* $Author:: $ *
* -------------------------------------------------------------------- *
* Copyright (c) 2003 - 2009 by Roland Haeder *
- * Copyright (c) 2009 - 2011 by Mailer Developer Team *
+ * Copyright (c) 2009 - 2012 by Mailer Developer Team *
* For more information visit: http://mxchange.org *
* *
* This program is free software; you can redistribute it and/or modify *
// Some security stuff...
if (!defined('__SECURITY')) {
- die();
+ exit();
} elseif (!isMember()) {
redirectToIndexMemberOnlyModule();
}
$valid_recipient = isValidUserId(postRequestElement('to_userid'));
// Re-check receivers and own personal data
- $result = SQL_QUERY_ESC("SELECT `userid`,`gender`,`surname`,`family`,`email` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `userid` IN ('%s','%s') AND `status`='CONFIRMED' LIMIT 2",
+ $result = SQL_QUERY_ESC("SELECT `userid`,`gender`,`surname`,`family`,`email` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `userid` IN ('%s','%s') AND `status`='CONFIRMED'" . runFilterChain('user_exclusion_sql', ' ') . " LIMIT 2",
array(
getMemberId(),
bigintval(postRequestElement('to_userid'))
$content['reason'] = postRequestElement('reason');
// Generate tranafer id
- $content['trans_id'] = bigintval(generateRandomCode('10', mt_rand(0, 99999), getMemberId(), postRequestElement('reason')));
+ $content['trans_id'] = bigintval(generateRandomCode('10', getRandomTan(), getMemberId(), postRequestElement('reason')));
// Add entries to both tables
SQL_QUERY_ESC("INSERT INTO `{?_MYSQL_PREFIX?}_user_transfers_in` (`userid`,`from_userid`,`points`,`reason`,`time_trans`,`trans_id`) VALUES (%s,%s,%s,'%s', UNIX_TIMESTAMP(),%s)",
sendEmail($content['sender']['userid'], '{--TRANSFER_MEMBER_SENDER_SUBJECT--}' . ': ' . $RECIPIENT, $message);
// At last send admin mail(s)
- $adminSubject = sprintf("%s (%s->%s)", '{--TRANSFER_ADMIN_SUBJECT--}', $SENDER, $RECIPIENT);
+ $adminSubject = sprintf("%s (%s->%s)", '{--ADMIN_TRANSFER_SUBJECT--}', $SENDER, $RECIPIENT);
sendAdminNotification($adminSubject, 'admin_transfer_points', $content);
// Transfer is completed
- displayMessage('<div>{--TRANSFER_COMPLETED--}' . '</div><div><a href="{%url=modules.php?module=login&what=transfer%}">{--TRANSFER_CONTINUE_OVERVIEW--}</a></div>');
+ displayMessage('<div>{--MEMBER_TRANSFER_COMPLETED--}' . '</div><div><a href="{%url=modules.php?module=login&what=transfer%}">{--MEMBER_TRANSFER_CONTINUE_OVERVIEW--}</a></div>');
} elseif ($valid_code === false) {
// Invalid Touring code!
