X-Git-Url: https://git.mxchange.org/?p=mailer.git;a=blobdiff_plain;f=inc%2Fmodules%2Fadmin%2Fwhat-list_payouts.php;h=e475a8408e4d0e71d9e9e2a45ea621a16f5d2353;hp=df76022cf6a82921972078cf09233b2480d633bc;hb=49acdb7a7adbcf25a8e8683b5581bfcec72b23bd;hpb=41d7cc2d4ab3b725d1cd2cbe022dd49fbfc0065a;ds=sidebyside diff --git a/inc/modules/admin/what-list_payouts.php b/inc/modules/admin/what-list_payouts.php index df76022cf6..e475a8408e 100644 --- a/inc/modules/admin/what-list_payouts.php +++ b/inc/modules/admin/what-list_payouts.php @@ -14,11 +14,10 @@ * $Date:: $ * * $Tag:: 0.2.1-FINAL $ * * $Author:: $ * - * Needs to be in all Files and every File needs "svn propset * - * svn:keywords Date Revision" (autoprobset!) at least!!!!!! * * -------------------------------------------------------------------- * * Copyright (c) 2003 - 2009 by Roland Haeder * - * For more information visit: http://www.mxchange.org * + * Copyright (c) 2009 - 2015 by Mailer Developer Team * + * For more information visit: http://mxchange.org * * * * This program is free software; you can redistribute it and/or modify * * it under the terms of the GNU General Public License as published by * @@ -42,248 +41,252 @@ if ((!defined('__SECURITY')) || (!isAdmin())) { } // END - if // Add description as navigation point -addMenuDescription('admin', __FILE__); +addYouAreHereLink('admin', __FILE__); -if (isGetRequestElementSet(('pid'))) { +if (isGetRequestElementSet('pid')) { // First let's get the member's id - $result = SQL_QUERY_ESC("SELECT userid, target_account, payout_total, payout_timestamp, password FROM `{?_MYSQL_PREFIX?}_user_payouts` WHERE `id`=%s LIMIT 1", - array(getRequestElement('pid')), __FILE__, __LINE__); - list($userid, $tuserid, $points, $tstamp, $tpass) = SQL_FETCHROW($result); - SQL_FREERESULT($result); + $result = sqlQueryEscaped("SELECT `userid`, `target_account`, `payout_total`, `payout_timestamp`, `password` FROM `{?_MYSQL_PREFIX?}_user_payouts` WHERE `id`=%s LIMIT 1", + array(getRequestElement('pid')), __FILE__, __LINE__); + list($userid, $tuserid, $points, $tstamp, $tpass) = sqlFetchRow($result); + sqlFreeResult($result); // Obtain some data - if (!isGetRequestElementSet(('task')) && (!empty($userid)) && ($userid > 0)) { + if (!isGetRequestElementSet('task') && (!empty($userid)) && (isValidId($userid))) { // Get task id from database - $result = SQL_QUERY_ESC("SELECT `id` FROM `{?_MYSQL_PREFIX?}_task_system` WHERE `userid`=%s AND `task_type`='PAYOUT_REQUEST' AND task_created='".$tstamp."' LIMIT 1", - array(bigintval($userid)), __FILE__, __LINE__); - list($task) = SQL_FETCHROW($result); - SQL_FREERESULT($result); - if (empty($task)) $task = '0'; - } elseif ((empty($userid)) || ($userid == '0')) { + $result = sqlQueryEscaped("SELECT `id` FROM `{?_MYSQL_PREFIX?}_task_system` WHERE `userid`=%s AND `task_type`='PAYOUT_REQUEST' AND `task_created`=%s LIMIT 1", + array(bigintval($userid), bigintval($tstamp)), __FILE__, __LINE__); + list($taskId) = sqlFetchRow($result); + sqlFreeResult($result); + if (empty($taskId)) $taskId = '0'; + } elseif (!isValidId($userid)) { // Cannot obtain member id! - loadTemplate('admin_settings_saved', false, getMessage('PAYOUT_FAILED_OBTAIN_USERID')); + displayMessage('{--ADMIN_PAYOUT_FAILED_OBTAIN_USERID--}'); } else { // Get task id from URL - $task = getRequestElement('task'); + $taskId = getRequestElement('task'); } - if ((!empty($task)) && (!empty($userid)) && ($userid > 0)) { + if ((!empty($taskId)) && (!empty($userid)) && (isValidId($userid))) { // Load user's data if (!fetchUserData($userid)) { // Abort here because it is not valid! - debug_report_bug('No user account ' . $userid . ' found.'); + reportBug(__FILE__, __LINE__, 'No user account ' . $userid . ' found.'); } // END - if - if ((getRequestElement('do') == 'accept') && (!empty(getUserData('email')))) { + if ((getRequestElement('do') == 'accept') && (getUserData('email') != '')) { // Ok, now we can output the form or execute accepting if (isFormSent()) { // Obtain payout type and other data - $result = SQL_QUERY_ESC("SELECT `payout_id` FROM `{?