LICENSE: AGPLv2
#
# CHANGES
#
# 60419-1705 - Added ability to change lead callback record from USERONLY to ANYONE or USERONLY-user
# 60421-1459 - check GET/POST vars lines with isset to not trigger PHP NOTICES
# 60609-1112 - Added DNC list addition if status changed to DNC
# 60619-1539 - Added variable filtering to eliminate SQL injection attack threat
# 61130-1639 - Added recording_log lookup and list for this lead_id
# 61201-1136 - Added recording_log user(TSR) display and link
# 70305-1133 - Changed to default CHECKED modify logs upon status change
# 70424-1128 - Added campaign-specific statuses, reformatted recordings list
# 70702-1259 - Added recording location link and truncation
# 70906-2132 - Added closer_log records display
# 80428-0144 - UTF8 cleanup
# 80501-0454 - Added Hangup Reason to logs display
# 80516-0936 - Cleanup of logging changes, added vicidial_agent_log display
# 80701-0832 - Changed to allow for altering of main phone number
# 80805-2106 - Changed comments to TEXTAREA
# 81210-1529 - Added server recording display options
# 90309-1829 - Added admin_log logging
# 90508-0644 - Changed to PHP long tags
# 90708-1549 - Added phone number dialed to outbound log
# 90721-1246 - Added rank and owner as vicidial_list fields
# 90917-2355 - Added extended alt phone entries
# 100405-1333 - Changed to show logs of non-found leads
# 100618-0148 - Added Middle name modify and fixes statuses list
# 100622-0945 - Added field labels
# 100703-1122 - Added custom fields display/edit
# 100712-1416 - Added entry_list_id field to vicidial_list to preserve link to custom fields if any
# 100924-1431 - Added Called Count display
# 101127-1610 - Added ability to set a scheduled callback date and time
# 110212-2041 - Added compatibility with definable scheduled callback statuses
# 110215-1411 - Added display of call notes to log records
# 110215-1717 - Changed empty lead_id behavior to be add-a-lead functionality
# 110525-1827 - Added ivr log records display
# 111103-1533 - Added admin_hide_phone_data and admin_hide_lead_data options
# 120223-2249 - Removed logging of good login passwords if webroot writable is enabled
# 120518-1004 - Fix for multi-line comments
# 120529-1635 - Added User Group Campaign-Lists validation
# 121116-1411 - Added QC functionality
# 121130-1033 - Changed scheduled callback user ID field to be 20 characters, issue #467
# 121222-2145 - Added email log
# 130123-1940 - Added options.php option to allow display of non-selectable statuses
# 130610-1049 - Finalized changing of all ereg instances to preg
# 130621-1731 - Added filtering of input to prevent SQL injection attacks and new user auth
# 130705-1726 - Minor change for encrypted password compatibility
# 130901-0816 - Changed to mysqli PHP functions
# 130926-2053 - Added option for viewing/modifying vicidial_list_archive leads
# 140125-1100 - Fixed issue with Callback records having no campaign_id
# 140304-2034 - Fixed issue with special characters in standard data fields
# 140706-0827 - Incorporated QC includes into code
# 140817-0937 - Added Archive Log search option
# 141001-2200 - Finalized adding QXZ translation to all admin files
# 141128-0859 - Code cleanup for QXZ functions
# 141229-1745 - Added code for on-the-fly language translations display
# 150107-1729 - Added ignore_group_on_search user option
# 150114-2321 - Added date_of_birth as editable field
# 150312-1506 - Fixed minor Iframe form bug related to custom fields
# 150514-1522 - Added $gmt_offset lookup for adding a new lead
# 150603-1527 - Allow non-digit characters in alt_phone field
# 150808-1437 - Added compatibility for custom fields data options
# 150908-1531 - Fixed input lengths for several standard fields to match DB
# 150917-1301 - Added dynamic default field maxlengths based on DB schema
# 150923-0700 - Fixed security issues with user access, issue #894
# 160102-1238 - Fixed issues with special characters, added $htmlconvert option
# 160112-2344 - Added link to direct to recording logging page, access log display
# 160122-1337 - Added display of gmt-offset, last-local-call and called-since-last-reset
# 160407-2023 - Design changes, added more variable scrubbing, added more admin logging
# 160926-1052 - Fix for inbound call notes display
# 170224-1639 - Added ability to display archived recordings
# 170409-1554 - Added IP List validation code
# 170527-2253 - Fix for rare inbound logging issue #1017
# 170710-2039 - Added Audit Comments display
# 170807-2255 - Added park log
# 170826-0858 - Added link to turn on/off archived logs display
# 171001-1109 - Added in-browser audio control, if recording access control is disabled
# 171216-2058 - Added ability to modify all active scheduled callbacks, and view callbacks log
# 180212-2340 - Added basic GDPR compliance features
# 180302-1605 - Added complete GDPR compliance features
# 180310-2300 - Added optional source_id display
# 180311-0008 - Added CIDdisplay
# 180410-1720 - Added switch lead log entry display
# 180506-1813 - Added switch_list log entry display
# 180807-0957 - Added new diff logging code
# 190310-2223 - Added indication of muted recordings by agent
# 190329-1917 - Added display of AMD log info when CIDdisplay=Yes is set
# 190609-0927 - Added sip_event_logging support
# 191113-2204 - Added support for per-User additional status groups
# 200815-0017 - Added support for additional modify_leads setting
# 200916-2321 - Added options to allow users to modify any call or agent log status
# 201113-0841 - Added server_ip information to extended log view
# 201117-0807 - Changes for better compatibility with non-latin data input
# 201109-1725 - Fix for blank page after certain updates submitted
# 201123-1704 - Added today called count display
# 210304-1509 - Added option '5' for modify_lead for this page to work as read-only
# 210421-2120 - Added more screen labels
# 210629-1545 - Added KHOMP stats display
# 210630-0838 - Added display of vicidial_vmm_counts data, if $CIDdisplay=="Yes"
# 220222-1454 - Added allow_web_debug system setting
# 220312-0953 - Added vicidial_dial_cid_log data
# 220427-1132 - Fixes for lead not found, Issue #1358
# 220520-1319 - Fix for admin hide phone data issue #1359
# 230204-0011 - Fix for inbound Call ID display
# 230205-2135 - Small fix for ignore_group_on_search issue
# 230307-1326 - Small fix for closer calls DID display, Issue #1447
# 230309-1444 - Added Inbound Call Menu Log display as part of IVR Log section
# 231117-1920 - Added vicidial_3way_press_log display
# 231126-2218 - Added vicidial_hci_log display
# 240704-2329 - Added coldstorage log view option
# 241002-0936 - Fix for displaying CID info on outbound calls that were blind transferred
#
require("dbconnect_mysqli.php");
require("functions.php");
$PHP_AUTH_USER=$_SERVER['PHP_AUTH_USER'];
$PHP_AUTH_PW=$_SERVER['PHP_AUTH_PW'];
$PHP_SELF=$_SERVER['PHP_SELF'];
$PHP_SELF = preg_replace('/\.php.*/i','.php',$PHP_SELF);
