)
+ $imap_mailbox = "$config_imap_host:$config_imap_port/imap/readonly/$config_imap_encryption";
+
+ // Connect
+ $imap = imap_open("{{$imap_mailbox}}INBOX", $config_smtp_username, $config_smtp_password);
+
+ if ($imap) {
+ $_SESSION['alert_message'] = "Connected successfully";
+ } else {
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Test IMAP connection failed";
+ }
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_invoice_settings'])) {
+
+ validateAdminRole();
+
+ $config_invoice_prefix = sanitizeInput($_POST['config_invoice_prefix']);
+ $config_invoice_next_number = intval($_POST['config_invoice_next_number']);
+ $config_invoice_footer = sanitizeInput($_POST['config_invoice_footer']);
+ $config_invoice_from_email = sanitizeInput($_POST['config_invoice_from_email']);
+ $config_invoice_from_name = sanitizeInput($_POST['config_invoice_from_name']);
+ $config_recurring_prefix = sanitizeInput($_POST['config_recurring_prefix']);
+ $config_recurring_next_number = intval($_POST['config_recurring_next_number']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_invoice_prefix = '$config_invoice_prefix', config_invoice_next_number = $config_invoice_next_number, config_invoice_footer = '$config_invoice_footer', config_invoice_from_email = '$config_invoice_from_email', config_invoice_from_name = '$config_invoice_from_name', config_recurring_prefix = '$config_recurring_prefix', config_recurring_next_number = $config_recurring_next_number WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified invoice settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Invoice Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_quote_settings'])) {
+
+ validateAdminRole();
+
+ $config_quote_prefix = sanitizeInput($_POST['config_quote_prefix']);
+ $config_quote_next_number = intval($_POST['config_quote_next_number']);
+ $config_quote_footer = sanitizeInput($_POST['config_quote_footer']);
+ $config_quote_from_email = sanitizeInput($_POST['config_quote_from_email']);
+ $config_quote_from_name = sanitizeInput($_POST['config_quote_from_name']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_quote_prefix = '$config_quote_prefix', config_quote_next_number = $config_quote_next_number, config_quote_footer = '$config_quote_footer', config_quote_from_email = '$config_quote_from_email', config_quote_from_name = '$config_quote_from_name' WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified quote settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Quote Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_ticket_settings'])) {
+
+ validateAdminRole();
+
+ $config_ticket_prefix = sanitizeInput($_POST['config_ticket_prefix']);
+ $config_ticket_next_number = intval($_POST['config_ticket_next_number']);
+ $config_ticket_from_email = sanitizeInput($_POST['config_ticket_from_email']);
+ $config_ticket_from_name = sanitizeInput($_POST['config_ticket_from_name']);
+ $config_ticket_email_parse = intval($_POST['config_ticket_email_parse']);
+ $config_ticket_client_general_notifications = intval($_POST['config_ticket_client_general_notifications']);
+ $config_ticket_autoclose = intval($_POST['config_ticket_autoclose']);
+ $config_ticket_autoclose_hours = intval($_POST['config_ticket_autoclose_hours']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_ticket_prefix = '$config_ticket_prefix', config_ticket_next_number = $config_ticket_next_number, config_ticket_from_email = '$config_ticket_from_email', config_ticket_from_name = '$config_ticket_from_name', config_ticket_email_parse = '$config_ticket_email_parse', config_ticket_client_general_notifications = $config_ticket_client_general_notifications , config_ticket_autoclose = $config_ticket_autoclose, config_ticket_autoclose_hours = $config_ticket_autoclose_hours WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified ticket settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Ticket Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_default_settings'])) {
+
+ validateAdminRole();
+
+ $expense_account = intval($_POST['expense_account']);
+ $payment_account = intval($_POST['payment_account']);
+ $payment_method = sanitizeInput($_POST['payment_method']);
+ $expense_payment_method = sanitizeInput($_POST['expense_payment_method']);
+ $transfer_from_account = intval($_POST['transfer_from_account']);
+ $transfer_to_account = intval($_POST['transfer_to_account']);
+ $calendar = intval($_POST['calendar']);
+ $net_terms = intval($_POST['net_terms']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_default_expense_account = $expense_account, config_default_payment_account = $payment_account, config_default_payment_method = '$payment_method', config_default_expense_payment_method = '$expense_payment_method', config_default_transfer_from_account = $transfer_from_account, config_default_transfer_to_account = $transfer_to_account, config_default_calendar = $calendar, config_default_net_terms = $net_terms WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified default settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Default settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['edit_theme_settings'])) {
+
+ validateAdminRole();
+
+ $theme = preg_replace("/[^0-9a-zA-Z-]/", "", sanitizeInput($_POST['theme']));
+
+ mysqli_query($mysqli,"UPDATE settings SET config_theme = '$theme' WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified theme settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Changed theme to $theme";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['edit_alert_settings'])) {
+
+ validateAdminRole();
+
+ $config_enable_cron = intval($_POST['config_enable_cron']);
+ $config_cron_key = sanitizeInput($_POST['config_cron_key']);
+ $config_enable_alert_domain_expire = intval($_POST['config_enable_alert_domain_expire']);
+ $config_send_invoice_reminders = intval($_POST['config_send_invoice_reminders']);
+ $config_invoice_overdue_reminders = sanitizeInput($_POST['config_invoice_overdue_reminders']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_send_invoice_reminders = $config_send_invoice_reminders, config_invoice_overdue_reminders = '$config_invoice_overdue_reminders', config_enable_cron = $config_enable_cron, config_enable_alert_domain_expire = $config_enable_alert_domain_expire WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified alert settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Alert Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['generate_cron_key'])) {
+ validateAdminRole();
+
+ $key = randomString(32);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_cron_key = '$key' WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name regenerated cron key', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Cron key regenerated!";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_online_payment_settings'])) {
+
+ validateAdminRole();
+
+ $config_stripe_enable = intval($_POST['config_stripe_enable']);
+ $config_stripe_publishable = sanitizeInput($_POST['config_stripe_publishable']);
+ $config_stripe_secret = sanitizeInput($_POST['config_stripe_secret']);
+ $config_stripe_account = intval($_POST['config_stripe_account']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_stripe_enable = $config_stripe_enable, config_stripe_publishable = '$config_stripe_publishable', config_stripe_secret = '$config_stripe_secret', config_stripe_account = $config_stripe_account WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified online payment settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Online Payment Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['edit_integrations_settings'])) {
+
+ validateAdminRole();
+
+ $azure_client_id = sanitizeInput($_POST['azure_client_id']);
+ $azure_client_secret = sanitizeInput($_POST['azure_client_secret']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_azure_client_id = '$azure_client_id', config_azure_client_secret = '$azure_client_secret' WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified integrations settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Integrations Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_module_settings'])) {
+
+ validateAdminRole();
+
+ $config_module_enable_itdoc = intval($_POST['config_module_enable_itdoc']);
+ $config_module_enable_ticketing = intval($_POST['config_module_enable_ticketing']);
+ $config_module_enable_accounting = intval($_POST['config_module_enable_accounting']);
+ $config_client_portal_enable = intval($_POST['config_client_portal_enable']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_module_enable_itdoc = $config_module_enable_itdoc, config_module_enable_ticketing = $config_module_enable_ticketing, config_module_enable_accounting = $config_module_enable_accounting, config_client_portal_enable = $config_client_portal_enable WHERE company_id = 1");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified module settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Module Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_security_settings'])) {
+ validateAdminRole();
+
+ $config_login_key_required = intval($_POST['config_login_key_required']);
+ $config_login_key_secret = sanitizeInput($_POST['config_login_key_secret']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_login_key_required = '$config_login_key_required', config_login_key_secret = '$config_login_key_secret' WHERE company_id = 1");
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified login key settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Login key settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['edit_telemetry_settings'])) {
+
+ validateAdminRole();
+
+ $config_telemetry = intval($_POST['config_telemetry']);
+
+ mysqli_query($mysqli,"UPDATE settings SET config_telemetry = $config_telemetry WHERE company_id = 1");
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Modify', log_description = '$session_name modified telemetry settings', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Telemetry Settings updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['send_telemetry_data'])) {
+
+ validateAdminRole();
+
+ $comments = sanitizeInput($_POST['comments']);
+
+ $sql = mysqli_query($mysqli,"SELECT * FROM companies WHERE company_id = 1");
+ $row = mysqli_fetch_array($sql);
+
+ $company_name = sanitizeInput($row['company_name']);
+ $city = sanitizeInput($row['company_city']);
+ $state = sanitizeInput($row['company_state']);
+ $country = sanitizeInput($row['company_country']);
+ $currency = sanitizeInput($row['company_currency']);
+ $current_version = exec("git rev-parse HEAD");
+
+ // Client Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('client_id') AS num FROM clients"));
+ $client_count = $row['num'];
+
+ // Ticket Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('recurring_id') AS num FROM tickets"));
+ $ticket_count = $row['num'];
+
+ // Calendar Event Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('event_id') AS num FROM events"));
+ $calendar_event_count = $row['num'];
+
+ // Quote Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('quote_id') AS num FROM quotes"));
+ $quote_count = $row['num'];
+
+ // Invoice Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('invoice_id') AS num FROM invoices"));
+ $invoice_count = $row['num'];
+
+ // Revenue Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('revenue_id') AS num FROM revenues"));
+ $revenue_count = $row['num'];
+
+ // Recurring Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('recurring_id') AS num FROM recurring"));
+ $recurring_count = $row['num'];
+
+ // Account Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('account_id') AS num FROM accounts"));
+ $account_count = $row['num'];
+
+ // Tax Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('tax_id') AS num FROM taxes"));
+ $tax_count = $row['num'];
+
+ // Product Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('product_id') AS num FROM products"));
+ $product_count = $row['num'];
+
+ // Payment Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('payment_id') AS num FROM payments WHERE payment_invoice_id > 0"));
+ $payment_count = $row['num'];
+
+ // Company Vendor Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('vendor_id') AS num FROM vendors WHERE vendor_template = 0 AND vendor_client_id = 0"));
+ $company_vendor_count = $row['num'];
