Skip to content
Snippets Groups Projects
index.php 15 KiB
Newer Older
  • Learn to ignore specific revisions
  • 
    /**
    * Copyright Maarch since 2008 under licence GPLv3.
    * See LICENCE.txt file at the root folder for more details.
    * This file is part of Maarch software.
    *
    */
    
    * @brief Rest Routes File
    
    * @author dev@maarch.org
    */
    
    
    require '../vendor/autoload.php';
    
    header('Content-Type: text/html; charset=utf-8');
    
    //create session if NO SESSION
    if (empty($_SESSION['user'])) {
        require_once('../core/class/class_functions.php');
        include_once('../core/init.php');
        require_once('core/class/class_portal.php');
        require_once('core/class/class_db.php');
        require_once('core/class/class_request.php');
        require_once('core/class/class_core_tools.php');
        require_once('core/class/web_service/class_web_service.php');
        require_once('core/services/CoreConfig.php');
    
        //load Maarch session vars
        $portal = new portal();
        $portal->unset_session();
        $portal->build_config();
        $coreTools = new core_tools();
        $_SESSION['custom_override_id'] = $coreTools->get_custom_id();
        if (isset($_SESSION['custom_override_id'])
            && ! empty($_SESSION['custom_override_id'])
            && isset($_SESSION['config']['corepath'])
            && ! empty($_SESSION['config']['corepath'])
        ) {
            $path = $_SESSION['config']['corepath'] . 'custom' . DIRECTORY_SEPARATOR
                . $_SESSION['custom_override_id'] . DIRECTORY_SEPARATOR;
            set_include_path(
                $path . PATH_SEPARATOR . $_SESSION['config']['corepath']
                . PATH_SEPARATOR . get_include_path()
            );
    
        } elseif (isset($_SESSION['config']['corepath'])
    
            && ! empty($_SESSION['config']['corepath'])
        ) {
            set_include_path(
                $_SESSION['config']['corepath'] . PATH_SEPARATOR . get_include_path()
            );
        }
        // Load configuration from xml into session
        Core_CoreConfig_Service::buildCoreConfig('core' . DIRECTORY_SEPARATOR . 'xml' . DIRECTORY_SEPARATOR . 'config.xml');
        $_SESSION['config']['app_id'] = $_SESSION['businessapps'][0]['appid'];
        require_once 'apps/' .$_SESSION['businessapps'][0]['appid']. '/class/class_business_app_tools.php';
    
        Core_CoreConfig_Service::buildBusinessAppConfig();
    
        // Load Modules configuration from xml into session
        Core_CoreConfig_Service::loadModulesConfig($_SESSION['modules']);
        Core_CoreConfig_Service::loadAppServices();
        Core_CoreConfig_Service::loadModulesServices($_SESSION['modules']);
    }
    
    
    //login management
    
    Damien's avatar
    Damien committed
    if (empty($_SESSION['user'])) {
    
        if (!empty($_SERVER['PHP_AUTH_USER']) && !empty($_SERVER['PHP_AUTH_PW'])) { //TODO Gestion cookie basic
    
            $_SESSION['error'] = '';
            $security = new security();
            $pass = $security->getPasswordHash($_SERVER['PHP_AUTH_PW']);
            $res  = $security->login($_SERVER['PHP_AUTH_USER'], $pass);
    
            $_SESSION['user'] = $res['user'];
            if (!empty($res['error'])) {
                $_SESSION['error'] = $res['error'];
            }
        } else {
            require_once('apps/maarch_entreprise/class/class_login.php');
            $loginObj = new login();
            $loginMethods = $loginObj->build_login_method();
            require_once('core/services/Session.php');
            $oSessionService = new \Core_Session_Service();
    
            $loginObj->execute_login_script($loginMethods, true);
        }
    
    
    if ($_SESSION['error']) {
    
        echo $_SESSION['error'];
        exit();
    
    if (strpos(getcwd(), '/rest')) {
        chdir('..');
    
    Damien's avatar
    Damien committed
    }
    
    
    $cookie = \Core\Models\SecurityModel::getCookieAuth(); // New Authentication System
    if (!empty($cookie) &&\Core\Models\SecurityModel::cookieAuthentication($cookie)) {
        \Core\Models\SecurityModel::setCookieAuth(['userId' => $cookie['userId']]);
        $userId = $cookie['userId'];
    } else {
        echo 'Authentication Failed';
        exit();
    }
    
    Damien's avatar
    Damien committed
    
    
    $app = new \Slim\App([
        'settings' => [
            'displayErrorDetails' => true
        ]
    ]);
    
