index.php 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205
  1. <?php
  2. /* For licensing terms, see /license.txt */
  3. /**
  4. * @package chamilo.main
  5. */
  6. use \ChamiloSession as Session;
  7. define('CHAMILO_HOMEPAGE', true);
  8. $language_file = array('courses', 'index', 'userInfo');
  9. /* Flag forcing the 'current course' reset, as we're not inside a course anymore. */
  10. // Maybe we should change this into an api function? an example: CourseManager::unset();
  11. $cidReset = true;
  12. require_once 'main/inc/global.inc.php';
  13. require_once api_get_path(LIBRARY_PATH).'userportal.lib.php';
  14. require_once 'main/chat/chat_functions.lib.php';
  15. require_once 'main/auth/external_login/facebook.inc.php';
  16. // The section (for the tabs).
  17. $this_section = SECTION_CAMPUS;
  18. $header_title = null;
  19. if (!api_is_anonymous()) {
  20. $header_title = " ";
  21. }
  22. $htmlHeadXtra[] = api_get_jquery_libraries_js(array('bxslider'));
  23. $htmlHeadXtra[] ='
  24. <script type="text/javascript">
  25. $(document).ready(function(){
  26. $("#slider").bxSlider({
  27. infiniteLoop : true,
  28. auto : true,
  29. pager : true,
  30. autoHover : true,
  31. pause : 10000
  32. });
  33. });
  34. </script>';
  35. // Facebook connexion, if activated
  36. if (api_is_facebook_auth_activated() && !api_get_user_id()) {
  37. facebookConnect();
  38. }
  39. $controller = new IndexManager($header_title);
  40. //Actions
  41. $loginFailed = isset($_GET['loginFailed']) ? true : isset($loginFailed);
  42. if (!empty($_GET['logout'])) {
  43. $controller->logout();
  44. }
  45. /* Table definitions */
  46. /* Constants and CONFIGURATION parameters */
  47. /** @todo these configuration settings should move to the Chamilo config settings. */
  48. /** Defines wether or not anonymous visitors can see a list of the courses on the Chamilo homepage that are open to the world. */
  49. $_setting['display_courses_to_anonymous_users'] = 'true';
  50. /* LOGIN */
  51. /**
  52. * Registers in the track_e_default table (view in important activities in admin
  53. * interface) a possible attempted break in, sending auth data through get.
  54. * @todo This piece of code should probably move to local.inc.php where the actual login / logout procedure is handled. The real use of this code block should be seriously considered as well. This form should just use a security token and get done with it.
  55. */
  56. if (isset($_GET['submitAuth']) && $_GET['submitAuth'] == 1) {
  57. $i = api_get_anonymous_id();
  58. event_system(LOG_ATTEMPTED_FORCED_LOGIN, 'tried_hacking_get', $_SERVER['REMOTE_ADDR'].(empty($_POST['login'])?'':'/'.$_POST['login']),null,$i);
  59. echo 'Attempted breakin - sysadmins notified.';
  60. session_destroy();
  61. die();
  62. }
  63. // Delete session neccesary for legal terms
  64. if (api_get_setting('allow_terms_conditions') == 'true') {
  65. unset($_SESSION['term_and_condition']);
  66. }
  67. //If we are not logged in and customapages activated
  68. if (!api_get_user_id() && CustomPages::enabled()) {
  69. if (Request::get('loggedout')) {
  70. CustomPages::display(CustomPages::LOGGED_OUT);
  71. } else {
  72. CustomPages::display(CustomPages::INDEX_UNLOGGED);
  73. }
  74. }
  75. /**
  76. * @todo This piece of code should probably move to local.inc.php where the actual login procedure is handled.
  77. * @todo Check if this code is used. I think this code is never executed because after clicking the submit button
  78. * the code does the stuff in local.inc.php and then redirects to index.php or user_portal.php depending
  79. * on api_get_setting('page_after_login').
  80. */
  81. if (!empty($_POST['submitAuth'])) {
  82. // The user has been already authenticated, we are now to find the last login of the user.
