@@ -55,7 +55,7 @@ discard block |
||
| 55 | 55 | // SQL where clause with folders list |
| 56 | 56 | if (isset($arrQueryStringParams['folders']) === true) { |
| 57 | 57 | // convert the folders to an array |
| 58 | - $arrQueryStringParams['folders'] = explode(',', str_replace( array('[',']') , '' , $arrQueryStringParams['folders'])); |
|
| 58 | + $arrQueryStringParams['folders'] = explode(',', str_replace(array('[', ']'), '', $arrQueryStringParams['folders'])); |
|
| 59 | 59 | |
| 60 | 60 | // ensure to only use the intersection |
| 61 | 61 | $foldersList = implode(',', array_intersect($arrQueryStringParams['folders'], $userData['folders_list'])); |
@@ -216,7 +216,7 @@ discard block |
||
| 216 | 216 | } else { |
| 217 | 217 | // Gérer le cas où les paramètres ne sont pas un tableau |
| 218 | 218 | $strErrorDesc = 'Data not consistent'; |
| 219 | - $strErrorHeader = 'Expected array, received ' . gettype($arrQueryStringParams); |
|
| 219 | + $strErrorHeader = 'Expected array, received '.gettype($arrQueryStringParams); |
|
| 220 | 220 | } |
| 221 | 221 | } |
| 222 | 222 | } else { |
@@ -263,10 +263,10 @@ discard block |
||
| 263 | 263 | // SQL where clause with item id |
| 264 | 264 | if (isset($arrQueryStringParams['id']) === true) { |
| 265 | 265 | // build sql where clause by ID |
| 266 | - $sqlExtra = ' WHERE i.id = '.$arrQueryStringParams['id'] . $sql_constraint; |
|
| 266 | + $sqlExtra = ' WHERE i.id = '.$arrQueryStringParams['id'].$sql_constraint; |
|
| 267 | 267 | } else if (isset($arrQueryStringParams['label']) === true) { |
| 268 | 268 | // build sql where clause by LABEL |
| 269 | - $sqlExtra = ' WHERE i.label '.(isset($arrQueryStringParams['like']) === true && (int) $arrQueryStringParams['like'] === 1 ? ' LIKE '.$arrQueryStringParams['label'] : ' = '.$arrQueryStringParams['label']) . $sql_constraint; |
|
| 269 | + $sqlExtra = ' WHERE i.label '.(isset($arrQueryStringParams['like']) === true && (int) $arrQueryStringParams['like'] === 1 ? ' LIKE '.$arrQueryStringParams['label'] : ' = '.$arrQueryStringParams['label']).$sql_constraint; |
|
| 270 | 270 | } else if (isset($arrQueryStringParams['description']) === true) { |
| 271 | 271 | // build sql where clause by LABEL |
| 272 | 272 | $sqlExtra = ' WHERE i.description '.(isset($arrQueryStringParams['like']) === true && (int) $arrQueryStringParams['like'] === 1 ? ' LIKE '.$arrQueryStringParams['description'] : ' = '.$arrQueryStringParams['description']).$sql_constraint; |
@@ -37,45 +37,45 @@ discard block |
||
| 37 | 37 | * @return boolean |
| 38 | 38 | */ |
| 39 | 39 | function is_jwt_valid($jwt) { |
| 40 | - try { |
|
| 41 | - $decoded = (array) JWT::decode($jwt, new Key(DB_PASSWD, 'HS256')); |
|
| 40 | + try { |
|
| 41 | + $decoded = (array) JWT::decode($jwt, new Key(DB_PASSWD, 'HS256')); |
|
| 42 | 42 | |
| 43 | - // Check if expiration is reached |
|
| 44 | - if ($decoded['exp'] - time() < 0) { |
|
| 45 | - return false; |
|
| 46 | - } |
|
| 43 | + // Check if expiration is reached |
|
| 44 | + if ($decoded['exp'] - time() < 0) { |
|
| 45 | + return false; |
|
| 46 | + } |
|
| 47 | 47 | /* |
| 48 | 48 | $decoded1 = JWT::decode($jwt, new Key(DB_PASSWD, 'HS256'), $headers = new stdClass()); |
| 49 | 49 | print_r($headers); |
| 50 | 50 | */ |
| 51 | 51 | |
| 52 | - return true; |
|
| 53 | - } catch (InvalidArgumentException $e) { |
|
| 54 | - // provided key/key-array is empty or malformed. |
|
| 55 | - return false; |
|
| 56 | - } catch (DomainException $e) { |
|
| 57 | - // provided algorithm is unsupported OR |
|
| 58 | - // provided key is invalid OR |
|
| 59 | - // unknown error thrown in openSSL or libsodium OR |
|
| 60 | - // libsodium is required but not available. |
|
| 61 | - return false; |
|
| 62 | - } catch (SignatureInvalidException $e) { |
|
| 63 | - // provided JWT signature verification failed. |
|
| 64 | - return false; |
|
| 65 | - } catch (BeforeValidException $e) { |
|
| 66 | - // provided JWT is trying to be used before "nbf" claim OR |
|
| 67 | - // provided JWT is trying to be used before "iat" claim. |
|
| 68 | - return false; |
|
| 69 | - } catch (ExpiredException $e) { |
|
| 70 | - // provided JWT is trying to be used after "exp" claim. |
|
| 71 | - return false; |
|
| 72 | - } catch (UnexpectedValueException $e) { |
|
| 73 | - // provided JWT is malformed OR |
|
| 74 | - // provided JWT is missing an algorithm / using an unsupported algorithm OR |
|
| 75 | - // provided JWT algorithm does not match provided key OR |
|
| 76 | - // provided key ID in key/key-array is empty or invalid. |
|
| 77 | - return false; |
|
| 78 | - } |
|
| 52 | + return true; |
|
| 53 | + } catch (InvalidArgumentException $e) { |
|
