acl_and_auth.go 23 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "strconv"
  6. "strings"
  7. "time"
  8. )
  9. func List_acl(func_type string) []string {
  10. if func_type == "user_document" {
  11. return []string{
  12. "",
  13. "user",
  14. "all",
  15. }
  16. } else {
  17. return []string{
  18. "",
  19. "all",
  20. "user",
  21. "admin",
  22. "owner",
  23. "50_edit",
  24. "email",
  25. "ban",
  26. "before",
  27. "30_day",
  28. "90_day",
  29. "ban_admin",
  30. "not_all",
  31. "up_to_level_3",
  32. "up_to_level_10",
  33. "30_day_50_edit",
  34. }
  35. }
  36. }
  37. func Do_insert_auth_history(db *sql.DB, ip string, what string) {
  38. var log_off string
  39. err := db.QueryRow(DB_change("select data from other where name = 'auth_history_off'")).Scan(&log_off)
  40. if err != nil {
  41. if err == sql.ErrNoRows {
  42. log_off = ""
  43. } else {
  44. log.Fatal(err)
  45. }
  46. }
  47. if log_off == "" {
  48. stmt, err := db.Prepare(DB_change("insert into re_admin (who, what, time) values (?, ?, ?)"))
  49. if err != nil {
  50. log.Fatal(err)
  51. }
  52. defer stmt.Close()
  53. time := Get_time()
  54. _, err = stmt.Exec(ip, what, time)
  55. if err != nil {
  56. log.Fatal(err)
  57. }
  58. }
  59. }
  60. func Get_user_auth(db *sql.DB, ip string) string {
  61. if !IP_or_user(ip) {
  62. var auth string
  63. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  64. if err != nil {
  65. log.Fatal(err)
  66. }
  67. defer stmt.Close()
  68. err = stmt.QueryRow(ip).Scan(&auth)
  69. if err != nil {
  70. if err == sql.ErrNoRows {
  71. auth = "user"
  72. } else {
  73. log.Fatal(err)
  74. }
  75. }
  76. if auth != "user" && auth != "ban" {
  77. return auth
  78. } else {
  79. return ""
  80. }
  81. }
  82. return ""
  83. }
  84. func Get_auth_group_info(db *sql.DB, auth string) map[string]bool {
  85. stmt, err := db.Prepare(DB_change("select acl from alist where name = ?"))
  86. if err != nil {
  87. log.Fatal(err)
  88. }
  89. defer stmt.Close()
  90. rows, err := stmt.Query(auth)
  91. if err != nil {
  92. log.Fatal(err)
  93. }
  94. defer rows.Close()
  95. data_list := map[string]bool{}
  96. for rows.Next() {
  97. var name string
  98. err := rows.Scan(&name)
  99. if err != nil {
  100. log.Fatal(err)
  101. }
  102. data_list[name] = true
  103. }
  104. return Check_auth(data_list)
  105. }
  106. func Check_auth(auth_info map[string]bool) map[string]bool {
  107. if _, ok := auth_info["owner"]; ok {
  108. auth_info["admin"] = true
  109. }
  110. admin_auth := []string{"ban", "toron", "check", "acl", "hidel", "give", "bbs"}
  111. if _, ok := auth_info["admin"]; ok {
  112. for _, v := range admin_auth {
  113. auth_info[v] = true
  114. }
  115. }
  116. check := false
  117. for _, v := range admin_auth {
  118. if _, ok := auth_info[v]; ok {
  119. check = true
  120. break
  121. }
  122. }
  123. if check {
  124. auth_info["admin_default_feature"] = true
  125. }
  126. admin_default_feature := []string{"treat_as_admin", "user_name_bold", "multiple_upload", "slow_edit_pass", "edit_bottom_compulsion_pass"}
  127. if _, ok := auth_info["admin_default_feature"]; ok {
  128. for _, v := range admin_default_feature {
  129. auth_info[v] = true
  130. }
  131. auth_info["user"] = true
  132. }
  133. return auth_info
  134. }
