04/28 Fixed some security issues
This commit is contained in:
@@ -60,24 +60,24 @@ class SecurityManager:
|
||||
self.register_security_routes()
|
||||
|
||||
def setup_encryption(self):
|
||||
"""Setup encryption for sensitive data"""
|
||||
"""Setup encryption for sensitive data.
|
||||
|
||||
Derives a stable Fernet key from the app's SECRET_KEY so that all
|
||||
gunicorn workers share the same key without needing a separate
|
||||
ENCRYPTION_KEY env var. A random key is only generated as a last
|
||||
resort (dev mode without SECRET_KEY set).
|
||||
"""
|
||||
if HAS_CRYPTOGRAPHY:
|
||||
encryption_key = self.app.config.get('ENCRYPTION_KEY')
|
||||
if not encryption_key:
|
||||
# Generate a new key (should be stored securely in production)
|
||||
encryption_key = Fernet.generate_key()
|
||||
if self.logger_handler:
|
||||
self.logger_handler.logger.warning(
|
||||
"Generated new encryption key - store this securely!"
|
||||
)
|
||||
|
||||
# Derive a deterministic 32-byte key from SECRET_KEY so every
|
||||
# worker produces the same value — no per-worker randomness.
|
||||
secret = self.app.config.get('SECRET_KEY', '')
|
||||
derived = hashlib.sha256(secret.encode()).digest()
|
||||
encryption_key = base64.urlsafe_b64encode(derived)
|
||||
self.cipher = Fernet(encryption_key)
|
||||
else:
|
||||
self.cipher = None
|
||||
if self.logger_handler:
|
||||
self.logger_handler.logger.warning(
|
||||
"Cryptography not available - encryption features disabled"
|
||||
)
|
||||
|
||||
def security_check(self):
|
||||
"""Comprehensive security check before each request"""
|
||||
@@ -93,11 +93,11 @@ class SecurityManager:
|
||||
})
|
||||
return jsonify({'error': 'Request blocked for security reasons'}), 403
|
||||
|
||||
# Validate session security
|
||||
if 'user_id' in session:
|
||||
if not self.validate_session_security():
|
||||
session.clear()
|
||||
return jsonify({'error': 'Session security validation failed'}), 401
|
||||
# NOTE: per-worker in-memory session token validation removed.
|
||||
# Flask's cryptographically signed session cookie provides session
|
||||
# integrity; CSRF tokens handle cross-site forgery. Keeping the
|
||||
# validate_session_security() call here would log users out on every
|
||||
# gunicorn worker boundary because session_tokens is not shared.
|
||||
|
||||
# Check for SQL injection attempts
|
||||
if self.detect_sql_injection():
|
||||
@@ -213,8 +213,19 @@ class SecurityManager:
|
||||
check_data.extend(request.args.values())
|
||||
check_data.extend(request.form.values())
|
||||
|
||||
if request.json:
|
||||
check_data.extend(str(v) for v in request.json.values() if isinstance(v, (str, int, float)))
|
||||
# Only attempt JSON parsing when the client declared application/json.
|
||||
# Calling request.json without this guard raises a 415 Unsupported Media Type
|
||||
# on every non-JSON request (GET pages, form POSTs, favicon, etc.).
|
||||
if request.content_type and 'application/json' in request.content_type:
|
||||
try:
|
||||
json_body = request.get_json(silent=True, force=False)
|
||||
if json_body and isinstance(json_body, dict):
|
||||
check_data.extend(
|
||||
str(v) for v in json_body.values()
|
||||
if isinstance(v, (str, int, float))
|
||||
)
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
for data in check_data:
|
||||
data_str = str(data).lower()
|
||||
|
||||
@@ -99,7 +99,45 @@ def create_app() -> Flask:
|
||||
from extensions import logger_handler as _lh
|
||||
create_location_logging_routes(app, db, _lh)
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Security: CSRF protection + rate-limiting via SecurityManager
|
||||
# ------------------------------------------------------------------
|
||||
from advanced_security_middleware import SecurityManager, generate_csrf_token
|
||||
from extensions import logger_handler as _lh2
|
||||
security_manager = SecurityManager()
|
||||
security_manager.init_app(app, db, _lh2)
|
||||
|
||||
# Endpoints exempt from CSRF validation:
|
||||
# - login / register (no session token exists yet)
|
||||
# - qr_checkin (public, unauthenticated QR scan endpoint)
|
||||
_CSRF_EXEMPT = {'auth.login', 'auth.register', 'qr_codes.qr_checkin', 'static'}
|
||||
|
||||
@app.before_request
|
||||
def csrf_protect():
|
||||
"""Validate CSRF token on every state-mutating request."""
|
||||
if request.method not in ('POST', 'PUT', 'PATCH', 'DELETE'):
|
||||
return
|
||||
if request.endpoint in _CSRF_EXEMPT:
|
||||
return
|
||||
token = (request.form.get('csrf_token')
|
||||
or request.headers.get('X-CSRF-Token'))
|
||||
expected = session.get('csrf_token')
|
||||
import hmac as _hmac
|
||||
if not token or not expected or not _hmac.compare_digest(token, expected):
|
||||
_lh2.logger.warning(
|
||||
f"CSRF validation failed | endpoint={request.endpoint} "
|
||||
f"| ip={request.remote_addr} | user={session.get('username','anon')}"
|
||||
)
|
||||
from flask import abort
|
||||
abort(403)
|
||||
|
||||
# Make generate_csrf_token() available in every template as csrf_token()
|
||||
@app.context_processor
|
||||
def inject_csrf_token():
|
||||
return {'csrf_token': generate_csrf_token}
|
||||
|
||||
# Expose security_manager to routes that need it (login rate-limiting)
|
||||
app.security_manager = security_manager
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Template filters (global — must be on app, not blueprints)
|
||||
|
||||
@@ -66,3 +66,5 @@ cryptography==44.0.0 # Required for MySQL SSL connections
|
||||
|
||||
# Employee Synchronization Dependencies
|
||||
schedule==1.2.2 # For automated scheduling
|
||||
|
||||
jwt
|
||||
+22
-1
@@ -28,6 +28,8 @@ def index():
|
||||
return redirect(url_for('auth.login'))
|
||||
|
||||
@bp.route('/register', methods=['GET', 'POST'], endpoint='register')
|
||||
@login_required
|
||||
@admin_required
|
||||
@log_user_activity('user_registration')
|
||||
def register():
|
||||
"""User registration endpoint"""
|
||||
@@ -84,6 +86,18 @@ def login():
|
||||
flash('Please enter both username and password.', 'error')
|
||||
return render_template('login.html')
|
||||
|
||||
