koha.git
4 months agoBug 36102: Fix expired session on the login page of the installer (?)
Jonathan Druart [Tue, 20 Feb 2024 14:12:23 +0000 (15:12 +0100)]
Bug 36102: Fix expired session on the login page of the installer (?)

I *think* this change fixes a bug when starting the installer with an
expired session. I am no longer able to reproduce the problem however.

Just skip if it does not make sense.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: If CSRF check fails, try with anonymous
Jonathan Druart [Tue, 20 Feb 2024 13:31:04 +0000 (14:31 +0100)]
Bug 36102: If CSRF check fails, try with anonymous

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: Remove cookie from the installer session
Jonathan Druart [Tue, 20 Feb 2024 13:10:40 +0000 (14:10 +0100)]
Bug 36102: Remove cookie from the installer session

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: Generate a new sessionID if the existing one is invalid
Jonathan Druart [Tue, 20 Feb 2024 13:01:04 +0000 (14:01 +0100)]
Bug 36102: Generate a new sessionID if the existing one is invalid

If the cookie contain an expired sessionID we need to create another
one to correctly generate the CSRF token.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: Do not repeat op or csrf_token on the login form - staff
Jonathan Druart [Tue, 20 Feb 2024 12:37:21 +0000 (13:37 +0100)]
Bug 36102: Do not repeat op or csrf_token on the login form - staff

Needed for OPAC?

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: (follow-up) Add cud-login to the login form
Jonathan Druart [Tue, 20 Feb 2024 10:03:37 +0000 (11:03 +0100)]
Bug 36102: (follow-up) Add cud-login to the login form

Hum this didn't make sense. We are not checking credentials after
checkauth.

This patch is suggesting to rename "userid" and "password" parameters
from login forms to "login_userid" and "login_password" to not interfere
with other parameters with the same name.

This looks quite correct, however I am seeing
  "The form submission failed (Wrong CSRF token)."
in the log after a successful login. Which feels wrong, what's
happening?

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: Do not keep op and csrf_token in param list after login - OPAC
Jonathan Druart [Tue, 20 Feb 2024 09:09:25 +0000 (10:09 +0100)]
Bug 36102: Do not keep op and csrf_token in param list after login - OPAC

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: Fix 01-installation.t
Jonathan Druart [Thu, 15 Feb 2024 13:06:33 +0000 (14:06 +0100)]
Bug 36102: Fix 01-installation.t

Something very weird is happening here.

There is a FIXME already, but the trick does not seem to work anymore
(?)

This patch contains some debug statements and take some screenshots.
We are reaching the cud-selectframeworks step then we are expecting the
form to submit the form with op=cud-addframeworks

BUT it seems that "op" is empty, and there is an unexpected warning from
Starman:

==> /var/log/koha/kohadev/plack-error.log <==
""
Use of uninitialized value in string ne at /usr/share/perl5/Starman/Server.pm line 304.

==> /var/log/koha/kohadev/plack-intranet-error.log <==
[2024/02/15 13:09:34] [WARN] Warning: something's wrong at /kohadevbox/koha/installer/install.pl line 89.

What's going on here??

UPDATE: This is fixed by "Bug 34478: Manual fix - Make Koha::Token use
session id not userenv id"

Bug 36102: [TO SQUASH] Fix 01-installation.t

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: Use Koha::Session from C4::InstallAuth
Jonathan Druart [Thu, 15 Feb 2024 13:04:46 +0000 (14:04 +0100)]
Bug 36102: Use Koha::Session from C4::InstallAuth

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 36102: Add cud-login to the login form
Jonathan Druart [Wed, 14 Feb 2024 13:54:55 +0000 (14:54 +0100)]
Bug 36102: Add cud-login to the login form

TODO This needs to be covered by tests.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: serials/routing-preview.pl
Jonathan Druart [Fri, 1 Mar 2024 09:46:41 +0000 (10:46 +0100)]
Bug 34478: serials/routing-preview.pl

Not totally done, still need the "save and preview"

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) Move resend link out of form for display reasons
Marcel de Rooy [Fri, 1 Mar 2024 07:27:00 +0000 (07:27 +0000)]
Bug 34478: (follow-up) Move resend link out of form for display reasons