+
+ // Expense Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('expense_id') AS num FROM expenses WHERE expense_vendor_id > 0"));
+ $expense_count = $row['num'];
+
+ // Trip Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('trip_id') AS num FROM trips"));
+ $trip_count = $row['num'];
+
+ // Transfer Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('transfer_id') AS num FROM transfers"));
+ $transfer_count = $row['num'];
+
+ // Contact Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('contact_id') AS num FROM contacts"));
+ $contact_count = $row['num'];
+
+ // Location Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('location_id') AS num FROM locations"));
+ $location_count = $row['num'];
+
+ // Asset Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('asset_id') AS num FROM assets"));
+ $asset_count = $row['num'];
+
+ // Software Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('software_id') AS num FROM software WHERE software_template = 0"));
+ $software_count = $row['num'];
+
+ // Software Template Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('software_id') AS num FROM software WHERE software_template = 1"));
+ $software_template_count = $row['num'];
+
+ // Password Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('login_id') AS num FROM logins"));
+ $password_count = $row['num'];
+
+ // Network Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('network_id') AS num FROM networks"));
+ $network_count = $row['num'];
+
+ // Certificate Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('certificate_id') AS num FROM certificates"));
+ $certificate_count = $row['num'];
+
+ // Domain Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('domain_id') AS num FROM domains"));
+ $domain_count = $row['num'];
+
+ // Service Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('service_id') AS num FROM services"));
+ $service_count = $row['num'];
+
+ // Client Vendor Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('vendor_id') AS num FROM vendors WHERE vendor_template = 0 AND vendor_client_id > 0"));
+ $client_vendor_count = $row['num'];
+
+ // Vendor Template Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('vendor_id') AS num FROM vendors WHERE vendor_template = 1"));
+ $vendor_template_count = $row['num'];
+
+ // File Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('file_id') AS num FROM files"));
+ $file_count = $row['num'];
+
+ // Document Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('document_id') AS num FROM documents WHERE document_template = 0"));
+ $document_count = $row['num'];
+
+ // Document Template Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('document_id') AS num FROM documents WHERE document_template = 1"));
+ $document_template_count = $row['num'];
+
+ // Shared Item Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('item_id') AS num FROM shared_items"));
+ $shared_item_count = $row['num'];
+
+ // Company Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('company_id') AS num FROM companies"));
+ $company_count = $row['num'];
+
+ // User Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('user_id') AS num FROM users"));
+ $user_count = $row['num'];
+
+ // Category Expense Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Expense'"));
+ $category_expense_count = $row['num'];
+
+ // Category Income Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Income'"));
+ $category_income_count = $row['num'];
+
+ // Category Referral Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Referral'"));
+ $category_referral_count = $row['num'];
+
+ // Category Payment Method Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Payment Method'"));
+ $category_payment_method_count = $row['num'];
+
+ // Tag Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('tag_id') AS num FROM tags"));
+ $tag_count = $row['num'];
+
+ // API Key Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('api_key_id') AS num FROM api_keys"));
+ $api_key_count = $row['num'];
+
+ // Log Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('log_id') AS num FROM logs"));
+ $log_count = $row['num'];
+
+ $postdata = http_build_query(
+ array(
+ 'installation_id' => "$installation_id",
+ 'version' => "$current_version",
+ 'company_name' => "$company_name",
+ 'city' => "$city",
+ 'state' => "$state",
+ 'country' => "$country",
+ 'currency' => "$currency",
+ 'comments' => "$comments",
+ 'client_count' => $client_count,
+ 'ticket_count' => $ticket_count,
+ 'calendar_event_count' => $calendar_event_count,
+ 'quote_count' => $quote_count,
+ 'invoice_count' => $invoice_count,
+ 'revenue_count' => $revenue_count,
+ 'recurring_count' => $recurring_count,
+ 'account_count' => $account_count,
+ 'tax_count' => $tax_count,
+ 'product_count' => $product_count,
+ 'payment_count' => $payment_count,
+ 'company_vendor_count' => $company_vendor_count,
+ 'expense_count' => $expense_count,
+ 'trip_count' => $trip_count,
+ 'transfer_count' => $transfer_count,
+ 'contact_count' => $contact_count,
+ 'location_count' => $location_count,
+ 'asset_count' => $asset_count,
+ 'software_count' => $software_count,
+ 'software_template_count' => $software_template_count,
+ 'password_count' => $password_count,
+ 'network_count' => $network_count,
+ 'certificate_count' => $certificate_count,
+ 'domain_count' => $domain_count,
+ 'service_count' => $service_count,
+ 'client_vendor_count' => $client_vendor_count,
+ 'vendor_template_count' => $vendor_template_count,
+ 'file_count' => $file_count,
+ 'document_count' => $document_count,
+ 'document_template_count' => $document_template_count,
+ 'shared_item_count' => $shared_item_count,
+ 'company_count' => $company_count,
+ 'user_count' => $user_count,
+ 'category_expense_count' => $category_expense_count,
+ 'category_income_count' => $category_income_count,
+ 'category_referral_count' => $category_referral_count,
+ 'category_payment_method_count' => $category_payment_method_count,
+ 'tag_count' => $tag_count,
+ 'api_key_count' => $api_key_count,
+ 'log_count' => $log_count,
+ 'config_theme' => "$config_theme",
+ 'config_enable_cron' => $config_enable_cron,
+ 'config_ticket_email_parse' => $config_ticket_email_parse,
+ 'config_module_enable_itdoc' => $config_module_enable_itdoc,
+ 'config_module_enable_ticketing' => $config_module_enable_ticketing,
+ 'config_module_enable_accounting' => $config_module_enable_accounting,
+ 'collection_method' => 2
+ )
+ );
+
+ $opts = array('http' =>
+ array(
+ 'method' => 'POST',
+ 'header' => 'Content-type: application/x-www-form-urlencoded',
+ 'content' => $postdata
+ )
+ );
+
+ $context = stream_context_create($opts);
+
+ $result = file_get_contents('https://telemetry.itflow.org', false, $context);
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Telemetry', log_action = 'Sent', log_description = '$session_name manually sent telemetry results to the ITFlow Developers', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Telemetry data sent to the ITFlow developers";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['download_database'])) {
+
+ validateAdminRole();
+
+ // Get All Table Names From the Database
+ $tables = array();
+ $sql = "SHOW TABLES";
+ $result = mysqli_query($mysqli, $sql);
+
+ while ($row = mysqli_fetch_row($result)) {
+ $tables[] = $row[0];
+ }
+
+ $sqlScript = "";
+ foreach ($tables as $table) {
+
+ // Prepare SQLscript for creating table structure
+ $query = "SHOW CREATE TABLE $table";
+ $result = mysqli_query($mysqli, $query);
+ $row = mysqli_fetch_row($result);
+
+ $sqlScript .= "\n\n" . $row[1] . ";\n\n";
+
+
+ $query = "SELECT * FROM $table";
+ $result = mysqli_query($mysqli, $query);
+
+ $columnCount = mysqli_num_fields($result);
+
+ // Prepare SQLscript for dumping data for each table
+ for ($i = 0; $i < $columnCount; $i ++) {
+ while ($row = mysqli_fetch_row($result)) {
+ $sqlScript .= "INSERT INTO $table VALUES(";
+ for ($j = 0; $j < $columnCount; $j ++) {
+
+ if (isset($row[$j])) {
+ $sqlScript .= '"' . $row[$j] . '"';
+ } else {
+ $sqlScript .= '""';
+ }
+ if ($j < ($columnCount - 1)) {
+ $sqlScript .= ',';
+ }
+ }
+ $sqlScript .= ");\n";
+ }
+ }
+
+ $sqlScript .= "\n";
+ }
+
+ if (!empty($sqlScript))
+ {
+ // Save the SQL script to a backup file
+ $backup_file_name = date('Y-m-d') . '_' . $config_company_name . '_backup.sql';
+ $fileHandler = fopen($backup_file_name, 'w+');
+ $number_of_lines = fwrite($fileHandler, $sqlScript);
+ fclose($fileHandler);
+
+ // Download the SQL backup file to the browser
+ header('Content-Description: File Transfer');
+ header('Content-Type: application/octet-stream');
+ header('Content-Disposition: attachment; filename=' . basename($backup_file_name));
+ header('Content-Transfer-Encoding: binary');
+ header('Expires: 0');
+ header('Cache-Control: must-revalidate');
+ header('Pragma: public');
+ header('Content-Length: ' . filesize($backup_file_name));
+ ob_clean();
+ flush();
+ readfile($backup_file_name);
+ exec('rm ' . $backup_file_name);
+ }
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Database', log_action = 'Download', log_description = '$session_name downloaded the database', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Database downloaded";
+}
+
+if (isset($_POST['backup_master_key'])) {
+
+ validateCSRFToken($_POST['csrf_token']);
+ validateAdminRole();
+
+ $password = $_POST['password'];
+
+ $sql = mysqli_query($mysqli, "SELECT * FROM users WHERE user_id = $session_user_id");
+ $userRow = mysqli_fetch_array($sql);
+
+ if (password_verify($password, $userRow['user_password'])) {
+ $site_encryption_master_key = decryptUserSpecificKey($userRow['user_specific_encryption_ciphertext'], $password);
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Master Key', log_action = 'Download', log_description = '$session_name retrieved the master encryption key', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+ mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Settings', notification = '$session_name retrieved the master encryption key'");
+
+
+ echo "==============================";
+ echo "
Master encryption key:
";
+ echo "$site_encryption_master_key";
+ echo "
==============================";
+ } else {
+ //Log the failure
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Master Key', log_action = 'Download', log_description = '$session_name attempted to retrieve the master encryption key (failure)', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Incorrect password.";
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+ }
+}
+
+if (isset($_GET['update'])) {
+
+ validateAdminRole();
+
+ exec("git pull");
+
+ //FORCE UPDATE FUNCTION (Will be added later as a checkbox)
+ //git fetch downloads the latest from remote without trying to merge or rebase anything. Then the git reset resets the master branch to what you just fetched. The --hard option changes all the files in your working tree to match the files in origin/master
+
+ //exec("git fetch --all");
+ //exec("git reset --hard origin/master");
+
+ //header("Location: post.php?update_db");
+
+
+ // Send Telemetry if enabled during update
+ if ($config_telemetry == 1) {
+
+ $sql = mysqli_query($mysqli,"SELECT * FROM companies WHERE company_id = 1");
+ $row = mysqli_fetch_array($sql);
+
+ $company_name = sanitizeInput($row['company_name']);
+ $city = sanitizeInput($row['company_city']);
+ $state = sanitizeInput($row['company_state']);
+ $country = sanitizeInput($row['company_country']);
+ $currency = sanitizeInput($row['company_currency']);
+ $current_version = exec("git rev-parse HEAD");
+
+ // Client Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('client_id') AS num FROM clients"));
+ $client_count = $row['num'];
+
+ // Ticket Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('recurring_id') AS num FROM tickets"));
+ $ticket_count = $row['num'];
+
+ // Calendar Event Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('event_id') AS num FROM events"));
+ $calendar_event_count = $row['num'];
+
+ // Quote Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('quote_id') AS num FROM quotes"));
+ $quote_count = $row['num'];
+
+ // Invoice Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('invoice_id') AS num FROM invoices"));
+ $invoice_count = $row['num'];
+
+ // Revenue Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('revenue_id') AS num FROM revenues"));
