| line |
stmt |
bran |
cond |
sub |
pod |
time |
code |
|
1
|
|
|
|
|
|
|
package Data::ACL::Realm; |
|
2
|
|
|
|
|
|
|
|
|
3
|
3
|
|
|
3
|
|
16
|
use Carp; |
|
|
3
|
|
|
|
|
5
|
|
|
|
3
|
|
|
|
|
158
|
|
|
4
|
|
|
|
|
|
|
|
|
5
|
3
|
|
|
3
|
|
18
|
use strict; |
|
|
3
|
|
|
|
|
5
|
|
|
|
3
|
|
|
|
|
97
|
|
|
6
|
3
|
|
|
3
|
|
13
|
use vars qw/ $VERSION /; |
|
|
3
|
|
|
|
|
4
|
|
|
|
3
|
|
|
|
|
1528
|
|
|
7
|
|
|
|
|
|
|
|
|
8
|
|
|
|
|
|
|
$VERSION = $Data::ACL::VERSION; |
|
9
|
|
|
|
|
|
|
|
|
10
|
|
|
|
|
|
|
|
|
11
|
|
|
|
|
|
|
sub AddPolicy { |
|
12
|
0
|
|
|
0
|
0
|
0
|
my ( $self, $right, @args ) = @_; |
|
13
|
0
|
|
|
|
|
0
|
$right = uc $right; |
|
14
|
0
|
0
|
0
|
|
|
0
|
unless( $right eq 'ALLOW' or $right eq 'DENY' ) { |
|
15
|
0
|
|
|
|
|
0
|
croak( __PACKAGE__, "->AddPolicy : Policy should be either 'ALLOW' or 'DENY'" ); |
|
16
|
|
|
|
|
|
|
} |
|
17
|
0
|
|
|
|
|
0
|
push @{ $self->{'policies'} }, [ $right, @args ]; |
|
|
0
|
|
|
|
|
0
|
|
|
18
|
|
|
|
|
|
|
} |
|
19
|
|
|
|
|
|
|
|
|
20
|
|
|
|
|
|
|
|
|
21
|
|
|
|
|
|
|
sub Allow { |
|
22
|
1
|
|
|
1
|
0
|
3
|
my ( $self, @args ) = @_; |
|
23
|
1
|
|
|
|
|
3
|
push @{ $self->{'policies'} }, [ 'ALLOW', @args ]; |
|
|
1
|
|
|
|
|
7
|
|
|
24
|
|
|
|
|
|
|
} |
|
25
|
|
|
|
|
|
|
|
|
26
|
|
|
|
|
|
|
|
|
27
|
|
|
|
|
|
|
sub Deny { |
|
28
|
1
|
|
|
1
|
0
|
378
|
my ( $self, @args ) = @_; |
|
29
|
1
|
|
|
|
|
3
|
push @{ $self->{'policies'} }, [ 'DENY', @args ]; |
|
|
1
|
|
|
|
|
7
|
|
|
30
|
|
|
|
|
|
|
} |
|
31
|
|
|
|
|
|
|
|
|
32
|
|
|
|
|
|
|
|
|
33
|
|
|
|
|
|
|
sub Is { |
|
34
|
6
|
|
|
6
|
0
|
7
|
my ( $self, $user, $group ) = @_; |
|
35
|
6
|
|
|
|
|
8
|
my $set = $self->{'set'}; |
|
36
|
6
|
100
|
|
|
|
31
|
return 1 if $group =~ /^all$/i; |
|
37
|
3
|
50
|
|
|
|
7
|
return ( $group eq $user ) if $group =~ s/^\.//; |
|
38
|
3
|
100
|
|
|
|
23
|
return undef unless $set->member( $user ); |
|
39
|
2
|
|
|
|
|
544
|
return $set->member( $user, $group ); |
|
40
|
|
|
|
|
|
|
} |
|
41
|
|
|
|
|
|
|
|
|
42
|
|
|
|
|
|
|
|
|
43
|
|
|
|
|
|
|
sub IsAuthorized { |
|
44
|
3
|
|
|
3
|
0
|
4
|
my ( $self, $user ) = @_; |
|
45
|
3
|
|
|
|
|
5
|
my $result = 0; |
|
46
|
3
|
|
|
|
|
3
|
foreach my $policy ( @{ $self->{'policies'} } ) { |
|
|
3
|
|
|
|
|
6
|
|
|
47
|
6
|
|
|
|
|
7
|
my ( $right, $group, $exception ) = @{ $policy }; |
|
|
6
|
|
|
|
|
21
|
|
|
48
|
6
|
100
|
33
|
|
|
13
|
if ( ( $self->Is( $user, $group ) ) and ( !( $exception and $self->Is( $user, $exception ) ) ) ) { |
|
|
|
|
66
|
|
|
|
|
|
49
|
4
|
|
|
|
|
74
|
$result = ( $right eq 'ALLOW' ); |
|
50
|
|
|
|
|
|
|
} |
|
51
|
|
|
|
|
|
|
} |
|
52
|
3
|
|
|
|
|
48
|
return $result; |
|
53
|
|
|
|
|
|
|
} |
|
54
|
|
|
|
|
|
|
|
|
55
|
|
|
|
|
|
|
|
|
56
|
|
|
|
|
|
|
sub new { |
|
57
|
1
|
|
|
1
|
0
|
3
|
my ( $class, $set ) = @_; |
|
58
|
1
|
|
|
|
|
5
|
my $self = bless { |
|
59
|
|
|
|
|
|
|
'policies' => [], |
|
60
|
|
|
|
|
|
|
'set' => $set |
|
61
|
|
|
|
|
|
|
}, $class; |
|
62
|
1
|
|
|
|
|
6
|
return $self; |
|
63
|
|
|
|
|
|
|
} |
|
64
|
|
|
|
|
|
|
|
|
65
|
|
|
|
|
|
|
|
|
66
|
|
|
|
|
|
|
1; |
|
67
|
|
|
|
|
|
|
|
|
68
|
|
|
|
|
|
|
|
|
69
|
|
|
|
|
|
|
__END__ |