user_edit.php 44 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073
  1. <?php
  2. /*
  3. FusionPBX
  4. Version: MPL 1.1
  5. The contents of this file are subject to the Mozilla Public License Version
  6. 1.1 (the "License"); you may not use this file except in compliance with
  7. the License. You may obtain a copy of the License at
  8. http://www.mozilla.org/MPL/
  9. Software distributed under the License is distributed on an "AS IS" basis,
  10. WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
  11. for the specific language governing rights and limitations under the
  12. License.
  13. The Original Code is FusionPBX
  14. The Initial Developer of the Original Code is
  15. Mark J Crane <[email protected]>
  16. Portions created by the Initial Developer are Copyright (C) 2008-2020
  17. the Initial Developer. All Rights Reserved.
  18. Contributor(s):
  19. Mark J Crane <[email protected]>
  20. Luis Daniel Lucio Quiroz <[email protected]>
  21. */
  22. //includes
  23. include "root.php";
  24. require_once "resources/require.php";
  25. require_once "resources/check_auth.php";
  26. //add multi-lingual support
  27. $language = new text;
  28. $text = $language->get();
  29. //get user uuid
  30. if ((is_uuid($_REQUEST["id"]) && permission_exists('user_edit')) || (is_uuid($_REQUEST["id"]) && $_REQUEST["id"] == $_SESSION['user_uuid'])) {
  31. $user_uuid = $_REQUEST["id"];
  32. $action = 'edit';
  33. }
  34. elseif (permission_exists('user_add') && !isset($_REQUEST["id"])) {
  35. $user_uuid = uuid();
  36. $action = 'add';
  37. }
  38. else {
  39. // load users own account
  40. header("Location: user_edit.php?id=".urlencode($_SESSION['user_uuid']));
  41. exit;
  42. }
  43. //get total user count from the database, check limit, if defined
  44. if (permission_exists('user_add') && $action == 'add' && $_SESSION['limit']['users']['numeric'] != '') {
  45. $sql = "select count(*) ";
  46. $sql .= "from v_users ";
  47. $sql .= "where domain_uuid = :domain_uuid ";
  48. $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
  49. $database = new database;
  50. $num_rows = $database->select($sql, $parameters, 'column');
  51. unset($sql, $parameters);
  52. if ($num_rows >= $_SESSION['limit']['users']['numeric']) {
  53. message::add($text['message-maximum_users'].' '.$_SESSION['limit']['users']['numeric'], 'negative');
  54. header('Location: users.php');
  55. exit;
  56. }
  57. }
  58. //required to be a superadmin to update an account that is a member of the superadmin group
  59. if (permission_exists('user_edit') && $action == 'edit') {
  60. $superadmins = superadmin_list();
  61. if (if_superadmin($superadmins, $user_uuid)) {
  62. if (!if_group("superadmin")) {
  63. echo "access denied";
  64. exit;
  65. }
  66. }
  67. }
  68. //delete the group from the user
  69. if ($_GET["a"] == "delete" && is_uuid($_GET["group_uuid"]) && is_uuid($user_uuid) && permission_exists("user_delete")) {
  70. //set the variables
  71. $group_uuid = $_GET["group_uuid"];
  72. //delete the group from the users
  73. $array['user_groups'][0]['group_uuid'] = $group_uuid;
  74. $array['user_groups'][0]['user_uuid'] = $user_uuid;
  75. $p = new permissions;
  76. $p->add('user_group_delete', 'temp');
  77. $database = new database;
  78. $database->app_name = 'users';
  79. $database->app_uuid = '112124b3-95c2-5352-7e9d-d14c0b88f207';
  80. $database->delete($array);
  81. unset($array);
  82. $p->delete('user_group_delete', 'temp');
  83. //redirect the user
  84. message::add($text['message-update']);
  85. header("Location: user_edit.php?id=".urlencode($user_uuid));
  86. exit;
  87. }
  88. //retrieve password requirements
  89. $required['length'] = $_SESSION['users']['password_length']['numeric'];
  90. $required['number'] = ($_SESSION['users']['password_number']['boolean'] == 'true') ? true : false;
  91. $required['lowercase'] = ($_SESSION['users']['password_lowercase']['boolean'] == 'true') ? true : false;
  92. $required['uppercase'] = ($_SESSION['users']['password_uppercase']['boolean'] == 'true') ? true : false;
  93. $required['special'] = ($_SESSION['users']['password_special']['boolean'] == 'true') ? true : false;
  94. //prepare the data
  95. if (count($_POST) > 0) {
  96. //get the HTTP values and set as variables
  97. if (permission_exists('user_edit') && $action == 'edit') {
  98. $user_uuid = $_REQUEST["id"];
  99. $username_old = $_POST["username_old"];
  100. }
  101. $domain_uuid = $_POST["domain_uuid"];
  102. $username = $_POST["username"];
  103. $password = $_POST["password"];
  104. $password_confirm = $_POST["password_confirm"];
  105. $user_email = $_POST["user_email"];
  106. $user_status = $_POST["user_status"];
  107. $user_language = $_POST["user_language"];
  108. $user_time_zone = $_POST["user_time_zone"];
  109. if (permission_exists('contact_add') && $action == 'edit') {
  110. $contact_uuid = $_POST["contact_uuid"];
  111. }
  112. else if (permission_exists('contact_add') && $action == 'add') {
  113. $contact_organization = $_POST["contact_organization"];
  114. $contact_name_given = $_POST["contact_name_given"];
  115. $contact_name_family = $_POST["contact_name_family"];
  116. }
  117. $group_uuid_name = $_POST["group_uuid_name"];
  118. $user_enabled = $_POST["user_enabled"];
  119. $api_key = $_POST["api_key"];
  120. if (permission_exists('message_view')) {
  121. $message_key = $_POST["message_key"];
  122. }
  123. //validate the token
  124. $token = new token;
  125. if (!$token->validate($_SERVER['PHP_SELF'])) {
  126. message::add($text['message-invalid_token'],'negative');
  127. header('Location: users.php');
  128. exit;
  129. }
  130. //check required values
  131. if ($username == '') {
  132. message::add($text['message-required'].$text['label-username'], 'negative', 7500);
  133. }
  134. if ((permission_exists('user_edit') && $action == 'edit' && $username != $username_old && $username != '') ||
  135. (permission_exists('user_add') && $action == 'add' && $username != '')) {
  136. $sql = "select count(*) from v_users where username = :username ";
