2009-11-01 10:42:45 +00:00
|
|
|
<?php
|
2011-11-02 09:26:31 +01:00
|
|
|
// This file is part of Moodle - http://moodle.org/
|
|
|
|
//
|
|
|
|
// Moodle is free software: you can redistribute it and/or modify
|
|
|
|
// it under the terms of the GNU General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// Moodle is distributed in the hope that it will be useful,
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU General Public License
|
|
|
|
// along with Moodle. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Security overview report
|
|
|
|
*
|
|
|
|
* @package report
|
|
|
|
* @subpackage security
|
|
|
|
* @copyright 2008 petr Skoda
|
|
|
|
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later
|
|
|
|
*/
|
2008-12-29 19:13:56 +00:00
|
|
|
|
2010-11-19 03:40:43 +00:00
|
|
|
define('NO_OUTPUT_BUFFERING', true);
|
|
|
|
|
2011-11-02 09:26:31 +01:00
|
|
|
require('../../config.php');
|
|
|
|
require_once($CFG->dirroot.'/report/security/locallib.php');
|
2008-12-29 19:13:56 +00:00
|
|
|
require_once($CFG->libdir.'/adminlib.php');
|
|
|
|
|
|
|
|
|
|
|
|
$issue = optional_param('issue', '', PARAM_ALPHANUMEXT); // show detailed info about one issue only
|
|
|
|
|
|
|
|
$issues = report_security_get_issue_list();
|
|
|
|
|
|
|
|
// test if issue valid string
|
|
|
|
if (array_search($issue, $issues, true) === false) {
|
|
|
|
$issue = '';
|
|
|
|
}
|
|
|
|
|
2009-01-27 15:06:40 +00:00
|
|
|
// we may need a bit more memory and this may take a long time to process
|
2010-10-19 10:13:15 +00:00
|
|
|
raise_memory_limit(MEMORY_EXTRA);
|
2013-10-15 13:22:19 +01:00
|
|
|
core_php_time_limit::raise();
|
2009-01-27 15:06:40 +00:00
|
|
|
|
2008-12-29 19:13:56 +00:00
|
|
|
// Print the header.
|
2011-11-20 18:58:49 +00:00
|
|
|
admin_externalpage_setup('reportsecurity', '', null, '', array('pagelayout'=>'report'));
|
2010-03-31 08:05:53 +00:00
|
|
|
echo $OUTPUT->header();
|
2008-12-29 19:13:56 +00:00
|
|
|
|
2010-08-12 18:18:47 +00:00
|
|
|
echo $OUTPUT->heading(get_string('pluginname', 'report_security'));
|
2008-12-29 19:13:56 +00:00
|
|
|
|
2009-01-27 16:21:56 +00:00
|
|
|
echo '<div id="timewarning">'.get_string('timewarning', 'report_security').'</div>';
|
|
|
|
|
2019-10-28 14:54:31 +01:00
|
|
|
$strok = '<span class="badge badge-success">'.get_string('statusok', 'report_security').'</span>';
|
|
|
|
$strinfo = '<span class="badge badge-info">'.get_string('statusinfo', 'report_security').'</span>';
|
|
|
|
$strwarning = '<span class="badge badge-warning">'.get_string('statuswarning', 'report_security').'</span>';
|
|
|
|
$strserious = '<span class="badge badge-danger">'.get_string('statusserious', 'report_security').'</span>';
|
|
|
|
$strcritical = '<span class="badge badge-danger">'.get_string('statuscritical', 'report_security').'</span>';
|
2008-12-29 19:13:56 +00:00
|
|
|
|
|
|
|
$strissue = get_string('issue', 'report_security');
|
|
|
|
$strstatus = get_string('status', 'report_security');
|
|
|
|
$strdesc = get_string('description', 'report_security');
|
|
|
|
$strconfig = get_string('configuration', 'report_security');
|
|
|
|
|
