使用PHP以每个用户权限为基础向MySQL数据库中的用户显示菜单项?

时间:2015-04-23 17:19:57

标签: php mysql acl

我有users的MySQL数据库表和menu links的新数据库表。使用PHP,更具体地说我也在使用Laravel。

我需要构建一个用户菜单,以每个用户权限为基础显示菜单项。

通常这是使用user groups完成的,但我的要求是基于每个用户构建它!

意味着每个菜单项需要为数据库中的每个用户保存一个yesno值。

然后我需要向每个用户显示此菜单,仅显示他们可以查看的菜单项。

我有用户并链接下面的MySQL数据库架构。

我需要帮助的是,我相信我需要添加另一个第3个表user_link_permissions,它将存储每个用户和菜单项的设置,以确定用户是否可以查看菜单项。

我不确定如何构建PHP以仅显示用户可以查看的菜单项,还可以使用一些帮助来了解第3个表可能需要的样子吗? < / p>

我非常喜欢构建菜单HTML输出的PHP代码,我认为可能有一个方法可以检查循环中的每个菜单项记录以查看当前用户是否有权查看它或者不......例子

// Array of menu items from MySQL Database or even just a MySQL result?
$menuItems = array();

foreach ($menuItems as $key => $value) {

    // can cureent user view this menu item record or not?
    if($this->user->canViewMenuItem($value)){
        // show menu item
    }

}

用户表

CREATE TABLE IF NOT EXISTS `users` (
  `user_id` int(10) unsigned NOT NULL AUTO_INCREMENT,
  `username` varchar(64) COLLATE utf8_unicode_ci NOT NULL,
  `password` varchar(160) COLLATE utf8_unicode_ci NOT NULL,
  `email` varchar(100) COLLATE utf8_unicode_ci DEFAULT NULL,
  `first_name` varchar(64) COLLATE utf8_unicode_ci NOT NULL,
  `last_name` varchar(64) COLLATE utf8_unicode_ci NOT NULL,
  `phone` varchar(100) COLLATE utf8_unicode_ci DEFAULT NULL,
  `address_street` varchar(64) COLLATE utf8_unicode_ci DEFAULT NULL,
  `address_city` varchar(64) COLLATE utf8_unicode_ci DEFAULT NULL,
  `address_state` varchar(64) COLLATE utf8_unicode_ci DEFAULT NULL,
  `address_postal_code` varchar(64) COLLATE utf8_unicode_ci DEFAULT NULL,
  `address_country` varchar(64) COLLATE utf8_unicode_ci NOT NULL DEFAULT 'USA',
  `job_position` varchar(100) COLLATE utf8_unicode_ci DEFAULT NULL,
  `user_role` enum('admin','manager','employee') COLLATE utf8_unicode_ci NOT NULL DEFAULT 'employee',
  `payday_group` varchar(100) COLLATE utf8_unicode_ci DEFAULT NULL,
  `default_user_photo_url` varchar(255) COLLATE utf8_unicode_ci DEFAULT NULL,
  `last_user_photo_url` varchar(255) COLLATE utf8_unicode_ci DEFAULT NULL,
  `created_date` datetime NOT NULL,
  `last_login_date` datetime DEFAULT NULL,
  `updated_date` datetime DEFAULT NULL,
  `login_counter` bigint(20) NOT NULL DEFAULT '0',
  `total_time_worked` bigint(20) DEFAULT NULL,
  `user_notes` text COLLATE utf8_unicode_ci,
  `time_zone` varchar(30) COLLATE utf8_unicode_ci NOT NULL DEFAULT 'US/Central',
  `clocked_in` tinyint(1) NOT NULL DEFAULT '0',
  `status` tinyint(1) NOT NULL DEFAULT '1',
  `webcam` tinyint(1) NOT NULL DEFAULT '1',
  PRIMARY KEY (`user_id`),
  UNIQUE KEY `users_username_unique` (`username`),
  UNIQUE KEY `users_email_unique` (`email`)
) ENGINE=InnoDB  DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci AUTO_INCREMENT=64 ;

链接表

CREATE TABLE IF NOT EXISTS `intranet_links` (
  `id` int(11) NOT NULL AUTO_INCREMENT,
  `title` varchar(255) DEFAULT NULL,
  `description` text NOT NULL,
  `url` varchar(255) DEFAULT NULL,
  `permission` varchar(50) NOT NULL DEFAULT 'admin',
  `notes` text,
  `active` int(2) NOT NULL DEFAULT '1',
  `sort_order` int(11) DEFAULT NULL,
  `parent_id` int(10) NOT NULL DEFAULT '1',
  PRIMARY KEY (`id`),
  UNIQUE KEY `id` (`id`)
) ENGINE=InnoDB  DEFAULT CHARSET=latin1 AUTO_INCREMENT=2 ;

稍微复杂一点,我的菜单也会有类似/文件夹/目录的层次结构。所以1个菜单项可以有子菜单项o我的实际菜单输出就像下面的图像一样,除了每个菜单项也会在每个用户权限设置的基础上显示或不显示!

enter image description here

现在我的问题是如何构建第三个数据库表,然后如何查询并显示每个用户的正确链接。在该部分完成之后,我将有一个设置页面,其中每个菜单项可以为数据库中的每个用户设置为yes/no。与此SugarCRM权限页面类似...但顶部水平列将为links,垂直记录将为用户....

enter image description here

3 个答案:

答案 0 :(得分:7)