This improves display. This only comes up when you try to reset your
password after you did already.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) Manual fix - Make Koha::Token use session id not userenv id
Jonathan Druart [Wed, 28 Feb 2024 12:15:14 +0000 (13:15 +0100)]
Bug 34478: (follow-up) Manual fix - Make Koha::Token use session id not userenv id

See comment 174.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix www/auth_values_input_www.t
Jonathan Druart [Wed, 28 Feb 2024 09:13:08 +0000 (10:13 +0100)]
Bug 34478: Fix www/auth_values_input_www.t

See bug 36189, we need to rewrite this using Selenium.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - reopen basket - add cud- - basket.tt
Nick Clemens [Tue, 27 Feb 2024 20:05:46 +0000 (15:05 -0500)]
Bug 34478: Manual fix - reopen basket - add cud- - basket.tt

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Add cud to updatestructure
Jonathan Druart [Tue, 27 Feb 2024 14:34:40 +0000 (15:34 +0100)]
Bug 34478: Add cud to updatestructure

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) batchMod
Jonathan Druart [Tue, 27 Feb 2024 14:00:31 +0000 (15:00 +0100)]
Bug 34478: (follow-up) batchMod

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) batch_record_modification
Jonathan Druart [Tue, 27 Feb 2024 13:54:52 +0000 (14:54 +0100)]
Bug 34478: (follow-up) batch_record_modification

Fix Edit > Modify record using template

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix delete from addbiblio
Jonathan Druart [Tue, 27 Feb 2024 13:48:14 +0000 (14:48 +0100)]
Bug 34478: Fix delete from addbiblio

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix delallitems for additem
Jonathan Druart [Tue, 27 Feb 2024 13:42:08 +0000 (14:42 +0100)]
Bug 34478: Fix delallitems for additem

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix saveitem and delete for additem
Jonathan Druart [Tue, 27 Feb 2024 13:19:18 +0000 (14:19 +0100)]
Bug 34478: Fix saveitem and delete for additem

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - adjust op for acqui/cancelorder
Jonathan Druart [Tue, 27 Feb 2024 12:45:11 +0000 (13:45 +0100)]
Bug 34478: Manual fix - adjust op for acqui/cancelorder

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Adjust 'op' on serials/subscription-renew
Jonathan Druart [Tue, 27 Feb 2024 12:23:09 +0000 (13:23 +0100)]
Bug 34478: Adjust 'op' on serials/subscription-renew

multi_renew now has a validation step
This patch also removes 2 variables that were not used ($mode and $done)

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Prevent renew if logged in user is not allowed to
Jonathan Druart [Tue, 27 Feb 2024 10:43:22 +0000 (11:43 +0100)]
Bug 34478: Prevent renew if logged in user is not allowed to

This should be on its own bug. Feel free to do it if you have the
energy, I do not.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Replace delete links with form - smart-rules
Jonathan Druart [Tue, 27 Feb 2024 10:17:30 +0000 (11:17 +0100)]
Bug 34478: Replace delete links with form - smart-rules

We can certainly do better here (too many duplicated code in on click
functions), but it's good enouh for now...

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - remove cud from members/search
Jonathan Druart [Mon, 26 Feb 2024 14:20:25 +0000 (15:20 +0100)]
Bug 34478: Manual fix - remove cud from members/search

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Move to get - reserve/request.tt:248
Jonathan Druart [Mon, 26 Feb 2024 13:38:23 +0000 (14:38 +0100)]
Bug 34478: Move to get - reserve/request.tt:248

This form is never sent

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Move to get - acqui/uncertainprice
Jonathan Druart [Mon, 26 Feb 2024 13:05:54 +0000 (14:05 +0100)]
Bug 34478: Move to get - acqui/uncertainprice

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Convert form to link - sci-main
Jonathan Druart [Mon, 26 Feb 2024 11:32:18 +0000 (12:32 +0100)]
Bug 34478: Convert form to link - sci-main

Nothing to POST, we could move to GET, but we do not have parameters. A
link is good here.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) Fix circ/set-library
Jonathan Druart [Mon, 26 Feb 2024 11:05:21 +0000 (12:05 +0100)]
Bug 34478: (follow-up) Fix circ/set-library

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Corrections to some serials scripts
Owen Leonard [Fri, 23 Feb 2024 18:58:16 +0000 (18:58 +0000)]
Bug 34478: Corrections to some serials scripts

This patch updates the serials toolbar and related JS so that delete,
close, and reopen are all POST operations.

