From 2bddfba99ad57adbe475f1def03ac8bd5077401d Mon Sep 17 00:00:00 2001 From: Rod Wright Date: Tue, 24 Feb 2026 20:13:13 -0500 Subject: [PATCH] Incorporated changes for release 1.3.2 --- CHANGELOG | 28 ++++ RPiSetup/server-setup.sh | 1 + RPiSetup/terminal-setup.sh | 13 +- TODO.txt | 15 +- boilerplate.php | 39 ++++-- distfiles/CHANGELOG | 28 ++++ distfiles/about.php | 18 +-- distfiles/changelog.php | 92 +++++++++++++ distfiles/common.php | 67 +++++---- distfiles/config.php | 123 +++++++++-------- distfiles/create.php | 98 +++++++------ distfiles/dbadmin.php | 268 ++++++++++++++++++++++++------------ distfiles/gpl.php | 20 +-- distfiles/groups.php | 136 ++++++++++-------- distfiles/login.php | 47 +++++-- distfiles/profile.php | 64 ++++++--- distfiles/search.php | 141 ++++++++++++------- distfiles/settings.php | 14 +- distfiles/writeupdetail.php | 82 +++++++---- distfiles/writeups.php | 79 ++++++----- install.sh | 10 +- opendrs-initial.sql | 4 +- opendrs-update.sql | 5 + 23 files changed, 929 insertions(+), 463 deletions(-) create mode 100644 distfiles/changelog.php diff --git a/CHANGELOG b/CHANGELOG index 302084b..a2b1f27 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -95,3 +95,31 @@ Changelog 1.3.1 - 2022-05-11 - Updated installation scripts and instructions to reflect changes in Raspberry Pi OS Release 2022-04-04. + +1.3.2 - 2022-08-08 + - Fixed typo in dbadmin.php that prevented adding new When Discovered + items. + - Fixed bug in create.php that prevented the page from working. + - Fixed bug in config.php that prevented banners from being modified. + - Fixed bug where action_by and action_reason were not preselected for + subsequent searches in search.php. + - Fixed bug in about.php and gpl.php that still used old $mts_db + database handle. + - Removed the server session directory option in config.php + Miscellaneous settings. For this to make sense, you'd have to have + shell access to the server and if that's the case, you'd be able + to make the necessary database changes as well. + - Fixed opendrs-initial.sql to make the default banner colors match + the ones in common.php. + - Created changelog.php for use by the "changes" link on the About + page so kiosk terminal users don't get dead-ended in the CHANGELOG + text file with no way to get back to the app. + - Extensive code cleanups/updates in all php files to make application + compatible with php8 and eliminate php warnings in apache2 error + log file. + - For Raspberry Pi: + - Updated server-setup.sh to attempt to install the php-mysqli package + for compatibility with php8. + - Chromium browser will use the printer designated as the local + default if it is selected as such in the Cups printer + configuration. diff --git a/RPiSetup/server-setup.sh b/RPiSetup/server-setup.sh index 2edaea3..e46c05f 100644 --- a/RPiSetup/server-setup.sh +++ b/RPiSetup/server-setup.sh @@ -71,6 +71,7 @@ echo "" echo "" echo "" apt install -y apache2 php mariadb-server phpmyadmin uuid-runtime +apt install -y php-mysqli cp etc/apache2/mods-available/alias.conf /etc/apache2/mods-available service apache2 restart echo "...done." diff --git a/RPiSetup/terminal-setup.sh b/RPiSetup/terminal-setup.sh index b3695be..e0482ab 100644 --- a/RPiSetup/terminal-setup.sh +++ b/RPiSetup/terminal-setup.sh @@ -176,11 +176,14 @@ echo "" echo "" echo "Terminal setup complete." echo "" -echo "If you would like to use this terminal as a DRS server, after rebooting" -echo "and logging back in, change directory to the extracted distribution's" -echo "RPiSetup directory, and run:" -echo " sudo ./server-setup.sh" -echo "" +if [ "$conftype" = "Terminal" ] +then + echo "If you would like to use this terminal as a DRS server, after rebooting" + echo "and logging back in, change directory to the extracted distribution's" + echo "RPiSetup directory, and run:" + echo " sudo ./server-setup.sh" + echo "" +fi echo "" echo "A reboot is required to start using this terminal." echo -n "Would you like to reboot now? [Y/n]: " diff --git a/TODO.txt b/TODO.txt index 78703a3..d605ec2 100644 --- a/TODO.txt +++ b/TODO.txt @@ -1,18 +1,11 @@ TODO -- Fix search.php to validate action taken date and time entries - -- Fix occurrences of $mts_db (should be $drs_db)in about.php and gpl.php - - Add ability to save/restore configuration. - Add ability to backup/restore writeups. -- Get Chromium to remember printer selection across reboots. +- Add a $border_visible debug variable to the end of settings.php and + use it wherever there's a "border=\"0\"" to be able to see and fix + table layout issues. -- Fix default banner colors in opendrs-initial.sql to match the ones shown in common.php. - -- Fix failure to preselect "action taken by" users on the search page for subsequent searches. - -- $border_visible debug variable to the end of settings.php and use it wherever there's a - "border=\"0\"" to be able to see and fix table layout issues. +- Automate installation on servers running Nginx as well as Apache. diff --git a/boilerplate.php b/boilerplate.php index 5a857ec..47890d5 100644 --- a/boilerplate.php +++ b/boilerplate.php @@ -8,6 +8,11 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // redirect to index.php on cancel button press if ($_REQUEST['cancel']) { @@ -18,38 +23,46 @@ if ($_REQUEST['cancel']) { } // import session variables -if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; +if (isset($_SESSION['userid'])) { + $userid=$_SESSION['userid']; +} else { + $userid=NULL; +} // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized - // form as "all_parameters" so we need to load those into $incoming + // form as "all_parameters" so we need to load those into $incoming[] $incoming=unserialize($_REQUEST['all_parameters']); + } else { - // copy $_REQUEST to $incoming + // copy $_REQUEST[] to $incoming[] $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array - - -// define local functions - - +// extract incoming array keys into variables +extract($incoming, EXTR_SKIP); +/* + * possible keys are: + * + */ + // assign variables from constants $appname=APP_NAME; -if ($print=="Printer Friendly") { - $sbcolor=P_SIDEBAR_COLOR; +if ($print) { $mbgcolor=P_MENUBG_COLOR; } else { - $sbcolor=SIDEBAR_COLOR; $mbgcolor=MENUBG_COLOR; } $role=dblookup($drs_db,"users","id","role",$userid); +// define local functions + + + + framework("begin","$appname","Boilerplate Page",$print); //echo "_REQUEST array
"; diff --git a/distfiles/CHANGELOG b/distfiles/CHANGELOG index 98c8823..ce3c49c 100644 --- a/distfiles/CHANGELOG +++ b/distfiles/CHANGELOG @@ -95,3 +95,31 @@ Changelog 1.3.1 - 2022-05-11 - Updated installation scripts and instructions to reflect changes in Raspberry Pi OS Release 2022-04-04. + +1.3.2 - 2022-08-08 + - Fixed typo in dbadmin.php that prevented adding new When Discovered + items. + - Fixed bug in create.php that prevented the page from working. + - Fixed bug in config.php that prevented banners from being modified. + - Fixed bug where action_by and action_reason were not preselected for + subsequent searches in search.php. + - Fixed bug in about.php and gpl.php that still used old $mts_db + database handle. + - Removed the server session directory option in config.php + Miscellaneous settings. For this to make sense, you'd have to have + shell access to the server and if that's the case, you'd be able + to make the necessary database changes as well. + - Fixed opendrs-initial.sql to make the default banner colors match + the ones in common.php. + - Created changelog.php for use by the "changes" link on the About + page so kiosk terminal users don't get dead-ended in the CHANGELOG + text file with no way to get back to the app. + - Extensive code cleanups/updates in all php files to make application + compatible with php8 and eliminate php warnings in apache2 error + log file. + - For Raspberry Pi: + - Updated server-setup.sh to attempt to install the php-mysqli package + for compatibility with php8. + - Chromium browser will use the printer designated as the local + default if it is selected as such in the Cups printer + configuration. diff --git a/distfiles/about.php b/distfiles/about.php index 0686df9..cb683e3 100644 --- a/distfiles/about.php +++ b/distfiles/about.php @@ -8,9 +8,14 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // redirect to index.php on cancel button press -if ($_REQUEST['cancel']) { +if (array_key_exists('cancel',$_REQUEST)) { header("Cache-Control:no-cache, must-revalidate"); header("Pragma:no-cache"); header("Location:index.php"); @@ -21,7 +26,6 @@ if ($_REQUEST['cancel']) { if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming @@ -31,7 +35,7 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array +// extract incoming array keys into variables // define local functions @@ -42,14 +46,12 @@ $appname=APP_NAME; $drs_version=DRS_VERSION; if ($print=="Printer Friendly") { - $sbcolor=P_SIDEBAR_COLOR; $mbgcolor=P_MENUBG_COLOR; } else { - $sbcolor=SIDEBAR_COLOR; $mbgcolor=MENUBG_COLOR; } -$role=dblookup($mts_db,"users","id","role",$userid); +$role=dblookup($drs_db,"users","id","role",$userid); framework("begin","$appname","About OpenDRS",$print); @@ -85,7 +87,7 @@ OpenDRS is a simple online maintenance tracking/discrepancy reporting applicatio view, and search writeups. The look and feel of the OpenDRS pages are easily changed. Settings that affect all users can be changed in the Admin Functions menu. User specific settings can be changed in the My Profile menu. No browser specific HTML is used in OpenDRS, so it should be useable in any browser, and it has been -tested using Google Chrome, Mozilla Firefox and Microsoft Internet Explorer. +tested using Google Chrome, Mozilla Firefox, Microsoft Internet Explorer, and Microsoft Edge.

