settings.php 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553
  1. <?php
  2. /* For licensing terms, see /license.txt */
  3. /**
  4. * With this tool you can easily adjust non critical configuration settings.
  5. * Non critical means that changing them will not result in a broken campus.
  6. *
  7. * @author Patrick Cool
  8. * @author Julio Montoya - Multiple URL site
  9. * @package chamilo.admin
  10. */
  11. // Resetting the course id.
  12. $cidReset = true;
  13. // Including some necessary library files.
  14. require_once 'settings.lib.php';
  15. // Setting the section (for the tabs).
  16. $this_section = SECTION_PLATFORM_ADMIN;
  17. $_SESSION['this_section'] = $this_section;
  18. // Access restrictions.
  19. api_protect_admin_script();
  20. // Settings to avoid
  21. $settings_to_avoid = array(
  22. 'stylesheets' => '', // handled by the handle_stylesheet() function
  23. 'server_type' => '',
  24. 'use_session_mode' => 'true',
  25. 'gradebook_enable' => 'false',
  26. 'example_material_course_creation' => 'true' // ON by default - now we have this option when we create a course
  27. );
  28. $convert_byte_to_mega_list = array(
  29. 'dropbox_max_filesize',
  30. 'message_max_upload_filesize',
  31. 'default_document_quotum',
  32. 'default_group_quotum'
  33. );
  34. // Database table definitions.
  35. $table_settings_current = Database :: get_main_table(TABLE_MAIN_SETTINGS_CURRENT);
  36. // Setting breadcrumbs.
  37. $interbreadcrumb[] = array('url' => 'index.php', 'name' => get_lang('PlatformAdmin'));
  38. // Setting the name of the tool.
  39. $tool_name = get_lang('PlatformConfigSettings');
  40. if (empty($_GET['category'])) {
  41. $_GET['category'] = 'Platform';
  42. }
  43. $watermark_deleted = false;
  44. if (isset($_GET['delete_watermark'])) {
  45. $watermark_deleted = PDF::delete_watermark();
  46. }
  47. if (isset($_GET['action']) && $_GET['action'] == 'delete_grading') {
  48. $id = intval($_GET['id']);
  49. api_delete_setting_option($id);
  50. }
  51. $keyword = isset($_REQUEST['keyword']) ? $_REQUEST['keyword'] : null;
  52. $form_search = new FormValidator('search_settings', 'get', api_get_self(), null, array('class' => 'form-search'));
  53. $form_search->addElement('text', 'keyword');
  54. $form_search->addElement('hidden', 'category', 'search_setting');
  55. $form_search->addElement(
  56. 'style_submit_button',
  57. 'submit_button',
  58. get_lang('Search'),
  59. array('class' => 'search')
  60. );
  61. $form_search->setDefaults(
  62. array('keyword' => $keyword)
  63. );
  64. $form_search_html = $form_search->return_form();
  65. $url_id = api_get_current_access_url_id();
  66. $settings = null;
  67. /**
  68. * @param string $category
  69. * @param string $keyword
  70. * @return array
  71. */
  72. function get_settings($category = null, $keyword = null)
  73. {
  74. $url_id = api_get_current_access_url_id();
  75. $settings_by_access_list = array();
  76. if ($url_id == 1) {
  77. $settings = api_get_settings($category, 'group', $url_id);
  78. } else {
  79. $url_info = api_get_access_url($url_id);
  80. if ($url_info['active'] == 1) {
  81. // The default settings of Chamilo
  82. $settings = api_get_settings($category, 'group', 1, 0);
  83. // The settings that are changeable from a particular site.
  84. $settings_by_access = api_get_settings($category, 'group', $url_id, 1);
  85. foreach ($settings_by_access as $row) {
  86. if (empty($row['variable'])) {
  87. $row['variable'] = 0;
  88. }
  89. if (empty($row['subkey'])) {
  90. $row['subkey'] = 0;
  91. }
  92. if (empty($row['category'])) {
  93. $row['category'] = 0;
  94. }
  95. // One more validation if is changeable.
