@@ -122,7 +122,7 @@ discard block |
||
122 | 122 | DB::update( |
123 | 123 | prefixTable('background_subtasks'), |
124 | 124 | array( |
125 | - 'sub_task_in_progress' => 0, // flag sub task is no more in prgoress |
|
125 | + 'sub_task_in_progress' => 0, // flag sub task is no more in prgoress |
|
126 | 126 | 'is_in_progress' => 0, |
127 | 127 | 'finished_at' => time(), |
128 | 128 | 'updated_at' => time(), |
@@ -158,7 +158,7 @@ discard block |
||
158 | 158 | // Check if user exists |
159 | 159 | $userInfo = DB::queryFirstRow( |
160 | 160 | 'SELECT public_key, private_key |
161 | - FROM ' . prefixTable('users') . ' |
|
161 | + FROM ' . prefixTable('users').' |
|
162 | 162 | WHERE id = %i', |
163 | 163 | $post_user_id |
164 | 164 | ); |
@@ -271,13 +271,13 @@ discard block |
||
271 | 271 | { |
272 | 272 | $userInfo = DB::queryFirstRow( |
273 | 273 | 'SELECT pw, public_key, private_key, login, name |
274 | - FROM ' . prefixTable('users') . ' |
|
274 | + FROM ' . prefixTable('users').' |
|
275 | 275 | WHERE id = %i', |
276 | 276 | $owner_id |
277 | 277 | ); |
278 | 278 | |
279 | 279 | // decrypt owner password |
280 | - $pwd = cryption($owner_pwd, '','decrypt', $SETTINGS)['string']; |
|
280 | + $pwd = cryption($owner_pwd, '', 'decrypt', $SETTINGS)['string']; |
|
281 | 281 | // decrypt private key and send back |
282 | 282 | return [ |
283 | 283 | 'private_key' => decryptPrivateKey($pwd, $userInfo['private_key']), |
@@ -317,10 +317,10 @@ discard block |
||
317 | 317 | // Loop on items |
318 | 318 | $rows = DB::query( |
319 | 319 | 'SELECT id, pw, perso |
320 | - FROM ' . prefixTable('items') . ' |
|
320 | + FROM ' . prefixTable('items').' |
|
321 | 321 | WHERE perso = %i |
322 | 322 | ORDER BY id ASC |
323 | - LIMIT ' . $post_start . ', ' . $post_length, |
|
323 | + LIMIT ' . $post_start.', '.$post_length, |
|
324 | 324 | ($extra_arguments['only_personal_items'] ?? 0) === 1 ? 1 : 0 |
325 | 325 | ); |
326 | 326 | |
@@ -328,7 +328,7 @@ discard block |
||
328 | 328 | // Get itemKey from current user |
329 | 329 | $currentUserKey = DB::queryFirstRow( |
330 | 330 | 'SELECT share_key, increment_id |
331 | - FROM ' . prefixTable('sharekeys_items') . ' |
|
331 | + FROM ' . prefixTable('sharekeys_items').' |
|
332 | 332 | WHERE object_id = %i AND user_id = %i', |
333 | 333 | $record['id'], |
334 | 334 | (int) $record['perso'] === 0 ? $extra_arguments['owner_id'] : $extra_arguments['new_user_id'] |
@@ -355,7 +355,7 @@ discard block |
||
355 | 355 | |
356 | 356 | $currentUserKey = DB::queryFirstRow( |
357 | 357 | 'SELECT increment_id |
358 | - FROM ' . prefixTable('sharekeys_items') . ' |
|
358 | + FROM ' . prefixTable('sharekeys_items').' |
|
359 | 359 | WHERE object_id = %i AND user_id = %i', |
360 | 360 | $record['id'], |
361 | 361 | $post_user_id |
@@ -429,15 +429,15 @@ discard block |
||
429 | 429 | // Loop on logs |
430 | 430 | $rows = DB::query( |
431 | 431 | 'SELECT increment_id |
432 | - FROM ' . prefixTable('log_items') . ' |
|
432 | + FROM ' . prefixTable('log_items').' |
|
433 | 433 | WHERE raison LIKE "at_pw :%" AND encryption_type = "teampass_aes" |
434 | - LIMIT ' . $post_start . ', ' . $post_length |
|
434 | + LIMIT ' . $post_start.', '.$post_length |
|
435 | 435 | ); |
436 | 436 | foreach ($rows as $record) { |
437 | 437 | // Get itemKey from current user |
438 | 438 | $currentUserKey = DB::queryFirstRow( |
439 | 439 | 'SELECT share_key |
440 | - FROM ' . prefixTable('sharekeys_logs') . ' |
|
440 | + FROM ' . prefixTable('sharekeys_logs').' |
|
441 | 441 | WHERE object_id = %i AND user_id = %i', |
442 | 442 | $record['increment_id'], |
443 | 443 | $extra_arguments['owner_id'] |
@@ -469,7 +469,7 @@ discard block |
||
469 | 469 | if ((int) $post_user_id !== (int) $extra_arguments['owner_id']) { |
470 | 470 | $currentUserKey = DB::queryFirstRow( |
471 | 471 | 'SELECT increment_id |
472 | - FROM ' . prefixTable('sharekeys_items') . ' |
|
472 | + FROM ' . prefixTable('sharekeys_items').' |
|
473 | 473 | WHERE object_id = %i AND user_id = %i', |
474 | 474 | $record['id'], |
475 | 475 | $post_user_id |
@@ -491,7 +491,7 @@ discard block |
||
491 | 491 | // SHould we change step? |
492 | 492 | DB::query( |
493 | 493 | 'SELECT increment_id |
494 | - FROM ' . prefixTable('log_items') . ' |
|
494 | + FROM ' . prefixTable('log_items').' |
|
495 | 495 | WHERE raison LIKE "at_pw :%" AND encryption_type = "teampass_aes"' |
496 | 496 | ); |
497 | 497 | |
@@ -531,15 +531,15 @@ discard block |
||
531 | 531 | // Loop on fields |
532 | 532 | $rows = DB::query( |
533 | 533 | 'SELECT id |
534 | - FROM ' . prefixTable('categories_items') . ' |
|
534 | + FROM ' . prefixTable('categories_items').' |
|
535 | 535 | WHERE encryption_type = "teampass_aes" |
536 | - LIMIT ' . $post_start . ', ' . $post_length |
|
536 | + LIMIT ' . $post_start.', '.$post_length |
