login.class.php 96 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707
  1. <?php
  2. if (!defined('IN_ONLINE')) {
  3. exit('Access Denied');
  4. }
  5. /**
  6. * Description of login
  7. *
  8. * @author Administrator
  9. */
  10. class login {
  11. private static $_login;
  12. public static function getInstance() {
  13. if (!self::$_login) {
  14. $c = __CLASS__;
  15. self::$_login = new $c;
  16. }
  17. return self::$_login;
  18. }
  19. private function getLoginSql() {
  20. return "select first_name,last_name,user_login,user_id,
  21. redant_decode(temp_password) as temp_password,(temp_password_expires > LOCALTIMESTAMP) as is_temp_password_expires,
  22. employee_company_name,employee_contact_id_user,employee_search_type,employee_air_company_name,employee_air_contact_id_user,employee_air_search_type,
  23. (select active from public.employee ee where ee.employee_id=u.employee_id) as employee_id_active,
  24. (select email from public.employee ee where ee.employee_id=u.employee_id) as employee_email,
  25. can_visit_vgm,can_add_booking, can_add_tk_status,truck_driver,po_booking,o_final_delivery_u,ipad_view_po,can_view_doc,can_upload_doc,can_add_catalog,can_add_po,packing_list_company,is_only_vgm,contact_id_user,is_demo, ra_password as password,employee_id, contact_id, user_type, last_pwd_change, EXTRACT(DAY from (now() - last_pwd_change)) as last_pwd_change_date, email, user_webtype_id, active, is_online, station, allow_login_remote, can_see_amslog,can_view_eccn, can_see_isflog, can_see_isflog_withaddress,
  26. customer_search_type, customer_destination, can_add_ams, can_add_isf, air_station, air_sales, ocean_station, ocean_sales,ocean_following_sales,ocean_following_sales_or,air_following_sales,air_following_sales_or, trucking_station, ocean_dest_op, can_see_password, can_add_opsales_code, ocean_station_or, ocean_agent_or, ocean_sales_or, ocean_dest_op_or, air_station_or, air_sales_or, trucking_station_or,
  27. can_add_user, can_add_employee, can_add_contact, company_name, ams_email, isf_email, customer_discharge, online_active, is_super, ocean_agent,active, can_send_email, view_file_format as docdownload, container_status, consolidated_cbsa_code, can_add_aci,
  28. air_customers, air_customer_search_type,trucking_customers,trucking_customer_search_type, upload_document, view_file_format, event_type, belong_schemas, main_schemas, error_login_count, EXTRACT(EPOCH FROM (now()-COALESCE(error_login_time, now()))) as second, po_status, view_air_file_format,
  29. special_customer_event, can_edi_vgm, isf_aci_ams_station,login_version,is_kerry_shipment,can_visit_delivery,currency_group,revenue_active,is_desensitization_kln from public.ra_online_user u where md5(lower(user_login)) = ?";
  30. }
  31. public function do_login() {
  32. $login_error_times = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Login_Error_Times'");
  33. $lock_user_seconds = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Lock_User_Seconds'");
  34. if (!empty($uname) || !empty($password)) {
  35. } else {
  36. $uname = common::check_input($_POST['uname']);
  37. //如是是token登录,则不用验证密码和verifcation_code
  38. if(!(isset($_POST['token']))){
  39. $is_verify = common::check_input($_POST['verifcation_code']);
  40. //首先校用户登录
  41. $AES_encrypted = utils::AES_encrypted($is_verify);
  42. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  43. where secret_key = '$is_verify'
  44. and create_time >= current_date - INTERVAL '3 months' limit 1");
  45. //记录这次的密钥记录
  46. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  47. if(!empty($AES_encrypted) && empty($secret_key)){
  48. }else{
  49. $data = array(
  50. 'msg' => 'verifcation_error',
  51. 'data' => ''
  52. );
  53. common::echo_json_encode(400, $data);
  54. exit();
  55. }
  56. }
  57. //检查长度,大于50,返回 no_exist
  58. common::checkUserNameLength($uname);
  59. $sql = $this->getLoginSql();
  60. $rs = common::excuteObjectPrepareSql($sql,[md5(strtolower($uname))]);
  61. if (!empty($rs)) {
  62. if (empty($rs['belong_schemas'])) {
  63. $rs['belong_schemas'] = "public";
  64. }
  65. if (empty($rs['main_schemas'])) {
  66. $rs['main_schemas'] = "public";
  67. }
  68. //验证employee是否active
  69. if (!empty($rs["employee_id"]) && $rs["employee_id_active"] != "t") {
  70. if (strtolower(Soure) =='topocean'){
  71. if (strtolower($rs['user_type']) == "employee" && utils::endWith($rs['email'], "cn")) {
  72. $data = "<a href='mailto:lilyyang@topocean.com.cn'>lilyyang@topocean.com.cn</a>";
  73. }else{
  74. $data = "<a href='mailto:winnie@topocean.com'>winnie@topocean.com</a>";
  75. }
  76. }
  77. if (strtolower(Soure) =='apex'){
  78. $data = "<a href='mailto:maria.wang@apexshipping.com.cn'>maria.wang@apexshipping.com.cn</a>";
  79. }
  80. $data = array(
  81. 'code' => 'no_active',
  82. 'login_version' => $rs["login_version"],
  83. 'data' => $data,
  84. 'msg' => "Please check with Doc Center $data for searching function"
  85. );
  86. common::echo_json_encode(500, $data);
  87. $this->failedLogin($uname, 'Employee not active');
  88. exit();
  89. }
  90. //处理登录状态
  91. $userInfo = common::check_input($_COOKIE['userInfo']);
  92. $noCheckPwd = false;
  93. if (!empty($userInfo)) {
  94. $userInfoSplit = explode("_", $userInfo);
  95. if ($uname == $userInfoSplit[0]) {
  96. if ($userInfoSplit[1] == md5($rs['password'])) {
  97. $noCheckPwd = true;
  98. }
  99. }
  100. }
  101. if ($rs['error_login_count'] > $login_error_times && $rs['second'] < $lock_user_seconds) {
  102. $data = array(
  103. 'msg' => 'error_times',
  104. 'login_version' => $rs["login_version"],
  105. 'data' => ceil(($lock_user_seconds - $rs['second']) / 60)
  106. );
  107. common::echo_json_encode(400, $data);
  108. $this->failedLogin($uname, 'Failed login too times');
  109. exit();
  110. }
  111. if ($rs['is_online'] != 't') {
  112. if (strtolower($rs['user_type']) != "employee") {
  113. $data =array(
  114. 'code' => 'no_online',
  115. 'login_version' => $rs["login_version"],
  116. 'data' => '',
  117. 'msg' => 'No activation or insufficient permissions'
  118. );
  119. common::echo_json_encode(500, $data);
  120. $this->failedLogin($uname, 'Online is not active');
  121. exit();
  122. }
  123. }
  124. //if ($rs['decrypt_password'] != $_POST['psw']) {
  125. if ($noCheckPwd) {
  126. }else{
  127. //如是是token登录,则不用验证密码
  128. if(isset($_POST['token']) && !empty($_POST['token'])){
  129. $is_verify = $_POST['token'];
  130. //$AES_encrypted = utils::AES_encrypted($is_verify,true,"fT5!R1k$7Mv@4Q9X","1234567890123456");
  131. $AES_encrypted = utils::AES_encrypted($is_verify,true,"USAIandy20244Q9X","1234567890123456");
  132. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  133. where secret_key = '$is_verify'
  134. and create_time >= current_date - INTERVAL '3 months' limit 1");
  135. //记录这次的密钥记录
  136. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  137. //密钥解析失败或者有重复的记录这提示登录失败
  138. if(!(!empty($AES_encrypted) && empty($secret_key))){
  139. $data = array(
  140. 'msg' => 'Invalid token',
  141. 'login_version' => $rs["login_version"],
  142. 'data' => ''
  143. );
  144. common::echo_json_encode(400, $data);
  145. exit();
  146. }
  147. }else{
  148. if ($rs['password'] != $_POST['psw'] && ($rs['temp_password'] != $_POST['psw'] || $rs['is_temp_password_expires'] == 'f')) {
  149. common::excuteUpdateSql("update public.ra_online_user set error_login_count=error_login_count+1, error_login_time=now() where lower(user_login) = '" . strtolower($uname) . "'");
  150. $data = array(
  151. 'msg' => 'password_error',
  152. 'login_version' => $rs["login_version"],
  153. 'data' => ''
  154. );
  155. common::echo_json_encode(400, $data);
  156. $this->failedLogin($uname, 'Password is wrong');
  157. exit();
  158. }
  159. }
  160. }
  161. if ($rs['online_active'] != 't') {
  162. $data = array(
  163. 'code' => 'no_active',
  164. 'login_version' => $rs["login_version"],
  165. 'data' => '',
  166. 'msg' => 'Please check with Doc Center for searching function'
  167. );
  168. common::echo_json_encode(500, $data);
  169. $this->failedLogin($uname, 'Online is not active');
  170. exit();
  171. }
  172. //check password length
  173. $tar = utils::checkPassword($rs['password']);
  174. if (!empty($tar)) {
  175. $data = array(
  176. 'code' => $tar,
  177. 'login_version' => $rs["login_version"],
  178. 'data' => '',
  179. 'msg' => $tar
  180. );
  181. common::echo_json_encode(500, $data);
  182. exit();
  183. }
  184. //第一次登录,改密码
  185. if (empty($rs['last_pwd_change'])) {
  186. $data = array(
  187. 'login_version' => $rs["login_version"],
  188. 'data' => '',
  189. 'uname' =>$uname,
  190. 'user_info' => array("uname"=>$uname),
  191. 'msg' => 'First login, please change your password'
  192. );
  193. common::echo_json_encode(400, $data);
  194. exit();
  195. }
  196. //get more infor by employee_id or contact_id
  197. $sql = '';
  198. $diffdate = $rs['last_pwd_change_date'];
  199. $user_type = $rs['user_type'];
  200. //if user is customer, check company
  201. if (strtolower($user_type) == 'customer') {
  202. $company = $rs['company_name'];
  203. } else {
  204. if (!empty($rs['station']))
  205. $company = $rs['station'];
  206. }
  207. if (strtolower($uname) == 'ra.admin') {
  208. $company = 'Admin';
  209. }
  210. // get system config
  211. $sql = "SELECT lower(ra_name) as ra_name, ra_value from ra_online_config where lower(ra_name) in ('employee_session_timeout', 'customer_session_timeout', 'password_change_alert', 'employee_password_change_cycle', 'customer_password_change_cycle')";
