265 if (is_array($var)) {
266 foreach ($var as $key => $value) {
268 if ($type === 0 && defined(
'NOSCANPOSTFORINJECTION') && is_array(constant(
'NOSCANPOSTFORINJECTION')) && in_array($key, constant(
'NOSCANPOSTFORINJECTION'))) {
275 http_response_code(403);
278 $ip = (empty($_SERVER[
'REMOTE_ADDR']) ?
'unknown' : $_SERVER[
'REMOTE_ADDR']);
281 $errormessage =
'Access refused to '.htmlentities($ip, ENT_COMPAT,
'UTF-8').
' by SQL or Script injection protection in main.inc.php:analyseVarsForSqlAndScriptsInjection type='.htmlentities((
string) $type, ENT_COMPAT,
'UTF-8');
284 $errormessage2 =
'page='.htmlentities((empty($_SERVER[
"REQUEST_URI"]) ?
'' : $_SERVER[
"REQUEST_URI"]), ENT_COMPAT,
'UTF-8');
285 $errormessage2 .=
' paramtype='.htmlentities((
string) $type, ENT_COMPAT,
'UTF-8');
286 $errormessage2 .=
' paramkey='.htmlentities($key, ENT_COMPAT,
'UTF-8');
287 $errormessage2 .=
' paramvalue='.htmlentities($value, ENT_COMPAT,
'UTF-8');
291 print
'Try to go back, fix data of your form and resubmit it. You can contact also your technical support.';
293 print
"\n".
'<!--'.
"\n";
294 print $errormessage2;
298 if (function_exists(
'error_log')) {
299 error_log($errormessage.
' '.substr($errormessage2, 2000));
306 if (class_exists(
'PHPUnit\Framework\TestSuite')) {
307 $message = $errormessage.
' '.substr($errormessage2, 2000);
308 throw new Exception(
"Security injection exception: $message");
328if ((defined(
'NOREQUIREDB') || defined(
'NOREQUIRETRAN')) && !defined(
'NOREQUIREMENU')) {
329 print
'If define NOREQUIREDB or NOREQUIRETRAN are set, you must also set NOREQUIREMENU or not set them.';
332if (defined(
'NOREQUIREUSER') && !defined(
'NOREQUIREMENU')) {
333 print
'If define NOREQUIREUSER is set, you must also set NOREQUIREMENU or not set it.';
338if (!defined(
'NOSCANPHPSELFFORINJECTION') && !empty($_SERVER[
"PHP_SELF"])) {
339 $morevaltochecklikepost = array($_SERVER[
"PHP_SELF"]);
343if (!defined(
'NOSCANGETFORINJECTION') && !empty($_SERVER[
"QUERY_STRING"])) {
347 $morevaltochecklikeget = array(urldecode($_SERVER[
"QUERY_STRING"]));
351if (!defined(
'NOSCANPOSTFORINJECTION') || is_array(constant(
'NOSCANPOSTFORINJECTION'))) {
356if (!empty($_SERVER[
'DOCUMENT_ROOT']) && substr($_SERVER[
'DOCUMENT_ROOT'], -6) !==
'htdocs') {
357 set_include_path($_SERVER[
'DOCUMENT_ROOT'].
'/htdocs');
361require_once
'filefunc.inc.php';
366if (
GETPOST(
"DOL_AUTOSET_COOKIE")) {
367 $tmpautoset = explode(
':',
GETPOST(
"DOL_AUTOSET_COOKIE"), 2);
368 $tmplist = explode(
',', $tmpautoset[1]);
369 $cookiearrayvalue = array();
370 foreach ($tmplist as $tmpkey) {
371 $postkey = $tmpautoset[0].
'_'.$tmpkey;
374 $cookiearrayvalue[$tmpkey] =
GETPOST($postkey);
377 $cookiename = $tmpautoset[0];
378 $cookievalue = json_encode($cookiearrayvalue);
380 if (PHP_VERSION_ID < 70300) {
381 setcookie($cookiename, empty($cookievalue) ?
'' : $cookievalue, empty($cookievalue) ? 0 : (time() + (86400 * 354)),
'/',
'', ((empty($dolibarr_main_force_https) &&
isHTTPS() === false) ? false : true), true);
384 $cookieparams = array(
385 'expires' => empty($cookievalue) ? 0 : (time() + (86400 * 354)),
388 'secure' => ((empty($dolibarr_main_force_https) &&
isHTTPS() === false) ? false : true),
392 setcookie($cookiename, empty($cookievalue) ?
'' : $cookievalue, $cookieparams);
394 if (empty($cookievalue)) {
395 unset($_COOKIE[$cookiename]);
401if (!empty($php_session_save_handler) && $php_session_save_handler ==
'db') {
402 require_once
'core/lib/phpsessionin'.$php_session_save_handler.
'.lib.php';
408$prefix = dol_getprefix(
'');
409$sessionname =
'DOLSESSID_'.$prefix;
410$sessiontimeout =
'DOLSESSTIMEOUT_'.$prefix;
411if (!empty($_COOKIE[$sessiontimeout])) {
412 ini_set(
'session.gc_maxlifetime', $_COOKIE[$sessiontimeout]);
417if (!defined(
'NOSESSION')) {
418 if (PHP_VERSION_ID < 70300) {
419 session_set_cookie_params(0,
'/',
null, ((empty($dolibarr_main_force_https) &&
isHTTPS() ===
false) ?
false : true), true);
422 $sessioncookieparams = array(
426 'secure' => ((empty($dolibarr_main_force_https) &&
isHTTPS() ===
false) ?
false : true),
430 session_set_cookie_params($sessioncookieparams);
432 session_name($sessionname);
439require_once
'master.inc.php';
447 if ((!session_id() || !isset($_SESSION[
"dol_login"])) && !isset($_POST[
"username"]) && !empty($_SERVER[
"GATEWAY_INTERFACE"])) {
449 } elseif (isset($_POST[
"username"]) && $_POST[
"username"] == $conf->global->MAIN_ONLY_LOGIN_ALLOWED) {
451 } elseif (defined(
'NOREQUIREDB')) {
453 } elseif (defined(
'EVEN_IF_ONLY_LOGIN_ALLOWED')) {
455 } elseif (session_id() && isset($_SESSION[
"dol_login"]) && $_SESSION[
"dol_login"] == $conf->global->MAIN_ONLY_LOGIN_ALLOWED) {
459 if (session_id() && isset($_SESSION[
"dol_login"]) && $_SESSION[
"dol_login"] != $conf->global->MAIN_ONLY_LOGIN_ALLOWED) {
460 print
'Sorry, your application is offline.'.
"\n";
461 print
'You are logged with user "'.$_SESSION[
"dol_login"].
'" and only administrator user "' .
getDolGlobalString(
'MAIN_ONLY_LOGIN_ALLOWED').
'" is allowed to connect for the moment.'.
"\n";
462 $nexturl = DOL_URL_ROOT.
'/user/logout.php?token='.
newToken();
463 print
'Please try later or <a href="'.$nexturl.
'">click here to disconnect and change login user</a>...'.
"\n";
465 print
'Sorry, your application is offline. Only administrator user "' .
getDolGlobalString(
'MAIN_ONLY_LOGIN_ALLOWED').
'" is allowed to connect for the moment.'.
"\n";
466 $nexturl = DOL_URL_ROOT.
'/';
467 print
'Please try later or <a href="'.$nexturl.
'">click here to change login user</a>...'.
"\n";
475register_shutdown_function(
'dol_shutdown');
478if (isModEnabled(
'debugbar') && !
GETPOST(
'dol_use_jmobile') && empty($_SESSION[
'dol_use_jmobile'])) {
480 include_once DOL_DOCUMENT_ROOT.
'/debugbar/class/DebugBar.php';
482 $renderer = $debugbar->getJavascriptRenderer();
484 $conf->global->MAIN_HTML_HEADER =
'';
486 $conf->global->MAIN_HTML_HEADER .= $renderer->renderHead();
488 $debugbar[
'time']->startMeasure(
'pageaftermaster',
'Page generation (after environment init)');
492if (isset($_SERVER[
"HTTP_USER_AGENT"])) {
494 $conf->browser->name = $tmp[
'browsername'];
495 $conf->browser->os = $tmp[
'browseros'];
496 $conf->browser->version = $tmp[
'browserversion'];
497 $conf->browser->ua = $tmp[
'browserua'];
498 $conf->browser->layout = $tmp[
'layout'];
501 if ($conf->browser->layout ==
'phone') {
502 $conf->dol_no_mouse_hover = 1;
508 $conf->theme =
GETPOST(
'theme',
'aZ09');
509 $conf->css =
"/theme/".$conf->theme.