  137. if ($_SESSION["users"]["unique"]["text"] != "global") {
  138. $sql .= "and domain_uuid = :domain_uuid ";
  139. $parameters['domain_uuid'] = $domain_uuid;
  140. }
  141. $parameters['username'] = $username;
  142. $database = new database;
  143. $num_rows = $database->select($sql, $parameters, 'column');
  144. if ($num_rows > 0) {
  145. message::add($text['message-username_exists'], 'negative', 7500);
  146. }
  147. unset($sql);
  148. }
  149. if ($password != '' && $password != $password_confirm) {
  150. message::add($text['message-password_mismatch'], 'negative', 7500);
  151. }
  152. if (permission_exists('user_add') && $action == 'add') {
  153. if ($password == '') {
  154. message::add($text['message-password_blank'], 'negative', 7500);
  155. }
  156. if ($user_email == '') {
  157. message::add($text['message-required'].$text['label-email'], 'negative', 7500);
  158. }
  159. if ($group_uuid_name == '') {
  160. message::add($text['message-required'].$text['label-group'], 'negative', 7500);
  161. }
  162. }
  163. if (strlen($password) > 0) {
  164. if (is_numeric($required['length']) && $required['length'] != 0) {
  165. if (strlen($password) < $required['length']) {
  166. message::add($text['message-required'].$text['label-characters'], 'negative', 7500);
  167. }
  168. }
  169. if ($required['number']) {
  170. if (!preg_match('/(?=.*[\d])/', $password)) {
  171. message::add($text['message-required'].$text['label-numbers'], 'negative', 7500);
  172. }
  173. }
  174. if ($required['lowercase']) {
  175. if (!preg_match('/(?=.*[a-z])/', $password)) {
  176. message::add($text['message-required'].$text['label-lowercase_letters'], 'negative', 7500);
  177. }
  178. }
  179. if ($required['uppercase']) {
  180. if (!preg_match('/(?=.*[A-Z])/', $password)) {
  181. message::add($text['message-required'].$text['label-uppercase_letters'], 'negative', 7500);
  182. }
  183. }
  184. if ($required['special']) {
  185. if (!preg_match('/(?=.*[\W])/', $password)) {
  186. message::add($text['message-required'].$text['label-special_characters'], 'negative', 7500);
  187. }
  188. }
  189. }
  190. //return if error
  191. if (message::count() != 0) {
  192. header("Location: user_edit.php".(permission_exists('user_edit') && $action != 'add' ? "?id=".urlencode($user_uuid) : null));
  193. exit;
  194. }
  195. //save the data
  196. $i = $n = $x = $c = 0; //set initial array indexes
  197. //check to see if user language is set
  198. $sql = "select user_setting_uuid, user_setting_value from v_user_settings ";
  199. $sql .= "where user_setting_category = 'domain' ";
  200. $sql .= "and user_setting_subcategory = 'language' ";
  201. $sql .= "and user_uuid = :user_uuid ";
  202. $parameters['user_uuid'] = $user_uuid;
  203. $database = new database;
  204. $row = $database->select($sql, $parameters, 'row');
  205. if (!is_uuid($row['user_setting_uuid']) && $user_language != '') {
  206. //add user setting to array for insert
  207. $array['user_settings'][$i]['user_setting_uuid'] = uuid();
  208. $array['user_settings'][$i]['user_uuid'] = $user_uuid;
  209. $array['user_settings'][$i]['domain_uuid'] = $domain_uuid;
  210. $array['user_settings'][$i]['user_setting_category'] = 'domain';
  211. $array['user_settings'][$i]['user_setting_subcategory'] = 'language';
  212. $array['user_settings'][$i]['user_setting_name'] = 'code';
  213. $array['user_settings'][$i]['user_setting_value'] = $user_language;
  214. $array['user_settings'][$i]['user_setting_enabled'] = 'true';
  215. $i++;
  216. }
  217. else {
  218. if ($row['user_setting_value'] == '' || $user_language == '') {
  219. $array_delete['user_settings'][0]['user_setting_category'] = 'domain';
  220. $array_delete['user_settings'][0]['user_setting_subcategory'] = 'language';
  221. $array_delete['user_settings'][0]['user_uuid'] = $user_uuid;
  222. $p = new permissions;
  223. $p->add('user_setting_delete', 'temp');
  224. $database = new database;
  225. $database->app_name = 'users';
  226. $database->app_uuid = '112124b3-95c2-5352-7e9d-d14c0b88f207';
  227. $database->delete($array_delete);
  228. unset($array_delete);
  229. $p->delete('user_setting_delete', 'temp');
  230. }
  231. else {
  232. //add user setting to array for update
  233. $array['user_settings'][$i]['user_setting_uuid'] = $row['user_setting_uuid'];
  234. $array['user_settings'][$i]['user_uuid'] = $user_uuid;
  235. $array['user_settings'][$i]['domain_uuid'] = $domain_uuid;
  236. $array['user_settings'][$i]['user_setting_category'] = 'domain';
  237. $array['user_settings'][$i]['user_setting_subcategory'] = 'language';
  238. $array['user_settings'][$i]['user_setting_name'] = 'code';
  239. $array['user_settings'][$i]['user_setting_value'] = $user_language;
  240. $array['user_settings'][$i]['user_setting_enabled'] = 'true';
  241. $i++;
  242. }
  243. }
  244. unset($sql, $parameters, $row);
  245. //check to see if user time zone is set
  246. $sql = "select user_setting_uuid, user_setting_value from v_user_settings ";
  247. $sql .= "where user_setting_category = 'domain' ";
  248. $sql .= "and user_setting_subcategory = 'time_zone' ";
  249. $sql .= "and user_uuid = :user_uuid ";
  250. $parameters['user_uuid'] = $user_uuid;
  251. $database = new database;
  252. $row = $database->select($sql, $parameters, 'row');
  253. if ($row['user_setting_uuid'] == '' && $user_time_zone != '') {
  254. //add user setting to array for insert
  255. $array['user_settings'][$i]['user_setting_uuid'] = uuid();
  256. $array['user_settings'][$i]['user_uuid'] = $user_uuid;
  257. $array['user_settings'][$i]['domain_uuid'] = $domain_uuid;
  258. $array['user_settings'][$i]['user_setting_category'] = 'domain';
  259. $array['user_settings'][$i]['user_setting_subcategory'] = 'time_zone';
  260. $array['user_settings'][$i]['user_setting_name'] = 'name';
  261. $array['user_settings'][$i]['user_setting_value'] = $user_time_zone;
  262. $array['user_settings'][$i]['user_setting_enabled'] = 'true';
  263. $i++;
  264. }
  265. else {
