Version 3.0.5

This commit is contained in:
Neo committed 2025-12-19 00:31:03 -08:00
1 parent 19b38c7c74
commit 1d4720f3e2
3755 files changed
+508378 -664541

No files matched your search

@@ -0,0 +1,30 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Define the default ajax section
* Last Updated: $Date: 2009-07-28 20:26:37 -0400 (Tue, 28 Jul 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @since 20th February 2002
* @version $Rev: 4948 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
/**
* Very simply returns the default section if one is not
* passed in the URL
*/
$DEFAULT_SECTION = 'editform';
@@ -0,0 +1,664 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Member property updater (AJAX)
* Last Updated: $Date: 2009-12-04 21:38:22 -0500 (Fri, 04 Dec 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5521 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class admin_members_ajax_editform extends ipsAjaxCommand
{
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
$this->registry->class_localization->loadLanguageFile( array( 'admin_member' ), 'members' );
switch( $this->request['do'] )
{
default:
case 'show':
$this->show();
break;
case 'save_display_name':
$this->save_member_name( 'members_display_name' );
break;
case 'save_name':
$this->save_member_name( 'name' );
break;
case 'save_password':
$this->save_password();
break;
case 'save_email':
$this->save_email();
break;
case 'remove_photo':
$this->remove_photo();
break;
}
}
/**
* Remove user's photo
*
* @access protected
* @return void [Outputs to screen]
*/
protected function remove_photo()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$member_id = intval( $this->request['member_id'] );
//-----------------------------------------
// Get member
//-----------------------------------------
$member = IPSMember::load( $member_id );
if ( ! $member['member_id'] )
{
$this->returnJsonError( $this->lang->words['m_noid'] );
exit();
}
//-----------------------------------------
// Allowed to upload pics for administrators?
//-----------------------------------------
if( $member['g_access_cp'] AND !$this->registry->getClass('class_permissions')->checkPermission( 'member_photo_admin', 'members', 'members' ) )
{
$this->returnJsonError( $this->lang->words['m_editadmin'] );
exit();
}
//-----------------------------------------
// Sort out upload dir
//-----------------------------------------
/* Fix for bug 5075 */
$this->settings[ 'upload_dir'] = str_replace( '&#46;', '.', $this->settings['upload_dir'] );
$upload_path = $this->settings['upload_dir'];
//-----------------------------------------
// Already a dir?
//-----------------------------------------
if ( file_exists( $upload_path . "/profile" ) )
{
# Set path and dir correct
$upload_path .= "/profile";
$upload_dir = "profile/";
}
IPSMember::getFunction()->removeUploadedPhotos( $member_id, $upload_path );
IPSMember::save( $member_id, array( 'extendedProfile' => array( 'pp_main_photo' => '',
'pp_main_width' => 0,
'pp_main_height' => 0,
'pp_thumb_photo' => '',
'pp_thumb_width' => 0,
'pp_thumb_height' => 0,
) ) );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf($this->lang->words['m_imgremlog'], $member_id ) );
$member = IPSMember::load( $member_id );
$member = IPSMember::buildDisplayData( $member, 0 );
//-----------------------------------------
// Return
//-----------------------------------------
$this->returnJsonArray( array(
'success' => TRUE,
'pp_main_photo' => $member['pp_main_photo'],
'pp_main_width' => $member['pp_main_width'],
'pp_main_height' => $member['pp_main_height']
) );
}
/**
* Change a member's email address
*
* @access protected
* @return void [Outputs to screen]
*/
protected function save_email()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$member_id = intval( $this->request['member_id'] );
$email = trim( $this->request['email'] );
//-----------------------------------------
// Get member
//-----------------------------------------
$member = IPSMember::load( $member_id );
if ( ! $member['member_id'] )
{
$this->returnJsonError( $this->lang->words['m_noid'] );
exit();
}
//-----------------------------------------
// Allowed to edit administrators?
//-----------------------------------------
if( $member['g_access_cp'] AND !$this->registry->getClass('class_permissions')->checkPermission( 'member_edit_admin', 'members', 'members' ) )
{
$this->returnJsonError( $this->lang->words['m_editadmin'] );
exit();
}
//-----------------------------------------
// Is this email addy taken? CONVERGE THIS??
//-----------------------------------------
$email_check = IPSMember::load( mb_strtolower($email) );
if ( $email_check['member_id'] AND $email_check['member_id'] != $member_id )
{
$this->returnJsonError( $this->lang->words['m_emailalready'] );
exit();
}
//-----------------------------------------
// Load handler...
//-----------------------------------------
require_once( IPS_ROOT_PATH . 'sources/handlers/han_login.php' );
$han_login = new han_login( $this->registry );
$han_login->init();
$han_login->changeEmail( trim( mb_strtolower( $member['email'] ) ), trim( mb_strtolower( $email ) ) );
//-----------------------------------------
// We don't want to die just from a Converge error
//-----------------------------------------
/*if ( $han_login->return_code AND ( $han_login->return_code != 'METHOD_NOT_DEFINED' AND $han_login->return_code != 'SUCCESS' ) )
{
$this->returnJsonError( $this->lang->words['m_emailalready'] );
exit();
}*/
//-----------------------------------------
// Update member
//-----------------------------------------
IPSMember::save( $member_id, array( 'core' => array( 'email' => mb_strtolower( $email ) ) ) );
IPSLib::runMemberSync( 'onEmailChange', $member_id, mb_strtolower( $email ) );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['m_emailchangelog'], $member['email'], $email, $member_id ) );
$this->returnJsonArray( array(
'success' => TRUE,
'email' => $email
) );
}
/**
* Change a member's password
*
* @access protected
* @return void [Outputs to screen]
*/
protected function save_password()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$member_id = intval( $this->request['member_id'] );
$password = IPSText::parseCleanValue( urldecode( $_REQUEST['password'] ) );
$password2 = IPSText::parseCleanValue( urldecode( $_REQUEST['password2'] ) );
$new_key = intval( $this->request['new_key'] );
$new_salt = intval( $this->request['new_salt'] );
$salt = str_replace( '\\', "\\\\", IPSMember::generatePasswordSalt(5) );
$key = IPSMember::generateAutoLoginKey();
$md5_once = md5( trim($password) );
//-----------------------------------------
// Check
//-----------------------------------------
if ( ! $password OR ! $password2 )
{
$this->returnJsonError( $this->lang->words['password_nogood'] );
exit();
}
if ( $password != $password2 )
{
$this->returnJsonError( $this->lang->words['m_passmatch'] );
exit();
}
//-----------------------------------------
// Get member
//-----------------------------------------
$member = IPSMember::load( $member_id );
//-----------------------------------------
// Allowed to edit administrators?
//-----------------------------------------
if( $member['g_access_cp'] AND !$this->registry->getClass('class_permissions')->checkPermission( 'member_edit_admin', 'members', 'members' ) )
{
$this->returnJsonError( $this->lang->words['m_editadmin'] );
exit();
}
//-----------------------------------------
// Check Converge: Password
//-----------------------------------------
require_once( IPS_ROOT_PATH . 'sources/handlers/han_login.php' );
$han_login = new han_login( $this->registry );
$han_login->init();
$han_login->changePass( $member['email'], $md5_once );
/*if ( $han_login->return_code != 'METHOD_NOT_DEFINED' AND $han_login->return_code != 'SUCCESS' )
{
$this->returnJsonError( $this->lang->words['m_passchange']);
exit();
}*/
//-----------------------------------------
// Local DB
//-----------------------------------------
$update = array();
if( $new_salt )
{
$update['members_pass_salt'] = $salt;
}
if( $new_key )
{
$update['member_login_key'] = $key;
}
if( count($update) )
{
IPSMember::save( $member_id, array( 'core' => $update ) );
}
IPSMember::updatePassword( $member_id, $md5_once );
IPSLib::runMemberSync( 'onPassChange', $member_id, $password );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['m_passlog'], $member_id ) );
$this->returnJsonArray( array(
'success' => TRUE,
'password' => "*************"
) );
}
/**
* Update a user's login or display name
*
* @access protected
* @param string Field to update
* @return void [Outputs to screen]
*/
protected function save_member_name( $field='members_display_name' )
{
$member_id = intval( $this->request['member_id'] );
$member = IPSMember::load( $member_id );
//-----------------------------------------
// Allowed to edit administrators?
//-----------------------------------------
if( $member['g_access_cp'] AND !$this->registry->getClass('class_permissions')->checkPermission( 'member_edit_admin', 'members', 'members' ) )
{
$this->returnJsonError( $this->lang->words['m_editadmin'] );
exit();
}
if ( $field == 'members_display_name' )
{
$display_name = $this->convertAndMakeSafe( $_POST['display_name'], 1 );
$display_name = str_replace("&#43;", "+", $display_name );
}
else
{
$display_name = $this->convertAndMakeSafe( $_POST['name'], 1 );
$display_name = str_replace("&#43;", "+", $display_name );
$display_name = str_replace( '|', '&#124;' , $display_name );
$display_name = trim( preg_replace( "/\s{2,}/", " ", $display_name ) );
}
if ( $this->settings['strip_space_chr'] )
{
// use hexdec to convert between '0xAD' and chr
$display_name = IPSText::removeControlCharacters( $display_name );
}
if ( $field == 'members_display_name' AND preg_match( "#[\[\];,\|]#", str_replace('&#39;', "'", str_replace('&amp;', '&', $members_display_name) ) ) )
{
$this->returnJsonError($this->lang->words['m_displaynames']);
}
try
{
if ( IPSMember::getFunction()->updateName( $member_id, $display_name, $field ) === TRUE )
{
if ( $field == 'members_display_name' )
{
ipsRegistry::getClass('adminFunctions')->saveAdminLog(sprintf( $this->lang->words['m_dnamelog'], $member['members_display_name'], $display_name ));
}
else
{
ipsRegistry::getClass('adminFunctions')->saveAdminLog(sprintf( $this->lang->words['m_namelog'], $member['name'], $display_name ) );
//-----------------------------------------
// If updating a name, and display names
// disabled, update display name too
//-----------------------------------------
if( !ipsRegistry::$settings['auth_allow_dnames'] )
{
IPSMember::getFunction()->updateName( $member_id, $display_name, 'members_display_name' );
}
//-----------------------------------------
// I say, did we choose to email 'dis member?