|
537 | 537 | ); |
538 | 538 | foreach ($rows as $record) { |
539 | 539 | // Get itemKey from current user |
540 | 540 | $currentUserKey = DB::queryFirstRow( |
541 | 541 | 'SELECT share_key |
542 | - FROM ' . prefixTable('sharekeys_fields') . ' |
|
542 | + FROM ' . prefixTable('sharekeys_fields').' |
|
543 | 543 | WHERE object_id = %i AND user_id = %i', |
544 | 544 | $record['id'], |
545 | 545 | $extra_arguments['owner_id'] |
@@ -567,7 +567,7 @@ discard block |
||
567 | 567 | if ((int) $post_user_id !== (int) $extra_arguments['owner_id']) { |
568 | 568 | $currentUserKey = DB::queryFirstRow( |
569 | 569 | 'SELECT increment_id |
570 | - FROM ' . prefixTable('sharekeys_items') . ' |
|
570 | + FROM ' . prefixTable('sharekeys_items').' |
|
571 | 571 | WHERE object_id = %i AND user_id = %i', |
572 | 572 | $record['id'], |
573 | 573 | $post_user_id |
@@ -590,7 +590,7 @@ discard block |
||
590 | 590 | // SHould we change step? |
591 | 591 | DB::query( |
592 | 592 | 'SELECT * |
593 | - FROM ' . prefixTable('categories_items') . ' |
|
593 | + FROM ' . prefixTable('categories_items').' |
|
594 | 594 | WHERE encryption_type = "teampass_aes"' |
595 | 595 | ); |
596 | 596 | |
@@ -630,14 +630,14 @@ discard block |
||
630 | 630 | // Loop on suggestions |
631 | 631 | $rows = DB::query( |
632 | 632 | 'SELECT id |
633 | - FROM ' . prefixTable('suggestion') . ' |
|
634 | - LIMIT ' . $post_start . ', ' . $post_length |
|
633 | + FROM ' . prefixTable('suggestion').' |
|
634 | + LIMIT ' . $post_start.', '.$post_length |
|
635 | 635 | ); |
636 | 636 | foreach ($rows as $record) { |
637 | 637 | // Get itemKey from current user |
638 | 638 | $currentUserKey = DB::queryFirstRow( |
639 | 639 | 'SELECT share_key |
640 | - FROM ' . prefixTable('sharekeys_suggestions') . ' |
|
640 | + FROM ' . prefixTable('sharekeys_suggestions').' |
|
641 | 641 | WHERE object_id = %i AND user_id = %i', |
642 | 642 | $record['id'], |
643 | 643 | $extra_arguments['owner_id'] |
@@ -669,7 +669,7 @@ discard block |
||
669 | 669 | if ((int) $post_user_id !== (int) $extra_arguments['owner_id']) { |
670 | 670 | $currentUserKey = DB::queryFirstRow( |
671 | 671 | 'SELECT increment_id |
672 | - FROM ' . prefixTable('sharekeys_items') . ' |
|
672 | + FROM ' . prefixTable('sharekeys_items').' |
|
673 | 673 | WHERE object_id = %i AND user_id = %i', |
674 | 674 | $record['id'], |
675 | 675 | $post_user_id |
@@ -729,16 +729,16 @@ discard block |
||
729 | 729 | // Loop on files |
730 | 730 | $rows = DB::query( |
731 | 731 | 'SELECT f.id AS id, i.perso AS perso |
732 | - FROM ' . prefixTable('files') . ' AS f |
|
733 | - INNER JOIN ' . prefixTable('items') . ' AS i ON i.id = f.id_item |
|
734 | - WHERE f.status = "' . TP_ENCRYPTION_NAME . '" |
|
735 | - LIMIT ' . $post_start . ', ' . $post_length |
|
732 | + FROM ' . prefixTable('files').' AS f |
|
733 | + INNER JOIN ' . prefixTable('items').' AS i ON i.id = f.id_item |
|
734 | + WHERE f.status = "' . TP_ENCRYPTION_NAME.'" |
|
735 | + LIMIT ' . $post_start.', '.$post_length |
|
736 | 736 | ); //aes_encryption |
737 | 737 | foreach ($rows as $record) { |
738 | 738 | // Get itemKey from current user |
739 | 739 | $currentUserKey = DB::queryFirstRow( |
740 | 740 | 'SELECT share_key, increment_id |
741 | - FROM ' . prefixTable('sharekeys_files') . ' |
|
741 | + FROM ' . prefixTable('sharekeys_files').' |
|
742 | 742 | WHERE object_id = %i AND user_id = %i', |
743 | 743 | $record['id'], |
744 | 744 | (int) $record['perso'] === 0 ? $extra_arguments['owner_id'] : $extra_arguments['new_user_id'] |
@@ -766,7 +766,7 @@ discard block |
||
766 | 766 | |
767 | 767 | $currentUserKey = DB::queryFirstRow( |
768 | 768 | 'SELECT increment_id |
769 | - FROM ' . prefixTable('sharekeys_files') . ' |
|
769 | + FROM ' . prefixTable('sharekeys_files').' |
|
770 | 770 | WHERE object_id = %i AND user_id = %i', |
771 | 771 | $record['id'], |
772 | 772 | $post_user_id |
@@ -797,8 +797,8 @@ discard block |
||
797 | 797 | // SHould we change step? Finished ? |
798 | 798 | DB::query( |
799 | 799 | 'SELECT * |
800 | - FROM ' . prefixTable('files') . ' |
|
801 | - WHERE status = "' . TP_ENCRYPTION_NAME . '"' |
|
800 | + FROM ' . prefixTable('files').' |
|
801 | + WHERE status = "' . TP_ENCRYPTION_NAME.'"' |
|
802 | 802 | ); |
803 | 803 | $counter = DB::count(); |
804 | 804 | $next_start = (int) $post_start + (int) $post_length; |
@@ -864,7 +864,7 @@ discard block |
||
864 | 864 | // get user info |
865 | 865 | $userInfo = DB::queryFirstRow( |
866 | 866 | 'SELECT email, login, auth_type, special, lastname, name |
867 | - FROM ' . prefixTable('users') . ' |
|
867 | + FROM ' . prefixTable('users').' |
|
868 | 868 | WHERE id = %i', |
869 | 869 | $extra_arguments['new_user_id'] |
870 | 870 | ); |
@@ -879,10 +879,10 @@ discard block |
||