OpenDRS is highly flexible. Instructions are included in the distribution for creating a user terminal with a Raspberry Pi. OpenDRS can be hosted on a @@ -93,7 +95,7 @@ centralized server, accessed by networked PCs and/or Raspberry Pi terminals. It terminal as a non-networked standalone system or in a small network of Raspberry Pi terminals.

-To read about the changes in this latest version of OpenDRS, click on the link or see the CHANGELOG file in the distribution. +To read about the changes in this latest version of OpenDRS, click on the link or see the CHANGELOG file in the distribution.

Several pieces of Open Source software make OpenDRS possible. diff --git a/distfiles/changelog.php b/distfiles/changelog.php new file mode 100644 index 0000000..c103fce --- /dev/null +++ b/distfiles/changelog.php @@ -0,0 +1,92 @@ +"; +//var_dump($_REQUEST); +//echo "


incoming array
"; +//var_dump($incoming); + +// ******** begin database manipulation ******** + + +// ******** end database manipulation ******** + +pagetable("begin"); +if (!$print) { + pageblock("left","begin"); + sidemenu(); + pageblock("left","end"); +} +pageblock("right","begin"); +banner($print); +echo "
"; + +echo " +
+";
+echo file_get_contents("CHANGELOG");
+echo "
+
+"; + +echo "
"; +banner($print); +pageblock("right","end"); +pagetable("end"); + +framework("end","","",$print); + +?> diff --git a/distfiles/common.php b/distfiles/common.php index 96ad3ab..eff1008 100644 --- a/distfiles/common.php +++ b/distfiles/common.php @@ -458,14 +458,19 @@ function banner($print) { } } -function dblookup($dbhandle,$table,$in_field,$out_field,$in_data) { +function dblookup($drs_db,$table,$in_field,$out_field,$in_data) { // look up a single field in a database given a value for a single field - $out_data=mysqli_fetch_row(mysqli_query($dbhandle,"select $out_field from $table where $in_field=\"$in_data\"")); - return($out_data[0]); + $lookup_result=(mysqli_query($drs_db,"select $out_field from $table where $in_field=\"$in_data\"")); + if (mysqli_num_rows($lookup_result) > 0) { + $out_data=mysqli_fetch_row($lookup_result); + return($out_data[0]); + } else { + return NULL; + } } function arrayCopy( array $array ) { - $result = array(); + $result=[]; foreach( $array as $key => $val ) { if( is_array( $val ) ) { $result[$key] = arrayCopy( $val ); @@ -494,7 +499,7 @@ function validate_password($pass,$passconf) { // first element is true if passwords match, false if not // second element is true if passwords meet complexity requirements, false if not - $results=array(); + $results=[]; // check for match if ($pass==$passconf) { @@ -597,7 +602,9 @@ function displaywriteup($id) { } else { $group_ind="\"GRP\""; } - } + } else { + $group_ind=NULL; + } echo "
@@ -667,29 +674,41 @@ function format_message($msgtype,$msgtxt) { function getsetting($setting_name,$user_id) { // get the value of a setting for a user global $drs_db; - $confvalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select id,value from config where name=\"$setting_name\""))['value']; - $uservalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\""))['value']; - if ($uservalue) { - return $uservalue; - } else { - return $confvalue; - } + $confqry=mysqli_query($drs_db,"select id,value from config where name=\"$setting_name\""); + $confvalue=mysqli_fetch_assoc($confqry)['value']; + $userqry=mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\""); + if (mysqli_num_rows($userqry) > 0) { + $uservalue=mysqli_fetch_assoc($userqry)['value']; + if ($uservalue) { + return $uservalue; + } else { + return $confvalue; + } + } else { + return $confvalue; + } } function putsetting($setting_name,$setting_value,$user_id) { // set the value of a setting for a tech global $drs_db; - $confvalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select value from config where name=\"$setting_name\""))['value']; - $uservalue=mysqli_fetch_assoc(mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\""))['value']; - if ($setting_value==$confvalue) { - mysqli_query($drs_db,"delete from profile where user=\"$user_id\" and name=\"$setting_name\""); - } else { - if ($uservalue) { - if ($uservalue != $setting_value) mysqli_query($drs_db,"update profile set value=\"$setting_value\" where name=\"$setting_name\" and user=\"$user_id\""); - } else { - mysqli_query($drs_db,"insert into profile(user,name,value) values(\"$user_id\",\"$setting_name\",\"$setting_value\")"); - } - } + $confqry=mysqli_query($drs_db,"select value from config where name=\"$setting_name\""); + $confvalue=mysqli_fetch_assoc($confqry)['value']; + $userqry=mysqli_query($drs_db,"select value from profile where name=\"$setting_name\" and user=\"$user_id\""); + if (mysqli_num_rows($userqry) > 0) { + $uservalue=mysqli_fetch_assoc($userqry)['value']; + if ($setting_value==$confvalue) { + mysqli_query($drs_db,"delete from profile where user=\"$user_id\" and name=\"$setting_name\""); + } else { + if ($uservalue) { + if ($uservalue != $setting_value) mysqli_query($drs_db,"update profile set value=\"$setting_value\" where name=\"$setting_name\" and user=\"$user_id\""); + } else { + mysqli_query($drs_db,"insert into profile(user,name,value) values(\"$user_id\",\"$setting_name\",\"$setting_value\")"); + } + } + } else { + mysqli_query($drs_db,"insert into profile(user,name,value) values(\"$user_id\",\"$setting_name\",\"$setting_value\")"); + } } function group_detail($groupid,$role=false,$mode="view",$selection="none") { diff --git a/distfiles/config.php b/distfiles/config.php index 7dccd54..442eb33 100644 --- a/distfiles/config.php +++ b/distfiles/config.php @@ -8,9 +8,14 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // redirect to index.php on cancel button press -if ($_REQUEST['cancel']) { +if (array_key_exists('cancel',$_REQUEST)) { header("Cache-Control:no-cache, must-revalidate"); header("Pragma:no-cache"); header("Location:index.php"); @@ -30,7 +35,6 @@ if ($role != ADMIN) { } // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming[] @@ -40,45 +44,55 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array -$update_display=$incoming['update_display']; -$display_appname=$incoming['display_appname']; -$display_banner=$incoming['display_banner']; -$display_footer=$incoming['display_footer']; -$display_funchelp=$incoming['display_funchelp']; -$display_device_term=$incoming['display_device_term']; -$display_discovered_term=$incoming['display_discovered_term']; -$display_discovered_term_short=$incoming['display_discovered_term_short']; -$display_disc_drop_data=$incoming['display_disc_drop_data']; -$display_functional_term=$incoming['display_functional_term']; -$display_functional_term_short=$incoming['display_functional_term_short']; -$display_functional_yes=$incoming['display_functional_yes']; -$display_functional_no=$incoming['display_functional_no']; -$display_functional_yes_short=$incoming['display_functional_yes_short']; -$display_functional_no_short=$incoming['display_functional_no_short']; +// extract incoming array keys into variables +extract($incoming, EXTR_SKIP); +/* + * possible keys are: + * update_display + * display_appname + * display_banner + * display_footer + * display_funchelp + * display_device_term + * display_discovered_term + * display_discovered_term_short + * display_disc_drop_data + * display_functional_term + * display_functional_term_short + * display_functional_yes + * display_functional_no + * display_functional_yes_short + * display_functional_no_short + * update_colors + * reset_colors + * newbgc + * newmbgc + * newtc + * newlc + * newvlc + * newhc + * edit_banner + * add_banner + * update_banner + * delete_banner + * bnrid + * bnrname + * bnrcolor + * bnrtxtcolor + * update_misc + * sessttl + * logoutall + */ -$update_colors=$incoming['update_colors']; -$reset_colors=$incoming['reset_colors']; -$newbgc=$incoming['newbgc']; -$newmbgc=$incoming['newmbgc']; -$newtc=$incoming['newtc']; -$newlc=$incoming['newlc']; -$newvlc=$incoming['newvlc']; -$newhc=$incoming['newhc']; - -$edit_banner=$incoming['edit_banner']; -$add_banner=$incoming['add_banner']; -$update_banner=$incoming['update_banner']; -$delete_banner=$incoming['delete_banner']; -$bnrid=$incoming['bnrid']; -$bnrname=$incoming['bnrname']; -$bnrcolor=$incoming['bnrcolor']; -$bnrtxtcolor=$incoming['bnrtxtcolor']; - -$update_misc=$incoming['update_misc']; -$sessttl=$incoming['sessttl']; -$sessdir=$incoming['sessdir']; -$logoutall=$incoming['logoutall']; +if (!isset($update_display)) $update_display=false; +if (!isset($update_colors)) $update_colors=false; +if (!isset($reset_colors)) $reset_colors=false; +if (!isset($add_banner)) $add_banner=false; +if (!isset($edit_banner)) $edit_banner=false; +if (!isset($update_banner)) $update_banner=false; +if (!isset($delete_banner)) $delete_banner=false; +if (!isset($update_misc)) $update_misc=false; +if (!isset($logoutall)) $logoutall=false; // assign variables from constants $appname=APP_NAME; @@ -97,6 +111,8 @@ framework("begin","$appname","Configuration",$print); //var_dump($incoming); // ******** begin database manipulation ******** +$nameunique_err=$namesuppld_err=$ttlsuppld_err=$dirsuppld_err=false; + if ($update_display) { // remove html tags from footer_message and sanitize $display_footer=strip_tags($display_footer); @@ -174,6 +190,7 @@ if ($add_banner) { // test for name supplied if (strlen(trim($bnrname))) { $namesuppld=true; + $namesuppld_err=false; } else { $namesuppld=false; $namesuppld_err=true; @@ -184,6 +201,7 @@ if ($add_banner) { $nameunique_err=true; } else { $nameunique=true; + $nameunique_err=false; } if ($namesuppld && $nameunique) { // sanitize banner name @@ -204,17 +222,19 @@ if ($edit_banner) { // test for name supplied if (strlen(trim($bnrname))) { $namesuppld=true; + $namesuppld_err=false; } else { $namesuppld=false; $namesuppld_err=true; } // test for name unique - if (mysqli_num_rows(mysqli_query($db,"select bannerid from banners where bannername=\"$bnrname\" and bannerid!