server_privileges.js 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478
  1. /* vim: set expandtab sw=4 ts=4 sts=4: */
  2. /**
  3. * @fileoverview functions used in server privilege pages
  4. * @name Server Privileges
  5. *
  6. * @requires jQuery
  7. * @requires jQueryUI
  8. * @requires js/functions.js
  9. *
  10. */
  11. /**
  12. * Validates the "add a user" form
  13. *
  14. * @return boolean whether the form is validated or not
  15. */
  16. function checkAddUser (the_form) {
  17. if (the_form.elements.pred_hostname.value === 'userdefined' && the_form.elements.hostname.value === '') {
  18. alert(PMA_messages.strHostEmpty);
  19. the_form.elements.hostname.focus();
  20. return false;
  21. }
  22. if (the_form.elements.pred_username.value === 'userdefined' && the_form.elements.username.value === '') {
  23. alert(PMA_messages.strUserEmpty);
  24. the_form.elements.username.focus();
  25. return false;
  26. }
  27. return PMA_checkPassword($(the_form));
  28. } // end of the 'checkAddUser()' function
  29. function checkPasswordStrength (value, meter_obj, meter_object_label, username) {
  30. // List of words we don't want to appear in the password
  31. customDict = [
  32. 'phpmyadmin',
  33. 'mariadb',
  34. 'mysql',
  35. 'php',
  36. 'my',
  37. 'admin',
  38. ];
  39. if (username !== null) {
  40. customDict.push(username);
  41. }
  42. var zxcvbn_obj = zxcvbn(value, customDict);
  43. var strength = zxcvbn_obj.score;
  44. strength = parseInt(strength);
  45. meter_obj.val(strength);
  46. switch (strength) {
  47. case 0: meter_obj_label.html(PMA_messages.strExtrWeak);
  48. break;
  49. case 1: meter_obj_label.html(PMA_messages.strVeryWeak);
  50. break;
  51. case 2: meter_obj_label.html(PMA_messages.strWeak);
  52. break;
  53. case 3: meter_obj_label.html(PMA_messages.strGood);
  54. break;
  55. case 4: meter_obj_label.html(PMA_messages.strStrong);
  56. }
  57. }
  58. /**
  59. * AJAX scripts for server_privileges page.
  60. *
  61. * Actions ajaxified here:
  62. * Add user
  63. * Revoke a user
  64. * Edit privileges
  65. * Export privileges
  66. * Paginate table of users
  67. * Flush privileges
  68. *
  69. * @memberOf jQuery
  70. * @name document.ready
  71. */
  72. /**
  73. * Unbind all event handlers before tearing down a page
  74. */
  75. AJAX.registerTeardown('server_privileges.js', function () {
  76. $('#fieldset_add_user_login').off('change', 'input[name=\'username\']');
  77. $(document).off('click', '#fieldset_delete_user_footer #buttonGo.ajax');
  78. $(document).off('click', 'a.edit_user_group_anchor.ajax');
  79. $(document).off('click', 'button.mult_submit[value=export]');
  80. $(document).off('click', 'a.export_user_anchor.ajax');
  81. $(document).off('click', '#initials_table a.ajax');
  82. $('#checkbox_drop_users_db').off('click');
  83. $(document).off('click', '.checkall_box');
  84. $(document).off('change', '#checkbox_SSL_priv');
  85. $(document).off('change', 'input[name="ssl_type"]');
  86. $(document).off('change', '#select_authentication_plugin');
  87. });
  88. AJAX.registerOnload('server_privileges.js', function () {
  89. /**
  90. * Display a warning if there is already a user by the name entered as the username.
