profile.php 29 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863
  1. <?php
  2. /* For licensing terms, see /license.txt */
  3. use Chamilo\UserBundle\Entity\User;
  4. use ChamiloSession as Session;
  5. /**
  6. * This file displays the user's profile,
  7. * optionally it allows users to modify their profile as well.
  8. *
  9. * See inc/conf/profile.conf.php to modify settings
  10. *
  11. * @package chamilo.auth
  12. */
  13. $cidReset = true;
  14. require_once __DIR__.'/../inc/global.inc.php';
  15. if (api_get_setting('allow_social_tool') == 'true') {
  16. $this_section = SECTION_SOCIAL;
  17. } else {
  18. $this_section = SECTION_MYPROFILE;
  19. }
  20. $_SESSION['this_section'] = $this_section;
  21. if (!(isset($_user['user_id']) && $_user['user_id']) || api_is_anonymous($_user['user_id'], true)) {
  22. api_not_allowed(true);
  23. }
  24. $gMapsPlugin = GoogleMapsPlugin::create();
  25. $geolocalization = $gMapsPlugin->get('enable_api') === 'true';
  26. if ($geolocalization) {
  27. $gmapsApiKey = $gMapsPlugin->get('api_key');
  28. $htmlHeadXtra[] = '<script type="text/javascript" src="//maps.googleapis.com/maps/api/js?sensor=true&key='.$gmapsApiKey.'" ></script>';
  29. }
  30. $htmlHeadXtra[] = api_get_password_checker_js('#username', '#password1');
  31. $htmlHeadXtra[] = api_get_css_asset('cropper/dist/cropper.min.css');
  32. $htmlHeadXtra[] = api_get_asset('cropper/dist/cropper.min.js');
  33. $htmlHeadXtra[] = '<script>
  34. $(document).ready(function() {
  35. $("#id_generate_api_key").on("click", function (e) {
  36. e.preventDefault();
  37. $.ajax({
  38. contentType: "application/x-www-form-urlencoded",
  39. type: "POST",
  40. url: "'.api_get_path(WEB_AJAX_PATH).'user_manager.ajax.php?a=generate_api_key",
  41. data: "num_key_id="+"",
  42. success: function(datos) {
  43. $("#div_api_key").html(datos);
  44. }
  45. });
  46. });
  47. });
  48. function confirmation(name) {
  49. if (confirm("'.get_lang('AreYouSureToDeleteJS', '').' " + name + " ?")) {
  50. document.forms["profile"].submit();
  51. } else {
  52. return false;
  53. }
  54. }
  55. function show_image(image,width,height) {
  56. width = parseInt(width) + 20;
  57. height = parseInt(height) + 20;
  58. window_x = window.open(image,\'windowX\',\'width=\'+ width + \', height=\'+ height + \'\');
  59. }
  60. function hide_icon_edit(element_html) {
  61. ident="#edit_image";
  62. $(ident).hide();
  63. }
  64. function show_icon_edit(element_html) {
  65. ident="#edit_image";
  66. $(ident).show();
  67. }
  68. </script>';
  69. $jquery_ready_content = '';
  70. if (api_get_setting('allow_message_tool') === 'true') {
  71. $jquery_ready_content = <<<EOF
  72. $(".message-content .message-delete").click(function(){
  73. $(this).parents(".message-content").animate({ opacity: "hide" }, "slow");
  74. $(".message-view").animate({ opacity: "show" }, "slow");
  75. });
  76. EOF;
  77. }
  78. $tool_name = is_profile_editable() ? get_lang('ModifProfile') : get_lang('ViewProfile');
  79. $table_user = Database::get_main_table(TABLE_MAIN_USER);
  80. /*
  81. * Get initial values for all fields.
  82. */
  83. $user_data = api_get_user_info(api_get_user_id());
  84. $array_list_key = UserManager::get_api_keys(api_get_user_id());
  85. $id_temp_key = UserManager::get_api_key_id(api_get_user_id(), 'dokeos');
  86. $value_array = $array_list_key[$id_temp_key];
  87. $user_data['api_key_generate'] = $value_array;
  88. if ($user_data !== false) {
  89. if (api_get_setting('login_is_email') == 'true') {
  90. $user_data['username'] = $user_data['email'];
  91. }
  92. if (is_null($user_data['language'])) {
  93. $user_data['language'] = api_get_setting('platformLanguage');
  94. }
  95. }
  96. /*
  97. * Initialize the form.
