* svn:keywords Date Revision" (autoprobset!) at least!!!!!! *
* -------------------------------------------------------------------- *
* Copyright (c) 2003 - 2009 by Roland Haeder *
+ * Copyright (c) 2009, 2010 by Mailer Developer Team *
* For more information visit: http://www.mxchange.org *
* *
* This program is free software; you can redistribute it and/or modify *
// Some security stuff...
if (!defined('__SECURITY')) {
die();
-}
+} // END - if
// Add links for selecting some users
function alpha ($sortby, $colspan, $return=false) {
- if (!isGetRequestElementSet('offset')) setRequestGetElement('offset', 0);
- $add = "&page=".getRequestElement('page')."&offset=".getRequestElement('offset');
- if (isGetRequestElementSet('mode')) $add .= "&mode=".getRequestElement('mode');
+ if (!isGetRequestParameterSet('offset')) setGetRequestParameter('offset', 0);
+ $add = '&page='.getRequestParameter('page').'&offset='.getRequestParameter('offset');
+ if (isGetRequestParameterSet('mode')) $add .= '&mode='.getRequestParameter('mode');
/* Creates the list of letters and makes them a link. */
$alphabet = explode(',', getMessage('_ALL2') . ',A,B,C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z,' . getMessage('_OTHERS'));
$num = count($alphabet) - 1;
$OUT = '';
while (list($counter, $ltr) = each($alphabet)) {
- if (getRequestElement('letter') == $ltr) {
+ if (getRequestParameter('letter') == $ltr) {
// Current letter is letter from URL
- $OUT .= "<strong>".$ltr."</strong>";
+ $OUT .= '<strong>' . $ltr . '</strong>';
} else {
// Output link to letter
- $OUT .= "<a href=\"{?URL?}/modules.php?module=admin&what=".getWhat();
- if (isGetRequestElementSet('mode')) $OUT .= "&mode=".getRequestElement('mode');
- $OUT .= "&letter=".$ltr."&sortby=".$sortby.$add."\">".$ltr."</a>";
+ $OUT .= '<a href="{%url=modules.php?module=admin&what=' . getWhat();
+ if (isGetRequestParameterSet('mode')) $OUT .= '&mode=' . getRequestParameter('mode');
+ $OUT .= '&letter=' . $ltr . '&sortby=' . $sortby . $add . '%}">' . $ltr . '</a>';
}
if ((($counter / getConfig('user_alpha')) == round($counter / getConfig('user_alpha'))) && ($counter > 0)) {
- $OUT .= " ]<br />[ ";
+ $OUT .= ' ]<br />[ ';
} elseif ( $counter != $num ) {
- $OUT .= " | ";
+ $OUT .= ' | ';
}
} // END - while
// Add links for sorting
function addSortLinks ($letter, $sortby, $colspan, $return=false) {
$OUT = '';
- if (!isGetRequestElementSet('offset')) setRequestGetElement('offset', 0);
- if (!isGetRequestElementSet('page')) setRequestGetElement('page' , 0);
+ if (!isGetRequestParameterSet('offset')) setGetRequestParameter('offset', 0);
+ if (!isGetRequestParameterSet('page')) setGetRequestParameter('page' , 0);
// Add page and offset
- $add = '&page=' . getRequestElement('page') . '&offset=' . getRequestElement('offset');
+ $add = '&page=' . getRequestParameter('page') . '&offset=' . getRequestParameter('offset');
// Add status or mode
- if (isGetRequestElementSet('status')) $add .= '&mode=' . getRequestElement('status');
- elseif (isGetRequestElementSet('mode')) $add .= '&mode=' . getRequestElement('mode');
+ if (isGetRequestParameterSet('status')) $add .= '&mode=' . getRequestParameter('status');
+ elseif (isGetRequestParameterSet('mode')) $add .= '&mode=' . getRequestParameter('mode');
// Makes order by links..
