Compare commits
24
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1600412a6d | ||
|
|
803c65616b | ||
|
|
0e163f6607 | ||
|
|
e1448d8ea2 | ||
|
|
b6c17096b5 | ||
|
|
6bd1bb082a | ||
|
|
a4828c1b7b | ||
|
|
86ef91abcb | ||
|
|
6d68af40e7 | ||
|
|
aa8173941a | ||
|
|
1b1801696f | ||
|
|
09cea2b388 | ||
|
|
9702aafacd | ||
|
|
66bf82bf46 | ||
|
|
fca0b42726 | ||
|
|
ae12fcd6fd | ||
|
|
5b96e75ff6 | ||
|
|
3db3749c46 | ||
|
|
9e83f8903a | ||
|
|
cabdae35cc | ||
|
|
3266373cdf | ||
|
|
f342e446d3 | ||
|
|
18c213ebd7 | ||
|
|
6adbb29964 |
@@ -84,3 +84,9 @@ LDAP_BASE_DN="dc=example,dc=com"
|
|||||||
LDAP_USER_BASE="ou=people,dc=example,dc=com"
|
LDAP_USER_BASE="ou=people,dc=example,dc=com"
|
||||||
; How long to cache avatar images locally (seconds, default 3600)
|
; How long to cache avatar images locally (seconds, default 3600)
|
||||||
AVATAR_CACHE_TTL=3600
|
AVATAR_CACHE_TTL=3600
|
||||||
|
|
||||||
|
; Session-based rate limits (requests per 60s window). These govern
|
||||||
|
; browser/session traffic on general and API endpoints respectively;
|
||||||
|
; Bearer-key API traffic is rate-limited separately, per API key.
|
||||||
|
RATE_LIMIT_DEFAULT=100
|
||||||
|
RATE_LIMIT_API=60
|
||||||
|
|||||||
+1
-1
@@ -20,6 +20,6 @@
|
|||||||
"no-useless-escape": "warn",
|
"no-useless-escape": "warn",
|
||||||
"no-regex-spaces": "warn",
|
"no-regex-spaces": "warn",
|
||||||
"semi": ["error", "always"],
|
"semi": ["error", "always"],
|
||||||
"eqeqeq": "warn"
|
"eqeqeq": ["warn", "smart"]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -255,6 +255,7 @@ Content-Type: application/json
|
|||||||
|
|
||||||
- `migrations/000_baseline.sql` is the full schema baseline for the whole database. It is written to be safe to re-run (idempotent) and is the source of truth for a fresh install.
|
- `migrations/000_baseline.sql` is the full schema baseline for the whole database. It is written to be safe to re-run (idempotent) and is the source of truth for a fresh install.
|
||||||
- `php migrations/migrate.php` applies any pending migration files in `migrations/` in order, tracking applied files in the `migrations` table. Use `--status` to list state and `--dry-run` to preview without executing.
|
- `php migrations/migrate.php` applies any pending migration files in `migrations/` in order, tracking applied files in the `migrations` table. Use `--status` to list state and `--dry-run` to preview without executing.
|
||||||
|
- Numbered migrations on top of the baseline (all idempotent, safe to re-run): `001_widen_bulk_operations_status.sql`, `002_fix_collation_consistency.sql`, `003_fk_on_delete_set_null.sql`, `004_fix_ticket_watchers_type.sql`. A fresh install via `000_baseline.sql` already includes all of these; they only matter for upgrading an existing database.
|
||||||
|
|
||||||
### API Endpoints
|
### API Endpoints
|
||||||
|
|
||||||
@@ -348,7 +349,9 @@ tinker_tickets/
|
|||||||
│ └── images/
|
│ └── images/
|
||||||
│ └── favicon.png
|
│ └── favicon.png
|
||||||
├── config/
|
├── config/
|
||||||
│ └── config.php # Config + .env loading
|
│ ├── config.php # Config + .env loading
|
||||||
|
│ └── requirements.php # PHP version/extension requirements (single source of
|
||||||
|
│ # truth for scripts/check_requirements.php + api/health.php)
|
||||||
├── controllers/
|
├── controllers/
|
||||||
│ ├── CommentController.php # Comment create/edit/delete + notifications
|
│ ├── CommentController.php # Comment create/edit/delete + notifications
|
||||||
│ ├── DashboardController.php # Dashboard with stats + filters
|
│ ├── DashboardController.php # Dashboard with stats + filters
|
||||||
@@ -389,6 +392,10 @@ tinker_tickets/
|
|||||||
│ └── WorkflowModel.php # Status transition workflows
|
│ └── WorkflowModel.php # Status transition workflows
|
||||||
├── migrations/
|
├── migrations/
|
||||||
│ ├── 000_baseline.sql # Full schema baseline (safe to re-run)
|
│ ├── 000_baseline.sql # Full schema baseline (safe to re-run)
|
||||||
|
│ ├── 001_widen_bulk_operations_status.sql # Upgrade-only (already in baseline for fresh installs)
|
||||||
|
│ ├── 002_fix_collation_consistency.sql # Upgrade-only (already in baseline for fresh installs)
|
||||||
|
│ ├── 003_fk_on_delete_set_null.sql # Upgrade-only (already in baseline for fresh installs)
|
||||||
|
│ ├── 004_fix_ticket_watchers_type.sql # Upgrade-only (already in baseline for fresh installs)
|
||||||
│ └── migrate.php # CLI migration runner (tracks applied migrations)
|
│ └── migrate.php # CLI migration runner (tracks applied migrations)
|
||||||
├── scripts/
|
├── scripts/
|
||||||
│ ├── check_requirements.php # Verify PHP extensions/config prerequisites
|
│ ├── check_requirements.php # Verify PHP extensions/config prerequisites
|
||||||
@@ -406,6 +413,9 @@ tinker_tickets/
|
|||||||
│ │ └── WorkflowDesignerView.php # Workflow transition designer
|
│ │ └── WorkflowDesignerView.php # Workflow transition designer
|
||||||
│ ├── CreateTicketView.php # Ticket creation with visibility
|
│ ├── CreateTicketView.php # Ticket creation with visibility
|
||||||
│ ├── DashboardView.php # Dashboard with kanban + sidebar + charts
|
│ ├── DashboardView.php # Dashboard with kanban + sidebar + charts
|
||||||
|
│ ├── error_403.php # Access-denied error page
|
||||||
|
│ ├── error_404.php # Not-found error page
|
||||||
|
│ ├── error_500.php # Fatal-error page (self-contained, no app-state deps)
|
||||||
│ ├── layout_footer.php # Shared footer (notification polling, boot sequence)
|
│ ├── layout_footer.php # Shared footer (notification polling, boot sequence)
|
||||||
│ ├── layout_header.php # Shared header (nav, command palette, theme toggle)
|
│ ├── layout_header.php # Shared header (nav, command palette, theme toggle)
|
||||||
│ └── TicketView.php # Ticket view with timeline, SLA, watcher avatars
|
│ └── TicketView.php # Ticket view with timeline, SLA, watcher avatars
|
||||||
|
|||||||
@@ -97,13 +97,39 @@ try {
|
|||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
$wf_active = (int)($data['is_active'] ?? 1);
|
||||||
|
|
||||||
|
// status_transitions already has a DB-level UNIQUE KEY on
|
||||||
|
// (from_status, to_status) (regardless of is_active), so a
|
||||||
|
// duplicate pair can't actually be inserted — but hitting that
|
||||||
|
// constraint raw surfaces as an opaque "internal error occurred"
|
||||||
|
// to the admin instead of a clear message. Check first so the
|
||||||
|
// common case (an admin re-adding a pair that already exists)
|
||||||
|
// gets a friendly, specific error.
|
||||||
|
$dupCheck = $conn->prepare(
|
||||||
|
"SELECT transition_id FROM status_transitions WHERE from_status = ? AND to_status = ?"
|
||||||
|
);
|
||||||
|
$dupCheck->bind_param('ss', $data['from_status'], $data['to_status']);
|
||||||
|
$dupCheck->execute();
|
||||||
|
if ($dupCheck->get_result()->fetch_assoc()) {
|
||||||
|
$dupCheck->close();
|
||||||
|
http_response_code(409);
|
||||||
|
echo json_encode([
|
||||||
|
'success' => false,
|
||||||
|
'error' => 'A transition already exists for '
|
||||||
|
. $data['from_status'] . ' → ' . $data['to_status']
|
||||||
|
. ' — edit that row instead of creating a duplicate.',
|
||||||
|
]);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
$dupCheck->close();
|
||||||
|
|
||||||
$stmt = $conn->prepare("INSERT INTO status_transitions (from_status, to_status, requires_comment, requires_admin, is_active)
|
$stmt = $conn->prepare("INSERT INTO status_transitions (from_status, to_status, requires_comment, requires_admin, is_active)
|
||||||
VALUES (?, ?, ?, ?, ?)");
|
VALUES (?, ?, ?, ?, ?)");
|
||||||
$wf_from = $data['from_status'];
|
$wf_from = $data['from_status'];
|
||||||
$wf_to = $data['to_status'];
|
$wf_to = $data['to_status'];
|
||||||
$wf_comment = (int)($data['requires_comment'] ?? 0);
|
$wf_comment = (int)($data['requires_comment'] ?? 0);
|
||||||
$wf_admin = (int)($data['requires_admin'] ?? 0);
|
$wf_admin = (int)($data['requires_admin'] ?? 0);
|
||||||
$wf_active = (int)($data['is_active'] ?? 1);
|
|
||||||
$stmt->bind_param('ssiii', $wf_from, $wf_to, $wf_comment, $wf_admin, $wf_active);
|
$stmt->bind_param('ssiii', $wf_from, $wf_to, $wf_comment, $wf_admin, $wf_active);
|
||||||
|
|
||||||
if ($stmt->execute()) {
|
if ($stmt->execute()) {
|
||||||
@@ -149,6 +175,28 @@ try {
|
|||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
$wf_active = (int)($data['is_active'] ?? 1);
|
||||||
|
|
||||||
|
// Same duplicate-pair guard as create, excluding this row itself.
|
||||||
|
$dupCheck = $conn->prepare(
|
||||||
|
"SELECT transition_id FROM status_transitions
|
||||||
|
WHERE from_status = ? AND to_status = ? AND transition_id != ?"
|
||||||
|
);
|
||||||
|
$dupCheck->bind_param('ssi', $data['from_status'], $data['to_status'], $id);
|
||||||
|
$dupCheck->execute();
|
||||||
|
if ($dupCheck->get_result()->fetch_assoc()) {
|
||||||
|
$dupCheck->close();
|
||||||
|
http_response_code(409);
|
||||||
|
echo json_encode([
|
||||||
|
'success' => false,
|
||||||
|
'error' => 'A transition already exists for '
|
||||||
|
. $data['from_status'] . ' → ' . $data['to_status']
|
||||||
|
. ' — edit that row instead of creating a duplicate.',
|
||||||
|
]);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
$dupCheck->close();
|
||||||
|
|
||||||
$stmt = $conn->prepare("UPDATE status_transitions SET
|
$stmt = $conn->prepare("UPDATE status_transitions SET
|
||||||
from_status = ?, to_status = ?, requires_comment = ?, requires_admin = ?, is_active = ?
|
from_status = ?, to_status = ?, requires_comment = ?, requires_admin = ?, is_active = ?