| 54 | + // provided key/key-array is empty or malformed. |
|
| 55 | + return false; |
|
| 56 | + } catch (DomainException $e) { |
|
| 57 | + // provided algorithm is unsupported OR |
|
| 58 | + // provided key is invalid OR |
|
| 59 | + // unknown error thrown in openSSL or libsodium OR |
|
| 60 | + // libsodium is required but not available. |
|
| 61 | + return false; |
|
| 62 | + } catch (SignatureInvalidException $e) { |
|
| 63 | + // provided JWT signature verification failed. |
|
| 64 | + return false; |
|
| 65 | + } catch (BeforeValidException $e) { |
|
| 66 | + // provided JWT is trying to be used before "nbf" claim OR |
|
| 67 | + // provided JWT is trying to be used before "iat" claim. |
|
| 68 | + return false; |
|
| 69 | + } catch (ExpiredException $e) { |
|
| 70 | + // provided JWT is trying to be used after "exp" claim. |
|
| 71 | + return false; |
|
| 72 | + } catch (UnexpectedValueException $e) { |
|
| 73 | + // provided JWT is malformed OR |
|
| 74 | + // provided JWT is missing an algorithm / using an unsupported algorithm OR |
|
| 75 | + // provided JWT algorithm does not match provided key OR |
|
| 76 | + // provided key ID in key/key-array is empty or invalid. |
|
| 77 | + return false; |
|
| 78 | + } |
|
| 79 | 79 | } |
| 80 | 80 | |
| 81 | 81 | function base64url_encode($data) { |
@@ -84,24 +84,24 @@ discard block |
||
| 84 | 84 | |
| 85 | 85 | function get_authorization_header() |
| 86 | 86 | { |
| 87 | - $request = symfonyRequest::createFromGlobals(); |
|
| 88 | - $authorizationHeader = $request->headers->get('Authorization'); |
|
| 89 | - $headers = null; |
|
| 87 | + $request = symfonyRequest::createFromGlobals(); |
|
| 88 | + $authorizationHeader = $request->headers->get('Authorization'); |
|
| 89 | + $headers = null; |
|
| 90 | 90 | |
| 91 | - // Check if the authorization header is not empty |
|
| 92 | - if (!empty($authorizationHeader)) { |
|
| 93 | - $headers = trim($authorizationHeader); |
|
| 94 | - } else if (function_exists('apache_request_headers') === true) { |
|
| 95 | - $requestHeaders = (array) apache_request_headers(); |
|
| 96 | - // Server-side fix for bug in old Android versions (a nice side-effect of this fix means we don't care about capitalization for Authorization) |
|
| 97 | - $requestHeaders = array_combine(array_map('ucwords', array_keys($requestHeaders)), array_values($requestHeaders)); |
|
| 98 | - //print_r($requestHeaders); |
|
| 99 | - if (isset($requestHeaders['Authorization']) === true) { |
|
| 100 | - $headers = trim($requestHeaders['Authorization']); |
|
| 101 | - } |
|
| 102 | - } |
|
| 91 | + // Check if the authorization header is not empty |
|
| 92 | + if (!empty($authorizationHeader)) { |
|
| 93 | + $headers = trim($authorizationHeader); |
|
| 94 | + } else if (function_exists('apache_request_headers') === true) { |
|
| 95 | + $requestHeaders = (array) apache_request_headers(); |
|
| 96 | + // Server-side fix for bug in old Android versions (a nice side-effect of this fix means we don't care about capitalization for Authorization) |
|
| 97 | + $requestHeaders = array_combine(array_map('ucwords', array_keys($requestHeaders)), array_values($requestHeaders)); |
|
| 98 | + //print_r($requestHeaders); |
|
| 99 | + if (isset($requestHeaders['Authorization']) === true) { |
|
| 100 | + $headers = trim($requestHeaders['Authorization']); |
|
| 101 | + } |
|
| 102 | + } |
|
| 103 | 103 | |
| 104 | - return $headers; |
|
| 104 | + return $headers; |
|
| 105 | 105 | } |
| 106 | 106 | |
| 107 | 107 | function get_bearer_token() { |
@@ -118,8 +118,8 @@ discard block |
||
| 118 | 118 | |
| 119 | 119 | function get_bearer_data($jwt) { |
| 120 | 120 | // split the jwt |
| 121 | - $tokenParts = explode('.', $jwt); |
|
| 122 | - $payload = base64_decode($tokenParts[1]); |
|
| 121 | + $tokenParts = explode('.', $jwt); |
|
| 122 | + $payload = base64_decode($tokenParts[1]); |
|
| 123 | 123 | |
| 124 | 124 | // HEADER: Get the access token from the header |
| 125 | 125 | if (empty($payload) === false) { |
@@ -39,13 +39,13 @@ discard block |
||
| 39 | 39 | header("Access-Control-Allow-Methods: POST, GET"); |
| 40 | 40 | header("Access-Control-Max-Age: 3600"); |
| 41 | 41 | header("Access-Control-Allow-Headers: Content-Type, Access-Control-Allow-Headers, Authorization, X-Requested-With"); |
| 42 | -require __DIR__ . "/inc/bootstrap.php"; |
|
| 42 | +require __DIR__."/inc/bootstrap.php"; |
|
| 43 | 43 | |
| 44 | 44 | // sanitize url segments |
| 45 | 45 | $base = new BaseController(); |
| 46 | 46 | $uri = $base->getUriSegments(); |
| 47 | 47 | if (!is_array($uri)) { |
| 48 | - $uri = [$uri]; // ensure $uril is table |
|
| 48 | + $uri = [$uri]; // ensure $uril is table |