=\"$bnrid\""))) { + if (mysqli_num_rows(mysqli_query($drs_db,"select bannerid from banners where bannername=\"$bnrname\" and bannerid!=\"$bnrid\""))) { if (mysqli_num_rows(mysqli_query($drs_db,"select bannerid from banners where bannername=\"$bnrname\""))) { $nameunique=false; $nameunique_err=true; } else { $nameunique=true; + $nameunique_err=false; } } else { $nameunique=true; @@ -246,20 +266,8 @@ if ($update_misc) { $ttlsuppld=false; $ttlsuppld_err=true; } - // test for sessdir supplied - if (strlen(trim($sessdir))) { - $dirsuppld=true; - } else { - $dirsuppld=false; - $dirsuppld_err=true; - } - if ($ttlsuppld && $dirsuppld) { + if ($ttlsuppld) { mysqli_query($drs_db,"update config set value=\"$sessttl\" where name=\"session_ttl_days\""); - if ($ostype == 'WIN') { - mysqli_query($drs_db,"update config set value=\"$sessdir\" where name=\"win_server_session_dir\""); - } else { - mysqli_query($drs_db,"update config set value=\"$sessdir\" where name=\"unix_server_session_dir\""); - } } } @@ -536,17 +544,10 @@ echo " "; if ($ttlsuppld_err) format_message(1,"Session expiration time cannot be blank."); -if ($dirsuppld_err) format_message(1,"Server session file directory cannot be blank."); $curttl=mysqli_fetch_row(mysqli_query($drs_db,"select value from config where name=\"session_ttl_days\""))[0]; -if ($ostype == 'WIN') { - $curssdir=mysqli_fetch_row(mysqli_query($drs_db,"select value from config where name=\"win_server_session_dir\""))[0]; -} else { - $curssdir=mysqli_fetch_row(mysqli_query($drs_db,"select value from config where name=\"unix_server_session_dir\""))[0]; -} echo " Miscellaneous Configuration Parameters



Session expiration time (users will have to log in again after this long) :   days

-Server session file directory (must be writable by the web server process) :


Force logout of all users  



    
diff --git a/distfiles/create.php b/distfiles/create.php index a6ab5b5..b099f81 100644 --- a/distfiles/create.php +++ b/distfiles/create.php @@ -8,9 +8,14 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // redirect to writeups.php on change cancel -if ($_REQUEST['cancel']) { +if (array_key_exists('cancel',$_REQUEST)) { header("Cache-Control:no-cache, must-revalidate"); header("Pragma:no-cache"); header("Location:writeups.php"); @@ -18,10 +23,14 @@ if ($_REQUEST['cancel']) { } // import session variables -if (isset($_SESSION['personid'])) $personid=$_SESSION['personid']; +if (isset($_SESSION['userid'])) { + $userid=$_SESSION['userid']; +} else { + $userid=NULL; +} + // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming[] @@ -31,28 +40,40 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array -$create=$incoming['create']; -$device=$incoming['device']; -$discovered=$incoming['discovered']; -$functional=$incoming['functional']; -$reported_by=$incoming['reported_by']; -$report_date=$incoming['report_date']; -$report_time=$incoming['report_time']; -$subsystem=$incoming['subsystem']; -$discrepancy_text=$incoming['discrepancy_text']; -$status=$incoming['status']; +// extract incoming array keys into variables +extract($incoming, EXTR_SKIP); +/* + * possible keys are: + * create + * device + * discovered + * functional + * reported_by + * report_date + * report_time + * subsystem + * discrepancy_text + * status + */ + +if (!isset($device)) $device=NULL; +if (!isset($discovered)) $discovered=NULL; +if (!isset($reported_by)) $reported_by=NULL; +if (!isset($discrepancy_text)) $discrepancy_text=NULL; +if (!isset($functional)) $functional=NULL; +if (!isset($subsystem)) $subsystem=NULL; + // assign variables from constants $appname=APP_NAME; -if ($print=="Printer Friendly") { +if ($print) { $mbgcolor=P_MENUBG_COLOR; } else { $mbgcolor=MENUBG_COLOR; } -$role=dblookup($drs_db,"persons","id","role",$personid); +$role=dblookup($drs_db,"users","id","role",$userid); framework("begin","$appname","New Writeup",$print); @@ -66,17 +87,17 @@ framework("begin","$appname","New Writeup",$print); // determine today's date and make it the default $today=date("Y-m-d"); $now=date("H:i:s"); -if (!$report_date || $report_date=="automatic") $report_date=$today; -if (!$report_time || $report_time=="automatic") $report_time=$now; +if (!isset($report_date) || $report_date=="automatic") $report_date=$today; +if (!isset($report_time) || $report_time=="automatic") $report_time=$now; -if ($create) { +if (isset($create)) { // add the entry if create is pressed - if ($discrepancy_text && $reported_by && $device && $subsystem && $discovered) { + if ($discrepancy_text!=NULL && $reported_by!=NULL && $device!=NULL && $subsystem!=NULL && $discovered!=NULL) { // sanitize and fix blank date and time $report_date=mysqli_real_escape_string($drs_db,$report_date); $report_time=mysqli_real_escape_string($drs_db,$report_time); - if (!$report_date) $report_date=$today; - if (!$report_time) $report_time=$now; + if (!isset($report_date)) $report_date=$today; + if (!isset($report_time)) $report_time=$now; // remove html tags from discrepancy text and sanitize $discrepancy_text=strip_tags($discrepancy_text); @@ -101,33 +122,33 @@ pageblock("right","begin"); banner($print); echo "
"; // display the form -if ($create) { - if ($discrepancy_text && $reported_by) { +if (isset($create)) { + if ($discrepancy_text!=NULL && $reported_by!=NULL) { format_message(0,"Writeup created. You may create another writeup or return to Open Writeups page."); - $preserve=FALSE; + $preserve=false; } - if (!$device) { + if ($device==NULL) { format_message(1,"You didn't select a $device_term. Please try again."); - $preserve=TRUE; + $preserve=true; } - if (!$subsystem) { + if ($subsystem==NULL) { format_message(1,"You didn't select a subsystem. Please try again."); - $preserve=TRUE; + $preserve=true; } - if (!$discovered) { + if ($discovered==NULL) { format_message(1,"You didn't select a $discovered_term. Please try again."); - $preserve=TRUE; + $preserve=true; } - if (!$discrepancy_text) { + if ($discrepancy_text==NULL) { format_message(1,"You didn't enter any discrepancy text. Please try again."); - $preserve=TRUE; + $preserve=true; } - if (!$reported_by) { + if ($reported_by==NULL) { format_message(1,"You didn't enter your name in the Reported by: block. Please try again."); - $preserve=TRUE; + $preserve=true; } } else { - $preserve=FALSE; + $preserve=false; } echo " @@ -135,9 +156,6 @@ echo " "; // start writeup entry section -if ($status==1) $statusind="OPEN"; -if ($status==2) $statusind="CLSD"; -if ($status==3) $statusind="DFRD"; echo "
@@ -185,7 +203,7 @@ if ($disc_drop_data=="Name") { } $drow=mysqli_query($drs_db,"select * from discovered where active is true order by whendiscoveredname asc"); while ($ditem=mysqli_fetch_assoc($drow)) { - if ($discoverd==$ditem["id"] && $preserve) { + if ($discovered==$ditem["id"] && $preserve) { printf("",$ditem["id"],$ditem["$discddtitle"],$ditem["$discddtext"]); } else { printf("",$ditem["id"],$ditem["$discddtitle"],$ditem["$discddtext"]); diff --git a/distfiles/dbadmin.php b/distfiles/dbadmin.php index 2bda465..c532301 100644 --- a/distfiles/dbadmin.php +++ b/distfiles/dbadmin.php @@ -8,9 +8,13 @@ */ include("common.php"); - +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // redirect to index.php on cancel button press -if ($_REQUEST['cancel']) { +if (array_key_exists('cancel',$_REQUEST)) { header("Cache-Control:no-cache, must-revalidate"); header("Pragma:no-cache"); header("Location:index.php"); @@ -30,7 +34,6 @@ if ($role != ADMIN) { } // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming[] @@ -40,53 +43,85 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array -$edit_user=$incoming['edit_user']; -$add_user=$incoming['add_user']; -$update_user=$incoming['update_user']; -$delete_user=$incoming['delete_user']; -$user_id=$incoming['user_id']; -$user_fname=$incoming['user_fname']; -$user_lname=$incoming['user_lname']; -$user_login=$incoming['user_login']; -$user_pass=$incoming['user_pass']; -$user_passconf=$incoming['user_passconf']; -$user_role=$incoming['user_role']; -$user_active=$incoming['user_active']; +// extract incoming array keys into variables +extract($incoming, EXTR_SKIP); +/* +* possible keys are: +* edit_user +* add_user +* update_user +* delete_user +* user_id +* user_fname +* user_lname +* user_login +* user_pass +* user_passconf +* user_role +* user_active +* edit_device +* add_device +* update_device +* delete_device +* device_id +* device_name +* device_active +* edit_subsystem +* add_subsystem +* update_subsystem +* delete_subsystem +* subsystem_id +* subsystem_name +* subsystem_desc +* subsystem_active +* edit_reason +* add_reason +* update_reason +* delete_reason +* reason_id +* reason_text +* reason_active +* edit_discovered +* add_discovered +* update_discovered +* delete_discovered +* discovered_id +* discovered_name +* discovered_desc +* discovered_active +*/ -$edit_device=$incoming['edit_device']; -$add_device=$incoming['add_device']; -$update_device=$incoming['update_device']; -$delete_device=$incoming['delete_device']; -$device_id=$incoming['device_id']; -$device_name=$incoming['device_name']; -$device_active=$incoming['device_active']; - -$edit_subsystem=$incoming['edit_subsystem']; -$add_subsystem=$incoming['add_subsystem']; -$update_subsystem=$incoming['update_subsystem']; -$delete_subsystem=$incoming['delete_subsystem']; -$subsystem_id=$incoming['subsystem_id']; -$subsystem_name=$incoming['subsystem_name']; -$subsystem_desc=$incoming['subsystem_desc']; -$subsystem_active=$incoming['subsystem_active']; - -$edit_reason=$incoming['edit_reason']; -$add_reason=$incoming['add_reason']; -$update_reason=$incoming['update_reason']; -$delete_reason=$incoming['delete_reason']; -$reason_id=$incoming['reason_id']; -$reason_text=$incoming['reason_text']; -$reason_active=$incoming['reason_active']; - -$edit_discovered=$incoming['edit_discovered']; -$add_discovered=$incoming['add_discovered']; -$update_discovered=$incoming['update_discovered']; -$delete_discovered=$incoming['delete_discovered']; -$discovered_id=$incoming['discovered_id']; -$discovered_name=$incoming['discovered_name']; -$discovered_desc=$incoming['discovered_desc']; -$discovered_active=$incoming['discovered_active']; +if (!isset($edit_user)) $edit_user=false; +if (!isset($add_user)) $add_user=false; +if (!isset($update_user)) $update_user=false; +if (!isset($delete_user)) $delete_user=false; +if (!isset($edit_device)) $edit_device=false; +if (!isset($add_device)) $add_device=false; +if (!isset($update_device)) $update_device=false; +if (!isset($delete_device)) $delete_device=false; +if (!isset($edit_subsystem)) $edit_subsystem=false; +if (!isset($add_subsystem)) $add_subsystem=false; +if (!isset($update_subsystem)) $update_subsystem=false; +if (!isset($delete_subsystem)) $delete_subsystem=false; +if (!isset($edit_reason)) $edit_reason=false; +if (!isset($add_reason)) $add_reason=false; +if (!isset($update_reason)) $update_reason=false; +if (!isset($delete_reason)) $delete_reason=false; +if (!isset($edit_discovered)) $edit_discovered=false; +if (!isset($add_discovered)) $add_discovered=false; +if (!isset($update_discovered)) $update_discovered=false; +if (!isset($delete_discovered)) $delete_discovered=false; +if (!isset($user_fname)) $user_fname=NULL; +if (!isset($user_lname)) $user_lname=NULL; +if (!isset($user_login)) $user_login=NULL; +if (!isset($user_pass)) $user_pass=NULL; +if (!isset($user_passconf)) $user_passconf=NULL; +if (!isset($device_name)) $device_name=NULL; +if (!isset($subsystem_name)) $subsystem_name=NULL; +if (!isset($subsystem_desc)) $subsystem_desc=NULL; +if (!isset($reason_text)) $reason_text=NULL; +if (!isset($discovered_name)) $discovered_name=NULL; +if (!isset($discovered_desc)) $discovered_desc=NULL; // define local functions @@ -94,7 +129,7 @@ $discovered_active=$incoming['discovered_active']; // assign variables from constants $appname=APP_NAME; -if ($print=="Printer Friendly") { +if ($print) { $mbgcolor=P_MENUBG_COLOR; } else { $mbgcolor=MENUBG_COLOR; @@ -110,6 +145,11 @@ framework("begin","$appname","Database Administration",$print); // ******** begin database manipulation ******** // users------------------------------------- +$usernameunique_err=$fnamesuppld_err=$lnamesuppld_err=false; +$loginsuppld_err=$loginunique_err=$passcomplex_err=$passmatch_err=false; +$userhaswriteups_err=false; +$user_add_fail=false; + if ($add_user) { // do error checking // remove html tags from user name @@ -119,6 +159,7 @@ if ($add_user) { // test for first name supplied if (strlen(trim($user_fname))) { $fnamesuppld=true; + $fnamesuppld_err=false; } else { $fnamesuppld=false; $fnamesuppld_err=true; @@ -126,6 +167,7 @@ if ($add_user) { // test for last name supplied if (strlen(trim($user_lname))) { $lnamesuppld=true; + $lnamesuppld_err=false; } else { $lnamesuppld=false; $lnamesuppld_err=true; @@ -136,10 +178,12 @@ if ($add_user) { $usernameunique_err=true; } else { $usernameunique=true; + $usernameunique_err=false; } // test for login supplied if (strlen(trim($user_login))) { $loginsuppld=true; + $loginsuppld_err=false; } else { $loginsuppld=false; $loginsuppld_err=true; @@ -150,27 +194,30 @@ if ($add_user) { $loginunique_err=true; } else { $loginunique=true; + $loginunique_err=false; } // test passwords $passresults=validate_password($user_pass,$user_passconf); if ($passresults['match']) { $passmatch=true; + $passmatch_err=false; } else { $passmatch=false; $passmatch_err=true; } if ($passresults['complex']) { $passcomplex=true; + $passcomplex_err=false; } else { $passcomplex=false; $passcomplex_err=true; } // set role - if (!$user_role) $user_role=USER; + if (!isset($user_role)) $user_role=USER; // set active status - if (!$user_active) $user_active=0; + if (!isset($user_active)) $user_active=0; if ($fnamesuppld && $lnamesuppld && $usernameunique && $loginsuppld && $loginunique && $passcomplex && $passmatch) { // sanitize first name, last name, login @@ -181,6 +228,7 @@ if ($add_user) { $passhash=password_hash($user_pass,PASSWORD_DEFAULT); // modify the table mysqli_query($drs_db,"insert into users(firstname,lastname,login,password_hash,role,active) values(\"$clean_fname\",\"$clean_lname\",\"$clean_login\",\"$passhash\",\"$user_role\",\"$user_active\")"); + $user_add_fail=false; } else { $user_add_fail=true; } @@ -194,6 +242,7 @@ if ($edit_user) { $userhaswriteups_err=true; } else { $userhaswriteups=false; + $userhaswriteups_err=false; } // if none, then remove from db if (!$userhaswriteups) mysqli_query($drs_db,"delete from users where id=\"$user_id\""); @@ -207,6 +256,7 @@ if ($edit_user) { // test for first name supplied if (strlen(trim($user_fname))) { $fnamesuppld=true; + $fnamesuppld_err=false; } else { $fnamesuppld=false; $fnamesuppld_err=true; @@ -214,6 +264,7 @@ if ($edit_user) { // test for last name supplied if (strlen(trim($user_lname))) { $lnamesuppld=true; + $lnamesuppld_err=false; } else { $lnamesuppld=false; $lnamesuppld_err=true; @@ -221,17 +272,20 @@ if ($edit_user) { // test for name unique if (mysqli_num_rows(mysqli_query($drs_db,"select id from users where firstname=\"$user_fname\" and lastname=\"$user_lname\" and id!=\"$user_id\""))) { if (mysqli_num_rows(mysqli_query($drs_db,"select id from users where firstname=\"$user_fname\" and lastname=\"$user_lname\""))) { - $nameunique=false; - $nameunique_err=true; + $nameunique=false; + $nameunique_err=true; } else { $nameunique=true; + $nameunique_err=false; } } else { $nameunique=true; + $nameunique_err=false; } // test for login supplied if (strlen(trim($user_login))) { $loginsuppld=true; + $loginsuppld_err=false; } else { $loginsuppld=false; $loginsuppld_err=true; @@ -243,9 +297,11 @@ if ($edit_user) { $loginunique_err=true; } else { $loginunique=true; + $loginunique_err=false; } } else { $loginunique=true; + $loginunique_err=false; } // sanitize first name, last name, login $clean_fname=mysqli_real_escape_string($drs_db,$user_fname); @@ -253,22 +309,24 @@ if ($edit_user) { $clean_login=mysqli_real_escape_string($drs_db,$user_login); // set role - if (!$user_role) $user_role=USER; + if (!isset($user_role)) $user_role=USER; // set active status - if (!$user_active) $user_active=0; + if (!isset($user_active)) $user_active=0; if ($user_pass!="password_is_unchanged") { // test passwords $passresults=validate_password($user_pass,$user_passconf); if ($passresults['match']) { $passmatch=true; + $passmatch_err=false; } else { $passmatch=false; $passmatch_err=true; } if ($passresults['complex']) { $passcomplex=true; + $passcomplex_err=false; } else { $passcomplex=false; $passcomplex_err=true; @@ -290,6 +348,10 @@ if ($edit_user) { } // devices------------------------------- +$devicenameunique_err=$devicenamesuppld_err=false; +$devicehaswriteups_err=false; +$device_add_fail=false; + if ($add_device) { // do error checking // remove html tags from device name @@ -297,6 +359,7 @@ if ($add_device) { // test for device name supplied if (strlen(trim($device_name))) { $devicenamesuppld=true; + $devicenamesuppld_err=false; } else { $devicenamesuppld=false; $devicenamesuppld_err=true; @@ -307,16 +370,18 @@ if ($add_device) { $devicenameunique_err=true; } else { $devicenameunique=true; + $devicenameunique_err=false; } // set active status - if (!