]> git.mxchange.org Git - mailer.git/blobdiff - inc/modules/admin/what-list_sponsor_pay.php
Security line in all includes changed
[mailer.git] / inc / modules / admin / what-list_sponsor_pay.php
index 587fc0580522e824dbeaf5c8c048ba0186f93819..884cb24adb2d99744d0804ec5cf91b0beaf41480 100644 (file)
@@ -1,7 +1,7 @@
 <?php
 /************************************************************************
- * MXChange v0.2.1                                    Start: 06/10/2005 *
- * ===============                              Last change: 05/18/2008 *
+ * M-XChange v0.2.1                                   Start: 06/10/2005 *
+ * ================                             Last change: 05/19/2008 *
  *                                                                      *
  * -------------------------------------------------------------------- *
  * File              : what-list_sponsor_pay.php                        *
@@ -31,8 +31,7 @@
  ************************************************************************/
 
 // Some security stuff...
-if ((ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) || (!is_admin()))
-{
+if ((!defined('__SECURITY')) || (!is_admin())) {
        $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4)."/security.php";
        require($INC);
 }
@@ -41,49 +40,39 @@ if ((ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) || (!is_admin()))
 ADD_DESCR("admin", basename(__FILE__));
 $MSG = "";
 
-if (isset($HTTP_POST_VARS['add']))
-{
+if (isset($_POST['add'])) {
        // Check input variables
-       if (empty($HTTP_POST_VARS['pay_name'])) unset($HTTP_POST_VARS['add']);
-       if ((round($HTTP_POST_VARS['pay_rate']) == 0) || (empty($HTTP_POST_VARS['pay_rate']))) unset($HTTP_POST_VARS['add']);
-       $HTTP_POST_VARS['pay_min_count'] = bigintval($HTTP_POST_VARS['pay_min_count']);
-       if (($HTTP_POST_VARS['pay_min_count'] == 0) || (empty($HTTP_POST_VARS['pay_min_count']))) unset($HTTP_POST_VARS['add']);
-       if (empty($HTTP_POST_VARS['pay_currency'])) unset($HTTP_POST_VARS['add']);
-}
- elseif ((isset($HTTP_POST_VARS['edit'])) || (isset($HTTP_POST_VARS['del'])) || (isset($HTTP_POST_VARS['change'])) || (isset($HTTP_POST_VARS['remove'])))
-{
+       if (empty($_POST['pay_name'])) unset($_POST['add']);
+       if ((round($_POST['pay_rate']) == 0) || (empty($_POST['pay_rate']))) unset($_POST['add']);
+       $_POST['pay_min_count'] = bigintval($_POST['pay_min_count']);
+       if (($_POST['pay_min_count'] == 0) || (empty($_POST['pay_min_count']))) unset($_POST['add']);
+       if (empty($_POST['pay_currency'])) unset($_POST['add']);
+} elseif ((isset($_POST['edit'])) || (isset($_POST['del'])) || (isset($_POST['change'])) || (isset($_POST['remove']))) {
        // Check if at least one entry was selected
-       if (empty($HTTP_POST_VARS['id']))
-       {
+       if (empty($_POST['id'])) {
                // Nothing selected for editing / deleting???
-               unset($HTTP_POST_VARS['edit']);
-               unset($HTTP_POST_VARS['del']);
-               unset($HTTP_POST_VARS['change']);
-               unset($HTTP_POST_VARS['remove']);
-       }
-        elseif (isset($HTTP_POST_VARS['change']))
-       {
+               unset($_POST['edit']);
+               unset($_POST['del']);
+               unset($_POST['change']);
+               unset($_POST['remove']);
+       } elseif (isset($_POST['change'])) {
                // Change entries here...
-               foreach ($HTTP_POST_VARS['id'] as $id=>$sel)
-               {
+               foreach ($_POST['id'] as $id => $sel) {
                        // Secure ID
                        $id = bigintval($id);
 
