]> git.wh0rd.org - tt-rss.git/blobdiff - modules/pref-prefs.php
use SSL serial to bind certificate to user; implement autologin using SSL certificate...
[tt-rss.git] / modules / pref-prefs.php
index 2133715a2df99e0eb8eeae98cf9d4426e566ecce..1a2b2cd77080f9b1b8e6963c727d6f80bee0df49 100644 (file)
@@ -1,12 +1,4 @@
 <?php
-       function prefs_js_redirect() {
-               print "<html><body>
-                       <script type=\"text/javascript\">
-                               window.location = 'prefs.php';
-                       </script>
-                       </body></html>";
-       }
-
        function module_pref_prefs($link) {
 
                global $access_level_names;
                $subop = $_REQUEST["subop"];
 
                $prefs_blacklist = array("HIDE_FEEDLIST", "SYNC_COUNTERS", "ENABLE_LABELS",
-                       "ENABLE_SEARCH_TOOLBAR", "HIDE_READ_FEEDS", "ENABLE_FEED_ICONS", 
-                       "ENABLE_OFFLINE_READING", "EXTENDED_FEEDLIST");
+                       "ENABLE_SEARCH_TOOLBAR", "HIDE_READ_FEEDS", "ENABLE_FEED_ICONS",
+                       "ENABLE_OFFLINE_READING", "EXTENDED_FEEDLIST", "FEEDS_SORT_BY_UNREAD",
+                       "OPEN_LINKS_IN_NEW_WINDOW", "USER_STYLESHEET_URL", "ENABLE_FLASH_PLAYER");
 
-               $profile_blacklist = array("ALLOW_DUPLICATE_POSTS", "PURGE_OLD_DAYS", 
-                       "PURGE_UNREAD_ARTICLES", "DIGEST_ENABLE", "DIGEST_CATCHUP", 
+               $profile_blacklist = array("ALLOW_DUPLICATE_POSTS", "PURGE_OLD_DAYS",
+                       "PURGE_UNREAD_ARTICLES", "DIGEST_ENABLE", "DIGEST_CATCHUP",
                        "BLACKLISTED_TAGS", "ENABLE_FEED_ICONS", "ENABLE_API_ACCESS",
                        "UPDATE_POST_ON_CHECKSUM_CHANGE", "DEFAULT_UPDATE_INTERVAL",
                        "MARK_UNREAD_ON_UPDATE", "USER_TIMEZONE", "SORT_HEADLINES_BY_FEED_DATE");
@@ -30,9 +23,9 @@
 
                if ($subop == "change-password") {
 
-                       $old_pw = $_POST["OLD_PASSWORD"];
-                       $new_pw = $_POST["NEW_PASSWORD"];
-                       $con_pw = $_POST["CONFIRM_PASSWORD"];
+                       $old_pw = $_POST["old_password"];
+                       $new_pw = $_POST["new_password"];
+                       $con_pw = $_POST["confirm_password"];
 
                        if ($old_pw == "") {
                                print "ERROR: ".__("Old password cannot be blank.");
                                return;
                        }
 
-                       $old_pw_hash1 = encrypt_password($_POST["OLD_PASSWORD"]);
-                       $old_pw_hash2 = encrypt_password($_POST["OLD_PASSWORD"],
-                               $_SESSION["name"]);
-
-                       $new_pw_hash = encrypt_password($_POST["NEW_PASSWORD"],
-                               $_SESSION["name"]);
+                       $old_pw_hash1 = encrypt_password($old_pw);
+                       $old_pw_hash2 = encrypt_password($old_pw, $_SESSION["name"]);
+                       $new_pw_hash = encrypt_password($new_pw, $_SESSION["name"]);
 
                        $active_uid = $_SESSION["uid"];
-                       
+
                        if ($old_pw && $new_pw) {
 
                                $login = db_escape_string($_SERVER['PHP_AUTH_USER']);
 
