diff --git a/admin/api_keys.php b/admin/api_keys.php index 387ae257..009f8cce 100644 --- a/admin/api_keys.php +++ b/admin/api_keys.php @@ -9,7 +9,7 @@ require_once "includes/inc_all_admin.php"; $sql = mysqli_query( $mysqli, "SELECT SQL_CALC_FOUND_ROWS * FROM api_keys - LEFT JOIN clients on api_keys.api_key_client_id = clients.client_id + LEFT JOIN users on api_keys.api_key_user_id = users.user_id WHERE (api_key_name LIKE '%$q%') ORDER BY $sort $order LIMIT $record_from, $record_to" ); @@ -80,8 +80,8 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); - - Client + + User @@ -115,11 +115,7 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); $api_key_expire = $api_key_expire . " (Expired)"; } - if ($row['api_key_client_id'] == 0) { - $api_key_client = "All Clients"; - } else { - $api_key_client = escapeHtml($row['client_name']); - } + $api_key_user = !empty($row['user_name']) ? escapeHtml($row['user_name']) : "None"; ?> @@ -129,7 +125,7 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); - + @@ -139,6 +135,9 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); diff --git a/admin/modals/api/api_key_edit.php b/admin/modals/api/api_key_edit.php new file mode 100644 index 00000000..d94daa47 --- /dev/null +++ b/admin/modals/api/api_key_edit.php @@ -0,0 +1,79 @@ + + + +
+ + +
+ +$name created"); @@ -30,6 +30,25 @@ if (isset($_POST['add_api_key'])) { } +if (isset($_POST['edit_api_key'])) { + + validateCSRFToken(); + + $api_key_id = intval($_POST['api_key_id']); + $name = escapeSql($_POST['name']); + $expire = escapeSql($_POST['expire']); + $user_id = intval($_POST['run_as_user']); + + mysqli_query($mysqli,"UPDATE api_keys SET api_key_name = '$name', api_key_expire = '$expire', api_key_user_id = $user_id WHERE api_key_id = $api_key_id"); + + logAudit("API Key", "Edit", "$session_name edited API key $name", 0, $api_key_id); + + flashAlert("API Key $name updated"); + + redirect(); + +} + if (isset($_GET['revoke_api_key'])) { validateCSRFToken(); @@ -37,13 +56,12 @@ if (isset($_GET['revoke_api_key'])) { $api_key_id = intval($_GET['revoke_api_key']); // Get API Key Name - $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name, api_key_client_id FROM api_keys WHERE api_key_id = $api_key_id")); + $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name FROM api_keys WHERE api_key_id = $api_key_id")); $api_key_name = escapeSql($row['api_key_name']); - $client_id = intval($row['api_key_client_id']); mysqli_query($mysqli,"UPDATE api_keys SET api_key_expire = NOW() WHERE api_key_id = $api_key_id"); - logAudit("API Key", "Revoke", "$session_name revoked API key $name", $client_id); + logAudit("API Key", "Revoke", "$session_name revoked API key $name", 0); flashAlert("API Key $name revoked", 'error'); @@ -58,13 +76,12 @@ if (isset($_GET['delete_api_key'])) { $api_key_id = intval($_GET['delete_api_key']); // Get API Key Name - $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name, api_key_client_id FROM api_keys WHERE api_key_id = $api_key_id")); + $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name FROM api_keys WHERE api_key_id = $api_key_id")); $api_key_name = escapeSql($row['api_key_name']); - $client_id = intval($row['api_key_client_id']); mysqli_query($mysqli,"DELETE FROM api_keys WHERE api_key_id = $api_key_id"); - logAudit("API Key", "Delete", "$session_name deleted API key $name", $client_id); + logAudit("API Key", "Delete", "$session_name deleted API key $name", 0); flashAlert("API Key $name deleted", 'error'); @@ -86,13 +103,12 @@ if (isset($_POST['bulk_delete_api_keys'])) { $api_key_id = intval($api_key_id); // Get API Key Name - $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name, api_key_client_id FROM api_keys WHERE api_key_id = $api_key_id")); + $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name FROM api_keys WHERE api_key_id = $api_key_id")); $api_key_name = escapeSql($row['api_key_name']); - $client_id = intval($row['api_key_client_id']); mysqli_query($mysqli, "DELETE FROM api_keys WHERE api_key_id = $api_key_id"); - logAudit("API Key", "Delete", "$session_name deleted API key $name", $client_id); + logAudit("API Key", "Delete", "$session_name deleted API key $name", 0); } diff --git a/agent/post/client.php b/agent/post/client.php index 00a0050f..1a43d33f 100644 --- a/agent/post/client.php +++ b/agent/post/client.php @@ -394,7 +394,6 @@ if (isset($_GET['delete_client'])) { // Delete Associations // Delete Client Data - mysqli_query($mysqli, "DELETE FROM api_keys WHERE api_key_client_id = $client_id"); mysqli_query($mysqli, "DELETE FROM certificates WHERE certificate_client_id = $client_id"); mysqli_query($mysqli, "DELETE FROM documents WHERE document_client_id = $client_id"); diff --git a/api/v1/assets/read.php b/api/v1/assets/read.php index 1dc1d9d0..0ba013a7 100644 --- a/api/v1/assets/read.php +++ b/api/v1/assets/read.php @@ -8,41 +8,41 @@ require_once '../require_get_method.php'; // Asset via ID (single) if (isset($_GET['asset_id'])) { $id = intval($_GET['asset_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_id = $id AND asset_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_id = $id AND 1=1 " . apiClientScopeSql('asset_client_id') . ""); } elseif (isset($_GET['asset_type'])) { // Asset query via type $type = mysqli_real_escape_string($mysqli, ucfirst($_GET['asset_type'])); - $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_type = '$type' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_type = '$type' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); } elseif (isset($_GET['asset_name'])) { // Asset query via name $name = mysqli_real_escape_string($mysqli, $_GET['asset_name']); - $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_name = '$name' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_name = '$name' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); } elseif (isset($_GET['asset_serial'])) { // Asset query via serial $serial = mysqli_real_escape_string($mysqli, $_GET['asset_serial']); - $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_serial = '$serial' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_serial = '$serial' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); } elseif (isset($_GET['asset_mac'])) { // Asset query via mac $mac = mysqli_real_escape_string($mysqli, $_GET['asset_mac']); - $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE interface_mac = '$mac' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE interface_mac = '$mac' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); } elseif (isset($_GET['asset_uri'])) { // Asset query via uri $uri = mysqli_real_escape_string($mysqli, $_GET['asset_uri']); - $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri = '$uri' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri = '$uri' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); } elseif (isset($_GET['asset_uri_2'])) { // Asset query via uri2 $uri2 = mysqli_real_escape_string($mysqli, $_GET['asset_uri_2']); - $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri_2 = '$uri2' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri_2 = '$uri2' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); }else { // All assets (by client ID or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/certificates/read.php b/api/v1/certificates/read.php index 7d08673c..210680b3 100644 --- a/api/v1/certificates/read.php +++ b/api/v1/certificates/read.php @@ -8,16 +8,16 @@ require_once '../require_get_method.php'; // Specific certificate via ID (single) if (isset($_GET['certificate_id'])) { $id = intval($_GET['certificate_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_id = '$id' AND certificate_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_id = '$id' AND 1=1 " . apiClientScopeSql('certificate_client_id') . ""); } elseif (isset($_GET['certificate_name'])) { // Certificate by name $name = mysqli_real_escape_string($mysqli, $_GET['certificate_name']); - $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_name = '$name' AND certificate_client_id LIKE '$client_id' ORDER BY certificate_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_name = '$name' AND 1=1 " . apiClientScopeSql('certificate_client_id') . " ORDER BY certificate_id LIMIT $limit OFFSET $offset"); } else { // All certificates (by client ID or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_client_id LIKE '$client_id' ORDER BY certificate_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE 1=1 " . apiClientScopeSql('certificate_client_id') . " ORDER BY certificate_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/contacts/read.php b/api/v1/contacts/read.php index 114c11dd..730e88a2 100644 --- a/api/v1/contacts/read.php +++ b/api/v1/contacts/read.php @@ -8,21 +8,21 @@ require_once '../require_get_method.php'; // Specific contact via ID (single) if (isset($_GET['contact_id'])) { $id = intval($_GET['contact_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_id = '$id' AND contact_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_id = '$id' AND 1=1 " . apiClientScopeSql('contact_client_id') . ""); } elseif (isset($_GET['contact_email'])) { // Specific contact via email (single) $email = mysqli_real_escape_string($mysqli, $_GET['contact_email']); - $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_email = '$email' AND contact_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_email = '$email' AND 1=1 " . apiClientScopeSql('contact_client_id') . ""); } elseif (isset($_GET['contact_phone_or_mobile'])) { // Specific contact via phone number or mobile (single) $phone_or_mob = mysqli_real_escape_string($mysqli, $_GET['contact_phone_or_mobile']); - $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_mobile = '$phone_or_mob' OR contact_phone = '$phone_or_mob' AND contact_client_id LIKE '$client_id' LIMIT 1"); + $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_mobile = '$phone_or_mob' OR contact_phone = '$phone_or_mob' AND 1=1 " . apiClientScopeSql('contact_client_id') . " LIMIT 1"); } else { // All contacts (by client ID, or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_client_id LIKE '$client_id' ORDER BY contact_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE 1=1 " . apiClientScopeSql('contact_client_id') . " ORDER BY contact_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/credentials/read.php b/api/v1/credentials/read.php index 6d540af3..d6bd98c0 100644 --- a/api/v1/credentials/read.php +++ b/api/v1/credentials/read.php @@ -17,13 +17,13 @@ if (isset($_GET['credential_id']) && !empty($api_key_decrypt_password)) { $id = intval($_GET['credential_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE credential_id = '$id' AND credential_client_id LIKE '$client_id' LIMIT 1"); + $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE credential_id = '$id' AND 1=1 " . apiClientScopeSql('credential_client_id') . " LIMIT 1"); } elseif (!empty($api_key_decrypt_password)) { // All credentials ("credentials") - $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE credential_client_id LIKE '$client_id' ORDER BY credential_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE 1=1 " . apiClientScopeSql('credential_client_id') . " ORDER BY credential_id LIMIT $limit OFFSET $offset"); } diff --git a/api/v1/documents/read.php b/api/v1/documents/read.php index a376381b..5abe9d10 100644 --- a/api/v1/documents/read.php +++ b/api/v1/documents/read.php @@ -8,11 +8,11 @@ require_once '../require_get_method.php'; if (isset($_GET['document_id'])) { // Document via ID (single) $id = intval($_GET['document_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE document_id = '$id' AND document_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE document_id = '$id' AND 1=1 " . apiClientScopeSql('document_client_id') . ""); } else { // All documents (by client ID if given, or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE document_client_id LIKE '$client_id' ORDER BY document_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE 1=1 " . apiClientScopeSql('document_client_id') . " ORDER BY document_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/domains/read.php b/api/v1/domains/read.php index 6bbd96a2..e75b31c0 100644 --- a/api/v1/domains/read.php +++ b/api/v1/domains/read.php @@ -8,16 +8,16 @@ require_once '../require_get_method.php'; // Specific domain via ID (single) if (isset($_GET['domain_id'])) { $id = intval($_GET['domain_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_id = '$id' AND domain_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_id = '$id' AND 1=1 " . apiClientScopeSql('domain_client_id') . ""); } elseif (isset($_GET['domain_name'])) { // Domain by name $name = mysqli_real_escape_string($mysqli, $_GET['domain_name']); - $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_name = '$name' AND domain_client_id LIKE '$client_id' ORDER BY domain_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_name = '$name' AND 1=1 " . apiClientScopeSql('domain_client_id') . " ORDER BY domain_id LIMIT $limit OFFSET $offset"); } else { // All domains (by client ID or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_client_id LIKE '$client_id' ORDER BY domain_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE 1=1 " . apiClientScopeSql('domain_client_id') . " ORDER BY domain_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/enforce_api_rbac.php b/api/v1/enforce_api_rbac.php new file mode 100644 index 00000000..08811f0b --- /dev/null +++ b/api/v1/enforce_api_rbac.php @@ -0,0 +1,173 @@ + yes; explicit deny -> no; otherwise allowed if in the allow list or the +// user has no allow list (unrestricted). +function apiUserCanAccessClient($client_id) { + global $session_is_admin, $client_access_array, $client_deny_array; + $client_id = intval($client_id); + if ($session_is_admin) { + return true; + } + if (in_array($client_id, $client_deny_array, true)) { + return false; + } + return empty($client_access_array) || in_array($client_id, $client_access_array, true); +} + +// Client-scope SQL fragment for a read query, from the user's allow / deny lists. +// Admin and unrestricted users get no restriction. Column-aware, so it works on any +// resource. Returns " AND ..." or "" (used after a "WHERE 1=1" anchor). +function apiClientScopeSql($column) { + global $session_is_admin, $client_access_array, $client_deny_array; + if ($session_is_admin) { + return ''; + } + if (empty($client_access_array) && empty($client_deny_array)) { + return ''; // unrestricted user - all clients + } + $sql = ''; + if (!empty($client_access_array)) { + $sql .