acl_and_auth.go 22 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "strconv"
  6. "strings"
  7. "time"
  8. )
  9. func List_acl(func_type string) []string {
  10. if func_type == "user_document" {
  11. return []string{
  12. "",
  13. "user",
  14. "all",
  15. }
  16. } else {
  17. return []string{
  18. "",
  19. "all",
  20. "user",
  21. "admin",
  22. "owner",
  23. "50_edit",
  24. "email",
  25. "ban",
  26. "before",
  27. "30_day",
  28. "90_day",
  29. "ban_admin",
  30. "not_all",
  31. "up_to_level_3",
  32. "up_to_level_10",
  33. "30_day_50_edit",
  34. }
  35. }
  36. }
  37. func Do_insert_auth_history(db *sql.DB, ip string, what string) {
  38. var log_off string
  39. err := db.QueryRow(DB_change("select data from other where name = 'auth_history_off'")).Scan(&log_off)
  40. if err != nil {
  41. if err == sql.ErrNoRows {
  42. log_off = ""
  43. } else {
  44. log.Fatal(err)
  45. }
  46. }
  47. if log_off == "" {
  48. stmt, err := db.Prepare(DB_change("insert into re_admin (who, what, time) values (?, ?, ?)"))
  49. if err != nil {
  50. log.Fatal(err)
  51. }
  52. defer stmt.Close()
  53. time := Get_time()
  54. _, err = stmt.Exec(ip, what, time)
  55. if err != nil {
  56. log.Fatal(err)
  57. }
  58. }
  59. }
  60. func Get_user_auth(db *sql.DB, ip string) string {
  61. if !IP_or_user(ip) {
  62. var auth string
  63. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  64. if err != nil {
  65. log.Fatal(err)
  66. }
  67. defer stmt.Close()
  68. err = stmt.QueryRow(ip).Scan(&auth)
  69. if err != nil {
  70. if err == sql.ErrNoRows {
  71. auth = "user"
  72. } else {
  73. log.Fatal(err)
  74. }
  75. }
  76. if auth != "user" && auth != "ban" {
  77. return auth
  78. } else {
  79. return ""
  80. }
  81. }
  82. return ""
  83. }
  84. func Get_auth_group_info(db *sql.DB, auth string) map[string]bool {
  85. stmt, err := db.Prepare(DB_change("select acl from alist where name = ?"))
  86. if err != nil {
  87. log.Fatal(err)
  88. }
  89. defer stmt.Close()
  90. rows, err := stmt.Query(auth)
  91. if err != nil {
  92. log.Fatal(err)
  93. }
  94. defer rows.Close()
  95. data_list := map[string]bool{}
  96. for rows.Next() {
  97. var name string
  98. err := rows.Scan(&name)
  99. if err != nil {
  100. log.Fatal(err)
  101. }
  102. data_list[name] = true
  103. }
  104. return Check_auth(data_list)
  105. }
  106. func Check_auth(auth_info map[string]bool) map[string]bool {
  107. if _, ok := auth_info["owner"]; ok {
  108. auth_info["admin"] = true
  109. }
  110. admin_auth := []string{"ban", "toron", "check", "acl", "hidel", "give", "bbs", "vote"}
  111. if _, ok := auth_info["admin"]; ok {
  112. for _, v := range admin_auth {
  113. auth_info[v] = true
  114. }
  115. }
  116. if _, ok := auth_info["check"]; ok {
  117. auth_info["view_user_watchlist"] = true
  118. }
  119. check := false
  120. for _, v := range admin_auth {
  121. if _, ok := auth_info[v]; ok {
  122. check = true
  123. break
  124. }
  125. }
  126. if check {
  127. auth_info["admin_default_feature"] = true
  128. }
  129. admin_default_feature := []string{"treat_as_admin", "user_name_bold", "multiple_upload", "slow_edit_pass", "edit_bottom_compulsion_pass", "view_hide_user_name", "doc_watch_list_view", "user"}
  130. if _, ok := auth_info["admin_default_feature"]; ok {
  131. for _, v := range admin_default_feature {
  132. auth_info[v] = true
  133. }
  134. }
  135. user_default := []string{"captcha_pass", "ip"}
  136. if _, ok := auth_info["user"]; ok {
  137. for _, v := range user_default {
  138. auth_info[v] = true
