2 /************************************************************************
3 * MXChange v0.2.1 Start: 04/23/2005 *
4 * =============== Last change: 05/18/2008 *
6 * -------------------------------------------------------------------- *
7 * File : sponsor_functions.php *
8 * -------------------------------------------------------------------- *
9 * Short description : Functions for the sponsor area *
10 * -------------------------------------------------------------------- *
11 * Kurzbeschreibung : Funktionen fuer den Sponsorenbereich *
12 * -------------------------------------------------------------------- *
15 * $Tag:: 0.2.1-FINAL $ *
17 * Needs to be in all Files and every File needs "svn propset *
18 * svn:keywords Date Revision" (autoprobset!) at least!!!!!! *
19 * -------------------------------------------------------------------- *
20 * Copyright (c) 2003 - 2008 by Roland Haeder *
21 * For more information visit: http://www.mxchange.org *
23 * This program is free software. You can redistribute it and/or modify *
24 * it under the terms of the GNU General Public License as published by *
25 * the Free Software Foundation; either version 2 of the License. *
27 * This program is distributed in the hope that it will be useful, *
28 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
29 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
30 * GNU General Public License for more details. *
32 * You should have received a copy of the GNU General Public License *
33 * along with this program; if not, write to the Free Software *
34 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, *
36 ************************************************************************/
38 // Some security stuff...
39 if (!defined('__SECURITY')) {
40 $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), '/inc') + 4) . '/security.php';
45 function SPONSOR_HANDLE_SPONSOR (&$POST, $NO_UPDATE=false, $messageArray=array(), $RET_STATUS=false) {
46 // Init a lot variables
55 'ok', 'edit', 'terms', 'pay_type'
64 // Check if sponsor already exists
65 foreach ($POST as $k => $v) {
66 if (!(array_search($k, $SKIPPED) > -1)) {
67 // Check only posted input entries not the submit button
72 if (!isEmailValid($v)) {
73 // Email address is not valid
76 // Do we want to add a new sponsor or update his data?
77 $result = SQL_QUERY_ESC("SELECT `id` FROM `{!_MYSQL_PREFIX!}_sponsor_data` WHERE email='%s' LIMIT 1",
78 array($POST['email']), __FUNCTION__, __LINE__);
80 // Is a sponsor alread in the db?
81 if (SQL_NUMROWS($result) == 1) {
83 if ((getWhat() == 'add_sponsor') || ($NO_UPDATE)) {
93 SQL_FREERESULT($result);
102 $k = 'password'; $v = md5($v);
106 if (!isUrlValid($v)) $SAVE = false;
110 // Test if there is are time selections
111 convertSelectionsToTimestamp($POST, $DATA, $k, $skip);
115 if ((!empty($k)) && ($skip == false)) {
117 $DATA['keys'][] = $k; $DATA['values'][] = $v;
123 if ($SAVE === true) {
124 // Default is no force even when a guest want to abuse this force switch
125 if ((empty($POST['force'])) || (!IS_ADMIN())) $POST['force'] = 0;
127 // SQL and message string is empty by default
128 $sql = ''; $message = '';
133 $sql = "UPDATE `{!_MYSQL_PREFIX!}_sponsor_data` SET ";
134 foreach ($DATA['keys'] as $k => $v) {
135 $sql .= $v."='%s', ";
138 // Remove last ", " from SQL string
139 $sql = substr($sql, 0, -2)." WHERE `id`='%s' LIMIT 1";
140 $DATA['values'][] = bigintval(REQUEST_GET('id'));
143 $message = SPONSOR_GET_MESSAGE(ADMIN_SPONSOR_UPDATED, "updated", $messageArray);
145 } elseif ((!$ALREADY) || (($POST['force'] == '1') && (IS_ADMIN()))) {
146 // Add new sponsor, first add more data
147 $DATA['keys'][] = "sponsor_created"; $DATA['values'][] = time();
148 $DATA['keys'][] = 'status';
149 if ((!$NO_UPDATE) && (IS_ADMIN()) && (getWhat() == "add_sponsor")) {
150 // Only allowed for admin
151 $DATA['values'][] = 'PENDING';
154 $DATA['values'][] = 'UNCONFIRMED';
156 // Generate hash code
157 $DATA['keys'][] = "hash";
158 $DATA['values'][] = md5(session_id().':'.$POST['email'].':'.detectRemoteAddr().':'.detectUserAgent().':'.time());
159 $DATA['keys'][] = "remote_addr";
160 $DATA['values'][] = detectRemoteAddr();
163 // Implode all data into strings
164 $KEYS = implode(", " , $DATA['keys']);
165 $valueS = str_repeat("%s', '", count($DATA['values']) - 1);
168 $sql = "INSERT INTO `{!_MYSQL_PREFIX!}_sponsor_data` (".$KEYS.") VALUES ('".$valueS."%s')";
171 $message = SPONSOR_GET_MESSAGE(getMessage('ADMIN_SPONSOR_ADDED'), "added", $messageArray);
173 } elseif ((!$NO_UPDATE) && (IS_ADMIN())) {
174 // Add all data as hidden data
176 foreach ($POST as $k => $v) {
177 // Do not add 'force' !