  266. if ($row['user_setting_value'] == '' || $user_time_zone == '') {
  267. $array_delete['user_settings'][0]['user_setting_category'] = 'domain';
  268. $array_delete['user_settings'][0]['user_setting_subcategory'] = 'time_zone';
  269. $array_delete['user_settings'][0]['user_uuid'] = $user_uuid;
  270. $p = new permissions;
  271. $p->add('user_setting_delete', 'temp');
  272. $database = new database;
  273. $database->app_name = 'users';
  274. $database->app_uuid = '112124b3-95c2-5352-7e9d-d14c0b88f207';
  275. $database->delete($array_delete);
  276. unset($array_delete);
  277. $p->delete('user_setting_delete', 'temp');
  278. }
  279. else {
  280. //add user setting to array for update
  281. $array['user_settings'][$i]['user_setting_uuid'] = $row['user_setting_uuid'];
  282. $array['user_settings'][$i]['user_uuid'] = $user_uuid;
  283. $array['user_settings'][$i]['domain_uuid'] = $domain_uuid;
  284. $array['user_settings'][$i]['user_setting_category'] = 'domain';
  285. $array['user_settings'][$i]['user_setting_subcategory'] = 'time_zone';
  286. $array['user_settings'][$i]['user_setting_name'] = 'name';
  287. $array['user_settings'][$i]['user_setting_value'] = $user_time_zone;
  288. $array['user_settings'][$i]['user_setting_enabled'] = 'true';
  289. $i++;
  290. }
  291. }
  292. unset($sql, $parameters, $row);
  293. //check to see if message key is set
  294. if (permission_exists('message_view')) {
  295. $sql = "select user_setting_uuid, user_setting_value from v_user_settings ";
  296. $sql .= "where user_setting_category = 'message' ";
  297. $sql .= "and user_setting_subcategory = 'key' ";
  298. $sql .= "and user_uuid = :user_uuid ";
  299. $parameters['user_uuid'] = $user_uuid;
  300. $database = new database;
  301. $row = $database->select($sql, $parameters, 'row');
  302. if ($row['user_setting_uuid'] == '' && $message_key != '') {
  303. //add user setting to array for insert
  304. $array['user_settings'][$i]['user_setting_uuid'] = uuid();
  305. $array['user_settings'][$i]['user_uuid'] = $user_uuid;
  306. $array['user_settings'][$i]['domain_uuid'] = $domain_uuid;
  307. $array['user_settings'][$i]['user_setting_category'] = 'message';
  308. $array['user_settings'][$i]['user_setting_subcategory'] = 'key';
  309. $array['user_settings'][$i]['user_setting_name'] = 'text';
  310. $array['user_settings'][$i]['user_setting_value'] = $message_key;
  311. $array['user_settings'][$i]['user_setting_enabled'] = 'true';
  312. $i++;
  313. }
  314. else {
  315. if ($row['user_setting_value'] == '' || $message_key == '') {
  316. $array_delete['user_settings'][0]['user_setting_category'] = 'message';
  317. $array_delete['user_settings'][0]['user_setting_subcategory'] = 'key';
  318. $array_delete['user_settings'][0]['user_uuid'] = $user_uuid;
  319. $p = new permissions;
  320. $p->add('user_setting_delete', 'temp');
  321. $database = new database;
  322. $database->app_name = 'users';
  323. $database->app_uuid = '112124b3-95c2-5352-7e9d-d14c0b88f207';
  324. $database->delete($array_delete);
  325. unset($array_delete);
  326. $p->delete('user_setting_delete', 'temp');
  327. }
  328. else {
  329. //add user setting to array for update
  330. $array['user_settings'][$i]['user_setting_uuid'] = $row['user_setting_uuid'];
  331. $array['user_settings'][$i]['user_uuid'] = $user_uuid;
  332. $array['user_settings'][$i]['domain_uuid'] = $domain_uuid;
  333. $array['user_settings'][$i]['user_setting_category'] = 'message';
  334. $array['user_settings'][$i]['user_setting_subcategory'] = 'key';
  335. $array['user_settings'][$i]['user_setting_name'] = 'text';
  336. $array['user_settings'][$i]['user_setting_value'] = $message_key;
  337. $array['user_settings'][$i]['user_setting_enabled'] = 'true';
  338. $i++;
  339. }
  340. }
  341. }
  342. //assign the user to the group
  343. if ((permission_exists('user_add') || permission_exists('user_edit')) && $_REQUEST["group_uuid_name"] != '') {
  344. $group_data = explode('|', $group_uuid_name);
  345. $group_uuid = $group_data[0];
  346. $group_name = $group_data[1];
  347. //compare the group level to only add groups at the same level or lower than the user
  348. $sql = "select * from v_groups ";
  349. $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) ";
  350. $sql .= "and group_uuid = :group_uuid ";
  351. $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
  352. $parameters['group_uuid'] = $group_uuid;
  353. $database = new database;
  354. $row = $database->select($sql, $parameters, 'row');
  355. if ($row['group_level'] <= $_SESSION['user']['group_level']) {
  356. $array['user_groups'][$n]['user_group_uuid'] = uuid();
  357. $array['user_groups'][$n]['domain_uuid'] = $domain_uuid;
  358. $array['user_groups'][$n]['group_name'] = $group_name;
  359. $array['user_groups'][$n]['group_uuid'] = $group_uuid;
  360. $array['user_groups'][$n]['user_uuid'] = $user_uuid;
  361. $n++;
  362. }
  363. unset($parameters);
  364. }
  365. //update domain, if changed
  366. if ((permission_exists('user_add') || permission_exists('user_edit')) && permission_exists('user_domain')) {
  367. //adjust group user records
  368. $sql = "select user_group_uuid from v_user_groups ";
  369. $sql .= "where user_uuid = :user_uuid ";
  370. $parameters['user_uuid'] = $user_uuid;
  371. $database = new database;
  372. $result = $database->select($sql, $parameters, 'all');
  373. if (is_array($result)) {
  374. foreach ($result as $row) {
  375. //add group user to array for update
  376. $array['user_groups'][$n]['user_group_uuid'] = $row['user_group_uuid'];
  377. $array['user_groups'][$n]['domain_uuid'] = $domain_uuid;
  378. $n++;
  379. }
  380. }
  381. unset($sql, $parameters);
  382. //adjust user setting records
  383. $sql = "select user_setting_uuid from v_user_settings ";
  384. $sql .= "where user_uuid = :user_uuid ";
  385. $parameters['user_uuid'] = $user_uuid;
  386. $database = new database;
  387. $result = $database->select($sql, $parameters);
  388. if (is_array($result)) {
  389. foreach ($result as $row) {
