More constant rewrites
[mailer.git] / inc / modules / member / what-transfer.php
1 <?php
2 /************************************************************************
3  * MXChange v0.2.1                                    Start: 10/07/2004 *
4  * ================                             Last change: 10/07/2004 *
5  *                                                                      *
6  * -------------------------------------------------------------------- *
7  * File              : what-transfer.php                                *
8  * -------------------------------------------------------------------- *
9  * Short description : Point transfers                                  *
10  * -------------------------------------------------------------------- *
11  * Kurzbeschreibung  : Punktetransfers                                  *
12  * -------------------------------------------------------------------- *
13  *                                                                      *
14  * -------------------------------------------------------------------- *
15  * Copyright (c) 2003 - 2008 by Roland Haeder                           *
16  * For more information visit: http://www.mxchange.org                  *
17  *                                                                      *
18  * This program is free software; you can redistribute it and/or modify *
19  * it under the terms of the GNU General Public License as published by *
20  * the Free Software Foundation; either version 2 of the License, or    *
21  * (at your option) any later version.                                  *
22  *                                                                      *
23  * This program is distributed in the hope that it will be useful,      *
24  * but WITHOUT ANY WARRANTY; without even the implied warranty of       *
25  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the        *
26  * GNU General Public License for more details.                         *
27  *                                                                      *
28  * You should have received a copy of the GNU General Public License    *
29  * along with this program; if not, write to the Free Software          *
30  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston,               *
31  * MA  02110-1301  USA                                                  *
32  ************************************************************************/
33
34 // Some security stuff...
35 if (!defined('__SECURITY')) {
36         $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
37         require($INC);
38 } elseif (!IS_MEMBER()) {
39         LOAD_URL("modules.php?module=index");
40 } elseif ((!EXT_IS_ACTIVE("transfer")) && (!IS_ADMIN())) {
41         addFatalMessage(__FILE__, __LINE__, getMessage('EXTENSION_PROBLEM_EXT_INACTIVE'), "transfer");
42         return;
43 }
44
45 // Add description as navigation point
46 ADD_DESCR("member", __FILE__);
47
48 // Load data
49 $result = SQL_QUERY_ESC("SELECT opt_in FROM `{!_MYSQL_PREFIX!}_user_data` WHERE userid=%s LIMIT 1",
50         array($GLOBALS['userid']), __FILE__, __LINE__);
51 list($opt_in) = SQL_FETCHROW($result);
52
53 // Free memory
54 SQL_FREERESULT($result);
55
56 $MODE = "";
57 if (REQUEST_ISSET_GET(('mode'))) $MODE = REQUEST_GET('mode');
58
59 // Check for "faker"
60 if (($opt_in == "N") && ($MODE == "new")) $MODE = "";
61
62 switch ($MODE)
63 {
64 case "new": // Start new transfer
65         // Get total points and subtract the balance amount from it = maximum transferable points
66         $total = GET_TOTAL_DATA($GLOBALS['userid'], "user_points", "points")  - GET_TOTAL_DATA($GLOBALS['userid'], "user_data", "used_points");
67
68         // Remember maximum value for template
69         define('__TRANSFER_MAX_VALUE', round($total - getConfig('transfer_balance') - 0.5));
70
71         if (IS_FORM_SENT()) {
72                 // Add new transfer
73                 if (getConfig('transfer_code') > 0) {
74                         // Check for code
75                         $code = generateRandomCodde(getConfig('transfer_code'), REQUEST_POST('code_chk'), $GLOBALS['userid'], constant('__TRANSFER_MAX_VALUE'));
76                         $valid_code = ($code == REQUEST_POST('code'));
77                 } else {
78                         // Zero length (= disabled) is always valid!
