Functions imported, some dev-scripts added
[mailer.git] / inc / modules / sponsor / account.php
index ec754c98e1c08c6dd5f2529eb0557fbfc0982f30..b5f9a51493a3c0045d560746126402ea3297f79c 100644 (file)
  ************************************************************************/
 
 // Some security stuff...
-if (ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) {
+if (!defined('__SECURITY')) {
        $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4)."/security.php";
        require($INC);
-} elseif ((!EXT_IS_ACTIVE("sponsor")) && (!IS_ADMIN())) {
-       ADD_FATAL(EXTENSION_PROBLEM_EXT_INACTIVE);
+} elseif ((!EXT_IS_ACTIVE("sponsor"))
+       addFatalMessage(getMessage('EXTENSION_PROBLEM_EXT_INACTIVE'), "sponsor");
        return;
 } elseif (!IS_SPONSOR()) {
        // No sponsor!
-       ADD_FATAL(SPONSOR_ONLY_AREA_ENTERED);
+       addFatalMessage(getMessage('SPONSOR_ONLY_AREA_ENTERED'));
        return;
 }
 
 // Data for the formular
 $result = SQL_QUERY_ESC("SELECT company, position, tax_ident,
-salut, surname, family, street_nr1, street_nr2, zip, city, country,
+gender, surname, family, street_nr1, street_nr2, zip, city, country,
 phone, fax, cell, email, url,
 status, receive_warnings
-FROM "._MYSQL_PREFIX."_sponsor_data
+FROM `{!_MYSQL_PREFIX!}_sponsor_data`
 WHERE id='%s' AND password='%s' LIMIT 1",
- array(bigintval($_COOKIE['sponsorid']), $_COOKIE['sponsorpass']), __FILE__, __LINE__);
+       array(bigintval(get_session('sponsorid')), get_session('sponsorpass')), __FILE__, __LINE__);
+
+// Entry found?
 if (SQL_NUMROWS($result) == 1) {
        // Load sponsor data
        $content = SQL_FETCHARRAY($result);
@@ -60,22 +62,22 @@ if (SQL_NUMROWS($result) == 1) {
                        // Check passwords
                        if (empty($_POST['pass_old'])) {
                                // No current password entered
-                               $MSG = SPONSOR_NO_CURRENT_PASSWORD_ENTERED;
-                       } elseif (md5($_POST['pass_old']) != $_COOKIE['sponsorpass']) {
+                               $MSG = getMessage('SPONSOR_NO_CURRENT_PASSWORD_ENTERED');
+                       } elseif (md5($_POST['pass_old']) != get_session('sponsorpass')) {
                                // Entered password didn't match password in DB
-                               $MSG = SPONSOR_CURRENT_PASSWORD_DIDNOT_MATCH_DB;
+                               $MSG = getMessage('SPONSOR_CURRENT_PASSWORD_DIDNOT_MATCH_DB');
                        } elseif ((!empty($_POST['pass1'])) && (!empty($_POST['pass2'])) && ($_POST['pass1'] != $_POST['pass2'])) {
                                // Both new passwords did not match
-                               $MSG = SPONSOR_BOTH_NEW_PASSWORDS_DIDNOT_MATCH;
+                               $MSG = getMessage('SPONSOR_BOTH_NEW_PASSWORDS_DIDNOT_MATCH');
                        } elseif ((empty($_POST['pass1'])) && (!empty($_POST['pass2']))) {
                                // No password one entered
-                               $MSG = SPONSOR_PASSWORD_ONE_EMPTY;
+                               $MSG = getMessage('SPONSOR_PASSWORD_ONE_EMPTY');
                        } elseif ((!empty($_POST['pass1'])) && (empty($_POST['pass2']))) {
                                // No password two entered
-                               $MSG = SPONSOR_PASSWORD_TWO_EMPTY;
-                       } elseif ((!empty($_POST['pass1'])) && (strlen($_POST['pass1']) < $CONFIG['pass_len'])) {
+                               $MSG = getMessage('SPONSOR_PASSWORD_TWO_EMPTY');
+                       } elseif ((!empty($_POST['pass1'])) && (strlen($_POST['pass1']) < getConfig('pass_len'))) {
                                // Too short password
-                               $MSG = SPONSOR_PASSWORD_TOO_SHORT_1.$CONFIG['pass_len'].SPONSOR_PASSWORD_TOO_SHORT_2;
+                               $MSG = sprintf(getMessage('SPONSOR_PASSWORD_TOO_SHORT'), getConfig('pass_len'));
                        } else {
                                // Default is we don't want to change password!
                                $PASS_AND = ""; $PASS_DATA = "";
@@ -88,7 +90,7 @@ if (SQL_NUMROWS($result) == 1) {
                                }
 
                                // Unsecure data which we don't want here
-                               $UNSAFE = array('receive_warnings', 'warning_interval');
+                                       $UNSAFE = array('receive_warnings', 'warning_interval');
 
                                // Remove all (maybe spoofed) unsafe data from array
                                foreach ($UNSAFE as $remove) {
@@ -107,28 +109,28 @@ if (SQL_NUMROWS($result) == 1) {
                                $OUT = LOAD_TEMPLATE("admin_settings_saved", true, $MSG);
                        } else {
                                // No message generated
-                               $OUT = LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_NO_MESSAGE_GENERATED);
+                               $OUT = LOAD_TEMPLATE("admin_settings_saved", true, getMessage('SPONSOR_NO_MESSAGE_GENERATED'));
                        }
                } else {
-                       // Check for salutation selection
-                       switch ($content['salut'])
+                       // Check for gender selection
+                       switch ($content['gender'])
                        {
                        case "M": // Male
-                               define('__SALUT_M', " selected");
-                               define('__SALUT_F', "");
-                               define('__SALUT_C', "");
+                               define('__GENDER_M', " selected=\"selected\"");
+                               define('__GENDER_F', "");
+                               define('__GENDER_C', "");
                                break;
 
                        case "F": // Female
-                               define('__SALUT_M', "");
-                               define('__SALUT_F', " selected");
-                               define('__SALUT_C', "");
+                               define('__GENDER_M', "");
+                               define('__GENDER_F', " selected=\"selected\"");
+                               define('__GENDER_C', "");
                                break;
 
                        case "C": // Company
-                               define('__SALUT_M', "");
-                               define('__SALUT_F', "");
-                               define('__SALUT_C', " selected");
+                               define('__GENDER_M', "");
+                               define('__GENDER_F', "");
+                               define('__GENDER_C', " selected=\"selected\"");
                                break;
                        }
 
@@ -142,7 +144,7 @@ if (SQL_NUMROWS($result) == 1) {
        }
 } else {
        // Sponsor account not found!
-       $OUT = LOAD_TEMPLATE("admin_settings_saved", true, SPONSOR_ACCOUNT_404_1.$_COOKIE['sponsorid'].SPONSOR_ACCOUNT_404_2);
+       $OUT = LOAD_TEMPLATE("admin_settings_saved", true, sprintf(getMessage('SPONSOR_ACCOUNT_404'), get_session('sponsorid')));
 }
 
 // Free memory