"/style.css.php";
513if (
GETPOSTINT(
'textbrowser') || (!empty($conf->browser->name) && $conf->browser->name ==
'lynxlinks')) {
514 $conf->global->MAIN_OPTIMIZEFORTEXTBROWSER = 2;
519if (!empty($conf->file->main_force_https) && !
isHTTPS() && !defined(
'NOHTTPSREDIRECT')) {
521 if (is_numeric($conf->file->main_force_https)) {
522 if ($conf->file->main_force_https ==
'1' && !empty($_SERVER[
"SCRIPT_URI"])) {
523 if (preg_match(
'/^http:/i', $_SERVER[
"SCRIPT_URI"]) && !preg_match(
'/^https:/i', $_SERVER[
"SCRIPT_URI"])) {
524 $newurl = preg_replace(
'/^http:/i',
'https:', $_SERVER[
"SCRIPT_URI"]);
528 $newurl = preg_replace(
'/^http:/i',
'https:', DOL_MAIN_URL_ROOT).$_SERVER[
"REQUEST_URI"];
532 $newurl = $conf->file->main_force_https.$_SERVER[
"REQUEST_URI"];
537 dol_syslog(
"main.inc: dolibarr_main_force_https is on, we make a redirect to ".$newurl);
538 header(
"Location: ".$newurl);
541 dol_syslog(
"main.inc: dolibarr_main_force_https is on but we failed to forge new https url so no redirect is done", LOG_WARNING);
545if (!defined(
'NOLOGIN') && !defined(
'NOIPCHECK') && !empty($dolibarr_main_restrict_ip)) {
546 $listofip = explode(
',', $dolibarr_main_restrict_ip);
548 foreach ($listofip as $ip) {
550 if ($ip == $_SERVER[
'REMOTE_ADDR']) {
556 print
'Access refused by IP protection. Your detected IP is '.$_SERVER[
'REMOTE_ADDR'];
562if (!defined(
'NOREQUIREHTML')) {
563 require_once DOL_DOCUMENT_ROOT.
'/core/class/html.form.class.php';
565if (!defined(
'NOREQUIREAJAX')) {
566 require_once DOL_DOCUMENT_ROOT.
'/core/lib/ajax.lib.php';
571 dol_syslog(
"main.inc: A previous install or upgrade was not complete. Redirect to install page.", LOG_WARNING);
572 header(
"Location: ".DOL_URL_ROOT.
"/install/index.php");
576$checkifupgraderequired =
false;
578 $checkifupgraderequired =
true;
581 $checkifupgraderequired =
true;
583if ($checkifupgraderequired) {
585 require_once DOL_DOCUMENT_ROOT.
'/core/lib/admin.lib.php';
586 $dolibarrversionlastupgrade = preg_split(
'/[.-]/', $versiontocompare);
587 $dolibarrversionprogram = preg_split(
'/[.-]/', DOL_VERSION);
588 $rescomp =
versioncompare($dolibarrversionprogram, $dolibarrversionlastupgrade);
590 if (!
getDolGlobalString(
'MAIN_NO_UPGRADE_REDIRECT_ON_LEVEL_3_CHANGE') || $rescomp < 3) {
592 dol_syslog(
"main.inc: database version ".$versiontocompare.
" is lower than programs version ".DOL_VERSION.
". Redirect to install/upgrade page.", LOG_WARNING);
593 if (php_sapi_name() ===
"cli") {
594 print
"main.inc: database version ".$versiontocompare.
" is lower than programs version ".DOL_VERSION.
". Try to run upgrade process.\n";
596 header(
"Location: ".DOL_URL_ROOT.
"/install/index.php");
604if (!defined(
'NOTOKENRENEWAL') && !defined(
'NOSESSION')) {
606 if (!preg_match(
'/\.(css|js|json)\.php$/', $_SERVER[
"PHP_SELF"])) {
608 if (isset($_SESSION[
'newtoken'])) {
609 $_SESSION[
'token'] = $_SESSION[
'newtoken'];
612 if (!isset($_SESSION[
'newtoken']) ||
getDolGlobalInt(
'MAIN_SECURITY_CSRF_TOKEN_RENEWAL_ON_EACH_CALL')) {
616 $token =
dol_hash(uniqid((
string) mt_rand(),
false),
'md5');
617 $_SESSION[
'newtoken'] = $token;
618 dol_syslog(
"NEW TOKEN generated by : ".$_SERVER[
'PHP_SELF'], LOG_DEBUG);
626if ((!defined(
'NOCSRFCHECK') && empty($dolibarr_nocsrfcheck) &&
getDolGlobalInt(
'MAIN_SECURITY_CSRF_WITH_TOKEN')) || defined(
'CSRFCHECK_WITH_TOKEN')) {
628 $sensitiveget =
false;
629 if ((GETPOSTISSET(
'massaction') ||
GETPOST(
'action',
'aZ09')) &&
getDolGlobalInt(
'MAIN_SECURITY_CSRF_WITH_TOKEN') >= 3) {
631 if (GETPOSTISSET(
'massaction') || !in_array(
GETPOST(
'action',
'aZ09'), array(
'create',
'createsite',
'createcard',
'edit',
'editcontract',
'editvalidator',
'file_manager',
'presend',
'presend_addmessage',
'preview',
'reconcile',
'specimen'))) {
632 $sensitiveget =
true;
636 $arrayofactiontoforcetokencheck = array(
638 'doprev',
'donext',
'dvprev',
'dvnext',
639 'freezone',
'install',
642 if (in_array(
GETPOST(
'action',
'aZ09'), $arrayofactiontoforcetokencheck)) {
643 $sensitiveget =
true;
646 if (preg_match(
'/^(confirm_)?(add|classify|close|confirm|copy|del|disable|enable|remove|set|unset|update|save)/',
GETPOST(
'action',
'aZ09'))) {
647 $sensitiveget =
true;
654 (!empty($_SERVER[
'REQUEST_METHOD']) && $_SERVER[
'REQUEST_METHOD'] ==
'POST') ||
656 GETPOSTISSET(
'massaction') ||
657 ((GETPOSTISSET(
'actionlogin') || GETPOSTISSET(
'action')) && defined(
'CSRFCHECK_WITH_TOKEN'))
660 if (!
GETPOST(
'token',
'alpha') ||
GETPOST(
'token',
'alpha') ==
'notrequired') {
663 dol_syslog(
"--- Access to ".(empty($_SERVER[
"REQUEST_METHOD"]) ?
'' : $_SERVER[
"REQUEST_METHOD"].
' ').$_SERVER[
"PHP_SELF"].
" refused. File size too large or not provided.");
664 $langs->loadLangs(array(
"errors",
"install"));
665 print $langs->trans(
"ErrorFileSizeTooLarge").
' ';
666 print $langs->trans(
"ErrorGoBackAndCorrectParameters");
668 http_response_code(403);
669 if (defined(
'CSRFCHECK_WITH_TOKEN')) {
670 dol_syslog(
"--- Access to ".(empty($_SERVER[
"REQUEST_METHOD"]) ?
'' : $_SERVER[
"REQUEST_METHOD"].
' ').$_SERVER[
"PHP_SELF"].
" refused by CSRF protection (CSRFCHECK_WITH_TOKEN protection) in main.inc.php. Token not provided.", LOG_WARNING);
671 print
"Access to a page that needs a token (constant CSRFCHECK_WITH_TOKEN is defined) is refused by CSRF protection in main.inc.php. Token not provided.\n";
673 dol_syslog(
"--- Access to ".(empty($_SERVER[
"REQUEST_METHOD"]) ?
'' : $_SERVER[
"REQUEST_METHOD"].
' ').$_SERVER[
"PHP_SELF"].
" refused by CSRF protection (POST method or GET with a sensible value for 'action' parameter) in main.inc.php. Token not provided.", LOG_WARNING);
674 print
"Access to this page this way (POST method or GET with a sensible value for 'action' parameter) is refused by CSRF protection in main.inc.php. Token not provided.\n";
675 print
"If you access your server behind a proxy using url rewriting and the parameter is provided by caller, you might check that all HTTP header are propagated (or add the line \$dolibarr_nocsrfcheck=1 into your conf.php file or MAIN_SECURITY_CSRF_WITH_TOKEN to 0";
679 print
" into setup).\n";
686 $sessiontokenforthisurl = (empty($_SESSION[
'token']) ?