-                               $result = db_query($link, "SELECT id FROM ttrss_users WHERE 
-                                       id = '$active_uid' AND (pwd_hash = '$old_pw_hash1' OR 
+                               $result = db_query($link, "SELECT id FROM ttrss_users WHERE
+                                       id = '$active_uid' AND (pwd_hash = '$old_pw_hash1' OR
                                                pwd_hash = '$old_pw_hash2')");
 
                                if (db_num_rows($result) == 1) {
-                                       db_query($link, "UPDATE ttrss_users SET pwd_hash = '$new_pw_hash' 
-                                               WHERE id = '$active_uid'");                             
+                                       db_query($link, "UPDATE ttrss_users SET pwd_hash = '$new_pw_hash'
+                                               WHERE id = '$active_uid'");
 
                                        $_SESSION["pwd_hash"] = $new_pw_hash;
 
@@ -91,7 +81,7 @@
                        $orig_theme = get_pref($link, "_THEME_ID");
 
                        foreach (array_keys($_POST) as $pref_name) {
-                       
+
                                $pref_name = db_escape_string($pref_name);
                                $value = db_escape_string($_POST[$pref_name]);
 
                        $active_uid = $_SESSION["uid"];
 
                        db_query($link, "UPDATE ttrss_users SET email = '$email',
-                               full_name = '$full_name' WHERE id = '$active_uid'");                            
-               
+                               full_name = '$full_name' WHERE id = '$active_uid'");
+
                        print __("Your personal data has been saved.");
-               
+
                        return;
 
                } else if ($subop == "reset-config") {
                                $profile_qpart = "profile IS NULL";
                        }
 
-                       db_query($link, "DELETE FROM ttrss_user_prefs 
+                       db_query($link, "DELETE FROM ttrss_user_prefs
                                WHERE $profile_qpart AND owner_uid = ".$_SESSION["uid"]);
 
                        initialize_user_prefs($link, $_SESSION["uid"], $_SESSION["profile"]);
 
                } else {
 
-                       set_pref($link, "_PREFS_ACTIVE_TAB", "genConfig");
-
-                       if ($_SESSION["profile"]) {
-                               print_notice("Some preferences are only available in default profile.");
-                       }
-
                        if (!SINGLE_USER_MODE) {
 
-                               $result = db_query($link, "SELECT id FROM ttrss_users
-                                       WHERE id = ".$_SESSION["uid"]." AND pwd_hash 
-                                       = 'SHA1:5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8'");
-
-                               if (db_num_rows($result) != 0) {
-                                       print format_warning(__("Your password is at default value, 
-                                               please change it."), "default_pass_warning");
-                               }
+                               $_SESSION["prefs_op_result"] = "";
 
-/*                             if ($_SESSION["pwd_change_result"] == "failed") {
-                                       print format_warning("Could not change the password.");
-                               }
+                               print "<div dojoType=\"dijit.layout.AccordionContainer\" region=\"center\">";
+                               print "<div dojoType=\"dijit.layout.AccordionPane\" title=\"".__('Personal data')."\">";
 
-                               if ($_SESSION["pwd_change_result"] == "ok") {
-                                       print format_notice("Password was changed.");
-                               }
+                               print "<form dojoType=\"dijit.form.Form\" id=\"changeUserdataForm\">";
 
-                               $_SESSION["pwd_change_result"] = ""; */
+                               print "<script type=\"dojo/method\" event=\"onSubmit\" args=\"evt\">
+                               evt.preventDefault();
+                               if (this.validate()) {
+                                       notify_progress('Saving data...', true);
 
-/*                             if ($_SESSION["prefs_op_result"] == "reset-to-defaults") {
-                                       print format_notice(__("The configuration was reset to defaults."));
-} */
+                                       new Ajax.Request('backend.php', {
+                                               parameters: dojo.objectToQuery(this.getValues()),
+                                               onComplete: function(transport) {
+                                                       notify_callback2(transport);
+                                       } });
 
