2 Commits

Author SHA1 Message Date
09155561f8 Incorporated changes for release 1.3.3 2026-02-24 20:18:58 -05:00
2bddfba99a Incorporated changes for release 1.3.2 2026-02-24 20:13:13 -05:00
27 changed files with 993 additions and 495 deletions

View File

@@ -1,5 +1,5 @@
OpenDRS - Online Discrepancy Reporting System OpenDRS - Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
This program is free software; you can redistribute it and/or modify This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by it under the terms of the GNU General Public License as published by
@@ -95,3 +95,43 @@ Changelog
1.3.1 - 2022-05-11 1.3.1 - 2022-05-11
- Updated installation scripts and instructions to reflect changes in - Updated installation scripts and instructions to reflect changes in
Raspberry Pi OS Release 2022-04-04. Raspberry Pi OS Release 2022-04-04.
1.3.2 - 2022-08-08
- Fixed typo in dbadmin.php that prevented adding new When Discovered
items.
- Fixed bug in create.php that prevented the page from working.
- Fixed bug in config.php that prevented banners from being modified.
- Fixed bug where action_by and action_reason were not preselected for
subsequent searches in search.php.
- Fixed bug in about.php and gpl.php that still used old $mts_db
database handle.
- Removed the server session directory option in config.php
Miscellaneous settings. For this to make sense, you'd have to have
shell access to the server and if that's the case, you'd be able
to make the necessary database changes as well.
- Fixed opendrs-initial.sql to make the default banner colors match
the ones in common.php.
- Created changelog.php for use by the "changes" link on the About
page so kiosk terminal users don't get dead-ended in the CHANGELOG
text file with no way to get back to the app.
- Extensive code cleanups/updates in all php files to make application
compatible with php8 and eliminate php warnings in apache2 error
log file.
- For Raspberry Pi:
- Updated server-setup.sh to attempt to install the php-mysqli package
for compatibility with php8.
- Chromium browser will use the printer designated as the local
default if it is selected as such in the Cups printer
configuration.
1.3.3 - 2023-10-03
- Restricted the ability to change the report date and time when
creating or editing a writeup to only logged in users. This is to
prevent reporters from backdating writeups, causing them to possibly
be missed.
- For Raspberry Pi:
- Updated the Webmin custom command scripts to use whatever user is
logged into Webmin instead of the user "pi" which may not exist
if rpi-imager options were used to set a different initial user
when the SD card was created.

View File

@@ -1,3 +1,3 @@
sudo wap-enable sudo wap-enable
Enable Wireless Access Point Enable Wireless Access Point
pi 0 1 0 0 0 0 0 - * 0 1 0 0 0 0 0 -

View File

@@ -1,3 +1,3 @@
sudo wap-disable sudo wap-disable
Disable Wireless Access Point Disable Wireless Access Point
pi 0 1 0 0 0 0 0 - * 0 1 0 0 0 0 0 -

View File

@@ -71,6 +71,7 @@ echo ""
echo "" echo ""
echo "" echo ""
apt install -y apache2 php mariadb-server phpmyadmin uuid-runtime apt install -y apache2 php mariadb-server phpmyadmin uuid-runtime
apt install -y php-mysqli
cp etc/apache2/mods-available/alias.conf /etc/apache2/mods-available cp etc/apache2/mods-available/alias.conf /etc/apache2/mods-available
service apache2 restart service apache2 restart
echo "...done." echo "...done."

View File

@@ -176,11 +176,14 @@ echo ""
echo "" echo ""
echo "Terminal setup complete." echo "Terminal setup complete."
echo "" echo ""
if [ "$conftype" = "Terminal" ]
then
echo "If you would like to use this terminal as a DRS server, after rebooting" echo "If you would like to use this terminal as a DRS server, after rebooting"
echo "and logging back in, change directory to the extracted distribution's" echo "and logging back in, change directory to the extracted distribution's"
echo "RPiSetup directory, and run:" echo "RPiSetup directory, and run:"
echo " sudo ./server-setup.sh" echo " sudo ./server-setup.sh"
echo "" echo ""
fi
echo "" echo ""
echo "A reboot is required to start using this terminal." echo "A reboot is required to start using this terminal."
echo -n "Would you like to reboot now? [Y/n]: " echo -n "Would you like to reboot now? [Y/n]: "

View File

@@ -1,5 +0,0 @@
#!/bin/bash
host=$1
rsync -rlptDvz rwright@$host:/home/rwright/ownCloud/Software_Projects/OpenDRS-1.1.0/distfiles/ /var/www/opendrs/ && chown -R www-data:www-data /var/www/opendrs/*

View File

@@ -1,18 +1,11 @@
TODO TODO
- Fix search.php to validate action taken date and time entries
- Fix occurrences of $mts_db (should be $drs_db)in about.php and gpl.php
- Add ability to save/restore configuration. - Add ability to save/restore configuration.
- Add ability to backup/restore writeups. - Add ability to backup/restore writeups.
- Get Chromium to remember printer selection across reboots. - Add a $border_visible debug variable to the end of settings.php and
use it wherever there's a "border=\"0\"" to be able to see and fix
table layout issues.
- Fix default banner colors in opendrs-initial.sql to match the ones shown in common.php. - Automate installation on servers running Nginx as well as Apache.
- Fix failure to preselect "action taken by" users on the search page for subsequent searches.
- $border_visible debug variable to the end of settings.php and use it wherever there's a
"border=\"0\"" to be able to see and fix table layout issues.

View File

@@ -2,12 +2,17 @@
/* /*
boilerplate.php boilerplate.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to index.php on cancel button press // redirect to index.php on cancel button press
if ($_REQUEST['cancel']) { if ($_REQUEST['cancel']) {
@@ -18,38 +23,46 @@ if ($_REQUEST['cancel']) {
} }
// import session variables // import session variables
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; if (isset($_SESSION['userid'])) {
$userid=$_SESSION['userid'];
} else {
$userid=NULL;
}
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming // form as "all_parameters" so we need to load those into $incoming[]
$incoming=unserialize($_REQUEST['all_parameters']); $incoming=unserialize($_REQUEST['all_parameters']);
} else { } else {
// copy $_REQUEST to $incoming // copy $_REQUEST[] to $incoming[]
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
extract($incoming, EXTR_SKIP);
/*
// define local functions * possible keys are:
*
*/
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
if ($print=="Printer Friendly") { if ($print) {
$sbcolor=P_SIDEBAR_COLOR;
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$sbcolor=SIDEBAR_COLOR;
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
} }
$role=dblookup($drs_db,"users","id","role",$userid); $role=dblookup($drs_db,"users","id","role",$userid);
// define local functions
framework("begin","$appname","Boilerplate Page",$print); framework("begin","$appname","Boilerplate Page",$print);
//echo "_REQUEST array <br>"; //echo "_REQUEST array <br>";

View File

@@ -3,7 +3,7 @@
/* /*
db.php db.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */

View File

@@ -1,5 +1,5 @@
OpenDRS - Online Discrepancy Reporting System OpenDRS - Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
This program is free software; you can redistribute it and/or modify This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by it under the terms of the GNU General Public License as published by
@@ -95,3 +95,43 @@ Changelog
1.3.1 - 2022-05-11 1.3.1 - 2022-05-11
- Updated installation scripts and instructions to reflect changes in - Updated installation scripts and instructions to reflect changes in
Raspberry Pi OS Release 2022-04-04. Raspberry Pi OS Release 2022-04-04.
1.3.2 - 2022-08-08
- Fixed typo in dbadmin.php that prevented adding new When Discovered
items.
- Fixed bug in create.php that prevented the page from working.
- Fixed bug in config.php that prevented banners from being modified.
- Fixed bug where action_by and action_reason were not preselected for
subsequent searches in search.php.
- Fixed bug in about.php and gpl.php that still used old $mts_db
database handle.
- Removed the server session directory option in config.php
Miscellaneous settings. For this to make sense, you'd have to have
shell access to the server and if that's the case, you'd be able
to make the necessary database changes as well.
- Fixed opendrs-initial.sql to make the default banner colors match
the ones in common.php.
- Created changelog.php for use by the "changes" link on the About
page so kiosk terminal users don't get dead-ended in the CHANGELOG
text file with no way to get back to the app.
- Extensive code cleanups/updates in all php files to make application
compatible with php8 and eliminate php warnings in apache2 error
log file.
- For Raspberry Pi:
- Updated server-setup.sh to attempt to install the php-mysqli package
for compatibility with php8.
- Chromium browser will use the printer designated as the local
default if it is selected as such in the Cups printer
configuration.
1.3.3 - 2023-10-03
- Restricted the ability to change the report date and time when
creating or editing a writeup to only logged in users. This is to
prevent reporters from backdating writeups, causing them to possibly
be missed.
- For Raspberry Pi:
- Updated the Webmin custom command scripts to use whatever user is
logged into Webmin instead of the user "pi" which may not exist
if rpi-imager options were used to set a different initial user
when the SD card was created.

View File

@@ -2,15 +2,20 @@
/* /*
about.php about.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to index.php on cancel button press // redirect to index.php on cancel button press
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
header("Location:index.php"); header("Location:index.php");
@@ -21,7 +26,6 @@ if ($_REQUEST['cancel']) {
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; if (isset($_SESSION['userid'])) $userid=$_SESSION['userid'];
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming // form as "all_parameters" so we need to load those into $incoming
@@ -31,7 +35,7 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
// define local functions // define local functions
@@ -42,14 +46,12 @@ $appname=APP_NAME;
$drs_version=DRS_VERSION; $drs_version=DRS_VERSION;
if ($print=="Printer Friendly") { if ($print=="Printer Friendly") {
$sbcolor=P_SIDEBAR_COLOR;
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$sbcolor=SIDEBAR_COLOR;
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
} }
$role=dblookup($mts_db,"users","id","role",$userid); $role=dblookup($drs_db,"users","id","role",$userid);
framework("begin","$appname","About OpenDRS",$print); framework("begin","$appname","About OpenDRS",$print);
@@ -78,14 +80,14 @@ echo "
OpenDRS $drs_version Discrepancy Reporting System OpenDRS $drs_version Discrepancy Reporting System
</h3><br> </h3><br>
<p>This program is licensed under the terms of the <a href=\"gpl.php\">GNU General Public License</a>. Click on the link <p>This program is licensed under the terms of the <a href=\"gpl.php\">GNU General Public License</a>. Click on the link
or see the LICENSE file in the distribution to read it. OpenDRS is Copyright (C) 2022 by Rod Wright. or see the LICENSE file in the distribution to read it. OpenDRS is Copyright (C) 2023 by Rod Wright.
</p> </p>
<p> <p>
OpenDRS is a simple online maintenance tracking/discrepancy reporting application. It allows anyone with a web browser to create, OpenDRS is a simple online maintenance tracking/discrepancy reporting application. It allows anyone with a web browser to create,
view, and search writeups. The look and feel of the OpenDRS pages are easily changed. view, and search writeups. The look and feel of the OpenDRS pages are easily changed.
Settings that affect all users can be changed in the Admin Functions menu. User specific settings can be changed in the Settings that affect all users can be changed in the Admin Functions menu. User specific settings can be changed in the
My Profile menu. No browser specific HTML is used in OpenDRS, so it should be useable in any browser, and it has been My Profile menu. No browser specific HTML is used in OpenDRS, so it should be useable in any browser, and it has been
tested using Google Chrome, Mozilla Firefox and Microsoft Internet Explorer. tested using Google Chrome, Mozilla Firefox, Microsoft Internet Explorer, and Microsoft Edge.
</p> </p>
<p> <p>
OpenDRS is highly flexible. Instructions are included in the distribution for creating a user terminal with a Raspberry Pi. OpenDRS can be hosted on a OpenDRS is highly flexible. Instructions are included in the distribution for creating a user terminal with a Raspberry Pi. OpenDRS can be hosted on a
@@ -93,7 +95,7 @@ centralized server, accessed by networked PCs and/or Raspberry Pi terminals. It
terminal as a non-networked standalone system or in a small network of Raspberry Pi terminals. terminal as a non-networked standalone system or in a small network of Raspberry Pi terminals.
</p> </p>
<p> <p>
To read about the <a href=\"CHANGELOG\" >changes</a> in this latest version of OpenDRS, click on the link or see the CHANGELOG file in the distribution. To read about the <a href=\"changelog.php\" >changes</a> in this latest version of OpenDRS, click on the link or see the CHANGELOG file in the distribution.
</p> </p>
<p>Several pieces of Open Source software make OpenDRS possible. <p>Several pieces of Open Source software make OpenDRS possible.

92
distfiles/changelog.php Normal file
View File

@@ -0,0 +1,92 @@
<?php
/*
changelog.php
OpenMTS Online Maintenance Tracking System
Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0
*/
include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to search.php on cancel button press
if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache");
header("Location:search.php");
exit();
}
// import session variables
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid'];
// import incoming arrays
if ($print) {
// if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming
$incoming=unserialize($_REQUEST['all_parameters']);
} else {
// copy $_REQUEST to $incoming
$incoming=arrayCopy($_REQUEST);
}
// extract incoming array keys into variables
// define local functions
// assign variables from constants
$appname=APP_NAME;
if ($print) {
$mbgcolor=P_MENUBG_COLOR;
} else {
$mbgcolor=MENUBG_COLOR;
}
$role=dblookup($drs_db,"users","id","role",$userid);
framework("begin","$appname","OpenDRS Change Log",$print);
//echo "_REQUEST array <br>";
//var_dump($_REQUEST);
//echo "<br><hr> incoming array <br>";
//var_dump($incoming);
// ******** begin database manipulation ********
// ******** end database manipulation ********
pagetable("begin");
if (!$print) {
pageblock("left","begin");
sidemenu();
pageblock("left","end");
}
pageblock("right","begin");
banner($print);
echo "<br>";
echo "
<pre>
";
echo file_get_contents("CHANGELOG");
echo "
</pre>
";
echo "<br>";
banner($print);
pageblock("right","end");
pagetable("end");
framework("end","","",$print);
?>

