]> git.mxchange.org Git - quix0rs-gnu-social.git/blobdiff - actions/emailsettings.php
notice_inbox.id -> notice_inbox.notice_id
[quix0rs-gnu-social.git] / actions / emailsettings.php
index d8a7bb6c3372e473e4362dbfd394cf50fd05a355..6e189a909d4a4c585cce158fa74a796a007a0b1f 100644 (file)
@@ -34,6 +34,7 @@ class EmailsettingsAction extends SettingsAction {
                                                                                   'id' => 'emailsettings',
                                                                                   'action' =>
                                                                                   common_local_url('emailsettings')));
+               common_hidden('token', common_session_token());
 
                common_element('h2', NULL, _('Address'));
 
@@ -83,14 +84,23 @@ class EmailsettingsAction extends SettingsAction {
                }
                
                common_element('h2', NULL, _('Preferences'));
-               
+
                common_checkbox('emailnotifysub',
-                                               _('Send me notices of new subscriptions through email.'),
-                                               $user->emailnotifysub);
+                               _('Send me notices of new subscriptions through email.'),
+                               $user->emailnotifysub);
+               common_checkbox('emailnotifyfav',
+                               _('Send me email when someone adds my notice as a favorite.'),
+                               $user->emailnotifyfav);
+               common_checkbox('emailnotifymsg',
+                               _('Send me email when someone sends me a private message.'),
+                               $user->emailnotifymsg);
                common_checkbox('emailpost',
                                                _('I want to post notices by email.'),
                                                $user->emailpost);
-                       
+               common_checkbox('emailmicroid',
+                               _('Publish a MicroID for my email address.'),
+                               $user->emailmicroid);
+
                common_submit('save', _('Save'));
                
                common_element_end('form');
@@ -111,6 +121,13 @@ class EmailsettingsAction extends SettingsAction {
 
        function handle_post() {
 
+               # CSRF protection
+               $token = $this->trimmed('token');
+               if (!$token || $token != common_session_token()) {
+                       $this->show_form(_('There was a problem with your session token. Try again, please.'));
+                       return;
+               }
+
                if ($this->arg('save')) {
                        $this->save_preferences();
                } else if ($this->arg('add')) {
@@ -131,6 +148,10 @@ class EmailsettingsAction extends SettingsAction {
        function save_preferences() {
 
                $emailnotifysub = $this->boolean('emailnotifysub');
+               $emailnotifyfav = $this->boolean('emailnotifyfav');
+               $emailnotifymsg = $this->boolean('emailnotifymsg');
+               $emailmicroid = $this->boolean('emailmicroid');
+               $emailpost = $this->boolean('emailpost');
 
                $user = common_current_user();
 
@@ -141,6 +162,10 @@ class EmailsettingsAction extends SettingsAction {
                $original = clone($user);
 
                $user->emailnotifysub = $emailnotifysub;
+               $user->emailnotifyfav = $emailnotifyfav;
+               $user->emailnotifymsg = $emailnotifymsg;
+               $user->emailmicroid = $emailmicroid;
+               $user->emailpost = $emailpost;
 
                $result = $user->update($original);
 
@@ -267,8 +292,8 @@ class EmailsettingsAction extends SettingsAction {
                
                $orig = clone($user);
                $user->incomingemail = NULL;
-               
-               if (!$user->update($orig)) {
+
+               if (!$user->updateKeys($orig)) {
                        common_log_db_error($user, 'UPDATE', __FILE__);
                        $this->server_error(_("Couldn't update user record."));
                }
@@ -282,7 +307,7 @@ class EmailsettingsAction extends SettingsAction {
                $orig = clone($user);
                $user->incomingemail = mail_new_incoming_address();
                
-               if (!$user->update($orig)) {
+               if (!$user->updateKeys($orig)) {
                        common_log_db_error($user, 'UPDATE', __FILE__);
                        $this->server_error(_("Couldn't update user record."));
                }