  96. if ($row['access_url_changeable'] == 1) {
  97. $settings_by_access_list[$row['variable']] [$row['subkey']] [$row['category']] = $row;
  98. } else {
  99. $settings_by_access_list[$row['variable']] [$row['subkey']] [$row['category']] = array();
  100. }
  101. }
  102. }
  103. }
  104. if (isset($category) && $category == 'search_setting') {
  105. if (!empty($keyword)) {
  106. $settings = search_setting($keyword);
  107. }
  108. }
  109. return array(
  110. 'settings' => $settings,
  111. 'settings_by_access_list' => $settings_by_access_list
  112. );
  113. }
  114. // Build the form.
  115. if (!empty($_GET['category']) && !in_array($_GET['category'], array('Plugins', 'stylesheets', 'Search'))) {
  116. $my_category = isset($_GET['category']) ? $_GET['category'] : null;
  117. $settings_array = get_settings($my_category, $keyword);
  118. $settings = $settings_array['settings'];
  119. $settings_by_access_list = $settings_array['settings_by_access_list'];
  120. $form = generate_settings_form($settings, $settings_by_access_list, $settings_to_avoid, $convert_byte_to_mega_list);
  121. $message = array();
  122. if ($form->validate()) {
  123. $values = $form->exportValues();
  124. $mark_all = false;
  125. $un_mark_all = false;
  126. if (api_is_multiple_url_enabled()) {
  127. if (isset($values['buttons_in_action_right']) && isset($values['buttons_in_action_right']['mark_all'])) {
  128. $mark_all = true;
  129. }
  130. if (isset($values['buttons_in_action_right']) && isset($values['buttons_in_action_right']['unmark_all'])) {
  131. $un_mark_all = true;
  132. }
  133. }
  134. if ($mark_all || $un_mark_all) {
  135. if (api_is_global_platform_admin()) {
  136. $locked_settings = api_get_locked_settings();
  137. foreach ($values as $key => $value) {
  138. if (!in_array($key, $locked_settings)) {
  139. $changeable = 0;
  140. if ($mark_all) {
  141. $changeable = 1;
  142. }
  143. $params = array('variable = ?' => array($key));
  144. $data = api_get_settings_params($params);
  145. if (!empty($data)) {
  146. foreach ($data as $item) {
  147. $params = array('id' => $item['id'], 'access_url_changeable' => $changeable);
  148. api_set_setting_simple($params);
  149. }
  150. }
  151. }
  152. }
  153. //Reload settings
  154. $settings_array = get_settings($my_category);
  155. $settings = $settings_array['settings'];
  156. $settings_by_access_list = $settings_array['settings_by_access_list'];
  157. $form = generate_settings_form($settings, $settings_by_access_list, $settings_to_avoid, $convert_byte_to_mega_list);
  158. }
  159. }
  160. $pdf_export_watermark_path = isset($_FILES['pdf_export_watermark_path']) ? $_FILES['pdf_export_watermark_path'] : null;
  161. if (isset($pdf_export_watermark_path) && !empty($pdf_export_watermark_path['name'])) {
  162. $pdf_export_watermark_path_result = PDF::upload_watermark(
  163. $pdf_export_watermark_path['name'],
  164. $pdf_export_watermark_path['tmp_name']
  165. );
  166. if ($pdf_export_watermark_path_result) {
  167. $message['confirmation'][] = get_lang('UplUploadSucceeded');
  168. } else {
  169. $message['warning'][] = get_lang('UplUnableToSaveFile').' '.get_lang('Folder').': '.api_get_path(SYS_DEFAULT_COURSE_DOCUMENT_PATH).'/images';
  170. }
  171. unset($update_values['pdf_export_watermark_path']);
  172. }
  173. // Set true for allow_message_tool variable if social tool is actived
  174. foreach ($convert_byte_to_mega_list as $item) {
  175. if (isset($values[$item])) {
  176. $values[$item] = round($values[$item] * 1024 * 1024);
  177. }
  178. }
  179. if (isset($values['allow_social_tool']) && $values['allow_social_tool'] == 'true') {
  180. $values['allow_message_tool'] = 'true';
  181. }
  182. foreach ($settings as $item) {
  183. $key = $item['variable'];
  184. if (in_array($key, $settings_to_avoid)) {
  185. continue;
  186. }
  187. if ($key == 'keyword' or $key == 'submit_fixed_in_bottom') {
  188. continue;
  189. }
  190. $key = Database::escape_string($key);
  191. $sql = "UPDATE $table_settings_current SET selected_value = 'false'
  192. WHERE variable = '".$key."' AND access_url = ".intval($url_id)." AND type IN ('checkbox', 'radio') ";
  193. $res = Database::query($sql);
  194. }
  195. // Save the settings.
