Add openid security
[contractdashboard.git] / lib / common.inc.php
blob:a/lib/common.inc.php -> blob:b/lib/common.inc.php
<?php <?php
date_default_timezone_set("Australia/ACT"); date_default_timezone_set("Australia/ACT");
   
error_reporting(E_ALL ^ E_NOTICE); error_reporting(E_ALL ^ E_NOTICE);
   
   
$conn = new PDO("pgsql:dbname=contractDashboard;user=postgres;password=snmc;host=localhost"); $conn = new PDO("pgsql:dbname=contractDashboard;user=postgres;password=snmc;host=localhost");
   
if (!$conn) { if (!$conn) {
die("A database error occurred.\n"); die("A database error occurred.\n");
} }
   
define('ROOT' , pathinfo(__FILE__, PATHINFO_DIRNAME)); define('ROOT', pathinfo(__FILE__, PATHINFO_DIRNAME));
if (strstr($_SERVER['PHP_SELF'], "labs/")) { if (strstr($_SERVER['PHP_SELF'], "labs/") || strstr($_SERVER['PHP_SELF'], "admin/") || strstr($_SERVER['PHP_SELF'], "heuristics/")) {
$basePath = "../"; $basePath = "../";
} }
  require ROOT . DIRECTORY_SEPARATOR . '..' . DIRECTORY_SEPARATOR . 'lib' . DIRECTORY_SEPARATOR . 'openid.php';
require ROOT . DIRECTORY_SEPARATOR.'..'.DIRECTORY_SEPARATOR.'lib'.DIRECTORY_SEPARATOR.'openid.php'; $openid = new LightOpenID($_SERVER['HTTP_HOST']);
$openid = new LightOpenID($_SERVER['HTTP_HOST']); // you have to open the session to be able to modify or remove it
  session_start();
function login() { function login() {
global $openid; global $openid;
if (!$openid->mode) { if (!$openid->mode) {
$openid->required = array('contact/email'); $openid->required = array('contact/email');
$openid->identity = 'https://www.google.com/accounts/o8/id'; $openid->identity = 'https://www.google.com/accounts/o8/id';
header('Location: ' . $openid->authUrl()); header('Location: ' . $openid->authUrl());
} }
} }
   
function auth() { function auth() {
global $openid; global $openid;
if ($_SESSION['authed'] == true) { if ($_SESSION['authed'] == true) {
return true; return true;
} }
   
if ($openid->mode) { if ($openid->mode) {
$attr = $openid->getAttributes(); $attr = $openid->getAttributes();
if ($attr['contact/email'] != 'maxious@gmail.com') { if ($attr['contact/email'] != 'maxious@gmail.com') {
die('Access Denied'); die('Access Denied');
} else { } else {
$_SESSION['authed'] = true; $_SESSION['authed'] = true;
} }
} else { } else {
login(); login();
} }
} }
   
