1
0

userdaydetaillog.php 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151
  1. <?php
  2. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/auth.php");
  3. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/languages/" . HTML_LANG . ".php");
  4. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/header.php");
  5. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/idfilter.php");
  6. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/datetimefilter.php");
  7. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/gatefilter.php");
  8. $default_sort='id';
  9. $sort_table = 'A';
  10. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/sortfilter.php");
  11. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/search.php");
  12. $rdns = 0;
  13. if (isset($_POST['dns'])) { $rdns=$_POST['dns']*1; }
  14. $_SESSION[$page_url]['dns']=$rdns;
  15. $dns_checked='';
  16. if ($rdns) { $dns_checked='checked="checked"'; }
  17. $dns_cache=NULL;
  18. $gateway_list = get_gateways($db_link);
  19. $usersip = get_record_sql($db_link, "SELECT ip,user_id,description FROM user_auth WHERE user_auth.id=?", [ $id ]);
  20. if (empty($usersip)) {
  21. header("location: /admin/reports/index-full.php");
  22. exit;
  23. }
  24. $fip = $usersip['ip'];
  25. $parent = $usersip['user_id'];
  26. $fcomm = $usersip['description'];
  27. print_trafdetail_submenu($page_url,"id=$id&date_start='$date1'&date_stop='$date2'","<b>".WEB_log_detail_for."&nbsp<a href=/admin/users/editauth.php?id=$id>$fip</a></b> ::&nbsp");
  28. ?>
  29. <div id="contsubmenu">
  30. <form action="<?php print $page_url; ?>" method="post">
  31. <input type="hidden" name="id" value=<?php echo $id; ?>>
  32. <?php print_date_fields($date1,$date2,$date_shift); ?>
  33. <?php echo WEB_cell_gateway; ?>:&nbsp <?php print_gateway_select($db_link, 'gateway', $rgateway); ?>
  34. DNS:&nbsp <input type=checkbox name=dns value="1" <?php print $dns_checked; ?>>
  35. <?php echo WEB_search; ?>:&nbsp<input type="text" minlength="7" maxlength="15" size="15" pattern="^(?>(\d|[1-9]\d{2}|1\d\d|2[0-4]\d|25[0-5])\.){3}(?1)$" name="search" value="<?php echo $search; ?>" />
  36. <?php print WEB_rows_at_page."&nbsp"; print_row_at_pages('rows',$displayed); ?>
  37. <input type="submit" value="<?php echo WEB_btn_show; ?>">
  38. </form>
  39. <b><?php echo WEB_log_full; ?></b>
  40. <?php
  41. $sort_url = "<a href='userdaydetaillog.php?id=".$id.'&date_start="'.$date1.'"&date_stop="'.$date2.'"';
  42. // === 1. Валидация и подготовка параметров ===
  43. $params = [$date1, $date2, (int)$id];
  44. $conditions = ["ts >= ?", "ts < ?", "auth_id = ?"];
  45. // Фильтр по gateway
  46. if (!empty($rgateway) && $rgateway > 0) {
  47. $conditions[] = "router_id = ?";
  48. $params[] = (int)$rgateway;
  49. }
  50. // Фильтр по IP (если search — валидный IPv4)
  51. if (!empty($search) && filter_var($search, FILTER_VALIDATE_IP, FILTER_FLAG_IPV4)) {
  52. $ip_long = sprintf('%u', ip2long($search)); // беззнаковое число
  53. $conditions[] = "(src_ip = ? OR dst_ip = ?)";
  54. $params[] = $ip_long;
  55. $params[] = $ip_long;
  56. }
  57. $whereClause = implode(' AND ', $conditions);
  58. // === 2. Подсчёт записей ===
  59. $countSQL = "SELECT COUNT(*) FROM traffic_detail WHERE $whereClause";
  60. $count_records = (int)get_single_field($db_link, $countSQL, $params);
  61. // === 3. Пагинация ===
  62. $total = ceil($count_records / $displayed);
  63. $page = max(1, min($page, $total));
  64. $start = ($page - 1) * $displayed;
  65. print_navigation($page_url, $page, $displayed, $count_records, $total);
  66. // === 4. Безопасная сортировка (БЕЛЫЙ СПИСОК!) ===
  67. $allowed_sort_fields = ['ts', 'proto', 'src_ip', 'dst_ip', 'bytes', 'pkt'];
  68. $allowed_order = ['ASC', 'DESC'];
  69. $sort_field = in_array($sort_field, $allowed_sort_fields, true) ? $sort_field : 'ts';
  70. $order = in_array(strtoupper($order), $allowed_order, true) ? strtoupper($order) : 'ASC';
  71. // === 5. Запрос данных с пагинацией ===
  72. $limit = (int)$displayed;
  73. $offset = (int)$start;
  74. $dataParams = array_merge($params, [$limit, $offset]);
  75. // Используем прямой запрос (без подзапроса — он не нужен для пагинации по id)
  76. $fsql = "
