login.class.php 84 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527
  1. <?php
  2. if (!defined('IN_ONLINE')) {
  3. exit('Access Denied');
  4. }
  5. /**
  6. * Description of login
  7. *
  8. * @author Administrator
  9. */
  10. class login {
  11. private static $_login;
  12. public static function getInstance() {
  13. if (!self::$_login) {
  14. $c = __CLASS__;
  15. self::$_login = new $c;
  16. }
  17. return self::$_login;
  18. }
  19. private function getLoginSql($uname) {
  20. return "select user_login,(select active from public.employee ee where ee.employee_id=u.employee_id) as employee_id_active, can_visit_vgm,can_add_booking, can_add_tk_status,truck_driver,po_booking,o_final_delivery_u,ipad_view_po,can_view_doc,can_upload_doc,can_add_catalog,can_add_po,packing_list_company,is_only_vgm,contact_id_user,is_demo, ra_password as password,employee_id, contact_id, user_type, last_pwd_change, EXTRACT(DAY from (now() - last_pwd_change)) as last_pwd_change_date, email, user_webtype_id, active, is_online, station, allow_login_remote, can_see_amslog,can_view_eccn, can_see_isflog, can_see_isflog_withaddress,
  21. customer_search_type, customer_destination, can_add_ams, can_add_isf, air_station, air_sales, ocean_station, ocean_sales,ocean_following_sales,ocean_following_sales_or,air_following_sales,air_following_sales_or, trucking_station, ocean_dest_op, can_see_password, can_add_opsales_code, ocean_station_or, ocean_agent_or, ocean_sales_or, ocean_dest_op_or, air_station_or, air_sales_or, trucking_station_or,
  22. can_add_user, can_add_employee, can_add_contact, company_name, ams_email, isf_email, customer_discharge, online_active, is_super, ocean_agent,active, can_send_email, view_file_format as docdownload, container_status, consolidated_cbsa_code, can_add_aci,
  23. air_customers, air_customer_search_type,trucking_customers,trucking_customer_search_type, upload_document, view_file_format, event_type, belong_schemas, main_schemas, error_login_count, EXTRACT(EPOCH FROM (now()-COALESCE(error_login_time, now()))) as second, po_status, view_air_file_format,
  24. special_customer_event, can_edi_vgm, isf_aci_ams_station,login_version,is_kerry_shipment,can_visit_delivery,currency_group from public.ra_online_user u where lower(user_login) = '" . strtolower($uname) . "'";
  25. }
  26. public function do_login() {
  27. $login_error_times = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Login_Error_Times'");
  28. $lock_user_seconds = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Lock_User_Seconds'");
  29. if (!empty($uname) || !empty($password)) {
  30. } else {
  31. $uname = common::check_input($_POST['uname']);
  32. //如是是token登录,则不用验证密码和verifcation_code
  33. if(!(isset($_POST['token']))){
  34. $is_verify = common::check_input($_POST['verifcation_code']);
  35. //首先校用户登录
  36. $AES_encrypted = $this->AES_encrypted($is_verify);
  37. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  38. where secret_key = '$is_verify'
  39. and create_time >= current_date - INTERVAL '3 months' limit 1");
  40. //记录这次的密钥记录
  41. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  42. if(!empty($AES_encrypted) && empty($secret_key)){
  43. }else{
  44. $data = array(
  45. 'msg' => 'verifcation_error',
  46. 'data' => ''
  47. );
  48. common::echo_json_encode(400, $data);
  49. exit();
  50. }
  51. }
  52. $sql = $this->getLoginSql($uname);
  53. $rs = common::excuteObjectSql($sql);
  54. if (!empty($rs)) {
  55. if (empty($rs['belong_schemas'])) {
  56. $rs['belong_schemas'] = "public";
  57. }
  58. if (empty($rs['main_schemas'])) {
  59. $rs['main_schemas'] = "public";
  60. }
  61. //验证employee是否active
  62. if (!empty($rs["employee_id"]) && $rs["employee_id_active"] != "t") {
  63. if (strtolower(Soure) =='topocean'){
  64. if (strtolower($rs['user_type']) == "employee" && utils::endWith($rs['email'], "cn")) {
  65. $data = "<a href='mailto:lilyyang@topocean.com.cn'>lilyyang@topocean.com.cn</a>";
  66. }else{
  67. $data = "<a href='mailto:winnie@topocean.com'>winnie@topocean.com</a>";
  68. }
  69. }
  70. if (strtolower(Soure) =='apex'){
  71. $data = "<a href='mailto:maria.wang@apexshipping.com.cn'>maria.wang@apexshipping.com.cn</a>";
  72. }
  73. $data = array(
  74. 'code' => 'no_active',
  75. 'login_version' => $rs["login_version"],
  76. 'data' => $data,
  77. 'msg' => "Please check with Doc Center $data for searching function"
  78. );
  79. common::echo_json_encode(500, $data);
  80. $this->failedLogin($uname, 'Employee not active');
  81. exit();
  82. }
  83. //处理登录状态
  84. $userInfo = common::check_input($_COOKIE['userInfo']);
  85. $noCheckPwd = false;
  86. if (!empty($userInfo)) {
  87. $userInfoSplit = explode("_", $userInfo);
  88. if ($uname == $userInfoSplit[0]) {
  89. if ($userInfoSplit[1] == md5($rs['password'])) {
  90. $noCheckPwd = true;
  91. }
  92. }
  93. }
  94. if ($rs['error_login_count'] > $login_error_times && $rs['second'] < $lock_user_seconds) {
  95. $data = array(
  96. 'msg' => 'error_times',
  97. 'login_version' => $rs["login_version"],
  98. 'data' => ceil(($lock_user_seconds - $rs['second']) / 60)
  99. );
  100. common::echo_json_encode(400, $data);
  101. $this->failedLogin($uname, 'Failed login too times');
  102. exit();
  103. }
  104. if ($rs['is_online'] != 't') {
  105. if (strtolower($rs['user_type']) != "employee") {
  106. $data =array(
  107. 'code' => 'no_online',
  108. 'login_version' => $rs["login_version"],
  109. 'data' => '',
  110. 'msg' => 'No activation or insufficient permissions'
  111. );
  112. common::echo_json_encode(500, $data);
  113. $this->failedLogin($uname, 'Online is not active');
  114. exit();
  115. }
  116. }
  117. //if ($rs['decrypt_password'] != $_POST['psw']) {
  118. if ($noCheckPwd) {
  119. }else{
  120. //如是是token登录,则不用验证密码
  121. if(isset($_POST['token']) && !empty($_POST['token'])){
  122. $is_verify = $_POST['token'];
  123. $AES_encrypted = $this->AES_encrypted($is_verify);
  124. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  125. where secret_key = '$is_verify'
  126. and create_time >= current_date - INTERVAL '3 months' limit 1");
  127. //记录这次的密钥记录
  128. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  129. //密钥解析失败或者有重复的记录这提示登录失败
  130. if(!(!empty($AES_encrypted) && empty($secret_key))){
  131. $data = array(
  132. 'msg' => 'Invalid token',
  133. 'login_version' => $rs["login_version"],
  134. 'data' => ''
  135. );
  136. common::echo_json_encode(400, $data);
  137. exit();
  138. }
  139. }else{
  140. if ($rs['password'] != $_POST['psw']) {
  141. common::excuteUpdateSql("update public.ra_online_user set error_login_count=error_login_count+1, error_login_time=now() where lower(user_login) = '" . strtolower($uname) . "'");
  142. $data = array(
  143. 'msg' => 'password_error',
  144. 'login_version' => $rs["login_version"],
  145. 'data' => ''
  146. );
  147. common::echo_json_encode(400, $data);
  148. $this->failedLogin($uname, 'Password is wrong');
  149. exit();
  150. }
  151. }
  152. }
  153. if ($rs['online_active'] != 't') {
  154. $data = array(
  155. 'code' => 'no_active',
  156. 'login_version' => $rs["login_version"],
  157. 'data' => '',
  158. 'msg' => 'Please check with Doc Center for searching function'
  159. );
  160. common::echo_json_encode(500, $data);
  161. $this->failedLogin($uname, 'Online is not active');
  162. exit();
  163. }
  164. //check password length
  165. $tar = utils::checkPassword($rs['password']);
  166. if (!empty($tar)) {
  167. $data = array(
  168. 'code' => $tar,
  169. 'login_version' => $rs["login_version"],
  170. 'data' => '',
  171. 'msg' => $tar
  172. );
  173. common::echo_json_encode(500, $data);
  174. exit();
  175. }
  176. if (empty($rs['last_pwd_change'])) {
  177. $data = array(
  178. 'code' => 'first_login',
  179. 'login_version' => $rs["login_version"],
  180. 'data' => '',
  181. 'msg' => 'First login, please change your password'
  182. );
  183. common::echo_json_encode(500, $data);
  184. exit();
  185. }
  186. //get more infor by employee_id or contact_id
  187. $sql = '';
  188. $diffdate = $rs['last_pwd_change_date'];
  189. $user_type = $rs['user_type'];
  190. //if user is customer, check company
  191. if (strtolower($user_type) == 'customer') {
  192. $company = $rs['company_name'];
  193. } else {
  194. if (!empty($rs['station']))