179 $OUT .= "<input type=\"hidden\" name=\"".$k."\" value=\"".stripslashes($v)."\" />\n";
182 define('__HIDDEN_DATA', $OUT);
183 define('__EMAIL' , $POST['email']);
185 // Ask for adding a sponsor with same email address
186 LOAD_TEMPLATE("admin_add_sponsor_already");
190 $message = sprintf(getMessage('SPONSOR_ALREADY_FOUND', $POST['email']));
196 $result = SQL_QUERY_ESC($sql, $DATA['values'], __FUNCTION__, __LINE__);
200 if ((!$NO_UPDATE) && (IS_ADMIN())) {
201 LOAD_TEMPLATE('admin_settings_saved', false, $message);
205 $message = SPONSOR_GET_MESSAGE(getMessage('SPONSOR_DATA_NOT_SAVED'), 'failed', $messageArray);
206 LOAD_TEMPLATE('admin_settings_saved', false, $message);
209 // Shall we return the status?
210 if ($RET_STATUS === true) return $ret;
213 function sponsorTranslateUserStatus ($status) {
214 // Construct constant name
215 $constantName = sprintf("ACCOUNT_%s", $status);
217 // Is the constant there?
218 if (defined($constantName)) {
220 $ret = constant($constantName);
223 DEBUG_LOG(__FUNCTION__, __LINE__, sprintf("Unknown status %s detected.", $status));
224 $ret = sprintf(getMessage('UNKNOWN_STATUS'), $status);
228 // Search for an email address in the database
229 function SPONSOR_FOUND_EMAIL_DB ($email) {
230 // Do we already have the provided email address in our DB?
231 $ret = (GET_TOTAL_DATA($email, "sponsor_data", 'id', 'email', true) == 1);
237 function SPONSOR_GET_MESSAGE ($message, $pos, $array) {
238 // Check if the requested message was found in array
239 if (isset($array[$pos])) {
240 // ... if yes then use it!
243 // ... else use default message
252 function IS_SPONSOR () {
255 if ((isSessionVariableSet('sponsorid')) && (isSessionVariableSet('sponsorpass'))) {
256 // Check cookies against database records...
257 $result = SQL_QUERY_ESC("SELECT
260 `{!_MYSQL_PREFIX!}_sponsor_data`
262 `id`='%s' AND `password`='%s' AND `status`='CONFIRMED'
265 bigintval(getSession('sponsorid')),
266 getSession('sponsorpass')
267 ), __FUNCTION__, __LINE__);
268 if (SQL_NUMROWS($result) == 1) {
274 SQL_FREERESULT($result);
282 function GENERATE_SPONSOR_MENU ($current) {
284 $WHERE = " AND active='Y'";
285 if (IS_ADMIN()) $WHERE = '';
287 // Load main menu entries
288 $result_main = SQL_QUERY("SELECT action AS main_action, title AS main_title FROM `{!_MYSQL_PREFIX!}_sponsor_menu`
