view.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425
  1. <?php
  2. /* Copyright (C) 2013-2016 Jean-François FERRY <hello@librethic.io>
  3. * Copyright (C) 2018 Frédéric France <frederic.france@netlogic.fr>
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation; either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <https://www.gnu.org/licenses/>.
  17. */
  18. /**
  19. * \file htdocs/public/ticket/view.php
  20. * \ingroup ticket
  21. * \brief Public file to show one ticket
  22. */
  23. if (!defined('NOREQUIREMENU')) {
  24. define('NOREQUIREMENU', '1');
  25. }
  26. // If there is no need to load and show top and left menu
  27. if (!defined("NOLOGIN")) {
  28. define("NOLOGIN", '1');
  29. }
  30. if (!defined('NOIPCHECK')) {
  31. define('NOIPCHECK', '1'); // Do not check IP defined into conf $dolibarr_main_restrict_ip
  32. }
  33. if (!defined('NOBROWSERNOTIF')) {
  34. define('NOBROWSERNOTIF', '1');
  35. }
  36. // If this page is public (can be called outside logged session)
  37. // For MultiCompany module.
  38. // Do not use GETPOST here, function is not defined and define must be done before including main.inc.php
  39. $entity = (!empty($_GET['entity']) ? (int) $_GET['entity'] : (!empty($_POST['entity']) ? (int) $_POST['entity'] : 1));
  40. if (is_numeric($entity)) {
  41. define("DOLENTITY", $entity);
  42. }
  43. // Load Dolibarr environment
  44. require '../../main.inc.php';
  45. require_once DOL_DOCUMENT_ROOT.'/ticket/class/actions_ticket.class.php';
  46. require_once DOL_DOCUMENT_ROOT.'/core/class/html.formticket.class.php';
  47. require_once DOL_DOCUMENT_ROOT.'/core/class/CMailFile.class.php';
  48. require_once DOL_DOCUMENT_ROOT.'/core/lib/ticket.lib.php';
  49. require_once DOL_DOCUMENT_ROOT.'/core/lib/security.lib.php';
  50. require_once DOL_DOCUMENT_ROOT.'/core/lib/company.lib.php';
  51. require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
  52. // Load translation files required by the page
  53. $langs->loadLangs(array("companies", "other", "ticket"));
  54. // Get parameters
  55. $action = GETPOST('action', 'aZ09');
  56. $cancel = GETPOST('cancel', 'aZ09');
  57. $track_id = GETPOST('track_id', 'alpha');
  58. $email = GETPOST('email', 'email');
  59. $suffix = "";
  60. if (GETPOST('btn_view_ticket')) {
  61. unset($_SESSION['email_customer']);
  62. }
  63. if (isset($_SESSION['email_customer'])) {
  64. $email = $_SESSION['email_customer'];
  65. }
  66. $object = new ActionsTicket($db);
  67. if (!isModEnabled('ticket')) {
  68. httponly_accessforbidden('Module Ticket not enabled');
  69. }
  70. /*
  71. * Actions
  72. */
  73. if ($cancel) {
  74. $backtopage = DOL_URL_ROOT.'/public/ticket/index.php';
  75. if (!empty($backtopage)) {
  76. header("Location: ".$backtopage);
  77. exit;
  78. }
  79. $action = 'view_ticket';
  80. }
  81. if ($action == "view_ticket" || $action == "presend" || $action == "close" || $action == "confirm_public_close" || $action == "add_message") {
  82. $error = 0;
  83. $display_ticket = false;
  84. if (!strlen($track_id)) {
  85. $error++;
  86. array_push($object->errors, $langs->trans("ErrorFieldRequired", $langs->transnoentities("TicketTrackId")));
  87. $action = '';
  88. }
  89. if (!strlen($email)) {
  90. $error++;
  91. array_push($object->errors, $langs->trans("ErrorFieldRequired", $langs->transnoentities("Email")));
  92. $action = '';
  93. } else {
  94. if (!isValidEmail($email)) {
  95. $error++;
  96. array_push($object->errors, $langs->trans("ErrorEmailInvalid"));
  97. $action = '';
  98. }
  99. }
  100. if (!$error) {
  101. $ret = $object->fetch('', '', $track_id);
  102. if ($ret && $object->dao->id > 0) {
  103. // Check if emails provided is the one of author
  104. $emailofticket = CMailFile::getValidAddress($object->dao->origin_email, 2);
  105. if (strtolower($emailofticket) == strtolower($email)) {
  106. $display_ticket = true;
  107. $_SESSION['email_customer'] = $email;
  108. } else {
  109. // Check if emails provided is inside list of contacts