  98. */
  99. $form = new FormValidator('profile');
  100. if (api_is_western_name_order()) {
  101. // FIRST NAME and LAST NAME
  102. $form->addElement('text', 'firstname', get_lang('FirstName'), array('size' => 40));
  103. $form->addElement('text', 'lastname', get_lang('LastName'), array('size' => 40));
  104. } else {
  105. // LAST NAME and FIRST NAME
  106. $form->addElement('text', 'lastname', get_lang('LastName'), array('size' => 40));
  107. $form->addElement('text', 'firstname', get_lang('FirstName'), array('size' => 40));
  108. }
  109. if (api_get_setting('profile', 'name') !== 'true') {
  110. $form->freeze(array('lastname', 'firstname'));
  111. }
  112. $form->applyFilter(array('lastname', 'firstname'), 'stripslashes');
  113. $form->applyFilter(array('lastname', 'firstname'), 'trim');
  114. $form->applyFilter(array('lastname', 'firstname'), 'html_filter');
  115. $form->addRule('lastname', get_lang('ThisFieldIsRequired'), 'required');
  116. $form->addRule('firstname', get_lang('ThisFieldIsRequired'), 'required');
  117. // USERNAME
  118. $form->addElement(
  119. 'text',
  120. 'username',
  121. get_lang('UserName'),
  122. array(
  123. 'id' => 'username',
  124. 'maxlength' => USERNAME_MAX_LENGTH,
  125. 'size' => USERNAME_MAX_LENGTH,
  126. )
  127. );
  128. if (api_get_setting('profile', 'login') !== 'true' || api_get_setting('login_is_email') == 'true') {
  129. $form->freeze('username');
  130. }
  131. $form->applyFilter('username', 'stripslashes');
  132. $form->applyFilter('username', 'trim');
  133. $form->addRule('username', get_lang('ThisFieldIsRequired'), 'required');
  134. $form->addRule('username', get_lang('UsernameWrong'), 'username');
  135. $form->addRule('username', get_lang('UserTaken'), 'username_available', $user_data['username']);
  136. // OFFICIAL CODE
  137. if (defined('CONFVAL_ASK_FOR_OFFICIAL_CODE') && CONFVAL_ASK_FOR_OFFICIAL_CODE === true) {
  138. $form->addElement('text', 'official_code', get_lang('OfficialCode'), array('size' => 40));
  139. if (api_get_setting('profile', 'officialcode') !== 'true') {
  140. $form->freeze('official_code');
  141. }
  142. $form->applyFilter('official_code', 'stripslashes');
  143. $form->applyFilter('official_code', 'trim');
  144. $form->applyFilter('official_code', 'html_filter');
  145. if (api_get_setting('registration', 'officialcode') === 'true' &&
  146. api_get_setting('profile', 'officialcode') === 'true'
  147. ) {
  148. $form->addRule('official_code', get_lang('ThisFieldIsRequired'), 'required');
  149. }
  150. }
  151. // EMAIL
  152. $form->addElement('email', 'email', get_lang('Email'), array('size' => 40));
  153. if (api_get_setting('profile', 'email') !== 'true') {
  154. $form->freeze('email');
  155. }
  156. if (api_get_setting('registration', 'email') == 'true' && api_get_setting('profile', 'email') == 'true') {
  157. $form->applyFilter('email', 'stripslashes');
  158. $form->applyFilter('email', 'trim');
  159. $form->addRule('email', get_lang('ThisFieldIsRequired'), 'required');
  160. $form->addRule('email', get_lang('EmailWrong'), 'email');
  161. }
  162. // OPENID URL
  163. if (is_profile_editable() && api_get_setting('openid_authentication') == 'true') {
