settings.php 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565
  1. <?php
  2. /* For licensing terms, see /license.txt */
  3. /**
  4. * With this tool you can easily adjust non critical configuration settings.
  5. * Non critical means that changing them will not result in a broken campus.
  6. *
  7. * @author Patrick Cool
  8. * @author Julio Montoya - Multiple URL site
  9. * @package chamilo.admin
  10. */
  11. /* INIT SECTION */
  12. // Language files that need to be included.
  13. if (isset($_GET['category']) && $_GET['category'] == 'Templates') {
  14. $language_file = array('admin', 'document');
  15. } else {
  16. if (isset($_GET['category']) && $_GET['category'] == 'Gradebook') {
  17. $language_file = array('admin', 'gradebook');
  18. } else {
  19. $language_file = array('admin', 'document');
  20. }
  21. }
  22. $language_file[] = 'tracking';
  23. // Resetting the course id.
  24. $cidReset = true;
  25. // Including some necessary library files.
  26. require_once '../inc/global.inc.php';
  27. require_once 'settings.lib.php';
  28. // Setting the section (for the tabs).
  29. $this_section = SECTION_PLATFORM_ADMIN;
  30. $_SESSION['this_section'] = $this_section;
  31. // Access restrictions.
  32. api_protect_admin_script();
  33. // Settings to avoid
  34. $settings_to_avoid = array(
  35. 'stylesheets' => '', // handled by the handle_stylesheet() function
  36. 'server_type' => '',
  37. 'use_session_mode' => 'true',
  38. 'gradebook_enable' => 'false',
  39. 'example_material_course_creation' => 'true' // ON by default - now we have this option when we create a course
  40. );
  41. $convert_byte_to_mega_list = array(
  42. 'dropbox_max_filesize',
  43. 'message_max_upload_filesize',
  44. 'default_document_quotum',
  45. 'default_group_quotum'
  46. );
  47. // Database table definitions.
  48. $table_settings_current = Database :: get_main_table(TABLE_MAIN_SETTINGS_CURRENT);
  49. // Setting breadcrumbs.
  50. $interbreadcrumb[] = array('url' => 'index.php', 'name' => get_lang('PlatformAdmin'));
  51. // Setting the name of the tool.
  52. $tool_name = get_lang('PlatformConfigSettings');
  53. if (empty($_GET['category'])) {
  54. $_GET['category'] = 'Platform';
  55. }
  56. $watermark_deleted = false;
  57. if (isset($_GET['delete_watermark'])) {
  58. $watermark_deleted = PDF::delete_watermark();
  59. }
  60. if (isset($_GET['action']) && $_GET['action'] == 'delete_grading') {
  61. $id = intval($_GET['id']);
  62. api_delete_setting_option($id);
  63. }
  64. $form_search = new FormValidator('search_settings', 'get', api_get_self(), null, array('class' => 'well form-inline'));
  65. $form_search->addElement('text', 'search_field');
  66. $form_search->addElement('hidden', 'category', 'search_setting');
  67. $form_search->addElement(
  68. 'style_submit_button',
  69. 'submit_button',
  70. get_lang('Search'),
  71. 'value="submit_button", class="search"'
  72. );
  73. $form_search->setDefaults(
  74. array('search_field' => (isset($_REQUEST['search_field']) ? $_REQUEST['search_field'] : null))
  75. );
  76. $form_search_html = $form_search->return_form();
  77. $url_id = api_get_current_access_url_id();
  78. $settings = null;
  79. /**
  80. * @param string $category
  81. * @return array
  82. */
  83. function get_settings($category = null)
  84. {
  85. $url_id = api_get_current_access_url_id();
  86. $settings_by_access_list = array();
  87. if ($url_id == 1) {
  88. $settings = api_get_settings($category, 'group', $url_id);
  89. } else {
  90. $url_info = api_get_access_url($url_id);
  91. if ($url_info['active'] == 1) {
  92. // The default settings of Chamilo
  93. $settings = api_get_settings($category, 'group', 1, 0);
  94. // The settings that are changeable from a particular site.
