Merge branch 'develop' into 14a22

This commit is contained in:
Laurent Destailleur 2021-03-20 19:48:43 +01:00 committed by GitHub
commit a2b3afb511
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
17 changed files with 294 additions and 144 deletions

View File

@ -19,9 +19,9 @@ WARNING:
Following changes may create regressions for some external modules, but were necessary to make Dolibarr better: Following changes may create regressions for some external modules, but were necessary to make Dolibarr better:
* The ICS value for direct debit or credit transfer is now store on each bank account instead of into the global setup. * The ICS value for direct debit or credit transfer is now store on each bank account instead of into the global setup.
* API /setup/shipment_methods has been replaced with API /setup/shipping_methods * API /setup/shipment_methods has been replaced with API /setup/shipping_methods
* Field "total" renamed into to "total_ht" in llx_facture, llx_facture_rec for better field name consistency * Field "total" renamed into to "total_ht" for table llx_facture, llx_facture_rec for better field name consistency
* Field "tva" renamed into to "total_tva" in llx_facture, llx_facture_rec, llx_propal, llx_supplier_proposal, llx_commande, llx_commande_fournisseur for better field name consistency * Field "tva" renamed into "total_tva" for table llx_propal, llx_supplier_proposal, llx_commande, llx_commande_fournisseur for better field name consistency
* Field "total" renamed into "total_ttc" in llx_propal, llx_supplier_proposal for better field name consistency * Field "total" renamed into "total_ttc" for table lx_propal, llx_supplier_proposal for better field name consistency
* If your database is PostgreSql, you must use version 9.1.0 or more (Dolibarr need the SQL function CONCAT) * If your database is PostgreSql, you must use version 9.1.0 or more (Dolibarr need the SQL function CONCAT)
* If your database is MySql or MariaDB, you need at least version 5.1 * If your database is MySql or MariaDB, you need at least version 5.1

View File

@ -286,6 +286,7 @@ class modBom extends DolibarrModules
$langs->load("mrp"); $langs->load("mrp");
$this->export_code[$r] = $this->rights_class.'_'.$r; $this->export_code[$r] = $this->rights_class.'_'.$r;
$this->export_label[$r] = 'BomAndBomLines'; // Translation key (used only if key ExportDataset_xxx_z not found) $this->export_label[$r] = 'BomAndBomLines'; // Translation key (used only if key ExportDataset_xxx_z not found)
$this->export_permission[$r] = array(array("bom", "read"));
$this->export_icon[$r] = 'bom'; $this->export_icon[$r] = 'bom';
$keyforclass = 'BOM'; $keyforclass = 'BOM';
$keyforclassfile = '/bom/class/bom.class.php'; $keyforclassfile = '/bom/class/bom.class.php';

View File

@ -109,6 +109,12 @@ class modWebsite extends DolibarrModules
$this->rights[$r][4] = 'delete'; $this->rights[$r][4] = 'delete';
$r++; $r++;
$this->rights[$r][0] = 10008;
$this->rights[$r][1] = 'Export website content';
$this->rights[$r][3] = 0;
$this->rights[$r][4] = 'export';
$r++;
// Main menu entries // Main menu entries
$r = 0; $r = 0;
$this->menu[$r] = array('fk_menu'=>'0', // Use 'fk_mainmenu=xxx' or 'fk_mainmenu=xxx,fk_leftmenu=yyy' where xxx is mainmenucode and yyy is a leftmenucode $this->menu[$r] = array('fk_menu'=>'0', // Use 'fk_mainmenu=xxx' or 'fk_mainmenu=xxx,fk_leftmenu=yyy' where xxx is mainmenucode and yyy is a leftmenucode
@ -130,6 +136,7 @@ class modWebsite extends DolibarrModules
$this->export_code[$r] = $this->rights_class.'_'.$r; $this->export_code[$r] = $this->rights_class.'_'.$r;
$this->export_label[$r] = 'MyWebsitePages'; // Translation key (used only if key ExportDataset_xxx_z not found) $this->export_label[$r] = 'MyWebsitePages'; // Translation key (used only if key ExportDataset_xxx_z not found)
$this->export_permission[$r] = array(array("website", "export"));
$this->export_icon[$r] = 'globe'; $this->export_icon[$r] = 'globe';
$keyforclass = 'WebsitePage'; $keyforclass = 'WebsitePage';
$keyforclassfile = '/website/class/websitepage.class.php'; $keyforclassfile = '/website/class/websitepage.class.php';

