]> git.wh0rd.org - tt-rss.git/blobdiff - modules/pref-users.php
subop -> method
[tt-rss.git] / modules / pref-users.php
index a57178d6c0253f4a873925abb6ef44780fe21aea..8f6ba10a2627cb377594653f561176954af69231 100644 (file)
@@ -3,46 +3,49 @@
 
                global $access_level_names;
 
-               if (!SINGLE_USER_MODE && $_SESSION["access_level"] < 10) { 
+               if (!SINGLE_USER_MODE && $_SESSION["access_level"] < 10) {
                        print __("Your access level is insufficient to open this tab.");
                        return;
                }
 
-               $subop = $_REQUEST["subop"];
+               $method = $_REQUEST["method"];
 
-               if ($subop == "user-details") {
+               if ($method == "user-details") {
+
+                       header("Content-Type: text/xml");
+                       print "<dlg id=\"$method\">";
 
                        $uid = sprintf("%d", $_REQUEST["id"]);
 
-                       print "<div id=\"infoBoxTitle\">".__('User details')."</div>";
+                       print "<title>".__('User details')."</title>";
 
-                       print "<div class='infoBoxContents'>";
+                       print "<content><![CDATA[";
 
                        $result = db_query($link, "SELECT login,
                                ".SUBSTRING_FOR_DATE."(last_login,1,16) AS last_login,
                                access_level,
-                               (SELECT COUNT(int_id) FROM ttrss_user_entries 
+                               (SELECT COUNT(int_id) FROM ttrss_user_entries
                                        WHERE owner_uid = id) AS stored_articles,
                                ".SUBSTRING_FOR_DATE."(created,1,16) AS created
-                               FROM ttrss_users 
+                               FROM ttrss_users
                                WHERE id = '$uid'");
-                               
+
                        if (db_num_rows($result) == 0) {
                                print "<h1>".__('User not found')."</h1>";
                                return;
                        }
-                       
+
                        // print "<h1>User Details</h1>";
 
                        $login = db_fetch_result($result, 0, "login");
 
                        print "<table width='100%'>";
 
-                       $last_login = date(get_pref($link, 'LONG_DATE_FORMAT'),
-                               strtotime(db_fetch_result($result, 0, "last_login")));
+                       $last_login = make_local_datetime($link,
+                               db_fetch_result($result, 0, "last_login"), true);
 
-                       $created = date(get_pref($link, 'LONG_DATE_FORMAT'),
-                               strtotime(db_fetch_result($result, 0, "created")));
+                       $created = make_local_datetime($link,
+                               db_fetch_result($result, 0, "created"), true);
 
                        $access_level = db_fetch_result($result, 0, "access_level");
                        $stored_articles = db_fetch_result($result, 0, "stored_articles");
@@ -56,7 +59,7 @@
                        $num_feeds = db_fetch_result($result, 0, "num_feeds");
 
                        print "<tr><td>".__('Subscribed feeds count')."</td><td>$num_feeds</td></tr>";
-       
+
                        print "</table>";
 
                        print "<h1>".__('Subscribed feeds')."</h1>";
 
                                print "<li class=\"$row_class\">$feed_icon&nbsp;<a href=\"".$line["site_url"]."\">".$line["title"]."</a></li>";
 
-                               $row_class = toggleEvenOdd($row_class);
+                               $row_class = $row_class == "even" ? "odd" : "even";
 
                        }
 
                        if (db_num_rows($result) < $num_feeds) {
                                // FIXME - add link to show ALL subscribed feeds here somewhere
-                               print "<li><img 
+                               print "<li><img
                                        class=\"tinyFeedIcon\" src=\"images/blank_icon.gif\">&nbsp;...</li>";
                        }
-                       
+
                        print "</ul>";
 
                        print "<div align='center'>
                                <button onclick=\"closeInfoBox()\">".__("Close this window").
                                "</button></div>";
 
-                       print "</div>";
+                       print "]]></content></dlg>";
 
                        return;
                }
 
-               if ($subop == "edit") {
+               if ($method == "edit") {
+
+                       header("Content-Type: text/xml");
 
                        $id = db_escape_string($_REQUEST["id"]);
 
