« Back to Product

Documentation

IPS_UserHasPermission

 bool IPS_UserHasPermission (string $User, int $ObjectID, string $Operation) 

Parameters

User

Name of the user (case-sensitive)

ObjectID

ID of the object to be checked

Operation

Name of the registered operation, e.g. VISUALIZATION

Returns

If the user has the permission, TRUE is returned, otherwise FALSE.

Description

The function checks whether the user User may perform the Operation on the object ObjectID. The permissions of the user and the permissions of all the user's roles are taken into account. Whether the user is active does not matter for this check.

The check is performed in this order: If the operation is not registered, the function fails with "Cannot verify unsupported operation"; if the object does not exist, with "Object #… does not exist". The @admin user always has all permissions, the @unknown user never has any. For all other users: If the user does not exist, the function fails with "User with name '…' does not exist". If the user has the @admin role, TRUE is returned. Otherwise TRUE is returned if a permission of the user or of one of the user's roles grants the operation on the object.

A recursive permission applies to the object itself and to all objects below it in the object tree (children, grandchildren, etc.). A recursive permission on the root object (ID 0) therefore applies to all objects. A non-recursive permission applies to exactly this object only. Links are not followed; only the position of the checked object in the object tree matters.

Operations are registered by modules. Currently the visualization registers the operation VISUALIZATION (access to a visualization with all its objects) as soon as a visualization instance (e.g. Tile Visualization or WebFront Visualization) exists. It is checked against the ID of the visualization instance. The operation name is case-sensitive. If the operation is not registered, the function fails with "Cannot verify unsupported operation".

The function requires neither the RBAC feature in the license nor administrator permissions. For the currently logged in user, IPS_HasPermission can be used.

Example

$VisuID = 12345; // ID of a tile visualization
IPS_AddPermissionToUser('anna', 0, 'VISUALIZATION', true); // recursive from the root object
var_dump(IPS_UserHasPermission('anna', $VisuID, 'VISUALIZATION'));

/* returns:
bool(true)
*/
Any questions?