From 2cb1563f63386b35a69e460051aa9b4a2851d104 Mon Sep 17 00:00:00 2001
From: ftimme <ft@falkotimme.com>
Date: Wed, 30 May 2012 07:30:44 -0400
Subject: [PATCH] - Added (clickable) placeholders to client messaging function. - Added check so that the client password isn't inserted into the message (for security reasons).

---
 interface/web/dns/dns_wizard.php |   90 +++++++++++++++++++++++++++++++++++---------
 1 files changed, 71 insertions(+), 19 deletions(-)

diff --git a/interface/web/dns/dns_wizard.php b/interface/web/dns/dns_wizard.php
index 64a5736..cdb2448 100644
--- a/interface/web/dns/dns_wizard.php
+++ b/interface/web/dns/dns_wizard.php
@@ -39,6 +39,7 @@
 $app->uses('tpl,validate_dns');
 $app->tpl->newTemplate("form.tpl.htm");
 $app->tpl->setInclude('content_tpl','templates/dns_wizard.htm');
+$app->load_language_file('/web/dns/lib/lang/'.$_SESSION['s']['language'].'_dns_wizard.lng');
 
 // import variables
 $template_id = (isset($_POST['template_id']))?intval($_POST['template_id']):0;
@@ -71,7 +72,7 @@
 if($_SESSION['s']['user']['typ'] == 'admin') {
 	
 	// Load the list of servers
-	$records = $app->db->queryAllRecords("SELECT server_id, server_name FROM server WHERE dns_server = 1 ORDER BY server_name");
+	$records = $app->db->queryAllRecords("SELECT server_id, server_name FROM server WHERE mirror_server_id = 0 AND dns_server = 1 ORDER BY server_name");
 	$server_id_option = '';
 	foreach($records as $rec){
 		$checked = ($rec['server_id'] == $server_id)?' SELECTED':'';
@@ -80,20 +81,42 @@
 	$app->tpl->setVar("server_id",$server_id_option);
 	
 	// load the list of clients
-	$sql = "SELECT groupid, name FROM sys_group WHERE client_id > 0";
+	$sql = "SELECT sys_group.groupid, sys_group.name, CONCAT(client.company_name,' :: ',client.contact_name) as contactname FROM sys_group, client WHERE sys_group.client_id = client.client_id AND sys_group.client_id > 0 ORDER BY sys_group.name";
 	$clients = $app->db->queryAllRecords($sql);
 	$client_select = '';
 	if($_SESSION["s"]["user"]["typ"] == 'admin') $client_select .= "<option value='0'></option>";
 	if(is_array($clients)) {
 		foreach( $clients as $client) {
 			$selected = ($client["groupid"] == $sys_groupid)?'SELECTED':'';
-			$client_select .= "<option value='$client[groupid]' $selected>$client[name]</option>\r\n";
+			$client_select .= "<option value='$client[groupid]' $selected>$client[name] :: $client[contactname]</option>\r\n";
 		}
 	}
 
 	$app->tpl->setVar("client_group_id",$client_select);
-	
 }
+
+if ($_SESSION["s"]["user"]["typ"] != 'admin' && $app->auth->has_clients($_SESSION['s']['user']['userid'])) {
+	
+	// Get the limits of the client
+	$client_group_id = $_SESSION["s"]["user"]["default_group"];
+	$client = $app->db->queryOneRecord("SELECT client.client_id, client.contact_name, CONCAT(client.company_name,' :: ',client.contact_name) as contactname, sys_group.name FROM sys_group, client WHERE sys_group.client_id = client.client_id and sys_group.groupid = $client_group_id");
+
+	
+	// load the list of clients
+	$sql = "SELECT sys_group.groupid, sys_group.name, CONCAT(client.company_name,' :: ',client.contact_name) as contactname FROM sys_group, client WHERE sys_group.client_id = client.client_id AND client.parent_client_id = ".$client['client_id'];
+	$clients = $app->db->queryAllRecords($sql);
+	$tmp = $app->db->queryOneRecord("SELECT groupid FROM sys_group WHERE client_id = ".$client['client_id']);
+	$client_select = '<option value="'.$tmp['groupid'].'">'.$client['name'].' :: '.$client['contactname'].'</option>';
+	if(is_array($clients)) {
+		foreach( $clients as $client) {
+			$selected = ($client["groupid"] == $sys_groupid)?'SELECTED':'';
+			$client_select .= "<option value='$client[groupid]' $selected>$client[name] :: $client[contactname]</option>\r\n";
+		}
+	}
+
+	$app->tpl->setVar("client_group_id",$client_select);
+}
+
 