879 | 879 | filter_var($userInfo['email'], FILTER_SANITIZE_FULL_SPECIAL_CHARS), |
880 | 880 | // @scrutinizer ignore-type |
881 | 881 | empty($extra_arguments['email_body']) === false ? $extra_arguments['email_body'] : $lang->get('email_body_user_config_1'), |
882 | - 'TEAMPASS - ' . $lang->get('login_credentials'), |
|
882 | + 'TEAMPASS - '.$lang->get('login_credentials'), |
|
883 | 883 | (array) filter_var_array( |
884 | 884 | [ |
885 | - '#code#' => cryption($extra_arguments['new_user_code'], '','decrypt', $SETTINGS)['string'], |
|
885 | + '#code#' => cryption($extra_arguments['new_user_code'], '', 'decrypt', $SETTINGS)['string'], |
|
886 | 886 | '#lastname#' => isset($userInfo['name']) === true ? $userInfo['name'] : '', |
887 | 887 | '#login#' => isset($userInfo['login']) === true ? $userInfo['login'] : '', |
888 | 888 | ], |
@@ -91,215 +91,215 @@ |
||
91 | 91 | switch ($post_type) { |
92 | 92 | //########################################################## |
93 | 93 | //CASE for creating a DB backup |
94 | -case 'perform_fix_pf_items-step1': |
|
95 | - // Check KEY |
|
96 | - if (!hash_equals((string) $session->get('key'), (string) $post_key)) { |
|
97 | - echo prepareExchangedData( |
|
98 | - array( |
|
99 | - 'error' => true, |
|
100 | - 'message' => $lang->get('key_is_not_correct'), |
|
101 | - ), |
|
102 | - 'encode' |
|
103 | - ); |
|
104 | - break; |
|
105 | - } |
|
106 | - // Is admin? |
|
107 | - if ((int) $session->get('user-admin') !== 1) { |
|
108 | - echo prepareExchangedData( |
|
109 | - array( |
|
110 | - 'error' => true, |
|
111 | - 'message' => $lang->get('error_not_allowed_to'), |
|
112 | - ), |
|
113 | - 'encode' |
|
114 | - ); |
|
115 | - break; |
|
116 | - } |
|
94 | + case 'perform_fix_pf_items-step1': |
|
95 | + // Check KEY |
|
96 | + if (!hash_equals((string) $session->get('key'), (string) $post_key)) { |
|
97 | + echo prepareExchangedData( |
|
98 | + array( |
|
99 | + 'error' => true, |
|
100 | + 'message' => $lang->get('key_is_not_correct'), |
|
101 | + ), |
|
102 | + 'encode' |
|
103 | + ); |
|
104 | + break; |
|
105 | + } |
|
106 | + // Is admin? |
|
107 | + if ((int) $session->get('user-admin') !== 1) { |
|
108 | + echo prepareExchangedData( |
|
109 | + array( |
|
110 | + 'error' => true, |
|
111 | + 'message' => $lang->get('error_not_allowed_to'), |
|
112 | + ), |
|
113 | + 'encode' |
|
114 | + ); |
|
115 | + break; |
|
116 | + } |
|
117 | 117 | |
118 | - // decrypt and retrieve data in JSON format |
|
119 | - $dataReceived = prepareExchangedData( |
|
120 | - $post_data, |
|
121 | - 'decode' |
|
122 | - ); |
|
118 | + // decrypt and retrieve data in JSON format |
|
119 | + $dataReceived = prepareExchangedData( |
|
120 | + $post_data, |
|
121 | + 'decode' |
|
122 | + ); |
|
123 | 123 | |
124 | - $userId = filter_var($dataReceived['userId'], FILTER_SANITIZE_NUMBER_INT); |
|
124 | + $userId = filter_var($dataReceived['userId'], FILTER_SANITIZE_NUMBER_INT); |
|
125 | 125 | |
126 | - // Get user info |
|
127 | - $userInfo = DB::queryFirstRow( |
|
128 | - 'SELECT private_key, public_key, psk, encrypted_psk |
|
126 | + // Get user info |
|
127 | + $userInfo = DB::queryFirstRow( |
|
128 | + 'SELECT private_key, public_key, psk, encrypted_psk |
|
129 | 129 | FROM teampass_users |
130 | 130 | WHERE id = %i', |
131 | - $userId |
|
132 | - ); |
|
131 | + $userId |
|
132 | + ); |
|
133 | 133 | |
134 | - // Get user's private folders |
|
135 | - $userPFRoot = DB::queryFirstRow( |
|
136 | - 'SELECT id |
|
134 | + // Get user's private folders |
|
135 | + $userPFRoot = DB::queryFirstRow( |
|
136 | + 'SELECT id |
|
137 | 137 | FROM teampass_nested_tree |
138 | 138 | WHERE title = %i', |
139 | - $userId |
|
140 | - ); |
|
141 | - if (DB::count() === 0) { |
|
142 | - echo prepareExchangedData( |
|
143 | - array( |
|
144 | - 'error' => true, |
|
145 | - 'message' => 'User has no personal folders', |
|
146 | - ), |
|
147 | - 'encode' |
|
148 | - ); |
|
149 | - break; |
|
150 | - } |
|
151 | - $personalFolders = []; |
|
152 | - $tree = new NestedTree(prefixTable('nested_tree'), 'id', 'parent_id', 'title'); |
|
153 | - $tree->rebuild(); |
|
154 | - $folders = $tree->getDescendants($userPFRoot['id'], true); |
|
155 | - foreach ($folders as $folder) { |
|
156 | - array_push($personalFolders, $folder->id); |
|
157 | - } |
|
158 | - |
|
159 | - //Show done |
|
160 | - echo prepareExchangedData( |
|
161 | - array( |
|
162 | - 'error' => false, |
|
163 | - 'message' => 'Personal Folders found: ', |
|
164 | - 'personalFolders' => json_encode($personalFolders), |
|
165 | - ), |
|
166 | - 'encode' |
|
167 | - ); |
|
168 | - break; |
|
169 | - |
|
170 | -case 'perform_fix_pf_items-step2': |
|
171 | - // Check KEY |
|
172 | - if (!hash_equals((string) $session->get('key'), (string) $post_key)) { |
|
173 | - echo prepareExchangedData( |
|
174 | - array( |
|
