|
@@ -88,10 +88,7 @@
|
|
else {
|
|
else {
|
|
//debug
|
|
//debug
|
|
if ($debug) {
|
|
if ($debug) {
|
|
- echo "<pre>";
|
|
|
|
- print_r($result);
|
|
|
|
- echo "</pre>";
|
|
|
|
- exit;
|
|
|
|
|
|
+ view_array($result);
|
|
}
|
|
}
|
|
|
|
|
|
//log the failed auth attempt to the system, to be available for fail2ban.
|
|
//log the failed auth attempt to the system, to be available for fail2ban.
|
|
@@ -107,19 +104,26 @@
|
|
}
|
|
}
|
|
|
|
|
|
//get the groups assigned to the user and then set the groups in $_SESSION["groups"]
|
|
//get the groups assigned to the user and then set the groups in $_SESSION["groups"]
|
|
- $sql = "select u.user_group_uuid, u.domain_uuid, u.user_uuid, u.group_uuid, g.group_name, g.group_level ";
|
|
|
|
- $sql .= "from v_user_groups as u, v_groups as g ";
|
|
|
|
|
|
+ $sql = "select ";
|
|
|
|
+ $sql .= "u.user_group_uuid, ";
|
|
|
|
+ $sql .= "u.domain_uuid, ";
|
|
|
|
+ $sql .= "u.user_uuid, ";
|
|
|
|
+ $sql .= "u.group_uuid, ";
|
|
|
|
+ $sql .= "g.group_name, ";
|
|
|
|
+ $sql .= "g.group_level ";
|
|
|
|
+ $sql .= "from ";
|
|
|
|
+ $sql .= "v_user_groups as u, ";
|
|
|
|
+ $sql .= "v_groups as g ";
|
|
$sql .= "where u.domain_uuid = :domain_uuid ";
|
|
$sql .= "where u.domain_uuid = :domain_uuid ";
|
|
$sql .= "and u.user_uuid = :user_uuid ";
|
|
$sql .= "and u.user_uuid = :user_uuid ";
|
|
$sql .= "and u.group_uuid = g.group_uuid ";
|
|
$sql .= "and u.group_uuid = g.group_uuid ";
|
|
- $prep_statement = $db->prepare($sql);
|
|
|
|
- $prep_statement->bindParam(':domain_uuid', $_SESSION["domain_uuid"] );
|
|
|
|
- $prep_statement->bindParam(':user_uuid', $_SESSION["user_uuid"]);
|
|
|
|
- $prep_statement->execute();
|
|
|
|
- $result = $prep_statement->fetchAll(PDO::FETCH_NAMED);
|
|
|
|
|
|
+ $parameters['domain_uuid'] = $_SESSION["domain_uuid"];
|
|
|
|
+ $parameters['user_uuid'] = $_SESSION["user_uuid"];
|
|
|
|
+ $database = new database;
|
|
|
|
+ $result = $database->select($sql, $parameters, 'all');
|
|
$_SESSION["groups"] = $result;
|
|
$_SESSION["groups"] = $result;
|
|
$_SESSION["user"]["groups"] = $result;
|
|
$_SESSION["user"]["groups"] = $result;
|
|
- unset($sql, $row_count, $prep_statement);
|
|
|
|
|
|
+ unset($sql, $parameters);
|
|
|
|
|
|
//get the users group level
|
|
//get the users group level
|
|
$_SESSION["user"]["group_level"] = 0;
|
|
$_SESSION["user"]["group_level"] = 0;
|
|
@@ -130,42 +134,42 @@
|
|
}
|
|
}
|
|
|
|
|
|
//get the permissions assigned to the groups that the user is a member of set the permissions in $_SESSION['permissions']
|
|
//get the permissions assigned to the groups that the user is a member of set the permissions in $_SESSION['permissions']
|
|
- if (count($_SESSION["groups"]) > 0) {
|
|
|
|
|
|
+ if (is_array($_SESSION["groups"]) && @sizeof($_SESSION["groups"]) != 0) {
|
|
$x = 0;
|
|
$x = 0;
|
|
$sql = "select distinct(permission_name) from v_group_permissions ";
|
|
$sql = "select distinct(permission_name) from v_group_permissions ";
|
|
