interface_20_all_Logevents.class.php 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170
  1. <?php
  2. /* Copyright (C) 2005-2009 Laurent Destailleur <eldy@users.sourceforge.net>
  3. * Copyright (C) 2009-2017 Regis Houssin <regis.houssin@inodbox.com>
  4. * Copyright (C) 2014 Marcos García <marcosgdf@gmail.com>
  5. * Copyright (C) 2023 Udo Tamm <dev@dolibit.de>
  6. * Copyright (C) 2023 William Mead <william.mead@manchenumerique.fr>
  7. *
  8. * This program is free software; you can redistribute it and/or modify
  9. * it under the terms of the GNU General Public License as published by
  10. * the Free Software Foundation; either version 3 of the License, or
  11. * (at your option) any later version.
  12. *
  13. * This program is distributed in the hope that it will be useful,
  14. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. * GNU General Public License for more details.
  17. *
  18. * You should have received a copy of the GNU General Public License
  19. * along with this program. If not, see <https://www.gnu.org/licenses/>.
  20. */
  21. /**
  22. * \file htdocs/core/triggers/interface_20_all_Logevents.class.php
  23. * \ingroup core
  24. * \brief Trigger file for log events
  25. */
  26. require_once DOL_DOCUMENT_ROOT.'/core/triggers/dolibarrtriggers.class.php';
  27. /**
  28. * Class of triggers for security audit events
  29. */
  30. class InterfaceLogevents extends DolibarrTriggers
  31. {
  32. const EVENT_ACTION_DICT = array( // TODO reduce number of events to CREATE, UPDATE & DELETE. Use object properties to pinpoint precise action.
  33. 'USER_LOGIN' => 'UserLogged',
  34. 'USER_LOGIN_FAILED' => 'UserLoginFailed',
  35. 'USER_LOGOUT' => 'UserLogoff',
  36. 'USER_CREATE' => 'NewUserCreated',
  37. 'USER_MODIFY' => 'EventUserModified',
  38. 'USER_NEW_PASSWORD' => 'NewUserPassword',
  39. 'USER_ENABLEDISABLE' => 'UserEnabledDisabled',
  40. 'USER_DELETE' => 'UserDeleted',
  41. 'USERGROUP_CREATE' => 'NewGroupCreated',
  42. 'USERGROUP_MODIFY' => 'GroupModified',
  43. 'USERGROUP_DELETE' => 'GroupDeleted'
  44. );
  45. /**
  46. * @var string Label
  47. */
  48. private $event_label;
  49. /**
  50. * @var string Description
  51. */
  52. private $event_desc;
  53. /**
  54. * @var int Date
  55. */
  56. private $event_date;
  57. /**
  58. * Constructor
  59. * @param DoliDB $db Database handler
  60. */
  61. public function __construct(DoliDB $db)
  62. {
  63. parent::__construct($db);
  64. $this->family = "core";
  65. $this->description = "Triggers of this module allows to add security event records inside Dolibarr.";
  66. $this->version = self::VERSION_DOLIBARR; // VERSION_ 'DEVELOPMENT' or 'EXPERIMENTAL' or 'DOLIBARR'
  67. $this->picto = 'technic';
  68. $this->event_label = '';
  69. $this->event_desc = '';
  70. $this->event_date = 0;
  71. }
  72. /**
  73. * Function called when a Dolibarr security audit event is done.
  74. * All functions "runTrigger" are triggered if file is inside directory htdocs/core/triggers or htdocs/module/code/triggers (and declared)
  75. *
  76. * @param string $action Event action code
  77. * @param Object $object Object
  78. * @param User $user Object user
  79. * @param Translate $langs Object langs
  80. * @param conf $conf Object conf
  81. * @return int if KO: <0, if no trigger ran: 0, if OK: >0
  82. * @throws Exception dol_syslog can throw Exceptions
  83. */
  84. public function runTrigger($action, $object, User $user, Translate $langs, Conf $conf)
  85. {
  86. if (getDolGlobalString('MAIN_LOGEVENTS_DISABLE_ALL')) {
  87. return 0; // Log events is disabled (hidden features)
  88. }
  89. $key = 'MAIN_LOGEVENTS_'.$action;
  90. if (empty($conf->global->$key)) {
  91. return 0; // Log events not enabled for this action
  92. }
  93. if (empty($conf->entity)) {
  94. global $entity;
  95. $conf->entity = $entity; // forcing of the entity if it's not defined (ex: in login form)
  96. }
  97. // Actions
  98. dol_syslog("Trigger '" . $this->name . "' for action '$action' launched by " . __FILE__ . ". id=" . $object->id);
  99. $this->initEventData(InterfaceLogevents::EVENT_ACTION_DICT[$action], $object);
  100. // Add entry in event table
  101. include_once DOL_DOCUMENT_ROOT.'/core/class/events.class.php';
  102. $event = new Events($this->db);
  103. $event->type = $action;
  104. $event->dateevent = $this->event_date;
  105. $event->label = $this->event_label;
  106. $event->description = $this->event_desc;
  107. $event->user_agent = (empty($_SERVER["HTTP_USER_AGENT"]) ? '' : $_SERVER["HTTP_USER_AGENT"]);
  108. $event->authentication_method = (empty($object->context['authentication_method']) ? '' : $object->context['authentication_method']);
  109. $result = $event->create($user);
  110. if ($result > 0) {
  111. return 1;
  112. } else {
  113. $error = "Failed to insert security event: ".$event->error;
  114. $this->errors[] = $error;
  115. $this->error = $error;
  116. dol_syslog(get_class($this).": ".$error, LOG_ERR);
  117. return -1;
  118. }
  119. }
  120. /**
  121. * Method called by runTrigger to initialize date, label & description data for event
  122. *
  123. * @param string $key_text Action string
  124. * @param Object $object Object
  125. * @return void
  126. */
  127. private function initEventData($key_text, $object)
  128. {
  129. $this->event_date = dol_now();
  130. $this->event_label = $this->event_desc = $key_text . ' : ' . $object->login;
  131. if ($key_text == InterfaceLogevents::EVENT_ACTION_DICT['USER_ENABLEDISABLE']) { // TODO should be refactored using an object property for event data.
  132. $object->statut ? $this->event_desc .= ' - disabled' : $this->event_desc .= ' - enabled';
  133. }
  134. // Add more information into event description from the context property
  135. if (!empty($object->context['audit'])) {
  136. $this->event_desc .= (empty($this->event_desc) ? '' : ' - ').$object->context['audit'];
  137. }
  138. }
  139. /**
  140. * Check if text contains an event action key. Used for dynamic localization on frontend events list.
  141. *
  142. * @param string $event_text Input event text
  143. * @return bool True if event text is a coded structured string
  144. */
  145. public static function isEventActionTextKey($event_text)
  146. {
  147. foreach (InterfaceLogevents::EVENT_ACTION_DICT as $value) {
  148. if (str_contains($event_text, $value)) {
  149. return true;
  150. }
  151. }
  152. return false;
  153. }
  154. }