View File

@@ -2,7 +2,7 @@
/* /*
common.php common.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
@@ -458,14 +458,19 @@ function banner($print) {
} }
} }
function dblookup($dbhandle,$table,$in_field,$out_field,$in_data) { function dblookup($drs_db,$table,$in_field,$out_field,$in_data) {
// look up a single field in a database given a value for a single field // look up a single field in a database given a value for a single field
$out_data=mysqli_fetch_row(mysqli_query($dbhandle,"select $out_field from $table where $in_field=\"$in_data\"")); $lookup_result=(mysqli_query($drs_db,"select $out_field from $table where $in_field=\"$in_data\""));
if (mysqli_num_rows($lookup_result) > 0) {
$out_data=mysqli_fetch_row($lookup_result);
return($out_data[0]); return($out_data[0]);
} else {
return NULL;
}
} }
function arrayCopy( array $array ) { function arrayCopy( array $array ) {
$result = array(); $result=[];
foreach( $array as $key => $val ) { foreach( $array as $key => $val ) {
if( is_array( $val ) ) { if( is_array( $val ) ) {
$result[$key] = arrayCopy( $val ); $result[$key] = arrayCopy( $val );
@@ -494,7 +499,7 @@ function validate_password($pass,$passconf) {
// first element is true if passwords match, false if not // first element is true if passwords match, false if not
// second element is true if passwords meet complexity requirements, false if not // second element is true if passwords meet complexity requirements, false if not
$results=array(); $results=[];
// check for match // check for match
if ($pass==$passconf) { if ($pass==$passconf) {
@@ -597,6 +602,8 @@ function displaywriteup($id) {
} else { } else {
$group_ind="<a href=\"writeupdetail.php?id={$writeupdata['id']}\"><img src=\"icons/block.png\" alt=\"GRP\" title=\"Member of $group_count groups. Click here to view.\"></a></div>"; $group_ind="<a href=\"writeupdetail.php?id={$writeupdata['id']}\"><img src=\"icons/block.png\" alt=\"GRP\" title=\"Member of $group_count groups. Click here to view.\"></a></div>";
} }
} else {
$group_ind=NULL;
} }
echo " echo "
<table border=\"2\" width=\"100%\"><tr><td> <table border=\"2\" width=\"100%\"><tr><td>
@@ -667,20 +674,29 @@ function format_message($msgtype,$msgtxt) {
function getsetting($setting_name,$user_id) { function getsetting($setting_name,$user_id) {
// get the value of a setting for a user // get the value of a setting for a user
global $drs_db; global $drs_db;
$confvalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select id,value from config where name=\"$setting_name\""))['value']; $confqry=mysqli_query($drs_db,"select id,value from config where name=\"$setting_name\"");
$uservalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\""))['value']; $confvalue=mysqli_fetch_assoc($confqry)['value'];
$userqry=mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\"");
if (mysqli_num_rows($userqry) > 0) {
$uservalue=mysqli_fetch_assoc($userqry)['value'];
if ($uservalue) { if ($uservalue) {
return $uservalue; return $uservalue;
} else { } else {
return $confvalue; return $confvalue;
} }
} else {
return $confvalue;
}
} }
function putsetting($setting_name,$setting_value,$user_id) { function putsetting($setting_name,$setting_value,$user_id) {
// set the value of a setting for a tech // set the value of a setting for a tech
global $drs_db; global $drs_db;
$confvalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select value from config where name=\"$setting_name\""))['value']; $confqry=mysqli_query($drs_db,"select value from config where name=\"$setting_name\"");
$uservalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\""))['value']; $confvalue=mysqli_fetch_assoc($confqry)['value'];
$userqry=mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\"");
if (mysqli_num_rows($userqry) > 0) {
$uservalue=mysqli_fetch_assoc($userqry)['value'];
if ($setting_value==$confvalue) { if ($setting_value==$confvalue) {
mysqli_query($drs_db,"delete from profile where user=\"$user_id\" and name=\"$setting_name\""); mysqli_query($drs_db,"delete from profile where user=\"$user_id\" and name=\"$setting_name\"");
} else { } else {
@@ -690,6 +706,9 @@ function putsetting($setting_name,$setting_value,$user_id) {
mysqli_query($drs_db,"insert into profile(user,name,value) values(\"$user_id\",\"$setting_name\",\"$setting_value\")"); mysqli_query($drs_db,"insert into profile(user,name,value) values(\"$user_id\",\"$setting_name\",\"$setting_value\")");
} }
} }
} else {
mysqli_query($drs_db,"insert into profile(user,name,value) values(\"$user_id\",\"$setting_name\",\"$setting_value\")");
}
} }
function group_detail($groupid,$role=false,$mode="view",$selection="none") { function group_detail($groupid,$role=false,$mode="view",$selection="none") {

View File

@@ -2,15 +2,20 @@
/* /*
config.php config.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to index.php on cancel button press // redirect to index.php on cancel button press
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
header("Location:index.php"); header("Location:index.php");
@@ -30,7 +35,6 @@ if ($role != ADMIN) {
} }
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming[] // form as "all_parameters" so we need to load those into $incoming[]
@@ -40,45 +44,55 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
$update_display=$incoming['update_display']; extract($incoming, EXTR_SKIP);
$display_appname=$incoming['display_appname']; /*
$display_banner=$incoming['display_banner']; * possible keys are:
$display_footer=$incoming['display_footer']; * update_display
$display_funchelp=$incoming['display_funchelp']; * display_appname
$display_device_term=$incoming['display_device_term']; * display_banner
$display_discovered_term=$incoming['display_discovered_term']; * display_footer
$display_discovered_term_short=$incoming['display_discovered_term_short']; * display_funchelp
$display_disc_drop_data=$incoming['display_disc_drop_data']; * display_device_term
$display_functional_term=$incoming['display_functional_term']; * display_discovered_term
$display_functional_term_short=$incoming['display_functional_term_short']; * display_discovered_term_short
$display_functional_yes=$incoming['display_functional_yes']; * display_disc_drop_data
$display_functional_no=$incoming['display_functional_no']; * display_functional_term
$display_functional_yes_short=$incoming['display_functional_yes_short']; * display_functional_term_short
$display_functional_no_short=$incoming['display_functional_no_short']; * display_functional_yes
* display_functional_no
* display_functional_yes_short
* display_functional_no_short
* update_colors
* reset_colors
* newbgc
* newmbgc
* newtc
* newlc
* newvlc
* newhc
* edit_banner
* add_banner
* update_banner
* delete_banner
* bnrid
* bnrname
* bnrcolor
* bnrtxtcolor
* update_misc
* sessttl
* logoutall
*/
$update_colors=$incoming['update_colors']; if (!isset($update_display)) $update_display=false;
$reset_colors=$incoming['reset_colors']; if (!isset($update_colors)) $update_colors=false;
$newbgc=$incoming['newbgc']; if (!isset($reset_colors)) $reset_colors=false;
$newmbgc=$incoming['newmbgc']; if (!isset($add_banner)) $add_banner=false;
$newtc=$incoming['newtc']; if (!isset($edit_banner)) $edit_banner=false;
$newlc=$incoming['newlc']; if (!isset($update_banner)) $update_banner=false;
$newvlc=$incoming['newvlc']; if (!isset($delete_banner)) $delete_banner=false;
$newhc=$incoming['newhc']; if (!isset($update_misc)) $update_misc=false;
if (!isset($logoutall)) $logoutall=false;
$edit_banner=$incoming['edit_banner'];
$add_banner=$incoming['add_banner'];
$update_banner=$incoming['update_banner'];
$delete_banner=$incoming['delete_banner'];
$bnrid=$incoming['bnrid'];
$bnrname=$incoming['bnrname'];
$bnrcolor=$incoming['bnrcolor'];
$bnrtxtcolor=$incoming['bnrtxtcolor'];
$update_misc=$incoming['update_misc'];
$sessttl=$incoming['sessttl'];
$sessdir=$incoming['sessdir'];
$logoutall=$incoming['logoutall'];
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
@@ -97,6 +111,8 @@ framework("begin","$appname","Configuration",$print);
//var_dump($incoming); //var_dump($incoming);
// ******** begin database manipulation ******** // ******** begin database manipulation ********
$nameunique_err=$namesuppld_err=$ttlsuppld_err=$dirsuppld_err=false;
if ($update_display) { if ($update_display) {
// remove html tags from footer_message and sanitize // remove html tags from footer_message and sanitize
$display_footer=strip_tags($display_footer); $display_footer=strip_tags($display_footer);
@@ -174,6 +190,7 @@ if ($add_banner) {
// test for name supplied // test for name supplied
if (strlen(trim($bnrname))) { if (strlen(trim($bnrname))) {
$namesuppld=true; $namesuppld=true;
$namesuppld_err=false;
} else { } else {
$namesuppld=false; $namesuppld=false;
$namesuppld_err=true; $namesuppld_err=true;
@@ -184,6 +201,7 @@ if ($add_banner) {
$nameunique_err=true; $nameunique_err=true;
} else { } else {
$nameunique=true; $nameunique=true;
$nameunique_err=false;
} }
if ($namesuppld && $nameunique) { if ($namesuppld && $nameunique) {
// sanitize banner name // sanitize banner name
@@ -204,17 +222,19 @@ if ($edit_banner) {
// test for name supplied // test for name supplied
if (strlen(trim($bnrname))) { if (strlen(trim($bnrname))) {
$namesuppld=true; $namesuppld=true;
$namesuppld_err=false;
} else { } else {
$namesuppld=false; $namesuppld=false;
$namesuppld_err=true; $namesuppld_err=true;
} }
// test for name unique // test for name unique
if (mysqli_num_rows(mysqli_query($db,"select bannerid from banners where bannername=\"$bnrname\" and bannerid!=\"$bnrid\""))) { if (mysqli_num_rows(mysqli_query($drs_db,"select bannerid from banners where bannername=\"$bnrname\" and bannerid!=\"$bnrid\""))) {
if (mysqli_num_rows(mysqli_query($drs_db,"select bannerid from banners where bannername=\"$bnrname\""))) { if (mysqli_num_rows(mysqli_query($drs_db,"select bannerid from banners where bannername=\"$bnrname\""))) {
$nameunique=false; $nameunique=false;
$nameunique_err=true; $nameunique_err=true;
} else { } else {
$nameunique=true; $nameunique=true;
$nameunique_err=false;
} }
} else { } else {
$nameunique=true; $nameunique=true;
@@ -246,20 +266,8 @@ if ($update_misc) {
$ttlsuppld=false; $ttlsuppld=false;
$ttlsuppld_err=true; $ttlsuppld_err=true;
} }
// test for sessdir supplied if ($ttlsuppld) {
if (strlen(trim($sessdir))) {
$dirsuppld=true;
} else {
$dirsuppld=false;
$dirsuppld_err=true;
}
if ($ttlsuppld && $dirsuppld) {
mysqli_query($drs_db,"update config set value=\"$sessttl\" where name=\"session_ttl_days\""); mysqli_query($drs_db,"update config set value=\"$sessttl\" where name=\"session_ttl_days\"");
if ($ostype == 'WIN') {
mysqli_query($drs_db,"update config set value=\"$sessdir\" where name=\"win_server_session_dir\"");
} else {
mysqli_query($drs_db,"update config set value=\"$sessdir\" where name=\"unix_server_session_dir\"");
}
} }
} }
@@ -536,17 +544,10 @@ echo "
<form method=\"post\" action=\"config.php#miscellaneous\"> <form method=\"post\" action=\"config.php#miscellaneous\">
"; ";
if ($ttlsuppld_err) format_message(1,"Session expiration time cannot be blank."); if ($ttlsuppld_err) format_message(1,"Session expiration time cannot be blank.");
if ($dirsuppld_err) format_message(1,"Server session file directory cannot be blank.");
$curttl=mysqli_fetch_row(mysqli_query($drs_db,"select value from config where name=\"session_ttl_days\""))[0]; $curttl=mysqli_fetch_row(mysqli_query($drs_db,"select value from config where name=\"session_ttl_days\""))[0];
if ($ostype == 'WIN') {
$curssdir=mysqli_fetch_row(mysqli_query($drs_db,"select value from config where name=\"win_server_session_dir\""))[0];
} else {
$curssdir=mysqli_fetch_row(mysqli_query($drs_db,"select value from config where name=\"unix_server_session_dir\""))[0];
}
echo " echo "
<font size=\"+1\"><b>Miscellaneous Configuration Parameters</b></font><br><br><br><br> <font size=\"+1\"><b>Miscellaneous Configuration Parameters</b></font><br><br><br><br>
Session expiration time (users will have to log in again after this long) : &nbsp;<input type=\"text\" name=\"sessttl\" size=\"3\" value=\"$curttl\"> days<br><br> Session expiration time (users will have to log in again after this long) : &nbsp;<input type=\"text\" name=\"sessttl\" size=\"3\" value=\"$curttl\"> days<br><br>
Server session file directory (must be writable by the web server process) : <br><input type=\"text\" name=\"sessdir\" size=\"40\" value=\"$curssdir\"><br><br>
Force logout of all users &nbsp;<input type=\"checkbox\" name=\"logoutall\"><br><br><br><br> Force logout of all users &nbsp;<input type=\"checkbox\" name=\"logoutall\"><br><br><br><br>
<input type=\"submit\" name=\"update_misc\" value=\"Update Options\">&nbsp;&nbsp;&nbsp;&nbsp; <input type=\"submit\" name=\"update_misc\" value=\"Update Options\">&nbsp;&nbsp;&nbsp;&nbsp;
<input type=\"submit\" name=\"reset\" value=\"Reset\"><br> <input type=\"submit\" name=\"reset\" value=\"Reset\"><br>

