182 Commits

Author SHA1 Message Date
dillard 43504d92dc Fix stale GitHub repo URL on About page (pre-dates the repo rename) 2026-07-11 13:04:14 +02:00
dillard 402bda0fbf Fix nginx serving no static assets in production compose (ported from qr-vip)
Same bug as qr-vip (2026-07-11): nginx and php-fpm are separate
containers in docker-compose.prod.yml, but nginx had no copy of the
static assets it needs to serve directly, so they'd fall through
try_files to the login-gated index.php. Not currently visible on
qr.ensembia.com (which runs docker-compose.yml, the single-container dev
variant, not this prod file) but would hit anyone using the production
compose as documented. New Dockerfile.nginx copies in dist/, plugins/,
manifest.json, service-worker.js, and favicon.ico.
2026-07-11 12:16:13 +02:00
dillard b5bfd9a4d8 Rename internal Docker service/network/volume identifiers to qrforge-*
Cosmetic-only rename, no functional/data-layer change: service names
(php-dynamic-qrcode -> qrforge-app, php-dynamic-qrcode-db -> qrforge-db),
the network (php-dynamic-qrcode-network -> qrforge-network), and the two
named volumes (php_dynamic_qrcode_db_data -> qrforge_db_data,
php_dynamic_qrcode_saved_qrcode_data -> qrforge_qrcode_storage), plus
matching references in nginx.conf's fastcgi_pass and .env.example's
DATABASE_HOST default. Database name itself ('qrcode') intentionally
left unchanged per user request.

Volume rename requires an explicit data migration on already-deployed
hosts (a bare name change would otherwise attach a fresh empty volume) -
handled separately as part of this same deploy, not by this commit.
2026-07-11 12:02:12 +02:00
dillard def7b81a11 Fix IDOR: getQrcode/editQrcode/deleteQrcode had no ownership check
Found while auditing the owner-scope SQL fix from the last commit:
getQrcode() queried purely by id with no scope applied at all (not even
the buggy old form), and editQrcode()/deleteQrcode() both call
getQrcode() first but then run their own unscoped where('id', $id) for
the actual update/delete. Net effect: any authenticated admin/user with
edit or delete rights could view, edit, or delete *any other tenant's*
qr code just by guessing/incrementing the id - in the static/dynamic
edit forms, the bulk download/delete endpoint, and the single delete
flow alike.

Fixed by applying qr_apply_owner_scope() in getQrcode() (covers the
edit-prefill and delete-lookup paths, and exits via failure() before
reaching the actual write query if out of scope) and adding it directly
to the update/delete queries in editQrcode()/deleteQrcode() too, for
defense in depth rather than relying solely on the earlier check.
Verified with a two-tenant scenario (separate admin accounts): before
the fix admin B could view/edit-prefill/delete admin A's qr code, after
the fix all three are correctly blocked (404 / "not found" / delete is
silently a no-op) and admin A's code is untouched.

Users.php and presets.php were checked too and already scope correctly
via different, unaffected patterns - this was isolated to the two
Qrcode classes.
2026-07-11 11:40:06 +02:00
dillard 9645ce94e2 Fix stale qr-storage volume mount path in dev docker-compose.yml
Fase 1 hardening (2026-07-08) moved saved QR code storage from
src/saved_qrcode/ to /var/www/qrcode-storage/ (outside the webroot,
SAVED_QRCODE_DIRECTORY in config.php), but docker-compose.yml's volume
mount was never updated and still pointed at the old path
(/var/www/html/saved_qrcode). The named volume was therefore mounted
somewhere the app never wrote to - every actual qr code image the app
generates at /var/www/qrcode-storage/ lived only in the container's
ephemeral filesystem and was silently lost on every container
recreation, while the qrcode_storage volume itself stayed permanently
empty. DB rows (filenames/content) were never affected, only the
generated image files.

Confirmed as the cause of qr.ensembia.com's "old and new QR codes not
showing in the list" report: qrcode_image.php's is_file() check failed
because the file genuinely wasn't there anymore. docker-compose.prod.yml
already had the correct path - only the dev compose file (what
qr.ensembia.com actually runs) had this bug.
2026-07-11 09:47:13 +02:00
dillard 164872de4d Fix owner-scope query bug returning the wrong qr code by id
qr_apply_owner_scope() used where('id_owner', X) + orWhere('id_owner', NULL,
'IS'). Any caller that had already added its own where('id', $id) before
calling it (qrcode_image.php, bulk_action.php's download path) ended up
with "WHERE id = ? AND id_owner = ? OR id_owner IS NULL" - AND binds
tighter than OR in SQL, so this was actually "(id = ? AND id_owner = ?) OR
(id_owner IS NULL)", which silently detaches the id filter and returns an
arbitrary null-owner row instead (or nothing, if that row's file is
missing) whenever the intended row didn't have a null owner. This is what
broke qr code thumbnails/downloads on qr.ensembia.com for scoped (non-super)
accounts, old and newly-created codes alike - reproduced and confirmed
fixed with a local before/after query dump, then with a live HTTP request
scenario (two accounts, two codes, one null-owner).

Fixed by building the scope as a single parenthesized raw condition
instead of two separate where() calls, so it can't be split apart by
whatever the caller already added to the query.

Also this session, per user feedback on the OSS rebrand review:
- Format moved back next to Filename in both qr-creation forms (was
  separated from it when Filename got grouped with Owner last session).
- README/About now mention the temporary admin/admin demo account instead
  of the not-yet-built self-registration flow.
2026-07-11 09:39:18 +02:00
Dillard Blom ad5a5df81e Update LICENSE 2026-07-11 04:37:49 +02:00
dillard 23e8d9b765 Rebrand to QRForge (local only - do not push before domain confirmed)
Applies the approved QRForge brand kit throughout the app:
- New logo/icon SVGs, favicon set (ico/svg/png), apple-touch-icon, all
  copied from the approved brand kit into src/dist/img/brand/. Old
  Symbol_WhiteBlue.png/DynamicQRCode_Original.png removed (unused after
  the swap).
- Sidebar brand image/text, login and change-password page logos, all
  <title> tags, manifest.json name/theme-color, and the PWA icons
  (dist/img/icon-192.png/icon-512.png, same filenames so no other
  reference needed to change) updated to QRForge branding and the
  #2563EB brand blue.
- New about.php page (+ sidebar link): credits the original upstream
  fork (Giandonato Inverso) and chillerlan/php-qrcode, links to the free
  qr.ensembia.com try-out, the commercial www.qrforge.eu product page,
  and this GitHub repo for self-hosters.
- Footer now reads "QRForge" + "About / credits" + "Version 3.0"
  (replaces the inherited "PHP Qrcode Generator by Giandonato Inverso" /
  "Version 2.3.0" line - full credit moved to the About page instead).
- README.md rewritten: current feature set (all 16 static qr types,
  presets, scanner, PWA, location search, roles), qr.ensembia.com as the
  free try-out, www.qrforge.eu as the commercial product page, corrected
  Docker Compose setup steps (.env is required now, the old README still
  described the single-file demo setup from the original upstream fork).

