source: trunk/admin/admin.php@ 378

Last change on this file since 378 was 378, checked in by roby, 19 months ago

ADMIN

  • aggiunta funzione sperimentale e parziale per l'aggiornamento automatico all'ultima rev
File size: 24.2 KB
Line 
1<?php
2
3/************************************************************************/
4/* Eleonline - Raccolta e diffusione dei dati elettorali */
5/* by Roberto Gigli & Luciano Apolito */
6/* http://www.eleonline.it */
7/* info@eleonline.it luciano@aniene.net rgigli@libero.it */
8/************************************************************************/
9/* Admin */
10/* Amministrazione */
11/************************************************************************/
12
13/* Descrizione file admin.php =
14effettua il login o il rilancio alla gestione */
15
16define('ADMIN_FILE', true);
17#$LIMITE=3; //fascia di separazione del maggioritario (15.000 abitanti)
18# tempo di sessione: ini_set('session.gc_maxlifetime','3600');
19global $multicomune,$msglogout,$language,$id_sez;
20
21// Adattamento variabili superglobal
22// Versione di php
23$phpver = phpversion();
24global $dbi;
25// converte superglobal se php e' < 4.1.0
26
27if ($phpver < '4.1.0') {
28 $_GET = $HTTP_GET_VARS;
29 $_POST = $HTTP_POST_VARS;
30 $_SERVER = $HTTP_SERVER_VARS;
31 $_FILES = $HTTP_POST_FILES;
32 $_ENV = $HTTP_ENV_VARS;
33 if($_SERVER['REQUEST_METHOD'] == "POST") {
34 $_REQUEST = $_POST;
35 } elseif($_SERVER['REQUEST_METHOD'] == "GET") {
36 $_REQUEST = $_GET;
37 }
38 if(isset($HTTP_COOKIE_VARS)) {
39 $_COOKIE = $HTTP_COOKIE_VARS;
40 }
41 if(isset($HTTP_SESSION_VARS)) {
42 $_SESSION = $HTTP_SESSION_VARS;
43 }
44}
45
46$param=strtolower($_SERVER['REQUEST_METHOD']) == 'get' ? $_GET : $_POST;
47if (isset($param['aid'])) $aid=addslashes($param['aid']); else $aid='';
48if (isset($param['pwd'])) $pwd2=addslashes($param['pwd']); else $pwd2='';
49if(isset($param['msglogout'])) $msglogout=intval($param['msglogout']); else $msglogout=0;
50
51// Additional security (Union, CLike, XSS)
52
53// We want to use the function stripos,
54// but thats only available since PHP5.
55// So we cloned the function...
56if(!function_exists('stripos')) {
57 function stripos_clone($haystack, $needle, $offset=0) {
58 return strpos(strtoupper($haystack), strtoupper($needle), $offset);
59 }
60} else {
61// But when this is PHP5, we use the original function
62 function stripos_clone($haystack, $needle, $offset=0) {
63 return stripos($haystack, $needle, $offset=0);
64 }
65}
66
67 if(isset($_SERVER['QUERY_STRING']) && (!stripos_clone($_SERVER['QUERY_STRING'], "ad_click") || !stripos_clone($_SERVER['QUERY_STRING'], "url"))) {
68 $queryString = $_SERVER['QUERY_STRING'];
69 if (stripos_clone($queryString,'%20union%20') OR stripos_clone($queryString,'/*') OR stripos_clone($queryString,'*/union/*') OR stripos_clone($queryString,'c2nyaxb0') OR stripos_clone($queryString,'+union+') OR stripos_clone($queryString,'http://') OR (stripos_clone($queryString,'cmd=') AND !stripos_clone($queryString,'&cmd')) OR (stripos_clone($queryString,'exec') AND !stripos_clone($queryString,'execu')) OR stripos_clone($queryString,'concat')) {
70 die('Operazione non consentita');
71 }
72 }
73
74
75foreach ($_GET as $sec_key => $secvalue) {
