Fix photo edition by other users (Closes #1160)
[platal.git] / modules / profile.php
CommitLineData
7d8b17cb 1<?php
2/***************************************************************************
9f5bd98e 3 * Copyright (C) 2003-2010 Polytechnique.org *
7d8b17cb 4 * http://opensource.polytechnique.org/ *
5 * *
6 * This program is free software; you can redistribute it and/or modify *
7 * it under the terms of the GNU General Public License as published by *
8 * the Free Software Foundation; either version 2 of the License, or *
9 * (at your option) any later version. *
10 * *
11 * This program is distributed in the hope that it will be useful, *
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
14 * GNU General Public License for more details. *
15 * *
16 * You should have received a copy of the GNU General Public License *
17 * along with this program; if not, write to the Free Software *
18 * Foundation, Inc., *
19 * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA *
20 ***************************************************************************/
21
22class ProfileModule extends PLModule
23{
24 function handlers()
25 {
26 return array(
2398e553
SJ
27 'photo' => $this->make_hook('photo', AUTH_PUBLIC),
28 'photo/change' => $this->make_hook('photo_change', AUTH_MDP),
e49018a7 29
2398e553
SJ
30 'fiche.php' => $this->make_hook('fiche', AUTH_PUBLIC),
31 'profile' => $this->make_hook('profile', AUTH_PUBLIC),
32 'profile/private' => $this->make_hook('profile', AUTH_COOKIE),
33 'profile/ax' => $this->make_hook('ax', AUTH_COOKIE, 'admin'),
34 'profile/edit' => $this->make_hook('p_edit', AUTH_MDP),
35 'profile/ajax/address' => $this->make_hook('ajax_address', AUTH_COOKIE, 'user', NO_AUTH),
36 'profile/ajax/tel' => $this->make_hook('ajax_tel', AUTH_COOKIE, 'user', NO_AUTH),
37 'profile/ajax/edu' => $this->make_hook('ajax_edu', AUTH_COOKIE, 'user', NO_AUTH),
38 'profile/ajax/medal' => $this->make_hook('ajax_medal', AUTH_COOKIE, 'user', NO_AUTH),
39 'profile/networking' => $this->make_hook('networking', AUTH_PUBLIC),
40 'profile/ajax/job' => $this->make_hook('ajax_job', AUTH_COOKIE, 'user', NO_AUTH),
541e8d03
SJ
41 'profile/ajax/sector' => $this->make_hook('ajax_sector', AUTH_COOKIE, 'user', NO_AUTH),
42 'profile/ajax/sub_sector' => $this->make_hook('ajax_sub_sector', AUTH_COOKIE, 'user', NO_AUTH),
07e72582 43 'profile/ajax/alternates' => $this->make_hook('ajax_alternates', AUTH_COOKIE, 'user', NO_AUTH),
2398e553
SJ
44 'profile/ajax/skill' => $this->make_hook('ajax_skill', AUTH_COOKIE, 'user', NO_AUTH),
45 'profile/ajax/searchname' => $this->make_hook('ajax_searchname', AUTH_COOKIE, 'user', NO_AUTH),
6e32823c 46 'profile/ajax/buildnames' => $this->make_hook('ajax_buildnames', AUTH_COOKIE, 'user', NO_AUTH),
f711b03f 47 'javascript/education.js' => $this->make_hook('education_js', AUTH_COOKIE),
2398e553
SJ
48 'javascript/grades.js' => $this->make_hook('grades_js', AUTH_COOKIE),
49 'profile/medal' => $this->make_hook('medal', AUTH_PUBLIC),
70c65f3a 50 'profile/name_info' => $this->make_hook('name_info', AUTH_PUBLIC),
e49018a7 51
2398e553
SJ
52 'referent' => $this->make_hook('referent', AUTH_COOKIE),
53 'emploi' => $this->make_hook('ref_search', AUTH_COOKIE),
bac2d162 54 'jobs' => $this->make_hook('ref_search', AUTH_COOKIE),
2398e553
SJ
55 'referent/search' => $this->make_hook('ref_search', AUTH_COOKIE),
56 'referent/ssect' => $this->make_hook('ref_sect', AUTH_COOKIE, 'user', NO_AUTH),
57 'referent/country' => $this->make_hook('ref_country', AUTH_COOKIE, 'user', NO_AUTH),
2f678da1 58
2398e553 59 'groupes-x' => $this->make_hook('xnet', AUTH_COOKIE),
1dc71da1 60 'groupes-x/logo' => $this->make_hook('xnetlogo', AUTH_PUBLIC),
926f16d7 61
2398e553
SJ
62 'vcard' => $this->make_hook('vcard', AUTH_COOKIE, 'user', NO_HTTPS),
63 'admin/binets' => $this->make_hook('admin_binets', AUTH_MDP, 'admin'),
64 'admin/medals' => $this->make_hook('admin_medals', AUTH_MDP, 'admin'),
65 'admin/education' => $this->make_hook('admin_education', AUTH_MDP, 'admin'),
66 'admin/education_field' => $this->make_hook('admin_education_field', AUTH_MDP, 'admin'),
67 'admin/education_degree' => $this->make_hook('admin_education_degree', AUTH_MDP, 'admin'),
043bbacf 68 'admin/education_degree_set' => $this->make_hook('admin_education_degree_set', AUTH_MDP, 'admin'),
2398e553 69 'admin/sections' => $this->make_hook('admin_sections', AUTH_MDP, 'admin'),
2398e553
SJ
70 'admin/networking' => $this->make_hook('admin_networking', AUTH_MDP, 'admin'),
71 'admin/trombino' => $this->make_hook('admin_trombino', AUTH_MDP, 'admin'),
b6e9d1ca 72 'admin/sectors' => $this->make_hook('admin_sectors', AUTH_MDP, 'admin'),
4962a9ce
SJ
73 'admin/corps_enum' => $this->make_hook('admin_corps_enum', AUTH_MDP, 'admin'),
74 'admin/corps_rank' => $this->make_hook('admin_corps_rank', AUTH_MDP, 'admin'),
b62db02e 75 'admin/names' => $this->make_hook('admin_names', AUTH_MDP, 'admin'),
7d8b17cb 76 );
77 }
78
e8599c21 79 /* XXX COMPAT */
80 function handler_fiche(&$page)
81 {
5e2307dc 82 return $this->handler_profile($page, Env::v('user'));
e8599c21 83 }
84
adbdf493 85 function handler_photo(&$page, $x = null, $req = null)
86 {
706f830d 87 if (!$x || !($profile = Profile::get($x))) {
adbdf493 88 return PL_NOT_FOUND;
89 }
90
954cfb01 91 // Retrieve the photo and its mime type.