//-----------------------------------------
if ( $this->request['send_email'] == 1 )
{
//-----------------------------------------
// By golly, we did!
//-----------------------------------------
$msg = trim( IPSText::stripslashes( nl2br( $_POST['email_contents'] ) ) );
$msg = str_replace( "{old_name}", $member['name'], $msg );
$msg = str_replace( "{new_name}", $display_name , $msg );
$msg = str_replace( "<#BOARD_NAME#>", $this->settings['board_name'], $msg );
$msg = str_replace( "<#BOARD_ADDRESS#>", $this->settings['board_url'] . '/index.' . $this->settings['php_ext'], $msg );
IPSText::getTextClass('email')->message = stripslashes( IPSText::getTextClass('email')->cleanMessage($msg) );
IPSText::getTextClass('email')->subject = $this->lang->words['m_changesubj'];
IPSText::getTextClass('email')->to = $member['email'];
IPSText::getTextClass('email')->sendMail();
}
}
$this->cache->rebuildCache( 'stats', 'global' );
}
else
{
# We should absolutely never get here. So this is a fail-safe, really to
# prevent a "false" positive outcome for the end-user
$this->returnJsonError($this->lang->words['m_namealready']);
}
}
catch( Exception $error )
{
$this->returnJsonError( $error->getMessage() );
switch( $error->getMessage() )
{
case 'NO_USER':
$this->returnJsonError( $this->lang->words['m_noid'] );
break;
case 'NO_PERMISSION':
case 'NO_NAME':
$this->returnJsonError( sprintf($this->lang->words['m_morethan3'], $this->settings['max_user_name_length'] ) );
break;
case 'ILLEGAL_CHARS':
$this->returnJsonError( $this->lang->words['m_illegal'] );
break;
case 'USER_NAME_EXISTS':
$this->returnJsonError( $this->lang->words['m_namealready'] );
break;
default:
$this->returnJsonError( $error->getMessage() );
break;
}
}
//-----------------------------------------
// Load handler...
//-----------------------------------------
if( $field == 'name' )
{
require_once( IPS_ROOT_PATH . 'sources/handlers/han_login.php' );
$han_login = new han_login( $this->registry );
$han_login->init();
$han_login->changeName( $member['name'], $display_name, $member['email'] );
}
else
{
IPSLib::runMemberSync( 'onNameChange', $member_id, $display_name );
}
$__display_name = addslashes( $display_name );
$this->returnJsonArray( array(
'success' => TRUE,
'display_name' => "$__display_name"
) );
}
/**
* Show the form
*
* @access protected
* @return void [Outputs to screen]
*/
protected function show()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$name = trim( IPSText::alphanumericalClean( $this->request['name'] ) );
$member_id = intval( $this->request['member_id'] );
$output = '';
//-----------------------------------------
// Load language and skin
//-----------------------------------------
$html = $this->registry->output->loadTemplate('cp_skin_member_form');
$this->lang->loadLanguageFile( array( 'admin_member' ) );
//-----------------------------------------
// Get member data
//-----------------------------------------
$member = IPSMember::load( $member_id, 'extendedProfile,customFields' );
//-----------------------------------------
// Got a member?
//-----------------------------------------
if ( ! $member['member_id'] )
{
$this->returnJsonError( $this->lang->words['m_noid'] );
}
//-----------------------------------------
// Return the form
//-----------------------------------------
if ( method_exists( $html, $name ) )
{
$output = $html->$name( $member );
}
else
{
$save_to = '';
$div_id = '';
$form_field = '';
$text = '';
$description = '';
$method = '';
switch( $name )
{
/*case 'inline_warn_level':
$method = 'inline_form_generic';
$save_to = 'save_generic&amp;field=warn_level';
$div_id = 'warn_level';
$form_field = ipsRegistry::getClass('output')->formInput( "generic__field", $member['warn_level'] );
$text = "Member Warn Level";
$description = "Make adjustments to the member's overall warn level. This does NOT add a warn log record - you should do so manually using the 'Add New Note' link if you wish to store a log of this adjustment";
break;*/
case 'inline_ban_member':
if( !$this->registry->getClass('class_permissions')->checkPermission( 'member_ban', 'members', 'members' ) )
{
$this->returnJsonError($this->lang->words['m_noban']);
}
if( $member['g_access_cp'] AND !$this->registry->getClass('class_permissions')->checkPermission( 'member_ban_admin', 'members', 'members' ) )
{
$this->returnJsonError($this->lang->words['m_noban']);
}
//-----------------------------------------
// INIT
//-----------------------------------------
$ban_filters = array( 'email' => array(), 'name' => array(), 'ip' => array() );
$email_banned = false;
$ip_banned = array();
$name_banned = false;
//-----------------------------------------
// Grab existing ban filters
//-----------------------------------------
$this->DB->build( array( 'select' => '*', 'from' => 'banfilters' ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$ban_filters[ $r['ban_type'] ][] = $r['ban_content'];
}
//-----------------------------------------
// Check name and email address
//-----------------------------------------
if( in_array( $member['email'], $ban_filters['email'] ) )
{
$email_banned = true;
}
if( in_array( $member['name'], $ban_filters['name'] ) )
{
$name_banned = true;
}
//-----------------------------------------
// Retrieve IP addresses
//-----------------------------------------
$ip_addresses = IPSMember::findIPAddresses( $member['member_id'] );
//-----------------------------------------
// Start form fields
//-----------------------------------------
$form['member'] = ipsRegistry::getClass('output')->formCheckbox( "ban__member", $member['member_banned'] );
$form['email'] = ipsRegistry::getClass('output')->formCheckbox( "ban__email", $email_banned );
$form['name'] = ipsRegistry::getClass('output')->formCheckbox( "ban__name", $name_banned );
$form['note'] = ipsRegistry::getClass('output')->formCheckbox( "ban__note", 0 );
$form['note_field'] = ipsRegistry::getClass('output')->formTextarea( "ban__note_field" );
$form['ips'] = array();
//-----------------------------------------
// What about IPs?
//-----------------------------------------
if( is_array($ip_addresses) AND count($ip_addresses) )
{
foreach( $ip_addresses as $ip_address => $count )
{
if( in_array( $ip_address, $ban_filters['ip'] ) )
{
$form['ips'][ $ip_address ] = ipsRegistry::getClass('output')->formCheckbox( "ban__ip_" . str_replace( '.', '_', $ip_address ), true );
}
else
{
$form['ips'][ $ip_address ] = ipsRegistry::getClass('output')->formCheckbox( "ban__ip_" . str_replace( '.', '_', $ip_address ), false );
}
}
}
$member_groups = array();
foreach( ipsRegistry::cache()->getCache('group_cache') as $group )
{
if( $group['g_id'] == $member['member_group_id'] )
{
$member['_group_title'] = $group['g_title'];
}
$member_groups[] = array( $group['g_id'], $group['g_title'] );
}
$form['groups_confirm'] = ipsRegistry::getClass('output')->formCheckbox( "ban__group_change", 0 );
$form['groups'] = ipsRegistry::getClass('output')->formDropdown( "ban__group", $member_groups, $member['member_group_id'] );
$output = $html->inline_ban_member_form( $member, $form );
break;
}
if( !$output AND $method AND method_exists( $html, $method ) )
{
$output = $html->$method( $member, $save_to, $div_id, $form_field, $text, $description );
}
}
//-----------------------------------------
// Print...
//-----------------------------------------
$this->returnHtml( $output );
}
}
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,839 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Bulk mail management
* Last Updated: $Date: 2009-09-22 11:55:32 -0400 (Tue, 22 Sep 2009) $
*
* @author $Author: matt $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5139 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly.";
exit();
}
class admin_members_bulkmail_bulkmail extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
//-----------------------------------------
// Load skin
//-----------------------------------------
$this->html = $this->registry->output->loadTemplate('cp_skin_bulkmail');
//-----------------------------------------
// Set up stuff
//-----------------------------------------
$this->form_code = $this->html->form_code = 'module=bulkmail&amp;section=bulkmail';
$this->form_code_js = $this->html->form_code_js = 'module=bulkmail&section=bulkmail';
//-----------------------------------------
// Load lang
//-----------------------------------------
ipsRegistry::getClass('class_localization')->loadLanguageFile( array( 'admin_bulkmail' ) );
switch( $this->request['do'] )
{
case 'mail_new':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_addedit' );
$this->_mailForm('add');
break;
case 'mail_edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_addedit' );
$this->_mailForm('edit');
break;
case 'mail_save':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_addedit' );
$this->_mailSave();
break;
case 'mail_preview':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_view' );
$this->_mailPreviewStart();
break;
case 'mail_preview_do':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_view' );
$this->_mailPreviewComplete();
break;
case 'mail_send_start':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_send' );
$this->_mailSendStart();
break;
case 'mail_send_complete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_send' );
$this->_mailSendComplete();
break;
case 'mail_send_cancel':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_cancel' );
$this->_mailSendCancel();
break;
case 'mail_delete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_delete' );
$this->_mailDelete();
break;
default:
case 'bulk_mail':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'bulkmail_view' );
$this->_mailStart();
break;
}
//-----------------------------------------
// Pass to CP output hander
//-----------------------------------------
$this->registry->getClass('output')->html_main .= $this->registry->getClass('output')->global_template->global_frame_wrapper();
$this->registry->getClass('output')->sendOutput();
}
/**
* Delete a bulk mail
*
* @access private
* @return void [Outputs to screen]
*/
private function _mailDelete()
{
$id = intval( $this->request['id'] );
$active = $this->DB->buildAndFetch( array( 'select' => 'mail_id', 'from' => 'bulk_mail', 'where' => 'mail_active=1 AND mail_id <>' . $id ) );
if( !$active['mail_id'] )
{
$this->DB->update( 'task_manager', array( 'task_enabled' => 0 ), "task_key='bulkmail'" );
}
$this->DB->delete( 'bulk_mail', 'mail_id=' . $id );
$this->registry->output->global_message = $this->lang->words['b_deleted'];
$this->_mailStart();
}
/**
* Cancels a bulk mail
*
* @access private
* @return void [Outputs to screen]
*/
private function _mailSendCancel()
{
$this->DB->update( 'bulk_mail', array( 'mail_active' => 0,
'mail_updated' => time(),
), "mail_active=1" );
$this->DB->update( 'task_manager', array( 'task_enabled' => 0 ), "task_key='bulkmail'" );
$this->registry->output->global_message = $this->lang->words['b_cancelled'];
$this->_mailStart();
}
/**
* Processes a bulk mail
*
* @access public
* @return void
*/
public function mailSendProcess()
{
//-----------------------------------------
// Set up
//-----------------------------------------
$done = 0;
$sent = 0;
//-----------------------------------------
// Get it from the db
//-----------------------------------------
$mail = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'bulk_mail', 'where' => 'mail_active=1' ) );
if ( ! $mail['mail_subject'] and ! $mail['mail_content'] )
{
$done = 1;
}
//-----------------------------------------
// Per go...