  110. $contacts = $object->dao->liste_contact(-1, 'external');
  111. foreach ($contacts as $contact) {
  112. if (strtolower($contact['email']) == strtolower($email)) {
  113. $display_ticket = true;
  114. $_SESSION['email_customer'] = $email;
  115. break;
  116. } else {
  117. $display_ticket = false;
  118. }
  119. }
  120. }
  121. // Check email of thirdparty of ticket
  122. if ($object->dao->fk_soc > 0 || $object->dao->socid > 0) {
  123. $object->dao->fetch_thirdparty();
  124. if ($email == $object->dao->thirdparty->email) {
  125. $display_ticket = true;
  126. $_SESSION['email_customer'] = $email;
  127. }
  128. }
  129. // Check if email is email of creator
  130. if ($object->dao->fk_user_create > 0) {
  131. $tmpuser = new User($db);
  132. $tmpuser->fetch($object->dao->fk_user_create);
  133. if (strtolower($email) == strtolower($tmpuser->email)) {
  134. $display_ticket = true;
  135. $_SESSION['email_customer'] = $email;
  136. }
  137. }
  138. // Check if email is email of creator
  139. if ($object->dao->fk_user_assign > 0 && $object->dao->fk_user_assign != $object->dao->fk_user_create) {
  140. $tmpuser = new User($db);
  141. $tmpuser->fetch($object->dao->fk_user_assign);
  142. if (strtolower($email) == strtolower($tmpuser->email)) {
  143. $display_ticket = true;
  144. $_SESSION['email_customer'] = $email;
  145. }
  146. }
  147. } else {
  148. $error++;
  149. array_push($object->errors, $langs->trans("ErrorTicketNotFound", $track_id));
  150. $action = '';
  151. }
  152. }
  153. if (!$error && $action == 'confirm_public_close' && $display_ticket) {
  154. if ($object->dao->close($user)) {
  155. setEventMessages($langs->trans('TicketMarkedAsClosed'), null, 'mesgs');
  156. $url = 'view.php?action=view_ticket&track_id='.GETPOST('track_id', 'alpha').(!empty($entity) && isModEnabled('multicompany')?'&entity='.$entity:'');
  157. header("Location: ".$url);
  158. exit;
  159. } else {
  160. $action = '';
  161. setEventMessages($object->error, $object->errors, 'errors');
  162. }
  163. }
  164. if (!$error && $action == "add_message" && $display_ticket && GETPOSTISSET('btn_add_message')) {
  165. // TODO Add message...
  166. $ret = $object->dao->newMessage($user, $action, 0, 1);
  167. if (!$error) {
  168. $action = 'view_ticket';
  169. }
  170. }
  171. if ($error || $errors) {
  172. setEventMessages($object->error, $object->errors, 'errors');
  173. if ($action == "add_message") {
  174. $action = 'presend';
  175. } else {
  176. $action = '';
  177. }
  178. }
  179. }
  180. //var_dump($action);
  181. //$object->doActions($action);
  182. // Actions to send emails (for ticket, we need to manage the addfile and removefile only)
  183. $triggersendname = 'TICKET_SENTBYMAIL';
  184. $paramname = 'id';
  185. $autocopy = 'MAIN_MAIL_AUTOCOPY_TICKET_TO'; // used to know the automatic BCC to add
  186. if (!empty($object->id)) $trackid = 'tic'.$object->id;
  187. include DOL_DOCUMENT_ROOT.'/core/actions_sendmails.inc.php';
  188. /*
  189. * View
  190. */
  191. $form = new Form($db);
  192. $formticket = new FormTicket($db);
  193. if (!$conf->global->TICKET_ENABLE_PUBLIC_INTERFACE) {
  194. print '<div class="error">'.$langs->trans('TicketPublicInterfaceForbidden').'</div>';
  195. $db->close();
  196. exit();
  197. }
  198. $arrayofjs = array();
  199. $arrayofcss = array('/ticket/css/styles.css.php');
  200. llxHeaderTicket($langs->trans("Tickets"), "", 0, 0, $arrayofjs, $arrayofcss);
  201. print '<div class="ticketpublicarea">';
  202. if ($action == "view_ticket" || $action == "presend" || $action == "close" || $action == "confirm_public_close") {
  203. if ($display_ticket) {
  204. // Confirmation close
  205. if ($action == 'close') {
  206. print $form->formconfirm($_SERVER["PHP_SELF"]."?track_id=".$track_id.(!empty($entity) && isModEnabled('multicompany')?'&entity='.$entity:''), $langs->trans("CloseATicket"), $langs->trans("ConfirmCloseAticket"), "confirm_public_close", '', '', 1);
  207. }
