dolibarr 25.0.0-alpha
actions_extrafields.inc.php
Go to the documentation of this file.
1<?php
2/* Copyright (C) 2011-2020 Laurent Destailleur <eldy@users.sourceforge.net>
3 * Copyright (C) 2024-2026 Frédéric France <frederic.france@free.fr>
4 * Copyright (C) 2025-2026 MDW <mdeweerd@users.noreply.github.com>
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 3 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program. If not, see <https://www.gnu.org/licenses/>.
18 * or see https://www.gnu.org/
19 *
20 * $elementype must be defined.
21 */
22
40'@phan-var-force int $error';
41'@phan-var-force string $action';
42'@phan-var-force ?string $pagekey';
43'@phan-var-force string $elementtype';
44'@phan-var-force string $value';
45
46// Prefer $pagekey (the whitelisted request key used by the unified admin/extrafields.php
47// controller) for self-referencing redirects; fall back to $elementtype for any other,
48// older-style caller of this shared include that only defines $elementtype.
49$pagekeyforredirect = isset($pagekey) ? $pagekey : $elementtype;
50
51$maxsizestring = 255;
52$maxsizeint = 10;
53$mesg = '';
54$mesgs = array();
55
56$extrasize = GETPOST('size', 'intcomma');
57$type = GETPOST('type', 'alphanohtml');
58$param = GETPOST('param', 'alphanohtml');
59$css = GETPOST('css', 'alphanohtml');
60$cssview = GETPOST('cssview', 'alphanohtml');
61$csslist = GETPOST('csslist', 'alphanohtml');
62$confirm = GETPOST('confirm', 'alpha');
63
64if ($type == 'double' && strpos($extrasize, ',') === false) {
65 $extrasize = '24,8';
66}
67if ($type == 'date') {
68 $extrasize = '';
69}
70if ($type == 'datetime') {
71 $extrasize = '';
72}
73if ($type == 'select') {
74 $extrasize = '';
75}
76
77// List of reserved words for databases
78$listofreservedwords = array(
79 'ADD', 'ALL', 'ALTER', 'ANALYZE', 'AND', 'AS', 'ASENSITIVE', 'BEFORE', 'BETWEEN', 'BINARY', 'BLOB', 'BOTH', 'CALL', 'CASCADE', 'CASE', 'CHANGE', 'CHAR', 'CHARACTER', 'CHECK', 'COLLATE', 'COLUMN', 'CONDITION', 'CONSTRAINT', 'CONTINUE', 'CONVERT', 'CREATE', 'CROSS', 'CURRENT_DATE', 'CURRENT_TIME', 'CURRENT_TIMESTAMP', 'CURRENT_USER',
80 'CURSOR', 'DATABASE', 'DATABASES', 'DAY_HOUR', 'DAY_MICROSECOND', 'DAY_MINUTE', 'DAY_SECOND', 'DECIMAL', 'DECLARE', 'DEFAULT', 'DELAYED', 'DELETE', 'DESC', 'DESCRIBE', 'DETERMINISTIC', 'DISTINCT', 'DISTINCTROW', 'DOUBLE', 'DROP', 'DUAL',
81 'EACH', 'ELSE', 'ELSEIF', 'ENCLOSED', 'ESCAPED', 'EXISTS', 'EXPLAIN', 'FALSE', 'FETCH', 'FLOAT', 'FLOAT4', 'FLOAT8', 'FORCE', 'FOREIGN', 'FULLTEXT', 'GRANT', 'GROUP', 'HAVING', 'HIGH_PRIORITY', 'HOUR_MICROSECOND', 'HOUR_MINUTE', 'HOUR_SECOND',
82 'IGNORE', 'IGNORE_SERVER_IDS', 'INDEX', 'INFILE', 'INNER', 'INOUT', 'INSENSITIVE', 'INSERT', 'INT', 'INTEGER', 'INTERVAL', 'INTO', 'ITERATE',
83 'KEYS', 'KEYWORD', 'LEAD', 'LEADING', 'LEAVE', 'LEFT', 'LIKE', 'LIMIT', 'LINES', 'LOCALTIME', 'LOCALTIMESTAMP', 'LONGBLOB', 'LONGTEXT', 'MASTER_SSL_VERIFY_SERVER_CERT', 'MATCH', 'MEDIUMBLOB', 'MEDIUMINT', 'MEDIUMTEXT', 'MIDDLEINT', 'MINUTE_MICROSECOND', 'MINUTE_SECOND', 'MODIFIES', 'NATURAL', 'NOT', 'NO_WRITE_TO_BINLOG', 'NUMERIC',
