本文整理匯總了PHP中PolicySet類的典型用法代碼示例。如果您正苦於以下問題:PHP PolicySet類的具體用法?PHP PolicySet怎麽用?PHP PolicySet使用的例子?那麽, 這裏精選的類代碼示例或許可以為您提供幫助。
在下文中一共展示了PolicySet類的15個代碼示例,這些例子默認根據受歡迎程度排序。您可以為喜歡或者感覺有用的代碼點讚,您的評價將有助於係統推薦出更棒的PHP代碼示例。
示例1: buildSubmissionAccessPolicy
/**
*
* @param PKPRequest $request
* @param array $args
* @param array $roleAssignments
* @param string $submissionParameterName
*/
function buildSubmissionAccessPolicy($request, $args, $roleAssignments, $submissionParameterName)
{
// We need a submission in the request.
import('lib.pkp.classes.security.authorization.internal.SubmissionRequiredPolicy');
$this->addPolicy(new SubmissionRequiredPolicy($request, $args, $submissionParameterName));
// Authors, managers and series editors potentially have
// access to submissions. We'll have to define differentiated
// policies for those roles in a policy set.
$submissionAccessPolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
//
// Managerial role
//
if (isset($roleAssignments[ROLE_ID_MANAGER])) {
// Managers have access to all submissions.
$submissionAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_MANAGER, $roleAssignments[ROLE_ID_MANAGER]));
}
//
// Author role
//
if (isset($roleAssignments[ROLE_ID_AUTHOR])) {
// 1) Author role user groups can access whitelisted operations ...
$authorSubmissionAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$authorSubmissionAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_AUTHOR, $roleAssignments[ROLE_ID_AUTHOR], 'user.authorization.authorRoleMissing'));
// 2) ... if they meet one of the following requirements:
$authorSubmissionAccessOptionsPolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
// 2a) ...the requested submission is their own ...
import('lib.pkp.classes.security.authorization.internal.SubmissionAuthorPolicy');
$authorSubmissionAccessOptionsPolicy->addPolicy(new SubmissionAuthorPolicy($request));
// 2b) ...OR, at least one workflow stage has been assigned to them in the requested submission.
import('classes.security.authorization.internal.UserAccessibleWorkflowStageRequiredPolicy');
$authorSubmissionAccessOptionsPolicy->addPolicy(new UserAccessibleWorkflowStageRequiredPolicy($request));
$authorSubmissionAccessPolicy->addPolicy($authorSubmissionAccessOptionsPolicy);
$submissionAccessPolicy->addPolicy($authorSubmissionAccessPolicy);
}
//
// Reviewer role
//
if (isset($roleAssignments[ROLE_ID_REVIEWER])) {
// 1) Reviewers can access whitelisted operations ...
$reviewerSubmissionAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$reviewerSubmissionAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_REVIEWER, $roleAssignments[ROLE_ID_REVIEWER]));
// 2) ... but only if they have been assigned to the submission as reviewers.
import('lib.pkp.classes.security.authorization.internal.ReviewAssignmentAccessPolicy');
$reviewerSubmissionAccessPolicy->addPolicy(new ReviewAssignmentAccessPolicy($request));
$submissionAccessPolicy->addPolicy($reviewerSubmissionAccessPolicy);
}
//
// Assistant role
//
if (isset($roleAssignments[ROLE_ID_ASSISTANT])) {
// 1) Assistants can access whitelisted operations ...
$contextSubmissionAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$contextSubmissionAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_ASSISTANT, $roleAssignments[ROLE_ID_ASSISTANT]));
// 2) ... but only if they have been assigned to the submission workflow.
import('classes.security.authorization.internal.UserAccessibleWorkflowStageRequiredPolicy');
$contextSubmissionAccessPolicy->addPolicy(new UserAccessibleWorkflowStageRequiredPolicy($request));
$submissionAccessPolicy->addPolicy($contextSubmissionAccessPolicy);
}
return $submissionAccessPolicy;
}
示例2: authorize
function authorize($request, &$args, $roleAssignments)
{
$fileIds = $request->getUserVar('filesIdsAndRevisions');
$libraryFileId = $request->getUserVar('libraryFileId');
if (is_string($fileIds)) {
$fileIdsArray = explode(';', $fileIds);
// Remove empty entries (a trailing ";" will cause these)
$fileIdsArray = array_filter($fileIdsArray, create_function('$a', 'return !empty($a);'));
}
if (!empty($fileIdsArray)) {
$multipleSubmissionFileAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
foreach ($fileIdsArray as $fileIdAndRevision) {
$multipleSubmissionFileAccessPolicy->addPolicy($this->_getAccessPolicy($request, $args, $roleAssignments, $fileIdAndRevision));
}
$this->addPolicy($multipleSubmissionFileAccessPolicy);
} else {
if (is_numeric($libraryFileId)) {
import('lib.pkp.classes.security.authorization.ContextAccessPolicy');
$this->addPolicy(new ContextAccessPolicy($request, $roleAssignments));
} else {
// IDs will be specified using the default parameters.