|
| 49 | 49 | } |
| 50 | 50 | |
| 51 | 51 | // Prepare DB password |
@@ -61,9 +61,9 @@ discard block |
||
| 61 | 61 | if ($uri[0] === 'authorize') { |
| 62 | 62 | // Is API enabled in Teampass settings |
| 63 | 63 | if ($apiStatus['error'] === false) { |
| 64 | - require API_ROOT_PATH . "/Controller/Api/AuthController.php"; |
|
| 64 | + require API_ROOT_PATH."/Controller/Api/AuthController.php"; |
|
| 65 | 65 | $objFeedController = new AuthController(); |
| 66 | - $strMethodName = $uri[0] . 'Action'; |
|
| 66 | + $strMethodName = $uri[0].'Action'; |
|
| 67 | 67 | $objFeedController->{$strMethodName}(); |
| 68 | 68 | } else { |
| 69 | 69 | // Error management |
@@ -89,9 +89,9 @@ discard block |
||
| 89 | 89 | |
| 90 | 90 | // action related to USER |
| 91 | 91 | } elseif ($controller === 'user') { |
| 92 | - require API_ROOT_PATH . "/Controller/Api/UserController.php"; |
|
| 92 | + require API_ROOT_PATH."/Controller/Api/UserController.php"; |
|
| 93 | 93 | $objFeedController = new UserController(); |
| 94 | - $strMethodName = (string) $action . 'Action'; |
|
| 94 | + $strMethodName = (string) $action.'Action'; |
|
| 95 | 95 | $objFeedController->{$strMethodName}(); |
| 96 | 96 | |
| 97 | 97 | // action related to ITEM |
@@ -77,7 +77,7 @@ discard block |
||
| 77 | 77 | ) { |
| 78 | 78 | // Not allowed page |
| 79 | 79 | $session->set('system-error_code', ERR_NOT_ALLOWED); |
| 80 | - include $SETTINGS['cpassman_dir'] . '/error.php'; |
|
| 80 | + include $SETTINGS['cpassman_dir'].'/error.php'; |
|
| 81 | 81 | exit; |
| 82 | 82 | } |
| 83 | 83 | |
@@ -462,7 +462,7 @@ discard block |
||
| 462 | 462 | ); |
| 463 | 463 | |
| 464 | 464 | // add new role to user |
| 465 | - $tmp = $data_tmp['fonction_id'] . (substr($data_tmp['fonction_id'], -1) == ';' ? $role_id : ';' . $role_id); |
|
| 465 | + $tmp = $data_tmp['fonction_id'].(substr($data_tmp['fonction_id'], -1) == ';' ? $role_id : ';'.$role_id); |
|
| 466 | 466 | $session->set('user-roles', str_replace(';;', ';', $tmp)); |
| 467 | 467 | |
| 468 | 468 | // store in DB |
@@ -723,7 +723,7 @@ discard block |
||
| 723 | 723 | $groupsData = $openLdapExtra->getADGroups($ldapConnection, $SETTINGS); |
| 724 | 724 | break; |
| 725 | 725 | default: |
| 726 | - throw new Exception("Unsupported LDAP type: " . $SETTINGS['ldap_type']); |
|
| 726 | + throw new Exception("Unsupported LDAP type: ".$SETTINGS['ldap_type']); |
|
| 727 | 727 | } |
| 728 | 728 | } catch (Exception $e) { |
| 729 | 729 | if (defined('LOG_TO_SERVER') && LOG_TO_SERVER === true) { |
@@ -743,7 +743,7 @@ discard block |
||
| 743 | 743 | } else { |
| 744 | 744 | // Handle successful retrieval of groups |
| 745 | 745 | // exists in Teampass |
| 746 | - foreach($groupsData['userGroups'] as $key => $group) { |
|
| 746 | + foreach ($groupsData['userGroups'] as $key => $group) { |
|
| 747 | 747 | $role_detail = DB::queryfirstrow( |
| 748 | 748 | 'SELECT a.increment_id as increment_id, a.role_id as role_id, r.title as title |
| 749 | 749 | FROM '.prefixTable('ldap_groups_roles').' AS a |
@@ -768,7 +768,7 @@ discard block |
||
| 768 | 768 | |
| 769 | 769 | // Get all groups in Teampass |
| 770 | 770 | $teampassRoles = array(); |
| 771 | - $rows = DB::query('SELECT id,title FROM ' . prefixTable('roles_title')); |
|
| 771 | + $rows = DB::query('SELECT id,title FROM '.prefixTable('roles_title')); |
|
| 772 | 772 | foreach ($rows as $record) { |
| 773 | 773 | array_push( |
| 774 | 774 | $teampassRoles, |
@@ -80,7 +80,7 @@ discard block |
||
| 80 | 80 | ) { |
| 81 | 81 | // Not allowed page |
| 82 | 82 | $session->set('system-error_code', ERR_NOT_ALLOWED); |
| 83 | - include $SETTINGS['cpassman_dir'] . '/error.php'; |
|
| 83 | + include $SETTINGS['cpassman_dir'].'/error.php'; |
|
| 84 | 84 | exit; |
| 85 | 85 | } |
| 86 | 86 | |
@@ -154,7 +154,7 @@ discard block |
||
| 154 | 154 | $openLdapExtra = new OpenLdapExtra(); |
| 155 | 155 | break; |
| 156 | 156 | default: |
| 157 | - throw new Exception("Unsupported LDAP type: " . $SETTINGS['ldap_type']); |
|
| 157 | + throw new Exception("Unsupported LDAP type: ".$SETTINGS['ldap_type']); |
|
| 158 | 158 | } |
| 159 | 159 | } catch (Exception $e) { |
| 160 | 160 | if (defined('LOG_TO_SERVER') && LOG_TO_SERVER === true) { |
@@ -173,7 +173,7 @@ discard block |
||
| 173 | 173 | // 2- Get user info from AD |
| 174 | 174 | // We want to isolate attribute ldap_user_attribute or mostly samAccountName |
| 175 | 175 | $userADInfos = $ldapConnection->query() |
| 176 | - ->where((isset($SETTINGS['ldap_user_attribute']) ===true && empty($SETTINGS['ldap_user_attribute']) === false) ? $SETTINGS['ldap_user_attribute'] : 'samaccountname', '=', $post_username) |
|