  135. func Check_acl(db *sql.DB, name string, topic_number string, tool string, ip string) bool {
  136. auth_name := Get_user_auth(db, ip)
  137. auth_info := Get_auth_group_info(db, auth_name)
  138. ip_or_user := IP_or_user(ip)
  139. level := "0"
  140. if !ip_or_user {
  141. level = Get_level(db, ip)[0]
  142. }
  143. level_int, _ := strconv.Atoi(level)
  144. get_ban := ""
  145. ban_type := ""
  146. if tool == "document_edit_request" {
  147. temp_arr := Get_user_ban(db, ip, "edit_request")
  148. get_ban = temp_arr[0]
  149. ban_type = temp_arr[1]
  150. } else {
  151. temp_arr := Get_user_ban(db, ip, "")
  152. get_ban = temp_arr[0]
  153. ban_type = temp_arr[1]
  154. }
  155. if ban_type != "" {
  156. ban_type_len := len(ban_type)
  157. if ban_type_len == 1 {
  158. ban_type = string(ban_type[0])
  159. } else if ban_type_len == 2 {
  160. ban_type = string(ban_type[1])
  161. }
  162. }
  163. if tool == "" && name != "" {
  164. if !Check_acl(db, name, "", "render", ip) {
  165. return false
  166. }
  167. if strings.HasPrefix(name, "user:") {
  168. user_page_str := name[5:]
  169. if slash_index := strings.Index(user_page_str, "/"); slash_index != -1 {
  170. user_page_str = user_page_str[:slash_index]
  171. }
  172. if auth_info["acl"] {
  173. return true
  174. }
  175. if get_ban == "true" {
  176. return false
  177. }
  178. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  179. if err != nil {
  180. log.Fatal(err)
  181. }
  182. defer stmt.Close()
  183. var acl_data string
  184. err = stmt.QueryRow(name).Scan(&acl_data)
  185. if err != nil {
  186. if err == sql.ErrNoRows {
  187. acl_data = ""
  188. } else {
  189. log.Fatal(err)
  190. }
  191. }
  192. if acl_data == "all" {
  193. return true
  194. } else if acl_data == "user" {
  195. if !ip_or_user {
  196. return true
  197. }
  198. } else if ip == user_page_str {
  199. if !ip_or_user {
  200. return true
  201. }
  202. }
  203. return false
  204. }
  205. }
  206. if Arr_in_str([]string{"document_edit", "document_edit_request", "document_move", "document_delete"}, tool) {
  207. if !Check_acl(db, name, topic_number, "", ip) {
  208. return false
  209. }
  210. } else if Arr_in_str([]string{"bbs_edit", "bbs_comment"}, tool) {
  211. if !Check_acl(db, name, topic_number, "bbs_view", ip) {
  212. return false
  213. }
  214. }
  215. if tool == "topic" {
  216. if name == "" {
  217. stmt, err := db.Prepare(DB_change("select title from rd where code = ?"))
  218. if err != nil {
  219. log.Fatal(err)
  220. }
  221. defer stmt.Close()
  222. err = stmt.QueryRow(topic_number).Scan(&name)
  223. if err != nil {
  224. if err == sql.ErrNoRows {
  225. name = "test"
  226. } else {
  227. log.Fatal(err)
  228. }
  229. }
  230. }
  231. }
  232. end_number := 1
  233. for for_a := 0; for_a < end_number; for_a++ {
  234. acl_data := ""
  235. acl_pass_auth := ""
  236. if tool == "all_admin_auth" {
  237. acl_pass_auth = "treat_as_admin"
  238. acl_data = "owner"
  239. } else if tool == "owner_auth" {
  240. acl_pass_auth = "owner"
  241. acl_data = "owner"
  242. } else if tool == "ban_auth" {
  243. acl_pass_auth = "bbs"
  244. acl_data = "owner"
  245. } else if tool == "toron_auth" {
  246. acl_pass_auth = "toron"
  247. acl_data = "owner"
  248. } else if tool == "check_auth" {