79                         $valid_code = true;
80                 }
81
82                 // Test password
83                 $valid_pass = ($pass == generateHash(REQUEST_POST('password'), $pass));
84
85                 // Test transfer amount
86                 $valid_amount = ((REQUEST_ISSET_POST(('points'))) && (REQUEST_POST('points') <= constant('__TRANSFER_MAX_VALUE')));
87
88                 // Test reason for transfer
89                 $valid_reason = (REQUEST_ISSET_POST(('reason')));
90
91                 // Test if a recipient is selected
92                 $valid_recipient = (REQUEST_POST('to_uid') > 0);
93
94                 // Check for nickname extension and set additional data
95                 $nick = false; $ADD = ", userid";
96                 if (EXT_IS_ACTIVE("nickname")) {
97                         $ADD = ", nickname";
98                         $nick = true;
99                 }
100
101                 // Re-check receivers and own personal data
102                 $result = SQL_QUERY_ESC("SELECT userid, gender, surname, family, email".$ADD." FROM `{!_MYSQL_PREFIX!}_user_data` WHERE userid IN ('%s','%s') AND `status`='CONFIRMED' ORDER BY userid LIMIT 2",
103                         array($GLOBALS['userid'], bigintval(REQUEST_POST('to_uid'))), __FILE__, __LINE__);
104                 $valid_data = (SQL_NUMROWS($result) == 2);
105
106                 if ($valid_code && $valid_pass && $valid_amount && $valid_reason && $valid_recipient) {
107                         // Let's start the transfer and load user data
108                         list($uid1, $gender1, $sname1, $fname1, $email1, $nick1) = SQL_FETCHROW($result);
109                         list($uid2, $gender2, $sname2, $fname2, $email2, $nick2) = SQL_FETCHROW($result);
110                         SQL_FREERESULT($result);
111                         // @TODO Rewrite all these constants to array elements
112                         if ($uid1 == $GLOBALS['userid']) {
113                                 // Data row 1 is sender's data
114                                 define('__SENDER_GENDER'   , TRANSLATE_GENDER($gender1));
115                                 define('__SENDER_NICK'     , $nick1);
116                                 define('__SENDER_SNAME'    , $sname1);
117                                 define('__SENDER_FNAME'    , $fname1);
118                                 define('__SENDER_EMAIL'    , $email1);
119                                 // Data row 2 is recpient's data
120                                 define('__RECIPIENT_GENDER', TRANSLATE_GENDER($gender2));
121                                 define('__RECIPIENT_NICK'  , $nick2);
122                                 define('__RECIPIENT_SNAME' , $sname2);
123                                 define('__RECIPIENT_FNAME' , $fname2);
124                                 define('__RECIPIENT_EMAIL' , $email2);
125
126                                 // Prepare variables for testing
127                                 $TEST_NICK_SENDER = $nick1;
128                                 $TEST_NICK_REC = $nick2;
129                         } else {
130                                 // Data row 2 is sender's data
131                                 define('__SENDER_GENDER'   , TRANSLATE_GENDER($gender2));
132                                 define('__SENDER_NICK'     , $nick2);
133                                 define('__SENDER_SNAME'    , $sname2);
134                                 define('__SENDER_FNAME'    , $fname2);
135                                 define('__SENDER_EMAIL'    , $email2);
136                                 // Data row 1 is recpient's data
137                                 define('__RECIPIENT_GENDER', TRANSLATE_GENDER($gender1));
138                                 define('__RECIPIENT_NICK'  , $nick1);
139                                 define('__RECIPIENT_SNAME' , $sname1);
140                                 define('__RECIPIENT_FNAME' , $fname1);
141                                 define('__RECIPIENT_EMAIL' , $email1);
142
143                                 // Prepare variables for testing
144                                 $TEST_NICK_SENDER = $nick2;
145                                 $TEST_NICK_REC = $nick1;
146                         }
147
148                         // Sender's UID is always currently stored in cookie userid...