  139. }
  140. }
  141. ip_default := []string{"document", "discuss", "upload", "vote", "bbs", "captcha_one_check_five_pass"}
  142. if _, ok := auth_info["ip"]; ok {
  143. for _, v := range ip_default {
  144. auth_info[v] = true
  145. }
  146. }
  147. document_default := []string{"edit", "edit_request", "move", "new_make", "delete"}
  148. if _, ok := auth_info["document"]; ok {
  149. for _, v := range document_default {
  150. auth_info[v] = true
  151. }
  152. }
  153. check = false
  154. for _, v := range document_default {
  155. if _, ok := auth_info[v]; ok {
  156. check = true
  157. break
  158. }
  159. }
  160. if check {
  161. auth_info["view"] = true
  162. }
  163. bbs_default := []string{"bbs_edit", "bbs_comment"}
  164. if _, ok := auth_info["bbs_use"]; ok {
  165. for _, v := range bbs_default {
  166. auth_info[v] = true
  167. }
  168. }
  169. check = false
  170. for _, v := range bbs_default {
  171. if _, ok := auth_info[v]; ok {
  172. check = true
  173. break
  174. }
  175. }
  176. if check {
  177. auth_info["bbs_view"] = true
  178. }
  179. return auth_info
  180. }
  181. func Check_acl(db *sql.DB, name string, topic_number string, tool string, ip string) bool {
  182. auth_name := Get_user_auth(db, ip)
  183. auth_info := Get_auth_group_info(db, auth_name)
  184. ip_or_user := IP_or_user(ip)
  185. level := "0"
  186. if !ip_or_user {
  187. level = Get_level(db, ip)[0]
  188. }
  189. level_int, _ := strconv.Atoi(level)
  190. get_ban := ""
  191. ban_type := ""
  192. if tool == "document_edit_request" {
  193. temp_arr := Get_user_ban(db, ip, "edit_request")
  194. get_ban = temp_arr[0]
  195. ban_type = temp_arr[1]
  196. } else {
  197. temp_arr := Get_user_ban(db, ip, "")
  198. get_ban = temp_arr[0]
  199. ban_type = temp_arr[1]
  200. }
  201. if ban_type != "" {
  202. ban_type_len := len(ban_type)
  203. if ban_type_len == 1 {
  204. ban_type = string(ban_type[0])
  205. } else if ban_type_len == 2 {
  206. ban_type = string(ban_type[1])
  207. }
  208. }
  209. if tool == "" && name != "" {
  210. if !Check_acl(db, name, "", "render", ip) {
  211. return false
  212. }
  213. if strings.HasPrefix(name, "user:") {
  214. user_page_str := name[5:]
  215. if slash_index := strings.Index(user_page_str, "/"); slash_index != -1 {
  216. user_page_str = user_page_str[:slash_index]
  217. }
  218. if auth_info["acl"] {
  219. return true
  220. }
  221. if get_ban == "true" {
  222. return false
  223. }
  224. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  225. if err != nil {
  226. log.Fatal(err)
  227. }
  228. defer stmt.Close()
  229. var acl_data string
  230. err = stmt.QueryRow(name).Scan(&acl_data)
  231. if err != nil {
  232. if err == sql.ErrNoRows {
  233. acl_data = ""
  234. } else {
  235. log.Fatal(err)
  236. }
  237. }
  238. if acl_data == "all" {
  239. return true
  240. } else if acl_data == "user" {
  241. if !ip_or_user {
  242. return true
  243. }
  244. } else if ip == user_page_str {
  245. if !ip_or_user {
  246. return true
  247. }
  248. }
  249. return false
  250. }
  251. }
  252. if Arr_in_str([]string{"document_edit", "document_edit_request", "document_move", "document_delete"}, tool) {
  253. if !Check_acl(db, name, topic_number, "", ip) {
  254. return false
  255. }
  256. } else if Arr_in_str([]string{"bbs_edit", "bbs_comment"}, tool) {
  257. if !Check_acl(db, name, topic_number, "bbs_view", ip) {
  258. return false
  259. }
  260. }
  261. if tool == "topic" {
  262. if name == "" {
  263. stmt, err := db.Prepare(DB_change("select title from rd where code = ?"))
