Typo in function name fixed, double->single quotes, some HTML fixes
[mailer.git] / inc / modules / member / what-transfer.php
1 <?php
2 /************************************************************************
3  * MXChange v0.2.1                                    Start: 10/07/2004 *
4  * ================                             Last change: 10/07/2004 *
5  *                                                                      *
6  * -------------------------------------------------------------------- *
7  * File              : what-transfer.php                                *
8  * -------------------------------------------------------------------- *
9  * Short description : Point transfers                                  *
10  * -------------------------------------------------------------------- *
11  * Kurzbeschreibung  : Punktetransfers                                  *
12  * -------------------------------------------------------------------- *
13  * $Revision::                                                        $ *
14  * $Date::                                                            $ *
15  * $Tag:: 0.2.1-FINAL                                                 $ *
16  * $Author::                                                          $ *
17  * Needs to be in all Files and every File needs "svn propset           *
18  * svn:keywords Date Revision" (autoprobset!) at least!!!!!!            *
19  * -------------------------------------------------------------------- *
20  * Copyright (c) 2003 - 2008 by Roland Haeder                           *
21  * For more information visit: http://www.mxchange.org                  *
22  *                                                                      *
23  * This program is free software; you can redistribute it and/or modify *
24  * it under the terms of the GNU General Public License as published by *
25  * the Free Software Foundation; either version 2 of the License, or    *
26  * (at your option) any later version.                                  *
27  *                                                                      *
28  * This program is distributed in the hope that it will be useful,      *
29  * but WITHOUT ANY WARRANTY; without even the implied warranty of       *
30  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the        *
31  * GNU General Public License for more details.                         *
32  *                                                                      *
33  * You should have received a copy of the GNU General Public License    *
34  * along with this program; if not, write to the Free Software          *
35  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston,               *
36  * MA  02110-1301  USA                                                  *
37  ************************************************************************/
38
39 // Some security stuff...
40 if (!defined('__SECURITY')) {
41         $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), '/inc') + 4) . '/security.php';
42         require($INC);
43 } elseif (!IS_MEMBER()) {
44         redirectToUrl('modules.php?module=index');
45 } elseif ((!EXT_IS_ACTIVE('transfer')) && (!IS_ADMIN())) {
46         addFatalMessage(__FILE__, __LINE__, sprintf(getMessage('EXTENSION_PROBLEM_EXT_INACTIVE'), 'transfer'));
47         return;
48 }
49
50 // Add description as navigation point
51 ADD_DESCR('member', __FILE__);
52
53 // Load data
54 $result = SQL_QUERY_ESC("SELECT opt_in FROM `{!_MYSQL_PREFIX!}_user_data` WHERE userid=%s LIMIT 1",
55 array(getUserId()), __FILE__, __LINE__);
56 list($opt_in) = SQL_FETCHROW($result);
57
58 // Free memory
59 SQL_FREERESULT($result);
60
61 $mode = '';
62 if (REQUEST_ISSET_GET(('mode'))) $mode = REQUEST_GET('mode');
63
64 // Check for "faker"
65 if (($opt_in == 'N') && ($mode == "new")) $mode = '';
66
67 switch ($mode)
68 {
69         case "new": // Start new transfer
70                 // Get total points and subtract the balance amount from it = maximum transferable points
71                 $total = GET_TOTAL_DATA(getUserId(), "user_points", "points")  - GET_TOTAL_DATA(getUserId(), "user_data", "used_points");
72
73                 // Remember maximum value for template
74                 define('__TRANSFER_MAX_VALUE', round($total - getConfig('transfer_balance') - 0.5));
75
76                 if (isFormSent()) {
77                         // Add new transfer
78                         if (getConfig('transfer_code') > 0) {
79                                 // Check for code
80                                 $code = generateRandomCode(getConfig('transfer_code'), REQUEST_POST('code_chk'), getUserId(), constant('__TRANSFER_MAX_VALUE'));
81                                 $valid_code = ($code == REQUEST_POST('code'));
82                         } else {
83                                 // Zero length (= disabled) is always valid!