-#                              if ($_SESSION["prefs_op_result"] == "save-config") {
-#                                      print format_notice(__("The configuration was saved."));
-#                              }
-
-                               $_SESSION["prefs_op_result"] = "";
+                               }
+                               </script>";
 
-                               print "<form onsubmit='return false' id='change_email_form'>";
-       
                                print "<table width=\"100%\" class=\"prefPrefsList\">";
-                               print "<tr><td colspan='3'><h3>".__("Personal data")."</h3></tr></td>";
 
                                $result = db_query($link, "SELECT email,full_name,
                                        access_level FROM ttrss_users
                                        WHERE id = ".$_SESSION["uid"]);
-                                       
+
                                $email = htmlspecialchars(db_fetch_result($result, 0, "email"));
                                $full_name = htmlspecialchars(db_fetch_result($result, 0, "full_name"));
 
                                print "<tr><td width=\"40%\">".__('Full name')."</td>";
-                               print "<td class=\"prefValue\"><input class=\"editbox\" name=\"full_name\" 
-                                       onfocus=\"javascript:disableHotkeys();\" 
-                                       onblur=\"javascript:enableHotkeys();\"
-                                       onkeypress=\"return filterCR(event, changeUserEmail)\"
+                               print "<td class=\"prefValue\"><input dojoType=\"dijit.form.ValidationTextBox\" name=\"full_name\" required=\"1\"
                                        value=\"$full_name\"></td></tr>";
 
                                print "<tr><td width=\"40%\">".__('E-mail')."</td>";
-                               print "<td class=\"prefValue\"><input class=\"editbox\" name=\"email\" 
-                                       onfocus=\"javascript:disableHotkeys();\" 
-                                       onblur=\"javascript:enableHotkeys();\"
-                                       onkeypress=\"return filterCR(event, changeUserEmail)\"
-                                       value=\"$email\"></td></tr>";
+                               print "<td class=\"prefValue\"><input dojoType=\"dijit.form.ValidationTextBox\" name=\"email\" required=\"1\" value=\"$email\"></td></tr>";
 
                                if (!SINGLE_USER_MODE) {
-
                                        $access_level = db_fetch_result($result, 0, "access_level");
-
                                        print "<tr><td width=\"40%\">".__('Access level')."</td>";
                                        print "<td>" . $access_level_names[$access_level] . "</td></tr>";
-
                                }
-       
+
                                print "</table>";
-       
-                               print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
-                               print "<input type=\"hidden\" name=\"subop\" value=\"change-email\">";
 
-                               print "</form>";
+                               print "<input dojoType=\"dijit.form.TextBox\" style=\"display : none\" name=\"op\" value=\"pref-prefs\">";
+                               print "<input dojoType=\"dijit.form.TextBox\" style=\"display : none\" name=\"subop\" value=\"change-email\">";
 
-                               print "<p><button onclick=\"return changeUserEmail()\">".
+                               print "<p><button dojoType=\"dijit.form.Button\" type=\"submit\">".
                                        __("Save data")."</button>";
 
