Add ability for administrator to control whether or not users can edit their reply...
[squirrelmail.git] / functions / db_prefs.php
CommitLineData
82474746 1<?php
15e6162e 2
d6c32258 3/**
35586184 4 * db_prefs.php
5 *
35586184 6 * This contains functions for manipulating user preferences
7 * stored in a database, accessed though the Pear DB layer.
8 *
35586184 9 * Database:
35586184 10 *
99a6c222 11 * The preferences table should have three columns:
12 * user char \ primary
35586184 13 * prefkey char / key
14 * prefval blob
15 *
4b7dd3d9 16 * CREATE TABLE userprefs (user CHAR(128) NOT NULL DEFAULT '',
35586184 17 * prefkey CHAR(64) NOT NULL DEFAULT '',
18 * prefval BLOB NOT NULL DEFAULT '',
19 * primary key (user,prefkey));
20 *
21 * Configuration of databasename, username and password is done
3499f99f 22 * by using conf.pl or the administrator plugin
35586184 23 *
5e5daa47 24 * @copyright 1999-2015 The SquirrelMail Project Team
4b4abf93 25 * @license http://opensource.org/licenses/gpl-license.php GNU Public License
31841a9e 26 * @version $Id$
d6c32258 27 * @package squirrelmail
ace4c62c 28 * @subpackage prefs
29 * @since 1.1.3
35586184 30 */
31
ace4c62c 32/** @ignore */
33if (!defined('SM_PATH')) define('SM_PATH','../');
34
d6c32258 35/** Unknown database */
98749983 36define('SMDB_UNKNOWN', 0);
d6c32258 37/** MySQL */
98749983 38define('SMDB_MYSQL', 1);
d6c32258 39/** PostgreSQL */
98749983 40define('SMDB_PGSQL', 2);
41
099fea11 42/**
43 * don't display errors (no code execution in functions/*.php).
44 * will handle error in dbPrefs class.
45 */
46@include_once('DB.php');
35586184 47
370059dd 48global $prefs_are_cached, $prefs_cache;
2d367c68 49
4d30c1b7 50/**
51 * @ignore
52 */
370059dd 53function cachePrefValues($username) {
54 global $prefs_are_cached, $prefs_cache;
55
37d5278d 56 sqgetGlobalVar('prefs_are_cached', $prefs_are_cached, SQ_SESSION );
370059dd 57 if ($prefs_are_cached) {
37d5278d 58 sqgetGlobalVar('prefs_cache', $prefs_cache, SQ_SESSION );
370059dd 59 return;
60 }
2d367c68 61
9eb0fbd4 62 sqsession_unregister('prefs_cache');
63 sqsession_unregister('prefs_are_cached');
370059dd 64
65 $db = new dbPrefs;
66 if(isset($db->error)) {
67 printf( _("Preference database error (%s). Exiting abnormally"),
68 $db->error);
69 exit;
70 }
2d367c68 71
370059dd 72 $db->fillPrefsCache($username);
73 if (isset($db->error)) {
74 printf( _("Preference database error (%s). Exiting abnormally"),
75 $db->error);
76 exit;
77 }
78
79 $prefs_are_cached = true;
80
9eb0fbd4 81 sqsession_register($prefs_cache, 'prefs_cache');
82 sqsession_register($prefs_are_cached, 'prefs_are_cached');
370059dd 83}
84
d6c32258 85/**
ace4c62c 86 * Class used to handle connections to prefs database and operations with preferences
37b11ab0 87 *
d6c32258 88 * @package squirrelmail
ace4c62c 89 * @subpackage prefs
90 * @since 1.1.3
37b11ab0 91 *
d6c32258 92 */
370059dd 93class dbPrefs {
ace4c62c 94 /**
95 * Table used to store preferences
96 * @var string
97 */
370059dd 98 var $table = 'userprefs';
37b11ab0 99
ace4c62c 100 /**
101 * Field used to store owner of preference
102 * @var string
103 */
99a6c222 104 var $user_field = 'user';
37b11ab0 105
ace4c62c 106 /**
107 * Field used to store preference name
108 * @var string
109 */
99a6c222 110 var $key_field = 'prefkey';
37b11ab0 111
ace4c62c 112 /**
113 * Field used to store preference value
114 * @var string
115 */
99a6c222 116 var $val_field = 'prefval';
370059dd 117
ace4c62c 118 /**
119 * Database connection object
120 * @var object
121 */
370059dd 122 var $dbh = NULL;
37b11ab0 123
ace4c62c 124 /**
125 * Error messages
126 * @var string
127 */
370059dd 128 var $error = NULL;
37b11ab0 129
ace4c62c 130 /**
131 * Database type (SMDB_* constants)
132 * Is used in setKey().
