123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300 |
- <?php
- /*
- FusionPBX
- Version: MPL 1.1
- The contents of this file are subject to the Mozilla Public License Version
- 1.1 (the "License"); you may not use this file except in compliance with
- the License. You may obtain a copy of the License at
- http://www.mozilla.org/MPL/
- Software distributed under the License is distributed on an "AS IS" basis,
- WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
- for the specific language governing rights and limitations under the
- License.
- The Original Code is FusionPBX
- The Initial Developer of the Original Code is
- Mark J Crane <[email protected]>
- Portions created by the Initial Developer are Copyright (C) 2008 - 2020
- the Initial Developer. All Rights Reserved.
- Contributor(s):
- Mark J Crane <[email protected]>
- */
- //includes
- require_once "root.php";
- require_once "resources/require.php";
- require_once "resources/check_auth.php";
- require_once "resources/paging.php";
- //check permissions
- if (permission_exists('user_view')) {
- //access granted
- }
- else {
- echo "access denied";
- exit;
- }
- //add multi-lingual support
- $language = new text;
- $text = $language->get();
- //get the http post data
- if (is_array($_POST['users'])) {
- $action = $_POST['action'];
- $search = $_POST['search'];
- $users = $_POST['users'];
- }
- //process the http post data by action
- if ($action != '' && is_array($users) && @sizeof($users) != 0) {
- switch ($action) {
- case 'copy':
- if (permission_exists('user_add')) {
- $obj = new users;
- $obj->copy($users);
- }
- break;
- case 'toggle':
- if (permission_exists('user_edit')) {
- $obj = new users;
- $obj->toggle($users);
- }
- break;
- case 'delete':
- if (permission_exists('user_delete')) {
- $obj = new users;
- $obj->delete($users);
- }
- break;
- }
- header('Location: users.php'.($search != '' ? '?search='.urlencode($search) : null));
- exit;
- }
- //get order and order by
- $order_by = $_GET["order_by"];
- $order = $_GET["order"];
- //add the search string
- if (isset($_GET["search"])) {
- $search = strtolower($_GET["search"]);
- $sql_search = " (";
- $sql_search .= " lower(username) like :search ";
- $sql_search .= " or lower(groups) like :search ";
- $sql_search .= " or lower(contact_organization) like :search ";
- $sql_search .= " or lower(contact_name) like :search ";
- //$sql_search .= " or lower(user_status) like :search ";
- $sql_search .= ") ";
- $parameters['search'] = '%'.$search.'%';
- }
- //get the count
- $sql = "select count(*) from view_users ";
- if ($_GET['show'] == "all" && permission_exists('user_all')) {
- if (isset($sql_search)) {
- $sql .= "where ".$sql_search;
- }
- else {
- $sql.= "where true ";
- }
- }
- else {
- $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) ";
- if (isset($sql_search)) {
- $sql .= "and ".$sql_search;
- }
- $parameters['domain_uuid'] = $domain_uuid;
- }
- $sql .= "and ( ";
- $sql .= " group_level <= :group_level ";
- $sql .= " or group_level is null ";
- $sql .= ") ";
- $parameters['group_level'] = $_SESSION['user']['group_level'];
- $database = new database;
- $num_rows = $database->select($sql, $parameters, 'column');
- //prepare to page the results
- $rows_per_page = ($_SESSION['domain']['paging']['numeric'] != '') ? $_SESSION['domain']['paging']['numeric'] : 50;
- $param = $search ? "&search=".$search : null;
- $param = ($_GET['show'] == 'all' && permission_exists('user_all')) ? "&show=all" : null;
- $page = is_numeric($_GET['page']) ? $_GET['page'] : 0;
- list($paging_controls, $rows_per_page) = paging($num_rows, $param, $rows_per_page);
- list($paging_controls_mini, $rows_per_page) = paging($num_rows, $param, $rows_per_page, true);
- $offset = $rows_per_page * $page;
- //get the list
- $sql = "select * from view_users ";
- if ($_GET['show'] == "all" && permission_exists('user_all')) {
- if (isset($sql_search)) {
- $sql .= "where ".$sql_search;