View File

@@ -2,15 +2,20 @@
/* /*
create.php create.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to writeups.php on change cancel // redirect to writeups.php on change cancel
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
header("Location:writeups.php"); header("Location:writeups.php");
@@ -18,10 +23,14 @@ if ($_REQUEST['cancel']) {
} }
// import session variables // import session variables
if (isset($_SESSION['personid'])) $personid=$_SESSION['personid']; if (isset($_SESSION['userid'])) {
$userid=$_SESSION['userid'];
} else {
$userid=NULL;
}
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming[] // form as "all_parameters" so we need to load those into $incoming[]
@@ -31,28 +40,40 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
$create=$incoming['create']; extract($incoming, EXTR_SKIP);
$device=$incoming['device']; /*
$discovered=$incoming['discovered']; * possible keys are:
$functional=$incoming['functional']; * create
$reported_by=$incoming['reported_by']; * device
$report_date=$incoming['report_date']; * discovered
$report_time=$incoming['report_time']; * functional
$subsystem=$incoming['subsystem']; * reported_by
$discrepancy_text=$incoming['discrepancy_text']; * report_date
$status=$incoming['status']; * report_time
* subsystem
* discrepancy_text
* status
*/
if (!isset($device)) $device=NULL;
if (!isset($discovered)) $discovered=NULL;
if (!isset($reported_by)) $reported_by=NULL;
if (!isset($discrepancy_text)) $discrepancy_text=NULL;
if (!isset($functional)) $functional=NULL;
if (!isset($subsystem)) $subsystem=NULL;
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
if ($print=="Printer Friendly") { if ($print) {
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
} }
$role=dblookup($drs_db,"persons","id","role",$personid); $role=dblookup($drs_db,"users","id","role",$userid);
framework("begin","$appname","New Writeup",$print); framework("begin","$appname","New Writeup",$print);
@@ -66,17 +87,17 @@ framework("begin","$appname","New Writeup",$print);
// determine today's date and make it the default // determine today's date and make it the default
$today=date("Y-m-d"); $today=date("Y-m-d");
$now=date("H:i:s"); $now=date("H:i:s");
if (!$report_date || $report_date=="automatic") $report_date=$today; if (!isset($report_date) || $report_date=="automatic") $report_date=$today;
if (!$report_time || $report_time=="automatic") $report_time=$now; if (!isset($report_time) || $report_time=="automatic") $report_time=$now;
if ($create) { if (isset($create)) {
// add the entry if create is pressed // add the entry if create is pressed
if ($discrepancy_text && $reported_by && $device && $subsystem && $discovered) { if ($discrepancy_text!=NULL && $reported_by!=NULL && $device!=NULL && $subsystem!=NULL && $discovered!=NULL) {
// sanitize and fix blank date and time // sanitize and fix blank date and time
$report_date=mysqli_real_escape_string($drs_db,$report_date); $report_date=mysqli_real_escape_string($drs_db,$report_date);
$report_time=mysqli_real_escape_string($drs_db,$report_time); $report_time=mysqli_real_escape_string($drs_db,$report_time);
if (!$report_date) $report_date=$today; if (!isset($report_date)) $report_date=$today;
if (!$report_time) $report_time=$now; if (!isset($report_time)) $report_time=$now;
// remove html tags from discrepancy text and sanitize // remove html tags from discrepancy text and sanitize
$discrepancy_text=strip_tags($discrepancy_text); $discrepancy_text=strip_tags($discrepancy_text);
@@ -101,33 +122,33 @@ pageblock("right","begin");
banner($print); banner($print);
echo "<br>"; echo "<br>";
// display the form // display the form
if ($create) { if (isset($create)) {
if ($discrepancy_text && $reported_by) { if ($discrepancy_text!=NULL && $reported_by!=NULL) {
format_message(0,"<strong>Writeup created.</strong> You may create another writeup or <a href=\"writeups.php\">return to Open Writeups page.</a>"); format_message(0,"<strong>Writeup created.</strong> You may create another writeup or <a href=\"writeups.php\">return to Open Writeups page.</a>");
$preserve=FALSE; $preserve=false;
} }
if (!$device) { if ($device==NULL) {
format_message(1,"You didn't select a $device_term. Please try again."); format_message(1,"You didn't select a $device_term. Please try again.");
$preserve=TRUE; $preserve=true;
} }
if (!$subsystem) { if ($subsystem==NULL) {
format_message(1,"You didn't select a subsystem. Please try again."); format_message(1,"You didn't select a subsystem. Please try again.");
$preserve=TRUE; $preserve=true;
} }
if (!$discovered) { if ($discovered==NULL) {
format_message(1,"You didn't select a $discovered_term. Please try again."); format_message(1,"You didn't select a $discovered_term. Please try again.");
$preserve=TRUE; $preserve=true;
} }
if (!$discrepancy_text) { if ($discrepancy_text==NULL) {
format_message(1,"You didn't enter any discrepancy text. Please try again."); format_message(1,"You didn't enter any discrepancy text. Please try again.");
$preserve=TRUE; $preserve=true;
} }
if (!$reported_by) { if ($reported_by==NULL) {
format_message(1,"You didn't enter your name in the Reported by: block. Please try again."); format_message(1,"You didn't enter your name in the Reported by: block. Please try again.");
$preserve=TRUE; $preserve=true;
} }
} else { } else {
$preserve=FALSE; $preserve=false;
} }
echo " echo "
@@ -135,9 +156,6 @@ echo "
"; ";
// start writeup entry section // start writeup entry section
if ($status==1) $statusind="<b><font color=\"#FF0000\">OPEN</font></b>";
if ($status==2) $statusind="<b><font color=\"#008000\">CLSD</font></b>";
if ($status==3) $statusind="<b><font color=\"#FFFF00\">DFRD</font></b>";
echo " echo "
<table border=\"0\" cellpadding=\"5\"> <table border=\"0\" cellpadding=\"5\">
@@ -185,7 +203,7 @@ if ($disc_drop_data=="Name") {
} }
$drow=mysqli_query($drs_db,"select * from discovered where active is true order by whendiscoveredname asc"); $drow=mysqli_query($drs_db,"select * from discovered where active is true order by whendiscoveredname asc");
while ($ditem=mysqli_fetch_assoc($drow)) { while ($ditem=mysqli_fetch_assoc($drow)) {
if ($discoverd==$ditem["id"] && $preserve) { if ($discovered==$ditem["id"] && $preserve) {
printf("<option value=\"%s\" title=\"%s\" selected>%s</option>",$ditem["id"],$ditem["$discddtitle"],$ditem["$discddtext"]); printf("<option value=\"%s\" title=\"%s\" selected>%s</option>",$ditem["id"],$ditem["$discddtitle"],$ditem["$discddtext"]);
} else { } else {
printf("<option value=\"%s\" title=\"%s\">%s</option>",$ditem["id"],$ditem["$discddtitle"],$ditem["$discddtext"]); printf("<option value=\"%s\" title=\"%s\">%s</option>",$ditem["id"],$ditem["$discddtitle"],$ditem["$discddtext"]);
@@ -207,12 +225,20 @@ if ($preserve) {
$funcyesstate="checked"; $funcyesstate="checked";
} }
echo "</select></td>";
if (!$role) {
$timedatedisable="disabled";
} else {
$timedatedisable="";
}
echo " echo "
</select></td>
<td align=\"left\" >Report Date<br> <td align=\"left\" >Report Date<br>
<input type=\"text\" name=\"report_date\" size=\"10\" maxlength=\"10\" value=\"$report_date\" id=\"singledatepicker\" title=\"Format: YYYY-MM-DD\"></td> <input type=\"text\" name=\"report_date\" size=\"10\" maxlength=\"10\" value=\"$report_date\" id=\"singledatepicker\" title=\"Format: YYYY-MM-DD\" $timedatedisable></td>
<td align=\"left\">Report Time<br> <td align=\"left\">Report Time<br>
<input type=\"text\" name=\"report_time\" size=\"8\" maxlength=\"8\" value=\"$report_time\" title=\"Format: HH:MM:SS\"></td> <input type=\"text\" name=\"report_time\" size=\"8\" maxlength=\"8\" value=\"$report_time\" title=\"Format: HH:MM:SS\" $timedatedisable></td>
";
echo "
</tr> </tr>
<tr><td></td><td></td><td></td></tr> <tr><td></td><td></td><td></td></tr>
<tr><td colspan=\"3\"> <tr><td colspan=\"3\">