  195. $company = $rs['station'];
  196. }
  197. if (strtolower($uname) == 'ra.admin') {
  198. $company = 'Admin';
  199. }
  200. // get system config
  201. $sql = "SELECT lower(ra_name) as ra_name, ra_value from ra_online_config where lower(ra_name) in ('employee_session_timeout', 'customer_session_timeout', 'password_change_alert', 'employee_password_change_cycle', 'customer_password_change_cycle')";
  202. $rs1s = common::excuteListSql($sql);
  203. foreach ($rs1s as $rs1) {
  204. if ($rs1['ra_name'] == 'employee_session_timeout')
  205. $EMPLOYEE_SESSION_TIMEOUT = $rs1['ra_value'];
  206. if ($rs1['ra_name'] == 'customer_session_timeout')
  207. $CUSTOMER_SESSION_TIMEOUT = $rs1['ra_value'];
  208. if ($rs1['ra_name'] == 'password_change_alert')
  209. $PASSWORD_CHANGE_ALERT = $rs1['ra_value'];
  210. if ($rs1['ra_name'] == 'employee_password_change_cycle')
  211. $EMPLOYEE_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  212. if ($rs1['ra_name'] == 'customer_password_change_cycle')
  213. $CUSTOMER_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  214. }
  215. $sql="select item_value from config where item='passwordChangePeriod'";
  216. $pcp = common::excuteObjectSql($sql);
  217. $passwordChangePeriod = json_decode($pcp["item_value"],true);
  218. if (strtolower($rs['user_type']) == 'employee') {
  219. $PASSWORD_CHANGE_CYCLE = $EMPLOYEE_PASSWORD_CHANGE_CYCLE;
  220. $SESSION_TIMEOUT = $EMPLOYEE_SESSION_TIMEOUT;
  221. //如果有新配置,则采用新配置
  222. if (!empty($pcp)) {
  223. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Employee"]["days"];
  224. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Employee"]["advanceDays"];
  225. }
  226. } else {
  227. $PASSWORD_CHANGE_CYCLE = $CUSTOMER_PASSWORD_CHANGE_CYCLE;
  228. $SESSION_TIMEOUT = $CUSTOMER_SESSION_TIMEOUT;
  229. //如果有新配置,则采用新配置
  230. if (!empty($pcp)) {
  231. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Customer"]["days"];
  232. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Customer"]["advanceDays"];
  233. }
  234. }
  235. $loginName = $rs['user_login'];
  236. $email = $rs['email'];
  237. //Timeout
  238. if ($diffdate > $PASSWORD_CHANGE_CYCLE) {
  239. if(empty($email)){
  240. $data = array(
  241. 'status' => '0',
  242. 'code' => 'login user email is empty',
  243. 'login_version' => $rs["login_version"],
  244. 'msg' => 'login user email is empty'
  245. );
  246. common::echo_json_encode(500, $data);
  247. exit();
  248. }else{
  249. $this -> passwordExpires($loginName,$email,$uname);
  250. }
  251. }
  252. if ($diffdate == $PASSWORD_CHANGE_CYCLE) {// Due today
  253. $login_tmp = array(
  254. 'msg' => 'today',
  255. 'uname' => $uname,
  256. 'login_version' => $rs["login_version"],
  257. 'data' => ''
  258. );
  259. } elseif ($diffdate >= ($PASSWORD_CHANGE_CYCLE - $PASSWORD_CHANGE_ALERT)) {// Password expires soon, JS Tips
  260. $login_tmp = array(
  261. 'msg' => 'last',
  262. 'uname' => $uname,
  263. 'login_version' => $rs["login_version"],
  264. 'data' => $PASSWORD_CHANGE_CYCLE - $diffdate,
  265. 'is_only_vgm' => $rs["is_only_vgm"]
  266. );
  267. }
  268. //insert into log table
  269. $ip = common::ip();
  270. $sql = "insert into public.ra_online_user_login_log (user_name,manufacturer,from_app,ip,date_time, session_id) values ('" . common::check_input($uname) . "', '" . common::check_input($company) . "','Online','$ip',now(), '" . session_id() . "')";
  271. if (common::excuteUpdateSql($sql)) {
  272. common::excuteUpdateSql("update public.ra_online_user set Last_Login_Time = now(), error_login_count=0, error_login_time=null where lower(user_login) = '" . strtolower($uname) . "'");
  273. if (isset($login_tmp)) {
  274. common::echo_json_encode(200, $login_tmp);
  275. } else {
  276. $data = array(
  277. 'msg' => 'success',
  278. 'uname' => $uname,
  279. 'login_version' => $rs["login_version"],
  280. 'data' => '',
  281. 'is_only_vgm' => $rs["is_only_vgm"]
  282. );
  283. common::echo_json_encode(200, $data);
  284. }
  285. $online_user = $rs;
  286. $online_user['user_login'] = $uname;
  287. $online_user['company'] = $company;
  288. $online_user['password'] = "";
  289. if (!_isAdmin()) {
  290. if ($rs["is_only_vgm"] == "t") {//VGM用户写死
  291. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where url_action in ('ocean_order','password','vgm') and menu_id in ('ship','profile') order by order_by asc), ',')";
  292. $rrrs = common::excuteOneSql($sql);
  293. } else {
  294. $sql = "select array_to_string(ARRAY(select p.url_action from public.ra_online_user_permission up left join public.ra_online_user u on up.user_name = u.user_login left join public.ra_online_permission p on up.p_id = p.id where lower(u.user_login) = '" . common::check_input(strtolower($uname)) . "'), ',')";
  295. $rrrs = common::excuteOneSql($sql);
  296. if (strtolower($rs['user_type']) == "employee" && empty($rrrs)) {
  297. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where is_customer = true order by order_by asc), ',')";
  298. $rrrs = common::excuteOneSql($sql);
  299. }
  300. }
  301. $online_user['permission'] = $rrrs;
  302. }
  303. if (!empty($online_user['docdownload']))
  304. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where lower(serial_no) " . common::getInNotInSql($online_user['docdownload']) . " and active = true group by display_name order by min(id)";
  305. else {
  306. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where active = true";
  307. if (strtolower($online_user['user_type']) == "customer")
  308. $sql .= " and client_display = true";
  309. $sql .= " group by display_name order by min(id)";
  310. }
  311. $online_user['view_doc_type'] = common::excuteListSql($sql);
  312. if (!empty($online_user['view_air_file_format']))
  313. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where lower(serial_no) " . common::getInNotInSql($online_user['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  314. else {
  315. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where active = true";
  316. if (strtolower($online_user['user_type']) == "customer")
  317. $sql .= " and client_display = true";
  318. $sql .= " group by display_name order by min(id)";
  319. }
  320. $online_user['view_air_doc_type'] = common::excuteListSql($sql);
  321. //补充aci and ams CustomerLogin station - public
  322. $ocean_station_temp = $online_user['ocean_station'];
  323. $online_user['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  324. $ocean_agent_temp = $online_user['ocean_agent'];
  325. $online_user['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  326. $_SESSION['ONLINE_USER'] = $online_user;
  327. $_SESSION['LAST_OPERATE_TIME'] = time();
  328. $_SESSION['SESSION_TIMEOUT'] = $SESSION_TIMEOUT;
  329. //判断是否记录密码 add
  330. if ($_POST['rememberpwd'] === 'true') {
  331. if (!$noCheckPwd) {
  332. $user_info = $uname . "_" . md5($rs['password']);
  333. setcookie('userInfo', $user_info, time() + 30 * 24 * 3600, "/");
  334. }
  335. } else {
  336. setcookie('userInfo', '', time() - 1, "/");
  337. }
  338. if ($rs['is_super'] == "t") {
  339. $schemas_list = common::excuteListSql("select * from schemas_list");
  340. } else {
  341. $schemas_list = common::excuteListSql("select * from schemas_list where schemas_name=any(regexp_split_to_array('" . $rs['belong_schemas'] . "'::text, ';'::text))");
  342. }
  343. ///if (count($schemas_list) > 1) {
  344. foreach ($schemas_list as $sk => $sv) {
  345. if ($sv['schemas_name'] == "public") {
  346. continue;
  347. }
  348. $ttdd = common::excuteObjectSql("select contact_id_user, employee_id, contact_id, user_type, email, user_webtype_id, active, is_online, station, allow_login_remote, can_see_amslog,can_view_eccn, can_see_isflog, can_see_isflog_withaddress,
  349. customer_search_type, customer_destination, can_add_ams, can_add_isf, air_station, air_sales, ocean_station, ocean_sales,ocean_following_sales,ocean_following_sales_or,air_following_sales,air_following_sales_or, trucking_station, ocean_dest_op, can_see_password, can_add_opsales_code, ocean_station_or, ocean_agent_or, ocean_sales_or, ocean_dest_op_or, air_station_or, air_sales_or, trucking_station_or,
  350. can_add_user, can_add_employee, can_add_contact, company_name, ams_email, isf_email, customer_discharge, online_active, is_super, ocean_agent,active, can_send_email, view_file_format as docdownload, container_status, consolidated_cbsa_code, can_add_aci,