$device_active) $device_active=0; + if (!isset($device_active)) $device_active=0; if ($devicenamesuppld && $devicenameunique) { // sanitize device name $clean_devicename=mysqli_real_escape_string($drs_db,$device_name); // modify the table mysqli_query($drs_db,"insert into devices(name,active) values(\"$clean_devicename\",\"$device_active\")"); + $device_add_fail=false; } else { $device_add_fail=true; } @@ -329,6 +394,7 @@ if ($edit_device) { $devicehaswriteups_err=true; } else { $devicehaswriteups=false; + $devicehaswriteups_err=false; } // if none, then remove from db if (!$devicehaswriteups) mysqli_query($drs_db,"delete from devices where id=\"$device_id\""); @@ -340,6 +406,7 @@ if ($edit_device) { // test for device name supplied if (strlen(trim($device_name))) { $devicenamesuppld=true; + $devicenamesuppld_err=false; } else { $devicenamesuppld=false; $devicenamesuppld_err=true; @@ -347,17 +414,19 @@ if ($edit_device) { // test for device name unique if (mysqli_num_rows(mysqli_query($drs_db,"select id from devices where name=\"$device_name\" and id!=\"$device_id\""))) { if (mysqli_num_rows(mysqli_query($drs_db,"select id from devices where name=\"$device_name\""))) { - $devicenameunique=false; - $devicenameunique_err=true; + $devicenameunique=false; + $devicenameunique_err=true; } else { $devicenameunique=true; + $devicenameunique_err=false; } } else { $devicenameunique=true; + $devicenameunique_err=false; } // set active status - if (!$user_active) $user_active=0; + if (!isset($device_active)) $device_active=0; // sanitize device name $clean_devicename=mysqli_real_escape_string($drs_db,$device_name); @@ -370,6 +439,10 @@ if ($edit_device) { } // subsystems-------------------------------- +$ssnameunique_err=$ssnamesuppld_err=false; +$sshaswriteups_err=false; +$subsystem_add_fail=false; + if ($add_subsystem) { // do error checking // remove html tags from subsystem name and description @@ -378,6 +451,7 @@ if ($add_subsystem) { // test for subsystem name supplied if (strlen(trim($subsystem_name))) { $ssnamesuppld=true; + $ssnamesuppld_err=false; } else { $ssnamesuppld=false; $ssnamesuppld_err=true; @@ -388,10 +462,11 @@ if ($add_subsystem) { $ssnameunique_err=true; } else { $ssnameunique=true; + $ssnameunique_err=false; } // set active status - if (!$subsystem_active) $subsystem_active=0; + if (!isset($subsystem_active)) $subsystem_active=0; if ($ssnamesuppld && $ssnameunique) { // sanitize subsystem name and description @@ -399,6 +474,7 @@ if ($add_subsystem) { $clean_subsystemdesc=mysqli_real_escape_string($drs_db,$subsystem_desc); // modify the table mysqli_query($drs_db,"insert into subsystems(name,description,active) values(\"$clean_subsystemname\",\"$clean_subsystemdesc\",\"$subsystem_active\")"); + $subsystem_add_fail=false; } else { $subsystem_add_fail=true; } @@ -411,6 +487,7 @@ if ($edit_subsystem) { $sshaswriteups_err=true; } else { $sshaswriteups=false; + $sshaswriteups_err=false; } // if none, then remove from db if (!$sshaswriteups) mysqli_query($drs_db,"delete from subsystems where id=\"$subsystem_id\""); @@ -423,6 +500,7 @@ if ($edit_subsystem) { // test for subsystem name supplied if (strlen(trim($subsystem_name))) { $ssnamesuppld=true; + $ssnamesuppld_err=false; } else { $ssnamesuppld=false; $ssnamesuppld_err=true; @@ -430,13 +508,15 @@ if ($edit_subsystem) { // test for subsystem name unique if (mysqli_num_rows(mysqli_query($drs_db,"select id from subsystems where name=\"$subsystem_name\" and id!=\"$subsystem_id\""))) { if (mysqli_num_rows(mysqli_query($drs_db,"select id from subsystems where name=\"$subsystem_name\""))) { - $ssnameunique=false; - $ssnameunique_err=true; + $ssnameunique=false; + $ssnameunique_err=true; } else { $ssnameunique=true; + $ssnameunique_err=false; } } else { $ssnameunique=true; + $ssnameunique_err=false; } // sanitize subsystem name and description $clean_ssname=mysqli_real_escape_string($drs_db,$subsystem_name); @@ -450,6 +530,10 @@ if ($edit_subsystem) { } // reasons------------------------------------ +$reastextunique_err=$reastextsuppld_err=false; +$reashaswriteups_err=false; +$reason_add_fail=false; + if ($add_reason) { // do error checking // remove html tags from reason text @@ -457,6 +541,7 @@ if ($add_reason) { // test for reason text supplied if (strlen(trim($reason_text))) { $reastextsuppld=true; + $reastextsuppld_err=false; } else { $reastextsuppld=false; $reastextsuppld_err=true; @@ -467,16 +552,18 @@ if ($add_reason) { $reastextunique_err=true; } else { $reastextunique=true; + $reastextunique_err=false; } // set active status - if (!$reason_active) $reason_active=0; + if (!isset($reason_active)) $reason_active=0; if ($reastextsuppld && $reastextunique) { // sanitize reason text $clean_reastext=mysqli_real_escape_string($drs_db,$reason_text); // modify the table mysqli_query($drs_db,"insert into reasons(text,active) values(\"$clean_reastext\",\"$reason_active\")"); + $reason_add_fail=false; } else { $reason_add_fail=true; } @@ -489,6 +576,7 @@ if ($edit_reason) { $reashaswriteups_err=true; } else { $reashaswriteups=false; + $reashaswriteups_err=false; } // if none, then remove from db if (!$reashaswriteups) mysqli_query($drs_db,"delete from reasons where id=\"$reason_id\""); @@ -500,6 +588,7 @@ if ($edit_reason) { // test for reason text supplied if (strlen(trim($reason_text))) { $reastextsuppld=true; + $reastextsuppld_err=false; } else { $reastextsuppld=false; $reastextsuppld_err=true; @@ -511,13 +600,15 @@ if ($edit_reason) { $reastextunique_err=true; } else { $reastextunique=true; + $reastextunique_err=false; } } else { $reastextunique=true; + $reastextunique_err=false; } // set active status - if (!$reason_active) $reason_active=0; + if (!isset($reason_active)) $reason_active=0; // sanitize reason text $clean_reastext=mysqli_real_escape_string($drs_db,$reason_text); @@ -530,6 +621,10 @@ if ($edit_reason) { } // when discovered----------------------------------- +$discnamesuppld_err=$discnameunique_err=$discdescsuppld_err=false; +$dischaswriteups_err=false; +$discovered_add_fail=false; + if ($add_discovered) { // do error checking // remove html tags from name and description @@ -538,6 +633,7 @@ if ($add_discovered) { // test for name supplied if (strlen(trim($discovered_name))) { $discnamesuppld=true; + $discnamesuppld_err=false; } else { $discnamesuppld=false; $discnamesuppld_err=true; @@ -548,24 +644,27 @@ if ($add_discovered) { $discnameunique_err=true; } else { $discnameunique=true; + $discnameunique_err=false; } // test for description supplied if (strlen(trim($discovered_desc))) { $discdescsuppld=true; + $discdescsuppld_err=false; } else { $discdescsuppld=false; $discdescsuppld_err=true; } // test for description unique - if (mysqli_num_rows(mysqli_query($drs_db,"select id from description where whendiscovereddesc =\"$discovered_desc\""))) { + if (mysqli_num_rows(mysqli_query($drs_db,"select id from discovered where whendiscovereddesc =\"$discovered_desc\""))) { $discdescunique=false; $discdescunique_err=true; } else { $discdescunique=true; + $discdescunique_err=false; } // set active status - if (!$discovered_active) $discovered_active=0; + if (!isset($discovered_active)) $discovered_active=0; if ($discnamesuppld && $discnameunique && $discdescsuppld) { // sanitize name @@ -574,6 +673,7 @@ if ($add_discovered) { $clean_discovered_desc=mysqli_real_escape_string($drs_db,$discovered_desc); // modify the table mysqli_query($drs_db,"insert into discovered(whendiscoveredname,whendiscovereddesc,active) values(\"$clean_discovered_name\",\"$clean_discovered_desc\",\"$discovered_active\")"); + $discovered_add_fail=false; } else { $discovered_add_fail=true; } @@ -586,6 +686,7 @@ if ($edit_discovered) { $dischaswriteups_err=true; } else { $dischaswriteups=false; + $dischaswriteups_err=false; } // if none, then remove from db if (!$dischaswriteups) mysqli_query($drs_db,"delete from discovered where id=\"$discovered_id\""); @@ -598,6 +699,7 @@ if ($edit_discovered) { // test for name supplied if (strlen(trim($discovered_name))) { $discnamesuppld=true; + $discnamesuppld_err=false; } else { $discnamesuppld=false; $discnamesuppld_err=true; @@ -609,30 +711,23 @@ if ($edit_discovered) { $discnameunique_err=true; } else { $discnameunique=true; + $discnameunique_err=false; } } else { $discnameunique=true; + $discnameunique_err=false; } // test for description supplied if (strlen(trim($discovered_desc))) { $discdescsuppld=true; + $discdescsuppld_err=false; } else { $discdescsuppld=false; $discdescsuppld_err=true; } - // test for description unique - if (mysqli_num_rows(mysqli_query($drs_db,"select id from discovered where whendiscovereddesc=\"$discovered_text\" and id!=\"$discovered_id\""))) { - if (mysqli_num_rows(mysqli_query($drs_db,"select id from discovered where whendiscovereddesc =\"$discovered_desc\""))) { - $discdescunique=false; - $discdescunique_err=true; - } else { - $discdescunique=true; - } - } else { - $discdescunique=true; - } - // set active status - if (!$discovered_active) $discovered_active=0; + + // set active status + if (!isset($discovered_active)) $discovered_active=0; // sanitize name $clean_discovered_name=mysqli_real_escape_string($drs_db,$discovered_name); @@ -640,7 +735,7 @@ if ($edit_discovered) { $clean_discovered_desc=mysqli_real_escape_string($drs_db,$discovered_desc); $updqry="update discovered set whendiscoveredname=\"$clean_discovered_name\",whendiscovereddesc=\"$clean_discovered_desc\",active=\"$discovered_active\" where id=\"$discovered_id\""; - if ($discnamesuppld && $discnameunique && $discdescsuppld && $discdescunique) { + if ($discnamesuppld && $discnameunique && $discdescsuppld) { // modify the table mysqli_query($drs_db,$updqry); } @@ -707,7 +802,7 @@ if ($edit_user && !$delete_user) { } } else { // set form options for add - if (!$user_add_fail) unset($user_id,$user_fname,$user_lname,$user_login,$user_pass,$user_passconf,$user_role,$user_active); + if (!$user_add_fail) $user_id=$user_fname=$user_lname=$user_login=$user_pass=$user_passconf=$user_role=$user_active=NULL; $sectiontitle="Add New User

