Fix for output to bots, 'slurp' is now detected
[mailer.git] / birthday_confirm.php
index b65d5e1b0ad23ed425a9589ba2b3d1644c3c5fb9..7e4750f2094bf6d319d51f51d664d5ebc717e83f 100644 (file)
@@ -1,18 +1,23 @@
 <?php
 /************************************************************************
- * MXChange v0.2.1                                    Start: 10/03/2004 *
- * ===============                              Last change: 10/03/2004 *
+ * Mailer v0.2.1-FINAL                                Start: 10/03/2004 *
+ * ===================                          Last change: 10/03/2004 *
  *                                                                      *
  * -------------------------------------------------------------------- *
  * File              : birthday_confirm.php                             *
  * -------------------------------------------------------------------- *
  * Short description : Birthday bonus confirmation link                 *
  * -------------------------------------------------------------------- *
- * Kurzbeschreibung  : Geburtstagsgutschrift bestaetigen                *
+ * Kurzbeschreibung  : Geburtstagsgutschrift best&auml;tigen                *
  * -------------------------------------------------------------------- *
- *                                                                      *
+ * $Revision::                                                        $ *
+ * $Date::                                                            $ *
+ * $Tag:: 0.2.1-FINAL                                                 $ *
+ * $Author::                                                          $ *
+ * Needs to be in all Files and every File needs "svn propset           *
+ * svn:keywords Date Revision" (autoprobset!) at least!!!!!!            *
  * -------------------------------------------------------------------- *
- * Copyright (c) 2003 - 2008 by Roland Haeder                           *
+ * Copyright (c) 2003 - 2009 by Roland Haeder                           *
  * For more information visit: http://www.mxchange.org                  *
  *                                                                      *
  * This program is free software; you can redistribute it and/or modify *
  * MA  02110-1301  USA                                                  *
  ************************************************************************/
 
-// Load security stuff here (Oh, I hope this is not unsecure? Am I paranoia??? ;-) )
-require_once("inc/libs/security_functions.php");
+// Load security stuff here
+require('inc/libs/security_functions.php');
 
-// Init "action" and "what"
-global $what, $action;
-$GLOBALS['what'] = ""; $GLOBALS['action'] = "";
-if (!empty($_GET['action'])) $GLOBALS['action'] = secureString($_GET['action']);
-if (!empty($_GET['what'])) $GLOBALS['what'] = secureString($_GET['what']);
+// Init start time
+$GLOBALS['startTime'] = microtime(true);
 
 // Set module
-$GLOBALS['module'] = "birthday_confirm"; $CSS = -1;
+$GLOBALS['module'] = 'birthday_confirm';
+$GLOBALS['output_mode'] = -1;
 
