]> git.wh0rd.org - tt-rss.git/blame - modules/pref-prefs.php
implement blacklist for disabled prefs options
[tt-rss.git] / modules / pref-prefs.php
CommitLineData
ef8be8ea 1<?php
f27d955a
AD
2 function prefs_js_redirect() {
3 print "<html><body>
4 <script type=\"text/javascript\">
5 window.location = 'prefs.php';
6 </script>
7 </body></html>";
8 }
9
ef8be8ea
AD
10 function module_pref_prefs($link) {
11 $subop = $_REQUEST["subop"];
12
4bb2b579
AD
13 $prefs_blacklist = array();
14 //$prefs_blacklist = array("HIDE_FEEDLIST");
15
d95bd220
AD
16 if ($subop == "change-password") {
17
18 $old_pw = $_POST["OLD_PASSWORD"];
19 $new_pw = $_POST["NEW_PASSWORD"];
20 $con_pw = $_POST["CONFIRM_PASSWORD"];
21
22 if ($old_pw == "") {
7990ac73 23 print "ERROR: ".__("Old password cannot be blank.");
d95bd220
AD
24 return;
25 }
26
27 if ($new_pw == "") {
7990ac73 28 print "ERROR: ".__("New password cannot be blank.");
d95bd220
AD
29 return;
30 }
31
32 if ($new_pw != $con_pw) {
7990ac73 33 print "ERROR: ".__("Entered passwords do not match.");
d95bd220
AD
34 return;
35 }
36
1a9f4d3c
AD
37 $old_pw_hash1 = encrypt_password($_POST["OLD_PASSWORD"]);
38 $old_pw_hash2 = encrypt_password($_POST["OLD_PASSWORD"],
39 $_SESSION["name"]);
40
41 $new_pw_hash = encrypt_password($_POST["NEW_PASSWORD"],
42 $_SESSION["name"]);
d95bd220
AD
43
44 $active_uid = $_SESSION["uid"];
45
46 if ($old_pw && $new_pw) {
47
48 $login = db_escape_string($_SERVER['PHP_AUTH_USER']);
49
50 $result = db_query($link, "SELECT id FROM ttrss_users WHERE
1a9f4d3c
AD
51 id = '$active_uid' AND (pwd_hash = '$old_pw_hash1' OR
52 pwd_hash = '$old_pw_hash2')");
d95bd220
AD
53
54 if (db_num_rows($result) == 1) {
55 db_query($link, "UPDATE ttrss_users SET pwd_hash = '$new_pw_hash'
56 WHERE id = '$active_uid'");
57
7990ac73 58 print __("Password has been changed.");
d95bd220 59 } else {
7990ac73 60 print "ERROR: ".__('Old password is incorrect.');
d95bd220
AD
61 }
62 }
63
64 return;
d95bd220 65
b652c1b7 66 } else if ($subop == "save-config") {
ef8be8ea 67
b652c1b7 68# $_SESSION["prefs_op_result"] = "save-config";
ef8be8ea
AD
69
70 $_SESSION["prefs_cache"] = false;
71
f541eb78
AD
72// print_r($_POST);
73
ef8be8ea
AD
74 foreach (array_keys($_POST) as $pref_name) {
75
76 $pref_name = db_escape_string($pref_name);
77 $value = db_escape_string($_POST[$pref_name]);
78
79 $result = db_query($link, "SELECT type_name
80 FROM ttrss_prefs,ttrss_prefs_types
81 WHERE pref_name = '$pref_name' AND type_id = ttrss_prefs_types.id");
82
83 if (db_num_rows($result) > 0) {
84
85 $type_name = db_fetch_result($result, 0, "type_name");
86
87// print "$pref_name : $type_name : $value<br>";
88
89 if ($type_name == "bool") {
90 if ($value == "1") {
91 $value = "true";
92 } else {
93 $value = "false";
94 }
95 } else if ($type_name == "integer") {
96 $value = sprintf("%d", $value);
97 }
98
99// print "$pref_name : $type_name : $value<br>";
100
101 db_query($link, "UPDATE ttrss_user_prefs SET value = '$value'
102 WHERE pref_name = '$pref_name' AND owner_uid = ".$_SESSION["uid"]);
103
104 }
105
ef8be8ea
AD
106 }
107
b652c1b7
AD
108 #return prefs_js_redirect();
109
110 print __("The configuration was saved.");
111
112 return;
f27d955a 113
ef8be8ea
AD
114 } else if ($subop == "getHelp") {
115
116 $pref_name = db_escape_string($_GET["pn"]);