  208. print '<div id="form_view_ticket" class="margintoponly">';
  209. print '<table class="ticketpublictable centpercent tableforfield">';
  210. // Ref
  211. print '<tr><td class="titlefield">'.$langs->trans("Ref").'</td><td>';
  212. print img_picto('', 'ticket', 'class="pictofixedwidth"');
  213. print dol_escape_htmltag($object->dao->ref);
  214. print '</td></tr>';
  215. // Tracking ID
  216. print '<tr><td>'.$langs->trans("TicketTrackId").'</td><td>';
  217. print dol_escape_htmltag($object->dao->track_id);
  218. print '</td></tr>';
  219. // Subject
  220. print '<tr><td>'.$langs->trans("Subject").'</td><td>';
  221. print '<span class="bold">';
  222. print dol_escape_htmltag($object->dao->subject);
  223. print '</span>';
  224. print '</td></tr>';
  225. // Statut
  226. print '<tr><td>'.$langs->trans("Status").'</td><td>';
  227. print $object->dao->getLibStatut(2);
  228. print '</td></tr>';
  229. // Type
  230. print '<tr><td>'.$langs->trans("Type").'</td><td>';
  231. print dol_escape_htmltag($object->dao->type_label);
  232. print '</td></tr>';
  233. // Category
  234. print '<tr><td>'.$langs->trans("Category").'</td><td>';
  235. if ($object->dao->category_label) {
  236. print img_picto('', 'category', 'class="pictofixedwidth"');
  237. print dol_escape_htmltag($object->dao->category_label);
  238. }
  239. print '</td></tr>';
  240. // Severity
  241. print '<tr><td>'.$langs->trans("Severity").'</td><td>';
  242. print dol_escape_htmltag($object->dao->severity_label);
  243. print '</td></tr>';
  244. // Creation date
  245. print '<tr><td>'.$langs->trans("DateCreation").'</td><td>';
  246. print dol_print_date($object->dao->datec, 'dayhour');
  247. print '</td></tr>';
  248. // Author
  249. print '<tr><td>'.$langs->trans("Author").'</td><td>';
  250. if ($object->dao->fk_user_create > 0) {
  251. $langs->load("users");
  252. $fuser = new User($db);
  253. $fuser->fetch($object->dao->fk_user_create);
  254. print img_picto('', 'user', 'class="pictofixedwidth"');
  255. print $fuser->getFullName($langs);
  256. } else {
  257. print img_picto('', 'email', 'class="pictofixedwidth"');
  258. print dol_escape_htmltag($object->dao->origin_email);
  259. }
  260. print '</td></tr>';
  261. // Read date
  262. if (!empty($object->dao->date_read)) {
  263. print '<tr><td>'.$langs->trans("TicketReadOn").'</td><td>';
  264. print dol_print_date($object->dao->date_read, 'dayhour');
  265. print '</td></tr>';
  266. }
  267. // Close date
  268. if (!empty($object->dao->date_close)) {
  269. print '<tr><td>'.$langs->trans("TicketCloseOn").'</td><td>';
  270. print dol_print_date($object->dao->date_close, 'dayhour');
  271. print '</td></tr>';
  272. }
  273. // User assigned
  274. print '<tr><td>'.$langs->trans("AssignedTo").'</td><td>';
  275. if ($object->dao->fk_user_assign > 0) {
  276. $fuser = new User($db);
  277. $fuser->fetch($object->dao->fk_user_assign);
  278. print img_picto('', 'user', 'class="pictofixedwidth"');
  279. print $fuser->getFullName($langs, 1);
  280. }
  281. print '</td></tr>';
  282. // Progression
  283. print '<tr><td>'.$langs->trans("Progression").'</td><td>';
  284. print ($object->dao->progress > 0 ? dol_escape_htmltag($object->dao->progress) : '0').'%';
  285. print '</td></tr>';
  286. print '</table>';
  287. print '</div>';
  288. print '<div style="clear: both; margin-top: 1.5em;"></div>';
  289. if ($action == 'presend') {
  290. print load_fiche_titre($langs->trans('TicketAddMessage'), '', 'conversation');
  291. $formticket = new FormTicket($db);
  292. $formticket->action = "add_message";
  293. $formticket->track_id = $object->dao->track_id;
  294. $formticket->id = $object->dao->id;
  295. $formticket->param = array('track_id' => $object->dao->track_id, 'fk_user_create' => '-1',
  296. 'returnurl' => DOL_URL_ROOT.'/public/ticket/view.php'.(!empty($entity) && isModEnabled('multicompany')?'?entity='.$entity:''));
  297. $formticket->withfile = 2;
  298. $formticket->withcancel = 1;
  299. $formticket->showMessageForm('100%');
  300. }
