From f7d9fe84792b0bb3c5d4fc02fe21e7da8c74918d Mon Sep 17 00:00:00 2001 From: Marcus Hill Date: Sat, 21 Jan 2023 12:29:39 +0000 Subject: [PATCH 01/12] Add email notifications when cron raises a scheduled ticket --- cron.php | 562 +++++++++++++++++++++++++++++-------------------------- 1 file changed, 301 insertions(+), 261 deletions(-) diff --git a/cron.php b/cron.php index aaca58bb..703d36ad 100644 --- a/cron.php +++ b/cron.php @@ -9,201 +9,241 @@ $sql_companies = mysqli_query($mysqli,"SELECT * FROM companies, settings WHERE companies.company_id = settings.company_id"); while($row = mysqli_fetch_array($sql_companies)){ - $company_id = $row['company_id']; - $company_name = $row['company_name']; - $company_phone = formatPhoneNumber($row['company_phone']); - $company_email = $row['company_email']; - $company_website = $row['company_website']; - $company_locale = $row['company_locale']; - $config_enable_cron = $row['config_enable_cron']; - $config_invoice_overdue_reminders = $row['config_invoice_overdue_reminders']; - $config_invoice_prefix = $row['config_invoice_prefix']; - $config_invoice_from_email = $row['config_invoice_from_email']; - $config_invoice_from_name = $row['config_invoice_from_name']; - $config_smtp_host = $row['config_smtp_host']; - $config_smtp_username = $row['config_smtp_username']; - $config_smtp_password = $row['config_smtp_password']; - $config_smtp_port = $row['config_smtp_port']; - $config_smtp_encryption = $row['config_smtp_encryption']; - $config_mail_from_email = $row['config_mail_from_email']; - $config_mail_from_name = $row['config_mail_from_name']; - $config_recurring_auto_send_invoice = $row['config_recurring_auto_send_invoice']; + $company_id = $row['company_id']; + $company_name = $row['company_name']; + $company_phone = formatPhoneNumber($row['company_phone']); + $company_email = $row['company_email']; + $company_website = $row['company_website']; + $company_locale = $row['company_locale']; + $config_enable_cron = $row['config_enable_cron']; + $config_invoice_overdue_reminders = $row['config_invoice_overdue_reminders']; + $config_invoice_prefix = $row['config_invoice_prefix']; + $config_invoice_from_email = $row['config_invoice_from_email']; + $config_invoice_from_name = $row['config_invoice_from_name']; + $config_smtp_host = $row['config_smtp_host']; + $config_smtp_username = $row['config_smtp_username']; + $config_smtp_password = $row['config_smtp_password']; + $config_smtp_port = $row['config_smtp_port']; + $config_smtp_encryption = $row['config_smtp_encryption']; + $config_mail_from_email = $row['config_mail_from_email']; + $config_mail_from_name = $row['config_mail_from_name']; + $config_recurring_auto_send_invoice = $row['config_recurring_auto_send_invoice']; - // Tickets - $config_ticket_prefix = $row['config_ticket_prefix']; - $config_ticket_next_number = $row['config_ticket_next_number']; + // Tickets + $config_ticket_prefix = $row['config_ticket_prefix']; + $config_ticket_next_number = $row['config_ticket_next_number']; + $config_ticket_from_name = $row['config_ticket_from_name']; + $config_ticket_from_email = $row['config_ticket_from_email']; - // Set Currency Format - $currency_format = numfmt_create($company_locale, NumberFormatter::CURRENCY); + // Set Currency Format + $currency_format = numfmt_create($company_locale, NumberFormatter::CURRENCY); - if($config_enable_cron == 1){ + if($config_enable_cron == 1){ - //Logging - mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Cron', log_action = 'Started', log_description = 'Cron started for $company_name', company_id = $company_id"); + //Logging + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Cron', log_action = 'Started', log_description = 'Cron started for $company_name', company_id = $company_id"); - // GET NOTIFICATIONS + // GET NOTIFICATIONS - // DOMAINS EXPIRING + // DOMAINS EXPIRING - $domainAlertArray = [1,7,14,30,90,120]; + $domainAlertArray = [1,7,14,30,90,120]; - foreach($domainAlertArray as $day){ + foreach($domainAlertArray as $day){ - //Get Domains Expiring - $sql = mysqli_query($mysqli,"SELECT * FROM domains + //Get Domains Expiring + $sql = mysqli_query($mysqli,"SELECT * FROM domains LEFT JOIN clients ON domain_client_id = client_id WHERE domain_expire = CURDATE() + INTERVAL $day DAY AND domains.company_id = $company_id" - ); + ); - while($row = mysqli_fetch_array($sql)){ - $domain_id = $row['domain_id']; - $domain_name = mysqli_real_escape_string($mysqli,$row['domain_name']); - $domain_expire = $row['domain_expire']; - $client_id = $row['client_id']; - $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); + while($row = mysqli_fetch_array($sql)){ + $domain_id = $row['domain_id']; + $domain_name = mysqli_real_escape_string($mysqli,$row['domain_name']); + $domain_expire = $row['domain_expire']; + $client_id = $row['client_id']; + $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Domain', notification = 'Domain $domain_name for $client_name will expire in $day Days on $domain_expire', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Domain', notification = 'Domain $domain_name for $client_name