IMPORTANT: not pushed to origin/gitea. Per user instruction, no push
until qrforge.eu domain registration is confirmed.
2026-07-11 02:48:05 +02:00
dillard a8f55506c8 Fase 3 feedback round 4: group filename with owner in the qr forms
Filename now sits in the same row as Owner instead of the crowded
top row shared with format/frame text/frame font/frame font size/icon.
Freeing that column lets those fields shift left and use the space
better. Applied to both the shared static-form partial
(qrcode_options.php) and the dynamic-form's separate copy of the same
fields (form_dynamic_add.php) - the two have diverged since Fase 3 and
don't share markup. Edit forms (form_static_edit.php/form_dynamic_edit.php)
already had filename/owner side by side, no change needed there.
2026-07-11 02:40:22 +02:00
dillard 89bf472867 Fase 3 feedback round 3: sidebar icons, thumbnail preview, location search
- Sidebar submenu bullets (List all/Add new/Batch create) swapped from
  far fa-circle to fas fa-angle-right - the outlined circle read as an
  unchecked radio button, per feedback.
- List-page qr thumbnails now sit in a fixed 100x100 box with
  object-fit:contain instead of width/height attrs, so taller images
  (e.g. icon-above-qr) no longer get squashed into a square. Thumbnails
  are now clickable, opening a shared Bootstrap modal with the full-size
  image (same data-toggle/data-target pattern already used for the
  delete-confirmation modal).
- Location QR form gets an address search box backed by OpenStreetMap
  Nominatim (dist/js/location-search.js): free-text query, pick a result,
  it fills in latitude/longitude. No API key needed; the browser talks to
  nominatim.openstreetmap.org directly, called out in the field's help
  text since queries leave the self-hosted server.
2026-07-11 02:18:34 +02:00
dillard 7276744f32 Fase 3 feedback round 2: live color preview, bigger top icon, dashboard links
- Style preview now updates immediately when picking a color via the
  colorpicker widget. It sets the input value through jQuery's synthetic
  trigger(), which a native addEventListener('change', ...) never sees -
  bound the listener through jQuery instead so both native and
  colorpicker-driven changes refresh the preview.
- Icon-above-QR max height raised from 25% to 62.5% of QR height (~2.5x
  bigger per feedback); the existing 60%-width cap now becomes the
  practical limit for most icons. Verified generated QR still decodes.
- Dashboard's "Dynamic Qr codes" and "Static QR codes" info-boxes now link
  to their list pages. "Total qr codes"/"Total Scans" left as-is - no
  combined-list or scan-report page exists yet to link them to.
- Random-style button now has a "Randomize" label to match its row-mates
  (Load preset/Save as preset/Style preview), instead of an empty spacer.
2026-07-11 02:09:58 +02:00
dillard 23daf9c236 Fase 3 feedback round: style preview, icon upload, font choice, optional bitcoin amount, WPA3
- Default the Owner select to the creator's own account instead of "All", so
  superadmin-created codes no longer silently become visible to every admin
  (the underlying NULL-fallback sharing behavior for an explicit "All" choice
  is unchanged).
- Add a live color/precision/size preview swatch next to the preset picker.
- Let the frame text use a chosen DejaVu font + font size instead of a fixed
  GD bitmap font.
- Add an optional self-uploaded icon rendered above the qr code (not embedded
  in it, so scanability is unaffected).
- Make the Bitcoin qr amount optional; a standing wallet address is useful
  without forcing a one-off amount per code.
- Add a WPA3 option to the WiFi qr encryption select.
- Fix a real bug surfaced while testing the preview/style JS: qrcode_options.php
  was included once per static qr type (16 times on one page) and each
  inclusion re-executed <script src="qrcode-style-tools.js">, so every button
  click fired once per type - e.g. saving one preset wrote 16 duplicate rows,
  and every tab except the first ("Text") had dead random-style/preset
  buttons since only the first DOM match ever got a listener. Moved the
  script include to load once per page and rewrote the JS to scope every
  lookup to the triggering element's own tab-pane/form instead of relying on
  getElementById's first-match behavior.
2026-07-09 23:11:36 +02:00
dillard c3c6f167e0 Fase 3 priority 2: presets, random style, qr scanner, PWA
Preset system: qr_presets table (migration 005) plus a presets.php AJAX
endpoint (list/save/delete, CSRF-protected, scoped to the logged-in user's
own id - presets are personal, never shared across accounts). UI/JS lives in
dist/js/qrcode-style-tools.js.

Random style button: client-side only, fills foreground/background with a
random hex color pair (playful randomize, no contrast/scannability
guarantee).

Qr scanner (scan_qrcode.php): camera or image upload, decoded entirely
client-side via html5-qrcode (CDN, pinned to 2.3.8).

PWA: manifest.json + service-worker.js, icons generated from the existing
DynamicQRCode_Original.png glyph. The service worker only caches static
assets (css/js/images) and deliberately never touches PHP pages, since those
carry CSRF tokens and session-specific content that must never be cached.

Fixes a gap found while testing: qrcode_options.php is only a shared partial
for the static qr forms - the dynamic qr form (form_dynamic_add.php) has its
own separate copy of the foreground/background/level/size/filename/format
fields (pre-existing structure, not something introduced here). That meant
frame_text and the new preset/random-style UI never showed up on the
dynamic qr page. Added the same fields there too, verified with a dynamic qr
plus frame text (150x180px, the expected +30px padding).
2026-07-09 00:49:45 +02:00
dillard 4e9fed755c Fase 3 v1: new qr types, svg export, clipboard, frame text, batch CSV
New static qr types:
- App Link: Android intent:// links (with package + optional browser
  fallback) or a generic custom-scheme URI. iOS Universal Links need no
  special encoding (they're just plain https:// URLs).
- Bluetooth: device name + MAC address. Purely informational, since unlike
  WIFI:/vCard there's no OS-native "scan to pair" convention.

SVG export: already worked (format whitelist/dropdown existed since Fase 1),
verified rather than reimplemented.

Copy-to-clipboard button next to the download button on both qr list tables,
using the Clipboard API against a fetched blob.

