Missing html escaping in addresses (Closes #1135)
[platal.git] / modules / profile.php
CommitLineData
7d8b17cb 1<?php
2/***************************************************************************
9f5bd98e 3 * Copyright (C) 2003-2010 Polytechnique.org *
7d8b17cb 4 * http://opensource.polytechnique.org/ *
5 * *
6 * This program is free software; you can redistribute it and/or modify *
7 * it under the terms of the GNU General Public License as published by *
8 * the Free Software Foundation; either version 2 of the License, or *
9 * (at your option) any later version. *
10 * *
11 * This program is distributed in the hope that it will be useful, *
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
14 * GNU General Public License for more details. *
15 * *
16 * You should have received a copy of the GNU General Public License *
17 * along with this program; if not, write to the Free Software *
18 * Foundation, Inc., *
19 * 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA *
20 ***************************************************************************/
21
22class ProfileModule extends PLModule
23{
24 function handlers()
25 {
26 return array(
2398e553
SJ
27 'photo' => $this->make_hook('photo', AUTH_PUBLIC),
28 'photo/change' => $this->make_hook('photo_change', AUTH_MDP),
e49018a7 29
2398e553
SJ
30 'fiche.php' => $this->make_hook('fiche', AUTH_PUBLIC),
31 'profile' => $this->make_hook('profile', AUTH_PUBLIC),
32 'profile/private' => $this->make_hook('profile', AUTH_COOKIE),
33 'profile/ax' => $this->make_hook('ax', AUTH_COOKIE, 'admin'),
34 'profile/edit' => $this->make_hook('p_edit', AUTH_MDP),
35 'profile/ajax/address' => $this->make_hook('ajax_address', AUTH_COOKIE, 'user', NO_AUTH),
36 'profile/ajax/tel' => $this->make_hook('ajax_tel', AUTH_COOKIE, 'user', NO_AUTH),
37 'profile/ajax/edu' => $this->make_hook('ajax_edu', AUTH_COOKIE, 'user', NO_AUTH),
38 'profile/ajax/medal' => $this->make_hook('ajax_medal', AUTH_COOKIE, 'user', NO_AUTH),
39 'profile/networking' => $this->make_hook('networking', AUTH_PUBLIC),
40 'profile/ajax/job' => $this->make_hook('ajax_job', AUTH_COOKIE, 'user', NO_AUTH),
541e8d03
SJ
41 'profile/ajax/sector' => $this->make_hook('ajax_sector', AUTH_COOKIE, 'user', NO_AUTH),
42 'profile/ajax/sub_sector' => $this->make_hook('ajax_sub_sector', AUTH_COOKIE, 'user', NO_AUTH),
07e72582 43 'profile/ajax/alternates' => $this->make_hook('ajax_alternates', AUTH_COOKIE, 'user', NO_AUTH),
2398e553
SJ
44 'profile/ajax/skill' => $this->make_hook('ajax_skill', AUTH_COOKIE, 'user', NO_AUTH),
45 'profile/ajax/searchname' => $this->make_hook('ajax_searchname', AUTH_COOKIE, 'user', NO_AUTH),
6e32823c 46 'profile/ajax/buildnames' => $this->make_hook('ajax_buildnames', AUTH_COOKIE, 'user', NO_AUTH),
f711b03f 47 'javascript/education.js' => $this->make_hook('education_js', AUTH_COOKIE),
2398e553
SJ
48 'javascript/grades.js' => $this->make_hook('grades_js', AUTH_COOKIE),
49 'profile/medal' => $this->make_hook('medal', AUTH_PUBLIC),
70c65f3a 50 'profile/name_info' => $this->make_hook('name_info', AUTH_PUBLIC),
e49018a7 51
2398e553
SJ
52 'referent' => $this->make_hook('referent', AUTH_COOKIE),
53 'emploi' => $this->make_hook('ref_search', AUTH_COOKIE),
54 'referent/search' => $this->make_hook('ref_search', AUTH_COOKIE),
55 'referent/ssect' => $this->make_hook('ref_sect', AUTH_COOKIE, 'user', NO_AUTH),
56 'referent/country' => $this->make_hook('ref_country', AUTH_COOKIE, 'user', NO_AUTH),
2f678da1 57
2398e553 58 'groupes-x' => $this->make_hook('xnet', AUTH_COOKIE),
1dc71da1 59 'groupes-x/logo' => $this->make_hook('xnetlogo', AUTH_PUBLIC),
926f16d7 60
2398e553
SJ
61 'vcard' => $this->make_hook('vcard', AUTH_COOKIE, 'user', NO_HTTPS),
62 'admin/binets' => $this->make_hook('admin_binets', AUTH_MDP, 'admin'),
63 'admin/medals' => $this->make_hook('admin_medals', AUTH_MDP, 'admin'),
64 'admin/education' => $this->make_hook('admin_education', AUTH_MDP, 'admin'),
65 'admin/education_field' => $this->make_hook('admin_education_field', AUTH_MDP, 'admin'),
66 'admin/education_degree' => $this->make_hook('admin_education_degree', AUTH_MDP, 'admin'),
043bbacf 67 'admin/education_degree_set' => $this->make_hook('admin_education_degree_set', AUTH_MDP, 'admin'),
2398e553 68 'admin/sections' => $this->make_hook('admin_sections', AUTH_MDP, 'admin'),
2398e553
SJ
69 'admin/networking' => $this->make_hook('admin_networking', AUTH_MDP, 'admin'),
70 'admin/trombino' => $this->make_hook('admin_trombino', AUTH_MDP, 'admin'),
b6e9d1ca 71 'admin/sectors' => $this->make_hook('admin_sectors', AUTH_MDP, 'admin'),
4962a9ce
SJ
72 'admin/corps_enum' => $this->make_hook('admin_corps_enum', AUTH_MDP, 'admin'),
73 'admin/corps_rank' => $this->make_hook('admin_corps_rank', AUTH_MDP, 'admin'),
b62db02e 74 'admin/names' => $this->make_hook('admin_names', AUTH_MDP, 'admin'),
7d8b17cb 75 );
76 }
77
e8599c21 78 /* XXX COMPAT */
79 function handler_fiche(&$page)
80 {
5e2307dc 81 return $this->handler_profile($page, Env::v('user'));
e8599c21 82 }
83
adbdf493 84 function handler_photo(&$page, $x = null, $req = null)
85 {
706f830d 86 if (!$x || !($profile = Profile::get($x))) {
adbdf493 87 return PL_NOT_FOUND;
88 }
89
954cfb01 90 // Retrieve the photo and its mime type.