  351. air_customers, air_customer_search_type,trucking_customers,trucking_customer_search_type, upload_document, view_file_format, event_type, po_status, view_air_file_format, special_customer_event, can_edi_vgm, isf_aci_ams_station, is_kerry_shipment from " . $sv['schemas_name'] . ".ra_online_user where lower(user_login) = '" . strtolower($uname) . "'");
  352. if (empty($ttdd)) {
  353. unset($schemas_list[$sk]);
  354. continue;
  355. }
  356. if (!empty($ttdd['docdownload'])) {
  357. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['docdownload']) . " and active = true group by display_name order by min(id)";
  358. } else {
  359. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where active = true";
  360. if (strtolower($ttdd['user_type']) == "customer")
  361. $sql .= " and client_display = true";
  362. $sql .= " group by display_name order by min(id)";
  363. }
  364. $ttdd['view_doc_type'] = common::excuteListSql($sql);
  365. if (!empty($ttdd['view_air_file_format'])) {
  366. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  367. } else {
  368. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where active = true";
  369. if (strtolower($ttdd['user_type']) == "customer")
  370. $sql .= " and client_display = true";
  371. $sql .= " group by display_name order by min(id)";
  372. }
  373. $ttdd['view_air_doc_type'] = common::excuteListSql($sql);
  374. //补充aci and ams CustomerLogin station - other like sfs
  375. $ocean_station_temp = $ttdd['ocean_station'];
  376. $ttdd['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  377. $ocean_agent_temp = $ttdd['ocean_agent'];
  378. $ttdd['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  379. $_SESSION[$sv['schemas_name'] . '_ONLINE_USER'] = $ttdd;
  380. }
  381. //}
  382. $_SESSION['schemas_list'] = $schemas_list;
  383. //不再返回登录页面,直接跳转
  384. if (isset($_GET['up'])) {
  385. if($_GET['v'] == 'new'){
  386. header("Location: main_new_version.php?action=main");
  387. }else{
  388. header("Location: main.php?action=main");
  389. }
  390. }
  391. exit();
  392. } else {
  393. $data = array(
  394. 'code' => 'database_error',
  395. 'login_version' => $rs["login_version"],
  396. 'msg' => 'database_error'
  397. );
  398. common::echo_json_encode(500, $data);
  399. exit();
  400. }
  401. } else {
  402. $data = array(
  403. 'code' => 'no_exist',
  404. 'login_version' => $rs["login_version"],
  405. 'msg' => 'The username or password you entered is incorrect'
  406. );
  407. common::echo_json_encode(500, $data);
  408. exit();
  409. }
  410. }
  411. }
  412. public function check_uname(){
  413. $uname = common::check_input($_POST['uname']);
  414. $sql = $this->getLoginSql($uname);
  415. $rs = common::excuteObjectSql($sql);
  416. if (!empty($rs)) {
  417. //只是验证用户是否存在,是否激活
  418. //验证employee是否active
  419. if (!empty($rs["employee_id"]) && $rs["employee_id_active"] != "t") {
  420. if (strtolower(Soure) =='topocean'){
  421. if (strtolower($rs['user_type']) == "employee" && utils::endWith($rs['email'], "cn")) {
  422. $data = "<a href='mailto:lilyyang@topocean.com.cn'>lilyyang@topocean.com.cn</a>";
  423. }else{
  424. $data = "<a href='mailto:winnie@topocean.com'>winnie@topocean.com</a>";
  425. }
  426. }
  427. if (strtolower(Soure) =='apex'){
  428. $data = "<a href='mailto:maria.wang@apexshipping.com.cn'>maria.wang@apexshipping.com.cn</a>";
  429. }
  430. $data = array(
  431. 'msg' => 'no_active',
  432. );
  433. common::echo_json_encode(200, $data);
  434. exit();
  435. }
  436. if ($rs['is_online'] != 't') {
  437. if (strtolower($rs['user_type']) != "employee") {
  438. $data =array(
  439. 'msg' => 'no_online',
  440. );
  441. common::echo_json_encode(200, $data);
  442. exit();
  443. }
  444. }
  445. if ($rs['online_active'] != 't') {
  446. $data = array(
  447. 'msg' => 'no_active',
  448. );
  449. common::echo_json_encode(200, $data);
  450. exit();
  451. }
  452. //验证成功
  453. $data = array(
  454. 'msg' => 'success',
  455. );
  456. common::echo_json_encode(200, $data);
  457. exit();
  458. } else {
  459. $data = array(
  460. 'msg' => 'no_exist',
  461. );
  462. common::echo_json_encode(200, $data);
  463. exit();
  464. }
  465. }
  466. public function verifcation_code(){
  467. // 生成一个4位随机数作为验证码
  468. //$random_num = mt_rand(1000, 9999);
  469. $random_num = $this->generateCaptcha(4);
  470. $_SESSION['captcha'] = $random_num;
  471. // 创建一个宽度为80像素、高度为30像素的图片
  472. $width = 130;
  473. $height = 40;
  474. $image = imagecreate($width, $height);
  475. // 设置颜色
  476. $white = imagecolorallocate($image, 255, 255, 255); // 白色作为背景
  477. $black = imagecolorallocate($image, 0, 0, 0); // 黑色作为文字
  478. // 填充背景
  479. imagefilledrectangle($image, 0, 0, $width, $height, $white);
  480. // 在图片上绘制四个字符
  481. $font_size = 18;
  482. $x = 34;
  483. $y = 12;
  484. for ($i = 0; $i < 4; $i++) {
  485. $char = substr($random_num, $i, 1);
  486. imagestring($image, $font_size, $x, $y, $char, $black);
  487. $x += $font_size+1;
  488. }
  489. // 返回Base64编码
  490. ob_start();
  491. imagepng($image);
  492. $image_data = ob_get_clean();
  493. // 释放内存
  494. imagedestroy($image);
  495. $data = array("imagePngBase64" =>base64_encode($image_data));
  496. common::echo_json_encode(200, $data);
  497. exit();
  498. }
  499. //邮件密码原文
  500. public function forgot_password() {
  501. $login = common::check_input($_POST['login']);
  502. $email = common::check_input($_POST['email']);
  503. $is_verify = common::check_input($_POST['verifcation_code']);
  504. //首先校用户验证
  505. $AES_encrypted = $this->AES_encrypted($is_verify);
  506. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  507. where secret_key = '$is_verify'
  508. and create_time >= current_date - INTERVAL '3 months' limit 1");
  509. //记录这次的密钥记录
  510. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  511. if(!empty($AES_encrypted) && empty($secret_key)){
  512. }else{
  513. $data = array(
  514. 'msg' => 'verifcation_error',
  515. 'data' => ''
  516. );
  517. common::echo_json_encode(400, $data);
  518. exit();
  519. }
  520. $msg = "";
  521. if (!empty($email) || !empty($login)) {
  522. $sql_p = "select User_Login, ra_password as password from public.ra_online_user where lower(user_login) = '" . strtolower($login) . "' and lower(email) = '" . strtolower($email) . "'";
  523. $rs = common::excuteObjectSql($sql_p);
  524. if (!empty($rs)) {
  525. $r = utils::sendEmailByPassword($login, $rs['password'], $email);
  526. if ($r == 'success') {
  527. $msg = "success";
  528. } else {
  529. $msg = $r;
  530. }
  531. } else {
  532. $msg = "Can not find this user with give login id and email, please confirm!";
  533. }
  534. } else {
  535. $msg = "Login Name or Email Required !";
  536. }
  537. if($msg == 'success'){
  538. $data = array(
  539. 'msg' => $msg,
  540. );
  541. common::echo_json_encode(200, $data);
  542. }else{
  543. $data = array(
  544. 'msg' => $msg,
  545. );
  546. common::echo_json_encode(500, $data);
  547. }
  548. exit();
  549. }
  550. public function generateCaptcha($length = 6) {
  551. $captcha = '';
  552. $chars = "abcdefghijkmnpqrstuvwxyzABCDEFGHIJKLMNPQRSTUVWXYZ23456789";
  553. for ($i = 0; $i < $length; $i++) {
  554. // 随机选择字母或数字
  555. $char = $chars[mt_rand(0, strlen($chars) - 1)];
  556. $captcha .= strval($char);
  557. }
  558. return $captcha;
  559. }
  560. public function do_login_auto() {
  561. $uname = common::check_input($_GET['u']);
  562. $password = common::check_input($_GET['p']);
  563. $login_error_times = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Login_Error_Times'");
  564. $lock_user_seconds = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Lock_User_Seconds'");
  565. if (!empty($uname) || !empty($password)) {
  566. } else {
  567. $uname = common::check_input($_POST['uname']);
  568. $sql = $this->getLoginSql($uname);
  569. $rs = common::excuteObjectSql($sql);
  570. if (empty($rs['belong_schemas'])) {
  571. $rs['belong_schemas'] = "public";
  572. }
  573. if (empty($rs['main_schemas'])) {
  574. $rs['main_schemas'] = "public";
  575. }
  576. if (!empty($rs)) {
  577. //验证employee是否active
  578. if (!empty($rs["employee_id"]) && $rs["employee_id_active"] != "t") {
  579. if (strtolower(Soure) =='topocean'){
