More queries now depends on UNIX_TIMESTAMP() SQL function, wrong index in autopurge...
[mailer.git] / inc / modules / member / what-transfer.php
1 <?php
2 /************************************************************************
3  * MXChange v0.2.1                                    Start: 10/07/2004 *
4  * ================                             Last change: 10/07/2004 *
5  *                                                                      *
6  * -------------------------------------------------------------------- *
7  * File              : what-transfer.php                                *
8  * -------------------------------------------------------------------- *
9  * Short description : Point transfers                                  *
10  * -------------------------------------------------------------------- *
11  * Kurzbeschreibung  : Punktetransfers                                  *
12  * -------------------------------------------------------------------- *
13  *                                                                      *
14  * -------------------------------------------------------------------- *
15  * Copyright (c) 2003 - 2008 by Roland Haeder                           *
16  * For more information visit: http://www.mxchange.org                  *
17  *                                                                      *
18  * This program is free software; you can redistribute it and/or modify *
19  * it under the terms of the GNU General Public License as published by *
20  * the Free Software Foundation; either version 2 of the License, or    *
21  * (at your option) any later version.                                  *
22  *                                                                      *
23  * This program is distributed in the hope that it will be useful,      *
24  * but WITHOUT ANY WARRANTY; without even the implied warranty of       *
25  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the        *
26  * GNU General Public License for more details.                         *
27  *                                                                      *
28  * You should have received a copy of the GNU General Public License    *
29  * along with this program; if not, write to the Free Software          *
30  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston,               *
31  * MA  02110-1301  USA                                                  *
32  ************************************************************************/
33
34 // Some security stuff...
35 if (!defined('__SECURITY')) {
36         $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
37         require($INC);
38 } elseif (!IS_MEMBER()) {
39         LOAD_URL("modules.php?module=index");
40 } elseif ((!EXT_IS_ACTIVE("transfer")) && (!IS_ADMIN())) {
41         ADD_FATAL(EXTENSION_PROBLEM_EXT_INACTIVE, "transfer");
42         return;
43 }
44
45 // Add description as navigation point
46 ADD_DESCR("member", basename(__FILE__));
47
48 // Load data
49 $result = SQL_QUERY_ESC("SELECT opt_in FROM "._MYSQL_PREFIX."_user_data WHERE userid=%s LIMIT 1",
50  array($GLOBALS['userid']), __FILE__, __LINE__);
51 list($opt_in) = SQL_FETCHROW($result);
52
53 // Free memory
54 SQL_FREERESULT($result);
55
56 $MODE = "";
57 if (!empty($_GET['mode'])) $MODE = $_GET['mode'];
58
59 // Check for "faker"
60 if (($opt_in == "N") && ($MODE == "new")) $MODE = "";
61
62 switch ($MODE)
63 {
64 case "new": // Start new transfer
65         // Get total points and subtract the balance amount from it = maximum transferable points
66         $result = SQL_QUERY_ESC("SELECT SUM(points) FROM "._MYSQL_PREFIX."_user_points WHERE userid=%s AND points > 0",
67          array($GLOBALS['userid']), __FILE__, __LINE__);
68         list($total) = SQL_FETCHROW($result);
69         SQL_FREERESULT($result);
70
71         // Get totally used points and password
72         $result = SQL_QUERY_ESC("SELECT used_points, password FROM "._MYSQL_PREFIX."_user_data WHERE userid=%s LIMIT 1",
73          array($GLOBALS['userid']), __FILE__, __LINE__);
74         list($used, $pass) = SQL_FETCHROW($result);
75         SQL_FREERESULT($result);
76
77         // Remember maximum value for template
78         define('__TRANSFER_MAX_VALUE', round($total - $used - $_CONFIG['transfer_balance'] - 0.5));
79
80         if (isset($_POST['ok']))
81         {
82                 // Add new transfer
83                 if ($_CONFIG['transfer_code'] > 0)
84                 {
85                         // Check for code
86                         $code = GEN_RANDOM_CODE($_CONFIG['transfer_code'], $_POST['code_chk'], $GLOBALS['userid'], __TRANSFER_MAX_VALUE);
87                         $valid_code = ($code == $_POST['code']);
88                 }
89                  else
90                 {
91                         // Zero length (= disabled) is always valid!
