diff --git a/core/user_settings/user_settings.php b/core/user_settings/user_settings.php index e72f08b58e..7f9e2a6870 100644 --- a/core/user_settings/user_settings.php +++ b/core/user_settings/user_settings.php @@ -43,13 +43,13 @@ } //get the http post data - if ($_POST['action'] != '') { - $action = $_POST['action']; - $user_uuid = $_POST['user_uuid']; - $user_settings = $_POST['user_settings']; + if (!empty($_POST['action'])) { + $action = $_POST['action'] ?? ''; + $user_uuid = $_POST['user_uuid'] ?? ''; + $user_settings = $_POST['user_settings'] ?? ''; //process the http post data by action - if (is_array($user_settings) && @sizeof($user_settings) != 0) { + if (!empty($user_settings)) { switch ($action) { case 'toggle': if (permission_exists('user_setting_edit')) { @@ -78,7 +78,7 @@ if ( is_uuid($_REQUEST["user_id"]) && is_array($_REQUEST["id"]) && - sizeof($_REQUEST["id"]) == 1 && + !empty($_REQUEST["id"]) && ($_REQUEST['enabled'] === 'true' || $_REQUEST['enabled'] === 'false') ) { @@ -103,27 +103,37 @@ */ //get the variables - $order_by = $_GET["order_by"]; - $order = $_GET["order"]; + $order_by = $_GET["order_by"] ?? ''; + $order = $_GET["order"] ?? ''; -//common sql where - $sql_where = "where user_uuid = :user_uuid "; - $sql_where .= "and not ( "; - $sql_where .= "(user_setting_category = 'domain' and user_setting_subcategory = 'language') "; - $sql_where .= "or (user_setting_category = 'domain' and user_setting_subcategory = 'time_zone') "; - $sql_where .= ") "; - $parameters['user_uuid'] = $user_uuid; +//set from session variables + $list_row_edit_button = !empty($_SESSION['theme']['list_row_edit_button']['boolean']) ? $_SESSION['theme']['list_row_edit_button']['boolean'] : 'false'; + $button_icon_back = !empty($_SESSION['theme']['button_icon_back']) ? $_SESSION['theme']['button_icon_back'] : ''; + $button_icon_add = !empty($_SESSION['theme']['button_icon_add']) ? $_SESSION['theme']['button_icon_add'] : ''; + $button_icon_copy = !empty($_SESSION['theme']['button_icon_copy']) ? $_SESSION['theme']['button_icon_copy'] : ''; + $button_icon_toggle = !empty($_SESSION['theme']['button_icon_toggle']) ? $_SESSION['theme']['button_icon_toggle'] : ''; + $button_icon_all = !empty($_SESSION['theme']['button_icon_all']) ? $_SESSION['theme']['button_icon_all'] : ''; + $button_icon_delete = !empty($_SESSION['theme']['button_icon_delete']) ? $_SESSION['theme']['button_icon_delete'] : ''; + $button_icon_search = !empty($_SESSION['theme']['button_icon_search']) ? $_SESSION['theme']['button_icon_search'] : ''; + $button_icon_edit = !empty($_SESSION['theme']['button_icon_edit']) ? $_SESSION['theme']['button_icon_edit'] : ''; + $button_icon_reset = !empty($_SESSION['theme']['button_icon_reset']) ? $_SESSION['theme']['button_icon_reset'] : ''; //prepare to page the results $sql = "select count(*) from v_user_settings "; - $sql .= $sql_where; + $sql .= "where user_uuid = :user_uuid "; + $sql .= "and not ( "; + $sql .= "(user_setting_category = 'domain' and user_setting_subcategory = 'language') "; + $sql .= "or (user_setting_category = 'domain' and user_setting_subcategory = 'time_zone') "; + $sql .= ") "; + $parameters['user_uuid'] = $user_uuid; $database = new database; $num_rows = $database->select($sql, $parameters, 'column'); unset($sql); //prepare to page the results - $rows_per_page = ($_SESSION['domain']['paging']['numeric'] != '') ? $_SESSION['domain']['paging']['numeric'] : 100; - $param = ""; + $rows_per_page = (!empty($_SESSION['domain']['paging']['numeric'])) ? $_SESSION['domain']['paging']['numeric'] : 100; + $param = ''; + $paging_controls = ''; if (isset($_GET['page'])) { $page = $_GET['page']; if (empty($page)) { $page = 0; $_GET['page'] = 0; } @@ -137,14 +147,19 @@ //get the list $sql = "select user_setting_uuid, user_uuid, user_setting_category, user_setting_subcategory, user_setting_name, user_setting_value, cast(user_setting_enabled as text), user_setting_description "; $sql .= "from v_user_settings "; - $sql .= $sql_where; - if ($order_by == '') { + $sql .= "where user_uuid = :user_uuid "; + $sql .= "and not ( "; + $sql .= "(user_setting_category = 'domain' and user_setting_subcategory = 'language') "; + $sql .= "or (user_setting_category = 'domain' and user_setting_subcategory = 'time_zone') "; + $sql .= ") "; + if (!empty($order_by)) { $sql .= "order by user_setting_category, user_setting_subcategory, user_setting_order asc "; } else { $sql .= order_by($order_by, $order); } $sql .= limit_offset($rows_per_page, $offset); + $parameters['user_uuid'] = $user_uuid; $database = new database; $user_settings = $database->select($sql, $parameters, 'all'); unset($sql, $sql_where, $parameters); @@ -157,15 +172,15 @@ echo "