133 * @var integer
134 */
98749983 135 var $db_type = SMDB_UNKNOWN;
370059dd 136
ace4c62c 137 /**
138 * Default preferences
139 * @var array
140 */
2ea6df85 141 var $default = Array('theme_default' => 0,
370059dd 142 'show_html_default' => '0');
143
06316c07 144 /**
145 * Preference owner field size
146 * @var integer
147 * @since 1.5.1
148 */
149 var $user_size = 128;
37b11ab0 150
06316c07 151 /**
152 * Preference key field size
153 * @var integer
154 * @since 1.5.1
155 */
156 var $key_size = 64;
37b11ab0 157
06316c07 158 /**
159 * Preference value field size
160 * @var integer
161 * @since 1.5.1
162 */
163 var $val_size = 65536;
164
37b11ab0 165
166
3ec364a4 167 /**
168 * initialize the default preferences array.
169 *
170 */
171 function dbPrefs() {
172 // Try and read the default preferences file.
173 $default_pref = SM_PATH . 'config/default_pref';
174 if (@file_exists($default_pref)) {
175 if ($file = @fopen($default_pref, 'r')) {
176 while (!feof($file)) {
177 $pref = fgets($file, 1024);
178 $i = strpos($pref, '=');
179 if ($i > 0) {
180 $this->default[trim(substr($pref, 0, $i))] = trim(substr($pref, $i + 1));
181 }
182 }
183 fclose($file);
184 }
185 }
186 }
187
ace4c62c 188 /**
189 * initialize DB connection object
37b11ab0 190 *
ace4c62c 191 * @return boolean true, if object is initialized
37b11ab0 192 *
ace4c62c 193 */
370059dd 194 function open() {
3499f99f 195 global $prefs_dsn, $prefs_table;
98749983 196 global $prefs_user_field, $prefs_key_field, $prefs_val_field;
06316c07 197 global $prefs_user_size, $prefs_key_size, $prefs_val_size;
3499f99f 198
099fea11 199 /* test if Pear DB class is available and freak out if it is not */
200 if (! class_exists('DB')) {
201 // same error also in abook_database.php
ae13f72f 202 $this->error = _("Could not include PEAR database functions required for the database backend.") . "\n";
099fea11 203 $this->error .= sprintf(_("Is PEAR installed, and is the include path set correctly to find %s?"),
ae13f72f 204 'DB.php') . "\n";
099fea11 205 $this->error .= _("Please contact your system administrator and report this error.");
206 return false;
207 }
208
370059dd 209 if(isset($this->dbh)) {
210 return true;
211 }
3499f99f 212
98749983 213 if (preg_match('/^mysql/', $prefs_dsn)) {
214 $this->db_type = SMDB_MYSQL;
215 } elseif (preg_match('/^pgsql/', $prefs_dsn)) {
216 $this->db_type = SMDB_PGSQL;
217 }
218
3499f99f 219 if (!empty($prefs_table)) {
220 $this->table = $prefs_table;
221 }
99a6c222 222 if (!empty($prefs_user_field)) {
223 $this->user_field = $prefs_user_field;
224 }
865050ce 225
226 // the default user field is "user", which in PostgreSQL
227 // is an identifier and causes errors if not escaped
228 //
229 if ($this->db_type == SMDB_PGSQL) {
230 $this->user_field = '"' . $this->user_field . '"';
231 }
232
99a6c222 233 if (!empty($prefs_key_field)) {
234 $this->key_field = $prefs_key_field;
235 }
236 if (!empty($prefs_val_field)) {
237 $this->val_field = $prefs_val_field;
238 }
06316c07 239 if (!empty($prefs_user_size)) {
240 $this->user_size = (int) $prefs_user_size;
241 }
242 if (!empty($prefs_key_size)) {
243 $this->key_size = (int) $prefs_key_size;
244 }
245 if (!empty($prefs_val_size)) {
246 $this->val_size = (int) $prefs_val_size;
247 }