  264. if err != nil {
  265. log.Fatal(err)
  266. }
  267. defer stmt.Close()
  268. err = stmt.QueryRow(topic_number).Scan(&name)
  269. if err != nil {
  270. if err == sql.ErrNoRows {
  271. name = "test"
  272. } else {
  273. log.Fatal(err)
  274. }
  275. }
  276. }
  277. }
  278. end_number := 1
  279. for for_a := 0; for_a < end_number; for_a++ {
  280. acl_data := ""
  281. acl_pass_auth := ""
  282. if tool == "all_admin_auth" {
  283. acl_pass_auth = "treat_as_admin"
  284. acl_data = "owner"
  285. } else if tool == "owner_auth" {
  286. acl_pass_auth = "owner"
  287. acl_data = "owner"
  288. } else if tool == "ban_auth" {
  289. acl_pass_auth = "ban"
  290. acl_data = "owner"
  291. } else if tool == "bbs_auth" {
  292. acl_pass_auth = "bbs"
  293. acl_data = "owner"
  294. } else if tool == "toron_auth" {
  295. acl_pass_auth = "toron"
  296. acl_data = "owner"
  297. } else if tool == "check_auth" {
  298. acl_pass_auth = "check"
  299. acl_data = "owner"
  300. } else if tool == "acl_auth" {
  301. acl_pass_auth = "acl"
  302. acl_data = "owner"
  303. } else if tool == "hidel_auth" {
  304. acl_pass_auth = "hidel"
  305. acl_data = "owner"
  306. } else if tool == "give_auth" {
  307. acl_pass_auth = "give"
  308. acl_data = "owner"
  309. } else if tool == "vote_auth" {
  310. acl_pass_auth = "vote_fix"
  311. acl_data = "owner"
  312. } else if tool == "" {
  313. acl_pass_auth = "acl"
  314. if for_a == 0 {
  315. end_number += 1
  316. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  317. if err != nil {
  318. log.Fatal(err)
  319. }
  320. defer stmt.Close()
  321. err = stmt.QueryRow(name).Scan(&acl_data)
  322. if err != nil {
  323. if err == sql.ErrNoRows {
  324. acl_data = ""
  325. } else {
  326. log.Fatal(err)
  327. }
  328. }
  329. } else {
  330. if auth_info["document"] {
  331. acl_data = ""
  332. } else {
  333. acl_data = "owner"
  334. }
  335. }
  336. } else if tool == "document_move" {
  337. acl_pass_auth = "acl"
  338. if for_a == 0 {
  339. end_number += 1
  340. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_move_acl'"))
  341. if err != nil {
  342. log.Fatal(err)
  343. }
  344. defer stmt.Close()
  345. err = stmt.QueryRow(name).Scan(&acl_data)
  346. if err != nil {
  347. if err == sql.ErrNoRows {
  348. acl_data = ""
  349. } else {
  350. log.Fatal(err)
  351. }
  352. }
  353. } else {
  354. if auth_info["move"] {
  355. acl_data = ""
  356. } else {
  357. acl_data = "owner"
  358. }
  359. }
  360. } else if tool == "document_edit" {
  361. acl_pass_auth = "acl"
  362. if for_a == 0 {
  363. end_number += 1
  364. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_acl'"))
  365. if err != nil {
  366. log.Fatal(err)
  367. }
  368. defer stmt.Close()
  369. err = stmt.QueryRow(name).Scan(&acl_data)
  370. if err != nil {
  371. if err == sql.ErrNoRows {
  372. acl_data = ""
  373. } else {
  374. log.Fatal(err)
  375. }
  376. }
  377. } else {
  378. if auth_info["edit"] {
  379. acl_data = ""
  380. } else {
  381. acl_data = "owner"
  382. }
  383. }
  384. } else if tool == "document_delete" {
  385. acl_pass_auth = "acl"
  386. if for_a == 0 {
  387. end_number += 1
  388. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_delete_acl'"))
  389. if err != nil {
  390. log.Fatal(err)
  391. }
  392. defer stmt.Close()
  393. err = stmt.QueryRow(name).Scan(&acl_data)
  394. if err != nil {
  395. if err == sql.ErrNoRows {
  396. acl_data = ""
  397. } else {
  398. log.Fatal(err)
  399. }
  400. }
  401. } else {
  402. if auth_info["delete"] {
  403. acl_data = ""
  404. } else {
  405. acl_data = "owner"
  406. }
  407. }
  408. } else if tool == "topic" {
  409. acl_pass_auth = "topic"
  410. if for_a == 0 {
  411. end_number += 1
  412. stmt, err := db.Prepare(DB_change("select acl from rd where code = ?"))
