Portions created by the Initial Developer are Copyright (C) 2008 - 2020 the Initial Developer. All Rights Reserved. Contributor(s): Mark J Crane */ //includes require_once "root.php"; require_once "resources/require.php"; require_once "resources/check_auth.php"; require_once "resources/paging.php"; //check permissions if (permission_exists('user_view')) { //access granted } else { echo "access denied"; exit; } //add multi-lingual support $language = new text; $text = $language->get(); //get the http post data if (is_array($_POST['users'])) { $action = $_POST['action']; $search = $_POST['search']; $users = $_POST['users']; } //process the http post data by action if ($action != '' && is_array($users) && @sizeof($users) != 0) { switch ($action) { case 'copy': if (permission_exists('user_add')) { $obj = new users; $obj->copy($users); } break; case 'toggle': if (permission_exists('user_edit')) { $obj = new users; $obj->toggle($users); } break; case 'delete': if (permission_exists('user_delete')) { $obj = new users; $obj->delete($users); } break; } header('Location: users.php'.($search != '' ? '?search='.urlencode($search) : null)); exit; } //get order and order by $order_by = $_GET["order_by"]; $order = $_GET["order"]; //add the search string if (isset($_GET["search"])) { $search = strtolower($_GET["search"]); $sql_search = " ("; $sql_search .= " lower(username) like :search "; $sql_search .= " or lower(groups) like :search "; $sql_search .= " or lower(contact_organization) like :search "; $sql_search .= " or lower(contact_name) like :search "; //$sql_search .= " or lower(user_status) like :search "; $sql_search .= ") "; $parameters['search'] = '%'.$search.'%'; } //get the count $sql = "select count(*) from view_users "; if ($_GET['show'] == "all" && permission_exists('user_all')) { if (isset($sql_search)) { $sql .= "where ".$sql_search; } else { $sql.= "where true "; } } else { $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) "; if (isset($sql_search)) { $sql .= "and ".$sql_search; } $parameters['domain_uuid'] = $domain_uuid; } $sql .= "and ( "; $sql .= " group_level <= :group_level "; $sql .= " or group_level is null "; $sql .= ") "; $parameters['group_level'] = $_SESSION['user']['group_level']; $database = new database; $num_rows = $database->select($sql, $parameters, 'column'); //prepare to page the results $rows_per_page = ($_SESSION['domain']['paging']['numeric'] != '') ? $_SESSION['domain']['paging']['numeric'] : 50; $param = $search ? "&search=".$search : null; $param = ($_GET['show'] == 'all' && permission_exists('user_all')) ? "&show=all" : null; $page = is_numeric($_GET['page']) ? $_GET['page'] : 0; list($paging_controls, $rows_per_page) = paging($num_rows, $param, $rows_per_page); list($paging_controls_mini, $rows_per_page) = paging($num_rows, $param, $rows_per_page, true); $offset = $rows_per_page * $page; //get the list $sql = "select * from view_users "; if ($_GET['show'] == "all" && permission_exists('user_all')) { if (isset($sql_search)) { $sql .= "where ".$sql_search; } else { $sql.= "where true "; } } else { $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) "; if (isset($sql_search)) { $sql .= "and ".$sql_search; } $parameters['domain_uuid'] = $domain_uuid; } $sql .= "and ( "; $sql .= " group_level <= :group_level "; $sql .= " or group_level is null "; $sql .= ") "; $parameters['group_level'] = $_SESSION['user']['group_level']; $sql .= order_by($order_by, $order, 'username', 'asc'); $sql .= limit_offset($rows_per_page, $offset); $database = new database; $users = $database->select($sql, $parameters, 'all'); unset($sql, $parameters); //create token $object = new token; $token = $object->create($_SERVER['PHP_SELF']); //include the header $document['title'] = $text['title-users']; require_once "resources/header.php"; //show the content echo "
\n"; echo "
".$text['title-users']." (".$num_rows.")
