group_model = new GroupModel(); $this->group_user_model = new GroupsUsersModel(); $this->user_model = new UserModel(); $this->viewData['pageTitle'] = lang('Users.moduleTitle'); // Breadcrumbs (IMN) $this->viewData['breadcrumb'] = [ ['title' => lang("App.menu_configuration"), 'route' => "javascript:void(0);", 'active' => false], ['title' => lang("App.menu_users"), 'route' => site_url('configuracion/users'), 'active' => true] ]; parent::initController($request, $response, $logger); } public function index() { $this->viewData['usingClientSideDataTable'] = true; $this->viewData['pageSubTitle'] = lang('Basic.global.ManageAllRecords', [lang('Users.user')]); $this->viewData['user_model'] = $this->user_model; $this->viewData['userList2'] = $this->user_model->getUsersList(); parent::index(); } public function add() { if ($this->request->getPost()) : $postData = $this->request->getPost(); $currentGroups = $postData['group']??[]; unset($postData['group']); $postData['username'] = strstr($postData['email'], '@', true); $sanitizedData = $this->sanitized($postData, true); $noException = true; $users = auth()->getProvider(); if ($successfulResult = $this->canValidate()) : // if ($successfulResult = $this->validate($this->formValidationRules) ) : if ($this->canValidate()) : try { $user = new User([ 'username' => $sanitizedData['username'], 'first_name' => $sanitizedData['first_name'], 'last_name' => $sanitizedData['last_name'], 'email' => $sanitizedData['email'], 'password' => 'Safekat2024', 'status' => $sanitizedData['status']??0, 'active' => $sanitizedData['active']??0, ]); $users->save($user); $successfulResult = true; // Hacked } catch (\Exception $e) { $noException = false; //$this->dealWithException($e); if (strpos($e->getMessage(), 'correo duplicado') !== false) { $this->viewData['errorMessage'] = "El correo electrónico ya está registrado en el sistema"; $this->session->setFlashdata('formErrors', $this->model->errors()); } } else: $this->viewData['errorMessage'] = lang('Basic.global.formErr1', [mb_strtolower(lang('Users.user'))]); $this->session->setFlashdata('formErrors', $this->model->errors()); endif; $thenRedirect = true; // Change this to false if you want your user to stay on the form after submission endif; if ($noException && $successfulResult) : $id = $users->getInsertID(); $this->group_user_model->where('user_id', $id)->delete(); foreach($currentGroups as $group){ $group_user_data = [ 'user_id' => $id, 'group' => $group ]; $this->group_user_model->insert($group_user_data); } $message = lang('Basic.global.saveSuccess', [mb_strtolower(lang('Users.user'))]) . 'Downloads'; $message .= anchor(route_to('editUser', $id), lang('Basic.global.continueEditing').'?'); $message = ucfirst(str_replace("'", "\'", $message)); if ($thenRedirect) : if (!empty($this->indexRoute)) : return redirect()->to(route_to($this->indexRoute))->with('successMessage', $message); else: return $this->redirect2listView('successMessage', $message); endif; else: $this->viewData['successMessage'] = $message; endif; endif; // $noException && $successfulResult endif; // ($requestMethod === 'post') $this->viewData['user'] = isset($sanitizedData) ? new UserEntity($sanitizedData) : new UserEntity(); $this->viewData['clienteList'] = $this->getClienteListItems(); $this->viewData['formAction'] = route_to('createUser'); $this->viewData['groups'] = $this->group_model->select('keyword, title')->findAll(); $this->viewData['boxTitle'] = lang('Basic.global.addNew') .lang('Users.user').' '.lang('Basic.global.addNewSuffix'); return $this->displayForm(__METHOD__); } // end function add() public function edit($requestedId = null) { if ($requestedId == null) : return $this->redirect2listView(); endif; $id = filter_var($requestedId, FILTER_SANITIZE_URL); $user = $this->model->find($id); if ($user == false) : $message = lang('Basic.global.notFoundWithIdErr', [mb_strtolower(lang('Users.user')), $id]); return $this->redirect2listView('errorMessage', $message); endif; if ($this->request->getPost()) : $postData = $this->request->getPost(); $currentGroups = $postData['group']; unset($postData['group']); $sanitizedData = $this->sanitized($postData, true); if ($this->request->getPost('status') == 0 ) { $sanitizedData['status'] = null; } $noException = true; if ($successfulResult = $this->canValidate()) : // if ($successfulResult = $this->validate($this->formValidationRules) ) : if ($this->canValidate()) : try { if (in_array('cliente-editor', $currentGroups) || in_array('cliente-administrador', $currentGroups)) { if(!array_key_exists('cliente_id', $sanitizedData) || is_null($sanitizedData['cliente_id'])) { $this->viewData['errorMessage'] = lang('Users.errors.cliente_sin_clienteID'); $this->session->setFlashdata('formErrors', $this->model->errors()); $successfulResult = false; } else{ $successfulResult = $this->model->skipValidation(true)->update($id, $sanitizedData); } } else { $successfulResult = $this->model->skipValidation(true)->update($id, $sanitizedData); } } catch (\Exception $e) { $noException = false; $this->dealWithException($e); } else: $this->viewData['warningMessage'] = lang('Basic.global.formErr1', [mb_strtolower(lang('Users.user'))]); $this->session->setFlashdata('formErrors', $this->model->errors()); endif; $user->fill($sanitizedData); $thenRedirect = false; endif; if ($noException && $successfulResult) : $this->group_user_model->where('user_id', $user->id)->delete(); foreach($currentGroups as $group){ $group_user_data = [ 'user_id' => $user->id, 'group' => $group ]; $this->group_user_model->insert($group_user_data); } $id = $user->id ?? $id; $message = lang('Basic.global.updateSuccess', [mb_strtolower(lang('Users.user'))]) . 'Downloads'; $message .= anchor(route_to('editUser', $id), lang('Basic.global.continueEditing').'?'); $message = ucfirst(str_replace("'", "\'", $message)); if ($thenRedirect) : if (!empty($this->indexRoute)) : return redirect()->to(route_to($this->indexRoute))->with('successMessage', $message); else: return $this->redirect2listView('successMessage', $message); endif; else: $this->session->setFlashData('sweet-success', $message); endif; endif; // $noException && $successfulResult endif; // ($requestMethod === 'post') $this->viewData['user'] = $user; $this->viewData['clienteList'] = $this->getClienteListItems($user->cliente_id); $this->viewData['formAction'] = route_to('updateUser', $id); $this->viewData['selectedGroups'] = $this->group_model->getUsersRoles($requestedId); $this->viewData['groups'] = $this->group_model->select('keyword, title')->findAll(); $this->viewData['boxTitle'] = lang('Basic.global.edit2') .lang('Users.user').' '.lang('Basic.global.edit3'); return $this->displayForm(__METHOD__, $id); } // end function edit(...) public function delete($requestedId = null, bool $deletePermanently = true) { if ($requestedId == null) : return $this->redirect2listView(); endif; $id = filter_var($requestedId, FILTER_SANITIZE_URL); $user = $this->model->find($id); if ($user == false) : $message = lang('Basic.global.notFoundWithIdErr', [mb_strtolower(lang('Users.user')), $id]); return $this->redirect2listView('errorMessage', $message); endif; $users = auth()->getProvider(); $users->delete($user->id, $deletePermanently); $message = "Usuario eliminado correctamente"; return $this->redirect2listView('successMessage', $message); } // end function delete(...) public function allItemsSelect() { if ($this->request->isAJAX()) { $onlyActiveOnes = true; $reqVal = $this->request->getPost('val') ?? 'id_user'; $menu = $this->model->getAllForMenu($reqVal.', first_name', 'first_name', $onlyActiveOnes, false); $nonItem = new \stdClass; $nonItem->id_user = ''; $nonItem->first_name = '- '.lang('Basic.global.None').' -'; array_unshift($menu , $nonItem); $newTokenHash = csrf_hash(); $csrfTokenName = csrf_token(); $data = [ 'menu' => $menu, $csrfTokenName => $newTokenHash ]; return $this->respond($data); } else { return $this->failUnauthorized('Invalid request', 403); } } public function menuItems() { if ($this->request->isAJAX()) { $searchStr = goSanitize($this->request->getPost('searchTerm'))[0]; $reqId = goSanitize($this->request->getPost('id'))[0]; $reqText = goSanitize($this->request->getPost('text'))[0]; $onlyActiveOnes = false; $columns2select = [$reqId ?? 'id_user', $reqText ?? 'first_name']; $onlyActiveOnes = false; $menu = $this->model->getSelect2MenuItems($columns2select, $columns2select[1], $onlyActiveOnes, $searchStr); $nonItem = new \stdClass; $nonItem->id = ''; $nonItem->text = '- '.lang('Basic.global.None').' -'; array_unshift($menu , $nonItem); $newTokenHash = csrf_hash(); $csrfTokenName = csrf_token(); $data = [ 'menu' => $menu, $csrfTokenName => $newTokenHash ]; return $this->respond($data); } else { return $this->failUnauthorized('Invalid request', 403); } } public function getMenuComerciales(){ if ($this->request->isAJAX()) { $comerciales = $this->model->getComerciales(); $newTokenHash = csrf_hash(); $csrfTokenName = csrf_token(); $data = [ 'menu' => $comerciales, $csrfTokenName => $newTokenHash ]; return $this->respond($data); } else { return $this->failUnauthorized('Invalid request', 403); } } protected function getPaisListItems() { $data = [''=>lang('Basic.global.pleaseSelectA', [mb_strtolower(lang('Pais.pais'))])]; $paisModel = model('App\Models\Configuracion\PaisModel'); $registers = $paisModel->findAll(); return $registers; } protected function getClienteListItems($selId = null) { $data = ['' => ""]; if (!empty($selId)) : $clienteModel = model('App\Models\Clientes\ClienteModel'); $selOption = $clienteModel->where('id', $selId)->findColumn('nombre'); if (!empty($selOption)) : $data[$selId] = $selOption[0]; endif; endif; return $data; } }