cab08090 91 if ($req && S::logged()) {
adbdf493 92 include 'validations.inc.php';
706f830d 93 $myphoto = PhotoReq::get_request($profile->owner()->id());
833a6e86 94 $photo = PlImage::fromData($myphoto->data, $myphoto->mimetype);
adbdf493 95 } else {
7988f7d6 96 $photo = $profile->getPhoto(true, true);
adbdf493 97 }
954cfb01
VZ
98
99 // Display the photo, or a default one when not available.
833a6e86 100 $photo->send();
adbdf493 101 }
102
85cc366b
FB
103 function handler_medal(&$page, $mid)
104 {
bd6a5fe3
VZ
105 $thumb = ($mid == 'thumb');
106 $mid = $thumb ? @func_get_arg(2) : $mid;
107
85cc366b 108 $res = XDB::query("SELECT img
5c8a71f2 109 FROM profile_medal_enum
85cc366b
FB
110 WHERE id = {?}",
111 $mid);
bd6a5fe3
VZ
112 $img = $thumb ?
113 dirname(__FILE__).'/../htdocs/images/medals/thumb/' . $res->fetchOneCell() :
114 dirname(__FILE__).'/../htdocs/images/medals/' . $res->fetchOneCell();
3cb500d5 115 pl_cached_content_headers(mime_content_type($img));
85cc366b
FB
116 echo file_get_contents($img);
117 exit;
118 }
119
70c65f3a
SJ
120 function handler_name_info(&$page)
121 {
122 header('Content-Type: text/html; charset=utf-8');
123 $page->changeTpl('profile/name_info.tpl', SIMPLE);
124 $res = XDB::iterator("SELECT name, explanations,
125 FIND_IN_SET('public', flags) AS public,
126 FIND_IN_SET('has_particle', flags) AS has_particle
97a98687 127 FROM profile_name_enum
70c65f3a
SJ
128 WHERE NOT FIND_IN_SET('not_displayed', flags)
129 ORDER BY NOT FIND_IN_SET('public', flags)");
130 $page->assign('types', $res);
131 }
132
40176c6c
GB
133 function handler_networking(&$page, $mid)
134 {
135 $res = XDB::query("SELECT icon
136 FROM profile_networking_enum
1f5cd004 137 WHERE nwid = {?}",
40176c6c
GB
138 $mid);
139 $img = dirname(__FILE__) . '/../htdocs/images/networking/' . $res->fetchOneCell();
140 $type = mime_content_type($img);
141 header("Content-Type: $type");
142 echo file_get_contents($img);
143 exit;
144 }
145
fb9a56cb 146 function handler_photo_change(&$page)
147 {
ebfdf077 148 global $globals;
8b1f8e12 149 $page->changeTpl('profile/trombino.tpl');
fb9a56cb 150
151 require_once('validations.inc.php');
152
54cabe90 153 $trombi_x = '/home/web/trombino/photos' . S::v('promo') . '/' . S::user()->login() . '.jpg';
fb9a56cb 154 if (Env::has('upload')) {
8827fc52
VZ
155 S::assert_xsrf_token();
156
954cfb01 157 $upload = new PlUpload(S::user()->login(), 'photo');
abe7e055 158 if (!$upload->upload($_FILES['userfile']) && !$upload->download(Env::v('photo'))) {
a7d35093 159 $page->trigError('Une erreur est survenue lors du téléchargement du fichier');
abe7e055 160 } else {
5daf68f6 161 $myphoto = new PhotoReq(S::user(), $upload);
abe7e055 162 if ($myphoto->isValid()) {
163 $myphoto->submit();
fb9a56cb 164 }
fb9a56cb 165 }
166 } elseif (Env::has('trombi')) {
8827fc52
VZ
167 S::assert_xsrf_token();
168
954cfb01 169 $upload = new PlUpload(S::user()->login(), 'photo');
abe7e055 170 if ($upload->copyFrom($trombi_x)) {
5daf68f6 171 $myphoto = new PhotoReq(S::user(), $upload);
abe7e055 172 if ($myphoto->isValid()) {
173 $myphoto->commit();
174 $myphoto->clean();
175 }
fb9a56cb 176 }
5e2307dc 177 } elseif (Env::v('suppr')) {
8827fc52
VZ
178 S::assert_xsrf_token();
179
5c4ea53f
FB
180 XDB::execute('DELETE FROM profile_photos
181 WHERE pid = {?}',
182 S::user()->profile()->id());
257ae408
SJ
183 XDB::execute("DELETE FROM requests
184 WHERE uid = {?} AND type = 'photo'",
84868ee9 185 S::v('uid'));
ebfdf077 186 $globals->updateNbValid();
716dedc5 187 $page->trigSuccess("Ta photo a bien été supprimée. Elle ne sera plus visible sur le site dans au plus une heure.");
5e2307dc 188 } elseif (Env::v('cancel')) {
8827fc52
VZ
189 S::assert_xsrf_token();
190
257ae408
SJ
191 $sql = XDB::query("DELETE FROM requests
192 WHERE uid = {?} AND type = 'photo'",
84868ee9 193 S::v('uid'));
ebfdf077 194 $globals->updateNbValid();
fb9a56cb 195 }
196
257ae408 197 $sql = XDB::query("SELECT COUNT(*)
84868ee9 198 FROM requests
257ae408 199 WHERE uid = {?} AND type = 'photo'",
abe7e055 200 S::v('uid'));
fb9a56cb 201 $page->assign('submited', $sql->fetchOneCell());
202 $page->assign('has_trombi_x', file_exists($trombi_x));
fb9a56cb 203 }
204
9b09e3fb 205 function handler_profile(&$page, $id = null)
e8599c21 206 {
9b09e3fb
SJ
207 // Checks if the identifier corresponds to an actual profile. Numeric
208 // identifiers canonly be user by logged users.
