Password reset for admin login added (still buggy if cache is installed and sql_patch...
[mailer.git] / inc / modules / member / what-transfer.php
1 <?php
2 /************************************************************************
3  * MXChange v0.2.1                                    Start: 10/07/2004 *
4  * ================                             Last change: 10/07/2004 *
5  *                                                                      *
6  * -------------------------------------------------------------------- *
7  * File              : what-transfer.php                                *
8  * -------------------------------------------------------------------- *
9  * Short description : Point transfers                                  *
10  * -------------------------------------------------------------------- *
11  * Kurzbeschreibung  : Punktetransfers                                  *
12  * -------------------------------------------------------------------- *
13  *                                                                      *
14  * -------------------------------------------------------------------- *
15  * Copyright (c) 2003 - 2008 by Roland Haeder                           *
16  * For more information visit: http://www.mxchange.org                  *
17  *                                                                      *
18  * This program is free software; you can redistribute it and/or modify *
19  * it under the terms of the GNU General Public License as published by *
20  * the Free Software Foundation; either version 2 of the License, or    *
21  * (at your option) any later version.                                  *
22  *                                                                      *
23  * This program is distributed in the hope that it will be useful,      *
24  * but WITHOUT ANY WARRANTY; without even the implied warranty of       *
25  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the        *
26  * GNU General Public License for more details.                         *
27  *                                                                      *
28  * You should have received a copy of the GNU General Public License    *
29  * along with this program; if not, write to the Free Software          *
30  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston,               *
31  * MA  02110-1301  USA                                                  *
32  ************************************************************************/
33
34 // Some security stuff...
35 if (ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) {
36         $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
37         require($INC);
38 } elseif (!IS_LOGGED_IN()) {
39         LOAD_URL("modules.php?module=index");
40 } elseif ((!EXT_IS_ACTIVE("transfer")) && (!IS_ADMIN())) {
41         ADD_FATAL(EXTENSION_PROBLEM_EXT_INACTIVE, "transfer");
42         return;
43 }
44
45 // Add description as navigation point
46 ADD_DESCR("member", basename(__FILE__));
47
48 // Load data
49 $result = SQL_QUERY_ESC("SELECT opt_in FROM "._MYSQL_PREFIX."_user_data WHERE userid=%d LIMIT 1",
50  array($GLOBALS['userid']), __FILE__, __LINE__);
51 list($opt_in) = SQL_FETCHROW($result);
52
53 // Free memory
54 SQL_FREERESULT($result);
55
56 $MODE = "";
57 if (!empty($_GET['mode'])) $MODE = $_GET['mode'];
58
59 // Check for "faker"
60 if (($opt_in == "N") && ($MODE == "new")) $MODE = "";
61
62 switch ($MODE)
63 {
64 case "new": // Start new transfer
65         // Get total points and subtract the balance amount from it = maximum transferable points
66         $result = SQL_QUERY_ESC("SELECT SUM(points) FROM "._MYSQL_PREFIX."_user_points WHERE userid=%d AND points > 0",
67          array($GLOBALS['userid']), __FILE__, __LINE__);
68         list($total) = SQL_FETCHROW($result);
69         SQL_FREERESULT($result);
70
71         // Get totally used points and password
72         $result = SQL_QUERY_ESC("SELECT used_points, password FROM "._MYSQL_PREFIX."_user_data WHERE userid=%d LIMIT 1",
73          array($GLOBALS['userid']), __FILE__, __LINE__);
74         list($used, $pass) = SQL_FETCHROW($result);
75         SQL_FREERESULT($result);
76
77         // Remember maximum value for template
78         define('__TRANSFER_MAX_VALUE', round($total - $used - $_CONFIG['transfer_balance'] - 0.5));
79
80         if (isset($_POST['ok']))
81         {
82                 // Add new transfer
83                 if ($_CONFIG['transfer_code'] > 0)
84                 {
85                         // Check for code
86                         $code = GEN_RANDOM_CODE($_CONFIG['transfer_code'], $_POST['code_chk'], $GLOBALS['userid'], __TRANSFER_MAX_VALUE);
87                         $valid_code = ($code == $_POST['code']);
88                 }
89                  else
90                 {
91                         // Zero length (= disabled) is always valid!