|
||||||
WHERE transition_id = ?");
|
WHERE transition_id = ?");
|
||||||
@@ -156,7 +204,6 @@ try {
|
|||||||
$wf_to = $data['to_status'];
|
$wf_to = $data['to_status'];
|
||||||
$wf_comment = (int)($data['requires_comment'] ?? 0);
|
$wf_comment = (int)($data['requires_comment'] ?? 0);
|
||||||
$wf_admin = (int)($data['requires_admin'] ?? 0);
|
$wf_admin = (int)($data['requires_admin'] ?? 0);
|
||||||
$wf_active = (int)($data['is_active'] ?? 1);
|
|
||||||
$stmt->bind_param('ssiiii', $wf_from, $wf_to, $wf_comment, $wf_admin, $wf_active, $id);
|
$stmt->bind_param('ssiiii', $wf_from, $wf_to, $wf_comment, $wf_admin, $wf_active, $id);
|
||||||
|
|
||||||
$success = $stmt->execute();
|
$success = $stmt->execute();
|
||||||
|
|||||||
+40
-1
@@ -15,8 +15,10 @@
|
|||||||
|
|
||||||
require_once __DIR__ . '/bootstrap.php';
|
require_once __DIR__ . '/bootstrap.php';
|
||||||
require_once dirname(__DIR__) . '/models/UserPreferencesModel.php';
|
require_once dirname(__DIR__) . '/models/UserPreferencesModel.php';
|
||||||
|
require_once dirname(__DIR__) . '/models/TicketModel.php';
|
||||||
|
|
||||||
$prefsModel = new UserPreferencesModel($conn);
|
$prefsModel = new UserPreferencesModel($conn);
|
||||||
|
$ticketModel = new TicketModel($conn);
|
||||||
|
|
||||||
// ── POST: mark all read (update last_seen timestamp) ──────────────
|
// ── POST: mark all read (update last_seen timestamp) ──────────────
|
||||||
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
||||||
@@ -204,7 +206,44 @@ foreach (array_merge($assignRows, $commentRows, $statusRows, $mentionRows) as $r
|
|||||||
$all[] = $row;
|
$all[] = $row;
|
||||||
}
|
}
|
||||||
usort($all, fn($a, $b) => strcmp($b['created_at'], $a['created_at']));
|
usort($all, fn($a, $b) => strcmp($b['created_at'], $a['created_at']));
|
||||||
$all = array_slice($all, 0, 30);
|
|
||||||
|
// Re-check current ticket visibility before surfacing anything: a
|
||||||
|
// notification's audit_log entry reflects historical activity, but the
|
||||||
|
// ticket's visibility (or the user's group/watcher standing) may have
|
||||||
|
// tightened since. Without this, a notification still discloses the
|
||||||
|
// ticket's title and that activity occurred to someone who currently
|
||||||
|
// shouldn't see it, even though the ticket view's own access check would
|
||||||
|
// correctly reject them from opening it.
|
||||||
|
$candidateTicketIds = [];
|
||||||
|
foreach ($all as $row) {
|
||||||
|
$details = json_decode($row['details'] ?? '{}', true) ?? [];
|
||||||
|
$actionType = ($row['action_type'] === 'create' && $row['entity_type'] === 'comment')
|
||||||
|
? 'comment'
|
||||||
|
: $row['action_type'];
|
||||||
|
$tid = ($actionType === 'comment' || $actionType === 'mention')
|
||||||
|
? ($details['ticket_id'] ?? 0)
|
||||||
|
: $row['entity_id'];
|
||||||
|
if ($tid) {
|
||||||
|
$candidateTicketIds[(string)$tid] = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
$ticketsById = !empty($candidateTicketIds)
|
||||||
|
? $ticketModel->getTicketsByIds(array_keys($candidateTicketIds))
|
||||||
|
: [];
|
||||||
|
|
||||||
|
$all = array_filter($all, function ($row) use ($ticketsById, $currentUser, $ticketModel) {
|
||||||
|
$details = json_decode($row['details'] ?? '{}', true) ?? [];
|
||||||
|
$actionType = ($row['action_type'] === 'create' && $row['entity_type'] === 'comment')
|
||||||
|
? 'comment'
|
||||||
|
: $row['action_type'];
|
||||||
|
$tid = (string)(($actionType === 'comment' || $actionType === 'mention')
|
||||||
|
? ($details['ticket_id'] ?? 0)
|
||||||
|
: $row['entity_id']);
|
||||||
|
$ticket = $ticketsById[$tid] ?? null;
|
||||||
|
return $ticket && $ticketModel->canUserAccessTicket($ticket, $currentUser);
|
||||||
|
});
|
||||||
|
|
||||||
|
$all = array_slice(array_values($all), 0, 30);
|
||||||
|
|
||||||
// Format for response
|
// Format for response
|
||||||
$notifications = [];
|
$notifications = [];
|
||||||
|
|||||||
@@ -0,0 +1,87 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Save custom field values for a ticket.
|
||||||
|
*
|
||||||
|
* POST { ticket_id, values: { [field_id]: value, ... } }
|
||||||
|
*
|
||||||
|
* Only fields applicable to the ticket's current category (or category-less
|
||||||
|
* fields) are considered; anything else in `values` is ignored rather than
|
||||||
|
* persisted, so a value typed for a field that no longer applies (e.g. the
|
||||||
|
* category changed) can't linger as orphaned/misleading data.
|
||||||
|
*/
|
||||||
|
|
||||||
|
require_once __DIR__ . '/bootstrap.php';
|
||||||
|
require_once dirname(__DIR__) . '/models/TicketModel.php';
|
||||||
|
require_once dirname(__DIR__) . '/models/CustomFieldModel.php';
|
||||||
|
|
||||||
|
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
|
||||||
|
http_response_code(405);
|
||||||
|
apiRespond(['success' => false, 'error' => 'Method not allowed']);
|
||||||
|
}
|
||||||
|
|
||||||
|
$data = json_decode(file_get_contents('php://input'), true);
|
||||||
|
$ticketId = isset($data['ticket_id']) ? trim((string)$data['ticket_id']) : '';
|
||||||
|
$values = is_array($data['values'] ?? null) ? $data['values'] : [];
|
||||||
|
|
||||||
|
if ($ticketId === '') {
|
||||||
|
http_response_code(400);
|
||||||
|
apiRespond(['success' => false, 'error' => 'ticket_id required']);
|
||||||
|
}
|
||||||
|
|
||||||
|
$ticketModel = new TicketModel($conn);
|
||||||
|
$ticket = $ticketModel->getTicketById($ticketId);
|
||||||
|
if (!$ticket || !$ticketModel->canUserAccessTicket($ticket, $currentUser)) {
|
||||||
|
http_response_code(404);
|
||||||
|
apiRespond(['success' => false, 'error' => 'Ticket not found']);
|
||||||
|
}
|
||||||
|
|
||||||
|
$fieldModel = new CustomFieldModel($conn);
|
||||||
|
$definitions = $fieldModel->getAllDefinitions($ticket['category'], true);
|
||||||
|
|
||||||
|
$errors = [];
|
||||||
|
$toSave = [];
|
||||||
|
foreach ($definitions as $def) {
|
||||||
|
$fieldId = (int)$def['field_id'];
|
||||||
|
$raw = $values[$fieldId] ?? ($values[(string)$fieldId] ?? null);
|
||||||
|
|
||||||
|
if ($def['field_type'] === 'checkbox') {
|
||||||
|
$normalized = !empty($raw) ? '1' : '0';
|
||||||
|
} else {
|
||||||
|
$normalized = is_scalar($raw) ? trim((string)$raw) : '';
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!empty($def['is_required']) && $def['field_type'] !== 'checkbox' && $normalized === '') {
|
||||||
|
$errors[] = $def['field_label'] . ' is required';
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($def['field_type'] === 'select' && $normalized !== '') {
|
||||||
|
$allowedOptions = $def['field_options']['options'] ?? [];
|
||||||
|
if (!in_array($normalized, $allowedOptions, true)) {
|
||||||
|
$errors[] = $def['field_label'] . ' has an invalid selection';
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($def['field_type'] === 'number' && $normalized !== '' && !is_numeric($normalized)) {
|
||||||
|
$errors[] = $def['field_label'] . ' must be a number';
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
$toSave[$fieldId] = $normalized;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!empty($errors)) {
|
||||||
|
http_response_code(422);
|
||||||
|
apiRespond(['success' => false, 'error' => implode('; ', $errors)]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$fieldModel->setValues($ticketId, $toSave);
|
||||||
|
|
||||||
|
require_once dirname(__DIR__) . '/models/AuditLogModel.php';
|
||||||
|
(new AuditLogModel($conn))->log($userId, 'update', 'ticket', $ticketId, [
|
||||||
|
'reason' => 'custom fields updated',
|
||||||
|
]);
|
||||||
|
|
||||||
|
apiRespond(['success' => true]);
|
||||||
@@ -104,7 +104,10 @@ try {
|
|||||||
'update',
|
'update',
|
||||||
'comment',
|
'comment',
|
||||||
(string)$commentId,
|
(string)$commentId,
|
||||||
['comment_text_preview' => substr($commentText, 0, 100)]
|
[
|
||||||
|
'ticket_id' => $comment['ticket_id'] ?? null,
|
||||||
|
'comment_text_preview' => substr($commentText, 0, 100),
|
||||||
|
]
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -276,7 +276,8 @@ try {
|
|||||||
$updateData['title'],
|
$updateData['title'],
|
||||||
'status_changed',
|
'status_changed',
|
||||||
['old_status' => $currentTicket['status'], 'new_status' => $updateData['status'], 'changed_by' => $changedBy],
|
['old_status' => $currentTicket['status'], 'new_status' => $updateData['status'], 'changed_by' => $changedBy],
|
||||||
(int)$this->userId
|
(int)$this->userId,
|
||||||
|
$currentTicket['visibility'] ?? 'public'
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -61,25 +61,46 @@ function populateCurrentFilters() {
|
|||||||
const urlParams = new URLSearchParams(window.location.search);
|
const urlParams = new URLSearchParams(window.location.search);
|
||||||
|
|
||||||
// Search text
|
// Search text
|
||||||
if (urlParams.has('search')) {
|
document.getElementById('adv-search-text').value = urlParams.get('search') || '';
|
||||||
document.getElementById('adv-search-text').value = urlParams.get('search');
|
|
||||||
}
|
|
||||||
|
|
||||||
// Status
|
// Status
|
||||||
if (urlParams.has('status')) {
|
const statuses = urlParams.has('status') ? urlParams.get('status').split(',') : [];
|
||||||
const statuses = urlParams.get('status').split(',');
|
const statusSelect = document.getElementById('adv-status');
|
||||||
const statusSelect = document.getElementById('adv-status');
|
Array.from(statusSelect.options).forEach(option => {
|
||||||
Array.from(statusSelect.options).forEach(option => {
|
option.selected = statuses.includes(option.value);
|
||||||
option.selected = statuses.includes(option.value);
|
});
|
||||||
});
|
|
||||||
}
|
// Date ranges
|
||||||
|
document.getElementById('adv-created-from').value = urlParams.get('created_from') || '';
|
||||||
|
document.getElementById('adv-created-to').value = urlParams.get('created_to') || '';
|
||||||
|
document.getElementById('adv-updated-from').value = urlParams.get('updated_from') || '';
|
||||||
|
document.getElementById('adv-updated-to').value = urlParams.get('updated_to') || '';
|
||||||
|
|
||||||
|
// Priority range
|
||||||
|
document.getElementById('adv-priority-min').value = urlParams.get('priority_min') || '';
|
||||||
|
document.getElementById('adv-priority-max').value = urlParams.get('priority_max') || '';
|
||||||
|
|
||||||
|
// Users
|
||||||
|
document.getElementById('adv-created-by').value = urlParams.get('created_by') || '';
|
||||||
|
document.getElementById('adv-assigned-to').value = urlParams.get('assigned_to') || '';
|
||||||
}
|
}
|
||||||
|
|
||||||
// Perform advanced search
|
// Perform advanced search
|
||||||
function performAdvancedSearch(event) {
|
function performAdvancedSearch(event) {
|
||||||
event.preventDefault();
|
event.preventDefault();
|
||||||
|
|
||||||
const params = new URLSearchParams();
|
// Start from the CURRENT URL's params, not a fresh set, so a filter this
|
||||||
|
// form doesn't represent (e.g. a category/type filter applied via a
|
||||||
|
// dashboard quick-filter pill or stats-widget click) isn't silently
|
||||||
|
// dropped on submit. Only the params this form actually controls are
|
||||||
|
// set/cleared below; everything else passes through untouched.