                        // Save entry
                        $result = SQL_QUERY_ESC("UPDATE "._MYSQL_PREFIX."_sponsor_paytypes
 SET pay_name='%s', pay_rate='%s', pay_min_count='%s', pay_currency='%s' WHERE id='%s' LIMIT 1",
- array($HTTP_POST_VARS['name'][$id], $HTTP_POST_VARS['rate'][$id], bigintval($HTTP_POST_VARS['min'][$id]), $HTTP_POST_VARS['curr'][$id], $id),
+ array($_POST['name'][$id], $_POST['rate'][$id], bigintval($_POST['min'][$id]), $_POST['curr'][$id], $id),
  __FILE__, __LINE__);
                }
 
                // Generate message
                $MSG = SPONSOR_PAY_ENTRIES_CHANGED;
-       }
-        elseif (isset($HTTP_POST_VARS['remove']))
-       {
+       } elseif (isset($_POST['remove'])) {
                // Remove entries here...
-               foreach ($HTTP_POST_VARS['id'] as $id=>$sel)
-               {
+               foreach ($_POST['id'] as $id => $sel) {
                        // Remove entry
                        $result = SQL_QUERY_ESC("DELETE LOW_PRIORITY FROM "._MYSQL_PREFIX."_sponsor_paytypes WHERE id='%s' LIMIT 1",
  array(bigintval($id)), __FILE__, __LINE__);
@@ -93,54 +82,45 @@ SET pay_name='%s', pay_rate='%s', pay_min_count='%s', pay_currency='%s' WHERE id
                $MSG = SPONSOR_PAY_ENTRIES_REMOVED;
        }
 
-       if (!empty($MSG))
-       {
+       if (!empty($MSG)) {
                // Output message
                LOAD_TEMPLATE("admin_settings_saved", false, $MSG);
-               OUTPUT_HTML("<BR>");
+               OUTPUT_HTML("<br />");
        }
 }
 
-if (isset($HTTP_POST_VARS['add']))
-{
+if (isset($_POST['add'])) {
        // Check if entry with same name does exists
        $result = SQL_QUERY_ESC("SELECT id FROM "._MYSQL_PREFIX."_sponsor_paytypes WHERE pay_name='%s' LIMIT 1",
-        array($HTTP_POST_VARS['pay_name']), __FILE__, __LINE__);
-       if (SQL_NUMROWS($result) == 0)
-       {
+        array($_POST['pay_name']), __FILE__, __LINE__);
+       if (SQL_NUMROWS($result) == 0) {
                // No entry found so add this line
                $result = SQL_QUERY_ESC("INSERT INTO "._MYSQL_PREFIX."_sponsor_paytypes (pay_name, pay_rate, pay_min_count, pay_currency)
  VALUES ('%s', '%s', '%s', '%s')",
- array(htmlspecialchars($HTTP_POST_VARS['pay_name']), str_replace(",", ".", $HTTP_POST_VARS['pay_rate']), bigintval($HTTP_POST_VARS['pay_min_count']), htmlspecialchars($HTTP_POST_VARS['pay_currency'])),
+ array(htmlspecialchars($_POST['pay_name']), str_replace(",", ".", $_POST['pay_rate']), bigintval($_POST['pay_min_count']), htmlspecialchars($_POST['pay_currency'])),
  __FILE__, __LINE__);
 
                // Payment type added!
-               $MSG = SPONSOR_ADMIN_PAYTYPE_ADDED_1.$HTTP_POST_VARS['pay_name'].SPONSOR_ADMIN_PAYTYPE_ADDED_2;
-       }
-        else
-       {
+               $MSG = SPONSOR_ADMIN_PAYTYPE_ADDED_1.$_POST['pay_name'].SPONSOR_ADMIN_PAYTYPE_ADDED_2;
+       } else {
                // Free memory
                SQL_FREERESULT($result);
 
                // Entry does already exists
-               $MSG = SPONSOR_ADMIN_PAYTYPE_ALREADY_1.$HTTP_POST_VARS['pay_name'].SPONSOR_ADMIN_PAYTYPE_ALREADY_2;
+               $MSG = SPONSOR_ADMIN_PAYTYPE_ALREADY_1.$_POST['pay_name'].SPONSOR_ADMIN_PAYTYPE_ALREADY_2;
        }
 
