dolibarr 25.0.0-alpha
editinline.php
Go to the documentation of this file.
1<?php
2/* Copyright (C) 2017 Laurent Destailleur <eldy@users.sourceforge.net>
3 * Copyright (C) 2024 Frédéric France <frederic.france@free.fr>
4 * Copyright (C) 2025 MDW <mdeweerd@users.noreply.github.com>
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 3 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program. If not, see <https://www.gnu.org/licenses/>.
18 */
19
26if (!defined('NOTOKENRENEWAL')) {
27 define('NOTOKENRENEWAL', '1'); // Disables token renewal
28}
29if (!defined('NOREQUIREMENU')) {
30 define('NOREQUIREMENU', '1');
31}
32if (!defined('NOREQUIREAJAX')) {
33 define('NOREQUIREAJAX', '1');
34}
35if (!defined('NOREQUIRESOC')) {
36 define('NOREQUIRESOC', '1');
37}
38
39// Load Dolibarr environment
40require '../../main.inc.php';
48require_once DOL_DOCUMENT_ROOT.'/website/class/website.class.php';
49require_once DOL_DOCUMENT_ROOT.'/website/class/websitepage.class.php';
50require_once DOL_DOCUMENT_ROOT.'/core/lib/website2.lib.php';
51
52$action = GETPOST('action', 'alpha');
53$website_ref = GETPOST('website_ref');
54$page_id = GETPOSTINT('page_id');
55$content = GETPOST('content', 'restricthtml');
56$element_id = GETPOSTINT('element_id');
57$element_type = GETPOST('element_type', 'aZ09');
58
59$usercanmodify = $user->hasRight('website', 'write');
60if (!$usercanmodify) {
61 http_response_code(403);
62 print "You don't have permission for this action.";
63 exit;
64}
65
66
67/*
68 * View
69 */
70
72
73if (!empty($action) && $action === 'updatedElementContent' && $usercanmodify && !empty($content) && !empty($element_id) && !empty($website_ref) && !empty($page_id)) {
74 // Page object
75 $objectpage = new WebsitePage($db);
76 $res = $objectpage->fetch((int) $page_id);
77 if (!$res) {
78 print "Cannot find page with ID = " . $page_id . ".";
79 exit;
80 }
81
82 // Website object
83 $objectwebsite = new Website($db);
84 $res = $objectwebsite->fetch($objectpage->fk_website);
85 if (!$res) {
86 print "Cannot find website with REF " . $objectpage->fk_website . ".";
87 exit;
88 }
89
90 $db->begin();
91 $error = 0;
92
93 $oldContent = $objectpage->content;
94
95 // Replace element content into database and tpl file
96 // TODO Enhance this by a DOM scan/replacement
97 $objectpage->content = preg_replace('/<' . preg_quote($element_type, '/') . '[^>]*\bid="' . $element_id . '"[^>]*>\K(.*?)(?=<\/' . preg_quote($element_type, '/') . '>)/s', $content, $objectpage->content, 1);
98
99 $oldPhp = dolKeepOnlyPhpCode($oldContent);
100 $newPhp = dolKeepOnlyPhpCode($objectpage->content);
101 if (checkPHPCode($oldPhp, $newPhp)) {
102 // Error php was modified when not allowed
103 $error++;
104 // A message was set by setEventMessages into checkPHPCode().
105 } else {
106 $res = $objectpage->update($user);
107 if ($res) {
108 global $dolibarr_main_data_root;
109 $pathofwebsite = $dolibarr_main_data_root.($conf->entity > 1 ? '/'.$conf->entity : '').'/website/'.$website_ref;
110 $filetpl = $pathofwebsite.'/page'.$objectpage->id.'.tpl.php';
111
112 $result = dolSavePageContent($filetpl, $objectwebsite, $objectpage, 1);
113 if (!$result) {
114 print "Failed to write file " . $filetpl . ".";
115 $error++;
116 }
117 } else {
118 print "Failed to save changes error " . $objectpage->error . ".";
119 $error++;
120 }
121 }
122
123 if (!$error) {
124 $db->commit();
125 print "Changes are saved for " . $element_type . " with id " . $element_id;
126 } else {
127 $db->rollback();
128 }
129
130 $db->close();
131}
Class Website.
dolKeepOnlyPhpCode($str)
Keep only PHP code part from a HTML string page.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
if(!defined( 'NOREQUIREMENU')) if(!empty(GETPOST('seteventmessages', 'alpha'))) if(!function_exists("llxHeader")) top_httphead($contenttype='text/html', $forcenocache=0)
Show HTTP header.
checkPHPCode(&$phpfullcodestringold, &$phpfullcodestring)
Check that the new string $phpfullcodestring contains only php code (including <php tag)
dolSavePageContent($filetpl, Website $object, WebsitePage $objectpage, $backupold=0)
Save content of a page on disk (page name is generally ID_of_page.php).