76 if ((preg_match("/<[^>]*script*\"?[^>]*>/i",$secvalue)) ||
77 (preg_match("/<[^>]*object*\"?[^>]*>/i", $secvalue)) ||
78 (preg_match("/<[^>]*iframe*\"?[^>]*>/i", $secvalue)) ||
79 (preg_match("/<[^>]*applet*\"?[^>]*>/i", $secvalue)) ||
80 (preg_match("/<[^>]*meta*\"?[^>]*>/i", $secvalue)) ||
81 (preg_match("/<[^>]*style*\"?[^>]*>/i", $secvalue)) ||
82 (preg_match("/<[^>]*form*\"?[^>]*>/i", $secvalue)) ||
83 (preg_match("/<[^>]*img*\"?[^>]*>/i", $secvalue)) ||
84 (preg_match("/<[^>]*onmouseover*\"?[^>]*>/i", $secvalue)) ||
85 (preg_match("/<[^>]*body*\"?[^>]*>/i", $secvalue)) ||
86 (preg_match("/\"/", $secvalue)) ||
87 (preg_match("/inside_mod/i", $sec_key))) {
88 die ("Operazione non consentita");
89 }
90 }
91
92 foreach ($_POST as $secvalue) {
93 if ((preg_match("/<[^>]*onmouseover*\"?[^>]*>/i", $secvalue)) || (preg_match("/<[^>]script*\"?[^>]*>/i", $secvalue)) || (preg_match("/<[^>]*body*\"?[^>]*>/i", $secvalue)) || (preg_match("/<[^>]style*\"?[^>]*>/i", $secvalue))) {
94 die ('Operazione non consentita');
95 }
96 }
97
98// Posting from other servers in not allowed
99// Fix by Quake
100// Bug found by PeNdEjO
101
102if ($_SERVER['REQUEST_METHOD'] == "POST") {
103 if (isset($_SERVER['HTTP_REFERER'])) {
104 if (!stripos_clone($_SERVER['HTTP_REFERER'], $_SERVER['HTTP_HOST'])) {
105 die('Posting da un altro server non consentito!');
106 }
107 } else {
108# die('<b>Attenzione:</b> il tuo browser non puo inviare gli header HTTP_REFERER al website.<br>'.$_SERVER['HTTP_REFERER']);
109 }
110}
111
112
113
114
115
116
117
118//===================================================================
119session_name('sesadmin');
120#session_start();//MODIFICHE PER GESTIONE SESSIONI
121 // gestione sessione
122$a = session_id();
123if(empty($a)) session_start();
124#echo "SID: ".SID."<br>session_id(): ".session_id()."<br>COOKIE: ".$_COOKIE["PHPSESSID"];
125
126if (file_exists("config.php")){
127 $install="0"; @require_once("config.php");
128}else{
129 $install="1";
130}
131
132# verifica se effettuata la configurazione
133if(empty($dbname) || $install=="1") {
134 die("<html><body><div style=\"text-align:center\"><br /><br /><img src=\"modules/Elezioni/images/logo.jpg\" alt=\"Eleonline\" title=\"Eleonline\"><br /><br /><strong>Sembra che <a href='http://www.eleonline.it' title='Eleonline'>Eleonline</a> non sia stato ancora installato.<br /><br />Puoi procedere <a href='../install/index.php'>cliccando qui</a> per iniziare l'installazione</strong></div></body></html>");
135}
136
137$dsn = "mysql:host=$dbhost";
138$opt = array(PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION, PDO::ATTR_EMULATE_PREPARES => false);
139if($prefix == '') {
140 db_err ('stepBack','Non avete indicato il prefisso tabelle database.');
141}
142try
143{
144 $dbi = new PDO($dsn, $dbuname, $dbpass, $opt);
145}
146catch(PDOException $e)
147{
148 echo $sql . "<br>" . $e->getMessage();die();
149}
150$sql = "use $dbname";
151try
152{
153 $dbi->exec($sql);
154}
155catch(PDOException $e)
156{
157 echo $sql . "<br>" . $e->getMessage();
158}
159$sth = $dbi->prepare("SET SESSION character_set_connection = 'utf8' ");
160$sth->execute();
161$sth = $dbi->prepare("SET SESSION character_set_client = 'utf8' ");
162$sth->execute();
