<?php
/************************************************************************
- * MXChange v0.2.1 Start: 10/19/2003 *
- * =============== Last change: 08/26/2004 *
+ * Mailer v0.2.1-FINAL Start: 10/19/2003 *
+ * =================== Last change: 08/26/2004 *
* *
* -------------------------------------------------------------------- *
* File : what-order.php *
return;
} // END - if
-$URL = ''; $id = 0;
+$URL = ''; $id = '0';
$whereStatement = " WHERE `visible`='Y'";
// Set undefined array elements
if (isAdmin()) $whereStatement = '';
// Count unconfirmed mails
-$links = countSumTotalData(getUserId(), 'user_links', 'id', 'userid', true);
+$links = countSumTotalData(getMemberId(), 'user_links', 'id', 'userid', true);
// Do we have ext-holiday installed?
-$HOLIDAY = 'serid';
+// @TODO Rewrite this to a filter
+$HOLIDAY = 'userid';
if ((isExtensionActive('holiday')) && (getExtensionVersion('holiday') >= '0.1.3')) {
// Fetch also holiday activation data
$HOLIDAY = 'holiday_active';
} // END - if
-$result_mmails = SQL_QUERY_ESC("SELECT `userid`, `receive_mails`, `mail_orders`, `".$HOLIDAY."`
-FROM `{?_MYSQL_PREFIX?}_user_data`
-WHERE `userid`=%s AND `max_mails` > 0 LIMIT 1",
- array(getUserId()), __FILE__, __LINE__);
+$result_mmails = SQL_QUERY_ESC("SELECT
+ `userid`, `receive_mails`, `mail_orders`, `".$HOLIDAY."`
+FROM
+ `{?_MYSQL_PREFIX?}_user_data`
+WHERE
+ `userid`=%s AND
+ `max_mails` > 0
+LIMIT 1",
+ array(getMemberId()), __FILE__, __LINE__);
$mmails = SQL_NUMROWS($result_mmails);
list($DMY, $MAXI, $ORDERS, $HOLIDAY) = SQL_FETCHROW($result_mmails);
if (getConfig('order_max_full') == 'MAX') $ALLOWED = $MAXI;
// Now check his points amount
-$total = countSumTotalData(getUserId(), 'user_points', 'points') - countSumTotalData(getUserId(), 'user_data', 'used_points');;
+$total = countSumTotalData(getMemberId(), 'user_points', 'points') - countSumTotalData(getMemberId(), 'user_data', 'used_points');;
if (($HOLIDAY == 'Y') && (getExtensionVersion('holiday') >= '0.1.3')) {
// Holiday is active!
loadTemplate('admin_settings_saved', false, getMessage('HOLIDAY_ORDER_NOT_POSSIBLE'));
-} elseif ((isPostRequestElementSet('frametester')) && ($ALLOWED > 0) && (postRequestElement('receiver') > 0)) {
+} elseif ((isPostRequestParameterSet('frametester')) && ($ALLOWED > 0) && (postRequestParameter('receiver') > 0)) {
// Continue with the frametester, we first need to store the data temporary in the pool
//
// First we would like to store the data and get it's pool position back...
`timestamp` > (UNIX_TIMESTAMP() - %s)
LIMIT 1",
array(
- getUserId(),
- postRequestElement('url'),
+ getMemberId(),
+ postRequestParameter('url'),
getConfig('url_tlock')
), __FILE__, __LINE__);
- $type = 'TEMP'; $id = 0;
+ $type = 'TEMP'; $id = '0';
if (SQL_NUMROWS($result) == 1) {
// Load id and mail type
list($id, $type) = SQL_FETCHROW($result);
// No entry found, so we need to check out the stats table as well... :)
// We have to add that suff here, now we continue WITHOUT checking and check the text and subject against some filters
$URL = '';
- if (getConfig('test_text') == 'Y') {
+ if (getConfig('allow_url_in_text') == 'Y') {
// Test submitted text against some filters (length, URLs in text etc.)