175 | - 'error' => true, |
|
176 | - 'message' => $lang->get('key_is_not_correct'), |
|
177 | - ), |
|
178 | - 'encode' |
|
139 | + $userId |
|
179 | 140 | ); |
180 | - break; |
|
181 | - } |
|
182 | - // Is admin? |
|
183 | - if ((int) $session->get('user-admin') !== 1) { |
|
141 | + if (DB::count() === 0) { |
|
142 | + echo prepareExchangedData( |
|
143 | + array( |
|
144 | + 'error' => true, |
|
145 | + 'message' => 'User has no personal folders', |
|
146 | + ), |
|
147 | + 'encode' |
|
148 | + ); |
|
149 | + break; |
|
150 | + } |
|
151 | + $personalFolders = []; |
|
152 | + $tree = new NestedTree(prefixTable('nested_tree'), 'id', 'parent_id', 'title'); |
|
153 | + $tree->rebuild(); |
|
154 | + $folders = $tree->getDescendants($userPFRoot['id'], true); |
|
155 | + foreach ($folders as $folder) { |
|
156 | + array_push($personalFolders, $folder->id); |
|
157 | + } |
|
158 | + |
|
159 | + //Show done |
|
184 | 160 | echo prepareExchangedData( |
185 | 161 | array( |
186 | - 'error' => true, |
|
187 | - 'message' => $lang->get('error_not_allowed_to'), |
|
162 | + 'error' => false, |
|
163 | + 'message' => 'Personal Folders found: ', |
|
164 | + 'personalFolders' => json_encode($personalFolders), |
|
188 | 165 | ), |
189 | 166 | 'encode' |
190 | 167 | ); |
191 | 168 | break; |
192 | - } |
|
193 | 169 | |
194 | - // decrypt and retrieve data in JSON format |
|
195 | - $dataReceived = prepareExchangedData( |
|
196 | - $post_data, |
|
197 | - 'decode' |
|
198 | - ); |
|
170 | + case 'perform_fix_pf_items-step2': |
|
171 | + // Check KEY |
|
172 | + if (!hash_equals((string) $session->get('key'), (string) $post_key)) { |
|
173 | + echo prepareExchangedData( |
|
174 | + array( |
|
175 | + 'error' => true, |
|
176 | + 'message' => $lang->get('key_is_not_correct'), |
|
177 | + ), |
|
178 | + 'encode' |
|
179 | + ); |
|
180 | + break; |
|
181 | + } |
|
182 | + // Is admin? |
|
183 | + if ((int) $session->get('user-admin') !== 1) { |
|
184 | + echo prepareExchangedData( |
|
185 | + array( |
|
186 | + 'error' => true, |
|
187 | + 'message' => $lang->get('error_not_allowed_to'), |
|
188 | + ), |
|
189 | + 'encode' |
|
190 | + ); |
|
191 | + break; |
|
192 | + } |
|
199 | 193 | |
200 | - $userId = filter_var($dataReceived['userId'], FILTER_SANITIZE_NUMBER_INT); |
|
201 | - $personalFolders = filter_var($dataReceived['personalFolders'], FILTER_SANITIZE_FULL_SPECIAL_CHARS); |
|
194 | + // decrypt and retrieve data in JSON format |
|
195 | + $dataReceived = prepareExchangedData( |
|
196 | + $post_data, |
|
197 | + 'decode' |
|
198 | + ); |
|
199 | + |
|
200 | + $userId = filter_var($dataReceived['userId'], FILTER_SANITIZE_NUMBER_INT); |
|
201 | + $personalFolders = filter_var($dataReceived['personalFolders'], FILTER_SANITIZE_FULL_SPECIAL_CHARS); |
|
202 | 202 | |
203 | - // Delete all private items with sharekeys |
|
204 | - $pfiSharekeys = DB::queryFirstColumn( |
|
205 | - 'select s.increment_id |
|
203 | + // Delete all private items with sharekeys |
|
204 | + $pfiSharekeys = DB::queryFirstColumn( |
|
205 | + 'select s.increment_id |
|
206 | 206 | from teampass_sharekeys_items as s |
207 | 207 | INNER JOIN teampass_items AS i ON (i.id = s.object_id) |
208 | 208 | WHERE s.user_id = %i AND i.perso = 1 AND i.id_tree IN %ls', |
209 | - $userId, |
|
210 | - $personalFolders |
|
211 | - ); |
|
212 | - $pfiSharekeysCount = DB::count(); |
|
213 | - if ($pfiSharekeysCount > 0) { |
|
214 | - DB::delete( |
|
215 | - "teampass_sharekeys_items", |
|
216 | - "increment_id IN %ls", |
|
217 | - $pfiSharekeys |
|
209 | + $userId, |
|
210 | + $personalFolders |
|
218 | 211 | ); |
219 | - } |
|
212 | + $pfiSharekeysCount = DB::count(); |
|
213 | + if ($pfiSharekeysCount > 0) { |
|
214 | + DB::delete( |
|
215 | + "teampass_sharekeys_items", |
|
216 | + "increment_id IN %ls", |
|
217 | + $pfiSharekeys |
|
218 | + ); |
|
219 | + } |
|
220 | 220 | |
221 | 221 | |
222 | - //Show done |
|
223 | - echo prepareExchangedData( |
|
224 | - array( |
|
225 | - 'error' => false, |
|
226 | - 'message' => '<br>Number of Sharekeys for private items DELETED: ', |
|
227 | - 'nbDeleted' => $pfiSharekeysCount, |
|
228 | - 'personalFolders' => json_encode($personalFolders), |
|
229 | - ), |
|
230 | - 'encode' |
|
231 | - ); |
|
232 | - break; |
|
233 | - |
|
234 | -case 'perform_fix_pf_items-step3': |
|
235 | - // Check KEY |
|
236 | - if (!hash_equals((string) $session->get('key'), (string) $post_key)) { |
|
237 | - echo prepareExchangedData( |
|
238 | - array( |
|
239 | - 'error' => true, |
|
240 | - 'message' => $lang->get('key_is_not_correct'), |
|
241 | - ), |
|
242 | - 'encode' |
|
243 | - ); |
|
244 | - break; |
|
245 | - } |
|
246 | - // Is admin? |
|
247 | - if ((int) $session->get('user-admin') !== 1) { |
|
222 | + //Show done |
|
248 | 223 | echo prepareExchangedData( |
249 | 224 | array( |