  249. acl_pass_auth = "check"
  250. acl_data = "owner"
  251. } else if tool == "acl_auth" {
  252. acl_pass_auth = "acl"
  253. acl_data = "owner"
  254. } else if tool == "hidel_auth" {
  255. acl_pass_auth = "hidel"
  256. acl_data = "owner"
  257. } else if tool == "give_auth" {
  258. acl_pass_auth = "give"
  259. acl_data = "owner"
  260. } else if tool == "" {
  261. acl_pass_auth = "acl"
  262. if for_a == 0 {
  263. end_number += 1
  264. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  265. if err != nil {
  266. log.Fatal(err)
  267. }
  268. defer stmt.Close()
  269. err = stmt.QueryRow(name).Scan(&acl_data)
  270. if err != nil {
  271. if err == sql.ErrNoRows {
  272. acl_data = ""
  273. } else {
  274. log.Fatal(err)
  275. }
  276. }
  277. } else {
  278. err := db.QueryRow(DB_change("select data from other where name = 'edit'")).Scan(&acl_data)
  279. if err != nil {
  280. if err == sql.ErrNoRows {
  281. acl_data = ""
  282. } else {
  283. log.Fatal(err)
  284. }
  285. }
  286. }
  287. } else if tool == "document_move" {
  288. acl_pass_auth = "acl"
  289. if for_a == 0 {
  290. end_number += 1
  291. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_move_acl'"))
  292. if err != nil {
  293. log.Fatal(err)
  294. }
  295. defer stmt.Close()
  296. err = stmt.QueryRow(name).Scan(&acl_data)
  297. if err != nil {
  298. if err == sql.ErrNoRows {
  299. acl_data = ""
  300. } else {
  301. log.Fatal(err)
  302. }
  303. }
  304. } else {
  305. err := db.QueryRow(DB_change("select data from other where name = 'document_move_acl'")).Scan(&acl_data)
  306. if err != nil {
  307. if err == sql.ErrNoRows {
  308. acl_data = ""
  309. } else {
  310. log.Fatal(err)
  311. }
  312. }
  313. }
  314. } else if tool == "document_edit" {
  315. acl_pass_auth = "acl"
  316. if for_a == 0 {
  317. end_number += 1
  318. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_acl'"))
  319. if err != nil {
  320. log.Fatal(err)
  321. }
  322. defer stmt.Close()
  323. err = stmt.QueryRow(name).Scan(&acl_data)
  324. if err != nil {
  325. if err == sql.ErrNoRows {
  326. acl_data = ""
  327. } else {
  328. log.Fatal(err)
  329. }
  330. }
  331. } else {
  332. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_acl'")).Scan(&acl_data)
  333. if err != nil {
  334. if err == sql.ErrNoRows {
  335. acl_data = ""
  336. } else {
  337. log.Fatal(err)
  338. }
  339. }
  340. }
  341. } else if tool == "document_edit" {
  342. acl_pass_auth = "acl"
  343. if for_a == 0 {
  344. end_number += 1
  345. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_delete_acl'"))
  346. if err != nil {
  347. log.Fatal(err)
  348. }
  349. defer stmt.Close()
  350. err = stmt.QueryRow(name).Scan(&acl_data)
  351. if err != nil {
  352. if err == sql.ErrNoRows {
  353. acl_data = ""
  354. } else {
  355. log.Fatal(err)
  356. }
  357. }
  358. } else {
  359. err := db.QueryRow(DB_change("select data from other where name = 'document_delete_acl'")).Scan(&acl_data)
  360. if err != nil {
  361. if err == sql.ErrNoRows {
  362. acl_data = ""
  363. } else {
  364. log.Fatal(err)
  365. }
  366. }
  367. }
  368. } else if tool == "topic" {
  369. acl_pass_auth = "topic"
  370. if for_a == 0 {
  371. end_number += 1
  372. stmt, err := db.Prepare(DB_change("select acl from rd where code = ?"))
