AbstractBuildForm.php 168 KB
Newer Older
1
<?php
Carsten  Rose's avatar
Carsten Rose committed
2
3
4
5
6
7
/**
 * Created by PhpStorm.
 * User: crose
 * Date: 1/6/16
 * Time: 8:02 PM
 */
Carsten  Rose's avatar
Carsten Rose committed
8

9
10
11
namespace qfq;

use qfq;
Carsten  Rose's avatar
Carsten Rose committed
12
use Symfony\Component\Console\Helper\Helper;
Carsten  Rose's avatar
Carsten Rose committed
13
14
15
16

//use qfq\Store;
//use qfq\OnArray;
//use qfq\UserFormException;
17

18
19
require_once(__DIR__ . '/store/Store.php');
require_once(__DIR__ . '/Constants.php');
20
21
require_once(__DIR__ . '/Evaluate.php');
require_once(__DIR__ . '/BodytextParser.php');
22
23
24
25
26
27
28
29
require_once(__DIR__ . '/exceptions/DbException.php');
require_once(__DIR__ . '/exceptions/UserFormException.php');
require_once(__DIR__ . '/database/Database.php');
require_once(__DIR__ . '/helper/HelperFormElement.php');
require_once(__DIR__ . '/helper/Support.php');
require_once(__DIR__ . '/helper/OnArray.php');
require_once(__DIR__ . '/helper/Ldap.php');
require_once(__DIR__ . '/report/Link.php');
30
require_once(__DIR__ . '/helper/Sanitize.php');
31
require_once(__DIR__ . '/helper/HelperFile.php');
32
require_once(__DIR__ . '/report/Report.php');
33

34
/**
Carsten  Rose's avatar
Carsten Rose committed
35
36
 * Class AbstractBuildForm
 * @package qfq
37
 */
38
abstract class AbstractBuildForm {
39
40
41
    /**
     * @var array
     */
42
    protected $formSpec = array();  // copy of the loaded form
43
44
45
    /**
     * @var array
     */
46
    protected $feSpecAction = array(); // copy of all formElement.class='action' of the loaded form
47
48
49
    /**
     * @var array
     */
50
    protected $feSpecNative = array(); // copy of all formElement.class='native' of the loaded form
51
52
53
    /**
     * @var array
     */
54
    protected $buildElementFunctionName = array();
55
56
57
    /**
     * @var array
     */
58
    protected $pattern = array();
59
60
61
    /**
     * @var array
     */
62
    protected $wrap = array();
63
64
65
    /**
     * @var array
     */
66
    protected $symbol = array();
67
68
69
    /**
     * @var bool
     */
70
    protected $showDebugInfoFlag = false;
Carsten  Rose's avatar
Carsten Rose committed
71

72
//    protected $feDivClass = array(); // Wrap FormElements in <div class="$feDivClass[type]">
73

74
75
76
77
78
79
80
81
    /**
     * @var Store
     */
    protected $store = null;
    /**
     * @var Evaluate
     */
    protected $evaluate = null;
82
83
84
    /**
     * @var string
     */
85
    private $formId = null;
86
87
88
89
    /**
     * @var Sip
     */
    private $sip = null;
90
91
92
93
    /**
     * @var Link
     */
    protected $link = null;
94
95
96
97
98
99
100
101
    /**
     * @var Report
     */
    private $report = null;
    /**
     * @var BodytextParser
     */
    private $bodytextParser = null;
102

103
    /**
104
     * @var Database[] Array of Database instantiated class
105
106
107
     */
    protected $dbArray = array();

108
109
110
    /**
     * @var bool|mixed
     */
111
    protected $dbIndexData = false;
112
113
114
    /**
     * @var bool|string
     */
115
    protected $dbIndexQfq = false;
Carsten  Rose's avatar
Carsten Rose committed
116

117
118
119
120
121
122
    /**
     * AbstractBuildForm constructor.
     *
     * @param array $formSpec
     * @param array $feSpecAction
     * @param array $feSpecNative
123
     * @param array Database $db
124
125
     * @throws CodeException
     * @throws UserFormException
126
     * @throws UserReportException
127
     */
128
    public function __construct(array $formSpec, array $feSpecAction, array $feSpecNative, array $db = null) {
129
130
131
132
        $this->formSpec = $formSpec;
        $this->feSpecAction = $feSpecAction;
        $this->feSpecNative = $feSpecNative;
        $this->store = Store::getInstance();
133
134
//        $this->dbIndexData = $this->store->getVar(SYSTEM_DB_INDEX_DATA, STORE_SYSTEM);
        $this->dbIndexData = $formSpec[F_DB_INDEX];
135
136
137
138
        $this->dbIndexQfq = $this->store->getVar(SYSTEM_DB_INDEX_QFQ, STORE_SYSTEM);

        $this->dbArray = $db;
        $this->evaluate = new Evaluate($this->store, $this->dbArray[$this->dbIndexData]);
139
        $this->showDebugInfoFlag = Support::findInSet(SYSTEM_SHOW_DEBUG_INFO_YES, $this->store->getVar(SYSTEM_SHOW_DEBUG_INFO, STORE_SYSTEM));
140

141
        $this->sip = $this->store->getSipInstance();
142

143
144
        $this->link = new Link($this->sip, $this->dbIndexData);