if (isset($_GET["vendor_id"])) {$vendor_id=$_GET["vendor_id"];}
elseif (isset($_POST["vendor_id"])) {$vendor_id=$_POST["vendor_id"];}
if (isset($_GET["source_id"])) {$source_id=$_GET["source_id"];}
elseif (isset($_POST["source_id"])) {$source_id=$_POST["source_id"];}
if (isset($_GET["old_phone"])) {$old_phone=$_GET["old_phone"];}
elseif (isset($_POST["old_phone"])) {$old_phone=$_POST["old_phone"];}
if (isset($_GET["lead_id"])) {$lead_id=$_GET["lead_id"];}
elseif (isset($_POST["lead_id"])) {$lead_id=$_POST["lead_id"];}
if (isset($_GET["title"])) {$title=$_GET["title"];}
elseif (isset($_POST["title"])) {$title=$_POST["title"];}
if (isset($_GET["first_name"])) {$first_name=$_GET["first_name"];}
elseif (isset($_POST["first_name"])) {$first_name=$_POST["first_name"];}
if (isset($_GET["middle_initial"])) {$middle_initial=$_GET["middle_initial"];}
elseif (isset($_POST["middle_initial"])) {$middle_initial=$_POST["middle_initial"];}
if (isset($_GET["last_name"])) {$last_name=$_GET["last_name"];}
elseif (isset($_POST["last_name"])) {$last_name=$_POST["last_name"];}
if (isset($_GET["phone_number"])) {$phone_number=$_GET["phone_number"];}
elseif (isset($_POST["phone_number"])) {$phone_number=$_POST["phone_number"];}
if (isset($_GET["end_call"])) {$end_call=$_GET["end_call"];}
elseif (isset($_POST["end_call"])) {$end_call=$_POST["end_call"];}
if (isset($_GET["DB"])) {$DB=$_GET["DB"];}
elseif (isset($_POST["DB"])) {$DB=$_POST["DB"];}
if (isset($_GET["dispo"])) {$dispo=$_GET["dispo"];}
elseif (isset($_POST["dispo"])) {$dispo=$_POST["dispo"];}
if (isset($_GET["list_id"])) {$list_id=$_GET["list_id"];}
elseif (isset($_POST["list_id"])) {$list_id=$_POST["list_id"];}
if (isset($_GET["campaign_id"])) {$campaign_id=$_GET["campaign_id"];}
elseif (isset($_POST["campaign_id"])) {$campaign_id=$_POST["campaign_id"];}
if (isset($_GET["phone_code"])) {$phone_code=$_GET["phone_code"];}
elseif (isset($_POST["phone_code"])) {$phone_code=$_POST["phone_code"];}
if (isset($_GET["server_ip"])) {$server_ip=$_GET["server_ip"];}
elseif (isset($_POST["server_ip"])) {$server_ip=$_POST["server_ip"];}
if (isset($_GET["extension"])) {$extension=$_GET["extension"];}
elseif (isset($_POST["extension"])) {$extension=$_POST["extension"];}
if (isset($_GET["channel"])) {$channel=$_GET["channel"];}
elseif (isset($_POST["channel"])) {$channel=$_POST["channel"];}
if (isset($_GET["call_began"])) {$call_began=$_GET["call_began"];}
elseif (isset($_POST["call_began"])) {$call_began=$_POST["call_began"];}
if (isset($_GET["parked_time"])) {$parked_time=$_GET["parked_time"];}
elseif (isset($_POST["parked_time"])) {$parked_time=$_POST["parked_time"];}
if (isset($_GET["tsr"])) {$tsr=$_GET["tsr"];}
elseif (isset($_POST["tsr"])) {$tsr=$_POST["tsr"];}
if (isset($_GET["address1"])) {$address1=$_GET["address1"];}
elseif (isset($_POST["address1"])) {$address1=$_POST["address1"];}
if (isset($_GET["address2"])) {$address2=$_GET["address2"];}
elseif (isset($_POST["address2"])) {$address2=$_POST["address2"];}
if (isset($_GET["address3"])) {$address3=$_GET["address3"];}
elseif (isset($_POST["address3"])) {$address3=$_POST["address3"];}
if (isset($_GET["city"])) {$city=$_GET["city"];}
elseif (isset($_POST["city"])) {$city=$_POST["city"];}
if (isset($_GET["state"])) {$state=$_GET["state"];}
elseif (isset($_POST["state"])) {$state=$_POST["state"];}
if (isset($_GET["postal_code"])) {$postal_code=$_GET["postal_code"];}
elseif (isset($_POST["postal_code"])) {$postal_code=$_POST["postal_code"];}
if (isset($_GET["province"])) {$province=$_GET["province"];}
elseif (isset($_POST["province"])) {$province=$_POST["province"];}
if (isset($_GET["country_code"])) {$country_code=$_GET["country_code"];}
elseif (isset($_POST["country_code"])) {$country_code=$_POST["country_code"];}
if (isset($_GET["alt_phone"])) {$alt_phone=$_GET["alt_phone"];}
elseif (isset($_POST["alt_phone"])) {$alt_phone=$_POST["alt_phone"];}
if (isset($_GET["email"])) {$email=$_GET["email"];}
elseif (isset($_POST["email"])) {$email=$_POST["email"];}
if (isset($_GET["security"])) {$security=$_GET["security"];}
elseif (isset($_POST["security"])) {$security=$_POST["security"];}
if (isset($_GET["comments"])) {$comments=$_GET["comments"];}
elseif (isset($_POST["comments"])) {$comments=$_POST["comments"];}
if (isset($_GET["status"])) {$status=$_GET["status"];}
elseif (isset($_POST["status"])) {$status=$_POST["status"];}
if (isset($_GET["rank"])) {$rank=$_GET["rank"];}
elseif (isset($_POST["rank"])) {$rank=$_POST["rank"];}
if (isset($_GET["owner"])) {$owner=$_GET["owner"];}
elseif (isset($_POST["owner"])) {$owner=$_POST["owner"];}
if (isset($_GET["submit"])) {$submit=$_GET["submit"];}
elseif (isset($_POST["submit"])) {$submit=$_POST["submit"];}
if (isset($_GET["SUBMIT"])) {$SUBMIT=$_GET["SUBMIT"];}
elseif (isset($_POST["SUBMIT"])) {$SUBMIT=$_POST["SUBMIT"];}
if (isset($_GET["CBchangeUSERtoANY"])) {$CBchangeUSERtoANY=$_GET["CBchangeUSERtoANY"];}
elseif (isset($_POST["CBchangeUSERtoANY"])) {$CBchangeUSERtoANY=$_POST["CBchangeUSERtoANY"];}
if (isset($_GET["CBchangeANYtoUSER"])) {$CBchangeANYtoUSER=$_GET["CBchangeANYtoUSER"];}
elseif (isset($_POST["CBchangeANYtoUSER"])) {$CBchangeANYtoUSER=$_POST["CBchangeANYtoUSER"];}
if (isset($_GET["CBchangeDATE"])) {$CBchangeDATE=$_GET["CBchangeDATE"];}
elseif (isset($_POST["CBchangeDATE"])) {$CBchangeDATE=$_POST["CBchangeDATE"];}
if (isset($_GET["callback_id"])) {$callback_id=$_GET["callback_id"];}
elseif (isset($_POST["callback_id"])) {$callback_id=$_POST["callback_id"];}
if (isset($_GET["CBuser"])) {$CBuser=$_GET["CBuser"];}
elseif (isset($_POST["CBuser"])) {$CBuser=$_POST["CBuser"];}
if (isset($_GET["modify_logs"])) {$modify_logs=$_GET["modify_logs"];}
elseif (isset($_POST["modify_logs"])) {$modify_logs=$_POST["modify_logs"];}
if (isset($_GET["modify_closer_logs"])) {$modify_closer_logs=$_GET["modify_closer_logs"];}
elseif (isset($_POST["modify_closer_logs"])) {$modify_closer_logs=$_POST["modify_closer_logs"];}
if (isset($_GET["modify_agent_logs"])) {$modify_agent_logs=$_GET["modify_agent_logs"];}
elseif (isset($_POST["modify_agent_logs"])) {$modify_agent_logs=$_POST["modify_agent_logs"];}
if (isset($_GET["add_closer_record"])) {$add_closer_record=$_GET["add_closer_record"];}
elseif (isset($_POST["add_closer_record"])) {$add_closer_record=$_POST["add_closer_record"];}
if (isset($_POST["appointment_date"])) {$appointment_date=$_POST["appointment_date"];}
elseif (isset($_GET["appointment_date"])) {$appointment_date=$_GET["appointment_date"];}
if (isset($_POST["appointment_time"])) {$appointment_time=$_POST["appointment_time"];}
elseif (isset($_GET["appointment_time"])) {$appointment_time=$_GET["appointment_time"];}
if (isset($_GET["CBstatus"])) {$CBstatus=$_GET["CBstatus"];}
elseif (isset($_POST["CBstatus"])) {$CBstatus=$_POST["CBstatus"];}
if (isset($_GET["archive_search"])) {$archive_search=$_GET["archive_search"];}
