Bug 25898: Prohibit indirect object notation
[koha.git] / opac / opac-search-history.pl
bloba9a4a73cea1fe24d55fe0f529c86184e3768c4e5
1 #!/usr/bin/perl
3 # Copyright 2013 BibLibre SARL
5 # This file is part of Koha.
7 # Koha is free software; you can redistribute it and/or modify it
8 # under the terms of the GNU General Public License as published by
9 # the Free Software Foundation; either version 3 of the License, or
10 # (at your option) any later version.
12 # Koha is distributed in the hope that it will be useful, but
13 # WITHOUT ANY WARRANTY; without even the implied warranty of
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 # GNU General Public License for more details.
17 # You should have received a copy of the GNU General Public License
18 # along with Koha; if not, see <http://www.gnu.org/licenses>.
20 use Modern::Perl;
22 use C4::Auth qw(:DEFAULT get_session);
23 use CGI qw ( -utf8 );
24 use C4::Context;
25 use C4::Output;
26 use C4::Log;
27 use C4::Items;
28 use C4::Debug;
29 use C4::Search::History;
31 use URI::Escape;
32 use POSIX qw(strftime);
35 my $cgi = CGI->new;
37 # Getting the template and auth
38 my ($template, $loggedinuser, $cookie) = get_template_and_user(
40 template_name => "opac-search-history.tt",
41 query => $cgi,
42 type => "opac",
43 authnotrequired => ( C4::Context->preference("OpacPublic") ? 1 : 0 ),
44 debug => 1,
48 unless ( C4::Context->preference("EnableOpacSearchHistory") ) {
49 print $cgi->redirect("/cgi-bin/koha/errors/404.pl"); # escape early
50 exit;
53 my $type = $cgi->param('type');
54 my $action = $cgi->param('action') || q{};
55 my $previous = $cgi->param('previous');
57 # If the user is not logged in, we deal with the session
58 unless ( $loggedinuser ) {
59 # Deleting search history
60 if ( $action eq 'delete') {
61 # Deleting session's search history
62 my @id = $cgi->multi_param('id');
63 my $all = not scalar( @id );
65 my $type = $cgi->param('type');
66 my @searches = ();
67 unless ( $all ) {
68 @searches = C4::Search::History::get_from_session({ cgi => $cgi });
69 if ( $type ) {
70 @searches = map { $_->{type} ne $type ? $_ : () } @searches;
72 if ( @id ) {
73 @searches = map { my $search = $_; ( grep { $_ eq $search->{id} } @id ) ? () : $_ } @searches;
76 C4::Search::History::set_to_session({ cgi => $cgi, search_history => \@searches });
78 # Redirecting to this same url so the user won't see the search history link in the header
79 print $cgi->redirect(-uri => '/cgi-bin/koha/opac-search-history.pl');
80 # Showing search history
81 } else {
82 # Getting the searches from session
83 my @current_searches = C4::Search::History::get_from_session({
84 cgi => $cgi,
85 });
87 my @current_biblio_searches = map {
88 $_->{type} eq 'biblio' ? $_ : ()
89 } @current_searches;
91 my @current_authority_searches = map {
92 $_->{type} eq 'authority' ? $_ : ()
93 } @current_searches;
95 $template->param(
96 current_biblio_searches => \@current_biblio_searches,
97 current_authority_searches => \@current_authority_searches,
100 } else {
101 # And if the user is logged in, we deal with the database
102 my $dbh = C4::Context->dbh;
104 # Deleting search history
105 if ( $action eq 'delete' ) {
106 my @id = $cgi->multi_param('id');
107 if ( @id ) {
108 C4::Search::History::delete(
110 userid => $loggedinuser,
111 id => [ $cgi->param('id') ],
114 } else {
115 C4::Search::History::delete(
117 userid => $loggedinuser,
121 # Redirecting to this same url so the user won't see the search history link in the header
122 print $cgi->redirect(-uri => '/cgi-bin/koha/opac-search-history.pl');
124 # Showing search history
125 } else {
126 my $current_searches = C4::Search::History::get({
127 userid => $loggedinuser,
128 sessionid => $cgi->cookie("CGISESSID")
130 my @current_biblio_searches = map {
131 $_->{type} eq 'biblio' ? $_ : ()
132 } @$current_searches;
134 my @current_authority_searches = map {
135 $_->{type} eq 'authority' ? $_ : ()
136 } @$current_searches;
138 my $previous_searches = C4::Search::History::get({
139 userid => $loggedinuser,
140 sessionid => $cgi->cookie("CGISESSID"),
141 previous => 1
144 my @previous_biblio_searches = map {
145 $_->{type} eq 'biblio' ? $_ : ()
146 } @$previous_searches;
148 my @previous_authority_searches = map {
149 $_->{type} eq 'authority' ? $_ : ()
150 } @$previous_searches;
152 $template->param(
153 current_biblio_searches => \@current_biblio_searches,
154 current_authority_searches => \@current_authority_searches,
155 previous_biblio_searches => \@previous_biblio_searches,
156 previous_authority_searches => \@previous_authority_searches,
162 $template->param(searchhistoryview => 1);
164 output_html_with_http_headers $cgi, $cookie, $template->output, undef, { force_no_caching => 1 };