dolibarr 25.0.0-alpha
viewandvote.php
1<?php
2/* Copyright (C) 2021 Dorian Vabre <dorian.vabre@gmail.com>
3 * Copyright (C) 2024-2025 Frédéric France <frederic.france@free.fr>
4 * Copyright (C) 2025 MDW <mdeweerd@users.noreply.github.com>
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 3 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program. If not, see <https://www.gnu.org/licenses/>.
18 */
19
26if (!defined('NOLOGIN')) {
27 define("NOLOGIN", 1); // This means this output page does not require to be logged.
28}
29if (!defined('NOCSRFCHECK')) {
30 define("NOCSRFCHECK", 1); // We accept to go on this page from external web site.
31}
32if (!defined('NOIPCHECK')) {
33 define('NOIPCHECK', '1'); // Do not check IP defined into conf $dolibarr_main_restrict_ip
34}
35if (!defined('NOBROWSERNOTIF')) {
36 define('NOBROWSERNOTIF', '1');
37}
38
39// For MultiCompany module.
40// Do not use GETPOST here, function is not defined and get of entity must be done before including main.inc.php
41// Because 2 entities can have the same ref.
42$entity = (!empty($_GET['entity']) ? (int) $_GET['entity'] : (!empty($_POST['entity']) ? (int) $_POST['entity'] : (!empty($_GET['e']) ? (int) $_GET['e'] : (!empty($_POST['e']) ? (int) $_POST['e'] : 1))));
43if (is_numeric($entity)) {
44 define("DOLENTITY", $entity);
45}
46
47// Load Dolibarr environment
48require '../../main.inc.php';
49require_once DOL_DOCUMENT_ROOT.'/core/lib/company.lib.php';
50require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
51require_once DOL_DOCUMENT_ROOT.'/core/lib/functions2.lib.php';
52require_once DOL_DOCUMENT_ROOT.'/product/class/product.class.php';
53require_once DOL_DOCUMENT_ROOT.'/societe/class/societeaccount.class.php';
54require_once DOL_DOCUMENT_ROOT.'/compta/facture/class/facture.class.php';
55require_once DOL_DOCUMENT_ROOT.'/projet/class/project.class.php';
56require_once DOL_DOCUMENT_ROOT . '/comm/action/class/actioncomm.class.php';
57
67// Hook to be used by external payment modules (ie Payzen, ...)
68$hookmanager = new HookManager($db);
69
70$hookmanager->initHooks(array('newpayment'));
71
72// For encryption
74
75// Load translation files
76$langs->loadLangs(array("main", "other", "dict", "bills", "companies", "errors", "paypal", "stripe")); // File with generic data
77
78// Security check
79// No check on module enabled. Done later according to $validpaymentmethod
80
81$errmsg = '';
82$error = 0;
83$action = GETPOST('action', 'aZ09');
84$id = GETPOST('id');
85$suffix = GETPOST("suffix", 'aZ09');
86$securekeyreceived = GETPOST("securekey");
87$securekeytocompare = dol_hash(getDolGlobalString('EVENTORGANIZATION_SECUREKEY') . 'conferenceorbooth'.((int) $id), 'md5');
88
89if ($securekeytocompare != $securekeyreceived) {
90 print $langs->trans('MissingOrBadSecureKey');
91 exit;
92}
93
94$listofvotes = explode(',', $_SESSION["savevotes"]);
95
96
97// Define $urlwithroot
98//$urlwithouturlroot=preg_replace('/'.preg_quote(DOL_URL_ROOT,'/').'$/i','',trim($dolibarr_main_url_root));
99//$urlwithroot=$urlwithouturlroot.DOL_URL_ROOT; // This is to use external domain name found into config file
100$urlwithroot = DOL_MAIN_URL_ROOT; // This is to use same domain name than current. For Paypal payment, we can use internal URL like localhost.
