Code

Updated system Management
[gosa.git] / gosa-plugins / systems / admin / systems / class_systemManagement.inc
index 60f407ae071a37073bbed97fa3918d47b9d05bbe..43af7119741498a082c4885cef4a66dfc60c6a33 100644 (file)
@@ -327,7 +327,7 @@ class systems extends plugin
           $this->systab->by_object[$tabname]->base = $this->DivListSystem->selectedBase;
           $this->systab->base = $this->DivListSystem->selectedBase;
         }else{
-          print_red(_("You are not allowed to create a new object of this type."));
+          msg_dialog::display(_("Error"), msgPool::permCreate(), ERROR_DIALOG);
         }
       }
     }
@@ -380,7 +380,7 @@ class systems extends plugin
         session::set('objectinfo',$this->dn);
         add_lock ($this->dn, $this->ui->dn);
       }else{ 
-        print_red (_("You can't edit this object type yet!"));
+        msg_dialog::display(_("Error"), _("Editing this type of object is not supported yet!"), ERROR_DIALOG);
         del_lock($this->dn);
       }
     }
@@ -393,22 +393,30 @@ class systems extends plugin
     /* Set terminals root password */
     if ($s_action=="change_pw"){
       $tabs = array(
-          "terminal"    => array("CLASS"=>"TERMTABS",     "TABNAME"=>"termgeneric",     "TABCLASS" =>"termtabs",      "ACL"=> "terminal"),
-          "workstation" => array("CLASS"=>"WORKTABS",     "TABNAME"=>"workgeneric",     "TABCLASS" =>"worktabs",      "ACL"=> "workstation"));
+          "ArpNewDevice"=> array("CLASS"=>"TERMTABS",     "TABCLASS" =>"termtabs",      "ACL"=> "incoming/systems"),
+          "NewDevice"   => array("CLASS"=>"TERMTABS",     "TABCLASS" =>"termtabs",      "ACL"=> "incoming/systems"),
+          "terminal"    => array("CLASS"=>"TERMTABS",     "TABCLASS" =>"termtabs",      "ACL"=> "terminal/termgeneric"),
+          "workstation" => array("CLASS"=>"WORKTABS",     "TABCLASS" =>"worktabs",      "ACL"=> "workstation/workgeneric"),
+          "server"      => array("CLASS"=>"SERVTABS",     "TABCLASS" =>"servtabs",      "ACL"=> "server/servgeneric"),
+          "printer"     => array("CLASS"=>"PRINTTABS",    "TABCLASS" =>"printtabs",     "ACL"=> "printer/printgeneric"),
+          "phone"       => array("CLASS"=>"PHONETABS",    "TABCLASS" =>"phonetabs",     "ACL"=> "phone/phoneGeneric"),
+          "winstation"  => array("CLASS"=>"WINTABS",      "TABCLASS" =>"wintabs",       "ACL"=> "winworkstation/wingeneric"),
+          "component"   => array("CLASS"=>"COMPONENTTABS","TABCLASS" =>"componenttabs", "ACL"=> "component/componentGeneric"));
 
+      $dn   = $this->terminals[$s_entry]['dn'];
       $type = $this->get_system_type($this->terminals[$s_entry]);
+
       $class    = $tabs[$type]["CLASS"];
-      $tabname  = $tabs[$type]["TABNAME"];
-      $acl_cat  = $tabs[$type]["ACL"];
+      $acl      = $tabs[$type]["ACL"];
       $tabclass = $tabs[$type]["TABCLASS"];
       $ui       = get_userinfo();
-      $tabacl   = $ui->get_permissions($this->DivListSystem->selectedBase,$acl_cat."/".$tabname,"gotoRootPasswd");
+      $tabacl   = $ui->get_permissions($dn,$acl,"userPassword");
       if(preg_match("/w/",$tabacl)){
         $this->dn= $this->terminals[$s_entry]['dn'];
         session::set('objectinfo',$this->dn);
         return ($smarty->fetch(get_template_path('password.tpl', TRUE)));
       }else{
-        print_red(_("You are not allowed to change the password for this object."));
+        msg_dialog::display(_("Permission error"), _("You have no permission to change this password!"), ERROR_DIALOG);
       }
     }
 