# Rate-limit check — blocks IPs with 5+ failed attempts in 15 minutes
|
||||
from flask import current_app
|
||||
sec_mgr = getattr(current_app, 'security_manager', None)
|
||||
if sec_mgr and sec_mgr.is_auth_rate_limited():
|
||||
logger_handler.log_security_event(
|
||||
event_type="login_rate_limited",
|
||||
description=f"Login blocked by rate limiter for username: {username}",
|
||||
severity="HIGH"
|
||||
)
|
||||
flash('Too many failed attempts. Please wait 15 minutes before trying again.', 'error')
|
||||
return render_template('login.html')
|
||||
|
||||
# Verify Turnstile if enabled
|
||||
if turnstile_utils.is_enabled():
|
||||
if not turnstile_utils.verify_turnstile(turnstile_response):
|
||||
@@ -126,6 +140,10 @@ def login():
|
||||
session['full_name'] = user.full_name
|
||||
session['login_time'] = datetime.now().isoformat()
|
||||
|
||||
# Create a secure session token (also clears failed attempts for this IP)
|
||||
if sec_mgr:
|
||||
sec_mgr.create_secure_session(user.id)
|
||||
|
||||
# Update last login date
|
||||
user.last_login_date = datetime.utcnow()
|
||||
db.session.commit()
|
||||
@@ -162,7 +180,10 @@ def login():
|
||||
return redirect(url_for('attendance.attendance_report'))
|
||||
|
||||
else:
|
||||
# Invalid credentials - log failed attempt
|
||||
# Invalid credentials — record failed attempt for rate limiting
|
||||
if sec_mgr:
|
||||
sec_mgr.record_failed_attempt(username)
|
||||
|
||||
user_id = user.id if user else None
|
||||
logger_handler.log_user_login(
|
||||
user_id=user_id,
|
||||
|
||||
@@ -420,6 +420,7 @@ function deleteRecord(recordId, employeeId) {
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
})
|
||||
.then((response) => response.json())
|
||||
|
||||
@@ -142,6 +142,7 @@ class ProjectDashboardManager {
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
});
|
||||
|
||||
@@ -348,6 +349,7 @@ class ProjectDashboardManager {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
});
|
||||
|
||||
@@ -376,6 +378,7 @@ class ProjectDashboardManager {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
});
|
||||
|
||||
@@ -528,6 +531,7 @@ class ProjectDashboardManager {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/x-www-form-urlencoded",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
});
|
||||
|
||||
|
||||
+4
-1
@@ -447,10 +447,13 @@ class QRManager {
|
||||
|
||||
// AJAX Helper
|
||||
async makeRequest(url, options = {}) {
|
||||
// Read the CSRF token injected by Flask into window.qrConfig
|
||||
const csrfToken = (window.qrConfig && window.qrConfig.csrfToken) || '';
|
||||
const defaultOptions = {
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-Requested-With': 'XMLHttpRequest'
|
||||
'X-Requested-With': 'XMLHttpRequest',
|
||||
'X-CSRF-Token': csrfToken
|
||||
},
|
||||
...options
|
||||
};
|
||||
|
||||
@@ -223,6 +223,7 @@ class UsersManager {
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
});
|
||||
|
||||
@@ -248,6 +249,7 @@ class UsersManager {
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
});
|
||||
|
||||
@@ -280,6 +282,7 @@ class UsersManager {
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
});
|
||||
|
||||
@@ -312,6 +315,7 @@ class UsersManager {
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
});
|
||||
|
||||
@@ -346,6 +350,7 @@ class UsersManager {
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
});
|
||||
|
||||
@@ -487,6 +492,7 @@ class UsersManager {
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
user_ids: Array.from(this.selectedUsers),
|
||||
@@ -529,6 +535,7 @@ class UsersManager {
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
user_ids: Array.from(this.selectedUsers),
|
||||
@@ -571,6 +578,7 @@ class UsersManager {
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
user_ids: Array.from(this.selectedUsers),
|
||||
|
||||
@@ -213,6 +213,7 @@
|
||||
</div>
|
||||
|
||||
<form id="manualAttendanceForm" method="POST" action="{{ url_for('attendance.save_manual_attendance') }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- Employee Selection with Autocomplete -->
|
||||
<div class="form-group">
|
||||
<label for="employee_search">
|
||||
|
||||
@@ -592,6 +592,7 @@ Management{% endblock %} {% block extra_head %}
|
||||
method: "GET",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
});
|
||||
|
||||
@@ -1050,6 +1051,7 @@ ${
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
});
|
||||
|
||||
@@ -1096,6 +1098,7 @@ ${
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
body: JSON.stringify({ days_to_keep: daysToKeep }),
|
||||
});
|
||||
@@ -1155,6 +1158,7 @@ ${
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
body: JSON.stringify({ days_threshold: daysThreshold }),
|
||||
});
|
||||
|
||||
@@ -673,7 +673,8 @@ function deleteRecord(recordId, employeeId) {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-Requested-With': 'XMLHttpRequest'
|
||||
'X-Requested-With': 'XMLHttpRequest',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || ''
|
||||
}
|
||||
})
|
||||
.then(response => response.json())
|
||||
|
||||
@@ -129,6 +129,7 @@
|
||||
</div>
|
||||
<div class="import-body">
|
||||
<form id="importForm" method="POST" enctype="multipart/form-data" action="{{ url_for('qr_codes.import_bulk_qr_codes') }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- File Upload Area -->
|
||||
<div class="file-upload-area" id="fileUploadArea">
|
||||
<div class="upload-icon">
|
||||
@@ -234,6 +235,7 @@
|
||||
<p>All {{ validation_result.valid_rows }} records are valid and ready to import.</p>
|
||||
</div>
|
||||
<form method="POST" action="{{ url_for('qr_codes.import_bulk_qr_codes') }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="proceed_import" value="true">
|
||||
<button type="submit" class="btn btn-success">
|
||||
<i class="fas fa-check"></i>
|
||||
|
||||
@@ -381,6 +381,7 @@ endblock %} {% block extra_head %}
|
||||
</a>
|
||||
|
||||
<form method="POST" style="display: inline" id="deleteForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<button type="button" class="btn btn-delete-confirm" id="deleteBtn">
|
||||
<i class="fas fa-trash"></i>
