svn+ssh://danydb@svn/svn/phpcompta/branches/rel430 ........ r2258 | danydb | 2008-12-18 23:21:00 +0100 (Thu, 18 Dec 2008) | 1 line Add debug ........ r2262 | danydb | 2008-12-19 22:38:25 +0100 (Fri, 19 Dec 2008) | 1 line Add a local admin ........ r2270 | danydb | 2008-12-21 20:11:26 +0100 (Sun, 21 Dec 2008) | 1 line Doc. remove the useless todo list ........ r2271 | danydb | 2008-12-22 21:18:46 +0100 (Mon, 22 Dec 2008) | 3 lines Remove obsolete functions insertRapt, deleteRapt and getconcerned Remove obsolete file user_update ........ r2272 | danydb | 2008-12-22 21:21:46 +0100 (Mon, 22 Dec 2008) | 2 lines Remove obsolete function isFicheOfJrn ........ r2273 | danydb | 2008-12-22 21:44:28 +0100 (Mon, 22 Dec 2008) | 1 line Improve Invoice : add the username ........ r2287 | danydb | 2009-01-13 21:37:07 +0100 (Tue, 13 Jan 2009) | 1 line Code cleaning replace GetConcerned by Acc_Reconciliation ........ r2288 | danydb | 2009-01-13 21:38:40 +0100 (Tue, 13 Jan 2009) | 1 line Add a comment on jrn operation ........ r2289 | danydb | 2009-01-13 21:40:13 +0100 (Tue, 13 Jan 2009) | 1 line Code cleaning : add comments to the code ........ r2290 | danydb | 2009-01-13 21:40:46 +0100 (Tue, 13 Jan 2009) | 1 line Code cleaning replace GetConcerned by Acc_Reconciliation ........ r2291 | danydb | 2009-01-13 21:41:35 +0100 (Tue, 13 Jan 2009) | 1 line Code cleaning replace GetConcerned by Acc_Reconciliation ........ r2292 | danydb | 2009-01-13 21:42:15 +0100 (Tue, 13 Jan 2009) | 1 line Add documentation about new tags ........ r2293 | danydb | 2009-01-13 21:43:22 +0100 (Tue, 13 Jan 2009) | 1 line Code cleaning start rewriting of the security part ........ r2294 | danydb | 2009-01-14 20:09:18 +0100 (Wed, 14 Jan 2009) | 1 line Improve : template of security + security code ........ r2295 | danydb | 2009-01-14 20:21:51 +0100 (Wed, 14 Jan 2009) | 1 line Improve security : add new variable ........ r2296 | danydb | 2009-01-14 20:39:58 +0100 (Wed, 14 Jan 2009) | 1 line Improve security : modify layout ........ r2297 | danydb | 2009-01-15 19:21:47 +0100 (Thu, 15 Jan 2009) | 1 line Improve security : user setting ........ r2299 | danydb | 2009-01-15 19:28:56 +0100 (Thu, 15 Jan 2009) | 2 lines Clean code : can_request doens't have a connx parameter ........ r2300 | danydb | 2009-01-16 19:12:47 +0100 (Fri, 16 Jan 2009) | 1 line Improve Ecriture directe libelle : new widget js_search_card_control ........ r2301 | danydb | 2009-01-16 22:29:39 +0100 (Fri, 16 Jan 2009) | 1 line Improve Quick Writing : remove span, and update the comment field ........ r2302 | danydb | 2009-01-16 23:01:24 +0100 (Fri, 16 Jan 2009) | 1 line Improve cosmetic : GL + remove the select topmenu ........ r2303 | danydb | 2009-01-19 08:41:09 +0100 (Mon, 19 Jan 2009) | 1 line Cosmetic : a inline ........ r2304 | danydb | 2009-01-20 23:03:59 +0100 (Tue, 20 Jan 2009) | 6 lines Code Cleaning Security : remove obsolete files & function Class_user : add new functions for the security Only the menu in text mode with a break line ........ r2305 | danydb | 2009-01-20 23:05:01 +0100 (Tue, 20 Jan 2009) | 1 line code cleaning rewriting of Security ........ r2306 | danydb | 2009-01-21 21:13:15 +0100 (Wed, 21 Jan 2009) | 1 line Security printing unicode and fix some bugs ........ r2309 | danydb | 2009-01-26 19:56:28 +0100 (Mon, 26 Jan 2009) | 1 line ADD : company without VAT ........ r2310 | danydb | 2009-01-26 23:33:14 +0100 (Mon, 26 Jan 2009) | 1 line Add : no vat for Purchase ledger ........ r2312 | danydb | 2009-01-28 19:57:30 +0100 (Wed, 28 Jan 2009) | 1 line Integration ........ r2313 | danydb | 2009-01-28 22:46:27 +0100 (Wed, 28 Jan 2009) | 1 line Work with or without VAT ........ r2314 | danydb | 2009-01-29 22:18:57 +0100 (Thu, 29 Jan 2009) | 2 lines Remove debug info ........ r2315 | danydb | 2009-01-29 23:23:14 +0100 (Thu, 29 Jan 2009) | 1 line ADD the possibility to enter a piece number ........ r2316 | danydb | 2009-01-31 23:20:00 +0100 (Sat, 31 Jan 2009) | 1 line Documentation ........ r2317 | danydb | 2009-02-04 20:14:54 +0100 (Wed, 04 Feb 2009) | 1 line Template for ledger ........ r2318 | danydb | 2009-02-05 15:52:58 +0100 (Thu, 05 Feb 2009) | 1 line Add PJ setting + default in Ledger, fix bug in listJrn ........ r2319 | danydb | 2009-02-05 17:09:56 +0100 (Thu, 05 Feb 2009) | 2 lines Search by PJ ........ r2320 | danydb | 2009-02-05 17:23:24 +0100 (Thu, 05 Feb 2009) | 1 line Finished with pj ........ r2321 | danydb | 2009-02-05 18:11:35 +0100 (Thu, 05 Feb 2009) | 1 line PJ is readonly ........ r2322 | danydb | 2009-02-05 20:10:34 +0100 (Thu, 05 Feb 2009) | 1 line Saldo : write the first saldo (ajax) ........ r2324 | danydb | 2009-02-06 00:07:50 +0100 (Fri, 06 Feb 2009) | 5 lines Add database script Cosmetic (menu) Fix Bug ........ r2325 | danydb | 2009-02-06 14:07:07 +0100 (Fri, 06 Feb 2009) | 1 line Improve Pj seq ........ r2326 | danydb | 2009-02-09 22:47:23 +0100 (Mon, 09 Feb 2009) | 6 lines Fix Bug privilege (compta_ven) Fix if the pj is empty do not increment the sequence (class_acc_operation) Fix remove PJ if pj is empty (modify_op.php) Cosmetic do not print PJ if pj is null or empty (listing) ........ r2327 | danydb | 2009-02-10 21:04:48 +0100 (Tue, 10 Feb 2009) | 5 lines Fix bug in PJ seq Fix bug in export jrn csv Improve avoid the removal of vat rate Add security for card ........ r2328 | danydb | 2009-02-12 20:26:36 +0100 (Thu, 12 Feb 2009) | 4 lines Cosmetic menu_tool Impression add tag PJ Cosmetic menu administration ........ r2329 | danydb | 2009-02-12 21:43:19 +0100 (Thu, 12 Feb 2009) | 5 lines filter the folder the local admin can access add a function check_dossier which must be implemented everywhere Printing with PJ NoAccess default = javascript ........ r2330 | danydb | 2009-02-14 18:11:49 +0100 (Sat, 14 Feb 2009) | 2 lines improve add libelle for balance csv ........ r2331 | danydb | 2009-02-14 19:10:56 +0100 (Sat, 14 Feb 2009) | 7 lines Balance csv add label Bug Financial ledger list BUG period access BUG stock access IMPROVE list ledger with PJ ........ r2332 | danydb | 2009-02-15 18:21:59 +0100 (Sun, 15 Feb 2009) | 1 line Bug order was not saved for report ........ r2333 | danydb | 2009-02-15 18:22:17 +0100 (Sun, 15 Feb 2009) | 1 line Add security for normal user ........ r2334 | danydb | 2009-02-15 18:23:24 +0100 (Sun, 15 Feb 2009) | 3 lines Bug forget to import class ........ r2335 | danydb | 2009-02-17 21:33:17 +0100 (Tue, 17 Feb 2009) | 5 lines Fix quick writing let write Fix card priv Remove button if no priv to add card or cancel an op ........ r2336 | danydb | 2009-02-19 21:01:36 +0100 (Thu, 19 Feb 2009) | 4 lines Check for CA common Bug with the repository ........ r2337 | danydb | 2009-02-19 21:50:35 +0100 (Thu, 19 Feb 2009) | 2 lines Test the parameter security part ........
