dolibarr 25.0.0-alpha
savekanbanfield.php
Go to the documentation of this file.
1<?php
2/* Copyright (C) 2026 Guenter Lukas <gl@gl.co.at>
3 *
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 3 of the License, or
7 * (at your option) any later version.
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program. If not, see <https://www.gnu.org/licenses/>.
16 */
17
25if (!defined('NOTOKENRENEWAL')) {
26 define('NOTOKENRENEWAL', '1'); // Disables token renewal, the page is called several times in a row
27}
28if (!defined('NOREQUIREMENU')) {
29 define('NOREQUIREMENU', '1');
30}
31if (!defined('NOREQUIREAJAX')) {
32 define('NOREQUIREAJAX', '1');
33}
34if (!defined('NOREQUIRESOC')) {
35 define('NOREQUIRESOC', '1');
36}
37
38// Load Dolibarr environment
39require '../../main.inc.php';
40
48$element = GETPOST('element', 'aZ09');
49$fk_element = GETPOSTINT('fk_element');
50$field = preg_replace('/^editval_/', '', GETPOST('field', 'aZ09'));
51$value = GETPOST('value', 'aZ09');
52
53// Load object according to $fk_element and $element
54$object = fetchObjectByElement($fk_element, $element);
55if (!is_object($object) || $object->id <= 0) {
56 httponly_accessforbidden('Not allowed, bad combination of parameters for fetchObjectByElement');
57}
58
59// Security check with mode 'write', so restrictedArea() tests the write permission and not only the read permission.
60$result = restrictedArea($user, empty($object->module) ? $element : $object->module, $object, $object->table_element, '', 'fk_soc', 'rowid', 0, 1, 'write'); // Call with nodie return
61if (!$result) {
62 httponly_accessforbidden('Not allowed by restrictArea');
63}
64
65// Add blacklist of some forbidden field name.
66$blacklistedfields = array('pass', 'pass_crypted', 'pass_temp', 'api_key', 'openid', 'admin', 'status', 'statut');
67$canreadsalary = ((isModEnabled('salaries') && $user->hasRight('salaries', 'read')) || !isModEnabled('salaries'));
68if (!$canreadsalary) {
69 $blacklistedfields[] = 'salary';
70 $blacklistedfields[] = 'salaryextra';
71 $blacklistedfields[] = 'thm';
72 $blacklistedfields[] = 'tjm';
73}
74if (in_array($field, $blacklistedfields)) {
75 httponly_accessforbidden("Can't edit a field blacklisted with name ".$field);
76}
77
78// Use also a whitelist for field
79$whitelistfields = array('fk_opp_status');
80if (!in_array($field, $whitelistfields)) {
81 httponly_accessforbidden("Can't edit a field ".$field." not in whiteliste");
82}
83
84// Use also a whitelist for module
85$whitelistelement = array('projet', 'project');
86if (!in_array($object->module, $whitelistelement)) {
87 httponly_accessforbidden("Can't edit a field for element module = ".$object->module);
88}
89
90// TODO Use a property into ->fields to defined whitelist properties allowed for savekanbanfield.php or more globally for inline standalone update?
91
92
93
94/*
95 * Actions
96 */
97
99
100// The column of the records without any value uses the id 'undefined' (see mode=kanbangroupby
101// into the list pages), it is stored as 0 like the "Undefined" entry of the column dictionary.
102$isint = preg_match('/^integer/', $object->fields[$field]['type']);
103if ($value === 'undefined' || $value === '') {
104 $newvalue = $isint ? 0 : '';
105} else {
106 $newvalue = $isint ? (int) $value : $value;
107}
108
109$return = array();
110
111// Save with a trigger key, so a change is seen by triggers, hooks and the agenda
112$res = $object->setValueFrom($field, $newvalue, '', null, $isint ? 'int' : 'text', '', $user, strtoupper($object->element).'_MODIFY');
113if ($res > 0) {
114 $return['value'] = $newvalue;
115} else {
116 $return['error'] = empty($object->error) ? $langs->trans('ErrorFailedToUpdateRecord') : $object->error;
117}
118
119echo json_encode($return);
if(! $sortfield) if(! $sortorder) $object
Definition account.php:100
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
GETPOSTINT($paramname, $method=0, $nodefault=0)
Return the value of a $_GET or $_POST supervariable, converted into integer.
isModEnabled($module)
Is Dolibarr module enabled.
if(!defined( 'NOREQUIREMENU')) if(!empty(GETPOST('seteventmessages', 'alpha'))) if(!function_exists("llxHeader")) top_httphead($contenttype='text/html', $forcenocache=0)
Show HTTP header.
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.
restrictedArea(User $user, $features, $object=0, $tableandshare='', $feature2='', $dbt_keyfield='fk_soc', $dbt_select='rowid', $isdraft=0, $nodie=0, $mode='')
Check permissions of a user to show a page and an object.