  413. if err != nil {
  414. log.Fatal(err)
  415. }
  416. defer stmt.Close()
  417. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  418. if err != nil {
  419. if err == sql.ErrNoRows {
  420. acl_data = ""
  421. } else {
  422. log.Fatal(err)
  423. }
  424. }
  425. } else if for_a == 1 {
  426. end_number += 1
  427. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'dis'"))
  428. if err != nil {
  429. log.Fatal(err)
  430. }
  431. defer stmt.Close()
  432. err = stmt.QueryRow(name).Scan(&acl_data)
  433. if err != nil {
  434. if err == sql.ErrNoRows {
  435. acl_data = ""
  436. } else {
  437. log.Fatal(err)
  438. }
  439. }
  440. } else {
  441. if auth_info["discuss"] {
  442. acl_data = ""
  443. } else {
  444. acl_data = "owner"
  445. }
  446. }
  447. } else if tool == "topic_view" {
  448. acl_pass_auth = "topic"
  449. if auth_info["discuss_view"] {
  450. acl_data = ""
  451. } else {
  452. acl_data = "owner"
  453. }
  454. } else if tool == "upload" {
  455. acl_pass_auth = "admin_default_feature"
  456. if auth_info["upload"] {
  457. acl_data = ""
  458. } else {
  459. acl_data = "owner"
  460. }
  461. } else if tool == "many_upload" {
  462. acl_pass_auth = "admin_default_feature"
  463. if auth_info["multiple_upload"] {
  464. acl_data = ""
  465. } else {
  466. acl_data = "owner"
  467. }
  468. } else if tool == "vote" {
  469. acl_pass_auth = "vote_fix"
  470. if for_a == 0 {
  471. end_number += 1
  472. if topic_number != "" {
  473. stmt, err := db.Prepare(DB_change("select acl from vote where id = ? and user = ''"))
  474. if err != nil {
  475. log.Fatal(err)
  476. }
  477. defer stmt.Close()
  478. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  479. if err != nil {
  480. if err == sql.ErrNoRows {
  481. acl_data = ""
  482. } else {
  483. log.Fatal(err)
  484. }
  485. }
  486. } else {
  487. continue
  488. }
  489. } else {
  490. if auth_info["vote"] {
  491. acl_data = ""
  492. } else {
  493. acl_data = "owner"
  494. }
  495. }
  496. } else if tool == "slow_edit" {
  497. acl_pass_auth = "admin_default_feature"
  498. if auth_info["slow_edit_pass"] {
  499. acl_data = ""
  500. } else {
  501. acl_data = "owner"
  502. }
  503. } else if tool == "edit_bottom_compulsion" {
  504. acl_pass_auth = "admin_default_feature"
  505. if auth_info["edit_bottom_compulsion_pass"] {
  506. acl_data = ""
  507. } else {
  508. acl_data = "owner"
  509. }
  510. } else if tool == "bbs_edit" {
  511. acl_pass_auth = "bbs"
  512. if for_a == 0 {
  513. end_number += 1
  514. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl' and set_id = ?"))
