dolibarr 25.0.0-alpha
updateextrafield.php
Go to the documentation of this file.
1<?php
2/* Copyright (C) 2022 Laurent Destailleur <eldy@users.sourceforge.net>
3 * Copyright (C) 2024-2025 Frédéric France <frederic.france@free.fr>
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 3 of the License, or
8 * (at your option) any later version.
9 *
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License
16 * along with this program. If not, see <https://www.gnu.org/licenses/>.
17 */
18
26if (!defined('NOTOKENRENEWAL')) {
27 define('NOTOKENRENEWAL', 1); // Disables token renewal
28}
29if (!defined('NOREQUIREMENU')) {
30 define('NOREQUIREMENU', '1');
31}
32if (!defined('NOREQUIREHTML')) {
33 define('NOREQUIREHTML', '1');
34}
35if (!defined('NOREQUIREAJAX')) {
36 define('NOREQUIREAJAX', '1');
37}
38if (!defined('NOREQUIRESOC')) {
39 define('NOREQUIRESOC', '1');
40}
41
42// Load Dolibarr environment
43include '../../main.inc.php';
53$objectType = GETPOST('objectType', 'aZ09'); // modulepart
54$objectId = GETPOST('objectId', 'aZ09');
55$field = GETPOST('field', 'aZ09');
56$value = GETPOST('value', 'alpha');
57
58$module = getElementProperties($objectType)['module'];
59$element_ref = '';
60if (is_numeric($objectId)) {
61 $objectId = (int) $objectId;
62} else {
63 $element_ref = $objectId;
64 $objectId = 0;
65}
66$object = fetchObjectByElement($objectId, $objectType, $element_ref);
68if (empty($object->element)) {
69 httponly_accessforbidden('Failed to get object with fetchObjectByElement(id=' . $objectId . ', objecttype=' . $objectType . ')');
70}
71
72$module = $object->module;
73$element = $object->element;
74
75// Security check
76$usesublevelpermission = ($module != $element ? $element : '');
77if ($usesublevelpermission && !$user->hasRight($module, $element, 'write') && !$user->hasRight($module, 'write')) { // There is no permission on object defined, we will check permission on module directly
78 $usesublevelpermission = '';
79}
80// print $object->id.' - '.$object->module.' - '.$object->element.' - '.$object->table_element.' - '.$usesublevelpermission."\n";
81
82// Security check with mode 'write', so restrictedArea() tests the write permission and not only the read
83// permission, because this page makes a write operation on the object (update of an extrafield value).
84$result = restrictedArea($user, $object->module, $object, $object->table_element, $usesublevelpermission, 'fk_soc', 'rowid', 0, 1, 'write'); // Call with nodie return
85if (!$result) {
86 httponly_accessforbidden('Not allowed by restrictArea');
87}
88
89// Add blacklist of some forbidden field name.
90/* Removed, this is useful only for main fields not for extrafields
91$blacklistedfields = array('pass', 'pass_crypted', 'pass_temp', 'api_key', 'openid', 'admin', 'status', 'statut');
92$canreadsalary = ((isModEnabled('salaries') && $user->hasRight('salaries', 'read')) || !isModEnabled('salaries'));
93if (!$canreadsalary) {
94 $blacklistedfields[] = 'salary';
95 $blacklistedfields[] = 'salaryextra';
96 $blacklistedfields[] = 'thm';
97 $blacklistedfields[] = 'tjm';
98}
99if (in_array($field, $blacklistedfields)) {
100 access_forbidden("Can't edit a field blacklisted with name ".$field);
101}
102*/
103
104
105/*
106 * View
107 */
108
109dol_syslog("Call ajax core/ajax/updateextrafield.php");
110
112
113// Update the object field with the new value
114if ($object->id > 0 && $field && isset($value)) {
115 // Fetch optionals attributes and labels
116 $extrafields->fetch_name_optionals_label($object->table_element);
117
118 // Test specific permission of extrafield $field for object $object. It is stored into $extrafields->attributes[$object->table_element]['label']['perms'][$key]
119 if (empty($field)
120 || empty($extrafields->attributes[$object->table_element]['label'][$field])
121 || !dol_eval((string) $extrafields->attributes[$object->table_element]['enabled'][$field])) {
122 http_response_code(403);
123 accessforbidden('Can\'t edit the invalid or disabled extrafield '.$field);
124 }
125
126 $fieldPermsExpr = $extrafields->attributes[$object->table_element]['perms'][$field] ?? '';
127
128 if (!empty($fieldPermsExpr)) {
129 $allowed = (int) dol_eval((string) $fieldPermsExpr);
130 if (empty($allowed)) {
131 http_response_code(403);
132 accessforbidden('The extrafield '.$field.' has dedicated permission and you are not allowed to edit it.');
133 }
134 }
135
136 $object->array_options['options_'.$field] = $value;
137
138 if ($object instanceof Societe) {
139 $result = $object->update($object->id, $user);
140 } else {
141 $result = $object->update($user);
142 }
143
144 if ($result < 0) {
145 print json_encode(['status' => 'error', 'message' => 'Error updating '. $field]);
146 } else {
147 print json_encode(['status' => 'success', 'message' => $field . ' updated successfully']);
148 }
149}
150
151$db->close();
if(! $sortfield) if(! $sortorder) $object
Definition account.php:100
Class to manage third parties objects (customers, suppliers, prospects...)
if(! $sortfield) if(! $sortorder) $module
Definition list.php:193
dol_eval($s, $returnvalue=1, $hideerrors=1, $onlysimplestring='1')
Replace eval function to add more security.
getElementProperties($elementType)
Get an array with properties of an element.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
if(!defined( 'NOREQUIREMENU')) if(!empty(GETPOST('seteventmessages', 'alpha'))) if(!function_exists("llxHeader")) top_httphead($contenttype='text/html', $forcenocache=0)
Show HTTP header.
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.
restrictedArea(User $user, $features, $object=0, $tableandshare='', $feature2='', $dbt_keyfield='fk_soc', $dbt_select='rowid', $isdraft=0, $nodie=0, $mode='')
Check permissions of a user to show a page and an object.
accessforbidden($message='', $printheader=1, $printfooter=1, $showonlymessage=0, $params=null)
Show a message to say access is forbidden and stop program.