source: extensions/NBC_UserAdvManager/trunk/main.inc.php @ 4281

Last change on this file since 4281 was 4281, checked in by Eric, 15 years ago

[NBC_UserAdvManager]

  • Bug 1238 fixed - Simple custom email text wasn't send when Extended Description plugin wasn't set.
  • Ending of IT translations
  • Property svn:eol-style set to LF
File size: 20.4 KB
Line 
1<?php
2/*
3Plugin Name: NBC UserAdvManager
4Version: 2.12.7
5Description: Renforcer les possibilités de gestion des utilisateurs - Enforce users management
6Plugin URI: http://fr.piwigo.org/ext/extension_view.php?eid=216
7Author: Nicco, Eric
8Author URI: http://gallery-nicco.no-ip.org, http://www.infernoweb.net
9*/
10
11/*
12 ***** Plugin history (branch 2.10)*****
13
14-- 2.10.0-beta : Initial beta release for Piwigo compatibility
15-- 2.10.1-beta : Small correction on generated path
16-- 2.10.2-beta : Bug resolved on register validation page
17
18-- 2.10.3 : Final and fully functional release
19                                                Bug resolved on plugin activation
20
21-- 2.10.4 : Bug fixed on profiles update
22
23-- 2.10.5 : Improved code on profiles update
24
25-- 2.10.6 : Old language packs (iso) deleted (forget from PWG 1.7.x version)
26
27-- 2.10.7 : Bug fixed on user's validation email sending
28
29-- 2.10.8 : ConfirmMail page looks better (Sylvia theme only)
30                                                Improved code for checking author on guest comments
31
32-- 2.10.9 : Bug fixed - Missing english translation
33                                                Bug fixed - Notice on forbidden characters function use
34                                                Bug fixed - Audit on forbidden characters in username didn't work
35                                                Adding of email provider exclusion (like *@hotmail.com) - Warning ! -> Known bug : This feature doesn't work on user profile page. So, already registered users can change their email address to a forbiden one.
36
37-- 2.10.9a : Email provider exclusion is no longer case sensitive
38
39-- 2.10.9b : Bug fixed - Home icon wasn't linked to gallery url in ConfirmMail page. If GALLERY_URL is not set, Home icon gets the pwg root path.
40
41-- 2.10.9c : Bug fixed - If Email provider exclusion is set off, new registered user will have a PHP notice on "Undefined variable: ncsemail"
42
43-- 2.10.9d : Code simplification - need no more ""template"" sub-directory in plugin directory for enhance "back link" icon in ConfirMail.tpl
44
45-- 2.10.9e : Compatibility improvement with PHP 5.3 - Some old functions will be deprecated like :
46                                                        ereg replaced by preg_match
47                                                        eregi replace by preg_match with "i" moderator
48                                                        split replace by preg_split
49                               
50-- 2.10.9f : Compatibility bug fixed when used with DynamicRecentPeriod plugin
51
52
53 ***** Plugin history (branch 2.11)*****
54
55-- 2.11.0 : New tabsheet menu to manage ConfirMail functions (setting a timeout without validation, Cleanup expired user's accounts, Force confirmation, Renew validation key, list unvalidated users,...)
56                                                Beautify plugin's main admin panel
57                                               
58-- 2.11.1 : Bug fixed with install and upgrade functions
59                                                Language files correction
60
61-- 2.11.2 : Bug fixed on bad query for unvalidated users display in unvalidated users list
62                                                Bug fixed : Sql syntax error on plugin activation
63
64-- 2.11.3 : On Patricia's request (french forum and bug 1173), the unvalidated users management tab shows users according with the settings of unvalidated group and / or unvalidated status.
65                                                Feature 1172 added : Email providers exclusion list can be set with CR/LF between each entry. The comma seperator (,) is still mandatory.
66                                                Bug 1175 fixed : Bad translation tag in french language file.
67                                                Improvement of unvalidated users management tab (feature 1174)- Expired users are displayed in red color text.
68
69-- 2.11.4 : Bug 1177 fixed : Width of excluded email providers list reset to ancient value (80 col)
70                                                Bug 1179 fixed : Adding a notice in plugin inline documentation for use of validation groups and status. A default group must be set in Piwigo's groups settings and the "Guest" (or another user) must be set as default for status values.