149                         define('__SENDER_UID'     , $GLOBALS['userid']);
150                         define('__RECIPIENT_UID'  , REQUEST_POST('to_uid'));
151
152                         $SENDER = constant('__SENDER_UID');
153                         $RECIPIENT = constant('__RECIPIENT_UID');
154                         if ($nick) {
155                                 if (($TEST_NICK_SENDER != constant('__SENDER_UID')) && (!empty($TEST_NICK_SENDER))) {
156                                         $SENDER = constant('__SENDER_NICK');
157                                 }
158
159                                 if (($TEST_NICK_REC != constant('__RECIPIENT_UID')) && (!empty($TEST_NICK_REC))) {
160                                         $RECIPIENT = constant('__RECIPIENT_NICK');
161                                 }
162                         }
163
164                         // Remember transfer reason and fancy date/time in constants
165                         define('__TRANSFER_REASON', REQUEST_POST('reason'));
166                         define('__TRANSFER_EXPIRES', CREATE_FANCY_TIME(getConfig('transfer_age')));
167
168                         // Generate tranafer id
169                         define('__TRANS_ID', bigintval(generateRandomCodde("10", mt_rand(0, 99999), $GLOBALS['userid'], REQUEST_POST('reason'))));
170
171                         // Add entries to both tables
172                         SQL_QUERY_ESC("INSERT INTO `{!_MYSQL_PREFIX!}_user_transfers_in` (userid, from_uid, points, reason, time_trans, trans_id) VALUES ('%s','%s','%s','%s', UNIX_TIMESTAMP(),'%s')",
173                                 array(bigintval(REQUEST_POST('to_uid')), $GLOBALS['userid'], bigintval(REQUEST_POST('points')), REQUEST_POST('reason'), __TRANS_ID),
174                                 __FILE__, __LINE__);
175                         SQL_QUERY_ESC("INSERT INTO `{!_MYSQL_PREFIX!}_user_transfers_out` (userid, to_uid, points, reason, time_trans, trans_id) VALUES ('%s','%s','%s','%s', UNIX_TIMESTAMP(),'%s')",
176                                 array($GLOBALS['userid'], bigintval(REQUEST_POST('to_uid')), bigintval(REQUEST_POST('points')), REQUEST_POST('reason'), __TRANS_ID),
177                                 __FILE__, __LINE__);
178
179                         // Add points to account *directly* ...
180                         ADD_POINTS_REFSYSTEM("member_transfer", bigintval(REQUEST_POST('to_uid')), bigintval(REQUEST_POST('points')), false, "0", false, "direct");
181
182                         // ... and add it to current user's used points
183                         SUB_POINTS("transfer", $GLOBALS['userid'], REQUEST_POST('points'));
184
185                         // First send email to recipient
186                         $msg = LOAD_EMAIL_TEMPLATE("member_transfer_recipient", "", constant('__RECIPIENT_UID'));
187                         SEND_EMAIL(constant('__RECIPIENT_EMAIL'), getMessage('TRANSFER_MEMBER_RECIPIENT_SUBJ').": ".$SENDER, $msg);
188
189                         // Second send email to sender
190                         $msg = LOAD_EMAIL_TEMPLATE("member_transfer_sender", "", constant('__SENDER_UID'));
191                         SEND_EMAIL(constant('__SENDER_EMAIL'), getMessage('TRANSFER_MEMBER_SENDER_SUBJ').": ".$RECIPIENT, $msg);
192
193                         // At last send admin mail(s)
194                         $ADMIN_SUBJ = sprintf("%s (%s->%s)", getMessage('TRANSFER_ADMIN_SUBJECT'), $SENDER, $RECIPIENT);
195                         SEND_ADMIN_NOTIFICATION($ADMIN_SUBJ, "admin_transfer_points");
196
197                         // Transfer is completed
198                         LOAD_TEMPLATE("admin_settings_saved", false, getMessage('TRANSFER_COMPLETED')."<br /><a href=\"{!URL!}/modules.php?module=login&amp;what=transfer\">{--TRANSFER_CONTINUE_OVERVIEW--}</a>");
199                 } elseif (!$valid_code) {
200                         // Invalid Touring code!