  212. $rs1s = common::excuteListSql($sql);
  213. foreach ($rs1s as $rs1) {
  214. if ($rs1['ra_name'] == 'employee_session_timeout')
  215. $EMPLOYEE_SESSION_TIMEOUT = $rs1['ra_value'];
  216. if ($rs1['ra_name'] == 'customer_session_timeout')
  217. $CUSTOMER_SESSION_TIMEOUT = $rs1['ra_value'];
  218. if ($rs1['ra_name'] == 'password_change_alert')
  219. $PASSWORD_CHANGE_ALERT = $rs1['ra_value'];
  220. if ($rs1['ra_name'] == 'employee_password_change_cycle')
  221. $EMPLOYEE_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  222. if ($rs1['ra_name'] == 'customer_password_change_cycle')
  223. $CUSTOMER_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  224. }
  225. $sql="select item_value from config where item='passwordChangePeriod'";
  226. $pcp = common::excuteObjectSql($sql);
  227. $passwordChangePeriod = json_decode($pcp["item_value"],true);
  228. if (strtolower($rs['user_type']) == 'employee') {
  229. $PASSWORD_CHANGE_CYCLE = $EMPLOYEE_PASSWORD_CHANGE_CYCLE;
  230. $SESSION_TIMEOUT = $EMPLOYEE_SESSION_TIMEOUT;
  231. //如果有新配置,则采用新配置
  232. if (!empty($pcp)) {
  233. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Employee"]["days"];
  234. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Employee"]["advanceDays"];
  235. }
  236. } else {
  237. $PASSWORD_CHANGE_CYCLE = $CUSTOMER_PASSWORD_CHANGE_CYCLE;
  238. $SESSION_TIMEOUT = $CUSTOMER_SESSION_TIMEOUT;
  239. //如果有新配置,则采用新配置
  240. if (!empty($pcp)) {
  241. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Customer"]["days"];
  242. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Customer"]["advanceDays"];
  243. }
  244. }
  245. $loginName = $rs['user_login'];
  246. $email = $rs['email'];
  247. //Timeout
  248. if ($diffdate > $PASSWORD_CHANGE_CYCLE) {
  249. if(empty($email)){
  250. $data = array(
  251. 'status' => '0',
  252. 'code' => 'login user email is empty',
  253. 'login_version' => $rs["login_version"],
  254. 'msg' => 'login user email is empty'
  255. );
  256. common::echo_json_encode(500, $data);
  257. exit();
  258. }else{
  259. $this -> passwordExpires($loginName,$email,$uname);
  260. }
  261. }
  262. //kln新版查询 date_format,numbers_format
  263. $kln_user = common::excuteObjectSql("select * from public.kln_user_extend where lower(user_login) = '".strtolower($uname)."'");
  264. //检查用户是否是设置过subscribe_notification,加在这里,少一次请求
  265. $count = common::excuteOneSql("select count(*) from public.notifications_rules where
  266. notifications_type = 'Subscribe'
  267. and lower(user_login) = '".strtolower($uname)."'");
  268. $subscribe_notification_default_init = $count > 0 ? false:true;
  269. //添加FAQ客户的访问类型
  270. $loginCount = common::excuteOneSql("select count(*) from public.ra_online_user_login_log where lower(user_name) = '".strtolower(common::check_input($uname))."' and date_time >= CURRENT_DATE - INTERVAL '30 day' AND date_time <= CURRENT_DATE");
  271. //查询该用户下的mapping
  272. $kam_customers_name = common::excuteListSql("select
  273. (select user_login from public.ra_online_user u where u.user_id = m.responsible_customers_id) as kam_customers_name
  274. from public.ra_online_user_kam_mapping m where m.kam_account_id = '".$rs['user_id']."'");
  275. $kln_user_info = array("uname"=>$rs['user_login'],
  276. "employee_email"=>$rs['employee_email'],
  277. //"employee_email"=>"andy.wu@united-cn.net",
  278. "user_type"=>strtolower($rs['user_type']),
  279. //"user_type"=>strtolower('customer'),
  280. "first_name"=>$rs['first_name'],
  281. "last_name"=>$rs['last_name'],
  282. "is_desensitization_kln"=>$rs['is_desensitization_kln'],
  283. "email"=>$rs['email'],
  284. "kam_customers_name"=>$kam_customers_name,
  285. "expire_day"=>$PASSWORD_CHANGE_CYCLE - $rs['last_pwd_change_date'],
  286. "PASSWORD_CHANGE_CYCLE"=>intval($PASSWORD_CHANGE_CYCLE),
  287. "subscribe_notification_default_init"=>$subscribe_notification_default_init,
  288. "last_pwd_change"=>$rs['last_pwd_change'],
  289. "date_format"=>$kln_user['date_format'],
  290. "numbers_format"=>$kln_user['numbers_format'],
  291. "loginCount"=>intval($loginCount));
  292. //添加密码是否快过期的消息通知 7 天内,3天内的通知
  293. $expire_day = ($PASSWORD_CHANGE_CYCLE - $rs['last_pwd_change_date']);
  294. if($expire_day <= 7){
  295. $exist = common::excuteListSql("select notifiation_type from public.kln_notifiation_info where notifiation_type = 'Passwond_Notifcations'
  296. and lower(user_login) = '".strtolower($uname)."' and other_pnum = '".$expire_day."'");
  297. if (empty($exist)){
  298. $other_name = "Password Expiration in $expire_day Days";
  299. $other_desc = "Your password will expire in $expire_day days. To ensure the security of your
  300. account, please change your password as soon as possible.";
  301. $message_sql ="INSERT INTO public.kln_notifiation_info(notifiation_type, other_name, other_desc, other_img, notifications_method, email_method,
  302. user_login, insert_date, readed_date, is_send_message, is_send_email,
  303. frequency_type, other_type, other_pnum)
  304. VALUES ('Passwond_Notifcations','".$other_name."','".$other_desc."','',true,false,'".$uname."',now(),null,null,null,'Instant','password','".$expire_day."');";
  305. common::excuteUpdateSql($message_sql);
  306. }
  307. }
  308. if ($diffdate == $PASSWORD_CHANGE_CYCLE) {// Due today
  309. $login_tmp = array(
  310. 'msg' => 'today',
  311. "uname"=>$uname,
  312. 'user_info' => $kln_user_info,
  313. 'login_version' => $rs["login_version"],
  314. 'data' => ''
  315. );
  316. } elseif ($diffdate >= ($PASSWORD_CHANGE_CYCLE - $PASSWORD_CHANGE_ALERT)) {// Password expires soon, JS Tips
  317. $login_tmp = array(
  318. 'msg' => 'last',
  319. "uname"=>$uname,
  320. 'user_info' => $kln_user_info,
  321. 'login_version' => $rs["login_version"],
  322. 'data' => $PASSWORD_CHANGE_CYCLE - $diffdate,
  323. 'is_only_vgm' => $rs["is_only_vgm"]
  324. );
  325. }
  326. //insert into log table
  327. $ip = common::ip();
  328. $sql = "insert into public.ra_online_user_login_log (user_name,manufacturer,from_app,ip,date_time, session_id) values ('" . common::check_input($uname) . "', '" . common::check_input($company) . "','Online','$ip',now(), '" . session_id() . "')";
  329. if (common::excuteUpdateSql($sql)) {
  330. common::excuteUpdateSql("update public.ra_online_user set Last_Login_Time = now(), error_login_count=0, error_login_time=null where lower(user_login) = '" . strtolower($uname) . "'");
  331. if (isset($login_tmp)) {
  332. common::echo_json_encode(200, $login_tmp);
  333. } else {
  334. $data = array(
  335. 'msg' => 'success',
  336. "uname"=>$uname,
  337. 'user_info' => $kln_user_info,
  338. 'login_version' => $rs["login_version"],
  339. 'data' => '',
  340. 'is_only_vgm' => $rs["is_only_vgm"]
  341. );
  342. common::echo_json_encode(200, $data);
  343. }
  344. $online_user = $rs;
  345. $online_user['user_login'] = $uname;
  346. $online_user['company'] = $company;
  347. $online_user['password'] = "";
  348. if (!_isAdmin()) {
  349. if ($rs["is_only_vgm"] == "t") {//VGM用户写死
  350. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where url_action in ('ocean_order','password','vgm') and menu_id in ('ship','profile') order by order_by asc), ',')";
  351. $rrrs = common::excuteOneSql($sql);
  352. } else {
  353. $sql = "select array_to_string(ARRAY(select p.url_action from public.ra_online_user_permission up left join public.ra_online_user u on up.user_name = u.user_login left join public.ra_online_permission p on up.p_id = p.id where lower(u.user_login) = '" . common::check_input(strtolower($uname)) . "'), ',')";
  354. $rrrs = common::excuteOneSql($sql);
  355. if (strtolower($rs['user_type']) == "employee" && empty($rrrs)) {
  356. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where is_customer = true order by order_by asc), ',')";
  357. $rrrs = common::excuteOneSql($sql);
  358. }
  359. }
  360. $online_user['permission'] = $rrrs;
  361. }
  362. if (!empty($online_user['docdownload']))
  363. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where lower(serial_no) " . common::getInNotInSql($online_user['docdownload']) . " and active = true group by display_name order by min(id)";
  364. else {
  365. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where active = true";
  366. if (strtolower($online_user['user_type']) == "customer")
  367. $sql .= " and client_display = true";
  368. $sql .= " group by display_name order by min(id)";
  369. }
  370. $online_user['view_doc_type'] = common::excuteListSql($sql);
  371. if (!empty($online_user['view_air_file_format']))
  372. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where lower(serial_no) " . common::getInNotInSql($online_user['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  373. else {
  374. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where active = true";
  375. if (strtolower($online_user['user_type']) == "customer")
  376. $sql .= " and client_display = true";
  377. $sql .= " group by display_name order by min(id)";
  378. }
  379. $online_user['view_air_doc_type'] = common::excuteListSql($sql);
  380. //补充aci and ams CustomerLogin station - public
  381. $ocean_station_temp = $online_user['ocean_station'];
  382. $online_user['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  383. $ocean_agent_temp = $online_user['ocean_agent'];
  384. $online_user['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  385. $_SESSION['ONLINE_USER'] = $online_user;