  164. $form->addElement('text', 'openid', get_lang('OpenIDURL'), array('size' => 40));
  165. if (api_get_setting('profile', 'openid') !== 'true') {
  166. $form->freeze('openid');
  167. }
  168. $form->applyFilter('openid', 'trim');
  169. }
  170. // PHONE
  171. $form->addElement('text', 'phone', get_lang('Phone'), array('size' => 20));
  172. if (api_get_setting('profile', 'phone') !== 'true') {
  173. $form->freeze('phone');
  174. }
  175. $form->applyFilter('phone', 'stripslashes');
  176. $form->applyFilter('phone', 'trim');
  177. $form->applyFilter('phone', 'html_filter');
  178. // PICTURE
  179. if (is_profile_editable() && api_get_setting('profile', 'picture') == 'true') {
  180. $form->addFile(
  181. 'picture',
  182. ($user_data['picture_uri'] != '' ? get_lang('UpdateImage') : get_lang(
  183. 'AddImage'
  184. )),
  185. array('id' => 'picture', 'class' => 'picture-form', 'crop_image' => true, 'crop_ratio' => '1 / 1')
  186. );
  187. $form->addProgress();
  188. if (!empty($user_data['picture_uri'])) {
  189. $form->addElement('checkbox', 'remove_picture', null, get_lang('DelImage'));
  190. }
  191. $allowed_picture_types = api_get_supported_image_extensions(false);
  192. $form->addRule(
  193. 'picture',
  194. get_lang('OnlyImagesAllowed').' ('.implode(', ', $allowed_picture_types).')',
  195. 'filetype',
  196. $allowed_picture_types
  197. );
  198. }
  199. // LANGUAGE
  200. $form->addSelectLanguage('language', get_lang('Language'));
  201. if (api_get_setting('profile', 'language') !== 'true') {
  202. $form->freeze('language');
  203. }
  204. //THEME
  205. if (is_profile_editable() && api_get_setting('user_selected_theme') == 'true') {
  206. $form->addElement('SelectTheme', 'theme', get_lang('Theme'));
  207. if (api_get_setting('profile', 'theme') !== 'true') {
  208. $form->freeze('theme');
  209. }
  210. $form->applyFilter('theme', 'trim');
  211. }
  212. // EXTENDED PROFILE this make the page very slow!
  213. if (api_get_setting('extended_profile') === 'true') {
  214. $width_extended_profile = 500;
  215. // MY COMPETENCES
  216. $form->addHtmlEditor(
  217. 'competences',
  218. get_lang('MyCompetences'),
  219. false,
  220. false,
  221. array(
  222. 'ToolbarSet' => 'Profile',
  223. 'Width' => $width_extended_profile,
  224. 'Height' => '130',
  225. )
  226. );
  227. // MY DIPLOMAS
  228. $form->addHtmlEditor(
  229. 'diplomas',
  230. get_lang('MyDiplomas'),
  231. false,
  232. false,
  233. array(
  234. 'ToolbarSet' => 'Profile',
  235. 'Width' => $width_extended_profile,
  236. 'Height' => '130',
  237. )
  238. );
  239. // WHAT I AM ABLE TO TEACH
  240. $form->addHtmlEditor(
  241. 'teach',
  242. get_lang('MyTeach'),
  243. false,
  244. false,
  245. array(
  246. 'ToolbarSet' => 'Profile',
  247. 'Width' => $width_extended_profile,
  248. 'Height' => '130',
  249. )
  250. );
  251. // MY PRODUCTIONS
  252. $form->addElement('file', 'production', get_lang('MyProductions'));
  253. if ($production_list = UserManager::build_production_list(api_get_user_id(), '', true)) {
  254. $form->addElement('static', 'productions_list', null, $production_list);
  255. }
  256. // MY PERSONAL OPEN AREA
  257. $form->addHtmlEditor(
  258. 'openarea',
  259. get_lang('MyPersonalOpenArea'),
  260. false,
  261. false,