- foreach($_SESSION["groups"] as $field) {
|
|
|
|
|
|
+ $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) ";
|
|
|
|
+ foreach ($_SESSION["groups"] as $field) {
|
|
if (strlen($field['group_name']) > 0) {
|
|
if (strlen($field['group_name']) > 0) {
|
|
- if ($x == 0) {
|
|
|
|
- $sql .= "where (domain_uuid = '".$_SESSION["domain_uuid"]."' and domain_uuid = null) ";
|
|
|
|
- }
|
|
|
|
- else {
|
|
|
|
- $sql .= "or (domain_uuid = '".$_SESSION["domain_uuid"]."' and domain_uuid = null) ";
|
|
|
|
- }
|
|
|
|
- $sql .= "or group_name = '".$field['group_name']."' ";
|
|
|
|
|
|
+ $sql_where_or[] = "group_name = :group_name_".$x;
|
|
|
|
+ $parameters['group_name_'.$x] = $field['group_name'];
|
|
$x++;
|
|
$x++;
|
|
}
|
|
}
|
|
}
|
|
}
|
|
- $prep_statement_sub = $db->prepare($sql);
|
|
|
|
- $prep_statement_sub->execute();
|
|
|
|
- $result = $prep_statement_sub->fetchAll(PDO::FETCH_NAMED);
|
|
|
|
- if (is_array($result)) {
|
|
|
|
|
|
+ if (is_array($sql_where_or) && @sizeof($sql_where_or) != 0) {
|
|
|
|
+ $sql .= "and (".implode(' or ', $sql_where_or).") ";
|
|
|
|
+ }
|
|
|
|
+ $parameters['domain_uuid'] = $_SESSION["domain_uuid"];
|
|
|
|
+ $database = new database;
|
|
|
|
+ $result = $database->select($sql, $parameters, 'all');
|
|
|
|
+ if (is_array($result) && @sizeof($result) != 0) {
|
|
foreach ($result as $row) {
|
|
foreach ($result as $row) {
|
|
$_SESSION['permissions'][$row["permission_name"]] = true;
|
|
$_SESSION['permissions'][$row["permission_name"]] = true;
|
|
$_SESSION["user"]["permissions"][$row["permission_name"]] = true;
|
|
$_SESSION["user"]["permissions"][$row["permission_name"]] = true;
|
|
}
|
|
}
|
|
}
|
|
}
|
|
- unset($sql, $prep_statement_sub);
|
|
|
|
|
|
+ unset($sql, $parameters, $result, $row);
|
|
}
|
|
}
|
|
|
|
|
|
//get the user settings
|
|
//get the user settings
|
|
$sql = "select * from v_user_settings ";
|
|
$sql = "select * from v_user_settings ";
|
|
- $sql .= "where domain_uuid = '" . $_SESSION["domain_uuid"] . "' ";
|
|
|
|
- $sql .= "and user_uuid = '" . $_SESSION["user_uuid"] . "' ";
|
|
|
|
|
|
+ $sql .= "where domain_uuid = :domain_uuid ";
|
|
|
|
+ $sql .= "and user_uuid = :user_uuid ";
|
|
$sql .= "and user_setting_enabled = 'true' ";
|
|
$sql .= "and user_setting_enabled = 'true' ";
|
|
- $prep_statement = $db->prepare($sql);
|
|
|
|
- if ($prep_statement) {
|
|
|
|
- $prep_statement->execute();
|
|
|
|
- $result = $prep_statement->fetchAll(PDO::FETCH_NAMED);
|
|
|
|
|
|
+ $parameters['domain_uuid'] = $_SESSION["domain_uuid"];
|
|
|
|
+ $parameters['user_uuid'] = $_SESSION["user_uuid"];
|
|
|
|
+ $database = new database;
|
|
|
|
+ $result = $database->select($sql, $parameters, 'all');
|
|
|
|
+ if (is_array($result) && @sizeof($result) != 0) {
|
|
foreach ($result as $row) {
|
|
foreach ($result as $row) {
|
|
$name = $row['user_setting_name'];
|
|
$name = $row['user_setting_name'];
|
|
$category = $row['user_setting_category'];
|
|
$category = $row['user_setting_category'];
|
|
