A MySQL query that has several subqueries, each with different types of connections

Let me first give you a diagram of the relationships between the tables used in my mysql query:

table relationship
(source: r717.net )

I have a query that looks like this:

SELECT  * 
FROM    'permissions'
WHERE   'id' IN (
    SELECT      pr.perm_id 
    FROM        'user_roles' as ur 
    LEFT JOIN   'permissions_role' as pr 
    ON          ur.role_id = pr.role_id
    WHERE       ur.user_id = '$userid'
)
OR      'id' IN (
    SELECT      'perm_id' 
    FROM        'permissions_user' 
    WHERE       'user_id' = '$userid'
)

$useridis the identifier from the user table for the current user. I save the permission name from the result in an array that represents all the permissions assigned to the user based on his / her role and his / her identifier:

<?php
$user_perms = array();
if(mysql_num_rows($query) > 0):
    while($result = mysql_fetch_array($query):
        $user_perms[] = $result('name');
    endwhile;
endif;
?>

print_r($user_perms); produces output that looks like this:

Array ( 
    [0] => ACCESS_TELEPHONELIST_PAGE
    [1] => ACCESS_VACATIONSCHED_PAGE
    [2] => ACCESS_TOURSCHED_PAGE
    [3] => ACCESS_WORKSCHED_PAGE
    [4] => ACCESS_RESOURCES_LINKS
    [5] => ACCESS_PMTOOL_PAGE
    [6] => ACCESS_TOOLSTOOL_PAGE
    [7] => ACCESS_SHOPTOOLLIST_PAGE
    [8] => ACCESS_TOOLINVENTORY_PAGE
    [9] => ACCESS_MANAGETOOLLIST_PAGE
    [10] => ACCESS_TOOLREPORTS_PAGE
    [11] => ACCESS_JOBSLIST_LINKS
    [12] => MAIN_TAB_TOOLSTOOL
    [13] => ADMIN_TAB_PODMANAGEMENT
    [14] => TOOL_TAB_SHOPTOOLLIST
)

. , , :

SELECT      permissions.*, usersroles.role_id 
FROM        'permissions'
INNER JOIN  (
    SELECT      ur.user_id, pr.perm_id, ur.role_id
    FROM        'user_roles' as ur
    LEFT JOIN   'permissions_role' as pr 
    ON          ur.role_id = pr.role_id
    WHERE       ur.user_id = '$userid'
) AS usersroles ON usersroles.perm_id = permissions.id
INNER JOIN  (
    SELECT      'perm_id', 'user_id' 
    FROM        'permissions_user' 
    WHERE       'user_id' = '$userid'
) AS userperms ON userperms.user_id = usersroles.user_id
              AND userperms.perm_id = permissions.id

, , ...

<?php
$user_perms = array();
$user_roles = array();
if(mysql_num_rows($query) > 0):
    while($result = mysql_fetch_array($query):
        $user_perms = $result('name');
        $user_roles = $result('role_id');
    endwhile;
endif;
?>

... :

Warning: mysql_num_rows() expects parameter 1 to be resource, boolean given

print_r($user_roles); , :

Array (
    [0] => administrator
    [1] => humanresources
    [2] => podmanager
)

- , , 2 ?

: , 2 , ImreL. . , , , , , 2 . ImreL!

+3
2

, , 30 000 3000 . hard, . 7 , , , , ( , )

, , :

" " - .

2 , 1 .

:

  • , , . , /.
  • ( )

, , , :

select * from (
    select ur.role_id, p.*
    from user_roles ur 
    left join permissions_role pr on ur.role_id =  pr.role_id
    left join permissions p on p.id = pr.perm_id
    where ur.user_id = '$userid'
  union all
    select null as role_id, p.*
    from permissions_user pu
    join permissions p on p.id = pu.perm_id
    where pu.user_id = '$userid'
) sub
group by ifnull(name,role_id) -- group by to eliminate duplicates

. 2- : 1-,

select p.* from permissions p
join permissions_role pr on pr.perm_id = p.id
join user_roles ur on ur.role_id =  pr.role_id and ur.user_id = '$userid'
union
select p.* from permissions p
join  permissions_user pu on pu.perm_id = p.id and pu.user_id = '$userid';

, .

