Test Setup Failed
Push — dependabot/composer/squizlabs/... ( bb2d99 )
by
unknown
12:41
created
includes/Pages/RequestAction/PageBreakReservation.php 2 patches
Indentation   +65 added lines, -65 removed lines patch added patch discarded remove patch
@@ -19,81 +19,81 @@
 block discarded – undo
19 19
 
20 20
 class PageBreakReservation extends RequestActionBase
21 21
 {
22
-    protected function main()
23
-    {
24
-        $this->checkPosted();
25
-        $database = $this->getDatabase();
26
-        $request = $this->getRequest($database);
22
+	protected function main()
23
+	{
24
+		$this->checkPosted();
25
+		$database = $this->getDatabase();
26
+		$request = $this->getRequest($database);
27 27
 
28
-        if ($request->getReserved() === null) {
29
-            throw new ApplicationLogicException('Request is not reserved!');
30
-        }
28
+		if ($request->getReserved() === null) {
29
+			throw new ApplicationLogicException('Request is not reserved!');
30
+		}
31 31
 
32
-        $currentUser = User::getCurrent($database);
32
+		$currentUser = User::getCurrent($database);
33 33
 
34
-        if ($currentUser->getId() === $request->getReserved()) {
35
-            $this->doUnreserve($request, $database);
36
-        }
37
-        else {
38
-            // not the same user!
39
-            if ($this->barrierTest('force', $currentUser)) {
40
-                $this->doBreakReserve($request, $database);
41
-            }
42
-            else {
43
-                throw new AccessDeniedException($this->getSecurityManager());
44
-            }
45
-        }
46
-    }
34
+		if ($currentUser->getId() === $request->getReserved()) {
35
+			$this->doUnreserve($request, $database);
36
+		}
37
+		else {
38
+			// not the same user!
39
+			if ($this->barrierTest('force', $currentUser)) {
40
+				$this->doBreakReserve($request, $database);
41
+			}
42
+			else {
43
+				throw new AccessDeniedException($this->getSecurityManager());
44
+			}
45
+		}
46
+	}
47 47
 
48
-    /**
49
-     * @param Request     $request
50
-     * @param PdoDatabase $database
51
-     *
52
-     * @throws Exception
53
-     */
54
-    protected function doUnreserve(Request $request, PdoDatabase $database)
55
-    {
56
-        // same user! we allow people to unreserve their own stuff
57
-        $request->setReserved(null);
58
-        $request->setUpdateVersion(WebRequest::postInt('updateversion'));
59
-        $request->save();
48
+	/**
49
+	 * @param Request     $request
50
+	 * @param PdoDatabase $database
51
+	 *
52
+	 * @throws Exception
53
+	 */
54
+	protected function doUnreserve(Request $request, PdoDatabase $database)
55
+	{
56
+		// same user! we allow people to unreserve their own stuff
57
+		$request->setReserved(null);
58
+		$request->setUpdateVersion(WebRequest::postInt('updateversion'));
59
+		$request->save();
60 60
 
61
-        Logger::unreserve($database, $request);
62
-        $this->getNotificationHelper()->requestUnreserved($request);
61
+		Logger::unreserve($database, $request);
62
+		$this->getNotificationHelper()->requestUnreserved($request);
63 63
 
64
-        // Redirect home!
65
-        $this->redirect();
66
-    }
64
+		// Redirect home!
65
+		$this->redirect();
66
+	}
67 67
 
68
-    /**
69
-     * @param Request     $request
70
-     * @param PdoDatabase $database
71
-     *
72
-     * @throws Exception
73
-     */
74
-    protected function doBreakReserve(Request $request, PdoDatabase $database)
75
-    {
76
-        if (!WebRequest::postBoolean("confirm")) {
77
-            $this->assignCSRFToken();
68
+	/**
69
+	 * @param Request     $request
70
+	 * @param PdoDatabase $database
71
+	 *
72
+	 * @throws Exception
73
+	 */
74
+	protected function doBreakReserve(Request $request, PdoDatabase $database)
75
+	{
76
+		if (!WebRequest::postBoolean("confirm")) {
77
+			$this->assignCSRFToken();
78 78
 
79
-            $this->assign("request", $request->getId());
80
-            $this->assign("reservedUser", User::getById($request->getReserved(), $database));
81
-            $this->assign("updateversion", WebRequest::postInt('updateversion'));
79
+			$this->assign("request", $request->getId());
80
+			$this->assign("reservedUser", User::getById($request->getReserved(), $database));
81
+			$this->assign("updateversion", WebRequest::postInt('updateversion'));
82 82
 
83
-            $this->skipAlerts();
83
+			$this->skipAlerts();
84 84
 
85
-            $this->setTemplate("confirmations/breakreserve.tpl");
86
-        }
87
-        else {
88
-            $request->setReserved(null);
89
-            $request->setUpdateVersion(WebRequest::postInt('updateversion'));
90
-            $request->save();
85
+			$this->setTemplate("confirmations/breakreserve.tpl");
86
+		}
87
+		else {
88
+			$request->setReserved(null);
89
+			$request->setUpdateVersion(WebRequest::postInt('updateversion'));
90
+			$request->save();
91 91
 
92
-            Logger::breakReserve($database, $request);
93
-            $this->getNotificationHelper()->requestReserveBroken($request);
92
+			Logger::breakReserve($database, $request);
93
+			$this->getNotificationHelper()->requestReserveBroken($request);
94 94
 
95
-            // Redirect home!
96
-            $this->redirect();
97
-        }
98
-    }
95
+			// Redirect home!
96
+			$this->redirect();
97
+		}
98
+	}
99 99
 }
Please login to merge, or discard this patch.
Braces   +3 added lines, -6 removed lines patch added patch discarded remove patch
@@ -33,13 +33,11 @@  discard block
 block discarded – undo
33 33
 
34 34
         if ($currentUser->getId() === $request->getReserved()) {
35 35
             $this->doUnreserve($request, $database);
36
-        }
37
-        else {
36
+        } else {
38 37
             // not the same user!
39 38
             if ($this->barrierTest('force', $currentUser)) {
40 39
                 $this->doBreakReserve($request, $database);
41
-            }
42
-            else {
40
+            } else {
43 41
                 throw new AccessDeniedException($this->getSecurityManager());
44 42
             }
45 43
         }
@@ -83,8 +81,7 @@  discard block
 block discarded – undo
83 81
             $this->skipAlerts();
84 82
 
85 83
             $this->setTemplate("confirmations/breakreserve.tpl");
86
-        }
87
-        else {
84
+        } else {
88 85
             $request->setReserved(null);
89 86
             $request->setUpdateVersion(WebRequest::postInt('updateversion'));
90 87
             $request->save();
Please login to merge, or discard this patch.
includes/Pages/RequestAction/RequestActionBase.php 1 patch
Indentation   +44 added lines, -44 removed lines patch added patch discarded remove patch
@@ -19,54 +19,54 @@
 block discarded – undo
19 19
 
20 20
 abstract class RequestActionBase extends InternalPageBase
21 21
 {
22
-    /**
23
-     * @param PdoDatabase $database
24
-     *
25
-     * @return Request
26
-     * @throws ApplicationLogicException
27
-     */
28
-    protected function getRequest(PdoDatabase $database)
29
-    {
30
-        $requestId = WebRequest::postInt('request');
31
-        if ($requestId === null) {
32
-            throw new ApplicationLogicException('Request ID not found');
33
-        }
22
+	/**
23
+	 * @param PdoDatabase $database
24
+	 *
25
+	 * @return Request
26
+	 * @throws ApplicationLogicException
27
+	 */
28
+	protected function getRequest(PdoDatabase $database)
29
+	{
30
+		$requestId = WebRequest::postInt('request');
31
+		if ($requestId === null) {
32
+			throw new ApplicationLogicException('Request ID not found');
33
+		}
34 34
 
35
-        /** @var Request $request */
36
-        $request = Request::getById($requestId, $database);
35
+		/** @var Request $request */
36
+		$request = Request::getById($requestId, $database);
37 37
 
38
-        if ($request === false) {
39
-            throw new ApplicationLogicException('Request not found');
40
-        }
38
+		if ($request === false) {
39
+			throw new ApplicationLogicException('Request not found');
40
+		}
41 41
 
42
-        return $request;
43
-    }
42
+		return $request;
43
+	}
44 44
 
45
-    final protected function checkPosted()
46
-    {
47
-        // if the request was not posted, send the user away.
48
-        if (!WebRequest::wasPosted()) {
49
-            throw new ApplicationLogicException('This page does not support GET methods.');
50
-        }
45
+	final protected function checkPosted()
46
+	{
47
+		// if the request was not posted, send the user away.
48
+		if (!WebRequest::wasPosted()) {
49
+			throw new ApplicationLogicException('This page does not support GET methods.');
50
+		}
51 51
 
52
-        // validate the CSRF token
53
-        $this->validateCSRFToken();
54
-    }
52
+		// validate the CSRF token
53
+		$this->validateCSRFToken();
54
+	}
55 55
 
56
-    /**
57
-     * @param Request     $request
58
-     * @param             $parentTaskId
59
-     * @param User        $user
60
-     * @param PdoDatabase $database
61
-     */
62
-    protected function enqueueWelcomeTask(Request $request, $parentTaskId, User $user, PdoDatabase $database)
63
-    {
64
-        $welcomeTask = new JobQueue();
65
-        $welcomeTask->setTask(WelcomeUserTask::class);
66
-        $welcomeTask->setRequest($request->getId());
67
-        $welcomeTask->setParent($parentTaskId);
68
-        $welcomeTask->setTriggerUserId($user->getId());
69
-        $welcomeTask->setDatabase($database);
70
-        $welcomeTask->save();
71
-    }
56
+	/**
57
+	 * @param Request     $request
58
+	 * @param             $parentTaskId
59
+	 * @param User        $user
60
+	 * @param PdoDatabase $database
61
+	 */
62
+	protected function enqueueWelcomeTask(Request $request, $parentTaskId, User $user, PdoDatabase $database)
63
+	{
64
+		$welcomeTask = new JobQueue();
65
+		$welcomeTask->setTask(WelcomeUserTask::class);
66
+		$welcomeTask->setRequest($request->getId());
67
+		$welcomeTask->setParent($parentTaskId);
68
+		$welcomeTask->setTriggerUserId($user->getId());
69
+		$welcomeTask->setDatabase($database);
70
+		$welcomeTask->save();
71
+	}
72 72
 }
73 73
\ No newline at end of file
Please login to merge, or discard this patch.
includes/Pages/RequestAction/PageComment.php 1 patch
Indentation   +37 added lines, -37 removed lines patch added patch discarded remove patch
@@ -15,52 +15,52 @@
 block discarded – undo
15 15
 
16 16
 class PageComment extends RequestActionBase
17 17
 {
18
-    /**
19
-     * Main function for this page, when no specific actions are called.
20
-     * @return void
21
-     */
22
-    protected function main()
23
-    {
24
-        $this->checkPosted();
25
-        $database = $this->getDatabase();
26
-        $request = $this->getRequest($database);
18
+	/**
19
+	 * Main function for this page, when no specific actions are called.
20
+	 * @return void
21
+	 */
22
+	protected function main()
23
+	{
24
+		$this->checkPosted();
25
+		$database = $this->getDatabase();
26
+		$request = $this->getRequest($database);
27 27
 
28
-        $commentText = WebRequest::postString('comment');
29
-        if ($commentText === false || $commentText == '') {
30
-            $this->redirect('viewRequest', null, array('id' => $request->getId()));
28
+		$commentText = WebRequest::postString('comment');
29
+		if ($commentText === false || $commentText == '') {
30
+			$this->redirect('viewRequest', null, array('id' => $request->getId()));
31 31
 
32
-            return;
33
-        }
32
+			return;
33
+		}
34 34
 
35
-        //Look for and detect IPv4/IPv6 addresses in comment text, and warn the commenter.
36
-        $ipv4Regex = '/\b' . RegexConstants::IPV4 . '\b/';
37
-        $ipv6Regex = '/\b' . RegexConstants::IPV6 . '\b/';
35
+		//Look for and detect IPv4/IPv6 addresses in comment text, and warn the commenter.
36
+		$ipv4Regex = '/\b' . RegexConstants::IPV4 . '\b/';
37
+		$ipv6Regex = '/\b' . RegexConstants::IPV6 . '\b/';
38 38
 