|
||||||
|
const params = new URLSearchParams(window.location.search);
|
||||||
|
const advParams = [
|
||||||
|
'search', 'created_from', 'created_to', 'updated_from', 'updated_to',
|
||||||
|
'status', 'priority_min', 'priority_max', 'created_by', 'assigned_to',
|
||||||
|
];
|
||||||
|
advParams.forEach(key => params.delete(key));
|
||||||
|
params.delete('page'); // filters changed — reset to page 1
|
||||||
|
|
||||||
// Search text
|
// Search text
|
||||||
const searchText = document.getElementById('adv-search-text').value.trim();
|
const searchText = document.getElementById('adv-search-text').value.trim();
|
||||||
|
|||||||
+21
-70
@@ -41,6 +41,16 @@
|
|||||||
* 32. Drag & Drop Upload
|
* 32. Drag & Drop Upload
|
||||||
* 33. Intersection Observer
|
* 33. Intersection Observer
|
||||||
* 34. Full Initialisation
|
* 34. Full Initialisation
|
||||||
|
*
|
||||||
|
* NOTE ON EMPTY CATCH BLOCKS: throughout this file, `try { ... } catch (_) {}`
|
||||||
|
* around localStorage/sessionStorage access (persisted tab/theme/column-
|
||||||
|
* visibility state, recent command-palette entries, etc.) and the terminal
|
||||||
|
* beep's AudioContext calls is intentional, not an oversight — these are
|
||||||
|
* best-effort UX affordances that must silently no-op rather than break the
|
||||||
|
* surrounding feature if storage is disabled/full (private browsing, quota)
|
||||||
|
* or audio is blocked (autoplay policy). Swallowing errors from arbitrary
|
||||||
|
* caller-supplied callbacks (e.g. viewport-change listeners) is handled
|
||||||
|
* separately with real logging, since those can hide genuine bugs.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
(function (global) {
|
(function (global) {
|
||||||
@@ -1398,7 +1408,7 @@
|
|||||||
_vpCurrent = bp;
|
_vpCurrent = bp;
|
||||||
if (bp !== prev) {
|
if (bp !== prev) {
|
||||||
const evt = { bp, w, h, prev };
|
const evt = { bp, w, h, prev };
|
||||||
_vpListeners.forEach(cb => { try { cb(evt); } catch (_) {} });
|
_vpListeners.forEach(cb => { try { cb(evt); } catch (e) { console.error('[lt.viewport] listener threw:', e); } });
|
||||||
bus.emit('viewport:change', evt);
|
bus.emit('viewport:change', evt);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -2801,7 +2811,7 @@
|
|||||||
};
|
};
|
||||||
|
|
||||||
// Patch lt.api — auth-aware wrapper (renamed to avoid strict-mode duplicate declaration)
|
// Patch lt.api — auth-aware wrapper (renamed to avoid strict-mode duplicate declaration)
|
||||||
async function _apiFetchAuth(method, url, body) {
|
async function _apiFetchAuth(method, url, body, retried) {
|
||||||
if (_authAccess && auth.isExpiringSoon()) await auth.refresh();
|
if (_authAccess && auth.isExpiringSoon()) await auth.refresh();
|
||||||
const opts = { method, headers: Object.assign({ 'Content-Type': 'application/json' }, csrfHeaders()) };
|
const opts = { method, headers: Object.assign({ 'Content-Type': 'application/json' }, csrfHeaders()) };
|
||||||
if (_authAccess) opts.headers['Authorization'] = 'Bearer ' + _authAccess;
|
if (_authAccess) opts.headers['Authorization'] = 'Bearer ' + _authAccess;
|
||||||
@@ -2821,6 +2831,15 @@
|
|||||||
// Resync CSRF token from any response body that carries a fresh one
|
// Resync CSRF token from any response body that carries a fresh one
|
||||||
// (bootstrap rotates on success and returns the current token on rejection).
|
// (bootstrap rotates on success and returns the current token on rejection).
|
||||||
if (data && data.csrf_token) global.CSRF_TOKEN = data.csrf_token;
|
if (data && data.csrf_token) global.CSRF_TOKEN = data.csrf_token;
|
||||||
|
// Auto-retry once on a stale-CSRF-token 403: the token lifetime (1h) is
|
||||||
|
// shorter than the session idle timeout (5h), so this is a routine,
|
||||||
|
// recoverable case (an hour of inactivity, or a write in another tab
|
||||||
|
// rotating the shared token) rather than a real rejection — resyncing
|
||||||
|
// above already has the fresh token, so silently resending once succeeds
|
||||||
|
// transparently instead of surfacing a confusing error on the first try.
|
||||||
|
if (resp.status === 403 && !retried && data && data.csrf_token) {
|
||||||
|
return _apiFetchAuth(method, url, body, true);
|
||||||
|
}
|
||||||
if (!resp.ok) {
|
if (!resp.ok) {
|
||||||
const err = new Error(data.error || data.message || 'HTTP ' + resp.status);
|
const err = new Error(data.error || data.message || 'HTTP ' + resp.status);
|
||||||
err.data = data;
|
err.data = data;
|
||||||
@@ -2911,73 +2930,6 @@
|
|||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
/* ================================================================
|
|
||||||
MODULE 54 — MARKDOWN RENDERER
|
|
||||||
lt.markdown.render(mdString) → HTML string (sanitized)
|
|
||||||
lt.markdown.init(selector) → renders all matching el's .textContent
|
|
||||||
Uses a built-in micro-renderer (no deps) for common syntax.
|
|
||||||
For full GFM, swap in marked.js: window.marked && marked.parse()
|
|
||||||
================================================================ */
|
|
||||||
const markdown = {
|
|
||||||
render(md) {
|
|
||||||
// Always use the built-in XSS-safe micro-renderer. Do NOT delegate to
|
|
||||||
// window.marked / window.markdownit: their raw HTML output is not sanitized
|
|
||||||
// here, so delegating would enable stored XSS if such a lib were ever loaded.
|
|
||||||
// Micro-renderer: covers headings, bold, italic, code, links, lists, blockquote, hr
|
|
||||||
let html = escHtml(md)
|
|
||||||
// Fenced code blocks
|
|
||||||
.replace(/```(\w*)\n([\s\S]*?)```/g, (_, lang, code) => `<pre class="lt-code-block"><code class="lt-tok tok-${lang || 'plain'}">${code.trim()}</code></pre>`)
|
|
||||||
// Inline code
|
|
||||||
.replace(/`([^`]+)`/g, '<code>$1</code>')
|
|
||||||
// Headings
|
|
||||||
.replace(/^######\s(.+)$/gm, '<h6>$1</h6>')
|
|
||||||
.replace(/^#####\s(.+)$/gm, '<h5>$1</h5>')
|
|
||||||
.replace(/^####\s(.+)$/gm, '<h4>$1</h4>')
|
|
||||||
.replace(/^###\s(.+)$/gm, '<h3>$1</h3>')
|
|
||||||
.replace(/^##\s(.+)$/gm, '<h2>$1</h2>')
|
|
||||||
.replace(/^#\s(.+)$/gm, '<h1>$1</h1>')
|
|
||||||
// Bold / italic
|
|
||||||
.replace(/\*\*\*(.+?)\*\*\*/g, '<strong><em>$1</em></strong>')
|
|
||||||
.replace(/\*\*(.+?)\*\*/g, '<strong>$1</strong>')
|
|
||||||
.replace(/\*(.+?)\*/g, '<em>$1</em>')
|
|
||||||
.replace(/__(.+?)__/g, '<strong>$1</strong>')
|
|
||||||
.replace(/_(.+?)_/g, '<em>$1</em>')
|
|
||||||
// Links — block javascript: and data: URIs
|
|
||||||
.replace(/\[([^\]]+)\]\(([^)]+)\)/g, (_, text, url) => {
|
|
||||||
const safeUrl = /^(https?:\/\/|\/|#|\.\.?\/)/i.test(url) ? url : '#';
|
|
||||||
return `<a href="${safeUrl}" target="_blank" rel="noopener noreferrer">${escHtml(text)}</a>`;
|
|
||||||
})
|
|
||||||
// Images — block javascript: and data: URIs
|
|
||||||
.replace(/!\[([^\]]*)\]\(([^)]+)\)/g, (_, alt, src) => {
|
|
||||||
const safeSrc = /^(https?:\/\/|\/|\.\.?\/)/i.test(src) ? src : '';
|
|
||||||
return `<img src="${safeSrc}" alt="${escHtml(alt)}" style="max-width:100%">`;
|
|
||||||
})
|
|
||||||
// Blockquote
|
|
||||||
.replace(/^>\s(.+)$/gm, '<blockquote>$1</blockquote>')
|
|
||||||
// Horizontal rule
|
|
||||||
.replace(/^(-{3,}|\*{3,}|_{3,})$/gm, '<hr>')
|
|
||||||
// Unordered list items
|
|
||||||
.replace(/^[-*+]\s(.+)$/gm, '<li>$1</li>')
|
|
||||||
.replace(/(<li>[\s\S]+?<\/li>\n?)+/g, m => `<ul>${m}</ul>`)
|
|
||||||
// Ordered list items
|
|
||||||
.replace(/^\d+\.\s(.+)$/gm, '<li>$1</li>')
|
|
||||||
// Paragraphs (double newline)
|
|
||||||
.replace(/\n{2,}/g, '</p><p>')
|
|
||||||
.replace(/\n/g, '<br>');
|
|
||||||
return `<p>${html}</p>`
|
|
||||||
.replace(/<p>(<(?:pre|ul|ol|h[1-6]|blockquote|hr)[^>]*>)/g, '$1')
|
|
||||||
.replace(/(<\/(?:pre|ul|ol|h[1-6]|blockquote|hr)>)<\/p>/g, '$1');
|
|
||||||
},
|
|
||||||
|
|
||||||
init(selector) {
|
|
||||||
document.querySelectorAll(selector).forEach(el => {
|
|
||||||
const raw = el.getAttribute('data-markdown') || el.textContent;
|
|
||||||
el.innerHTML = markdown.render(raw);
|
|
||||||
el.classList.add('lt-markdown');
|
|
||||||
});
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
/* ================================================================
|
/* ================================================================
|
||||||
MODULE 55 — PAGINATION
|
MODULE 55 — PAGINATION
|
||||||
lt.pagination.init(navEl, opts)
|
lt.pagination.init(navEl, opts)
|
||||||
@@ -3140,7 +3092,6 @@
|
|||||||
timer,
|
timer,
|
||||||
lightbox,
|
lightbox,
|
||||||
auth,
|
auth,
|
||||||
markdown,
|
|
||||||
ticketStatus,
|
ticketStatus,
|
||||||
pagination,
|
pagination,
|
||||||
sidebarSubmenus: { init: initSidebarSubmenus },
|
sidebarSubmenus: { init: initSidebarSubmenus },
|
||||||
|
|||||||
@@ -506,6 +506,25 @@ function toolbarHeading(textareaId) {
|
|||||||
textarea.dispatchEvent(new Event('input', { bubbles: true }));
|
textarea.dispatchEvent(new Event('input', { bubbles: true }));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function toolbarTable(textareaId) {
|
||||||
|
const textarea = document.getElementById(textareaId);
|
||||||
|
if (!textarea) return;
|
||||||
|
|
||||||
|
const start = textarea.selectionStart;
|
||||||
|
const text = textarea.value;
|
||||||
|
|
||||||
|
// Insert on its own line(s), matching the blank-line-before convention
|
||||||
|
// toolbarList/toolbarHeading rely on the surrounding text for — a table
|
||||||
|
// needs a full line to itself both before and after the separator row.
|
||||||
|
const needsLeadingNewline = start > 0 && text[start - 1] !== '\n';
|
||||||
|
const template = (needsLeadingNewline ? '\n' : '')
|
||||||
|
+ '| Header 1 | Header 2 |\n'
|
||||||
|
+ '| --- | --- |\n'
|
||||||
|
+ '| Cell 1 | Cell 2 |\n';
|
||||||
|
|
||||||
|
insertMarkdownText(textareaId, template);
|
||||||
|
}
|
||||||
|
|
||||||
function toolbarQuote(textareaId) {
|
function toolbarQuote(textareaId) {
|
||||||
const textarea = document.getElementById(textareaId);
|
const textarea = document.getElementById(textareaId);
|
||||||
if (!textarea) return;
|
if (!textarea) return;
|
||||||
@@ -544,6 +563,7 @@ function createEditorToolbar(textareaId, containerId) {
|
|||||||
<button type="button" data-toolbar-action="heading" data-textarea="${textareaId}" title="Heading">H</button>
|
<button type="button" data-toolbar-action="heading" data-textarea="${textareaId}" title="Heading">H</button>
|
||||||
<button type="button" data-toolbar-action="list" data-textarea="${textareaId}" title="List">≡</button>
|
<button type="button" data-toolbar-action="list" data-textarea="${textareaId}" title="List">≡</button>
|
||||||
<button type="button" data-toolbar-action="quote" data-textarea="${textareaId}" title="Quote">"</button>
|
<button type="button" data-toolbar-action="quote" data-textarea="${textareaId}" title="Quote">"</button>
|
||||||
|
<button type="button" data-toolbar-action="table" data-textarea="${textareaId}" title="Table">▦</button>
|
||||||
<span class="toolbar-separator"></span>
|
<span class="toolbar-separator"></span>
|
||||||
<button type="button" data-toolbar-action="link" data-textarea="${textareaId}" title="Link">[ @ ]</button>
|
<button type="button" data-toolbar-action="link" data-textarea="${textareaId}" title="Link">[ @ ]</button>
|
||||||
`;
|
`;
|
||||||
@@ -563,6 +583,7 @@ function createEditorToolbar(textareaId, containerId) {
|
|||||||
case 'heading': toolbarHeading(targetId); break;
|
case 'heading': toolbarHeading(targetId); break;
|
||||||
case 'list': toolbarList(targetId); break;
|
case 'list': toolbarList(targetId); break;
|
||||||
case 'quote': toolbarQuote(targetId); break;
|
case 'quote': toolbarQuote(targetId); break;
|
||||||
|
case 'table': toolbarTable(targetId); break;
|
||||||
case 'link': toolbarLink(targetId); break;
|
case 'link': toolbarLink(targetId); break;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -578,6 +599,7 @@ window.toolbarLink = toolbarLink;
|
|||||||
window.toolbarList = toolbarList;
|
window.toolbarList = toolbarList;
|
||||||
window.toolbarHeading = toolbarHeading;
|
window.toolbarHeading = toolbarHeading;
|
||||||
window.toolbarQuote = toolbarQuote;
|
window.toolbarQuote = toolbarQuote;
|
||||||
|
window.toolbarTable = toolbarTable;
|
||||||
window.createEditorToolbar = createEditorToolbar;
|
window.createEditorToolbar = createEditorToolbar;
|
||||||
window.insertMarkdownFormat = insertMarkdownFormat;
|
window.insertMarkdownFormat = insertMarkdownFormat;
|
||||||
window.insertMarkdownText = insertMarkdownText;
|
window.insertMarkdownText = insertMarkdownText;
|
||||||
|
|||||||
+7
-2
@@ -357,12 +357,17 @@ function togglePreview() {
|
|||||||
|
|
||||||
if (isPreviewEnabled) {
|
if (isPreviewEnabled) {
|
||||||
preview.innerHTML = parseMarkdown(textarea.value);
|
preview.innerHTML = parseMarkdown(textarea.value);
|
||||||
textarea.addEventListener('input', updatePreview);
|
textarea.addEventListener('input', debouncedUpdatePreview);
|
||||||
} else {
|
} else {
|
||||||
textarea.removeEventListener('input', updatePreview);
|
textarea.removeEventListener('input', debouncedUpdatePreview);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Re-running the full markdown parser on every single keystroke is wasted
|
||||||
|
// work while the user is still mid-word; 150ms debounce keeps the preview
|
||||||
|
// feeling live without re-parsing on every keystroke.