"; $formtag=""; $buttontags=" @@ -812,7 +907,7 @@ if ($edit_device && !$delete_device) { } } else { // set form options for add - if (!$device_add_fail) unset($device_id,$device_name,$device_active); + if (!$device_add_fail) $device_id=$device_name=$device_active=NULL; $sectiontitle="Add New Device

"; $formtag=""; $buttontags=" @@ -889,7 +984,7 @@ if ($edit_subsystem && !$delete_subsystem) { } } else { // set form options for add - if (!$subsystem_add_fail) unset($subsystem_id,$subsystem_name,$subsystem_desc,$subsystem_active); + if (!$subsystem_add_fail) $subsystem_id=$subsystem_name=$subsystem_desc=$subsystem_active=NULL; $sectiontitle="Add New Subsystem

"; $formtag=""; $buttontags=" @@ -969,7 +1064,7 @@ if ($edit_reason && !$delete_reason) { } } else { // set form options for add - if (!$reason_add_fail) unset($reason_id,$reason_text,$reason_active); + if (!$reason_add_fail) $reason_id=$reason_text=$reason_active=NULL; $sectiontitle="Add New Reason

"; $formtag=""; $buttontags=" @@ -1024,6 +1119,7 @@ echo " "; if ($discnamesuppld_err) format_message(1,"When Discovered name cannot be blank."); if ($discnameunique_err) format_message(1,"When Discovered name already exists."); +if ($discdescsuppld_err) format_message(1,"When Discovered description cannot be blank."); if ($dischaswriteups_err) format_message(1,"When Discovered has writeups in the database and cannot be deleted."); if ($edit_discovered && !$delete_discovered) { @@ -1047,7 +1143,7 @@ if ($edit_discovered && !$delete_discovered) { } } else { // set form options for add - if (!$discovered_add_fail) unset($discovered_id,$discovered_name,$discovered_desc,$discovered_active); + if (!$discovered_add_fail) $discovered_id=$discovered_name=$discovered_desc=$discovered_active=NULL; $sectiontitle="Add New When Discovered

"; $formtag=""; $buttontags=" diff --git a/distfiles/gpl.php b/distfiles/gpl.php index 4bc2858..1fb3b42 100644 --- a/distfiles/gpl.php +++ b/distfiles/gpl.php @@ -8,12 +8,17 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} -// redirect to index.php on cancel button press -if ($_REQUEST['cancel']) { +// redirect to search.php on cancel button press +if (array_key_exists('cancel',$_REQUEST)) { header("Cache-Control:no-cache, must-revalidate"); header("Pragma:no-cache"); - header("Location:index.php"); + header("Location:search.php"); exit(); } @@ -21,7 +26,6 @@ if ($_REQUEST['cancel']) { if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming @@ -31,7 +35,7 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array +// extract incoming array keys into variables // define local functions @@ -40,15 +44,13 @@ if ($print) { // assign variables from constants $appname=APP_NAME; -if ($print=="Printer Friendly") { - $sbcolor=P_SIDEBAR_COLOR; +if ($print) { $mbgcolor=P_MENUBG_COLOR; } else { - $sbcolor=SIDEBAR_COLOR; $mbgcolor=MENUBG_COLOR; } -$role=dblookup($mts_db,"users","id","role",$userid); +$role=dblookup($drs_db,"users","id","role",$userid); framework("begin","$appname","GNU General Public License",$print); diff --git a/distfiles/groups.php b/distfiles/groups.php index d3b7e64..9c732b5 100644 --- a/distfiles/groups.php +++ b/distfiles/groups.php @@ -8,9 +8,14 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // redirect to groups.php on cancel button press -if ($_REQUEST['cancel']) { +if (array_key_exists('cancel',$_REQUEST)) { header("Cache-Control:no-cache, must-revalidate"); header("Pragma:no-cache"); header("Location:groups.php"); @@ -18,10 +23,13 @@ if ($_REQUEST['cancel']) { } // import session variables -if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; +if (isset($_SESSION['userid'])) { + $userid=$_SESSION['userid']; +} else { + $userid=NULL; +} // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming @@ -31,33 +39,47 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array +// extract incoming array keys into variables +extract($incoming, EXTR_SKIP); +/* +* possible keys are: +* action +* save +* targets +* group +* name +* search +* s_status +* s_device +* s_subsystem +* s_discovered +* s_report_date_start +* s_report_date_end +* s_report_time_start +* s_report_time_end +* s_discrepancy_text +* s_reported_by +* s_functional +* edit_status +* edit_action_by +* edit_action_reason +* edit_action_date +* edit_action_time +* edit_action_text +*/ -$action=$incoming['action']; -$save=$incoming['save']; -$targets=$incoming['targets']; -$group=$incoming['group']; -$name=$incoming['name']; +if (!isset($action)) $action=NULL; +if (!isset($s_discrepancy_text)) $s_discrepancy_text=NULL; +if (!isset($s_reported_by)) $s_reported_by=NULL; +if (!isset($edit_status)) $edit_status=NULL; +if (!isset($edit_action_by)) $edit_action_by=NULL; +if (!isset($edit_action_reason)) $edit_action_reason=NULL; +if (!isset($edit_action_text)) $edit_action_text=NULL; +if (!isset($save)) $save=false; +if (!isset($search)) $search=false; +if (!isset($group)) $group=NULL; +if (!isset($name)) $name=NULL; -$search=$incoming['search']; -$s_status=$incoming['s_status']; -$s_device=$incoming['s_device']; -$s_subsystem=$incoming['s_subsystem']; -$s_discovered=$incoming['s_discovered']; -$s_report_date_start=$incoming['s_report_date_start']; -$s_report_date_end=$incoming['s_report_date_end']; -$s_report_time_start=$incoming['s_report_time_start']; -$s_report_time_end=$incoming['s_report_time_end']; -$s_discrepancy_text=$incoming['s_discrepancy_text']; -$s_reported_by=$incoming['s_reported_by']; -$s_functional=$incoming['s_functional']; - -$edit_status=$incoming['edit_status']; -$edit_action_by=$incoming['edit_action_by']; -$edit_action_reason=$incoming['edit_action_reason']; -$edit_action_date=$incoming['edit_action_date']; -$edit_action_time=$incoming['edit_action_time']; -$edit_action_text=$incoming['edit_action_text']; // define local functions @@ -65,11 +87,9 @@ $edit_action_text=$incoming['edit_action_text']; // assign variables from constants $appname=APP_NAME; -if ($print=="Printer Friendly") { - $sbcolor=P_SIDEBAR_COLOR; +if ($print) { $mbgcolor=P_MENUBG_COLOR; } else { - $sbcolor=SIDEBAR_COLOR; $mbgcolor=MENUBG_COLOR; } @@ -91,17 +111,17 @@ $now=date("H:i:s"); // get max report date from writeups table, validate input dates/times and set defaults $maxrepdate_qry=mysqli_query($drs_db,"select max(report_date) from writeups"); $maxrepdate=mysqli_fetch_row($maxrepdate_qry)[0]; -if (!$s_report_date_start || !validateDate($s_report_date_start)) $s_report_date_start=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 30 day)"))[0]; -if (!$s_report_date_end || !validateDate($s_report_date_end)) $s_report_date_end=$maxrepdate; -if (!$s_report_time_start || !validateTime($s_report_time_start)) $s_report_time_start="00:00:00"; -if (!$s_report_time_end || !validateTime($s_report_time_end)) $s_report_time_end="23:59:59"; -if (!$edit_action_date || !validateDate($edit_action_date)) $edit_action_date=$today; -if (!$edit_action_time || !validateTime($edit_action_time)) $edit_action_time=$now; +if (!isset($s_report_date_start) || !validateDate($s_report_date_start)) $s_report_date_start=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 30 day)"))[0]; +if (!isset($s_report_date_end) || !validateDate($s_report_date_end)) $s_report_date_end=$maxrepdate; +if (!isset($s_report_time_start) || !validateTime($s_report_time_start)) $s_report_time_start="00:00:00"; +if (!isset($s_report_time_end) || !validateTime($s_report_time_end)) $s_report_time_end="23:59:59"; +if (!isset($edit_action_date) || !validateDate($edit_action_date)) $edit_action_date=$today; +if (!isset($edit_action_time) || !validateTime($edit_action_time)) $edit_action_time=$now; if ($action=="add" && $role && $save) { $fail=false; - if (!