0byt3m1n1
Path:
/
data
/
applications
/
aps.bak
/
sugarcrm
/
6.5.16-25
/
standard
/
htdocs
/
modules
/
Administration
/
[
Home
]
File: Async.php
<?php if(!defined('sugarEntry') || !sugarEntry) die('Not A Valid Entry Point'); /********************************************************************************* * SugarCRM Community Edition is a customer relationship management program developed by * SugarCRM, Inc. Copyright (C) 2004-2013 SugarCRM Inc. * * This program is free software; you can redistribute it and/or modify it under * the terms of the GNU Affero General Public License version 3 as published by the * Free Software Foundation with the addition of the following permission added * to Section 15 as permitted in Section 7(a): FOR ANY PART OF THE COVERED WORK * IN WHICH THE COPYRIGHT IS OWNED BY SUGARCRM, SUGARCRM DISCLAIMS THE WARRANTY * OF NON INFRINGEMENT OF THIRD PARTY RIGHTS. * * This program is distributed in the hope that it will be useful, but WITHOUT * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS * FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more * details. * * You should have received a copy of the GNU Affero General Public License along with * this program; if not, see http://www.gnu.org/licenses or write to the Free * Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA * 02110-1301 USA. * * You can contact SugarCRM, Inc. headquarters at 10050 North Wolfe Road, * SW2-130, Cupertino, CA 95014, USA. or at email address contact@sugarcrm.com. * * The interactive user interfaces in modified source and object code versions * of this program must display Appropriate Legal Notices, as required under * Section 5 of the GNU Affero General Public License version 3. * * In accordance with Section 7(b) of the GNU Affero General Public License version 3, * these Appropriate Legal Notices must retain the display of the "Powered by * SugarCRM" logo. If the display of the logo is not reasonably feasible for * technical reasons, the Appropriate Legal Notices must display the words * "Powered by SugarCRM". ********************************************************************************/ /********************************************************************************* * Description: * Portions created by SugarCRM are Copyright (C) SugarCRM, Inc. All Rights * Reserved. Contributor(s): ______________________________________.. *********************************************************************************/ require_once("include/entryPoint.php"); if (!is_admin($GLOBALS['current_user'])) { sugar_die($GLOBALS['app_strings']['ERR_NOT_ADMIN']); } $json = getJSONObj(); $out = ""; switch($_REQUEST['adminAction']) { /////////////////////////////////////////////////////////////////////////// //// REPAIRXSS case "refreshEstimate": include("include/modules.php"); // provide $moduleList $target = ''; if (!empty($_REQUEST['bean'])) { $target = $_REQUEST['bean']; } $count = 0; $toRepair = array(); if($target == 'all') { $hide = array('Activities', 'Home', 'iFrames', 'Calendar', 'Dashboard'); sort($moduleList); $options = array(); foreach($moduleList as $module) { if(!in_array($module, $hide)) { $options[$module] = $module; } } foreach($options as $module) { if(!isset($beanFiles[$beanList[$module]])) continue; $file = $beanFiles[$beanList[$module]]; if(!file_exists($file)) continue; require_once($file); $bean = new $beanList[$module](); $q = "SELECT count(*) as count FROM {$bean->table_name}"; $r = $bean->db->query($q); $a = $bean->db->fetchByAssoc($r); $count += $a['count']; // populate to_repair array $q2 = "SELECT id FROM {$bean->table_name}"; $r2 = $bean->db->query($q2); $ids = ''; while($a2 = $bean->db->fetchByAssoc($r2)) { $ids[] = $a2['id']; } $toRepair[$module] = $ids; } } elseif(in_array($target, $moduleList)) { require_once($beanFiles[$beanList[$target]]); $bean = new $beanList[$target](); $q = "SELECT count(*) as count FROM {$bean->table_name}"; $r = $bean->db->query($q); $a = $bean->db->fetchByAssoc($r); $count += $a['count']; // populate to_repair array $q2 = "SELECT id FROM {$bean->table_name}"; $r2 = $bean->db->query($q2); $ids = ''; while($a2 = $bean->db->fetchByAssoc($r2)) { $ids[] = $a2['id']; } $toRepair[$target] = $ids; } $out = array('count' => $count, 'target' => $target, 'toRepair' => $toRepair); break; case "repairXssExecute": if(isset($_REQUEST['bean']) && !empty($_REQUEST['bean']) && isset($_REQUEST['id']) && !empty($_REQUEST['id'])) { include("include/modules.php"); // provide $moduleList $target = $_REQUEST['bean']; require_once($beanFiles[$beanList[$target]]); $ids = $json->decode(from_html($_REQUEST['id'])); $count = 0; foreach($ids as $id) { if(!empty($id)) { $bean = new $beanList[$target](); $bean->retrieve($id,true,false); $bean->new_with_id = false; $bean->save(); // cleanBean() is called on save() $count++; } } $out = array('msg' => "success", 'count' => $count); } else { $out = array('msg' => "failure: bean or ID not defined"); } break; //// END REPAIRXSS /////////////////////////////////////////////////////////////////////////// default: die(); break; } $ret = $json->encode($out, true); echo $ret;