Several kinky code smoothed, fixes for admin login
[mailer.git] / inc / mysql-connect.php
index 59921655d456eb81294f022e6db0667f7e444fe2..a733ea9abd2440a6c38aa14c0f974e3fcc7b151d 100644 (file)
  * -------------------------------------------------------------------- *
  * Kurzbeschreibung  : Verbindet zu Ihrer Datenbank                     *
  * -------------------------------------------------------------------- *
- *                                                                      *
+ * $Revision::                                                        $ *
+ * $Date::                                                            $ *
+ * $Tag:: 0.2.1-FINAL                                                 $ *
+ * $Author::                                                          $ *
+ * Needs to be in all Files and every File needs "svn propset           *
+ * svn:keywords Date Revision" (autoprobset!) at least!!!!!!            *
  * -------------------------------------------------------------------- *
- * Copyright (c) 2003 - 2008 by Roland Haeder                           *
+ * Copyright (c) 2003 - 2009 by Roland Haeder                           *
  * For more information visit: http://www.mxchange.org                  *
  *                                                                      *
  * This program is free software; you can redistribute it and/or modify *
  ************************************************************************/
 
 // Some security stuff...
-if (ereg(basename(__FILE__), $_SERVER['PHP_SELF'])) {
-       $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
-       require($INC);
-}
+if (!defined('__SECURITY')) {
+       die();
+} // END - if
 
-// CFG: DEBUG-SQL (if enabled and DEBUG_MODE is enabled all SQL queries will be logged to debug.log)
-define('DEBUG_SQL', false);
+// Load more function libraries or includes
+foreach (array('functions', 'request-functions', 'session-functions', 'code-functions', 'language-functions', 'sql-functions', 'filter-functions', 'filters', 'mysql-manager', 'extensions-functions', 'handler') as $lib) {
+       // Load special functions
+       loadIncludeOnce('inc/' . $lib . '.php');
+} // END - foreach
 
-// Default is not a frameset
-global $isFrameset;
-$isFrameset = false;
+// Set error handler
+set_error_handler('__errorHandler');
 
-// Load library
-require_once(PATH."inc/db/lib.php");
+// Disable block-mode by default
+enableBlockMode(false);
 
-// Load general functions
-require_once(PATH."inc/functions.php");  // Non-database functions
-require_once(PATH."inc/extensions.php");
-require_once(PATH."inc/language.php");
+// Init error handler
+initErrorHandler();
 
-// Check if the user setups his MySQL stuff...
-if ((empty($MySQL['login'])) && (!isBooleanConstantAndTrue('mxchange_installing')) && (!isset($_GET['installing'])) && (isBooleanConstantAndTrue('mxchange_installed'))) {
-       // No login entered and outside installation mode
-       echo "<STRONG>".LANG_WARNING.":</STRONG> ";
-       if (isBooleanConstantAndTrue('mxchange_installed')) {
-               // You have changed my configuration file!
-               die(DIE_CONFIG_CHANGED_YOU);
-       } else {
-               // Please run the installation script (maybe again)
-               die(DIE_RUN_INSTALL_MYSQL);
-       }
-} elseif ((!isBooleanConstantAndTrue('mxchange_installing')) && (!isset($_GET['installing'])) && (empty($MySQL['password'])) && (isBooleanConstantAndTrue('warn_no_pass'))) {
-       // No database password entered!!!
-       echo "<STRONG>".LANG_WARNING.":</STRONG> ".WARN_NULL_PASSWORD;
-}
+// Init request
+initRequest();
+
+// Set important header_sent
+if (!isset($GLOBALS['header_sent'])) $GLOBALS['header_sent'] = 0;
+
+// Init fatal messages
+initFatalMessages();
+
+// Init message system
+initMessages();
 
 // Check if this file is writeable or read-only and warn the user
-if ((!isBooleanConstantAndTrue('mxchange_installing')) && (isBooleanConstantAndTrue('mxchange_installed'))) {
-       // Check for write-permission for config.php and inc directory
-       if (empty($GLOBALS['module'])) $GLOBALS['module'] = "index";
-       if (($GLOBALS['module'] != "admin") && (isBooleanConstantAndTrue('admin_registered')) && (!isset($_SERVER['WINDIR']))) {
-               if (is_INCWritable("config"))     ADD_FATAL(FATAL_CONFIG_WRITABLE);
-               if (is_INCWritable("dummy"))      ADD_FATAL(FATAL_INC_WRITABLE);
-       }
-       $EXT_CSS_FILES = array();
+if (!isInstalling()) {
+       // Load configuration file(s) here
+       loadIncludeOnce('inc/load_config.php');
 