145
        // render mode specific
146
        $this->fillWrap();
147
148

        $this->buildElementFunctionName = [
149
            FE_TYPE_CHECKBOX => 'Checkbox',
Carsten  Rose's avatar
Carsten Rose committed
150
            FE_TYPE_DATE => 'DateTime',
151
            FE_TYPE_DATETIME => 'DateTime',
Carsten  Rose's avatar
Carsten Rose committed
152
153
154
155
156
157
158
159
160
            'dateJQW' => 'DateJQW',
            'datetimeJQW' => 'DateJQW',
            'email' => 'Input',
            'gridJQW' => 'GridJQW',
            FE_TYPE_EXTRA => 'Extra',
            FE_TYPE_TEXT => 'Input',
            FE_TYPE_EDITOR => 'Editor',
            FE_TYPE_TIME => 'DateTime',
            FE_TYPE_NOTE => 'Note',
161
            FE_TYPE_PASSWORD => 'Input',
Carsten  Rose's avatar
Carsten Rose committed
162
163
            FE_TYPE_RADIO => 'Radio',
            FE_TYPE_SELECT => 'Select',
164
            FE_TYPE_SUBRECORD => 'Subrecord',
Carsten  Rose's avatar
Carsten Rose committed
165
            FE_TYPE_UPLOAD => 'File',
166
            FE_TYPE_ANNOTATE => 'Annotate',
167
            FE_TYPE_IMAGE_CUT => 'ImageCut',
Carsten  Rose's avatar
Carsten Rose committed
168
169
170
            'fieldset' => 'Fieldset',
            'pill' => 'Pill',
            'templateGroup' => 'TemplateGroup',
171
172
        ];

173
        $this->buildRowName = [
174
            FE_TYPE_CHECKBOX => 'Native',
Carsten  Rose's avatar
Carsten Rose committed
175
            FE_TYPE_DATE => 'Native',
176
            FE_TYPE_DATETIME => 'Native',
Carsten  Rose's avatar
Carsten Rose committed
177
178
179
180
181
182
183
184
185
            'dateJQW' => 'Native',
            'datetimeJQW' => 'Native',
            'email' => 'Native',
            'gridJQW' => 'Native',
            FE_TYPE_EXTRA => 'Native',
            FE_TYPE_TEXT => 'Native',
            FE_TYPE_EDITOR => 'Native',
            FE_TYPE_TIME => 'Native',
            FE_TYPE_NOTE => 'Native',
186
            FE_TYPE_PASSWORD => 'Native',
Carsten  Rose's avatar
Carsten Rose committed
187
188
            FE_TYPE_RADIO => 'Native',
            FE_TYPE_SELECT => 'Native',
189
            FE_TYPE_SUBRECORD => 'Subrecord',
Carsten  Rose's avatar
Carsten Rose committed
190
            FE_TYPE_UPLOAD => 'Native',
191
            FE_TYPE_ANNOTATE => 'Native',
192
            FE_TYPE_IMAGE_CUT => 'Native',
Carsten  Rose's avatar
Carsten Rose committed
193
194
195
            'fieldset' => 'Fieldset',
            'pill' => 'Pill',
            'templateGroup' => 'TemplateGroup',
196
197
        ];

198
        $this->symbol[SYMBOL_EDIT] = "<span class='glyphicon " . GLYPH_ICON_EDIT . "'></span>";
199
        $this->symbol[SYMBOL_SHOW] = "<span class='glyphicon " . GLYPH_ICON_SHOW . "'></span>";
200
201
        $this->symbol[SYMBOL_NEW] = "<span class='glyphicon " . GLYPH_ICON_NEW . "'></span>";
        $this->symbol[SYMBOL_DELETE] = "<span class='glyphicon " . GLYPH_ICON_DELETE . "'></span>";
202
203
    }

204
205
    abstract public function fillWrap();

206
    /**
207
     * Builds complete 'form'. Depending of form specification, the layout will be 'plain' / 'table' / 'bootstrap'.
208
     *
209
     * @param string $mode FORM_LOAD | FORM_UPDATE | FORM_SAVE
210
     *
211
212
213
     * @param bool $htmlElementNameIdZero
     * @param array $latestFeSpecNative
     * @return array|string $mode=LOAD_FORM: The whole form as HTML, $mode=FORM_UPDATE: array of all
214
     *                        formElement.dynamicUpdate-yes  values/states
215
216
     * @throws CodeException
     * @throws DbException
217
     * @throws DownloadException
218
     * @throws UserFormException
219
     * @throws UserReportException
220
221
222
     * @throws \PhpOffice\PhpSpreadsheet\Exception
     * @throws \PhpOffice\PhpSpreadsheet\Reader\Exception
     * @throws \PhpOffice\PhpSpreadsheet\Writer\Exception
223
     */
224
    public function process($mode, $htmlElementNameIdZero = false, $latestFeSpecNative = array()) {
Carsten  Rose's avatar
Carsten Rose committed
225
226
        $htmlHead = '';
        $htmlTail = '';
227
        $htmlT3vars = '';
Carsten  Rose's avatar
Carsten Rose committed
228
229
230
        $htmlSubrecords = '';
        $htmlElements = '';
        $json = array();
231

232
        // After action 'afterSave', it's necessary to reinitialize the FeSpecNative
233
234
235
236
        if (!empty($latestFeSpecNative)) {
            $this->feSpecNative = $latestFeSpecNative;
        }

