mirror of
https://github.com/itflow-org/itflow
synced 2026-08-17 04:55:13 +00:00
More Client Enforcement in modals across the app
This commit is contained in:
@@ -13,6 +13,8 @@ $row = mysqli_fetch_assoc($sql);
|
|||||||
$contact_name = escapeHtml($row['contact_name']);
|
$contact_name = escapeHtml($row['contact_name']);
|
||||||
$client_id = intval($row['contact_client_id']);
|
$client_id = intval($row['contact_client_id']);
|
||||||
|
|
||||||
|
enforceClientAccess();
|
||||||
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|||||||
@@ -13,7 +13,8 @@ $row = mysqli_fetch_assoc($sql);
|
|||||||
$contact_name = escapeHtml($row['contact_name']);
|
$contact_name = escapeHtml($row['contact_name']);
|
||||||
$client_id = intval($row['contact_client_id']);
|
$client_id = intval($row['contact_client_id']);
|
||||||
|
|
||||||
// Generate the HTML form content using output buffering.
|
enforceClientAccess();
|
||||||
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|||||||
@@ -13,7 +13,8 @@ $row = mysqli_fetch_assoc($sql);
|
|||||||
$contact_name = escapeHtml($row['contact_name']);
|
$contact_name = escapeHtml($row['contact_name']);
|
||||||
$client_id = intval($row['contact_client_id']);
|
$client_id = intval($row['contact_client_id']);
|
||||||
|
|
||||||
// Generate the HTML form content using output buffering.
|
enforceClientAccess();
|
||||||
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|||||||
@@ -13,7 +13,8 @@ $row = mysqli_fetch_assoc($sql);
|
|||||||
$contact_name = escapeHtml($row['contact_name']);
|
$contact_name = escapeHtml($row['contact_name']);
|
||||||
$client_id = intval($row['contact_client_id']);
|
$client_id = intval($row['contact_client_id']);
|
||||||
|
|
||||||
// Generate the HTML form content using output buffering.
|
enforceClientAccess();
|
||||||
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|||||||
@@ -13,7 +13,8 @@ $row = mysqli_fetch_assoc($sql);
|
|||||||
$contact_name = escapeHtml($row['contact_name']);
|
$contact_name = escapeHtml($row['contact_name']);
|
||||||
$client_id = intval($row['contact_client_id']);
|
$client_id = intval($row['contact_client_id']);
|
||||||
|
|
||||||
// Generate the HTML form content using output buffering.
|
enforceClientAccess();
|
||||||
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|||||||
@@ -2,12 +2,19 @@
|
|||||||
|
|
||||||
require_once '../../../includes/modal_header.php';
|
require_once '../../../includes/modal_header.php';
|
||||||
|
|
||||||
|
enforceUserPermission('module_support', 2);
|
||||||
|
|
||||||
$ticket_id = intval($_GET['ticket_id']);
|
$ticket_id = intval($_GET['ticket_id']);
|
||||||
$client_id = intval(getFieldById('tickets', $ticket_id, 'ticket_client_id'));
|
$client_id = intval(getFieldById('tickets', $ticket_id, 'ticket_client_id'));
|
||||||
|
|
||||||
|
if ($client_id) {
|
||||||
|
enforceClientAccess();
|
||||||
|
}
|
||||||
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|
||||||
<div class="modal-header bg-dark">
|
<div class="modal-header bg-dark">
|
||||||
<h5 class="modal-title"><i class="fa fa-fw fa-eye mr-2"></i>Adding a ticket Watcher</h5>
|
<h5 class="modal-title"><i class="fa fa-fw fa-eye mr-2"></i>Adding a ticket Watcher</h5>
|
||||||
<button type="button" class="close text-white" data-dismiss="modal">
|
<button type="button" class="close text-white" data-dismiss="modal">
|
||||||
@@ -65,4 +72,5 @@ ob_start();
|
|||||||
</form>
|
</form>
|
||||||
|
|
||||||
<?php
|
<?php
|
||||||
|
|
||||||
require_once '../../../includes/modal_footer.php';
|
require_once '../../../includes/modal_footer.php';
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
|
|
||||||
require_once '../../../includes/modal_header.php';
|
require_once '../../../includes/modal_header.php';
|
||||||
|
|
||||||
|
enforceUserPermission('module_support', 2);
|
||||||
|
|
||||||
$ticket_reply_id = intval($_GET['id']);
|
$ticket_reply_id = intval($_GET['id']);
|
||||||
|
|
||||||
$sql = mysqli_query($mysqli, "SELECT * FROM ticket_replies
|
$sql = mysqli_query($mysqli, "SELECT * FROM ticket_replies
|
||||||
@@ -14,7 +16,10 @@ $row = mysqli_fetch_assoc($sql);
|
|||||||
$ticket_reply = escapeHtml($row['ticket_reply']);
|
$ticket_reply = escapeHtml($row['ticket_reply']);
|
||||||
$client_id = intval($row['ticket_client_id']);
|
$client_id = intval($row['ticket_client_id']);
|
||||||
|
|
||||||
// Generate the HTML form content using output buffering.