70561170 248 $dbh = DB::connect($prefs_dsn, true);
2d367c68 249
286fe80b 250 if(DB::isError($dbh)) {
2d367c68 251 $this->error = DB::errorMessage($dbh);
252 return false;
253 }
254
255 $this->dbh = $dbh;
256 return true;
370059dd 257 }
82474746 258
ace4c62c 259 /**
260 * Function used to handle database connection errors
37b11ab0 261 *
202bcbcc 262 * @param object PEAR Error object
37b11ab0 263 *
ace4c62c 264 */
370059dd 265 function failQuery($res = NULL) {
2d367c68 266 if($res == NULL) {
267 printf(_("Preference database error (%s). Exiting abnormally"),
370059dd 268 $this->error);
2d367c68 269 } else {
270 printf(_("Preference database error (%s). Exiting abnormally"),
370059dd 271 DB::errorMessage($res));
2d367c68 272 }
273 exit;
370059dd 274 }
82474746 275
ace4c62c 276 /**
277 * Get user's prefs setting
37b11ab0 278 *
ace4c62c 279 * @param string $user user name
280 * @param string $key preference name
281 * @param mixed $default (since 1.2.5) default value
37b11ab0 282 *
ace4c62c 283 * @return mixed preference value
37b11ab0 284 *
ace4c62c 285 */
370059dd 286 function getKey($user, $key, $default = '') {
287 global $prefs_cache;
2d367c68 288
971c7b1a 289 $temp = array(&$user, &$key);
290 $result = do_hook('get_pref_override', $temp);
291 if (is_null($result)) {
292 cachePrefValues($user);
2d367c68 293
971c7b1a 294 if (isset($prefs_cache[$key])) {
295 $result = $prefs_cache[$key];
62337234 296 } else {
971c7b1a 297//FIXME: is there a justification for having two prefs hooks so close? who uses them?
298 $temp = array(&$user, &$key);
299 $result = do_hook('get_pref', $temp);
300 if (is_null($result)) {
301 if (isset($this->default[$key])) {
302 $result = $this->default[$key];
303 } else {
304 $result = $default;
305 }
306 }
62337234 307 }
2d367c68 308 }
971c7b1a 309 return $result;
370059dd 310 }
2d367c68 311
ace4c62c 312 /**
313 * Delete user's prefs setting
37b11ab0 314 *
202bcbcc 315 * @param string $user user name
37b11ab0 316 * @param string $key preference name
317 *
ace4c62c 318 * @return boolean
37b11ab0 319 *
ace4c62c 320 */
370059dd 321 function deleteKey($user, $key) {
322 global $prefs_cache;
82474746 323
b279d7f4 324 if (!$this->open()) {
325 return false;
326 }
99a6c222 327 $query = sprintf("DELETE FROM %s WHERE %s='%s' AND %s='%s'",
370059dd 328 $this->table,
99a6c222 329 $this->user_field,
370059dd 330 $this->dbh->quoteString($user),
99a6c222 331 $this->key_field,
370059dd 332 $this->dbh->quoteString($key));
82474746 333
2d367c68 334 $res = $this->dbh->simpleQuery($query);
370059dd 335 if(DB::isError($res)) {
2d367c68 336 $this->failQuery($res);
370059dd 337 }
338
339 unset($prefs_cache[$key]);
82474746 340
2d367c68 341 return true;
370059dd 342 }
82474746 343
ace4c62c 344 /**
345 * Set user's preference
37b11ab0 346 *
347 * @param string $user user name
348 * @param string $key preference name
349 * @param mixed $value preference value
350 *
ace4c62c 351 * @return boolean
37b11ab0 352 *
ace4c62c 353 */
370059dd 354 function setKey($user, $key, $value) {
b279d7f4 355 if (!$this->open()) {
356 return false;
357 }
06316c07 358
359 /**
360 * Check if username fits into db field
361 */
362 if (strlen($user) > $this->user_size) {
363 $this->error = "Oversized username value."
5e07597f 364 ." Your preferences can't be saved."
