| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339 |
- <?php
- /*
- FusionPBX
- Version: MPL 1.1
- The contents of this file are subject to the Mozilla Public License Version
- 1.1 (the "License"); you may not use this file except in compliance with
- the License. You may obtain a copy of the License at
- http://www.mozilla.org/MPL/
- Software distributed under the License is distributed on an "AS IS" basis,
- WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
- for the specific language governing rights and limitations under the
- License.
- The Original Code is FusionPBX
- The Initial Developer of the Original Code is
- Mark J Crane <[email protected]>
- Portions created by the Initial Developer are Copyright (C) 2008-2024
- the Initial Developer. All Rights Reserved.
- Contributor(s):
- Mark J Crane <[email protected]>
- */
- //includes files
- require_once dirname(__DIR__, 2) . "/resources/require.php";
- require_once "resources/check_auth.php";
- require_once "resources/paging.php";
- //check permissions
- if (permission_exists('user_view')) {
- //access granted
- }
- else {
- echo "access denied";
- exit;
- }
- //connect to the database
- $database = new database;
- //add multi-lingual support
- $language = new text;
- $text = $language->get();
- //get the http post data
- if (!empty($_POST['users'])) {
- $action = $_POST['action'] ?? '';
- $search = $_POST['search'] ?? '';
- $users = $_POST['users'] ?? '';
- }
- //check to see if contact details are in the view
- $sql = "select * from view_users ";
- $sql .= "where domain_uuid = :domain_uuid ";
- $parameters = null;
- $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
- $row = $database->select($sql, $parameters, 'row');
- if (isset($row['contact_organization'])) {
- $show_contact_fields = true;
- }
- else {
- $show_contact_fields = false;
- }
- unset($parameters);
- //process the http post data by action
- if (!empty($action) && is_array($users) && @sizeof($users) != 0) {
- switch ($action) {
- case 'copy':
- if (permission_exists('user_add')) {
- $obj = new users;
- $obj->copy($users);
- }
- break;
- case 'toggle':
- if (permission_exists('user_edit')) {
- $obj = new users;
- $obj->toggle($users);
- }
- break;
- case 'delete':
- if (permission_exists('user_delete')) {
- $obj = new users;
- $obj->delete($users);
- }
- break;
- }
- header('Location: users.php'.($search != '' ? '?search='.urlencode($search) : null));
- exit;
- }
- //get order and order by
- $order_by = $_GET["order_by"] ?? '';
- $order = $_GET["order"] ?? '';
- //set additional variables
- $context = !empty($_GET["context"]) ? $_GET["context"] : '';
- $search = !empty($_GET["search"]) ? $_GET["search"] : '';
- $show = !empty($_GET["show"]) ? $_GET["show"] : '';
- //set from session variables
- $list_row_edit_button = !empty($_SESSION['theme']['list_row_edit_button']['boolean']) ? $_SESSION['theme']['list_row_edit_button']['boolean'] : 'false';
- //add the search string
- if (!empty($search)) {
- $search = strtolower($_GET["search"]);
- $sql_search = " (";
- $sql_search .= " lower(username) like :search ";
- $sql_search .= " or lower(group_names) like :search ";
- $sql_search .= " or lower(contact_organization) like :search ";
- $sql_search .= " or lower(contact_name) like :search ";
- //$sql_search .= " or lower(user_status) like :search ";
- $sql_search .= ") ";
- $parameters['search'] = '%'.$search.'%';
- }
- //get the count
- $sql = "select count(*) from view_users ";
