From db076bd218819cce948ac5fa4350a6c53d4eec4a Mon Sep 17 00:00:00 2001 From: mattf Date: Thu, 9 Nov 2023 14:25:07 +0000 Subject: [PATCH] Added 2FA for agent screen logins Added several campaign fields to update_settings related to manual dial calls in the agent screen git-svn-id: svn://192.168.202.10@3770 3d104415-ff17-0410-8863-d5cf3c621b8a --- agc_2-X/trunk/docs/AGENT_API.txt | 2 +- .../trunk/extras/MySQL_AST_CREATE_tables.sql | 5 +- agc_2-X/trunk/extras/upgrade_2.14.sql | 4 + agc_2-X/trunk/www/agc/css/style.css | 6 + agc_2-X/trunk/www/agc/images/2FA_icon.png | Bin 0 -> 1215 bytes .../trunk/www/agc/images/2FA_icon_white.png | Bin 0 -> 1319 bytes .../www/agc/images/icon_black_inbound.png | Bin 0 -> 1246 bytes agc_2-X/trunk/www/agc/images/icon_chat.png | Bin 0 -> 802 bytes agc_2-X/trunk/www/agc/images/icon_email.png | Bin 0 -> 932 bytes agc_2-X/trunk/www/agc/options-example.php | 3 +- agc_2-X/trunk/www/agc/vdc_db_query.php | 26 +- agc_2-X/trunk/www/agc/vicidial.php | 619 +++++++++++++++++- agc_2-X/trunk/www/vicidial/admin.php | 22 +- .../trunk/www/vicidial/help_documentation.txt | 5 +- .../trunk/www/vicidial/lead_report_export.php | 18 +- .../trunk/www/vicidial/options-example.php | 3 + 16 files changed, 684 insertions(+), 29 deletions(-) create mode 100644 agc_2-X/trunk/www/agc/images/2FA_icon.png create mode 100644 agc_2-X/trunk/www/agc/images/2FA_icon_white.png create mode 100644 agc_2-X/trunk/www/agc/images/icon_black_inbound.png create mode 100644 agc_2-X/trunk/www/agc/images/icon_chat.png create mode 100644 agc_2-X/trunk/www/agc/images/icon_email.png diff --git a/agc_2-X/trunk/docs/AGENT_API.txt b/agc_2-X/trunk/docs/AGENT_API.txt index 1c0fd7e8..ce25e3f7 100644 --- a/agc_2-X/trunk/docs/AGENT_API.txt +++ b/agc_2-X/trunk/docs/AGENT_API.txt @@ -451,7 +451,7 @@ LEAD DATA (must populate at least one) vendor_lead_code rank owner -OPTIONAL NON-LEAD TRIGGERS - +OPTIONAL NON-LEAD TRIGGERS (these still require a lead to be on the agent screen) - formreload scriptreload script2reload diff --git a/agc_2-X/trunk/extras/MySQL_AST_CREATE_tables.sql b/agc_2-X/trunk/extras/MySQL_AST_CREATE_tables.sql index b238c2f1..322a8c47 100644 --- a/agc_2-X/trunk/extras/MySQL_AST_CREATE_tables.sql +++ b/agc_2-X/trunk/extras/MySQL_AST_CREATE_tables.sql @@ -2020,7 +2020,8 @@ agent_notifications ENUM('0','1','2','3','4','5','6','7') default '0', demographic_quotas ENUM('0','1','2','3','4','5','6','7') default '0', log_latency_gaps ENUM('0','1','2','3','4','5','6','7') default '1', inbound_credits ENUM('0','1','2','3','4','5','6','7') default '0', -weekday_resets ENUM('0','1','2','3','4','5','6','7') default '0' +weekday_resets ENUM('0','1','2','3','4','5','6','7') default '0', +two_factor_auth_agent_hours SMALLINT(5) default '0' ) ENGINE=MyISAM; CREATE TABLE vicidial_campaigns_list_mix ( @@ -5441,4 +5442,4 @@ INSERT INTO `wallboard_reports` VALUES ('AGENTS_AND_QUEUES','Agents and Queues', UPDATE system_settings set vdc_agent_api_active='1'; -UPDATE system_settings SET db_schema_version='1697',db_schema_update_date=NOW(),reload_timestamp=NOW(); +UPDATE system_settings SET db_schema_version='1698',db_schema_update_date=NOW(),reload_timestamp=NOW(); diff --git a/agc_2-X/trunk/extras/upgrade_2.14.sql b/agc_2-X/trunk/extras/upgrade_2.14.sql index 7f11ad7d..3a02ace4 100644 --- a/agc_2-X/trunk/extras/upgrade_2.14.sql +++ b/agc_2-X/trunk/extras/upgrade_2.14.sql @@ -2427,3 +2427,7 @@ ALTER TABLE phones MODIFY conf_secret VARCHAR(100) default 'test'; ALTER TABLE servers MODIFY conf_secret VARCHAR(100) default 'test'; UPDATE system_settings SET db_schema_version='1697',db_schema_update_date=NOW() where db_schema_version < 1697; + +ALTER TABLE system_settings ADD two_factor_auth_agent_hours SMALLINT(5) default '0'; + +UPDATE system_settings SET db_schema_version='1698',db_schema_update_date=NOW() where db_schema_version < 1698; diff --git a/agc_2-X/trunk/www/agc/css/style.css b/agc_2-X/trunk/www/agc/css/style.css index bbe14745..4e3ff056 100644 --- a/agc_2-X/trunk/www/agc/css/style.css +++ b/agc_2-X/trunk/www/agc/css/style.css @@ -35,6 +35,12 @@ div.text_input { overflow: auto; font-size: 10px; font-family: sans-serif; } animation: blink .75s linear infinite; } +.adminmenu_style_selected + { + background-color: white; + } +.adminmenu_style_selected:hover{background-color: #E6E6E6;} + @-webkit-keyframes blink { 0% { opacity: 1; } 50% { opacity: 1; } diff --git a/agc_2-X/trunk/www/agc/images/2FA_icon.png b/agc_2-X/trunk/www/agc/images/2FA_icon.png new file mode 100644 index 0000000000000000000000000000000000000000..c77b11d32599bc732ce71ba2b9e4dc1b3112b990 GIT binary patch literal 1215 zcmV;w1VHWFU8GbZ8()Nlj2>E@cM*00bjRL_t(o!