将您的权限设为整数,并为每个菜单项或按权限分组的菜单项使用1位。

然后使用位智能AND来确定权限是否匹配。

用户和链接都有权限列。

权限是一个整数

权限A = 1
权限B = 2
权限C = 4
权限D = 8
权限E = 16
权限F = 32

如果同时显示B组和D组的菜单项,则:

if(link_permission&amp; user_permission)不为零,则用户有权限。

如果只有B和D,则链接权限的值为:
权限B +权限D,或2 + 8(00000010 + 00001000)= 00001010(十进制10,十六进制)

现在,如果用户的权限= 2(0010)或用户的权限= 8(1000)
当使用00001010的链接权限进行AND运算时,用户权限和链接权限的比特结果将不为零(如果非零=真,则为true)。

define('LINK_PERMISSION_ACCESS' ,1);  // 000000001
define('LINK_PERMISSION_DELETE' ,2) ; // 000000010
define('LINK_PERMISSION_EDIT'   ,4) ; // 000000100
define('LINK_PERMISSION_EXPORT' ,8) ; // 000001000
define('LINK_PERMISSION_IMPORT',16) ; // 000010000
define('LINK_PERMISSION_UPDATE',32) ; // 000100000
define('LINK_PERMISSION_VIEW'  ,64) ; // 001000000

$linkPermission =  LINK_PERMISSION_B + LINK_PERMISSION_D;  // 0010 + 01000 

$userPermission = LINK_PERMISSION_D;  // 01000

您也可以定义组级别值

define('LINK_PERMISSION_ADMIN' ,255); // 11111111

您可以定义多个提交

我要去十六进制而不是十进制,否则数字将无法管理

define('LINK_PERMISSION_ACCOUNTS'  ,0x8000); 
define('LINK_PERMISSION_AUDIT'     ,0x4000); 
define('LINK_PERMISSION_WORKFLOW'  ,0x2000); 
define('LINK_PERMISSION_BUGTRACKER',0x1000); 

只有帐户访问权限的用户才是

`user.permission` = LINK_PERMISSION_ACCOUNTS + LINK_PERMISSION_ACCESS ;

具有帐户访问权限,编辑权限和删除权限的用户将是

`user.permission` = LINK_PERMISSION_ACCOUNTS 
                  + LINK_PERMISSION_ACCESS 
                  + LINK_PERMISSION_DELETE 
                  + LINK_PERMISSION_EDIT;

如果您需要每个区域的用户权限列:

CREATE TABLE IF NOT EXISTS `user` (
  ...
`accountPermission`  int(11) NOT NULL DEFAULT '0',
`workFlowPermission` int(11) NOT NULL DEFAULT '0',
`contactsPermission` int(11) NOT NULL DEFAULT '0',
`campaignPermission` int(11) NOT NULL DEFAULT '0',

但是,如果权限数量为4或更少,例如:

define('LINK_PERMISSION_ACCESS' ,1);  // 000000001
define('LINK_PERMISSION_DELETE' ,2) ; // 000000010
define('LINK_PERMISSION_EDIT'   ,4) ; // 000000100
define('LINK_PERMISSION_VIEW'   ,8) ; // 000001000

`permission`  int(11) NOT NULL DEFAULT '0', 

帐户,工作流程,联系人和广告系列分为4位:

account  workflow  contacts campaign
 0000     0000       0000     0000

PERMISSION_ACCOUNT_ACCESS,  0x1000
PERMISSION_WORKFLOW_ACCESS, 0x0100
PERMISSION_CONTACTS_ACCESS, 0x0010
PERMISSION_CAMPAIGN_ACCESS, 0x0001

PERMISSION_ACCOUNT_DELETE,  0x2000
PERMISSION_WORKFLOW_DELETE, 0x0200
PERMISSION_CONTACTS_DELETE, 0x0020
PERMISSION_CAMPAIGN_DELETE, 0x0002

PERMISSION_ACCOUNT_EDIT,  0x4000
PERMISSION_WORKFLOW_EDIT, 0x0400
PERMISSION_CONTACTS_EDIT, 0x0040
PERMISSION_CAMPAIGN_EDIT, 0x0004

PERMISSION_ACCOUNT_VIEW,  0x8000
PERMISSION_WORKFLOW_VIEW, 0x0800
PERMISSION_CONTACTS_VIEW, 0x0080
PERMISSION_CAMPAIGN_VIEW, 0x0008

返回您的链接

定义常量

define ('SERVER_ADMIN',2);
define ('UBUNTU_DASHBOARD',4);
define ('REDIS_CACHE_ADMIN',8);
define ('MYSQL_DB_MANAGEMENT',16);
define ('NEON_AND_MORE',32);
define ('NEON_AND_MORE_(NAM)',64);
define ('SUGARCRM',128);
define ('NAM_MAGENTO_ADMIN',256);
define ('NAM_TIME_CLOCK',512);
define ('NEONANDMORE_BLOG_ADMIN',1024);
define ('ORDER_REPORTS',2048);
define ('WORK_ORDERS',4096);
define ('UPDATE_ORDER_STATUS',8192);
define ('CHANNEL_LETTER',16384);
define ('CHANNEL_LETTER',32768);
define ('MAGENTO_ADMIN',65536);
define ('BORDER_TUBING',131072);
define ('BORDER_TUBING',262144);
define ('SIGN_PARTS_AND_MORE',524288);
define ('SIGN_PARTS_AND_MORE',1048576);
define ('OTHER_SERVICES',2097152);
define ('PUSHER_REALTIME_EVENTS',4194304);
define ('ZOPIM_CUSTOMER_SUPPORT_CHAT',8388608);
define ('GOOGLE_ANALYTICS',16777216);
define ('GITLAB_(PRIVATE_GITHUB_CLONE)',33554432);
define ('LABS_/_PROJECTS',67108864);
define ('NAM_LABS',134217728);
define ('CAMERA_PHONE',268435456);
define ('SERVER_EMAIL_VERIFICATION',536870912);

