Skip to content

Commit 18fce37

Browse files
committed
Fix subuser permissions not migrating correctly from 0.7; closes pterodactyl#2309
1 parent 1e08f7d commit 18fce37

File tree

2 files changed

+71
-82
lines changed

2 files changed

+71
-82
lines changed

app/Models/Permission.php

Lines changed: 0 additions & 76 deletions
Original file line numberDiff line numberDiff line change
@@ -219,80 +219,4 @@ public static function permissions(): Collection
219219
{
220220
return Collection::make(self::$permissions);
221221
}
222-
223-
/**
224-
* A list of all permissions available for a user.
225-
*
226-
* @var array
227-
* @deprecated
228-
*/
229-
protected static $deprecatedPermissions = [
230-
'power' => [
231-
'power-start' => 's:power:start',
232-
'power-stop' => 's:power:stop',
233-
'power-restart' => 's:power:restart',
234-
'power-kill' => 's:power:kill',
235-
'send-command' => 's:command',
236-
],
237-
'subuser' => [
238-
'list-subusers' => null,
239-
'view-subuser' => null,
240-
'edit-subuser' => null,
241-
'create-subuser' => null,
242-
'delete-subuser' => null,
243-
],
244-
'server' => [
245-
'view-allocations' => null,
246-
'edit-allocation' => null,
247-
'view-startup' => null,
248-
'edit-startup' => null,
249-
],
250-
'database' => [
251-
'view-databases' => null,
252-
'reset-db-password' => null,
253-
'delete-database' => null,
254-
'create-database' => null,
255-
],
256-
'file' => [
257-
'access-sftp' => null,
258-
'list-files' => 's:files:get',
259-
'edit-files' => 's:files:read',
260-
'save-files' => 's:files:post',
261-
'move-files' => 's:files:move',
262-
'copy-files' => 's:files:copy',
263-
'compress-files' => 's:files:compress',
264-
'decompress-files' => 's:files:decompress',
265-
'create-files' => 's:files:create',
266-
'upload-files' => 's:files:upload',
267-
'delete-files' => 's:files:delete',
268-
'download-files' => 's:files:download',
269-
],
270-
'task' => [
271-
'list-schedules' => null,
272-
'view-schedule' => null,
273-
'toggle-schedule' => null,
274-
'queue-schedule' => null,
275-
'edit-schedule' => null,
276-
'create-schedule' => null,
277-
'delete-schedule' => null,
278-
],
279-
];
280-
281-
/**
282-
* Return a collection of permissions available.
283-
*
284-
* @param bool $array
285-
* @return array|\Illuminate\Database\Eloquent\Collection
286-
* @deprecated
287-
*/
288-
public static function getPermissions($array = false)
289-
{
290-
if ($array) {
291-
return collect(self::$deprecatedPermissions)->mapWithKeys(function ($item) {
292-
return $item;
293-
})->all();
294-
}
295-
296-
return collect(self::$deprecatedPermissions);
297-
}
298222
}

database/migrations/2020_03_22_163911_merge_permissions_table_into_subusers.php

Lines changed: 71 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,64 @@
11
<?php
22

33
use Illuminate\Support\Facades\DB;
4+
use Illuminate\Support\Collection;
5+
use Pterodactyl\Models\Permission;
46
use Illuminate\Support\Facades\Schema;
7+
use Pterodactyl\Models\Permission as P;
58
use Illuminate\Database\Schema\Blueprint;
69
use Illuminate\Database\Migrations\Migration;
710