cab08090 92 if ($req && S::logged()) {
adbdf493 93 include 'validations.inc.php';
58bb2d9c 94 $myphoto = PhotoReq::get_request($profile->id());
833a6e86 95 $photo = PlImage::fromData($myphoto->data, $myphoto->mimetype);
adbdf493 96 } else {
7988f7d6 97 $photo = $profile->getPhoto(true, true);
adbdf493 98 }
954cfb01
VZ
99
100 // Display the photo, or a default one when not available.
833a6e86 101 $photo->send();
adbdf493 102 }
103
85cc366b
FB
104 function handler_medal(&$page, $mid)
105 {
bd6a5fe3
VZ
106 $thumb = ($mid == 'thumb');
107 $mid = $thumb ? @func_get_arg(2) : $mid;
108
85cc366b 109 $res = XDB::query("SELECT img
5c8a71f2 110 FROM profile_medal_enum
85cc366b
FB
111 WHERE id = {?}",
112 $mid);
bd6a5fe3
VZ
113 $img = $thumb ?
114 dirname(__FILE__).'/../htdocs/images/medals/thumb/' . $res->fetchOneCell() :
115 dirname(__FILE__).'/../htdocs/images/medals/' . $res->fetchOneCell();
3cb500d5 116 pl_cached_content_headers(mime_content_type($img));
85cc366b
FB
117 echo file_get_contents($img);
118 exit;
119 }
120
70c65f3a
SJ
121 function handler_name_info(&$page)
122 {
e5ef8615 123 pl_content_headers("text/html");
70c65f3a
SJ
124 $page->changeTpl('profile/name_info.tpl', SIMPLE);
125 $res = XDB::iterator("SELECT name, explanations,
126 FIND_IN_SET('public', flags) AS public,
127 FIND_IN_SET('has_particle', flags) AS has_particle
97a98687 128 FROM profile_name_enum
70c65f3a
SJ
129 WHERE NOT FIND_IN_SET('not_displayed', flags)
130 ORDER BY NOT FIND_IN_SET('public', flags)");
131 $page->assign('types', $res);
132 }
133
40176c6c
GB
134 function handler_networking(&$page, $mid)
135 {
136 $res = XDB::query("SELECT icon
137 FROM profile_networking_enum
1f5cd004 138 WHERE nwid = {?}",
40176c6c
GB
139 $mid);
140 $img = dirname(__FILE__) . '/../htdocs/images/networking/' . $res->fetchOneCell();
e5ef8615 141 pl_cached_content_headers(mime_content_type($img));
40176c6c
GB
142 echo file_get_contents($img);
143 exit;
144 }
145
58bb2d9c
RB
146 /** Tries to return the correct user from given hrpid
147 * Will redirect to $returnurl$hrpid if $hrpid was empty
148 */
149 private function findProfile($returnurl, $hrpid = null)
150 {
151 if (is_null($hrpid)) {
152 $user = S::user();
153 if (!$user->hasProfile()) {
154 return PL_NOT_FOUND;
155 } else {
156 pl_redirect($returnurl . $user->profile()->hrid());
157 }
158 } else {
159 $profile = Profile::get($hrpid);
160 if (!$profile) {
161 return PL_NOT_FOUND;
162 } else if (!S::user()->canEdit($profile) && Platal::notAllowed()) {
163 return PL_FORBIDDEN;
164 }
165 }
166 return $profile;
167 }
168
169 function handler_photo_change(&$page, $hrpid = null)
fb9a56cb 170 {
ebfdf077 171 global $globals;
58bb2d9c
RB
172 $profile = $this->findProfile('photo/change/', $hrpid);
173 if (! ($profile instanceof Profile) && ($profile == PL_NOT_FOUND || $profile == PL_FORBIDDEN)) {
174 return $profile;
175 }
176
8b1f8e12 177 $page->changeTpl('profile/trombino.tpl');
58bb2d9c 178 $page->assign('hrpid', $profile->hrid());
fb9a56cb 179
180 require_once('validations.inc.php');
181
58bb2d9c 182 $trombi_x = '/home/web/trombino/photos' . $profile->promo() . '/' . $profile->hrid() . '.jpg';
fb9a56cb 183 if (Env::has('upload')) {
8827fc52
VZ
184 S::assert_xsrf_token();
185
58bb2d9c 186 $upload = new PlUpload($profile->hrid(), 'photo');
abe7e055 187 if (!$upload->upload($_FILES['userfile']) && !$upload->download(Env::v('photo'))) {
a7d35093 188 $page->trigError('Une erreur est survenue lors du téléchargement du fichier');
abe7e055 189 } else {
58bb2d9c 190 $myphoto = new PhotoReq(S::user(), $profile, $upload);
abe7e055 191 if ($myphoto->isValid()) {
192 $myphoto->submit();
fb9a56cb 193 }
fb9a56cb 194 }
195 } elseif (Env::has('trombi')) {
8827fc52
VZ
196 S::assert_xsrf_token();
197
58bb2d9c 198 $upload = new PlUpload($profile->hrid(), 'photo');
abe7e055 199 if ($upload->copyFrom($trombi_x)) {
58bb2d9c 200 $myphoto = new PhotoReq(S::user(), $profile, $upload);
abe7e055 201 if ($myphoto->isValid()) {
202 $myphoto->commit();
203 $myphoto->clean();
204 }
fb9a56cb 205 }
5e2307dc 206 } elseif (Env::v('suppr')) {
8827fc52
VZ
207 S::assert_xsrf_token();
208
5c4ea53f
FB
209 XDB::execute('DELETE FROM profile_photos
210 WHERE pid = {?}',
58bb2d9c 211 $profile->id());
257ae408 212 XDB::execute("DELETE FROM requests
58bb2d9c
RB
213 WHERE pid = {?} AND type = 'photo'",
214 $profile->id());