elseif (isset($_POST["archive_search"])) {$archive_search=$_POST["archive_search"];}
if (isset($_GET["archive_log"])) {$archive_log=$_GET["archive_log"];}
elseif (isset($_POST["archive_log"])) {$archive_log=$_POST["archive_log"];}
if (isset($_GET["date_of_birth"])) {$date_of_birth=$_GET["date_of_birth"];}
elseif (isset($_POST["date_of_birth"])) {$date_of_birth=$_POST["date_of_birth"];}
if (isset($_GET["gdpr_action"])) {$gdpr_action=$_GET["gdpr_action"];}
elseif (isset($_POST["gdpr_action"])) {$gdpr_action=$_POST["gdpr_action"];}
if (isset($_GET["CIDdisplay"])) {$CIDdisplay=$_GET["CIDdisplay"];}
elseif (isset($_POST["CIDdisplay"])) {$CIDdisplay=$_POST["CIDdisplay"];}
if (isset($_GET["modify_log_submit"])) {$modify_log_submit=$_GET["modify_log_submit"];}
elseif (isset($_POST["modify_log_submit"])) {$modify_log_submit=$_POST["modify_log_submit"];}
if (isset($_GET["modify_log_table"])) {$modify_log_table=$_GET["modify_log_table"];}
elseif (isset($_POST["modify_log_table"])) {$modify_log_table=$_POST["modify_log_table"];}
if (isset($_GET["modify_log_status"])) {$modify_log_status=$_GET["modify_log_status"];}
elseif (isset($_POST["modify_log_status"])) {$modify_log_status=$_POST["modify_log_status"];}
if (isset($_GET["modify_old_status"])) {$modify_old_status=$_GET["modify_old_status"];}
elseif (isset($_POST["modify_old_status"])) {$modify_old_status=$_POST["modify_old_status"];}
if (isset($_GET["vicidial_id"])) {$vicidial_id=$_GET["vicidial_id"];}
elseif (isset($_POST["vicidial_id"])) {$vicidial_id=$_POST["vicidial_id"];}
if (isset($_GET["log_date"])) {$log_date=$_GET["log_date"];}
elseif (isset($_POST["log_date"])) {$log_date=$_POST["log_date"];}
if ($archive_search=="Yes") {$vl_table="vicidial_list_archive";}
else {$vl_table="vicidial_list"; $archive_search="No";}
$altCIDdisplay="Yes";
if ($CIDdisplay=="Yes") {$altCIDdisplay="No";}
$DB=preg_replace("/[^0-9a-zA-Z]/","",$DB);
$STARTtime = date("U");
$TODAY = date("Y-m-d");
$NOW_TIME = date("Y-m-d H:i:s");
$date = date("r");
$ip = getenv("REMOTE_ADDR");
$browser = getenv("HTTP_USER_AGENT");
$AMDcount=0;
$uniqueidLIST="'XYZ'";
$htmlconvert=1;
$nonselectable_statuses=0;
if (file_exists('options.php'))
{
require('options.php');
}
$selectableSQL = "where selectable='Y'";
$selectableSQLand = "and selectable='Y'";
if ($nonselectable_statuses > 0)
{$selectableSQL=''; $selectableSQLand='';}
#############################################
##### START SYSTEM_SETTINGS LOOKUP #####
$stmt = "SELECT use_non_latin,custom_fields_enabled,webroot_writable,allow_emails,enable_languages,language_method,active_modules,log_recording_access,admin_screen_colors,enable_gdpr_download_deletion,source_id_display,mute_recordings,sip_event_logging,allow_web_debug,hopper_hold_inserts,coldstorage_server_ip,coldstorage_dbname,coldstorage_login,coldstorage_pass,coldstorage_port FROM system_settings;";
$rslt=mysql_to_mysqli($stmt, $link);
#if ($DB) {echo "$stmt\n";}
$qm_conf_ct = mysqli_num_rows($rslt);
if ($qm_conf_ct > 0)
{
$row=mysqli_fetch_row($rslt);
$non_latin = $row[0];
$custom_fields_enabled = $row[1];
$webroot_writable = $row[2];
$allow_emails = $row[3];
$SSenable_languages = $row[4];
$SSlanguage_method = $row[5];
$active_modules = $row[6];
$log_recording_access = $row[7];
$SSadmin_screen_colors = $row[8];
$enable_gdpr_download_deletion = $row[9];
$SSsource_id_display = $row[10];
$SSmute_recordings = $row[11];
$SSsip_event_logging = $row[12];
$SSallow_web_debug = $row[13];
$SShopper_hold_inserts = $row[14];
$SScoldstorage_server_ip = $row[15];
$SScoldstorage_dbname = $row[16];
$SScoldstorage_login = $row[17];
$SScoldstorage_pass = $row[18];
$SScoldstorage_port = $row[19];
}
if ($SSallow_web_debug < 1) {$DB=0;}
##### END SETTINGS LOOKUP #####
### See if KHOMP is set up
$stmt = "SELECT container_id FROM vicidial_settings_containers where container_id IN('KHOMPSETTINGS','KHOMPSTATUSMAP');";
$rslt=mysql_to_mysqli($stmt, $link);
if ($DB) {echo "$stmt\n";}
$kh_conf_ct = mysqli_num_rows($rslt);
###########################################
$DB=preg_replace('/[^0-9]/','',$DB);
$list_id = preg_replace('/[^0-9]/','',$list_id);
$lead_id = preg_replace('/[^0-9a-zA-Z]/','',$lead_id);
$entry_list_id = preg_replace('/[^0-9]/','',$entry_list_id);
$phone_code = preg_replace('/[^0-9]/','',$phone_code);
$update_phone_number=preg_replace('/[^A-Z]/','',$update_phone_number);
$phone_number = preg_replace('/[^0-9]/','',$phone_number);
$old_phone = preg_replace('/[^0-9]/','',$old_phone);
$vendor_lead_code = preg_replace('/;|#/','',$vendor_lead_code);
$vendor_lead_code = preg_replace('/\+/',' ',$vendor_lead_code);
$source_id = preg_replace('/;|#/','',$source_id);
$source_id = preg_replace('/\+/',' ',$source_id);
$gmt_offset_now = preg_replace('/[^-\_\.0-9]/','',$gmt_offset_now);
$country_code = preg_replace('/[^A-Z]/','',$country_code);
$gender = preg_replace('/[^A-Z]/','',$gender);
$date_of_birth = preg_replace('/[^-0-9]/','',$date_of_birth);
$comments = preg_replace('/;|#/','',$comments);
$comments = preg_replace('/\+/',' ',$comments);
$rank = preg_replace('/[^0-9]/','',$rank);
$no_update = preg_replace('/[^A-Z]/','',$no_update);
$called_count=preg_replace('/[^0-9]/','',$called_count);
$local_gmt=preg_replace('/[^-\.0-9]/','',$local_gmt);
$callback = preg_replace('/[^A-Z]/','',$callback);
$callback_type = preg_replace('/[^A-Z]/','',$callback_type);
$end_call=preg_replace('/[^0-9]/','',$end_call);
$server_ip = preg_replace('/[^-\.\:\_0-9a-zA-Z]/','',$server_ip);
$extension = preg_replace("/\<|\>|\'|\"|\\\\|;/",'',$extension);
$channel = preg_replace("/\<|\>|\'|\"|\\\\|;/",'',$channel);
$submit = preg_replace('/[^- \.\_0-9a-zA-Z]/','',$submit);
$SUBMIT = preg_replace('/[^- \.\_0-9a-zA-Z]/','',$SUBMIT);
$modify_logs=preg_replace('/[^0-9]/','',$modify_logs);
$modify_closer_logs=preg_replace('/[^0-9]/','',$modify_closer_logs);
$modify_agent_logs=preg_replace('/[^0-9]/','',$modify_agent_logs);
$add_closer_record=preg_replace('/[^0-9]/','',$add_closer_record);
$call_began = preg_replace('/[^- \:\_0-9a-zA-Z]/','',$call_began);
$parked_time = preg_replace('/[^- \:\_0-9a-zA-Z]/','',$parked_time);
$callback_id = preg_replace('/[^-_0-9a-zA-Z]/','',$callback_id);
$CBchangeUSERtoANY = preg_replace('/[^-_0-9a-zA-Z]/','',$CBchangeUSERtoANY);
$CBchangeANYtoUSER = preg_replace('/[^-_0-9a-zA-Z]/','',$CBchangeANYtoUSER);
$CBchangeDATE = preg_replace('/[^-_0-9a-zA-Z]/','',$CBchangeDATE);
$archive_search = preg_replace('/[^-_0-9a-zA-Z]/','',$archive_search);
$archive_log = preg_replace('/[^-_0-9a-zA-Z]/','',$archive_log);
$gdpr_action = preg_replace('/[^-_0-9a-zA-Z]/','',$gdpr_action);
$CIDdisplay = preg_replace('/[^-_0-9a-zA-Z]/','',$CIDdisplay);
$appointment_date = preg_replace('/[^- \:\_0-9a-zA-Z]/','',$appointment_date);
$appointment_time = preg_replace('/[^- \:\_0-9a-zA-Z]/','',$appointment_time);
# Variables filtered further down in the code
# $vendor_id
if ($non_latin < 1)
{
$PHP_AUTH_USER = preg_replace('/[^-_0-9a-zA-Z]/','',$PHP_AUTH_USER);