92                         $valid_code = true;
93                 }
94
95                 // Test password
96                 $valid_pass = ($pass == generateHash($_POST['password'], $pass));
97
98                 // Test transfer amount
99                 $valid_amount = ((!empty($_POST['points'])) && ($_POST['points'] <= __TRANSFER_MAX_VALUE));
100
101                 // Test reason for transfer
102                 $valid_reason = (!empty($_POST['reason']));
103
104                 // Test if a recipient is selected
105                 $valid_recipient = ($_POST['to_uid'] > 0);
106
107                 // Check for nickname extension and set additional data
108                 $nick = false; $ADD = ", userid";
109                 if (EXT_IS_ACTIVE("nickname"))
110                 {
111                         $ADD = ", nickname";
112                         $nick = true;
113                 }
114                 // Re-check receivers and own personal data
115                 $result = SQL_QUERY_ESC("SELECT userid, sex, surname, family, email".$ADD." FROM "._MYSQL_PREFIX."_user_data WHERE userid IN ('%s', '%s') AND status='CONFIRMED' ORDER BY userid LIMIT 2",
116                  array($GLOBALS['userid'], bigintval($_POST['to_uid'])), __FILE__, __LINE__);
117                 $valid_data = (SQL_NUMROWS($result) == 2);
118
119                 if ($valid_code && $valid_pass && $valid_amount && $valid_reason && $valid_recipient)
120                 {
121                         // Let's start the transfer and load user data
122                         list($uid1, $sex1, $sname1, $fname1, $email1, $nick1) = SQL_FETCHROW($result);
123                         list($uid2, $sex2, $sname2, $fname2, $email2, $nick2) = SQL_FETCHROW($result);
124                         SQL_FREERESULT($result);
125                         if ($uid1 == $GLOBALS['userid'])
126                         {
127                                 // Data row 1 is sender's data
128                                 define('__SENDER_SEX'     , TRANSLATE_SEX($sex1));
129                                 define('__SENDER_NICK'    , $nick1);
130                                 define('__SENDER_SNAME'   , $sname1);
131                                 define('__SENDER_FNAME'   , $fname1);
132                                 define('__SENDER_EMAIL'   , $email1);
133                                 // Data row 2 is recpient's data
134                                 define('__RECIPIENT_SEX'  , TRANSLATE_SEX($sex2));
135                                 define('__RECIPIENT_NICK' , $nick2);
136                                 define('__RECIPIENT_SNAME', $sname2);
137                                 define('__RECIPIENT_FNAME', $fname2);
138                                 define('__RECIPIENT_EMAIL', $email2);
139
140                                 // Prepare variables for testing
141                                 $TEST_NICK_SENDER = $nick1;
142                                 $TEST_NICK_REC = $nick2;
143                         }
144                          else
145                         {
146                                 // Data row 2 is sender's data
147                                 define('__SENDER_SEX'     , TRANSLATE_SEX($sex2));
148                                 define('__SENDER_NICK'    , $nick2);
149                                 define('__SENDER_SNAME'   , $sname2);
150                                 define('__SENDER_FNAME'   , $fname2);
151                                 define('__SENDER_EMAIL'   , $email2);
152                                 // Data row 1 is recpient's data
153                                 define('__RECIPIENT_SEX'  , TRANSLATE_SEX($sex1));
154                                 define('__RECIPIENT_NICK' , $nick1);
155                                 define('__RECIPIENT_SNAME', $sname1);
156                                 define('__RECIPIENT_FNAME', $fname1);
157                                 define('__RECIPIENT_EMAIL', $email1);
158
159                                 // Prepare variables for testing
160                                 $TEST_NICK_SENDER = $nick2;
161                                 $TEST_NICK_REC = $nick1;
162                         }
163                         // Sender's UID is always currently stored in cookie userid...