_C=ih?P|o z2H?lWNmCos?xmC^L6A{-iL8($#4dFI6JfK zpn|BZq@i-itVGSbHqOlH&wJqGaL&v*#^_f4p!kW>_S&wMt=8TTfIPAFcUXp1bQ=XG>*gMyu`lPZ|KCP zq)6F1@g%m^<76xr_47IRSL;o_SKY1E`UWfccVSe$Ko#<4FsxK-(=^L=;LmXAa2$!_ zo8`P2K$qfU{EW@nxh)tIpy%LnoY3shkHbrKB>uO!7L)q%cPM7W=bnCi?g;HQEu!z@ z(U7@B?lMfp`0(ReEXOi@mAR|&STw_n-M0jy)0QR68yRk8;F{|MJmdtG^ zqKyLm0aG%s4J!kvzckqpRaLgYn@v?-V|61y4{9JKKEoGr zxFBV=k-~6Tq~GL#ZckL}){*tvC-^=5czpy)f7XLnF&%H@<;wZmj-Aa0x)(oX;fn&c z45X*VGu?O%_uw0RomxI8&##RLDK!)5-%&bnW^`oFOYj@R~w`1^l1#N7@+>GCwNR<-R*#*IUT_P?Z zS5~2*6$P=fBA|=wOsf}YEAFhaz-<{n9qS7H9oZm7s|B)zN5UARv!RM(n;KPIS5{e| zy|CNcDi&G3{;L{o)*N37czjsuOcl2?Nt7Noxin&=-V*w9Zcya-yrp8i2R9Am=Hsp!3oa}$z$|>w z55P`5h@mwb<8YF8Ab#>MNxH}v=cc}c~Fem4y?G=)3VWGwk8EeA>iC}v{5)N5A dHlUko{{vFgCr$twpTqzF002ovPDHLkV1m*YJumH1p*3JL`03B&m zSad^gZEa<4bN~PV002XBWnpw>WFU8GbZ8()Nlj2>E@cM*00fIkL_t(o!_Ap%h?P|o zhM(;?Ickl0OG~Xx34)BuG}1znkjl_5{>+k!jOa#`1a`sdM_E{5<)5Gknl6|WmXv50 zLW}B07fs9ZLTV-6#_Ke)q=>6`>AM=c?1` ziBNl~XQ?aw7YEgOYHd#<*OI!1)G6wz#gC_GrkRYDy7tz=d%t_7u!8(SErWZ)vL@{O*fs*BS62rM9IWW zx17~dgT1Th;1I9_I2d+^0wbzryc$GT0v`bzfW1IdgwBaU^b%kua7K3#{SH_Ne3eq# z(!t^U5O@Q)8Mrkv$#En4F7Q}NX?>6x0n7l#1A`(zZUt5Yt5Ql|tLuSvz~jJ>YE+$p z>PsD@kY(zbF}GHIQr)aJs?BPf+NvH^cSrr7lCgh#%q@jOxdlxpM1NGr#k_j;(;(Ct zcB!*7KAu;b{!gMesVQpx>e#uw*r(3S_*hp7(Owlq#pl4e!Uh zKA<5oL@rc9^kZO)Iuy7u1WIRU16~6r0B^?P3h~+i9IiIe7T~9pQX6npB=Z81wleRu z0xPsE!A22!H1S zC&j!i)h2p0BgX~;Cjgs(St+F%z@iM@7jmyhJV1 zhy<~kjKXP)qUpwFlx`(E%x1a0KLaaLN{55w!pz|*;MZ6z!0APsC9pql9<5dHE|KHzi09|2+cV>v z)M-UFCPXnPg-6x8xD;+JdbTIZaqcpDT?q#bk(!AA+l$Cv9mQax`dJy0JJm^HV^$=1 zi|nLIh)z^@6dBpCUJ=j7mAD@N7FU=x9aN`>)w-~;B6L9kZR)a0g~`YeAEgAzDKY1o z5F>f3rN%#^HiOLqVOQzTXMKZR$hnuz2UWlH&H>y9V@2L+&81;#{lhn0k7PPply0kWS&oX4+R>u@wvq!08)Y0m& zZ0{+WXB*1cYg9)ci-;blep$wNOQe?<)C+b=3oa}`MLRwq}TWKkF_iH>qtu`vY8acShJ1p+Goi2DEl03B&m zSad^gZEa<4bN~PV002XBWnpw>WFU8GbZ8()Nlj2>E@cM*00crwL_t(o!|j+`h*eb> z$A9~rGjm3L@Ra5)ykH?^;)9omF(gGHrF>8$Ba|WrL8u^z1QkRSeenX3D3ORyLOu-& zDkXuHL4=TE7fJ-Fyp1|Gf47L8Z6@sP#{_(*f53|w>|W&%gG{vVCsn*V|j=G?6bg8x46t(z^TqZvz0} zMc^k-AI|`DG`|z*)_3Rj4kU@*IqP06dP@3N%;Bheq_3{c2A&ZiZNNV1;cehJuw3U1 z83}Y}F_bsNf$P9uG5wn6x)M0M+vu{BRHuM+==}xYQj9blS2tu0kriO9bk^?^6hdzq zs~Bw8i4MA?~MN|Bt)Y9Mh}yKo^?LE&|qXbWGHqK z)lnM@}06msM zbgm4)tX@jt;$+}Ng1@x=vSNMEfU)PQ0svkzp|e^8WFN39MbA??SC3L#kQ)^9qYQp? zqt>+LF`8l>d8!px1^C2(8At%>^3YvcS8haf?ZEqT(n*Pk1^GPir2!KraM6L^o7Z1j z{rJGtMjsoo1RhcDeHHLaiauJ9J56a4gkKo(tKkl+B7XPSl~NlXaEG zfpIajfbR|Ujw?HqY>f5RE|lvDYlu2hdF{rx@`5aw9Q3AVrFVhXG`~;j*Cy3H=aiSG z`Nuwuzna1?ciUsYIqH7|o>lI7%HvKoLs>Ft_Uu%KpSx9nuS{qQO(-jh1HWb9T9WID zfGxm?M&tAEo-T&k7~nl4wt9-Y&|D_8H!IZrU=FzfER)_I%u$89e|x3JZz?8Wtaz~{zTN=>+bO-#qyjkRa#{VJP3 zGnHjgfgl(TfVM3G-qlrLSzIofLai#}x(S@rwa*Qc=vH&yIM)R<@D7=w`eu~5;ObU# zd&{e#!kCJ4*c0Az2K{Q4h#yK89;D0#-u-%H?x!9q_x?BSUxbtVCa{$DNB{r;07*qo IM6N<$f`E)c2mk;8 literal 0 HcmV?d00001 diff --git a/agc_2-X/trunk/www/agc/images/icon_chat.png b/agc_2-X/trunk/www/agc/images/icon_chat.png new file mode 100644 index 0000000000000000000000000000000000000000..a5ba95b05c585f4353e3135452b4c22c95957c62 GIT binary patch literal 802 zcmV+-1Ks?IP)WFU8GbZ8()Nlj2>E@cM*00M?dL_t(o!|m8fYm-qF z#_?a9Y8|j>s})p4L_ut&D(F%W9KekW5kx_7rEUa2f-c^qF_^_?UDQNt;&$O zoV^*nc?eX#&Ba#CNN7@aU{iin3xTe{>N1YkQmrxSV`eeX6jtUxlt5J5@_TE2fmB$8 zhJ?jZGv*ZotwU3SuYK^K`H!Q17!ffMY@k>~bG2kj;q^#;^Z{-q7|mW>#*fkTv0Zqd&Ts`AG6BY zHugpyjTbPD$2f*HqgC?_C8R*p2#e-m>I(dp#^(U+!bRMV>mKC=JnHTM65eb zjkA+fFs(RoIR5f54iWJW}Y>$NR!dpBIWph7dSl>jr$ZZKv$K>dZ g?-@0#SWFU8GbZ8()Nlj2>E@cM*00Rg~L_t(o!