diff --git a/core/default_settings/default_settings.php b/core/default_settings/default_settings.php index 955a575ba6..313209e221 100644 --- a/core/default_settings/default_settings.php +++ b/core/default_settings/default_settings.php @@ -48,7 +48,7 @@ //get the http post data $search = $_REQUEST['search'] ?? ''; $default_setting_category = $_REQUEST['default_setting_category'] ?? ''; - if (is_array($_POST['default_settings'])) { + if (!empty($_POST['default_settings'])) { $action = $_POST['action']; $domain_uuid = $_POST['domain_uuid']; $default_settings = $_POST['default_settings']; @@ -58,23 +58,30 @@ $default_settings = ''; } +//set additional variables + $search = !empty($_GET["search"]) ? $_GET["search"] : ''; + $show = !empty($_GET["show"]) ? $_GET["show"] : ''; + //sanitize the variables $action = preg_replace('#[^a-zA-Z0-9_\-\.]#', '', $action); $search = preg_replace('#[^a-zA-Z0-9_\-\. ]#', '', $search); $default_setting_category = preg_replace('#[^a-zA-Z0-9_\-\.]#', '', $default_setting_category); +//set from session variables + $list_row_edit_button = !empty($_SESSION['theme']['list_row_edit_button']['boolean']) ? $_SESSION['theme']['list_row_edit_button']['boolean'] : 'false'; + //build the query string $query_string = ''; - if ($search != '') { + if (!empty($search)) { $query_string .= 'search='.urlencode($search); } - if ($default_setting_category != '') { + if (!empty($default_setting_category)) { if ($query_string == '') { $query_string = ''; } else { $query_string .= '&'; } $query_string .= 'default_setting_category='.urlencode($default_setting_category); } //process the http post data by action - if ($action != '' && is_array($default_settings) && @sizeof($default_settings) != 0) { + if (!empty($action) && !empty($default_settings)) { switch ($action) { case 'copy': if (permission_exists('default_setting_add')) { @@ -96,17 +103,17 @@ } break; } - header('Location: default_settings.php?'.($query_string != '' ? $query_string : null)); + header('Location: default_settings.php?'.(!empty($query_string) ? $query_string : null)); exit; } -//get order and order by - $order_by = $_GET["order_by"]; - $order = $_GET["order"]; +//get order and order by and sanitize the values + $order_by = (!empty($_GET["order_by"])) ? $_GET["order_by"] : ''; + $order = (!empty($_GET["order"])) ? $_GET["order"] : ''; //get the count $sql = "select count(default_setting_uuid) from v_default_settings "; - if (isset($search) && !empty($search)) { + if (!empty($search) && !empty($search)) { $sql .= "where ("; $sql .= " lower(default_setting_category) like :search "; $sql .= " or lower(default_setting_subcategory) like :search "; @@ -116,19 +123,19 @@ $sql .= ") "; $parameters['search'] = '%'.$search.'%'; } - if (isset($default_setting_category) && !empty($default_setting_category)) { + if (!empty($default_setting_category) && !empty($default_setting_category)) { $sql .= (stripos($sql,'WHERE') === false) ? 'where ' : 'and '; $sql .= "lower(default_setting_category) = :default_setting_category "; $parameters['default_setting_category'] = strtolower($default_setting_category); } $database = new database; - $num_rows = $database->select($sql, $parameters, 'column'); + $num_rows = $database->select($sql, $parameters ?? null, 'column'); //get the list $sql = "select default_setting_uuid, default_setting_category, default_setting_subcategory, default_setting_name, "; $sql .= "default_setting_value, cast(default_setting_enabled as text), default_setting_description "; $sql .= "from v_default_settings "; - if (isset($search) && !empty($search)) { + if (!empty($search) && !empty($search)) { $sql .= "where ("; $sql .= " lower(default_setting_category) like :search "; $sql .= " or lower(default_setting_subcategory) like :search "; @@ -138,7 +145,7 @@ $sql .= ") "; $parameters['search'] = '%'.$search.'%'; } - if (isset($default_setting_category) && !empty($default_setting_category)) { + if (!empty($default_setting_category) && !empty($default_setting_category)) { $sql .= (stripos($sql,'WHERE') === false) ? 'where ' : 'and '; $sql .