|
||||
Delete Permanently
|
||||
|
||||
@@ -195,6 +195,7 @@
|
||||
|
||||
<div class="form-body">
|
||||
<form method="POST" id="createEmployeeForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- Employee ID and Contract ID Row -->
|
||||
<div class="form-row">
|
||||
<div class="form-group">
|
||||
|
||||
@@ -29,6 +29,7 @@
|
||||
|
||||
<div style="padding: 1.5rem;">
|
||||
<form method="POST" id="createProjectForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<div style="max-width: 600px;">
|
||||
<!-- Project Name -->
|
||||
<div class="form-group" style="margin-bottom: 1.5rem;">
|
||||
|
||||
@@ -564,6 +564,7 @@
|
||||
</div>
|
||||
|
||||
<form method="POST" class="form" id="createQRForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- Basic Information Section -->
|
||||
<div class="form-section">
|
||||
<div class="section-header">
|
||||
@@ -1225,6 +1226,7 @@
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({ address: address })
|
||||
})
|
||||
|
||||
@@ -17,6 +17,7 @@ Code Management{% endblock %} {% block content %}
|
||||
method="POST"
|
||||
action="{{ url_for('users.create_user') }}"
|
||||
>
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<div class="form-section">
|
||||
<h3>
|
||||
<i class="fas fa-user"></i>
|
||||
@@ -463,6 +464,7 @@ Code Management{% endblock %} {% block content %}
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({ project_ids: projectIds })
|
||||
});
|
||||
|
||||
@@ -145,6 +145,7 @@
|
||||
</div>
|
||||
|
||||
<form method="POST" action="{{ url_for('attendance.edit_attendance', record_id=attendance_record.id) }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
|
||||
<!-- Audit Note Section -->
|
||||
<div class="audit-note-section">
|
||||
|
||||
@@ -198,6 +198,7 @@
|
||||
|
||||
<div class="form-body">
|
||||
<form method="POST" id="editEmployeeForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- Employee ID and Contract ID Row -->
|
||||
<div class="form-row">
|
||||
<div class="form-group">
|
||||
|
||||
@@ -67,6 +67,7 @@
|
||||
|
||||
<div style="padding: 1.5rem;">
|
||||
<form method="POST" id="editProjectForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<div style="max-width: 600px;">
|
||||
<!-- Project Name -->
|
||||
<div class="form-group" style="margin-bottom: 1.5rem; position: relative;">
|
||||
|
||||
+265
-188
@@ -289,7 +289,7 @@
|
||||
background: var(--primary-color);
|
||||
cursor: pointer;
|
||||
border: 2px solid white;
|
||||
box-shadow: 0 2px 4px rgba(0, 0, 0, 0.2);
|
||||
box-shadow: 0 2px 4px rgba(0,0,0,0.2);
|
||||
}
|
||||
|
||||
.range-input-group input[type="range"]::-moz-range-thumb {
|
||||
@@ -299,7 +299,7 @@
|
||||
background: var(--primary-color);
|
||||
cursor: pointer;
|
||||
border: 2px solid white;
|
||||
box-shadow: 0 2px 4px rgba(0, 0, 0, 0.2);
|
||||
box-shadow: 0 2px 4px rgba(0,0,0,0.2);
|
||||
}
|
||||
|
||||
.range-value {
|
||||
@@ -579,17 +579,9 @@
|
||||
}
|
||||
|
||||
@keyframes pulse {
|
||||
0% {
|
||||
transform: scale(1);
|
||||
}
|
||||
|
||||
50% {
|
||||
transform: scale(1.05);
|
||||
}
|
||||
|
||||
100% {
|
||||
transform: scale(1);
|
||||
}
|
||||
0% { transform: scale(1); }
|
||||
50% { transform: scale(1.05); }
|
||||
100% { transform: scale(1); }
|
||||
}
|
||||
|
||||
/* Toast notification styles */
|
||||
@@ -624,6 +616,7 @@
|
||||
</div>
|
||||
|
||||
<form method="POST" class="form" id="editQRForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- Basic Information Section -->
|
||||
<div class="form-section">
|
||||
<div class="section-header">
|
||||
@@ -637,19 +630,24 @@
|
||||
<div class="form-group">
|
||||
<label for="name">
|
||||
<i class="fas fa-tag"></i>
|
||||
QR Code Name
|
||||
<span
|
||||
style="margin-left: 0.4rem; font-size: 0.75rem; font-weight: 500; color: var(--gray-500); background: var(--gray-100); border: 1px solid var(--gray-300); border-radius: 4px; padding: 0.1rem 0.4rem;">
|
||||
<i class="fas fa-lock" style="font-size: 0.7rem;"></i> Read-only
|
||||
</span>
|
||||
QR Code Name <span style="color: var(--error-color)">*</span>
|
||||
</label>
|
||||
<input type="text" id="name" name="name" readonly value="{{ qr_code.name }}"
|
||||
<input
|
||||
type="text"
|
||||
id="name"
|
||||
name="name"
|
||||
required
|
||||
value="{{ qr_code.name }}"
|
||||
data-original="{{ qr_code.name }}"
|
||||
style="background-color: var(--gray-100); color: var(--gray-600); cursor: not-allowed; border-color: var(--gray-300);" />
|
||||
<small class="form-help">
|
||||
<i class="fas fa-info-circle"></i>
|
||||
The QR code name cannot be changed after creation.
|
||||
</small>
|
||||
placeholder="e.g., Main Office Entrance, Conference Room A"
|
||||
maxlength="100"
|
||||
/>
|
||||
<small class="form-help"
|
||||
>A unique name to identify this QR code</small
|
||||
>
|
||||
<div class="character-counter">
|
||||
<span id="nameCounter">{{ qr_code.name|length }}/100</span>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- ===== ADDED: QR Code Type selector ===== -->
|
||||
@@ -660,10 +658,8 @@
|
||||
<span style="color: var(--error-color)">*</span>
|
||||
</label>
|
||||
<select id="qr_type" name="qr_type" class="form-control" onchange="toggleQRTypeSection()">
|
||||
<option value="standard" {% if qr_code.qr_type !='dynamic' %}selected{% endif %}>Standard — Fixed Location
|
||||
</option>
|
||||
<option value="dynamic" {% if qr_code.qr_type=='dynamic' %}selected{% endif %}>Dynamic — Employee Selects
|
||||
Location</option>
|
||||
<option value="standard" {% if qr_code.qr_type != 'dynamic' %}selected{% endif %}>Standard — Fixed Location</option>
|
||||
<option value="dynamic" {% if qr_code.qr_type == 'dynamic' %}selected{% endif %}>Dynamic — Employee Selects Location</option>
|
||||
</select>
|
||||
<small class="form-help">
|
||||
<strong>Standard:</strong> employee checks in at one fixed location.<br>
|
||||
@@ -673,23 +669,30 @@
|
||||
<!-- ===== END ADDED ===== -->
|
||||
|
||||
<!-- ADDED: wrapper to hide/show for standard QR only -->
|
||||
<div id="standardLocationNameGroup" {% if qr_code.qr_type=='dynamic' %}style="display:none;" {% endif %}>