|
|
|
$statusarr = array(REPORT_SECURITY_OK => $strok,
|
|
|
|
REPORT_SECURITY_INFO => $strinfo,
|
|
|
|
REPORT_SECURITY_WARNING => $strwarning,
|
|
|
|
REPORT_SECURITY_SERIOUS => $strserious,
|
|
|
|
REPORT_SECURITY_CRITICAL => $strcritical);
|
|
|
|
|
2011-11-02 09:04:48 +01:00
|
|
|
$url = "$CFG->wwwroot/report/security/index.php";
|
2008-12-29 19:13:56 +00:00
|
|
|
|
|
|
|
if ($issue and ($result = $issue(true))) {
|
2009-01-27 16:21:56 +00:00
|
|
|
report_security_hide_timearning();
|
|
|
|
|
2009-08-20 08:39:07 +00:00
|
|
|
$table = new html_table();
|
2008-12-29 19:13:56 +00:00
|
|
|
$table->head = array($strissue, $strstatus, $strdesc, $strconfig);
|
2013-01-07 17:14:43 +08:00
|
|
|
$table->rowclasses = array('leftalign issue', 'leftalign status', 'leftalign desc', 'leftalign config');
|
|
|
|
$table->attributes = array('class'=>'admintable securityreport generaltable');
|
|
|
|
$table->id = 'securityissuereporttable';
|
2008-12-29 19:13:56 +00:00
|
|
|
$table->data = array();
|
|
|
|
|
|
|
|
// print detail of one issue only
|
|
|
|
$row = array();
|
2009-02-15 09:45:34 +00:00
|
|
|
$row[0] = report_security_doc_link($issue, $result->name);
|
2008-12-29 19:13:56 +00:00
|
|
|
$row[1] = $statusarr[$result->status];
|
|
|
|
$row[2] = $result->info;
|
2009-01-15 18:30:26 +00:00
|
|
|
$row[3] = is_null($result->link) ? ' ' : $result->link;
|
2008-12-29 19:13:56 +00:00
|
|
|
|
2011-11-02 09:04:48 +01:00
|
|
|
$PAGE->set_docs_path('report/security/' . $issue);
|
2009-02-19 07:32:23 +00:00
|
|
|
|
2008-12-29 19:13:56 +00:00
|
|
|
$table->data[] = $row;
|
|
|
|
|
2010-03-20 22:15:54 +00:00
|
|
|
echo html_writer::table($table);
|
2008-12-29 19:13:56 +00:00
|
|
|
|
2009-08-10 04:53:22 +00:00
|
|
|
echo $OUTPUT->box($result->details, 'generalbox boxwidthnormal boxaligncenter'); // TODO: add proper css
|
2008-12-29 19:13:56 +00:00
|
|
|
|
2009-08-18 04:28:40 +00:00
|
|
|
echo $OUTPUT->continue_button($url);
|
2008-12-29 19:13:56 +00:00
|
|
|
|
|
|
|
} else {
|
2009-01-27 16:21:56 +00:00
|
|
|
report_security_hide_timearning();
|
|
|
|
|
2009-08-20 08:39:07 +00:00
|
|
|
$table = new html_table();
|
2008-12-29 19:13:56 +00:00
|
|
|
$table->head = array($strissue, $strstatus, $strdesc);
|
2013-01-07 17:14:43 +08:00
|
|
|
$table->colclasses = array('leftalign issue', 'leftalign status', 'leftalign desc');
|
|
|
|
$table->attributes = array('class'=>'admintable securityreport generaltable');
|
|
|
|
$table->id = 'securityreporttable';
|
2008-12-29 19:13:56 +00:00
|
|
|
$table->data = array();
|
|
|
|
|
|
|
|
foreach ($issues as $issue) {
|
|
|
|
$result = $issue(false);
|
|
|
|
if (!$result) {
|
|
|
|
// ignore this test
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
$row = array();
|
|
|
|
$row[0] = "<a href='$url?issue=$result->issue'>$result->name</a>";
|
|
|
|
$row[1] = $statusarr[$result->status];
|
|
|
|
$row[2] = $result->info;
|
|
|
|
|
|
|
|
$table->data[] = $row;
|
|
|
|
}
|
2010-03-20 22:15:54 +00:00
|
|
|
echo html_writer::table($table);
|
2008-12-29 19:13:56 +00:00
|
|
|
}
|
|
|
|
|
2009-08-06 14:12:46 +00:00
|
|
|
echo $OUTPUT->footer();
|