Fork of FusionPBX but with LDAP kinda working
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

249 lines
9.8 KiB

2 years ago
  1. <?php
  2. /*
  3. FusionPBX
  4. Version: MPL 1.1
  5. The contents of this file are subject to the Mozilla Public License Version
  6. 1.1 (the "License"); you may not use this file except in compliance with
  7. the License. You may obtain a copy of the License at
  8. http://www.mozilla.org/MPL/
  9. Software distributed under the License is distributed on an "AS IS" basis,
  10. WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
  11. for the specific language governing rights and limitations under the
  12. License.
  13. The Original Code is FusionPBX
  14. The Initial Developer of the Original Code is
  15. Mark J Crane <markjcrane@fusionpbx.com>
  16. Portions created by the Initial Developer are Copyright (C) 2018 - 2020
  17. the Initial Developer. All Rights Reserved.
  18. Contributor(s):
  19. Mark J Crane <markjcrane@fusionpbx.com>
  20. */
  21. //includes
  22. require_once "root.php";
  23. require_once "resources/require.php";
  24. require_once "resources/check_auth.php";
  25. //check permissions
  26. if (permission_exists('access_control_view')) {
  27. //access granted
  28. }
  29. else {
  30. echo "access denied";
  31. exit;
  32. }
  33. //add multi-lingual support
  34. $language = new text;
  35. $text = $language->get();
  36. //get the http post data
  37. if (is_array($_POST['access_controls'])) {
  38. $action = $_POST['action'];
  39. $search = $_POST['search'];
  40. $access_controls = $_POST['access_controls'];
  41. }
  42. //process the http post data by action
  43. if ($action != '' && is_array($access_controls) && @sizeof($access_controls) != 0) {
  44. //validate the token
  45. $token = new token;
  46. if (!$token->validate($_SERVER['PHP_SELF'])) {
  47. message::add($text['message-invalid_token'],'negative');
  48. header('Location: access_controls.php');
  49. exit;
  50. }
  51. //prepare the array
  52. foreach($access_controls as $row) {
  53. $array['access_controls'][$x]['checked'] = $row['checked'];
  54. $array['access_controls'][$x]['access_control_uuid'] = $row['access_control_uuid'];
  55. $x++;
  56. }
  57. //prepare the database object
  58. $database = new database;
  59. $database->app_name = 'access_controls';
  60. $database->app_uuid = '1416a250-f6e1-4edc-91a6-5c9b883638fd';
  61. //send the array to the database class
  62. switch ($action) {
  63. case 'copy':
  64. if (permission_exists('access_control_add')) {
  65. $database->copy($array);
  66. }
  67. break;
  68. case 'toggle':
  69. if (permission_exists('access_control_edit')) {
  70. $database->toggle($array);
  71. }
  72. break;
  73. case 'delete':
  74. if (permission_exists('access_control_delete')) {
  75. $database->delete($array);
  76. }
  77. break;
  78. }
  79. //redirect the user
  80. header('Location: access_controls.php'.($search != '' ? '?search='.urlencode($search) : null));
  81. exit;
  82. }
  83. //get order and order by
  84. $order_by = $_GET["order_by"];
  85. $order = $_GET["order"];
  86. //add the search
  87. if (isset($_GET["search"])) {
  88. $search = strtolower($_GET["search"]);
  89. $parameters['search'] = '%'.$search.'%';
  90. }
  91. //get the count
  92. $sql = "select count(access_control_uuid) ";
  93. $sql .= "from v_access_controls ";
  94. if (isset($_GET["search"])) {
  95. $sql .= "where (";
  96. $sql .= " lower(access_control_name) like :search ";
  97. $sql .= " or lower(access_control_default) like :search ";
  98. $sql .= " or lower(access_control_description) like :search ";
  99. $sql .= ") ";
  100. }
  101. $database = new database;