Optional frame text label rendered below the qr code via GD after
generation (raster formats only, no-op for svg/eps).

Batch CSV upload (batch_qrcode.php): filename,link rows create dynamic qr
codes with sane defaults, downloadable as a zip. Required refactoring
Qrcode-intchil.php's generation path (previously always redirected/exited
via failure()/success(), which can't run in a loop) into a private
renderAndStore() that throws instead, shared by addQrcode() and the new
addQrcodeBatch(). Qrcode.php's addQrcodeBatch() is a separate, deliberately
duplicated implementation instead, since its generation logic is small
enough that duplication carries less risk than refactoring the working
external-API code path.
2026-07-09 00:03:01 +02:00
dillard 6387d24846 Admin-scoped user accounts, secure qr code storage, PHP 8.4 upgrade
Admin-scoped users (answers: who can create a 'user' account, only super or
also an admin within their own scope?):
- New owner_admin_id column on users (migration 004). NULL means created by
  super (company-wide, previous behavior); otherwise scoped to that admin's
  own codes.
- Users::addUser/editUser/deleteUser now allow an 'admin' session, but force
  type='user' and owner_admin_id to their own id regardless of submitted
  input. user.php/users.php open up to admins with a restricted UI (no type
  picker, listing limited to their own created users).
- New qr_compute_scope_owner_id()/qr_apply_owner_scope()/qr_has_full_visibility()
  helpers in includes/security.php, replacing the ad-hoc type==='admin' checks
  in index.php, dynamic_qrcodes.php, static_qrcodes.php and bulk_action.php.
  A 'user' account created by an admin is now scoped to that admin's codes
  instead of seeing everything company-wide.

Qr code storage hardening: images were served as plain static files under the
document root with no auth check at all. Storage now lives outside the web
root; qrcode_image.php and qrcode_zip_download.php gate access with the same
permission model as the list pages, and the bulk zip download is bound to the
session that generated it.

PHP 8.4 + chillerlan/php-qrcode 6.0.1: bumped since this is a dockerized app,
so the PHP version shipped doesn't matter to end users. Note: the 6.0.1 tag
itself only requires PHP 8.2 - the earlier "needs 8.4" read was from an
unpinned clone of master, which has since moved past the tag. Fixed along the
way, surfaced by testing on 8.4:
- The hardcoded Imagick build (an old pinned master commit, workaround for
  3.7.0 being broken on PHP 8.3+) no longer compiles on 8.4. Imagick 3.8.1 is
  now a normal stable release, so the workaround is gone.
- config.php had display_errors=On + error_reporting(E_ALL), so PHP 8.4's new
  deprecation notices got dumped straight into the response before
  session_start() could run, breaking login outright. Also an info-disclosure
  risk on its own. Now logged instead of displayed.
- MysqliDb::insertMulti() had an implicit nullable parameter, now explicit.
- includes/auth_validate.php redirected unauthenticated requests but never
  called exit(), so the rest of the script kept running.
- Dockerfile.fpm was missing both git (needed to clone chillerlan/php-qrcode)
  and the imagick extension entirely.

Also removes the unused sample qr code images that shipped in the original
repo; storage now lives outside the document root so they were never going
to be served again.
2026-07-08 20:38:58 +02:00
dillard 52c9f65c61 Fase 2: read-only user role with per-category view toggles
Adds a third account type 'user' alongside super/admin: no create/edit/delete
rights on qr codes, view access to dynamic/static lists gated per-account by
two admin-controlled toggles (can_view_static, can_view_dynamic), and always
full visibility into the dashboard/reports regardless of those toggles.

- New columns can_view_static/can_view_dynamic on users (migrations/003)
- Users class + form_users.php: 'user' type option with the two toggles
- Access control: dynamic_qrcode.php/static_qrcode.php/bulk_action.php reject
  all mutations for type=user; dynamic_qrcodes.php/static_qrcodes.php enforce
  the view toggle and show all codes (no owner scoping, since 'user' owns none)
- Sidebar and list tables hide add/edit/delete/bulk UI for the read-only role
- index.php dashboard stats are unscoped for both 'super' and 'user'
2026-07-08 16:37:25 +02:00
dillard 3afe3b7698 Security hardening: CSRF, rate limiting, session/password policy, audit log
Fixes critical pre-existing issues found during review: bulk_action.php had no
auth check at all (unauthenticated download/delete of any qrcode) and built a
table name from unwhitelisted user input (SQL injection); the QR generator
classes wrote files from unvalidated filename/format, allowing path traversal
and arbitrary file writes. Also pins chillerlan/php-qrcode to 5.0.5 since
master now requires PHP 8.4, breaking the PHP 8.3 build.

- CSRF tokens on all POST forms and the bulk_action.php JSON endpoint
- Login rate limiting (5 attempts / 15 min) via new login_attempts table
- Hardened sessions: httponly/samesite cookies, 30 min idle timeout,
  session regeneration on login
- Forced password change for the default superadmin/superadmin account
- Server-side validation in Users/DynamicQrcode/Qrcode classes
- Audit log table for auth, user, and qrcode actions
- Checked-in db schema (db/init.sql, migrations/) instead of relying on an
  opaque prebuilt db image
- Production docker-compose with Nginx + php-fpm instead of the PHP dev server
2026-07-08 15:00:33 +02:00
Giandonato Inverso 8db3158239 Remove unnecessary extra information from documentation 2025-09-02 21:56:03 +02:00
Giandonato Inverso b3b799819e Delete support section from index.html 2025-09-02 21:53:41 +02:00
Giandonato Inverso f89b39bde3 Remove donation button from README 2025-09-02 21:52:03 +02:00
Giandonato Inverso acb154502b Merge pull request #144 from CLAlberto/master
fix(read.php): replace deprecated FILTER_SANITIZE_STRING for PHP 8.3 …
2025-05-08 08:56:07 +02:00
CLAlberto f24a7086ab fix(read.php): replace deprecated FILTER_SANITIZE_STRING for PHP 8.3 compatibility
### Problem

The usage of `FILTER_SANITIZE_STRING` in `read.php` causes a deprecation warning in PHP 8.1 and breaks functionality entirely in PHP 8.3, as the constant was removed.