201                         LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"member_note\">{--TRANSFER_INVALID_CODE--}</div>");
202                         REQUEST_UNSET_POST('ok');
203                 } elseif (!$valid_pass) {
204                         // Wrong password entered
205                         LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"member_note\">{--TRANSFER_INVALID_PASSWORD--}</div>");
206                         REQUEST_UNSET_POST('ok');
207                 } elseif (!$valid_amount) {
208                         // Too much points entered
209                         LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"member_note\">{--TRANSFER_INVALID_POINTS--}</div>");
210                         REQUEST_UNSET_POST('ok');
211                 } elseif (!$valid_reason) {
212                         // No transfer reason entered
213                         LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"member_note\">{--TRANSFER_INVALID_REASON--}</div>");
214                         REQUEST_UNSET_POST('ok');
215                 } elseif (!$valid_recipient) {
216                         // No recipient selected
217                         LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"member_note\">{--TRANSFER_INVALID_RECIPIENT--}</div>");
218                         REQUEST_UNSET_POST('ok');
219                 } elseif (!$valid_data) {
220                         // No recipient selected
221                         LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"member_note\">{--TRANSFER_INVALID_DATA--}</div>");
222                         REQUEST_UNSET_POST('ok');
223                 }
224         }
225
226         if (!IS_FORM_SENT()) {
227                 // Load member list
228                 if (EXT_IS_ACTIVE("nickname")) {
229                         // Load userid and nickname
230                         $result = SQL_QUERY_ESC("SELECT userid, nickname FROM `{!_MYSQL_PREFIX!}_user_data` WHERE `status`='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY userid",
231                          array($GLOBALS['userid']), __FILE__, __LINE__);
232                 } else {
233                         // Load only userid
234                         $result = SQL_QUERY_ESC("SELECT userid, userid FROM `{!_MYSQL_PREFIX!}_user_data` WHERE `status`='CONFIRMED' AND opt_in='Y' AND userid != '%s' ORDER BY userid",
235                          array($GLOBALS['userid']), __FILE__, __LINE__);
236                 }
237
238                 if (SQL_NUMROWS($result) > 0) {
239                         // Load list
240                         $OUT  = "<select name=\"to_uid\" size=\"1\" class=\"member_select\">
241   <option value=\"0\">".SELECT_NONE."</option>\n";
242                         while (list($uid, $nick) = SQL_FETCHROW($result)) {
243                                 $OUT .= "<option value=\"".$uid."\"";
244                                 if ((REQUEST_ISSET_POST(('to_uid'))) && (REQUEST_POST('to_uid') == $uid)) $OUT .= " selected=\"selected\"";
245                                 $OUT .= ">";
246                                 if (($nick != $uid) && (!empty($nick))) {
247                                         // Output nickname
248                                         $OUT .= $nick;
249                                 } else {
250                                         // Output userid
251                                         $OUT .= $uid;
252                                 }
253                                 $OUT .= "</option>\n";
254                         }
255                         $OUT .= "</select>\n";
256                         define('__TRANSFER_TO_DISABLED', "");
257
258                         // Free memory
259                         SQL_FREERESULT($result);
260                 } else {
261                         // No one else is opt-in
262                         $OUT = getMessage('TRANSFER_NO_ONE_ELSE_OPT_IN');
263                         define('__TRANSFER_TO_DISABLED', " disabled");
264                 }
265
266                 // Transfer output to constant for the template
267                 define('__TRANSFER_USERID_SELECTION', $OUT);
268
269                 // Generate Code
270                 if (getConfig('transfer_code') > 0) {
271                         $rand = mt_rand(0, 99999);
272                         $code = generateRandomCodde(getConfig('transfer_code'), $rand, $GLOBALS['userid'], constant('__TRANSFER_MAX_VALUE'));
273                         $img = GENERATE_IMAGE($code, false);