'' : $_SESSION[
'token']);
688 if (GETPOSTISSET(
'token') &&
GETPOST(
'token') !=
'notrequired' &&
GETPOST(
'token',
'alpha') != $sessiontokenforthisurl) {
689 dol_syslog(
"--- Access to ".(empty($_SERVER[
"REQUEST_METHOD"]) ?
'' : $_SERVER[
"REQUEST_METHOD"].
' ').$_SERVER[
"PHP_SELF"].
" refused by CSRF protection (invalid token), so we disable POST and some GET parameters - referrer=".(empty($_SERVER[
'HTTP_REFERER']) ?
'' : $_SERVER[
'HTTP_REFERER']).
", action=".
GETPOST(
'action',
'aZ09').
", _GET|POST['token']=".
GETPOST(
'token',
'alpha'), LOG_WARNING);
692 if (!defined(
'NOTOKENRENEWAL')) {
694 setEventMessages(
'SecurityTokenHasExpiredSoActionHasBeenCanceledPleaseRetry',
null,
'warnings',
'', 1);
697 if (isset($_POST[
'id'])) {
698 $savid = ((int) $_POST[
'id']);
701 unset($_GET[
'confirm']);
702 unset($_GET[
'action']);
703 unset($_GET[
'confirmmassaction']);
704 unset($_GET[
'massaction']);
705 unset($_GET[
'token']);
707 $_POST[
'id'] = ((int) $savid);
710 $_GET[
'errorcode'] =
'InvalidToken';
717if (GETPOSTISSET(
'disablemodules')) {
718 $_SESSION[
"disablemodules"] =
GETPOST(
'disablemodules',
'alpha');
720if (!empty($_SESSION[
"disablemodules"])) {
721 $modulepartkeys = array(
'css',
'js',
'tabs',
'triggers',
'login',
'substitutions',
'menus',
'theme',
'sms',
'tpl',
'barcode',
'models',
'societe',
'hooks',
'dir',
'syslog',
'tpllinkable',
'contactelement',
'moduleforexternal',
'websitetemplates');
723 $disabled_modules = explode(
',', $_SESSION[
"disablemodules"]);
724 foreach ($disabled_modules as $module) {
726 if (empty($conf->$module)) {
729 $conf->$module->enabled =
false;
730 foreach ($modulepartkeys as $modulepartkey) {
731 unset($conf->modules_parts[$modulepartkey][$module]);
733 if ($module ==
'fournisseur') {
734 $conf->supplier_order->enabled = 0;
735 $conf->supplier_invoice->enabled = 0;
742$modulepart = explode(
"/", $_SERVER[
"PHP_SELF"]);
743if (is_array($modulepart) && count($modulepart) > 0) {
744 foreach ($conf->modules as $module) {
745 if (in_array($module, $modulepart)) {
746 $modulepart = $module;
751if (is_array($modulepart)) {
762if (!defined(
'NOLOGIN')) {
766 if (defined(
'MAIN_AUTHENTICATION_MODE')) {
767 $dolibarr_main_authentication = constant(
'MAIN_AUTHENTICATION_MODE');
770 if (empty($dolibarr_main_authentication)) {
771 $dolibarr_main_authentication =
'dolibarr';
774 if ($dolibarr_main_authentication ==
'forceuser' && empty($dolibarr_auto_user)) {
775 $dolibarr_auto_user =
'auto';
779 $authmode = explode(
',', $dolibarr_main_authentication);
782 if (!count($authmode)) {
783 $langs->load(
'main');
784 dol_print_error(
null, $langs->trans(
"ErrorConfigParameterNotDefined",
'dolibarr_main_authentication'));
791 $resultFetchUser =
'';
793 if (!isset($_SESSION[
"dol_login"])) {
795 include_once DOL_DOCUMENT_ROOT.
'/core/lib/security2.lib.php';
797 $dol_dst_observed =
GETPOSTINT(
"dst_observed", 3);
799 $dol_dst_second =
GETPOSTINT(
"dst_second", 3);
800 $dol_screenwidth =
GETPOSTINT(
"screenwidth", 3);
801 $dol_screenheight =
GETPOSTINT(
"screenheight", 3);
802 $dol_hide_topmenu =
GETPOSTINT(
'dol_hide_topmenu', 3);
803 $dol_hide_leftmenu =
GETPOSTINT(
'dol_hide_leftmenu', 3);
804 $dol_optimize_smallscreen =
GETPOSTINT(
'dol_optimize_smallscreen', 3);
805 $dol_no_mouse_hover =
GETPOSTINT(
'dol_no_mouse_hover', 3);
806 $dol_use_jmobile =
GETPOSTINT(
'dol_use_jmobile', 3);
809 if (!empty($dolibarr_main_demo) && $_SERVER[
'PHP_SELF'] == DOL_URL_ROOT.
'/index.php') {
810 if (empty($_SERVER[
'HTTP_REFERER']) || !preg_match(
'/public/', $_SERVER[
'HTTP_REFERER'])) {
811 dol_syslog(
"Call index page from another url than demo page (call is done from page ".(empty($_SERVER[
'HTTP_REFERER']) ?
'' : $_SERVER[
'HTTP_REFER']).
")");
813 $url .= ($url ?
'&' :
'').($dol_hide_topmenu ?
'dol_hide_topmenu='.$dol_hide_topmenu :
'');
814 $url .= ($url ?
'&' :
'').($dol_hide_leftmenu ?
'dol_hide_leftmenu='.$dol_hide_leftmenu :
'');
815 $url .= ($url ?
'&' :
'').($dol_optimize_smallscreen ?
'dol_optimize_smallscreen='.$dol_optimize_smallscreen :
'');
816 $url .= ($url ?
'&' :
'').($dol_no_mouse_hover ?
'dol_no_mouse_hover='.$dol_no_mouse_hover :
'');
817 $url .= ($url ?
'&' :
'').($dol_use_jmobile ?
'dol_use_jmobile='.$dol_use_jmobile :
'');
818 $url = DOL_URL_ROOT.
'/public/demo/index.php'.($url ?
'?'.$url :
'');
819 header(
"Location: ".$url);
826 $hookmanager->initHooks(array(
'login'));
827 $parameters = array();
828 $reshook = $hookmanager->executeHooks(
'beforeLoginAuthentication', $parameters, $user, $action);
835 if ($test &&
GETPOST(
"username",
"alpha", 2) &&
getDolGlobalString(
'MAIN_SECURITY_ENABLECAPTCHA') && !isset($_SESSION[
'dol_bypass_antispam'])) {
836 $sessionkey =
'dol_antispam_value';
837 $ok = (array_key_exists($sessionkey, $_SESSION) ===
true && (strtolower($_SESSION[$sessionkey]) === strtolower(
GETPOST(
'code',
'restricthtml'))));
841 dol_syslog(
'Bad value for code, connection refused', LOG_NOTICE);
843 $langs->loadLangs(array(
'main',
'errors'));
845 $_SESSION[
"dol_loginmesg"] = $langs->transnoentitiesnoconv(
"ErrorBadValueForCode");
849 $user->context[
'audit'] =
'ErrorBadValueForCode - login='.GETPOST(
"username",
"alpha", 2);
852 $result = $user->call_trigger(
'USER_LOGIN_FAILED', $user);
860 $hookmanager->initHooks(array(
'login'));
861 $parameters = array(
'dol_authmode' => $authmode,
'dol_loginmesg' => $_SESSION[
"dol_loginmesg"]);
862 $reshook = $hookmanager->executeHooks(
'afterLoginFailed', $parameters, $user, $action);
871 $allowedmethodtopostusername = 3;
872 if (defined(
'MAIN_AUTHENTICATION_POST_METHOD')) {
873 $allowedmethodtopostusername = constant(
'MAIN_AUTHENTICATION_POST_METHOD');
876 $usertotest = (!empty($_COOKIE[
'login_dolibarr']) ? preg_replace(
'/[^a-zA-Z0-9_@\-\.]/',
'', $_COOKIE[
'login_dolibarr']) :
GETPOST(
"username",
"alpha", $allowedmethodtopostusername));
877 $passwordtotest =
GETPOST(
'password',
'none', $allowedmethodtopostusername);
878 $entitytotest = (
GETPOSTINT(
'entity') ?
