, lots of cleanup + several improvements */ /** * Code */ // name of the language file that needs to be included $language_file = array('exercice','tracking'); // including the global library require_once '../inc/global.inc.php'; require_once '../gradebook/lib/be.inc.php'; // Setting the tabs $this_section = SECTION_COURSES; $htmlHeadXtra[] = api_get_jquery_ui_js(); // Access control api_protect_course_script(true); $show = (isset ($_GET['show']) && $_GET['show'] == 'result') ? 'result' : 'test'; // moved down to fix bug: http://www.dokeos.com/forum/viewtopic.php?p=18609#18609 // including additional libraries require_once 'exercise.class.php'; require_once 'exercise.lib.php'; require_once 'question.class.php'; require_once 'answer.class.php'; require_once api_get_path(LIBRARY_PATH) . 'fileManage.lib.php'; require_once api_get_path(LIBRARY_PATH) . 'fileUpload.lib.php'; require_once 'hotpotatoes.lib.php'; require_once api_get_path(LIBRARY_PATH) . 'document.lib.php'; require_once api_get_path(LIBRARY_PATH) . 'mail.lib.inc.php'; /* Constants and variables */ $is_allowedToEdit = api_is_allowed_to_edit(null,true); $is_tutor = api_is_allowed_to_edit(true); $is_tutor_course = api_is_course_tutor(); $tbl_course_rel_user = Database :: get_main_table(TABLE_MAIN_COURSE_USER); $TBL_USER = Database :: get_main_table(TABLE_MAIN_USER); $TBL_DOCUMENT = Database :: get_course_table(TABLE_DOCUMENT); $TBL_ITEM_PROPERTY = Database :: get_course_table(TABLE_ITEM_PROPERTY); $TBL_EXERCICE_ANSWER = Database :: get_course_table(TABLE_QUIZ_ANSWER); $TBL_EXERCICE_QUESTION = Database :: get_course_table(TABLE_QUIZ_TEST_QUESTION); $TBL_EXERCICES = Database :: get_course_table(TABLE_QUIZ_TEST); $TBL_QUESTIONS = Database :: get_course_table(TABLE_QUIZ_QUESTION); $TBL_TRACK_EXERCICES = Database :: get_statistic_table(TABLE_STATISTIC_TRACK_E_EXERCICES); $TBL_TRACK_HOTPOTATOES = Database :: get_statistic_table(TABLE_STATISTIC_TRACK_E_HOTPOTATOES); $TBL_TRACK_ATTEMPT = Database :: get_statistic_table(TABLE_STATISTIC_TRACK_E_ATTEMPT); $TBL_TRACK_ATTEMPT_RECORDING= Database :: get_statistic_table(TABLE_STATISTIC_TRACK_E_ATTEMPT_RECORDING); $TBL_LP_ITEM_VIEW = Database :: get_course_table(TABLE_LP_ITEM_VIEW); $TBL_LP_ITEM = Database :: get_course_table(TABLE_LP_ITEM); $TBL_LP_VIEW = Database :: get_course_table(TABLE_LP_VIEW); // document path $documentPath = api_get_path(SYS_COURSE_PATH) . $_course['path'] . "/document"; // picture path $picturePath = $documentPath . '/images'; // audio path $audioPath = $documentPath . '/audio'; // hotpotatoes $uploadPath = DIR_HOTPOTATOES; //defined in main_api $exercicePath = api_get_self(); $exfile = explode('/', $exercicePath); $exfile = strtolower($exfile[sizeof($exfile) - 1]); $exercicePath = substr($exercicePath, 0, strpos($exercicePath, $exfile)); $exercicePath = $exercicePath . "exercice.php"; if ($show == 'result') { if (empty($_GET['exerciseId']) && empty($_GET['path']) ) { //header('Location: exercice.php?' . api_get_cidreq()); } } // Clear the exercise session if (isset ($_SESSION['objExercise'])) { api_session_unregister('objExercise'); } if (isset ($_SESSION['objQuestion'])) { api_session_unregister('objQuestion'); } if (isset ($_SESSION['objAnswer'])) { api_session_unregister('objAnswer'); } if (isset ($_SESSION['questionList'])) { api_session_unregister('questionList'); } if (isset ($_SESSION['exerciseResult'])) { api_session_unregister('exerciseResult'); } //General POST/GET/SESSION/COOKIES parameters recovery if (empty ($origin)) { $origin = Security::remove_XSS($_REQUEST['origin']); } if (empty ($choice)) { $choice = $_REQUEST['choice']; } if (empty ($hpchoice)) { $hpchoice = $_REQUEST['hpchoice']; } if (empty ($exerciseId)) { $exerciseId = intval($_REQUEST['exerciseId']); } if (empty ($file)) { $file = Database :: escape_string($_REQUEST['file']); } $learnpath_id = intval($_REQUEST['learnpath_id']); $learnpath_item_id = intval($_REQUEST['learnpath_item_id']); $page = intval($_REQUEST['page']); if ($page < 0) { $page = 1; } if ($origin == 'learnpath') { $show = 'result'; } //Deleting an attempt if ($_GET['delete'] == 'delete' && ($is_allowedToEdit || api_is_coach()) && !empty ($_GET['did']) && $_GET['did'] == strval(intval($_GET['did']))) { $sql = 'DELETE FROM ' . Database :: get_statistic_table(TABLE_STATISTIC_TRACK_E_EXERCICES) . ' WHERE exe_id = ' . $_GET['did']; //_GET[did] filtered by entry condition Database::query($sql); $filter=Security::remove_XSS($_GET['filter']); header('Location: exercice.php?cidReq=' . Security::remove_XSS($_GET['cidReq']) . '&show=result&filter=' . $filter . '&exerciseId='.