$PHP_AUTH_PW = preg_replace('/[^-_0-9a-zA-Z]/','',$PHP_AUTH_PW);
$user=preg_replace('/[^-_0-9a-zA-Z]/','',$user);
$pass=preg_replace('/[^-_0-9a-zA-Z]/','',$pass);
$function = preg_replace('/[^-\_0-9a-zA-Z]/', '',$function);
$format = preg_replace('/[^0-9a-zA-Z]/','',$format);
$title = preg_replace('/[^- \'\_\.0-9a-zA-Z]/','',$title);
$first_name = preg_replace('/[^- \'\+\_\.0-9a-zA-Z]/','',$first_name);
$middle_initial = preg_replace('/[^0-9a-zA-Z]/','',$middle_initial);
$last_name = preg_replace('/[^- \'\+\_\.0-9a-zA-Z]/','',$last_name);
$address1 = preg_replace('/[^- \'\+\.\:\/\@\_0-9a-zA-Z]/','',$address1);
$address2 = preg_replace('/[^- \'\+\.\:\/\@\_0-9a-zA-Z]/','',$address2);
$address3 = preg_replace('/[^- \'\+\.\:\/\@\_0-9a-zA-Z]/','',$address3);
$city = preg_replace('/[^- \'\+\.\:\/\@\_0-9a-zA-Z]/','',$city);
$state = preg_replace('/[^- 0-9a-zA-Z]/','',$state);
$province = preg_replace('/[^- \'\+\.\_0-9a-zA-Z]/','',$province);
$postal_code = preg_replace('/[^- \'\+0-9a-zA-Z]/','',$postal_code);
$alt_phone = preg_replace('/[^- \'\+\_\.0-9a-zA-Z]/','',$alt_phone);
$email = preg_replace('/[^- \'\+\.\:\/\@\%\_0-9a-zA-Z]/','',$email);
$security_phrase = preg_replace('/[^- \'\+\.\:\/\@\_0-9a-zA-Z]/','',$security_phrase);
$security = preg_replace('/[^- \'\+\.\:\/\@\_0-9a-zA-Z]/','',$security);
$campaign_id = preg_replace('/[^-\_0-9a-zA-Z]/', '',$campaign_id);
$multi_alt_phones = preg_replace('/[^- \+\!\:\_0-9a-zA-Z]/','',$multi_alt_phones);
$source = preg_replace('/[^0-9a-zA-Z]/','',$source);
$stage = preg_replace('/[^a-zA-Z]/','',$stage);
$owner = preg_replace('/[^- \'\+\.\:\/\@\_0-9a-zA-Z]/','',$owner);
$custom_fields = preg_replace('/[^0-9a-zA-Z]/','',$custom_fields);
$callback_status = preg_replace('/[^-\_0-9a-zA-Z]/', '',$callback_status);
$callback_datetime = preg_replace('/[^- \+\.\:\/\@\_0-9a-zA-Z]/','',$callback_datetime);
$callback_user = preg_replace('/[^-\_0-9a-zA-Z]/', '',$callback_user);
$callback_comments = preg_replace('/[^- \+\.\:\/\@\_0-9a-zA-Z]/','',$callback_comments);
$modify_log_status = preg_replace('/[^-\_0-9a-zA-Z]/', '',$modify_log_status);
$modify_old_status = preg_replace('/[^-\_0-9a-zA-Z]/', '',$modify_old_status);
$log_date = preg_replace('/[^- \+\.\:\/\@\_0-9a-zA-Z]/','',$log_date);
$modify_log_submit = preg_replace('/[^-_0-9a-zA-Z]/','',$modify_log_submit);
$modify_log_table = preg_replace('/[^-_0-9a-zA-Z]/','',$modify_log_table);
$vicidial_id = preg_replace('/[^-\+\.\:\_0-9a-zA-Z]/','',$vicidial_id);
$dispo = preg_replace('/[^-_0-9a-zA-Z]/','',$dispo);
$status = preg_replace('/[^-_0-9a-zA-Z]/','',$status);
$CBstatus = preg_replace('/[^-_0-9a-zA-Z]/','',$CBstatus);
$tsr = preg_replace('/[^-_0-9a-zA-Z]/','',$tsr);
$CBuser = preg_replace('/[^-_0-9a-zA-Z]/','',$CBuser);
}
else
{
$PHP_AUTH_USER = preg_replace('/[^-_0-9\p{L}]/u', '', $PHP_AUTH_USER);
$PHP_AUTH_PW = preg_replace('/[^-_0-9\p{L}]/u', '', $PHP_AUTH_PW);
$user=preg_replace('/[^-_0-9\p{L}]/u','',$user);
$pass=preg_replace('/[^-_0-9\p{L}]/u','',$pass);
$function = preg_replace('/[^-\_0-9\p{L}]/u', '',$function);
$format = preg_replace('/[^0-9\p{L}]/u','',$format);
$title = preg_replace('/[^- \'\_\.0-9\p{L}]/u','',$title);
$first_name = preg_replace('/[^- \'\+\_\.0-9\p{L}]/u','',$first_name);
$middle_initial = preg_replace('/[^0-9\p{L}]/u','',$middle_initial);
$last_name = preg_replace('/[^- \'\+\_\.0-9\p{L}]/u','',$last_name);
$address1 = preg_replace('/[^- \'\+\.\:\/\@\_0-9\p{L}]/u','',$address1);
$address2 = preg_replace('/[^- \'\+\.\:\/\@\_0-9\p{L}]/u','',$address2);
$address3 = preg_replace('/[^- \'\+\.\:\/\@\_0-9\p{L}]/u','',$address3);
$city = preg_replace('/[^- \'\+\.\:\/\@\_0-9\p{L}]/u','',$city);
$state = preg_replace('/[^- 0-9\p{L}]/u','',$state);
$province = preg_replace('/[^- \'\+\.\_0-9\p{L}]/u','',$province);
$postal_code = preg_replace('/[^- \'\+0-9\p{L}]/u','',$postal_code);
$alt_phone = preg_replace('/[^- \'\+\_\.0-9\p{L}]/u','',$alt_phone);
$email = preg_replace('/[^- \'\+\.\:\/\@\%\_0-9\p{L}]/u','',$email);
$security_phrase = preg_replace('/[^- \'\+\.\:\/\@\_0-9\p{L}]/u','',$security_phrase);
$security = preg_replace('/[^- \'\+\.\:\/\@\_0-9\p{L}]/u','',$security);
$campaign_id = preg_replace('/[^-\_0-9\p{L}]/u', '',$campaign_id);
$multi_alt_phones = preg_replace('/[^- \+\!\:\_0-9\p{L}]/u','',$multi_alt_phones);
$source = preg_replace('/[^0-9\p{L}]/u','',$source);
$stage = preg_replace('/[^\p{L}]/u','',$stage);
$owner = preg_replace('/[^- \'\+\.\:\/\@\_0-9\p{L}]/u','',$owner);
$custom_fields = preg_replace('/[^0-9\p{L}]/u','',$custom_fields);
$callback_status = preg_replace('/[^-\_0-9\p{L}]/u', '',$callback_status);
$callback_datetime = preg_replace('/[^- \+\.\:\/\@\_0-9\p{L}]/u','',$callback_datetime);
$callback_user = preg_replace('/[^-\_0-9\p{L}]/u', '',$callback_user);
$callback_comments = preg_replace('/[^- \+\.\:\/\@\_0-9\p{L}]/u','',$callback_comments);
$modify_log_status = preg_replace('/[^-\_0-9\p{L}]/u', '',$modify_log_status);
$modify_old_status = preg_replace('/[^-\_0-9\p{L}]/u', '',$modify_old_status);
$log_date = preg_replace('/[^- \+\.\:\/\@\_0-9\p{L}]/u','',$log_date);
$modify_log_submit = preg_replace('/[^-_0-9\p{L}]/u','',$modify_log_submit);
$modify_log_table = preg_replace('/[^-_0-9\p{L}]/u','',$modify_log_table);
$vicidial_id = preg_replace('/[^-\+\.\:\_0-9\p{L}]/u','',$vicidial_id);
$dispo = preg_replace('/[^-_0-9\p{L}]/u','',$dispo);
$status = preg_replace('/[^-_0-9\p{L}]/u','',$status);
$CBstatus = preg_replace('/[^-_0-9\p{L}]/u','',$CBstatus);
$tsr = preg_replace('/[^-_0-9\p{L}]/u','',$tsr);
$CBuser = preg_replace('/[^-_0-9\p{L}]/u','',$CBuser);
}
$first_name = preg_replace('/\+/',' ',$first_name);
$last_name = preg_replace('/\+/',' ',$last_name);
$address1 = preg_replace('/\+/',' ',$address1);
$address2 = preg_replace('/\+/',' ',$address2);
$address3 = preg_replace('/\+/',' ',$address3);
$city = preg_replace('/\+/',' ',$city);
$province = preg_replace('/\+/',' ',$province);
$postal_code = preg_replace('/\+/',' ',$postal_code);
$alt_phone = preg_replace('/\+/',' ',$alt_phone);
$email = preg_replace('/\+/',' ',$email);
$security_phrase = preg_replace('/\+/',' ',$security_phrase);
$multi_alt_phones = preg_replace('/\+/',' ',$multi_alt_phones);
$owner = preg_replace('/\+/',' ',$owner);
if (strlen($phone_number)<6) {$phone_number=$old_phone;}
$auth=0;
$auth_message = user_authorization($PHP_AUTH_USER,$PHP_AUTH_PW,'',1,0);
if ( ($auth_message == 'GOOD') or ($auth_message == '2FA') )
{
$auth=1;
if ($auth_message == '2FA')
{
header ("Content-type: text/html; charset=utf-8");
echo _QXZ("Your session is expired").". "._QXZ("Click here to log in")." .\n";
exit;
}
}
if ($auth < 1)
{
$VDdisplayMESSAGE = _QXZ("Login incorrect, please try again");
if ($auth_message == 'LOCK')
{
$VDdisplayMESSAGE = _QXZ("Too many login attempts, try again in 15 minutes");
Header ("Content-type: text/html; charset=utf-8");
echo "$VDdisplayMESSAGE: |$PHP_AUTH_USER|$auth_message|\n";