163$sth = $dbi->prepare("SET SESSION character_set_database = 'utf8' ");
164$sth->execute();
165$sth = $dbi->prepare("SET CHARACTER SET utf8");
166$sth->execute();
167
168$sth = $dbi->prepare("SET NAMES 'utf8'");
169$sth->execute();
170$sth = $dbi->prepare("select * from ".$prefix."_config");
171$sth->execute();
172
173# $dbi=mysql_connect($dbhost, $dbuname, $dbpass) or die("Connessione non riuscita: " . mysql_error());
174# mysql_select_db($dbname)or die("Connessione non riuscita:" . mysql_error());
175## mysql_query("SET NAMES 'utf8'", $dbi);
176//---10/05/2009 gestione consultazione predefinita
177$sth = $dbi->prepare("select * from ".$prefix."_config");
178$sth->execute();
179$row = $sth->fetch(PDO::FETCH_ASSOC);
180#$row = $sth->fetchAll();
181$siteistat=$row['siteistat'];
182if (!isset($_SESSION['id_comune'])){
183 $_SESSION['sitename']=$row['sitename'];
184 $_SESSION['siteurl']=$row['siteurl'];
185 $_SESSION['site_logo']=$row['site_logo'];
186 $_SESSION['slogan']=$row['slogan'];
187 $_SESSION['startdate']=$row['startdate'];
188 $_SESSION['adminmail']=$row['adminmail'];
189# if (isset($tema) and $tema=='facebook')
190# $_SESSION['tema']=$row['tema'];
191 $_SESSION['foot']=$row['foot'];
192 $_SESSION['lang']=$row['language'];
193 $_SESSION['blocco']=$row['blocco'];
194 $_SESSION['testata']=$row['testata'];
195# $_SESSION['logo']=$row['logo'];
196 $_SESSION['fileout']=$row['fileout'];
197 $_SESSION['copyright']=$row['copyright'];
198 $_SESSION['versione']=$row['versione'];
199 $_SESSION['patch']=$row['patch'];
200 $_SESSION['id_comune']=$row['siteistat'];
201 $_SESSION['multicomune']=$row['multicomune'];
202 $_SESSION['flash']=$row['flash'];
203 $_SESSION['displayerrors']=$row['displayerrors'];
204 $_SESSION['editor']=$row['editor'];
205 $_SESSION['tema_on']=$row['tema_on'];
206 $_SESSION['ed_user']=$row['ed_user'];
207 $multicomune=$row['multicomune'];
208}
209if(!isset($_SESSION['aggiornamento']) and isset($_SESSION['aid']) and ChiSei(0)==256)
210{
211 $sql="SELECT COLUMN_NAME
212 FROM INFORMATION_SCHEMA.COLUMNS
213 WHERE TABLE_SCHEMA = '$dbname'
214 AND TABLE_NAME = '".$prefix."_config'
215 AND COLUMN_NAME = 'aggiornamento'";
216 $sth = $dbi->prepare($sql);
217 $sth->execute();
218 if($sth->rowCount())
219 {
220 $sth = $dbi->prepare("select aggiornamento from ".$prefix."_config");
221 $sth->execute();
222 list($agg)=$sth->fetch(PDO::FETCH_NUM);
223 $_SESSION['aggiornamento']=$agg;
224 if($agg) include('aggiornamento.php');
225 }else{
226 $sql="ALTER TABLE `soraldo_config` ADD `aggiornamento` ENUM('0','1','2') CHARACTER SET utf8 COLLATE utf8_general_ci NOT NULL DEFAULT '2' AFTER `ed_user`;";
227 $sth = $dbi->prepare($sql);
228 $sth->execute();
229 }
230}
231//fine
232 if (isset($param['tema'])) $_SESSION['tema']=$param['tema'];
233 if (!isset($_SESSION['tema']))
234 $_SESSION['tema']='default';
235 $tema=$_SESSION['tema'];
236
237if (isset($param['aid'])) {
238 if (strlen($aid)>25 ) { die ("Nome utente troppo lungo: $aid"); }
239 if (!isset($param['id_ses']) or $param['id_ses'] != session_id()) logout();
240 if (strstr( $aid," ")) { die ("Gli spazi non sono ammessi nel nome utente: $aid"); }
241 if (isset($_SESSION['aid'])){
242 logout();//se hai gia' una sessione aperta non puoi postare 'aid'
243 }else{
