index.php 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191
  1. <?php
  2. /* For licensing terms, see /license.txt */
  3. use ChamiloSession as Session;
  4. /**
  5. * @package chamilo.main
  6. */
  7. define('CHAMILO_HOMEPAGE', true);
  8. define('CHAMILO_LOAD_WYSIWYG', false);
  9. /* Flag forcing the 'current course' reset, as we're not inside a course anymore. */
  10. // Maybe we should change this into an api function? an example: CourseManager::unset();
  11. $cidReset = true;
  12. require_once 'main/inc/global.inc.php';
  13. // The section (for the tabs).
  14. $this_section = SECTION_CAMPUS; //rewritten below if including HTML file
  15. $includeFile = !empty($_GET['include']);
  16. if ($includeFile) {
  17. $this_section = SECTION_INCLUDE;
  18. } elseif (api_get_configuration_value('plugin_redirection_enabled')) {
  19. RedirectionPlugin::redirectUser(api_get_user_id());
  20. }
  21. $header_title = null;
  22. if (!api_is_anonymous()) {
  23. $header_title = ' ';
  24. }
  25. $controller = new IndexManager($header_title);
  26. //Actions
  27. $loginFailed = isset($_GET['loginFailed']) ? true : isset($loginFailed);
  28. if (!empty($_GET['logout'])) {
  29. $redirect = !empty($_GET['no_redirect']) ? false : true;
  30. // pass $logoutInfo defined in local.inc.php
  31. $controller->logout($redirect, $logoutInfo);
  32. }
  33. /**
  34. * Registers in the track_e_default table (view in important activities in admin
  35. * interface) a possible attempted break in, sending auth data through get.
  36. *
  37. * @todo This piece of code should probably move to local.inc.php where the
  38. * actual login / logout procedure is handled.
  39. * The real use of this code block should be seriously considered as well.
  40. * This form should just use a security token and get done with it.
  41. */
  42. if (isset($_GET['submitAuth']) && $_GET['submitAuth'] == 1) {
  43. $i = api_get_anonymous_id();
  44. Event::addEvent(
  45. LOG_ATTEMPTED_FORCED_LOGIN,
  46. 'tried_hacking_get',
  47. $_SERVER['REMOTE_ADDR'].(empty($_POST['login']) ? '' : '/'.$_POST['login']),
  48. null,
  49. $i
  50. );
  51. echo 'Attempted breakin - sysadmins notified.';
  52. session_destroy();
  53. die();
  54. }
  55. // Delete session item necessary to check for legal terms
  56. if (api_get_setting('allow_terms_conditions') === 'true') {
  57. Session::erase('term_and_condition');
  58. }
  59. //If we are not logged in and customapages activated
  60. if (!api_user_is_login() && CustomPages::enabled()) {
  61. if (Request::get('loggedout')) {
  62. CustomPages::display(CustomPages::LOGGED_OUT);
  63. } else {
  64. CustomPages::display(CustomPages::INDEX_UNLOGGED);
  65. }
  66. }
  67. /**
  68. * @todo This piece of code should probably move to local.inc.php where the
  69. * actual login procedure is handled.
  70. * @todo Check if this code is used. I think this code is never executed because
  71. * after clicking the submit button the code does the stuff
  72. * in local.inc.php and then redirects to index.php or user_portal.php depending
  73. * on api_get_setting('page_after_login').
  74. */
  75. if (!empty($_POST['submitAuth'])) {
  76. // The user has been already authenticated, we are now to find the last login of the user.
  77. if (isset($_user['user_id'])) {
  78. $track_login_table = Database::get_main_table(TABLE_STATISTIC_TRACK_E_LOGIN);
  79. $sql = "SELECT UNIX_TIMESTAMP(login_date)
  80. FROM $track_login_table
  81. WHERE login_user_id = '".$_user['user_id']."'
  82. ORDER BY login_date DESC LIMIT 1";
  83. $result_last_login = Database::query($sql);
  84. if (!$result_last_login) {
  85. if (Database::num_rows($result_last_login) > 0) {
  86. $user_last_login_datetime = Database::fetch_array($result_last_login);
  87. $user_last_login_datetime = $user_last_login_datetime[0];
  88. Session::write('user_last_login_datetime', $user_last_login_datetime);
  89. }
  90. }
  91. }
  92. } else {
  93. // Only if login form was not sent because if the form is sent the user was already on the page.
