3 +--------------------------------------------------------------------+
5 +--------------------------------------------------------------------+
6 | Copyright CiviCRM LLC (c) 2004-2019 |
7 +--------------------------------------------------------------------+
8 | This file is a part of CiviCRM. |
10 | CiviCRM is free software; you can copy, modify, and distribute it |
11 | under the terms of the GNU Affero General Public License |
12 | Version 3, 19 November 2007 and the CiviCRM Licensing Exception. |
14 | CiviCRM is distributed in the hope that it will be useful, but |
15 | WITHOUT ANY WARRANTY; without even the implied warranty of |
16 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
17 | See the GNU Affero General Public License for more details. |
19 | You should have received a copy of the GNU Affero General Public |
20 | License and the CiviCRM Licensing Exception along |
21 | with this program; if not, contact CiviCRM LLC |
22 | at info[AT]civicrm[DOT]org. If you have questions about the |
23 | GNU Affero General Public License or the licensing of CiviCRM, |
24 | see the CiviCRM license FAQ at http://civicrm.org/licensing |
25 +--------------------------------------------------------------------+
31 * @copyright CiviCRM LLC (c) 2004-2019
37 * This is base class for all ajax calls
39 class CRM_Core_Page_AJAX
{
42 * Call generic ajax forms.
45 public static function run() {
46 $className = CRM_Utils_Type
::escape($_REQUEST['class_name'], 'String');
48 if (!empty($_REQUEST['type'])) {
49 $type = CRM_Utils_Type
::escape($_REQUEST['type'], 'String');
53 CRM_Core_Error
::fatal(ts('Invalid className: %1', [1 => $className]));
57 if (isset($_REQUEST['fn_name'])) {
58 $fnName = CRM_Utils_Type
::escape($_REQUEST['fn_name'], 'String');
61 if (!self
::checkAuthz($type, $className, $fnName)) {
62 CRM_Utils_System
::civiExit();
67 call_user_func([$className, $fnName]);
73 // FIXME: This is done to maintain current wire protocol, but it might be
74 // simpler to just require different 'types' for pages and forms
75 if (preg_match('/^CRM_[a-zA-Z0-9]+_Page_Inline_/', $className)) {
76 $page = new $className();
80 $wrapper = new CRM_Utils_Wrapper();
81 $wrapper->run($className);
86 CRM_Core_Error
::debug_log_message('Unsupported inline request type: ' . var_export($type, TRUE));
88 CRM_Utils_System
::civiExit();
92 * Change is_quick_config priceSet to complex.
95 public static function setIsQuickConfig() {
96 $id = $context = NULL;
97 if (!empty($_REQUEST['id'])) {
98 $id = CRM_Utils_Type
::escape($_REQUEST['id'], 'Integer');
101 $context = CRM_Utils_Request
::retrieve('context', 'Alphanumeric');
103 // return false if $id is null and
104 // $context is not civicrm_event or civicrm_contribution_page
105 if (!$id ||
!in_array($context, ['civicrm_event', 'civicrm_contribution_page'])) {
108 $priceSetId = CRM_Price_BAO_PriceSet
::getFor($context, $id, NULL);
111 civicrm_price_set cps
112 INNER JOIN civicrm_price_set_entity cpse ON cps.id = cpse.price_set_id
113 INNER JOIN {$context} ce ON cpse.entity_id = ce.id AND ce.id = %1
114 SET cps.is_quick_config = 0, cps.financial_type_id = IF(cps.financial_type_id IS NULL, ce.financial_type_id, cps.financial_type_id)
116 CRM_Core_DAO
::executeQuery($sql, [1 => [$id, 'Integer']]);
118 if ($context == 'civicrm_event') {
119 CRM_Core_BAO_Discount
::del($id, $context);
123 CRM_Utils_JSON
::output($priceSetId);
127 * Determine whether the request is for a valid class/method name.
129 * @param string $type
130 * 'method'|'class'|''.
