<?php
/************************************************************************
- * MXChange v0.2.1 Start: 09/30/2005 *
- * =============== Last change: 05/19/2008 *
+ * Mailer v0.2.1-FINAL Start: 09/30/2005 *
+ * =================== Last change: 05/19/2008 *
* *
* -------------------------------------------------------------------- *
* File : account.php *
* -------------------------------------------------------------------- *
* Kurzbeschreibung : Der Sponsor kann sein Account verwalten *
* -------------------------------------------------------------------- *
- * *
+ * $Revision:: $ *
+ * $Date:: $ *
+ * $Tag:: 0.2.1-FINAL $ *
+ * $Author:: $ *
+ * Needs to be in all Files and every File needs "svn propset *
+ * svn:keywords Date Revision" (autoprobset!) at least!!!!!! *
* -------------------------------------------------------------------- *
- * Copyleft (c) 2003, 2004, 2005 by Roland Haeder *
+ * Copyright (c) 2003 - 2009 by Roland Haeder *
+ * Copyright (c) 2009, 2010 by Mailer Developer Team *
* For more information visit: http://www.mxchange.org *
* *
- * This program is free software. You can redistribute it and/or modify *
+ * This program is free software; you can redistribute it and/or modify *
* it under the terms of the GNU General Public License as published by *
- * the Free Software Foundation; either version 2 of the License. *
+ * the Free Software Foundation; either version 2 of the License, or *
+ * (at your option) any later version. *
* *
* This program is distributed in the hope that it will be useful, *
* but WITHOUT ANY WARRANTY; without even the implied warranty of *
************************************************************************/
// Some security stuff...
-if (ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) {
- $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4)."/security.php";
- require($INC);
-} elseif ((!EXT_IS_ACTIVE("sponsor")) && (!IS_ADMIN())) {
- $FATAL[] = EXTENSION_PROBLEM_EXT_INACTIVE;
+if (!defined('__SECURITY')) {
+ die();
+} elseif (!isExtensionActive('sponsor')) {
+ loadTemplate('admin_settings_saved', false, generateExtensionInactiveNotInstalledMessage('sponsor'));
return;
-} elseif (!IS_SPONSOR()) {
+} elseif (!isSponsor()) {
// No sponsor!
- $FATAL[] = SPONSOR_ONLY_AREA_ENTERED;
+ addFatalMessage(__FILE__, __LINE__, getMessage('SPONSOR_ONLY_AREA_ENTERED'));
return;
}
// Data for the formular
-$result = SQL_QUERY_ESC("SELECT company, position, tax_ident,
-salut, surname, family, street_nr1, street_nr2, zip, city, country,
-phone, fax, cell, email, url,
-status, receive_warnings
-FROM "._MYSQL_PREFIX."_sponsor_data
-WHERE id='%s' AND password='%s' LIMIT 1",
- array(bigintval($_COOKIE['sponsorid']), $_COOKIE['sponsorpass']), __FILE__, __LINE__);
+$result = SQL_QUERY_ESC("SELECT `company`, `position`, `tax_ident`,
+`gender`, `surname`, `family`, `street_nr1`, `street_nr2`, `zip`, `city`, `country`,
+`phone`, `fax`, `cell`, `email`, `url`,
+`status`, `receive_warnings`
+FROM `{?_MYSQL_PREFIX?}_sponsor_data`
+WHERE `id`='%s' AND `password`='%s' LIMIT 1",
+ array(bigintval(getSession('sponsorid')), getSession('sponsorpass')), __FILE__, __LINE__);
+
+// Entry found?
if (SQL_NUMROWS($result) == 1) {
// Load sponsor data
$content = SQL_FETCHARRAY($result);
- if ($content['status'] == "CONFIRMED") {
+ if ($content['status'] == 'CONFIRMED') {
// Check if form was submitted or not
- if (!empty($_POST['ok'])) {
+ if (isFormSent()) {
// Check passwords
- if (empty($_POST['pass_old'])) {
+ if (!isPostRequestParameterSet('pass_old')) {
// No current password entered
- $MSG = SPONSOR_NO_CURRENT_PASSWORD_ENTERED;
- } elseif (md5($_POST['pass_old']) != $_COOKIE['sponsorpass']) {
+ $message = getMessage('SPONSOR_NO_CURRENT_PASSWORD_ENTERED');
+ } elseif (md5(postRequestParameter('pass_old')) != getSession('sponsorpass')) {
// Entered password didn't match password in DB
- $MSG = SPONSOR_CURRENT_PASSWORD_DIDNOT_MATCH_DB;
- } elseif ((!empty($_POST['pass1'])) && (!empty($_POST['pass2'])) && ($_POST['pass1'] != $_POST['pass2'])) {
+ $message = getMessage('SPONSOR_CURRENT_PASSWORD_DIDNOT_MATCH_DB');
+ } elseif ((isPostRequestParameterSet('pass1')) && (isPostRequestParameterSet('pass2')) && (postRequestParameter('pass1') != postRequestParameter('pass2'))) {
// Both new passwords did not match
- $MSG = SPONSOR_BOTH_NEW_PASSWORDS_DIDNOT_MATCH;
- } elseif ((empty($_POST['pass1'])) && (!empty($_POST['pass2']))) {
+ $message = getMessage('SPONSOR_BOTH_NEW_PASSWORDS_DIDNOT_MATCH');
+ } elseif ((!isPostRequestParameterSet('pass1')) && (isPostRequestParameterSet('pass2'))) {
// No password one entered
- $MSG = SPONSOR_PASSWORD_ONE_EMPTY;
- } elseif ((!empty($_POST['pass1'])) && (empty($_POST['pass2']))) {
+ $message = getMessage('SPONSOR_PASSWORD_ONE_EMPTY');
+ } elseif ((isPostRequestParameterSet('pass1')) && (!isPostRequestParameterSet('pass2'))) {
// No password two entered
- $MSG = SPONSOR_PASSWORD_TWO_EMPTY;
- } elseif ((!empty($_POST['pass1'])) && (strlen($_POST['pass1']) < $CONFIG['pass_len'])) {
+ $message = getMessage('SPONSOR_PASSWORD_TWO_EMPTY');
+ } elseif ((isPostRequestParameterSet('pass1')) && (strlen(postRequestParameter('pass1')) < getConfig('pass_len'))) {
// Too short password
- $MSG = SPONSOR_PASSWORD_TOO_SHORT_1.$CONFIG['pass_len'].SPONSOR_PASSWORD_TOO_SHORT_2;
+ $message = getMessage('SPONSOR_PASSWORD_TOO_SHORT');
} else {
// Default is we don't want to change password!