237
238
239
240
241
242
243
        $modeCollectFe = FLAG_DYNAMIC_UPDATE;
        $storeUse = STORE_USE_DEFAULT;

        if ($mode === FORM_SAVE) {
            $modeCollectFe = FLAG_ALL;
            $storeUse = STORE_RECORD . STORE_TABLE_DEFAULT;
        }
244

245
        // <form>
Carsten  Rose's avatar
Carsten Rose committed
246
247
248
        if ($mode === FORM_LOAD) {
            $htmlHead = $this->head();
        }
249

250
        $filter = $this->getProcessFilter();
251

252
        if ($this->formSpec['multiMode'] !== 'none') {
253

254
            $parentRecords = $this->dbArray[$this->dbIndexQfq]->sql($this->formSpec['multiSql']);
255
            foreach ($parentRecords as $row) {
256
                $this->store->setStore($row, STORE_PARENT_RECORD, true);
Carsten  Rose's avatar
Carsten Rose committed
257
                $jsonTmp = array();
258
                $htmlElements = $this->elements($row['_id'], $filter, 0, $jsonTmp, $modeCollectFe);
Carsten  Rose's avatar
Carsten Rose committed
259
                $json[] = $jsonTmp;
260
            }
261

262
        } else {
263

264
            $recordId = $this->store->getVar(SIP_RECORD_ID, STORE_SIP);
265
            if (!($recordId == '' || is_numeric($recordId))) {
266
267
268
                throw new UserFormException(
                    json_encode([ERROR_MESSAGE_TO_USER => 'Invalid record ID', ERROR_MESSAGE_SUPPORT => 'Invalid record ID: r="' . $recordId]),
                    ERROR_INVALID_VALUE);
269
            }
270

271
            $htmlElements = $this->elements($recordId, $filter, 0, $json, $modeCollectFe, $htmlElementNameIdZero, $storeUse, $mode);
Carsten  Rose's avatar
Carsten Rose committed
272
273

            if ($mode === FORM_SAVE && $recordId != 0) {
274
275
276

                // element-update: with 'value'
                $recordId = $this->store->getVar(SIP_RECORD_ID, STORE_SIP . STORE_ZERO);
277
                $md5 = $this->buildRecordHashMd5($this->formSpec[F_TABLE_NAME], $recordId, $this->formSpec[F_PRIMARY_KEY]);
278
279

                // Via 'element-update'
280
                $json[][API_ELEMENT_UPDATE][DIRTY_RECORD_HASH_MD5][API_ELEMENT_ATTRIBUTE]['value'] = $md5;
Carsten  Rose's avatar
Carsten Rose committed
281
            }
282
        }
283
284
285

        // <form>
        if ($mode === FORM_LOAD) {
286
            $htmlT3vars = $this->prepareT3VarsForSave();
287
            $htmlTail = $this->tail();
288
289
            $htmlSubrecords = $this->doSubrecords();
        }
290
        $htmlHidden = $this->buildAdditionalFormElements();
291

292
293
        $htmlSip = $this->buildHiddenSip($json);

294
        return ($mode === FORM_LOAD) ? $htmlHead . $htmlHidden . $htmlElements . $htmlSip . $htmlT3vars . $htmlTail . $htmlSubrecords : $json;
295
296
    }

297
    /**
298
     * Builds the head area of the form.
299
     *
300
     * @param string $mode
301
     * @return string
302
     * @throws CodeException
303
     * @throws DbException
304
     * @throws UserFormException
305
     */
306
    public function head($mode = FORM_LOAD) {
307
        $html = '';
308

309
        $html .= '<div ' . Support::doAttribute('class', $this->formSpec[F_CLASS], true) . '>'; // main <div class=...> around everything
310

311
312
        // Logged in BE User will see a FormEdit Link
        $sipParamString = OnArray::toString($this->store->getStore(STORE_SIP), ':', ', ', "'");
313
        $formEditUrl = $this->createFormEditorUrl(FORM_NAME_FORM, $this->formSpec[F_ID]);
314

315
        $html .= "<p><a " . Support::doAttribute('href', $formEditUrl) . ">Edit</a> <small>[$sipParamString]</small></p>";
316

317
        $html .= $this->wrapItem(WRAP_SETUP_TITLE, $this->formSpec[F_TITLE], true);
318

319
320
321
        $html .= $this->getFormTag();

        return $html;
322
323
    }

324
    /**
325
326
     * If SHOW_DEBUG_INFO=yes: create a link (incl. SIP) to edit the current form. Show also the hidden content of
     * the SIP.
327
     *
328
     * @param string $form FORM_NAME_FORM | FORM_NAME_FORM_ELEMENT
Carsten  Rose's avatar
Carsten Rose committed
329
330
     * @param int $recordId id of form or formElement
     * @param array $param
331
332
333
     *
     * @return string String: <a href="?pageId&sip=....">Edit</a> <small>[sip:..., r:..., urlparam:...,
     *                ...]</small>
334
335
     * @throws CodeException
     * @throws UserFormException
336
     */
337
    public function createFormEditorUrl($form, $recordId, array $param = array()) {
338

339
        if (!$this->showDebugInfoFlag) {
340
341
            return '';
        }
342