164                         define('__SENDER_UID'     , $GLOBALS['userid']);
165                         define('__RECIPIENT_UID'  , $_POST['to_uid']);
166
167                         $SENDER = __SENDER_UID;
168                         $RECIPIENT = __RECIPIENT_UID;
169                         if ($nick)
170                         {
171                                 if (($TEST_NICK_SENDER != __SENDER_UID) && (!empty($TEST_NICK_SENDER)))
172                                 {
173                                         $SENDER = __SENDER_NICK;
174                                 }
175                                 if (($TEST_NICK_REC != __RECIPIENT_UID) && (!empty($TEST_NICK_REC)))
176                                 {
177                                         $RECIPIENT = __RECIPIENT_NICK;
178                                 }
179                         }
180
181                         // Remember transfer reason and fancy date/time in constants
182                         define('__TRANSFER_REASON', $_POST['reason']);
183                         if (function_exists('CREATE_FANCY_TIME'))
184                         {
185                                 define('__TRANSFER_EXPIRES', CREATE_FANCY_TIME($_CONFIG['transfer_age']));
186                         }
187                          else
188                         {
189                                 define('__TRANSFER_EXPIRES', round($_CONFIG['transfer_age']/60/60/24)." ".DAYS);
190                         }
191
192                         // Generate tranafer id
193                         define('__TRANS_ID', bigintval(GEN_RANDOM_CODE("10", rand(0, 99999), $GLOBALS['userid'], $_POST['reason'])));
194
195                         // Add entries to both tables
196                         $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_user_transfers_in (userid, from_uid, points, reason, time_trans, trans_id) VALUES ('%s', '%s', '%s', '%s', UNIX_TIMESTAMP(), '%s')",
197                          array(bigintval($_POST['to_uid']), $GLOBALS['userid'], bigintval($_POST['points']), addslashes($_POST['reason']), __TRANS_ID),
198                          __FILE__, __LINE__);
199                         $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_user_transfers_out (userid, to_uid, points, reason, time_trans, trans_id) VALUES ('%s', '%s', '%s', '%s', UNIX_TIMESTAMP(), '%s')",
200                          array($GLOBALS['userid'], bigintval($_POST['to_uid']), bigintval($_POST['points']), addslashes($_POST['reason']), __TRANS_ID),
201                          __FILE__, __LINE__);
202
203                         // Add points to account *directly* ...
204                         $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_user_points SET points=points+%s WHERE userid=%d AND ref_depth=0 LIMIT 1",
205                          array(bigintval($_POST['points']), bigintval($_POST['to_uid'])), __FILE__, __LINE__);
206
207                         // ... and add it to current user's used points
208                         $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_user_data SET used_points=used_points+%s WHERE userid=%d LIMIT 1",
209                          array(bigintval($_POST['points']), $GLOBALS['userid']), __FILE__, __LINE__);
210
211                         // First send email to recipient
212                         $msg = LOAD_EMAIL_TEMPLATE("member_transfer_recipient", "", __RECIPIENT_UID);
213                         SEND_EMAIL(__RECIPIENT_EMAIL, TRANSFER_MEMBER_RECIPIENT_SUBJ.": ".$SENDER, $msg);
214
215                         // Second send email to sender
216                         $msg = LOAD_EMAIL_TEMPLATE("member_transfer_sender", "", __SENDER_UID);
217                         SEND_EMAIL(__SENDER_EMAIL, TRANSFER_MEMBER_SENDER_SUBJ.": ".$RECIPIENT, $msg);
218
219                         // At last send admin mail(s)
220                         $ADMIN_SUBJ = TRANSFER_ADMIN_SUBJECT." (".$SENDER."->".$RECIPIENT.")";
221                         if (GET_EXT_VERSION("admins") >= "0.4.1")
222                         {
223                                 SEND_ADMIN_EMAILS_PRO($ADMIN_SUBJ, "admin_transfer_points");
224                         }
225                          else
226                         {
227                                 $msg = LOAD_EMAIL_TEMPLATE("admin_transfer_points");
228                                 SEND_ADMIN_EMAILS($ADMIN_SUBJ, $msg);
229                         }
230
231                         // Transfer is completed
232                         OUTPUT_HTML("<P>");
233                         LOAD_TEMPLATE("admin_settings_saved", false, TRANSFER_COMPLETED."<br /><A href=\"".URL."/modules.php?module=login&amp;what=transfer\">".TRANSFER_CONTINUE_OVERVIEW."</A>");
234                         OUTPUT_HTML("</P>");
235                 }
236                  elseif (!$valid_code)
237                 {
238                         // Invalid Touring code!
