Fix for missing array element 'userid', see ticket #205, thanks to piter01
[mailer.git] / inc / modules / admin / what-edit_emails.php
index bf98dad7c04761ebe40a2c9bb0805d5537b21220..fdfe3c8bc03dff42e81d8e043acbb0304ed65ac0 100644 (file)
@@ -1,7 +1,7 @@
 <?php
 /************************************************************************
- * MXChange v0.2.1                                    Start: 09/28/2003 *
- * ===============                              Last change: 04/09/2004 *
+ * Mailer v0.2.1-FINAL                                Start: 09/28/2003 *
+ * ===================                          Last change: 04/09/2004 *
  *                                                                      *
  * -------------------------------------------------------------------- *
  * File              : what-edit_emails.php                             *
  * -------------------------------------------------------------------- *
  * Kurzbeschreibung  : Werbebuchungen aendern (z.B. umleiten der URL)   *
  * -------------------------------------------------------------------- *
- *                                                                      *
+ * $Revision::                                                        $ *
+ * $Date::                                                            $ *
+ * $Tag:: 0.2.1-FINAL                                                 $ *
+ * $Author::                                                          $ *
+ * Needs to be in all Files and every File needs "svn propset           *
+ * svn:keywords Date Revision" (autoprobset!) at least!!!!!!            *
  * -------------------------------------------------------------------- *
- * Copyright (c) 2003 - 2008 by Roland Haeder                           *
+ * Copyright (c) 2003 - 2009 by Roland Haeder                           *
+ * Copyright (c) 2009, 2010 by Mailer Developer Team                    *
  * For more information visit: http://www.mxchange.org                  *
  *                                                                      *
  * This program is free software; you can redistribute it and/or modify *
  ************************************************************************/
 
 // Some security stuff...
-if ((ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) || (!IS_ADMIN()))
-{
-       $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
-       require($INC);
-}
+if ((!defined('__SECURITY')) || (!isAdmin())) {
+       die();
+} // END - if
+
 // Add description as navigation point
-ADD_DESCR("admin", basename(__FILE__));
+addYouAreHereLink('admin', __FILE__);
 
-OPEN_TABLE("100%", "admin_content admin_content_align", "");
-global $link;
+if ((isFormSent()) && (!isPostRequestParameterSet('id'))) {
+       unsetPostRequestParameter('ok');
+} // END - if
 
-if ((isset($_POST['ok'])) && (empty($_POST['id'])))
-{
-       unset($_POST['ok']);
-}
+// Query the pool
+$result = SQL_QUERY('SELECT
+       `id`, `sender` AS `userid`, `subject`, `payment_id`, `cat_id`
+FROM
+       `{?_MYSQL_PREFIX?}_pool`
+ORDER BY
+       `timestamp` ASC', __FILE__, __LINE__);
 
-$result = SQL_QUERY("SELECT id, sender, subject, payment_id, cat_id FROM "._MYSQL_PREFIX."_pool ORDER BY timestamp", __FILE__, __LINE__);
-if (SQL_NUMROWS($result) > 0)
-{
-       if (isset($_POST['ok']))
-       {
+// Entries found?
+if (!SQL_HASZERONUMS($result)) {
+       if (isFormSent()) {
                // Make mail editable...
-               $result = SQL_QUERY_ESC("SELECT subject, text, url FROM "._MYSQL_PREFIX."_pool WHERE id=%d LIMIT 1",
-                array(bigintval($_POST['id'])), __FILE__, __LINE__);
-               list($subj, $text, $url) = SQL_FETCHROW($result);
+               $result = SQL_QUERY_ESC("SELECT `id`, `sender` AS `userid`, `subject`, `text`, `url` FROM `{?_MYSQL_PREFIX?}_pool` WHERE `id`=%s LIMIT 1",
+                       array(bigintval(postRequestParameter('id'))), __FILE__, __LINE__);
+
+               // Fetch row
+               $content = SQL_FETCHARRAY($result);
+
+               // Free result
                SQL_FREERESULT($result);
-               define('__ID_VALUE'  , $_POST['id']);
-               define('__URL_VALUE' , stripslashes($url));
-               define('__SUBJ_VALUE', stripslashes($subj));
-               define('__TEXT_VALUE', stripslashes($text));
 
