File size: 3,878 Bytes
07c3cdd
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
<?php
/**

 * authentication.php

 *

 * ProcessMaker Open Source Edition

 * Copyright (C) 2004 - 2008 Colosa Inc.23

 *

 * This program is free software: you can redistribute it and/or modify

 * it under the terms of the GNU Affero General Public License as

 * published by the Free Software Foundation, either version 3 of the

 * License, or (at your option) any later version.

 *

 * This program is distributed in the hope that it will be useful,

 * but WITHOUT ANY WARRANTY; without even the implied warranty of

 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the

 * GNU Affero General Public License for more details.

 *

 * You should have received a copy of the GNU Affero General Public License

 * along with this program. If not, see <http://www.gnu.org/licenses/>.

 *

 * For more information, contact Colosa Inc, 2566 Le Jeune Rd.,

 * Coral Gables, FL, 33134, USA, or email info@colosa.com.

 */
/*

   * Authentication for Case Tracker

   *

   * @author Everth S. Berrios Morales <everth@colosa.com>

   *

   */

if (! isset( $_POST['form'] )) {
    G::SendTemporalMessage( 'ID_USER_HAVENT_RIGHTS_SYSTEM', "error" );
    G::header( "location: login.php" );
    die();
}

try {
    $frm = $_POST['form'];
    $case = '';
    $pin = '';

    if (isset( $frm['CASE'] )) {
        $case = strtolower( trim( $frm['CASE'] ) );
        $pin = trim( $frm['PIN'] );
    }

    $cases = new Cases();

    $uid = $cases->verifyCaseTracker( $case, $pin );
    switch ($uid) {
        //The case doesn't exist
        case - 1:
            G::SendTemporalMessage( 'ID_CASE_NOT_EXISTS', "error" );
            break;
        //The pin is invalid
        case - 2:
            G::SendTemporalMessage( 'ID_PIN_INVALID', "error" );
            break;
    }

    if ($uid < 0) {
        G::header( "location: login.php" );
        die();
    }

    if (is_array( $uid )) {
        require_once ("classes/model/CaseTracker.php");
        require_once ("classes/model/CaseTrackerObject.php");
        $_SESSION['CASE'] = $case;
        $_SESSION['PIN'] = $pin;
        $_SESSION['PROCESS'] = $uid['PRO_UID'];
        $_SESSION['APPLICATION'] = $uid['APP_UID'];
        $_SESSION['TASK'] = - 1;
        $_SESSION['INDEX'] = - 1;

        $criteria = new Criteria();
        $criteria->add( CaseTrackerPeer::PRO_UID, $_SESSION['PROCESS'] );
        $caseTracker = new CaseTracker();
        if (CaseTrackerPeer::doCount( $criteria ) === 0) {
            $permissionsCaseTracker = array ('PRO_UID' => $_SESSION['PROCESS'],'CT_MAP_TYPE' => 'PROCESSMAP','CT_DERIVATION_HISTORY' => 1,'CT_MESSAGE_HISTORY' => 1
            );
            $caseTracker->create( $permissionsCaseTracker );
        }
        $caseTracker = $cases->caseTrackerPermissions( $_SESSION['PROCESS'] );

        if ($caseTracker['CT_MAP_TYPE']) {
            G::header( 'location: tracker_ViewMap' );
        } else {
            if ($caseTracker['DYNADOC']) {
                G::header( "location: tracker_DynaDocs" );
            } else {
                if ($caseTracker['CT_DERIVATION_HISTORY']) {
                    G::header( "location: tracker_History" );
                } else {
                    if ($caseTracker['CT_MESSAGE_HISTORY']) {
                        G::header( "location: tracker_No" );
                    } else {
                        G::header( "location: login.php" );
                        G::SendTemporalMessage( 'ID_ACCOUNT_DISABLED_CONTACT_ADMIN', "error" );
                    }
                }
            }
        }
    }
} catch (Exception $e) {
    $aMessage['MESSAGE'] = $e->getMessage();
    $G_PUBLISH = new Publisher();
    $G_PUBLISH->AddContent( 'xmlform', 'xmlform', 'login/showMessage', '', $aMessage );
    G::RenderPage( 'publish' );
    die();
}