_MYSQL_PREFIX?}_user_payouts` WHERE `id`=%s LIMIT 1", + $result = sqlQueryEscaped("SELECT `payout_id` FROM `{?_MYSQL_PREFIX?}_user_payouts` WHERE `id`=%s LIMIT 1", array(bigintval(getRequestElement('pid'))), __FILE__, __LINE__); - list($ptype) = SQL_FETCHROW($result); - SQL_FREERESULT($result); + + // Load ptype (id) + list($ptype) = sqlFetchRow($result); + + // Free result + sqlFreeResult($result); if (!empty($ptype)) { // Obtain data from payout type - $result = SQL_QUERY_ESC("SELECT `from_account`, `from_pass`, `engine_url`, `engine_ret_ok`, `engine_ret_failed`, `pass_enc`, `allow_url` + $result = sqlQueryEscaped("SELECT + `from_account`, + `from_pass`, + `engine_url`, + `engine_ret_ok`, + `engine_ret_failed`, + `pass_enc`, + `allow_url` FROM `{?_MYSQL_PREFIX?}_payout_types` WHERE `id`=%s LIMIT 1", array(bigintval($ptype)), __FILE__, __LINE__); - list($fuserid, $fpass, $eurl, $eok, $failed, $eenc, $allow) = SQL_FETCHROW($result); - SQL_FREERESULT($result); - if (!empty($eurl)) { + // Load data + $data = sqlFetchArray($result); + + // Free result + sqlFreeResult($result); + + if (!empty($data['engine_url'])) { // Ok, run URL... - switch ($eenc) { + switch ($data['pass_enc']) { case 'md5': - $fpass = md5($fpass); + $data['from_pass'] = md5($data['from_pass']); $tpass = md5($tpass); break; case 'base64': - $fpass = base64_encode($fpass); + $data['from_pass'] = base64_encode($data['from_pass']); $tpass = base64_encode($tpass); break; - } + } // END - switch // Transfer variables... - $eval = "\$URL = \"".$eurl."\";"; - $reason = encodeString(getMessage('PAYOUT_REASON_PAYOUT'), false); - - // Run code... - // @TODO Do we need this time-consuming eval() here? - eval($eval); + $reason = encodeString(getMessage('ADMIN_PAYOUT_REASON'), FALSE); // Execute transfer - $ret = sendGetRequest($URL); + $ret = sendHttpGetRequest($data['engine_url']); } else { // No URL to run - $ret[0] = $eok; + $ret[0] = $data['engine_ret_ok']; } - if ($ret[0] == $eok) { + if ($ret[0] == $data['engine_ret_ok']) { // Clear task - if ($task > 0) { - runFilterChain('solve_task', $task); - } + if (isValidId($taskId)) { + runFilterChain('solve_task', $taskId); + } // END - if // Clear payout request - SQL_QUERY_ESC("UPDATE `{?_MYSQL_PREFIX?}_user_payouts` SET `status`='ACCEPTED' WHERE `id`=%s LIMIT 1", + sqlQueryEscaped("UPDATE `{?_MYSQL_PREFIX?}_user_payouts` SET `status`='ACCEPTED' WHERE `id`=%s LIMIT 1", array(bigintval(getRequestElement('pid'))), __FILE__, __LINE__); // Send out mail $message = loadEmailTemplate('member_payout_accepted', postRequestElement('text'), $userid); // Output message - if ($allow == 'Y') { + if ($data['allow_url'] == 'Y') { // Banner / Textlink request - loadTemplate('admin_settings_saved', false, getMessage('PAYOUT_BANNER_ACCEPTED_NOTIFIED')); + displayMessage('{--ADMIN_PAYOUT_BANNER_ACCEPTED_NOTIFIED--}'); } else { // Normal request - loadTemplate('admin_settings_saved', false, getMessage('PAYOUT_ACCEPTED_NOTIFIED')); + displayMessage('{--ADMIN_PAYOUT_ACCEPTED_NOTIFIED--}'); } // Finally send mail - sendEmail(getUserData('email'), getMessage('PAYOUT_ACCEPTED_SUBJECT'), $message); + sendEmail(getUserData('userid'), '{--MEMBER_PAYOUT_ACCEPTED_SUBJECT--}', $message); } else { // Something goes wrong... :-( - $content = implode("
