golden hour
/home/doctorbruno/public_html/doctorbruno.info/taeionline/support/include
⬆️ Go Up
Upload
File/Folder
Size
Actions
.MANIFEST
194.97 KB
Del
OK
.htaccess
14 B
Del
OK
JSON.php
33.13 KB
Del
OK
PasswordHash.php
6.92 KB
Del
OK
Spyc.php
31.74 KB
Del
OK
UniversalClassLoader.php
8.61 KB
Del
OK
ajax.admin.php
7.29 KB
Del
OK
ajax.config.php
4.61 KB
Del
OK
ajax.content.php
9.76 KB
Del
OK
ajax.draft.php
13.03 KB
Del
OK
ajax.email.php
2.33 KB
Del
OK
ajax.export.php
1006 B
Del
OK
ajax.filter.php
874 B
Del
OK
ajax.forms.php
13.84 KB
Del
OK
ajax.i18n.php
5.1 KB
Del
OK
ajax.kbase.php
2.93 KB
Del
OK
ajax.note.php
2.05 KB
Del
OK
ajax.orgs.php
11.73 KB
Del
OK
ajax.plugins.php
2.15 KB
Del
OK
ajax.schedule.php
4.29 KB
Del
OK
ajax.search.php
12.72 KB
Del
OK
ajax.sequence.php
3.2 KB
Del
OK
ajax.staff.php
11.62 KB
Del
OK
ajax.tasks.php
33.87 KB
Del
OK
ajax.thread.php
8.81 KB
Del
OK
ajax.tickets.php
79.7 KB
Del
OK
ajax.tips.php
1.66 KB
Del
OK
ajax.upgrader.php
2.24 KB
Del
OK
ajax.users.php
18.33 KB
Del
OK
api.cron.php
1.06 KB
Del
OK
api.tickets.php
10.36 KB
Del
OK
class.2fa.php
7.76 KB
Del
OK
class.ajax.php
1.45 KB
Del
OK
class.api.php
15.31 KB
Del
OK
class.app.php
1.49 KB
Del
OK
class.attachment.php
6.95 KB
Del
OK
class.auth.php
50.73 KB
Del
OK
class.avatar.php
6.44 KB
Del
OK
class.banlist.php
2.58 KB
Del
OK
class.base32.php
4.07 KB
Del
OK
class.businesshours.php
7.08 KB
Del
OK
class.canned.php
9.05 KB
Del
OK
class.captcha.php
1.73 KB
Del
OK
class.category.php
11.14 KB
Del
OK
class.charset.php
3.41 KB
Del
OK
class.cli.php
9.48 KB
Del
OK
class.client.php
15.39 KB
Del
OK
class.collaborator.php
5.65 KB
Del
OK
class.company.php
2.65 KB
Del
OK
class.config.php
60.36 KB
Del
OK
class.controller.php
1.15 KB
Del
OK
class.cron.php
3.6 KB
Del
OK
class.crypto.php
18.92 KB
Del
OK
class.csrf.php
2.38 KB
Del
OK
class.dept.php
33.21 KB
Del
OK
class.dispatcher.php
7.12 KB
Del
OK
class.draft.php
6.23 KB
Del
OK
class.dynamic_forms.php
64.98 KB
Del
OK
class.email.php
49 KB
Del
OK
class.error.php
1.69 KB
Del
OK
class.export.php
32.92 KB
Del
OK
class.faq.php
15.05 KB
Del
OK
class.file.php
34.59 KB
Del
OK
class.filter.php
31.9 KB
Del
OK
class.filter_action.php
23.67 KB
Del
OK
class.format.php
44.3 KB
Del
OK
class.forms.php
195.58 KB
Del
OK
class.http.php
7.16 KB
Del
OK
class.i18n.php
24.28 KB
Del
OK
class.import.php
6.9 KB
Del
OK
class.json.php
2.71 KB
Del
OK
class.knowledgebase.php
5.8 KB
Del
OK
class.list.php
42 KB
Del
OK
class.lock.php
4.05 KB
Del
OK
class.log.php
1.55 KB
Del
OK
class.mail.php
35.76 KB
Del
OK
class.mailer.php
25.75 KB
Del
OK
class.mailfetch.php
9.72 KB
Del
OK
class.mailparse.php
30.99 KB
Del
OK
class.message.php
6.42 KB
Del
OK
class.migrater.php
5.2 KB
Del
OK
class.misc.php
7.5 KB
Del
OK
class.model.php
2.3 KB
Del
OK
class.nav.php
14.15 KB
Del
OK
class.note.php
2.39 KB
Del
OK
class.oauth2.php
4.04 KB
Del
OK
class.organization.php
22.45 KB
Del
OK
class.orm.php
120.9 KB
Del
OK
class.osticket.php
20.64 KB
Del
OK
class.ostsession.php
21.86 KB
Del
OK
class.page.php
10.59 KB
Del
OK
class.pagenate.php
5.53 KB
Del
OK
class.passwd.php
1.21 KB
Del
OK
class.pdf.php
3.83 KB
Del
OK
class.plugin.php