  580. if (strtolower($rs['user_type']) == "employee" && utils::endWith($rs['email'], "cn")) {
  581. $data = "<a href='mailto:lilyyang@topocean.com.cn'>lilyyang@topocean.com.cn</a>";
  582. }else{
  583. $data = "<a href='mailto:winnie@topocean.com'>winnie@topocean.com</a>";
  584. }
  585. }
  586. if (strtolower(Soure) =='apex'){
  587. $data = "<a href='mailto:maria.wang@apexshipping.com.cn'>maria.wang@apexshipping.com.cn</a>";
  588. }
  589. $data = array(
  590. 'msg' => 'no_active',
  591. 'login_version' => $rs["login_version"],
  592. 'data' => $data
  593. );
  594. common::echo_json_encode(500, $data);
  595. $this->failedLogin($uname, 'Employee not active');
  596. exit();
  597. }
  598. //add 处理登录状态
  599. $userInfo = common::check_input($_COOKIE['userInfo']);
  600. $noCheckPwd = false;
  601. if (!empty($userInfo)) {
  602. $userInfoSplit = explode("_", $userInfo);
  603. if ($uname == $userInfoSplit[0]) {
  604. if ($userInfoSplit[1] == md5($rs['password'])) {
  605. $noCheckPwd = true;
  606. }
  607. }
  608. }
  609. //if (!$noCheckPwd) {
  610. if ($rs['error_login_count'] > $login_error_times && $rs['second'] < $lock_user_seconds) {
  611. $data = array(
  612. 'msg' => 'error_times',
  613. 'login_version' => $rs["login_version"],
  614. 'data' => ceil(($lock_user_seconds - $rs['second']) / 60)
  615. );
  616. common::echo_json_encode(500, $data);
  617. $this->failedLogin($uname, 'Failed login too times');
  618. exit();
  619. }
  620. if ($rs['is_online'] != 't') {
  621. if (strtolower($rs['user_type']) != "employee") {
  622. $data =array(
  623. 'msg' => 'no_online',
  624. 'login_version' => $rs["login_version"],
  625. 'data' => ''
  626. );
  627. common::echo_json_encode(500, $data);
  628. $this->failedLogin($uname, 'Online is not active');
  629. exit();
  630. }
  631. }
  632. //if ($rs['decrypt_password'] != $_POST['psw']) {
  633. if ($noCheckPwd) {
  634. }else{
  635. if ($rs['password'] != $_POST['psw']) {
  636. common::excuteUpdateSql("update public.ra_online_user set error_login_count=error_login_count+1, error_login_time=now() where lower(user_login) = '" . strtolower($uname) . "'");
  637. $data = array(
  638. 'msg' => 'password_error',
  639. 'login_version' => $rs["login_version"],
  640. 'data' => ''
  641. );
  642. common::echo_json_encode(500, $data);
  643. $this->failedLogin($uname, 'Password is wrong');
  644. exit();
  645. }
  646. }
  647. if ($rs['online_active'] != 't') {
  648. $data = array(
  649. 'msg' => 'no_active',
  650. 'login_version' => $rs["login_version"],
  651. 'data' => ''
  652. );
  653. common::echo_json_encode(500, $data);
  654. $this->failedLogin($uname, 'Online is not active');
  655. exit();
  656. }
  657. //check password length
  658. $tar = utils::checkPassword($rs['password']);
  659. if (!empty($tar)) {
  660. $data = array(
  661. 'msg' => $tar,
  662. 'login_version' => $rs["login_version"],
  663. 'data' => ''
  664. );
  665. common::echo_json_encode(500, $data);
  666. exit();
  667. }
  668. if (empty($rs['last_pwd_change'])) {
  669. $data = array(
  670. 'msg' => 'first_login',
  671. 'login_version' => $rs["login_version"],
  672. 'data' => ''
  673. );
  674. common::echo_json_encode(500, $data);
  675. exit();
  676. }
  677. //}
  678. //get more infor by employee_id or contact_id
  679. $sql = '';
  680. $diffdate = $rs['last_pwd_change_date'];
  681. $user_type = $rs['user_type'];
  682. //if user is customer, check company
  683. if (strtolower($user_type) == 'customer') {
  684. $company = $rs['company_name'];
  685. } else {
  686. if (!empty($rs['station']))
  687. $company = $rs['station'];
  688. }
  689. if (strtolower($uname) == 'ra.admin') {
  690. $company = 'Admin';
  691. }
  692. // get system config
  693. $sql = "SELECT lower(ra_name) as ra_name, ra_value from ra_online_config where lower(ra_name) in ('employee_session_timeout', 'customer_session_timeout', 'password_change_alert', 'employee_password_change_cycle', 'customer_password_change_cycle')";
  694. $rs1s = common::excuteListSql($sql);
  695. foreach ($rs1s as $rs1) {
  696. if ($rs1['ra_name'] == 'employee_session_timeout')
  697. $EMPLOYEE_SESSION_TIMEOUT = $rs1['ra_value'];
  698. if ($rs1['ra_name'] == 'customer_session_timeout')
  699. $CUSTOMER_SESSION_TIMEOUT = $rs1['ra_value'];
  700. if ($rs1['ra_name'] == 'password_change_alert')
  701. $PASSWORD_CHANGE_ALERT = $rs1['ra_value'];
  702. if ($rs1['ra_name'] == 'employee_password_change_cycle')
  703. $EMPLOYEE_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  704. if ($rs1['ra_name'] == 'customer_password_change_cycle')
  705. $CUSTOMER_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  706. }
  707. $sql="select item_value from config where item='passwordChangePeriod'";
  708. $pcp = common::excuteObjectSql($sql);
  709. $passwordChangePeriod = json_decode($pcp["item_value"],true);
  710. if (strtolower($rs['user_type']) == 'employee') {
  711. $PASSWORD_CHANGE_CYCLE = $EMPLOYEE_PASSWORD_CHANGE_CYCLE;
  712. $SESSION_TIMEOUT = $EMPLOYEE_SESSION_TIMEOUT;
  713. //如果有新配置,则采用新配置
  714. if (!empty($pcp)) {
  715. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Employee"]["days"];
  716. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Employee"]["advanceDays"];
  717. }
  718. } else {
  719. $PASSWORD_CHANGE_CYCLE = $CUSTOMER_PASSWORD_CHANGE_CYCLE;
  720. $SESSION_TIMEOUT = $CUSTOMER_SESSION_TIMEOUT;
  721. //如果有新配置,则采用新配置
  722. if (!empty($pcp)) {
  723. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Customer"]["days"];
  724. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Customer"]["advanceDays"];
  725. }
  726. }
  727. /* if ($diffdate > $PASSWORD_CHANGE_CYCLE) {// Timeout
  728. echo json_encode(array(
  729. 'msg' => 'password_require_change',
  730. 'login_version' => $rs["login_version"],
  731. 'data' => ''
  732. ));
  733. $this->failedLogin($uname, 'Required password change');
  734. exit();
  735. }*/
  736. $loginName = $rs['user_login'];
  737. $email = $rs['email'];
  738. if ($diffdate > $PASSWORD_CHANGE_CYCLE) {// Timeout
  739. if(empty($email)){
  740. $data = array(
  741. 'status' => '0',
  742. 'msg' => 'login user email is empty',
  743. 'login_version' => $rs["login_version"],
  744. 'data' => ''
  745. );
  746. common::echo_json_encode(500, $data);
  747. exit();
  748. }else{
  749. //$this -> passwordExpires($loginName,$email);
  750. }
  751. }
  752. if ($diffdate == $PASSWORD_CHANGE_CYCLE) {// Due today
  753. $login_tmp = array(
  754. 'msg' => 'today',
  755. 'login_version' => $rs["login_version"],
  756. 'data' => ''
  757. );
  758. } elseif ($diffdate >= ($PASSWORD_CHANGE_CYCLE - $PASSWORD_CHANGE_ALERT)) {// Password expires soon, JS Tips
  759. $login_tmp = array(
  760. 'msg' => 'last',
  761. 'login_version' => $rs["login_version"],
  762. 'data' => $PASSWORD_CHANGE_CYCLE - $diffdate,
  763. 'is_only_vgm' => $rs["is_only_vgm"]
  764. );
  765. }
  766. //insert into log table
  767. $ip = common::ip();
  768. $sql = "insert into public.ra_online_user_login_log (user_name,manufacturer,from_app,ip,date_time, session_id) values ('" . common::check_input($uname) . "', '" . common::check_input($company) . "','Online','$ip',now(), '" . session_id() . "')";
  769. if (common::excuteUpdateSql($sql)) {
  770. common::excuteUpdateSql("update public.ra_online_user set Last_Login_Time = now(), error_login_count=0, error_login_time=null where lower(user_login) = '" . strtolower($uname) . "'");
  771. //自动登录。为了方便调用,先注销掉
  772. if (isset($login_tmp)) {
  773. //common::echo_json_encode(500, $login_tmp);
  774. } else {
  775. $data = array(
  776. 'msg' => 'success',
  777. 'login_version' => $rs["login_version"],
  778. 'data' => '',
  779. 'is_only_vgm' => $rs["is_only_vgm"]
  780. );
  781. //common::echo_json_encode("200", $data);
  782. }
  783. $online_user = $rs;
  784. $online_user['user_login'] = $uname;
  785. $online_user['company'] = $company;
  786. $online_user['password'] = "";
  787. if (!_isAdmin()) {
  788. if ($rs["is_only_vgm"] == "t") {//VGM用户写死
  789. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where url_action in ('ocean_order','password','vgm') and menu_id in ('ship','profile') order by order_by asc), ',')";
  790. $rrrs = common::excuteOneSql($sql);
  791. } else {