343
        $queryStringArray = [
344
            'id' => $this->store->getVar(SYSTEM_EDIT_FORM_PAGE, STORE_SYSTEM),
345
            'form' => $form,
Carsten  Rose's avatar
Carsten Rose committed
346
            'r' => $recordId,
347
            PARAM_DB_INDEX_DATA => $this->dbIndexQfq,
348
        ];
349
        $queryStringArray = array_merge($queryStringArray, $param);
350

351
        $queryString = Support::arrayToQueryString($queryStringArray);
352

353
354
        $sip = $this->store->getSipInstance();
        $url = $sip->queryStringToSip($queryString);
355

356
        return $url;
357
358
359
    }

    /**
360
361
     * Wrap's $this->wrap[$item][WRAP_SETUP_START] around $value. If $flagOmitEmpty==true && $value=='': return ''.
     *
Carsten  Rose's avatar
Carsten Rose committed
362
363
     * @param string $item
     * @param string $value
364
     * @param bool|false $flagOmitEmpty
365
     *
366
367
368
     * @return string
     */
    public function wrapItem($item, $value, $flagOmitEmpty = false) {
369
370

        if ($flagOmitEmpty && $value === "") {
371
            return '';
372
373
        }

374
375
376
377
        return $this->wrap[$item][WRAP_SETUP_START] . $value . $this->wrap[$item][WRAP_SETUP_END];
    }

    /**
378
     * Returns '<form ...>'-tag with various attributes.
379
380
     *
     * @return string
381
382
383
     * @throws CodeException
     * @throws DbException
     * @throws UserFormException
384
385
     */
    public function getFormTag() {
Carsten  Rose's avatar
Carsten Rose committed
386
        $md5 = '';
387

388
        $attribute = $this->getFormTagAttributes();
389

390
391
        $honeypot = $this->getHoneypotVars();

392
        $md5 = $this->buildInputRecordHashMd5();
Carsten  Rose's avatar
Carsten Rose committed
393
394
395
396
397
398

        return '<form ' . OnArray::toString($attribute, '=', ' ', "'") . '>' . $honeypot . $md5;
    }

    /**
     * Build MD5 from the current record. Return HTML Input element.
399
     *
400
     * @return string
401
     * @throws CodeException
402
     * @throws DbException
403
     * @throws UserFormException
Carsten  Rose's avatar
Carsten Rose committed
404
     */
405
    public function buildInputRecordHashMd5() {
406

Carsten  Rose's avatar
Carsten Rose committed
407
        $recordId = $this->store->getVar(SIP_RECORD_ID, STORE_SIP . STORE_ZERO);
408
        $md5 = $this->buildRecordHashMd5($this->formSpec[F_TABLE_NAME], $recordId, $this->formSpec[F_PRIMARY_KEY]);
409
410

        $data = "<input id='" . DIRTY_RECORD_HASH_MD5 . "' name='" . DIRTY_RECORD_HASH_MD5 . "' type='hidden' value='$md5'>";
411

412
//        $data = "<input id='" . DIRTY_RECORD_HASH_MD5 . "' name='" . DIRTY_RECORD_HASH_MD5 . "' type='text' value='$md5'>";
413
414
415
416
417
418
419
420

        return $data;
    }


    /**
     * @param $tableName
     * @param $recordId
421
     * @param string $primaryKey
422
     *
423
     * @return string
424
425
426
     * @throws CodeException
     * @throws DbException
     * @throws UserFormException
427
     */
428
    public function buildRecordHashMd5($tableName, $recordId, $primaryKey = F_PRIMARY_KEY_DEFAULT) {
429
        $record = array();
Carsten  Rose's avatar
Carsten Rose committed
430
431

        if ($recordId != 0) {
432
            $record = $this->dbArray[$this->dbIndexData]->sql("SELECT * FROM $tableName WHERE $primaryKey=?", ROW_EXPECT_1, [$recordId], "Record to load not found.");
Carsten  Rose's avatar
Carsten Rose committed
433
434
        }

435
        return OnArray::getMd5($record);
436
437
    }

438
439
440
441
    /**
     * Create HTML Input vars to detect bot automatic filling of forms.
     *
     * @return string
442
443
     * @throws CodeException
     * @throws UserFormException
444
445
446
447
448
449
450
451
452
     */
    public function getHoneypotVars() {
        $html = '';

        $vars = $this->store->getVar(SYSTEM_SECURITY_VARS_HONEYPOT, STORE_SYSTEM);

        // Iterate over all fake vars
        $arr = explode(',', $vars);
        foreach ($arr as $name) {
453
454
455
456
            $name = trim($name);
            if ($name === '') {
                continue;
            }
457
458
459
460
461
            $html .= "<input name='$name' type='hidden' value='' readonly>";
        }

        return $html;
    }
462

Carsten  Rose's avatar
Carsten Rose committed
463

464
465
466
    /**
     * Build an assoc array with standard form attributes.
     *
467
     * @return array
468
469
470
     * @throws CodeException
     * @throws DbException
     * @throws UserFormException
471
     */
472
    public function getFormTagAttributes() {
473