+ $revenue_count = $row['num'];
+
+ // Recurring Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('recurring_id') AS num FROM recurring"));
+ $recurring_count = $row['num'];
+
+ // Account Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('account_id') AS num FROM accounts"));
+ $account_count = $row['num'];
+
+ // Tax Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('tax_id') AS num FROM taxes"));
+ $tax_count = $row['num'];
+
+ // Product Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('product_id') AS num FROM products"));
+ $product_count = $row['num'];
+
+ // Payment Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('payment_id') AS num FROM payments WHERE payment_invoice_id > 0"));
+ $payment_count = $row['num'];
+
+ // Company Vendor Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('vendor_id') AS num FROM vendors WHERE vendor_template = 0 AND vendor_client_id = 0"));
+ $company_vendor_count = $row['num'];
+
+ // Expense Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('expense_id') AS num FROM expenses WHERE expense_vendor_id > 0"));
+ $expense_count = $row['num'];
+
+ // Trip Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('trip_id') AS num FROM trips"));
+ $trip_count = $row['num'];
+
+ // Transfer Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('transfer_id') AS num FROM transfers"));
+ $transfer_count = $row['num'];
+
+ // Contact Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('contact_id') AS num FROM contacts"));
+ $contact_count = $row['num'];
+
+ // Location Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('location_id') AS num FROM locations"));
+ $location_count = $row['num'];
+
+ // Asset Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('asset_id') AS num FROM assets"));
+ $asset_count = $row['num'];
+
+ // Software Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('software_id') AS num FROM software WHERE software_template = 0"));
+ $software_count = $row['num'];
+
+ // Software Template Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('software_id') AS num FROM software WHERE software_template = 1"));
+ $software_template_count = $row['num'];
+
+ // Password Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('login_id') AS num FROM logins"));
+ $password_count = $row['num'];
+
+ // Network Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('network_id') AS num FROM networks"));
+ $network_count = $row['num'];
+
+ // Certificate Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('certificate_id') AS num FROM certificates"));
+ $certificate_count = $row['num'];
+
+ // Domain Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('domain_id') AS num FROM domains"));
+ $domain_count = $row['num'];
+
+ // Service Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('service_id') AS num FROM services"));
+ $service_count = $row['num'];
+
+ // Client Vendor Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('vendor_id') AS num FROM vendors WHERE vendor_template = 0 AND vendor_client_id > 0"));
+ $client_vendor_count = $row['num'];
+
+ // Vendor Template Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('vendor_id') AS num FROM vendors WHERE vendor_template = 1"));
+ $vendor_template_count = $row['num'];
+
+ // File Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('file_id') AS num FROM files"));
+ $file_count = $row['num'];
+
+ // Document Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('document_id') AS num FROM documents WHERE document_template = 0"));
+ $document_count = $row['num'];
+
+ // Document Template Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('document_id') AS num FROM documents WHERE document_template = 1"));
+ $document_template_count = $row['num'];
+
+ // Shared Item Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('item_id') AS num FROM shared_items"));
+ $shared_item_count = $row['num'];
+
+ // Company Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('company_id') AS num FROM companies"));
+ $company_count = $row['num'];
+
+ // User Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('user_id') AS num FROM users"));
+ $user_count = $row['num'];
+
+ // Category Expense Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Expense'"));
+ $category_expense_count = $row['num'];
+
+ // Category Income Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Income'"));
+ $category_income_count = $row['num'];
+
+ // Category Referral Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Referral'"));
+ $category_referral_count = $row['num'];
+
+ // Category Payment Method Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('category_id') AS num FROM categories WHERE category_type = 'Payment Method'"));
+ $category_payment_method_count = $row['num'];
+
+ // Tag Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('tag_id') AS num FROM tags"));
+ $tag_count = $row['num'];
+
+ // API Key Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('api_key_id') AS num FROM api_keys"));
+ $api_key_count = $row['num'];
+
+ // Log Count
+ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT COUNT('log_id') AS num FROM logs"));
+ $log_count = $row['num'];
+
+ $postdata = http_build_query(
+ array(
+ 'installation_id' => "$installation_id",
+ 'version' => "$current_version",
+ 'company_name' => "$company_name",
+ 'city' => "$city",
+ 'state' => "$state",
+ 'country' => "$country",
+ 'currency' => "$currency",
+ 'comments' => "$comments",
+ 'client_count' => $client_count,
+ 'ticket_count' => $ticket_count,
+ 'calendar_event_count' => $calendar_event_count,
+ 'quote_count' => $quote_count,
+ 'invoice_count' => $invoice_count,
+ 'revenue_count' => $revenue_count,
+ 'recurring_count' => $recurring_count,
+ 'account_count' => $account_count,
+ 'tax_count' => $tax_count,
+ 'product_count' => $product_count,
+ 'payment_count' => $payment_count,
+ 'company_vendor_count' => $company_vendor_count,
+ 'expense_count' => $expense_count,
+ 'trip_count' => $trip_count,
+ 'transfer_count' => $transfer_count,
+ 'contact_count' => $contact_count,
+ 'location_count' => $location_count,
+ 'asset_count' => $asset_count,
+ 'software_count' => $software_count,
+ 'software_template_count' => $software_template_count,
+ 'password_count' => $password_count,
+ 'network_count' => $network_count,
+ 'certificate_count' => $certificate_count,
+ 'domain_count' => $domain_count,
+ 'service_count' => $service_count,
+ 'client_vendor_count' => $client_vendor_count,
+ 'vendor_template_count' => $vendor_template_count,
+ 'file_count' => $file_count,
+ 'document_count' => $document_count,
+ 'document_template_count' => $document_template_count,
+ 'shared_item_count' => $shared_item_count,
+ 'company_count' => $company_count,
+ 'user_count' => $user_count,
+ 'category_expense_count' => $category_expense_count,
+ 'category_income_count' => $category_income_count,
+ 'category_referral_count' => $category_referral_count,
+ 'category_payment_method_count' => $category_payment_method_count,
+ 'tag_count' => $tag_count,
+ 'api_key_count' => $api_key_count,
+ 'log_count' => $log_count,
+ 'config_theme' => "$config_theme",
+ 'config_enable_cron' => $config_enable_cron,
+ 'config_ticket_email_parse' => $config_ticket_email_parse,
+ 'config_module_enable_itdoc' => $config_module_enable_itdoc,
+ 'config_module_enable_ticketing' => $config_module_enable_ticketing,
+ 'config_module_enable_accounting' => $config_module_enable_accounting,
+ 'config_telemetry' => $config_telemetry,
+ 'collection_method' => 4
+ )
+ );
+
+ $opts = array('http' =>
+ array(
+ 'method' => 'POST',
+ 'header' => 'Content-type: application/x-www-form-urlencoded',
+ 'content' => $postdata
+ )
+ );
+
+ $context = stream_context_create($opts);
+
+ $result = file_get_contents('https://telemetry.itflow.org', false, $context);
+
+ }
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Update', log_description = '$session_name ran updates', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Update successful";
+
+ sleep(1);
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['update_db'])) {
+
+ validateAdminRole();
+
+ // Get the current version
+ require_once ('database_version.php');
+
+ // Perform upgrades, if required
+ require_once ('database_updates.php');
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Settings', log_action = 'Update', log_description = '$session_name updated the database structure', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Database structure update successful";
+
+ sleep(1);
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
diff --git a/models/company.php b/post/setting_company_model.php
similarity index 100%
rename from models/company.php
rename to post/setting_company_model.php
diff --git a/post/software.php b/post/software.php
new file mode 100644
index 00000000..07502704
--- /dev/null
+++ b/post/software.php
@@ -0,0 +1,349 @@
+$name created $alert_extended";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_software'])) {
+
+ validateTechRole();
+
+ $software_id = intval($_POST['software_id']);
+ $login_id = intval($_POST['login_id']);
+ $client_id = intval($_POST['client_id']);
+ $name = sanitizeInput($_POST['name']);
+ $version = sanitizeInput($_POST['version']);
+ $type = sanitizeInput($_POST['type']);
+ $license_type = sanitizeInput($_POST['license_type']);
+ $notes = sanitizeInput($_POST['notes']);
+ $key = sanitizeInput($_POST['key']);
+ $seats = intval($_POST['seats']);
+ $purchase = sanitizeInput($_POST['purchase']);
+ if (empty($purchase)) {
+ $purchase = "NULL";
+ } else {
+ $purchase = "'" . $purchase . "'";
+ }
+ $expire = sanitizeInput($_POST['expire']);
+ if (empty($expire)) {
+ $expire = "NULL";
+ } else {
+ $expire = "'" . $expire . "'";
+ }
+ $notes = sanitizeInput($_POST['notes']);
+ $username = trim(mysqli_real_escape_string($mysqli, encryptLoginEntry($_POST['username'])));
+ $password = trim(mysqli_real_escape_string($mysqli, encryptLoginEntry($_POST['password'])));
+
+ mysqli_query($mysqli,"UPDATE software SET software_name = '$name', software_version = '$version', software_type = '$type', software_key = '$key', software_license_type = '$license_type', software_seats = $seats, software_purchase = $purchase, software_expire = $expire, software_notes = '$notes' WHERE software_id = $software_id");
+
+
+ // Update Asset Licenses
+ mysqli_query($mysqli,"DELETE FROM software_assets WHERE software_id = $software_id");
+ if (!empty($_POST['assets'])) {
+ foreach($_POST['assets'] as $asset) {
+ $asset = intval($asset);
+ mysqli_query($mysqli,"INSERT INTO software_assets SET software_id = $software_id, asset_id = $asset");
+ }
+ }
+
+ // Update Contact Licenses
+ mysqli_query($mysqli,"DELETE FROM software_contacts WHERE software_id = $software_id");
+ if (!empty($_POST['contacts'])) {
+ foreach($_POST['contacts'] as $contact) {
+ $contact = intval($contact);
+ mysqli_query($mysqli,"INSERT INTO software_contacts SET software_id = $software_id, contact_id = $contact");
+ }
+ }
+
+ //If login exists then update the login
+ if ($login_id > 0) {
+ mysqli_query($mysqli,"UPDATE logins SET login_name = '$name', login_username = '$username', login_password = '$password' WHERE login_id = $login_id");
+ }else{
+ //If Username is filled in then add a login
+ if (!empty($username)) {
+
+ mysqli_query($mysqli,"INSERT INTO logins SET login_name = '$name', login_username = '$username', login_password = '$password', login_software_id = $software_id, login_client_id = $client_id");
+
+ }
+ }
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Software', log_action = 'Modify', log_description = '$session_name modified software $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $software_id");
+
+ $_SESSION['alert_message'] = "Software $name updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['archive_software'])) {
+
+ validateTechRole();
+
+ $software_id = intval($_GET['archive_software']);
+
+ // Get Software Name and Client ID for logging and alert message
+ $sql = mysqli_query($mysqli,"SELECT software_name, software_client_id FROM software WHERE software_id = $software_id");
+ $row = mysqli_fetch_array($sql);
+ $software_name = sanitizeInput($row['software_name']);
+ $client_id = intval($row['software_client_id']);
+
+ mysqli_query($mysqli,"UPDATE software SET software_archived_at = NOW() WHERE software_id = $software_id");
