2 /**********************************************************************
3 Copyright (C) FrontAccounting, LLC.
4 Released under the terms of the GNU Affero General Public License,
5 AGPL, as published by the Free Software Foundation, either version
6 3 of the License, or (at your option) any later version.
7 This program is distributed in the hope that it will be useful,
8 but WITHOUT ANY WARRANTY; without even the implied warranty of
9 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
10 See the License here <http://www.gnu.org/licenses/agpl-3.0.html>.
11 ***********************************************************************/
14 include_once($path_to_root . "/includes/session.inc");
18 include_once($path_to_root . "/includes/date_functions.inc");
19 include_once($path_to_root . "/includes/ui.inc");
21 include_once($path_to_root . "/admin/db/users_db.inc");
23 simple_page_mode(false);
24 //-------------------------------------------------------------------------------------------------
26 function can_process()
29 if (strlen($_POST['user_id']) < 4)
31 display_error( _("The user login entered must be at least 4 characters long."));
36 if ($_POST['password'] != "")
38 if (strlen($_POST['password']) < 4)
40 display_error( _("The password entered must be at least 4 characters long."));
41 set_focus('password');
45 if (strstr($_POST['password'], $_POST['user_id']) != false)
47 display_error( _("The password cannot contain the user login."));
48 set_focus('password');
56 //-------------------------------------------------------------------------------------------------
58 if ($Mode=='ADD_ITEM' || $Mode=='UPDATE_ITEM')
63 if ($selected_id != '')
65 update_user($_POST['user_id'], $_POST['real_name'], $_POST['phone'],
66 $_POST['email'], $_POST['Access'], $_POST['language'],
67 $_POST['profile'], check_value('rep_popup'), $_POST['pos']);
69 if ($_POST['password'] != "")
70 update_user_password($_POST['user_id'], md5($_POST['password']));
72 display_notification_centered(_("The selected user has been updated."));
76 add_user($_POST['user_id'], $_POST['real_name'], md5($_POST['password']),
77 $_POST['phone'], $_POST['email'], $_POST['Access'], $_POST['language'],
78 $_POST['profile'], check_value('rep_popup'), $_POST['pos']);
80 display_notification_centered(_("A new user has been added."));
86 //-------------------------------------------------------------------------------------------------
88 if ($Mode == 'Delete')
90 delete_user($selected_id);
91 display_notification_centered(_("User has been deleted."));
95 //-------------------------------------------------------------------------------------------------
99 unset($_POST); // clean all input fields
102 $result = get_users();
104 start_table($table_style);
106 if ($_SESSION["wa_current_user"]->access == 2)
107 $th = array(_("User login"), _("Full Name"), _("Phone"),
108 _("E-mail"), _("Last Visit"), _("Access Level"), "", "");
110 $th = array(_("User login"), _("Full Name"), _("Phone"),
111 _("E-mail"), _("Last Visit"), _("Access Level"), "");
114 $k = 0; //row colour counter
116 while ($myrow = db_fetch($result))
119 alt_table_row_color($k);
121 $last_visit_date = sql2date($myrow["last_visit_date"]);
123 /*The security_headings array is defined in config.php */
125 label_cell($myrow["user_id"]);
126 label_cell($myrow["real_name"]);
127 label_cell($myrow["phone"]);
128 email_cell($myrow["email"]);
129 label_cell($last_visit_date, "nowrap");
130 label_cell($security_headings[$myrow["full_access"]]);
131 edit_button_cell("Edit".$myrow["user_id"], _("Edit"));
132 if (strcasecmp($myrow["user_id"], $_SESSION["wa_current_user"]->username) &&
133 $_SESSION["wa_current_user"]->access == 2)
134 delete_button_cell("Delete".$myrow["user_id"], _("Delete"));
139 } //END WHILE LIST LOOP
145 //-------------------------------------------------------------------------------------------------
148 start_table($table_style2);
150 $_POST['email'] = "";
151 if ($selected_id != '')
153 if ($Mode == 'Edit') {
154 //editing an existing User
155 $myrow = get_user($selected_id);
157 $_POST['user_id'] = $myrow["user_id"];
158 $_POST['real_name'] = $myrow["real_name"];
159 $_POST['phone'] = $myrow["phone"];
160 $_POST['email'] = $myrow["email"];
161 $_POST['Access'] = $myrow["full_access"];
162 $_POST['language'] = $myrow["language"];
163 $_POST['profile'] = $myrow["print_profile"];
164 $_POST['rep_popup'] = $myrow["rep_popup"];
165 $_POST['pos'] = $myrow["pos"];
167 hidden('selected_id', $selected_id);
171 label_row(_("User login:"), $_POST['user_id']);
174 { //end of if $selected_id only do the else when a new record is being entered
175 text_row(_("User Login:"), "user_id", null, 22, 20);
176 $_POST['rep_popup'] = 1;
178 $_POST['password'] = "";
180 label_cell(_("Password:"));
181 label_cell("<input type='password' name='password' size=22 maxlength=20 value='" . $_POST['password'] . "'>");
184 if ($selected_id != '')
186 table_section_title(_("Enter a new password to change, leave empty to keep current."));
189 text_row_ex(_("Full Name").":", 'real_name', 50);
191 text_row_ex(_("Telephone No.:"), 'phone', 30);
193 email_row_ex(_("Email Address:"), 'email', 50);
195 security_headings_list_row(_("Access Level:"), 'Access', null);
197 languages_list_row(_("Language:"), 'language', null);
199 pos_list_row(_("User's POS"). ':', 'pos', null);
201 print_profiles_list_row(_("Printing profile"). ':', 'profile', null,
202 _('Browser printing support'));
204 check_row(_("Use popup window for reports:"), 'rep_popup', $_POST['rep_popup'],
205 false, _('Set this option to on if your browser directly supports pdf files'));
209 submit_add_or_update_center($selected_id == '', '', true);