84                                 $valid_code = true;
85                         }
86
87                         // Test password
88                         $valid_pass = ($pass == generateHash(REQUEST_POST('password'), $pass));
89
90                         // Test transfer amount
91                         $valid_amount = ((REQUEST_ISSET_POST(('points'))) && (REQUEST_POST('points') <= constant('__TRANSFER_MAX_VALUE')));
92
93                         // Test reason for transfer
94                         $valid_reason = (REQUEST_ISSET_POST(('reason')));
95
96                         // Test if a recipient is selected
97                         $valid_recipient = (REQUEST_POST('to_uid') > 0);
98
99                         // Check for nickname extension and set additional data
100                         $nick = false; $add = ", userid";
101                         if (EXT_IS_ACTIVE('nickname')) {
102                                 $add = ", nickname";
103                                 $nick = true;
104                         }
105
106                         // Re-check receivers and own personal data
107                         $result = SQL_QUERY_ESC("SELECT userid, gender, surname, family, email".$add." FROM `{!_MYSQL_PREFIX!}_user_data` WHERE userid IN ('%s','%s') AND `status`='CONFIRMED' ORDER BY userid LIMIT 2",
108                         array(getUserId(), bigintval(REQUEST_POST('to_uid'))), __FILE__, __LINE__);
109                         $valid_data = (SQL_NUMROWS($result) == 2);
110
111                         if ($valid_code && $valid_pass && $valid_amount && $valid_reason && $valid_recipient) {
112                                 // Let's start the transfer and load user data
113                                 list($uid1, $gender1, $sname1, $fname1, $email1, $nick1) = SQL_FETCHROW($result);
114                                 list($uid2, $gender2, $sname2, $fname2, $email2, $nick2) = SQL_FETCHROW($result);
115                                 SQL_FREERESULT($result);
116                                 // @TODO Rewrite all these constants to array elements
117                                 if ($uid1 == getUserId()) {
118                                         // Data row 1 is sender's data
119                                         define('__SENDER_GENDER'   , translateGender($gender1));
120                                         define('__SENDER_NICK'     , $nick1);
121                                         define('__SENDER_SNAME'    , $sname1);
122                                         define('__SENDER_FNAME'    , $fname1);
123                                         define('__SENDER_EMAIL'    , $email1);
124                                         // Data row 2 is recpient's data
125                                         define('__RECIPIENT_GENDER', translateGender($gender2));
126                                         define('__RECIPIENT_NICK'  , $nick2);
127                                         define('__RECIPIENT_SNAME' , $sname2);
128                                         define('__RECIPIENT_FNAME' , $fname2);
129                                         define('__RECIPIENT_EMAIL' , $email2);
130
131                                         // Prepare variables for testing
132                                         $TEST_NICK_SENDER = $nick1;
133                                         $TEST_NICK_REC = $nick2;
134                                 } else {
135                                         // Data row 2 is sender's data
136                                         define('__SENDER_GENDER'   , translateGender($gender2));
137                                         define('__SENDER_NICK'     , $nick2);
138                                         define('__SENDER_SNAME'    , $sname2);
139                                         define('__SENDER_FNAME'    , $fname2);
140                                         define('__SENDER_EMAIL'    , $email2);
141                                         // Data row 1 is recpient's data
142                                         define('__RECIPIENT_GENDER', translateGender($gender1));
143                                         define('__RECIPIENT_NICK'  , $nick1);
144                                         define('__RECIPIENT_SNAME' , $sname1);
145                                         define('__RECIPIENT_FNAME' , $fname1);
146                                         define('__RECIPIENT_EMAIL' , $email1);
147
148                                         // Prepare variables for testing
149                                         $TEST_NICK_SENDER = $nick2;
150                                         $TEST_NICK_REC = $nick1;
151                                 }
152
153                                 // Sender's UID is always currently stored in cookie userid...