6f4c512c 365 ." See the administrator's manual or contact your system administrator.";
06316c07 366
367 /**
202bcbcc 368 * Debugging function. Can be used to log all issues that trigger
369 * oversized field errors. Function should be enabled in all three
06316c07 370 * strlen checks. See http://www.php.net/error-log
371 */
372 // error_log($user.'|'.$key.'|'.$value."\n",3,'/tmp/oversized_log');
373
374 // error is fatal
375 $this->failQuery(null);
376 }
377 /**
378 * Check if preference key fits into db field
379 */
380 if (strlen($key) > $this->key_size) {
381 $err_msg = "Oversized user's preference key."
5e07597f 382 ." Some preferences were not saved."
6f4c512c 383 ." See the administrator's manual or contact your system administrator.";
06316c07 384 // error is not fatal. Only some preference is not saved.
385 trigger_error($err_msg,E_USER_WARNING);
386 return false;
387 }
388 /**
389 * Check if preference value fits into db field
390 */
391 if (strlen($value) > $this->val_size) {
392 $err_msg = "Oversized user's preference value."
5e07597f 393 ." Some preferences were not saved."
6f4c512c 394 ." See the administrator's manual or contact your system administrator.";
06316c07 395 // error is not fatal. Only some preference is not saved.
396 trigger_error($err_msg,E_USER_WARNING);
397 return false;
398 }
399
400
98749983 401 if ($this->db_type == SMDB_MYSQL) {
402 $query = sprintf("REPLACE INTO %s (%s, %s, %s) ".
403 "VALUES('%s','%s','%s')",
404 $this->table,
405 $this->user_field,
406 $this->key_field,
407 $this->val_field,
408 $this->dbh->quoteString($user),
409 $this->dbh->quoteString($key),
410 $this->dbh->quoteString($value));
411
412 $res = $this->dbh->simpleQuery($query);
413 if(DB::isError($res)) {
414 $this->failQuery($res);
415 }
416 } elseif ($this->db_type == SMDB_PGSQL) {
417 $this->dbh->simpleQuery("BEGIN TRANSACTION");
418 $query = sprintf("DELETE FROM %s WHERE %s='%s' AND %s='%s'",
419 $this->table,
420 $this->user_field,
421 $this->dbh->quoteString($user),
422 $this->key_field,
423 $this->dbh->quoteString($key));
424 $res = $this->dbh->simpleQuery($query);
425 if (DB::isError($res)) {
426 $this->dbh->simpleQuery("ROLLBACK TRANSACTION");
427 $this->failQuery($res);
428 }
429 $query = sprintf("INSERT INTO %s (%s, %s, %s) VALUES ('%s', '%s', '%s')",
430 $this->table,
431 $this->user_field,
432 $this->key_field,
433 $this->val_field,
434 $this->dbh->quoteString($user),
435 $this->dbh->quoteString($key),
436 $this->dbh->quoteString($value));
437 $res = $this->dbh->simpleQuery($query);
438 if (DB::isError($res)) {
439 $this->dbh->simpleQuery("ROLLBACK TRANSACTION");
440 $this->failQuery($res);
441 }
442 $this->dbh->simpleQuery("COMMIT TRANSACTION");
443 } else {
444 $query = sprintf("DELETE FROM %s WHERE %s='%s' AND %s='%s'",
445 $this->table,
446 $this->user_field,
447 $this->dbh->quoteString($user),
448 $this->key_field,
449 $this->dbh->quoteString($key));
450 $res = $this->dbh->simpleQuery($query);
451 if (DB::isError($res)) {
452 $this->failQuery($res);
453 }
454 $query = sprintf("INSERT INTO %s (%s, %s, %s) VALUES ('%s', '%s', '%s')",
455 $this->table,
456 $this->user_field,
457 $this->key_field,
458 $this->val_field,
459 $this->dbh->quoteString($user),
460 $this->dbh->quoteString($key),
461 $this->dbh->quoteString($value));
462 $res = $this->dbh->simpleQuery($query);
463 if (DB::isError($res)) {
464 $this->failQuery($res);
465 }
370059dd 466 }
2d367c68 467
468 return true;
370059dd 469 }
82474746 470
ace4c62c 471 /**
472 * Fill preference cache array
37b11ab0 473 *
ace4c62c 474 * @param string $user user name
37b11ab0 475 *
ace4c62c 476 * @since 1.2.3
37b11ab0 477 *
ace4c62c 478 */
370059dd 479 function fillPrefsCache($user) {
480 global $prefs_cache;
2d367c68 481
b279d7f4 482 if (!$this->open()) {
483 return;
484 }
370059dd 485
486 $prefs_cache = array();
99a6c222 487 $query = sprintf("SELECT %s as prefkey, %s as prefval FROM %s ".