274                         define('__TRANSFER_IMAGE_INPUT', "<input type=\"hidden\" name=\"code_chk\" value=\"".$rand."\" /><input type=\"text\" name=\"code\" class=\"member_normal\" size=\"5\" maxlength=\"7\"{!__TRANSFER_TO_DISABLED!} />&nbsp;".$img);
275                 } else {
276                         $code = "00000";
277                         define('__TRANSFER_IMAGE_INPUT', getMessage('TRANSFER_NO_CODE'));
278                 }
279
280                 // Transfer maybe already entered valued'
281                 if (REQUEST_ISSET_GET('ok')) {
282                         // Get values from form
283                         define('__TRANSFER_POINTS_VALUE', bigintval(REQUEST_POST('points')));
284                         define('__TRANSFER_REASON_VALUE', strip_tags(REQUEST_POST('reason')));
285                 } else {
286                         // Set empty values
287                         define('__TRANSFER_POINTS_VALUE', "");
288                         define('__TRANSFER_REASON_VALUE', "");
289                 }
290
291                 // Output form
292                 LOAD_TEMPLATE("member_transfer_new");
293         }
294         break;
295
296 case "list_in": // List only incoming transactions
297 case "list_out": // List only outgoing transactions
298         // As you can see I put list_in and list_out together. I now do a switch() again on it for the right SQL command
299         switch ($MODE)
300         {
301         case "list_in":
302                 $sql = "SELECT trans_id, from_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_in` WHERE userid=%s ORDER BY time_trans DESC LIMIT ".getConfig('transfer_max');
303                 $NOTHING = getMessage('TRANSFER_NO_INCOMING_TRANSFERS');
304                 define('__TRANSFER_SUM', getMessage('TRANSFER_TOTAL_INCOMING'));
305                 define('__TRANSFER_TITLE', getMessage('TRANSFER_LIST_INCOMING'));
306                 break;
307
308         case "list_out":
309                 $sql = "SELECT trans_id, to_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_out` WHERE userid=%s ORDER BY time_trans DESC LIMIT ".getConfig('transfer_max');
310                 $NOTHING = getMessage('TRANSFER_NO_OUTGOING_TRANSFERS');
311                 define('__TRANSFER_SUM', getMessage('TRANSFER_TOTAL_OUTGOING'));
312                 define('__TRANSFER_TITLE', getMessage('TRANSFER_LIST_OUTGOING'));
313                 break;
314         }
315
316         // Run the SQL command
317         $total = 0;
318         $result = SQL_QUERY_ESC($sql, array($GLOBALS['userid']), __FILE__, __LINE__);
319         if (SQL_NUMROWS($result) > 0) {
320                 $OUT = ""; $SW = 2;
321                 while (list($tid, $uid, $points, $reason, $stamp) = SQL_FETCHROW($result)) {
322                         if ($type == "OUT") $points = "$points-";
323                         $OUT .= "<tr>
324   <td class=\"transfer_row1 switch_sw".$SW." bottom2 right2\">
325     <div class=\"transfer_row1\">".$tid."</div>
326   </td>
327   <td class=\"transfer_row2 switch_sw".$SW." bottom2 right2\">
328     <div class=\"transfer_row2\">".MAKE_DATETIME($stamp, "3")."</div>
329   </td>
330   <td class=\"transfer_row3 switch_sw".$SW." bottom2 right2\">
331     <div class=\"transfer_row3\">".$uid."</div>
332   </td>
333   <td class=\"transfer_row4 switch_sw".$SW." bottom2 right2\">
334     <div class=\"transfer_row4\">".$reason."</div>
335   </td>
336   <td class=\"transfer_row5 switch_sw".$SW." bottom2\">
337     <div class=\"transfer_row5\">".$points."</div>
338   </td>
339 </tr>\n";
340                         $total += $points;
341                         $SW = 3 - $SW;
342                 }
343
344                 // Free memory
345                 SQL_FREERESULT($result);
346         } else {
347                 // Nothing for in or out
348                 $OUT = "<tr>
349   <td colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
350     ".LOAD_TEMPLATE("admin_settings_saved", true, $NOTHING)."
351   </td>
352 </tr>";
353         }
354
355         // ... and add them to a constant for the template
356         define('__TRANSFER_ROWS', $OUT);
357
358         // Remeber total amount
359         define('__TRANSFER_TOTAL_VALUE', $total);
360
361         // Load final template
362         LOAD_TEMPLATE("member_transfer_list");
363         break;
364
365 case "list_all": // List all transactions
366         // We fill a temporary table with data from both tables. This is much easier
367         // to code and unstand by you as sub-SELECT queries. I know this is not the
368         // fastest way but it shall be fine for now.