84 'OFFSET', 'ON', 'OPTION', 'OPTIONALLY', 'OUTER', 'OUTFILE', 'OVER',
85 'PARTITION', 'POSITION', 'PRECISION', 'PRIMARY', 'PROCEDURE', 'PURGE', 'RANGE', 'READS', 'READ_WRITE', 'REAL', 'REFERENCES', 'REGEXP', 'RELEASE', 'RENAME', 'REPEAT', 'REQUIRE', 'RESTRICT', 'RETURN', 'REVOKE', 'RIGHT', 'RLIKE',
86 'SCHEMAS', 'SECOND_MICROSECOND', 'SENSITIVE', 'SEPARATOR', 'SIGNAL', 'SMALLINT', 'SPATIAL', 'SPECIFIC', 'SQLEXCEPTION', 'SQLSTATE', 'SQLWARNING', 'SQL_BIG_RESULT', 'SQL_CALC_FOUND_ROWS', 'SQL_SMALL_RESULT', 'SSL', 'STARTING', 'STRAIGHT_JOIN',
87 'TABLE', 'TERMINATED', 'TINYBLOB', 'TINYINT', 'TINYTEXT', 'TRAILING', 'TRIGGER', 'UNDO', 'UNIQUE', 'UNSIGNED', 'UPDATE', 'USAGE', 'USING', 'UTC_DATE', 'UTC_TIME', 'UTC_TIMESTAMP', 'VALUES', 'VARBINARY', 'VARCHAR', 'VARYING',
88 'WHEN', 'WHERE', 'WHILE', 'WRITE', 'XOR', 'YEAR_MONTH', 'ZEROFILL'
89);
90
91// Add attribute
92if ($action == 'add') {
93 if (GETPOST("button") != $langs->trans("Cancel")) {
94 // Check values
95 if (!$type) {
96 $error++;
97 $langs->load("errors");
98 $mesgs[] = $langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("Type"));
99 $action = 'create';
100 }
101 if ($type == 'varchar' && $extrasize <= 0) {
102 $error++;
103 $langs->load("errors");
104 $mesgs[] = $langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("Size"));
105 $action = 'edit';
106 }
107 if ($type == 'varchar' && $extrasize > $maxsizestring) {
108 $error++;
109 $langs->load("errors");
110 $mesgs[] = $langs->trans("ErrorSizeTooLongForVarcharType", $maxsizestring);
111 $action = 'create';
112 }
113 if ($type == 'int' && $extrasize > $maxsizeint) {
114 $error++;
115 $langs->load("errors");
116 $mesgs[] = $langs->trans("ErrorSizeTooLongForIntType", $maxsizeint);
117 $action = 'create';
118 }
119 if ($type == 'stars' && ($extrasize < 1 || $extrasize > 10)) {
120 $error++;
121 $langs->load("errors");
122 $mesgs[] = $langs->trans("ErrorSizeForStarsType");
123 $action = 'create';
124 }
125 if ($type == 'select' && !$param) {
126 $error++;
127 $langs->load("errors");
128 $mesgs[] = $langs->trans("ErrorNoValueForSelectType");
129 $action = 'create';
130 }
131 if ($type == 'sellist' && !$param) {
132 $error++;
133 $langs->load("errors");
134 $mesgs[] = $langs->trans("ErrorNoValueForSelectListType");
135 $action = 'create';
136 }
137 if ($type == 'checkbox' && !$param) {
138 $error++;
139 $langs->load("errors");
140 $mesgs[] = $langs->trans("ErrorNoValueForCheckBoxType");
141 $action = 'create';
142 }
143 if ($type == 'link' && !$param) {
144 $error++;
145 $langs->load("errors");
146 $mesgs[] = $langs->trans("ErrorNoValueForLinkType");
147 $action = 'create';
148 }
149 if ($type == 'link' && $param) {
150 // $param is 'ObjectName:classPath'. Check the class file really exists, a wrong path
151 // makes the link render as a raw id later, with nothing shown to the user.