  373. if err != nil {
  374. log.Fatal(err)
  375. }
  376. defer stmt.Close()
  377. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  378. if err != nil {
  379. if err == sql.ErrNoRows {
  380. acl_data = ""
  381. } else {
  382. log.Fatal(err)
  383. }
  384. }
  385. } else if for_a == 1 {
  386. end_number += 1
  387. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'dis'"))
  388. if err != nil {
  389. log.Fatal(err)
  390. }
  391. defer stmt.Close()
  392. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  393. if err != nil {
  394. if err == sql.ErrNoRows {
  395. acl_data = ""
  396. } else {
  397. log.Fatal(err)
  398. }
  399. }
  400. } else {
  401. err := db.QueryRow(DB_change("select data from other where name = 'discussion'")).Scan(&acl_data)
  402. if err != nil {
  403. if err == sql.ErrNoRows {
  404. acl_data = ""
  405. } else {
  406. log.Fatal(err)
  407. }
  408. }
  409. }
  410. } else if tool == "topic_view" {
  411. acl_pass_auth = "topic"
  412. stmt, err := db.Prepare(DB_change("select set_data from topic_set where thread_code = ? and set_name = 'thread_view_acl'"))
  413. if err != nil {
  414. log.Fatal(err)
  415. }
  416. defer stmt.Close()
  417. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  418. if err != nil {
  419. if err == sql.ErrNoRows {
  420. acl_data = ""
  421. } else {
  422. log.Fatal(err)
  423. }
  424. }
  425. } else if tool == "upload" {
  426. acl_pass_auth = "multiple_upload"
  427. err := db.QueryRow(DB_change("select data from other where name = 'upload_acl'")).Scan(&acl_data)
  428. if err != nil {
  429. if err == sql.ErrNoRows {
  430. acl_data = ""
  431. } else {
  432. log.Fatal(err)
  433. }
  434. }
  435. } else if tool == "many_upload" {
  436. acl_pass_auth = "multiple_upload"
  437. err := db.QueryRow(DB_change("select data from other where name = 'many_upload_acl'")).Scan(&acl_data)
  438. if err != nil {
  439. if err == sql.ErrNoRows {
  440. acl_data = ""
  441. } else {
  442. log.Fatal(err)
  443. }
  444. }
  445. } else if tool == "vote" {
  446. acl_pass_auth = "owner"
  447. if for_a == 0 {
  448. end_number += 1
  449. if topic_number != "" {
  450. stmt, err := db.Prepare(DB_change("select acl from vote where id = ? and user = ''"))
  451. if err != nil {
  452. log.Fatal(err)
  453. }
  454. defer stmt.Close()
  455. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  456. if err != nil {
  457. if err == sql.ErrNoRows {
  458. acl_data = ""
  459. } else {
  460. log.Fatal(err)
  461. }
  462. }
  463. } else {
  464. continue
  465. }
  466. } else {
  467. err := db.QueryRow(DB_change("select data from other where name = 'vote_acl'")).Scan(&acl_data)
  468. if err != nil {
  469. if err == sql.ErrNoRows {
  470. acl_data = ""
  471. } else {
  472. log.Fatal(err)
  473. }
  474. }
  475. }
  476. } else if tool == "slow_edit" {
  477. acl_pass_auth = "slow_edit_pass"
  478. err := db.QueryRow(DB_change("select data from other where name = 'slow_edit_acl'")).Scan(&acl_data)
  479. if err != nil {
  480. if err == sql.ErrNoRows {
  481. acl_data = ""
  482. } else {
  483. log.Fatal(err)
  484. }
  485. }
  486. } else if tool == "edit_bottom_compulsion" {
  487. acl_pass_auth = "edit_bottom_compulsion_pass"
  488. err := db.QueryRow(DB_change("select data from other where name = 'edit_bottom_compulsion_acl'")).Scan(&acl_data)
  489. if err != nil {
  490. if err == sql.ErrNoRows {
  491. acl_data = ""
  492. } else {
  493. log.Fatal(err)
  494. }
  495. }
  496. } else if tool == "bbs_edit" {
  497. acl_pass_auth = "bbs"
  498. if for_a == 0 {
  499. end_number += 1
  500. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl' and set_id = ?"))