|
||||
<div class="form-group">
|
||||
<label for="location">
|
||||
<i class="fas fa-map-marker-alt"></i>
|
||||
Location Name <span style="color: var(--error-color)">*</span>
|
||||
</label>
|
||||
<input type="text" id="location" name="location" {% if qr_code.qr_type !='dynamic' %}required{% endif %}
|
||||
value="{{ qr_code.location if qr_code.qr_type != 'dynamic' else '' }}"
|
||||
data-original="{{ qr_code.location }}" placeholder="e.g., Corporate Headquarters, Branch Office"
|
||||
maxlength="100" />
|
||||
<small class="form-help">The name of the physical location where this QR code will be
|
||||
used</small>
|
||||
<div class="character-counter">
|
||||
<span id="locationCounter">{{ qr_code.location|length if qr_code.qr_type != 'dynamic' else '0'
|
||||
}}/100</span>
|
||||
</div>
|
||||
<div id="standardLocationNameGroup" {% if qr_code.qr_type == 'dynamic' %}style="display:none;"{% endif %}>
|
||||
<div class="form-group">
|
||||
<label for="location">
|
||||
<i class="fas fa-map-marker-alt"></i>
|
||||
Location Name <span style="color: var(--error-color)">*</span>
|
||||
</label>
|
||||
<input
|
||||
type="text"
|
||||
id="location"
|
||||
name="location"
|
||||
{% if qr_code.qr_type != 'dynamic' %}required{% endif %}
|
||||
value="{{ qr_code.location if qr_code.qr_type != 'dynamic' else '' }}"
|
||||
data-original="{{ qr_code.location }}"
|
||||
placeholder="e.g., Corporate Headquarters, Branch Office"
|
||||
maxlength="100"
|
||||
/>
|
||||
<small class="form-help"
|
||||
>The name of the physical location where this QR code will be
|
||||
used</small
|
||||
>
|
||||
<div class="character-counter">
|
||||
<span id="locationCounter">{{ qr_code.location|length if qr_code.qr_type != 'dynamic' else '0' }}/100</span>
|
||||
</div>
|
||||
</div>
|
||||
</div><!-- end standardLocationNameGroup -->
|
||||
|
||||
<div class="form-group">
|
||||
@@ -697,11 +700,10 @@
|
||||
<i class="fas fa-folder"></i>
|
||||
Project (Optional)
|
||||
</label>
|
||||
<select id="project_id" name="project_id" class="form-select"
|
||||
data-original="{{ qr_code.project_id or '' }}">
|
||||
<select id="project_id" name="project_id" class="form-select" data-original="{{ qr_code.project_id or '' }}">
|
||||
<option value="">Select a project (Optional)</option>
|
||||
{% for project in projects %}
|
||||
<option value="{{ project.id }}" {% if qr_code.project_id==project.id %}selected{% endif %}>
|
||||
<option value="{{ project.id }}" {% if qr_code.project_id == project.id %}selected{% endif %}>
|
||||
{{ project.name }} ({{ project.qr_count }} QR codes)
|
||||
</option>
|
||||
{% endfor %}
|
||||
@@ -714,81 +716,96 @@
|
||||
</div>
|
||||
|
||||
<!-- Location Details Section — hidden when Dynamic QR type is selected -->
|
||||
<div id="standardLocationDetailsSection" {% if qr_code.qr_type=='dynamic' %}style="display:none;" {% endif %}>
|
||||
<div class="form-section">
|
||||
<div class="section-header">
|
||||
<h3>
|
||||
<i class="fas fa-building"></i>
|
||||
Location Details
|
||||
</h3>
|
||||
<p>Update the complete address and event information</p>
|
||||
</div>
|
||||
|
||||
<div class="form-group">
|
||||
<label for="location_address">
|
||||
<i class="fas fa-home"></i>
|
||||
Complete Address
|
||||
<span style="color: var(--error-color)">*</span>
|
||||
</label>
|
||||
<textarea id="location_address" name="location_address" required
|
||||
data-original="{{ qr_code.location_address }}"
|
||||
placeholder="Enter the full address including street, city, state, and ZIP code" rows="3"
|
||||
maxlength="500">{{ qr_code.location_address }}</textarea>
|
||||
<small class="form-help">Include all address details for accurate location
|
||||
identification</small>
|
||||
<div class="character-counter">
|
||||
<span id="addressCounter">{{ qr_code.location_address|length }}/500</span>
|
||||
</div>
|
||||
|
||||
<!-- Address Coordinates Section -->
|
||||
<div class="coordinates-section" id="coordinatesSection">
|
||||
<div class="coordinates-header">
|
||||
<i class="fas fa-crosshairs"></i>
|
||||
<h4>Address Coordinates</h4>
|
||||
</div>
|
||||
|
||||
<div class="coordinates-content">
|
||||
<div class="coordinate-display">
|
||||
<div class="coordinate-info">
|
||||
<div class="coordinate-value" id="latitudeDisplay">
|
||||
{% if qr_code.has_coordinates %}
|
||||
{{ "%.6f"|format(qr_code.address_latitude) }}
|
||||
{% else %}
|
||||
---.----------
|
||||
{% endif %}
|
||||
</div>
|
||||
<div class="coordinate-label">Latitude</div>
|
||||
</div>
|
||||
<div class="coordinate-info">
|
||||
<div class="coordinate-value" id="longitudeDisplay">
|
||||
{% if qr_code.has_coordinates %}
|
||||
{{ "%.6f"|format(qr_code.address_longitude) }}
|
||||
{% else %}
|
||||
---.----------
|
||||
{% endif %}
|
||||
</div>
|
||||
<div class="coordinate-label">Longitude</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="coordinates-actions">
|
||||
<button type="button" class="btn-coordinate" id="geocodeBtn">
|
||||
<i class="fas fa-search-location"></i>
|
||||
{% if qr_code.has_coordinates %}Update{% else %}Get{% endif %} Coordinates
|
||||
</button>
|
||||
<button type="button" class="btn-coordinate" id="clearCoordinatesBtn"
|
||||
style="display: {% if qr_code.has_coordinates %}inline-flex{% else %}none{% endif %};">
|
||||
<i class="fas fa-times"></i>
|
||||
Clear
|
||||
</button>
|
||||
</div>
|
||||
|
||||
<div id="coordinateStatus"></div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div id="standardLocationDetailsSection" {% if qr_code.qr_type == 'dynamic' %}style="display:none;"{% endif %}>
|
||||
<div class="form-section">
|
||||
<div class="section-header">
|
||||
<h3>
|
||||
<i class="fas fa-building"></i>
|
||||
Location Details
|
||||
</h3>
|
||||
<p>Update the complete address and event information</p>
|
||||
</div>
|
||||
|
||||
<div class="form-group">
|
||||
<label for="location_address">
|
||||
<i class="fas fa-home"></i>
|
||||
Complete Address
|
||||
<span style="color: var(--error-color)">*</span>
|
||||
</label>
|
||||
<textarea
|
||||
id="location_address"
|
||||
name="location_address"
