dolibarr 25.0.0-alpha
changepositionfields.php
Go to the documentation of this file.
1<?php
2/* Copyright (C) 2026 Frédéric France <frederic.france@free.fr>
3 *
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 3 of the License, or
7 * (at your option) any later version.
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program. If not, see <https://www.gnu.org/licenses/>.
16 */
17
23if (!defined('NOTOKENRENEWAL')) {
24 define('NOTOKENRENEWAL', '1'); // Disables token renewal
25}
26if (!defined('NOREQUIREMENU')) {
27 define('NOREQUIREMENU', '1');
28}
29if (!defined('NOREQUIREHTML')) {
30 define('NOREQUIREHTML', '1');
31}
32if (!defined('NOREQUIREAJAX')) {
33 define('NOREQUIREAJAX', '1');
34}
35if (!defined('NOREQUIRESOC')) {
36 define('NOREQUIRESOC', '1');
37}
38if (!defined('NOREQUIRETRAN')) {
39 define('NOREQUIRETRAN', '1');
40}
41if (!defined('CSRFCHECK_WITH_TOKEN')) {
42 define('CSRFCHECK_WITH_TOKEN', '1'); // Token is required even in GET mode
43}
44
45// Load Dolibarr environment
46require '../../main.inc.php';
47
56$action = GETPOST('action', 'aZ09'); // set or del
57$contextpage = GETPOST('contextpage');
58$postitionfields = GETPOST("positionfields", "array");
59$userid = GETPOSTINT('userid');
60
61// Security check
62if ($userid != $user->id) {
63 httponly_accessforbidden('Bad userid parameter. Must match logged user.');
64}
65
66
67/*
68 * Actions
69 */
70
71$result = 0;
72
73// Registering the new value of constant
74if (!empty($action) && !empty($contextpage)) {
75 if ($action == "listafterchangingpositionfields") { // Test on permission not required here. Done in security check
76 dol_syslog("Ajax changepositionfields contextpage=".$contextpage." postitionfields=".$postitionfields." userid=".$userid, LOG_DEBUG);
77 $tabparam = array();
78 if (!empty($postitionfields)) {
79 $position = "";
80 foreach ($postitionfields as $pos => $field) {
81 $position .= ($pos != 0 ? "," : "").$field.":".$pos;
82 }
83 $tabparam["MAIN_POSITIONFIELDS_".$contextpage] = $position;
84 } else {
85 $tabparam["MAIN_POSITIONFIELDS_".$contextpage] = '';
86 }
87 include_once DOL_DOCUMENT_ROOT.'/core/lib/functions2.lib.php';
88
89 $result = dol_set_user_param($db, $conf, $user, $tabparam);
90 }
91} else {
92 httponly_accessforbidden('Param action and contextpage are required', 403);
93}
94
95
96/*
97 * View
98 */
99
100if ($result < 0) {
101 http_response_code(500);
102}
103
105
106// No output
if(!isModEnabled('ai')||!getDolGlobalString('AI_ASSISTANT_ENABLED')) global $conf
The main.inc.php has been included so the following variable are now defined:
dol_set_user_param($db, $conf, &$user, $tab, $entity=-1)
Save personal parameter.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
if(!defined( 'NOREQUIREMENU')) if(!empty(GETPOST('seteventmessages', 'alpha'))) if(!function_exists("llxHeader")) top_httphead($contenttype='text/html', $forcenocache=0)
Show HTTP header.
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.