  515. if err != nil {
  516. log.Fatal(err)
  517. }
  518. defer stmt.Close()
  519. err = stmt.QueryRow(name).Scan(&acl_data)
  520. if err != nil {
  521. if err == sql.ErrNoRows {
  522. acl_data = ""
  523. } else {
  524. log.Fatal(err)
  525. }
  526. }
  527. } else if for_a == 1 {
  528. end_number += 1
  529. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  530. if err != nil {
  531. log.Fatal(err)
  532. }
  533. defer stmt.Close()
  534. err = stmt.QueryRow(name).Scan(&acl_data)
  535. if err != nil {
  536. if err == sql.ErrNoRows {
  537. acl_data = ""
  538. } else {
  539. log.Fatal(err)
  540. }
  541. }
  542. } else if for_a == 2 {
  543. end_number += 1
  544. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl_all'")).Scan(&acl_data)
  545. if err != nil {
  546. if err == sql.ErrNoRows {
  547. acl_data = ""
  548. } else {
  549. log.Fatal(err)
  550. }
  551. }
  552. } else {
  553. if auth_info["bbs_edit"] {
  554. acl_data = ""
  555. } else {
  556. acl_data = "owner"
  557. }
  558. }
  559. } else if tool == "bbs_comment" {
  560. acl_pass_auth = "bbs"
  561. if for_a == 0 {
  562. end_number += 1
  563. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl' and set_id = ?"))
  564. if err != nil {
  565. log.Fatal(err)
  566. }
  567. defer stmt.Close()
  568. err = stmt.QueryRow(name).Scan(&acl_data)
  569. if err != nil {
  570. if err == sql.ErrNoRows {
  571. acl_data = ""
  572. } else {
  573. log.Fatal(err)
  574. }
  575. }
  576. } else if for_a == 1 {
  577. end_number += 1
  578. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  579. if err != nil {
  580. log.Fatal(err)
  581. }
  582. defer stmt.Close()
  583. err = stmt.QueryRow(name).Scan(&acl_data)
  584. if err != nil {
  585. if err == sql.ErrNoRows {
  586. acl_data = ""
  587. } else {
  588. log.Fatal(err)
  589. }
  590. }
  591. } else if for_a == 2 {
  592. end_number += 1
  593. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl_all'")).Scan(&acl_data)
  594. if err != nil {
  595. if err == sql.ErrNoRows {
  596. acl_data = ""
  597. } else {
  598. log.Fatal(err)
  599. }
  600. }
  601. } else {
  602. if auth_info["bbs_comment"] {
  603. acl_data = ""
  604. } else {
  605. acl_data = "owner"
  606. }
  607. }
  608. } else if tool == "bbs_view" {
  609. acl_pass_auth = "bbs"
  610. if for_a == 0 {
  611. end_number += 1
  612. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl' and set_id = ?"))
  613. if err != nil {
  614. log.Fatal(err)
  615. }
  616. defer stmt.Close()
  617. err = stmt.QueryRow(name).Scan(&acl_data)
  618. if err != nil {
  619. if err == sql.ErrNoRows {
  620. acl_data = ""
  621. } else {
  622. log.Fatal(err)
  623. }
  624. }
  625. } else {
  626. if auth_info["bbs_view"] {
  627. acl_data = ""
  628. } else {
  629. acl_data = "owner"
  630. }
  631. }
  632. } else if tool == "recaptcha" {
  633. acl_pass_auth = "admin_default_feature"
  634. if auth_info["captcha_pass"] {
  635. acl_data = ""
  636. } else {
  637. acl_data = "owner"
  638. }
  639. } else if tool == "recaptcha_five_pass" {
  640. acl_pass_auth = "admin_default_feature"
  641. if auth_info["captcha_one_check_five_pass"] {
  642. acl_data = ""
  643. } else {
  644. acl_data = "owner"
  645. }
  646. } else if tool == "view_hide_user_name" {