209 if (is_null($id)) {
e8599c21 210 return PL_NOT_FOUND;
211 }
23ff6dd6 212 $pid = (!is_numeric($id) || S::admin()) ? Profile::getPID($id) : null;
9b09e3fb 213 if (is_null($pid)) {
efe597c5 214 if (S::logged()) {
9b09e3fb 215 $page->trigError($id . " inconnu dans l'annuaire.");
efe597c5 216 }
344234db 217 return PL_NOT_FOUND;
e8599c21 218 }
e8599c21 219
9b09e3fb
SJ
220 // Now that we know this is an existing profile, we can switch to the
221 // appropriate template.
b13048df 222 $page->changeTpl('profile/profile.tpl', SIMPLE);
e8599c21 223
54cabe90
VZ
224 // Determines the access level at which the profile will be displayed.
225 if (!S::logged() || Env::v('view') == 'public') {
226 $view = 'public';
227 } else if (S::logged() && Env::v('view') == 'ax') {
228 $view = 'ax';
e8599c21 229 } else {
54cabe90 230 $view = 'private';
e8599c21 231 }
232
9b09e3fb
SJ
233 // Fetches profile's and profile's owner information and redirects to
234 // marketing if the owner has not subscribed and the requirer has logged in.
d1095b1d 235 $profile = Profile::get($pid, Profile::FETCH_ALL, $view);
9b09e3fb
SJ
236 $owner = $profile->owner();
237 if (S::logged() && !is_null($owner) && $owner->state == 'pending') {
238 pl_redirect('marketing/public/' . $profile->hrid());
e8599c21 239 }
ba25f663 240
54cabe90 241 // Profile view are logged.
e31c1c3e 242 if (S::logged()) {
9b09e3fb 243 S::logger()->log('view_profile', $profile->hrid());
e8599c21 244 }
245
54cabe90 246 // Sets the title of the html page.
9b09e3fb 247 $page->setTitle($profile->fullName());
e8599c21 248
54cabe90 249 // Determines and displays the virtual alias.
9b09e3fb 250 if (!is_null($owner)) {
efe597c5
FB
251 $page->assign('virtualalias', $owner->emailAlias());
252 }
54cabe90 253
68f988a8
RB
254 $page->assign_by_ref('profile', $profile);
255 $page->assign_by_ref('owner', $owner);
bdce53bb 256 $page->assign('view', $view);
e859bdaf 257 $page->assign('logged', S::logged());
e8599c21 258
c99ef281 259 $page->addJsLink('close_on_esc.js');
9b09e3fb 260 header('Last-Modified: ' . date('r', strtotime($profile->last_change)));
e8599c21 261 }
262
5122b820 263 function handler_ax(&$page, $user = null)
264 {
c52d86d1 265 $user = Profile::get($user);
5122b820 266 if (!$user) {
267 return PL_NOT_FOUND;
268 }
c52d86d1
FB
269 if (!$user->ax_id) {
270 $page->kill("Le matricule AX de {$user->hrid()} est inconnu");
5122b820 271 }
e46cf8c4 272 http_redirect("http://www.polytechniciens.com/?page=AX_FICHE_ANCIEN&ancc_id=" . $user->ax_id);
5122b820 273 }
274
d1e61677 275 function handler_p_edit(&$page, $user = null, $opened_tab = null, $mode = null, $success = null)
2f678da1 276 {
277 global $globals;
278
3af21f99
FB
279 if (is_null($user)) {
280 $user = S::user();
281 if (!$user->hasProfile()) {
282 return PL_NOT_FOUND;
283 } else {
284 pl_redirect('profile/edit/' . $user->profile()->hrid());
285 }
286 } else {
287 $user = Profile::get($user);
288 if (!$user) {
289 return PL_NOT_FOUND;
290 } else if (!S::user()->canEdit($user) && Platal::notAllowed()) {
291 return PL_FORBIDDEN;
292 }
293 }
294
7bff4cb0 295 // Build the page
c6a7beb2 296 $page->addJsLink('ajax.js');
6dc215d1
SJ
297 $page->addJsLink('education.js', false); /* dynamic content */
298 $page->addJsLink('grades.js', false); /* dynamic content */
16594a1a 299 $page->addJsLink('profile.js');
4b4b4b67 300 $page->addJsLink('jquery.autocomplete.js');
e5bcd851
FB
301 $wiz = new PlWizard('Profil', PlPage::getCoreTpl('plwizard.tpl'), true, true, false);
302 $wiz->addUserData('profile', $user);
303 $wiz->addUserData('owner', $user->owner());
460d8f55 304 $this->load('page.inc.php');
12bcf04b
RB
305 $wiz->addPage('ProfileSettingGeneral', 'Général', 'general');
306 $wiz->addPage('ProfileSettingAddresses', 'Adresses personnelles', 'adresses');
307 $wiz->addPage('ProfileSettingGroups', 'Groupes X - Binets', 'poly');
308 $wiz->addPage('ProfileSettingDecos', 'Décorations - Medailles', 'deco');
309 $wiz->addPage('ProfileSettingJobs', 'Informations professionnelles', 'emploi');
310 $wiz->addPage('ProfileSettingSkills', 'Compétences diverses', 'skill');