= "lower(default_setting_category) = :default_setting_category "; $parameters['default_setting_category'] = strtolower($default_setting_category); @@ -146,7 +153,7 @@ $sql .= order_by($order_by, $order, 'default_setting_category, default_setting_subcategory, default_setting_order', 'asc'); //$sql .= limit_offset($rows_per_page, $offset ?? ''); //$offset is always null $database = new database; - $default_settings = $database->select($sql, $parameters, 'all'); + $default_settings = $database->select($sql, $parameters ?? null, 'all'); unset($sql, $parameters); //get default setting categories @@ -171,16 +178,18 @@ $sql .= "from v_default_settings as d1 "; $sql .= "order by d1.default_setting_category asc "; $database = new database; - $rows = $database->select($sql, $parameters, 'all'); - if (is_array($rows) && @sizeof($rows) != 0) { + $rows = $database->select($sql, $parameters ?? null, 'all'); + if (!empty($rows) && @sizeof($rows) != 0) { foreach ($rows as $row) { - $default_setting_categories[$row['default_setting_category']] += $row['quantity']; + if (!empty($row['default_setting_category']) && !empty($row['quantity'])) { + $default_setting_categories[$row['default_setting_category']] = $row['quantity']; + } } } unset($sql, $rows, $row); //get the list of categories - if (is_array($default_setting_categories) && @sizeof($default_setting_categories) != 0) { + if (!empty($default_setting_categories)) { foreach ($default_setting_categories as $default_setting_category => $quantity) { $category = strtolower($default_setting_category); switch ($category) { @@ -209,10 +218,10 @@ } $x = 0; foreach ($apps as $app) { - if (is_array($app['default_settings'])) { + if (!empty($app['default_settings'])) { foreach ($app['default_settings'] as $setting) { $setting_array[$x] = ($setting); - $setting_array[$x]['app_uuid'] = $app['uuid']; + $setting_array[$x]['app_uuid'] = $app['uuid'] ?? null; $x++; } } @@ -270,11 +279,11 @@ echo "
".$text['title-default_settings']." (".number_format($num_rows).")
\n"; echo "
\n"; echo button::create(['type'=>'button','label'=>$text['label-domain'],'icon'=>$_SESSION['theme']['button_icon_domain'],'style'=>'','link'=>PROJECT_PATH.'/core/domain_settings/domain_settings.php?id='.$domain_uuid]); - echo button::create(['label'=>$text['button-reload'],'icon'=>$_SESSION['theme']['button_icon_reload'],'type'=>'button','id'=>'button_reload','link'=>'default_settings_reload.php'.($search != '' ? '?search='.urlencode($search) : null),'style'=>'margin-right: 15px;']); + echo button::create(['label'=>$text['button-reload'],'icon'=>$_SESSION['theme']['button_icon_reload'],'type'=>'button','id'=>'button_reload','link'=>'default_settings_reload.php'.(!empty($search) ? '?search='.urlencode($search) : null),'style'=>'margin-right: 15px;']); if (permission_exists('default_setting_add')) { echo button::create(['type'=>'button','label'=>$text['button-add'],'icon'=>$_SESSION['theme']['button_icon_add'],'id'=>'btn_add','link'=>'default_setting_edit.php?'.$query_string]); } - if (permission_exists('default_setting_add') && $default_settings) { + if (permission_exists('default_setting_add') && !empty($default_settings)) { if (permission_exists("domain_select") && permission_exists("domain_setting_add") && count($_SESSION['domains']) > 1) { echo button::create(['type'=>'button','label'=>$text['button-copy'],'id'=>'btn_copy','name'=>'btn_copy','style'=>'display: none;','icon'=>$_SESSION['theme']['button_icon_copy'],'id'=>'btn_copy','onclick'=>'show_domains();']); echo button::create(['type'=>'button','label'=>$text['button-cancel'],'id'=>'btn_copy_cancel','icon'=>$_SESSION['theme']['button_icon_cancel'],'style'=>'display: none;','onclick'=>'hide_domains();']); @@ -295,7 +304,7 @@ echo button::create(['type'=>'button','label'=>$text['button-delete'],'icon'=>$_SESSION['theme']['button_icon_delete'],'id'=>'btn_delete','name'=>'btn_delete','style'=>'display: none;','onclick'=>"modal_open('modal-delete','btn_delete');"]); } echo "\n"; echo "
\n"; echo "