|
||||||
|
const debouncedUpdatePreview = window.lt ? lt.debounce(updatePreview, 150) : updatePreview;
|
||||||
|
|
||||||
function updatePreview() {
|
function updatePreview() {
|
||||||
const textarea = document.getElementById('newComment');
|
const textarea = document.getElementById('newComment');
|
||||||
const previewDiv = document.getElementById('markdownPreview');
|
const previewDiv = document.getElementById('markdownPreview');
|
||||||
|
|||||||
+3
-3
@@ -141,9 +141,9 @@ $GLOBALS['config'] = [
|
|||||||
],
|
],
|
||||||
'UPLOAD_DIR' => __DIR__ . '/../uploads',
|
'UPLOAD_DIR' => __DIR__ . '/../uploads',
|
||||||
|
|
||||||
// Rate limiting
|
// Rate limiting (requests per minute; read by RateLimitMiddleware)
|
||||||
'RATE_LIMIT_DEFAULT' => 100, // Requests per minute for general
|
'RATE_LIMIT_DEFAULT' => (int)($envVars['RATE_LIMIT_DEFAULT'] ?? 100), // Session-based, general endpoints
|
||||||
'RATE_LIMIT_API' => 60, // Requests per minute for API
|
'RATE_LIMIT_API' => (int)($envVars['RATE_LIMIT_API'] ?? 60), // Session-based, API endpoints
|
||||||
|
|
||||||
// Audit log settings
|
// Audit log settings
|
||||||
'AUDIT_LOG_RETENTION_DAYS' => 90,
|
'AUDIT_LOG_RETENTION_DAYS' => 90,
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ require_once dirname(__DIR__) . '/models/AuditLogModel.php';
|
|||||||
require_once dirname(__DIR__) . '/models/UserModel.php';
|
require_once dirname(__DIR__) . '/models/UserModel.php';
|
||||||
require_once dirname(__DIR__) . '/models/WorkflowModel.php';
|
require_once dirname(__DIR__) . '/models/WorkflowModel.php';
|
||||||
require_once dirname(__DIR__) . '/models/TemplateModel.php';
|
require_once dirname(__DIR__) . '/models/TemplateModel.php';
|
||||||
|
require_once dirname(__DIR__) . '/models/CustomFieldModel.php';
|
||||||
require_once dirname(__DIR__) . '/helpers/UrlHelper.php';
|
require_once dirname(__DIR__) . '/helpers/UrlHelper.php';
|
||||||
require_once dirname(__DIR__) . '/helpers/NotificationHelper.php';
|
require_once dirname(__DIR__) . '/helpers/NotificationHelper.php';
|
||||||
|
|
||||||
@@ -18,6 +19,7 @@ class TicketController
|
|||||||
private $userModel;
|
private $userModel;
|
||||||
private $workflowModel;
|
private $workflowModel;
|
||||||
private $templateModel;
|
private $templateModel;
|
||||||
|
private $customFieldModel;
|
||||||
private $conn;
|
private $conn;
|
||||||
|
|
||||||
public function __construct($conn)
|
public function __construct($conn)
|
||||||
@@ -29,6 +31,7 @@ class TicketController
|
|||||||
$this->userModel = new UserModel($conn);
|
$this->userModel = new UserModel($conn);
|
||||||
$this->workflowModel = new WorkflowModel($conn);
|
$this->workflowModel = new WorkflowModel($conn);
|
||||||
$this->templateModel = new TemplateModel($conn);
|
$this->templateModel = new TemplateModel($conn);
|
||||||
|
$this->customFieldModel = new CustomFieldModel($conn);
|
||||||
}
|
}
|
||||||
|
|
||||||
public function view($id)
|
public function view($id)
|
||||||
@@ -60,6 +63,11 @@ class TicketController
|
|||||||
// Get allowed status transitions for this ticket
|
// Get allowed status transitions for this ticket
|
||||||
$allowedTransitions = $this->workflowModel->getAllowedTransitions($ticket['status']);
|
$allowedTransitions = $this->workflowModel->getAllowedTransitions($ticket['status']);
|
||||||
|
|
||||||
|
// Custom fields applicable to this ticket's category, with any
|
||||||
|
// already-saved values for it
|
||||||
|
$customFieldDefs = $this->customFieldModel->getAllDefinitions($ticket['category'], true);
|
||||||
|
$customFieldValues = $this->customFieldModel->getValuesForTicket($id);
|
||||||
|
|
||||||
// Make $conn available to view for visibility groups
|
// Make $conn available to view for visibility groups
|
||||||
$conn = $this->conn;
|
$conn = $this->conn;
|
||||||
|
|
||||||
@@ -73,6 +81,12 @@ class TicketController
|
|||||||
$currentUser = $GLOBALS['currentUser'] ?? null;
|
$currentUser = $GLOBALS['currentUser'] ?? null;
|
||||||
$userId = $currentUser['user_id'] ?? null;
|
$userId = $currentUser['user_id'] ?? null;
|
||||||
|
|
||||||
|
// All active custom field definitions (every category, plus
|
||||||
|
// category-less ones) — the create form renders them all and toggles
|
||||||
|
// visibility client-side as the Category select changes, since the
|
||||||
|
// ticket doesn't exist yet to scope the query to one category.
|
||||||
|
$allCustomFieldDefs = $this->customFieldModel->getAllDefinitions(null, true);
|
||||||
|
|
||||||
// Check if form was submitted
|
// Check if form was submitted
|
||||||
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
||||||
// Validate CSRF token
|
// Validate CSRF token
|
||||||
@@ -131,6 +145,38 @@ class TicketController
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Custom fields applicable to the submitted category — validate
|
||||||
|
// is_required server-side (the form is novalidate, and a field
|
||||||
|
// hidden by the client-side category toggle must not silently
|
||||||
|
// bypass a requirement that applies to the category actually
|
||||||
|
// submitted).
|
||||||
|
$submittedCustomFields = is_array($_POST['custom_fields'] ?? null) ? $_POST['custom_fields'] : [];
|
||||||
|
$applicableFieldDefs = array_filter(
|
||||||
|
$allCustomFieldDefs,
|
||||||
|
fn($def) => $def['category'] === null || $def['category'] === $ticketData['category']
|
||||||
|
);
|
||||||
|
$customFieldsToSave = [];
|
||||||
|
foreach ($applicableFieldDefs as $def) {
|
||||||
|
$fieldId = (int)$def['field_id'];
|
||||||
|
$raw = $submittedCustomFields[$fieldId] ?? null;
|
||||||
|
$normalized = $def['field_type'] === 'checkbox'
|
||||||
|
? (!empty($raw) ? '1' : '0')
|
||||||
|
: (is_scalar($raw) ? trim((string)$raw) : '');
|
||||||
|
|
||||||
|
if (!empty($def['is_required']) && $def['field_type'] !== 'checkbox' && $normalized === '') {
|
||||||
|
$error = $def['field_label'] . ' is required';
|
||||||
|
$templates = $this->templateModel->getAllTemplates();
|
||||||
|
$allUsers = $this->userModel->getAllUsers();
|
||||||
|
$conn = $this->conn;
|
||||||
|
include dirname(__DIR__) . '/views/CreateTicketView.php';
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($normalized !== '') {
|
||||||
|
$customFieldsToSave[$fieldId] = $normalized;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Create ticket with user tracking
|
// Create ticket with user tracking
|
||||||
$result = $this->ticketModel->createTicket($ticketData, $userId);
|
$result = $this->ticketModel->createTicket($ticketData, $userId);
|
||||||
|
|
||||||
@@ -144,6 +190,12 @@ class TicketController
|
|||||||
require_once dirname(__DIR__) . '/models/StatsModel.php';
|
require_once dirname(__DIR__) . '/models/StatsModel.php';
|
||||||
(new StatsModel($this->conn))->invalidateCache();
|
(new StatsModel($this->conn))->invalidateCache();
|
||||||
|
|
||||||
|
// Persist custom field values for the fields applicable to
|
||||||
|
// this ticket's category
|
||||||
|
if (!empty($customFieldsToSave)) {
|
||||||
|
$this->customFieldModel->setValues($result['ticket_id'], $customFieldsToSave);
|
||||||
|
}
|
||||||
|
|
||||||
// Auto-link as duplicate if requested from create form
|
// Auto-link as duplicate if requested from create form
|
||||||
$linkDupOfRaw = trim($_POST['link_duplicate_of'] ?? '');
|
$linkDupOfRaw = trim($_POST['link_duplicate_of'] ?? '');
|
||||||
if ($linkDupOfRaw !== '' && ctype_digit($linkDupOfRaw)) {
|
if ($linkDupOfRaw !== '' && ctype_digit($linkDupOfRaw)) {
|
||||||
|
|||||||
+70
-23
@@ -42,6 +42,8 @@ try {
|
|||||||
require_once __DIR__ . '/middleware/ApiKeyAuth.php';
|
require_once __DIR__ . '/middleware/ApiKeyAuth.php';
|
||||||
require_once __DIR__ . '/models/AuditLogModel.php';
|
require_once __DIR__ . '/models/AuditLogModel.php';
|
||||||
require_once __DIR__ . '/models/StatsModel.php';
|
require_once __DIR__ . '/models/StatsModel.php';
|
||||||
|
require_once __DIR__ . '/models/TicketModel.php';
|
||||||
|
require_once __DIR__ . '/models/WorkflowModel.php';
|
||||||
require_once __DIR__ . '/helpers/UrlHelper.php';
|
require_once __DIR__ . '/helpers/UrlHelper.php';
|
||||||
|
|
||||||
$apiKeyAuth = new ApiKeyAuth($conn);
|
$apiKeyAuth = new ApiKeyAuth($conn);
|
||||||
@@ -338,17 +340,52 @@ if ($existing) {
|
|||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Ticket was closed — reopen it and add a recurrence comment
|
// Ticket was closed — reopen it and add a recurrence comment. Route
|
||||||
$reopenStmt = $conn->prepare(
|
// through the Workflow Designer like every other status-write path in
|
||||||
"UPDATE tickets SET status = 'Open', closed_at = NULL, updated_at = NOW(), updated_by = ? WHERE ticket_id = ?"
|
// the app, rather than forcing status='Open' via raw SQL regardless of
|
||||||
);
|
// configured transition rules.
|
||||||
$reopenStmt->bind_param("is", $userId, $existingId);
|
$workflowModel = new WorkflowModel($conn);
|
||||||
$reopenStmt->execute();
|
$reopenStatus = 'Open';
|
||||||
$reopenStmt->close();
|
if (!$workflowModel->isTransitionAllowed('Closed', 'Open', false)) {
|
||||||
|
// Direct Closed->Open isn't configured — fall back to any transition
|
||||||
|
// the Workflow Designer does allow from Closed that this unattended,
|
||||||
|
// non-admin automation can actually satisfy (no comment prompt, no
|
||||||
|
// admin elevation). If even that doesn't exist, leave the ticket
|
||||||
|
// Closed rather than force an unconfigured state.