152 $tmplink = explode(':', $param);
153 if (empty($tmplink[1]) || !file_exists(dol_buildpath($tmplink[1]))) {
154 $error++;
155 $langs->load("errors");
156 $mesgs[] = $langs->trans("ErrorFileNotFound", empty($tmplink[1]) ? $param : $tmplink[1]);
157 $action = 'create';
158 }
159 }
160 if ($type == 'radio' && !$param) {
161 $error++;
162 $langs->load("errors");
163 $mesgs[] = $langs->trans("ErrorNoValueForRadioType");
164 $action = 'create';
165 }
166 if ((($type == 'radio') || ($type == 'checkbox')) && $param) {
167 // Construct array for parameter (value of select list)
168 $parameters = $param;
169 $parameters_array = explode("\r\n", $parameters);
170 foreach ($parameters_array as $param_ligne) {
171 if (!empty($param_ligne)) {
172 $matches = array();
173 if (preg_match_all('/,/', $param_ligne, $matches)) {
174 if (count($matches[0]) > 1) {
175 $error++;
176 $langs->load("errors");
177 $mesgs[] = $langs->trans("ErrorBadFormatValueList", $param_ligne);
178 $action = 'create';
179 }
180 } else {
181 $error++;
182 $langs->load("errors");
183 $mesgs[] = $langs->trans("ErrorBadFormatValueList", $param_ligne);
184 $action = 'create';
185 }
186 }
187 }
188 }
189
190 if (!$error) {
191 if (strlen(GETPOST('attrname', 'aZ09')) < 3) {
192 $error++;
193 $langs->load("errors");
194 $mesgs[] = $langs->trans("ErrorValueLength", $langs->transnoentitiesnoconv("AttributeCode"), 3);
195 $action = 'create';
196 }
197 }
198
199 // Check reserved keyword with more than 3 characters
200 if (!$error) {
201 if (in_array(strtoupper(GETPOST('attrname', 'aZ09')), $listofreservedwords)) {
202 $error++;
203 $langs->load("errors");
204 $mesgs[] = $langs->trans("ErrorReservedKeyword", GETPOST('attrname', 'aZ09'));
205 $action = 'create';
206 }
207 }
208
209 if (!$error) {
210 // attrname must be alphabetical and lower case only
211 if (GETPOSTISSET("attrname") && preg_match("/^[a-z0-9_]+$/", GETPOST('attrname', 'aZ09')) && !is_numeric(GETPOST('attrname', 'aZ09'))) {
212 // Construct array for parameter (value of select list)
213 $default_value = GETPOST('default_value', 'alpha');
214 $parameters = $param;
215 $parameters_array = explode("\r\n", $parameters);
216 $params = array();
217 //In sellist we have only one line and it can have come to do SQL expression
218 if ($type == 'sellist' || $type == 'chkbxlst') {
219 foreach ($parameters_array as $param_ligne) {
220 $params['options'] = array($parameters => null);
221 }
222 } else {
223 // Else it's separated key/value and coma list
224 foreach ($parameters_array as $param_ligne) {
225 if (strpos($param_ligne, ',') !== false) {
226 list($key, $value) = explode(',', $param_ligne);
227 if (!array_key_exists('options', $params)) {
228 $params['options'] = array();
229 }
230 } else {
231 $key = $param_ligne;
232 $value = null;
233 }
234 $params['options'][$key] = $value;
235 }
236 }
237
238 // Visibility: -1=not visible by default in list, 1=visible, 0=hidden
239 $visibility = GETPOST('list', 'alpha');
240 if (in_array($type, ['separate', 'point', 'linestrg', 'polygon'])) {
241 $visibility = 3;
242 }
243
244 $result = $extrafields->addExtraField(
245 GETPOST('attrname', 'aZ09'),
246 GETPOST('label', 'alpha'),
247 $type,
248 GETPOSTINT('pos'),
249 $extrasize,
250 $elementtype,
251 (GETPOST('unique', 'alpha') ? 1 : 0),
252 (GETPOST('required', 'alpha') ? 1 : 0),
253 $default_value,
