PluginProbe ʕ •ᴥ•ʔ
VikAppointments Services Booking Calendar / trunk
VikAppointments Services Booking Calendar vtrunk
trunk 1.2.17 1.2.18 1.2.19
vikappointments / admin / controllers / configcron.php
vikappointments / admin / controllers Last commit date
analytics.php 4 years ago apiban.php 4 years ago apilog.php 4 years ago apiplugin.php 4 years ago apiuser.php 4 years ago backup.php 4 years ago calendar.php 4 years ago city.php 4 years ago closure.php 1 month ago configapp.php 4 years ago configcldays.php 2 years ago configcron.php 4 years ago configemp.php 4 years ago configsmsapi.php 4 years ago configuration.php 1 month ago conversion.php 1 year ago country.php 4 years ago coupon.php 4 years ago coupongroup.php 4 years ago cronjob.php 2 years ago cronjoblog.php 4 years ago customer.php 5 months ago customf.php 1 year ago dashboard.php 4 years ago emplocwdays.php 4 years ago employee.php 1 year ago emprates.php 4 years ago export.php 4 years ago exportres.php 4 years ago file.php 5 months ago findreservation.php 1 month ago group.php 4 years ago import.php 4 years ago index.html 4 years ago invoice.php 1 month ago langcustomf.php 4 years ago langemployee.php 4 years ago langgroup.php 4 years ago langmedia.php 4 years ago langoption.php 4 years ago langoptiongroup.php 4 years ago langpackage.php 4 years ago langpackgroup.php 4 years ago langpayment.php 4 years ago langservice.php 4 years ago langstatuscode.php 4 years ago langsubscr.php 4 years ago langtax.php 4 years ago location.php 4 years ago mailtext.php 2 years ago makerecurrence.php 1 month ago media.php 4 years ago multiorder.php 4 years ago option.php 5 months ago optiongroup.php 4 years ago package.php 2 years ago packgroup.php 4 years ago packorder.php 1 year ago payment.php 4 years ago rate.php 4 years ago reportsemp.php 4 years ago reportsser.php 4 years ago reservation.php 1 month ago restriction.php 4 years ago review.php 4 years ago service.php 1 year ago serworkday.php 5 months ago state.php 4 years ago statuscode.php 4 years ago subscription.php 4 years ago subscrorder.php 4 years ago tag.php 4 years ago tax.php 4 years ago usernote.php 4 years ago waitinglist.php 4 years ago webhook.php 4 years ago wizard.php 1 year ago
configcron.php
183 lines
1 <?php
2 /**
3 * @package VikAppointments
4 * @subpackage core
5 * @author E4J s.r.l.
6 * @copyright Copyright (C) 2021 E4J s.r.l. All Rights Reserved.
7 * @license http://www.gnu.org/licenses/gpl-2.0.html GNU/GPL
8 * @link https://vikwp.com
9 */
10
11 // No direct access
12 defined('ABSPATH') or die('No script kiddies please!');
13
14 VAPLoader::import('libraries.mvc.controllers.admin');
15
16 /**
17 * VikAppointments cron jobs configuration controller.
18 *
19 * @since 1.7
20 */
21 class VikAppointmentsControllerConfigcron extends VAPControllerAdmin
22 {
23 /**
24 * Task used to save the record data set in the request.
25 * After saving, the user is redirected to the management
26 * page of the record that has been saved.
27 *
28 * @return boolean
29 */
30 public function save()
31 {
32 $app = JFactory::getApplication();
33 $input = $app->input;
34 $user = JFactory::getUser();
35
36 /**
37 * Added token validation.