-       if ((!empty($MySQL['host'])) && (!empty($MySQL['login'])) && (!empty($MySQL['password'])) && (!empty($MySQL['dbase']))) {
+       // Load database layer here
+       loadIncludeOnce('inc/db/lib.php');
+
+       // CSS array
+       initExtensionCssFiles();
+
+       if ((!empty($GLOBALS['mysql']['host'])) && (!empty($GLOBALS['mysql']['login'])) && (!empty($GLOBALS['mysql']['password'])) && (!empty($GLOBALS['mysql']['dbase']))) {
                // Connect to DB
-               global $link;
-               $link = SQL_CONNECT($MySQL['host'], $MySQL['login'], $MySQL['password'], __FILE__, __LINE__);
+               SQL_CONNECT($GLOBALS['mysql']['host'], $GLOBALS['mysql']['login'], $GLOBALS['mysql']['password'], __FILE__, __LINE__);
 
                // Is the link valid?
-               if (is_resource($link)) {
-                       // Choose the database
-                       global $db;
-                       $db = SQL_SELECT_DB($MySQL['dbase'], $link, __FILE__, __LINE__);
+               if (SQL_IS_LINK_UP()) {
+                       // Enable exit on error
+                       enableExitOnError();
 
                        // Is it a valid resource?
-                       if ($db === true) {
-                               // Load more include files
-                               require_once(PATH."inc/mysql-manager.php"); // Functions which interact with the database
-
-                               // Load configuration stuff
-                               $result = SQL_QUERY("SELECT pass_len, points_register, points_ref, least_cats, check_double_email, check_double_pass, admin_notify, url_tlock, test_text, max_tlength, test_subj, autosend_active, max_send, url_blacklist, auto_purge, auto_purge_active, last_update, unconfirmed, profile_lock, online_timeout, mad_timestamp, mad_count, profile_update, send_prof_update, resend_profile_update, code_length, patch_level, patch_ctime, guest_stats, ref_payout, activate_xchange, order_multi_page, display_refid, ip_timeout, allow_direct_pay, config
-FROM "._MYSQL_PREFIX."_config
-WHERE config=0
-LIMIT 1", __FILE__, __LINE__);
-
-                               if (SQL_NUMROWS($result) == 1) {
-                                       // Load data when previous SQL query did not fail
-                                       if (!is_resource($result)) {
-                                               // Something went wrong
-                                               ADD_FATAL(FATAL_CANNOT_LOAD_CONFIG);
-                                               return;
-                                       } // END - if
-
-                                       // Load the configuration
-                                       $_CONFIG = array_merge($_CONFIG, SQL_FETCHARRAY($result));
-
-                                       // Initialize include-file-pool
-                                       $INC_POOL = array();
-
-                                       // Load "databases" aka static arrays
-                                       require_once(PATH."inc/databases.php");
-
-                                       // Loading patching system is required here...
-                                       require_once(PATH."inc/patch-system.php"); // Initialize patch system
-
-                                       // Functions which are related to themes
-                                       require_once(PATH."inc/theme-manager.php");
-
-                                       // Run daily reset
-                                       // 01    2                            2        2         3321    1                         2                     21    1                        2                    21    1                        2                  21    1      2                 21    1         10
-                                       if ((date("d", $_CONFIG['last_update']) != date("d", time())) && (!isBooleanConstantAndTrue('mxchange_installing')) && (isBooleanConstantAndTrue('mxchange_installed')) && (isBooleanConstantAndTrue('admin_registered')) && (!isset($_GET['register'])) && ($CSS != 1)) {
-                                               // Do daily things in external PHP file but only when script is completely setup
-                                               $INC_POOL = array();
-                                               $INC_POOL[] = sprintf("%sinc/reset/reset_daily.php", PATH);
-
-                                               // Daily reset was run!
-                                               define('__DAILY_RESET', true);
-
-                                               // Add more includes
-                                               RESET_ADD_INCLUDES();
-
-                                               // Run the full reset scripts
-                                               foreach ($INC_POOL as $incFile) {
-                                                       require_once($incFile);
-                                               } // END - foreach
-                                       } // END - if
-
-                                       // Load admin include file if he is admin
-                                       if (IS_ADMIN()) {
-                                               // Administrative functions
-                                               require_once(PATH."inc/modules/admin/admin-inc.php");
-                                       } // END - if
-
-                                       // Get all values
-                                       if (($CSS != 1) && ($CSS != -1)) {
-                                               if (empty($GLOBALS['module']))  $GLOBALS['module'] = "empty";
-                                               if (empty($GLOBALS['what']))    $GLOBALS['what']   = GET_WHAT($GLOBALS['module']);
-                                               if (empty($GLOBALS['action']))  $GLOBALS['action'] = GET_ACTION($GLOBALS['module'], $GLOBALS['what']);
-                                       } else {
-                                               // Set action/what to empty
-                                               $GLOBALS['action'] = "";
-                                               $GLOBALS['what']   = "";
-                                       }
-
-                                       // Secure and validate user ID from cookie
-                                       UPDATE_LOGIN_DATA();