|m8#sAXdq z2JqjRvoXe*p+;l~7gEX*$s{4A$e>11lIF@xDOaQ1xWI)ADH0RY6cP z_c(6Dl~{#kOU!2)zu*hJhlwV_cj0qPqK(b~RvR-oj8|}JN%V4j)N(xac9I5yzgC|F`NYZhCIyqqrn|AD7*aUb30CcJ~GhGMGn^;m>z zBzhd5;-@0P|H7-dxxCoEp>>PAomp!h>X53M$ z>`o5)eAGO2qG9Q#Xz6K>;nzZyqiJ_nG+4`ed{R@WipH0?FSb}m&!I0dmO|TIIKmX( zjpdA_?QO!h4bQ!go4X7=J%_%jQ*Fa<$U@L^yrX8=ShKVS1FbCX%AA2$1R*$CL!ADVc0{13tBT=>f+&;Vzr4RPn zC0Z7SU3ffXH-=;t>Na-bIlP{HGbo~>*i-l!cV}GdU{9>)!+wm3{U9nKeKEOPwbo-9 zX8MAD5v@YKf3YU(rM|okiT-cUs`*`~W-X%&9F7+<`7bMc_+La1*N861y7cw-5)&QE zTv~}VnKesvSFRc>YXkGT0V!I)Xzt0CXcp(=jba=d^!gKzRAP?SLjQgG^_rY&5QSEK zA=#T7!PZ3jKLxWI*W~K3asUN2leu9>*5vRz<`6@itoR3HpIqF-P7`SW0000 0) {mysql_error_logging($NOW_TIME,$link,$mel,$stmt,'00594',$user,$server_ip,$session_name,$one_mysql_log);} if ($DB) {echo "$stmt\n";} @@ -2203,6 +2204,18 @@ if ($ACTION == 'update_settings') $manual_dial_timeout = trim("$row[10]"); $in_man_dial_next_ready_seconds = trim("$row[11]"); $in_man_dial_next_ready_seconds_override = trim("$row[12]"); + $campaign_cid = trim("$row[13]"); + $omit_phone_code = trim("$row[14]"); + $use_internal_dnc = trim("$row[15]"); + $use_campaign_dnc = trim("$row[16]"); + $dial_prefix = trim("$row[17]"); + $manual_dial_prefix = trim("$row[18]"); + $three_way_dial_prefix = trim("$row[19]"); + + if (strlen($manual_dial_prefix) < 1) + {$manual_dial_prefix = $dial_prefix;} + if (strlen($three_way_dial_prefix) < 1) + {$three_way_dial_prefix = $dial_prefix;} } if ( ($manual_dial_timeout < 1) or (strlen($manual_dial_timeout) < 1) ) @@ -2262,6 +2275,13 @@ if ($ACTION == 'update_settings') $SettingS_InfO .= "wrapup_after_hotkey: " . $wrapup_after_hotkey . "\n"; $SettingS_InfO .= "manual_dial_timeout: " . $manual_dial_timeout . "\n"; $SettingS_InfO .= "in_man_dial_next_ready_seconds: " . $in_man_dial_next_ready_seconds . "\n"; + $SettingS_InfO .= "campaign_cid: " . $campaign_cid . "\n"; + $SettingS_InfO .= "omit_phone_code: " . $omit_phone_code . "\n"; + $SettingS_InfO .= "use_internal_dnc: " . $use_internal_dnc . "\n"; + $SettingS_InfO .= "use_campaign_dnc: " . $use_campaign_dnc . "\n"; + $SettingS_InfO .= "dial_prefix: " . $dial_prefix . "\n"; + $SettingS_InfO .= "dial_manual_prefix: " . $manual_dial_prefix . "\n"; + $SettingS_InfO .= "dial_three_way_prefix: " . $three_way_dial_prefix . "\n"; $SettingS_InfO .= "\n"; } echo $SettingS_InfO; diff --git a/agc_2-X/trunk/www/agc/vicidial.php b/agc_2-X/trunk/www/agc/vicidial.php index 6ca25488..f49c14a4 100644 --- a/agc_2-X/trunk/www/agc/vicidial.php +++ b/agc_2-X/trunk/www/agc/vicidial.php @@ -725,10 +725,12 @@ # 230615-0842 - Added dead_stop_recording feature # 230810-1652 - Added force_per_call_notes campaign setting # 230927-2036 - Added agent_search_ingroup_list campaign and agent_search_list ingroup options +# 231108-0820 - Added several fields to update_settings related to manual dial calls +# 231109-0827 - Added 2FA for agent screen logins # -$version = '2.14-692c'; -$build = '230927-2036'; +$version = '2.14-693c'; +$build = '231109-0827'; $php_script = 'vicidial.php'; $mel=1; # Mysql Error Log enabled = 1 $mysql_log_count=103; @@ -780,6 +782,12 @@ if (isset($_GET["new_pass1"])) {$new_pass1=$_GET["new_pass1"];} elseif (isset($_POST["new_pass1"])) {$new_pass1=$_POST["new_pass1"];} if (isset($_GET["new_pass2"])) {$new_pass2=$_GET["new_pass2"];} elseif (isset($_POST["new_pass2"])) {$new_pass2=$_POST["new_pass2"];} +if (isset($_GET["stage"])) {$stage=$_GET["stage"];} + elseif (isset($_POST["stage"])) {$stage=$_POST["stage"];} +if (isset($_GET["rank"])) {$rank=$_GET["rank"];} + elseif (isset($_POST["rank"])) {$rank=$_POST["rank"];} +if (isset($_GET["auth_entry"])) {$auth_entry=$_GET["auth_entry"];} + elseif (isset($_POST["auth_entry"])) {$auth_entry=$_POST["auth_entry"];} if (!isset($phone_login)) { @@ -804,6 +812,9 @@ if (!isset($flag_channels)) $DB=preg_replace("/[^0-9a-z]/","",$DB); $VD_login = preg_replace('/[^-_0-9\p{L}]/u','',$VD_login); +$stage = preg_replace('/[^-_0-9\p{L}]/u','',$stage); +$rank = preg_replace('/[^-_0-9\p{L}]/u','',$rank); +$auth_entry = preg_replace('/[^-_0-9\p{L}]/u','',$auth_entry); $forever_stop=0; @@ -828,7 +839,7 @@ $random = (rand(1000000, 9999999) + 10000000); ############################################# ##### START SYSTEM_SETTINGS AND USER LANGUAGE LOOKUP ##### -$stmt = "SELECT