  792. $sql = "select array_to_string(ARRAY(select p.url_action from public.ra_online_user_permission up left join public.ra_online_user u on up.user_name = u.user_login left join public.ra_online_permission p on up.p_id = p.id where lower(u.user_login) = '" . common::check_input(strtolower($uname)) . "'), ',')";
  793. $rrrs = common::excuteOneSql($sql);
  794. if (strtolower($rs['user_type']) == "employee" && empty($rrrs)) {
  795. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where is_customer = true order by order_by asc), ',')";
  796. $rrrs = common::excuteOneSql($sql);
  797. }
  798. }
  799. $online_user['permission'] = $rrrs;
  800. }
  801. if (!empty($online_user['docdownload']))
  802. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where lower(serial_no) " . common::getInNotInSql($online_user['docdownload']) . " and active = true group by display_name order by min(id)";
  803. else {
  804. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where active = true";
  805. if (strtolower($online_user['user_type']) == "customer")
  806. $sql .= " and client_display = true";
  807. $sql .= " group by display_name order by min(id)";
  808. }
  809. $online_user['view_doc_type'] = common::excuteListSql($sql);
  810. if (!empty($online_user['view_air_file_format']))
  811. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where lower(serial_no) " . common::getInNotInSql($online_user['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  812. else {
  813. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where active = true";
  814. if (strtolower($online_user['user_type']) == "customer")
  815. $sql .= " and client_display = true";
  816. $sql .= " group by display_name order by min(id)";
  817. }
  818. $online_user['view_air_doc_type'] = common::excuteListSql($sql);
  819. //补充aci and ams CustomerLogin station - public
  820. $ocean_station_temp = $online_user['ocean_station'];
  821. $online_user['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  822. $ocean_agent_temp = $online_user['ocean_agent'];
  823. $online_user['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  824. $_SESSION['ONLINE_USER'] = $online_user;
  825. $_SESSION['LAST_OPERATE_TIME'] = time();
  826. $_SESSION['SESSION_TIMEOUT'] = $SESSION_TIMEOUT;
  827. //判断是否记录密码 add
  828. if ($_POST['rememberpwd'] === 'true') {
  829. if (!$noCheckPwd) {
  830. $user_info = $uname . "_" . md5($rs['password']);
  831. setcookie('userInfo', $user_info, time() + 30 * 24 * 3600, "/");
  832. }
  833. } else {
  834. setcookie('userInfo', '', time() - 1, "/");
  835. }
  836. if ($rs['is_super'] == "t") {
  837. $schemas_list = common::excuteListSql("select * from schemas_list");
  838. } else {
  839. $schemas_list = common::excuteListSql("select * from schemas_list where schemas_name=any(regexp_split_to_array('" . $rs['belong_schemas'] . "'::text, ';'::text))");
  840. }
  841. ///if (count($schemas_list) > 1) {
  842. foreach ($schemas_list as $sk => $sv) {
  843. if ($sv['schemas_name'] == "public") {
  844. continue;
  845. }
  846. $ttdd = common::excuteObjectSql("select contact_id_user, employee_id, contact_id, user_type, email, user_webtype_id, active, is_online, station, allow_login_remote, can_see_amslog,can_view_eccn, can_see_isflog, can_see_isflog_withaddress,
  847. customer_search_type, customer_destination, can_add_ams, can_add_isf, air_station, air_sales, ocean_station, ocean_sales,ocean_following_sales,ocean_following_sales_or,air_following_sales,air_following_sales_or, trucking_station, ocean_dest_op, can_see_password, can_add_opsales_code, ocean_station_or, ocean_agent_or, ocean_sales_or, ocean_dest_op_or, air_station_or, air_sales_or, trucking_station_or,
  848. can_add_user, can_add_employee, can_add_contact, company_name, ams_email, isf_email, customer_discharge, online_active, is_super, ocean_agent,active, can_send_email, view_file_format as docdownload, container_status, consolidated_cbsa_code, can_add_aci,
  849. air_customers, air_customer_search_type,trucking_customers,trucking_customer_search_type, upload_document, view_file_format, event_type, po_status, view_air_file_format, special_customer_event, can_edi_vgm, isf_aci_ams_station, is_kerry_shipment from " . $sv['schemas_name'] . ".ra_online_user where lower(user_login) = '" . strtolower($uname) . "'");
  850. if (empty($ttdd)) {
  851. unset($schemas_list[$sk]);
  852. continue;
  853. }
  854. if (!empty($ttdd['docdownload'])) {
  855. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['docdownload']) . " and active = true group by display_name order by min(id)";
  856. } else {
  857. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where active = true";
  858. if (strtolower($ttdd['user_type']) == "customer")
  859. $sql .= " and client_display = true";
  860. $sql .= " group by display_name order by min(id)";
  861. }
  862. $ttdd['view_doc_type'] = common::excuteListSql($sql);
  863. if (!empty($ttdd['view_air_file_format'])) {
  864. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  865. } else {
  866. $sql = "select string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where active = true";
  867. if (strtolower($ttdd['user_type']) == "customer")
  868. $sql .= " and client_display = true";
  869. $sql .= " group by display_name order by min(id)";
  870. }
  871. $ttdd['view_air_doc_type'] = common::excuteListSql($sql);
  872. //补充aci and ams CustomerLogin station - other like sfs
  873. $ocean_station_temp = $ttdd['ocean_station'];
  874. $ttdd['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  875. $ocean_agent_temp = $ttdd['ocean_agent'];
  876. $ttdd['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  877. $_SESSION[$sv['schemas_name'] . '_ONLINE_USER'] = $ttdd;
  878. }
  879. //}
  880. $_SESSION['schemas_list'] = $schemas_list;
  881. //不再返回登录页面,直接跳转
  882. if (isset($_GET['up'])) {
  883. if($_GET['v'] == 'new'){
  884. header("Location: main_new_version.php?action=main");
  885. }else{
  886. header("Location: main.php?action=main");
  887. }
  888. }
  889. //自动登录。为了方便调用,先注销掉
  890. //exit();
  891. } else {
  892. $data = array(
  893. 'msg' => 'database_error',
  894. 'login_version' => $rs["login_version"],
  895. 'data' => ''
  896. );
  897. common::echo_json_encode(500, $data);
  898. exit();
  899. }
  900. } else {
  901. $data = array(
  902. 'msg' => 'no_exist',
  903. 'login_version' => $rs["login_version"],
  904. 'data' => ''
  905. );
  906. common::echo_json_encode(500, $data);
  907. exit();
  908. }
  909. }
  910. }
  911. private function failedLogin($uname, $company){
  912. $ip = common::ip();
  913. common::excuteUpdateSql("insert into public.ra_online_user_login_log (user_name,manufacturer,from_app,ip,date_time, session_id) values ('" . common::check_input($uname) . "', '" . common::check_input($company) . "','Online','$ip',now(), '" . session_id() . "')");
  914. }
  915. //重置密码
  916. public function passwordExpires($loginName,$email,$uname){
  917. $result = array(
  918. 'msg' => "passwordExpires",
  919. 'uname' => $uname,
  920. );
  921. common::echo_json_encode(400, $result);
  922. exit();
  923. }
  924. //submit change form -- change expires password
  925. public function update_pwd_expires(){
  926. $loginName = common::check_input($_POST['uname']);
  927. $old_password = common::check_input($_POST['old_password']);
  928. $password = common::check_input($_POST['password']);
  929. //首先校验验证码 暂时注销掉
  930. // $verifcation_code = "";
  931. // $verifcation_code = common::check_input($_POST['verifcation_code']);
  932. // if (strtolower($_SESSION['captcha']) != strtolower($verifcation_code)) {
  933. // $data = array(
  934. // 'msg' => 'verifcation_error',
  935. // 'data' => ''
  936. // );
  937. // common::echo_json_encode(400, $data);
  938. // exit();
  939. // }
  940. $sql = "select ra_password as password from ra_online_user where lower(user_login) = '" . strtolower($loginName) . "'";
  941. $rs = common::excuteObjectSql($sql);
  942. $str = '';
  943. if (!empty($rs)) {
  944. if ($rs['password'] != $old_password) {
  945. $str = "Old password is incorrect!";
  946. }
  947. } else {
  948. $str = "Old password is incorrect!";
  949. }
  950. if(!empty($str)){
  951. $data = array(
  952. 'msg' => $str,
  953. 'data' => ''
  954. );
  955. common::echo_json_encode(500, $data);
  956. exit();
  957. }
  958. //验证通过,进行修改密码
  959. $msg = $this->updateExpirePassword($loginName, $password);