+
+ // Remove Software Relations
+ mysqli_query($mysqli,"DELETE FROM software_contacts WHERE software_id = $software_id");
+ mysqli_query($mysqli,"DELETE FROM software_assets WHERE software_id = $software_id");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Software', log_action = 'Archive', log_description = '$session_name archived software $software_name and removed all device/user license associations', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $software_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Software $software_name archived and removed all device/user license associations";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['delete_software'])) {
+
+ validateAdminRole();
+
+ $software_id = intval($_GET['delete_software']);
+
+ // Get Software Name and Client ID for logging and alert message
+ $sql = mysqli_query($mysqli,"SELECT software_name, software_client_id FROM software WHERE software_id = $software_id");
+ $row = mysqli_fetch_array($sql);
+ $software_name = sanitizeInput($row['software_name']);
+ $client_id = intval($row['software_client_id']);
+
+ mysqli_query($mysqli,"DELETE FROM software WHERE software_id = $software_id");
+
+ // Remove Software Relations
+ mysqli_query($mysqli,"DELETE FROM software_contacts WHERE software_id = $software_id");
+ mysqli_query($mysqli,"DELETE FROM software_assets WHERE software_id = $software_id");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Software', log_action = 'Delete', log_description = '$session_name deleted software $software_name and removed all device/user license associations', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $software_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Software $software_name deleted and removed all device/user license associations";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['export_client_software_csv'])) {
+
+ validateTechRole();
+
+ $client_id = intval($_POST['client_id']);
+
+ //get records from database
+ $sql = mysqli_query($mysqli,"SELECT * FROM clients WHERE client_id = $client_id");
+ $row = mysqli_fetch_array($sql);
+
+ $client_name = $row['client_name'];
+
+ $sql = mysqli_query($mysqli,"SELECT * FROM software WHERE software_client_id = $client_id ORDER BY software_name ASC");
+
+ $num_rows = mysqli_num_rows($sql);
+
+ if ($num_rows > 0) {
+ $delimiter = ",";
+ $filename = $client_name . "-Software-" . date('Y-m-d') . ".csv";
+
+ //create a file pointer
+ $f = fopen('php://memory', 'w');
+
+ //set column headers
+ $fields = array('Name', 'Version', 'Type', 'License Type', 'Seats', 'Key', 'Assets', 'Contacts', 'Purchased', 'Expires', 'Notes');
+ fputcsv($f, $fields, $delimiter);
+
+ //output each row of the data, format line as csv and write to file pointer
+ while($row = $sql->fetch_assoc()) {
+
+ // Generate asset & user license list for this software
+
+ // Asset licenses
+ $assigned_to_assets = '';
+ $asset_licenses_sql = mysqli_query($mysqli,"SELECT software_assets.asset_id, assets.asset_name
+ FROM software_assets
+ LEFT JOIN assets
+ ON software_assets.asset_id = assets.asset_id
+ WHERE software_id = $row[software_id]");
+ while($asset_row = mysqli_fetch_array($asset_licenses_sql)) {
+ $assigned_to_assets .= $asset_row['asset_name'] . ", ";
+ }
+
+ // Contact Licenses
+ $assigned_to_contacts = '';
+ $contact_licenses_sql = mysqli_query($mysqli,"SELECT software_contacts.contact_id, contacts.contact_name
+ FROM software_contacts
+ LEFT JOIN contacts
+ ON software_contacts.contact_id = contacts.contact_id
+ WHERE software_id = $row[software_id]");
+ while($contact_row = mysqli_fetch_array($contact_licenses_sql)) {
+ $assigned_to_contacts .= $contact_row['contact_name'] . ", ";
+ }
+
+ $lineData = array($row['software_name'], $row['software_version'], $row['software_type'], $row['software_license_type'], $row['software_seats'], $row['software_key'], $assigned_to_assets, $assigned_to_contacts, $row['software_purchase'], $row['software_expire'], $row['software_notes']);
+ fputcsv($f, $lineData, $delimiter);
+ }
+
+ //move back to beginning of file
+ fseek($f, 0);
+
+ //set headers to download file rather than displayed
+ header('Content-Type: text/csv');
+ header('Content-Disposition: attachment; filename="' . $filename . '";');
+
+ //output all remaining data on a file pointer
+ fpassthru($f);
+ }
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Software', log_action = 'Export', log_description = '$session_name exported $num_rows software license(s) to a CSV file', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id");
+
+ exit;
+
+}
+
diff --git a/post/tag.php b/post/tag.php
new file mode 100644
index 00000000..d543e6d2
--- /dev/null
+++ b/post/tag.php
@@ -0,0 +1,53 @@
+ 0 && $contact == 0) {
+ $sql = mysqli_query($mysqli,"SELECT primary_contact FROM clients WHERE client_id = $client_id");
+ $row = mysqli_fetch_array($sql);
+ $contact = intval($row['primary_contact']);
+ }
+
+ //Get the next Ticket Number and add 1 for the new ticket number
+ $ticket_number = $config_ticket_next_number;
+ $new_config_ticket_next_number = $config_ticket_next_number + 1;
+ mysqli_query($mysqli,"UPDATE settings SET config_ticket_next_number = $new_config_ticket_next_number WHERE company_id = 1");
+
+ mysqli_query($mysqli,"INSERT INTO tickets SET ticket_prefix = '$config_ticket_prefix', ticket_number = $ticket_number, ticket_subject = '$subject', ticket_details = '$details', ticket_priority = '$priority', ticket_status = 'Open', ticket_vendor_ticket_number = '$vendor_ticket_number', ticket_vendor_id = $vendor_id, ticket_asset_id = $asset_id, ticket_created_by = $session_user_id, ticket_assigned_to = $assigned_to, ticket_contact_id = $contact, ticket_client_id = $client_id");
+
+ $ticket_id = mysqli_insert_id($mysqli);
+
+ // E-mail client
+ if (!empty($config_smtp_host) && $config_ticket_client_general_notifications == 1) {
+
+ // Get contact/ticket details
+ $sql = mysqli_query($mysqli,"SELECT contact_name, contact_email, ticket_prefix, ticket_number, ticket_subject FROM tickets
+ LEFT JOIN clients ON ticket_client_id = client_id
+ LEFT JOIN contacts ON ticket_contact_id = contact_id
+ WHERE ticket_id = $ticket_id");
+ $row = mysqli_fetch_array($sql);
+
+ $contact_name = $row['contact_name'];
+ $contact_email = $row['contact_email'];
+ $ticket_prefix = $row['ticket_prefix'];
+ $ticket_number = intval($row['ticket_number']);
+ $ticket_subject = $row['ticket_subject'];
+
+ $sql = mysqli_query($mysqli,"SELECT company_phone FROM companies WHERE company_id = 1");
+
+ $company_phone = formatPhoneNumber($row['company_phone']);
+
+ // Verify contact email is valid
+ if (filter_var($contact_email, FILTER_VALIDATE_EMAIL)) {
+
+ $subject = "Ticket created - [$ticket_prefix$ticket_number] - $ticket_subject";
+ $body = "##- Please type your reply above this line -##
Hello, $contact_name
A ticket regarding \"$ticket_subject\" has been created for you.
--------------------------------
$details--------------------------------
Ticket: $ticket_prefix$ticket_number
Subject: $ticket_subject
Status: Open
Portal: https://$config_base_url/portal/ticket.php?id=$id
~
$session_company_name
Support Department
$config_ticket_from_email
$company_phone";
+
+ $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port,
+ $config_ticket_from_email, $config_ticket_from_name,
+ $contact_email, $contact_name,
+ $subject, $body);
+
+ if ($mail !== true) {
+ mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email rearding ticket $config_ticket_prefix$ticket_number - $ticket_subject', notification_client_id = $client_id, notification_user_id = $session_user_id");
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject relating to ticket $config_ticket_prefix$ticket_number. $mail', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_id");
+ }
+
+ }
+ }
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Create', log_description = '$session_name created ticket $config_ticket_prefix$ticket_number - $subject', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_number");
+
+ $_SESSION['alert_message'] = "Ticket $config_ticket_prefix$ticket_number created";
+
+ header("Location: ticket.php?ticket_id=" . $ticket_id);
+
+}
+
+if (isset($_POST['edit_ticket'])) {
+
+ validateTechRole();
+
+ $ticket_id = intval($_POST['ticket_id']);
+ $assigned_to = intval($_POST['assigned_to']);
+ $contact_id = intval($_POST['contact']);
+ $subject = sanitizeInput($_POST['subject']);
+ $priority = sanitizeInput($_POST['priority']);
+ $details = mysqli_real_escape_string($mysqli,$_POST['details']);
+ $vendor_ticket_number = sanitizeInput($_POST['vendor_ticket_number']);
+ $vendor_id = intval($_POST['vendor']);
+ $asset_id = intval($_POST['asset']);
+ $client_id = intval($_POST['client_id']);
+ $ticket_number = intval($_POST['ticket_number']);
+
+ mysqli_query($mysqli,"UPDATE tickets SET ticket_subject = '$subject', ticket_priority = '$priority', ticket_details = '$details', ticket_vendor_ticket_number = '$vendor_ticket_number', ticket_assigned_to = $assigned_to, ticket_contact_id = $contact_id, ticket_vendor_id = $vendor_id, ticket_asset_id = $asset_id WHERE ticket_id = $ticket_id");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Modify', log_description = '$session_name modified ticket $ticket_number - $subject', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_id");
+
+ $_SESSION['alert_message'] = "Ticket $ticket_number updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['assign_ticket'])) {
+
+ // Role check
+ validateTechRole();
+
+ // POST variables
+ $ticket_id = intval($_POST['ticket_id']);
+ $assigned_to = intval($_POST['assigned_to']);
+
+ // Allow for un-assigning tickets
+ if ($assigned_to == 0) {
+ $ticket_reply = "Ticket unassigned.";
+ $agent_name = "No One";
+
+ } else {
+ // Get & verify assigned agent details
+ $agent_details_sql = mysqli_query($mysqli, "SELECT user_name, user_email FROM users LEFT JOIN user_settings ON users.user_id = user_settings.user_id WHERE users.user_id = $assigned_to AND user_settings.user_role > 1");
+ $agent_details = mysqli_fetch_array($agent_details_sql);
+ $agent_name = sanitizeInput($agent_details['user_name']);
+ $agent_email = sanitizeInput($agent_details['user_email']);
+ $ticket_reply = "Ticket re-assigned to $agent_name.";
+
+ if (!$agent_name) {
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Invalid agent!";
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+ exit();
+ }
+ }
+
+ // Get & verify ticket details
+ $ticket_details_sql = mysqli_query($mysqli, "SELECT ticket_prefix, ticket_number, ticket_subject, ticket_client_id FROM tickets WHERE ticket_id = '$ticket_id' AND ticket_status != 'Closed'");
+ $ticket_details = mysqli_fetch_array($ticket_details_sql);
+ $ticket_prefix = sanitizeInput($ticket_details['ticket_prefix']);
+ $ticket_number = intval($ticket_details['ticket_number']);
+ $ticket_subject = sanitizeInput($ticket_details['ticket_subject']);
+ $client_id = intval($ticket_details['ticket_client_id']);
+
+ if (!$ticket_subject) {
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Invalid ticket!";
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+ exit();
+ }
+
+ // Update ticket & insert reply
+ mysqli_query($mysqli,"UPDATE tickets SET ticket_assigned_to = $assigned_to WHERE ticket_id = $ticket_id");
+
+ mysqli_query($mysqli,"INSERT INTO ticket_replies SET ticket_reply = '$ticket_reply', ticket_reply_type = 'Internal', ticket_reply_time_worked = '00:01:00', ticket_reply_by = $session_user_id, ticket_reply_ticket_id = $ticket_id") or die(mysqli_error($mysqli));
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Modify', log_description = '$session_name reassigned ticket $ticket_prefix$ticket_number - $ticket_subject to $agent_name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_id");
+
+ // Email notification
+ if (intval($session_user_id) !== $assigned_to || $assigned_to !== 0) {
+
+ mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Ticket', notification = 'Ticket $ticket_prefix$ticket_number - Subject: $ticket_subject has been assigned to you by $session_name', notification_client_id = $client_id, notification_user_id = $assigned_to");
+
+ $subject = "$config_app_name ticket $ticket_prefix$ticket_number assigned to you";
+ $body = "Hi $agent_name,
A ticket has been assigned to you!