The patch also fixes an incorrect op check in the subscription search
popup.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Correct op name for list edit confirmation
Owen Leonard [Fri, 23 Feb 2024 18:05:16 +0000 (18:05 +0000)]
Bug 34478: Correct op name for list edit confirmation

The 'delete_confirm' op leads to a confirmation page, so it's GET.

The patch also consolidates JS for handling deletions, using the same
class for both the delete button in the toolbar and in the table of
lists.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: OPAC problem reports template update for messages
Owen Leonard [Fri, 23 Feb 2024 16:55:12 +0000 (16:55 +0000)]
Bug 34478: OPAC problem reports template update for messages

The template uses checks on the op value to show messages, so those
checks have to be updated with the new values.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Correct op name in CSV profile deletion confirmation step
Owen Leonard [Fri, 23 Feb 2024 16:52:05 +0000 (16:52 +0000)]
Bug 34478: Correct op name in CSV profile deletion confirmation step

The 'delete_confirm' op leads to a confirmation page, so it's GET.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Correct op name in notice deletion confirmation step
Owen Leonard [Fri, 23 Feb 2024 15:47:43 +0000 (15:47 +0000)]
Bug 34478: Correct op name in notice deletion confirmation step

The 'delete_confirm' op leads to a confirmation page, so it's GET.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fixes for MARC modification template management
Owen Leonard [Fri, 23 Feb 2024 15:30:22 +0000 (15:30 +0000)]
Bug 34478: Fixes for MARC modification template management

This patch converts several delete links to POSTed forms and corrects
the op variable names in the script. The patch also simplifies the
deletion click handlers.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: SQUASH Follow-up to previous batch operations patches
Owen Leonard [Fri, 23 Feb 2024 13:15:39 +0000 (13:15 +0000)]
Bug 34478: SQUASH Follow-up to previous batch operations patches

- Get the CSRF token from the pop-up instead of from the parent window,
  since that seems to work
- Remove some click handlers which were made obsolete

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) Changes for opac-password-recovery
Jonathan Druart [Fri, 23 Feb 2024 12:26:14 +0000 (13:26 +0100)]
Bug 34478: (follow-up) Changes for opac-password-recovery

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: SQUASH further changes to batch biblio operations
Owen Leonard [Fri, 23 Feb 2024 12:08:50 +0000 (12:08 +0000)]
Bug 34478: SQUASH further changes to batch biblio operations

This patch makes a number of changes to finish incomplete work in
668cd06e1960a3878ec1c976ce7f2e1f93688468

Initial submissions to batch biblio operations have to accommodate
POSTed file data, so this patch makes changes to instances where we were
submitting biblionumbers in a URL.

We could also choose to make a change in tools/batch_delete_records.pl
and tools/batch_record_modification.pl to handle different "list"
operations differently based on the method of submission. This patch
presents only the client-side option.

The cart presented a unique problem in that it requires that data be
passed from the pop-up window to the parent window, something which
can't as easily be done with a form as with a URL. The workaround I came
up with is to dynamically generate the form in the parent page and
trigger the submission from there.

Also changed:

- More updated CSS to handle buttons inside dropdowns inside toolbars.
- Correct op names for the "list" operation in batch modify and delete

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - serials/subscription-add.pl
Jonathan Druart [Fri, 23 Feb 2024 12:12:02 +0000 (13:12 +0100)]
Bug 34478: Manual fix - serials/subscription-add.pl

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: import_export_authtype - cud-import, export
Marcel de Rooy [Fri, 23 Feb 2024 10:41:02 +0000 (10:41 +0000)]
Bug 34478: import_export_authtype - cud-import, export

Changing action to op.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) patroncards: FIXMEs for op and missing script
Marcel de Rooy [Fri, 23 Feb 2024 10:23:41 +0000 (10:23 +0000)]
Bug 34478: (follow-up) patroncards: FIXMEs for op and missing script