- if ((strpos(strtolower(postRequestElement('text')), "https://") > -1) || (strpos(strtolower(postRequestElement('text')), 'http://') > -1) || (strpos(strtolower(postRequestElement('text')), "www") > -1)) {
+ if ((strpos(strtolower(postRequestParameter('text')), 'https://') > -1) || (strpos(strtolower(postRequestParameter('text')), 'http://') > -1) || (strpos(strtolower(postRequestParameter('text')), "www") > -1)) {
// URL found!
$URL = 'modules.php?module=login&what=order&code=' . getCode('URL_FOUND');
} // END - if
// Remove new-line and carriage-return characters
- $TEST = str_replace("\n", '', str_replace("\r", '', postRequestElement('text')));
+ $TEST = str_replace("\n", '', str_replace("\r", '', postRequestParameter('text')));
// Text length within allowed length?
if (strlen($TEST) > getConfig('max_tlength')) {
} // END - if
// Shall I test the subject line against URLs?
- if (getConfig('test_subj') == 'Y') {
+ if (getConfig('allow_url_in_subject') == 'Y') {
// Check the subject line for issues
- setRequestPostElement('subject', str_replace("\\", '[nl]', substr(postRequestElement('subject'), 0, 200)));
- if ((strpos(strtolower(postRequestElement('subject')), 'http://') > -1) || (strpos(strtolower(postRequestElement('subject')), "www") > -1)) {
+ setPostRequestParameter('subject', str_replace("\\", '[nl]', substr(postRequestParameter('subject'), 0, 200)));
+ if ((strpos(strtolower(postRequestParameter('subject')), 'http://') > -1) || (strpos(strtolower(postRequestParameter('subject')), "www") > -1)) {
// URL in subject found
$URL = 'modules.php?module=login&what=order&code=' . getCode('SUBJ_URL');
} // END - if
if (getConfig('url_blacklist') == 'Y') {
// Ok, I do that for you know...
$result = SQL_QUERY_ESC("SELECT UNIX_TIMESTAMP(`timestamp`) AS tstamp FROM `{?_MYSQL_PREFIX?}_url_blacklist` WHERE `url`='%s' LIMIT 1",
- array(postRequestElement('url')), __FILE__, __LINE__);
+ array(postRequestParameter('url')), __FILE__, __LINE__);
if (SQL_NUMROWS($result) == 1) {
// Jupp, we got one listed
} // END - if
// Enougth receivers entered?
- if ((postRequestElement('receiver') < getConfig('order_min')) && (!isAdmin())) {
+ if ((postRequestParameter('receiver') < getConfig('order_min')) && (!isAdmin())) {
// Less than allowed receivers entered!
$URL = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS3');
} // END - if
// Validate URL
- if (!isUrlValid(postRequestElement('url'))) {
+ if (!isUrlValid(postRequestParameter('url'))) {
// URL is invalid!
$URL = 'modules.php?module=login&what=order&code=' . getCode('INVALID_URL');
} // END - if
// Probe for HTML extension
if (isExtensionActive('html_mail')) {
// HTML or regular text mail?
- if (postRequestElement('html') == 'Y') {
+ if (postRequestParameter('html') == 'Y') {
// Chek for valid HTML tags
- setRequestPostElement('text', checkHtmlTags(postRequestElement('text')));
+ setPostRequestParameter('text', checkHtmlTags(postRequestParameter('text')));
// Maybe invalid tags found?
- if (!isPostRequestElementSet('text')) $URL = 'modules.php?module=login&what=order&code=' . getCode('INVALID_TAGS')."&id=".$id;
+ if (!isPostRequestParameterSet('text')) $URL = 'modules.php?module=login&what=order&code=' . getCode('INVALID_TAGS')."&id=".$id;
} else {
// Remove any HTML code
- setRequestPostElement('text', str_replace('<', '{OPEN_HTML}', str_replace('>', '{CLOSE_HTML}', postRequestElement('text'))));
+ setPostRequestParameter('text', str_replace('<', '{OPEN_HTML}', str_replace('>', '{CLOSE_HTML}', postRequestParameter('text'))));
}
}
} elseif (!isAdmin()) {
if (empty($URL)) {
// Check if category and number of receivers is okay
$add = '';
- if ((getConfig('order_multi_page') == 'Y') && (isPostRequestElementSet('zip'))) {
+ if ((getConfig('order_multi_page') == 'Y') && (isPostRequestParameterSet('zip'))) {
// Choose recipients by ZIP code
- $add = " AND d.zip LIKE '".bigintval(postRequestElement('zip'))."{PER}'";
+ $add = " AND d.zip LIKE '".bigintval(postRequestParameter('zip'))."{PER}'";
} // END - if
// Check for userids
ORDER BY
d.%s %s",
array(
- bigintval(postRequestElement('cat')),
- getUserId(),
+ bigintval(postRequestParameter('cat')),
+ getMemberId(),
getConfig('order_select'),
getConfig('order_mode'),
), __FILE__, __LINE__);
// Do we enougth receivers left?
