altocompta/html/priv_user.php
Dany De Bontridder 8834d14ee5 Merged revisions 2258,2260-2262,2264-2268,2270-2283,2285-2297,2299-2322,2324-2340 via svnmerge from
svn+ssh://danydb@svn/svn/phpcompta/branches/rel430

........
  r2258 | danydb | 2008-12-18 23:21:00 +0100 (Thu, 18 Dec 2008) | 1 line
  
  Add debug
........
  r2262 | danydb | 2008-12-19 22:38:25 +0100 (Fri, 19 Dec 2008) | 1 line
  
  Add a local admin 
........
  r2270 | danydb | 2008-12-21 20:11:26 +0100 (Sun, 21 Dec 2008) | 1 line
  
  Doc. remove the useless todo list
........
  r2271 | danydb | 2008-12-22 21:18:46 +0100 (Mon, 22 Dec 2008) | 3 lines
  
  Remove obsolete functions insertRapt, deleteRapt and getconcerned
  Remove obsolete file user_update
........
  r2272 | danydb | 2008-12-22 21:21:46 +0100 (Mon, 22 Dec 2008) | 2 lines
  
  Remove obsolete function isFicheOfJrn
........
  r2273 | danydb | 2008-12-22 21:44:28 +0100 (Mon, 22 Dec 2008) | 1 line
  
  Improve Invoice : add the username 
........
  r2287 | danydb | 2009-01-13 21:37:07 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning replace GetConcerned by Acc_Reconciliation
........
  r2288 | danydb | 2009-01-13 21:38:40 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Add a comment on jrn operation
........
  r2289 | danydb | 2009-01-13 21:40:13 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning : add comments to the code
........
  r2290 | danydb | 2009-01-13 21:40:46 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning replace GetConcerned by Acc_Reconciliation
........
  r2291 | danydb | 2009-01-13 21:41:35 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning replace GetConcerned by Acc_Reconciliation
........
  r2292 | danydb | 2009-01-13 21:42:15 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Add documentation about new tags
........
  r2293 | danydb | 2009-01-13 21:43:22 +0100 (Tue, 13 Jan 2009) | 1 line
  
  Code cleaning start rewriting of the security part 
........
  r2294 | danydb | 2009-01-14 20:09:18 +0100 (Wed, 14 Jan 2009) | 1 line
  
  Improve : template of security + security code
........
  r2295 | danydb | 2009-01-14 20:21:51 +0100 (Wed, 14 Jan 2009) | 1 line
  
  Improve security : add new variable
........
  r2296 | danydb | 2009-01-14 20:39:58 +0100 (Wed, 14 Jan 2009) | 1 line
  
  Improve security : modify layout
........
  r2297 | danydb | 2009-01-15 19:21:47 +0100 (Thu, 15 Jan 2009) | 1 line
  
  Improve security : user setting
........
  r2299 | danydb | 2009-01-15 19:28:56 +0100 (Thu, 15 Jan 2009) | 2 lines
  
  Clean code : can_request doens't have a connx parameter
........
  r2300 | danydb | 2009-01-16 19:12:47 +0100 (Fri, 16 Jan 2009) | 1 line
  
  Improve Ecriture directe libelle : new widget js_search_card_control
........
  r2301 | danydb | 2009-01-16 22:29:39 +0100 (Fri, 16 Jan 2009) | 1 line
  
  Improve Quick Writing : remove span, and update the comment field
........
  r2302 | danydb | 2009-01-16 23:01:24 +0100 (Fri, 16 Jan 2009) | 1 line
  
  Improve cosmetic : GL + remove the select topmenu
........
  r2303 | danydb | 2009-01-19 08:41:09 +0100 (Mon, 19 Jan 2009) | 1 line
  
  Cosmetic : a inline
........
  r2304 | danydb | 2009-01-20 23:03:59 +0100 (Tue, 20 Jan 2009) | 6 lines
  
  Code Cleaning
  Security : remove obsolete files & function
  Class_user : add new functions for the security
  Only the menu in text mode with a break line
........
  r2305 | danydb | 2009-01-20 23:05:01 +0100 (Tue, 20 Jan 2009) | 1 line
  
  code cleaning rewriting of Security 
........
  r2306 | danydb | 2009-01-21 21:13:15 +0100 (Wed, 21 Jan 2009) | 1 line
  