36.13 KB
Del
OK
class.priority.php
1.81 KB
Del
OK
class.queue.php
103.51 KB
Del
OK
class.report.php
11.76 KB
Del
OK
class.role.php
11.27 KB
Del
OK
class.schedule.php
46.28 KB
Del
OK
class.search.php
61.66 KB
Del
OK
class.sequence.php
7.27 KB
Del
OK
class.session.php
19.25 KB
Del
OK
class.setup.php
3.55 KB
Del
OK
class.signal.php
4.16 KB
Del
OK
class.sla.php
9.11 KB
Del
OK
class.staff.php
60.21 KB
Del
OK
class.task.php
56.21 KB
Del
OK
class.team.php
12.31 KB
Del
OK
class.template.php
23.45 KB
Del
OK
class.thread.php
108.96 KB
Del
OK
class.thread_actions.php
17.08 KB
Del
OK
class.ticket.php
167.39 KB
Del
OK
class.timezone.php
21.94 KB
Del
OK
class.topic.php
20.06 KB
Del
OK
class.translation.php
34.79 KB
Del
OK
class.upgrader.php
13.76 KB
Del
OK
class.user.php
43.4 KB
Del
OK
class.usersession.php
7.55 KB
Del
OK
class.util.php
10.07 KB
Del
OK
class.validator.php
12.94 KB
Del
OK
class.variable.php
11.93 KB
Del
OK
class.xml.php
3.23 KB
Del
OK
class.yaml.php
1.15 KB
Del
OK
cli
-
Del
OK
client
-
Del
OK
config
-
Del
OK
fpdf
-
Del
OK
htmLawed.php
53.53 KB
Del
OK
html2text.php
33.71 KB
Del
OK
i18n
-
Del
OK
index.php
37 B
Del
OK
laminas-mail
-
Del
OK
mpdf
-
Del
OK
mysqli.php
9.55 KB
Del
OK
ost-config.php
5.63 KB
Del
OK
ost-sampleconfig.php
6.24 KB
Del
OK
pear
-
Del
OK
plugins
-
Del
OK
staff
-
Del
OK
tnef_decoder.php
19.82 KB
Del
OK
upgrader
-
Del
OK
Edit: ajax.staff.php
<?php require_once(INCLUDE_DIR . 'class.staff.php'); class StaffAjaxAPI extends AjaxController { /** * Ajax: GET /staff/<id>/set-password * * Uses a dialog to add a new department * * Returns: * 200 - HTML form for addition * 201 - {id: <id>, name: <name>} * * Throws: * 403 - Not logged in * 403 - Not an administrator * 404 - No such agent exists */ function setPassword($id) { global $ost, $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if (!$thisstaff->isAdmin()) Http::response(403, 'Access denied'); if ($id && !($staff = Staff::lookup($id))) Http::response(404, 'No such agent'); $form = new PasswordResetForm($_POST); $errors = array(); if (!$_POST && isset($_SESSION['new-agent-passwd'])) $form->data($_SESSION['new-agent-passwd']); if ($_POST && $form->isValid()) { $clean = $form->getClean(); try { // Validate password if (!$clean['welcome_email']) Staff::checkPassword($clean['passwd1'], null); if ($id == 0) { // Stash in the session later when creating the user $_SESSION['new-agent-passwd'] = $clean; Http::response(201, 'Carry on'); } if ($clean['welcome_email']) { $staff->sendResetEmail(); } else { $staff->setPassword($clean['passwd1'], null); if ($clean['change_passwd']) $staff->change_passwd = 1; } if ($staff->save()) Http::response(201, 'Successfully updated'); } catch (BadPassword $ex) { if ($passwd1 = $form->getField('passwd1')) $passwd1->addError($ex->getMessage()); } catch (PasswordUpdateFailed $ex) { $errors['err'] = __('Password update failed:').' '.$ex->getMessage(); } } $title = __("Set Agent Password"); $verb = $id == 0 ? __('Set') : __('Update'); $path = ltrim(Osticket::get_path_info(), '/'); include STAFFINC_DIR . 'templates/quick-add.tmpl.php'; } function changePassword($id) { global $cfg, $ost, $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if (!