acl_and_auth.go 23 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "strconv"
  6. "strings"
  7. "time"
  8. )
  9. func List_acl(func_type string) []string {
  10. if func_type == "user_document" {
  11. return []string{
  12. "",
  13. "user",
  14. "all",
  15. }
  16. } else {
  17. return []string{
  18. "",
  19. "all",
  20. "user",
  21. "admin",
  22. "owner",
  23. "50_edit",
  24. "email",
  25. "ban",
  26. "before",
  27. "30_day",
  28. "90_day",
  29. "ban_admin",
  30. "not_all",
  31. "up_to_level_3",
  32. "up_to_level_10",
  33. "30_day_50_edit",
  34. }
  35. }
  36. }
  37. func Do_insert_auth_history(db *sql.DB, ip string, what string) {
  38. var log_off string
  39. err := db.QueryRow(DB_change("select data from other where name = 'auth_history_off'")).Scan(&log_off)
  40. if err != nil {
  41. if err == sql.ErrNoRows {
  42. log_off = ""
  43. } else {
  44. log.Fatal(err)
  45. }
  46. }
  47. if log_off == "" {
  48. stmt, err := db.Prepare(DB_change("insert into re_admin (who, what, time) values (?, ?, ?)"))
  49. if err != nil {
  50. log.Fatal(err)
  51. }
  52. defer stmt.Close()
  53. time := Get_time()
  54. _, err = stmt.Exec(ip, what, time)
  55. if err != nil {
  56. log.Fatal(err)
  57. }
  58. }
  59. }
  60. func Get_user_auth(db *sql.DB, ip string) string {
  61. if !IP_or_user(ip) {
  62. var auth string
  63. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  64. if err != nil {
  65. log.Fatal(err)
  66. }
  67. defer stmt.Close()
  68. err = stmt.QueryRow(ip).Scan(&auth)
  69. if err != nil {
  70. if err == sql.ErrNoRows {
  71. auth = "user"
  72. } else {
  73. log.Fatal(err)
  74. }
  75. }
  76. if auth != "user" && auth != "ban" {
  77. return auth
  78. } else {
  79. return ""
  80. }
  81. }
  82. return ""
  83. }
  84. func Get_auth_group_info(db *sql.DB, auth string) map[string]bool {
  85. stmt, err := db.Prepare(DB_change("select acl from alist where name = ?"))
  86. if err != nil {
  87. log.Fatal(err)
  88. }
  89. defer stmt.Close()
  90. rows, err := stmt.Query(auth)
  91. if err != nil {
  92. log.Fatal(err)
  93. }
  94. defer rows.Close()
  95. data_list := map[string]bool{}
  96. for rows.Next() {
  97. var name string
  98. err := rows.Scan(&name)
  99. if err != nil {
  100. log.Fatal(err)
  101. }
  102. data_list[name] = true
  103. }
  104. return Check_auth(data_list)
  105. }
  106. func Check_auth(auth_info map[string]bool) map[string]bool {
  107. if _, ok := auth_info["owner"]; ok {
  108. auth_info["admin"] = true
  109. }
  110. admin_auth := []string{"ban", "toron", "check", "acl", "hidel", "give", "bbs", "vote"}
  111. if _, ok := auth_info["admin"]; ok {
  112. for _, v := range admin_auth {
  113. auth_info[v] = true
  114. }
  115. }
  116. check := false
  117. for _, v := range admin_auth {
  118. if _, ok := auth_info[v]; ok {
  119. check = true
  120. break
  121. }
  122. }
  123. if check {
  124. auth_info["admin_default_feature"] = true
  125. }
  126. admin_default_feature := []string{"treat_as_admin", "user_name_bold", "multiple_upload", "slow_edit_pass", "edit_bottom_compulsion_pass"}
  127. if _, ok := auth_info["admin_default_feature"]; ok {
  128. for _, v := range admin_default_feature {
  129. auth_info[v] = true
  130. }
  131. auth_info["user"] = true
  132. }
  133. return auth_info
  134. }