-
-                                       // Update online list
-                                       UPDATE_ONLINE_LIST(get_session('PHPSESSID'), $GLOBALS['module'], $GLOBALS['action'], $GLOBALS['what']);
-
-                                       // Load theme name
-                                       $currTheme = GET_CURR_THEME();
-
-                                       // Set default 'what' value
-                                       //* DEBUG */ echo "-".$GLOBALS['module']."/".$GLOBALS['what']."-<br />\n";
-                                       if ((empty($GLOBALS['what'])) && (empty($GLOBALS['action'])) && ($CSS != 1) && ($CSS != -1)) {
-                                               if ($GLOBALS['module'] == "admin") {
-                                                       // Set 'action' value to 'login' in admin menu
-                                                       $GLOBALS['action'] = GET_ACTION($GLOBALS['module'], $GLOBALS['what']);
-                                               } elseif (($GLOBALS['module'] == "index") || ($GLOBALS['module'] == "login")) {
-                                                       // Set 'what' value to 'welcome' in guest and member menu
-                                                       $GLOBALS['what'] = "welcome";
-                                                       if (!empty($_CONFIG['index_home'])) $GLOBALS['what'] = $_CONFIG['index_home'];
-                                               } else {
-                                                       // Anything else like begging link
-                                                       $GLOBALS['what'] = "";
-                                               }
-                                       }
-
-                                       // Update sending pool
-                                       if (($CSS != "1") && ($CSS != "-1")) require_once(PATH."inc/pool-update.php"); // Sends out mails in configureable steps
-
-                                       // Load all active extension including language files when not upgrading.
-                                       // Check module for testing and count one click
-                                       $dummy = CHECK_MODULE($GLOBALS['module']);
-                                       if ($dummy == "done") COUNT_MODULE($GLOBALS['module']);
-                                       unset($dummy);
-
-                                       // Shall we activate the exchange?
-                                       if ($_CONFIG['activate_xchange'] > 0) activateExchange();
-                               } else {
-                                       // If you will read following error message you probably need to contact me (webmaster@mxchange.org)
-                                       // and download the sql-upgrades extension from my server. Please ask me which SQL file(s) you need to
-                                       // import *BEFORE* you import them!
-                                       ADD_FATAL(FATAL_CANNOT_LOAD_CONFIG);
-
-                                       // Reset link and db here, close database first
-                                       SQL_CLOSE($link, __FILE__, __LINE__);
-                                       $link = false; $db = false;
-                               }
-
-                               // Free memory
-                               SQL_FREERESULT($result);
-
-                               // Generate random number
-                               if (isset($GLOBALS['userid'])) {
-                                       define('RAND_NUMBER', GEN_RANDOM_CODE(10, mt_rand(10000,32766), $GLOBALS['userid'], ""));
-                               } else {
-                                       define('RAND_NUMBER', GEN_RANDOM_CODE(10, mt_rand(10000,32766), 0, ""));
+                       if (SQL_SELECT_DB($GLOBALS['mysql']['dbase'], __FILE__, __LINE__) === true) {
+                               // This is required for extension 'optimize' to work
+                               setConfigEntry('__DB_NAME', $GLOBALS['mysql']['dbase']);
+
+                               // Remove MySQL array from namespace
+                               unset($GLOBALS['mysql']);
+
+                               // Load cache
+                               loadIncludeOnce('inc/load_cache.php');
+
+                               // Init filter system
+                               initFilterSystem();
+
+                               // Run the init filter chain
+                               runFilterChain('init');
+
+                               // Check module for permissions
+                               $checkModule = checkModulePermissions();
+
+                               // Admin module should be accessable by guests to login
+                               if ((getModule() == 'admin') && ($checkModule == 'admin_only')) {
+                                       // This is fine and can be ignored
+                               } elseif ($checkModule != 'done') {
+                                       // Not fine!
+                                       logDebugMessage(__FILE__, __LINE__, sprintf("Check of module %s results in unexpected value: %s",
+                                               getModule(),
+                                               $checkModule
+                                       ));
                                }
                        } else {
                                // Wrong database?
-                               ADD_FATAL(WRONG_DB_SELECTED);
+                               addFatalMessage(__FILE__, __LINE__, getMessage('WRONG_DB_SELECTED'));
                        }
                } else {
                        // No link to database!
-                       ADD_FATAL(NO_DB_LINK);
-                       $db = false;
+                       addFatalMessage(__FILE__, __LINE__, getMessage('NO_DB_LINK'));
                }
        } else {
                // Maybe you forgot to enter your MySQL data?
-               ADD_FATAL(MYSQL_DATA_MISSING);
+               addFatalMessage(__FILE__, __LINE__, getMessage('MYSQL_DATA_MISSING'));
        }
 } else {
        ///////////////////////////////////////////////////
        // Include neccessary functions for installation //
        ///////////////////////////////////////////////////
 
