if (Env::has('del')) {
$crc = Env::v('crc');
XDB::execute("UPDATE postfix_mailseen SET release = 'del' WHERE crc = {?}", $crc);
- $page->trig($crc." verra tous ses mails supprimés !");
+ $page->trigSuccess($crc." verra tous ses mails supprimés !");
} elseif (Env::has('ok')) {
$crc = Env::v('crc');
XDB::execute("UPDATE postfix_mailseen SET release = 'ok' WHERE crc = {?}", $crc);
- $page->trig($crc." a le droit de passer !");
+ $page->trigSuccess($crc." a le droit de passer !");
}
$sql = XDB::iterator(
}
$mr = $r->fetchOneAssoc();
- if (!is_numeric($login)) { //user has a forlife
+ // Checks the user has a forlife, as non-registered user can't have redirections.
+ if ($mr['forlife']) {
$redirect = new Redirect($mr['user_id']);
}
// Check if there was a submission
foreach($_POST as $key => $val) {
+ S::assert_xsrf_token();
+
switch ($key) {
case "add_fwd":
$email = trim(Env::v('email'));
if (!isvalid_email_redirection($email)) {
- $page->trig("invalid email $email");
+ $page->trigError("Email non valide: $email");
} else {
$redirect->add_email($email);
- $page->trig("Ajout de $email effectué");
+ $page->trigSuccess("Ajout de $email effectué");
}
break;
WHERE uid = {?} AND rewrite LIKE CONCAT({?}, '@%')",
$mr['user_id'], $val);
fix_bestalias($mr['user_id']);
- $page->trig($val." a été supprimé");
+ $page->trigSuccess($val." a été supprimé");
}
break;
case "activate_fwd":
break;
case "clean_fwd":
if (!empty($val)) {
- $redirect->cleanErrors($val);
+ $redirect->clean_errors($val);
}
break;
case "add_alias":
$domain = $globals->mail->domain;
}
if (!preg_match('/[-a-z0-9\.]+/s', $alias)) {
- $page->trig("'$alias' n'est pas un alias valide");
+ $page->trigError("'$alias' n'est pas un alias valide");
}
if ($domain == $globals->mail->alias_dom || $domain == $globals->mail->alias_dom2) {
$req = new AliasReq($mr['user_id'], $alias, 'Admin request', false);
if ($req->commit()) {
- $page->trig("Nouvel alias '$alias@$domain' attribué");
+ $page->trigSuccess("Nouvel alias '$alias@$domain' attribué");
} else {
- $page->trig("Impossible d'ajouter l'alias '$alias@$domain', il est probablement déjà attribué");
+ $page->trigError("Impossible d'ajouter l'alias '$alias@$domain', il est probablement déjà attribué");
}
} elseif ($domain == $globals->mail->domain || $domain == $globals->mail->domain2) {
if (XDB::execute("INSERT INTO aliases (id,alias,type) VALUES ({?}, {?}, 'alias')",
$mr['user_id'], $alias)) {
- $page->trig("Nouvel alias '$alias' ajouté");
+ $page->trigSuccess("Nouvel alias '$alias' ajouté");
} else {
- $page->trig("Impossible d'ajouter l'alias '$alias', il est probablement déjà attribué");
+ $page->trigError("Impossible d'ajouter l'alias '$alias', il est probablement déjà attribué");
}
} else {
- $page->trig("Le domaine '$domain' n'est pas valide");
+ $page->trigError("Le domaine '$domain' n'est pas valide");
}
break;
case "u_edit":
require_once('secure_hash.inc.php');
$pass_encrypted = Env::v('newpass_clair') != "********" ? hash_encrypt(Env::v('newpass_clair')) : Env::v('passw');
- $naiss = Env::v('naissanceN');
- $deces = Env::v('decesN');
- $perms = Env::v('permsN');
- $prenm = Env::v('prenomN');
- $nom = Env::v('nomN');
- $promo = Env::i('promoN');
- $sexe = Env::v('sexeN');
- $comm = trim(Env::v('commentN'));
- $watch = Env::v('watchN');
- $flags = '';
+ $naiss = Env::v('naissanceN');
+ $deces = Env::v('decesN');
+ $perms = Env::v('permsN');
+ $prenm = Env::v('prenomN');
+ $nom = Env::v('nomN');
+ $nomusage = Env::v('nomusageN');
+ $promo = Env::i('promoN');
+ $sexe = Env::v('sexeN');
+ $comm = trim(Env::v('commentN'));
+ $watch = Env::v('watchN');
+ $flags = '';
if ($sexe) {
$flags = 'femme';
}
}
if ($watch && !$comm) {
- $page->trig("Il est nécessaire de mettre un commentaire pour surveiller un compte");
+ $page->trigError("Il est nécessaire de mettre un commentaire pour surveiller un compte");
break;
}
- $watch = 'SELECT naissance, deces, password, perms,
+ $watch = 'SELECT naissance, deces, password, perms, nom_usage,
prenom, nom, flags, promo, comment
FROM auth_user_md5
WHERE user_id = ' . $mr['user_id'];
perms = '$perms',
prenom = '".addslashes($prenm)."',
nom = '".addslashes($nom)."',
+ nom_usage = '".addslashes($nomusage)."',
flags = '$flags',
promo = $promo,
comment = '".addslashes($comm)."'