Looks like create-csv never made it.
Some op's look like GET to me. Creating a pdf is just downloading.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) patroncards: cud-delete from edit-batch and manage
Marcel de Rooy [Fri, 23 Feb 2024 10:02:16 +0000 (10:02 +0000)]
Bug 34478: (follow-up) patroncards: cud-delete from edit-batch and manage

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) patron-cards/edit-batch: op cud-remove, cud-dedup
Marcel de Rooy [Fri, 23 Feb 2024 09:18:54 +0000 (09:18 +0000)]
Bug 34478: (follow-up) patron-cards/edit-batch: op cud-remove, cud-dedup

This is about the links for Remove selected patrons, and Remove duplicates.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: patroncards/edit-batch: Fix for removing patrons
Marcel de Rooy [Fri, 23 Feb 2024 08:36:37 +0000 (08:36 +0000)]
Bug 34478: patroncards/edit-batch: Fix for removing patrons

Added a form for delete link from patron table.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) audio_alerts: Correct duplicate form id's
Marcel de Rooy [Fri, 23 Feb 2024 07:55:02 +0000 (07:55 +0000)]
Bug 34478: (follow-up) audio_alerts: Correct duplicate form id's

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) upload-cover-image.pl: Remove bitwise-and from condition
Marcel de Rooy [Fri, 23 Feb 2024 07:16:02 +0000 (07:16 +0000)]
Bug 34478: (follow-up) upload-cover-image.pl: Remove bitwise-and from condition

Add one character and we should be fine :)

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - tools/batchMod-del
Jonathan Druart [Thu, 22 Feb 2024 15:21:21 +0000 (16:21 +0100)]
Bug 34478: Manual fix - tools/batchMod-del

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - admin/systempreferences
Jonathan Druart [Thu, 22 Feb 2024 15:12:44 +0000 (16:12 +0100)]
Bug 34478: Manual fix - admin/systempreferences

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - admin/patron-attr-types
Jonathan Druart [Thu, 22 Feb 2024 15:07:40 +0000 (16:07 +0100)]
Bug 34478: Manual fix - admin/patron-attr-types

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - admin/matching-rules
Jonathan Druart [Thu, 22 Feb 2024 15:03:10 +0000 (16:03 +0100)]
Bug 34478: Manual fix - admin/matching-rules

Bug 34478: [TO SQUASH] Manual fix - admin/matching-rules

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - acqui/basket.pl - export
Jonathan Druart [Thu, 22 Feb 2024 15:01:01 +0000 (16:01 +0100)]
Bug 34478: Manual fix - acqui/basket.pl - export

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - acqui/duplicate_orders.tt
Jonathan Druart [Thu, 22 Feb 2024 14:59:01 +0000 (15:59 +0100)]
Bug 34478: Manual fix - acqui/duplicate_orders.tt

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - acqui/vendor_issues.pl
Jonathan Druart [Thu, 22 Feb 2024 14:50:51 +0000 (15:50 +0100)]
Bug 34478: Manual fix - acqui/vendor_issues.pl

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Correct check of list op in batch record modification
Owen Leonard [Thu, 22 Feb 2024 12:46:52 +0000 (12:46 +0000)]
Bug 34478: Correct check of list op in batch record modification

The "list" step (previewing records to be modified) is a post operation
so the op must be cud-list.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - add cud- op for checkouts - circulation.tt
Nick Clemens [Thu, 22 Feb 2024 12:39:06 +0000 (07:39 -0500)]
Bug 34478: Manual fix - add cud- op for checkouts - circulation.tt

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix style and markup of forms within dropdowns
Owen Leonard [Thu, 22 Feb 2024 12:10:16 +0000 (12:10 +0000)]
Bug 34478: Fix style and markup of forms within dropdowns

This patch adds some CSS for handling the style of form buttons inside
Bootstrap dropdowns and corrects related markup in two places: Authority
search results and Suggestion management.