238 lines
7.5 KiB
PHP
238 lines
7.5 KiB
PHP
<?php
|
|
/*
|
|
* This file is part of PhpCompta.
|
|
*
|
|
* PhpCompta is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* PhpCompta is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with PhpCompta; if not, write to the Free Software
|
|
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
|
*/
|
|
// Copyright Author Dany De Bontridder ddebontridder@yahoo.fr
|
|
|
|
/* $Revision$ */
|
|
|
|
/*! \file
|
|
* \brief Set the security for an user
|
|
*/
|
|
|
|
include_once ("ac_common.php");
|
|
include_once("check_priv.php");
|
|
require_once('class_dossier.php');
|
|
$gDossier=dossier::id();
|
|
$str_dossier=dossier::get();
|
|
|
|
include_once ("postgres.php");
|
|
/* Admin. Dossier */
|
|
$cn=DbConnect($gDossier);
|
|
include_once ("class_user.php");
|
|
$User=new User($cn);
|
|
$User->Check();
|
|
$User->check_dossier($gDossier);
|
|
|
|
include_once ("user_menu.php");
|
|
$cn_dossier=DbConnect($gDossier);
|
|
|
|
|
|
if ( $User->check_action(PARSEC) == 0 ) {
|
|
/* Cannot Access */
|
|
NoAccess();
|
|
exit -1;
|
|
}
|
|
|
|
$cn=DbConnect();
|
|
/* Show all the users, included local admin */
|
|
$user_sql=ExecSql($cn,"select use_id,use_first_name,use_name,use_login,use_admin,priv_priv from ac_users natural join jnt_use_dos ".
|
|
" join priv_user on (jnt_id=priv_jnt) where use_login != 'phpcompta' and dos_id=".$gDossier);
|
|
$MaxUser=pg_NumRows($user_sql);
|
|
|
|
echo '<DIV class="content" >';
|
|
|
|
echo '<TABLE CELLSPACING="20" ALIGN="CENTER">';
|
|
for ($i = 0;$i < $MaxUser;$i++) {
|
|
$l_line=pg_fetch_array($user_sql,$i);
|
|
// echo '<TR>';
|
|
if ( $i % 3 == 0 && $i != 0)
|
|
echo "</TR><TR>";
|
|
$str=($l_line['priv_priv'] == 'L')?'Local Admin':' Utilisateur normal';
|
|
if ( $l_line['use_admin'] == 1 )
|
|
$str=' Super Admin';
|
|
|
|
printf ('<TD><A href="?p_action=sec&action=view&user_id=%s&'.$str_dossier.'">%s %s ( %s )[%s]</A></TD>',
|
|
$l_line['use_id'],
|
|
$l_line['use_first_name'],
|
|
$l_line['use_name'],
|
|
$l_line['use_login'],
|
|
$str);
|
|
|
|
}
|
|
echo "</TR>";
|
|
echo '</TABLE>';
|
|
$action="";
|
|
|
|
if ( isset ($_GET["action"] )) {
|
|
$action=$_GET["action"];
|
|
|
|
}
|
|
//----------------------------------------------------------------------
|
|
// Action = save
|
|
//----------------------------------------------------------------------
|
|
if ( isset($_POST['ok'])) {
|
|
|
|
$sec_User=new User($cn_dossier,$_POST['user_id']);
|
|
/* Save first the ledger */
|
|
$cn_dossier=DbConnect(dossier::id());
|
|
$a=get_array($cn_dossier,'select jrn_def_id from jrn_def');
|
|
foreach ($a as $key) {
|
|
$id=$key['jrn_def_id'];
|
|
$priv=sprintf("jrn_act%d",$id);
|
|
$count=getDbValue($cn_dossier,'select count(*) from user_sec_jrn where uj_login=$1 '.
|
|
' and uj_jrn_id=$2',array($sec_User->login,$id));
|
|
if ( $count == 0 )
|
|
{
|
|
ExecSqlParam($cn_dossier,'insert into user_sec_jrn (uj_login,uj_jrn_id,uj_priv)'.
|
|
' values ($1,$2,$3)',
|
|
array($sec_User->login,$id,$_POST[$priv]));
|
|
|
|
} else {
|
|
ExecSqlParam($cn_dossier,'update user_sec_jrn set uj_priv=$1 where uj_login=$2 and uj_jrn_id=$3',
|
|
array($_POST[$priv],$sec_User->login,$id));
|
|
}
|
|
}
|
|
/* now save all the actions */
|
|
$a=get_array($cn_dossier,'select ac_id from action');
|
|
|
|
foreach ($a as $key) {
|
|
$id=$key['ac_id'];
|
|
$priv=sprintf("action%d",$id);
|
|
$count=getDbValue($cn_dossier,'select count(*) from user_sec_act where ua_login=$1 '.
|
|
' and ua_act_id=$2',array($sec_User->login,$id));
|
|
if ( $_POST[$priv] == 1 && $count == 0)
|
|
{
|
|
ExecSqlParam($cn_dossier,'insert into user_sec_act (ua_login,ua_act_id)'.