WHERE user_id = '{$mr['user_id']}'";
+ if ($perms == 'disabled' && $old_fields['perms'] != 'disabled') {
+ // A user has been banned ==> ensure his php session has been killed
+ // This solution is ugly and overkill, but, it should be efficient.
+ kill_sessions();
+ }
if (XDB::execute($query)) {
user_reindex($mr['user_id']);
$new_fields = $res->fetchOneAssoc();
$mailer = new PlMailer("admin/useredit.mail.tpl");
- $mailer->assign("user", S::v('forlife'));
+ $mailer->assign("admin", S::v('forlife'));
+ $mailer->assign("user", $mr['forlife']);
$mailer->assign('old', $old_fields);
$mailer->assign('new', $new_fields);
$mailer->send();
-
+
// update number of subscribers (perms or deceased may have changed)
update_NbIns();
- $page->trig("updaté correctement.");
+ $page->trigSuccess("updaté correctement.");
}
if (Env::v('nomusageN') != $mr['nom_usage']) {
require_once "xorg.misc.inc.php";
// and the password was changed, updates the Google Apps password as well.
if ($globals->mailstorage->googleapps_domain && Env::v('newpass_clair') != "********") {
require_once 'googleapps.inc.php';
- $account = new GoogleAppsAccount($mr['user_id'], $mr['forlife']);
- if ($account->g_status == 'active' && $account->sync_password) {
+ $account = new GoogleAppsAccount(User::get($mr['forlife']));
+ if ($account->active() && $account->sync_password) {
$account->set_password($pass_encrypted);
}
}
$new_fields['perms'] == 'disabled' &&
$new_fields['perms'] != $old_fields['perms']) {
require_once 'googleapps.inc.php';
- $account = new GoogleAppsAccount($mr['user_id'], $mr['forlife']);
+ $account = new GoogleAppsAccount(User::get($mr['forlife']));
$account->suspend();
}
break;
user_clear_all_subs($mr['user_id']);
// update number of subscribers (perms or deceased may have changed)
update_NbIns();
- $page->trig("'{$mr['user_id']}' a été désinscrit !");
+ $page->trigSuccess("'{$mr['user_id']}' a été désinscrit !");
$mailer = new PlMailer("admin/useredit.mail.tpl");
- $mailer->assign("user", S::v('forlife'));
+ $mailer->assign("admin", S::v('forlife'));
+ $mailer->assign("user", $mr['forlife']);
$mailer->assign("deletion", true);
$mailer->send();
break;
$action = Env::v('valid_promo') == 'Ajouter des membres' ? 'add' : 'ax';
pl_redirect('admin/promo/' . $action . '/' . Env::i('promo'));
} else {
- $page->trig('Promo non valide');
+ $page->trigError('Promo non valide');
}
}
}
}
- $page->assign('op',$op);
- $page->assign('target',$target);
+ $page->assign('op', $op);
+ $page->assign('target', $target);
// on a un $target valide, on prepare les mails
if ($target) {
-
// on examine l'op a effectuer
switch ($op) {
case 'mail':
- send_warning_homonyme($prenom, $nom, $forlife, $loginbis);
- switch_bestalias($target, $loginbis);
+ S::assert_xsrf_token();
+
+ send_warning_homonyme($prenom, $nom, $forlife, $loginbis);
+ switch_bestalias($target, $loginbis);
$op = 'list';
break;
+
case 'correct':
- switch_bestalias($target, $loginbis);
+ S::assert_xsrf_token();
+
+ switch_bestalias($target, $loginbis);
XDB::execute("UPDATE aliases SET type='homonyme',expire=NOW() WHERE alias={?}", $loginbis);
XDB::execute("REPLACE INTO homonymes (homonyme_id,user_id) VALUES({?},{?})", $target, $target);
- send_robot_homonyme($prenom, $nom, $forlife, $loginbis);
+ send_robot_homonyme($prenom, $nom, $forlife, $loginbis);
$op = 'list';
break;
}
$page->assign('promo',$promo);
if ($validate) {
+ S::assert_xsrf_token();
+
$new_deces = array();
$res = XDB::iterRow("SELECT user_id,matricule,nom,prenom,deces FROM auth_user_md5 WHERE promo = {?}", $promo);
while (list($uid,$mat,$nom,$prenom,$deces) = $res->next()) {
$val = Env::v($mat);