will expire in $day Days on $domain_expire', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); - } + } - } + } - // CERTIFICATES EXPIRING + // CERTIFICATES EXPIRING - $certificateAlertArray = [1,7,14,30,90,120]; + $certificateAlertArray = [1,7,14,30,90,120]; - foreach($certificateAlertArray as $day){ + foreach($certificateAlertArray as $day){ - //Get Certs Expiring - $sql = mysqli_query($mysqli,"SELECT * FROM certificates + //Get Certs Expiring + $sql = mysqli_query($mysqli,"SELECT * FROM certificates LEFT JOIN clients ON certificate_client_id = client_id WHERE certificate_expire = CURDATE() + INTERVAL $day DAY AND certificates.company_id = $company_id" - ); + ); - while($row = mysqli_fetch_array($sql)){ - $certificate_id = $row['certificate_id']; - $certificate_name = mysqli_real_escape_string($mysqli,$row['certificate_name']); - $certificate_domain = $row['certificate_domain']; - $certificate_expire = $row['certificate_expire']; - $client_id = $row['client_id']; - $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); + while($row = mysqli_fetch_array($sql)){ + $certificate_id = $row['certificate_id']; + $certificate_name = mysqli_real_escape_string($mysqli,$row['certificate_name']); + $certificate_domain = $row['certificate_domain']; + $certificate_expire = $row['certificate_expire']; + $client_id = $row['client_id']; + $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Certificate', notification = 'Certificate $certificate_name for $client_name will expire in $day Days on $certificate_expire', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Certificate', notification = 'Certificate $certificate_name for $client_name will expire in $day Days on $certificate_expire', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); - } + } - } + } - // Asset Warranties Expiring + // Asset Warranties Expiring - $warranty_alert_array = [1,7,14,30,90,120]; + $warranty_alert_array = [1,7,14,30,90,120]; - foreach($warranty_alert_array as $day){ + foreach($warranty_alert_array as $day){ - //Get Asset Warranty Expiring - $sql = mysqli_query($mysqli,"SELECT * FROM assets + //Get Asset Warranty Expiring + $sql = mysqli_query($mysqli,"SELECT * FROM assets LEFT JOIN clients ON asset_client_id = client_id WHERE asset_warranty_expire = CURDATE() + INTERVAL $day DAY AND assets.company_id = $company_id" - ); + ); - while($row = mysqli_fetch_array($sql)){ - $asset_id = $row['asset_id']; - $asset_name = mysqli_real_escape_string($mysqli,$row['asset_name']); - $asset_warranty_expire = $row['asset_warranty_expire']; - $client_id = $row['client_id']; - $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); + while($row = mysqli_fetch_array($sql)){ + $asset_id = $row['asset_id']; + $asset_name = mysqli_real_escape_string($mysqli,$row['asset_name']); + $asset_warranty_expire = $row['asset_warranty_expire']; + $client_id = $row['client_id']; + $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Asset', notification = 'Asset $asset_name warranty for $client_name will expire in $day Days on $asset_warranty_expire', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Asset', notification = 'Asset $asset_name warranty for $client_name will expire in $day Days on $asset_warranty_expire', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); - } + } - } - - // Scheduled tickets - - // Get date for search - $today = new DateTime(); - $today_text = $today->format('Y-m-d'); - - // Get scheduled tickets for today - $sql_scheduled_tickets = mysqli_query($mysqli, "SELECT * FROM scheduled_tickets WHERE scheduled_ticket_next_run = '$today_text'"); - - if(mysqli_num_rows($sql_scheduled_tickets) > 0){ - while($row = mysqli_fetch_array($sql_scheduled_tickets)){ - $schedule_id = $row['scheduled_ticket_id']; - $subject = mysqli_real_escape_string($mysqli,$row['scheduled_ticket_subject']); - $details = mysqli_real_escape_string($mysqli,$row['scheduled_ticket_details']); - $priority = $row['scheduled_ticket_priority']; - $frequency = strtolower($row['scheduled_ticket_frequency']); - $created_id = $row['scheduled_ticket_created_by']; - $client_id = $row['scheduled_ticket_client_id']; - $contact_id = $row['scheduled_ticket_contact_id']; - $asset_id = $row['scheduled_ticket_asset_id']; - $company_id = $row['company_id']; - - //Get the next Ticket Number and add 1 for the new ticket number - $ticket_number = $config_ticket_next_number; - $new_config_ticket_next_number = $config_ticket_next_number + 1; - mysqli_query($mysqli,"UPDATE settings SET config_ticket_next_number = $new_config_ticket_next_number WHERE company_id = '$company_id'"); - - // Raise the ticket - mysqli_query($mysqli,"INSERT INTO tickets SET ticket_prefix = '$config_ticket_prefix', ticket_number = $ticket_number, ticket_subject = '$subject', ticket_details = '$details', ticket_priority = '$priority', ticket_status = 'Open', ticket_created_at = NOW(), ticket_created_by = $created_id, ticket_contact_id = $contact_id, ticket_client_id = $client_id, ticket_asset_id = $asset_id, company_id = $company_id"); - - // Logging - mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Create', log_description = 'System created scheduled $frequency ticket - $subject', log_created_at = NOW(), log_client_id = $client_id, company_id = $company_id, log_user_id = $created_id"); - - // Set the next run date - if($frequency == "weekly"){ - // Note: We seemingly have to initialize a new datetime for each loop to avoid stacking the dates - $now = new DateTime(); - $next_run = date_add($now, date_interval_create_from_date_string('1 week')); - } - elseif($frequency == "monthly"){ - $now = new DateTime(); - $next_run = date_add($now, date_interval_create_from_date_string('1 month')); - } - elseif($frequency == "quarterly"){ - $now = new DateTime(); - $next_run = date_add($now, date_interval_create_from_date_string('3 months')); - } - elseif($frequency == "biannually"){ - $now = new DateTime(); - $next_run = date_add($now, date_interval_create_from_date_string('6 months')); - } - elseif($frequency == "annually"){ - $now = new DateTime(); - $next_run = date_add($now, date_interval_create_from_date_string('12 months')); } - // Update the run date - $next_run = $next_run->format('Y-m-d'); - $a = mysqli_query($mysqli, "UPDATE scheduled_tickets SET scheduled_ticket_next_run = '$next_run' WHERE scheduled_ticket_id = '$schedule_id'"); + // Scheduled tickets - } - } + // Get date for search + $today = new DateTime(); + $today_text = $today->format('Y-m-d'); - // Clean-up ticket views table used for collision detection - mysqli_query($mysqli, "TRUNCATE TABLE ticket_views"); + // Get scheduled tickets for today + $sql_scheduled_tickets = mysqli_query($mysqli, "SELECT * FROM scheduled_tickets WHERE scheduled_ticket_next_run = '$today_text'"); - // Clean-up shared items that have been used - mysqli_query($mysqli, "DELETE FROM shared_items WHERE item_views = item_view_limit"); + if(mysqli_num_rows($sql_scheduled_tickets) > 0){ + while($row = mysqli_fetch_array($sql_scheduled_tickets)){ + $schedule_id = $row['scheduled_ticket_id']; + $subject = mysqli_real_escape_string($mysqli,$row['scheduled_ticket_subject']); + $details = mysqli_real_escape_string($mysqli,$row['scheduled_ticket_details']); + $priority = $row['scheduled_ticket_priority']; + $frequency = strtolower($row['scheduled_ticket_frequency']); + $created_id = $row['scheduled_ticket_created_by']; + $client_id = $row['scheduled_ticket_client_id']; + $contact_id = $row['scheduled_ticket_contact_id']; + $asset_id = $row['scheduled_ticket_asset_id']; + $company_id = $row['company_id']; - // Clean-up shared items that have expired - mysqli_query($mysqli, "DELETE FROM shared_items WHERE item_expire_at < NOW()"); + //Get the next Ticket Number and add 1 for the new ticket number + $ticket_number = $config_ticket_next_number; + $new_config_ticket_next_number = $config_ticket_next_number + 1; + mysqli_query($mysqli,"UPDATE settings SET config_ticket_next_number = $new_config_ticket_next_number WHERE company_id = '$company_id'"); - // Invalidate any password reset links - mysqli_query($mysqli, "UPDATE contacts SET contact_password_reset_token = NULL WHERE contact_archived_at IS NULL"); + // Raise the ticket + mysqli_query($mysqli,"INSERT INTO tickets SET ticket_prefix = '$config_ticket_prefix', ticket_number = $ticket_number, ticket_subject = '$subject', ticket_details = '$details', ticket_priority = '$priority', ticket_status = 'Open', ticket_created_at = NOW(), ticket_created_by = $created_id, ticket_contact_id = $contact_id, ticket_client_id = $client_id, ticket_asset_id = $asset_id, company_id = $company_id"); + $id = mysqli_insert_id($mysqli); - // PAST DUE INVOICE Notifications - //$invoiceAlertArray = [$config_invoice_overdue_reminders]; - $invoiceAlertArray = [30,60,90,120,150,180,210,240,270,300,330,360,390,420,450,480,510,540,570,590,620]; + // Logging + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Ticket', log_action = 'Create', log_description = 'System created scheduled $frequency ticket - $subject', log_created_at = NOW(), log_client_id = $client_id, company_id = $company_id, log_user_id = $created_id"); - foreach($invoiceAlertArray as $day){ + // E-mail client + if (!empty($config_smtp_host)) { - $sql = mysqli_query($mysqli,"SELECT * FROM invoices + // Get contact/ticket/company details + $sql = mysqli_query($mysqli,"SELECT contact_name, contact_email, ticket_prefix, ticket_number, ticket_subject, company_phone FROM tickets + LEFT JOIN clients ON ticket_client_id = client_id + LEFT JOIN contacts ON ticket_contact_id = contact_id + LEFT JOIN companies ON tickets.company_id = companies.company_id + WHERE ticket_id = $id AND tickets.company_id = $company_id"); + $row = mysqli_fetch_array($sql); + + $contact_name = $row['contact_name']; + $contact_email = $row['contact_email']; + $ticket_prefix = $row['ticket_prefix']; + $ticket_number = $row['ticket_number']; + $ticket_subject = $row['ticket_subject']; + $company_phone = formatPhoneNumber($row['company_phone']); + + // Verify contact email is valid + if(filter_var($contact_email, FILTER_VALIDATE_EMAIL)){ + + $subject = "Ticket created - [$ticket_prefix$ticket_number] - $ticket_subject (scheduled)"; + $body = "#--itflow--#