View File

@@ -2,15 +2,19 @@
/* /*
dbadmin.php dbadmin.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to index.php on cancel button press // redirect to index.php on cancel button press
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
header("Location:index.php"); header("Location:index.php");
@@ -30,7 +34,6 @@ if ($role != ADMIN) {
} }
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming[] // form as "all_parameters" so we need to load those into $incoming[]
@@ -40,53 +43,85 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
$edit_user=$incoming['edit_user']; extract($incoming, EXTR_SKIP);
$add_user=$incoming['add_user']; /*
$update_user=$incoming['update_user']; * possible keys are:
$delete_user=$incoming['delete_user']; * edit_user
$user_id=$incoming['user_id']; * add_user
$user_fname=$incoming['user_fname']; * update_user
$user_lname=$incoming['user_lname']; * delete_user
$user_login=$incoming['user_login']; * user_id
$user_pass=$incoming['user_pass']; * user_fname
$user_passconf=$incoming['user_passconf']; * user_lname
$user_role=$incoming['user_role']; * user_login
$user_active=$incoming['user_active']; * user_pass
* user_passconf
* user_role
* user_active
* edit_device
* add_device
* update_device
* delete_device
* device_id
* device_name
* device_active
* edit_subsystem
* add_subsystem
* update_subsystem
* delete_subsystem
* subsystem_id
* subsystem_name
* subsystem_desc
* subsystem_active
* edit_reason
* add_reason
* update_reason
* delete_reason
* reason_id
* reason_text
* reason_active
* edit_discovered
* add_discovered
* update_discovered
* delete_discovered
* discovered_id
* discovered_name
* discovered_desc
* discovered_active
*/
$edit_device=$incoming['edit_device']; if (!isset($edit_user)) $edit_user=false;
$add_device=$incoming['add_device']; if (!isset($add_user)) $add_user=false;
$update_device=$incoming['update_device']; if (!isset($update_user)) $update_user=false;
$delete_device=$incoming['delete_device']; if (!isset($delete_user)) $delete_user=false;
$device_id=$incoming['device_id']; if (!isset($edit_device)) $edit_device=false;
$device_name=$incoming['device_name']; if (!isset($add_device)) $add_device=false;
$device_active=$incoming['device_active']; if (!isset($update_device)) $update_device=false;
if (!isset($delete_device)) $delete_device=false;
$edit_subsystem=$incoming['edit_subsystem']; if (!isset($edit_subsystem)) $edit_subsystem=false;
$add_subsystem=$incoming['add_subsystem']; if (!isset($add_subsystem)) $add_subsystem=false;
$update_subsystem=$incoming['update_subsystem']; if (!isset($update_subsystem)) $update_subsystem=false;
$delete_subsystem=$incoming['delete_subsystem']; if (!isset($delete_subsystem)) $delete_subsystem=false;
$subsystem_id=$incoming['subsystem_id']; if (!isset($edit_reason)) $edit_reason=false;
$subsystem_name=$incoming['subsystem_name']; if (!isset($add_reason)) $add_reason=false;
$subsystem_desc=$incoming['subsystem_desc']; if (!isset($update_reason)) $update_reason=false;
$subsystem_active=$incoming['subsystem_active']; if (!isset($delete_reason)) $delete_reason=false;
if (!isset($edit_discovered)) $edit_discovered=false;
$edit_reason=$incoming['edit_reason']; if (!isset($add_discovered)) $add_discovered=false;
$add_reason=$incoming['add_reason']; if (!isset($update_discovered)) $update_discovered=false;
$update_reason=$incoming['update_reason']; if (!isset($delete_discovered)) $delete_discovered=false;
$delete_reason=$incoming['delete_reason']; if (!isset($user_fname)) $user_fname=NULL;
$reason_id=$incoming['reason_id']; if (!isset($user_lname)) $user_lname=NULL;
$reason_text=$incoming['reason_text']; if (!isset($user_login)) $user_login=NULL;
$reason_active=$incoming['reason_active']; if (!isset($user_pass)) $user_pass=NULL;
if (!isset($user_passconf)) $user_passconf=NULL;
$edit_discovered=$incoming['edit_discovered']; if (!isset($device_name)) $device_name=NULL;
$add_discovered=$incoming['add_discovered']; if (!isset($subsystem_name)) $subsystem_name=NULL;
$update_discovered=$incoming['update_discovered']; if (!isset($subsystem_desc)) $subsystem_desc=NULL;
$delete_discovered=$incoming['delete_discovered']; if (!isset($reason_text)) $reason_text=NULL;
$discovered_id=$incoming['discovered_id']; if (!isset($discovered_name)) $discovered_name=NULL;
$discovered_name=$incoming['discovered_name']; if (!isset($discovered_desc)) $discovered_desc=NULL;
$discovered_desc=$incoming['discovered_desc'];
$discovered_active=$incoming['discovered_active'];
// define local functions // define local functions
@@ -94,7 +129,7 @@ $discovered_active=$incoming['discovered_active'];
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
if ($print=="Printer Friendly") { if ($print) {
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
@@ -110,6 +145,11 @@ framework("begin","$appname","Database Administration",$print);
// ******** begin database manipulation ******** // ******** begin database manipulation ********
// users------------------------------------- // users-------------------------------------
$usernameunique_err=$fnamesuppld_err=$lnamesuppld_err=false;
$loginsuppld_err=$loginunique_err=$passcomplex_err=$passmatch_err=false;
$userhaswriteups_err=false;
$user_add_fail=false;
if ($add_user) { if ($add_user) {
// do error checking // do error checking
// remove html tags from user name // remove html tags from user name
@@ -119,6 +159,7 @@ if ($add_user) {
// test for first name supplied // test for first name supplied
if (strlen(trim($user_fname))) { if (strlen(trim($user_fname))) {
$fnamesuppld=true; $fnamesuppld=true;
$fnamesuppld_err=false;
} else { } else {
$fnamesuppld=false; $fnamesuppld=false;
$fnamesuppld_err=true; $fnamesuppld_err=true;
@@ -126,6 +167,7 @@ if ($add_user) {
// test for last name supplied // test for last name supplied
if (strlen(trim($user_lname))) { if (strlen(trim($user_lname))) {
$lnamesuppld=true; $lnamesuppld=true;
$lnamesuppld_err=false;
} else { } else {
$lnamesuppld=false; $lnamesuppld=false;
$lnamesuppld_err=true; $lnamesuppld_err=true;
@@ -136,10 +178,12 @@ if ($add_user) {
$usernameunique_err=true; $usernameunique_err=true;
} else { } else {
$usernameunique=true; $usernameunique=true;
$usernameunique_err=false;
} }
// test for login supplied // test for login supplied
if (strlen(trim($user_login))) { if (strlen(trim($user_login))) {
$loginsuppld=true; $loginsuppld=true;
$loginsuppld_err=false;
} else { } else {
$loginsuppld=false; $loginsuppld=false;
$loginsuppld_err=true; $loginsuppld_err=true;
@@ -150,27 +194,30 @@ if ($add_user) {
$loginunique_err=true; $loginunique_err=true;
} else { } else {
$loginunique=true; $loginunique=true;
$loginunique_err=false;
} }
// test passwords // test passwords
$passresults=validate_password($user_pass,$user_passconf); $passresults=validate_password($user_pass,$user_passconf);
if ($passresults['match']) { if ($passresults['match']) {
$passmatch=true; $passmatch=true;
$passmatch_err=false;
} else { } else {
$passmatch=false; $passmatch=false;
$passmatch_err=true; $passmatch_err=true;
} }
if ($passresults['complex']) { if ($passresults['complex']) {
$passcomplex=true; $passcomplex=true;
$passcomplex_err=false;
} else { } else {
$passcomplex=false; $passcomplex=false;
$passcomplex_err=true; $passcomplex_err=true;
} }
// set role // set role
if (!$user_role) $user_role=USER; if (!isset($user_role)) $user_role=USER;
// set active status // set active status
if (!$user_active) $user_active=0; if (!isset($user_active)) $user_active=0;
if ($fnamesuppld && $lnamesuppld && $usernameunique && $loginsuppld && $loginunique && $passcomplex && $passmatch) { if ($fnamesuppld && $lnamesuppld && $usernameunique && $loginsuppld && $loginunique && $passcomplex && $passmatch) {
// sanitize first name, last name, login // sanitize first name, last name, login
@@ -181,6 +228,7 @@ if ($add_user) {
$passhash=password_hash($user_pass,PASSWORD_DEFAULT); $passhash=password_hash($user_pass,PASSWORD_DEFAULT);
// modify the table // modify the table
mysqli_query($drs_db,"insert into users(firstname,lastname,login,password_hash,role,active) values(\"$clean_fname\",\"$clean_lname\",\"$clean_login\",\"$passhash\",\"$user_role\",\"$user_active\")"); mysqli_query($drs_db,"insert into users(firstname,lastname,login,password_hash,role,active) values(\"$clean_fname\",\"$clean_lname\",\"$clean_login\",\"$passhash\",\"$user_role\",\"$user_active\")");
$user_add_fail=false;
} else { } else {
$user_add_fail=true; $user_add_fail=true;
} }
@@ -194,6 +242,7 @@ if ($edit_user) {
$userhaswriteups_err=true; $userhaswriteups_err=true;
} else { } else {
$userhaswriteups=false; $userhaswriteups=false;
$userhaswriteups_err=false;
} }
// if none, then remove from db // if none, then remove from db
if (!$userhaswriteups) mysqli_query($drs_db,"delete from users where id=\"$user_id\""); if (!$userhaswriteups) mysqli_query($drs_db,"delete from users where id=\"$user_id\"");
@@ -207,6 +256,7 @@ if ($edit_user) {
// test for first name supplied // test for first name supplied
if (strlen(trim($user_fname))) { if (strlen(trim($user_fname))) {
$fnamesuppld=true; $fnamesuppld=true;
$fnamesuppld_err=false;
} else { } else {
$fnamesuppld=false; $fnamesuppld=false;
$fnamesuppld_err=true; $fnamesuppld_err=true;
@@ -214,6 +264,7 @@ if ($edit_user) {
// test for last name supplied // test for last name supplied
if (strlen(trim($user_lname))) { if (strlen(trim($user_lname))) {
$lnamesuppld=true; $lnamesuppld=true;
$lnamesuppld_err=false;
} else { } else {
$lnamesuppld=false; $lnamesuppld=false;
$lnamesuppld_err=true; $lnamesuppld_err=true;
@@ -225,13 +276,16 @@ if ($edit_user) {
$nameunique_err=true; $nameunique_err=true;
} else { } else {
$nameunique=true; $nameunique=true;
$nameunique_err=false;
} }
} else { } else {
$nameunique=true; $nameunique=true;
$nameunique_err=false;
} }
// test for login supplied // test for login supplied
if (strlen(trim($user_login))) { if (strlen(trim($user_login))) {
$loginsuppld=true; $loginsuppld=true;
$loginsuppld_err=false;
} else { } else {
$loginsuppld=false; $loginsuppld=false;
$loginsuppld_err=true; $loginsuppld_err=true;
@@ -243,9 +297,11 @@ if ($edit_user) {
$loginunique_err=true; $loginunique_err=true;
} else { } else {
$loginunique=true; $loginunique=true;
$loginunique_err=false;
} }
} else { } else {
$loginunique=true; $loginunique=true;
$loginunique_err=false;
} }
// sanitize first name, last name, login // sanitize first name, last name, login
$clean_fname=mysqli_real_escape_string($drs_db,$user_fname); $clean_fname=mysqli_real_escape_string($drs_db,$user_fname);
@@ -253,22 +309,24 @@ if ($edit_user) {
$clean_login=mysqli_real_escape_string($drs_db,$user_login); $clean_login=mysqli_real_escape_string($drs_db,$user_login);
// set role // set role
if (!$user_role) $user_role=USER; if (!isset($user_role)) $user_role=USER;
// set active status // set active status
if (!$user_active) $user_active=0; if (!isset($user_active)) $user_active=0;
if ($user_pass!="password_is_unchanged") { if ($user_pass!="password_is_unchanged") {
// test passwords // test passwords
$passresults=validate_password($user_pass,$user_passconf); $passresults=validate_password($user_pass,$user_passconf);
if ($passresults['match']) { if ($passresults['match']) {
$passmatch=true; $passmatch=true;
$passmatch_err=false;
} else { } else {
$passmatch=false; $passmatch=false;
$passmatch_err=true; $passmatch_err=true;
} }
if ($passresults['complex']) { if ($passresults['complex']) {
$passcomplex=true; $passcomplex=true;
$passcomplex_err=false;
} else { } else {
$passcomplex=false; $passcomplex=false;
$passcomplex_err=true; $passcomplex_err=true;
@@ -290,6 +348,10 @@ if ($edit_user) {
} }
// devices------------------------------- // devices-------------------------------
$devicenameunique_err=$devicenamesuppld_err=false;
$devicehaswriteups_err=false;
$device_add_fail=false;
if ($add_device) { if ($add_device) {
// do error checking // do error checking
// remove html tags from device name // remove html tags from device name
@@ -297,6 +359,7 @@ if ($add_device) {
// test for device name supplied // test for device name supplied
if (strlen(trim($device_name))) { if (strlen(trim($device_name))) {
$devicenamesuppld=true; $devicenamesuppld=true;
$devicenamesuppld_err=false;
} else { } else {
$devicenamesuppld=false; $devicenamesuppld=false;
$devicenamesuppld_err=true; $devicenamesuppld_err=true;
@@ -307,16 +370,18 @@ if ($add_device) {
$devicenameunique_err=true; $devicenameunique_err=true;
} else { } else {
$devicenameunique=true; $devicenameunique=true;
$devicenameunique_err=false;
} }
// set active status // set active status
if (!$device_active) $device_active=0; if (!isset($device_active)) $device_active=0;
if ($devicenamesuppld && $devicenameunique) { if ($devicenamesuppld && $devicenameunique) {
// sanitize device name // sanitize device name
$clean_devicename=mysqli_real_escape_string($drs_db,$device_name); $clean_devicename=mysqli_real_escape_string($drs_db,$device_name);
// modify the table // modify the table
mysqli_query($drs_db,"insert into devices(name,active) values(\"$clean_devicename\",\"$device_active\")"); mysqli_query($drs_db,"insert into devices(name,active) values(\"$clean_devicename\",\"$device_active\")");
$device_add_fail=false;
} else { } else {
$device_add_fail=true; $device_add_fail=true;
} }
@@ -329,6 +394,7 @@ if ($edit_device) {
$devicehaswriteups_err=true; $devicehaswriteups_err=true;
} else { } else {
$devicehaswriteups=false; $devicehaswriteups=false;
$devicehaswriteups_err=false;
} }
// if none, then remove from db // if none, then remove from db
if (!$devicehaswriteups) mysqli_query($drs_db,"delete from devices where id=\"$device_id\""); if (!$devicehaswriteups) mysqli_query($drs_db,"delete from devices where id=\"$device_id\"");
@@ -340,6 +406,7 @@ if ($edit_device) {
// test for device name supplied // test for device name supplied
if (strlen(trim($device_name))) { if (strlen(trim($device_name))) {
$devicenamesuppld=true; $devicenamesuppld=true;
$devicenamesuppld_err=false;
} else { } else {
$devicenamesuppld=false; $devicenamesuppld=false;
$devicenamesuppld_err=true; $devicenamesuppld_err=true;
@@ -351,13 +418,15 @@ if ($edit_device) {
$devicenameunique_err=true; $devicenameunique_err=true;
} else { } else {
$devicenameunique=true; $devicenameunique=true;
$devicenameunique_err=false;
} }
} else { } else {
$devicenameunique=true; $devicenameunique=true;
$devicenameunique_err=false;
} }
// set active status // set active status
if (!$user_active) $user_active=0; if (!isset($device_active)) $device_active=0;
// sanitize device name // sanitize device name
$clean_devicename=mysqli_real_escape_string($drs_db,$device_name); $clean_devicename=mysqli_real_escape_string($drs_db,$device_name);
@@ -370,6 +439,10 @@ if ($edit_device) {
} }
// subsystems-------------------------------- // subsystems--------------------------------
$ssnameunique_err=$ssnamesuppld_err=false;
$sshaswriteups_err=false;
$subsystem_add_fail=false;
if ($add_subsystem) { if ($add_subsystem) {
// do error checking // do error checking
// remove html tags from subsystem name and description // remove html tags from subsystem name and description
@@ -378,6 +451,7 @@ if ($add_subsystem) {
// test for subsystem name supplied // test for subsystem name supplied
if (strlen(trim($subsystem_name))) { if (strlen(trim($subsystem_name))) {