Ticket Number: $ticket_prefix$ticket_number
Subject: $ticket_subject
Thanks,
$session_name
$session_company_name";
+
+ $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port,
+ $config_ticket_from_email, $config_ticket_from_name,
+ $agent_email, $agent_name,
+ $subject, $body);
+ }
+
+ $_SESSION['alert_message'] = "Ticket $ticket_prefix$ticket_number assigned to $agent_name";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['delete_ticket'])) {
+
+ validateAdminRole();
+
+ $ticket_id = intval($_GET['delete_ticket']);
+
+ // Get Ticket and Client ID for logging and alert message
+ $sql = mysqli_query($mysqli,"SELECT ticket_prefix, ticket_number, ticket_subject, ticket_status, ticket_client_id FROM tickets WHERE ticket_id = $ticket_id");
+ $row = mysqli_fetch_array($sql);
+ $ticket_prefix = sanitizeInput($row['ticket_prefix']);
+ $ticket_number = sanitizeInput($row['ticket_number']);
+ $ticket_subject = sanitizeInput($row['ticket_subject']);
+ $ticket_status = sanitizeInput($row['ticket_status']);
+ $client_id = intval($row['ticket_client_id']);
+
+ if ($ticket_status !== 'Closed') {
+ mysqli_query($mysqli,"DELETE FROM tickets WHERE ticket_id = $ticket_id");
+
+ // Delete all ticket replies
+ mysqli_query($mysqli,"DELETE FROM ticket_replies WHERE ticket_reply_ticket_id = $ticket_id");
+
+ // Delete all ticket views
+ mysqli_query($mysqli,"DELETE FROM ticket_views WHERE view_ticket_id = $ticket_id");
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Delete', log_description = '$session_name deleted ticket $ticket_prefix$ticket_number - $ticket_subject along with all replies', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Ticket $ticket_prefix$ticket_number along with all replies deleted";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+ }
+
+}
+
+if (isset($_POST['add_ticket_reply'])) {
+
+ validateTechRole();
+
+ $ticket_id = intval($_POST['ticket_id']);
+ $ticket_reply = mysqli_real_escape_string($mysqli,$_POST['ticket_reply']);
+ $ticket_status = sanitizeInput($_POST['status']);
+ $ticket_reply_time_worked = sanitizeInput($_POST['time']);
+
+ $client_id = intval($_POST['client_id']);
+
+ if (isset($_POST['public_reply_type'])) {
+ $ticket_reply_type = 'Public';
+ } else {
+ $ticket_reply_type = 'Internal';
+ }
+
+ // Add reply
+ mysqli_query($mysqli,"INSERT INTO ticket_replies SET ticket_reply = '$ticket_reply', ticket_reply_time_worked = '$ticket_reply_time_worked', ticket_reply_type = '$ticket_reply_type', ticket_reply_by = $session_user_id, ticket_reply_ticket_id = $ticket_id") or die(mysqli_error($mysqli));
+
+ $ticket_reply_id = mysqli_insert_id($mysqli);
+
+ // Update Ticket Last Response Field
+ mysqli_query($mysqli,"UPDATE tickets SET ticket_status = '$ticket_status' WHERE ticket_id = $ticket_id") or die(mysqli_error($mysqli));
+
+ if ($ticket_status == 'Closed') {
+ mysqli_query($mysqli,"UPDATE tickets SET ticket_closed_at = NOW() WHERE ticket_id = $ticket_id");
+ }
+
+ // Get Ticket Details
+ $ticket_sql = mysqli_query($mysqli,"SELECT contact_name, contact_email, ticket_prefix, ticket_number, ticket_subject, ticket_client_id, ticket_created_by, ticket_assigned_to FROM tickets
+ LEFT JOIN clients ON ticket_client_id = client_id
+ LEFT JOIN contacts ON ticket_contact_id = contact_id
+ WHERE ticket_id = $ticket_id
+ ");
+
+ $row = mysqli_fetch_array($ticket_sql);
+
+ $contact_name = sanitizeInput($row['contact_name']);
+ $contact_email = sanitizeInput($row['contact_email']);
+ $ticket_prefix = sanitizeInput($row['ticket_prefix']);
+ $ticket_number = intval($row['ticket_number']);
+ $ticket_subject = sanitizeInput($row['ticket_subject']);
+ $client_id = intval($row['ticket_client_id']);
+ $ticket_created_by = intval($row['ticket_created_by']);
+ $ticket_assigned_to = intval($row['ticket_assigned_to']);
+
+
+ $company_sql = mysqli_query($mysqli,"SELECT company_phone FROM companies WHERE company_id = 1");
+ $row = mysqli_fetch_array($company_sql);
+ $company_phone = formatPhoneNumber($row['company_phone']);
+
+ // Send e-mail to client if public update & email is set up
+ if ($ticket_reply_type == 'Public' && !empty($config_smtp_host)) {
+
+ if (filter_var($contact_email, FILTER_VALIDATE_EMAIL)) {
+
+ $ticket_reply = preg_replace('/]*>/', '', $ticket_reply); // Remove the start
or
+ $ticket_reply = preg_replace('/
/', '
', $ticket_reply); // Replace the end
+
+ // Slightly different email subject/text depending on if this update closed the ticket or not
+
+ if ($ticket_status == 'Closed') {
+ $subject = "Ticket closed - [$ticket_prefix$ticket_number] - $ticket_subject | (do not reply)";
+ $body = "Hello, $contact_name
Your ticket regarding \"$ticket_subject\" has been closed.
--------------------------------
$ticket_reply--------------------------------
We hope the issue was resolved to your satisfaction. If you need further assistance, please raise a new ticket using the below details. Please do not reply to this email.
Ticket: $ticket_prefix$ticket_number
Subject: $ticket_subject
Portal: https://$config_base_url/portal/ticket.php?id=$ticket_id
~
$session_company_name
Support Department
$config_ticket_from_email
$company_phone";
+
+ } elseif ($ticket_status == 'Auto Close') {
+ $subject = "Ticket update - [$ticket_prefix$ticket_number] - $ticket_subject | (pending closure)";
+ $body = "##- Please type your reply above this line -##
Hello, $contact_name
Your ticket regarding \"$ticket_subject\" has been updated and is pending closure.
--------------------------------
$ticket_reply--------------------------------
If your issue is resolved, you can ignore this email. If you need further assistance, please respond!
Ticket: $ticket_prefix$ticket_number
Subject: $ticket_subject
Status: $ticket_status
Portal: https://$config_base_url/portal/ticket.php?id=$ticket_id
~
$session_company_name
Support Department
$config_ticket_from_email
$company_phone";
+
+ } else {
+ $subject = "Ticket update - [$ticket_prefix$ticket_number] - $ticket_subject";
+ $body = "##- Please type your reply above this line -##
Hello, $contact_name
Your ticket regarding \"$ticket_subject\" has been updated.
--------------------------------
$ticket_reply--------------------------------
Ticket: $ticket_prefix$ticket_number
Subject: $ticket_subject
Status: $ticket_status
Portal: https://$config_base_url/portal/ticket.php?id=$ticket_id
~
$session_company_name
Support Department
$config_ticket_from_email
$company_phone";
+
+ }
+
+ $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port,
+ $config_ticket_from_email, $config_ticket_from_name,
+ $contact_email, $contact_name,
+ $subject, $body);
+
+ if ($mail !== true) {
+ mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email'");
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject. $mail', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+ }
+ }
+ }
+ //End Mail IF
+
+ // Notification for assigned ticket user
+ if (intval($session_user_id) !== $ticket_assigned_to || $ticket_assigned_to !== 0) {
+
+ mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Ticket', notification = '$session_name updated Ticket $ticket_prefix$ticket_number - Subject: $ticket_subject that is assigned to you', notification_client_id = $client_id, notification_user_id = $ticket_assigned_to");
+ }
+
+ // Notification for user that opened the ticket
+ if (intval($session_user_id) !== $ticket_created_by || $ticket_created_by !== 0) {
+
+ mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Ticket', notification = '$session_name updated Ticket $ticket_prefix$ticket_number - Subject: $ticket_subject that you opened', notification_client_id = $client_id, notification_user_id = $ticket_created_by");
+ }
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket Reply', log_action = 'Create', log_description = '$session_name replied to ticket $ticket_prefix$ticket_number - $ticket_subject and was a $ticket_reply_type reply', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_reply_id");
+
+ $_SESSION['alert_message'] = "Ticket $ticket_prefix$ticket_number has been updated with your reply and was $ticket_reply_type";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_ticket_reply'])) {
+
+ validateTechRole();
+
+ $ticket_reply_id = intval($_POST['ticket_reply_id']);
+ $ticket_reply = mysqli_real_escape_string($mysqli,$_POST['ticket_reply']);
+ $ticket_reply_time_worked = sanitizeInput($_POST['time']);
+
+ $client_id = intval($_POST['client_id']);
+
+ mysqli_query($mysqli,"UPDATE ticket_replies SET ticket_reply = '$ticket_reply', ticket_reply_time_worked = '$ticket_reply_time_worked' WHERE ticket_reply_id = $ticket_reply_id AND ticket_reply_type != 'Client'") or die(mysqli_error($mysqli));
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket Reply', log_action = 'Modify', log_description = '$session_name modified ticket reply', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_reply_id");
+
+ $_SESSION['alert_message'] = "Ticket reply updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['archive_ticket_reply'])) {
+
+ validateAdminRole();
+
+ $ticket_reply_id = intval($_GET['archive_ticket_reply']);
+
+ mysqli_query($mysqli,"UPDATE ticket_replies SET ticket_reply_archived_at = NOW() WHERE ticket_reply_id = $ticket_reply_id");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket Reply', log_action = 'Archive', log_description = '$session_name arhived ticket reply', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_reply_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Ticket reply archived";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['merge_ticket'])) {
+
+ validateTechRole();
+
+ $ticket_id = intval($_POST['ticket_id']);
+ $merge_into_ticket_number = intval($_POST['merge_into_ticket_number']);
+ $merge_comment = sanitizeInput($_POST['merge_comment']);
+ $ticket_reply_type = 'Internal';
+
+ //Get current ticket details
+ $sql = mysqli_query($mysqli, "SELECT ticket_prefix, ticket_number, ticket_subject, ticket_details FROM tickets WHERE ticket_id = $ticket_id");
+ if (mysqli_num_rows($sql) == 0) {
+ $_SESSION['alert_message'] = "No ticket with that ID found.";
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+ exit();
+ }
+ $row = mysqli_fetch_array($sql);
+ $ticket_prefix = sanitizeInput($row['ticket_prefix']);
+ $ticket_number = intval($row['ticket_number']);
+ $ticket_subject = sanitizeInput($row['ticket_subject']);
+ $ticket_details = sanitizeInput($row['ticket_details']);
+
+ //Get merge into ticket id (as it may differ from the number)
+ $sql = mysqli_query($mysqli, "SELECT ticket_id FROM tickets WHERE ticket_number = $merge_into_ticket_number");
+ if (mysqli_num_rows($sql) == 0) {
+ $_SESSION['alert_message'] = "Cannot merge into that ticket.";
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+ exit();
+ }
+ $merge_row = mysqli_fetch_array($sql);
+ $merge_into_ticket_id = intval($merge_row['ticket_id']);
+
+ if ($ticket_number == $merge_into_ticket_number) {
+ $_SESSION['alert_message'] = "Cannot merge into the same ticket.";
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+ exit();
+ }
+
+ //Update current ticket
+ mysqli_query($mysqli,"INSERT INTO ticket_replies SET ticket_reply = 'Ticket $ticket_prefix$ticket_number merged into $ticket_prefix$merge_into_ticket_number. Comment: $merge_comment', ticket_reply_time_worked = '00:01:00', ticket_reply_type = '$ticket_reply_type', ticket_reply_by = $session_user_id, ticket_reply_ticket_id = $ticket_id") or die(mysqli_error($mysqli));
+ mysqli_query($mysqli,"UPDATE tickets SET ticket_status = 'Closed', ticket_closed_at = NOW() WHERE ticket_id = $ticket_id") or die(mysqli_error($mysqli));
+
+ //Update new ticket
+ mysqli_query($mysqli,"INSERT INTO ticket_replies SET ticket_reply = 'Ticket $ticket_prefix$ticket_number was merged into this ticket with comment: $merge_comment.
