4 * This is called as a pop-up to display patient education materials.
7 * @link http://www.open-emr.org
8 * @author Rod Roark <rod@sunsetsystems.com>
9 * @author Brady Miller <brady.g.miller@gmail.com>
10 * @copyright Copyright (c) 2014 Rod Roark <rod@sunsetsystems.com>
11 * @copyright Copyright (c) 2017-2018 Brady Miller <brady.g.miller@gmail.com>
12 * @license https://github.com/openemr/openemr/blob/master/LICENSE GNU General Public License 3
15 require_once("../globals.php");
16 require_once("$srcdir/options.inc.php");
18 use OpenEMR\Common\Csrf\CsrfUtils
;
19 use OpenEMR\Core\Header
;
21 $educationdir = "$OE_SITE_DIR/documents/education";
23 $codetype = empty($_REQUEST['type' ]) ?
'' : $_REQUEST['type' ];
24 $codevalue = empty($_REQUEST['code' ]) ?
'' : $_REQUEST['code' ];
25 $language = empty($_REQUEST['language']) ?
'' : strtolower($_REQUEST['language']);
26 $source = empty($_REQUEST['source' ]) ?
'' : $_REQUEST['source' ];
30 if (!empty($_POST['bn_submit'])) {
31 if (!CsrfUtils
::verifyCsrfToken($_POST["csrf_token_form"])) {
32 CsrfUtils
::csrfNotVerified();
35 if ($source == 'MLP') {
36 // MedlinePlus Connect Web Application. See:
37 // https://www.nlm.nih.gov/medlineplus/connect/application.html
38 $url = 'https://connect.medlineplus.gov/application';
39 // Set code type in URL.
40 $url .= '?mainSearchCriteria.v.cs=';
41 if ('ICD9' == $codetype) {
42 $url .= '2.16.840.1.113883.6.103';
43 } elseif ('ICD10' == $codetype) {
44 $url .= '2.16.840.1.113883.6.90' ;
45 } elseif ('SNOMED' == $codetype) {
46 $url .= '2.16.840.1.113883.6.96' ;
47 } elseif ('RXCUI' == $codetype) {
48 $url .= '2.16.840.1.113883.6.88' ;
49 } elseif ('NDC' == $codetype) {
50 $url .= '2.16.840.1.113883.6.69' ;
51 } elseif ('LOINC' == $codetype) {
52 $url .= '2.16.840.1.113883.6.1' ;
54 die(xlt('Code type not recognized') . ': ' . text($codetype));
57 // Set code value in URL.
58 $url .= '&mainSearchCriteria.v.c=' . urlencode($codevalue);
59 // Set language in URL if relevant. MedlinePlus supports only English or Spanish.
60 if ($language == 'es' ||
$language == 'spanish') {
61 $url .= '&informationRecipient.languageCode.c=es';
64 // There are 2 different ways to get the data: have the server do it, or
65 // have the browser do it.
67 $data = file_get_contents($url);
69 } else { // Removed opener because this is not a dialog. sjp 12/14/17
71 //."<script type=\"text/javascript\" src=\"". $webroot ."/interface/main/tabs/js/include_opener.js\"></script>"
73 echo "document.location.href = " . js_escape($url) . ";\n";
74 echo "</script></body></html>\n";
80 if ($language == 'es' ||
$language == 'spanish') {
84 $filename = strtolower("{$codetype}_{$codevalue}_{$lang}.pdf");
85 $filepath = "$educationdir/$filename";
86 if (is_file($filepath)) {
87 header('Content-Description: File Transfer');
88 header('Content-Transfer-Encoding: binary');
90 header('Cache-Control: must-revalidate, post-check=0, pre-check=0');
91 header('Pragma: public');
92 // attachment, not inline
93 header("Content-Disposition: attachment; filename=\"$filename\"");
94 header("Content-Type: application/pdf");
95 header("Content-Length: " . filesize($filepath));
101 $errmsg = xl('There is no local content for this topic.');
109 <title
><?php
echo xlt('Education'); ?
></title
>
111 <?php Header
::setupHeader(); ?
>
115 <div
class="container mt-3">
120 echo xlt('Educational materials for');
121 echo ' ' . text($codetype) . ' ';
123 echo ' "' . text($codevalue) . '"';
125 echo ' ' . xlt('with preferred language') . ' ' .
126 text(getListItemTitle('language', $_REQUEST['language']));
132 echo "<p class='text-danger'>" . text($errmsg) . "</p>\n";
139 <form method
='post' action
='education.php' onsubmit
='return top.restoreSession()'>
140 <input type
="hidden" name
="csrf_token_form" value
="<?php echo attr(CsrfUtils::collectCsrfToken()); ?>" />
141 <input type
='hidden' name
='type' value
='<?php echo attr($codetype); ?>' />
142 <input type
='hidden' name
='code' value
='<?php echo attr($codevalue); ?>' />
143 <input type
='hidden' name
='language' value
='<?php echo attr($language); ?>' />
144 <div
class='form-group'>
145 <label
for="source"><?php
echo xlt('Select source'); ?
></label
>
146 <select name
='source' id
='source' class='form-control'>
147 <option value
='MLP'><?php
echo xlt('MedlinePlus Connect'); ?
></option
>
148 <option value
='Local'><?php
echo xlt('Local Content'); ?
></option
>
151 <div
class='form-group'>
152 <div
class='btn-group' role
='group'>
153 <button type
='submit' class='btn btn-primary btn-search' name
='bn_submit' value
='bn_submit'>
154 <?php
echo xlt('Submit'); ?
>
156 <button type
='button' class='btn btn-secondary btn-cancel' onclick
='window.close()'>
157 <?php
echo xlt('Cancel'); ?
>