GETPOSTINT(
'entity') : (!empty($conf->entity) ? $conf->entity : 1));
881 $goontestloop =
false;
882 if (isset($_SERVER[
"REMOTE_USER"]) && in_array(
'http', $authmode)) {
883 $goontestloop =
true;
885 if ($dolibarr_main_authentication ==
'forceuser' && !empty($dolibarr_auto_user)) {
886 $goontestloop =
true;
888 if (
GETPOST(
"username",
"alpha", $allowedmethodtopostusername)) {
889 $goontestloop =
true;
891 if (
GETPOST(
'openid_mode',
'alpha', 1)) {
892 $goontestloop =
true;
894 if (
GETPOST(
'beforeoauthloginredirect') ||
GETPOST(
'afteroauthloginreturn')) {
895 $goontestloop =
true;
897 if (!empty($_COOKIE[
'login_dolibarr'])) {
898 $goontestloop =
true;
901 if (!is_object($langs)) {
902 include_once DOL_DOCUMENT_ROOT.
'/core/class/translate.class.php';
905 if (defined(
'MAIN_LANG_DEFAULT')) {
906 $langcode = constant(
'MAIN_LANG_DEFAULT');
908 $langs->setDefaultLang($langcode);
914 if ($test && $goontestloop && (
GETPOST(
'actionlogin',
'aZ09') ==
'login' || $dolibarr_main_authentication !=
'dolibarr')) {
917 $oauthmodetotestarray = array(
'google');
918 foreach ($oauthmodetotestarray as $oauthmodetotest) {
919 if (in_array($oauthmodetotest.
'oauth', $authmode)) {
921 if (
GETPOST(
'beforeoauthloginredirect') == $oauthmodetotest ||
GETPOST(
'afteroauthloginreturn')) {
925 dol_syslog(
"User did not click on link for OAuth or is not on the OAuth return, so we disable check using ".$oauthmodetotest);
926 foreach ($authmode as $tmpkey => $tmpval) {
927 if ($tmpval == $oauthmodetotest.
'oauth') {
928 unset($authmode[$tmpkey]);
937 if ($login ===
'--bad-login-validity--') {
944 $dol_authmode = $conf->authmode;
945 $dol_tz = empty($_POST[
"tz"]) ? (empty($_SESSION[
"tz"]) ?
'' : $_SESSION[
"tz"]) : $_POST[
"tz"];
946 $dol_tz_string = empty($_POST[
"tz_string"]) ? (empty($_SESSION[
"tz_string"]) ?
'' : $_SESSION[
"tz_string"]) : $_POST[
"tz_string"];
947 $dol_tz_string = preg_replace(
'/\s*\(.+\)$/',
'', $dol_tz_string);
948 $dol_tz_string = preg_replace(
'/,/',
'/', $dol_tz_string);
949 $dol_tz_string = preg_replace(
'/\s/',
'_', $dol_tz_string);
952 $dol_dst_first = empty($_POST[
"dst_first"]) ? (empty($_SESSION[
"dst_first"]) ?
'' : $_SESSION[
"dst_first"]) : $_POST[
"dst_first"];
953 $dol_dst_second = empty($_POST[
"dst_second"]) ? (empty($_SESSION[
"dst_second"]) ?
'' : $_SESSION[
"dst_second"]) : $_POST[
"dst_second"];
954 if ($dol_dst_first && $dol_dst_second) {
955 include_once DOL_DOCUMENT_ROOT.
'/core/lib/date.lib.php';
959 if ($datenow >= $datefirst && $datenow < $datesecond) {
963 $dol_screenheight = empty($_POST[
"screenheight"]) ? (empty($_SESSION[
"dol_screenheight"]) ?
'' : $_SESSION[
"dol_screenheight"]) : $_POST[
"screenheight"];
964 $dol_screenwidth = empty($_POST[
"screenwidth"]) ? (empty($_SESSION[
"dol_screenwidth"]) ?
'' : $_SESSION[
"dol_screenwidth"]) : $_POST[
"screenwidth"];
969 dol_syslog(
'Bad password, connection refused (see a previous notice message for more info)', LOG_NOTICE);
971 $langs->loadLangs(array(
'main',
'errors'));
975 if (empty($_SESSION[
"dol_loginmesg"])) {
976 $_SESSION[
"dol_loginmesg"] = $langs->transnoentitiesnoconv(
"ErrorBadLoginPassword");
980 $user->context[
'audit'] = $langs->trans(
"ErrorBadLoginPassword").
' - login='.
GETPOST(
"username",
"alpha", 2);
983 $result = $user->call_trigger(
'USER_LOGIN_FAILED', $user);
991 $hookmanager->initHooks(array(
'login'));
992 $parameters = array(
'dol_authmode' => $dol_authmode,
'dol_loginmesg' => $_SESSION[
"dol_loginmesg"]);
993 $reshook = $hookmanager->executeHooks(
'afterLoginFailed', $parameters, $user, $action);
1003 if (!$login || (in_array(
'ldap', $authmode) && empty($passwordtotest))) {
1005 dol_syslog(
"--- Access to ".(empty($_SERVER[
"REQUEST_METHOD"]) ?
'' : $_SERVER[
"REQUEST_METHOD"].
' ').$_SERVER[
"PHP_SELF"].
" - action=".
GETPOST(
'action',
'aZ09').
" - actionlogin=".
GETPOST(
'actionlogin',
'aZ09').
" - showing the login form and exit", LOG_NOTICE);
1006 if (defined(
'NOREDIRECTBYMAINTOLOGIN')) {
1011 return 'ERROR_NOT_LOGGED';
1013 if (!empty($_SERVER[
"HTTP_USER_AGENT"]) && $_SERVER[
"HTTP_USER_AGENT"] ==
'securitytest') {
1014 http_response_code(401);
1016 dol_loginfunction($langs, $conf, (!empty($mysoc) ? $mysoc :
''));
1021 $resultFetchUser = $user->fetch(
'', $login,
'', 1, ($entitytotest > 0 ? $entitytotest : -1));
1022 if ($resultFetchUser <= 0 || $user->isNotIntoValidityDateRange()) {
1023 dol_syslog(
'User not found or not valid, connection refused');
1025 session_set_cookie_params(0,
'/',
null, (empty($dolibarr_main_force_https) ?
false : true), true);
1026 session_name($sessionname);
1029 if ($resultFetchUser == 0) {
1031 $langs->loadLangs(array(
'main',
'errors'));
1033 $_SESSION[
"dol_loginmesg"] = $langs->transnoentitiesnoconv(
"ErrorCantLoadUserFromDolibarrDatabase", $login);
1035 $user->context[
'audit'] =
'ErrorCantLoadUserFromDolibarrDatabase - login='.$login;
1036 } elseif ($resultFetchUser < 0) {
1037 $_SESSION[
"dol_loginmesg"] = $user->error;
1039 $user->context[
'audit'] = $user->error;
1042 $langs->loadLangs(array(
'main',
'errors'));
1044 $_SESSION[
"dol_loginmesg"] = $langs->transnoentitiesnoconv(
"ErrorLoginDateValidity");
1046 $user->context[
'audit'] = $langs->trans(
"ErrorLoginDateValidity").
' - login='.$login;
1050 $result = $user->call_trigger(
'USER_LOGIN_FAILED', $user);
1059 $hookmanager->initHooks(array(
'login'));
1060 $parameters = array(
'dol_authmode' => $dol_authmode,
'dol_loginmesg' => $_SESSION[
"dol_loginmesg"]);
1061 $reshook = $hookmanager->executeHooks(
'afterLoginFailed', $parameters, $user, $action);
1066 $paramsurl = array();
1068 $paramsurl[] =
'textbrowser='.GETPOSTINT(
'textbrowser');
1071 $paramsurl[] =
'nojs='.GETPOSTINT(
'nojs');
1073 if (
GETPOST(
'lang',
'aZ09')) {
1074 $paramsurl[] =
'lang='.GETPOST(
'lang',
'aZ09');
1076 header(
'Location: '.DOL_URL_ROOT.
'/index.php'.(count($paramsurl) ?
'?'.implode(
'&', $paramsurl) :
''));
1080 if (!empty($user->conf->MAIN_LANG_DEFAULT)) {
1081 $langs->setDefaultLang($user->conf->MAIN_LANG_DEFAULT);
1086 $login = $_SESSION[
"dol_login"];
1087 $entity = isset($_SESSION[
"dol_entity"]) ? $_SESSION[
"dol_entity"] : 0;
1088 dol_syslog(
"- This is an already logged session. _SESSION['dol_login']=".$login.