239                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_CODE."</STRONG></P>");
240                         unset($_POST['ok']);
241                 }
242                  elseif (!$valid_pass)
243                 {
244                         // Wrong password entered
245                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_PASSWORD."</STRONG></P>");
246                         unset($_POST['ok']);
247                 }
248                  elseif (!$valid_amount)
249                 {
250                         // Too much points entered
251                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_POINTS."</STRONG></P>");
252                         unset($_POST['ok']);
253                 }
254                  elseif (!$valid_reason)
255                 {
256                         // No transfer reason entered
257                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_REASON."</STRONG></P>");
258                         unset($_POST['ok']);
259                 }
260                  elseif (!$valid_recipient)
261                 {
262                         // No recipient selected
263                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_RECIPIENT."</STRONG></P>");
264                         unset($_POST['ok']);
265                 }
266                  elseif (!$valid_data)
267                 {
268                         // No recipient selected
269                         OUTPUT_HTML("<P><STRONG class=\"member_note\">".TRANSFER_INVALID_DATA."</STRONG></P>");
270                         unset($_POST['ok']);
271                 }
272         }
273         if (!isset($_POST['ok']))
274         {
275                 // Load member list
276                 if (EXT_IS_ACTIVE("nickname"))
277                 {
278                         // Load userid and nickname
279                         $result = SQL_QUERY_ESC("SELECT userid, nickname FROM "._MYSQL_PREFIX."_user_data WHERE status='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY userid",
280                          array($GLOBALS['userid']), __FILE__, __LINE__);
281                 }
282                  else
283                 {
284                         // Load only userid
285                         $result = SQL_QUERY_ESC("SELECT userid, userid FROM "._MYSQL_PREFIX."_user_data WHERE status='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY userid",
286                          array($GLOBALS['userid']), __FILE__, __LINE__);
287                 }
288                 if (SQL_NUMROWS($result) > 0)
289                 {
290                         // Load list
291                         $OUT  = "<SELECT name=\"to_uid\" size=\"1\" class=\"member_select\">
292   <OPTION value=\"0\">".SELECT_NONE."</OPTION>\n";
293                         while (list($uid, $nick) = SQL_FETCHROW($result))
294                         {
295                                 $OUT .= "<OPTION value=\"".$uid."\"";
296                                 if ((isset($_POST['to_uid'])) && ($_POST['to_uid'] == $uid)) $OUT .= " selected=\"selected\"";
297                                 $OUT .= ">";
298                                 if (($nick != $uid) && (!empty($nick)))
299                                 {
300                                         // Output nickname
301                                         $OUT .= $nick;
302                                 }
303                                  else
304                                 {
305                                         // Output userid
306                                         $OUT .= $uid;
307                                 }
308                                 $OUT .= "</OPTION>\n";
309                         }
310                         $OUT .= "</SELECT>\n";
311                         define('__TRANSFER_TO_DISABLED', "");
312
313                         // Free memory
314                         SQL_FREERESULT($result);
315                 }
316                  else
317                 {
318                         // No one else is opt-in
319                         $OUT = TRANSFER_NO_ONE_ELSE_OPT_IN;
320                         define('__TRANSFER_TO_DISABLED', " disabled");
321                 }
322                 // Transfer output to constant for the template
323                 define('__TRANSFER_USERID_SELECTION', $OUT);
324
325                 // Generate Code
326                 if ($_CONFIG['transfer_code'] > 0)
327                 {
328                         $rand = rand(0, 99999);
329                         $code = GEN_RANDOM_CODE($_CONFIG['transfer_code'], $rand, $GLOBALS['userid'], __TRANSFER_MAX_VALUE);
