]> WPIA git - gigi.git/blobdiff - src/org/cacert/gigi/pages/orga/ViewOrgPage.java
Clean: use "authorizationContexts"
[gigi.git] / src / org / cacert / gigi / pages / orga / ViewOrgPage.java
index c4b65ca965bb3ba062b696c4109717abffb48045..b2b39f1ac89631218502cdd1083cbef1d754e586 100644 (file)
@@ -18,6 +18,7 @@ import org.cacert.gigi.output.template.IterableDataset;
 import org.cacert.gigi.output.template.Template;
 import org.cacert.gigi.pages.LoginPage;
 import org.cacert.gigi.pages.Page;
+import org.cacert.gigi.util.AuthorizationContext;
 
 public class ViewOrgPage extends Page {
 
@@ -32,24 +33,28 @@ public class ViewOrgPage extends Page {
     }
 
     @Override
-    public boolean isPermitted(User u) {
-        return u != null && (u.isInGroup(CreateOrgPage.ORG_ASSURER) || u.getOrganisations().size() != 0);
+    public boolean isPermitted(AuthorizationContext ac) {
+        return ac != null && (ac.isInGroup(CreateOrgPage.ORG_ASSURER) || ac.getActor().getOrganisations().size() != 0);
     }
 
     @Override
     public void doPost(HttpServletRequest req, HttpServletResponse resp) throws IOException {
         try {
             User u = LoginPage.getUser(req);
-            if ( !u.isInGroup(CreateOrgPage.ORG_ASSURER)) {
-                return;
-            }
-            if (req.getParameter("affiliate") != null) {
+            if (req.getParameter("do_affiliate") != null || req.getParameter("del") != null) {
                 AffiliationForm form = Form.getForm(req, AffiliationForm.class);
-                form.submit(resp.getWriter(), req);
-                resp.sendRedirect(DEFAULT_PATH + "/" + form.getOrganisation().getId());
+                if (form.submit(resp.getWriter(), req)) {
+                    resp.sendRedirect(DEFAULT_PATH + "/" + form.getOrganisation().getId());
+                }
+                return;
             } else {
+                if ( !u.isInGroup(CreateOrgPage.ORG_ASSURER)) {
+                    resp.sendError(403, "Access denied");
+                    return;
+                }
                 Form.getForm(req, CreateOrgForm.class).submit(resp.getWriter(), req);
             }
+
         } catch (GigiApiException e) {
             e.format(resp.getWriter(), getLanguage(req));
         }
@@ -96,8 +101,9 @@ public class ViewOrgPage extends Page {
 
             @Override
             public boolean next(Language l, Map<String, Object> vars) {
-                if (count >= orgas.length)
+                if (count >= orgas.length) {
                     return false;
+                }
                 Organisation org = orgas[count++];
                 vars.put("id", Integer.toString(org.getId()));
                 vars.put("name", org.getName());