92                         $valid_code = true;
93                 }
94
95                 // Test password
96                 $valid_pass = ($pass == generateHash($_POST['password'], $pass));
97
98                 // Test transfer amount
99                 $valid_amount = ((!empty($_POST['points'])) && ($_POST['points'] <= __TRANSFER_MAX_VALUE));
100
101                 // Test reason for transfer
102                 $valid_reason = (!empty($_POST['reason']));
103
104                 // Test if a recipient is selected
105                 $valid_recipient = ($_POST['to_uid'] > 0);
106
107                 // Check for nickname extension and set additional data
108                 $nick = false; $ADD = ", userid";
109                 if (EXT_IS_ACTIVE("nickname"))
110                 {
111                         $ADD = ", nickname";
112                         $nick = true;
113                 }
114                 // Re-check receivers and own personal data
115                 $result = SQL_QUERY_ESC("SELECT userid, gender, surname, family, email".$ADD." FROM "._MYSQL_PREFIX."_user_data WHERE userid IN ('%s', '%s') AND status='CONFIRMED' ORDER BY userid LIMIT 2",
116                  array($GLOBALS['userid'], bigintval($_POST['to_uid'])), __FILE__, __LINE__);
117                 $valid_data = (SQL_NUMROWS($result) == 2);
118
119                 if ($valid_code && $valid_pass && $valid_amount && $valid_reason && $valid_recipient)
120                 {
121                         // Let's start the transfer and load user data
122                         list($uid1, $gender1, $sname1, $fname1, $email1, $nick1) = SQL_FETCHROW($result);
123                         list($uid2, $gender2, $sname2, $fname2, $email2, $nick2) = SQL_FETCHROW($result);
124                         SQL_FREERESULT($result);
125                         if ($uid1 == $GLOBALS['userid'])
126                         {
127                                 // Data row 1 is sender's data
128                                 define('__SENDER_GENDER'     , TRANSLATE_GENDER($gender1));
129                                 define('__SENDER_NICK'    , $nick1);
130                                 define('__SENDER_SNAME'   , $sname1);
131                                 define('__SENDER_FNAME'   , $fname1);
132                                 define('__SENDER_EMAIL'   , $email1);
133                                 // Data row 2 is recpient's data
134                                 define('__RECIPIENT_GENDER'  , TRANSLATE_GENDER($gender2));
135                                 define('__RECIPIENT_NICK' , $nick2);
136                                 define('__RECIPIENT_SNAME', $sname2);
137                                 define('__RECIPIENT_FNAME', $fname2);
138                                 define('__RECIPIENT_EMAIL', $email2);
139
140                                 // Prepare variables for testing
141                                 $TEST_NICK_SENDER = $nick1;
142                                 $TEST_NICK_REC = $nick2;
143                         }
144                          else
145                         {
146                                 // Data row 2 is sender's data
147                                 define('__SENDER_GENDER'     , TRANSLATE_GENDER($gender2));
148                                 define('__SENDER_NICK'    , $nick2);
149                                 define('__SENDER_SNAME'   , $sname2);
150                                 define('__SENDER_FNAME'   , $fname2);
151                                 define('__SENDER_EMAIL'   , $email2);
152                                 // Data row 1 is recpient's data
153                                 define('__RECIPIENT_GENDER'  , TRANSLATE_GENDER($gender1));
154                                 define('__RECIPIENT_NICK' , $nick1);
155                                 define('__RECIPIENT_SNAME', $sname1);
156                                 define('__RECIPIENT_FNAME', $fname1);
157                                 define('__RECIPIENT_EMAIL', $email1);
158
159                                 // Prepare variables for testing
160                                 $TEST_NICK_SENDER = $nick2;
161                                 $TEST_NICK_REC = $nick1;
162                         }
163                         // Sender's UID is always currently stored in cookie userid...