|
||||||
|
$reopenStatus = null;
|
||||||
|
foreach ($workflowModel->getAllowedTransitions('Closed') as $transition) {
|
||||||
|
if (!$transition['requires_comment'] && !$transition['requires_admin']) {
|
||||||
|
$reopenStatus = $transition['to_status'];
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($reopenStatus !== null) {
|
||||||
|
$ticketModel = new TicketModel($conn);
|
||||||
|
$ticketModel->updateTicket([
|
||||||
|
'ticket_id' => $existingId,
|
||||||
|
'title' => $title,
|
||||||
|
'description' => $description,
|
||||||
|
'category' => $category,
|
||||||
|
'type' => $type,
|
||||||
|
'status' => $reopenStatus,
|
||||||
|
'priority' => $priority,
|
||||||
|
], $userId);
|
||||||
|
} else {
|
||||||
|
error_log("create_ticket_api: hwmonDaemon recurrence for ticket $existingId — "
|
||||||
|
. "no admin-free, comment-free transition from Closed is configured; leaving ticket Closed");
|
||||||
|
}
|
||||||
|
|
||||||
$commentText = "**Issue recurred — ticket reopened automatically.**\n\n" .
|
$commentText = "**Issue recurred — ticket reopened automatically.**\n\n" .
|
||||||
"hwmonDaemon detected this condition again. The ticket description reflects the "
|
"hwmonDaemon detected this condition again. The ticket description reflects the "
|
||||||
. "original report; see this comment's timestamp for when the issue recurred.";
|
. "original report; see this comment's timestamp for when the issue recurred.";
|
||||||
|
if ($reopenStatus === null) {
|
||||||
|
$commentText = "**Issue recurred, but the ticket could not be reopened automatically.**\n\n"
|
||||||
|
. "hwmonDaemon detected this condition again. No Workflow Designer transition from "
|
||||||
|
. "Closed is configured that this automation can perform unattended (no comment/admin "
|
||||||
|
. "requirement); the ticket remains Closed. Please review and reopen manually if appropriate.";
|
||||||
|
}
|
||||||
$commentStmt = $conn->prepare(
|
$commentStmt = $conn->prepare(
|
||||||
"INSERT INTO ticket_comments (ticket_id, user_id, user_name, comment_text, markdown_enabled) VALUES (?, ?, 'hwmonDaemon', ?, 1)"
|
"INSERT INTO ticket_comments (ticket_id, user_id, user_name, comment_text, markdown_enabled) VALUES (?, ?, 'hwmonDaemon', ?, 1)"
|
||||||
);
|
);
|
||||||
@@ -356,30 +393,40 @@ if ($existing) {
|
|||||||
$commentStmt->execute();
|
$commentStmt->execute();
|
||||||
$commentStmt->close();
|
$commentStmt->close();
|
||||||
|
|
||||||
$auditLog->log($userId, 'update', 'ticket', $existingId, [
|
if ($reopenStatus !== null) {
|
||||||
'status' => ['from' => 'Closed', 'to' => 'Open'],
|
$auditLog->log($userId, 'update', 'ticket', $existingId, [
|
||||||
'reason' => 'auto-reopened by hwmonDaemon (issue recurred)',
|
'status' => ['from' => 'Closed', 'to' => $reopenStatus],
|
||||||
]);
|
'reason' => 'auto-reopened by hwmonDaemon (issue recurred)',
|
||||||
|
]);
|
||||||
|
|
||||||
// Ticket reopened (Closed → Open) — refresh dashboard stats.
|
// Ticket reopened — refresh dashboard stats.
|
||||||
(new StatsModel($conn))->invalidateCache();
|
(new StatsModel($conn))->invalidateCache();
|
||||||
|
} else {
|
||||||
|
$auditLog->log($userId, 'update', 'ticket', $existingId, [
|
||||||
|
'reason' => 'hwmonDaemon recurrence detected but no valid reopen transition configured; ticket left Closed',
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
Database::close();
|
Database::close();
|
||||||
|
|
||||||
require_once __DIR__ . '/helpers/NotificationHelper.php';
|
if ($reopenStatus !== null) {
|
||||||
NotificationHelper::sendTicketNotification($existingId, [
|
require_once __DIR__ . '/helpers/NotificationHelper.php';
|
||||||
'title' => $title,
|
NotificationHelper::sendTicketNotification($existingId, [
|
||||||
'priority' => $priority,
|
'title' => $title,
|
||||||
'category' => $category,
|
'priority' => $priority,
|
||||||
'type' => $type,
|
'category' => $category,
|
||||||
'status' => 'Open',
|
'type' => $type,
|
||||||
], 'automated');
|
'status' => $reopenStatus,
|
||||||
|
], 'automated');
|
||||||
|
}
|
||||||
|
|
||||||
echo json_encode([
|
echo json_encode([
|
||||||
'success' => true,
|
'success' => true,
|
||||||
'ticket_id' => $existingId,
|
'ticket_id' => $existingId,
|
||||||
'message' => 'Existing closed ticket reopened',
|
'message' => $reopenStatus !== null
|
||||||
'action' => 'reopened',
|
? 'Existing closed ticket reopened'
|
||||||
|
: 'Recurrence noted; ticket left Closed (no valid workflow transition configured)',
|
||||||
|
'action' => $reopenStatus !== null ? 'reopened' : 'recurrence_noted',
|
||||||
]);
|
]);
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -29,6 +29,38 @@ function logMessage($message)
|
|||||||
echo "[" . date('Y-m-d H:i:s') . "] " . $message . "\n";
|
echo "[" . date('Y-m-d H:i:s') . "] " . $message . "\n";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Record a recurring-ticket occurrence that was claimed (next_run_at already
|
||||||
|
* advanced to the next future run) but then failed to actually produce a
|
||||||
|
* ticket. That claim-then-fail ordering is deliberate — it stops a failing
|
||||||
|
* creation from re-firing and flooding duplicates on every subsequent cron
|
||||||
|
* tick — but means this specific occurrence has no other record anywhere an
|
||||||
|
* admin would normally look: no audit_log entry (nothing was created), no
|
||||||
|
* Matrix "ticket created" alert, no failure table. Without this, it's simply
|
||||||
|
* gone, silently, forever.
|
||||||
|
*/
|
||||||
|
function recordMissedOccurrence($auditLog, $recurring, $reason)
|
||||||
|
{
|
||||||
|
$auditLog->log(
|
||||||
|
$recurring['created_by'],
|
||||||
|
'error',
|
||||||
|
'recurring_ticket',
|
||||||
|
(string)$recurring['recurring_id'],
|
||||||
|
[
|
||||||
|
'reason' => $reason,
|
||||||
|
'title_template' => $recurring['title_template'],
|
||||||
|
'schedule_type' => $recurring['schedule_type'],
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
|
NotificationHelper::sendSystemAlert(
|
||||||
|
"Recurring ticket occurrence lost: schedule #{$recurring['recurring_id']} "
|
||||||
|
. "(\"{$recurring['title_template']}\") was claimed for this run but ticket "
|
||||||
|
. "creation failed, so this occurrence will not be created or retried.",
|
||||||
|
['reason' => $reason, 'recurring_id' => $recurring['recurring_id']]
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
logMessage("Starting recurring tickets cron job");
|
logMessage("Starting recurring tickets cron job");
|
||||||
|
|
||||||
try {
|
try {
|
||||||
@@ -100,11 +132,17 @@ try {
|
|||||||
|
|
||||||
$created++;
|
$created++;
|
||||||
} else {
|
} else {
|
||||||
logMessage("ERROR: Failed to create ticket - " . ($result['error'] ?? 'Unknown error'));
|
$reason = $result['error'] ?? 'Unknown error';
|
||||||
|
logMessage("ERROR: Failed to create ticket - " . $reason);
|
||||||
|
recordMissedOccurrence($auditLog, $recurring, $reason);
|
||||||
$errors++;
|
$errors++;
|
||||||
}
|
}
|
||||||
} catch (Exception $e) {
|
} catch (Exception $e) {
|
||||||
logMessage("ERROR: Exception processing recurring ticket - " . $e->getMessage());
|
logMessage("ERROR: Exception processing recurring ticket - " . $e->getMessage());
|
||||||
|
// claimForRun() already advanced next_run_at before this point, so
|
||||||
|
// this occurrence is permanently gone unless recorded somewhere an
|
||||||
|
// admin would actually look — a cron log line alone doesn't count.
|
||||||
|
recordMissedOccurrence($auditLog, $recurring, $e->getMessage());
|
||||||
$errors++;
|
$errors++;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,6 +20,12 @@ class NotificationHelper
|
|||||||
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($payload));
|
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($payload));
|
||||||
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
|
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
|
||||||
curl_setopt($ch, CURLOPT_TIMEOUT, 10);
|
curl_setopt($ch, CURLOPT_TIMEOUT, 10);
|
||||||
|
// A slow-but-not-fully-hung hookshot endpoint could otherwise add up
|
||||||
|
// to the full CURLOPT_TIMEOUT per fire() call, and a single request
|
||||||
|
// can call fire() (via notifyWatchers/sendCommentNotification/etc.)
|
||||||
|
// more than once sequentially — capping just the connect phase keeps
|
||||||
|
// that from stacking into tens of seconds of added latency.
|
||||||
|
curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 3);
|
||||||
|
|
||||||
$response = curl_exec($ch);
|
$response = curl_exec($ch);
|
||||||
$httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
|
$httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
|
||||||
@@ -53,6 +59,23 @@ class NotificationHelper
|
|||||||
|
|
||||||
// ─── Public event methods ─────────────────────────────────────────────────
|
// ─── Public event methods ─────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Generic operational alert with no associated ticket (e.g. a recurring
|
||||||
|
* schedule whose ticket creation failed after its next_run_at was
|
||||||
|
* already advanced, so the missed occurrence has no other record an
|
||||||
|
* admin would normally see). Always sent to the shared
|
||||||
|
* MATRIX_NOTIFY_USERS list, regardless of any per-event notify toggle.
|
||||||
|
*/
|
||||||
|
public static function sendSystemAlert(string $message, array $context = []): void
|
||||||
|
{
|
||||||
|
self::fire(array_merge([
|
||||||
|
'event' => 'system_alert',
|
||||||
|
'message' => $message,
|
||||||
|
], $context, [
|
||||||
|
'notify_users' => self::notifyUsers(),
|
||||||
|
]));
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* New ticket created (manual or automated/API).
|
* New ticket created (manual or automated/API).
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -3,21 +3,34 @@
|
|||||||
/**
|
/**
|
||||||
* Rate Limiting Middleware
|
* Rate Limiting Middleware
|
||||||
*
|
*
|
||||||
* Implements both session-based and IP-based rate limiting to prevent abuse.
|
* Implements session-based, IP-based, and (for Bearer-authenticated
|
||||||
* IP-based limiting prevents attackers from bypassing limits by creating new sessions.
|
* requests) API-key-based rate limiting to prevent abuse.
|
||||||
|
* IP-based limiting prevents attackers from bypassing limits by creating new
|
||||||
|
* sessions; API-key-based limiting keeps distinct Bearer clients from
|
||||||
|
* starving each other's shared IP bucket.
|
||||||
*/
|
*/
|
||||||
class RateLimitMiddleware
|
class RateLimitMiddleware
|
||||||
{
|
{
|
||||||
// Default limits
|
// Fallback limits, used only if $GLOBALS['config'] isn't populated
|
||||||
|
// (e.g. very early in bootstrap, or a test harness). Normal requests read
|
||||||
|
// RATE_LIMIT_DEFAULT/RATE_LIMIT_API from config (backed by .env).
|
||||||
public const DEFAULT_LIMIT = 100; // requests per window (session)
|
public const DEFAULT_LIMIT = 100; // requests per window (session)
|
||||||
public const API_LIMIT = 60; // API requests per window (session)
|
public const API_LIMIT = 60; // API requests per window (session)
|
||||||
public const IP_LIMIT = 300; // IP-based requests per window (more generous)
|
public const IP_LIMIT = 300; // IP-based requests per window (more generous)
|
||||||
public const IP_API_LIMIT = 120; // IP-based API requests per window
|
public const IP_API_LIMIT = 120; // IP-based API requests per window
|
||||||
|
public const API_KEY_LIMIT = 120; // Per-Bearer-token requests per window
|
||||||
public const WINDOW_SECONDS = 60; // 1 minute window
|
public const WINDOW_SECONDS = 60; // 1 minute window
|
||||||
|
|
||||||
// Directory for IP rate limit storage
|
// Directory for IP rate limit storage
|
||||||
private static ?string $rateLimitDir = null;
|
private static ?string $rateLimitDir = null;
|
||||||
|
|
||||||
|
private static function sessionLimit(string $type): int
|
||||||
|
{
|
||||||
|
$configKey = $type === 'api' ? 'RATE_LIMIT_API' : 'RATE_LIMIT_DEFAULT';
|
||||||
|
$fallback = $type === 'api' ? self::API_LIMIT : self::DEFAULT_LIMIT;
|
||||||
|
return (int)($GLOBALS['config'][$configKey] ?? $fallback);
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get the rate limit storage directory
|
* Get the rate limit storage directory
|
||||||
*
|
*
|
||||||
@@ -69,24 +82,47 @@ class RateLimitMiddleware
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Check IP-based rate limit
|
* Extract the raw Bearer token from the Authorization header, if present.