$id || $thisstaff->getId() != $id) Http::response(404, 'No such agent'); $form = new PasswordChangeForm($_POST); $errors = array(); if ($_POST && $form->isValid()) { $clean = $form->getClean(); if (($rtoken = $_SESSION['_staff']['reset-token'])) { $_config = new Config('pwreset'); if ($_config->get($rtoken) != $thisstaff->getId()) $errors['err'] = __('Invalid reset token. Logout and try again'); elseif (!($ts = $_config->lastModified($rtoken)) && ($cfg->getPwResetWindow() < (time() - strtotime($ts)))) $errors['err'] = __('Invalid reset token. Logout and try again'); } if (!$errors) { try { $thisstaff->setPassword($clean['passwd1'], @$clean['current']); if ($thisstaff->save()) { if ($rtoken) { $thisstaff->cancelResetTokens(); Http::response(200, $this->encode(array( 'redirect' => 'index.php' ))); } Http::response(201, 'Successfully updated'); } } catch (BadPassword $ex) { if ($passwd1 = $form->getField('passwd1')) $passwd1->addError($ex->getMessage()); } catch (PasswordUpdateFailed $ex) { $errors['err'] = __('Password update failed:').' '.$ex->getMessage(); } } } $title = __("Change Password"); $verb = __('Update'); $path = ltrim(Osticket::get_path_info(), '/'); include STAFFINC_DIR . 'templates/quick-add.tmpl.php'; } function getAgentPerms($id) { global $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if (!$thisstaff->isAdmin()) Http::response(403, 'Access denied'); if (!($staff = Staff::lookup($id))) Http::response(404, 'No such agent'); return $this->encode($staff->getPermissionInfo()); } function resetPermissions() { global $ost, $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if (!$thisstaff->isAdmin()) Http::response(403, 'Access denied'); $form = new ResetAgentPermissionsForm($_POST); if (@is_array($_GET['ids'])) { $perms = new RolePermission(null); $selected = Staff::objects()->filter(array('staff_id__in' => $_GET['ids'])); foreach ($selected as $staff) // XXX: This maybe should be intersection rather than union $perms->merge($staff->getPermission()); $form->getField('perms')->setValue($perms->getInfo()); } if ($_POST && $form->isValid()) { $clean = $form->getClean(); Http::response(201, $this->encode(array('perms' => $clean['perms']))); } $title = __("Reset Agent Permissions"); $verb = __("Continue"); $path = ltrim(Osticket::get_path_info(), '/'); include STAFFINC_DIR . 'templates/reset-agent-permissions.tmpl.php'; } function changeDepartment() { global $ost, $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if (!$thisstaff->isAdmin()) Http::response(403, 'Access denied'); $form = new ChangeDepartmentForm($_POST); // Preselect reasonable dept and role based on the current settings // of the received staff ids if (@is_array($_GET['ids'])) { $dept_id = null; $role_id = null; $selected = Staff::objects()->filter(array('staff_id__in' => $_GET['ids'])); foreach ($selected as $staff) { if (!isset($dept_id)) { $dept_id = $staff->dept_id; $role_id = $staff->role_id; } elseif ($dept_id != $staff->dept_id) $dept_id = 0; elseif ($role_id != $staff->role_id) $role_id = 0; } $form->getField('dept_id')->setValue($dept_id); $form->getField('role_id')->setValue($role_id); } if ($_POST && $form->isValid()) { $clean = $form->getClean(); Http::response(201, $this->encode($clean)); } $title = __("Change Primary Department"); $verb = __("Continue"); $path = ltrim(Osticket::get_path_info(), '/'); include STAFFINC_DIR . 