function checkInstallation() { if (!file_exists('configuration/db.php')) { doAlert('Configuration file missing!\\nHave you done the setup procedure?'); if (file_exists('setup.php')) { header('Location:setup.php'); } else { doAlert('Your installation is compromised!\\nPlease, restart setup or contact support'); } } else { return true; } }
<?php require_once '../configuration/db.php'; require_once '../configuration/ClassUser.php'; require_once '../function/funcs.php'; session_start(); checkLogin(); $user = new User(); setupUser($user); if (checkUserAdminOrSuperUser($user)) { echo "\n <html>\n <head>\n <title>OpenTroubleTicketing | Edit Categories</title>\n <meta charset='utf-8'>\n <meta name='viewport' content='width=device-width, initial-scale=1'>\n <link rel='icon' href='icon/icon.png'/>\n <link rel='stylesheet' href='../style/bootstrap.min.css'>\n <link rel='stylesheet' href='cpanelCategoryStyle.css'>\n <link rel='stylesheet' href='../style/defaultStyle.css'>\n <script src='../js/jquery.min.js'></script>\n <script src='../js/bootstrap.min.js'></script>\n <script src='cpanelCategoryScript.js'></script>\n <script src='../js/defaultScript.js'></script>\n </head>\n <body>"; if (!isset($_GET['catNameQuery'])) { echo "\n \n <div id='addCategory' class='container'>\n <h2 id='showCatMenu' class='entry'>Add a new category</h2>\n <div class='container' id='newCat'>\n <form role='form'>\n <div class='form-group'>\n <label for='catName'>Enter the category's name</label>\n <input type='text' class='form-control' id='catName' size='10'> \n </div>\n <div class='form-group'>\n <label for='catDesc'>Enter the category's description</label>\n <textarea row='4' cols='4' class='form-control' id='catDesc' size='500'></textarea> \n </div>\n <div class='form-group'>\n <input type='button' value='INSERT' class='btn btn-warning btn-sm' id='insertCat'>\n </div>\n </form>\n </div> \n </div>\n <div id='showCategories' class='container'>\n <h2 id='showAllCats' class='entry'>Show all categories</h2>\n <div class='container' id='catTable'></div>\n </div>\n </body>\n </html>\n "; } else { $catNameEdit = $_GET['catNameQuery']; $connection = new mysqli(HOST, USER, PSW, DB); $query = "SELECT description FROM category WHERE name='" . $catNameEdit . "'"; $exec = $connection->query($query); $res = $exec->fetch_assoc(); echo "\n <div id='editCategory' class='container'>\n <form role='form'>\n <div class='form-group'>\n <label for='catName'>Edit name:</label>\n <input type='text' class='form-control' id='catName' size='10' value='" . $catNameEdit . "'>\n <input type='text' id='originalCatName' class='hidden' value='" . $catNameEdit . "'>\n </div>\n <div class='form-group'>\n <label for='catDesc'>Edit description:</label>\n <textarea row='4' cols='4' class='form-control' id='catDesc' size='500'>" . $res['description'] . "</textarea>\n <textarea row='4' cols='4' class='hidden' id='originalCatDesc' size='500'>" . $res['description'] . "</textarea> \n </div>\n <div class='form-group'>\n <input type='button' value='EDIT' class='btn btn-warning btn-sm' id='editCat'>\n <input type='button' value='DELETE' class='btn btn-danger btn-sm' id='deleteCat'>\n <button class='btn btn-info btn-sm' id='close'>CLOSE</button>\n </div>\n </form>\n </div> \n </div>\n "; $connection->close(); } } else { echo doAlert('You don\'t have the rights to do this'); }
<span class="icon-bar"></span> </button> <a class="navbar-brand" href="#"><?php echo getBoardName(); ?> </a> </div> <?php if (!checkFirstSetup()) { echo "\n <!-- Collect the nav links, forms, and other content for toggling -->\n <div class='collapse navbar-collapse navbar-ex1-collapse'>\n <ul class='nav navbar-nav'>\n <li class='dropdown'>\n <a href='#' class='dropdown-toggle' data-toggle='dropdown'>New..<b class='caret'></b></a>\n <ul class='dropdown-menu'>\n <li><a href='#' id='tktNew'>Ticket</a></li>\n "; if ($user->getPosition() == 'admin' || $user->getPosition() == 'superuser') { echo "\n <li><a href='#' id='customerNew'>Customer</a></li>\n <li><a href='#' id='assetNew'>Asset</a></li>"; } echo " \n </ul>\n </li>\n <li class='dropdown'>\n <a href='#' class='dropdown-toggle' data-toggle='dropdown'>List Custom<b class='caret'></b></a>\n <ul class='dropdown-menu'>\n <li><a href='#'>list</a></li>\n <li><a href='#'>something</a></li>\n <li><a href='#'>custom</a></li>\n <li><a href='#'>TO DO</a></li>\n </ul>\n </li>\n </ul>\n <form class='navbar-form navbar-left' role='search'>\n <div class='form-group'>\n <input type='text' class='form-control' data-toggle='tooltip' data-placement='bottom' title='You can use any parameter to search a ticket' id='ticketField' placeholder='Search Ticket'>\n </div>\n <button type='submit' id='searchTicket' class='btn btn-default'>Go</button>\n </form>\n <form class='navbar-form navbar-left' role='search'>\n <div class='form-group'>\n <input type='text' class='form-control' data-toggle='tooltip' data-placement='bottom' title='You can use any parameter to search a customer' id='customerField' placeholder='Search Customer'>\n </div>\n <button type='submit' id='searchCustomer' class='btn btn-default'>Go</button>\n </form>\n <form class='navbar-form navbar-left' role='search'>\n <div class='form-group'>\n <input type='text' class='form-control'data-toggle='tooltip' data-placement='bottom' title='You can use any parameter to search an asset' id='assetField' placeholder='Search Asset'>\n </div>\n <button type='submit' id='searchAsset' class='btn btn-default'>Go</button>\n </form>\n "; } else { doAlert('An admin must complete the first setup procedure.\\nUse the control panel on the right!'); } ?> <ul class='nav navbar-nav navbar-right'> <?php if ($user->getPosition() == 'admin' || $user->getPosition() == 'superuser') { echo " \n <li><a href='#cpanel' id='cpanelButton'>Control Panel</a></li>"; } ?> <li class='dropdown'> <a href='#' class='dropdown-toggle' data-toggle='dropdown'><?php echo $user->getName() . " " . $user->getSurname() . ""; ?> <b class='caret'></b></a> <ul class='dropdown-menu'> <li><a href='#'>Send a message</a></li>