@@ -420,7 +428,7 @@ class systems extends plugin
     /* Correctly specified? */
     if (isset($_POST['password_finish'])){
       if ($_POST['new_password'] != $_POST['repeated_password']){
-        print_red (_("Passwords entered as new and repeated do not match!"));
+        msg_dialog::display(_("Error"), _("The passwords you've entered as 'New password' and 'Repeated password' do not match!"), ERROR_DIALOG);
         return($smarty->fetch(get_template_path('password.tpl', TRUE)));
       }
     }
@@ -435,49 +443,92 @@ class systems extends plugin
 
       /* Check if user is allowed to set password */
       $tabs = array(
-          "terminal"    => array("CLASS"=>"TERMTABS",     "TABNAME"=>"termgeneric",     "TABCLASS" =>"termtabs",      "ACL"=> "terminal"),
-          "workstation" => array("CLASS"=>"WORKTABS",     "TABNAME"=>"workgeneric",     "TABCLASS" =>"worktabs",      "ACL"=> "workstation"));
+          "terminal"    => array("CLASS"=>"TERMTABS",     "TABCLASS" =>"termtabs",      "ACL"=> "terminal/termgeneric"    ,"PLUG"=>"termgeneric"),
+          "workstation" => array("CLASS"=>"WORKTABS",     "TABCLASS" =>"worktabs",      "ACL"=> "workstation/workgeneric" ,"PLUG"=>"workgeneric"),
+          "server"      => array("CLASS"=>"SERVTABS",     "TABCLASS" =>"servtabs",      "ACL"=> "server/servgeneric"      ,"PLUG"=>"servgeneric"),
+          "component"   => array("CLASS"=>"COMPONENTTABS","TABCLASS" =>"componenttabs", "ACL"=> "component/componentGeneric","PLUG"=>"componentGeneric"));
 
       /* Detect object type */
       $type = "";
       foreach($this->terminals as $terminal){
         if($terminal['dn'] == $this->dn){
-          $type = $this->get_system_type($terminal);
+          $type  = $this->get_system_type($terminal);
           break;
         } 
       }
 
       /* Type detected */
-      if(!empty($type)){
+      $allow_for = array("terminal","workstation","server","component");
+      if(!empty($type) && in_array($type,$allow_for)){
 
         /* Get infos */
+        $plug     = $tabs[$type]["PLUG"];
         $class    = $tabs[$type]["CLASS"];
-        $tabname  = $tabs[$type]["TABNAME"];
-        $acl_cat  = $tabs[$type]["ACL"];
+        $acl      = $tabs[$type]["ACL"];
         $tabclass = $tabs[$type]["TABCLASS"];
     
         /* Get acls */
         $ui       = get_userinfo();
-        $tabacl   = $ui->get_permissions($this->DivListSystem->selectedBase,$acl_cat."/".$tabname,"gotoRootPasswd");
+        $tabacl   = $ui->get_permissions($this->dn,$acl,"userPassword");
 
         /* Check acls */
         if(preg_match("/w/",$tabacl)){
           $ldap = $this->config->get_ldap_link();
           $ldap->cd($this->dn);
+          $ldap->cat($this->dn);
+          $old_attrs = $ldap->fetch();
 
