Edit file File name : Async.php Content :<?php if (!defined('sugarEntry') || !sugarEntry) { die('Not A Valid Entry Point'); } /** * * SugarCRM Community Edition is a customer relationship management program developed by * SugarCRM, Inc. Copyright (C) 2004-2013 SugarCRM Inc. * * SuiteCRM is an extension to SugarCRM Community Edition developed by SalesAgility Ltd. * Copyright (C) 2011 - 2018 SalesAgility Ltd. * * This program is free software; you can redistribute it and/or modify it under * the terms of the GNU Affero General Public License version 3 as published by the * Free Software Foundation with the addition of the following permission added * to Section 15 as permitted in Section 7(a): FOR ANY PART OF THE COVERED WORK * IN WHICH THE COPYRIGHT IS OWNED BY SUGARCRM, SUGARCRM DISCLAIMS THE WARRANTY * OF NON INFRINGEMENT OF THIRD PARTY RIGHTS. * * This program is distributed in the hope that it will be useful, but WITHOUT * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS * FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more * details. * * You should have received a copy of the GNU Affero General Public License along with * this program; if not, see http://www.gnu.org/licenses or write to the Free * Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA * 02110-1301 USA. * * You can contact SugarCRM, Inc. headquarters at 10050 North Wolfe Road, * SW2-130, Cupertino, CA 95014, USA. or at email address contact@sugarcrm.com. * * The interactive user interfaces in modified source and object code versions * of this program must display Appropriate Legal Notices, as required under * Section 5 of the GNU Affero General Public License version 3. * * In accordance with Section 7(b) of the GNU Affero General Public License version 3, * these Appropriate Legal Notices must retain the display of the "Powered by * SugarCRM" logo and "Supercharged by SuiteCRM" logo. If the display of the logos is not * reasonably feasible for technical reasons, the Appropriate Legal Notices must * display the words "Powered by SugarCRM" and "Supercharged by SuiteCRM". */ require_once("include/entryPoint.php"); if (!is_admin($GLOBALS['current_user'])) { sugar_die($GLOBALS['app_strings']['ERR_NOT_ADMIN']); } $json = getJSONObj(); $out = ""; switch ($_REQUEST['adminAction']) { /////////////////////////////////////////////////////////////////////////// //// REPAIRXSS case "refreshEstimate": include("include/modules.php"); // provide $moduleList $target = ''; if (!empty($_REQUEST['bean'])) { $target = $_REQUEST['bean']; } $count = 0; $toRepair = array(); if ($target == 'all') { $hide = array('Activities', 'Home', 'iFrames', 'Calendar', 'Dashboard'); sort($moduleList); $options = array(); foreach ($moduleList as $module) { if (!in_array($module, $hide)) { $options[$module] = $module; } } foreach ($options as $module) { if (!isset($beanFiles[$beanList[$module]])) { continue; } $file = $beanFiles[$beanList[$module]]; if (!file_exists($file)) { continue; } require_once($file); $bean = new $beanList[$module](); $q = "SELECT count(*) as count FROM {$bean->table_name}"; $r = $bean->db->query($q); $a = $bean->db->fetchByAssoc($r); $count += $a['count']; // populate to_repair array $q2 = "SELECT id FROM {$bean->table_name}"; $r2 = $bean->db->query($q2); $ids = []; while ($a2 = $bean->db->fetchByAssoc($r2)) { $ids[] = $a2['id']; } $toRepair[$module] = $ids; } } elseif (in_array($target, $moduleList)) { require_once($beanFiles[$beanList[$target]]); $bean = new $beanList[$target](); $q = "SELECT count(*) as count FROM {$bean->table_name}"; $r = $bean->db->query($q); $a = $bean->db->fetchByAssoc($r); $count += $a['count']; // populate to_repair array $q2 = "SELECT id FROM {$bean->table_name}"; $r2 = $bean->db->query($q2); $ids = []; while ($a2 = $bean->db->fetchByAssoc($r2)) { $ids[] = $a2['id']; } $toRepair[$target] = $ids; } $out = array('count' => $count, 'target' => $target, 'toRepair' => $toRepair); break; case "repairXssExecute": if (isset($_REQUEST['bean']) && !empty($_REQUEST['bean']) && isset($_REQUEST['id']) && !empty($_REQUEST['id'])) { include("include/modules.php"); // provide $moduleList $target = $_REQUEST['bean']; require_once($beanFiles[$beanList[$target]]); $ids = $json->decode(from_html($_REQUEST['id'])); $count = 0; foreach ($ids as $id) { if (!empty($id)) { $bean = new $beanList[$target](); $bean->retrieve($id, true, false); $bean->new_with_id = false; $bean->save(); // cleanBean() is called on save() $count++; } } $out = array('msg' => "success", 'count' => $count); } else { $out = array('msg' => "failure: bean or ID not defined"); } break; //// END REPAIRXSS /////////////////////////////////////////////////////////////////////////// default: die(); break; } $ret = $json->encode($out, true); echo $ret; Save