", $ret); - loadTemplate('admin_payout_failed_transfer', false, $content); + $content = implode('
', $ret); + loadTemplate('admin_payout_failed_transfer', FALSE, $content); } } else { // Cannot load payout id - loadTemplate('admin_settings_saved', false, "
{--PAYOUT_FAILED_OBTAIN_PAYOUT_ID--}
"); + displayErrorMessage('{--ADMIN_PAYOUT_FAILED_OBTAIN_PAYOUT_ID--}'); } } else { // Prepare content $content = array( - 'task' => $task, + 'task' => $taskId, 'pid' => bigintval(getRequestElement('pid')), - 'user' => "".translateGender(getUserData('gender'))." ".getUserData('surname')." ".getUserData('family')."", + 'user' => '{%pipe,translateGender=' . getUserData('gender') . '%} ' . getUserData('surname') . ' ' . getUserData('family') . '', ); // Load template - loadTemplate('admin_payout_accept_form', false, $content); + loadTemplate('admin_payout_accept_form', FALSE, $content); } - } elseif ((getRequestElement('do') == 'reject') && (!empty(getUserData('email')))) { + } elseif ((getRequestElement('do') == 'reject') && (getUserData('email') != '')) { // Ok, now we can output the form or execute rejecting if (isFormSent()) { - if ($task > 0) { + if (isValidId($taskId)) { // Clear task - runFilterChain('solve_task', $task); + runFilterChain('solve_task', $taskId); } // END - if // Clear payout request - SQL_QUERY_ESC("UPDATE `{?_MYSQL_PREFIX?}_user_payouts` SET `status`='REJECTED' WHERE `id`=%s LIMIT 1", + sqlQueryEscaped("UPDATE `{?_MYSQL_PREFIX?}_user_payouts` SET `status`='REJECTED' WHERE `id`=%s LIMIT 1", array(bigintval(getRequestElement('pid'))), __FILE__, __LINE__); // Send out mail $message = loadEmailTemplate('member_payout_rejected', postRequestElement('text'), $userid); // Output message - loadTemplate('admin_settings_saved', false, getMessage('PAYOUT_REJECTED_NOTIFIED')); + displayMessage('{--ADMIN_PAYOUT_REJECTED_NOTIFIED--}'); // Finally send mail - sendEmail(getUserData('email'), getMessage('PAYOUT_REJECTED_SUBJECT'), $message); + sendEmail(getUserData('userid'), '{--MEMBER_PAYOUT_REJECTED_SUBJECT--}', $message); } else { // Prepare content $content = array( - 'task' => $task, + 'task' => $taskId, 'pid' => bigintval(getRequestElement('pid')), - 'user' => "".translateGender(getUserData('gender'))." ".getUserData('surname')." ".getUserData('family')."", + 'user' => '{%pipe,translateGender=' . getUserData('gender') . '%} ' . getUserData('surname') . ' ' . getUserData('family') . '', ); // Load template - loadTemplate('admin_payout_reject_form', false, $content); + loadTemplate('admin_payout_reject_form', FALSE, $content); } } else { // Cannot load user data - loadTemplate('admin_settings_saved', false, getMessage('PAYOUT_FAILED_OBTAIN_USERDATA')); + displayMessage('{--ADMIN_PAYOUT_FAILED_OBTAIN_USERDATA--}'); } - } elseif ((empty($task)) || ($task == '0')) { + } elseif (!isValidId($taskId)) { // Failed loading task id - loadTemplate('admin_settings_saved', false, getMessage('PAYOUT_FAILED_OBTAIN_TASK_ID')); + displayMessage('{--ADMIN_PAYOUT_FAILED_OBTAIN_TASK_ID--}'); } } else { if (getRequestElement('do') == 'delete') { // Delete all requests - $result = SQL_QUERY("TRUNCATE `{?_MYSQL_PREFIX?}_user_payouts`", __FILE__, __LINE__); + $result = sqlQuery("TRUNCATE `{?_MYSQL_PREFIX?