Fix serveral cross site scripting bugs found by Martijn Brinkers and
[squirrelmail.git] / functions / addressbook.php
CommitLineData
5100704d 1<?php
7390e240 2
35586184 3/**
6ad2bbe2 4 * functions/addressbook.php - Functions and classes for the addressbook system
35586184 5 *
6c84ba1e 6 * Copyright (c) 1999-2005 The SquirrelMail Project Team
35586184 7 * Licensed under the GNU GPL. For full terms see the file COPYING.
8 *
6ad2bbe2 9 * Functions require SM_PATH and support of forms.php functions
35586184 10 *
a9d318b0 11 * @version $Id$
d6c32258 12 * @package squirrelmail
a9d318b0 13 * @subpackage addressbook
35586184 14 */
15
04875ae0 16/**
17 * If SM_PATH isn't defined, define it. Required to include files.
18 * @ignore
19 */
20if (!defined('SM_PATH')) {
21 define('SM_PATH','../');
22}
23
24/* make sure that display_messages.php is loaded */
25include_once(SM_PATH . 'functions/display_messages.php');
26
30e9932c 27global $addrbook_dsn, $addrbook_global_dsn;
81fa4801 28
d6c32258 29/**
0d4096aa 30 * Create and initialize an addressbook object.
f8a1ed5a 31 * @param boolean $showerr display any address book init errors. html page header
0d4096aa 32 * must be created before calling addressbook_init() with $showerr enabled.
33 * @param boolean $onlylocal enable only local address book backends
34 * @return object address book object.
35 */
81fa4801 36function addressbook_init($showerr = true, $onlylocal = false) {
04875ae0 37 global $data_dir, $username, $color, $ldap_server, $address_book_global_filename;
81fa4801 38 global $addrbook_dsn, $addrbook_table;
e59a9c41 39 global $abook_global_file, $abook_global_file_writeable, $abook_global_file_listing;
30e9932c 40 global $addrbook_global_dsn, $addrbook_global_table, $addrbook_global_writeable, $addrbook_global_listing;
81fa4801 41
42 /* Create a new addressbook object */
43 $abook = new AddressBook;
44
04875ae0 45 /* Create empty error message */
46 $abook_init_error='';
47
81fa4801 48 /*
49 Always add a local backend. We use *either* file-based *or* a
50 database addressbook. If $addrbook_dsn is set, the database
51 backend is used. If not, addressbooks are stores in files.
52 */
53 if (isset($addrbook_dsn) && !empty($addrbook_dsn)) {
54 /* Database */
55 if (!isset($addrbook_table) || empty($addrbook_table)) {
56 $addrbook_table = 'address';
57 }
58 $r = $abook->add_backend('database', Array('dsn' => $addrbook_dsn,
59 'owner' => $username,
60 'table' => $addrbook_table));
61 if (!$r && $showerr) {
0d4096aa 62 $abook_init_error.=_("Error initializing addressbook database.") . "<br />\n" . $abook->error;
81fa4801 63 }
64 } else {
65 /* File */
66 $filename = getHashedFile($username, $data_dir, "$username.abook");
67 $r = $abook->add_backend('local_file', Array('filename' => $filename,
68 'create' => true));
69 if(!$r && $showerr) {
0d4096aa 70 // no need to use $abook->error, because message explains error.