254 $params,
255 (GETPOST('alwayseditable', 'alpha') ? 1 : 0),
256 (GETPOST('perms', 'alpha') ? GETPOST('perms', 'alpha') : ''),
257 $visibility,
258 GETPOST('help', 'alpha'),
259 GETPOST('computed_value', 'alpha'),
260 (GETPOST('entitycurrentorall', 'alpha') ? 0 : ''),
261 GETPOST('langfile', 'alpha'),
262 '1',
263 (GETPOST('totalizable', 'alpha') ? 1 : 0),
264 GETPOSTINT('printable'),
265 array('css' => $css, 'cssview' => $cssview, 'csslist' => $csslist),
266 GETPOST("ai_prompt"),
267 (GETPOST('emptyonclone', 'alpha') ? 1 : 0),
268 (GETPOST('showintooltip', 'int') ? 1 : 0),
269 GETPOSTINT('personal_data')
270 );
271 if ($result > 0) {
272 setEventMessages($langs->trans('SetupSaved'), null, 'mesgs');
273 header("Location: ".$_SERVER["PHP_SELF"].(empty($pagekeyforredirect) ? '' : '?elementtype='.urlencode($pagekeyforredirect)));
274 exit;
275 } else {
276 $error++;
277 $mesg = $extrafields->error;
278 $mesgs = array_merge($mesgs, $extrafields->errors);
279 setEventMessages($mesg, $mesgs, 'errors');
280 }
281 } else {
282 $error++;
283 $langs->load("errors");
284 $mesg = $langs->trans("ErrorFieldCanNotContainSpecialNorUpperCharacters", $langs->transnoentities("AttributeCode"));
285 setEventMessages($mesg, $mesgs, 'errors');
286 $action = 'create';
287 }
288 } else {
289 setEventMessages($mesg, $mesgs, 'errors');
290 }
291 }
292}
293
294// Rename field
295if ($action == 'update') {
296 if (GETPOST("button") != $langs->trans("Cancel")) {
297 // Check values
298 if (!$type) {
299 $error++;
300 $langs->load("errors");
301 $mesgs[] = $langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("Type"));
302 $action = 'edit';
303 }
304 if ($type == 'varchar' && $extrasize <= 0) {
305 $error++;
306 $langs->load("errors");
307 $mesgs[] = $langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("Size"));
308 $action = 'edit';
309 }
310 if ($type == 'varchar' && $extrasize > $maxsizestring) {
311 $error++;
312 $langs->load("errors");
313 $mesgs[] = $langs->trans("ErrorSizeTooLongForVarcharType", $maxsizestring);
314 $action = 'edit';
315 }
316 if ($type == 'int' && $extrasize > $maxsizeint) {
317 $error++;
318 $langs->load("errors");
319 $mesgs[] = $langs->trans("ErrorSizeTooLongForIntType", $maxsizeint);
320 $action = 'edit';
321 }
322 if ($type == 'select' && !$param) {
323 $error++;
324 $langs->load("errors");
325 $mesgs[] = $langs->trans("ErrorNoValueForSelectType");
326 $action = 'edit';
327 }
328 if ($type == 'sellist' && !$param) {
329 $error++;
330 $langs->load("errors");
331 $mesgs[] = $langs->trans("ErrorNoValueForSelectListType");
332 $action = 'edit';
333 }
334 if ($type == 'stars' && ($extrasize < 1 || $extrasize > 10)) {
335 $error++;
336 $langs->load("errors");
337 $mesgs[] = $langs->trans("ErrorSizeForStarsType");
338 $action = 'edit';
339 }
340 if ($type == 'checkbox' && !$param) {
341 $error++;
342 $langs->load("errors");
343 $mesgs[] = $langs->trans("ErrorNoValueForCheckBoxType");
344 $action = 'edit';
345 }
346 if ($type == 'radio' && !$param) {
347 $error++;
348 $langs->load("errors");
349 $mesgs[] = $langs->trans("ErrorNoValueForRadioType");
350 $action = 'edit';
351 }
352 if ($type == 'link' && $param) {
353 // $param is 'ObjectName:classPath'. Check the class file really exists, a wrong path
354 // makes the link render as a raw id later, with nothing shown to the user.