244
245 // $pwd2=$param['pwd'];
246 $mpwd=md5($pwd2);
247
248 // se superUserAdmin
249 ########
250 # $sth = $dbi->prepare("select adminsuper from ".$prefix."_authors where aid='$aid' and pwd='$mpwd'");
251 # $sth->execute();
252 # $row = $sth->fetch(PDO::FETCH_ASSOC);
253 if (isset($param['id_comune']) and intval($param['id_comune'])>0) $id_comune=intval($param['id_comune']); else $id_comune=0;;
254 # if ($adminsuper==1) $id_comune2=0; else
255 $id_comune2=$id_comune;
256 $sth = $dbi->prepare("select pwd,adminop,adminsuper,counter,admlanguage from ".$prefix."_authors where aid='$aid' and (id_comune='$id_comune2' or adminsuper='1')");
257 $sth->execute();
258 $esiste=$sth->rowCount();
259 # $adminsuper=$row['adminsuper'];
260 $row = $sth->fetch(PDO::FETCH_ASSOC);
261 if(!$esiste) {
262 $msglogout=2;
263 logout();
264 }else{
265 if ($row['pwd']!=$mpwd) {
266 $msglogout=3;
267 logout();
268 }elseif($row['adminop']==1) {
269 $msglogout=1;
270 logout();
271 }
272 $counter=$row['counter'];
273 $tmplang=$row['admlanguage'];
274 if(strlen($tmplang)==2) $language=$tmplang;
275 $sth = $dbi->prepare("update ".$prefix."_authors set counter=$counter where aid='$aid' and pwd='$mpwd' and id_comune='$id_comune2'");
276 $sth->execute();
277# $row = $sth->fetch(PDO::FETCH_ASSOC);
278 if ($esiste==1) {
279# $_SESSION['dbi']=$dbi;
280 $_SESSION['aid']="$aid";
281 $_SESSION['pwd']="$mpwd";
282 $_SESSION['lang']="$language";
283 $_SESSION['id_comune']="$id_comune";
284 $_SESSION['prefix']="soraldo";
285 $_SESSION['remote']=$_SERVER['REMOTE_ADDR'];
286 $_SESSION['bgcolor1']='#ffffff';
287 $_SESSION['bgcolor2']='#c5c5c5';
288 if (!isset($op)) $op='consultazione';
289 session_regenerate_id();
290 }
291 }
292 }
293}else{
294#$_SESSION['dbi']=$dbi;
295
296}
297if(!isset($_SESSION['BASE'])) $_SESSION['BASE']=substr($_SERVER['PHP_SELF'], 0, strrpos($_SERVER['REQUEST_URI'], "/")-16);
298if(!isset($language)) $language=$_SESSION['lang'];
299if (! isset($_SESSION['lang'])) $_SESSION['lang']=$language;
300$currentlang=strlen($_SESSION['lang'])==2 ? $_SESSION['lang']: $language;
301
302if (isset($_SESSION['aid']))
303{
304//lettura sessione
305$aid=$_SESSION['aid'];
306#$dbi=$_SESSION['dbi'];
307$prefix=$_SESSION['prefix'];
308$id_comune=$_SESSION['id_comune'];
309if($id_comune==0) $rifcomune='58047'; else $rifcomune=$id_comune;
310if (isset($_GET['id_cons_gen'])) {$id_cons_gen=intval($_GET['id_cons_gen']);}
311else {
312 $oggi=date("Y-m-d",mktime(0,0,0,date("m"),date("d")-3,date("Y")));
313 $sql="select t1.id_cons_gen from ".$prefix."_ele_consultazione as t1, ".$prefix."_ele_cons_comune as t2 where t1.id_cons_gen=t2.id_cons_gen and t2.id_comune=$id_comune and t1.data_fine>'$oggi' and t2.id_cons in (select id_cons from ".$prefix."_ele_operatori where aid='$aid' and permessi>0) limit 0,1"; # TEST: and id_sez>0
314 $rese = $dbi->prepare("$sql");
315 $rese->execute();
316 if($rese->rowCount())
317 {list($id_cons_gen)=$rese->fetch(PDO::FETCH_NUM); }
318 else {
319 $sql="SELECT t1.id_cons_gen FROM ".$prefix."_ele_cons_comune as t1, ".$prefix."_ele_comuni as t2 where t1.id_cons=t2.id_cons and t2.id_comune='$id_comune'";
320 $sth = $dbi->prepare($sql);
321 $sth->execute();
322 $row = $sth->fetch(PDO::FETCH_BOTH);
323 if($sth->rowCount())