474
        $attribute['id'] = $this->getFormId();
475
476
477
478
        $attribute['method'] = 'post';
        $attribute['action'] = $this->getActionUrl();
        $attribute['target'] = '_top';
        $attribute['accept-charset'] = 'UTF-8';
479
        $attribute[FE_INPUT_AUTOCOMPLETE] = 'on';
480
        $attribute['enctype'] = $this->getEncType();
481
        $attribute['data-disable-return-key-submit'] = $this->formSpec[F_ENTER_AS_SUBMIT] == '1' ? "false" : "true"; // attribute meaning is inverted
482
483
484
485

        return $attribute;
    }

486
    /**
Carsten  Rose's avatar
Carsten Rose committed
487
488
     * Return a uniq form id
     *
489
490
491
492
493
494
     * @return string
     */
    public function getFormId() {
        if ($this->formId === null) {
            $this->formId = uniqid('qfq-form-');
        }
495

496
497
498
        return $this->formId;
    }

499
500
501
    /**
     * Builds the HTML 'form'-tag inlcuding all attributes and target.
     *
502
503
     * Notice: the SIP will be transferred as POST Parameter.
     *
504
505
506
507
     * @return string
     */
    public function getActionUrl() {

508
        return API_DIR . '/save.php';
509
510
511
512
513
514
515
516
    }

    /**
     * Determines the enctype.
     *
     * See: https://www.w3.org/wiki/HTML/Elements/form#HTML_Attributes
     *
     * @return string
517
518
519
     * @throws CodeException
     * @throws DbException
     * @throws UserFormException
520
521
522
     */
    public function getEncType() {

523
        $result = $this->dbArray[$this->dbIndexQfq]->sql("SELECT id FROM FormElement AS fe WHERE fe.formId=? AND fe.type='upload' LIMIT 1", ROW_REGULAR, [$this->formSpec['id']], 'Look for Formelement.type="upload"');
524

525
526
527
        return (count($result) === 1) ? 'multipart/form-data' : 'application/x-www-form-urlencoded';

    }
528

529
    abstract public function getProcessFilter();
530

531
532
533
534
    /**
     * @param array|string $value
     *
     * @return array|string
535
536
     * @throws CodeException
     * @throws DbException
537
     * @throws DownloadException
538
539
     * @throws UserFormException
     * @throws UserReportException
540
541
542
     * @throws \PhpOffice\PhpSpreadsheet\Exception
     * @throws \PhpOffice\PhpSpreadsheet\Reader\Exception
     * @throws \PhpOffice\PhpSpreadsheet\Writer\Exception
543
     */
544
545
    private function processReportSyntax($value) {

546
547
548
549
550
551
552
553
554
555
556
        if (is_array($value)) {
            $new = array();

            //might happen for e.g Template Groups
            foreach ($value as $item) {
                $new[] = $this->processReportSyntax($item);
            }

            return $new;
        }

557
        $value = trim($value);
558
559
560
561
562
563
564
565
566
        if (substr($value, 0, 8) == SHEBANG_REPORT) {
            if ($this->report === null) {
                $this->report = new Report(array(), $this->evaluate, false);
            }

            if ($this->bodytextParser === null) {
                $this->bodytextParser = new BodytextParser();
            }

567
            $storeRecord = $this->store->getStore(STORE_RECORD);
568
            $value = $this->report->process($this->bodytextParser->process($value));
569
            $this->store->setStore($storeRecord, STORE_RECORD, true);
Carsten  Rose's avatar
Carsten Rose committed
570
            $this->store->setVar(SYSTEM_REPORT_FULL_LEVEL, '', STORE_SYSTEM); // debug
571
572
573
574
575
        }

        return $value;
    }

576
    /**
577
     * Process all FormElements in $this->feSpecNative: Collect and return all HTML code & JSON.
578
     *
Carsten  Rose's avatar
Carsten Rose committed
579
     * @param int $recordId
580
     * @param string $filter FORM_ELEMENTS_NATIVE | FORM_ELEMENTS_SUBRECORD | FORM_ELEMENTS_NATIVE_SUBRECORD
Carsten  Rose's avatar
Carsten Rose committed
581
582
     * @param int $feIdContainer
     * @param array $json
583
     * @param string $modeCollectFe
Carsten  Rose's avatar
Carsten Rose committed
584
     * @param bool $htmlElementNameIdZero
585
     * @param string $storeUseDefault
586
     * @param string $mode FORM_LOAD | FORM_UPDATE | FORM_SAVE
587
     *
588
     * @return string
589
590
     * @throws CodeException
     * @throws DbException
591
     * @throws DownloadException
592
593
     * @throws UserFormException
     * @throws UserReportException
594
595
596
     * @throws \PhpOffice\PhpSpreadsheet\Exception
     * @throws \PhpOffice\PhpSpreadsheet\Reader\Exception
     * @throws \PhpOffice\PhpSpreadsheet\Writer\Exception
597
     */
598
    public function elements($recordId, $filter, $feIdContainer, array &$json,
599
                             $modeCollectFe = FLAG_DYNAMIC_UPDATE, $htmlElementNameIdZero = false,
600
                             $storeUseDefault = STORE_USE_DEFAULT, $mode = FORM_LOAD) {
601
        $html = '';
602

603
        // The following 'FormElement.parameter' will never be used during load (fe.type='upload'). FE_PARAMETER has been already expanded.
604
        $skip = [FE_SQL_UPDATE, FE_SQL_INSERT, FE_SQL_DELETE, FE_SQL_AFTER, FE_SQL_BEFORE, FE_PARAMETER, FE_FILL_STORE_VAR, FE_FILE_DOWNLOAD_BUTTON];
605