- if($val == $deces || empty($val)) continue;
- XDB::execute('UPDATE auth_user_md5 SET deces={?} WHERE matricule = {?}', $val, $mat);
- $new_deces[] = array('name' => "$prenom $nom", 'date' => "$val");
- if($deces=='0000-00-00' or empty($deces)) {
- require_once('notifs.inc.php');
- register_watch_op($uid, WATCH_DEATH, $val);
- require_once('user.func.inc.php');
- user_clear_all_subs($uid, false); // by default, dead ppl do not loose their email
- }
+ if($val == $deces || empty($val)) {
+ continue;
+ }
+
+ XDB::execute('UPDATE auth_user_md5 SET deces={?} WHERE matricule = {?}', $val, $mat);
+ $new_deces[] = array('name' => "$prenom $nom", 'date' => "$val");
+ if($deces == '0000-00-00' || empty($deces)) {
+ require_once('notifs.inc.php');
+ register_watch_op($uid, WATCH_DEATH, $val);
+ require_once('user.func.inc.php');
+ user_clear_all_subs($uid, false); // by default, dead ppl do not loose their email
+ }
}
$page->assign('new_deces',$new_deces);
}
$page->assign('xorg_title','Polytechnique.org - Administration - Décédés');
$res = XDB::iterator(
- "SELECT u.promo, u.nom, u.prenom, u.deces, u.matricule_ax, a.alias,
- DATEDIFF(NOW(), u.deces) AS days
+ "SELECT u.promo, u.nom, u.prenom, u.deces, u.matricule_ax, a.alias, DATE(MAX(s.start)) AS last
FROM auth_user_md5 AS u
LEFT JOIN aliases AS a ON (a.id = u.user_id AND a.type = 'a_vie')
+ LEFT JOIN logger.sessions AS s ON (s.uid = u.user_id AND suid = 0)
WHERE perms IN ('admin', 'user') AND deces <> 0
+ GROUP BY u.user_id
ORDER BY u.promo, u.nom");
$page->assign('dead', $res);
}
}
if(Env::has('uid') && Env::has('type') && Env::has('stamp')) {
+ S::assert_xsrf_token();
+
$req = Validate::get_typed_request(Env::v('uid'), Env::v('type'), Env::v('stamp'));
- if($req) { $req->handle_formu(); }
+ $req->handle_formu();
}
$r = XDB::iterator('SHOW COLUMNS FROM requests_answers');
$page->assign('categories', $categories = explode(',', str_replace("'", '', substr($a['Type'], 5, -1))));
$hidden = array();
+ $res = XDB::query('SELECT hidden_requests FROM requests_hidden WHERE user_id = {?}', S::v('uid'));
+ $hide_requests = $res->fetchOneCell();
if (Post::has('hide')) {
$hide = array();
foreach ($categories as $cat)
$hidden[$cat] = 1;
$hide[] = $cat;
}
- setcookie('hide_requests', join(',',$hide), time()+(count($hide)?25920000:(-3600)), '/', '', 0);
- } elseif (Env::has('hide_requests')) {
- foreach (explode(',',Env::v('hide_requests')) as $hide_type)
+ $hide_requests = join(',', $hide);
+ XDB::query('REPLACE INTO requests_hidden (user_id, hidden_requests) VALUES({?}, {?})',
+ S::v('uid'), $hide_requests);
+ } elseif ($hide_requests) {
+ foreach (explode(',', $hide_requests) as $hide_type)
$hidden[$hide_type] = true;
}
$page->assign('hide_requests', $hidden);
+ // Update the count of item to validate here... useful in development configuration
+ // where several copies of the site use the same DB, but not the same "dynamic configuration"
+ update_NbValid();
$page->assign('vit', new ValidateIterator());
}
$page->setRssLink('Changement Récents',
'/Site/AllRecentChanges?action=rss&user=' . S::v('forlife') . '&hash=' . S::v('core_rss_hash'));
}
+
// update wiki perms
if ($action == 'update') {
+ S::assert_xsrf_token();
+
$perms_read = Post::v('read');
$perms_edot = Post::v('edit');
if ($perms_read || $perms_edit) {
}
if ($action == 'delete' && $wikipage != '') {
+ S::assert_xsrf_token();
+
if (wiki_delete_page($wikipage)) {
- $page->trig("La page ".$wikipage." a été supprimée.");
+ $page->trigSuccess("La page ".$wikipage." a été supprimée.");
} else {
- $page->trig("Impossible de supprimer la page ".$wikipage.".");