101
102$project = new Project($db);
103$resultproject = $project->fetch((int) $id);
104if ($resultproject < 0) {
105 $error++;
106 $errmsg .= $project->error;
107}
108
109// Security check
110if (!isModEnabled('eventorganization')) {
111 httponly_accessforbidden('Module Event organization not enabled');
112}
113
114
115/*
116 * Actions
117 */
118
119$tmpthirdparty = new Societe($db);
120
121$listOfConferences = '<tr><td>'.$langs->trans('Label').'</td>';
122$listOfConferences .= '<td>'.$langs->trans('Type').'</td>';
123$listOfConferences .= '<td>'.$langs->trans('ThirdParty').'</td>';
124$listOfConferences .= '<td>'.$langs->trans('Note').'</td></tr>';
125
126$sql = "SELECT a.id, a.fk_action, a.datep, a.datep2, a.label, a.fk_soc, a.note, ca.libelle as label
127 FROM ".MAIN_DB_PREFIX."actioncomm as a
128 INNER JOIN ".MAIN_DB_PREFIX."c_actioncomm as ca ON (a.fk_action = ca.id)
129 WHERE a.status < 2";
130
131$sqlforconf = $sql." AND ca.module='conference@eventorganization'";
132//$sqlforbooth = $sql." AND ca.module='booth@eventorganization'";
133
134// For conferences
135$result = $db->query($sqlforconf);
136$i = 0;
137while ($i < $db->num_rows($result)) {
138 $obj = $db->fetch_object($result);
139 if (!empty($obj->fk_soc)) {
140 $resultthirdparty = $tmpthirdparty->fetch($obj->fk_soc);
141 if ($resultthirdparty) {
142 $thirdpartyname = $tmpthirdparty->name;
143 } else {
144 $thirdpartyname = '';
145 }
146 } else {
147 $thirdpartyname = '';
148 }
149
150 $listOfConferences .= '<tr><td>'.$obj->label.'</td><td>'.$obj->label.'</td><td>'.$thirdpartyname.'</td><td>'.$obj->note.'</td>';
151 $listOfConferences .= '<td><button type="submit" name="vote" value="'.$obj->id.'" class="button">'.$langs->trans("Vote").'</button></td></tr>';
152 $i++;
153}
154
155// For booths
156/*
157$result = $db->query($sqlforbooth);
158$i = 0;
159while ($i < $db->num_rows($result)) {
160 $obj = $db->fetch_object($result);
161 if (!empty($obj->fk_soc)) {
162 $resultthirdparty = $tmpthirdparty->fetch($obj->fk_soc);
163 if ($resultthirdparty) {
164 $thirdpartyname = $tmpthirdparty->name;
165 } else {
166 $thirdpartyname = '';
167 }
168 } else {
169 $thirdpartyname = '';
170 }
171
172 $listOfBooths .= '<tr><td>'.$obj->label.'</td><td>'.$obj->libelle.'</td><td>'.$obj->datep.'</td><td>'.$obj->datep2.'</td><td>'.$thirdpartyname.'</td><td>'.$obj->note.'</td>';
173 $listOfBooths .= '<td><button type="submit" name="vote" value="'.$obj->id.'" class="button">'.$langs->trans("Vote").'</button></td></tr>';
174 $i++;
175}
176*/
177
178// Get vote result
179$idvote = GETPOSTINT("vote");
180// A simple hashed value saved into session (in $_SESSION["savevotes"]) to know if current user has already voted for this conference or booth.
181// This var is used for both reading votes already saved and to flag in session a new vote done.