$this->addPolicy($this->_getAccessPolicy($request, $args, $roleAssignments));
}
}
return parent::authorize($request, $args, $roleAssignments);
}
示例3: addPolicy
/**
* Add a new policy to the Resource
*
* @param Policy $policy Policy instance
*
* @return \Xacmlphp\Resource instance
*/
public function addPolicy(Policy $policy)
{
if ($this->policySet === null) {
$this->policySet = new PolicySet();
}
$this->policySet->addPolicy($policy);
return $this;
}
示例4: buildSignoffAccessPolicy
/**
*
* @param PKPRequest $request
* @param array $args
* @param array $roleAssignments
* @param $mode int bitfield SIGNOFF_ACCESS_...
* @param $stageId int
*/
function buildSignoffAccessPolicy($request, $args, $roleAssignments, $mode, $stageId)
{
// We need a submission matching the file in the request.
import('lib.pkp.classes.security.authorization.internal.SignoffExistsAccessPolicy');
$this->addPolicy(new SignoffExistsAccessPolicy($request, $args));
// We need a valid workflow stage.
import('lib.pkp.classes.security.authorization.internal.WorkflowStageRequiredPolicy');
$this->addPolicy(new WorkflowStageRequiredPolicy($stageId));
// Authors, context managers and sub editors potentially have
// access to signoffs. We'll have to define
// differentiated policies for those roles in a policy set.
$signoffAccessPolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
//
// Managerial role
//
if (isset($roleAssignments[ROLE_ID_MANAGER])) {
// Managers have all access to all signoffs.
$signoffAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_MANAGER, $roleAssignments[ROLE_ID_MANAGER]));
}
//
// Assistants
//
if (isset($roleAssignments[ROLE_ID_ASSISTANT])) {
// 1) Assistants can access all operations on signoffs...
$assistantSignoffAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$assistantSignoffAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_ASSISTANT, $roleAssignments[ROLE_ID_ASSISTANT]));
// 2) ... but only if they have access to the workflow stage.
import('classes.security.authorization.WorkflowStageAccessPolicy');
// pulled from context-specific class path.
$assistantSignoffAccessPolicy->addPolicy(new WorkflowStageAccessPolicy($request, $args, $roleAssignments, 'submissionId', $stageId));
$signoffAccessPolicy->addPolicy($assistantSignoffAccessPolicy);
}
//
// Authors
//
if (isset($roleAssignments[ROLE_ID_AUTHOR])) {
if ($mode & SIGNOFF_ACCESS_READ) {
// 1) Authors can access read operations on signoffs...
$authorSignoffAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$authorSignoffAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_AUTHOR, $roleAssignments[ROLE_ID_AUTHOR]));
// 2) ... but only if they are assigned to the workflow stage as an stage participant.
import('classes.security.authorization.WorkflowStageAccessPolicy');
$authorSignoffAccessPolicy->addPolicy(new WorkflowStageAccessPolicy($request, $args, $roleAssignments, 'submissionId', $stageId));
$signoffAccessPolicy->addPolicy($authorSignoffAccessPolicy);
}
}
//
// User owns the signoff (all roles): permit
//
import('lib.pkp.classes.security.authorization.internal.SignoffAssignedToUserAccessPolicy');
$userOwnsSignoffPolicy = new SignoffAssignedToUserAccessPolicy($request);
$signoffAccessPolicy->addPolicy($userOwnsSignoffPolicy);
$this->addPolicy($signoffAccessPolicy);
return $signoffAccessPolicy;
}
示例5: testRoleAuthorization
/**
* @covers RoleBasedHandlerOperationPolicy
*/
public function testRoleAuthorization()
{
// Construct the user roles array.
$userRoles = array(ROLE_ID_SITE_ADMIN, ROLE_ID_TEST);
// Test the user-group/role policy with a default
// authorized request.