" _SESSION['dol_entity']=".$entity, LOG_DEBUG);
1090 $resultFetchUser = $user->fetch(
'', $login,
'', 1, ($entity > 0 ? $entity : -1));
1094 if ($resultFetchUser <= 0
1095 || ($user->flagdelsessionsbefore && !empty($_SESSION[
"dol_logindate"]) && $user->flagdelsessionsbefore > $_SESSION[
"dol_logindate"])
1096 || ($user->status != $user::STATUS_ENABLED)
1097 || ($user->isNotIntoValidityDateRange())) {
1098 if ($resultFetchUser <= 0) {
1100 dol_syslog(
"Can't load user even if session logged. _SESSION['dol_login']=".$login, LOG_WARNING);
1101 } elseif ($user->flagdelsessionsbefore && !empty($_SESSION[
"dol_logindate"]) && $user->flagdelsessionsbefore > $_SESSION[
"dol_logindate"]) {
1103 dol_syslog(
"The user has a date for session invalidation = ".$user->flagdelsessionsbefore.
" and a session date = ".$_SESSION[
"dol_logindate"].
". We must invalidate its sessions.");
1104 } elseif ($user->status != $user::STATUS_ENABLED) {
1109 dol_syslog(
"The user login has a validity between [".$user->datestartvalidity.
" and ".$user->dateendvalidity.
"], current date is ".
dol_now());
1112 session_set_cookie_params(0,
'/',
null, (empty($dolibarr_main_force_https) ?
false : true), true);
1113 session_name($sessionname);
1116 if ($resultFetchUser == 0) {
1117 $langs->loadLangs(array(
'main',
'errors'));
1119 $_SESSION[
"dol_loginmesg"] = $langs->transnoentitiesnoconv(
"ErrorCantLoadUserFromDolibarrDatabase", $login);
1121 $user->context[
'audit'] =
'ErrorCantLoadUserFromDolibarrDatabase - login='.$login;
1122 } elseif ($resultFetchUser < 0) {
1123 $_SESSION[
"dol_loginmesg"] = $user->error;
1125 $user->context[
'audit'] = $user->error;
1127 $langs->loadLangs(array(
'main',
'errors'));
1129 $_SESSION[
"dol_loginmesg"] = $langs->transnoentitiesnoconv(
"ErrorSessionInvalidatedAfterPasswordChange");
1131 $user->context[
'audit'] =
'ErrorUserSessionWasInvalidated - login='.$login;
1135 $result = $user->call_trigger(
'USER_LOGIN_FAILED', $user);
1143 $hookmanager->initHooks(array(
'login'));
1144 $parameters = array(
'dol_authmode' => (isset($dol_authmode) ? $dol_authmode :
''),
'dol_loginmesg' => $_SESSION[
"dol_loginmesg"]);
1145 $reshook = $hookmanager->executeHooks(
'afterLoginFailed', $parameters, $user, $action);
1150 $paramsurl = array();
1152 $paramsurl[] =
'textbrowser='.GETPOSTINT(
'textbrowser');
1155 $paramsurl[] =
'nojs='.GETPOSTINT(
'nojs');
1157 if (
GETPOST(
'lang',
'aZ09')) {
1158 $paramsurl[] =
'lang='.GETPOST(
'lang',
'aZ09');
1161 header(
'Location: '.DOL_URL_ROOT.
'/index.php'.(count($paramsurl) ?
'?'.implode(
'&', $paramsurl) :
''));
1165 $hookmanager->initHooks(array(
'main'));
1168 if (!empty($_GET[
'save_lastsearch_values']) && !empty($_SERVER[
"HTTP_REFERER"])) {
1169 $relativepathstring = preg_replace(
'/\?.*$/',
'', $_SERVER[
"HTTP_REFERER"]);
1170 $relativepathstring = preg_replace(
'/^https?:\/\/[^\/]*/',
'', $relativepathstring);
1172 if (constant(
'DOL_URL_ROOT')) {
1173 $relativepathstring = preg_replace(
'/^'.preg_quote(constant(
'DOL_URL_ROOT'),
'/').
'/',
'', $relativepathstring);
1175 $relativepathstring = preg_replace(
'/^\//',
'', $relativepathstring);
1176 $relativepathstring = preg_replace(
'/^custom\//',
'', $relativepathstring);
1180 if (!empty($_SESSION[
'lastsearch_values_tmp_'.$relativepathstring])) {
1181 $_SESSION[
'lastsearch_values_'.$relativepathstring] = $_SESSION[
'lastsearch_values_tmp_'.$relativepathstring];
1182 unset($_SESSION[
'lastsearch_values_tmp_'.$relativepathstring]);
1184 if (!empty($_SESSION[
'lastsearch_contextpage_tmp_'.$relativepathstring])) {
1185 $_SESSION[
'lastsearch_contextpage_'.$relativepathstring] = $_SESSION[
'lastsearch_contextpage_tmp_'.$relativepathstring];
1186 unset($_SESSION[
'lastsearch_contextpage_tmp_'.$relativepathstring]);
1188 if (!empty($_SESSION[
'lastsearch_limit_tmp_'.$relativepathstring]) && $_SESSION[
'lastsearch_limit_tmp_'.$relativepathstring] != $conf->liste_limit) {
1189 $_SESSION[
'lastsearch_limit_'.$relativepathstring] = $_SESSION[
'lastsearch_limit_tmp_'.$relativepathstring];
1190 unset($_SESSION[
'lastsearch_limit_tmp_'.$relativepathstring]);
1192 if (!empty($_SESSION[
'lastsearch_page_tmp_'.$relativepathstring]) && $_SESSION[
'lastsearch_page_tmp_'.$relativepathstring] > 0) {
1193 $_SESSION[
'lastsearch_page_'.$relativepathstring] = $_SESSION[
'lastsearch_page_tmp_'.$relativepathstring];
1194 unset($_SESSION[
'lastsearch_page_tmp_'.$relativepathstring]);
1196 if (!empty($_SESSION[
'lastsearch_mode_tmp_'.$relativepathstring])) {
1197 $_SESSION[
'lastsearch_mode_'.$relativepathstring] = $_SESSION[
'lastsearch_mode_tmp_'.$relativepathstring];
1198 unset($_SESSION[
'lastsearch_mode_tmp_'.$relativepathstring]);
1201 if (!empty($_GET[
'save_pageforbacktolist']) && !empty($_SERVER[
"HTTP_REFERER"])) {
1202 if (empty($_SESSION[
'pageforbacktolist'])) {
1203 $pageforbacktolistarray = array();
1205 $pageforbacktolistarray = $_SESSION[
'pageforbacktolist'];
1207 $tmparray = explode(
':', $_GET[
'save_pageforbacktolist'], 2);
1208 if (!empty($tmparray[0]) && !empty($tmparray[1])) {
1209 $pageforbacktolistarray[$tmparray[0]] = $tmparray[1];
1210 $_SESSION[
'pageforbacktolist'] = $pageforbacktolistarray;
1215 $parameters = array();
1216 $reshook = $hookmanager->executeHooks(
'updateSession', $parameters, $user, $action);
1225 if (!isset($_SESSION[
"dol_login"])) {
1230 $_SESSION[
"dol_login"] = $user->login;
1231 $_SESSION[
"dol_logindate"] =
dol_now(
'gmt');
1232 $_SESSION[
"dol_authmode"] = isset($dol_authmode) ? $dol_authmode :
'';
1233 $_SESSION[
"dol_tz"] = isset($dol_tz) ? $dol_tz :
'';
1234 $_SESSION[
"dol_tz_string"] = isset($dol_tz_string) ? $dol_tz_string :
'';
1235 $_SESSION[
"dol_dst"] = isset($dol_dst) ? $dol_dst :
'';
1236 $_SESSION[
"dol_dst_observed"] = isset($dol_dst_observed) ? $dol_dst_observed :
'';
1237 $_SESSION[
"dol_dst_first"] = isset($dol_dst_first) ? $dol_dst_first :
'';
1238 $_SESSION[
"dol_dst_second"] = isset($dol_dst_second) ? $dol_dst_second :
'';
1239 $_SESSION[
"dol_screenwidth"] = isset($dol_screenwidth) ? $dol_screenwidth :
'';
1240 $_SESSION[
"dol_screenheight"] = isset($dol_screenheight) ? $dol_screenheight :
'';
1242 $_SESSION[
"dol_entity"] = $conf->entity;
1244 if (!empty($dol_hide_topmenu)) {
1245 $_SESSION[
'dol_hide_topmenu'] = $dol_hide_topmenu;
1247 if (!empty($dol_hide_leftmenu)) {
1248 $_SESSION[
'dol_hide_leftmenu'] = $dol_hide_leftmenu;
1250 if (!empty($dol_optimize_smallscreen)) {
1251 $_SESSION[
'dol_optimize_smallscreen'] = $dol_optimize_smallscreen;
1253 if (!empty($dol_no_mouse_hover)) {
1254 $_SESSION[
'dol_no_mouse_hover'] = $dol_no_mouse_hover;
1256 if (!empty($dol_use_jmobile)) {
1257 $_SESSION[
'dol_use_jmobile'] = $dol_use_jmobile;
1260 dol_syslog(
"This is a new started user session. _SESSION['dol_login']=".$_SESSION[
"dol_login"].