$ssnamesuppld=true; $ssnamesuppld=true;
$ssnamesuppld_err=false;
} else { } else {
$ssnamesuppld=false; $ssnamesuppld=false;
$ssnamesuppld_err=true; $ssnamesuppld_err=true;
@@ -388,10 +462,11 @@ if ($add_subsystem) {
$ssnameunique_err=true; $ssnameunique_err=true;
} else { } else {
$ssnameunique=true; $ssnameunique=true;
$ssnameunique_err=false;
} }
// set active status // set active status
if (!$subsystem_active) $subsystem_active=0; if (!isset($subsystem_active)) $subsystem_active=0;
if ($ssnamesuppld && $ssnameunique) { if ($ssnamesuppld && $ssnameunique) {
// sanitize subsystem name and description // sanitize subsystem name and description
@@ -399,6 +474,7 @@ if ($add_subsystem) {
$clean_subsystemdesc=mysqli_real_escape_string($drs_db,$subsystem_desc); $clean_subsystemdesc=mysqli_real_escape_string($drs_db,$subsystem_desc);
// modify the table // modify the table
mysqli_query($drs_db,"insert into subsystems(name,description,active) values(\"$clean_subsystemname\",\"$clean_subsystemdesc\",\"$subsystem_active\")"); mysqli_query($drs_db,"insert into subsystems(name,description,active) values(\"$clean_subsystemname\",\"$clean_subsystemdesc\",\"$subsystem_active\")");
$subsystem_add_fail=false;
} else { } else {
$subsystem_add_fail=true; $subsystem_add_fail=true;
} }
@@ -411,6 +487,7 @@ if ($edit_subsystem) {
$sshaswriteups_err=true; $sshaswriteups_err=true;
} else { } else {
$sshaswriteups=false; $sshaswriteups=false;
$sshaswriteups_err=false;
} }
// if none, then remove from db // if none, then remove from db
if (!$sshaswriteups) mysqli_query($drs_db,"delete from subsystems where id=\"$subsystem_id\""); if (!$sshaswriteups) mysqli_query($drs_db,"delete from subsystems where id=\"$subsystem_id\"");
@@ -423,6 +500,7 @@ if ($edit_subsystem) {
// test for subsystem name supplied // test for subsystem name supplied
if (strlen(trim($subsystem_name))) { if (strlen(trim($subsystem_name))) {
$ssnamesuppld=true; $ssnamesuppld=true;
$ssnamesuppld_err=false;
} else { } else {
$ssnamesuppld=false; $ssnamesuppld=false;
$ssnamesuppld_err=true; $ssnamesuppld_err=true;
@@ -434,9 +512,11 @@ if ($edit_subsystem) {
$ssnameunique_err=true; $ssnameunique_err=true;
} else { } else {
$ssnameunique=true; $ssnameunique=true;
$ssnameunique_err=false;
} }
} else { } else {
$ssnameunique=true; $ssnameunique=true;
$ssnameunique_err=false;
} }
// sanitize subsystem name and description // sanitize subsystem name and description
$clean_ssname=mysqli_real_escape_string($drs_db,$subsystem_name); $clean_ssname=mysqli_real_escape_string($drs_db,$subsystem_name);
@@ -450,6 +530,10 @@ if ($edit_subsystem) {
} }
// reasons------------------------------------ // reasons------------------------------------
$reastextunique_err=$reastextsuppld_err=false;
$reashaswriteups_err=false;
$reason_add_fail=false;
if ($add_reason) { if ($add_reason) {
// do error checking // do error checking
// remove html tags from reason text // remove html tags from reason text
@@ -457,6 +541,7 @@ if ($add_reason) {
// test for reason text supplied // test for reason text supplied
if (strlen(trim($reason_text))) { if (strlen(trim($reason_text))) {
$reastextsuppld=true; $reastextsuppld=true;
$reastextsuppld_err=false;
} else { } else {
$reastextsuppld=false; $reastextsuppld=false;
$reastextsuppld_err=true; $reastextsuppld_err=true;
@@ -467,16 +552,18 @@ if ($add_reason) {
$reastextunique_err=true; $reastextunique_err=true;
} else { } else {
$reastextunique=true; $reastextunique=true;
$reastextunique_err=false;
} }
// set active status // set active status
if (!$reason_active) $reason_active=0; if (!isset($reason_active)) $reason_active=0;
if ($reastextsuppld && $reastextunique) { if ($reastextsuppld && $reastextunique) {
// sanitize reason text // sanitize reason text
$clean_reastext=mysqli_real_escape_string($drs_db,$reason_text); $clean_reastext=mysqli_real_escape_string($drs_db,$reason_text);
// modify the table // modify the table
mysqli_query($drs_db,"insert into reasons(text,active) values(\"$clean_reastext\",\"$reason_active\")"); mysqli_query($drs_db,"insert into reasons(text,active) values(\"$clean_reastext\",\"$reason_active\")");
$reason_add_fail=false;
} else { } else {
$reason_add_fail=true; $reason_add_fail=true;
} }
@@ -489,6 +576,7 @@ if ($edit_reason) {
$reashaswriteups_err=true; $reashaswriteups_err=true;
} else { } else {
$reashaswriteups=false; $reashaswriteups=false;
$reashaswriteups_err=false;
} }
// if none, then remove from db // if none, then remove from db
if (!$reashaswriteups) mysqli_query($drs_db,"delete from reasons where id=\"$reason_id\""); if (!$reashaswriteups) mysqli_query($drs_db,"delete from reasons where id=\"$reason_id\"");
@@ -500,6 +588,7 @@ if ($edit_reason) {
// test for reason text supplied // test for reason text supplied
if (strlen(trim($reason_text))) { if (strlen(trim($reason_text))) {
$reastextsuppld=true; $reastextsuppld=true;
$reastextsuppld_err=false;
} else { } else {
$reastextsuppld=false; $reastextsuppld=false;
$reastextsuppld_err=true; $reastextsuppld_err=true;
@@ -511,13 +600,15 @@ if ($edit_reason) {
$reastextunique_err=true; $reastextunique_err=true;
} else { } else {
$reastextunique=true; $reastextunique=true;
$reastextunique_err=false;
} }
} else { } else {
$reastextunique=true; $reastextunique=true;
$reastextunique_err=false;
} }
// set active status // set active status
if (!$reason_active) $reason_active=0; if (!isset($reason_active)) $reason_active=0;
// sanitize reason text // sanitize reason text
$clean_reastext=mysqli_real_escape_string($drs_db,$reason_text); $clean_reastext=mysqli_real_escape_string($drs_db,$reason_text);
@@ -530,6 +621,10 @@ if ($edit_reason) {
} }
// when discovered----------------------------------- // when discovered-----------------------------------
$discnamesuppld_err=$discnameunique_err=$discdescsuppld_err=false;
$dischaswriteups_err=false;
$discovered_add_fail=false;
if ($add_discovered) { if ($add_discovered) {
// do error checking // do error checking
// remove html tags from name and description // remove html tags from name and description
@@ -538,6 +633,7 @@ if ($add_discovered) {
// test for name supplied // test for name supplied
if (strlen(trim($discovered_name))) { if (strlen(trim($discovered_name))) {
$discnamesuppld=true; $discnamesuppld=true;
$discnamesuppld_err=false;
} else { } else {
$discnamesuppld=false; $discnamesuppld=false;
$discnamesuppld_err=true; $discnamesuppld_err=true;
@@ -548,24 +644,27 @@ if ($add_discovered) {
$discnameunique_err=true; $discnameunique_err=true;
} else { } else {
$discnameunique=true; $discnameunique=true;
$discnameunique_err=false;
} }
// test for description supplied // test for description supplied
if (strlen(trim($discovered_desc))) { if (strlen(trim($discovered_desc))) {
$discdescsuppld=true; $discdescsuppld=true;
$discdescsuppld_err=false;
} else { } else {
$discdescsuppld=false; $discdescsuppld=false;
$discdescsuppld_err=true; $discdescsuppld_err=true;
} }
// test for description unique // test for description unique
if (mysqli_num_rows(mysqli_query($drs_db,"select id from description where whendiscovereddesc =\"$discovered_desc\""))) { if (mysqli_num_rows(mysqli_query($drs_db,"select id from discovered where whendiscovereddesc =\"$discovered_desc\""))) {
$discdescunique=false; $discdescunique=false;
$discdescunique_err=true; $discdescunique_err=true;
} else { } else {
$discdescunique=true; $discdescunique=true;
$discdescunique_err=false;
} }
// set active status // set active status
if (!$discovered_active) $discovered_active=0; if (!isset($discovered_active)) $discovered_active=0;
if ($discnamesuppld && $discnameunique && $discdescsuppld) { if ($discnamesuppld && $discnameunique && $discdescsuppld) {
// sanitize name // sanitize name
@@ -574,6 +673,7 @@ if ($add_discovered) {
$clean_discovered_desc=mysqli_real_escape_string($drs_db,$discovered_desc); $clean_discovered_desc=mysqli_real_escape_string($drs_db,$discovered_desc);
// modify the table // modify the table
mysqli_query($drs_db,"insert into discovered(whendiscoveredname,whendiscovereddesc,active) values(\"$clean_discovered_name\",\"$clean_discovered_desc\",\"$discovered_active\")"); mysqli_query($drs_db,"insert into discovered(whendiscoveredname,whendiscovereddesc,active) values(\"$clean_discovered_name\",\"$clean_discovered_desc\",\"$discovered_active\")");
$discovered_add_fail=false;
} else { } else {
$discovered_add_fail=true; $discovered_add_fail=true;
} }
@@ -586,6 +686,7 @@ if ($edit_discovered) {
$dischaswriteups_err=true; $dischaswriteups_err=true;
} else { } else {
$dischaswriteups=false; $dischaswriteups=false;
$dischaswriteups_err=false;
} }
// if none, then remove from db // if none, then remove from db
if (!$dischaswriteups) mysqli_query($drs_db,"delete from discovered where id=\"$discovered_id\""); if (!$dischaswriteups) mysqli_query($drs_db,"delete from discovered where id=\"$discovered_id\"");
@@ -598,6 +699,7 @@ if ($edit_discovered) {
// test for name supplied // test for name supplied
if (strlen(trim($discovered_name))) { if (strlen(trim($discovered_name))) {
$discnamesuppld=true; $discnamesuppld=true;
$discnamesuppld_err=false;
} else { } else {
$discnamesuppld=false; $discnamesuppld=false;
$discnamesuppld_err=true; $discnamesuppld_err=true;
@@ -609,30 +711,23 @@ if ($edit_discovered) {
$discnameunique_err=true; $discnameunique_err=true;
} else { } else {
$discnameunique=true; $discnameunique=true;
$discnameunique_err=false;
} }
} else { } else {
$discnameunique=true; $discnameunique=true;
$discnameunique_err=false;
} }
// test for description supplied // test for description supplied
if (strlen(trim($discovered_desc))) { if (strlen(trim($discovered_desc))) {
$discdescsuppld=true; $discdescsuppld=true;
$discdescsuppld_err=false;
} else { } else {
$discdescsuppld=false; $discdescsuppld=false;
$discdescsuppld_err=true; $discdescsuppld_err=true;
} }
// test for description unique
if (mysqli_num_rows(mysqli_query($drs_db,"select id from discovered where whendiscovereddesc=\"$discovered_text\" and id!=\"$discovered_id\""))) {
if (mysqli_num_rows(mysqli_query($drs_db,"select id from discovered where whendiscovereddesc =\"$discovered_desc\""))) {
$discdescunique=false;
$discdescunique_err=true;
} else {
$discdescunique=true;
}
} else {
$discdescunique=true;
}
// set active status // set active status
if (!$discovered_active) $discovered_active=0; if (!isset($discovered_active)) $discovered_active=0;
// sanitize name // sanitize name
$clean_discovered_name=mysqli_real_escape_string($drs_db,$discovered_name); $clean_discovered_name=mysqli_real_escape_string($drs_db,$discovered_name);
@@ -640,7 +735,7 @@ if ($edit_discovered) {
$clean_discovered_desc=mysqli_real_escape_string($drs_db,$discovered_desc); $clean_discovered_desc=mysqli_real_escape_string($drs_db,$discovered_desc);
$updqry="update discovered set whendiscoveredname=\"$clean_discovered_name\",whendiscovereddesc=\"$clean_discovered_desc\",active=\"$discovered_active\" where id=\"$discovered_id\""; $updqry="update discovered set whendiscoveredname=\"$clean_discovered_name\",whendiscovereddesc=\"$clean_discovered_desc\",active=\"$discovered_active\" where id=\"$discovered_id\"";
if ($discnamesuppld && $discnameunique && $discdescsuppld && $discdescunique) { if ($discnamesuppld && $discnameunique && $discdescsuppld) {
// modify the table // modify the table
mysqli_query($drs_db,$updqry); mysqli_query($drs_db,$updqry);
} }
@@ -707,7 +802,7 @@ if ($edit_user && !$delete_user) {
} }
} else { } else {
// set form options for add // set form options for add
if (!$user_add_fail) unset($user_id,$user_fname,$user_lname,$user_login,$user_pass,$user_passconf,$user_role,$user_active); if (!$user_add_fail) $user_id=$user_fname=$user_lname=$user_login=$user_pass=$user_passconf=$user_role=$user_active=NULL;
$sectiontitle="<b><font size=\"+1\">Add New User</font></b><br><br>"; $sectiontitle="<b><font size=\"+1\">Add New User</font></b><br><br>";
$formtag="<form method=\"post\" action=\"dbadmin.php#users\">"; $formtag="<form method=\"post\" action=\"dbadmin.php#users\">";
$buttontags=" $buttontags="
@@ -812,7 +907,7 @@ if ($edit_device && !$delete_device) {
} }
} else { } else {
// set form options for add // set form options for add
if (!$device_add_fail) unset($device_id,$device_name,$device_active); if (!$device_add_fail) $device_id=$device_name=$device_active=NULL;
$sectiontitle="<b><font size=\"+1\">Add New Device</font></b><br><br>"; $sectiontitle="<b><font size=\"+1\">Add New Device</font></b><br><br>";
$formtag="<form method=\"post\" action=\"dbadmin.php#devices\">"; $formtag="<form method=\"post\" action=\"dbadmin.php#devices\">";
$buttontags=" $buttontags="
@@ -889,7 +984,7 @@ if ($edit_subsystem && !$delete_subsystem) {
} }
} else { } else {
// set form options for add // set form options for add
if (!$subsystem_add_fail) unset($subsystem_id,$subsystem_name,$subsystem_desc,$subsystem_active); if (!$subsystem_add_fail) $subsystem_id=$subsystem_name=$subsystem_desc=$subsystem_active=NULL;
$sectiontitle="<b><font size=\"+1\">Add New Subsystem</font></b><br><br>"; $sectiontitle="<b><font size=\"+1\">Add New Subsystem</font></b><br><br>";
$formtag="<form method=\"post\" action=\"dbadmin.php#subsystems\">"; $formtag="<form method=\"post\" action=\"dbadmin.php#subsystems\">";
$buttontags=" $buttontags="
@@ -969,7 +1064,7 @@ if ($edit_reason && !$delete_reason) {
} }
} else { } else {
// set form options for add // set form options for add
if (!$reason_add_fail) unset($reason_id,$reason_text,$reason_active); if (!$reason_add_fail) $reason_id=$reason_text=$reason_active=NULL;
$sectiontitle="<b><font size=\"+1\">Add New Reason</font></b><br><br>"; $sectiontitle="<b><font size=\"+1\">Add New Reason</font></b><br><br>";
$formtag="<form method=\"post\" action=\"dbadmin.php#reasons\">"; $formtag="<form method=\"post\" action=\"dbadmin.php#reasons\">";
$buttontags=" $buttontags="
@@ -1024,6 +1119,7 @@ echo "
"; ";
if ($discnamesuppld_err) format_message(1,"When Discovered name cannot be blank."); if ($discnamesuppld_err) format_message(1,"When Discovered name cannot be blank.");
if ($discnameunique_err) format_message(1,"When Discovered name already exists."); if ($discnameunique_err) format_message(1,"When Discovered name already exists.");
if ($discdescsuppld_err) format_message(1,"When Discovered description cannot be blank.");
if ($dischaswriteups_err) format_message(1,"When Discovered has writeups in the database and cannot be deleted."); if ($dischaswriteups_err) format_message(1,"When Discovered has writeups in the database and cannot be deleted.");
if ($edit_discovered && !$delete_discovered) { if ($edit_discovered && !$delete_discovered) {
@@ -1047,7 +1143,7 @@ if ($edit_discovered && !$delete_discovered) {
} }
} else { } else {
// set form options for add // set form options for add
if (!$discovered_add_fail) unset($discovered_id,$discovered_name,$discovered_desc,$discovered_active); if (!$discovered_add_fail) $discovered_id=$discovered_name=$discovered_desc=$discovered_active=NULL;
$sectiontitle="<b><font size=\"+1\">Add New When Discovered</font></b><br><br>"; $sectiontitle="<b><font size=\"+1\">Add New When Discovered</font></b><br><br>";
$formtag="<form method=\"post\" action=\"dbadmin.php#discovered\">"; $formtag="<form method=\"post\" action=\"dbadmin.php#discovered\">";
$buttontags=" $buttontags="