// $conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // $conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
function databaseError($errMsg) { function databaseError($errMsg) {
if ($errMsg[2] != "") { if ($errMsg[2] != "") {
echo '<div class="alert-message error">'; echo '<div class="alert-message error">';
die(print_r($errMsg, true)); if ($_SERVER['HTTP_HOST'] != "localhost") Amon::log(print_r($errMsg, true).print_r($_REQUEST, true).print_r($_SERVER, true), array('error'));
echo "</div>"; die(print_r($errMsg, true));
} echo "</div>";
} }
  }
function ucsmart($str) {  
$shortWords = Array("The", "Pty", "Ltd", "Inc", "Red", "Oil", "A", "An", "And", "At", "For", "In" function ucsmart($str) {
, "Of", "On", "Or", "The", "To", "With"); $shortWords = Array("The", "Pty", "Ltd", "Inc", "Red", "Oil", "A", "An", "And", "At", "For", "In"
$strArray = explode(" ", preg_replace("/(?<=(?<!:|’s)\W) , "Of", "On", "Or", "The", "To", "With");
(A|An|And|At|For|In|Of|On|Or|The|To|With) $strArray = explode(" ", preg_replace("/(?<=(?<!:|’s)\W)
(?=\W)/e", 'strtolower("$1")', ucwords(strtolower($str)))); (A|An|And|At|For|In|Of|On|Or|The|To|With)
foreach ($strArray as &$word) { (?=\W)/e", 'strtolower("$1")', ucwords(strtolower($str))));
if (strlen($word) <= 4 && !in_array($word, $shortWords)) foreach ($strArray as &$word) {
$word = strtoupper($word); if (strlen($word) <= 4 && !in_array($word, $shortWords))
} $word = strtoupper($word);
return implode(" ", $strArray); }
} return implode(" ", $strArray);
  }
function percent($num_amount, $num_total) {  
$count1 = $num_amount / $num_total; function percent($num_amount, $num_total) {
$count2 = $count1 * 100; $count1 = $num_amount / $num_total;
$count = number_format($count2, 2); $count2 = $count1 * 100;
return $count; $count = number_format($count2, 2);
} return $count;
  }
function array_sum_all($a) {  
if (!is_array($a)) function array_sum_all($a) {
return $a; if (!is_array($a))
foreach ($a as $key => $value) return $a;
$totale += array_sum_all($value); foreach ($a as $key => $value)
return $totale; $totale += array_sum_all($value);
} return $totale;
  }
// magic query modifiers  
$agency = filter_var($_REQUEST['agency'], FILTER_SANITIZE_STRING); // magic query modifiers
if ($agency != "") $agency = filter_var($_REQUEST['agency'], FILTER_SANITIZE_STRING);
$agencyQ = "agencyName = '" . $agency . "' AND "; if ($agency != "")
  $agencyQ = "agencyName = '" . $agency . "' AND ";
$supplier = filter_var($_REQUEST['supplier'], FILTER_SANITIZE_STRING);  
if ($supplier != "") { $supplier = filter_var($_REQUEST['supplier'], FILTER_SANITIZE_STRING);
$supplierParts = explode("-", $supplier); if ($supplier != "") {
$supplierName = "%" . $supplierParts[1] . "%"; $supplierParts = explode("-", $supplier);
$supplierABN = $supplierParts[0]; $supplierName = "%" . $supplierParts[1] . "%";
if ($supplierParts[0] > 0) $supplierABN = $supplierParts[0];
$supplierQ = ' "supplierABN" = :supplierABN AND '; if ($supplierParts[0] > 0)
else $supplierQ = ' "supplierABN" = :supplierABN AND ';
$supplierQ = ' "supplierName" LIKE :supplierName AND '; else
} $supplierQ = ' "supplierName" LIKE :supplierName AND ';
  }
$startYear = 2007;  
$year = filter_var($_REQUEST['year'], FILTER_SANITIZE_NUMBER_INT); $startYear = 2007;
if ($year != "") $year = filter_var($_REQUEST['year'], FILTER_SANITIZE_NUMBER_INT);
$yearQ = "YEAR(publishDate) = " . $year . " AND "; if ($year != "") {
  $yearQ = "YEAR(publishDate) = " . $year . " AND ";
$standardQ = ' "childCN" is null '; // AND YEAR(contractStart) >= 2007 AND YEAR(contractStart) <= 2010'; }
$start = 0.0; $standardQ = ' "childCN" is null '; // AND YEAR(contractStart) >= 2007 AND YEAR(contractStart) <= 2010';
  $start = 0.0;
function include_header($title) {  
global $start; function local_url() {
?> return "http://" . $_SERVER['HTTP_HOST'] . rtrim(dirname($_SERVER['PHP_SELF']), '/\\') . "/";
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" }
"http://www.w3.org/TR/html4/strict.dtd">  
<html> function include_header($title) {
<head> global $start;
<title>Contract Dashboard - <?php echo $title; ?></title> ?>
<link rel="stylesheet" type="text/css" href="bootstrap.min.css"> <!DOCTYPE html>
<!-- Le HTML5 shim, for IE6-8 support of HTML elements --> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" version="XHTML+RDFa 1.1"
<!--[if lt IE 9]> xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
<script src="http://html5shim.googlecode.com/svn/trunk/html5.js"></script> xmlns:rdfs="http://www.w3.org/2000/01/rdf-schema#"
<![endif]--> xmlns:gr="http://purl.org/goodrelations/v1#"
