4 require_once 'Pman.php';
8 * not really sure how save our factory method is....!!!
11 * Uses these methods of the dataobjects:
12 * - checkPerm('L'/'E'/'A', $authuser) - can we list the stuff
14 * - applySort($au, $sortcol, $direction)
15 * - applyFilters($_REQUEST, $authUser) -- apply any query filters on data. and hide stuff not to be seen.
16 * - postListExtra - add extra column data on the results (like new messages etc.)
17 * -postListFilter($data, $authUser, $request) return $data - add extra data to an object
19 * - toRooSingleArray() // single fetch, add data..
20 * - toRooArray($request) /// toArray if you need to return different data.. for a list fetch.
23 * - beforeDelete() -- return false for fail and set DO->err;
24 * - onUpdate($old, $request,$roo) - after update
25 * - onInsert($request,$roo) - after insert
27 * - setFromRoo($ar) - values from post (deal with dates etc.) - return true|error string.
29 * - toEventString (for logging)
32 class Pman_Roo extends Pman
36 parent::getAuth(); // load company!
37 $au = $this->getAuthUser();
39 $this->jerr("Not authenticated", array('authFailure' => true));
41 $this->authUser = $au;
45 * GET method Roo/TABLENAME.php
46 * -- defaults to listing data. with args.
49 * _post = simulate a post with debuggin on.
50 * lookup = array( k=>v) single fetch based on a key/value pair
51 * _id = single fetch based on id.
52 * _delete = delete a list of ids element. (seperated by ,);
53 * _columns = comma seperated list of columns.
54 * _distinct = a distinct column lookup.
56 * csvCols = return data as csv
58 * csvTitles = return data as csv
61 * dir = sort direction
63 * limit = limit number
65 * _toggleActive !:!:!:! - this hsould not really be here..
66 * query[add_blank] - add a line in with an empty option... - not really needed???
71 // $this->jerr("Not authenticated", array('authFailure' => true));
72 //DB_DataObject::debuglevel(1);
75 if (!empty($_GET['_post'])) {
77 DB_DAtaObject::debuglevel(1);
78 return $this->post($tab);
80 $tab = str_replace('/', '',$tab); // basic protection??
81 $x = DB_DataObject::factory($tab);
82 if (!is_a($x, 'DB_DataObject')) {
83 $this->jerr('invalid url');
85 $_columns = !empty($_REQUEST['_columns']) ? explode(',', $_REQUEST['_columns']) : false;
87 if (isset( $_REQUEST['lookup'] )) { // single fetch based on key/value pairs
88 if (method_exists($x, 'checkPerm') && !$x->checkPerm('S', $this->authUser)) {
89 $this->jerr("PERMISSION DENIED");
91 $this->loadMap($x, $_columns);
92 $x->setFrom($_REQUEST['lookup'] );
94 if (!$x->find(true)) {
97 $this->jok($x->toArray());
102 if (isset($_REQUEST['_id'])) { // single fetch
104 if (empty($_REQUEST['_id'])) {
105 $this->jok($x->toArray()); // return an empty array!
108 $this->loadMap($x, $_columns);
110 if (!$x->get($_REQUEST['_id'])) {
111 $this->jerr("no such record");
114 if (method_exists($x, 'checkPerm') && !$x->checkPerm('S', $this->authUser)) {
115 $this->jerr("PERMISSION DENIED");
118 $this->jok(method_exists($x, 'toRooSingleArray') ? $x->toRooSingleArray($this->authUser) : $x->toArray());
121 if (isset($_REQUEST['_delete'])) {
122 // do we really delete stuff!?!?!?
123 return $this->delete($x, $_REQUEST['_delete']);
129 if (isset($_REQUEST['_toggleActive'])) {
130 // do we really delete stuff!?!?!?
131 if (!$this->hasPerm("Core.Staff", 'E')) {
132 $this->jerr("PERMISSION DENIED");
134 $clean = create_function('$v', 'return (int)$v;');
135 $bits = array_map($clean, explode(',', $_REQUEST['_toggleActive']));
136 if (in_array($this->authUser->id, $bits) && $this->authUser->active) {
137 $this->jerr("you can not disable yourself");
139 $x->query('UPDATE Person SET active = !active WHERE id IN (' .implode(',', $bits).')');
140 $this->addEvent("USERTOGGLE", false, implode(',', $bits));
141 $this->jok("Updated");
144 // DB_DataObject::debugLevel(1);
145 if (method_exists($x, 'checkPerm') && !$x->checkPerm('S', $this->authUser)) {
146 $this->jerr("PERMISSION DENIED");
148 $map = $this->loadMap($x, $_columns);
150 $this->setFilters($x,$_REQUEST);
154 // build join if req.