71 $abook_init_error.=sprintf( _("Error opening file %s"), $filename );
81fa4801 72 }
81fa4801 73 }
74
e59a9c41 75 /* Global file based addressbook */
f8a1ed5a 76 if (isset($abook_global_file) &&
e59a9c41 77 isset($abook_global_file_writeable) &&
78 isset($abook_global_file_listing) &&
79 trim($abook_global_file)!=''){
80
4272758c 81 // Detect place of address book
82 if (! preg_match("/[\/\\\]/",$abook_global_file)) {
e4a468a7 83 /* no path chars, address book stored in data directory
f8a1ed5a 84 * make sure that there is a slash between data directory
e4a468a7 85 * and address book file name
86 */
87 $abook_global_filename=$data_dir
88 . ((substr($data_dir, -1) != '/') ? '/' : '')
89 . $abook_global_file;
4272758c 90 } elseif (preg_match("/^\/|\w:/",$abook_global_file)) {
91 // full path is set in options (starts with slash or x:)
92 $abook_global_filename=$abook_global_file;
93 } else {
94 $abook_global_filename=SM_PATH . $abook_global_file;
95 }
e59a9c41 96
4272758c 97 $r = $abook->add_backend('local_file',array('filename'=>$abook_global_filename,
98 'name' => _("Global address book"),
99 'detect_writeable' => false,
e59a9c41 100 'writeable'=> $abook_global_file_writeable,
101 'listing' => $abook_global_file_listing));
04875ae0 102
103 /* global abook init error is not fatal. add error message and continue */
81fa4801 104 if (!$r && $showerr) {
0d4096aa 105 if ($abook_init_error!='') $abook_init_error.="<br />\n";
106 $abook_init_error.=_("Error initializing global addressbook.") . "<br />\n" . $abook->error;
81fa4801 107 }
108 }
109
30e9932c 110 /* Load global addressbook from SQL if configured */
111 if (isset($addrbook_global_dsn) && !empty($addrbook_global_dsn)) {
112 /* Database configured */
113 if (!isset($addrbook_global_table) || empty($addrbook_global_table)) {
c1ac62d4 114 $addrbook_global_table = 'global_abook';
30e9932c 115 }
116 $r = $abook->add_backend('database',
c1ac62d4 117 Array('dsn' => $addrbook_global_dsn,
118 'owner' => 'global',
119 'name' => _("Global address book"),
120 'writeable' => $addrbook_global_writeable,
121 'listing' => $addrbook_global_listing,
122 'table' => $addrbook_global_table));
0d4096aa 123 /* global abook init error is not fatal. add error message and continue */
124 if (!$r && $showerr) {
125 if ($abook_init_error!='') $abook_init_error.="<br />\n";
126 $abook_init_error.=_("Error initializing global addressbook.") . "<br />\n" . $abook->error;
127 }
30e9932c 128 }
129
df788686 130 /*
131 * hook allows to include different address book backends.
132 * plugins should extract $abook and $r from arguments
133 * and use same add_backend commands as above functions.
7390e240 134 * @since 1.5.1 and 1.4.5
df788686 135 */
136 $hookReturn = do_hook('abook_init', $abook, $r);
137 $abook = $hookReturn[1];
138 $r = $hookReturn[2];
62f7daa5 139
0d4096aa 140 if (! $onlylocal) {
141 /* Load configured LDAP servers (if PHP has LDAP support) */
95501c13 142 if (isset($ldap_server) && is_array($ldap_server)) {
0d4096aa 143 reset($ldap_server);
144 while (list($undef,$param) = each($ldap_server)) {
145 if (is_array($param)) {
146 $r = $abook->add_backend('ldap_server', $param);
147 if (!$r && $showerr) {
148 if ($abook_init_error!='') $abook_init_error.="<br />\n";
149 $abook_init_error.=sprintf(_("Error initializing LDAP server %s:") .
7390e240 150 "<br />\n", $param['host']);
0d4096aa 151 $abook_init_error.= $abook->error;
152 }
81fa4801 153 }
154 }
0d4096aa 155 } // end of ldap server init
156 } // end of remote abook backend init
4935919f 157
04875ae0 158 /**
159 * display address book init errors.
160 */
161 if ($abook_init_error!='' && $showerr) {
162 error_box($abook_init_error,$color);
163 }
7390e240 164
81fa4801 165 /* Return the initialized object */
166 return $abook;
4935919f 167}
168
c1ac62d4 169/**
170 * Display the "new address" form
171 *
172 * Form is not closed and you must add closing form tag.
173 * @since 1.5.1
174 * @param string $form_url form action url
175 * @param string $name form name
176 * @param string $title form title
177 * @param string $button form button name
178 * @param array $defdata values of form fields
179 */
180function abook_create_form($form_url,$name,$title,$button,$defdata=array()) {
181 global $color;
182 echo addForm($form_url, 'post', 'f_add').