$ticket_subject
$ticket_details', ticket_reply_time_worked = '00:01:00', ticket_reply_type = '$ticket_reply_type', ticket_reply_by = $session_user_id, ticket_reply_ticket_id = $merge_into_ticket_id") or die(mysqli_error($mysqli));
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Merged', log_description = 'Merged ticket $ticket_prefix$ticket_number into $ticket_prefix$merge_into_ticket_number', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Ticket merged into $ticket_prefix$merge_into_ticket_number";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['change_client_ticket'])) {
+
+ validateTechRole();
+
+ $ticket_id = intval($_POST['ticket_id']);
+ $client_id = intval($_POST['new_client_id']);
+ $contact_id = intval($_POST['new_contact_id']);
+
+ // Set any/all existing replies to internal
+ mysqli_query($mysqli, "UPDATE ticket_replies SET ticket_reply_type = 'Internal' WHERE ticket_reply_ticket_id = $ticket_id");
+
+ // Update ticket client & contact
+ mysqli_query($mysqli, "UPDATE tickets SET ticket_client_id = $client_id, ticket_contact_id = $contact_id WHERE ticket_id = $ticket_id LIMIT 1");
+
+ //Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Ticket Reply', log_action = 'Modify', log_description = '$session_name modified ticket - client changed', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $ticket_id");
+
+ $_SESSION['alert_message'] = "Ticket client updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['close_ticket'])) {
+
+ validateTechRole();
+
+ $ticket_id = intval($_GET['close_ticket']);
+
+ mysqli_query($mysqli,"UPDATE tickets SET ticket_status = 'Closed', ticket_closed_at = NOW(), ticket_closed_by = $session_user_id WHERE ticket_id = $ticket_id") or die(mysqli_error($mysqli));
+
+ mysqli_query($mysqli,"INSERT INTO ticket_replies SET ticket_reply = 'Ticket closed.', ticket_reply_type = 'Internal', ticket_reply_time_worked = '00:01:00', ticket_reply_by = $session_user_id, ticket_reply_ticket_id = $ticket_id") or die(mysqli_error($mysqli));
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Closed', log_description = '$ticket_id Closed', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ // Client notification email
+ if (!empty($config_smtp_host) && $config_ticket_client_general_notifications == 1) {
+
+ // Get details
+ $ticket_sql = mysqli_query($mysqli,"SELECT contact_name, contact_email, ticket_prefix, ticket_number, ticket_subject FROM tickets
+ LEFT JOIN clients ON ticket_client_id = client_id
+ LEFT JOIN contacts ON ticket_contact_id = contact_id
+ WHERE ticket_id = $ticket_id
+ ");
+ $row = mysqli_fetch_array($ticket_sql);
+
+ $contact_name = sanitizeInput($row['contact_name']);
+ $contact_email = sanitizeInput($row['contact_email']);
+ $ticket_prefix = sanitizeInput($row['ticket_prefix']);
+ $ticket_number = intval($row['ticket_number']);
+ $ticket_subject = sanitizeInput($row['ticket_subject']);
+
+ $company_sql = mysqli_query($mysqli,"SELECT company_phone FROM companies WHERE company_id = 1");
+ $row = mysqli_fetch_array($company_sql);
+ $company_phone = formatPhoneNumber($row['company_phone']);
+
+ // Check email valid
+ if (filter_var($contact_email, FILTER_VALIDATE_EMAIL)) {
+
+ $subject = "Ticket closed - [$ticket_prefix$ticket_number] - $ticket_subject | (do not reply)";
+ $body = "Hello, $contact_name
Your ticket regarding \"$ticket_subject\" has been closed.
We hope the issue was resolved to your satisfaction. If you need further assistance, please raise a new ticket using the below details. Please do not reply to this email.
Ticket: $ticket_prefix$ticket_number
Subject: $ticket_subject
Portal: https://$config_base_url/portal/ticket.php?id=$ticket_id
~
$session_company_name
Support Department
$config_ticket_from_email
$company_phone";
+
+ $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port,
+ $config_ticket_from_email, $config_ticket_from_name,
+ $contact_email, $contact_name,
+ $subject, $body);
+
+ if ($mail !== true) {
+ mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email'");
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject. $mail', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+ }
+
+ }
+
+ }
+ //End Mail IF
+
+ $_SESSION['alert_message'] = "Ticket Closed, this cannot not be reopened but you may start another one";
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['add_invoice_from_ticket'])) {
+
+ $invoice_id = intval($_POST['invoice_id']);
+ $ticket_id = intval($_POST['ticket_id']);
+ $date = sanitizeInput($_POST['date']);
+ $category = intval($_POST['category']);
+ $scope = sanitizeInput($_POST['scope']);
+
+ $sql = mysqli_query($mysqli, "SELECT * FROM tickets
+ LEFT JOIN clients ON ticket_client_id = client_id
+ LEFT JOIN contacts ON ticket_contact_id = contact_id
+ LEFT JOIN assets ON ticket_asset_id = asset_id
+ LEFT JOIN locations ON ticket_location_id = location_id
+ WHERE ticket_id = $ticket_id"
+ );
+
+ $row = mysqli_fetch_array($sql);
+ $client_id = intval($row['client_id']);
+ $client_net_terms = intval($row['client_net_terms']);
+ if ($client_net_terms == 0) {
+ $client_net_terms = $config_default_net_terms;
+ }
+
+ $ticket_prefix = sanitizeInput($row['ticket_prefix']);
+ $ticket_number = intval($row['ticket_number']);
+ $ticket_category = sanitizeInput($row['ticket_category']);
+ $ticket_subject = sanitizeInput($row['ticket_subject']);
+ $ticket_created_at = sanitizeInput($row['ticket_created_at']);
+ $ticket_updated_at = sanitizeInput($row['ticket_updated_at']);
+ $ticket_closed_at = sanitizeInput($row['ticket_closed_at']);
+
+ $contact_id = intval($row['contact_id']);
+ $contact_name = sanitizeInput($row['contact_name']);
+ $contact_email = sanitizeInput($row['contact_email']);
+
+ $asset_id = intval($row['asset_id']);
+
+ $location_name = sanitizeInput($row['location_name']);
+
+ if ($invoice_id == 0) {
+
+ //Get the last Invoice Number and add 1 for the new invoice number
+ $invoice_number = $config_invoice_next_number;
+ $new_config_invoice_next_number = $config_invoice_next_number + 1;
+ mysqli_query($mysqli,"UPDATE settings SET config_invoice_next_number = $new_config_invoice_next_number WHERE company_id = 1");
+
+ //Generate a unique URL key for clients to access
+ $url_key = randomString(156);
+
+ mysqli_query($mysqli,"INSERT INTO invoices SET invoice_prefix = '$config_invoice_prefix', invoice_number = $invoice_number, invoice_scope = '$scope', invoice_date = '$date', invoice_due = DATE_ADD('$date', INTERVAL $client_net_terms day), invoice_currency_code = '$session_company_currency', invoice_category_id = $category, invoice_status = 'Draft', invoice_url_key = '$url_key', invoice_client_id = $client_id");
+ $invoice_id = mysqli_insert_id($mysqli);
+ }
+
+ //Add Item
+ $item_name = sanitizeInput($_POST['item_name']);
+ $item_description = sanitizeInput($_POST['item_description']);
+ $qty = floatval($_POST['qty']);
+ $price = floatval($_POST['price']);
+ $tax_id = intval($_POST['tax_id']);
+
+ $subtotal = $price * $qty;
+
+ if ($tax_id > 0) {
+ $sql = mysqli_query($mysqli,"SELECT * FROM taxes WHERE tax_id = $tax_id");
+ $row = mysqli_fetch_array($sql);
+ $tax_percent = floatval($row['tax_percent']);
+ $tax_amount = $subtotal * $tax_percent / 100;
+ }else{
+ $tax_amount = 0;
+ }
+
+ $total = $subtotal + $tax_amount;
+
+ mysqli_query($mysqli,"INSERT INTO invoice_items SET item_name = '$item_name', item_description = '$item_description', item_quantity = $qty, item_price = $price, item_subtotal = $subtotal, item_tax = $tax_amount, item_total = $total, item_tax_id = $tax_id, item_invoice_id = $invoice_id");
+
+ //Update Invoice Balances
+
+ $sql = mysqli_query($mysqli,"SELECT * FROM invoices WHERE invoice_id = $invoice_id");
+ $row = mysqli_fetch_array($sql);
+
+ $new_invoice_amount = floatval($row['invoice_amount']) + $total;
+
+ mysqli_query($mysqli,"UPDATE invoices SET invoice_amount = $new_invoice_amount WHERE invoice_id = $invoice_id");
+
+ mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Draft', history_description = 'Invoice created from Ticket $ticket_prefix$ticket_number', history_invoice_id = $invoice_id");
+
+ // Add internal note to ticket
+ mysqli_query($mysqli, "INSERT INTO ticket_replies SET ticket_reply = 'Created invoice $config_invoice_prefix$invoice_number for this ticket.', ticket_reply_type = 'Internal', ticket_reply_time_worked = '00:01:00', ticket_reply_by = $session_user_id, ticket_reply_ticket_id = $ticket_id");
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Invoice', log_action = 'Create', log_description = '$config_invoice_prefix$invoice_number created from Ticket $ticket_prefix$ticket_number', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Invoice created from ticket";
+
+ header("Location: invoice.php?invoice_id=$invoice_id");
+}
+
+if (isset($_POST['export_client_tickets_csv'])) {
+
+ validateTechRole();
+
+ $client_id = intval($_POST['client_id']);
+
+ //get records from database
+ $sql = mysqli_query($mysqli,"SELECT * FROM clients WHERE client_id = $client_id");
+ $row = mysqli_fetch_array($sql);
+
+ $client_name = $row['client_name'];
+
+ $sql = mysqli_query($mysqli,"SELECT * FROM tickets WHERE ticket_client_id = $client_id ORDER BY ticket_number ASC");
+ if ($sql->num_rows > 0) {
+ $delimiter = ",";
+ $filename = $client_name . "-Tickets-" . date('Y-m-d') . ".csv";
+
+ //create a file pointer
+ $f = fopen('php://memory', 'w');
+
+ //set column headers
+ $fields = array('Ticket Number', 'Priority', 'Status', 'Subject', 'Date Opened', 'Date Closed');
+ fputcsv($f, $fields, $delimiter);
+
+ //output each row of the data, format line as csv and write to file pointer
+ while($row = $sql->fetch_assoc()) {
+ $lineData = array($row['ticket_number'], $row['ticket_priority'], $row['ticket_status'], $row['ticket_subject'], $row['ticket_created_at'], $row['ticket_closed_at']);
+ fputcsv($f, $lineData, $delimiter);
+ }
+
+ //move back to beginning of file
+ fseek($f, 0);
+
+ //set headers to download file rather than displayed
+ header('Content-Type: text/csv');
+ header('Content-Disposition: attachment; filename="' . $filename . '";');
+
+ //output all remaining data on a file pointer
+ fpassthru($f);
+ }
+ exit;
+
+}
+
+if (isset($_POST['add_scheduled_ticket'])) {
+
+ validateTechRole();
+
+ require_once('post/scheduled_ticket_model.php');
+ $start_date = sanitizeInput($_POST['start_date']);
+
+ if ($client_id > 0 && $contact_id == 0) {
+ $sql = mysqli_query($mysqli, "SELECT primary_contact FROM clients WHERE client_id = $client_id");
+ $row = mysqli_fetch_array($sql);
+ $contact_id = intval($row['primary_contact']);
+ }
+
+ // Add scheduled ticket
+ mysqli_query($mysqli, "INSERT INTO scheduled_tickets SET scheduled_ticket_subject = '$subject', scheduled_ticket_details = '$details', scheduled_ticket_priority = '$priority', scheduled_ticket_frequency = '$frequency', scheduled_ticket_start_date = '$start_date', scheduled_ticket_next_run = '$start_date', scheduled_ticket_created_by = $session_user_id, scheduled_ticket_client_id = $client_id, scheduled_ticket_contact_id = $contact_id, scheduled_ticket_asset_id = $asset_id");
+
+ $scheduled_ticket_id = mysqli_insert_id($mysqli);
+
+ // Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Scheduled Ticket', log_action = 'Create', log_description = '$session_name created scheduled ticket for $subject - $frequency', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $scheduled_ticket_id");
+