39
-        $overridePolicy = WebRequest::postBoolean('privpol-check-override');
39
+		$overridePolicy = WebRequest::postBoolean('privpol-check-override');
40 40
 
41
-        if ((preg_match($ipv4Regex, $commentText) || preg_match($ipv6Regex, $commentText)) && !$overridePolicy) {
42
-            $this->assignCSRFToken();
43
-            $this->assign("request", $request);
44
-            $this->assign("comment", $commentText);
45
-            $this->skipAlerts();
46
-            $this->setTemplate("privpol-warning.tpl");
41
+		if ((preg_match($ipv4Regex, $commentText) || preg_match($ipv6Regex, $commentText)) && !$overridePolicy) {
42
+			$this->assignCSRFToken();
43
+			$this->assign("request", $request);
44
+			$this->assign("comment", $commentText);
45
+			$this->skipAlerts();
46
+			$this->setTemplate("privpol-warning.tpl");
47 47
 
48
-            return;
49
-        }
48
+			return;
49
+		}
50 50
 
51
-        $visibility = WebRequest::postBoolean('adminOnly') ? 'admin' : 'user';
51
+		$visibility = WebRequest::postBoolean('adminOnly') ? 'admin' : 'user';
52 52
 
53
-        $comment = new Comment();
54
-        $comment->setDatabase($database);
53
+		$comment = new Comment();
54
+		$comment->setDatabase($database);
55 55
 
56
-        $comment->setRequest($request->getId());
57
-        $comment->setVisibility($visibility);
58
-        $comment->setUser(User::getCurrent($database)->getId());
59
-        $comment->setComment($commentText);
56
+		$comment->setRequest($request->getId());
57
+		$comment->setVisibility($visibility);
58
+		$comment->setUser(User::getCurrent($database)->getId());
59
+		$comment->setComment($commentText);
60 60
 
61
-        $comment->save();
61
+		$comment->save();
62 62
 
63
-        $this->getNotificationHelper()->commentCreated($comment, $request);
64
-        $this->redirect('viewRequest', null, array('id' => $request->getId()));
65
-    }
63
+		$this->getNotificationHelper()->commentCreated($comment, $request);
64
+		$this->redirect('viewRequest', null, array('id' => $request->getId()));
65
+	}
66 66
 }
Please login to merge, or discard this patch.
includes/Pages/RequestAction/PageDropRequest.php 1 patch
Indentation   +15 added lines, -15 removed lines patch added patch discarded remove patch
@@ -15,22 +15,22 @@
 block discarded – undo
15 15
 
16 16
 class PageDropRequest extends PageCloseRequest
17 17
 {
18
-    protected function getTemplate(PdoDatabase $database)
19
-    {
20
-        return EmailTemplate::getDroppedTemplate();
21
-    }
18
+	protected function getTemplate(PdoDatabase $database)
19
+	{
20
+		return EmailTemplate::getDroppedTemplate();
21
+	}
22 22
 
23
-    protected function confirmEmailAlreadySent(Request $request, EmailTemplate $template)
24
-    {
25
-        return false;
26
-    }
23
+	protected function confirmEmailAlreadySent(Request $request, EmailTemplate $template)
24
+	{
25
+		return false;
26
+	}
27 27
 
28
-    protected function confirmAccountCreated(Request $request, EmailTemplate $template)
29
-    {
30
-        return false;
31
-    }
28
+	protected function confirmAccountCreated(Request $request, EmailTemplate $template)
29
+	{
30
+		return false;
31
+	}
32 32
 
33
-    protected function sendMail(Request $request, $mailText, User $currentUser, $ccMailingList)
34
-    {
35
-    }
33
+	protected function sendMail(Request $request, $mailText, User $currentUser, $ccMailingList)
34
+	{
35
+	}
36 36
 }
37 37
\ No newline at end of file
Please login to merge, or discard this patch.
includes/Pages/RequestAction/PageCloseRequest.php 2 patches
Indentation   +227 added lines, -227 removed lines patch added patch discarded remove patch
@@ -21,231 +21,231 @@
 block discarded – undo
21 21
 