View File

@ -154,6 +154,9 @@ $upload_dir = $conf->export->dir_temp.'/'.$user->id;
//$usefilters=($conf->global->MAIN_FEATURES_LEVEL > 1); //$usefilters=($conf->global->MAIN_FEATURES_LEVEL > 1);
$usefilters = 1; $usefilters = 1;
// Security check
$result = restrictedArea($user, 'export');
/* /*
* Actions * Actions
@ -449,7 +452,7 @@ if ($step == 1 || !$datatoexport) {
if ($objexport->array_export_perms[$key]) { if ($objexport->array_export_perms[$key]) {
print '<a href="'.DOL_URL_ROOT.'/exports/export.php?step=2&module_position='.$objexport->array_export_module[$key]->module_position.'&datatoexport='.$objexport->array_export_code[$key].'">'.img_picto($langs->trans("NewExport"), 'next', 'class="fa-15x"').'</a>'; print '<a href="'.DOL_URL_ROOT.'/exports/export.php?step=2&module_position='.$objexport->array_export_module[$key]->module_position.'&datatoexport='.$objexport->array_export_code[$key].'">'.img_picto($langs->trans("NewExport"), 'next', 'class="fa-15x"').'</a>';
} else { } else {
print $langs->trans("NotEnoughPermissions"); print '<span class="opacitymedium">'.$langs->trans("NotEnoughPermissions").'</span>';
} }
print '</td></tr>'; print '</td></tr>';
} }

View File

@ -27,11 +27,12 @@ require_once DOL_DOCUMENT_ROOT.'/exports/class/export.class.php';
// Load translation files required by the page // Load translation files required by the page
$langs->load("exports"); $langs->load("exports");
$export = new Export($db);
$export->load_arrays($user);
// Security check // Security check
$result = restrictedArea($user, 'export'); $result = restrictedArea($user, 'export');
$export = new Export($db);
$export->load_arrays($user);
/* /*
* View * View

View File

@ -32,6 +32,8 @@ $langs->load("users");
// Security check // Security check
$id = GETPOST('id', 'int'); $id = GETPOST('id', 'int');
$ref = GETPOST('ref', 'alpha');
$object = new User($db); $object = new User($db);
if ($id > 0 || !empty($ref)) { if ($id > 0 || !empty($ref)) {
$result = $object->fetch($id, $ref, '', 1); $result = $object->fetch($id, $ref, '', 1);