311 $wiz->addPage('ProfileSettingMentor', 'Mentoring', 'mentor');
3af21f99 312 $wiz->apply($page, 'profile/edit/' . $user->hrid(), $opened_tab, $mode);
35aedff2 313
c52d86d1 314 if (!$user->birthdate) {
a7d35093 315 $page->trigWarning("Ta date de naissance n'est pas renseignée, ce qui t'empêcheras de réaliser"
6e32823c 316 . " la procédure de récupération de mot de passe si un jour tu le perdais.");
7bff4cb0
FB
317 }
318
46f272fe 319 $page->setTitle('Mon Profil');
eb563236
SJ
320 if (isset($success) && $success) {
321 $page->trigSuccess('Ton profil a bien été mis à jour.');
322 }
2f678da1 323 }
324
f711b03f 325 function handler_education_js(&$page)
46ae38a9 326 {
3cb500d5 327 pl_cached_content_headers("text/javascript", "utf-8");
f711b03f 328 $page->changeTpl('profile/education.js.tpl', NO_SKIN);
ee718651 329 require_once 'education.func.inc.php';
46ae38a9
FB
330 }
331
332 function handler_grades_js(&$page)
333 {
3cb500d5 334 pl_cached_content_headers("text/javascript", "utf-8");
46ae38a9
FB
335 $page->changeTpl('profile/grades.js.tpl', NO_SKIN);
336 $res = XDB::iterator("SELECT *
c6d16b24 337 FROM profile_medal_grade_enum
46ae38a9
FB
338 ORDER BY mid, pos");
339 $grades = array();
340 while ($tmp = $res->next()) {
341 $grades[$tmp['mid']][] = $tmp;
342 }
343 $page->assign('grades', $grades);
344
345 $res = XDB::iterator("SELECT *, FIND_IN_SET('validation', flags) AS validate
5c8a71f2 346 FROM profile_medal_enum
46ae38a9
FB
347 ORDER BY type, text");
348 $mlist = array();
349 while ($tmp = $res->next()) {
350 $mlist[$tmp['type']][] = $tmp;
351 }
352 $page->assign('medal_list', $mlist);
353 }
354
041a5cec 355 function handler_ajax_address(&$page, $id)
c6a7beb2 356 {
3cb500d5 357 pl_content_headers("text/html");
c6a7beb2 358 $page->changeTpl('profile/adresses.address.tpl', NO_SKIN);
041a5cec
SJ
359 $page->assign('i', $id);
360 $page->assign('address', array());
c6a7beb2
FB
361 }
362
bde2be3b 363 function handler_ajax_tel(&$page, $prefid, $prefname, $telid)
c6a7beb2 364 {
3cb500d5 365 pl_content_headers("text/html");
bde2be3b
GB
366 $page->changeTpl('profile/phone.tpl', NO_SKIN);
367 $page->assign('prefid', $prefid);
368 $page->assign('prefname', $prefname);
369 $page->assign('telid', $telid);
c6a7beb2 370 $page->assign('tel', array());
c6a7beb2
FB
371 }
372
58acfe8b 373 function handler_ajax_edu(&$page, $eduid, $class)
043bbacf
SJ
374 {
375 header('Content-Type: text/html; charset=utf-8');
2700a4f5 376 $page->changeTpl('profile/general.edu.tpl', NO_SKIN);
043bbacf
SJ
377 $res = XDB::iterator("SELECT id, field
378 FROM profile_education_field_enum
379 ORDER BY field");
380 $page->assign('edu_fields', $res->fetchAllAssoc());
381 $page->assign('eduid', $eduid);
58acfe8b 382 $page->assign('class', $class);
f711b03f 383 require_once "education.func.inc.php";
043bbacf
SJ
384 }
385
85cc366b
FB
386 function handler_ajax_medal(&$page, $id)
387 {
3cb500d5 388 pl_content_headers("text/html");
85cc366b
FB
389 $page->changeTpl('profile/deco.medal.tpl', NO_SKIN);
390 $page->assign('id', $id);
391 $page->assign('medal', array('valid' => 0, 'grade' => 0));
85cc366b
FB
392 }
393
2dcac0f5
FB
394 function handler_ajax_job(&$page, $id)
395 {
3cb500d5 396 pl_content_headers("text/html");
2dcac0f5
FB
397 $page->changeTpl('profile/jobs.job.tpl', NO_SKIN);
398 $page->assign('i', $id);
399 $page->assign('job', array());
2dcac0f5 400 $page->assign('new', true);
2992a284 401 $res = XDB::query("SELECT id, name AS label
b814a8b8 402 FROM profile_job_sector_enum");
541e8d03 403 $page->assign('sectors', $res->fetchAllAssoc());
06a99865
SJ
404 require_once "emails.combobox.inc.php";
405 fill_email_combobox($page);
2dcac0f5
FB
406 }
407
541e8d03 408 function handler_ajax_sector(&$page, $id, $jobid, $jobpref, $sect, $ssect = -1)
2dcac0f5 409 {
3cb500d5 410 pl_content_headers("text/html");
541e8d03 411 $res = XDB::iterator("SELECT id, name, FIND_IN_SET('optgroup', flags) AS optgroup
c7139c07
SJ
412 FROM profile_job_subsector_enum
413 WHERE sectorid = {?}", $sect);
541e8d03 414 $page->changeTpl('profile/jobs.sector.tpl', NO_SKIN);
2dcac0f5 415 $page->assign('id', $id);