-                       print "<div id=\"infoBoxTitle\">".__('User Editor')."</div>";
-                       
-                       print "<div class=\"infoBoxContents\">";
+                       print "<dlg id=\"$method\">";
+                       print "<title>".__('User Editor')."</title>";
+                       print "<content><![CDATA[";
 
                        print "<form id=\"user_edit_form\" onsubmit='return false'>";
 
                        print "<input type=\"hidden\" name=\"id\" value=\"$id\">";
                        print "<input type=\"hidden\" name=\"op\" value=\"pref-users\">";
-                       print "<input type=\"hidden\" name=\"subop\" value=\"editSave\">";
+                       print "<input type=\"hidden\" name=\"method\" value=\"editSave\">";
 
                        $result = db_query($link, "SELECT * FROM ttrss_users WHERE id = '$id'");
 
 
                        if ($sel_disabled) {
                                print "<input type=\"hidden\" name=\"login\" value=\"$login\">";
-                               print "<input size=\"30\" style=\"font-size : 16px\" 
+                               print "<input size=\"30\" style=\"font-size : 16px\"
                                        onkeypress=\"return filterCR(event, userEditSave)\" $sel_disabled
                                        value=\"$login\">";
                        } else {
-                               print "<input size=\"30\" style=\"font-size : 16px\" 
+                               print "<input size=\"30\" style=\"font-size : 16px\"
                                        onkeypress=\"return filterCR(event, userEditSave)\" $sel_disabled
                                        name=\"login\" value=\"$login\">";
                        }
                        print __('Access level: ') . " ";
 
                        if (!$sel_disabled) {
-                               print_select_hash("access_level", $access_level, $access_level_names, 
+                               print_select_hash("access_level", $access_level, $access_level_names,
                                        $sel_disabled);
                        } else {
-                               print_select_hash("", $access_level, $access_level_names, 
+                               print_select_hash("", $access_level, $access_level_names,
                                        $sel_disabled);
                                print "<input type=\"hidden\" name=\"access_level\" value=\"$access_level\">";
                        }
                                <button onclick=\"return userEditCancel()\">".
                                        __('Cancel')."</button></div>";
 
-                       print "</div>";
+                       print "]]></content></dlg>";
 
                        return;
                }
 
-               if ($subop == "editSave") {
-       
-                       if (!WEB_DEMO_MODE && $_SESSION["access_level"] >= 10) {
+               if ($method == "editSave") {
+
+                       if ($_SESSION["access_level"] >= 10) {
 
                                $login = db_escape_string(trim($_REQUEST["login"]));
                                $uid = db_escape_string($_REQUEST["id"]);
 
                                if ($password) {
                                        $pwd_hash = encrypt_password($password, $login);
-                                       $pass_query_part = "pwd_hash = '$pwd_hash', ";                                  
-                                       print_notice(T_sprintf('Changed password of user <b>%s</b>.', $login));
+                                       $pass_query_part = "pwd_hash = '$pwd_hash', ";
+                                       $status_msg = format_notice(T_sprintf('Changed password of user <b>%s</b>.', $login));
                                } else {
                                        $pass_query_part = "";
                                }
 
-                               db_query($link, "UPDATE ttrss_users SET $pass_query_part login = '$login', 
+                               db_query($link, "UPDATE ttrss_users SET $pass_query_part login = '$login',
                                        access_level = '$access_level', email = '$email' WHERE id = '$uid'");
 
                        }
-               } else if ($subop == "remove") {
+               } else if ($method == "remove") {
 
                        if ($_SESSION["access_level"] >= 10) {
 
                                $ids = split(",", db_escape_string($_REQUEST["ids"]));
 
                                foreach ($ids as $id) {
-                                       if ($id != $_SESSION["uid"]) {
+                                       if ($id != $_SESSION["uid"] && $id != 1) {
                                                db_query($link, "DELETE FROM ttrss_tags WHERE owner_uid = '$id'");
                                                db_query($link, "DELETE FROM ttrss_feeds WHERE owner_uid = '$id'");
                                                db_query($link, "DELETE FROM ttrss_users WHERE id = '$id'");
                                        }
                                }
                        }
-               } else if ($subop == "add") {
-               
+               } else if ($method == "add") {
+
                        if ($_SESSION["access_level"] >= 10) {
 
