]> WPIA git - gigi.git/blobdiff - src/org/cacert/gigi/pages/orga/ViewOrgPage.java
fix: SQL change database call pattern
[gigi.git] / src / org / cacert / gigi / pages / orga / ViewOrgPage.java
index 16c8bc5388a7b90e4a815c853c54444b93bf136e..9e470240d95124bab73db23e98d5fc558ec67553 100644 (file)
@@ -18,6 +18,7 @@ import org.cacert.gigi.output.template.IterableDataset;
 import org.cacert.gigi.output.template.Template;
 import org.cacert.gigi.pages.LoginPage;
 import org.cacert.gigi.pages.Page;
+import org.cacert.gigi.util.AuthorizationContext;
 
 public class ViewOrgPage extends Page {
 
@@ -32,25 +33,33 @@ public class ViewOrgPage extends Page {
     }
 
     @Override
-    public boolean isPermitted(User u) {
-        return u != null && (u.isInGroup(CreateOrgPage.ORG_ASSURER) || u.getOrganisations().size() != 0);
+    public boolean isPermitted(AuthorizationContext ac) {
+        return ac != null && (ac.isInGroup(CreateOrgPage.ORG_ASSURER) || ac.getActor().getOrganisations().size() != 0);
     }
 
     @Override
     public void doPost(HttpServletRequest req, HttpServletResponse resp) throws IOException {
         try {
             User u = LoginPage.getUser(req);
-            if ( !u.isInGroup(CreateOrgPage.ORG_ASSURER)) {
-                return;
-            }
             if (req.getParameter("do_affiliate") != null || req.getParameter("del") != null) {
                 AffiliationForm form = Form.getForm(req, AffiliationForm.class);
                 if (form.submit(resp.getWriter(), req)) {
                     resp.sendRedirect(DEFAULT_PATH + "/" + form.getOrganisation().getId());
                 }
+                return;
+            } else if (req.getParameter("addDomain") != null) {
+                if (Form.getForm(req, OrgDomainAddForm.class).submit(resp.getWriter(), req)) {
+                    // resp.sendRedirect(DEFAULT_PATH + "/" +
+                    // form.getOrganisation().getId());
+                }
             } else {
+                if ( !u.isInGroup(CreateOrgPage.ORG_ASSURER)) {
+                    resp.sendError(403, "Access denied");
+                    return;
+                }
                 Form.getForm(req, CreateOrgForm.class).submit(resp.getWriter(), req);
             }
+
         } catch (GigiApiException e) {
             e.format(resp.getWriter(), getLanguage(req));
         }
@@ -87,6 +96,7 @@ public class ViewOrgPage extends Page {
         HashMap<String, Object> vars = new HashMap<>();
         vars.put("editForm", new CreateOrgForm(req, o));
         vars.put("affForm", new AffiliationForm(req, o));
+        vars.put("addDom", new OrgDomainAddForm(req, o));
         mainTempl.output(out, lang, vars);
     }