71                                                Bug 1182 fixed : Language tag missing in confirmation email generation
72
73-- 2.11.5 : Bug 1195 fixed : Registration displays the good title
74
75
76 ***** Plugin history (branch 2.12)*****
77
78-- 2.12.0 : Bug 1206 fixed : All plugin functionnalities work in user's profile page
79                Plugin's core code and admin panel refactoring
80                Password control and enforcement : A complexity score is computed on user registration. If this score is less than the goal set by admin, the password choosen is rejected.
81                Feature 1194 "Ghost Tracker" added : New plugin tab displays users who don't comes back to the gallery since x days. Ability to send email reminders and to delete reminded but "dead" users. It's the reason why this feature is called "Ghost Tracker".
82
83-- 2.12.1 : Rollback on admin panel improvement (it was a bad idea)
84
85-- 2.12.2 : Bug 1221 fixed - Adding of a new funtion to populate the lastvisit table on Ghost Tracker activation
86            Bug 1224 fixed - Error in database after plugin activation
87            Bug 1225 fixed - "Reminder" status don't change from "false" to "true" after the sent of a reminder email
88            Some code beautify (SQL requests and HTML 4 strict for tpl)
89
90-- 2.12.3 : Bug 1226 fixed - "duplicate key error" when lastvisit table is not empty and on using Ghost Tracker init function
91
92-- 2.12.4 : Adding a password field control for SendMail2User - Neighborhood plugin compatibility improvement
93            Bug 1229 fixed - Email was no longer mandatory when plugin was active, even if Piwigo's email madatory option was set.
94
95-- 2.12.5 : Bug 1233 fixed -  "duplicate key error" when a user wants to register with an existing username. In fact, all standard Piwigo's register controls didn't work when plugin was activated. That fixes this too.
96            Adding DE, ES and IT languages. All translations are not finalized and could be improved.
97            Adding of description.txt file in language directories.
98
99-- 2.12.6 : Bug 1236 fixed -  Admins was unable to add a new user in the user_list page.
100            Beginning of IT translations
101           
102-- 2.12.7 : Bug 1238 fixed -  Simple custom email text wasn't send when Extended Description plugin wasn't set.
103            Ending of IT translations
104*/
105
106/*
107
108 ***** TODO List *****
109++ No validation needed for admins users comments (new trigger needed in comments.php ?)
110
111++ No single email check for admins (new trigger needed in functions_user.inc.php ?)
112
113++ Password control and enforcement
114  ?? Can not be the same as username -> Could password score control be sufficient ?
115 
116++ Security : Blocking brut-force attacks !
117              -> Way to do that : Count the number of failed attempts to connect and lock the targetted account after x attempts. Where x will be settable by admin.
118              To unlock the locked account :
119               -> A new table in admin's plugin panel which would display the locked accounts.
120               -> Sending an email to account owner to inform him his account is blocked due to multiple failed connexions attempts. This email could have a link with a security key to unlock the account.
121               -> Both of above solutions ?
122
123++ Opportunity to copy a registered user for new user creation
124  ++ new copied user will (or not) belong to the same groups
125  ++ new copied user will (or not) get the same status (visitor, admin, webmaster, guest (??))
