1b8056b99e39a22a68d0ea05eeeadb22560be9b8
[mailer.git] / inc / libs / sponsor_functions.php
1 <?php
2 /************************************************************************
3  * MXChange v0.2.1                                    Start: 04/23/2005 *
4  * ===============                              Last change: 05/18/2008 *
5  *                                                                      *
6  * -------------------------------------------------------------------- *
7  * File              : sponsor_functions.php                            *
8  * -------------------------------------------------------------------- *
9  * Short description : Functions for the sponsor area                   *
10  * -------------------------------------------------------------------- *
11  * Kurzbeschreibung  : Funktionen fuer den Sponsorenbereich             *
12  * -------------------------------------------------------------------- *
13  *                                                                      *
14  * -------------------------------------------------------------------- *
15  * Copyright (c) 2003 - 2008 by Roland Haeder                           *
16  * For more information visit: http://www.mxchange.org                  *
17  *                                                                      *
18  * This program is free software. You can redistribute it and/or modify *
19  * it under the terms of the GNU General Public License as published by *
20  * the Free Software Foundation; either version 2 of the License.       *
21  *                                                                      *
22  * This program is distributed in the hope that it will be useful,      *
23  * but WITHOUT ANY WARRANTY; without even the implied warranty of       *
24  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the        *
25  * GNU General Public License for more details.                         *
26  *                                                                      *
27  * You should have received a copy of the GNU General Public License    *
28  * along with this program; if not, write to the Free Software          *
29  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston,               *
30  * MA  02110-1301  USA                                                  *
31  ************************************************************************/
32
33 // Some security stuff...
34 if (!defined('__SECURITY')) {
35         $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4)."/security.php";
36         require($INC);
37 }
38
39 //
40 function SPONSOR_HANDLE_SPONSOR (&$POST, $NO_UPDATE=false, $MSGs=array(), $RET_STATUS=false) {
41         // Init a lot variables
42         $SAVE = true;
43         $UPDATE = false;
44         $skip = false;
45         $ALREADY = false;
46         $ret = "unused";
47
48         // Skip these entries
49         $SKIPPED = array(
50                 'ok', 'edit', 'terms', 'pay_type'
51         );
52
53         // Save sponsor data
54         $DATA = array(
55                 'keys'   => array(),
56                 'values' => array()
57         );
58
59         // Check if sponsor already exists
60         foreach ($POST as $k => $v) {
61                 if (!(array_search($k, $SKIPPED) > -1)) {
62                         // Check only posted input entries not the submit button
63                         switch ($k)
64                         {
65                         case "email":
66                                 $ALREADY = false;
67                                 if (!VALIDATE_EMAIL($v)) {
68                                         // Email address is not valid
69                                         $SAVE = false;
70                                 } else {
71                                         // Do we want to add a new sponsor or update his data?
72                                         $result = SQL_QUERY_ESC("SELECT id FROM "._MYSQL_PREFIX."_sponsor_data WHERE email='%s' LIMIT 1",
73                                                 array($POST['email']), __FILE__, __LINE__);
74
75                                         // Is a sponsor alread in the db?
76                                         if (SQL_NUMROWS($result) == 1) {
77                                                 // Yes, he is!
78                                                 if (($GLOBALS['what'] == "add_sponsor") || ($NO_UPDATE)) {
79                                                         // Already found!
80                                                         $ALREADY = true;
81                                                 } else {
82                                                         // Update his data
83                                                         $UPDATE = true;
84                                                 }
85                                         }
86
87                                         // Free memory
88                                         SQL_FREERESULT($result);
89                                 }
90                                 break;
91
92                         case "pass1":
93                                 $k = ""; $v = "";
94                                 break;
95
96                         case "pass2":
97                                 $k = "password"; $v = md5($v);
98                                 break;
99
100                         case "url":
101                                 if (!VALIDATE_URL($v)) $SAVE = false;
102                                 break;
103
104                         default:
105                                 // Test if there is are time selections
106                                 $TEST = substr($k, -3);
107                                 if ((($TEST == "_ye") || ($TEST == "_mo") || ($TEST == "_we") || ($TEST == "_da") || ($TEST == "_ho") || ($TEST == "_mi") || ($TEST == "_se")) && (!empty($v))) {
108                                         // Found a multi-selection for timings?