|
||||||
|
* Deliberately independent of ApiKeyAuth: rate limiting must be cheap and
|
||||||
|
* must not require a DB round-trip to validate the key before counting
|
||||||
|
* the request, and needs to run whether or not the token turns out to be
|
||||||
|
* valid. The raw token string (not the validated api_key_id) is hashed as
|
||||||
|
* the bucket identifier — good enough to isolate distinct keys/clients
|
||||||
|
* from each other without needing to authenticate first.
|
||||||
*
|
*
|
||||||
* @param string $type 'default' or 'api'
|
* @return string|null
|
||||||
* @return bool True if request is allowed, false if rate limited
|
|
||||||
*/
|
*/
|
||||||
private static function checkIpRateLimit(string $type = 'default'): bool
|
private static function getBearerToken(): ?string
|
||||||
{
|
{
|
||||||
$ip = self::getClientIp();
|
$header = $_SERVER['HTTP_AUTHORIZATION']
|
||||||
$limit = $type === 'api' ? self::IP_API_LIMIT : self::IP_LIMIT;
|
?? $_SERVER['REDIRECT_HTTP_AUTHORIZATION']
|
||||||
$now = time();
|
?? null;
|
||||||
|
if ($header === null && function_exists('getallheaders')) {
|
||||||
|
$headers = getallheaders();
|
||||||
|
$header = $headers['Authorization'] ?? null;
|
||||||
|
}
|
||||||
|
if ($header && preg_match('/^Bearer\s+(.+)$/i', $header, $m)) {
|
||||||
|
return $m[1];
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
// Create a hash of the IP for the filename (security + filesystem safety)
|
/**
|
||||||
$ipHash = hash('sha256', $ip . '_' . $type);
|
* Generic file-based sliding-window counter, shared by the IP-based and
|
||||||
$filePath = self::getRateLimitDir() . '/' . $ipHash . '.json';
|
* API-key-based buckets below.
|
||||||
|
*
|
||||||
|
* @param string $bucketKey Stable identifier for this bucket (already hashed)
|
||||||
|
* @param int $limit Max requests allowed per window
|
||||||
|
* @return bool True if this request is within the limit
|
||||||
|
*/
|
||||||
|
private static function checkCounter(string $bucketKey, int $limit): bool
|
||||||
|
{
|
||||||
|
$now = time();
|
||||||
|
$filePath = self::getRateLimitDir() . '/' . $bucketKey . '.json';
|
||||||
|
|
||||||
// Hold an exclusive lock across the whole read-modify-write so concurrent
|
// Hold an exclusive lock across the whole read-modify-write so concurrent
|
||||||
// requests from the same IP can't both read the same count and each write
|
// requests from the same bucket can't both read the same count and each
|
||||||
// count+1 (which would undercount and let the limit be exceeded).
|
// write count+1 (which would undercount and let the limit be exceeded).
|
||||||
$fh = @fopen($filePath, 'c+');
|
$fh = @fopen($filePath, 'c+');
|
||||||
if ($fh === false) {
|
if ($fh === false) {
|
||||||
// Can't open the counter file — fail open (don't block legitimate traffic).
|
// Can't open the counter file — fail open (don't block legitimate traffic).
|
||||||
@@ -122,10 +158,60 @@ class RateLimitMiddleware
|
|||||||
flock($fh, LOCK_UN);
|
flock($fh, LOCK_UN);
|
||||||
fclose($fh);
|
fclose($fh);
|
||||||
|
|
||||||
// Check if over limit
|
|
||||||
return $rateData['count'] <= $limit;
|
return $rateData['count'] <= $limit;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Read (without incrementing) the current state of a counter bucket, for
|
||||||
|
* status/header reporting.
|
||||||
|
*/
|
||||||
|
private static function peekCounter(string $bucketKey, int $limit): array
|
||||||
|
{
|
||||||
|
$now = time();
|
||||||
|
$filePath = self::getRateLimitDir() . '/' . $bucketKey . '.json';
|
||||||
|
|
||||||
|
$rateData = null;
|
||||||
|
$content = @file_get_contents($filePath);
|
||||||
|
if ($content !== false && $content !== '') {
|
||||||
|
$decoded = json_decode($content, true);
|
||||||
|
if (is_array($decoded)) {
|
||||||
|
$rateData = $decoded;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($rateData === null || $now - ($rateData['window_start'] ?? $now) >= self::WINDOW_SECONDS) {
|
||||||
|
return ['limit' => $limit, 'remaining' => $limit, 'reset' => $now + self::WINDOW_SECONDS];
|
||||||
|
}
|
||||||
|
|
||||||
|
return [
|
||||||
|
'limit' => $limit,
|
||||||
|
'remaining' => max(0, $limit - $rateData['count']),
|
||||||
|
'reset' => $rateData['window_start'] + self::WINDOW_SECONDS,
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
private static function ipBucketKey(string $type): string
|
||||||
|
{
|
||||||
|
return hash('sha256', self::getClientIp() . '_' . $type);
|
||||||
|
}
|
||||||
|
|
||||||
|
private static function apiKeyBucketKey(string $token): string
|
||||||
|
{
|
||||||
|
return hash('sha256', 'apikey_' . $token);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check IP-based rate limit
|
||||||
|
*
|
||||||
|
* @param string $type 'default' or 'api'
|
||||||
|
* @return bool True if request is allowed, false if rate limited
|
||||||
|
*/
|
||||||
|
private static function checkIpRateLimit(string $type = 'default'): bool
|
||||||
|
{
|
||||||
|
$limit = $type === 'api' ? self::IP_API_LIMIT : self::IP_LIMIT;
|
||||||
|
return self::checkCounter(self::ipBucketKey($type), $limit);
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Clean up old rate limit files (call periodically)
|
* Clean up old rate limit files (call periodically)
|
||||||
*
|
*
|
||||||
@@ -185,7 +271,14 @@ class RateLimitMiddleware
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Check rate limit for current request (both session and IP)
|
* Check rate limit for current request.
|
||||||
|
*
|
||||||
|
* Bearer-authenticated requests (Authorization: Bearer ...) are limited
|
||||||
|
* by a per-token bucket instead of a session — a stateless API client
|
||||||
|
* never sends a session cookie back, so the session-based counter never
|
||||||
|
* accumulates and starting a session for it is pure overhead. The
|
||||||
|
* IP-based bucket still applies underneath as defense-in-depth against
|
||||||
|
* volumetric abuse from one network path.
|
||||||
*
|
*
|
||||||
* @param string $type 'default' or 'api'
|
* @param string $type 'default' or 'api'
|
||||||
* @return bool True if request is allowed, false if rate limited
|
* @return bool True if request is allowed, false if rate limited
|
||||||
@@ -197,12 +290,17 @@ class RateLimitMiddleware
|
|||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
$token = self::getBearerToken();
|
||||||
|
if ($token !== null) {
|
||||||
|
return self::checkCounter(self::apiKeyBucketKey($token), self::API_KEY_LIMIT);
|
||||||
|
}
|
||||||
|
|
||||||
// Then check session-based rate limit
|
// Then check session-based rate limit
|
||||||
if (session_status() === PHP_SESSION_NONE) {
|
if (session_status() === PHP_SESSION_NONE) {
|
||||||
session_start();
|
session_start();
|
||||||
}
|
}
|
||||||
|
|
||||||
$limit = $type === 'api' ? self::API_LIMIT : self::DEFAULT_LIMIT;
|
$limit = self::sessionLimit($type);
|
||||||
$key = 'rate_limit_' . $type;
|
$key = 'rate_limit_' . $type;
|
||||||
$now = time();
|
$now = time();
|
||||||
|
|
||||||
@@ -270,18 +368,28 @@ class RateLimitMiddleware
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get current rate limit status
|
* Get current rate limit status.
|
||||||
|
*
|
||||||
|
* For a Bearer-authenticated request, reports the per-API-key bucket
|
||||||
|
* (the one that actually governs it) rather than the session-based
|
||||||
|
* counter, which is meaningless for a client that never sends a session
|
||||||
|
* cookie back.
|
||||||
*
|
*
|
||||||
* @param string $type 'default' or 'api'
|
* @param string $type 'default' or 'api'
|
||||||
* @return array Rate limit status
|
* @return array Rate limit status
|
||||||
*/
|
*/
|
||||||
public static function getStatus(string $type = 'default'): array
|
public static function getStatus(string $type = 'default'): array
|
||||||
{
|
{
|
||||||
|
$token = self::getBearerToken();
|
||||||
|
if ($token !== null) {
|
||||||
|
return self::peekCounter(self::apiKeyBucketKey($token), self::API_KEY_LIMIT);
|
||||||
|
}
|
||||||
|
|
||||||
if (session_status() === PHP_SESSION_NONE) {
|
if (session_status() === PHP_SESSION_NONE) {
|
||||||
session_start();
|
session_start();
|
||||||
}
|
}
|
||||||
|
|
||||||
$limit = $type === 'api' ? self::API_LIMIT : self::DEFAULT_LIMIT;
|
$limit = self::sessionLimit($type);
|
||||||
$key = 'rate_limit_' . $type;
|
$key = 'rate_limit_' . $type;
|
||||||
$now = time();
|
$now = time();
|
||||||
|
|
||||||
|
|||||||
@@ -125,13 +125,23 @@ class BulkOperationsModel
|
|||||||
$processed = 0;
|
$processed = 0;
|
||||||
$failed = 0;
|
$failed = 0;
|
||||||
$errors = [];
|
$errors = [];
|
||||||
|
// Status-change notifications collected during the loop below and
|
||||||
|
// sent only after a successful commit, matching how the single-ticket
|
||||||
|
// and Bearer API paths never notify for a change that didn't durably
|
||||||
|
// land (and how an atomic-mode rollback must not fire any at all).
|
||||||
|
$notificationQueue = [];
|
||||||
|
|
||||||
// Load required models
|
// Load required models
|
||||||
require_once dirname(__DIR__) . '/models/TicketModel.php';
|
require_once dirname(__DIR__) . '/models/TicketModel.php';
|
||||||
require_once dirname(__DIR__) . '/models/AuditLogModel.php';
|
require_once dirname(__DIR__) . '/models/AuditLogModel.php';
|
||||||
|
require_once dirname(__DIR__) . '/models/UserModel.php';
|
||||||
|
require_once dirname(__DIR__) . '/helpers/NotificationHelper.php';
|
||||||
|
|
||||||
$ticketModel = new TicketModel($this->conn);
|
$ticketModel = new TicketModel($this->conn);
|
||||||
$auditLogModel = new AuditLogModel($this->conn);
|
$auditLogModel = new AuditLogModel($this->conn);
|
||||||
|
$userModel = new UserModel($this->conn);
|
||||||
|
$actor = $operation['performed_by'] ? $userModel->getUserById((int)$operation['performed_by']) : null;
|
||||||
|
$changedByDisplay = $actor['display_name'] ?? $actor['username'] ?? null;
|
||||||
|
|
||||||
// Batch load all tickets in one query to eliminate N+1 problem
|
// Batch load all tickets in one query to eliminate N+1 problem
|
||||||
$ticketsById = $ticketModel->getTicketsByIds($ticketIds);
|
$ticketsById = $ticketModel->getTicketsByIds($ticketIds);
|
||||||
@@ -221,8 +231,18 @@ class BulkOperationsModel
|
|||||||
'update',
|
'update',
|
||||||
'ticket',
|
'ticket',
|
||||||
$ticketId,
|
$ticketId,
|
||||||
['status' => 'Closed', 'bulk_operation_id' => $operationId]
|
[
|
||||||
|
'status' => ['from' => $currentTicket['status'], 'to' => 'Closed'],
|
||||||
|
'bulk_operation_id' => $operationId,
|
||||||
|
]
|
||||||
);
|
);
|
||||||
|
$notificationQueue[] = [
|
||||||
|
'ticketId' => $ticketId,
|
||||||
|
'title' => $currentTicket['title'],
|
||||||
|
'visibility' => $currentTicket['visibility'] ?? 'public',
|
||||||
|
'oldStatus' => $currentTicket['status'],
|
||||||
|
'newStatus' => 'Closed',
|
||||||
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
@@ -291,8 +311,18 @@ class BulkOperationsModel
|
|||||||
'update',
|
'update',
|
||||||
'ticket',
|
'ticket',
|
||||||
$ticketId,
|
$ticketId,
|
||||||
['status' => $parameters['status'], 'bulk_operation_id' => $operationId]
|
[
|
||||||
|
'status' => ['from' => $currentTicket['status'], 'to' => $parameters['status']],
|
||||||
|
'bulk_operation_id' => $operationId,
|
||||||
|
]
|
||||||
);
|
);
|
||||||
|
$notificationQueue[] = [
|
||||||
|
'ticketId' => $ticketId,
|
||||||
|
'title' => $currentTicket['title'],
|
||||||
|
'visibility' => $currentTicket['visibility'] ?? 'public',
|
||||||
|
'oldStatus' => $currentTicket['status'],
|
||||||
|
'newStatus' => $parameters['status'],
|
||||||
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -364,6 +394,35 @@ class BulkOperationsModel
|
|||||||
@unlink($path);
|
@unlink($path);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Fire the same Matrix/watcher notifications the single-ticket and
|
||||||
|
// Bearer API status-change paths send, now that every change in
|
||||||
|
// this batch is durably committed. Best-effort: a notification
|
||||||
|
// failure must never turn an otherwise-successful bulk operation
|
||||||
|
// into an error.
