INFRA-132 - CRM/Price - phpcbf
[civicrm-core.git] / CRM / Profile / Page / Dynamic.php
CommitLineData
6a488035
TO
1<?php
2/*
3 +--------------------------------------------------------------------+
39de6fd5 4 | CiviCRM version 4.6 |
6a488035 5 +--------------------------------------------------------------------+
06b69b18 6 | Copyright CiviCRM LLC (c) 2004-2014 |
6a488035
TO
7 +--------------------------------------------------------------------+
8 | This file is a part of CiviCRM. |
9 | |
10 | CiviCRM is free software; you can copy, modify, and distribute it |
11 | under the terms of the GNU Affero General Public License |
12 | Version 3, 19 November 2007 and the CiviCRM Licensing Exception. |
13 | |
14 | CiviCRM is distributed in the hope that it will be useful, but |
15 | WITHOUT ANY WARRANTY; without even the implied warranty of |
16 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
17 | See the GNU Affero General Public License for more details. |
18 | |
19 | You should have received a copy of the GNU Affero General Public |
20 | License and the CiviCRM Licensing Exception along |
21 | with this program; if not, contact CiviCRM LLC |
22 | at info[AT]civicrm[DOT]org. If you have questions about the |
23 | GNU Affero General Public License or the licensing of CiviCRM, |
24 | see the CiviCRM license FAQ at http://civicrm.org/licensing |
25 +--------------------------------------------------------------------+
26*/
27
28/**
29 *
30 * @package CRM
06b69b18 31 * @copyright CiviCRM LLC (c) 2004-2014
6a488035
TO
32 * $Id$
33 *
34 */
35
36/**
37 * Create a page for displaying CiviCRM Profile Fields.
38 *
39 * Heart of this class is the run method which checks
40 * for action type and then displays the appropriate
41 * page.
42 *
43 */
44class CRM_Profile_Page_Dynamic extends CRM_Core_Page {
45
46 /**
47 * The contact id of the person we are viewing
48 *
49 * @var int
6a488035
TO
50 */
51 protected $_id;
52
53 /**
100fef9d 54 * The profile group are are interested in
6a488035
TO
55 *
56 * @var int
6a488035
TO
57 */
58 protected $_gid;
59
60 /**
61 * The profile types we restrict this page to display
62 *
63 * @var string
6a488035
TO
64 */
65 protected $_restrict;
66
67 /**
68 * Should we bypass permissions
69 *
70 * @var boolean
6a488035
TO
71 */
72 protected $_skipPermission;
73
74 /**
75 * Store profile ids if multiple profile ids are passed using comma separated.
76 * Currently lets implement this functionality only for dialog mode
77 */
78 protected $_profileIds = array();
79
80 /**
81 * Contact profile having activity fields?
82 *
83 * @var string
84 */
85 protected $_isContactActivityProfile = FALSE;
86
87 /**
88 * Activity Id connected to the profile
89 *
90 * @var string
91 */
92 protected $_activityId = NULL;
93
94 protected $_multiRecord = NULL;
95
96 protected $_recordId = NULL;
366fe2a3 97
6a488035
TO
98 /*
99 * fetch multirecord as well as non-multirecord fields
100 */
101 protected $_allFields = NULL;
102
103 /**
100fef9d 104 * Class constructor
6a488035 105 *
68c9fb83
TO
106 * @param int $id
107 * The contact id.
108 * @param int $gid
109 * The group id.
6a488035 110 *
77b97be7
EM
111 * @param $restrict
112 * @param bool $skipPermission
113 * @param null $profileIds
114 *
115 * @return \CRM_Profile_Page_Dynamic
6a488035 116 */
00be9182 117 public function __construct($id, $gid, $restrict, $skipPermission = FALSE, $profileIds = NULL) {
6a488035
TO
118 parent::__construct();
119
120 $this->_id = $id;
121 $this->_gid = $gid;
122 $this->_restrict = $restrict;
123 $this->_skipPermission = $skipPermission;
124
125 if (!array_key_exists('multiRecord', $_GET)) {
126 $this->set('multiRecord', NULL);
127 }
128 if (!array_key_exists('recordId', $_GET)) {
129 $this->set('recordId', NULL);
130 }
131 if (!array_key_exists('allFields', $_GET)) {
132 $this->set('allFields', NULL);
133 }
366fe2a3 134
6a488035
TO
135 //specifies the action being done on a multi record field
136 $multiRecordAction = CRM_Utils_Request::retrieve('multiRecord', 'String', $this);
366fe2a3 137
138 $this->_multiRecord = (!is_numeric($multiRecordAction)) ?