" Session id=".session_id());
1264 $user->update_last_login_date();
1266 $loginfo =
'TZ='.$_SESSION[
"dol_tz"].
';TZString='.$_SESSION[
"dol_tz_string"].
';Screen='.$_SESSION[
"dol_screenwidth"].
'x'.$_SESSION[
"dol_screenheight"];
1267 $loginfo .=
' - authmode='.$dol_authmode.
' - entity='.$conf->entity;
1270 $user->context[
'audit'] = $loginfo;
1271 $user->context[
'authentication_method'] = $dol_authmode;
1274 $result = $user->call_trigger(
'USER_LOGIN', $user);
1282 $hookmanager->initHooks(array(
'login'));
1283 $parameters = array(
'dol_authmode' => $dol_authmode,
'dol_loginfo' => $loginfo);
1284 $reshook = $hookmanager->executeHooks(
'afterLogin', $parameters, $user, $action);
1292 dol_print_error($db,
'Error in some triggers USER_LOGIN or in some hooks afterLogin');
1299 $landingpage = (empty($user->conf->MAIN_LANDING_PAGE) ? (!
getDolGlobalString(
'MAIN_LANDING_PAGE') ?
'' : $conf->global->MAIN_LANDING_PAGE) : $user->
conf->MAIN_LANDING_PAGE);
1300 if (!empty($landingpage)) {
1302 if ($_SERVER[
"PHP_SELF"] != $newpath) {
1303 header(
'Location: '.$newpath);
1312 $user->rights->user->user->lire = 1;
1313 $user->rights->user->user->creer = 1;
1314 $user->rights->user->user->password = 1;
1315 $user->rights->user->user->supprimer = 1;
1316 $user->rights->user->self->creer = 1;
1317 $user->rights->user->self->password = 1;
1321 if (!$user->hasRight(
'user',
'user_advance')) {
1322 $user->rights->user->user_advance =
new stdClass();
1324 if (!$user->hasRight(
'user',
'self_advance')) {
1325 $user->rights->user->self_advance =
new stdClass();
1327 if (!$user->hasRight(
'user',
'group_advance')) {
1328 $user->rights->user->group_advance =
new stdClass();
1331 $user->rights->user->user_advance->readperms = 1;
1332 $user->rights->user->user_advance->write = 1;
1333 $user->rights->user->self_advance->readperms = 1;
1334 $user->rights->user->self_advance->writeperms = 1;
1335 $user->rights->user->group_advance->read = 1;
1336 $user->rights->user->group_advance->readperms = 1;
1337 $user->rights->user->group_advance->write = 1;
1338 $user->rights->user->group_advance->delete = 1;
1347 if (isset($user->conf->MAIN_SIZE_LISTE_LIMIT)) {
1348 $conf->liste_limit = $user->conf->MAIN_SIZE_LISTE_LIMIT;
1350 if (isset($user->conf->PRODUIT_LIMIT_SIZE)) {
1351 $conf->product->limit_size = $user->conf->PRODUIT_LIMIT_SIZE;
1356 $conf->theme = $user->conf->MAIN_THEME;
1357 $conf->css =
"/theme/".$conf->theme.
"/style.css.php";
1361 if (!empty($user) && method_exists($user,
'loadDefaultValues') && !defined(
'NODEFAULTVALUES')) {
1362 $user->loadDefaultValues();
1368if (
GETPOST(
'theme',
'aZ09')) {
1369 $conf->theme =
GETPOST(
'theme',
'aZ09', 1);
1370 $conf->css =
"/theme/".$conf->theme.
"/style.css.php";
1375 $conf->use_javascript_ajax = 0;
1377 if (!empty($user->conf->MAIN_DISABLE_JAVASCRIPT)) {
1378 $conf->use_javascript_ajax = !$user->conf->MAIN_DISABLE_JAVASCRIPT;
1383if (!
getDolGlobalString(
'MAIN_OPTIMIZEFORTEXTBROWSER') && !empty($user->conf->MAIN_OPTIMIZEFORTEXTBROWSER)) {
1384 $conf->global->MAIN_OPTIMIZEFORTEXTBROWSER = $user->conf->MAIN_OPTIMIZEFORTEXTBROWSER;
1386 $conf->global->THEME_TOPMENU_DISABLE_IMAGE = 1;
1393$conf->global->MAIN_OPTIMIZEFORCOLORBLIND = empty($user->conf->MAIN_OPTIMIZEFORCOLORBLIND) ?
'' : $user->conf->MAIN_OPTIMIZEFORCOLORBLIND;
1396if (
GETPOSTINT(
'dol_hide_leftmenu') || !empty($_SESSION[
'dol_hide_leftmenu'])) {
1397 $conf->dol_hide_leftmenu = 1;
1399if (
GETPOSTINT(
'dol_hide_topmenu') || !empty($_SESSION[
'dol_hide_topmenu'])) {
1400 $conf->dol_hide_topmenu = 1;
1402if (
GETPOSTINT(
'dol_optimize_smallscreen') || !empty($_SESSION[
'dol_optimize_smallscreen'])) {
1403 $conf->dol_optimize_smallscreen = 1;
1405if (
GETPOSTINT(
'dol_no_mouse_hover') || !empty($_SESSION[
'dol_no_mouse_hover'])) {
1406 $conf->dol_no_mouse_hover = 1;
1408if (
GETPOSTINT(
'dol_use_jmobile') || !empty($_SESSION[
'dol_use_jmobile'])) {
1409 $conf->dol_use_jmobile = 1;
1412if (!empty($conf->browser->layout) && $conf->browser->layout !=
'classic') {
1413 $conf->dol_no_mouse_hover = 1;
1417if ((!empty($conf->browser->layout) && $conf->browser->layout ==
'phone')
1418 || (!empty($_SESSION[
'dol_screenwidth']) && $_SESSION[
'dol_screenwidth'] < 400)
1419 || (!empty($_SESSION[
'dol_screenheight']) && $_SESSION[
'dol_screenheight'] < 400
1422 $conf->dol_optimize_smallscreen = 1;
1425 $conf->global->PRODUIT_DESC_IN_FORM_ACCORDING_TO_DEVICE = 0;
1429if (!empty($conf->dol_use_jmobile) && in_array($conf->theme, array(
'bureau2crea',
'cameleo',
'amarok'))) {
1430 $conf->theme =
'eldy';
1431 $conf->css =
"/theme/".$conf->theme.
"/style.css.php";
1434if (!defined(
'NOREQUIRETRAN')) {
1435 if (!
GETPOST(
'lang',
'aZ09')) {
1437 if (!empty($user->conf->MAIN_LANG_DEFAULT)) {
1440 if ($langs->getDefaultLang() != $user->conf->MAIN_LANG_DEFAULT) {
1441 $langs->setDefaultLang($user->conf->MAIN_LANG_DEFAULT);
1447if (!defined(
'NOLOGIN')) {
1450 if (!$user->login) {
1455 if ($user->statut < 1) {
1457 $langs->loadLangs(array(
"errors",
"other"));
1458 dol_syslog(
"Authentication KO as login is disabled", LOG_NOTICE);
1466dol_syslog(
"--- Access to ".(empty($_SERVER[
"REQUEST_METHOD"]) ?
'' : $_SERVER[
"REQUEST_METHOD"].
' ').$_SERVER[
"PHP_SELF"].
' - action='.
GETPOST(
'action',
'aZ09').
', massaction='.
GETPOST(
'massaction',
'aZ09').(defined(
'NOTOKENRENEWAL') ?