154                                 define('__SENDER_UID'     , getUserId());
155                                 define('__RECIPIENT_UID'  , REQUEST_POST('to_uid'));
156
157                                 $SENDER = constant('__SENDER_UID');
158                                 $RECIPIENT = constant('__RECIPIENT_UID');
159                                 if ($nick) {
160                                         if (($TEST_NICK_SENDER != constant('__SENDER_UID')) && (!empty($TEST_NICK_SENDER))) {
161                                                 $SENDER = constant('__SENDER_NICK');
162                                         }
163
164                                         if (($TEST_NICK_REC != constant('__RECIPIENT_UID')) && (!empty($TEST_NICK_REC))) {
165                                                 $RECIPIENT = constant('__RECIPIENT_NICK');
166                                         }
167                                 }
168
169                                 // Remember transfer reason and fancy date/time in constants
170                                 define('__TRANSFER_REASON', REQUEST_POST('reason'));
171                                 define('__TRANSFER_EXPIRES', createFancyTime(getConfig('transfer_age')));
172
173                                 // Generate tranafer id
174                                 define('__TRANS_ID', bigintval(generateRandomCode("10", mt_rand(0, 99999), getUserId(), REQUEST_POST('reason'))));
175
176                                 // Add entries to both tables
177                                 SQL_QUERY_ESC("INSERT INTO `{!_MYSQL_PREFIX!}_user_transfers_in` (userid, from_uid, points, reason, time_trans, trans_id) VALUES ('%s','%s','%s','%s', UNIX_TIMESTAMP(),'%s')",
178                                 array(bigintval(REQUEST_POST('to_uid')), getUserId(), bigintval(REQUEST_POST('points')), REQUEST_POST('reason'), __TRANS_ID),
179                                 __FILE__, __LINE__);
180                                 SQL_QUERY_ESC("INSERT INTO `{!_MYSQL_PREFIX!}_user_transfers_out` (userid, to_uid, points, reason, time_trans, trans_id) VALUES ('%s','%s','%s','%s', UNIX_TIMESTAMP(),'%s')",
181                                 array(getUserId(), bigintval(REQUEST_POST('to_uid')), bigintval(REQUEST_POST('points')), REQUEST_POST('reason'), __TRANS_ID),
182                                 __FILE__, __LINE__);
183
184                                 // Add points to account *directly* ...
185                                 ADD_POINTS_REFSYSTEM_DIRECT('member_transfer', bigintval(REQUEST_POST('to_uid')), bigintval(REQUEST_POST('points')));
186
187                                 // ... and add it to current user's used points
188                                 SUB_POINTS('transfer', getUserId(), REQUEST_POST('points'));
189
190                                 // First send email to recipient
191                                 $msg = LOAD_EMAIL_TEMPLATE('member_transfer_recipient', '', constant('__RECIPIENT_UID'));
192                                 sendEmail(constant('__RECIPIENT_EMAIL'), getMessage('TRANSFER_MEMBER_RECIPIENT_SUBJ') . ': ' . $SENDER, $msg);
193
194                                 // Second send email to sender
195                                 $msg = LOAD_EMAIL_TEMPLATE('member_transfer_sender', '', constant('__SENDER_UID'));
196                                 sendEmail(constant('__SENDER_EMAIL'), getMessage('TRANSFER_MEMBER_SENDER_SUBJ') . ': ' . $RECIPIENT, $msg);
197
198                                 // At last send admin mail(s)
199                                 $ADMIN_SUBJ = sprintf("%s (%s->%s)", getMessage('TRANSFER_ADMIN_SUBJECT'), $SENDER, $RECIPIENT);
200                                 sendAdminNotification($ADMIN_SUBJ, 'admin_transfer_points');
201
202                                 // Transfer is completed
203                                 LOAD_TEMPLATE('admin_settings_saved', false, getMessage('TRANSFER_COMPLETED')."<br /><a href=\"{!URL!}/modules.php?module=login&amp;what=transfer\">{--TRANSFER_CONTINUE_OVERVIEW--}</a>");
204                         } elseif (!$valid_code) {
205                                 // Invalid Touring code!