109                                         $TEST = substr($k, 0, -3);
110                                         if ((!empty($POST[$TEST."_ye"])) && (!empty($POST[$TEST."_mo"])) && (!empty($POST[$TEST."_we"])) && (!empty($POST[$TEST."_da"])) && (!empty($POST[$TEST."_ho"])) && (!empty($POST[$TEST."_mi"])) && (!empty($POST[$TEST."_se"])) && ($TEST != $TEST2)) {
111                                                 // Generate timestamp
112                                                 $POST[$TEST] = CREATE_TIMESTAMP_FROM_SELECTIONS($TEST, $POST);
113                                                 $DATA['keys'][] = $TEST;
114                                                 $DATA['values'][] = $POST[$TEST];
115
116                                                 // Remove data from array
117                                                 // @TODO Do we still need this all?
118                                                 unset($POST[$TEST."_ye"]);
119                                                 unset($POST[$TEST."_mo"]);
120                                                 unset($POST[$TEST."_we"]);
121                                                 unset($POST[$TEST."_da"]);
122                                                 unset($POST[$TEST."_ho"]);
123                                                 unset($POST[$TEST."_mi"]);
124                                                 unset($POST[$TEST."_se"]);
125
126                                                 // Skip adding
127                                                 $k = ""; $skip = true; $TEST2 = $TEST;
128                                         }
129                                 } else {
130                                         $skip = false; $TEST2 = "";
131                                 }
132                                 break;
133                         }
134
135                         if ((!empty($k)) && ($skip == false)) {
136                                 // Add data
137                                 $DATA['keys'][] = $k; $DATA['values'][] = $v;
138                         }
139                 }
140         }
141
142         // Save sponsor?
143         if ($SAVE) {
144                 // Default is no force even when a guest want to abuse this force switch
145                 if ((empty($POST['force'])) || (!IS_ADMIN())) $POST['force'] = 0;
146
147                 // SQL and message string is empty by default
148                 $SQL = ""; $MSG = "";
149
150                 // Update?
151                 if ($UPDATE) {
152                         // Update his data
153                         $SQL = "UPDATE "._MYSQL_PREFIX."_sponsor_data SET ";
154                         foreach ($DATA['keys'] as $k => $v) {
155                                 $SQL .= $v."='%s', ";
156                         }
157
158                         // Remove last ", " from SQL string
159                         $SQL = substr($SQL, 0, -2)." WHERE id='%s' LIMIT 1";
160                         $DATA['values'][] = bigintval($_GET['id']);
161
162                         // Generate message
163                         $MSG = SPONSOR_GET_MESSAGE(ADMIN_SPONSOR_UPDATED, "updated", $MSGs);
164                         $ret = "updated";
165                 } elseif ((!$ALREADY) || (($POST['force'] == "1") && (IS_ADMIN()))) {
166                         // Add new sponsor, first add more data
167                         $DATA['keys'][] = "sponsor_created"; $DATA['values'][] = time();
168                         $DATA['keys'][] = "status";
169                         if ((!$NO_UPDATE) && (IS_ADMIN()) && ($GLOBALS['what'] == "add_sponsor")) {
170                                 // Only allowed for admin
171                                 $DATA['values'][] = "PENDING";
172                         } elsen{
173                                 // Guest area
174                                 $DATA['values'][] = "UNCONFIRMED";
175
176                                 // Generate hash code
177                                 $DATA['keys'][] = "hash";
178                                 $DATA['values'][] = md5(session_id().":".$POST['email'].":".GET_REMOTE_ADDR().":".GET_USER_AGENT().":".time());
179                                 $DATA['keys'][] = "remote_addr";
180                                 $DATA['values'][] = GET_REMOTE_ADDR();
181                         }
182
183                         // Implode all data into strings
184                         $KEYS   = implode(", "  , $DATA['keys']);
185                         $VALUES = str_repeat("%s', '", count($DATA['values']) - 1);
186
187                         // Generate string
188                         $SQL = "INSERT INTO "._MYSQL_PREFIX."_sponsor_data (".$KEYS.") VALUES ('".$VALUES."%s')";
189
190                         // Generate message
191                         $MSG = SPONSOR_GET_MESSAGE(ADMIN_SPONSOR_ADDED, "added", $MSGs);
192                         $ret = "added";
193                 } elseif ((!$NO_UPDATE) && (IS_ADMIN())) {
194                         // Add all data as hidden data
195                         $OUT = "";
196                         foreach ($POST as $k => $v) {
197                                 // Do not add 'force' !