324 $id_cons_gen=$row[0];
325 else
326 $id_cons_gen=0; #die("TEST IN CORSO : idconsgen: $id_cons_gen -- sql:$sql");
327 }
328}
329$currentlang=$_SESSION['lang'];
330#$bgcolor1=$_SESSION['bgcolor1'];
331$bgcolor2=$_SESSION['bgcolor2'];
332$bgcolor1='#e7e7e7';
333$session=$_SESSION['remote'];
334
335}
336
337
338
339/*********************************************************/
340/* Login Function */
341/*********************************************************/
342function ChiSei($id_cons_gen){
343global $dbi, $msglogout;
344
345$aid=$_SESSION['aid'];
346$prefix=$_SESSION['prefix'];
347$pwd=$_SESSION['pwd'];
348$id_comune=$_SESSION['id_comune'];
349
350$perms=0;
351$sql="select adminsuper, admincomune, adminop from ".$prefix."_authors where aid='$aid' and pwd='$pwd' and (id_comune='$id_comune' or id_comune=0)";
352$sth = $dbi->prepare("$sql");
353$sth->execute();
354$row = $sth->fetch(PDO::FETCH_BOTH);
355
356$adminsuper=$row[0];
357$admincomune=$row[1];
358$oper=$row[2];
359
360#if (($adminsuper==1 || $admincomune==1 || $adminop==1)) {
361 if ($adminsuper==1)
362 return 256;
363 elseif ($admincomune==1)
364 return 64;
365# $sth = $dbi->prepare("select permessi from ".$prefix."_ele_operatori where id_cons='0' and aid='$aid' and id_comune='$id_comune'");
366 elseif($oper) {$msglogout=1; return 0;} # id_cons='$id_cons' and
367 else {
368 $oggi=date("Y-m-d",mktime(0,0,0,date("m"),date("d")-3,date("Y")));
369 $sql="SELECT id_sez FROM ".$prefix."_ele_operatori where aid='$aid' and permessi>0 and id_cons in (select t1.id_cons from ".$prefix."_ele_cons_comune as t1, ".$prefix."_ele_consultazione as t2 where t1.id_cons_gen=t2.id_cons_gen and t1.id_comune='$id_comune' and t2.data_fine>$oggi)";
370 $sth = $dbi->prepare("$sql");
371 $sth->execute(); #die("TEST: $sql");
372 if($sth->rowCount()) {$perms=16; return $perms;}
373 else {$msglogout=1; return 0;}
374 }
375/* $sth = $dbi->prepare("select id_cons from ".$prefix."_ele_cons_comune where id_comune='$id_comune' and id_cons_gen='$id_cons_gen'");
376 $sth->execute();
377 $row = $sth->fetch(PDO::FETCH_BOTH);
378 $id_cons=$row[0];
379 $sth = $dbi->prepare("select permessi from ".$prefix."_ele_operatori where id_cons='$id_cons' and aid='$aid' and id_comune='$id_comune'");
380
381 $sth->execute();
382 list($perms)=$sth->fetch(PDO::FETCH_NUM);
383# $row = die("test:$sql".$row[0] );
384 if (!$perms) {die("qui: select permessi from ".$prefix."_ele_operatori where id_cons='$id_cons' and aid='$aid' and id_comune='$id_comune'"); $msglogout=1; $perms=0; }
385
386 return $perms; */
387#} else return 0;
388}
389
390function OpenTable(){
391echo "<table width=\"100%\" cellpadding=\"0\" cellspacing=\"2\" BORDER=\"0\">";
392}
393
394function CloseTable(){
395echo "</table>";
396}
397
398function login() {
399 global $param,$prefix,$dbi,$multicomune,$siteistat,$language,$tema, $id_cons_gen, $perms, $msglogout;
400 if (isset($param['id_comune'])) $id_comune=intval($param['id_comune']);
401 if (!isset($id_comune)) $id_comune=0;
402 if(isset($_SESSION['aid'])){
403 session_regenerate_id();
404 }
405 $lang=(isset($_SESSION['lang']) and strlen($_SESSION['lang'])==2) ? $_SESSION['lang']: $language;
406 $id_ses=session_id();
407
408 //include("modules/Elezioni/language/lang-$lang.php");