541e8d03 416 $page->assign('subSectors', $res);
2dcac0f5 417 $page->assign('sel', $ssect);
5fecdf6d
SJ
418 if ($id != -1) {
419 $page->assign('change', 1);
420 $page->assign('jobid', $jobid);
421 $page->assign('jobpref', $jobpref);
422 }
c7139c07
SJ
423 }
424
541e8d03 425 function handler_ajax_sub_sector(&$page, $id, $ssect, $sssect = -1)
c7139c07
SJ
426 {
427 header('Content-Type: text/html; charset=utf-8');
541e8d03 428 $res = XDB::iterator("SELECT id, name
c7139c07
SJ
429 FROM profile_job_subsubsector_enum
430 WHERE subsectorid = {?}", $ssect);
541e8d03 431 $page->changeTpl('profile/jobs.sub_sector.tpl', NO_SKIN);
c7139c07 432 $page->assign('id', $id);
541e8d03 433 $page->assign('subSubSectors', $res);
c7139c07 434 $page->assign('sel', $sssect);
2dcac0f5
FB
435 }
436
07e72582
SJ
437 function handler_ajax_alternates(&$page, $id, $sssect)
438 {
439 header('Content-Type: text/html; charset=utf-8');
440 $res = XDB::iterator('SELECT name
441 FROM profile_job_alternates
442 WHERE subsubsectorid = {?}
443 ORDER BY id',
444 $sssect);
445 $page->changeTpl('profile/jobs.alternates.tpl', NO_SKIN);
ee199bc8
SJ
446 $alternates = '';
447 if ($res->total() > 0) {
448 $alternate = $res->next();
449 $alternates = $alternate['name'];
450 while ($alternate = $res->next()) {
451 $alternates .= ', ' . $alternate['name'];
452 }
07e72582
SJ
453 }
454 $page->assign('alternates', $alternates);
455 }
456
f25e1a56
FB
457 function handler_ajax_skill(&$page, $cat, $id)
458 {
3cb500d5 459 pl_content_headers("text/html");
f25e1a56 460 $page->changeTpl('profile/skill.skill.tpl', NO_SKIN);
f25e1a56
FB
461 $page->assign('cat', $cat);
462 $page->assign('id', $id);
463 if ($cat == 'competences') {
464 $page->assign('levels', array('initié' => 'initié',
465 'bonne connaissance' => 'bonne connaissance',
466 'expert' => 'expert'));
467 } else {
468 $page->assign('levels', array(1 => 'connaissance basique',
469 2 => 'maîtrise des bases',
470 3 => 'maîtrise limitée',
471 4 => 'maîtrise générale',
472 5 => 'bonne maîtrise',
473 6 => 'maîtrise complète'));
474 }
475 }
476
04e200e0 477 function handler_ajax_searchname(&$page, $id, $isFemale)
b04882ff
PC
478 {
479 header('Content-Type: text/html; charset=utf-8');
480 $page->changeTpl('profile/general.searchname.tpl', NO_SKIN);
6e32823c 481 $res = XDB::query("SELECT id, name, FIND_IN_SET('public', flags) AS pub
97a98687 482 FROM profile_name_enum
6e32823c
SJ
483 WHERE NOT FIND_IN_SET('not_displayed', flags)
484 AND NOT FIND_IN_SET('always_displayed', flags)");
485 $page->assign('sn_type_list', $res->fetchAllAssoc());
04e200e0 486 $page->assign('isFemale', $isFemale);
6e32823c 487 $page->assign('i', $id);
b04882ff 488 }
6e32823c 489
e8a7cf31 490 function handler_ajax_buildnames(&$page, $data, $isFemale)
6e32823c
SJ
491 {
492 header('Content-Type: text/html; charset=utf-8');
493 $page->changeTpl('profile/general.buildnames.tpl', NO_SKIN);
494 require_once 'name.func.inc.php';
e8a7cf31 495 $page->assign('names', build_javascript_names($data, $isFemale));
b04882ff 496 }
6e32823c 497
eccb9b82 498 function handler_referent(&$page, $pf)
28e16d4d 499 {
8b1f8e12 500 $page->changeTpl('profile/fiche_referent.tpl', SIMPLE);
28e16d4d 501
eccb9b82
RB
502 $pf = Profile::get($pf);
503 if (!$pf) {
28e16d4d 504 return PL_NOT_FOUND;
505 }
506
eccb9b82 507 $page->assign_by_ref('profile', $pf);
28e16d4d 508
509 ///// recuperations infos referent
510
541e8d03
SJ
511 // Sectors
512 $sectors = $subSectors = Array();
08cce2ff 513 $res = XDB::iterRow(
f926f2b8 514 "SELECT s.name AS label, ss.name AS label
5fecdf6d
SJ
515 FROM profile_mentor_sector AS m
516 LEFT JOIN profile_job_sector_enum AS s ON(m.sectorid = s.id)
517 LEFT JOIN profile_job_subsector_enum AS ss ON(m.sectorid = ss.sectorid AND m.subsectorid = ss.id)
eccb9b82 518 WHERE pid = {?}", $pf->id());
541e8d03
SJ
519 while (list($sector, $subSector) = $res->next()) {
520 $sectors[] = $sector;
521 $subSectors[] = $subSector;
28e16d4d 522 }
541e8d03
SJ
523 $page->assign_by_ref('sectors', $sectors);
524 $page->assign_by_ref('subSectors', $subSectors);
28e16d4d 525
e4cd7a1f 526 // Countries.