- if (SQL_NUMROWS($result) >= postRequestElement('receiver')) {
+ if (SQL_NUMROWS($result) >= postRequestParameter('receiver')) {
// Check for holiday extensions
$HOLIDAY = false;
if (getExtensionVersion('holiday') >= '0.1.3') {
} // END - if
// Load receivers from database
- $TEST = array(); $cnt = 0;
+ $TEST = array(); $cnt = '0';
while ($holidayContent = SQL_FETCHARRAY($result)) {
if ($HOLIDAY) {
// Check for his holiday status
`userid`=%s AND `holiday_start` < UNIX_TIMESTAMP() AND `holiday_end` > UNIX_TIMESTAMP()
LIMIT 1",
array($holidayContent['userid']), __FILE__, __LINE__);
- if (SQL_NUMROWS($result_holiday) == 1) $holidayContent['userid'] = 0; // Exclude user who are in holiday
+ if (SQL_NUMROWS($result_holiday) == 1) $holidayContent['userid'] = '0'; // Exclude user who are in holiday
// Free memory
SQL_FREERESULT($result_holiday);
SQL_FREERESULT($result);
// Implode array into string for the sending pool
- $RECEIVER = implode($TEST, ';');
+ $receiver = implode($TEST, ';');
// Count array for maximum sent
$content['target_send'] = count($TEST);
// Update receiver list
SQL_QUERY_ESC("UPDATE `{?_MYSQL_PREFIX?}_user_data` SET `receive_mails`=`receive_mails`-1 WHERE `userid` IN (%s) LIMIT %s",
- array(convertReceivers($RECEIVER), $content['target_send']), __FILE__, __LINE__);
+ array(convertReceivers($receiver), $content['target_send']), __FILE__, __LINE__);
// Is calculated max receivers larger than wanted receivers then reset it
- if ($content['target_send'] > postRequestElement('receiver')) $content['target_send'] = bigintval(postRequestElement('receiver'));
+ if ($content['target_send'] > postRequestParameter('receiver')) $content['target_send'] = bigintval(postRequestParameter('receiver'));
// Calculate used points
- $USED = $content['target_send'] * getPaymentPoints(bigintval(postRequestElement('type')));
+ $USED = $content['target_send'] * getPaymentPoints(bigintval(postRequestParameter('type')));
// Fix empty zip code
- if (!isPostRequestElementSet('zip')) setRequestPostElement('zip', 0);
+ if (!isPostRequestParameterSet('zip')) setPostRequestParameter('zip', 0);
// Check if he has enougth points for this order and selected more than 0 receivers
if (($USED > 0) && ($USED <= $total) && ($content['target_send'] > 0)) {
// Gettings points is okay, so we can add $USED later from
- if (($id == 0) || ($type != 'TEMP')) {
+ if (($id == '0') || ($type != 'TEMP')) {
// New order
- $id = 0;
+ $id = '0';
if (isExtensionActive('html_mail')) {
// HTML extension is active
SQL_QUERY_ESC("INSERT INTO `{?_MYSQL_PREFIX?}_pool` (`sender`, `subject`, `text`, `receivers`, `payment_id`, `data_type`, `timestamp`, `url`, `cat_id`, `target_send`, `zip`, `html_msg`)
