TYPO3中借助fal_securedownload自动配置用户组文件夹访问权限
我在TYPO3中实现了一个EventListener,可为每个新注册用户生成用户组,注册过程中还会为每个用户组在文件系统创建对应文件夹。使用fal_securedownload扩展管理访问限制,已在根目录外配置非公开文件存储。
需求是:用户注册时自动将用户组(或直接用户)分配到专属文件夹,确保用户仅能访问自己文件夹内的文件。
我尝试往tx_falsecuredownload_folder表中添加文件夹路径和组ID,但代码未生效,用户组未被添加到文件夹权限中。以下是我的EventListener代码片段:
<?php namespace xxx\yyy\EventListener; use TYPO3\CMS\Core\Utility\GeneralUtility; use TYPO3\CMS\Extbase\Object\ObjectManager; use TYPO3\CMS\Extbase\Domain\Repository\FrontendUserGroupRepository; use TYPO3\CMS\Extbase\Domain\Model\FrontendUserGroup; use TYPO3\CMS\Extbase\Domain\Repository\FrontendUserRepository; use TYPO3\CMS\Core\Database\ConnectionPool; class FinalCreateEventListener { protected $objectManager; public function __construct(ObjectManager $objectManager) { $this->objectManager = $objectManager; } public function __invoke($event): void { $feUser = $event->getUser(); // Load the needed Repos $groupRepository = $this->objectManager->get(\TYPO3\CMS\Extbase\Domain\Repository\FrontendUserGroupRepository::class); $frontendUserRepository = $this->objectManager->get(\TYPO3\CMS\Extbase\Domain\Repository\FrontendUserRepository::class); $persistenceManager = $this->objectManager->get(\TYPO3\CMS\Extbase\Persistence\Generic\PersistenceManager::class); // Create the new Group and set the properties $userGroup = $this->objectManager->get(\TYPO3\CMS\Extbase\Domain\Model\FrontendUserGroup::class); $userGroup->setTitle($feUser->getUsername()); $userGroup->setPid(125); // Set the parent ID to the desired folder ID // Add the new user group to the repository and persist the changes $groupRepository->add($userGroup); $persistenceManager->persistAll(); // Assign the user group to the user, update the FeUser, and persist the changes $feUser->addUsergroup($userGroup); $frontendUserRepository->update($feUser); $persistenceManager->persistAll(); // Construct the folder name $folderName = $feUser->getUsername(); // Create the folder path $folderPath = '../data/' . $folderName; // Attempt to create the folder if (mkdir($folderPath, 0755)) { // Folder created successfully // Set folder permissions chmod($folderPath, 0755); // Adjust the permissions as needed // Get the database connection $connectionPool = GeneralUtility::makeInstance(ConnectionPool::class); $queryBuilder = $connectionPool->getQueryBuilderForTable('tx_falsecuredownload_folder'); // Generate folder hash $folderHash = md5($folderPath); // Prepare the data to be inserted $data = [ 'pid' => 0, 'tstamp' => time(), 'crdate' => time(), 'storage' => 8, // Adjust the storage value as per your requirements 'folder' => '/'.$folderName.'/', // Adjust the folder name format as needed 'folder_hash' => $folderHash, 'fe_groups' => $userGroup->getUid(), ]; // Insert the data into the table $queryBuilder->insert('tx_falsecuredownload_folder')->values($data)->execute(); } } }
问题排查与修复建议
1. 匹配folder字段格式
fal_securedownload的folder字段需与存储配置的根路径对应。若存储(storage=8)的根路径为../data/,则folder应设为/.$folderName(而非带尾部斜杠),或与存储根路径组合后完全匹配实际文件路径。可参考后台手动添加权限时的folder格式保持一致。
2. 修正folder_hash生成逻辑
插件内部并非直接对$folderPath做MD5哈希,而是基于存储ID + 文件夹路径的组合计算。可参考\TYPO3\CMS\FalSecuredownload\Service\FolderPermissionService中的哈希生成逻辑,确保你的哈希值与插件生成的一致。
3. 调整pid字段值
当前pid设为0,建议改为与用户组相同的PID(125),确保记录归属于正确站点树,避免权限继承异常。
4. 添加缓存清理步骤
TYPO3数据库操作后需清理相关缓存,尤其是fal_securedownload的权限缓存:
GeneralUtility::makeInstance(\TYPO3\CMS\Core\Cache\CacheManager::class)->flushCachesInGroup('pages');
5. 使用扩展官方API替代直接数据库操作
优先使用fal_securedownload提供的API添加权限,避免直接操作表引发的兼容问题:
// 创建文件夹后替换原数据库插入代码 $storageUid = 8; $relativeFolderPath = '/'.$folderName.'/'; $permissionService = GeneralUtility::makeInstance(\TYPO3\CMS\FalSecuredownload\Service\FolderPermissionService::class); $permissionService->addPermission( $storageUid, $relativeFolderPath, [$userGroup->getUid()], // 用户组ID数组 [] // 直接分配用户的ID数组(可选) );
6. 调试数据库插入结果
插入后可打印SQL语句确认正确性,或直接检查数据库表tx_falsecuredownload_folder是否存在对应记录,以及fe_groups字段是否正确存储组ID(该字段为逗号分隔的字符串,多组时需用逗号拼接)。
7. 验证文件夹权限与存储配置
确保创建的文件夹../data/.$folderName权限允许TYPO3进程读写,且存储配置(storage=8)的根路径正确指向../data/,否则插件无法识别该文件夹。
内容的提问来源于stack exchange,提问作者weiss