### Solution

This commit replaces:
```php
filter_input(INPUT_GET, 'id', FILTER_SANITIZE_STRING);



with a safer and future-proof alternative:

$id = filter_input(INPUT_GET, 'id', FILTER_UNSAFE_RAW);
$id = trim(strip_tags($id));


> _Thanks for maintaining this project! Happy to contribute._ 😊
2025-05-06 16:16:22 +02:00
Giandonato Inverso 2f0c879158 Merge pull request #143 from angelosleebos/patch-1
Make environment variables compatible for other platforms
2025-04-14 12:19:34 +02:00
Giandonato Inverso 2ce6a03921 Merge pull request #142 from rafinou62/patch-1
Update read.php prevent SQL Injection & XSS attacks
2025-04-14 12:18:32 +02:00
Angelo Sleebos 40ec07fbb1 Make environment variables compatible for other platforms
Make environment variables compatible for other platforms
2025-04-07 01:11:17 +02:00
Raphaël Wanecque 6cfbc4a759 Update read.php prevent SQL Injection & XSS attacks 2025-03-26 17:04:33 +01:00
giandonato.inverso@edempg.it 3ee79bfab7 edit demo url 2025-03-22 15:51:02 +01:00
giandonato.inverso@edempg.it a2fdf79491 config rollback 2025-03-20 23:38:55 +01:00
giandonato.inverso@edempg.it 236d7342d3 Merge remote-tracking branch 'origin/master' 2025-03-19 23:40:50 +01:00
giandonato.inverso@edempg.it 1f3110b26e bug fix Class Qrcode not found 2025-03-19 23:40:36 +01:00
Giandonato Inverso 8b24fd839d Merge pull request #136 from MickGe/patch-1
add cookies secure flags
2025-02-09 16:16:53 +01:00
MickGe 011e91e3d0 add cookies secure flags 2025-02-07 11:35:24 +01:00
giandonato.inverso@edempg.it 737ceca97b updated readme and docs 2025-01-21 22:41:14 +01:00
giandonato.inverso@edempg.it b4b42ddb29 updated readme 2025-01-12 23:50:15 +01:00
giandonato.inverso@edempg.it 3ca4163715 Local setup eliminated and documentation updated 2025-01-12 23:48:49 +01:00
giandonato.inverso@edempg.it c5f1b0d74f Merge remote-tracking branch 'origin/master' 2025-01-12 19:48:31 +01:00
Giandonato Inverso d825f597b8 Merge pull request #130 from Shineson1001/feature/129-QRCodeGeneratorSwitch
🐛 Global switch for the QR code generator (#129)
2025-01-02 12:04:55 +01:00
Shine 850f5e5c52 🐛 Global switch for the QR code generator (#129) 2024-12-31 20:48:56 +01:00
giandonato.inverso@edempg.it c46dae55ce Revert "Revert "Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode""
This reverts commit 4d33cf5379.
2024-12-23 18:52:11 +01:00
giandonato.inverso@edempg.it 4d33cf5379 Revert "Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode"
This reverts commit 6d42677732.
2024-12-23 18:49:05 +01:00
Giandonato Inverso a1bd583ad3 Merge pull request #128 from Shineson1001/feature/116-EventIncorrectTimeZone
🐛 Event: Incorrect Time Zone
2024-12-20 20:02:32 +01:00
Shine 597afbb1fe 🐛 Event: Incorrect Time Zone
- Add "Time zone" input field.
- 24-Hour time format.
- Set Min-Year and Max-Year dynamically
2024-12-19 22:34:42 +01:00
Giandonato Inverso 5028541bfd Merge pull request #127 from Shineson1001/feature/88-SelfHostedQRCodeGenerator
Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode
2024-12-15 16:35:29 +01:00
Shine 6d42677732 Instead using external API (api.qrserver.com) .. use chillerlan/php-qrcode 2024-12-15 14:36:39 +01:00
Giandonato Inverso 1499f06c71 Merge pull request #126 from Shineson1001/feature/2FA-QRCodes
Add 2FA QR Code
2024-12-14 09:17:50 +01:00
Shine 058277c0fc Add 2FA QR Code
Save your 2FA secrets to QR-Code.
2024-12-13 23:42:57 +01:00
Giandonato Inverso a426d45be1 available plugins 2024-10-20 16:32:58 +02:00
Giandonato Inverso 3f7ac0bce1 Update README.md 2024-10-20 11:07:12 +02:00
giandonato.inverso@edempg.it 9548a6d73a bug fix in helpers.php 2024-04-21 12:55:03 +02:00
giandonato.inverso@edempg.it 2715f2106c edit readme 2024-04-21 12:38:35 +02:00
giandonato.inverso@edempg.it e43e8f774e bug fix 2024-04-18 20:54:04 +02:00
giandonato.inverso@edempg.it acebfdd708 fix in bulk action 2024-04-18 20:44:22 +02:00
giandonato.inverso@edempg.it 005c67d721 readme 2024-04-18 20:35:04 +02:00
giandonato.inverso@edempg.it 9f2d14abf8 bug fix in read.php, bump version in footer, NEW: bulk delete 2024-04-18 20:33:20 +02:00
giandonato.inverso@edempg.it eba0ebbba7 bug fix database prefix in Qrcode class 2024-03-11 15:43:16 +01:00
giandonato.inverso@edempg.it 068ddebd35 bug fix bulk download 2024-03-04 14:36:18 +01:00
Giandonato Inverso d0d3daf7db Merge pull request #94 from tranmh/xss_static_qrcode
Fix Security: Stored Cross Site Scripting for static QR code
2024-03-01 09:58:29 +01:00
Minh Cuong Tran 92eb66fb35 Fix Security: Stored Cross Site Scripting for static QR code, see https://github.com/giandonatoinverso/PHP-Dynamic-Qr-code/issues/93 2024-03-01 08:03:31 +01:00
Giandonato Inverso b85f98e16d Merge pull request #92 from tranmh/fix_remove_DATABASE_PREFIX_for_getOne
Inconsistency of using DATABASE_PREFIX with getOne()
2024-02-29 00:25:17 +01:00
Minh Cuong Tran a7953f05bb Inconsistency of using DATABASE_PREFIX with getOne() 2024-02-28 16:56:39 +01:00
Giandonato Inverso 06ddd19378 Merge pull request #91 from tranmh/mixed_content_blocked
fix: mixed content blocked for http and https
2024-02-28 14:16:21 +01:00
Minh Cuong Tran 2b6c802659 fix mixed content blocked for http and https: Mixed Content: The page at 'https://localhost/qrcode/dynamic_qrcodes.php' was loaded over HTTPS, but requested an insecure stylesheet 'http://code.ionicframework.com/ionicons/2.0.1/css/ionicons.min.css'. This request has been blocked; the content must be served over HTTPS. 2024-02-28 13:55:44 +01:00
Giandonato Inverso 33651fcabb Merge pull request #90 from tranmh/fix_case_sensitive_filename
Fix case sensitive filename
2024-02-27 13:25:17 +01:00