811
class MergePermissionsTableIntoSubusers extends Migration
912
{
13+
/**
14+
* A list of all pre-1.0 permissions available to a user and their associated
15+
* casting for the new permissions system.
16+
*
17+
* @var array
18+
*/
19+
protected static $permissionsMap = [
20+
'power-start' => P::ACTION_CONTROL_START,
21+
'power-stop' => P::ACTION_CONTROL_STOP,
22+
'power-restart' => P::ACTION_CONTROL_RESTART,
23+
'power-kill' => P::ACTION_CONTROL_STOP,
24+
'send-command' => P::ACTION_CONTROL_CONSOLE,
25+
'list-subusers' => P::ACTION_USER_READ,
26+
'view-subuser' => P::ACTION_USER_READ,
27+
'edit-subuser' => P::ACTION_USER_UPDATE,
28+
'create-subuser' => P::ACTION_USER_CREATE,
29+
'delete-subuser' => P::ACTION_USER_DELETE,
30+
'view-allocations' => P::ACTION_ALLOCATION_READ,
31+
'edit-allocation' => P::ACTION_ALLOCATION_UPDATE,
32+
'view-startup' => P::ACTION_STARTUP_READ,
33+
'edit-startup' => P::ACTION_STARTUP_UPDATE,
34+
'view-databases' => P::ACTION_DATABASE_READ,
35+
// Better to just break this flow a bit than accidentally grant a dangerous permission.
36+
'reset-db-password' => P::ACTION_DATABASE_UPDATE,
37+
'delete-database' => P::ACTION_DATABASE_DELETE,
38+
'create-database' => P::ACTION_DATABASE_CREATE,
39+
'access-sftp' => P::ACTION_FILE_SFTP,
40+
'list-files' => P::ACTION_FILE_READ,
41+
'edit-files' => P::ACTION_FILE_READ_CONTENT,
42+
'save-files' => P::ACTION_FILE_UPDATE,
43+
'create-files' => P::ACTION_FILE_CREATE,
44+
'delete-files' => P::ACTION_FILE_DELETE,
45+
'compress-files' => P::ACTION_FILE_ARCHIVE,
46+
'list-schedules' => P::ACTION_SCHEDULE_READ,
47+
'view-schedule' => P::ACTION_SCHEDULE_READ,
48+
'edit-schedule' => P::ACTION_SCHEDULE_UPDATE,
49+
'create-schedule' => P::ACTION_SCHEDULE_CREATE,
50+
'delete-schedule' => P::ACTION_SCHEDULE_DELETE,
51+
// Skipping these permissions as they are granted if you have more specific read/write permissions.
52+
'move-files' => null,
53+
'copy-files' => null,
54+
'decompress-files' => null,
55+
'upload-files' => null,
56+
'download-files' => null,
57+
// These permissions do not exist in 1.0
58+
'toggle-schedule' => null,
59+
'queue-schedule' => null,
60+
];
61+
1062
/**
1163
* Run the migrations.
1264
*
@@ -27,10 +79,19 @@ public function up()
2779

2880
DB::transaction(function () use (&$cursor) {
2981
$cursor->each(function ($datum) {
30-
DB::update('UPDATE subusers SET permissions = ? WHERE id = ?', [
31-
json_encode(explode(',', $datum->permissions)),
32-
$datum->subuser_id,
33-
]);
82+
$updated = Collection::make(explode(',', $datum->permissions))
83+
->map(function ($value) {
84+
return self::$permissionsMap[$value] ?? null;
85+
})->filter(function ($value) {
86+
return !is_null($value) && $value !== Permission::ACTION_WEBSOCKET_CONNECT;
87+
})
88+
// All subusers get this permission, so make sure it gets pushed into the array.
89+
->merge([ Permission::ACTION_WEBSOCKET_CONNECT ])
90+
->unique()
91+
->values()
92+
->toJson();
93+
94+
DB::update('UPDATE subusers SET permissions = ? WHERE id = ?', [$updated, $datum->subuser_id]);
3495
});
3596
});
3697
}
@@ -42,11 +103,15 @@ public function up()
42103
*/
43104
public function down()
44105
{
106+
$flipped = array_flip(self::$permissionsMap);
107+
45108
foreach (DB::select('SELECT id, permissions FROM subusers') as $datum) {
46109
$values = [];
47110
foreach (json_decode($datum->permissions, true) as $permission) {
48-
$values[] = $datum->id;
49-
$values[] = $permission;
111+
if (!empty($v = $flipped[$permission])) {
112+
$values[] = $datum->id;
113+
$values[] = $v;
114+
}
50115
}
51116

52117
if (! empty($values)) {

0 commit comments

Comments
 (0)