198                                 if ($k != "force") {
199                                         $OUT .= "<INPUT type=\"hidden\" name=\"".$k."\" value=\"".stripslashes($v)."\">\n";
200                                 }
201                         }
202                         define('__HIDDEN_DATA', $OUT);
203                         define('__EMAIL'      , $POST['email']);
204
205                         // Ask for adding a sponsor with same email address
206                         LOAD_TEMPLATE("admin_add_sponsor_already");
207                         return;
208                 } else {
209                         // Already added!
210                         $MSG = SPONSOR_ALREADY_FOUND_1.$POST['email'].SPONSOR_ALREADY_FOUND_2;
211                         $ret = "already";
212                 }
213
214                 if (!empty($SQL)) {
215                         // Run SQL command
216                         $result = SQL_QUERY_ESC($SQL, $DATA['values'], __FILE__, __LINE__);
217                 }
218
219                 // Output message
220                 if ((!$NO_UPDATE) && (IS_ADMIN())) {
221                         LOAD_TEMPLATE("admin_settings_saved", false, $MSG);
222                 }
223         } else {
224                 // Error found!
225                 $MSG = SPONSOR_GET_MESSAGE(SPONSOR_DATA_NOT_SAVED, "failed", $MSGs);
226                 LOAD_TEMPLATE("admin_settings_saved", false, $MSG);
227         }
228
229         // Shall we return the status?
230         if ($RET_STATUS) return $ret;
231 }
232 //
233 function SPONSOR_TRANSLATE_STATUS($status) {
234         switch ($status)
235         {
236         case "UNCONFIRMED":
237                 $ret = ACCOUNT_UNCONFIRMED;
238                 break;
239
240         case "CONFIRMED":
241                 $ret = ACCOUNT_CONFIRMED;
242                 break;
243
244         case "LOCKED":
245                 $ret = ACCOUNT_LOCKED;
246                 break;
247
248         case "PENDING":
249                 $ret = ACCOUNT_PENDING;
250                 break;
251
252         case "EMAIL":
253                 $ret = ACCOUNT_EMAIL;
254                 break;
255
256         default:
257                 DEBUG_LOG(__FUNCTION__, __LINE__, sprintf("Unknown status %s detected.", $status));
258                 $ret = UNKNOWN_STATUS_1.$status.UNKNOWN_STATUS_2;
259                 break;
260         }
261         return $ret;
262 }
263 // Search for an email address in the database
264 function SPONSOR_FOUND_EMAIL_DB ($email) {
265         // Do we already have the provided email address in our DB?
266         $ret = (GET_TOTAL_DATA($email, "sponsor_data", "id", "email", true) == 1);
267
268         // Return result
269         return $ret;
270 }
271 //
272 function SPONSOR_GET_MESSAGE ($msg, $pos, $array) {
273         // Check if the requested message was found in array
274         if (isset($array[$pos])) {
275                 // ... if yes then use it!