  196. $keys = array();
  197. foreach ($values as $key => $value) {
  198. if (in_array($key, $settings_to_avoid)) {
  199. continue;
  200. }
  201. // Avoid form elements which have nothing to do with settings
  202. if ($key == 'keyword' or $key == 'submit_fixed_in_bottom') {
  203. continue;
  204. }
  205. // Treat gradebook values in separate function.
  206. //if (strpos($key, 'gradebook_score_display_custom_values') === false) {
  207. if (!is_array($value)) {
  208. $old_value = api_get_setting($key);
  209. switch ($key) {
  210. case 'header_extra_content':
  211. file_put_contents(
  212. api_get_path(SYS_PATH).api_get_home_path().'/header_extra_content.txt',
  213. $value
  214. );
  215. $value = api_get_home_path().'/header_extra_content.txt';
  216. break;
  217. case 'footer_extra_content':
  218. file_put_contents(
  219. api_get_path(SYS_PATH).api_get_home_path().'/footer_extra_content.txt',
  220. $value
  221. );
  222. $value = api_get_home_path().'/footer_extra_content.txt';
  223. break;
  224. // URL validation for some settings.
  225. case 'InstitutionUrl':
  226. case 'course_validation_terms_and_conditions_url':
  227. $value = trim(Security::remove_XSS($value));
  228. if ($value != '') {
  229. // Here we accept absolute URLs only.
  230. if (strpos($value, '://') === false) {
  231. $value = 'http://'.$value;
  232. }
  233. if (!api_valid_url($value, true)) {
  234. // If the new (non-empty) URL value is invalid, then the old URL value stays.
  235. $value = $old_value;
  236. }
  237. }
  238. // If the new URL value is empty, then it will be stored (i.e. the setting will be deleted).
  239. break;
  240. // Validation against e-mail address for some settings.
  241. case 'emailAdministrator':
  242. $value = trim(Security::remove_XSS($value));
  243. if ($value != '' && !api_valid_email($value)) {
  244. // If the new (non-empty) e-mail address is invalid, then the old e-mail address stays.
  245. // If the new e-mail address is empty, then it will be stored (i.e. the setting will be deleted).
  246. $value = $old_value;
  247. }
  248. break;
  249. }
  250. if ($old_value != $value) {
  251. $keys[] = $key;
  252. }
  253. $result = api_set_setting($key, $value, null, null, $url_id);
  254. } else {
  255. $sql = "SELECT subkey FROM $table_settings_current WHERE variable = '$key'";
  256. $res = Database::query($sql);
  257. while ($row_subkeys = Database::fetch_array($res)) {
  258. // If subkey is changed:
  259. if ((isset($value[$row_subkeys['subkey']]) && api_get_setting(
  260. $key,
  261. $row_subkeys['subkey']
  262. ) == 'false') ||
  263. (!isset($value[$row_subkeys['subkey']]) && api_get_setting(
  264. $key,
  265. $row_subkeys['subkey']
  266. ) == 'true')
  267. ) {
  268. $keys[] = $key;
  269. break;
  270. }
  271. }
  272. foreach ($value as $subkey => $subvalue) {
  273. $result = api_set_setting($key, 'true', $subkey, null, $url_id);
  274. }
  275. }
  276. }
  277. // Add event configuration settings category to the system log.
  278. $user_id = api_get_user_id();
  279. $category = $_GET['category'];
  280. Event::addEvent(
  281. LOG_CONFIGURATION_SETTINGS_CHANGE,
  282. LOG_CONFIGURATION_SETTINGS_CATEGORY,
  283. $category,
  284. api_get_utc_datetime(),
  285. $user_id
  286. );
  287. api_set_setting_last_update();
  288. // Add event configuration settings variable to the system log.