+ $_SESSION['alert_message'] = "Scheduled ticket $subject - $frequency created";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_scheduled_ticket'])) {
+
+ validateTechRole();
+
+ require_once('post/scheduled_ticket_model.php');
+ $scheduled_ticket_id = intval($_POST['scheduled_ticket_id']);
+ $next_run_date = sanitizeInput($_POST['next_date']);
+
+ // Edit scheduled ticket
+ mysqli_query($mysqli, "UPDATE scheduled_tickets SET scheduled_ticket_subject = '$subject', scheduled_ticket_details = '$details', scheduled_ticket_priority = '$priority', scheduled_ticket_frequency = '$frequency', scheduled_ticket_next_run = '$next_run_date', scheduled_ticket_asset_id = $asset_id WHERE scheduled_ticket_id = $scheduled_ticket_id");
+
+ // Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Scheduled Ticket', log_action = 'Modify', log_description = '$session_name modified scheduled ticket for $subject - $frequency', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $scheduled_ticket_id");
+
+ $_SESSION['alert_message'] = "Scheduled ticket $subject - $frequency updated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['delete_scheduled_ticket'])) {
+
+ validateAdminRole();
+
+ $scheduled_ticket_id = intval($_GET['delete_scheduled_ticket']);
+
+ // Get Scheduled Ticket Subject Ticket Prefix, Number and Client ID for logging and alert message
+ $sql = mysqli_query($mysqli, "SELECT * FROM scheduled_tickets WHERE scheduled_ticket_id = $scheduled_ticket_id");
+ $row = mysqli_fetch_array($sql);
+ $scheduled_ticket_subject = sanitizeInput($row['scheduled_ticket_subject']);
+ $scheduled_ticket_frequency = sanitizeInput($row['scheduled_ticket_frequency']);
+
+ $client_id = intval($row['scheduled_ticket_client_id']);
+
+ // Delete
+ mysqli_query($mysqli, "DELETE FROM scheduled_tickets WHERE scheduled_ticket_id = $scheduled_ticket_id");
+
+ //Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Scheduled Ticket', log_action = 'Delete', log_description = '$session_name deleted scheduled ticket for $subject - $frequency', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $scheduled_ticket_id");
+
+ $_SESSION['alert_message'] = "Scheduled ticket $subject - $frequency deleted";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['bulk_delete_scheduled_tickets'])) {
+ validateAdminRole();
+ validateCSRFToken($_POST['csrf_token']);
+
+ $count = 0; // Default 0
+ $scheduled_ticket_ids = $_POST['scheduled_ticket_ids']; // Get array of scheduled tickets IDs to be deleted
+
+ if (!empty($scheduled_ticket_ids)) {
+
+ // Cycle through array and delete each scheduled ticket
+ foreach ($scheduled_ticket_ids as $scheduled_ticket_id) {
+
+ $scheduled_ticket_id = intval($scheduled_ticket_id);
+ mysqli_query($mysqli, "DELETE FROM scheduled_tickets WHERE scheduled_ticket_id = $scheduled_ticket_id");
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Scheduled Ticket', log_action = 'Delete', log_description = '$session_name deleted scheduled ticket (bulk)', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id, log_entity_id = $scheduled_ticket_id");
+
+ $count++;
+ }
+
+ // Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Scheduled Ticket', log_action = 'Delete', log_description = '$session_name bulk deleted $count scheduled tickets', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Deleted $count scheduled ticket(s)";
+
+ }
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
diff --git a/post/transfer.php b/post/transfer.php
new file mode 100644
index 00000000..6eeb815b
--- /dev/null
+++ b/post/transfer.php
@@ -0,0 +1,73 @@
+ 0){
+ $delimiter = ",";
+ $filename = "$session_company_name-Trips-$file_name_date.csv";
+
+ //create a file pointer
+ $f = fopen('php://memory', 'w');
+
+ //set column headers
+ $fields = array('Date', 'Purpose', 'Source', 'Destination', 'Miles');
+ fputcsv($f, $fields, $delimiter);
+
+ //output each row of the data, format line as csv and write to file pointer
+ while($row = mysqli_fetch_assoc($sql)){
+ $lineData = array($row['trip_date'], $row['trip_purpose'], $row['trip_source'], $row['trip_destination'], $row['trip_miles']);
+ fputcsv($f, $lineData, $delimiter);
+ }
+
+ //move back to beginning of file
+ fseek($f, 0);
+
+ //set headers to download file rather than displayed
+ header('Content-Type: text/csv');
+ header('Content-Disposition: attachment; filename="' . $filename . '";');
+
+ //output all remaining data on a file pointer
+ fpassthru($f);
+ }
+ exit;
+
+}
+
+if (isset($_POST['export_client_trips_csv'])) {
+ $client_id = intval($_POST['client_id']);
+
+ //get records from database
+ $sql = mysqli_query($mysqli,"SELECT * FROM clients WHERE client_id = $client_id");
+ $row = mysqli_fetch_array($sql);
+
+ $client_name = $row['client_name'];
+
+ $sql = mysqli_query($mysqli,"SELECT * FROM trips WHERE trip_client_id = $client_id ORDER BY trip_date ASC");
+ if($sql->num_rows > 0){
+ $delimiter = ",";
+ $filename = $client_name . "-Trips-" . date('Y-m-d') . ".csv";
+
+ //create a file pointer
+ $f = fopen('php://memory', 'w');
+
+ //set column headers
+ $fields = array('Date', 'Purpose', 'Source', 'Destination', 'Miles');
+ fputcsv($f, $fields, $delimiter);
+
+ //output each row of the data, format line as csv and write to file pointer
+ while($row = $sql->fetch_assoc()){
+ $lineData = array($row['trip_date'], $row['trip_purpose'], $row['trip_source'], $row['trip_destination'], $row['trip_miles']);
+ fputcsv($f, $lineData, $delimiter);
+ }
+
+ //move back to beginning of file
+ fseek($f, 0);
+
+ //set headers to download file rather than displayed
+ header('Content-Type: text/csv');
+ header('Content-Disposition: attachment; filename="' . $filename . '";');
+
+ //output all remaining data on a file pointer
+ fpassthru($f);
+ }
+ exit;
+
+}
diff --git a/models/trip.php b/post/trip_model.php
similarity index 100%
rename from models/trip.php
rename to post/trip_model.php
diff --git a/post/user.php b/post/user.php
new file mode 100644
index 00000000..591527fb
--- /dev/null
+++ b/post/user.php
@@ -0,0 +1,282 @@
+
An ITFlow account has been setup for you. Please change your password upon login.
Username: $email
Password: $_POST[password]
Login URL: https://$config_base_url
~
$session_company_name
Support Department
$config_ticket_from_email";
+
+ $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port,
+ $config_ticket_from_email, $config_ticket_from_name,
+ $email, $name,
+ $subject, $body);
+
+ if ($mail !== true) {
+ mysqli_query($mysqli, "INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $email'");
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $email regarding $subject. $mail', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id, log_entity_id = $user_id");
+ }
+
+ }
+
+ // Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'User', log_action = 'Create', log_description = '$session_name created user $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id, log_entity_id = $user_id");
+
+ $_SESSION['alert_message'] = "User $name created" . $extended_alert_description;
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['edit_user'])) {
+
+ require_once('post/user_model.php');
+
+ validateAdminRole();
+
+ validateCSRFToken($_POST['csrf_token']);
+
+ $user_id = intval($_POST['user_id']);
+ $new_password = trim($_POST['new_password']);
+
+ // Get current Avatar
+ $sql = mysqli_query($mysqli, "SELECT user_avatar FROM users WHERE user_id = $user_id");
+ $row = mysqli_fetch_array($sql);
+ $existing_file_name = sanitizeInput($row['user_avatar']);
+
+ $extended_log_description = '';
+ if (!empty($_POST['2fa'])) {
+ $two_fa = $_POST['2fa'];
+ }
+
+ if (!file_exists("uploads/users/$user_id/")) {
+ mkdir("uploads/users/$user_id");
+ }
+
+ // Check for and process image/photo
+ $extended_alert_description = '';
+ if ($_FILES['file']['tmp_name'] != '') {
+ if ($new_file_name = checkFileUpload($_FILES['file'], array('jpg', 'jpeg', 'gif', 'png'))) {
+
+ $file_tmp_path = $_FILES['file']['tmp_name'];
+
+ // directory in which the uploaded file will be moved
+ $upload_file_dir = "uploads/users/$user_id/";
+ $dest_path = $upload_file_dir . $new_file_name;
+ move_uploaded_file($file_tmp_path, $dest_path);
+
+ // Delete old file
+ unlink("uploads/users/$user_id/$existing_file_name");
+
+ // Set Avatar
+ mysqli_query($mysqli, "UPDATE users SET user_avatar = '$new_file_name' WHERE user_id = $user_id");
+ $extended_alert_description = '. File successfully uploaded.';
+ } else {
+ $_SESSION['alert_type'] = "error";
+ $extended_alert_description = '. Error uploading photo. Check upload directory is writable/correct file type/size';
+ }
+ }
+
+ mysqli_query($mysqli, "UPDATE users SET user_name = '$name', user_email = '$email' WHERE user_id = $user_id");
+
+ if (!empty($new_password)) {
+ $new_password = password_hash($new_password, PASSWORD_DEFAULT);
+ $user_specific_encryption_ciphertext = encryptUserSpecificKey(trim($_POST['new_password']));
+ mysqli_query($mysqli, "UPDATE users SET user_password = '$new_password', user_specific_encryption_ciphertext = '$user_specific_encryption_ciphertext' WHERE user_id = $user_id");
+ //Extended Logging
+ $extended_log_description .= ", password changed";
+ }
+
+ if (!empty($two_fa) && $two_fa == 'disable') {
+ mysqli_query($mysqli, "UPDATE users SET user_token = '' WHERE user_id = '$user_id'");
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'User', log_action = 'Modify', log_description = '$session_name disabled 2FA for $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+ }
+
+ //Update User Settings
+ mysqli_query($mysqli, "UPDATE user_settings SET user_role = $role WHERE user_id = $user_id");
+
+ //Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'User', log_action = 'Modify', log_description = '$session_name modified user $name $extended_log_description', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id, log_entity_id = $user_id");
+
+ $_SESSION['alert_message'] = "User $name updated" . $extended_alert_description;
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['activate_user'])) {
+
+ validateAdminRole();
+ validateCSRFToken($_GET['csrf_token']);
+
+ $user_id = intval($_GET['activate_user']);
+
+ // Get User Name
+ $sql = mysqli_query($mysqli, "SELECT * FROM users WHERE user_id = $user_id");
+ $row = mysqli_fetch_array($sql);
+ $user_name = sanitizeInput($row['user_name']);
+
+ mysqli_query($mysqli, "UPDATE users SET user_status = 1 WHERE user_id = $user_id");
+
+ //Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'User', log_action = 'Modify', log_description = '$session_name activated user $user_name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id, log_entity_id = $user_id");
+
+ $_SESSION['alert_message'] = "User $user_name activated";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['disable_user'])) {
+
+ validateAdminRole();
+ validateCSRFToken($_GET['csrf_token']);
+
+ $user_id = intval($_GET['disable_user']);
+
+ // Get User Name
+ $sql = mysqli_query($mysqli, "SELECT * FROM users WHERE user_id = $user_id");
+ $row = mysqli_fetch_array($sql);
+ $user_name = sanitizeInput($row['user_name']);
+
+ mysqli_query($mysqli, "UPDATE users SET user_status = 0 WHERE user_id = $user_id");
+
+ //Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'User', log_action = 'Modify', log_description = '$session_name disabled user $user_name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id, log_entity_id = $user_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "User $user_name disabled";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_GET['archive_user'])) {