  135. func Check_acl(db *sql.DB, name string, topic_number string, tool string, ip string) bool {
  136. auth_name := Get_user_auth(db, ip)
  137. auth_info := Get_auth_group_info(db, auth_name)
  138. ip_or_user := IP_or_user(ip)
  139. level := "0"
  140. if !ip_or_user {
  141. level = Get_level(db, ip)[0]
  142. }
  143. level_int, _ := strconv.Atoi(level)
  144. get_ban := ""
  145. ban_type := ""
  146. if tool == "document_edit_request" {
  147. temp_arr := Get_user_ban(db, ip, "edit_request")
  148. get_ban = temp_arr[0]
  149. ban_type = temp_arr[1]
  150. } else {
  151. temp_arr := Get_user_ban(db, ip, "")
  152. get_ban = temp_arr[0]
  153. ban_type = temp_arr[1]
  154. }
  155. if ban_type != "" {
  156. ban_type_len := len(ban_type)
  157. if ban_type_len == 1 {
  158. ban_type = string(ban_type[0])
  159. } else if ban_type_len == 2 {
  160. ban_type = string(ban_type[1])
  161. }
  162. }
  163. if tool == "" && name != "" {
  164. if !Check_acl(db, name, "", "render", ip) {
  165. return false
  166. }
  167. if strings.HasPrefix(name, "user:") {
  168. user_page_str := name[5:]
  169. if slash_index := strings.Index(user_page_str, "/"); slash_index != -1 {
  170. user_page_str = user_page_str[:slash_index]
  171. }
  172. if auth_info["acl"] {
  173. return true
  174. }
  175. if get_ban == "true" {
  176. return false
  177. }
  178. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  179. if err != nil {
  180. log.Fatal(err)
  181. }
  182. defer stmt.Close()
  183. var acl_data string
  184. err = stmt.QueryRow(name).Scan(&acl_data)
  185. if err != nil {
  186. if err == sql.ErrNoRows {
  187. acl_data = ""
  188. } else {
  189. log.Fatal(err)
  190. }
  191. }
  192. if acl_data == "all" {
  193. return true
  194. } else if acl_data == "user" {
  195. if !ip_or_user {
  196. return true
  197. }
  198. } else if ip == user_page_str {
  199. if !ip_or_user {
  200. return true
  201. }
  202. }
  203. return false
  204. }
  205. }
  206. if Arr_in_str([]string{"document_edit", "document_edit_request", "document_move", "document_delete"}, tool) {
  207. if !Check_acl(db, name, topic_number, "", ip) {
  208. return false
  209. }
  210. } else if Arr_in_str([]string{"bbs_edit", "bbs_comment"}, tool) {
  211. if !Check_acl(db, name, topic_number, "bbs_view", ip) {
  212. return false
  213. }
  214. }
  215. if tool == "topic" {
  216. if name == "" {
  217. stmt, err := db.Prepare(DB_change("select title from rd where code = ?"))
  218. if err != nil {
  219. log.Fatal(err)
  220. }
  221. defer stmt.Close()
  222. err = stmt.QueryRow(topic_number).Scan(&name)
  223. if err != nil {
  224. if err == sql.ErrNoRows {
  225. name = "test"
  226. } else {
  227. log.Fatal(err)
  228. }
  229. }
  230. }
  231. }
  232. end_number := 1
  233. for for_a := 0; for_a < end_number; for_a++ {
  234. acl_data := ""
  235. acl_pass_auth := ""
  236. if tool == "all_admin_auth" {
  237. acl_pass_auth = "treat_as_admin"
  238. acl_data = "owner"
  239. } else if tool == "owner_auth" {
  240. acl_pass_auth = "owner"
  241. acl_data = "owner"
  242. } else if tool == "ban_auth" {
  243. acl_pass_auth = "bbs"
  244. acl_data = "owner"
  245. } else if tool == "toron_auth" {
  246. acl_pass_auth = "toron"
  247. acl_data = "owner"
  248. } else if tool == "check_auth" {
  249. acl_pass_auth = "check"
  250. acl_data = "owner"