164                         define('__SENDER_UID'     , $GLOBALS['userid']);
165                         define('__RECIPIENT_UID'  , $_POST['to_uid']);
166
167                         $SENDER = __SENDER_UID;
168                         $RECIPIENT = __RECIPIENT_UID;
169                         if ($nick)
170                         {
171                                 if (($TEST_NICK_SENDER != __SENDER_UID) && (!empty($TEST_NICK_SENDER)))
172                                 {
173                                         $SENDER = __SENDER_NICK;
174                                 }
175                                 if (($TEST_NICK_REC != __RECIPIENT_UID) && (!empty($TEST_NICK_REC)))
176                                 {
177                                         $RECIPIENT = __RECIPIENT_NICK;
178                                 }
179                         }
180
181                         // Remember transfer reason and fancy date/time in constants
182                         define('__TRANSFER_REASON', $_POST['reason']);
183                         if (function_exists('CREATE_FANCY_TIME'))
184                         {
185                                 define('__TRANSFER_EXPIRES', CREATE_FANCY_TIME($_CONFIG['transfer_age']));
186                         }
187                          else
188                         {
189                                 define('__TRANSFER_EXPIRES', round($_CONFIG['transfer_age']/60/60/24)." ".DAYS);
190                         }
191
192                         // Generate tranafer id
193                         define('__TRANS_ID', bigintval(GEN_RANDOM_CODE("10", rand(0, 99999), $GLOBALS['userid'], $_POST['reason'])));
194
195                         // Add entries to both tables
196                         $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_user_transfers_in (userid, from_uid, points, reason, time_trans, trans_id) VALUES ('%s', '%s', '%s', '%s', UNIX_TIMESTAMP(), '%s')",
197                          array(bigintval($_POST['to_uid']), $GLOBALS['userid'], bigintval($_POST['points']), addslashes($_POST['reason']), __TRANS_ID),
198                          __FILE__, __LINE__);
199                         $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_user_transfers_out (userid, to_uid, points, reason, time_trans, trans_id) VALUES ('%s', '%s', '%s', '%s', UNIX_TIMESTAMP(), '%s')",
200                          array($GLOBALS['userid'], bigintval($_POST['to_uid']), bigintval($_POST['points']), addslashes($_POST['reason']), __TRANS_ID),
201                          __FILE__, __LINE__);
202
203                         // Add points to account *directly* ...
204                         $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_user_points SET points=points+%s WHERE userid=%s AND ref_depth=0 LIMIT 1",
205                          array(bigintval($_POST['points']), bigintval($_POST['to_uid'])), __FILE__, __LINE__);
206
207                         // ... and add it to current user's used points
208                         SUB_POINTS($GLOBALS['userid'], $_POST['points']);
209
210                         // First send email to recipient
211                         $msg = LOAD_EMAIL_TEMPLATE("member_transfer_recipient", "", __RECIPIENT_UID);
212                         SEND_EMAIL(__RECIPIENT_EMAIL, TRANSFER_MEMBER_RECIPIENT_SUBJ.": ".$SENDER, $msg);
213
214                         // Second send email to sender
215                         $msg = LOAD_EMAIL_TEMPLATE("member_transfer_sender", "", __SENDER_UID);
216                         SEND_EMAIL(__SENDER_EMAIL, TRANSFER_MEMBER_SENDER_SUBJ.": ".$RECIPIENT, $msg);
217
218                         // At last send admin mail(s)
219                         $ADMIN_SUBJ = sprintf("%s (%s->%s)", TRANSFER_ADMIN_SUBJECT, $SENDER, $RECIPIENT);
220                         SEND_ADMIN_NOTIFICATION($ADMIN_SUBJ, "admin_transfer_points");
221
222                         // Transfer is completed
223                         LOAD_TEMPLATE("admin_settings_saved", false, TRANSFER_COMPLETED."<br /><A href=\"".URL."/modules.php?module=login&amp;what=transfer\">".TRANSFER_CONTINUE_OVERVIEW."</A>");
224                 }
225                  elseif (!$valid_code)
226                 {
227                         // Invalid Touring code!