链接和用户都有权限列:

`permissions` int(11) NOT NULL DEFAULT '0',

define('LINK_PERMISSION_ACCOUNTS'  ,0x8000); 
define('LINK_PERMISSION_AUDIT'     ,0x4000); 
define('LINK_PERMISSION_WORKFLOW'  ,0x2000); 
define('LINK_PERMISSION_BUGTRACKER',0x1000); 

如果用户拥有帐户和错误跟踪器访问权限:

$userPermission = LINK_PERMISSION_ACCOUNTS + LINK_PERMISSION_BUGTRACKER;
UPDATE `users` SET `permissions`= $userPermission WHERE `id` = $user  

然后是必需的链接权限:

$linkPermission = LINK_PERMISSION_ACCOUNTS;

我们使用用户权限

对链接权限进行了明智的AND(&amp;)
SELECT * FROM `links` WHERE (`permissions` & $userPermission) 

链接是否为子菜单链接

无关紧要

这是典型的分层表:

CREATE TABLE IF NOT EXISTS `links` (
  `id` int(11) NOT NULL AUTO_INCREMENT,
  `parent` int(11) NOT NULL DEFAULT '0',
  `sort` int(11) NOT NULL DEFAULT '0',
  `text` char(32) COLLATE utf8_bin NOT NULL,
  `link` text COLLATE utf8_bin NOT NULL,
  `permission` int(11) NOT NULL DEFAULT '0',
  PRIMARY KEY (`id`)
) ENGINE=InnoDB DEFAULT CHARSET=utf8 COLLATE=utf8_bin AUTO_INCREMENT=1 ;

相反,我们可以消除,父级和排序,id列将完成所有操作。

一个包含2个级别的菜单结构:主菜单和子菜单,&#39; id&#39;分解了

菜单子菜单

菜单编号为0x0100到0xFF00

子菜单号为0x0002到0x00FE

对于此菜单:

enter image description here

用于创建链接表的SQL:

CREATE TABLE IF NOT EXISTS `links` (
  `id` int(11) NOT NULL,
  `text` char(64) COLLATE utf8_bin NOT NULL,
  `link` text COLLATE utf8_bin NOT NULL,
  `permission` int(11) NOT NULL DEFAULT '0',
  PRIMARY KEY (`id`)
) ENGINE=InnoDB DEFAULT CHARSET=utf8 COLLATE=utf8_bin;

INSERT INTO `links` (`id`, `text`, `link`, `permission`) VALUES
(512, 'Server Admin', '#', 1),
(514, 'Ubuntu Dashboard', '#', 2),
(518, 'Redis Cache Admin', '#', 4),
(522, 'MySQL dB Management', '#', 8),
(1024, 'Neon and More', '#', 16),
(1026, 'Neon and More (NAM)', '#', 32),
(1030, 'SugarCRM', '#', 64),
(1034, 'NAM Magento Admin', '#', 128),
(1038, 'NAM Time Clock', '#', 256),
(1042, 'NeonAndMore Blog Admin', '#', 512),
(1046, 'Order Reports', '#', 1024),
(1050, 'Work Orders', '#', 2048),
(1054, 'Update Order Status', '#', 4096),
(1536, 'Channel Letter', '#', 8192),
(1538, 'Channel Letter', '#', 16384),
(1542, 'Magento Admin', '#', 32768),
(2048, 'Border Tubing', '#', 65536),
(2050, 'Border Tubing', '#', 131072),
(2560, 'Sign Parts And More', '#', 262144),
(2562, 'Sign Parts And More', '#', 524288),
(3072, 'Other Services', '#', 1048576),
(3074, 'Pusher Realtime Events<br/>Instant Caller ID Alerts', '#', 2097152),
(3078, 'Zopim Customer Support Chat', '#', 4194304),
(3082, 'Google Analytics', '#', 8388608),
(3086, 'GitLab (Private GitHub Clone)', '#', 16777216),
(3584, 'Labs / Projects', '#', 33554432),
(3586, 'NAM LABS', '#', 67108864),
(3590, 'Camera Phone', '#', 134217728),
(3594, 'Server Email Verification', '#', 268435456);

现在为链接菜单创建HTML:

<强> SQL

SELECT `id`, `text`, `link`, `permission` 
FROM `links` 
WHERE (`permission` & $userpermission )

<强> PHP

HEAD和CSS

<?php 
ob_start("ob_gzhandler");
header('Content-Type: text/html; charset=utf-8');
header('Connection: Keep-Alive');
header('Keep-Alive: timeout=5, max=100');
header('Cache-Control: max-age=84600');
header('Vary: Accept-Encoding');
echo <<<EOT
<!DOCTYPE html>
<html lang="en"><head><title>Daily Rx</title><meta name="viewport" content="width=device-width, initial-scale=1.0" />
<style type="text/css">
.submenu,.mainmenu{text-align:left;border-radius: 3px 3px 3px 3px;font: 700 1.1em Arial,Helvetica,Calibri,sans-serif;overflow: visible;}
.submenu{border:1px solid #0f0;color: #fff;margin:.2em 0 .2em .8em;width:16.8em;padding: 0 0 0 .8em;
background-image: -o-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: -moz-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: -webkit-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: -ms-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: linear-gradient(to bottom, #3d5 0%, #370 100%);}
.mainmenu{font-size:1.2em;margin:.2em .2em .2em .2em ;width:16em;padding-left:1em;border:1px solid #00f;color: #fff;
background-image: -o-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -moz-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -webkit-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -ms-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: linear-gradient(to bottom, #2ef 0%, #02f 100%);}
.hide{display:none;}
#x{height:40em;}
#page{margin:0;padding:0;}
hr{font-size:.1em;padding:0;margin:0 0 0 1em;width:50em;opacity:0;}
</style></head><body><div id="page">
EOT;
ob_flush();