$group) { + if ($group==NULL) { // group was not supplied, so create a new one mysqli_query($drs_db,"insert into groups(name) value(\"\")"); $fail=mysqli_error($drs_db); @@ -117,18 +137,24 @@ if ($action=="add" && $role && $save) { } } elseif ($action=="remove" && $role && $save) { $fail=false; - $writeups=array(); + $writeups=[]; $writeups_qry=mysqli_query($drs_db,"select writeupid from links where linkgroup=\"$group\""); while ($writeuprow=mysqli_fetch_row($writeups_qry)) { $writeups[]=$writeuprow[0]; } foreach ($writeups as $writeup) { - if (!in_array($writeup,$targets)) { + if (!isset($targets) || !in_array($writeup,$targets)) { // remove writeup from group mysqli_query($drs_db,"delete from links where writeupid=$writeup and linkgroup=$group"); $fail=mysqli_error($drs_db); } } + // if there are no longer any writeups in this group, dissolve it + $memb_qty_query=mysqli_query($drs_db,"select id from links where linkgroup=\"$group\""); + if (mysqli_num_rows($memb_qty_query) == 0) { + mysqli_query($drs_db,"delete from groups where id=$group"); + $fail=mysqli_error($drs_db); + } } elseif ($action=="dissolve" && $role && $save) { $fail=false; // unassign all writeups from a group and delete the group @@ -148,7 +174,7 @@ if ($action=="add" && $role && $save) { $fail=false; // set the status, action by, reason action date/time and append supplied text to action text // for all ids in group - if ($edit_action_text) { + if ($edit_action_reason!=NULL) { // sanitize date and time $edit_action_date=mysqli_real_escape_string($drs_db,$edit_action_date); $edit_action_time=mysqli_real_escape_string($drs_db,$edit_action_time); @@ -160,22 +186,23 @@ if ($action=="add" && $role && $save) { while ($edit_row=mysqli_fetch_row($groupmem_qry)) { $writeup_to_edit=$edit_row[0]; $writeup_action_text=dblookup($drs_db,"writeups","id","action_text",$writeup_to_edit); - $full_action_text=$writeup_action_text." STATUS CHANGED: ".$clean_edit_action_text; + $full_action_text=$writeup_action_text." GROUP ACTION TAKEN: ".$clean_edit_action_text; mysqli_query($drs_db,"update writeups set status=\"$edit_status\",action_by=\"$edit_action_by\",action_date=\"$edit_action_date\",action_time=\"$edit_action_time\",action_reason=\"$edit_action_reason\",action_text=\"$full_action_text\" where id=\"$writeup_to_edit\""); $fail=mysqli_error($drs_db); } - } + } else { + $fail="A status change reason was not selected."; + } } if ($search) { // strip whitespace from beginning and end of text fields $s_reported_by=trim($s_reported_by); - $s_action_text=trim($s_action_text); $s_discrepancy_text=trim($s_discrepancy_text); // build the query string $query_string=""; // device - if ($s_device) { + if (isset($s_device)) { $query_string="{$query_string}("; $device_param="Devices:"; foreach ($s_device as $dev_val) { @@ -191,7 +218,7 @@ if ($search) { $query_string="{$query_string} and "; } // subsystem - if ($s_subsystem) { + if (isset($s_subsystem)) { $query_string="{$query_string}("; $subsystem_param="Subsystems:"; foreach ($s_subsystem as $sub_val) { @@ -207,7 +234,7 @@ if ($search) { $query_string="{$query_string} and "; } // discovered - if ($s_discovered) { + if (isset($s_discovered)) { $query_string="{$query_string}("; $discovered_param="{$discovered_term_short}s:"; foreach ($s_discovered as $disc_val) { @@ -223,7 +250,7 @@ if ($search) { $query_string="{$query_string} and "; } // functional - if ($s_functional) { + if (isset($s_functional)) { $query_string="{$query_string}("; $func_param="$functional_term:"; foreach ($s_functional as $func_val) { @@ -238,7 +265,7 @@ if ($search) { $query_string="{$query_string} and "; } // status - if ($s_status) { + if (isset($s_status)) { $query_string="{$query_string}("; $status_param="Status:"; foreach ($s_status as $stat_val) { @@ -266,7 +293,7 @@ if ($search) { $query_string="{$query_string} and "; $reporttime_param="Report time between {$s_report_time_start} and {$s_report_time_end}"; // discrepancy text - if ($s_discrepancy_text) { + if (isset($s_discrepancy_text)) { $query_string="{$query_string}("; $query_string="{$query_string}discrepancy_text like \"%{$s_discrepancy_text}%\""; $query_string="{$query_string})"; @@ -276,7 +303,7 @@ if ($search) { $discrepancytext_param="Text in discrepancy: any"; } // reported by - if ($s_reported_by) { + if (isset($s_reported_by)) { $query_string="{$query_string}("; $query_string="{$query_string}reported_by like \"%{$s_reported_by}%\""; $query_string="{$query_string})"; @@ -303,6 +330,7 @@ banner($print); echo "
"; if ($action=="add") { + if (!isset($targets)) $targets=[]; if (count($targets) > 1) { $plural="s"; } else { @@ -774,9 +802,9 @@ if ($action=="add") { "; + if (!isset($s_group)) $s_group=[]; $grow=mysqli_query($drs_db,"select * from groups order by id asc"); while ($gitem=mysqli_fetch_assoc($grow)) { if ($gitem["name"]=="") { @@ -566,7 +602,11 @@ if (! $exportcsv) { "; $persrow=mysqli_query($drs_db,"select id,firstname,lastname from users order by lastname asc"); while ($persitem=mysqli_fetch_assoc($persrow)) { - printf("",$persitem["id"],$persitem["firstname"],$persitem["lastname"]); + if (!$search || in_array($persitem["id"],$s_action_by,true)) { + printf("",$persitem["id"],$persitem["firstname"],$persitem["lastname"]); + } else { + printf("",$persitem["id"],$persitem["firstname"],$persitem["lastname"]); + } } echo " @@ -584,7 +624,11 @@ if (! $exportcsv) { "; $reasrow=mysqli_query($drs_db,"select id,text from reasons order by id asc"); while ($reasitem=mysqli_fetch_assoc($reasrow)) { - printf("",$reasitem["id"],$reasitem["text"]); + if (!$search || in_array($reasitem["id"],$s_action_reason,true)) { + printf("",$reasitem["id"],$reasitem["text"]); + } else { + printf("",$reasitem["id"],$reasitem["text"]); + } } echo " @@ -776,19 +820,20 @@ if ($search) { } $writeup=mysqli_query($drs_db,$query_string); // create an array of ids returned by the query string - $result_ids=array(); + $result_ids=[]; while ($eachid=mysqli_fetch_assoc($writeup)) { $result_ids[]=$eachid['id']; } mysqli_data_seek($writeup,0); + if (!isset($group_writeups)) $group_writeups=[]; reset($group_writeups); $num_results=mysqli_num_rows($writeup); if ($num_results > 0) { if ($exportcsv) { // generate csv file // create an array of lines of the csv data - $csv_data=array(); + $csv_data=[]; $csv_data[]=['WriteupID','Status',$device_term,'Subsystem',$discovered_term_short,$functional_term,'Discrepancy','Group','Report date','Report time','Reported by','Action taken by','Status Change Reason','Action taken','Action date','Action time']; $csv_fp=fopen('php://temp', 'w+'); @@ -871,14 +916,10 @@ if ($search) { // action time for csv $csv_action_time="{$tablerow["action_time"]}"; - - - if (($show_groupmems == $show_nongroupmems) || ($is_member && $show_groupmems) || (!$is_member && $show_nongroupmems)) { - // add line of results to csv array - $csv_data[]=[$csv_id, $csv_status_text, $csv_dname, $csv_ssname, $csv_discovered, $csv_func_text, $csv_disc_txt, $csv_member_group_name, $csv_report_date, $csv_report_time, $csv_reported_by_text, $csv_action_by, $csv_reasonname, $csv_action_text, $csv_action_date, $csv_action_time]; - - } + // add line of results to csv array + $csv_data[]=[$csv_id, $csv_status_text, $csv_dname, $csv_ssname, $csv_discovered, $csv_func_text, $csv_disc_txt, $csv_member_group_name, $csv_report_date, $csv_report_time, $csv_reported_by_text, $csv_action_by, $csv_reasonname, $csv_action_text, $csv_action_date, $csv_action_time]; } + foreach ($csv_data as $csv_fields) { // add row to csv buffer fputcsv($csv_fp, $csv_fields); diff --git a/distfiles/settings.php b/distfiles/settings.php index 5ea598c..af105bd 100644 --- a/distfiles/settings.php +++ b/distfiles/settings.php @@ -35,17 +35,23 @@ $configqry=mysqli_query($drs_db,"select name,value from config"); while ($configrow = mysqli_fetch_assoc($configqry)) { $constname=strtoupper($configrow['name']); if (isset($userid)) { - $usrval=mysqli_fetch_row(mysqli_query($drs_db,"select value from profile where name=\"{$configrow['name']}\" and user=\"$userid\""))[0]; + $usrvalqry=mysqli_query($drs_db,"select value from profile where name=\"{$configrow['name']}\" and user=\"$userid\""); + if (mysqli_num_rows($usrvalqry) > 0) { + $usrrow=mysqli_fetch_row($usrvalqry); + $usrval=$usrrow[0]; + } } - if ($usrval) { + if (isset($usrval)) { $constvalue=$usrval; + unset($usrval); } else { $constvalue=$configrow['value']; } - define("$constname","$constvalue"); + if (!defined("$constname")) define("$constname","$constvalue"); } -//report no errors +// level of error reporting. Set to 0 for production or E_ALL for development/troubleshooting error_reporting(0); +//error_reporting(E_ALL); ?