Minh Cuong Tran b496e51ace fix: case sensitive for filename 2024-02-27 13:18:52 +01:00
Minh Cuong Tran 1217e32856 fix: case sensitive for filename 2024-02-27 13:18:01 +01:00
Giandonato Inverso 6646cc9545 increased size of column link - dynamic qrcode
increased size of column link - dynamic qrcode
2024-02-14 23:58:00 +01:00
Giandonato Inverso 915ea383b7 Update README.md
updated php version requirement
2024-01-03 00:43:50 +01:00
Giandonato Inverso 93980efdb7 Update README.md 2023-10-30 17:02:13 +01:00
Giandonato Inverso b52a61ca40 bug fix redirect url with docker installation 2023-10-17 23:24:34 +02:00
Giandonato Inverso c9fa6abf06 bug fix 2023-10-17 00:41:15 +02:00
Giandonato Inverso 15c84c0863 bug fix and documentation 2023-10-16 22:57:16 +02:00
Giandonato Inverso 90a7b2890b updated documentation 2023-10-16 22:24:15 +02:00
Giandonato Inverso 03da2d0432 updated documentation 2023-10-16 20:56:06 +02:00
Giandonato Inverso 68a2b9f7f3 Refactoring docker image building, NEW: added docker compose support
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 19:49:29 +02:00
Giandonato Inverso 5335b6fb7e readme updated
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 13:15:53 +02:00
giandonato.inverso@edempg.it fadde16882 readme updated
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 13:15:07 +02:00
Giandonato Inverso 575a6b3caa refactoring of table database, added script for upgrading to versions >= 2.0, added multi-user support
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 13:10:57 +02:00
Giandonato Inverso cdab7df35d readme updated
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 01:43:56 +02:00
Giandonato Inverso 9a0a2c7928 eliminazione file superflui, spostamento file read.php all'interno del progetto, aggiunta astrazione classe Qrcode, miglioramento download bulk, refactoring generale
Signed-off-by: giandonato.inverso@edempg.it <giandonato.inverso@studenti.unimi.it>
2023-10-16 01:41:27 +02:00
Giandonato Inverso 995272fa8d Bug fix login.php
removed .min extension adminlte js file
2023-09-16 14:51:04 +02:00
Giandonato Inverso ef6410253c paypal donations 2023-09-05 23:31:38 +02:00
Giandonato Inverso f9ad48f65a Update README.md 2023-09-05 23:29:51 +02:00
giandonato.inverso@edempg.it 4b28c09d49 Merge remote-tracking branch 'origin/master' 2023-08-22 17:15:09 +02:00
giandonato.inverso@edempg.it d14ec02e4e doc update
Signed-off-by: giandonato.inverso@edempg.it <Zannabianca20>
2023-08-22 17:14:52 +02:00
Giandonato Inverso c87a99a067 Update Dockerfile 2023-01-25 18:51:10 +01:00
Giandonato Inverso eb3c275035 Merge pull request #52 from AyhamAl-Ali/fix/db_prefix
🚀 Fix DB Prefix in `read.php`
2023-01-25 18:50:15 +01:00
Ayham Al-Ali e448066176 Fix DB Prefix 2023-01-25 20:47:52 +03:00
Giandonato Inverso abd55062f3 Merge pull request #45 from chilluniverse/patch-1
DATABASE_HOST
2022-10-14 10:36:59 +02:00
Pascal e99e97cae2 DATABASE_HOST
In the docker-compose.yml is the Database_Host defined as "mariadb". If Host is not changed in the environment.php to "mariadb" as well the setup will fail
2022-10-14 01:26:06 +02:00
giandonato.inverso@edempg.it 6d1c3ac7c4 new version dockerfile 2022-09-28 16:23:44 +02:00
giandonato.inverso@edempg.it e2d9aad91f new version dockerfile 2022-09-28 16:22:18 +02:00
Giandonato Inverso fa709c95db Merge pull request #37 from 0xRenegade/feature/download-multiple-qr-img-at-once
Error Message for no qrcodes selected.
2022-09-24 22:43:16 +02:00
0xRenegade 8cb8e36114 Error Message for no qrcodes selected. 2022-09-24 15:40:56 -05:00
Giandonato Inverso c3225c6f3f Merge pull request #36 from 0xRenegade/feature/download-multiple-qr-img-at-once
Feature/download multiple qr img at once
2022-09-24 22:26:36 +02:00
0xRenegade 9cf354910b download multiple qrcodes at once feature 2022-09-24 15:14:20 -05:00
0xRenegade a18657994e add base_url() function in helpers, works with https and port number 2022-09-24 14:32:04 -05:00
0xRenegade 4b5c9a800b adds in custom.css for, well, custom styles. 2022-09-24 13:09:17 -05:00
Giandonato Inverso a85cee4fda Merge pull request #35 from 0xRenegade/issue-30/update-docker-yml-for-db-prefix
Issue 30/update docker yml for db prefix
2022-09-24 19:44:31 +02:00
Giandonato Inverso 327cadaddb Merge pull request #33 from 0xRenegade/QOL/ignore-env-and-use-example-instead
QOL/ignore env and use example instead
2022-09-24 19:44:23 +02:00
0xRenegade 4da9be3e3e update docker-compose.yml for database prefix option 2022-09-24 12:19:40 -05:00
0xRenegade b26c905b2e update docs for this change 2022-09-24 11:52:34 -05:00
0xRenegade f458094e0d update main gitignore to add in environment.php 2022-09-24 11:44:02 -05:00
0xRenegade b16f30b5a3 move env to example, so we don't run into merge conflicts constantly 2022-09-24 11:42:17 -05:00
0xRenegade f072f151fd Merge pull request #1 from giandonatoinverso/master
sync master branch with remote
2022-09-24 11:28:55 -05:00
Giandonato Inverso 38ddbe43c7 Merge pull request #31 from 0xRenegade/renegade/general-fixes
general fixes, fixed database prefix during install
2022-09-24 11:53:34 +02:00
0xRenegade 9799509ff6 set static attribute of class rather than non-DRY code 2022-09-24 00:24:03 -05:00
0xRenegade f0d43fd18b remove error_log debugging 2022-09-24 00:05:50 -05:00
0xRenegade 5e531f4e15 updated MysqliDb class functions to handle prefix properly. 2022-09-23 23:44:01 -05:00
0xRenegade a0944afd3c if this feature is accepted in Pull Request, will need to add this back 2022-09-23 23:02:05 -05:00
0xRenegade 9b61284a1e Merge branch 'renegade/general-fixes' of github.com:0xRenegade/PHP-Dynamic-Qr-code into renegade/general-fixes 2022-09-23 23:01:05 -05:00