|
if ($client_id) {
|
||||||
|
enforceClientAccess();
|
||||||
|
}
|
||||||
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
@@ -28,7 +33,6 @@ ob_start();
|
|||||||
<form action="post.php" method="post" autocomplete="off">
|
<form action="post.php" method="post" autocomplete="off">
|
||||||
<input type="hidden" name="csrf_token" value="<?= $_SESSION['csrf_token'] ?>">
|
<input type="hidden" name="csrf_token" value="<?= $_SESSION['csrf_token'] ?>">
|
||||||
<input type="hidden" name="ticket_reply_id" value="<?php echo $ticket_reply_id; ?>">
|
<input type="hidden" name="ticket_reply_id" value="<?php echo $ticket_reply_id; ?>">
|
||||||
<input type="hidden" name="client_id" value="<?php echo $client_id; ?>">
|
|
||||||
|
|
||||||
<div class="modal-body">
|
<div class="modal-body">
|
||||||
|
|
||||||
|
|||||||
@@ -2,82 +2,89 @@
|
|||||||
|
|
||||||
require_once '../../../includes/modal_header.php';
|
require_once '../../../includes/modal_header.php';
|
||||||
|
|
||||||
|
enforceUserPermission('module_support', 2);
|
||||||
|
|
||||||
$task_id = intval($_GET['id']);
|
$task_id = intval($_GET['id']);
|
||||||
|
|
||||||
$sql = mysqli_query($mysqli, "SELECT * FROM tasks
|
$sql = mysqli_query($mysqli, "SELECT * FROM tasks
|
||||||
|
LEFT JOIN tickets ON task_ticket_id = ticket_id
|
||||||
WHERE task_id = $task_id
|
WHERE task_id = $task_id
|
||||||
LIMIT 1"
|
LIMIT 1"
|
||||||
);
|
);
|
||||||
|
|
||||||
$row = mysqli_fetch_assoc($sql);
|
$row = mysqli_fetch_assoc($sql);
|
||||||
$task_name = escapeHtml($row['task_name']);
|
$task_name = escapeHtml($row['task_name']);
|
||||||
|
$client_id = intval($row['ticket_client_id']);
|
||||||
|
|
||||||
|
if ($client_id) {
|
||||||
|
enforceClientAccess();
|
||||||
|
}
|
||||||
|
|
||||||
// Generate the HTML form content using output buffering.