Hello, $contact_name

A ticket regarding \"$ticket_subject\" has been automatically created for you.

--------------------------------
$details--------------------------------

Ticket: $ticket_prefix$ticket_number
Subject: $ticket_subject
Status: Open
Portal: https://$config_base_url/portal/ticket.php?id=$id

~
$company_name
Support Department
$config_ticket_from_email
$company_phone"; + + $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port, + $config_ticket_from_email, $config_ticket_from_name, + $contact_email, $contact_name, + $subject, $body); + + if ($mail !== true) { + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email', notification_timestamp = NOW(), company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject. $mail', company_id = $company_id"); + } + + } + } + + // Set the next run date + if($frequency == "weekly"){ + // Note: We seemingly have to initialize a new datetime for each loop to avoid stacking the dates + $now = new DateTime(); + $next_run = date_add($now, date_interval_create_from_date_string('1 week')); + } + elseif($frequency == "monthly"){ + $now = new DateTime(); + $next_run = date_add($now, date_interval_create_from_date_string('1 month')); + } + elseif($frequency == "quarterly"){ + $now = new DateTime(); + $next_run = date_add($now, date_interval_create_from_date_string('3 months')); + } + elseif($frequency == "biannually"){ + $now = new DateTime(); + $next_run = date_add($now, date_interval_create_from_date_string('6 months')); + } + elseif($frequency == "annually"){ + $now = new DateTime(); + $next_run = date_add($now, date_interval_create_from_date_string('12 months')); + } + + // Update the run date + $next_run = $next_run->format('Y-m-d'); + $a = mysqli_query($mysqli, "UPDATE scheduled_tickets SET scheduled_ticket_next_run = '$next_run' WHERE scheduled_ticket_id = '$schedule_id'"); + + } + } + + // Clean-up ticket views table used for collision detection + mysqli_query($mysqli, "TRUNCATE TABLE ticket_views"); + + // Clean-up shared items that have been used + mysqli_query($mysqli, "DELETE FROM shared_items WHERE item_views = item_view_limit"); + + // Clean-up shared items that have expired + mysqli_query($mysqli, "DELETE FROM shared_items WHERE item_expire_at < NOW()"); + + // Invalidate any password reset links + mysqli_query($mysqli, "UPDATE contacts SET contact_password_reset_token = NULL WHERE contact_archived_at IS NULL"); + + // PAST DUE INVOICE Notifications + //$invoiceAlertArray = [$config_invoice_overdue_reminders]; + $invoiceAlertArray = [30,60,90,120,150,180,210,240,270,300,330,360,390,420,450,480,510,540,570,590,620]; + + foreach($invoiceAlertArray as $day){ + + $sql = mysqli_query($mysqli,"SELECT * FROM invoices LEFT JOIN clients ON invoice_client_id = client_id LEFT JOIN contacts ON contact_id = primary_contact WHERE invoice_status NOT LIKE 'Draft' @@ -212,159 +252,159 @@ while($row = mysqli_fetch_array($sql_companies)){ AND DATE_ADD(invoice_due, INTERVAL $day DAY) = CURDATE() AND invoices.company_id = $company_id ORDER BY invoice_number DESC" - ); + ); - while($row = mysqli_fetch_array($sql)){ - $invoice_id = $row['invoice_id']; - $invoice_prefix = $row['invoice_prefix']; - $invoice_number = $row['invoice_number']; - $invoice_status = $row['invoice_status']; - $invoice_date = $row['invoice_date']; - $invoice_due = $row['invoice_due']; - $invoice_url_key = $row['invoice_url_key']; - $invoice_amount = $row['invoice_amount']; - $invoice_currency_code = $row['invoice_currency_code']; - $client_id = $row['client_id']; - $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); - $contact_name = $row['contact_name']; - $contact_email = $row['contact_email']; + while($row = mysqli_fetch_array($sql)){ + $invoice_id = $row['invoice_id']; + $invoice_prefix = $row['invoice_prefix']; + $invoice_number = $row['invoice_number']; + $invoice_status = $row['invoice_status']; + $invoice_date = $row['invoice_date']; + $invoice_due = $row['invoice_due']; + $invoice_url_key = $row['invoice_url_key']; + $invoice_amount = $row['invoice_amount']; + $invoice_currency_code = $row['invoice_currency_code']; + $client_id = $row['client_id']; + $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); + $contact_name = $row['contact_name']; + $contact_email = $row['contact_email']; - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Invoice Overdue', notification = 'Invoice $invoice_prefix$invoice_number for $client_name in the amount of $invoice_amount is overdue by $day days', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Invoice Overdue', notification = 'Invoice $invoice_prefix$invoice_number for $client_name in the amount of $invoice_amount is overdue by $day days', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); - $subject = "Overdue Invoice $invoice_prefix$invoice_number"; - $body = "Hello $contact_name,

According to our records, we have not received payment for invoice $invoice_prefix$invoice_number. Please submit your payment as soon as possible. If you have any questions please contact us at $company_phone. + $subject = "Overdue Invoice $invoice_prefix$invoice_number"; + $body = "Hello $contact_name,

According to our records, we have not received payment for invoice $invoice_prefix$invoice_number. Please submit your payment as soon as possible. If you have any questions please contact us at $company_phone.

Please view the details of the invoice below.

Invoice: $invoice_prefix$invoice_number
Issue Date: $invoice_date
Total: " . numfmt_format_currency($currency_format, $invoice_amount, $invoice_currency_code) . "
Due Date: $invoice_due