View File

@ -32,9 +32,11 @@ require_once DOL_DOCUMENT_ROOT.'/user/class/user.class.php';
require_once DOL_DOCUMENT_ROOT.'/core/triggers/interface_50_modNotification_Notification.class.php'; require_once DOL_DOCUMENT_ROOT.'/core/triggers/interface_50_modNotification_Notification.class.php';
// Load translation files required by page // Load translation files required by page
$langs->loadLangs(array('companies', 'mails', 'admin', 'other')); $langs->loadLangs(array('companies', 'mails', 'admin', 'other', 'errors'));
$id = GETPOST("id", 'int'); $id = GETPOST("id", 'int');
$ref = GETPOST('ref', 'alpha');
$action = GETPOST('action', 'aZ09'); $action = GETPOST('action', 'aZ09');
$actionid = GETPOST('actionid'); $actionid = GETPOST('actionid');
@ -63,11 +65,24 @@ $pagenext = $page + 1;
$now = dol_now(); $now = dol_now();
// Security check
$object = new User($db);
if ($id > 0 || !empty($ref)) {
$result = $object->fetch($id, $ref, '', 1);
$object->getrights();
}
$permissiontoadd = (($object->id == $user->id) || (!empty($user->rights->user->user->lire)));
/* /*
* Actions * Actions
*/ */
if (GETPOST('cancel', 'alpha')) {
$action = 'list';
}
// Add a notification // Add a notification
if ($action == 'add') { if ($action == 'add') {
$error = 0; $error = 0;
@ -75,6 +90,7 @@ if ($action == 'add') {
if ($actionid <= 0) { if ($actionid <= 0) {
setEventMessages($langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("Action")), null, 'errors'); setEventMessages($langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("Action")), null, 'errors');
$error++; $error++;
$action = 'create';
} }
if (!$error) { if (!$error) {
@ -98,6 +114,7 @@ if ($action == 'add') {
$db->commit(); $db->commit();
} else { } else {
$db->rollback(); $db->rollback();
$action = 'create';
} }
} }
} }
@ -185,7 +202,7 @@ if ($result > 0) {
// Add notification form // Add notification form
print load_fiche_titre($langs->trans("AddNewNotification"), '', ''); // print load_fiche_titre($langs->trans("AddNewNotification"), '', '');
print '<form action="'.$_SERVER["PHP_SELF"].'?id='.$id.'" method="post">'; print '<form action="'.$_SERVER["PHP_SELF"].'?id='.$id.'" method="post">';
print '<input type="hidden" name="token" value="'.newToken().'">'; print '<input type="hidden" name="token" value="'.newToken().'">';
@ -194,7 +211,7 @@ if ($result > 0) {
$param = "&id=".$id; $param = "&id=".$id;
// Line with titles // Line with titles
print '<table width="100%" class="noborder">'; /* print '<table width="100%" class="noborder">';
print '<tr class="liste_titre">'; print '<tr class="liste_titre">';
print_liste_field_titre("Target", $_SERVER["PHP_SELF"], "c.lastname,c.firstname", '', $param, 'width="45%"', $sortfield, $sortorder); print_liste_field_titre("Target", $_SERVER["PHP_SELF"], "c.lastname,c.firstname", '', $param, 'width="45%"', $sortfield, $sortorder);
print_liste_field_titre("Action", $_SERVER["PHP_SELF"], "", '', $param, 'width="35%"', $sortfield, $sortorder); print_liste_field_titre("Action", $_SERVER["PHP_SELF"], "", '', $param, 'width="35%"', $sortfield, $sortorder);
@ -202,7 +219,47 @@ if ($result > 0) {
print_liste_field_titre(''); print_liste_field_titre('');
print "</tr>\n"; print "</tr>\n";
print '</table>';
print '<br>';
*/
// List of notifications enabled for contacts
$sql = "SELECT n.rowid, n.type,";
$sql .= " a.code, a.label,";
$sql .= " c.rowid as userid, c.lastname, c.firstname, c.email";
$sql .= " FROM ".MAIN_DB_PREFIX."c_action_trigger as a,";
$sql .= " ".MAIN_DB_PREFIX."notify_def as n,";
$sql .= " ".MAIN_DB_PREFIX."user c";
$sql .= " WHERE a.rowid = n.fk_action";
$sql .= " AND c.rowid = n.fk_user";
$sql .= " AND c.rowid = ".$object->id;
$resql = $db->query($sql);
if ($resql) {
$num = $db->num_rows($resql);
} else {
dol_print_error($db);
}
$newcardbutton = dolGetButtonTitle($langs->trans('New'), '', 'fa fa-plus-circle', $_SERVER["PHP_SELF"].'?id='.$object->id.'&action=create&backtopage='.urlencode($_SERVER['PHP_SELF']), '', $permissiontoadd);
$title = $langs->trans("ListOfActiveNotifications");
// List of active notifications
//print load_fiche_titre($langs->trans("ListOfActiveNotifications").' ('.$num.')', '', '');