+
+ validateAdminRole();
+
+ // CSRF Check
+ validateCSRFToken($_GET['csrf_token']);
+
+ // Variables from GET
+ $user_id = intval($_GET['archive_user']);
+ $password = password_hash(randomString(), PASSWORD_DEFAULT);
+
+ // Get user details
+ $sql = mysqli_query($mysqli, "SELECT * FROM users WHERE user_id = $user_id");
+ $row = mysqli_fetch_array($sql);
+ $name = sanitizeInput($row['user_name']);
+
+ // Archive user query
+ mysqli_query($mysqli, "UPDATE users SET user_name = '$name (archived)', user_password = '$password', user_specific_encryption_ciphertext = '', user_archived_at = NOW() WHERE user_id = $user_id");
+
+ // Logging
+ mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'User', log_action = 'Archive', log_description = '$session_name archived user $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id, log_entity_id = $user_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "User $name archived";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+if (isset($_POST['export_users_csv'])) {
+
+ validateAdminRole();
+
+ //get records from database
+ $sql = mysqli_query($mysqli, "SELECT * FROM users ORDER BY user_name ASC");
+
+ if ($sql->num_rows > 0) {
+ $delimiter = ", ";
+ $filename = $session_company_name . "-Users-" . date('Y-m-d') . ".csv";
+
+ //create a file pointer
+ $f = fopen('php://memory', 'w');
+
+ //set column headers
+ $fields = array('Name', 'Email', 'Role', 'Status', 'Creation Date');
+ fputcsv($f, $fields, $delimiter);
+
+ //output each row of the data, format line as csv and write to file pointer
+ while($row = $sql->fetch_assoc()) {
+
+ $user_status = intval($row['user_status']);
+ if ($user_status == 2) {
+ $user_status_display = "Invited";
+ } elseif ($user_status == 1) {
+ $user_status_display = "Active";
+ } else{
+ $user_status_display = "Disabled";
+ }
+ $user_role = $row['user_role'];
+ if ($user_role == 3) {
+ $user_role_display = "Administrator";
+ } elseif ($user_role == 2) {
+ $user_role_display = "Technician";
+ } else {
+ $user_role_display = "Accountant";
+ }
+
+ $lineData = array($row['user_name'], $row['user_email'], $user_role_display, $user_status_display, $row['user_created_at']);
+ fputcsv($f, $lineData, $delimiter);
+ }
+
+ //move back to beginning of file
+ fseek($f, 0);
+
+ //set headers to download file rather than displayed
+ header('Content-Type: text/csv');
+ header('Content-Disposition: attachment; filename="' . $filename . '";');
+
+ //output all remaining data on a file pointer
+ fpassthru($f);
+ }
+ exit;
+
+}
diff --git a/models/user.php b/post/user_model.php
similarity index 100%
rename from models/user.php
rename to post/user_model.php
diff --git a/post/vendor.php b/post/vendor.php
new file mode 100644
index 00000000..76718c09
--- /dev/null
+++ b/post/vendor.php
@@ -0,0 +1,211 @@
+$name created";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['edit_vendor_template'])) {
+
+ require_once('post/vendor_model.php');
+
+ $vendor_id = intval($_POST['vendor_id']);
+ $vendor_template_id = intval($_POST['vendor_template_id']);
+
+ if ($_POST['update_base_vendors'] == 1) {
+ $sql_update_vendors = "OR vendor_template_id = $vendor_id";
+ } else {
+ $sql_update_vendors = "";
+ }
+
+ //Update the exisiting template and all templates bassed of this vendor template
+ mysqli_query($mysqli,"UPDATE vendors SET vendor_name = '$name', vendor_description = '$description', vendor_contact_name = '$contact_name', vendor_phone = '$phone', vendor_extension = '$extension', vendor_email = '$email', vendor_website = '$website', vendor_hours = '$hours', vendor_sla = '$sla', vendor_code = '$code', vendor_account_number = '$account_number', vendor_notes = '$notes' WHERE (vendor_id = $vendor_id $sql_update_vendors)");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Vendor Template', log_action = 'Modify', log_description = '$session_name modified vendor template $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Vendor template $name modified";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['add_vendor_from_template'])) {
+
+ // GET POST Data
+ $client_id = intval($_POST['client_id']); //Used if this vendor is under a contact otherwise its 0 for under company and or template
+ $vendor_template_id = intval($_POST['vendor_template_id']);
+
+ //GET Vendor Info
+ $sql_vendor = mysqli_query($mysqli,"SELECT * FROM vendors WHERE vendor_id = $vendor_template_id");
+
+ $row = mysqli_fetch_array($sql_vendor);
+
+ $name = sanitizeInput($row['vendor_name']);
+ $description = sanitizeInput($row['vendor_description']);
+ $account_number = sanitizeInput($row['vendor_account_number']);
+ $contact_name = sanitizeInput($row['vendor_contact_name']);
+ $phone = preg_replace("/[^0-9]/", '',$row['vendor_phone']);
+ $extension = preg_replace("/[^0-9]/", '',$row['vendor_extension']);
+ $email = sanitizeInput($row['vendor_email']);
+ $website = sanitizeInput($row['vendor_website']);
+ $hours = sanitizeInput($row['vendor_hours']);
+ $sla = sanitizeInput($row['vendor_sla']);
+ $code = sanitizeInput($row['vendor_code']);
+ $notes = sanitizeInput($row['vendor_notes']);
+
+ // Vendor add query
+ mysqli_query($mysqli,"INSERT INTO vendors SET vendor_name = '$name', vendor_description = '$description', vendor_contact_name = '$contact_name', vendor_phone = '$phone', vendor_extension = '$extension', vendor_email = '$email', vendor_website = '$website', vendor_hours = '$hours', vendor_sla = '$sla', vendor_code = '$code', vendor_account_number = '$account_number', vendor_notes = '$notes', vendor_client_id = $client_id, vendor_template_id = $vendor_template_id");
+
+ $vendor_id = mysqli_insert_id($mysqli);
+
+ // Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Vendor', log_action = 'Create', log_description = 'Vendor created from template $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Vendor created from template";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+
+}
+
+// Vendors
+
+if (isset($_POST['add_vendor'])) {
+
+ require_once('post/vendor_model.php');
+
+ $client_id = intval($_POST['client_id']); // Used if this vendor is under a contact otherwise its 0 for under company
+
+ mysqli_query($mysqli,"INSERT INTO vendors SET vendor_name = '$name', vendor_description = '$description', vendor_contact_name = '$contact_name', vendor_phone = '$phone', vendor_extension = '$extension', vendor_email = '$email', vendor_website = '$website', vendor_hours = '$hours', vendor_sla = '$sla', vendor_code = '$code', vendor_account_number = '$account_number', vendor_notes = '$notes', vendor_client_id = $client_id");
+
+ $vendor_id = mysqli_insert_id($mysqli);
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Vendor', log_action = 'Create', log_description = '$session_name created vendor $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Vendor $name created";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['edit_vendor'])) {
+
+ require_once('post/vendor_model.php');
+
+ $vendor_id = intval($_POST['vendor_id']);
+ $vendor_template_id = intval($_POST['vendor_template_id']);
+
+ mysqli_query($mysqli,"UPDATE vendors SET vendor_name = '$name', vendor_description = '$description', vendor_contact_name = '$contact_name', vendor_phone = '$phone', vendor_extension = '$extension', vendor_email = '$email', vendor_website = '$website', vendor_hours = '$hours', vendor_sla = '$sla', vendor_code = '$code',vendor_account_number = '$account_number', vendor_notes = '$notes', vendor_template_id = $vendor_template_id WHERE vendor_id = $vendor_id");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Vendor', log_action = 'Modify', log_description = '$session_name modified vendor $name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_user_id = $session_user_id");
+
+ $_SESSION['alert_message'] = "Vendor $name modified";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_GET['archive_vendor'])) {
+ $vendor_id = intval($_GET['archive_vendor']);
+
+ //Get Vendor Name
+ $sql = mysqli_query($mysqli,"SELECT * FROM vendors WHERE vendor_id = $vendor_id");
+ $row = mysqli_fetch_array($sql);
+ $vendor_name = sanitizeInput($row['vendor_name']);
+
+ mysqli_query($mysqli,"UPDATE vendors SET vendor_archived_at = NOW() WHERE vendor_id = $vendor_id");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Vendor', log_action = 'Archive', log_description = '$session_name archived vendor $vendor_name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Vendor $vendor_name archived";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_GET['delete_vendor'])) {
+ $vendor_id = intval($_GET['delete_vendor']);
+
+ //Get Vendor Name
+ $sql = mysqli_query($mysqli,"SELECT * FROM vendors WHERE vendor_id = $vendor_id");
+ $row = mysqli_fetch_array($sql);
+ $vendor_name = sanitizeInput($row['vendor_name']);
+ $client_id = intval($row['vendor_client_id']);
+ $vendor_template_id = intval($row['vendor_template_id']);
+
+ // If its a template reset all vendors based off this template to no template base
+ if ($vendor_template_id > 0) {
+ mysqli_query($mysqli,"UPDATE vendors SET vendor_template_id = 0 WHERE vendor_template_id = $vendor_template_id");
+ }
+
+ mysqli_query($mysqli,"DELETE FROM vendors WHERE vendor_id = $vendor_id");
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Vendor', log_action = 'Delete', log_description = '$session_name deleted vendor $vendor_name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id");
+
+ $_SESSION['alert_type'] = "error";
+ $_SESSION['alert_message'] = "Vendor $vendor_name deleted";
+
+ header("Location: " . $_SERVER["HTTP_REFERER"]);
+}
+
+if (isset($_POST['export_client_vendors_csv'])) {
+ $client_id = intval($_POST['client_id']);
+
+ //get records from database
+ $sql = mysqli_query($mysqli,"SELECT * FROM clients WHERE client_id = $client_id");
+ $row = mysqli_fetch_array($sql);
+
+ $client_name = $row['client_name'];
+
+ $sql = mysqli_query($mysqli,"SELECT * FROM vendors WHERE vendor_client_id = $client_id ORDER BY vendor_name ASC");
+ if ($sql->num_rows > 0) {
+ $delimiter = ",";
+ $filename = $client_name . "-Vendors-" . date('Y-m-d') . ".csv";
+
+ //create a file pointer
+ $f = fopen('php://memory', 'w');
+
+ //set column headers
+ $fields = array('Name', 'Description', 'Contact Name', 'Phone', 'Website', 'Account Number', 'Notes');
+ fputcsv($f, $fields, $delimiter);
+
+ //output each row of the data, format line as csv and write to file pointer
+ while($row = $sql->fetch_assoc()) {
+ $lineData = array($row['vendor_name'], $row['vendor_description'], $row['vendor_contact_name'], $row['vendor_phone'], $row['vendor_website'], $row['vendor_account_number'], $row['vendor_notes']);
+ fputcsv($f, $lineData, $delimiter);
+ }
+
+ //move back to beginning of file
+ fseek($f, 0);
+
+ //set headers to download file rather than displayed
+ header('Content-Type: text/csv');
+ header('Content-Disposition: attachment; filename="' . $filename . '";');
+
+ //output all remaining data on a file pointer
+ fpassthru($f);
+ }
+
+ //Logging
+ mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Vendor', log_action = 'Export', log_description = '$session_name exported vendors to CSV', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id");
+
+ exit;
+}
diff --git a/models/vendor.php b/post/vendor_model.php
similarity index 100%
rename from models/vendor.php
rename to post/vendor_model.php