forked from aces/Loris
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathValidateEmailSubmitInput.php
More file actions
135 lines (120 loc) · 3.43 KB
/
Copy pathValidateEmailSubmitInput.php
File metadata and controls
135 lines (120 loc) · 3.43 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
<?php declare(strict_types=1);
/**
* This is used by the survey accounts module to validate inputs
* before the email message popup appears
*
* PHP Version 8
*
* @category Survey
* @package Loris
* @author David Blader <dblader.mcin@gmail.com>
* @license Loris license
* @link https://www.github.com/aces/Loris-Trunk/
*/
$user = \User::singleton();
if (!$user->hasPermission('survey_accounts_view')) {
header("HTTP/1.1 403 Forbidden");
exit(0);
}
header("Content-Type: application/json; charset=utf-8");
set_include_path(get_include_path().":../project/libraries:../php/libraries:");
ini_set('default_charset', 'utf-8');
require_once "Database.class.inc";
require_once 'NDB_Config.class.inc';
require_once 'NDB_Client.class.inc';
$config =& NDB_Config::singleton();
$client = new NDB_Client();
$client->makeCommandLine();
$client->initialize();
$db = \NDB_Factory::singleton()->database();
$numCandidates = $db->pselectOne(
"SELECT COUNT(*) FROM candidate
WHERE PSCID=:v_PSCID
AND CandID=:v_CandID AND Active='Y'",
[
'v_PSCID' => $_REQUEST['pscid'],
'v_CandID' => $_REQUEST['dccid'],
]
);
$error_msg = dgettext(
'survey_accounts',
'PSCID and DCCID do not match or candidate does not exist.'
);
if ($numCandidates != 1) {
echo json_encode(
['error_msg' => $error_msg]
);
exit(0);
}
$numSessions = $db->pselectOne(
"SELECT COUNT(*) FROM session s
JOIN candidate c ON (c.ID=s.CandidateID)
WHERE c.CandID=:v_CandID
AND UPPER(Visit_label)=UPPER(:v_VL)
AND s.Active='Y'",
[
'v_CandID' => $_REQUEST['dccid'],
'v_VL' => $_REQUEST['VL'],
]
);
if ($numSessions != 1) {
echo json_encode(
[
'error_msg' => dgettext('loris', 'Visit').' '.
$_REQUEST['VL'].' '.
dgettext('survey_accounts', 'does not exist for given candidate'),
]
);
exit(0);
}
if (empty($_REQUEST['TN'])) {
echo json_encode(
['error_msg' => dgettext('survey_accounts', 'Please choose an instrument.')]
);
exit(0);
}
$instrument_list = $db->pselect(
"SELECT tn.Test_name FROM flag f
JOIN session s on s.ID = f.SessionID
JOIN candidate c ON c.ID = s.CandidateID
JOIN test_names tn ON tn.ID = f.TestID
WHERE c.CandID=:v_CandID
AND UPPER(s.Visit_label)=UPPER(:v_VL)
AND s.Active='Y'",
[
'v_CandID' => $_REQUEST['dccid'],
'v_VL' => $_REQUEST['VL'],
]
);
foreach ($instrument_list as $instrument) {
if ($_REQUEST['TN'] == $instrument['Test_name']) {
echo json_encode(
[
'error_msg' => dcngettext(
'loris',
'Instrument',
'Instruments',
1,
LC_MESSAGES
).' '. $_REQUEST['TN'].' ' .dgettext(
'survey_accounts',
'already exists for given candidate for visit'
).' '. $_REQUEST['VL'],
]
);
exit(0);
}
}
if (!empty($_REQUEST['Email']) ) {
if (!filter_var($_REQUEST['Email'], FILTER_VALIDATE_EMAIL) ) {
echo json_encode(
['error_msg' => dgettext(
'survey_accounts',
'Email is not valid.'
)
]
);
exit(0);
}
}
print "";