409 if($multicomune==''){
410 $sth = $dbi->prepare("select multicomune from ".$prefix."_config");
411 $sth->execute();
412 list($multicomune) = $sth->fetch(PDO::FETCH_NUM);
413 }
414 include ("header.php");
415 echo "<div align=\"middle\"><font class=\"title\"><b>"._GESTIONE."</b></font></center>";
416 echo "<br>"; # method=\"post\"
417 if ($msglogout==1) echo "<h1 style=\"color:red;\">Utente non autorizzato</h1><br>";
418 elseif ($msglogout==2) echo "<h1 style=\"color:red;\">Nome Utente non presente in archivio</h1><br>";
419 elseif ($msglogout==3) echo "<h1 style=\"color:red;\">Password Errata</h1><br>";
420 elseif ($msglogout==4) echo "<h1 style=\"color:red;\">Accesso non ammesso da cellulare</h1><br>";
421 echo "<form name=\"login\" data-ajax=\"false\" method=\"post\" action=\"admin.php\">"
422 ."<table class=\"table-menu\">"
423 ."<tr><td>"._ADMINID."</td>"
424 ."<td><input type=\"text\" NAME=\"aid\" SIZE=\"20\" MAXLENGTH=\"25\"></td></tr>"
425 ."<tr><td>"._PASSWORD."</td>"
426 ."<td><input type=\"password\" NAME=\"pwd\" SIZE=\"20\" MAXLENGTH=\"18\"></td></tr>"
427 ."<tr><td>";
428 // scelta comune
429 if($multicomune=='1'){
430 echo ""._COMUNE."</td><td>";
431 $sql="select * from ".$prefix."_ele_comuni order by descrizione asc";
432 $sth = $dbi->prepare("$sql");
433 $sth->execute();
434 $row = $sth->fetchAll();
435 echo "<select name=\"id_comune\">";
436 foreach($row as $comuni)
437 {$id=$comuni[0];$descrizione=$comuni[1];
438 $sel=($id == $id_comune) ? "selected":"";
439 echo "<option value=\"$id\" $sel>$descrizione";
440 }
441 }else{
442 echo "<input type=\"hidden\" name=\"id_comune\" value=\"$siteistat\">";
443 }
444// echo "<input type=\"hidden\" name=\"id_comune\" value=\"$id_comune\">";
445 if(strlen($lang)==2) echo "<input type=\"hidden\" name=\"language\" value=\"$lang\">";
446 echo "</td></tr><tr><td>";
447 echo "<input type=\"hidden\" name=\"id_ses\" value=\"$id_ses\">";
448 echo "<input type=\"submit\" VALUE=\""._OK."\">"
449 ."</td></tr></table>"
450 ."</form></div>";
451
452 include ("footer.php");
453}
454
455function logout()
456{
457/* $lang=$_SESSION['lang'];
458$id_comune=$_SESSION['id_comune'];
459// setcookie ("PHPSESSID", "", time() - 3600);
460 session_cache_expire (0);
461 $_SESSION=array(); //MODIFICHE PER GESTIONE SESSIONI
462 session_unset();
463 session_destroy();
464 Header("Location: admin.php?id_comune=$id_comune&language=$lang");
465*/
466
467global $siteistat,$perms,$msglogout;
468$language=$_SESSION['lang'];
469$ref="Location: admin.php?";
470#$ref="Location: https://www.eleonline.it/adminmob/admin.php?";
471if (isset($_SESSION['id_comune']))
472$id_comune=$_SESSION['id_comune'];
473else
474$id_comune=$siteistat;
475$ref=$ref."id_comune=".$id_comune;
476
477if (isset($_SESSION['lang']))
478$ref=$ref."&language=$language";
479$ref.="&msglogout=$msglogout";
480$_SESSION=array();
481session_unset();
482session_destroy();
483session_cache_expire (0);
484Header($ref);
485
486}
487#include("TEST tema: $tema--");
488#include("modules/Elezioni/language/lang-".$_SESSION['lang'].".php");
489
490if(isset($id_cons_gen) and isset($id_comune)){
491 if(!isset($id_cons)){