  390. //add user setting to array for update
  391. $array['user_settings'][$i]['user_setting_uuid'] = $row['user_setting_uuid'];
  392. $array['user_settings'][$i]['domain_uuid'] = $domain_uuid;
  393. $i++;
  394. }
  395. }
  396. unset($sql, $parameters);
  397. //unassign any foreign domain groups
  398. $sql = "delete from v_user_groups ";
  399. $sql .= "where domain_uuid = :domain_uuid ";
  400. $sql .= "and user_uuid = :user_uuid ";
  401. $sql .= "and group_uuid not in (";
  402. $sql .= " select group_uuid from v_groups where domain_uuid = :domain_uuid or domain_uuid is null ";
  403. $sql .= ") ";
  404. $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
  405. $parameters['user_uuid'] = $user_uuid;
  406. $database = new database;
  407. $database->execute($sql, $parameters);
  408. unset($sql, $parameters);
  409. }
  410. //add contact to array for insert
  411. if ($action == 'add' && permission_exists('user_add') && permission_exists('contact_add')) {
  412. $contact_uuid = uuid();
  413. $array['contacts'][$c]['domain_uuid'] = $domain_uuid;
  414. $array['contacts'][$c]['contact_uuid'] = $contact_uuid;
  415. $array['contacts'][$c]['contact_type'] = 'user';
  416. $array['contacts'][$c]['contact_organization'] = $contact_organization;
  417. $array['contacts'][$c]['contact_name_given'] = $contact_name_given;
  418. $array['contacts'][$c]['contact_name_family'] = $contact_name_family;
  419. $array['contacts'][$c]['contact_nickname'] = $username;
  420. $c++;
  421. if (permission_exists('contact_email_add')) {
  422. $contact_email_uuid = uuid();
  423. $array['contact_emails'][$c]['contact_email_uuid'] = $contact_email_uuid;
  424. $array['contact_emails'][$c]['domain_uuid'] = $domain_uuid;
  425. $array['contact_emails'][$c]['contact_uuid'] = $contact_uuid;
  426. $array['contact_emails'][$c]['email_address'] = $user_email;
  427. $array['contact_emails'][$c]['email_primary'] = '1';
  428. $c++;
  429. }
  430. }
  431. //add user setting to array for update
  432. $array['users'][$x]['user_uuid'] = $user_uuid;
  433. $array['users'][$x]['domain_uuid'] = $domain_uuid;
  434. if ($username != '' && $username != $username_old) {
  435. $array['users'][$x]['username'] = $username;
  436. }
  437. if ($password != '' && $password == $password_confirm) {
  438. $salt = uuid();
  439. $array['users'][$x]['password'] = md5($salt.$password);
  440. $array['users'][$x]['salt'] = $salt;
  441. }
  442. $array['users'][$x]['user_email'] = $user_email;
  443. $array['users'][$x]['user_status'] = $user_status;
  444. if (permission_exists('user_add') || permission_exists('user_edit')) {
  445. $array['users'][$x]['api_key'] = ($api_key != '') ? $api_key : null;
  446. $array['users'][$x]['user_enabled'] = $user_enabled;
  447. if (permission_exists('contact_add')) {
  448. $array['users'][$x]['contact_uuid'] = ($contact_uuid != '') ? $contact_uuid : null;
  449. }
  450. if ($action == 'add') {
  451. $array['users'][$x]['add_user'] = $_SESSION["user"]["username"];
  452. $array['users'][$x]['add_date'] = date("Y-m-d H:i:s.uO");
  453. }
  454. }
  455. $x++;
  456. //add the user_edit permission
  457. $p = new permissions;
  458. $p->add("user_setting_add", "temp");
  459. $p->add("user_setting_edit", "temp");
  460. $p->add("user_edit", "temp");
  461. $p->add('user_group_add', 'temp');
  462. //save the data
  463. $database = new database;
  464. $database->app_name = 'users';
  465. $database->app_uuid = '112124b3-95c2-5352-7e9d-d14c0b88f207';
  466. $database->save($array);
  467. //$message = $database->message;
  468. //remove the temporary permission
  469. $p->delete("user_setting_add", "temp");
  470. $p->delete("user_setting_edit", "temp");
  471. $p->delete("user_edit", "temp");
  472. $p->delete('user_group_add', 'temp');
  473. //if call center installed
  474. if ($action == 'edit' && permission_exists('user_edit') && file_exists($_SERVER["PROJECT_ROOT"]."/app/call_centers/app_config.php")) {
  475. //get the call center agent uuid
  476. $sql = "select call_center_agent_uuid from v_call_center_agents ";
  477. $sql .= "where domain_uuid = :domain_uuid ";
  478. $sql .= "and user_uuid = :user_uuid ";
  479. $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
  480. $parameters['user_uuid'] = $user_uuid;
  481. $database = new database;
  482. $call_center_agent_uuid = $database->select($sql, $parameters, 'column');
  483. unset($sql, $parameters);
  484. //update the user_status
  485. if (isset($call_center_agent_uuid) && is_uuid($call_center_agent_uuid)) {
  486. $fp = event_socket_create($_SESSION['event_socket_ip_address'], $_SESSION['event_socket_port'], $_SESSION['event_socket_password']);
  487. $switch_cmd .= "callcenter_config agent set status ".$call_center_agent_uuid." '".$user_status."'";
  488. $switch_result = event_socket_request($fp, 'api '.$switch_cmd);
  489. }
  490. //update the user state
  491. if (isset($call_center_agent_uuid) && is_uuid($call_center_agent_uuid)) {
  492. $cmd = "api callcenter_config agent set state ".$call_center_agent_uuid." Waiting";
  493. $response = event_socket_request($fp, $cmd);
  494. }
  495. }
  496. //response message
  497. if ($action == 'edit') {
  498. message::add($text['message-update'],'positive');
  499. }
  500. else {
  501. message::add($text['message-add'],'positive');
  502. }
  503. header("Location: user_edit.php?id=".urldecode($user_uuid));
  504. exit;
  505. }
  506. //populate the form with values from db
  507. if ($action == 'edit') {
  508. $sql = "select * from v_users where user_uuid = :user_uuid ";
  509. if (!permission_exists('user_all')) {
  510. $sql .= "and domain_uuid = :domain_uuid ";
  511. $parameters['domain_uuid'] = $domain_uuid;
  512. }
  513. $parameters['user_uuid'] = $user_uuid;
  514. $database = new database;
  515. $row = $database->select($sql, $parameters, 'row');
  516. if (is_array($row) && sizeof($row) > 0) {
  517. $domain_uuid = $row["domain_uuid"];
  518. $user_uuid = $row["user_uuid"];
  519. $username = $row["username"];
  520. $user_email = $row["user_email"];