  262. array(
  263. 'ToolbarSet' => 'Profile',
  264. 'Width' => $width_extended_profile,
  265. 'Height' => '350',
  266. )
  267. );
  268. // openarea is untrimmed for maximum openness
  269. $form->applyFilter(array('competences', 'diplomas', 'teach', 'openarea'), 'stripslashes');
  270. $form->applyFilter(array('competences', 'diplomas', 'teach'), 'trim');
  271. }
  272. // PASSWORD, if auth_source is platform
  273. if (is_platform_authentication() &&
  274. is_profile_editable() &&
  275. api_get_setting('profile', 'password') == 'true'
  276. ) {
  277. $form->addElement('password', 'password0', array(get_lang('CurrentPassword'), get_lang('Enter2passToChange')), array('size' => 40));
  278. $form->addElement('password', 'password1', get_lang('NewPass'), array('id'=> 'password1', 'size' => 40));
  279. $checkPass = api_get_setting('allow_strength_pass_checker');
  280. if ($checkPass == 'true') {
  281. $form->addElement('label', null, '<div id="password_progress"></div>');
  282. }
  283. $form->addElement('password', 'password2', get_lang('Confirmation'), array('size' => 40));
  284. // user must enter identical password twice so we can prevent some user errors
  285. $form->addRule(array('password1', 'password2'), get_lang('PassTwo'), 'compare');
  286. $form->addPasswordRule('password1');
  287. }
  288. $extraField = new ExtraField('user');
  289. $return = $extraField->addElements(
  290. $form,
  291. api_get_user_id()
  292. );
  293. $jquery_ready_content = $return['jquery_ready_content'];
  294. // the $jquery_ready_content variable collects all functions that
  295. // will be load in the $(document).ready javascript function
  296. $htmlHeadXtra[] = '<script>
  297. $(document).ready(function(){
  298. '.$jquery_ready_content.'
  299. });
  300. </script>';
  301. if (api_get_setting('profile', 'apikeys') == 'true') {
  302. $form->addElement('html', '<div id="div_api_key">');
  303. $form->addElement(
  304. 'text',
  305. 'api_key_generate',
  306. get_lang('MyApiKey'),
  307. array('size' => 40, 'id' => 'id_api_key_generate')
  308. );
  309. $form->addElement('html', '</div>');
  310. $form->addButton(
  311. 'generate_api_key',
  312. get_lang('GenerateApiKey'),
  313. 'cogs',
  314. 'default',
  315. 'default',
  316. null,
  317. ['id' => 'id_generate_api_key']
  318. );
  319. }
  320. // SUBMIT
  321. if (is_profile_editable()) {
  322. $form->addButtonUpdate(get_lang('SaveSettings'), 'apply_change');
  323. } else {
  324. $form->freeze();
  325. }
  326. $form->setDefaults($user_data);
  327. /**
  328. * Is user auth_source is platform ?
  329. *
  330. * @return boolean if auth_source is platform
  331. */
  332. function is_platform_authentication()
  333. {
  334. $tab_user_info = api_get_user_info();
  335. return $tab_user_info['auth_source'] == PLATFORM_AUTH_SOURCE;
  336. }
  337. /**
  338. * Can a user edit his/her profile?
  339. *
  340. * @return boolean Editability of the profile
  341. */
  342. function is_profile_editable()
  343. {
  344. if (isset($GLOBALS['profileIsEditable'])) {
  345. return (bool) $GLOBALS['profileIsEditable'];
  346. }
  347. return true;
  348. }
  349. /*
  350. PRODUCTIONS FUNCTIONS
  351. */
  352. /**
  353. * Upload a submitted user production.