//-----------------------------------------
$pergo = intval($mail['mail_pergo']);
if ( ! $pergo or $pergo > 1000 )
{
$pergo = 50;
}
//-----------------------------------------
// So far...
//-----------------------------------------
$sofar = intval($mail['mail_sentto']);
$mail['mail_content'] = IPSText::stripslashes( $mail['mail_content'] );
$mail['mail_subject'] = IPSText::stripslashes( $mail['mail_subject'] );
//-----------------------------------------
// Unconvert options
//-----------------------------------------
$opts = unserialize( stripslashes( $mail['mail_opts'] ) );
foreach( $opts as $k => $v )
{
$mail[ $k ] = $v;
}
if ( $mail['mail_html_on'] )
{
$this->settings['html_email'] = 1;
}
//-----------------------------------------
// Format the query
//-----------------------------------------
$query = $this->_buildMembersQuery( $mail );
//-----------------------------------------
// Clear out any other temp headers
//-----------------------------------------
IPSText::getTextClass('email')->clearHeaders();
//-----------------------------------------
// Now get members....
//-----------------------------------------
$this->DB->build( array( 'select' => '*',
'from' => 'members',
'where' => $query,
'order' => 'member_id',
'limit' => array( $sofar, $pergo ) ) );
$o = $this->DB->execute();
while ( $r = $this->DB->fetch( $o ) )
{
$sent++;
$contents = $this->_convertQuicktags( $mail['mail_content'], $r );
IPSText::getTextClass('email')->from = $this->settings['email_out'];
IPSText::getTextClass('email')->to = $r['email'];
IPSText::getTextClass('email')->message = str_replace( "\r\n", "\n", $contents );
IPSText::getTextClass('email')->subject = $mail['mail_subject'];
IPSText::getTextClass('email')->setHeader( 'Precedence', 'bulk' );
IPSText::getTextClass('email')->sendMail();
}
//-----------------------------------------
// Did we send any?
//-----------------------------------------
if ( ! $sent )
{
$done = 1;
}
$this->settings['html_email'] = 0;
//-----------------------------------------
// Save out..
//-----------------------------------------
if ( $done )
{
$this->DB->update( 'bulk_mail', array( 'mail_active' => 0,
'mail_updated' => time(),
'mail_sentto' => $sofar + $sent
), 'mail_id=' . $mail['mail_id'] );
$this->DB->update( 'task_manager', array( 'task_enabled' => 0 ), "task_key='bulkmail'" );
}
else
{
$this->DB->update( 'bulk_mail', array( 'mail_updated' => time(),
'mail_sentto' => $sofar + $sent
), 'mail_id=' . $mail['mail_id'] );
}
}
/**
* Complete bulk mail processing
*
* @access private
* @return void
*/
private function _mailSendComplete()
{
$pergo = intval( $this->request['pergo'] );
$id = intval( $this->request['id'] );
if ( ! $id )
{
$this->registry->output->global_message = $this->lang->words['b_norecord'];
$this->_mailStart();
return;
}
//-----------------------------------------
// Get it from the db
//-----------------------------------------
$mail = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'bulk_mail', 'where' => 'mail_id=' . $id ) );
if ( ! $mail['mail_subject'] and ! $mail['mail_content'] )
{
$this->registry->output->global_message = $this->lang->words['b_nosend'];
$this->_mailStart();
return;
}
//-----------------------------------------
// Update mail
//-----------------------------------------
if ( ! $pergo or $pergo > 1000 )
{
$pergo = 50;
}
$this->DB->update( 'bulk_mail', array( 'mail_active' => 1, 'mail_pergo' => $pergo, 'mail_sentto' => 0, 'mail_start' => time() ), 'mail_id=' . $id );
$this->DB->update( 'bulk_mail', array( 'mail_active' => 0 ) , 'mail_id <> ' . $id );
//-----------------------------------------
// Wake up task manager
//-----------------------------------------
require_once( IPS_ROOT_PATH . 'sources/classes/class_taskmanager.php' );
$task = new class_taskmanager( $this->registry );
$this->DB->update( 'task_manager', array( 'task_enabled' => 1 ), "task_key='bulkmail'" );
$this_task = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'task_manager', 'where' => "task_key='bulkmail'" ) );
$newdate = $task->generateNextRun( $this_task );
$this->DB->update( 'task_manager', array( 'task_next_run' => $newdate ), "task_id=".$this_task['task_id'] );
$task->saveNextRunStamp();
//-----------------------------------------
// Sit back and watch the show
//-----------------------------------------
$this->registry->output->global_message = $this->lang->words['b_initiated'];
$this->_mailStart();
}
/**
* Start the sending of the bulk mail
*
* @access private
* @return void
*/
private function _mailSendStart()
{
$id = intval($this->request['id']);
if ( ! $id )
{
$this->registry->output->global_message = $this->lang->words['b_noid'];
$this->_mailStart();
return;
}
//-----------------------------------------
// Get it from the db
//-----------------------------------------
$mail = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'bulk_mail', 'where' => 'mail_id=' . $id ) );
if ( ! $mail['mail_subject'] and ! $mail['mail_content'] )
{
$this->registry->output->global_message = $this->lang->words['b_nosend'];
$this->_mailStart();
return;
}
//-----------------------------------------
// Unconvert options
//-----------------------------------------
$opts = unserialize( stripslashes( $mail['mail_opts'] ) );
foreach( $opts as $k => $v )
{
$mail[ $k ] = $v;
}
//-----------------------------------------
// Format the query
//-----------------------------------------
$query = $this->_buildMembersQuery( $mail );
//-----------------------------------------
// Count how many matches
//-----------------------------------------
$count = $this->DB->buildAndFetch( array( 'select' => 'count(*) as cnt', 'from' => 'members', 'where' => $query ) );
$the_count = intval( $count['cnt'] );
//-----------------------------------------
// Print 'continue' screen
//-----------------------------------------
$this->registry->output->html .= $this->html->mailSendStart( $mail, $the_count );
}
/**
* Process the sending of the bulk mail
*
* @access private
* @return void
*/
private function _mailPreviewComplete()
{
$id = intval($this->request['id']);
$content = "";
//-----------------------------------------
// Grab content and format it
//-----------------------------------------
if( $id )
{
//-----------------------------------------
// Get it from the db
//-----------------------------------------
$mail = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'bulk_mail', 'where' => 'mail_id=' . $id ) );
$content = $this->_convertQuickTags( IPSText::stripslashes($mail['mail_content']), $this->memberData );
$mailopts = unserialize( $mail['mail_opts'] );
if( $mailopts['mail_html_on'] == 0 )
{
$content = nl2br( htmlspecialchars( $content, ENT_QUOTES ) );
}
}
else
{
if( $_POST['html'] )
{
$content = $this->_convertQuickTags( IPSText::stripslashes($_POST['text']), $this->memberData );
}
else
{
$content = nl2br( htmlspecialchars( $this->_convertQuickTags( IPSText::stripslashes($_POST['text']), $this->memberData ), ENT_QUOTES) );
}
}
//-----------------------------------------
// Print headers and content (to iframe)
//-----------------------------------------
header("Content-Disposition: inline");
ob_end_clean();
$this->registry->output->html .= $this->html->mailIframeContent( $content );
$this->registry->output->printPopupWindow();
exit();
}
/**
* Preview the email (javascript popup)
*
* @access private
* @return void
*/
private function _mailPreviewStart()
{
$this->registry->output->html .= $this->html->mailPopupContent();
$this->registry->output->printPopupWindow();
exit();
}
/**
* Save the new or edited bulk mail
*
* @access private
* @return void
*/
private function _mailSave()
{
//-----------------------------------------
// Set up
//-----------------------------------------
$ids = array();
$id = intval($this->request['id']);
$type = $this->request['type'];
//-----------------------------------------
// Start
//-----------------------------------------
if ( ! $this->request['mail_subject'] or ! $this->request['mail_content'] )
{
$this->registry->output->global_message = $this->lang->words['b_entercont'];
$this->_mailForm( $type );
return;
}
//-----------------------------------------
// Groups...
