Contacts: Fixed/implemented permissions, added Relations.

This commit is contained in:
Nate Jones
2015-03-27 04:35:21 +00:00
parent fbbd475ad6
commit 41acf3c968
26 changed files with 881 additions and 336 deletions
+14 -41
View File
@@ -26,7 +26,7 @@
require_once "root.php";
require_once "resources/require.php";
require_once "resources/check_auth.php";
if (permission_exists('contact_view')) {
if (permission_exists('contact_address_view')) {
//access granted
}
else {
@@ -34,15 +34,7 @@ else {
exit;
}
//require_once "resources/header.php";
require_once "resources/paging.php";
//get variables used to control the order
// $order_by = $_GET["order_by"];
// $order = $_GET["order"];
//show the content
echo "<table width='100%' border='0'>\n";
echo "<tr>\n";
echo "<td width='50%' align='left' nowrap='nowrap'><b>".$text['label-addresses']."</b></td>\n";
@@ -50,38 +42,11 @@ require_once "resources/paging.php";
echo "</tr>\n";
echo "</table>\n";
//prepare to page the results
// $sql = " select count(*) as num_rows from v_contact_addresses ";
// $sql .= " where domain_uuid = '".$_SESSION['domain_uuid']."' ";
// $sql .= " and contact_uuid = '$contact_uuid' ";
// if (strlen($order_by)> 0) { $sql .= "order by $order_by $order "; }
// $prep_statement = $db->prepare($sql);
// if ($prep_statement) {
// $prep_statement->execute();
// $row = $prep_statement->fetch(PDO::FETCH_ASSOC);
// if ($row['num_rows'] > 0) {
// $num_rows = $row['num_rows'];
// }
// else {
// $num_rows = '0';
// }
// }
//prepare to page the results
// $rows_per_page = 10;
// $param = "";
// $page = $_GET['page'];
// if (strlen($page) == 0) { $page = 0; $_GET['page'] = 0; }
// list($paging_controls, $rows_per_page, $var_3) = paging($num_rows, $param, $rows_per_page);
// $offset = $rows_per_page * $page;
//get the contact list
$sql = "select * from v_contact_addresses ";
$sql .= "where domain_uuid = '".$_SESSION['domain_uuid']."' ";
$sql .= "and contact_uuid = '$contact_uuid' ";
$sql .= "order by address_primary desc, address_label asc ";
// if (strlen($order_by)> 0) { $sql .= "order by $order_by $order "; }
// $sql .= " limit $rows_per_page offset $offset ";
$prep_statement = $db->prepare(check_sql($sql));
$prep_statement->execute();
$result = $prep_statement->fetchAll(PDO::FETCH_NAMED);
@@ -102,14 +67,18 @@ require_once "resources/paging.php";
echo "<th>&nbsp;</th>\n";
echo "<th>".$text['label-address_description']."</th>\n";
echo "<td class='list_control_icons'>";
echo "<a href='contact_address_edit.php?contact_uuid=".$_GET['id']."' alt='".$text['button-add']."'>$v_link_label_add</a>";
if (permission_exists('contact_address_add')) {
echo "<a href='contact_address_edit.php?contact_uuid=".$_GET['id']."' alt='".$text['button-add']."'>$v_link_label_add</a>";
}
echo "</td>\n";
echo "</tr>\n";
if ($result_count > 0) {
foreach($result as $row) {
$map_query = $row['address_street']." ".$row['address_extended'].", ".$row['address_locality'].", ".$row['address_region'].", ".$row['address_region'].", ".$row['address_postal_code'];
$tr_link = "href='contact_address_edit.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_address_uuid']."'";
if (permission_exists('contact_address_edit')) {
$tr_link = "href='contact_address_edit.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_address_uuid']."'";
}
echo "<tr ".$tr_link." ".(($row['address_primary']) ? "style='font-weight: bold;'" : null).">\n";
echo " <td valign='top' class='".$row_style[$c]."'>".$row['address_label']."&nbsp;</td>\n";
echo " <td valign='top' class='".$row_style[$c]."' style='width: 25%; max-width: 50px; overflow: hidden; text-overflow: ellipsis; white-space: nowrap;'>".$row['address_street']."&nbsp;</td>\n";
@@ -120,11 +89,15 @@ require_once "resources/paging.php";
echo " </td>\n";
echo " <td valign='top' class='row_stylebg'>".$row['address_description']."&nbsp;</td>\n";
echo " <td class='list_control_icons'>";
echo "<a href='contact_address_edit.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_address_uuid']."' alt='".$text['button-edit']."'>$v_link_label_edit</a>";
echo "<a href='contact_address_delete.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_address_uuid']."' alt='".$text['button-delete']."' onclick=\"return confirm('".$text['confirm-delete']."')\">$v_link_label_delete</a>";
if (permission_exists('contact_address_edit')) {
echo "<a href='contact_address_edit.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_address_uuid']."' alt='".$text['button-edit']."'>$v_link_label_edit</a>";
}
if (permission_exists('contact_address_delete')) {
echo "<a href='contact_address_delete.php?contact_uuid=".$row['contact_uuid']."&id=".$row['contact_address_uuid']."' alt='".$text['button-delete']."' onclick=\"return confirm('".$text['confirm-delete']."')\">$v_link_label_delete</a>";
}
echo " </td>\n";
echo "</tr>\n";
if ($c==0) { $c=1; } else { $c=0; }
$c = ($c) ? 0 : 1;
} //end foreach
unset($sql, $result, $row_count);
} //end if results