To view your invoice click here


~
$company_name
Billing Department
$config_invoice_from_email
$company_phone"; - $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port, - $config_invoice_from_email, $config_invoice_from_name, - $contact_email, $contact_name, - $subject, $body); + $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port, + $config_invoice_from_email, $config_invoice_from_name, + $contact_email, $contact_name, + $subject, $body); - if ($mail === true) { - mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Cron Emailed Overdue Invoice', history_created_at = NOW(), history_invoice_id = $invoice_id, company_id = $company_id"); - } else { - mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Cron Failed to send Overdue Invoice', history_created_at = NOW(), history_invoice_id = $invoice_id, company_id = $company_id"); + if ($mail === true) { + mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Cron Emailed Overdue Invoice', history_created_at = NOW(), history_invoice_id = $invoice_id, company_id = $company_id"); + } else { + mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Cron Failed to send Overdue Invoice', history_created_at = NOW(), history_invoice_id = $invoice_id, company_id = $company_id"); + + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email', notification_timestamp = NOW(), company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject. $mail', company_id = $company_id"); + } + + } - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email', notification_timestamp = NOW(), company_id = $company_id"); - mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject. $mail', company_id = $company_id"); } - } + //Send Recurring Invoices that match todays date and are active - } + //Loop through all recurring that match today's date and is active + $sql_recurring = mysqli_query($mysqli,"SELECT * FROM recurring LEFT JOIN clients ON client_id = recurring_client_id WHERE recurring_next_date = CURDATE() AND recurring_status = 1 AND recurring.company_id = $company_id"); - //Send Recurring Invoices that match todays date and are active - - //Loop through all recurring that match today's date and is active - $sql_recurring = mysqli_query($mysqli,"SELECT * FROM recurring LEFT JOIN clients ON client_id = recurring_client_id WHERE recurring_next_date = CURDATE() AND recurring_status = 1 AND recurring.company_id = $company_id"); - - while($row = mysqli_fetch_array($sql_recurring)){ - $recurring_id = $row['recurring_id']; - $recurring_scope = $row['recurring_scope']; - $recurring_frequency = $row['recurring_frequency']; - $recurring_status = $row['recurring_status']; - $recurring_last_sent = $row['recurring_last_sent']; - $recurring_next_date = $row['recurring_next_date']; - $recurring_amount = $row['recurring_amount']; - $recurring_currency_code = $row['recurring_currency_code']; - $recurring_note = mysqli_real_escape_string($mysqli,$row['recurring_note']); //Escape SQL - $category_id = $row['recurring_category_id']; - $client_id = $row['recurring_client_id']; - $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); //Escape SQL just in case a name is like Safran's etc - $client_net_terms = $row['client_net_terms']; + while($row = mysqli_fetch_array($sql_recurring)){ + $recurring_id = $row['recurring_id']; + $recurring_scope = $row['recurring_scope']; + $recurring_frequency = $row['recurring_frequency']; + $recurring_status = $row['recurring_status']; + $recurring_last_sent = $row['recurring_last_sent']; + $recurring_next_date = $row['recurring_next_date']; + $recurring_amount = $row['recurring_amount']; + $recurring_currency_code = $row['recurring_currency_code']; + $recurring_note = mysqli_real_escape_string($mysqli,$row['recurring_note']); //Escape SQL + $category_id = $row['recurring_category_id']; + $client_id = $row['recurring_client_id']; + $client_name = mysqli_real_escape_string($mysqli,$row['client_name']); //Escape SQL just in case a name is like Safran's etc + $client_net_terms = $row['client_net_terms']; - //Get the last Invoice Number and add 1 for the new invoice number - $sql_invoice_number = mysqli_query($mysqli,"SELECT * FROM settings WHERE company_id = $company_id"); - $row = mysqli_fetch_array($sql_invoice_number); - $config_invoice_next_number = $row['config_invoice_next_number']; + //Get the last Invoice Number and add 1 for the new invoice number + $sql_invoice_number = mysqli_query($mysqli,"SELECT * FROM settings WHERE company_id = $company_id"); + $row = mysqli_fetch_array($sql_invoice_number); + $config_invoice_next_number = $row['config_invoice_next_number']; - $new_invoice_number = $config_invoice_next_number; - $new_config_invoice_next_number = $config_invoice_next_number + 1; - mysqli_query($mysqli,"UPDATE settings SET config_invoice_next_number = $new_config_invoice_next_number WHERE company_id = $company_id"); + $new_invoice_number = $config_invoice_next_number; + $new_config_invoice_next_number = $config_invoice_next_number + 1; + mysqli_query($mysqli,"UPDATE settings SET config_invoice_next_number = $new_config_invoice_next_number WHERE company_id = $company_id"); - //Generate a unique URL key for clients to access - $url_key = bin2hex(random_bytes(78)); + //Generate a unique URL key for clients to access + $url_key = bin2hex(random_bytes(78)); - mysqli_query($mysqli,"INSERT INTO invoices SET invoice_prefix = '$config_invoice_prefix', invoice_number = $new_invoice_number, invoice_scope = '$recurring_scope', invoice_date = CURDATE(), invoice_due = DATE_ADD(CURDATE(), INTERVAL $client_net_terms day), invoice_amount = '$recurring_amount', invoice_currency_code = '$recurring_currency_code', invoice_note = '$recurring_note', invoice_category_id = $category_id, invoice_status = 'Sent', invoice_url_key = '$url_key', invoice_created_at = NOW(), invoice_client_id = $client_id, company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO invoices SET invoice_prefix = '$config_invoice_prefix', invoice_number = $new_invoice_number, invoice_scope = '$recurring_scope', invoice_date = CURDATE(), invoice_due = DATE_ADD(CURDATE(), INTERVAL $client_net_terms day), invoice_amount = '$recurring_amount', invoice_currency_code = '$recurring_currency_code', invoice_note = '$recurring_note', invoice_category_id = $category_id, invoice_status = 'Sent', invoice_url_key = '$url_key', invoice_created_at = NOW(), invoice_client_id = $client_id, company_id = $company_id"); - $new_invoice_id = mysqli_insert_id($mysqli); + $new_invoice_id = mysqli_insert_id($mysqli); - //Copy Items from original recurring invoice to new invoice - $sql_invoice_items = mysqli_query($mysqli,"SELECT * FROM invoice_items WHERE item_recurring_id = $recurring_id ORDER BY item_id ASC"); + //Copy Items from original recurring invoice to new invoice + $sql_invoice_items = mysqli_query($mysqli,"SELECT * FROM invoice_items WHERE item_recurring_id = $recurring_id ORDER BY item_id ASC"); - while($row = mysqli_fetch_array($sql_invoice_items)){ - $item_id = $row['item_id']; - $item_name = mysqli_real_escape_string($mysqli,$row['item_name']); //SQL Escape incase of , - $item_description = mysqli_real_escape_string($mysqli,$row['item_description']); //SQL Escape incase of , - $item_quantity = $row['item_quantity']; - $item_price = $row['item_price']; - $item_subtotal = $row['item_subtotal']; - $item_tax = $row['item_tax']; - $item_total = $row['item_total']; - $tax_id = $row['item_tax_id']; + while($row = mysqli_fetch_array($sql_invoice_items)){ + $item_id = $row['item_id']; + $item_name = mysqli_real_escape_string($mysqli,$row['item_name']); //SQL Escape incase of , + $item_description = mysqli_real_escape_string($mysqli,$row['item_description']); //SQL Escape incase of , + $item_quantity = $row['item_quantity']; + $item_price = $row['item_price']; + $item_subtotal = $row['item_subtotal']; + $item_tax = $row['item_tax']; + $item_total = $row['item_total']; + $tax_id = $row['item_tax_id']; - //Insert Items into New Invoice - mysqli_query($mysqli,"INSERT INTO invoice_items SET item_name = '$item_name', item_description = '$item_description', item_quantity = '$item_quantity', item_price = '$item_price', item_subtotal = '$item_subtotal', item_tax = '$item_tax', item_total = '$item_total', item_created_at = NOW(), item_tax_id = $tax_id, item_invoice_id = $new_invoice_id, company_id = $company_id"); + //Insert Items into New Invoice + mysqli_query($mysqli,"INSERT INTO invoice_items SET item_name = '$item_name', item_description = '$item_description', item_quantity = '$item_quantity', item_price = '$item_price', item_subtotal = '$item_subtotal', item_tax = '$item_tax', item_total = '$item_total', item_created_at = NOW(), item_tax_id = $tax_id, item_invoice_id = $new_invoice_id, company_id = $company_id"); - } + } - mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Invoice Generated from Recurring!', history_created_at = NOW(), history_invoice_id = $new_invoice_id, company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Invoice Generated from Recurring!', history_created_at = NOW(), history_invoice_id = $new_invoice_id, company_id = $company_id"); - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Recurring Sent', notification = 'Recurring Invoice $config_invoice_prefix$new_invoice_number for $client_name Sent', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Recurring Sent', notification = 'Recurring Invoice $config_invoice_prefix$new_invoice_number for $client_name Sent', notification_timestamp = NOW(), notification_client_id = $client_id, company_id = $company_id"); - //Update recurring dates + //Update recurring dates - mysqli_query($mysqli,"UPDATE recurring SET recurring_last_sent = CURDATE(), recurring_next_date = DATE_ADD(CURDATE(), INTERVAL 1 $recurring_frequency), recurring_updated_at = NOW() WHERE recurring_id = $recurring_id"); + mysqli_query($mysqli,"UPDATE recurring SET recurring_last_sent = CURDATE(), recurring_next_date = DATE_ADD(CURDATE(), INTERVAL 1 $recurring_frequency), recurring_updated_at = NOW() WHERE recurring_id = $recurring_id"); - if($config_recurring_auto_send_invoice == 1){ - $sql = mysqli_query($mysqli,"SELECT * FROM invoices + if($config_recurring_auto_send_invoice == 1){ + $sql = mysqli_query($mysqli,"SELECT * FROM invoices LEFT JOIN clients ON invoice_client_id = client_id LEFT JOIN contacts ON contact_id = primary_contact WHERE invoice_id = $new_invoice_id AND invoices.company_id = $company_id" - ); + ); - $row = mysqli_fetch_array($sql); - $invoice_prefix = $row['invoice_prefix']; - $invoice_number = $row['invoice_number']; - $invoice_date = $row['invoice_date']; - $invoice_due = $row['invoice_due']; - $invoice_amount = $row['invoice_amount']; - $invoice_url_key = $row['invoice_url_key']; - $client_id = $row['client_id']; - $client_name = $row['client_name']; - $contact_name = $row['contact_name']; - $contact_email = $row['contact_email']; + $row = mysqli_fetch_array($sql); + $invoice_prefix = $row['invoice_prefix']; + $invoice_number = $row['invoice_number']; + $invoice_date = $row['invoice_date']; + $invoice_due = $row['invoice_due']; + $invoice_amount = $row['invoice_amount']; + $invoice_url_key = $row['invoice_url_key']; + $client_id = $row['client_id']; + $client_name = $row['client_name']; + $contact_name = $row['contact_name']; + $contact_email = $row['contact_email']; - $subject = "Invoice $invoice_prefix$invoice_number"; - $body = "Hello $contact_name,