ebfdf077 215 $globals->updateNbValid();
716dedc5 216 $page->trigSuccess("Ta photo a bien été supprimée. Elle ne sera plus visible sur le site dans au plus une heure.");
5e2307dc 217 } elseif (Env::v('cancel')) {
8827fc52
VZ
218 S::assert_xsrf_token();
219
257ae408 220 $sql = XDB::query("DELETE FROM requests
58bb2d9c
RB
221 WHERE pid = {?} AND type = 'photo'",
222 $profile->id());
ebfdf077 223 $globals->updateNbValid();
fb9a56cb 224 }
225
257ae408 226 $sql = XDB::query("SELECT COUNT(*)
84868ee9 227 FROM requests
58bb2d9c
RB
228 WHERE pid = {?} AND type = 'photo'",
229 $profile->id());
fb9a56cb 230 $page->assign('submited', $sql->fetchOneCell());
231 $page->assign('has_trombi_x', file_exists($trombi_x));
fb9a56cb 232 }
233
9b09e3fb 234 function handler_profile(&$page, $id = null)
e8599c21 235 {
9b09e3fb
SJ
236 // Checks if the identifier corresponds to an actual profile. Numeric
237 // identifiers canonly be user by logged users.
238 if (is_null($id)) {
e8599c21 239 return PL_NOT_FOUND;
240 }
23ff6dd6 241 $pid = (!is_numeric($id) || S::admin()) ? Profile::getPID($id) : null;
9b09e3fb 242 if (is_null($pid)) {
efe597c5 243 if (S::logged()) {
9b09e3fb 244 $page->trigError($id . " inconnu dans l'annuaire.");
efe597c5 245 }
344234db 246 return PL_NOT_FOUND;
e8599c21 247 }
e8599c21 248
9b09e3fb
SJ
249 // Now that we know this is an existing profile, we can switch to the
250 // appropriate template.
b13048df 251 $page->changeTpl('profile/profile.tpl', SIMPLE);
e8599c21 252
54cabe90
VZ
253 // Determines the access level at which the profile will be displayed.
254 if (!S::logged() || Env::v('view') == 'public') {
255 $view = 'public';
256 } else if (S::logged() && Env::v('view') == 'ax') {
257 $view = 'ax';
e8599c21 258 } else {
54cabe90 259 $view = 'private';
e8599c21 260 }
261
9b09e3fb
SJ
262 // Fetches profile's and profile's owner information and redirects to
263 // marketing if the owner has not subscribed and the requirer has logged in.
d1095b1d 264 $profile = Profile::get($pid, Profile::FETCH_ALL, $view);
9b09e3fb
SJ
265 $owner = $profile->owner();
266 if (S::logged() && !is_null($owner) && $owner->state == 'pending') {
267 pl_redirect('marketing/public/' . $profile->hrid());
e8599c21 268 }
ba25f663 269
54cabe90 270 // Profile view are logged.
e31c1c3e 271 if (S::logged()) {
9b09e3fb 272 S::logger()->log('view_profile', $profile->hrid());
e8599c21 273 }
274
54cabe90 275 // Sets the title of the html page.
9b09e3fb 276 $page->setTitle($profile->fullName());
e8599c21 277
54cabe90 278 // Determines and displays the virtual alias.
8446dbd3 279 if (!is_null($owner) && $profile->alias_pub == 'public') {
efe597c5
FB
280 $page->assign('virtualalias', $owner->emailAlias());
281 }
54cabe90 282
68f988a8
RB
283 $page->assign_by_ref('profile', $profile);
284 $page->assign_by_ref('owner', $owner);
bdce53bb 285 $page->assign('view', $view);
e859bdaf 286 $page->assign('logged', S::logged());
e8599c21 287
c99ef281 288 $page->addJsLink('close_on_esc.js');
9b09e3fb 289 header('Last-Modified: ' . date('r', strtotime($profile->last_change)));
e8599c21 290 }
291
5122b820 292 function handler_ax(&$page, $user = null)
293 {
c52d86d1 294 $user = Profile::get($user);
5122b820 295 if (!$user) {
296 return PL_NOT_FOUND;
297 }
c52d86d1
FB
298 if (!$user->ax_id) {
299 $page->kill("Le matricule AX de {$user->hrid()} est inconnu");
5122b820 300 }
e46cf8c4 301 http_redirect("http://www.polytechniciens.com/?page=AX_FICHE_ANCIEN&ancc_id=" . $user->ax_id);
5122b820 302 }
303
58bb2d9c 304 function handler_p_edit(&$page, $hrpid = null, $opened_tab = null, $mode = null, $success = null)
2f678da1 305 {
306 global $globals;
307
58bb2d9c
RB
308 $profile = $this->findProfile('profile/edit/', $hrpid);
309 if (! ($profile instanceof Profile) && ($profile == PL_NOT_FOUND || $profile == PL_FORBIDDEN)) {
310 return $profile;
3af21f99
FB
311 }
312
7bff4cb0 313 // Build the page
c6a7beb2 314 $page->addJsLink('ajax.js');
6dc215d1
SJ
315 $page->addJsLink('education.js', false); /* dynamic content */
316 $page->addJsLink('grades.js', false); /* dynamic content */
16594a1a 317 $page->addJsLink('profile.js');
4b4b4b67 318 $page->addJsLink('jquery.autocomplete.js');
e5bcd851 319 $wiz = new PlWizard('Profil', PlPage::getCoreTpl('plwizard.tpl'), true, true, false);
58bb2d9c
RB
320 $wiz->addUserData('profile', $profile);
321 $wiz->addUserData('owner', $profile->owner());