- if ($show == "all" && permission_exists('user_all')) {
- if (isset($sql_search)) {
- $sql .= "where ".$sql_search;
- }
- else {
- $sql.= "where true ";
- }
- }
- else {
- $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) ";
- if (!empty($sql_search)) {
- $sql .= "and ".$sql_search;
- }
- $parameters['domain_uuid'] = $domain_uuid;
- }
- $sql .= "and ( ";
- $sql .= " group_level <= :group_level ";
- $sql .= " or group_level is null ";
- $sql .= ") ";
- $parameters['group_level'] = $_SESSION['user']['group_level'];
- $num_rows = $database->select($sql, $parameters, 'column');
- //prepare to page the results
- $rows_per_page = ($_SESSION['domain']['paging']['numeric'] != '') ? $_SESSION['domain']['paging']['numeric'] : 50;
- $param = $search ? "&search=".$search : null;
- $param .= ($show == 'all' && permission_exists('user_all')) ? "&show=all" : null;
- $page = !empty($_GET['page']) ? $_GET['page'] : 0;
- list($paging_controls, $rows_per_page) = paging($num_rows, $param, $rows_per_page);
- list($paging_controls_mini, $rows_per_page) = paging($num_rows, $param, $rows_per_page, true);
- $offset = $rows_per_page * $page;
- //get the list
- $sql = "select domain_name, domain_uuid, user_uuid, username, group_names, ";
- if ($show_contact_fields) {
- $sql .= "contact_organization,contact_name, ";
- }
- $sql .= "cast(user_enabled as text) ";
- $sql .= "from view_users ";
- if ($show == "all" && permission_exists('user_all')) {
- if (isset($sql_search)) {
- $sql .= "where ".$sql_search;
- }
- else {
- $sql.= "where true ";
- }
- }
- else {
- $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) ";
- if (isset($sql_search)) {
- $sql .= "and ".$sql_search;
- }
- $parameters['domain_uuid'] = $domain_uuid;
- }
- $sql .= "and ( ";
- $sql .= " group_level <= :group_level ";
- $sql .= " or group_level is null ";
- $sql .= ") ";
- $parameters['group_level'] = $_SESSION['user']['group_level'];
- $sql .= order_by($order_by, $order, 'username', 'asc');
- $sql .= limit_offset($rows_per_page, $offset);
- $users = $database->select($sql, $parameters, 'all');
- unset($sql, $parameters);
- //create token
- $object = new token;
- $token = $object->create($_SERVER['PHP_SELF']);
- //include the header
- $document['title'] = $text['title-users'];
- require_once "resources/header.php";
- //show the content
- echo "<div class='action_bar' id='action_bar'>\n";
- echo " <div class='heading'><b>".$text['title-users']."</b><div class='count'>".number_format($num_rows)."</div></div>\n";
- echo " <div class='actions'>\n";
- if (permission_exists('user_add')) {
- if (!isset($id)) {
- echo button::create(['type'=>'button','label'=>$text['button-import'],'icon'=>$_SESSION['theme']['button_icon_import'],'style'=>'margin-right: 15px;','link'=>'user_imports.php']);
- }
- echo button::create(['type'=>'button','label'=>$text['button-add'],'icon'=>$_SESSION['theme']['button_icon_add'],'id'=>'btn_add','link'=>'user_edit.php']);
- }
- if (permission_exists('user_add') && $users) {
- echo button::create(['type'=>'button','label'=>$text['button-copy'],'icon'=>$_SESSION['theme']['button_icon_copy'],'id'=>'btn_copy','name'=>'btn_copy','style'=>'display: none;','onclick'=>"modal_open('modal-copy','btn_copy');"]);
- }
- if (permission_exists('user_edit') && $users) {
- echo button::create(['type'=>'button','label'=>$text['button-toggle'],'icon'=>$_SESSION['theme']['button_icon_toggle'],'id'=>'btn_toggle','name'=>'btn_toggle','style'=>'display: none;','onclick'=>"modal_open('modal-toggle','btn_toggle');"]);