| 176 | + ->where((isset($SETTINGS['ldap_user_attribute']) === true && empty($SETTINGS['ldap_user_attribute']) === false) ? $SETTINGS['ldap_user_attribute'] : 'samaccountname', '=', $post_username) |
|
| 177 | 177 | ->firstOrFail(); |
| 178 | 178 | |
| 179 | 179 | // Is user enabled? Only ActiveDirectory |
@@ -194,7 +194,7 @@ discard block |
||
| 194 | 194 | } catch (\LdapRecord\Query\ObjectNotFoundException $e) { |
| 195 | 195 | $error = $e->getDetailedError(); |
| 196 | 196 | if ($error && defined('LOG_TO_SERVER') && LOG_TO_SERVER === true) { |
| 197 | - error_log('TEAMPASS Error - LDAP - '.$error->getErrorCode()." - ".$error->getErrorMessage(). " - ".$error->getDiagnosticMessage()); |
|
| 197 | + error_log('TEAMPASS Error - LDAP - '.$error->getErrorCode()." - ".$error->getErrorMessage()." - ".$error->getDiagnosticMessage()); |
|
| 198 | 198 | } |
| 199 | 199 | // deepcode ignore ServerLeak: No important data is sent and is encrypted before being sent |
| 200 | 200 | echo prepareExchangedData( |
@@ -213,7 +213,7 @@ discard block |
||
| 213 | 213 | // For OpenLDAP and others, we use attribute dn |
| 214 | 214 | $userAuthAttempt = $ldapConnection->auth()->attempt( |
| 215 | 215 | $SETTINGS['ldap_type'] === 'ActiveDirectory' ? |
| 216 | - $userADInfos['userprincipalname'][0] : // refering to https://ldaprecord.com/docs/core/v2/authentication#basic-authentication |
|
| 216 | + $userADInfos['userprincipalname'][0] : // refering to https://ldaprecord.com/docs/core/v2/authentication#basic-authentication |
|
| 217 | 217 | $userADInfos['dn'], |
| 218 | 218 | $post_password |
| 219 | 219 | ); |
@@ -232,7 +232,7 @@ discard block |
||
| 232 | 232 | } catch (\LdapRecord\Query\ObjectNotFoundException $e) { |
| 233 | 233 | $error = $e->getDetailedError(); |
| 234 | 234 | if ($error && defined('LOG_TO_SERVER') && LOG_TO_SERVER === true) { |
| 235 | - error_log('TEAMPASS Error - LDAP - '.$error->getErrorCode()." - ".$error->getErrorMessage(). " - ".$error->getDiagnosticMessage()); |
|
| 235 | + error_log('TEAMPASS Error - LDAP - '.$error->getErrorCode()." - ".$error->getErrorMessage()." - ".$error->getDiagnosticMessage()); |
|
| 236 | 236 | } |
| 237 | 237 | // deepcode ignore ServerLeak: No important data is sent and is encrypted before being sent |
| 238 | 238 | echo prepareExchangedData( |
@@ -102,11 +102,11 @@ discard block |
||
| 102 | 102 | function provideLog(string $message, array $SETTINGS) |
| 103 | 103 | { |
| 104 | 104 | if (defined('LOG_TO_SERVER') && LOG_TO_SERVER === true) { |
| 105 | - error_log((string) date($SETTINGS['date_format'] . ' ' . $SETTINGS['time_format'], time()) . ' - '.$message); |
|
| 105 | + error_log((string) date($SETTINGS['date_format'].' '.$SETTINGS['time_format'], time()).' - '.$message); |
|
| 106 | 106 | } |
| 107 | 107 | } |
| 108 | 108 | |
| 109 | -function performVisibleFoldersHtmlUpdate (int $user_id) |
|
| 109 | +function performVisibleFoldersHtmlUpdate(int $user_id) |
|
| 110 | 110 | { |
| 111 | 111 | $html = []; |
| 112 | 112 | |
@@ -116,10 +116,10 @@ discard block |
||
| 116 | 116 | |
| 117 | 117 | // get current folders visible for user |
| 118 | 118 | $cache_tree = DB::queryFirstRow( |
| 119 | - 'SELECT increment_id, data FROM ' . prefixTable('cache_tree') . ' WHERE user_id = %i', |
|
| 119 | + 'SELECT increment_id, data FROM '.prefixTable('cache_tree').' WHERE user_id = %i', |
|
| 120 | 120 | $user_id |
| 121 | 121 | ); |
| 122 | - $folders = json_decode($cache_tree['data'], true);//print_r($folders); |
|
| 122 | + $folders = json_decode($cache_tree['data'], true); //print_r($folders); |
|
| 123 | 123 | foreach ($folders as $folder) { |
| 124 | 124 | $idFolder = (int) explode("li_", $folder['id'])[1]; |
| 125 | 125 | |
@@ -132,7 +132,7 @@ discard block |
||
| 132 | 132 | |
| 133 | 133 | // get folder info |
| 134 | 134 | $folder = DB::queryFirstRow( |
| 135 | - 'SELECT title, parent_id, personal_folder FROM ' . prefixTable('nested_tree') . ' WHERE id = %i', |
|
| 135 | + 'SELECT title, parent_id, personal_folder FROM '.prefixTable('nested_tree').' WHERE id = %i', |
|
| 136 | 136 | $idFolder |
| 137 | 137 | ); |
| 138 | 138 | |
@@ -167,7 +167,7 @@ discard block |
||
| 167 | 167 | function subTaskStatus($taskId) |
| 168 | 168 | { |
| 169 | 169 | $subTasks = DB::query( |
| 170 | - 'SELECT * FROM ' . prefixTable('background_subtasks') . ' WHERE task_id = %i', |
|
| 170 | + 'SELECT * FROM '.prefixTable('background_subtasks').' WHERE task_id = %i', |
|
| 171 | 171 | $taskId |
| 172 | 172 | ); |
| 173 | 173 | |
@@ -149,8 +149,7 @@ |
||
| 149 | 149 | </div> |
| 150 | 150 | <?php |
| 151 | 151 | } |
| 152 | -} |
|
| 153 | -catch (Exception $e) { |
|
| 152 | +} catch (Exception $e) { |
