From 095ef5d20be860a7834f082790a842c260759718 Mon Sep 17 00:00:00 2001 From: Rom1-B <8530352+Rom1-B@users.noreply.github.com> Date: Wed, 7 Oct 2026 10:47:05 +0200 Subject: [PATCH 1/2] Fix: preserve profile rights on plugin install/update --- CHANGELOG.md | 1 + inc/profile.class.php | 80 +++++++++++++++++++++++++------------------ 2 files changed, 47 insertions(+), 34 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e51f0094..173c61b3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,7 @@ and this project adheres to [Semantic Versioning](http://semver.org/). ### Fixed - CI: fix Psalm cache directory, drop the stray `glpi-project/tools` composer dependency, declare a unique composer autoloader suffix +- Profile rights to reports are no longer reset to "no access" each time the plugin is installed or updated ## [1.10.3] - 2026-09-28 diff --git a/inc/profile.class.php b/inc/profile.class.php index f5495aa1..7d4bb46c 100644 --- a/inc/profile.class.php +++ b/inc/profile.class.php @@ -154,27 +154,34 @@ public static function addRightToAllProfiles() /** @var DBmysql $DB */ global $DB; - $query_config = [ - 'SELECT' => 'id', - 'FROM' => PluginMreportingConfig::getTable(), - ]; - - $query_profil = [ - 'SELECT' => 'id', - 'FROM' => Profile::getTable(), - ]; + $profiles_ids = array_column( + iterator_to_array($DB->request(['SELECT' => 'id', 'FROM' => Profile::getTable()])), + 'id', + ); + $reports_ids = array_column( + iterator_to_array($DB->request(['SELECT' => 'id', 'FROM' => PluginMreportingConfig::getTable()])), + 'id', + ); - $result_config = $DB->request($query_config); - foreach ($DB->request($query_profil) as $prof) { - foreach ($result_config as $report) { - $DB->updateOrInsert('glpi_plugin_mreporting_profiles', [ - 'profiles_id' => $prof['id'], - 'reports' => $report['id'], - 'right' => null, - ], [ - 'profiles_id' => $prof['id'], - 'reports' => $report['id'], - ]); + // Only create the missing profile/report combinations, never overwrite an existing right + foreach ($profiles_ids as $profile_id) { + foreach ($reports_ids as $report_id) { + $already_exists = $DB->request([ + 'COUNT' => 'cpt', + 'FROM' => self::getTable(), + 'WHERE' => [ + 'profiles_id' => $profile_id, + 'reports' => $report_id, + ], + ])->current()['cpt'] > 0; + + if (!$already_exists) { + $DB->insert(self::getTable(), [ + 'profiles_id' => $profile_id, + 'reports' => $report_id, + 'right' => null, + ]); + } } } } @@ -209,26 +216,31 @@ public static function addRightToProfile(?int $idProfile = null): void /** @var DBmysql $DB */ global $DB; - $profiles_ids = []; $profiles_ids = is_null($idProfile) ? Profile::getSuperAdminProfilesId() : [$idProfile]; + $reports_ids = array_column( + iterator_to_array($DB->request(['SELECT' => 'id', 'FROM' => PluginMreportingConfig::getTable()])), + 'id', + ); - $config = new PluginMreportingConfig(); - $reports = $config->find(); - + // Only create the missing profile/report combinations, never overwrite an existing right foreach ($profiles_ids as $profileId) { - foreach ($reports as $report) { - $DB->updateOrInsert( - 'glpi_plugin_mreporting_profiles', - [ + foreach ($reports_ids as $report_id) { + $already_exists = $DB->request([ + 'COUNT' => 'cpt', + 'FROM' => self::getTable(), + 'WHERE' => [ 'profiles_id' => $profileId, - 'reports' => $report['id'], - 'right' => READ, + 'reports' => $report_id, ], - [ + ])->current()['cpt'] > 0; + + if (!$already_exists) { + $DB->insert(self::getTable(), [ 'profiles_id' => $profileId, - 'reports' => $report['id'], - ], - ); + 'reports' => $report_id, + 'right' => READ, + ]); + } } } } From c0e110404136ebe9dcc924b7dea265667970f9be Mon Sep 17 00:00:00 2001 From: Rom1-B <8530352+Rom1-B@users.noreply.github.com> Date: Fri, 9 Oct 2026 12:58:17 +0200 Subject: [PATCH 2/2] stan --- hook.php | 3 ++- inc/profile.class.php | 56 ++++++++++++++++--------------------------- 2 files changed, 23 insertions(+), 36 deletions(-) diff --git a/hook.php b/hook.php index 5d3984b1..71aa4557 100644 --- a/hook.php +++ b/hook.php @@ -270,8 +270,9 @@ function plugin_mreporting_install() $config = new PluginMreportingConfig(); $config->createFirstConfig(); - PluginMreportingProfile::addRightToAllProfiles(); + // Super-admin READ defaults first, so the NULL seeding below does not pre-empt them PluginMreportingProfile::addRightToProfile(); + PluginMreportingProfile::addRightToAllProfiles(); return true; } diff --git a/inc/profile.class.php b/inc/profile.class.php index 7d4bb46c..9abf61b1 100644 --- a/inc/profile.class.php +++ b/inc/profile.class.php @@ -163,27 +163,7 @@ public static function addRightToAllProfiles() 'id', ); - // Only create the missing profile/report combinations, never overwrite an existing right - foreach ($profiles_ids as $profile_id) { - foreach ($reports_ids as $report_id) { - $already_exists = $DB->request([ - 'COUNT' => 'cpt', - 'FROM' => self::getTable(), - 'WHERE' => [ - 'profiles_id' => $profile_id, - 'reports' => $report_id, - ], - ])->current()['cpt'] > 0; - - if (!$already_exists) { - $DB->insert(self::getTable(), [ - 'profiles_id' => $profile_id, - 'reports' => $report_id, - 'right' => null, - ]); - } - } - } + self::addMissingRights($profiles_ids, $reports_ids, null); } public static function getRight() @@ -222,23 +202,29 @@ public static function addRightToProfile(?int $idProfile = null): void 'id', ); - // Only create the missing profile/report combinations, never overwrite an existing right - foreach ($profiles_ids as $profileId) { - foreach ($reports_ids as $report_id) { - $already_exists = $DB->request([ - 'COUNT' => 'cpt', - 'FROM' => self::getTable(), - 'WHERE' => [ - 'profiles_id' => $profileId, - 'reports' => $report_id, - ], - ])->current()['cpt'] > 0; + self::addMissingRights($profiles_ids, $reports_ids, READ); + } - if (!$already_exists) { + /** + * Only create the missing profile/report combinations, never overwrite an existing right + */ + private static function addMissingRights(array $profiles_ids, array $reports_ids, ?int $right): void + { + /** @var DBmysql $DB */ + global $DB; + + $existing = []; + foreach ($DB->request(['SELECT' => ['profiles_id', 'reports'], 'FROM' => self::getTable()]) as $row) { + $existing[$row['profiles_id'] . '-' . $row['reports']] = true; + } + + foreach ($profiles_ids as $profile_id) { + foreach ($reports_ids as $report_id) { + if (!isset($existing[$profile_id . '-' . $report_id])) { $DB->insert(self::getTable(), [ - 'profiles_id' => $profileId, + 'profiles_id' => $profile_id, 'reports' => $report_id, - 'right' => READ, + 'right' => $right, ]); } }