Cleanup - removed ancient references to pre-2.2 modules/plugins.
[fa-stable.git] / sql / alter2.2.php
1 <?php
2 /**********************************************************************
3     Copyright (C) FrontAccounting, LLC.
4         Released under the terms of the GNU General Public License, GPL, 
5         as published by the Free Software Foundation, either version 3 
6         of the License, or (at your option) any later version.
7     This program is distributed in the hope that it will be useful,
8     but WITHOUT ANY WARRANTY; without even the implied warranty of
9     MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  
10     See the License here <http://www.gnu.org/licenses/gpl-3.0.html>.
11 ***********************************************************************/
12
13 class fa2_2 {
14         var $version = '2.2';   // version installed
15         var $description;
16         var $sql = 'alter2.2.sql';
17         var $preconf = true;
18         var $beta = false; // upgrade from 2.1 or 2.2beta; set in pre_check
19         
20         function fa2_2() {
21                 global $security_groups;
22                 $this->beta = !isset($security_groups);
23                 $this->description = _('Upgrade from version 2.1/2.2beta to 2.2');
24                 $this->preconf = fix_extensions();
25         }
26         
27         //
28         //      Install procedure. All additional changes 
29         //      not included in sql file should go here.
30         //
31         function install($pref, $force) 
32         {
33                 global $db, $systypes_array;
34                 
35                 if (!$this->preconf)
36                         return false;
37
38                 // Until 2.2 sanitizing text input with db_escape was not
39                 // consequent enough. To avoid comparision problems we have to 
40                 // fix this now.
41                 sanitize_database($pref);
42
43                 if ($this->beta)        // nothing more to be done on upgrade from 2.2beta
44                         return true;
45
46                 // set item category dflt accounts to values from company GL setup
47                 $prefs = get_company_prefs();
48                 $sql = "UPDATE {$pref}stock_category SET "
49                         ."dflt_sales_act = '" . $prefs['default_inv_sales_act'] . "',"
50                         ."dflt_cogs_act = '". $prefs['default_cogs_act'] . "',"
51                         ."dflt_inventory_act = '" . $prefs['default_inventory_act'] . "',"
52                         ."dflt_adjustment_act = '" . $prefs['default_adj_act'] . "',"
53                         ."dflt_assembly_act = '" . $prefs['default_assembly_act']."'";
54                 if (db_query($sql)==false) {
55                         display_error("Cannot update category default GL accounts"
56                         .':<br>'. db_error_msg($db));
57                         return false;
58                 }
59                 // add all references to refs table for easy searching via journal interface
60                 foreach($systypes_array as $typeno => $typename) {
61                         $info = get_systype_db_info($typeno);
62                         if ($info == null || $info[3] == null) continue;
63                         $tbl = str_replace(TB_PREF, $pref, $info[0]);
64                         $sql = "SELECT DISTINCT {$info[2]} as id,{$info[3]} as ref FROM $tbl";
65                         if ($info[1])
66                                 $sql .= " WHERE {$info[1]}=$typeno";
67                         $result = db_query($sql);
68                         if (db_num_rows($result)) {
69                                 while ($row = db_fetch($result)) {
70                                         $res2 = db_query("INSERT INTO {$pref}refs VALUES("
71                                                 . $row['id'].",".$typeno.",'".$row['ref']."')");
72                                         if (!$res2) {
73                                                 display_error(_("Cannot copy references from $tbl")
74                                                         .':<br>'. db_error_msg($db));
75                                                 return false;
76                                         }
77                                 }
78                         }
79                 }
80
81                 if (!($ret = db_query("SELECT MAX(`order_no`) FROM `{$pref}sales_orders`")) ||
82                         !db_num_rows($ret))
83                 {
84                                 display_error(_('Cannot query max sales order number.'));
85                                 return false;
86                 } 
87                 $row = db_fetch($ret);
88                 $max_order = $row[0];
89                 $next_ref = $max_order+1;
90                 $sql = "UPDATE `{$pref}sys_types` 
91                         SET `type_no`='$max_order',`next_reference`='$next_ref'
92                         WHERE `type_id`=30";
93                 if(!db_query($sql))
94                 {
95                         display_error(_('Cannot store next sales order reference.'));
96                         return false;
97                 }
98                 return convert_roles($pref);
99         }
100         //
101         //      Checking before install
102         //
103         function pre_check($pref, $force)
104         {       
105                 global $security_groups;
106                 
107                 if ($this->beta && !$force)
108                         $this->sql = 'alter2.2rc.sql';
109                 // return ok when security groups still defined (upgrade from 2.1)
110                 // or usersonline not defined (upgrade from 2.2 beta)
111                 return isset($security_groups) || (check_table($pref, 'usersonline')!=0);
112         }
113         //
114         //      Test if patch was applied before.
