26if (!defined(
'NOTOKENRENEWAL')) {
28 define(
'NOTOKENRENEWAL', 1);
30if (!defined(
'NOREQUIREMENU')) {
31 define(
'NOREQUIREMENU',
'1');
33if (!defined(
'NOREQUIREHTML')) {
34 define(
'NOREQUIREHTML',
'1');
36if (!defined(
'NOREQUIREAJAX')) {
37 define(
'NOREQUIREAJAX',
'1');
39if (!defined(
'NOHEADERNOFOOTER')) {
40 define(
'NOHEADERNOFOOTER',
'1');
43include
'../../main.inc.php';
50include_once DOL_DOCUMENT_ROOT .
'/core/class/html.form.class.php';
53$objectid =
GETPOST(
'objectid',
'aZ09');
55$objecttype =
GETPOST(
'objecttype',
'aZ09arobase');
56$objectkey =
GETPOST(
'objectkey',
'restricthtml');
57$search =
GETPOST(
'search',
'restricthtml');
60$value =
GETPOST(
'value',
'alphanohtml');
62$offset = (($page - 1) * $limit);
64if (is_numeric($objectid)) {
65 $objectid = (int) $objectid;
67 $element_ref = $objectid;
71$object = fetchObjectByElement($objectid, $objecttype, $element_ref);
73 httponly_accessforbidden(
'Failed to get object with fetchObjectByElement(id=' . $objectid .
', objecttype=' . $objecttype .
')');
79$usesublevelpermission = (
$module != $element ? $element :
'');
80if ($usesublevelpermission && !$user->hasRight($module, $element)) {
81 $usesublevelpermission =
'';
103 $data[
'results'][] = [
111 $extrafields->fetch_name_optionals_label($element);
112 $options = $extrafields->attributes[$element][
'param'][$objectkey][
'options'];
113 if (is_array($options)) {
116 $tmpparamoptions = array_keys($options);
117 $paramoptions = preg_split(
'/[\r\n]+/', $tmpparamoptions[0]);
119 $InfoFieldList = explode(
":", $paramoptions[0], 5);
131 if (! empty($InfoFieldList[4])) {
133 $parenthesisopen = 0;
134 while (substr($InfoFieldList[4], $pos, 1) !==
'' && ($parenthesisopen || $pos == 0 || substr($InfoFieldList[4], $pos, 1) !=
':')) {
135 if (substr($InfoFieldList[4], $pos, 1) ==
'(') {
138 if (substr($InfoFieldList[4], $pos, 1) ==
')') {
143 $tmpbefore = substr($InfoFieldList[4], 0, $pos);
144 $tmpafter = substr($InfoFieldList[4], $pos + 1);
146 $InfoFieldList[4] = $tmpbefore;
147 if ($tmpafter !==
'') {
148 $InfoFieldList = array_merge($InfoFieldList, explode(
':', $tmpafter));
153 if (preg_match(
'/^\(?([a-z0-9]+)([=<>]+)(\d+)\)?$/i', $InfoFieldList[4], $reg)) {
154 $InfoFieldList[4] =
'(' . $reg[1] .
':' . $reg[2] .
':' . $reg[3] .
')';
162 $keyList = (empty($InfoFieldList[2]) ?
'rowid' : $InfoFieldList[2] .
' as rowid');
164 if (count($InfoFieldList) > 3 && !empty($InfoFieldList[3])) {
165 list($parentName, $parentField) = explode(
'|', $InfoFieldList[3]);
166 $keyList .=
', ' . $parentField;
168 if (count($InfoFieldList) > 4 && !empty($InfoFieldList[4])) {
169 if (strpos($InfoFieldList[4],
'extra.') !==
false) {
170 $keyList =
'main.' . $db->sanitize($InfoFieldList[2]) .
' as rowid';
172 $keyList = $db->sanitize($InfoFieldList[2]) .
