Skip to content

Commit f523390

Browse files
committed
Fix: apply missing checks on block and field handling
1 parent 8ba3e73 commit f523390

13 files changed

Lines changed: 1016 additions & 262 deletions

‎CHANGELOG.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,20 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](http://keepachangelog.com/)
66
and this project adheres to [Semantic Versioning](http://semver.org/).
77

8+
## [Unreleased]
9+
10+
### Fixed
11+
12+
- Fix blocks export, block deletion and read-only fields not applying expected checks.
13+
- Fix read-only status overrides being resolved with the previous status instead of the submitted one.
14+
- Fix read-only fields of "Insertion in form" blocks being overwritable from the item form.
15+
- Fix block's associated item types and type being changeable after creation.
16+
- Remove obsolete FusionInventory integration.
17+
18+
### Changed
19+
20+
- "GLPI item" field now rejects a new reference to an item the current user cannot read, instead of silently clearing it. Automated writes (CLI, cron, inventory) are not affected.
21+
822
## [1.21.30] 2026-09-11
923

1024
- Fix additional fields being saved on an item the user is not allowed to update.

‎composer.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"require": {
3-
"php": ">=7.4",
4-
"symfony/yaml": "^5.4"
3+
"php": ">=7.4"
54
},
65
"require-dev": {
76
"glpi-project/tools": "^0.8"
87
},
98
"config": {
9+
"autoloader-suffix": "PluginField",
1010
"optimize-autoloader": true,
1111
"platform": {
1212
"php": "7.4.0"

‎front/container.form.php‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -45,12 +45,14 @@
4545
$container->check($_POST['id'], DELETE);
4646
$ok = $container->delete($_POST);
4747
Html::redirect(PLUGINFIELDS_WEB_DIR . '/front/container.php');
48-
} elseif (isset($_REQUEST['purge'])) {
49-
$container->check($_REQUEST['id'], PURGE);
50-
$container->delete($_REQUEST, true);
48+
} elseif (isset($_POST['purge'])) {
49+
$container->check($_POST['id'], PURGE);
50+
$container->delete($_POST, true);
5151
Html::redirect(PLUGINFIELDS_WEB_DIR . '/front/container.php');
5252
} elseif (isset($_POST['update'])) {
5353
$container->check($_POST['id'], UPDATE);
54+
// structural fields drive generated classes and tables; only migrations may change them
55+
unset($_POST['itemtypes'], $_POST['type'], $_POST['subtype']);
5456
$container->update($_POST);
5557
Html::back();
5658
} elseif (isset($_POST['update_fields_values'])) {
@@ -66,7 +68,7 @@
6668
Html::displayRightError();
6769
}
6870

69-
$container->updateFieldsValues($_REQUEST, $_REQUEST['itemtype'], false);
71+
$container->updateFieldsValues(PluginFieldsContainer::removeReadonlyValues($_REQUEST, $item), $_REQUEST['itemtype'], false);
7072
}
7173
Html::back();
7274
} else {

‎front/field.form.php‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -46,9 +46,9 @@
4646
$field->check($_POST['id'], DELETE);
4747
$field->delete($_POST);
4848
Html::back();
49-
} elseif (isset($_REQUEST['purge'])) {
50-
$field->check($_REQUEST['id'], PURGE);
51-
$field->delete($_REQUEST, true);
49+
} elseif (isset($_POST['purge'])) {
50+
$field->check($_POST['id'], PURGE);
51+
$field->delete($_POST, true);
5252
$field->redirectToList();
5353
} elseif (isset($_POST['update'])) {
5454
$field->check($_POST['id'], UPDATE);

‎hook.php‎

Lines changed: 0 additions & 82 deletions
Original file line numberDiff line numberDiff line change
@@ -231,88 +231,6 @@ function plugin_fields_MassiveActionsFieldsDisplay($options = [])
231231
return false;
232232
}
233233

234-
235-
/**** RULES ENGINE ****/
236-
237-
/**
238-
*
239-
* Actions for rules
240-
* @since 0.84
241-
* @param array $params input data
242-
* @return array an array of actions
243-
*/
244-
function plugin_fields_getRuleActions($params = [])
245-
{
246-
$actions = [];
247-
248-
switch ($params['rule_itemtype']) {
249-
case 'PluginFusioninventoryTaskpostactionRule':
250-
$options = PluginFieldsContainer::getAddSearchOptions('Computer');
251-
foreach ($options as $option) {
252-
$actions[$option['linkfield']]['name'] = $option['name'];
253-
$actions[$option['linkfield']]['type'] = $option['pfields_type'];
254-
if ($option['pfields_type'] == 'dropdown') {
255-
$actions[$option['linkfield']]['table'] = $option['table'];
256-
}
257-
}
258-
259-
break;
260-
}
261-
262-
return $actions;
263-
}
264-
265-
266-
function plugin_fields_rule_matched($params = [])
267-
{
268-
/** @var DBmysql $DB */
269-
global $DB;
270-
271-
$container = new PluginFieldsContainer();
272-
273-
if (class_exists('PluginFusioninventoryAgent') && $params['sub_type'] == 'PluginFusioninventoryTaskpostactionRule') {
274-
$agent = new PluginFusioninventoryAgent();
275-
276-
if (isset($params['input']['plugin_fusioninventory_agents_id'])) {
277-
foreach ($params['output'] as $field => $value) {
278-
// check if current field is in a tab container
279-
$iterator = $DB->request([
280-
'SELECT' => 'glpi_plugin_fields_containers.id',
281-
'FROM' => 'glpi_plugin_fields_containers',
282-
'LEFT JOIN' => [
283-
'glpi_plugin_fields_fields' => [
284-
'FKEY' => [
285-
'glpi_plugin_fields_containers' => 'id',
286-
'glpi_plugin_fields_fields' => 'plugin_fields_containers_id',
287-
],
288-
],
289-
],
290-
'WHERE' => [
291-
'glpi_plugin_fields_fields.name' => $field,
292-
],
293-
]);
294-
if (count($iterator) > 0) {
295-
$data = $iterator->current();
296-
297-
//retrieve computer
298-
$agents_id = $params['input']['plugin_fusioninventory_agents_id'];
299-
$agent->getFromDB($agents_id);
300-
301-
// update current field
302-
$container->updateFieldsValues(
303-
[
304-
'plugin_fields_containers_id' => $data['id'],
305-
$field => $value,
306-
'items_id' => $agent->fields['computers_id'],
307-
],
308-
Computer::getType(),
309-
);
310-
}
311-
}
312-
}
313-
}
314-
}
315-
316234
function plugin_fields_giveItem($itemtype, $ID, $data, $num)
317235
{
318236
$searchopt = &Search::getOptions($itemtype);

0 commit comments

Comments
 (0)