22 22
 class PageCloseRequest extends RequestActionBase
23 23
 {
24
-    protected function main()
25
-    {
26
-        $this->processClose();
27
-    }
28
-
29
-    /**
30
-     * Main function for this page, when no specific actions are called.
31
-     * @throws ApplicationLogicException
32
-     */
33
-    final protected function processClose()
34
-    {
35
-        $this->checkPosted();
36
-        $database = $this->getDatabase();
37
-
38
-        $currentUser = User::getCurrent($database);
39
-        $template = $this->getTemplate($database);
40
-        $request = $this->getRequest($database);
41
-        $request->setUpdateVersion(WebRequest::postInt('updateversion'));
42
-
43
-        if ($request->getStatus() === 'Closed') {
44
-            throw new ApplicationLogicException('Request is already closed');
45
-        }
46
-
47
-        if ($this->confirmEmailAlreadySent($request, $template)) {
48
-            return;
49
-        }
50
-
51
-        if ($this->checkReserveProtect($request, $currentUser)) {
52
-            return;
53
-        }
54
-
55
-        if ($this->confirmAccountCreated($request, $template)) {
56
-            return;
57
-        }
58
-
59
-        // I think we're good here...
60
-        $request->setStatus('Closed');
61
-        $request->setReserved(null);
62
-
63
-        Logger::closeRequest($database, $request, $template->getId(), null);
64
-
65
-        $request->save();
66
-
67
-        $this->processWelcome($template->getDefaultAction());
68
-
69
-        // Perform the notifications and stuff *after* we've successfully saved, since the save can throw an OLE and
70
-        // be rolled back.
71
-
72
-        $this->getNotificationHelper()->requestClosed($request, $template->getName());
73
-        $sanitisedTemplateName = htmlentities($template->getName(), ENT_COMPAT, 'UTF-8');
74
-        SessionAlert::success("Request {$request->getId()} has been closed as {$sanitisedTemplateName}");
75
-
76
-        $this->sendMail($request, $template->getText(), $currentUser, false);
77
-
78
-        $this->redirect();
79
-    }
80
-
81
-    /**
82
-     * @param PdoDatabase $database
83
-     *
84
-     * @return EmailTemplate
85
-     * @throws ApplicationLogicException
86
-     */
87
-    protected function getTemplate(PdoDatabase $database)
88
-    {
89
-        $templateId = WebRequest::postInt('template');
90
-        if ($templateId === null) {
91
-            throw new ApplicationLogicException('No template specified');
92
-        }
93
-
94
-        /** @var EmailTemplate $template */
95
-        $template = EmailTemplate::getById($templateId, $database);
96
-        if ($template === false || !$template->getActive()) {
97
-            throw new ApplicationLogicException('Invalid or inactive template specified');
98
-        }
99
-
100
-        return $template;
101
-    }
102
-
103
-    /**
104
-     * @param Request       $request
105
-     * @param EmailTemplate $template
106
-     *
107
-     * @return bool
108
-     */
109
-    protected function confirmEmailAlreadySent(Request $request, EmailTemplate $template)
110
-    {
111
-        if ($this->checkEmailAlreadySent($request)) {
112
-            $this->showConfirmation($request, $template, 'close-confirmations/email-sent.tpl');
113
-
114
-            return true;
115
-        }
116
-
117
-        return false;
118
-    }
119
-
120
-    protected function checkEmailAlreadySent(Request $request)
121
-    {
122
-        if ($request->getEmailSent() && !WebRequest::postBoolean('emailSentOverride')) {
123
-            return true;
124
-        }
125
-
126
-        return false;
127
-    }
128
-
129
-    protected function checkReserveProtect(Request $request, User $currentUser)
130
-    {
131
-        $reservationId = $request->getReserved();
132
-
133
-        if ($reservationId !== 0 && $reservationId !== null) {
134
-            if ($currentUser->getId() !== $reservationId) {
135
-                SessionAlert::error("Request is reserved by someone else.");
136
-                $this->redirect('/viewRequest', null, ['id' => $request->getId()] );
137
-                return true;
138
-            }
139
-        }
140
-
141
-        return false;
142
-    }
143
-
144
-    /**
145
-     * @param Request       $request
146
-     * @param EmailTemplate $template
147
-     *
148
-     * @return bool
149
-     * @throws Exception
150
-     */
151
-    protected function confirmAccountCreated(Request $request, EmailTemplate $template)
152
-    {
153
-        if ($this->checkAccountCreated($request, $template)) {
154
-            $this->showConfirmation($request, $template, 'close-confirmations/account-created.tpl');
155
-
156
-            return true;
157
-        }
158
-
159
-        return false;
160
-    }
161
-
162
-    protected function checkAccountCreated(Request $request, EmailTemplate $template)
163
-    {
164
-        if ($template->getDefaultAction() === EmailTemplate::CREATED && !WebRequest::postBoolean('createOverride')) {
165
-            $parameters = array(
166
-                'action'  => 'query',
167
-                'list'    => 'users',
168
-                'format'  => 'php',
169
-                'ususers' => $request->getName(),
170
-            );
171
-
172
-            $content = $this->getHttpHelper()->get($this->getSiteConfiguration()->getMediawikiWebServiceEndpoint(),
173
-                $parameters);
174
-
175
-            $apiResult = unserialize($content);
176
-            $exists = !isset($apiResult['query']['users']['0']['missing']);
177
-
178
-            if (!$exists) {
179
-                return true;
180
-            }
181
-        }
182
-
183
-        return false;
184
-    }
185
-
186
-    /**
187
-     * @param Request $request
188
-     * @param string  $mailText
189
-     * @param User    $currentUser
190
-     * @param boolean $ccMailingList
191
-     */
192
-    protected function sendMail(Request $request, $mailText, User $currentUser, $ccMailingList)
193
-    {
194
-        $requestEmailHelper = new RequestEmailHelper($this->getEmailHelper());
195
-        $requestEmailHelper->sendMail($request, $mailText, $currentUser, $ccMailingList);
196
-
197
-        $request->setEmailSent(true);
198
-        $request->save();
199
-    }
200
-
201
-    /**
202
-     * @param Request       $request
203
-     * @param EmailTemplate $template
204
-     * @param string        $templateName
205
-     *
206
-     * @throws Exception
207
-     * @return void
208
-     */
209
-    protected function showConfirmation(Request $request, EmailTemplate $template, $templateName)
210
-    {
211
-        $this->assignCSRFToken();
212
-
213
-        $this->assign('request', $request->getId());
214
-        $this->assign('template', $template->getId());
215
-
216
-        $this->assign('updateversion', $request->getUpdateVersion());
217
-
218
-        $this->assign('emailSentOverride', WebRequest::postBoolean('emailSentOverride') ? 'true' : 'false');
219
-        $this->assign('reserveOverride', WebRequest::postBoolean('reserveOverride') ? 'true' : 'false');
220
-        $this->assign('createOverride', WebRequest::postBoolean('createOverride') ? 'true' : 'false');
221
-
222
-        $this->skipAlerts();
223
-
224
-        $this->setTemplate($templateName);
225
-    }
226
-
227
-    /**
228
-     * @param string $action
229
-     *
230
-     * @throws ApplicationLogicException
231
-     */
232
-    final protected function processWelcome(string $action): void
233
-    {
234
-        $database = $this->getDatabase();
235
-        $currentUser = User::getCurrent($database);
236
-
237
-        if ($action !== EmailTemplate::CREATED) {
238
-            return;
239
-        }
240
-
241
-        if ($currentUser->getWelcomeTemplate() === null) {
242
-            return;
243
-        }
244
-
245
-        if (WebRequest::postBoolean('skipAutoWelcome')) {
246
-            return;
247
-        }
248
-
249
-        $this->enqueueWelcomeTask($this->getRequest($database), null, $currentUser, $database);
250
-    }
24
+	protected function main()
25
+	{
26
+		$this->processClose();
27
+	}
28
+
29
+	/**
30
+	 * Main function for this page, when no specific actions are called.
31
+	 * @throws ApplicationLogicException
32
+	 */
33
+	final protected function processClose()
34
+	{
35
+		$this->checkPosted();
36
+		$database = $this->getDatabase();
37
+
38
+		$currentUser = User::getCurrent($database);
39
+		$template = $this->getTemplate($database);
40
+		$request = $this->getRequest($database);
41
+		$request->setUpdateVersion(WebRequest::postInt('updateversion'));
42
+
43
+		if ($request->getStatus() === 'Closed') {
44
+			throw new ApplicationLogicException('Request is already closed');
45
+		}
46
+
47
+		if ($this->confirmEmailAlreadySent($request, $template)) {
48
+			return;
49
+		}
50
+
51
+		if ($this->checkReserveProtect($request, $currentUser)) {
52
+			return;
53
+		}
54
+
55
+		if ($this->confirmAccountCreated($request, $template)) {
56
+			return;
57
+		}
58
+
59
+		// I think we're good here...
60
+		$request->setStatus('Closed');
61
+		$request->setReserved(null);
62
+
63
+		Logger::closeRequest($database, $request, $template->getId(), null);
64
+
65
+		$request->save();
66
+
67
+		$this->processWelcome($template->getDefaultAction());
68
+
69
+		// Perform the notifications and stuff *after* we've successfully saved, since the save can throw an OLE and
70
+		// be rolled back.
71
+
72
+		$this->getNotificationHelper()->requestClosed($request, $template->getName());
73
+		$sanitisedTemplateName = htmlentities($template->getName(), ENT_COMPAT, 'UTF-8');
74
+		SessionAlert::success("Request {$request->getId()} has been closed as {$sanitisedTemplateName}");
75
+
76
+		$this->sendMail($request, $template->getText(), $currentUser, false);
77
+
78
+		$this->redirect();
79
+	}
80
+
81
+	/**
82
+	 * @param PdoDatabase $database
83
+	 *
84
+	 * @return EmailTemplate
85
+	 * @throws ApplicationLogicException
86
+	 */
87
+	protected function getTemplate(PdoDatabase $database)
88
+	{
89
+		$templateId = WebRequest::postInt('template');
90
+		if ($templateId === null) {
91
+			throw new ApplicationLogicException('No template specified');
92
+		}
93
+
94
+		/** @var EmailTemplate $template */
95
+		$template = EmailTemplate::getById($templateId, $database);
96
+		if ($template === false || !$template->getActive()) {
97
+			throw new ApplicationLogicException('Invalid or inactive template specified');
98
+		}
99
+
100
+		return $template;
101
+	}
102
+
103
+	/**
104
+	 * @param Request       $request
105
+	 * @param EmailTemplate $template
106
+	 *
107
+	 * @return bool
108
+	 */
109
+	protected function confirmEmailAlreadySent(Request $request, EmailTemplate $template)
110
+	{
111
+		if ($this->checkEmailAlreadySent($request)) {
112
+			$this->showConfirmation($request, $template, 'close-confirmations/email-sent.tpl');
113
+
114
+			return true;
115
+		}
116
+
117
+		return false;
118
+	}
119
+
120
+	protected function checkEmailAlreadySent(Request $request)
121
+	{
122
+		if ($request->getEmailSent() && !WebRequest::postBoolean('emailSentOverride')) {
123
+			return true;
124
+		}
125
+
126
+		return false;
127
+	}
128
+
129
+	protected function checkReserveProtect(Request $request, User $currentUser)
130
+	{
131
+		$reservationId = $request->getReserved();
132
+
133
+		if ($reservationId !== 0 && $reservationId !== null) {
134
+			if ($currentUser->getId() !== $reservationId) {
135
+				SessionAlert::error("Request is reserved by someone else.");
136
+				$this->redirect('/viewRequest', null, ['id' => $request->getId()] );
137
+				return true;
138
+			}
139
+		}
140
+
141
+		return false;
142
+	}
143
+
144
+	/**
145
+	 * @param Request       $request
146
+	 * @param EmailTemplate $template
147
+	 *
148
+	 * @return bool
149
+	 * @throws Exception
150
+	 */
151
+	protected function confirmAccountCreated(Request $request, EmailTemplate $template)
152
+	{
153
+		if ($this->checkAccountCreated($request, $template)) {
154
+			$this->showConfirmation($request, $template, 'close-confirmations/account-created.tpl');
155
+
156
+			return true;
157
+		}
158
+
159
+		return false;
160
+	}
161
+
162
+	protected function checkAccountCreated(Request $request, EmailTemplate $template)
163
+	{
164
+		if ($template->getDefaultAction() === EmailTemplate::CREATED && !WebRequest::postBoolean('createOverride')) {
165
+			$parameters = array(
166
+				'action'  => 'query',
167
+				'list'    => 'users',
168
+				'format'  => 'php',
169
+				'ususers' => $request->getName(),
170
+			);
171
+
172
+			$content = $this->getHttpHelper()->get($this->getSiteConfiguration()->getMediawikiWebServiceEndpoint(),
173
+				$parameters);
174
+
175
+			$apiResult = unserialize($content);
176
+			$exists = !isset($apiResult['query']['users']['0']['missing']);
177
+
178
+			if (!$exists) {
179
+				return true;
180
+			}
181
+		}
182
+
183
+		return false;
184
+	}
185
+
186
+	/**
187
+	 * @param Request $request
188
+	 * @param string  $mailText
189
+	 * @param User    $currentUser
190
+	 * @param boolean $ccMailingList
191
+	 */
192
+	protected function sendMail(Request $request, $mailText, User $currentUser, $ccMailingList)
193
+	{
194
+		$requestEmailHelper = new RequestEmailHelper($this->getEmailHelper());
195
+		$requestEmailHelper->sendMail($request, $mailText, $currentUser, $ccMailingList);
196
+
197
+		$request->setEmailSent(true);
198
+		$request->save();
199
+	}
200
+
201
+	/**
202
+	 * @param Request       $request
203
+	 * @param EmailTemplate $template
204
+	 * @param string        $templateName
205
+	 *
206
+	 * @throws Exception
207
+	 * @return void
208
+	 */
209
+	protected function showConfirmation(Request $request, EmailTemplate $template, $templateName)
210
+	{
211
+		$this->assignCSRFToken();
212
+
213
+		$this->assign('request', $request->getId());
214
+		$this->assign('template', $template->getId());
215
+
216
+		$this->assign('updateversion', $request->getUpdateVersion());
217
+
218
+		$this->assign('emailSentOverride', WebRequest::postBoolean('emailSentOverride') ? 'true' : 'false');
219
+		$this->assign('reserveOverride', WebRequest::postBoolean('reserveOverride') ? 'true' : 'false');
220
+		$this->assign('createOverride', WebRequest::postBoolean('createOverride') ? 'true' : 'false');
221
+
222
+		$this->skipAlerts();
223
+
224
+		$this->setTemplate($templateName);
225
+	}
226
+
227
+	/**
228
+	 * @param string $action
229
+	 *
230
+	 * @throws ApplicationLogicException
231
+	 */
232
+	final protected function processWelcome(string $action): void
233
+	{
234
+		$database = $this->getDatabase();
235
+		$currentUser = User::getCurrent($database);
236
+
237
+		if ($action !== EmailTemplate::CREATED) {
238
+			return;
239
+		}
240
+
241
+		if ($currentUser->getWelcomeTemplate() === null) {
242
+			return;
243
+		}
244
+
245
+		if (WebRequest::postBoolean('skipAutoWelcome')) {
246
+			return;
247
+		}
248
+
249
+		$this->enqueueWelcomeTask($this->getRequest($database), null, $currentUser, $database);
250
+	}
251 251
 }
Please login to merge, or discard this patch.
Spacing   +1 added lines, -1 removed lines patch added patch discarded remove patch
@@ -133,7 +133,7 @@
 block discarded – undo
133 133
         if ($reservationId !== 0 && $reservationId !== null) {
134 134
             if ($currentUser->getId() !== $reservationId) {
135 135
                 SessionAlert::error("Request is reserved by someone else.");
136
-                $this->redirect('/viewRequest', null, ['id' => $request->getId()] );
136
+                $this->redirect('/viewRequest', null, ['id' => $request->getId()]);
137 137
                 return true;
138 138
             }
139 139
         }
Please login to merge, or discard this patch.
includes/Pages/RequestAction/PageCreateRequest.php 2 patches
Indentation   +149 added lines, -149 removed lines patch added patch discarded remove patch
@@ -33,153 +33,153 @@
 block discarded – undo
33 33
  */
34 34
 class PageCreateRequest extends RequestActionBase
35 35
 {
36
-    /**
37
-     * Main function for this page, when no specific actions are called.
38
-     * @return void
39
-     * @throws AccessDeniedException
40
-     * @throws ApplicationLogicException
41
-     */
42
-    protected function main()
43
-    {
44
-        $this->checkPosted();
45
-
46
-        $database = $this->getDatabase();
47
-
48
-        $request = $this->getRequest($database);
49
-        $template = $this->getTemplate($database);
50
-        $creationMode = $this->getCreationMode();
51
-        $user = User::getCurrent($database);
52
-
53
-        $secMgr = $this->getSecurityManager();
54
-        if ($secMgr->allows('RequestCreation', User::CREATION_BOT, $user) !== SecurityManager::ALLOWED
55
-            && $creationMode === 'bot'
56
-        ) {
57
-            throw new AccessDeniedException($secMgr);
58
-        }
59
-        elseif ($secMgr->allows('RequestCreation', User::CREATION_OAUTH, $user) !== SecurityManager::ALLOWED
60
-            && $creationMode === 'oauth'
61
-        ) {
62
-            throw new AccessDeniedException($secMgr);
63
-        }
64
-
65
-        if ($request->getEmailSent()) {
66
-            throw new ApplicationLogicException('This requester has already had an email sent to them. Please fall back to manual creation');
67
-        }
68
-
69
-        $request->setStatus(RequestStatus::JOBQUEUE);
70
-        $request->setReserved(null);
71
-        $request->save();
72
-
73
-        Logger::enqueuedJobQueue($database, $request);
74
-
75
-        $creationTaskId = $this->enqueueCreationTask($creationMode, $request, $template, $user, $database);
76
-
77
-        if ($user->getWelcomeTemplate() !== null && !WebRequest::postBoolean('skipAutoWelcome')) {
78
-            $this->enqueueWelcomeTask($request, $creationTaskId, $user, $database);
79
-        }
80
-
81
-        $this->getNotificationHelper()->requestCloseQueued($request, $template->getName());
82
-
83
-        SessionAlert::success("Request {$request->getId()} has been queued for autocreation");
84
-
85
-        $this->redirect();
86
-    }
87
-
88
-    protected function getCreationMode()
89
-    {
90
-        $creationMode = WebRequest::postString('mode');
91
-        if ($creationMode !== 'oauth' && $creationMode !== 'bot') {
92
-            throw new ApplicationLogicException('Unknown creation mode');
93
-        }
94
-
95
-        return $creationMode;
96
-    }
97
-
98
-    /**
99
-     * @param PdoDatabase $database
100
-     *
101
-     * @return EmailTemplate
102
-     * @throws ApplicationLogicException
103
-     */
104
-    protected function getTemplate(PdoDatabase $database)
105
-    {
106
-        $templateId = WebRequest::postInt('template');
107
-        if ($templateId === null) {
108
-            throw new ApplicationLogicException('No template specified');
109
-        }
110
-
111
-        /** @var EmailTemplate $template */
112
-        $template = EmailTemplate::getById($templateId, $database);
113
-        if ($template === false || !$template->getActive()) {
114
-            throw new ApplicationLogicException('Invalid or inactive template specified');
115
-        }
116
-
117
-        if ($template->getDefaultAction() !== EmailTemplate::CREATED) {
118
-            throw new ApplicationLogicException('Specified template is not a creation template!');
119
-        }
120
-
121
-        return $template;
122
-    }
123
-
124
-    /**
125
-     * @param PdoDatabase $database
126
-     *
127
-     * @return Request
128
-     * @throws ApplicationLogicException
129
-     */
130
-    protected function getRequest(PdoDatabase $database)
131
-    {
132
-        $request = parent::getRequest($database);
133
-
134
-        if ($request->getStatus() == RequestStatus::CLOSED) {
135
-            throw new ApplicationLogicException('Request is already closed');
136
-        }
137
-
138
-        return $request;
139
-    }
140
-
141
-    /**
142
-     * @param               $creationMode
143
-     * @param Request       $request
144
-     * @param EmailTemplate $template
145
-     * @param User          $user
146
-     *
147
-     * @param PdoDatabase   $database
148
-     *
149
-     * @return int
150
-     * @throws ApplicationLogicException
151
-     */
152
-    protected function enqueueCreationTask(
153
-        $creationMode,
154
-        Request $request,
155
-        EmailTemplate $template,
156
-        User $user,
157
-        PdoDatabase $database
158
-    ) {
159
-        $creationTaskClass = null;
160
-
161
-        if ($creationMode == "oauth") {
162
-            $creationTaskClass = UserCreationTask::class;
163
-        }
164
-
165
-        if ($creationMode == "bot") {
166
-            $creationTaskClass = BotCreationTask::class;
167
-        }
168
-
169
-        if ($creationTaskClass === null) {
170
-            throw new ApplicationLogicException('Cannot determine creation mode');
171
-        }
172
-
173
-        $creationTask = new JobQueue();
174
-        $creationTask->setTask($creationTaskClass);
175
-        $creationTask->setRequest($request->getId());
176
-        $creationTask->setEmailTemplate($template->getId());
177
-        $creationTask->setTriggerUserId($user->getId());
178
-        $creationTask->setDatabase($database);
179
-        $creationTask->save();
180
-
181
-        $creationTaskId = $creationTask->getId();
182
-
183
-        return $creationTaskId;
184
-    }
36
+	/**
37
+	 * Main function for this page, when no specific actions are called.
38
+	 * @return void
39
+	 * @throws AccessDeniedException
40
+	 * @throws ApplicationLogicException
41
+	 */
42
+	protected function main()
43
+	{
44
+		$this->checkPosted();
45
+
46
+		$database = $this->getDatabase();
47
+
48
+		$request = $this->getRequest($database);
49
+		$template = $this->getTemplate($database);
50
+		$creationMode = $this->getCreationMode();
51
+		$user = User::getCurrent($database);
52
+
53
+		$secMgr = $this->getSecurityManager();
54
+		if ($secMgr->allows('RequestCreation', User::CREATION_BOT, $user) !== SecurityManager::ALLOWED
55
+			&& $creationMode === 'bot'
56
+		) {
57
+			throw new AccessDeniedException($secMgr);
58
+		}
59
+		elseif ($secMgr->allows('RequestCreation', User::CREATION_OAUTH, $user) !== SecurityManager::ALLOWED
60
+			&& $creationMode === 'oauth'
61
+		) {
62
+			throw new AccessDeniedException($secMgr);
63
+		}
64
+
65
+		if ($request->getEmailSent()) {
66
+			throw new ApplicationLogicException('This requester has already had an email sent to them. Please fall back to manual creation');
67
+		}
68
+
69
+		$request->setStatus(RequestStatus::JOBQUEUE);
70
+		$request->setReserved(null);
71
+		$request->save();
72
+
73
+		Logger::enqueuedJobQueue($database, $request);
74
+
75
+		$creationTaskId = $this->enqueueCreationTask($creationMode, $request, $template, $user, $database);
76
+
77
+		if ($user->getWelcomeTemplate() !== null && !WebRequest::postBoolean('skipAutoWelcome')) {
78
+			$this->enqueueWelcomeTask($request, $creationTaskId, $user, $database);
79
+		}
80
+
81
+		$this->getNotificationHelper()->requestCloseQueued($request, $template->getName());
82
+
83
+		SessionAlert::success("Request {$request->getId()} has been queued for autocreation");
84
+
85
+		$this->redirect();
86
+	}
87
+
88
+	protected function getCreationMode()
89
+	{
90
+		$creationMode = WebRequest::postString('mode');
91
+		if ($creationMode !== 'oauth' && $creationMode !== 'bot') {
92
+			throw new ApplicationLogicException('Unknown creation mode');
93
+		}
94
+
95
+		return $creationMode;
96
+	}
97
+
98
+	/**
99
+	 * @param PdoDatabase $database
100
+	 *
101
+	 * @return EmailTemplate
102
+	 * @throws ApplicationLogicException
103
+	 */
104
+	protected function getTemplate(PdoDatabase $database)
105
+	{
106
+		$templateId = WebRequest::postInt('template');
107
+		if ($templateId === null) {
108
+			throw new ApplicationLogicException('No template specified');
109
+		}
110
+
111
+		/** @var EmailTemplate $template */
112
+		$template = EmailTemplate::getById($templateId, $database);
113
+		if ($template === false || !$template->getActive()) {
114
+			throw new ApplicationLogicException('Invalid or inactive template specified');
115
+		}
116
+
117
+		if ($template->getDefaultAction() !== EmailTemplate::CREATED) {
118
+			throw new ApplicationLogicException('Specified template is not a creation template!');
119
+		}
120
+
121
+		return $template;
122
+	}
123
+
124
+	/**
125
+	 * @param PdoDatabase $database
126
+	 *
127
+	 * @return Request
128
+	 * @throws ApplicationLogicException
129
+	 */
130
+	protected function getRequest(PdoDatabase $database)
131
+	{
132
+		$request = parent::getRequest($database);
133
+
134
+		if ($request->getStatus() == RequestStatus::CLOSED) {
135
+			throw new ApplicationLogicException('Request is already closed');
136
+		}
137
+
138
+		return $request;
139
+	}
140
+
141
+	/**
142
+	 * @param               $creationMode
143
+	 * @param Request       $request
144
+	 * @param EmailTemplate $template
145
+	 * @param User          $user
146
+	 *
147
+	 * @param PdoDatabase   $database
148
+	 *
149
+	 * @return int
150
+	 * @throws ApplicationLogicException
151
+	 */
152
+	protected function enqueueCreationTask(
153
+		$creationMode,
154
+		Request $request,
155
+		EmailTemplate $template,
156
+		User $user,
157
+		PdoDatabase $database
158
+	) {
159
+		$creationTaskClass = null;
160
+
161
+		if ($creationMode == "oauth") {
162
+			$creationTaskClass = UserCreationTask::class;
163
+		}
164
+
165
+		if ($creationMode == "bot") {
166
+			$creationTaskClass = BotCreationTask::class;
167
+		}
168
+
169
+		if ($creationTaskClass === null) {
170
+			throw new ApplicationLogicException('Cannot determine creation mode');
171
+		}
172
+
173
+		$creationTask = new JobQueue();
174
+		$creationTask->setTask($creationTaskClass);
175
+		$creationTask->setRequest($request->getId());
176
+		$creationTask->setEmailTemplate($template->getId());
177
+		$creationTask->setTriggerUserId($user->getId());
178
+		$creationTask->setDatabase($database);
179
+		$creationTask->save();
180
+
181
+		$creationTaskId = $creationTask->getId();
182
+
183
+		return $creationTaskId;
184
+	}
185 185
 }
Please login to merge, or discard this patch.
Braces   +1 added lines, -2 removed lines patch added patch discarded remove patch
@@ -55,8 +55,7 @@
 block discarded – undo
55 55
             && $creationMode === 'bot'
56 56
         ) {
57 57
             throw new AccessDeniedException($secMgr);
58
-        }
59
-        elseif ($secMgr->allows('RequestCreation', User::CREATION_OAUTH, $user) !== SecurityManager::ALLOWED
58
+        } elseif ($secMgr->allows('RequestCreation', User::CREATION_OAUTH, $user) !== SecurityManager::ALLOWED
60 59
             && $creationMode === 'oauth'
61 60
         ) {
62 61
             throw new AccessDeniedException($secMgr);
Please login to merge, or discard this patch.
includes/Pages/RequestAction/PageDeferRequest.php 1 patch
Indentation   +67 added lines, -67 removed lines patch added patch discarded remove patch
@@ -20,71 +20,71 @@
 block discarded – undo
20 20
 