//-----------------------------------------
foreach( $_POST as $key => $value )
{
if( preg_match( "/^sg_(\d+)$/", $key, $match ) )
{
if( $this->request[ $match[0] ] AND $value )
{
$ids[] = $match[1];
}
}
}
$ids = IPSLib::cleanIntArray( $ids );
if( ! count( $ids ) )
{
$this->registry->output->global_message = $this->lang->words['b_nogroups'];
$this->_mailForm( $type );
return;
}
$this->request[ 'mail_groups'] = implode( ",", $ids );
//-----------------------------------------
// Format the query
//-----------------------------------------
$query = $this->_buildMembersQuery( array( 'mail_post_ltmt' => $this->request['mail_post_ltmt'],
'mail_filter_post' => $this->request['mail_filter_post'],
'mail_visit_ltmt' => $this->request['mail_visit_ltmt'],
'mail_filter_visit' => intval($this->request['mail_filter_visit']),
'mail_joined_ltmt' => $this->request['mail_joined_ltmt'],
'mail_filter_joined' => intval($this->request['mail_filter_joined']),
'mail_honor' => 1,//intval($this->request['mail_honor']),
'mail_groups' => $this->request['mail_groups'],
) );
//-----------------------------------------
// Count how many matches
//-----------------------------------------
$count = $this->DB->buildAndFetch( array( 'select' => 'count(*) as cnt', 'from' => 'members', 'where' => $query ) );
if ( ! $count['cnt'] )
{
$this->registry->output->global_message = $this->lang->words['b_nonefound'];
$this->_mailForm( $type );
return;
}
//-----------------------------------------
// Save
//-----------------------------------------
$save_array = array(
'mail_subject' => IPSText::stripslashes( $_POST['mail_subject'] ),
'mail_content' => IPSText::stripslashes( $_POST['mail_content'] ),
'mail_groups' => $this->request['mail_groups'],
'mail_honor' => 1,//intval($this->request['mail_honor']),
'mail_start' => time(),
'mail_updated' => time(),
'mail_sentto' => 0,
'mail_opts' => serialize( array( 'mail_post_ltmt' => $_POST['mail_post_ltmt'],
'mail_filter_post' => $_POST['mail_filter_post'],
'mail_visit_ltmt' => $_POST['mail_visit_ltmt'],
'mail_filter_visit' => $_POST['mail_filter_visit'],
'mail_joined_ltmt' => $_POST['mail_joined_ltmt'],
'mail_filter_joined' => $_POST['mail_filter_joined'],
'mail_html_on' => $_POST['mail_html_on'],
) )
);
if ( $type == 'add' )
{
//-----------------------------------------
// Save to DB
//-----------------------------------------
$this->DB->insert( 'bulk_mail', $save_array );
$this->request[ 'id'] = $this->DB->getInsertId( );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['b_maillogadd'], $this->request['mail_subject'] ) );
$this->_mailSendStart();
return;
}
else
{
if ( ! $id )
{
$this->registry->output->global_message = $this->lang->words['b_norecord'];
$this->_mailForm( $type );
return;
}
$this->DB->update( 'bulk_mail', $save_array, 'mail_id=' . $id );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['b_maillogedit'], $this->request['mail_subject'] ) );
$this->registry->output->global_message = $this->lang->words['b_edited'];
$this->_mailStart();
return;
}
}
/**
* Show the edit bulk mail form
*
* @access private
* @param string [add|edit]
* @return void
*/
private function _mailForm( $type='add' )
{
//-----------------------------------------
// Init some values
//-----------------------------------------
$id = intval($this->request['id']);
if ( $type == 'add' )
{
$mail = array();
}
else
{
$mail = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'bulk_mail', 'where' => 'mail_id='.$this->request['id'] ) );
}
if ( $this->request['mail_groups'] )
{
$mail['mail_groups'] = $this->request['mail_groups'];
}
//-----------------------------------------
// Format mail content
//-----------------------------------------
$mail_content = $_POST['mail_content'] ? IPSText::stripslashes($_POST['mail_content']) : $mail['mail_content'];
$mail_content = preg_replace( "[^\r]\n", "\r\n", $mail_content );
if ( !$mail_content and $type == 'add' )
{
$mail_content = $this->_getDefaultMailContents();
}
$mail_content = htmlspecialchars( $mail_content, ENT_QUOTES );
$this->registry->output->html .= $this->html->mailForm( $type, $mail, $mail_content );
}
/**
* Show the main bulk mail overview screen
*
* @access private
* @return void
*/
private function _mailStart()
{
$content = '';
$st = intval( $this->request['st'] );
$perpage = 50;
/* Get count */
$items = $this->DB->buildAndFetch( array( 'select' => 'COUNT(*) as cnt',
'from' => 'bulk_mail' ) );
//-----------------------------------------
// Get mail from DB
//-----------------------------------------
$this->DB->build( array( 'select' => '*', 'from' => 'bulk_mail', 'order' => 'mail_start DESC', 'limit' => array( $st, $perpage ) ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$r['_mail_start'] = ipsRegistry::getClass( 'class_localization')->getDate( $r['mail_start'], 'SHORT' );
$r['_mail_sentto'] = ipsRegistry::getClass('class_localization')->formatNumber( $r['mail_sentto'] ) . ' members';
$content .= $this->html->mailOverviewRow( $r );
}
/* Pages */
$pages = $this->registry->output->generatePagination( array( 'totalItems' => $items['cnt'],
'itemsPerPage' => $perpage,
'currentStartValue' => $st,
'baseUrl' => $this->settings['base_url'] . 'app=members&amp;module=bulkmail&do=bulk_mail' ) );
$this->registry->output->html .= $this->html->mailOverviewWrapper( $content, $pages );
}
/**
* Build the query to retrieve the members
*
* @access private
* @param array Arguments to send to the query
* @return string Formatted query
*/
private function _buildMembersQuery( $args = array() )
{
$query = array();
if ( is_numeric($args['mail_filter_post']) )
{
$ltmt = $args['mail_post_ltmt'] == 'lt' ? '<' : '>';
$query[] = "posts " . $ltmt . " " . intval($args['mail_filter_post']);
}
if ( $args['mail_filter_visit'] )
{
$ltmt = $args['mail_visit_ltmt'] == 'lt' ? '>' : '<';
$time = time() - ( $args['mail_filter_visit'] * 86400 );
$query[] = "last_visit " . $ltmt . " " . $time;
}
if ( $args['mail_filter_joined'] )
{
$ltmt = $args['mail_joined_ltmt'] == 'lt' ? '>' : '<';
$time = time() - ( $args['mail_filter_joined'] * 86400 );
$query[] = "joined " . $ltmt . " " . $time;
}
if ( $args['mail_honor'] )
{
$query[] = "allow_admin_mails=1";
}
if ( $args['mail_groups'] )
{
$tmp_q = '(member_group_id IN (' . $args['mail_groups'] . ')';
$temp = explode( ',', $args['mail_groups'] );
if ( is_array( $temp ) and count( $temp ) )
{
$tmp = array();
foreach( $temp as $id )
{
$tmp[] = $this->DB->buildConcat( array( array( ',', 'string' ), array( 'mgroup_others' ), array( ',', 'string' ) ) ) . "LIKE '%,{$id},%'";
}
$tmp_q .= " OR ( " . implode( ' OR ', $tmp ) . " ) )";
}
else
{
$tmp_q .= ")";
}
$query[] = $tmp_q;
}
return implode( ' AND ', $query );
}
/**
* Conver the 'quick tags' in the email
*
* @access private
* @param string The email contents
* @param array Member information
* @return string The email contents, replaced
*/
private function _convertQuickTags( $contents="", $member=array() )
{
$contents = str_replace( "{board_name}" , str_replace( "&#39;", "'", $this->settings['board_name'] ) , $contents );
$contents = str_replace( "{board_url}" , $this->settings['board_url'] . "/index." . $this->settings['php_ext'] , $contents );
$contents = str_replace( "{reg_total}" , $this->caches['stats']['mem_count'] , $contents );
$contents = str_replace( "{total_posts}" , $this->caches['stats']['total_topics'] + $this->caches['stats']['total_replies'] , $contents );
$contents = str_replace( "{busy_count}" , $this->caches['stats']['most_count'] , $contents );
$contents = str_replace( "{busy_time}" , ipsRegistry::getClass( 'class_localization')->getDate( $this->caches['stats']['most_date'], 'SHORT' ), $contents );
$contents = str_replace( "{member_id}" , $member['member_id'], $contents );
$contents = str_replace( "{member_name}" , $member['members_display_name'], $contents );
$contents = str_replace( "{member_joined}", ipsRegistry::getClass( 'class_localization')->getDate( $member['joined'], 'JOINED' ), $contents );
$contents = str_replace( "{member_posts}" , $member['posts'], $contents );
return $contents;
}
/**
* Retrieve the 'default' email contents
*
* @access private
* @return string Default email contents
*/
private function _getDefaultMailContents()
{
$mail = $this->lang->words['b_mailcontents'];
return $mail;
}
}
@@ -0,0 +1,30 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Define the default bulkmail section
* Last Updated: $Date: 2009-07-28 20:26:37 -0400 (Tue, 28 Jul 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @since 20th February 2002
* @version $Rev: 4948 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
/**
* Very simply returns the default section if one is not
* passed in the URL
*/
$DEFAULT_SECTION = 'bulkmail';
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,18 @@
<?xml version="1.0" encoding="UTF-8"?>
<menu>
<tabitems>
<item>
<title>Рассылки</title>
<subitems>
<subitem>
<subitemtitle>Рассылки</subitemtitle>
<subsection>bulkmail</subsection>
<subitemurl>do=bulk_mail</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
</tabitems>
</menu>
@@ -0,0 +1,33 @@
<?xml version="1.0" encoding="UTF-8"?>
<permissions>
<group>
<grouptitle>Управление рассылками</grouptitle>
<items>
<item>
<key>bulkmail_addedit</key>
<string>Может добавлять/изменять рассылки?</string>
</item>
<item>
<key>bulkmail_delete</key>
<string>Может удалять рассылки?</string>
</item>
</items>
</group>
<group>
<grouptitle>Отправка рассылок</grouptitle>
<items>
<item>
<key>bulkmail_view</key>
<string>Может просматривать текущие рассылки?</string>
</item>
<item>
<key>bulkmail_send</key>
<string>Может запускать отправку рассылки?</string>
</item>
<item>
<key>bulkmail_cancel</key>
<string>Может отменить отправку рассылки?</string>
</item>
</items>
</group>
</permissions>
@@ -0,0 +1,30 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Define the default groups section
* Last Updated: $Date: 2009-07-28 20:26:37 -0400 (Tue, 28 Jul 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @since 20th February 2002
* @version $Rev: 4948 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
/**
* Very simply returns the default section if one is not
* passed in the URL
*/
$DEFAULT_SECTION = 'groups';
@@ -0,0 +1,877 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Group management
* Last Updated: $Date: 2009-11-25 05:46:35 -0500 (Wed, 25 Nov 2009) $
*
* @author $Author: matt $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5468 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_groups_groups extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
//-----------------------------------------
// Load skin
//-----------------------------------------
$this->html = $this->registry->output->loadTemplate('cp_skin_groups');
//-----------------------------------------
// Set up stuff
//-----------------------------------------
$this->form_code = $this->html->form_code = 'module=groups&amp;section=groups';
$this->form_code_js = $this->html->form_code_js = 'module=groups&section=groups';
//-----------------------------------------
// Load lang
//-----------------------------------------
ipsRegistry::getClass('class_localization')->loadLanguageFile( array( 'admin_groups' ) );
///----------------------------------------
// What to do...
