Improved access checks in notifications config.
[timetracker.git] / notification_add.php
1 <?php
2 // +----------------------------------------------------------------------+
3 // | Anuko Time Tracker
4 // +----------------------------------------------------------------------+
5 // | Copyright (c) Anuko International Ltd. (https://www.anuko.com)
6 // +----------------------------------------------------------------------+
7 // | LIBERAL FREEWARE LICENSE: This source code document may be used
8 // | by anyone for any purpose, and freely redistributed alone or in
9 // | combination with other software, provided that the license is obeyed.
10 // |
11 // | There are only two ways to violate the license:
12 // |
13 // | 1. To redistribute this code in source form, with the copyright
14 // |    notice or license removed or altered. (Distributing in compiled
15 // |    forms without embedded copyright notices is permitted).
16 // |
17 // | 2. To redistribute modified versions of this code in *any* form
18 // |    that bears insufficient indications that the modifications are
19 // |    not the work of the original author(s).
20 // |
21 // | This license applies to this document only, not any other software
22 // | that it may be combined with.
23 // |
24 // +----------------------------------------------------------------------+
25 // | Contributors:
26 // | https://www.anuko.com/time_tracker/credits.htm
27 // +----------------------------------------------------------------------+
28
29 require_once('initialize.php');
30 require_once(LIBRARY_DIR.'/tdcron/class.tdcron.php');
31 require_once(LIBRARY_DIR.'/tdcron/class.tdcron.entry.php');
32 import('form.Form');
33 import('ttFavReportHelper');
34 import('ttNotificationHelper');
35
36 // Access checks.
37 if (!ttAccessAllowed('manage_advanced_settings')) {
38   header('Location: access_denied.php');
39   exit();
40 }
41 if (!$user->isPluginEnabled('no')) {
42   header('Location: feature_disabled.php');
43   exit();
44 }
45 if (!$user->exists()) {
46   header('Location: access_denied.php'); // No users in subgroup.
47   exit();
48 }
49 if ($request->isPost()) {
50   // TODO: improve this, perhaps by refactoring elsewhere.
51   $cl_fav_report = (int) $request->getParameter('fav_report');
52   $fav_report = ttFavReportHelper::getReport($cl_fav_report);
53   if ($user->getUser() != $fav_report['user_id']) {
54     header('Location: access_denied.php'); // Invalid fav report id in post.
55     exit();
56   }
57 }
58 // End of access checks.
59
60 $fav_reports = ttFavReportHelper::getReports($user->getUser());
61
62 if ($request->isPost()) {
63   $cl_cron_spec = trim($request->getParameter('cron_spec'));
64   $cl_email = trim($request->getParameter('email'));
65   $cl_cc = trim($request->getParameter('cc'));
66   $cl_subject = trim($request->getParameter('subject'));
67   $cl_report_condition = trim($request->getParameter('report_condition'));
68 } else {
69   $cl_cron_spec = '0 4 * * 1'; // Default schedule - weekly on Mondays at 04:00 (server time).
70 }
71
72 $form = new Form('notificationForm');
73 $form->addInput(array('type'=>'combobox',
74   'name'=>'fav_report',
75   'style'=>'width: 250px;',
76   'value'=>$cl_fav_report,
77   'data'=>$fav_reports,
78   'datakeys'=>array('id','name'),
79   'empty'=>array(''=>$i18n->get('dropdown.select'))
80 ));
81 $form->addInput(array('type'=>'text','maxlength'=>'100','name'=>'cron_spec','style'=>'width: 250px;','value'=>$cl_cron_spec));
82 $form->addInput(array('type'=>'text','maxlength'=>'100','name'=>'email','style'=>'width: 250px;','value'=>$cl_email));
83 $form->addInput(array('type'=>'text','name'=>'cc','style'=>'width: 300px;','value'=>$cl_cc));
84 $form->addInput(array('type'=>'text','name'=>'subject','style'=>'width: 300px;','value'=>$cl_subject));
85 $form->addInput(array('type'=>'text','maxlength'=>'100','name'=>'report_condition','style'=>'width: 250px;','value'=>$cl_report_condition));
86 $form->addInput(array('type'=>'submit','name'=>'btn_add','value'=>$i18n->get('button.add')));
87
88 if ($request->isPost()) {
89   // Validate user input.
90   if (!$cl_fav_report) $err->add($i18n->get('error.report'));
91   if (!ttValidCronSpec($cl_cron_spec)) $err->add($i18n->get('error.field'), $i18n->get('label.schedule'));
92   if (!ttValidEmail($cl_email)) $err->add($i18n->get('error.field'), $i18n->get('label.email'));
93   if (!ttValidEmail($cl_cc, true)) $err->add($i18n->get('error.field'), $i18n->get('label.cc'));
94   if (!ttValidString($cl_subject, true)) $err->add($i18n->get('error.field'), $i18n->get('label.subject'));
95   if (!ttValidCondition($cl_report_condition)) $err->add($i18n->get('error.field'), $i18n->get('label.condition'));
96
97   if ($err->no()) {
98     // Calculate next execution time.
99     $next = tdCron::getNextOccurrence($cl_cron_spec, mktime()); 
100
101     if (ttNotificationHelper::insert(array(
102         'cron_spec' => $cl_cron_spec,
103         'next' => $next,
104         'report_id' => $cl_fav_report,
105         'email' => $cl_email,
106         'cc' => $cl_cc,
107         'subject' => $cl_subject,
108         'report_condition' => $cl_report_condition,
109         'status' => ACTIVE))) {
110         header('Location: notifications.php');
111         exit();
112       } else
113         $err->add($i18n->get('error.db'));
114   }
115 } // isPost
116
117 $smarty->assign('forms', array($form->getName()=>$form->toArray()));
118 $smarty->assign('title', $i18n->get('title.add_notification'));
119 $smarty->assign('content_page_name', 'notification_add.tpl');
120 $smarty->display('index.tpl');