创建菜单

$userpermission = 4294967295; // 0xffffffff
$sql = "SELECT `id`, `text`, `link`, `permission` FROM `links` WHERE (`permission` & $userpermission ) > 0";
$results = mysqli_query($conn,$sql);
if (mysqli_errno($conn) > 0){echo mysqli_error($conn) . "<br>\n$sql\n";}
while($row = mysqli_fetch_array($results, MYSQL_NUM)){
  $class = $row[0] & 1;
  if($class == 0){
    $i++;
    echo "$closeSubmenu\n<button class=\"mainmenu\" onclick=\"show($i)\">$row[1]</button>\n<div class=\"hide\" id=\"d$i\">\n";
  }
  else{
    echo "<form action=\"$row[2]\"><div><input type=\"hidden\" name=\"user\" value=\"$user\" /><input type=\"hidden\" name=\"id\" value=\"$row[0]\" /><input type=\"hidden\" name=\"permission\" value=\"$userpermission\" /><button class=\"submenu\">$row[1]</button></div></form>\n";
  }
  $closeSubmenu = '</div><hr/>';
}

扩展和收缩子菜单的JavaScript

ob_flush();
echo <<<EOT
</div><div id="x"><p>&#x2003;</p></div>
<script type="text/javascript">
//<![CDATA[
var toggle = new Array();
toggle[''] ='block';
toggle['none'] ='block';
toggle['block'] ='none';
var div,disp;
var prev = document.getElementById('d1');
prev.style.display='none';
function show(id){
  div = document.getElementById('d' + id);
  disp = div.style.display;
  prev.style.display='none';
  div.style.display=toggle[disp];
  prev=div;
  var y=div.offsetTop;
  window.scrollTo(0, y-32);
}
//]]>
</script></div></body></html>
EOT;
ob_end_flush();
?>

快速页面加载,仅132毫秒

这个PHP页面在浏览中加载的时间超过100毫秒 这就是TPC / IP连接所需的时间。

将HTML从服务器传输到浏览器所需的时间仅为2毫秒。

以下图片来自http://www.webpagetest.org

enter image description here

DNS Lookup: 20 ms
Initial Connection: 35 ms
Time to First Byte: 95 ms
Content Download: 2 ms

W3C MobileOK Checker得分:100%

W3C mobileOK Checker

您将找不到许多可以执行此操作的网页:

enter image description here

Google PageSpeed Insights 100%移动和桌面速度和可用性

Google PageSpeed Insights

enter image description here

enter image description here

此代码段是使用上面的PHP制作的,并在此处粘贴了查看源:

&#13;
&#13;
var toggle = new Array();
toggle[''] ='block';
toggle['none'] ='block';
toggle['block'] ='none';
var div,disp;
var prev = document.getElementById('x');
function show(id){
  div = document.getElementById('d' + id);
  disp = div.style.display;
  prev.style.display='none';
  div.style.display=toggle[disp];
  prev=div;
  var y=div.offsetTop;
  window.scrollTo(0, y-32);    }
&#13;
.submenu,.mainmenu{text-align:left;border-radius: 3px 3px 3px 3px;font: 700 1.1em Arial,Helvetica,Calibri,sans-serif;overflow: visible;}
.submenu{border:1px solid #0f0;color: #fff;margin:.2em 0 .2em .8em;width:16.8em;padding: 0 0 0 .8em;
background-image: -o-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: -moz-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: -webkit-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: -ms-linear-gradient(bottom, #3d5 0%, #370 100%);
background-image: linear-gradient(to bottom, #3d5 0%, #370 100%);}
.mainmenu{font-size:1.2em;margin:.2em .2em .2em .2em ;width:16em;padding-left:1em;border:1px solid #00f;color: #fff;
background-image: -o-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -moz-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -webkit-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -ms-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: linear-gradient(to bottom, #2ef 0%, #02f 100%);}
.hide{display:none;}
#x{height:40em;}
#page{margin:0;padding:0;}
hr{font-size:.1em;padding:0;margin:0 0 0 1em;width:50em;opacity:0;}
&#13;
<div id="page">
<button class="mainmenu" onclick="show(1)">Server Admin</button>
<div class="hide" id="d1">
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="257" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Ubuntu Dashboard</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="259" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Redis Cache Admin</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="261" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">MySQL dB Management</button></div></form>
</div><hr/>
<button class="mainmenu" onclick="show(2)">Neon and More</button>
<div class="hide" id="d2">
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="513" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Neon and More (NAM)</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="515" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">SugarCRM</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="517" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">NAM Magento Admin</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="519" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">NAM Time Clock</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="521" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">NeonAndMore Blog Admin</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="523" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Order Reports</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="525" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Work Orders</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="527" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Update Order Status</button></div></form>
</div><hr/>
<button class="mainmenu" onclick="show(3)">Channel Letter</button>
<div class="hide" id="d3">
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="769" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Channel Letter</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="771" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Magento Admin</button></div></form>
</div><hr/>
<button class="mainmenu" onclick="show(4)">Border Tubing</button>
<div class="hide" id="d4">
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1025" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Border Tubing</button></div></form>
</div><hr/>
<button class="mainmenu" onclick="show(5)">Sign Parts And More</button>
<div class="hide" id="d5">
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1281" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Sign Parts And More</button></div></form>
</div><hr/>
<button class="mainmenu" onclick="show(6)">Other Services</button>
<div class="hide" id="d6">
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1537" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Pusher Realtime Events<br/>Instant Caller ID Alerts</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1539" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Zopim Customer Support Chat</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1541" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Google Analytics</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1543" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">GitLab (Private GitHub Clone)</button></div></form>
</div><hr/>
<button class="mainmenu" onclick="show(7)">Labs / Projects</button>
<div class="hide" id="d7">
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1793" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">NAM LABS</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1795" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Camera Phone</button></div></form>
<form action="#"><div><input type="hidden" name="user" value="123" /><input type="hidden" name="id" value="1797" /><input type="hidden" name="permission" value="4294967295" /><button class="submenu">Server Email Verification</button></div></form>
</div><div id="x"><p>&#x2003;</p></div>
&#13;
&#13;
&#13;

