// Some security stuff...
if (!defined('__SECURITY')) {
die();
-}
+} // END - if
// Add links for selecting some users
function alpha ($sortby, $colspan, $return=false) {
- if (!isGetRequestElementSet('offset')) setRequestGetElement('offset', 0);
- $add = "&page=".getRequestElement('page')."&offset=".getRequestElement('offset');
- if (isGetRequestElementSet('mode')) $add .= "&mode=".getRequestElement('mode');
+ if (!isGetRequestElementSet('offset')) setGetRequestElement('offset', 0);
+ $add = '&page='.getRequestElement('page').'&offset='.getRequestElement('offset');
+ if (isGetRequestElementSet('mode')) $add .= '&mode='.getRequestElement('mode');
/* Creates the list of letters and makes them a link. */
$alphabet = explode(',', getMessage('_ALL2') . ',A,B,C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z,' . getMessage('_OTHERS'));
while (list($counter, $ltr) = each($alphabet)) {
if (getRequestElement('letter') == $ltr) {
// Current letter is letter from URL
- $OUT .= "<strong>".$ltr."</strong>";
+ $OUT .= '<strong>' . $ltr . '</strong>';
} else {
// Output link to letter
- $OUT .= "<a href=\"{?URL?}/modules.php?module=admin&what=".getWhat();
- if (isGetRequestElementSet('mode')) $OUT .= "&mode=".getRequestElement('mode');
- $OUT .= "&letter=".$ltr."&sortby=".$sortby.$add."\">".$ltr."</a>";
+ $OUT .= '<a href="{%url=modules.php?module=admin&what=' . getWhat();
+ if (isGetRequestElementSet('mode')) $OUT .= '&mode=' . getRequestElement('mode');
+ $OUT .= '&letter=' . $ltr . '&sortby=' . $sortby . $add . '%}">' . $ltr . '</a>';
}
if ((($counter / getConfig('user_alpha')) == round($counter / getConfig('user_alpha'))) && ($counter > 0)) {
- $OUT .= " ]<br />[ ";
+ $OUT .= ' ]<br />[ ';
} elseif ( $counter != $num ) {
- $OUT .= " | ";
+ $OUT .= ' | ';
}
} // END - while
// Add links for sorting
function addSortLinks ($letter, $sortby, $colspan, $return=false) {
$OUT = '';
- if (!isGetRequestElementSet('offset')) setRequestGetElement('offset', 0);
- if (!isGetRequestElementSet('page')) setRequestGetElement('page' , 0);
+ if (!isGetRequestElementSet('offset')) setGetRequestElement('offset', 0);
+ if (!isGetRequestElementSet('page')) setGetRequestElement('page' , 0);
// Add page and offset
$add = '&page=' . getRequestElement('page') . '&offset=' . getRequestElement('offset');
// Prepare array with all possible sorters
$list = array(
'userid' => getMessage('_UID'),
- 'family' => getMessage('FAMILY_NAME'),
- 'email' => getMessage('EMAIL_ADDRESS'),
+ 'family' => getMessage('FAMILY'),
+ 'email' => getMessage('EMAIL'),
'REMOTE_ADDR' => getMessage('REMOTE_IP')
);
foreach ($list as $sort => $title) {
if ($sortby == $sort) {
- $OUT .= "<strong>" . $title . "</strong> | ";
+ $OUT .= '<strong>' . $title . '</strong> | ';
} else {
- $OUT .= "<a href=\"{?URL?}/modules.php?module=admin&what=list_user&letter=" . $letter . "&sortby=" . $sort.$add . "\">" . $title . "</a> | ";
+ $OUT .= '<a href="{%url=modules.php?module=admin&what=list_user&letter=' . $letter . '&sortby=' . $sort.$add . '%}">' . $title . '</a> | ';
}
} // END - foreach
if (($page == getRequestElement('page')) || ((!isGetRequestElementSet('page')) && ($page == 1))) {
$OUT .= '<strong>-';
} else {
- if (!isGetRequestElementSet('letter')) setRequestGetElement('letter', getMessage('_ALL2'));
- if (!isGetRequestElementSet('sortby')) setRequestGetElement('sortby', 'userid');
+ if (!isGetRequestElementSet('letter')) setGetRequestElement('letter', getMessage('_ALL2'));
+ if (!isGetRequestElementSet('sortby')) setGetRequestElement('sortby', 'userid');
// Base link
- $OUT .= '<a href="{?URL?}/modules.php?module=admin&what=' . getWhat();
+ $OUT .= '<a href="{%url=modules.php?module=admin&what=' . getWhat();
// Add status or mode
if (isGetRequestElementSet('status')) $OUT .= '&mode=' . getRequestElement('status');
elseif (isGetRequestElementSet('mode')) $OUT .= '&mode=' . getRequestElement('mode');
// Letter and so on
- $OUT .= '&letter=' . getRequestElement('letter') . '&sortby=' . getRequestElement('sortby') . '&page=' . $page . '&offset=' . $offset . '">';
+ $OUT .= '&letter=' . getRequestElement('letter') . '&sortby=' . getRequestElement('sortby') . '&page=' . $page . '&offset=' . $offset . '%}">';
}
$OUT .= $page;
list($userid) = SQL_FETCHROW($result);
// Rewrite email address to contact link
- $email = '{?URL?}/modules.php?module=' . $mod . '&what=user_contct&userid=' . bigintval($userid);
+ $email = '{%url=modules.php?module=' . $mod . '&what=user_contct&userid=' . bigintval($userid) . '%}';
} // END - if
// Free memory
}
// Selects a random user id as the new referal id if they have at least X confirmed mails in this run
+// @TODO Double-check configuration entry here
function determineRandomReferalId () {
// Default is zero refid
$refid = '0';
if (!empty($content['userid'])) $userid = bigintval($content['userid']);
// Is there an entry?