115         //
116         function installed($pref) {
117                 $n = 1; // number of patches to be installed
118                 $patchcnt = 0;
119                 if (!$this->beta) {
120                         $n = 16;
121                         if (check_table($pref, 'company')) // skip in 2.3
122                                 $n -= 3;
123                         else {
124                                 if (check_table($pref, 'company', 'custom1_name')) $patchcnt++;
125                                 if (!check_table($pref, 'company', 'profit_loss_year_act'))     $patchcnt++;
126                                 if (!check_table($pref, 'company', 'login_tout')) $patchcnt++;
127                         }
128                         if (!check_table($pref, 'stock_category', 'dflt_no_sale')) $patchcnt++;
129                         if (!check_table($pref, 'users', 'sticky_doc_date')) $patchcnt++;
130                         if (!check_table($pref, 'users', 'startup_tab')) $patchcnt++;
131                         if (!check_table($pref, 'cust_branch', 'inactive')) $patchcnt++;
132                         if (!check_table($pref, 'chart_class', 'ctype')) $patchcnt++;
133                         if (!check_table($pref, 'audit_trail')) $patchcnt++;
134                         if (!check_table($pref, 'currencies', 'auto_update')) $patchcnt++;
135                         if (!check_table($pref, 'stock_master','no_sale')) $patchcnt++;
136                         if (!check_table($pref, 'suppliers', 'supp_ref')) $patchcnt++;
137                         if (!check_table($pref, 'users', 'role_id')) $patchcnt++;
138                         if (!check_table($pref, 'sales_orders', 'reference')) $patchcnt++;
139                         if (!check_table($pref, 'tags')) $patchcnt++;
140                 } 
141                 if (!check_table($pref, 'useronline')) $patchcnt++;
142
143                 $n -= $patchcnt;
144                 return $n == 0 ? true : $patchcnt;
145         }
146 };
147
148 /*
149         Conversion of old security roles stored into $security_groups table
150 */
151 function convert_roles($pref) 
152 {
153                 global $security_groups, $security_headings, $security_areas, $path_to_root;
154                 include_once($path_to_root."/includes/access_levels.inc");
155
156         $trans_sec = array(
157                 1 => array('SA_CHGPASSWD', 'SA_SETUPDISPLAY', 'SA_BANKTRANSVIEW',
158                         'SA_ITEMSTRANSVIEW','SA_SUPPTRANSVIEW', 'SA_SALESORDER',
159                         'SA_SALESALLOC', 'SA_SALESTRANSVIEW'),
160                 2 => array('SA_DIMTRANSVIEW', 'SA_STANDARDCOST', 'SA_ITEMSTRANSVIEW',
161                         'SA_ITEMSSTATVIEW', 'SA_SALESPRICE', 'SA_MANUFTRANSVIEW',
162                         'SA_WORKORDERANALYTIC', 'SA_WORKORDERCOST', 'SA_SUPPTRANSVIEW',
163                         'SA_SUPPLIERALLOC', 'SA_STEMPLATE', 'SA_SALESTRANSVIEW',
164                         'SA_SALESINVOICE', 'SA_SALESDELIVERY', 'SA_CUSTPAYMREP',
165                         'SA_CUSTBULKREP', 'SA_PRICEREP', 'SA_SALESBULKREP', 'SA_SALESMANREP',
166                         'SA_SALESBULKREP', 'SA_CUSTSTATREP', 'SA_SUPPLIERANALYTIC',
167                         'SA_SUPPPAYMREP', 'SA_SUPPBULKREP', 'SA_ITEMSVALREP', 'SA_ITEMSANALYTIC',
168                         'SA_BOMREP', 'SA_MANUFBULKREP', 'SA_DIMENSIONREP', 'SA_BANKREP', 'SA_GLREP',
169                         'SA_GLANALYTIC', 'SA_TAXREP', 'SA_SALESANALYTIC', 'SA_SALESQUOTE'),
170                 3 => array('SA_GLACCOUNTGROUP', 'SA_GLACCOUNTCLASS','SA_PAYMENT', 