  960. if($msg == "success"){
  961. $data = array(
  962. 'msg' => "success",
  963. 'data' => ''
  964. );
  965. common::echo_json_encode(200, $data);
  966. exit();
  967. } else {
  968. $data = array(
  969. 'msg' => $msg,
  970. 'data' => ''
  971. );
  972. common::echo_json_encode(500, $data);
  973. exit();
  974. }
  975. }
  976. //更新密码
  977. public function updateExpirePassword($login,$new_password) {
  978. $str = common::checkPasswordRule($login, $new_password);
  979. //更新密码,擦除expire pwd痕迹
  980. if (empty($str)) {
  981. $sql = "UPDATE public.ra_online_user SET ra_password = '" . common::check_input($new_password) . "',password_new=redant_encode('".$new_password."'),
  982. last_pwd_change = now(),password_expires_keycode = null,password_expires_time = null
  983. WHERE lower(user_login) = '" . common::check_input(strtolower($login)) . "';";
  984. $rls = common::excuteUpdateSql($sql);
  985. if (!$rls) {
  986. $str = "Database Error, Try Later.";
  987. } else {
  988. $sql = "INSERT INTO public.ra_online_user_password_history (user_login, password, create_user, create_date) VALUES ('" . $login . "', " . common::check_input($new_password) . ", '" . $login . "', now());";
  989. common::excuteUpdateSql($sql);
  990. $str = "success";
  991. }
  992. }
  993. return $str;
  994. }
  995. public function getOriginOrAgent($ocean_station_temp){
  996. $session_ocean_station = "";
  997. if (strtolower($ocean_station_temp) == 'all'){
  998. $session_ocean_station = $ocean_station_temp;
  999. }
  1000. if (!(strtolower($ocean_station_temp) == 'all' || empty($ocean_station_temp))){
  1001. if (utils::checkExist($ocean_station_temp, ";")) {
  1002. $ost = str_replace(";","','",strtolower($ocean_station_temp));
  1003. $sql="select kerry_station_id,contact_id from ocean.contacts where coalesce(kerry_station_id,'') <>''and lower(contact_id) in ('".$ost."')";
  1004. $tar = common::excuteListSql($sql);
  1005. foreach ($tar as $tk => $tv) {
  1006. $tar[$tv['contact_id']] = $tv['kerry_station_id'];
  1007. }
  1008. $_tt = explode(";", $ocean_station_temp);
  1009. foreach ($_tt as $vv) {
  1010. if (!empty($vv)){
  1011. $session_ocean_station .= trim($vv).';';
  1012. if (!empty($tar[$vv])) {
  1013. $session_ocean_station .= $tar[trim($vv)].';';
  1014. }
  1015. }
  1016. }
  1017. } else {
  1018. $session_ocean_station .= trim($ocean_station_temp).';';
  1019. $temp_contacts = common::excuteObjectSql("select kerry_station_id from ocean.contacts where lower(contact_id)='".strtolower(common::check_input($ocean_station_temp))."'");
  1020. if (!empty($temp_contacts['kerry_station_id'])){
  1021. $session_ocean_station .= $temp_contacts['kerry_station_id'].';';
  1022. }
  1023. }
  1024. }
  1025. return $session_ocean_station;
  1026. }
  1027. public function logout() {
  1028. unset($_SESSION['ONLINE_USER']);
  1029. unset($_SESSION['LAST_OPERATE_TIME']);
  1030. unset($_SESSION['SESSION_TIMEOUT']);
  1031. common::sessionDestroy();
  1032. session_write_close();
  1033. $data = array("msg" =>"logout Successful");
  1034. common::echo_json_encode(200, $data);
  1035. exit();
  1036. }
  1037. public function tracking_checked(){
  1038. $reference_number = common::check_input($_POST['reference_number']);
  1039. $is_verify = common::check_input($_POST['verifcation_code']);
  1040. if($this->signUpAndTrackingChecked($is_verify)){
  1041. $data = array("msg" =>"visit limit");
  1042. common::echo_json_encode(400, $data);
  1043. exit();
  1044. }else{
  1045. $data = $this->getTrackingInfo($reference_number);
  1046. common::echo_json_encode(200, $data);
  1047. //记录查询log情况
  1048. $detail = "";
  1049. if($data['msg'] == "success"){
  1050. $detail = "Public tracking number:".$reference_number."; search successful";
  1051. } else {
  1052. $detail = "Public tracking number:".$reference_number."; search fail(".$data['msg'].")";
  1053. }
  1054. utils::single_operation_log_save("Tracking","Public tracking",$detail);
  1055. exit();
  1056. }
  1057. }
  1058. private function signUpAndTrackingChecked($is_verify){
  1059. $Tracking_Search_Count = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Tracking_Search_Count'");
  1060. $ip = common::ip();
  1061. global $db;
  1062. $db->StartTrans();
  1063. $db->Execute("update tracking_login_record set visit_count = 1, visit_time=now() "
  1064. . " where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' < NOW()::timestamp ") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1065. $ipInfo = $db->GetRow("select ip, visit_count from tracking_login_record where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' > NOW()::timestamp");
  1066. if(empty($ipInfo)){
  1067. $db->Execute("INSERT INTO public.tracking_login_record(ip, visit_count,visit_time,type)VALUES ('$ip', '1', now(),'".common::check_input($_POST['type'])."');") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1068. }else{
  1069. if ($ipInfo['visit_count'] > $Tracking_Search_Count){
  1070. $AES_encrypted = $this->AES_encrypted($is_verify);
  1071. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  1072. where secret_key = '$is_verify'
  1073. and create_time >= current_date - INTERVAL '3 months' limit 1");
  1074. //记录这次的密钥记录
  1075. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  1076. if(!empty($AES_encrypted) && empty($secret_key)){
  1077. //归零验证次数
  1078. $db->Execute("update tracking_login_record set visit_count = 1 "
  1079. . " where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' > NOW()::timestamp ") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1080. }else{
  1081. return TRUE;
  1082. }
  1083. }else{
  1084. $db->Execute("update tracking_login_record set visit_count = visit_count::integer + 1 "
  1085. . " where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' > NOW()::timestamp ") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1086. }
  1087. }
  1088. if ($db->CompleteTrans() === FALSE) {
  1089. //出错拦截
  1090. return TRUE;
  1091. } else {
  1092. return FALSE;
  1093. }
  1094. }
  1095. private function getTrackingInfo($reference_number){
  1096. $reference_number = strtolower($reference_number);
  1097. $sql = "with o as(
  1098. SELECT o.*
  1099. from public.ocean o
  1100. where o.status::text <> 'Cancelled'::text AND o.bol_type::text <> 'BOOKING'::text AND o.bol_type::text <> 'QUOTE'::text AND o.iscts = true
  1101. AND o.iscts IS NOT NULL and ARRAY['$reference_number'] && array_append(array[lower(tracking_no)::text,lower(booking_no)::text,lower(h_bol)::text,lower(m_bol)::text, lower(po_no),lower(quote_no)::text,lower(invoice_no)],'')
  1102. union
  1103. SELECT o.*
  1104. from public.ocean o
  1105. where o.status::text <> 'Cancelled'::text AND o.bol_type::text <> 'BOOKING'::text AND o.bol_type::text <> 'QUOTE'::text AND o.iscts = true
  1106. AND o.iscts IS NOT NULL and exists (select 1 from oc_container oc where o.serial_no = oc.serial_no and oc.ctnr = '$reference_number')
  1107. )
  1108. SELECT m_eta as _m_eta, h_bol as _h_bol, m_bol as _m_bol,job_no as _job_bol,
  1109. o.* ,sh.*, cn.* ,aa.*,dd.*,fd.*,oo.*,
  1110. (select uncode from ports where code = o.port_of_transshipment) as port_of_transshipment_un
  1111. from o
  1112. LEFT JOIN LATERAL ( SELECT tracking_no as _tracking_no,shippr_uncode,shipper_city,
  1113. consignee_uncode,consignee_city,incoterms,
  1114. fport_of_loading_un,
  1115. mport_of_discharge_un,
  1116. place_of_receipt_un,
  1117. place_of_delivery_un,
  1118. (select time_zone from public.city_timezone where uncode = oo.fport_of_loading_un limit 1) as pol_timezone,
  1119. (select uncity from public.ports where uncode = oo.fport_of_loading_un limit 1) as pol_uncity,
  1120. (select time_zone from public.city_timezone where uncode = oo.mport_of_discharge_un limit 1) as mpod_timezone,
  1121. (select uncity from public.ports where uncode = oo.mport_of_discharge_un limit 1) as mpod_uncity,
  1122. (select time_zone from public.city_timezone where uncode = oo.place_of_receipt_un limit 1) as por_timezone,
  1123. (select uncity from public.ports where uncode = oo.place_of_receipt_un limit 1) as por_uncity,
  1124. (select time_zone from public.city_timezone where uncode = oo.place_of_delivery_un limit 1) as pod_timezone,
  1125. (select uncity from public.ports where uncode = oo.place_of_delivery_un limit 1) as pod_uncity,