  354. *
  355. * @param $user_id User id
  356. * @return The filename of the new production or FALSE if the upload has failed
  357. */
  358. function upload_user_production($user_id)
  359. {
  360. $production_repository = UserManager::getUserPathById($user_id, 'system');
  361. if (!file_exists($production_repository)) {
  362. @mkdir($production_repository, api_get_permissions_for_new_directories(), true);
  363. }
  364. $filename = api_replace_dangerous_char($_FILES['production']['name']);
  365. $filename = disable_dangerous_file($filename);
  366. if (filter_extension($filename)) {
  367. if (@move_uploaded_file($_FILES['production']['tmp_name'], $production_repository.$filename)) {
  368. return $filename;
  369. }
  370. }
  371. return false; // this should be returned if anything went wrong with the upload
  372. }
  373. /**
  374. * Check current user's current password
  375. * @param char email
  376. * @return bool true o false
  377. * @uses Gets user ID from global variable
  378. */
  379. function check_user_email($email)
  380. {
  381. $user_id = api_get_user_id();
  382. if ($user_id != strval(intval($user_id)) || empty($email)) {
  383. return false;
  384. }
  385. $table_user = Database::get_main_table(TABLE_MAIN_USER);
  386. $email = Database::escape_string($email);
  387. $sql = "SELECT * FROM $table_user
  388. WHERE user_id='".$user_id."' AND email='".$email."'";
  389. $result = Database::query($sql);
  390. return Database::num_rows($result) != 0;
  391. }
  392. $filtered_extension = false;
  393. if ($form->validate()) {
  394. $wrong_current_password = false;
  395. $user_data = $form->getSubmitValues(1);
  396. /** @var User $user */
  397. $user = UserManager::getRepository()->find(api_get_user_id());
  398. // set password if a new one was provided
  399. $validPassword = false;
  400. $passwordWasChecked = false;
  401. if ($user &&
  402. (!empty($user_data['password0']) &&
  403. !empty($user_data['password1'])) ||
  404. (!empty($user_data['password0']) &&
  405. api_get_setting('profile', 'email') == 'true')
  406. ) {
  407. $passwordWasChecked = true;
  408. $validPassword = UserManager::isPasswordValid(
  409. $user->getPassword(),
  410. $user_data['password0'],
  411. $user->getSalt()
  412. );
  413. if ($validPassword) {
  414. $password = $user_data['password1'];
  415. } else {
  416. Display::addFlash(
  417. Display:: return_message(
  418. get_lang('CurrentPasswordEmptyOrIncorrect'),
  419. 'warning',
  420. false
  421. )
  422. );
  423. }
  424. }
  425. $allow_users_to_change_email_with_no_password = true;
  426. if (is_platform_authentication() &&
  427. api_get_setting('allow_users_to_change_email_with_no_password') == 'false'
  428. ) {
  429. $allow_users_to_change_email_with_no_password = false;
  430. }
  431. // If user sending the email to be changed (input available and not frozen )
  432. if (api_get_setting('profile', 'email') == 'true') {
  433. if ($allow_users_to_change_email_with_no_password) {
  434. if (!check_user_email($user_data['email'])) {
  435. $changeemail = $user_data['email'];
  436. }
  437. } else {
  438. // Normal behaviour
  439. if (!check_user_email($user_data['email']) && $validPassword) {
  440. $changeemail = $user_data['email'];
  441. }
  442. if (!check_user_email($user_data['email']) && empty($user_data['password0'])) {
  443. Display::addFlash(
  444. Display:: return_message(
  445. get_lang('ToChangeYourEmailMustTypeYourPassword'),
  446. 'error',
  447. false
  448. )
  449. );
  450. }
  451. }
  452. }
  453. // Upload picture if a new one is provided
  454. if ($_FILES['picture']['size']) {
  455. $new_picture = UserManager::update_user_picture(
  456. api_get_user_id(),
  457. $_FILES['picture']['name'],
  458. $_FILES['picture']['tmp_name'],
  459. $user_data['picture_crop_result']
  460. );
  461. if ($new_picture) {
  462. $user_data['picture_uri'] = $new_picture;
  463. Display::addFlash(
  464. Display:: return_message(
  465. get_lang('PictureUploaded'),
  466. 'normal',
  467. false
  468. )
  469. );
  470. }
  471. } elseif (!empty($user_data['remove_picture'])) {
  472. // remove existing picture if asked
  473. UserManager::delete_user_picture(api_get_user_id());
  474. $user_data['picture_uri'] = '';
  475. }
  476. // Remove production.