355 $tmplink = explode(':', $param);
356 if (empty($tmplink[1]) || !file_exists(dol_buildpath($tmplink[1]))) {
357 $error++;
358 $langs->load("errors");
359 $mesgs[] = $langs->trans("ErrorFileNotFound", empty($tmplink[1]) ? $param : $tmplink[1]);
360 $action = 'edit';
361 }
362 }
363 if ((($type == 'radio') || ($type == 'checkbox')) && $param) {
364 // Construct array for parameter (value of select list)
365 $parameters = $param;
366 $parameters_array = explode("\r\n", $parameters);
367 foreach ($parameters_array as $param_ligne) {
368 if (!empty($param_ligne)) {
369 if (preg_match_all('/,/', $param_ligne, $matches)) {
370 if (count($matches[0]) > 1) {
371 $error++;
372 $langs->load("errors");
373 $mesgs[] = $langs->trans("ErrorBadFormatValueList", $param_ligne);
374 $action = 'edit';
375 }
376 } else {
377 $error++;
378 $langs->load("errors");
379 $mesgs[] = $langs->trans("ErrorBadFormatValueList", $param_ligne);
380 $action = 'edit';
381 }
382 }
383 }
384 }
385
386 if (!$error) {
387 if (strlen(GETPOST('attrname', 'aZ09')) < 3 && !getDolGlobalString('MAIN_DISABLE_EXTRAFIELDS_CHECK_FOR_UPDATE')) {
388 $error++;
389 $langs->load("errors");
390 $mesgs[] = $langs->trans("ErrorValueLength", $langs->transnoentitiesnoconv("AttributeCode"), 3);
391 $action = 'edit';
392 }
393 }
394
395 // Check reserved keyword with more than 3 characters
396 if (!$error) {
397 if (in_array(strtoupper(GETPOST('attrname', 'aZ09')), $listofreservedwords) && !getDolGlobalString('MAIN_DISABLE_EXTRAFIELDS_CHECK_FOR_UPDATE')) {
398 $error++;
399 $langs->load("errors");
400 $mesgs[] = $langs->trans("ErrorReservedKeyword", GETPOST('attrname', 'aZ09'));
401 $action = 'edit';
402 }
403 }
404
405 if (!$error) {
406 if (GETPOSTISSET("attrname") && preg_match("/^\w[a-zA-Z0-9-_]*$/", GETPOST('attrname', 'aZ09')) && !is_numeric(GETPOST('attrname', 'aZ09'))) {
407 $pos = GETPOSTINT('pos');
408 // Construct array for parameter (value of select list)
409 $parameters = $param;
410 $parameters_array = explode("\r\n", $parameters);
411 $params = array();
412 //In sellist we have only one line and it can have come to do SQL expression
413 if ($type == 'sellist' || $type == 'chkbxlst') {
414 foreach ($parameters_array as $param_ligne) {
415 $params['options'] = array($parameters => null);
416 }
417 } else {
418 //Else it's separated key/value and coma list
419 foreach ($parameters_array as $param_ligne) {
420 $tmp = explode(',', $param_ligne);
421 $key = $tmp[0];
422 if (!empty($tmp[1])) {
423 $value = $tmp[1];
424 }
425 if (!array_key_exists('options', $params)) {
426 $params['options'] = array();
427 }
428 $params['options'][$key] = $value;
429 }
430 }
431
432 // $params['options'][$key] can be 'Facture:/compta/facture/class/facture.class.php' => '/custom'
433
434 // Visibility: -1=not visible by default in list, 1=visible, 0=hidden
435 $visibility = GETPOST('list', 'alpha');
436 if (in_array($type, ['separate', 'point', 'linestrg', 'polygon'])) {
437 $visibility = 3;
438 }
439
440 // Example: is_object($object) ? ($object->id < 10 ? round($object->id / 2, 2) : (2 * $user->id) * (int) substr($mysoc->zip, 1, 2)) : 'objnotdefined'