View File

@@ -2,18 +2,23 @@
/* /*
gpl.php gpl.php
OpenMTS Online Maintenance Tracking System OpenMTS Online Maintenance Tracking System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to index.php on cancel button press // redirect to search.php on cancel button press
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
header("Location:index.php"); header("Location:search.php");
exit(); exit();
} }
@@ -21,7 +26,6 @@ if ($_REQUEST['cancel']) {
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; if (isset($_SESSION['userid'])) $userid=$_SESSION['userid'];
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming // form as "all_parameters" so we need to load those into $incoming
@@ -31,7 +35,7 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
// define local functions // define local functions
@@ -40,15 +44,13 @@ if ($print) {
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
if ($print=="Printer Friendly") { if ($print) {
$sbcolor=P_SIDEBAR_COLOR;
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$sbcolor=SIDEBAR_COLOR;
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
} }
$role=dblookup($mts_db,"users","id","role",$userid); $role=dblookup($drs_db,"users","id","role",$userid);
framework("begin","$appname","GNU General Public License",$print); framework("begin","$appname","GNU General Public License",$print);

View File

@@ -2,15 +2,20 @@
/* /*
groups.php groups.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to groups.php on cancel button press // redirect to groups.php on cancel button press
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
header("Location:groups.php"); header("Location:groups.php");
@@ -18,10 +23,13 @@ if ($_REQUEST['cancel']) {
} }
// import session variables // import session variables
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; if (isset($_SESSION['userid'])) {
$userid=$_SESSION['userid'];
} else {
$userid=NULL;
}
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming // form as "all_parameters" so we need to load those into $incoming
@@ -31,33 +39,47 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
extract($incoming, EXTR_SKIP);
/*
* possible keys are:
* action
* save
* targets
* group
* name
* search
* s_status
* s_device
* s_subsystem
* s_discovered
* s_report_date_start
* s_report_date_end
* s_report_time_start
* s_report_time_end
* s_discrepancy_text
* s_reported_by
* s_functional
* edit_status
* edit_action_by
* edit_action_reason
* edit_action_date
* edit_action_time
* edit_action_text
*/
$action=$incoming['action']; if (!isset($action)) $action=NULL;
$save=$incoming['save']; if (!isset($s_discrepancy_text)) $s_discrepancy_text=NULL;
$targets=$incoming['targets']; if (!isset($s_reported_by)) $s_reported_by=NULL;
$group=$incoming['group']; if (!isset($edit_status)) $edit_status=NULL;
$name=$incoming['name']; if (!isset($edit_action_by)) $edit_action_by=NULL;
if (!isset($edit_action_reason)) $edit_action_reason=NULL;
if (!isset($edit_action_text)) $edit_action_text=NULL;
if (!isset($save)) $save=false;
if (!isset($search)) $search=false;
if (!isset($group)) $group=NULL;
if (!isset($name)) $name=NULL;
$search=$incoming['search'];
$s_status=$incoming['s_status'];
$s_device=$incoming['s_device'];
$s_subsystem=$incoming['s_subsystem'];
$s_discovered=$incoming['s_discovered'];
$s_report_date_start=$incoming['s_report_date_start'];
$s_report_date_end=$incoming['s_report_date_end'];
$s_report_time_start=$incoming['s_report_time_start'];
$s_report_time_end=$incoming['s_report_time_end'];
$s_discrepancy_text=$incoming['s_discrepancy_text'];
$s_reported_by=$incoming['s_reported_by'];
$s_functional=$incoming['s_functional'];
$edit_status=$incoming['edit_status'];
$edit_action_by=$incoming['edit_action_by'];
$edit_action_reason=$incoming['edit_action_reason'];
$edit_action_date=$incoming['edit_action_date'];
$edit_action_time=$incoming['edit_action_time'];
$edit_action_text=$incoming['edit_action_text'];
// define local functions // define local functions
@@ -65,11 +87,9 @@ $edit_action_text=$incoming['edit_action_text'];
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
if ($print=="Printer Friendly") { if ($print) {
$sbcolor=P_SIDEBAR_COLOR;
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$sbcolor=SIDEBAR_COLOR;
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
} }
@@ -91,17 +111,17 @@ $now=date("H:i:s");
// get max report date from writeups table, validate input dates/times and set defaults // get max report date from writeups table, validate input dates/times and set defaults
$maxrepdate_qry=mysqli_query($drs_db,"select max(report_date) from writeups"); $maxrepdate_qry=mysqli_query($drs_db,"select max(report_date) from writeups");
$maxrepdate=mysqli_fetch_row($maxrepdate_qry)[0]; $maxrepdate=mysqli_fetch_row($maxrepdate_qry)[0];
if (!$s_report_date_start || !validateDate($s_report_date_start)) $s_report_date_start=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 30 day)"))[0]; if (!isset($s_report_date_start) || !validateDate($s_report_date_start)) $s_report_date_start=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 30 day)"))[0];
if (!$s_report_date_end || !validateDate($s_report_date_end)) $s_report_date_end=$maxrepdate; if (!isset($s_report_date_end) || !validateDate($s_report_date_end)) $s_report_date_end=$maxrepdate;
if (!$s_report_time_start || !validateTime($s_report_time_start)) $s_report_time_start="00:00:00"; if (!isset($s_report_time_start) || !validateTime($s_report_time_start)) $s_report_time_start="00:00:00";
if (!$s_report_time_end || !validateTime($s_report_time_end)) $s_report_time_end="23:59:59"; if (!isset($s_report_time_end) || !validateTime($s_report_time_end)) $s_report_time_end="23:59:59";
if (!$edit_action_date || !validateDate($edit_action_date)) $edit_action_date=$today; if (!isset($edit_action_date) || !validateDate($edit_action_date)) $edit_action_date=$today;
if (!$edit_action_time || !validateTime($edit_action_time)) $edit_action_time=$now; if (!isset($edit_action_time) || !validateTime($edit_action_time)) $edit_action_time=$now;
if ($action=="add" && $role && $save) { if ($action=="add" && $role && $save) {
$fail=false; $fail=false;
if (!$group) { if ($group==NULL) {
// group was not supplied, so create a new one // group was not supplied, so create a new one
mysqli_query($drs_db,"insert into groups(name) value(\"\")"); mysqli_query($drs_db,"insert into groups(name) value(\"\")");
$fail=mysqli_error($drs_db); $fail=mysqli_error($drs_db);
@@ -117,18 +137,24 @@ if ($action=="add" && $role && $save) {
} }
} elseif ($action=="remove" && $role && $save) { } elseif ($action=="remove" && $role && $save) {
$fail=false; $fail=false;
$writeups=array(); $writeups=[];
$writeups_qry=mysqli_query($drs_db,"select writeupid from links where linkgroup=\"$group\""); $writeups_qry=mysqli_query($drs_db,"select writeupid from links where linkgroup=\"$group\"");
while ($writeuprow=mysqli_fetch_row($writeups_qry)) { while ($writeuprow=mysqli_fetch_row($writeups_qry)) {
$writeups[]=$writeuprow[0]; $writeups[]=$writeuprow[0];
} }
foreach ($writeups as $writeup) { foreach ($writeups as $writeup) {
if (!in_array($writeup,$targets)) { if (!isset($targets) || !in_array($writeup,$targets)) {
// remove writeup from group // remove writeup from group
mysqli_query($drs_db,"delete from links where writeupid=$writeup and linkgroup=$group"); mysqli_query($drs_db,"delete from links where writeupid=$writeup and linkgroup=$group");
$fail=mysqli_error($drs_db); $fail=mysqli_error($drs_db);
} }
} }
// if there are no longer any writeups in this group, dissolve it
$memb_qty_query=mysqli_query($drs_db,"select id from links where linkgroup=\"$group\"");
if (mysqli_num_rows($memb_qty_query) == 0) {
mysqli_query($drs_db,"delete from groups where id=$group");
$fail=mysqli_error($drs_db);
}
} elseif ($action=="dissolve" && $role && $save) { } elseif ($action=="dissolve" && $role && $save) {
$fail=false; $fail=false;
// unassign all writeups from a group and delete the group // unassign all writeups from a group and delete the group
@@ -148,7 +174,7 @@ if ($action=="add" && $role && $save) {
$fail=false; $fail=false;
// set the status, action by, reason action date/time and append supplied text to action text // set the status, action by, reason action date/time and append supplied text to action text
// for all ids in group // for all ids in group
if ($edit_action_text) { if ($edit_action_reason!=NULL) {
// sanitize date and time // sanitize date and time
$edit_action_date=mysqli_real_escape_string($drs_db,$edit_action_date); $edit_action_date=mysqli_real_escape_string($drs_db,$edit_action_date);
$edit_action_time=mysqli_real_escape_string($drs_db,$edit_action_time); $edit_action_time=mysqli_real_escape_string($drs_db,$edit_action_time);
@@ -160,22 +186,23 @@ if ($action=="add" && $role && $save) {
while ($edit_row=mysqli_fetch_row($groupmem_qry)) { while ($edit_row=mysqli_fetch_row($groupmem_qry)) {
$writeup_to_edit=$edit_row[0]; $writeup_to_edit=$edit_row[0];
$writeup_action_text=dblookup($drs_db,"writeups","id","action_text",$writeup_to_edit); $writeup_action_text=dblookup($drs_db,"writeups","id","action_text",$writeup_to_edit);
$full_action_text=$writeup_action_text." STATUS CHANGED: ".$clean_edit_action_text; $full_action_text=$writeup_action_text." GROUP ACTION TAKEN: ".$clean_edit_action_text;
mysqli_query($drs_db,"update writeups set status=\"$edit_status\",action_by=\"$edit_action_by\",action_date=\"$edit_action_date\",action_time=\"$edit_action_time\",action_reason=\"$edit_action_reason\",action_text=\"$full_action_text\" where id=\"$writeup_to_edit\""); mysqli_query($drs_db,"update writeups set status=\"$edit_status\",action_by=\"$edit_action_by\",action_date=\"$edit_action_date\",action_time=\"$edit_action_time\",action_reason=\"$edit_action_reason\",action_text=\"$full_action_text\" where id=\"$writeup_to_edit\"");
$fail=mysqli_error($drs_db); $fail=mysqli_error($drs_db);
} }
} else {
$fail="A status change reason was not selected.";
} }
} }
if ($search) { if ($search) {
// strip whitespace from beginning and end of text fields // strip whitespace from beginning and end of text fields
$s_reported_by=trim($s_reported_by); $s_reported_by=trim($s_reported_by);
$s_action_text=trim($s_action_text);
$s_discrepancy_text=trim($s_discrepancy_text); $s_discrepancy_text=trim($s_discrepancy_text);
// build the query string // build the query string
$query_string=""; $query_string="";
// device // device
if ($s_device) { if (isset($s_device)) {
$query_string="{$query_string}("; $query_string="{$query_string}(";
$device_param="Devices:"; $device_param="Devices:";
foreach ($s_device as $dev_val) { foreach ($s_device as $dev_val) {
@@ -191,7 +218,7 @@ if ($search) {
$query_string="{$query_string} and "; $query_string="{$query_string} and ";
} }
// subsystem // subsystem
if ($s_subsystem) { if (isset($s_subsystem)) {
$query_string="{$query_string}("; $query_string="{$query_string}(";
$subsystem_param="Subsystems:"; $subsystem_param="Subsystems:";
foreach ($s_subsystem as $sub_val) { foreach ($s_subsystem as $sub_val) {
@@ -207,7 +234,7 @@ if ($search) {
$query_string="{$query_string} and "; $query_string="{$query_string} and ";
} }
// discovered // discovered
if ($s_discovered) { if (isset($s_discovered)) {
$query_string="{$query_string}("; $query_string="{$query_string}(";
$discovered_param="{$discovered_term_short}s:"; $discovered_param="{$discovered_term_short}s:";
foreach ($s_discovered as $disc_val) { foreach ($s_discovered as $disc_val) {
@@ -223,7 +250,7 @@ if ($search) {
$query_string="{$query_string} and "; $query_string="{$query_string} and ";
} }
// functional // functional
if ($s_functional) { if (isset($s_functional)) {
$query_string="{$query_string}("; $query_string="{$query_string}(";
$func_param="$functional_term:"; $func_param="$functional_term:";
foreach ($s_functional as $func_val) { foreach ($s_functional as $func_val) {
@@ -238,7 +265,7 @@ if ($search) {
$query_string="{$query_string} and "; $query_string="{$query_string} and ";
} }
// status // status
if ($s_status) { if (isset($s_status)) {
$query_string="{$query_string}("; $query_string="{$query_string}(";
$status_param="Status:"; $status_param="Status:";
foreach ($s_status as $stat_val) { foreach ($s_status as $stat_val) {
@@ -266,7 +293,7 @@ if ($search) {
$query_string="{$query_string} and "; $query_string="{$query_string} and ";
$reporttime_param="Report time between {$s_report_time_start} and {$s_report_time_end}"; $reporttime_param="Report time between {$s_report_time_start} and {$s_report_time_end}";
// discrepancy text // discrepancy text
if ($s_discrepancy_text) { if (isset($s_discrepancy_text)) {
$query_string="{$query_string}("; $query_string="{$query_string}(";
$query_string="{$query_string}discrepancy_text like \"%{$s_discrepancy_text}%\""; $query_string="{$query_string}discrepancy_text like \"%{$s_discrepancy_text}%\"";
$query_string="{$query_string})"; $query_string="{$query_string})";
@@ -276,7 +303,7 @@ if ($search) {
$discrepancytext_param="Text in discrepancy: any"; $discrepancytext_param="Text in discrepancy: any";
} }
// reported by // reported by
if ($s_reported_by) { if (isset($s_reported_by)) {
$query_string="{$query_string}("; $query_string="{$query_string}(";
$query_string="{$query_string}reported_by like \"%{$s_reported_by}%\""; $query_string="{$query_string}reported_by like \"%{$s_reported_by}%\"";
$query_string="{$query_string})"; $query_string="{$query_string})";
@@ -303,6 +330,7 @@ banner($print);
echo "<br>"; echo "<br>";
if ($action=="add") { if ($action=="add") {
if (!isset($targets)) $targets=[];
if (count($targets) > 1) { if (count($targets) > 1) {
$plural="s"; $plural="s";
} else { } else {
@@ -774,9 +802,9 @@ if ($action=="add") {
<select name=\"edit_action_reason\" id=\"reason\"> <select name=\"edit_action_reason\" id=\"reason\">
"; ";
$reasrow=mysqli_query($drs_db,"select id,text from reasons where active is true order by id asc"); $reasrow=mysqli_query($drs_db,"select id,text from reasons where active is true order by id asc");
if (!$action_reason) echo "<option selected></option>"; if ($edit_action_reason==NULL) echo "<option selected></option>";
while ($reasitem=mysqli_fetch_assoc($reasrow)) { while ($reasitem=mysqli_fetch_assoc($reasrow)) {
if ($action_reason==$reasitem["id"]) { if ($edit_action_reason==$reasitem["id"]) {
printf("<option value=\"%s\" selected>%s</option>",$reasitem["id"],$reasitem["text"]); printf("<option value=\"%s\" selected>%s</option>",$reasitem["id"],$reasitem["text"]);
} else { } else {
printf("<option value=\"%s\">%s</option>",$reasitem["id"],$reasitem["text"]); printf("<option value=\"%s\">%s</option>",$reasitem["id"],$reasitem["text"]);
@@ -817,7 +845,7 @@ if ($action=="add") {
<hr> <hr>
"; ";
} }
if ($group) { if ($group!=NULL) {
// show only the requested group // show only the requested group
$mode="view"; $mode="view";
group_detail($group,$role,$mode); group_detail($group,$role,$mode);

View File

@@ -2,24 +2,49 @@
/* /*
login.php login.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=$_REQUEST['print']; $print=true;
$userid=$_REQUEST['userid']; } else {
$userlogin=$_REQUEST['userlogin']; $print=false;
$pass=$_REQUEST['pass'];
$login=$_REQUEST['login'];
$cancel=$_REQUEST['cancel'];
if ($cancel) {
session_destroy();
} }
// import incoming arrays
if ($print) {
// if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming[]
$incoming=unserialize($_REQUEST['all_parameters']);
} else {
// copy $_REQUEST[] to $incoming[]
$incoming=arrayCopy($_REQUEST);
}
// extract incoming array keys into variables
extract($incoming, EXTR_SKIP);
/*
* possible keys are:
* userid
* userlogin
* pass
* login
* cancel
*/
if (!isset($userlogin)) $userlogin=NULL;
if (!isset($pass)) $pass=NULL;
if (isset($cancel)) {
session_destroy();
} else {
$cancel=false;
}
$appname=APP_NAME; $appname=APP_NAME;
if ($print) { if ($print) {
@@ -44,7 +69,7 @@ if(!$print){
pageblock("left","end"); pageblock("left","end");
} }
pageblock("right","begin"); pageblock("right","begin");
if ($login) { if (isset($login)) {
// get the id from the userlogin // get the id from the userlogin
$userid=dblookup($drs_db,"users","login","id",$userlogin); $userid=dblookup($drs_db,"users","login","id",$userlogin);
$useractive=dblookup($drs_db,"users","id","active",$userid); $useractive=dblookup($drs_db,"users","id","active",$userid);

View File

@@ -2,15 +2,20 @@
/* /*
profile.php profile.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to index.php on cancel button press // redirect to index.php on cancel button press
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
header("Location:index.php"); header("Location:index.php");
@@ -30,7 +35,6 @@ if (!$role) {
} }
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming[] // form as "all_parameters" so we need to load those into $incoming[]
@@ -40,24 +44,34 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
$update_colors=$incoming['update_colors']; extract($incoming, EXTR_SKIP);
$reset_colors=$incoming['reset_colors']; /*
$newbgc=$incoming['newbgc']; * possible keys are:
$newmbgc=$incoming['newmbgc']; * update_colors
$newtc=$incoming['newtc']; * reset_colors
$newlc=$incoming['newlc']; * newbgc
$newvlc=$incoming['newvlc']; * newmbgc
$newhc=$incoming['newhc']; * newtc
* newlc
* newvlc
* newhc
* edit_user
* update_user
* user_id
* user_fname
* user_lname
* user_login
* user_pass
* user_passconf
*/
$edit_user=$incoming['edit_user'];
$update_user=$incoming['update_user'];
$user_id=$userid; // ensures that I can only change my own profile $user_id=$userid; // ensures that I can only change my own profile
$user_fname=$incoming['user_fname'];
$user_lname=$incoming['user_lname']; if (!isset($update_colors)) $update_colors=false;
$user_login=$incoming['user_login']; if (!isset($reset_colors)) $reset_colors=false;
$user_pass=$incoming['user_pass']; if (!isset($edit_user)) $edit_user=false;
$user_passconf=$incoming['user_passconf']; if (!isset($update_user)) $update_user=false;
// define local functions // define local functions
@@ -65,7 +79,7 @@ $user_passconf=$incoming['user_passconf'];
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
if ($print=="Printer Friendly") { if ($print) {
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
@@ -94,6 +108,9 @@ if ($reset_colors) {
echo "<meta http-equiv='refresh' content='0'>"; echo "<meta http-equiv='refresh' content='0'>";
} }
$usernameunique_err=$fnamesuppld_err=$lnamesuppld_err=$loginsuppld_err=false;
$loginunique_err=$passcomplex_err=$passmatch_err=false;
if ($edit_user) { if ($edit_user) {
if ($update_user) { if ($update_user) {
// do error checking // do error checking
@@ -104,6 +121,7 @@ if ($edit_user) {
// test for first name supplied // test for first name supplied
if (strlen(trim($user_fname))) { if (strlen(trim($user_fname))) {
$fnamesuppld=true; $fnamesuppld=true;
$fnamesuppld_err=false;
} else { } else {
$fnamesuppld=false; $fnamesuppld=false;
$fnamesuppld_err=true; $fnamesuppld_err=true;
@@ -111,6 +129,7 @@ if ($edit_user) {
// test for last name supplied // test for last name supplied
if (strlen(trim($user_lname))) { if (strlen(trim($user_lname))) {
$lnamesuppld=true; $lnamesuppld=true;
$lnamesuppld_err=false;
} else { } else {
$lnamesuppld=false; $lnamesuppld=false;
$lnamesuppld_err=true; $lnamesuppld_err=true;
@@ -122,13 +141,16 @@ if ($edit_user) {
$nameunique_err=true; $nameunique_err=true;
} else { } else {
$nameunique=true; $nameunique=true;
$nameunique_err=false;
} }
} else { } else {
$nameunique=true; $nameunique=true;
$nameunique_err=false;
} }
// test for login supplied // test for login supplied
if (strlen(trim($user_login))) { if (strlen(trim($user_login))) {
$loginsuppld=true; $loginsuppld=true;
$loginsuppld_err=false;
} else { } else {
$loginsuppld=false; $loginsuppld=false;
$loginsuppld_err=true; $loginsuppld_err=true;
@@ -140,9 +162,11 @@ if ($edit_user) {
$loginunique_err=true; $loginunique_err=true;
} else { } else {
$loginunique=true; $loginunique=true;
$loginunique_err=false;
} }
} else { } else {
$loginunique=true; $loginunique=true;
$loginunique_err=false;
} }
// sanitize first name, last name, login // sanitize first name, last name, login
$clean_fname=mysqli_real_escape_string($drs_db,$user_fname); $clean_fname=mysqli_real_escape_string($drs_db,$user_fname);
@@ -154,12 +178,14 @@ if ($edit_user) {
$passresults=validate_password($user_pass,$user_passconf); $passresults=validate_password($user_pass,$user_passconf);
if ($passresults['match']) { if ($passresults['match']) {
$passmatch=true; $passmatch=true;
$passmatch_err=false;
} else { } else {
$passmatch=false; $passmatch=false;
$passmatch_err=true; $passmatch_err=true;
} }
if ($passresults['complex']) { if ($passresults['complex']) {
$passcomplex=true; $passcomplex=true;
$passcomplex_err=false;
} else { } else {
$passcomplex=false; $passcomplex=false;
$passcomplex_err=true; $passcomplex_err=true;