-                               print "<form onsubmit=\"return false\" 
-                                       name=\"change_pass_form\" id=\"change_pass_form\">";
-       
+                               print "</form>";
+
+                               print "</div>"; # pane
+                               print "<div dojoType=\"dijit.layout.AccordionPane\" title=\"".__('Authentication')."\">";
+
+                               $result = db_query($link, "SELECT id FROM ttrss_users
+                                       WHERE id = ".$_SESSION["uid"]." AND pwd_hash
+                                       = 'SHA1:5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8'");
+
+                               if (db_num_rows($result) != 0) {
+                                       print format_warning(__("Your password is at default value, please change it."), "default_pass_warning");
+                               }
+
+                               print "<form dojoType=\"dijit.form.Form\">";
+
+                               print "<script type=\"dojo/method\" event=\"onSubmit\" args=\"evt\">
+                               evt.preventDefault();
+                               if (this.validate()) {
+                                       notify_progress('Changing password...', true);
+
+                                       new Ajax.Request('backend.php', {
+                                               parameters: dojo.objectToQuery(this.getValues()),
+                                               onComplete: function(transport) {
+                                                       notify('');
+                                                       if (transport.responseText.indexOf('ERROR: ') == 0) {
+                                                               notify_error(transport.responseText.replace('ERROR: ', ''));
+                                                       } else {
+                                                               notify_info(transport.responseText);
+                                                               var warn = $('default_pass_warning');
+                                                               if (warn) Element.hide(warn);
+                                                       }
+                                       }});
+                                       this.reset();
+                               }
+                               </script>";
+
                                print "<table width=\"100%\" class=\"prefPrefsList\">";
-                               print "<tr><td colspan='3'><h3>".__("Authentication")."</h3></tr></td>";
-       
+
                                print "<tr><td width=\"40%\">".__("Old password")."</td>";
-                               print "<td class=\"prefValue\"><input class=\"editbox\" type=\"password\"
-                                       onfocus=\"javascript:disableHotkeys();\" 
-                                       onblur=\"javascript:enableHotkeys();\"
-                                       onkeypress=\"return filterCR(event, changeUserPassword)\"
-                                       name=\"OLD_PASSWORD\"></td></tr>";
-       
+                               print "<td class=\"prefValue\"><input dojoType=\"dijit.form.ValidationTextBox\" type=\"password\" required=\"1\" name=\"old_password\"></td></tr>";
+
                                print "<tr><td width=\"40%\">".__("New password")."</td>";
-                               
-                               print "<td class=\"prefValue\"><input class=\"editbox\" type=\"password\"
-                                       onfocus=\"javascript:disableHotkeys();\" 
-                                       onblur=\"javascript:enableHotkeys();\"
-                                       onkeypress=\"return filterCR(event, changeUserPassword)\"
-                                       name=\"NEW_PASSWORD\"></td></tr>";
+
+                               print "<td class=\"prefValue\"><input dojoType=\"dijit.form.ValidationTextBox\" type=\"password\" required=\"1\"
+                                       name=\"new_password\"></td></tr>";
 
                                print "<tr><td width=\"40%\">".__("Confirm password")."</td>";
 
-                               print "<td class=\"prefValue\"><input class=\"editbox\" type=\"password\"
-                                       onfocus=\"javascript:disableHotkeys();\" 
-                                       onblur=\"javascript:enableHotkeys();\"
-                                       onkeypress=\"return filterCR(event, changeUserPassword)\"
-                                       name=\"CONFIRM_PASSWORD\"></td></tr>";
+                               print "<td class=\"prefValue\"><input dojoType=\"dijit.form.ValidationTextBox\" type=\"password\" required=\"1\" name=\"confirm_password\"></td></tr>";
 
                                print "</table>";
-       
-                               print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
-                               print "<input type=\"hidden\" name=\"subop\" value=\"change-password\">";
 
-                               print "</form>";
+                               print "<input dojoType=\"dijit.form.TextBox\" style=\"display : none\" name=\"op\" value=\"pref-prefs\">";
+                               print "<input dojoType=\"dijit.form.TextBox\" style=\"display : none\" name=\"subop\" value=\"change-password\">";
 
-                               print "<p><button       onclick=\"return changeUserPassword()\">".
+                               print "<p><button dojoType=\"dijit.form.Button\" type=\"submit\">".
                                        __("Change password")."</button>";
 
+                               print "</form>";
+
+                               print "</div>"; #pane
+                       }
+
+                       print "<div dojoType=\"dijit.layout.AccordionPane\" selected=\"true\" title=\"".__('Preferences')."\">";
+
+                       if ($_SESSION["profile"]) {
+                               print_notice("Some preferences are only available in default profile.");
                        }
 
                        if ($_SESSION["profile"]) {
                                $profile_qpart = "profile IS NULL";
                        }
 