6a488035
TO
139 CRM_Core_Action::resolve($multiRecordAction) : $multiRecordAction;
140 if ($this->_multiRecord) {
141 $this->set('multiRecord', $this->_multiRecord);
142 }
366fe2a3 143
6a488035
TO
144 if ($this->_multiRecord & CRM_Core_Action::VIEW) {
145 $this->_recordId = CRM_Utils_Request::retrieve('recordId', 'Positive', $this);
146 $this->_allFields = CRM_Utils_Request::retrieve('allFields', 'Integer', $this);
147 }
366fe2a3 148
6a488035
TO
149 if ($profileIds) {
150 $this->_profileIds = $profileIds;
151 }
152 else {
153 $this->_profileIds = array($gid);
154 }
155
156 $this->_activityId = CRM_Utils_Request::retrieve('aid', 'Positive', $this, FALSE, 0, 'GET');
157 if (is_numeric($this->_activityId)) {
158 $latestRevisionId = CRM_Activity_BAO_Activity::getLatestActivityId($this->_activityId);
159 if ($latestRevisionId) {
160 $this->_activityId = $latestRevisionId;
161 }
162 }
163 $this->_isContactActivityProfile = CRM_Core_BAO_UFField::checkContactActivityProfileType($this->_gid);
164 }
165
166 /**
167 * Get the action links for this page.
168 *
169 * @return array $_actionLinks
170 *
171 */
00be9182 172 public function &actionLinks() {
6a488035
TO
173 return NULL;
174 }
175
176 /**
177 * Run the page.
178 *
179 * This method is called after the page is created. It checks for the
180 * type of action and executes that action.
181 *
182 * @return void
6a488035
TO
183 *
184 */
00be9182 185 public function run() {
6a488035
TO
186 $template = CRM_Core_Smarty::singleton();
187 if ($this->_id && $this->_gid) {
188
189 // first check that id is part of the limit group id, CRM-4822
190 $limitListingsGroupsID = CRM_Core_DAO::getFieldValue('CRM_Core_DAO_UFGroup',
191 $this->_gid,
192 'limit_listings_group_id'
193 );
194 $config = CRM_Core_Config::singleton();
195 if ($limitListingsGroupsID) {
196
197 if (!CRM_Contact_BAO_GroupContact::isContactInGroup($this->_id,
198 $limitListingsGroupsID
199 )) {
200 CRM_Utils_System::setTitle(ts('Profile View - Permission Denied'));
201 return CRM_Core_Session::setStatus(ts('You do not have permission to view this contact record. Contact the site administrator if you need assistance.'), ts('Permission Denied'), 'error');
202 }
203 }
204
205 $session = CRM_Core_Session::singleton();
206 $userID = $session->get('userID');
207
208 $this->_isPermissionedChecksum = FALSE;
209 $permissionType = CRM_Core_Permission::VIEW;
210 if ($this->_id != $userID) {
211 // do not allow edit for anon users in joomla frontend, CRM-4668, unless u have checksum CRM-5228
212 if ($config->userFrameworkFrontend) {
213 $this->_isPermissionedChecksum = CRM_Contact_BAO_Contact_Permission::validateOnlyChecksum($this->_id, $this, FALSE);
214 }
215 else {
216 $this->_isPermissionedChecksum = CRM_Contact_BAO_Contact_Permission::validateChecksumContact($this->_id, $this, FALSE);
217 }
218 }
219 // CRM-10853
220 // Users with create or edit permission should be allowed to view their own profile
221 if ($this->_id == $userID || $this->_isPermissionedChecksum) {
222 if (!CRM_Core_Permission::check('profile view')) {
223 if (CRM_Core_Permission::check('profile create') || CRM_Core_Permission::check('profile edit')) {
224 $this->_skipPermission = TRUE;