|
| 154 | 153 | if (defined('LOG_TO_SERVER') && LOG_TO_SERVER === true) { |
| 155 | 154 | error_log('TEAMPASS Error - tasks page - '.$e->getMessage()); |
| 156 | 155 | } |
@@ -64,7 +64,7 @@ discard block |
||
| 64 | 64 | if ($checkUserAccess->checkSession() === false || $checkUserAccess->userAccessPage('tasks') === false) { |
| 65 | 65 | // Not allowed page |
| 66 | 66 | $session->set('system-error_code', ERR_NOT_ALLOWED); |
| 67 | - include $SETTINGS['cpassman_dir'] . '/error.php'; |
|
| 67 | + include $SETTINGS['cpassman_dir'].'/error.php'; |
|
| 68 | 68 | exit; |
| 69 | 69 | } |
| 70 | 70 | |
@@ -126,7 +126,7 @@ discard block |
||
| 126 | 126 | // Get last cron execution timestamp |
| 127 | 127 | $queryResults = DB::query( |
| 128 | 128 | 'SELECT valeur |
| 129 | - FROM ' . prefixTable('misc') . ' |
|
| 129 | + FROM ' . prefixTable('misc').' |
|
| 130 | 130 | WHERE type = %s AND intitule = %s and valeur >= %d', |
| 131 | 131 | 'admin', |
| 132 | 132 | 'last_cron_exec', |
@@ -234,7 +234,7 @@ discard block |
||
| 234 | 234 | $task = isset($SETTINGS['users_personal_folder_task']) === true ? explode(";", $SETTINGS['users_personal_folder_task']) : []; |
| 235 | 235 | ?> |
| 236 | 236 | <input type='text' disabled class='form-control form-control-sm' id='users_personal_folder_task_parameter' value='<?php echo isset($task[0]) === true && empty($task[0]) === false ? $lang->get($task[0])." ".(isset($task[2]) === true ? strtolower($lang->get('day')).' '.$task[2].' ' : '').$lang->get('at')." ".(isset($task[1]) === true ? $task[1] : '') : $lang->get('not_defined') ?>'> |
| 237 | - <input type='hidden' disabled class='form-control form-control-sm' id='users_personal_folder_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : '';?>'> |
|
| 237 | + <input type='hidden' disabled class='form-control form-control-sm' id='users_personal_folder_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : ''; ?>'> |
|
| 238 | 238 | </div> |
| 239 | 239 | <div class='col-2'> |
| 240 | 240 | <button class="btn btn-primary task-define" data-task="users_personal_folder_task"> |
@@ -256,7 +256,7 @@ discard block |
||
| 256 | 256 | $task = isset($SETTINGS['clean_orphan_objects_task']) === true ? explode(";", $SETTINGS['clean_orphan_objects_task']) : []; |
| 257 | 257 | ?> |
| 258 | 258 | <input type='text' disabled class='form-control form-control-sm' id='clean_orphan_objects_task_parameter' value='<?php echo isset($task[0]) === true && empty($task[0]) === false ? $lang->get($task[0])." ".(isset($task[2]) === true ? strtolower($lang->get('day')).' '.$task[2].' ' : '').$lang->get('at')." ".(isset($task[1]) === true ? $task[1] : '') : $lang->get('not_defined') ?>'> |
| 259 | - <input type='hidden' disabled class='form-control form-control-sm' id='clean_orphan_objects_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : '';?>'> |
|
| 259 | + <input type='hidden' disabled class='form-control form-control-sm' id='clean_orphan_objects_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : ''; ?>'> |
|
| 260 | 260 | </div> |
| 261 | 261 | <div class='col-2'> |
| 262 | 262 | <button class="btn btn-primary task-define" data-task="clean_orphan_objects_task"> |
@@ -278,7 +278,7 @@ discard block |
||
| 278 | 278 | $task = isset($SETTINGS['purge_temporary_files_task']) === true ? explode(";", $SETTINGS['purge_temporary_files_task']) : []; |
| 279 | 279 | ?> |
| 280 | 280 | <input type='text' disabled class='form-control form-control-sm' id='purge_temporary_files_task_parameter' value='<?php echo isset($task[0]) === true && empty($task[0]) === false ? $lang->get($task[0])." ".(isset($task[2]) === true ? strtolower($lang->get('day')).' '.$task[2].' ' : '').$lang->get('at')." ".(isset($task[1]) === true ? $task[1] : '') : $lang->get('not_defined') ?>'> |
| 281 | - <input type='hidden' disabled class='form-control form-control-sm' id='purge_temporary_files_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : '';?>'> |
|
| 281 | + <input type='hidden' disabled class='form-control form-control-sm' id='purge_temporary_files_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : ''; ?>'> |
|
| 282 | 282 | </div> |
| 283 | 283 | <div class='col-2'> |
| 284 | 284 | <button class="btn btn-primary task-define" data-task="purge_temporary_files_task"> |
@@ -300,7 +300,7 @@ discard block |
||
| 300 | 300 | $task = isset($SETTINGS['reload_cache_table_task']) === true ? explode(";", $SETTINGS['reload_cache_table_task']) : []; |
| 301 | 301 | ?> |
| 302 | 302 | <input type='text' disabled class='form-control form-control-sm' id='reload_cache_table_task_parameter' value='<?php echo isset($task[0]) === true && empty($task[0]) === false ? $lang->get($task[0])." ".(isset($task[2]) === true ? strtolower($lang->get('day')).' '.$task[2].' ' : '').$lang->get('at')." ".(isset($task[1]) === true ? $task[1] : '') : $lang->get('not_defined') ?>'> |