 $template_record = $app->db->queryOneRecord("SELECT * FROM dns_template WHERE template_id = '$template_id'");
 $fields = explode(',',$template_record['fields']);
@@ -109,11 +132,38 @@
 	
 	$error = '';
 	
-	if(isset($_POST['domain']) && $_POST['domain'] == '') $error .= $app->lng('error_domain_empty');
-	if(isset($_POST['ip']) && $_POST['ip'] == '') $error .= $app->lng('error_ip_empty');
-	if(isset($_POST['ns1']) && $_POST['ns1'] == '') $error .= $app->lng('error_ns1_empty');
-	if(isset($_POST['ns2']) && $_POST['ns2'] == '') $error .= $app->lng('error_ns2_empty');
-	if(isset($_POST['email']) && $_POST['email'] == '') $error .= $app->lng('error_email_empty');
+	if(isset($_POST['domain']) && $_POST['domain'] == '') $error .= $app->lng('error_domain_empty').'<br />';
+	if(isset($_POST['ip']) && $_POST['ip'] == '') $error .= $app->lng('error_ip_empty').'<br />';
+	if(isset($_POST['ns1']) && $_POST['ns1'] == '') $error .= $app->lng('error_ns1_empty').'<br />';
+	if(isset($_POST['ns2']) && $_POST['ns2'] == '') $error .= $app->lng('error_ns2_empty').'<br />';
+	if(isset($_POST['email']) && $_POST['email'] == '') $error .= $app->lng('error_email_empty').'<br />';
+	
+	if(isset($_POST['domain']) && !preg_match('/^[\w\.\-]{2,64}\.[a-zA-Z0-9\-]{2,30}[\.]{0,1}$/',$_POST['domain'])) $error .= $app->lng('error_domain_regex').'<br />';
+	if(isset($_POST['ns1']) && !preg_match('/^[\w\.\-]{2,64}\.[a-zA-Z0-9]{2,30}[\.]{0,1}$/',$_POST['ns1'])) $error .= $app->lng('error_ns1_regex').'<br />';
+	if(isset($_POST['ns2']) && !preg_match('/^[\w\.\-]{2,64}\.[a-zA-Z0-9]{2,30}[\.]{0,1}$/',$_POST['ns2'])) $error .= $app->lng('error_ns2_regex').'<br />';
+	if(isset($_POST['email']) && !preg_match('/^\w+[\w.-]*\w+@\w+[\w.-]*\w+\.[a-z0-9\-]{2,30}$/i',$_POST['email'])) $error .= $app->lng('error_email_regex').'<br />';
+	
+	// make sure that the record belongs to the clinet group and not the admin group when a dmin inserts it
+	if($_SESSION["s"]["user"]["typ"] == 'admin' && isset($_POST['client_group_id'])) {
+		$sys_groupid = intval($_POST['client_group_id']);
+	} elseif($app->auth->has_clients($_SESSION['s']['user']['userid']) && isset($_POST['client_group_id'])) {
+		$sys_groupid = intval($_POST['client_group_id']);
+	} else {
+		$sys_groupid = $_SESSION["s"]["user"]["default_group"];
+	}
+	
+	$tform_def_file = "form/dns_soa.tform.php";
+	$app->uses('tform');
+	$app->tform->loadFormDef($tform_def_file);
+	
+	if($_SESSION['s']['user']['typ'] != 'admin') {
+		if(!$app->tform->checkClientLimit('limit_dns_zone')) {
+			$error .= $app->tform->wordbook["limit_dns_zone_txt"];
+		}
+		if(!$app->tform->checkResellerLimit('limit_dns_zone')) {
+			$error .= $app->tform->wordbook["limit_dns_zone_txt"];
+		}
+	}
 	