答案 1 :(得分:0)

如果我得到你想要显示的问题,或者根据请求php动态页面的用户类型显示某些菜单。

我使用Bootstrap创建一些项目,并始终使用PHP-oop。因此,菜单显示状态始终根据用户状态进行控制。

link上查看这些图片。序列 d .jpg, e .jpg, f .jpg, g .jpg, h < /strong>.jpg和 ha .jpg。如您所见,左侧菜单的某些链接是否已锁定。我可以显示或隐藏基于我从Mysql中获取的一些信息。比PHP控制变量锁定或显示。这是菜单代码的一部分:

<li class="list-group-item list-toggle lv1">
         <a data-toggle="collapse" data-parent="#menuHomeUserPrivate" href="#collapse-PerfilManage"><i class="fa fa-cog"></i>Perfil Profissional</a>
         <ul id="collapse-PerfilManage" class="collapse">
             <li class="list-group-item lv2"><a id="to_CodAtivacao" class="privateMenuLinkJS "><i class="fa  fa-lock"></i> Código de Ativação</a></li>
             <li class="list-group-item lv2">$badgeInativar_Code<a id="to_EditarFoto" class="privateMenuLinkJS "><i class="fa  fa-camera-retro"></i> Editar Foto</a></li>
             <li class="list-group-item lv2">$badgeInativar_Code<a id="to_URL_Manage" class="privateMenuLinkJS "><i class="fa  fa-link"></i>Site (URL) Profissional</a></li>
             <li class="list-group-item lv2"><a id="to_NivelEcucacional" class="privateMenuLinkJS "><i class="fa   fa-university"></i>Nível Educaional</a></li>
             <li class="list-group-item lv2"><a id="to_OrdemProfissional" class="privateMenuLinkJS "><i class="fa   fa-users"></i> N&deg;Profissional</a></li>
             <li class="list-group-item lv2"><a id="to_EspecialidadeProfissional" class="privateMenuLinkJS "><i class="fa  fa-codepen"></i>Especialidade(s)</a></li>
             <li class="list-group-item lv2">$badgeInativar_Code<a id="to_EnderecoProfissional" class="privateMenuLinkJS "><i class="fa  fa-hospital-o"></i>Endereço Profissional</a></li>
             <li class="list-group-item lv2">$badgeInativar_Code<a id="to_GestaoEnderecos" class="privateMenuLinkJS "><i class="fa  fa-cogs"></i>Gestão de Endereço(s)</a></li>    
         </ul>
     </li>

正如您所看到的,我使用变量$badgeInativar_Code标记了要锁定的菜单项,并使用php代码来控制行为

if($eventMenuInactivate===0||$eventMenuInactivate===NULL||$eventMenuInactivate===""){
$badgeInativar_Code="";
} 
elseif ($eventMenuInactivate===1) {//$eventMenuInactivate===1 O usuário não preencheu o código de ativação
$badgeInativar_Code = "<span class=\" hidden spmInatCode badge rounded badge-red\"><i class=\"fa  fa-lock\"></i>Locked</span>";
}

这是创建菜单的方法

static function section_MENU_HomeUser_Private($eventMenuInactivate=FALSE) { ....

答案 2 :(得分:0)

更新用户权限

这与我关于根据用户权限制作菜单的其他答案一致。

这是PHP脚本将根据选中的复选框生成权限。

主菜单有权限,但没有复选框。所有复选框值=子菜单的权限值及其关联的主菜单。

如果将用户权限传递给此脚本,则会在页面加载时检查用户当前权限的复选框。

这是为了向自己提交POST值。这将生成新的用户权限$userpermissions,并显示在页面底部。你应该如何处理它们取决于你。插入数据库记录,或将值放在链接中或从提交到另一个脚本中保存值。

检索POST值是非常规的。

为了测试,我在GET查询字符串值('up')中传递用户权限:

updateUser.php?up=4575

$userpermissions = intval($_GET['up']);

如果没有传递GET值,则$userpermissionsintval()设置为零,并且只检查值是否粘贴在POST数据中的复选框。
< / p>

然后我扫描每个POST复选框值:

foreach($_POST as $key => $value){
  if(substr($key,0,1) == 'c'){
    $userpermissions |= $value;
  }
}

复选框的名称为“c”加上序号。

我找到所有以“c”开头的POSTed键值。然后将值与任何现有权限进行对比。

这就是我将主菜单值添加到子菜单复选框的原因。如果未选择子菜单,则主菜单的权限也不在用户权限中。

如果选择了多个子菜单,则无关紧要,因为该值是ORed而不是添加。

选中包含现有权限的框:

如果设置了菜单位,则复选框将在HTML标记中显示“checked =”。“

for($i=1;$i<33;$i++){
  if($userpermissions & $permissions[$i]){
    $checked[$i] = 'checked="checked"';
  }
}

