// ajax process off adminaccess is now in the controller
This commit is contained in:
@@ -996,85 +996,3 @@ if (Tools::isSubmit('ajaxUpdateTaxRule'))
|
|||||||
die(Tools::jsonEncode($output));
|
die(Tools::jsonEncode($output));
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Update Access Tabs */
|
|
||||||
if (Tools::isSubmit('submitAddAccess'))
|
|
||||||
{
|
|
||||||
$perm = Tools::getValue('perm');
|
|
||||||
if (!in_array($perm, array('view', 'add', 'edit', 'delete', 'all')))
|
|
||||||
throw new PrestashopException('permission not exists');
|
|
||||||
|
|
||||||
$enabled = (int)Tools::getValue('enabled');
|
|
||||||
$id_tab = (int)Tools::getValue('id_tab');
|
|
||||||
$id_profile = (int)Tools::getValue('id_profile');
|
|
||||||
$res = true;
|
|
||||||
|
|
||||||
if ($id_tab == -1 && $perm == 'all' && $enabled == 0)
|
|
||||||
$res &= Db::getInstance()->execute('
|
|
||||||
UPDATE `'._DB_PREFIX_.'access`
|
|
||||||
SET `view` = '.$enabled.', `add` = '.$enabled.', `edit` = '.$enabled.', `delete` = '.$enabled.'
|
|
||||||
WHERE `id_profile` = '.(int)$id_profile.' AND `id_tab` != 31
|
|
||||||
');
|
|
||||||
else if ($id_tab == -1 && $perm == 'all')
|
|
||||||
$res &= Db::getInstance()->execute('
|
|
||||||
UPDATE `'._DB_PREFIX_.'access`
|
|
||||||
SET `view` = '.$enabled.', `add` = '.$enabled.', `edit` = '.$enabled.', `delete` = '.$enabled.'
|
|
||||||
WHERE `id_profile` = '.(int)$id_profile
|
|
||||||
);
|
|
||||||
else if ($id_tab == -1)
|
|
||||||
$res &= Db::getInstance()->execute('
|
|
||||||
UPDATE `'._DB_PREFIX_.'access`
|
|
||||||
SET `'.pSQL($perm).'` = '.$enabled.'
|
|
||||||
WHERE `id_profile` = '.(int)$id_profile
|
|
||||||
);
|
|
||||||
else if ($perm == 'all')
|
|
||||||
$res &= Db::getInstance()->execute('
|
|
||||||
UPDATE `'._DB_PREFIX_.'access`
|
|
||||||
SET `view` = '.$enabled.', `add` = '.$enabled.', `edit` = '.$enabled.', `delete` = '.$enabled.'
|
|
||||||
WHERE `id_tab` = '.(int)$id_tab.'
|
|
||||||
AND `id_profile` = '.(int)$id_profile
|
|
||||||
);
|
|
||||||
else
|
|
||||||
$res &= Db::getInstance()->execute('
|
|
||||||
UPDATE `'._DB_PREFIX_.'access`
|
|
||||||
SET `'.pSQL($perm).'` = '.$enabled.'
|
|
||||||
WHERE `id_tab` = '.(int)$id_tab.'
|
|
||||||
AND `id_profile` = '.(int)$id_profile
|
|
||||||
);
|
|
||||||
$res = $res?'ok':'error';
|
|
||||||
die($res);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Update Access Modules */
|
|
||||||
if (Tools::isSubmit('changeModuleAccess'))
|
|
||||||
{
|
|
||||||
$perm = Tools::getValue('perm');
|
|
||||||
$enabled = (int)Tools::getValue('enabled');
|
|
||||||
$id_module = (int)Tools::getValue('id_module');
|
|
||||||
$id_profile = (int)Tools::getValue('id_profile');
|
|
||||||
$res = true;
|
|
||||||
|
|
||||||
if (!in_array($perm, array('view', 'configure')))
|
|
||||||
throw new PrestashopException('permission not exists');
|
|
||||||
|
|
||||||
if ($id_module == -1)
|
|
||||||
{
|
|
||||||
$res &= Db::getInstance()->execute('
|
|
||||||
UPDATE `'._DB_PREFIX_.'module_access`
|
|
||||||
SET `'.pSQL($perm).'` = '.(int)$enabled.'