-                       $result = db_query($link, "SELECT 
+                       $result = db_query($link, "SELECT
                                ttrss_user_prefs.pref_name,short_desc,help_text,value,type_name,
                                section_name,def_value,section_id
                                FROM ttrss_prefs,ttrss_prefs_types,ttrss_prefs_sections,ttrss_user_prefs
-                               WHERE type_id = ttrss_prefs_types.id AND 
+                               WHERE type_id = ttrss_prefs_types.id AND
                                        $profile_qpart AND
                                        section_id = ttrss_prefs_sections.id AND
                                        ttrss_user_prefs.pref_name = ttrss_prefs.pref_name AND
                                        owner_uid = ".$_SESSION["uid"]."
                                ORDER BY section_id,short_desc");
 
-                       print "<form onsubmit='return false' action=\"backend.php\" 
-                               method=\"POST\" id=\"pref_prefs_form\">";
+                       print "<form dojoType=\"dijit.form.Form\" id=\"changeSettingsForm\">";
+
+                       print "<script type=\"dojo/method\" event=\"onSubmit\" args=\"evt\">
+                       evt.preventDefault();
+                       if (this.validate()) {
+                               console.log(dojo.objectToQuery(this.getValues()));
+
+                               new Ajax.Request('backend.php', {
+                                       parameters: dojo.objectToQuery(this.getValues()),
+                                       onComplete: function(transport) {
+                                               var msg = transport.responseText;
+                                               if (msg.match('PREFS_THEME_CHANGED')) {
+                                                       window.location.reload();
+                                               } else {
+                                                       notify_info(msg);
+                                               }
+                               } });
+                       }
+                       </script>";
 
                        $lnum = 0;
 
                        $active_section = "";
-       
+
                        while ($line = db_fetch_assoc($result)) {
 
                                if (in_array($line["pref_name"], $prefs_blacklist)) {
                                        continue;
                                }
 
-                               if ($_SESSION["profile"] && in_array($line["pref_name"], 
+                               if ($_SESSION["profile"] && in_array($line["pref_name"],
                                                $profile_blacklist)) {
                                        continue;
                                }
                                                print "</table>";
                                        }
 
-                                       print "<p><table width=\"100%\" class=\"prefPrefsList\">";
+                                       print "<table width=\"100%\" class=\"prefPrefsList\">";
+
+                                       $active_section = $line["section_name"];
 
-                                       $active_section = $line["section_name"];                                
-                                       
                                        print "<tr><td colspan=\"3\"><h3>".__($active_section)."</h3></td></tr>";
 
                                        if ($line["section_id"] == 2) {
                                                $user_theme = get_pref($link, "_THEME_ID");
                                                $themes = get_all_themes();
 
-                                               print "<td><select name=\"_THEME_ID\">";
-                                               print "<option value=''>".__('Default')."</option>";
-                                               print "<option disabled>--------</option>";                             
+                                               print "<td><select name=\"_THEME_ID\" dojoType=\"dijit.form.Select\">";
+                                               print "<option value='Default'>".__('Default')."</option>";
+                                               print "<option value='----------------' disabled=\"1\">--------</option>";
 
                                                foreach ($themes as $t) {
                                                        $base = $t['base'];
                                                        print "<option $selected value='$base'>$name</option>";
 
                                                }
-                       
+
                                                print "</select></td></tr>";
                                        }
 
                                print "<td width=\"40%\" class=\"prefName\" id=\"$pref_name\">" . __($line["short_desc"]);
 
                                if ($help_text) print "<div class=\"prefHelp\">".__($help_text)."</div>";
-                               
+
                                print "</td>";
 
                                print "<td class=\"prefValue\">";
 
                                        $timezones = explode("\n", file_get_contents("lib/timezones.txt"));
 
