PluginProbe ʕ •ᴥ•ʔ
VikAppointments Services Booking Calendar / trunk
VikAppointments Services Booking Calendar vtrunk
trunk 1.2.17 1.2.18 1.2.19
vikappointments / admin / controllers / restriction.php
vikappointments / admin / controllers Last commit date
analytics.php 4 years ago apiban.php 4 years ago apilog.php 4 years ago apiplugin.php 4 years ago apiuser.php 4 years ago backup.php 4 years ago calendar.php 4 years ago city.php 4 years ago closure.php 1 month ago configapp.php 4 years ago configcldays.php 2 years ago configcron.php 4 years ago configemp.php 4 years ago configsmsapi.php 4 years ago configuration.php 1 month ago conversion.php 1 year ago country.php 4 years ago coupon.php 4 years ago coupongroup.php 4 years ago cronjob.php 2 years ago cronjoblog.php 4 years ago customer.php 5 months ago customf.php 1 year ago dashboard.php 4 years ago emplocwdays.php 4 years ago employee.php 1 year ago emprates.php 4 years ago export.php 4 years ago exportres.php 4 years ago file.php 5 months ago findreservation.php 1 month ago group.php 4 years ago import.php 4 years ago index.html 4 years ago invoice.php 1 month ago langcustomf.php 4 years ago langemployee.php 4 years ago langgroup.php 4 years ago langmedia.php 4 years ago langoption.php 4 years ago langoptiongroup.php 4 years ago langpackage.php 4 years ago langpackgroup.php 4 years ago langpayment.php 4 years ago langservice.php 4 years ago langstatuscode.php 4 years ago langsubscr.php 4 years ago langtax.php 4 years ago location.php 4 years ago mailtext.php 2 years ago makerecurrence.php 1 month ago media.php 4 years ago multiorder.php 4 years ago option.php 5 months ago optiongroup.php 4 years ago package.php 2 years ago packgroup.php 4 years ago packorder.php 1 year ago payment.php 4 years ago rate.php 4 years ago reportsemp.php 4 years ago reportsser.php 4 years ago reservation.php 1 month ago restriction.php 4 years ago review.php 4 years ago service.php 1 year ago serworkday.php 5 months ago state.php 4 years ago statuscode.php 4 years ago subscription.php 4 years ago subscrorder.php 4 years ago tag.php 4 years ago tax.php 4 years ago usernote.php 4 years ago waitinglist.php 4 years ago webhook.php 4 years ago wizard.php 1 year ago
restriction.php
320 lines
1 <?php
2 /**
3 * @package VikAppointments
4 * @subpackage core
5 * @author E4J s.r.l.
6 * @copyright Copyright (C) 2021 E4J s.r.l. All Rights Reserved.
7 * @license http://www.gnu.org/licenses/gpl-2.0.html GNU/GPL
8 * @link https://vikwp.com
9 */
10
11 // No direct access
12 defined('ABSPATH') or die('No script kiddies please!');
13
14 VAPLoader::import('libraries.mvc.controllers.admin');
15
16 /**
17 * VikAppointments special restriction controller.
18 *
19 * @since 1.7
20 */
21 class VikAppointmentsControllerRestriction extends VAPControllerAdmin
22 {
23 /**
24 * Task used to access the creation page of a new record.
25 *
26 * @return boolean
27 */
28 public function add()
29 {
30 $app = JFactory::getApplication();
31 $user = JFactory::getUser();
32
33 // unset user state for being recovered again
34 $app->setUserState('vap.restriction.data', array());
35
36 // check user permissions
37 if (!$user->authorise('core.create', 'com_vikappointments') || !$user->authorise('core.access.services', 'com_vikappointments'))
38 {
39 // back to main list, not authorised to create records
40 $app->enqueueMessage(JText::translate('JERROR_ALERTNOAUTHOR'), 'error');
41 $this->cancel();
42
43 return false;
44 }
45
46 $this->setRedirect('index.php?option=com_vikappointments&view=managerestriction');
47
48 return true;
49 }
50
51 /**
52 * Task used to access the management page of an existing record.
53 *
54 * @return boolean
55 */
56 public function edit()
57 {
58 $app = JFactory::getApplication();
59 $user = JFactory::getUser();
60
61 // unset user state for being recovered again
62 $app->setUserState('vap.restriction.data', array());
63
64 // check user permissions
65 if (!$user->authorise('core.edit', 'com_vikappointments') || !$user->authorise('core.access.services', 'com_vikappointments'))
66 {
67 // back to main list, not authorised to edit records
68 $app->enqueueMessage(JText::translate('JERROR_ALERTNOAUTHOR'), 'error');
69 $this->cancel();
70
71 return false;
72 }
73
74 $cid = $app->input->getUint('cid', array(0));
75
76 $this->setRedirect('index.php?option=com_vikappointments&view=managerestriction&cid[]=' . $cid[0]);
77
78 return true;
79 }
80
81 /**
82 * Task used to save the record data set in the request.
83 * After saving, the user is redirected to the main list.
84 *
85 * @return void
86 */
87 public function saveclose()
88 {
89 if ($this->save())
90 {
91 $this->cancel();
92 }
93 }
94
95 /**
96 * Task used to save the record data set in the request.
97 * After saving, the user is redirected to the creation
98 * page of a new record.
99 *
100 * @return void
101 */
102 public function savenew()
103 {
104 if ($this->save())
105 {
106 $this->setRedirect('index.php?option=com_vikappointments&task=restriction.add');
107 }
108 }
109
110 /**
111 * Task used to save the record data as a copy of the current item.
112 * After saving, the user is redirected to the management
113 * page of the record that has been saved.