606
        // get current data record
607
608
        $primaryKey = $this->formSpec[F_PRIMARY_KEY];
        if ($recordId > 0 && $this->store->getVar($primaryKey, STORE_RECORD) === false) {
609
            $tableName = $this->formSpec[F_TABLE_NAME];
610
611
            $row = $this->dbArray[$this->dbIndexData]->sql("SELECT * FROM $tableName WHERE $primaryKey = ?", ROW_EXPECT_1,
                array($recordId), "Form '" . $this->formSpec[F_NAME] . "' failed to load record '$primaryKey'='$recordId' from table '" .
612
                $this->formSpec[F_TABLE_NAME] . "'.");
613
            $this->store->setStore($row, STORE_RECORD);
614
        }
615

616
617
        $this->checkAutoFocus();

618
619
        $parameterLanguageFieldName = $this->store->getVar(SYSTEM_PARAMETER_LANGUAGE_FIELD_NAME, STORE_SYSTEM);

620
621
        // Iterate over all FormElements
        foreach ($this->feSpecNative as $fe) {
622
            $storeUse = $storeUseDefault;
623

624
625
            if (($filter === FORM_ELEMENTS_NATIVE && $fe[FE_TYPE] === 'subrecord')
                || ($filter === FORM_ELEMENTS_SUBRECORD && $fe[FE_TYPE] !== 'subrecord')
626
//                || ($filter === FORM_ELEMENTS_DYNAMIC_UPDATE && $fe[FE_DYNAMIC_UPDATE] === 'no')
627
628
629
630
            ) {
                continue; // skip this FE
            }

631
            $flagOutput = ($fe[FE_TYPE] !== FE_TYPE_EXTRA); // type='extra' will not displayed and not transmitted to the form.
632

633
634
            $debugStack = array();

635
636
            // Preparation for Log, Debug
            $this->store->setVar(SYSTEM_FORM_ELEMENT, Logger::formatFormElementName($fe), STORE_SYSTEM);
637
            $this->store->setVar(SYSTEM_FORM_ELEMENT_ID, $fe[FE_ID], STORE_SYSTEM);
638

Carsten  Rose's avatar
Carsten Rose committed
639
640
            // Fill STORE_LDAP
            $fe = $this->prepareFillStoreFireLdap($fe);
641

642
643
644
645
646
647
            if (isset($fe[FE_FILL_STORE_VAR])) {
                $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN, FE_FILL_STORE_VAR, STORE_SYSTEM); // debug
                $fe[FE_FILL_STORE_VAR] = $this->evaluate->parse($fe[FE_FILL_STORE_VAR], ROW_EXPECT_0_1);
                $this->store->appendToStore($fe[FE_FILL_STORE_VAR], STORE_VAR);
            }

648
            // for Upload FormElements, it's necessary to pre-calculate an optional given 'slaveId'.
649
            if ($fe[FE_TYPE] === FE_TYPE_UPLOAD) {
650
                Support::setIfNotSet($fe, FE_SLAVE_ID);
651
                $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN, FE_SLAVE_ID, STORE_SYSTEM); // debug
652
653
                $slaveId = Support::falseEmptyToZero($this->evaluate->parse($fe[FE_SLAVE_ID]));
                $this->store->setVar(VAR_SLAVE_ID, $slaveId, STORE_VAR);
654
655
            }

656
            $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN, FE_VALUE, STORE_SYSTEM); // debug
657
            $fe[FE_VALUE] = $this->processReportSyntax($fe[FE_VALUE]);
658
659

            $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN, FE_NOTE, STORE_SYSTEM); // debug
660
661
            $fe[FE_NOTE] = $this->processReportSyntax($fe[FE_NOTE]);

Carsten  Rose's avatar
Carsten Rose committed
662
            // ** evaluate current FormElement **
663
            $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN, 'Some of the columns of current FormElement', STORE_SYSTEM); // debug
664
            $formElement = $this->evaluate->parseArray($fe, $skip, $debugStack);
665
            $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN, 'Set language', STORE_SYSTEM); // debug
666
            $formElement = HelperFormElement::setLanguage($formElement, $parameterLanguageFieldName);
667

668
            // Some Defaults
669
            $formElement = Support::setFeDefaults($formElement, $this->formSpec);
670

671
672
673
674
675
676
//            // Copy global readonly mode.
//            if ($this->formSpec[F_MODE] == F_MODE_READONLY) {
//                $fe[FE_MODE] = FE_MODE_READONLY;
//                $fe[FE_MODE_SQL] = '';
//            }

677
            if ($flagOutput === true) {
678
                $this->fillWrapLabelInputNote($formElement[FE_BS_LABEL_COLUMNS], $formElement[FE_BS_INPUT_COLUMNS], $formElement[FE_BS_NOTE_COLUMNS]);
679
            }
680

681
682
            //In case the current element is a 'RETYPE' element: take the element name of the source FormElement. Needed in the next row to retrieve the default value.
            $name = (isset($formElement[FE_RETYPE_SOURCE_NAME])) ? $formElement[FE_RETYPE_SOURCE_NAME] : $formElement[FE_NAME];
683

684
685
686
            $value = '';
            Support::setIfNotSet($formElement, FE_VALUE);