-       // Set CONFIG array
-       $_CONFIG = array(
-               'code_length' => 0
-       );
+       // Default output is 'direct' for HTML output
+       setConfigEntry('OUTPUT_MODE', 'direct');
+
+       // This hack prevents a backtrace in CSS output
+       if (getOutputMode() == 1) {
+               // Problem with config so set output mode
+               setConfigEntry('OUTPUT_MODE', 'render');
+       } // END - if
 
        // Set other missing variables
-       $link = false; // No database link by default
+       if (!isOutputModeSet()) setOutputMode(0);
 
-       // Include required files
-       require_once(PATH."inc/databases.php");
-       require_once(PATH."inc/theme-manager.php");
+       // Include more
+       foreach (array('inc/databases.php','inc/versions.php','inc/db/lib.php','inc/session.php','inc/install-functions.php','inc/load_config.php') as $inc) {
+               // Load the include
+               loadIncludeOnce($inc);
+       } // END - foreach
 
-       // Check if we are in installation routine
-       $installPhp = basename($_SERVER['PHP_SELF']);
-       if (($installPhp != "install.php") && ($CSS != "1") && ($CSS != -1)) {
-               // Redirect to the installation system
-               LOAD_URL("install.php");
-       }
+       // Load config
+       loadIncludeOnce('inc/load_config.php');
 
-       // Double-check installation mode
-       if ((!isBooleanConstantAndTrue('mxchange_installed')) || (!isBooleanConstantAndTrue('admin_registered'))) {
-               // Check for file permissions
-               if (!is_INCWritable("config")) {
-                       ADD_FATAL(CONFIG_IS_WRITE_PROTECTED);
-               }
-               if (!is_INCWritable("dummy")) {
-                       ADD_FATAL(DUMMY_IS_WRITE_PROTECTED);
-               }
-               if (!is_INCWritable(".secret/dummy")) {
-                       ADD_FATAL(SECRET_IS_WRITE_PROTECTED);
-               }
-       }
-}
+       // Are we installation routine?
+       if ((!isInstalling()) && (getOutputMode() != 1) && (getOutputMode() != -1)) {
+               // You have to install first!
+               redirectToUrl('install.php');
+       } // END - if
 
-// Any fatal messages?
-if (!is_array($FATAL)) $FATAL = array();
-if (((sizeof($FATAL) > 0) || (!empty($FATAL[0]))) && (isBooleanConstantAndTrue('mxchange_installed')) && (!isBooleanConstantAndTrue('mxchange_installing')) && ($CSS != "1"))
-{
-       // One or more fatal error(s) occur during connect...
-       include (PATH."inc/header.php");
-       include (PATH."inc/fatal_errors.php");
-       unset($FATAL);
-       include (PATH."inc/footer.php");
-       exit;
+       // Init filter system here
+       initFilterSystem();
+
+       // Load cache
+       loadIncludeOnce('inc/load_cache.php');
+
+       // Run the init filter chain
+       runFilterChain('init');
 }
 
-//
+// Handle fatal errors
+runFilterChain('handle_fatal_errors');
+
+// [EOF]
 ?>