- $PASS_AND = ""; $PASS_DATA = "";
+ $PASS_AND = ''; $PASS_DATA = '';
// Check if we want to change password or not
- if (($_POST['pass1'] == $_POST['pass2']) && (!empty($_POST['pass1'])) && ($_POST['pass1'] != $_POST['pass_old'])) {
+ if ((postRequestParameter('pass1') == postRequestParameter('pass2')) && (isPostRequestParameterSet('pass1')) && (postRequestParameter('pass1') != postRequestParameter('pass_old'))) {
// Change current password
- $PASS_AND = ", password='%s'";
- $PASS_DATA = md5($_POST['pass1']);
+ $PASS_AND = ", `password`='%s'";
+ $PASS_DATA = md5(postRequestParameter('pass1'));
}
// Unsecure data which we don't want here
// Remove all (maybe spoofed) unsafe data from array
foreach ($UNSAFE as $remove) {
- unset($_POST[$remove]);
+ unsetPostRequestParameter($remove);
}
// Set last change timestamp
- $_POST['last_change'] = time();
+ setPostRequestParameter('last_change', 'UNIX_TIMESTAMP()');
// Save data
- $MSG = SPONSOR_SAVE_DATA($_POST, $content);
+ $message = saveSponsorData(postRequestArray(), $content);
}
- if (!empty($MSG)) {
+ if (!empty($message)) {
// Output message
- $OUT = LOAD_TEMPLATE("admin_settings_saved", true, $MSG);
+ $OUT = loadTemplate('admin_settings_saved', true, $message);
} else {
// No message generated
- $OUT = LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_NO_MESSAGE_GENERATED);
+ $OUT = loadTemplate('admin_settings_saved', true, getMessage('SPONSOR_NO_MESSAGE_GENERATED'));
}
} else {
- // Check for salutation selection
- switch ($content['salut'])
- {
- case "M": // Male
- define('__SALUT_M', " selected");
- define('__SALUT_F', "");
- define('__SALUT_C', "");
- break;
+ // Init gender
+ foreach (array('m', 'f', 'c') as $gender) {
+ $content['gender_' . $gender] = '';
+ } // END - foreach
- case "F": // Female
- define('__SALUT_M', "");
- define('__SALUT_F', " selected");
- define('__SALUT_C', "");
- break;
-
- case "C": // Company
- define('__SALUT_M', "");
- define('__SALUT_F', "");
- define('__SALUT_C', " selected");
- break;
- }
+ // Check for gender selection
+ $content['gender_' . strtolower($content['gender'])] = ' selected="selected"';
// Output formular
- $OUT = LOAD_TEMPLATE("sponsor_account_form", true, $content);
+ $OUT = loadTemplate('sponsor_account_form', true, $content);
}
} else {
// Locked or so?
- $STATUS = SPONSOR_TRANSLATE_STATUS($content['status']);
- $OUT = LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_ACCOUNT_FAILED_1.$STATUS.SPONSOR_ACCOUNT_FAILED_2);
+ $STATUS = sponsorTranslateUserStatus($content['status']);
+ $OUT = loadTemplate('admin_settings_saved', true, getMaskedMessage('SPONSOR_ACCOUNT_FAILED', $STATUS));
}
} else {
// Sponsor account not found!
- $OUT = LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_ACCOUNT_404_1.$_COOKIE['sponsorid'].SPONSOR_ACCOUNT_404_2);
+ $OUT = loadTemplate('admin_settings_saved', true, getMaskedMessage('SPONSOR_ACCOUNT_404', getSession('sponsorid')));
}
// Free memory
SQL_FREERESULT($result);
-//
+// [EOF]
?>