|
||||||
|
foreach ($notificationQueue as $n) {
|
||||||
|
try {
|
||||||
|
NotificationHelper::sendStatusChangeNotification(
|
||||||
|
$n['ticketId'],
|
||||||
|
$n['oldStatus'],
|
||||||
|
$n['newStatus'],
|
||||||
|
$n['title'],
|
||||||
|
$changedByDisplay,
|
||||||
|
$n['visibility']
|
||||||
|
);
|
||||||
|
NotificationHelper::notifyWatchers(
|
||||||
|
$this->conn,
|
||||||
|
$n['ticketId'],
|
||||||
|
$n['title'],
|
||||||
|
'status_changed',
|
||||||
|
['old_status' => $n['oldStatus'], 'new_status' => $n['newStatus'], 'changed_by' => $changedByDisplay],
|
||||||
|
(int)$operation['performed_by'],
|
||||||
|
$n['visibility']
|
||||||
|
);
|
||||||
|
} catch (Throwable $e) {
|
||||||
|
error_log("Bulk operation $operationId: notification failed for ticket {$n['ticketId']}: " . $e->getMessage());
|
||||||
|
}
|
||||||
|
}
|
||||||
} catch (Exception $e) {
|
} catch (Exception $e) {
|
||||||
// Rollback on any unexpected error
|
// Rollback on any unexpected error
|
||||||
$this->conn->rollback();
|
$this->conn->rollback();
|
||||||
|
|||||||
@@ -8,6 +8,9 @@ class CustomFieldModel
|
|||||||
{
|
{
|
||||||
private $conn;
|
private $conn;
|
||||||
|
|
||||||
|
// Must match custom_field_definitions.field_type's enum() in the schema.
|
||||||
|
private const ALLOWED_FIELD_TYPES = ['text', 'textarea', 'select', 'checkbox', 'date', 'number'];
|
||||||
|
|
||||||
public function __construct($conn)
|
public function __construct($conn)
|
||||||
{
|
{
|
||||||
$this->conn = $conn;
|
$this->conn = $conn;
|
||||||
@@ -87,6 +90,10 @@ class CustomFieldModel
|
|||||||
*/
|
*/
|
||||||
public function createDefinition($data)
|
public function createDefinition($data)
|
||||||
{
|
{
|
||||||
|
if (!in_array($data['field_type'] ?? '', self::ALLOWED_FIELD_TYPES, true)) {
|
||||||
|
return ['success' => false, 'error' => 'Invalid field_type'];
|
||||||
|
}
|
||||||
|
|
||||||
$options = null;
|
$options = null;
|
||||||
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
||||||
$options = json_encode($data['field_options']);
|
$options = json_encode($data['field_options']);
|
||||||
@@ -129,6 +136,10 @@ class CustomFieldModel
|
|||||||
*/
|
*/
|
||||||
public function updateDefinition($fieldId, $data)
|
public function updateDefinition($fieldId, $data)
|
||||||
{
|
{
|
||||||
|
if (!in_array($data['field_type'] ?? '', self::ALLOWED_FIELD_TYPES, true)) {
|
||||||
|
return ['success' => false, 'error' => 'Invalid field_type'];
|
||||||
|
}
|
||||||
|
|
||||||
$options = null;
|
$options = null;
|
||||||
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
if (isset($data['field_options']) && !empty($data['field_options'])) {
|
||||||
$options = json_encode($data['field_options']);
|
$options = json_encode($data['field_options']);
|
||||||
|
|||||||
@@ -773,9 +773,68 @@ class TicketModel
|
|||||||
$stmt->bind_param("ssis", $visibility, $visibilityGroups, $updatedBy, $ticketId);
|
$stmt->bind_param("ssis", $visibility, $visibilityGroups, $updatedBy, $ticketId);
|
||||||
$result = $stmt->execute();
|
$result = $stmt->execute();
|
||||||
$stmt->close();
|
$stmt->close();
|
||||||
|
|
||||||
|
if ($result) {
|
||||||
|
$this->pruneWatchersForVisibility($ticketId, $visibility, $visibilityGroups);
|
||||||
|
}
|
||||||
|
|
||||||
return $result;
|
return $result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Remove any watchers who no longer qualify for a ticket's access rules
|
||||||
|
* after its visibility was tightened. Without this, a user watching a
|
||||||
|
* ticket that's later made confidential/internal (and who isn't
|
||||||
|
* creator/assignee/admin/in the new visibility_groups) keeps receiving
|
||||||
|
* Matrix notifications about a ticket canUserAccessTicket() would now
|
||||||
|
* reject them from opening directly.
|
||||||
|
*/
|
||||||
|
private function pruneWatchersForVisibility(string $ticketId, string $visibility, ?string $visibilityGroups): void
|
||||||
|
{
|
||||||
|
$ticket = $this->getTicketById($ticketId);
|
||||||
|
if (!$ticket) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
// getTicketById() reflects the just-committed UPDATE, but set these
|
||||||
|
// explicitly so pruning is correct even if a caller reorders things.
|
||||||
|
$ticket['visibility'] = $visibility;
|
||||||
|
$ticket['visibility_groups'] = $visibilityGroups;
|
||||||
|
|
||||||
|
$sql = "SELECT tw.user_id, u.is_admin, u.`groups`
|
||||||
|
FROM ticket_watchers tw
|
||||||
|
JOIN users u ON tw.user_id = u.user_id
|
||||||
|
WHERE tw.ticket_id = ?";
|
||||||
|
$stmt = $this->conn->prepare($sql);
|
||||||
|
$stmt->bind_param('s', $ticketId);
|
||||||
|
$stmt->execute();
|
||||||
|
$watchers = $stmt->get_result()->fetch_all(MYSQLI_ASSOC);
|
||||||
|
$stmt->close();
|
||||||
|
|
||||||
|
$toRemove = [];
|
||||||
|
foreach ($watchers as $watcher) {
|
||||||
|
$watcherUser = [
|
||||||
|
'user_id' => $watcher['user_id'],
|
||||||
|
'is_admin' => $watcher['is_admin'],
|
||||||
|
'groups' => $watcher['groups'],
|
||||||
|
];
|
||||||
|
if (!$this->canUserAccessTicket($ticket, $watcherUser)) {
|
||||||
|
$toRemove[] = $watcher['user_id'];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (empty($toRemove)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$placeholders = implode(',', array_fill(0, count($toRemove), '?'));
|
||||||
|
$delSql = "DELETE FROM ticket_watchers WHERE ticket_id = ? AND user_id IN ($placeholders)";
|
||||||
|
$delStmt = $this->conn->prepare($delSql);
|
||||||
|
$types = 's' . str_repeat('i', count($toRemove));
|
||||||
|
$delStmt->bind_param($types, $ticketId, ...$toRemove);
|
||||||
|
$delStmt->execute();
|
||||||
|
$delStmt->close();
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Delete a ticket and all its associated records.
|
* Delete a ticket and all its associated records.
|
||||||
* Admin-only operation. Removes comments, attachments, watchers, dependencies.
|
* Admin-only operation. Removes comments, attachments, watchers, dependencies.
|
||||||
|
|||||||
@@ -31,9 +31,15 @@ class WorkflowModel
|
|||||||
return $cached;
|
return $cached;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ORDER BY makes which row wins deterministic (most recently created,
|
||||||
|
// by transition_id) in the pathological case where two active rows
|
||||||
|
// exist for the same (from_status, to_status) pair — manage_workflows.php
|
||||||
|
// now rejects creating that duplicate going forward, but this is a
|
||||||
|
// defense-in-depth backstop against any duplicate already in the DB.
|
||||||
$sql = "SELECT from_status, to_status, requires_comment, requires_admin
|
$sql = "SELECT from_status, to_status, requires_comment, requires_admin
|
||||||
FROM status_transitions
|
FROM status_transitions
|
||||||
WHERE is_active = TRUE";
|
WHERE is_active = TRUE
|
||||||
|
ORDER BY transition_id ASC";
|
||||||
$result = $this->conn->query($sql);
|
$result = $this->conn->query($sql);
|
||||||
|
|
||||||
if (!$result) {
|
if (!$result) {
|
||||||
|
|||||||
@@ -124,7 +124,7 @@ include __DIR__ . '/layout_header.php';
|
|||||||
|
|
||||||
<div class="lt-form-group">
|
<div class="lt-form-group">
|
||||||
<label class="lt-label" for="category">Category</label>
|
<label class="lt-label" for="category">Category</label>
|
||||||
<select id="category" name="category" class="lt-select">
|
<select id="category" name="category" class="lt-select" data-action="toggle-custom-fields">
|
||||||
<option value="Hardware">Hardware</option>
|
<option value="Hardware">Hardware</option>
|
||||||
<option value="Software">Software</option>
|
<option value="Software">Software</option>
|
||||||
<option value="Network">Network</option>
|
<option value="Network">Network</option>
|
||||||
@@ -211,6 +211,55 @@ include __DIR__ . '/layout_header.php';
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<?php if (!empty($allCustomFieldDefs)) : ?>
|
||||||
|
<!-- ── SECTION 5b: Custom Fields ─────────────────────────── -->
|
||||||
|
<div class="lt-frame lt-mb-md">
|
||||||
|
<span class="lt-frame-bl">╚</span><span class="lt-frame-br">╝</span>
|
||||||
|
<div class="lt-section-header">Additional Fields</div>
|
||||||
|
<div class="lt-section-body">
|
||||||
|
<?php foreach ($allCustomFieldDefs as $cfDef) : ?>
|
||||||
|
<div class="lt-form-group custom-field-group"
|
||||||
|
data-custom-field-category="<?= htmlspecialchars($cfDef['category'] ?? '', ENT_QUOTES, 'UTF-8') ?>">
|
||||||
|
<?php
|
||||||
|
$cfName = 'custom_fields[' . (int)$cfDef['field_id'] . ']';
|
||||||
|
$cfId = 'custom_field_' . (int)$cfDef['field_id'];
|
||||||
|
?>
|
||||||
|
<label class="lt-label" for="<?= $cfId ?>">
|
||||||
|
<?= htmlspecialchars($cfDef['field_label'], ENT_QUOTES, 'UTF-8') ?><?= $cfDef['is_required'] ? ' *' : '' ?>
|
||||||
|
</label>
|
||||||
|
<?php if ($cfDef['field_type'] === 'textarea') : ?>
|
||||||
|
<textarea id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input lt-textarea" rows="3"
|
||||||
|
<?= $cfDef['is_required'] ? 'data-custom-field-required="1"' : '' ?>></textarea>
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'select') : ?>
|
||||||
|
<select id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-select"
|
||||||
|
<?= $cfDef['is_required'] ? 'data-custom-field-required="1"' : '' ?>>
|
||||||
|
<option value="">— Select —</option>
|
||||||
|
<?php foreach (($cfDef['field_options']['options'] ?? []) as $opt) : ?>
|
||||||
|
<option value="<?= htmlspecialchars($opt, ENT_QUOTES, 'UTF-8') ?>"><?= htmlspecialchars($opt, ENT_QUOTES, 'UTF-8') ?></option>
|
||||||
|
<?php endforeach ?>
|
||||||
|
</select>
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'checkbox') : ?>
|
||||||
|
<label class="lt-filter-option">
|
||||||
|
<input type="checkbox" class="lt-checkbox" id="<?= $cfId ?>" name="<?= $cfName ?>" value="1">
|
||||||
|
<?= htmlspecialchars($cfDef['field_label'], ENT_QUOTES, 'UTF-8') ?>
|
||||||
|
</label>
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'date') : ?>
|
||||||
|
<input type="date" id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input"
|
||||||
|
<?= $cfDef['is_required'] ? 'data-custom-field-required="1"' : '' ?>>
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'number') : ?>
|
||||||
|
<input type="number" id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input"
|
||||||
|
<?= $cfDef['is_required'] ? 'data-custom-field-required="1"' : '' ?>>
|
||||||
|
<?php else : ?>
|
||||||
|
<input type="text" id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input"
|
||||||
|
<?= $cfDef['is_required'] ? 'data-custom-field-required="1"' : '' ?>>
|