Please view the details of the invoice below.

Invoice: $invoice_prefix$invoice_number
Issue Date: $invoice_date
Total: " . numfmt_format_currency($currency_format, $invoice_amount, $recurring_currency_code) . "
Due Date: $invoice_due


To view your invoice click here


~
$company_name
Billing Department
$config_invoice_from_email
$company_phone"; + $subject = "Invoice $invoice_prefix$invoice_number"; + $body = "Hello $contact_name,

Please view the details of the invoice below.

Invoice: $invoice_prefix$invoice_number
Issue Date: $invoice_date
Total: " . numfmt_format_currency($currency_format, $invoice_amount, $recurring_currency_code) . "
Due Date: $invoice_due


To view your invoice click here


~
$company_name
Billing Department
$config_invoice_from_email
$company_phone"; - $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port, - $config_invoice_from_email, $config_invoice_from_name, - $contact_email, $contact_name, - $subject, $body); + $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port, + $config_invoice_from_email, $config_invoice_from_name, + $contact_email, $contact_name, + $subject, $body); - if ($mail === true) { - mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Cron Emailed Invoice!', history_created_at = NOW(), history_invoice_id = $new_invoice_id, company_id = $company_id"); - mysqli_query($mysqli,"UPDATE invoices SET invoice_status = 'Sent', invoice_updated_at = NOW(), invoice_client_id = $client_id WHERE invoice_id = $new_invoice_id"); + if ($mail === true) { + mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Sent', history_description = 'Cron Emailed Invoice!', history_created_at = NOW(), history_invoice_id = $new_invoice_id, company_id = $company_id"); + mysqli_query($mysqli,"UPDATE invoices SET invoice_status = 'Sent', invoice_updated_at = NOW(), invoice_client_id = $client_id WHERE invoice_id = $new_invoice_id"); - } else { - mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Draft', history_description = 'Cron Failed to send Invoice!', history_created_at = NOW(), history_invoice_id = $new_invoice_id, company_id = $company_id"); + } else { + mysqli_query($mysqli,"INSERT INTO history SET history_status = 'Draft', history_description = 'Cron Failed to send Invoice!', history_created_at = NOW(), history_invoice_id = $new_invoice_id, company_id = $company_id"); - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email', notification_timestamp = NOW(), company_id = $company_id"); - mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject. $mail', company_id = $company_id"); - } + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Mail', notification = 'Failed to send email to $contact_email', notification_timestamp = NOW(), company_id = $company_id"); + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Mail', log_action = 'Error', log_description = 'Failed to send email to $contact_email regarding $subject. $mail', company_id = $company_id"); + } - } //End if Autosend is on - } //End Recurring Invoices Loop - //Send Alert to inform Cron was run - mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Cron', notification = 'Cron.php successfully executed', notification_timestamp = NOW(), company_id = $company_id"); - //Logging - mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Cron', log_action = 'Ended', log_description = 'Cron executed successfully for $company_name', company_id = $company_id"); - } //End Cron Check + } //End if Autosend is on + } //End Recurring Invoices Loop + //Send Alert to inform Cron was run + mysqli_query($mysqli,"INSERT INTO notifications SET notification_type = 'Cron', notification = 'Cron.php successfully executed', notification_timestamp = NOW(), company_id = $company_id"); + //Logging + mysqli_query($mysqli,"INSERT INTO logs SET log_type = 'Cron', log_action = 'Ended', log_description = 'Cron executed successfully for $company_name', company_id = $company_id"); + } //End Cron Check } //End Company Loop through From 6d26b07d70009dccf899760acf7090261d4e079c Mon Sep 17 00:00:00 2001 From: Marcus Hill Date: Sat, 21 Jan 2023 12:30:33 +0000 Subject: [PATCH 02/12] Fix the ticket notification email subject to just show the ticket subject in the message body for new tickets --- post.php | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/post.php b/post.php index b95b627a..5a6f39d3 100644 --- a/post.php +++ b/post.php @@ -5921,7 +5921,7 @@ if(isset($_POST['add_ticket'])){ if (!empty($config_smtp_host)) { // Get contact/ticket details - $sql = mysqli_query($mysqli,"SELECT contact_name, contact_email, ticket_prefix, ticket_number, company_phone FROM tickets + $sql = mysqli_query($mysqli,"SELECT contact_name, contact_email, ticket_prefix, ticket_number, ticket_subject, company_phone FROM tickets LEFT JOIN clients ON ticket_client_id = client_id LEFT JOIN contacts ON ticket_contact_id = contact_id LEFT JOIN companies ON tickets.company_id = companies.company_id @@ -5932,13 +5932,14 @@ if(isset($_POST['add_ticket'])){ $contact_email = $row['contact_email']; $ticket_prefix = $row['ticket_prefix']; $ticket_number = $row['ticket_number']; + $ticket_subject = $row['ticket_subject']; $company_phone = formatPhoneNumber($row['company_phone']); // Verify contact email is valid if(filter_var($contact_email, FILTER_VALIDATE_EMAIL)){ - $subject = "Ticket created - [$ticket_prefix$ticket_number] - $subject"; - $body = "#--itflow--#

Hello, $contact_name

A ticket regarding \"$subject\" has been created for you.

--------------------------------
$details--------------------------------

Ticket: $ticket_prefix$ticket_number
Subject: $subject
Status: Open
Portal: https://$config_base_url/portal/ticket.php?id=$id

~
$session_company_name
Support Department
$config_ticket_from_email
$company_phone"; + $subject = "Ticket created - [$ticket_prefix$ticket_number] - $ticket_subject"; + $body = "#--itflow--#

Hello, $contact_name

A ticket regarding \"$ticket_subject\" has been created for you.

--------------------------------
$details--------------------------------

Ticket: $ticket_prefix$ticket_number
Subject: $ticket_subject
Status: Open
Portal: https://$config_base_url/portal/ticket.php?id=$id