206                                 LOAD_TEMPLATE('admin_settings_saved', false, "<div class=\"member_note\">{--TRANSFER_INVALID_CODE--}</div>");
207                                 REQUEST_UNSET_POST('ok');
208                         } elseif (!$valid_pass) {
209                                 // Wrong password entered
210                                 LOAD_TEMPLATE('admin_settings_saved', false, "<div class=\"member_note\">{--TRANSFER_INVALID_PASSWORD--}</div>");
211                                 REQUEST_UNSET_POST('ok');
212                         } elseif (!$valid_amount) {
213                                 // Too much points entered
214                                 LOAD_TEMPLATE('admin_settings_saved', false, "<div class=\"member_note\">{--TRANSFER_INVALID_POINTS--}</div>");
215                                 REQUEST_UNSET_POST('ok');
216                         } elseif (!$valid_reason) {
217                                 // No transfer reason entered
218                                 LOAD_TEMPLATE('admin_settings_saved', false, "<div class=\"member_note\">{--TRANSFER_INVALID_REASON--}</div>");
219                                 REQUEST_UNSET_POST('ok');
220                         } elseif (!$valid_recipient) {
221                                 // No recipient selected
222                                 LOAD_TEMPLATE('admin_settings_saved', false, "<div class=\"member_note\">{--TRANSFER_INVALID_RECIPIENT--}</div>");
223                                 REQUEST_UNSET_POST('ok');
224                         } elseif (!$valid_data) {
225                                 // No recipient selected
226                                 LOAD_TEMPLATE('admin_settings_saved', false, "<div class=\"member_note\">{--TRANSFER_INVALID_DATA--}</div>");
227                                 REQUEST_UNSET_POST('ok');
228                         }
229                 }
230
231                 if (!isFormSent()) {
232                         // Load member list
233                         if (EXT_IS_ACTIVE('nickname')) {
234                                 // Load userid and nickname
235                                 $result = SQL_QUERY_ESC("SELECT userid, nickname FROM `{!_MYSQL_PREFIX!}_user_data` WHERE `status`='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY `userid` ASC",
236                                         array(getUserId()), __FILE__, __LINE__);
237                         } else {
238                                 // Load only userid
239                                 $result = SQL_QUERY_ESC("SELECT userid, userid FROM `{!_MYSQL_PREFIX!}_user_data` WHERE `status`='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY `userid` ASC",
240                                         array(getUserId()), __FILE__, __LINE__);
241                         }
242
243                         if (SQL_NUMROWS($result) > 0) {
244                                 // Load list
245                                 $OUT  = "<select name=\"to_uid\" size=\"1\" class=\"member_select\">
246         <option value=\"0\">{--SELECT_NONE--}</option>\n";
247                                 // @TODO Try to rewrite his to $content = SQL_FETCHARRAY(), see some lines above for two different queries
248                                 while (list($uid, $nick) = SQL_FETCHROW($result)) {
249                                         $OUT .= "       <option value=\"".$uid."\"";
250                                         if ((REQUEST_ISSET_POST(('to_uid'))) && (REQUEST_POST('to_uid') == $uid)) $OUT .= ' selected="selected"';
251                                         $OUT .= ">";
252                                         if (($nick != $uid) && (!empty($nick))) {
253                                                 // Output nickname
254                                                 $OUT .= $nick;
255                                         } else {
256                                                 // Output userid
257                                                 $OUT .= $uid;
258                                         }
259                                         $OUT .= "</option>\n";
260                                 }
261                                 $OUT .= "</select>\n";
262                                 define('__TRANSFER_TO_DISABLED', '');
263
264                                 // Free memory
265                                 SQL_FREERESULT($result);
266                         } else {
267                                 // No one else is opt-in
268                                 $OUT = getMessage('TRANSFER_NO_ONE_ELSE_OPT_IN');
269                                 define('__TRANSFER_TO_DISABLED', ' disabled="disabled"');
270                         }
271
272                         // Transfer output to constant for the template
273                         define('__TRANSFER_USERID_SELECTION', $OUT);
274
275                         // Generate Code
276                         if (getConfig('transfer_code') > 0) {
277                                 $rand = mt_rand(0, 99999);
278                                 $code = generateRandomCode(getConfig('transfer_code'), $rand, getUserId(), constant('__TRANSFER_MAX_VALUE'));
279                                 $img = GENERATE_IMAGE($code, false);
280                                 define('__TRANSFER_IMAGE_INPUT', "<input type=\"hidden\" name=\"code_chk\" value=\"".$rand."\" /><input type=\"text\" name=\"code\" class=\"member_normal\" size=\"5\" maxlength=\"7\"{!__TRANSFER_TO_DISABLED!} />&nbsp;".$img);