21 21
 class PageDeferRequest extends RequestActionBase
22 22
 {
23
-    /**
24
-     * Main function for this page, when no specific actions are called.
25
-     * @throws ApplicationLogicException
26
-     */
27
-    protected function main()
28
-    {
29
-        $this->checkPosted();
30
-        $database = $this->getDatabase();
31
-        $request = $this->getRequest($database);
32
-        $currentUser = User::getCurrent($database);
33
-
34
-        $target = WebRequest::postString('target');
35
-        $requestStates = $this->getSiteConfiguration()->getRequestStates();
36
-
37
-        if (!array_key_exists($target, $requestStates)) {
38
-            throw new ApplicationLogicException('Defer target not valid');
39
-        }
40
-
41
-        if ($request->getStatus() == $target) {
42
-            SessionAlert::warning('This request is already in the specified queue.');
43
-            $this->redirect('viewRequest', null, array('id' => $request->getId()));
44
-
45
-            return;
46
-        }
47
-
48
-        $closureDate = $request->getClosureDate();
49
-        $date = new DateTime();
50
-        $date->modify("-7 days");
51
-        $oneweek = $date->format("Y-m-d H:i:s");
52
-
53
-
54
-        if ($request->getStatus() == "Closed" && $closureDate < $oneweek) {
55
-            if (!$this->barrierTest('reopenOldRequest', $currentUser, 'RequestData')) {
56
-                throw new ApplicationLogicException(
57
-                    "You are not allowed to re-open a request that has been closed for over a week.");
58
-            }
59
-        }
60
-
61
-        if ($request->getStatus() === RequestStatus::JOBQUEUE) {
62
-            /** @var JobQueue[] $pendingJobs */
63
-            $pendingJobs = JobQueueSearchHelper::get($database)->byRequest($request->getId())->statusIn([
64
-                JobQueue::STATUS_READY,
65
-                JobQueue::STATUS_WAITING,
66
-            ])->fetch();
67
-
68
-            foreach ($pendingJobs as $job) {
69
-                $job->setStatus(JobQueue::STATUS_CANCELLED);
70
-                $job->setError('Cancelled by request deferral');
71
-                $job->save();
72
-            }
73
-        }
74
-
75
-        $request->setReserved(null);
76
-        $request->setStatus($target);
77
-        $request->setUpdateVersion(WebRequest::postInt('updateversion'));
78
-        $request->save();
79
-
80
-        $deto = $requestStates[$target]['deferto'];
81
-        $detolog = $requestStates[$target]['defertolog'];
82
-
83
-        Logger::deferRequest($database, $request, $detolog);
84
-
85
-        $this->getNotificationHelper()->requestDeferred($request);
86
-        SessionAlert::success("Request {$request->getId()} deferred to {$deto}");
87
-
88
-        $this->redirect();
89
-    }
23
+	/**
24
+	 * Main function for this page, when no specific actions are called.
25
+	 * @throws ApplicationLogicException
26
+	 */
27
+	protected function main()
28
+	{
29
+		$this->checkPosted();
30
+		$database = $this->getDatabase();
31
+		$request = $this->getRequest($database);
32
+		$currentUser = User::getCurrent($database);
33
+
34
+		$target = WebRequest::postString('target');
35
+		$requestStates = $this->getSiteConfiguration()->getRequestStates();
36
+
37
+		if (!array_key_exists($target, $requestStates)) {
38
+			throw new ApplicationLogicException('Defer target not valid');
39
+		}
40
+
41
+		if ($request->getStatus() == $target) {
42
+			SessionAlert::warning('This request is already in the specified queue.');
43
+			$this->redirect('viewRequest', null, array('id' => $request->getId()));
44
+
45
+			return;
46
+		}
47
+
48
+		$closureDate = $request->getClosureDate();
49
+		$date = new DateTime();
50
+		$date->modify("-7 days");
51
+		$oneweek = $date->format("Y-m-d H:i:s");
52
+
53
+
54
+		if ($request->getStatus() == "Closed" && $closureDate < $oneweek) {
55
+			if (!$this->barrierTest('reopenOldRequest', $currentUser, 'RequestData')) {
56
+				throw new ApplicationLogicException(
57
+					"You are not allowed to re-open a request that has been closed for over a week.");
58
+			}
59
+		}
60
+
61
+		if ($request->getStatus() === RequestStatus::JOBQUEUE) {
62
+			/** @var JobQueue[] $pendingJobs */
63
+			$pendingJobs = JobQueueSearchHelper::get($database)->byRequest($request->getId())->statusIn([
64
+				JobQueue::STATUS_READY,
65
+				JobQueue::STATUS_WAITING,
66
+			])->fetch();
67
+
68
+			foreach ($pendingJobs as $job) {
69
+				$job->setStatus(JobQueue::STATUS_CANCELLED);
70
+				$job->setError('Cancelled by request deferral');
71
+				$job->save();
72
+			}
73
+		}
74
+
75
+		$request->setReserved(null);
76
+		$request->setStatus($target);
77
+		$request->setUpdateVersion(WebRequest::postInt('updateversion'));
78
+		$request->save();
79
+
80
+		$deto = $requestStates[$target]['deferto'];
81
+		$detolog = $requestStates[$target]['defertolog'];
82
+
83
+		Logger::deferRequest($database, $request, $detolog);
84
+
85
+		$this->getNotificationHelper()->requestDeferred($request);
86
+		SessionAlert::success("Request {$request->getId()} deferred to {$deto}");
87
+
88
+		$this->redirect();
89
+	}
90 90
 }
Please login to merge, or discard this patch.
includes/Pages/Page404.php 1 patch
Indentation   +15 added lines, -15 removed lines patch added patch discarded remove patch
@@ -12,21 +12,21 @@
 block discarded – undo
12 12
 