289 WHERE (`what`='' OR `what` IS NULL) ".$WHERE."
290 ORDER BY `sort`", __FUNCTION__, __LINE__);
291 if (SQL_NUMROWS($result_main) > 0) {
292 // Load every menu and it's sub menus
293 while ($content = SQL_FETCHARRAY($result_main)) {
295 $result_sub = SQL_QUERY_ESC("SELECT what AS sub_what, title AS sub_title FROM `{!_MYSQL_PREFIX!}_sponsor_menu`
296 WHERE `action`='%s' AND `what` != '' AND `what` IS NOT NULL ".$WHERE."
298 array($content['main_action']), __FUNCTION__, __LINE__);
299 if (SQL_NUMROWS($result_sub) > 0) {
302 while ($content2 = SQL_FETCHARRAY($result_sub)) {
304 $content = merge_array($content, $content2);
306 // Check if current selected menu is matching the loaded one
307 if ($current == $content['sub_what']) $content['sub_title'] = "<strong>".$content['sub_title']."</strong>";
309 // Prepare data for the sub template
311 'what' => $content['sub_what'],
312 'title' => $content['sub_title']
316 $SUB .= LOAD_TEMPLATE("sponsor_what", true, $content);
319 // Prepare data for the main template
321 'title' => $content['main_title'],
325 // Load menu template
326 $OUT .= LOAD_TEMPLATE("sponsor_action", true, $content);
328 // No sub menus active
329 $OUT .= LOAD_TEMPLATE('admin_settings_saved', true, getMessage('SPONSOR_NO_SUB_MENUS_ACTIVE'));
333 SQL_FREERESULT($result_sub);
336 // No main menus active
337 $OUT .= LOAD_TEMPLATE('admin_settings_saved', true, getMessage('SPONSOR_NO_MAIN_MENUS_ACTIVE'));
341 SQL_FREERESULT($result_main);
348 function GENERATE_SPONSOR_CONTENT ($what) {
350 $INC = sprintf("inc/modules/sponsor/%s.php", $what);
351 if (isIncludeReadable($INC)) {
352 // Every sponsor action will output nothing directly. It will be written into $OUT!
353 loadIncludeOnce($INC);
356 $OUT .= LOAD_TEMPLATE('admin_settings_saved', true, sprintf(getMessage('SPONSOR_CONTENT_404'), $what));
364 function UPDATE_SPONSOR_LOGIN () {
370 // Update last online timestamp
371 SQL_QUERY_ESC("UPDATE `{!_MYSQL_PREFIX!}_sponsor_data`
372 SET last_online=UNIX_TIMESTAMP()
373 WHERE `id`='%s' AND password='%s' LIMIT 1",
374 array(bigintval(getSession('sponsorid')), getSession('sponsorpass')), __FUNCTION__, __LINE__);
376 // This update went fine?
377 $login = (SQL_AFFECTEDROWS() == 1);
384 function SPONSOR_SAVE_DATA ($POST, $content) {
387 // Unsecure data which we don't want
388 $UNSAFE = array('password', 'id', 'remote_addr', 'sponsor_created', 'last_online', 'status', 'ref_count',
389 'points_amount', 'points_used', 'refid', 'hash', 'last_pay', 'last_curr', 'pass_old',
390 'ok', 'pass1', 'pass2');
392 // Set default message ("not saved")
393 $message = getMessage('SPONSOR_ACCOUNT_DATA_NOT_SAVED');
395 // Check for submitted passwords
396 if ((!empty($POST['pass1'])) && (!empty($POST['pass2']))) {
397 // Are both passwords the same?
398 if ($POST['pass1'] == $POST['pass2']) {
399 // Okay, then set password and remove pass1 and pass2
400 $POST['password'] = md5($POST['pass1']);
404 // Remove all (maybe spoofed) unsafe data from array
405 foreach ($UNSAFE as $remove) {
406 unset($POST[$remove]);
409 // This array is for the submitted data which we will use with the SQL_QUERY_ESC() function to
413 // Prepare SQL string
414 $sql = "UPDATE `{!_MYSQL_PREFIX!}_sponsor_data` SET";
415 foreach ($POST as $key => $value) {
416 // Mmmmm, too less security here???