  102. $num_rows = $database->select($sql, $parameters, 'column');
  103. //get the list
  104. $sql = "select ";
  105. $sql .= "access_control_uuid, ";
  106. $sql .= "access_control_name, ";
  107. $sql .= "access_control_default, ";
  108. $sql .= "access_control_description ";
  109. $sql .= "from v_access_controls ";
  110. if (isset($_GET["search"])) {
  111. $sql .= "where (";
  112. $sql .= " lower(access_control_name) like :search ";
  113. $sql .= " or lower(access_control_default) like :search ";
  114. $sql .= " or lower(access_control_description) like :search ";
  115. $sql .= ") ";
  116. }
  117. $sql .= order_by($order_by, $order, 'access_control_name', 'asc');
  118. $sql .= limit_offset($rows_per_page, $offset);
  119. $database = new database;
  120. $access_controls = $database->select($sql, $parameters, 'all');
  121. unset($sql, $parameters);
  122. //create token
  123. $object = new token;
  124. $token = $object->create($_SERVER['PHP_SELF']);
  125. //additional includes
  126. $document['title'] = $text['title-access_controls'];
  127. require_once "resources/header.php";
  128. //show the content
  129. echo "<div class='action_bar' id='action_bar'>\n";
  130. echo " <div class='heading'><b>".$text['title-access_controls']." (".$num_rows.")</b></div>\n";
  131. echo " <div class='actions'>\n";
  132. if (permission_exists('access_control_add')) {
  133. echo button::create(['type'=>'button','label'=>$text['button-add'],'icon'=>$_SESSION['theme']['button_icon_add'],'id'=>'btn_add','name'=>'btn_add','link'=>'access_control_edit.php']);
  134. }
  135. if (permission_exists('access_control_add') && $access_controls) {
  136. echo button::create(['type'=>'button','label'=>$text['button-copy'],'icon'=>$_SESSION['theme']['button_icon_copy'],'id'=>'btn_copy','name'=>'btn_copy','style'=>'display:none;','onclick'=>"modal_open('modal-copy','btn_copy');"]);
  137. }
  138. if (permission_exists('access_control_delete') && $access_controls) {
  139. echo button::create(['type'=>'button','label'=>$text['button-delete'],'icon'=>$_SESSION['theme']['button_icon_delete'],'id'=>'btn_delete','name'=>'btn_delete','style'=>'display:none;','onclick'=>"modal_open('modal-delete','btn_delete');"]);
  140. }
  141. echo "<form id='form_search' class='inline' method='get'>\n";
  142. echo "<input type='text' class='txt list-search' name='search' id='search' value=\"".escape($search)."\" placeholder=\"".$text['label-search']."\" onkeydown=''>";
  143. echo button::create(['label'=>$text['button-search'],'icon'=>$_SESSION['theme']['button_icon_search'],'type'=>'submit','id'=>'btn_search']);
  144. //echo button::create(['label'=>$text['button-reset'],'icon'=>$_SESSION['theme']['button_icon_reset'],'type'=>'button','id'=>'btn_reset','link'=>'access_controls.php','style'=>($search == '' ? 'display: none;' : null)]);
  145. if ($paging_controls_mini != '') {
  146. echo "<span style='margin-left: 15px;'>".$paging_controls_mini."</span>\n";
  147. }
  148. echo " </form>\n";
  149. echo " </div>\n";
  150. echo " <div style='clear: both;'></div>\n";
  151. echo "</div>\n";
  152. if (permission_exists('access_control_add') && $access_controls) {
  153. echo modal::create(['id'=>'modal-copy','type'=>'copy','actions'=>button::create(['type'=>'button','label'=>$text['button-continue'],'icon'=>'check','id'=>'btn_copy','style'=>'float: right; margin-left: 15px;','collapse'=>'never','onclick'=>"modal_close(); list_action_set('copy'); list_form_submit('form_list');"])]);
  154. }
  155. if (permission_exists('access_control_delete') && $access_controls) {