250 | - 'error' => true, |
|
251 | - 'message' => $lang->get('error_not_allowed_to'), |
|
225 | + 'error' => false, |
|
226 | + 'message' => '<br>Number of Sharekeys for private items DELETED: ', |
|
227 | + 'nbDeleted' => $pfiSharekeysCount, |
|
228 | + 'personalFolders' => json_encode($personalFolders), |
|
252 | 229 | ), |
253 | 230 | 'encode' |
254 | 231 | ); |
255 | 232 | break; |
256 | - } |
|
257 | 233 | |
258 | - // decrypt and retrieve data in JSON format |
|
259 | - $dataReceived = prepareExchangedData( |
|
260 | - $post_data, |
|
261 | - 'decode' |
|
262 | - ); |
|
234 | + case 'perform_fix_pf_items-step3': |
|
235 | + // Check KEY |
|
236 | + if (!hash_equals((string) $session->get('key'), (string) $post_key)) { |
|
237 | + echo prepareExchangedData( |
|
238 | + array( |
|
239 | + 'error' => true, |
|
240 | + 'message' => $lang->get('key_is_not_correct'), |
|
241 | + ), |
|
242 | + 'encode' |
|
243 | + ); |
|
244 | + break; |
|
245 | + } |
|
246 | + // Is admin? |
|
247 | + if ((int) $session->get('user-admin') !== 1) { |
|
248 | + echo prepareExchangedData( |
|
249 | + array( |
|
250 | + 'error' => true, |
|
251 | + 'message' => $lang->get('error_not_allowed_to'), |
|
252 | + ), |
|
253 | + 'encode' |
|
254 | + ); |
|
255 | + break; |
|
256 | + } |
|
257 | + |
|
258 | + // decrypt and retrieve data in JSON format |
|
259 | + $dataReceived = prepareExchangedData( |
|
260 | + $post_data, |
|
261 | + 'decode' |
|
262 | + ); |
|
263 | 263 | |
264 | - $userId = filter_var($dataReceived['userId'], FILTER_SANITIZE_NUMBER_INT); |
|
265 | - $personalFolders = filter_var($dataReceived['personalFolders'], FILTER_SANITIZE_FULL_SPECIAL_CHARS); |
|
264 | + $userId = filter_var($dataReceived['userId'], FILTER_SANITIZE_NUMBER_INT); |
|
265 | + $personalFolders = filter_var($dataReceived['personalFolders'], FILTER_SANITIZE_FULL_SPECIAL_CHARS); |
|
266 | 266 | |
267 | - // Update from items_old to items all the private itemsitems that have been converted to teampass_aes |
|
268 | - // Get all key back |
|
269 | - $items = DB::query( |
|
270 | - "SELECT id |
|
267 | + // Update from items_old to items all the private itemsitems that have been converted to teampass_aes |
|
268 | + // Get all key back |
|
269 | + $items = DB::query( |
|
270 | + "SELECT id |
|
271 | 271 | FROM teampass_items |
272 | 272 | WHERE id_tree IN %ls AND encryption_type = %s", |
273 | - $personalFolders, |
|
274 | - "teampass_aes" |
|
275 | - ); |
|
276 | - //DB::debugMode(false); |
|
277 | - $nbItems = DB::count(); |
|
278 | - foreach ($items as $item) { |
|
279 | - $defusePwd = DB::queryFirstField("SELECT pw FROM teampass_items_old WHERE id = %i", $item['id']); |
|
280 | - DB::update( |
|
281 | - "teampass_items", |
|
282 | - ['pw' => $defusePwd, "encryption_type" => "defuse"], |
|
283 | - "id = %i", |
|
284 | - $item['id'] |
|
273 | + $personalFolders, |
|
274 | + "teampass_aes" |
|
285 | 275 | ); |
286 | - } |
|
276 | + //DB::debugMode(false); |
|
277 | + $nbItems = DB::count(); |
|
278 | + foreach ($items as $item) { |
|
279 | + $defusePwd = DB::queryFirstField("SELECT pw FROM teampass_items_old WHERE id = %i", $item['id']); |
|
280 | + DB::update( |
|
281 | + "teampass_items", |
|
282 | + ['pw' => $defusePwd, "encryption_type" => "defuse"], |
|
283 | + "id = %i", |
|
284 | + $item['id'] |
|
285 | + ); |
|
286 | + } |
|
287 | 287 | |
288 | 288 | |
289 | - //Show done |
|
290 | - echo prepareExchangedData( |
|
291 | - array( |
|
292 | - 'error' => false, |
|
293 | - 'message' => '<br>Number of items reseted to Defuse: ', |
|
294 | - 'nbItems' => $nbItems, |
|
295 | - 'personalFolders' => json_encode($personalFolders), |
|
296 | - ), |
|
297 | - 'encode' |
|
298 | - ); |
|
299 | - break; |
|
300 | - |
|
301 | - /* TOOL #2 - Fixing items master keys */ |
|
302 | - /* |
|
289 | + //Show done |
|
290 | + echo prepareExchangedData( |
|
291 | + array( |
|
292 | + 'error' => false, |
|
293 | + 'message' => '<br>Number of items reseted to Defuse: ', |
|
294 | + 'nbItems' => $nbItems, |
|
295 | + 'personalFolders' => json_encode($personalFolders), |
|
296 | + ), |
|
297 | + 'encode' |
|
298 | + ); |
|
299 | + break; |
|
300 | + |
|
301 | + /* TOOL #2 - Fixing items master keys */ |
|
302 | + /* |
|
303 | 303 | * STEP 1 - Check if we have the correct pwd for TP_USER |
304 | 304 | */ |
305 | 305 | case 'perform_fix_items_master_keys-step1': |
@@ -70,7 +70,7 @@ discard block |
||
70 | 70 | if ($checkUserAccess->checkSession() === false || $checkUserAccess->userAccessPage('tools') === false) { |
71 | 71 | // Not allowed page |
72 | 72 | $session->set('system-error_code', ERR_NOT_ALLOWED); |
73 | - include $SETTINGS['cpassman_dir'] . '/error.php'; |
|
73 | + include $SETTINGS['cpassman_dir'].'/error.php'; |
|
74 | 74 | exit; |
75 | 75 | } |
76 | 76 | |
