本文讲述SharePoint 2010/2013 使用Javascript来判断权限的三种方法的实现方式及其优缺点。

1. 根据用户所在的SharePoint组(比如用户在Leader 组才可以使用审批按钮)

a. 优点,简单明了,容易理解,要获得这个权限只有一个入口,就是将用户加入到SharePoint组

b. 缺点, 不能兼容AD group套SharePoint组的情况,只能将用户直接加入到SharePoint组的情况下起作用

c. 实现代码如下:

  1. function IsCurrentUserMemberOfGroup(strGroupName, functionComplete) {
  2. //Setup Vars
  3. currentContext  = null;
  4. currentWeb  = null;
  5. allGroups   = null;
  6. leaderGroup     = null;
  7. currentUser     = null;
  8. groupUsers  = null;
  9. //Get an instance of the Client Content.
  10. currentContext = new SP.ClientContext.get_current();
  11. //Grab the client web object.
  12. currentWeb = currentContext.get_web();
  13. //Get the current user object
  14. currentUser = currentContext.get_web().get_currentUser();
  15. currentContext.load(currentUser);
  16. //Setup the groupColletion.
  17. allGroups = currentWeb.get_siteGroups();
  18. currentContext.load(allGroups);
  19. //Now populate the objects above.
  20. currentContext.executeQueryAsync(
  21. Function.createDelegate(this, GetAllGroupsExecuteOnSuccess),
  22. Function.createDelegate(this, ExecuteOnFailure)
  23. );
  24. // GroupCollection - Load - SUCCESS
  25. function GetAllGroupsExecuteOnSuccess(sender, args) {
  26. // CHECK THE GROUPS
  27. // Time to Enumerate through the group collection that was returned.
  28. var groupEnumerator = allGroups.getEnumerator();
  29. // Loop for the collection.
  30. while (groupEnumerator.moveNext()) {
  31. //Grab the Group Item.
  32. var group = groupEnumerator.get_current();
  33. if (group.get_title().indexOf(strGroupName) > -1) {
  34. // Now that we have the group let's grab the list of users.
  35. groupUsers = group.get_users();
  36. currentContext.load(groupUsers);
  37. currentContext.executeQueryAsync(
  38. Function.createDelegate(this, SingleGroupExecuteOnSuccess),
  39. Function.createDelegate(this, ExecuteOnFailure)
  40. );
  41. }
  42. }
  43. }
  44. // Single Group - Load - SUCCESS
  45. function SingleGroupExecuteOnSuccess(sender, args) {
  46. // Time to setup the Enumerator
  47. var groupUserEnumerator = groupUsers.getEnumerator();
  48. // This is the flag to set to true if the user is in the group.
  49. var boolUserInGroup = false;
  50. // and start looping.
  51. while (groupUserEnumerator.moveNext()) {
  52. //Grab the User Item.
  53. var groupUser = groupUserEnumerator.get_current();
  54. // and finally. If a Group User ID Matches the current user ID then they are in the group!
  55. if (groupUser.get_id() == currentUser.get_id()) {
  56. boolUserInGroup = true;
  57. }
  58. }
  59. //Run the delegate function with the bool;
  60. functionComplete(boolUserInGroup);
  61. }
  62. // GroupCollection or Single Group - Load - FAILURE
  63. function ExecuteOnFailure(sender, args) {
  64. //Run the delegate function and return false because there was no match.
  65. functionComplete(false);
  66. }
  67. }
  68. IsCurrentUserMemberOfGroup("Lead", function (isCurrentUserInGroup) {
  69. if(isCurrentUserInGroup)
  70. {
  71. // Do something for the user in the correct SP group
  72. }
  73. });
function IsCurrentUserMemberOfGroup(strGroupName, functionComplete) {
 
        //Setup Vars
        currentContext  = null;
        currentWeb  = null;
        allGroups   = null;
        leaderGroup     = null;
        currentUser     = null;
        groupUsers  = null;
 
        //Get an instance of the Client Content.
        currentContext = new SP.ClientContext.get_current();
 
        //Grab the client web object.
        currentWeb = currentContext.get_web();
 
        //Get the current user object
        currentUser = currentContext.get_web().get_currentUser();
        currentContext.load(currentUser);
 
        //Setup the groupColletion.
        allGroups = currentWeb.get_siteGroups();
        currentContext.load(allGroups);
 
        //Now populate the objects above.
        currentContext.executeQueryAsync(
            Function.createDelegate(this, GetAllGroupsExecuteOnSuccess),
            Function.createDelegate(this, ExecuteOnFailure)
        );
 
        // GroupCollection - Load - SUCCESS
        function GetAllGroupsExecuteOnSuccess(sender, args) {
 