276                 $ret = $array[$pos];
277         } else {
278                 // ... else use default message
279                 $ret = $msg;
280         }
281
282         // Return result
283         return $ret;
284 }
285
286 //
287 function IS_SPONSOR () {
288         // Failed...
289         $ret = false;
290         if ((isSessionVariableSet('sponsorid'))) && (isSessionVariableSet('sponsorpass')))) {
291                 // Check cookies against database records...
292                 $result = SQL_QUERY_ESC("SELECT id FROM "._MYSQL_PREFIX."_sponsor_data
293 WHERE id='%s' AND password='%s' AND status='CONFIRMED' LIMIT 1",
294                         array(bigintval(get_session('sponsorid')), get_session('sponsorpass')), __FILE__, __LINE__);
295                 if (SQL_NUMROWS($result) == 1) {
296                         // All is fine
297                         $ret = true;
298                 }
299
300                 // Free memory
301                 SQL_FREERESULT($result);
302         }
303
304         // Return status
305         return $ret;
306 }
307 //
308 function GENERATE_SPONSOR_MENU($current)
309 {
310         $OUT = "";
311         $WHERE = " AND active='Y'";
312         if (IS_ADMIN()) $WHERE = "";
313
314         // Load main menu entries
315         $result_main = SQL_QUERY("SELECT action, title FROM "._MYSQL_PREFIX."_sponsor_menu
316 WHERE (what='' OR what IS NULL) ".$WHERE."
317 ORDER BY sort", __FILE__, __LINE__);
318         if (SQL_NUMROWS($result_main) > 0)
319         {
320                 // Load every menu and it's sub menus
321                 while(list($action, $title_main) = SQL_FETCHROW($result_main))
322                 {
323                         // Load sub menus
324                         $result_sub = SQL_QUERY_ESC("SELECT what, title FROM "._MYSQL_PREFIX."_sponsor_menu
325 WHERE action='%s' AND what != '' AND what IS NOT NULL ".$WHERE."
326 ORDER BY sort", array($action), __FILE__, __LINE__);
327                         if (SQL_NUMROWS($result_sub) > 0)
328                         {
329                                 // Load sub menus
330                                 $SUB = "";
331                                 while(list($what, $title_sub) = SQL_FETCHROW($result_sub))
332                                 {
333                                         // Check if current selected menu is matching the loaded one
334                                         if ($current == $what) $title_sub = "<strong>".$title_sub."</strong>";
335
336                                         // Prepare data for the sub template
337                                         $content = array(
338                                                 'what'  => $what,
339                                                 'title' => $title_sub
340                                         );
341
342                                         // Load row template
343                                         $SUB .= LOAD_TEMPLATE("sponsor_what", true, $content);
344                                 }
345
346                                 // Prepare data for the main template
347                                 $content = array(
348                                         'title' => $title_main,
349                                         'menu'  => $SUB
350                                 );
351
352                                 // Load menu template
353                                 $OUT .= LOAD_TEMPLATE("sponsor_action", true, $content);
354                         }
355                          else
356                         {
357                                 // No sub menus active
358                                 $OUT .= LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_NO_SUB_MENUS_ACTIVE);
359                         }
360
361                         // Free memory
362                         SQL_FREERESULT($result_sub);
363                 }
364         }
365          else
366         {
367                 // No main menus active
368                 $OUT .= LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_NO_MAIN_MENUS_ACTIVE);
369         }
370
371         // Free memory
372         SQL_FREERESULT($result_main);
373
374         // Return content
375         return $OUT;
376 }
377 //
378 function GENERATE_SPONSOR_CONTENT($what)
379 {
380         global $_CONFIG;
381         $OUT = "";
382         $FILE = sprintf("%sinc/modules/sponsor/%s.php", PATH, $what);
383         if (FILE_READABLE($FILE)) {
384                 // Every sponsor action will output nothing directly. It will be written into $OUT!