13 13
 class Page404 extends InternalPageBase
14 14
 {
15
-    /**
16
-     * Main function for this page, when no actions are called.
17
-     */
18
-    protected function main()
19
-    {
20
-        if (!headers_sent()) {
21
-            header("HTTP/1.1 404 Not Found");
22
-        }
15
+	/**
16
+	 * Main function for this page, when no actions are called.
17
+	 */
18
+	protected function main()
19
+	{
20
+		if (!headers_sent()) {
21
+			header("HTTP/1.1 404 Not Found");
22
+		}
23 23
 
24
-        $this->skipAlerts();
25
-        $this->setTemplate("404.tpl");
26
-    }
24
+		$this->skipAlerts();
25
+		$this->setTemplate("404.tpl");
26
+	}
27 27
 
28
-    protected function isProtectedPage()
29
-    {
30
-        return false;
31
-    }
28
+	protected function isProtectedPage()
29
+	{
30
+		return false;
31
+	}
32 32
 }
Please login to merge, or discard this patch.
includes/Pages/PageUserManagement.php 3 patches
Indentation   +561 added lines, -561 removed lines patch added patch discarded remove patch
@@ -24,565 +24,565 @@
 block discarded – undo
24 24
  */
25 25
 class PageUserManagement extends InternalPageBase
26 26
 {
27
-    /** @var string */
28
-    private $adminMailingList = '[email protected]';
29
-
30
-    /**
31
-     * Main function for this page, when no specific actions are called.
32
-     */
33
-    protected function main()
34
-    {
35
-        $this->setHtmlTitle('User Management');
36
-
37
-        $database = $this->getDatabase();
38
-        $currentUser = User::getCurrent($database);
39
-
40
-        $userSearchRequest = WebRequest::getString('usersearch');
41
-        if ($userSearchRequest !== null) {
42
-            $searchedUser = User::getByUsername($userSearchRequest, $database);
43
-            if($searchedUser !== false) {
44
-                $this->redirect('statistics/users', 'detail', ['user' => $searchedUser->getId()]);
45
-                return;
46
-            }
47
-        }
48
-
49
-        // A bit hacky, but it's better than my last solution of creating an object for each user and passing that to
50
-        // the template. I still don't have a particularly good way of handling this.
51
-        OAuthUserHelper::prepareTokenCountStatement($database);
52
-
53
-        if (WebRequest::getBoolean("showAll")) {
54
-            $this->assign("showAll", true);
55
-
56
-            $suspendedUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_SUSPENDED)->fetch();
57
-            $this->assign("suspendedUsers", $suspendedUsers);
58
-
59
-            $declinedUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_DECLINED)->fetch();
60
-            $this->assign("declinedUsers", $declinedUsers);
61
-
62
-            UserSearchHelper::get($database)->getRoleMap($roleMap);
63
-        }
64
-        else {
65
-            $this->assign("showAll", false);
66
-            $this->assign("suspendedUsers", array());
67
-            $this->assign("declinedUsers", array());
68
-
69
-            UserSearchHelper::get($database)->statusIn(array('New', 'Active'))->getRoleMap($roleMap);
70
-        }
71
-
72
-        $newUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_NEW)->fetch();
73
-        $normalUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('user')->fetch();
74
-        $adminUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('admin')->fetch();
75
-        $checkUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('checkuser')->fetch();
76
-        $toolRoots = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('toolRoot')->fetch();
77
-        $this->assign('newUsers', $newUsers);
78
-        $this->assign('normalUsers', $normalUsers);
79
-        $this->assign('adminUsers', $adminUsers);
80
-        $this->assign('checkUsers', $checkUsers);
81
-        $this->assign('toolRoots', $toolRoots);
82
-
83
-        $this->assign('roles', $roleMap);
84
-
85
-        $this->addJs("/api.php?action=users&all=true&targetVariable=typeaheaddata");
86
-
87
-        $this->assign('canApprove', $this->barrierTest('approve', $currentUser));
88
-        $this->assign('canDecline', $this->barrierTest('decline', $currentUser));
89
-        $this->assign('canRename', $this->barrierTest('rename', $currentUser));
90
-        $this->assign('canEditUser', $this->barrierTest('editUser', $currentUser));
91
-        $this->assign('canSuspend', $this->barrierTest('suspend', $currentUser));
92
-        $this->assign('canEditRoles', $this->barrierTest('editRoles', $currentUser));
93
-
94
-        $this->setTemplate("usermanagement/main.tpl");
95
-    }
96
-
97
-    #region Access control
98
-
99
-    /**
100
-     * Action target for editing the roles assigned to a user
101
-     */
102
-    protected function editRoles()
103
-    {
104
-        $this->setHtmlTitle('User Management');
105
-        $database = $this->getDatabase();
106
-        $userId = WebRequest::getInt('user');
107
-
108
-        /** @var User $user */
109
-        $user = User::getById($userId, $database);
110
-
111
-        if ($user === false) {
112
-            throw new ApplicationLogicException('Sorry, the user you are trying to edit could not be found.');
113
-        }
114
-
115
-        $roleData = $this->getRoleData(UserRole::getForUser($user->getId(), $database));
116
-
117
-        // Dual-mode action
118
-        if (WebRequest::wasPosted()) {
119
-            $this->validateCSRFToken();
120
-
121
-            $reason = WebRequest::postString('reason');
122
-            if ($reason === false || trim($reason) === '') {
123
-                throw new ApplicationLogicException('No reason specified for roles change');
124
-            }
125
-
126
-            /** @var UserRole[] $delete */
127
-            $delete = array();
128
-            /** @var string[] $delete */
129
-            $add = array();
130
-
131
-            foreach ($roleData as $name => $r) {
132
-                if ($r['allowEdit'] !== 1) {
133
-                    // not allowed, to touch this, so ignore it
134
-                    continue;
135
-                }
136
-
137
-                $newValue = WebRequest::postBoolean('role-' . $name) ? 1 : 0;
138
-                if ($newValue !== $r['active']) {
139
-                    if ($newValue === 0) {
140
-                        $delete[] = $r['object'];
141
-                    }
142
-
143
-                    if ($newValue === 1) {
144
-                        $add[] = $name;
145
-                    }
146
-                }
147
-            }
148
-
149
-            // Check there's something to do
150
-            if ((count($add) + count($delete)) === 0) {
151
-                $this->redirect('statistics/users', 'detail', array('user' => $user->getId()));
152
-                SessionAlert::warning('No changes made to roles.');
153
-
154
-                return;
155
-            }
156
-
157
-            $removed = array();
158
-
159
-            /** @var UserRole $d */
160
-            foreach ($delete as $d) {
161
-                $removed[] = $d->getRole();
162
-                $d->delete();
163
-            }
164
-
165
-            foreach ($add as $x) {
166
-                $a = new UserRole();
167
-                $a->setUser($user->getId());
168
-                $a->setRole($x);
169
-                $a->setDatabase($database);
170
-                $a->save();
171
-            }
172
-
173
-            Logger::userRolesEdited($database, $user, $reason, $add, $removed);
174
-
175
-            // dummy save for optimistic locking. If this fails, the entire txn will roll back.
176
-            $user->setUpdateVersion(WebRequest::postInt('updateversion'));
177
-            $user->save();
178
-
179
-            $this->getNotificationHelper()->userRolesEdited($user, $reason);
180
-            SessionAlert::quick('Roles changed for user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
181
-
182
-            $this->redirect('statistics/users', 'detail', array('user' => $user->getId()));
183
-
184
-            return;
185
-        }
186
-        else {
187
-            $this->assignCSRFToken();
188
-            $this->setTemplate('usermanagement/roleedit.tpl');
189
-            $this->assign('user', $user);
190
-            $this->assign('roleData', $roleData);
191
-        }
192
-    }
193
-
194
-    /**
195
-     * Action target for suspending users
196
-     *
197
-     * @throws ApplicationLogicException
198
-     */
199
-    protected function suspend()
200
-    {
201
-        $this->setHtmlTitle('User Management');
202
-
203
-        $database = $this->getDatabase();
204
-
205
-        $userId = WebRequest::getInt('user');
206
-
207
-        /** @var User $user */
208
-        $user = User::getById($userId, $database);
209
-
210
-        if ($user === false) {
211
-            throw new ApplicationLogicException('Sorry, the user you are trying to suspend could not be found.');
212
-        }
213
-
214
-        if ($user->isSuspended()) {
215
-            throw new ApplicationLogicException('Sorry, the user you are trying to suspend is already suspended.');
216
-        }
217
-
218
-        // Dual-mode action
219
-        if (WebRequest::wasPosted()) {
220
-            $this->validateCSRFToken();
221
-            $reason = WebRequest::postString('reason');
222
-
223
-            if ($reason === null || trim($reason) === "") {
224
-                throw new ApplicationLogicException('No reason provided');
225
-            }
226
-
227
-            $user->setStatus(User::STATUS_SUSPENDED);
228
-            $user->setUpdateVersion(WebRequest::postInt('updateversion'));
229
-            $user->save();
230
-            Logger::suspendedUser($database, $user, $reason);
231
-
232
-            $this->getNotificationHelper()->userSuspended($user, $reason);
233
-            SessionAlert::quick('Suspended user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
234
-
235
-            // send email
236
-            $this->sendStatusChangeEmail(
237
-                'Your WP:ACC account has been suspended',
238
-                'usermanagement/emails/suspended.tpl',
239
-                $reason,
240
-                $user,
241
-                User::getCurrent($database)->getUsername()
242
-            );
243
-
244
-            $this->redirect('userManagement');
245
-
246
-            return;
247
-        }
248
-        else {
249
-            $this->assignCSRFToken();
250
-            $this->setTemplate('usermanagement/changelevel-reason.tpl');
251
-            $this->assign('user', $user);
252
-            $this->assign('status', 'Suspended');
253
-            $this->assign("showReason", true);
254
-
255
-            if (WebRequest::getString('preload')) {
256
-                $this->assign('preload', WebRequest::getString('preload'));
257
-            }
258
-        }
259
-    }
260
-
261
-    /**
262
-     * Entry point for the decline action
263
-     *
264
-     * @throws ApplicationLogicException
265
-     */
266
-    protected function decline()
267
-    {
268
-        $this->setHtmlTitle('User Management');
269
-
270
-        $database = $this->getDatabase();
271
-
272
-        $userId = WebRequest::getInt('user');
273
-        $user = User::getById($userId, $database);
274
-
275
-        if ($user === false) {
276
-            throw new ApplicationLogicException('Sorry, the user you are trying to decline could not be found.');
277
-        }
278
-
279
-        if (!$user->isNewUser()) {
280
-            throw new ApplicationLogicException('Sorry, the user you are trying to decline is not new.');
281
-        }
282
-
283
-        // Dual-mode action
284
-        if (WebRequest::wasPosted()) {
285
-            $this->validateCSRFToken();
286
-            $reason = WebRequest::postString('reason');
287
-
288
-            if ($reason === null || trim($reason) === "") {
289
-                throw new ApplicationLogicException('No reason provided');
290
-            }
291
-
292
-            $user->setStatus(User::STATUS_DECLINED);
293
-            $user->setUpdateVersion(WebRequest::postInt('updateversion'));
294
-            $user->save();
295
-            Logger::declinedUser($database, $user, $reason);
296
-
297
-            $this->getNotificationHelper()->userDeclined($user, $reason);
298
-            SessionAlert::quick('Declined user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
299
-
300
-            // send email
301
-            $this->sendStatusChangeEmail(
302
-                'Your WP:ACC account has been declined',
303
-                'usermanagement/emails/declined.tpl',
304
-                $reason,
305
-                $user,
306
-                User::getCurrent($database)->getUsername()
307
-            );
308
-
309
-            $this->redirect('userManagement');
310
-
311
-            return;
312
-        }
313
-        else {
314
-            $this->assignCSRFToken();
315
-            $this->setTemplate('usermanagement/changelevel-reason.tpl');
316
-            $this->assign('user', $user);
317
-            $this->assign('status', 'Declined');
318
-            $this->assign("showReason", true);
319
-        }
320
-    }
321
-
322
-    /**
323
-     * Entry point for the approve action
324
-     *
325
-     * @throws ApplicationLogicException
326
-     */
327
-    protected function approve()
328
-    {
329
-        $this->setHtmlTitle('User Management');
330
-
331
-        $database = $this->getDatabase();
332
-
333
-        $userId = WebRequest::getInt('user');
334
-        $user = User::getById($userId, $database);
335
-
336
-        if ($user === false) {
337
-            throw new ApplicationLogicException('Sorry, the user you are trying to approve could not be found.');
338
-        }
339
-
340
-        if ($user->isActive()) {
341
-            throw new ApplicationLogicException('Sorry, the user you are trying to approve is already an active user.');
342
-        }
343
-
344
-        // Dual-mode action
345
-        if (WebRequest::wasPosted()) {
346
-            $this->validateCSRFToken();
347
-            $user->setStatus(User::STATUS_ACTIVE);
348
-            $user->setUpdateVersion(WebRequest::postInt('updateversion'));
349
-            $user->save();
350
-            Logger::approvedUser($database, $user);
351
-
352
-            $this->getNotificationHelper()->userApproved($user);
353
-            SessionAlert::quick('Approved user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
354
-
355
-            // send email
356
-            $this->sendStatusChangeEmail(
357
-                'Your WP:ACC account has been approved',
358
-                'usermanagement/emails/approved.tpl',
359
-                null,
360
-                $user,
361
