+
+ // Add current group.
+ $groups[] = array('id'=>$selected_group_id,'name'=>$selected_group_name);
+
+ // Add subgroups.
+ $sql = "select id, name from tt_groups where org_id = $this->org_id and parent_id = $selected_group_id";
+ $res = $mdb2->query($sql);
+ if (!is_a($res, 'PEAR_Error')) {
+ while ($val = $res->fetchRow()) {
+ $groups[] = array('id'=>$val['id'],'name'=>$val['name']);
+ }
+ }
+ return $groups;
+ }
+
+ // getUser function is used to manage users in group and returns user details.
+ // At the moment, the function is used for user edits and deletes.
+ function getUser($user_id) {
+ if (!$this->can('manage_users')) return false;
+
+ $mdb2 = getConnection();
+
+ $sql = "select u.id, u.name, u.login, u.role_id, u.client_id, u.status, u.rate, u.email from tt_users u".
+ " left join tt_roles r on (u.role_id = r.id)".
+ " where u.id = $user_id and u.group_id = $this->group_id and u.status is not null".
+ " and (r.rank < $this->rank or (r.rank = $this->rank and u.id = $this->id))"; // Users with lesser roles or self.
+ $res = $mdb2->query($sql);
+ if (!is_a($res, 'PEAR_Error')) {
+ $val = $res->fetchRow();
+ return $val;
+ }
+ return false;
+ }
+
+ // checkBehalfId checks whether behalf_id is appropriate.
+ // On behalf user must be active and have lower rank if the user is from home group,
+ // otherwise:
+ // - subgroup must ve valid;
+ // - user should be a member of it.
+ function checkBehalfId() {
+ if (!$this->behalf_group_id) {
+ // Checking user from home group.
+ $options = array('status'=>ACTIVE,'max_rank'=>$this->rank-1);
+ $users = $this->getUsers($options);
+ foreach($users as $one_user) {
+ if ($one_user['id'] == $this->behalf_id)
+ return true;
+ }
+ } else {
+ // Checking user from a subgroup.
+ $group_id = $this->behalf_group_id;
+ if (!$this->isSubgroupValid($group_id))
+ return false;
+
+ // So far, so good. Check user now.
+ $options = array('group_id'=>$group_id,'status'=>ACTIVE,'max_rank'=>MAX_RANK);
+ $users = $this->getUsers($options);
+ foreach($users as $one_user) {
+ if ($one_user['id'] == $this->behalf_id)
+ return true;
+ }
+ }
+ return false;
+ }
+
+ // adjustBehalfId attempts to adjust behalf_id and behalf_name to a first found
+ // apropriate user.
+ //
+ // Needed for situations when user does not have do_own_something right.
+ // Example: has view_charts but does not have view_own_charts.
+ // In this case we still allow access to charts, but set behalf_id to someone else.
+ // Another example: working in a subgroup on behalf of someone else.
+ function adjustBehalfId() {
+ $group_id = $this->behalf_group_id ? $this->behalf_group_id : $this->group_id;
+ $rank = $this->getMaxRankForGroup($group_id);
+
+ // Adjust to first found user in group.
+ $options = array('group_id'=>$group_id,'status'=>ACTIVE,'max_rank'=>$rank);
+ $users = $this->getUsers($options);
+ foreach($users as $one_user) {
+ // Fake loop to access first element.
+ $this->behalf_id = $one_user['id'];
+ $this->behalf_name = $one_user['name'];
+ $_SESSION['behalf_id'] = $this->behalf_id;
+ $_SESSION['behalf_name'] = $this->behalf_name;
+ return true;
+ }