  251. } else if tool == "acl_auth" {
  252. acl_pass_auth = "acl"
  253. acl_data = "owner"
  254. } else if tool == "hidel_auth" {
  255. acl_pass_auth = "hidel"
  256. acl_data = "owner"
  257. } else if tool == "give_auth" {
  258. acl_pass_auth = "give"
  259. acl_data = "owner"
  260. } else if tool == "vote_auth" {
  261. acl_pass_auth = "vote_fix"
  262. acl_data = "owner"
  263. } else if tool == "" {
  264. acl_pass_auth = "acl"
  265. if for_a == 0 {
  266. end_number += 1
  267. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  268. if err != nil {
  269. log.Fatal(err)
  270. }
  271. defer stmt.Close()
  272. err = stmt.QueryRow(name).Scan(&acl_data)
  273. if err != nil {
  274. if err == sql.ErrNoRows {
  275. acl_data = ""
  276. } else {
  277. log.Fatal(err)
  278. }
  279. }
  280. } else {
  281. err := db.QueryRow(DB_change("select data from other where name = 'edit'")).Scan(&acl_data)
  282. if err != nil {
  283. if err == sql.ErrNoRows {
  284. acl_data = ""
  285. } else {
  286. log.Fatal(err)
  287. }
  288. }
  289. }
  290. } else if tool == "document_move" {
  291. acl_pass_auth = "acl"
  292. if for_a == 0 {
  293. end_number += 1
  294. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_move_acl'"))
  295. if err != nil {
  296. log.Fatal(err)
  297. }
  298. defer stmt.Close()
  299. err = stmt.QueryRow(name).Scan(&acl_data)
  300. if err != nil {
  301. if err == sql.ErrNoRows {
  302. acl_data = ""
  303. } else {
  304. log.Fatal(err)
  305. }
  306. }
  307. } else {
  308. err := db.QueryRow(DB_change("select data from other where name = 'document_move_acl'")).Scan(&acl_data)
  309. if err != nil {
  310. if err == sql.ErrNoRows {
  311. acl_data = ""
  312. } else {
  313. log.Fatal(err)
  314. }
  315. }
  316. }
  317. } else if tool == "document_edit" {
  318. acl_pass_auth = "acl"
  319. if for_a == 0 {
  320. end_number += 1
  321. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_acl'"))
  322. if err != nil {
  323. log.Fatal(err)
  324. }
  325. defer stmt.Close()
  326. err = stmt.QueryRow(name).Scan(&acl_data)
  327. if err != nil {
  328. if err == sql.ErrNoRows {
  329. acl_data = ""
  330. } else {
  331. log.Fatal(err)
  332. }
  333. }
  334. } else {
  335. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_acl'")).Scan(&acl_data)
  336. if err != nil {
  337. if err == sql.ErrNoRows {
  338. acl_data = ""
  339. } else {
  340. log.Fatal(err)
  341. }
  342. }
  343. }
  344. } else if tool == "document_edit" {
  345. acl_pass_auth = "acl"
  346. if for_a == 0 {
  347. end_number += 1
  348. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_delete_acl'"))
  349. if err != nil {
  350. log.Fatal(err)
  351. }
  352. defer stmt.Close()
  353. err = stmt.QueryRow(name).Scan(&acl_data)
  354. if err != nil {
  355. if err == sql.ErrNoRows {
  356. acl_data = ""
  357. } else {
  358. log.Fatal(err)
  359. }
  360. }
  361. } else {
  362. err := db.QueryRow(DB_change("select data from other where name = 'document_delete_acl'")).Scan(&acl_data)
  363. if err != nil {
  364. if err == sql.ErrNoRows {
  365. acl_data = ""
  366. } else {
  367. log.Fatal(err)
  368. }
  369. }
  370. }
  371. } else if tool == "topic" {
  372. acl_pass_auth = "topic"
  373. if for_a == 0 {
  374. end_number += 1
  375. stmt, err := db.Prepare(DB_change("select acl from rd where code = ?"))