126  ++ new copied user will (or not) get the same properties
127  ++ new copied user will (or not) get the same language
128  ... and so on
129 
130*/
131
132
133if (!defined('PHPWG_ROOT_PATH'))
134{
135  die('Hacking attempt!');
136}
137
138define('NBC_UserAdvManager_DIR' , basename(dirname(__FILE__)));
139define('NBC_UserAdvManager_PATH' , PHPWG_PLUGINS_PATH.basename(dirname(__FILE__)).'/');
140
141include_once (NBC_UserAdvManager_PATH.'include/constants.php');
142include_once (NBC_UserAdvManager_PATH.'include/functions_UserAdvManager.inc.php');
143
144load_language('plugin.lang', NBC_UserAdvManager_PATH);
145
146
147/* Plugin admin */
148add_event_handler('get_admin_plugin_menu_links', 'nbc_UserAdvManager_admin_menu');
149
150function nbc_UserAdvManager_admin_menu($menu)
151{
152  array_push($menu,
153    array(
154      'NAME' => 'UserAdvManager',
155      'URL'  => get_admin_plugin_menu_link(NBC_UserAdvManager_PATH.'/admin/UserAdvManager_admin.php')
156    )
157  );
158
159  return $menu;
160}
161
162
163add_event_handler('loc_begin_index', 'UserAdvManager_GhostTracker');
164
165function UserAdvManager_GhostTracker()
166{
167  global $conf, $user;
168 
169  $conf_nbc_UserAdvManager = isset($conf['nbc_UserAdvManager']) ? explode(";" , $conf['nbc_UserAdvManager']) : array();
170
171  if (isset($conf_nbc_UserAdvManager[17]) and $conf_nbc_UserAdvManager[17] == 'true' and !is_admin() and !is_a_guest())
172  {
173
174    $userid = get_userid($user['username']);
175         
176    /* Looking for existing entry in last visit table */
177    $query = '
178SELECT *
179  FROM '.USER_LASTVISIT_TABLE.'
180WHERE user_id = '.$userid.'
181;';
182       
183    $count = mysql_num_rows(pwg_query($query));
184         
185    if ($count == 0)
186    {
187      /* If not, data are inserted in table */
188      $query = '
189INSERT INTO '.USER_LASTVISIT_TABLE.' (user_id, lastvisit, reminder)
190VALUES ('.$userid.', now(), "false")
191;';
192      pwg_query($query);
193    }
194    else if ($count > 0)
195    {
196      /* If yes, data are updated in table */
197      $query = '
198UPDATE '.USER_LASTVISIT_TABLE.'
199SET lastvisit = now(), reminder = "false"
200WHERE user_id = '.$userid.'
201LIMIT 1
202;';
203      pwg_query($query);
204    }
205  }
206}
207
208
209/* User creation */
210add_event_handler('register_user', 'UserAdvManager_Adduser');
211
212function UserAdvManager_Adduser($register_user)
213{
214  global $conf;
215 
216  $conf_nbc_UserAdvManager = isset($conf['nbc_UserAdvManager']) ? explode(";" , $conf['nbc_UserAdvManager']) : array();
217 
218  /* Sending registration confirmation by email */
219  if ((isset($conf_nbc_UserAdvManager[0]) and $conf_nbc_UserAdvManager[0] == 'true') or (isset($conf_nbc_UserAdvManager[2]) and $conf_nbc_UserAdvManager[2] == 'true'))
220  {
221    $passwd = (isset($_POST['password'])) ? $_POST['password'] : '';
222    SendMail2User(1, $register_user['id'], $register_user['username'], $passwd, $register_user['email'], true);
223  }
224}
225
226
227
228/* User deletion */
229add_event_handler('delete_user', 'UserAdvManager_Deluser');
230
231function UserAdvManager_Deluser($user_id)
232{
233  /* Cleanup for ConfirmMail table */
234  DeleteConfirmMail($user_id);
235  /* Cleanup for LastVisit table */
236  DeleteLastVisit($user_id);
237}
238
239
240/* Check users registration */
241add_event_handler('register_user_check', 'UserAdvManager_RegistrationCheck', EVENT_HANDLER_PRIORITY_NEUTRAL, 2);
242
243function UserAdvManager_RegistrationCheck($err, $user)
244{
245  global $errors, $conf;
246
247/* *********************************************************** */
248/* We need to reset the standard Piwigo's register controls    */
249/* because the call of register_user_check trigger resets them */
250/* *********************************************************** */
251  /* ********************************** */
252  /* Standard Piwigo's username control */
253  /* ********************************** */
254  if ($_POST['login'] == '')
255  {
256    return l10n('reg_err_login1');
257  }
258  if (preg_match('/^.* $/', $_POST['login']))
259  {
260    return l10n('reg_err_login2');
261  }
262  if (preg_match('/^ .*$/', $_POST['login']))
263  {
264    return l10n('reg_err_login3');
265  }
266  if (get_userid($_POST['login']))
267  {
268    return l10n('reg_err_login5');
269  }
270
271  if (script_basename() == 'admin' and isset($_GET['page']) and $_GET['page'] == 'user_list') /* not the same email variable if we are on users registration page or on admin's user registration page*/
272  {
273    /* ***************************** */
274    /* Standard Piwigo's email check */
275    /* ***************************** */
276    $atom   = '[-a-z0-9!#$%&\'*+\\/=?^_`{|}~]';   // before  arobase
277    $domain = '([a-z0-9]([-a-z0-9]*[a-z0-9]+)?)'; // domain name
278    $regex = '/^' . $atom . '+' . '(\.' . $atom . '+)*' . '@' . '(' . $domain . '{1,63}\.)+' . $domain . '{2,63}$/i';
279 
280    if (!preg_match($regex, $_POST['email']))
281    {
282      return l10n('reg_err_mail_address');
283    }
284   
285    if (!empty($_POST['email']))
286    {
287      $query = '
288select count(*)
289from '.USERS_TABLE.'