460d8f55 322 $this->load('page.inc.php');
12bcf04b
RB
323 $wiz->addPage('ProfileSettingGeneral', 'Général', 'general');
324 $wiz->addPage('ProfileSettingAddresses', 'Adresses personnelles', 'adresses');
325 $wiz->addPage('ProfileSettingGroups', 'Groupes X - Binets', 'poly');
326 $wiz->addPage('ProfileSettingDecos', 'Décorations - Medailles', 'deco');
327 $wiz->addPage('ProfileSettingJobs', 'Informations professionnelles', 'emploi');
328 $wiz->addPage('ProfileSettingSkills', 'Compétences diverses', 'skill');
329 $wiz->addPage('ProfileSettingMentor', 'Mentoring', 'mentor');
58bb2d9c 330 $wiz->apply($page, 'profile/edit/' . $profile->hrid(), $opened_tab, $mode);
35aedff2 331
58bb2d9c 332 if (!$profile->birthdate) {
a7d35093 333 $page->trigWarning("Ta date de naissance n'est pas renseignée, ce qui t'empêcheras de réaliser"
6e32823c 334 . " la procédure de récupération de mot de passe si un jour tu le perdais.");
7bff4cb0
FB
335 }
336
46f272fe 337 $page->setTitle('Mon Profil');
eb563236
SJ
338 if (isset($success) && $success) {
339 $page->trigSuccess('Ton profil a bien été mis à jour.');
340 }
2f678da1 341 }
342
f711b03f 343 function handler_education_js(&$page)
46ae38a9 344 {
3cb500d5 345 pl_cached_content_headers("text/javascript", "utf-8");
f711b03f 346 $page->changeTpl('profile/education.js.tpl', NO_SKIN);
ee718651 347 require_once 'education.func.inc.php';
46ae38a9
FB
348 }
349
350 function handler_grades_js(&$page)
351 {
3cb500d5 352 pl_cached_content_headers("text/javascript", "utf-8");
46ae38a9
FB
353 $page->changeTpl('profile/grades.js.tpl', NO_SKIN);
354 $res = XDB::iterator("SELECT *
c6d16b24 355 FROM profile_medal_grade_enum
46ae38a9
FB
356 ORDER BY mid, pos");
357 $grades = array();
358 while ($tmp = $res->next()) {
359 $grades[$tmp['mid']][] = $tmp;
360 }
361 $page->assign('grades', $grades);
362
363 $res = XDB::iterator("SELECT *, FIND_IN_SET('validation', flags) AS validate
5c8a71f2 364 FROM profile_medal_enum
46ae38a9
FB
365 ORDER BY type, text");
366 $mlist = array();
367 while ($tmp = $res->next()) {
368 $mlist[$tmp['type']][] = $tmp;
369 }
370 $page->assign('medal_list', $mlist);
371 }
372
041a5cec 373 function handler_ajax_address(&$page, $id)
c6a7beb2 374 {
3cb500d5 375 pl_content_headers("text/html");
c6a7beb2 376 $page->changeTpl('profile/adresses.address.tpl', NO_SKIN);
041a5cec
SJ
377 $page->assign('i', $id);
378 $page->assign('address', array());
c6a7beb2
FB
379 }
380
bde2be3b 381 function handler_ajax_tel(&$page, $prefid, $prefname, $telid)
c6a7beb2 382 {
3cb500d5 383 pl_content_headers("text/html");
bde2be3b
GB
384 $page->changeTpl('profile/phone.tpl', NO_SKIN);
385 $page->assign('prefid', $prefid);
386 $page->assign('prefname', $prefname);
387 $page->assign('telid', $telid);
c6a7beb2 388 $page->assign('tel', array());
c6a7beb2
FB
389 }
390
58acfe8b 391 function handler_ajax_edu(&$page, $eduid, $class)
043bbacf 392 {
e5ef8615 393 pl_content_headers("text/html");
2700a4f5 394 $page->changeTpl('profile/general.edu.tpl', NO_SKIN);
043bbacf
SJ
395 $res = XDB::iterator("SELECT id, field
396 FROM profile_education_field_enum
397 ORDER BY field");
398 $page->assign('edu_fields', $res->fetchAllAssoc());
399 $page->assign('eduid', $eduid);
58acfe8b 400 $page->assign('class', $class);
f711b03f 401 require_once "education.func.inc.php";
043bbacf
SJ
402 }
403
85cc366b
FB
404 function handler_ajax_medal(&$page, $id)
405 {
3cb500d5 406 pl_content_headers("text/html");
85cc366b
FB
407 $page->changeTpl('profile/deco.medal.tpl', NO_SKIN);
408 $page->assign('id', $id);
409 $page->assign('medal', array('valid' => 0, 'grade' => 0));
85cc366b
FB
410 }
411
2dcac0f5
FB
412 function handler_ajax_job(&$page, $id)
413 {
3cb500d5 414 pl_content_headers("text/html");
2dcac0f5
FB
415 $page->changeTpl('profile/jobs.job.tpl', NO_SKIN);
416 $page->assign('i', $id);
417 $page->assign('job', array());
2dcac0f5 418 $page->assign('new', true);
2992a284 419 $res = XDB::query("SELECT id, name AS label
b814a8b8 420 FROM profile_job_sector_enum");
541e8d03 421 $page->assign('sectors', $res->fetchAllAssoc());
06a99865
SJ
422 require_once "emails.combobox.inc.php";
423 fill_email_combobox($page);
2dcac0f5
FB
424 }
425
541e8d03 426 function handler_ajax_sector(&$page, $id, $jobid, $jobpref, $sect, $ssect = -1)
2dcac0f5 427 {
3cb500d5 428 pl_content_headers("text/html");