183 html_tag( 'table',
184 html_tag( 'tr',
185 html_tag( 'td', "\n". '<strong>' . $title . '</strong>' . "\n",
186 'center', $color[0]
187 )
188 )
81642286 189 , 'center', '', 'width="90%"' ) ."\n";
c1ac62d4 190 address_form($name, $button, $defdata);
191}
192
4935919f 193
81fa4801 194/*
195 * Had to move this function outside of the Addressbook Class
196 * PHP 4.0.4 Seemed to be having problems with inline functions.
abd74f7d 197 * Note: this can return now since we don't support 4.0.4 anymore.
62f7daa5 198 */
81fa4801 199function addressbook_cmp($a,$b) {
4935919f 200
81fa4801 201 if($a['backend'] > $b['backend']) {
202 return 1;
203 } else if($a['backend'] < $b['backend']) {
204 return -1;
205 }
62f7daa5 206
81fa4801 207 return (strtolower($a['name']) > strtolower($b['name'])) ? 1 : -1;
4935919f 208
81fa4801 209}
4935919f 210
c1ac62d4 211/**
212 * Make an input field
213 * @param string $label
214 * @param string $field
215 * @param string $name
216 * @param string $size
217 * @param array $values
218 * @param string $add
219 */
220function addressbook_inp_field($label, $field, $name, $size, $values, $add='') {
221 global $color;
222 $value = ( isset($values[$field]) ? $values[$field] : '');
223
224 if (is_array($value)) {
225 $td_str = addSelect($name.'['.$field.']', $value);
226 } else {
227 $td_str = addInput($name.'['.$field.']', $value, $size);
228 }
229 $td_str .= $add ;
230
231 return html_tag( 'tr' ,
232 html_tag( 'td', $label . ':', 'right', $color[4]) .
233 html_tag( 'td', $td_str, 'left', $color[4])
234 )
235 . "\n";
236}
237
238/**
239 * Output form to add and modify address data
240 */
241function address_form($name, $submittext, $values = array()) {
242 global $color, $squirrelmail_language;
243
244 if ($squirrelmail_language == 'ja_JP') {
245 echo html_tag( 'table',
246 addressbook_inp_field(_("Nickname"), 'nickname', $name, 15, $values,
247 ' <small>' . _("Must be unique") . '</small>') .
248 addressbook_inp_field(_("E-mail address"), 'email', $name, 45, $values, '') .
249 addressbook_inp_field(_("Last name"), 'lastname', $name, 45, $values, '') .
250 addressbook_inp_field(_("First name"), 'firstname', $name, 45, $values, '') .
251 addressbook_inp_field(_("Additional info"), 'label', $name, 45, $values, '') .
252 list_writable_backends($name) .
253 html_tag( 'tr',
254 html_tag( 'td',
255 addSubmit($submittext, $name.'[SUBMIT]'),
256 'center', $color[4], 'colspan="2"')
257 )
258 , 'center', '', 'border="0" cellpadding="1" width="90%"') ."\n";
259 } else {
260 echo html_tag( 'table',
261 addressbook_inp_field(_("Nickname"), 'nickname', $name, 15, $values,
262 ' <small>' . _("Must be unique") . '</small>') .
263 addressbook_inp_field(_("E-mail address"), 'email', $name, 45, $values, '') .
264 addressbook_inp_field(_("First name"), 'firstname', $name, 45, $values, '') .
265 addressbook_inp_field(_("Last name"), 'lastname', $name, 45, $values, '') .
266 addressbook_inp_field(_("Additional info"), 'label', $name, 45, $values, '') .
267 list_writable_backends($name) .
268 html_tag( 'tr',
269 html_tag( 'td',
270 addSubmit($submittext, $name.'[SUBMIT]') ,
271 'center', $color[4], 'colspan="2"')
272 )
273 , 'center', '', 'border="0" cellpadding="1" width="90%"') ."\n";
274 }
275}
276
6ad2bbe2 277/**
278 * Provides list of writeable backends.