Buttons should look correct if we avoid using <fieldset> inside
dropdowns and make sure the button has "btn btn-default" classes.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix selenium/administration_tasks.t
Jonathan Druart [Thu, 22 Feb 2024 10:05:20 +0000 (11:05 +0100)]
Bug 34478: Fix selenium/administration_tasks.t

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - add cud- op - alert-subscriptions.pl
Nick Clemens [Wed, 21 Feb 2024 19:56:41 +0000 (14:56 -0500)]
Bug 34478: Manual fix - add cud- op - alert-subscriptions.pl

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - remove csrf - histsearch.tt
Nick Clemens [Wed, 21 Feb 2024 19:24:35 +0000 (14:24 -0500)]
Bug 34478: Manual fix - remove csrf - histsearch.tt

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - add cud- ops or remove form submit - returns.tt / checkin...
Nick Clemens [Wed, 21 Feb 2024 19:14:57 +0000 (14:14 -0500)]
Bug 34478: Manual fix - add cud- ops or remove form submit - returns.tt / checkin-search-box.inc

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Remove warnings from members/memberentry.pl
Jonathan Druart [Wed, 21 Feb 2024 13:04:50 +0000 (14:04 +0100)]
Bug 34478: Remove warnings from members/memberentry.pl

Use of uninitialized value $op in string eq at /kohadevbox/koha/members/memberentry.pl line 86.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - Make Koha::Token use session id not userenv id
David Cook [Thu, 15 Feb 2024 03:06:00 +0000 (03:06 +0000)]
Bug 34478: Manual fix - Make Koha::Token use session id not userenv id

Bug 34478: [TO SQUASH] Manual fix - Make Koha::Token use session id not userenv id

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix sco-patron-image.pl access control regression
David Cook [Tue, 20 Feb 2024 23:06:08 +0000 (23:06 +0000)]
Bug 34478: Fix sco-patron-image.pl access control regression

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Update numbering patterns modification and deletion
Owen Leonard [Tue, 20 Feb 2024 19:38:34 +0000 (19:38 +0000)]
Bug 34478: Update numbering patterns modification and deletion

The numbering patterns script has been update to look for "cud-modify"
to load the edit form, but that's a GET operation and can stay "modify."

The delete buttons have been updated to be a POSTed form.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Comment deletion should be POSTed form
Owen Leonard [Tue, 20 Feb 2024 19:26:56 +0000 (19:26 +0000)]
Bug 34478: Comment deletion should be POSTed form

This patch updates the "Delete" button on the comments moderation page
to convert the GET link to a posted form.

Unrelated: The JavaScript has also been modified so that it asks for
confirmation.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Item removal deletion should be POSTed form
Owen Leonard [Tue, 20 Feb 2024 19:19:24 +0000 (19:19 +0000)]
Bug 34478: Item removal deletion should be POSTed form

This patch updates the "Remove" button from items which are in a
rotating collection (in the "Manage items" stage). A GET link is
converted to a posted form.

Unrelated: The JavaScript has also been modified so that it asks for
confirmation.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix name of CGI variable
Owen Leonard [Tue, 20 Feb 2024 17:16:04 +0000 (17:16 +0000)]
Bug 34478: Fix name of CGI variable

'$query->param' in this script should be '$input->param'

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Convert patron file delete link to a posted form
Owen Leonard [Tue, 20 Feb 2024 15:49:41 +0000 (15:49 +0000)]
Bug 34478: Convert patron file delete link to a posted form

This patch modifies the patron file template to convert the "Delete"
link to a form which includes the CSRF token. The script has already
been modified to check for the "op" value updated in the template.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix various parameters on housebound details page
Owen Leonard [Tue, 20 Feb 2024 15:37:42 +0000 (15:37 +0000)]
Bug 34478: Fix various parameters on housebound details page

This patch converts the delivery delete buttons to a form and changes
the corresponding op check in the script.

The patch also fixes an error in the form markup and corrects the op
parameter name in several links.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Correct value of "op" when loading the edit form.
Owen Leonard [Fri, 16 Feb 2024 17:00:27 +0000 (17:00 +0000)]
Bug 34478: Correct value of "op" when loading the edit form.