//-----------------------------------------
switch( $this->request['do'] )
{
case 'doadd':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_add' );
$this->_saveGroup('add');
break;
case 'add':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_add' );
$this->_groupForm('add');
break;
case 'edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit' );
$this->_groupForm('edit');
break;
case 'doedit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit' );
$this->_saveGroup('edit');
break;
case 'delete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete' );
$this->_deleteForm();
break;
case 'dodelete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete' );
$this->_doDelete();
break;
case 'master_xml_export':
$this->masterXMLExport();
break;
case 'groups_overview':
default:
$this->_mainScreen();
break;
}
//-----------------------------------------
// Pass to CP output hander
//-----------------------------------------
$this->registry->getClass('output')->html_main .= $this->registry->getClass('output')->global_template->global_frame_wrapper();
$this->registry->getClass('output')->sendOutput();
}
/**
* List the groups
*
* @access private
* @return void [Outputs to screen]
*/
private function _mainScreen()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$g_array = array();
$content = "";
$form = array();
$rows = array();
//-----------------------------------------
// Page details
//-----------------------------------------
$this->registry->output->extra_nav[] = array( $this->form_code, $this->lang->words['g_nav'] );
//-----------------------------------------
// Get groups
//-----------------------------------------
$this->DB->build( array( 'select' => 'g_id, g_access_cp, g_is_supmod, g_title, prefix, suffix',
'from' => 'groups',
'order' => 'g_title' ) );
$o = $this->DB->execute();
while ( $row = $this->DB->fetch( $o ) )
{
$_extra = ( $this->request['showSecondary'] ) ? ' OR mgroup_others LIKE \'%,' . intval($row['g_id']) . ',%\'' : '';
/* As much as I hate nested queries, this is actually quicker especially when you add in the LIKE check.*/
$count = $this->DB->buildAndFetch( array( 'select' => 'COUNT(*) as count',
'from' => 'members',
'where' => 'member_group_id=' . intval($row['g_id']) . $_extra ) );
$row['count'] = $count['count'];
$rows[ $row['g_id'] ] = $row;
}
foreach( $rows as $row )
{
//-----------------------------------------
// Set up basics
//-----------------------------------------
$row['_can_delete'] = ( $row['g_id'] > 4 ) ? 1 : 0;
$row['_can_acp'] = ( $row['g_access_cp'] == 1 ) ? 1 : 0;
$row['_can_supmod'] = ( $row['g_is_supmod'] == 1 ) ? 1 : 0;
//-----------------------------------------
// Add
//-----------------------------------------
$content .= $this->html->groupsOverviewRow( $row );
//-----------------------------------------
// Add to array
//-----------------------------------------
$g_array[] = array( $row['g_id'], $row['g_title'] );
}
//-----------------------------------------
// And output
//-----------------------------------------
$this->registry->output->html .= $this->html->groupsOverviewWrapper( $content, $g_array );
}
/**
* Exports the groups to a master XML file for distribution
*
* @access public
* @return void [Outputs to screen]
*/
public function masterXMLExport()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$entry = array();
$skip = IPSLib::fetchNonDefaultGroupFields();
//-----------------------------------------
// Get XML class
//-----------------------------------------
require_once( IPS_KERNEL_PATH . 'class_xml.php' );
$xml = new class_xml();
$xml->doc_type = IPS_DOC_CHAR_SET;
$xml->xml_set_root( 'export', array( 'exported' => time() ) );
//-----------------------------------------
// Set group
//-----------------------------------------
$xml->xml_add_group( 'group' );
//-----------------------------------------
// Grab our default 6 groups
//-----------------------------------------
$this->DB->build( array( 'select' => '*',
'from' => 'groups',
'order' => 'g_id ASC',
'limit' => array( 0, 6 )
) );
$this->DB->execute();
while ( $r = $this->DB->fetch() )
{
$content = array();
$r['g_icon'] = '';
//-----------------------------------------
// Sort the fields...
//-----------------------------------------
foreach( $r as $k => $v )
{
if ( ! in_array( $k, $skip ) )
{
$content[] = $xml->xml_build_simple_tag( $k, $v );
}
}
$entry[] = $xml->xml_build_entry( 'row', $content );
}
$xml->xml_add_entry_to_group( 'group', $entry );
$xml->xml_format_document();
//-----------------------------------------
// Print to browser
//-----------------------------------------
$this->registry->output->showDownload( $xml->xml_document, 'groups.xml', '', 0 );
}
/**
* Form to delete a group
*
* @access private
* @return void [Outputs to screen]
*/
private function _deleteForm()
{
$group_id = intval($this->request['id']);
$group = $this->caches['group_cache'][ $group_id ];
if ( !$group_id )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1120 );
}
if ( $group_id < 6 )
{
$this->registry->output->showError( $this->lang->words['g_preset'], 1121 );
}
if( $group['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete_admin' );
}
//-----------------------------------------
// How many users will we be moving?
//-----------------------------------------
$black_adder = $this->DB->buildAndFetch( array( 'select' => 'COUNT(*) as users', 'from' => 'members', 'where' => "member_group_id=" . $group_id ) );
$extra_group = $this->DB->buildAndFetch( array( 'select' => 'COUNT(*) as users', 'from' => 'members', 'where' => "mgroup_others LIKE '%,". $group_id .",%'" ) );
$black_adder['users'] = $black_adder['users'] > 0 ? $black_adder['users'] : 0;
$extra_group['users'] = $extra_group['users'] > 1 ? $extra_group['users'] : 0;
$this->registry->output->html .= $this->html->groupDelete( $group, $black_adder['users'], $extra_group['users'] );
}
/**
* Delete the group
*
* @access private
* @return void [Outputs to screen]
*/
private function _doDelete()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$this->request['id'] = intval($this->request['id'] );
$this->request['to_id'] = intval($this->request['to_id'] );
//-----------------------------------------
// Auth check...
//-----------------------------------------
ipsRegistry::getClass('adminFunctions')->checkSecurityKey( $this->request['secure_key'] );
//-----------------------------------------
// Check
//-----------------------------------------
if ( ! $this->request['id'] )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1122 );
}
if ( $this->request['id'] < 6 )
{
$this->registry->output->showError( $this->lang->words['g_preset'], 1124 );
}
if ( ! $this->request['to_id'] )
{
$this->registry->output->showError( $this->lang->words['g_mecries'], 1123 );
}
//-----------------------------------------
// Check to make sure that the relevant groups exist.