$exerciseId.'&filter_by_user='.$_GET['filter_by_user']); exit; } //Send student email @todo move this code in a class, library if ($show == 'result' && $_REQUEST['comments'] == 'update' && ($is_allowedToEdit || $is_tutor) && $_GET['exeid']== strval(intval($_GET['exeid']))) { $id = intval($_GET['exeid']); //filtered by post-condition $track_exercise_info = get_exercise_track_exercise_info($id); if (empty($track_exercise_info)) { api_not_allowed(); } $test = $track_exercise_info['title']; $student_id = $track_exercise_info['exe_user_id']; $course_id = $track_exercise_info['exe_cours_id']; $session_id = $track_exercise_info['session_id']; $lp_id = $track_exercise_info['orig_lp_id']; $lp_item_id = $track_exercise_info['orig_lp_item_id']; $lp_item_view_id = $track_exercise_info['orig_lp_item_view_id']; // Teacher data $teacher_info = api_get_user_info(api_get_user_id()); $user_info = api_get_user_info($student_id); $student_email = $user_info['mail']; $from = $teacher_info['mail']; $from_name = api_get_person_name($teacher_info['firstname'], $teacher_info['lastname'], null, PERSON_NAME_EMAIL_ADDRESS); $url = api_get_path(WEB_CODE_PATH) . 'exercice/exercice.php?' . api_get_cidreq() . '&id_session='.$session_id.'&show=result&exerciseId='.$exerciseId; $my_post_info = array(); $post_content_id = array(); $comments_exist = false; foreach ($_POST as $key_index=>$key_value) { $my_post_info = explode('_',$key_index); $post_content_id[]=$my_post_info[1]; if ($my_post_info[0]=='comments') { $comments_exist=true; } } $loop_in_track=($comments_exist===true) ? (count($_POST)/2) : count($_POST); $array_content_id_exe=array(); if ($comments_exist===true) { $array_content_id_exe = array_slice($post_content_id,$loop_in_track); } else { $array_content_id_exe = $post_content_id; } for ($i=0;$i<$loop_in_track;$i++) { $my_marks = Database::escape_string($_POST['marks_'.$array_content_id_exe[$i]]); $contain_comments = Database::escape_string($_POST['comments_'.$array_content_id_exe[$i]]); if (isset($contain_comments)) { $my_comments = Database::escape_string($_POST['comments_'.$array_content_id_exe[$i]]); } else { $my_comments = ''; } $my_questionid=$array_content_id_exe[$i]; $sql = "SELECT question from $TBL_QUESTIONS WHERE id = '$my_questionid'"; $result =Database::query($sql); $ques_name = Database::result($result,0,"question"); $query = "UPDATE $TBL_TRACK_ATTEMPT SET marks = '$my_marks',teacher_comment = '$my_comments' WHERE question_id = ".$my_questionid." AND exe_id=".$id; Database::query($query); //Saving results in the track recording table $recording_changes = 'INSERT INTO '.$TBL_TRACK_ATTEMPT_RECORDING.' (exe_id, question_id, marks, insert_date, author, teacher_comment) VALUES ('."'$id','".$my_questionid."','$my_marks','".api_get_utc_datetime()."','".api_get_user_id()."'".',"'.$my_comments.'")'; Database::query($recording_changes); } $qry = 'SELECT DISTINCT question_id, marks FROM ' . $TBL_TRACK_ATTEMPT . ' WHERE exe_id = '.$id .' GROUP BY question_id'; $res = Database::query($qry); $tot = 0; while ($row = Database :: fetch_array($res, 'ASSOC')) { $tot += $row['marks']; } $totquery = "UPDATE $TBL_TRACK_EXERCICES SET exe_result = '".floatval($tot)."' WHERE exe_id = ".$id; Database::query($totquery); //@todo move this somewhere else $subject = get_lang('ExamSheetVCC'); $course_info = api_get_course_info(); $message = '
'.get_lang('DearStudentEmailIntroduction') . '
'.get_lang('AttemptVCC'); $message .= '
'.Security::remove_XSS($course_info['name']).''; $message .= '
'.Security::remove_XSS($test); //Only for exercises not in a LP if ($lp_id == 0) { $message .= '
