Portions created by the Initial Developer are Copyright (C) 2018 the Initial Developer. All Rights Reserved. Contributor(s): Mark J Crane */ //includes require_once "root.php"; require_once "resources/require.php"; require_once "resources/check_auth.php"; //check permissions if (!permission_exists('access_control_add') && !permission_exists('access_control_edit')) { echo "access denied"; exit; } //add multi-lingual support $language = new text; $text = $language->get(); //action add or update if (is_uuid($_REQUEST["id"])) { $action = "update"; $access_control_uuid = $_REQUEST["id"]; } else { $action = "add"; } //get http post variables and set them to php variables if (count($_POST)>0) { $access_control_name = $_POST["access_control_name"]; $access_control_default = $_POST["access_control_default"]; $access_control_description = $_POST["access_control_description"]; } if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { //delete the access control if (permission_exists('access_control_delete')) { if ($_POST['action'] == 'delete' && is_uuid($access_control_uuid)) { //prepare $array[0]['checked'] = 'true'; $array[0]['uuid'] = $access_control_uuid; //delete $obj = new access_controls; $obj->delete($array); //redirect header('Location: access_controls.php'); exit; } } //get the primary key if ($action == "update") { $access_control_uuid = $_POST["access_control_uuid"]; } //validate the token $token = new token; if (!$token->validate($_SERVER['PHP_SELF'])) { message::add($text['message-invalid_token'],'negative'); header('Location: access_controls.php'); exit; } //check for all required data $msg = ''; if (strlen($access_control_name) == 0) { $msg .= $text['message-required']." ".$text['label-access_control_name']."
\n"; } if (strlen($access_control_default) == 0) { $msg .= $text['message-required']." ".$text['label-access_control_default']."
\n"; } //if (strlen($access_control_description) == 0) { $msg .= $text['message-required']." ".$text['label-access_control_description']."
\n"; } if (strlen($msg) > 0 && strlen($_POST["persistformvar"]) == 0) { require_once "resources/header.php"; require_once "resources/persist_form_var.php"; echo "
\n"; echo "
\n"; echo $msg."
"; echo "
\n"; persistformvar($_POST); echo "
\n"; require_once "resources/footer.php"; return; } //add or update the database if ($_POST["persistformvar"] != "true") { $execute = false; if ($action == "add" && permission_exists('access_control_add')) { $execute = true; $access_control_uuid = uuid(); //set the message message::add($text['message-add']); //set redirect url $redirect_url = 'access_control_edit.php?id='.$access_control_uuid; } if ($action == "update" && permission_exists('access_control_edit')) { $execute = true; //set the message message::add($text['message-update']); } if ($execute) { $array['access_controls'][0]['access_control_uuid'] = $access_control_uuid; $array['access_controls'][0]['access_control_name'] = $access_control_name; $array['access_controls'][0]['access_control_default'] = $access_control_default; $array['access_controls'][0]['access_control_description'] = $access_control_description; $database = new database; $database->app_name = 'access_control'; $database->app_uuid = '1416a250-f6e1-4edc-91a6-5c9b883638fd'; $database->save($array); unset($array); //clear the cache $cache = new cache; $cache->delete("configuration:acl.conf"); //create the event socket connection $fp = event_socket_create($_SESSION['event_socket_ip_address'], $_SESSION['event_socket_port'], $_SESSION['event_socket_password']); if ($fp) { event_socket_request($fp, "api reloadacl"); } } //redirect the user header('Location: '.($redirect_url ? $redirect_url : 'access_controls.php')); exit; } } //pre-populate the form if (count($_GET) > 0 && $_POST["persistformvar"] != "true" && is_uuid($_GET["id"])) { $access_control_uuid = $_GET["id"]; $sql = "select * from v_access_controls "; $sql .= "where access_control_uuid = :access_control_uuid "; $parameters['access_control_uuid'] = $access_control_uuid; $database = new database; $row = $database->select($sql, $parameters, 'row'); if (is_array($row) && sizeof($row)) { $access_control_name = $row["access_control_name"]; $access_control_default = $row["access_control_default"]; $access_control_description = $row["access_control_description"]; } unset ($sql, $parameters, $row); } //create token $object = new token; $token = $object->create($_SERVER['PHP_SELF']); //show the header $document['title'] = $text['title-access_control']; require_once "resources/header.php"; //show the content echo "
\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo "\n"; echo " \n"; echo " \n"; echo " "; echo "
".$text['title-access_control']."

\n"; echo " "; if ($action == 'update' && permission_exists('access_control_delete')) { echo button::create(['type'=>'submit','label'=>$text['button-delete'],'icon'=>$_SESSION['theme']['button_icon_delete'],'name'=>'action','value'=>'delete','onclick'=>"if (confirm('".$text['confirm-delete']."')) { document.getElementById('frm').submit(); } else { this.blur(); return false; }",'style'=>'margin-right: 15px;']); } echo " "; echo "
\n"; echo " ".$text['label-access_control_name']."\n"; echo "\n"; echo " \n"; echo "
\n"; echo $text['description-access_control_name']."\n"; echo "
\n"; echo " ".$text['label-access_control_default']."\n"; echo "\n"; echo " \n"; echo "
\n"; echo $text['description-access_control_default']."\n"; echo "
\n"; echo " ".$text['label-access_control_description']."\n"; echo "\n"; echo " \n"; echo "
\n"; echo $text['description-access_control_description']."\n"; echo "
\n"; if ($action == "update") { echo " \n"; } echo " \n"; echo "
"; echo "
"; echo "

"; if ($action == "update") { require "access_control_nodes.php"; echo "

"; } //include the footer require_once "resources/footer.php"; ?>