//-----------------------------------------
$original = $this->caches['group_cache'][ $this->request['id'] ];
$move_to = $this->caches['group_cache'][ $this->request['to_id'] ];
if( !count($original) )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1125 );
}
if( !count($move_to) )
{
$this->registry->output->showError( $this->lang->words['g_mecries'], 1126 );
}
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( $original['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_delete_admin' );
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'member_move_admin1', 'members', 'members' );
}
else if( $move_to['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'member_move_admin2', 'members', 'members' );
}
//-----------------------------------------
// Move and delete
//-----------------------------------------
$this->DB->update( 'members', array( 'member_group_id' => $this->request['to_id'] ), 'member_group_id=' . $this->request['id'] );
$this->DB->delete( 'groups', "g_id=" . $this->request['id'] );
$this->DB->delete( 'admin_permission_rows', "row_id_type='group' AND row_id=" . $this->request['id'] );
//-----------------------------------------
// Can't promote to non-existent group
//-----------------------------------------
foreach( $this->cache->getCache('group_cache') as $row )
{
$promotion = explode( '&', $row['g_promotion'] );
if( $promotion[0] == $this->request['id'] )
{
$this->DB->update( 'groups', array( 'g_promotion' => '-1&-1' ), 'g_id=' . $row['g_id'] );
}
}
//-----------------------------------------
// Remove from moderators table
//-----------------------------------------
$this->DB->delete( 'moderators', "is_group=1 AND group_id=" . $this->request['id'] );
//-----------------------------------------
// Remove as a secondary group
//-----------------------------------------
$this->DB->build( array(
'select' => 'member_group_id, mgroup_others, member_id',
'from' => 'members',
'where' => "mgroup_others LIKE '%," . $this->request['id'] . ",%'"
) );
$exg = $this->DB->execute();
while( $others = $this->DB->fetch($exg) )
{
$extra = array();
$extra = explode( ",", IPSText::cleanPermString( $others['mgroup_others'] ) );
$to_insert = array();
if( count( $extra ) )
{
foreach( $extra as $mgroup_other )
{
if( $mgroup_other != $this->request['id'] )
{
if( $mgroup_other != "" )
{
$to_insert[] = $mgroup_other;
}
}
}
if( count( $to_insert ) )
{
$new_others = ',' . implode( ',', $to_insert ) . ',';
}
else
{
$new_others = "";
}
$this->DB->update( 'members', array( 'mgroup_others' => $new_others ), 'member_id=' . $others['member_id'] );
}
}
//-----------------------------------------
// Rebuild caches
//-----------------------------------------
$this->rebuildGroupCache();
$this->cache->rebuildCache( 'moderators', 'forums' );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['g_removedlog'], $original['g_title'] ) );
$this->registry->output->global_message = $this->lang->words['g_removed'];
$this->_mainScreen();
}
/**
* Save the group [add/edit]
*
* @access private
* @param string 'add' or 'edit'
* @return void [Outputs to screen]
*/
private function _saveGroup( $type='edit' )
{
//-----------------------------------------
// INIT
//-----------------------------------------
$group_id = intval($this->request['id']);
$oldGroup = $this->caches['group_cache'][ $group_id ];
//-----------------------------------------
// Auth check...
//-----------------------------------------
ipsRegistry::getClass('adminFunctions')->checkSecurityKey( $this->request['secure_key'] );
//-----------------------------------------
// Check...
//-----------------------------------------
if ( ! $this->request['g_title'] )
{
$this->registry->output->showError( $this->lang->words['g_title_error'], 1127 );
}
if( intval($this->request['g_max_mass_pm']) > 500 )
{
$this->registry->output->showError( $this->lang->words['g_mass_pm_too_large'], 1127 );
}
#MSSQL needs a check on this
if ( IPSText::mbstrlen( $this->request['g_title'] ) > 32 )
{
$this->registry->output->showError( $this->lang->words['g_title_error'], 1127 );
}
if ( $type == 'edit' )
{
if ( !$group_id )
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 1128 );
}
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( $this->caches['group_cache'][ $group_id ]['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit_admin' );
}
}
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( ( $type == 'add' OR !$this->caches['group_cache'][ $group_id ]['g_access_cp'] ) AND $this->request['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_add_admin' );
}
//-----------------------------------------
// Sort out the perm mask id things
//-----------------------------------------
$new_perm_set_id = 0;
if( $this->request['g_new_perm_set'] )
{
$this->DB->insert( 'forum_perms', array( 'perm_name' => $this->request['g_new_perm_set'] ) );
$new_perm_set_id = $this->DB->getInsertId();
}
else
{
if ( !is_array( $this->request['permid'] ) )
{
$this->registry->output->showError( $this->lang->words['g_oneperm'], 1129 );
}
}
$this->lang->loadLanguageFile( array( 'admin_permissions' ), 'members' );
//-----------------------------------------
// Some other generic fields
//-----------------------------------------
$promotion_a = '-1'; // id
$promotion_b = '-1'; // posts
if ( $this->request['g_promotion_id'] AND $this->request['g_promotion_id'] > 0 )
{
$promotion_a = $this->request['g_promotion_id'];
$promotion_b = $this->request['g_promotion_posts'];
}
if ( $this->request['g_attach_per_post'] and $this->request['g_attach_max'] > 0 )
{
if ( $this->request['g_attach_per_post'] > $this->request['g_attach_max'] )
{
$this->registry->output->global_message = $this->lang->words['g_pergreater'];
$this->_groupForm('edit');
return;
}
}
$this->request[ 'p_max'] = str_replace( ":", "", $this->request['p_max'] );
$this->request[ 'p_width'] = str_replace( ":", "", $this->request['p_width'] );
$this->request[ 'p_height'] = str_replace( ":", "", $this->request['p_height'] );
$sig_limits = array(
$this->request['use_signatures'],
$this->request['max_images'],
$this->request['max_dims_x'],
$this->request['max_dims_y'],
$this->request['max_urls'],
$this->request['max_lines'],
);
//-----------------------------------------
// Set the db array
//-----------------------------------------
$db_string = array(
'g_view_board' => intval($this->request['g_view_board']),
'g_mem_info' => intval($this->request['g_mem_info']),
'g_can_add_friends' => intval($this->request['g_can_add_friends']),
'g_use_search' => intval($this->request['g_use_search']),
'g_email_friend' => intval($this->request['g_email_friend']),
'g_invite_friend' => $this->request['g_invite_friend'] ? intval( $this->request['g_invite_friend'] ) : 0,
'g_edit_profile' => intval($this->request['g_edit_profile']),
'g_use_pm' => intval($this->request['g_use_pm']),
'g_pm_perday' => intval($this->request['g_pm_perday']),
'g_is_supmod' => intval($this->request['g_is_supmod']),
'g_access_cp' => intval($this->request['g_access_cp']),
'g_title' => trim($this->request['g_title']),
'g_access_offline' => intval($this->request['g_access_offline']),
'g_dname_changes' => intval($this->request['g_dname_changes']),
'g_dname_date' => intval($this->request['g_dname_date']),
'prefix' => trim( IPSText::safeslashes( $_POST['prefix'] ) ),
'suffix' => trim( IPSText::safeslashes( $_POST['suffix'] ) ),
'g_hide_from_list' => intval($this->request['g_hide_from_list']),
'g_perm_id' => $new_perm_set_id ? $new_perm_set_id : implode( ",", $this->request['permid'] ),
'g_icon' => trim( IPSText::safeslashes( $_POST['g_icon'] ) ),
'g_attach_max' => $this->request['g_attach_max'],
'g_avatar_upload' => intval($this->request['g_avatar_upload']),
'g_max_messages' => intval($this->request['g_max_messages']),
'g_max_mass_pm' => intval($this->request['g_max_mass_pm']),
'g_pm_flood_mins' => intval($this->request['g_pm_flood_mins']),
'g_search_flood' => intval($this->request['g_search_flood']),
'g_promotion' => $promotion_a . '&' . $promotion_b,
'g_photo_max_vars' => $this->request['p_max'].':'.$this->request['p_width'].':'.$this->request['p_height'],
'g_dohtml' => intval($this->request['g_dohtml']),
'g_email_limit' => intval($this->request['join_limit']).':'.intval($this->request['join_flood']),
'g_bypass_badwords' => intval($this->request['g_bypass_badwords']),
'g_can_msg_attach' => intval($this->request['g_can_msg_attach']),
'g_attach_per_post' => intval($this->request['g_attach_per_post']),
'g_rep_max_positive' => intval( $this->request['g_rep_max_positive'] ),
'g_rep_max_negative' => intval( $this->request['g_rep_max_negative'] ),
'g_signature_limits' => implode( ':', $sig_limits ),
'g_hide_online_list' => intval( $this->request['g_hide_online_list'] ),
'g_displayname_unit' => intval( $this->request['g_displayname_unit'] ),
'g_sig_unit' => intval( $this->request['g_sig_unit'] ),
'g_bitoptions' => IPSBWOPtions::freeze( $this->request, 'groups', 'global' ), # Saves all BW options for all apps
);
//-----------------------------------------
// Ok? Load interface and child classes
//-----------------------------------------
IPSLib::loadInterface( 'admin/group_form.php' );
foreach( ipsRegistry::$applications as $app_dir => $app_data )
{
if ( ! IPSLib::appIsInstalled( $app_dir ) )
{
continue;
}
if ( file_exists( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' ) )
{
require_once( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' );
$_class = 'admin_group_form__' . $app_dir;
$_object = new $_class( $this->registry );
$remote = $_object->getForSave();
$db_string = array_merge( $remote, $db_string );
}
}
$this->DB->force_data_type = array( 'g_title' => 'string' );
//-----------------------------------------
// Editing...do an update
//-----------------------------------------
if ($type == 'edit')
{
$this->DB->update( 'groups', $db_string, 'g_id=' . $group_id );
//-----------------------------------------
// Update moderator table too
//-----------------------------------------
$this->DB->update( 'moderators', array( 'group_name' => $db_string['g_title'] ), 'group_id=' . $group_id );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['g_editedlog'], $db_string['g_title'] ) );
$this->registry->output->global_message = $this->lang->words['g_edited'];
}
else
{
$this->DB->insert( 'groups', $db_string );
$group_id = $this->DB->getInsertId();
ipsRegistry::getClass('adminFunctions')->saveAdminLog( sprintf( $this->lang->words['g_addedlog'], $db_string['g_title'] ) );
$this->registry->output->global_message = $this->lang->words['g_added'];
}
$this->rebuildGroupCache();
if( $new_perm_set_id )
{
$from = '';
if( ( $type == 'edit' AND $db_string['g_access_cp'] AND !$oldGroup['g_access_cp'] ) OR ( $type == 'add' AND $db_string['g_access_cp'] ) )
{
//-----------------------------------------
// Do they already have restrictions?
//-----------------------------------------
$test = $this->DB->buildAndFetch( array( 'select' => 'row_id', 'from' => 'admin_permission_rows', 'where' => "row_id_type='group' AND row_id=" . $group_id ) );
if( !$test['row_id'] )
{
$from = '&amp;_from=group-' . $group_id;
}
}
$this->registry->output->doneScreen( $this->lang->words['per_saved'], $this->lang->words['per_manage'], 'module=groups&amp;section=permissions&amp;do=edit_set_form' . $from . '&amp;id=' . $new_perm_set_id, 'redirect' );
return;
}
else
{
if( ( $type == 'edit' AND $db_string['g_access_cp'] AND !$oldGroup['g_access_cp'] ) OR ( $type == 'add' AND $db_string['g_access_cp'] ) )
{
//-----------------------------------------
// Do they already have restrictions?