VALUES ('%s','%s','%s','%s','%s','TEMP',UNIX_TIMESTAMP(),'%s','%s','%s','%s','%s')",
array(
- getUserId(),
- postRequestElement('subject'),
- postRequestElement('text'),
- $RECEIVER,
- bigintval(postRequestElement('type')),
- postRequestElement('url'),
- bigintval(postRequestElement('cat')),
+ getMemberId(),
+ postRequestParameter('subject'),
+ postRequestParameter('text'),
+ $receiver,
+ bigintval(postRequestParameter('type')),
+ postRequestParameter('url'),
+ bigintval(postRequestParameter('cat')),
$content['target_send'],
- bigintval(postRequestElement('zip')),
- postRequestElement('html')
+ bigintval(postRequestParameter('zip')),
+ postRequestParameter('html')
), __FILE__, __LINE__);
} else {
// No HTML extension is active
SQL_QUERY_ESC("INSERT INTO `{?_MYSQL_PREFIX?}_pool` (`sender`, `subject`, `text`, `receivers`, `payment_id`, `data_type`, `timestamp`, `url`, `cat_id`, `target_send`, `zip`)
VALUES ('%s','%s','%s','%s','%s','TEMP',UNIX_TIMESTAMP(),'%s','%s','%s','%s')",
array(
- getUserId(),
- postRequestElement('subject'),
- postRequestElement('text'),
- $RECEIVER,
- bigintval(postRequestElement('type')),
- postRequestElement('url'),
- bigintval(postRequestElement('cat')),
+ getMemberId(),
+ postRequestParameter('subject'),
+ postRequestParameter('text'),
+ $receiver,
+ bigintval(postRequestParameter('type')),
+ postRequestParameter('url'),
+ bigintval(postRequestParameter('cat')),
$content['target_send'],
- bigintval(postRequestElement('zip')),
+ bigintval(postRequestParameter('zip')),
), __FILE__, __LINE__);
}
} else {
`id`=%s
LIMIT 1",
array(
- postRequestElement('subject'),
- postRequestElement('text'),
- $RECEIVER,
- bigintval(postRequestElement('type')),
- postRequestElement('url'),
- bigintval(postRequestElement('cat')),
+ postRequestParameter('subject'),
+ postRequestParameter('text'),
+ $receiver,
+ bigintval(postRequestParameter('type')),
+ postRequestParameter('url'),
+ bigintval(postRequestParameter('cat')),
$content['target_send'],
- bigintval(postRequestElement('zip')),
- postRequestElement('html'),
+ bigintval(postRequestParameter('zip')),
+ postRequestParameter('html'),
bigintval($id)
), __FILE__, __LINE__);
} else {
`id`=%s
LIMIT 1",
array(
- postRequestElement('subject'),
- postRequestElement('text'),
- $RECEIVER,
- bigintval(postRequestElement('type')),
- postRequestElement('url'),
- bigintval(postRequestElement('cat')),
+ postRequestParameter('subject'),
+ postRequestParameter('text'),
+ $receiver,
+ bigintval(postRequestParameter('type')),
+ postRequestParameter('url'),
+ bigintval(postRequestParameter('cat')),
$content['target_send'],
- bigintval(postRequestElement('zip')),
+ bigintval(postRequestParameter('zip')),
bigintval($id)
), __FILE__, __LINE__);
}
}
// Do we need to get the id number?