290where upper('.$conf['user_fields']['email'].') = upper(\''.$_POST['email'].'\');';
291      list($count) = mysql_fetch_array(pwg_query($query));
292      if ($count != 0)
293      {
294        return l10n('reg_err_mail_address_dbl');
295      }
296    }
297  }
298  else
299  {
300    /* ***************************** */
301    /* Standard Piwigo's email check */
302    /* ***************************** */
303    $atom   = '[-a-z0-9!#$%&\'*+\\/=?^_`{|}~]';   // before  arobase
304    $domain = '([a-z0-9]([-a-z0-9]*[a-z0-9]+)?)'; // domain name
305    $regex = '/^' . $atom . '+' . '(\.' . $atom . '+)*' . '@' . '(' . $domain . '{1,63}\.)+' . $domain . '{2,63}$/i';
306
307    if (!preg_match($regex, $_POST['mail_address']))
308    {
309      return l10n('reg_err_mail_address');
310    }
311   
312    if (!empty($_POST['mail_address']))
313    {
314      $query = '
315select count(*)
316from '.USERS_TABLE.'
317where upper('.$conf['user_fields']['email'].') = upper(\''.$_POST['mail_address'].'\');';
318      list($count) = mysql_fetch_array(pwg_query($query));
319      if ($count != 0)
320      {
321        return l10n('reg_err_mail_address_dbl');
322      }
323    }
324  }
325/* ****************************************** */
326/* End of Piwigo's standard register controls */
327/* ****************************************** */
328
329
330/* ****************************************** */
331/* Here begins the advanced register controls */
332/* ****************************************** */
333  $PasswordCheck = 0;
334 
335  $conf_nbc_UserAdvManager = isset($conf['nbc_UserAdvManager']) ? explode(";" , $conf['nbc_UserAdvManager']) : array();
336
337  /* Password enforcement control */
338  if (isset($conf_nbc_UserAdvManager[14]) and $conf_nbc_UserAdvManager[14] == 'true' and !empty($conf_nbc_UserAdvManager[15]))
339  {
340    if (!empty($user['password']) and !is_admin())
341    {
342      $PasswordCheck = testpassword($user['password']);
343 
344      if ($PasswordCheck < $conf_nbc_UserAdvManager[15])
345      {
346        $message = get_l10n_args('reg_err_login4_%s', $PasswordCheck);
347        return($lang['reg_err_pass'] = l10n_args($message).$conf_nbc_UserAdvManager[15]);
348      }
349    }
350    else if (!empty($user['password']) and is_admin() and isset($conf_nbc_UserAdvManager[16]) and $conf_nbc_UserAdvManager[16] == 'true')
351    { 
352      $PasswordCheck = testpassword($user['password']);
353 
354      if ($PasswordCheck < $conf_nbc_UserAdvManager[15])
355      {
356        $message = get_l10n_args('reg_err_login4_%s', $PasswordCheck);
357        return($lang['reg_err_pass'] = l10n_args($message).$conf_nbc_UserAdvManager[15]);
358      }
359    }
360  }
361
362  /* Username non case sensitive */
363  if (isset($conf_nbc_UserAdvManager[1]) and $conf_nbc_UserAdvManager[1] == 'true')
364  {
365    $new_username =  NotSensibleSearchUsername($_POST['login']);
366    $_POST['login'] = $new_username == '' ? $_POST['login'] : $new_username;
367  }
368
369  /* Username without forbidden keys */
370  if (isset($conf_nbc_UserAdvManager[7]) and $conf_nbc_UserAdvManager[7] == 'true' and !empty($_POST['login']) and !ValidateUsername($_POST['login']))
371  {
372    $_POST['login'] = '';