  386. $_SESSION['LAST_OPERATE_TIME'] = time();
  387. $_SESSION['SESSION_TIMEOUT'] = $SESSION_TIMEOUT;
  388. //判断是否记录密码 add
  389. if ($_POST['rememberpwd'] === 'true') {
  390. if (!$noCheckPwd) {
  391. $user_info = $uname . "_" . md5($rs['password']);
  392. setcookie('userInfo', $user_info, time() + 30 * 24 * 3600, "/");
  393. }
  394. } else {
  395. setcookie('userInfo', '', time() - 1, "/");
  396. }
  397. if ($rs['is_super'] == "t") {
  398. $schemas_list = common::excuteListSql("select * from schemas_list");
  399. } else {
  400. $schemas_list = common::excuteListSql("select * from schemas_list where schemas_name=any(regexp_split_to_array('" . $rs['belong_schemas'] . "'::text, ';'::text))");
  401. }
  402. ///if (count($schemas_list) > 1) {
  403. foreach ($schemas_list as $sk => $sv) {
  404. if ($sv['schemas_name'] == "public") {
  405. continue;
  406. }
  407. $ttdd = common::excuteObjectSql("select contact_id_user, employee_id, contact_id, user_type, email, user_webtype_id, active, is_online, station, allow_login_remote, can_see_amslog,can_view_eccn, can_see_isflog, can_see_isflog_withaddress,
  408. customer_search_type, customer_destination, can_add_ams, can_add_isf, air_station, air_sales, ocean_station, ocean_sales,ocean_following_sales,ocean_following_sales_or,air_following_sales,air_following_sales_or, trucking_station, ocean_dest_op, can_see_password, can_add_opsales_code, ocean_station_or, ocean_agent_or, ocean_sales_or, ocean_dest_op_or, air_station_or, air_sales_or, trucking_station_or,
  409. can_add_user, can_add_employee, can_add_contact, company_name, ams_email, isf_email, customer_discharge, online_active, is_super, ocean_agent,active, can_send_email, view_file_format as docdownload, container_status, consolidated_cbsa_code, can_add_aci,
  410. air_customers, air_customer_search_type,trucking_customers,trucking_customer_search_type, upload_document, view_file_format, event_type, po_status, view_air_file_format, special_customer_event, can_edi_vgm, isf_aci_ams_station, is_kerry_shipment from " . $sv['schemas_name'] . ".ra_online_user where lower(user_login) = '" . strtolower($uname) . "'");
  411. if (empty($ttdd)) {
  412. unset($schemas_list[$sk]);
  413. continue;
  414. }
  415. if (!empty($ttdd['docdownload'])) {
  416. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['docdownload']) . " and active = true group by display_name order by min(id)";
  417. } else {
  418. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where active = true";
  419. if (strtolower($ttdd['user_type']) == "customer")
  420. $sql .= " and client_display = true";
  421. $sql .= " group by display_name order by min(id)";
  422. }
  423. $ttdd['view_doc_type'] = common::excuteListSql($sql);
  424. if (!empty($ttdd['view_air_file_format'])) {
  425. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  426. } else {
  427. $sql = "select string_agg(standard, ';') as standard, string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where active = true";
  428. if (strtolower($ttdd['user_type']) == "customer")
  429. $sql .= " and client_display = true";
  430. $sql .= " group by display_name order by min(id)";
  431. }
  432. $ttdd['view_air_doc_type'] = common::excuteListSql($sql);
  433. //补充aci and ams CustomerLogin station - other like sfs
  434. $ocean_station_temp = $ttdd['ocean_station'];
  435. $ttdd['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  436. $ocean_agent_temp = $ttdd['ocean_agent'];
  437. $ttdd['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  438. $_SESSION[$sv['schemas_name'] . '_ONLINE_USER'] = $ttdd;
  439. }
  440. //}
  441. $_SESSION['schemas_list'] = $schemas_list;
  442. //不再返回登录页面,直接跳转
  443. if (isset($_GET['up'])) {
  444. if($_GET['v'] == 'new'){
  445. header("Location: main_new_version.php?action=main");
  446. }else{
  447. header("Location: main.php?action=main");
  448. }
  449. }
  450. //处理登录成功后的记录保存
  451. //$user_type,$user_name,$page,$operation,$operation_detail
  452. // $user_type = _isCustomerLogin() ? "Customer" : "Employee";
  453. // $user_name = _getLoginName();
  454. // $detail = 'System Account,Login successful';
  455. // if(isset($_POST['token']) && !empty($_POST['token'])){
  456. // $detail = 'From Apex Online,Login successful';
  457. // }
  458. // utils::single_operation_log_save($user_type,$user_name,"Login","Login",$detail);
  459. exit();
  460. } else {
  461. $data = array(
  462. 'code' => 'database_error',
  463. 'login_version' => $rs["login_version"],
  464. 'msg' => 'database_error'
  465. );
  466. common::echo_json_encode(500, $data);
  467. exit();
  468. }
  469. } else {
  470. $data = array(
  471. 'code' => 'no_exist',
  472. 'login_version' => $rs["login_version"],
  473. 'msg' => 'The username or password you entered is incorrect'
  474. );
  475. common::echo_json_encode(500, $data);
  476. exit();
  477. }
  478. }
  479. }
  480. public function check_uname(){
  481. $uname = common::check_input($_POST['uname']);
  482. $sql = $this->getLoginSql();
  483. $rs = common::excuteObjectPrepareSql($sql,[md5(strtolower($uname))]);
  484. if (!empty($rs)) {
  485. //只是验证用户是否存在,是否激活
  486. //验证employee是否active
  487. if (!empty($rs["employee_id"]) && $rs["employee_id_active"] != "t") {
  488. if (strtolower(Soure) =='topocean'){
  489. if (strtolower($rs['user_type']) == "employee" && utils::endWith($rs['email'], "cn")) {
  490. $data = "<a href='mailto:lilyyang@topocean.com.cn'>lilyyang@topocean.com.cn</a>";
  491. }else{
  492. $data = "<a href='mailto:winnie@topocean.com'>winnie@topocean.com</a>";
  493. }
  494. }
  495. if (strtolower(Soure) =='apex'){
  496. $data = "<a href='mailto:maria.wang@apexshipping.com.cn'>maria.wang@apexshipping.com.cn</a>";
  497. }
  498. $data = array(
  499. 'msg' => 'no_active',
  500. );
  501. common::echo_json_encode(200, $data);
  502. exit();
  503. }
  504. if ($rs['is_online'] != 't') {
  505. if (strtolower($rs['user_type']) != "employee") {
  506. $data =array(
  507. 'msg' => 'no_online',
  508. );
  509. common::echo_json_encode(200, $data);
  510. exit();
  511. }
  512. }
  513. if ($rs['online_active'] != 't') {
  514. $data = array(
  515. 'msg' => 'no_active',
  516. );
  517. common::echo_json_encode(200, $data);
  518. exit();
  519. }
  520. //验证成功
  521. $data = array(
  522. 'msg' => 'success',
  523. );
  524. common::echo_json_encode(200, $data);
  525. exit();
  526. } else {
  527. $data = array(
  528. 'msg' => 'no_exist',
  529. );
  530. common::echo_json_encode(200, $data);
  531. exit();
  532. }
  533. }
  534. public function verifcation_code(){
  535. // 生成一个4位随机数作为验证码
  536. //$random_num = mt_rand(1000, 9999);
  537. $random_num = $this->generateCaptcha(4);
  538. $_SESSION['captcha'] = $random_num;
  539. // 创建一个宽度为80像素、高度为30像素的图片
  540. $width = 130;
  541. $height = 40;
  542. $image = imagecreate($width, $height);
  543. // 设置颜色
  544. $white = imagecolorallocate($image, 255, 255, 255); // 白色作为背景
  545. $black = imagecolorallocate($image, 0, 0, 0); // 黑色作为文字
  546. // 填充背景
  547. imagefilledrectangle($image, 0, 0, $width, $height, $white);
  548. // 在图片上绘制四个字符
  549. $font_size = 18;
  550. $x = 34;
  551. $y = 12;
  552. for ($i = 0; $i < 4; $i++) {
  553. $char = substr($random_num, $i, 1);
  554. imagestring($image, $font_size, $x, $y, $char, $black);
  555. $x += $font_size+1;
  556. }
  557. // 返回Base64编码
  558. ob_start();
  559. imagepng($image);
  560. $image_data = ob_get_clean();
  561. // 释放内存
  562. imagedestroy($image);
  563. $data = array("imagePngBase64" =>base64_encode($image_data));
  564. common::echo_json_encode(200, $data);
  565. exit();
  566. }
  567. //邮件密码原文
  568. public function forgot_password() {
  569. $login = common::check_input($_POST['login']);
  570. $email = common::check_input($_POST['email']);
  571. $is_verify = common::check_input($_POST['verifcation_code']);
  572. //首先校用户验证
  573. $AES_encrypted = utils::AES_encrypted($is_verify);
  574. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  575. where secret_key = '$is_verify'
  576. and create_time >= current_date - INTERVAL '3 months' limit 1");
  577. //记录这次的密钥记录
  578. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  579. if(!empty($AES_encrypted) && empty($secret_key)){
  580. }else{
  581. $data = array(
  582. 'msg' => 'verifcation_error',
  583. 'data' => ''
  584. );
  585. common::echo_json_encode(400, $data);
  586. exit();
  587. }
  588. $msg = "";
  589. if (!empty($email) || !empty($login)) {
  590. $sql_p = "select user_login, ra_password as password,user_type,
  591. to_char(now(), 'Mon-DD-YYYY') as current_date,to_char(now(), 'Mon-DD-YYYY HH24:MI:SS') as current_time
  592. from public.ra_online_user where md5(lower(user_login)) = ? and md5(lower(email)) = ?";
  593. //$rs = common::excuteObjectSql($sql_p);
  594. $rs = common::excuteObjectPrepareSql($sql_p,[md5(strtolower($login)),md5(strtolower($email))]);
  595. if (!empty($rs)) {
  596. //$r = utils::sendEmailByPassword($login, $rs['password'], $email);
  597. $r = utils::sendEmailByResetPassword($rs, $email);
  598. if ($r == 'success') {
  599. $msg = "success";
  600. } else {
  601. $msg = $r;
  602. }
  603. } else {
  604. $msg = "Can not find this user with give login id and email, please confirm!";
  605. }
  606. } else {
  607. $msg = "Login Name or Email Required !";
  608. }
  609. if($msg == 'success'){
  610. $data = array(
  611. 'msg' => $msg,
  612. );
  613. common::echo_json_encode(200, $data);
  614. }else{
  615. $data = array(
