Database class integration.

This commit is contained in:
Nate 2019-07-26 10:26:32 -06:00
parent 1c2e0c2fc7
commit faca29d5bc
6 changed files with 159 additions and 170 deletions

View File

@ -39,25 +39,26 @@ else {
$text = $language->get(); $text = $language->get();
//get the http values and set as variables //get the http values and set as variables
if (count($_GET) > 0) { $contact_time_uuid = $_GET["id"];
$contact_time_uuid = check_str($_GET["id"]); $contact_uuid = $_GET["contact_uuid"];
$contact_uuid = check_str($_GET["contact_uuid"]);
}
//delete the record //delete the record
if (strlen($contact_time_uuid) > 0) { if (is_uuid($contact_time_uuid) && is_uuid($contact_uuid)) {
$sql = "delete from v_contact_times "; $array['contact_times'][0]['domain_uuid'] = $domain_uuid;
$sql .= "where domain_uuid = '".$domain_uuid."' "; $array['contact_times'][0]['contact_uuid'] = $contact_uuid;
$sql .= "and contact_uuid = '".$contact_uuid."' "; $array['contact_times'][0]['contact_time_uuid'] = $contact_time_uuid;
$sql .= "and contact_time_uuid = '".$contact_time_uuid."' ";
$prep_statement = $db->prepare(check_sql($sql)); $database = new database;
$prep_statement->execute(); $database->app_name = 'contacts';
unset($sql); $database->app_uuid = '04481e0e-a478-c559-adad-52bd4174574c';
$database->delete($array);
unset($array);
message::add($text['message-delete']);
} }
//redirect the browser //redirect the browser
message::add($text['message-delete']);
header("Location: contact_edit.php?id=".$contact_uuid); header("Location: contact_edit.php?id=".$contact_uuid);
return; exit;
?> ?>