541e8d03 429 $res = XDB::iterator("SELECT id, name, FIND_IN_SET('optgroup', flags) AS optgroup
c7139c07
SJ
430 FROM profile_job_subsector_enum
431 WHERE sectorid = {?}", $sect);
541e8d03 432 $page->changeTpl('profile/jobs.sector.tpl', NO_SKIN);
2dcac0f5 433 $page->assign('id', $id);
541e8d03 434 $page->assign('subSectors', $res);
2dcac0f5 435 $page->assign('sel', $ssect);
5fecdf6d
SJ
436 if ($id != -1) {
437 $page->assign('change', 1);
438 $page->assign('jobid', $jobid);
439 $page->assign('jobpref', $jobpref);
440 }
c7139c07
SJ
441 }
442
541e8d03 443 function handler_ajax_sub_sector(&$page, $id, $ssect, $sssect = -1)
c7139c07 444 {
e5ef8615 445 pl_content_headers("text/html");
541e8d03 446 $res = XDB::iterator("SELECT id, name
c7139c07
SJ
447 FROM profile_job_subsubsector_enum
448 WHERE subsectorid = {?}", $ssect);
541e8d03 449 $page->changeTpl('profile/jobs.sub_sector.tpl', NO_SKIN);
c7139c07 450 $page->assign('id', $id);
541e8d03 451 $page->assign('subSubSectors', $res);
c7139c07 452 $page->assign('sel', $sssect);
2dcac0f5
FB
453 }
454
07e72582
SJ
455 function handler_ajax_alternates(&$page, $id, $sssect)
456 {
e5ef8615 457 pl_content_headers("text/html");
07e72582
SJ
458 $res = XDB::iterator('SELECT name
459 FROM profile_job_alternates
460 WHERE subsubsectorid = {?}
461 ORDER BY id',
462 $sssect);
463 $page->changeTpl('profile/jobs.alternates.tpl', NO_SKIN);
ee199bc8
SJ
464 $alternates = '';
465 if ($res->total() > 0) {
466 $alternate = $res->next();
467 $alternates = $alternate['name'];
468 while ($alternate = $res->next()) {
469 $alternates .= ', ' . $alternate['name'];
470 }
07e72582
SJ
471 }
472 $page->assign('alternates', $alternates);
473 }
474
f25e1a56
FB
475 function handler_ajax_skill(&$page, $cat, $id)
476 {
3cb500d5 477 pl_content_headers("text/html");
f25e1a56 478 $page->changeTpl('profile/skill.skill.tpl', NO_SKIN);
f25e1a56
FB
479 $page->assign('cat', $cat);
480 $page->assign('id', $id);
481 if ($cat == 'competences') {
482 $page->assign('levels', array('initié' => 'initié',
483 'bonne connaissance' => 'bonne connaissance',
484 'expert' => 'expert'));
485 } else {
486 $page->assign('levels', array(1 => 'connaissance basique',
487 2 => 'maîtrise des bases',
488 3 => 'maîtrise limitée',
489 4 => 'maîtrise générale',
490 5 => 'bonne maîtrise',
491 6 => 'maîtrise complète'));
492 }
493 }
494
04e200e0 495 function handler_ajax_searchname(&$page, $id, $isFemale)
b04882ff 496 {
e5ef8615 497 pl_content_headers("text/html");
b04882ff 498 $page->changeTpl('profile/general.searchname.tpl', NO_SKIN);
6e32823c 499 $res = XDB::query("SELECT id, name, FIND_IN_SET('public', flags) AS pub
97a98687 500 FROM profile_name_enum
6e32823c
SJ
501 WHERE NOT FIND_IN_SET('not_displayed', flags)
502 AND NOT FIND_IN_SET('always_displayed', flags)");
503 $page->assign('sn_type_list', $res->fetchAllAssoc());
04e200e0 504 $page->assign('isFemale', $isFemale);
6e32823c 505 $page->assign('i', $id);
b04882ff 506 }
6e32823c 507
e8a7cf31 508 function handler_ajax_buildnames(&$page, $data, $isFemale)
6e32823c 509 {
e5ef8615 510 pl_content_headers("text/html");
6e32823c
SJ
511 $page->changeTpl('profile/general.buildnames.tpl', NO_SKIN);
512 require_once 'name.func.inc.php';
e8a7cf31 513 $page->assign('names', build_javascript_names($data, $isFemale));
b04882ff 514 }
6e32823c 515
eccb9b82 516 function handler_referent(&$page, $pf)
28e16d4d 517 {
8b1f8e12 518 $page->changeTpl('profile/fiche_referent.tpl', SIMPLE);
28e16d4d 519
eccb9b82
RB
520 $pf = Profile::get($pf);
521 if (!$pf) {
28e16d4d 522 return PL_NOT_FOUND;
523 }
524
eccb9b82 525 $page->assign_by_ref('profile', $pf);
28e16d4d 526
527 ///// recuperations infos referent
528
541e8d03
SJ
529 // Sectors
530 $sectors = $subSectors = Array();
08cce2ff 531 $res = XDB::iterRow(
f926f2b8 532 "SELECT s.name AS label, ss.name AS label
5fecdf6d
SJ
533 FROM profile_mentor_sector AS m
534 LEFT JOIN profile_job_sector_enum AS s ON(m.sectorid = s.id)
535 LEFT JOIN profile_job_subsector_enum AS ss ON(m.sectorid = ss.sectorid AND m.subsectorid = ss.id)
eccb9b82 536 WHERE pid = {?}", $pf->id());
541e8d03
SJ
537 while (list($sector, $subSector) = $res->next()) {
538 $sectors[] = $sector;
539 $subSectors[] = $subSector;
28e16d4d 540 }
541e8d03
SJ
541 $page->assign_by_ref('sectors', $sectors);
542 $page->assign_by_ref('subSectors', $subSectors);
28e16d4d 543
e4cd7a1f 544 // Countries.