print_barre_liste($title, $page, $_SERVER["PHP_SELF"], $param, $sortfield, $sortorder, '', $num, $num, 'email', 0, $newcardbutton, '', $limit, 0, 0, 1);
// Line with titles
print '<table width="100%" class="noborder">';
print '<tr class="liste_titre">';
print_liste_field_titre("Target", $_SERVER["PHP_SELF"], "c.lastname,c.firstname", '', $param, 'width="45%"', $sortfield, $sortorder);
print_liste_field_titre("Action", $_SERVER["PHP_SELF"], "", '', $param, 'width="35%"', $sortfield, $sortorder);
print_liste_field_titre("Type", $_SERVER["PHP_SELF"], "n.type", '', $param, 'width="10%"', $sortfield, $sortorder);
print_liste_field_titre('', '', '');
print '</tr>';
if ($action == 'create') {
// $listofemails=$object->thirdparty_and_contact_email_array(); // $listofemails=$object->thirdparty_and_contact_email_array();
if ($object->email) { if ($object->email) {
$actions = array(); $actions = array();
@ -231,52 +288,18 @@ if ($result > 0) {
$type = array('email'=>$langs->trans("EMail")); $type = array('email'=>$langs->trans("EMail"));
print $form->selectarray("typeid", $type); print $form->selectarray("typeid", $type);
print '</td>'; print '</td>';
print '<td class="right"><input type="submit" class="button" value="'.$langs->trans("Add").'"></td>'; print '<td class="nowraponall">';
print '<input type="submit" class="button" value="'.$langs->trans("Add").'">';
print '&nbsp;';
print '<input type="submit" class="button" name="cancel" value="'.$langs->trans("Cancel").'">';
print '</td>';
print '</tr>'; print '</tr>';
} else { } else {
print '<tr class="oddeven"><td colspan="4">'; print '<tr class="oddeven"><td colspan="4">';
print $langs->trans("YouMustAssignUserMailFirst"); print $langs->trans("YouMustAssignUserMailFirst");
print '</td></tr>'; print '</td></tr>';
} }
print '</table>';
print '</form>';
print '<br>';
// List of notifications enabled for contacts
$sql = "SELECT n.rowid, n.type,";
$sql .= " a.code, a.label,";
$sql .= " c.rowid as userid, c.lastname, c.firstname, c.email";
$sql .= " FROM ".MAIN_DB_PREFIX."c_action_trigger as a,";
$sql .= " ".MAIN_DB_PREFIX."notify_def as n,";
$sql .= " ".MAIN_DB_PREFIX."user c";
$sql .= " WHERE a.rowid = n.fk_action";
$sql .= " AND c.rowid = n.fk_user";
$sql .= " AND c.rowid = ".$object->id;
$resql = $db->query($sql);
if ($resql) {
$num = $db->num_rows($resql);
} else { } else {
dol_print_error($db);
}
// List of active notifications
print load_fiche_titre($langs->trans("ListOfActiveNotifications").' ('.$num.')', '', '');
// Line with titles
print '<table width="100%" class="noborder">';
print '<tr class="liste_titre">';
print_liste_field_titre("Target", $_SERVER["PHP_SELF"], "c.lastname,c.firstname", '', $param, 'width="45%"', $sortfield, $sortorder);
print_liste_field_titre("Action", $_SERVER["PHP_SELF"], "", '', $param, 'width="35%"', $sortfield, $sortorder);
print_liste_field_titre("Type", $_SERVER["PHP_SELF"], "n.type", '', $param, 'width="10%"', $sortfield, $sortorder);
print_liste_field_titre('', '', '');
print '</tr>';
$langs->load("errors");
$langs->load("other");
if ($num) { if ($num) {
$i = 0; $i = 0;
@ -364,9 +387,12 @@ if ($result > 0) {
print '+ <a href="'.DOL_URL_ROOT.'/admin/notification.php">'.$langs->trans("SeeModuleSetup", $langs->transnoentitiesnoconv("Module600Name")).'</a>'; print '+ <a href="'.DOL_URL_ROOT.'/admin/notification.php">'.$langs->trans("SeeModuleSetup", $langs->transnoentitiesnoconv("Module600Name")).'</a>';
print '</td></tr>'; print '</td></tr>';
}*/ }*/
}
print '</table>'; print '</table>';
print '</form>';
print '<br><br>'."\n"; print '<br><br>'."\n";
@ -422,7 +448,7 @@ if ($result > 0) {
print '<input type="hidden" name="id" value="'.$object->id.'">'; print '<input type="hidden" name="id" value="'.$object->id.'">';
// List of notifications done // List of notifications done
print_barre_liste($langs->trans("ListOfNotificationsDone"), $page, $_SERVER["PHP_SELF"], $param, $sortfield, $sortorder, '', $num, $nbtotalofrecords, '', 0, '', '', $limit); print_barre_liste($langs->trans("ListOfNotificationsDone"), $page, $_SERVER["PHP_SELF"], $param, $sortfield, $sortorder, '', $num, $nbtotalofrecords, 'email', 0, '', '', $limit);
// Line with titles // Line with titles
print '<table width="100%" class="noborder">'; print '<table width="100%" class="noborder">';