  1126. po_no as _po_no,
  1127. CASE
  1128. WHEN ((m_iffbcf is not null or m_iffbcf is null) and m_iffcpu is null and m_iffrec is null and m_iffdep is null and m_iffarr is null and m_iffdel is null) THEN 'Created'::text
  1129. WHEN ((m_iffcpu is not null or m_iffrec is not null) and m_iffdep is null and m_iffarr is null and m_iffdel is null) THEN 'Cargo Received'::text
  1130. WHEN (m_iffdep is not null and m_iffarr is null and m_iffdel is null) THEN 'Departure'::text
  1131. WHEN (m_iffarr is not null and m_iffdel is null) THEN 'Arrived'::text
  1132. WHEN (m_iffdel is not null) THEN 'Completed'::text
  1133. ELSE 'Created'::text
  1134. END AS new_status
  1135. FROM public.online_ocean oo WHERE oo.serial_no::text = o.serial_no::text) oo ON true
  1136. LEFT JOIN LATERAL ( SELECT company as cn_company,
  1137. address_1 as cn_address_1,
  1138. address_2 as cn_address_2,
  1139. address_3 as cn_address_3,
  1140. address_4 as cn_address_4,
  1141. city as cn_city, state as cn_state, zipcode as cn_zipcode, country as cn_country,
  1142. phone_1 as cn_phone
  1143. FROM ocean.contacts c WHERE o.consignee::text = c.contact_id::text) cn ON true
  1144. LEFT JOIN LATERAL ( SELECT company as sh_company,
  1145. address_1 as sh_address_1,
  1146. address_2 as sh_address_2,
  1147. address_3 as sh_address_3,
  1148. address_4 as sh_address_4,
  1149. city as sh_city, state as sh_state, zipcode as sh_zipcode, country as sh_country,
  1150. phone_1 as sh_phone
  1151. FROM ocean.contacts c WHERE o.shipper::text = c.contact_id::text) sh ON true
  1152. LEFT JOIN LATERAL ( SELECT company as aa_company,
  1153. address_1 as aa_address_1,
  1154. address_2 as aa_address_2,
  1155. address_3 as aa_address_3,
  1156. address_4 as aa_address_4,
  1157. city as aa_city, state as aa_state, zipcode as aa_zipcode, country as aa_country,
  1158. phone_1 as aa_phone,
  1159. (select time_zone from public.city_timezone where uncode = LEFT(country, 2) || COALESCE(city_code,'') limit 1) as aa_timezone
  1160. FROM ocean.contacts c WHERE o.origin_station::text = c.contact_id::text) aa ON true
  1161. LEFT JOIN LATERAL ( SELECT company as dd_company,
  1162. address_1 as dd_address_1,
  1163. address_2 as dd_address_2,
  1164. address_3 as dd_address_3,
  1165. address_4 as dd_address_4,
  1166. city as dd_city, state as dd_state, zipcode as dd_zipcode, country as dd_country,
  1167. phone_1 as dd_phone,
  1168. (select time_zone from public.city_timezone where uncode = LEFT(country, 2) || COALESCE(city_code,'') limit 1) as dd_timezone
  1169. FROM ocean.contacts c WHERE o.destination_station::text = c.contact_id::text) dd ON true
  1170. LEFT JOIN LATERAL ( SELECT
  1171. city as fd_city,
  1172. (select time_zone from public.city_timezone where uncode = LEFT(country, 2) || COALESCE(city_code,'') limit 1) as fd_timezone
  1173. FROM ocean.contacts c WHERE o.final_desination::text = c.contact_id::text) fd ON true";
  1174. $ocean_arr = common::excuteListSql($sql);
  1175. if(empty($ocean_arr)){
  1176. $sql = $this->trackingSfsSql($reference_number);
  1177. $ocean_arr = common::excuteListSql($sql);
  1178. if(empty($ocean_arr)){
  1179. $data = array("msg" =>"No matches");
  1180. return $data;
  1181. }
  1182. }
  1183. if(!empty($ocean_arr) && count($ocean_arr) > 1){
  1184. $data = array("msg" =>"Multiple results");
  1185. return $data;
  1186. }
  1187. $ocean = $ocean_arr[0];
  1188. //获取对应uncode 对应的时间
  1189. $uncodes = $ocean['fport_of_loading_un'].";".$ocean['mport_of_discharge_un'];
  1190. $codeinfo = common::getCityPortsInfo($uncodes);
  1191. //处理transportInfo信息数据
  1192. $transportInfo = array("Tracking No." =>$ocean['_tracking_no'],"status"=>$ocean['new_status'],"mode" => "Ocean Freight",
  1193. "origin" =>$ocean['shippr_uncode'],"destination" =>$ocean['consignee_uncode'],
  1194. "etd" =>$ocean['f_etd'],"atd" =>$ocean['atd'],
  1195. "etd_timezone" =>$codeinfo[$ocean['fport_of_loading_un']],
  1196. "atd_timezone" =>$codeinfo[$ocean['fport_of_loading_un']],
  1197. "eta" =>$ocean['m_eta'],"ata" =>$ocean['ata'],
  1198. "eta_timezone" =>$codeinfo[$ocean['mport_of_discharge_un']],
  1199. "ata_timezone" =>$codeinfo[$ocean['mport_of_discharge_un']]);
  1200. $data['transportInfo'] = $transportInfo;
  1201. //处理basicInfo信息数据
  1202. $vessel = utils::outDisplayForMerge($ocean['f_vessel'],$ocean['m_vessel']);
  1203. $voyage = utils::outDisplayForMerge($ocean['f_voyage'],$ocean['m_voyage']);
  1204. $basicInfo = array("MAWB/MBL No." =>$ocean['m_bol'],"HAWB/HBOL" => $ocean['h_bol'],"Carrier_Booking_No" =>$ocean['booking_no'],
  1205. "PO_NO" =>$ocean['po_no'],"Vessel/Airline" =>$vessel,"Voyage/Filght" =>$voyage,
  1206. "Incoterm" =>$ocean['incoterms'],"Service_Type" =>$ocean['service']);
  1207. //处理 拼接地址 ocean表单exp 字段无法精准分割电话和地址信息,只能从contacts表里查询
  1208. $shipper_address = common::retStationInfo($ocean['sh_address_1'], $ocean['sh_address_2'], $ocean['sh_address_3'], $ocean['sh_address_4'],
  1209. $ocean['sh_city'], $ocean['sh_state'], $ocean['sh_zipcode'], $ocean['sh_country']);
  1210. $consignee_address = common::retStationInfo($ocean['cn_address_1'], $ocean['cn_address_2'], $ocean['cn_address_3'], $ocean['cn_address_4'],
  1211. $ocean['cn_city'], $ocean['cn_state'], $ocean['cn_zipcode'], $ocean['cn_country']);
  1212. $origin_address = common::retStationInfo($ocean['aa_address_1'], $ocean['aa_address_2'], $ocean['aa_address_3'], $ocean['aa_address_4'],
  1213. $ocean['aa_city'], $ocean['aa_state'], $ocean['aa_zipcode'], $ocean['aa_country']);
  1214. $destination_address = common::retStationInfo($ocean['dd_address_1'], $ocean['dd_address_2'], $ocean['dd_address_3'], $ocean['dd_address_4'],
  1215. $ocean['dd_city'], $ocean['dd_state'], $ocean['dd_zipcode'], $ocean['dd_country']);
  1216. $shipperPartners = array("company" =>$ocean['sh_company'],"address"=>$shipper_address,"phone"=>$ocean['sh_phone']);
  1217. $consigneePartners = array("company" =>$ocean['cn_company'],"address"=>$consignee_address,"phone"=>$ocean['cn_phone']);
  1218. $originPartners = array("company" =>$ocean['aa_company'],"address"=>$origin_address,"phone"=>$ocean['aa_phone']);
  1219. $destinationPartners = array("company" =>$ocean['dd_company'],"address"=>$destination_address,"phone"=>$ocean['dd_phone']);
  1220. $businessPartners = array("shipper"=>$shipperPartners,"consignee" => $consigneePartners,"origin" => $originPartners,"destination" => $destinationPartners);
  1221. //处理marksAndDescription
  1222. $marksAndDescription = array("marks"=>$ocean['marks'],"description"=>$ocean['description']);
  1223. $sql = "SELECT " . column::getInstance()->getSearchSql('Ocean_Container') . " ,net_lbs from oc_container where lower(serial_no) = '" . strtolower($ocean['serial_no']) . "'";
  1224. $rss = common::excuteListSql($sql);
  1225. $quantity_unit = array();
  1226. $g_weight_tolal = 0;
  1227. $ch_weight_tolal = 0;
  1228. $ch_weight_tolal_grs_lbs = 0;
  1229. $cbm_tolal = 0;
  1230. foreach ($rss as $key => $rs) {
  1231. $unit = $rs['unit'];
  1232. if (array_key_exists($unit, $quantity_unit)) {
  1233. $quantity_unit[$unit] = $quantity_unit[$unit] + $rs['qty'];
  1234. } else {
  1235. $quantity_unit[$unit] = $rs['qty'];
  1236. }
  1237. $g_weight_tolal += $rs['grs_kgs'];
  1238. $ch_weight_tolal += $rs['net_lbs'];
  1239. $ch_weight_tolal_grs_lbs += $rs['grs_lbs'];
  1240. $cbm_tolal += $rs['cbm'];
  1241. }
  1242. $quantity_tolal = "";
  1243. foreach($quantity_unit as $uk => $uv){
  1244. $quantity_tolal.=$uv." ".$uk." ";
  1245. }
  1246. $ch_weight_tolal = empty($ch_weight_tolal) ? $ch_weight_tolal_grs_lbs : $ch_weight_tolal;
  1247. //Packing 不确定信息
  1248. $packing = array("Quantity/Unit"=>$quantity_tolal,"G. Weight" => $g_weight_tolal." KGS","Ch. Weight" => $ch_weight_tolal." LBS","Volume" => $cbm_tolal." CBM");
  1249. /* Container Status */
  1250. //数据库里配置好
  1251. //$sql = "SELECT " . column::getInstance()->getSearchSql('Ocean_Container_Status') . " from oc_container_v where lower(serial_no) = '" . strtolower($serial_no) . "'";
  1252. $serial_no = $ocean["serial_no"];
  1253. $ctnr_sql = "SELECT oc.ctnr, oc.serial_no,oc.size FROM oc_container oc LEFT JOIN ocean o ON oc.serial_no = o.serial_no
  1254. WHERE o.serial_no='$serial_no'";
  1255. $ctnr_data = common::excuteListSql($ctnr_sql);
  1256. foreach ($ctnr_data as $cd){
  1257. //存在柜号为空的数据情况
  1258. if(empty($cd['ctnr'])){