||||||
|
<?php endif ?>
|
||||||
|
</div>
|
||||||
|
<?php endforeach ?>
|
||||||
|
<p class="lt-form-hint">Fields shown depend on the selected Category.</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<?php endif ?>
|
||||||
|
|
||||||
<!-- ── SECTION 6: Description ───────────────────────────── -->
|
<!-- ── SECTION 6: Description ───────────────────────────── -->
|
||||||
<div class="lt-frame lt-mb-md">
|
<div class="lt-frame lt-mb-md">
|
||||||
<span class="lt-frame-bl">╚</span><span class="lt-frame-br">╝</span>
|
<span class="lt-frame-bl">╚</span><span class="lt-frame-br">╝</span>
|
||||||
@@ -316,6 +365,15 @@ include __DIR__ . '/layout_header.php';
|
|||||||
.catch(function () { /* silent — duplicate check is non-critical */ });
|
.catch(function () { /* silent — duplicate check is non-critical */ });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── Custom fields: show only the selected category's fields ──
|
||||||
|
function toggleCustomFields() {
|
||||||
|
var category = document.getElementById('category').value;
|
||||||
|
document.querySelectorAll('.custom-field-group').forEach(function (group) {
|
||||||
|
var fieldCategory = group.getAttribute('data-custom-field-category');
|
||||||
|
group.classList.toggle('is-hidden', fieldCategory !== '' && fieldCategory !== category);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// ── Visibility groups toggle ──────────────────────────────
|
// ── Visibility groups toggle ──────────────────────────────
|
||||||
var visibilityHints = {
|
var visibilityHints = {
|
||||||
'public': 'Everyone who is logged in can view this ticket.',
|
'public': 'Everyone who is logged in can view this ticket.',
|
||||||
@@ -387,9 +445,11 @@ include __DIR__ . '/layout_header.php';
|
|||||||
switch (target.getAttribute('data-action')) {
|
switch (target.getAttribute('data-action')) {
|
||||||
case 'load-template': loadTemplate(); break;
|
case 'load-template': loadTemplate(); break;
|
||||||
case 'toggle-visibility-groups': toggleVisibilityGroups(); break;
|
case 'toggle-visibility-groups': toggleVisibilityGroups(); break;
|
||||||
|
case 'toggle-custom-fields': toggleCustomFields(); break;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
toggleCustomFields();
|
||||||
if (window.lt) lt.keys.initDefaults();
|
if (window.lt) lt.keys.initDefaults();
|
||||||
}());
|
}());
|
||||||
</script>
|
</script>
|
||||||
|
|||||||
@@ -397,6 +397,12 @@ document.addEventListener('DOMContentLoaded', function() {
|
|||||||
role="tab" data-tab="dependencies-panel" aria-selected="false" aria-controls="dependencies-panel">
|
role="tab" data-tab="dependencies-panel" aria-selected="false" aria-controls="dependencies-panel">
|
||||||
Dependencies
|
Dependencies
|
||||||
</button>
|
</button>
|
||||||
|
<?php if (!empty($customFieldDefs)) : ?>
|
||||||
|
<button type="button" class="lt-tab" id="custom-fields-tab-btn"
|
||||||
|
role="tab" data-tab="custom-fields-panel" aria-selected="false" aria-controls="custom-fields-panel">
|
||||||
|
Custom Fields
|
||||||
|
</button>
|
||||||
|
<?php endif ?>
|
||||||
<button type="button" class="lt-tab" id="activity-tab-btn"
|
<button type="button" class="lt-tab" id="activity-tab-btn"
|
||||||
role="tab" data-tab="activity-panel" aria-selected="false" aria-controls="activity-panel">
|
role="tab" data-tab="activity-panel" aria-selected="false" aria-controls="activity-panel">
|
||||||
Activity
|
Activity
|
||||||
@@ -682,6 +688,60 @@ document.addEventListener('DOMContentLoaded', function() {
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<?php if (!empty($customFieldDefs)) : ?>
|
||||||
|
<!-- ═══════════════════════════════════════════════════════════
|
||||||
|
TAB PANEL: CUSTOM FIELDS
|
||||||
|
═══════════════════════════════════════════════════════════ -->
|
||||||
|
<div id="custom-fields-panel" class="lt-tab-panel" role="tabpanel" aria-labelledby="custom-fields-tab-btn">
|
||||||
|
<div class="lt-frame">
|
||||||
|
<span class="lt-frame-bl">╚</span><span class="lt-frame-br">╝</span>
|
||||||
|
<div class="lt-section-header">Custom Fields</div>
|
||||||
|
<div class="lt-section-body">
|
||||||
|
<div id="customFieldsMsg" class="lt-msg is-hidden lt-mb-md" role="alert" aria-live="polite"></div>
|
||||||
|
<?php foreach ($customFieldDefs as $cfDef) :
|
||||||
|
$cfValue = $customFieldValues[$cfDef['field_name']]['field_value'] ?? '';
|
||||||
|
$cfName = 'custom_fields[' . (int)$cfDef['field_id'] . ']';
|
||||||
|
$cfId = 'ticket_custom_field_' . (int)$cfDef['field_id'];
|
||||||
|
?>
|
||||||
|
<div class="lt-form-group">
|
||||||
|
<label class="lt-label" for="<?= $cfId ?>">
|
||||||
|
<?= htmlspecialchars($cfDef['field_label'], ENT_QUOTES, 'UTF-8') ?><?= $cfDef['is_required'] ? ' *' : '' ?>
|
||||||
|
</label>
|
||||||
|
<?php if ($cfDef['field_type'] === 'textarea') : ?>
|
||||||
|
<textarea id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input lt-textarea" rows="3"
|
||||||
|
><?= htmlspecialchars($cfValue, ENT_QUOTES, 'UTF-8') ?></textarea>
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'select') : ?>
|
||||||
|
<select id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-select">
|
||||||
|
<option value="">— Select —</option>
|
||||||
|
<?php foreach (($cfDef['field_options']['options'] ?? []) as $opt) : ?>
|
||||||
|
<option value="<?= htmlspecialchars($opt, ENT_QUOTES, 'UTF-8') ?>"
|
||||||
|
<?= $opt === $cfValue ? 'selected' : '' ?>><?= htmlspecialchars($opt, ENT_QUOTES, 'UTF-8') ?></option>
|
||||||
|
<?php endforeach ?>
|
||||||
|
</select>
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'checkbox') : ?>
|
||||||
|
<label class="lt-filter-option">
|
||||||
|
<input type="checkbox" class="lt-checkbox" id="<?= $cfId ?>" name="<?= $cfName ?>" value="1"
|
||||||
|
<?= $cfValue === '1' ? 'checked' : '' ?>>
|
||||||
|
<?= htmlspecialchars($cfDef['field_label'], ENT_QUOTES, 'UTF-8') ?>
|
||||||
|
</label>
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'date') : ?>
|
||||||
|
<input type="date" id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input"
|
||||||
|
value="<?= htmlspecialchars($cfValue, ENT_QUOTES, 'UTF-8') ?>">
|
||||||
|
<?php elseif ($cfDef['field_type'] === 'number') : ?>
|
||||||
|
<input type="number" id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input"
|
||||||
|
value="<?= htmlspecialchars($cfValue, ENT_QUOTES, 'UTF-8') ?>">
|
||||||
|
<?php else : ?>
|
||||||
|
<input type="text" id="<?= $cfId ?>" name="<?= $cfName ?>" class="lt-input"
|
||||||
|
value="<?= htmlspecialchars($cfValue, ENT_QUOTES, 'UTF-8') ?>">
|
||||||
|
<?php endif ?>
|
||||||
|
</div>
|
||||||
|
<?php endforeach ?>
|
||||||
|
<button type="button" id="saveCustomFieldsBtn" class="lt-btn lt-btn-primary lt-btn-sm">SAVE CUSTOM FIELDS</button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<?php endif ?>
|
||||||
|
|
||||||
<!-- ═══════════════════════════════════════════════════════════
|
<!-- ═══════════════════════════════════════════════════════════
|
||||||
TAB PANEL: ACTIVITY
|
TAB PANEL: ACTIVITY
|
||||||
═══════════════════════════════════════════════════════════ -->
|
═══════════════════════════════════════════════════════════ -->
|
||||||
@@ -1013,6 +1073,46 @@ document.addEventListener('DOMContentLoaded', function () {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Save custom fields button
|
||||||
|
var saveCustomFieldsBtn = document.getElementById('saveCustomFieldsBtn');
|
||||||
|
if (saveCustomFieldsBtn) {
|
||||||
|
saveCustomFieldsBtn.addEventListener('click', function () {
|
||||||
|
var panel = document.getElementById('custom-fields-panel');
|
||||||
|
var msg = document.getElementById('customFieldsMsg');
|
||||||
|
var values = {};
|
||||||
|
panel.querySelectorAll('[name^="custom_fields["]').forEach(function (el) {
|
||||||
|
var m = el.name.match(/custom_fields\[(\d+)\]/);
|
||||||
|
if (!m) return;
|
||||||
|
var fieldId = m[1];
|
||||||
|
if (el.type === 'checkbox') {
|
||||||
|
values[fieldId] = el.checked ? '1' : '0';
|
||||||
|
} else {
|
||||||
|
values[fieldId] = el.value;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
saveCustomFieldsBtn.disabled = true;
|
||||||
|
msg.classList.add('is-hidden');
|
||||||
|
|
||||||
|
lt.api.post('/api/ticket_custom_fields.php', {
|
||||||
|
ticket_id: window.ticketData.id,
|
||||||
|
values: values
|
||||||
|
}).then(function (data) {
|
||||||
|
saveCustomFieldsBtn.disabled = false;
|
||||||
|
if (data.success) {
|
||||||
|
lt.toast.success('Custom fields saved', 3000);
|
||||||
|
} else {
|
||||||
|
msg.textContent = data.error || 'Failed to save custom fields';
|
||||||
|
msg.className = 'lt-msg lt-msg-danger lt-mb-md';
|
||||||
|
}
|
||||||
|
}).catch(function (error) {
|
||||||
|
saveCustomFieldsBtn.disabled = false;
|
||||||
|
msg.textContent = 'Failed to save custom fields: ' + error.message;
|
||||||
|
msg.className = 'lt-msg lt-msg-danger lt-mb-md';
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Settings save/cancel
|
// Settings save/cancel
|
||||||
// Load user preference toggles on settings modal open
|
// Load user preference toggles on settings modal open
|
||||||
(function() {
|
(function() {
|
||||||
|
|||||||
@@ -235,8 +235,7 @@
|
|||||||
}
|
}
|
||||||
|
|
||||||
function loadNotifications() {
|
function loadNotifications() {
|
||||||
return fetch('/api/notifications.php', { credentials: 'same-origin' })
|
return lt.api.get('/api/notifications.php')
|
||||||
.then(function(r) { return r.json(); })
|
|
||||||
.then(function(data) { renderNotifications(data); return true; })
|
.then(function(data) { renderNotifications(data); return true; })
|
||||||
.catch(function() {
|
.catch(function() {
|
||||||
list.innerHTML = '<div style="padding:0.75rem;font-size:0.75rem;color:var(--text-muted);text-align:center">Could not load</div>';
|
list.innerHTML = '<div style="padding:0.75rem;font-size:0.75rem;color:var(--text-muted);text-align:center">Could not load</div>';
|
||||||
@@ -251,11 +250,7 @@
|
|||||||
|
|
||||||
if (clearBtn) {
|
if (clearBtn) {
|
||||||
clearBtn.addEventListener('click', function() {
|
clearBtn.addEventListener('click', function() {
|
||||||
fetch('/api/notifications.php', {
|
lt.api.post('/api/notifications.php', { action: 'mark_read' }).then(loadNotifications);
|
||||||
method: 'POST', credentials: 'same-origin',
|
|
||||||
headers: { 'Content-Type': 'application/json', 'X-CSRF-Token': window.CSRF_TOKEN || '' },
|
|
||||||
body: JSON.stringify({ action: 'mark_read' })
|
|
||||||
}).then(loadNotifications);
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user