  91. */
  92. $('#fieldset_add_user_login').on('change', 'input[name=\'username\']', function () {
  93. var username = $(this).val();
  94. var $warning = $('#user_exists_warning');
  95. if ($('#select_pred_username').val() === 'userdefined' && username !== '') {
  96. var href = $('form[name=\'usersForm\']').attr('action');
  97. var params = {
  98. 'ajax_request' : true,
  99. 'server' : PMA_commonParams.get('server'),
  100. 'validate_username' : true,
  101. 'username' : username
  102. };
  103. $.get(href, params, function (data) {
  104. if (data.user_exists) {
  105. $warning.show();
  106. } else {
  107. $warning.hide();
  108. }
  109. });
  110. } else {
  111. $warning.hide();
  112. }
  113. });
  114. /**
  115. * Indicating password strength
  116. */
  117. $('#text_pma_pw').on('keyup', function () {
  118. meter_obj = $('#password_strength_meter');
  119. meter_obj_label = $('#password_strength');
  120. username = $('input[name="username"]');
  121. username = username.val();
  122. checkPasswordStrength($(this).val(), meter_obj, meter_obj_label, username);
  123. });
  124. $('#text_pma_change_pw').on('keyup', function () {
  125. meter_obj = $('#change_password_strength_meter');
  126. meter_obj_label = $('#change_password_strength');
  127. checkPasswordStrength($(this).val(), meter_obj, meter_obj_label, PMA_commonParams.get('user'));
  128. });
  129. /**
  130. * Display a notice if sha256_password is selected
  131. */
  132. $(document).on('change', '#select_authentication_plugin', function () {
  133. var selected_plugin = $(this).val();
  134. if (selected_plugin === 'sha256_password') {
  135. $('#ssl_reqd_warning').show();
  136. } else {
  137. $('#ssl_reqd_warning').hide();
  138. }
  139. });
  140. /**
  141. * AJAX handler for 'Revoke User'
  142. *
  143. * @see PMA_ajaxShowMessage()
  144. * @memberOf jQuery
  145. * @name revoke_user_click
  146. */
  147. $(document).on('click', '#fieldset_delete_user_footer #buttonGo.ajax', function (event) {
  148. event.preventDefault();
  149. var $thisButton = $(this);
  150. var $form = $('#usersForm');
  151. $thisButton.PMA_confirm(PMA_messages.strDropUserWarning, $form.attr('action'), function (url) {
  152. var $drop_users_db_checkbox = $('#checkbox_drop_users_db');
  153. if ($drop_users_db_checkbox.is(':checked')) {
  154. var is_confirmed = confirm(PMA_messages.strDropDatabaseStrongWarning + '\n' + PMA_sprintf(PMA_messages.strDoYouReally, 'DROP DATABASE'));
  155. if (! is_confirmed) {
  156. // Uncheck the drop users database checkbox
  157. $drop_users_db_checkbox.prop('checked', false);
  158. }
  159. }
  160. PMA_ajaxShowMessage(PMA_messages.strRemovingSelectedUsers);
  161. var argsep = PMA_commonParams.get('arg_separator');
  162. $.post(url, $form.serialize() + argsep + 'delete=' + $thisButton.val() + argsep + 'ajax_request=true', function (data) {
  163. if (typeof data !== 'undefined' && data.success === true) {
  164. PMA_ajaxShowMessage(data.message);
  165. // Refresh navigation, if we droppped some databases with the name
  166. // that is the same as the username of the deleted user
  167. if ($('#checkbox_drop_users_db:checked').length) {
  168. PMA_reloadNavigation();
  169. }
  170. // Remove the revoked user from the users list
  171. $form.find('input:checkbox:checked').parents('tr').slideUp('medium', function () {
  172. var this_user_initial = $(this).find('input:checkbox').val().charAt(0).toUpperCase();
  173. $(this).remove();
  174. // If this is the last user with this_user_initial, remove the link from #initials_table
  175. if ($('#tableuserrights').find('input:checkbox[value^="' + this_user_initial + '"], input:checkbox[value^="' + this_user_initial.toLowerCase() + '"]').length === 0) {
  176. $('#initials_table').find('td > a:contains(' + this_user_initial + ')').parent('td').html(this_user_initial);
  177. }
  178. // Re-check the classes of each row
  179. $form
  180. .find('tbody').find('tr:odd')
  181. .removeClass('even').addClass('odd')
  182. .end()
  183. .find('tr:even')
  184. .removeClass('odd').addClass('even');
  185. // update the checkall checkbox
  186. $(checkboxes_sel).trigger('change');
  187. });
  188. } else {
  189. PMA_ajaxShowMessage(data.error, false);
  190. }
  191. }); // end $.post()
  192. });