    
    Odran PHILIBERT's avatar
    Odran PHILIBERT committed
    //Initialize
    $app->post('/initialize', \Core\Controllers\CoreController::class . ':initialize');
    
    
    Damien's avatar
    Damien committed
    //Administration
    $app->get('/administration', \Core\Controllers\CoreController::class . ':getAdministration');
    
    $app->get('/administration/users', \Core\Controllers\UserController::class . ':getUsersForAdministration');
    
    $app->get('/administration/users/new', \Core\Controllers\UserController::class . ':getNewUserForAdministration');
    $app->get('/administration/users/{id}', \Core\Controllers\UserController::class . ':getUserForAdministration');
    
    $app->get('/administration/notifications/new', \Notifications\Controllers\NotificationController::class . ':getNewNotificationForAdministration');
    $app->get('/administration/notifications/{id}', \Notifications\Controllers\NotificationController::class . ':getNotificationForAdministration');
    
    //Baskets
    $app->get('/baskets', \Basket\controllers\BasketController::class . ':get');
    $app->get('/baskets/{id}', \Basket\controllers\BasketController::class . ':getById');
    $app->post('/baskets', \Basket\controllers\BasketController::class . ':create');
    $app->put('/baskets/{id}', \Basket\controllers\BasketController::class . ':update');
    $app->delete('/baskets/{id}', \Basket\controllers\BasketController::class . ':delete');
    $app->get('/baskets/{id}/groups', \Basket\controllers\BasketController::class . ':getGroups');
    $app->post('/baskets/{id}/groups', \Basket\controllers\BasketController::class . ':createGroup');
    $app->put('/baskets/{id}/groups/{groupId}', \Basket\controllers\BasketController::class . ':updateGroup');
    $app->delete('/baskets/{id}/groups/{groupId}', \Basket\controllers\BasketController::class . ':deleteGroup');
    $app->get('/baskets/{id}/groups/data', \Basket\controllers\BasketController::class . ':getDataForGroupById');
    
    
    $app->get('/administration/status', \Core\Controllers\StatusController::class . ':getList');
    
    $app->get('/administration/status/new', \Core\Controllers\StatusController::class . ':getNewInformations');
    $app->get('/administration/status/{identifier}', \Core\Controllers\StatusController::class . ':getByIdentifier');
    
    //groups
    $app->get('/groups', \Core\Controllers\GroupController::class . ':get');
    
    $app->post('/groups', \Core\Controllers\GroupController::class . ':create');
    $app->put('/groups/{id}', \Core\Controllers\GroupController::class . ':update');
    $app->delete('/groups/{id}', \Core\Controllers\GroupController::class . ':delete');
    $app->get('/groups/{id}/details', \Core\Controllers\GroupController::class . ':getDetailledById');
    $app->put('/groups/{id}/services/{serviceId}', \Core\Controllers\GroupController::class . ':updateService');
    $app->put('/groups/{id}/reassign/{newGroupId}', \Core\Controllers\GroupController::class . ':reassignUsers');
    
    //status
    
    $app->post('/status', \Core\Controllers\StatusController::class . ':create');
    
    $app->put('/status/{identifier}', \Core\Controllers\StatusController::class . ':update');
    $app->delete('/status/{identifier}', \Core\Controllers\StatusController::class . ':delete');
    
    //Docservers
    $app->get('/docservers', \Core\Controllers\DocserverController::class . ':get');
    $app->get('/docservers/{id}', \Core\Controllers\DocserverController::class . ':getById');
    
    //DocserverTypes
    $app->get('/docserverTypes', \core\Controllers\DocserverTypeController::class . ':get');
    $app->get('/docserverTypes/{id}', \core\Controllers\DocserverTypeController::class . ':getById');
    
    //ListModels
    $app->get('/listModels/itemId/{itemId}/itemMode/{itemMode}/objectType/{objectType}', \Entities\Controllers\ListModelsController::class . ':getListModelsDiffListDestByUserId');
    $app->put('/listModels/itemId/{itemId}/itemMode/{itemMode}/objectType/{objectType}', \Entities\Controllers\ListModelsController::class . ':updateListModelsDiffListDestByUserId');
    
    
    Damien's avatar
    Damien committed
    //Visa
    
    Odran PHILIBERT's avatar
    Odran PHILIBERT committed
    $app->get('/{basketId}/signatureBook/resList', \Visa\Controllers\VisaController::class . ':getResList');
    $app->get('/{basketId}/signatureBook/resList/details', \Visa\Controllers\VisaController::class . ':getDetailledResList');
    