View File

@ -25,7 +25,7 @@ $langs->loadLangs(array("admin", "products"));
$action = GETPOST('action', 'alphanohtml'); $action = GETPOST('action', 'alphanohtml');
// Security check // Security check
if (!$user->admin || (empty($conf->product->enabled) && empty($conf->service->enabled))) { if (!$user->admin || empty($conf->variants->enabled)) {
accessforbidden(); accessforbidden();
} }

View File

@ -36,7 +36,24 @@ require '../../main.inc.php';
require_once DOL_DOCUMENT_ROOT.'/product/class/product.class.php'; require_once DOL_DOCUMENT_ROOT.'/product/class/product.class.php';
require_once DOL_DOCUMENT_ROOT.'/variants/class/ProductCombination.class.php'; require_once DOL_DOCUMENT_ROOT.'/variants/class/ProductCombination.class.php';
header('Content-Type: application/json'); $permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/*
* View
*/
top_httphead('application/json');
$id = GETPOST('id', 'int'); $id = GETPOST('id', 'int');

View File

@ -36,7 +36,24 @@ require_once DOL_DOCUMENT_ROOT.'/product/class/product.class.php';
require_once DOL_DOCUMENT_ROOT.'/variants/class/ProductAttribute.class.php'; require_once DOL_DOCUMENT_ROOT.'/variants/class/ProductAttribute.class.php';
require_once DOL_DOCUMENT_ROOT.'/variants/class/ProductAttributeValue.class.php'; require_once DOL_DOCUMENT_ROOT.'/variants/class/ProductAttributeValue.class.php';
header('Content-Type: application/json'); $permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/*
* View
*/
top_httphead('application/json');
$id = GETPOST('id', 'int'); $id = GETPOST('id', 'int');

View File

@ -37,6 +37,18 @@ if (!defined('NOREQUIRETRAN')) {
require '../../main.inc.php'; require '../../main.inc.php';
$permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/* /*
* View * View

View File

@ -36,6 +36,18 @@ if ($object->fetch($id) < 1) {
exit(); exit();
} }
$permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/* /*
* Actions * Actions

View File

@ -64,6 +64,18 @@ if ($id > 0 || $ref) {
$selectedvariant = $_SESSION['addvariant_'.$object->id]; $selectedvariant = $_SESSION['addvariant_'.$object->id];
$permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/* /*
* Actions * Actions

View File

@ -24,6 +24,18 @@ $label = GETPOST('label', 'alpha');
$backtopage = GETPOST('backtopage', 'alpha'); $backtopage = GETPOST('backtopage', 'alpha');
$action = GETPOST('action', 'alpha'); $action = GETPOST('action', 'alpha');
$permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/* /*
* Actions * Actions

View File

@ -36,6 +36,18 @@ if ($object->fetch($id) < 1) {
exit(); exit();
} }
$permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/* /*
* Actions * Actions

View File

@ -21,6 +21,18 @@ require DOL_DOCUMENT_ROOT.'/variants/class/ProductAttribute.class.php';
$action = GETPOST('action', 'aZ09'); $action = GETPOST('action', 'aZ09');
$object = new ProductAttribute($db); $object = new ProductAttribute($db);
$permissiontoread = $user->rights->produit->lire || $user->rights->service->lire;
// Security check
if (empty($conf->variants->enabled)) {
accessforbidden('Module not enabled');
}
if ($user->socid > 0) { // Protection if external user
accessforbidden();
}
//$result = restrictedArea($user, 'variant');
if (!$permissiontoread) accessforbidden();
/* /*