- if ($id == 0) {
+ if ($id == '0') {
// Order is placed as temporary. We need to get it's id for the frametester
$result = SQL_QUERY_ESC("SELECT `id` FROM `{?_MYSQL_PREFIX?}_pool` WHERE `sender`=%s AND `subject`='%s' AND `payment_id`=%s AND `data_type`='TEMP' AND `timestamp`=UNIX_TIMESTAMP() LIMIT 1",
array(
- getUserId(),
- postRequestElement('subject'),
- bigintval(postRequestElement('type'))
+ getMemberId(),
+ postRequestParameter('subject'),
+ bigintval(postRequestParameter('type'))
), __FILE__, __LINE__);
// Get pool id
// id is received so we can redirect the user, used points will be added when he send's out the mail
$URL = 'modules.php?module=frametester&order=' . $id;
- } elseif ($content['target_send'] == 0) {
+ } elseif ($content['target_send'] == '0') {
// Not enougth receivers found which can receive mails
$URL = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS2');
} else {
$URL = 'modules.php?module=login&what=order&code=' . getCode('NO_RECS_LEFT');
}
}
-} elseif (postRequestElement('receiver') == '0') {
+} elseif (postRequestParameter('receiver') == '0') {
// Not enougth receivers selected
$URL = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS1');
-} elseif (($ALLOWED == 0) && (getConfig('order_max_full') == 'ORDER')) {
+} elseif (($ALLOWED == '0') && (getConfig('order_max_full') == 'ORDER')) {
// No more mail orders allowed
loadTemplate('admin_settings_saved', false, getMessage('MEMBER_ORDER_ALLOWED_EXHAUSTED'));
} elseif (($links < getConfig('unconfirmed')) && ($mmails == 1)) {
// Enable HTML checking
// @TODO Rewrite this to a filter
$HTML = ''; $HOLIDAY = false; $HOL_STRING = '';
- if ((isExtensionActive('html_mail')) && (postRequestElement('html') == 'Y')) $HTML = " AND `html`='Y'";
+ if ((isExtensionActive('html_mail')) && (postRequestParameter('html') == 'Y')) $HTML = " AND `html`='Y'";
if (getExtensionVersion('holiday') >= '0.1.3') {
// Extension's version is fine
$HOLIDAY = true; $HOL_STRING = " AND `holiday_active`='N'";
// Select users in current category
$result_userids = SQL_QUERY_ESC("SELECT `userid` FROM `{?_MYSQL_PREFIX?}_user_cats` WHERE `cat_id`=%s AND `userid` != '%s' ORDER BY `userid` ASC",
- array(bigintval($categoriesContent['id']), getUserId()), __FILE__, __LINE__);
+ array(bigintval($categoriesContent['id']), getMemberId()), __FILE__, __LINE__);
- $userid_cnt = 0;
+ $userid_cnt = '0';
while (list($ucat) = SQL_FETCHROW($result_userids)) {
// Check for holiday system
$HOL_ACTIVE = false;
$result_ver = SQL_QUERY_ESC("SELECT `zip` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `userid`=%s".$HTML." AND `receive_mails` > 0 AND `status`='CONFIRMED' LIMIT 1",
array(bigintval($ucat)), __FILE__, __LINE__);
- if ((SQL_NUMROWS($result_ver) == 1) && (isPostRequestElementSet('zip')) && (getConfig('order_multi_page') == 'Y')) {
+ if ((SQL_NUMROWS($result_ver) == 1) && (isPostRequestParameterSet('zip')) && (getConfig('order_multi_page') == 'Y')) {
// Get zip code
list($zip) = SQL_FETCHROW($result_ver);
- if (substr($zip, 0, strlen(postRequestElement('zip'))) == postRequestElement('zip')) {
+ if (substr($zip, 0, strlen(postRequestParameter('zip'))) == postRequestParameter('zip')) {
// Ok, ZIP part is found
$userid_cnt++;
} // END - if
$types = array();
if (SQL_NUMROWS($result) > 0) {
// Check for message id in URL
- $message = getMessageFromErrorCode(getRequestElement('code'));
+ $message = getMessageFromErrorCode(getRequestParameter('code'));
if (!empty($message)) {
// We got system message so we drop it out to the user
default: // Unknown/invalid
logDebugMessage(__FILE__, __LINE__, sprintf("Unknown order_mas_full config detected.", getConfig('order_max_full')));
- $content['order_max_full'] = sprintf(getMessage('MEMBER_ORDER_ALLOWED_UNKNOWN'), getConfig('order_max_full'));
+ $content['order_max_full'] = getMessage('MEMBER_ORDER_ALLOWED_UNKNOWN');
break;
} // END - switch
`sender`=%s AND
`data_type`='TEMP'
LIMIT 1",
- array(getUserId()), __FILE__, __LINE__);
+ array(getMemberId()), __FILE__, __LINE__);
if (SQL_NUMROWS($result) == 1) {
