TYPO3中fe_users的细粒度文件与文件夹访问权限配置问询
TYPO3前端用户专属文件夹细粒度访问控制求助
核心需求
基于fe_users实现单用户级细粒度文件访问控制,仅允许每个前端用户访问自己的专属文件夹。目前已通过修改sr_feuser_register扩展实现新用户注册时自动生成fileadmin下的专属文件夹,需为用户配置对应文件夹的只读权限。
已尝试方案及问题
- TYPO3内置权限系统仅支持组级权限分配,无法实现单文件夹对单个用户的精准控制
- 测试了
secure_downloads、fal_securedownload等扩展,均无法满足单用户专属文件夹的访问控制需求
当前环境
- TYPO3 v11.5.22(非Composer模式)
- 使用
sr_feuser_register扩展管理前端用户注册
现有自定义代码(修改的sr_feuser_register扩展CreateActionController.php)
<?php namespace SJBR\SrFeuserRegister\Controller; //....classes /** * Create action controller */ class CreateActionController extends AbstractActionController { /** * Processes the create request * * @param array $dataArray: array of form input fields * @param string $cmd: the command * @param string $cmdKey: the command key * @return string the template with substituted markers */ public function doProcessing(array $finalDataArray, $cmd, $cmdKey) { //...... // Set the time zone date_default_timezone_set('Europe/Berlin'); // Replace 'Europe/Berlin' with your desired time zone // Get the current date $currentDate = date('ymd'); // Prepare the folder name $firstName = $finalDataArray['first_name']; $lastName = $finalDataArray['last_name']; // Convert special characters to ASCII equivalents $firstName = iconv('UTF-8', 'ASCII//TRANSLIT', $firstName); $lastName = iconv('UTF-8', 'ASCII//TRANSLIT', $lastName); // Replace umlaut characters with their ASCII equivalents $firstName = str_replace(['ä', 'ö', 'ü', 'ß'], ['ae', 'oe', 'ue', 'ss'], $firstName); $lastName = str_replace(['ä', 'ö', 'ü', 'ß'], ['ae', 'oe', 'ue', 'ss'], $lastName); // Remove non-alphanumeric characters $firstName = preg_replace('/[^a-zA-Z0-9]/', '', $firstName); $lastName = preg_replace('/[^a-zA-Z0-9]/', '', $lastName); // Check if the first name and last name are not empty if (!empty($firstName) && !empty($lastName)) { // Construct the folder name $folderName = $currentDate . '_' . strtolower($lastName) . '_' . strtolower($firstName); // Create the folder path $folderPath = 'fileadmin/data/' . $folderName; // Attempt to create the folder if (mkdir($folderPath, 0755)) { // Folder created successfully // Set folder permissions chmod($folderPath, 0755); // Adjust the permissions as needed // Get the FE user UID $feUserUid = $GLOBALS['TSFE']->fe_user->user['uid']; // Set folder access rights for the FE user $feUserUid = $GLOBALS['TSFE']->fe_user->user['uid']; // Get the FE user group ID $groupId = $GLOBALS['TSFE']->fe_user->user['usergroup']; // Get the TYPO3 database connection $databaseConnection = GeneralUtility::makeInstance(\TYPO3\CMS\Core\Database\ConnectionPool::class)->getConnectionForTable('sys_file_metadata'); // Clear any existing folder permissions for the patient's folder $databaseConnection->exec_DELETEquery( 'sys_file_metadata', $databaseConnection->quoteIdentifier('table_local') . ' = 1 AND ' . $databaseConnection->quoteIdentifier('identifier') . ' = ' . $databaseConnection->quote($folderName) ); // Grant folder permissions to the FE user group for the patient's folder $databaseConnection->insert( 'sys_file_metadata', [ 'uid' => $groupId, 'table_local' => 1, 'identifier' => $folderName, 'permissions' => 31, // Set desired folder permissions (e.g., 31 for full access) 'modified' => time() ] ); } } //...... } }
期望
寻求能与现有组件无缝集成的解决方案,接受自定义开发或合适的第三方扩展。
内容的提问来源于stack exchange,提问作者weiss
相关产品推荐
相关产品推荐