用户权限与数组进行AND运算,$permissions,存储每个复选框的位值,并使用div的id编号和复选框编制索引。

$permissions = array(0,1,2,4,8,16,32,64,128,256,512,1024,2048,4096,8192,16384,32768,65536,131072,262144,524288,1048576,2097152,4194304,8388608,16777216,33554432,67108864,134217728,268435456);

复选框用div封装。这个div的id以“d”开头,后跟相同的序列号和复选框中的id。 div的目的是在选中复选框时更改背景颜色。

有一个JS init()例程检查每个复选框,并将背景设置为选中或未选中的颜色。

每个复选框都有一个onclick事件来更改背景颜色。背景颜色存储在索引值为true和false的数组中。

bg = new Array;
bg[true] = '#f00';
bg[false] = '#2985EA';

颜色设置为复选框输入的真/假值。

这是init()函数中的代码:

c[i] = document.getElementById('c' + i);
d[i] = document.getElementById('d' + i);

d[i].style.backgroundColor=bg[c[i].checked];

所有div和复选框DOM Elements都保存在一个数组中。

var divs = document.getElementsByTagName("div");

int()函数遍历正在查找任何以“d”开头的id(“getAttribute("id")”)的div

PHP

<?php 
ob_start("ob_gzhandler");
header('Content-Type: text/html; charset=utf-8');
header('Connection: Keep-Alive');
header('Keep-Alive: timeout=5, max=100');
header('Cache-Control: max-age=84600');
header('Vary: Accept-Encoding');
echo <<<EOT
<!DOCTYPE html>
<html lang="en"><head><title>Daily Rx</title><meta name="viewport" content="width=device-width, initial-scale=1.0" />
<style type="text/css">
.link,.btn{text-align:center;border-radius: 3px 3px 3px 3px;
font: 700 1em Arial,Helvetica,Calibri,sans-serif;overflow: visible;}
.btn{border:1px solid #00f;color: #fff;background:#004;margin:.2em;width:18em;padding:.8em;
}
.link{border:1px solid #0f0;color: #fff;margin:.2em;width:18em;padding:.8em;
background-image: -o-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -moz-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -webkit-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -ms-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: linear-gradient(to bottom, #2ef 0%, #02f 100%);}
.hide{display:none;}
#x{height:40em;}
#page{margin:0;padding:0;}
.dchk{font:700 1em Arial,sans-serif;color:#fff;width:18em;display:inline-block;padding:2px 0 2px 2px;margin:0 0 .5em;vertical-align: middle;position: relative;}
.chk{color:#fff;display:inline;padding:6px 0 6px 6px;margin-bottom:6px;outline:2px solid #000;}
.dchk,.chk,.component{background:#2985EA;text-align:left}
input[type="radio"],input[type="checkbox"]{width:2em;height:2em;border:2px solid #eee;outline:2px solid #eee;display: inline;margin:1px;margin:4px 0 4px 4px;vertical-align: middle;position: relative;background:#144;color:#eee;   display: inline;vertical-align: middle;position: relative;}   
.hr{font-size:.1em;padding:0;margin:0 0 0 1em;width:50em;opacity:1;}
</style></head><body><div id="page">
<form action="updateUser.php" method="post"><div>
EOT;
ob_flush();
$check = array(1 => 1,2 => 2,3 => 4,4 => 8,5 => 16,6 => 32,7 => 64,8 => 128,9 => 256,10 => 512,11 => 1024,12 => 2048,13 => 4096,14 => 8192,15 => 16384,16 => 32768,17 => 65536,18 => 131072,19 => 262144,20 => 524288,21 => 1048576,22 => 2097152,23 => 4194304,24 => 8388608,25 => 16777216,26 => 33554432,27 => 67108864,28 => 134217728,29 => 268435456);
$permissions = array(0,1,2,4,8,16,32,64,128,256,512,1024,2048,4096,8192,16384,32768,65536,131072,262144,524288,1048576,2097152,4194304,8388608,16777216,33554432,67108864,134217728,268435456);
$checked = array_fill(0,32,'');
$userpermissions = intval($_GET['up']);
foreach($_POST as $key => $value){
  if(substr($key,0,1) == 'c'){
    $userpermissions |= $value;
  }
}
for($i=1;$i<33;$i++){
  if($userpermissions & $permissions[$i]){$checked[$i] = 'checked="checked"';}
}
echo <<<EOT
<button class="btn" type"button">Server Admin</button><br/>
<div id="d2" class="dchk "><input type="checkbox" id="c2" class="chk" name="c2" value="3" onclick="chk('2')" $checked[2] />&#x2002;Ubuntu Dashboard</div><br/>
<div id="d3" class="dchk "><input type="checkbox" id="c3" class="chk" name="c3" value="5" onclick="chk('3')" $checked[3] />&#x2002;Redis Cache Admin</div><br/>
<div id="d4" class="dchk "><input type="checkbox" id="c4" class="chk" name="c4" value="9" onclick="chk('4')" $checked[4] />&#x2002;MySQL dB Management</div><br/>