330                         $img = GENERATE_IMAGE($code, false);
331                         define('__TRANSFER_IMAGE_INPUT', "<INPUT type=\"hidden\" name=\"code_chk\" value=\"".$rand."\"><INPUT type=\"text\" name=\"code\" class=\"member_normal\" size=\"5\" maxlength=\"7\"".__TRANSFER_TO_DISABLED.">&nbsp;".$img);
332                 }
333                  else
334                 {
335                         $code = "00000";
336                         define('__TRANSFER_IMAGE_INPUT', TRANSFER_NO_CODE);
337                 }
338
339                 // Transfer maybe already entered valued'
340                 if (isset($_GET['ok'])) {
341                         // Get values from form
342                         define('__TRANSFER_POINTS_VALUE', bigintval($_POST['points']));
343                         define('__TRANSFER_REASON_VALUE', strip_tags($_POST['reason']));
344                 } else {
345                         // Set empty values
346                         define('__TRANSFER_POINTS_VALUE', "");
347                         define('__TRANSFER_REASON_VALUE', "");
348                 }
349
350                 // Output form
351                 LOAD_TEMPLATE("member_transfer_new");
352         }
353         break;
354
355 case "list_in": // List only incoming transactions
356 case "list_out": // List only outgoing transactions
357         // As you can see I put list_in and list_out together. I now do a switch() again on it for the right SQL command
358         switch ($MODE)
359         {
360         case "list_in":
361                 $SQL = "SELECT trans_id, from_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_in WHERE userid=%d ORDER BY time_trans DESC LIMIT ".$_CONFIG['transfer_max'];
362                 $NOTHING = TRANSFER_NO_INCOMING_TRANSFERS;
363                 define('__TRANSFER_SUM', TRANSFER_TOTAL_INCOMING);
364                 define('__TRANSFER_TITLE', TRANSFER_LIST_INCOMING);
365                 break;
366
367         case "list_out":
368                 $SQL = "SELECT trans_id, to_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_out WHERE userid=%d ORDER BY time_trans DESC LIMIT ".$_CONFIG['transfer_max'];
369                 $NOTHING = TRANSFER_NO_OUTGOING_TRANSFERS;
370                 define('__TRANSFER_SUM', TRANSFER_TOTAL_OUTGOING);
371                 define('__TRANSFER_TITLE', TRANSFER_LIST_OUTGOING);
372                 break;
373         }
374
375         // Run the SQL command
376         $total = "0";
377         $result = SQL_QUERY_ESC($SQL, array($GLOBALS['userid']), __FILE__, __LINE__);
378         if (SQL_NUMROWS($result) > 0)
379         {
380                 $OUT = ""; $SW = 2;
381                 while (list($tid, $uid, $points, $reason, $stamp) = SQL_FETCHROW($result))
382                 {
383                         if ($type == "OUT") $points = "$points-";
384                         $OUT .= "<TR>
385   <TD class=\"transfer_row1 switch_sw".$SW." bottom2 right2\">
386     <FONT class=\"transfer_row1\">".$tid."</FONT>
387   </TD>
388   <TD class=\"transfer_row2 switch_sw".$SW." bottom2 right2\">
389     <FONT class=\"transfer_row2\">".MAKE_DATETIME($stamp, "3")."</FONT>
390   </TD>
391   <TD class=\"transfer_row3 switch_sw".$SW." bottom2 right2\">
392     <FONT class=\"transfer_row3\">".$uid."</FONT>
393   </TD>
394   <TD class=\"transfer_row4 switch_sw".$SW." bottom2 right2\">
395     <FONT class=\"transfer_row4\">".$reason."</FONT>
396   </TD>
397   <TD class=\"transfer_row5 switch_sw".$SW." bottom2\">
398     <FONT class=\"transfer_row5\">".$points."</FONT>
399   </TD>
400 </TR>\n";
401                         $total += $points;
402                         $SW = 3 - $SW;
403                 }
404
405                 // Free memory
406                 SQL_FREERESULT($result);
407         }
408          else
409         {
410                 // Nothing for in or out
411                 $OUT = "<TR>
412   <TD colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
413     ".LOAD_TEMPLATE("admin_settings_saved", true, $NOTHING)."
414   </TD>
415 </TR>";
416         }
417
418         // ... and add them to a constant for the template
419         define('__TRANSFER_ROWS', $OUT);
420
421         // Remeber total amount
422         define('__TRANSFER_TOTAL_VALUE', $total);
423
424         // Load final template
425         LOAD_TEMPLATE("member_transfer_list");
426         break;
427
428 case "list_all": // List all transactions
429         // We fill a temporary table with data from both tables. This is much easier
430         // to code and unstand by you as sub-SELECT queries. I know this is not the
431         // fastest way but it shall be fine for now.