279 * Works only when address is added ($name='addaddr')
280 * @param string $name name of form
281 * @return string html formated backend field (select or hidden)
282 */
c1ac62d4 283function list_writable_backends($name) {
284 global $color, $abook;
285 if ( $name != 'addaddr' ) { return; }
6ad2bbe2 286 $writeable_abook = 1;
c1ac62d4 287 if ( $abook->numbackends > 1 ) {
c1ac62d4 288 $backends = $abook->get_backend_list();
6ad2bbe2 289 $writeable_abooks=array();
c1ac62d4 290 while (list($undef,$v) = each($backends)) {
291 if ($v->writeable) {
6ad2bbe2 292 // add each backend to array
293 $writeable_abooks[$v->bnum]=$v->sname;
294 // save backend number
295 $writeable_abook=$v->bnum;
c1ac62d4 296 }
297 }
6ad2bbe2 298 if (count($writeable_abooks)>1) {
299 // we have more than one writeable backend
300 $ret=addSelect('backend',$writeable_abooks,null,true);
301 return html_tag( 'tr',
302 html_tag( 'td', _("Add to:"),'right', $color[4] ) .
303 html_tag( 'td', $ret, 'left', $color[4] )) . "\n";
304 }
c1ac62d4 305 }
6ad2bbe2 306 // Only one backend exists or is writeable.
307 return html_tag( 'tr',
308 html_tag( 'td',
309 addHidden('backend', $writeable_abook),
310 'center', $color[4], 'colspan="2"')) . "\n";
c1ac62d4 311}
312
313/**
314 * Sort array by the key "name"
315 */
316function alistcmp($a,$b) {
317 $abook_sort_order=get_abook_sort();
318
319 switch ($abook_sort_order) {
320 case 0:
321 case 1:
322 $abook_sort='nickname';
323 break;
324 case 4:
325 case 5:
326 $abook_sort='email';
327 break;
328 case 6:
329 case 7:
330 $abook_sort='label';
331 break;
332 case 2:
333 case 3:
334 case 8:
335 default:
336 $abook_sort='name';
337 }
338
339 if ($a['backend'] > $b['backend']) {
340 return 1;
341 } else {
342 if ($a['backend'] < $b['backend']) {
343 return -1;
344 }
345 }
346
347 if( (($abook_sort_order+2) % 2) == 1) {
348 return (strtolower($a[$abook_sort]) < strtolower($b[$abook_sort])) ? 1 : -1;
349 } else {
350 return (strtolower($a[$abook_sort]) > strtolower($b[$abook_sort])) ? 1 : -1;
351 }
352}
353
354/**
355 * Address book sorting options
356 *
357 * returns address book sorting order
358 * @return integer book sorting options order
359 */
360function get_abook_sort() {
361 global $data_dir, $username;
362
363 /* get sorting order */
364 if(sqgetGlobalVar('abook_sort_order', $temp, SQ_GET)) {
365 $abook_sort_order = (int) $temp;
366
367 if ($abook_sort_order < 0 or $abook_sort_order > 8)
368 $abook_sort_order=8;
369
370 setPref($data_dir, $username, 'abook_sort_order', $abook_sort_order);
371 } else {
372 /* get previous sorting options. default to unsorted */
373 $abook_sort_order = getPref($data_dir, $username, 'abook_sort_order', 8);
374 }
375
376 return $abook_sort_order;
377}
378
379/**
380 * This function shows the address book sort button.
381 *
382 * @param integer $abook_sort_order current sort value
383 * @param string $alt_tag alt tag value (string visible to text only browsers)
384 * @param integer $Down sort value when list is sorted ascending
385 * @param integer $Up sort value when list is sorted descending
386 * @return string html code with sorting images and urls
387 */
388function show_abook_sort_button($abook_sort_order, $alt_tag, $Down, $Up ) {
389 global $form_url;
390
391 /* Figure out which image we want to use. */
392 if ($abook_sort_order != $Up && $abook_sort_order != $Down) {
393 $img = 'sort_none.png';
394 $which = $Up;
395 } elseif ($abook_sort_order == $Up) {
396 $img = 'up_pointer.png';
397 $which = $Down;
398 } else {
399 $img = 'down_pointer.png';
400 $which = 8;
401 }
402
403 /* Now that we have everything figured out, show the actual button. */
404 return ' <a href="' . $form_url .'?abook_sort_order=' . $which
405 . '"><img src="../images/' . $img
406 . '" border="0" width="12" height="10" alt="' . $alt_tag . '" title="'
407 . _("Click here to change the sorting of the address list") .'" /></a>';
408}
409
4935919f 410
8f6f9ba5 411/**
81fa4801 412 * This is the main address book class that connect all the
413 * backends and provide services to the functions above.