  95. $settings_by_access = api_get_settings($category, 'group', $url_id, 1);
  96. foreach ($settings_by_access as $row) {
  97. if (empty($row['variable'])) {
  98. $row['variable'] = 0;
  99. }
  100. if (empty($row['subkey'])) {
  101. $row['subkey'] = 0;
  102. }
  103. if (empty($row['category'])) {
  104. $row['category'] = 0;
  105. }
  106. // One more validation if is changeable.
  107. if ($row['access_url_changeable'] == 1) {
  108. $settings_by_access_list[$row['variable']] [$row['subkey']] [$row['category']] = $row;
  109. } else {
  110. $settings_by_access_list[$row['variable']] [$row['subkey']] [$row['category']] = array();
  111. }
  112. }
  113. }
  114. }
  115. if (isset($category) && $category == 'search_setting') {
  116. if (!empty($_REQUEST['search_field'])) {
  117. $settings = search_setting($_REQUEST['search_field']);
  118. }
  119. }
  120. return array(
  121. 'settings' => $settings,
  122. 'settings_by_access_list' => $settings_by_access_list
  123. );
  124. }
  125. // Build the form.
  126. if (!empty($_GET['category']) && !in_array($_GET['category'], array('Plugins', 'stylesheets', 'Search'))) {
  127. $my_category = isset($_GET['category']) ? $_GET['category'] : null;
  128. $settings_array = get_settings($my_category);
  129. $settings = $settings_array['settings'];
  130. $settings_by_access_list = $settings_array['settings_by_access_list'];
  131. $form = generate_settings_form($settings, $settings_by_access_list, $settings_to_avoid, $convert_byte_to_mega_list);
  132. $message = array();
  133. if ($form->validate()) {
  134. $values = $form->exportValues();
  135. $mark_all = false;
  136. $un_mark_all = false;
  137. if (!empty($_configuration['multiple_access_urls'])) {
  138. if (isset($values['buttons_in_action_right']) && isset($values['buttons_in_action_right']['mark_all'])) {
  139. $mark_all = true;
  140. }
  141. if (isset($values['buttons_in_action_right']) && isset($values['buttons_in_action_right']['unmark_all'])) {
  142. $un_mark_all = true;
  143. }
  144. }
  145. if ($mark_all || $un_mark_all) {
  146. if (api_is_global_platform_admin()) {
  147. $locked_settings = api_get_locked_settings();
  148. foreach ($values as $key => $value) {
  149. if (!in_array($key, $locked_settings)) {
  150. $changeable = 0;
  151. if ($mark_all) {
  152. $changeable = 1;
  153. }
  154. $params = array('variable = ?' => array($key));
  155. $data = api_get_settings_params($params);
  156. if (!empty($data)) {
  157. foreach ($data as $item) {
  158. $params = array('id' => $item['id'], 'access_url_changeable' => $changeable);
  159. api_set_setting_simple($params);
  160. }
  161. }
  162. }
  163. }
  164. //Reload settings
  165. $settings_array = get_settings($my_category);
  166. $settings = $settings_array['settings'];
  167. $settings_by_access_list = $settings_array['settings_by_access_list'];
  168. $form = generate_settings_form($settings, $settings_by_access_list, $settings_to_avoid, $convert_byte_to_mega_list);
  169. }
  170. }
  171. if (isset($_FILES['pdf_export_watermark_path'])) {
  172. $pdf_export_watermark_path = $_FILES['pdf_export_watermark_path'];
  173. }
  174. if (isset($pdf_export_watermark_path) && !empty($pdf_export_watermark_path['name'])) {
  175. $pdf_export_watermark_path_result = PDF::upload_watermark(
  176. $pdf_export_watermark_path['name'],
  177. $pdf_export_watermark_path['tmp_name']
  178. );
  179. if ($pdf_export_watermark_path_result) {
  180. $message['confirmation'][] = get_lang('UplUploadSucceeded');
  181. } else {
  182. $message['warning'][] = get_lang('UplUnableToSaveFile').' '.get_lang('Folder').': '.api_get_path(SYS_DEFAULT_COURSE_DOCUMENT_PATH).'/images';
  183. }
  184. unset($update_values['pdf_export_watermark_path']);
  185. }
  186. // Set true for allow_message_tool variable if social tool is actived
  187. foreach ($convert_byte_to_mega_list as $item) {
  188. if (isset($values[$item])) {
  189. $values[$item] = round($values[$item] * 1024 * 1024);
  190. }
  191. }
  192. if (isset($values['allow_social_tool']) && $values['allow_social_tool'] == 'true') {
  193. $values['allow_message_tool'] = 'true';
  194. }
  195. foreach ($settings as $item) {
  196. $key = $item['variable'];
  197. if (in_array($key, $settings_to_avoid)) {
  198. continue;
  199. }
  200. if ($key == 'search_field' or $key == 'submit_fixed_in_bottom') {
  201. continue;
  202. }
  203. $key = Database::escape_string($key);
  204. $sql = "UPDATE $table_settings_current SET selected_value = 'false'
  205. WHERE variable = '".$key."' AND access_url = ".intval($url_id)." AND type IN ('checkbox', 'radio') ";
  206. $res = Database::query($sql);
  207. }
  208. // Save the settings.