' as rowid';
176 $filter_categorie =
false;
177 if (count($InfoFieldList) > 5) {
178 if ($InfoFieldList[0] ==
'categorie') {
179 $filter_categorie =
true;
183 if (!$filter_categorie) {
184 $fields_label = isset($InfoFieldList[1]) ? explode(
'|', $InfoFieldList[1]) : array();
185 if (!empty($fields_label)) {
187 $keyList .= implode(
', ', $fields_label);
191 $sql =
"SELECT " . $db->sanitize($keyList, 0, 0, 1);
192 $sql .=
' FROM ' . $db->prefix() . $db->sanitize($InfoFieldList[0]);
195 if (!empty($InfoFieldList[4])) {
197 if (strpos($InfoFieldList[4],
'$ENTITY$') !==
false) {
198 $InfoFieldList[4] = str_replace(
'$ENTITY$', (
string)
$conf->entity, $InfoFieldList[4]);
201 global $dolibarr_allow_unsecured_select_in_extrafields_filter;
202 if (!empty($dolibarr_allow_unsecured_select_in_extrafields_filter)) {
203 if (strpos($InfoFieldList[4],
'$SEL$') !==
false) {
204 $InfoFieldList[4] = str_replace(
'$SEL$',
'SELECT', $InfoFieldList[4]);
208 if (strpos($InfoFieldList[4],
'$MODE$') !==
false) {
209 $InfoFieldList[4] = str_replace(
'$MODE$', preg_replace(
'/[^a-z0-9_]/i',
'', (
string) $mode), $InfoFieldList[4]);
213 if (strpos($InfoFieldList[4],
'$ID$') !==
false && !empty($objectid)) {
214 $InfoFieldList[4] = str_replace(
'$ID$', (
string) $objectid, $InfoFieldList[4]);
216 $InfoFieldList[4] = str_replace(
'$ID$',
'0', $InfoFieldList[4]);
222 preg_match_all(
'/\$(.*?)\$/', $InfoFieldList[4], $tags);
223 foreach ($tags[0] as $keytag => $valuetag) {
224 $property = preg_replace(
'/[^a-z0-9_]/',
'', strtolower($tags[1][$keytag]));
225 if (strpos($InfoFieldList[4], $valuetag) !==
false && property_exists($object, $property) && !empty(
$object->$property)) {
226 $InfoFieldList[4] = str_replace($valuetag, (
string)
$object->$property, $InfoFieldList[4]);
228 $InfoFieldList[4] = str_replace($valuetag,
'0', $InfoFieldList[4]);
235 if (strpos($InfoFieldList[4],
'extra.') !==
false) {
236 $sql .=
' as main, ' . $db->sanitize($db->prefix() . $InfoFieldList[0]) .
'_extrafields as extra';
237 $sqlwhere .=
" WHERE extra.fk_object = main." . $db->sanitize($InfoFieldList[2]);
243 $sqlwhere .=
' WHERE 1=1';
247 if (in_array($InfoFieldList[0], array(
'tablewithentity'))) {
248 $sqlwhere .=
' AND entity = ' . ((int)
$conf->entity);
258 $orderfields = explode(
'|', $InfoFieldList[1]);
259 $keyList = $InfoFieldList[1];
260 if (count($orderfields)) {
261 $keyList = implode(
', ', $orderfields);
263 $sql .= $db->order($keyList);
264 $sql .= $db->plimit($limit, $offset);
268 $resql = $db->query($sql);
271 $num = $db->num_rows($resql);
275 $obj = $db->fetch_object($resql);
279 $fields_label = explode(
'|', $InfoFieldList[1]);
280 if (count($fields_label) > 1) {
282 foreach ($fields_label as $field_toshow) {
283 $labeltoshow .= $obj->$field_toshow .
' ';
286 $labeltoshow = $obj->{$InfoFieldList[1]};
289 if ($value == $obj->rowid) {
291 foreach ($fields_label as $field_toshow) {
292 $translabel = $langs->trans($obj->$field_toshow);
293 $labeltoshow = $translabel .
' ';
297 $data[
'results'][] = [
299 'text' => $labeltoshow,
303 $translabel = $langs->trans($obj->{$InfoFieldList[1]});
304 $labeltoshow = $translabel;
306 if (empty($labeltoshow)) {
307 $labeltoshow =
'(not defined)';
320 $data[
'results'][] = [
322 'text' => $labeltoshow,
330 dol_syslog(
'Error in request ' . $db->lasterror() .
'. Check setup of extra parameters.', LOG_ERR);
333 require_once DOL_DOCUMENT_ROOT .
'/categories/class/categorie.class.php';
334 require_once DOL_DOCUMENT_ROOT .
'/core/class/html.form.class.php';
339if ($page > 1 && $i < 9) {
340 $data[
'pagination'] = [
344print json_encode($data);
if(! $sortfield) if(! $sortorder) $object
if(! $sortfield) if(! $sortorder) $module
natural_search($fields, $value, $mode=0, $nofirstand=0, $sqltoadd='')
Generate natural SQL search string for a criteria (this criteria can be tested on one or several fiel...
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
forgeSQLFromUniversalSearchCriteria($filter, &$errorstr='', $noand=0, $nopar=0, $noerror=0, $forbiddenfields=array())
forgeSQLFromUniversalSearchCriteria
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
if(!defined( 'NOREQUIREMENU')) if(!empty(GETPOST('seteventmessages', 'alpha'))) if(!function_exists("llxHeader")) top_httphead($contenttype='text/html', $forcenocache=0)
Show HTTP header.
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.
restrictedArea(User $user, $features, $object=0, $tableandshare='', $feature2='', $dbt_keyfield='fk_soc', $dbt_select='rowid', $isdraft=0, $nodie=0, $mode='')
Check permissions of a user to show a page and an object.