@@ -335,7 +335,7 @@ discard block |
||
335 | 335 | // Get PT_USER info |
336 | 336 | $userInfo = DB::queryFirstRow( |
337 | 337 | 'SELECT pw, public_key, private_key, login, name |
338 | - FROM ' . prefixTable('users') . ' |
|
338 | + FROM ' . prefixTable('users').' |
|
339 | 339 | WHERE id = %i', |
340 | 340 | TP_USER_ID |
341 | 341 | ); |
@@ -372,8 +372,8 @@ discard block |
||
372 | 372 | // Get one itemKey from current user |
373 | 373 | $currentUserKey = DB::queryFirstRow( |
374 | 374 | 'SELECT ski.share_key, ski.increment_id AS increment_id, l.id_user |
375 | - FROM ' . prefixTable('sharekeys_items') . ' AS ski |
|
376 | - INNER JOIN ' . prefixTable('log_items') . ' AS l ON ski.object_id = l.id_item |
|
375 | + FROM ' . prefixTable('sharekeys_items').' AS ski |
|
376 | + INNER JOIN ' . prefixTable('log_items').' AS l ON ski.object_id = l.id_item |
|
377 | 377 | WHERE ski.user_id = %i |
378 | 378 | ORDER BY RAND() |
379 | 379 | LIMIT 1', |
@@ -392,7 +392,7 @@ discard block |
||
392 | 392 | echo prepareExchangedData( |
393 | 393 | array( |
394 | 394 | 'error' => true, |
395 | - 'message' => 'No issue found, normal process should work. This process is now finished. (item id : ' . $currentUserKey['increment_id'] . ')', |
|
395 | + 'message' => 'No issue found, normal process should work. This process is now finished. (item id : '.$currentUserKey['increment_id'].')', |
|
396 | 396 | ), |
397 | 397 | 'encode' |
398 | 398 | ); |
@@ -452,7 +452,7 @@ discard block |
||
452 | 452 | // Get user info |
453 | 453 | $userInfo = DB::queryFirstRow( |
454 | 454 | 'SELECT public_key, private_key |
455 | - FROM ' . prefixTable('users') . ' |
|
455 | + FROM ' . prefixTable('users').' |
|
456 | 456 | WHERE id = %i', |
457 | 457 | $userId |
458 | 458 | ); |
@@ -475,8 +475,8 @@ discard block |
||
475 | 475 | // Get one itemKey from current user |
476 | 476 | $currentUserKey = DB::queryFirstRow( |
477 | 477 | 'SELECT ski.share_key, ski.increment_id AS increment_id, l.id_user |
478 | - FROM ' . prefixTable('sharekeys_items') . ' AS ski |
|
479 | - INNER JOIN ' . prefixTable('log_items') . ' AS l ON ski.object_id = l.id_item |
|
478 | + FROM ' . prefixTable('sharekeys_items').' AS ski |
|
479 | + INNER JOIN ' . prefixTable('log_items').' AS l ON ski.object_id = l.id_item |
|
480 | 480 | WHERE ski.user_id = %i |
481 | 481 | ORDER BY RAND() |
482 | 482 | LIMIT 1', |
@@ -514,8 +514,8 @@ discard block |
||
514 | 514 | // Get number of users to treat |
515 | 515 | DB::query( |
516 | 516 | 'SELECT i.id |
517 | - FROM ' . prefixTable('items') . ' AS i |
|
518 | - INNER JOIN ' . prefixTable('sharekeys_items') . ' AS si ON i.id = si.object_id |
|
517 | + FROM ' . prefixTable('items').' AS i |
|
518 | + INNER JOIN ' . prefixTable('sharekeys_items').' AS si ON i.id = si.object_id |
|
519 | 519 | WHERE i.perso = %i AND si.user_id = %i;', |
520 | 520 | 0, |
521 | 521 | $userId |
@@ -597,11 +597,11 @@ discard block |
||
597 | 597 | // Loop on items |
598 | 598 | $rows = DB::query( |
599 | 599 | 'SELECT si.object_id AS object_id, si.share_key AS share_key, i.pw AS pw, si.increment_id as increment_id |
600 | - FROM ' . prefixTable('sharekeys_items') . ' AS si |
|
601 | - INNER JOIN ' . prefixTable('items') . ' AS i ON (i.id = si.object_id) |
|
600 | + FROM ' . prefixTable('sharekeys_items').' AS si |
|
601 | + INNER JOIN ' . prefixTable('items').' AS i ON (i.id = si.object_id) |
|
602 | 602 | WHERE si.user_id = %i |
603 | 603 | ORDER BY si.increment_id ASC |
604 | - LIMIT ' . $startIndex . ', ' . $limit, |
|
604 | + LIMIT ' . $startIndex.', '.$limit, |
|
605 | 605 | $userId |
606 | 606 | ); |
607 | 607 | |
@@ -625,7 +625,7 @@ discard block |
||
625 | 625 | // It will be updated if already exists |
626 | 626 | $currentTPUserKey = DB::queryFirstRow( |
627 | 627 | 'SELECT increment_id, user_id, share_key |
628 | - FROM ' . prefixTable('sharekeys_items') . ' |
|
628 | + FROM ' . prefixTable('sharekeys_items').' |
|
629 | 629 | WHERE object_id = %i AND user_id = %i', |
630 | 630 | $record['object_id'], |
631 | 631 | TP_USER_ID |
@@ -661,7 +661,7 @@ discard block |
||
661 | 661 | DB::commit(); |
662 | 662 | } catch (Exception $e) { |
663 | 663 | DB::rollback(); |
664 | - error_log("Teampass - Error: Keys treatment: " . $e->getMessage()); |
|
664 | + error_log("Teampass - Error: Keys treatment: ".$e->getMessage()); |
|
665 | 665 | } |
666 | 666 | |
667 | 667 | $nextIndex = (int) $startIndex + (int) $limit; |
@@ -717,7 +717,7 @@ discard block |
||
717 | 717 | // Get PT_USER info |
718 | 718 | DB::queryFirstRow( |
719 | 719 | 'SELECT operation_code |
720 | - FROM ' . prefixTable('sharekeys_backup') . ' |
|
720 | + FROM ' . prefixTable('sharekeys_backup').' |
|
721 | 721 | WHERE operation_code = %s', |
722 | 722 | $operationCode |
723 | 723 | ); |
@@ -727,7 +727,7 @@ discard block |
||