687
688
689
            if (is_array($formElement[FE_VALUE])) {
                $formElement[FE_VALUE] = (count($formElement[FE_VALUE])) > 0 ? current($formElement[FE_VALUE][0]) : '';
            }
690

691
            $value = $formElement[FE_VALUE];
692

693
            if ($value === '') {
694
695
696
697
                // #2064 / Only take the default, if the FE is a real tablecolumn.
                // #3426 / Dynamic Update: Inputs loose the new content and shows the old value.
                if ($storeUse == STORE_USE_DEFAULT && $this->store->getVar($formElement[FE_NAME], STORE_TABLE_COLUMN_TYPES) === false) {
                    $storeUse = str_replace(STORE_TABLE_DEFAULT, '', $storeUse); // Remove STORE_DEFAULT
698
                }
699
                // Retrieve value via FSRVD
Marc Egger's avatar
Marc Egger committed
700
                $sanitizeClass=($mode == FORM_UPDATE) ? SANITIZE_ALLOW_ALL : $formElement[FE_CHECK_TYPE];
701
                $value = $this->store->getVar($name, $storeUse, $sanitizeClass, $foundInStore);
702
703
704
            }

            if ($formElement[FE_ENCODE] === FE_ENCODE_SPECIALCHAR) {
705
706
//                $value = htmlspecialchars_decode($value, ENT_QUOTES);
                $value = Support::htmlEntityEncodeDecode(MODE_DECODE, $value);
707
            }
708

709
710
            // Typically: $htmlElementNameIdZero = true
            // After Saving a record, staying on the form, the FormElements on the Client are still known as '<feName>:0'.
711
            $htmlFormElementName = HelperFormElement::buildFormElementName($formElement, ($htmlElementNameIdZero) ? 0 : $recordId);
712
713
714
            $formElement[FE_HTML_ID] = HelperFormElement::buildFormElementId($this->formSpec[F_ID], $formElement[FE_ID],
                ($htmlElementNameIdZero) ? 0 : $recordId,
                $formElement[FE_TG_INDEX]);
715

Carsten  Rose's avatar
Carsten Rose committed
716
            // Construct Marshaller Name: buildElement
717
            $buildElementFunctionName = 'build' . $this->buildElementFunctionName[$formElement[FE_TYPE]];
718

Carsten  Rose's avatar
Carsten Rose committed
719
            $jsonElement = array();
720
            $elementExtra = '';
721
            // Render pure element
722
            $elementHtml = $this->$buildElementFunctionName($formElement, $htmlFormElementName, $value, $jsonElement, $mode);
Carsten  Rose's avatar
Carsten Rose committed
723
724

            // container elements do not have dynamicUpdate='yes'. Instead they deliver nested elements.
725
            if ($formElement[FE_CLASS] == FE_CLASS_CONTAINER) {
Carsten  Rose's avatar
Carsten Rose committed
726
727
728
729
                if (count($jsonElement) > 0) {
                    $json = array_merge($json, $jsonElement);
                }
            } else {
730
                // for non-container elements: just add the current json status
731
                if ($modeCollectFe === FLAG_ALL || ($modeCollectFe == FLAG_DYNAMIC_UPDATE && $fe[FE_DYNAMIC_UPDATE] === 'yes')) {
Carsten  Rose's avatar
Carsten Rose committed
732
733
734
735
736
737
                    if (isset($jsonElement[0]) && is_array($jsonElement[0])) {
                        // Checkboxes are delivered as array of arrays: unnest them and append them to the existing json array.
                        $json = array_merge($json, $jsonElement);
                    } else {
                        $json[] = $jsonElement;
                    }
Carsten  Rose's avatar
Carsten Rose committed
738
739
                }
            }
740

741
742
            if ($flagOutput) {
                // debugStack as Tooltip
743
                if ($this->showDebugInfoFlag) {
744
745
746
747
748
                    if (count($debugStack) > 0) {
                        $elementHtml .= Support::doTooltip($formElement[FE_HTML_ID] . HTML_ID_EXTENSION_TOOLTIP, implode("\n", $debugStack));
                    }

                    // Build 'FormElement' Edit symbol
Carsten  Rose's avatar
Carsten Rose committed
749
                    $feEditUrl = $this->createFormEditorUrl(FORM_NAME_FORM_ELEMENT, $formElement[FE_ID], ['formId' => $formElement[FE_FORM_ID]]);
750
751
                    $titleAttr = Support::doAttribute('title', $this->formSpec[FE_NAME] . ' / ' . $formElement[FE_NAME] . ' [' . $formElement[FE_ID] . ']');
                    $icon = Support::wrapTag('<span class="' . GLYPH_ICON . ' ' . GLYPH_ICON_EDIT . '">', '');
752
                    $elementHtml .= Support::wrapTag("<a class='hidden " . CLASS_FORM_ELEMENT_EDIT . "' href='$feEditUrl' $titleAttr>", $icon);
753
                }
754

755
756
                // Construct Marshaller Name: buildRow
                $buildRowName = 'buildRow' . $this->buildRowName[$formElement[FE_TYPE]];
757

758
                $html .= $formElement[FE_HTML_BEFORE] . $this->$buildRowName($formElement, $elementHtml, $htmlFormElementName) . $formElement[FE_HTML_AFTER];
759
            }
760
        }
761

762
763
        $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN, '', STORE_SYSTEM); // debug