                                $login = db_escape_string(trim($_REQUEST["login"]));
                                $tmp_user_pwd = make_password(8);
                                $pwd_hash = encrypt_password($tmp_user_pwd, $login);
 
-                               $result = db_query($link, "SELECT id FROM ttrss_users WHERE 
+                               $result = db_query($link, "SELECT id FROM ttrss_users WHERE
                                        login = '$login'");
 
                                if (db_num_rows($result) == 0) {
 
-                                       db_query($link, "INSERT INTO ttrss_users 
+                                       db_query($link, "INSERT INTO ttrss_users
                                                (login,pwd_hash,access_level,last_login,created)
                                                VALUES ('$login', '$pwd_hash', 0, null, NOW())");
-       
-       
-                                       $result = db_query($link, "SELECT id FROM ttrss_users WHERE 
+
+
+                                       $result = db_query($link, "SELECT id FROM ttrss_users WHERE
                                                login = '$login' AND pwd_hash = '$pwd_hash'");
-       
+
                                        if (db_num_rows($result) == 1) {
-       
+
                                                $new_uid = db_fetch_result($result, 0, "id");
-       
-                                               print_notice(T_sprintf("Added user <b>%s</b> with password <b>%s</b>", 
+
+                                               $status_msg = format_notice(T_sprintf("Added user <b>%s</b> with password <b>%s</b>",
                                                        $login, $tmp_user_pwd));
-       
+
                                                initialize_user($link, $new_uid);
-       
+
                                        } else {
-                                       
-                                               print_warning(T_sprintf("Could not create user <b>%s</b>", $login));
-       
+
+                                               $status_msg = format_warning(T_sprintf("Could not create user <b>%s</b>", $login));
+
                                        }
                                } else {
-                                       print_warning(T_sprintf("User <b>%s</b> already exists.", $login));
+                                       $status_msg = format_warning(T_sprintf("User <b>%s</b> already exists.", $login));
                                }
-                       } 
-               } else if ($subop == "resetPass") {
+                       }
+               } else if ($method == "resetPass") {
 
-                       if (!WEB_DEMO_MODE && $_SESSION["access_level"] >= 10) {
+                       if ($_SESSION["access_level"] >= 10) {
 
                                $uid = db_escape_string($_REQUEST["id"]);
 
-                               $result = db_query($link, "SELECT login,email 
+                               $result = db_query($link, "SELECT login,email
                                        FROM ttrss_users WHERE id = '$uid'");
 
                                $login = db_fetch_result($result, 0, "login");
                                db_query($link, "UPDATE ttrss_users SET pwd_hash = '$pwd_hash'
                                        WHERE id = '$uid'");
 
-                               print_notice(T_sprintf("Changed password of user <b>%s</b>
+                               $status_msg = format_notice(T_sprintf("Changed password of user <b>%s</b>
                                         to <b>%s</b>", $login, $tmp_user_pwd));
 
+                               require_once 'lib/phpmailer/class.phpmailer.php';
+
                                if ($email) {
-                                       print_notice(T_sprintf("Notifying <b>%s</b>.", $email));
+                                       $status_msg += format_notice(T_sprintf("Notifying <b>%s</b>.", $email));
 
                                        require_once "lib/MiniTemplator.class.php";
 
                                                "\n".
                                                "Sincerely, TT-RSS Mail Daemon.", "From: " . MAIL_FROM); */
                                }
-                                       
-                               print "</div>";                         
+
+                               print "</div>";
 
                        }
                }
 
-               set_pref($link, "_PREFS_ACTIVE_TAB", "userConfig");
+               print "<div id=\"pref-user-wrap\" dojoType=\"dijit.layout.BorderContainer\" gutters=\"false\">";
+               print "<div id=\"pref-user-header\" dojoType=\"dijit.layout.ContentPane\" region=\"top\">";
+
+               print "<div id=\"pref-user-toolbar\" dojoType=\"dijit.Toolbar\">";
 
                $user_search = db_escape_string($_REQUEST["search"]);
 