> diff --git a/distfiles/writeupdetail.php b/distfiles/writeupdetail.php index 56aec41..ea68975 100644 --- a/distfiles/writeupdetail.php +++ b/distfiles/writeupdetail.php @@ -8,9 +8,14 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // redirect to writeups.php on change cancel -if ($_REQUEST['cancel']) { +if (array_key_exists('cancel',$_REQUEST)) { $id=$_REQUEST['id']; header("Cache-Control:no-cache, must-revalidate"); header("Pragma:no-cache"); @@ -22,7 +27,6 @@ if ($_REQUEST['cancel']) { if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming[] @@ -32,32 +36,42 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array -$usersave=$incoming['usersave']; -$techsave=$incoming['techsave']; -$useredit=$incoming['useredit']; -$techedit=$incoming['techedit']; -$id=$incoming['id']; -$device=$incoming['device']; -$discovered=$incoming['discovered']; -$functional=$incoming['functional']; -$reported_by=$incoming['reported_by']; -$report_date=$incoming['report_date']; -$report_time=$incoming['report_time']; -$subsystem=$incoming['subsystem']; -$discrepancy_text=$incoming['discrepancy_text']; -$status=$incoming['status']; -$action_by=$incoming['action_by']; -$action_date=$incoming['action_date']; -$action_time=$incoming['action_time']; -$action_reason=$incoming['action_reason']; -$action_text=$incoming['action_text']; -$group=$incoming['group']; +// extract incoming array keys into variables +extract($incoming, EXTR_SKIP); +/* +* possible keys are: +* usersave +* techsave +* useredit +* techedit +* id +* device +* discovered +* functional +* reported_by +* report_date +* report_time +* subsystem +* discrepancy_text +* status +* action_by +* action_date +* action_time +* action_reason +* action_text +* group +*/ + +if (!isset($usersave)) $usersave=false; +if (!isset($techsave)) $techsave=false; +if (!isset($useredit)) $useredit=false; +if (!isset($techedit)) $techedit=false; +if (!isset($group)) $group=[]; // assign variables from constants $appname=APP_NAME; -if ($print=="Printer Friendly") { +if ($print) { $mbgcolor=P_MENUBG_COLOR; } else { $mbgcolor=MENUBG_COLOR; @@ -392,11 +406,11 @@ if ($useredit) { "; $linkquery=mysqli_query($drs_db,"select * from links where writeupid=\"$id\""); // create an array of ids returned by group query - $wugroups=array(); + $wugroups=[]; while ($eachlink=mysqli_fetch_assoc($linkquery)) { $wugroups[]=$eachlink['linkgroup']; } - mysqli_data_seek($wugroups,0); + reset($wugroups); $grow=mysqli_query($drs_db,"select * from groups order by id asc"); printf("",0,"New group"); while ($gitem=mysqli_fetch_assoc($grow)) { @@ -423,18 +437,22 @@ if ($useredit) { } else { echo " "; } else { - if (!$role) $live="disabled"; + if (!$role) { + $live="disabled"; + } else { + $live=NULL; + } echo " diff --git a/distfiles/writeups.php b/distfiles/writeups.php index d5e76c6..f5bc1d7 100644 --- a/distfiles/writeups.php +++ b/distfiles/writeups.php @@ -8,12 +8,20 @@ */ include("common.php"); +if (array_key_exists('print',$_REQUEST)) { + $print=true; +} else { + $print=false; +} // import session variables -if (isset($_SESSION['userid'])) $userid=$_SESSION['userid']; +if (isset($_SESSION['userid'])) { + $userid=$_SESSION['userid']; +} else { + $userid=NULL; +} // import incoming arrays -$print=$_REQUEST['print']; if ($print) { // if printer friendly was clicked, values will be passed in serialized // form as "all_parameters" so we need to load those into $incoming[] @@ -24,20 +32,24 @@ if ($print) { $incoming=arrayCopy($_REQUEST); } -// load variables from incoming array +// extract incoming array keys into variables +extract($incoming, EXTR_SKIP); +/* + * possible keys are: + * + * view + * start_date + * end_date + * showtoday + * showyesterday + * show7day + * show30day + * viewtype + * togroup + * addtogroup + * selectedids +*/ -$view=$incoming['view']; -$start_date=$incoming['start_date']; -$end_date=$incoming['end_date']; -$showtoday=$incoming['showtoday']; -$showyesterday=$incoming['showyesterday']; -$show7day=$incoming['show7day']; -$show30day=$incoming['show30day']; -$viewtype=$incoming['viewtype']; - -$togroup=$incoming['togroup']; -$addtogroup=$incoming['addtogroup']; -$selectedids=$incoming['selectedids']; // assign variables from constants $appname=APP_NAME; @@ -51,14 +63,14 @@ if ($print) { $role=dblookup($drs_db,"users","id","role",$userid); // define local functions -function opentable($start_date,$end_date,$print,$drs_db,$viewtype="summary") { - // grab some important global variables +function opentable($incoming,$start_date,$end_date,$print,$drs_db,$viewtype="summary") { + // grab some important global variables global $device_term; global $discovered_term, $discovered_term_short, $disc_drop_data; global $functional_term, $functional_term_short; global $functional_yes, $functional_no; global $functional_yes_short, $functional_no_short; - + // show date range selector echo " @@ -161,11 +173,11 @@ function opentable($start_date,$end_date,$print,$drs_db,$viewtype="summary") { } echo "
Group Assignments:  "; $wustat=dblookup($drs_db,"writeups","id","status",$id); - if ($wustat==2 && !$role) $allowuseredit="disabled"; + if ($wustat==2 && !$role) { + $allowuseredit="disabled"; + } else { + $allowuseredit=NULL; + } // Group multi-select ******************** echo "
\n"; } else { - if ($_REQUEST['showyesterday']) { + if (array_key_exists('showyesterday',$incoming)) { $datespec="yesterday"; - } elseif ($_REQUEST['show7day']) { + } elseif (array_key_exists('show7day',$incoming)) { $datespec="the last 7 days"; - } elseif ($_REQUEST['show30day']) { + } elseif (array_key_exists('show30day',$incoming)) { $datespec="the last 30 days"; } else { $datespec="today"; @@ -359,30 +371,31 @@ function viewtable($start_date,$end_date,$print,$drs_db,$viewtype="summary",$rol // use default date values if not supplied $today = date("Y-m-d"); -if ($start_date=="") $start_date=$today; -if ($end_date=="") $end_date=$today; -if ($showtoday) { +if (!isset($start_date)) $start_date=$today; +if (!isset($end_date)) $end_date=$today; +if (isset($showtoday)) { $start_date=$today; $end_date=$today; } -if ($showyesterday) { +if (isset($showyesterday)) { $start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 1 day)"))[0]; $end_date=$start_date; } -if ($show7day) { +if (isset($show7day)) { $start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 7 day)"))[0]; $end_date=$today; } -if ($show30day) { +if (isset($show30day)) { $start_date=mysqli_fetch_row(mysqli_query($drs_db,"select date_sub(curdate(),interval 30 day)"))[0]; $end_date=$today; } -if ($view) { +if (isset($view)) { $pgtitle="Recent Writeups"; } else { $pgtitle="Open Writeups"; } + framework("begin","$appname",$pgtitle,$print); //echo "_REQUEST array
"; @@ -393,7 +406,7 @@ framework("begin","$appname",$pgtitle,$print); // ******** begin database manipulation ******** -if ($addtogroup && $togroup && $selectedids && $role) { +if (isset($addtogroup) && isset($togroup) && isset($selectedids) && $role!=NULL) { $fail=false; if ($togroup=="newgroup") { // Create a new group @@ -424,7 +437,7 @@ pageblock("right","begin"); banner($print); echo "
"; -if ($addtogroup) { +if (isset($addtogroup)) { if (count($selectedids) > 1) { $plural="s"; } else { @@ -436,14 +449,14 @@ if ($addtogroup) { format_message(2,"An error was encountered when adding writeup$plural. The error was \" $fail \""); } } -if (!$viewtype) $viewtype="summary"; +if (!isset($viewtype)) $viewtype="summary"; -if ($view==1) { +if (isset($view)) { // show writeup table viewtable($start_date,$end_date,$print,$drs_db,$viewtype,$role); } else { // show open table - opentable($start_date,$end_date,$print,$drs_db,$viewtype); + opentable($incoming,$start_date,$end_date,$print,$drs_db,$viewtype); } echo "
"; diff --git a/install.sh b/install.sh index db8d111..56a489b 100644 --- a/install.sh +++ b/install.sh @@ -7,7 +7,7 @@ # SPDX-License-Identifier: GPL-2.0 -DRS_VERSION="1.3.1" +DRS_VERSION="1.3.2" DOC_ROOT="/var/www" INSTALL_LOC="opendrs" APACHE_USER="www-data" @@ -78,7 +78,7 @@ then curr_username=`grep username $install_path/db.php | head -1 | cut -d "\"" -f2` curr_dbpass=`grep dbpass $install_path/db.php | head -1 | cut -d "\"" -f2` export MYSQL_PWD="$curr_dbpass" - mysqldump -u"$curr_username" $curr_dbname > $curr_dbname-`date +%Y-%m-%d_%H:%M:%S`-backup.sql + mysqldump --no-tablespaces -u"$curr_username" $curr_dbname > $curr_dbname-`date +%Y-%m-%d_%H:%M:%S`-backup.sql # back up existing installation echo "Backing up current installation to the package directory." cp -R $install_path $install_loc_in-`date +%Y-%m-%d_%H:%M:%S`-backup @@ -169,7 +169,11 @@ else echo "This can be changed later in the application itself." echo -n "Installation name [OpenDRS]: " read new_inst_name - echo "" + if [ "$new_inst_name" = "" ] + then + new_inst_name="OpenDRS" + fi + echo "" # Create initial database db_create_fail=1 diff --git a/opendrs-initial.sql b/opendrs-initial.sql index ee363a7..65b06e2 100644 --- a/opendrs-initial.sql +++ b/opendrs-initial.sql @@ -38,7 +38,7 @@ CREATE TABLE `banners` ( LOCK TABLES `banners` WRITE; /*!40000 ALTER TABLE `banners` DISABLE KEYS */; INSERT INTO `banners` VALUES -(1,'no banner','#000000','#000000'), +(1,'no banner','#000000','#FFFFFF'), (2,'UNCLASSIFIED','#009900','#FFFFFF'), (3,'CONFIDENTIAL','#000099','#FFFFFF'), (4,'SECRET','#990000','#FFFFFF'), @@ -69,7 +69,7 @@ CREATE TABLE `config` ( LOCK TABLES `config` WRITE; /*!40000 ALTER TABLE `config` DISABLE KEYS */; INSERT INTO `config` VALUES -(1,'drs_version','1.3.1','1.3.1'), +(1,'drs_version','1.3.2','1.3.2'), (5,'app_name','OpenDRS - Discrepancy Reporting System','OpenDRS Discrepancy Reporting System'), (6,'banner','1','1'), (7,'background_color','0B3144','0B3144'), diff --git a/opendrs-update.sql b/opendrs-update.sql index 6454a03..88bb195 100644 --- a/opendrs-update.sql +++ b/opendrs-update.sql @@ -221,3 +221,8 @@ UPDATE config SET value="1.3.0",defaultvalue="1.3.0" WHERE name="drs_version"; -- Update version number UPDATE config SET value="1.3.1",defaultvalue="1.3.1" WHERE name="drs_version"; -- -------------------------------------- + +-- ---------- version 1.3.2 ------------- +-- Update version number +UPDATE config SET value="1.3.2",defaultvalue="1.3.2" WHERE name="drs_version"; +-- --------------------------------------