156 if (!empty($_REQUEST['_distinct'])) {
160 if (isset($cols[$_REQUEST['_distinct']])) {
161 $countWhat = 'distinct ' . $_REQUEST['_distinct'];
163 $x->selectAdd('distinct('.$_REQUEST['_distinct'].')');
164 $_columns = array( $_REQUEST['_distinct'] );
166 $this->jerr('invalid distinct');
170 $total = $x->count($countWhat);
172 // DB_DataObject::debugLevel(1);
174 $sort = empty($_REQUEST['sort']) ? '' : $_REQUEST['sort'];
175 $dir = (empty($_REQUEST['dir']) || strtoupper($_REQUEST['dir']) == 'ASC' ? 'ASC' : 'DESC');
178 if (method_exists($x, 'applySort')) {
179 $sorted = $x->applySort($this->authUser, $sort, $dir, $this->cols);
181 if ($sorted === false) {
184 // echo '<PRE>';print_r(array($sort, $this->cols));
186 // $otherSorts = array('person_id_name');
188 if (strlen($sort) && isset($cols[$sort]) ) {
189 $sort = $x->tableName() .'.'.$sort . ' ' . $dir ;
191 } else if (in_array($sort, $this->cols)) {
192 $sort = $sort . ' ' . $dir ;
194 }// else other formatas?
195 //if ( in_array($sort, $otherSorts)) {
196 // $x->orderBy($sort . ' ' . $dir);
203 empty($_REQUEST['start']) ? 0 : (int)$_REQUEST['start'],
204 min(empty($_REQUEST['limit']) ? 25 : (int)$_REQUEST['limit'], 1000)
207 $queryObj = clone($x);
212 if (!empty($_REQUEST['query']['add_blank'])) {
213 $ret[] = array( 'id' => 0, 'name' => '----');
218 //if (($tab == 'Groups') && ($_REQUEST['type'] != 0)) { // then it's a list of teams..
219 if ($tab == 'Groups') {
221 $ret[] = array( 'id' => 0, 'name' => 'EVERYONE');
222 $ret[] = array( 'id' => -1, 'name' => 'NOT_IN_GROUP');
223 //$ret[] = array( 'id' => 999999, 'name' => 'ADMINISTRATORS');
229 if (!empty($_REQUEST['csvCols']) && !empty($_REQUEST['csvTitles']) ) {
230 header('Content-type: text/csv');
232 header('Content-Disposition: attachment; filename="documentlist-export-'.date('Y-m-d') . '.csv"');
233 //header('Content-type: text/plain');
234 $fh = fopen('php://output', 'w');
235 fputcsv($fh, $_REQUEST['csvTitles']);
236 while ($x->fetch()) {
237 //echo "<PRE>"; print_r(array($_REQUEST['csvCols'], $x->toArray())); exit;
239 foreach($_REQUEST['csvCols'] as $k) {
240 $line[] = isset($x->$k) ? $x->$k : '';
251 $rooar = method_exists($x, 'toRooArray');
253 while ($x->fetch()) {
254 $add = $rooar ? $x->toRooArray($_REQUEST) : $x->toArray();
256 $ret[] = !$_columns ? $add : array_intersect_key($add, array_flip($_columns));
258 //if ($x->tableName() == 'Documents_Tracking') {
259 // $ret = $this->replaceSubject(&$ret, 'doc_id_subject');
263 if (method_exists($queryObj ,'postListExtra')) {
264 $extra = $queryObj->postListExtra($_REQUEST);
266 // filter results, and add any data that is needed...
267 if (method_exists($x,'postListFilter')) {
268 $ret = $x->postListFilter($ret, $this->authUser, $_REQUEST);
273 // echo "<PRE>"; print_r($ret);
274 $this->jdata($ret,$total, $extra );
279 * POST method Roo/TABLENAME.php
280 * -- updates the data..
283 * _debug - forces debugging on.
284 * _get - forces a get request
285 * _ids - multiple update of records.
286 * {colid} - forces fetching
289 function post($tab) // update / insert (?? dleete??)
291 // DB_DataObject::debugLevel(1);
292 if (!empty($_REQUEST['_debug'])) {
293 DB_DataObject::debugLevel(1);
296 if (!empty($_REQUEST['_get'])) {
297 return $this->get($tab);
299 $_columns = !empty($_REQUEST['_columns']) ? explode(',', $_REQUEST['_columns']) : false;
301 $tab = str_replace('/', '',$tab); // basic protection??