727 | 727 | // using increment_id_value in order to update the correct record |
728 | 728 | $rows = DB::query( |
729 | 729 | 'SELECT * |
730 | - FROM ' . prefixTable('sharekeys_backup') . ' |
|
730 | + FROM ' . prefixTable('sharekeys_backup').' |
|
731 | 731 | WHERE operation_code = %s', |
732 | 732 | $operationCode |
733 | 733 | ); |
@@ -746,7 +746,7 @@ discard block |
||
746 | 746 | |
747 | 747 | // Delete all sharekeys for this operation |
748 | 748 | DB::query( |
749 | - 'DELETE FROM ' . prefixTable('sharekeys_backup') . ' |
|
749 | + 'DELETE FROM '.prefixTable('sharekeys_backup').' |
|
750 | 750 | WHERE operation_code = %i', |
751 | 751 | $operationCode |
752 | 752 | ); |
@@ -809,7 +809,7 @@ discard block |
||
809 | 809 | // Get operation info |
810 | 810 | DB::query( |
811 | 811 | 'SELECT operation_code |
812 | - FROM ' . prefixTable('sharekeys_backup') . ' |
|
812 | + FROM ' . prefixTable('sharekeys_backup').' |
|
813 | 813 | WHERE operation_code = %s', |
814 | 814 | $operationCode |
815 | 815 | ); |
@@ -818,7 +818,7 @@ discard block |
||
818 | 818 | if ($nbKeys > 0) { |
819 | 819 | // Delete all sharekeys for this operation |
820 | 820 | DB::query( |
821 | - 'DELETE FROM ' . prefixTable('sharekeys_backup') . ' |
|
821 | + 'DELETE FROM '.prefixTable('sharekeys_backup').' |
|
822 | 822 | WHERE operation_code = %s', |
823 | 823 | $operationCode |
824 | 824 | ); |
@@ -75,7 +75,7 @@ discard block |
||
75 | 75 | ) { |
76 | 76 | // Not allowed page |
77 | 77 | $session->set('system-error_code', ERR_NOT_ALLOWED); |
78 | - include $SETTINGS['cpassman_dir'] . '/error.php'; |
|
78 | + include $SETTINGS['cpassman_dir'].'/error.php'; |
|
79 | 79 | exit; |
80 | 80 | } |
81 | 81 | |
@@ -145,7 +145,7 @@ discard block |
||
145 | 145 | if (isset($order['column']) && preg_match('#^(asc|desc)$#i', $order['dir'])) { |
146 | 146 | $columnIndex = $order['column']; |
147 | 147 | $dir = $inputData['dir']; |
148 | - $sOrder .= $aColumns[$columnIndex] . ' ' . $dir . ', '; |
|
148 | + $sOrder .= $aColumns[$columnIndex].' '.$dir.', '; |
|
149 | 149 | } |
150 | 150 | |
151 | 151 | $sOrder = substr_replace($sOrder, '', -2); |
@@ -113,7 +113,7 @@ |
||
113 | 113 | private function isParentFolderAllowed($parent_id, $user_accessible_folders, $user_is_admin, $user_can_create_root_folder) |
114 | 114 | { |
115 | 115 | if ($parent_id == 0 && $user_can_create_root_folder == true) |
116 | - return true; |
|
116 | + return true; |
|
117 | 117 | |
118 | 118 | if (in_array($parent_id, $user_accessible_folders) === false |
119 | 119 | && (int) $user_is_admin !== 1 |
@@ -112,8 +112,9 @@ discard block |
||
112 | 112 | */ |
113 | 113 | private function isParentFolderAllowed($parent_id, $user_accessible_folders, $user_is_admin, $user_can_create_root_folder) |
114 | 114 | { |
115 | - if ($parent_id == 0 && $user_can_create_root_folder == true) |
|
116 | - return true; |
|
115 | + if ($parent_id == 0 && $user_can_create_root_folder == true) { |
|
116 | + return true; |
|
117 | + } |
|
117 | 118 | |
118 | 119 | if (in_array($parent_id, $user_accessible_folders) === false |
119 | 120 | && (int) $user_is_admin !== 1 |
@@ -438,8 +439,9 @@ discard block |
||
438 | 439 | )['count']; |
439 | 440 | |
440 | 441 | // Don't insert duplicates |
441 | - if ($count > 0) |
|
442 | - continue; |
|
442 | + if ($count > 0) { |
|
443 | + continue; |
|
444 | + } |
|
443 | 445 | |
444 | 446 | // Insert new background task |
445 | 447 | DB::insert( |
@@ -84,7 +84,7 @@ discard block |
||
84 | 84 | |
85 | 85 | $parentComplexity = $this->checkComplexityLevel($parentFolderData, $complexity, $parent_id); |
86 | 86 | if (isset($parentComplexity ['error']) && $parentComplexity['error'] === true) { |
87 | - return $this->errorResponse($this->lang->get('error_folder_complexity_lower_than_top_folder') . " [<b>{$this->settings['TP_PW_COMPLEXITY'][$parentComplexity['valeur']][1]}</b>]"); |
|
87 | + return $this->errorResponse($this->lang->get('error_folder_complexity_lower_than_top_folder')." [<b>{$this->settings['TP_PW_COMPLEXITY'][$parentComplexity['valeur']][1]}</b>]"); |
|
88 | 88 | } |
89 | 89 | |
90 | 90 | return $this->createFolder($params, array_merge($parentFolderData, $parentComplexity)); |
@@ -137,7 +137,7 @@ discard block |
||
137 | 137 | ) { |
138 | 138 | DB::query( |
139 | 139 | 'SELECT * |
140 | - FROM ' . prefixTable('nested_tree') . ' |
|
140 | + FROM ' . prefixTable('nested_tree').' |
|
141 | 141 | WHERE title = %s AND personal_folder = 0', |
142 | 142 | $title |
143 | 143 | ); |
@@ -161,7 +161,7 @@ discard block |
||
161 | 161 | //check if parent folder is personal |
162 | 162 | $data = DB::queryfirstrow( |
163 | 163 | 'SELECT personal_folder, bloquer_creation, bloquer_modification |
164 | - FROM ' . prefixTable('nested_tree') . ' |
|
164 | + FROM ' . prefixTable('nested_tree').' |
|