  301. if ($action != 'presend') {
  302. print '<form method="post" id="form_view_ticket_list" name="form_view_ticket_list" action="'.DOL_URL_ROOT.'/public/ticket/list.php'.(!empty($entity) && isModEnabled('multicompany')?'?entity='.$entity:'').'">';
  303. print '<input type="hidden" name="token" value="'.newToken().'">';
  304. print '<input type="hidden" name="action" value="view_ticketlist">';
  305. print '<input type="hidden" name="track_id" value="'.$object->dao->track_id.'">';
  306. print '<input type="hidden" name="email" value="'.$_SESSION['email_customer'].'">';
  307. //print '<input type="hidden" name="search_fk_status" value="non_closed">';
  308. print "</form>\n";
  309. print '<div class="tabsAction">';
  310. // List ticket
  311. print '<div class="inline-block divButAction"><a class="left" style="padding-right: 50px" href="javascript:$(\'#form_view_ticket_list\').submit();">'.$langs->trans('ViewMyTicketList').'</a></div>';
  312. if ($object->dao->fk_statut < Ticket::STATUS_CLOSED) {
  313. // New message
  314. print '<div class="inline-block divButAction"><a class="butAction" href="'.$_SERVER['PHP_SELF'].'?action=presend&mode=init&track_id='.$object->dao->track_id.(!empty($entity) && isModEnabled('multicompany')?'&entity='.$entity:'').'">'.$langs->trans('TicketAddMessage').'</a></div>';
  315. // Close ticket
  316. if ($object->dao->fk_statut >= Ticket::STATUS_NOT_READ && $object->dao->fk_statut < Ticket::STATUS_CLOSED) {
  317. print '<div class="inline-block divButAction"><a class="butAction" href="'.$_SERVER['PHP_SELF'].'?action=close&token='.newToken().'&track_id='.$object->dao->track_id.(!empty($entity) && isModEnabled('multicompany')?'&entity='.$entity:'').'">'.$langs->trans('CloseTicket').'</a></div>';
  318. }
  319. }
  320. print '</div>';
  321. }
  322. // Message list
  323. print load_fiche_titre($langs->trans('TicketMessagesList'), '', 'conversation');
  324. $object->viewTicketMessages(false, true, $object->dao);
  325. } else {
  326. print '<div class="error">Not Allowed<br><a href="'.$_SERVER['PHP_SELF'].'?track_id='.$object->dao->track_id.(!empty($entity) && isModEnabled('multicompany')?'?entity='.$entity:'').'" rel="nofollow noopener">'.$langs->trans('Back').'</a></div>';
  327. }
  328. } else {
  329. print '<div class="center opacitymedium margintoponly marginbottomonly">'.$langs->trans("TicketPublicMsgViewLogIn").'</div>';
  330. print '<div id="form_view_ticket">';
  331. print '<form method="post" name="form_view_ticket" action="'.$_SERVER['PHP_SELF'].(!empty($entity) && isModEnabled('multicompany')?'?entity='.$entity:'').'">';
  332. print '<input type="hidden" name="token" value="'.newToken().'">';
  333. print '<input type="hidden" name="action" value="view_ticket">';
  334. print '<p><label for="track_id" style="display: inline-block; width: 30%; "><span class="fieldrequired">'.$langs->trans("TicketTrackId").'</span></label>';
  335. print '<input size="30" id="track_id" name="track_id" value="'.(GETPOST('track_id', 'alpha') ? GETPOST('track_id', 'alpha') : '').'" />';
  336. print '</p>';
  337. print '<p><label for="email" style="display: inline-block; width: 30%; "><span class="fieldrequired">'.$langs->trans('Email').'</span></label>';
  338. print '<input size="30" id="email" name="email" value="'.(GETPOST('email', 'alpha') ? GETPOST('email', 'alpha') : (!empty($_SESSION['customer_email']) ? $_SESSION['customer_email'] : "")).'" />';
  339. print '</p>';
  340. print '<p style="text-align: center; margin-top: 1.5em;">';
  341. print '<input type="submit" class="button" name="btn_view_ticket" value="'.$langs->trans('ViewTicket').'" />';
  342. print ' &nbsp; ';
  343. print '<input type="submit" class="button button-cancel" name="cancel" value="'.$langs->trans("Cancel").'">';
  344. print "</p>\n";
  345. print "</form>\n";
  346. print "</div>\n";
  347. }
  348. print "</div>";
  349. // End of page
  350. htmlPrintOnlinePaymentFooter($mysoc, $langs, 0, $suffix, $object);
  351. llxFooter('', 'public');
  352. $db->close();