use_non_latin,vdc_header_date_format,vdc_customer_date_format,vdc_header_phone_format,webroot_writable,timeclock_end_of_day,vtiger_url,enable_vtiger_integration,outbound_autodial_active,enable_second_webform,user_territories_active,static_agent_url,custom_fields_enabled,pllb_grouping_limit,qc_features_active,allow_emails,callback_time_24hour,enable_languages,language_method,meetme_enter_login_filename,meetme_enter_leave3way_filename,enable_third_webform,default_language,active_modules,allow_chats,chat_url,default_phone_code,agent_screen_colors,manual_auto_next,agent_xfer_park_3way,admin_web_directory,agent_script,agent_push_events,agent_push_url,agent_logout_link,agentonly_callback_campaign_lock,manual_dial_validation,mute_recordings,enable_second_script,enable_first_webform,recording_buttons,outbound_cid_any,browser_call_alerts,manual_dial_phone_strip,require_password_length,pass_hash_enabled,agent_hidden_sound_seconds,agent_hidden_sound,agent_hidden_sound_volume,agent_screen_timer,agent_hide_hangup,allow_web_debug,max_logged_in_agents,login_kickall,agent_notifications,inbound_credits FROM system_settings;"; +$stmt = "SELECT use_non_latin,vdc_header_date_format,vdc_customer_date_format,vdc_header_phone_format,webroot_writable,timeclock_end_of_day,vtiger_url,enable_vtiger_integration,outbound_autodial_active,enable_second_webform,user_territories_active,static_agent_url,custom_fields_enabled,pllb_grouping_limit,qc_features_active,allow_emails,callback_time_24hour,enable_languages,language_method,meetme_enter_login_filename,meetme_enter_leave3way_filename,enable_third_webform,default_language,active_modules,allow_chats,chat_url,default_phone_code,agent_screen_colors,manual_auto_next,agent_xfer_park_3way,admin_web_directory,agent_script,agent_push_events,agent_push_url,agent_logout_link,agentonly_callback_campaign_lock,manual_dial_validation,mute_recordings,enable_second_script,enable_first_webform,recording_buttons,outbound_cid_any,browser_call_alerts,manual_dial_phone_strip,require_password_length,pass_hash_enabled,agent_hidden_sound_seconds,agent_hidden_sound,agent_hidden_sound_volume,agent_screen_timer,agent_hide_hangup,allow_web_debug,max_logged_in_agents,login_kickall,agent_notifications,inbound_credits,two_factor_auth_agent_hours,two_factor_container FROM system_settings;"; $rslt=mysql_to_mysqli($stmt, $link); if ($mel > 0) {mysql_error_logging($NOW_TIME,$link,$mel,$stmt,'01001',$VD_login,$server_ip,$session_name,$one_mysql_log);} #if ($DB) {echo "$stmt\n";} @@ -892,6 +903,8 @@ if ($qm_conf_ct > 0) $SSlogin_kickall = $row[53]; $SSagent_notifications = $row[54]; $SSinbound_credits = $row[55]; + $SStwo_factor_auth_hours = $row[56]; + $SStwo_factor_container = $row[57]; if ( ($SSagent_hidden_sound == '---NONE---') or ($SSagent_hidden_sound == '') ) {$SSagent_hidden_sound_seconds=0;} } else @@ -1006,7 +1019,7 @@ $conf_check_attempts = '3'; # number of attempts to try before loosing webserver $focus_blur_enabled = '0'; # set to 1 to enable the focus/blur enter key blocking(some IE instances have issues) $consult_custom_delay = '2'; # number of seconds to delay consultative transfers when customfields are active $mrglock_ig_select_ct = '4'; # number of seconds to leave in-group select screen open if agent select is disabled -$link_to_grey_version = '1'; # show link to old grey version of agent screen at login screen, next to timeclock link +$link_to_grey_version = '0'; # show link to old grey version of agent screen at login screen, next to timeclock link $no_empty_session_warnings=0; # set to 1 to disable empty session warnings on agent screen $logged_in_refresh_link = '0'; # set to 1 to allow clickable "Logged in as..." link at top to force Javascript refresh $webphone_call_seconds = '0'; # set to 1 or higher to have the agent phone(if set to webphone) called X seconds after login @@ -1750,6 +1763,587 @@ else if($auth>0) { + # check for 2FA being active, and if so, see if there is a non-expired 2FA auth + $VALID_2FA=1; + + if ( ($SStwo_factor_auth_hours > 0) and ($SStwo_factor_container != '') and ($SStwo_factor_container != '---DISABLED---') ) + { + $stmt="SELECT