  616. 'msg' => $msg,
  617. );
  618. common::echo_json_encode(500, $data);
  619. }
  620. exit();
  621. }
  622. public function generateCaptcha($length = 6) {
  623. $captcha = '';
  624. $chars = "abcdefghijkmnpqrstuvwxyzABCDEFGHIJKLMNPQRSTUVWXYZ23456789";
  625. for ($i = 0; $i < $length; $i++) {
  626. // 随机选择字母或数字
  627. $char = $chars[mt_rand(0, strlen($chars) - 1)];
  628. $captcha .= strval($char);
  629. }
  630. return $captcha;
  631. }
  632. public function do_login_auto($is_demo = '') {
  633. $uname = common::check_input($_GET['u']);
  634. $password = common::check_input($_GET['p']);
  635. $login_error_times = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Login_Error_Times'");
  636. $lock_user_seconds = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Lock_User_Seconds'");
  637. if (!empty($uname) || !empty($password)) {
  638. } else {
  639. $uname = common::check_input($_POST['uname']);
  640. //检查长度,大于50,返回 no_exist
  641. common::checkUserNameLength($uname);
  642. $sql = $this->getLoginSql();
  643. $rs = common::excuteObjectPrepareSql($sql,[md5(strtolower($uname))]);
  644. if (!empty($rs)) {
  645. if (empty($rs['belong_schemas'])) {
  646. $rs['belong_schemas'] = "public";
  647. }
  648. if (empty($rs['main_schemas'])) {
  649. $rs['main_schemas'] = "public";
  650. }
  651. //验证employee是否active
  652. if (!empty($rs["employee_id"]) && $rs["employee_id_active"] != "t") {
  653. if (strtolower(Soure) =='topocean'){
  654. if (strtolower($rs['user_type']) == "employee" && utils::endWith($rs['email'], "cn")) {
  655. $data = "<a href='mailto:lilyyang@topocean.com.cn'>lilyyang@topocean.com.cn</a>";
  656. }else{
  657. $data = "<a href='mailto:winnie@topocean.com'>winnie@topocean.com</a>";
  658. }
  659. }
  660. if (strtolower(Soure) =='apex'){
  661. $data = "<a href='mailto:maria.wang@apexshipping.com.cn'>maria.wang@apexshipping.com.cn</a>";
  662. }
  663. $data = array(
  664. 'code' => 'no_active',
  665. 'login_version' => $rs["login_version"],
  666. 'data' => $data,
  667. 'msg' => "Please check with Doc Center $data for searching function"
  668. );
  669. common::echo_json_encode(4002, $data);
  670. $this->failedLogin($uname, 'Employee not active');
  671. exit();
  672. }
  673. //处理登录状态
  674. $userInfo = common::check_input($_COOKIE['userInfo']);
  675. $noCheckPwd = false;
  676. if (!empty($userInfo)) {
  677. $userInfoSplit = explode("_", $userInfo);
  678. if ($uname == $userInfoSplit[0]) {
  679. if ($userInfoSplit[1] == md5($rs['password'])) {
  680. $noCheckPwd = true;
  681. }
  682. }
  683. }
  684. if ($rs['error_login_count'] > $login_error_times && $rs['second'] < $lock_user_seconds) {
  685. $data = array(
  686. 'msg' => 'error_times',
  687. 'login_version' => $rs["login_version"],
  688. 'data' => ceil(($lock_user_seconds - $rs['second']) / 60)
  689. );
  690. common::echo_json_encode(400, $data);
  691. $this->failedLogin($uname, 'Failed login too times');
  692. exit();
  693. }
  694. if ($rs['is_online'] != 't') {
  695. if (strtolower($rs['user_type']) != "employee") {
  696. $data =array(
  697. 'code' => 'no_online',
  698. 'login_version' => $rs["login_version"],
  699. 'data' => '',
  700. 'msg' => 'No activation or insufficient permissions'
  701. );
  702. common::echo_json_encode(4002, $data);
  703. $this->failedLogin($uname, 'Online is not active');
  704. exit();
  705. }
  706. }
  707. //if ($rs['decrypt_password'] != $_POST['psw']) {
  708. if ($noCheckPwd) {
  709. }else{
  710. //如是是token登录,则不用验证密码
  711. if(isset($_POST['token']) && !empty($_POST['token'])){
  712. $is_verify = $_POST['token'];
  713. //$AES_encrypted = utils::AES_encrypted($is_verify,true,"fT5!R1k$7Mv@4Q9X","1234567890123456");
  714. $AES_encrypted = utils::AES_encrypted($is_verify,true,"USAIandy20244Q9X","1234567890123456");
  715. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  716. where secret_key = '$is_verify'
  717. and create_time >= current_date - INTERVAL '3 months' limit 1");
  718. //记录这次的密钥记录
  719. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  720. //密钥解析失败或者有重复的记录这提示登录失败
  721. if(!(!empty($AES_encrypted) && empty($secret_key))){
  722. $data = array(
  723. 'msg' => 'Invalid token',
  724. 'login_version' => $rs["login_version"],
  725. 'data' => ''
  726. );
  727. common::echo_json_encode(400, $data);
  728. exit();
  729. }
  730. }else{
  731. if ($rs['password'] != $_POST['psw'] && ($rs['temp_password'] != $_POST['psw'] || $rs['is_temp_password_expires'] == 'f')) {
  732. common::excuteUpdateSql("update public.ra_online_user set error_login_count=error_login_count+1, error_login_time=now() where lower(user_login) = '" . strtolower($uname) . "'");
  733. $data = array(
  734. 'msg' => 'password_error',
  735. 'login_version' => $rs["login_version"],
  736. 'data' => ''
  737. );
  738. common::echo_json_encode(400, $data);
  739. $this->failedLogin($uname, 'Password is wrong');
  740. exit();
  741. }
  742. }
  743. }
  744. if ($rs['online_active'] != 't') {
  745. $data = array(
  746. 'code' => 'no_active',
  747. 'login_version' => $rs["login_version"],
  748. 'data' => '',
  749. 'msg' => 'Please check with Doc Center for searching function'
  750. );
  751. common::echo_json_encode(4003, $data);
  752. $this->failedLogin($uname, 'Online is not active');
  753. exit();
  754. }
  755. //check password length
  756. $tar = utils::checkPassword($rs['password']);
  757. if (!empty($tar)) {
  758. $data = array(
  759. 'code' => $tar,
  760. 'login_version' => $rs["login_version"],
  761. 'data' => '',
  762. 'msg' => $tar
  763. );
  764. common::echo_json_encode(500, $data);
  765. exit();
  766. }
  767. //第一次登录,改密码
  768. if (empty($rs['last_pwd_change'])) {
  769. $data = array(
  770. 'login_version' => $rs["login_version"],
  771. 'data' => '',
  772. 'uname' =>$uname,
  773. 'user_info' => array("uname"=>$uname),
  774. 'msg' => 'First login, please change your password'
  775. );
  776. common::echo_json_encode(4001, $data);
  777. exit();
  778. }
  779. //get more infor by employee_id or contact_id
  780. $sql = '';
  781. $diffdate = $rs['last_pwd_change_date'];
  782. $user_type = $rs['user_type'];
  783. //if user is customer, check company
  784. if (strtolower($user_type) == 'customer') {
  785. $company = $rs['company_name'];
  786. } else {
  787. if (!empty($rs['station']))
  788. $company = $rs['station'];
  789. }
  790. if (strtolower($uname) == 'ra.admin') {
  791. $company = 'Admin';
  792. }
  793. // get system config
  794. $sql = "SELECT lower(ra_name) as ra_name, ra_value from ra_online_config where lower(ra_name) in ('employee_session_timeout', 'customer_session_timeout', 'password_change_alert', 'employee_password_change_cycle', 'customer_password_change_cycle')";
  795. $rs1s = common::excuteListSql($sql);
  796. foreach ($rs1s as $rs1) {
  797. if ($rs1['ra_name'] == 'employee_session_timeout')
  798. $EMPLOYEE_SESSION_TIMEOUT = $rs1['ra_value'];
  799. if ($rs1['ra_name'] == 'customer_session_timeout')
  800. $CUSTOMER_SESSION_TIMEOUT = $rs1['ra_value'];
  801. if ($rs1['ra_name'] == 'password_change_alert')
  802. $PASSWORD_CHANGE_ALERT = $rs1['ra_value'];
  803. if ($rs1['ra_name'] == 'employee_password_change_cycle')
  804. $EMPLOYEE_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  805. if ($rs1['ra_name'] == 'customer_password_change_cycle')
  806. $CUSTOMER_PASSWORD_CHANGE_CYCLE = $rs1['ra_value'];
  807. }
  808. $sql="select item_value from config where item='passwordChangePeriod'";
  809. $pcp = common::excuteObjectSql($sql);
  810. $passwordChangePeriod = json_decode($pcp["item_value"],true);
  811. if (strtolower($rs['user_type']) == 'employee') {
  812. $PASSWORD_CHANGE_CYCLE = $EMPLOYEE_PASSWORD_CHANGE_CYCLE;
  813. $SESSION_TIMEOUT = $EMPLOYEE_SESSION_TIMEOUT;
  814. //如果有新配置,则采用新配置
  815. if (!empty($pcp)) {
  816. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Employee"]["days"];
  817. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Employee"]["advanceDays"];
  818. }
  819. } else {
  820. $PASSWORD_CHANGE_CYCLE = $CUSTOMER_PASSWORD_CHANGE_CYCLE;
  821. $SESSION_TIMEOUT = $CUSTOMER_SESSION_TIMEOUT;
  822. //如果有新配置,则采用新配置
  823. if (!empty($pcp)) {
  824. $PASSWORD_CHANGE_CYCLE = $passwordChangePeriod["Customer"]["days"];
  825. $PASSWORD_CHANGE_ALERT = $passwordChangePeriod["Customer"]["advanceDays"];
  826. }
  827. }
  828. //Timeout
  829. if ($diffdate > $PASSWORD_CHANGE_CYCLE) {
  830. //自动登录这里移除这个邮箱为空的检查
  831. $kln_user_info = array("uname"=>$uname);
  832. $result = array(
  833. 'msg' => "passwordExpires",
  834. 'uname' => $uname,
  835. 'user_info' => $kln_user_info
  836. );
  837. common::echo_json_encode(4001, $result);
  838. exit();
  839. }
  840. //kln新版查询 date_format,numbers_format
  841. $kln_user = common::excuteObjectSql("select * from public.kln_user_extend where lower(user_login) = '".strtolower($uname)."'");
  842. //检查用户是否是设置过subscribe_notification,加在这里,少一次请求
  843. $count = common::excuteOneSql("select count(*) from public.notifications_rules where
  844. notifications_type = 'Subscribe'
  845. and lower(user_login) = '".strtolower($uname)."'");
  846. $subscribe_notification_default_init = $count > 0 ? false:true;
  847. //添加FAQ客户的访问类型
  848. $loginCount = common::excuteOneSql("select count(*) from public.ra_online_user_login_log where lower(user_name) = '".strtolower(common::check_input($uname))."' and date_time >= CURRENT_DATE - INTERVAL '30 day' AND date_time <= CURRENT_DATE");
  849. //查询该用户下的mapping