8f6f9ba5 414 * @package squirrelmail
c1ac62d4 415 * @subpackage addressbook
81fa4801 416 */
81fa4801 417class AddressBook {
4272758c 418 /**
419 * Enabled address book backends
420 * @var array
421 */
81fa4801 422 var $backends = array();
4272758c 423 /**
424 * Number of enabled backends
425 * @var integer
426 */
81fa4801 427 var $numbackends = 0;
4272758c 428 /**
429 * Error messages
430 * @var string
431 */
81fa4801 432 var $error = '';
4272758c 433 /**
434 * id of backend with personal address book
435 * @var integer
436 */
81fa4801 437 var $localbackend = 0;
4272758c 438 /**
439 * Name of backend with personal address book
440 * @var string
441 */
81fa4801 442 var $localbackendname = '';
62f7daa5 443
4272758c 444 /**
445 * Constructor function.
446 */
81fa4801 447 function AddressBook() {
c6b8b46c 448 $this->localbackendname = _("Personal address book");
81fa4801 449 }
4935919f 450
4272758c 451 /**
81fa4801 452 * Return an array of backends of a given type,
453 * or all backends if no type is specified.
4272758c 454 * @param string $type backend type
455 * @return array list of backends
81fa4801 456 */
457 function get_backend_list($type = '') {
458 $ret = array();
459 for ($i = 1 ; $i <= $this->numbackends ; $i++) {
460 if (empty($type) || $type == $this->backends[$i]->btype) {
461 $ret[] = &$this->backends[$i];
462 }
4935919f 463 }
81fa4801 464 return $ret;
465 }
4935919f 466
467
4272758c 468 /* ========================== Public ======================== */
81fa4801 469
4272758c 470 /**
471 * Add a new backend.
472 *
473 * @param string $backend backend name (without the abook_ prefix)
474 * @param mixed optional variable that is passed to the backend constructor.
475 * See each of the backend classes for valid parameters
476 * @return integer number of backends
81fa4801 477 */
478 function add_backend($backend, $param = '') {
479 $backend_name = 'abook_' . $backend;
480 eval('$newback = new ' . $backend_name . '($param);');
481 if(!empty($newback->error)) {
482 $this->error = $newback->error;
483 return false;
484 }
485
486 $this->numbackends++;
487
488 $newback->bnum = $this->numbackends;
489 $this->backends[$this->numbackends] = $newback;
62f7daa5 490
81fa4801 491 /* Store ID of first local backend added */
492 if ($this->localbackend == 0 && $newback->btype == 'local') {
493 $this->localbackend = $this->numbackends;
494 $this->localbackendname = $newback->sname;
495 }
496
497 return $this->numbackends;
498 }
4935919f 499
4935919f 500
4272758c 501 /**
502 * create string with name and email address
503 *
62f7daa5 504 * This function takes a $row array as returned by the addressbook
2e542990 505 * search and returns an e-mail address with the full name or
506 * nickname optionally prepended.
4272758c 507 * @param array $row address book entry
508 * @return string email address with real name prepended
2e542990 509 */
2e542990 510 function full_address($row) {
1ba8cd6b 511 global $addrsrch_fullname, $data_dir, $username;
20ad4fdd 512 $prefix = getPref($data_dir, $username, 'addrsrch_fullname');
513 if (($prefix != "" || (isset($addrsrch_fullname) &&
514 $prefix == $addrsrch_fullname)) && $prefix != 'noprefix') {
515 $name = ($prefix == 'nickname' ? $row['nickname'] : $row['name']);
2e542990 516 return $name . ' <' . trim($row['email']) . '>';
517 } else {
518 return trim($row['email']);
519 }
520 }
521
4272758c 522 /**
523 * Search for entries in address books
524 *
525 * Return a list of addresses matching expression in
526 * all backends of a given type.