  289. if (is_array($keys) && count($keys) > 0) {
  290. foreach ($keys as $variable) {
  291. if (in_array($key, $settings_to_avoid)) {
  292. continue;
  293. }
  294. Event::addEvent(
  295. LOG_CONFIGURATION_SETTINGS_CHANGE,
  296. LOG_CONFIGURATION_SETTINGS_VARIABLE,
  297. $variable,
  298. api_get_utc_datetime(),
  299. $user_id
  300. );
  301. }
  302. }
  303. }
  304. }
  305. $htmlHeadXtra[] = '<script>
  306. var hide_icon = "'.api_get_path(WEB_IMG_PATH).'shared_setting_na.png";
  307. var show_icon = "'.api_get_path(WEB_IMG_PATH).'shared_setting.png";
  308. var url = "'.api_get_path(WEB_AJAX_PATH).'admin.ajax.php?a=update_changeable_setting";
  309. $(function() {
  310. $(".share_this_setting").on("click", function() {
  311. var my_img = $(this).find("img");
  312. var link = $(this);
  313. $.ajax({
  314. url: url,
  315. data: { changeable: $(this).attr("data_status"), id: $(this).attr("data_to_send") },
  316. success: function(data) {
  317. if (data == 1) {
  318. if (link.attr("data_status") == 1) {
  319. my_img.attr("src", show_icon);
  320. link.attr("data_status", 0);
  321. } else {
  322. my_img.attr("src", hide_icon);
  323. link.attr("data_status", 1);
  324. }
  325. }
  326. }
  327. });
  328. });
  329. });
  330. </script>';
  331. // Including the header (banner).
  332. Display :: display_header($tool_name);
  333. // The action images.
  334. $action_images['platform'] = 'platform.png';
  335. $action_images['admin'] = 'teacher.png';
  336. $action_images['registration'] = 'lock.png';
  337. $action_images['course'] = 'course.png';
  338. $action_images['session'] = 'session.png';
  339. $action_images['tools'] = 'tools.png';
  340. $action_images['user'] = 'user.png';
  341. $action_images['gradebook'] = 'gradebook.png';
  342. $action_images['ldap'] = 'ldap.png';
  343. $action_images['cas'] = 'user_access.png';
  344. $action_images['security'] = 'security.png';
  345. $action_images['languages'] = 'languages.png';
  346. $action_images['tuning'] = 'tuning.png';
  347. $action_images['templates'] = 'template.png';
  348. $action_images['search'] = 'search.png';
  349. $action_images['editor'] = 'html_editor.png';
  350. $action_images['timezones'] = 'timezone.png';
  351. $action_images['extra'] = 'wizard.png';
  352. $action_images['tracking'] = 'statistics.png';
  353. $action_images['gradebook'] = 'gradebook.png';
  354. $action_images['search'] = 'search.png';
  355. $action_images['stylesheets'] = 'stylesheets.png';
  356. $action_images['templates'] = 'template.png';
  357. $action_images['plugins'] = 'plugins.png';
  358. //$action_images['shibboleth'] = 'shibboleth.png';
  359. //$action_images['facebook'] = 'facebook.png';
  360. //$action_images['logtransactions'] = 'tuning.png';
  361. $action_array = array();
  362. $resultcategories = array();
  363. $resultcategories[] = array('category' => 'Platform');
  364. $resultcategories[] = array('category' => 'Admin');
  365. $resultcategories[] = array('category' => 'Registration');
  366. $resultcategories[] = array('category' => 'Course');
  367. $resultcategories[] = array('category' => 'Session');
  368. $resultcategories[] = array('category' => 'Languages');
  369. $resultcategories[] = array('category' => 'User');
  370. $resultcategories[] = array('category' => 'Tools');
  371. $resultcategories[] = array('category' => 'Editor');
  372. $resultcategories[] = array('category' => 'Security');
  373. $resultcategories[] = array('category' => 'Tuning');
  374. $resultcategories[] = array('category' => 'Gradebook');
  375. $resultcategories[] = array('category' => 'Timezones');
  376. $resultcategories[] = array('category' => 'Tracking');
  377. $resultcategories[] = array('category' => 'Search');
  378. $resultcategories[] = array('category' => 'Stylesheets');
  379. $resultcategories[] = array('category' => 'Templates');
  380. $resultcategories[] = array('category' => 'Plugins');
  381. //$resultcategories[] = array('category' => 'LDAP');
  382. //$resultcategories[] = array('category' => 'CAS');
  383. //$resultcategories[] = array('category' => 'Shibboleth');
  384. //$resultcategories[] = array('category' => 'Facebook');
  385. //$resultcategories[] = array('category' => 'LogTransactions');
  386. foreach ($resultcategories as $row) {
  387. $url = array();
  388. $url['url'] = api_get_self()."?category=".$row['category'];
  389. $url['content'] = Display::return_icon(
  390. $action_images[strtolower($row['category'])],
  391. api_ucfirst(get_lang($row['category'])),
  392. '',
  393. ICON_SIZE_MEDIUM
  394. );
  395. if (strtolower($row['category']) == strtolower($_GET['category'])) {
  396. $url['active'] = true;
  397. }
  398. $action_array[] = $url;
  399. }
  400. echo Display::actions($action_array);
  401. echo '<br />';
  402. echo '<div class="well">'.$form_search_html."</div>";
  403. if ($watermark_deleted) {
  404. Display :: display_normal_message(get_lang('FileDeleted'));
  405. }
  406. // Displaying the message that the settings have been stored.