385                 require_once($FILE);
386         } else {
387                 // File not found!
388                 $OUT .= LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_CONTENT_404_1.$what.SPONSOR_CONTENT_404_2);
389         }
390
391         // Return content
392         return $OUT;
393 }
394 //
395 function UPDATE_SPONSOR_LOGIN () {
396         // Failed by default
397         $login = false;
398
399         // Is sponsor?
400         if (IS_SPONSOR()) {
401                 // Update last online timestamp
402                 SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_sponsor_data
403 SET last_online=UNIX_TIMESTAMP()
404 WHERE id='%s' AND password='%s' LIMIT 1",
405                         array(bigintval(get_session('sponsorid')), get_session('sponsorpass')), __FILE__, __LINE__);
406
407                 // This update went fine?
408                 $login = (SQL_AFFECTEDROWS() == 1);
409         }
410
411         // Return status
412         return $login;
413 }
414 //
415 function SPONSOR_SAVE_DATA ($POST, $content) {
416         $EMAIL = false;
417
418         // Unsecure data which we don't want
419         $UNSAFE = array('password', 'id', 'remote_addr', 'sponsor_created', 'last_online', 'status', 'ref_count',
420                         'points_amount', 'points_used', 'refid', 'hash', 'last_pay', 'last_curr', 'pass_old',
421                         'ok', 'pass1', 'pass2');
422
423         // Set default message ("not saved")
424         $MSG = SPONSOR_ACCOUNT_DATA_NOT_SAVED;
425
426         // Check for submitted passwords
427         if ((!empty($POST['pass1'])) && (!empty($POST['pass2']))) {
428                 // Are both passwords the same?
429                 if ($POST['pass1'] == $POST['pass2']) {
430                         // Okay, then set password and remove pass1 and pass2
431                         $POST['password'] = md5($POST['pass1']);
432                 }
433         }
434
435         // Remove all (maybe spoofed) unsafe data from array
436         foreach ($UNSAFE as $remove) {
437                 unset($POST[$remove]);
438         }
439
440         // This array is for the submitted data which we will use with the SQL_QUERY_ESC() function to
441         // secure the data
442         $DATA = array();
443
444         // Prepare SQL string
445         $SQL = "UPDATE "._MYSQL_PREFIX."_sponsor_data SET";
446         foreach ($POST as $key => $value) {
447                 // Mmmmm, too less security here???
448                 $SQL   .= " ".strip_tags($key)."='%s',";
449
450                 // We will secure this later inside the SQL_QUERY_ESC() function
451                 $DATA[] = strip_tags($value);
452
453                 // Compile {SLASH} and so on for the email templates
454                 $POST[$key] = COMPILE_CODE($value);
455         }
456
457         // Check if email has changed
458         if ((!empty($content['email'])) && (!empty($POST['email']))) {
459                 if ($content['email'] != $POST['email']) {
460                         // Change email address
461                         $EMAIL = true;
462
463                         // Okay, has changed then add status with UNCONFIRMED and new hash code
464                         $SQL .= " status='EMAIL', hash='%s',";
465
466                         // Generate hash code
467                         $HASH = md5(session_id().":".$POST['email'].":".GET_REMOTE_ADDR().":".GET_USER_AGENT().":".time());
468                         $DATA[] = $HASH;
469                 }
470         }
471
472         // Remove last commata
473         $SQL = substr($SQL, 0, -1);
474
475         // Add SQL tail data
476         $SQL .= " WHERE id='%s' AND password='%s' LIMIT 1";
477         $DATA[] = bigintval(get_session('sponsorid'));
478         $DATA[] = get_session('sponsorpass');
479
480         // Saving data was completed... ufff...