exit;
}
if ($auth_message == 'IPBLOCK')
{
$VDdisplayMESSAGE = _QXZ("Your IP Address is not allowed") . ": $ip";
Header ("Content-type: text/html; charset=utf-8");
echo "$VDdisplayMESSAGE: |$PHP_AUTH_USER|$auth_message|\n";
exit;
}
Header("WWW-Authenticate: Basic realm=\"CONTACT-CENTER-ADMIN\"");
Header("HTTP/1.0 401 Unauthorized");
echo "$VDdisplayMESSAGE: |$PHP_AUTH_USER|$PHP_AUTH_PW|$auth_message|\n";
exit;
}
if ($non_latin > 0) {$rslt=mysql_to_mysqli("SET NAMES 'UTF8'", $link);}
$rights_stmt = "SELECT modify_leads,selected_language,status_group_id from vicidial_users where user='$PHP_AUTH_USER';";
if ($DB) {echo "|$stmt|\n";}
$rights_rslt=mysql_to_mysqli($rights_stmt, $link);
$rights_row=mysqli_fetch_row($rights_rslt);
$modify_leads = $rights_row[0];
$VUselected_language = $rights_row[1];
$VU_status_group_id = $rights_row[2];
# check their permissions
if ($modify_leads < 1)
{
header ("Content-type: text/html; charset=utf-8");
echo _QXZ("You do not have permissions to modify leads")."\n";
exit;
}
$stmt="SELECT full_name,modify_leads,admin_hide_lead_data,admin_hide_phone_data,user_group,user_level,ignore_group_on_search from vicidial_users where user='$PHP_AUTH_USER';";
$rslt=mysql_to_mysqli($stmt, $link);
$row=mysqli_fetch_row($rslt);
$LOGfullname = $row[0];
$LOGmodify_leads = $row[1];
$LOGadmin_hide_lead_data = $row[2];
$LOGadmin_hide_phone_data = $row[3];
$LOGuser_group = $row[4];
$LOGuser_level = $row[5];
$LOGignore_group_on_search = $row[6];
$LOGallowed_listsSQL='';
$stmt="SELECT allowed_campaigns from vicidial_user_groups where user_group='$LOGuser_group';";
if ($DB) {$HTML_text.="|$stmt|\n";}
$rslt=mysql_to_mysqli($stmt, $link);
$row=mysqli_fetch_row($rslt);
$LOGallowed_campaigns = $row[0];
if ( (!preg_match('/\-ALL/i', $LOGallowed_campaigns)) and ($LOGignore_group_on_search != '1') )
{
$rawLOGallowed_campaignsSQL = preg_replace("/ -/",'',$LOGallowed_campaigns);
$rawLOGallowed_campaignsSQL = preg_replace("/ /","','",$rawLOGallowed_campaignsSQL);
$LOGallowed_campaignsSQL = "and campaign_id IN('$rawLOGallowed_campaignsSQL')";
$whereLOGallowed_campaignsSQL = "where campaign_id IN('$rawLOGallowed_campaignsSQL')";
$stmt="SELECT list_id from vicidial_lists $whereLOGallowed_campaignsSQL;";
$rslt=mysql_to_mysqli($stmt, $link);
$lists_to_print = mysqli_num_rows($rslt);
$o=0;
while ($lists_to_print > $o)
{
$rowx=mysqli_fetch_row($rslt);
$camp_lists .= "'$rowx[0]',";
$o++;
}
$camp_lists = preg_replace('/.$/i','',$camp_lists);;
if (strlen($camp_lists)<2) {$camp_lists="''";}
$LOGallowed_listsSQL = "and list_id IN($camp_lists)";
$whereLOGallowed_listsSQL = "where list_id IN($camp_lists)";
}
$SSmenu_background='015B91';
$SSframe_background='D9E6FE';
$SSstd_row1_background='9BB9FB';
$SSstd_row2_background='B9CBFD';
$SSstd_row3_background='8EBCFD';
$SSstd_row4_background='B6D3FC';
$SSstd_row5_background='A3C3D6';
$SSalt_row1_background='BDFFBD';
$SSalt_row2_background='99FF99';
$SSalt_row3_background='CCFFCC';
$SSweb_logo='default_old';
$SSbutton_color='EFEFEF';
if ($SSadmin_screen_colors != 'default')
{
$stmt = "SELECT menu_background,frame_background,std_row1_background,std_row2_background,std_row3_background,std_row4_background,std_row5_background,alt_row1_background,alt_row2_background,alt_row3_background,web_logo,button_color FROM vicidial_screen_colors where colors_id='$SSadmin_screen_colors';";
$rslt=mysql_to_mysqli($stmt, $link);
if ($DB) {echo "$stmt\n";}
$colors_ct = mysqli_num_rows($rslt);
if ($colors_ct > 0)
{
$row=mysqli_fetch_row($rslt);
$SSmenu_background = $row[0];
$SSframe_background = $row[1];
$SSstd_row1_background = $row[2];
$SSstd_row2_background = $row[3];
$SSstd_row3_background = $row[4];
$SSstd_row4_background = $row[5];
$SSstd_row5_background = $row[6];
$SSalt_row1_background = $row[7];
$SSalt_row2_background = $row[8];
$SSalt_row3_background = $row[9];
$SSweb_logo = $row[10];
$SSbutton_color = $row[11];
}
}
#############################################
##### BEGIN modify log status functions #####
#############################################
if ($modify_log_submit>0)
{
if ( ($LOGmodify_leads == '3') or ($LOGmodify_leads == '4') )
{
if (strlen($modify_log_status)>0)
{
if ( (strlen($lead_id)>0) and (strlen($modify_log_table)>3) and (strlen($modify_log_status)>0) and (strlen($modify_old_status)>0) and (strlen($vicidial_id) > 0) and (strlen($log_date) > 10) )
{
$stmt='';
if ($modify_log_table == 'vicidial_log')
{
$stmt="UPDATE vicidial_log set status='$modify_log_status' where lead_id='$lead_id' and uniqueid='$vicidial_id' and call_date='$log_date';";
}
if ($modify_log_table == 'vicidial_log_archive')
{
$stmt="UPDATE vicidial_log_archive set status='$modify_log_status' where lead_id='$lead_id' and uniqueid='$vicidial_id' and call_date='$log_date';";
}
if ($modify_log_table == 'vicidial_closer_log')
{
$stmt="UPDATE vicidial_closer_log set status='$modify_log_status' where lead_id='$lead_id' and closecallid='$vicidial_id' and call_date='$log_date';";
}
if ($modify_log_table == 'vicidial_closer_log_archive')
{
$stmt="UPDATE vicidial_closer_log_archive set status='$modify_log_status' where lead_id='$lead_id' and closecallid='$vicidial_id' and call_date='$log_date';";
}
if ($modify_log_table == 'vicidial_agent_log')
{
$stmt="UPDATE vicidial_agent_log set status='$modify_log_status' where lead_id='$lead_id' and agent_log_id='$vicidial_id' and event_time='$log_date';";
}
if ($modify_log_table == 'vicidial_agent_log_archive')
{
$stmt="UPDATE vicidial_agent_log_archive set status='$modify_log_status' where lead_id='$lead_id' and agent_log_id='$vicidial_id' and event_time='$log_date';";
}
if (strlen($stmt)>20)
{
if ($DB) {echo "$stmt\n";}
$rslt=mysql_to_mysqli($stmt, $link);
$affected_rows = mysqli_affected_rows($link);
$SQL_log = addslashes($stmt);
$stmt="INSERT INTO vicidial_admin_log set event_date='$NOW_TIME', user='$PHP_AUTH_USER', ip_address='$ip', event_section='LEADS', event_type='MODIFY', record_id='$lead_id', event_code='MODIFY LEAD LOG STATUS', event_sql=\"$SQL_log\", event_notes='$lead_id|$modify_log_table|$modify_log_status|$modify_old_status|$vicidial_id|$log_date|$affected_rows';";
if ($DB) {echo "|$stmt|\n";}
$rslt=mysql_to_mysqli($stmt, $link);
echo "SUCCESS: "._QXZ("Log Status Modified").": $modify_log_status \n";
exit;
}
else
{
echo "ERROR: "._QXZ("Modification could not be completed").": $stmt|$lead_id|$modify_log_table|$modify_log_status|$modify_old_status|$vicidial_id|$log_date \n";
exit;
}
}
else
{
echo "ERROR: "._QXZ("Missing required fields").": $lead_id|$modify_log_table|$modify_log_status|$modify_old_status|$vicidial_id|$log_date \n";
exit;
}
}
else
{
echo "ERROR: "._QXZ("Log status not changed, new status is blank or the same as the old status").": $modify_log_status \n";
exit;
}
}
else
{
echo "ERROR: "._QXZ("You do not have permission to modify log statuses").": $LOGmodify_leads \n";
exit;
}
}
############################################