373    return($lang['reg_err_login1'] = l10n('reg_err_login6')."'".$conf_nbc_UserAdvManager[8]."'");
374  }
375
376  /* Email without forbidden domains */
377  if (isset($conf_nbc_UserAdvManager[12]) and $conf_nbc_UserAdvManager[12] == 'true' and !empty($_POST['mail_address']) and !ValidateEmailProvider($_POST['mail_address']))
378  {
379    //$_POST['mail_address'] = '';
380    return($lang['reg_err_login1'] = l10n('reg_err_login7')."'".$conf_nbc_UserAdvManager[13]."'");
381  }
382}
383
384
385if (script_basename() == 'profile')
386{
387  add_event_handler('loc_begin_profile', 'UserAdvManager_Profile_Init');
388
389  function UserAdvManager_Profile_Init()
390  {
391    global $conf, $user, $template;
392
393    $conf_nbc_UserAdvManager = isset($conf['nbc_UserAdvManager']) ? explode(";" , $conf['nbc_UserAdvManager']) : array();
394
395    if (isset($_POST['validate']))
396    {
397      /* Email without forbidden domains */
398      if (isset($conf_nbc_UserAdvManager[12]) and $conf_nbc_UserAdvManager[12] == 'true' and !empty($_POST['mail_address']))
399      {
400        if (!ValidateEmailProvider($_POST['mail_address']))
401        {
402          $template->append('errors', l10n('reg_err_login7')."'".$conf_nbc_UserAdvManager[13]."'");
403          unset($_POST['validate']);
404        }
405      }
406
407      $typemail = 3;
408     
409      if (!empty($_POST['use_new_pwd']))
410      {
411        $typemail = 2;
412       
413        /* Password enforcement control */
414        if (isset($conf_nbc_UserAdvManager[14]) and $conf_nbc_UserAdvManager[14] == 'true' and !empty($conf_nbc_UserAdvManager[15]))
415        {
416          $PasswordCheck = testpassword($_POST['use_new_pwd']);
417         
418          if ($PasswordCheck < $conf_nbc_UserAdvManager[15])
419          {
420            $message = get_l10n_args('reg_err_login4_%s', $PasswordCheck);
421            $template->append('errors', l10n_args($message).$conf_nbc_UserAdvManager[15]);
422            unset($_POST['use_new_pwd']);
423            unset($_POST['validate']);
424          }
425        }
426      }
427     
428      /* Sending registration confirmation by email */
429      if (( isset($conf_nbc_UserAdvManager[0]) and $conf_nbc_UserAdvManager[0] == 'true') or ( isset($conf_nbc_UserAdvManager[2]) and $conf_nbc_UserAdvManager[2] == 'true'))
430      {
431        $confirm_mail_need = false;
432             
433        if (!empty($_POST['mail_address']) and ValidateEmailProvider($_POST['mail_address']))
434        {
435          $query = '
436SELECT '.$conf['user_fields']['email'].' AS email
437FROM '.USERS_TABLE.'
438WHERE '.$conf['user_fields']['id'].' = \''.$user['id'].'\'
439;';
440         
441          list($current_email) = mysql_fetch_row(pwg_query($query));
442     
443          if ( $_POST['mail_address'] != $current_email and ( isset($conf_nbc_UserAdvManager[2]) and $conf_nbc_UserAdvManager[2] == 'true') )
444       
445            $confirm_mail_need = true;
446        }
447       
448        if ((!empty($_POST['use_new_pwd']) and ( isset($conf_nbc_UserAdvManager[0]) and $conf_nbc_UserAdvManager[0] == 'true') or $confirm_mail_need) )
449        {
450          $query = '
451SELECT '.$conf['user_fields']['username'].'