  376. if err != nil {
  377. log.Fatal(err)
  378. }
  379. defer stmt.Close()
  380. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  381. if err != nil {
  382. if err == sql.ErrNoRows {
  383. acl_data = ""
  384. } else {
  385. log.Fatal(err)
  386. }
  387. }
  388. } else if for_a == 1 {
  389. end_number += 1
  390. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'dis'"))
  391. if err != nil {
  392. log.Fatal(err)
  393. }
  394. defer stmt.Close()
  395. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  396. if err != nil {
  397. if err == sql.ErrNoRows {
  398. acl_data = ""
  399. } else {
  400. log.Fatal(err)
  401. }
  402. }
  403. } else {
  404. err := db.QueryRow(DB_change("select data from other where name = 'discussion'")).Scan(&acl_data)
  405. if err != nil {
  406. if err == sql.ErrNoRows {
  407. acl_data = ""
  408. } else {
  409. log.Fatal(err)
  410. }
  411. }
  412. }
  413. } else if tool == "topic_view" {
  414. acl_pass_auth = "topic"
  415. stmt, err := db.Prepare(DB_change("select set_data from topic_set where thread_code = ? and set_name = 'thread_view_acl'"))
  416. if err != nil {
  417. log.Fatal(err)
  418. }
  419. defer stmt.Close()
  420. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  421. if err != nil {
  422. if err == sql.ErrNoRows {
  423. acl_data = ""
  424. } else {
  425. log.Fatal(err)
  426. }
  427. }
  428. } else if tool == "upload" {
  429. acl_pass_auth = "multiple_upload"
  430. err := db.QueryRow(DB_change("select data from other where name = 'upload_acl'")).Scan(&acl_data)
  431. if err != nil {
  432. if err == sql.ErrNoRows {
  433. acl_data = ""
  434. } else {
  435. log.Fatal(err)
  436. }
  437. }
  438. } else if tool == "many_upload" {
  439. acl_pass_auth = "multiple_upload"
  440. err := db.QueryRow(DB_change("select data from other where name = 'many_upload_acl'")).Scan(&acl_data)
  441. if err != nil {
  442. if err == sql.ErrNoRows {
  443. acl_data = ""
  444. } else {
  445. log.Fatal(err)
  446. }
  447. }
  448. } else if tool == "vote" {
  449. acl_pass_auth = "vote_fix"
  450. if for_a == 0 {
  451. end_number += 1
  452. if topic_number != "" {
  453. stmt, err := db.Prepare(DB_change("select acl from vote where id = ? and user = ''"))
  454. if err != nil {
  455. log.Fatal(err)
  456. }
  457. defer stmt.Close()
  458. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  459. if err != nil {
  460. if err == sql.ErrNoRows {
  461. acl_data = ""
  462. } else {
  463. log.Fatal(err)
  464. }
  465. }
  466. } else {
  467. continue
  468. }
  469. } else {
  470. err := db.QueryRow(DB_change("select data from other where name = 'vote_acl'")).Scan(&acl_data)
  471. if err != nil {
  472. if err == sql.ErrNoRows {
  473. acl_data = ""
  474. } else {
  475. log.Fatal(err)
  476. }
  477. }
  478. }
  479. } else if tool == "slow_edit" {
  480. acl_pass_auth = "slow_edit_pass"
  481. err := db.QueryRow(DB_change("select data from other where name = 'slow_edit_acl'")).Scan(&acl_data)
  482. if err != nil {
  483. if err == sql.ErrNoRows {
  484. acl_data = ""
  485. } else {
  486. log.Fatal(err)
  487. }
  488. }
  489. } else if tool == "edit_bottom_compulsion" {
  490. acl_pass_auth = "edit_bottom_compulsion_pass"
  491. err := db.QueryRow(DB_change("select data from other where name = 'edit_bottom_compulsion_acl'")).Scan(&acl_data)
  492. if err != nil {
  493. if err == sql.ErrNoRows {
  494. acl_data = ""
  495. } else {
  496. log.Fatal(err)
  497. }
  498. }
  499. } else if tool == "bbs_edit" {
  500. acl_pass_auth = "bbs"
  501. if for_a == 0 {
  502. end_number += 1
  503. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl' and set_id = ?"))