if ($letter == 'front') $letter = getMessage('_ALL2');
// Prepare array with all possible sorters
$list = array(
'userid' => getMessage('_UID'),
- 'family' => getMessage('FAMILY_NAME'),
- 'email' => getMessage('EMAIL_ADDRESS'),
+ 'family' => getMessage('FAMILY'),
+ 'email' => getMessage('EMAIL'),
'REMOTE_ADDR' => getMessage('REMOTE_IP')
);
foreach ($list as $sort => $title) {
if ($sortby == $sort) {
- $OUT .= "<strong>" . $title . "</strong> | ";
+ $OUT .= '<strong>' . $title . '</strong> | ';
} else {
- $OUT .= "<a href=\"{?URL?}/modules.php?module=admin&what=list_user&letter=" . $letter . "&sortby=" . $sort.$add . "\">" . $title . "</a> | ";
+ $OUT .= '<a href="{%url=modules.php?module=admin&what=list_user&letter=' . $letter . '&sortby=' . $sort.$add . '%}">' . $title . '</a> | ';
}
} // END - foreach
}
// Add page navigation
-function addPageNavigation ($PAGES, $offset, $show_form, $colspan,$return=false) {
+function addPageNavigation ($pages, $offset, $showForm, $colspan, $return=false) {
// @TODO These two constants are no longer used, maybe we reactivate this code?
- //if ($show_form === true) {
+ //if ($showForm === true) {
// // Load form for changing number of lines
// define('__FORM_HEADER', loadTemplate('admin_list_user_sort_form', true));
// define('__FORM_FOOTER', '<tr><td colspan="'.$colspan.'" class="seperator bottom"> </td></tr>');
//}
$OUT = '';
- for ($page = 1; $page <= $PAGES; $page++) {
- if (($page == getRequestElement('page')) || ((!isGetRequestElementSet('page')) && ($page == 1))) {
+ for ($page = 1; $page <= $pages; $page++) {
+ if (($page == getRequestParameter('page')) || ((!isGetRequestParameterSet('page')) && ($page == 1))) {
$OUT .= '<strong>-';
} else {
- if (!isGetRequestElementSet('letter')) setRequestGetElement('letter', getMessage('_ALL2'));
- if (!isGetRequestElementSet('sortby')) setRequestGetElement('sortby', 'userid');
+ if (!isGetRequestParameterSet('letter')) setGetRequestParameter('letter', getMessage('_ALL2'));
+ if (!isGetRequestParameterSet('sortby')) setGetRequestParameter('sortby', 'userid');
// Base link
- $OUT .= '<a href="{?URL?}/modules.php?module=admin&what=' . getWhat();
+ $OUT .= '<a href="{%url=modules.php?module=admin&what=' . getWhat();
// Add status or mode
- if (isGetRequestElementSet('status')) $OUT .= '&mode=' . getRequestElement('status');
- elseif (isGetRequestElementSet('mode')) $OUT .= '&mode=' . getRequestElement('mode');
+ if (isGetRequestParameterSet('status')) $OUT .= '&mode=' . getRequestParameter('status');
+ elseif (isGetRequestParameterSet('mode')) $OUT .= '&mode=' . getRequestParameter('mode');
// Letter and so on
- $OUT .= '&letter=' . getRequestElement('letter') . '&sortby=' . getRequestElement('sortby') . '&page=' . $page . '&offset=' . $offset . '">';
+ $OUT .= '&letter=' . getRequestParameter('letter') . '&sortby=' . getRequestParameter('sortby') . '&page=' . $page . '&offset=' . $offset . '%}">';
}
$OUT .= $page;
- if (($page == getRequestElement('page')) || ((!isGetRequestElementSet('page')) && ($page == 1))) {
+ if (($page == getRequestParameter('page')) || ((!isGetRequestParameterSet('page')) && ($page == 1))) {
$OUT .= '-</strong>';
} else {
$OUT .= '</a>';
}
- if ($page < $PAGES) $OUT .= ' | ';
+ if ($page < $pages) $OUT .= ' | ';
} // END - for
// Remember the list