View File

@@ -2,15 +2,32 @@
/* /*
search.php search.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
if ($_REQUEST['exportcsv']) { // redirect to search.php on cancel button press
$csv_filename="OpenDRS_Search_Results_" . date("Y-m-d_His") . ".csv"; if (array_key_exists('cancel',$_REQUEST)) {
header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache");
header("Location:search.php");
exit();
}
// assign variables from constants
$appname=APP_NAME;
if (array_key_exists('exportcsv',$_REQUEST)) {
$exportcsv=true;
$csv_filename="{$appname}_Search_Results_" . date("Y-m-d_His") . ".csv";
// disable caching // disable caching
$now = gmdate("D, d M Y H:i:s"); $now = gmdate("D, d M Y H:i:s");
header("Expires: Tue, 03 Jul 2001 06:00:00 GMT"); header("Expires: Tue, 03 Jul 2001 06:00:00 GMT");
@@ -25,51 +42,69 @@ if ($_REQUEST['exportcsv']) {
// disposition / encoding on response body // disposition / encoding on response body
header("Content-Disposition: attachment;filename={$csv_filename}"); header("Content-Disposition: attachment;filename={$csv_filename}");
header("Content-Transfer-Encoding: binary"); header("Content-Transfer-Encoding: binary");
} else {
$exportcsv=false;
} }
// import session variables // import session variables
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; if (isset($_SESSION['userid'])) {
$userid=$_SESSION['userid'];
} else {
$userid=NULL;
}
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
$exportcsv=$_REQUEST['exportcsv'];
if ($print || $exportcsv) { if ($print || $exportcsv) {
// if printer friendly or export csv was clicked, values will be // if printer friendly or export csv was clicked, values will be
// passed in serialized form as "all_parameters" so we need to load // passed in serialized form as "all_parameters" so we need to load
// those into $incoming[] // those into $incoming[]
$incoming=unserialize($_REQUEST['all_parameters']); $incoming=unserialize($_REQUEST['all_parameters']);
} else { } else {
if (!$_REQUEST['cancel']) $incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
$search=$incoming['search']; extract($incoming, EXTR_SKIP);
$viewtype=$incoming['viewtype']; /*
$s_device=$incoming['s_device']; * possible keys are:
$s_discovered=$incoming['s_discovered']; * search
$s_functional=$incoming['s_functional']; * viewtype
$s_reported_by=$incoming['s_reported_by']; * s_device
$s_report_date_start=$incoming['s_report_date_start']; * s_discovered
$s_report_date_end=$incoming['s_report_date_end']; * s_functional
$s_report_time_start=$incoming['s_report_time_start']; * s_reported_by
$s_report_time_end=$incoming['s_report_time_end']; * s_report_date_start
$s_action_date_start=$incoming['s_action_date_start']; * s_report_date_end
$s_action_date_end=$incoming['s_action_date_end']; * s_report_time_start
$s_action_time_start=$incoming['s_action_time_start']; * s_report_time_end
$s_action_time_end=$incoming['s_action_time_end']; * s_action_date_start
$s_action_by=$incoming['s_action_by']; * s_action_date_end
$s_action_reason=$incoming['s_action_reason']; * s_action_time_start
$s_action_text=$incoming['s_action_text']; * s_action_time_end
$s_subsystem=$incoming['s_subsystem']; * s_action_by
$s_id=$incoming['s_id']; * s_action_reason
$s_discrepancy_text=$incoming['s_discrepancy_text']; * s_action_text
$s_status=$incoming['s_status']; * s_subsystem
$s_group=$incoming['s_group']; * s_id
$sort=$incoming['sort']; * s_discrepancy_text
$order=$incoming['order']; * s_status
* s_group
* sort
* order
*/
// assign variables from constants if (!isset($search)) $search=false;
$appname=APP_NAME; if (!isset($viewtype)) $viewtype="summary";
if (!isset($s_id)) $s_id=NULL;
if (!isset($s_discrepancy_text)) $s_discrepancy_text=NULL;
if (!isset($s_reported_by)) $s_reported_by=NULL;
if (!isset($s_action_text)) $s_action_text=NULL;
if (!isset($s_action_date_start)) $s_action_date_start=NULL;
if (!isset($s_action_date_end)) $s_action_date_end=NULL;
if (!isset($s_action_time_start)) $s_action_time_start=NULL;
if (!isset($s_action_time_end)) $s_action_time_end=NULL;
if (!isset($sort)) $sort=NULL;
if (!isset($order)) $order=NULL;
if ($print) { if ($print) {
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
@@ -93,10 +128,10 @@ if (! $exportcsv) framework("begin","$appname",$pgtitle,$print);
// get min, max report and action_dates from writeups table, validate input dates/times and set defaults // get min, max report and action_dates from writeups table, validate input dates/times and set defaults
$minmaxqry=mysqli_query($drs_db,"select min(report_date),max(report_date),min(action_date),max(action_date) from writeups"); $minmaxqry=mysqli_query($drs_db,"select min(report_date),max(report_date),min(action_date),max(action_date) from writeups");
$minmaxdates=mysqli_fetch_row($minmaxqry); $minmaxdates=mysqli_fetch_row($minmaxqry);
if (!$s_report_date_start || !validateDate($s_report_date_start)) $s_report_date_start=$minmaxdates[0]; if (!isset($s_report_date_start) || !validateDate($s_report_date_start)) $s_report_date_start=$minmaxdates[0];
if (!$s_report_date_end || !validateDate($s_report_date_end)) $s_report_date_end=$minmaxdates[1]; if (!isset($s_report_date_end) || !validateDate($s_report_date_end)) $s_report_date_end=$minmaxdates[1];
if (!$s_report_time_start || !validateTime($s_report_time_start)) $s_report_time_start="00:00:00"; if (!isset($s_report_time_start) || !validateTime($s_report_time_start)) $s_report_time_start="00:00:00";
if (!$s_report_time_end || !validateTime($s_report_time_end)) $s_report_time_end="23:59:59"; if (!isset($s_report_time_end) || !validateTime($s_report_time_end)) $s_report_time_end="23:59:59";
if ($search) { if ($search) {
// strip whitespace from beginning and end of text fields // strip whitespace from beginning and end of text fields
@@ -303,10 +338,10 @@ if ($search) {
$query_string="select * from writeups where {$query_string} order by $sort $order"; $query_string="select * from writeups where {$query_string} order by $sort $order";
// group membership // group membership
if ($s_group) { if (isset($s_group)) {
$group_param="Group member: "; $group_param="Group member: ";
// create an array of writeups that are members of the groups specified // create an array of writeups that are members of the groups specified
$group_writeups=array(); $group_writeups=[];
foreach ($s_group as $group_val) { foreach ($s_group as $group_val) {
$wulink_query=mysqli_query($drs_db,"select writeupid from links where linkgroup=$group_val"); $wulink_query=mysqli_query($drs_db,"select writeupid from links where linkgroup=$group_val");
while($wulinkrow=mysqli_fetch_assoc($wulink_query)){ while($wulinkrow=mysqli_fetch_assoc($wulink_query)){
@@ -505,6 +540,7 @@ if (! $exportcsv) {
Group Assignments:<br> Group Assignments:<br>
<select style=\"max-width:40%;\" name=\"s_group[]\" id=\"ms-group\" multiple title=\"Select the groups the results should be a member of. If you uncheck them all, this field will not be included in the search.\"> <select style=\"max-width:40%;\" name=\"s_group[]\" id=\"ms-group\" multiple title=\"Select the groups the results should be a member of. If you uncheck them all, this field will not be included in the search.\">
"; ";
if (!isset($s_group)) $s_group=[];
$grow=mysqli_query($drs_db,"select * from groups order by id asc"); $grow=mysqli_query($drs_db,"select * from groups order by id asc");
while ($gitem=mysqli_fetch_assoc($grow)) { while ($gitem=mysqli_fetch_assoc($grow)) {
if ($gitem["name"]=="") { if ($gitem["name"]=="") {
@@ -566,7 +602,11 @@ if (! $exportcsv) {
"; ";
$persrow=mysqli_query($drs_db,"select id,firstname,lastname from users order by lastname asc"); $persrow=mysqli_query($drs_db,"select id,firstname,lastname from users order by lastname asc");
while ($persitem=mysqli_fetch_assoc($persrow)) { while ($persitem=mysqli_fetch_assoc($persrow)) {
if (!$search || in_array($persitem["id"],$s_action_by,true)) {
printf("<option value=\"%s\" selected>%s %s</option>",$persitem["id"],$persitem["firstname"],$persitem["lastname"]); printf("<option value=\"%s\" selected>%s %s</option>",$persitem["id"],$persitem["firstname"],$persitem["lastname"]);
} else {
printf("<option value=\"%s\">%s %s</option>",$persitem["id"],$persitem["firstname"],$persitem["lastname"]);
}
} }
echo " echo "
</select> </select>
@@ -584,7 +624,11 @@ if (! $exportcsv) {
"; ";
$reasrow=mysqli_query($drs_db,"select id,text from reasons order by id asc"); $reasrow=mysqli_query($drs_db,"select id,text from reasons order by id asc");
while ($reasitem=mysqli_fetch_assoc($reasrow)) { while ($reasitem=mysqli_fetch_assoc($reasrow)) {
if (!$search || in_array($reasitem["id"],$s_action_reason,true)) {
printf("<option value=\"%s\" selected>%s</option>",$reasitem["id"],$reasitem["text"]); printf("<option value=\"%s\" selected>%s</option>",$reasitem["id"],$reasitem["text"]);
} else {
printf("<option value=\"%s\">%s</option>",$reasitem["id"],$reasitem["text"]);
}
} }
echo " echo "
</select> </select>
@@ -776,19 +820,20 @@ if ($search) {
} }
$writeup=mysqli_query($drs_db,$query_string); $writeup=mysqli_query($drs_db,$query_string);
// create an array of ids returned by the query string // create an array of ids returned by the query string
$result_ids=array(); $result_ids=[];
while ($eachid=mysqli_fetch_assoc($writeup)) { while ($eachid=mysqli_fetch_assoc($writeup)) {
$result_ids[]=$eachid['id']; $result_ids[]=$eachid['id'];
} }
mysqli_data_seek($writeup,0); mysqli_data_seek($writeup,0);
if (!isset($group_writeups)) $group_writeups=[];
reset($group_writeups); reset($group_writeups);
$num_results=mysqli_num_rows($writeup); $num_results=mysqli_num_rows($writeup);
if ($num_results > 0) { if ($num_results > 0) {
if ($exportcsv) { if ($exportcsv) {
// generate csv file // generate csv file
// create an array of lines of the csv data // create an array of lines of the csv data
$csv_data=array(); $csv_data=[];
$csv_data[]=['WriteupID','Status',$device_term,'Subsystem',$discovered_term_short,$functional_term,'Discrepancy','Group','Report date','Report time','Reported by','Action taken by','Status Change Reason','Action taken','Action date','Action time']; $csv_data[]=['WriteupID','Status',$device_term,'Subsystem',$discovered_term_short,$functional_term,'Discrepancy','Group','Report date','Report time','Reported by','Action taken by','Status Change Reason','Action taken','Action date','Action time'];
$csv_fp=fopen('php://temp', 'w+'); $csv_fp=fopen('php://temp', 'w+');
@@ -871,14 +916,10 @@ if ($search) {
// action time for csv // action time for csv
$csv_action_time="{$tablerow["action_time"]}"; $csv_action_time="{$tablerow["action_time"]}";
if (($show_groupmems == $show_nongroupmems) || ($is_member && $show_groupmems) || (!$is_member && $show_nongroupmems)) {
// add line of results to csv array // add line of results to csv array
$csv_data[]=[$csv_id, $csv_status_text, $csv_dname, $csv_ssname, $csv_discovered, $csv_func_text, $csv_disc_txt, $csv_member_group_name, $csv_report_date, $csv_report_time, $csv_reported_by_text, $csv_action_by, $csv_reasonname, $csv_action_text, $csv_action_date, $csv_action_time]; $csv_data[]=[$csv_id, $csv_status_text, $csv_dname, $csv_ssname, $csv_discovered, $csv_func_text, $csv_disc_txt, $csv_member_group_name, $csv_report_date, $csv_report_time, $csv_reported_by_text, $csv_action_by, $csv_reasonname, $csv_action_text, $csv_action_date, $csv_action_time];
}
}
}
foreach ($csv_data as $csv_fields) { foreach ($csv_data as $csv_fields) {
// add row to csv buffer // add row to csv buffer
fputcsv($csv_fp, $csv_fields); fputcsv($csv_fp, $csv_fields);

View File

@@ -2,7 +2,7 @@
/* /*
settings.php settings.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
@@ -35,17 +35,23 @@ $configqry=mysqli_query($drs_db,"select name,value from config");
while ($configrow = mysqli_fetch_assoc($configqry)) { while ($configrow = mysqli_fetch_assoc($configqry)) {
$constname=strtoupper($configrow['name']); $constname=strtoupper($configrow['name']);
if (isset($userid)) { if (isset($userid)) {
$usrval=mysqli_fetch_row(mysqli_query($drs_db,"select value from profile where name=\"{$configrow['name']}\" and user=\"$userid\""))[0]; $usrvalqry=mysqli_query($drs_db,"select value from profile where name=\"{$configrow['name']}\" and user=\"$userid\"");
if (mysqli_num_rows($usrvalqry) > 0) {
$usrrow=mysqli_fetch_row($usrvalqry);
$usrval=$usrrow[0];
} }
if ($usrval) { }
if (isset($usrval)) {
$constvalue=$usrval; $constvalue=$usrval;
unset($usrval);
} else { } else {
$constvalue=$configrow['value']; $constvalue=$configrow['value'];
} }
define("$constname","$constvalue"); if (!defined("$constname")) define("$constname","$constvalue");
} }
//report no errors // level of error reporting. Set to 0 for production or E_ALL for development/troubleshooting
error_reporting(0); error_reporting(0);
//error_reporting(E_ALL);
?> ?>

