<?php # $Id$ # http://www.mapbender.org/index.php/Administration # Copyright (C) 2002 CCGIS # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; either version 2, or (at your option) # any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program; if not, write to the Free Software # Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. $e_id="User_Group"; require_once(dirname(__FILE__)."/../php/mb_validatePermission.php"); /* * @security_patch irv done */ //security_patch_log(__FILE__,__LINE__); $postvars = explode(",", "filter1,selected_user,insert,remove,remove_group,selected_group"); foreach ($postvars as $value) { $$value = $_POST[$value]; } ?> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <?php echo '<meta http-equiv="Content-Type" content="text/html; charset='.CHARSET.'">'; include '../include/dyn_css.php'; ?> <script language="JavaScript"> function validate(wert){ if(document.forms[0]["selected_user"].selectedIndex == -1){ document.getElementsByName("selected_user")[0].style.backgroundColor = '#ff0000'; return; }else{ if(wert == "remove"){ if(document.forms[0]["remove_group[]"].selectedIndex == -1){ document.getElementsByName("remove_group[]")[0].style.backgroundColor = '#ff0000'; return; } document.form1.remove.value = 'true'; document.form1.submit(); } if(wert == "insert"){ if(document.forms[0]["selected_group[]"].selectedIndex == -1){ document.getElementsByName("selected_group[]")[0].style.backgroundColor = '#ff0000'; return; } document.form1.insert.value = 'true'; document.form1.submit(); } } } /** * filter the Userlist by str */ function filterUser(list, all, str){ str=str.toLowerCase(); var selection=[]; var i,j,selected; for(i=0;i<list.options.length;i++){ if(list.options[i].selected) selection[selection.length]=list.options[i].value; } list.options.length = 0; for(i=0; i<all.length; i++){ if(all[i]['name'].toLowerCase().indexOf(str)==-1) continue; selected=false; for(j=0;j<selection.length;j++){ if(selection[j]==all[i]['id']){ selected=true; break; } } var newOption = new Option(selected?all[i]['name']+" ("+all[i]['email']+")":all[i]['name'],all[i]['id'],false,selected); newOption.setAttribute("title", all[i]['email']); list.options[list.options.length] = newOption; } } /** * add Mail adress on selection */ function updateMail(list, all){ var j=0; for(var i=0; i<list.options.length;i++){ if(list.options[i].selected){ for(j=j;j<all.length;j++){ if(all[j]['id']==list.options[i].value){ list.options[i].text=all[j]['name']+" ("+all[j]['email']+")"; list.options[i].selected = true; break; } } } else{ for(j=j;j<all.length;j++){ if(all[j]['id']==list.options[i].value){ list.options[i].text=all[j]['name']; list.options[i].selected = false; break; } } } } } </script> </head> <body> <?php $fieldHeight = 20; $cnt_group = 0; $cnt_user = 0; $cnt_group = 0; $cnt_group_user = 0; $cnt_group_group = 0; $exists = false; /*handle remove, update and insert*****************************************************************/ if($insert){ if(count($selected_group)>0){ for($i=0; $i<count($selected_group); $i++){ $exists = false; $sql_insert = "SELECT * from mb_user_mb_group where fkey_mb_user_id = $1 and fkey_mb_group_id = $2 "; $v = array($selected_user,$selected_group[$i]); $t = array('i','i'); $res_insert = db_prep_query($sql_insert,$v,$t); while(db_fetch_row($res_insert)){$exists = true;} if($exists == false){ $sql_insert = "INSERT INTO mb_user_mb_group(fkey_mb_user_id, fkey_mb_group_id) VALUES($1,$2)"; $v = array($selected_user,$selected_group[$i]); $t = array('i','i'); $res_insert = db_prep_query($sql_insert,$v,$t); } } } } if($remove){ if(count($remove_group)>0){ for($i=0; $i<count($remove_group); $i++){ $sql_remove = "DELETE FROM mb_user_mb_group WHERE fkey_mb_group_id = $1 and fkey_mb_user_id = $2"; $v = array($remove_group[$i],$selected_user); $t = array('i','i'); db_prep_query($sql_remove,$v,$t); } } } /*get all groups ********************************************************************************************/ $sql_group = "SELECT * FROM mb_group ORDER BY mb_group_name"; $res_group = db_query($sql_group); while($row = db_fetch_array($res_group)){ $group_id[$cnt_group] = $row["mb_group_id"]; $group_name[$cnt_group] = $row["mb_group_name"]; $cnt_group++; } /*get all user **********************************************************************************************/ $sql_user = "SELECT * FROM mb_user ORDER BY mb_user_name"; $res_user = db_query($sql_user); while($row = db_fetch_array($res_user)){ $user_id[$cnt_user] = $row["mb_user_id"]; $user_name[$cnt_user] = $row["mb_user_name"]; $user_email[$cnt_user] = $row["mb_user_email"]; $cnt_user++; } /*get all group from selected_user******************************************************************************/ $sql_user_mb_group = "SELECT mb_group.mb_group_id, mb_group.mb_group_name, mb_user_mb_group.fkey_mb_user_id FROM mb_user_mb_group "; $sql_user_mb_group .= "INNER JOIN mb_group ON mb_user_mb_group.fkey_mb_group_id = mb_group.mb_group_id "; $sql_user_mb_group .= "WHERE mb_user_mb_group.fkey_mb_user_id = $1 "; $sql_user_mb_group .= " ORDER BY mb_group.mb_group_name"; if(!$selected_user){$v = array($user_id[0]);} if($selected_user){$v = array($selected_user);} $t = array('i'); $res_user_mb_group = db_prep_query($sql_user_mb_group,$v,$t); while($row = db_fetch_array($res_user_mb_group)){ $group_id_user[$cnt_group_user] = $row["mb_group_id"]; $group_name_user[$cnt_group_user] = $row["mb_group_name"]; $cnt_group_user++; } /*INSERT HTML*/ echo "<form name='form1' action='" . $self ."' method='post'>"; /*filterbox****************************************************************************************/ echo "<input type='text' value='' class='filter1' id='filter1' name='filter1' onkeyup='filterUser(document.getElementById(\"selecteduser\"),user,this.value);'/>"; /*insert all user in selectbox*************************************************************************************/ echo "<div class='text1'>USER: </div>"; echo "<select style='background:#ffffff' onchange='updateMail(this, user);submit();' class='select1' id='selecteduser' name='selected_user' size='10'>"; for($i=0; $i<$cnt_user; $i++){ echo "<option value='" . $user_id[$i] . "' title='".$user_email[$i]."' "; if($selected_user && $selected_user == $user_id[$i]){ echo "selected>".$user_name[$i]." (".$user_email[$i].")"; } else echo ">" . $user_name[$i]; echo "</option>"; } echo "</select>"; /*insert all group in selectbox**************************************************************************/ echo "<div class='text2'>GROUP:</div>"; echo "<select style='background:#ffffff' class='select2' multiple='multiple' name='selected_group[]' size='$fieldHeight' >"; for($i=0; $i<$cnt_group; $i++){ echo "<option value='" . $group_id[$i] . "'>" . $group_name[$i] . "</option>"; } echo "</select>"; /*Button****************************************************************************************************/ echo "<div class='button1'><input type='button' value='==>' onClick='validate(\"insert\")'></div>"; echo "<input type='hidden' name='insert'>"; echo "<div class='button2'><input type='button' value='<==' onClick='validate(\"remove\")'></div>"; echo "<input type='hidden' name='remove'>"; /*insert user_group_dependence in selectbox**************************************************/ echo "<div class='text3'>SELECTED GROUP:</div>"; echo "<select style='background:#ffffff' class='select3' multiple='multiple' name='remove_group[]' size='$fieldHeight' >"; for($i=0; $i<$cnt_group_user; $i++){ echo "<option value='" . $group_id_user[$i] . "'>" . $group_name_user[$i] . "</option>"; } echo "</select>"; echo "</form>"; ?> <script type="text/javascript"> <!-- document.forms[0].selected_user.focus(); var user=[]; <?php for($i=0; $i<$cnt_user; $i++){ echo "user[".$i."]=[];\n"; echo "user[".$i."]['id']='" . $user_id[$i] . "';\n"; echo "user[".$i."]['name']='" . $user_name[$i] . "';\n"; echo "user[".$i."]['email']='" . $user_email[$i] . "';\n"; } ?> // --> </script> </body> </html>