171                         'SA_DEPOSIT', 'SA_JOURNALENTRY', 'SA_INVENTORYMOVETYPE',
172                         'SA_LOCATIONTRANSFER', 'SA_INVENTORYADJUSTMENT', 'SA_WORKCENTRES',
173                         'SA_MANUFISSUE', 'SA_SUPPLIERALLOC', 'SA_CUSTOMER', 'SA_CRSTATUS',
174                         'SA_SALESMAN', 'SA_SALESAREA', 'SA_SALESALLOC', 'SA_SALESCREDITINV',
175                         'SA_SALESPAYMNT', 'SA_SALESCREDIT', 'SA_SALESGROUP', 'SA_SRECURRENT',
176                         'SA_TAXRATES', 'SA_ITEMTAXTYPE', 'SA_TAXGROUPS', 'SA_QUICKENTRY'),
177                 4 => array('SA_REORDER', 'SA_PURCHASEPRICING', 'SA_PURCHASEORDER'),
178                 5 => array('SA_VIEWPRINTTRANSACTION', 'SA_BANKTRANSFER', 'SA_SUPPLIER',
179                         'SA_SUPPLIERINVOICE', 'SA_SUPPLIERPAYMNT', 'SA_SUPPLIERCREDIT'),
180                 8 => array('SA_ATTACHDOCUMENT', 'SA_RECONCILE', 'SA_GLANALYTIC',
181                         'SA_TAXREP', 'SA_BANKTRANSVIEW', 'SA_GLTRANSVIEW'),
182                 9 => array('SA_FISCALYEARS', 'SA_CURRENCY', 'SA_EXCHANGERATE', 
183                         'SA_BOM'),
184                 10 => array('SA_PAYTERMS', 'SA_GLSETUP', 'SA_SETUPCOMPANY',
185                         'SA_FORMSETUP', 'SA_DIMTRANSVIEW', 'SA_DIMENSION', 'SA_BANKACCOUNT',
186                         'SA_GLACCOUNT', 'SA_BUDGETENTRY', 'SA_MANUFRECEIVE',
187                         'SA_MANUFRELEASE', 'SA_WORKORDERENTRY', 'SA_MANUFTRANSVIEW',
188                         'SA_WORKORDERCOST'),
189                 11 => array('SA_ITEMCATEGORY', 'SA_ITEM', 'SA_UOM', 'SA_INVENTORYLOCATION',
190                          'SA_GRN', 'SA_FORITEMCODE', 'SA_SALESKIT'),
191                 14 => array('SA_SHIPPING', 'SA_VOIDTRANSACTION', 'SA_SALESTYPES'),
192                 15 => array('SA_PRINTERS', 'SA_PRINTPROFILE', 'SA_BACKUP', 'SA_USERS',
193                         'SA_POSSETUP'),
194                 20 => array('SA_CREATECOMPANY', 'SA_CREATELANGUAGE', 'SA_CREATEMODULES',
195                         'SA_SOFTWAREUPGRADE', 'SA_SECROLES', 'SA_DIMTAGS', 'SA_GLACCOUNTTAGS')
196                 );
197                 $new_ids = array();
198                 foreach ($security_groups as $role_id => $areas) {
199                         $area_set = array();
200                         $sections = array();
201                         foreach ($areas as $a) {
202                          if (isset($trans_sec[$a]))
203                                 foreach ($trans_sec[$a] as $id) {
204                                  if ($security_areas[$id][0] != 0)
205 //                                      error_log('invalid area id: '.$a.':'.$id);
206                                         $area_set[] = $security_areas[$id][0];
207                                         $sections[$security_areas[$id][0]&~0xff] = 1;
208                                 }
209                         }
210                         $sections  = array_keys($sections);
211                         sort($sections); sort($area_set);
212                         import_security_role($pref, $security_headings[$role_id], $sections, $area_set);
213                         $new_ids[$role_id] = db_insert_id();
214                 }
215                 $result = get_users(true);
216                 $users = array();
217                 while($row = db_fetch($result)) { // complete old user ids and roles
218                         $users[$row['role_id']][] = $row['id'];
219                 }
220                 foreach($users as $old_id => $uids)
221                         foreach( $uids as $id) {
222                                 $sql = "UPDATE {$pref}users set role_id=".$new_ids[$old_id].