  477. if (isset($user_data['remove_production']) &&
  478. is_array($user_data['remove_production'])
  479. ) {
  480. foreach (array_keys($user_data['remove_production']) as $production) {
  481. UserManager::remove_user_production(api_get_user_id(), urldecode($production));
  482. }
  483. if ($production_list = UserManager::build_production_list(api_get_user_id(), true, true)) {
  484. $form->insertElementBefore(
  485. $form->createElement('static', null, null, $production_list),
  486. 'productions_list'
  487. );
  488. }
  489. $form->removeElement('productions_list');
  490. Display::addFlash(
  491. Display:: return_message(get_lang('FileDeleted'), 'normal', false)
  492. );
  493. }
  494. // upload production if a new one is provided
  495. if (isset($_FILES['production']) && $_FILES['production']['size']) {
  496. $res = upload_user_production(api_get_user_id());
  497. if (!$res) {
  498. //it's a bit excessive to assume the extension is the reason why
  499. // upload_user_production() returned false, but it's true in most cases
  500. $filtered_extension = true;
  501. } else {
  502. Display::addFlash(
  503. Display:: return_message(
  504. get_lang('ProductionUploaded'),
  505. 'normal',
  506. false
  507. )
  508. );
  509. }
  510. }
  511. // remove values that shouldn't go in the database
  512. unset(
  513. $user_data['password0'],
  514. $user_data['password1'],
  515. $user_data['password2'],
  516. $user_data['MAX_FILE_SIZE'],
  517. $user_data['remove_picture'],
  518. $user_data['apply_change'],
  519. $user_data['email']
  520. );
  521. // Following RFC2396 (http://www.faqs.org/rfcs/rfc2396.html), a URI uses ':' as a reserved character
  522. // we can thus ensure the URL doesn't contain any scheme name by searching for ':' in the string
  523. $my_user_openid = isset($user_data['openid']) ? $user_data['openid'] : '';
  524. if (!preg_match('/^[^:]*:\/\/.*$/', $my_user_openid)) {
  525. //ensure there is at least a http:// scheme in the URI provided
  526. $user_data['openid'] = 'http://'.$my_user_openid;
  527. }
  528. $extras = array();
  529. //Checking the user language
  530. $languages = api_get_languages();
  531. if (!in_array($user_data['language'], $languages['folder'])) {
  532. $user_data['language'] = api_get_setting('platformLanguage');
  533. }
  534. $_SESSION['_user']['language'] = $user_data['language'];
  535. //Only update values that are request by the "profile" setting
  536. $profile_list = api_get_setting('profile');
  537. //Adding missing variables
  538. $available_values_to_modify = array();
  539. foreach ($profile_list as $key => $status) {
  540. if ($status == 'true') {
  541. switch ($key) {
  542. case 'login':
  543. $available_values_to_modify[] = 'username';
  544. break;
  545. case 'name':
  546. $available_values_to_modify[] = 'firstname';
  547. $available_values_to_modify[] = 'lastname';
  548. break;
  549. case 'picture':
  550. $available_values_to_modify[] = 'picture_uri';
  551. break;
  552. default:
  553. $available_values_to_modify[] = $key;
  554. break;
  555. }
  556. }
  557. }
  558. //Fixing missing variables
  559. $available_values_to_modify = array_merge(
  560. $available_values_to_modify,
  561. array('competences', 'diplomas', 'openarea', 'teach', 'openid', 'address')
  562. );
  563. // build SQL query
  564. $sql = "UPDATE $table_user SET";
  565. unset($user_data['api_key_generate']);
  566. foreach ($user_data as $key => $value) {
  567. if (substr($key, 0, 6) === 'extra_') { //an extra field
  568. continue;
  569. } elseif (strpos($key, 'remove_extra_') !== false) {
  570. } else {
  571. if (in_array($key, $available_values_to_modify)) {
  572. $sql .= " $key = '".Database::escape_string($value)."',";
  573. }
  574. }
  575. }
  576. $changePassword = false;
  577. // Change email
  578. if ($allow_users_to_change_email_with_no_password) {
  579. if (isset($changeemail) && in_array('email', $available_values_to_modify)) {
  580. $sql .= " email = '".Database::escape_string($changeemail)."' ";
  581. }
  582. if (isset($password) && in_array('password', $available_values_to_modify)) {
  583. $changePassword = true;
  584. }
  585. } else {
  586. if (isset($changeemail) && !isset($password) && in_array('email', $available_values_to_modify)) {