           $attrs= array();
           if ($_POST['new_password'] == ""){
-            $attrs['gotoRootPasswd']= array();
+
+            /* Remove password attribute 
+             */
+            if(in_array("simpleSecurityObject",$old_attrs['objectClass'])){
+              $attrs['objectClass'] = array();
+              for($i = 0 ; $i < $old_attrs['objectClass']['count'] ; $i ++){
+                if(!preg_match("/simpleSecurityObject/i",$old_attrs['objectClass'][$i])){
+                  $attrs['objectClass'][] = $old_attrs['objectClass'][$i];
+                }
+              }
+            }
+            $attrs['userPassword']= array();
           } else {
-            $attrs['gotoRootPasswd']= crypt($_POST['new_password'],substr(session_id(),0,2));
+
+            /* Add/modify password attribute 
+             */
+            if(!in_array("simpleSecurityObject",$old_attrs['objectClass'])){
+              $attrs['objectClass'] = array();
+              for($i = 0 ; $i < $old_attrs['objectClass']['count'] ; $i ++){
+                $attrs['objectClass'][] = $old_attrs['objectClass'][$i];
+              }
+              $attrs['objectClass'][] = "simpleSecurityObject";
+            }
+
+            if(class_available("passwordMethodCrypt")){
+              $pwd_m = new passwordMethodCrypt($this->config);
+              $pwd_m->set_hash("crypt/md5");
+              $attrs['userPassword'] = $pwd_m->generate_hash($_POST['new_password']);
+            }else{
+              msg_dialog::display(_("Password method"),_("Password method crypt is missing. Cannot set system password."));
+              $attrs = array();
+            }
           }
           $ldap->modify($attrs);
+          if (!$ldap->success()){
+            msg_dialog::display(_("LDAP error"), msgPool::ldaperror($ldap->get_error(), $this->dn, LDAP_MOD, get_class()));
+          }else{
+            if(class_available($plug)){
+              $p = new $plug($this->config,$this->dn);
+              $p->handle_post_events("modify");
+            }
+          }
+  
           new log("security","systems/".get_class($this),$this->dn,array_keys($attrs),$ldap->get_error());
         }else{
-          print_red(_("You are not allowed to change the password for this object."));
+          msg_dialog::display(_("Permission error"), _("You have no permission to change this password!"), ERROR_DIALOG);
         }
       }else{
-        print_red(_("Can't detect object to change password."));
+        msg_dialog::display(_("Error"), _("Cannot determine object to change password!"), ERROR_DIALOG);
       }
       session::un_set('objectinfo');
     }
@@ -519,6 +570,27 @@ class systems extends plugin
         }
         $events = DaemonEvent::get_event_types(SYSTEM_EVENT);
         $type = preg_replace("/^[a-z]*_event_/","",$s_action);
+        $o_queue = new gosaSupportDaemon();
+
+        /* Skip installation or update trigerred events, 
+         *  if this entry is currently processing.
+         */
+        if(preg_match("/trigger_event/",$s_action) && in_array($type,array("DaemonEvent_reinstall","DaemonEvent_update"))){
+          foreach($mac as $key => $mac_address){
+            foreach($o_queue->get_entries_by_mac(array($mac_address)) as $entry){
+
+              $entry['STATUS'] = strtoupper($entry['STATUS']);
+              if($entry['STATUS'] == "PROCESSING" && 
+                  isset($events['QUEUED'][$entry['HEADERTAG']]) && 
+                  in_array($events['QUEUED'][$entry['HEADERTAG']],array("DaemonEvent_reinstall","DaemonEvent_update"))){
+                unset($mac[$key]);
+
+                new log("security","systems/".get_class($this),"",array(),"Skip adding 'DaemonEvent::".$type."' for mac '".$mac_address."', there is already a job in progress.");
+                break;
+              }
+            }
+          }
+        }        
 
         /* Prepare event to be added 
          */
@@ -545,8 +617,7 @@ class systems extends plugin
         $o_queue = new gosaSupportDaemon();
         $o_queue->append($this->systab);
         if($o_queue->is_error()){
-          msg_dialog::display(_("Daemon"),sprintf(_("Something went wrong while talking to the daemon: %s."),
-                $o_queue->get_error()),ERROR_DIALOG);
+          msg_dialog::display(_("Service infrastructure"),msgPool::siError($o_queue->get_error()),ERROR_DIALOG);
         }else{
           $this->systab = FALSE;
         }
@@ -575,19 +646,14 @@ class systems extends plugin
           return(gen_locked_message($user,$this->dns));
         }
 
-        $dns_names = "<br><pre>";
+        $dns_names = array();
         foreach($this->dns as $dn){
           add_lock ($dn, $this->ui->dn);
-          $dns_names .= $dn."\n";
+          $dns_names[] = @LDAP::fix($dn);
         }
-        $dns_names .="</pre>";
 
         /* Lock the current entry, so nobody will edit it during deletion */
-        if (count($this->dns) == 1){
-          $smarty->assign("warning",     sprintf(_("You're about to delete the following entry %s"), @LDAP::fix($dns_names)));
-        } else {
-          $smarty->assign("warning",     sprintf(_("You're about to delete the following entries %s"), @LDAP::fix($dns_names)));
-        }
+        $smarty->assign("warning", msgPool::deleteInfo($dns_names));
         $smarty->assign("multiple", true);
         return($smarty->fetch(get_template_path('remove.tpl', TRUE)));
       }
@@ -654,7 +720,7 @@ class systems extends plugin
           } else {
             /* Normally this shouldn't be reached, send some extra
                logs to notify the administrator */
-            print_red (_("You are not allowed to delete this component!"));
+            msg_dialog::display(_("Permission error"), msgPool::permDelete(), ERROR_DIALOG);
             new log("security","systems/".get_class($this),$dn,array(),"Tried to trick deletion.");
           }
           /* Remove lock file after successfull deletion */
@@ -725,14 +791,14 @@ class systems extends plugin
 