117
118 $result = db_query($link, "SELECT help_text FROM ttrss_prefs
119 WHERE pref_name = '$pref_name'");
120
121 if (db_num_rows($result) > 0) {
122 $help_text = db_fetch_result($result, 0, "help_text");
123 print $help_text;
124 } else {
125 print "Unknown option: $pref_name";
126 }
127
42395d28 128 } else if ($subop == "change-email") {
ef8be8ea 129
42395d28 130 $email = db_escape_string($_POST["email"]);
ef8be8ea
AD
131 $active_uid = $_SESSION["uid"];
132
42395d28
AD
133 db_query($link, "UPDATE ttrss_users SET email = '$email'
134 WHERE id = '$active_uid'");
135
b652c1b7 136 print __("E-mail has been changed.");
42395d28
AD
137
138 return;
ef8be8ea 139
b652c1b7 140 } else if ($subop == "reset-config") {
ef8be8ea 141
ef8be8ea
AD
142 $_SESSION["prefs_op_result"] = "reset-to-defaults";
143
eb7ab952
AD
144 db_query($link, "DELETE FROM ttrss_user_prefs
145 WHERE owner_uid = ".$_SESSION["uid"]);
146 initialize_user_prefs($link, $_SESSION["uid"]);
ef8be8ea 147
b652c1b7
AD
148 print __("The configuration was reset to defaults.");
149
150 return;
ef8be8ea 151
f541eb78 152 } else if ($subop == __("Change theme")) {
ef8be8ea
AD
153
154 $theme = db_escape_string($_POST["theme"]);
155
156 if ($theme == "Default") {
157 $theme_qpart = 'NULL';
158 } else {
159 $theme_qpart = "'$theme'";
160 }
161
162 $result = db_query($link, "SELECT id,theme_path FROM ttrss_themes
163 WHERE theme_name = '$theme'");
164
165 if (db_num_rows($result) == 1) {
166 $theme_id = db_fetch_result($result, 0, "id");
167 $theme_path = db_fetch_result($result, 0, "theme_path");
168 } else {
169 $theme_id = "NULL";
170 $theme_path = "";
171 }
172
173 db_query($link, "UPDATE ttrss_users SET
174 theme_id = $theme_id WHERE id = " . $_SESSION["uid"]);
175
176 $_SESSION["theme"] = $theme_path;
177
f27d955a 178 return prefs_js_redirect();
ef8be8ea
AD
179
180 } else {
181
2b2044bc 182// print check_for_update($link);
ef8be8ea 183
fe8d2059
AD
184 set_pref($link, "_PREFS_ACTIVE_TAB", "genConfig");
185
ef8be8ea
AD
186 if (!SINGLE_USER_MODE) {
187
d84f9523
AD
188 $result = db_query($link, "SELECT id FROM ttrss_users
189 WHERE id = ".$_SESSION["uid"]." AND pwd_hash
190 = 'SHA1:5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8'");
ef8be8ea
AD
191
192 if (db_num_rows($result) != 0) {
7990ac73
AD
193 print format_warning(__("Your password is at default value,
194 please change it."), "default_pass_warning");
ef8be8ea
AD
195 }
196
d95bd220 197/* if ($_SESSION["pwd_change_result"] == "failed") {
0d32b41e 198 print format_warning("Could not change the password.");
ef8be8ea
AD
199 }
200
201 if ($_SESSION["pwd_change_result"] == "ok") {
0d32b41e 202 print format_notice("Password was changed.");
ef8be8ea
AD
203 }
204
d95bd220 205 $_SESSION["pwd_change_result"] = ""; */
ef8be8ea
AD
206
207 if ($_SESSION["prefs_op_result"] == "reset-to-defaults") {
7990ac73 208 print format_notice(__("The configuration was reset to defaults."));
ef8be8ea
AD
209 }
210
b652c1b7
AD
211# if ($_SESSION["prefs_op_result"] == "save-config") {
212# print format_notice(__("The configuration was saved."));
213# }
ef8be8ea
AD
214
215 $_SESSION["prefs_op_result"] = "";
216
42395d28 217 print "<form onsubmit='return false' id='change_email_form'>";
ef8be8ea
AD
218
219 print "<table width=\"100%\" class=\"prefPrefsList\">";