08cce2ff 545 $res = XDB::query(
e4cd7a1f 546 "SELECT gc.countryFR
5fecdf6d 547 FROM profile_mentor_country AS m
e4cd7a1f 548 LEFT JOIN geoloc_countries AS gc ON (m.country = gc.iso_3166_1_a2)
eccb9b82 549 WHERE pid = {?}", $pf->id());
28e16d4d 550 $page->assign('pays', $res->fetchColumn());
551
c99ef281 552 $page->addJsLink('close_on_esc.js');
28e16d4d 553 }
554
ff3eb9b7 555 function handler_ref_search(&$page, $action = null, $subaction = null)
2f678da1 556 {
8f201b69
FB
557 $wp = new PlWikiPage('Docs.Emploi');
558 $wp->buildCache();
559
75691c60 560 $page->setTitle('Emploi et Carrières');
2f678da1 561
541e8d03 562 // Retrieval of sector names
75691c60
FB
563 $sectors = XDB::fetchAllAssoc('id', 'SELECT pjse.id, pjse.name
564 FROM profile_job_sector_enum AS pjse
565 INNER JOIN profile_mentor_sector AS pms ON (pms.sectorid = pjse.id)
566 GROUP BY pjse.id
567 ORDER BY pjse.name');
541e8d03 568 $page->assign_by_ref('sectors', $sectors);
2f678da1 569
2f678da1 570 // nb de mentors
5fecdf6d 571 $res = XDB::query("SELECT count(*) FROM profile_mentor");
2f678da1 572 $page->assign('mentors_number', $res->fetchOneCell());
573
2f678da1 574 // On vient d'un formulaire
307c3710
RB
575 require_once 'ufbuilder.inc.php';
576 $ufb = new UFB_MentorSearch();
577 if (!$ufb->isEmpty()) {
578 require_once 'userset.inc.php';
579 $ufc = $ufb->getUFC();
580 $set = new ProfileSet($ufc);
82110d15 581 $set->addMod('mentor', 'Référents');
ff3eb9b7 582 $set->apply('referent/search', $page, $action, $subaction);
583 if ($set->count() > 100) {
e1635d16 584 $page->assign('recherche_trop_large', true);
2f678da1 585 }
ff3eb9b7 586 }
307c3710 587
e1635d16 588 $page->changeTpl('profile/referent.tpl');
ff3eb9b7 589 }
2f678da1 590
e1635d16 591 function handler_ref_sect(&$page, $sect)
ff3eb9b7 592 {
3cb500d5 593 pl_content_headers("text/html");
05cb05c0 594 $page->changeTpl('include/field.select.tpl', NO_SKIN);
541e8d03 595 $page->assign('onchange', 'setSSectors()');
ff3eb9b7 596 $page->assign('id', 'ssect_field');
541e8d03 597 $page->assign('name', 'subSector');
75691c60
FB
598 $it = XDB::iterator("SELECT pjsse.id, pjsse.name AS field
599 FROM profile_job_subsector_enum AS pjsse
600 INNER JOIN profile_mentor_sector AS pms ON (pms.sectorid = pjsse.sectorid AND pms.subsectorid = pjsse.id)
601 WHERE pjsse.sectorid = {?}
602 GROUP BY pjsse.id
603 ORDER BY pjsse.name", $sect);
ff3eb9b7 604 $page->assign('list', $it);
605 }
2f678da1 606
ff3eb9b7 607 function handler_ref_country(&$page, $sect, $ssect = '')
608 {
3cb500d5 609 pl_content_headers("text/html");
05cb05c0 610 $page->changeTpl('include/field.select.tpl', NO_SKIN);
ff3eb9b7 611 $page->assign('name', 'pays_sel');
5fecdf6d 612 $where = ($ssect ? ' AND ms.subsectorid = {?}' : '');
e4cd7a1f
SJ
613 $it = XDB::iterator("SELECT gc.iso_3166_1_a2 AS id, gc.countryFR AS field
614 FROM geoloc_countries AS gc
615 INNER JOIN profile_mentor_country AS mp ON (mp.country = gc.iso_3166_1_a2)
ce0b2c6f 616 INNER JOIN profile_mentor_sector AS ms ON (ms.pid = mp.pid)
e4cd7a1f
SJ
617 WHERE ms.sectorid = {?} " . $where . "
618 GROUP BY iso_3166_1_a2
619 ORDER BY countryFR", $sect, $ssect);
ff3eb9b7 620 $page->assign('list', $it);
2f678da1 621 }
622
a1d79217 623 function handler_xnet(&$page)
624 {
8b1f8e12 625 $page->changeTpl('profile/groupesx.tpl');
46f272fe 626 $page->setTitle('Promo, Groupes X, Binets');
e1635d16 627
a1d79217 628 $req = XDB::query('
e1635d16 629 SELECT m.asso_id, a.nom, diminutif, a.logo IS NOT NULL AS has_logo,
46e1d3ba 630 COUNT(e.eid) AS events, mail_domain AS lists
eb41eda9
FB
631 FROM group_members AS m
632 INNER JOIN groups AS a ON(m.asso_id = a.id)
633 LEFT JOIN group_events AS e ON(e.asso_id = m.asso_id AND e.archive = 0)
46e1d3ba 634 WHERE uid = {?} GROUP BY m.asso_id ORDER BY a.nom', S::i('uid'));
a1d79217 635 $page->assign('assos', $req->fetchAllAssoc());
636 }
e1635d16 637
23fb3e6f
SJ
638 function handler_xnetlogo(&$page, $id)
639 {
640 if (is_null($id)) {
641 return PL_NOT_FOUND;
642 }
643
644 $res = XDB::query('SELECT logo, logo_mime
eb41eda9 645 FROM groups
23fb3e6f
SJ
646 WHERE id = {?}', $id);
647 list($logo, $logo_mime) = $res->fetchOneRow();
648
649 if (!empty($logo)) {
3cb500d5 650 pl_cached_dynamic_content_headers($logo_mime);
23fb3e6f
SJ
651 echo $logo;
652 } else {
3cb500d5 653 pl_cached_dynamic_content_headers("image/jpeg");
23fb3e6f
SJ
654 readfile(dirname(__FILE__) . '/../htdocs/images/dflt_carre.jpg');
655 }
656
657 exit;
658 }
659
e49018a7 660 function handler_vcard(&$page, $x = null)
661 {
662 if (is_null($x)) {
663 return PL_NOT_FOUND;
664 }
665
666 global $globals;
667
668 if (substr($x, -4) == '.vcf') {
669 $x = substr($x, 0, strlen($x) - 4);
670 }
671
5d42c993 672 $vcard = new VCard();
07d7f498 673 $vcard->addProfile(Profile::get($x));
5d42c993 674 $vcard->show();
e49018a7 675 }
92423144 676
54cabe90 677 function handler_admin_trombino(&$page, $login = null, $action = null) {