= " AND $column IN (" . implode(',', array_map('intval', $client_access_array)) . ")"; + } + if (!empty($client_deny_array)) { + $sql .= " AND $column NOT IN (" . implode(',', array_map('intval', $client_deny_array)) . ")"; + } + return $sql; +} + +// --- Every key must be tied to a user (legacy keys were removed in the 2.4.7 migration) --- +if (empty($api_key_user_id)) { + apiDeny("This API key is not tied to a user and is no longer valid. Please recreate it."); +} + +// --- 1) Load the linked user's session context (mirrors load_user_session.php) --- +$sql_api_user = mysqli_query($mysqli, + "SELECT users.user_id, user_name, user_type, user_status, user_archived_at, + user_role_id, role_is_admin + FROM users + LEFT JOIN user_roles ON user_role_id = role_id + WHERE users.user_id = $api_key_user_id + LIMIT 1"); + +$api_user = $sql_api_user ? mysqli_fetch_assoc($sql_api_user) : null; + +// Linked user must exist, be an active agent (user_type 1), and not be archived. +if (!$api_user + || intval($api_user['user_type']) !== 1 + || intval($api_user['user_status']) !== 1 + || $api_user['user_archived_at'] !== null) { + apiDeny("The user linked to this API key is inactive, archived, or invalid."); +} + +$session_user_id = intval($api_user['user_id']); +$session_name = escapeSql($api_user['user_name']); +$session_user_role = intval($api_user['user_role_id']); +$session_is_admin = isset($api_user['role_is_admin']) && $api_user['role_is_admin'] == 1; + +// Load the user's client allow / deny lists. +$client_access_array = []; +$client_deny_array = []; +$sql_api_perms = mysqli_query($mysqli, + "SELECT client_id, permission_type FROM user_client_permissions WHERE user_id = $session_user_id"); +while ($sql_api_perms && $prow = mysqli_fetch_assoc($sql_api_perms)) { + if ($prow['permission_type'] === 'deny') { + $client_deny_array[] = (int) $prow['client_id']; + } else { + $client_access_array[] = (int) $prow['client_id']; + } +} + +// --- 2) Enforce module + operation permission for the requested endpoint --- +// SCRIPT_NAME is the file actually executed, so rewrites can't spoof the resource. +$script = $_SERVER['SCRIPT_NAME'] ?? $_SERVER['PHP_SELF'] ?? ''; +$parts = array_values(array_filter(explode('/', $script), 'strlen')); +$n = count($parts); +$operation_file = $n >= 1 ? strtolower($parts[$n - 1]) : ''; +$resource = $n >= 2 ? strtolower($parts[$n - 2]) : ''; + +// API resource -> UI module (matches the mapping used across the app). +$resource_module = [ + 'assets' => 'module_support', + 'certificates' => 'module_support', + 'documents' => 'module_support', + 'domains' => 'module_support', + 'networks' => 'module_support', + 'software' => 'module_support', + 'tickets' => 'module_support', + 'technicians' => 'module_support', + 'clients' => 'module_client', + 'contacts' => 'module_client', + 'locations' => 'module_client', + 'vendors' => 'module_client', + 'invoices' => 'module_sales', + 'invoice_items' => 'module_sales', + 'quotes' => 'module_sales', + 'products' => 'module_sales', + 'expenses' => 'module_financial', + 'credentials' => 'module_credential', +]; + +// Operation -> required permission level (read = 1, create/update = 2, delete = 3). +$operation_level = [ + 'read.php' => 1, + 'create.php' => 2, + 'update.php' => 2, + 'delete.php' => 3, +]; + +if (!isset($resource_module[$resource])) { + // Fail closed: any endpoint that reaches the enforcer must map to a module. When + // you add a new API resource, add it to $resource_module above - that deliberate + // step is what brings it under RBAC, so nothing can slip through ungated. + apiDeny("This API resource is not mapped to a permission module."); +} + +$required_level = $operation_level[$operation_file] ?? 2; +if (lookupUserPermission($resource_module[$resource]) < $required_level) { + apiDeny("The user linked to this API key does not have permission for this action."); +} + +// --- 3) Target client for writes: taken from the request, validated against the user --- +// Reads ignore this and use apiClientScopeSql(). Create/update/delete act on a single +// client the caller names (client_id in the body/query); it must be within the user's +// access. Callers that omit it get $client_id = 0 (creates that require a client fail +// their own !empty($client_id) guard, which is the intended "must name a client"). +$client_id = intval($_POST['client_id'] ?? $_GET['client_id'] ?? 0); +$is_write = in_array($operation_file, ['create.php', 'update.php', 'delete.php'], true); +if ($is_write && !apiUserCanAccessClient($client_id)) { + // Writes act on a single client the caller names (client_id 0 = a global record). + // The user must be able to access it - this also blocks a restricted user from + // writing global (client_id 0) records, which their access does not include. + apiDeny("The user linked to this API key does not have access to the target client for this write."); +} +// Reads ignore $client_id entirely and are scoped by apiClientScopeSql(). diff --git a/api/v1/invoice_items/read.php b/api/v1/invoice_items/read.php index 9b6a435b..eca3276f 100644 --- a/api/v1/invoice_items/read.php +++ b/api/v1/invoice_items/read.php @@ -33,7 +33,7 @@ if (isset($_GET['item_id'])) { FROM invoice_items ii INNER JOIN invoices i ON i.invoice_id = ii.item_invoice_id WHERE ii.item_id = '$item_id' - AND i.invoice_client_id LIKE '$client_id' + AND i.1=1 " . apiClientScopeSql('invoice_client_id') . " LIMIT 1" ); } elseif (isset($_GET['invoice_id'])) { @@ -44,7 +44,7 @@ if (isset($_GET['item_id'])) { FROM invoice_items ii INNER JOIN invoices i ON i.invoice_id = ii.item_invoice_id WHERE ii.item_invoice_id = '$invoice_id' - AND i.invoice_client_id LIKE '$client_id' + AND i.1=1 " . apiClientScopeSql('invoice_client_id') . " ORDER BY ii.item_order ASC, ii.item_id ASC LIMIT $limit OFFSET $offset" ); diff --git a/api/v1/invoices/read.php b/api/v1/invoices/read.php index f9f40425..072489e6 100644 --- a/api/v1/invoices/read.php +++ b/api/v1/invoices/read.php @@ -8,11 +8,11 @@ require_once '../require_get_method.php'; if (isset($_GET['invoice_id'])) { // Invoice via ID (single) $id = intval($_GET['invoice_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE invoice_id = '$id' AND invoice_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE invoice_id = '$id' AND 1=1 " . apiClientScopeSql('invoice_client_id') . ""); } else { // All invoices (by client ID if given, or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE invoice_client_id LIKE '$client_id' ORDER BY invoice_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE 1=1 " . apiClientScopeSql('invoice_client_id') . " ORDER BY invoice_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/locations/read.php b/api/v1/locations/read.php index d26efd0d..516fad78 100644 --- a/api/v1/locations/read.php +++ b/api/v1/locations/read.php @@ -8,11 +8,11 @@ require_once '../require_get_method.php'; if (isset($_GET['location_id'])) { // Location via ID (single) $id = intval($_GET['location_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE location_id = '$id' AND location_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE location_id = '$id' AND 1=1 " . apiClientScopeSql('location_client_id') . ""); } else { // All locations (by client ID if given, or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE location_client_id LIKE '$client_id' ORDER BY location_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE 1=1 " . apiClientScopeSql('location_client_id') . " ORDER BY location_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/networks/read.php b/api/v1/networks/read.php index 168757ae..28b01756 100644 --- a/api/v1/networks/read.php +++ b/api/v1/networks/read.php @@ -8,16 +8,16 @@ require_once '../require_get_method.php'; // Specific network via ID (single) if (isset($_GET['network_id'])) { $id = intval($_GET['network_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_id = '$id' AND network_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_id = '$id' AND 1=1 " . apiClientScopeSql('network_client_id') . ""); } elseif (isset($_GET['network_name'])) { // Network by name $name = mysqli_real_escape_string($mysqli, $_GET['network_name']); - $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_name = '$name' AND network_client_id LIKE '$client_id' ORDER BY network_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_name = '$name' AND 1=1 " . apiClientScopeSql('network_client_id') . " ORDER BY network_id LIMIT $limit OFFSET $offset"); } else { // All networks (by client ID or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_client_id LIKE '$client_id' ORDER BY network_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE 1=1 " . apiClientScopeSql('network_client_id') . " ORDER BY network_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/quotes/read.php b/api/v1/quotes/read.php index 7331de49..194c7800 100644 --- a/api/v1/quotes/read.php +++ b/api/v1/quotes/read.php @@ -12,7 +12,7 @@ if (isset($_GET['quote_id'])) { } else { // All quotes (by client ID if given, or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM quotes WHERE quote_client_id LIKE '$client_id' ORDER BY quote_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM quotes WHERE 1=1 " . apiClientScopeSql('quote_client_id') . " ORDER BY quote_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/software/read.php b/api/v1/software/read.php index 7ff2dbf5..e738d22e 100644 --- a/api/v1/software/read.php +++ b/api/v1/software/read.php @@ -8,26 +8,26 @@ require_once '../require_get_method.php'; // Specific software via ID (single) if (isset($_GET['software_id'])) { $id = intval($_GET['software_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_id = '$id' AND software_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_id = '$id' AND 1=1 " . apiClientScopeSql('software_client_id') . ""); } elseif (isset($_GET['software_key'])) { // Specific software via key $key = mysqli_real_escape_string($mysqli, $_GET['software_license']); - $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_key = '$key' AND software_client_id LIKE '$client_id' ORDER BY software_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_key = '$key' AND 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY software_id LIMIT $limit OFFSET $offset"); } elseif (isset($_GET['software_name'])) { // Software by name $name = mysqli_real_escape_string($mysqli, $_GET['software_name']); - $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_name = '$name' AND software_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_name = '$name' AND 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); } elseif (isset($_GET['software_type'])) { // Software via type $type = intval($_GET['software_type']); - $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_type = '$type' AND software_client_id LIKE '$client_id' ORDER BY software_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_type = '$type' AND 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY software_id LIMIT $limit OFFSET $offset"); } else { // All software(s) (by client ID if given, or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_client_id LIKE '$client_id' ORDER BY software_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY software_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/technicians/time.php b/api/v1/technicians/time.php index 5d17be98..3e67ea6d 100644 --- a/api/v1/technicians/time.php +++ b/api/v1/technicians/time.php @@ -62,7 +62,7 @@ $sql = mysqli_query( WHERE tr.ticket_reply_time_worked IS NOT NULL AND tr.ticket_reply_time_worked != '00:00:00' AND $date_conditions - AND t.ticket_client_id LIKE '$client_id' + AND t.1=1 " . apiClientScopeSql('ticket_client_id') . " $technician_condition GROUP BY t.ticket_id, u.user_id ORDER BY c.client_name ASC, t.ticket_number ASC, u.user_name ASC diff --git a/api/v1/tickets/read.php b/api/v1/tickets/read.php index 408190ae..d6a28a32 100644 --- a/api/v1/tickets/read.php +++ b/api/v1/tickets/read.php @@ -12,12 +12,12 @@ if (isset($_GET['ticket_id'])) { $mysqli, "SELECT * FROM tickets LEFT JOIN ticket_statuses ON ticket_status = ticket_status_id - WHERE ticket_id = '$id' AND ticket_client_id LIKE '$client_id'" + WHERE ticket_id = '$id' AND 1=1 " . apiClientScopeSql('ticket_client_id') . "" ); } else { // All tickets (by client ID if given, or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM tickets WHERE ticket_client_id LIKE '$client_id' ORDER BY ticket_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM tickets WHERE 1=1 " . apiClientScopeSql('ticket_client_id') . " ORDER BY ticket_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api/v1/validate_api_key.php b/api/v1/validate_api_key.php index 2945a321..2404bc8c 100644 --- a/api/v1/validate_api_key.php +++ b/api/v1/validate_api_key.php @@ -94,7 +94,7 @@ if (isset($api_key)) { $row = mysqli_fetch_assoc($sql); $api_key_name = htmlentities($row['api_key_name']); $api_key_decrypt_hash = $row['api_key_decrypt_hash']; // No sanitization - $client_id = intval($row['api_key_client_id']); + $api_key_user_id = intval($row['api_key_user_id']); // Set limit & offset for queries if (isset($_GET['limit'])) { @@ -113,5 +113,8 @@ if (isset($api_key)) { $offset = 0; } + // When the key is tied to a user, enforce that user's RBAC (module + operation + client scope) + require __DIR__ . '/enforce_api_rbac.php'; + } } diff --git a/api/v1/vendors/read.php b/api/v1/vendors/read.php index e6971f52..f12d572c 100644 --- a/api/v1/vendors/read.php +++ b/api/v1/vendors/read.php @@ -7,11 +7,11 @@ require_once '../require_get_method.php'; // Specific vendor via their ID (single) if (isset($_GET['vendor_id'])) { $id = intval($_GET['vendor_id']); - $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE vendor_id = '$id' AND vendor_client_id LIKE '$client_id'"); + $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE vendor_id = '$id' AND 1=1 " . apiClientScopeSql('vendor_client_id') . ""); } else { // All Vendors (by client ID or all in general if key permits) - $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE vendor_client_id LIKE '$client_id' ORDER BY vendor_id LIMIT $limit OFFSET $offset"); + $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE 1=1 " . apiClientScopeSql('vendor_client_id') . " ORDER BY vendor_id LIMIT $limit OFFSET $offset"); } // Output diff --git a/api_rbac_edits.patch b/api_rbac_edits.patch new file mode 100644 index 00000000..c079b5c4 --- /dev/null +++ b/api_rbac_edits.patch @@ -0,0 +1,590 @@ +diff --git a/admin/api_keys.php b/admin/api_keys.php +index 387ae257..009f8cce 100644 +--- a/admin/api_keys.php ++++ b/admin/api_keys.php +@@ -9,7 +9,7 @@ require_once "includes/inc_all_admin.php"; + $sql = mysqli_query( + $mysqli, + "SELECT SQL_CALC_FOUND_ROWS * FROM api_keys +- LEFT JOIN clients on api_keys.api_key_client_id = clients.client_id ++ LEFT JOIN users on api_keys.api_key_user_id = users.user_id + WHERE (api_key_name LIKE '%$q%') + ORDER BY $sort $order LIMIT $record_from, $record_to" + ); +@@ -80,8 +80,8 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); +
+ + +- +- Client ++ ++ User + + + +@@ -115,11 +115,7 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); + $api_key_expire = $api_key_expire . " (Expired)"; + } + +- if ($row['api_key_client_id'] == 0) { +- $api_key_client = "All Clients"; +- } else { +- $api_key_client = escapeHtml($row['client_name']); +- } ++ $api_key_user = !empty($row['user_name']) ? escapeHtml($row['user_name']) : "None"; + + ?> + +@@ -129,7 +125,7 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); + + + +- ++ + + + +@@ -139,6 +135,9 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()")); + + + + +
+- ++ +
+
+- ++ +
+- ++ + +- ++ $sql_run_users = mysqli_query($mysqli, "SELECT user_id, user_name FROM users WHERE user_type = 1 AND user_status = 1 AND user_archived_at IS NULL ORDER BY user_name ASC"); ++ while ($run_user = mysqli_fetch_assoc($sql_run_users)) { ++ $run_user_id = intval($run_user['user_id']); ++ $run_user_name = escapeHtml($run_user['user_name']); ?> ++ + + +
++ The key inherits this user's module permissions and client access. +
+ + +diff --git a/admin/post/api_keys.php b/admin/post/api_keys.php +index c36751d3..659f36c6 100644 +--- a/admin/post/api_keys.php ++++ b/admin/post/api_keys.php +@@ -12,17 +12,17 @@ if (isset($_POST['add_api_key'])) { + + $name = escapeSql($_POST['name']); + $expire = escapeSql($_POST['expire']); +- $client_id = intval($_POST['client']); ++ $user_id = intval($_POST['run_as_user']); + $secret = escapeSql($_POST['key']); // API Key + + // Credential decryption password + $apikey_specific_encryption_ciphertext = encryptUserSpecificKey(trim($_POST['password'])); + +- mysqli_query($mysqli,"INSERT INTO api_keys SET api_key_name = '$name', api_key_secret = '$secret', api_key_decrypt_hash = '$apikey_specific_encryption_ciphertext', api_key_expire = '$expire', api_key_client_id = $client_id"); ++ mysqli_query($mysqli,"INSERT INTO api_keys SET api_key_name = '$name', api_key_secret = '$secret', api_key_decrypt_hash = '$apikey_specific_encryption_ciphertext', api_key_expire = '$expire', api_key_user_id = $user_id"); + + $api_key_id = mysqli_insert_id($mysqli); + +- logAudit("API Key", "Create", "$session_name created API key $name set to expire on $expire", $client_id, $api_key_id); ++ logAudit("API Key", "Create", "$session_name created API key $name set to expire on $expire", 0, $api_key_id); + + flashAlert("API Key $name created"); + +@@ -30,6 +30,25 @@ if (isset($_POST['add_api_key'])) { + + } + ++if (isset($_POST['edit_api_key'])) { ++ ++ validateCSRFToken(); ++ ++ $api_key_id = intval($_POST['api_key_id']); ++ $name = escapeSql($_POST['name']); ++ $expire = escapeSql($_POST['expire']); ++ $user_id = intval($_POST['run_as_user']); ++ ++ mysqli_query($mysqli,"UPDATE api_keys SET api_key_name = '$name', api_key_expire = '$expire', api_key_user_id = $user_id WHERE api_key_id = $api_key_id"); ++ ++ logAudit("API Key", "Edit", "$session_name edited API key $name", 0, $api_key_id); ++ ++ flashAlert("API Key $name updated"); ++ ++ redirect(); ++ ++} ++ + if (isset($_GET['revoke_api_key'])) { + + validateCSRFToken(); +@@ -37,13 +56,12 @@ if (isset($_GET['revoke_api_key'])) { + $api_key_id = intval($_GET['revoke_api_key']); + + // Get API Key Name +- $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name, api_key_client_id FROM api_keys WHERE api_key_id = $api_key_id")); ++ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name FROM api_keys WHERE api_key_id = $api_key_id")); + $api_key_name = escapeSql($row['api_key_name']); +- $client_id = intval($row['api_key_client_id']); + + mysqli_query($mysqli,"UPDATE api_keys SET api_key_expire = NOW() WHERE api_key_id = $api_key_id"); + +- logAudit("API Key", "Revoke", "$session_name revoked API key $name", $client_id); ++ logAudit("API Key", "Revoke", "$session_name revoked API key $name", 0); + + flashAlert("API Key $name revoked", 'error'); + +@@ -58,13 +76,12 @@ if (isset($_GET['delete_api_key'])) { + $api_key_id = intval($_GET['delete_api_key']); + + // Get API Key Name +- $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name, api_key_client_id FROM api_keys WHERE api_key_id = $api_key_id")); ++ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name FROM api_keys WHERE api_key_id = $api_key_id")); + $api_key_name = escapeSql($row['api_key_name']); +- $client_id = intval($row['api_key_client_id']); + + mysqli_query($mysqli,"DELETE FROM api_keys WHERE api_key_id = $api_key_id"); + +- logAudit("API Key", "Delete", "$session_name deleted API key $name", $client_id); ++ logAudit("API Key", "Delete", "$session_name deleted API key $name", 0); + + flashAlert("API Key $name deleted", 'error'); + +@@ -86,13 +103,12 @@ if (isset($_POST['bulk_delete_api_keys'])) { + $api_key_id = intval($api_key_id); + + // Get API Key Name +- $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name, api_key_client_id FROM api_keys WHERE api_key_id = $api_key_id")); ++ $row = mysqli_fetch_assoc(mysqli_query($mysqli,"SELECT api_key_name FROM api_keys WHERE api_key_id = $api_key_id")); + $api_key_name = escapeSql($row['api_key_name']); +- $client_id = intval($row['api_key_client_id']); + + mysqli_query($mysqli, "DELETE FROM api_keys WHERE api_key_id = $api_key_id"); + +- logAudit("API