492# $sql = "SELECT t2.id_cons FROM ".$prefix."_ele_consultazione as t1, ".$prefix."_ele_cons_comune as t2 where t1.id_cons_gen=t2.id_cons_gen and t2.id_cons_gen='$id_cons_gen' and t2.id_comune='$id_comune'";
493 $sql = "SELECT id_cons from ".$prefix."_ele_comuni where id_comune='$id_comune'";
494 $sth = $dbi->prepare("$sql");
495 $sth->execute();
496 if ($sth->rowCount()) {
497 list($id_cons) = $sth->fetch(PDO::FETCH_NUM);
498 $_SESSION['id_cons']=$id_cons;
499 }
500 }
501 if(isset($id_cons)) {
502 $sql="SELECT id_sez FROM ".$prefix."_ele_operatori where id_sez>0 and aid='$aid' and id_comune=$id_comune";
503 $resmod = $dbi->prepare("$sql");
504 $resmod->execute();
505 list($id_sez) = $resmod->fetch(PDO::FETCH_NUM); #die("qui:$id_sez:$sql");
506 if($id_sez) {
507 $oggi=date("Y-m-d",mktime(0,0,0,date("m"),date("d")-3,date("Y")));
508 $sql="select t1.id_cons_gen,t1.descrizione,t2.id_cons from ".$prefix."_ele_consultazione as t1, ".$prefix."_ele_cons_comune as t2 where t1.id_cons_gen=t2.id_cons_gen and t2.id_comune=$id_comune and t1.data_fine>'$oggi' and t2.id_cons in (select id_cons from ".$prefix."_ele_operatori where aid='$aid' and id_sez>0 and permessi>0)";
509 $resmod = $dbi->prepare("$sql");
510 $resmod->execute();
511 if ($resmod->rowCount()>0) {
512 $tema='Futura2'; #die( "TEST id_cons:$id_cons:".$_SESSION['aid']);
513 $_SESSION['tema']=$tema;
514 } #else {die("TEST: $sql"); logout();}
515 }
516 }
517$perms=ChiSei($id_cons_gen); #die("qui".$_SESSION['aid']);
518if($perms==0) {logout();}
519}
520
521#echo "op:".$param['op']." -- aid:".$_SESSION['aid']."remote:".$_SESSION['remote']."REMOTE:".$_SERVER['REMOTE_ADDR'];
522if (isset($param['op'])) $op=addslashes($param['op']); else $op='ele';
523//if (isset($param['op'])) $op=$param['op']; else $op='ele';
524#
525#die("TEST: qui $aid $id_cons $id_sez ".$_SESSION['aid']);
526
527if (isset($_SESSION['aid']) AND $_SESSION['remote']==$_SERVER['REMOTE_ADDR']) {
528 if($tema=='Futura2' and $op!='logout')
529 {
530 include("temi/$tema/index.php");
531 }else
532switch($op) {
533 case "tipo":
534 include("modules/Elezioni/ele_tipi.php");
535 break;
536 case "constipi":
537 include("modules/Elezioni/ele_consultazionitipi.php");
538 break;
539 case "aggiorna":
540 include("modules/Elezioni/aggiorna.php");
541 break;
542 case "parziali":
543 include("modules/Elezioni/ele_parziali.php");
544 break;
545 case "ele":
546 include("modules/Elezioni/ele.php");
547 break;
548 case "consultazione":
549 include("modules/Elezioni/ele_consultazioni.php");
550 break;
551 case "configurazione":
552 include("modules/Elezioni/ele_configurazione.php");
553 break;
554 case "cons_comuni":
555 include("modules/Elezioni/ele_cons_comuni.php");
556 break;
557 case "confconsiglio":
558 include("modules/Elezioni/ele_confcons.php");
559 break;
560 case "inscomuni":
561 include("modules/Elezioni/ele_comuni.php");
562 break;
563 case "oper_admin":
564 include("modules/Elezioni/ele_operatori.php");
565 break;
566 case "inscollegi":
567 include("modules/Elezioni/ele_collegi.php");
568 break;
569 case "associazioni":
570 include("modules/Elezioni/ele_associazioni.php");
571 break;
572 case "operatori":
573 include("modules/Elezioni/ele_operatori.php");
574 break;
575 case "permessi":
576 include("modules/Elezioni/ele_permessi.php");
577 break;
578 case "circo":
