selectobject.php 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160
  1. <?php
  2. /* Copyright (C) 2017 Laurent Destailleur <eldy@users.sourceforge.net>
  3. *
  4. * This program is free software; you can redistribute it and/or modify
  5. * it under the terms of the GNU General Public License as published by
  6. * the Free Software Foundation; either version 3 of the License, or
  7. * (at your option) any later version.
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program. If not, see <https://www.gnu.org/licenses/>.
  16. */
  17. /**
  18. * \file htdocs/core/ajax/selectobject.php
  19. * \brief File to return Ajax response on a selection list request
  20. */
  21. if (!defined('NOTOKENRENEWAL')) {
  22. define('NOTOKENRENEWAL', 1); // Disables token renewal
  23. }
  24. if (!defined('NOREQUIREMENU')) {
  25. define('NOREQUIREMENU', '1');
  26. }
  27. if (!defined('NOREQUIREHTML')) {
  28. define('NOREQUIREHTML', '1');
  29. }
  30. if (!defined('NOREQUIREAJAX')) {
  31. define('NOREQUIREAJAX', '1');
  32. }
  33. if (!defined('NOREQUIRESOC')) {
  34. define('NOREQUIRESOC', '1');
  35. }
  36. // Load Dolibarr environment
  37. require '../../main.inc.php';
  38. require_once DOL_DOCUMENT_ROOT.'/core/class/html.form.class.php';
  39. require_once DOL_DOCUMENT_ROOT.'/core/class/extrafields.class.php';
  40. $extrafields = new ExtraFields($db);
  41. $objectdesc = GETPOST('objectdesc', 'alphanohtml', 0, null, null, 1);
  42. $htmlname = GETPOST('htmlname', 'aZ09');
  43. $outjson = (GETPOST('outjson', 'int') ? GETPOST('outjson', 'int') : 0);
  44. $id = GETPOSTINT('id');
  45. $objectfield = GETPOST('objectfield', 'alpha'); // 'MyObject:field' or 'MyModule_MyObject:field' or 'MyObject:option_field' or 'MyModule_MyObject:option_field'
  46. if (empty($htmlname)) {
  47. httponly_accessforbidden('Bad value for param htmlname');
  48. }
  49. if (!empty($objectfield)) {
  50. // Recommended method to call selectobject.
  51. // $objectfield is Object:Field that contains the definition (in table $fields or extrafield). Example: 'Societe:t.ddd' or 'Societe:options_xxx'
  52. $tmparray = explode(':', $objectfield);
  53. $objectdesc = '';
  54. // Load object according to $id and $element
  55. $objectforfieldstmp = fetchObjectByElement(0, strtolower($tmparray[0]));
  56. $reg = array();
  57. if (preg_match('/^options_(.*)$/', $tmparray[1], $reg)) {
  58. // For a property in extrafields
  59. $key = $reg[1];
  60. // fetch optionals attributes and labels
  61. $extrafields->fetch_name_optionals_label($objectforfieldstmp->table_element);
  62. if (!empty($extrafields->attributes[$objectforfieldstmp->table_element]['type'][$key]) && $extrafields->attributes[$objectforfieldstmp->table_element]['type'][$key] == 'link') {
  63. if (!empty($extrafields->attributes[$objectforfieldstmp->table_element]['param'][$key]['options'])) {
  64. $tmpextrafields = array_keys($extrafields->attributes[$objectforfieldstmp->table_element]['param'][$key]['options']);
  65. $objectdesc = $tmpextrafields[0];
  66. }
  67. }
  68. } else {
  69. // For a property in ->fields
  70. $objectdesc = $objectforfieldstmp->fields[$tmparray[1]]['type'];
  71. $objectdesc = preg_replace('/^integer[^:]*:/', '', $objectdesc);
  72. }
  73. }
  74. if ($objectdesc) {
  75. // Example of value for $objectdesc:
  76. // Bom:bom/class/bom.class.php:0:t.status=1
  77. // Bom:bom/class/bom.class.php:0:t.status=1:ref
  78. // Bom:bom/class/bom.class.php:0:(t.status:=:1) OR (t.field2:=:2):ref
  79. $InfoFieldList = explode(":", $objectdesc, 4);
  80. $vartmp = (empty($InfoFieldList[3]) ? '' : $InfoFieldList[3]);
  81. $reg = array();
  82. if (preg_match('/^.*:(\w*)$/', $vartmp, $reg)) {
  83. $InfoFieldList[4] = $reg[1]; // take the sort field
  84. }
  85. $InfoFieldList[3] = preg_replace('/:\w*$/', '', $vartmp); // take the filter field
  86. $classname = $InfoFieldList[0];
  87. $classpath = $InfoFieldList[1];
  88. //$addcreatebuttonornot = empty($InfoFieldList[2]) ? 0 : $InfoFieldList[2];
  89. $filter = empty($InfoFieldList[3]) ? '' : $InfoFieldList[3];
  90. $sortfield = empty($InfoFieldList[4]) ? '' : $InfoFieldList[4];
  91. // Load object according to $id and $element
  92. $objecttmp = fetchObjectByElement(0, strtolower($InfoFieldList[0]));
  93. // Fallback to another solution to get $objecttmp
  94. if (empty($objecttmp) && !empty($classpath)) {
  95. dol_include_once($classpath);
  96. if ($classname && class_exists($classname)) {
  97. $objecttmp = new $classname($db);
  98. }
  99. }
  100. }
  101. // Make some replacement
  102. $sharedentities = getEntity(strtolower($objecttmp->element));
  103. $filter = str_replace(
  104. array('__ENTITY__', '__SHARED_ENTITIES__', '__USER_ID__', '$ID$'),
  105. array($conf->entity, $sharedentities, $user->id, $id),
  106. $filter
  107. );
  108. /*
  109. $module = $object->module;
  110. $element = $object->element;
  111. $usesublevelpermission = ($module != $element ? $element : '');
  112. if ($usesublevelpermission && !isset($user->rights->$module->$element)) { // There is no permission on object defined, we will check permission on module directly
  113. $usesublevelpermission = '';
  114. }
  115. */
  116. // When used from jQuery, the search term is added as GET param "term".
  117. $searchkey = (($id && GETPOST($id, 'alpha')) ? GETPOST($id, 'alpha') : (($htmlname && GETPOST($htmlname, 'alpha')) ? GETPOST($htmlname, 'alpha') : ''));
  118. // Add a security test to avoid to get content of all tables
  119. restrictedArea($user, $objecttmp->element, $id);
  120. /*
  121. * View
  122. */
  123. $form = new Form($db);
  124. top_httphead($outjson ? 'application/json' : 'text/html');
  125. //print '<!-- Ajax page called with url '.dol_escape_htmltag($_SERVER["PHP_SELF"]).'?'.dol_escape_htmltag($_SERVER["QUERY_STRING"]).' -->'."\n";
  126. //print_r($_GET);
  127. $arrayresult = $form->selectForFormsList($objecttmp, $htmlname, '', 0, $searchkey, '', '', '', 0, 1, 0, '', $filter);
  128. $db->close();
  129. if ($outjson) {
  130. print json_encode($arrayresult);
  131. }