<button class="btn" type"button">Neon and More</button><br/>
<div id="d6" class="dchk "><input type="checkbox" id="c6" class="chk" name="c6" value="48" onclick="chk('6')" $checked[6] />&#x2002;Neon and More (NAM)</div><br/>
<div id="d7" class="dchk "><input type="checkbox" id="c7" class="chk" name="c7" value="80" onclick="chk('7')" $checked[7] />&#x2002;SugarCRM</div><br/>
<div id="d8" class="dchk "><input type="checkbox" id="c8" class="chk" name="c8" value="144" onclick="chk('8')" $checked[8] />&#x2002;NAM Magento Admin</div><br/>
<div id="d9" class="dchk "><input type="checkbox" id="c9" class="chk" name="c9" value="272" onclick="chk('9')" $checked[9] />&#x2002;NAM Time Clock</div><br/>
<div id="d10" class="dchk "><input type="checkbox" id="c10" class="chk" name="c10" value="528" onclick="chk('10')" $checked[10] />&#x2002;NeonAndMore Blog Admin</div><br/>
<div id="d11" class="dchk "><input type="checkbox" id="c11" class="chk" name="c11" value="1040" onclick="chk('11')" $checked[11] />&#x2002;Order Reports</div><br/>
<div id="d12" class="dchk "><input type="checkbox" id="c12" class="chk" name="c12" value="2064" onclick="chk('12')" $checked[12] />&#x2002;Work Orders</div><br/>
<div id="d13" class="dchk "><input type="checkbox" id="c13" class="chk" name="c13" value="4112" onclick="chk('13')" $checked[13] />&#x2002;Update Order Status</div><br/>
<button class="btn" type"button">Channel Letter</button><br/>
<div id="d15" class="dchk "><input type="checkbox" id="c15" class="chk" name="c15" value="24576" onclick="chk('15')" $checked[15] />&#x2002;Channel Letter</div><br/>
<div id="d16" class="dchk "><input type="checkbox" id="c16" class="chk" name="c16" value="40960" onclick="chk('16')" $checked[16] />&#x2002;Magento Admin</div><br/>
<button class="btn" type"button">Border Tubing</button><br/>
<div id="d18" class="dchk "><input type="checkbox" id="c18" class="chk" name="c18" value="196608" onclick="chk('18')" $checked[18] />&#x2002;Border Tubing</div><br/>
<button class="btn" type"button">Sign Parts And More</button><br/>
<div id="d20" class="dchk "><input type="checkbox" id="c20" class="chk" name="c20" value="786432" onclick="chk('20')" $checked[20] />&#x2002;Sign Parts And More</div><br/>
<button class="btn" type"button">Other Services</button><br/>
<div id="d22" class="dchk "><input type="checkbox" id="c22" class="chk" name="c22" value="3145728" onclick="chk('22')" $checked[22] />&#x2002;Pusher Realtime Events</div><br/>
<div id="d23" class="dchk "><input type="checkbox" id="c23" class="chk" name="c23" value="5242880" onclick="chk('23')" $checked[23] />&#x2002;Zopim Customer Support Chat</div><br/>
<div id="d24" class="dchk "><input type="checkbox" id="c24" class="chk" name="c24" value="9437184" onclick="chk('24')" $checked[24] />&#x2002;Google Analytics</div><br/>
<div id="d25" class="dchk "><input type="checkbox" id="c25" class="chk" name="c25" value="17825792" onclick="chk('25')" $checked[25] />&#x2002;GitLab (Private GitHub Clone)</div><br/>
<button class="btn" type"button">Labs / Projects</button><br/>
<div id="d27" class="dchk "><input type="checkbox" id="c27" class="chk" name="c27" value="100663296" onclick="chk('27')" $checked[27] />&#x2002;NAM LABS</div><br/>
<div id="d28" class="dchk "><input type="checkbox" id="c28" class="chk" name="c28" value="167772160" onclick="chk('28')" $checked[28] />&#x2002;Camera Phone</div><br/>
<div id="d29" class="dchk "><input type="checkbox" id="c29" class="chk" name="c29" value="301989888" onclick="chk('29')" $checked[29] />&#x2002;Server Email Verification</div><br/>
<button class="link" type="submit">Submit</button></div></form>
<h3> $userpermissions</h3>
<script type="text/javascript"> //<![CDATA[
var d = new Array;
var c = new Array;
function chk(id){
  d[id].style.backgroundColor=bg[c[id].checked];
}
function init(){
var checked,did;
bg = new Array;
bg[true] = '#f00';
bg[false] = '#2985EA';