View File

@ -477,7 +477,7 @@ if ($massaction == 'setcategory' && GETPOST('confirmmassaction', 'alpha') && $us
} }
// Replacement of string into pages // Replacement of string into pages
if ($massaction == 'replace' && GETPOST('confirmmassaction', 'alpha')) { if ($massaction == 'replace' && GETPOST('confirmmassaction', 'alpha') && $usercanedit) {
$replacestring = GETPOST('replacestring', 'none'); $replacestring = GETPOST('replacestring', 'none');
if (empty($user->rights->website->writephp)) { if (empty($user->rights->website->writephp)) {
@ -567,7 +567,7 @@ if ($action == 'adddir' && $permtouploadfile)
*/ */
// Add site // Add site
if ($action == 'addsite') { if ($action == 'addsite' && $usercanedit) {
$db->begin(); $db->begin();
if (GETPOST('virtualhost', 'alpha') && !preg_match('/^http/', GETPOST('virtualhost', 'alpha'))) { if (GETPOST('virtualhost', 'alpha') && !preg_match('/^http/', GETPOST('virtualhost', 'alpha'))) {
@ -625,7 +625,7 @@ if ($action == 'addsite') {
} }
// Add page/container // Add page/container
if ($action == 'addcontainer') { if ($action == 'addcontainer' && $usercanedit) {
dol_mkdir($pathofwebsite); dol_mkdir($pathofwebsite);
$db->begin(); $db->begin();
@ -1148,7 +1148,7 @@ if ($action == 'addcontainer') {
} }
// Delete site // Delete site
if ($action == 'confirm_deletesite' && $confirm == 'yes') { if ($action == 'confirm_deletesite' && $confirm == 'yes' && $permissiontodelete) {
$error = 0; $error = 0;
$db->begin(); $db->begin();
@ -1276,7 +1276,7 @@ if (!GETPOSTISSET('pageid')) {
} }
// Update css Update site properties // Update css Update site properties
if ($action == 'updatecss') { if ($action == 'updatecss' && $usercanedit) {
// If we tried to reload another site/page, we stay on editcss mode. // If we tried to reload another site/page, we stay on editcss mode.
if (GETPOST('refreshsite') || GETPOST('refreshsite_x') || GETPOST('refreshsite.x') || GETPOST('refreshpage') || GETPOST('refreshpage_x') || GETPOST('refreshpage.x')) { if (GETPOST('refreshsite') || GETPOST('refreshsite_x') || GETPOST('refreshsite.x') || GETPOST('refreshpage') || GETPOST('refreshpage_x') || GETPOST('refreshpage.x')) {
$action = 'editcss'; $action = 'editcss';
@ -1523,7 +1523,7 @@ if ($action == 'updatecss') {
} }
// Update page // Update page
if ($action == 'setashome') { if ($action == 'setashome' && $usercanedit) {
$db->begin(); $db->begin();
$object->fetch(0, $websitekey); $object->fetch(0, $websitekey);
$website = $object; $website = $object;
@ -1556,7 +1556,7 @@ if ($action == 'setashome') {
} }
// Update page properties (meta) // Update page properties (meta)
if ($action == 'updatemeta') { if ($action == 'updatemeta' && $usercanedit) {
$db->begin(); $db->begin();
$result = $object->fetch(0, $websitekey); $result = $object->fetch(0, $websitekey);
@ -1778,8 +1778,8 @@ if ($action == 'updatemeta') {
} }
// Update page // Update page
if (($action == 'updatesource' || $action == 'updatecontent' || $action == 'confirm_createfromclone' || $action == 'confirm_createpagefromclone') if ($usercanedit && (($action == 'updatesource' || $action == 'updatecontent' || $action == 'confirm_createfromclone' || $action == 'confirm_createpagefromclone')
|| ($action == 'preview' && (GETPOST('refreshsite') || GETPOST('refreshpage') || GETPOST('preview')))) { || ($action == 'preview' && (GETPOST('refreshsite') || GETPOST('refreshpage') || GETPOST('preview'))))) {
$object->fetch(0, $websitekey); $object->fetch(0, $websitekey);