}_user_payouts`", __FILE__, __LINE__); } // END - if // Search for payouts - $result = SQL_QUERY("SELECT - p.id, p.userid, p.payout_total, p.target_account, - p.target_bank, t.type, p.payout_timestamp, p.status, - t.allow_url AS allow, p.target_url AS url, p.link_text AS alt, - p.banner_url AS banner + $result = sqlQuery('SELECT + `p`.`id`, + `p`.`userid`, + `p`.`payout_total`, + `p`.`target_account`, + `p`.`target_bank`, + `t`.`type`, + `p`.`payout_timestamp`, + `p`.`status`, + `t`.`allow_url` + `p`.`target_url`, + `p`.`link_text` + `p`.`banner_url` FROM - `{?_MYSQL_PREFIX?}_user_payouts` AS p + `{?_MYSQL_PREFIX?}_user_payouts` AS `p` LEFT JOIN - `{?_MYSQL_PREFIX?}_payout_types` AS t + `{?_MYSQL_PREFIX?}_payout_types` AS `t` ON - p.payout_id=t.id + `p`.`payout_id`=`t`.`id` ORDER BY - p.payout_timestamp DESC", __FILE__, __LINE__); + `p`.`payout_timestamp` DESC', __FILE__, __LINE__); - if (SQL_NUMROWS($result) > 0) { + if (!ifSqlHasZeroNumRows($result)) { // List found payouts - $OUT = ''; $SW = 2; - while ($content = SQL_FETCHARRAY($result)) { + $OUT = ''; + while ($content = sqlFetchArray($result)) { if ($content['status'] == 'NEW') { // Generate links for direct accepting and rejecting - $content['status'] = "".PAYOUT_ACCEPT_PAYOUT." | ".PAYOUT_REJECT_PAYOUT.""; + $content['status'] = '{--ADMIN_PAYOUT_ACCEPT_PAYOUT--}|{--ADMIN_PAYOUT_REJECT_PAYOUT--}'; } else { // Translate status - $content['status'] = getMessage('PAYOUT_STATUS_'.strtoupper($content['status']).''); - $content['status'] = "
".$content['status']."
"; + $content['status'] = translatePayoutStatus($content['status']); } // Nothing entered must be secured in member/what-payputs.php ! - if ($content['allow'] == 'Y') { + if ($content['allow_url'] == 'Y') { // Banner/Textlink views/clicks request - if (!empty($content['banner'])) { + if (!empty($content['banner_url'])) { // Load template for the banner - $content['target_account'] = loadTemplate('admin_list_payouts_banner', true, $content); + $content['target_account'] = loadTemplate('admin_list_payouts_banner', TRUE, $content); } else { // Textlink - $content['target_account'] = loadTemplate('admin_list_payouts_txt', true, $content); + $content['target_account'] = loadTemplate('admin_list_payouts_txt', TRUE, $content); } // Admins can addionally test the URL for framekillers - $content['target_bank'] = "{--CLICK_HERE--}"; - } else { - // e-currency payout request - if (empty($content['target_account'])) $content['target_account'] = '---'; - if (empty($content['target_bank'])) $content['target_bank'] = '---'; - } + $content['target_bank'] = '{--CLICK_HERE--}'; + } // END - if - // Remember data in array for the template - $content = array( - 'sw' => $SW, - 'ulink' => generateUserProfileLink($content['userid']), - 'ptype' => translateComma($content['payout_total']) . ' ' . $content['type'], - 'account' => $content['target_account'], - 'bank' => $content['target_bank'], - 'tstamp' => generateDateTime($content['payout_timestamp'], 2), - 'status' => $content['status'], - ); + // Add/Translate some data + $content['payout_timestamp'] = generateDateTime($content['payout_timestamp'], 2); // Add row and switch color - $OUT .= loadTemplate('admin_list_payouts_row', true, $content); - $SW = 3 - $SW; - } + $OUT .= loadTemplate('admin_list_payouts_row', TRUE, $content); + } // END - while // Free memory - SQL_FREERESULT($result); + sqlFreeResult($result); // Load final template - loadTemplate('admin_list_payouts', false, $OUT); + loadTemplate('admin_list_payouts', FALSE, $OUT); } else { // No payout requests are sent so far - loadTemplate('admin_settings_saved', false, getMessage('PAYOUT_ADMIN_NO_REQUESTS_FOUND')); + displayMessage('{--ADMIN_PAYOUT_NO_REQUESTS_FOUND--}'); } }