228                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_CODE."</STRONG></P>");
229                         unset($_POST['ok']);
230                 }
231                  elseif (!$valid_pass)
232                 {
233                         // Wrong password entered
234                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_PASSWORD."</STRONG></P>");
235                         unset($_POST['ok']);
236                 }
237                  elseif (!$valid_amount)
238                 {
239                         // Too much points entered
240                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_POINTS."</STRONG></P>");
241                         unset($_POST['ok']);
242                 }
243                  elseif (!$valid_reason)
244                 {
245                         // No transfer reason entered
246                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_REASON."</STRONG></P>");
247                         unset($_POST['ok']);
248                 }
249                  elseif (!$valid_recipient)
250                 {
251                         // No recipient selected
252                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_RECIPIENT."</STRONG></P>");
253                         unset($_POST['ok']);
254                 }
255                  elseif (!$valid_data)
256                 {
257                         // No recipient selected
258                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_DATA."</STRONG></P>");
259                         unset($_POST['ok']);
260                 }
261         }
262         if (!isset($_POST['ok']))
263         {
264                 // Load member list
265                 if (EXT_IS_ACTIVE("nickname"))
266                 {
267                         // Load userid and nickname
268                         $result = SQL_QUERY_ESC("SELECT userid, nickname FROM "._MYSQL_PREFIX."_user_data WHERE status='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY userid",
269                          array($GLOBALS['userid']), __FILE__, __LINE__);
270                 }
271                  else
272                 {
273                         // Load only userid
274                         $result = SQL_QUERY_ESC("SELECT userid, userid FROM "._MYSQL_PREFIX."_user_data WHERE status='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY userid",
275                          array($GLOBALS['userid']), __FILE__, __LINE__);
276                 }
277                 if (SQL_NUMROWS($result) > 0)
278                 {
279                         // Load list
280                         $OUT  = "<SELECT name=\"to_uid\" size=\"1\" class=\"member_select\">
281   <OPTION value=\"0\">".SELECT_NONE."</OPTION>\n";
282                         while (list($uid, $nick) = SQL_FETCHROW($result))
283                         {
284                                 $OUT .= "<OPTION value=\"".$uid."\"";
285                                 if ((isset($_POST['to_uid'])) && ($_POST['to_uid'] == $uid)) $OUT .= " selected=\"selected\"";
286                                 $OUT .= ">";
287                                 if (($nick != $uid) && (!empty($nick)))
288                                 {
289                                         // Output nickname
290                                         $OUT .= $nick;
291                                 }
292                                  else
293                                 {
294                                         // Output userid
295                                         $OUT .= $uid;
296                                 }
297                                 $OUT .= "</OPTION>\n";
298                         }
299                         $OUT .= "</SELECT>\n";
300                         define('__TRANSFER_TO_DISABLED', "");
301
302                         // Free memory
303                         SQL_FREERESULT($result);
304                 }
305                  else
306                 {
307                         // No one else is opt-in
308                         $OUT = TRANSFER_NO_ONE_ELSE_OPT_IN;
309                         define('__TRANSFER_TO_DISABLED', " disabled");
310                 }
311                 // Transfer output to constant for the template
312                 define('__TRANSFER_USERID_SELECTION', $OUT);
313
314                 // Generate Code
315                 if ($_CONFIG['transfer_code'] > 0)
316                 {
317                         $rand = rand(0, 99999);
318                         $code = GEN_RANDOM_CODE($_CONFIG['transfer_code'], $rand, $GLOBALS['userid'], __TRANSFER_MAX_VALUE);