Key", "Delete", "$session_name deleted API key $name", $client_id); ++ logAudit("API Key", "Delete", "$session_name deleted API key $name", 0); + + } + +diff --git a/agent/post/client.php b/agent/post/client.php +index 00a0050f..1a43d33f 100644 +--- a/agent/post/client.php ++++ b/agent/post/client.php +@@ -394,7 +394,6 @@ if (isset($_GET['delete_client'])) { + + // Delete Associations + // Delete Client Data +- mysqli_query($mysqli, "DELETE FROM api_keys WHERE api_key_client_id = $client_id"); + mysqli_query($mysqli, "DELETE FROM certificates WHERE certificate_client_id = $client_id"); + mysqli_query($mysqli, "DELETE FROM documents WHERE document_client_id = $client_id"); + +diff --git a/api/v1/assets/read.php b/api/v1/assets/read.php +index 1dc1d9d0..0ba013a7 100644 +--- a/api/v1/assets/read.php ++++ b/api/v1/assets/read.php +@@ -8,41 +8,41 @@ require_once '../require_get_method.php'; + // Asset via ID (single) + if (isset($_GET['asset_id'])) { + $id = intval($_GET['asset_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_id = $id AND asset_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_id = $id AND 1=1 " . apiClientScopeSql('asset_client_id') . ""); + + } elseif (isset($_GET['asset_type'])) { + // Asset query via type + $type = mysqli_real_escape_string($mysqli, ucfirst($_GET['asset_type'])); +- $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_type = '$type' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_type = '$type' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + + } elseif (isset($_GET['asset_name'])) { + // Asset query via name + $name = mysqli_real_escape_string($mysqli, $_GET['asset_name']); +- $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_name = '$name' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_name = '$name' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + + } elseif (isset($_GET['asset_serial'])) { + // Asset query via serial + $serial = mysqli_real_escape_string($mysqli, $_GET['asset_serial']); +- $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_serial = '$serial' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_serial = '$serial' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + + } elseif (isset($_GET['asset_mac'])) { + // Asset query via mac + $mac = mysqli_real_escape_string($mysqli, $_GET['asset_mac']); +- $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE interface_mac = '$mac' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE interface_mac = '$mac' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + + } elseif (isset($_GET['asset_uri'])) { + // Asset query via uri + $uri = mysqli_real_escape_string($mysqli, $_GET['asset_uri']); +- $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri = '$uri' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri = '$uri' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + + } elseif (isset($_GET['asset_uri_2'])) { + // Asset query via uri2 + $uri2 = mysqli_real_escape_string($mysqli, $_GET['asset_uri_2']); +- $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri_2 = '$uri2' AND asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets WHERE asset_uri_2 = '$uri2' AND 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + + }else { + // All assets (by client ID or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE asset_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM assets LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1 WHERE 1=1 " . apiClientScopeSql('asset_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/certificates/read.php b/api/v1/certificates/read.php +index 7d08673c..210680b3 100644 +--- a/api/v1/certificates/read.php ++++ b/api/v1/certificates/read.php +@@ -8,16 +8,16 @@ require_once '../require_get_method.php'; + // Specific certificate via ID (single) + if (isset($_GET['certificate_id'])) { + $id = intval($_GET['certificate_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_id = '$id' AND certificate_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_id = '$id' AND 1=1 " . apiClientScopeSql('certificate_client_id') . ""); + + } elseif (isset($_GET['certificate_name'])) { + // Certificate by name + $name = mysqli_real_escape_string($mysqli, $_GET['certificate_name']); +- $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_name = '$name' AND certificate_client_id LIKE '$client_id' ORDER BY certificate_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_name = '$name' AND 1=1 " . apiClientScopeSql('certificate_client_id') . " ORDER BY certificate_id LIMIT $limit OFFSET $offset"); + + } else { + // All certificates (by client ID or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE certificate_client_id LIKE '$client_id' ORDER BY certificate_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM certificates WHERE 1=1 " . apiClientScopeSql('certificate_client_id') . " ORDER BY certificate_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/contacts/read.php b/api/v1/contacts/read.php +index 114c11dd..730e88a2 100644 +--- a/api/v1/contacts/read.php ++++ b/api/v1/contacts/read.php +@@ -8,21 +8,21 @@ require_once '../require_get_method.php'; + // Specific contact via ID (single) + if (isset($_GET['contact_id'])) { + $id = intval($_GET['contact_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_id = '$id' AND contact_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_id = '$id' AND 1=1 " . apiClientScopeSql('contact_client_id') . ""); + + } elseif (isset($_GET['contact_email'])) { + // Specific contact via email (single) + $email = mysqli_real_escape_string($mysqli, $_GET['contact_email']); +- $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_email = '$email' AND contact_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_email = '$email' AND 1=1 " . apiClientScopeSql('contact_client_id') . ""); + + } elseif (isset($_GET['contact_phone_or_mobile'])) { + // Specific contact via phone number or mobile (single) + $phone_or_mob = mysqli_real_escape_string($mysqli, $_GET['contact_phone_or_mobile']); +- $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_mobile = '$phone_or_mob' OR contact_phone = '$phone_or_mob' AND contact_client_id LIKE '$client_id' LIMIT 1"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_mobile = '$phone_or_mob' OR contact_phone = '$phone_or_mob' AND 1=1 " . apiClientScopeSql('contact_client_id') . " LIMIT 1"); + + } else { + // All contacts (by client ID, or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE contact_client_id LIKE '$client_id' ORDER BY contact_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM contacts WHERE 1=1 " . apiClientScopeSql('contact_client_id') . " ORDER BY contact_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/credentials/read.php b/api/v1/credentials/read.php +index 6d540af3..d6bd98c0 100644 +--- a/api/v1/credentials/read.php ++++ b/api/v1/credentials/read.php +@@ -17,13 +17,13 @@ if (isset($_GET['credential_id']) && !empty($api_key_decrypt_password)) { + + $id = intval($_GET['credential_id']); + +- $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE credential_id = '$id' AND credential_client_id LIKE '$client_id' LIMIT 1"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE credential_id = '$id' AND 1=1 " . apiClientScopeSql('credential_client_id') . " LIMIT 1"); + + + } elseif (!empty($api_key_decrypt_password)) { + // All credentials ("credentials") + +- $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE credential_client_id LIKE '$client_id' ORDER BY credential_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM credentials WHERE 1=1 " . apiClientScopeSql('credential_client_id') . " ORDER BY credential_id LIMIT $limit OFFSET $offset"); + + } + +diff --git a/api/v1/documents/read.php b/api/v1/documents/read.php +index a376381b..5abe9d10 100644 +--- a/api/v1/documents/read.php ++++ b/api/v1/documents/read.php +@@ -8,11 +8,11 @@ require_once '../require_get_method.php'; + if (isset($_GET['document_id'])) { + // Document via ID (single) + $id = intval($_GET['document_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE document_id = '$id' AND document_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE document_id = '$id' AND 1=1 " . apiClientScopeSql('document_client_id') . ""); + + } else { + // All documents (by client ID if given, or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE document_client_id LIKE '$client_id' ORDER BY document_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM documents WHERE 1=1 " . apiClientScopeSql('document_client_id') . " ORDER BY document_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/domains/read.php b/api/v1/domains/read.php +index 6bbd96a2..e75b31c0 100644 +--- a/api/v1/domains/read.php ++++ b/api/v1/domains/read.php +@@ -8,16 +8,16 @@ require_once '../require_get_method.php'; + // Specific domain via ID (single) + if (isset($_GET['domain_id'])) { + $id = intval($_GET['domain_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_id = '$id' AND domain_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_id = '$id' AND 1=1 " . apiClientScopeSql('domain_client_id') . ""); + + } elseif (isset($_GET['domain_name'])) { + // Domain by name + $name = mysqli_real_escape_string($mysqli, $_GET['domain_name']); +- $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_name = '$name' AND domain_client_id LIKE '$client_id' ORDER BY domain_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_name = '$name' AND 1=1 " . apiClientScopeSql('domain_client_id') . " ORDER BY domain_id LIMIT $limit OFFSET $offset"); + + } else { + // All domains (by client ID or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE domain_client_id LIKE '$client_id' ORDER BY domain_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM domains WHERE 1=1 " . apiClientScopeSql('domain_client_id') . " ORDER BY domain_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/invoice_items/read.php b/api/v1/invoice_items/read.php +index 9b6a435b..eca3276f 100644 +--- a/api/v1/invoice_items/read.php ++++ b/api/v1/invoice_items/read.php +@@ -33,7 +33,7 @@ if (isset($_GET['item_id'])) { + FROM invoice_items ii + INNER JOIN invoices i ON i.invoice_id = ii.item_invoice_id + WHERE ii.item_id = '$item_id' +- AND i.invoice_client_id LIKE '$client_id' ++ AND i.1=1 " . apiClientScopeSql('invoice_client_id') . " + LIMIT 1" + ); + } elseif (isset($_GET['invoice_id'])) { +@@ -44,7 +44,7 @@ if (isset($_GET['item_id'])) { + FROM invoice_items ii + INNER JOIN invoices i ON i.invoice_id = ii.item_invoice_id + WHERE ii.item_invoice_id = '$invoice_id' +- AND i.invoice_client_id LIKE '$client_id' ++ AND i.1=1 " . apiClientScopeSql('invoice_client_id') . " + ORDER BY ii.item_order ASC, ii.item_id ASC + LIMIT $limit OFFSET $offset" + ); +diff --git a/api/v1/invoices/read.php b/api/v1/invoices/read.php +index f9f40425..072489e6 100644 +--- a/api/v1/invoices/read.php ++++ b/api/v1/invoices/read.php +@@ -8,11 +8,11 @@ require_once '../require_get_method.php'; + if (isset($_GET['invoice_id'])) { + // Invoice via ID (single) + $id = intval($_GET['invoice_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE invoice_id = '$id' AND invoice_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE invoice_id = '$id' AND 1=1 " . apiClientScopeSql('invoice_client_id') . ""); + + } else { + // All invoices (by client ID if given, or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE invoice_client_id LIKE '$client_id' ORDER BY invoice_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM invoices WHERE 1=1 " . apiClientScopeSql('invoice_client_id') . " ORDER BY invoice_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/locations/read.php b/api/v1/locations/read.php +index d26efd0d..516fad78 100644 +--- a/api/v1/locations/read.php ++++ b/api/v1/locations/read.php +@@ -8,11 +8,11 @@ require_once '../require_get_method.php'; + if (isset($_GET['location_id'])) { + // Location via ID (single) + $id = intval($_GET['location_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE location_id = '$id' AND location_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE location_id = '$id' AND 1=1 " . apiClientScopeSql('location_client_id') . ""); + + } else { + // All locations (by client ID if given, or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE location_client_id LIKE '$client_id' ORDER BY location_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM locations WHERE 1=1 " . apiClientScopeSql('location_client_id') . " ORDER BY location_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/networks/read.php b/api/v1/networks/read.php +index 168757ae..28b01756 100644 +--- a/api/v1/networks/read.php ++++ b/api/v1/networks/read.php +@@ -8,16 +8,16 @@ require_once '../require_get_method.php'; + // Specific network via ID (single) + if (isset($_GET['network_id'])) { + $id = intval($_GET['network_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_id = '$id' AND network_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_id = '$id' AND 1=1 " . apiClientScopeSql('network_client_id') . ""); + + } elseif (isset($_GET['network_name'])) { + // Network by name + $name = mysqli_real_escape_string($mysqli, $_GET['network_name']); +- $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_name = '$name' AND network_client_id LIKE '$client_id' ORDER BY network_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_name = '$name' AND 1=1 " . apiClientScopeSql('network_client_id') . " ORDER BY network_id LIMIT $limit OFFSET $offset"); + + } else { + // All networks (by client ID or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE network_client_id LIKE '$client_id' ORDER BY network_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM networks WHERE 1=1 " . apiClientScopeSql('network_client_id') . " ORDER BY network_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/quotes/read.php b/api/v1/quotes/read.php +index 7331de49..194c7800 100644 +--- a/api/v1/quotes/read.php ++++ b/api/v1/quotes/read.php +@@ -12,7 +12,7 @@ if (isset($_GET['quote_id'])) { + + } else { + // All quotes (by client ID if given, or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM quotes WHERE quote_client_id LIKE '$client_id' ORDER BY quote_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM quotes WHERE 1=1 " . apiClientScopeSql('quote_client_id') . " ORDER BY quote_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/software/read.php b/api/v1/software/read.php +index 7ff2dbf5..e738d22e 100644 +--- a/api/v1/software/read.php ++++ b/api/v1/software/read.php +@@ -8,26 +8,26 @@ require_once '../require_get_method.php'; + // Specific software via ID (single) + if (isset($_GET['software_id'])) { + $id = intval($_GET['software_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_id = '$id' AND software_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_id = '$id' AND 1=1 " . apiClientScopeSql('software_client_id') . ""); + + } elseif (isset($_GET['software_key'])) { + // Specific software via key + $key = mysqli_real_escape_string($mysqli, $_GET['software_license']); +- $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_key = '$key' AND software_client_id LIKE '$client_id' ORDER BY software_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_key = '$key' AND 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY software_id LIMIT $limit OFFSET $offset"); + + } elseif (isset($_GET['software_name'])) { + // Software by name + $name = mysqli_real_escape_string($mysqli, $_GET['software_name']); +- $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_name = '$name' AND software_client_id LIKE '$client_id' ORDER BY asset_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_name = '$name' AND 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY asset_id LIMIT $limit OFFSET $offset"); + + } elseif (isset($_GET['software_type'])) { + // Software via type + $type = intval($_GET['software_type']); +- $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_type = '$type' AND software_client_id LIKE '$client_id' ORDER BY software_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_type = '$type' AND 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY software_id LIMIT $limit OFFSET $offset"); + + } else { + // All software(s) (by client ID if given, or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE software_client_id LIKE '$client_id' ORDER BY software_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM software WHERE 1=1 " . apiClientScopeSql('software_client_id') . " ORDER BY software_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/technicians/time.php b/api/v1/technicians/time.php +index 5d17be98..3e67ea6d 100644 +--- a/api/v1/technicians/time.php ++++ b/api/v1/technicians/time.php +@@ -62,7 +62,7 @@ $sql = mysqli_query( + WHERE tr.ticket_reply_time_worked IS NOT NULL + AND tr.ticket_reply_time_worked != '00:00:00' + AND $date_conditions +- AND t.ticket_client_id LIKE '$client_id' ++ AND t.1=1 " . apiClientScopeSql('ticket_client_id') . " + $technician_condition + GROUP BY t.ticket_id, u.user_id + ORDER BY c.client_name ASC, t.ticket_number ASC, u.user_name ASC +diff --git a/api/v1/tickets/read.php b/api/v1/tickets/read.php +index 408190ae..d6a28a32 100644 +--- a/api/v1/tickets/read.php ++++ b/api/v1/tickets/read.php +@@ -12,12 +12,12 @@ if (isset($_GET['ticket_id'])) { + $mysqli, + "SELECT * FROM tickets + LEFT JOIN ticket_statuses ON ticket_status = ticket_status_id +- WHERE ticket_id = '$id' AND ticket_client_id LIKE '$client_id'" ++ WHERE ticket_id = '$id' AND 1=1 " . apiClientScopeSql('ticket_client_id') . "" + ); + + } else { + // All tickets (by client ID if given, or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM tickets WHERE ticket_client_id LIKE '$client_id' ORDER BY ticket_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM tickets WHERE 1=1 " . apiClientScopeSql('ticket_client_id') . " ORDER BY ticket_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/api/v1/validate_api_key.php b/api/v1/validate_api_key.php +index 2945a321..2404bc8c 100644 +--- a/api/v1/validate_api_key.php ++++ b/api/v1/validate_api_key.php +@@ -94,7 +94,7 @@ if (isset($api_key)) { + $row = mysqli_fetch_assoc($sql); + $api_key_name = htmlentities($row['api_key_name']); + $api_key_decrypt_hash = $row['api_key_decrypt_hash']; // No sanitization +- $client_id = intval($row['api_key_client_id']); ++ $api_key_user_id = intval($row['api_key_user_id']); + + // Set limit & offset for queries + if (isset($_GET['limit'])) { +@@ -113,5 +113,8 @@ if (isset($api_key)) { + $offset = 0; + } + ++ // When the key is tied to a user, enforce that user's RBAC (module + operation + client scope) ++ require __DIR__ . '/enforce_api_rbac.php'; ++ + } + } +diff --git a/api/v1/vendors/read.php b/api/v1/vendors/read.php +index e6971f52..f12d572c 100644 +--- a/api/v1/vendors/read.php ++++ b/api/v1/vendors/read.php +@@ -7,11 +7,11 @@ require_once '../require_get_method.php'; + // Specific vendor via their ID (single) + if (isset($_GET['vendor_id'])) { + $id = intval($_GET['vendor_id']); +- $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE vendor_id = '$id' AND vendor_client_id LIKE '$client_id'"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE vendor_id = '$id' AND 1=1 " . apiClientScopeSql('vendor_client_id') . ""); + + } else { + // All Vendors (by client ID or all in general if key permits) +- $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE vendor_client_id LIKE '$client_id' ORDER BY vendor_id LIMIT $limit OFFSET $offset"); ++ $sql = mysqli_query($mysqli, "SELECT * FROM vendors WHERE 1=1 " . apiClientScopeSql('vendor_client_id') . " ORDER BY vendor_id LIMIT $limit OFFSET $offset"); + } + + // Output +diff --git a/db.sql b/db.sql +index 832e141b..5a6abded 100644 +--- a/db.sql ++++ b/db.sql +@@ -91,7 +91,7 @@ CREATE TABLE `api_keys` ( + `api_key_decrypt_hash` varchar(200) NOT NULL, + `api_key_created_at` datetime NOT NULL DEFAULT current_timestamp(), + `api_key_expire` date NOT NULL, +- `api_key_client_id` int(11) NOT NULL DEFAULT 0, ++ `api_key_user_id` int(11) NOT NULL DEFAULT 0, + PRIMARY KEY (`api_key_id`) + ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_general_ci; + /*!40101 SET character_set_client = @saved_cs_client */; diff --git a/db.sql b/db.sql index 832e141b..4154805b 100644 --- a/db.sql +++ b/db.sql @@ -91,7 +91,7 @@ CREATE TABLE `api_keys` ( `api_key_decrypt_hash` varchar(200) NOT NULL, `api_key_created_at` datetime NOT NULL DEFAULT current_timestamp(), `api_key_expire` date NOT NULL, - `api_key_client_id` int(11) NOT NULL DEFAULT 0, + `api_key_user_id` int(11) NOT NULL DEFAULT 0, PRIMARY KEY (`api_key_id`) ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_general_ci; /*!40101 SET character_set_client = @saved_cs_client */; @@ -2996,4 +2996,4 @@ CREATE TABLE `vendors` ( /*!40101 SET COLLATION_CONNECTION=@OLD_COLLATION_CONNECTION */; /*!40111 SET SQL_NOTES=@OLD_SQL_NOTES */; --- Dump completed on 2026-07-25 13:20:49 +-- Dump completed on 2026-07-25 16:50:10