-                User::getCurrent($database)->getUsername()
362
-            );
363
-
364
-            $this->redirect("userManagement");
365
-
366
-            return;
367
-        }
368
-        else {
369
-            $this->assignCSRFToken();
370
-            $this->setTemplate("usermanagement/changelevel-reason.tpl");
371
-            $this->assign("user", $user);
372
-            $this->assign("status", "Active");
373
-            $this->assign("showReason", false);
374
-        }
375
-    }
376
-
377
-    #endregion
378
-
379
-    #region Renaming / Editing
380
-
381
-    /**
382
-     * Entry point for the rename action
383
-     *
384
-     * @throws ApplicationLogicException
385
-     */
386
-    protected function rename()
387
-    {
388
-        $this->setHtmlTitle('User Management');
389
-
390
-        $database = $this->getDatabase();
391
-
392
-        $userId = WebRequest::getInt('user');
393
-        $user = User::getById($userId, $database);
394
-
395
-        if ($user === false) {
396
-            throw new ApplicationLogicException('Sorry, the user you are trying to rename could not be found.');
397
-        }
398
-
399
-        // Dual-mode action
400
-        if (WebRequest::wasPosted()) {
401
-            $this->validateCSRFToken();
402
-            $newUsername = WebRequest::postString('newname');
403
-
404
-            if ($newUsername === null || trim($newUsername) === "") {
405
-                throw new ApplicationLogicException('The new username cannot be empty');
406
-            }
407
-
408
-            if (User::getByUsername($newUsername, $database) != false) {
409
-                throw new ApplicationLogicException('The new username already exists');
410
-            }
411
-
412
-            $oldUsername = $user->getUsername();
413
-            $user->setUsername($newUsername);
414
-            $user->setUpdateVersion(WebRequest::postInt('updateversion'));
415
-
416
-            $user->save();
417
-
418
-            $logEntryData = serialize(array(
419
-                'old' => $oldUsername,
420
-                'new' => $newUsername,
421
-            ));
422
-
423
-            Logger::renamedUser($database, $user, $logEntryData);
424
-
425
-            SessionAlert::quick("Changed User "
426
-                . htmlentities($oldUsername, ENT_COMPAT, 'UTF-8')
427
-                . " name to "
428
-                . htmlentities($newUsername, ENT_COMPAT, 'UTF-8'));
429
-
430
-            $this->getNotificationHelper()->userRenamed($user, $oldUsername);
431
-
432
-            // send an email to the user.
433
-            $this->assign('targetUsername', $user->getUsername());
434
-            $this->assign('toolAdmin', User::getCurrent($database)->getUsername());
435
-            $this->assign('oldUsername', $oldUsername);
436
-            $this->assign('mailingList', $this->adminMailingList);
437
-
438
-            $this->getEmailHelper()->sendMail(
439
-                $user->getEmail(),
440
-                'Your username on WP:ACC has been changed',
441
-                $this->fetchTemplate('usermanagement/emails/renamed.tpl'),
442
-                array('Reply-To' => $this->adminMailingList)
443
-            );
444
-
445
-            $this->redirect("userManagement");
446
-
447
-            return;
448
-        }
449
-        else {
450
-            $this->assignCSRFToken();
451
-            $this->setTemplate('usermanagement/renameuser.tpl');
452
-            $this->assign('user', $user);
453
-        }
454
-    }
455
-
456
-    /**
457
-     * Entry point for the edit action
458
-     *
459
-     * @throws ApplicationLogicException
460
-     */
461
-    protected function editUser()
462
-    {
463
-        $this->setHtmlTitle('User Management');
464
-
465
-        $database = $this->getDatabase();
466
-
467
-        $userId = WebRequest::getInt('user');
468
-        $user = User::getById($userId, $database);
469
-        $oauth = new OAuthUserHelper($user, $database, $this->getOAuthProtocolHelper(), $this->getSiteConfiguration());
470
-
471
-        if ($user === false) {
472
-            throw new ApplicationLogicException('Sorry, the user you are trying to edit could not be found.');
473
-        }
474
-
475
-        // Dual-mode action
476
-        if (WebRequest::wasPosted()) {
477
-            $this->validateCSRFToken();
478
-            $newEmail = WebRequest::postEmail('user_email');
479
-            $newOnWikiName = WebRequest::postString('user_onwikiname');
480
-
481
-            if ($newEmail === null) {
482
-                throw new ApplicationLogicException('Invalid email address');
483
-            }
484
-
485
-            if (!($oauth->isFullyLinked() || $oauth->isPartiallyLinked())) {
486
-                if (trim($newOnWikiName) == "") {
487
-                    throw new ApplicationLogicException('New on-wiki username cannot be blank');
488
-                }
489
-
490
-                $user->setOnWikiName($newOnWikiName);
491
-                $user->setWelcomeSig(WebRequest::postString('sig'));
492
-            }
493
-
494
-            $user->setEmail($newEmail);
495
-            $user->setCreationMode(WebRequest::postInt('creationmode'));
496
-
497
-            $user->setUpdateVersion(WebRequest::postInt('updateversion'));
498
-
499
-            $user->save();
500
-
501
-            Logger::userPreferencesChange($database, $user);
502
-            $this->getNotificationHelper()->userPrefChange($user);
503
-            SessionAlert::quick('Changes to user\'s preferences have been saved');
504
-
505
-            $this->redirect("userManagement");
506
-
507
-            return;
508
-        }
509
-        else {
510
-            $this->assignCSRFToken();
511
-            $oauth = new OAuthUserHelper($user, $database, $this->getOAuthProtocolHelper(),
512
-                $this->getSiteConfiguration());
513
-            $this->setTemplate('usermanagement/edituser.tpl');
514
-            $this->assign('user', $user);
515
-            $this->assign('oauth', $oauth);
516
-
517
-            $this->assign('canManualCreate',
518
-                $this->barrierTest(User::CREATION_MANUAL, $user, 'RequestCreation'));
519
-            $this->assign('canOauthCreate',
520
-                $this->barrierTest(User::CREATION_OAUTH, $user, 'RequestCreation'));
521
-            $this->assign('canBotCreate',
522
-                $this->barrierTest(User::CREATION_BOT, $user, 'RequestCreation'));
523
-        }
524
-    }
525
-
526
-    #endregion
527
-
528
-    /**
529
-     * Sends a status change email to the user.
530
-     *
531
-     * @param string      $subject           The subject of the email
532
-     * @param string      $template          The smarty template to use
533
-     * @param string|null $reason            The reason for performing the status change
534
-     * @param User        $user              The user affected
535
-     * @param string      $toolAdminUsername The tool admin's username who is making the edit
536
-     */
537
-    private function sendStatusChangeEmail($subject, $template, $reason, $user, $toolAdminUsername)
538
-    {
539
-        $this->assign('targetUsername', $user->getUsername());
540
-        $this->assign('toolAdmin', $toolAdminUsername);
541
-        $this->assign('actionReason', $reason);
542
-        $this->assign('mailingList', $this->adminMailingList);
543
-
544
-        $this->getEmailHelper()->sendMail(
545
-            $user->getEmail(),
546
-            $subject,
547
-            $this->fetchTemplate($template),
548
-            array('Reply-To' => $this->adminMailingList)
549
-        );
550
-    }
551
-
552
-    /**
553
-     * @param UserRole[] $activeRoles
554
-     *
555
-     * @return array
556
-     */
557
-    private function getRoleData($activeRoles)
558
-    {
559
-        $availableRoles = $this->getSecurityManager()->getRoleConfiguration()->getAvailableRoles();
560
-
561
-        $currentUser = User::getCurrent($this->getDatabase());
562
-        $this->getSecurityManager()->getActiveRoles($currentUser, $userRoles, $inactiveRoles);
563
-
564
-        $initialValue = array('active' => 0, 'allowEdit' => 0, 'description' => '???', 'object' => null);
565
-
566
-        $roleData = array();
567
-        foreach ($availableRoles as $role => $data) {
568
-            $intersection = array_intersect($data['editableBy'], $userRoles);
569
-
570
-            $roleData[$role] = $initialValue;
571
-            $roleData[$role]['allowEdit'] = count($intersection) > 0 ? 1 : 0;
572
-            $roleData[$role]['description'] = $data['description'];
573
-        }
574
-
575
-        foreach ($activeRoles as $role) {
576
-            if (!isset($roleData[$role->getRole()])) {
577
-                // This value is no longer available in the configuration, allow changing (aka removing) it.
578
-                $roleData[$role->getRole()] = $initialValue;
579
-                $roleData[$role->getRole()]['allowEdit'] = 1;
580
-            }
581
-
582
-            $roleData[$role->getRole()]['object'] = $role;
583
-            $roleData[$role->getRole()]['active'] = 1;
584
-        }
585
-
586
-        return $roleData;
587
-    }
27
+	/** @var string */
28
+	private $adminMailingList = '[email protected]';
29
+
30
+	/**
31
+	 * Main function for this page, when no specific actions are called.
32
+	 */
33
+	protected function main()
34
+	{
35
+		$this->setHtmlTitle('User Management');
36
+
37
+		$database = $this->getDatabase();
38
+		$currentUser = User::getCurrent($database);
39
+
40
+		$userSearchRequest = WebRequest::getString('usersearch');
41
+		if ($userSearchRequest !== null) {
42
+			$searchedUser = User::getByUsername($userSearchRequest, $database);
43
+			if($searchedUser !== false) {
44
+				$this->redirect('statistics/users', 'detail', ['user' => $searchedUser->getId()]);
45
+				return;
46
+			}
47
+		}
48
+
49
+		// A bit hacky, but it's better than my last solution of creating an object for each user and passing that to
50
+		// the template. I still don't have a particularly good way of handling this.
51
+		OAuthUserHelper::prepareTokenCountStatement($database);
52
+
53
+		if (WebRequest::getBoolean("showAll")) {
54
+			$this->assign("showAll", true);
55
+
56
+			$suspendedUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_SUSPENDED)->fetch();
57
+			$this->assign("suspendedUsers", $suspendedUsers);
58
+
59
+			$declinedUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_DECLINED)->fetch();
60
+			$this->assign("declinedUsers", $declinedUsers);
61
+
62
+			UserSearchHelper::get($database)->getRoleMap($roleMap);
63
+		}
64
+		else {
65
+			$this->assign("showAll", false);
66
+			$this->assign("suspendedUsers", array());
67
+			$this->assign("declinedUsers", array());
68
+
69
+			UserSearchHelper::get($database)->statusIn(array('New', 'Active'))->getRoleMap($roleMap);
70
+		}
71
+
72
+		$newUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_NEW)->fetch();
73
+		$normalUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('user')->fetch();
74
+		$adminUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('admin')->fetch();
75
+		$checkUsers = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('checkuser')->fetch();
76
+		$toolRoots = UserSearchHelper::get($database)->byStatus(User::STATUS_ACTIVE)->byRole('toolRoot')->fetch();
77
+		$this->assign('newUsers', $newUsers);
78
+		$this->assign('normalUsers', $normalUsers);
79
+		$this->assign('adminUsers', $adminUsers);
80
+		$this->assign('checkUsers', $checkUsers);
81
+		$this->assign('toolRoots', $toolRoots);
82
+
83
+		$this->assign('roles', $roleMap);
84
+
85
+		$this->addJs("/api.php?action=users&all=true&targetVariable=typeaheaddata");
86
+
87
+		$this->assign('canApprove', $this->barrierTest('approve', $currentUser));
88
+		$this->assign('canDecline', $this->barrierTest('decline', $currentUser));
89
+		$this->assign('canRename', $this->barrierTest('rename', $currentUser));
90
+		$this->assign('canEditUser', $this->barrierTest('editUser', $currentUser));
91
+		$this->assign('canSuspend', $this->barrierTest('suspend', $currentUser));
92
+		$this->assign('canEditRoles', $this->barrierTest('editRoles', $currentUser));
93
+
94
+		$this->setTemplate("usermanagement/main.tpl");
95
+	}
96
+
97
+	#region Access control
98
+
99
+	/**
100
+	 * Action target for editing the roles assigned to a user
101
+	 */
102
+	protected function editRoles()
103
+	{
104
+		$this->setHtmlTitle('User Management');
105
+		$database = $this->getDatabase();
106
+		$userId = WebRequest::getInt('user');
107
+
108
+		/** @var User $user */
109
+		$user = User::getById($userId, $database);
110
+
111
+		if ($user === false) {
112
+			throw new ApplicationLogicException('Sorry, the user you are trying to edit could not be found.');
113
+		}
114
+
115
+		$roleData = $this->getRoleData(UserRole::getForUser($user->getId(), $database));
116
+
117
+		// Dual-mode action
118
+		if (WebRequest::wasPosted()) {
119
+			$this->validateCSRFToken();
120
+
121
+			$reason = WebRequest::postString('reason');
122
+			if ($reason === false || trim($reason) === '') {
123
+				throw new ApplicationLogicException('No reason specified for roles change');
124
+			}
125
+
126
+			/** @var UserRole[] $delete */
127
+			$delete = array();
128
+			/** @var string[] $delete */
129
+			$add = array();
130
+
131
+			foreach ($roleData as $name => $r) {
132
+				if ($r['allowEdit'] !== 1) {
133
+					// not allowed, to touch this, so ignore it
134
+					continue;
135
+				}
136
+
137
+				$newValue = WebRequest::postBoolean('role-' . $name) ? 1 : 0;
138
+				if ($newValue !== $r['active']) {
139
+					if ($newValue === 0) {
140
+						$delete[] = $r['object'];
141
+					}
142
+
143
+					if ($newValue === 1) {
144
+						$add[] = $name;
145
+					}
146
+				}
147
+			}
148
+
149
+			// Check there's something to do
150
+			if ((count($add) + count($delete)) === 0) {
151
+				$this->redirect('statistics/users', 'detail', array('user' => $user->getId()));
152
+				SessionAlert::warning('No changes made to roles.');
153
+
154
+				return;
155
+			}
156
+
157
+			$removed = array();
158
+
159
+			/** @var UserRole $d */
160
+			foreach ($delete as $d) {
161
+				$removed[] = $d->getRole();
162
+				$d->delete();
163
+			}
164
+
165
+			foreach ($add as $x) {
166
+				$a = new UserRole();
167
+				$a->setUser($user->getId());
168
+				$a->setRole($x);
169
+				$a->setDatabase($database);
170
+				$a->save();
171
+			}
172
+
173
+			Logger::userRolesEdited($database, $user, $reason, $add, $removed);
174
+
175
+			// dummy save for optimistic locking. If this fails, the entire txn will roll back.
176
+			$user->setUpdateVersion(WebRequest::postInt('updateversion'));
177