$request = $this->getMockRequest('permittedOperation');
$rolePolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$rolePolicy->addPolicy($this->getAuthorizationContextManipulationPolicy());
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, array(ROLE_ID_TEST), 'permittedOperation'));
$decisionManager = new AuthorizationDecisionManager();
$decisionManager->addPolicy($rolePolicy);
self::assertEquals(AUTHORIZATION_PERMIT, $decisionManager->decide());
// Test the user-group/role policy with a non-authorized role.
$rolePolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$rolePolicy->addPolicy($this->getAuthorizationContextManipulationPolicy());
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_NON_AUTHORIZED, 'permittedOperation'));
$decisionManager = new AuthorizationDecisionManager();
$decisionManager->addPolicy($rolePolicy);
self::assertEquals(AUTHORIZATION_DENY, $decisionManager->decide());
// Test the policy with an authorized role but a non-authorized operation.
$request = $this->getMockRequest('privateOperation');
$rolePolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$rolePolicy->addPolicy($this->getAuthorizationContextManipulationPolicy());
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_SITE_ADMIN, 'permittedOperation'));
$decisionManager = new AuthorizationDecisionManager();
$decisionManager->addPolicy($rolePolicy);
self::assertEquals(AUTHORIZATION_DENY, $decisionManager->decide());
// Test the policy with an authorized role and a
// non-authorized operation but bypass the the operation check.
// FIXME: Remove the "bypass operation check" code once we've removed the
// HandlerValidatorRole compatibility class, see #5868.
$rolePolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$rolePolicy->addPolicy($this->getAuthorizationContextManipulationPolicy());
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_SITE_ADMIN, array(), 'some.message', false, true));
$decisionManager = new AuthorizationDecisionManager();
$decisionManager->addPolicy($rolePolicy);
self::assertEquals(AUTHORIZATION_PERMIT, $decisionManager->decide());
// Test the "all roles must match" feature.
$request = $this->getMockRequest('permittedOperation');
$rolePolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$rolePolicy->addPolicy($this->getAuthorizationContextManipulationPolicy());
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, array(ROLE_ID_SITE_ADMIN, ROLE_ID_TEST), 'permittedOperation', 'some.message', true, false));
$decisionManager = new AuthorizationDecisionManager();
$decisionManager->addPolicy($rolePolicy);
self::assertEquals(AUTHORIZATION_PERMIT, $decisionManager->decide());
// Test again the "all roles must match" feature but this time
// with one role not matching.
$rolePolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$rolePolicy->addPolicy($this->getAuthorizationContextManipulationPolicy());
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, array(ROLE_ID_TEST, ROLE_ID_SITE_ADMIN, ROLE_ID_NON_AUTHORIZED), 'permittedOperation', 'some.message', true, false));
$decisionManager = new AuthorizationDecisionManager();
$decisionManager->addPolicy($rolePolicy);
self::assertEquals(AUTHORIZATION_DENY, $decisionManager->decide());
}
示例6: authorize
/**
* @copydoc PKPHandler::authorize()
*/
function authorize($request, &$args, $roleAssignments)
{
import('lib.pkp.classes.security.authorization.PolicySet');
$rolePolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
import('lib.pkp.classes.security.authorization.RoleBasedHandlerOperationPolicy');
foreach ($roleAssignments as $role => $operations) {
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, $role, $operations));
}
$this->addPolicy($rolePolicy);
return parent::authorize($request, $args, $roleAssignments);
}
示例7: OjsJournalAccessPolicy
/**
* Constructor
* @param $request PKPRequest
* @param $roleAssignments array
*/
function OjsJournalAccessPolicy(&$request, $roleAssignments)
{
parent::JournalPolicy($request);
// On journal level we don't have role-specific conditions
// so we can simply add all role assignments. It's ok if
// any of these role conditions permits access.
$journalRolePolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
import('lib.pkp.classes.security.authorization.RoleBasedHandlerOperationPolicy');
foreach ($roleAssignments as $role => $operations) {
$journalRolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, $role, $operations));
}
$this->addPolicy($journalRolePolicy);
}
示例8: OjsAuthorDashboardAccessPolicy
/**
* Constructor
* @param $request PKPRequest
* @param $args array request arguments
* @param $roleAssignments array
*/
function OjsAuthorDashboardAccessPolicy($request, &$args, $roleAssignments)
{
parent::ContextPolicy($request);
$authorDashboardPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
// AuthorDashboard requires a valid monograph in request.
import('classes.security.authorization.SubmissionAccessPolicy');
$authorDashboardPolicy->addPolicy(new SubmissionAccessPolicy($request, $args, $roleAssignments), true);
// Check if the user has an stage assignment with the monograph in request.