  504. if err != nil {
  505. log.Fatal(err)
  506. }
  507. defer stmt.Close()
  508. err = stmt.QueryRow(name).Scan(&acl_data)
  509. if err != nil {
  510. if err == sql.ErrNoRows {
  511. acl_data = ""
  512. } else {
  513. log.Fatal(err)
  514. }
  515. }
  516. } else if for_a == 1 {
  517. end_number += 1
  518. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  519. if err != nil {
  520. log.Fatal(err)
  521. }
  522. defer stmt.Close()
  523. err = stmt.QueryRow(name).Scan(&acl_data)
  524. if err != nil {
  525. if err == sql.ErrNoRows {
  526. acl_data = ""
  527. } else {
  528. log.Fatal(err)
  529. }
  530. }
  531. } else if for_a == 2 {
  532. end_number += 1
  533. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl_all'")).Scan(&acl_data)
  534. if err != nil {
  535. if err == sql.ErrNoRows {
  536. acl_data = ""
  537. } else {
  538. log.Fatal(err)
  539. }
  540. }
  541. } else {
  542. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  543. if err != nil {
  544. if err == sql.ErrNoRows {
  545. acl_data = ""
  546. } else {
  547. log.Fatal(err)
  548. }
  549. }
  550. }
  551. } else if tool == "bbs_comment" {
  552. acl_pass_auth = "bbs"
  553. if for_a == 0 {
  554. end_number += 1
  555. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl' and set_id = ?"))
  556. if err != nil {
  557. log.Fatal(err)
  558. }
  559. defer stmt.Close()
  560. err = stmt.QueryRow(name).Scan(&acl_data)
  561. if err != nil {
  562. if err == sql.ErrNoRows {
  563. acl_data = ""
  564. } else {
  565. log.Fatal(err)
  566. }
  567. }
  568. } else if for_a == 1 {
  569. end_number += 1
  570. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  571. if err != nil {
  572. log.Fatal(err)
  573. }
  574. defer stmt.Close()
  575. err = stmt.QueryRow(name).Scan(&acl_data)
  576. if err != nil {
  577. if err == sql.ErrNoRows {
  578. acl_data = ""
  579. } else {
  580. log.Fatal(err)
  581. }
  582. }
  583. } else if for_a == 2 {
  584. end_number += 1
  585. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl_all'")).Scan(&acl_data)
  586. if err != nil {
  587. if err == sql.ErrNoRows {
  588. acl_data = ""
  589. } else {
  590. log.Fatal(err)
  591. }
  592. }
  593. } else {
  594. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  595. if err != nil {
  596. if err == sql.ErrNoRows {
  597. acl_data = ""
  598. } else {
  599. log.Fatal(err)
  600. }
  601. }
  602. }
  603. } else if tool == "bbs_view" {
  604. acl_pass_auth = "bbs"
  605. if for_a == 0 {
  606. end_number += 1
  607. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl' and set_id = ?"))
  608. if err != nil {
  609. log.Fatal(err)
  610. }
  611. defer stmt.Close()
  612. err = stmt.QueryRow(name).Scan(&acl_data)
  613. if err != nil {
  614. if err == sql.ErrNoRows {
  615. acl_data = ""
  616. } else {
  617. log.Fatal(err)
  618. }
  619. }
  620. } else {
  621. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl_all'")).Scan(&acl_data)
  622. if err != nil {
  623. if err == sql.ErrNoRows {
  624. acl_data = ""
  625. } else {
  626. log.Fatal(err)
  627. }
  628. }
  629. }
  630. } else if tool == "recaptcha" {
  631. acl_pass_auth = "captcha_pass"
  632. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_pass_acl'")).Scan(&acl_data)
  633. if err != nil {
  634. if err == sql.ErrNoRows {
  635. acl_data = ""
  636. } else {
  637. log.Fatal(err)
  638. }
  639. }
  640. } else if tool == "recaptcha_five_pass" {
  641. acl_pass_auth = "captcha_one_check_five_pass"