View File

@ -39,32 +39,32 @@ else {
$text = $language->get(); $text = $language->get();
//action add or update //action add or update
if (isset($_REQUEST["id"])) { if (is_uuid($_REQUEST["id"])) {
$action = "update"; $action = "update";
$contact_time_uuid = check_str($_REQUEST["id"]); $contact_time_uuid = $_REQUEST["id"];
} }
else { else {
$action = "add"; $action = "add";
} }
//get the contact uuid //get the contact uuid
if (strlen($_GET["contact_uuid"]) > 0) { if (is_uuid($_GET["contact_uuid"])) {
$contact_uuid = check_str($_GET["contact_uuid"]); $contact_uuid = $_GET["contact_uuid"];
} }
//get http post variables and set them to php variables //get http post variables and set them to php variables
if (count($_POST)>0) { if (is_array($_POST) && @sizeof($_POST) != 0) {
$time_start = check_str($_POST["time_start"]); $time_start = $_POST["time_start"];
$time_stop = check_str($_POST["time_stop"]); $time_stop = $_POST["time_stop"];
$time_description = check_str($_POST["time_description"]); $time_description = $_POST["time_description"];
} }
//process the form data //process the form data
if (count($_POST) > 0 && strlen($_POST["persistformvar"]) == 0) { if (is_array($_POST) && @sizeof($_POST) != 0 && strlen($_POST["persistformvar"]) == 0) {
//set the uuid //set the uuid
if ($action == "update") { if ($action == "update") {
$contact_time_uuid = check_str($_POST["contact_time_uuid"]); $contact_time_uuid = $_POST["contact_time_uuid"];
} }
//check for all required data //check for all required data
@ -86,82 +86,76 @@ else {
if ($_POST["persistformvar"] != "true") { if ($_POST["persistformvar"] != "true") {
//update last modified //update last modified
$sql = "update v_contacts set "; $array['contacts'][0]['contact_uuid'] = $contact_uuid;
$sql .= "last_mod_date = now(), "; $array['contacts'][0]['domain_uuid'] = $domain_uuid;
$sql .= "last_mod_user = '".$_SESSION['username']."' "; $array['contacts'][0]['last_mod_date'] = 'now()';
$sql .= "where domain_uuid = '".$domain_uuid."' "; $array['contacts'][0]['last_mod_user'] = $_SESSION['username'];
$sql .= "and contact_uuid = '".$contact_uuid."' ";
$db->exec(check_sql($sql)); $p = new permissions;
unset($sql); $p->add('contact_edit', 'temp');
$database = new database;
$database->app_name = 'contacts';
$database->app_uuid = '04481e0e-a478-c559-adad-52bd4174574c';
$database->save($array);
unset($array);
$p->delete('contact_edit', 'temp');
if ($action == "add") { if ($action == "add") {
$contact_time_uuid = uuid(); $contact_time_uuid = uuid();
$sql = "insert into v_contact_times "; $array['contact_times'][0]['contact_time_uuid'] = $contact_time_uuid;
$sql .= "( ";
$sql .= "domain_uuid, ";
$sql .= "contact_time_uuid, ";
$sql .= "contact_uuid, ";
$sql .= "user_uuid, ";
$sql .= "time_start, ";
$sql .= "time_stop, ";
$sql .= "time_description ";
$sql .= ") ";
$sql .= "values ";
$sql .= "( ";
$sql .= "'".$domain_uuid."', ";
$sql .= "'".$contact_time_uuid."', ";
$sql .= "'".$contact_uuid."', ";
$sql .= "'".$_SESSION["user"]["user_uuid"]."', ";
$sql .= "'".$time_start."', ";
$sql .= "'".$time_stop."', ";
$sql .= "'".$time_description."' ";
$sql .= ")";
$db->exec(check_sql($sql));
unset($sql);
message::add($text['message-add']); message::add($text['message-add']);
header("Location: contact_edit.php?id=".$contact_uuid); }
return;
} //if ($action == "add")
if ($action == "update") { if ($action == "update") {
$sql = "update v_contact_times "; $array['contact_times'][0]['contact_time_uuid'] = $contact_time_uuid;
$sql .= "set ";
$sql .= "time_start = '".$time_start."', ";
$sql .= "time_stop = '".$time_stop."', ";
$sql .= "time_description = '".$time_description."' ";
$sql .= "where ";
$sql .= "contact_time_uuid = '".$contact_time_uuid."' ";
$sql .= "and domain_uuid = '".$domain_uuid."' ";
$sql .= "and contact_uuid = '".$contact_uuid."' ";
$sql .= "and user_uuid = '".$_SESSION["user"]["user_uuid"]."' ";
$db->exec(check_sql($sql));
unset($sql);
message::add($text['message-update']); message::add($text['message-update']);
header("Location: contact_edit.php?id=".$contact_uuid); }
return;
} //if ($action == "update") if (is_array($array) && @sizeof($array) != 0) {
} //if ($_POST["persistformvar"] != "true") $array['contact_times'][0]['domain_uuid'] = $domain_uuid;
} //(count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) $array['contact_times'][0]['contact_uuid'] = $contact_uuid;
$array['contact_times'][0]['user_uuid'] = $_SESSION["user"]["user_uuid"];
$array['contact_times'][0]['time_start'] = $time_start;
$array['contact_times'][0]['time_stop'] = $time_stop;
$array['contact_times'][0]['time_description'] = $time_description;
$database = new database;
$database->app_name = 'contacts';
$database->app_uuid = '04481e0e-a478-c559-adad-52bd4174574c';
$database->save($array);
unset($array);
}
header("Location: contact_edit.php?id=".$contact_uuid);
exit;
}
}
//pre-populate the form //pre-populate the form
if (count($_GET)>0 && $_POST["persistformvar"] != "true") { if (is_array($_GET) && @sizeof($_GET) != 0 && $_POST["persistformvar"] != "true") {
$contact_time_uuid = $_GET["id"]; $contact_time_uuid = $_GET["id"];
$sql = "select ct.*, u.username "; $sql = "select ct.*, u.username ";
$sql .= "from v_contact_times as ct, v_users as u "; $sql .= "from v_contact_times as ct, v_users as u ";
$sql .= "where ct.user_uuid = u.user_uuid "; $sql .= "where ct.user_uuid = u.user_uuid ";
$sql .= "and ct.domain_uuid = '".$domain_uuid."' "; $sql .= "and ct.domain_uuid = :domain_uuid ";
$sql .= "and ct.contact_uuid = '".$contact_uuid."' "; $sql .= "and ct.contact_uuid = :contact_uuid ";
$sql .= "and ct.user_uuid = '".$_SESSION["user"]["user_uuid"]."' "; $sql .= "and ct.user_uuid = :user_uuid ";
$sql .= "and contact_time_uuid = '".$contact_time_uuid."' "; $sql .= "and contact_time_uuid = :contact_time_uuid ";
$prep_statement = $db->prepare(check_sql($sql)); $parameters['domain_uuid'] = $domain_uuid;
$prep_statement->execute(); $parameters['contact_uuid'] = $contact_uuid;
$result = $prep_statement->fetch(PDO::FETCH_NAMED); $parameters['user_uuid'] = $_SESSION["user"]["user_uuid"];
$time_start = $result["time_start"]; $parameters['contact_time_uuid'] = $contact_time_uuid;
$time_stop = $result["time_stop"]; $database = new database;
$time_description = $result["time_description"]; $row = $database->select($sql, $parameters, 'row');
unset ($prep_statement); $time_start = $row["time_start"];
$time_stop = $row["time_stop"];
$time_description = $row["time_description"];
unset($sql, $parameters, $row);
} }
//show the header //show the header