  501. if err != nil {
  502. log.Fatal(err)
  503. }
  504. defer stmt.Close()
  505. err = stmt.QueryRow(name).Scan(&acl_data)
  506. if err != nil {
  507. if err == sql.ErrNoRows {
  508. acl_data = ""
  509. } else {
  510. log.Fatal(err)
  511. }
  512. }
  513. } else if for_a == 1 {
  514. end_number += 1
  515. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  516. if err != nil {
  517. log.Fatal(err)
  518. }
  519. defer stmt.Close()
  520. err = stmt.QueryRow(name).Scan(&acl_data)
  521. if err != nil {
  522. if err == sql.ErrNoRows {
  523. acl_data = ""
  524. } else {
  525. log.Fatal(err)
  526. }
  527. }
  528. } else if for_a == 2 {
  529. end_number += 1
  530. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl_all'")).Scan(&acl_data)
  531. if err != nil {
  532. if err == sql.ErrNoRows {
  533. acl_data = ""
  534. } else {
  535. log.Fatal(err)
  536. }
  537. }
  538. } else {
  539. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  540. if err != nil {
  541. if err == sql.ErrNoRows {
  542. acl_data = ""
  543. } else {
  544. log.Fatal(err)
  545. }
  546. }
  547. }
  548. } else if tool == "bbs_comment" {
  549. acl_pass_auth = "bbs"
  550. if for_a == 0 {
  551. end_number += 1
  552. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl' and set_id = ?"))
  553. if err != nil {
  554. log.Fatal(err)
  555. }
  556. defer stmt.Close()
  557. err = stmt.QueryRow(name).Scan(&acl_data)
  558. if err != nil {
  559. if err == sql.ErrNoRows {
  560. acl_data = ""
  561. } else {
  562. log.Fatal(err)
  563. }
  564. }
  565. } else if for_a == 1 {
  566. end_number += 1
  567. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  568. if err != nil {
  569. log.Fatal(err)
  570. }
  571. defer stmt.Close()
  572. err = stmt.QueryRow(name).Scan(&acl_data)
  573. if err != nil {
  574. if err == sql.ErrNoRows {
  575. acl_data = ""
  576. } else {
  577. log.Fatal(err)
  578. }
  579. }
  580. } else if for_a == 2 {
  581. end_number += 1
  582. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl_all'")).Scan(&acl_data)
  583. if err != nil {
  584. if err == sql.ErrNoRows {
  585. acl_data = ""
  586. } else {
  587. log.Fatal(err)
  588. }
  589. }
  590. } else {
  591. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  592. if err != nil {
  593. if err == sql.ErrNoRows {
  594. acl_data = ""
  595. } else {
  596. log.Fatal(err)
  597. }
  598. }
  599. }
  600. } else if tool == "bbs_view" {
  601. acl_pass_auth = "bbs"
  602. if for_a == 0 {
  603. end_number += 1
  604. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl' and set_id = ?"))
  605. if err != nil {
  606. log.Fatal(err)
  607. }
  608. defer stmt.Close()
  609. err = stmt.QueryRow(name).Scan(&acl_data)
  610. if err != nil {
  611. if err == sql.ErrNoRows {
  612. acl_data = ""
  613. } else {
  614. log.Fatal(err)
  615. }
  616. }
  617. } else {
  618. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl_all'")).Scan(&acl_data)
  619. if err != nil {
  620. if err == sql.ErrNoRows {
  621. acl_data = ""
  622. } else {
  623. log.Fatal(err)
  624. }
  625. }
  626. }
  627. } else if tool == "recaptcha" {
  628. acl_pass_auth = "captcha_pass"
  629. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_pass_acl'")).Scan(&acl_data)
  630. if err != nil {
  631. if err == sql.ErrNoRows {
  632. acl_data = ""
  633. } else {
  634. log.Fatal(err)
  635. }
  636. }
  637. } else if tool == "recaptcha_five_pass" {
  638. acl_pass_auth = "captcha_one_check_five_pass"