  1259. continue;
  1260. }
  1261. $ctnr_status_sql = "select s.source_id, s.event_base as event,
  1262. to_char(to_timestamp(s.event_date, 'YYYYMMDD'), 'YYYY-MM-DD') as eventdate,
  1263. to_char(to_timestamp(s.event_time, 'HH24MI'), 'HH24:MI') as eventtime,
  1264. e.description,s.event_type as eventtype,
  1265. s.event_code as eventcode, s.event_city as eventcity,
  1266. (select time_zone from public.city_timezone where uncode = s.event_code) as timezone,
  1267. (select uncity from public.ports where uncode = s.event_code) as uncity,
  1268. case when event ='I' then 'IFFREC'::text
  1269. when event ='AE' then 'IFFONB'::text
  1270. when event ='VD' then 'IFFDEP'::text
  1271. when event ='EB' or event ='VA' then 'IFFARR'::text
  1272. when event ='UV' then 'IFFUND'::text
  1273. when event ='VA' then 'IFFAFD'::text
  1274. when event ='AV' then 'IFFCTA'::text
  1275. when event ='CT' then 'IFFICC'::text
  1276. when event ='OA' or event ='D' then 'IFFPPD'::text
  1277. when event ='EE' then 'IFFECP'::text
  1278. else '' ::text
  1279. end as milestone_code
  1280. from public.ra_online_container_status_v s
  1281. left join ra_online_edi_event e on s.event_base = e.ra_name
  1282. where s.serial_no = '" . pg_escape_string($cd['serial_no']) . "'
  1283. and s.container_no = '" . pg_escape_string($cd['ctnr']) . "' and is_display = true
  1284. order by to_timestamp(s.event_date, 'YYYYMMDD') asc,
  1285. to_timestamp(s.event_time, 'HH24MI') asc,e.ra_order asc";
  1286. $ctnr_status = common::excuteListSql($ctnr_status_sql);
  1287. //记录所有的信息
  1288. $EDI315TimeAndLocation = array();
  1289. foreach($ctnr_status as $event){
  1290. if(!empty($EDI315TimeAndLocation['IFFARR']) && $EDI315TimeAndLocation['IFFARR']['code'] == "EB"){
  1291. //如果存在EB 的EB 的优先级最高
  1292. continue;
  1293. }
  1294. if(!empty($EDI315TimeAndLocation['IFFPPD']) && $EDI315TimeAndLocation['IFFARR']['code'] == "OA"){
  1295. //如果存在OA 的OA 的优先级最高
  1296. continue;
  1297. }
  1298. $EDI315TimeAndLocation[$event['milestone_code']] = array("code"=>$event['event'],"timezone"=>$event['timezone'],"location"=>$event['uncity']);
  1299. }
  1300. }
  1301. //Milestones 数据信息待定
  1302. $Milestones = common::getMilestonesInfo($ocean,$EDI315TimeAndLocation);
  1303. global $_COPYRIGHT;
  1304. $data = array('transportInfo' => $transportInfo,
  1305. 'basicInfo' => $basicInfo,
  1306. 'businessPartners' => $businessPartners,
  1307. 'packing' => $packing,
  1308. 'marksAndDescription' => $marksAndDescription,
  1309. 'Milestones' => $Milestones,
  1310. 'copyright' =>$_COPYRIGHT);
  1311. return array("msg" =>"success","data" =>$data);
  1312. }
  1313. private function trackingSfsSql($reference_number){
  1314. $sql = "with o as(
  1315. SELECT o.*
  1316. from sfs.ocean o
  1317. where o.status::text <> 'Cancelled'::text AND o.bol_type::text <> 'BOOKING'::text AND o.bol_type::text <> 'QUOTE'::text AND o.iscts = true
  1318. AND o.iscts IS NOT NULL and ARRAY['$reference_number'] && array_append(array[lower(tracking_no)::text,lower(booking_no)::text,lower(h_bol)::text,lower(m_bol)::text, lower(po_no),lower(quote_no)::text,lower(invoice_no)],'')
  1319. union
  1320. SELECT o.*
  1321. from sfs.ocean o
  1322. where o.status::text <> 'Cancelled'::text AND o.bol_type::text <> 'BOOKING'::text AND o.bol_type::text <> 'QUOTE'::text AND o.iscts = true
  1323. AND o.iscts IS NOT NULL and exists (select 1 from oc_container oc where o.serial_no = oc.serial_no and oc.ctnr = '$reference_number')
  1324. )
  1325. SELECT m_eta as _m_eta, h_bol as _h_bol, m_bol as _m_bol,job_no as _job_bol,
  1326. o.* ,sh.*, cn.* ,aa.*,dd.*,fd.*,oo.*,
  1327. (select uncode from ports where code = o.port_of_transshipment) as port_of_transshipment_un
  1328. from sfs.ocean o
  1329. LEFT JOIN LATERAL ( SELECT tracking_no as _tracking_no,shippr_uncode,shipper_city,
  1330. consignee_uncode,consignee_city,incoterms,
  1331. fport_of_loading_un,
  1332. mport_of_discharge_un,
  1333. place_of_receipt_un,
  1334. place_of_delivery_un,
  1335. (select time_zone from public.city_timezone where uncode = oo.fport_of_loading_un limit 1) as pol_timezone,
  1336. (select uncity from public.ports where uncode = oo.fport_of_loading_un limit 1) as pol_uncity,
  1337. (select time_zone from public.city_timezone where uncode = oo.mport_of_discharge_un limit 1) as mpod_timezone,
  1338. (select uncity from public.ports where uncode = oo.mport_of_discharge_un limit 1) as mpod_uncity,
  1339. (select time_zone from public.city_timezone where uncode = oo.place_of_receipt_un limit 1) as por_timezone,
  1340. (select uncity from public.ports where uncode = oo.place_of_receipt_un limit 1) as por_uncity,
  1341. (select time_zone from public.city_timezone where uncode = oo.place_of_delivery_un limit 1) as pod_timezone,
  1342. (select uncity from public.ports where uncode = oo.place_of_delivery_un limit 1) as pod_uncity,
  1343. po_no as _po_no,
  1344. CASE
  1345. WHEN ((m_iffbcf is not null or m_iffbcf is null) and m_iffcpu is null and m_iffrec is null and m_iffdep is null and m_iffarr is null and m_iffdel is null) THEN 'Created'::text
  1346. WHEN ((m_iffcpu is not null or m_iffrec is not null) and m_iffdep is null and m_iffarr is null and m_iffdel is null) THEN 'Cargo Received'::text
  1347. WHEN (m_iffdep is not null and m_iffarr is null and m_iffdel is null) THEN 'Departure'::text
  1348. WHEN (m_iffarr is not null and m_iffdel is null) THEN 'Arrived'::text
  1349. WHEN (m_iffdel is not null) THEN 'Completed'::text
  1350. ELSE 'Created'::text
  1351. END AS new_status
  1352. FROM public.online_ocean oo WHERE oo.serial_no::text = o.serial_no::text) oo ON true
  1353. LEFT JOIN LATERAL ( SELECT company as cn_company,
  1354. address_1 as cn_address_1,
  1355. address_2 as cn_address_2,
  1356. address_3 as cn_address_3,
  1357. address_4 as cn_address_4,
  1358. city as cn_city, state as cn_state, zipcode as cn_zipcode, country as cn_country,
  1359. phone_1 as cn_phone
  1360. FROM sfs.contacts c WHERE o.consignee::text = c.contact_id::text) cn ON true
  1361. LEFT JOIN LATERAL ( SELECT company as sh_company,
  1362. address_1 as sh_address_1,
  1363. address_2 as sh_address_2,
  1364. address_3 as sh_address_3,
  1365. address_4 as sh_address_4,
  1366. city as sh_city, state as sh_state, zipcode as sh_zipcode, country as sh_country,
  1367. phone_1 as sh_phone
  1368. FROM sfs.contacts c WHERE o.shipper::text = c.contact_id::text) sh ON true
  1369. LEFT JOIN LATERAL ( SELECT company as aa_company,
  1370. address_1 as aa_address_1,
  1371. address_2 as aa_address_2,
  1372. address_3 as aa_address_3,
  1373. address_4 as aa_address_4,
  1374. city as aa_city, state as aa_state, zipcode as aa_zipcode, country as aa_country,
  1375. phone_1 as aa_phone,
  1376. (select time_zone from public.city_timezone where uncode = LEFT(country, 2) || COALESCE(city_code,'') limit 1) as aa_timezone
  1377. FROM sfs.contacts c WHERE o.origin_station::text = c.contact_id::text) aa ON true
  1378. LEFT JOIN LATERAL ( SELECT company as dd_company,
  1379. address_1 as dd_address_1,
  1380. address_2 as dd_address_2,
  1381. address_3 as dd_address_3,
  1382. address_4 as dd_address_4,
  1383. city as dd_city, state as dd_state, zipcode as dd_zipcode, country as dd_country,
  1384. phone_1 as dd_phone,
  1385. (select time_zone from public.city_timezone where uncode = LEFT(country, 2) || COALESCE(city_code,'') limit 1) as dd_timezone
  1386. FROM sfs.contacts c WHERE o.destination_station::text = c.contact_id::text) dd ON true
  1387. LEFT JOIN LATERAL ( SELECT
  1388. city as fd_city,
  1389. (select time_zone from public.city_timezone where uncode = LEFT(country, 2) || COALESCE(city_code,'') limit 1) as fd_timezone
  1390. FROM sfs.contacts c WHERE o.final_desination::text = c.contact_id::text) fd ON true";
  1391. return $sql;
  1392. }
  1393. private function AES_encrypted($encrypted_string,$isbase64_encode = true){
  1394. $key = 'fT5!R1k$7Mv@4Q9X'; // 16 bytes key
  1395. $iv = '1234567890123456'; // 16 bytes IV
  1396. if($isbase64_encode){
  1397. $decrypted = openssl_decrypt(base64_decode($encrypted_string), 'AES-128-CBC', $key, OPENSSL_RAW_DATA, $iv);
  1398. }else{
  1399. $decrypted = openssl_decrypt($encrypted_string, 'AES-128-CBC', $key, OPENSSL_RAW_DATA, $iv);
  1400. }
  1401. return $decrypted;
  1402. }
  1403. }
  1404. ?>