View File

@ -33,54 +33,41 @@ if (!permission_exists('contact_time_add')) { echo "access denied"; exit; }
$text = $language->get(); $text = $language->get();
//get contact uuid //get contact uuid
$domain_uuid = check_str($_REQUEST['domain_uuid']); $domain_uuid = $_REQUEST['domain_uuid'];
$contact_uuid = check_str($_REQUEST['contact_uuid']); $contact_uuid = $_REQUEST['contact_uuid'];
//get posted variables & set time status //get posted variables & set time status
if (sizeof($_POST) > 0) { if (is_array($_POST) && @sizeof($_POST) != 0) {
$contact_time_uuid = check_str($_POST['contact_time_uuid']); $contact_time_uuid = $_POST['contact_time_uuid'];
$contact_uuid = check_str($_POST['contact_uuid']); $contact_uuid = $_POST['contact_uuid'];
$time_action = check_str($_POST['time_action']); $time_action = $_POST['time_action'];
$time_description = check_str($_POST['time_description']); $time_description = $_POST['time_description'];
if ($time_description == 'Description...') { unset($time_description); } if ($time_description == 'Description...') { unset($time_description); }
if ($time_action == 'start') { if ($time_action == 'start') {
$contact_time_uuid = uuid(); $contact_time_uuid = uuid();
$sql = "insert into v_contact_times "; $array['contact_times'][0]['domain_uuid'] = $domain_uuid;
$sql .= "( "; $array['contact_times'][0]['contact_time_uuid'] = $contact_time_uuid;
$sql .= "domain_uuid, "; $array['contact_times'][0]['contact_uuid'] = $contact_uuid;
$sql .= "contact_time_uuid, "; $array['contact_times'][0]['user_uuid'] = $_SESSION["user"]["user_uuid"];
$sql .= "contact_uuid, "; $array['contact_times'][0]['time_start'] = date("Y-m-d H:i:s");
$sql .= "user_uuid, "; $array['contact_times'][0]['time_description'] = $time_description;
$sql .= "time_start, ";
$sql .= "time_description ";
$sql .= ") ";
$sql .= "values ";
$sql .= "( ";
$sql .= "'".$domain_uuid."', ";
$sql .= "'".$contact_time_uuid."', ";
$sql .= "'".$contact_uuid."', ";
$sql .= "'".$_SESSION["user"]["user_uuid"]."', ";
$sql .= "'".date("Y-m-d H:i:s")."', ";
$sql .= "'".$time_description."' ";
$sql .= ")";
$db->exec(check_sql($sql));
unset($sql);
} }
if ($time_action == 'stop') { if ($time_action == 'stop') {
$sql = "update v_contact_times "; $array['contact_times'][0]['contact_time_uuid'] = $contact_time_uuid;
$sql .= "set "; $array['contact_times'][0]['time_stop'] = date("Y-m-d H:i:s");
$sql .= "time_stop = '".date("Y-m-d H:i:s")."', "; $array['contact_times'][0]['time_description'] = $time_description;
$sql .= "time_description = '".$time_description."' ";
$sql .= "where ";
$sql .= "contact_time_uuid = '".$contact_time_uuid."' ";
$sql .= "and domain_uuid = '".$domain_uuid."' ";
$sql .= "and contact_uuid = '".$contact_uuid."' ";
$sql .= "and user_uuid = '".$_SESSION["user"]["user_uuid"]."' ";
$db->exec(check_sql($sql));
unset($sql);
} }
if (is_array($array) && @sizeof($array) != 0) {
$database = new database;
$database->app_name = 'contacts';
$database->app_uuid = '04481e0e-a478-c559-adad-52bd4174574c';
$database->save($array);
unset($array);
}
header("Location: contact_timer.php?domain_uuid=".$domain_uuid."&contact_uuid=".$contact_uuid); header("Location: contact_timer.php?domain_uuid=".$domain_uuid."&contact_uuid=".$contact_uuid);
} }