225 }
226 }
227 }
228
229 // make sure we dont expose all fields based on permission
230 $admin = FALSE;
231 if ((!$config->userFrameworkFrontend &&
232 (CRM_Core_Permission::check('administer users') ||
233 CRM_Core_Permission::check('view all contacts') ||
234 CRM_Contact_BAO_Contact_Permission::allow($this->_id)
235 )
236 ) ||
237 $this->_id == $userID ||
238 $this->_isPermissionedChecksum
239 ) {
240 $admin = TRUE;
241 }
242
243 $values = array();
244 $fields = CRM_Core_BAO_UFGroup::getFields($this->_profileIds, FALSE, CRM_Core_Action::VIEW,
245 NULL, NULL, FALSE, $this->_restrict,
246 $this->_skipPermission, NULL,
247 $permissionType
248 );
249
250 if ($this->_multiRecord & CRM_Core_Action::VIEW && $this->_recordId && !$this->_allFields) {
251 CRM_Core_BAO_UFGroup::shiftMultiRecordFields($fields, $multiRecordFields);
252 $fields = $multiRecordFields;
253 }
254 if ($this->_isContactActivityProfile && $this->_gid) {
255 $errors = CRM_Profile_Form::validateContactActivityProfile($this->_activityId, $this->_id, $this->_gid);
256 if (!empty($errors)) {
257 CRM_Core_Error::fatal(array_pop($errors));
258 }
259 }
260
261 //reformat fields array
262 foreach ($fields as $name => $field) {
263 // also eliminate all formatting fields
264 if (CRM_Utils_Array::value('field_type', $field) == 'Formatting') {
265 unset($fields[$name]);
266 }
267
268 // make sure that there is enough permission to expose this field
269 if (!$admin && $field['visibility'] == 'User and User Admin Only') {
270 unset($fields[$name]);
271 }
272 }
273
274 if ($this->_isContactActivityProfile) {
275 $contactFields = $activityFields = array();
276
277 foreach ($fields as $fieldName => $field) {
278 if (CRM_Utils_Array::value('field_type', $field) == 'Activity') {
279 $activityFields[$fieldName] = $field;
280 }
281 else {
282 $contactFields[$fieldName] = $field;
283 }
284 }
285
286 CRM_Core_BAO_UFGroup::getValues($this->_id, $contactFields, $values);
287 if ($this->_activityId) {
288 CRM_Core_BAO_UFGroup::getValues(
289 NULL,
290 $activityFields,
291 $values,
292 TRUE,
293 array(array('activity_id', '=', $this->_activityId, 0, 0))
294 );
295 }
296 }
297 else {
298 $customWhereClause = NULL;
299 if ($this->_multiRecord & CRM_Core_Action::VIEW && $this->_recordId) {
300 if ($this->_allFields) {
301 $copyFields = $fields;
302 CRM_Core_BAO_UFGroup::shiftMultiRecordFields($copyFields, $multiRecordFields);
303 $fieldKey = key($multiRecordFields);
304 } else {
305 $fieldKey = key($fields);
306 }
307 if ($fieldID = CRM_Core_BAO_CustomField::getKeyID($fieldKey)) {
308 $tableColumnGroup = CRM_Core_BAO_CustomField::getTableColumnGroup($fieldID);
309 $columnName = "{$tableColumnGroup[0]}.id";
310 $customWhereClause = $columnName . ' = ' . $this->_recordId;
311 }
312 }
313 CRM_Core_BAO_UFGroup::getValues($this->_id, $fields, $values, TRUE, NULL, FALSE, $customWhereClause);
314 }
315
316 // $profileFields array can be used for customized display of field labels and values in Profile/View.tpl
317 $profileFields = array();
318 $labels = array();
319
320 foreach ($fields as $name => $field) {
50bf705c
KJ
321 //CRM-14338
322 // Create a unique, non-empty index for each field.