$website = $object; $website = $object;
@ -2041,7 +2041,7 @@ if (($action == 'updatesource' || $action == 'updatecontent' || $action == 'conf
} }
// Export site // Export site
if ($action == 'exportsite') { if ($action == 'exportsite' && !empty($user->rights->website->export)) {
$fileofzip = $object->exportWebSite(); $fileofzip = $object->exportWebSite();
if ($fileofzip) { if ($fileofzip) {
@ -2060,7 +2060,7 @@ if ($action == 'exportsite') {
} }
// Regenerate site // Regenerate site
if ($action == 'regeneratesite') { if ($action == 'regeneratesite' && $usercanedit) {
// Check symlink to medias and restore it if ko. Recreate also dir of website if not found. // Check symlink to medias and restore it if ko. Recreate also dir of website if not found.
$pathtomedias = DOL_DATA_ROOT.'/medias'; $pathtomedias = DOL_DATA_ROOT.'/medias';
$pathtomediasinwebsite = $pathofwebsite.'/medias'; $pathtomediasinwebsite = $pathofwebsite.'/medias';
@ -2085,7 +2085,7 @@ if ($action == 'regeneratesite') {
} }
// Import site // Import site
if ($action == 'importsiteconfirm') { if ($action == 'importsiteconfirm' && $usercanedit) {
if (empty($_FILES) && !GETPOSTISSET('templateuserfile')) { if (empty($_FILES) && !GETPOSTISSET('templateuserfile')) {
setEventMessages($langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("File")), null, 'errors'); setEventMessages($langs->trans("ErrorFieldRequired", $langs->transnoentitiesnoconv("File")), null, 'errors');
$action = 'importsite'; $action = 'importsite';
@ -2162,7 +2162,7 @@ $domainname = '0.0.0.0:8080';
$tempdir = $conf->website->dir_output.'/'.$websitekey.'/'; $tempdir = $conf->website->dir_output.'/'.$websitekey.'/';
// Generate web site sitemaps // Generate web site sitemaps
if ($action == 'generatesitemaps') { if ($action == 'generatesitemaps' && $usercanedit) {
$domtree = new DOMDocument('1.0', 'UTF-8'); $domtree = new DOMDocument('1.0', 'UTF-8');
$root = $domtree->createElementNS('http://www.sitemaps.org/schemas/sitemap/0.9', 'urlset'); $root = $domtree->createElementNS('http://www.sitemaps.org/schemas/sitemap/0.9', 'urlset');
$domtree->formatOutput = true; $domtree->formatOutput = true;
@ -2331,6 +2331,10 @@ if (!GETPOST('hide_websitemenu')) {
if (empty($user->rights->website->write)) { if (empty($user->rights->website->write)) {
$disabled = ' disabled="disabled"'; $disabled = ' disabled="disabled"';
} }
$disabledexport = '';
if (empty($user->rights->website->export)) {
$disabledexport = ' disabled="disabled"';
}
if ($websitekey) { if ($websitekey) {
$virtualurl = ''; $virtualurl = '';
@ -2446,7 +2450,7 @@ if (!GETPOST('hide_websitemenu')) {
} }
//print '<input type="submit" class="button"'.$disabled.' value="'.dol_escape_htmltag($langs->trans("EditMenu")).'" name="editmenu">'; //print '<input type="submit" class="button"'.$disabled.' value="'.dol_escape_htmltag($langs->trans("EditMenu")).'" name="editmenu">';
print '<input type="submit" class="button bordertransp"'.$disabled.' value="'.dol_escape_htmltag($exportlabel).'" name="exportsite">'; print '<input type="submit" class="button bordertransp"'.$disabledexport.' value="'.dol_escape_htmltag($exportlabel).'" name="exportsite">';
print '<input type="submit" class="button bordertransp"'.$disabled.' value="'.dol_escape_htmltag($langs->trans("CloneSite")).'" name="createfromclone">'; print '<input type="submit" class="button bordertransp"'.$disabled.' value="'.dol_escape_htmltag($langs->trans("CloneSite")).'" name="createfromclone">';