' NOTOKENRENEWAL='.constant(
'NOTOKENRENEWAL') :
''), LOG_NOTICE);
1471if (!defined(
'NOREQUIRETRAN')) {
1473 $langs->loadLangs(array(
'main',
'dict'));
1477$bc = array(0 =>
'class="impair"', 1 =>
'class="pair"');
1478$bcdd = array(0 =>
'class="drag drop oddeven"', 1 =>
'class="drag drop oddeven"');
1479$bcnd = array(0 =>
'class="nodrag nodrop nohover"', 1 =>
'class="nodrag nodrop nohoverpair"');
1480$bctag = array(0 =>
'class="impair tagtr"', 1 =>
'class="pair tagtr"');
1492if (empty($conf->browser->firefox)) {
1493 define(
'ROWS_1', 1);
1494 define(
'ROWS_2', 2);
1495 define(
'ROWS_3', 3);
1496 define(
'ROWS_4', 4);
1497 define(
'ROWS_5', 5);
1498 define(
'ROWS_6', 6);
1499 define(
'ROWS_7', 7);
1500 define(
'ROWS_8', 8);
1501 define(
'ROWS_9', 9);
1503 define(
'ROWS_1', 0);
1504 define(
'ROWS_2', 1);
1505 define(
'ROWS_3', 2);
1506 define(
'ROWS_4', 3);
1507 define(
'ROWS_5', 4);
1508 define(
'ROWS_6', 5);
1509 define(
'ROWS_7', 6);
1510 define(
'ROWS_8', 7);
1511 define(
'ROWS_9', 8);
1514$heightforframes = 50;
1517if (!defined(
'NOREQUIREMENU')) {
1518 if (empty($user->socid)) {
1519 $conf->standard_menu = (!
getDolGlobalString(
'MAIN_MENU_STANDARD_FORCED') ? (!
getDolGlobalString(
'MAIN_MENU_STANDARD') ?
'eldy_menu.php' : $conf->global->MAIN_MENU_STANDARD) : $conf->global->MAIN_MENU_STANDARD_FORCED);
1522 $conf->standard_menu = (!
getDolGlobalString(
'MAIN_MENUFRONT_STANDARD_FORCED') ? (!
getDolGlobalString(
'MAIN_MENUFRONT_STANDARD') ?
'eldy_menu.php' : $conf->global->MAIN_MENUFRONT_STANDARD) : $conf->global->MAIN_MENUFRONT_STANDARD_FORCED);
1526 $file_menu = $conf->standard_menu;
1527 if (
GETPOST(
'menu',
'alpha')) {
1528 $file_menu =
GETPOST(
'menu',
'alpha');
1530 if (!class_exists(
'MenuManager')) {
1532 $dirmenus = array_merge(array(
"/core/menus/"), (array) $conf->modules_parts[
'menus']);
1533 foreach ($dirmenus as $dirmenu) {
1535 if (class_exists(
'MenuManager')) {
1539 if (!class_exists(
'MenuManager')) {
1540 dol_syslog(
"You define a menu manager '".$file_menu.
"' that can not be loaded.", LOG_WARNING);
1541 $file_menu =
'eldy_menu.php';
1542 include_once DOL_DOCUMENT_ROOT.
"/core/menus/standard/".$file_menu;
1545 $menumanager =
new MenuManager($db, empty($user->socid) ? 0 : 1);
1549if (!empty(
GETPOST(
'seteventmessages',
'alpha'))) {
1550 $message =
GETPOST(
'seteventmessages',
'alpha');
1551 $messages = explode(
',', $message);
1552 foreach ($messages as $key => $msg) {
1553 $tmp = explode(
':', $msg);
1560if (!function_exists(
"llxHeader")) {
1581 function llxHeader($head =
'', $title =
'', $help_url =
'', $target =
'', $disablejs = 0, $disablehead = 0, $arrayofjs =
'', $arrayofcss =
'', $morequerystring =
'', $morecssonbody =
'', $replacemainareaby =
'', $disablenofollow = 0, $disablenoindex = 0)
1583 global $conf, $hookmanager;
1585 $parameters = array(
1587 'title' => & $title,
1588 'help_url' => & $help_url,
1589 'target' => & $target,
1590 'disablejs' => & $disablejs,
1591 'disablehead' => & $disablehead,
1592 'arrayofjs' => & $arrayofjs,
1593 'arrayofcss' => & $arrayofcss,
1594 'morequerystring' => & $morequerystring,
1595 'morecssonbody' => & $morecssonbody,
1596 'replacemainareaby' => & $replacemainareaby,
1597 'disablenofollow' => & $disablenofollow,
1598 'disablenoindex' => & $disablenoindex
1601 $reshook = $hookmanager->executeHooks(
'llxHeader', $parameters);
1603 print $hookmanager->resPrint;
1608 top_htmlhead($head, $title, $disablejs, $disablehead, $arrayofjs, $arrayofcss, 0, $disablenofollow, $disablenoindex);
1610 $tmpcsstouse =
'sidebar-collapse'.($morecssonbody ?
' '.$morecssonbody :
'');
1612 if ($conf->theme ==
'md' && !in_array($conf->browser->layout, array(
'phone',
'tablet')) && !
getDolGlobalString(
'MAIN_OPTIMIZEFORTEXTBROWSER')) {
1614 if ($mainmenu !=
'website') {
1615 $tmpcsstouse = $morecssonbody;
1620 $tmpcsstouse .=
' colorblind-'.strip_tags(
getDolGlobalString(
'MAIN_OPTIMIZEFORCOLORBLIND'));
1623 print
'<body id="mainbody" class="'.$tmpcsstouse.
'">'.
"\n";
1626 if ((empty($conf->dol_hide_topmenu) ||
GETPOSTINT(
'dol_invisible_topmenu')) && !
GETPOSTINT(
'dol_openinpopup')) {
1627 top_menu($head, $title, $target, $disablejs, $disablehead, $arrayofjs, $arrayofcss, $morequerystring, $help_url);
1630 if (empty($conf->dol_hide_leftmenu) && !
GETPOST(
'dol_openinpopup',
'aZ09')) {
1631 left_menu(array(), $help_url,
'',
'', 1, $title, 1);
1635 if ($replacemainareaby) {
1636 print $replacemainareaby;
3282function left_menu($menu_array_before, $helppagename =
'', $notused =
'', $menu_array_after = array(), $leftmenuwithoutmainarea = 0, $title =
'', $acceptdelayedhtml = 0)
3284 global $user, $conf, $langs, $db, $form;
3285 global $hookmanager, $menumanager;
3289 if (!empty($menu_array_before)) {
3290 dol_syslog(
"Deprecated parameter menu_array_before was used when calling main::left_menu function. Menu entries of module should now be defined into module descriptor and not provided when calling left_menu.", LOG_WARNING);
3293 if (empty($conf->dol_hide_leftmenu) && (!defined(
'NOREQUIREMENU') || !constant(
'NOREQUIREMENU'))) {
3295 $hookmanager->initHooks(array(
'leftblock'));
3297 print
"\n".
'<!-- Begin side-nav id-left -->'.
"\n".
'<div class="side-nav"><div id="id-left">'.
"\n";
3300 if (!is_object($form)) {
3301 $form =
new Form($db);
3306 if ($conf->browser->layout ==
'phone') {
3307 $conf->global->MAIN_USE_OLD_SEARCH_FORM = 1;
3311 $arrayresult = array();
3312 include DOL_DOCUMENT_ROOT.
'/core/ajax/selectsearchbox.php';
3317 $stringforfirstkey = $langs->trans(
"KeyboardShortcut");
3318 if ($conf->browser->name ==
'chrome') {
3319 $stringforfirstkey .=
' ALT +';
3320 } elseif ($conf->browser->name ==
'firefox') {
3321 $stringforfirstkey .=
' ALT + SHIFT +';
3323 $stringforfirstkey .=
' CTL +';
3327 $textsearch =
'<span class="fa fa-search paddingright pictofixedwidth"></span>'.$langs->trans(
"Search");
3328 $searchform .= $form->selectArrayFilter(
'searchselectcombo', $arrayresult, $selected,
'accesskey="s"', 1, 0, (!
getDolGlobalString(
'MAIN_SEARCHBOX_CONTENT_LOADED_BEFORE_KEY') ? 1 : 0),
'vmenusearchselectcombo', 1, $textsearch, 1, $stringforfirstkey.
' s');
3330 if (is_array($arrayresult)) {
3331 foreach ($arrayresult as $key => $val) {
3332 $searchform .=
printSearchForm($val[
'url'], $val[
'url'], $val[
'label'],
'maxwidth125',
'search_all', (empty($val[
'shortcut']) ?