319                         $img = GENERATE_IMAGE($code, false);
320                         define('__TRANSFER_IMAGE_INPUT', "<INPUT type=\"hidden\" name=\"code_chk\" value=\"".$rand."\"><INPUT type=\"text\" name=\"code\" class=\"member_normal\" size=\"5\" maxlength=\"7\"".__TRANSFER_TO_DISABLED.">&nbsp;".$img);
321                 }
322                  else
323                 {
324                         $code = "00000";
325                         define('__TRANSFER_IMAGE_INPUT', TRANSFER_NO_CODE);
326                 }
327
328                 // Transfer maybe already entered valued'
329                 if (isset($_GET['ok'])) {
330                         // Get values from form
331                         define('__TRANSFER_POINTS_VALUE', bigintval($_POST['points']));
332                         define('__TRANSFER_REASON_VALUE', strip_tags($_POST['reason']));
333                 } else {
334                         // Set empty values
335                         define('__TRANSFER_POINTS_VALUE', "");
336                         define('__TRANSFER_REASON_VALUE', "");
337                 }
338
339                 // Output form
340                 LOAD_TEMPLATE("member_transfer_new");
341         }
342         break;
343
344 case "list_in": // List only incoming transactions
345 case "list_out": // List only outgoing transactions
346         // As you can see I put list_in and list_out together. I now do a switch() again on it for the right SQL command
347         switch ($MODE)
348         {
349         case "list_in":
350                 $SQL = "SELECT trans_id, from_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_in WHERE userid=%s ORDER BY time_trans DESC LIMIT ".$_CONFIG['transfer_max'];
351                 $NOTHING = TRANSFER_NO_INCOMING_TRANSFERS;
352                 define('__TRANSFER_SUM', TRANSFER_TOTAL_INCOMING);
353                 define('__TRANSFER_TITLE', TRANSFER_LIST_INCOMING);
354                 break;
355
356         case "list_out":
357                 $SQL = "SELECT trans_id, to_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_out WHERE userid=%s ORDER BY time_trans DESC LIMIT ".$_CONFIG['transfer_max'];
358                 $NOTHING = TRANSFER_NO_OUTGOING_TRANSFERS;
359                 define('__TRANSFER_SUM', TRANSFER_TOTAL_OUTGOING);
360                 define('__TRANSFER_TITLE', TRANSFER_LIST_OUTGOING);
361                 break;
362         }
363
364         // Run the SQL command
365         $total = 0;
366         $result = SQL_QUERY_ESC($SQL, array($GLOBALS['userid']), __FILE__, __LINE__);
367         if (SQL_NUMROWS($result) > 0)
368         {
369                 $OUT = ""; $SW = 2;
370                 while (list($tid, $uid, $points, $reason, $stamp) = SQL_FETCHROW($result))
371                 {
372                         if ($type == "OUT") $points = "$points-";
373                         $OUT .= "<TR>
374   <TD class=\"transfer_row1 switch_sw".$SW." bottom2 right2\">
375     <FONT class=\"transfer_row1\">".$tid."</FONT>
376   </TD>
377   <TD class=\"transfer_row2 switch_sw".$SW." bottom2 right2\">
378     <FONT class=\"transfer_row2\">".MAKE_DATETIME($stamp, "3")."</FONT>
379   </TD>
380   <TD class=\"transfer_row3 switch_sw".$SW." bottom2 right2\">
381     <FONT class=\"transfer_row3\">".$uid."</FONT>
382   </TD>
383   <TD class=\"transfer_row4 switch_sw".$SW." bottom2 right2\">
384     <FONT class=\"transfer_row4\">".$reason."</FONT>
385   </TD>
386   <TD class=\"transfer_row5 switch_sw".$SW." bottom2\">
387     <FONT class=\"transfer_row5\">".$points."</FONT>
388   </TD>
389 </TR>\n";
390                         $total += $points;
391                         $SW = 3 - $SW;
392                 }
393
394                 // Free memory
395                 SQL_FREERESULT($result);
396         }
397          else
398         {
399                 // Nothing for in or out
400                 $OUT = "<TR>
401   <TD colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
402     ".LOAD_TEMPLATE("admin_settings_saved", true, $NOTHING)."
403   </TD>
404 </TR>";
405         }
406
407         // ... and add them to a constant for the template
408         define('__TRANSFER_ROWS', $OUT);
409
410         // Remeber total amount
411         define('__TRANSFER_TOTAL_VALUE', $total);
412
413         // Load final template
414         LOAD_TEMPLATE("member_transfer_list");
415         break;
416
417 case "list_all": // List all transactions
418         // We fill a temporary table with data from both tables. This is much easier
419         // to code and unstand by you as sub-SELECT queries. I know this is not the
420         // fastest way but it shall be fine for now.