369         //
370         // First of all create the temporary table
371         $result = SQL_QUERY("CREATE TEMPORARY TABLE `{!_MYSQL_PREFIX!}_transfers_tmp` (
372 trans_id VARCHAR(12) NOT NULL DEFAULT '',
373 party_uid BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
374 points BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
375 reason VARCHAR(255) NOT NULL DEFAULT '',
376 time_trans VARCHAR(10) NOT NULL DEFAULT '0',
377 trans_type ENUM('IN','OUT') NOT NULL DEFAULT 'IN',
378 KEY(party_uid)
379 ) TYPE=HEAP", __FILE__, __LINE__);
380
381         // Let's begin with the incoming list
382         $result = SQL_QUERY_ESC("SELECT trans_id, from_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_in` WHERE userid=%s ORDER BY `id` LIMIT %s",
383 array($GLOBALS['userid'], getConfig('transfer_max')), __FILE__, __LINE__);
384         while ($DATA = SQL_FETCHROW($result)) {
385                 $DATA[] = "IN";
386                 $DATA = implode("','", $DATA);
387                 $res_temp = SQL_QUERY("INSERT INTO `{!_MYSQL_PREFIX!}_transfers_tmp` (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
388         }
389
390         // Free memory
391         SQL_FREERESULT($result);
392
393         // As the last table transfer data from outgoing table to temporary
394         $result = SQL_QUERY_ESC("SELECT trans_id, to_uid, points, reason, time_trans FROM `{!_MYSQL_PREFIX!}_user_transfers_out` WHERE userid=%s ORDER BY `id` LIMIT %s",
395 array($GLOBALS['userid'], getConfig('transfer_max')), __FILE__, __LINE__);
396         while ($DATA = SQL_FETCHROW($result)) {
397                 $DATA[] = "OUT";
398                 $DATA = implode("','", $DATA);
399                 $res_temp = SQL_QUERY("INSERT INTO `{!_MYSQL_PREFIX!}_transfers_tmp` (trans_id, party_uid, points, reason, time_trans, trans_type) VALUES ('".$DATA."')", __FILE__, __LINE__);
400         }
401
402         // Free memory
403         SQL_FREERESULT($result);
404
405         $total = 0;
406         if (SQL_NUMROWS($result) > 0) {
407                 // Output rows
408                 $OUT = ""; $SW = 2;
409                 $result = SQL_QUERY("SELECT party_uid, trans_id, points, reason, time_trans, trans_type FROM `{!_MYSQL_PREFIX!}_transfers_tmp` ORDER BY time_trans DESC", __FILE__, __LINE__);
410                 while (list($uid, $idx, $points, $reason, $stamp, $type) = SQL_FETCHROW($result)) {
411                         if ($type == "OUT") $points = "-$points";
412                         $OUT .= "<tr>
413   <td class=\"transfer_row1 switch_sw".$SW." bottom2 right2\">
414     <div class=\"transfer_row1\">".$idx."</div>
415   </td>
416   <td class=\"transfer_row2 switch_sw".$SW." bottom2 right2\">
417     <div class=\"transfer_row2\">".MAKE_DATETIME($stamp, "3")."</div>
418   </td>
419   <td class=\"transfer_row3 switch_sw".$SW." bottom2 right2\">
420     <div class=\"transfer_row3\">".$uid."</div>
421   </td>
422   <td class=\"transfer_row4 switch_sw".$SW." bottom2 right2\">
423     <div class=\"transfer_row4\">".$reason."</div>
424   </td>
425   <td class=\"transfer_row5 switch_sw".$SW." bottom2\">
426     <div class=\"transfer_row5\">".$points."</div>
427   </td>
428 </tr>\n";
429                         $total += $points;
430                         $SW = 3 - $SW;
431                 }
432
433                 // Free memory
434                 SQL_FREERESULT($result);
435         } else {
436                 // Nothing for in and out
437                 $OUT = "<tr>
438   <td colspan=\"5\" align=\"center\" class=\"bottom2\" height=\"70\">
439     ".LOAD_TEMPLATE("admin_settings_saved", true, getMessage('TRANSFER_NO_INOUT_TRANSFERS'))."
440   </td>
441 </tr>";
442         }
443
444         // ... and add them to a constant for the template
445         define('__TRANSFER_ROWS', $OUT);
446
447         // Remeber total amount
448         define('__TRANSFER_TOTAL_VALUE', $total);
449
450         // Set title
451         define('__TRANSFER_TITLE', getMessage('TRANSFER_LIST_ALL'));
452
453         // Set "balance" word
454         define('__TRANSFER_SUM', getMessage('TRANSFER_TOTAL_BALANCE'));
455
456         // Load final template
457         LOAD_TEMPLATE("member_transfer_list");
458
459         // At the end we don't need a temporary table in memory
460         $result = SQL_QUERY("DROP TABLE IF EXISTS `{!_MYSQL_PREFIX!}_transfers_tmp`", __FILE__, __LINE__);
461
462         // Free some memory...