0xRenegade 70ec7afc90 some queries are manually entered, which aren't picked up by 'prefix' class attribute in database class 2022-09-23 22:59:53 -05:00
0xRenegade 1934c78251 Merge branch 'master' into renegade/general-fixes 2022-09-23 21:05:16 -05:00
0xRenegade 8f053474e7 added in prefix by default, oops. 2022-09-23 21:00:41 -05:00
0xRenegade b80636049f Issue #30: Fixes database_prefix option during install 2022-09-23 20:55:55 -05:00
Giandonato Inverso a8e4cf18ff Update config.php 2022-09-24 03:24:15 +02:00
Giandonato Inverso 418215cd23 Update docker-compose.yml 2022-09-24 03:23:41 +02:00
Giandonato Inverso 8bbb4354c0 Update environment.php 2022-09-24 03:23:20 +02:00
0xRenegade 2057df1924 missing scroll bar on documentation page sidebar 2022-09-23 20:09:22 -05:00
Giandonato Inverso b457823654 Update add_dynamic_form.php
added support for http url
2022-09-10 11:50:19 +02:00
Giandonato Inverso 02754fba37 Update MysqliDb.php
fix deprecated implode()
2022-09-05 20:40:26 +02:00
Giandonato Inverso 25add5b7fd Merge pull request #25 from nirpt/master
docker build now supports app release version code.
2022-08-29 14:09:34 +02:00
nirpt 2aa867aa2a Docker build with app version added. 2022-08-29 12:32:20 +02:00
nirpt 9cbf68a99e Merge remote-tracking branch 'origin/master'
# Conflicts:
#	docker/README.md
2022-08-28 13:22:12 +02:00
Giandonato Inverso dfaee77d86 Update README.md 2022-08-28 12:33:14 +02:00
Giandonato Inverso 59c6dc9233 doc update
Signed-off-by: giandonato.inverso@edempg.it <Zannabianca20>
2022-08-28 12:04:48 +02:00
Giandonato Inverso c3e04a4357 new installation process via script, elimination of data entry form for installation
Signed-off-by: giandonato.inverso@edempg.it <Zannabianca20>
2022-08-28 11:57:31 +02:00
nirpt 97da7f0d4f Minor refactor and cleanup 2022-08-28 11:29:20 +02:00
Giandonato Inverso 4dd7f9ab25 configuration file modification, docker environment variable support 2022-08-28 11:24:32 +02:00
Giandonato Inverso 3000271d95 Merge pull request #23 from nirpt/master
docker support added
2022-08-28 10:47:05 +02:00
nirpt 1194259e6e docker support added 2022-08-28 10:24:07 +02:00
Giandonato Inverso 5f1534f0be Update README.md 2022-06-17 11:49:06 +02:00
Giandonato Inverso c76c1164fc Update README.md 2022-06-17 11:48:44 +02:00
Giandonato Inverso c8b3bba9f0 Merge pull request #16 from neoteknic/patch-1
Fix php 8.1 warning in form field
2022-02-22 16:55:19 +01:00
neoteknic 10091ac8e4 Update filters.php
Fix php 8.1 warning in form field
2022-02-22 16:22:13 +01:00
Giandonato Inverso a6bf0d6ca9 Add files via upload 2020-09-08 18:43:51 +02:00
Giandonato Inverso 44e8465129 Add files via upload 2020-09-08 18:42:29 +02:00
Giandonato Inverso cd00141252 Add files via upload 2020-09-08 18:41:51 +02:00
Giandonato Inverso 0ca8bd7cb2 Add files via upload 2020-09-08 18:30:32 +02:00
Giandonato Inverso 554a27762d Add files via upload 2020-09-08 18:28:26 +02:00
Giandonato Inverso 36c52ba003 Add files via upload 2020-09-08 18:22:57 +02:00
Giandonato Inverso 773d4960fd Add files via upload 2020-09-08 18:20:38 +02:00
Giandonato Inverso 7757bcf76b Add files via upload 2020-09-08 18:17:08 +02:00
Giandonato Inverso 76883de681 Add files via upload 2020-09-08 18:15:54 +02:00
Giandonato Inverso 8d45a02149 Add files via upload 2020-09-08 18:13:36 +02:00
Giandonato Inverso d3e11399f7 Add files via upload 2020-09-08 18:11:37 +02:00
Giandonato Inverso 86f32b6327 Add files via upload 2020-09-08 18:09:19 +02:00
Giandonato Inverso 97df13f3f0 Add files via upload 2020-09-08 18:06:28 +02:00
Giandonato Inverso 4ac9cd811a Add files via upload 2020-09-08 17:59:49 +02:00
Giandonato Inverso 1968201a48 Add files via upload 2020-09-08 17:59:21 +02:00
Giandonato Inverso b39c88fc12 Update README.md 2020-09-08 17:31:01 +02:00
Giandonato Inverso 9118d4f33c Update README.md 2020-09-08 17:29:26 +02:00
Giandonato Inverso f8bc49c164 Update README.md 2020-09-08 17:26:41 +02:00
Giandonato Inverso 9db2388d51 Update README.md 2020-09-08 17:25:38 +02:00
Giandonato Inverso 03c9c2d720 Update README.md 2020-09-08 17:24:07 +02:00
Giandonato Inverso 3bb2545521 Update README.md 2020-09-08 17:23:38 +02:00
Giandonato Inverso 283df4b81c Update README.md 2020-09-08 17:23:17 +02:00
Giandonato Inverso e64ca74003 Update README.md 2020-09-08 17:23:02 +02:00
Giandonato Inverso 0c2988791f Update README.md 2020-09-08 17:22:41 +02:00
Giandonato Inverso e123385dac Update README.md 2020-09-08 17:22:25 +02:00
Giandonato Inverso 1c819e6626 Update README.md 2020-09-08 17:21:33 +02:00
Giandonato Inverso 8af83452ba Update README.md 2020-09-08 17:21:07 +02:00
Giandonato Inverso 527eb7b3ba Update README.md 2020-09-08 17:20:39 +02:00
Giandonato Inverso fe4c63e3a6 Update README.md 2020-09-08 17:20:20 +02:00
Giandonato Inverso 601be05d5c Update README.md 2020-09-08 17:20:05 +02:00
Giandonato Inverso f4f061d857 Update README.md 2020-09-08 17:18:41 +02:00
Giandonato Inverso f1eb8545b4 Update README.md 2020-09-08 17:17:36 +02:00
Giandonato Inverso 7e3cef7544 Update README.md 2020-09-08 17:14:57 +02:00
Giandonato Inverso 5530f62195 Update README.md 2020-09-08 17:13:33 +02:00
Giandonato Inverso df3211d583 Update README.md 2020-09-08 17:13:06 +02:00
Giandonato Inverso 117b2b21a2 Update README.md 2020-09-08 17:12:50 +02:00
Giandonato Inverso 5430504fa0 Update README.md 2020-09-08 17:12:34 +02:00
Giandonato Inverso 65c279b65d Update README.md 2020-09-08 17:12:01 +02:00
Giandonato Inverso ceda04f97e Update README.md 2020-09-08 17:11:45 +02:00
Giandonato Inverso 76cad846f9 Update README.md 2020-09-08 17:11:27 +02:00