302 $x = DB_DataObject::factory($tab);
303 if (!is_a($x, 'DB_DataObject')) {
304 $this->jerr('invalid url');
306 // find the key and use that to get the thing..
309 $this->jerr('no key');
313 if (!empty($_REQUEST['_ids'])) {
314 $ids = explode(',',$_REQUEST['_ids']);
315 $x->whereAddIn($keys[0], $ids, 'int');
316 $ar = $x->fetchAll();
318 $this->update($x, $_REQUEST);
322 $this->jok("UPDATED");
328 if (!empty($_REQUEST[$keys[0]])) {
330 if (!$x->get($keys[0], $_REQUEST[$keys[0]])) {
331 $this->jerr("Invalid request");
333 $this->jok($this->update($x, $_REQUEST));
335 $this->jok($this->insert($x, $_REQUEST));
342 function insert($x, $req)
346 if (method_exists($x, 'checkPerm') && !$x->checkPerm('A', $this->authUser, $req)) {
347 $this->jerr("PERMISSION DENIED");
350 $_columns = !empty($req['_columns']) ? explode(',', $req['_columns']) : false;
352 if (method_exists($x, 'setFromRoo')) {
353 $res = $x->setFromRoo($req, $this);
354 if (is_string($res)) {
364 if (isset($cols['created'])) {
365 $x->created = date('Y-m-d H:i:s');
367 if (isset($cols['created_dt'])) {
368 $x->created_dt = date('Y-m-d H:i:s');
370 if (isset($cols['created_by'])) {
371 $x->created_by = $this->authUser->id;
375 if (isset($cols['modified'])) {
376 $x->modified = date('Y-m-d H:i:s');
378 if (isset($cols['modified_dt'])) {
379 $x->modified_dt = date('Y-m-d H:i:s');
381 if (isset($cols['modified_by'])) {
382 $x->modified_by = $this->authUser->id;
385 if (isset($cols['updated'])) {
386 $x->updated = date('Y-m-d H:i:s');
388 if (isset($cols['updated_dt'])) {
389 $x->updated_dt = date('Y-m-d H:i:s');
391 if (isset($cols['updated_by'])) {
392 $x->updated_by = $this->authUser->id;
400 if (method_exists($x, 'onInsert')) {
401 $x->onInsert($_REQUEST, $this);
403 $this->addEvent("ADD", $x, $x->toEventString());
405 // note setFrom might handle this before hand...!??!
406 if (!empty($_FILES) && method_exists($x, 'onUpload')) {
410 $r = DB_DataObject::factory($x->tableName());
412 $this->loadMap($r, $_columns);
416 $rooar = method_exists($r, 'toRooArray');
417 //print_r(var_dump($rooar)); exit;
418 return $rooar ? $r->toRooArray() : $r->toArray();
422 function update($x, $req)
424 if (method_exists($x, 'checkPerm') && !$x->checkPerm('E', $this->authUser, $_REQUEST)) {
425 $this->jerr("PERMISSION DENIED");
428 $_columns = !empty($req['_columns']) ? explode(',', $req['_columns']) : false;
433 // this lot is generic.. needs moving
434 if (method_exists($x, 'setFromRoo')) {
435 $res = $x->setFromRoo($req, $this);
436 if (is_string($res)) {
442 $this->addEvent("EDIT", $x, $x->toEventString());
448 if (isset($cols['modified'])) {
449 $x->modified = date('Y-m-d H:i:s');
451 if (isset($cols['modified_dt'])) {
452 $x->modified_dt = date('Y-m-d H:i:s');
454 if (isset($cols['modified_by'])) {
455 $x->modified_by = $this->authUser->id;
458 if (isset($cols['updated'])) {
459 $x->updated = date('Y-m-d H:i:s');
461 if (isset($cols['updated_dt'])) {
462 $x->updated_dt = date('Y-m-d H:i:s');
464 if (isset($cols['updated_by'])) {
465 $x->updated_by = $this->authUser->id;
470 if (method_exists($x, 'onUpdate')) {
471 $x->onUpdate($old, $req, $this);
474 $r = DB_DataObject::factory($x->tableName());
476 $this->loadMap($r, $_columns);
479 $rooar = method_exists($r, 'toRooArray');
480 //print_r(var_dump($rooar)); exit;
481 return $rooar ? $r->toRooArray() : $r->toArray();
484 function delete($x, $req)
486 // do we really delete stuff!?!?!?
489 // build a list of tables to queriy for dependant data..
