More constant rewrites
[mailer.git] / inc / modules / frametester.php
index 0b42976a8dde8d19b7ed99c41ebfe17144ac9ee3..bd090bdd7e4963fde51527a39b81fc489153631e 100644 (file)
  ************************************************************************/
 
 // Some security stuff...
-if (ereg(basename(__FILE__), $_SERVER['PHP_SELF']))
-{
+if (!defined('__SECURITY')) {
        $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
        require($INC);
 }
 
 $MODE = "guest";
 
-if (!empty($_GET['order']))
-{
+if (REQUEST_ISSET_GET(('order'))) {
        // Order number placed, is he also logged in?
-       if(IS_LOGGED_IN())
-       {
+       if (IS_MEMBER()) {
                // Ok, test passed... :)
-               $result = SQL_QUERY_ESC("SELECT subject, url FROM "._MYSQL_PREFIX."_pool WHERE id=%d AND sender=%d AND data_type='TEMP' LIMIT 1",
-                array(bigintval($_GET['order']), $GLOBALS['userid']), __FILE__, __LINE__);
+               $result = SQL_QUERY_ESC("SELECT subject, url FROM `{!_MYSQL_PREFIX!}_pool` WHERE id=%s AND sender=%s AND data_type='TEMP' LIMIT 1",
+                array(bigintval(REQUEST_GET('order')), $GLOBALS['userid']), __FILE__, __LINE__);
 
                // Finally is the entry valid?
-               if (SQL_NUMROWS($result) == 1)
-               {
+               if (SQL_NUMROWS($result) == 1) {
                        // Load subject and URL (but forwhat do we need the subject line here???
                        list($sub, $url) = SQL_FETCHROW($result);
 
                        // This fixes a white page
-                       $_POST['url'] = $url;
+                       REQUEST_SET_POST('url', $url);
 
-                       // Update his login data
-                       UPDATE_LOGIN_DATA();
+                       // Mode is member
                        $MODE = "member";
-               }
-                else
-               {
+               } else {
                        // Matching line not found!
-                       LOAD_URL(URL."/modules.php?module=index&what=login");
+                       LOAD_URL("modules.php?module=index&what=login");
                }
 
                // Free memory
                SQL_FREERESULT($result);
-       }
-        else
-       {
+       } else {
                // He is no longer logged in
-               LOAD_URL(URL."/modules.php?module=index&what=login");
+               LOAD_URL("modules.php?module=index&what=login");
        }
 }
 
-if ((!empty($_POST['url'])) || (!empty($_GET['url'])) || (!empty($_GET['frame'])))
-{
-       $url = URL;
-       if (!empty($_POST['url'])) $url = $_POST['url'];
-       if (!empty($_GET['url']))  $url = base64_decode(urldecode(COMPILE_CODE($_GET['url'])));
-       switch ($_GET['frame'])
+if ((REQUEST_ISSET_POST(('url'))) || (REQUEST_ISSET_GET(('url'))) || (REQUEST_ISSET_GET(('frame')))) {
+       // Default URL is ours
+       $url = constant('URL');
+
+       // Decode URL if set in GET parameters
+       if (REQUEST_ISSET_GET(('url')))  $url = decodeString(str_replace(" ", "+", compileUriCode(urldecode(REQUEST_GET('url')))));
+
+       // Use URL from POST data if set
+       if (REQUEST_ISSET_POST(('url'))) $url = REQUEST_POST('url');
+
+       // Add missing element
+       $frame = "";
+       if (REQUEST_ISSET_GET(('frame'))) $frame = REQUEST_GET(('frame'));
+       switch ($frame)
        {
        case "":
                switch ($MODE)
                {
                case "member":
                        // Build frameset
-                       define('__ORDER_VALUE', bigintval($_GET['order']));
+                       define('__ORDER_VALUE', bigintval(REQUEST_GET('order')));
                        define('__URL_VALUE'  , DEREFERER($url));
                        LOAD_TEMPLATE("member_order_frametester");
                        break;
@@ -103,22 +102,20 @@ if ((!empty($_POST['url'])) || (!empty($_GET['url'])) || (!empty($_GET['frame'])
                break;
 
        case "test_top":
-               OUTPUT_HTML("<STRONG class=\"guest_done\">".GUEST_FRAMETESTER_TOP."</SPAN>");
+               LOAD_TEMPLATE("admin_settings_saved", false, "<div class=\"guest_done\">{--GUEST_FRAMETESTER_TOP--}</span>");
                break;
 
        case "back": // Back buttom
-               LOAD_TEMPLATE("member_order_back", false, $_GET['order']);
+               LOAD_TEMPLATE("member_order_back", false, REQUEST_GET('order'));
                break;
 
        case "send": // Send mail away
-               LOAD_TEMPLATE("member_order_send", false, $_GET['order']);
+               LOAD_TEMPLATE("member_order_send", false, REQUEST_GET('order'));
                break;
        }
-}
- else
-{
+} else {
        // Go away...
-       LOAD_URL(URL."/modules.php?module=login");
+       LOAD_URL("modules.php?module=login");
 }
 //
 ?>