114 *
115 * @return void
116 */
117 public function savecopy()
118 {
119 $this->save(true);
120 }
121
122 /**
123 * Task used to save the record data set in the request.
124 * After saving, the user is redirected to the management
125 * page of the record that has been saved.
126 *
127 * @param boolean $copy True to save the record as a copy.
128 *
129 * @return boolean
130 */
131 public function save($copy = false)
132 {
133 $app = JFactory::getApplication();
134 $input = $app->input;
135 $user = JFactory::getUser();
136
137 /**
138 * Added token validation.
139 *
140 * @since 1.7
141 */
142 if (!JSession::checkToken())
143 {
144 // back to main list, missing CSRF-proof token
145 $app->enqueueMessage(JText::translate('JINVALID_TOKEN'), 'error');
146 $this->cancel();
147
148 return false;
149 }
150
151 $args = array();
152 $args['name'] = $input->getString('name');
153 $args['published'] = $input->getUint('published', 0);
154 $args['maxapp'] = $input->getUint('maxapp', 1);
155 $args['interval'] = $input->getString('interval');
156 $args['mode'] = $input->getUint('mode', 1);
157 $args['usergroups'] = $input->getString('usergroups', array());
158 $args['services'] = $input->getUint('services', array());
159 $args['id'] = $input->getUint('id', 0);
160
161 if ($copy)
162 {
163 // unset ID to create a copy
164 $args['id'] = 0;
165 }
166
167 $rule = 'core.' . ($args['id'] > 0 ? 'edit' : 'create');
168
169 // check user permissions
170 if (!$user->authorise($rule, 'com_vikappointments') || !$user->authorise('core.access.services', 'com_vikappointments'))
171 {
172 // back to main list, not authorised to create/edit records
173 $app->enqueueMessage(JText::translate('JERROR_ALERTNOAUTHOR'), 'error');
174 $this->cancel();
175
176 return false;
177 }
178
179 // get restriction model
180 $restr = $this->getModel();
181
182 // try to save arguments
183 $id = $restr->save($args);
184
185 if (!$id)
186 {
187 // get string error
188 $error = $restr->getError(null, true);
189
190 // display error message
191 $app->enqueueMessage(JText::sprintf('JLIB_APPLICATION_ERROR_SAVE_FAILED', $error), 'error');
192
193 $url = 'index.php?option=com_vikappointments&view=managerestriction';
194
195 if ($args['id'])
196 {
197 $url .= '&cid[]=' . $args['id'];
198 }
199
200 // redirect to new/edit page
201 $this->setRedirect($url);
202
203 return false;
204 }
205
206 // display generic successful message
207 $app->enqueueMessage(JText::translate('JLIB_APPLICATION_SAVE_SUCCESS'));
208
209 // redirect to edit page
210 $this->setRedirect('index.php?option=com_vikappointments&task=restriction.edit&cid[]=' . $id);
211
212 return true;
213 }
214
215 /**
216 * Deletes a list of records set in the request.
217 *
218 * @return boolean
219 */
220 public function delete()
221 {
222 $app = JFactory::getApplication();
223 $user = JFactory::getUser();
224
225 /**
226 * Added token validation.
227 * Both GET and POST are supported.
228 *
229 * @since 1.7
230 */
231 if (!JSession::checkToken() && !JSession::checkToken('get'))
232 {
233 // back to main list, missing CSRF-proof token
234 $app->enqueueMessage(JText::translate('JINVALID_TOKEN'), 'error');
235 $this->cancel();
236
237 return false;
238 }
239
240 $cid = $app->input->get('cid', array(), 'uint');
241
242 // check user permissions
243 if (!$user->authorise('core.delete', 'com_vikappointments') || !$user->authorise('core.access.services', 'com_vikappointments'))
244 {
245 // back to main list, not authorised to delete records
246 $app->enqueueMessage(JText::translate('JERROR_ALERTNOAUTHOR'), 'error');
247 $this->cancel();
248
249 return false;
250 }
251
252 // delete selected records
253 $this->getModel()->delete($cid);
254
255 // back to main list
256 $this->cancel();
257
258 return true;
259 }
260
261 /**
262 * Publishes the selected records.
263 *
264 * @return boolean
265 */
266 public function publish()
267 {
268 $app = JFactory::getApplication();
269 $user = JFactory::getUser();
270
271 /**
272 * Added token validation.
273 * Both GET and POST are supported.
274 *
275 * @since 1.7
276 */
277 if (!JSession::checkToken() && !JSession::checkToken('get'))
278 {
279 // back to main list, missing CSRF-proof token
280 $app->enqueueMessage(JText::translate('JINVALID_TOKEN'), 'error');
281 $this->cancel();
282
283 return false;
284 }
285
286 $cid = $app->input->get('cid', array(), 'uint');
287 $task = $app->input->get('task', null);
288
289 $state = $task == 'unpublish' ? 0 : 1;
290
291 // check user permissions
292 if (!$user->authorise('core.edit.state', 'com_vikappointments') || !$user->authorise('core.access.services', 'com_vikappointments'))
293 {
294 // back to main list, not authorised to edit records
295 $app->enqueueMessage(JText::translate('JERROR_ALERTNOAUTHOR'), 'error');
296 $this->cancel();
297
298 return false;
299 }
300
301 // change state of selected records
302 $this->getModel()->publish($cid, $state);
303
304 // back to main list
305 $this->cancel();
306
307 return true;
308 }
309
310 /**
311 * Redirects the users to the main records list.
312 *
313 * @return void
314 */
315 public function cancel()
316 {
317 $this->setRedirect('index.php?option=com_vikappointments&view=restrictions');
318 }
319 }
320