8b1f8e12 678 $page->changeTpl('profile/admin_trombino.tpl');
46f272fe 679 $page->setTitle('Administration - Trombino');
e1635d16 680
54cabe90
VZ
681 if (!$login || !($user = User::get($login))) {
682 return PL_NOT_FOUND;
683 } else {
684 $page->assign_by_ref('user', $user);
685 }
e1635d16 686
92423144 687 switch ($action) {
92423144 688 case "original":
5c4ea53f 689 PlImage::fromFile("/home/web/trombino/photos" . $user->promo() . "/" . $user->login() . ".jpg", "image/jpeg")->send();
92423144 690 exit;
e1635d16 691
92423144 692 case "new":
8827fc52
VZ
693 S::assert_xsrf_token();
694
92423144 695 $data = file_get_contents($_FILES['userfile']['tmp_name']);
696 list($x, $y) = getimagesize($_FILES['userfile']['tmp_name']);
697 $mimetype = substr($_FILES['userfile']['type'], 6);
698 unlink($_FILES['userfile']['tmp_name']);
699 XDB::execute(
5c4ea53f
FB
700 "REPLACE INTO profile_photos SET pid={?}, attachmime = {?}, attach={?}, x={?}, y={?}",
701 $user->profile()->id(), $mimetype, $data, $x, $y);
92423144 702 break;
e1635d16 703
92423144 704 case "delete":
8827fc52
VZ
705 S::assert_xsrf_token();
706
5c4ea53f 707 XDB::execute('DELETE FROM profile_photos WHERE pid = {?}', $user->profile()->id());
92423144 708 break;
709 }
92423144 710 }
b62db02e
SJ
711 function handler_admin_names(&$page, $action = 'list', $id = null) {
712 $page->setTitle('Administration - Types de noms');
713 $page->assign('title', 'Gestion des types de noms');
714 $table_editor = new PLTableEditor('admin/names', 'profile_name_enum', 'id', true);
715 $table_editor->describe('name', 'Nom', true);
716 $table_editor->describe('explanations', 'Explications', true);
717 $table_editor->describe('type', 'Type', true);
718 $table_editor->describe('flags', 'Flags', true);
719 $table_editor->describe('score', 'Score', true);
720 $table_editor->apply($page, $action, $id);
721 }
92423144 722 function handler_admin_binets(&$page, $action = 'list', $id = null) {
46f272fe 723 $page->setTitle('Administration - Binets');
92423144 724 $page->assign('title', 'Gestion des binets');
5c8a71f2
FB
725 $table_editor = new PLTableEditor('admin/binets', 'profile_binet_enum', 'id');
726 $table_editor->add_join_table('profile_binets','binet_id',true);
a7de4ef7 727 $table_editor->describe('text','intitulé',true);
92423144 728 $table_editor->apply($page, $action, $id);
729 }
043bbacf 730 function handler_admin_education(&$page, $action = 'list', $id = null) {
46f272fe 731 $page->setTitle('Administration - Formations');
92423144 732 $page->assign('title', 'Gestion des formations');
043bbacf
SJ
733 $table_editor = new PLTableEditor('admin/education', 'profile_education_enum', 'id');
734 $table_editor->add_join_table('profile_education', 'eduid', true);
735 $table_editor->add_join_table('profile_education_degree', 'eduid', true);
736 $table_editor->describe('name', 'intitulé', true);
737 $table_editor->describe('url', 'site web', false);
738 $table_editor->apply($page, $action, $id);
739 }
740 function handler_admin_education_field(&$page, $action = 'list', $id = null) {
741 $page->setTitle('Administration - Domaines de formation');
742 $page->assign('title', 'Gestion des domaines de formation');
743 $table_editor = new PLTableEditor('admin/education_field', 'profile_education_field_enum', 'id', true);
744 $table_editor->add_join_table('profile_education', 'fieldid', true);
745 $table_editor->describe('field', 'domaine', true);
746 $table_editor->apply($page, $action, $id);
747 }
748 function handler_admin_education_degree(&$page, $action = 'list', $id = null) {
749 $page->setTitle('Administration - Niveau de formation');
750 $page->assign('title', 'Gestion des niveau de formation');
751 $table_editor = new PLTableEditor('admin/education_degree', 'profile_education_degree_enum', 'id', true);
752 $table_editor->add_join_table('profile_education_degree', 'degreeid', true);
753 $table_editor->add_join_table('profile_education', 'degreeid', true);
754 $table_editor->describe('degree', 'niveau', true);
755 $table_editor->apply($page, $action, $id);
756 }
757 function handler_admin_education_degree_set(&$page, $action = 'list', $id = null) {
758 $page->setTitle('Administration - Correspondances formations - niveau de formation');
759 $page->assign('title', 'Gestion des correspondances formations - niveau de formation');
760 $table_editor = new PLTableEditor('admin/education_degree_set', 'profile_education_degree', 'eduid', true);
00f0e0b0
PC
761 $table_editor->describe('eduid', 'id formation', true);
762 $table_editor->describe('degreeid', 'id niveau', true);
763
764 // Adds fields to show the names of education
765 $table_editor->add_option_table('profile_education_enum','profile_education_enum.id = eduid');
766 $table_editor->add_option_field('profile_education_enum.name', 'edu_name', 'formation', null, 'degreeid');