  209. $keys = array();
  210. foreach ($values as $key => $value) {
  211. if (in_array($key, $settings_to_avoid)) {
  212. continue;
  213. }
  214. // Avoid form elements which have nothing to do with settings
  215. if ($key == 'search_field' or $key == 'submit_fixed_in_bottom') {
  216. continue;
  217. }
  218. // Treat gradebook values in separate function.
  219. //if (strpos($key, 'gradebook_score_display_custom_values') === false) {
  220. if (!is_array($value)) {
  221. $old_value = api_get_setting($key);
  222. switch ($key) {
  223. case 'header_extra_content':
  224. file_put_contents(
  225. api_get_path(SYS_PATH).api_get_home_path().'/header_extra_content.txt',
  226. $value
  227. );
  228. $value = api_get_home_path().'/header_extra_content.txt';
  229. break;
  230. case 'footer_extra_content':
  231. file_put_contents(
  232. api_get_path(SYS_PATH).api_get_home_path().'/footer_extra_content.txt',
  233. $value
  234. );
  235. $value = api_get_home_path().'/footer_extra_content.txt';
  236. break;
  237. // URL validation for some settings.
  238. case 'InstitutionUrl':
  239. case 'course_validation_terms_and_conditions_url':
  240. $value = trim(Security::remove_XSS($value));
  241. if ($value != '') {
  242. // Here we accept absolute URLs only.
  243. if (strpos($value, '://') === false) {
  244. $value = 'http://'.$value;
  245. }
  246. if (!api_valid_url($value, true)) {
  247. // If the new (non-empty) URL value is invalid, then the old URL value stays.
  248. $value = $old_value;
  249. }
  250. }
  251. // If the new URL value is empty, then it will be stored (i.e. the setting will be deleted).
  252. break;
  253. // Validation against e-mail address for some settings.
  254. case 'emailAdministrator':
  255. $value = trim(Security::remove_XSS($value));
  256. if ($value != '' && !api_valid_email($value)) {
  257. // If the new (non-empty) e-mail address is invalid, then the old e-mail address stays.
  258. // If the new e-mail address is empty, then it will be stored (i.e. the setting will be deleted).
  259. $value = $old_value;
  260. }
  261. break;
  262. }
  263. if ($old_value != $value) {
  264. $keys[] = $key;
  265. }
  266. $result = api_set_setting($key, $value, null, null, $url_id);
  267. } else {
  268. $sql = "SELECT subkey FROM $table_settings_current WHERE variable = '$key'";
  269. $res = Database::query($sql);
  270. while ($row_subkeys = Database::fetch_array($res)) {
  271. // If subkey is changed:
  272. if ((isset($value[$row_subkeys['subkey']]) && api_get_setting(
  273. $key,
  274. $row_subkeys['subkey']
  275. ) == 'false') ||
  276. (!isset($value[$row_subkeys['subkey']]) && api_get_setting(
  277. $key,
  278. $row_subkeys['subkey']
  279. ) == 'true')
  280. ) {
  281. $keys[] = $key;
  282. break;
  283. }
  284. }
  285. foreach ($value as $subkey => $subvalue) {
  286. $result = api_set_setting($key, 'true', $subkey, null, $url_id);
  287. }
  288. }
  289. }
  290. // Add event configuration settings category to the system log.