+ $page->trigError("Impossible de supprimer la page ".$wikipage.".");
}
}
if ($action == 'rename' && $wikipage != '' && $wikipage2 != '' && $wikipage != $wikipage2) {
+ S::assert_xsrf_token();
+
if ($changedLinks = wiki_rename_page($wikipage, $wikipage2)) {
$s = 'La page <em>'.$wikipage.'</em> a été déplacée en <em>'.$wikipage2.'</em>.';
if (is_numeric($changedLinks)) {
$s .= $changedLinks.' lien'.(($changedLinks>1)?'s ont été modifiés.':' a été modifié.');
}
- $page->trig($s);
+ $page->trigSuccess($s);
} else {
- $page->trig("Impossible de déplacer la page ".$wikipage);
+ $page->trigError("Impossible de déplacer la page ".$wikipage);
}
}
$page->assign('states', $states);
switch (Post::v('action')) {
- case 'create':
+ case 'create':
if (trim(Post::v('ipN')) != '') {
- Xdb::execute('INSERT IGNORE INTO ip_watch (ip, state, detection, last, uid, description)
- VALUES ({?}, {?}, CURDATE(), NOW(), {?}, {?})',
- ip_to_uint(trim(Post::v('ipN'))), Post::v('stateN'), S::i('uid'), Post::v('descriptionN'));
+ S::assert_xsrf_token();
+ Xdb::execute('INSERT IGNORE INTO ip_watch (ip, mask, state, detection, last, uid, description)
+ VALUES ({?}, {?}, {?}, CURDATE(), NOW(), {?}, {?})',
+ ip_to_uint(trim(Post::v('ipN'))), ip_to_uint(trim(Post::v('maskN'))),
+ Post::v('stateN'), S::i('uid'), Post::v('descriptionN'));
};
break;
- case 'edit':
+ case 'edit':
+ S::assert_xsrf_token();
Xdb::execute('UPDATE ip_watch
- SET state = {?}, last = NOW(), uid = {?}, description = {?}
+ SET state = {?}, last = NOW(), uid = {?}, description = {?}, mask = {?}
WHERE ip = {?}', Post::v('stateN'), S::i('uid'), Post::v('descriptionN'),
- ip_to_uint(Post::v('ipN')));
+ ip_to_uint(Post::v('maskN')), ip_to_uint(Post::v('ipN')));
break;
- default:
+ default:
if ($action == 'delete' && !is_null($ip)) {
+ S::assert_xsrf_token();
Xdb::execute('DELETE FROM ip_watch WHERE ip = {?}', ip_to_uint($ip));
}
}
$sql = "SELECT w.ip, IF(s.ip IS NULL,
IF(w.ip = s2.ip, s2.host, s2.forward_host),
IF(w.ip = s.ip, s.host, s.forward_host)),
- w.detection, w.state, a.alias AS forlife
+ w.mask, w.detection, w.state, a.alias AS forlife
FROM ip_watch AS w
LEFT JOIN logger.sessions AS s ON (s.ip = w.ip)
LEFT JOIN logger.sessions AS s2 ON (s2.forward_ip = w.ip)
$table = array();
$props = array();
- while (list($ip, $host, $date, $state, $forlife) = $it->next()) {
+ while (list($ip, $host, $mask, $date, $state, $forlife) = $it->next()) {
$ip = uint_to_ip($ip);
+ $mask = uint_to_ip($mask);
if (count($props) == 0 || $props['ip'] != $ip) {
if (count($props) > 0) {
$table[] = $props;
}
$props = array('ip' => $ip,
+ 'mask' => $mask,
'host' => $host,
'detection' => $date,
'state' => $state,
}
$page->assign('table', $table);
} elseif ($action == 'edit') {
- $sql = "SELECT w.detection, w.state, w.last, w.description,
+ $sql = "SELECT w.detection, w.state, w.last, w.description, w.mask,
a1.alias AS edit, a2.alias AS forlife, s.host
FROM ip_watch AS w
LEFT JOIN aliases AS a1 ON (a1.id = w.uid AND a1.type = 'a_vie')
$it = Xdb::iterRow($sql, ip_to_uint($ip));
$props = array();
- while (list($detection, $state, $last, $description, $edit, $forlife, $host) = $it->next()) {
+ while (list($detection, $state, $last, $description, $mask, $edit, $forlife, $host) = $it->next()) {
if (count($props) == 0) {
$props = array('ip' => $ip,
+ 'mask' => uint_to_ip($mask),
'host' => $host,
'detection' => $detection,
'state' => $state,
$page->changeTpl('admin/icons.tpl');
$dh = opendir('../htdocs/images/icons');
if (!$dh) {
- $page->trig('Dossier des icones introuvables.');
+ $page->trigError('Dossier des icones introuvables.');
}
$icons = array();
while (($file = readdir($dh)) !== false) {