'' : $val[
'shortcut']),
'searchleft'.$key, $val[
'img']);
3338 $parameters = array(
'searchform' => $searchform);
3339 $reshook = $hookmanager->executeHooks(
'printSearchForm', $parameters);
3340 if (empty($reshook)) {
3341 $searchform .= $hookmanager->resPrint;
3343 $searchform = $hookmanager->resPrint;
3347 if (
getDolGlobalString(
'MAIN_OPTIMIZEFORTEXTBROWSER') || empty($conf->use_javascript_ajax)) {
3348 $urltosearch = DOL_URL_ROOT.
'/core/search_page.php?showtitlebefore=1';
3349 $searchform =
'<div class="blockvmenuimpair blockvmenusearchphone"><div id="divsearchforms1"><a href="'.$urltosearch.
'" accesskey="s" alt="'.
dol_escape_htmltag($langs->trans(
"ShowSearchFields")).
'">'.$langs->trans(
"Search").
'...</a></div></div>';
3350 } elseif ($conf->use_javascript_ajax &&
getDolGlobalString(
'MAIN_USE_OLD_SEARCH_FORM')) {
3351 $searchform =
'<div class="blockvmenuimpair blockvmenusearchphone"><div id="divsearchforms1"><a href="#" alt="'.dol_escape_htmltag($langs->trans(
"ShowSearchFields")).
'">'.$langs->trans(
"Search").
'...</a></div><div id="divsearchforms2" style="display: none">'.$searchform.
'</div>';
3352 $searchform .=
'<script>
3353 jQuery(document).ready(function () {
3354 jQuery("#divsearchforms1").click(function(){
3355 jQuery("#divsearchforms2").toggle();
3359 $searchform .=
'</div>';
3363 $searchform .=
'<script>
3364 jQuery(document).keydown(function(e){
3365 if( e.which === 70 && e.ctrlKey && e.shiftKey ){
3366 console.log(\'control + shift + f : trigger open global-search dropdown\');
3367 openGlobalSearchDropDown();
3369 if( (e.which === 83 || e.which === 115) && e.altKey ){
3370 console.log(\'alt + s : trigger open global-search dropdown\');
3371 openGlobalSearchDropDown();
3375 var openGlobalSearchDropDown = function() {
3376 jQuery("#searchselectcombo").select2(\'open\');
3382 print
'<!-- Begin left menu -->'.
"\n";
3384 print
'<div class="vmenu"'.(getDolGlobalString(
'MAIN_OPTIMIZEFORTEXTBROWSER') ?
' alt="Left menu"' :
'').
'>'.
"\n\n";
3387 $menumanager->menu_array = $menu_array_before;
3388 $menumanager->menu_array_after = $menu_array_after;
3389 $menumanager->showmenu(
'left', array(
'searchform' => $searchform));
3393 print
"<!-- Begin Help Block-->\n";
3394 print
'<div id="blockvmenuhelp" class="blockvmenuhelp">'.
"\n";
3398 $doliurl =
'https://www.dolibarr.org';
3400 if (preg_match(
'/fr/i', $langs->defaultlang)) {
3401 $doliurl =
'https://www.dolibarr.fr';
3403 if (preg_match(
'/es/i', $langs->defaultlang)) {
3404 $doliurl =
'https://www.dolibarr.es';
3406 if (preg_match(
'/de/i', $langs->defaultlang)) {
3407 $doliurl =
'https://www.dolibarr.de';
3409 if (preg_match(
'/it/i', $langs->defaultlang)) {
3410 $doliurl =
'https://www.dolibarr.it';
3412 if (preg_match(
'/gr/i', $langs->defaultlang)) {
3413 $doliurl =
'https://www.dolibarr.gr';
3416 $appli = constant(
'DOL_APPLICATION_TITLE');
3420 if (preg_match(
'/\d\.\d/', $appli)) {
3421 if (!preg_match(
'/'.preg_quote(DOL_VERSION).
'/', $appli)) {
3422 $appli .=
" (".DOL_VERSION.
")";
3425 $appli .=
" ".DOL_VERSION;
3428 $appli .=
" ".DOL_VERSION;
3430 print
'<div id="blockvmenuhelpapp" class="blockvmenuhelp">';
3432 print
'<a class="help" target="_blank" rel="noopener noreferrer" href="'.$doliurl.
'">';
3434 print
'<span class="help">';
3442 print
'</div>'.
"\n";
3447 require_once DOL_DOCUMENT_ROOT.
'/core/lib/functions2.lib.php';
3450 $bugbaseurl =
'https://github.com/Dolibarr/dolibarr/issues/new?labels=Bug';
3451 $bugbaseurl .=
'&title=';
3452 $bugbaseurl .= urlencode(
"Bug: ");
3453 $bugbaseurl .=
'&body=';
3454 $bugbaseurl .= urlencode(
"# Instructions\n");
3455 $bugbaseurl .= urlencode(
"*This is a template to help you report good issues. You may use [Github Markdown](https://help.github.com/articles/getting-started-with-writing-and-formatting-on-github/) syntax to format your issue report.*\n");
3456 $bugbaseurl .= urlencode(
"*Please:*\n");
3457 $bugbaseurl .= urlencode(
"- *replace the bracket enclosed texts with meaningful information*\n");
3458 $bugbaseurl .= urlencode(
"- *remove any unused sub-section*\n");
3459 $bugbaseurl .= urlencode(
"\n");
3460 $bugbaseurl .= urlencode(
"\n");
3461 $bugbaseurl .= urlencode(
"# Bug\n");
3462 $bugbaseurl .= urlencode(
"[*Short description*]\n");
3463 $bugbaseurl .= urlencode(
"\n");
3464 $bugbaseurl .= urlencode(
"## Environment\n");
3465 $bugbaseurl .= urlencode(
"- **Version**: ".DOL_VERSION.
"\n");
3466 $bugbaseurl .= urlencode(
"- **OS**: ".php_uname(
's').
"\n");
3467 $bugbaseurl .= urlencode(
"- **Web server**: ".$_SERVER[
"SERVER_SOFTWARE"].
"\n");
3468 $bugbaseurl .= urlencode(
"- **PHP**: ".php_sapi_name().
' '.phpversion().
"\n");
3469 $bugbaseurl .= urlencode(
"- **Database**: ".$db::LABEL.
' '.$db->getVersion().
"\n");
3470 $bugbaseurl .= urlencode(
"- **URL(s)**: ".$_SERVER[
"REQUEST_URI"].
"\n");
3471 $bugbaseurl .= urlencode(
"\n");
3472 $bugbaseurl .= urlencode(
"## Expected and actual behavior\n");
3473 $bugbaseurl .= urlencode(
"[*Verbose description*]\n");
3474 $bugbaseurl .= urlencode(
"\n");
3475 $bugbaseurl .= urlencode(
"## Steps to reproduce the behavior\n");
3476 $bugbaseurl .= urlencode(
"[*Verbose description*]\n");
3477 $bugbaseurl .= urlencode(
"\n");
3478 $bugbaseurl .= urlencode(
"## [Attached files](https://help.github.com/articles/issue-attachments) (Screenshots, screencasts, dolibarr.log, debugging information…)\n");
3479 $bugbaseurl .= urlencode(
"[*Files*]\n");
3480 $bugbaseurl .= urlencode(
"\n");
3482 $bugbaseurl .= urlencode(
"\n");
3483 $bugbaseurl .= urlencode(
"## Report\n");
3491 $parameters = array(
'bugbaseurl' => $bugbaseurl);
3492 $reshook = $hookmanager->executeHooks(
'printBugtrackInfo', $parameters);
3493 if (empty($reshook)) {
3494 $bugbaseurl .= $hookmanager->resPrint;
3496 $bugbaseurl = $hookmanager->resPrint;
3499 print
'<div id="blockvmenuhelpbugreport" class="blockvmenuhelp">';
3500 print
'<a class="help" target="_blank" rel="noopener noreferrer" href="'.$bugbaseurl.
'"><i class="fas fa-bug"></i> '.$langs->trans(
"FindBug").
'</a>';
3505 print
"<!-- End Help Block-->\n";
3509 print
"<!-- End left menu -->\n";
3513 $parameters = array();
3514 $reshook = $hookmanager->executeHooks(
'printLeftBlock', $parameters);
3515 print $hookmanager->resPrint;
3517 print
'</div></div> <!-- End side-nav id-left -->';
3521 print
'<!-- Begin right area -->'.
"\n";
3523 if (empty($leftmenuwithoutmainarea)) {