  521. $api_key = $row["api_key"];
  522. $user_enabled = $row["user_enabled"];
  523. if (permission_exists('contact_view')) {
  524. $contact_uuid = $row["contact_uuid"];
  525. }
  526. $user_status = $row["user_status"];
  527. }
  528. else {
  529. message::add($text['message-invalid_user'], 'negative', 7500);
  530. header("Location: user_edit.php?id=".$_SESSION['user_uuid']);
  531. exit;
  532. }
  533. unset($sql, $parameters, $row);
  534. //get user settings
  535. $sql = "select * from v_user_settings ";
  536. $sql .= "where user_uuid = :user_uuid ";
  537. $sql .= "and user_setting_enabled = 'true' ";
  538. $parameters['user_uuid'] = $user_uuid;
  539. $database = new database;
  540. $result = $database->select($sql, $parameters, 'all');
  541. if (is_array($result)) {
  542. foreach($result as $row) {
  543. $name = $row['user_setting_name'];
  544. $category = $row['user_setting_category'];
  545. $subcategory = $row['user_setting_subcategory'];
  546. if (strlen($subcategory) == 0) {
  547. //$$category[$name] = $row['domain_setting_value'];
  548. $user_settings[$category][$name] = $row['user_setting_value'];
  549. }
  550. else {
  551. $user_settings[$category][$subcategory][$name] = $row['user_setting_value'];
  552. }
  553. }
  554. }
  555. unset($sql, $parameters, $result, $row);
  556. }
  557. //create token
  558. $object = new token;
  559. $token = $object->create($_SERVER['PHP_SELF']);
  560. //include the header
  561. require_once "resources/header.php";
  562. $document['title'] = $text['title-user_edit'];
  563. //show the content
  564. echo "<script>\n";
  565. echo " function compare_passwords() {\n";
  566. echo " if (document.getElementById('password') === document.activeElement || document.getElementById('password_confirm') === document.activeElement) {\n";
  567. echo " if ($('#password').val() != '' || $('#password_confirm').val() != '') {\n";
  568. echo " if ($('#password').val() != $('#password_confirm').val()) {\n";
  569. echo " $('#password').removeClass('formfld_highlight_good');\n";
  570. echo " $('#password_confirm').removeClass('formfld_highlight_good');\n";
  571. echo " $('#password').addClass('formfld_highlight_bad');\n";
  572. echo " $('#password_confirm').addClass('formfld_highlight_bad');\n";
  573. echo " }\n";
  574. echo " else {\n";
  575. echo " $('#password').removeClass('formfld_highlight_bad');\n";
  576. echo " $('#password_confirm').removeClass('formfld_highlight_bad');\n";
  577. echo " $('#password').addClass('formfld_highlight_good');\n";
  578. echo " $('#password_confirm').addClass('formfld_highlight_good');\n";
  579. echo " }\n";
  580. echo " }\n";
  581. echo " }\n";
  582. echo " else {\n";
  583. echo " $('#password').removeClass('formfld_highlight_bad');\n";
  584. echo " $('#password_confirm').removeClass('formfld_highlight_bad');\n";
  585. echo " $('#password').removeClass('formfld_highlight_good');\n";
  586. echo " $('#password_confirm').removeClass('formfld_highlight_good');\n";
  587. echo " }\n";
  588. echo " }\n";
  589. echo " function show_strength_meter() {\n";
  590. echo " $('#pwstrength_progress').slideDown();\n";
  591. echo " }\n";
  592. echo "</script>\n";
  593. echo "<form name='frm' id='frm' method='post'>\n";
  594. echo "<div class='action_bar' id='action_bar'>\n";
  595. echo " <div class='heading'><b>".$text['header-user_edit']."</b></div>\n";
  596. echo " <div class='actions'>\n";
  597. if ($unsaved) {
  598. echo "<span style='color: #b00;'>".$text['message-unsaved_changes']." <i class='fas fa-exclamation-triangle' style='margin-right: 15px;'></i></span>";
  599. }
  600. if (permission_exists('user_add') || permission_exists('user_edit')) {
  601. echo button::create(['type'=>'button','label'=>$text['button-back'],'icon'=>$_SESSION['theme']['button_icon_back'],'style'=>'margin-right: 15px;','link'=>'users.php']);
  602. }
  603. if (permission_exists('ticket_add') || permission_exists('ticket_edit')) {
  604. echo button::create(['type'=>'button','label'=>$text['button-tickets'],'icon'=>'tags','style'=>'margin-right: 15px;','link'=>PROJECT_PATH.'/app/tickets/tickets.php?user_uuid='.urlencode($user_uuid)]);
  605. }
  606. echo button::create(['type'=>'submit','label'=>$text['button-save'],'icon'=>$_SESSION['theme']['button_icon_save']]);
  607. echo " </div>\n";
  608. echo " <div style='clear: both;'></div>\n";
  609. echo "</div>\n";
  610. echo $text['description-user_edit']."\n";
  611. echo "<br /><br />\n";
  612. echo "<table cellpadding='0' cellspacing='0' border='0' width='100%'>";
  613. echo " <tr>";
  614. echo " <td width='30%' class='vncellreq' valign='top'>".$text['label-username']."</td>";
  615. echo " <td width='70%' class='vtable'>";
  616. if (permission_exists("user_edit")) {
  617. echo " <input type='text' class='formfld' name='username' id='username' autocomplete='new-password' value='".escape($username)."' required='required'>\n";
  618. echo " <input type='text' style='display: none;' disabled='disabled'>\n"; //help defeat browser auto-fill
  619. }
  620. else {
  621. echo " ".escape($username)."\n";
  622. echo " <input type='hidden' name='username' id='username' autocomplete='new-password' value='".escape($username)."'>\n";
  623. }
  624. echo " </td>";
  625. echo " </tr>";
  626. echo " <tr>";
  627. echo " <td class='vncell".(($action == 'add') ? 'req' : null)."' valign='top'>".$text['label-password']."</td>";
  628. echo " <td class='vtable'>";
  629. echo " <input type='password' style='display: none;' disabled='disabled'>"; //help defeat browser auto-fill
  630. echo " <input type='password' autocomplete='new-password' class='formfld' name='password' id='password' value=\"".escape($password)."\" ".($action == 'add' ? "required='required'" : null)." onkeypress='show_strength_meter();' onfocus='compare_passwords();' onkeyup='compare_passwords();' onblur='compare_passwords();'>";
  631. echo " <div id='pwstrength_progress' class='pwstrength_progress'></div><br />\n";