  Security printing unicode and fix some bugs
........
  r2309 | danydb | 2009-01-26 19:56:28 +0100 (Mon, 26 Jan 2009) | 1 line
  
  ADD : company without VAT
........
  r2310 | danydb | 2009-01-26 23:33:14 +0100 (Mon, 26 Jan 2009) | 1 line
  
  Add : no vat for Purchase ledger 
........
  r2312 | danydb | 2009-01-28 19:57:30 +0100 (Wed, 28 Jan 2009) | 1 line
  
  Integration 
........
  r2313 | danydb | 2009-01-28 22:46:27 +0100 (Wed, 28 Jan 2009) | 1 line
  
  Work with or without VAT
........
  r2314 | danydb | 2009-01-29 22:18:57 +0100 (Thu, 29 Jan 2009) | 2 lines
  
  Remove debug info
........
  r2315 | danydb | 2009-01-29 23:23:14 +0100 (Thu, 29 Jan 2009) | 1 line
  
  ADD the possibility to enter a piece number
........
  r2316 | danydb | 2009-01-31 23:20:00 +0100 (Sat, 31 Jan 2009) | 1 line
  
  Documentation
........
  r2317 | danydb | 2009-02-04 20:14:54 +0100 (Wed, 04 Feb 2009) | 1 line
  
  Template for ledger
........
  r2318 | danydb | 2009-02-05 15:52:58 +0100 (Thu, 05 Feb 2009) | 1 line
  
  Add PJ setting + default in Ledger, fix bug in listJrn
........
  r2319 | danydb | 2009-02-05 17:09:56 +0100 (Thu, 05 Feb 2009) | 2 lines
  
  Search by PJ
........
  r2320 | danydb | 2009-02-05 17:23:24 +0100 (Thu, 05 Feb 2009) | 1 line
  
  Finished with pj
........
  r2321 | danydb | 2009-02-05 18:11:35 +0100 (Thu, 05 Feb 2009) | 1 line
  
  PJ is readonly
........
  r2322 | danydb | 2009-02-05 20:10:34 +0100 (Thu, 05 Feb 2009) | 1 line
  
  Saldo : write the first saldo (ajax)
........
  r2324 | danydb | 2009-02-06 00:07:50 +0100 (Fri, 06 Feb 2009) | 5 lines
  
  Add database script
  Cosmetic (menu)
  Fix Bug 
........
  r2325 | danydb | 2009-02-06 14:07:07 +0100 (Fri, 06 Feb 2009) | 1 line
  
  Improve Pj seq 
........
  r2326 | danydb | 2009-02-09 22:47:23 +0100 (Mon, 09 Feb 2009) | 6 lines
  
  Fix Bug privilege (compta_ven)
  Fix if the pj is empty do not increment the sequence (class_acc_operation)
  Fix remove PJ if pj is empty (modify_op.php)
  Cosmetic do not print PJ if pj is null or empty (listing)
........
  r2327 | danydb | 2009-02-10 21:04:48 +0100 (Tue, 10 Feb 2009) | 5 lines
  
  Fix bug in PJ seq
  Fix bug in export jrn csv
  Improve avoid the removal of vat rate
  Add security for card
........
  r2328 | danydb | 2009-02-12 20:26:36 +0100 (Thu, 12 Feb 2009) | 4 lines
  
  Cosmetic menu_tool
  Impression add tag PJ
  Cosmetic menu administration
........
  r2329 | danydb | 2009-02-12 21:43:19 +0100 (Thu, 12 Feb 2009) | 5 lines
  
  filter the folder the local admin can access
  add a function check_dossier which must be implemented everywhere
  Printing with PJ
  NoAccess default = javascript
........
  r2330 | danydb | 2009-02-14 18:11:49 +0100 (Sat, 14 Feb 2009) | 2 lines
  
  improve add libelle for balance csv
........
  r2331 | danydb | 2009-02-14 19:10:56 +0100 (Sat, 14 Feb 2009) | 7 lines
  
  Balance csv add label
  Bug Financial ledger list
  BUG period access 
  BUG stock access
  IMPROVE list ledger with PJ
........
  r2332 | danydb | 2009-02-15 18:21:59 +0100 (Sun, 15 Feb 2009) | 1 line
  