  291. $user_id = api_get_user_id();
  292. $category = $_GET['category'];
  293. event_system(
  294. LOG_CONFIGURATION_SETTINGS_CHANGE,
  295. LOG_CONFIGURATION_SETTINGS_CATEGORY,
  296. $category,
  297. api_get_utc_datetime(),
  298. $user_id
  299. );
  300. api_set_setting_last_update();
  301. // Add event configuration settings variable to the system log.
  302. if (is_array($keys) && count($keys) > 0) {
  303. foreach ($keys as $variable) {
  304. if (in_array($key, $settings_to_avoid)) {
  305. continue;
  306. }
  307. event_system(
  308. LOG_CONFIGURATION_SETTINGS_CHANGE,
  309. LOG_CONFIGURATION_SETTINGS_VARIABLE,
  310. $variable,
  311. api_get_utc_datetime(),
  312. $user_id
  313. );
  314. }
  315. }
  316. }
  317. }
  318. $htmlHeadXtra[] = '<script>
  319. var hide_icon = "'.api_get_path(WEB_IMG_PATH).'shared_setting_na.png";
  320. var show_icon = "'.api_get_path(WEB_IMG_PATH).'shared_setting.png";
  321. var url = "'.api_get_path(WEB_AJAX_PATH).'admin.ajax.php?a=update_changeable_setting";
  322. $(function() {
  323. $(".share_this_setting").on("click", function() {
  324. var my_img = $(this).find("img");
  325. var link = $(this);
  326. $.ajax({
  327. url: url,
  328. data: { changeable: $(this).attr("data_status"), id: $(this).attr("data_to_send") },
  329. success: function(data) {
  330. if (data == 1) {
  331. if (link.attr("data_status") == 1) {
  332. my_img.attr("src", show_icon);
  333. link.attr("data_status", 0);
  334. } else {
  335. my_img.attr("src", hide_icon);
  336. link.attr("data_status", 1);
  337. }
  338. }
  339. }
  340. });
  341. });
  342. });
  343. </script>';
  344. // Including the header (banner).
  345. Display :: display_header($tool_name);
  346. // The action images.
  347. $action_images['platform'] = 'platform.png';
  348. $action_images['course'] = 'course.png';
  349. $action_images['session'] = 'session.png';
  350. $action_images['tools'] = 'tools.png';
  351. $action_images['user'] = 'user.png';
  352. $action_images['gradebook'] = 'gradebook.png';
  353. $action_images['ldap'] = 'ldap.png';
  354. $action_images['cas'] = 'user_access.png';
  355. $action_images['security'] = 'security.png';
  356. $action_images['languages'] = 'languages.png';
  357. $action_images['tuning'] = 'tuning.png';
  358. $action_images['templates'] = 'template.png';
  359. $action_images['search'] = 'search.png';
  360. $action_images['editor'] = 'html_editor.png';
  361. $action_images['timezones'] = 'timezone.png';
  362. $action_images['extra'] = 'wizard.png';
  363. $action_images['tracking'] = 'statistics.png';
  364. $action_images['gradebook'] = 'gradebook.png';
  365. $action_images['search'] = 'search.png';
  366. $action_images['stylesheets'] = 'stylesheets.png';
  367. $action_images['templates'] = 'template.png';
  368. $action_images['plugins'] = 'plugins.png';
  369. $action_images['shibboleth'] = 'shibboleth.png';
  370. $action_images['facebook'] = 'facebook.png';
  371. // @todo Use a different image.