// Old order found
// Free result
SQL_FREERESULT($result);
- if ((isPostRequestElementSet('data')) || ((getConfig('order_multi_page') != 'Y') && ((!isAdmin()) && (!isExtensionActive('html_mail'))))) {
+ if ((isPostRequestParameterSet('data')) || ((getConfig('order_multi_page') != 'Y') && ((!isAdmin()) && (!isExtensionActive('html_mail'))))) {
// Pre-output categories
$content['category_selection'] = '';
foreach ($categories['id'] as $key => $value) {
} // END - if
} // END - foreach
- if (isPostRequestElementSet('zip')) {
+ // No content is default
+ $content['zip_content'] = '';
+
+ if (isPostRequestParameterSet('zip')) {
// Output entered ZIP code
- $content['zip_content'] = loadTemplate('member_order-zip', true, postRequestElement('zip'));
- } else {
- $content['zip_content'] = "<tr><td colspan=\"5\" height=\"5\" class=\"seperator\"> </td></tr>";
- }
+ $content['zip_content'] = loadTemplate('member_order-zip2', true, postRequestParameter('zip'));
+ } // END - if
// HTML extension
- if ((isExtensionActive('html_mail')) && (postRequestElement('html') == 'Y')) {
+ if ((isExtensionActive('html_mail')) && (postRequestParameter('html') == 'Y')) {
// Extension is active so output valid HTML tags
$content['html_extension'] = loadTemplate('member_order-html_ext', true, addValidHtmlTags());
} else {
// Extension not active and/or class not uploaded
- $content['html_extension'] = "<tr><td colspan=\"5\"><input type=\"hidden\" name=\"html\" value=\"N\" /></td></tr>";
+ $content['html_extension'] = '<tr><td colspan="3"><input type="hidden" name="html" value="N" /></td></tr>';
}
// Output form for page 2
loadTemplate('member_order_page2', false, $content);
} else {
// Remember maybe entered ZIP code in constant
- $add = '';
if (isExtensionActive('html_mail')) {
// Add some content when html extension is active
- if ((getConfig('order_multi_page') == 'Y') || (isAdmin())) $add = "<tr><td colspan=\"2\" class=\"seperator bottom2\" height=\"5\"> </td></tr>\n";
$content['html_extension'] = loadTemplate('member_order-html_intro', true);
} else {
// No HTML extension installed
- $content['html_extension'] = "<tr><td colspan=\"2\"><input type=\"hidden\" name=\"html\" value=\"N\" /></td></tr>";
+ $content['html_extension'] = '<tr><td colspan="3"><input type="hidden" name="html" value="N" /></td></tr>';
}
// Default is no ZIP code
// Do we want ZIP code or not?
if ((getConfig('order_multi_page') == 'Y') || (isAdmin())) {
// Yes
- if (postRequestElement('zip') > 0) {
+ if (postRequestParameter('zip') > 0) {
$data = array(
- 'zip' => bigintval(postRequestElement('zip')),
- 'add' => $add
+ 'zip' => bigintval(postRequestParameter('zip'))
);
} else {
$data = array(
- 'zip' => '',
- 'add' => $add
+ 'zip' => ''
);
}
$content['zip_content'] = loadTemplate('member_order-zip1', true, $data);
}
} else {
// No mail types defined
- loadTemplate('admin_settings_saved', false, "<span class=\"member_failed\">{--MEMBER_NO_PAYMENTS--}</span>");
+ loadTemplate('admin_settings_saved', false, '<span class="member_failed">{--MEMBER_NO_PAYMENTS--}</span>');
}
} else {
// No points left
- loadTemplate('admin_settings_saved', false, "<span class=\"member_failed\">{--MEMBER_NO_POINTS--}</span>");
+ loadTemplate('admin_settings_saved', false, '<span class="member_failed">{--MEMBER_NO_POINTS--}</span>');
}
} else {
// No cateogries are defined yet
- loadTemplate('admin_settings_saved', false, "<span class=\"member_failed\">{--MEMBER_NO_CATS--}</span>");
+ loadTemplate('admin_settings_saved', false, '<span class="member_failed">{--MEMBER_NO_CATS--}</span>');
}
-} elseif ($mmails == 0) {
+} elseif ($mmails == '0') {
// Please set more than 0 mails per day
loadTemplate('admin_settings_saved', false, getMessage('MEMBER_HAS_ZERO_MMAILS'));
} else {
// Please confirm some mails first
- loadTemplate('admin_settings_saved', false, sprintf(getMessage('MEMBER_LINKS_LEFT'), $links, getConfig('unconfirmed')));
+ loadTemplate('admin_settings_saved', false, getMaskedMessage('MEMBER_LINKS_LEFT'), $links);
}
if (!empty($URL)) {