441 $computedvalue = GETPOST('computed_value', 'nohtml');
442
443 $result = $extrafields->update(
444 GETPOST('attrname', 'aZ09'),
445 GETPOST('label', 'alpha'),
446 $type,
447 $extrasize,
448 $elementtype,
449 (GETPOST('unique', 'alpha') ? 1 : 0),
450 (GETPOST('required', 'alpha') ? 1 : 0),
451 $pos,
452 $params,
453 (GETPOST('alwayseditable', 'alpha') ? 1 : 0),
454 (GETPOST('perms', 'alpha') ? GETPOST('perms', 'alpha') : ''),
455 $visibility,
456 GETPOST('help', 'alpha'),
457 GETPOST('default_value', 'alpha'),
458 $computedvalue,
459 (GETPOST('entitycurrentorall', 'alpha') ? 0 : ''),
460 GETPOST('langfile'),
461 GETPOST('enabled', 'nohtml'),
462 (GETPOST('totalizable', 'alpha') ? 1 : 0),
463 GETPOSTINT('printable'),
464 array('css' => $css, 'cssview' => $cssview, 'csslist' => $csslist),
465 GETPOST("ai_prompt"),
466 (GETPOST('emptyonclone', 'alpha') ? 1 : 0),
467 (GETPOST('showintooltip', 'int') ? 1 : 0),
468 GETPOSTINT('personal_data')
469 );
470 if ($result > 0) {
471 setEventMessages($langs->trans('SetupSaved'), null, 'mesgs');
472 header("Location: ".$_SERVER["PHP_SELF"].(empty($pagekeyforredirect) ? '' : '?elementtype='.urlencode($pagekeyforredirect)));
473 exit;
474 } else {
475 $error++;
476 $mesg = $extrafields->error;
477 $mesgs = array_merge($mesgs, $extrafields->errors);
478 setEventMessages($mesg, $mesgs, 'errors');
479 }
480 } else {
481 $error++;
482 $langs->load("errors");
483 $mesg = $langs->trans("ErrorFieldCanNotContainSpecialCharacters", $langs->transnoentities("AttributeCode"));
484 setEventMessages($mesg, null, 'errors');
485 }
486 } else {
487 setEventMessages($mesg, $mesgs, 'errors');
488 }
489 }
490}
491
492// Delete attribute
493if ($action == 'confirm_delete' && $confirm == "yes") {
494 if (GETPOSTISSET("attrname") && preg_match("/^\w[a-zA-Z0-9-_]*$/", GETPOST("attrname", 'aZ09'))) {
495 $attributekey = GETPOST('attrname', 'aZ09');
496
497 $result = $extrafields->delete($attributekey, $elementtype);
498 if ($result >= 0) {
499 setEventMessages($langs->trans("ExtrafieldsDeleted", $attributekey), null, 'mesgs');
500
501 header("Location: ".$_SERVER["PHP_SELF"].(empty($pagekeyforredirect) ? '' : '?elementtype='.urlencode($pagekeyforredirect)));
502 exit;
503 } else {
504 $mesg = $extrafields->error;
505 $mesgs = array_merge($mesgs, $extrafields->errors);
506 }
507 } else {
508 $error++;
509 $langs->load("errors");
510 $mesg = $langs->trans("ErrorFieldCanNotContainSpecialCharacters", $langs->transnoentities("AttributeCode"));
511 }
512}
513
514// Recrypt data password
515if ($action == 'encrypt') {
516 // Load $extrafields->attributes
517 $extrafields->fetch_name_optionals_label($elementtype);
518 $attributekey = GETPOST('attrname', 'aZ09');
519
520 if (!empty($extrafields->attributes[$elementtype]['type'][$attributekey]) && $extrafields->attributes[$elementtype]['type'][$attributekey] == 'password') {
521 if (!empty($extrafields->attributes[$elementtype]['param'][$attributekey]['options'])) {
522 if (array_key_exists('dolcrypt', $extrafields->attributes[$elementtype]['param'][$attributekey]['options'])) {