'templates/quick-add.tmpl.php'; } function setAvatar($id) { global $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if ($id != $thisstaff->getId() && !$thisstaff->isAdmin()) Http::response(403, 'Access denied'); if ($id == $thisstaff->getId()) $staff = $thisstaff; else $staff = Staff::lookup((int) $id); if (!($avatar = $staff->getAvatar())) Http::response(404, 'User does not have an avatar'); if ($code = $avatar->toggle()) return $this->encode(array( 'img' => (string) $avatar, // XXX: This is very inflexible 'code' => $code, )); } function configure2FA($staffId, $id=0) { global $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if ($staffId != $thisstaff->getId()) Http::response(403, 'Access denied'); if ($id && !($auth= Staff2FABackend::lookup($id))) Http::response(404, 'Unknown 2FA'); $staff = $thisstaff; $info = array(); if ($auth) { // Simple state machine to manage settings and verification $state = @$_POST['state'] ?: 'validate'; switch ($state) { case 'verify': try { $form = $auth->getInputForm($_POST); if ($_POST && $form && $form->isValid() && $auth->validate($form, $staff)) { // Mark the settings as verified if (($config = $staff->get2FAConfig($auth->getId()))) { $config['verified'] = time(); $staff->updateConfig(array( $auth->getId() => JsonDataEncoder::encode($config))); } // We're done here $auth = null; $info['notice'] = __('Setup completed successfully'); } else { $info['error'] = __('Unable to verify the token - try again!'); } } catch (ExpiredOTP $ex) { // giving up cleanly $info['error'] = $ex->getMessage(); $auth = null; } break; case 'validate': default: $config = $staff->get2FAConfig($auth->getId()); $vars = $_POST ?: $config['config'] ?: array('email' => $staff->getEmail()); $form = $auth->getSetupForm($vars); if ($_POST && $form && $form->isValid()) { if ($config['config'] && $config['config']['external2fa']) $external2fa = true; // Save the setting based on setup form $clean = $form->getClean(); if (!$external2fa) { $config = ['config' => $clean, 'verified' => 0]; $staff->updateConfig(array( $auth->getId() => JsonDataEncoder::encode($config))); } // Send verification token to the user if ($token=$auth->send($staff)) { // Transition to verify state $form = $auth->getInputForm($vars); $state = 'verify'; $info['notice'] = __('Token sent to you!'); } else { // Generic error TODO: better wording $info['error'] = __('Error sending Token - double check entry'); } } } } include STAFFINC_DIR . 'templates/2fas.tmpl.php'; } function reset2fA($staffId) { global $thisstaff; if (!$thisstaff) Http::response(403, 'Agent login required'); if (!$thisstaff->isAdmin()) Http::response(403, 'Access denied'); $default_2fa = ConfigItem::getConfigsByNamespace('staff.'.$staffId, 'default_2fa'); if ($default_2fa) $default_2fa->delete(); } }
Save