Referal levels for surfbar added (unfinished)
[mailer.git] / ref.php
diff --git a/ref.php b/ref.php
index f4ee90afee8d6cefa90a7ad64d979a1c73c643f5..05321030896f7026537c2529a0af1a355580b907 100644 (file)
--- a/ref.php
+++ b/ref.php
@@ -37,8 +37,6 @@ require_once("inc/libs/security_functions.php");
 // Init "action" and "what"
 global $what, $action;
 $GLOBALS['what'] = ""; $GLOBALS['action'] = "";
-if (!empty($_GET['action'])) $GLOBALS['action'] = secureString($_GET['action']);
-if (!empty($_GET['what'])) $GLOBALS['what'] = secureString($_GET['what']);
 
 // Set module
 $GLOBALS['module'] = "ref"; $CSS = -1;
@@ -47,10 +45,10 @@ $GLOBALS['module'] = "ref"; $CSS = -1;
 require ("inc/config.php");
 
 // Redirect only to registration page when this script is installed
-if (defined('mxchange_installed') && (mxchange_installed))
+if (defined('mxchange_installed') && (isBooleanConstantAndTrue('mxchange_installed')))
 {
        // Base URL for redirection
-       switch ($CONFIG['refid_target'])
+       switch ($_CONFIG['refid_target'])
        {
        case "register":
                $URL = URL."/modules.php?module=index&what=register&refid=";
@@ -62,7 +60,7 @@ if (defined('mxchange_installed') && (mxchange_installed))
        }
 
        // Get referral ID from ref or refid variable
-       if (!empty($_GET['ref']))        $ref = strip_tags(htmlentities($_GET['ref']));
+       if (!empty($_GET['ref']))        $ref = secureString($_GET['ref']);
         elseif (!empty($_GET['refid'])) $ref = bigintval($_GET['refid']);
 
        if (!empty($ref))
@@ -76,6 +74,7 @@ if (defined('mxchange_installed') && (mxchange_installed))
                        list($ref) = SQL_FETCHROW($result);
                        SQL_FREERESULT($result);
                }
+
                // Also edit this 0 !
                if (empty($ref)) $ref = "0";
 
@@ -98,7 +97,7 @@ if (defined('mxchange_installed') && (mxchange_installed))
  else
 {
        // You have to configure first!
-       LOAD_URL(URL."/install.php");
+       LOAD_URL("install.php");
 }
 
 // Really all done here... ;-)