return;
} // END - if
-$URL = ''; $id = '0';
+$url = ''; $id = '0';
$whereStatement = " WHERE `visible`='Y'";
// Set undefined array elements
if (($HOLIDAY == 'Y') && (isExtensionInstalledAndNewer('holiday', '0.1.3'))) {
// Holiday is active!
- loadTemplate('admin_settings_saved', false, getMessage('HOLIDAY_ORDER_NOT_POSSIBLE'));
+ loadTemplate('admin_settings_saved', false, '{--HOLIDAY_ORDER_NOT_POSSIBLE--}');
} elseif ((isPostRequestParameterSet('frametester')) && ($ALLOWED > 0) && (postRequestParameter('receiver') > 0)) {
// Continue with the frametester, we first need to store the data temporary in the pool
//
WHERE
`sender`=%s AND
`url`='%s' AND
- `timestamp` > (UNIX_TIMESTAMP() - %s)
+ `timestamp` > (UNIX_TIMESTAMP() - {?url_tlock?})
LIMIT 1",
array(
getMemberId(),
- postRequestParameter('url'),
- getConfig('url_tlock')
+ postRequestParameter('url')
), __FILE__, __LINE__);
$type = 'TEMP'; $id = '0';
if ($type == 'TEMP') {
// No entry found, so we need to check out the stats table as well... :)
// We have to add that suff here, now we continue WITHOUT checking and check the text and subject against some filters
- $URL = '';
+ $url = '';
if (getConfig('allow_url_in_text') == 'Y') {
// Test submitted text against some filters (length, URLs in text etc.)
if ((strpos(strtolower(postRequestParameter('text')), 'https://') > -1) || (strpos(strtolower(postRequestParameter('text')), 'http://') > -1) || (strpos(strtolower(postRequestParameter('text')), "www") > -1)) {
// URL found!
- $URL = 'modules.php?module=login&what=order&code=' . getCode('URL_FOUND');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('URL_FOUND');
} // END - if
// Remove new-line and carriage-return characters
// Text length within allowed length?
if (strlen($TEST) > getConfig('max_tlength')) {
// Text is too long!
- $URL = 'modules.php?module=login&what=order&code=' . getCode('OVERLENGTH');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('OVERLENGTH');
} // END - if
} // END - if
setPostRequestParameter('subject', str_replace("\\", '[nl]', substr(postRequestParameter('subject'), 0, 200)));
if ((strpos(strtolower(postRequestParameter('subject')), 'http://') > -1) || (strpos(strtolower(postRequestParameter('subject')), "www") > -1)) {
// URL in subject found
- $URL = 'modules.php?module=login&what=order&code=' . getCode('SUBJ_URL');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('SUBJ_URL');
} // END - if
} // END - if
list($blist) = SQL_FETCHROW($result);
// Create redirect-URL
- $URL = 'modules.php?module=login&what=order&code=' . getCode('BLIST_URL') . '&blist=' . $blist;
+ $url = 'modules.php?module=login&what=order&code=' . getCode('BLIST_URL') . '&blist=' . $blist;
} // END - if
// Free result
// Enougth receivers entered?
if ((postRequestParameter('receiver') < getConfig('order_min')) && (!isAdmin())) {
// Less than allowed receivers entered!
- $URL = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS3');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS3');
} // END - if
// Validate URL
if (!isUrlValid(postRequestParameter('url'))) {
// URL is invalid!
- $URL = 'modules.php?module=login&what=order&code=' . getCode('INVALID_URL');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('INVALID_URL');
} // END - if
// Probe for HTML extension
setPostRequestParameter('text', checkHtmlTags(postRequestParameter('text')));
// Maybe invalid tags found?
- if (!isPostRequestParameterSet('text')) $URL = 'modules.php?module=login&what=order&code=' . getCode('INVALID_TAGS')."&id=".$id;
+ if (!isPostRequestParameterSet('text')) $url = 'modules.php?module=login&what=order&code=' . getCode('INVALID_TAGS')."&id=".$id;
} else {
// Remove any HTML code
setPostRequestParameter('text', str_replace('<', '{OPEN_HTML}', str_replace('>', '{CLOSE_HTML}', postRequestParameter('text'))));
// Is mail type set?
if ((!isPostRequestParameterSet('mail_type')) || (postRequestParameter('mail_type') < 1)) {
// Not correctly set
- $URL = 'modules.php?module=login&what=order&code=' . getCode('NO_MAIL_TYPE');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('NO_MAIL_TYPE');
} // END - if
} elseif (!isAdmin()) {
// He has already sent a mail within a specific time
- $URL = 'modules.php?module=login&what=order&code=' . getCode('URL_TLOCK') . '&id=' . $id;
+ $url = 'modules.php?module=login&what=order&code=' . getCode('URL_TLOCK') . '&id=' . $id;
}
// Still no error?
- if (empty($URL)) {
+ if (empty($url)) {
// Check if category and number of receivers is okay
$add = '';
if ((getConfig('order_multi_page') == 'Y') && (isPostRequestParameterSet('zip')) && (postRequestParameter('zip') != '')) {
// Choose recipients by ZIP code
- $add = " AND d.zip LIKE '".bigintval(postRequestParameter('zip'))."{PER}'";
+ $add = sprintf(" AND d.zip LIKE '%s%%'",
+ bigintval(postRequestParameter('zip'))
+ );
} // END - if
// Check for userids
} // END - if
// id is received so we can redirect the user, used points will be added when he send's out the mail
- $URL = 'modules.php?module=frametester&order=' . $id;
+ $url = 'modules.php?module=frametester&order=' . $id;
} elseif ($content['target_send'] == '0') {
// Not enougth receivers found which can receive mails
- $URL = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS2');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS2');
} else {
// No enougth points left!
- $URL = 'modules.php?module=login&what=order&code=' . getCode('MORE_POINTS');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('MORE_POINTS');
}
} else {
// Ordered more mails than he can send in this category
- $URL = 'modules.php?module=login&what=order&code=' . getCode('NO_RECS_LEFT');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('NO_RECS_LEFT');
}
}
} elseif (postRequestParameter('receiver') == '0') {
// Not enougth receivers selected
- $URL = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS1');
+ $url = 'modules.php?module=login&what=order&code=' . getCode('MORE_RECEIVERS1');
} elseif (($ALLOWED == '0') && (getConfig('order_max_full') == 'ORDER')) {
// No more mail orders allowed
- loadTemplate('admin_settings_saved', false, getMessage('MEMBER_ORDER_ALLOWED_EXHAUSTED'));
+ loadTemplate('admin_settings_saved', false, '{--MEMBER_ORDER_ALLOWED_EXHAUSTED--}');
} elseif (($links < getConfig('unconfirmed')) && ($mmails == 1)) {
// Display order form
$result_cats = SQL_QUERY("SELECT
}
} elseif ($mmails == '0') {
// Please set more than 0 mails per day
- loadTemplate('admin_settings_saved', false, getMessage('MEMBER_HAS_ZERO_MMAILS'));
+ loadTemplate('admin_settings_saved', false, '{--MEMBER_HAS_ZERO_MMAILS--}');
} else {
// Please confirm some mails first
loadTemplate('admin_settings_saved', false, getMaskedMessage('MEMBER_LINKS_LEFT'), $links);
}
-if (!empty($URL)) {
+if (!empty($url)) {
// Redirect to requested URL
- redirectToUrl($URL);
+ redirectToUrl($url);
} // END - if
// [EOF]