|
||||
required
|
||||
data-original="{{ qr_code.location_address }}"
|
||||
placeholder="Enter the full address including street, city, state, and ZIP code"
|
||||
rows="3"
|
||||
maxlength="500"
|
||||
>{{ qr_code.location_address }}</textarea>
|
||||
<small class="form-help"
|
||||
>Include all address details for accurate location
|
||||
identification</small
|
||||
>
|
||||
<div class="character-counter">
|
||||
<span id="addressCounter">{{ qr_code.location_address|length }}/500</span>
|
||||
</div>
|
||||
|
||||
<!-- Address Coordinates Section -->
|
||||
<div class="coordinates-section" id="coordinatesSection">
|
||||
<div class="coordinates-header">
|
||||
<i class="fas fa-crosshairs"></i>
|
||||
<h4>Address Coordinates</h4>
|
||||
</div>
|
||||
|
||||
<div class="coordinates-content">
|
||||
<div class="coordinate-display">
|
||||
<div class="coordinate-info">
|
||||
<div class="coordinate-value" id="latitudeDisplay">
|
||||
{% if qr_code.has_coordinates %}
|
||||
{{ "%.6f"|format(qr_code.address_latitude) }}
|
||||
{% else %}
|
||||
---.----------
|
||||
{% endif %}
|
||||
</div>
|
||||
<div class="coordinate-label">Latitude</div>
|
||||
</div>
|
||||
<div class="coordinate-info">
|
||||
<div class="coordinate-value" id="longitudeDisplay">
|
||||
{% if qr_code.has_coordinates %}
|
||||
{{ "%.6f"|format(qr_code.address_longitude) }}
|
||||
{% else %}
|
||||
---.----------
|
||||
{% endif %}
|
||||
</div>
|
||||
<div class="coordinate-label">Longitude</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="coordinates-actions">
|
||||
<button
|
||||
type="button"
|
||||
class="btn-coordinate"
|
||||
id="geocodeBtn"
|
||||
>
|
||||
<i class="fas fa-search-location"></i>
|
||||
{% if qr_code.has_coordinates %}Update{% else %}Get{% endif %} Coordinates
|
||||
</button>
|
||||
<button
|
||||
type="button"
|
||||
class="btn-coordinate"
|
||||
id="clearCoordinatesBtn"
|
||||
style="display: {% if qr_code.has_coordinates %}inline-flex{% else %}none{% endif %};"
|
||||
>
|
||||
<i class="fas fa-times"></i>
|
||||
Clear
|
||||
</button>
|
||||
</div>
|
||||
|
||||
<div id="coordinateStatus"></div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
</div><!-- end standardLocationDetailsSection -->
|
||||
|
||||
<!-- Event or Purpose — always visible for both Standard and Dynamic QR -->
|
||||
@@ -799,14 +816,20 @@
|
||||
Event or Purpose
|
||||
<span style="color: var(--error-color)">*</span>
|
||||
</label>
|
||||
<select id="location_event" name="location_event" required class="form-control"
|
||||
data-original="{{ qr_code.location_event }}">
|
||||
<select
|
||||
id="location_event"
|
||||
name="location_event"
|
||||
required
|
||||
class="form-control"
|
||||
data-original="{{ qr_code.location_event }}"
|
||||
>
|
||||
<option value="">Select Event Type</option>
|
||||
<option value="Check In" {% if qr_code.location_event=='Check In' %}selected{% endif %}>Check In</option>
|
||||
<option value="Check Out" {% if qr_code.location_event=='Check Out' %}selected{% endif %}>Check Out
|
||||
</option>
|
||||
<option value="Check In" {% if qr_code.location_event == 'Check In' %}selected{% endif %}>Check In</option>
|
||||
<option value="Check Out" {% if qr_code.location_event == 'Check Out' %}selected{% endif %}>Check Out</option>
|
||||
</select>
|
||||
<small class="form-help">Select the event type for this QR code</small>
|
||||
<small class="form-help"
|
||||
>Select the event type for this QR code</small
|
||||
>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
@@ -830,9 +853,13 @@
|
||||
<select id="style_id" name="style_id" onchange="applyStylePreset()">
|
||||
<option value="">Custom Style</option>
|
||||
{% for style in styles %}
|
||||
<option value="{{ style.id }}" {% if qr_code.style_id==style.id %}selected{% endif %}
|
||||
data-fill="{{ style.fill_color }}" data-back="{{ style.back_color }}"
|
||||
data-box-size="{{ style.box_size }}" data-border="{{ style.border }}"
|
||||
<option
|
||||
value="{{ style.id }}"
|
||||
{% if qr_code.style_id == style.id %}selected{% endif %}
|
||||
data-fill="{{ style.fill_color }}"
|
||||
data-back="{{ style.back_color }}"
|
||||
data-box-size="{{ style.box_size }}"
|
||||
data-border="{{ style.border }}"
|
||||
data-error-correction="{{ style.error_correction }}">
|
||||
{{ style.name }}
|
||||
</option>
|
||||
@@ -849,10 +876,21 @@
|
||||
QR Code Color
|
||||
</label>
|
||||
<div class="color-input-group">
|
||||
<input type="color" id="fill_color" name="fill_color" value="{{ qr_code.fill_color or '#000000' }}"
|
||||
onchange="updatePreview()" />
|
||||
<input type="text" id="fill_color_text" value="{{ qr_code.fill_color or '#000000' }}"
|
||||
pattern="^#[0-9A-Fa-f]{6}$" placeholder="#000000" onchange="syncColorInput('fill')" />
|
||||
<input
|
||||
type="color"
|
||||
id="fill_color"
|
||||
name="fill_color"
|
||||
value="{{ qr_code.fill_color or '#000000' }}"
|
||||
onchange="updatePreview()"
|
||||
/>
|
||||
<input
|
||||
type="text"
|
||||
id="fill_color_text"
|
||||
value="{{ qr_code.fill_color or '#000000' }}"
|
||||
pattern="^#[0-9A-Fa-f]{6}$"
|
||||
placeholder="#000000"
|
||||
onchange="syncColorInput('fill')"
|
||||
/>
|
||||
</div>
|
||||
<span class="form-help">Color of the QR code modules</span>
|
||||
</div>
|
||||
@@ -863,10 +901,21 @@
|
||||
Background Color
|
||||
</label>
|
||||
<div class="color-input-group">
|
||||
<input type="color" id="back_color" name="back_color" value="{{ qr_code.back_color or '#FFFFFF' }}"
|
||||
onchange="updatePreview()" />
|
||||
<input type="text" id="back_color_text" value="{{ qr_code.back_color or '#FFFFFF' }}"
|
||||
pattern="^#[0-9A-Fa-f]{6}$" placeholder="#FFFFFF" onchange="syncColorInput('back')" />
|
||||
<input
|
||||
type="color"
|
||||
id="back_color"
|
||||
name="back_color"
|
||||
value="{{ qr_code.back_color or '#FFFFFF' }}"
|
||||
onchange="updatePreview()"
|
||||
/>
|
||||
<input
|
||||
type="text"
|
||||
id="back_color_text"
|
||||
value="{{ qr_code.back_color or '#FFFFFF' }}"
|
||||
pattern="^#[0-9A-Fa-f]{6}$"
|
||||
placeholder="#FFFFFF"
|
||||
onchange="syncColorInput('back')"
