diff --git a/client_contacts.php b/client_contacts.php index 6546d0ba..f6994bff 100644 --- a/client_contacts.php +++ b/client_contacts.php @@ -120,6 +120,19 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); Set Roles + +
+ + + + + diff --git a/post/contact.php b/post/contact.php index 8131ebb9..f1891c66 100644 --- a/post/contact.php +++ b/post/contact.php @@ -334,6 +334,88 @@ if (isset($_POST['bulk_edit_contact_role'])) { } +if (isset($_POST['bulk_archive_contacts'])) { + validateAdminRole(); + //validateCSRFToken($_POST['csrf_token']); + + $count = 0; // Default 0 + $contact_ids = $_POST['contact_ids']; // Get array of contact IDs to be deleted + + if (!empty($contact_ids)) { + + // Cycle through array and archive each contact + foreach ($contact_ids as $contact_id) { + + $contact_id = intval($contact_id); + + // Get Contact Name and Client ID for logging and alert message + $sql = mysqli_query($mysqli,"SELECT contact_name, contact_client_id, contact_primary FROM contacts WHERE contact_id = $contact_id"); + $row = mysqli_fetch_array($sql); + $contact_name = sanitizeInput($row['contact_name']); + $contact_primary = intval($row['contact_primary']); + $client_id = intval($row['contact_client_id']); + + + if($contact_primary == 0) { + mysqli_query($mysqli,"UPDATE contacts SET contact_important = 0, contact_billing = 0, contact_technical = 0, contact_auth_method = '', contact_password_hash = '', contact_archived_at = NOW() WHERE contact_id = $contact_id"); + + // Individual Contact logging + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Contact', log_action = 'Archive', log_description = '$session_name archived contact $contact_name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $contact_id"); + $count++; + } + + } + + // Bulk Logging + mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Contact', log_action = 'Archive', log_description = '$session_name archived $count contacts', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id"); + + $_SESSION['alert_type'] = "error"; + $_SESSION['alert_message'] = "Archived $count contact(s)"; + + } + + header("Location: " . $_SERVER["HTTP_REFERER"]); +} + +if (isset($_POST['bulk_unarchive_contacts'])) { + validateAdminRole(); + //validateCSRFToken($_POST['csrf_token']); + + $count = 0; // Default 0 + $contact_ids = $_POST['contact_ids']; // Get array of contact IDs + + if (!empty($contact_ids)) { + + // Cycle through array and unarchive each contact + foreach ($contact_ids as $contact_id) { + + $contact_id = intval($contact_id); + + // Get Contact Name and Client ID for logging and alert message + $sql = mysqli_query($mysqli,"SELECT contact_name, contact_client_id FROM contacts WHERE contact_id = $contact_id"); + $row = mysqli_fetch_array($sql); + $contact_name = sanitizeInput($row['contact_name']); + $client_id = intval($row['contact_client_id']); + + mysqli_query($mysqli,"UPDATE contacts SET contact_archived_at = NULL WHERE contact_id = $contact_id"); + + // Individual Contact logging + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Asset', log_action = 'Unarchive', log_description = '$session_name Unarchived contact $contact_name', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id, log_entity_id = $contact_id"); + + + $count++; + } + + // Bulk Logging + mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Asset', log_action = 'Unarchive', log_description = '$session_name Unarchived $count contacts', log_ip = '$session_ip', log_user_agent = '$session_user_agent', log_client_id = $client_id, log_user_id = $session_user_id"); + + $_SESSION['alert_message'] = "Unarchived $count contact(s)"; + + } + + header("Location: " . $_SERVER["HTTP_REFERER"]); +} + if (isset($_GET['anonymize_contact'])) { validateAdminRole();