##### END modify log status functions #####
#############################################
################################
##### BEGIN GDPR functions #####
################################
if ($enable_gdpr_download_deletion>0)
{
$stmt="SELECT export_gdpr_leads from vicidial_users where user='$PHP_AUTH_USER' and export_gdpr_leads >= 1;";
$rslt=mysql_to_mysqli($stmt, $link);
$row=mysqli_fetch_row($rslt);
$gdpr_display=$row[0];
if ($gdpr_display>=1 && $gdpr_action && $lead_id)
{
$table_array=array("vicidial_list", "recording_log", "vicidial_log", "vicidial_xfer_log", "vicidial_closer_log", "vicidial_carrier_log", "vicidial_agent_log");
$date_field_array=array("entry_date", "start_time", "call_date", "call_date", "call_date", "call_date", "event_time");
$purge_field_array=array(
"vicidial_list" => array("phone_code", "phone_number", "title", "first_name", "middle_initial", "last_name", "address1", "address2", "address3", "city", "state", "province", "postal_code", "country_code", "gender", "date_of_birth", "alt_phone", "email", "security_phrase", "comments"),
"vicidial_log" => array(),
"vicidial_xfer_log" => array(),
"vicidial_closer_log" => array(),
"vicidial_carrier_log" => array(),
"vicidial_agent_log" => array(),
"recording_log" => array("filename", "location")
);
$table_count=count($table_array);
$CSV_text="";
$HTML_text="";
$SQL_log = "";
if ($gdpr_action=="confirm_purge")
{
$archive_table_name=use_archive_table("vicidial_list");
$mysql_stmt="(select list_id from vicidial_list where lead_id='$lead_id')";
if ($archive_table_name!="vicidial_list") {$mysql_stmt.=" UNION (select list_id from ".$archive_table_name." where lead_id='$lead_id')";}
$mysql_rslt=mysql_to_mysqli($mysql_stmt, $link);
if(mysqli_num_rows($mysql_rslt)>0)
{
$mysql_row=mysqli_fetch_row($mysql_rslt);
$list_id=$mysql_row[0];
}
for ($t=0; $t<$table_count; $t++)
{
$table_name=$table_array[$t];
$archive_table_name=use_archive_table($table_name);
if ($list_id && $table_name=="vicidial_list" && table_exists("custom_$list_id"))
{
array_splice($table_array, 1, 0, "custom_$list_id");
array_splice($date_field_array, 1, 0, "lead_id");
$custom_table_array=array("custom_$list_id" => array());
$purge_field_array=array_merge($purge_field_array, $custom_table_array);
$table_count++;
$custom_stmt="SHOW COLUMNS FROM custom_".$list_id."";
$custom_rslt=mysql_to_mysqli($custom_stmt, $link);
while($custom_row=mysqli_fetch_row($custom_rslt))
{
if ($custom_row[0]!="lead_id")
{
array_push($purge_field_array["custom_$list_id"], $custom_row[0]);
}
}
}
if(count($purge_field_array["$table_name"])>0)
{
if ($table_name=="recording_log")
{
$ins_stmt="insert ignore into recording_log_deletion_queue(recording_id,lead_id, filename, location, date_queued) (select recording_id,lead_id, filename, location, now() from recording_log where lead_id='$lead_id') UNION (select recording_id,lead_id, filename, location, now() from recording_log_archive where lead_id='$lead_id')";
$ins_rslt=mysql_to_mysqli($ins_stmt, $link);
}
$upd_clause=implode("=null, ", $purge_field_array["$table_name"])."=null ";
$upd_stmt="update $table_name set $upd_clause where lead_id='$lead_id'";
$upd_rslt=mysql_to_mysqli($upd_stmt, $link);
$SQL_log.="$upd_stmt|";
if ($archive_table_name!=$table_name)
{
$upd_stmt="update $archive_table_name set $upd_clause where lead_id='$lead_id'";
$upd_rslt=mysql_to_mysqli($upd_stmt, $link);
$SQL_log.="$upd_stmt|";
}
}
}
$SQL_log = addslashes($SQL_log);
$stmt="INSERT INTO vicidial_admin_log set event_date='$NOW_TIME', user='$PHP_AUTH_USER', ip_address='$ip', event_section='LEADS', event_type='DELETE', record_id='$lead_id', event_code='GDPR PURGE LEAD DATA', event_sql=\"$SQL_log\", event_notes='';";
if ($DB) {echo "|$stmt|\n";}
$rslt=mysql_to_mysqli($stmt, $link);
}
$HTML_text.=" ";
$HTML_text.="
\n";
$HTML_text.="\n";
$HTML_text.="\t"._QXZ("GDPR DATA PURGE PREVIEW")." ("._QXZ("greyed fields will be emptied").") : ";
$HTML_text.="\t"._QXZ("DOWNLOAD")." ";
$HTML_text.="\t"._QXZ("CONFIRM PURGE")." ";
$HTML_text.=" ";
$HTML_text.="
";
for ($t=0; $t<$table_count; $t++)
{
$table_name=$table_array[$t];
$archive_table_name=use_archive_table($table_name);
$mysql_stmt="(select * from ".$table_name." where lead_id='$lead_id')";
if ($archive_table_name!=$table_name) {$mysql_stmt.=" UNION (select * from ".$archive_table_name." where lead_id='$lead_id')";}
$list_id=""; $HTML_header=""; $CSV_header=""; $HTML_body=""; $CSV_body="";
$mysql_stmt.=" order by ".$date_field_array[$t]." desc";
$mysql_rslt=mysql_to_mysqli($mysql_stmt, $link);
if ($DB) {echo "|$mysql_stmt|\n";}
if (mysqli_num_rows($mysql_rslt)>0)
{
$CSV_text.="\""._QXZ("TABLE NAME").":\",\"$table_name\"\n";
$HTML_text.=""._QXZ("TABLE NAME").": $table_name \n";
$HTML_text.="\n";
$j=0;
while($row=mysqli_fetch_array($mysql_rslt,MYSQLI_ASSOC))
{
if ($j%2==0)
{
$bgcolor=$SSstd_row2_background;
}
else
{
$bgcolor=$SSstd_row3_background;
}
if ($j==0)
{
$HTML_header.="\n";
}
$HTML_body.=" \n";
# while (list($key, $val)=each($row))
foreach ($row as $key => $val)
{
if ($key=="entry_list_id") {$list_id=$val;}
if (in_array($key, $purge_field_array["$table_name"]) || (preg_match("/^custom_/", $table_name) && $key!="lead_id"))
{
$bgcolor="bgcolor='#999999'";
$sb="";
$eb=" ";
}
else
{
$bgcolor="bgcolor='#$SSstd_row1_background'";
$sb="";
$eb="";
}
if ($j==0)
{
$CSV_header.="\"".$key."\",";
$HTML_header.="\t$sb".$key." $eb \n";
}
$CSV_body.="\"$val\",";
$HTML_body.="\t$sb".$val." $eb \n";
}
if ($j==0)
{
$CSV_header=substr($CSV_header, 0, -1)."\n";
$HTML_header.=" \n";
}
$CSV_body=substr($CSV_body, 0, -1)."\n";
$HTML_body.="\n";
$j++;
}
$CSV_text.=$CSV_header.$CSV_body;
$HTML_text.=$HTML_header.$HTML_body;
$CSV_text.="\n";
$HTML_text.="
";
}
if ($list_id && $table_name=="vicidial_list" && table_exists("custom_$list_id") && !in_array("custom_$list_id", $table_array))
{
array_splice($table_array, 1, 0, "custom_$list_id");
array_splice($date_field_array, 1, 0, "lead_id");
$custom_table_array=array("custom_$list_id" => array());
$purge_field_array=array_merge($purge_field_array, $custom_table_array);
$table_count++;
}
}
if (strlen($CSV_text)>0 && $gdpr_action=="download")
{
$rec_stmt="select start_time, location, filename from recording_log where lead_id='$lead_id' order by start_time asc";
$rec_rslt=mysql_to_mysqli($rec_stmt, $link);
$files_to_zip=array();
while ($rec_row=mysqli_fetch_row($rec_rslt)) {
$start_time=$rec_row[0];
$start_date=substr($start_time, 1, 10);
$location=$rec_row[1];
$filename=$rec_row[2];
preg_match("/$filename.*$/", $location, $matches);
$destination_filename=$matches[0];
set_time_limit(0);
$fp = fopen("/tmp/$destination_filename", 'w+');
$ch = curl_init(str_replace(" ","%20",$location));
curl_setopt($ch, CURLOPT_TIMEOUT, 50);
curl_setopt($ch, CURLOPT_FILE, $fp);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
curl_exec($ch);
curl_close($ch);
fclose($fp);
