aboutsummaryrefslogtreecommitdiffstats
path: root/apps/admin_audit/lib/Listener/UserManagementEventListener.php
blob: c22d04dce9a7ca8b20f4718c4752f1ecfddcd551 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
<?php

declare(strict_types=1);

/**
 * SPDX-FileCopyrightText: 2017 Nextcloud GmbH and Nextcloud contributors
 * SPDX-License-Identifier: AGPL-3.0-or-later
 */

namespace OCA\AdminAudit\Listener;

use OCA\AdminAudit\Actions\Action;
use OCP\EventDispatcher\Event;
use OCP\EventDispatcher\IEventListener;
use OCP\User\Events\PasswordUpdatedEvent;
use OCP\User\Events\UserChangedEvent;
use OCP\User\Events\UserCreatedEvent;
use OCP\User\Events\UserDeletedEvent;
use OCP\User\Events\UserIdAssignedEvent;
use OCP\User\Events\UserIdUnassignedEvent;

/**
 * @template-implements IEventListener<UserCreatedEvent|UserDeletedEvent|UserChangedEvent|PasswordUpdatedEvent|UserIdAssignedEvent|UserIdUnassignedEvent>
 */
class UserManagementEventListener extends Action implements IEventListener {
	public function handle(Event $event): void {
		if ($event instanceof UserCreatedEvent) {
			$this->userCreated($event);
		} elseif ($event instanceof UserDeletedEvent) {
			$this->userDeleted($event);
		} elseif ($event instanceof UserChangedEvent) {
			$this->userChanged($event);
		} elseif ($event instanceof PasswordUpdatedEvent) {
			$this->passwordUpdated($event);
		} elseif ($event instanceof UserIdAssignedEvent) {
			$this->userIdAssigned($event);
		} elseif ($event instanceof UserIdUnassignedEvent) {
			$this->userIdUnassigned($event);
		}
	}

	private function userCreated(UserCreatedEvent $event): void {
		$this->log(
			'User created: "%s"',
			[
				'uid' => $event->getUid()
			],
			[
				'uid',
			]
		);
	}

	private function userDeleted(UserDeletedEvent $event): void {
		$this->log(
			'User deleted: "%s"',
			[
				'uid' => $event->getUser()->getUID()
			],
			[
				'uid',
			]
		);
	}

	private function userChanged(UserChangedEvent $event): void {
		switch ($event->getFeature()) {
			case 'enabled':
				$this->log(
					$event->getValue() === true
						? 'User enabled: "%s"'
						: 'User disabled: "%s"',
					['user' => $event->getUser()->getUID()],
					[
						'user',
					]
				);
				break;
			case 'eMailAddress':
				$this->log(
					'Email address changed for user %s',
					['user' => $event->getUser()->getUID()],
					[
						'user',
					]
				);
				break;
		}
	}

	private function passwordUpdated(PasswordUpdatedEvent $event): void {
		if ($event->getUser()->getBackendClassName() === 'Database') {
			$this->log(
				'Password of user "%s" has been changed',
				[
					'user' => $event->getUser()->getUID(),
				],
				[
					'user',
				]
			);
		}
	}

	/**
	 * Log assignments of users (typically user backends)
	 */
	private function userIdAssigned(UserIdAssignedEvent $event): void {
		$this->log(
			'UserID assigned: "%s"',
			[ 'uid' => $event->getUserId() ],
			[ 'uid' ]
		);
	}

	/**
	 * Log unassignments of users (typically user backends, no data removed)
	 */
	private function userIdUnassigned(UserIdUnassignedEvent $event): void {
		$this->log(
			'UserID unassigned: "%s"',
			[ 'uid' => $event->getUserId() ],
			[ 'uid' ]
		);
	}
}