ESH/audit_log_script.php
2024-10-23 18:28:06 +05:30

133 lines
4.4 KiB
PHP

<?php
include('includes/config/config.php');
include('includes/auth/auth.php');
include('includes/functions.php');include('access.php');
include('log_entry.php');
error_reporting ( E_ERROR | E_PARSE );
?>
<?php
// Connect to mysqli database
$page = 1; // The current page
$sortname = 'created_time'; // Sort column
$sortorder = 'desc'; // Sort order
$qtype = ''; // Search column
$query = ''; // Search string
// Get posted data
if (isset($_POST['page'])) {
$page = mysqli_real_escape_string($conn,$_POST['page']);
}
if (isset($_POST['sortname'])) {
$sortname = mysqli_real_escape_string($conn,$_POST['sortname']);
}
if (isset($_POST['sortorder'])) {
$sortorder = mysqli_real_escape_string($conn,$_POST['sortorder']);
}
if (isset($_POST['qtype'])) {
$qtype = mysqli_real_escape_string($conn,$_POST['qtype']);
}
if (isset($_POST['query'])) {
$query = mysqli_real_escape_string($conn,$_POST['query']);
}
if (isset($_POST['rp'])) {
$rp = mysqli_real_escape_string($conn,$_POST['rp']);
}
if (! isSet($rp)) {
$rp = 20;
}
// Setup sort and search SQL using posted data
$sortSql = "order by $sortname $sortorder";
$searchSql = ($qtype != '' && $query != '') ? "where upper($qtype) like upper('%" . trim($query) . "%')" : '';
if ($searchSql != '') {
if ($qtype == 'created_time') {
$searchSql = " and date_format(date(created_time),'%Y-%m-%d')=str_to_date('$query','%d/%m/%Y') ";
// $searchSql = " and date_format(date(appointment_date),'%Y-%m-%d')=str_to_date('$query','%d-%m-%Y') ";
}
}
error_log("searchsql:".$searchSql);
// Get total count of records
$searchSql=preg_replace('/and/', 'where', $searchSql, 1);
$sql = "select count(*) from audit_log $searchSql";
$result = mysqli_query($conn,$sql);
$row = mysqli_fetch_array($result);
$total = $row[0];
// Setup paging SQL
$pageStart = ($page-1)*$rp;
$limitSql = "limit $pageStart, $rp";
// Return JSON data
$data = array();
$data['page'] = $page;
$data['total'] = $total;
$data['rows'] = array();
$sql_medicine = "select id,created_time,feature_name,feature_action,file_name,modified_by,request_param from audit_log ";
//echo $sql;
$sql_export=$sql_medicine;
$sql_medicine .="$searchSql $sortSql $limitSql";
error_log("compl sql:".$sql_medicine);
error_log("sql:".$sql_medicine);
$sql_export .="$searchSql $sortSql ";
$results = mysqli_query($conn,$sql_medicine);
$count=($page-1)*$rp+1;
while ($row_med = mysqli_fetch_assoc($results)) {
$id=$row_med['id'];
$user=$row_med['modified_by'];
$user_query="SELECT b.role_name FROM tbl_users a left join role_master b on a.role_id=b.role_id left join patient_master e on a.emp_id=e.id where a.user_id='".$user."'";
$result2=mysqli_query($conn,$user_query);
$row3=mysqli_fetch_assoc($result2);
// if($access_level=='R' ||$access_level=='W' || $access_level=='E' )
// {
// $view_link="<a href=\"#\"class=\"grey\" onclick=\"open_medicine_usage_cat('".$medicine_usage_cat_id."','V');\"><i class=\"ace-icon fa fa-eye bigger-130\"></i></a>";
// }
// if($access_level=='W' || $access_level=='E' )
// {
// $edit_link="<a href=\"#\" class=\"blue\" onclick=\"open_medicine_usage_cat('".$medicine_usage_cat_id."','E');\"><i class=\"ace-icon fa fa-edit bigger-130\"></i></a>";
// }
// if($access_level=='W' || $access_level=='E' )
// {
// $delete_link = "<a href=\"#\" class=\"blue\" onclick=\"delete_medicine_category('" .$medicine_usage_cat_id. "');\"><i class=\"ace-icon fa fa-trash-o bigger-130\"></i></a>";
// }
// $space="&nbsp;&nbsp;&nbsp;";
// $links = $assign_link.$space.$view_link.$space.$edit_link.$space.$delete_link;
//$links="<div class=\"hidden-sm hidden-xs btn-group\">".$links."</div>";
$data['rows'][] = array(
'id' => $row_med['id'],
'cell' => array($count++, date_format(date_create($row_med['created_time']), "d-M-Y H:i A"),
$row_med['feature_name'],$row_med['feature_action'],$row_med['file_name'],$row3['role_name'],$row_med['request_param'])
);
}
$data['rows'][] = array(
'id' => $row['filterkey'],
'cell' => array(
'',
"<input type=hidden name='filterkey' id='filterkey' value=\"" . base64_encode($sql_export) . "\">",
"<input type=hidden name=paramlist id=paramlist value=\"" . base64_encode($paramlist) . "\">",
'',
'',
'',
'',
'',
'',
'',
'',
'',
'',
'',
'',
'',
'',
'',
'',
''
)
);
echo json_encode($data);
?>