@@ -179,7 +183,8 @@
|
|
else {
|
|
else {
|
|
$_SESSION[$category][$name] = $row['user_setting_value'];
|
|
$_SESSION[$category][$name] = $row['user_setting_value'];
|
|
}
|
|
}
|
|
- } else {
|
|
|
|
|
|
+ }
|
|
|
|
+ else {
|
|
//$$category[$subcategory][$name] = $row['domain_setting_value'];
|
|
//$$category[$subcategory][$name] = $row['domain_setting_value'];
|
|
if ($name == "array") {
|
|
if ($name == "array") {
|
|
$_SESSION[$category][$subcategory][] = $row['user_setting_value'];
|
|
$_SESSION[$category][$subcategory][] = $row['user_setting_value'];
|
|
@@ -191,57 +196,62 @@
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
+ unset($sql, $parameters, $result, $row);
|
|
|
|
|
|
//get the extensions that are assigned to this user
|
|
//get the extensions that are assigned to this user
|
|
if (file_exists($_SERVER["PROJECT_ROOT"]."/app/extensions/app_config.php")) {
|
|
if (file_exists($_SERVER["PROJECT_ROOT"]."/app/extensions/app_config.php")) {
|
|
- if (isset($_SESSION["user"]) && isset($_SESSION["user_uuid"]) && $db && strlen($_SESSION["domain_uuid"]) > 0 && strlen($_SESSION["user_uuid"]) > 0 && count($_SESSION['user']['extension']) == 0) {
|
|
|
|
|
|
+ if (
|
|
|
|
+ isset($_SESSION["user"]) &&
|
|
|
|
+ is_uuid($_SESSION["user_uuid"]) &&
|
|
|
|
+ is_uuid($_SESSION["domain_uuid"]) &&
|
|
|
|
+ count($_SESSION['user']['extension']) == 0
|
|
|
|
+ ) {
|
|
//get the user extension list
|
|
//get the user extension list
|
|
$_SESSION['user']['extension'] = null;
|
|
$_SESSION['user']['extension'] = null;
|
|
$sql = "select ";
|
|
$sql = "select ";
|
|
- $sql .= " e.extension_uuid, ";
|
|
|
|
- $sql .= " e.extension, ";
|
|
|
|
- $sql .= " e.number_alias, ";
|
|
|
|
- $sql .= " e.user_context, ";
|
|
|
|
- $sql .= " e.outbound_caller_id_name, ";
|
|
|
|
- $sql .= " e.outbound_caller_id_number, ";
|
|
|
|
- $sql .= " e.description ";
|
|
|
|
|
|
+ $sql .= "e.extension_uuid, ";
|
|
|
|
+ $sql .= "e.extension, ";
|
|
|
|
+ $sql .= "e.number_alias, ";
|
|
|
|
+ $sql .= "e.user_context, ";
|
|
|
|
+ $sql .= "e.outbound_caller_id_name, ";
|
|
|
|
+ $sql .= "e.outbound_caller_id_number, ";
|
|
|
|
+ $sql .= "e.description ";
|
|
$sql .= "from ";
|
|
$sql .= "from ";
|
|
- $sql .= " v_extension_users as u, ";
|
|
|
|
- $sql .= " v_extensions as e ";
|
|
|
|
|
|
+ $sql .= "v_extension_users as u, ";
|
|
|
|
+ $sql .= "v_extensions as e ";
|
|
$sql .= "where ";
|
|
$sql .= "where ";
|
|
- $sql .= " e.domain_uuid = '".$_SESSION['domain_uuid']."' ";
|
|
|
|
- $sql .= " and e.extension_uuid = u.extension_uuid ";
|
|
|
|
- $sql .= " and u.user_uuid = '".$_SESSION['user_uuid']."' ";
|
|
|
|
- $sql .= " and e.enabled = 'true' ";
|
|
|
|
|
|
+ $sql .= "e.domain_uuid = :domain_uuid ";
|
|
|
|
+ $sql .= "and e.extension_uuid = u.extension_uuid ";
|
|
|
|
+ $sql .= "and u.user_uuid = :user_uuid ";
|
|
|
|
+ $sql .= "and e.enabled = 'true' ";
|
|
$sql .= "order by ";
|
|
$sql .= "order by ";
|
|
- $sql .= " e.extension asc ";
|
|
|
|
- $query = $db->query($sql);