  632. if ((is_numeric($required['length']) && $required['length'] != 0) || $required['number'] || $required['lowercase'] || $required['uppercase'] || $required['special']) {
  633. echo $text['label-required'].': ';
  634. if (is_numeric($required['length']) && $required['length'] != 0) {
  635. echo $required['length']." ".$text['label-characters'];
  636. if ($required['number'] || $required['lowercase'] || $required['uppercase'] || $required['special']) {
  637. echo " (";
  638. }
  639. }
  640. if ($required['number']) {
  641. $required_temp[] = $text['label-number'];
  642. }
  643. if ($required['lowercase']) {
  644. $required_temp[] = $text['label-lowercase'];
  645. }
  646. if ($required['uppercase']) {
  647. $required_temp[] = $text['label-uppercase'];
  648. }
  649. if ($required['special']) {
  650. $required_temp[] = $text['label-special'];
  651. }
  652. if (is_array($required_temp) && sizeof($required_temp) != 0) {
  653. echo implode(', ',$required_temp);
  654. if (is_numeric($required['length']) && $required['length'] != 0) {
  655. echo ")";
  656. }
  657. }
  658. unset($required_temp);
  659. }
  660. echo " </td>";
  661. echo " </tr>";
  662. echo " <tr>";
  663. echo " <td class='vncell".(($action == 'add') ? 'req' : null)."' valign='top'>".$text['label-confirm_password']."</td>";
  664. echo " <td class='vtable'>";
  665. echo " <input type='password' autocomplete='new-password' class='formfld' name='password_confirm' id='password_confirm' value=\"".escape($password_confirm)."\" ".($action == 'add' ? "required='required'" : null)." onfocus='compare_passwords();' onkeyup='compare_passwords();' onblur='compare_passwords();'><br />\n";
  666. echo " ".$text['message-green_border_passwords_match']."\n";
  667. echo " </td>";
  668. echo " </tr>";
  669. echo " <tr>";
  670. echo " <td class='vncellreq'>".$text['label-email']."</td>";
  671. echo " <td class='vtable'><input type='text' class='formfld' name='user_email' value='".escape($user_email)."' required='required'></td>";
  672. echo " </tr>";
  673. echo " <tr>\n";
  674. echo " <td width='20%' class=\"vncell\" valign='top'>\n";
  675. echo " ".$text['label-user_language']."\n";
  676. echo " </td>\n";
  677. echo " <td class=\"vtable\" align='left'>\n";
  678. echo " <select id='user_language' name='user_language' class='formfld' style=''>\n";
  679. echo " <option value=''></option>\n";
  680. //get all language codes from database
  681. $sql = "select * from v_languages order by language asc ";
  682. $database = new database;
  683. $languages = $database->select($sql, null, 'all');
  684. if (is_array($languages) && sizeof($languages) != 0) {
  685. foreach ($languages as $row) {
  686. $language_codes[$row["code"]] = $row["language"];
  687. }
  688. }
  689. unset($sql, $languages, $row);
  690. if (is_array($_SESSION['app']['languages']) && sizeof($_SESSION['app']['languages']) != 0) {
  691. foreach ($_SESSION['app']['languages'] as $code) {
  692. $selected = ($code == $user_settings['domain']['language']['code']) ? "selected='selected'" : null;
  693. echo " <option value='".$code."' ".$selected.">".escape($language_codes[$code])." [".escape($code)."]</option>\n";
  694. }
  695. }
  696. echo " </select>\n";
  697. echo " <br />\n";
  698. echo " ".$text['description-user_language']."<br />\n";
  699. echo " </td>\n";
  700. echo " </tr>\n";
  701. echo " <tr>\n";
  702. echo " <td width='20%' class=\"vncell\" valign='top'>\n";
  703. echo " ".$text['label-time_zone']."\n";
  704. echo " </td>\n";
  705. echo " <td class=\"vtable\" align='left'>\n";
  706. echo " <select id='user_time_zone' name='user_time_zone' class='formfld' style=''>\n";
  707. echo " <option value=''></option>\n";
  708. //$list = DateTimeZone::listAbbreviations();
  709. $time_zone_identifiers = DateTimeZone::listIdentifiers();
  710. $previous_category = '';
  711. $x = 0;
  712. foreach ($time_zone_identifiers as $key => $row) {
  713. $time_zone = explode("/", $row);
  714. $category = $time_zone[0];
  715. if ($category != $previous_category) {
  716. if ($x > 0) {
  717. echo " </optgroup>\n";
  718. }
  719. echo " <optgroup label='".$category."'>\n";
  720. }
  721. if ($row == $user_settings['domain']['time_zone']['name']) {
  722. echo " <option value='".escape($row)."' selected='selected'>".escape($row)."</option>\n";
  723. }
  724. else {
  725. echo " <option value='".escape($row)."'>".escape($row)."</option>\n";
  726. }
  727. $previous_category = $category;
  728. $x++;
  729. }
  730. echo " </select>\n";
  731. echo " <br />\n";
  732. echo " ".$text['description-time_zone']."<br />\n";
  733. echo " </td>\n";
  734. echo " </tr>\n";
  735. if ($_SESSION['user_status_display'] != "false") {
  736. echo " <tr>\n";
  737. echo " <td width='20%' class=\"vncell\" valign='top'>\n";
  738. echo " ".$text['label-status']."\n";
  739. echo " </td>\n";
  740. echo " <td class=\"vtable\">\n";
  741. $cmd = "'".PROJECT_PATH."/app/calls_active/v_calls_exec.php?cmd=callcenter_config+agent+set+status+".escape($username)."@".$_SESSION['domains'][$domain_uuid]['domain_name']."+'+this.value";
  742. echo " <select id='user_status' name='user_status' class='formfld' style='' onchange=\"send_cmd($cmd);\">\n";
  743. echo " <option value=''></option>\n";
  744. echo " <option value='Available' ".(($user_status == "Available") ? "selected='selected'" : null).">".$text['option-available']."</option>\n";
  745. echo " <option value='Available (On Demand)' ".(($user_status == "Available (On Demand)") ? "selected='selected'" : null).">".$text['option-available_on_demand']."</option>\n";
  746. echo " <option value='Logged Out' ".(($user_status == "Logged Out") ? "selected='selected'" : null).">".$text['option-logged_out']."</option>\n";
  747. echo " <option value='On Break' ".(($user_status == "On Break") ? "selected='selected'" : null).">".$text['option-on_break']."</option>\n";
  748. echo " <option value='Do Not Disturb' ".(($user_status == "Do Not Disturb") ? "selected='selected'" : null).">".$text['option-do_not_disturb']."</option>\n";
  749. echo " </select>\n";
  750. echo " <br />\n";