|
||||
/>
|
||||
</div>
|
||||
<span class="form-help">Background color of the QR code</span>
|
||||
</div>
|
||||
@@ -880,8 +929,15 @@
|
||||
Module Size
|
||||
</label>
|
||||
<div class="range-input-group">
|
||||
<input type="range" id="box_size" name="box_size" min="5" max="20" value="{{ qr_code.box_size or 10 }}"
|
||||
oninput="updateRangeValue('box_size'); updatePreview()" />
|
||||
<input
|
||||
type="range"
|
||||
id="box_size"
|
||||
name="box_size"
|
||||
min="5"
|
||||
max="20"
|
||||
value="{{ qr_code.box_size or 10 }}"
|
||||
oninput="updateRangeValue('box_size'); updatePreview()"
|
||||
/>
|
||||
<span class="range-value" id="box_size_value">{{ qr_code.box_size or 10 }}px</span>
|
||||
</div>
|
||||
<span class="form-help">Size of each QR code module (affects overall size)</span>
|
||||
@@ -893,8 +949,15 @@
|
||||
Border Size
|
||||
</label>
|
||||
<div class="range-input-group">
|
||||
<input type="range" id="border" name="border" min="1" max="10" value="{{ qr_code.border or 4 }}"
|
||||
oninput="updateRangeValue('border'); updatePreview()" />
|
||||
<input
|
||||
type="range"
|
||||
id="border"
|
||||
name="border"
|
||||
min="1"
|
||||
max="10"
|
||||
value="{{ qr_code.border or 4 }}"
|
||||
oninput="updateRangeValue('border'); updatePreview()"
|
||||
/>
|
||||
<span class="range-value" id="border_value">{{ qr_code.border or 4 }} modules</span>
|
||||
</div>
|
||||
<span class="form-help">White border around the QR code</span>
|
||||
@@ -908,11 +971,10 @@
|
||||
Error Correction Level
|
||||
</label>
|
||||
<select id="error_correction" name="error_correction" onchange="updatePreview()">
|
||||
<option value="L" {% if qr_code.error_correction=='L' %}selected{% endif %}>Low (7% recovery)</option>
|
||||
<option value="M" {% if qr_code.error_correction=='M' %}selected{% endif %}>Medium (15% recovery)</option>
|
||||
<option value="Q" {% if qr_code.error_correction=='Q' %}selected{% endif %}>Quartile (25% recovery)
|
||||
</option>
|
||||
<option value="H" {% if qr_code.error_correction=='H' %}selected{% endif %}>High (30% recovery)</option>
|
||||
<option value="L" {% if qr_code.error_correction == 'L' %}selected{% endif %}>Low (7% recovery)</option>
|
||||
<option value="M" {% if qr_code.error_correction == 'M' %}selected{% endif %}>Medium (15% recovery)</option>
|
||||
<option value="Q" {% if qr_code.error_correction == 'Q' %}selected{% endif %}>Quartile (25% recovery)</option>
|
||||
<option value="H" {% if qr_code.error_correction == 'H' %}selected{% endif %}>High (30% recovery)</option>
|
||||
</select>
|
||||
<span class="form-help">Higher levels allow QR code to work even if partially damaged</span>
|
||||
</div>
|
||||
@@ -947,12 +1009,24 @@
|
||||
</div>
|
||||
|
||||
<!-- Hidden coordinate fields for form submission -->
|
||||
<input type="hidden" id="address_latitude" name="address_latitude"
|
||||
value="{% if qr_code.has_coordinates %}{{ qr_code.address_latitude }}{% endif %}" />
|
||||
<input type="hidden" id="address_longitude" name="address_longitude"
|
||||
value="{% if qr_code.has_coordinates %}{{ qr_code.address_longitude }}{% endif %}" />
|
||||
<input type="hidden" id="coordinate_accuracy" name="coordinate_accuracy"
|
||||
value="{% if qr_code.has_coordinates %}{{ qr_code.coordinate_accuracy }}{% endif %}" />
|
||||
<input
|
||||
type="hidden"
|
||||
id="address_latitude"
|
||||
name="address_latitude"
|
||||
value="{% if qr_code.has_coordinates %}{{ qr_code.address_latitude }}{% endif %}"
|
||||
/>
|
||||
<input
|
||||
type="hidden"
|
||||
id="address_longitude"
|
||||
name="address_longitude"
|
||||
value="{% if qr_code.has_coordinates %}{{ qr_code.address_longitude }}{% endif %}"
|
||||
/>
|
||||
<input
|
||||
type="hidden"
|
||||
id="coordinate_accuracy"
|
||||
name="coordinate_accuracy"
|
||||
value="{% if qr_code.has_coordinates %}{{ qr_code.coordinate_accuracy }}{% endif %}"
|
||||
/>
|
||||
|
||||
<!-- Form Actions -->
|
||||
<div class="form-actions">
|
||||
@@ -1037,11 +1111,9 @@
|
||||
<div class="detail-row">
|
||||
<strong>Colors:</strong>
|
||||
<span>
|
||||
<span
|
||||
style="display: inline-block; width: 12px; height: 12px; background: {{ qr_code.fill_color or '#000000' }}; border-radius: 2px; margin-right: 4px;"></span>
|
||||
<span style="display: inline-block; width: 12px; height: 12px; background: {{ qr_code.fill_color or '#000000' }}; border-radius: 2px; margin-right: 4px;"></span>
|
||||
on
|
||||
<span
|
||||
style="display: inline-block; width: 12px; height: 12px; background: {{ qr_code.back_color or '#FFFFFF' }}; border: 1px solid #ccc; border-radius: 2px; margin-left: 4px;"></span>
|
||||
<span style="display: inline-block; width: 12px; height: 12px; background: {{ qr_code.back_color or '#FFFFFF' }}; border: 1px solid #ccc; border-radius: 2px; margin-left: 4px;"></span>
|
||||
</span>
|
||||
</div>
|
||||
</div>
|
||||
@@ -1281,25 +1353,26 @@
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({ address: address })
|
||||
})
|
||||
.then(response => response.json())
|
||||
.then(data => {
|
||||
if (data.success) {
|
||||
const lat = data.data.latitude;
|
||||
const lng = data.data.longitude;
|
||||
.then(response => response.json())
|
||||
.then(data => {
|
||||
if (data.success) {
|
||||
const lat = data.data.latitude;
|
||||
const lng = data.data.longitude;
|
||||
|
||||
updateCoordinates(lat, lng, 'geocoded');
|
||||
showStatus('success', data.message || 'Coordinates updated successfully');
|
||||
} else {
|
||||
showStatus('warning', data.message || 'No coordinates found for this address');
|
||||
}
|
||||
})
|
||||
.catch(error => {
|
||||
console.error('Geocoding error:', error);
|
||||
showStatus('error', 'Failed to get coordinates. Please try again.');
|
||||
});
|
||||
updateCoordinates(lat, lng, 'geocoded');
|
||||
showStatus('success', data.message || 'Coordinates updated successfully');
|
||||
} else {
|
||||
showStatus('warning', data.message || 'No coordinates found for this address');
|
||||
}
|
||||
})
|
||||
.catch(error => {
|
||||
console.error('Geocoding error:', error);
|
||||