493 echo '<PRE>';print_r($GLOBALS['_DB_DATAOBJECT']['LINKS'][$x->_database]);exit;
497 $clean = create_function('$v', 'return (int)$v;');
499 $bits = array_map($clean, explode(',', $req['_delete']));
500 $x->whereAdd('id IN ('. implode(',', $bits) .')');
503 while ($x->fetch()) {
506 if (method_exists($x, 'checkPerm') && !$x->checkPerm('D', $this->authUser)) {
507 $this->jerr("PERMISSION DENIED");
510 $this->addEvent("DELETE", $x, $x->toEventString());
511 if ( method_exists($xx, 'beforeDelete') && ($xx->beforeDelete() === false)) {
512 $errs[] = "Delete failed ({$xx->id})\n". (isset($xx->err) ? $xx->err : '');
518 $this->jerr(implode("\n<BR>", $errs));
520 $this->jok("Deleted");
528 function loadMap($do, $filter=false)
530 //DB_DataObject::debugLevel(1);
535 $mods = explode(',',$this->appModules);
537 $ff = HTML_FlexyFramework::geT();
538 //$db->databaseName();
540 //$ff->DB_DataObject['ini_'. $db->database()];
541 //echo '<PRE>';print_r($do->links());exit;
544 if (in_array('Builder', $mods) ) {
546 foreach(in_array('Builder', $mods) ? scandir($this->rootDir.'/Pman') : $mods as $m) {
548 if (!strlen($m) || $m[0] == '.' || !is_dir($this->rootDir."/Pman/$m")) {
551 $ini = $this->rootDir."/Pman/$m/DataObjects/pman.links.ini";
552 if (!file_exists($ini)) {
555 $conf = array_merge($conf, parse_ini_file($ini,true));
556 if (!isset($conf[$do->tableName()])) {
559 $map = $conf[$do->tableName()];
569 $tabdef = $do->table();
570 if (isset($tabdef['passwd'])) {
571 // prevent exposure of passwords..
572 unset($tabdef['passwd']);
575 $xx = array_keys($tabdef);
576 $do->selectAdd(); // we need thsi as normally it's only cleared by an empty selectAs call.
582 if (in_array($c, $filter)) {
586 $do->selectAs($cols);
600 foreach($map as $ocl=>$info) {
602 list($tab,$col) = explode(':', $info);
603 // what about multiple joins on the same table!!!
604 $xx = DB_DataObject::factory($tab);
605 if (!is_a($xx, 'DB_DataObject')) {
608 // this is borked ... for multiple jions..
609 $do->joinAdd($xx, 'LEFT', 'join_'.$ocl.'_'. $col, $ocl);
610 $tabdef = $xx->table();
611 $table = $xx->tableName();
612 if (isset($tabdef['passwd'])) {
614 unset($tabdef['passwd']);
617 $xx = array_keys($tabdef);
624 $tn = sprintf($ocl.'_%s', $c);
625 if (in_array($tn, $filter)) {
629 $do->selectAs($cols, $ocl.'_%s', 'join_'.$ocl.'_'. $col);
631 $do->selectAs($xx, $ocl.'_%s', 'join_'.$ocl.'_'. $col);
639 $this->cols[] = sprintf($ocl.'_%s', $k);
644 //DB_DataObject::debugLevel(1);
649 function setFilters($x, $q)
651 // if a column is type int, and we get ',' -> the it should be come an inc clause..
652 // DB_DataObject::debugLevel(1);
653 if (method_exists($x, 'applyFilters')) {
654 // DB_DataObject::debugLevel(1);
655 $x->applyFilters($q, $this->authUser);
657 $q_filtered = array();
659 foreach($q as $key=>$val) {
661 if (is_array($val)) {
664 if ($key[0] == '!' && in_array(substr($key, 1), $this->cols)) {
666 $x->whereAdd( $x->tableName() .'.' .substr($key, 1) . ' != ' .
667 (is_numeric($val) ? $val : "'". $x->escape($val) . "'")
677 // Events and remarks
678 case 'on_id': // where TF is this used...
679 if (!empty($q['query']['original'])) {
680 // DB_DataObject::debugLevel(1);
681 $o = (int) $q['query']['original'];
683 $x->whereAdd("(on_id = $oid OR
684 on_id IN ( SELECT distinct(id) FROM Documents WHERE original = $o )
694 $q_filtered[$key] = $val;
700 $x->setFrom($q_filtered);
702 // nice generic -- let's get rid of it.. where is it used!!!!
705 if (!empty($q['query']['name'])) {
706 $x->whereAdd($x->tableName().".name LIKE '". $x->escape($q['query']['name']) . "%'");
709 // - projectdirectory staff list - persn queuy