var divs = document.getElementsByTagName("div");
  for (div=0; div<divs.length; div++){
    did = divs[div].getAttribute("id");
    if (did != null){
      if (did.substring(0,1) == "d"){
        var i = did.substring(1,5);
        c[i] = document.getElementById('c' + i);
        d[i] = document.getElementById('d' + i);
        checked = c[i].checked;
        d[i].style.backgroundColor=bg[checked];
        //show = show + i + ',';
      }
    }
  }
}
window.onload = init;
//]]>
</script>
</body></html>
EOT;
ob_end_flush();
?>

var d = new Array;
var c = new Array;
function chk(id){
  d[id].style.backgroundColor=bg[c[id].checked];
}
function init(){
var checked,did;
bg = new Array;
bg[true] = '#f00';
bg[false] = '#2985EA';

var divs = document.getElementsByTagName("div");
  for (div=0; div<divs.length; div++){
did = divs[div].getAttribute("id");
if (did != null){
  if (did.substring(0,1) == "d"){
    var i = did.substring(1,5);
	c[i] = document.getElementById('c' + i);
	d[i] = document.getElementById('d' + i);
	checked = c[i].checked;
	d[i].style.backgroundColor=bg[checked];
	//show = show + i + ',';
  }
}
  }
}
window.onload = init;
.link,.btn{text-align:center;border-radius: 3px 3px 3px 3px;
font: 700 1em Arial,Helvetica,Calibri,sans-serif;overflow: visible;}
.btn{border:1px solid #00f;color: #fff;background:#004;margin:.2em;width:18em;padding:.8em;
}
.link{border:1px solid #0f0;color: #fff;margin:.2em;width:18em;padding:.8em;
background-image: -o-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -moz-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -webkit-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: -ms-linear-gradient(bottom, #2ef 0%, #02f 100%);
background-image: linear-gradient(to bottom, #2ef 0%, #02f 100%);}
.hide{display:none;}
#x{height:40em;}
#page{margin:0;padding:0;}
.dchk{font:700 1em Arial,sans-serif;color:#fff;width:18em;display:inline-block;padding:2px 0 2px 2px;margin:0 0 .5em;vertical-align: middle;position: relative;}
.chk{color:#fff;display:inline;padding:6px 0 6px 6px;margin-bottom:6px;outline:2px solid #000;}
.dchk,.chk,.component{background:#2985EA;text-align:left}
input[type="radio"],input[type="checkbox"]{width:2em;height:2em;border:2px solid #eee;outline:2px solid #eee;display: inline;margin:1px;margin:4px 0 4px 4px;vertical-align: middle;position: relative;background:#144;color:#eee;   display: inline;vertical-align: middle;position: relative;}   
.hr{font-size:.1em;padding:0;margin:0 0 0 1em;width:50em;opacity:1;}
<div id="page">
<form action="updateUser.php" method="post"><div><button class="btn" type"button">&#x2002;Server Admin</button><br/>
<div id="d2" class="dchk "><input type="checkbox" id="c2" class="chk" name="c2" value="3" onclick="chk('2')"  />&#x2002;Ubuntu Dashboard</div><br/>
<div id="d3" class="dchk "><input type="checkbox" id="c3" class="chk" name="c3" value="5" onclick="chk('3')"  />&#x2002;Redis Cache Admin</div><br/>
<div id="d4" class="dchk "><input type="checkbox" id="c4" class="chk" name="c4" value="9" onclick="chk('4')"  />&#x2002;MySQL dB Management</div><br/>
<button class="btn" type"button">&#x2002;Neon and More</button><br/>
<div id="d6" class="dchk "><input type="checkbox" id="c6" class="chk" name="c6" value="48" onclick="chk('6')"  />&#x2002;Neon and More (NAM)</div><br/>
<div id="d7" class="dchk "><input type="checkbox" id="c7" class="chk" name="c7" value="80" onclick="chk('7')"  />&#x2002;SugarCRM</div><br/>
<div id="d8" class="dchk "><input type="checkbox" id="c8" class="chk" name="c8" value="144" onclick="chk('8')"  />&#x2002;NAM Magento Admin</div><br/>
<div id="d9" class="dchk "><input type="checkbox" id="c9" class="chk" name="c9" value="272" onclick="chk('9')"  />&#x2002;NAM Time Clock</div><br/>
<div id="d10" class="dchk "><input type="checkbox" id="c10" class="chk" name="c10" value="528" onclick="chk('10')"  />&#x2002;NeonAndMore Blog Admin</div><br/>
<div id="d11" class="dchk "><input type="checkbox" id="c11" class="chk" name="c11" value="1040" onclick="chk('11')"  />&#x2002;Order Reports</div><br/>
<div id="d12" class="dchk "><input type="checkbox" id="c12" class="chk" name="c12" value="2064" onclick="chk('12')"  />&#x2002;Work Orders</div><br/>
<div id="d13" class="dchk "><input type="checkbox" id="c13" class="chk" name="c13" value="4112" onclick="chk('13')"  />&#x2002;Update Order Status</div><br/>
<button class="btn" type"button">&#x2002;Channel Letter</button><br/>
<div id="d15" class="dchk "><input type="checkbox" id="c15" class="chk" name="c15" value="24576" onclick="chk('15')"  />&#x2002;Channel Letter</div><br/>
<div id="d16" class="dchk "><input type="checkbox" id="c16" class="chk" name="c16" value="40960" onclick="chk('16')"  />&#x2002;Magento Admin</div><br/>
<button class="btn" type"button">&#x2002;Border Tubing</button><br/>
<div id="d18" class="dchk "><input type="checkbox" id="c18" class="chk" name="c18" value="196608" onclick="chk('18')"  />&#x2002;Border Tubing</div><br/>
<button class="btn" type"button">&#x2002;Sign Parts And More</button><br/>
<div id="d20" class="dchk "><input type="checkbox" id="c20" class="chk" name="c20" value="786432" onclick="chk('20')"  />&#x2002;Sign Parts And More</div><br/>
<button class="btn" type"button">&#x2002;Other Services</button><br/>
<div id="d22" class="dchk "><input type="checkbox" id="c22" class="chk" name="c22" value="3145728" onclick="chk('22')"  />&#x2002;Pusher Realtime Events</div><br/>
<div id="d23" class="dchk "><input type="checkbox" id="c23" class="chk" name="c23" value="5242880" onclick="chk('23')"  />&#x2002;Zopim Customer Support Chat</div><br/>
<div id="d24" class="dchk "><input type="checkbox" id="c24" class="chk" name="c24" value="9437184" onclick="chk('24')"  />&#x2002;Google Analytics</div><br/>
<div id="d25" class="dchk "><input type="checkbox" id="c25" class="chk" name="c25" value="17825792" onclick="chk('25')"  />&#x2002;GitLab (Private GitHub Clone)</div><br/>
<button class="btn" type"button">&#x2002;Labs / Projects</button><br/>
<div id="d27" class="dchk "><input type="checkbox" id="c27" class="chk" name="c27" value="100663296" onclick="chk('27')"  />&#x2002;NAM LABS</div><br/>
<div id="d28" class="dchk "><input type="checkbox" id="c28" class="chk" name="c28" value="167772160" onclick="chk('28')"  />&#x2002;Camera Phone</div><br/>
<div id="d29" class="dchk "><input type="checkbox" id="c29" class="chk" name="c29" value="301989888" onclick="chk('29')"  />&#x2002;Server Email Verification</div><br/>
<button class="link" type="submit">Submit</button></div></form></div>