281                         } else {
282                                 $code = '00000';
283                                 define('__TRANSFER_IMAGE_INPUT', getMessage('TRANSFER_NO_CODE'));
284                         }
285
286                         // Transfer maybe already entered valued'
287                         if (REQUEST_ISSET_GET('ok')) {
288                                 // Get values from form
289                                 define('__TRANSFER_POINTS_VALUE', bigintval(REQUEST_POST('points')));
290                                 define('__TRANSFER_REASON_VALUE', strip_tags(REQUEST_POST('reason')));
291                         } else {
292                                 // Set empty values
293                                 define('__TRANSFER_POINTS_VALUE', '');
294                                 define('__TRANSFER_REASON_VALUE', '');
295                         }
296
297                         // Output form
298                         LOAD_TEMPLATE('member_transfer_new');
299                 }
300                 break;
301
302         case 'list_in': // List only incoming transactions
303         case 'list_out': // List only outgoing transactions
304                 // As you can see I put list_in and list_out together. I now do a switch() again on it for the right SQL command
305                 switch ($mode)
306                 {
307                         case 'list_in':
308                                 $sql = "SELECT trans_id, from_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_in` WHERE userid=%s ORDER BY time_trans DESC LIMIT ".getConfig('transfer_max');
309                                 // @TODO Rewrite these constants
310                                 $NOTHING = getMessage('TRANSFER_NO_INCOMING_TRANSFERS');
311                                 define('__TRANSFER_SUM', getMessage('TRANSFER_TOTAL_INCOMING'));
312                                 define('__TRANSFER_TITLE', getMessage('TRANSFER_LIST_INCOMING'));
313                                 break;
314
315                         case 'list_out':
316                                 $sql = "SELECT trans_id, to_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_out` WHERE userid=%s ORDER BY time_trans DESC LIMIT ".getConfig('transfer_max');
317                                 // @TODO Rewrite these constants
318                                 $NOTHING = getMessage('TRANSFER_NO_OUTGOING_TRANSFERS');
319                                 define('__TRANSFER_SUM', getMessage('TRANSFER_TOTAL_OUTGOING'));
320                                 define('__TRANSFER_TITLE', getMessage('TRANSFER_LIST_OUTGOING'));
321                                 break;
322                 }
323
324                 // Run the SQL command
325                 $total = 0;
326                 $result = SQL_QUERY_ESC($sql, array(getUserId()), __FILE__, __LINE__);
327                 if (SQL_NUMROWS($result) > 0) {
328                         $OUT = ''; $SW = 2;
329                         // @TODO This should be somehow rewritten to $content = SQL_FETCHARRAY(), see switch() block above for SQL queries
330                         while (list($tid, $uid, $points, $reason, $stamp) = SQL_FETCHROW($result)) {
331                                 // Rewrite points
332                                 if ($type == 'OUT') $points = $points.'-';
333
334                                 // Prepare content for template
335                                 $content = array(
336                                 'sw'     => $SW,
337                                 'tid'    => $id,
338                                 'stamp'  => generateDateTime($stamp, '3'),
339                                 'uid'    => $uid,
340                                 'reason' => $reason,
341                                 'points' => translateComma($points)
342                                 );
343
344                                 // Load row template
345                                 $OUT .= LOAD_TEMPLATE('member_transfer_row2', true, $content);
346
347                                 // Add points and switch color
348                                 $total += $points;
349                                 $SW = 3 - $SW;
350                         } // END - while
351
352                         // Free memory
353                         SQL_FREERESULT($result);
354                 } else {
355                         // Nothing for in or out
356                         $OUT = "<tr>
357   <td colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
358     ".LOAD_TEMPLATE('admin_settings_saved', true, $NOTHING)."
359   </td>
360 </tr>";
361                 }
362
363                 // ... and add them to a constant for the template
364                 // @TODO Rewrite these constants
365                 define('__TRANSFER_ROWS', $OUT);
366
367                 // Remeber total amount
368                 define('__TRANSFER_TOTAL_VALUE', $total);
369
370                 // Load final template
371                 LOAD_TEMPLATE('member_transfer_list');
372                 break;
373
374                         case 'list_all': // List all transactions
375                                 // We fill a temporary table with data from both tables. This is much easier
376                                 // to code and unstand by you as sub-SELECT queries. I know this is not the
377                                 // fastest way but it shall be fine for now.