- if (((isUserDataValid()) && (getUserData('status') == 'CONFIRMED') && (!empty($content['userid']))) || ($content['userid'] == $userid)) {
+ if ((isUserDataValid()) && (getUserData('status') == 'CONFIRMED') && (!empty($content['userid']))) {
// Check for old MD5 passwords
- if ((strlen($content['password']) == 32) && (md5($passwd) == $content['password'])) {
+ if ((strlen(getUserData('password')) == 32) && (md5($passwd) == getUserData('password'))) {
// Just set the hash to the password from DB... :)
- $content['hash'] = $content['password'];
+ $content['hash'] = getUserData('password');
} else {
// Hash password with improved way for comparsion
- $content['hash'] = generateHash($passwd, substr($content['password'], 0, -40));
+ $content['hash'] = generateHash($passwd, substr(getUserData('password'), 0, -40));
}
// Does the password match the hash?
- if ($content['hash'] == $content['password']) {
+ if ($content['hash'] == getUserData('password')) {
// New hashed password found so let's generate a new one
$content['hash'] = generateHash($passwd);
$GLOBALS['bonus_payed'] = false;
// Probe for last online timemark
- $probe = time() - $content['last_online'];
- if (!empty($content['last_login'])) $probe = time() - $content['last_login'];
+ $probe = time() - getUserData('last_online');
+ if (getUserData('last_login') > 0) $probe = time() - getUserData('last_login');
+
if ((isExtensionInstalledAndNewer('bonus', '0.2.2')) && ($probe >= getConfig('login_timeout'))) {
// Add login bonus to user's account
$add = ', `login_bonus`=`login_bonus`+{?login_bonus?}';
}
} else {
// Cookies not setable!
- $errorCode = getCode('NO_COOKIES');
+ $errorCode = getCode('COOKIES_DISABLED');
}
} elseif (getExtensionVersion('sql_patches') >= '0.6.1') {
// Update failture counter
// Wrong password!
$errorCode = getCode('WRONG_PASS');
}
- } elseif (((isExtensionActive('nickname')) && (isNicknameUsed($content['userid'])) && (!empty($content['userid']))) || ($content['userid'] == $userid)) {
- // Other account status?
- if (fetchUserData($userid)) {
- // Create an error code from given status
- $errorCode = generateErrorCodeFromUserStatus(getUserData('status'));
- } else {
- // id not found!
- $errorCode = getCode('WRONG_ID');
- }
- } elseif ($errorCode == '0') {
- // id not found!
+ } elseif (getUserData('status') != 'CONFIRMED') {
+ // Create an error code from given status
+ $errorCode = generateErrorCodeFromUserStatus(getUserData('status'));
+
+ // Set userid in session
+ setSession('current_userid', getUserData('userid'));
+ } elseif (!isUserDataValid()) {
+ // User id not found!
$errorCode = getCode('WRONG_ID');
+ } else {
+ // Unknown error
+ $errorCode = getCode('UNKNOWN_ERROR');
}
// Error code provided?
// Try to send a new password for the given user account
function doNewUserPassword ($email, $userid) {
- // Compile email when found in address (only secure chars!)
- if (!empty($email)) $email = str_replace('{DOT}', '.', $email);
-
// Init result and error
$errorCode = '';
$result = false;
// @TODO We should try to rewrite this to fetchUserData() somehow
if (!empty($email)) {
// Email entered
- $result = SQL_QUERY_ESC("SELECT `userid`, `status` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `email`='%s' LIMIT 1",
- array($email), __FUNCTION__, __LINE__);
+ $result = SQL_QUERY_ESC("SELECT `userid`, `status` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `email`='%s' OR `email`='%s' LIMIT 1",
+ array($email, str_replace('.', '{DOT}', $email)), __FUNCTION__, __LINE__);
} elseif ((isExtensionActive('nickname')) && (isNicknameOrUserid($userid))) {
// Nickname entered
$result = SQL_QUERY_ESC("SELECT `userid`, `status` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `nickname`='%s' OR `userid`='%s' OR `email`='%s' LIMIT 1",