421         //
422         // First of all create the temporary table
423         $result = SQL_QUERY("CREATE TEMPORARY TABLE "._MYSQL_PREFIX."_transfers_tmp (
424 trans_id VARCHAR(12) NOT NULL DEFAULT '',
425 party_uid BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
426 points BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
427 reason VARCHAR(255) NOT NULL DEFAULT '',
428 time_trans VARCHAR(10) NOT NULL DEFAULT '0',
429 trans_type ENUM('IN', 'OUT') NOT NULL DEFAULT 'IN',
430 KEY(party_uid)
431 ) TYPE=HEAP", __FILE__, __LINE__);
432
433         // Let's begin with the incoming list
434         $result = SQL_QUERY_ESC("SELECT trans_id, from_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_in WHERE userid=%s ORDER BY id LIMIT %s",
435 array($GLOBALS['userid'], $_CONFIG['transfer_max']), __FILE__, __LINE__);
436         while ($DATA = SQL_FETCHROW($result))
437         {
438                 $DATA[] = "IN";
439                 $DATA = implode("', '", $DATA);
440                 $res_temp = SQL_QUERY("INSERT INTO "._MYSQL_PREFIX."_transfers_tmp (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
441         }
442
443         // Free memory
444         SQL_FREERESULT($result);
445
446         // As the last table transfer data from outgoing table to temporary
447         $result = SQL_QUERY_ESC("SELECT trans_id, to_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_out WHERE userid=%s ORDER BY id LIMIT %s",
448 array($GLOBALS['userid'], $_CONFIG['transfer_max']), __FILE__, __LINE__);
449         while ($DATA = SQL_FETCHROW($result))
450         {
451                 $DATA[] = "OUT";
452                 $DATA = implode("', '", $DATA);
453                 $res_temp = SQL_QUERY("INSERT INTO "._MYSQL_PREFIX."_transfers_tmp (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
454         }
455
456         // Free memory
457         SQL_FREERESULT($result);
458
459         $total = 0;
460         if (SQL_NUMROWS($result) > 0)
461         {
462                 // Output rows
463                 $OUT = ""; $SW = 2;
464                 $result = SQL_QUERY("SELECT party_uid, trans_id, points, reason, time_trans, trans_type FROM "._MYSQL_PREFIX."_transfers_tmp ORDER BY time_trans DESC", __FILE__, __LINE__);
465                 while(list($uid, $idx, $points, $reason, $stamp, $type) = SQL_FETCHROW($result))
466                 {
467                         if ($type == "OUT") $points = "-$points";
468                         $OUT .= "<TR>
469   <TD class=\"transfer_row1 switch_sw".$SW." bottom2 right2\">
470     <FONT class=\"transfer_row1\">".$idx."</FONT>
471   </TD>
472   <TD class=\"transfer_row2 switch_sw".$SW." bottom2 right2\">
473     <FONT class=\"transfer_row2\">".MAKE_DATETIME($stamp, "3")."</FONT>
474   </TD>
475   <TD class=\"transfer_row3 switch_sw".$SW." bottom2 right2\">
476     <FONT class=\"transfer_row3\">".$uid."</FONT>
477   </TD>
478   <TD class=\"transfer_row4 switch_sw".$SW." bottom2 right2\">
479     <FONT class=\"transfer_row4\">".$reason."</FONT>
480   </TD>
481   <TD class=\"transfer_row5 switch_sw".$SW." bottom2\">
482     <FONT class=\"transfer_row5\">".$points."</FONT>
483   </TD>
484 </TR>\n";
485                         $total += $points;
486                         $SW = 3 - $SW;
487                 }
488
489                 // Free memory
490                 SQL_FREERESULT($result);
491         }
492          else
493         {
494                 // Nothing for in and out
495                 $OUT = "<TR>
496   <TD colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
497     ".LOAD_TEMPLATE("admin_settings_saved", true, TRANSFER_NO_INOUT_TRANSFERS)."