  Bug order was not saved for report
........
  r2333 | danydb | 2009-02-15 18:22:17 +0100 (Sun, 15 Feb 2009) | 1 line
  
  Add security for normal user
........
  r2334 | danydb | 2009-02-15 18:23:24 +0100 (Sun, 15 Feb 2009) | 3 lines
  
  Bug forget to import class
........
  r2335 | danydb | 2009-02-17 21:33:17 +0100 (Tue, 17 Feb 2009) | 5 lines
  
  Fix quick writing let write
  Fix card priv
  Remove button if no priv to add card or cancel an op
........
  r2336 | danydb | 2009-02-19 21:01:36 +0100 (Thu, 19 Feb 2009) | 4 lines
  
  Check for CA
  common Bug with the repository
........
  r2337 | danydb | 2009-02-19 21:50:35 +0100 (Thu, 19 Feb 2009) | 2 lines
  
  Test the parameter security part
........
2009-02-19 21:11:08 +00:00

250 lines
6.4 KiB
PHP

<?php
/*
* This file is part of PhpCompta.
*
* PhpCompta is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* PhpCompta is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with PhpCompta; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
*/
// Copyright Author Dany De Bontridder ddebontridder@yahoo.fr
/*! \file
* \brief Users Security
*/
include_once("ac_common.php");
include_once("postgres.php");
include_once("debug.php");
include_once("user_menu.php");
html_page_start($_SESSION['g_theme']);
$rep=DbConnect();
include_once ("class_user.php");
$User=new User($rep);
$User->Check();
/* only the global admin can modify something here
*/
if ($User->admin != 1) {
html_page_stop();
return;
}
if (! isset ($_GET['UID']) && ! isset($_POST['UID']) ) {
//Message d'erreur si UID non positionné
echo_debug('priv_user.php',__LINE__,"UID NOT DEFINED");
html_page_stop();
return;
}
$uid=( isset ($_GET['UID']))? $_GET['UID']: $_POST['UID'];
$UserChange=new User($rep,$uid);
echo_debug('priv_user.php',__LINE__,"UID IS DEFINED");
$r_UID=$UserChange->id;
if ( $r_UID == false ) {
echo_debug('priv_user.php',__LINE__,"UID NOT VALID");
// Message d'erreur
html_page_stop();
return;
}
echo_debug('priv_user.php',__LINE__,"UID IS VALID");
echo '<H2 class="info"> Administration Globale</H2>';
echo "<div>".MenuAdmin()."</div>";
echo '<DIV>';
echo '<h2>Gestion Utilisateurs</h2>';
// User is valid and you're an admin
?>
<?php
/* Parse the changes */
if ( isset ( $_GET['reset_passwd']) ){
$cn=DbConnect();
$l_pass=md5('phpcompta');
$Res=ExecSql($cn, "update ac_users set use_pass='$l_pass' where use_id=$uid");
echo '<H2 class="info"> Password remis à phpcompta</H2>';
}
/* Save the changes */
if ( isset ($_POST['SAVE']) ){
$uid = $_POST['UID'];
// Update User
$cn=DbConnect();
$last_name=pg_escape_string($_POST['fname']);
$first_name=pg_escape_string($_POST['lname']);
$Sql="update ac_users set use_first_name='".$first_name."', use_name='".$last_name."'
,use_active=".$_POST['Actif'].",use_admin=".$_POST['Admin']." where
use_id=".$uid;
$Res=ExecSql($cn,$Sql);
// Update Priv on Folder
foreach ($_POST as $name=>$elem)
{
echo_debug('priv_user.php',__LINE__,"_POST $name $elem");
if ( substr_count($name,'PRIV')!=0 )
{
echo_debug('priv_user.php',__LINE__,"Found a priv");
$db_id=substr($name,4);
$cn=DbConnect();
if ( ExisteJnt($db_id,$uid) != 1 )
{
$Res=ExecSql($cn,"insert into jnt_use_dos(dos_id,use_id) values(".$db_id.",".$uid.")");
}
$jnt=GetJnt($db_id,$uid);