count(*) from vicidial_two_factor_auth where user='$VD_login' and auth_stage='1' and auth_exp_date > NOW();"; + if ($DB) {echo "$stmt\n";} + $rslt=mysql_to_mysqli($stmt, $link); + if ($mel > 0) {mysql_error_logging($NOW_TIME,$link,$mel,$stmt,'01XXX',$VD_login,$server_ip,$session_name,$one_mysql_log);} + $auth_check_to_print = mysqli_num_rows($rslt); + if ($auth_check_to_print < 1) + {$VALID_2FA=0;} + else + { + $row=mysqli_fetch_row($rslt); + $VALID_2FA = $row[0]; + } + } + if ($VALID_2FA < 1) + { + $subhead_font = "style=\"font-family:HELVETICA;font-size:14;color:BLACK;font-weight:bold;\""; + + echo "\"Two-Factor-Authentication\" "._QXZ("Two-Factor-Authentication"),"
\n"; + + if ( ($SStwo_factor_auth_hours < 1) or ($SStwo_factor_container == '') or ($SStwo_factor_container == '---DISABLED---') ) + { + echo _QXZ("Two-Factor-Authentication is disabled on your system. Please contact your system administrator")." $SStwo_factor_auth_hours|$SStwo_factor_container\n"; + exit; + } + + $stmt="SELECT full_name,email,mobile_number,user_group from vicidial_users where user='$VD_login' and active='Y' and api_only_user != '1';"; + $rslt=mysql_to_mysqli($stmt, $link); + if ($mel > 0) {mysql_error_logging($NOW_TIME,$link,$mel,$stmt,'01XXX',$VD_login,$server_ip,$session_name,$one_mysql_log);} + $row=mysqli_fetch_row($rslt); + $LOGfullname = $row[0]; + $LOGemail = $row[1]; + $LOGmobile_number = $row[2]; + $LOGuser_group = $row[3]; + $OBSCUREemail = $LOGemail; + $OBSCUREmobile_number = $LOGmobile_number; + + # first character and last 6 characters + $temp_emailARY = explode('@',$OBSCUREemail); + $field_temp_val = $temp_emailARY[0]; + $OBSCUREemail = substr($field_temp_val,0,2) . str_repeat(".", (strlen($field_temp_val) - 2)) . '@' . $temp_emailARY[1]; + # first 3 digits and last 2 digits + $field_temp_val = $OBSCUREmobile_number; + $OBSCUREmobile_number = substr($field_temp_val,0,3) . str_repeat("x", (strlen($field_temp_val) - 5)) . substr($field_temp_val,-2,2); + + ### BEGIN Gather 2FA settings container details ### + $valid_2FA_config=0; + $active_2FA_methods=0; + $auth_code_expire_minutes='30'; + $auth_code_attempts='10'; + $auth_code_length='6'; + $email_auth=''; + $email_from=''; + $email_subject=''; + $email_message=''; + $phone_auth=''; + $phone_prefix=''; + $phone_server_ip=''; + $phone_cid_number=''; + $phone_message_override=''; + $sms_auth=''; + $sms_cid_number=''; + $sms_url=''; + $stmt = "SELECT container_entry FROM vicidial_settings_containers where container_id='$SStwo_factor_container';"; + $rslt=mysql_to_mysqli($stmt, $link); + $SCinfo_ct = mysqli_num_rows($rslt); + if ($DB) {echo "$SCinfo_ct|$stmt\n";} + if ($SCinfo_ct > 0) + { + $row=mysqli_fetch_row($rslt); + $TFAcontainer_entry = $row[0]; + $TFAcontainer_entry = preg_replace("/\r|\t|\'|\"/",'',$TFAcontainer_entry); + $TFAcontainer_entry = preg_replace("/ => | =>|=> /",'=>',$TFAcontainer_entry); + $two_factor_settings = explode("\n",$TFAcontainer_entry); + $two_factor_settings_ct = count($two_factor_settings); + $tfal=0; + while ($two_factor_settings_ct >= $tfal) + { + if (preg_match("/^auth_code_expire_minutes=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/auth_code_expire_minutes=>/",'',$two_factor_settings[$tfal]); + $auth_code_expire_minutes = $two_factor_settings[$tfal]; + } + if (preg_match("/^auth_code_attempts=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/auth_code_attempts=>/",'',$two_factor_settings[$tfal]); + $auth_code_attempts = $two_factor_settings[$tfal]; + } + if (preg_match("/^auth_code_length=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/auth_code_length=>/",'',$two_factor_settings[$tfal]); + $auth_code_length = $two_factor_settings[$tfal]; + } + if (preg_match("/^email_auth=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/email_auth=>/",'',$two_factor_settings[$tfal]); + $email_auth = $two_factor_settings[$tfal]; + $active_2FA_methods++; + } + if (preg_match("/^email_from=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/email_from=>/",'',$two_factor_settings[$tfal]); + $email_from = $two_factor_settings[$tfal]; + $valid_2FA_config++; + } + if (preg_match("/^email_subject=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/email_subject=>/",'',$two_factor_settings[$tfal]); + $email_subject = $two_factor_settings[$tfal]; + } + if (preg_match("/^email_message=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/email_message=>/",'',$two_factor_settings[$tfal]); + $email_message = $two_factor_settings[$tfal]; + } + if (preg_match("/^phone_auth=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/phone_auth=>/",'',$two_factor_settings[$tfal]); + $phone_auth = $two_factor_settings[$tfal]; + $active_2FA_methods++; + } + if (preg_match("/^phone_prefix=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/phone_prefix=>/",'',$two_factor_settings[$tfal]); + $phone_prefix = $two_factor_settings[$tfal]; + } + if (preg_match("/^phone_server_ip=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/phone_server_ip=>/",'',$two_factor_settings[$tfal]); + $phone_server_ip = $two_factor_settings[$tfal]; + $valid_2FA_config++; + } + if (preg_match("/^phone_cid_number=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/phone_cid_number=>/",'',$two_factor_settings[$tfal]); + $phone_cid_number = $two_factor_settings[$tfal]; + } + if (preg_match("/^phone_message_override=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/phone_message_override=>/",'',$two_factor_settings[$tfal]); + $phone_message_override = $two_factor_settings[$tfal]; + } + if (preg_match("/^sms_auth=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/sms_auth=>/",'',$two_factor_settings[$tfal]); + $sms_auth = $two_factor_settings[$tfal]; + $active_2FA_methods++; + } + if (preg_match("/^sms_cid_number=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/sms_cid_number=>/",'',$two_factor_settings[$tfal]); + $sms_cid_number = $two_factor_settings[$tfal]; + } + if (preg_match("/^sms_url=>/",$two_factor_settings[$tfal])) + { + $two_factor_settings[$tfal] = preg_replace("/sms_url=>/",'',$two_factor_settings[$tfal]); + $sms_url = $two_factor_settings[$tfal]; + $valid_2FA_config++; + } + + $tfal++; + } + } + ### END Gather 2FA settings container details ### + if ( ($valid_2FA_config < 1) or ($active_2FA_methods < 1) ) + { + echo "
"._QXZ("Two-Factor-Authentication is not properly configured on your system. Please contact your system administrator")."

$valid_2FA_config|$SStwo_factor_auth_hours|$SStwo_factor_container

\n"; + exit; + } + if ( (strlen($LOGemail) < 4) and (strlen($LOGmobile_number) < 2) ) + { + echo _QXZ("Your User account is not configured for Two-Factor-Authentication. Please contact your system administrator. (no email or mobile number)").".\n"; + exit; + } + + $show_form=1; + if ( ($stage=='SUBMIT') or ($stage==_QXZ("SUBMIT")) ) + { + $auth_fail=0; + echo "
"; + if (strlen($rank) < 2) + { + echo _QXZ("Please go back and enter a valid authorization code")." |1|" . strlen($rank) . "|"; $auth_fail++; + } + else + { + $stmt="SELECT count(*) from vicidial_two_factor_auth where user='$VD_login' and auth_code='$rank' and auth_stage='0' and auth_code_exp_date > NOW() and (auth_attempts < $auth_code_attempts);"; + $rslt=mysql_to_mysqli($stmt, $link); + if ($DB) {echo "$stmt\n";} + $auth_check_to_print = mysqli_num_rows($rslt); + if ($auth_check_to_print < 1) + {echo _QXZ("Please go back and enter a valid authorization code")." |2|$auth_check_to_print"; $auth_fail++;} + else + { + $row=mysqli_fetch_row($rslt); + if ($row[0] < 1) + {echo _QXZ("Please go back and enter a valid authorization code")." |3|$row[0]"; $auth_fail++;} + else + { + $stmt="UPDATE vicidial_two_factor_auth SET auth_stage='1', auth_attempts=(auth_attempts + 1) where user='$VD_login' and auth_stage='0' and auth_code='$rank';"; + $rslt=mysql_to_mysqli($stmt, $link); + + $stmt = "INSERT INTO vicidial_agent_function_log set agent_log_id='0',user='$VD_login',function='2FA_good',event_time=NOW(),campaign_id='-ADMIN-',user_group='$LOGuser_group',lead_id='0',uniqueid='SUCCESS',caller_code='$ip',stage='',comments='';"; + if ($DB) {echo "|$stmt|\n";} + $rslt=mysql_to_mysqli($stmt, $link); + + echo _QXZ("Authorization code accepted, you may now continue")."