182$hashedvote = dol_hash(getDolGlobalString('EVENTORGANIZATION_SECUREKEY').'vote'.$idvote, 'md5');
183
184
185if ($idvote > 0) {
186 $votestatus = 'err';
187 if (in_array($hashedvote, $listofvotes)) {
188 // Has already voted
189 $votestatus = 'ko';
190 } else {
191 // Has not already voted
192 $conforbooth = new ActionComm($db);
193 $resultconforbooth = $conforbooth->fetch($idvote);
194 if ($resultconforbooth <= 0) {
195 $error++;
196 $errmsg .= $conforbooth->error;
197 } else {
198 // Process to vote
199 $conforbooth->num_vote++;
200 $resupdate = $conforbooth->update($user);
201 if ($resupdate) {
202 $votestatus = 'ok';
203 $_SESSION["savevotes"] = $hashedvote.','.(empty($_SESSION["savevotes"]) ? '' : $_SESSION["savevotes"]); // Save voter
204 } else {
205 //Error during update
206 $votestatus = 'err';
207 }
208 }
209 }
210 if ($votestatus == "ok") {
211 setEventMessage($langs->trans("VoteOk"), 'mesgs');
212 } elseif ($votestatus == "ko") {
213 setEventMessage($langs->trans("AlreadyVoted"), 'warnings');
214 } elseif ($votestatus == "err") {
215 setEventMessage($langs->trans("VoteError"), 'warnings');
216 }
217 header("Refresh:0;url=".dol_buildpath('/public/project/viewandvote.php?id='.$id.'&securekey=', 1).$securekeyreceived);
218 exit;
219}
220
221
222/*
223 * View
224 */
225
226$head = '';
227if (getDolGlobalString('ONLINE_PAYMENT_CSS_URL')) {
228 $head = '<link rel="stylesheet" type="text/css" href="' . getDolGlobalString('ONLINE_PAYMENT_CSS_URL').'?lang='.$langs->defaultlang.'">'."\n";
229}
230
231$conf->dol_hide_topmenu = 1;
232$conf->dol_hide_leftmenu = 1;
233
234$replacemainarea = (empty($conf->dol_hide_leftmenu) ? '<div>' : '').'<div>';
235llxHeader($head, $langs->trans("SuggestForm"), '', '', 0, 0, '', '', '', 'onlinepaymentbody', $replacemainarea);
236
237print '<span id="dolpaymentspan"></span>'."\n";
238print '<div class="center">'."\n";
239print '<form id="dolpaymentform" class="center" name="paymentform" action="'.$_SERVER["PHP_SELF"].'" method="POST">'."\n";
240print '<input type="hidden" name="token" value="'.newToken().'">'."\n";
241print '<input type="hidden" name="action" value="dopayment">'."\n";
242print '<input type="hidden" name="tag" value="'.GETPOST("tag", 'alpha').'">'."\n";
243//print '<input type="hidden" name="suffix" value="'.dol_escape_htmltag($suffix).'">'."\n";
244print '<input type="hidden" name="id" value="'.dol_escape_htmltag($id).'">'."\n";
245print '<input type="hidden" name="securekey" value="'.dol_escape_htmltag($securekeyreceived).'">'."\n";
246print '<input type="hidden" name="e" value="'.$entity.'" />';
247//print '<input type="hidden" name="forcesandbox" value="'.GETPOSTINT('forcesandbox').'" />';
248print "\n";
249
250
251// Show logo (search order: logo defined by PAYMENT_LOGO_suffix, then PAYMENT_LOGO, then small company logo, large company logo, theme logo, common logo)
252// Define logo and logosmall
253$logosmall = $mysoc->logo_small;
254$logo = $mysoc->logo;
255$paramlogo = 'ONLINE_PAYMENT_LOGO_'.$suffix;
256if (getDolGlobalString($paramlogo)) {
257 $logosmall = getDolGlobalString($paramlogo);
258} elseif (getDolGlobalString('ONLINE_PAYMENT_LOGO')) {
259 $logosmall = getDolGlobalString('ONLINE_PAYMENT_LOGO');
260}
261//print '<!-- Show logo (logosmall='.$logosmall.' logo='.$logo.') -->'."\n";
262// Define urllogo
263$urllogo = '';
264$urllogofull = '';
265if (!empty($logosmall) && is_readable($conf->mycompany->dir_output.'/logos/thumbs/'.$logosmall)) {
266 $urllogo = DOL_URL_ROOT.'/viewimage.php?modulepart=mycompany&amp;entity='.$conf->entity.'&amp;file='.urlencode('logos/thumbs/'.$logosmall);
267 $urllogofull = $dolibarr_main_url_root.'/viewimage.php?modulepart=mycompany&entity='.$conf->entity.'&file='.urlencode('logos/thumbs/'.$logosmall);
268} elseif (!empty($logo) && is_readable($conf->mycompany->dir_output.'/logos/'.$logo)) {
269 $urllogo = DOL_URL_ROOT.'/viewimage.php?modulepart=mycompany&amp;entity='.$conf->entity.'&amp;file='.urlencode('logos/'.$logo);