                // Load template
-               LOAD_TEMPLATE("admin_edit_email");
-       }
-        elseif (!empty($_POST['save']))
-       {
+               loadTemplate('admin_edit_email', false, $content);
+       } elseif (isPostRequestParameterSet('save')) {
                // Save changes
-               if (!empty($SQL))
-               {
-                       $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_pool SET
-subject='%s',
-text='%s',
-url='%s'
-WHERE id=%d LIMIT 1",
- array(
-       addslashes($_POST['subj']),
-       addslashes($_POST['text']),
-       addslashes($_POST['url']),
-       bigintval($_POST['id']),
-), __FILE__, __LINE__);
-                       if (SQL_AFFECTEDROWS($link, __FILE__, __LINE__) == 1)
-                       {
-                               $content = "<SPAN class=\"admin_done\">".SETTINGS_SAVED."</SPAN>";
-                       }
-                        else
-                       {
-                               $content = "<SPAN class=\"admin_failed\">".SETTINGS_NOT_SAVED."</SPAN>";
-                       }
-               }
-                else
-               {
-                       $content = "<SPAN class=\"admin_failed\">".SETTINGS_NOT_SAVED."</SPAN>";
+               SQL_QUERY_ESC("UPDATE
+       `{?_MYSQL_PREFIX?}_pool`
+SET
+       `subject`='%s',
+       `text`='%s',
+       `url`='%s'
+WHERE
+       `id`=%s
+LIMIT 1",
+                       array(
+                               postRequestParameter('subject'),
+                               postRequestParameter('text'),
+                               postRequestParameter('url'),
+                               bigintval(postRequestParameter('id')),
+                       ), __FILE__, __LINE__);
+
+               if (!SQL_HASZEROAFFECTED()) {
+                       $content = '{--SETTINGS_SAVED--}';
+               } else {
+                       $content = '<span class="notice">{--SETTINGS_NOT_SAVED--}</span>';
                }
 
                // Display message
-               LOAD_TEMPLATE("admin_settings_saved", false, $content);
-       }
-        else
-       {
+               loadTemplate('admin_settings_saved', false, $content);
+       } else {
                // There are mail orders available
-               $SW = 2; $OUT = "";
-               while (list($id, $sender, $subj, $pay, $cat) = SQL_FETCHROW($result))
-               {
-                       // Prepare data for the row template
-                       $content = array(
-                               'sw'   => $SW,
-                               'id'   => $id,
-                               'subj' => $subj,
-                               'uid'  => ADMIN_USER_PROFILE_LINK($sender),
-                               'pay'  => GET_PAYMENT($pay),
-                               'cat'  => GET_CATEGORY($cat),
-                       );
-
+               $OUT = '';
+               while ($content = SQL_FETCHARRAY($result)) {
                        // Load row template and switch colors
-                       $OUT .= LOAD_TEMPLATE("admin_edit_email_row", true, $content);
-                       $SW = 3 - $SW;
-               }
+                       $OUT .= loadTemplate('admin_edit_email_row', true, $content);
+               } // END - while
 
                // Free memory
                SQL_FREERESULT($result);
-               define('__EMAIL_SELECT_ROWS', $OUT);
 
                // Load email template
-               LOAD_TEMPLATE("admin_edit_email_select");
+               loadTemplate('admin_edit_email_select', false, $OUT);
        }
-}
- else
-{
+} else {
        // No mail orders left in pool
-       OUTPUT_HTML("<SPAN class=\"admin_failed\">".ADMIN_NO_MAILS_IN_POOL."</SPAN>");
+       loadTemplate('admin_settings_saved', false, '<span class="notice">{--ADMIN_NO_MAILS_IN_POOL--}</span>');
 }
-CLOSE_TABLE();
-//
+
+// [EOF]
 ?>