432         //
433         // First of all create the temporary table
434         $result = SQL_QUERY("CREATE TEMPORARY TABLE "._MYSQL_PREFIX."_transfers_tmp (
435 trans_id varchar(12) not null default '',
436 party_uid bigint(20) not null default '0',
437 points bigint(20) not null default '0',
438 reason varchar(255) not null default '',
439 time_trans varchar(10) not null default '0',
440 trans_type enum('IN', 'OUT') not null default 'IN',
441 KEY(party_uid)
442 ) TYPE=HEAP", __FILE__, __LINE__);
443
444         // Let's begin with the incoming list
445         $result = SQL_QUERY_ESC("SELECT trans_id, from_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_in WHERE userid=%d ORDER BY id LIMIT %s",
446 array($GLOBALS['userid'], $_CONFIG['transfer_max']), __FILE__, __LINE__);
447         while ($DATA = SQL_FETCHROW($result))
448         {
449                 $DATA[] = "IN";
450                 $DATA = implode("', '", $DATA);
451                 $res_temp = SQL_QUERY("INSERT INTO "._MYSQL_PREFIX."_transfers_tmp (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
452         }
453
454         // Free memory
455         SQL_FREERESULT($result);
456
457         // As the last table transfer data from outgoing table to temporary
458         $result = SQL_QUERY_ESC("SELECT trans_id, to_uid, points, reason, time_trans FROM "._MYSQL_PREFIX."_user_transfers_out WHERE userid=%d ORDER BY id LIMIT %s",
459 array($GLOBALS['userid'], $_CONFIG['transfer_max']), __FILE__, __LINE__);
460         while ($DATA = SQL_FETCHROW($result))
461         {
462                 $DATA[] = "OUT";
463                 $DATA = implode("', '", $DATA);
464                 $res_temp = SQL_QUERY("INSERT INTO "._MYSQL_PREFIX."_transfers_tmp (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
465         }
466
467         // Free memory
468         SQL_FREERESULT($result);
469
470         $total = "0";
471         if (SQL_NUMROWS($result) > 0)
472         {
473                 // Output rows
474                 $OUT = ""; $SW = 2;
475                 $result = SQL_QUERY("SELECT party_uid, trans_id, points, reason, time_trans, trans_type FROM "._MYSQL_PREFIX."_transfers_tmp ORDER BY time_trans DESC", __FILE__, __LINE__);
476                 while(list($uid, $idx, $points, $reason, $stamp, $type) = SQL_FETCHROW($result))
477                 {
478                         if ($type == "OUT") $points = "-$points";
479                         $OUT .= "<TR>
480   <TD class=\"transfer_row1 switch_sw".$SW." bottom2 right2\">
481     <FONT class=\"transfer_row1\">".$idx."</FONT>
482   </TD>
483   <TD class=\"transfer_row2 switch_sw".$SW." bottom2 right2\">
484     <FONT class=\"transfer_row2\">".MAKE_DATETIME($stamp, "3")."</FONT>
485   </TD>
486   <TD class=\"transfer_row3 switch_sw".$SW." bottom2 right2\">
487     <FONT class=\"transfer_row3\">".$uid."</FONT>
488   </TD>
489   <TD class=\"transfer_row4 switch_sw".$SW." bottom2 right2\">
490     <FONT class=\"transfer_row4\">".$reason."</FONT>
491   </TD>
492   <TD class=\"transfer_row5 switch_sw".$SW." bottom2\">
493     <FONT class=\"transfer_row5\">".$points."</FONT>
494   </TD>
495 </TR>\n";
496                         $total += $points;
497                         $SW = 3 - $SW;
498                 }
499
500                 // Free memory
501                 SQL_FREERESULT($result);
502         }
503          else
504         {
505                 // Nothing for in and out
506                 $OUT = "<TR>
507   <TD colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
508     ".LOAD_TEMPLATE("admin_settings_saved", true, TRANSFER_NO_INOUT_TRANSFERS)."