                        $user_search = $_SESSION["prefs_user_search"];
                }
 
-               print "<div style='float : right'>
-                       <input id=\"user_search\" size=\"20\" type=\"search\"
-                               onfocus=\"javascript:disableHotkeys();\" 
-                               onblur=\"javascript:enableHotkeys();\"
-                               onchange=\"javascript:updateUsersList()\" value=\"$user_search\">
-                       <button onclick=\"javascript:updateUsersList()\">".
+               print "<div style='float : right; padding-right : 4px;'>
+                       <input dojoType=\"dijit.form.TextBox\" id=\"user_search\" size=\"20\" type=\"search\"
+                               value=\"$user_search\">
+                       <button dojoType=\"dijit.form.Button\" onclick=\"javascript:updateUsersList()\">".
                                __('Search')."</button>
                        </div>";
 
                        $sort = "login";
                }
 
-               print "<button onclick=\"javascript:addUser()\">".__('Create user')."</button>";
+               print "<div dojoType=\"dijit.form.DropDownButton\">".
+                               "<span>" . __('Select')."</span>";
+               print "<div dojoType=\"dijit.Menu\" style=\"display: none;\">";
+               print "<div onclick=\"selectTableRows('prefUserList', 'all')\"
+                       dojoType=\"dijit.MenuItem\">".__('All')."</div>";
+               print "<div onclick=\"selectTableRows('prefUserList', 'none')\"
+                       dojoType=\"dijit.MenuItem\">".__('None')."</div>";
+               print "</div></div>";
 
-               print "
-                       <button onclick=\"javascript:selectedUserDetails()\">".
-                       __('Details')."</button>
-                       <button onclick=\"javascript:editSelectedUser()\">".
-                       __('Edit')."</button>
-                       <button onclick=\"javascript:removeSelectedUsers()\">".
-                       __('Remove')."</button>
-                       <button onclick=\"javascript:resetSelectedUserPass()\">".
-                       __('Reset password')."</button>";
+               print "<button dojoType=\"dijit.form.Button\" onclick=\"javascript:addUser()\">".__('Create user')."</button>";
 
-               print "</div>";
+               print "
+                       <button dojoType=\"dijit.form.Button\" onclick=\"javascript:selectedUserDetails()\">".
+                       __('Details')."</button dojoType=\"dijit.form.Button\">
+                       <button dojoType=\"dijit.form.Button\" onclick=\"javascript:editSelectedUser()\">".
+                       __('Edit')."</button dojoType=\"dijit.form.Button\">
+                       <button dojoType=\"dijit.form.Button\" onclick=\"javascript:removeSelectedUsers()\">".
+                       __('Remove')."</button dojoType=\"dijit.form.Button\">
+                       <button dojoType=\"dijit.form.Button\" onclick=\"javascript:resetSelectedUserPass()\">".
+                       __('Reset password')."</button dojoType=\"dijit.form.Button\">";
+
+               print "</div>"; #toolbar
+               print "</div>"; #pane
+               print "<div id=\"pref-user-content\" dojoType=\"dijit.layout.ContentPane\" region=\"center\">";
+               print "<p>$status_msg";
 
                if ($user_search) {
 
                        $user_search = split(" ", $user_search);
                        $tokens = array();
 
-                       foreach ($user_search as $token) {                      
+                       foreach ($user_search as $token) {
                                $token = trim($token);
                                array_push($tokens, "(UPPER(login) LIKE UPPER('%$token%'))");
                        }
                        $user_search_query = "";
                }
 
-               $result = db_query($link, "SELECT 
+               $result = db_query($link, "SELECT
                                id,login,access_level,email,
                                ".SUBSTRING_FOR_DATE."(last_login,1,16) as last_login,
                                ".SUBSTRING_FOR_DATE."(created,1,16) as created
-                       FROM 
+                       FROM
                                ttrss_users
                        WHERE
                                $user_search_query
 
                if (db_num_rows($result) > 0) {
 
-//             print "<div id=\"infoBoxShadow\"><div id=\"infoBox\">PLACEHOLDER</div></div>";
-
-               print "<p><table width=\"100%\" cellspacing=\"0\" 
+               print "<p><table width=\"100%\" cellspacing=\"0\"
                        class=\"prefUserList\" id=\"prefUserList\">";
 