showStatus('error', 'Failed to get coordinates. Please try again.');
|
||||
});
|
||||
}
|
||||
|
||||
function updateCoordinates(lat, lng, accuracy) {
|
||||
@@ -1347,8 +1420,12 @@
|
||||
}
|
||||
|
||||
// Initialize on page load
|
||||
document.addEventListener('DOMContentLoaded', function () {
|
||||
document.addEventListener('DOMContentLoaded', function() {
|
||||
// Set up character counters
|
||||
document.getElementById('name').addEventListener('input', () => {
|
||||
updateCharacterCount('name', 'nameCounter', 100);
|
||||
updateCurrentInfo();
|
||||
});
|
||||
document.getElementById('location').addEventListener('input', () => {
|
||||
updateCharacterCount('location', 'locationCounter', 100);
|
||||
updateCurrentInfo();
|
||||
@@ -1369,7 +1446,7 @@
|
||||
// Add form validation
|
||||
const form = document.getElementById('editQRForm');
|
||||
if (form) {
|
||||
form.addEventListener('submit', function (e) {
|
||||
form.addEventListener('submit', function(e) {
|
||||
if (!validateQRCustomization()) {
|
||||
e.preventDefault();
|
||||
return false;
|
||||
@@ -1378,12 +1455,12 @@
|
||||
}
|
||||
|
||||
// Add color input synchronization
|
||||
document.getElementById('fill_color').addEventListener('change', function () {
|
||||
document.getElementById('fill_color').addEventListener('change', function() {
|
||||
document.getElementById('fill_color_text').value = this.value.toUpperCase();
|
||||
updatePreview();
|
||||
});
|
||||
|
||||
document.getElementById('back_color').addEventListener('change', function () {
|
||||
document.getElementById('back_color').addEventListener('change', function() {
|
||||
document.getElementById('back_color_text').value = this.value.toUpperCase();
|
||||
updatePreview();
|
||||
});
|
||||
@@ -1392,7 +1469,7 @@
|
||||
const geocodeBtn = document.getElementById('geocodeBtn');
|
||||
const clearBtn = document.getElementById('clearCoordinatesBtn');
|
||||
|
||||
geocodeBtn.addEventListener('click', function () {
|
||||
geocodeBtn.addEventListener('click', function() {
|
||||
const address = document.getElementById('location_address').value.trim();
|
||||
if (address.length > 10) {
|
||||
geocodeAddress(address);
|
||||
@@ -1408,26 +1485,26 @@
|
||||
<!-- ===== Dynamic QR Type Toggle ===== -->
|
||||
<script>
|
||||
function toggleQRTypeSection() {
|
||||
var type = document.getElementById('qr_type').value;
|
||||
var stdName = document.getElementById('standardLocationNameGroup');
|
||||
var stdDetails = document.getElementById('standardLocationDetailsSection');
|
||||
var locInput = document.getElementById('location');
|
||||
var type = document.getElementById('qr_type').value;
|
||||
var stdName = document.getElementById('standardLocationNameGroup');
|
||||
var stdDetails= document.getElementById('standardLocationDetailsSection');
|
||||
var locInput = document.getElementById('location');
|
||||
var addrInput = document.getElementById('location_address');
|
||||
|
||||
if (type === 'dynamic') {
|
||||
if (stdName) stdName.style.display = 'none';
|
||||
if (stdDetails) stdDetails.style.display = 'none';
|
||||
if (locInput) locInput.removeAttribute('required');
|
||||
if (stdName) stdName.style.display = 'none';
|
||||
if (stdDetails)stdDetails.style.display = 'none';
|
||||
if (locInput) locInput.removeAttribute('required');
|
||||
if (addrInput) addrInput.removeAttribute('required');
|
||||
} else {
|
||||
if (stdName) stdName.style.display = 'block';
|
||||
if (stdDetails) stdDetails.style.display = 'block';
|
||||
if (locInput) locInput.setAttribute('required', '');
|
||||
if (stdName) stdName.style.display = 'block';
|
||||
if (stdDetails)stdDetails.style.display = 'block';
|
||||
if (locInput) locInput.setAttribute('required', '');
|
||||
if (addrInput) addrInput.setAttribute('required', '');
|
||||
}
|
||||
}
|
||||
|
||||
document.addEventListener('DOMContentLoaded', function () {
|
||||
document.addEventListener('DOMContentLoaded', function() {
|
||||
toggleQRTypeSection();
|
||||
});
|
||||
</script>
|
||||
|
||||
@@ -15,6 +15,7 @@
|
||||
|
||||
<div class="edit-user-container">
|
||||
<form id="editUserForm" method="POST" action="{{ url_for('users.edit_user', user_id=user.id) }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- User Information Section -->
|
||||
<div class="form-section">
|
||||
<h3>
|
||||
@@ -470,6 +471,7 @@
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({ project_ids: projectIds })
|
||||
});
|
||||
|
||||
@@ -304,6 +304,7 @@ extra_head %}
|
||||
<div class="modal-footer">
|
||||
<button class="btn btn-secondary" data-modal="deleteModal">Cancel</button>
|
||||
<form id="deleteForm" method="POST" style="display: inline">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<button type="submit" class="btn btn-danger">
|
||||
<i class="fas fa-trash"></i>
|
||||
Delete Employee
|
||||
|
||||
@@ -86,6 +86,7 @@
|
||||
<!-- Export Configuration Form -->
|
||||
<div class="export-config-section">
|
||||
<form method="POST" action="{{ url_for('attendance.generate_excel_export') }}" id="exportForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<!-- Hidden fields for filters -->
|
||||
<input type="hidden" name="date_from" value="{{ filters.date_from }}">
|
||||
<input type="hidden" name="date_to" value="{{ filters.date_to }}">
|
||||
|
||||
@@ -18,6 +18,7 @@
|
||||
</div>
|
||||
|
||||
<form method="POST" class="auth-form" id="loginForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<div class="form-group">
|
||||
<label for="username">
|
||||
<i class="fas fa-user"></i>
|
||||
|
||||
@@ -821,6 +821,7 @@
|
||||
<div class="export-actions">
|
||||
<!--
|
||||
<form method="POST" action="{{ url_for('payroll.export_payroll_excel') }}" style="display: inline;">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="date_from" value="{{ date_from }}">
|
||||
<input type="hidden" name="date_to" value="{{ date_to }}">
|
||||
<input type="hidden" name="project_filter" value="{{ project_filter }}">
|
||||
@@ -832,6 +833,7 @@
|
||||
</form>
|
||||
|
||||
<form method="POST" action="{{ url_for('payroll.export_payroll_excel') }}" style="display: inline;">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="date_from" value="{{ date_from }}">