- }
- else {
- $sql.= "where true ";
- }
- }
- else {
- $sql .= "where (domain_uuid = :domain_uuid or domain_uuid is null) ";
- if (isset($sql_search)) {
- $sql .= "and ".$sql_search;
- }
- $parameters['domain_uuid'] = $domain_uuid;
- }
- $sql .= "and ( ";
- $sql .= " group_level <= :group_level ";
- $sql .= " or group_level is null ";
- $sql .= ") ";
- $parameters['group_level'] = $_SESSION['user']['group_level'];
- $sql .= order_by($order_by, $order, 'username', 'asc');
- $sql .= limit_offset($rows_per_page, $offset);
- $database = new database;
- $users = $database->select($sql, $parameters, 'all');
- unset($sql, $parameters);
- //create token
- $object = new token;
- $token = $object->create($_SERVER['PHP_SELF']);
- //include the header
- $document['title'] = $text['title-users'];
- require_once "resources/header.php";
- //show the content
- echo "<div class='action_bar' id='action_bar'>\n";
- echo " <div class='heading'><b>".$text['title-users']." (".$num_rows.")</b></div>\n";
- echo " <div class='actions'>\n";
- if (permission_exists('user_add')) {
- if (!isset($id)) {
- echo button::create(['type'=>'button','label'=>$text['button-import'],'icon'=>$_SESSION['theme']['button_icon_import'],'style'=>'margin-right: 15px;','link'=>'user_imports.php']);
- }
- echo button::create(['type'=>'button','label'=>$text['button-add'],'icon'=>$_SESSION['theme']['button_icon_add'],'link'=>'user_edit.php']);
- }
- if (permission_exists('user_add') && $users) {
- echo button::create(['type'=>'button','label'=>$text['button-copy'],'icon'=>$_SESSION['theme']['button_icon_copy'],'onclick'=>"if (confirm('".$text['confirm-copy']."')) { list_action_set('copy'); list_form_submit('form_list'); } else { this.blur(); return false; }"]);
- }
- if (permission_exists('user_edit') && $users) {
- echo button::create(['type'=>'button','label'=>$text['button-toggle'],'icon'=>$_SESSION['theme']['button_icon_toggle'],'onclick'=>"if (confirm('".$text['confirm-toggle']."')) { list_action_set('toggle'); list_form_submit('form_list'); } else { this.blur(); return false; }"]);
- }
- if (permission_exists('user_delete') && $users) {
- echo button::create(['type'=>'button','label'=>$text['button-delete'],'icon'=>$_SESSION['theme']['button_icon_delete'],'onclick'=>"if (confirm('".$text['confirm-delete']."')) { list_action_set('delete'); list_form_submit('form_list'); } else { this.blur(); return false; }"]);
- }
- echo "<form id='form_search' class='inline' method='get'>\n";
- if (permission_exists('user_all')) {
- if ($_GET['show'] == 'all') {
- echo " <input type='hidden' name='show' value='all'>\n";
- }
- else {
- echo button::create(['type'=>'button','label'=>$text['button-show_all'],'icon'=>$_SESSION['theme']['button_icon_all'],'link'=>'?show=all']);
- }
- }
- echo "<input type='text' class='txt list-search' name='search' id='search' value=\"".escape($search)."\" placeholder=\"".$text['label-search']."\" onkeydown='list_search_reset();'>";
- echo button::create(['label'=>$text['button-search'],'icon'=>$_SESSION['theme']['button_icon_search'],'type'=>'submit','id'=>'btn_search','style'=>($search != '' ? 'display: none;' : null)]);
- echo button::create(['label'=>$text['button-reset'],'icon'=>$_SESSION['theme']['button_icon_reset'],'type'=>'button','id'=>'btn_reset','link'=>'users.php','style'=>($search == '' ? 'display: none;' : null)]);
- if ($paging_controls_mini != '') {
- echo "<span style='margin-left: 15px;'>".$paging_controls_mini."</span>\n";
- }
- echo " </form>\n";
- echo " </div>\n";
- echo " <div style='clear: both;'></div>\n";
- echo "</div>\n";
- echo $text['description-users']."\n";
- echo "<br /><br />\n";
- echo "<form id='form_list' method='post'>\n";
- echo "<input type='hidden' id='action' name='action' value=''>\n";
- echo "<input type='hidden' name='search' value=\"".escape($search)."\">\n";
- echo "<table class='list'>\n";
- echo "<tr class='list-header'>\n";