  193. }); // end Revoke User
  194. $(document).on('click', 'a.edit_user_group_anchor.ajax', function (event) {
  195. event.preventDefault();
  196. $(this).parents('tr').addClass('current_row');
  197. var $msg = PMA_ajaxShowMessage();
  198. $.get(
  199. $(this).attr('href'),
  200. {
  201. 'ajax_request': true,
  202. 'edit_user_group_dialog': true
  203. },
  204. function (data) {
  205. if (typeof data !== 'undefined' && data.success === true) {
  206. PMA_ajaxRemoveMessage($msg);
  207. var buttonOptions = {};
  208. buttonOptions[PMA_messages.strGo] = function () {
  209. var usrGroup = $('#changeUserGroupDialog')
  210. .find('select[name="userGroup"]')
  211. .val();
  212. var $message = PMA_ajaxShowMessage();
  213. var argsep = PMA_commonParams.get('arg_separator');
  214. $.post(
  215. 'server_privileges.php',
  216. $('#changeUserGroupDialog').find('form').serialize() + argsep + 'ajax_request=1',
  217. function (data) {
  218. PMA_ajaxRemoveMessage($message);
  219. if (typeof data !== 'undefined' && data.success === true) {
  220. $('#usersForm')
  221. .find('.current_row')
  222. .removeClass('current_row')
  223. .find('.usrGroup')
  224. .text(usrGroup);
  225. } else {
  226. PMA_ajaxShowMessage(data.error, false);
  227. $('#usersForm')
  228. .find('.current_row')
  229. .removeClass('current_row');
  230. }
  231. }
  232. );
  233. $(this).dialog('close');
  234. };
  235. buttonOptions[PMA_messages.strClose] = function () {
  236. $(this).dialog('close');
  237. };
  238. var $dialog = $('<div/>')
  239. .attr('id', 'changeUserGroupDialog')
  240. .append(data.message)
  241. .dialog({
  242. width: 500,
  243. minWidth: 300,
  244. modal: true,
  245. buttons: buttonOptions,
  246. title: $('legend', $(data.message)).text(),
  247. close: function () {
  248. $(this).remove();
  249. }
  250. });
  251. $dialog.find('legend').remove();
  252. } else {
  253. PMA_ajaxShowMessage(data.error, false);
  254. $('#usersForm')
  255. .find('.current_row')
  256. .removeClass('current_row');
  257. }
  258. }
  259. );
  260. });
  261. /**
  262. * AJAX handler for 'Export Privileges'
  263. *
  264. * @see PMA_ajaxShowMessage()
  265. * @memberOf jQuery
  266. * @name export_user_click
  267. */
  268. $(document).on('click', 'button.mult_submit[value=export]', function (event) {
  269. event.preventDefault();
  270. // can't export if no users checked
  271. if ($(this.form).find('input:checked').length === 0) {
  272. PMA_ajaxShowMessage(PMA_messages.strNoAccountSelected, 2000, 'success');
  273. return;
  274. }
  275. var $msgbox = PMA_ajaxShowMessage();
  276. var button_options = {};
  277. button_options[PMA_messages.strClose] = function () {
  278. $(this).dialog('close');
  279. };
  280. var argsep = PMA_commonParams.get('arg_separator');
  281. $.post(
  282. $(this.form).prop('action'),
  283. $(this.form).serialize() + argsep + 'submit_mult=export' + argsep + 'ajax_request=true',
  284. function (data) {
  285. if (typeof data !== 'undefined' && data.success === true) {
  286. var $ajaxDialog = $('<div />')
  287. .append(data.message)
  288. .dialog({
  289. title: data.title,
  290. width: 500,
  291. buttons: button_options,
  292. close: function () {
  293. $(this).remove();
  294. }
  295. });
  296. PMA_ajaxRemoveMessage($msgbox);
  297. // Attach syntax highlighted editor to export dialog
  298. PMA_getSQLEditor($ajaxDialog.find('textarea'));
  299. } else {
  300. PMA_ajaxShowMessage(data.error, false);
  301. }
  302. }
  303. ); // end $.post
  304. });
  305. // if exporting non-ajax, highlight anyways
  306. PMA_getSQLEditor($('textarea.export'));
  307. $(document).on('click', 'a.export_user_anchor.ajax', function (event) {
  308. event.preventDefault();
  309. var $msgbox = PMA_ajaxShowMessage();
  310. /**
  311. * @var button_options Object containing options for jQueryUI dialog buttons
  312. */
  313. var button_options = {};
  314. button_options[PMA_messages.strClose] = function () {
  315. $(this).dialog('close');
  316. };
  317. $.get($(this).attr('href'), { 'ajax_request': true }, function (data) {
  318. if (typeof data !== 'undefined' && data.success === true) {
  319. var $ajaxDialog = $('<div />')
  320. .append(data.message)
  321. .dialog({
  322. title: data.title,
  323. width: 500,