            // CHECK THE GROUPS
            // Time to Enumerate through the group collection that was returned.
            var groupEnumerator = allGroups.getEnumerator();
 
            // Loop for the collection.
            while (groupEnumerator.moveNext()) {
 
                //Grab the Group Item.
                var group = groupEnumerator.get_current();
                if (group.get_title().indexOf(strGroupName) > -1) {
 
                    // Now that we have the group let's grab the list of users.
                    groupUsers = group.get_users();
                    currentContext.load(groupUsers);
                    currentContext.executeQueryAsync(
                        Function.createDelegate(this, SingleGroupExecuteOnSuccess),
                        Function.createDelegate(this, ExecuteOnFailure)
                    );
                }
            }
        }
 
        // Single Group - Load - SUCCESS
        function SingleGroupExecuteOnSuccess(sender, args) {
 
            // Time to setup the Enumerator
            var groupUserEnumerator = groupUsers.getEnumerator();
 
            // This is the flag to set to true if the user is in the group.
            var boolUserInGroup = false;
 
            // and start looping.
            while (groupUserEnumerator.moveNext()) {
 
                //Grab the User Item.
                var groupUser = groupUserEnumerator.get_current();
 
                // and finally. If a Group User ID Matches the current user ID then they are in the group!
                if (groupUser.get_id() == currentUser.get_id()) {
                    boolUserInGroup = true;
                }
            }
 
            //Run the delegate function with the bool;
            functionComplete(boolUserInGroup);
        }
 
        // GroupCollection or Single Group - Load - FAILURE
        function ExecuteOnFailure(sender, args) {
            //Run the delegate function and return false because there was no match.
            functionComplete(false);
        }
    }
IsCurrentUserMemberOfGroup("Lead", function (isCurrentUserInGroup) {
    if(isCurrentUserInGroup)
    {
        // Do something for the user in the correct SP group
    }
});

2. 使用User 类的isSiteAdmin属性

a. 优点:需要写代码少,效率高

b. 缺点:只能判断用户是否为当前站点集管理员,适用场景很少

c. 代码实现如下:

  1. var currentUser;
  2. SP.SOD.executeFunc('sp.js', 'SP.ClientContext', GetCurrentUser);
  3. function GetCurrentUser() {
  4. var clientContext = new SP.ClientContext.get_current();
  5. var oWeb = clientContext.get_web();
  6. currentUser = oWeb.get_currentUser();
  7. clientContext.load(currentUser);
  8. clientContext.executeQueryAsync(Onsuccess, OnFailed);
  9. }
  10. function Onsuccess()
  11. {
  12. if(currentUser.get_isSiteAdmin())
  13. {
  14. // Do something for the user who is the current site collection admin
  15. }
  16. }
  17. function OnFailed(request, message)
  18. {
  19. alert('error'  + message);
  20. }
var currentUser;
SP.SOD.executeFunc('sp.js', 'SP.ClientContext', GetCurrentUser);
function GetCurrentUser() {
var clientContext = new SP.ClientContext.get_current();
var oWeb = clientContext.get_web();
currentUser = oWeb.get_currentUser();
clientContext.load(currentUser);
clientContext.executeQueryAsync(Onsuccess, OnFailed);
}
function Onsuccess()
{
if(currentUser.get_isSiteAdmin())
{
// Do something for the user who is the current site collection admin
}
}
function OnFailed(request, message)
{
alert('error' + message);
}

3. 使用 EffectiveBasePermissions,这个也是微软推荐的做法

a. 优点:功能上基本没有限制,可以检查所有SharePoint的权限级别: http://msdn.microsoft.com/en-us/library/ee556747(v=office.14).aspx

b. 缺点:获得权限的入口不是唯一的,可以单独给用户权限,也可以由用户加入到某个组来获取权限

c. 代码实现如下:

  1. <script type="text/javascript">
  2. SP.SOD.executeFunc('sp.js', 'SP.ClientContext', CheckPermissionOnWeb);
  3. function CheckPermissionOnWeb() {
  4. context = new SP.ClientContext.get_current();
  5. web = context.get_web();
  6. this._currentUser = web.get_currentUser();
  7. context.load(this._currentUser);
  8. context.load(web, 'EffectiveBasePermissions');
  9. context.executeQueryAsync(Function.createDelegate(this, this.onSuccessMethod), Function.createDelegate(this, this.onFailureMethod));
  10. }
  11. function onSuccessMethod(sender, args) {
  12. if (web.get_effectiveBasePermissions().has(SP.PermissionKind.manageWeb)) {
  13. // User Has permission to manage web
  14. //  Do something you want to do for the user who can manage the web
  15. }
  16. }
  17. Function onFailureMethod(sender, args)
  18. {
  19. alert('error'  +args.message);
  20. }
  21. </script>

原文地址:http://blog.csdn.net/abrahamcheng/article/details/17447479

[转]SharePoint 2010/2013 使用Javascript来判断权限的三种方法的更多相关文章

  1. [转]Javascript定义类的三种方法

    作者: 阮一峰 原文地址:http://www.ruanyifeng.com/blog/2012/07/three_ways_to_define_a_javascript_class.html 将近2 ...