-               print "<tr><td class=\"selectPrompt\" colspan=\"8\">
-                               ".__('Select:')." 
-                                       <a href=\"javascript:selectPrefRows('user', true)\">".__('All')."</a>,
-                                       <a href=\"javascript:selectPrefRows('user', false)\">".__('None')."</a>
-                               </td</tr>";
-
                print "<tr class=\"title\">
                                        <td align='center' width=\"5%\">&nbsp;</td>
-                                       <td width=''><a href=\"javascript:updateUsersList('login')\">".__('Login')."</a></td>
-                                       <td width='20%'><a href=\"javascript:updateUsersList('access_level')\">".__('Access Level')."</a></td>
-                                       <td width='20%'><a href=\"javascript:updateUsersList('created')\">".__('Registered')."</a></td>
-                                       <td width='20%'><a href=\"javascript:updateUsersList('last_login')\">".__('Last login')."</a></td></tr>";
-               
+                                       <td width=''><a href=\"#\" onclick=\"updateUsersList('login')\">".__('Login')."</a></td>
+                                       <td width='20%'><a href=\"#\" onclick=\"updateUsersList('access_level')\">".__('Access Level')."</a></td>
+                                       <td width='20%'><a href=\"#\" onclick=\"updateUsersList('created')\">".__('Registered')."</a></td>
+                                       <td width='20%'><a href=\"#\" onclick=\"updateUsersList('last_login')\">".__('Last login')."</a></td></tr>";
+
                $lnum = 0;
-               
+
                while ($line = db_fetch_assoc($result)) {
 
                        $class = ($lnum % 2) ? "even" : "odd";
                        $uid = $line["id"];
                        $edit_uid = $_REQUEST["id"];
 
-                       if ($subop == "edit" && $uid != $edit_uid) {
-                               $class .= "Grayed";
+                       if ($method == "edit" && $uid != $edit_uid) {
+                               $class .= " Grayed";
                                $this_row_id = "";
                        } else {
                                $this_row_id = "id=\"UMRR-$uid\"";
-                       }               
-                       
+                       }
+
                        print "<tr class=\"$class\" $this_row_id>";
 
                        $line["login"] = htmlspecialchars($line["login"]);
 
-#                      $line["last_login"] = date(get_pref($link, 'SHORT_DATE_FORMAT'),
-#                              strtotime($line["last_login"]));
+                       $line["created"] = make_local_datetime($link, $line["created"], false);
+                       $line["last_login"] = make_local_datetime($link, $line["last_login"], false);
 
-                       if (get_pref($link, 'HEADLINES_SMART_DATE')) {
-                               $line["last_login"] = smart_date_time(strtotime($line["last_login"]));
-                               $line["created"] = smart_date_time(strtotime($line["created"]));
-                       } else {
-                               $line["last_login"] = date(get_pref($link, 'SHORT_DATE_FORMAT'),
-                                       strtotime($line["last_login"]));
-                               $line["created"] = date(get_pref($link, 'SHORT_DATE_FORMAT'),
-                                       strtotime($line["created"]));
-                       }                               
-
-                       print "<td align='center'><input onclick='toggleSelectPrefRow(this, \"user\");' 
+                       print "<td align='center'><input onclick='toggleSelectRow(this);'
                                type=\"checkbox\" id=\"UMCHK-$uid\"></td>";
 
-                       $onclick = "onclick='editUser($uid)' title='".__('Click to edit')."'";
+                       $onclick = "onclick='editUser($uid, event)' title='".__('Click to edit')."'";
 
-                       print "<td $onclick>" . $line["login"] . "</td>";               
+                       print "<td $onclick>" . $line["login"] . "</td>";
 
                        if (!$line["email"]) $line["email"] = "&nbsp;";
 
-                       print "<td $onclick>" . $access_level_names[$line["access_level"]] . "</td>";   
-                       print "<td $onclick>" . $line["created"] . "</td>";             
-                       print "<td $onclick>" . $line["last_login"] . "</td>";          
-               
+                       print "<td $onclick>" . $access_level_names[$line["access_level"]] . "</td>";
+                       print "<td $onclick>" . $line["created"] . "</td>";
+                       print "<td $onclick>" . $line["last_login"] . "</td>";
+
                        print "</tr>";
 
                        ++$lnum;
 
                }
 
+               print "</div>"; #pane
+               print "</div>"; #container
+
        }
 ?>