userdaydetaillog.php 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150
  1. <?php
  2. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/auth.php");
  3. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/languages/" . HTML_LANG . ".php");
  4. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/header.php");
  5. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/idfilter.php");
  6. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/datetimefilter.php");
  7. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/gatefilter.php");
  8. $default_sort='id';
  9. $sort_table = 'A';
  10. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/sortfilter.php");
  11. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/search.php");
  12. $rdns = 0;
  13. if (isset($_POST['dns'])) { $rdns=$_POST['dns']*1; }
  14. $_SESSION[$page_url]['dns']=$rdns;
  15. $dns_checked='';
  16. if ($rdns) { $dns_checked='checked="checked"'; }
  17. $dns_cache=NULL;
  18. $usersip = get_record_sql($db_link, "SELECT ip,user_id,description FROM user_auth WHERE user_auth.id=?", [ $id ]);
  19. if (empty($usersip)) {
  20. header("location: /admin/reports/index-full.php");
  21. exit;
  22. }
  23. $fip = $usersip['ip'];
  24. $parent = $usersip['user_id'];
  25. $fcomm = $usersip['description'];
  26. print_trafdetail_submenu($page_url,"id=$id&date_start='$date1'&date_stop='$date2'","<b>".WEB_log_detail_for."&nbsp<a href=/admin/users/editauth.php?id=$id>$fip</a></b> ::&nbsp");
  27. ?>
  28. <div id="contsubmenu">
  29. <form action="<?php print $page_url; ?>" method="post">
  30. <input type="hidden" name="id" value=<?php echo $id; ?>>
  31. <?php print_date_fields($date1,$date2,$date_shift); ?>
  32. <?php echo WEB_cell_gateway; ?>:&nbsp <?php print_gateway_select($db_link, 'gateway', $rgateway); ?>
  33. DNS:&nbsp <input type=checkbox name=dns value="1" <?php print $dns_checked; ?>>
  34. <?php echo WEB_search; ?>:&nbsp<input type="text" minlength="7" maxlength="15" size="15" pattern="^(?>(\d|[1-9]\d{2}|1\d\d|2[0-4]\d|25[0-5])\.){3}(?1)$" name="search" value="<?php echo $search; ?>" />
  35. <?php print WEB_rows_at_page."&nbsp"; print_row_at_pages('rows',$displayed); ?>
  36. <input type="submit" value="<?php echo WEB_btn_show; ?>">
  37. </form>
  38. <b><?php echo WEB_log_full; ?></b>
  39. <?php
  40. $sort_url = "<a href='userdaydetaillog.php?id=".$id.'&date_start="'.$date1.'"&date_stop="'.$date2.'"';
  41. // === 1. Валидация и подготовка параметров ===
  42. $params = [$date1, $date2, (int)$id];
  43. $conditions = ["ts >= ?", "ts < ?", "auth_id = ?"];
  44. // Фильтр по gateway
  45. if (!empty($rgateway) && $rgateway > 0) {
  46. $conditions[] = "router_id = ?";
  47. $params[] = (int)$rgateway;
  48. }
  49. // Фильтр по IP (если search — валидный IPv4)
  50. if (!empty($search) && filter_var($search, FILTER_VALIDATE_IP, FILTER_FLAG_IPV4)) {
  51. $ip_long = sprintf('%u', ip2long($search)); // беззнаковое число
  52. $conditions[] = "(src_ip = ? OR dst_ip = ?)";
  53. $params[] = $ip_long;
  54. $params[] = $ip_long;
  55. }
  56. $whereClause = implode(' AND ', $conditions);
  57. // === 2. Подсчёт записей ===
  58. $countSQL = "SELECT COUNT(*) FROM traffic_detail WHERE $whereClause";
  59. $count_records = (int)get_single_field($db_link, $countSQL, $params);
  60. // === 3. Пагинация ===
  61. $total = ceil($count_records / $displayed);
  62. $page = max(1, min($page, $total));
  63. $start = ($page - 1) * $displayed;
  64. print_navigation($page_url, $page, $displayed, $count_records, $total);
  65. // === 4. Безопасная сортировка (БЕЛЫЙ СПИСОК!) ===
  66. $allowed_sort_fields = ['ts', 'proto', 'src_ip', 'dst_ip', 'bytes', 'pkt'];
  67. $allowed_order = ['ASC', 'DESC'];
  68. $sort_field = in_array($sort_field, $allowed_sort_fields, true) ? $sort_field : 'ts';
  69. $order = in_array(strtoupper($order), $allowed_order, true) ? strtoupper($order) : 'ASC';
  70. // === 5. Запрос данных с пагинацией ===
  71. $limit = (int)$displayed;
  72. $offset = (int)$start;
  73. $dataParams = array_merge($params, [$limit, $offset]);
  74. // Используем прямой запрос (без подзапроса — он не нужен для пагинации по id)
  75. $fsql = "