323 $index = $field['title'];
324 if ($index === '') $index = ' ';
325 while (array_key_exists($index, $labels))
326 $index .= ' ';
327
328 $labels[$index] = preg_replace('/\s+|\W+/', '_', $name);
6a488035
TO
329 }
330
331 foreach ($values as $title => $value) {
332 $profileFields[$labels[$title]] = array(
333 'label' => $title,
334 'value' => $value,
335 );
336 }
337
338 $template->assign_by_ref('row', $values);
339 $template->assign_by_ref('profileFields', $profileFields);
340 }
341
342 $name = CRM_Core_DAO::getFieldValue('CRM_Core_DAO_UFGroup', $this->_gid, 'name');
46312a4d 343 $this->assign('ufGroupName', $name);
a8387f19 344 CRM_Utils_Hook::viewProfile($name);
6a488035
TO
345
346 if (strtolower($name) == 'summary_overlay') {
347 $template->assign('overlayProfile', TRUE);
348 }
349
350 if (($this->_multiRecord & CRM_Core_Action::VIEW) && $this->_recordId && !$this->_allFields) {
351 $fieldDetail = reset($fields);
352 $fieldId = CRM_Core_BAO_CustomField::getKeyID($fieldDetail['name']);
353 $customGroupDetails = CRM_Core_BAO_CustomGroup::getGroupTitles(array($fieldId));
fcc8f207 354 $multiRecTitle = $customGroupDetails[$fieldId]['groupTitle'];
6a488035
TO
355 } else {
356 $title = CRM_Core_DAO::getFieldValue('CRM_Core_DAO_UFGroup', $this->_gid, 'title');
357 }
358
359 //CRM-4131.
360 $displayName = CRM_Core_DAO::getFieldValue('CRM_Contact_DAO_Contact', $this->_id, 'display_name');
361 if ($displayName) {
362 $session = CRM_Core_Session::singleton();
363 $config = CRM_Core_Config::singleton();
364 if ($session->get('userID') &&
365 CRM_Core_Permission::check('access CiviCRM') &&
366 CRM_Contact_BAO_Contact_Permission::allow($session->get('userID'), CRM_Core_Permission::VIEW) &&
367 !$config->userFrameworkFrontend
368 ) {
369 $contactViewUrl = CRM_Utils_System::url('civicrm/contact/view', "action=view&reset=1&cid={$this->_id}", TRUE);
370 $this->assign('displayName', $displayName);
371 $displayName = "<a href=\"$contactViewUrl\">{$displayName}</a>";
372 }
373 $title .= ' - ' . $displayName;
374 }
375
fcc8f207 376 $title = isset($multiRecTitle) ? ts('View %1 Record', array(1 => $multiRecTitle)) : $title;
6a488035
TO
377 CRM_Utils_System::setTitle($title);
378
379 // invoke the pagRun hook, CRM-3906
380 CRM_Utils_Hook::pageRun($this);
381
8aac22c8 382 return trim($template->fetch($this->getHookedTemplateFileName()));
6a488035
TO
383 }
384
ffd93213
EM
385 /**
386 * @param string $suffix
387 *
388 * @return null|string
389 */
00be9182 390 public function checkTemplateFileExists($suffix = '') {
6a488035
TO
391 if ($this->_gid) {
392 $templateFile = "CRM/Profile/Page/{$this->_gid}/Dynamic.{$suffix}tpl";
393 $template = CRM_Core_Page::getTemplate();
394 if ($template->template_exists($templateFile)) {
395 return $templateFile;
396 }
397
398 // lets see if we have customized by name
399 $ufGroupName = CRM_Core_DAO::getFieldValue('CRM_Core_DAO_UFGroup', $this->_gid, 'name');
400 if ($ufGroupName) {
401 $templateFile = "CRM/Profile/Page/{$ufGroupName}/Dynamic.{$suffix}tpl";
402 if ($template->template_exists($templateFile)) {
403 return $templateFile;
404 }
405 }
406 }
407 return NULL;
408 }
409
ffd93213
EM
410 /**
411 * Use the form name to create the tpl file name
412 *
413 * @return string
ffd93213
EM
414 */
415 /**
416 * @return string
417 */
00be9182 418 public function getTemplateFileName() {
6a488035
TO
419 $fileName = $this->checkTemplateFileExists();
420 return $fileName ? $fileName : parent::getTemplateFileName();
421 }
422
ffd93213
EM
423 /**
424 * Default extra tpl file basically just replaces .tpl with .extra.tpl
425 * i.e. we dont override
426 *
427 * @return string
ffd93213
EM
428 */
429 /**
430 * @return string
431 */
00be9182 432 public function overrideExtraTemplateFileName() {
6a488035
TO
433 $fileName = $this->checkTemplateFileExists('extra.');
434 return $fileName ? $fileName : parent::overrideExtraTemplateFileName();
435 }
436}