<script type="text/javascript" src="lib/bsn.AutoSuggest_2.1.3_comp.js" charset="utf-8"></script> xmlns:dc="http://purl.org/dc/terms/"
<link rel="stylesheet" href="autosuggest_inquisitor.css" type="text/css" media="screen" charset="utf-8" /> xmlns:pc="http://purl.org/procurement#"
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.6.4/jquery.min.js"></script> xmlns:unspsc="http://www.ksl.stanford.edu/projects/DAML/UNSPSC.daml#"
<script type="text/javascript"> xmlns:xsd="http://www.w3.org/2001/XMLSchema#"
$(document).ready(function() xmlns:pcdt="http://purl.org/procurement/public-contracts-datatypes#"
{ prefix="rdf: http://www.w3.org/1999/02/22-rdf-syntax-ns#
//hide the all of the element with class msg_body rdfs: http://www.w3.org/2000/01/rdf-schema#
$(".msg_body").hide(); gr: http://purl.org/goodrelations/v1#
//toggle the componenet with class msg_body dcterms: http://purl.org/dc/terms/
$(".msg_head").click(function() pc: http://purl.org/procurement/public-contracts#
{ cpv: http://purl.org/weso/pscs/cpv/2008/resource/
$(this).next(".msg_body").slideToggle(600); unspsc: http://www.ksl.stanford.edu/projects/DAML/UNSPSC.daml#
}); v: http://www.w3.org/2006/vcard/ns#
}); payment: http://reference.data.gov.uk/def/payment#
</script> br: http://purl.org/business-register#
  xsd: http://www.w3.org/2001/XMLSchema#
<style type="text/css" title="currentStyle"> pcdt: http://purl.org/procurement/public-contracts-datatypes#">
@import "media/css/demo_table.css"; <head>
</style> <title><?php echo $title; ?> - Contract Dashboard</title>
<script type="text/javascript" language="javascript" src="media/js/jquery.dataTables.js"></script> <link rel="stylesheet" type="text/css" href="bootstrap.min.css">
<script type="text/javascript" language="javascript" src="lib/bootstrap-dropdown.js"></script> <link rel="stylesheet" type="text/css" href="bootstrap-responsive.css">
<script type="text/javascript" charset="utf-8"> <!-- Le HTML5 shim, for IE6-8 support of HTML elements -->
jQuery.fn.dataTableExt.aTypes.unshift( <!--[if lt IE 9]>
function ( sData ) <script src="http://html5shim.googlecode.com/svn/trunk/html5.js"></script>
{ <![endif]-->
var sValidChars = "0123456789.-,"; <script type="text/javascript" src="lib/bsn.AutoSuggest_2.1.3_comp.js" charset="utf-8"></script>
var Char; <link rel="stylesheet" href="autosuggest_inquisitor.css" type="text/css" media="screen" charset="utf-8" />
  <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.6.4/jquery.min.js"></script>
/* Check the numeric part */ <script type="text/javascript">
for ( i=1 ; i<sData.length ; i++ ) $(document).ready(function()
{ {
Char = sData.charAt(i); //hide the all of the element with class msg_body
if (sValidChars.indexOf(Char) == -1) $(".msg_body").hide();
{ //toggle the componenet with class msg_body
return null; $(".msg_head").click(function()
} {
} $(this).next(".msg_body").slideToggle(600);
  });
/* Check prefixed by currency */ });
if ( sData.charAt(0) == '$' || sData.charAt(0) == '£' ) </script>
{  
return 'currency'; <style type="text/css" title="currentStyle">
} @import "media/css/demo_table.css";
return null; </style>
} <script type="text/javascript" language="javascript" src="media/js/jquery.dataTables.js"></script>
); <script type="text/javascript" language="javascript" src="lib/bootstrap-dropdown.js"></script>
jQuery.fn.dataTableExt.oSort['currency-asc'] = function(a,b) { <script type="text/javascript" charset="utf-8">
/* Remove any commas (assumes that if present all strings will have a fixed number of d.p) */ jQuery.fn.dataTableExt.aTypes.unshift(
var x = a == "-" ? 0 : a.replace( /,/g, "" ); function ( sData )
var y = b == "-" ? 0 : b.replace( /,/g, "" ); {
  var sValidChars = "0123456789.-,";
/* Remove the currency sign */ var Char;
x = x.substring( 1 );  
y = y.substring( 1 ); /* Check the numeric part */
  for ( i=1 ; i<sData.length ; i++ )
/* Parse and return */ {
x = parseFloat( x ); Char = sData.charAt(i);
y = parseFloat( y ); if (sValidChars.indexOf(Char) == -1)
return x - y; {
}; return null;
  }
jQuery.fn.dataTableExt.oSort['currency-desc'] = function(a,b) { }
/* Remove any commas (assumes that if present all strings will have a fixed number of d.p) */  
var x = a == "-" ? 0 : a.replace( /,/g, "" ); /* Check prefixed by currency */
var y = b == "-" ? 0 : b.replace( /,/g, "" ); if ( sData.charAt(0) == '$' || sData.charAt(0) == '£' )
  {
/* Remove the currency sign */ return 'currency';
x = x.substring( 1 ); }
y = y.substring( 1 ); return null;
  }
/* Parse and return */ );
x = parseFloat( x ); jQuery.fn.dataTableExt.oSort['currency-asc'] = function(a,b) {