509   </TD>
510 </TR>";
511         }
512
513         // ... and add them to a constant for the template
514         define('__TRANSFER_ROWS', $OUT);
515
516         // Remeber total amount
517         define('__TRANSFER_TOTAL_VALUE', $total);
518
519         // Set title
520         define('__TRANSFER_TITLE', TRANSFER_LIST_ALL);
521
522         // Set "balance" word
523         define('__TRANSFER_SUM', TRANSFER_TOTAL_BALANCE);
524
525         // Load final template
526         LOAD_TEMPLATE("member_transfer_list");
527
528         // At the end we don't need a temporary table in memory
529         $result = SQL_QUERY("DROP TABLE IF EXISTS "._MYSQL_PREFIX."_transfers_tmp", __FILE__, __LINE__);
530
531         // Free some memory...
532         SQL_FREERESULT($result);
533         break;
534
535 case "": // Overview page
536         // Check incoming transfers
537         $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM "._MYSQL_PREFIX."_user_transfers_in WHERE userid=%d", array($GLOBALS['userid']), __FILE__, __LINE__);
538         list($dmy) = SQL_FETCHROW($result);
539         SQL_FREERESULT($result);
540
541         $total=$dmy;
542         if ($dmy > 0)
543         {
544                 define('__TRANSFER_IN_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=list_in\">".$dmy."</A>");
545         }
546          else
547         {
548                 define('__TRANSFER_IN_LINK', $dmy);
549         }
550
551         // Check outgoing transfers
552         $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM "._MYSQL_PREFIX."_user_transfers_out WHERE userid=%d", array($GLOBALS['userid']), __FILE__, __LINE__);
553         list($dmy) = SQL_FETCHROW($result);
554         SQL_FREERESULT($result);
555
556         $total+=$dmy;
557         if ($dmy > 0)
558         {
559                 define('__TRANSFER_OUT_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=list_out\">".$dmy."</A>");
560         }
561          else
562         {
563                 define('__TRANSFER_OUT_LINK', $dmy);
564         }
565
566         // Total transactions
567         if ($total > 0)
568         {
569                 define('__TRANSFER_ALL_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=list_all\">".$total."</A>");
570         }
571          else
572         {
573                 define('__TRANSFER_ALL_LINK', $total);
574         }
575
576         if (isset($_POST['ok']))
577         {
578                 // Save settings
579                 $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_user_data SET opt_in='%s' WHERE userid=%d LIMIT 1",
580                  array($_POST['opt_in'], $GLOBALS['userid']), __FILE__, __LINE__);
581
582                 // Rember for next switch() command
583                 $opt_in = $_POST['opt_in'];
584
585                 // "Settings saved..."
586                 OUTPUT_HTML("<P><STRONG class=\"member_done\">".SETTINGS_SAVED."</STRONG></P>");
587         }
588         switch ($opt_in)
589         {
590         case 'Y':
591                 define('__TRANSFER_ALLOW_Y', ' checked');
592                 define('__TRANSFER_ALLOW_N', "");
593                 define('__TRANSFER_NEW_LINK', "<A href=\"".URL."/modules.php?module=login&amp;what=transfer&amp;mode=new\">".TRANSFER_NOW_LINK."</A>");
594                 break;
595
596         case 'N':
597                 define('__TRANSFER_ALLOW_Y', "");
598                 define('__TRANSFER_ALLOW_N', ' checked');
599                 define('__TRANSFER_NEW_LINK', TRANSFER_PLEASE_ALLOW_OPT_IN);
600                 break;
601         }
602
603         // Check for latest out-transfers
604         $result = SQL_QUERY_ESC("SELECT time_trans FROM "._MYSQL_PREFIX."_user_transfers_out WHERE time_trans > ".(time() - $_CONFIG['transfer_timeout'])." AND userid=%d ORDER BY time_trans DESC LIMIT 1", array($GLOBALS['userid']), __FILE__, __LINE__);
605         if (SQL_NUMROWS($result) == 0)
606         {
607                 // Load template
608                 define('__TRANSFER_SETTINGS_CONTENT', LOAD_TEMPLATE("member_transfer_settings", true));
609         }
610          else
611         {
612                 // Load newest transaction
613                 list($newest) = SQL_FETCHROW($result);
614                 SQL_FREERESULT($result);
615                 define('__TRANSFER_SETTINGS_CONTENT', TRANSFER_LATEST_IS_1.MAKE_DATETIME($newest, "3").TRANSFER_LATEST_IS_2);
616         }
617         // Load template
618         LOAD_TEMPLATE("member_transfer_overview");
619         break;
620 }
621 //
622 ?>