@ -91,43 +78,46 @@ if (!permission_exists('contact_time_add')) { echo "access denied"; exit; }
$sql .= "contact_name_family, "; $sql .= "contact_name_family, ";
$sql .= "contact_nickname "; $sql .= "contact_nickname ";
$sql .= "from v_contacts "; $sql .= "from v_contacts ";
$sql .= "where domain_uuid = '".$domain_uuid."' "; $sql .= "where domain_uuid = :domain_uuid ";
$sql .= "and contact_uuid = '".$contact_uuid."' "; $sql .= "and contact_uuid = :contact_uuid ";
$prep_statement = $db->prepare(check_sql($sql)); $parameters['domain_uuid'] = $domain_uuid;
$prep_statement->execute(); $parameters['contact_uuid'] = $contact_uuid;
$result = $prep_statement->fetch(PDO::FETCH_NAMED); $database = new database;
if (sizeof($result) > 0) { $row = $database->select($sql, $parameters, 'row');
$contact_organization = $result["contact_organization"]; if (is_array($row) && @sizeof($row) != 0) {
$contact_name_given = $result["contact_name_given"]; $contact_organization = $row["contact_organization"];
$contact_name_family = $result["contact_name_family"]; $contact_name_given = $row["contact_name_given"];
$contact_nickname = $result["contact_nickname"]; $contact_name_family = $row["contact_name_family"];
$contact_nickname = $row["contact_nickname"];
} }
else { else {
exit; exit;
} }
unset ($sql, $prep_statement, $result); unset($sql, $parameters, $row);
//determine timer state and action //determine timer state and action
$sql = "select "; $sql = "select ";
$sql .= "contact_time_uuid, "; $sql .= "contact_time_uuid, ";
$sql .= "time_description "; $sql .= "time_description ";
$sql .= "from v_contact_times "; $sql .= "from v_contact_times ";
$sql .= "where domain_uuid = '".$domain_uuid."' "; $sql .= "where domain_uuid = :domain_uuid ";
$sql .= "and user_uuid = '".$_SESSION['user']['user_uuid']."' "; $sql .= "and user_uuid = :user_uuid ";
$sql .= "and contact_uuid = '".$contact_uuid."' "; $sql .= "and contact_uuid = :contact_uuid ";
$sql .= "and time_start is not null "; $sql .= "and time_start is not null ";
$sql .= "and time_stop is null "; $sql .= "and time_stop is null ";
$prep_statement = $db->prepare(check_sql($sql)); $parameters['domain_uuid'] = $domain_uuid;
$prep_statement->execute(); $parameters['user_uuid'] = $_SESSION['user']['user_uuid'];
$result = $prep_statement->fetch(PDO::FETCH_NAMED); $parameters['contact_uuid'] = $contact_uuid;
if (sizeof($result) > 0) { $database = new database;
$contact_time_uuid = $result["contact_time_uuid"]; $row = $database->select($sql, $parameters, 'row');
$time_description = $result["time_description"]; if (is_array($row) && @sizeof($row) != 0) {
$contact_time_uuid = $row["contact_time_uuid"];
$time_description = $row["time_description"];
} }
unset ($sql, $prep_statement, $result); unset($sql, $parameters, $row);
$timer_state = ($contact_time_uuid != '') ? 'running' : 'stopped'; $timer_state = is_uuid($contact_time_uuid) ? 'running' : 'stopped';
$timer_action = ($timer_state == 'running') ? 'stop' : 'start'; $timer_action = $timer_state == 'running' ? 'stop' : 'start';
//determine contact name to display //determine contact name to display
if ($contact_nickname != '') { if ($contact_nickname != '') {
@ -358,4 +348,4 @@ if (!permission_exists('contact_time_add')) { echo "access denied"; exit; }
</center> </center>
</form> </form>
</body> </body>
</html> </html>