The op doesn't need "cud-" because it's a GET operation.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Correct op value for SMS provider deletion
Owen Leonard [Fri, 16 Feb 2024 16:51:31 +0000 (16:51 +0000)]
Bug 34478: Correct op value for SMS provider deletion

The op value is set in the JavaScript, where it hasn't been updated to
match the "cud-delete" value checked in the script.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Corrections to add and delete of OAI sets
Owen Leonard [Fri, 16 Feb 2024 14:18:06 +0000 (14:18 +0000)]
Bug 34478: Corrections to add and delete of OAI sets

This patch makes two changes: The first changes the name of the op value
matched in the script when editing a set. The "mod" step is a GET
operation to load the edit form.

The second change is a workaround for the fact that a submit
button looks bad in a Bootstrap dropdown. The patch creates a hidden
form for deletion operations. Clicking a "delete" link in a dropdown
fills the hidden form with the OAI set id to be deleted and submits it.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Item type deletion - correct delete_confirm and delete_confirmed
Owen Leonard [Fri, 16 Feb 2024 13:32:30 +0000 (13:32 +0000)]
Bug 34478: Item type deletion - correct delete_confirm and delete_confirmed

"delete_confirm" is a GET operation leading to a confirmation page,
where "cud-delete_confirmed" should submit a POST to delete.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Convert item search field delete to POST form
Owen Leonard [Fri, 16 Feb 2024 13:21:38 +0000 (13:21 +0000)]
Bug 34478: Convert item search field delete to POST form

This patch converts the delete link on the item search field page to a
form with a POST operation.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix op variable in item circulation alerts
Owen Leonard [Fri, 16 Feb 2024 13:06:55 +0000 (13:06 +0000)]
Bug 34478: Fix op variable in item circulation alerts

The AJAX call in the template still used "action" instead of
"op".

The patch also fixes references to "action" in the POD and corrects
"toggle" to "cud-toggle".

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Add notes to pay.pl
Martin Renvoize [Fri, 16 Feb 2024 12:29:11 +0000 (12:29 +0000)]
Bug 34478: Add notes to pay.pl

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Add cud-pay and cud-writeoff to paycollect
Martin Renvoize [Fri, 16 Feb 2024 12:21:25 +0000 (12:21 +0000)]
Bug 34478: Add cud-pay and cud-writeoff to paycollect

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Add op to pay_individual
Martin Renvoize [Fri, 16 Feb 2024 09:32:57 +0000 (09:32 +0000)]
Bug 34478: Add op to pay_individual

I also move the writeoff handling out of it's own block in into the rest
of the x_individual handling.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Move writeoff-individual to paycollect.pl
Martin Renvoize [Thu, 15 Feb 2024 17:10:00 +0000 (17:10 +0000)]
Bug 34478: Move writeoff-individual to paycollect.pl

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Fix op check in table settings admin
Owen Leonard [Fri, 16 Feb 2024 11:46:50 +0000 (11:46 +0000)]
Bug 34478: Fix op check in table settings admin

The "action" hidden field was renamed to "op", but "action" was still
being looked for in the script.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Changes for opac-shareshelf
Marcel de Rooy [Fri, 16 Feb 2024 10:42:16 +0000 (10:42 +0000)]
Bug 34478: Changes for opac-shareshelf

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Changes for suggestion/suggestion
Marcel de Rooy [Thu, 15 Feb 2024 11:07:29 +0000 (11:07 +0000)]
Bug 34478: Changes for suggestion/suggestion

Too much changes needed. Main functionality works again.
Some improvements can still be made.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Make plack.psgi change more comprehensive
David Cook [Fri, 16 Feb 2024 00:11:10 +0000 (00:11 +0000)]
Bug 34478: Make plack.psgi change more comprehensive

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Classification config - Convert delete links to form POSTS
Owen Leonard [Thu, 15 Feb 2024 18:02:02 +0000 (18:02 +0000)]
Bug 34478: Classification config - Convert delete links to form POSTS

This patch converts the delete links on the classification
configuration page for sources, filing rules, and splitting rules to
POST forms.

A couple of op checks in the script are corrected to match.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Cities - Incorrect op check for cud-delete_confirm
Owen Leonard [Thu, 15 Feb 2024 17:35:32 +0000 (17:35 +0000)]
Bug 34478: Cities - Incorrect op check for cud-delete_confirm

On the cities administration page, the delete button is a GET operation
to a second form for confirmation.