452FROM '.USERS_TABLE.'
453WHERE '.$conf['user_fields']['id'].' = \''.$user['id'].'\'
454;';
455       
456          list($username) = mysql_fetch_row(pwg_query($query));
457
458          SendMail2User($typemail, $user['id'], $username, $_POST['use_new_pwd'], $_POST['mail_address'], $confirm_mail_need);
459        }
460      }
461    }
462  }
463}
464
465
466add_event_handler('init', 'UserAdvManager_InitPage');
467 
468function UserAdvManager_InitPage()
469{
470  load_language('plugin.lang', NBC_UserAdvManager_PATH);
471  global $conf, $template, $page, $lang, $errors;
472
473  $conf_nbc_UserAdvManager = isset($conf['nbc_UserAdvManager']) ? explode(";" , $conf['nbc_UserAdvManager']) : array();
474 
475  /* Username non case sensitive */
476  if (isset($conf_nbc_UserAdvManager[1]) and $conf_nbc_UserAdvManager[1] == 'true')
477  {
478    $lang['reg_err_login5'] = l10n('reg_err_login5');
479  }
480 
481
482 
483/* User identification */
484  if (script_basename() == 'identification')
485  {
486    if (isset($_POST['login']))
487    {
488      /* User non case sensitive */
489      if (isset($conf_nbc_UserAdvManager[1]) and $conf_nbc_UserAdvManager[1] == 'true' )
490      {
491        $new_username =  NotSensibleSearchUsername($_POST['username']);
492        $_POST['username'] = $new_username == '' ? $_POST['username'] : $new_username;
493      }
494    }
495  }
496
497
498/* Admin user management */
499  if (script_basename() == 'admin' and isset($_GET['page']) and $_GET['page'] == 'user_list')
500  {
501    if (isset($_POST['submit_add']))
502    {
503      /* User non case sensitive */
504      if (isset($conf_nbc_UserAdvManager[1]) and $conf_nbc_UserAdvManager[1] == 'true' )
505      {
506        $new_username =  NotSensibleSearchUsername($_POST['login']);
507        $_POST['login'] = $new_username == '' ? $_POST['login'] : $new_username;
508      }
509
510      /* Username without forbidden keys */
511      if (isset($conf_nbc_UserAdvManager[7]) and $conf_nbc_UserAdvManager[7] == 'true' and !empty($_POST['login']) and !ValidateUsername($_POST['login']))
512      {
513        $template->append('errors', l10n('reg_err_login6')."'".$conf_nbc_UserAdvManager[8]."'");
514        unset($_POST['submit_add']);
515      }
516
517      /* Email without forbidden domains */
518      if (isset($conf_nbc_UserAdvManager[12]) and $conf_nbc_UserAdvManager[12] == 'true' and !empty($_POST['email']) and !ValidateEmailProvider($_POST['email']))
519      {
520        $template->append('errors', l10n('reg_err_login7')."'".$conf_nbc_UserAdvManager[13]."'");
521        unset($_POST['submit_add']);
522      }
523    }
524  }
525}
526
527
528add_event_handler('user_comment_check', 'UserAdvManager_CheckEmptyCommentAuthor', 50, 2);
529
530function UserAdvManager_CheckEmptyCommentAuthor($comment_action, $comm)
531{
532  load_language('plugin.lang', NBC_UserAdvManager_PATH);
533  global $infos, $conf, $template;
534
535  $conf_nbc_UserAdvManager = isset($conf['nbc_UserAdvManager']) ? explode(";" , $conf['nbc_UserAdvManager']) : array();
536
537/* User creation OR update */
538  if (isset($conf_nbc_UserAdvManager[6]) and $conf_nbc_UserAdvManager[6] == 'true' and $conf['comments_forall'] == 'true' and $comm['author'] == 'guest')
539  {
540    $comment_action = 'reject';
541
542    array_push($infos, l10n('UserAdvManager_Empty Author'));
543  }
544
545  return $comment_action;
546}
547
548?>
Note: See TracBrowser for help on using the repository browser.