  324. buttons: button_options,
  325. close: function () {
  326. $(this).remove();
  327. }
  328. });
  329. PMA_ajaxRemoveMessage($msgbox);
  330. // Attach syntax highlighted editor to export dialog
  331. PMA_getSQLEditor($ajaxDialog.find('textarea'));
  332. } else {
  333. PMA_ajaxShowMessage(data.error, false);
  334. }
  335. }); // end $.get
  336. }); // end export privileges
  337. /**
  338. * AJAX handler to Paginate the Users Table
  339. *
  340. * @see PMA_ajaxShowMessage()
  341. * @name paginate_users_table_click
  342. * @memberOf jQuery
  343. */
  344. $(document).on('click', '#initials_table a.ajax', function (event) {
  345. event.preventDefault();
  346. var $msgbox = PMA_ajaxShowMessage();
  347. $.get($(this).attr('href'), { 'ajax_request' : true }, function (data) {
  348. if (typeof data !== 'undefined' && data.success === true) {
  349. PMA_ajaxRemoveMessage($msgbox);
  350. // This form is not on screen when first entering Privileges
  351. // if there are more than 50 users
  352. $('div.notice').remove();
  353. $('#usersForm').hide('medium').remove();
  354. $('#fieldset_add_user').hide('medium').remove();
  355. $('#initials_table')
  356. .prop('id', 'initials_table_old')
  357. .after(data.message).show('medium')
  358. .siblings('h2').not(':first').remove();
  359. // prevent double initials table
  360. $('#initials_table_old').remove();
  361. } else {
  362. PMA_ajaxShowMessage(data.error, false);
  363. }
  364. }); // end $.get
  365. }); // end of the paginate users table
  366. $(document).on('change', 'input[name="ssl_type"]', function (e) {
  367. var $div = $('#specified_div');
  368. if ($('#ssl_type_SPECIFIED').is(':checked')) {
  369. $div.find('input').prop('disabled', false);
  370. } else {
  371. $div.find('input').prop('disabled', true);
  372. }
  373. });
  374. $(document).on('change', '#checkbox_SSL_priv', function (e) {
  375. var $div = $('#require_ssl_div');
  376. if ($(this).is(':checked')) {
  377. $div.find('input').prop('disabled', false);
  378. $('#ssl_type_SPECIFIED').trigger('change');
  379. } else {
  380. $div.find('input').prop('disabled', true);
  381. }
  382. });
  383. $('#checkbox_SSL_priv').trigger('change');
  384. /*
  385. * Create submenu for simpler interface
  386. */
  387. var addOrUpdateSubmenu = function () {
  388. var $topmenu2 = $('#topmenu2');
  389. var $edit_user_dialog = $('#edit_user_dialog');
  390. var submenu_label;
  391. var submenu_link;
  392. var link_number;
  393. // if submenu exists yet, remove it first
  394. if ($topmenu2.length > 0) {
  395. $topmenu2.remove();
  396. }
  397. // construct a submenu from the existing fieldsets
  398. $topmenu2 = $('<ul/>').prop('id', 'topmenu2');
  399. $('#edit_user_dialog .submenu-item').each(function () {
  400. submenu_label = $(this).find('legend[data-submenu-label]').data('submenu-label');
  401. submenu_link = $('<a/>')
  402. .prop('href', '#')
  403. .html(submenu_label);
  404. $('<li/>')
  405. .append(submenu_link)
  406. .appendTo($topmenu2);
  407. });
  408. // click handlers for submenu
  409. $topmenu2.find('a').click(function (e) {
  410. e.preventDefault();
  411. // if already active, ignore click
  412. if ($(this).hasClass('tabactive')) {
  413. return;
  414. }
  415. $topmenu2.find('a').removeClass('tabactive');
  416. $(this).addClass('tabactive');
  417. // which section to show now?
  418. link_number = $topmenu2.find('a').index($(this));
  419. // hide all sections but the one to show
  420. $('#edit_user_dialog .submenu-item').hide().eq(link_number).show();
  421. });
  422. // make first menu item active
  423. // TODO: support URL hash history
  424. $topmenu2.find('> :first-child a').addClass('tabactive');
  425. $edit_user_dialog.prepend($topmenu2);
  426. // hide all sections but the first
  427. $('#edit_user_dialog .submenu-item').hide().eq(0).show();
  428. // scroll to the top
  429. $('html, body').animate({ scrollTop: 0 }, 'fast');
  430. };
  431. $('input.autofocus').focus();
  432. $(checkboxes_sel).trigger('change');
  433. displayPasswordGenerateButton();
  434. if ($('#edit_user_dialog').length > 0) {
  435. addOrUpdateSubmenu();
  436. }
  437. var windowwidth = $(window).width();
  438. $('.jsresponsive').css('max-width', (windowwidth - 35) + 'px');
  439. });