378                                 //
379                                 // First of all create the temporary table
380                                 $result = SQL_QUERY("CREATE TEMPORARY TABLE `{!_MYSQL_PREFIX!}_transfers_tmp` (
381 trans_id VARCHAR(12) NOT NULL DEFAULT '',
382 party_uid BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
383 points BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
384 reason VARCHAR(255) NOT NULL DEFAULT '',
385 time_trans VARCHAR(10) NOT NULL DEFAULT '0',
386 trans_type ENUM('IN','OUT') NOT NULL DEFAULT 'IN',
387 KEY(party_uid)
388 ) TYPE=HEAP", __FILE__, __LINE__);
389
390                                 // Let's begin with the incoming list
391                                 $result = SQL_QUERY_ESC("SELECT trans_id, from_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_in` WHERE userid=%s ORDER BY `id` LIMIT %s",
392                                 array(getUserId(), getConfig('transfer_max')), __FILE__, __LINE__);
393                                 while ($DATA = SQL_FETCHROW($result)) {
394                                         $DATA[] = 'IN';
395                                         $DATA = implode("','", $DATA);
396                                         $res_temp = SQL_QUERY("INSERT INTO `{!_MYSQL_PREFIX!}_transfers_tmp` (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
397                                 }
398
399                                 // Free memory
400                                 SQL_FREERESULT($result);
401
402                                 // As the last table transfer data from outgoing table to temporary
403                                 $result = SQL_QUERY_ESC("SELECT trans_id, to_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_out` WHERE userid=%s ORDER BY `id` LIMIT %s",
404                                 array(getUserId(), getConfig('transfer_max')), __FILE__, __LINE__);
405                                 while ($DATA = SQL_FETCHROW($result)) {
406                                         $DATA[] = 'OUT';
407                                         $DATA = implode("','", $DATA);
408                                         $res_temp = SQL_QUERY("INSERT INTO `{!_MYSQL_PREFIX!}_transfers_tmp` (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
409                                 }
410
411                                 // Free memory
412                                 SQL_FREERESULT($result);
413
414                                 $total = 0;
415                                 if (SQL_NUMROWS($result) > 0) {
416                                         // Search for entries
417                                         $result = SQL_QUERY("SELECT party_uid, trans_id, points, reason, time_trans, trans_type FROM `{!_MYSQL_PREFIX!}_transfers_tmp` ORDER BY time_trans DESC",
418                                         __FILE__, __LINE__);
419
420                                         // Output rows
421                                         $OUT = ''; $SW = 2;
422                                         while ($content = SQL_FETCHARRAY($result)) {
423                                                 // Rewrite points
424                                                 if ($content['trans_type'] == 'OUT') $content['points'] = '-'.$content['points']."";
425
426                                                 // Prepare content for template
427                                                 $content['sw']     = $SW;
428                                                 $content['time']   = generateDateTime($content['time_trans'], '3');
429                                                 $content['points'] = translateComma($content['points']);
430
431                                                 // Load row template
432                                                 $OUT .= LOAD_TEMPLATE("member_transfer_row", true, $content);
433
434                                                 // Add points and switch color
435                                                 $total += $content['points'];
436                                                 $SW = 3 - $SW;
437                                         } // END - while
438
439                                         // Free memory
440                                         SQL_FREERESULT($result);
441                                 } else {
442                                         // Nothing for in and out
443                                         $OUT = "<tr>
444   <td colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
445     ".LOAD_TEMPLATE('admin_settings_saved', true, getMessage('TRANSFER_NO_INOUT_TRANSFERS'))."
446   </td>
447 </tr>";
448                                 }
449
450                                 // ... and add them to a constant for the template
451                                 // @TODO Rewrite all these constants
452                                 define('__TRANSFER_ROWS', $OUT);
453
454                                 // Remeber total amount
455                                 define('__TRANSFER_TOTAL_VALUE', $total);
456
457                                 // Set title
458                                 define('__TRANSFER_TITLE', getMessage('TRANSFER_LIST_ALL'));
459
460                                 // Set "balance" word
461                                 define('__TRANSFER_SUM', getMessage('TRANSFER_TOTAL_BALANCE'));
462
463                                 // Load final template
464                                 LOAD_TEMPLATE('member_transfer_list');
465
466                                 // At the end we don't need a temporary table in memory
467                                 $result = SQL_QUERY("DROP TABLE IF EXISTS `{!_MYSQL_PREFIX!}_transfers_tmp`", __FILE__, __LINE__);
468
469                                 // Free some memory...