7990ac73 220 print "<tr><td colspan='3'><h3>".__("Personal data")."</h3></tr></td>";
ef8be8ea
AD
221
222 $result = db_query($link, "SELECT email FROM ttrss_users
223 WHERE id = ".$_SESSION["uid"]);
224
225 $email = db_fetch_result($result, 0, "email");
226
e400230e 227 print "<tr><td width=\"40%\">".__('E-mail')."</td>";
ef8be8ea 228 print "<td><input class=\"editbox\" name=\"email\"
42395d28 229 onkeypress=\"return filterCR(event, changeUserEmail)\"
ef8be8ea
AD
230 value=\"$email\"></td></tr>";
231
232 print "</table>";
233
234 print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
42395d28 235 print "<input type=\"hidden\" name=\"subop\" value=\"change-email\">";
ef8be8ea
AD
236
237 print "</form>";
238
42395d28 239 print "<p><input class=\"button\" type=\"submit\"
7990ac73 240 onclick=\"return changeUserEmail()\" value=\"".__("Change e-mail")."\">";
42395d28 241
e6312f6c 242 print "<form onsubmit=\"return false\"
d95bd220 243 name=\"change_pass_form\" id=\"change_pass_form\">";
ef8be8ea
AD
244
245 print "<table width=\"100%\" class=\"prefPrefsList\">";
7990ac73 246 print "<tr><td colspan='3'><h3>".__("Authentication")."</h3></tr></td>";
ef8be8ea 247
7990ac73 248 print "<tr><td width=\"40%\">".__("Old password")."</td>";
ef8be8ea 249 print "<td><input class=\"editbox\" type=\"password\"
d95bd220 250 onkeypress=\"return filterCR(event, changeUserPassword)\"
ef8be8ea
AD
251 name=\"OLD_PASSWORD\"></td></tr>";
252
7990ac73 253 print "<tr><td width=\"40%\">".__("New password")."</td>";
ef8be8ea
AD
254
255 print "<td><input class=\"editbox\" type=\"password\"
d95bd220 256 onkeypress=\"return filterCR(event, changeUserPassword)\"
ef8be8ea 257 name=\"NEW_PASSWORD\"></td></tr>";
d95bd220 258
7990ac73 259 print "<tr><td width=\"40%\">".__("Confirm password")."</td>";
d95bd220
AD
260
261 print "<td><input class=\"editbox\" type=\"password\"
262 onkeypress=\"return filterCR(event, changeUserPassword)\"
263 name=\"CONFIRM_PASSWORD\"></td></tr>";
264
ef8be8ea
AD
265 print "</table>";
266
267 print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
d95bd220
AD
268 print "<input type=\"hidden\" name=\"subop\" value=\"change-password\">";
269
ef8be8ea
AD
270 print "</form>";
271
d95bd220
AD
272 print "<p><input class=\"button\" type=\"submit\"
273 onclick=\"return changeUserPassword()\"
7990ac73 274 value=\"".__("Change password")."\">";
d95bd220 275
ef8be8ea
AD
276 }
277
278 $result = db_query($link, "SELECT
279 theme_id FROM ttrss_users WHERE id = " . $_SESSION["uid"]);
280
281 $user_theme_id = db_fetch_result($result, 0, "theme_id");
282
283 $result = db_query($link, "SELECT
284 id,theme_name FROM ttrss_themes ORDER BY theme_name");
285
286 if (db_num_rows($result) > 0) {
287
288 print "<form action=\"backend.php\" method=\"POST\">";
289 print "<table width=\"100%\" class=\"prefPrefsList\">";
7990ac73
AD
290 print "<tr><td colspan='3'><h3>".__("Themes")."</h3></tr></td>";
291 print "<tr><td width=\"40%\">".__("Select theme")."</td>";
ef8be8ea 292 print "<td><select name=\"theme\">";
89cb787e 293 print "<option value='Default'>".__('Default')."</option>";
ef8be8ea
AD
294 print "<option disabled>--------</option>";
295
296 while ($line = db_fetch_assoc($result)) {
297 if ($line["id"] == $user_theme_id) {
298 $selected = "selected";
299 } else {