223                                         " WHERE id=$id";
224                                 $ret = db_query($sql, 'cannot update users roles');
225                                 if(!$ret) return false;
226                         }
227                 return true;
228 }
229
230 function import_security_role($pref, $name, $sections, $areas)
231 {
232         $sql = "INSERT INTO {$pref}security_roles (role, description, sections, areas)
233         VALUES (".db_escape('FA 2.1 '.$name).",".db_escape($name).","
234         .db_escape(implode(';',$sections)).",".db_escape(implode(';',$areas)).")";
235
236         db_query($sql, "could not add new security role");
237 }
238
239 /*
240         Changes in extensions system.
241         This function is executed once on first Upgrade System display.
242 */
243 function fix_extensions() {
244         global $path_to_root, $db_connections;
245
246         if (!file_exists($path_to_root.'/modules/installed_modules.php'))
247                 return true; // already converted
248         
249         if (!is_writable($path_to_root.'/modules/installed_modules.php')) {
250                 display_error(_('Cannot upgrade extensions system: file /modules/installed_modules.php is not writeable'));
251                 return false;
252         }
253         
254         $exts = array();
255         include($path_to_root.'/installed_extensions.php');
256         foreach($installed_extensions as $ext) {
257                 $ext['filename'] = $ext['app_file']; unset($ext['app_file']);
258                 $ext['tab'] = $ext['name'];
259                 $ext['name'] = access_string($ext['title'], true); 
260                 $ext['path'] = $ext['folder']; unset($ext['folder']);
261                 $ext['type'] = 'extension';
262                 $ext['active'] = '1';
263                 $exts[] = $ext;
264         }
265
266         if (!write_extensions($exts))
267                 return false;
268         
269         $cnt = count($db_connections);
270         for ($i = 0; $i < $cnt; $i++)
271                 write_extensions($exts, $i);
272
273         unlink($path_to_root.'/modules/installed_modules.php');
274         return true;
275 }
276
277 /*
278         Find and update all database records with special chars in text fields 
279         to ensure all of them are changed to html entites.
280 */
281 function sanitize_database($pref, $test = false) {
282
283          if ($test)
284                 error_log('Sanitizing database ...');
285
286          $tsql = "SHOW TABLES LIKE '".($pref=='' ? '' : substr($pref,0,-1).'\\_')."%'";
287          $tresult = db_query($tsql, "Cannot select all tables with prefix '$pref'");
288          while($tbl = db_fetch($tresult)) {
289                 $table = $tbl[0];
290                 $csql = "SHOW COLUMNS FROM $table";
291                 $cresult = db_query($csql, "Cannot select column names for table '$table'");
292                 $textcols = $keys = array();
293                 while($col = db_fetch($cresult)) {
294                         if (strpos($col['Type'], 'char')!==false 
295                                         || strpos($col['Type'], 'text')!==false)
296                                 $textcols[] = '`'.$col['Field'].'`';
297                         if ($col['Key'] == 'PRI') {
298                                 $keys[] = '`'.$col['Field'].'`';
299                         }
300                 }
301
302                 if (empty($keys)) { // comments table have no primary key, so let's give up
303                         continue;
304                 }
305                 if ($test)
306                         error_log("Table $table (".implode(',',$keys)."):(".implode(',',$textcols)."):");
307
308                 if (!count($textcols)) continue;
309
310                 // fetch all records containing special characters in text fields
311                 $sql = "SELECT ".implode(',', array_unique(array_merge($keys,$textcols)))
312                         ." FROM {$table} WHERE 
313                         CONCAT(".implode(',', $textcols).") REGEXP '[\\'\"><&]'";
314                 $result = db_query($sql, "Cannot select all suspicious fields in $table");
315
316                 // and fix them
317                 while($rec= db_fetch($result)) {
318                         $sql = "UPDATE {$table} SET ";
319                         $val = $key = array();
320                         foreach ($textcols as $f) {
321                                 $val[] = $f.'='.db_escape($rec[substr($f,1,-1)]);
322                         }
323                         $sql .= implode(',', $val). ' WHERE ';
324                         foreach ($keys as $k) {
325                                 $key[] = $k.'=\''.$rec[substr($k,1,-1)].'\'';
326                         }
327                         $sql .= implode( ' AND ', $key);
328                         if ($test) {
329                                 error_log($sql);
330                                 error_log("\t(".implode(',',$val).") updated");
331                         } else
332                                 db_query($sql, 'cannot update record');
333                 }
334         }
335          if ($test)
336                 error_log('Sanitizing done.');
337 }
338
339 $install = new fa2_2;
340 ?>