 	
 	// replace template placeholders
@@ -164,14 +214,14 @@
 		
 	} // end foreach
 	
-	if($vars['origin'] == '') $error .= $app->lng('error_origin_empty');
-	if($vars['ns'] == '') $error .= $app->lng('error_ns_empty');
-	if($vars['mbox'] == '') $error .= $app->lng('error_mbox_empty');
-	if($vars['refresh'] == '') $error .= $app->lng('error_refresh_empty');
-	if($vars['retry'] == '') $error .= $app->lng('error_retry_empty');
-	if($vars['expire'] == '') $error .= $app->lng('error_expire_empty');
-	if($vars['minimum'] == '') $error .= $app->lng('error_minimum_empty');
-	if($vars['ttl'] == '') $error .= $app->lng('error_ttl_empty');
+	if($vars['origin'] == '') $error .= $app->lng('error_origin_empty').'<br />';
+	if($vars['ns'] == '') $error .= $app->lng('error_ns_empty').'<br />';
+	if($vars['mbox'] == '') $error .= $app->lng('error_mbox_empty').'<br />';
+	if($vars['refresh'] == '') $error .= $app->lng('error_refresh_empty').'<br />';
+	if($vars['retry'] == '') $error .= $app->lng('error_retry_empty').'<br />';
+	if($vars['expire'] == '') $error .= $app->lng('error_expire_empty').'<br />';
+	if($vars['minimum'] == '') $error .= $app->lng('error_minimum_empty').'<br />';
+	if($vars['ttl'] == '') $error .= $app->lng('error_ttl_empty').'<br />';
 	
 	if($error == '') {
 		// Insert the soa record
@@ -185,10 +235,12 @@
 		$minimum = $app->db->quote($vars['minimum']);
 		$ttl = $app->db->quote($vars['ttl']);
 		$xfer = $app->db->quote($vars['xfer']);
+		$also_notify = $app->db->quote($vars['also_notify']);
+		$update_acl = $app->db->quote($vars['update_acl']);
 		$serial = $app->validate_dns->increase_serial(0);
 		
-		$insert_data = "(`sys_userid`, `sys_groupid`, `sys_perm_user`, `sys_perm_group`, `sys_perm_other`, `server_id`, `origin`, `ns`, `mbox`, `serial`, `refresh`, `retry`, `expire`, `minimum`, `ttl`, `active`, `xfer`) VALUES 
-		('$sys_userid', '$sys_groupid', 'riud', 'riud', '', '$server_id', '$origin', '$ns', '$mbox', '$serial', '$refresh', '$retry', '$expire', '$minimum', '$ttl', 'Y', '$xfer')";
+		$insert_data = "(`sys_userid`, `sys_groupid`, `sys_perm_user`, `sys_perm_group`, `sys_perm_other`, `server_id`, `origin`, `ns`, `mbox`, `serial`, `refresh`, `retry`, `expire`, `minimum`, `ttl`, `active`, `xfer`, `also_notify`, `update_acl`) VALUES 
+		('$sys_userid', '$sys_groupid', 'riud', 'riud', '', '$server_id', '$origin', '$ns', '$mbox', '$serial', '$refresh', '$retry', '$expire', '$minimum', '$ttl', 'Y', '$xfer', '$also_notify', '$update_acl')";
 		$dns_soa_id = $app->db->datalogInsert('dns_soa', $insert_data, 'id');
 		
 		// Insert the dns_rr records

--
Gitblit v1.9.1