08cce2ff 527 $res = XDB::query(
e4cd7a1f 528 "SELECT gc.countryFR
5fecdf6d 529 FROM profile_mentor_country AS m
e4cd7a1f 530 LEFT JOIN geoloc_countries AS gc ON (m.country = gc.iso_3166_1_a2)
eccb9b82 531 WHERE pid = {?}", $pf->id());
28e16d4d 532 $page->assign('pays', $res->fetchColumn());
533
c99ef281 534 $page->addJsLink('close_on_esc.js');
28e16d4d 535 }
536
ff3eb9b7 537 function handler_ref_search(&$page, $action = null, $subaction = null)
2f678da1 538 {
8f201b69
FB
539 $wp = new PlWikiPage('Docs.Emploi');
540 $wp->buildCache();
541
46f272fe 542 $page->setTitle('Conseil Pro');
2f678da1 543
541e8d03 544 // Retrieval of sector names
2998edf1 545 $sectors = DirEnum::getOptions(DirEnum::SECTORS);
541e8d03 546 $sectors[''] = '';
541e8d03 547 $page->assign_by_ref('sectors', $sectors);
2f678da1 548
2f678da1 549 // nb de mentors
5fecdf6d 550 $res = XDB::query("SELECT count(*) FROM profile_mentor");
2f678da1 551 $page->assign('mentors_number', $res->fetchOneCell());
552
2f678da1 553 // On vient d'un formulaire
307c3710
RB
554 require_once 'ufbuilder.inc.php';
555 $ufb = new UFB_MentorSearch();
556 if (!$ufb->isEmpty()) {
557 require_once 'userset.inc.php';
558 $ufc = $ufb->getUFC();
559 $set = new ProfileSet($ufc);
82110d15 560 $set->addMod('mentor', 'Référents');
ff3eb9b7 561 $set->apply('referent/search', $page, $action, $subaction);
562 if ($set->count() > 100) {
e1635d16 563 $page->assign('recherche_trop_large', true);
2f678da1 564 }
ff3eb9b7 565 }
307c3710 566
e1635d16 567 $page->changeTpl('profile/referent.tpl');
ff3eb9b7 568 }
2f678da1 569
e1635d16 570 function handler_ref_sect(&$page, $sect)
ff3eb9b7 571 {
3cb500d5 572 pl_content_headers("text/html");
05cb05c0 573 $page->changeTpl('include/field.select.tpl', NO_SKIN);
541e8d03 574 $page->assign('onchange', 'setSSectors()');
ff3eb9b7 575 $page->assign('id', 'ssect_field');
541e8d03 576 $page->assign('name', 'subSector');
5fecdf6d
SJ
577 $it = XDB::iterator("SELECT id, name AS field
578 FROM profile_job_subsector_enum
579 WHERE sectorid = {?}", $sect);
ff3eb9b7 580 $page->assign('list', $it);
581 }
2f678da1 582
ff3eb9b7 583 function handler_ref_country(&$page, $sect, $ssect = '')
584 {
3cb500d5 585 pl_content_headers("text/html");
05cb05c0 586 $page->changeTpl('include/field.select.tpl', NO_SKIN);
ff3eb9b7 587 $page->assign('name', 'pays_sel');
5fecdf6d 588 $where = ($ssect ? ' AND ms.subsectorid = {?}' : '');
e4cd7a1f
SJ
589 $it = XDB::iterator("SELECT gc.iso_3166_1_a2 AS id, gc.countryFR AS field
590 FROM geoloc_countries AS gc
591 INNER JOIN profile_mentor_country AS mp ON (mp.country = gc.iso_3166_1_a2)
ce0b2c6f 592 INNER JOIN profile_mentor_sector AS ms ON (ms.pid = mp.pid)
e4cd7a1f
SJ
593 WHERE ms.sectorid = {?} " . $where . "
594 GROUP BY iso_3166_1_a2
595 ORDER BY countryFR", $sect, $ssect);
ff3eb9b7 596 $page->assign('list', $it);
2f678da1 597 }
598
a1d79217 599 function handler_xnet(&$page)
600 {
8b1f8e12 601 $page->changeTpl('profile/groupesx.tpl');
46f272fe 602 $page->setTitle('Promo, Groupes X, Binets');
e1635d16 603
a1d79217 604 $req = XDB::query('
e1635d16 605 SELECT m.asso_id, a.nom, diminutif, a.logo IS NOT NULL AS has_logo,
46e1d3ba 606 COUNT(e.eid) AS events, mail_domain AS lists
eb41eda9
FB
607 FROM group_members AS m
608 INNER JOIN groups AS a ON(m.asso_id = a.id)
609 LEFT JOIN group_events AS e ON(e.asso_id = m.asso_id AND e.archive = 0)
46e1d3ba 610 WHERE uid = {?} GROUP BY m.asso_id ORDER BY a.nom', S::i('uid'));
a1d79217 611 $page->assign('assos', $req->fetchAllAssoc());
612 }
e1635d16 613
23fb3e6f
SJ
614 function handler_xnetlogo(&$page, $id)
615 {
616 if (is_null($id)) {
617 return PL_NOT_FOUND;
618 }
619
620 $res = XDB::query('SELECT logo, logo_mime
eb41eda9 621 FROM groups
23fb3e6f
SJ
622 WHERE id = {?}', $id);
623 list($logo, $logo_mime) = $res->fetchOneRow();
624
625 if (!empty($logo)) {
3cb500d5 626 pl_cached_dynamic_content_headers($logo_mime);
23fb3e6f
SJ
627 echo $logo;
628 } else {
3cb500d5 629 pl_cached_dynamic_content_headers("image/jpeg");
23fb3e6f
SJ
630 readfile(dirname(__FILE__) . '/../htdocs/images/dflt_carre.jpg');
631 }
632
633 exit;
634 }
635
e49018a7 636 function handler_vcard(&$page, $x = null)
637 {
638 if (is_null($x)) {
639 return PL_NOT_FOUND;
640 }
641
642 global $globals;
643
644 if (substr($x, -4) == '.vcf') {
645 $x = substr($x, 0, strlen($x) - 4);
646 }
647
5d42c993 648 $vcard = new VCard();
07d7f498 649 $vcard->addProfile(Profile::get($x));
5d42c993 650 $vcard->show();
e49018a7 651 }
92423144 652
54cabe90 653 function handler_admin_trombino(&$page, $login = null, $action = null) {