498   </TD>
499 </TR>";
500         }
501
502         // ... and add them to a constant for the template
503         define('__TRANSFER_ROWS', $OUT);
504
505         // Remeber total amount
506         define('__TRANSFER_TOTAL_VALUE', $total);
507
508         // Set title
509         define('__TRANSFER_TITLE', TRANSFER_LIST_ALL);
510
511         // Set "balance" word
512         define('__TRANSFER_SUM', TRANSFER_TOTAL_BALANCE);
513
514         // Load final template
515         LOAD_TEMPLATE("member_transfer_list");
516
517         // At the end we don't need a temporary table in memory
518         $result = SQL_QUERY("DROP TABLE IF EXISTS "._MYSQL_PREFIX."_transfers_tmp", __FILE__, __LINE__);
519
520         // Free some memory...
521         SQL_FREERESULT($result);
522         break;
523
524 case "": // Overview page
525         // Check incoming transfers
526         $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM "._MYSQL_PREFIX."_user_transfers_in WHERE userid=%s", array($GLOBALS['userid']), __FILE__, __LINE__);
527         list($dmy) = SQL_FETCHROW($result);
528         SQL_FREERESULT($result);
529
530         $total=$dmy;
531         if ($dmy > 0)
532         {
533                 define('__TRANSFER_IN_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=list_in\">".$dmy."</A>");
534         }
535          else
536         {
537                 define('__TRANSFER_IN_LINK', $dmy);
538         }
539
540         // Check outgoing transfers
541         $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM "._MYSQL_PREFIX."_user_transfers_out WHERE userid=%s", array($GLOBALS['userid']), __FILE__, __LINE__);
542         list($dmy) = SQL_FETCHROW($result);
543         SQL_FREERESULT($result);
544
545         $total+=$dmy;
546         if ($dmy > 0)
547         {
548                 define('__TRANSFER_OUT_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=list_out\">".$dmy."</A>");
549         }
550          else
551         {
552                 define('__TRANSFER_OUT_LINK', $dmy);
553         }
554
555         // Total transactions
556         if ($total > 0)
557         {
558                 define('__TRANSFER_ALL_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=list_all\">".$total."</A>");
559         }
560          else
561         {
562                 define('__TRANSFER_ALL_LINK', $total);
563         }
564
565         if (isset($_POST['ok'])) {
566                 // Save settings
567                 $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_user_data SET opt_in='%s' WHERE userid=%s LIMIT 1",
568                  array($_POST['opt_in'], $GLOBALS['userid']), __FILE__, __LINE__);
569
570                 // Rember for next switch() command
571                 $opt_in = $_POST['opt_in'];
572
573                 // "Settings saved..."
574                 OUTPUT_HTML("<P><STRONG class=\"member_done\">".SETTINGS_SAVED."</STRONG></P>");
575         }
576
577         switch ($opt_in)
578         {
579         case 'Y':
580                 define('__TRANSFER_ALLOW_Y', " checked");
581                 define('__TRANSFER_ALLOW_N', "");
582                 define('__TRANSFER_NEW_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=new\">".TRANSFER_NOW_LINK."</A>");
583                 break;
584
585         case 'N':
586                 define('__TRANSFER_ALLOW_Y', "");
587                 define('__TRANSFER_ALLOW_N', " checked");
588                 define('__TRANSFER_NEW_LINK', TRANSFER_PLEASE_ALLOW_OPT_IN);
589                 break;
590         }
591
592         // Check for latest out-transfers
593         $result = SQL_QUERY_ESC("SELECT time_trans FROM "._MYSQL_PREFIX."_user_transfers_out WHERE time_trans > (UNIX_TIMESTAMP() - ".$_CONFIG['transfer_timeout'].") AND userid=%s ORDER BY time_trans DESC LIMIT 1", array($GLOBALS['userid']), __FILE__, __LINE__);
594         if (SQL_NUMROWS($result) == 0) {
595                 // Load template
596                 define('__TRANSFER_SETTINGS_CONTENT', LOAD_TEMPLATE("member_transfer_settings", true));
597         } else {
598                 // Load newest transaction
599                 list($newest) = SQL_FETCHROW($result);
600                 SQL_FREERESULT($result);
601                 define('__TRANSFER_SETTINGS_CONTENT', TRANSFER_LATEST_IS_1.MAKE_DATETIME($newest, "3").TRANSFER_LATEST_IS_2);
602         }
603
604         // Load template
605         LOAD_TEMPLATE("member_transfer_overview");
606         break;
607 }
608 //
609 ?>