|
|
||||||
WHERE `id_profile` = '.(int)$id_profile
|
|
||||||
);
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
$res &= Db::getInstance()->execute('
|
|
||||||
UPDATE `'._DB_PREFIX_.'module_access`
|
|
||||||
SET `'.pSQL($perm).'` = '.(int)$enabled.'
|
|
||||||
WHERE `id_module` = '.(int)$id_module.'
|
|
||||||
AND `id_profile` = '.(int)$id_profile
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
$res = $res?'ok':'error';
|
|
||||||
die($res);
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|||||||
@@ -51,7 +51,7 @@
|
|||||||
perfect_access_js_gestion(this, perm, id_tab, tabsize, tabnumber, table);
|
perfect_access_js_gestion(this, perm, id_tab, tabsize, tabnumber, table);
|
||||||
|
|
||||||
$.ajax({
|
$.ajax({
|
||||||
url: "ajax.php",
|
url: "{$link->getAdminLink('AdminAccess')}",
|
||||||
cache: false,
|
cache: false,
|
||||||
data : {
|
data : {
|
||||||
ajaxMode : '1',
|
ajaxMode : '1',
|
||||||
@@ -59,7 +59,10 @@
|
|||||||
id_profile: id_profile,
|
id_profile: id_profile,
|
||||||
perm: perm,
|
perm: perm,
|
||||||
enabled: enabled,
|
enabled: enabled,
|
||||||
submitAddAccess: '1'
|
submitAddAccess: '1',
|
||||||
|
action: 'updateAccess',
|
||||||
|
ajax: '1',
|
||||||
|
token: '{getAdminToken tab='AdminAccess'}',
|
||||||
},
|
},
|
||||||
success : function(res,textStatus,jqXHR)
|
success : function(res,textStatus,jqXHR)
|
||||||
{
|
{
|
||||||
@@ -96,7 +99,7 @@
|
|||||||
});
|
});
|
||||||
|
|
||||||
$.ajax({
|
$.ajax({
|
||||||
url: "ajax.php",
|
url: "{$link->getAdminLink('AdminAccess')}",
|
||||||
cache: false,
|
cache: false,
|
||||||
data : {
|
data : {
|
||||||
ajaxMode: '1',
|
ajaxMode: '1',
|
||||||
@@ -105,6 +108,9 @@
|
|||||||
enabled: enabled,
|
enabled: enabled,
|
||||||
id_profile: id_profile,
|
id_profile: id_profile,
|
||||||
changeModuleAccess: '1',
|
changeModuleAccess: '1',
|
||||||
|
action: 'updateModuleAccess',
|
||||||
|
ajax: '1',
|
||||||
|
token: '{getAdminToken tab='AdminAccess'}',
|
||||||
},
|
},
|
||||||
success : function(res,textStatus,jqXHR)
|
success : function(res,textStatus,jqXHR)
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -69,7 +69,8 @@ class AdminAccessController extends AdminController
|
|||||||
'admin_profile' => (int)_PS_ADMIN_PROFILE_,
|
'admin_profile' => (int)_PS_ADMIN_PROFILE_,
|
||||||
'access_edit' => $this->tabAccess['edit'],
|
'access_edit' => $this->tabAccess['edit'],
|
||||||
'perms' => array('view', 'add', 'edit', 'delete'),
|
'perms' => array('view', 'add', 'edit', 'delete'),
|
||||||
'modules' => $modules
|
'modules' => $modules,
|
||||||
|
'link' => $this->context->link
|
||||||
);
|
);
|
||||||
|
|
||||||
return parent::initForm();
|
return parent::initForm();
|
||||||
@@ -98,6 +99,99 @@ class AdminAccessController extends AdminController
|
|||||||
));
|
));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function ajaxProcessUpdateAccess()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] != '1')
|
||||||
|
throw new PrestashopException(Tools::displayError('You do not have permission to edit here.'));
|
||||||
|
|
||||||
|
if (Tools::isSubmit('submitAddAccess'))
|
||||||
|
{
|
||||||
|
$perm = Tools::getValue('perm');
|
||||||
|
if (!in_array($perm, array('view', 'add', 'edit', 'delete', 'all')))
|
||||||
|
throw new PrestashopException('permission not exists');
|
||||||
|
|
||||||
|
$enabled = (int)Tools::getValue('enabled');
|
||||||
|
$id_tab = (int)Tools::getValue('id_tab');
|
||||||
|
$id_profile = (int)Tools::getValue('id_profile');
|
||||||
|
$res = true;
|
||||||
|
|
||||||
|
if ($id_tab == -1 && $perm == 'all' && $enabled == 0)
|
||||||
|
$res &= Db::getInstance()->execute('
|
||||||
|
UPDATE `'._DB_PREFIX_.'access`
|
||||||
|
SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.'