  639. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_one_check_five_pass_acl'")).Scan(&acl_data)
  640. if err != nil {
  641. if err == sql.ErrNoRows {
  642. acl_data = ""
  643. } else {
  644. log.Fatal(err)
  645. }
  646. }
  647. } else if tool == "document_edit_request" {
  648. acl_pass_auth = "acl"
  649. if for_a == 0 {
  650. end_number += 1
  651. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_request_acl'"))
  652. if err != nil {
  653. log.Fatal(err)
  654. }
  655. defer stmt.Close()
  656. err = stmt.QueryRow(name).Scan(&acl_data)
  657. if err != nil {
  658. if err == sql.ErrNoRows {
  659. acl_data = ""
  660. } else {
  661. log.Fatal(err)
  662. }
  663. }
  664. } else {
  665. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_request_acl'")).Scan(&acl_data)
  666. if err != nil {
  667. if err == sql.ErrNoRows {
  668. acl_data = ""
  669. } else {
  670. log.Fatal(err)
  671. }
  672. }
  673. }
  674. } else if tool == "document_make_acl" {
  675. acl_pass_auth = "acl"
  676. err := db.QueryRow(DB_change("select data from other where name = 'document_make_acl'")).Scan(&acl_data)
  677. if err != nil {
  678. if err == sql.ErrNoRows {
  679. acl_data = ""
  680. } else {
  681. log.Fatal(err)
  682. }
  683. }
  684. } else {
  685. // tool == "render"
  686. acl_pass_auth = "acl"
  687. if for_a == 0 {
  688. end_number += 1
  689. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'view'"))
  690. if err != nil {
  691. log.Fatal(err)
  692. }
  693. defer stmt.Close()
  694. err = stmt.QueryRow(name).Scan(&acl_data)
  695. if err != nil {
  696. if err == sql.ErrNoRows {
  697. acl_data = ""
  698. } else {
  699. log.Fatal(err)
  700. }
  701. }
  702. } else {
  703. err := db.QueryRow(DB_change("select data from other where name = 'all_view_acl'")).Scan(&acl_data)
  704. if err != nil {
  705. if err == sql.ErrNoRows {
  706. acl_data = ""
  707. } else {
  708. log.Fatal(err)
  709. }
  710. }
  711. }
  712. }
  713. if auth_info[acl_pass_auth] {
  714. return true
  715. } else if ban_type == "4" {
  716. return false
  717. }
  718. if acl_data == "" {
  719. if tool == "recaptcha" {
  720. acl_data = "admin"
  721. } else if tool == "slow_edit" || tool == "edit_bottom_compulsion" {
  722. acl_data = "not_all"
  723. } else {
  724. acl_data = "normal"
  725. }
  726. }
  727. except_ban_tool_list := []string{"render", "topic_view", "bbs_view"}
  728. if acl_data != "normal" {
  729. if !(acl_data == "ban" || acl_data == "ban_admin") || ban_type == "3" {
  730. if !Arr_in_str(except_ban_tool_list, tool) {
  731. if get_ban == "true" {
  732. return false
  733. }
  734. }
  735. }
  736. if acl_data == "all" || acl_data == "ban" {
  737. return true
  738. } else if acl_data == "user" {
  739. if !ip_or_user {
  740. return true
  741. }
  742. } else if acl_data == "admin" {
  743. if auth_info["treat_as_admin"] {
  744. return true
  745. }
  746. } else if acl_data == "50_edit" {
  747. if !ip_or_user {
  748. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  749. if err != nil {
  750. log.Fatal(err)
  751. }
  752. defer stmt.Close()
  753. var count int
  754. err = stmt.QueryRow(ip).Scan(&count)
  755. if err != nil {
  756. if err == sql.ErrNoRows {
  757. count = 0
  758. } else {
  759. log.Fatal(err)
  760. }
  761. }
  762. if count >= 50 {
  763. return true
  764. }
  765. }
  766. } else if acl_data == "before" {
  767. stmt, err := db.Prepare(DB_change("select ip from history where title = ? and ip = ?"))