+2

EDIT: . , , , , , .

//build the array(s)
$userperms = array();
$userroles = array();
if(isset($_SESSION['userid'])):
    //get the userid
    $thisuserid = $_SESSION['userid'];
    //get the permissions for each of the user roles
    $Cpermissions_role = mysql_query(" 
    SELECT      r.type, ur.user_id, pr.perm_id, ur.role_id, p.name
    FROM        user_roles ur
    LEFT JOIN   permissions_role pr ON ur.role_id = pr.role_id
    LEFT JOIN   roles r ON ur.role_id = r.id
    LEFT JOIN   permissions p ON p.id = pr.perm_id
    WHERE       ur.user_id = '$userid'") or die(mysql_error());
    //get the extra permissions for the user
    $Cpermissions_user = mysql_query("
    SELECT      pu.user_id, pu.perm_id, p.name
    FROM        permissions_user pu
    LEFT JOIN   permissions p ON p.id = pu.perm_id
    WHERE       pu.user_id = '$userid'") or die(mysql_error());
    //build an array of the user roles & an array of the user permissions
    if(mysql_num_rows($Cpermissions_role) > 0):
        while($Rpermissions_role = mysql_fetch_array($Cpermissions_role)):
            if(empty($userperms)):
                $userperms[] = $Rpermissions_role['name'];
            elseif(!in_array($Rpermissions_role['name'],$userperms)):
                $userperms[] = $Rpermissions_role['name'];
            endif;
            if(empty($userroles)):
                $userroles[] = $Rpermissions_role['type'];
            elseif(!in_array($Rpermissions_role['type'],$userroles)):
                $userroles[] = $Rpermissions_role['type'];
            endif;
        endwhile;
    endif;
    if(mysql_num_rows($Cpermissions_user) > 0):
        while($Rpermissions_user = mysql_fetch_array($Cpermissions_user)):
            if(empty($userperms)):
                $userperms[] = $Rpermissions_user['name'];
            elseif(!in_array($Rpermissions_user['name'],$userperms)):
                $userperms[] = $Rpermissions_user['name'];
            endif;
        endwhile;
    endif;
endif;
/**
 * Determines if the user has permission for the page or parts of page
 * @param string $perm the permission constant
 * @return boolean true if user has access, false if not
 */
function hasPermission($perm){
    global $userperms;
    if(empty($userperms)):
        return false;
    else:
        if(is_array($userperms)):
            if(in_array($perm,$userperms)):
                return true;
            else:
                return false;
            endif;
        else:
            if($perm == $userperms):
                return true;
            else:
                return false;
            endif;
        endif;
    endif;
}

:

if(hasPermission("ACCESS_HOME_PAGE")):
    //perform circus tricks here
endif;

, print_r($userperms); :

Array ( 
    [0] => ACCESS_TELEPHONELIST_PAGE
    [1] => ACCESS_VACATIONSCHED_PAGE
    [2] => ACCESS_TOURSCHED_PAGE
    [3] => ACCESS_WORKSCHED_PAGE
    [4] => ACCESS_RESOURCES_LINKS
    [5] => ACCESS_PMTOOL_PAGE
    [6] => ACCESS_TOOLSTOOL_PAGE
    [7] => ACCESS_SHOPTOOLLIST_PAGE
    [8] => ACCESS_TOOLINVENTORY_PAGE
    [9] => ACCESS_MANAGETOOLLIST_PAGE
    [10] => ACCESS_TOOLREPORTS_PAGE
    [11] => ACCESS_JOBSLIST_LINKS
    [12] => MAIN_TAB_TOOLSTOOL
    [13] => ADMIN_TAB_PODMANAGEMENT
    [14] => TOOL_TAB_SHOPTOOLLIST
    [15] => ACCESS_HOME_PAGE
)

, print_r($userroles); :

Array ( 
    [0] => administrator
    [1] => humanresourcees
    [2] => podmanager
)

, , JavaScript, php:

var js_userperms = new Array();
js_userperms = ["<?php echo join("\", \"", $userperms); ?>"];

, jQuery:

if(jQuery.inArray("ACCESS_HOME_PAGE", js_userperms) != -1){
    //perform circus tricks here
}
0

All Articles