|
||||||
|
WHERE `id_profile` = '.(int)$id_profile.' AND `id_tab` != 31
|
||||||
|
');
|
||||||
|
else if ($id_tab == -1 && $perm == 'all')
|
||||||
|
$res &= Db::getInstance()->execute('
|
||||||
|
UPDATE `'._DB_PREFIX_.'access`
|
||||||
|
SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.'
|
||||||
|
WHERE `id_profile` = '.(int)$id_profile
|
||||||
|
);
|
||||||
|
else if ($id_tab == -1)
|
||||||
|
$res &= Db::getInstance()->execute('
|
||||||
|
UPDATE `'._DB_PREFIX_.'access`
|
||||||
|
SET `'.bqSQL($perm).'` = '.(int)$enabled.'
|
||||||
|
WHERE `id_profile` = '.(int)$id_profile
|
||||||
|
);
|
||||||
|
else if ($perm == 'all')
|
||||||
|
$res &= Db::getInstance()->execute('
|
||||||
|
UPDATE `'._DB_PREFIX_.'access`
|
||||||
|
SET `view` = '.(int)$enabled.', `add` = '.(int)$enabled.', `edit` = '.(int)$enabled.', `delete` = '.(int)$enabled.'
|
||||||
|
WHERE `id_tab` = '.(int)$id_tab.'
|
||||||
|
AND `id_profile` = '.(int)$id_profile
|
||||||
|
);
|
||||||
|
else
|
||||||
|
$res &= Db::getInstance()->execute('
|
||||||
|
UPDATE `'._DB_PREFIX_.'access`
|
||||||
|
SET `'.bqSQL($perm).'` = '.(int)$enabled.'
|
||||||
|
WHERE `id_tab` = '.(int)$id_tab.'
|
||||||
|
AND `id_profile` = '.(int)$id_profile
|
||||||
|
);
|
||||||
|
$res = $res?'ok':'error';
|
||||||
|
die($res);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public function ajaxProcessUpdateModuleAccess()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] != '1')
|
||||||
|
throw new PrestashopException(Tools::displayError('You do not have permission to edit here.'));
|
||||||
|
/* Update Access Modules */
|
||||||
|
|
||||||
|
if (Tools::isSubmit('changeModuleAccess'))
|
||||||
|
{
|
||||||
|
$perm = Tools::getValue('perm');
|
||||||
|
$enabled = (int)Tools::getValue('enabled');
|
||||||
|
$id_module = (int)Tools::getValue('id_module');
|
||||||
|
$id_profile = (int)Tools::getValue('id_profile');
|
||||||
|
$res = true;
|
||||||
|
|
||||||
|
if (!in_array($perm, array('view', 'configure')))
|
||||||
|
throw new PrestashopException('permission not exists');
|
||||||
|
|
||||||
|
if ($id_module == -1)
|
||||||
|
{
|
||||||
|
$res &= Db::getInstance()->execute('
|
||||||
|
UPDATE `'._DB_PREFIX_.'module_access`
|
||||||
|
SET `'.bqSQL($perm).'` = '.(int)$enabled.'
|
||||||
|
WHERE `id_profile` = '.(int)$id_profile
|
||||||
|
);
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
$res &= Db::getInstance()->execute('
|
||||||
|
UPDATE `'._DB_PREFIX_.'module_access`
|
||||||
|
SET `'.bqSQL($perm).'` = '.(int)$enabled.'