  642. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_one_check_five_pass_acl'")).Scan(&acl_data)
  643. if err != nil {
  644. if err == sql.ErrNoRows {
  645. acl_data = ""
  646. } else {
  647. log.Fatal(err)
  648. }
  649. }
  650. } else if tool == "document_edit_request" {
  651. acl_pass_auth = "acl"
  652. if for_a == 0 {
  653. end_number += 1
  654. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_request_acl'"))
  655. if err != nil {
  656. log.Fatal(err)
  657. }
  658. defer stmt.Close()
  659. err = stmt.QueryRow(name).Scan(&acl_data)
  660. if err != nil {
  661. if err == sql.ErrNoRows {
  662. acl_data = ""
  663. } else {
  664. log.Fatal(err)
  665. }
  666. }
  667. } else {
  668. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_request_acl'")).Scan(&acl_data)
  669. if err != nil {
  670. if err == sql.ErrNoRows {
  671. acl_data = ""
  672. } else {
  673. log.Fatal(err)
  674. }
  675. }
  676. }
  677. } else if tool == "document_make_acl" {
  678. acl_pass_auth = "acl"
  679. err := db.QueryRow(DB_change("select data from other where name = 'document_make_acl'")).Scan(&acl_data)
  680. if err != nil {
  681. if err == sql.ErrNoRows {
  682. acl_data = ""
  683. } else {
  684. log.Fatal(err)
  685. }
  686. }
  687. } else {
  688. // tool == "render"
  689. acl_pass_auth = "acl"
  690. if for_a == 0 {
  691. end_number += 1
  692. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'view'"))
  693. if err != nil {
  694. log.Fatal(err)
  695. }
  696. defer stmt.Close()
  697. err = stmt.QueryRow(name).Scan(&acl_data)
  698. if err != nil {
  699. if err == sql.ErrNoRows {
  700. acl_data = ""
  701. } else {
  702. log.Fatal(err)
  703. }
  704. }
  705. } else {
  706. err := db.QueryRow(DB_change("select data from other where name = 'all_view_acl'")).Scan(&acl_data)
  707. if err != nil {
  708. if err == sql.ErrNoRows {
  709. acl_data = ""
  710. } else {
  711. log.Fatal(err)
  712. }
  713. }
  714. }
  715. }
  716. if auth_info[acl_pass_auth] {
  717. return true
  718. } else if ban_type == "4" {
  719. return false
  720. }
  721. if acl_data == "" {
  722. if tool == "recaptcha" {
  723. acl_data = "admin"
  724. } else if tool == "slow_edit" || tool == "edit_bottom_compulsion" {
  725. acl_data = "not_all"
  726. } else {
  727. acl_data = "normal"
  728. }
  729. }
  730. except_ban_tool_list := []string{"render", "topic_view", "bbs_view"}
  731. if acl_data != "normal" {
  732. if !(acl_data == "ban" || acl_data == "ban_admin") || ban_type == "3" {
  733. if !Arr_in_str(except_ban_tool_list, tool) {
  734. if get_ban == "true" {
  735. return false
  736. }
  737. }
  738. }
  739. if acl_data == "all" || acl_data == "ban" {
  740. return true
  741. } else if acl_data == "user" {
  742. if !ip_or_user {
  743. return true
  744. }
  745. } else if acl_data == "admin" {
  746. if auth_info["treat_as_admin"] {
  747. return true
  748. }
  749. } else if acl_data == "50_edit" {
  750. if !ip_or_user {
  751. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  752. if err != nil {
  753. log.Fatal(err)
  754. }
  755. defer stmt.Close()
  756. var count int
  757. err = stmt.QueryRow(ip).Scan(&count)
  758. if err != nil {
  759. if err == sql.ErrNoRows {
  760. count = 0
  761. } else {
  762. log.Fatal(err)
  763. }
  764. }
  765. if count >= 50 {
  766. return true
  767. }
  768. }
  769. } else if acl_data == "before" {
  770. stmt, err := db.Prepare(DB_change("select ip from history where title = ? and ip = ?"))