~
$session_company_name
Support Department
$config_ticket_from_email
$company_phone"; $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port, $config_ticket_from_email, $config_ticket_from_name, From b9b0440186ea13687c5af0ed4a7dece37e151d8a Mon Sep 17 00:00:00 2001 From: Marcus Hill Date: Sat, 21 Jan 2023 13:25:16 +0000 Subject: [PATCH 03/12] - Add email notification to agents if their 2FA code is entered incorrectly (this may be a sign of account compromise) - Tidy login code flow so that the "logged" session variable only has to be set in one place, rather than in two (both for 2fa and non-2fa logins) --- login.php | 249 +++++++++++++++++++++++++++++++----------------------- 1 file changed, 143 insertions(+), 106 deletions(-) diff --git a/login.php b/login.php index 0e88297b..4ac43edd 100644 --- a/login.php +++ b/login.php @@ -12,6 +12,20 @@ include("functions.php"); $ip = strip_tags(mysqli_real_escape_string($mysqli,get_ip())); $user_agent = strip_tags(mysqli_real_escape_string($mysqli,$_SERVER['HTTP_USER_AGENT'])); +// Query Settings for "default" company (as companies are being removed shortly) +$sql_settings = mysqli_query($mysqli,"SELECT * FROM settings WHERE company_id = 1"); +$row = mysqli_fetch_array($sql_settings); + +// Mail +$config_smtp_host = $row['config_smtp_host']; +$config_smtp_port = $row['config_smtp_port']; +$config_smtp_encryption = $row['config_smtp_encryption']; +$config_smtp_username = $row['config_smtp_username']; +$config_smtp_password = $row['config_smtp_password']; +$config_mail_from_email = $row['config_mail_from_email']; +$config_mail_from_name = $row['config_mail_from_name']; + + // HTTP-Only cookies ini_set("session.cookie_httponly", True); @@ -48,47 +62,64 @@ if (isset($_POST['login'])) { // Passed login brute force check $email = strip_tags(mysqli_real_escape_string($mysqli, $_POST['email'])); $password = $_POST['password']; + + $current_code = 0; // Default value if (isset($_POST['current_code'])) { $current_code = strip_tags(mysqli_real_escape_string($mysqli, $_POST['current_code'])); } $row = mysqli_fetch_assoc(mysqli_query($mysqli, "SELECT * FROM users LEFT JOIN user_settings on users.user_id = user_settings.user_id WHERE user_email = '$email' AND user_archived_at IS NULL AND user_status = 1")); + + // Check password if ($row && password_verify($password, $row['user_password'])) { - // User variables - $token = $row['user_token']; + // User password correct (partial login) + + // Set temporary user variables $user_name = strip_tags(mysqli_real_escape_string($mysqli, $row['user_name'])); $user_id = $row['user_id']; + $user_email = $row['user_email']; + $token = $row['user_token']; - // Session info - $_SESSION['user_id'] = $user_id; - $_SESSION['user_name'] = $user_name; - $_SESSION['user_role'] = $row['user_role']; - $_SESSION['csrf_token'] = bin2hex(random_bytes(78)); + // Checking for user 2FA + require_once("rfc6238.php"); + if (empty($token) || TokenAuth6238::verify($token, $current_code)) { - // Setup encryption session key - if (isset($row['user_specific_encryption_ciphertext']) && $row['user_role'] > 1) { - $user_encryption_ciphertext = $row['user_specific_encryption_ciphertext']; - $site_encryption_master_key = decryptUserSpecificKey($user_encryption_ciphertext, $password); - generateUserSessionKey($site_encryption_master_key); + // FULL LOGIN SUCCESS - 2FA not configured or was successful - // Setup extension - if (isset($row['user_extension_key']) && !empty($row['user_extension_key'])) { - // Extension cookie - // Note: Browsers don't accept cookies with SameSite None if they are not HTTPS. - setcookie("user_extension_key", "$row[user_extension_key]", ['path' => '/', 'secure' => true, 'httponly' => true, 'samesite' => 'None']); - - // Set PHP session in DB so we can access the session encryption data (above) - $user_php_session = session_id(); - mysqli_query($mysqli, "UPDATE users SET user_php_session = '$user_php_session' WHERE user_id = '$user_id'"); + // Determine whether 2FA was used (for logs) + $extended_log = ''; // Default value + if ($current_code !== 0 ) { + $extended_log = 'with 2FA'; } - } - if (empty($token)) { - // Full Login successful + // Logging successful login + mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Login', log_action = 'Success', log_description = '$user_name successfully logged in $extended_log', log_ip = '$ip', log_user_agent = '$user_agent', log_user_id = $user_id"); + // Session info + $_SESSION['user_id'] = $user_id; + $_SESSION['user_name'] = $user_name; + $_SESSION['user_role'] = $row['user_role']; + $_SESSION['csrf_token'] = bin2hex(random_bytes(78)); $_SESSION['logged'] = TRUE; - mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Login', log_action = 'Success', log_description = '$user_name successfully logged in', log_ip = '$ip', log_user_agent = '$user_agent', log_user_id = $user_id"); + + // Setup encryption session key + if (isset($row['user_specific_encryption_ciphertext']) && $row['user_role'] > 1) { + $user_encryption_ciphertext = $row['user_specific_encryption_ciphertext']; + $site_encryption_master_key = decryptUserSpecificKey($user_encryption_ciphertext, $password); + generateUserSessionKey($site_encryption_master_key); + + // Setup extension + if (isset($row['user_extension_key']) && !empty($row['user_extension_key'])) { + // Extension cookie + // Note: Browsers don't accept cookies with SameSite None if they are not HTTPS. + setcookie("user_extension_key", "$row[user_extension_key]", ['path' => '/', 'secure' => true, 'httponly' => true, 'samesite' => 'None']); + + // Set PHP session in DB so we can access the session encryption data (above) + $user_php_session = session_id(); + mysqli_query($mysqli, "UPDATE users SET user_php_session = '$user_php_session' WHERE user_id = '$user_id'"); + } + } // Show start page/dashboard depending on role if ($row['user_role'] == 2) { @@ -97,53 +128,59 @@ if (isset($_POST['login'])) { header("Location: dashboard_financial.php"); } + } else { - // Prompt for MFA - $token_field = "
- -
-
- -
-
-
"; + // MFA is configured and needs to be confirmed, or was unsuccessful - require_once("rfc6238.php"); + // HTML code for the token input field + $token_field = " +
+ +
+
+ +
+
+
"; - if (TokenAuth6238::verify($token, $current_code)) { - // Full login (with MFA) successful - $_SESSION['logged'] = TRUE; - mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Login 2FA', log_action = 'Success', log_description = '$user_name successfully logged in using 2FA', log_ip = '$ip', log_user_agent = '$user_agent', log_created_at = NOW(), log_user_id = $user_id"); + // Log/notify if MFA was unsuccessful + if ($current_code !== 0) { - // Show start page/dashboard depending on role - if ($row['user_role'] == 2) { - header("Location: dashboard_technical.php"); - } else { - header("Location: dashboard_financial.php"); - } - - } else { + // Logging mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Login', log_action = '2FA Failed', log_description = '$user_name failed 2FA', log_ip = '$ip', log_user_agent = '$user_agent', log_created_at = NOW(), log_user_id = $user_id"); + // Email the tech to advise their credentials may be compromised + if (!empty($config_smtp_host)) { + $subject = "Important: ITFlow failed 2FA login attempt for $user_name"; + $body = "Hi $user_name,

A recent login to ITFlow was unsuccessful due to an incorrect 2FA code. If you did not attempt this login, your credentials may be compromised.

Thanks,
ITFlow"; + + $mail = sendSingleEmail($config_smtp_host, $config_smtp_username, $config_smtp_password, $config_smtp_encryption, $config_smtp_port, + $config_mail_from_email, $config_mail_from_name, + $user_email, $user_name, + $subject, $body); + } + + // HTML feedback for incorrect 2FA code $response = " -
- Please Enter 2FA Key! - -
- "; +
+ Please Enter 2FA Key! + +
"; } } } else { + + // Password incorrect or user doesn't exist - show generic error + mysqli_query($mysqli, "INSERT INTO logs SET log_type = 'Login', log_action = 'Failed', log_description = 'Failed login attempt using $email', log_ip = '$ip', log_user_agent = '$user_agent', log_created_at = NOW()"); $response = " -
- Incorrect username or password. - -
- "; +
+ Incorrect username or password. + +
"; } } } @@ -153,60 +190,60 @@ if (isset($_POST['login'])) { - - - <?php echo $config_app_name; ?> | Login - - - + + + <?php echo $config_app_name; ?> | Login + + + - - - - - - + + + + + +