  768. if err != nil {
  769. log.Fatal(err)
  770. }
  771. defer stmt.Close()
  772. var exist string
  773. err = stmt.QueryRow(name, ip).Scan(&exist)
  774. if err != nil {
  775. if err == sql.ErrNoRows {
  776. exist = ""
  777. } else {
  778. log.Fatal(err)
  779. }
  780. }
  781. if exist != "" {
  782. return true
  783. }
  784. } else if acl_data == "30_day" || acl_data == "90_day" {
  785. if !ip_or_user {
  786. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  787. if err != nil {
  788. log.Fatal(err)
  789. }
  790. defer stmt.Close()
  791. var signup_date string
  792. err = stmt.QueryRow(ip).Scan(&signup_date)
  793. if err != nil {
  794. if err == sql.ErrNoRows {
  795. signup_date = Get_time()
  796. } else {
  797. log.Fatal(err)
  798. }
  799. }
  800. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  801. if acl_data == "30_day" {
  802. time_1 = time_1.AddDate(0, 0, 30)
  803. } else {
  804. time_1 = time_1.AddDate(0, 0, 90)
  805. }
  806. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  807. if time_2.After(time_1) {
  808. return true
  809. }
  810. }
  811. } else if acl_data == "email" {
  812. if !ip_or_user {
  813. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'email'"))
  814. if err != nil {
  815. log.Fatal(err)
  816. }
  817. defer stmt.Close()
  818. var exist string
  819. err = stmt.QueryRow(ip).Scan(&exist)
  820. if err != nil {
  821. if err == sql.ErrNoRows {
  822. exist = ""
  823. } else {
  824. log.Fatal(err)
  825. }
  826. }
  827. if exist != "" {
  828. return true
  829. }
  830. }
  831. } else if acl_data == "owner" {
  832. if auth_info["owner"] {
  833. return true
  834. }
  835. } else if acl_data == "ban_admin" {
  836. if auth_info["treat_as_admin"] || get_ban == "true" {
  837. return true
  838. }
  839. } else if acl_data == "not_all" {
  840. return false
  841. } else if acl_data == "up_to_level_3" || acl_data == "up_to_level_10" {
  842. if acl_data == "up_to_level_3" {
  843. if level_int >= 3 {
  844. return true
  845. }
  846. } else if acl_data == "up_to_level_10" {
  847. if level_int >= 10 {
  848. return true
  849. }
  850. }
  851. } else if acl_data == "30_day_50_edit" {
  852. if !ip_or_user {
  853. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  854. if err != nil {
  855. log.Fatal(err)
  856. }
  857. defer stmt.Close()
  858. var signup_date string
  859. err = stmt.QueryRow(ip).Scan(&signup_date)
  860. if err != nil {
  861. if err == sql.ErrNoRows {
  862. signup_date = Get_time()
  863. } else {
  864. log.Fatal(err)
  865. }
  866. }
  867. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  868. time_1 = time_1.AddDate(0, 0, 30)
  869. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  870. if time_2.After(time_1) {
  871. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  872. if err != nil {
  873. log.Fatal(err)
  874. }
  875. defer stmt.Close()
  876. var count int
  877. err = stmt.QueryRow(ip).Scan(&count)
  878. if err != nil {
  879. if err == sql.ErrNoRows {
  880. count = 0
  881. } else {
  882. log.Fatal(err)
  883. }
  884. }
  885. if count >= 50 {
  886. return true
  887. }
  888. }
  889. }
  890. }
  891. return false
  892. } else if for_a == end_number-1 {
  893. if !Arr_in_str(except_ban_tool_list, tool) {
  894. if get_ban == "true" {
  895. return false
  896. }
  897. }
  898. if tool == "topic" {
  899. stmt, err := db.Prepare(DB_change("select title from rd where code = ? and stop != ''"))
  900. if err != nil {
  901. log.Fatal(err)
  902. }
  903. defer stmt.Close()
  904. var topic_state string
  905. err = stmt.QueryRow(topic_number).Scan(&topic_state)
  906. if err != nil {
  907. if err == sql.ErrNoRows {
  908. topic_state = ""
  909. } else {
  910. log.Fatal(err)
  911. }
  912. }
  913. if topic_state != "" {
  914. if auth_info["topic"] {
  915. return true
  916. } else {
  917. return false
  918. }
  919. } else {
  920. return true
  921. }
  922. } else {
  923. return true
  924. }
  925. }
  926. }
  927. return false
  928. }