// Any workflow stage assignment is suficient to access the author dashboard.
import('classes.security.authorization.internal.UserAccessibleWorkflowStageRequiredPolicy');
$authorDashboardPolicy->addPolicy(new UserAccessibleWorkflowStageRequiredPolicy($request));
$this->addPolicy($authorDashboardPolicy);
}
示例9: JournalPolicy
/**
* Constructor
* @param $request PKPRequest
*/
function JournalPolicy(&$request)
{
parent::PolicySet();
// Ensure that we have a journal in the context.
import('lib.pkp.classes.security.authorization.ContextRequiredPolicy');
$this->addPolicy(new ContextRequiredPolicy($request, 'user.authorization.noJournal'));
}
示例10: authorize
/**
* @see PKPHandler::authorize()
*/
function authorize($request, &$args, $roleAssignments)
{
import('lib.pkp.classes.security.authorization.PolicySet');
$rolePolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
import('lib.pkp.classes.security.authorization.RoleBasedHandlerOperationPolicy');
foreach ($roleAssignments as $role => $operations) {
$rolePolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, $role, $operations));
}
$this->addPolicy($rolePolicy);
$this->reviewFormId = (int) $request->getUserVar('reviewFormId');
$reviewFormDao = DAORegistry::getDAO('ReviewFormDAO');
if (!$reviewFormDao->reviewFormExists($this->reviewFormId, Application::getContextAssocType(), $request->getContext()->getId())) {
return false;
}
return parent::authorize($request, $args, $roleAssignments);
}
開發者ID:relaciones-internacionales-journal,項目名稱:pkp-lib,代碼行數:19,代碼來源:ReviewFormElementsGridHandler.inc.php
示例11: PressPolicy
/**
* Constructor
* @param $request PKPRequest
*/
function PressPolicy(&$request)
{
parent::PolicySet();
// Ensure we're in a press
import('lib.pkp.classes.security.authorization.ContextRequiredPolicy');
$this->addPolicy(new ContextRequiredPolicy($request, 'user.authorization.noPress'));
}
示例12: OjsSubmissionAccessPolicy
/**
* Constructor
* @param $request PKPRequest
* @param $args array
* @param $roleAssignments array
* @param $submissionParameterName string
*/
function OjsSubmissionAccessPolicy(&$request, &$args, $roleAssignments, $submissionParameterName = 'articleId')
{
parent::JournalPolicy($request);
// Create a "permit overrides" policy set that specifies
// editor and copyeditor access to submissions.
$submissionEditingPolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
//
// Editor roles (Editor and Section Editor) policy
//
$editorsPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
// Editorial components can only be called if there's a
// valid section editor submission in the request.
// FIXME: We should find a way to check whether the user actually
// is a (section) editor before we execute this expensive policy.
import('classes.security.authorization.internal.SectionEditorSubmissionRequiredPolicy');
$editorsPolicy->addPolicy(new SectionEditorSubmissionRequiredPolicy($request, $args, $submissionParameterName));
$editorRolesPolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
// Editors can access all operations.
$editorRolesPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_EDITOR, $roleAssignments[ROLE_ID_EDITOR]));
// Section editors
$sectionEditorPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
// 1) Section editors can access all remote operations ...
$sectionEditorPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_SECTION_EDITOR, $roleAssignments[ROLE_ID_SECTION_EDITOR]));
// 2) ... but only if the requested submission has been explicitly assigned to them.
import('classes.security.authorization.internal.SectionSubmissionAssignmentPolicy');
$sectionEditorPolicy->addPolicy(new SectionSubmissionAssignmentPolicy($request));
$editorRolesPolicy->addPolicy($sectionEditorPolicy);
$editorsPolicy->addPolicy($editorRolesPolicy);
$submissionEditingPolicy->addPolicy($editorsPolicy);
//
// Copyeditor policy
//
$copyeditorPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
// 1) Copyeditors can only access editorial components when a valid
// copyeditor submission is in the request ...
import('classes.security.authorization.internal.CopyeditorSubmissionRequiredPolicy');
$copyeditorPolicy->addPolicy(new CopyeditorSubmissionRequiredPolicy($request, $args, $submissionParameterName));
// 2) ... If that's the case then copyeditors can access all remote operations ...
$copyeditorPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_COPYEDITOR, $roleAssignments[ROLE_ID_SECTION_EDITOR]));
// 3) ... but only if the requested submission has been explicitly assigned to them.
import('classes.security.authorization.internal.CopyeditorSubmissionAssignmentPolicy');
$copyeditorPolicy->addPolicy(new CopyeditorSubmissionAssignmentPolicy($request));
$submissionEditingPolicy->addPolicy($copyeditorPolicy);
// Add the submission editing policies to this policy set.