 // Load the required file(s)
-require ("inc/config.php");
-
-if (defined('mxchange_installed') && (mxchange_installed))
-{
-       // Script is installed so let's check for his confirmation link...
-       $uid = strip_tags(bigintval($_GET['uid']));
-
-       // Only allow numbers here...
-       $chk = strip_tags(bigintval($_GET['check']));
-
-       // .. only first 32 numbers
-       $chk = substr($chk, 0, 32);
-
-       // Check if link is not clicked so far
-       $result = SQL_QUERY_ESC("SELECT DISTINCT b.points, d.sex, d.surname, d.family, d.status
-FROM "._MYSQL_PREFIX."_user_birthday AS b
-LEFT JOIN "._MYSQL_PREFIX."_user_data AS d
-ON b.userid=d.userid
-WHERE b.userid=%d AND b.chk_value='%s' LIMIT 1",
- array($uid, $chk), __FILE__, __LINE__);
-
-       if (SQL_NUMROWS($result) == 1)
-       {
-               // Ok, congratulation again! Here's your gift from us...
-               list($GIFT, $salut, $sname, $fname, $status) = SQL_FETCHROW($result);
-               if ($status == "CONFIRMED")
-               {
-                       // Set mode depending on how many mails the member has to confirm
-                       $locked = false;
-                       if (($ref_payout > 0) && ($CONFIG['allow_direct_pay'] == 'N')) $locked = true;
-
-                       // Add points to account
-                       ADD_POINTS_REFSYSTEM($uid, $GIFT, false, "0", $locked, strtolower($CONFIG['birthday_mode']));
-
-                       // Remove entry from table
-                       $result = SQL_QUERY_ESC("DELETE LOW_PRIORITY FROM "._MYSQL_PREFIX."_user_birthday WHERE userid=%d LIMIT 1",
-                        array($uid), __FILE__, __LINE__);
-
-                       // Update mediadata if version is 0.0.4 or newer
-                       if (GET_EXT_VERSION("mediadata") >= "0.0.4")
-                       {
-                               // Update database
-                               MEDIA_UPDATE_ENTRY(array("total_points"), "add", $GIFT);
-                       }
-
-                       // Transfer data to constants for the template
-                       define('__SALUT', TRANSLATE_SEX($salut));
-                       define('__SNAME', $sname);
-                       define('__FNAME', $fname);
-                       define('__GIFT' , $GIFT);
-
-                       // Load message from template
-                       define('__MSG', LOAD_TEMPLATE("birthday_msg", true));
-               }
-                else
-               {
-                       // Unconfirmed / locked accounts cannot get points
-                       define('__MSG', BIRTHDAY_CANNOT_STATUS_1.TRANSLATE_STATUS($status).BIRTHDAY_CANNOT_STATUS_2);
-               }
-       }
-        else
-       {
-               // Cannot load data!
-               define('__MSG', BIRTHDAY_CANNOT_LOAD_DATA);
+require('inc/config-global.php');
+
+// Set content type
+setContentType('text/html');
+
+// Is the 'birthday' extension active?
+redirectOnUninstalledExtension('birthday');
+
+// Script is installed so let's check for his confirmation link...
+$userid = bigintval(getRequestElement('userid'));
+
+// Only allow numbers here...
+$chk = bigintval(getRequestElement('check'), false);
+
+// Check if link is not clicked so far
+$result = SQL_QUERY_ESC("SELECT b.points, d.gender, d.surname, d.family, d.status, d.ref_payout
+FROM
+       `{?_MYSQL_PREFIX?}_user_birthday` AS b
+INNER JOIN
+       `{?_MYSQL_PREFIX?}_user_data` AS d
+ON
+       b.userid=d.userid
+WHERE
+       b.userid=%s AND b.chk_value='%s'
+LIMIT 1",
+       array($userid, $chk), __FILE__, __LINE__);
+//* DEBUG: */ outputHtml("userid=".$userid.",chk=".$chk." (".strlen($chk).'/'.strlen(getRequestElement('check')).'/'.SQL_NUMROWS($result).")<br />");
+
+// Prepare content
+$content = array();
+
+// Is an entry there?
+if (SQL_NUMROWS($result) == 1) {
+       // Ok, congratulation again! Here's your gift from us...
+       $data = SQL_FETCHARRAY($result, false);
+
+       // Is the account confirmed?
+       if ($data['status'] == 'CONFIRMED') {
+               // Set mode depending on how many mails the member has to confirm
+               $locked = false;
+               if (($data['ref_payout'] > 0) && (getConfig('allow_direct_pay') != 'Y')) $locked = true;
+
+               // Add points to account
+               // @TODO Try to rewrite the following unset()
+               unset($GLOBALS['ref_level']);
+               addPointsThroughReferalSystem('birthday_confirm', $userid, $data['points'], false, 0, $locked, strtolower(getConfig('birthday_mode')));
+
+               // Remove entry from table
+               SQL_QUERY_ESC("DELETE LOW_PRIORITY FROM `{?_MYSQL_PREFIX?}_user_birthday` WHERE `userid`=%s AND `chk_value`='%s' LIMIT 1",
+                       array($userid, $chk), __FILE__, __LINE__);
+
+               // "Translate" some data
+               $data['gender'] = translateGender($data['gender']);
+               $data['points'] = translateComma($data['points']);
+
+               // Load message from template
+               $content['message'] = loadTemplate('birthday_msg', true, $data);
+       } else {
+               // Unconfirmed / locked accounts cannot get points
+               $content['message'] = sprintf(getMessage('BIRTHDAY_CANNOT_STATUS'), translateUserStatus($data['status']));
        }
+} else {
+       // Cannot load data!
+       $content['message'] = getMessage('BIRTHDAY_CANNOT_LOAD_DATA');
+}
 
-       // Free memory
-       SQL_FREERESULT($result);
+// Free memory
+SQL_FREERESULT($result);
 
-       // Set this because we have no module in URI
-       $GLOBALS['module'] = "birthday_confirm";
+// Set this because we have no module in URI
+$GLOBALS['module'] = 'birthday_confirm';
 
-       // Include header
-       include(PATH."inc/header.php");
+// Include header
+loadIncludeOnce('inc/header.php');
 
-       // Load birthday header template (for your banners, e.g.?)
-       define('__BIRTHDAY_HEADER', LOAD_TEMPLATE("birthday_header", true));
+// Load birthday header template (for your banners, e.g.?)
+$content['header'] =  loadTemplate('birthday_header', true);
 
-       // Load birthday footer template (for your banners, e.g.?)
-       define('__BIRTHDAY_FOOTER', LOAD_TEMPLATE("birthday_footer", true));
+// Load birthday footer template (for your banners, e.g.?)
+$content['footer'] =  loadTemplate('birthday_footer', true);
 
-       // Load final template and output it
-       LOAD_TEMPLATE("birthday_confirm");
+// Load final template and output it
+loadTemplate('birthday_confirm', false, $content);
 
-       // Include footer
-       include(PATH."inc/footer.php");
-}
- else
-{
-       // You have to configure first!
-       LOAD_URL(URL."/install.php");
-}
-// Really all done here... ;-)
+// Include footer
+loadIncludeOnce('inc/footer.php');
+
+// [EOF]
 ?>