal(err)
  611. }
  612. }
  613. }
  614. } else if tool == "document_make_acl" {
  615. acl_pass_auth = "acl"
  616. err := db.QueryRow(DB_change("select data from other where name = 'document_make_acl'")).Scan(&acl_data)
  617. if err != nil {
  618. if err == sql.ErrNoRows {
  619. acl_data = ""
  620. } else {
  621. log.Fatal(err)
  622. }
  623. }
  624. } else {
  625. // tool == "render"
  626. acl_pass_auth = "acl"
  627. if for_a == 0 {
  628. end_number += 1
  629. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'view'"))
  630. if err != nil {
  631. log.Fatal(err)
  632. }
  633. defer stmt.Close()
  634. err = stmt.QueryRow(name).Scan(&acl_data)
  635. if err != nil {
  636. if err == sql.ErrNoRows {
  637. acl_data = ""
  638. } else {
  639. log.Fatal(err)
  640. }
  641. }
  642. } else {
  643. err := db.QueryRow(DB_change("select data from other where name = 'all_view_acl'")).Scan(&acl_data)
  644. if err != nil {
  645. if err == sql.ErrNoRows {
  646. acl_data = ""
  647. } else {
  648. log.Fatal(err)
  649. }
  650. }
  651. }
  652. }
  653. if acl_data == "" {
  654. if tool == "recaptcha" {
  655. acl_data = "admin"
  656. } else if tool == "slow_edit" || tool == "edit_bottom_compulsion" {
  657. acl_data = "not_all"
  658. } else {
  659. acl_data = "normal"
  660. }
  661. }
  662. except_ban_tool_list := []string{"render", "topic_view", "bbs_view"}
  663. if acl_data != "normal" {
  664. if !(acl_data == "ban" || acl_data == "ban_admin") && !Arr_in_str(except_ban_tool_list, tool) {
  665. if get_ban == "true" {
  666. return false
  667. }
  668. }
  669. if auth_info[acl_pass_auth] {
  670. return true
  671. } else if acl_data == "all" || acl_data == "ban" {
  672. return true
  673. } else if acl_data == "user" {
  674. if !ip_or_user {
  675. return true
  676. }
  677. } else if acl_data == "admin" {
  678. if auth_info["admin_default_feature"] {
  679. return true
  680. }
  681. } else if acl_data == "50_edit" {
  682. if !ip_or_user {
  683. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  684. if err != nil {
  685. log.Fatal(err)
  686. }
  687. defer stmt.Close()
  688. var count int
  689. err = stmt.QueryRow(ip).Scan(&count)
  690. if err != nil {
  691. if err == sql.ErrNoRows {
  692. count = 0
  693. } else {
  694. log.Fatal(err)
  695. }
  696. }
  697. if count >= 50 {
  698. return true
  699. }
  700. }
  701. } else if acl_data == "before" {
  702. stmt, err := db.Prepare(DB_change("select ip from history where title = ? and ip = ?"))
  703. if err != nil {
  704. log.Fatal(err)
  705. }
  706. defer stmt.Close()
  707. var exist string
  708. err = stmt.QueryRow(name, ip).Scan(&exist)
  709. if err != nil {
  710. if err == sql.ErrNoRows {
  711. exist = ""
  712. } else {
  713. log.Fatal(err)
  714. }
  715. }
  716. if exist != "" {
  717. return true
  718. }
  719. } else if acl_data == "30_day" || acl_data == "90_day" {
  720. if !ip_or_user {
  721. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  722. if err != nil {
  723. log.Fatal(err)
  724. }
  725. defer stmt.Close()
  726. var signup_date string
  727. err = stmt.QueryRow(ip).Scan(&signup_date)
  728. if err != nil {
  729. if err == sql.ErrNoRows {
  730. signup_date = Get_time()
  731. } else {
  732. log.Fatal(err)
  733. }
  734. }
  735. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  736. if acl_data == "30_day" {
  737. time_1 = time_1.AddDate(0, 0, 30)
  738. } else {
  739. time_1 = time_1.AddDate(0, 0, 90)
  740. }
  741. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  742. if time_2.After(time_1) {
  743. return true
  744. }
  745. }
  746. } else if acl_data == "email" {
  747. if !ip_or_user {
  748. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'email'"))
  749. if err != nil {
  750. log.Fatal(err)
  751. }
  752. defer stmt.Close()
  753. var exist string
  754. err = stmt.QueryRow(ip).Scan(&exist)
  755. if err != nil {
  756. if err == sql.ErrNoRows {
  757. exist = ""
  758. } else {
  759. log.Fatal(err)
  760. }
  761. }
  762. if exist != "" {
  763. return true
  764. }
  765. }
  766. } else if acl_data == "owner" {
  767. if auth_info["owner"] {
  768. return true
  769. }
  770. } else if acl_data == "ban_admin" {
  771. if auth_info["admin_default_feature"] || get_ban == "true" {
  772. return true
  773. }
  774. } else if acl_data == "not_all" {
  775. return false
  776. } else if acl_data == "up_to_level_3" || acl_data == "up_to_level_10" {
  777. if acl_data == "up_to_level_3" {
  778. if level_int >= 3 {
  779. return true
  780. }
  781. } else if acl_data == "up_to_level_10" {
  782. if level_int >= 10 {
  783. return true
  784. }
  785. }
  786. } else if acl_data == "30_day_50_edit" {
  787. if !ip_or_user {
  788. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  789. if err != nil {
  790. log.Fatal(err)
  791. }
  792. defer stmt.Close()
  793. var signup_date string
  794. err = stmt.QueryRow(ip).Scan(&signup_date)
  795. if err != nil {
  796. if err == sql.ErrNoRows {
  797. signup_date = Get_time()
  798. } else {
  799. log.Fatal(err)
  800. }
  801. }
  802. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  803. time_1 = time_1.AddDate(0, 0, 30)
  804. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  805. if time_2.After(time_1) {
  806. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  807. if err != nil {
  808. log.Fatal(err)
  809. }
  810. defer stmt.Close()
  811. var count int
  812. err = stmt.QueryRow(ip).Scan(&count)
  813. if err != nil {
  814. if err == sql.ErrNoRows {
  815. count = 0
  816. } else {
  817. log.Fatal(err)
  818. }
  819. }
  820. if count >= 50 {
  821. return true
  822. }
  823. }
  824. }
  825. }
  826. return false
  827. } else if for_a == end_number-1 {
  828. if !Arr_in_str(except_ban_tool_list, tool) {
  829. if get_ban == "true" {
  830. return false
  831. }
  832. }
  833. if tool == "topic" {
  834. stmt, err := db.Prepare(DB_change("select title from rd where code = ? and stop != ''"))
  835. if err != nil {
  836. log.Fatal(err)
  837. }
  838. defer stmt.Close()
  839. var topic_state string
  840. err = stmt.QueryRow(topic_number).Scan(&topic_state)
  841. if err != nil {
  842. if err == sql.ErrNoRows {
  843. topic_state = ""
  844. } else {
  845. log.Fatal(err)
  846. }
  847. }
  848. if topic_state != "" {
  849. if auth_info["topic"] {
  850. return true
  851. } else {
  852. return false
  853. }
  854. } else {
  855. return true
  856. }
  857. } else {
  858. return true
  859. }
  860. }
  861. }
  862. return false
  863. }