-                                       print_select($pref_name, $value, $timezones);
+                                       print_select($pref_name, $value, $timezones, 'dojoType="dijit.form.FilteringSelect"');
+                               } else if ($pref_name == "USER_STYLESHEET") {
+
+                                       print "<button dojoType=\"dijit.form.Button\"
+                                               onclick=\"customizeCSS()\">" . __('Customize') . "</button>";
+
+                               } else if ($pref_name == "DEFAULT_ARTICLE_LIMIT") {
+
+                                       $limits = array(15, 30, 45, 60);
+
+                                       print_select($pref_name, $value, $limits,
+                                               'dojoType="dijit.form.Select"');
 
                                } else if ($pref_name == "DEFAULT_UPDATE_INTERVAL") {
 
                                        global $update_intervals_nodefault;
 
-                                       print_select_hash($pref_name, $value, $update_intervals_nodefault);
+                                       print_select_hash($pref_name, $value, $update_intervals_nodefault,
+                                               'dojoType="dijit.form.Select"');
 
                                } else if ($type_name == "bool") {
 //                                     print_select($pref_name, $value, array("true", "false"));
                                        }
 
                                        print_radio($pref_name, $value, __("Yes"), array(__("Yes"), __("No")));
-                       
+
+                               } else if (array_search($pref_name, array('FRESH_ARTICLE_MAX_AGE', 'DEFAULT_ARTICLE_LIMIT',
+                                               'PURGE_OLD_DAYS', 'LONG_DATE_FORMAT', 'SHORT_DATE_FORMAT')) !== false) {
+
+                                       $regexp = ($type_name == 'integer') ? 'regexp="^\d*$"' : '';
+
+                                       print "<input dojoType=\"dijit.form.ValidationTextBox\"
+                                               required=\"1\" $regexp
+                                               name=\"$pref_name\" value=\"$value\">";
+
+                               } else if ($pref_name == "SSL_CERT_SERIAL") {
+
+                                       print "<input dojoType=\"dijit.form.ValidationTextBox\"
+                                               id=\"SSL_CERT_SERIAL\"
+                                               name=\"$pref_name\" value=\"$value\">";
+
+                                       $cert_serial = htmlspecialchars($_SERVER["REDIRECT_SSL_CLIENT_M_SERIAL"]);
+
+                                       if ($cert_serial) {
+                                               print " <button dojoType=\"dijit.form.Button\"
+                                                       onclick=\"insertSSLserial('$cert_serial')\">" .
+                                                       __('Fill automatically') . "</button>";
+                                       }
+
                                } else {
-                                       print "<input class=\"editbox\"
-                                               onfocus=\"javascript:disableHotkeys();\" 
-                                               onblur=\"javascript:enableHotkeys();\"  
+                                       $regexp = ($type_name == 'integer') ? 'regexp="^\d*$"' : '';
+
+                                       print "<input dojoType=\"dijit.form.ValidationTextBox\"
+                                               $regexp
                                                name=\"$pref_name\" value=\"$value\">";
                                }
 
 
                        print "</table>";
 
-                       print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
+                       print "<input dojoType=\"dijit.form.TextBox\" style=\"display : none\" name=\"op\" value=\"pref-prefs\">";
+                       print "<input dojoType=\"dijit.form.TextBox\" style=\"display : none\" name=\"subop\" value=\"save-config\">";
 
-                       print "<p><button onclick=\"return validatePrefsSave()\">".
+                       print "<p><button dojoType=\"dijit.form.Button\" type=\"submit\">".
                                __('Save configuration')."</button> ";
 
-                       print "<button onclick=\"return editProfiles()\">".
+                       print "<button dojoType=\"dijit.form.Button\" onclick=\"return editProfiles()\">".
                                __('Manage profiles')."</button> ";
 
-                       print "<button onclick=\"return validatePrefsReset()\">".
+                       print "<button dojoType=\"dijit.form.Button\" onclick=\"return validatePrefsReset()\">".
                                __('Reset to defaults')."</button></p>";
 
                        print "</form>";
 
+                       print "</div>"; #pane
+                       print "</div>"; #container
+
                }
        }
 ?>