Added permissions errors warning messages for lead management tools

git-svn-id: svn://192.168.202.10@3998 3d104415-ff17-0410-8863-d5cf3c621b8a
This commit is contained in:
mattf
2026-06-01 21:08:13 +00:00
parent 8d20427a51
commit 9740b76c00
2 changed files with 37 additions and 10 deletions
+19 -5
View File
@@ -1,7 +1,7 @@
<?php <?php
# lead_tools.php - Various tools for lead basic lead management. # lead_tools.php - Various tools for lead basic lead management.
# #
# Copyright (C) 2022 Matt Florell,Michael Cargile <vicidial@gmail.com> LICENSE: AGPLv2 # Copyright (C) 2026 Matt Florell,Michael Cargile <vicidial@gmail.com> LICENSE: AGPLv2
# #
# CHANGES # CHANGES
# 121110-1446 - Initial Build # 121110-1446 - Initial Build
@@ -18,10 +18,11 @@
# 170819-1002 - Added allow_manage_active_lists option # 170819-1002 - Added allow_manage_active_lists option
# 191119-1815 - Fixes for translations compatibility, issue #1142 # 191119-1815 - Fixes for translations compatibility, issue #1142
# 220228-1025 - Added allow_web_debug system setting # 220228-1025 - Added allow_web_debug system setting
# 260601-1702 - Added permissions errors warning messages
# #
$version = '2.14-14'; $version = '2.14-15';
$build = '220228-1025'; $build = '260601-1702';
# This limit is to prevent data inconsistancies. # This limit is to prevent data inconsistancies.
# If there are too many leads in a list this # If there are too many leads in a list this
@@ -748,9 +749,16 @@ if (
$allowed_campaigns_sql = "'$allowed_campaigns_sql'"; $allowed_campaigns_sql = "'$allowed_campaigns_sql'";
} }
if (strlen($allowed_campaigns_sql)<3)
{
echo "<BR>"._QXZ("ERROR: You can't use this tool as your user group is not allowed to access any campaigns");
exit;
}
# figure out which lists they are allowed to see # figure out which lists they are allowed to see
$activeSQL = "and active = 'N'"; $activeSQL = "and active = 'N'"; $activeSQL_msg = "be inactive, and";
if ($SSallow_manage_active_lists > 0) {$activeSQL = '';} if ($SSallow_manage_active_lists > 0) {$activeSQL = ''; $activeSQL_msg = "";}
$lists_stmt = "SELECT list_id, list_name FROM vicidial_lists WHERE campaign_id IN ($allowed_campaigns_sql) $activeSQL ORDER BY list_id"; $lists_stmt = "SELECT list_id, list_name FROM vicidial_lists WHERE campaign_id IN ($allowed_campaigns_sql) $activeSQL ORDER BY list_id";
if ($DB) { echo "|$lists_stmt|\n"; } if ($DB) { echo "|$lists_stmt|\n"; }
$lists_rslt = mysql_to_mysqli($lists_stmt, $link); $lists_rslt = mysql_to_mysqli($lists_stmt, $link);
@@ -789,6 +797,12 @@ if (
$i++; $i++;
} }
if ($allowed_lists_count==0)
{
echo "<BR>"._QXZ("You can't use this tool as your user group does not have access to any valid lists. A valid list must $activeSQL_msg have less than $list_lead_limit leads in it.");
exit;
}
# figure out which statuses are in the lists they are allowed to look at # figure out which statuses are in the lists they are allowed to look at
$status_stmt = "SELECT DISTINCT status FROM vicidial_list WHERE list_id IN ( $allowed_lists_sql ) ORDER BY status"; $status_stmt = "SELECT DISTINCT status FROM vicidial_list WHERE list_id IN ( $allowed_lists_sql ) ORDER BY status";
if ($DB) { echo "|$status_stmt|\n"; } if ($DB) { echo "|$status_stmt|\n"; }
@@ -20,10 +20,11 @@
# 241114-0813 - Raised max_count default to 60 # 241114-0813 - Raised max_count default to 60
# 250321-1152 - Changed status selector from dropdown to multi-select on Move, Update, and Delete # 250321-1152 - Changed status selector from dropdown to multi-select on Move, Update, and Delete
# 260529-0905 - Code updates for PHP8 compatibility # 260529-0905 - Code updates for PHP8 compatibility
# 260601-1701 - Added permissions errors warning messages
#
$version = '2.14-17';
$version = '2.14-16'; $build = '260601-1701';
$build = '260529-0905';
# This limit is to prevent data inconsistancies. # This limit is to prevent data inconsistancies.
# If there are too many leads in a list this # If there are too many leads in a list this
@@ -4309,9 +4310,15 @@ if (
$allowed_campaigns_sql = "'$allowed_campaigns_sql'"; $allowed_campaigns_sql = "'$allowed_campaigns_sql'";
} }
if (strlen($allowed_campaigns_sql)<3)
{
echo "<BR>"._QXZ("ERROR: You can't use this tool as your user group is not allowed to access any campaigns");
exit;
}
# figure out which lists they are allowed to see # figure out which lists they are allowed to see
$activeSQL = "and active = 'N'"; $activeSQL = "and active = 'N'"; $activeSQL_msg = "be inactive, and";
if ($SSallow_manage_active_lists > 0) {$activeSQL = '';} if ($SSallow_manage_active_lists > 0) {$activeSQL = ''; $activeSQL_msg = "";}
$lists_stmt = "SELECT list_id, list_name FROM vicidial_lists WHERE campaign_id IN ($allowed_campaigns_sql) $activeSQL ORDER BY list_id"; $lists_stmt = "SELECT list_id, list_name FROM vicidial_lists WHERE campaign_id IN ($allowed_campaigns_sql) $activeSQL ORDER BY list_id";
if ($DB) { echo "|$lists_stmt|\n"; } if ($DB) { echo "|$lists_stmt|\n"; }
$lists_rslt = mysql_to_mysqli($lists_stmt, $link); $lists_rslt = mysql_to_mysqli($lists_stmt, $link);
@@ -4350,6 +4357,12 @@ if (
$i++; $i++;
} }
if ($allowed_lists_count==0)
{
echo "<BR>"._QXZ("You can't use this tool as your user group does not have access to any valid lists. A valid list must $activeSQL_msg have less than $list_lead_limit leads in it.");
exit;
}
# figure out which statuses are in the lists they are allowed to look at # figure out which statuses are in the lists they are allowed to look at
$status_stmt = "SELECT DISTINCT status FROM vicidial_list WHERE list_id IN ( $allowed_lists_sql ) ORDER BY status"; $status_stmt = "SELECT DISTINCT status FROM vicidial_list WHERE list_id IN ( $allowed_lists_sql ) ORDER BY status";
if ($DB) { echo "|$status_stmt|\n"; } if ($DB) { echo "|$status_stmt|\n"; }