  76. SELECT id, ts, router_id, proto, src_ip, src_port, dst_ip, dst_port, bytes, pkt
  77. FROM traffic_detail
  78. WHERE $whereClause
  79. ORDER BY $sort_field $order
  80. LIMIT ? OFFSET ?
  81. ";
  82. $userdata = get_records_sql($db_link, $fsql, $dataParams);
  83. ?>
  84. <br>
  85. <table class="data">
  86. <tr align="center">
  87. <td class="data" width=150><b><?php $url = $sort_url.'&sort=ts&order='.$new_order."'>".WEB_date."</a>"; print $url; ?></b></td>
  88. <td class="data" width=30><b><?php echo WEB_cell_gateway; ?></b></td>
  89. <td class="data" width=30><b><?php echo WEB_traffic_proto; ?></b></td>
  90. <td class="data" width=150><b><?php $url = $sort_url.'&sort=src_ip&order='.$new_order."'>".WEB_traffic_source_address."</a>"; print $url; ?></b></td>
  91. <td class="data"><b>DNS</b></td>
  92. <td class="data" width=50><b><?php echo WEB_traffic_src_port; ?></b></td>
  93. <td class="data" width=150><b><?php $url = $sort_url.'&sort=dst_ip&order='.$new_order."'>".WEB_traffic_dest_address."</a>"; print $url; ?></b></td>
  94. <td class="data"><b>DNS</b></td>
  95. <td class="data" width=50><b><?php echo WEB_traffic_dst_port; ?></b></td>
  96. <td class="data" width=80><b><?php $url = $sort_url.'&sort=bytes&order='.$new_order."'>".WEB_bytes."</a>"; print $url; ?></b></td>
  97. <td class="data" width=80><b><?php $url = $sort_url.'&sort=pkt&order='.$new_order."'>".WEB_pkts."</a>"; print $url; ?></b></td>
  98. </tr>
  99. <?php
  100. foreach ($userdata as $row) {
  101. print "<tr align=center class=\"tr1\" onmouseover=\"className='tr2'\" onmouseout=\"className='tr1'\">\n";
  102. print "<td class=\"data\">" . $row['ts'] . "</td>\n";
  103. print "<td class=\"data\">" . $gateway_list[$row['router_id']] . "</td>\n";
  104. $proto_name = getprotobynumber($row['proto']);
  105. if (!$proto_name) { $proto_name = $row['proto']; }
  106. print "<td class=\"data\">" . $proto_name . "</td>\n";
  107. print "<td class=\"data\" align=left>" . long2ip($row['src_ip']) . "</td>\n";
  108. $ip_name = '-';
  109. if ($rdns) { $ip_name = ResolveIP($db_link, $row['src_ip']); }
  110. print "<td class=\"data\" align=left>" . $ip_name . "</td>\n";
  111. print "<td class=\"data\">" . $row['src_port'] . "</td>\n";
  112. print "<td class=\"data\" align=left>" . long2ip($row['dst_ip']) . "</td>\n";
  113. $ip_name = '-';
  114. if ($rdns) { $ip_name = ResolveIP($db_link, $row['dst_ip']); }
  115. print "<td class=\"data\" align=left>" . $ip_name . "</td>\n";
  116. print "<td class=\"data\">" . $row['dst_port'] . "</td>\n";
  117. print "<td class=\"data\" align=right>" . fbytes($row['bytes']) . "</td>\n";
  118. print "<td class=\"data\" align=right>" . $row['pkt'] . "</td>\n";
  119. print "</tr>\n";
  120. }
  121. ?>
  122. </table>
  123. <?php print_navigation($page_url,$page,$displayed,$count_records,$total); ?>
  124. <br>
  125. <?php
  126. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/footer.php");
  127. ?>