array_push($files_to_zip, "$destination_filename");
}
$stmt="INSERT INTO vicidial_admin_log set event_date='$NOW_TIME', user='$PHP_AUTH_USER', ip_address='$ip', event_section='LEADS', event_type='EXPORT', record_id='$lead_id', event_code='GDPR EXPORT LEAD DATA', event_sql=\"$SQL_log\", event_notes='';";
if ($DB) {echo "|$stmt|\n";}
$rslt=mysql_to_mysqli($stmt, $link);
$FILE_TIME = date("Ymd-His");
$CSVfilename = "GDPR_export_$US$FILE_TIME.csv";
$CSV_text=preg_replace('/^\s+/', '', $CSV_text);
$CSV_text=preg_replace('/ +\"/', '"', $CSV_text);
$CSV_text=preg_replace('/\" +/', '"', $CSV_text);
array_push($files_to_zip, "$CSVfilename");
$fp = fopen("/tmp/$CSVfilename", 'w+');
fwrite($fp, $CSV_text);
fclose($fp);
$zipname = "$lead_id.zip";
$zip = new ZipArchive;
$zip->open($zipname, ZipArchive::CREATE);
foreach ($files_to_zip as $file) {
$tempfile="/tmp/$file";
$zip->addFile($tempfile);
}
$zip->close();
header('Content-Type: application/zip');
header('Content-disposition: attachment; filename='.$zipname);
header('Content-Length: ' . filesize($zipname));
readfile($zipname);
/*
// We'll be outputting a TXT file
header('Content-type: application/octet-stream');
// It will be called LIST_101_20090209-121212.txt
header("Content-Disposition: attachment; filename=\"$CSVfilename\"");
header('Expires: 0');
header('Cache-Control: must-revalidate, post-check=0, pre-check=0');
header('Pragma: public');
ob_clean();
flush();
echo "$CSV_text";
*/
exit;
}
}
}
################################
##### END GDPR functions #####
################################
$label_title = _QXZ("Title");
$label_first_name = _QXZ("First");
$label_middle_initial = _QXZ("MI");
$label_last_name = _QXZ("Last");
$label_address1 = _QXZ("Address1");
$label_address2 = _QXZ("Address2");
$label_address3 = _QXZ("Address3");
$label_city = _QXZ("City");
$label_state = _QXZ("State");
$label_province = _QXZ("Province");
$label_postal_code = _QXZ("Postal Code");
$label_vendor_lead_code = _QXZ("Vendor ID");
$label_source_id = _QXZ("Source ID");
$label_gender = _QXZ("Gender");
$label_phone_number = _QXZ("Phone");
$label_phone_code = _QXZ("DialCode");
$label_alt_phone = _QXZ("Alt. Phone");
$label_security_phrase = _QXZ("Show");
$label_email = _QXZ("Email");
$label_comments = _QXZ("Comments");
$label_lead_id = _QXZ("Lead ID");
$label_list_id = _QXZ("List ID");
$label_entry_date = _QXZ("Entry Date");
$label_gmt_offset_now = _QXZ("Timezone");
$label_source_id = _QXZ("Source ID");
$label_called_since_last_reset = _QXZ("Reset Code");
$label_status = _QXZ("Status");
$label_user = _QXZ("User");
$label_date_of_birth = _QXZ("Date of Birth");
$label_country_code = _QXZ("Country");
$label_last_local_call_time = _QXZ("Last Call");
$label_called_count = _QXZ("Called Count");
$label_rank = _QXZ("Rank");
$label_owner = _QXZ("Owner");
$label_entry_list_id = _QXZ("Entry List ID");
### find any custom field labels
$stmt="SELECT label_title,label_first_name,label_middle_initial,label_last_name,label_address1,label_address2,label_address3,label_city,label_state,label_province,label_postal_code,label_vendor_lead_code,label_gender,label_phone_number,label_phone_code,label_alt_phone,label_security_phrase,label_email,label_comments,label_lead_id,label_list_id,label_entry_date,label_gmt_offset_now,label_source_id,label_called_since_last_reset,label_status,label_user,label_date_of_birth,label_country_code,label_last_local_call_time,label_called_count,label_rank,label_owner,label_entry_list_id from system_settings;";
$rslt=mysql_to_mysqli($stmt, $link);
$row=mysqli_fetch_row($rslt);
if (strlen($row[0])>0) {$label_title = $row[0];}
if (strlen($row[1])>0) {$label_first_name = $row[1];}
if (strlen($row[2])>0) {$label_middle_initial = $row[2];}
if (strlen($row[3])>0) {$label_last_name = $row[3];}
if (strlen($row[4])>0) {$label_address1 = $row[4];}
if (strlen($row[5])>0) {$label_address2 = $row[5];}
if (strlen($row[6])>0) {$label_address3 = $row[6];}
if (strlen($row[7])>0) {$label_city = $row[7];}
if (strlen($row[8])>0) {$label_state = $row[8];}
if (strlen($row[9])>0) {$label_province = $row[9];}
if (strlen($row[10])>0) {$label_postal_code = $row[10];}
if (strlen($row[11])>0) {$label_vendor_lead_code = $row[11];}
if (strlen($row[12])>0) {$label_gender = $row[12];}
if (strlen($row[13])>0) {$label_phone_number = $row[13];}
if (strlen($row[14])>0) {$label_phone_code = $row[14];}
if (strlen($row[15])>0) {$label_alt_phone = $row[15];}
if (strlen($row[16])>0) {$label_security_phrase = $row[16];}
if (strlen($row[17])>0) {$label_email = $row[17];}
if (strlen($row[18])>0) {$label_comments = $row[18];}
if (strlen($row[19])>0) {$label_lead_id = $row[19];}
if (strlen($row[20])>0) {$label_list_id = $row[20];}
if (strlen($row[21])>0) {$label_entry_date = $row[21];}
if (strlen($row[22])>0) {$label_gmt_offset_now = $row[22];}
if (strlen($row[23])>0) {$label_source_id = $row[23];}
if (strlen($row[24])>0) {$label_called_since_last_reset = $row[24];}
if (strlen($row[25])>0) {$label_status = $row[25];}
if (strlen($row[26])>0) {$label_user = $row[26];}
if (strlen($row[27])>0) {$label_date_of_birth = $row[27];}
if (strlen($row[28])>0) {$label_country_code = $row[28];}
if (strlen($row[29])>0) {$label_last_local_call_time = $row[29];}
if (strlen($row[30])>0) {$label_called_count = $row[30];}
if (strlen($row[31])>0) {$label_rank = $row[31];}
if (strlen($row[32])>0) {$label_owner = $row[32];}
if (strlen($row[33])>0) {$label_entry_list_id = $row[33];}
##### BEGIN vicidial_list FIELD LENGTH LOOKUP #####
$MAXvendor_lead_code = '20';
$MAXsource_id = '50';
$MAXphone_code = '10';
$MAXphone_number = '18';
$MAXtitle = '4';
$MAXfirst_name = '30';
$MAXmiddle_initial = '1';
$MAXlast_name = '30';
$MAXaddress1 = '100';
$MAXaddress2 = '100';
$MAXaddress3 = '100';
$MAXcity = '50';
$MAXstate = '2';
$MAXprovince = '50';
$MAXpostal_code = '10';
$MAXalt_phone = '12';
$MAXemail = '70';
$MAXsecurity_phrase = '100';
$MAXcountry_code = '3';
$MAXowner = '20';
$stmt = "SHOW COLUMNS FROM vicidial_list;";
$rslt=mysql_to_mysqli($stmt, $link);
if ($DB) {echo "$stmt\n";}
$scvl_ct = mysqli_num_rows($rslt);
$s=0;
while ($scvl_ct > $s)
{
$row=mysqli_fetch_row($rslt);
$vl_field = $row[0];
$vl_type = preg_replace("/[^0-9]/",'',$row[1]);
if (strlen($vl_type) > 0)
{
if ( ($vl_field == 'vendor_lead_code') and ($MAXvendor_lead_code != $vl_type) )
{$MAXvendor_lead_code = $vl_type;}
if ( ($vl_field == 'source_id') and ($MAXsource_id != $vl_type) )
{$MAXsource_id = $vl_type;}
if ( ($vl_field == 'phone_code') and ($MAXphone_code != $vl_type) )
{$MAXphone_code = $vl_type;}
if ( ($vl_field == 'phone_number') and ($MAXphone_number != $vl_type) )
{$MAXphone_number = $vl_type;}
if ( ($vl_field == 'title') and ($MAXtitle != $vl_type) )
{$MAXtitle = $vl_type;}
if ( ($vl_field == 'first_name') and ($MAXfirst_name != $vl_type) )
{$MAXfirst_name = $vl_type;}
if ( ($vl_field == 'middle_initial') and ($MAXmiddle_initial != $vl_type) )
{$MAXmiddle_initial = $vl_type;}