- }
- if (permission_exists('user_delete') && $users) {
- echo button::create(['type'=>'button','label'=>$text['button-delete'],'icon'=>$_SESSION['theme']['button_icon_delete'],'id'=>'btn_delete','name'=>'btn_delete','style'=>'display: none;','onclick'=>"modal_open('modal-delete','btn_delete');"]);
- }
- echo "<form id='form_search' class='inline' method='get'>\n";
- if (permission_exists('user_all')) {
- if ($show == 'all') {
- echo " <input type='hidden' name='show' value='all'>\n";
- }
- else {
- echo button::create(['type'=>'button','label'=>$text['button-show_all'],'icon'=>$_SESSION['theme']['button_icon_all'],'link'=>'?show=all']);
- }
- }
- echo "<input type='text' class='txt list-search' name='search' id='search' value=\"".escape($search)."\" placeholder=\"".$text['label-search']."\" onkeydown=''>";
- echo button::create(['label'=>$text['button-search'],'icon'=>$_SESSION['theme']['button_icon_search'],'type'=>'submit','id'=>'btn_search']);
- //echo button::create(['label'=>$text['button-reset'],'icon'=>$_SESSION['theme']['button_icon_reset'],'type'=>'button','id'=>'btn_reset','link'=>'users.php','style'=>($search == '' ? 'display: none;' : null)]);
- if ($paging_controls_mini != '') {
- echo "<span style='margin-left: 15px;'>".$paging_controls_mini."</span>\n";
- }
- echo " </form>\n";
- echo " </div>\n";
- echo " <div style='clear: both;'></div>\n";
- echo "</div>\n";
- if (permission_exists('user_add') && $users) {
- echo modal::create(['id'=>'modal-copy','type'=>'copy','actions'=>button::create(['type'=>'button','label'=>$text['button-continue'],'icon'=>'check','id'=>'btn_copy','style'=>'float: right; margin-left: 15px;','collapse'=>'never','onclick'=>"modal_close(); list_action_set('copy'); list_form_submit('form_list');"])]);
- }
- if (permission_exists('user_edit') && $users) {
- echo modal::create(['id'=>'modal-toggle','type'=>'toggle','actions'=>button::create(['type'=>'button','label'=>$text['button-continue'],'icon'=>'check','id'=>'btn_toggle','style'=>'float: right; margin-left: 15px;','collapse'=>'never','onclick'=>"modal_close(); list_action_set('toggle'); list_form_submit('form_list');"])]);
- }
- if (permission_exists('user_delete') && $users) {
- echo modal::create(['id'=>'modal-delete','type'=>'delete','actions'=>button::create(['type'=>'button','label'=>$text['button-continue'],'icon'=>'check','id'=>'btn_delete','style'=>'float: right; margin-left: 15px;','collapse'=>'never','onclick'=>"modal_close(); list_action_set('delete'); list_form_submit('form_list');"])]);
- }
- echo $text['description-users']."\n";
- echo "<br /><br />\n";
- echo "<form id='form_list' method='post'>\n";
- echo "<input type='hidden' id='action' name='action' value=''>\n";
- echo "<input type='hidden' name='search' value=\"".escape($search)."\">\n";
- echo "<div class='card'>\n";
- echo "<table class='list'>\n";
- echo "<tr class='list-header'>\n";
- if (permission_exists('user_add') || permission_exists('user_edit') || permission_exists('user_delete')) {
- echo " <th class='checkbox'>\n";
- echo " <input type='checkbox' id='checkbox_all' name='checkbox_all' onclick='list_all_toggle(); checkbox_on_change(this);' ".(!empty($users) ?: "style='visibility: hidden;'").">\n";
- echo " </th>\n";
- }
- if ($show == 'all' && permission_exists('user_all')) {
- echo th_order_by('domain_name', $text['label-domain'], $order_by, $order, null, null, $param);
- }
- echo th_order_by('username', $text['label-username'], $order_by, $order, null, null, $param);