|
||||
<input type="hidden" name="date_to" value="{{ date_to }}">
|
||||
<input type="hidden" name="project_filter" value="{{ project_filter }}">
|
||||
@@ -843,6 +845,7 @@
|
||||
</form>
|
||||
-->
|
||||
<form method="POST" action="{{ url_for('payroll.export_payroll_excel') }}" style="display: inline;">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="date_from" value="{{ date_from }}">
|
||||
<input type="hidden" name="date_to" value="{{ date_to }}">
|
||||
<input type="hidden" name="project_filter" value="{{ project_filter }}">
|
||||
@@ -854,6 +857,7 @@
|
||||
</form>
|
||||
<!--
|
||||
<form method="POST" action="{{ url_for('payroll.export_payroll_excel') }}" style="display: inline;">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="date_from" value="{{ date_from }}">
|
||||
<input type="hidden" name="date_to" value="{{ date_to }}">
|
||||
<input type="hidden" name="project_filter" value="{{ project_filter }}">
|
||||
@@ -865,6 +869,7 @@
|
||||
</form>
|
||||
|
||||
<form method="POST" action="{{ url_for('payroll.export_payroll_excel') }}" style="display: inline;">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="date_from" value="{{ date_from }}">
|
||||
<input type="hidden" name="date_to" value="{{ date_to }}">
|
||||
<input type="hidden" name="project_filter" value="{{ project_filter }}">
|
||||
|
||||
@@ -114,6 +114,7 @@ endblock %} {% block content %}
|
||||
</div>
|
||||
|
||||
<form method="POST" class="profile-form" id="profileForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="form_type" value="profile" />
|
||||
|
||||
<div class="form-row">
|
||||
@@ -192,6 +193,7 @@ endblock %} {% block content %}
|
||||
</div>
|
||||
|
||||
<form method="POST" class="profile-form" id="passwordForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="form_type" value="password" />
|
||||
|
||||
<div class="form-group">
|
||||
|
||||
@@ -114,6 +114,7 @@
|
||||
<!-- Activate/Deactivate button (for future use)
|
||||
<form method="POST" action="{{ url_for('projects.toggle_project', project_id=project.id) }}"
|
||||
style="display: inline;">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<button type="submit"
|
||||
class="btn {% if project.active_status %}btn-warning{% else %}btn-success{% endif %}">
|
||||
<i class="fas {% if project.active_status %}fa-pause{% else %}fa-play{% endif %}"></i>
|
||||
|
||||
@@ -11,6 +11,7 @@ endblock %} {% block content %}
|
||||
</div>
|
||||
|
||||
<form method="POST" class="auth-form" id="registerForm">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<div class="form-group">
|
||||
<label for="full_name">
|
||||
<i class="fas fa-id-card"></i>
|
||||
|
||||
@@ -367,6 +367,7 @@
|
||||
<!-- Duplicates List -->
|
||||
{% if analysis.duplicate_records > 0 %}
|
||||
<form id="duplicateReviewForm" method="POST" action="{{ url_for('time_attendance.import_time_attendance') }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="analyze_duplicates" value="false">
|
||||
<input type="hidden" name="skip_duplicates" value="true">
|
||||
<input type="hidden" name="import_source" value="Import with Duplicates - {{ filename }}">
|
||||
|
||||
@@ -343,6 +343,7 @@
|
||||
</div>
|
||||
<div class="import-body">
|
||||
<form id="importForm" method="POST" enctype="multipart/form-data" action="{{ url_for('time_attendance.import_time_attendance') }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
|
||||
<!-- Project Selection - REQUIRED (moved to top) -->
|
||||
<div class="form-group" style="margin-bottom: 1.5rem;">
|
||||
@@ -885,6 +886,7 @@ importForm.addEventListener('submit', async (e) => {
|
||||
try {
|
||||
const resp = await fetch('{{ url_for("time_attendance.start_import_job") }}', {
|
||||
method: 'POST',
|
||||
headers: { 'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '' },
|
||||
body: formData
|
||||
});
|
||||
const data = await resp.json();
|
||||
|
||||
@@ -243,6 +243,7 @@ fetch('/time-attendance/import/execute', {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
batch_id: batchId,
|
||||
|
||||
@@ -321,6 +321,7 @@
|
||||
<!-- Invalid Rows List -->
|
||||
{% if analysis.invalid_rows > 0 %}
|
||||
<form id="invalidReviewForm" method="POST" action="{{ url_for('time_attendance.import_time_attendance') }}">
|
||||
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
||||
<input type="hidden" name="from_invalid_review" value="true">
|
||||
<input type="hidden" name="analyze_invalid" value="false">
|
||||
<input type="hidden" name="analyze_duplicates" value="false">
|
||||
|
||||
@@ -867,7 +867,7 @@ function submitDelete() {
|
||||
}
|
||||
|
||||
// Add CSRF token
|
||||
const sessionCsrfToken = '{{ session.get("csrf_token", "") }}';
|
||||
const sessionCsrfToken = (window.qrConfig && window.qrConfig.csrfToken) || '';
|
||||
if (sessionCsrfToken) {
|
||||
const csrfInput = document.createElement('input');
|
||||
csrfInput.type = 'hidden';
|
||||
|
||||
@@ -630,7 +630,7 @@ function confirmDelete(recordId, employeeName, date) {
|
||||
}
|
||||
|
||||
// Add CSRF token if available
|
||||
const sessionCsrfToken = '{{ session.get("csrf_token", "") }}';
|
||||
const sessionCsrfToken = (window.qrConfig && window.qrConfig.csrfToken) || '';
|
||||
if (sessionCsrfToken) {
|
||||
const csrfInput = document.createElement('input');
|
||||
csrfInput.type = 'hidden';
|
||||
|
||||
@@ -442,7 +442,9 @@ Code Management{% endblock %} {% block extra_head %}
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
"X-CSRF-Token": (window.qrConfig && window.qrConfig.csrfToken) || "",
|
||||
},
|
||||
body: JSON.stringify({
|
||||
new_status: newStatus,
|
||||
|
||||
@@ -817,6 +817,7 @@
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
status: status,
|
||||
|
||||
@@ -497,6 +497,7 @@ QR Code Management{% endblock %} {% block extra_head %}
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-CSRF-Token': (window.qrConfig && window.qrConfig.csrfToken) || '',
|
||||
},
|
||||
body: JSON.stringify({
|
||||
status: status,
|
||||
|
||||
Reference in New Issue
Block a user