From c0fbfea48df38e1eb14e1449dafc33a8749daaab Mon Sep 17 00:00:00 2001 From: Rom1-B <8530352+Rom1-B@users.noreply.github.com> Date: Wed, 7 Oct 2026 10:47:05 +0200 Subject: [PATCH] Fix: preserve profile rights on plugin install/update --- CHANGELOG.md | 6 ++++ inc/profile.class.php | 80 +++++++++++++++++++++++++------------------ 2 files changed, 52 insertions(+), 34 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index aa2ac1a0..7300a5e7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,12 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](http://keepachangelog.com/) and this project adheres to [Semantic Versioning](http://semver.org/). +## [Unreleased] + +### Fixed + +- Profile rights to reports are no longer reset to "no access" each time the plugin is installed or updated + ## [1.11.0] - 2026-10-06 ### Added diff --git a/inc/profile.class.php b/inc/profile.class.php index bb57775c..166de063 100644 --- a/inc/profile.class.php +++ b/inc/profile.class.php @@ -154,27 +154,34 @@ public static function addRightToAllProfiles() /** @var DBmysql $DB */ global $DB; - $query_config = [ - 'SELECT' => 'id', - 'FROM' => PluginMreportingConfig::getTable(), - ]; - - $query_profil = [ - 'SELECT' => 'id', - 'FROM' => Profile::getTable(), - ]; + $profiles_ids = array_column( + iterator_to_array($DB->request(['SELECT' => 'id', 'FROM' => Profile::getTable()])), + 'id', + ); + $reports_ids = array_column( + iterator_to_array($DB->request(['SELECT' => 'id', 'FROM' => PluginMreportingConfig::getTable()])), + 'id', + ); - $result_config = $DB->request($query_config); - foreach ($DB->request($query_profil) as $prof) { - foreach ($result_config as $report) { - $DB->updateOrInsert('glpi_plugin_mreporting_profiles', [ - 'profiles_id' => $prof['id'], - 'reports' => $report['id'], - 'right' => null, - ], [ - 'profiles_id' => $prof['id'], - 'reports' => $report['id'], - ]); + // Only create the missing profile/report combinations, never overwrite an existing right + foreach ($profiles_ids as $profile_id) { + foreach ($reports_ids as $report_id) { + $already_exists = $DB->request([ + 'COUNT' => 'cpt', + 'FROM' => self::getTable(), + 'WHERE' => [ + 'profiles_id' => $profile_id, + 'reports' => $report_id, + ], + ])->current()['cpt'] > 0; + + if (!$already_exists) { + $DB->insert(self::getTable(), [ + 'profiles_id' => $profile_id, + 'reports' => $report_id, + 'right' => null, + ]); + } } } } @@ -209,26 +216,31 @@ public static function addRightToProfile(?int $idProfile = null): void /** @var DBmysql $DB */ global $DB; - $profiles_ids = []; $profiles_ids = is_null($idProfile) ? Profile::getSuperAdminProfilesId() : [$idProfile]; + $reports_ids = array_column( + iterator_to_array($DB->request(['SELECT' => 'id', 'FROM' => PluginMreportingConfig::getTable()])), + 'id', + ); - $config = new PluginMreportingConfig(); - $reports = $config->find(); - + // Only create the missing profile/report combinations, never overwrite an existing right foreach ($profiles_ids as $profileId) { - foreach ($reports as $report) { - $DB->updateOrInsert( - 'glpi_plugin_mreporting_profiles', - [ + foreach ($reports_ids as $report_id) { + $already_exists = $DB->request([ + 'COUNT' => 'cpt', + 'FROM' => self::getTable(), + 'WHERE' => [ 'profiles_id' => $profileId, - 'reports' => $report['id'], - 'right' => READ, + 'reports' => $report_id, ], - [ + ])->current()['cpt'] > 0; + + if (!$already_exists) { + $DB->insert(self::getTable(), [ 'profiles_id' => $profileId, - 'reports' => $report['id'], - ], - ); + 'reports' => $report_id, + 'right' => READ, + ]); + } } } }