1
|
|
|
<?php |
2
|
|
|
/** |
3
|
|
|
* Approve donors page controller class file |
4
|
|
|
* |
5
|
|
|
* @package EBloodBank |
6
|
|
|
* @subpackage Controllers |
7
|
|
|
* @since 1.1 |
8
|
|
|
*/ |
9
|
|
|
namespace EBloodBank\Controllers; |
10
|
|
|
|
11
|
|
|
use EBloodBank as EBB; |
12
|
|
|
|
13
|
|
|
/** |
14
|
|
|
* Approve donors page controller class |
15
|
|
|
* |
16
|
|
|
* @since 1.1 |
17
|
|
|
*/ |
18
|
|
|
class ApproveDonors extends Controller |
19
|
|
|
{ |
20
|
|
|
/** |
21
|
|
|
* @var \EBloodBank\Models\Donor[] |
22
|
|
|
* @since 1.1 |
23
|
|
|
*/ |
24
|
|
|
protected $donors = []; |
25
|
|
|
|
26
|
|
|
/** |
27
|
|
|
* @return void |
28
|
|
|
* @since 1.1 |
29
|
|
|
*/ |
30
|
|
|
public function __invoke() |
31
|
|
|
{ |
32
|
|
|
if (! $this->hasAuthenticatedUser() || ! $this->getAcl()->isUserAllowed($this->getAuthenticatedUser(), 'Donor', 'approve')) { |
33
|
|
|
$this->viewFactory->displayView('error-403'); |
34
|
|
|
return; |
35
|
|
|
} |
36
|
|
|
|
37
|
|
|
if (filter_has_var(INPUT_POST, 'donors')) { |
38
|
|
|
$donorsIDs = filter_input(INPUT_POST, 'donors', FILTER_SANITIZE_NUMBER_INT, FILTER_REQUIRE_ARRAY); |
39
|
|
|
if (! empty($donorsIDs) && is_array($donorsIDs)) { |
40
|
|
|
$this->donors = $this->getDonorRepository()->findBy(['id' => $donorsIDs]); |
41
|
|
|
} |
42
|
|
|
} |
43
|
|
|
|
44
|
|
|
$this->doActions(); |
45
|
|
|
$this->viewFactory->displayView( |
46
|
|
|
'approve-donors', |
47
|
|
|
[ |
48
|
|
|
'donors' => $this->donors, |
49
|
|
|
] |
50
|
|
|
); |
51
|
|
|
} |
52
|
|
|
|
53
|
|
|
/** |
54
|
|
|
* @return void |
55
|
|
|
* @since 1.1 |
56
|
|
|
*/ |
57
|
|
|
protected function doActions() |
58
|
|
|
{ |
59
|
|
|
switch (filter_input(INPUT_POST, 'action')) { |
60
|
|
|
case 'approve_donors': |
61
|
|
|
$this->doApproveAction(); |
62
|
|
|
break; |
63
|
|
|
} |
64
|
|
|
} |
65
|
|
|
|
66
|
|
|
/** |
67
|
|
|
* @return void |
68
|
|
|
* @since 1.1 |
69
|
|
|
*/ |
70
|
|
|
protected function doApproveAction() |
71
|
|
|
{ |
72
|
|
|
if (! $this->hasAuthenticatedUser() || ! $this->getAcl()->isUserAllowed($this->getAuthenticatedUser(), 'Donor', 'approve')) { |
73
|
|
|
return; |
74
|
|
|
} |
75
|
|
|
|
76
|
|
|
$actionToken = filter_input(INPUT_POST, 'token'); |
77
|
|
|
$sessionToken = $this->getSession()->getCsrfToken(); |
78
|
|
|
|
79
|
|
|
if (! $actionToken || ! $sessionToken->isValid($actionToken)) { |
80
|
|
|
return; |
81
|
|
|
} |
82
|
|
|
|
83
|
|
|
$donors = $this->donors; |
84
|
|
|
|
85
|
|
|
if (! $donors || ! is_array($donors)) { |
|
|
|
|
86
|
|
|
return; |
87
|
|
|
} |
88
|
|
|
|
89
|
|
|
$approvedDonorsCount = 0; |
90
|
|
|
|
91
|
|
|
foreach ($donors as $donor) { |
92
|
|
|
if (! $donor->isPending()) { |
93
|
|
|
continue; |
94
|
|
|
} |
95
|
|
|
if ($this->getAcl()->canApproveDonor($this->getAuthenticatedUser(), $donor)) { |
96
|
|
|
$donor->set('status', 'approved'); |
97
|
|
|
$approvedDonorsCount++; |
98
|
|
|
} |
99
|
|
|
} |
100
|
|
|
|
101
|
|
|
$this->getEntityManager()->flush(); |
102
|
|
|
|
103
|
|
|
EBB\redirect( |
|
|
|
|
104
|
|
|
EBB\addQueryArgs( |
|
|
|
|
105
|
|
|
EBB\getEditDonorsURL(), |
|
|
|
|
106
|
|
|
['flag-approved' => $approvedDonorsCount] |
107
|
|
|
) |
108
|
|
|
); |
109
|
|
|
} |
110
|
|
|
} |
111
|
|
|
|
This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.
Consider making the comparison explicit by using
empty(..)
or! empty(...)
instead.