Giandonato Inverso f0d187f8b7 Update README.md 2020-09-08 17:10:01 +02:00
Giandonato Inverso fefac0fa9f Update README.md 2020-09-08 17:09:36 +02:00
Giandonato Inverso 6f920aec63 Update README.md 2020-09-08 17:09:15 +02:00
Giandonato Inverso ab7a82edbf Update README.md 2020-09-08 17:08:42 +02:00
Giandonato Inverso 7e867ddf9d Update README.md 2020-09-08 17:07:06 +02:00
Giandonato Inverso 255201169f Update README.md 2020-09-08 17:06:25 +02:00
Giandonato Inverso ca0108c247 Update README.md 2020-09-08 17:05:43 +02:00
Giandonato Inverso 23864047ce Initial commit 2020-09-08 16:56:05 +02:00
11 changed files with 15 additions and 39 deletions
-1
View File
@@ -75,7 +75,6 @@ RUN cd /opt \
&& rm /opt/composer-setup.php /opt/composer-setup.sha384sum && rm /opt/composer-setup.php /opt/composer-setup.sha384sum
RUN docker-php-source extract RUN docker-php-source extract
RUN docker-php-ext-configure gd --with-freetype --with-jpeg
RUN docker-php-ext-install pdo_mysql zip exif pcntl gd RUN docker-php-ext-install pdo_mysql zip exif pcntl gd
RUN docker-php-ext-install mysqli && docker-php-ext-enable mysqli RUN docker-php-ext-install mysqli && docker-php-ext-enable mysqli
RUN docker-php-ext-install gettext && docker-php-ext-enable gettext RUN docker-php-ext-install gettext && docker-php-ext-enable gettext
+3 -7
View File
@@ -10,11 +10,8 @@ project by Giandonato Inverso, built on [AdminLTE](https://adminlte.io/).
- **Try it free:** [qr.ensembia.com](https://qr.ensembia.com) - fully functional OSS test - **Try it free:** [qr.ensembia.com](https://qr.ensembia.com) - fully functional OSS test
instance. Self-service signup isn't live yet, so log in with the temporary shared demo instance. Self-service signup isn't live yet, so log in with the temporary shared demo
account `admin` / `admin` in the meantime. account `admin` / `admin` in the meantime.
- **Commercial VIP edition:** the ability to give sub-users the ability to create - **Commercial VIP edition** (self-service create-rights, logo-embedded QR codes):
QR codes as well, from their own (sub)account. If you have a bigger organisation, [www.qrforge.eu](https://www.qrforge.eu).
having more users being able to create new QR codes delegates your workload. To
fund our open-source project, a small fee (€49/year subscription per organisation
("tenant")) is requested for this. [www.qrforge.eu](https://www.qrforge.eu).
- **Self-host it yourself:** this repository, MIT-licensed. - **Self-host it yourself:** this repository, MIT-licensed.
# Features # Features
@@ -34,8 +31,7 @@ project by Giandonato Inverso, built on [AdminLTE](https://adminlte.io/).
- Installable as a PWA - Installable as a PWA
- Role-based access: `super` (full access + user management), `admin` - Role-based access: `super` (full access + user management), `admin`
(scoped to their own codes and sub-users), `user` (read-only, with (scoped to their own codes and sub-users), `user` (read-only, with
optional view toggles set by an admin; per-account create rights are optional per-account create rights and view toggles set by an admin)
a VIP-edition feature, not available in this OSS version)
- Dashboard with QR/scan statistics and a 7-day activity chart - Dashboard with QR/scan statistics and a 7-day activity chart
- CSRF protection, login rate limiting, session hardening, audit log - CSRF protection, login rate limiting, session hardening, audit log
- Docker Compose setup, both a dev image and a production Nginx + PHP-FPM image - Docker Compose setup, both a dev image and a production Nginx + PHP-FPM image
+1 -1
View File
@@ -11,7 +11,7 @@ server {
add_header Referrer-Policy "same-origin" always; add_header Referrer-Policy "same-origin" always;
location / { location / {
try_files $uri /index.php$is_args$args; try_files $uri $uri/ /index.php$is_args$args;
} }
location ~ \.php$ { location ~ \.php$ {
BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.9 KiB

After

Width:  |  Height:  |  Size: 2.8 KiB

BIN
View File
Binary file not shown.

Before

Width:  |  Height:  |  Size: 7.9 KiB

After

Width:  |  Height:  |  Size: 7.4 KiB

+3 -7
View File
@@ -26,29 +26,25 @@
</div> </div>
<?php if ($_SESSION['type'] === 'super'): ?> <?php if ($_SESSION['type'] === 'super'): ?>
<?php $editing_self = $edit && (int) $user['id'] === (int) $_SESSION['user_id']; ?>
<div class="col-sm-4"> <div class="col-sm-4">
<label for="user-type">User type *</label> <label for="user-type">User type *</label>
<div class="form-group"> <div class="form-group">
<div class="radio"> <div class="radio">
<label class="radio"> <label class="radio">
<input type="radio" name="type" value="super" required="required" <?php echo ($edit && $user['type'] =='super') ? "checked": "" ; ?> <?php echo $editing_self ? "disabled" : ""; ?>/> Super admin</label> <input type="radio" name="type" value="super" required="required" <?php echo ($edit && $user['type'] =='super') ? "checked": "" ; ?>/> Super admin</label>
</div> </div>
<div class="radio"> <div class="radio">
<label class="radio"> <label class="radio">
<input type="radio" name="type" value="admin" required="required" <?php echo ($edit && $user['type'] =='admin') ? "checked": "" ; ?> <?php echo $editing_self ? "disabled" : ""; ?>/> Admin</label> <input type="radio" name="type" value="admin" required="required" <?php echo ($edit && $user['type'] =='admin') ? "checked": "" ; ?>/> Admin</label>
</div> </div>
<div class="radio"> <div class="radio">
<label class="radio"> <label class="radio">