  156. echo modal::create(['id'=>'modal-delete','type'=>'delete','actions'=>button::create(['type'=>'button','label'=>$text['button-continue'],'icon'=>'check','id'=>'btn_delete','style'=>'float: right; margin-left: 15px;','collapse'=>'never','onclick'=>"modal_close(); list_action_set('delete'); list_form_submit('form_list');"])]);
  157. }
  158. echo $text['title_description-access_controls']."\n";
  159. echo "<br /><br />\n";
  160. echo "<form id='form_list' method='post'>\n";
  161. echo "<input type='hidden' id='action' name='action' value=''>\n";
  162. echo "<input type='hidden' name='search' value=\"".escape($search)."\">\n";
  163. echo "<table class='list'>\n";
  164. echo "<tr class='list-header'>\n";
  165. if (permission_exists('access_control_add') || permission_exists('access_control_edit') || permission_exists('access_control_delete')) {
  166. echo " <th class='checkbox'>\n";
  167. echo " <input type='checkbox' id='checkbox_all' name='checkbox_all' onclick='list_all_toggle(); checkbox_on_change(this);' ".($access_controls ?: "style='visibility: hidden;'").">\n";
  168. echo " </th>\n";
  169. }
  170. echo th_order_by('access_control_name', $text['label-access_control_name'], $order_by, $order);
  171. echo th_order_by('access_control_default', $text['label-access_control_default'], $order_by, $order);
  172. echo " <th class='hide-sm-dn'>".$text['label-access_control_description']."</th>\n";
  173. if (permission_exists('access_control_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') {
  174. echo " <td class='action-button'>&nbsp;</td>\n";
  175. }
  176. echo "</tr>\n";
  177. if (is_array($access_controls) && @sizeof($access_controls) != 0) {
  178. $x = 0;
  179. foreach ($access_controls as $row) {
  180. if (permission_exists('access_control_edit')) {
  181. $list_row_url = "access_control_edit.php?id=".urlencode($row['access_control_uuid']);
  182. }
  183. echo "<tr class='list-row' href='".$list_row_url."'>\n";
  184. if (permission_exists('access_control_add') || permission_exists('access_control_edit') || permission_exists('access_control_delete')) {
  185. echo " <td class='checkbox'>\n";
  186. echo " <input type='checkbox' name='access_controls[$x][checked]' id='checkbox_".$x."' value='true' onclick=\"checkbox_on_change(this); if (!this.checked) { document.getElementById('checkbox_all').checked = false; }\">\n";
  187. echo " <input type='hidden' name='access_controls[$x][access_control_uuid]' value='".escape($row['access_control_uuid'])."' />\n";
  188. echo " </td>\n";
  189. }
  190. echo " <td>\n";
  191. if (permission_exists('access_control_edit')) {
  192. echo " <a href='".$list_row_url."' title=\"".$text['button-edit']."\">".escape($row['access_control_name'])."</a>\n";
  193. }
  194. else {
  195. echo " ".escape($row['access_control_name']);
  196. }
  197. echo " </td>\n";
  198. echo " <td>".escape($row['access_control_default'])."</td>\n";
  199. echo " <td class='description overflow hide-sm-dn'>".escape($row['access_control_description'])."</td>\n";
  200. if (permission_exists('access_control_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') {
  201. echo " <td class='action-button'>\n";
  202. echo button::create(['type'=>'button','title'=>$text['button-edit'],'icon'=>$_SESSION['theme']['button_icon_edit'],'link'=>$list_row_url]);
  203. echo " </td>\n";
  204. }
  205. echo "</tr>\n";
  206. $x++;
  207. }
  208. unset($access_controls);
  209. }
  210. echo "</table>\n";
  211. echo "<br />\n";
  212. echo "<div align='center'>".$paging_controls."</div>\n";
  213. echo "<input type='hidden' name='".$token['name']."' value='".$token['hash']."'>\n";
  214. echo "</form>\n";
  215. //include the footer
  216. require_once "resources/footer.php";
  217. ?>