527 * @param string $expression search expression
528 * @param integer $bnum backend number. default to search in all backends
529 * @return array search results
530 */
81fa4801 531 function search($expression, $bnum = -1) {
532 $ret = array();
533 $this->error = '';
534
535 /* Search all backends */
536 if ($bnum == -1) {
537 $sel = $this->get_backend_list('');
538 $failed = 0;
539 for ($i = 0 ; $i < sizeof($sel) ; $i++) {
540 $backend = &$sel[$i];
541 $backend->error = '';
542 $res = $backend->search($expression);
543 if (is_array($res)) {
544 $ret = array_merge($ret, $res);
545 } else {
6fd95361 546 $this->error .= "<br />\n" . $backend->error;
81fa4801 547 $failed++;
75e19c7f 548 }
549 }
4935919f 550
81fa4801 551 /* Only fail if all backends failed */
552 if( $failed >= sizeof( $sel ) ) {
553 $ret = FALSE;
4935919f 554 }
4935919f 555
81fa4801 556 } else {
4935919f 557
81fa4801 558 /* Search only one backend */
4935919f 559
81fa4801 560 $ret = $this->backends[$bnum]->search($expression);
561 if (!is_array($ret)) {
6fd95361 562 $this->error .= "<br />\n" . $this->backends[$bnum]->error;
81fa4801 563 $ret = FALSE;
564 }
565 }
566
567 return( $ret );
4935919f 568 }
569
570
4272758c 571 /**
572 * Sorted search
573 * @param string $expression search expression
574 * @param integer $bnum backend number. default to search in all backends
575 * @return array search results
576 */
81fa4801 577 function s_search($expression, $bnum = -1) {
62f7daa5 578
81fa4801 579 $ret = $this->search($expression, $bnum);
580 if ( is_array( $ret ) ) {
581 usort($ret, 'addressbook_cmp');
62f7daa5 582 }
81fa4801 583 return $ret;
584 }
4935919f 585
586
4272758c 587 /**
588 * Lookup an address by alias.
589 * Only possible in local backends.
590 * @param string $alias
591 * @param integer backend number
592 * @return array lookup results. False, if not found.
81fa4801 593 */
594 function lookup($alias, $bnum = -1) {
62f7daa5 595
81fa4801 596 $ret = array();
62f7daa5 597
81fa4801 598 if ($bnum > -1) {
599 $res = $this->backends[$bnum]->lookup($alias);
600 if (is_array($res)) {
601 return $res;
602 } else {
603 $this->error = $backend->error;
604 return false;
605 }
606 }
62f7daa5 607
81fa4801 608 $sel = $this->get_backend_list('local');
609 for ($i = 0 ; $i < sizeof($sel) ; $i++) {
610 $backend = &$sel[$i];
611 $backend->error = '';
612 $res = $backend->lookup($alias);
613 if (is_array($res)) {
614 if(!empty($res))
615 return $res;
616 } else {
617 $this->error = $backend->error;
618 return false;
619 }
620 }
62f7daa5 621
81fa4801 622 return $ret;
4935919f 623 }
624
4935919f 625
4272758c 626 /**
627 * Return all addresses
628 * @param integer $bnum backend number
629 * @return array search results
630 */
81fa4801 631 function list_addr($bnum = -1) {
632 $ret = array();
62f7daa5 633
81fa4801 634 if ($bnum == -1) {
4272758c 635 $sel = $this->get_backend_list('');
81fa4801 636 } else {
637 $sel = array(0 => &$this->backends[$bnum]);
638 }
62f7daa5 639
81fa4801 640 for ($i = 0 ; $i < sizeof($sel) ; $i++) {
641 $backend = &$sel[$i];
642 $backend->error = '';
643 $res = $backend->list_addr();
644 if (is_array($res)) {
645 $ret = array_merge($ret, $res);
646 } else {
647 $this->error = $backend->error;
648 return false;
649 }
650 }
62f7daa5 651
81fa4801 652 return $ret;
653 }
4935919f 654
4272758c 655 /**
91e0dccc 656 * Create a new address
4272758c 657 * @param array $userdata added address record
658 * @param integer $bnum backend number
659 * @return integer the backend number that the/ address was added
81fa4801 660 * to, or false if it failed.