if ( ($vl_field == 'last_name') and ($MAXlast_name != $vl_type) )
{$MAXlast_name = $vl_type;}
if ( ($vl_field == 'address1') and ($MAXaddress1 != $vl_type) )
{$MAXaddress1 = $vl_type;}
if ( ($vl_field == 'address2') and ($MAXaddress2 != $vl_type) )
{$MAXaddress2 = $vl_type;}
if ( ($vl_field == 'address3') and ($MAXaddress3 != $vl_type) )
{$MAXaddress3 = $vl_type;}
if ( ($vl_field == 'city') and ($MAXcity != $vl_type) )
{$MAXcity = $vl_type;}
if ( ($vl_field == 'state') and ($MAXstate != $vl_type) )
{$MAXstate = $vl_type;}
if ( ($vl_field == 'province') and ($MAXprovince != $vl_type) )
{$MAXprovince = $vl_type;}
if ( ($vl_field == 'postal_code') and ($MAXpostal_code != $vl_type) )
{$MAXpostal_code = $vl_type;}
if ( ($vl_field == 'alt_phone') and ($MAXalt_phone != $vl_type) )
{$MAXalt_phone = $vl_type;}
if ( ($vl_field == 'email') and ($MAXemail != $vl_type) )
{$MAXemail = $vl_type;}
if ( ($vl_field == 'security_phrase') and ($MAXsecurity_phrase != $vl_type) )
{$MAXsecurity_phrase = $vl_type;}
if ( ($vl_field == 'country_code') and ($MAXcountry_code != $vl_type) )
{$MAXcountry_code = $vl_type;}
if ( ($vl_field == 'owner') and ($MAXowner != $vl_type) )
{$MAXowner = $vl_type;}
}
$s++;
}
##### END vicidial_list FIELD LENGTH LOOKUP #####
### find out if status(dispo) is a scheduled callback status
$scheduled_callback='';
$stmt="SELECT scheduled_callback from vicidial_statuses where status='$dispo';";
$rslt=mysql_to_mysqli($stmt, $link);
$scb_count_to_print = mysqli_num_rows($rslt);
if ($scb_count_to_print > 0)
{
$row=mysqli_fetch_row($rslt);
if (strlen($row[0])>0) {$scheduled_callback = $row[0];}
}
$stmt="SELECT scheduled_callback from vicidial_campaign_statuses where status='$dispo';";
$rslt=mysql_to_mysqli($stmt, $link);
$scb_count_to_print = mysqli_num_rows($rslt);
if ($scb_count_to_print > 0)
{
$row=mysqli_fetch_row($rslt);
if (strlen($row[0])>0) {$scheduled_callback = $row[0];}
}
$search_archived_data='';
if ($archive_log == 'Yes') {$search_archived_data='checked';}
$vdc_form_display = 'vdc_form_display.php';
if (preg_match("/cf_encrypt/",$active_modules))
{$vdc_form_display = 'vdc_form_display_encrypt.php';}
header ("Content-type: text/html; charset=utf-8");
echo "\n";
echo "\n";
echo " \n";
echo ""._QXZ("Modify Lead")." \n";
?>
\n";
echo " \n";
echo "\n";
echo "\n";
echo $HTML_text;
echo "";
exit;
}
$messagesHTML='';
$messagesHTML .= "\n";
### BEGIN - Add a new lead in the system ###
if ($lead_id == 'NEW')
{
$secX = date("U");
$hour = date("H");
$min = date("i");
$sec = date("s");
$mon = date("m");
$mday = date("d");
$year = date("Y");
$isdst = date("I");
$Shour = date("H");
$Smin = date("i");
$Ssec = date("s");
$Smon = date("m");
$Smday = date("d");
$Syear = date("Y");
### Grab Server GMT value from the database
$stmt="SELECT local_gmt FROM servers where active='Y' limit 1;";
$rslt=mysql_to_mysqli($stmt, $link);
$gmt_recs = mysqli_num_rows($rslt);
if ($gmt_recs > 0)
{
$row=mysqli_fetch_row($rslt);
$DBSERVER_GMT = $row[0];
if (strlen($DBSERVER_GMT)>0) {$SERVER_GMT = $DBSERVER_GMT;}
if ($isdst) {$SERVER_GMT++;}
}
else
{
$SERVER_GMT = date("O");
$SERVER_GMT = preg_replace("/\+/i","",$SERVER_GMT);
$SERVER_GMT = ($SERVER_GMT + 0);
$SERVER_GMT = ($SERVER_GMT / 100);
}
$LOCAL_GMT_OFF = $SERVER_GMT;
$LOCAL_GMT_OFF_STD = $SERVER_GMT;
$USarea = substr($phone_number, 0, 3);
$USprefix = substr($phone_number, 3, 1);
$postalgmt='';
$gmt_offset = lookup_gmt($phone_code,$USarea,$state,$LOCAL_GMT_OFF_STD,$Shour,$Smin,$Ssec,$Smon,$Smday,$Syear,$postalgmt,$postal_code,$owner,$USprefix);
$comments = preg_replace("/\n/",'!N',$comments);
$comments = preg_replace("/\r/",'',$comments);
$list_valid=0;
$stmt="SELECT count(*) from vicidial_lists where list_id='" . mysqli_real_escape_string($link, $list_id) . "' $LOGallowed_campaignsSQL;";
$rslt=mysql_to_mysqli($stmt, $link);
$list_to_print = mysqli_num_rows($rslt);
if ($list_to_print > 0)
{
$rowx=mysqli_fetch_row($rslt);
$list_valid = $rowx[0];
}
if ( ( ($list_valid > 0) or (preg_match('/\-ALL/i', $LOGallowed_campaigns)) ) and ($LOGmodify_leads != '5') )
{
$source_idSQL='';
if ($SSsource_id_display > 0)
{$source_idSQL = ",source_id='" . mysqli_real_escape_string($link, $source_id) . "'";}
$stmt="INSERT INTO vicidial_list set status='" . mysqli_real_escape_string($link, $status) . "',title='" . mysqli_real_escape_string($link, $title) . "',first_name='" . mysqli_real_escape_string($link, $first_name) . "',middle_initial='" . mysqli_real_escape_string($link, $middle_initial) . "',last_name='" . mysqli_real_escape_string($link, $last_name) . "',address1='" . mysqli_real_escape_string($link, $address1) . "',address2='" . mysqli_real_escape_string($link, $address2) . "',address3='" . mysqli_real_escape_string($link, $address3) . "',city='" . mysqli_real_escape_string($link, $city) . "',state='" . mysqli_real_escape_string($link, $state) . "',province='" . mysqli_real_escape_string($link, $province) . "',postal_code='" . mysqli_real_escape_string($link, $postal_code) . "',country_code='" . mysqli_real_escape_string($link, $country_code) . "',alt_phone='" . mysqli_real_escape_string($link, $alt_phone) . "',phone_number='$phone_number',phone_code='$phone_code',email='" . mysqli_real_escape_string($link, $email) . "',security_phrase='" . mysqli_real_escape_string($link, $security) . "',comments='" . mysqli_real_escape_string($link, $comments) . "',rank='" . mysqli_real_escape_string($link, $rank) . "',owner='" . mysqli_real_escape_string($link, $owner) . "',vendor_lead_code='" . mysqli_real_escape_string($link, $vendor_id) . "'$source_idSQL, list_id='" . mysqli_real_escape_string($link, $list_id) . "',date_of_birth='" . mysqli_real_escape_string($link, $date_of_birth) . "',gmt_offset_now='$gmt_offset',entry_date=NOW();";
if ($DB) {echo "$stmt\n";}
$rslt=mysql_to_mysqli($stmt, $link);
$affected_rows = mysqli_affected_rows($link);
if ($affected_rows > 0)
{
$lead_id = mysqli_insert_id($link);
$messagesHTML .= _QXZ("Lead has been added").": $lead_id ($gmt_offset) \n";
$end_call=0;
}
else
{$messagesHTML .= _QXZ("ERROR: Lead not added, please go back and look at what you entered")." \n";}
}
else
{
$messagesHTML .= _QXZ("you do not have permission to add this lead")." $list_id $NOW_TIME\n \n";
}
### END - Add a new lead in the system ###
}
else
{
$stmt="SELECT count(*) from $vl_table where lead_id='" . mysqli_real_escape_string($link, $lead_id) . "'";
$rslt=mysql_to_mysqli($stmt, $link);
if ($DB) {echo "$stmt\n";}
$row=mysqli_fetch_row($rslt);
$lead_exists = $row[0];
$stmt="SELECT count(*) from $vl_table where lead_id='" . mysqli_real_escape_string($link, $lead_id) . "' $LOGallowed_listsSQL";
$rslt=mysql_to_mysqli($stmt, $link);
if ($DB) {echo "$stmt\n";}
$row=mysqli_fetch_row($rslt);
$lead_count = $row[0];
if ( ($lead_exists > 0) and ($lead_count < 1) )
{
echo "\n";
echo " \n";
echo "\n";
echo "\n";
echo ""._QXZ("lead does not exist").": $lead_id \n";
echo "\n";
echo "