list($userid) = SQL_FETCHROW($result);
// Rewrite email address to contact link
- $email = '{?URL?}/modules.php?module=' . $mod . '&what=user_contct&userid=' . bigintval($userid);
+ $email = '{%url=modules.php?module=' . $mod . '&what=user_contct&userid=' . bigintval($userid) . '%}';
} // END - if
// Free memory
}
// Selects a random user id as the new referal id if they have at least X confirmed mails in this run
+// @TODO Double-check configuration entry here
function determineRandomReferalId () {
// Default is zero refid
$refid = '0';
$errorCode = '0';
$ext = '';
- // Add last_login if available
- $lastOnline = '';
- if (getExtensionVersion('sql_patches') >= '0.2.8') {
- $lastOnline = ', `last_login`';
- } // END - if
-
// Init array
$content = array(
'password' => '',
fetchUserData($userid);
}
- // Load entry
- $content = getUserDataArray();
- if (!empty($content['userid'])) $userid = bigintval($content['userid']);
+ // No error found?
+ if ($errorCode == '0') {
+ // Get user data array and set userid (e.g. important if we login with nickname)
+ $content = getUserDataArray();
+ if (!empty($content['userid'])) $userid = bigintval($content['userid']);
+ } // END - if
// Is there an entry?
- if (((isUserDataValid()) && (getUserData('status') == 'CONFIRMED') && (!empty($content['userid']))) || ($content['userid'] == $userid)) {
+ if ((isUserDataValid()) && (getUserData('status') == 'CONFIRMED') && (!empty($content['userid']))) {
// Check for old MD5 passwords
- if ((strlen($content['password']) == 32) && (md5($passwd) == $content['password'])) {
+ if ((strlen(getUserData('password')) == 32) && (md5($passwd) == getUserData('password'))) {
// Just set the hash to the password from DB... :)
- $content['hash'] = $content['password'];
+ $content['hash'] = getUserData('password');
} else {
// Hash password with improved way for comparsion
- $content['hash'] = generateHash($passwd, substr($content['password'], 0, -40));
+ $content['hash'] = generateHash($passwd, substr(getUserData('password'), 0, -40));
}
// Does the password match the hash?
- if ($content['hash'] == $content['password']) {
+ if ($content['hash'] == getUserData('password')) {
// New hashed password found so let's generate a new one
$content['hash'] = generateHash($passwd);
$GLOBALS['bonus_payed'] = false;
// Probe for last online timemark
- $probe = time() - $content['last_online'];
- if (!empty($content['last_login'])) $probe = time() - $content['last_login'];
+ $probe = time() - getUserData('last_online');
+ if (getUserData('last_login') > 0) $probe = time() - getUserData('last_login');
+
if ((isExtensionInstalledAndNewer('bonus', '0.2.2')) && ($probe >= getConfig('login_timeout'))) {
// Add login bonus to user's account
$add = ', `login_bonus`=`login_bonus`+{?login_bonus?}';
if ((getExtensionVersion('bonus') >= '0.3.5') && (getConfig('bonus_mode') != 'ADD')) handleBonusPoints('login_bonus');
} // END - if
- // Calculate new hash with the secret key and master salt together
- $content['hash'] = generatePassString($content['hash']);
-
- // Update global array
// @TODO Make this filter working: $URL = runFilterChain('do_login', array('content' => $content, 'addon' => $ADDON));
+
+ // Set member id
setMemberId($userid);
// Try to set session data (which shall normally always work!)