764
765
766
        // Log / Debug: Last FormElement has been processed.
        $this->store->setVar(SYSTEM_FORM_ELEMENT, '', STORE_SYSTEM);

767
768
769
        return $html;
    }

770
    /**
Carsten  Rose's avatar
Carsten Rose committed
771
772
773
774
775
     * Checks if LDAP search is requested.
     * Yes: prepare configuration and fire the query.
     * No: do nothing.
     *
     * @param array $formElement
776
     *
Carsten  Rose's avatar
Carsten Rose committed
777
     * @return array
778
779
780
781
     * @throws CodeException
     * @throws DbException
     * @throws UserFormException
     * @throws UserReportException
Carsten  Rose's avatar
Carsten Rose committed
782
783
784
785
     */
    private function prepareFillStoreFireLdap(array $formElement) {

        if (isset($formElement[FE_FILL_STORE_LDAP]) || isset($formElement[FE_TYPEAHEAD_LDAP])) {
786
787
788
            $keyNames = [F_LDAP_SERVER, F_LDAP_BASE_DN, F_LDAP_ATTRIBUTES,
                F_LDAP_SEARCH, F_TYPEAHEAD_LDAP_SEARCH, F_TYPEAHEAD_LDAP_SEARCH_PER_TOKEN, F_TYPEAHEAD_LDAP_SEARCH_PREFETCH,
                F_TYPEAHEAD_LIMIT, F_TYPEAHEAD_MINLENGTH, F_TYPEAHEAD_LDAP_VALUE_PRINTF,
789
                F_TYPEAHEAD_LDAP_ID_PRINTF, F_LDAP_TIME_LIMIT, F_LDAP_USE_BIND_CREDENTIALS];
790
            $formElement = OnArray::copyArrayItemsIfNotAlreadyExist($this->formSpec, $formElement, $keyNames);
Carsten  Rose's avatar
Carsten Rose committed
791
792
793
794
795
796
797
        } else {
            return $formElement; // nothing to do.
        }

        if (isset($formElement[FE_FILL_STORE_LDAP])) {

            // Extract necessary elements
798
            $config = OnArray::getArrayItems($formElement, [FE_LDAP_SERVER, FE_LDAP_BASE_DN, FE_LDAP_SEARCH, FE_LDAP_ATTRIBUTES]);
799
800
801

            $this->store->setVar(SYSTEM_FORM_ELEMENT_COLUMN,
                FE_LDAP_SERVER . ',' . FE_LDAP_BASE_DN . ',' . FE_LDAP_SEARCH . ',' . FE_LDAP_ATTRIBUTES, STORE_SYSTEM);
Carsten  Rose's avatar
Carsten Rose committed
802
803
            $config = $this->evaluate->parseArray($config);

804
            if ($formElement[FE_LDAP_USE_BIND_CREDENTIALS] == 1) {
805
806
807
808
                $config[SYSTEM_LDAP_1_RDN] = $this->store->getVar(SYSTEM_LDAP_1_RDN, STORE_SYSTEM);
                $config[SYSTEM_LDAP_1_PASSWORD] = $this->store->getVar(SYSTEM_LDAP_1_PASSWORD, STORE_SYSTEM);
            }

Carsten  Rose's avatar
Carsten Rose committed
809
810
811
812
813
814
815
816
            $ldap = new Ldap();
            $arr = $ldap->process($config, '', MODE_LDAP_SINGLE);
            $this->store->setStore($arr, STORE_LDAP, true);
        }

        return $formElement;
    }

817
818
819
820
821
822
823
    /**
     * Check if there is an explicit 'autofocus' definition in at least one FE.
     * Found: do nothing, it will be rendered at the correct position.
     * Not found: set 'autofocus' on the first FE.
     *
     * Accepted misbehaviour on forms with pills: if there is at least one editable element on the first pill,
     *   the other pills are not checked - independent if there was a definition on the first pill or not.
824
825
     *   Reason: checks happens per pill - if there is no explizit definition on the first pill, take the first
     *   editable element of that pill.
826
827
828
829
830
831
832
833
834
835
836
837
838
     */
    private function checkAutoFocus() {
        static $found = false;
        $idx = false;

        if ($found) {
            return;
        }

        // Search if there is an explicit autofocus definition.
        for ($i = 0; $i < count($this->feSpecNative); ++$i) {
            // Only check native elements which will be shown
            if ($this->feSpecNative[$i][FE_CLASS] == FE_CLASS_NATIVE &&
839
840
                ($this->feSpecNative[$i][FE_MODE] == FE_MODE_SHOW || $this->feSpecNative[$i][FE_MODE] == FE_MODE_REQUIRED ||
                    $this->feSpecNative[$i][FE_MODE] == FE_MODE_SHOW_REQUIRED)
841
842
843
844
845
846
847
848
849
            ) {
                // Check if there is an explicit definition.
                if (isset($this->feSpecNative[$i][FE_AUTOFOCUS])) {
                    if ($this->feSpecNative[$i][FE_AUTOFOCUS] == '' || $this->feSpecNative[$i][FE_AUTOFOCUS] == '1') {
                        $this->feSpecNative[$i][FE_AUTOFOCUS] = '1'; // fix to '=1'
                    } else {
                        unset($this->feSpecNative[$i][FE_AUTOFOCUS]);
                    }
                    $found = true;
850