+			$user->save();
178
+
179
+			$this->getNotificationHelper()->userRolesEdited($user, $reason);
180
+			SessionAlert::quick('Roles changed for user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
181
+
182
+			$this->redirect('statistics/users', 'detail', array('user' => $user->getId()));
183
+
184
+			return;
185
+		}
186
+		else {
187
+			$this->assignCSRFToken();
188
+			$this->setTemplate('usermanagement/roleedit.tpl');
189
+			$this->assign('user', $user);
190
+			$this->assign('roleData', $roleData);
191
+		}
192
+	}
193
+
194
+	/**
195
+	 * Action target for suspending users
196
+	 *
197
+	 * @throws ApplicationLogicException
198
+	 */
199
+	protected function suspend()
200
+	{
201
+		$this->setHtmlTitle('User Management');
202
+
203
+		$database = $this->getDatabase();
204
+
205
+		$userId = WebRequest::getInt('user');
206
+
207
+		/** @var User $user */
208
+		$user = User::getById($userId, $database);
209
+
210
+		if ($user === false) {
211
+			throw new ApplicationLogicException('Sorry, the user you are trying to suspend could not be found.');
212
+		}
213
+
214
+		if ($user->isSuspended()) {
215
+			throw new ApplicationLogicException('Sorry, the user you are trying to suspend is already suspended.');
216
+		}
217
+
218
+		// Dual-mode action
219
+		if (WebRequest::wasPosted()) {
220
+			$this->validateCSRFToken();
221
+			$reason = WebRequest::postString('reason');
222
+
223
+			if ($reason === null || trim($reason) === "") {
224
+				throw new ApplicationLogicException('No reason provided');
225
+			}
226
+
227
+			$user->setStatus(User::STATUS_SUSPENDED);
228
+			$user->setUpdateVersion(WebRequest::postInt('updateversion'));
229
+			$user->save();
230
+			Logger::suspendedUser($database, $user, $reason);
231
+
232
+			$this->getNotificationHelper()->userSuspended($user, $reason);
233
+			SessionAlert::quick('Suspended user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
234
+
235
+			// send email
236
+			$this->sendStatusChangeEmail(
237
+				'Your WP:ACC account has been suspended',
238
+				'usermanagement/emails/suspended.tpl',
239
+				$reason,
240
+				$user,
241
+				User::getCurrent($database)->getUsername()
242
+			);
243
+
244
+			$this->redirect('userManagement');
245
+
246
+			return;
247
+		}
248
+		else {
249
+			$this->assignCSRFToken();
250
+			$this->setTemplate('usermanagement/changelevel-reason.tpl');
251
+			$this->assign('user', $user);
252
+			$this->assign('status', 'Suspended');
253
+			$this->assign("showReason", true);
254
+
255
+			if (WebRequest::getString('preload')) {
256
+				$this->assign('preload', WebRequest::getString('preload'));
257
+			}
258
+		}
259
+	}
260
+
261
+	/**
262
+	 * Entry point for the decline action
263
+	 *
264
+	 * @throws ApplicationLogicException
265
+	 */
266
+	protected function decline()
267
+	{
268
+		$this->setHtmlTitle('User Management');
269
+
270
+		$database = $this->getDatabase();
271
+
272
+		$userId = WebRequest::getInt('user');
273
+		$user = User::getById($userId, $database);
274
+
275
+		if ($user === false) {
276
+			throw new ApplicationLogicException('Sorry, the user you are trying to decline could not be found.');
277
+		}
278
+
279
+		if (!$user->isNewUser()) {
280
+			throw new ApplicationLogicException('Sorry, the user you are trying to decline is not new.');
281
+		}
282
+
283
+		// Dual-mode action
284
+		if (WebRequest::wasPosted()) {
285
+			$this->validateCSRFToken();
286
+			$reason = WebRequest::postString('reason');
287
+
288
+			if ($reason === null || trim($reason) === "") {
289
+				throw new ApplicationLogicException('No reason provided');
290
+			}
291
+
292
+			$user->setStatus(User::STATUS_DECLINED);
293
+			$user->setUpdateVersion(WebRequest::postInt('updateversion'));
294
+			$user->save();
295
+			Logger::declinedUser($database, $user, $reason);
296
+
297
+			$this->getNotificationHelper()->userDeclined($user, $reason);
298
+			SessionAlert::quick('Declined user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
299
+
300
+			// send email
301
+			$this->sendStatusChangeEmail(
302
+				'Your WP:ACC account has been declined',
303
+				'usermanagement/emails/declined.tpl',
304
+				$reason,
305
+				$user,
306
+				User::getCurrent($database)->getUsername()
307
+			);
308
+
309
+			$this->redirect('userManagement');
310
+
311
+			return;
312
+		}
313
+		else {
314
+			$this->assignCSRFToken();
315
+			$this->setTemplate('usermanagement/changelevel-reason.tpl');
316
+			$this->assign('user', $user);
317
+			$this->assign('status', 'Declined');
318
+			$this->assign("showReason", true);
319
+		}
320
+	}
321
+
322
+	/**
323
+	 * Entry point for the approve action
324
+	 *
325
+	 * @throws ApplicationLogicException
326
+	 */
327
+	protected function approve()
328
+	{
329
+		$this->setHtmlTitle('User Management');
330
+
331
+		$database = $this->getDatabase();
332
+
333
+		$userId = WebRequest::getInt('user');
334
+		$user = User::getById($userId, $database);
335
+
336
+		if ($user === false) {
337
+			throw new ApplicationLogicException('Sorry, the user you are trying to approve could not be found.');
338
+		}
339
+
340
+		if ($user->isActive()) {
341
+			throw new ApplicationLogicException('Sorry, the user you are trying to approve is already an active user.');
342
+		}
343
+
344
+		// Dual-mode action
345
+		if (WebRequest::wasPosted()) {
346
+			$this->validateCSRFToken();
347
+			$user->setStatus(User::STATUS_ACTIVE);
348
+			$user->setUpdateVersion(WebRequest::postInt('updateversion'));
349
+			$user->save();
350
+			Logger::approvedUser($database, $user);
351
+
352
+			$this->getNotificationHelper()->userApproved($user);
353
+			SessionAlert::quick('Approved user ' . htmlentities($user->getUsername(), ENT_COMPAT, 'UTF-8'));
354
+
355
+			// send email
356
+			$this->sendStatusChangeEmail(
357
+				'Your WP:ACC account has been approved',
358
+				'usermanagement/emails/approved.tpl',
359
+				null,
360
+				$user,
361
+				User::getCurrent($database)->getUsername()
362
+			);
363
+
364
+			$this->redirect("userManagement");
365
+
366
+			return;
367
+		}
368
+		else {
369
+			$this->assignCSRFToken();
370
+			$this->setTemplate("usermanagement/changelevel-reason.tpl");
371
+			$this->assign("user", $user);
372
+			$this->assign("status", "Active");
373
+			$this->assign("showReason", false);
374
+		}
375
+	}
376
+
377
+	#endregion
378
+
379
+	#region Renaming / Editing
380
+
381
+	/**
382
+	 * Entry point for the rename action
383
+	 *
384
+	 * @throws ApplicationLogicException
385
+	 */
386
+	protected function rename()
387
+	{
388
+		$this->setHtmlTitle('User Management');
389
+
390
+		$database = $this->getDatabase();
391
+
392
+		$userId = WebRequest::getInt('user');
393
+		$user = User::getById($userId, $database);
394
+
395
+		if ($user === false) {
396
+			throw new ApplicationLogicException('Sorry, the user you are trying to rename could not be found.');
397
+		}
398
+
399
+		// Dual-mode action
400
+		if (WebRequest::wasPosted()) {
401
+			$this->validateCSRFToken();
402
+			$newUsername = WebRequest::postString('newname');
403
+
404
+			if ($newUsername === null || trim($newUsername) === "") {
405
+				throw new ApplicationLogicException('The new username cannot be empty');
406
+			}
407
+
408
+			if (User::getByUsername($newUsername, $database) != false) {
409
+				throw new ApplicationLogicException('The new username already exists');
410
+			}
411
+
412
+			$oldUsername = $user->getUsername();
413
+			$user->setUsername($newUsername);
414
+			$user->setUpdateVersion(WebRequest::postInt('updateversion'));
415
+
416
+			$user->save();
417
+
418
+			$logEntryData = serialize(array(
419
+				'old' => $oldUsername,
420
+				'new' => $newUsername,
421
+			));
422
+
423
+			Logger::renamedUser($database, $user, $logEntryData);
424
+
425
+			SessionAlert::quick("Changed User "
426
+				. htmlentities($oldUsername, ENT_COMPAT, 'UTF-8')
427
+				. " name to "
428
+				. htmlentities($newUsername, ENT_COMPAT, 'UTF-8'));
429
+
430
+			$this->getNotificationHelper()->userRenamed($user, $oldUsername);
431
+
432
+			// send an email to the user.
433
+			$this->assign('targetUsername', $user->getUsername());
434
+			$this->assign('toolAdmin', User::getCurrent($database)->getUsername());
435
+			$this->assign('oldUsername', $oldUsername);
436
+			$this->assign('mailingList', $this->adminMailingList);
437
+
438
+			$this->getEmailHelper()->sendMail(
439
+				$user->getEmail(),
440
+				'Your username on WP:ACC has been changed',
441
+				$this->fetchTemplate('usermanagement/emails/renamed.tpl'),
442
+				array('Reply-To' => $this->adminMailingList)
443
+			);
444
+
445
+			$this->redirect("userManagement");
446
+
447
+			return;
448
+		}
449
+		else {
450
+			$this->assignCSRFToken();
451
+			$this->setTemplate('usermanagement/renameuser.tpl');
452
+			$this->assign('user', $user);
453
+		}
454
+	}
455
+
456
+	/**
457
+	 * Entry point for the edit action
458
+	 *
459
+	 * @throws ApplicationLogicException
460
+	 */
461
+	protected function editUser()
462
+	{
463
+		$this->setHtmlTitle('User Management');
464
+
465
+		$database = $this->getDatabase();
466
+
467
+		$userId = WebRequest::getInt('user');
468
+		$user = User::getById($userId, $database);
469
+		$oauth = new OAuthUserHelper($user, $database, $this->getOAuthProtocolHelper(), $this->getSiteConfiguration());
470
+
471
+		if ($user === false) {
472
+			throw new ApplicationLogicException('Sorry, the user you are trying to edit could not be found.');
473
+		}
474
+
475
+		// Dual-mode action
476
+		if (WebRequest::wasPosted()) {
477
+			$this->validateCSRFToken();
478
+			$newEmail = WebRequest::postEmail('user_email');
479
+			$newOnWikiName = WebRequest::postString('user_onwikiname');
480
+
481
+			if ($newEmail === null) {
482
+				throw new ApplicationLogicException('Invalid email address');
483
+			}
484
+
485
+			if (!($oauth->isFullyLinked() || $oauth->isPartiallyLinked())) {
486
+				if (trim($newOnWikiName) == "") {
487
+					throw new ApplicationLogicException('New on-wiki username cannot be blank');
488
+				}
489
+
490
+				$user->setOnWikiName($newOnWikiName);
491
+				$user->setWelcomeSig(WebRequest::postString('sig'));
492
+			}
493
+
494
+			$user->setEmail($newEmail);
495
+			$user->setCreationMode(WebRequest::postInt('creationmode'));
496
+
497
+			$user->setUpdateVersion(WebRequest::postInt('updateversion'));
498
+
499
+			$user->save();
500
+
501
+			Logger::userPreferencesChange($database, $user);
502
+			$this->getNotificationHelper()->userPrefChange($user);
503
+			SessionAlert::quick('Changes to user\'s preferences have been saved');
504
+
505
+			$this->redirect("userManagement");
506
+
507
+			return;
508
+		}
509
+		else {
510
+			$this->assignCSRFToken();
511
+			$oauth = new OAuthUserHelper($user, $database, $this->getOAuthProtocolHelper(),
512
+				$this->getSiteConfiguration());
513
+			$this->setTemplate('usermanagement/edituser.tpl');
514
+			$this->assign('user', $user);
515
+			$this->assign('oauth', $oauth);
516
+
517
+			$this->assign('canManualCreate',
518
+				$this->barrierTest(User::CREATION_MANUAL, $user, 'RequestCreation'));
519
+			$this->assign('canOauthCreate',
520
+				$this->barrierTest(User::CREATION_OAUTH, $user, 'RequestCreation'));
521
+			$this->assign('canBotCreate',
522
+				$this->barrierTest(User::CREATION_BOT, $user, 'RequestCreation'));
523
+		}
524
+	}
525
+
526
+	#endregion
527
+
528
+	/**
529
+	 * Sends a status change email to the user.
530
+	 *
531
+	 * @param string      $subject           The subject of the email
532
+	 * @param string      $template          The smarty template to use
533
+	 * @param string|null $reason            The reason for performing the status change
534
+	 * @param User        $user              The user affected
535
+	 * @param string      $toolAdminUsername The tool admin's username who is making the edit
536
+	 */
537
+	private function sendStatusChangeEmail($subject, $template, $reason, $user, $toolAdminUsername)
538
+	{
539
+		$this->assign('targetUsername', $user->getUsername());
540
+		$this->assign('toolAdmin', $toolAdminUsername);
541
+		$this->assign('actionReason', $reason);
542
+		$this->assign('mailingList', $this->adminMailingList);
543
+
544
+		$this->getEmailHelper()->sendMail(
545
+			$user->getEmail(),
546
+			$subject,
547
+			$this->fetchTemplate($template),
548
+			array('Reply-To' => $this->adminMailingList)
549
+		);
550
+	}
551
+
552
+	/**
553
+	 * @param UserRole[] $activeRoles
554
+	 *
555
+	 * @return array
556
+	 */
557
+	private function getRoleData($activeRoles)
558
+	{
559
+		$availableRoles = $this->getSecurityManager()->getRoleConfiguration()->getAvailableRoles();
560
+
561
+		$currentUser = User::getCurrent($this->getDatabase());
562
+		$this->getSecurityManager()->getActiveRoles($currentUser, $userRoles, $inactiveRoles);
563
+
564
+		$initialValue = array('active' => 0, 'allowEdit' => 0, 'description' => '???', 'object' => null);
565
+
566
+		$roleData = array();
567
+		foreach ($availableRoles as $role => $data) {
568
+			$intersection = array_intersect($data['editableBy'], $userRoles);
569
+
570
+			$roleData[$role] = $initialValue;
571
+			$roleData[$role]['allowEdit'] = count($intersection) > 0 ? 1 : 0;
572
+			$roleData[$role]['description'] = $data['description'];
573
+		}
574
+
575
+		foreach ($activeRoles as $role) {
576
+			if (!isset($roleData[$role->getRole()])) {
577
+				// This value is no longer available in the configuration, allow changing (aka removing) it.
578
+				$roleData[$role->getRole()] = $initialValue;
579
+				$roleData[$role->getRole()]['allowEdit'] = 1;
580
+			}
581
+
582
+			$roleData[$role->getRole()]['object'] = $role;
583
+			$roleData[$role->getRole()]['active'] = 1;
584
+		}
585
+
586
+		return $roleData;
587
+	}
588 588
 }
Please login to merge, or discard this patch.
Spacing   +1 added lines, -1 removed lines patch added patch discarded remove patch
@@ -40,7 +40,7 @@
 block discarded – undo
40 40
         $userSearchRequest = WebRequest::getString('usersearch');
41 41
         if ($userSearchRequest !== null) {
42 42
             $searchedUser = User::getByUsername($userSearchRequest, $database);
43
-            if($searchedUser !== false) {
43
+            if ($searchedUser !== false) {
44 44
                 $this->redirect('statistics/users', 'detail', ['user' => $searchedUser->getId()]);
45 45
                 return;
46 46
             }
Please login to merge, or discard this patch.
Braces   +7 added lines, -14 removed lines patch added patch discarded remove patch
@@ -60,8 +60,7 @@  discard block
 block discarded – undo
60 60
             $this->assign("declinedUsers", $declinedUsers);
61 61
 