270 $urllogofull = $dolibarr_main_url_root.'/viewimage.php?modulepart=mycompany&entity='.$conf->entity.'&file='.urlencode('logos/'.$logo);
271}
272
273// Output html code for logo
274if ($urllogo) {
275 print '<div class="backgreypublicpayment">';
276 print '<div class="logopublicpayment">';
277 print '<img id="dolpaymentlogo" src="'.$urllogo.'"';
278 print '>';
279 print '</div>';
280 if (!getDolGlobalString('MAIN_HIDE_POWERED_BY')) {
281 print '<div class="poweredbypublicpayment opacitymedium right"><a class="poweredbyhref" href="https://www.dolibarr.org?utm_medium=website&utm_source=poweredby" target="dolibarr" rel="noopener">'.$langs->trans("PoweredBy").'<br><img class="poweredbyimg" src="'.DOL_URL_ROOT.'/theme/dolibarr_logo.svg" width="80px"></a></div>';
282 }
283 print '</div>';
284}
285
286if (getDolGlobalString('PROJECT_IMAGE_PUBLIC_SUGGEST_BOOTH')) {
287 print '<div class="backimagepublicsuggestbooth">';
288 print '<img id="idPROJECT_IMAGE_PUBLIC_SUGGEST_BOOTH" src="' . getDolGlobalString('PROJECT_IMAGE_PUBLIC_SUGGEST_BOOTH').'">';
289 print '</div>';
290}
291
292print '<table id="welcome" class="center">'."\n";
293$text = '<tr><td class="textpublicpayment"><br><strong>'.$langs->trans("EvntOrgRegistrationWelcomeMessage").'</strong></td></tr>'."\n";
294$text .= '<tr><td class="textpublicpayment">'.$langs->trans("EvntOrgVoteHelpMessage").' : "'.dol_escape_htmltag($project->title).'".<br><br></td></tr>'."\n";
295$text .= '<tr><td class="textpublicpayment">'.dol_htmlentitiesbr($project->note_public).'</td></tr>'."\n";
296print $text;
297print '</table>'."\n";
298
299
300print '<table cellpadding="10" id="conferences" border="1" class="center">'."\n";
301print '<th colspan="7">'.$langs->trans("ListOfSuggestedConferences").'</th>';
302print $listOfConferences.'<br>';
303print '</table>'."\n";
304
305/*
306print '<br>';
307
308print '<table border=1 cellpadding="10" id="conferences" class="center">'."\n";
309print '<th colspan="7">'.$langs->trans("ListOfSuggestedBooths").'</th>';
310print $listOfBooths.'<br>';
311print '</table>'."\n";
312*/
313
314$object = null;
315
316htmlPrintOnlineFooter($mysoc, $langs, 1, $suffix, $object);
317
318llxFooter('', 'public');
319
320$db->close();
$id
Support class for third parties, contacts, members, users or resources.
Definition account.php:47
if(! $sortfield) if(! $sortorder) $object
Definition account.php:100
global $dolibarr_main_url_root
llxFooter($comment='', $zone='private', $disabledoutputofmessages=0)
Empty footer.
Definition wrapper.php:91
if(!defined('NOREQUIRESOC')) if(!defined( 'NOREQUIRETRAN')) if(!defined('NOTOKENRENEWAL')) if(!defined( 'NOREQUIREMENU')) if(!defined('NOREQUIREHTML')) if(!defined( 'NOREQUIREAJAX')) llxHeader($head='', $title='', $help_url='', $target='', $disablejs=0, $disablehead=0, $arrayofjs='', $arrayofcss='', $morequerystring='', $morecssonbody='', $replacemainareaby='', $disablenofollow=0, $disablenoindex=0)
Empty header.
Definition wrapper.php:73
Class to manage agenda events (actions)
Class to manage hooks.
Class to manage projects.
Class to manage third parties objects (customers, suppliers, prospects...)
htmlPrintOnlineFooter($fromcompany, $langs, $addformmessage=0, $suffix='', $object=null)
Show footer of company in HTML public pages.
global $mysoc
if(!isModEnabled('ai')||!getDolGlobalString('AI_ASSISTANT_ENABLED')) global $conf
The main.inc.php has been included so the following variable are now defined:
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
dol_buildpath($path, $type=0, $returnemptyifnotfound=0)
Return path of url or filesystem.
getDolGlobalString($key, $default='')
Return a Dolibarr global constant string value.
isModEnabled($module)
Is Dolibarr module enabled.
dol_escape_htmltag($stringtoescape, $keepb=0, $keepn=0, $noescapetags='', $escapeonlyhtmltags=0, $cleanalsojavascript=0)
Definition html.lib.php:181
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.
dol_hash($chain, $type='0', $nosalt=0, $mode=0)
Returns a hash (non reversible encryption) of a string.