661 */
662 function add($userdata, $bnum) {
62f7daa5 663
81fa4801 664 /* Validate data */
665 if (!is_array($userdata)) {
666 $this->error = _("Invalid input data");
667 return false;
668 }
669 if (empty($userdata['firstname']) && empty($userdata['lastname'])) {
670 $this->error = _("Name is missing");
671 return false;
672 }
673 if (empty($userdata['email'])) {
674 $this->error = _("E-mail address is missing");
675 return false;
676 }
677 if (empty($userdata['nickname'])) {
678 $userdata['nickname'] = $userdata['email'];
679 }
62f7daa5 680
81fa4801 681 if (eregi('[ \\:\\|\\#\\"\\!]', $userdata['nickname'])) {
682 $this->error = _("Nickname contains illegal characters");
683 return false;
684 }
62f7daa5 685
81fa4801 686 /* Check that specified backend accept new entries */
687 if (!$this->backends[$bnum]->writeable) {
688 $this->error = _("Addressbook is read-only");
689 return false;
690 }
62f7daa5 691
81fa4801 692 /* Add address to backend */
693 $res = $this->backends[$bnum]->add($userdata);
694 if ($res) {
695 return $bnum;
696 } else {
697 $this->error = $this->backends[$bnum]->error;
698 return false;
699 }
62f7daa5 700
81fa4801 701 return false; // Not reached
702 } /* end of add() */
703
704
4272758c 705 /**
706 * Remove the entries from address book
91e0dccc 707 * @param mixed $alias entries that have to be removed. Can be string with nickname or array with list of nicknames
4272758c 708 * @param integer $bnum backend number
709 * @return bool true if removed successfully. false if there s an error. $this->error contains error message
81fa4801 710 */
711 function remove($alias, $bnum) {
62f7daa5 712
81fa4801 713 /* Check input */
714 if (empty($alias)) {
715 return true;
716 }
62f7daa5 717
81fa4801 718 /* Convert string to single element array */
719 if (!is_array($alias)) {
720 $alias = array(0 => $alias);
721 }
62f7daa5 722
723 /* Check that specified backend is writable */
81fa4801 724 if (!$this->backends[$bnum]->writeable) {
725 $this->error = _("Addressbook is read-only");
726 return false;
727 }
62f7daa5 728
81fa4801 729 /* Remove user from backend */
730 $res = $this->backends[$bnum]->remove($alias);
731 if ($res) {
732 return $bnum;
733 } else {
734 $this->error = $this->backends[$bnum]->error;
735 return false;
736 }
62f7daa5 737
81fa4801 738 return FALSE; /* Not reached */
739 } /* end of remove() */
740
741
4272758c 742 /**
743 * Modify entry in address book
744 * @param string $alias nickname
745 * @param array $userdata newdata
746 * @param integer $bnum backend number
81fa4801 747 */
748 function modify($alias, $userdata, $bnum) {
62f7daa5 749
81fa4801 750 /* Check input */
751 if (empty($alias) || !is_string($alias)) {
752 return true;
753 }
62f7daa5 754
81fa4801 755 /* Validate data */
756 if(!is_array($userdata)) {
757 $this->error = _("Invalid input data");
758 return false;
759 }
760 if (empty($userdata['firstname']) && empty($userdata['lastname'])) {
761 $this->error = _("Name is missing");
762 return false;
763 }
764 if (empty($userdata['email'])) {
765 $this->error = _("E-mail address is missing");
766 return false;
767 }
62f7daa5 768
81fa4801 769 if (eregi('[\\: \\|\\#"\\!]', $userdata['nickname'])) {
770 $this->error = _("Nickname contains illegal characters");
771 return false;
772 }
62f7daa5 773
81fa4801 774 if (empty($userdata['nickname'])) {
775 $userdata['nickname'] = $userdata['email'];
776 }
62f7daa5 777
778 /* Check that specified backend is writable */
81fa4801 779 if (!$this->backends[$bnum]->writeable) {
780 $this->error = _("Addressbook is read-only");;
781 return false;
782 }
62f7daa5 783
81fa4801 784 /* Modify user in backend */
785 $res = $this->backends[$bnum]->modify($alias, $userdata);
786 if ($res) {
787 return $bnum;
788 } else {
789 $this->error = $this->backends[$bnum]->error;
790 return false;
791 }
62f7daa5 792
81fa4801 793 return FALSE; /* Not reached */
794 } /* end of modify() */
62f7daa5 795
796
81fa4801 797} /* End of class Addressbook */
798
8f6f9ba5 799/**
81fa4801 800 * Generic backend that all other backends extend
8f6f9ba5 801 * @package squirrelmail
c1ac62d4 802 * @subpackage addressbook
81fa4801 803 */
804class addressbook_backend {
805
806 /* Variables that all backends must provide. */
4272758c 807 /**
808 * Backend type
809 *
810 * Can be 'local' or 'remote'
811 * @var string backend type
812 */
81fa4801 813 var $btype = 'dummy';
4272758c 814 /**
815 * Internal backend name
816 * @var string
817 */
81fa4801 818 var $bname = 'dummy';
4272758c 819 /**
820 * Displayed backend name
821 * @var string
822 */
81fa4801 823 var $sname = 'Dummy backend';
62f7daa5 824
81fa4801 825 /*
826 * Variables common for all backends, but that
827 * should not be changed by the backends.