|
||||||
|
WHERE `id_module` = '.(int)$id_module.'
|
||||||
|
AND `id_profile` = '.(int)$id_profile
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
$res = $res?'ok':'error';
|
||||||
|
die($res);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get the current profile id
|
* Get the current profile id
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -182,6 +182,8 @@ class AdminCartsController extends AdminController
|
|||||||
}
|
}
|
||||||
|
|
||||||
public function ajaxPreProcess()
|
public function ajaxPreProcess()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$id_customer = (int)Tools::getValue('id_customer');
|
$id_customer = (int)Tools::getValue('id_customer');
|
||||||
$customer = new Customer((int)$id_customer);
|
$customer = new Customer((int)$id_customer);
|
||||||
@@ -216,10 +218,12 @@ class AdminCartsController extends AdminController
|
|||||||
$this->context->cart->save();
|
$this->context->cart->save();
|
||||||
$currency = new Currency((int)$this->context->cart->id_currency);
|
$currency = new Currency((int)$this->context->cart->id_currency);
|
||||||
$this->context->currency = $currency;
|
$this->context->currency = $currency;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public function ajaxProcessDeleteProduct()
|
public function ajaxProcessDeleteProduct()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$errors = array();
|
$errors = array();
|
||||||
if (!$id_product = (int)Tools::getValue('id_product') || !$id_product_attribute = (int)Tools::getValue('id_product_attribute'))
|
if (!$id_product = (int)Tools::getValue('id_product') || !$id_product_attribute = (int)Tools::getValue('id_product_attribute'))
|
||||||
@@ -230,8 +234,11 @@ class AdminCartsController extends AdminController
|
|||||||
if ($this->context->cart->deleteProduct($id_product, $id_product_attribute))
|
if ($this->context->cart->deleteProduct($id_product, $id_product_attribute))
|
||||||
echo Tools::jsonEncode($this->ajaxReturnVars());
|
echo Tools::jsonEncode($this->ajaxReturnVars());
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
public function ajaxProcessUpdateQty()
|
public function ajaxProcessUpdateQty()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$errors = array();
|
$errors = array();
|
||||||
if (!$this->context->cart->id)
|
if (!$this->context->cart->id)
|
||||||
@@ -267,10 +274,12 @@ class AdminCartsController extends AdminController
|
|||||||
}
|
}
|
||||||
|
|
||||||
echo Tools::jsonEncode(array_merge($this->ajaxReturnVars(), array('errors' => $errors)));
|
echo Tools::jsonEncode(array_merge($this->ajaxReturnVars(), array('errors' => $errors)));
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public function ajaxProcessUpdateCarrier()
|
public function ajaxProcessUpdateCarrier()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
if (Validate::isBool(($recyclable = (int)Tools::getValue('recyclable'))))
|
if (Validate::isBool(($recyclable = (int)Tools::getValue('recyclable'))))
|
||||||
$this->context->cart->recyclable = $recyclable;
|
$this->context->cart->recyclable = $recyclable;
|
||||||
@@ -281,8 +290,11 @@ class AdminCartsController extends AdminController
|
|||||||
$this->context->cart->save();
|
$this->context->cart->save();
|
||||||
echo Tools::jsonEncode($this->ajaxReturnVars());
|
echo Tools::jsonEncode($this->ajaxReturnVars());
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
public function ajaxProcessUpdateCurrency()
|
public function ajaxProcessUpdateCurrency()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$currency = new Currency((int)Tools::getValue('id_currency'));
|
$currency = new Currency((int)Tools::getValue('id_currency'));
|
||||||
if (Validate::isLoadedObject($currency) && !$currency->deleted && $currency->active)
|
if (Validate::isLoadedObject($currency) && !$currency->deleted && $currency->active)
|
||||||
@@ -292,7 +304,10 @@ class AdminCartsController extends AdminController
|
|||||||
}
|
}
|
||||||
echo Tools::jsonEncode($this->ajaxReturnVars());
|
echo Tools::jsonEncode($this->ajaxReturnVars());
|
||||||
}
|
}
|
||||||
|
}
|
||||||
public function ajaxProcessUpdateLang()