579 include("modules/Elezioni/ele_circo.php");
580 break;
581 case "sede":
582 include("modules/Elezioni/ele_sede.php");
583 break;
584case "sezione":
585 include("modules/Elezioni/ele_sezione.php");
586 break;
587case "gruppo":
588 include("modules/Elezioni/ele_gruppo.php");
589 break;
590case "rec_add_aff":
591 include("modules/Elezioni/ele_affluenze.php");
592 break;
593case "rec_add_mod":
594 include("modules/Elezioni/ele_modelli.php");
595 break;
596case "upgruppo":
597 include("modules/Elezioni/ele_gruppo.php");
598 break;
599case "delimggruppo":
600 include("modules/Elezioni/ele_gruppo.php");
601 break;
602case "lista":
603 include("modules/Elezioni/ele_lista.php");
604 break;
605case "uplista":
606 include("modules/Elezioni/ele_lista.php");
607 break;
608case "delimglista":
609 include("modules/Elezioni/ele_lista.php");
610 break;
611case "candidato":
612 include("modules/Elezioni/ele_candidato.php");
613 break;
614case "upcandidato":
615 include("modules/Elezioni/ele_candidato.php");
616 break;
617case "delimgcandidato":
618 include("modules/Elezioni/ele_candidato.php");
619 break;
620
621case "voti":
622 include("modules/Elezioni/ele_voti.php");
623 break;
624case "sezioni_voti":
625 include("modules/Elezioni/ele_voti.php");
626 break;
627case "rec_voti":
628 include("modules/Elezioni/ele_voti.php");
629 break;
630case "rec_voti_gruppi":
631 include("modules/Elezioni/ele_voti.php");
632 break;
633case "rec_add_votanti":
634 include("modules/Elezioni/ele_voti.php");
635 break;
636case "rec_finale":
637 include("modules/Elezioni/ele_voti.php");
638 break;
639case "controllo_voti":
640 include("modules/Elezioni/controllo_voti.php");
641 break;
642case "controllo_votanti":
643 include("modules/Elezioni/controllo_votanti.php");
644 break;
645case "come":
646 include("modules/Elezioni/ele_come.php");
647 break;
648case "numeri":
649 include("modules/Elezioni/ele_come.php");
650 break;
651case "servizi":
652 include("modules/Elezioni/ele_come.php");
653 break;
654case "link":
655 include("modules/Elezioni/ele_come.php");
656 break;
657case "conf":
658 include("modules/Elezioni/ele_conf.php");
659 break;
660case "stampa":
661 include("modules/Elezioni/ele_stampe.php");
662 break;
663case "cambiopwd":
664 include("modules/Elezioni/ele_pwd.php");
665 break;
666case "eletti":
667 include("modules/Elezioni/ele_eletti.php");
668 break;
669case "foto":
670 include("modules/Elezioni/foto.php");
671 break;
672case "consiglieri":
673 include("modules/Elezioni/ele_consiglieri.php");
674 break;
675case "backup":
676 include("modules/Elezioni/backup.php");
677 break;
678case "restore":
679 include("modules/Elezioni/restore.php");
680 break;
681case "scarica":
682 include("modules/Elezioni/scarica.php");
683 break;
684case "importa":
685 include("modules/Elezioni/importa.php");
686 break;
687case "widget":
688 include("modules/Elezioni/ele_widget.php");
689 break;
690case "riepilogo":
691 include("modules/Elezioni/ele_riepilogo.php");
692 break;
693case "riepilogovoti":
694 include("modules/Elezioni/ele_riepilogovoti.php");
695 break;
696case "logout":
697 logout();
698 break;
699}
700
701}else {
702
703 login();
704
705}
706
707?>
Note: See TracBrowser for help on using the repository browser.