62 62
             UserSearchHelper::get($database)->getRoleMap($roleMap);
63
-        }
64
-        else {
63
+        } else {
65 64
             $this->assign("showAll", false);
66 65
             $this->assign("suspendedUsers", array());
67 66
             $this->assign("declinedUsers", array());
@@ -182,8 +181,7 @@  discard block
 block discarded – undo
182 181
             $this->redirect('statistics/users', 'detail', array('user' => $user->getId()));
183 182
 
184 183
             return;
185
-        }
186
-        else {
184
+        } else {
187 185
             $this->assignCSRFToken();
188 186
             $this->setTemplate('usermanagement/roleedit.tpl');
189 187
             $this->assign('user', $user);
@@ -244,8 +242,7 @@  discard block
 block discarded – undo
244 242
             $this->redirect('userManagement');
245 243
 
246 244
             return;
247
-        }
248
-        else {
245
+        } else {
249 246
             $this->assignCSRFToken();
250 247
             $this->setTemplate('usermanagement/changelevel-reason.tpl');
251 248
             $this->assign('user', $user);
@@ -309,8 +306,7 @@  discard block
 block discarded – undo
309 306
             $this->redirect('userManagement');
310 307
 
311 308
             return;
312
-        }
313
-        else {
309
+        } else {
314 310
             $this->assignCSRFToken();
315 311
             $this->setTemplate('usermanagement/changelevel-reason.tpl');
316 312
             $this->assign('user', $user);
@@ -364,8 +360,7 @@  discard block
 block discarded – undo
364 360
             $this->redirect("userManagement");
365 361
 
366 362
             return;
367
-        }
368
-        else {
363
+        } else {
369 364
             $this->assignCSRFToken();
370 365
             $this->setTemplate("usermanagement/changelevel-reason.tpl");
371 366
             $this->assign("user", $user);
@@ -445,8 +440,7 @@  discard block
 block discarded – undo
445 440
             $this->redirect("userManagement");
446 441
 
447 442
             return;
448
-        }
449
-        else {
443
+        } else {
450 444
             $this->assignCSRFToken();
451 445
             $this->setTemplate('usermanagement/renameuser.tpl');
452 446
             $this->assign('user', $user);
@@ -505,8 +499,7 @@  discard block
 block discarded – undo
505 499
             $this->redirect("userManagement");
506 500
 
507 501
             return;
508
-        }
509
-        else {
502
+        } else {
510 503
             $this->assignCSRFToken();
511 504
             $oauth = new OAuthUserHelper($user, $database, $this->getOAuthProtocolHelper(),
512 505
                 $this->getSiteConfiguration());
Please login to merge, or discard this patch.