X-Git-Url: http://git.rot13.org/?a=blobdiff_plain;f=opac%2Fopac-sendbasket.pl;h=09c462c8dc88e8468ab82318715a4a3611f27748;hb=69f74104d5e705b95d8207e61fedfbd71ca2e673;hp=57d2c7924b69ab35d6204c4e43f5f58a1d7356cf;hpb=fffe2ccbf514918ad536d88fe79ce00bef27c389;p=koha.git diff --git a/opac/opac-sendbasket.pl b/opac/opac-sendbasket.pl index 57d2c7924b..09c462c8dc 100755 --- a/opac/opac-sendbasket.pl +++ b/opac/opac-sendbasket.pl @@ -4,70 +4,78 @@ # # This file is part of Koha. # -# Koha is free software; you can redistribute it and/or modify it under the -# terms of the GNU General Public License as published by the Free Software -# Foundation; either version 2 of the License, or (at your option) any later -# version. +# Koha is free software; you can redistribute it and/or modify it +# under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 3 of the License, or +# (at your option) any later version. # -# Koha is distributed in the hope that it will be useful, but WITHOUT ANY -# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR -# A PARTICULAR PURPOSE. See the GNU General Public License for more details. +# Koha is distributed in the hope that it will be useful, but +# WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. # -# You should have received a copy of the GNU General Public License along -# with Koha; if not, write to the Free Software Foundation, Inc., -# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. +# You should have received a copy of the GNU General Public License +# along with Koha; if not, see . -use strict; -use warnings; +use Modern::Perl; -use CGI; +use CGI qw ( -utf8 ); use Encode qw(encode); use Carp; - use Mail::Sendmail; use MIME::QuotedPrint; use MIME::Base64; + use C4::Biblio; use C4::Items; use C4::Auth; use C4::Output; -use C4::Biblio; use C4::Members; +use C4::Templates (); +use Koha::Email; +use Koha::Patrons; +use Koha::Token; my $query = new CGI; my ( $template, $borrowernumber, $cookie ) = get_template_and_user ( { - template_name => "opac-sendbasketform.tmpl", + template_name => "opac-sendbasketform.tt", query => $query, type => "opac", authnotrequired => 0, - flagsrequired => { borrow => 1 }, } ); -my $bib_list = $query->param('bib_list'); +my $bib_list = $query->param('bib_list') || ''; my $email_add = $query->param('email_add'); -my $email_sender = $query->param('email_sender'); my $dbh = C4::Context->dbh; if ( $email_add ) { - my $email_from = C4::Context->preference('KohaAdminEmailAddress'); + die "Wrong CSRF token" unless Koha::Token->new->check_csrf({ + session_id => scalar $query->cookie('CGISESSID'), + token => scalar $query->param('csrf_token'), + }); + my $email = Koha::Email->new(); + my $patron = Koha::Patrons->find( $borrowernumber ); + my $user_email = $patron->first_valid_email_address + || C4::Context->preference('KohaAdminEmailAddress'); + + my $email_replyto = $patron->firstname . " " . $patron->surname . " <$user_email>"; my $comment = $query->param('comment'); - my %mail = ( - To => $email_add, - From => $email_from - ); - my ( $template2, $borrowernumber, $cookie ) = get_template_and_user( - { - template_name => "opac-sendbasket.tmpl", - query => $query, - type => "opac", - authnotrequired => 1, - flagsrequired => { borrow => 1 }, - } + # if you want to use the KohaAdmin address as from, that is the default no need to set it + my %mail = $email->create_message_headers({ + to => $email_add, + replyto => $email_replyto, + }); + $mail{'X-Abuse-Report'} = C4::Context->preference('KohaAdminEmailAddress'); + + # Since we are