'.get_lang('ClickLinkToViewComment') . ' #url#
';
}
$message .= '
'.get_lang('Regards') . '
'; $message .= $from_name; $message = str_replace("#test#", Security::remove_XSS($test), $message); $message = str_replace("#url#", $url, $message); @api_mail_html($student_email, $student_email, $subject, $message, $from_name, $from, array('charset'=>api_get_system_encoding())); //Updating LP score here if (in_array($origin, array ('tracking_course','user_course','correct_exercise_in_lp'))) { $sql_update_score = "UPDATE $TBL_LP_ITEM_VIEW SET score = '" . floatval($tot) . "' WHERE id = " .$lp_item_view_id; Database::query($sql_update_score); if ($origin == 'tracking_course') { //Redirect to the course detail in lp header('location: exercice.php?course=' . Security :: remove_XSS($_GET['course'])); exit; } else { //Redirect to the reporting header('location: ../mySpace/myStudents.php?origin=' . $origin . '&student=' . $student_id . '&details=true&course=' . $course_id.'&session_id='.$session_id); exit; } } } if (!empty($_GET['gradebook']) && $_GET['gradebook']=='view' ) { $_SESSION['gradebook']=Security::remove_XSS($_GET['gradebook']); $gradebook= $_SESSION['gradebook']; } elseif (empty($_GET['gradebook'])) { unset($_SESSION['gradebook']); $gradebook= ''; } if (!empty($gradebook) && $gradebook=='view') { $interbreadcrumb[] = array ('url' => '../gradebook/' . $_SESSION['gradebook_dest'],'name' => get_lang('ToolGradebook')); } if ($show != 'result') { $nameTools = get_lang('Exercices'); } else { if ($is_allowedToEdit || $is_tutor) { $nameTools = get_lang('StudentScore'); $interbreadcrumb[] = array("url" => "exercice.php?gradebook=$gradebook","name" => get_lang('Exercices')); $objExerciseTmp = new Exercise(); if ($objExerciseTmp->read($exerciseId)) { $interbreadcrumb[] = array("url" => "admin.php?exerciseId=".$exerciseId, "name" => $objExerciseTmp->name); } } else { $nameTools = get_lang('YourScore'); $interbreadcrumb[] = array ("url" => "exercice.php?gradebook=$gradebook","name" => get_lang('Exercices')); } } // need functions of statsutils lib to display previous exercices scores require_once api_get_path(LIBRARY_PATH) . 'statsUtils.lib.inc.php'; if ($is_allowedToEdit && !empty ($choice) && $choice == 'exportqti2') { require_once 'export/qti2/qti2_export.php'; $export = export_exercise($exerciseId, true); require_once api_get_path(LIBRARY_PATH) . 'pclzip/pclzip.lib.php'; $archive_path = api_get_path(SYS_ARCHIVE_PATH); $temp_dir_short = api_get_unique_id(); $temp_zip_dir = $archive_path . "/" . $temp_dir_short; if (!is_dir($temp_zip_dir)) mkdir($temp_zip_dir, api_get_permissions_for_new_directories()); $temp_zip_file = $temp_zip_dir . "/" . api_get_unique_id() . ".zip"; $temp_xml_file = $temp_zip_dir . "/qti2export_" . $exerciseId . '.xml'; file_put_contents($temp_xml_file, $export); $zip_folder = new PclZip($temp_zip_file); $zip_folder->add($temp_xml_file, PCLZIP_OPT_REMOVE_ALL_PATH); $name = 'qti2_export_' . $exerciseId . '.zip'; //DocumentManager::string_send_for_download($export,true,'qti2export_'.$exerciseId.'.xml'); DocumentManager :: file_send_for_download($temp_zip_file, true, $name); unlink($temp_zip_file); unlink($temp_xml_file); rmdir($temp_zip_dir); exit; //otherwise following clicks may become buggy } if (!empty ($_GET['extra_data'])) { switch ($_GET['extra_data']) { case 'on' : $_SESSION['export_user_fields'] = true; break; default : $_SESSION['export_user_fields'] = false; break; } } if (!empty($_GET['export_report']) && $_GET['export_report'] == '1') { if (api_is_platform_admin() || api_is_course_admin() || api_is_course_tutor() || api_is_course_coach()) { $user_id = null; if (empty($_SESSION['export_user_fields'])) $_SESSION['export_user_fields'] = false; if (!$is_allowedToEdit and !