//-----------------------------------------
$test = $this->DB->buildAndFetch( array( 'select' => 'row_id', 'from' => 'admin_permission_rows', 'where' => "row_id_type='group' AND row_id=" . $group_id ) );
if( !$test['row_id'] )
{
$this->registry->output->html .= $this->html->groupAdminConfirm( $group_id );
}
}
$this->_mainScreen();
}
}
/**
* Rebuilds the group cache
*
* @access public
* @return void
*/
public function rebuildGroupCache()
{
$cache = array();
$this->DB->build( array( 'select' => '*',
'from' => 'groups',
'order' => 'g_title ASC' ) );
$this->DB->execute();
while ( $i = $this->DB->fetch() )
{
$cache[ $i['g_id'] ] = IPSLib::unpackGroup( $i );
}
$this->cache->setCache( 'group_cache', $cache, array( 'array' => 1 ) );
}
/**
* Show the add/edit group form
*
* @access private
* @param string 'add' or 'edit'
* @return void [Outputs to screen]
*/
private function _groupForm( $type='edit' )
{
//-----------------------------------------
// Grab group data and start us off
//-----------------------------------------
if ($type == 'edit')
{
if ($this->request['id'] == "")
{
$this->registry->output->showError( $this->lang->words['g_whichgroup'], 11210 );
}
$group = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'groups', 'where' => "g_id=" . intval($this->request['id']) ) );
$group = IPSLib::unpackGroup( $group );
//-----------------------------------------
// Check restrictions.
//-----------------------------------------
if( $group['g_access_cp'] )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'groups_edit_admin' );
}
}
else
{
$group = array();
if( $this->request['id'] )
{
$group = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'groups', 'where' => "g_id=" . intval($this->request['id']) ) );
$group = IPSLib::unpackGroup( $group );
}
$group['g_title'] = 'New Group';
}
//-----------------------------------------
// Grab permission masks
//-----------------------------------------
$perm_masks = array();
$this->DB->build( array( 'select' => '*', 'from' => 'forum_perms' ) );
$this->DB->execute();
while ( $r = $this->DB->fetch() )
{
$perm_masks[] = array( $r['perm_id'], $r['perm_name'] );
}
//-----------------------------------------
// Ok? Load interface and child classes
//-----------------------------------------
$blocks = array( 'tabs' => array(), 'area' => array() );
IPSLib::loadInterface( 'admin/group_form.php' );
$tabsUsed = 2;
$firsttab = false;
foreach( ipsRegistry::$applications as $app_dir => $app_data )
{
if ( ! IPSLib::appIsInstalled( $app_dir ) )
{
continue;
}
if ( file_exists( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' ) )
{
require_once( IPSLib::getAppDir( $app_dir ) . '/extensions/admin/group_form.php' );
$_class = 'admin_group_form__' . $app_dir;
if ( class_exists( $_class ) )
{
$_object = new $_class( $this->registry );
$data = $_object->getDisplayContent( $group, $tabsUsed );
$blocks['area'][ $app_dir ] = $data['content'];
$blocks['tabs'][ $app_dir ] = $data['tabs'];
$tabsUsed = $data['tabsUsed'] ? ( $tabsUsed + $data['tabsUsed'] ) : ( $tabsUsed + 1 );
if ( $this->request['_initTab'] == $app_dir )
{
$firsttab = $tabsUsed;
}
}
}
}
//-----------------------------------------
// And output to form
//-----------------------------------------
$this->registry->output->html .= $this->html->groupsForm( $type, $group, $perm_masks, $blocks, $firsttab );
}
}
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,639 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Permissions management
* Last Updated: $Date: 2009-10-19 06:55:42 -0400 (Mon, 19 Oct 2009) $
*
* @author $Author: matt $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5240 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_groups_permissions extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
/* Load Skin and Lang */
$this->html = $this->registry->output->loadTemplate('cp_skin_permissions');
$this->registry->class_localization->loadLanguageFile( array( 'admin_permissions' ) );
/* URL Bits */
$this->form_code = $this->html->form_code = 'module=groups&amp;section=permissions&amp;';
$this->form_code_js = $this->html->form_code_js = 'module=groups&section=permissions&';
/* What to do */
switch( $this->request['do'] )
{
case 'delete_set':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_delete' );
$this->_doDeleteSet();
break;
case 'do_create_set':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_doCreatePermissionSet();
break;
case 'do_edit_set':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_permissionSaveForm();
break;
case 'edit_set_form':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_permissionSetForm();
break;
case 'view_perm_users':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'permmasks_view' );
$this->permissionSetUsers();
break;
case 'remove_mask':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'permmasks_delete' );
$this->removePermissionSet();
break;
case 'overview':
default:
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'perms_manage' );
$this->_mainScreen();
break;
}
/* Output */
$this->registry->getClass('output')->html_main .= $this->registry->getClass('output')->global_template->global_frame_wrapper();
$this->registry->getClass('output')->sendOutput();
}
/**
* Removes permission set(s) from a user
*
* @access public
* @return void
**/
public function removePermissionSet()
{
/* INI */
$member_id = intval( $this->request['id'] );
$perm_id = $this->request['pid'];
if( ! $member_id )
{
$this->registry->output->showError( $this->lang->words['per_memid'], 11338 );
}
/* Get the member */
$this->DB->build( array( 'select' => 'member_id, members_display_name, org_perm_id', 'from' => 'members', 'where' => "member_id={$member_id}" ) );
$this->DB->execute();
if( ! $mem = $this->DB->fetch() )
{
$this->registry->output->showError( $this->lang->words['per_memid'], 11339 );
}
/* Remove all permission sets */
if( $perm_id == 'all' )
{
$this->DB->update( 'members', array( 'org_perm_id' => 0 ), "member_id={$member_id}" );
}
/* Remove specific permission set */
else
{
/* Make Safe */
$perm_id = intval( $perm_id );
/* Get an array of permission ids */
$pid_array = explode( ",", IPSText::cleanPermString( $mem['org_perm_id'] ) );
/* If there's only one, then we can just remove it */
if( count( $pid_array ) < 2 )
{
$this->DB->update( 'members', array( 'org_perm_id' => 0 ), "member_id={$member_id}" );
}
else
{
/* Remove the specified element */
unset( $pid_array[ array_search( $perm_id, $pid_array ) ] );
/* Update the database */
$this->DB->update( 'members', array( 'org_perm_id' => implode( ",", $pid_array ) ), "member_id={$member_id}" );
}
}
/* Output */
$this->registry->output->html .= $this->html->permissionSetRemoveDone( $mem['members_display_name'] );
$this->registry->output->printPopupWindow();
}
/**
* Show users that are assigned the specified permission set
*
* @access public
* @return void
**/
public function permissionSetUsers()
{
/* Check ID */
$perm_id = intval( $this->request['id'] );
if( ! $perm_id )
{
$this->registry->output->showError( $this->lang->words['per_setid'], 11340 );
}
/* Query the permission set */
$this->DB->build( array( 'select' => '*', 'from' => 'forum_perms', 'where' => "perm_id={$perm_id}" ) );
$this->DB->execute();
if ( ! $perms = $this->DB->fetch() )
{
$this->registry->output->showError( $this->lang->words['per_setid'], 11341 );
}
/* Query the users who have this set */
$this->DB->build( array(
'select' => 'member_id, members_display_name, email, posts, org_perm_id',
'from' => 'members',
'where' => "(org_perm_id IS NOT NULL AND org_perm_id != '')",
'order' => 'name'
) );
$outer = $this->DB->execute();
/* Loop through the users */
$rows = array();
while( $r = $this->DB->fetch( $outer ) )
{
/* Arrayize the perm ids */
$exp_pid = explode( ",", IPSText::cleanPermString( $r['org_perm_id'] ) );
/* Loop through the ids */
foreach( $exp_pid as $pid )
{
/* Is the perm id we are looking for? */
if( $pid == $perm_id )
{
/* What other sets is this member using? */
if( count( $exp_pid ) > 1 )
{
/* INI the extra field */
$extra = "<em style='color:red'>";
/* Query the set names */
$this->DB->build( array(
'select' => '*',
'from' => 'forum_perms',
'where' => "perm_id IN (" . IPSText::cleanPermString( $r['org_perm_id'] ) . ") AND perm_id <> {$perm_id}"
) );
$this->DB->execute();
/* Add each set to the extra field */
while( $mr = $this->DB->fetch() )
{
$extra .= $mr['perm_name'].",";
}
/* Finish the extra field */
$extra = rtrim( $extra, ',' );
$extra .= "</em>";
}
/* No other sets in use */
else
{
$extra = "";
}
/* Add to array */
$r['_extra'] = $extra;
$rows[] = $r;
}
}
}
/* Output */
$this->registry->output->html .= $this->html->permissionSetUsers( $perm_id, $perms['perm_name'], $rows );
$this->registry->output->printPopupWindow();
}
/**
* Deletes a permission set
*
* @access private
* @return void [Outputs to screen]
*/
private function _doDeleteSet()
{
/* INIT */
$id = $this->request['id'];
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Loop through applications */