  751. echo " ".$text['description-status']."<br />\n";
  752. echo " </td>\n";
  753. echo " </tr>\n";
  754. }
  755. if ($action == 'edit' && permission_exists("user_edit") && permission_exists('contact_edit')) {
  756. echo " <tr>";
  757. echo " <td class='vncell' valign='top'>".$text['label-contact']."</td>";
  758. echo " <td class='vtable'>\n";
  759. $sql = "select ";
  760. $sql .= "c.contact_uuid, ";
  761. $sql .= "c.contact_organization, ";
  762. $sql .= "c.contact_name_given, ";
  763. $sql .= "c.contact_name_family, ";
  764. $sql .= "c.contact_nickname ";
  765. $sql .= "from ";
  766. $sql .= "v_contacts as c ";
  767. $sql .= "where ";
  768. $sql .= "c.domain_uuid = :domain_uuid ";
  769. $sql .= "and not exists ( ";
  770. $sql .= " select ";
  771. $sql .= " contact_uuid ";
  772. $sql .= " from ";
  773. $sql .= " v_users as u ";
  774. $sql .= " where ";
  775. $sql .= " u.domain_uuid = :domain_uuid ";
  776. if (is_uuid($contact_uuid)) { //don't exclude currently assigned contact
  777. $sql .= "and u.contact_uuid <> :contact_uuid ";
  778. $parameters['contact_uuid'] = $contact_uuid;
  779. }
  780. $sql .= " and u.contact_uuid = c.contact_uuid ";
  781. $sql .= ") ";
  782. $sql .= "order by ";
  783. $sql .= "lower(c.contact_organization) asc, ";
  784. $sql .= "lower(c.contact_name_family) asc, ";
  785. $sql .= "lower(c.contact_name_given) asc, ";
  786. $sql .= "lower(c.contact_nickname) asc ";
  787. $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
  788. $database = new database;
  789. $contacts = $database->select($sql, $parameters, 'all');
  790. unset($parameters);
  791. echo "<select name=\"contact_uuid\" id=\"contact_uuid\" class=\"formfld\">\n";
  792. echo "<option value=\"\"></option>\n";
  793. foreach($contacts as $row) {
  794. $contact_name = array();
  795. if ($row['contact_organization'] != '') { $contact_name[] = $row['contact_organization']; }
  796. if ($row['contact_name_family'] != '') { $contact_name[] = $row['contact_name_family']; }
  797. if ($row['contact_name_given'] != '') { $contact_name[] = $row['contact_name_given']; }
  798. if ($row['contact_name_family'] == '' && $row['contact_name_family'] == '' && $row['contact_nickname'] != '') { $contact_name[] = $row['contact_nickname']; }
  799. echo "<option value='".escape($row['contact_uuid'])."' ".(($row['contact_uuid'] == $contact_uuid) ? "selected='selected'" : null).">".escape(implode(', ', $contact_name))."</option>\n";
  800. }
  801. unset($sql, $row_count);
  802. echo "</select>\n";
  803. echo "<br />\n";
  804. echo $text['description-contact']."\n";
  805. if (strlen($contact_uuid) > 0) {
  806. echo " <a href=\"".PROJECT_PATH."/app/contacts/contact_edit.php?id=".urlencode($contact_uuid)."\">".$text['description-contact_view']."</a>\n";
  807. }
  808. echo " </td>";
  809. echo " </tr>";
  810. }
  811. elseif ($action == 'add' && permission_exists("user_add") && permission_exists('contact_add')) {
  812. echo " <tr>";
  813. echo " <td class='vncell'>".$text['label-first_name']."</td>";
  814. echo " <td class='vtable'><input type='text' class='formfld' name='contact_name_given' value='".escape($contact_name_given)."'></td>";
  815. echo " </tr>";
  816. echo " <tr>";
  817. echo " <td class='vncell'>".$text['label-last_name']."</td>";
  818. echo " <td class='vtable'><input type='text' class='formfld' name='contact_name_family' value='".escape($contact_name_family)."'></td>";
  819. echo " </tr>";
  820. echo " <tr>";
  821. echo " <td class='vncell'>".$text['label-organization']."</td>";
  822. echo " <td class='vtable'><input type='text' class='formfld' name='contact_organization' value='".escape($contact_organization)."'></td>";
  823. echo " </tr>";
  824. }
  825. if (permission_exists("user_groups")) {
  826. echo " <tr>";
  827. echo " <td class='vncellreq' valign='top'>".$text['label-groups']."</td>";
  828. echo " <td class='vtable'>";
  829. $sql = "select ";
  830. $sql .= " ug.*, g.domain_uuid as group_domain_uuid ";
  831. $sql .= "from ";
  832. $sql .= " v_user_groups as ug, ";
  833. $sql .= " v_groups as g ";
  834. $sql .= "where ";
  835. $sql .= " ug.group_uuid = g.group_uuid ";
  836. $sql .= " and (";
  837. $sql .= " g.domain_uuid = :domain_uuid ";
  838. $sql .= " or g.domain_uuid is null ";
  839. $sql .= " ) ";
  840. $sql .= " and ug.domain_uuid = :domain_uuid ";
  841. $sql .= " and ug.user_uuid = :user_uuid ";
  842. $sql .= "order by ";
  843. $sql .= " g.domain_uuid desc, ";
  844. $sql .= " g.group_name asc ";
  845. $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
  846. $parameters['user_uuid'] = $user_uuid;
  847. $database = new database;
  848. $user_groups = $database->select($sql, $parameters, 'all');
  849. if (is_array($user_groups)) {
  850. echo "<table cellpadding='0' cellspacing='0' border='0'>\n";
  851. foreach($user_groups as $field) {
  852. if (strlen($field['group_name']) > 0) {
  853. echo "<tr>\n";
  854. echo " <td class='vtable' style='white-space: nowrap; padding-right: 30px;' nowrap='nowrap'>";
  855. echo escape($field['group_name']).(($field['group_domain_uuid'] != '') ? "@".$_SESSION['domains'][$field['group_domain_uuid']]['domain_name'] : null);
  856. echo " </td>\n";
  857. if (permission_exists('group_member_delete') || if_group("superadmin")) {
  858. echo " <td class='list_control_icons' style='width: 25px;'>\n";
  859. echo " <a href='user_edit.php?id=".urlencode($user_uuid)."&domain_uuid=".urlencode($domain_uuid)."&group_uuid=".urlencode($field['group_uuid'])."&a=delete' alt='".$text['button-delete']."' onclick=\"return confirm('".$text['confirm-delete']."')\">".$v_link_label_delete."</a>\n";
  860. echo " </td>\n";
  861. }
  862. echo "</tr>\n";
  863. if (is_uuid($field['group_uuid'])) {
  864. $assigned_groups[] = $field['group_uuid'];
  865. }
  866. }
  867. }
  868. echo "</table>\n";
  869. }
  870. unset($sql, $parameters, $user_groups, $field);
  871. $sql = "select * from v_groups ";
  872. $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) ";