523 // We can encrypt data with dolCrypt()
524 $arrayofelement = getElementProperties($elementtype);
525 if (!empty($arrayofelement['table_element'])) {
526 if ($extrafields->attributes[$elementtype]['entityid'][$attributekey] == $conf->entity || empty($extrafields->attributes[$elementtype]['entityid'][$attributekey])) {
527 dol_syslog("Loop on each extafields of table ".$arrayofelement['table_element']);
528
529 $sql = "SELECT te.rowid, te.".$db->sanitize($attributekey);
530 $sql .= " FROM ".MAIN_DB_PREFIX.$db->sanitize($arrayofelement['table_element'])." as t, ".MAIN_DB_PREFIX.$db->sanitize($arrayofelement['table_element']).'_extrafields as te';
531 $sql .= " WHERE te.fk_object = t.rowid";
532 $sql .= " AND te.".$db->sanitize($attributekey)." NOT LIKE 'dolcrypt:%'";
533 $sql .= " AND te.".$db->sanitize($attributekey)." IS NOT NULL";
534 $sql .= " AND te.".$db->sanitize($attributekey)." <> ''";
535 if ($extrafields->attributes[$elementtype]['entityid'][$attributekey] == $conf->entity) {
536 $sql .= " AND t.entity = ".getEntity($arrayofelement['element'], 0);
537 }
538
539 //print $sql;
540 $nbupdatedone = 0;
541 $resql = $db->query($sql);
542 if ($resql) {
543 $num_rows = $db->num_rows($resql);
544 $i = 0;
545 while ($i < $num_rows) {
546 $objtmp = $db->fetch_object($resql);
547 $id = $objtmp->rowid;
548 $pass = $objtmp->$attributekey;
549 if ($pass) {
550 $newpassword = dolEncrypt($pass);
551
552 $sqlupdate = "UPDATE ".MAIN_DB_PREFIX.$db->sanitize($arrayofelement['table_element']).'_extrafields';
553 $sqlupdate .= " SET ".$db->sanitize($attributekey)." = '".$db->escape($newpassword)."'";
554 $sqlupdate .= " WHERE rowid = ".((int) $id);
555
556 $resupdate = $db->query($sqlupdate);
557 if ($resupdate) {
558 $nbupdatedone++;
559 } else {
560 setEventMessages($db->lasterror(), null, 'errors');
561 $error++;
562 break;
563 }
564 }
565
566 $i++;
567 }
568 }
569
570 if ($nbupdatedone > 0) {
571 setEventMessages($langs->trans("PasswordFieldEncrypted", $nbupdatedone), null, 'mesgs');
572 } else {
573 setEventMessages($langs->trans("PasswordFieldEncrypted", $nbupdatedone), null, 'warnings');
574 }
575 }
576 }
577 }
578 }
579 }
580}
$id
Support class for third parties, contacts, members, users or resources.
Definition account.php:47
if(!isModEnabled('ai')||!getDolGlobalString('AI_ASSISTANT_ENABLED')) global $conf
The main.inc.php has been included so the following variable are now defined:
getElementProperties($elementType)
Get an array with properties of an element.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
dol_buildpath($path, $type=0, $returnemptyifnotfound=0)
Return path of url or filesystem.
GETPOSTISSET($paramname)
Return true if we are in a context of submitting the parameter $paramname from a POST of a form.
getDolGlobalString($key, $default='')
Return a Dolibarr global constant string value.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
dolEncrypt($chain, $key='', $ciphering='', $forceseed='', $obfuscationmode='dolcrypt')
Encode a string with a symmetric encryption.