481         switch ($GLOBALS['what'])
482         {
483         case "account": // Change account data
484                 if ($EMAIL) {
485                         $MSG   = SPONSOR_ACCOUNT_EMAIL_CHANGED;
486                         $templ = "admin_sponsor_change_email";
487                         $subj  = ADMIN_SPONSOR_ACC_EMAIL_SUBJ;
488                 }
489                  else
490                 {
491                         $MSG   = SPONSOR_ACCOUNT_DATA_SAVED;
492                         $templ = "admin_sponsor_change_data";
493                         $subj  = ADMIN_SPONSOR_ACC_DATA_SUBJ;
494                 }
495                 break;
496
497         case "settings": // Change settings
498                 // Translate some data
499                 $content['receive']  = TRANSLATE_YESNO($content['receive_warnings']);
500                 $content['interval'] = CREATE_FANCY_TIME($content['warning_interval']);
501
502                 // Set message template and subject for admin
503                 $MSG   = SPONSOR_SETTINGS_SAVED;
504                 $templ = "admin_sponsor_settings";
505                 $subj  = ADMIN_SPONSOR_SETTINGS_SUBJ;
506                 break;
507
508         default: // Unknown sponsor what value!
509                 DEBUG_LOG(__FUNCTION__, __LINE__, sprintf("Unknown sponsor module (what) %s detected.", $GLOBALS['what']));
510                 $MSG = SPONSOR_UNKNOWN_WHAT_1.$GLOBALS['what'].SPONSOR_UNKNOWN_WHAT_2;
511                 $templ = ""; $subj = "";
512                 break;
513         }
514
515         if (SQL_AFFECTEDROWS() == 1)
516         {
517                 if (!empty($templ) && !empty($subj))
518                 {
519                         // Run SQL command and check for success
520                         $result = SQL_QUERY_ESC($SQL, $DATA, __FILE__, __LINE__);
521
522                         // Add all data to content
523                         global $DATA;
524                         $DATA = $POST;
525
526                         // Change some data
527                         if (isset($content['gender'])) $content['gender'] = TRANSLATE_GENDER($content['gender']);
528                         if (isset($DATA['gender']))    $DATA['gender']    = TRANSLATE_GENDER($DATA['gender']);
529                         if (isset($content['receive_warnings'])) $DATA['receive']     = TRANSLATE_YESNO($POST['receive_warnings']);
530                         if (isset($content['warning_interval'])) $DATA['interval']    = CREATE_FANCY_TIME($POST['warning_interval']);
531
532                         // Send email to admins
533                         SEND_ADMIN_NOTIFICATION($subj, $templ, $content);
534
535                         // Shall we send mail to the sponsor's new email address?
536                         if ($content['receive_warnings'] == "Y")
537                         {
538                                 // Okay send email with confirmation link to new address and with no confirmation link
539                                 // to the old address
540
541                                 // First to old address
542                                 switch ($GLOBALS['what'])
543                                 {
544                                 case "account": // Change account data
545                                         $email_msg = LOAD_EMAIL_TEMPLATE("sponsor_change_data", $content);
546                                         SEND_EMAIL($content['email'], SPONSOR_ACC_DATA_SUBJ, $email_msg);
547
548                                         if ($EMAIL)
549                                         {
550                                                 // Add hash code to content array
551                                                 $content['hash'] = $HASH;
552
553                                                 // Second mail goes to the new address
554                                                 $email_msg = LOAD_EMAIL_TEMPLATE("sponsor_change_email", $content);
555                                                 SEND_EMAIL($content['email'], SPONSOR_ACC_EMAIL_SUBJ, $email_msg);
556                                         }
557                                         break;
558
559                                 case "settings": // Change settings
560                                         // Send email
561                                         $email_msg = LOAD_EMAIL_TEMPLATE("sponsor_settings", $content);
562                                         SEND_EMAIL($content['email'], SPONSOR_SETTINGS_SUBJ, $email_msg);
563                                         break;
564                                 }
565                         }
566                 }
567         }
568
569         // Return final message
570         return $MSG;
571 }
572 //
573 ?>