  94. Event::open();
  95. }
  96. if (!api_is_anonymous()) {
  97. $url = api_get_configuration_value('redirect_index_to_url_for_logged_users');
  98. if (!empty($url)) {
  99. header("Location: $url");
  100. exit;
  101. }
  102. }
  103. if (api_get_setting('display_categories_on_homepage') === 'true') {
  104. $controller->tpl->assign('course_category_block', $controller->return_courses_in_categories());
  105. }
  106. $controller->set_login_form();
  107. //@todo move this inside the IndexManager
  108. if (!api_is_anonymous()) {
  109. $controller->tpl->assign('profile_block', $controller->return_profile_block());
  110. $controller->tpl->assign('user_image_block', $controller->return_user_image_block());
  111. $controller->tpl->assign('course_block', $controller->return_course_block());
  112. }
  113. $hotCourses = '';
  114. $announcements_block = '';
  115. // Display the Site Use Cookie Warning Validation
  116. $useCookieValidation = api_get_setting('cookie_warning');
  117. if ($useCookieValidation === 'true') {
  118. if (isset($_POST['acceptCookies'])) {
  119. api_set_site_use_cookie_warning_cookie();
  120. } elseif (!api_site_use_cookie_warning_cookie_exist()) {
  121. if (Template::isToolBarDisplayedForUser()) {
  122. $controller->tpl->assign('toolBarDisplayed', true);
  123. } else {
  124. $controller->tpl->assign('toolBarDisplayed', false);
  125. }
  126. $controller->tpl->assign('displayCookieUsageWarning', true);
  127. }
  128. }
  129. // When loading a chamilo page do not include the hot courses and news
  130. if (!isset($_REQUEST['include'])) {
  131. if (api_get_setting('show_hot_courses') == 'true') {
  132. $hotCourses = $controller->return_hot_courses();
  133. }
  134. $announcements_block = $controller->return_announcements();
  135. }
  136. if (api_get_configuration_value('show_hot_sessions') === true) {
  137. $hotSessions = SessionManager::getHotSessions();
  138. $controller->tpl->assign('hot_sessions', $hotSessions);
  139. }
  140. $controller->tpl->assign('hot_courses', $hotCourses);
  141. $controller->tpl->assign('announcements_block', $announcements_block);
  142. if ($includeFile) {
  143. // If we are including a static page, then home_welcome is empty
  144. $controller->tpl->assign('home_welcome', '');
  145. $controller->tpl->assign('home_include', $controller->return_home_page($includeFile));
  146. } else {
  147. // If we are including the real homepage, then home_include is empty
  148. $controller->tpl->assign('home_welcome', $controller->return_home_page(false));
  149. $controller->tpl->assign('home_include', '');
  150. }
  151. $controller->tpl->assign('navigation_links', $controller->return_navigation_links());
  152. $controller->tpl->assign('notice_block', $controller->return_notice());
  153. //$controller->tpl->assign('main_navigation_block', $controller->return_navigation_links());
  154. $controller->tpl->assign('help_block', $controller->return_help());
  155. if (api_is_platform_admin() || api_is_drh()) {
  156. $controller->tpl->assign('skills_block', $controller->returnSkillLinks());
  157. }
  158. if (api_is_anonymous()) {
  159. $controller->tpl->setLoginBodyClass();
  160. }
  161. // direct login to course
  162. if (isset($_GET['firstpage'])) {
  163. api_set_firstpage_parameter($_GET['firstpage']);
  164. // if we are already logged, go directly to course
  165. if (api_user_is_login()) {
  166. echo "<script>self.location.href='index.php?firstpage=".Security::remove_XSS($_GET['firstpage'])."'</script>";
  167. }
  168. } else {
  169. api_delete_firstpage_parameter();
  170. }
  171. $controller->setGradeBookDependencyBar(api_get_user_id());
  172. $controller->tpl->display_two_col_template();
  173. // Deleting the session_id.
  174. Session::erase('session_id');
  175. Session::erase('id_session');
  176. Session::erase('studentview');
  177. api_remove_in_gradebook();