- if (permission_exists('user_add') || permission_exists('user_edit') || permission_exists('user_delete')) {
- echo " <th class='checkbox'>\n";
- echo " <input type='checkbox' id='checkbox_all' name='checkbox_all' onclick='list_all_toggle();' ".($users ?: "style='visibility: hidden;'").">\n";
- echo " </th>\n";
- }
- if ($_GET['show'] == 'all' && permission_exists('user_all')) {
- echo th_order_by('domain_name', $text['label-domain'], $order_by, $order);
- }
- echo th_order_by('username', $text['label-username'], $order_by, $order);
- echo th_order_by('groups', $text['label-groups'], $order_by, $order);
- if (permission_exists('contact_view')) {
- echo th_order_by('contact_organization', $text['label-organization'], $order_by, $order);
- echo th_order_by('contact_name', $text['label-name'], $order_by, $order);
- //echo th_order_by('contact_name_family', $text['label-contact_name_family'], $order_by, $order);
- }
- //echo th_order_by('user_status', $text['label-user_status'], $order_by, $order);
- //echo th_order_by('add_date', $text['label-add_date'], $order_by, $order);
- echo th_order_by('user_enabled', $text['label-user_enabled'], $order_by, $order, null, "class='center'");
- if (permission_exists('user_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') {
- echo " <td class='action-button'> </td>\n";
- }
- echo "</tr>\n";
- if (is_array($users) && @sizeof($users) != 0) {
- $x = 0;
- foreach ($users as $row) {
- if (permission_exists('user_edit')) {
- $list_row_url = "user_edit.php?id=".urlencode($row['user_uuid']);
- }
- echo "<tr class='list-row' href='".$list_row_url."'>\n";
- if (permission_exists('user_add') || permission_exists('user_edit') || permission_exists('user_delete')) {
- echo " <td class='checkbox'>\n";
- echo " <input type='checkbox' name='users[$x][checked]' id='checkbox_".$x."' value='true' onclick=\"if (!this.checked) { document.getElementById('checkbox_all').checked = false; }\">\n";
- echo " <input type='hidden' name='users[$x][uuid]' value='".escape($row['user_uuid'])."' />\n";
- echo " </td>\n";
- }
- if ($_GET['show'] == 'all' && permission_exists('user_all')) {
- echo " <td>".escape($_SESSION['domains'][$row['domain_uuid']]['domain_name'])."</td>\n";
- }
- echo " <td>\n";
- if (permission_exists('user_edit')) {
- echo " <a href='".$list_row_url."' title=\"".$text['button-edit']."\">".escape($row['username'])."</a>\n";
- }
- else {
- echo " ".escape($row['username']);
- }
- echo " </td>\n";
- echo " <td>".escape($row['groups'])."</td>\n";
- if (permission_exists('contact_view')) {
- echo " <td>".escape($row['contact_organization'])."</td>\n";
- echo " <td>".escape($row['contact_name'])."</td>\n";
- //echo " <td>".escape($row['contact_name_given'])."</td>\n";
- //echo " <td>".escape($row['contact_name_family'])."</td>\n";
- }
- //echo " <td>".escape($row['user_status'])."</td>\n";
- //echo " <td>".escape($row['add_date'])."</td>\n";
- if (permission_exists('user_edit')) {
- echo " <td class='no-link center'>\n";
- echo button::create(['type'=>'submit','class'=>'link','label'=>$text['label-'.$row['user_enabled']],'title'=>$text['button-toggle'],'onclick'=>"list_self_check('checkbox_".$x."'); list_action_set('toggle'); list_form_submit('form_list')"]);
- }
- else {
- echo " <td class='center'>\n";
- echo $text['label-'.$row['user_enabled']];
- }
- echo " </td>\n";
- if (permission_exists('user_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') {
- echo " <td class='action-button'>\n";
- echo button::create(['type'=>'button','title'=>$text['button-edit'],'icon'=>$_SESSION['theme']['button_icon_edit'],'link'=>$list_row_url]);
- echo " </td>\n";
- }
- echo "</tr>\n";
- $x++;
- }
- unset($users);
- }
- echo "</table>\n";
- echo "<br />\n";
- echo "<div align='center'>".$paging_controls."</div>\n";
- echo "<input type='hidden' name='".$token['name']."' value='".$token['hash']."'>\n";
- echo "</form>\n";
- //include the footer
- require_once "resources/footer.php";
- ?>
|