    Damien's avatar
    Damien committed
    $app->get('/groups/{groupId}/baskets/{basketId}/signatureBook/{resId}', \Visa\Controllers\VisaController::class . ':getSignatureBook');
    
    $app->get('/signatureBook/{resId}/attachments', \Visa\Controllers\VisaController::class . ':getAttachmentsById');
    
    $app->get('/signatureBook/{resId}/incomingMailAttachments', \Visa\Controllers\VisaController::class . ':getIncomingMailAndAttachmentsById');
    
    $app->put('/{collId}/{resId}/unsign', \Visa\Controllers\VisaController::class . ':unsignFile');
    
    $app->put('/attachments/{id}/inSignatureBook', \Attachments\Controllers\AttachmentsController::class . ':setInSignatureBook');
    
    $app->post('/res', \Core\Controllers\ResController::class . ':create');
    
    Damien's avatar
    Damien committed
    $app->post('/resExt', \Core\Controllers\ResController::class . ':createExt');
    
    $app->put('/res', \Core\Controllers\ResController::class . ':update');
    
    Damien's avatar
    Damien committed
    $app->put('/res/{resId}/status', \Core\Controllers\ResController::class . ':updateStatus');
    
    $app->get('/res/{resId}/lock', \Core\Controllers\ResController::class . ':isLock');
    
    $app->get('/res/{resId}/notes/count', \Core\Controllers\ResController::class . ':getNotesCountForCurrentUserById');
    
    $app->get('/users/autocompleter', \Core\Controllers\UserController::class . ':getUsersForAutocompletion');
    
    $app->get('/users/profile', \Core\Controllers\UserController::class . ':getCurrentUserInfos');
    $app->put('/users/profile', \Core\Controllers\UserController::class . ':updateProfile');
    
    $app->post('/users', \Core\Controllers\UserController::class . ':create');
    
    $app->get('/users/{id}/details', \Core\Controllers\UserController::class . ':getDetailledById');
    
    Damien's avatar
    Damien committed
    $app->put('/users/{id}', \Core\Controllers\UserController::class . ':update');
    $app->delete('/users/{id}', \Core\Controllers\UserController::class . ':delete');
    $app->post('/users/{id}/groups', \Core\Controllers\UserController::class . ':addGroup');
    $app->put('/users/{id}/groups/{groupId}', \Core\Controllers\UserController::class . ':updateGroup');
    $app->delete('/users/{id}/groups/{groupId}', \Core\Controllers\UserController::class . ':deleteGroup');
    $app->post('/users/{id}/entities', \Core\Controllers\UserController::class . ':addEntity');
    $app->put('/users/{id}/entities/{entityId}', \Core\Controllers\UserController::class . ':updateEntity');
    $app->put('/users/{id}/entities/{entityId}/primaryEntity', \Core\Controllers\UserController::class . ':updatePrimaryEntity');
    $app->delete('/users/{id}/entities/{entityId}', \Core\Controllers\UserController::class . ':deleteEntity');
    $app->put('/users/{id}/password', \Core\Controllers\UserController::class . ':resetPassword');
    
    Damien's avatar
    Damien committed
    $app->put('/users/{id}/status', \Core\Controllers\UserController::class . ':updateStatus');
    
    $app->post('/users/{id}/signatures', \Core\Controllers\UserController::class . ':addSignature');
    $app->put('/users/{id}/signatures/{signatureId}', \Core\Controllers\UserController::class . ':updateSignature');
    $app->delete('/users/{id}/signatures/{signatureId}', \Core\Controllers\UserController::class . ':deleteSignature');
    
    $app->post('/users/{id}/baskets/absence', \Core\Controllers\UserController::class . ':setRedirectedBaskets'); //TODO penser à une meilleure route
    $app->delete('/users/{id}/baskets/{basketId}/absence', \Core\Controllers\UserController::class . ':deleteRedirectedBaskets'); //TODO penser à une meilleure route
    
    
    Odran PHILIBERT's avatar
    Odran PHILIBERT committed
    $app->put('/currentUser/password', \Core\Controllers\UserController::class . ':updateCurrentUserPassword');
    $app->post('/currentUser/emailSignature', \Core\Controllers\UserController::class . ':createCurrentUserEmailSignature');
    $app->put('/currentUser/emailSignature/{id}', \Core\Controllers\UserController::class . ':updateCurrentUserEmailSignature');
    $app->delete('/currentUser/emailSignature/{id}', \Core\Controllers\UserController::class . ':deleteCurrentUserEmailSignature');
    