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|
||||||
<div class="modal-header bg-dark">
|
<div class="modal-header bg-dark">
|
||||||
<h5 class="modal-title"><i class="fa fa-fw fa-shield-alt mr-2"></i>New approver for task <?=$task_name?></h5>
|
<h5 class="modal-title"><i class="fa fa-fw fa-shield-alt mr-2"></i>New approver for task <?=$task_name?></h5>
|
||||||
<button type="button" class="close text-white" data-dismiss="modal">
|
<button type="button" class="close text-white" data-dismiss="modal">
|
||||||
<span>×</span>
|
<span>×</span>
|
||||||
</button>
|
</button>
|
||||||
|
</div>
|
||||||
|
<form action="post.php" method="post" autocomplete="off">
|
||||||
|
<input type="hidden" name="csrf_token" value="<?= $_SESSION['csrf_token'] ?>">
|
||||||
|
<input type="hidden" name="task_id" value="<?php echo $task_id; ?>">
|
||||||
|
|
||||||
|
<div class="modal-body">
|
||||||
|
|
||||||
|
<div class="form-group">
|
||||||
|
<label>Approval scope <strong class="text-danger">*</strong></label>
|
||||||
|
<div class="input-group">
|
||||||
|
<div class="input-group-prepend">
|
||||||
|
<span class="input-group-text"><i class="fa fa-fw fa-layer-group"></i></span>
|
||||||
|
</div>
|
||||||
|
<select class="form-control" name="approval_scope" id="approval_scope" required>
|
||||||
|
<option value="">Select scope...</option>
|
||||||
|
<option value="internal">Internal</option>
|
||||||
|
<option value="client">Client</option>
|
||||||
|
</select>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
|
||||||
|
<div class="form-group d-none" id="approval_type_wrapper">
|
||||||
|
<label>Who can approve? <strong class="text-danger">*</strong></label>
|
||||||
|
<div class="input-group">
|
||||||
|
<div class="input-group-prepend">
|
||||||
|
<span class="input-group-text"><i class="fa fa-fw fa-user-check"></i></span>
|
||||||
|
</div>
|
||||||
|
<select class="form-control" name="approval_type" id="approval_type" required>
|
||||||
|
<!-- JS -->
|
||||||
|
</select>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
|
||||||
|
<div class="form-group d-none" id="specific_user_wrapper">
|
||||||
|
<label>Select specific internal approver <strong class="text-danger">*</strong></label>
|
||||||
|
<div class="input-group">
|
||||||
|
<div class="input-group-prepend">
|
||||||
|
<span class="input-group-text"><i class="fa fa-fw fa-user-circle"></i></span>
|
||||||
|
</div>
|
||||||
|
<select class="form-control select2" name="approval_required_user_id" id="specific_user_select">
|
||||||
|
<option value="">Select user...</option>
|
||||||
|
</select>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
|
||||||
</div>
|
</div>
|
||||||
<form action="post.php" method="post" autocomplete="off">
|
|
||||||
<input type="hidden" name="csrf_token" value="<?= $_SESSION['csrf_token'] ?>">
|
|
||||||
<input type="hidden" name="task_id" value="<?php echo $task_id; ?>">
|
|
||||||
|
|
||||||
<div class="modal-body">
|
<div class="modal-footer">
|
||||||
|
<button type="submit" name="add_ticket_task_approver" class="btn btn-primary text-bold"><i class="fa fa-check mr-2"></i>Save</button>
|
||||||
|
<button type="button" class="btn btn-light" data-dismiss="modal"><i class="fa fa-times mr-2"></i>Cancel</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
<div class="form-group">
|
</form>
|
||||||
<label>Approval scope <strong class="text-danger">*</strong></label>
|
|
||||||
<div class="input-group">
|
|
||||||
<div class="input-group-prepend">
|
|
||||||
<span class="input-group-text"><i class="fa fa-fw fa-layer-group"></i></span>
|
|
||||||
</div>
|
|
||||||
<select class="form-control" name="approval_scope" id="approval_scope" required>
|
|
||||||
<option value="">Select scope...</option>
|
|
||||||
<option value="internal">Internal</option>
|
|
||||||
<option value="client">Client</option>
|
|
||||||
</select>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
|
|
||||||
<div class="form-group d-none" id="approval_type_wrapper">
|
|
||||||
<label>Who can approve? <strong class="text-danger">*</strong></label>
|
|
||||||
<div class="input-group">
|
|
||||||
<div class="input-group-prepend">