         /* Lock the current entry, so nobody will edit it during deletion */
         add_lock ($this->dn, $this->ui->dn);
-        $smarty->assign("warning", sprintf(_("You're about to delete all information about the component at '%s'."), @LDAP::fix($this->dn)));
+        $smarty->assign("warning", msgPool::deleteInfo(@LDAP::fix($this->dn)));
         $smarty->assign("multiple", false);
         return($smarty->fetch(get_template_path('remove.tpl', TRUE)));
       } else {
 
         /* Obviously the user isn't allowed to delete. Show message and
            clean session. */
-        print_red (_("You are not allowed to delete this component!"));
+        msg_dialog::display(_("Permission error"), msgPool::permDelete(), ERROR_DIALOG);
       }
     }
 
@@ -797,7 +863,7 @@ class systems extends plugin
 
         /* Normally this shouldn't be reached, send some extra
            logs to notify the administrator */
-        print_red (_("You are not allowed to delete this component!"));
+        msg_dialog::display(_("Permission error"), msgPool::permDelete(), ERROR_DIALOG);
         new log("security","systems/".get_class($this),$dn,array(),"Tried to trick deletion.");
       }
 
@@ -806,14 +872,7 @@ class systems extends plugin
     }
 
 
-
-
-
-
-
-
-
-   /********************
+    /********************
       Edit system type finished, check if everything went ok
      ********************/
     /* Finish user edit is triggered by the tabulator dialog, so
@@ -836,7 +895,7 @@ class systems extends plugin
           }
         }
         if(!$found){
-          print_red(sprintf(_("Can't set gotoMode to status 'active', the current object couldn't be identified.")));
+          msg_dialog::display(_("Internal error"), _("Cannot set mode to 'active'!"), ERROR_DIALOG);
         }
 
       }
@@ -851,7 +910,6 @@ class systems extends plugin
          * entry and not an edited one, so we will delete it.
          *
          */
-
         if(session::is_set('SelectedSystemType')){
           $SelectedSystemType = session::get('SelectedSystemType');
           if($SelectedSystemType['ogroup'] != "none"){
@@ -877,40 +935,6 @@ class systems extends plugin
         }
 
         $this->systab->save();
-        /* Get macAddress to be able to an installation event 
-         */ 
-        if($this->systab instanceof ArpNewDeviceTabs || session::is_set('SelectedSystemType')){
-          $events = DaemonEvent::get_event_types(SYSTEM_EVENT);
-         
-          /* Get mac of currently edited entry */ 
-          $mac = "";
-          if($this->systab instanceof ArpNewDeviceTabs){
-            $mac = $this->systab->by_object['ArpNewDevice']->netConfigDNS->macAddress;
-          }else{
-            foreach(array("workgeneric","termgeneric","servgeneric") as $type){
-              if(isset($this->systab->by_object[$type]->netConfigDNS->macAddress)){
-                $mac = $this->systab->by_object[$type]->netConfigDNS->macAddress;
-                break;
-              }
-            } 
-          }
-
-          /* Add installation event
-           */
-          if(!empty($mac) && isset($events['BY_CLASS']['DaemonEvent_reinstall'])){
-            $evt = $events['BY_CLASS']['DaemonEvent_reinstall'];
-            $tmp = new $evt['CLASS_NAME']($this->config);
-            $tmp->add_targets(array($mac));
-            $tmp->set_type(SCHEDULED_EVENT);
-            $o_queue = new gosaSupportDaemon();
-            $o_queue->append($tmp);
-            if($o_queue->is_error()){
-              msg_dialog::display(_("Daemon"),sprintf(_("Something went wrong while talking to the daemon: %s."),
-                    $o_queue->get_error()),ERROR_DIALOG);
-            }
-          }
-        }
 
         if(session::is_set('SelectedSystemType')){
           session::un_set('SelectedSystemType');
@@ -939,7 +963,7 @@ class systems extends plugin
       } else {
         /* Ok. There seem to be errors regarding to the tab data,
            show message and continue as usual. */
-        show_errors($message);
+        msg_dialog::displayChecks($message);
       }
     }
 