- if ((setSession('userid', $userid )) && (setSession('u_hash', $content['hash']))) {
+ //* DEBUG: */ logDebugMessage(__FUNCTION__, __LINE__, 'userid=' . $userid . ',hash=' . $content['hash'] . '(' . strlen($content['hash']) . ')');
+ if ((setSession('userid', $userid )) && (setSession('u_hash', encodeHashForCookie($content['hash'])))) {
// Update database records
SQL_QUERY_ESC("UPDATE `{?_MYSQL_PREFIX?}_user_data` SET `total_logins`=`total_logins`+1" . $add . " WHERE `userid`=%s LIMIT 1",
array($userid), __FUNCTION__, __LINE__);
// Is a success URL set?
if (empty($successUrl)) {
// Procedure to checking for login data
- if (($GLOBALS['bonus_payed']) && (isExtensionActive('bonus'))) {
+ if (($GLOBALS['bonus_payed'] === true) && (isExtensionActive('bonus'))) {
// Bonus added (just displaying!)
$URL = 'modules.php?module=chk_login&mode=bonus';
} else {
}
} else {
// Cookies not setable!
- $errorCode = getCode('NO_COOKIES');
+ $errorCode = getCode('COOKIES_DISABLED');
}
} elseif (getExtensionVersion('sql_patches') >= '0.6.1') {
// Update failture counter
// Wrong password!
$errorCode = getCode('WRONG_PASS');
}
- } elseif (((isExtensionActive('nickname')) && (isNicknameUsed($content['userid'])) && (!empty($content['userid']))) || ($content['userid'] == $userid)) {
- // Other account status?
- if (fetchUserData($userid)) {
- // Create an error code from given status
- $errorCode = generateErrorCodeFromUserStatus(getUserData('status'));
- } else {
- // id not found!
- $errorCode = getCode('WRONG_ID');
- }
- } elseif ($errorCode == '0') {
- // id not found!
+ } elseif (getUserData('status') != 'CONFIRMED') {
+ // Create an error code from given status
+ $errorCode = generateErrorCodeFromUserStatus(getUserData('status'));
+
+ // Set userid in session
+ setSession('current_userid', getUserData('userid'));
+ } elseif (!isUserDataValid()) {
+ // User id not found!
$errorCode = getCode('WRONG_ID');
+ } else {
+ // Unknown error
+ $errorCode = getCode('UNKNOWN_ERROR');
}
// Error code provided?
// Try to send a new password for the given user account
function doNewUserPassword ($email, $userid) {
- // Compile email when found in address (only secure chars!)
- if (!empty($email)) $email = str_replace('{DOT}', '.', $email);
-
// Init result and error
$errorCode = '';
$result = false;
// Probe userid/nickname
// @TODO We should try to rewrite this to fetchUserData() somehow
- if ((isExtensionActive('nickname')) && (isNicknameOrUserid($userid))) {
+ if (!empty($email)) {
+ // Email entered
+ $result = SQL_QUERY_ESC("SELECT `userid`, `status` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `email`='%s' OR `email`='%s' LIMIT 1",
+ array($email, str_replace('.', '{DOT}', $email)), __FUNCTION__, __LINE__);
+ } elseif ((isExtensionActive('nickname')) && (isNicknameOrUserid($userid))) {
// Nickname entered
$result = SQL_QUERY_ESC("SELECT `userid`, `status` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `nickname`='%s' OR `userid`='%s' OR `email`='%s' LIMIT 1",
array($userid, $userid, $email), __FUNCTION__, __LINE__);
// Direct userid entered
$result = SQL_QUERY_ESC("SELECT `userid`, `status` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `userid`=%s LIMIT 1",
array(bigintval($userid)), __FUNCTION__, __LINE__);
- } elseif (!empty($email)) {
- // Email entered
- $result = SQL_QUERY_ESC("SELECT `userid`, `status` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `email`='%s' LIMIT 1",
- array($email), __FUNCTION__, __LINE__);
} else {
// Userid not set!
logDebugMessage(__FUNCTION__, __LINE__, 'Userid is not set! BUG!');