« Back to Product

Documentation

IPS_HasPermission

 bool IPS_HasPermission (int $ObjectID, string $Operation) 

Parameters

ObjectID

ID of the object to be checked

Operation

Name of the registered operation, e.g. VISUALIZATION

Returns

If the currently logged in user has the permission, TRUE is returned, otherwise FALSE.

Description

The function checks whether the user in whose context the current execution runs (see IPS_GetLoggedInUser) may perform the Operation on the object ObjectID. The permissions of the user and the permissions of all the user's roles are taken into account. It corresponds to IPS_UserHasPermission for the current user.

The check is performed in this order: If the operation is not registered, the function fails with "Cannot verify unsupported operation"; if the object does not exist, with "Object #… does not exist". The @admin user always has all permissions, the @unknown user never has any. For all other users: If the user does not exist, the function fails with "User with name '…' does not exist". If the user has the @admin role, TRUE is returned. Otherwise TRUE is returned if a permission of the user or of one of the user's roles grants the operation on the object.

A recursive permission applies to the object itself and to all objects below it in the object tree (children, grandchildren, etc.). A recursive permission on the root object (ID 0) therefore applies to all objects. A non-recursive permission applies to exactly this object only. Links are not followed; only the position of the checked object in the object tree matters.

Operations are registered by modules. Currently the visualization registers the operation VISUALIZATION (access to a visualization with all its objects) as soon as a visualization instance (e.g. Tile Visualization or WebFront Visualization) exists. It is checked against the ID of the visualization instance. The operation name is case-sensitive. If the operation is not registered, the function fails with "Cannot verify unsupported operation".

The function does not require the RBAC feature in the license.

Example

$VisuID = 12345; // ID of a tile visualization
if (IPS_HasPermission($VisuID, 'VISUALIZATION')) {
    echo 'Access granted';
}
Any questions?