  850. // $kam_customers_name = common::excuteListSql("select
  851. // (select user_login from public.ra_online_user u where u.user_id = m.responsible_customers_id) as kam_customers_name
  852. // from public.ra_online_user_kam_mapping m where m.kam_account_id = '".$rs['user_id']."'");
  853. $kln_user_info = array("uname"=>$rs['user_login'],
  854. "employee_email"=>$rs['employee_email'],
  855. //"employee_email"=>"andy.wu@united-cn.net",
  856. "user_type"=>strtolower($rs['user_type']),
  857. "first_name"=>$rs['first_name'],
  858. "last_name"=>$rs['last_name'],
  859. "is_desensitization_kln"=>$rs['is_desensitization_kln'],
  860. "email"=>$rs['email'],
  861. //"kam_customers_name"=>$kam_customers_name,
  862. "expire_day"=>$PASSWORD_CHANGE_CYCLE - $rs['last_pwd_change_date'],
  863. "PASSWORD_CHANGE_CYCLE"=>intval($PASSWORD_CHANGE_CYCLE),
  864. "subscribe_notification_default_init"=>$subscribe_notification_default_init,
  865. "last_pwd_change"=>$rs['last_pwd_change'],
  866. "date_format"=>$kln_user['date_format'],
  867. "numbers_format"=>$kln_user['numbers_format'],
  868. "loginCount"=>intval($loginCount));
  869. //添加密码是否快过期的消息通知 7 天内,3天内的通知
  870. $expire_day = ($PASSWORD_CHANGE_CYCLE - $rs['last_pwd_change_date']);
  871. if($expire_day <= 7){
  872. $exist = common::excuteListSql("select notifiation_type from public.kln_notifiation_info where notifiation_type = 'Passwond_Notifcations'
  873. and lower(user_login) = '".strtolower($uname)."' and other_pnum = '".$expire_day."'");
  874. if (empty($exist)){
  875. $other_name = "Password Expiration in $expire_day Days";
  876. $other_desc = "Your password will expire in $expire_day days. To ensure the security of your
  877. account, please change your password as soon as possible.";
  878. $message_sql ="INSERT INTO public.kln_notifiation_info(notifiation_type, other_name, other_desc, other_img, notifications_method, email_method,
  879. user_login, insert_date, readed_date, is_send_message, is_send_email,
  880. frequency_type, other_type, other_pnum)
  881. VALUES ('Passwond_Notifcations','".$other_name."','".$other_desc."','',true,false,'".$uname."',now(),null,null,null,'Instant','password','".$expire_day."');";
  882. common::excuteUpdateSql($message_sql);
  883. }
  884. }
  885. if ($diffdate == $PASSWORD_CHANGE_CYCLE) {// Due today
  886. $login_tmp = array(
  887. 'msg' => 'today',
  888. "uname"=>$uname,
  889. 'user_info' => $kln_user_info,
  890. 'login_version' => $rs["login_version"],
  891. 'data' => ''
  892. );
  893. } elseif ($diffdate >= ($PASSWORD_CHANGE_CYCLE - $PASSWORD_CHANGE_ALERT)) {// Password expires soon, JS Tips
  894. $login_tmp = array(
  895. 'msg' => 'last',
  896. "uname"=>$uname,
  897. 'user_info' => $kln_user_info,
  898. 'login_version' => $rs["login_version"],
  899. 'data' => $PASSWORD_CHANGE_CYCLE - $diffdate,
  900. 'is_only_vgm' => $rs["is_only_vgm"]
  901. );
  902. }
  903. //insert into log table
  904. $ip = common::ip();
  905. $sql = "insert into public.ra_online_user_login_log (user_name,manufacturer,from_app,ip,date_time, session_id) values ('" . common::check_input($uname) . "', '" . common::check_input($company) . "','Online','$ip',now(), '" . session_id() . "')";
  906. if (common::excuteUpdateSql($sql)) {
  907. common::excuteUpdateSql("update public.ra_online_user set Last_Login_Time = now(), error_login_count=0, error_login_time=null where lower(user_login) = '" . strtolower($uname) . "'");
  908. //自动登录。为了方便调用,先注销掉
  909. if (isset($login_tmp)) {
  910. if($is_demo <> 'test'){
  911. common::echo_json_encode(500, $login_tmp);
  912. }
  913. } else {
  914. $data = array(
  915. 'msg' => 'success',
  916. "uname"=>$uname,
  917. 'user_info' => $kln_user_info,
  918. 'login_version' => $rs["login_version"],
  919. 'data' => '',
  920. 'is_only_vgm' => $rs["is_only_vgm"]
  921. );
  922. if($is_demo <> 'test'){
  923. common::echo_json_encode(200, $data);
  924. }
  925. }
  926. $online_user = $rs;
  927. $online_user['user_login'] = $uname;
  928. $online_user['company'] = $company;
  929. $online_user['password'] = "";
  930. if (!($rs['is_super'] == 't')) {
  931. if ($rs["is_only_vgm"] == "t") {//VGM用户写死
  932. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where url_action in ('ocean_order','password','vgm') and menu_id in ('ship','profile') order by order_by asc), ',')";
  933. $rrrs = common::excuteOneSql($sql);
  934. } else {
  935. $sql = "select array_to_string(ARRAY(select p.url_action from public.ra_online_user_permission up left join public.ra_online_user u on up.user_name = u.user_login left join public.ra_online_permission p on up.p_id = p.id where lower(u.user_login) = '" . common::check_input(strtolower($uname)) . "'), ',')";
  936. $rrrs = common::excuteOneSql($sql);
  937. if (strtolower($rs['user_type']) == "employee" && empty($rrrs)) {
  938. $sql = "select array_to_string(ARRAY(select url_action from public.ra_online_permission where is_customer = true order by order_by asc), ',')";
  939. $rrrs = common::excuteOneSql($sql);
  940. }
  941. }
  942. $online_user['permission'] = $rrrs;
  943. }
  944. if (!empty($online_user['docdownload']))
  945. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where lower(serial_no) " . common::getInNotInSql($online_user['docdownload']) . " and active = true group by display_name order by min(id)";
  946. else {
  947. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from ra_online_file_format where active = true";
  948. if (strtolower($online_user['user_type']) == "customer")
  949. $sql .= " and client_display = true";
  950. $sql .= " group by display_name order by min(id)";
  951. }
  952. $online_user['view_doc_type'] = common::excuteListSql($sql);
  953. if (!empty($online_user['view_air_file_format']))
  954. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where lower(serial_no) " . common::getInNotInSql($online_user['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  955. else {
  956. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from air_file_format where active = true";
  957. if (strtolower($online_user['user_type']) == "customer")
  958. $sql .= " and client_display = true";
  959. $sql .= " group by display_name order by min(id)";
  960. }
  961. $online_user['view_air_doc_type'] = common::excuteListSql($sql);
  962. //补充aci and ams CustomerLogin station - public
  963. $ocean_station_temp = $online_user['ocean_station'];
  964. $online_user['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  965. $ocean_agent_temp = $online_user['ocean_agent'];
  966. $online_user['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  967. session_start();
  968. //重新登录后,SESSION先注销,在创建
  969. $_SESSION = [];
  970. $_SESSION['ONLINE_USER'] = $online_user;
  971. $_SESSION['LAST_OPERATE_TIME'] = time();
  972. $_SESSION['SESSION_TIMEOUT'] = $SESSION_TIMEOUT;
  973. //判断是否记录密码
  974. if ($_POST['rememberpwd'] === 'true') {
  975. if (!$noCheckPwd) {
  976. $user_info = $uname . "_" . md5($rs['password']);
  977. setcookie('userInfo', $user_info, time() + 30 * 24 * 3600, "/");
  978. }
  979. } else {
  980. setcookie('userInfo', '', time() - 1, "/");
  981. }
  982. if ($rs['is_super'] == "t") {
  983. $schemas_list = common::excuteListSql("select * from schemas_list");
  984. } else {
  985. $schemas_list = common::excuteListSql("select * from schemas_list where schemas_name=any(regexp_split_to_array('" . $rs['belong_schemas'] . "'::text, ';'::text))");
  986. }
  987. ///if (count($schemas_list) > 1) {
  988. foreach ($schemas_list as $sk => $sv) {
  989. if ($sv['schemas_name'] == "public") {
  990. continue;
  991. }
  992. $ttdd = common::excuteObjectSql("select contact_id_user, employee_id, contact_id, user_type, email, user_webtype_id, active, is_online, station, allow_login_remote, can_see_amslog,can_view_eccn, can_see_isflog, can_see_isflog_withaddress,
  993. customer_search_type, customer_destination, can_add_ams, can_add_isf, air_station, air_sales, ocean_station, ocean_sales,ocean_following_sales,ocean_following_sales_or,air_following_sales,air_following_sales_or, trucking_station, ocean_dest_op, can_see_password, can_add_opsales_code, ocean_station_or, ocean_agent_or, ocean_sales_or, ocean_dest_op_or, air_station_or, air_sales_or, trucking_station_or,
  994. can_add_user, can_add_employee, can_add_contact, company_name, ams_email, isf_email, customer_discharge, online_active, is_super, ocean_agent,active, can_send_email, view_file_format as docdownload, container_status, consolidated_cbsa_code, can_add_aci,
  995. air_customers, air_customer_search_type,trucking_customers,trucking_customer_search_type, upload_document, view_file_format, event_type, po_status, view_air_file_format, special_customer_event, can_edi_vgm, isf_aci_ams_station, is_kerry_shipment from " . $sv['schemas_name'] . ".ra_online_user where lower(user_login) = '" . strtolower($uname) . "'");
  996. if (empty($ttdd)) {
  997. unset($schemas_list[$sk]);
  998. continue;
  999. }
  1000. if (!empty($ttdd['docdownload'])) {
  1001. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['docdownload']) . " and active = true group by display_name order by min(id)";
  1002. } else {
  1003. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".ra_online_file_format where active = true";
  1004. if (strtolower($ttdd['user_type']) == "customer")
  1005. $sql .= " and client_display = true";
  1006. $sql .= " group by display_name order by min(id)";
  1007. }
  1008. $ttdd['view_doc_type'] = common::excuteListSql($sql);
