Files
mrbs-equbao-2026/del_entry.php
T
人事系统开发 1ba6efd8ed MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、
强制改密、登录审计日志、屏幕水印、企业背景图、
备案信息固定底部、favicon、JS空集合保护、
会话过期体验优化(403 JSON)、display_errors 关闭、
固定 key 根治 Integrity check failed 等全部改动

注意:config.inc.php/.htaccess/.user.ini 含敏感信息,
通过 .gitignore 排除,勿推送到公开仓库。
2026-09-09 16:55:02 +08:00

113 lines
3.8 KiB
PHP

<?php
declare(strict_types=1);
namespace MRBS;
use MRBS\Form\Form;
// Deletes an entry, or a series. The $id is always the id of
// an individual entry. If $series is set then the entire series
// of which $id is a member should be deleted. [Note - this use of
// $series is inconsistent with use in the rest of MRBS where it
// means that $id is the id of an entry in the repeat table. This
// should be fixed sometime.]
require "defaultincludes.inc";
require_once "mrbs_sql.inc";
require_once "functions_mail.inc";
// Get non-standard form variables
$id = get_form_var('id', 'int', null, INPUT_POST);
$series = get_form_var('series', 'bool', null, INPUT_POST);
$returl = get_form_var('returl', 'url_local', null, INPUT_POST);
$action = get_form_var('action', 'string', 'delete', INPUT_POST);
$note = get_form_var('note', 'string', '', INPUT_POST);
// Check the CSRF token
Form::checkToken();
// Check the user is authorised for this page
checkAuthorised(this_page());
if (empty($returl))
{
$vars = array('view' => $default_view,
'year' => $year,
'month' => $month,
'day' => $day,
'area' => $area,
'room' => $room);
$returl .= 'index.php?' . http_build_query($vars, '', '&');
}
if ($info = get_booking_info($id, FALSE, TRUE))
{
// check that the user is allowed to delete this entry
if (isset($action) && ($action == "reject"))
{
$authorised = is_book_admin($info['room_id']);
}
else
{
$authorised = getWritable($info['create_by'], $info['room_id']);
}
if ($authorised)
{
$day = (int) date('d', $info['start_time']);
$month = (int) date('m', $info['start_time']);
$year = (int) date('Y', $info['start_time']);
$area = get_area($info["room_id"]);
if (empty($area))
{
throw new \Exception("Room " . $info['room_id'] . " does not exist");
}
// Get the settings for this area (they will be needed for policy checking)
get_area_settings($area);
$notify_by_email = $mail_settings['on_delete'] && need_to_send_mail();
if ($notify_by_email)
{
// Gather all fields values for use in emails.
$mail_previous = get_booking_info($id, FALSE);
// If this is an individual entry of a series then force the entry_type
// to be a changed entry, so that when we create the iCalendar object we know that
// we only want to delete the individual entry
if (!$series && ($mail_previous['repeat_rule']->getType() != RepeatRule::NONE))
{
$mail_previous['entry_type'] = ENTRY_RPT_CHANGED;
}
}
$start_times = mrbsDelEntry($id, $series, true);
// [At the moment MRBS does not inform the user if it was not able to delete
// an entry, or, for a series, some entries in a series. This could happen for
// example if a booking policy is in force that prevents the deletion of entries
// in the past. It would be better to inform the user that the operation has
// been unsuccessful or only partially successful]
if (($start_times !== FALSE) && (count($start_times) > 0))
{
// Send a mail to the Administrator
if ($notify_by_email)
{
// Now that we've finished with mrbsDelEntry, change the id so that it's
// the repeat_id if we're looking at a series. (This is a complete hack,
// but brings us back into line with the rest of MRBS until the anomaly
// of del_entry is fixed)
if ($series)
{
$mail_previous['id'] = $mail_previous['repeat_id'];
}
notify_by_email($mail_previous, [], $series, $action, $start_times, $note);
}
}
location_header($returl);
}
}
// If you got this far then we got an access denied.
showAccessDenied($view, $view_all, $year, $month, $day, $area);