* @since 1.8
*/
function elgg_delete_annotations(array $options) {
- if (!$options || !is_array($options)) {
+ if (!elgg_is_valid_options_for_batch_operation($options, 'annotations')) {
return false;
}
* @since 1.8
*/
function elgg_disable_annotations(array $options) {
- if (!$options || !is_array($options)) {
+ if (!elgg_is_valid_options_for_batch_operation($options, 'annotations')) {
return false;
}
if (!$owner_guid) {
return false;
}
- return elgg_delete_metadata(array('metadata_owner' => $owner_guid, 'limit' => 0));
+ return elgg_delete_metadata(array('metadata_owner_guid' => $owner_guid, 'limit' => 0));
}
/**
return $object->delete() ? true : false;
}
+/**
+ * Checks if there are some constraints on the options array for
+ * potentially dangerous operations.
+ *
+ * @param array $options Options array
+ * @param string $type Options type: metadata or annotations
+ * @return bool
+ */
+function elgg_is_valid_options_for_batch_operation($options, $type) {
+ if (!$options || !is_array($options)) {
+ return false;
+ }
+
+ // at least one of these is required.
+ $required = array(
+ // generic restraints
+ 'guid', 'guids', 'limit'
+ );
+
+ switch ($type) {
+ case 'metadata':
+ $metadata_required = array(
+ 'metadata_owner_guid', 'metadata_owner_guids',
+ 'metadata_name', 'metadata_names',
+ 'metadata_value', 'metadata_values'
+ );
+
+ $required = array_merge($required, $metadata_required);
+ break;
+
+ case 'annotations':
+ case 'annotation':
+ $annotations_required = array(
+ 'annotation_owner_guid', 'annotation_owner_guids',
+ 'annotation_name', 'annotation_names',
+ 'annotation_value', 'annotation_values'
+ );
+
+ $required = array_merge($required, $annotations_required);
+ break;
+
+ default:
+ return false;
+ }
+
+ foreach ($required as $key) {
+ // check that it exists and is something.
+ if (isset($options[$key]) && $options[$key]) {
+ return true;
+ }
+ }
+
+ return false;
+}
+
/**
* Intercepts the index page when Walled Garden mode is enabled.
*
* Deletes metadata based on $options.
*
* @warning Unlike elgg_get_metadata() this will not accept an empty options array!
+ * This requires some constraints: metadata_owner_guid(s),
+ * metadata_name(s), metadata_value(s), or limit must be set.
*
* @param array $options An options array. {@See elgg_get_metadata()}
* @return mixed
* @since 1.8
*/
function elgg_delete_metadata(array $options) {
- if (!$options || !is_array($options)) {
+ if (!elgg_is_valid_options_for_batch_operation($options, 'metadata')) {
return false;
}
* @since 1.8
*/
function elgg_disable_metadata(array $options) {
- if (!$options || !is_array($options)) {
+ if (!elgg_is_valid_options_for_batch_operation($options, 'metadata')) {
return false;
}
}
}
+ public function testKeepMeFromDeletingEverything() {
+ foreach ($this->metastringTypes as $type) {
+ $required = array(
+ 'guid', 'guids', 'limit'
+ );
+
+ switch ($type) {
+ case 'metadata':
+ $metadata_required = array(
+ 'metadata_owner_guid', 'metadata_owner_guids',
+ 'metadata_name', 'metadata_names',
+ 'metadata_value', 'metadata_values'
+ );
+
+ $required = array_merge($required, $metadata_required);
+ break;
+
+ case 'annotations':
+ $annotations_required = array(
+ 'annotation_owner_guid', 'annotation_owner_guids',
+ 'annotation_name', 'annotation_names',
+ 'annotation_value', 'annotation_values'
+ );
+
+ $required = array_merge($required, $annotations_required);
+ break;
+ }
+
+ $options = array();
+ $this->assertFalse(elgg_is_valid_options_for_batch_operation($options), $type);
+
+ foreach ($required as $key) {
+ $options = array();
+ $options[$key] = ELGG_ENTITIES_ANY_VALUE;
+ $this->assertFalse(elgg_is_valid_options_for_batch_operation($options, $type), "Sent $key = ELGG_ENTITIES_ANY_VALUE");
+
+ $options[$key] = ELGG_ENTITIES_NO_VALUE;
+ $this->assertFalse(elgg_is_valid_options_for_batch_operation($options, $type), "Sent $key = ELGG_ENTITIES_NO_VALUE");
+
+ $options[$key] = false;
+ $this->assertFalse(elgg_is_valid_options_for_batch_operation($options, $type), "Sent $key = bool false");
+
+ $options[$key] = true;
+ $this->assertTrue(elgg_is_valid_options_for_batch_operation($options, $type), "Sent $key = bool true");
+
+ $options[$key] = 'test';
+ $this->assertTrue(elgg_is_valid_options_for_batch_operation($options, $type), "Sent $key = 'test'");
+
+ $options[$key] = array('test');
+ $this->assertTrue(elgg_is_valid_options_for_batch_operation($options, $type), "Sent $key = array('test')");
+ }
+ }
+ }
}
$annotation = $annotation[0];
}
}
+$annotation = null;
$page_icon = elgg_view('pages/icon', array('annotation' => $annotation, 'size' => 'small'));