  587. $sql .= " email = '".Database::escape_string($changeemail)."'";
  588. } else {
  589. if (isset($password) && in_array('password', $available_values_to_modify)) {
  590. if (isset($changeemail) && in_array('email', $available_values_to_modify)) {
  591. $sql .= " email = '".Database::escape_string($changeemail)."' ";
  592. }
  593. $changePassword = true;
  594. }
  595. }
  596. }
  597. $sql = rtrim($sql, ',');
  598. if ($changePassword && !empty($password)) {
  599. UserManager::updatePassword(api_get_user_id(), $password);
  600. }
  601. if (api_get_setting('profile', 'officialcode') === 'true' &&
  602. isset($user_data['official_code'])
  603. ) {
  604. $sql .= ", official_code = '".Database::escape_string($user_data['official_code'])."'";
  605. }
  606. $sql .= " WHERE user_id = '".api_get_user_id()."'";
  607. Database::query($sql);
  608. $webserviceUrl = api_get_plugin_setting('logintcc', 'webservice_url');
  609. $hash = api_get_plugin_setting('logintcc', 'hash');
  610. $extraField = new ExtraFieldValue('user');
  611. $extraField->saveFieldValues($user_data);
  612. if (!empty($webserviceUrl) && !empty($hash)) {
  613. $tccUserIdData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'tcc_user_id');
  614. $tccUserId = $tccUserIdData['value'];
  615. $tccHashData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'tcc_hash_key');
  616. $tccHash = $tccHashData['value'];
  617. $genreData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'terms_genre');
  618. $genre = $genreData['value'] == 'homme' ? 'Masculin' : 'Féminin';
  619. $codeData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'terms_codepostal');
  620. $cp = $codeData['value'];
  621. $citizenshipData = $extraField->get_values_by_handler_and_field_variable(
  622. api_get_user_id(),
  623. 'terms_nationalite'
  624. );
  625. $citizenship = $citizenshipData['value'];
  626. $birthData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'terms_datedenaissance');
  627. $birthDate = $birthData['value'];
  628. $countryData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'terms_paysresidence');
  629. $country = $countryData['value'];
  630. $cityData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'terms_ville');
  631. $city = $cityData['value'];
  632. $AddressData = $extraField->get_values_by_handler_and_field_variable(api_get_user_id(), 'terms_adresse');
  633. $Adresse = $AddressData['value'];
  634. switch ($user_data['language']) {
  635. case 'french':
  636. case 'french2':
  637. $language = 'fr-FR';
  638. break;
  639. case 'german':
  640. case 'german2':
  641. $language = 'de-DE';
  642. break;
  643. default:
  644. $language = 'fr-FR';
  645. break;
  646. }
  647. $params = [
  648. 'UserID' => $tccUserId,
  649. 'Genre' => $genre,
  650. 'Nom' => $user_data['lastname'],
  651. 'Prenom' => $user_data['firstname'],
  652. 'DateNaissance' => $birthDate,
  653. 'Langue' => $language,
  654. 'Nationalite' => $citizenship,
  655. 'Adresse' => $Adresse,
  656. 'CP' => $cp,
  657. 'PaysResidence' => $country,
  658. 'Ville' => $city,
  659. 'Email' => $user->getEmail(),
  660. 'HashKey' => $hash
  661. ];
  662. try {
  663. $client = new GuzzleHttp\Client();
  664. $response = $client->request('POST', $webserviceUrl.'/UpdateUser', ['json' => $params]);
  665. } catch (Exception $e) {
  666. echo $e->getMessage();
  667. }
  668. }
  669. if ($passwordWasChecked == false) {
  670. Display::addFlash(
  671. Display:: return_message(get_lang('ProfileReg'), 'normal', false)
  672. );
  673. } else {
  674. if ($validPassword) {
  675. Display::addFlash(
  676. Display:: return_message(get_lang('ProfileReg'), 'normal', false)
  677. );
  678. }
  679. }
  680. $userInfo = api_get_user_info();
  681. Session::write('_user', $userInfo);
  682. $url = api_get_self();
  683. header("Location: ".$url);
  684. exit;
  685. }
  686. // the header
  687. $actions = '';
  688. if (api_get_setting('allow_social_tool') !== 'true') {
  689. if (api_get_setting('extended_profile') === 'true') {
  690. if (
  691. api_get_setting('allow_message_tool') === 'true'
  692. ) {
  693. $actions .= '<a href="'.api_get_path(WEB_PATH).'main/social/profile.php">'.