38 *
39 * @since 1.7
40 */
41 if (!JSession::checkToken())
42 {
43 // back to main list, missing CSRF-proof token
44 $app->enqueueMessage(JText::translate('JINVALID_TOKEN'), 'error');
45 $this->cancel();
46
47 return false;
48 }
49
50 // check user permissions
51 if (!$user->authorise('core.access.config', 'com_vikappointments'))
52 {
53 // back to main list, not authorised to access the configuration
54 $app->enqueueMessage(JText::translate('JERROR_ALERTNOAUTHOR'), 'error');
55 $this->cancel();
56
57 return false;
58 }
59
60 $args = array();
61
62 ////////////////////////////////////////////////////
63 ///////////////////// SETTINGS /////////////////////
64 ////////////////////////////////////////////////////
65
66 $args['cron_secure_key'] = $input->getString('cron_secure_key', '');
67 $args['cron_log_mode'] = $input->getUint('cron_log_mode', 1);
68 $args['cron_log_flush'] = $input->getUint('cron_log_flush', 0);
69
70 ////////////////////////////////////////////////////
71
72 // get configuration model
73 $config = $this->getModel();
74
75 // Save all configuration.
76 // Do not care of any errors.
77 $changed = $config->saveAll($args);
78
79 if ($changed)
80 {
81 // display generic successful message
82 $app->enqueueMessage(JText::translate('JLIB_APPLICATION_SAVE_SUCCESS'));
83 }
84
85 // redirect to configuration page
86 $this->cancel();
87
88 return true;
89 }
90
91 /**
92 * Redirects the users to the main records list.
93 *
94 * @return void
95 */
96 public function cancel()
97 {
98 $this->setRedirect('index.php?option=com_vikappointments&view=editconfigcron');
99 }
100
101 /**
102 * Task used to download the installation file of the specified cron job.
103 *
104 * @return void
105 */
106 function downloadInstallationFile()
107 {
108 $app = JFactory::getApplication();
109 $vik = VAPApplication::getInstance();
110
111 /**
112 * Added token validation.
113 * Both GET and POST are supported.
114 *
115 * @since 1.7
116 */
117 if (!JSession::checkToken() && !JSession::checkToken('get'))
118 {
119 // back to main list, missing CSRF-proof token
120 $app->enqueueMessage(JText::translate('JINVALID_TOKEN'), 'error');
121 $this->cancel();
122
123 return false;
124 }
125
126 // get CRON ID from request
127 $id_cron = $app->input->getUint('id_cron');
128 // get secure key from config
129 $key = VAPFactory::getConfig()->get('cron_secure_key');
130
131 // build loopback query string
132 $url = 'index.php?option=com_vikappointments&task=cronjob_listener_rq';
133 // create full URI
134 $url = $vik->routeForExternalUse($url, false);
135
136 /**
137 * The code of the cron job now escapes the internal variables properly.
138 *
139 * @since 1.6.2
140 */
141
142 $php_cron_code = "<?php
143
144 define(\"ID_CRON\", {$id_cron});
145 define(\"SECURE_KEY\", \"{$key}\");
146
147 // make sure the domain is correct
148 \$url = \"{$url}\";
149
150 \$fields = array(
151 \"id_cron\" => ID_CRON,
152 \"secure_key\" => md5(SECURE_KEY),
153 );
154
155 \$ch = curl_init();
156 curl_setopt(\$ch, CURLOPT_URL, \$url);
157 curl_setopt(\$ch, CURLOPT_SSL_VERIFYHOST, 0);
158 curl_setopt(\$ch, CURLOPT_SSL_VERIFYPEER, 0);
159 curl_setopt(\$ch, CURLOPT_CONNECTTIMEOUT, 10);
160 curl_setopt(\$ch, CURLOPT_TIMEOUT, 20);
161 curl_setopt(\$ch, CURLOPT_FOLLOWLOCATION, 1);
162 curl_setopt(\$ch, CURLOPT_RETURNTRANSFER, 1);
163 curl_setopt(\$ch, CURLOPT_POST, count(\$fields));
164 curl_setopt(\$ch, CURLOPT_POSTFIELDS, http_build_query(\$fields));
165
166 \$output = curl_exec(\$ch);
167
168 curl_close(\$ch);
169
170 echo \$output;";
171
172 // configure headers
173 $app->setHeader('Content-Disposition', 'attachment; filename="cron_runnable.php"');
174 $app->setHeader('Content-Type', 'text/php');
175 $app->sendHeaders();
176
177 // download file
178 echo $php_cron_code;
179
180 $app->close();
181 }
182 }
183