  77. SELECT id, ts, router_id, proto, src_ip, src_port, dst_ip, dst_port, bytes, pkt
  78. FROM traffic_detail
  79. WHERE $whereClause
  80. ORDER BY $sort_field $order
  81. LIMIT ? OFFSET ?
  82. ";
  83. $userdata = get_records_sql($db_link, $fsql, $dataParams);
  84. ?>
  85. <br>
  86. <table class="data">
  87. <tr align="center">
  88. <td class="data" width=150><b><?php $url = $sort_url.'&sort=ts&order='.$new_order."'>".WEB_date."</a>"; print $url; ?></b></td>
  89. <td class="data" width=30><b><?php echo WEB_cell_gateway; ?></b></td>
  90. <td class="data" width=30><b><?php echo WEB_traffic_proto; ?></b></td>
  91. <td class="data" width=150><b><?php $url = $sort_url.'&sort=src_ip&order='.$new_order."'>".WEB_traffic_source_address."</a>"; print $url; ?></b></td>
  92. <td class="data"><b>DNS</b></td>
  93. <td class="data" width=50><b><?php echo WEB_traffic_src_port; ?></b></td>
  94. <td class="data" width=150><b><?php $url = $sort_url.'&sort=dst_ip&order='.$new_order."'>".WEB_traffic_dest_address."</a>"; print $url; ?></b></td>
  95. <td class="data"><b>DNS</b></td>
  96. <td class="data" width=50><b><?php echo WEB_traffic_dst_port; ?></b></td>
  97. <td class="data" width=80><b><?php $url = $sort_url.'&sort=bytes&order='.$new_order."'>".WEB_bytes."</a>"; print $url; ?></b></td>
  98. <td class="data" width=80><b><?php $url = $sort_url.'&sort=pkt&order='.$new_order."'>".WEB_pkts."</a>"; print $url; ?></b></td>
  99. </tr>
  100. <?php
  101. foreach ($userdata as $row) {
  102. print "<tr align=center class=\"tr1\" onmouseover=\"className='tr2'\" onmouseout=\"className='tr1'\">\n";
  103. print "<td class=\"data\">" . $row['ts'] . "</td>\n";
  104. print "<td class=\"data\">" . $gateway_list[$row['router_id']] . "</td>\n";
  105. $proto_name = getprotobynumber($row['proto']);
  106. if (!$proto_name) { $proto_name = $row['proto']; }
  107. print "<td class=\"data\">" . $proto_name . "</td>\n";
  108. print "<td class=\"data\" align=left>" . long2ip($row['src_ip']) . "</td>\n";
  109. $ip_name = '-';
  110. if ($rdns) { $ip_name = ResolveIP($db_link, $row['src_ip']); }
  111. print "<td class=\"data\" align=left>" . $ip_name . "</td>\n";
  112. print "<td class=\"data\">" . $row['src_port'] . "</td>\n";
  113. print "<td class=\"data\" align=left>" . long2ip($row['dst_ip']) . "</td>\n";
  114. $ip_name = '-';
  115. if ($rdns) { $ip_name = ResolveIP($db_link, $row['dst_ip']); }
  116. print "<td class=\"data\" align=left>" . $ip_name . "</td>\n";
  117. print "<td class=\"data\">" . $row['dst_port'] . "</td>\n";
  118. print "<td class=\"data\" align=right>" . fbytes($row['bytes']) . "</td>\n";
  119. print "<td class=\"data\" align=right>" . $row['pkt'] . "</td>\n";
  120. print "</tr>\n";
  121. }
  122. ?>
  123. </table>
  124. <?php print_navigation($page_url,$page,$displayed,$count_records,$total); ?>
  125. <br>
  126. <?php
  127. require_once ($_SERVER['DOCUMENT_ROOT']."/inc/footer.php");
  128. ?>