\n"; @@ -333,7 +342,10 @@ echo "\n"; echo ""; - if (is_array($default_settings) && @sizeof($default_settings) != 0) { + if (!empty($default_settings)) { + //define the variable + $previous_default_setting_category = ''; + $x = 0; foreach ($default_settings as $row) { $default_setting_category = strtolower($row['default_setting_category']); @@ -344,8 +356,14 @@ //check if the default setting uuid exists in the array $field = find_in_array($setting_array, 'default_setting_uuid', $row['default_setting_uuid'], 'row'); - unset($setting_bold, $enabled_bold, $default_value, $default_enabled); - if (is_array($field)) { + + //set default empty string + $setting_bold = ''; + $enabled_bold = ''; + $default_value = ''; + $default_enabled = ''; + + if (!empty($field)) { if ($row['default_setting_value'] !== $field['default_setting_value']) { $setting_bold = 'font-weight:bold;'; } @@ -378,7 +396,7 @@ } if ($previous_default_setting_category != $row['default_setting_category']) { - if ($previous_default_setting_category != '') { + if (!empty($previous_default_setting_category)) { echo "\n"; echo "
\n"; echo "\n"; @@ -393,7 +411,7 @@ echo " \n"; echo " \n"; } - if ($_GET['show'] == 'all' && permission_exists('default_setting_all')) { + if ($show == 'all' && permission_exists('default_setting_all')) { echo th_order_by('domain_name', $text['label-domain'], $order_by, $order); } echo th_order_by('default_setting_subcategory', $text['label-subcategory'], $order_by, $order, null, "class='pct-35'"); @@ -401,7 +419,7 @@ echo th_order_by('default_setting_value', $text['label-value'], $order_by, $order, null, "class='pct-30'"); echo th_order_by('default_setting_enabled', $text['label-enabled'], $order_by, $order, null, "class='center'"); echo " ".$text['label-description']."\n"; - if (permission_exists('default_setting_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') { + if (permission_exists('default_setting_edit') && $list_row_edit_button == 'true') { echo "  \n"; } echo "\n"; @@ -416,7 +434,7 @@ echo " \n"; echo " \n"; } - if ($_GET['show'] == 'all' && permission_exists('default_setting_all')) { + if ($show == 'all' && permission_exists('default_setting_all')) { echo " ".escape($_SESSION['domains'][$row['domain_uuid']]['domain_name'])."\n"; } echo " "; @@ -431,15 +449,15 @@ echo " ".$setting_types[array_search(strtolower($row['default_setting_name']), array_map('strtolower',$setting_types))]."\n"; echo " \n"; - $category = $row['default_setting_category']; - $subcategory = $row['default_setting_subcategory']; - $name = $row['default_setting_name']; + $category = $row['default_setting_category'] ?? ''; + $subcategory = $row['default_setting_subcategory'] ?? ''; + $name = $row['default_setting_name'] ?? ''; if ($category == "domain" && $subcategory == "menu" && $name == "uuid" ) { $sql = "select * from v_menus "; $sql .= "where menu_uuid = :menu_uuid "; $parameters['menu_uuid'] = $row['default_setting_value']; $database = new database; - $sub_result = $database->select($sql, $parameters, 'all'); + $sub_result = $database->select($sql, $parameters ?? null, 'all'); foreach ($sub_result as &$sub_row) { echo $sub_row["menu_language"]." - ".$sub_row["menu_name"]."\n"; } @@ -517,7 +535,7 @@ echo " \n"; if (permission_exists('default_setting_edit')) { echo " \n"; - if (isset($enabled_bold)) { + if (!empty($enabled_bold)) { echo button::create(['type'=>'submit','class'=>'link','style'=>'font-weight:bold', 'label'=>$text['label-'.$row['default_setting_enabled']],'title'=>$text['button-toggle'],'onclick'=>"list_self_check('checkbox_".$x."'); list_action_set('toggle'); list_form_submit('form_list')"]); } else { @@ -530,7 +548,7 @@ } echo " \n"; echo " ".escape($row['default_setting_description'])."\n"; - if (permission_exists('default_setting_edit') && $_SESSION['theme']['list_row_edit_button']['boolean'] == 'true') { + if (permission_exists('default_setting_edit') && $list_row_edit_button == 'true') { echo " \n"; echo button::create(['type'=>'button','title'=>$text['button-edit'],'icon'=>$_SESSION['theme']['button_icon_edit'],'link'=>$list_row_url]); echo " \n"; @@ -548,7 +566,7 @@ echo "
\n"; echo "\n"; - echo "
".$paging_controls."
\n"; + //echo "
".$paging_controls."
\n"; echo "\n"; echo "\n";