131 * @param string $className
133 * @param string $fnName
138 public static function checkAuthz($type, $className, $fnName = NULL) {
141 if (!preg_match('/^CRM_[a-zA-Z0-9]+_Page_AJAX$/', $className)) {
144 if (!preg_match('/^[a-zA-Z0-9]+$/', $fnName)) {
148 // ensure that function exists
149 return method_exists($className, $fnName);
154 if (!preg_match('/^CRM_[a-zA-Z0-9]+_(Page|Form)_Inline_[a-zA-Z0-9]+$/', $className)) {
157 return class_exists($className);
165 * Outputs the CiviCRM standard json-formatted page/form response
166 * @param array|string $response
168 public static function returnJsonResponse($response) {
169 // Allow lazy callers to not wrap content in an array
170 if (is_string($response)) {
171 $response = ['content' => $response];
173 // Add session variables to response
174 $session = CRM_Core_Session
::singleton();
176 'status' => 'success',
177 'userContext' => htmlspecialchars_decode($session->readUserContext()),
178 'title' => CRM_Utils_System
::$title,
180 // crmMessages will be automatically handled by our ajax preprocessor
182 if ($session->getStatus(FALSE)) {
183 $response['crmMessages'] = $session->getStatus(TRUE);
185 $output = json_encode($response);
187 // CRM-11831 @see http://www.malsup.com/jquery/form/#file-upload
188 if (isset($_SERVER['HTTP_X_REQUESTED_WITH']) && $_SERVER['HTTP_X_REQUESTED_WITH'] == 'XMLHttpRequest') {
189 CRM_Utils_System
::setHttpHeader('Content-Type', 'application/json');
192 $output = "<textarea>$output</textarea>";
195 CRM_Utils_System
::civiExit();
199 * Set headers appropriate for a js file.
201 * @param int|NULL $ttl
202 * Time-to-live (seconds).
204 public static function setJsHeaders($ttl = NULL) {
206 // Encourage browsers to cache for a long time - 1 year
207 $ttl = 60 * 60 * 24 * 364;
209 CRM_Utils_System
::setHttpHeader('Expires', gmdate('D, d M Y H:i:s \G\M\T', time() +
$ttl));
210 CRM_Utils_System
::setHttpHeader('Content-Type', 'application/javascript');
211 CRM_Utils_System
::setHttpHeader('Cache-Control', "max-age=$ttl, public");
215 * Set defaults for sort and pager.
217 * @param int $defaultOffset
218 * @param int $defaultRowCount
219 * @param string $defaultSort
220 * @param string $defaultsortOrder
224 public static function defaultSortAndPagerParams($defaultOffset = 0, $defaultRowCount = 25, $defaultSort = NULL, $defaultsortOrder = 'asc') {
230 if (isset($_GET['columns'])) {
231 foreach ($_GET['columns'] as $key => $value) {
232 $sortMapper[$key] = CRM_Utils_Type
::validate($value['data'], 'MysqlColumnNameOrAlias');
236 $offset = isset($_GET['start']) ? CRM_Utils_Type
::validate($_GET['start'], 'Integer') : $defaultOffset;
237 $rowCount = isset($_GET['length']) ? CRM_Utils_Type
::validate($_GET['length'], 'Integer') : $defaultRowCount;
238 // Why is the number of order by columns limited to 1?
239 $sort = isset($_GET['order'][0]['column']) ? CRM_Utils_Array
::value(CRM_Utils_Type
::validate($_GET['order'][0]['column'], 'Integer'), $sortMapper) : $defaultSort;
240 $sortOrder = isset($_GET['order'][0]['dir']) ? CRM_Utils_Type
::validate($_GET['order'][0]['dir'], 'MysqlOrderByDirection') : $defaultsortOrder;
243 $params['sortBy'] = "{$sort} {$sortOrder}";
245 $params['_raw_values']['sort'][0] = $sort;
246 $params['_raw_values']['order'][0] = $sortOrder;
249 $params['offset'] = $offset;
250 $params['rp'] = $rowCount;
251 $params['page'] = ($offset / $rowCount) +
1;
257 * Validate ajax input parameters.
259 * @param array $requiredParams
260 * @param array $optionalParams
264 public static function validateParams($requiredParams = [], $optionalParams = []) {
267 foreach ($requiredParams as $param => $type) {
268 $params[$param] = CRM_Utils_Type
::validate(CRM_Utils_Array
::value($param, $_GET), $type);
271 foreach ($optionalParams as $param => $type) {
272 if (CRM_Utils_Array
::value($param, $_GET)) {
273 if (!is_array($_GET[$param])) {
274 $params[$param] = CRM_Utils_Type
::validate(CRM_Utils_Array
::value($param, $_GET), $type);
277 foreach ($_GET[$param] as $index => $value) {
278 $params[$param][$index] = CRM_Utils_Type
::validate($value, $type);