already logged in, no need to check credentials again + # when loading a second template. + my $template2 = C4::Templates::gettemplate( + 'opac-sendbasket.tt', 'opac', $query, ); my @bibs = split( /\//, $bib_list ); @@ -78,8 +86,10 @@ if ( $email_add ) { $template2->param( biblionumber => $biblionumber ); my $dat = GetBiblioData($biblionumber); - my $record = GetMarcBiblio($biblionumber); - my $marcnotesarray = GetMarcNotes( $record, $marcflavour ); + next unless $dat; + my $record = GetMarcBiblio({ + biblionumber => $biblionumber, + embed_items => 1 }); my $marcauthorsarray = GetMarcAuthors( $record, $marcflavour ); my $marcsubjctsarray = GetMarcSubjects( $record, $marcflavour ); @@ -91,7 +101,6 @@ if ( $email_add ) { } - $dat->{MARCNOTES} = $marcnotesarray; $dat->{MARCSUBJCTS} = $marcsubjctsarray; $dat->{MARCAUTHORS} = $marcauthorsarray; $dat->{HASAUTHORS} = $hasauthors; @@ -105,14 +114,11 @@ if ( $email_add ) { my $resultsarray = \@results; - my $user = GetMember(borrowernumber => $borrowernumber); - $template2->param( BIBLIO_RESULTS => $resultsarray, - email_sender => $email_sender, comment => $comment, - firstname => $user->{firstname}, - surname => $user->{surname}, + firstname => $patron->firstname, + surname => $patron->surname, ); # Getting template result @@ -120,39 +126,44 @@ if ( $email_add ) { my $body; # Analysing information and getting mail properties - if ( $template_res =~ /\n(.*)\n/s ) { - $mail{'subject'} = $1; + + if ( $template_res =~ /(.*)/s ) { + $mail{subject} = $1; + $mail{subject} =~ s|\n?(.*)\n?|$1|; + $mail{subject} = Encode::encode("UTF-8", $mail{subject}); } else { $mail{'subject'} = "no subject"; } my $email_header = ""; - if ( $template_res =~ /
\n(.*)\n/s ) { + if ( $template_res =~ /
(.*)/s ) { $email_header = $1; + $email_header =~ s|\n?(.*)\n?|$1|; + $email_header = encode_qp(Encode::encode("UTF-8", $email_header)); } my $email_file = "basket.txt"; - if ( $template_res =~ /\n(.*)\n/s ) { + if ( $template_res =~ /(.*)/s ) { $email_file = $1; + $email_file =~ s|\n?(.*)\n?|$1|; + } + + if ( $template_res =~ /(.*)/s ) { + $body = $1; + $body =~ s|\n?(.*)\n?|$1|; + $body = encode_qp(Encode::encode("UTF-8", $body)); } - if ( $template_res =~ /\n(.*)\n/s ) { $body = encode_qp($1); } + $mail{body} = $body; my $boundary = "====" . time() . "===="; - # $mail{'content-type'} = "multipart/mixed; boundary=\"$boundary\""; - # - # $email_header = encode_qp($email_header); - # - # $boundary = "--".$boundary; - # - # # Writing mail - # $mail{body} = $mail{'content-type'} = "multipart/mixed; boundary=\"$boundary\""; my $isofile = encode_base64(encode("UTF-8", $iso2709)); $boundary = '--' . $boundary; $mail{body} = <param( SENT => "1" ); } else { # do something if it doesnt work.... - carp "Error sending mail: $Mail::Sendmail::error \n"; + carp "Error sending mail: empty basket" if !defined($iso2709); + carp "Error sending mail: $Mail::Sendmail::error" if $Mail::Sendmail::error; $template->param( error => 1 ); } $template->param( email_add => $email_add ); output_html_with_http_headers $query, $cookie, $template->output; } else { - $template->param( bib_list => $bib_list ); + my $new_session_id = $cookie->value; $template->param( + bib_list => $bib_list, url => "/cgi-bin/koha/opac-sendbasket.pl", suggestion => C4::Context->preference("suggestion"), virtualshelves => C4::Context->preference("virtualshelves"), + csrf_token => Koha::Token->new->generate_csrf( + { session_id => $new_session_id, } ), ); output_html_with_http_headers $query, $cookie, $template->output; }