8b1f8e12 654 $page->changeTpl('profile/admin_trombino.tpl');
46f272fe 655 $page->setTitle('Administration - Trombino');
e1635d16 656
54cabe90
VZ
657 if (!$login || !($user = User::get($login))) {
658 return PL_NOT_FOUND;
659 } else {
660 $page->assign_by_ref('user', $user);
661 }
e1635d16 662
92423144 663 switch ($action) {
92423144 664 case "original":
5c4ea53f 665 PlImage::fromFile("/home/web/trombino/photos" . $user->promo() . "/" . $user->login() . ".jpg", "image/jpeg")->send();
92423144 666 exit;
e1635d16 667
92423144 668 case "new":
8827fc52
VZ
669 S::assert_xsrf_token();
670
92423144 671 $data = file_get_contents($_FILES['userfile']['tmp_name']);
672 list($x, $y) = getimagesize($_FILES['userfile']['tmp_name']);
673 $mimetype = substr($_FILES['userfile']['type'], 6);
674 unlink($_FILES['userfile']['tmp_name']);
675 XDB::execute(
5c4ea53f
FB
676 "REPLACE INTO profile_photos SET pid={?}, attachmime = {?}, attach={?}, x={?}, y={?}",
677 $user->profile()->id(), $mimetype, $data, $x, $y);
92423144 678 break;
e1635d16 679
92423144 680 case "delete":
8827fc52
VZ
681 S::assert_xsrf_token();
682
5c4ea53f 683 XDB::execute('DELETE FROM profile_photos WHERE pid = {?}', $user->profile()->id());
92423144 684 break;
685 }
92423144 686 }
b62db02e
SJ
687 function handler_admin_names(&$page, $action = 'list', $id = null) {
688 $page->setTitle('Administration - Types de noms');
689 $page->assign('title', 'Gestion des types de noms');
690 $table_editor = new PLTableEditor('admin/names', 'profile_name_enum', 'id', true);
691 $table_editor->describe('name', 'Nom', true);
692 $table_editor->describe('explanations', 'Explications', true);
693 $table_editor->describe('type', 'Type', true);
694 $table_editor->describe('flags', 'Flags', true);
695 $table_editor->describe('score', 'Score', true);
696 $table_editor->apply($page, $action, $id);
697 }
92423144 698 function handler_admin_binets(&$page, $action = 'list', $id = null) {
46f272fe 699 $page->setTitle('Administration - Binets');
92423144 700 $page->assign('title', 'Gestion des binets');
5c8a71f2
FB
701 $table_editor = new PLTableEditor('admin/binets', 'profile_binet_enum', 'id');
702 $table_editor->add_join_table('profile_binets','binet_id',true);
a7de4ef7 703 $table_editor->describe('text','intitulé',true);
92423144 704 $table_editor->apply($page, $action, $id);
705 }
043bbacf 706 function handler_admin_education(&$page, $action = 'list', $id = null) {
46f272fe 707 $page->setTitle('Administration - Formations');
92423144 708 $page->assign('title', 'Gestion des formations');
043bbacf
SJ
709 $table_editor = new PLTableEditor('admin/education', 'profile_education_enum', 'id');
710 $table_editor->add_join_table('profile_education', 'eduid', true);
711 $table_editor->add_join_table('profile_education_degree', 'eduid', true);
712 $table_editor->describe('name', 'intitulé', true);
713 $table_editor->describe('url', 'site web', false);
714 $table_editor->apply($page, $action, $id);
715 }
716 function handler_admin_education_field(&$page, $action = 'list', $id = null) {
717 $page->setTitle('Administration - Domaines de formation');
718 $page->assign('title', 'Gestion des domaines de formation');
719 $table_editor = new PLTableEditor('admin/education_field', 'profile_education_field_enum', 'id', true);
720 $table_editor->add_join_table('profile_education', 'fieldid', true);
721 $table_editor->describe('field', 'domaine', true);
722 $table_editor->apply($page, $action, $id);
723 }
724 function handler_admin_education_degree(&$page, $action = 'list', $id = null) {
725 $page->setTitle('Administration - Niveau de formation');
726 $page->assign('title', 'Gestion des niveau de formation');
727 $table_editor = new PLTableEditor('admin/education_degree', 'profile_education_degree_enum', 'id', true);
728 $table_editor->add_join_table('profile_education_degree', 'degreeid', true);
729 $table_editor->add_join_table('profile_education', 'degreeid', true);
730 $table_editor->describe('degree', 'niveau', true);
731 $table_editor->apply($page, $action, $id);
732 }
733 function handler_admin_education_degree_set(&$page, $action = 'list', $id = null) {
734 $page->setTitle('Administration - Correspondances formations - niveau de formation');
735 $page->assign('title', 'Gestion des correspondances formations - niveau de formation');
736 $table_editor = new PLTableEditor('admin/education_degree_set', 'profile_education_degree', 'eduid', true);
737 $table_editor->describe('eduid', 'formation', true);
738 $table_editor->describe('degreeid', 'niveau', true);
92423144 739 $table_editor->apply($page, $action, $id);