  407. if (isset($form) && $form->validate()) {
  408. Display::display_confirmation_message(get_lang('SettingsStored'));
  409. if (is_array($message)) {
  410. foreach ($message as $type => $content) {
  411. foreach ($content as $msg) {
  412. echo Display::return_message($msg, $type);
  413. }
  414. }
  415. }
  416. }
  417. if (!empty($_GET['category'])) {
  418. switch ($_GET['category']) {
  419. case 'Regions':
  420. handle_regions();
  421. break;
  422. case 'Plugins':
  423. // Displaying the extensions: Plugins.
  424. // This will be available to all the sites (access_urls).
  425. if (isset($_POST['submit_dashboard_plugins'])) {
  426. $affected_rows = DashboardManager::store_dashboard_plugins($_POST);
  427. if ($affected_rows) {
  428. // add event to system log
  429. $user_id = api_get_user_id();
  430. $category = $_GET['category'];
  431. Event::addEvent(
  432. LOG_CONFIGURATION_SETTINGS_CHANGE,
  433. LOG_CONFIGURATION_SETTINGS_CATEGORY,
  434. $category,
  435. api_get_utc_datetime(),
  436. $user_id
  437. );
  438. Display :: display_confirmation_message(get_lang('DashboardPluginsHaveBeenUpdatedSucesslly'));
  439. }
  440. }
  441. echo '<script>
  442. $(function(){
  443. $("#tabs").tabs();
  444. });
  445. </script>';
  446. echo '<div id="tabs">';
  447. echo '<ul>';
  448. echo '<li><a href="#tabs-1">'.get_lang('Plugins').'</a></li>';
  449. echo '<li><a href="#tabs-2">'.get_lang('DashboardPlugins').'</a></li>';
  450. echo '<li><a href="#tabs-3">'.get_lang('ConfigureExtensions').'</a></li>';
  451. echo '</ul>';
  452. echo '<div id="tabs-1">';
  453. handle_plugins();
  454. echo '</div>';
  455. echo '<div id="tabs-2">';
  456. DashboardManager::handle_dashboard_plugins();
  457. echo '</div>';
  458. echo '<div id="tabs-3">';
  459. handle_extensions();
  460. echo '</div>';
  461. echo '</div>';
  462. break;
  463. case 'Stylesheets':
  464. // Displaying the extensions: Stylesheets.
  465. handle_stylesheets();
  466. if (isset($_POST)) {
  467. api_set_setting_last_update();
  468. }
  469. $form->display();
  470. break;
  471. case 'Search':
  472. handle_search();
  473. break;
  474. case 'Templates':
  475. handle_templates();
  476. break;
  477. case 'search_setting':
  478. search_setting($keyword);
  479. if (!empty($keyword)) {
  480. $form->display();
  481. }
  482. break;
  483. default:
  484. if (isset($form)) {
  485. $form->display();
  486. }
  487. }
  488. }
  489. /* FOOTER */
  490. Display :: display_footer();