417 $sql .= " ".strip_tags($key)."='%s',";
419 // We will secure this later inside the SQL_QUERY_ESC() function
420 $DATA[] = strip_tags($value);
422 // Compile {SLASH} and so on for the email templates
423 $POST[$key] = COMPILE_CODE($value);
426 // Check if email has changed
427 if ((!empty($content['email'])) && (!empty($POST['email']))) {
428 if ($content['email'] != $POST['email']) {
429 // Change email address
432 // Okay, has changed then add status with UNCONFIRMED and new hash code
433 $sql .= " `status`='EMAIL', hash='%s',";
435 // Generate hash code
436 $HASH = md5(session_id().':'.$POST['email'].':'.detectRemoteAddr().':'.detectUserAgent().':'.time());
441 // Remove last commata
442 $sql = substr($sql, 0, -1);
445 $sql .= " WHERE `id`='%s' AND password='%s' LIMIT 1";
446 $DATA[] = bigintval(getSession('sponsorid'));
447 $DATA[] = getSession('sponsorpass');
449 // Saving data was completed... ufff...
452 case 'account': // Change account data
453 if ($EMAIL === true) {
454 $message = getMessage('SPONSOR_ACCOUNT_EMAIL_CHANGED');
455 $templ = 'admin_sponsor_change_email';
456 $subj = getMessage('ADMIN_SPONSOR_ACC_EMAIL_SUBJ');
458 $message = getMessage('SPONSOR_ACCOUNT_DATA_SAVED');
459 $templ = 'admin_sponsor_change_data';
460 $subj = getMessage('ADMIN_SPONSOR_ACC_DATA_SUBJ');
464 case 'settings': // Change settings
465 // Translate some data
466 $content['receive'] = translateYesNo($content['receive_warnings']);
467 $content['interval'] = createFancyTime($content['warning_interval']);
469 // Set message template and subject for admin
470 $message = getMessage('SPONSOR_SETTINGS_SAVED');
471 $templ = 'admin_sponsor_settings';
472 $subj = getMessage('ADMIN_SPONSOR_SETTINGS_SUBJ');
475 default: // Unknown sponsor what value!
476 DEBUG_LOG(__FUNCTION__, __LINE__, sprintf("Unknown sponsor module (what) %s detected.", getWhat()));
477 $message = sprintf(getMessage('SPONSOR_UNKNOWN_WHAT'), getWhat());
478 $templ = ''; $subj = '';
482 if (SQL_AFFECTEDROWS() == 1) {
483 if (!empty($templ) && !empty($subj)) {
484 // Run SQL command and check for success
485 $result = SQL_QUERY_ESC($sql, $DATA, __FUNCTION__, __LINE__);
487 // Add all data to content
492 if (isset($content['gender'])) $content['gender'] = translateGender($content['gender']);
493 if (isset($DATA['gender'])) $DATA['gender'] = translateGender($DATA['gender']);
494 if (isset($content['receive_warnings'])) $DATA['receive'] = translateYesNo($POST['receive_warnings']);
495 if (isset($content['warning_interval'])) $DATA['interval'] = createFancyTime($POST['warning_interval']);
497 // Send email to admins
498 sendAdminNotification($subj, $templ, $content);
500 // Shall we send mail to the sponsor's new email address?
501 if ($content['receive_warnings'] == 'Y') {
502 // Okay send email with confirmation link to new address and with no confirmation link
503 // to the old address
505 // First to old address
508 case 'account': // Change account data
509 $email_msg = LOAD_EMAIL_TEMPLATE('sponsor_change_data', $content);
510 sendEmail($content['email'], getMessage('SPONSOR_ACC_DATA_SUBJ'), $email_msg);
512 if ($EMAIL === true) {
513 // Add hash code to content array
514 $content['hash'] = $HASH;
516 // Second mail goes to the new address
517 $email_msg = LOAD_EMAIL_TEMPLATE('sponsor_change_email', $content);
518 sendEmail($content['email'], getMessage('SPONSOR_ACC_EMAIL_SUBJ'), $email_msg);
522 case 'settings': // Change settings
524 $email_msg = LOAD_EMAIL_TEMPLATE('sponsor_settings', $content);
525 sendEmail($content['email'], getMessage('SPONSOR_SETTINGS_SUBJ'), $email_msg);
532 // Return final message