  1009. if (!empty($ttdd['view_air_file_format'])) {
  1010. $sql = "select string_agg(standard, ';') as standard,string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where lower(serial_no) " . common::getInNotInSql($ttdd['view_air_file_format']) . " and active = true group by display_name order by min(id)";
  1011. } else {
  1012. $sql = "select string_agg(standard, ';') as standard, string_agg(serial_no, ';') as serial_no, string_agg(m_h, ';') as m_h, display_name from " . $sv['schemas_name'] . ".air_file_format where active = true";
  1013. if (strtolower($ttdd['user_type']) == "customer")
  1014. $sql .= " and client_display = true";
  1015. $sql .= " group by display_name order by min(id)";
  1016. }
  1017. $ttdd['view_air_doc_type'] = common::excuteListSql($sql);
  1018. //补充aci and ams CustomerLogin station - other like sfs
  1019. $ocean_station_temp = $ttdd['ocean_station'];
  1020. $ttdd['session_ocean_station'] = $this->getOriginOrAgent($ocean_station_temp);
  1021. $ocean_agent_temp = $ttdd['ocean_agent'];
  1022. $ttdd['session_ocean_agent'] = $this->getOriginOrAgent($ocean_agent_temp);
  1023. $_SESSION[$sv['schemas_name'] . '_ONLINE_USER'] = $ttdd;
  1024. }
  1025. //}
  1026. $_SESSION['schemas_list'] = $schemas_list;
  1027. //不再返回登录页面,直接跳转
  1028. if (isset($_GET['up'])) {
  1029. if($_GET['v'] == 'new'){
  1030. header("Location: main_new_version.php?action=main");
  1031. }else{
  1032. header("Location: main.php?action=main");
  1033. }
  1034. }
  1035. //自动登录。为了方便调用,先注销掉
  1036. if($is_demo <> 'test'){
  1037. exit();
  1038. }
  1039. } else {
  1040. $data = array(
  1041. 'code' => 'database_error',
  1042. 'login_version' => $rs["login_version"],
  1043. 'msg' => 'database_error'
  1044. );
  1045. common::echo_json_encode(500, $data);
  1046. exit();
  1047. }
  1048. } else {
  1049. $data = array(
  1050. 'code' => 'no_exist',
  1051. 'login_version' => $rs["login_version"],
  1052. 'msg' => 'The username or password you entered is incorrect'
  1053. );
  1054. common::echo_json_encode(500, $data);
  1055. exit();
  1056. }
  1057. }
  1058. }
  1059. private function failedLogin($uname, $company){
  1060. $ip = common::ip();
  1061. common::excuteUpdateSql("insert into public.ra_online_user_login_log (user_name,manufacturer,from_app,ip,date_time, session_id) values ('" . common::check_input($uname) . "', '" . common::check_input($company) . "','Online','$ip',now(), '" . session_id() . "')");
  1062. }
  1063. //重置密码
  1064. public function passwordExpires($loginName,$email,$uname){
  1065. $kln_user_info = array("uname"=>$uname);
  1066. $result = array(
  1067. 'msg' => "passwordExpires",
  1068. 'uname' => $uname,
  1069. 'user_info' => $kln_user_info
  1070. );
  1071. common::echo_json_encode(400, $result);
  1072. exit();
  1073. }
  1074. //submit change form -- change expires password
  1075. public function update_pwd_expires(){
  1076. $loginName = common::check_input($_POST['uname']);
  1077. $old_password = common::check_input($_POST['old_password']);
  1078. $password = common::check_input($_POST['password']);
  1079. if (empty($old_password) || empty($password)){
  1080. $data = array(
  1081. 'msg' => 'Old password or New password is incorrect!',
  1082. 'data' => ''
  1083. );
  1084. common::echo_json_encode(500, $data);
  1085. exit();
  1086. }
  1087. //首先校验验证码 暂时注销掉
  1088. // $verifcation_code = "";
  1089. // $verifcation_code = common::check_input($_POST['verifcation_code']);
  1090. // if (strtolower($_SESSION['captcha']) != strtolower($verifcation_code)) {
  1091. // $data = array(
  1092. // 'msg' => 'verifcation_error',
  1093. // 'data' => ''
  1094. // );
  1095. // common::echo_json_encode(400, $data);
  1096. // exit();
  1097. // }
  1098. $sql = "select ra_password as password from ra_online_user where md5(lower(user_login)) = ?";
  1099. $rs = common::excuteObjectPrepareSql($sql,[md5(strtolower($loginName))]);
  1100. $str = '';
  1101. if (!empty($rs)) {
  1102. if ($rs['password'] != $old_password) {
  1103. $str = "Old password is incorrect!";
  1104. }
  1105. } else {
  1106. $str = "Old password is incorrect!";
  1107. }
  1108. if(!empty($str)){
  1109. $data = array(
  1110. 'msg' => $str,
  1111. 'data' => ''
  1112. );
  1113. common::echo_json_encode(500, $data);
  1114. exit();
  1115. }
  1116. //验证通过,进行修改密码
  1117. $msg = $this->updateExpirePassword($loginName, $password);
  1118. if($msg == "success"){
  1119. $data = array(
  1120. 'msg' => "success",
  1121. 'data' => ''
  1122. );
  1123. common::echo_json_encode(200, $data);
  1124. exit();
  1125. } else {
  1126. $data = array(
  1127. 'msg' => $msg,
  1128. 'data' => ''
  1129. );
  1130. common::echo_json_encode(500, $data);
  1131. exit();
  1132. }
  1133. }
  1134. //更新密码
  1135. public function updateExpirePassword($login,$new_password) {
  1136. $str = common::checkPasswordRule($login, $new_password);
  1137. //更新密码,擦除expire pwd痕迹
  1138. if (empty($str)) {
  1139. $sql = "UPDATE public.ra_online_user SET ra_password = '" . common::check_input($new_password) . "',password_new=redant_encode('".$new_password."'),
  1140. last_pwd_change = now(),password_expires_keycode = null,password_expires_time = null
  1141. WHERE lower(user_login) = '" . common::check_input(strtolower($login)) . "';";
  1142. $rls = common::excuteUpdateSql($sql);
  1143. if (!$rls) {
  1144. $str = "Database Error, Try Later.";
  1145. } else {
  1146. $sql = "INSERT INTO public.ra_online_user_password_history (user_login, password, create_user, create_date) VALUES ('" . $login . "', '" . common::check_input($new_password) . "', '" . $login . "', now());";
  1147. common::excuteUpdateSql($sql);
  1148. $str = "success";
  1149. }
  1150. }
  1151. return $str;
  1152. }
  1153. public function getOriginOrAgent($ocean_station_temp){
  1154. $session_ocean_station = "";
  1155. if (strtolower($ocean_station_temp) == 'all'){
  1156. $session_ocean_station = $ocean_station_temp;
  1157. }
  1158. if (!(strtolower($ocean_station_temp) == 'all' || empty($ocean_station_temp))){
  1159. if (utils::checkExist($ocean_station_temp, ";")) {
  1160. $ost = str_replace(";","','",strtolower($ocean_station_temp));
  1161. $sql="select kerry_station_id,contact_id from ocean.contacts where coalesce(kerry_station_id,'') <>''and lower(contact_id) in ('".$ost."')";
  1162. $tar = common::excuteListSql($sql);
  1163. foreach ($tar as $tk => $tv) {
  1164. $tar[$tv['contact_id']] = $tv['kerry_station_id'];
  1165. }
  1166. $_tt = explode(";", $ocean_station_temp);
  1167. foreach ($_tt as $vv) {
  1168. if (!empty($vv)){
  1169. $session_ocean_station .= trim($vv).';';
  1170. if (!empty($tar[$vv])) {
  1171. $session_ocean_station .= $tar[trim($vv)].';';
  1172. }
  1173. }
  1174. }
  1175. } else {
  1176. $session_ocean_station .= trim($ocean_station_temp).';';
  1177. $temp_contacts = common::excuteObjectSql("select kerry_station_id from ocean.contacts where lower(contact_id)='".strtolower(common::check_input($ocean_station_temp))."'");
  1178. if (!empty($temp_contacts['kerry_station_id'])){
  1179. $session_ocean_station .= $temp_contacts['kerry_station_id'].';';
  1180. }
  1181. }
  1182. }
  1183. return $session_ocean_station;
  1184. }
  1185. public function logout() {
  1186. unset($_SESSION['ONLINE_USER']);
  1187. unset($_SESSION['LAST_OPERATE_TIME']);
  1188. unset($_SESSION['SESSION_TIMEOUT']);
  1189. common::sessionDestroy();
  1190. session_write_close();
  1191. $data = array("msg" =>"logout Successful");
  1192. common::echo_json_encode(200, $data);
  1193. exit();
  1194. }
  1195. public function tracking_checked(){
  1196. $reference_number = common::check_input($_POST['reference_number']);
  1197. $is_verify = common::check_input($_POST['verifcation_code']);
  1198. if($this->signUpAndTrackingChecked($is_verify)){
  1199. $data = array("msg" =>"visit limit");
  1200. common::echo_json_encode(400, $data);
  1201. exit();
  1202. }else{
  1203. $reference_number_lower = strtolower($reference_number);
  1204. $checked = common::checkInputInval($reference_number_lower);
  1205. if ($checked){
  1206. $online_ocean_sql = "select serial_no,order_from,agent,from_station from public.kln_ocean
  1207. where ((ARRAY['$reference_number_lower'] && array_append(ARRAY[lower(booking_no::text), lower(h_bol::text), lower(m_bol), lower(carrier_booking), lower(quote_no), lower(tracking_no)]||string_to_array(lower(ctnrs),','), ''::text))
  1208. or lower(po_no) like '%$reference_number_lower%'
  1209. or lower(invoice_no) like '%$reference_number_lower%') and coalesce(schem_not_display, false)=false";
  1210. $online_ocean_arr = common::excuteListSql($online_ocean_sql);
  1211. if(empty($online_ocean_arr)){
  1212. $data = array("msg" =>"No matches");
  1213. }elseif(!empty($online_ocean_arr) && utils::count($online_ocean_arr) > 1){
  1214. //當同一個hawb有超過一條數據時,選擇destination office和from station(job的創建站點)一致的shipment進行展示
  1215. $is_job_flag = true;
  1216. foreach($online_ocean_arr as $arr){
  1217. if ($arr['agent'] == $arr['from_station']){
  1218. $data = $this->getTrackingInfo($arr["serial_no"],$arr["order_from"]);
  1219. $is_job_flag = false;
  1220. break;
  1221. }
  1222. }
  1223. if ($is_job_flag) {
  1224. $data = array("msg" =>"Multiple results");
  1225. }
  1226. }else{
  1227. $data = $this->getTrackingInfo($online_ocean_arr[0]["serial_no"],$online_ocean_arr[0]["order_from"]);
  1228. }
  1229. } else {
  1230. $data = array("msg" =>"No matches");
  1231. }