- echo th_order_by('group_names', $text['label-groups'], $order_by, $order, null, null, $param);
- if ($show_contact_fields) {
- echo th_order_by('contact_organization', $text['label-organization'], $order_by, $order, null, null, $param);
- echo th_order_by('contact_name', $text['label-name'], $order_by, $order, null, null, $param);
- }
- //echo th_order_by('contact_name_family', $text['label-contact_name_family'], $order_by, $order);
- //echo th_order_by('user_status', $text['label-user_status'], $order_by, $order);
- //echo th_order_by('add_date', $text['label-add_date'], $order_by, $order);
- echo th_order_by('user_enabled', $text['label-user_enabled'], $order_by, $order, null, "class='center'", $param);
- if (permission_exists('user_edit') && $list_row_edit_button == 'true') {
- echo " <td class='action-button'> </td>\n";
- }
- echo "</tr>\n";
- if (is_array($users) && @sizeof($users) != 0) {
- $x = 0;
- foreach ($users as $row) {
- if (permission_exists('user_edit')) {
- $list_row_url = "user_edit.php?id=".urlencode($row['user_uuid']);
- }
- echo "<tr class='list-row' href='".$list_row_url."'>\n";
- if (permission_exists('user_add') || permission_exists('user_edit') || permission_exists('user_delete')) {
- echo " <td class='checkbox'>\n";
- echo " <input type='checkbox' name='users[$x][checked]' id='checkbox_".$x."' value='true' onclick=\"checkbox_on_change(this); if (!this.checked) { document.getElementById('checkbox_all').checked = false; }\">\n";
- echo " <input type='hidden' name='users[$x][uuid]' value='".escape($row['user_uuid'])."' />\n";
- echo " </td>\n";
- }
- if ($show == 'all' && permission_exists('user_all')) {
- echo " <td>".escape($_SESSION['domains'][$row['domain_uuid']]['domain_name'])."</td>\n";
- }
- echo " <td>\n";
- if (permission_exists('user_edit')) {
- echo " <a href='".$list_row_url."' title=\"".$text['button-edit']."\">".escape($row['username'])."</a>\n";
- }
- else {
- echo " ".escape($row['username']);
- }
- echo " </td>\n";
- echo " <td>".escape($row['group_names'])."</td>\n";
- if ($show_contact_fields) {
- echo " <td>".escape($row['contact_organization'])."</td>\n";
- echo " <td>".escape($row['contact_name'])."</td>\n";
- }
- //echo " <td>".escape($row['contact_name_given'])."</td>\n";
- //echo " <td>".escape($row['contact_name_family'])."</td>\n";
- //echo " <td>".escape($row['user_status'])."</td>\n";
- //echo " <td>".escape($row['add_date'])."</td>\n";
- if (permission_exists('user_edit')) {
- echo " <td class='no-link center'>\n";
- echo button::create(['type'=>'submit','class'=>'link','label'=>$text['label-'.$row['user_enabled']],'title'=>$text['button-toggle'],'onclick'=>"list_self_check('checkbox_".$x."'); list_action_set('toggle'); list_form_submit('form_list')"]);
- }
- else {
- echo " <td class='center'>\n";
- echo $text['label-'.$row['user_enabled']];
- }
- echo " </td>\n";
- if (permission_exists('user_edit') && $list_row_edit_button == 'true') {
- echo " <td class='action-button'>\n";
- echo button::create(['type'=>'button','title'=>$text['button-edit'],'icon'=>$_SESSION['theme']['button_icon_edit'],'link'=>$list_row_url]);
- echo " </td>\n";
- }
- echo "</tr>\n";
- $x++;
- }
- unset($users);
- }
- echo "</table>\n";
- echo "</div>\n";
- echo "<br />\n";
- echo "<div align='center'>".$paging_controls."</div>\n";
- echo "<input type='hidden' name='".$token['name']."' value='".$token['hash']."'>\n";
- echo "</form>\n";
- //include the footer
- require_once "resources/footer.php";
- ?>
|