- loadTemplate('admin_settings_unsaved', false, '{--TRANSFER_INVALID_CODE--}');
+ loadTemplate('admin_settings_unsaved', false, '{--MEMBER_TRANSFER_INVALID_CODE--}');
unsetPostRequestElement('ok');
} elseif ($valid_pass === false) {
// Wrong password entered
- loadTemplate('admin_settings_unsaved', false, '{--TRANSFER_INVALID_PASSWORD--}');
+ loadTemplate('admin_settings_unsaved', false, '{--MEMBER_TRANSFER_INVALID_PASSWORD--}');
unsetPostRequestElement('ok');
} elseif ($valid_amount === false) {
// Too much points entered
- loadTemplate('admin_settings_unsaved', false, '{--TRANSFER_INVALID_POINTS--}');
+ loadTemplate('admin_settings_unsaved', false, '{--MEMBER_TRANSFER_INVALID_POINTS--}');
unsetPostRequestElement('ok');
} elseif ($valid_reason === false) {
// No transfer reason entered
- loadTemplate('admin_settings_unsaved', false, '{--TRANSFER_INVALID_REASON--}');
+ loadTemplate('admin_settings_unsaved', false, '{--MEMBER_TRANSFER_INVALID_REASON--}');
unsetPostRequestElement('ok');
} elseif ($valid_recipient === false) {
// No recipient selected
- loadTemplate('admin_settings_unsaved', false, '{--TRANSFER_INVALID_RECIPIENT--}');
+ loadTemplate('admin_settings_unsaved', false, '{--MEMBER_TRANSFER_INVALID_RECIPIENT--}');
unsetPostRequestElement('ok');
} elseif ($valid_data === false) {
// No recipient/sender selected
- loadTemplate('admin_settings_unsaved', false, '{--TRANSFER_INVALID_DATA--}');
+ loadTemplate('admin_settings_unsaved', false, '{--MEMBER_TRANSFER_INVALID_DATA--}');
unsetPostRequestElement('ok');
}
if (!isFormSent()) {
// Load member list
- $result = SQL_QUERY_ESC("SELECT `userid` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `status`='CONFIRMED' AND `opt_in`='Y' AND `userid` != '%s' ORDER BY `userid` ASC",
+ $result = SQL_QUERY_ESC("SELECT `userid` FROM `{?_MYSQL_PREFIX?}_user_data` WHERE `status`='CONFIRMED'" . runFilterChain('user_exclusion_sql', ' ') . " AND `opt_in`='Y' AND `userid` != '%s' ORDER BY `userid` ASC",
array(getMemberId()), __FILE__, __LINE__);
if (!SQL_HASZERONUMS($result)) {
SQL_FREERESULT($result);
} else {
// No one else is opt-in
- $OUT = displayMessage('{--TRANSFER_NO_ONE_ELSE_OPT_IN--}', true);
+ $OUT = displayMessage('{--MEMBER_TRANSFER_NO_ONE_ELSE_OPT_IN--}', true);
$content['to_disabled'] = ' disabled="disabled"';
}
// Generate Code
if (getTransferCode() > 0) {
// Generate random number
- $rand = mt_rand(0, 99999);
+ $rand = getRandomTan();
// Generate CAPTCHA code
$code = generateRandomCode(getTransferCode(), $rand, getMemberId(), $content['max_transferable']);
$content['captcha_code'] = '<input type="hidden" name="code_chk" value="' . $rand . '" /><input type="text" name="code" class="form_field" size="5" maxlength="7"' . $content['to_disabled'] . ' /> ' . $img;
} else {
$code = '00000';
- $content['captcha_code'] = displayMessage('{--TRANSFER_NO_CODE--}', true);
+ $content['captcha_code'] = displayMessage('{--MEMBER_TRANSFER_NO_CODE--}', true);
}
// Init points/reason
switch ($mode) {
case 'list_in':
$sql = 'SELECT `trans_id`,`from_userid` AS party_userid,`points`,`reason`,`time_trans` FROM `{?_MYSQL_PREFIX?}_user_transfers_in` WHERE `userid`=%s ORDER BY `time_trans` DESC LIMIT {?transfer_max?}';