|
public function ajaxProcessUpdateLang()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$lang = new Language((int)Tools::getValue('id_lang'));
|
$lang = new Language((int)Tools::getValue('id_lang'));
|
||||||
if (Validate::isLoadedObject($lang) && $lang->active)
|
if (Validate::isLoadedObject($lang) && $lang->active)
|
||||||
@@ -302,7 +317,10 @@ class AdminCartsController extends AdminController
|
|||||||
}
|
}
|
||||||
echo Tools::jsonEncode($this->ajaxReturnVars());
|
echo Tools::jsonEncode($this->ajaxReturnVars());
|
||||||
}
|
}
|
||||||
|
}
|
||||||
public function ajaxProcessDuplicateOrder()
|
public function ajaxProcessDuplicateOrder()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$errors = array();
|
$errors = array();
|
||||||
if (!$id_order = Tools::getValue('id_order'))
|
if (!$id_order = Tools::getValue('id_order'))
|
||||||
@@ -318,16 +336,22 @@ class AdminCartsController extends AdminController
|
|||||||
$this->context->cart = $new_cart['cart'];
|
$this->context->cart = $new_cart['cart'];
|
||||||
echo Tools::jsonEncode($this->ajaxReturnVars());
|
echo Tools::jsonEncode($this->ajaxReturnVars());
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
public function ajaxProcessDeleteVoucher()
|
public function ajaxProcessDeleteVoucher()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
if ($this->context->cart->removeCartRule((int)Tools::getValue('id_cart_rule')))
|
if ($this->context->cart->removeCartRule((int)Tools::getValue('id_cart_rule')))
|
||||||
echo Tools::jsonEncode($this->ajaxReturnVars());
|
echo Tools::jsonEncode($this->ajaxReturnVars());
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
public function ajaxProcessAddVoucher()
|
public function ajaxProcessAddVoucher()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$errors = array();
|
$errors = array();
|
||||||
$customer = new Customer((int)$this->context->cart->id_customer);
|
$customer = new Customer((int)$this->context->cart->id_customer);
|
||||||
@@ -341,8 +365,11 @@ class AdminCartsController extends AdminController
|
|||||||
$errors[] = Tools::displayError('Can\'t add the voucher');
|
$errors[] = Tools::displayError('Can\'t add the voucher');
|
||||||
echo Tools::jsonEncode(array_merge($this->ajaxReturnVars(), array('errors' => $errors)));
|
echo Tools::jsonEncode(array_merge($this->ajaxReturnVars(), array('errors' => $errors)));
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
public function ajaxProcessUpdateAddresses()
|
public function ajaxProcessUpdateAddresses()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
if (($id_address_delivery = (int)Tools::getValue('id_address_delivery')) &&
|
if (($id_address_delivery = (int)Tools::getValue('id_address_delivery')) &&
|
||||||
$address_delivery = new Address((int)$id_address_delivery) &&
|
$address_delivery = new Address((int)$id_address_delivery) &&
|
||||||
@@ -357,6 +384,7 @@ class AdminCartsController extends AdminController
|
|||||||
|
|
||||||
echo Tools::jsonEncode($this->ajaxReturnVars());
|
echo Tools::jsonEncode($this->ajaxReturnVars());
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
protected function getCartSummary()
|
protected function getCartSummary()
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -603,6 +603,8 @@ class AdminOrdersControllerCore extends AdminController
|
|||||||
}
|
}
|
||||||
|
|
||||||
public function ajaxProcessSendMailValidateOrder()
|
public function ajaxProcessSendMailValidateOrder()
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$errors = array();
|
$errors = array();
|
||||||
$cart = new Cart((int)Tools::getValue('id_cart'));
|
$cart = new Cart((int)Tools::getValue('id_cart'));
|
||||||
@@ -620,4 +622,5 @@ class AdminOrdersControllerCore extends AdminController
|
|||||||
}
|
}
|
||||||
$this->content = Tools::jsonEncode(array('errors' => true, 'result' => $this->l('Error in sending the email to your customer.')));
|
$this->content = Tools::jsonEncode(array('errors' => true, 'result' => $this->l('Error in sending the email to your customer.')));
|
||||||
}
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user