  771. if err != nil {
  772. log.Fatal(err)
  773. }
  774. defer stmt.Close()
  775. var exist string
  776. err = stmt.QueryRow(name, ip).Scan(&exist)
  777. if err != nil {
  778. if err == sql.ErrNoRows {
  779. exist = ""
  780. } else {
  781. log.Fatal(err)
  782. }
  783. }
  784. if exist != "" {
  785. return true
  786. }
  787. } else if acl_data == "30_day" || acl_data == "90_day" {
  788. if !ip_or_user {
  789. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  790. if err != nil {
  791. log.Fatal(err)
  792. }
  793. defer stmt.Close()
  794. var signup_date string
  795. err = stmt.QueryRow(ip).Scan(&signup_date)
  796. if err != nil {
  797. if err == sql.ErrNoRows {
  798. signup_date = Get_time()
  799. } else {
  800. log.Fatal(err)
  801. }
  802. }
  803. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  804. if acl_data == "30_day" {
  805. time_1 = time_1.AddDate(0, 0, 30)
  806. } else {
  807. time_1 = time_1.AddDate(0, 0, 90)
  808. }
  809. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  810. if time_2.After(time_1) {
  811. return true
  812. }
  813. }
  814. } else if acl_data == "email" {
  815. if !ip_or_user {
  816. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'email'"))
  817. if err != nil {
  818. log.Fatal(err)
  819. }
  820. defer stmt.Close()
  821. var exist string
  822. err = stmt.QueryRow(ip).Scan(&exist)
  823. if err != nil {
  824. if err == sql.ErrNoRows {
  825. exist = ""
  826. } else {
  827. log.Fatal(err)
  828. }
  829. }
  830. if exist != "" {
  831. return true
  832. }
  833. }
  834. } else if acl_data == "owner" {
  835. if auth_info["owner"] {
  836. return true
  837. }
  838. } else if acl_data == "ban_admin" {
  839. if auth_info["treat_as_admin"] || get_ban == "true" {
  840. return true
  841. }
  842. } else if acl_data == "not_all" {
  843. return false
  844. } else if acl_data == "up_to_level_3" || acl_data == "up_to_level_10" {
  845. if acl_data == "up_to_level_3" {
  846. if level_int >= 3 {
  847. return true
  848. }
  849. } else if acl_data == "up_to_level_10" {
  850. if level_int >= 10 {
  851. return true
  852. }
  853. }
  854. } else if acl_data == "30_day_50_edit" {
  855. if !ip_or_user {
  856. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  857. if err != nil {
  858. log.Fatal(err)
  859. }
  860. defer stmt.Close()
  861. var signup_date string
  862. err = stmt.QueryRow(ip).Scan(&signup_date)
  863. if err != nil {
  864. if err == sql.ErrNoRows {
  865. signup_date = Get_time()
  866. } else {
  867. log.Fatal(err)
  868. }
  869. }
  870. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  871. time_1 = time_1.AddDate(0, 0, 30)
  872. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  873. if time_2.After(time_1) {
  874. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  875. if err != nil {
  876. log.Fatal(err)
  877. }
  878. defer stmt.Close()
  879. var count int
  880. err = stmt.QueryRow(ip).Scan(&count)
  881. if err != nil {
  882. if err == sql.ErrNoRows {
  883. count = 0
  884. } else {
  885. log.Fatal(err)
  886. }
  887. }
  888. if count >= 50 {
  889. return true
  890. }
  891. }
  892. }
  893. }
  894. return false
  895. } else if for_a == end_number-1 {
  896. if !Arr_in_str(except_ban_tool_list, tool) {
  897. if get_ban == "true" {
  898. return false
  899. }
  900. }
  901. if tool == "topic" {
  902. stmt, err := db.Prepare(DB_change("select title from rd where code = ? and stop != ''"))
  903. if err != nil {
  904. log.Fatal(err)
  905. }
  906. defer stmt.Close()
  907. var topic_state string
  908. err = stmt.QueryRow(topic_number).Scan(&topic_state)
  909. if err != nil {
  910. if err == sql.ErrNoRows {
  911. topic_state = ""
  912. } else {
  913. log.Fatal(err)
  914. }
  915. }
  916. if topic_state != "" {
  917. if auth_info["topic"] {
  918. return true
  919. } else {
  920. return false
  921. }
  922. } else {
  923. return true
  924. }
  925. } else {
  926. return true
  927. }
  928. }
  929. }
  930. return false
  931. }