300 $selected = "";
301 }
302 print "<option $selected>" . $line["theme_name"] . "</option>";
303 }
304 print "</select></td></tr>";
305 print "</table>";
306 print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
89cb787e 307 print "<input type=\"hidden\" name=\"subop\" value=\"Change theme\">";
ef8be8ea 308 print "<p><input class=\"button\" type=\"submit\"
89cb787e 309 value=\"".__('Change theme')."\">";
ef8be8ea
AD
310 print "</form>";
311 }
312
313 initialize_user_prefs($link, $_SESSION["uid"]);
314
315 $result = db_query($link, "SELECT
316 ttrss_user_prefs.pref_name,short_desc,help_text,value,type_name,
317 section_name,def_value
318 FROM ttrss_prefs,ttrss_prefs_types,ttrss_prefs_sections,ttrss_user_prefs
319 WHERE type_id = ttrss_prefs_types.id AND
320 section_id = ttrss_prefs_sections.id AND
321 ttrss_user_prefs.pref_name = ttrss_prefs.pref_name AND
40496720 322 short_desc != '' AND
ef8be8ea
AD
323 owner_uid = ".$_SESSION["uid"]."
324 ORDER BY section_id,short_desc");
325
ae661a8c
AD
326 print "<form onsubmit='return false' action=\"backend.php\"
327 method=\"POST\" id=\"pref_prefs_form\">";
ef8be8ea
AD
328
329 $lnum = 0;
330
331 $active_section = "";
332
333 while ($line = db_fetch_assoc($result)) {
334
4bb2b579
AD
335 if (in_array($line["pref_name"], $prefs_blacklist)) {
336 continue;
337 }
338
ef8be8ea
AD
339 if ($active_section != $line["section_name"]) {
340
341 if ($active_section != "") {
342 print "</table>";
343 }
344
345 print "<p><table width=\"100%\" class=\"prefPrefsList\">";
346
347 $active_section = $line["section_name"];
348
89cb787e 349 print "<tr><td colspan=\"3\"><h3>".__($active_section)."</h3></td></tr>";
ef8be8ea
AD
350// print "<tr class=\"title\">
351// <td width=\"25%\">Option</td><td>Value</td></tr>";
352
353 $lnum = 0;
354 }
355
356// $class = ($lnum % 2) ? "even" : "odd";
357
358 print "<tr>";
359
360 $type_name = $line["type_name"];
361 $pref_name = $line["pref_name"];
362 $value = $line["value"];
363 $def_value = $line["def_value"];
364 $help_text = $line["help_text"];
365
89cb787e 366 print "<td width=\"40%\" id=\"$pref_name\">" . __($line["short_desc"]);
ef8be8ea 367
89cb787e 368 if ($help_text) print "<div class=\"prefHelp\">".__($help_text)."</div>";
ef8be8ea
AD
369
370 print "</td>";
371
372 print "<td>";
373
374 if ($type_name == "bool") {
375// print_select($pref_name, $value, array("true", "false"));
376
377 if ($value == "true") {
836537f7 378 $value = __("Yes");
ef8be8ea 379 } else {
836537f7 380 $value = __("No");
ef8be8ea
AD
381 }
382
f541eb78 383 print_radio($pref_name, $value, __("Yes"), array(__("Yes"), __("No")));
ef8be8ea
AD
384
385 } else {
386 print "<input class=\"editbox\" name=\"$pref_name\" value=\"$value\">";
387 }
388
389 print "</td>";
390
391 print "</tr>";
392
393 $lnum++;
394 }
395
396 print "</table>";
397
398 print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
399
400 print "<p><input class=\"button\" type=\"submit\"
b652c1b7
AD
401 onclick=\"return validatePrefsSave()\"
402 value=\"".__('Save configuration')."\">";
ef8be8ea
AD
403
404 print "&nbsp;<input class=\"button\" type=\"submit\"
b652c1b7 405 onclick=\"return validatePrefsReset()\"
89cb787e 406 value=\"".__('Reset to defaults')."\"></p>";
ef8be8ea
AD
407
408 print "</form>";
409
410 }
411 }
412?>