470                                 SQL_FREERESULT($result);
471                                 break;
472
473                         case '': // Overview page
474                                 // Check incoming transfers
475                                 $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM `{!_MYSQL_PREFIX!}_user_transfers_in` WHERE userid=%s", array(getUserId()), __FILE__, __LINE__);
476                                 list($dmy) = SQL_FETCHROW($result);
477                                 SQL_FREERESULT($result);
478
479                                 $total=$dmy;
480                                 if ($dmy > 0) {
481                                         define('__TRANSFER_IN_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=list_in\">".$dmy."</a>");
482                                 } else {
483                                         define('__TRANSFER_IN_LINK', $dmy);
484                                 }
485
486                                 // Check outgoing transfers
487                                 $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM `{!_MYSQL_PREFIX!}_user_transfers_out` WHERE userid=%s", array(getUserId()), __FILE__, __LINE__);
488                                 list($dmy) = SQL_FETCHROW($result);
489                                 SQL_FREERESULT($result);
490
491                                 $total+=$dmy;
492                                 if ($dmy > 0) {
493                                         define('__TRANSFER_OUT_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=list_out\">".$dmy."</a>");
494                                 } else {
495                                         define('__TRANSFER_OUT_LINK', $dmy);
496                                 }
497
498                                 // Total transactions
499                                 if ($total > 0) {
500                                         define('__TRANSFER_ALL_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=list_all\">".$total."</a>");
501                                 } else {
502                                         define('__TRANSFER_ALL_LINK', $total);
503                                 }
504
505                                 if (isFormSent()) {
506                                         // Save settings
507                                         SQL_QUERY_ESC("UPDATE `{!_MYSQL_PREFIX!}_user_data` SET opt_in='%s' WHERE userid=%s LIMIT 1",
508                                         array(REQUEST_POST('opt_in'), getUserId()), __FILE__, __LINE__);
509
510                                         // Rember for next switch() command
511                                         $opt_in = REQUEST_POST('opt_in');
512
513                                         // "Settings saved..."
514                                         LOAD_TEMPLATE('admin_settings_saved', false, "<div class=\"member_done\">{--SETTINGS_SAVED--}</div>");
515                                 } // END - if
516
517                                 switch ($opt_in) {
518                                         case 'Y':
519                                                 define('__TRANSFER_ALLOW_Y', ' checked="checked"');
520                                                 define('__TRANSFER_ALLOW_N', '');
521                                                 define('__TRANSFER_NEW_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=new\">{--TRANSFER_NOW_LINK--}</a>");
522                                                 break;
523
524                                         case 'N':
525                                                 define('__TRANSFER_ALLOW_Y', '');
526                                                 define('__TRANSFER_ALLOW_N', ' checked="checked"');
527                                                 define('__TRANSFER_NEW_LINK', getMessage('TRANSFER_PLEASE_ALLOW_OPT_IN'));
528                                                 break;
529                                 } // END - switch
530
531                                 // Check for latest out-transfers
532                                 $result = SQL_QUERY_ESC("SELECT time_trans
533 FROM `{!_MYSQL_PREFIX!}_user_transfers_out`
534 WHERE time_trans > (UNIX_TIMESTAMP() - %s) AND `userid`=%s
535 ORDER BY time_trans DESC
536 LIMIT 1",
537                                         array(getConfig('transfer_timeout'), getUserId()), __FILE__, __LINE__);
538                                 if (SQL_NUMROWS($result) == 0) {
539                                         // Load template
540                                         define('__TRANSFER_SETTINGS_CONTENT', LOAD_TEMPLATE("member_transfer_settings", true));
541                                 } else {
542                                         // Load newest transaction
543                                         list($newest) = SQL_FETCHROW($result);
544                                         SQL_FREERESULT($result);
545                                         define('__TRANSFER_SETTINGS_CONTENT', sprintf(getMessage('TRANSFER_LATEST_IS'), generateDateTime($newest, '3')));
546                                 }
547
548                                 // Load template
549                                 LOAD_TEMPLATE("member_transfer_overview");
550                                 break;
551 }
552
553 //
554 ?>