165 | 165 | WHERE id = %i', |
166 | 166 | $parent_id |
167 | 167 | ); |
@@ -200,7 +200,7 @@ discard block |
||
200 | 200 | // get complexity level for this folder |
201 | 201 | $data = DB::queryfirstrow( |
202 | 202 | 'SELECT valeur |
203 | - FROM ' . prefixTable('misc') . ' |
|
203 | + FROM ' . prefixTable('misc').' |
|
204 | 204 | WHERE intitule = %i AND type = %s', |
205 | 205 | $parent_id, |
206 | 206 | 'complex' |
@@ -251,11 +251,11 @@ discard block |
||
251 | 251 | */ |
252 | 252 | private function canCreateFolder($isPersonal, $user_is_admin, $user_is_manager, $user_can_manage_all_users, $user_can_create_root_folder) |
253 | 253 | { |
254 | - return (int)$isPersonal === 1 || |
|
255 | - (int)$user_is_admin === 1 || |
|
256 | - ((int)$user_is_manager === 1 || (int)$user_can_manage_all_users === 1) || |
|
254 | + return (int) $isPersonal === 1 || |
|
255 | + (int) $user_is_admin === 1 || |
|
256 | + ((int) $user_is_manager === 1 || (int) $user_can_manage_all_users === 1) || |
|
257 | 257 | ($this->settings['enable_user_can_create_folders'] ?? false) || |
258 | - ((int)$user_can_create_root_folder === 1); |
|
258 | + ((int) $user_can_create_root_folder === 1); |
|
259 | 259 | } |
260 | 260 | |
261 | 261 | /** |
@@ -335,7 +335,7 @@ discard block |
||
335 | 335 | $path = ''; |
336 | 336 | $tree_path = $tree->getPath(0, false); |
337 | 337 | foreach ($tree_path as $fld) { |
338 | - $path .= empty($path) ? $fld->title : '/' . $fld->title; |
|
338 | + $path .= empty($path) ? $fld->title : '/'.$fld->title; |
|
339 | 339 | } |
340 | 340 | |
341 | 341 | $new_json = [ |
@@ -349,7 +349,7 @@ discard block |
||
349 | 349 | "is_visible_active" => 0, |
350 | 350 | ]; |
351 | 351 | |
352 | - $cache_tree = DB::queryFirstRow('SELECT increment_id, folders, visible_folders FROM ' . prefixTable('cache_tree') . ' WHERE user_id = %i', (int)$user_id); |
|
352 | + $cache_tree = DB::queryFirstRow('SELECT increment_id, folders, visible_folders FROM '.prefixTable('cache_tree').' WHERE user_id = %i', (int) $user_id); |
|
353 | 353 | |
354 | 354 | if (empty($cache_tree)) { |
355 | 355 | DB::insert(prefixTable('cache_tree'), [ |
@@ -369,7 +369,7 @@ discard block |
||
369 | 369 | 'folders' => json_encode($folders), |
370 | 370 | 'visible_folders' => json_encode($visible_folders), |
371 | 371 | 'timestamp' => time(), |
372 | - ], 'increment_id = %i', (int)$cache_tree['increment_id']); |
|
372 | + ], 'increment_id = %i', (int) $cache_tree['increment_id']); |
|
373 | 373 | } |
374 | 374 | } |
375 | 375 | |
@@ -379,7 +379,7 @@ discard block |
||
379 | 379 | private function manageFolderPermissions($parent_id, $newId, $user_roles, $access_rights, $user_is_admin) |
380 | 380 | { |
381 | 381 | if ($parent_id !== 0 && $this->settings['subfolder_rights_as_parent'] ?? false) { |
382 | - $rows = DB::query('SELECT role_id, type FROM ' . prefixTable('roles_values') . ' WHERE folder_id = %i', $parent_id); |
|
382 | + $rows = DB::query('SELECT role_id, type FROM '.prefixTable('roles_values').' WHERE folder_id = %i', $parent_id); |
|
383 | 383 | foreach ($rows as $record) { |
384 | 384 | DB::insert(prefixTable('roles_values'), [ |
385 | 385 | 'role_id' => $record['role_id'], |
@@ -387,7 +387,7 @@ discard block |
||
387 | 387 | 'type' => $record['type'], |
388 | 388 | ]); |
389 | 389 | } |
390 | - } elseif ((int)$user_is_admin !== 1) { |
|
390 | + } elseif ((int) $user_is_admin !== 1) { |
|
391 | 391 | foreach (array_unique(explode(';', $user_roles)) as $role) { |
392 | 392 | if (!empty($role)) { |
393 | 393 | DB::insert(prefixTable('roles_values'), [ |
@@ -405,7 +405,7 @@ discard block |
||
405 | 405 | */ |
406 | 406 | private function copyCustomFieldsCategories($parent_id, $newId) |
407 | 407 | { |
408 | - $rows = DB::query('SELECT id_category FROM ' . prefixTable('categories_folders') . ' WHERE id_folder = %i', $parent_id); |
|
408 | + $rows = DB::query('SELECT id_category FROM '.prefixTable('categories_folders').' WHERE id_folder = %i', $parent_id); |
|
409 | 409 | foreach ($rows as $record) { |
410 | 410 | DB::insert(prefixTable('categories_folders'), [ |
411 | 411 | 'id_category' => $record['id_category'], |
@@ -430,7 +430,7 @@ discard block |
||
430 | 430 | // Search for existing job |
431 | 431 | $count = DB::queryFirstRow( |
432 | 432 | 'SELECT COUNT(*) AS count |
433 | - FROM ' . prefixTable('background_tasks') . ' |
|
433 | + FROM ' . prefixTable('background_tasks').' |
|
434 | 434 | WHERE is_in_progress = %i AND process_type = %s AND arguments = %s', |
435 | 435 | 0, |
436 | 436 | 'user_build_cache_tree', |
@@ -464,7 +464,7 @@ discard block |
||
464 | 464 | return [ |
465 | 465 | 'error' => true, |
466 | 466 | 'message' => $message, |
467 | - 'newId' => '' . $newIdSuffix, |
|
467 | + 'newId' => ''.$newIdSuffix, |
|
468 | 468 | ]; |
469 | 469 | } |
470 | 470 | } |