View File

@@ -2,15 +2,20 @@
/* /*
writeupdetail.php writeupdetail.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// redirect to writeups.php on change cancel // redirect to writeups.php on change cancel
if ($_REQUEST['cancel']) { if (array_key_exists('cancel',$_REQUEST)) {
$id=$_REQUEST['id']; $id=$_REQUEST['id'];
header("Cache-Control:no-cache, must-revalidate"); header("Cache-Control:no-cache, must-revalidate");
header("Pragma:no-cache"); header("Pragma:no-cache");
@@ -22,7 +27,6 @@ if ($_REQUEST['cancel']) {
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; if (isset($_SESSION['userid'])) $userid=$_SESSION['userid'];
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming[] // form as "all_parameters" so we need to load those into $incoming[]
@@ -32,32 +36,42 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
$usersave=$incoming['usersave']; extract($incoming, EXTR_SKIP);
$techsave=$incoming['techsave']; /*
$useredit=$incoming['useredit']; * possible keys are:
$techedit=$incoming['techedit']; * usersave
$id=$incoming['id']; * techsave
$device=$incoming['device']; * useredit
$discovered=$incoming['discovered']; * techedit
$functional=$incoming['functional']; * id
$reported_by=$incoming['reported_by']; * device
$report_date=$incoming['report_date']; * discovered
$report_time=$incoming['report_time']; * functional
$subsystem=$incoming['subsystem']; * reported_by
$discrepancy_text=$incoming['discrepancy_text']; * report_date
$status=$incoming['status']; * report_time
$action_by=$incoming['action_by']; * subsystem
$action_date=$incoming['action_date']; * discrepancy_text
$action_time=$incoming['action_time']; * status
$action_reason=$incoming['action_reason']; * action_by
$action_text=$incoming['action_text']; * action_date
$group=$incoming['group']; * action_time
* action_reason
* action_text
* group
*/
if (!isset($usersave)) $usersave=false;
if (!isset($techsave)) $techsave=false;
if (!isset($useredit)) $useredit=false;
if (!isset($techedit)) $techedit=false;
if (!isset($group)) $group=[];
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
if ($print=="Printer Friendly") { if ($print) {
$mbgcolor=P_MENUBG_COLOR; $mbgcolor=P_MENUBG_COLOR;
} else { } else {
$mbgcolor=MENUBG_COLOR; $mbgcolor=MENUBG_COLOR;
@@ -317,7 +331,7 @@ if($status==3) $deferredstate="selected";
echo " echo "
<td align=\"left\" >Report Date<br> <td align=\"left\" >Report Date<br>
"; ";
if ($useredit) { if ($useredit && $role) {
echo " echo "
<input type=\"text\" name=\"report_date\" size=\"10\" maxlength=\"10\" value=\"$report_date\" id=\"reportdatepicker\" title=\"Format: YYYY-MM-DD\"></td> <input type=\"text\" name=\"report_date\" size=\"10\" maxlength=\"10\" value=\"$report_date\" id=\"reportdatepicker\" title=\"Format: YYYY-MM-DD\"></td>
"; ";
@@ -329,7 +343,7 @@ if ($useredit) {
echo " echo "
<td align=\"left\">Report Time<br> <td align=\"left\">Report Time<br>
"; ";
if ($useredit) { if ($useredit && $role) {
echo " echo "
<input type=\"text\" name=\"report_time\" size=\"8\" maxlength=\"8\" value=\"$report_time\" title=\"Format: HH:MM:SS\"></td> <input type=\"text\" name=\"report_time\" size=\"8\" maxlength=\"8\" value=\"$report_time\" title=\"Format: HH:MM:SS\"></td>
"; ";
@@ -392,11 +406,11 @@ if ($useredit) {
"; ";
$linkquery=mysqli_query($drs_db,"select * from links where writeupid=\"$id\""); $linkquery=mysqli_query($drs_db,"select * from links where writeupid=\"$id\"");
// create an array of ids returned by group query // create an array of ids returned by group query
$wugroups=array(); $wugroups=[];
while ($eachlink=mysqli_fetch_assoc($linkquery)) { while ($eachlink=mysqli_fetch_assoc($linkquery)) {
$wugroups[]=$eachlink['linkgroup']; $wugroups[]=$eachlink['linkgroup'];
} }
mysqli_data_seek($wugroups,0); reset($wugroups);
$grow=mysqli_query($drs_db,"select * from groups order by id asc"); $grow=mysqli_query($drs_db,"select * from groups order by id asc");
printf("<option value=\"%s\">%s</option>",0,"New group"); printf("<option value=\"%s\">%s</option>",0,"New group");
while ($gitem=mysqli_fetch_assoc($grow)) { while ($gitem=mysqli_fetch_assoc($grow)) {
@@ -423,18 +437,22 @@ if ($useredit) {
} else { } else {
echo "<tr></tr><td colspan=\"2\">Group Assignments:&nbsp;&nbsp"; echo "<tr></tr><td colspan=\"2\">Group Assignments:&nbsp;&nbsp";
$wustat=dblookup($drs_db,"writeups","id","status",$id); $wustat=dblookup($drs_db,"writeups","id","status",$id);
if ($wustat==2 && !$role) $allowuseredit="disabled"; if ($wustat==2 && !$role) {
$allowuseredit="disabled";
} else {
$allowuseredit=NULL;
}
// Group multi-select ******************** // Group multi-select ********************
echo " echo "
<select style=\"max-width:60%;\" name=\"groupshow\" id=\"ms-group\" multiple title=\"The groups this writeup is a member of.\"> <select style=\"max-width:60%;\" name=\"groupshow\" id=\"ms-group\" multiple title=\"The groups this writeup is a member of.\">
"; ";
$linkquery=mysqli_query($drs_db,"select * from links where writeupid=\"$id\""); $linkquery=mysqli_query($drs_db,"select * from links where writeupid=\"$id\"");
// create an array of ids returned by group query // create an array of ids returned by group query
$wugroups=array(); $wugroups=[];
while ($eachlink=mysqli_fetch_assoc($linkquery)) { while ($eachlink=mysqli_fetch_assoc($linkquery)) {
$wugroups[]=$eachlink['linkgroup']; $wugroups[]=$eachlink['linkgroup'];
} }
mysqli_data_seek($wugroups,0); reset($wugroups);
$grow=mysqli_query($drs_db,"select * from groups order by id asc"); $grow=mysqli_query($drs_db,"select * from groups order by id asc");
while ($gitem=mysqli_fetch_assoc($grow)) { while ($gitem=mysqli_fetch_assoc($grow)) {
if ($gitem["name"]=="") { if ($gitem["name"]=="") {
@@ -598,7 +616,11 @@ if ($techedit) {
</tr> </tr>
"; ";
} else { } else {
if (!$role) $live="disabled"; if (!$role) {
$live="disabled";
} else {
$live=NULL;
}
echo " echo "
<td align=\"right\" valign=\"bottom\"><input $live type=\"submit\" name=\"techedit\" value=\"Edit this Action\"></td> <td align=\"right\" valign=\"bottom\"><input $live type=\"submit\" name=\"techedit\" value=\"Edit this Action\"></td>
</tr> </tr>

View File

@@ -2,18 +2,26 @@
/* /*
writeups.php writeups.php
OpenDRS Online Discrepancy Reporting System OpenDRS Online Discrepancy Reporting System
Copyright (C) 2022 Rod Wright Copyright (C) 2023 Rod Wright
SPDX-License-Identifier: GPL-2.0 SPDX-License-Identifier: GPL-2.0
*/ */
include("common.php"); include("common.php");
if (array_key_exists('print',$_REQUEST)) {
$print=true;
} else {
$print=false;
}
// import session variables // import session variables
if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; if (isset($_SESSION['userid'])) {
$userid=$_SESSION['userid'];
} else {
$userid=NULL;
}
// import incoming arrays // import incoming arrays
$print=$_REQUEST['print'];
if ($print) { if ($print) {
// if printer friendly was clicked, values will be passed in serialized // if printer friendly was clicked, values will be passed in serialized
// form as "all_parameters" so we need to load those into $incoming[] // form as "all_parameters" so we need to load those into $incoming[]
@@ -24,20 +32,24 @@ if ($print) {
$incoming=arrayCopy($_REQUEST); $incoming=arrayCopy($_REQUEST);
} }
// load variables from incoming array // extract incoming array keys into variables
extract($incoming, EXTR_SKIP);
/*
* possible keys are:
*
* view
* start_date
* end_date
* showtoday
* showyesterday
* show7day
* show30day
* viewtype
* togroup
* addtogroup
* selectedids
*/
$view=$incoming['view'];
$start_date=$incoming['start_date'];
$end_date=$incoming['end_date'];
$showtoday=$incoming['showtoday'];
$showyesterday=$incoming['showyesterday'];
$show7day=$incoming['show7day'];
$show30day=$incoming['show30day'];
$viewtype=$incoming['viewtype'];
$togroup=$incoming['togroup'];
$addtogroup=$incoming['addtogroup'];
$selectedids=$incoming['selectedids'];
// assign variables from constants // assign variables from constants
$appname=APP_NAME; $appname=APP_NAME;
@@ -51,7 +63,7 @@ if ($print) {
$role=dblookup($drs_db,"users","id","role",$userid); $role=dblookup($drs_db,"users","id","role",$userid);
// define local functions // define local functions
function opentable($start_date,$end_date,$print,$drs_db,$viewtype="summary") { function opentable($incoming,$start_date,$end_date,$print,$drs_db,$viewtype="summary") {
// grab some important global variables // grab some important global variables
global $device_term; global $device_term;
global $discovered_term, $discovered_term_short, $disc_drop_data; global $discovered_term, $discovered_term_short, $disc_drop_data;
@@ -161,11 +173,11 @@ function opentable($start_date,$end_date,$print,$drs_db,$viewtype="summary") {
} }
echo "</table>\n"; echo "</table>\n";
} else { } else {
if ($_REQUEST['showyesterday']) { if (array_key_exists('showyesterday',$incoming)) {
$datespec="yesterday"; $datespec="yesterday";
} elseif ($_REQUEST['show7day']) { } elseif (array_key_exists('show7day',$incoming)) {
$datespec="the last 7 days"; $datespec="the last 7 days";
} elseif ($_REQUEST['show30day']) { } elseif (array_key_exists('show30day',$incoming)) {
$datespec="the last 30 days"; $datespec="the last 30 days";
} else { } else {
$datespec="today"; $datespec="today";
@@ -359,30 +371,31 @@ function viewtable($start_date,$end_date,$print,$drs_db,$viewtype="summary",$rol
// use default date values if not supplied // use default date values if not supplied
$today = date("Y-m-d"); $today = date("Y-m-d");
if ($start_date=="") $start_date=$today; if (!isset($start_date)) $start_date=$today;
if ($end_date=="") $end_date=$today; if (!isset($end_date)) $end_date=$today;
if ($showtoday) { if (isset($showtoday)) {
$start_date=$today; $start_date=$today;
$end_date=$today; $end_date=$today;
} }
if ($showyesterday) { if (isset($showyesterday)) {
$start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 1 day)"))[0]; $start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 1 day)"))[0];
$end_date=$start_date; $end_date=$start_date;
} }
if ($show7day) { if (isset($show7day)) {
$start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 7 day)"))[0]; $start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 7 day)"))[0];
$end_date=$today; $end_date=$today;
} }
if ($show30day) { if (isset($show30day)) {
$start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 30 day)"))[0]; $start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 30 day)"))[0];
$end_date=$today; $end_date=$today;
} }
if ($view) { if (isset($view)) {
$pgtitle="Recent Writeups"; $pgtitle="Recent Writeups";
} else { } else {
$pgtitle="Open Writeups"; $pgtitle="Open Writeups";
} }
framework("begin","$appname",$pgtitle,$print); framework("begin","$appname",$pgtitle,$print);
//echo "_REQUEST array <br>"; //echo "_REQUEST array <br>";
@@ -393,7 +406,7 @@ framework("begin","$appname",$pgtitle,$print);
// ******** begin database manipulation ******** // ******** begin database manipulation ********
if ($addtogroup && $togroup && $selectedids && $role) { if (isset($addtogroup) && isset($togroup) && isset($selectedids) && $role!=NULL) {
$fail=false; $fail=false;
if ($togroup=="newgroup") { if ($togroup=="newgroup") {
// Create a new group // Create a new group
@@ -424,7 +437,7 @@ pageblock("right","begin");
banner($print); banner($print);
echo "<br>"; echo "<br>";
if ($addtogroup) { if (isset($addtogroup)) {
if (count($selectedids) > 1) { if (count($selectedids) > 1) {
$plural="s"; $plural="s";
} else { } else {
@@ -436,14 +449,14 @@ if ($addtogroup) {
format_message(2,"<strong>An error was encountered when adding writeup$plural.</strong> The error was \" $fail \""); format_message(2,"<strong>An error was encountered when adding writeup$plural.</strong> The error was \" $fail \"");
} }
} }
if (!$viewtype) $viewtype="summary"; if (!isset($viewtype)) $viewtype="summary";
if ($view==1) { if (isset($view)) {
// show writeup table // show writeup table
viewtable($start_date,$end_date,$print,$drs_db,$viewtype,$role); viewtable($start_date,$end_date,$print,$drs_db,$viewtype,$role);
} else { } else {
// show open table // show open table
opentable($start_date,$end_date,$print,$drs_db,$viewtype); opentable($incoming,$start_date,$end_date,$print,$drs_db,$viewtype);
} }
echo "<br>"; echo "<br>";

View File

@@ -2,12 +2,12 @@
# install.sh # install.sh
# OpenDRS Online Discrepancy Reporting System # OpenDRS Online Discrepancy Reporting System
# Copyright (C) 2022 Rod Wright # Copyright (C) 2023 Rod Wright
# SPDX-License-Identifier: GPL-2.0 # SPDX-License-Identifier: GPL-2.0
DRS_VERSION="1.3.1" DRS_VERSION="1.3.3"
DOC_ROOT="/var/www" DOC_ROOT="/var/www"
INSTALL_LOC="opendrs" INSTALL_LOC="opendrs"
APACHE_USER="www-data" APACHE_USER="www-data"
@@ -78,7 +78,7 @@ then
curr_username=`grep username $install_path/db.php | head -1 | cut -d "\"" -f2` curr_username=`grep username $install_path/db.php | head -1 | cut -d "\"" -f2`
curr_dbpass=`grep dbpass $install_path/db.php | head -1 | cut -d "\"" -f2` curr_dbpass=`grep dbpass $install_path/db.php | head -1 | cut -d "\"" -f2`
export MYSQL_PWD="$curr_dbpass" export MYSQL_PWD="$curr_dbpass"
mysqldump -u"$curr_username" $curr_dbname > $curr_dbname-`date +%Y-%m-%d_%H:%M:%S`-backup.sql mysqldump --no-tablespaces -u"$curr_username" $curr_dbname > $curr_dbname-`date +%Y-%m-%d_%H:%M:%S`-backup.sql
# back up existing installation # back up existing installation
echo "Backing up current installation to the package directory." echo "Backing up current installation to the package directory."
cp -R $install_path $install_loc_in-`date +%Y-%m-%d_%H:%M:%S`-backup cp -R $install_path $install_loc_in-`date +%Y-%m-%d_%H:%M:%S`-backup
@@ -169,6 +169,10 @@ else
echo "This can be changed later in the application itself." echo "This can be changed later in the application itself."
echo -n "Installation name [OpenDRS]: " echo -n "Installation name [OpenDRS]: "
read new_inst_name read new_inst_name
if [ "$new_inst_name" = "" ]
then
new_inst_name="OpenDRS"
fi
echo "" echo ""
# Create initial database # Create initial database

View File

@@ -38,7 +38,7 @@ CREATE TABLE `banners` (
LOCK TABLES `banners` WRITE; LOCK TABLES `banners` WRITE;
/*!40000 ALTER TABLE `banners` DISABLE KEYS */; /*!40000 ALTER TABLE `banners` DISABLE KEYS */;
INSERT INTO `banners` VALUES INSERT INTO `banners` VALUES
(1,'no banner','#000000','#000000'), (1,'no banner','#000000','#FFFFFF'),
(2,'UNCLASSIFIED','#009900','#FFFFFF'), (2,'UNCLASSIFIED','#009900','#FFFFFF'),
(3,'CONFIDENTIAL','#000099','#FFFFFF'), (3,'CONFIDENTIAL','#000099','#FFFFFF'),
(4,'SECRET','#990000','#FFFFFF'), (4,'SECRET','#990000','#FFFFFF'),
@@ -69,7 +69,7 @@ CREATE TABLE `config` (
LOCK TABLES `config` WRITE; LOCK TABLES `config` WRITE;
/*!40000 ALTER TABLE `config` DISABLE KEYS */; /*!40000 ALTER TABLE `config` DISABLE KEYS */;
INSERT INTO `config` VALUES INSERT INTO `config` VALUES
(1,'drs_version','1.3.1','1.3.1'), (1,'drs_version','1.3.3','1.3.3'),
(5,'app_name','OpenDRS - Discrepancy Reporting System','OpenDRS Discrepancy Reporting System'), (5,'app_name','OpenDRS - Discrepancy Reporting System','OpenDRS Discrepancy Reporting System'),
(6,'banner','1','1'), (6,'banner','1','1'),
(7,'background_color','0B3144','0B3144'), (7,'background_color','0B3144','0B3144'),

View File

@@ -221,3 +221,13 @@ UPDATE config SET value="1.3.0",defaultvalue="1.3.0" WHERE name="drs_version";
-- Update version number -- Update version number
UPDATE config SET value="1.3.1",defaultvalue="1.3.1" WHERE name="drs_version"; UPDATE config SET value="1.3.1",defaultvalue="1.3.1" WHERE name="drs_version";
-- -------------------------------------- -- --------------------------------------
-- ---------- version 1.3.2 -------------
-- Update version number
UPDATE config SET value="1.3.2",defaultvalue="1.3.2" WHERE name="drs_version";
-- --------------------------------------
-- ---------- version 1.3.3 -------------
-- Update version number
UPDATE config SET value="1.3.3",defaultvalue="1.3.3" WHERE name="drs_version";
-- --------------------------------------