        // Output message
        LOAD_TEMPLATE("admin_settings_saved", false, $MSG);
-       OUTPUT_HTML("<BR>");
-}
- elseif ((isset($HTTP_POST_VARS['edit'])) || (isset($HTTP_POST_VARS['del'])))
-{
+       OUTPUT_HTML("<br />");
+} elseif ((isset($_POST['edit'])) || (isset($_POST['del']))) {
        // Load all data
        $OUT = ""; $SW = 2;
-       foreach ($HTTP_POST_VARS['id'] as $id=>$sel)
-       {
+       foreach ($_POST['id'] as $id => $sel) {
                // Load entry
                $result = SQL_QUERY_ESC("SELECT pay_name, pay_rate, pay_min_count, pay_currency FROM "._MYSQL_PREFIX."_sponsor_paytypes WHERE id='%s' LIMIT 1",
                 array(bigintval($id)), __FILE__, __LINE__);
-               if (SQL_NUMROWS($result) == 1)
-               {
+               if (SQL_NUMROWS($result) == 1) {
                        // Load data
                        list($name, $rate, $min, $curr) = SQL_FETCHROW($result);
                        SQL_FREERESULT($result);
@@ -155,19 +135,14 @@ if (isset($HTTP_POST_VARS['add']))
                                'curr' => htmlspecialchars($curr)
                        );
 
-                       if (isset($HTTP_POST_VARS['edit']))
-                       {
+                       if (isset($_POST['edit'])) {
                                // Edit entry
                                $OUT .= LOAD_TEMPLATE("admin_list_sponsor_pay_edit_row", true, $content);
-                       }
-                        else
-                       {
+                       } else {
                                // Delete entry
                                $OUT .= LOAD_TEMPLATE("admin_list_sponsor_pay_del_row", true, $content);
                        }
-               }
-                else
-               {
+               } else {
                        // Entry invalid
                        $OUT .= LOAD_TEMPLATE("admin_list_sponsor_pay_404", true, $id);
                }
@@ -180,32 +155,25 @@ if (isset($HTTP_POST_VARS['add']))
        define('__SPONSOR_ROWS', $OUT);
 
        // Load main template depending on mode (edit/delete)
-       if (isset($HTTP_POST_VARS['edit']))
-       {
+       if (isset($_POST['edit'])) {
                // Load main edit template
                LOAD_TEMPLATE("admin_list_sponsor_pay_edit");
-       }
-        else
-       {
+       } else {
                // Load main delete template
                LOAD_TEMPLATE("admin_list_sponsor_pay_del");
        }
-}
- else
-{
+} else {
        // Load all payment types
        $result = SQL_QUERY("SELECT id, pay_name, pay_rate, pay_min_count, pay_currency FROM "._MYSQL_PREFIX."_sponsor_paytypes ORDER BY pay_name",
         __FILE__, __LINE__);
 
        // Do we have some paytypes setup?
-       if (SQL_NUMROWS($result) > 0)
-       {
+       if (SQL_NUMROWS($result) > 0) {
                // Prepare variables for listing
                $SW = 2; $OUT = "";
 
                // List alle found payment types
-               while(list($id, $name, $rate, $min, $currency) = SQL_FETCHROW($result))
-               {
+               while(list($id, $name, $rate, $min, $currency) = SQL_FETCHROW($result)) {
                        // Remember data in array
                        $content = array(
                                'sw'       => $SW,
@@ -231,9 +199,7 @@ if (isset($HTTP_POST_VARS['add']))
 
                // Load list template
                define('__LIST_CONTENT', LOAD_TEMPLATE("admin_list_sponsor_pay", true));
-       }
-        else
-       {
+       } else {
                // Noting setup so far!
                define('__LIST_CONTENT', LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_ADMIN_NO_PAYTYPES));
        }