  1232. common::echo_json_encode(200, $data);
  1233. //记录查询log情况
  1234. $detail = "";
  1235. if($data['msg'] == "success"){
  1236. $detail = "Public tracking number:".$reference_number."; search successful";
  1237. } else {
  1238. $detail = "Public tracking number:".$reference_number."; search fail(".$data['msg'].")";
  1239. }
  1240. $user_name = common::ip();
  1241. utils::single_operation_log_save("Customer",$user_name,"Tracking","Public tracking",$detail);
  1242. exit();
  1243. }
  1244. }
  1245. private function signUpAndTrackingChecked($is_verify){
  1246. $Tracking_Search_Count = common::excuteOneSql("select ra_value from ra_online_config where ra_name='Tracking_Search_Count'");
  1247. $ip = common::ip();
  1248. global $db;
  1249. $db->StartTrans();
  1250. $db->Execute("update tracking_login_record set visit_count = 1, visit_time=now() "
  1251. . " where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' < NOW()::timestamp ") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1252. $ipInfo = $db->GetRow("select ip, visit_count from tracking_login_record where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' > NOW()::timestamp");
  1253. if(empty($ipInfo)){
  1254. $db->Execute("INSERT INTO public.tracking_login_record(ip, visit_count,visit_time,type)VALUES ('$ip', '1', now(),'".common::check_input($_POST['type'])."');") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1255. }else{
  1256. if ($ipInfo['visit_count'] > $Tracking_Search_Count){
  1257. $AES_encrypted = utils::AES_encrypted($is_verify);
  1258. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  1259. where secret_key = '$is_verify'
  1260. and create_time >= current_date - INTERVAL '3 months' limit 1");
  1261. //记录这次的密钥记录
  1262. common::excuteUpdateSql("INSERT INTO public.customer_service_secret_key(secret_key, create_time)VALUES ('$is_verify', now());");
  1263. if(!empty($AES_encrypted) && empty($secret_key)){
  1264. //归零验证次数
  1265. $db->Execute("update tracking_login_record set visit_count = 1 "
  1266. . " where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' > NOW()::timestamp ") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1267. }else{
  1268. return TRUE;
  1269. }
  1270. }else{
  1271. $db->Execute("update tracking_login_record set visit_count = visit_count::integer + 1 "
  1272. . " where ip = '$ip' and type ilike '".common::check_input($_POST['type'])."' and visit_time + '5 min' > NOW()::timestamp ") or ( (!$db->ErrorMsg()) or error_log($db->ErrorMsg(), 0));
  1273. }
  1274. }
  1275. if ($db->CompleteTrans() === FALSE) {
  1276. //出错拦截
  1277. return TRUE;
  1278. } else {
  1279. return FALSE;
  1280. }
  1281. }
  1282. private function getTrackingInfo($serial_no,$order_from){
  1283. $sql = common::trackingSql($serial_no,$order_from);
  1284. $ocean_arr = common::excuteListSql($sql);
  1285. if(empty($ocean_arr)){
  1286. $data = array("msg" =>"No matches");
  1287. return $data;
  1288. }
  1289. if(!empty($ocean_arr) && utils::count($ocean_arr) > 1){
  1290. $data = array("msg" =>"Multiple results");
  1291. return $data;
  1292. }
  1293. $ocean = $ocean_arr[0];
  1294. //处理transportInfo信息数据
  1295. $transportInfo = array("Tracking No." =>$ocean['tracking_no'],"status"=>$ocean['new_status'],
  1296. "mode" =>$ocean['transport_mode_extend'] == 'sea' ? "Ocean Freight" :
  1297. ($ocean['transport_mode_extend'] == 'air' ? "Air Freight":
  1298. ($ocean['transport_mode_extend'] == 'rail' ? "Rail Freight":
  1299. ($ocean['transport_mode_extend'] == 'road' ? "Road Freight": ""))),
  1300. "origin" =>$ocean['shippr_uncode'],"destination" =>$ocean['consignee_uncode'],
  1301. "etd" =>$ocean['etd'],"atd" =>$ocean['atd'],
  1302. "etd_timezone" =>$ocean['pol_timezone'],
  1303. "atd_timezone" =>$ocean['pol_timezone'],
  1304. "eta" =>$ocean['eta'],"ata" =>$ocean['ata'],
  1305. "eta_timezone" =>$ocean['mpod_timezone'],
  1306. "ata_timezone" =>$ocean['mpod_timezone']);
  1307. $data['transportInfo'] = $transportInfo;
  1308. //处理basicInfo信息数据
  1309. if($ocean['transport_mode'] == "sea"){
  1310. $vessel = utils::outDisplayForMerge($ocean['f_vessel'],$ocean['m_vessel']);
  1311. $voyage = utils::outDisplayForMerge($ocean['f_voyage'],$ocean['m_voyage']);
  1312. } elseif ($ocean['transport_mode'] == "air"){
  1313. $vessel = $ocean['vessel'];
  1314. $voyage = $ocean['voyage'];
  1315. }
  1316. $basicInfo = array("MAWB/MBL No." =>$ocean['m_bol'],"HAWB/HBOL" => $ocean['h_bol'],"Carrier_Booking_No" =>$ocean['booking_no'],
  1317. "PO_NO" =>$ocean['po_no'],"Vessel/Airline" =>$vessel,"Voyage/Filght" =>$voyage,
  1318. "Incoterm" =>$ocean['incoterms'],"Service_Type" =>$ocean['service']);
  1319. //处理 拼接地址 ocean表单exp 字段无法精准分割电话和地址信息,只能从contacts表里查询
  1320. $shipper_address = common::retStationInfo($ocean['sh_address_1'], $ocean['sh_address_2'], $ocean['sh_address_3'], $ocean['sh_address_4'],
  1321. $ocean['sh_city'], $ocean['sh_state'], $ocean['sh_zipcode'], $ocean['sh_country']);
  1322. $consignee_address = common::retStationInfo($ocean['cn_address_1'], $ocean['cn_address_2'], $ocean['cn_address_3'], $ocean['cn_address_4'],
  1323. $ocean['cn_city'], $ocean['cn_state'], $ocean['cn_zipcode'], $ocean['cn_country']);
  1324. $origin_address = common::retStationInfo($ocean['aa_address_1'], $ocean['aa_address_2'], $ocean['aa_address_3'], $ocean['aa_address_4'],
  1325. $ocean['aa_city'], $ocean['aa_state'], $ocean['aa_zipcode'], $ocean['aa_country']);
  1326. $destination_address = common::retStationInfo($ocean['dd_address_1'], $ocean['dd_address_2'], $ocean['dd_address_3'], $ocean['dd_address_4'],
  1327. $ocean['dd_city'], $ocean['dd_state'], $ocean['dd_zipcode'], $ocean['dd_country']);
  1328. $shipperPartners = array("company" =>$ocean['sh_company'],"address"=>$shipper_address,"phone"=>$ocean['sh_phone']);
  1329. $consigneePartners = array("company" =>$ocean['cn_company'],"address"=>$consignee_address,"phone"=>$ocean['cn_phone']);
  1330. $originPartners = array("company" =>$ocean['aa_company'],"address"=>$origin_address,"phone"=>$ocean['aa_phone']);
  1331. $destinationPartners = array("company" =>$ocean['dd_company'],"address"=>$destination_address,"phone"=>$ocean['dd_phone']);
  1332. $businessPartners = array("shipper"=>$shipperPartners,"consignee" => $consigneePartners,"origin" => $originPartners,"destination" => $destinationPartners);
  1333. //处理marksAndDescription
  1334. $marksAndDescription = array("marks"=>$ocean['marks'],"description"=>$ocean['description']);
  1335. if($ocean['transport_mode'] == "sea"){
  1336. $sql = "SELECT " . column::getInstance()->getSearchSql('Ocean_Container') . " ,net_lbs from $order_from.oc_container where lower(serial_no) = '" . strtolower($ocean['serial_no']) . "'";
  1337. $rss = common::excuteListSql($sql);
  1338. $quantity_unit = array();
  1339. $g_weight_tolal = 0;
  1340. $ch_weight_tolal = 0;
  1341. $ch_weight_tolal_grs_lbs = 0;
  1342. $cbm_tolal = 0;
  1343. foreach ($rss as $key => $rs) {
  1344. $unit = $rs['unit'];
  1345. if (array_key_exists($unit, $quantity_unit)) {
  1346. $quantity_unit[$unit] = $quantity_unit[$unit] + $rs['qty'];
  1347. } else {
  1348. $quantity_unit[$unit] = $rs['qty'];
  1349. }
  1350. $g_weight_tolal += $rs['grs_kgs'];
  1351. $ch_weight_tolal += $rs['net_lbs'];
  1352. $ch_weight_tolal_grs_lbs += $rs['grs_lbs'];
  1353. $cbm_tolal += $rs['cbm'];
  1354. }
  1355. $quantity_tolal = "";
  1356. foreach($quantity_unit as $uk => $uv){
  1357. $quantity_tolal.=$uv." ".$uk." ";
  1358. }
  1359. $ch_weight_tolal = empty($ch_weight_tolal) ? $ch_weight_tolal_grs_lbs : $ch_weight_tolal;
  1360. //Packing 不确定信息
  1361. $packing = array("Quantity/Unit"=>$quantity_tolal,"G. Weight" => $g_weight_tolal." KGS","Ch. Weight" => $ch_weight_tolal." LBS","Volume" => $cbm_tolal." CBM");
  1362. } elseif ($ocean['transport_mode'] == "air"){
  1363. $quantity_tolal = empty($ocean['qty']) ? "" : $ocean['qty'].$ocean['qty_uom'];
  1364. $g_weight_tolal = empty($ocean['piece_count']) ? "" : sprintf("%.3f", $ocean['piece_count'])." KGS";
  1365. $ch_weight_tolal = empty($ocean['piece_count']) ? "": sprintf("%.3f", $ocean['weight'])." KGS";
  1366. $cbm_tolal = empty($ocean['cbm']) ? "" : sprintf("%.4f", $ocean['cbm'])." CBM";
  1367. //Packing信息
  1368. $packing = array("Quantity/Unit"=>$quantity_tolal,"G. Weight" => $g_weight_tolal,"Ch. Weight" => $ch_weight_tolal,"Volume" => $cbm_tolal);
  1369. }
  1370. /* Container Status */
  1371. //sea 才有EDI315
  1372. if($ocean['transport_mode'] == "sea"){
  1373. $serial_no = $ocean["serial_no"];
  1374. $ctnr_sql = "SELECT oc.ctnr, oc.serial_no,oc.size FROM $order_from.oc_container oc LEFT JOIN ocean o ON oc.serial_no = o.serial_no
  1375. WHERE o.serial_no='$serial_no'";
  1376. $ctnr_data = common::excuteListSql($ctnr_sql);
  1377. foreach ($ctnr_data as $cd){
  1378. //存在柜号为空的数据情况
  1379. if(empty($cd['ctnr'])){
  1380. continue;
  1381. }
  1382. $ctnr_status_sql = "select s.source_id, s.event_base as event,
  1383. to_char(to_timestamp(s.event_date, 'YYYYMMDD'), 'YYYY-MM-DD') as eventdate,
  1384. to_char(to_timestamp(s.event_time, 'HH24MI'), 'HH24:MI') as eventtime,
  1385. e.description,s.event_type as eventtype,
  1386. s.event_code as eventcode, s.event_city as eventcity,
  1387. (select time_zone from public.city_timezone where uncode = s.event_code) as timezone,
  1388. s.event_city as uncity,
  1389. case when s.event_base ='I' then 'IFFREC'::text
  1390. when s.event_base ='AE' then 'IFFONB'::text
  1391. when s.event_base ='VD' then 'IFFDEP'::text