View File

@ -29,29 +29,32 @@ require_once "resources/check_auth.php";
if (!permission_exists('contact_time_add')) { echo "access denied"; exit; } if (!permission_exists('contact_time_add')) { echo "access denied"; exit; }
//get contact and time uuids //get contact and time uuids
$domain_uuid = check_str($_REQUEST['domain_uuid']); $domain_uuid = $_REQUEST['domain_uuid'];
$contact_uuid = check_str($_REQUEST['contact_uuid']); $contact_uuid = $_REQUEST['contact_uuid'];
$contact_time_uuid = check_str($_REQUEST['contact_time_uuid']); $contact_time_uuid = $_REQUEST['contact_time_uuid'];
//get time quantity //get time quantity
$sql = "select "; $sql = "select ";
$sql .= "time_start "; $sql .= "time_start ";
$sql .= "from v_contact_times "; $sql .= "from v_contact_times ";
$sql .= "where domain_uuid = '".$domain_uuid."' "; $sql .= "where domain_uuid = :domain_uuid ";
$sql .= "and contact_time_uuid = '".$contact_time_uuid."' "; $sql .= "and contact_time_uuid = :contact_time_uuid ";
$sql .= "and user_uuid = '".$_SESSION['user']['user_uuid']."' "; $sql .= "and user_uuid = :user_uuid ";
$sql .= "and contact_uuid = '".$contact_uuid."' "; $sql .= "and contact_uuid = :contact_uuid ";
$sql .= "and time_start is not null "; $sql .= "and time_start is not null ";
$sql .= "and time_stop is null "; $sql .= "and time_stop is null ";
$prep_statement = $db->prepare(check_sql($sql)); $parameters['domain_uuid'] = $domain_uuid;
$prep_statement->execute(); $parameters['contact_uuid'] = $contact_uuid;
$result = $prep_statement->fetch(PDO::FETCH_NAMED); $parameters['user_uuid'] = $_SESSION['user']['user_uuid'];
if (sizeof($result) > 0) { $parameters['contact_time_uuid'] = $contact_time_uuid;
$time_start = strtotime($result["time_start"]); $database = new database;
$row = $database->select($sql, $parameters, 'row');
if (is_array($row) && @sizeof($row) != 0) {
$time_start = strtotime($row["time_start"]);
$time_now = strtotime(date("Y-m-d H:i:s")); $time_now = strtotime(date("Y-m-d H:i:s"));
$time_diff = gmdate("H:i:s", ($time_now - $time_start)); $time_diff = gmdate("H:i:s", ($time_now - $time_start));
echo $time_diff; echo $time_diff;
echo "<script id='title_script'>set_title('".$time_diff."');</script>"; echo "<script id='title_script'>set_title('".$time_diff."');</script>";
} }
unset ($sql, $prep_statement, $result); unset ($sql, $parameters, $row);
?> ?>