$is_tutor) { $user_id = api_get_user_id(); } require_once 'exercise_result.class.php'; switch ($_GET['export_format']) { case 'xls' : $export = new ExerciseResult(); $export->exportCompleteReportXLS($documentPath, $user_id, $_SESSION['export_user_fields'], $_GET['export_filter'], $_GET['exerciseId'], $_GET['hotpotato_name']); exit; break; case 'csv' : default : $export = new ExerciseResult(); $export->exportCompleteReportCSV($documentPath, $user_id, $_SESSION['export_user_fields'], $_GET['export_filter'], $_GET['exerciseId'], $_GET['hotpotato_name']); exit; break; } } else { api_not_allowed(true); } } if ($origin != 'learnpath') { //so we are not in learnpath tool Display :: display_header($nameTools, get_lang('Exercise')); if (isset ($_GET['message'])) { if (in_array($_GET['message'], array ('ExerciseEdited'))) { Display :: display_confirmation_message(get_lang($_GET['message'])); } } } else { echo ''; } event_access_tool(TOOL_QUIZ); // Tool introduction Display :: display_introduction_section(TOOL_QUIZ); HotPotGCt($documentPath, 1, api_get_user_id() ); // only for administrator if ($is_allowedToEdit) { if (!empty($choice)) { // construction of Exercise $objExerciseTmp = new Exercise(); $check = Security::check_token('get'); if ($objExerciseTmp->read($exerciseId)) { if ($check) { switch ($choice) { case 'delete' : // deletes an exercise $objExerciseTmp->delete(); require_once api_get_path(SYS_CODE_PATH).'gradebook/lib/gradebook_functions.inc.php'; $link_id = is_resource_in_course_gradebook(api_get_course_id(), 1 , $exerciseId, api_get_session_id()); if ($link_id !== false) { remove_resource_from_course_gradebook($link_id); } Display :: display_confirmation_message(get_lang('ExerciseDeleted')); break; case 'enable' : // enables an exercise $objExerciseTmp->enable(); $objExerciseTmp->save(); // "WHAT'S NEW" notification: update table item_property (previously last_tooledit) Display :: display_confirmation_message(get_lang('VisibilityChanged')); break; case 'disable' : // disables an exercise $objExerciseTmp->disable(); $objExerciseTmp->save(); Display :: display_confirmation_message(get_lang('VisibilityChanged')); break; case 'disable_results' : //disable the results for the learners $objExerciseTmp->disable_results(); $objExerciseTmp->save(); Display :: display_confirmation_message(get_lang('ResultsDisabled')); break; case 'enable_results' : //disable the results for the learners $objExerciseTmp->enable_results(); $objExerciseTmp->save(); Display :: display_confirmation_message(get_lang('ResultsEnabled')); break; case 'clean_results' : //clean student results $quantity_results_deleted= $objExerciseTmp->clean_results(); Display :: display_confirmation_message(sprintf(get_lang('XResultsCleaned'),$quantity_results_deleted)); break; case 'copy_exercise' : //copy an exercise $objExerciseTmp->copy_exercise(); Display :: display_confirmation_message(get_lang('ExerciseCopied')); break; } } } // destruction of Exercise unset ($objExerciseTmp); Security::clear_token(); } if (!empty($hpchoice)) { switch($hpchoice) { case 'delete' : // deletes an exercise $imgparams = array (); $imgcount = 0; GetImgParams($file, $documentPath, $imgparams, $imgcount); $fld = GetFolderName($file); for ($i = 0; $i < $imgcount; $i++) { my_delete($documentPath . $uploadPath . "/" . $fld . "/" . $imgparams[$i]); update_db_info("delete", $uploadPath . "/" . $fld . "/" . $imgparams[$i]); } if (my_delete($documentPath . $file)) { update_db_info("delete", $file); } my_delete($documentPath . $uploadPath . "/" . $fld . "/"); break; case 'enable' : // enables an exercise $newVisibilityStatus = "1"; //"visible" $query = "SELECT id FROM $TBL_DOCUMENT WHERE path='" . Database :: escape_string($file) . "'"; $res = Database::query($query); $row = Database :: fetch_array($res, 'ASSOC'); api_item_property_update($_course, TOOL_DOCUMENT, $row['id'], 'visible', $_user['user_id']); //$dialogBox = get_lang('ViMod'); break; case 'disable' : // disables an exercise $newVisibilityStatus = "0"; //"invisible" $query = "SELECT id FROM $TBL_DOCUMENT WHERE path='" . Database :: escape_string($file) . "'"; $res = Database::query($query); $row = Database :: fetch_array($res, 'ASSOC'); api_item_property_update($_course, TOOL_DOCUMENT, $row['id'], 'invisible', $_user['user_id']); break; default : break; } } } // Actions div bar if ($is_allowedToEdit) { echo '