\n"; echo "
\n"; if (permission_exists('user_add')) { if (!isset($id)) { echo button::create(['type'=>'button','label'=>$text['button-import'],'icon'=>$_SESSION['theme']['button_icon_import'],'style'=>'margin-right: 15px;','link'=>'user_imports.php']); } echo button::create(['type'=>'button','label'=>$text['button-add'],'icon'=>$_SESSION['theme']['button_icon_add'],'link'=>'user_edit.php']); } if (permission_exists('user_add') && $users) { echo button::create(['type'=>'button','label'=>$text['button-copy'],'icon'=>$_SESSION['theme']['button_icon_copy'],'onclick'=>"if (confirm('".$text['confirm-copy']."')) { list_action_set('copy'); list_form_submit('form_list'); } else { this.blur(); return false; }"]); } if (permission_exists('user_edit') && $users) { echo button::create(['type'=>'button','label'=>$text['button-toggle'],'icon'=>$_SESSION['theme']['button_icon_toggle'],'onclick'=>"if (confirm('".$text['confirm-toggle']."')) { list_action_set('toggle'); list_form_submit('form_list'); } else { this.blur(); return false; }"]); } if (permission_exists('user_delete') && $users) { echo button::create(['type'=>'button','label'=>$text['button-delete'],'icon'=>$_SESSION['theme']['button_icon_delete'],'onclick'=>"if (confirm('".$text['confirm-delete']."')) { list_action_set('delete'); list_form_submit('form_list'); } else { this.blur(); return false; }"]); } echo "\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo $text['description-users']."\n"; echo "

\n"; echo "
\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; if (permission_exists('user_add') || permission_exists('user_edit') || permission_exists('user_delete')) { echo " \n"; } if ($_GET['show'] == 'all' && permission_exists('user_all')) { echo th_order_by('domain_name', $text['label-domain'], $order_by, $order); } echo th_order_by('username', $text['label-username'], $order_by, $order); echo th_order_by('groups', $text['label-groups'], $order_by, $order); if (permission_exists('contact_view')) { echo th_order_by('contact_organization', $text['label-organization'], $order_by, $order); echo th_order_by('contact_name', $text['label-name'], $order_by, $order); //echo th_order_by('contact_name_family', $text['label-contact_name_family'], $order_by, $order); } //echo th_order_by('user_status', $text['label-user_status'], $order_by, $order); //echo th_order_by('add_date', $text['label-add_date'], $order_by, $order); echo th_order_by('user_enabled', $text['label-user_enabled'], $order_by, $order, null, "class='center'"); if (permission_exists('user_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') { echo " \n"; } echo "\n"; if (is_array($users) && @sizeof($users) != 0) { $x = 0; foreach ($users as $row) { if (permission_exists('user_edit')) { $list_row_url = "user_edit.php?id=".urlencode($row['user_uuid']); } echo "\n"; if (permission_exists('user_add') || permission_exists('user_edit') || permission_exists('user_delete')) { echo " \n"; } if ($_GET['show'] == 'all' && permission_exists('user_all')) { echo " \n"; } echo " \n"; echo " \n"; if (permission_exists('contact_view')) { echo " \n"; echo " \n"; //echo " \n"; //echo " \n"; } //echo " \n"; //echo " \n"; if (permission_exists('user_edit')) { echo " \n"; if (permission_exists('user_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') { echo " \n"; } echo "\n"; $x++; } unset($users); } echo "
\n"; echo " \n"; echo "  
\n"; echo " \n"; echo " \n"; echo " ".escape($_SESSION['domains'][$row['domain_uuid']]['domain_name'])."\n"; if (permission_exists('user_edit')) { echo " ".escape($row['username'])."\n"; } else { echo " ".escape($row['username']); } echo " ".escape($row['groups'])."".escape($row['contact_organization'])."".escape($row['contact_name'])."".escape($row['contact_name_given'])."".escape($row['contact_name_family'])."".escape($row['user_status'])."".escape($row['add_date'])."\n"; echo $text['label-'.$row['user_enabled']]; } echo " \n"; echo button::create(['type'=>'button','title'=>$text['button-edit'],'icon'=>$_SESSION['theme']['button_icon_edit'],'link'=>$list_row_url]); echo "
\n"; echo "
\n"; echo "
".$paging_controls."
\n"; echo "\n"; echo "
\n"; //include the footer require_once "resources/footer.php"; ?>