  694. Display::return_icon('shared_profile.png', get_lang('ViewSharedProfile')).'</a>';
  695. $actions .= '<a href="'.api_get_path(WEB_PATH).'main/messages/inbox.php">'.
  696. Display::return_icon('inbox.png', get_lang('Messages')).'</a>';
  697. }
  698. $show = isset($_GET['show']) ? '&amp;show='.Security::remove_XSS($_GET['show']) : '';
  699. if (isset($_GET['type']) && $_GET['type'] === 'extended') {
  700. $actions .= '<a href="profile.php?type=reduced'.$show.'">'.
  701. Display::return_icon('edit.png', get_lang('EditNormalProfile'), '', 16).'</a>';
  702. } else {
  703. $actions .= '<a href="profile.php?type=extended'.$show.'">'.
  704. Display::return_icon('edit.png', get_lang('EditExtendProfile'), '', 16).'</a>';
  705. }
  706. }
  707. }
  708. $show_delete_account_button = api_get_setting('platform_unsubscribe_allowed') === 'true' ? true : false;
  709. if (api_get_setting('show_terms_if_profile_completed') === 'true') {
  710. if (empty($user_data['profile_completed'])) {
  711. Display::addFlash(Display::return_message(get_lang('ProfileIsNotCompleted'), 'warning'));
  712. }
  713. $profileCompleteResults = Session::read('profile_completed_result');
  714. if (!empty($profileCompleteResults)) {
  715. foreach ($profileCompleteResults as $profileVariable => $value) {
  716. if ($value === false) {
  717. $data = $extraField->get_handler_field_info_by_field_variable($profileVariable);
  718. Display::addFlash(
  719. Display::return_message('"'.$data['display_text'].'" '.get_lang('ThisFieldIsRequired'),
  720. 'warning',
  721. false
  722. )
  723. );
  724. }
  725. }
  726. }
  727. Session::erase('profile_completed_result');
  728. }
  729. $tpl = new Template(get_lang('ModifyProfile'));
  730. if ($actions) {
  731. $tpl->assign(
  732. 'actions',
  733. Display::toolbarAction('toolbar', [$actions])
  734. );
  735. }
  736. SocialManager::setSocialUserBlock($tpl, api_get_user_id(), 'messages');
  737. if (api_get_setting('allow_social_tool') === 'true') {
  738. SocialManager::setSocialUserBlock($tpl, api_get_user_id(), 'home');
  739. $menu = SocialManager::show_social_menu(
  740. 'home',
  741. null,
  742. api_get_user_id(),
  743. false,
  744. $show_delete_account_button
  745. );
  746. $tpl->assign('social_menu_block', $menu);
  747. $tpl->assign('social_right_content', $form->returnForm());
  748. $social_layout = $tpl->get_template('social/edit_profile.tpl');
  749. $tpl->display($social_layout);
  750. } else {
  751. $bigImage = UserManager::getUserPicture(api_get_user_id(), USER_IMAGE_SIZE_BIG);
  752. $normalImage = UserManager::getUserPicture(api_get_user_id(), USER_IMAGE_SIZE_ORIGINAL);
  753. $imageToShow = '<div id="image-message-container">';
  754. $imageToShow .= '<a class="expand-image" href="'.$bigImage.'" /><img src="'.$normalImage.'"></a>';
  755. $imageToShow .= '</div>';
  756. $content = $imageToShow.$form->returnForm();
  757. $tpl->assign('content', $content);
  758. $tpl->display_one_col_template();
  759. }