if (ExistePriv($jnt) > 0)
{
$Res=ExecSql($cn,"update priv_user set priv_priv='".$elem."' where priv_jnt=".$jnt);
} else {
$Res=ExecSql($cn,"insert into priv_user(priv_jnt,priv_priv) values (".$jnt.",'".$elem."')");
}
}
}
} else {
if ( isset ($_POST["DELETE"]) ) {
$cn=DbConnect();
$Res=ExecSql($cn,"delete from priv_user where priv_jnt in ( select jnt_id from jnt_use_dos where use_id=".$uid.")");
$Res=ExecSql($cn,"delete from jnt_use_dos where use_id=".$uid);
$Res=ExecSql($cn,"delete from ac_users where use_id=".$uid);
echo "<center><H2 class=\"info\"> User ".$_POST['fname']." ".$_POST['lname']." (".
$_POST['login'].") is deleted </H2></CENTER>";
require_once("user.inc.php");
return;
}
}
$UserChange->load();
?>
<FORM ACTION="priv_user.php" METHOD="POST">
<?php printf('<INPUT TYPE=HIDDEN NAME=UID VALUE="%s">',$uid); ?>
<TABLE BORDER=0>
<TR>
<?php printf('<td>login</td><td> %s</td>',$UserChange->login); ?>
</TD></tr>
<TR><TD>
<?php printf('Nom de famille </TD><td><INPUT type="text" NAME="fname" value="%s"> ',$UserChange->name); ?>
</TD></TR>
<?php printf('<td>prénom</td><td>
<INPUT type="text" NAME="lname" value="%s"> ',$UserChange->first_name); ?>
</TD>
</TR>
</table>
<TABLE>
<?php
if ( $UserChange->active == 1 ) {
$ACT="CHECKED";$NACT="UNCHECKED";
} else {
$ACT="UNCHECKED";$NACT="CHECKED";
}
echo "<TR><TD>";
printf('<INPUT type="RADIO" NAME="Actif" VALUE="1" %s> Actif',$ACT);
echo "</TD><TD>";
printf('<INPUT type="RADIO" NAME="Actif" VALUE="0" %s> Non Actif',$NACT);
echo "</TD></TR>";
?>
</TABLE>
</TD>
<TD>
<TABLE>
<?php
if ( $UserChange->admin == 1 ) {
$ACT="CHECKED";$NACT="UNCHECKED";
} else {
$ACT="UNCHECKED";$NACT="CHECKED";
}
echo "<TR><TD>";
printf('<INPUT type="RADIO" NAME="Admin" VALUE="1" %s> Administrateur global',$ACT);
echo "</TD><TD>";
printf('<INPUT type="RADIO" NAME="Admin" VALUE="0" %s> Pas administrateur global ',$NACT);
echo "</TD></TR>";
?>
</TABLE>
</TD>
</TR>
<TR>
<TD>
<!-- Show all database and rights -->
<H2 class="info"> Droit sur les dossiers pour les utilisateurs normaux </H2>
<p class="notice">
Les autres droits doivent être réglés dans les dossiers (paramètre->sécurité)
</p>
<TABLE>
<?php
$array=array(
array('value'=>'X','label'=>'Aucun Accès'),
array('value'=>'R','label'=>'Utilisateur normal'),
array('value'=>'L','label'=>'Administrateur local(Tous les droits)')
);
$Dossier=ShowDossier('all',1,0);
if ( empty ( $Dossier )) {
echo '* Aucun Dossier *';
echo '</div>';
exit();
}
$mod_user=new User(DbConnect(),$uid);
foreach ( $Dossier as $rDossier) {
$priv=$mod_user->get_privilege($rDossier['dos_id']);
printf("<TR><TD> Dossier : %s </TD>",$rDossier['dos_name']);
$select=new widget('select');
$select->table=1;
$select->name=sprintf('PRIV%s',$rDossier['dos_id']);
$select->value=$array;
$select->selected=$priv;
echo $select->IOValue();
echo "</TD></TR>";
}
?>
</TABLE>
<?php echo widget::button_href('Reinitialiser le mot de passe',
sprintf('priv_user.php?reset_passwd&UID=%s',$uid));
?>
<input type="Submit" NAME="SAVE" VALUE="Sauver les changements changes">
<input type="Submit" NAME="DELETE" VALUE="Effacer" onclick="return confirm('Confirmer effacement ?');" >
</FORM>
<A href='admin_repo.php?action=user_mgt'>Retour</a>
</DIV>
<?php
html_page_stop();
?>