<input type="radio" name="type" value="user" required="required" id="type-user" <?php echo ($edit && $user['type'] =='user') ? "checked": "" ; ?> <?php echo $editing_self ? "disabled" : ""; ?>/> User (read-only)</label> <input type="radio" name="type" value="user" required="required" id="type-user" <?php echo ($edit && $user['type'] =='user') ? "checked": "" ; ?>/> User (read-only)</label>
</div> </div>
</div> </div>
<?php if ($editing_self): ?>
<small class="form-text text-muted">You can't change your own access level.</small>
<?php endif; ?>
</div> </div>
<div class="col-sm-12 mt-2" id="user-view-toggles"> <div class="col-sm-12 mt-2" id="user-view-toggles">
+1 -8
View File
@@ -138,14 +138,7 @@
<input type="text" name="state" value="" placeholder="" class="form-control"> <input type="text" name="state" value="" placeholder="" class="form-control">
</div> </div>
</div> </div>
<div class="col-6 col-md-3">
<div class="form-group">
<label>Country</label>
<input type="text" name="country" value="" placeholder="" class="form-control">
</div>
</div>
</div> </div>
</div> </div>
+3 -3
View File
@@ -171,7 +171,7 @@ class StaticQrcode {
* create a qr code of type "vcard" * create a qr code of type "vcard"
* *
*/ */
public function vcardQrcode($fullname, $nickname, $email, $website, $phone, $home_phone, $work_phone, $company, $role, $categories, $note, $photo, $address, $city, $postcode, $state, $country) public function vcardQrcode($fullname, $nickname, $email, $website, $phone, $home_phone, $work_phone, $company, $role, $categories, $note, $photo, $address, $city, $postcode, $state)
{ {
if($fullname != NULL && $phone != NULL){ if($fullname != NULL && $phone != NULL){
@@ -188,7 +188,7 @@ class StaticQrcode {
$vcard->categories($categories); $vcard->categories($categories);
$vcard->note($note); $vcard->note($note);
$vcard->photo($photo); $vcard->photo($photo);
$vcard->address($address, $city, $state, $postcode, $country); $vcard->address($address, $city, $postcode, $state);
$vcard->create(); $vcard->create();
$this->sData = $vcard->get(); $this->sData = $vcard->get();
@@ -202,7 +202,7 @@ class StaticQrcode {
$this->sContent .= '<div class="col-sm-4">'; $this->sContent .= '<div class="col-sm-4">';
$this->sContent .= '<strong>Phone:</strong> '.$phone.'<br>'.'<strong>Home Phone:</strong> '.$home_phone.'<br>'.'<strong>Work phone:</strong> '.$work_phone.'<br>'.'<strong>Address:</strong> '.$address.'&nbsp;'.$city.'&nbsp;'.$postcode.'&nbsp;'.$state.'&nbsp;'.$country.'</div>'; $this->sContent .= '<strong>Phone:</strong> '.$phone.'<br>'.'<strong>Home Phone:</strong> '.$home_phone.'<br>'.'<strong>Work phone:</strong> '.$work_phone.'<br>'.'<strong>Address:</strong> '.$address.'&nbsp;'.$city.'&nbsp;'.$postcode.'&nbsp;'.$state.'</div>';
$this->sContent .= '</div>'; $this->sContent .= '</div>';
+1 -8
View File
@@ -160,14 +160,7 @@ class Users
'edit' => "true", 'edit' => "true",
)); ));
$is_self_edit = (int) $input_data['id'] === (int) $_SESSION['user_id']; $requested_type = $_SESSION['type'] === 'admin' ? 'user' : ($input_data['type'] ?? '');
// A user editing their own account keeps their current type, even if a
// different value was submitted - prevents accidentally (or deliberately)
// locking yourself out by downgrading your own access level.
$requested_type = $_SESSION['type'] === 'admin'
? 'user'
: ($is_self_edit ? $target['type'] : ($input_data['type'] ?? ''));
$validation_error = $this->validateUsernameAndType($input_data['username'] ?? '', $requested_type); $validation_error = $this->validateUsernameAndType($input_data['username'] ?? '', $requested_type);
if ($validation_error !== null) { if ($validation_error !== null) {
+2 -3
View File
@@ -43,11 +43,10 @@ class vCard
* *
* @return self * @return self
*/ */
public function address($sAddress, $sCity, $sState, $sPostcode, $sCountry) public function address($sAddress, $sCity, $sPostcode, $sState)
{ {
// Component order per vCard 4.0 ADR: pobox;ext;street;locality;region;code;country
$this->sData .= 'ADR:;;'.$sAddress.';'; $this->sData .= 'ADR:;;'.$sAddress.';';
$this->sData .= $sCity.';'.$sState.';'.$sPostcode.';'.$sCountry."\n"; $this->sData .= $sCity.';'.$sPostcode.';'.$sState."\n";
return $this; return $this;
} }
+1 -1
View File
@@ -65,7 +65,7 @@ if($_SERVER["REQUEST_METHOD"] === "POST" && !isset($_POST["edit"]) && !isset($_P
case 'location': $static_qrcode_instance->locationQrcode($_POST['latitude'], $_POST['longitude']); case 'location': $static_qrcode_instance->locationQrcode($_POST['latitude'], $_POST['longitude']);
break; break;
case 'vcard': $static_qrcode_instance->vcardQrcode($_POST['full_name'], $_POST['nickname'], $_POST['email'], $_POST['website'], $_POST['phone'], $_POST['home_phone'], $_POST['work_phone'], $_POST['company'], $_POST['role'], $_POST['categories'], $_POST['note'], $_POST['photo'], $_POST['address'], $_POST['city'], $_POST['post_code'], $_POST['state'], $_POST['country']); case 'vcard': $static_qrcode_instance->vcardQrcode($_POST['full_name'], $_POST['nickname'], $_POST['email'], $_POST['website'], $_POST['phone'], $_POST['home_phone'], $_POST['work_phone'], $_POST['company'], $_POST['role'], $_POST['categories'], $_POST['note'], $_POST['photo'], $_POST['address'], $_POST['city'], $_POST['post_code'], $_POST['state']);
break; break;
case 'event': $static_qrcode_instance->eventQrcode($_POST['title'], $_POST['start'], $_POST['end'], $_POST['timezone'], $_POST['location'], $_POST['description'], $_POST['url']); case 'event': $static_qrcode_instance->eventQrcode($_POST['title'], $_POST['start'], $_POST['end'], $_POST['timezone'], $_POST['location'], $_POST['description'], $_POST['url']);