463         SQL_FREERESULT($result);
464         break;
465
466 case "": // Overview page
467         // Check incoming transfers
468         $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM `{!_MYSQL_PREFIX!}_user_transfers_in` WHERE userid=%s", array($GLOBALS['userid']), __FILE__, __LINE__);
469         list($dmy) = SQL_FETCHROW($result);
470         SQL_FREERESULT($result);
471
472         $total=$dmy;
473         if ($dmy > 0) {
474                 define('__TRANSFER_IN_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=list_in\">".$dmy."</a>");
475         } else {
476                 define('__TRANSFER_IN_LINK', $dmy);
477         }
478
479         // Check outgoing transfers
480         $result = SQL_QUERY_ESC("SELECT COUNT(id) FROM `{!_MYSQL_PREFIX!}_user_transfers_out` WHERE userid=%s", array($GLOBALS['userid']), __FILE__, __LINE__);
481         list($dmy) = SQL_FETCHROW($result);
482         SQL_FREERESULT($result);
483
484         $total+=$dmy;
485         if ($dmy > 0) {
486                 define('__TRANSFER_OUT_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=list_out\">".$dmy."</a>");
487         } else {
488                 define('__TRANSFER_OUT_LINK', $dmy);
489         }
490
491         // Total transactions
492         if ($total > 0) {
493                 define('__TRANSFER_ALL_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=list_all\">".$total."</a>");
494         } else {
495                 define('__TRANSFER_ALL_LINK', $total);
496         }
497
498         if (IS_FORM_SENT()) {
499                 // Save settings
500                 SQL_QUERY_ESC("UPDATE `{!_MYSQL_PREFIX!}_user_data` SET opt_in='%s' WHERE userid=%s LIMIT 1",
501                         array(REQUEST_POST('opt_in'), $GLOBALS['userid']), __FILE__, __LINE__);
502
503                 // Rember for next switch() command
504                 $opt_in = REQUEST_POST('opt_in');
505
506                 // "Settings saved..."
507                 LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"member_done\">{--SETTINGS_SAVED--}</div>");
508         }
509
510         switch ($opt_in)
511         {
512         case "Y":
513                 define('__TRANSFER_ALLOW_Y', " checked=\"checked\"");
514                 define('__TRANSFER_ALLOW_N', "");
515                 define('__TRANSFER_NEW_LINK', "<a href=\"{!URL!}/modules.php?module=login&amp;what=transfer&amp;mode=new\">{--TRANSFER_NOW_LINK--}</a>");
516                 break;
517
518         case "N":
519                 define('__TRANSFER_ALLOW_Y', "");
520                 define('__TRANSFER_ALLOW_N', " checked=\"checked\"");
521                 define('__TRANSFER_NEW_LINK', getMessage('TRANSFER_PLEASE_ALLOW_OPT_IN'));
522                 break;
523         }
524
525         // Check for latest out-transfers
526         $result = SQL_QUERY_ESC("SELECT time_trans
527 FROM `{!_MYSQL_PREFIX!}_user_transfers_out`
528 WHERE time_trans > (UNIX_TIMESTAMP() - %s) AND userid=%s
529 ORDER BY time_trans DESC
530 LIMIT 1", array(getConfig('transfer_timeout'), $GLOBALS['userid']), __FILE__, __LINE__);
531         if (SQL_NUMROWS($result) == 0) {
532                 // Load template
533                 define('__TRANSFER_SETTINGS_CONTENT', LOAD_TEMPLATE("member_transfer_settings", true));
534         } else {
535                 // Load newest transaction
536                 list($newest) = SQL_FETCHROW($result);
537                 SQL_FREERESULT($result);
538                 define('__TRANSFER_SETTINGS_CONTENT', sprintf(getMessage('TRANSFER_LATEST_IS'), MAKE_DATETIME($newest, "3")));
539         }
540
541         // Load template
542         LOAD_TEMPLATE("member_transfer_overview");
543         break;
544 }
545 //
546 ?>