828 */
4272758c 829 /**
830 * Backend number
831 * @var integer
832 */
81fa4801 833 var $bnum = -1;
4272758c 834 /**
835 * Error messages
836 * @var string
837 */
81fa4801 838 var $error = '';
4272758c 839 /**
840 * Writeable flag
841 * @var bool
842 */
81fa4801 843 var $writeable = false;
62f7daa5 844
4272758c 845 /**
846 * Set error message
847 * @param string $string error message
848 * @return bool
849 */
81fa4801 850 function set_error($string) {
851 $this->error = '[' . $this->sname . '] ' . $string;
852 return false;
853 }
62f7daa5 854
855
81fa4801 856 /* ========================== Public ======================== */
62f7daa5 857
4272758c 858 /**
859 * Search for entries in backend
860 * @param string $expression
861 * @return bool
862 */
81fa4801 863 function search($expression) {
864 $this->set_error('search not implemented');
865 return false;
866 }
62f7daa5 867
4272758c 868 /**
869 * Find entry in backend by alias
870 * @param string $alias name used for id
871 * @return bool
872 */
81fa4801 873 function lookup($alias) {
874 $this->set_error('lookup not implemented');
875 return false;
a10110a5 876 }
62f7daa5 877
4272758c 878 /**
879 * List all entries in backend
880 * @return bool
881 */
81fa4801 882 function list_addr() {
883 $this->set_error('list_addr not implemented');
884 return false;
885 }
62f7daa5 886
4272758c 887 /**
888 * Add entry to backend
889 * @param array userdata
890 * @return bool
891 */
81fa4801 892 function add($userdata) {
893 $this->set_error('add not implemented');
894 return false;
895 }
62f7daa5 896
4272758c 897 /**
898 * Remove entry from backend
899 * @param string $alias name used for id
900 * @return bool
901 */
81fa4801 902 function remove($alias) {
903 $this->set_error('delete not implemented');
904 return false;
905 }
62f7daa5 906
4272758c 907 /**
908 * Modify entry in backend
909 * @param string $alias name used for id
910 * @param array $newuserdata new data
911 * @return bool
912 */
81fa4801 913 function modify($alias, $newuserdata) {
914 $this->set_error('modify not implemented');
915 return false;
916 }
81fa4801 917}
918
0419106e 919/*
920 PHP 5 requires that the class be made first, which seems rather
921 logical, and should have been the way it was generated the first time.
922*/
923
924require_once(SM_PATH . 'functions/abook_local_file.php');
925require_once(SM_PATH . 'functions/abook_ldap_server.php');
926
0419106e 927/* Only load database backend if database is configured */
62f7daa5 928if((isset($addrbook_dsn) && !empty($addrbook_dsn)) ||
7390e240 929 (isset($addrbook_global_dsn) && !empty($addrbook_global_dsn))) {
930 include_once(SM_PATH . 'functions/abook_database.php');
0419106e 931}
932
df788686 933/*
934 * hook allows adding different address book classes.
935 * class must follow address book class coding standards.
936 *
937 * see addressbook_backend class and functions/abook_*.php files.
7390e240 938 * @since 1.5.1 and 1.4.5
df788686 939 */
940do_hook('abook_add_class');
0419106e 941
796f91d9 942?>