|
|
' values ($1,$2)',
|
|
array($sec_User->login,$id));
|
|
|
|
}
|
|
if ($_POST[$priv] == 0 ){
|
|
ExecSqlParam($cn_dossier,'delete from user_sec_act where ua_login=$1 and ua_act_id=$2',
|
|
array($sec_User->login,$id));
|
|
}
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
//--------------------------------------------------------------------------------
|
|
// Action == View detail for users
|
|
//--------------------------------------------------------------------------------
|
|
|
|
if ( $action == "view" ) {
|
|
$l_Db=sprintf("dossier%d",$gDossier);
|
|
|
|
$cn=DbConnect();
|
|
$User=ExecSqlParam($cn,
|
|
"select use_id,use_first_name,use_name,use_login,use_admin,priv_priv from ac_users natural join jnt_use_dos ".
|
|
" join priv_user on (jnt_id=priv_jnt) where use_login != 'phpcompta' and dos_id=$1 and use_id=$2",
|
|
array($gDossier,$_GET['user_id']));
|
|
|
|
$MaxUser=pg_NumRows($User);
|
|
if ( $MaxUser == 0 ) return;
|
|
$l2_line=pg_fetch_array($User,0);
|
|
|
|
$admin=0;
|
|
if ( $l2_line['priv_priv'] == 'L') {
|
|
$str='Local Admin';$admin=1;
|
|
} else {
|
|
$str=' Utilisateur normal';}
|
|
if ( $l2_line['use_admin'] == 1 ) {
|
|
$str=' Super Admin';$admin=1;
|
|
}
|
|
|
|
if ( $admin != 0 ) {
|
|
echo '<h2 class="info"> Cet utilisateur est administrateur, il a tous les droits</h2>';
|
|
exit();
|
|
}
|
|
//
|
|
// Check if the user can access that folder
|
|
if ( CheckDossier($l2_line['use_login'],$gDossier) == 0 ) {
|
|
echo "<H2 class=\"error\">L'utilisateur n'a pas accès à ce dossier</H2>";
|
|
$action="";
|
|
return;
|
|
}
|
|
|
|
//--------------------------------------------------------------------------------
|
|
// Show access for journal
|
|
//--------------------------------------------------------------------------------
|
|
|
|
$Res=ExecSql($cn_dossier,"select jrn_def_id,jrn_def_name from jrn_def ".
|
|
" order by jrn_def_name");
|
|
$sec_User=new User($cn_dossier,$_GET['user_id']);
|
|
|
|
echo '<form method="post">';
|
|
$sHref=sprintf ('sec_pdf.php?p_action=sec&user_id=%s&'.$str_dossier ,
|
|
$_GET ['user_id']
|
|
);
|
|
|
|
echo widget::button('Imprime','imprime',"onclick=\"window.open('".$sHref."');\"");
|
|
echo widget::submit('ok','Sauve');
|
|
echo widget::reset('Annule');
|
|
echo dossier::hidden();
|
|
echo widget::hidden('action','sec');
|
|
echo widget::hidden('user_id',$_GET['user_id']);
|
|
|
|
echo '<Fieldset><legend>Journaux </legend>';
|
|
echo '<table align="CENTER" width="100%">';
|
|
$MaxJrn=pg_NumRows($Res);
|
|
$jrn_priv=new widget ('select');
|
|
$array=array(
|
|
array ('value'=>'R','label'=>'Uniquement lecture'),
|
|
array ('value'=>'W','label'=>'Lecture et écriture'),
|
|
// array ('value'=>'O','label'=>'Uniquement opérations prédéfinies'),
|
|
array ('value'=>'X','label'=>'Aucun accès')
|
|
);
|
|
|
|
for ( $i =0 ; $i < $MaxJrn; $i++ ) {
|
|
/* set the widget */
|
|
$l_line=pg_fetch_array($Res,$i);
|
|
|
|
echo '<TR> ';
|
|
if ( $i == 0 ) echo '<TD> <B> Journal </B> </TD>';else echo "<TD></TD>";
|
|
echo "<TD> $l_line[jrn_def_name] </TD>";
|
|
|
|
$jrn_priv->name='jrn_act'.$l_line['jrn_def_id'];
|
|
$jrn_priv->value=$array;
|
|
$jrn_priv->selected=$sec_User->get_ledger_access($l_line['jrn_def_id']);
|
|
|
|
echo '<td>';
|
|
echo $jrn_priv->IOValue();
|
|
echo '</td>';
|
|
echo '</tr>';
|
|
}
|
|
echo '</table>';
|
|
echo '</fieldset>';
|
|
|
|
//**********************************************************************
|
|
// Show Priv. for actions
|
|
//**********************************************************************
|
|
echo '<fieldset> <legend>Actions </legend>';
|
|
include('template/security_list_action.php');
|
|
echo '</fieldset>';
|
|
echo widget::button('Imprime','imprime',"onclick=\"window.open('".$sHref."');\"");
|
|
echo widget::submit('ok','Sauve');
|
|
echo widget::reset('Annule');
|
|
echo '</form>';
|
|
} // end of the form
|
|
echo "</DIV>";
|
|
html_page_stop();
|
|
?>
|