488 "WHERE %s = '%s'",
489 $this->key_field,
490 $this->val_field,
370059dd 491 $this->table,
99a6c222 492 $this->user_field,
370059dd 493 $this->dbh->quoteString($user));
494 $res = $this->dbh->query($query);
495 if (DB::isError($res)) {
496 $this->failQuery($res);
497 }
498
499 while ($row = $res->fetchRow(DB_FETCHMODE_ASSOC)) {
500 $prefs_cache[$row['prefkey']] = $row['prefval'];
501 }
502 }
503
370059dd 504} /* end class dbPrefs */
82474746 505
506
4d30c1b7 507/**
37b11ab0 508 * Returns the value for the requested preference
4d30c1b7 509 * @ignore
510 */
37b11ab0 511function getPref($data_dir, $username, $pref_name, $default = '') {
370059dd 512 $db = new dbPrefs;
513 if(isset($db->error)) {
2d367c68 514 printf( _("Preference database error (%s). Exiting abnormally"),
370059dd 515 $db->error);
2d367c68 516 exit;
370059dd 517 }
518
37b11ab0 519 return $db->getKey($username, $pref_name, $default);
370059dd 520}
521
4d30c1b7 522/**
37b11ab0 523 * Remove the desired preference setting ($pref_name)
4d30c1b7 524 * @ignore
525 */
37b11ab0 526function removePref($data_dir, $username, $pref_name) {
1fa62ab9 527 global $prefs_cache;
370059dd 528 $db = new dbPrefs;
529 if(isset($db->error)) {
530 $db->failQuery();
531 }
532
37b11ab0 533 $db->deleteKey($username, $pref_name);
88a99543 534
37b11ab0 535 if (isset($prefs_cache[$pref_name])) {
536 unset($prefs_cache[$pref_name]);
88a99543 537 }
538
539 sqsession_register($prefs_cache , 'prefs_cache');
370059dd 540 return;
541}
542
4d30c1b7 543/**
37b11ab0 544 * Sets the desired preference setting ($pref_name) to whatever is in $value
4d30c1b7 545 * @ignore
546 */
37b11ab0 547function setPref($data_dir, $username, $pref_name, $value) {
370059dd 548 global $prefs_cache;
549
37b11ab0 550 if (isset($prefs_cache[$pref_name]) && ($prefs_cache[$pref_name] == $value)) {
1fa62ab9 551 return;
370059dd 552 }
553
37b11ab0 554 if ($value === '') {
555 removePref($data_dir, $username, $pref_name);
370059dd 556 return;
557 }
558
559 $db = new dbPrefs;
560 if(isset($db->error)) {
561 $db->failQuery();
562 }
563
37b11ab0 564 $db->setKey($username, $pref_name, $value);
565 $prefs_cache[$pref_name] = $value;
370059dd 566 assert_options(ASSERT_ACTIVE, 1);
567 assert_options(ASSERT_BAIL, 1);
37b11ab0 568 assert ('$value == $prefs_cache[$pref_name]');
88a99543 569 sqsession_register($prefs_cache , 'prefs_cache');
370059dd 570 return;
571}
572
4d30c1b7 573/**
574 * This checks if the prefs are available
575 * @ignore
576 */
370059dd 577function checkForPrefs($data_dir, $username) {
578 $db = new dbPrefs;
579 if(isset($db->error)) {
580 $db->failQuery();
581 }
582}
583
4d30c1b7 584/**
585 * Writes the Signature
586 * @ignore
587 */
37b11ab0 588function setSig($data_dir, $username, $number, $value) {
16e5635d 589 if ($number == "g") {
590 $key = '___signature___';
591 } else {
592 $key = sprintf('___sig%s___', $number);
593 }
37b11ab0 594 setPref($data_dir, $username, $key, $value);
370059dd 595 return;
596}
597
4d30c1b7 598/**
599 * Gets the signature
600 * @ignore
601 */
16e5635d 602function getSig($data_dir, $username, $number) {
16e5635d 603 if ($number == "g") {
604 $key = '___signature___';
605 } else {
606 $key = sprintf('___sig%d___', $number);
607 }
57f1d1c1 608 return getPref($data_dir, $username, $key);
370059dd 609}