| 303 | - <input type='hidden' disabled class='form-control form-control-sm' id='reload_cache_table_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : '';?>'> |
|
| 303 | + <input type='hidden' disabled class='form-control form-control-sm' id='reload_cache_table_task_parameter_value' value='<?php echo isset($task[0]) === true ? $task[0].";".(isset($task[1]) === true ? $task[1] : '').(isset($task[2]) === true ? $task[2] : '') : ''; ?>'> |
|
| 304 | 304 | </div> |
| 305 | 305 | <div class='col-2'> |
| 306 | 306 | <button class="btn btn-primary task-define" data-task="reload_cache_table_task"> |
@@ -517,7 +517,7 @@ discard block |
||
| 517 | 517 | <h5><?php echo $lang->get('day_of_month'); ?></h5> |
| 518 | 518 | <select class='form-control form-control-sm no-save' id='task-define-modal-parameter-monthly-value' style="width:100%;"> |
| 519 | 519 | <?php |
| 520 | - for ($i=1; $i<=31; $i++) { |
|
| 520 | + for ($i = 1; $i <= 31; $i++) { |
|
| 521 | 521 | echo '<option value="'.$i.'">'.$lang->get('day').' '.$i.'</option>'; |
| 522 | 522 | } |
| 523 | 523 | ?> |
@@ -222,8 +222,7 @@ |
||
| 222 | 222 | </div> |
| 223 | 223 | <?php |
| 224 | 224 | } |
| 225 | -} |
|
| 226 | -catch (Exception $e) { |
|
| 225 | +} catch (Exception $e) { |
|
| 227 | 226 | if (defined('LOG_TO_SERVER') && LOG_TO_SERVER === true) { |
| 228 | 227 | error_log('TEAMPASS Error - admin page - '.$e->getMessage()); |
| 229 | 228 | } |
@@ -68,7 +68,7 @@ discard block |
||
| 68 | 68 | if ($checkUserAccess->checkSession() === false || $checkUserAccess->userAccessPage('admin') === false) { |
| 69 | 69 | // Not allowed page |
| 70 | 70 | $session->set('system-error_code', ERR_NOT_ALLOWED); |
| 71 | - include $SETTINGS['cpassman_dir'] . '/error.php'; |
|
| 71 | + include $SETTINGS['cpassman_dir'].'/error.php'; |
|
| 72 | 72 | exit; |
| 73 | 73 | } |
| 74 | 74 | |
@@ -199,7 +199,7 @@ discard block |
||
| 199 | 199 | // Get last cron execution timestamp |
| 200 | 200 | DB::query( |
| 201 | 201 | 'SELECT valeur |
| 202 | - FROM ' . prefixTable('misc') . ' |
|
| 202 | + FROM ' . prefixTable('misc').' |
|
| 203 | 203 | WHERE type = %s AND intitule = %s and valeur >= %d', |
| 204 | 204 | 'admin', |
| 205 | 205 | 'last_cron_exec', |
@@ -270,7 +270,7 @@ discard block |
||
| 270 | 270 | <div class="card-body"> |
| 271 | 271 | <?php |
| 272 | 272 | // Display information about server |
| 273 | - $dbSize = DB::queryFirstRow("SELECT ROUND(SUM(data_length + index_length) / 1024 / 1024, 2) AS 'size' FROM information_schema.TABLES WHERE table_schema = '" . DB_NAME . "'"); |
|
| 273 | + $dbSize = DB::queryFirstRow("SELECT ROUND(SUM(data_length + index_length) / 1024 / 1024, 2) AS 'size' FROM information_schema.TABLES WHERE table_schema = '".DB_NAME."'"); |
|
| 274 | 274 | |
| 275 | 275 | // Get OS |
| 276 | 276 | $uname = php_uname('s'); |
@@ -326,17 +326,17 @@ discard block |
||
| 326 | 326 | } |
| 327 | 327 | |
| 328 | 328 | echo |
| 329 | - '<p>' . $os. |
|
| 329 | + '<p>'.$os. |
|
| 330 | 330 | '<br><span class="ml-4"></span>'. |
| 331 | 331 | '</p>'. |
| 332 | 332 | $internetAccess. |
| 333 | - '<p><i class="fa-brands fa-php mr-2"></i>PHP version: ' . phpversion(). |
|
| 333 | + '<p><i class="fa-brands fa-php mr-2"></i>PHP version: '.phpversion(). |
|
| 334 | 334 | '<br><span class="ml-4">Memory limit: '.(ini_get('memory_limit')).'</span>'. |
| 335 | 335 | '<br><span class="ml-4">Memory usage: '.formatSizeUnits(memory_get_usage()).'</span>'. |
| 336 | 336 | '<br><span class="ml-4">Maximum time execution: '.ini_get('max_execution_time').'</span>'. |
| 337 | 337 | '<br><span class="ml-4">Maximum file size upload: '.ini_get('upload_max_filesize').'</span>'. |
| 338 | 338 | '</p>'. |
| 339 | - '<p><i class="fa-solid fa-server mr-2"></i>Server version: ' . DB::serverVersion(). |
|
| 339 | + '<p><i class="fa-solid fa-server mr-2"></i>Server version: '.DB::serverVersion(). |
|
| 340 | 340 | '<br><span class="ml-4">Database size: '.($dbSize['size']).'MB</span>'. |
| 341 | 341 | '</p>'; |
| 342 | 342 | |
@@ -344,11 +344,11 @@ discard block |
||
| 344 | 344 | $serverTime = localtime(time(), true); |
| 345 | 345 | echo '<div class="row">'. |
| 346 | 346 | '<div class="col-6"><i class="fa-solid fa-clock mr-2"></i>Server time:</div>'. |
| 347 | - '<div class="col-6"><span class="badge badge-info">' . |
|
| 348 | - str_pad(strval($serverTime['tm_hour']), 2, "0", STR_PAD_LEFT) . ':' . |
|
| 349 | - str_pad(strval($serverTime['tm_min']), 2, "0", STR_PAD_LEFT) . ':' . |
|