$this->addPolicy($submissionEditingPolicy);
}
示例13: SignoffAccessPolicy
/**
* Constructor
* @param $request PKPRequest
* @param $args array request parameters
* @param $roleAssignments array
* @param $mode int bitfield SIGNOFF_ACCESS_...
* @param $stageId int
*/
function SignoffAccessPolicy($request, $args, $roleAssignments, $mode, $stageId)
{
parent::PKPSignoffAccessPolicy($request, $args, $roleAssignments, $mode, $stageId);
$signoffAccessPolicy = $this->_baseSignoffAccessPolicy;
//
// Series editor role
//
if (isset($roleAssignments[ROLE_ID_SUB_EDITOR])) {
// 1) Section editors can access all operations on signoffs ...
$sectionEditorFileAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$sectionEditorFileAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_SUB_EDITOR, $roleAssignments[ROLE_ID_SUB_EDITOR]));
// 2) ... but only if the requested signoff submission is part of their series.
import('classes.security.authorization.internal.SectionAssignmentPolicy');
$sectionEditorFileAccessPolicy->addPolicy(new SectionAssignmentPolicy($request));
$signoffAccessPolicy->addPolicy($sectionEditorFileAccessPolicy);
}
}
示例14: OmpPublishedMonographAccessPolicy
/**
* Constructor
* @param $request PKPRequest
* @param $args array request parameters
* @param $roleAssignments array
* @param $submissionParameterName string the request parameter we
* expect the submission id in.
*/
function OmpPublishedMonographAccessPolicy($request, $args, $roleAssignments, $submissionParameterName = 'submissionId')
{
parent::ContextPolicy($request);
// Access may be made either as a member of the public, or
// via pre-publication access to editorial users.
$monographAccessPolicy = new PolicySet(COMBINING_PERMIT_OVERRIDES);
// Published monograph access for the public
$publishedMonographAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
import('lib.pkp.classes.security.authorization.internal.SubmissionRequiredPolicy');
$publishedMonographAccessPolicy->addPolicy(new SubmissionRequiredPolicy($request, $args, $submissionParameterName));
import('classes.security.authorization.internal.MonographPublishedPolicy');
$publishedMonographAccessPolicy->addPolicy(new MonographPublishedPolicy($request));
$monographAccessPolicy->addPolicy($publishedMonographAccessPolicy);
// Pre-publication access for editorial roles
import('classes.security.authorization.SubmissionAccessPolicy');
$monographAccessPolicy->addPolicy(new SubmissionAccessPolicy($request, $args, array_intersect_key($roleAssignments, array(ROLE_ID_MANAGER, ROLE_ID_SUB_EDITOR)), $submissionParameterName));
$this->addPolicy($monographAccessPolicy);
}
示例15: SubmissionFileAccessPolicy
/**
* Constructor
* @param $request PKPRequest
* @param $args array request parameters
* @param $roleAssignments array
* @param $mode int bitfield SUBMISSION_FILE_ACCESS_...
* @param $fileIdAndRevision string
* @param $submissionParameterName string the request parameter we expect
* the submission id in.
*/
function SubmissionFileAccessPolicy($request, $args, $roleAssignments, $mode, $fileIdAndRevision = null, $submissionParameterName = 'submissionId')
{
parent::PKPSubmissionFileAccessPolicy($request, $args, $roleAssignments, $mode, $fileIdAndRevision, $submissionParameterName);
$fileAccessPolicy = $this->_baseFileAccessPolicy;
//
// Series editor role
//
if (isset($roleAssignments[ROLE_ID_SUB_EDITOR])) {
// 1) Series editors can access all operations on submissions ...
$seriesEditorFileAccessPolicy = new PolicySet(COMBINING_DENY_OVERRIDES);
$seriesEditorFileAccessPolicy->addPolicy(new RoleBasedHandlerOperationPolicy($request, ROLE_ID_SUB_EDITOR, $roleAssignments[ROLE_ID_SUB_EDITOR]));
// 2) ... but only if the requested submission is part of their series.
import('classes.security.authorization.internal.SeriesAssignmentPolicy');
$seriesEditorFileAccessPolicy->addPolicy(new SeriesAssignmentPolicy($request));
$fileAccessPolicy->addPolicy($seriesEditorFileAccessPolicy);
}
$this->addPolicy($fileAccessPolicy);
}