  647. acl_pass_auth = "admin_default_feature"
  648. if auth_info["view_hide_user_name"] {
  649. acl_data = ""
  650. } else {
  651. acl_data = "owner"
  652. }
  653. } else if tool == "user_name_bold" {
  654. acl_pass_auth = "admin_default_feature"
  655. if auth_info["user_name_bold"] {
  656. acl_data = ""
  657. } else {
  658. acl_data = "owner"
  659. }
  660. } else if tool == "doc_watch_list_view" {
  661. acl_pass_auth = "admin_default_feature"
  662. if auth_info["doc_watch_list_view"] {
  663. acl_data = ""
  664. } else {
  665. acl_data = "owner"
  666. }
  667. } else if tool == "document_edit_request" {
  668. acl_pass_auth = "acl"
  669. if for_a == 0 {
  670. end_number += 1
  671. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_request_acl'"))
  672. if err != nil {
  673. log.Fatal(err)
  674. }
  675. defer stmt.Close()
  676. err = stmt.QueryRow(name).Scan(&acl_data)
  677. if err != nil {
  678. if err == sql.ErrNoRows {
  679. acl_data = ""
  680. } else {
  681. log.Fatal(err)
  682. }
  683. }
  684. } else {
  685. if auth_info["edit_request"] {
  686. acl_data = ""
  687. } else {
  688. acl_data = "owner"
  689. }
  690. }
  691. } else if tool == "document_make_acl" {
  692. acl_pass_auth = "acl"
  693. if auth_info["new_make"] {
  694. acl_data = ""
  695. } else {
  696. acl_data = "owner"
  697. }
  698. } else {
  699. // tool == "render"
  700. acl_pass_auth = "acl"
  701. if for_a == 0 {
  702. end_number += 1
  703. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'view'"))
  704. if err != nil {
  705. log.Fatal(err)
  706. }
  707. defer stmt.Close()
  708. err = stmt.QueryRow(name).Scan(&acl_data)
  709. if err != nil {
  710. if err == sql.ErrNoRows {
  711. acl_data = ""
  712. } else {
  713. log.Fatal(err)
  714. }
  715. }
  716. } else {
  717. if auth_info["view"] {
  718. acl_data = ""
  719. } else {
  720. acl_data = "owner"
  721. }
  722. }
  723. }
  724. if auth_info[acl_pass_auth] {
  725. return true
  726. } else if ban_type == "4" {
  727. return false
  728. }
  729. if acl_data == "" {
  730. acl_data = "normal"
  731. }
  732. except_ban_tool_list := []string{"render", "topic_view", "bbs_view"}
  733. if acl_data != "normal" {
  734. if !(acl_data == "ban" || acl_data == "ban_admin") || ban_type == "3" {
  735. if !Arr_in_str(except_ban_tool_list, tool) {
  736. if get_ban == "true" {
  737. return false
  738. }
  739. }
  740. }
  741. if acl_data == "all" || acl_data == "ban" {
  742. return true
  743. } else if acl_data == "user" {
  744. if !ip_or_user {
  745. return true
  746. }
  747. } else if acl_data == "admin" {
  748. if auth_info["treat_as_admin"] {
  749. return true
  750. }
  751. } else if acl_data == "50_edit" {
  752. if !ip_or_user {
  753. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  754. if err != nil {
  755. log.Fatal(err)
  756. }
  757. defer stmt.Close()
  758. var count int
  759. err = stmt.QueryRow(ip).Scan(&count)
  760. if err != nil {
  761. if err == sql.ErrNoRows {
  762. count = 0
  763. } else {
  764. log.Fatal(err)
  765. }
  766. }
  767. if count >= 50 {
  768. return true
  769. }
  770. }
  771. } else if acl_data == "before" {
  772. stmt, err := db.Prepare(DB_change("select ip from history where title = ? and ip = ?"))