  873. if (is_array($assigned_groups) && sizeof($assigned_groups) > 0) {
  874. $sql .= "and group_uuid not in ('".implode("','",$assigned_groups)."') ";
  875. }
  876. $sql .= "order by domain_uuid desc, group_name asc ";
  877. $parameters['domain_uuid'] = $_SESSION['domain_uuid'];
  878. $database = new database;
  879. $groups = $database->select($sql, $parameters, 'all');
  880. if (is_array($groups)) {
  881. if (isset($assigned_groups)) { echo "<br />\n"; }
  882. echo "<select name='group_uuid_name' class='formfld' style='width: auto; margin-right: 3px;' ".($action == 'add' ? "required='required'" : null).">\n";
  883. echo " <option value=''></option>\n";
  884. foreach($groups as $field) {
  885. if ($field['group_level'] <= $_SESSION['user']['group_level']) {
  886. if (!isset($assigned_groups) || (isset($assigned_groups) && !in_array($field["group_uuid"], $assigned_groups))) {
  887. if ($group_uuid_name == $field['group_uuid']."|".$field['group_name']) { $selected = "selected='selected'"; } else { $selected = ''; }
  888. echo " <option value='".$field['group_uuid']."|".$field['group_name']."' $selected>".$field['group_name'].(($field['domain_uuid'] != '') ? "@".$_SESSION['domains'][$field['domain_uuid']]['domain_name'] : null)."</option>\n";
  889. }
  890. }
  891. }
  892. echo "</select>";
  893. if ($action == 'edit') {
  894. echo button::create(['type'=>'submit','label'=>$text['button-add'],'icon'=>$_SESSION['theme']['button_icon_add']]);
  895. }
  896. }
  897. unset($sql, $parameters, $groups, $field);
  898. echo " </td>";
  899. echo " </tr>";
  900. }
  901. if (permission_exists('user_domain')) {
  902. echo "<tr>\n";
  903. echo "<td class='vncell' valign='top' align='left' nowrap='nowrap'>\n";
  904. echo " ".$text['label-domain']."\n";
  905. echo "</td>\n";
  906. echo "<td class='vtable' align='left'>\n";
  907. echo " <select class='formfld' name='domain_uuid'>\n";
  908. foreach ($_SESSION['domains'] as $row) {
  909. echo " <option value='".escape($row['domain_uuid'])."' ".(($row['domain_uuid'] == $domain_uuid) ? "selected='selected'" : null).">".escape($row['domain_name'])."</option>\n";
  910. }
  911. echo " </select>\n";
  912. echo "<br />\n";
  913. echo $text['description-domain_name']."\n";
  914. echo "</td>\n";
  915. echo "</tr>\n";
  916. }
  917. else {
  918. echo "<input type='hidden' name='domain_uuid' value='".escape($domain_uuid)."'>";
  919. }
  920. if (permission_exists('api_key')) {
  921. echo " <tr>";
  922. echo " <td class='vncell' valign='top'>".$text['label-api_key']."</td>";
  923. echo " <td class='vtable'>\n";
  924. echo " <input type='text' class='formfld' style='width: 250px;' name='api_key' id='api_key' value=\"".escape($api_key)."\" >";
  925. echo button::create(['type'=>'button','label'=>$text['button-generate'],'icon'=>'key','onclick'=>"document.getElementById('api_key').value = uuid();"]);
  926. if (strlen($text['description-api_key']) > 0) {
  927. echo " <br />".$text['description-api_key']."<br />\n";
  928. }
  929. echo " </td>";
  930. echo " </tr>";
  931. }
  932. if (permission_exists('message_view')) {
  933. echo " <tr>";
  934. echo " <td class='vncell' valign='top'>".$text['label-message_key']."</td>";
  935. echo " <td class='vtable'>\n";
  936. echo " <input type='text' class='formfld' style='width: 250px;' name='message_key' id='message_key' value=\"".escape($user_settings["message"]["key"]["text"])."\" >";
  937. echo button::create(['type'=>'button','label'=>$text['button-generate'],'icon'=>'key','onclick'=>"document.getElementById('message_key').value = uuid();"]);
  938. if (strlen($text['description-message_key']) > 0) {
  939. echo " <br />".$text['description-message_key']."<br />\n";
  940. }
  941. echo " </td>";
  942. echo " </tr>";
  943. }
  944. echo "<tr ".($user_uuid == $_SESSION['user_uuid'] ? "style='display: none;'" : null).">\n";
  945. echo "<td class='vncell' valign='top' align='left' nowrap='nowrap'>\n";
  946. echo " ".$text['label-enabled']."\n";
  947. echo "</td>\n";
  948. echo "<td class='vtable' align='left'>\n";
  949. echo " <select class='formfld' name='user_enabled'>\n";
  950. echo " <option value='true'>".$text['option-true']."</option>\n";
  951. echo " <option value='false' ".(($user_enabled != "true") ? "selected='selected'" : null).">".$text['option-false']."</option>\n";
  952. echo " </select>\n";
  953. echo "<br />\n";
  954. echo $text['description-enabled']."\n";
  955. echo "</td>\n";
  956. echo "</tr>\n";
  957. if ($unsaved) {
  958. echo "<tr>";
  959. echo "<td colspan='2' align='right' style='white-space: nowrap;'>";
  960. echo " <span style='color: #b00;'>".$text['message-unsaved_changes']." <i class='fas fa-exclamation-triangle' style='margin-right: 15px;'></i></span>";
  961. echo "</td>";
  962. echo "</tr>";
  963. }
  964. echo "</table>";
  965. echo "<br /><br />";
  966. if ($action == 'edit') {
  967. echo "<input type='hidden' name='id' value=\"".escape($user_uuid)."\">";
  968. if (permission_exists("user_edit")) {
  969. echo "<input type='hidden' name='username_old' value=\"".escape($username)."\">";
  970. }
  971. }
  972. echo "<input type='hidden' name='".$token['name']."' value='".$token['hash']."'>\n";
  973. echo "</form>";
  974. if (permission_exists("user_edit") && permission_exists('user_setting_view') && $action == 'edit') {
  975. require $_SERVER["DOCUMENT_ROOT"].PROJECT_PATH."/core/user_settings/user_settings.php";
  976. echo "<br><br>";
  977. }
  978. //uuid generation script
  979. echo "<script>\n";
  980. echo "function uuid() {\n";
  981. echo " var d = new Date().getTime();\n";
  982. echo " var uuid = 'xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx'.replace(/[xy]/g, function(c) {\n";
  983. echo " var r = (d + Math.random()*16)%16 | 0;\n";
  984. echo " d = Math.floor(d/16);\n";
  985. echo " return (c=='x' ? r : (r&0x3|0x8)).toString(16);\n";
  986. echo " });\n";
  987. echo " return uuid;\n";
  988. echo "};\n";
  989. echo "</script>\n";
  990. //include the footer
  991. require_once "resources/footer.php";
  992. ?>