  372. $action_images['logtransactions'] = 'tuning.png';
  373. $action_array = array();
  374. $resultcategories = array();
  375. $resultcategories[] = array('category' => 'Platform');
  376. $resultcategories[] = array('category' => 'Course');
  377. $resultcategories[] = array('category' => 'Session');
  378. $resultcategories[] = array('category' => 'Languages');
  379. $resultcategories[] = array('category' => 'User');
  380. $resultcategories[] = array('category' => 'Tools');
  381. $resultcategories[] = array('category' => 'Editor');
  382. $resultcategories[] = array('category' => 'Security');
  383. $resultcategories[] = array('category' => 'Tuning');
  384. $resultcategories[] = array('category' => 'Gradebook');
  385. $resultcategories[] = array('category' => 'Timezones');
  386. $resultcategories[] = array('category' => 'Tracking');
  387. $resultcategories[] = array('category' => 'Search');
  388. $resultcategories[] = array('category' => 'Stylesheets');
  389. $resultcategories[] = array('category' => 'Templates');
  390. $resultcategories[] = array('category' => 'Plugins');
  391. $resultcategories[] = array('category' => 'LDAP');
  392. $resultcategories[] = array('category' => 'CAS');
  393. $resultcategories[] = array('category' => 'Shibboleth');
  394. $resultcategories[] = array('category' => 'Facebook');
  395. $resultcategories[] = array('category' => 'LogTransactions');
  396. foreach ($resultcategories as $row) {
  397. $url = array();
  398. $url['url'] = api_get_self()."?category=".$row['category'];
  399. $url['content'] = Display::return_icon(
  400. $action_images[strtolower($row['category'])],
  401. api_ucfirst(get_lang($row['category'])),
  402. '',
  403. ICON_SIZE_MEDIUM
  404. );
  405. if (strtolower($row['category']) == strtolower($_GET['category'])) {
  406. $url['active'] = true;
  407. }
  408. $action_array[] = $url;
  409. }
  410. echo Display::actions($action_array);
  411. echo '<br />';
  412. echo $form_search_html;
  413. if ($watermark_deleted) {
  414. Display :: display_normal_message(get_lang('FileDeleted'));
  415. }
  416. // Displaying the message that the settings have been stored.
  417. if (isset($form) && $form->validate()) {
  418. Display::display_confirmation_message(get_lang('SettingsStored'));
  419. if (is_array($message)) {
  420. foreach ($message as $type => $content) {
  421. foreach ($content as $msg) {
  422. echo Display::return_message($msg, $type);
  423. }
  424. }
  425. }
  426. }
  427. if (!empty($_GET['category'])) {
  428. switch ($_GET['category']) {
  429. case 'Regions':
  430. handle_regions();
  431. break;
  432. case 'Plugins':
  433. // Displaying the extensions: Plugins.
  434. // This will be available to all the sites (access_urls).
  435. if (isset($_POST['submit_dashboard_plugins'])) {
  436. $affected_rows = DashboardManager::store_dashboard_plugins($_POST);
  437. if ($affected_rows) {
  438. // add event to system log
  439. $user_id = api_get_user_id();
  440. $category = $_GET['category'];
  441. event_system(
  442. LOG_CONFIGURATION_SETTINGS_CHANGE,
  443. LOG_CONFIGURATION_SETTINGS_CATEGORY,
  444. $category,
  445. api_get_utc_datetime(),
  446. $user_id
  447. );
  448. Display :: display_confirmation_message(get_lang('DashboardPluginsHaveBeenUpdatedSucesslly'));
  449. }
  450. }
  451. echo '<script>
  452. $(function(){
  453. $("#tabs").tabs();
  454. });
  455. </script>';
  456. echo '<div id="tabs">';
  457. echo '<ul>';
  458. echo '<li><a href="#tabs-1">'.get_lang('Plugins').'</a></li>';
  459. echo '<li><a href="#tabs-2">'.get_lang('DashboardPlugins').'</a></li>';
  460. echo '<li><a href="#tabs-3">'.get_lang('ConfigureExtensions').'</a></li>';
  461. echo '</ul>';
  462. echo '<div id="tabs-1">';
  463. handle_plugins();
  464. echo '</div>';
  465. echo '<div id="tabs-2">';
  466. DashboardManager::handle_dashboard_plugins();
  467. echo '</div>';
  468. echo '<div id="tabs-3">';
  469. handle_extensions();
  470. echo '</div>';
  471. echo '</div>';
  472. break;
  473. case 'Stylesheets':
  474. // Displaying the extensions: Stylesheets.
  475. handle_stylesheets();
  476. if (isset($_POST)) {
  477. api_set_setting_last_update();
  478. }
  479. $form->display();
  480. break;
  481. case 'Search':
  482. handle_search();
  483. break;
  484. case 'Templates':
  485. handle_templates();
  486. break;
  487. case 'search_setting':
  488. search_setting($_REQUEST['search_field']);
  489. if (isset($_REQUEST['search_field'])) {
  490. $form->display();
  491. }
  492. break;
  493. default:
  494. if (isset($form)) {
  495. $form->display();
  496. }
  497. }
  498. }
  499. /* FOOTER */
  500. Display :: display_footer();