| 350 | - str_pad(strval($serverTime['tm_sec']), 2, "0", STR_PAD_LEFT) . |
|
| 351 | - '</span></div>' . |
|
| 347 | + '<div class="col-6"><span class="badge badge-info">'. |
|
| 348 | + str_pad(strval($serverTime['tm_hour']), 2, "0", STR_PAD_LEFT).':'. |
|
| 349 | + str_pad(strval($serverTime['tm_min']), 2, "0", STR_PAD_LEFT).':'. |
|
| 350 | + str_pad(strval($serverTime['tm_sec']), 2, "0", STR_PAD_LEFT). |
|
| 351 | + '</span></div>'. |
|
| 352 | 352 | '</div>'. |
| 353 | 353 | '<div class="row">'. |
| 354 | 354 | '<div class="col-6"><span class="ml-4">Timezone:</span></div>'. |
@@ -57,16 +57,16 @@ discard block |
||
| 57 | 57 | { |
| 58 | 58 | // Load AntiXSS |
| 59 | 59 | $antiXss = new AntiXSS(); |
| 60 | - if (! headers_sent()) { //If headers not sent yet... then do php redirect |
|
| 61 | - header('Location: ' . $antiXss->xss_clean($url)); |
|
| 60 | + if (!headers_sent()) { //If headers not sent yet... then do php redirect |
|
| 61 | + header('Location: '.$antiXss->xss_clean($url)); |
|
| 62 | 62 | } |
| 63 | 63 | |
| 64 | 64 | //If headers are sent... do java redirect... if java disabled, do html redirect. |
| 65 | 65 | echo '<script type="text/javascript">'; |
| 66 | - echo 'window.location.href="' . $antiXss->xss_clean($url) . '";'; |
|
| 66 | + echo 'window.location.href="'.$antiXss->xss_clean($url).'";'; |
|
| 67 | 67 | echo '</script>'; |
| 68 | 68 | echo '<noscript>'; |
| 69 | - echo '<meta http-equiv="refresh" content="0;url=' . $antiXss->xss_clean($url) . '" />'; |
|
| 69 | + echo '<meta http-equiv="refresh" content="0;url='.$antiXss->xss_clean($url).'" />'; |
|
| 70 | 70 | echo '</noscript>'; |
| 71 | 71 | } |
| 72 | 72 | |
@@ -92,7 +92,7 @@ discard block |
||
| 92 | 92 | && isset($SETTINGS['enable_sts']) === true |
| 93 | 93 | && (int) $SETTINGS['enable_sts'] === 1 |
| 94 | 94 | ) { |
| 95 | - teampassRedirect('https://' . $server['http_host'] . $server['request_uri']); |
|
| 95 | + teampassRedirect('https://'.$server['http_host'].$server['request_uri']); |
|
| 96 | 96 | } |
| 97 | 97 | |
| 98 | 98 | // Load pwComplexity |
@@ -113,11 +113,11 @@ discard block |
||
| 113 | 113 | // LOAD CPASSMAN SETTINGS |
| 114 | 114 | if ( |
| 115 | 115 | isset($SETTINGS['cpassman_dir']) === true |
| 116 | - && is_dir($SETTINGS['cpassman_dir'] . '/install') === true |
|
| 116 | + && is_dir($SETTINGS['cpassman_dir'].'/install') === true |
|
| 117 | 117 | ) { |
| 118 | 118 | // Should we delete folder INSTALL? |
| 119 | 119 | $row = DB::queryFirstRow( |
| 120 | - 'SELECT valeur FROM ' . prefixTable('misc') . ' WHERE type=%s AND intitule=%s', |
|
| 120 | + 'SELECT valeur FROM '.prefixTable('misc').' WHERE type=%s AND intitule=%s', |
|
| 121 | 121 | 'install', |
| 122 | 122 | 'clear_install_folder' |
| 123 | 123 | ); |
@@ -135,11 +135,11 @@ discard block |
||
| 135 | 135 | if ($directories !== false) { |
| 136 | 136 | $files = array_diff($directories, ['.', '..']); |
| 137 | 137 | foreach ($files as $file) { |
| 138 | - if (is_dir($dir . '/' . $file)) { |
|
| 139 | - delTree($dir . '/' . $file); |
|
| 138 | + if (is_dir($dir.'/'.$file)) { |
|
| 139 | + delTree($dir.'/'.$file); |
|
| 140 | 140 | } else { |
| 141 | 141 | try { |
| 142 | - unlink($dir . '/' . $file); |
|
| 142 | + unlink($dir.'/'.$file); |
|
| 143 | 143 | } catch (Exception $e) { |
| 144 | 144 | // do nothing... php will ignore and continue |
| 145 | 145 | } |
@@ -153,13 +153,13 @@ discard block |
||
| 153 | 153 | return false; |
| 154 | 154 | } |
| 155 | 155 | |
| 156 | - if (is_dir($SETTINGS['cpassman_dir'] . '/install')) { |
|
| 156 | + if (is_dir($SETTINGS['cpassman_dir'].'/install')) { |
|
| 157 | 157 | // Set the permissions on the install directory and delete |
| 158 | 158 | // is server Windows or Linux? |
| 159 | 159 | if (strtoupper(substr(PHP_OS, 0, 3)) !== 'WIN') { |
| 160 | - recursiveChmod($SETTINGS['cpassman_dir'] . '/install', 0755, 0440); |
|
| 160 | + recursiveChmod($SETTINGS['cpassman_dir'].'/install', 0755, 0440); |
|
| 161 | 161 | } |
| 162 | - delTree($SETTINGS['cpassman_dir'] . '/install'); |
|
| 162 | + delTree($SETTINGS['cpassman_dir'].'/install'); |
|
| 163 | 163 | } |
| 164 | 164 | |
| 165 | 165 | // Delete temporary install table |
@@ -177,10 +177,10 @@ discard block |
||
| 177 | 177 | // Load Languages stuff |
| 178 | 178 | if (isset($languagesList) === false) { |
| 179 | 179 | $languagesList = []; |
| 180 | - $rows = DB::query('SELECT * FROM ' . prefixTable('languages') . ' GROUP BY name, label, code, flag, id ORDER BY name ASC'); |
|
| 180 | + $rows = DB::query('SELECT * FROM '.prefixTable('languages').' GROUP BY name, label, code, flag, id ORDER BY name ASC'); |
|
| 181 | 181 | foreach ($rows as $record) { |