767 // Adds fields to show the names of degrees
768 $table_editor->add_option_table('profile_education_degree_enum','profile_education_degree_enum.id = t.degreeid');
769 $table_editor->add_option_field('profile_education_degree_enum.degree', 'degree_name', 'niveau');
770
92423144 771 $table_editor->apply($page, $action, $id);
e1635d16 772 }
b09690be 773 function handler_admin_sections(&$page, $action = 'list', $id = null) {
46f272fe 774 $page->setTitle('Administration - Sections');
a20aab02 775 $page->assign('title', 'Gestion des sections');
5c8a71f2 776 $table_editor = new PLTableEditor('admin/sections','profile_section_enum','id');
b09690be 777 $table_editor->describe('text','intitulé',true);
778 $table_editor->apply($page, $action, $id);
e1635d16 779 }
b6e9d1ca
SJ
780 function handler_admin_sectors(&$page, $action = 'list', $id = null) {
781 $page->setTitle('Administration - Secteurs');
782 $page->assign('title', 'Gestion des secteurs');
783 $table_editor = new PLTableEditor('admin/sectors', 'profile_job_subsubsector_enum', 'id', true);
784 $table_editor->describe('sectorid', 'id du secteur', false);
785 $table_editor->describe('subsectorid', 'id du sous-secteur', false);
786 $table_editor->describe('name', 'nom', true);
787 $table_editor->describe('flags', 'affichage', true);
a20aab02
SJ
788 $table_editor->apply($page, $action, $id);
789 }
15beefb3
GB
790 function handler_admin_networking(&$page, $action = 'list', $id = null) {
791 $page->assign('xorg_title', 'Polytechnique.org - Administration - Networking');
792 $page->assign('title', 'Gestion des types de networking');
1f5cd004 793 $table_editor = new PLTableEditor('admin/networking', 'profile_networking_enum', 'nwid');
15beefb3
GB
794 $table_editor->describe('name', 'intitulé', true);
795 $table_editor->describe('icon', 'nom de l\'icône', false);
dc6378df
GB
796 $table_editor->describe('filter', 'filtre', true);
797 $table_editor->describe('link', 'lien web', true);
15beefb3
GB
798 $table_editor->apply($page, $action, $id);
799 }
4962a9ce
SJ
800 function handler_admin_corps_enum(&$page, $action = 'list', $id = null) {
801 $page->setTitle('Administration - Corps');
802 $page->assign('title', 'Gestion des Corps');
803 $table_editor = new PLTableEditor('admin/corps_enum', 'profile_corps_enum', 'id');
804 $table_editor->describe('name', 'intitulé', true);
805 $table_editor->describe('abbreviation', 'abbréviation', true);
806 $table_editor->describe('still_exists', 'existe encore ?', true);
807 $table_editor->apply($page, $action, $id);
808 }
809 function handler_admin_corps_rank(&$page, $action = 'list', $id = null) {
810 $page->setTitle('Administration - Grade dans les Corps');
811 $page->assign('title', 'Gestion des grade dans les Corps');
812 $table_editor = new PLTableEditor('admin/corps_rank', 'profile_corps_rank_enum', 'id');
813 $table_editor->describe('name', 'intitulé', true);
814 $table_editor->describe('abbreviation', 'abbréviation', true);
815 $table_editor->apply($page, $action, $id);
816 }
92423144 817 function handler_admin_medals(&$page, $action = 'list', $id = null) {
46f272fe 818 $page->setTitle('Administration - Distinctions');
92423144 819 $page->assign('title', 'Gestion des Distinctions');
5c8a71f2 820 $table_editor = new PLTableEditor('admin/medals','profile_medal_enum','id');
a7de4ef7 821 $table_editor->describe('text', 'intitulé', true);
92423144 822 $table_editor->describe('img', 'nom de l\'image', false);
d02b8359 823 $table_editor->describe('flags', 'valider', true);
92423144 824 $table_editor->apply($page, $action, $id);
825 if ($id && $action == 'edit') {
8b1f8e12 826 $page->changeTpl('profile/admin_decos.tpl');
e1635d16 827
92423144 828 $mid = $id;
e1635d16 829
92423144 830 if (Post::v('act') == 'del') {
c6d16b24 831 XDB::execute('DELETE FROM profile_medal_grade_enum
75a17710 832 WHERE mid={?} AND gid={?}', $mid, Post::i('gid'));
92423144 833 } else {
834 foreach (Post::v('grades', array()) as $gid=>$text) {
154ee23a
OLF
835 if ($gid === 0) {
836 if (!empty($text)) {
837 $res = XDB::query('SELECT MAX(gid)
c6d16b24 838 FROM profile_medal_grade_enum
154ee23a
OLF
839 WHERE mid = {?}', $mid);
840 $gid = $res->fetchOneCell() + 1;
841
c6d16b24 842 XDB::execute('INSERT INTO profile_medal_grade_enum (mid, gid, text, pos)
154ee23a
OLF
843 VALUES ({?}, {?}, {?}, {?})',
844 $mid, $gid, $text, $_POST['pos']['0']);
845 }
846 } else {
c6d16b24 847 XDB::execute('UPDATE profile_medal_grade_enum
154ee23a
OLF
848 SET pos={?}, text={?}
849 WHERE gid={?} AND mid={?}', $_POST['pos'][$gid], $text, $gid, $mid);
850 }
92423144 851 }
852 }
c6d16b24 853 $res = XDB::iterator('SELECT gid, text, pos FROM profile_medal_grade_enum WHERE mid={?} ORDER BY pos', $mid);
92423144 854 $page->assign('grades', $res);
855 }
e1635d16 856 }
7d8b17cb 857}
858
a7de4ef7 859// vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8:
7d8b17cb 860?>