X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;ds=sidebyside;f=modules.php;h=a56acc311ba784f7c096935c48150511515c9016;hb=5deec33be1baf2135eefc2bbb0d1b63c6cbd2f9a;hp=c862671e537600364e013c03b91ca14b8095284d;hpb=8ece7fd45c386f7ccd60f9c4800ad207602b0240;p=mailer.git diff --git a/modules.php b/modules.php index c862671e53..a56acc311b 100644 --- a/modules.php +++ b/modules.php @@ -35,27 +35,21 @@ //xdebug_start_trace(); // Load security stuff here (Oh, I hope this is not unsecure? Am I paranoia??? ;-) ) -require_once("inc/libs/security_functions.php"); +require("inc/libs/security_functions.php"); // Init "action" and "what" -global $what, $action, $startTime; $GLOBALS['startTime'] = microtime(true); -$CSS = 0; -$GLOBALS['what'] = ""; $GLOBALS['action'] = ""; +$GLOBALS['output_mode'] = 0; +$GLOBALS['what'] = ""; +$GLOBALS['action'] = ""; $GLOBALS['userid'] = 0; - -// Fix missing module to "index" -if (empty($_GET['module'])) $_GET['module'] = "index"; - -// Secure action/what if present -if (!empty($_GET['action'])) $GLOBALS['action'] = secureString($_GET['action']); -if (!empty($_GET['what'])) $GLOBALS['what'] = secureString($_GET['what']); - -// Secure the module name (very important line!) -$GLOBALS['module'] = secureString($_GET['module']); +$GLOBALS['module'] = ""; // Needed include files -require_once("inc/config.php"); +require("inc/config.php"); + +// Fix missing module to "index" +if (!REQUEST_ISSET_GET(('module'))) REQUEST_SET_GET('module', "index"); // Check if logged in if (IS_MEMBER()) { @@ -70,11 +64,11 @@ if (IS_MEMBER()) { // Additionally admin? if (IS_ADMIN()) { // Add it - $username .= " ({!_ADMIN_SHORT!})"; + $username .= " ({--_ADMIN_SHORT--})"; } // END - if } else { // Hmmm, logged in and no valid userid? - $username = "{!_UNKNOWN!}"; + $username = "{--_UNKNOWN--}"; // Destroy session destroy_user_session(); @@ -87,10 +81,10 @@ if (IS_MEMBER()) { SQL_FREERESULT($result); } elseif (IS_ADMIN()) { // Admin is there - $username = _ADMIN; + $username = getMessage('_ADMIN'); } else { // He's a guest, hello there... ;-) - $username = _GUEST; + $username = getMessage('_GUEST'); } // The header file @@ -100,52 +94,52 @@ LOAD_INC_ONCE("inc/header.php"); $MOD_VALID = false; $check = "failed"; if ((getConfig('maintenance') == "Y") && (!IS_ADMIN()) && ($GLOBALS['module'] != "admin")) { // Maintain mode is active and you are no admin - addFatalMessage(getMessage('LANG_DOWN_MAINTAINCE')); -} elseif (($link) && ($db) && (getTotalFatalErrors() == 0)) { + addFatalMessage(__FILE__, __LINE__, getMessage('LANG_DOWN_MAINTAINCE')); +} elseif ((SQL_IS_LINK_UP()) && (getTotalFatalErrors() == 0)) { // Construct module name define('__MODULE', sprintf("inc/modules/%s.php", SQL_ESCAPE($GLOBALS['module']))); // Did we found the module listed in allowed modules and are we successfully connected? - $check = CHECK_MODULE($GLOBALS['module']); + $check = checkModulePermissions($GLOBALS['module']); switch ($check) { case "admin_only": case "mem_only": case "done": // Does the module exists on local file system? - if ((FILE_READABLE(__MODULE)) && (getTotalFatalErrors() == 0)) { + if ((FILE_READABLE(constant('__MODULE'))) && (getTotalFatalErrors() == 0)) { // Module is valid, active and located on the local disc... $MOD_VALID = true; } elseif (!empty($URL)) { // An URL was specified so we load the de-referrer module LOAD_URL(DEREFERER($URL)); } elseif (getTotalFatalErrors() == 0) { - addFatalMessage(LANG_MOD_REG_404_1.$GLOBALS['module'].LANG_MOD_REG_404_2); + addFatalMessage(__FILE__, __LINE__, sprintf(getMessage('LANG_MOD_REG_404'), $GLOBALS['module'])); } break; case "404": - addFatalMessage(LANG_MOD_REG_404_1.$GLOBALS['module'].LANG_MOD_REG_404_2); + addFatalMessage(__FILE__, __LINE__, sprintf(getMessage('LANG_MOD_REG_404'), $GLOBALS['module'])); break; case "locked": - if (!FILE_READABLE(__MODULE)) { + if (!FILE_READABLE(constant('__MODULE'))) { // Module does addionally not exists - addFatalMessage(LANG_MOD_REG_404_1.$GLOBALS['module'].LANG_MOD_REG_404_2); + addFatalMessage(__FILE__, __LINE__, sprintf(getMessage('LANG_MOD_REG_404'), $GLOBALS['module'])); } // END - if // Add fatal message - addFatalMessage(LANG_MOD_LOCKED_1.$GLOBALS['module'].LANG_MOD_LOCKED_2); + addFatalMessage(__FILE__, __LINE__, sprintf(getMessage('LANG_MOD_REG_LOCKED'), $GLOBALS['module'])); break; default: DEBUG_LOG(__FILE__, __LINE__, sprintf("Unknown status %s return from module check. Module=%s", $check, $GLOBALS['module'])); - addFatalMessage(LANG_MOD_UNKNOWN_1.$check.LANG_MOD_UNKNOWN_2); + addFatalMessage(__FILE__, __LINE__, sprintf(getMessage('LANG_MOD_REG_UNKNOWN'), $check)); break; } } elseif (getTotalFatalErrors() == 0) { // MySQL problems! - addFatalMessage(getMessage('MYSQL_ERRORS')); + addFatalMessage(__FILE__, __LINE__, getMessage('MYSQL_ERRORS')); } if (($MOD_VALID) && (defined('__MODULE'))) { @@ -154,7 +148,7 @@ if (($MOD_VALID) && (defined('__MODULE'))) { ///////////////////////////////////////////// // // Everything is okay so we can load the module - LOAD_INC_ONCE(__MODULE); + LOAD_INC_ONCE(constant('__MODULE')); } // END - if // Next-to-end add the footer