This script should be checking for op=delete_confirm, not
cud-delete_confirm.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Convert authorised value delete link to POST form
Owen Leonard [Thu, 15 Feb 2024 17:07:01 +0000 (17:07 +0000)]
Bug 34478: Convert authorised value delete link to POST form

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Authority frameworks - first subfield delete button has incorrect op value
Owen Leonard [Thu, 15 Feb 2024 16:35:39 +0000 (16:35 +0000)]
Bug 34478: Authority frameworks - first subfield delete button has incorrect op value

From the list of a tag's subfields (e.g.
/cgi-bin/koha/admin/auth_subfields_structure.pl?tagfield=245&frameworkcode=)
the delete button is a GET operation to a second form for confirmation.

This script should be checking for op=delete_confirm, not cud-delete-confirm.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Frameworks - first subfield delete button has incorrect op value
Owen Leonard [Thu, 15 Feb 2024 16:19:56 +0000 (16:19 +0000)]
Bug 34478: Frameworks - first subfield delete button has incorrect op value

From the list of a tag's subfields (e.g.
/cgi-bin/koha/admin/marc_subfields_structure.pl?tagfield=245&frameworkcode=)
the delete button is a GET operation to a second form for confirmation.

This script should be checking for op=delete_confirm, not
cud-delete-confirm.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Convert EDIFACT messages deletion to POST
Owen Leonard [Thu, 15 Feb 2024 15:10:56 +0000 (15:10 +0000)]
Bug 34478: Convert EDIFACT messages deletion to POST

Modify DataTables rendering to put the delete button inside a POSTed
form.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Use op and cud in pay -> paycollect redirect
Martin Renvoize [Thu, 15 Feb 2024 15:25:17 +0000 (15:25 +0000)]
Bug 34478: Use op and cud in pay -> paycollect redirect

The pay to paycollect post/redirect flow here doesn't actually
consistute a state change, however it's much simpler to add the csrf
token check flow here than to refactor the code to a get (url's quickly
grow too large for a GET) or rework it in other ways.  I opted to do
this for now and work on a refactor at a future date.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Re-correct account-table pay
Martin Renvoize [Thu, 15 Feb 2024 13:03:39 +0000 (13:03 +0000)]
Bug 34478: Re-correct account-table pay

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Basket group export CSV option should not check cud-op
Owen Leonard [Thu, 15 Feb 2024 12:32:25 +0000 (12:32 +0000)]
Bug 34478: Basket group export CSV option should not check cud-op

The Export CSV operation is GET and uses op=export, so the script should
not check for "cud-op."

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Changes for authorities/searchresultlist (new delete form)
Marcel de Rooy [Thu, 15 Feb 2024 09:13:15 +0000 (09:13 +0000)]
Bug 34478: Changes for authorities/searchresultlist (new delete form)

Replaces a delete with GET.
FIXME: Trouble with closing dropdown.

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Regression - fix installer stuck
Jonathan Druart [Thu, 15 Feb 2024 09:43:06 +0000 (10:43 +0100)]
Bug 34478: Regression - fix installer stuck

Installer was stuck after "Set up database" with a blank page

It also fixes 00-onboarding.t

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Regression - fix change auth type
Jonathan Druart [Thu, 15 Feb 2024 09:24:02 +0000 (10:24 +0100)]
Bug 34478: Regression - fix change auth type

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Regression - fix change framework
Jonathan Druart [Thu, 15 Feb 2024 09:18:37 +0000 (10:18 +0100)]
Bug 34478: Regression - fix change framework

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: (follow-up) Change invoice files delete link to POST
Owen Leonard [Wed, 14 Feb 2024 18:51:57 +0000 (18:51 +0000)]
Bug 34478: (follow-up) Change invoice files delete link to POST

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - Fix controller op handling of self-checkout
David Cook [Thu, 15 Feb 2024 03:06:36 +0000 (03:06 +0000)]
Bug 34478: Manual fix - Fix controller op handling of self-checkout

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
4 months agoBug 34478: Manual fix - Fix session cookie management of self-checkout
David Cook [Thu, 15 Feb 2024 00:35:16 +0000 (00:35 +0000)]
Bug 34478: Manual fix - Fix session cookie management of self-checkout

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>