Documentation
IPS_AddPermissionToUser
bool IPS_AddPermissionToUser (string $User, int $ObjectID, string $Operation, bool $Recursive)
Parameters
| User | Name of the user (case-sensitive) |
| ObjectID | ID of the object the permission applies to |
| Operation | Name of the registered operation, e.g. VISUALIZATION |
| Recursive | TRUE if the permission also applies to all objects below ObjectID, otherwise FALSE |
Returns
If the function succeeds, it returns TRUE, otherwise FALSE.
Description
The function grants the user User the permission to perform the Operation on the object ObjectID. Alternatively, permissions can be granted via roles (see IPS_AddPermissionToRole). Access to a visualization can also be configured directly in its instance configuration under Security.
A recursive permission applies to the object itself and to all objects below it in the object tree (children, grandchildren, etc.). A recursive permission on the root object (ID 0) therefore applies to all objects. A non-recursive permission applies to exactly this object only. Links are not followed; only the position of the checked object in the object tree matters.
Operations are registered by modules. Currently the visualization registers the operation VISUALIZATION (access to a visualization with all its objects) as soon as a visualization instance (e.g. Tile Visualization or WebFront Visualization) exists. It is checked against the ID of the visualization instance. The operation name is case-sensitive. If the operation is not registered, the function fails with "Cannot verify unsupported operation".
This function is only available for licenses that include the RBAC feature (Permission Control). Otherwise it fails with "This function is only available for licenses with the RBAC feature enabled!". If there are more users than the license allows (10 users by default, the @admin user is not counted), it fails with "Your license is currently limited to 10 users. Please consider upgrading the license to more users!" (the number is the limit of the license).
The currently logged in user (see IPS_GetLoggedInUser) must be an administrator, i.e. the @admin user or a user with the @admin role. Otherwise the function fails with "Administrator permissions are required for this action!".
Further checks in this order: If the operation is not registered, the function fails with "Cannot verify unsupported operation". If the user does not exist, the function fails with "User with name '…' does not exist". The @admin user cannot be modified; trying to do so fails with "User @admin cannot be modified!". If the object does not exist, it fails with "Object #… does not exist". If the user already has a permission with identical ObjectID, Operation and Recursive, it fails with "User already has this permission". A permission that only differs in Recursive counts as a separate entry.
See also: IPS_RemovePermissionFromUser, IPS_UserHasPermission
Example
$VisuID = 12345; // ID of a tile visualization
IPS_AddPermissionToUser('anna', $VisuID, 'VISUALIZATION', false);