- $nothingMessage = '{--TRANSFER_NO_INCOMING_TRANSFERS--}';
- $content['balance'] = '{--TRANSFER_TOTAL_INCOMING--}';
- $content['title'] = '{--TRANSFER_LIST_INCOMING--}';
+ $nothingMessage = '{--MEMBER_TRANSFER_NO_INCOMING_TRANSFERS--}';
+ $content['balance'] = '{--MEMBER_TRANSFER_TOTAL_INCOMING--}';
+ $content['title'] = '{--MEMBER_LIST_INCOMING_TRANSFER_TITLE--}';
break;
case 'list_out':
$sql = 'SELECT `trans_id`,`to_userid` AS party_userid,`points`,`reason`,`time_trans` FROM `{?_MYSQL_PREFIX?}_user_transfers_out` WHERE `userid`=%s ORDER BY `time_trans` DESC LIMIT {?transfer_max?}';
- $nothingMessage = '{--TRANSFER_NO_OUTGOING_TRANSFERS--}';
+ $nothingMessage = '{--MEMBER_TRANSFER_NO_OUTGOING_TRANSFERS--}';
$content['balance'] = '{--TRANSFER_TOTAL_OUTGOING--}';
- $content['title'] = '{--TRANSFER_LIST_OUTGOING--}';
+ $content['title'] = '{--MEMBER_LIST_OUTGOING_TRANSFER_TITLE--}';
break;
} // END - switch
$result = SQL_QUERY_ESC("SELECT `trans_id`,`from_userid`,`points`,`reason`,`time_trans` FROM `{?_MYSQL_PREFIX?}_user_transfers_in` WHERE `userid`=%s ORDER BY `id` ASC LIMIT {?transfer_max?}",
array(getMemberId()), __FILE__, __LINE__);
while ($content = SQL_FETCHROW($result)) {
- $content[] = 'IN';
+ array_push($content, 'IN');
$content = implode("','", $content);
$res_temp = SQL_QUERY_ESC("INSERT INTO `{?_MYSQL_PREFIX?}_%s_transfers_tmp` (`trans_id`,`party_userid`,`points`,`reason`,`time_trans`,`trans_type`) VALUES ('" . $content . "')", array(getMemberId()), __FILE__, __LINE__);
} // END - while
$result = SQL_QUERY_ESC("SELECT `trans_id`,`to_userid`,`points`,`reason`,`time_trans` FROM `{?_MYSQL_PREFIX?}_user_transfers_out` WHERE `userid`=%s ORDER BY `id` LIMIT {?transfer_max?}",
array(getMemberId()), __FILE__, __LINE__);
while ($content = SQL_FETCHROW($result)) {
- $content[] = 'OUT';
+ array_push($content, 'OUT');
$content = implode("','", $content);
$res_temp = SQL_QUERY_ESC("INSERT INTO `{?_MYSQL_PREFIX?}_%s_transfers_tmp` (`trans_id`,`party_userid`,`points`,`reason`,`time_trans`,`trans_type`) VALUES ('" . $content . "')", array(getMemberId()), __FILE__, __LINE__);
} // END - while
// Set 'new transfer' link according to above option
switch (getUserData('opt_in')) {
case 'Y':
- $content['new_link'] = '<a href="{%url=modules.php?module=login&what=transfer&do=new%}" title="{--TRANSFER_NOW_TITLE--}">{--TRANSFER_NOW_LINK--}</a>';
+ $content['new_link'] = '<a href="{%url=modules.php?module=login&what=transfer&do=new%}" title="{--MEMBER_TRANSFER_NOW_LINK_TITLE--}">{--MEMBER_TRANSFER_NOW_LINK--}</a>';
break;
case 'N':
- $content['new_link'] = '{--TRANSFER_PLEASE_ALLOW_OPT_IN--}';
+ $content['new_link'] = '{--MEMBER_PLEASE_ALLOW_TRANSFER_RECEIVE--}';
break;
} // END - switch
if (SQL_NUMROWS($result) == 1) {
// Load newest transaction
list($newest) = SQL_FETCHROW($result);
- $content['settings'] = '{%message,TRANSFER_LATEST_IS=' . generateDateTime($newest, '3') . '%}';
+ $content['settings'] = '{%message,MEMBER_TRANSFER_LATEST_IS=' . generateDateTime($newest, '3') . '%}';
} else {
// Load template
$content['settings'] = loadTemplate('member_transfer_settings', true, $content);