|
|
|
|
- if($query !== false) {
|
|
|
|
- $result = $db->query($sql)->fetchAll(PDO::FETCH_ASSOC);
|
|
|
|
- $x = 0;
|
|
|
|
- foreach($result as $row) {
|
|
|
|
|
|
+ $sql .= "e.extension asc ";
|
|
|
|
+ $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
|
|
|
|
+ $parameters['user_uuid'] = $_SESSION['user_uuid'];
|
|
|
|
+ $database = new database;
|
|
|
|
+ $result = $database->select($sql, $parameters, 'all');
|
|
|
|
+ if (is_array($result) && @sizeof($result) != 0) {
|
|
|
|
+ foreach($result as $x => $row) {
|
|
//set the destination
|
|
//set the destination
|
|
- $destination = $row['extension'];
|
|
|
|
- if (strlen($row['number_alias']) > 0) {
|
|
|
|
- $destination = $row['number_alias'];
|
|
|
|
- }
|
|
|
|
-
|
|
|
|
- //build the uers array
|
|
|
|
- $_SESSION['user']['extension'][$x]['user'] = $row['extension'];
|
|
|
|
- $_SESSION['user']['extension'][$x]['number_alias'] = $row['number_alias'];
|
|
|
|
- $_SESSION['user']['extension'][$x]['destination'] = $destination;
|
|
|
|
- $_SESSION['user']['extension'][$x]['extension_uuid'] = $row['extension_uuid'];
|
|
|
|
- $_SESSION['user']['extension'][$x]['outbound_caller_id_name'] = $row['outbound_caller_id_name'];
|
|
|
|
- $_SESSION['user']['extension'][$x]['outbound_caller_id_number'] = $row['outbound_caller_id_number'];
|
|
|
|
- $_SESSION['user']['extension'][$x]['user_context'] = $row['user_context'];
|
|
|
|
- $_SESSION['user']['extension'][$x]['description'] = $row['description'];
|
|
|
|
-
|
|
|
|
|
|
+ $destination = $row['extension'];
|
|
|
|
+ if (strlen($row['number_alias']) > 0) {
|
|
|
|
+ $destination = $row['number_alias'];
|
|
|
|
+ }
|
|
|
|
+ //build the user array
|
|
|
|
+ $_SESSION['user']['extension'][$x]['user'] = $row['extension'];
|
|
|
|
+ $_SESSION['user']['extension'][$x]['number_alias'] = $row['number_alias'];
|
|
|
|
+ $_SESSION['user']['extension'][$x]['destination'] = $destination;
|
|
|
|
+ $_SESSION['user']['extension'][$x]['extension_uuid'] = $row['extension_uuid'];
|
|
|
|
+ $_SESSION['user']['extension'][$x]['outbound_caller_id_name'] = $row['outbound_caller_id_name'];
|
|
|
|
+ $_SESSION['user']['extension'][$x]['outbound_caller_id_number'] = $row['outbound_caller_id_number'];
|
|
|
|
+ $_SESSION['user']['extension'][$x]['user_context'] = $row['user_context'];
|
|
|
|
+ $_SESSION['user']['extension'][$x]['description'] = $row['description'];
|
|
//set the user context
|
|
//set the user context
|
|
- $_SESSION['user']['user_context'] = $row["user_context"];
|
|
|
|
- $_SESSION['user_context'] = $row["user_context"];
|
|
|
|
- $x++;
|
|
|
|
|
|
+ $_SESSION['user']['user_context'] = $row["user_context"];
|
|
|
|
+ $_SESSION['user_context'] = $row["user_context"];
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
+ unset($sql, $parameters, $result, $row);
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
|
|
@@ -281,4 +291,4 @@
|
|
$v_path_show = false;
|
|
$v_path_show = false;
|
|
}
|
|
}
|
|
|
|
|
|
-?>
|
|
|
|
|
|
+?>
|