|
|
||||||
<span class="input-group-text"><i class="fa fa-fw fa-user-check"></i></span>
|
|
||||||
</div>
|
|
||||||
<select class="form-control" name="approval_type" id="approval_type" required>
|
|
||||||
<!-- JS -->
|
|
||||||
</select>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
|
|
||||||
<div class="form-group d-none" id="specific_user_wrapper">
|
|
||||||
<label>Select specific internal approver <strong class="text-danger">*</strong></label>
|
|
||||||
<div class="input-group">
|
|
||||||
<div class="input-group-prepend">
|
|
||||||
<span class="input-group-text"><i class="fa fa-fw fa-user-circle"></i></span>
|
|
||||||
</div>
|
|
||||||
<select class="form-control select2" name="approval_required_user_id" id="specific_user_select">
|
|
||||||
<option value="">Select user...</option>
|
|
||||||
</select>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<div class="modal-footer">
|
|
||||||
<button type="submit" name="add_ticket_task_approver" class="btn btn-primary text-bold"><i class="fa fa-check mr-2"></i>Save</button>
|
|
||||||
<button type="button" class="btn btn-light" data-dismiss="modal"><i class="fa fa-times mr-2"></i>Cancel</button>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</form>
|
|
||||||
|
|
||||||
|
|
||||||
<!-- JS to make the correct boxes appear depending on if internal/client approval) -->
|
<!-- JS to make the correct boxes appear depending on if internal/client approval) -->
|
||||||
|
|||||||
@@ -2,9 +2,11 @@
|
|||||||
|
|
||||||
require_once '../../../includes/modal_header.php';
|
require_once '../../../includes/modal_header.php';
|
||||||
|
|
||||||
|
enforceUserPermission('module_support', 2);
|
||||||
|
|
||||||
$task_id = intval($_GET['id']);
|
$task_id = intval($_GET['id']);
|
||||||
|
|
||||||
$sql = mysqli_query($mysqli, "SELECT * FROM tasks
|
$sql = mysqli_query($mysqli, "SELECT * FROM tasks LEFT JOIN tickets ON task_ticket_id = ticket_id
|
||||||
WHERE task_id = $task_id
|
WHERE task_id = $task_id
|
||||||
LIMIT 1"
|
LIMIT 1"
|
||||||
);
|
);
|
||||||
@@ -13,6 +15,11 @@ $row = mysqli_fetch_assoc($sql);
|
|||||||
$task_name = escapeHtml($row['task_name']);
|
$task_name = escapeHtml($row['task_name']);
|
||||||
$task_completion_estimate = intval($row['task_completion_estimate']);
|
$task_completion_estimate = intval($row['task_completion_estimate']);
|
||||||
$task_completed_at = escapeHtml($row['task_completed_at']);
|
$task_completed_at = escapeHtml($row['task_completed_at']);
|
||||||
|
$client_id = intval($row['ticket_client_id']);
|
||||||
|
|
||||||
|
if ($client_id) {
|
||||||
|
enforceClientAccess();
|
||||||
|
}
|
||||||
|
|
||||||
// Approvals
|
// Approvals
|
||||||
$sql_task_approvals = mysqli_query($mysqli, "
|
$sql_task_approvals = mysqli_query($mysqli, "
|
||||||
@@ -22,7 +29,6 @@ $sql_task_approvals = mysqli_query($mysqli, "
|
|||||||
ORDER BY approval_approved_by"
|
ORDER BY approval_approved_by"
|
||||||
);
|
);
|
||||||
|
|
||||||
// Generate the HTML form content using output buffering.
|
|
||||||
ob_start();
|
ob_start();
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
|||||||
@@ -1943,7 +1943,14 @@ if (isset($_POST['redact_ticket_reply'])) {
|
|||||||
$ticket_reply_id = intval($_POST['ticket_reply_id']);
|
$ticket_reply_id = intval($_POST['ticket_reply_id']);
|
||||||
$ticket_reply = mysqli_real_escape_string($mysqli, $_POST['ticket_reply']);
|
$ticket_reply = mysqli_real_escape_string($mysqli, $_POST['ticket_reply']);
|
||||||
|
|
||||||
$client_id = intval($_POST['client_id']);
|
$sql = mysqli_query($mysqli, "SELECT ticket_client_id FROM ticket_replies
|
||||||
|
LEFT JOIN tickets ON ticket_id = ticket_reply_ticket_id
|
||||||
|
WHERE ticket_reply_id = $ticket_reply_id
|
||||||
|
LIMIT 1"
|
||||||
|
);
|
||||||
|
|
||||||
|
$row = mysqli_fetch_assoc($sql);
|
||||||
|
$client_id = intval($row['ticket_client_id']);
|
||||||
|
|
||||||
// Don't Enforce Client Access if Ticket doesn't have an assigned client
|
// Don't Enforce Client Access if Ticket doesn't have an assigned client
|
||||||
if ($client_id) {
|
if ($client_id) {
|
||||||
|
|||||||
Reference in New Issue
Block a user