| 182 | 182 | array_push($languagesList, $record['name']); |
| 183 | - if ($session->get('user-language') === $record['name'] ) { |
|
| 183 | + if ($session->get('user-language') === $record['name']) { |
|
| 184 | 184 | $session->set('user-language_flag', $record['flag']); |
| 185 | 185 | $session->set('user-language_code', $record['code']); |
| 186 | 186 | //$session->set('user-language_label', $record['label']); |
@@ -237,7 +237,7 @@ discard block |
||
| 237 | 237 | // CHECK IF SESSION EXISTS AND IF SESSION IS VALID |
| 238 | 238 | if (empty($session->get('user-session_duration')) === false) { |
| 239 | 239 | $dataSession = DB::queryFirstRow( |
| 240 | - 'SELECT key_tempo FROM ' . prefixTable('users') . ' WHERE id=%i', |
|
| 240 | + 'SELECT key_tempo FROM '.prefixTable('users').' WHERE id=%i', |
|
| 241 | 241 | $session->get('user-id') |
| 242 | 242 | ); |
| 243 | 243 | } else { |
@@ -292,7 +292,7 @@ discard block |
||
| 292 | 292 | && ($session->has('user-admin') && $session->get('user-admin') && null !== $session->get('user-admin') && $session->get('user-admin') === 1) |
| 293 | 293 | ) { |
| 294 | 294 | $row = DB::queryFirstRow( |
| 295 | - 'SELECT valeur FROM ' . prefixTable('misc') . ' WHERE type=%s_type AND intitule=%s_intitule', |
|
| 295 | + 'SELECT valeur FROM '.prefixTable('misc').' WHERE type=%s_type AND intitule=%s_intitule', |
|
| 296 | 296 | [ |
| 297 | 297 | 'type' => 'admin', |
| 298 | 298 | 'intitule' => 'teampass_version', |
@@ -333,7 +333,7 @@ discard block |
||
| 333 | 333 | |
| 334 | 334 | syslog( |
| 335 | 335 | LOG_WARNING, |
| 336 | - 'Unlog user: ' . date('Y/m/d H:i:s') . " {$server['remote_addr']} ({$server['http_user_agent']})" |
|
| 336 | + 'Unlog user: '.date('Y/m/d H:i:s')." {$server['remote_addr']} ({$server['http_user_agent']})" |
|
| 337 | 337 | ); |
| 338 | 338 | // erase session table |
| 339 | 339 | $session->invalidate(); |
@@ -389,7 +389,7 @@ discard block |
||
| 389 | 389 | if ($session->has('user-timezone') && null !== $session->get('user-id') && empty($session->get('user-id')) === false) { |
| 390 | 390 | // query on user |
| 391 | 391 | $data = DB::queryfirstrow( |
| 392 | - 'SELECT login, admin, gestionnaire, can_manage_all_users, groupes_visibles, groupes_interdits, fonction_id, last_connexion, roles_from_ad_groups, auth_type, last_pw_change FROM ' . prefixTable('users') . ' WHERE id=%i', |
|
| 392 | + 'SELECT login, admin, gestionnaire, can_manage_all_users, groupes_visibles, groupes_interdits, fonction_id, last_connexion, roles_from_ad_groups, auth_type, last_pw_change FROM '.prefixTable('users').' WHERE id=%i', |
|
| 393 | 393 | $session->get('user-id') |
| 394 | 394 | ); |
| 395 | 395 | //Check if user has been deleted or unlogged |
@@ -436,7 +436,7 @@ discard block |
||
| 436 | 436 | $data['groupes_visibles'], |
| 437 | 437 | $data['groupes_interdits'], |
| 438 | 438 | $data['admin'], |
| 439 | - is_null($data['roles_from_ad_groups']) === true ? $data['fonction_id'] : (empty($data['roles_from_ad_groups']) === true ? $data['fonction_id'] : $data['fonction_id'] . ';' . $data['roles_from_ad_groups']), |
|
| 439 | + is_null($data['roles_from_ad_groups']) === true ? $data['fonction_id'] : (empty($data['roles_from_ad_groups']) === true ? $data['fonction_id'] : $data['fonction_id'].';'.$data['roles_from_ad_groups']), |
|
| 440 | 440 | $SETTINGS |
| 441 | 441 | ); |
| 442 | 442 | if ($session->has('user-can_create_root_folder') && (int) $session->get('user-can_create_root_folder') && null !== $session->get('user-can_create_root_folder') && (int) $session->get('user-can_create_root_folder') === 1) { |
@@ -471,7 +471,7 @@ discard block |
||
| 471 | 471 | $session->set('system-item_fields', []); |
| 472 | 472 | $rows = DB::query( |
| 473 | 473 | 'SELECT * |
| 474 | - FROM ' . prefixTable('categories') . ' |
|
| 474 | + FROM ' . prefixTable('categories').' |
|
| 475 | 475 | WHERE level=%i', |
| 476 | 476 | '0' |
| 477 | 477 | ); |
@@ -480,7 +480,7 @@ discard block |
||
| 480 | 480 | // get each field |
| 481 | 481 | $rows2 = DB::query( |
| 482 | 482 | 'SELECT * |
| 483 | - FROM ' . prefixTable('categories') . ' |
|
| 483 | + FROM ' . prefixTable('categories').' |
|
| 484 | 484 | WHERE parent_id=%i |
| 485 | 485 | ORDER BY `order` ASC', |
| 486 | 486 | $record['id'] |
@@ -567,5 +567,5 @@ discard block |
||
| 567 | 567 | } |
| 568 | 568 | |
| 569 | 569 | /* CHECK NUMBER OF USER ONLINE */ |
| 570 | -DB::query('SELECT * FROM ' . prefixTable('users') . ' WHERE timestamp>=%i', time() - 600); |
|
| 570 | +DB::query('SELECT * FROM '.prefixTable('users').' WHERE timestamp>=%i', time() - 600); |
|
| 571 | 571 | $session->set('system-nb_users_online', DB::count()); |