y = parseFloat( y ); /* Remove any commas (assumes that if present all strings will have a fixed number of d.p) */
return y - x; var x = a == "-" ? 0 : a.replace( /,/g, "" );
}; var y = b == "-" ? 0 : b.replace( /,/g, "" );
$(document).ready(function() {  
$('table').dataTable(); /* Remove the currency sign */
} ); x = x.substring( 1 );
</script> y = y.substring( 1 );
<link type="text/css" rel="stylesheet" href="style.css">  
</head> /* Parse and return */
<body> x = parseFloat( x );
<div class="topbar"> y = parseFloat( y );
<div class="topbar-inner"> return x - y;
<div class="container-fluid"> };
<a class="brand" href="#">contract dashboard</a>  
<ul class="nav"> jQuery.fn.dataTableExt.oSort['currency-desc'] = function(a,b) {
<li><a href="displayAgency.php">agencies</a></li> /* Remove any commas (assumes that if present all strings will have a fixed number of d.p) */
<li><a href="displaySupplier.php">suppliers</a></li> var x = a == "-" ? 0 : a.replace( /,/g, "" );
<li><a href="displayCategory.php">categories</a></li> var y = b == "-" ? 0 : b.replace( /,/g, "" );
<li><a href="displayCalendar.php">time periods</a></li>  
<!-- <li class="dropdown"> /* Remove the currency sign */
<a href="#" class="dropdown-toggle">metrics</a> x = x.substring( 1 );
<ul class="dropdown-menu">--> y = y.substring( 1 );
<li><a href="displayProcurementMethod.php">tenderm</a></li>  
<li><a href="displayConfidentialities.php">confidentiality</a></li> /* Parse and return */
<li><a href="displayConsultancies.php">consultancies</a></li> x = parseFloat( x );
<li><a href="displayAmendments.php">amendments</a></li> y = parseFloat( y );
<li><a href="displayMap.php">geo</a></li> return y - x;
<!-- </ul> };
</li>--> $(document).ready(function() {
</ul> $('table').dataTable();
  } );
  </script>
<form method="post" action="search.php" class="pull-right"> <link type="text/css" rel="stylesheet" href="style.css">
<input type="text" id="searchKeyword" name="searchKeyword" value="" placeholder="Search" /> </head>
<input type="hidden" id="searchID" name="searchID" value=""/> <body>
</form> <div class="navbar">
  <div class="navbar-inner">
</div> <div class="container-fluid">
</div><!-- /topbar-inner --> <a class="brand" href="#">contract dashboard</a>
</div><!-- /topbar --> <ul class="nav">
</div><!-- /topbar-wrapper --> <li><a href="displayAgency.php">agencies</a></li>
<script type="text/javascript"> <li><a href="displaySupplier.php">suppliers</a></li>
  <li><a href="displayCategory.php">categories</a></li>
var options_xml = { <li><a href="displayCalendar.php">time periods</a></li>
script: function (input) { return "search_autosuggest.php?input="+input; }, <!-- <li class="dropdown">
varname:"input", <a href="#" class="dropdown-toggle">metrics</a>
callback: function (obj) { document.getElementById('searchID').value = obj.id; } <ul class="dropdown-menu">-->
}; <li><a href="displayProcurementMethod.php">tenderm</a></li>
var as_xml = new bsn.AutoSuggest('searchKeyword', options_xml); <li><a href="displayConfidentialities.php">confidentiality</a></li>
</script> <li><a href="displayConsultancies.php">consultancies</a></li>
<div class="container-fluid"> <li><a href="displayAmendments.php">amendments</a></li>
<div class="sidebar"> <li><a href="displayMap.php">geo</a></li>
<div class="well"> </ul>
Filter by:<li>  
<li>year  
<li><li>2008</li> <form method="post" action="search.php" class="pull-right">
</li> <input type="text" id="searchKeyword" name="searchKeyword" value="" placeholder="Search" />
</li> <input type="hidden" id="searchID" name="searchID" value=""/>
</li> <br> </form>
</div> </div>  
<div class="content"> </div>
<?php </div><!-- /topbar-inner -->
$start = (float) array_sum(explode(' ', microtime())); </div><!-- /topbar -->
} </div><!-- /topbar-wrapper -->
  <script type="text/javascript">
function include_footer() {  
global $start; var options_xml = {
$end = (float) array_sum(explode(' ', microtime())); script: function (input) { return "search_autosuggest.php?input="+input; },
  varname:"input",
echo ' <footer>' . "Processing time: " . sprintf("%.4f", ($end - $start)) . " seconds" . ' <footer>'; callback: function (obj) { document.getElementById('searchID').value = obj.id; }
echo '</div> </div></body> </html>'; };
} var as_xml = new bsn.AutoSuggest('searchKeyword', options_xml);
  </script>
include ("graphs.inc.php"); <div class="container-fluid">
?> <div class="row-fluid">
  <div class="span3">
  <div class="well sidebar-nav">
  <li class="nav-header">Filter by:</li>
  <li>2008</li>
  </div>
  </div>
  <div class="span9">
  <?php
  $start = (float) array_sum(explode(' ', microtime()));
  }