\n"; + + echo ""._QXZ("Agent web client: 2FA Auth")."\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "$DBoutput"; + echo "
\n"; + echo "
\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + # echo "\n"; + echo "\n"; + echo "


"; + echo ""; + echo "\n"; + echo "\n"; + echo "\n"; + echo "
\"Agent
  \n"; + echo "

"._QXZ("VERSION:")." $version       "._QXZ("BUILD:")." $build
\n"; + echo "\n\n"; + echo "\n\n"; + echo "$LoginLoadingBox"; + echo "
\n"; + echo "$INSERT_before_body_close"; + echo "\n\n"; + echo "\n\n"; + exit; + } + } + } + if ($auth_fail > 0) + { + $stmt="UPDATE vicidial_two_factor_auth SET auth_attempts=(auth_attempts + 1) where user='$VD_login' and auth_stage='0';"; + $rslt=mysql_to_mysqli($stmt, $link); + + $auth_failed_attempts=1; + $stmt="SELECT auth_attempts from vicidial_two_factor_auth where user='$VD_login' and auth_stage='0' order by auth_code_exp_date desc limit 1;"; + $rslt=mysql_to_mysqli($stmt, $link); + if ($DB) {echo "$stmt\n";} + $auth_attempt_to_print = mysqli_num_rows($rslt); + if ($auth_attempt_to_print > 0) + { + $row=mysqli_fetch_row($rslt); + $auth_failed_attempts = $row[0]; + } + if ($auth_failed_attempts >= $auth_code_attempts) + { + $stmt="UPDATE vicidial_users set failed_login_count='$auth_failed_attempts',last_ip='$ip' where user='$VD_login';"; + $rslt=mysql_to_mysqli($stmt, $link); + } + } + echo "
\n"; + exit; + } + + ##### BEGIN send out AUTH CODE and show auth-code entry page ##### + if ($auth_entry > 0) + { + $ACbegin = '1'; + $ACend = '9'; + $i=1; + while($i < $auth_code_length) + { + $ACbegin .= '0'; + $ACend .= '9'; + $i++; + } + $NEWauth_code = rand($ACbegin, $ACend); + $auth_exp_date = date("Y-m-d H:i:s", mktime(date("H")+$SStwo_factor_auth_hours,date("i"),date("s"),date("m"),date("d"),date("Y"))); + $auth_code_exp_date = date("Y-m-d H:i:s", mktime(date("H"),date("i")+$auth_code_expire_minutes,date("s"),date("m"),date("d"),date("Y"))); + + ### insert auth_code into vicidial_two_factor_auth table + $stmt="INSERT INTO vicidial_two_factor_auth SET auth_date=NOW(),auth_exp_date='$auth_exp_date',user='$VD_login',auth_stage='0',auth_code='$NEWauth_code',auth_code_exp_date='$auth_code_exp_date',auth_method='$stage',auth_attempts='0';"; + $rslt=mysql_to_mysqli($stmt, $link); + $affected_rows = mysqli_affected_rows($link); + if ($DB) {echo "$affected_rows|$stmt\n";} + + # invalidate all older auth_code entries + if ($affected_rows > 0) + { + $stmt="UPDATE vicidial_two_factor_auth SET auth_stage='6' where user='$VD_login' and auth_stage!='6' and auth_code!='$NEWauth_code';"; + $rslt=mysql_to_mysqli($stmt, $link); + $affected_rows = mysqli_affected_rows($link); + if ($DB) {echo "$affected_rows|$stmt\n";} + } + + ### Send auth code by EMAIL + if ($stage == 'EMAIL') + { + $email_message = preg_replace('/--A--auth_code--B--/i',"$NEWauth_code",$email_message); + + // To send HTML mail, the Content-type header must be set + $headers = 'MIME-Version: 1.0' . "\r\n"; + $headers .= 'Content-type: text/html; charset=iso-8859-1' . "\r\n"; + + // Create email headers + $headers .= 'From: ' . $email_from . "\r\n" . 'Reply-To: ' . $email_from . "\r\n" . 'X-Mailer: PHP/' . phpversion(); + + $body = "" . $email_message . ""; + + $success = mail($LOGemail, $email_subject, $body, $headers ); + if ($success) + { + $stmt = "INSERT INTO vicidial_agent_function_log set agent_log_id='0',user='$VD_login',function='2FA_send',event_time=NOW(),campaign_id='-ADMIN-',user_group='$LOGuser_group',lead_id='0',uniqueid='SUCCESS',caller_code='$ip',stage='$stage',comments='EMAIL: $LOGemail';"; + + echo "
"._QXZ("Your authorization code has been sent by %1s to",0,'',$stage).": $OBSCUREemail
\n"; + } + else + { + $stmt = "INSERT INTO vicidial_agent_function_log set agent_log_id='0',user='$VD_login',function='2FA_send',event_time=NOW(),campaign_id='-ADMIN-',user_group='$LOGuser_group',lead_id='0',uniqueid='ERROR',caller_code='$ip',stage='$stage',comments='EMAIL: $LOGemail';"; + + $error_msg = error_get_last()['message']; + echo "$error_msg"; + } + + ### LOG INSERTION Admin Log Table ### + if ($DB) {echo "|$stmt|\n";} + $rslt=mysql_to_mysqli($stmt, $link); + } + + ### Send auth code by PHONE + if ($stage == 'PHONE') + { + $context_2FA = '2FA_say_auth_code'; + if (strlen($phone_message_override) > 0) {$context_2FA = $phone_message_override;} + if (strlen($ext_context) < 1) {$ext_context='default';} + $local_DEF = 'Local/'; + $local_AMP = '@'; + $Local_dial_timeout = '60000'; + $Ndialstring = "$phone_prefix$LOGmobile_number"; + $VMvariable = "Variable: access_code=$NEWauth_code"; + ### insert a NEW record to the vicidial_manager table to be processed + $stmtB = "INSERT INTO vicidial_manager(uniqueid,entry_date,status,response,server_ip,channel,action,callerid,cmd_line_b,cmd_line_c,cmd_line_d,cmd_line_e,cmd_line_f,cmd_line_g,cmd_line_h,cmd_line_i,cmd_line_j,cmd_line_k) values('',NOW(),'NEW','N','$phone_server_ip','','Originate','$VqueryCID','Exten: s','Context: $context_2FA','Channel: $local_DEF$Ndialstring$local_AMP$ext_context','Priority: 1','Callerid: $phone_cid_number','Timeout: $Local_dial_timeout','$VMvariable','','','')"; + $rslt=mysql_to_mysqli($stmtB, $link); + + $stmt = "INSERT INTO vicidial_agent_function_log set agent_log_id='0',user='$VD_login',function='2FA_send',event_time=NOW(),campaign_id='-ADMIN-',user_group='$LOGuser_group',lead_id='0',uniqueid='SUCCESS',caller_code='$ip',stage='$stage',comments='PHONE: $LOGmobile_number';"; + if ($DB) {echo "|$stmt|\n";} + $rslt=mysql_to_mysqli($stmt, $link); + + echo "