  83. if (isset ($_user['user_id'])) {
  84. $track_login_table = Database :: get_statistic_table(TABLE_STATISTIC_TRACK_E_LOGIN);
  85. $sql_last_login = "SELECT UNIX_TIMESTAMP(login_date)
  86. FROM $track_login_table
  87. WHERE login_user_id = '".$_user['user_id']."'
  88. ORDER BY login_date DESC LIMIT 1";
  89. $result_last_login = Database::query($sql_last_login);
  90. if (!$result_last_login) {
  91. if (Database::num_rows($result_last_login) > 0) {
  92. $user_last_login_datetime = Database::fetch_array($result_last_login);
  93. $user_last_login_datetime = $user_last_login_datetime[0];
  94. Session::write('user_last_login_datetime',$user_last_login_datetime);
  95. }
  96. }
  97. Database::free_result($result_last_login);
  98. //event_login();
  99. if (api_is_platform_admin()) {
  100. // decode all open event informations and fill the track_c_* tables
  101. include api_get_path(LIBRARY_PATH).'stats.lib.inc.php';
  102. decodeOpenInfos();
  103. }
  104. }
  105. // End login -- if ($_POST['submitAuth'])
  106. } else {
  107. // Only if login form was not sent because if the form is sent the user was already on the page.
  108. event_open();
  109. }
  110. if (api_get_setting('display_categories_on_homepage') == 'true') {
  111. $controller->tpl->assign('course_category_block', $controller->return_courses_in_categories());
  112. }
  113. $controller->set_login_form();
  114. //@todo move this inside the IndexManager
  115. if (!api_is_anonymous()) {
  116. $controller->tpl->assign('profile_block', $controller->return_profile_block());
  117. $controller->tpl->assign('user_image_block', $controller->return_user_image_block());
  118. if (api_is_platform_admin()) {
  119. $controller->tpl->assign('course_block', $controller->return_course_block());
  120. } else {
  121. $controller->tpl->assign('teacher_block', $controller->return_teacher_link());
  122. }
  123. }
  124. $hot_courses = null;
  125. $announcements_block = null;
  126. // Display the Site Use Cookie Warning Validation
  127. $useCookieValidation = api_get_configuration_value('cookie_warning');
  128. if ($useCookieValidation) {
  129. if (isset($_POST['acceptCookies'])) {
  130. api_set_site_use_cookie_warning_cookie();
  131. } else if (!api_site_use_cookie_warning_cookie_exist()) {
  132. if (Template::isToolBarDisplayedForUser()) {
  133. $controller->tpl->assign('toolBarDisplayed', true);
  134. } else {
  135. $controller->tpl->assign('toolBarDisplayed', false);
  136. }
  137. $controller->tpl->assign('displayCookieUsageWarning', true);
  138. }
  139. }
  140. // When loading a chamilo page do not include the hot courses and news
  141. if (!isset($_REQUEST['include'])) {
  142. if (api_get_setting('show_hot_courses') == 'true') {
  143. $hot_courses = $controller->return_hot_courses();
  144. }
  145. $announcements_block = $controller->return_announcements();
  146. }
  147. $controller->tpl->assign('hot_courses', $hot_courses);
  148. $controller->tpl->assign('announcements_block', $announcements_block);
  149. $controller->tpl->assign('home_page_block', $controller->return_home_page());
  150. $controller->tpl->assign('navigation_course_links', $controller->return_navigation_links());
  151. $controller->tpl->assign('notice_block', $controller->return_notice());
  152. $controller->tpl->assign('main_navigation_block', $controller->return_navigation_links());
  153. $controller->tpl->assign('help_block', $controller->return_help());
  154. if (api_is_platform_admin() || api_is_drh()) {
  155. $controller->tpl->assign('skills_block', $controller->return_skills_links());
  156. }
  157. if (api_is_anonymous()) {
  158. $controller->tpl->setLoginBodyClass();
  159. }
  160. // direct login to course
  161. if (isset($_GET['firstpage'])) {
  162. api_set_firstpage_parameter($_GET['firstpage']);
  163. // if we are already logged, go directly to course
  164. if (api_user_is_login()) {
  165. echo "<script type='text/javascript'>self.location.href='index.php?firstpage=".Security::remove_XSS($_GET['firstpage'])."'</script>";
  166. }
  167. } else {
  168. api_delete_firstpage_parameter();
  169. }
  170. $controller->tpl->display_two_col_template();