@@ -991,13 +1015,13 @@ class systems extends plugin
 
       if (!$dialog){
         $display.= "<p style=\"text-align:right\">\n";
-        $display.= "<input type=\"submit\" name=\"edit_finish\" style=\"width:80px\" value=\""._("Ok")."\">\n";
+        $display.= "<input type=\"submit\" name=\"edit_finish\" style=\"width:80px\" value=\"".msgPool::okButton()."\">\n";
         $display.= "&nbsp;\n";
         if (!$hide_apply){
-          $display.= "<input type=submit name=\"edit_apply\" value=\""._("Apply")."\">\n";
+          $display.= "<input type=submit name=\"edit_apply\" value=\"".msgPool::applyButton()."\">\n";
           $display.= "&nbsp;\n";
         }
-        $display.= "<input type=\"submit\" name=\"edit_cancel\" value=\""._("Cancel")."\">\n";
+        $display.= "<input type=\"submit\" name=\"edit_cancel\" value=\"".msgPool::cancelButton()."\">\n";
         $display.= "</p>";
       }
       return ($display);
@@ -1063,6 +1087,9 @@ class systems extends plugin
   function save_object()
   {
     $this->DivListSystem->save_object();
+    if(is_object($this->CopyPasteHandler)){
+      $this->CopyPasteHandler->save_object();
+    }
   }
 
 
@@ -1077,7 +1104,7 @@ class systems extends plugin
   {
   }
 
-  function adapt_from_template($dn)
+  function adapt_from_template($dn, $skip= array())
   {
   }
 
@@ -1132,17 +1159,18 @@ class systems extends plugin
     }    
 
     /* Walk through all possible search combinations, and search for some objects if the checkbox is enabled  */
-    $filter = "(|(&".$userregex."(objectClass=goHard)(cn=".$this->DivListSystem->Regex.")))";
     foreach($objs as $checkBox => $oc){
       if($this->DivListSystem->$checkBox){
         if($this->DivListSystem->SubSearch){
           if($oc['CLASS'] != ""){
+            $filter = "(&".$userregex."(objectClass=".$oc['CLASS'].")(cn=".$this->DivListSystem->Regex."))";
             $new_res = get_sub_list($filter, $sys_categories ,$oc['TREE'], $base,$sys_attrs, GL_SUBSEARCH | GL_SIZELIMIT);
             $res = array_merge($res,$new_res);
           }
         }else{
           /* User filter? */
           if($oc['CLASS'] != ""){
+            $filter = "(&".$userregex."(objectClass=".$oc['CLASS'].")(cn=".$this->DivListSystem->Regex."))";
             $res = array_merge($res,get_list($filter,$sys_categories,$oc['TREE'].$base, $sys_attrs,  GL_SIZELIMIT));
           }
         }
@@ -1150,6 +1178,7 @@ class systems extends plugin
     }
 
     /* Search for incoming objects */ 
+    $filter = "(|(&".$userregex."(objectClass=goHard)(cn=".$this->DivListSystem->Regex.")))";
     $res = array_merge($res,get_list($filter,$sys_categories, get_ou('incomingou').$base,$sys_attrs, GL_SIZELIMIT));
 
     /* Get all gotoTerminal's */
@@ -1431,7 +1460,7 @@ class systems extends plugin
   {
     $temp= "";
     $conv= array(      
-        "NQ" => array("select_newsystem.png",_("New System from incoming")),
+        "NQ" => array("select_newsystem.png",_("New system from incoming")),
         "D" => array("select_default.png",_("Template")),
         "T" => array("select_terminal.png",_("Terminal")),
         "L" => array("select_workstation.png",_("Workstation")),
@@ -1443,10 +1472,10 @@ class systems extends plugin
         "GS" => array("select_server_green.png",_("Server is installing")),
         "YS" => array("select_server_yellow.png",_("Server is waiting for action")),
         "RS" => array("select_server_red.png",_("Server installation failed")),
-        "W" => array("select_winstation.png",_("Winstation")),
-        "C" => array("select_component.png",_("Network Device")),
-        "NT"=> array("select_new_terminal.png",_("New Terminal")),
-        "NL"=> array("select_new_workstation.png",_("New Workstation")),
+        "W" => array("select_winstation.png",_("Win workstation")),
+        "C" => array("select_component.png",_("Network device")),
+        "NT"=> array("select_new_terminal.png",_("New terminal")),
+        "NL"=> array("select_new_workstation.png",_("New workstation")),
         "P" => array("select_printer.png",_("Printer")));
 
     if((isset($input['is_new']))&&(!empty($input['is_new']))){