  773. if err != nil {
  774. log.Fatal(err)
  775. }
  776. defer stmt.Close()
  777. var exist string
  778. err = stmt.QueryRow(name, ip).Scan(&exist)
  779. if err != nil {
  780. if err == sql.ErrNoRows {
  781. exist = ""
  782. } else {
  783. log.Fatal(err)
  784. }
  785. }
  786. if exist != "" {
  787. return true
  788. }
  789. } else if acl_data == "30_day" || acl_data == "90_day" {
  790. if !ip_or_user {
  791. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  792. if err != nil {
  793. log.Fatal(err)
  794. }
  795. defer stmt.Close()
  796. var signup_date string
  797. err = stmt.QueryRow(ip).Scan(&signup_date)
  798. if err != nil {
  799. if err == sql.ErrNoRows {
  800. signup_date = Get_time()
  801. } else {
  802. log.Fatal(err)
  803. }
  804. }
  805. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  806. if acl_data == "30_day" {
  807. time_1 = time_1.AddDate(0, 0, 30)
  808. } else {
  809. time_1 = time_1.AddDate(0, 0, 90)
  810. }
  811. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  812. if time_2.After(time_1) {
  813. return true
  814. }
  815. }
  816. } else if acl_data == "email" {
  817. if !ip_or_user {
  818. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'email'"))
  819. if err != nil {
  820. log.Fatal(err)
  821. }
  822. defer stmt.Close()
  823. var exist string
  824. err = stmt.QueryRow(ip).Scan(&exist)
  825. if err != nil {
  826. if err == sql.ErrNoRows {
  827. exist = ""
  828. } else {
  829. log.Fatal(err)
  830. }
  831. }
  832. if exist != "" {
  833. return true
  834. }
  835. }
  836. } else if acl_data == "owner" {
  837. if auth_info["owner"] {
  838. return true
  839. }
  840. } else if acl_data == "ban_admin" {
  841. if auth_info["treat_as_admin"] || get_ban == "true" {
  842. return true
  843. }
  844. } else if acl_data == "not_all" {
  845. return false
  846. } else if acl_data == "up_to_level_3" || acl_data == "up_to_level_10" {
  847. if acl_data == "up_to_level_3" {
  848. if level_int >= 3 {
  849. return true
  850. }
  851. } else if acl_data == "up_to_level_10" {
  852. if level_int >= 10 {
  853. return true
  854. }
  855. }
  856. } else if acl_data == "30_day_50_edit" {
  857. if !ip_or_user {
  858. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  859. if err != nil {
  860. log.Fatal(err)
  861. }
  862. defer stmt.Close()
  863. var signup_date string
  864. err = stmt.QueryRow(ip).Scan(&signup_date)
  865. if err != nil {
  866. if err == sql.ErrNoRows {
  867. signup_date = Get_time()
  868. } else {
  869. log.Fatal(err)
  870. }
  871. }
  872. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  873. time_1 = time_1.AddDate(0, 0, 30)
  874. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  875. if time_2.After(time_1) {
  876. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  877. if err != nil {
  878. log.Fatal(err)
  879. }
  880. defer stmt.Close()
  881. var count int
  882. err = stmt.QueryRow(ip).Scan(&count)
  883. if err != nil {
  884. if err == sql.ErrNoRows {
  885. count = 0
  886. } else {
  887. log.Fatal(err)
  888. }
  889. }
  890. if count >= 50 {
  891. return true
  892. }
  893. }
  894. }
  895. }
  896. return false
  897. } else if for_a == end_number-1 {
  898. if !Arr_in_str(except_ban_tool_list, tool) {
  899. if get_ban == "true" {
  900. return false
  901. }
  902. }
  903. if tool == "topic" {
  904. stmt, err := db.Prepare(DB_change("select title from rd where code = ? and stop != ''"))
  905. if err != nil {
  906. log.Fatal(err)
  907. }
  908. defer stmt.Close()
  909. var topic_state string
  910. err = stmt.QueryRow(topic_number).Scan(&topic_state)
  911. if err != nil {
  912. if err == sql.ErrNoRows {
  913. topic_state = ""
  914. } else {
  915. log.Fatal(err)
  916. }
  917. }
  918. if topic_state != "" {
  919. if auth_info["topic"] {
  920. return true
  921. } else {
  922. return false
  923. }
  924. } else {
  925. return true
  926. }
  927. } else {
  928. return true
  929. }
  930. }
  931. }
  932. return false
  933. }