    Damien's avatar
    Damien committed
    $app->put('/currentUser/groups/{groupId}/baskets/{basketId}', \Core\Controllers\UserController::class . ':updateBasketPreference');
    
    Odran PHILIBERT's avatar
    Odran PHILIBERT committed
    
    //parameters
    
    Alex ORLUC's avatar
    Alex ORLUC committed
    $app->get('/administration/parameters', \Core\Controllers\ParametersController::class . ':getParametersForAdministration');
    $app->get('/administration/parameters/new', \Core\Controllers\ParametersController::class . ':getNewParameterForAdministration');
    $app->get('/administration/parameters/{id}', \Core\Controllers\ParametersController::class . ':getParameterForAdministration');
    
    Odran PHILIBERT's avatar
    Odran PHILIBERT committed
    $app->post('/parameters', \Core\Controllers\ParametersController::class . ':create');
    $app->put('/parameters/{id}', \Core\Controllers\ParametersController::class . ':update');
    $app->delete('/parameters/{id}', \Core\Controllers\ParametersController::class . ':delete');
    
    
    //Priorities
    
    $app->get('/priorities', \Core\Controllers\PriorityController::class . ':get');
    
    $app->post('/priorities', \Core\Controllers\PriorityController::class . ':create');
    
    $app->get('/priorities/{id}', \Core\Controllers\PriorityController::class . ':getById');
    
    $app->put('/priorities/{id}', \Core\Controllers\PriorityController::class . ':update');
    $app->delete('/priorities/{id}', \Core\Controllers\PriorityController::class . ':delete');
    
    Odran PHILIBERT's avatar
    Odran PHILIBERT committed
    
    
    Alex ORLUC's avatar
    Alex ORLUC committed
    //History
    $app->get('/administration/history/eventDate/{date}', \Core\Controllers\HistoryController::class . ':getForAdministration');
    
    
    //HistoryBatch
    $app->get('/administration/historyBatch/eventDate/{date}', \Core\Controllers\HistoryController::class . ':getBatchForAdministration');
    
    
    Odran PHILIBERT's avatar
    Odran PHILIBERT committed
    //actions
    
    Damien's avatar
    Damien committed
    $app->get('/administration/actions', \Core\Controllers\ActionController::class . ':getForAdministration');
    $app->get('/initAction', \Core\Controllers\ActionController::class . ':initAction');
    $app->get('/administration/actions/{id}', \Core\Controllers\ActionController::class . ':getByIdForAdministration');
    $app->post('/actions', \Core\Controllers\ActionController::class . ':create');
    $app->put('/actions/{id}', \Core\Controllers\ActionController::class . ':update');
    $app->delete('/actions/{id}', \Core\Controllers\ActionController::class . ':delete');
    
    //Notifications
    $app->get('/notifications', \Notifications\Controllers\NotificationController::class . ':get');
    $app->post('/notifications', \Notifications\Controllers\NotificationController::class . ':create');
    $app->get('/notifications/{id}', \Notifications\Controllers\NotificationController::class . ':getById');
    $app->put('/notifications/{id}', \Notifications\Controllers\NotificationController::class . ':update');
    $app->delete('/notifications/{id}', \Notifications\Controllers\NotificationController::class . ':delete');
    
    
    //Reports
    $app->get('/reports/groups/{groupId}', \Core\Controllers\ReportController::class . ':getByGroupId');
    $app->put('/reports/groups/{groupId}', \Core\Controllers\ReportController::class . ':updateForGroupId');
    
    
    //Listinstance
    $app->get('/listinstance/{id}', \Core\Controllers\ListinstanceController::class . ':getById');
    
    
    //Contacts
    $app->post('/contacts', \Core\Controllers\ContactController::class . ':create');
    
    
    //Templates
    $app->post('/templates/{id}/duplicate', \Templates\Controllers\TemplateController::class . ':duplicate');
    
    
    Damien's avatar
    Damien committed
    //Links
    $app->get('/links/resId/{resId}', \Core\Controllers\LinkController::class . ':getByResId');
    
    
    //liste documents
    $app->get('/res/listDocs/{clause}/{select}', \Core\Controllers\ResController::class . ':getListDocs');
    
    
    $app->run();
    
    
    if ($_SESSION['user']['UserId'] == 'restUser') {
        $name = $_SESSION['sessionName'];
    
        setcookie ($name, "", 1);
        setcookie ($name, false);
        unset($_COOKIE[$name]);
    
        session_unset();
        session_destroy();
        unset($_SESSION['sessionName']);
    }