e1635d16 740 }
b09690be 741 function handler_admin_sections(&$page, $action = 'list', $id = null) {
46f272fe 742 $page->setTitle('Administration - Sections');
a20aab02 743 $page->assign('title', 'Gestion des sections');
5c8a71f2 744 $table_editor = new PLTableEditor('admin/sections','profile_section_enum','id');
b09690be 745 $table_editor->describe('text','intitulé',true);
746 $table_editor->apply($page, $action, $id);
e1635d16 747 }
b6e9d1ca
SJ
748 function handler_admin_sectors(&$page, $action = 'list', $id = null) {
749 $page->setTitle('Administration - Secteurs');
750 $page->assign('title', 'Gestion des secteurs');
751 $table_editor = new PLTableEditor('admin/sectors', 'profile_job_subsubsector_enum', 'id', true);
752 $table_editor->describe('sectorid', 'id du secteur', false);
753 $table_editor->describe('subsectorid', 'id du sous-secteur', false);
754 $table_editor->describe('name', 'nom', true);
755 $table_editor->describe('flags', 'affichage', true);
a20aab02
SJ
756 $table_editor->apply($page, $action, $id);
757 }
15beefb3
GB
758 function handler_admin_networking(&$page, $action = 'list', $id = null) {
759 $page->assign('xorg_title', 'Polytechnique.org - Administration - Networking');
760 $page->assign('title', 'Gestion des types de networking');
1f5cd004 761 $table_editor = new PLTableEditor('admin/networking', 'profile_networking_enum', 'nwid');
15beefb3
GB
762 $table_editor->describe('name', 'intitulé', true);
763 $table_editor->describe('icon', 'nom de l\'icône', false);
dc6378df
GB
764 $table_editor->describe('filter', 'filtre', true);
765 $table_editor->describe('link', 'lien web', true);
15beefb3
GB
766 $table_editor->apply($page, $action, $id);
767 }
4962a9ce
SJ
768 function handler_admin_corps_enum(&$page, $action = 'list', $id = null) {
769 $page->setTitle('Administration - Corps');
770 $page->assign('title', 'Gestion des Corps');
771 $table_editor = new PLTableEditor('admin/corps_enum', 'profile_corps_enum', 'id');
772 $table_editor->describe('name', 'intitulé', true);
773 $table_editor->describe('abbreviation', 'abbréviation', true);
774 $table_editor->describe('still_exists', 'existe encore ?', true);
775 $table_editor->apply($page, $action, $id);
776 }
777 function handler_admin_corps_rank(&$page, $action = 'list', $id = null) {
778 $page->setTitle('Administration - Grade dans les Corps');
779 $page->assign('title', 'Gestion des grade dans les Corps');
780 $table_editor = new PLTableEditor('admin/corps_rank', 'profile_corps_rank_enum', 'id');
781 $table_editor->describe('name', 'intitulé', true);
782 $table_editor->describe('abbreviation', 'abbréviation', true);
783 $table_editor->apply($page, $action, $id);
784 }
92423144 785 function handler_admin_medals(&$page, $action = 'list', $id = null) {
46f272fe 786 $page->setTitle('Administration - Distinctions');
92423144 787 $page->assign('title', 'Gestion des Distinctions');
5c8a71f2 788 $table_editor = new PLTableEditor('admin/medals','profile_medal_enum','id');
a7de4ef7 789 $table_editor->describe('text', 'intitulé', true);
92423144 790 $table_editor->describe('img', 'nom de l\'image', false);
d02b8359 791 $table_editor->describe('flags', 'valider', true);
92423144 792 $table_editor->apply($page, $action, $id);
793 if ($id && $action == 'edit') {
8b1f8e12 794 $page->changeTpl('profile/admin_decos.tpl');
e1635d16 795
92423144 796 $mid = $id;
e1635d16 797
92423144 798 if (Post::v('act') == 'del') {
c6d16b24 799 XDB::execute('DELETE FROM profile_medal_grade_enum
75a17710 800 WHERE mid={?} AND gid={?}', $mid, Post::i('gid'));
92423144 801 } else {
802 foreach (Post::v('grades', array()) as $gid=>$text) {
154ee23a
OLF
803 if ($gid === 0) {
804 if (!empty($text)) {
805 $res = XDB::query('SELECT MAX(gid)
c6d16b24 806 FROM profile_medal_grade_enum
154ee23a
OLF
807 WHERE mid = {?}', $mid);
808 $gid = $res->fetchOneCell() + 1;
809
c6d16b24 810 XDB::execute('INSERT INTO profile_medal_grade_enum (mid, gid, text, pos)
154ee23a
OLF
811 VALUES ({?}, {?}, {?}, {?})',
812 $mid, $gid, $text, $_POST['pos']['0']);
813 }
814 } else {
c6d16b24 815 XDB::execute('UPDATE profile_medal_grade_enum
154ee23a
OLF
816 SET pos={?}, text={?}
817 WHERE gid={?} AND mid={?}', $_POST['pos'][$gid], $text, $gid, $mid);
818 }
92423144 819 }
820 }
c6d16b24 821 $res = XDB::iterator('SELECT gid, text, pos FROM profile_medal_grade_enum WHERE mid={?} ORDER BY pos', $mid);
92423144 822 $page->assign('grades', $res);
823 }
e1635d16 824 }
7d8b17cb 825}
826
a7de4ef7 827// vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8:
7d8b17cb 828?>