"._QXZ("Your authorization code has been sent by %1s to",0,'',$stage).": $OBSCUREmobile_number
\n"; + } + + ### Send auth code by SMS + if ($stage == 'SMS') + { + $sms_url = preg_replace('/--A--auth_code--B--/i',"$NEWauth_code",$sms_url); + $sms_url = preg_replace('/--A--mobile_number--B--/i',"$LOGmobile_number",$sms_url); + + ### insert a new url log entry + $SQL_log = "$sms_url"; + $SQL_log = preg_replace('/;/','',$SQL_log); + $SQL_log = addslashes($SQL_log); + $stmt = "INSERT INTO vicidial_url_log SET uniqueid='2FA',url_date=NOW(),url_type='2FA_SMS',url='$SQL_log',url_response='';"; + # if ($DB) {echo "$stmt\n";} + $rslt=mysql_to_mysqli($stmt, $link); + $affected_rows = mysqli_affected_rows($link); + $url_id = mysqli_insert_id($link); + + $URLstart_sec = date("U"); + + ### grab the call_start_url ### + # if ($DB > 0) {echo "$sms_url
\n";} + $SCUfile = file("$sms_url"); + if ( !($SCUfile) ) + { + $error_array = error_get_last(); + $error_type = $error_array["type"]; + $error_message = $error_array["message"]; + $error_line = $error_array["line"]; + $error_file = $error_array["file"]; + } + + if ($DB > 0) {echo "$SCUfile[0]
\n";} + + ### update url log entry + $URLend_sec = date("U"); + $URLdiff_sec = ($URLend_sec - $URLstart_sec); + if ($SCUfile) + { + $SCUfile_contents = implode("", $SCUfile); + $SCUfile_contents = preg_replace('/;/','',$SCUfile_contents); + $SCUfile_contents = addslashes($SCUfile_contents); + } + else + { + $SCUfile_contents = "PHP ERROR: Type=$error_type - Message=$error_message - Line=$error_line - File=$error_file"; + } + $stmt = "UPDATE vicidial_url_log SET response_sec='$URLdiff_sec',url_response='$SCUfile_contents' where url_log_id='$url_id';"; + if ($DB) {echo "$stmt\n";} + $rslt=mysql_to_mysqli($stmt, $link); + $affected_rows = mysqli_affected_rows($link); + + $stmt = "INSERT INTO vicidial_agent_function_log set agent_log_id='0',user='$VD_login',function='2FA_send',event_time=NOW(),campaign_id='-ADMIN-',user_group='$LOGuser_group',lead_id='0',uniqueid='SUCCESS',caller_code='$ip',stage='$stage',comments='SMS: $LOGmobile_number';"; + if ($DB) {echo "|$stmt|\n";} + $rslt=mysql_to_mysqli($stmt, $link); + + echo "
"._QXZ("Your authorization code has been sent by %1s to",0,'',$stage).": $OBSCUREmobile_number
\n"; + } + + echo ""._QXZ("Agent web client: 2FA Auth")."\n"; + echo "\n"; + echo "\n"; + + echo "
\n"; + echo "
\n"; + echo ""; + + echo "
\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + # echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + # echo "\n"; + echo "
\n"; + + echo "\n"; + + echo "\n"; + + + echo "\n"; + echo "
"._QXZ("Please enter the Auth Code that you have received by %1s into the field below, and click the SUBMIT button",0,'',$stage).". "._QXZ("To resend your auth code, click here to go back").".
 
"._QXZ("Authorization Code").":
\n"; + exit; + } + ##### END send out AUTH CODE and show auth-code entry page ##### + + ##### BEGIN choose how to send out AUTH CODE page ##### + else + { + if ($show_form > 0) + { + echo ""._QXZ("Agent web client: 2FA Auth")."\n"; + echo "\n"; + echo "\n"; + + echo "
\n"; + echo "
\n"; + echo ""; + + echo "
\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + # echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + echo "\n"; + # echo "\n"; + echo "
\n"; + + echo "\n"; + + echo "\n"; + + #echo "\n"; + echo "
"._QXZ("Your account has Two-Factor-Authorization enabled on it. In order to log in, you will need to verify your identity by submitting a temporary authorization code. Click on the icon below for the delivery method you would like to use to receive your authorization code").":

\n"; + + echo "\n"; + $displayed_2FA=0; + if ( (preg_match("/YES/i",$email_auth)) and (strlen($LOGemail) > 3) ) + { + echo " 0) {echo " onclick=\"send_2FA('EMAIL');\"";} echo ">\n"; + echo "\n"; + echo "\n"; + echo "\n"; + $displayed_2FA++; + } + if ( (preg_match("/YES/i",$phone_auth)) and (strlen($LOGmobile_number) > 1) ) + { + echo " 0) {echo " onclick=\"send_2FA('PHONE');\"";} echo ">\n"; + echo "\n"; + echo "\n"; + echo "\n"; + $displayed_2FA++; + } + if ( (preg_match("/YES/i",$sms_auth)) and (strlen($LOGmobile_number) > 1) ) + { + echo " 0) {echo " onclick=\"send_2FA('SMS');\"";} echo ">\n"; + echo "\n"; + echo "\n"; + echo "\n"; + $displayed_2FA++; + } + if ($displayed_2FA < 1) + { + echo _QXZ("Your User account is not configured for Two-Factor-Authentication. Please contact your system administrator").".\n"; + exit; + } + echo "
"._QXZ("Email you an auth code")."
"._QXZ("Send an email to").":
$OBSCUREemail
"._QXZ("Call you and play an auth code")."
"._QXZ("Place a phone call to").":
$OBSCUREmobile_number
"._QXZ("Text-Message you an auth code")."
"._QXZ("Send a message to").":
$OBSCUREmobile_number

 \n"; + + echo "
\n"; + exit; + } + } + ##### END choose how to send out AUTH CODE page ##### + } + if ($VUforce_change_password == 'Y') { echo "