  1392. when s.event_base ='EB' or s.event_base ='VA' then 'IFFARR'::text
  1393. when s.event_base ='UV' then 'IFFUND'::text
  1394. when s.event_base ='VA' then 'IFFAFD'::text
  1395. when s.event_base ='AV' then 'IFFCTA'::text
  1396. when s.event_base ='CT' then 'IFFICC'::text
  1397. when s.event_base ='OA' or s.event_base ='D' then 'IFFPPD'::text
  1398. when s.event_base ='EE' then 'IFFECP'::text
  1399. else '' ::text
  1400. end as milestone_code
  1401. from public.ra_online_container_status_v s
  1402. left join ra_online_edi_event e on s.event_base = e.ra_name
  1403. where s.serial_no = '" . pg_escape_string($cd['serial_no']) . "'
  1404. and s.container_no = '" . pg_escape_string($cd['ctnr']) . "' and is_display = true
  1405. order by to_timestamp(s.event_date, 'YYYYMMDD') asc,
  1406. to_timestamp(s.event_time, 'HH24MI') asc,e.ra_order asc";
  1407. $ctnr_status = common::excuteListSql($ctnr_status_sql);
  1408. //记录所有的信息
  1409. $EDI315TimeAndLocation = array();
  1410. foreach($ctnr_status as $event){
  1411. if(!empty($EDI315TimeAndLocation['IFFARR']) && $EDI315TimeAndLocation['IFFARR']['code'] == "EB"){
  1412. //如果存在EB 的EB 的优先级最高
  1413. continue;
  1414. }
  1415. if(!empty($EDI315TimeAndLocation['IFFPPD']) && $EDI315TimeAndLocation['IFFARR']['code'] == "OA"){
  1416. //如果存在OA 的OA 的优先级最高
  1417. continue;
  1418. }
  1419. $EDI315TimeAndLocation[$event['milestone_code']] = array("code"=>$event['event'],"timezone"=>$event['timezone'],"location"=>$event['uncity']);
  1420. }
  1421. }
  1422. }else if ($ocean['transport_mode'] == "air"){
  1423. $EDI315TimeAndLocation = array();
  1424. }
  1425. //Milestones 数据信息待定
  1426. $Milestones = common::getMilestonesInfo($ocean,$ocean['transport_mode'],$order_from,$EDI315TimeAndLocation);
  1427. global $_COPYRIGHT;
  1428. $data = array('transportInfo' => $transportInfo,
  1429. 'basicInfo' => $basicInfo,
  1430. 'businessPartners' => $businessPartners,
  1431. 'packing' => $packing,
  1432. 'marksAndDescription' => $marksAndDescription,
  1433. 'Milestones' => $Milestones,
  1434. 'copyright' =>$_COPYRIGHT);
  1435. return array("msg" =>"success","data" =>$data);
  1436. }
  1437. private function trackingSql($serial_no,$order_from){
  1438. $_schemas = $order_from;
  1439. if($_schemas == 'public'){
  1440. $_schemas = "ocean";
  1441. }
  1442. $sql = "with o as(
  1443. SELECT oo.*,m_bol as _m_bol, h_bol as _h_bol,
  1444. (select time_zone from public.city_timezone where uncode = oo.fport_of_loading_un limit 1) as pol_timezone,
  1445. case when oo.transport_mode ='sea'
  1446. then (select uncity from $order_from.ports where uncode = oo.fport_of_loading_un limit 1)
  1447. else (select city from sfs.airport where coalesce(airport.country_abb,'')||airport.airport_code = oo.fport_of_loading_un limit 1)
  1448. end as pol_uncity,
  1449. (select time_zone from public.city_timezone where uncode = oo.mport_of_discharge_un limit 1) as mpod_timezone,
  1450. case when oo.transport_mode ='sea'
  1451. then (select uncity from $order_from.ports where uncode = oo.mport_of_discharge_un limit 1)
  1452. else (select city from sfs.airport where coalesce(airport.country_abb,'')||airport.airport_code = oo.mport_of_discharge_un limit 1)
  1453. end as mpod_uncity,
  1454. (select time_zone from public.city_timezone where uncode = oo.place_of_receipt_un limit 1) as por_timezone,
  1455. case when oo.transport_mode ='sea'
  1456. then (select uncity from $order_from.ports where uncode = oo.place_of_receipt_un limit 1)
  1457. else (select city from sfs.airport where coalesce(airport.country_abb,'')||airport.airport_code = oo.place_of_receipt_un limit 1)
  1458. end as por_uncity,
  1459. (select time_zone from public.city_timezone where uncode = oo.place_of_delivery_un limit 1) as pod_timezone,
  1460. case when oo.transport_mode ='sea'
  1461. then (select uncity from $order_from.ports where uncode = oo.place_of_delivery_un limit 1)
  1462. else (select city from sfs.airport where coalesce(airport.country_abb,'')||airport.airport_code = oo.place_of_delivery_un limit 1)
  1463. end as pod_uncity,
  1464. (select time_zone from public.city_timezone where uncode = oo.final_desination_uncode limit 1) as _fd_timezone,
  1465. case when oo.transport_mode ='sea'
  1466. then (select uncity from $order_from.ports where uncode = oo.final_desination_uncode limit 1)
  1467. else (select city from sfs.airport where coalesce(airport.country_abb,'')||airport.airport_code = oo.final_desination_uncode limit 1)
  1468. end as _pd_uncity,
  1469. CASE
  1470. WHEN ((m_iffbcf is not null or m_iffbcf is null) and m_iffcpu is null and m_iffrec is null and m_iffdep is null and m_iffarr is null and m_iffdel is null) THEN 'Created'::text
  1471. WHEN ((m_iffcpu is not null or m_iffrec is not null) and m_iffdep is null and m_iffarr is null and m_iffdel is null) THEN 'Cargo Received'::text
  1472. WHEN (m_iffdep is not null and m_iffarr is null and m_iffdel is null) THEN 'Departure'::text
  1473. WHEN (m_iffarr is not null and m_iffdel is null) THEN 'Arrived'::text
  1474. WHEN (m_iffdel is not null) THEN 'Completed'::text
  1475. ELSE 'Created'::text
  1476. END AS new_status
  1477. from public.kln_ocean oo where oo.serial_no = '" . $serial_no . "' and oo.order_from = '$order_from'
  1478. )
  1479. SELECT o.* ,sh.*, cn.*,aa.*,dd.*,fd.*
  1480. from o
  1481. LEFT JOIN LATERAL ( SELECT company as cn_company,
  1482. address_1 as cn_address_1,
  1483. address_2 as cn_address_2,
  1484. address_3 as cn_address_3,
  1485. address_4 as cn_address_4,
  1486. city as cn_city, state as cn_state, zipcode as cn_zipcode, country as cn_country,
  1487. phone_1 as cn_phone
  1488. FROM $_schemas.contacts c WHERE o.consignee_id::text = c.contact_id::text) cn ON true
  1489. LEFT JOIN LATERAL ( SELECT company as sh_company,
  1490. address_1 as sh_address_1,
  1491. address_2 as sh_address_2,
  1492. address_3 as sh_address_3,
  1493. address_4 as sh_address_4,
  1494. city as sh_city, state as sh_state, zipcode as sh_zipcode, country as sh_country,
  1495. phone_1 as sh_phone
  1496. FROM $_schemas.contacts c WHERE o.shipper_id::text = c.contact_id::text) sh ON true
  1497. LEFT JOIN LATERAL ( SELECT company as aa_company,
  1498. address_1 as aa_address_1,
  1499. address_2 as aa_address_2,
  1500. address_3 as aa_address_3,
  1501. address_4 as aa_address_4,
  1502. city as aa_city, state as aa_state, zipcode as aa_zipcode, country as aa_country,
  1503. phone_1 as aa_phone,
  1504. (select time_zone from public.city_timezone where uncode = LEFT(c.country, 2) || COALESCE(c.city_code,'') limit 1) as aa_timezone
  1505. FROM $_schemas.contacts c WHERE o.origin::text = c.contact_id::text) aa ON true
  1506. LEFT JOIN LATERAL ( SELECT company as dd_company,
  1507. address_1 as dd_address_1,
  1508. address_2 as dd_address_2,
  1509. address_3 as dd_address_3,
  1510. address_4 as dd_address_4,
  1511. city as dd_city, state as dd_state, zipcode as dd_zipcode, country as dd_country,
  1512. phone_1 as dd_phone,
  1513. (select time_zone from public.city_timezone where uncode = LEFT(c.country, 2) || COALESCE(c.city_code,'') limit 1) as dd_timezone
  1514. FROM $_schemas.contacts c WHERE o.agent::text = c.contact_id::text) dd ON true
  1515. LEFT JOIN LATERAL ( SELECT
  1516. city as fd_city,
  1517. (select time_zone from public.city_timezone where uncode = LEFT(c.country, 2) || COALESCE(c.city_code,'') limit 1) as fd_timezone
  1518. FROM $_schemas.contacts c WHERE o.final_desination::text = c.contact_id::text) fd ON true";
  1519. return $sql;
  1520. }
  1521. public function resetAndActivateUpdate(){
  1522. $verifcation_code = $_REQUEST['verifcation_code'];
  1523. $AES_encrypted = utils::AES_encrypted($verifcation_code,true,"USAIandy20244Q9X","0123456123456789");
  1524. //七天内有效
  1525. $secret_key = common::excuteOneSql("select secret_key from customer_service_secret_key
  1526. where secret_key = '$verifcation_code'
  1527. and create_time >= current_date - INTERVAL '7 days' limit 1");
  1528. if(!empty($AES_encrypted) && !empty($secret_key)){
  1529. //提交的时候再次验证通过,进行修改密码
  1530. $loginName = $AES_encrypted;
  1531. $password = $_REQUEST['password'];
  1532. $msg = $this->updateExpirePassword($loginName, $password);
  1533. if($msg == "success"){
  1534. //使用后,移除之前数据库里安全密
  1535. common::excuteUpdateSql("delete from customer_service_secret_key where secret_key = '$verifcation_code'");
  1536. $data = array(
  1537. 'msg' => "success",
  1538. 'data' => ''
  1539. );
  1540. common::echo_json_encode(200, $data);
  1541. exit();
  1542. } else {
  1543. $data = array(
  1544. 'msg' => $msg,
  1545. 'data' => ''
  1546. );
  1547. common::echo_json_encode(500, $data);
  1548. exit();
  1549. }
  1550. } else {
  1551. $msg = 'verifcation_Invalid';
  1552. if(empty($AES_encrypted)){
  1553. $msg="Invalid link. Please use the original link from your activation email.";
  1554. } else {
  1555. $secret_key_exist = common::excuteOneSql("select secret_key from customer_service_secret_key where secret_key = '$verifcation_code' limit 1");
  1556. if(!empty($secret_key_exist)){
  1557. $msg="Link expired (valid for 7 days). Use \"Forgot Password\" on the login page to reset and activate.";
  1558. } else {
  1559. $msg="Account already activated. Please log in with your existing password.";
  1560. }
  1561. }
  1562. $data = array(
  1563. 'msg' => $msg,
  1564. 'data' => ''
  1565. );
  1566. }
  1567. common::echo_json_encode(500, $data);
  1568. exit();
  1569. }
  1570. }
  1571. ?>