View File

@ -42,14 +42,14 @@
$sql = "select ct.*, u.username, u.domain_uuid as user_domain_uuid "; $sql = "select ct.*, u.username, u.domain_uuid as user_domain_uuid ";
$sql .= "from v_contact_times as ct, v_users as u "; $sql .= "from v_contact_times as ct, v_users as u ";
$sql .= "where ct.user_uuid = u.user_uuid "; $sql .= "where ct.user_uuid = u.user_uuid ";
$sql .= "and ct.domain_uuid = '".$domain_uuid."' "; $sql .= "and ct.domain_uuid = :domain_uuid ";
$sql .= "and ct.contact_uuid = '".$contact_uuid."' "; $sql .= "and ct.contact_uuid = :contact_uuid ";
$sql .= "order by ct.time_start desc "; $sql .= "order by ct.time_start desc ";
$prep_statement = $db->prepare(check_sql($sql)); $parameters['domain_uuid'] = $domain_uuid;
$prep_statement->execute(); $parameters['contact_uuid'] = $contact_uuid;
$result = $prep_statement->fetchAll(PDO::FETCH_NAMED); $database = new database;
$result_count = count($result); $result = $database->select($sql, $parameters, 'all');
unset ($prep_statement, $sql); unset($sql, $parameters);
//set the row style //set the row style
$c = 0; $c = 0;
@ -85,7 +85,7 @@
echo "<div id='div_contact_times' style='width: 100%; overflow: auto; direction: rtl; text-align: right; margin-bottom: 23px;'>"; echo "<div id='div_contact_times' style='width: 100%; overflow: auto; direction: rtl; text-align: right; margin-bottom: 23px;'>";
echo "<table id='table_contact_times' class='tr_hover' style='width: 100%; direction: ltr;' border='0' cellpadding='0' cellspacing='0'>\n"; echo "<table id='table_contact_times' class='tr_hover' style='width: 100%; direction: ltr;' border='0' cellpadding='0' cellspacing='0'>\n";
if ($result_count > 0) { if (is_array($result) && @sizeof($result) != 0) {
foreach($result as $row) { foreach($result as $row) {
$tr_link = (permission_exists('contact_time_edit') && $row['user_uuid'] == $_SESSION["user"]["user_uuid"]) ? "href='contact_time_edit.php?contact_uuid=".escape($row['contact_uuid'])."&id=".escape($row['contact_time_uuid'])."'" : null; $tr_link = (permission_exists('contact_time_edit') && $row['user_uuid'] == $_SESSION["user"]["user_uuid"]) ? "href='contact_time_edit.php?contact_uuid=".escape($row['contact_uuid'])."&id=".escape($row['contact_time_uuid'])."'" : null;
echo "<tr ".$tr_link.">\n"; echo "<tr ".$tr_link.">\n";
@ -120,9 +120,9 @@
} }
echo " </td>\n"; echo " </td>\n";
echo "</tr>\n"; echo "</tr>\n";
$c = ($c) ? 0 : 1; $c = $c ? 0 : 1;
} //end foreach } //end foreach
unset($sql, $result, $row_count); unset($result, $row);
} //end if results } //end if results
echo "</table>"; echo "</table>";
echo "</div>\n"; echo "</div>\n";

View File

@ -150,6 +150,7 @@ else {
header("Location: contact_edit.php?id=".$contact_uuid); header("Location: contact_edit.php?id=".$contact_uuid);
exit; exit;
} }
} }