  2. JavaScript去除空格的三种方法(正则/传参函数/trim)

    方法一: 个人认为最好的方法.采用的是正则表达式,这是最核心的原理. 其次.这个方法使用了JavaScript 的prototype 属性 其实你不使用这个属性一样可以用函数实现.但这样做后用起来比较 ...

  3. JavaScript 复制变量的三种方法

    参考:Copying Objects in JavaScript - Orinami Olatunji(@orinamio_) October 23, 2017    直接将一个变量赋给另一个变量时, ...

  4. JavaScript RegExp 对象的三种方法

    JavaScript RegExp 对象有 3 个方法:test().exec() 和 compile().(1) test() 方法用来检测一个字符串是否匹配某个正则表达式,如果匹配成功,返回 tr ...

  5. JavaScript调用后台的三种方法实例(包含两种Ajax)

    方法一:直接使用<%=%>调用(ASPX页面) 前台JS,代码如下: <script type="text/javascript"> var methodS ...

  6. 获得Window窗口权限的三种方法

    1.第一种方法:利用视图控制器自带的View的window属性:  具体使用 self.view.window.rootViewController = ... 2.第二种方法:通过导入APPDele ...

  7. javascript生成对象的三种方法

    /** js生成对象的三种方法*/ // 1.通过new Object,然后添加属性 示例如下: var people1 = new Object(); people1.name = 'xiaohai ...

  8. javascript获取DOM对象三种方法

    1. getElementByID() getElementByID()方法可返回对拥有指定ID的第一个对象的引用 2. getElementByTagName() getElementByTagNa ...

  9. JavaScript实现选项卡(三种方法)

    本文实例讲述了js选项卡的实现方法. 一.html代码: <div id="div1"> <input class="active" type ...

随机推荐

  1. BZOJ_1619_[Usaco2008_Nov]_Guarding_the_Farm_保卫牧场_(模拟+bfs)

    描述 http://www.lydsy.com/JudgeOnline/problem.php?id=1619 给出一张图每个点的高度,在一个点上安排守卫可以监视周围所有不高于于当前点的点.也就是类似 ...

  2. DedeCms 5.7友情链接模块注入漏洞

    漏洞版本: DedeCms 5.7 漏洞描述: DedeCms基于PHP+MySQL的技术开发,是目前国内应用最广泛的php类CMS系统. DedeCms 5.7前台提交友情链接处,可以插入恶意JS代 ...

  3. MS dos版本

    1981年,MS-DOS 1.0发行,作为IBM PC的操作系统进行捆绑发售,支持16k内存及160k的5寸软盘.在硬件昂贵,操作系统基本属于送硬件奉送的年代,谁也没能想到,微软公司竟会从这个不起眼的 ...

  4. 物联网操作系统HelloX V1.77(beta)版本发布

    物联网操作系统HelloX V1.77发布 经过近半年的努力,物联网操作系统HelloX V1.77版本正式完成,源代码已上载到github(github.com/hellox-project/Hel ...

  5. 【转】Android 源码编译make的错误处理--不错

    原文网址:http://blog.csdn.net/ithomer/article/details/6977386 Android源码下载:官方下载 或参考android源码下载方式 Android编 ...

  6. 使用Action、Func和Lambda表达式

    使用Action.Func和Lambda表达式 在.NET在,我们经常使用委托,委托的作用不必多说,在.NET 2.0之前,我们在使用委托之前,得自定义一个委托类型,再使用这个自定义的委托类型定义一个 ...

  7. 从头开始编写一个Orchard网上商店模块(2) - 配置您的Orchard开发环境

    原文地址:http://skywalkersoftwaredevelopment.net/blog/writing-an-orchard-webshop-module-from-scratch-par ...

  8. 不使用CvvImage类来在MFC中显示图像

    /* * ===================================================================================== * * Filen ...

  9. Lua包管理工具Luarocks详解 - 15134559390的个人空间 - 开源中国社区

    Lua包管理工具Luarocks详解 - 15134559390的个人空间 - 开源中国社区 Lua包管理工具Luarocks详解

  10. Video Surveillance - POJ 1474(判断是否存在内核)

    题目大意:询问是否在家里装一个监视器就可以监控所有的角落. 分析:赤裸裸的判断多边形内核题目. 代码如下: #include<iostream> #include<string.h& ...