$where = array();
foreach( $this->registry->getApplications() as $app )
{
/* Check to see if there is a permission map */
$_file = IPSLib::getAppDir( $app['app_directory'] ) . '/extensions/coreExtensions.php';
if( file_exists( $_file ) )
{
/* Get the permission mappings */
require_once( $_file );
/* Check for a config array */
if( isset( $_PERM_CONFIG ) && is_array( $_PERM_CONFIG ) && count( $_PERM_CONFIG ) )
{
/* Loop through the types */
foreach( $_PERM_CONFIG as $perm_type )
{
$where[] = " app='{$app['app_directory']}' AND perm_type='" . strtolower( $perm_type ) . "' ";
}
}
}
}
/* Query Permission Rows */
$this->DB->build( array( 'select' => '*', 'from' => 'permission_index', 'where' => implode( ' OR ', $where ) ) );
$outer = $this->DB->execute();
while( $r = $this->DB->fetch( $outer ) )
{
foreach( array( 'perm_view', 'perm_2', 'perm_3', 'perm_4', 'perm_5', 'perm_6', 'perm_7' ) as $p )
{
if( $r[$p] != '*' )
{
$_perm_arr = explode( ',', IPSText::cleanPermString( $r[$p] ) );
if( in_array( $id, $_perm_arr ) )
{
unset( $_perm_arr[ array_search( $id, $_perm_arr ) ] );
}
$r[$p] = ',' . implode( ',', $_perm_arr ) . ',';
}
}
$update = $r;
unset( $update['perm_id'] );
/* Update */
$this->DB->update( 'permission_index', $update, "perm_id={$r['perm_id']}" );
}
/* Delete */
$this->DB->delete( 'forum_perms', "perm_id=$id" );
/* Done */
$this->registry->output->doneScreen( $this->lang->words['per_removed'], $this->lang->words['per_manage'], $this->form_code, 'redirect' );
}
/**
* Creates a nwe permission set
*
* @access private
* @return void [Outputs to screen]
*/
private function _doCreatePermissionSet()
{
/* INIT */
$set_name = $this->request['new_perm_name'];
$base_on = $this->request['new_perm_copy'];
if( ! $set_name )
{
$this->registry->output->global_message = $this->words['err_specify_set_name'];
$this->_mainScreen();
return;
}
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Loop through applications */
$where = array();
foreach( $this->registry->getApplications() as $app )
{
/* Check to see if there is a permission map */
$_file = IPSLib::getAppDir( $app['app_directory'] ) . '/extensions/coreExtensions.php';
if( file_exists( $_file ) )
{
/* Get the permission mappings */
require_once( $_file );
/* Check for a config array */
if( isset( $_PERM_CONFIG ) && is_array( $_PERM_CONFIG ) && count( $_PERM_CONFIG ) )
{
/* Loop through the types */
foreach( $_PERM_CONFIG as $perm_type )
{
$where[] = " app='{$app['app_directory']}' AND perm_type='" . strtolower( $perm_type ) . "' ";
}
}
}
}
/* Create the set */
$this->DB->insert( 'forum_perms', array( 'perm_name' => $set_name ) );
$new_set_id = $this->DB->getInsertId();
/* Query Permission Rows */
$this->DB->build( array( 'select' => '*', 'from' => 'permission_index', 'where' => implode( ' OR ', $where ) ) );
$outer = $this->DB->execute();
while( $r = $this->DB->fetch( $outer ) )
{
$perm_id = $r['perm_id'];
foreach( array( 'perm_view', 'perm_2', 'perm_3', 'perm_4', 'perm_5', 'perm_6', 'perm_7' ) as $p )
{
if( $r[$p] != '*' )
{
if( in_array( $base_on, explode( ',', IPSText::cleanPermString( $r[$p] ) ) ) )
{
$r[$p] .= $new_set_id . ',';
}
}
}
/* Unset main ID */
unset( $r['perm_id'] );
/* Update */
$this->DB->update( 'permission_index', $r, "perm_id=" . $perm_id );
}
/* Done */
$this->registry->output->doneScreen( $this->lang->words['per_saved'], $this->lang->words['per_manage'], $this->form_code . 'do=edit_set_form&amp;id=' . $new_set_id, 'redirect' );
}
/**
* Saves the global permission set form
*
* @access private
* @return void [Outputs to screen]
*/
private function _permissionSaveForm()
{
/* ID */
$id = intval( $this->request['id'] );
$matricies = array();
/* Query Set Name */
$set_data = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'forum_perms', 'where' => "perm_id={$id}" ) );
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Save */
$perm_obj->saveItemPermMatrix( $this->request['perms'], $id, $this->request['apps'] );
if( $this->request['perm_name'] != $set_data['perm_name'] )
{
$this->DB->update( 'forum_perms', array( 'perm_name' => $this->request['perm_name'] ), "perm_id={$id}" );
}
/* Done */
$this->registry->output->doneScreen( $this->lang->words['per_saved'], $this->lang->words['per_manage'], $this->form_code . '&amp;_from=' . $this->request['_from'], 'redirect' );
}
/**
* Form for modifying a permission set
*
* @access private
* @return void [Outputs to screen]
*/
private function _permissionSetForm()
{
/* ID */
$id = intval( $this->request['id'] );
$matricies = array();
$apps = array();
/* Query Set Name */
$set_data = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'forum_perms', 'where' => "perm_id={$id}" ) );
/* Permissions Class */
require_once( IPS_ROOT_PATH . 'sources/classes/class_public_permissions.php' );
$perm_obj = new classPublicPermissions( $this->registry );
/* Loop through applications */
foreach( $this->registry->getApplications() as $app )
{
/* Check to see if there is a permission map */
$_file = IPSLib::getAppDir( $app['app_directory'] ) . '/extensions/coreExtensions.php';
if( file_exists( $_file ) )
{
/* Get the permission mappings */
require_once( $_file );
/* Check for a config array */
if( isset( $_PERM_CONFIG ) && is_array( $_PERM_CONFIG ) && count( $_PERM_CONFIG ) )
{
/* Loop through the types */
foreach( $_PERM_CONFIG as $perm_type )
{
/* Check for a class */
$_class = $app['app_directory'] . 'PermMapping' . $perm_type;
if( class_exists( $_class ) )
{
/* Create the object */
$perm_map = new $_class;
/* Make sure the function exists */
if( method_exists( $perm_map, 'getPermItems' ) )
{
$matricies[$app['app_title']] = $perm_obj->adminItemPermMatrix( $perm_map, $perm_map->getPermItems(), $id, $app['app_directory'], $perm_type );
$apps[$app['app_directory']] = $perm_type;
}
}
}
}
}
}
/* Output */
$this->registry->output->html .= $this->html->permissionEditor( $set_data['perm_name'], $matricies, $id, $apps );
}
/**
* List permission masks
*
* @access private
* @return void [Outputs to screen]
*/
private function _mainScreen()
{
/* INIT */
$perms = array();
$mems = array();
$groups = array();
$dlist = "";
$content = "";
/* Get the names for the perm masks w/id */
$this->DB->build( array( 'select' => '*', 'from' => 'forum_perms', 'order' => 'perm_name ASC' ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$perms[ $r['perm_id'] ] = $r['perm_name'];
}
/* Number of users using this mask as an override */
$this->DB->build( array( 'select' => 'COUNT(member_id) as count, org_perm_id',
'from' => 'members',
'where' => "(org_perm_id " . $this->DB->buildIsNull( false ) . " AND org_perm_id != '')",
'group' => 'org_perm_id',
) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
if ( strstr( $r['org_perm_id'] , "," ) )
{
foreach( explode( ",", $r['org_perm_id'] ) as $pid )
{
$mems[ $pid ] = ! isset( $mems[ $pid ] ) ? 0 : $mems[ $pid ];
$mems[ $pid ] += $r['count'];
}
}
else
{
$mems[ $r['org_perm_id'] ] += $r['count'];
}
}
/* Groups using this mask */
$this->DB->build( array( 'select' => 'g_id, g_title, g_perm_id', 'from' => 'groups' ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
if ( strstr( $r['g_perm_id'] , "," ) )
{
foreach( explode( ",", $r['g_perm_id'] ) as $pid )
{
$groups[ $pid ][] = $r['g_title'];
}
}
else
{
$groups[ $r['g_perm_id'] ][] = $r['g_title'];
}
}
/* Build the output data */
$display_groups = array();
foreach( $perms as $id => $name )
{
$groups_used = "";
$mems_used = 0;
$is_active = 0;
$dlist .= "<option value='$id'>$name</option>\n";
if ( isset( $groups[ $id ] ) AND is_array( $groups[ $id ] ) )
{
foreach( $groups[ $id ] as $g_title )
{
$groups_used .= '&middot; ' . $g_title . "<br />";
}
$is_active = 1;
}
else
{
$groups_used = "{$this->lang->words['per_none']}";
}
if ( isset($mems[ $id ]) AND $mems[ $id ] > 0 )
{
$is_active = 1;
}
$r['id'] = $id;
$r['name'] = $name;
$r['isactive'] = $is_active;
$r['groups'] = $groups_used;
$r['mems'] = isset( $mems[ $id ] ) ? intval( $mems[ $id ] ) : 0;
$display_groups[] = $r;
}
/**
* Wow this is convoluted...
*/
if( $this->request['_from'] )
{
$from = explode( '-', $this->request['_from'] );
if( $from[1] )
{
$this->registry->class_localization->loadLanguageFile( array( 'admin_groups' ), 'members' );
$this->registry->output->html .= $this->html->groupAdminConfirm( $from[1] );
}
}
$this->registry->output->html .= $this->html->permissionsSplash( $display_groups, $dlist );
}
}
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,29 @@
<?xml version="1.0" encoding="UTF-8"?>
<menu>
<tabitems>
<item>
<title>Управление группами</title>
<subitems>
<subitem>
<subitemtitle>Управление группами пользователей</subitemtitle>
<subsection>groups</subsection>
<subitemurl>do=groups_overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Маски доступа</title>
<subitems>
<subitem>
<subitemtitle>Управление масками доступа</subitemtitle>
<subsection>permissions</subsection>
<subitemurl>do=overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
</tabitems>
</menu>
@@ -0,0 +1,45 @@
<?xml version="1.0" encoding="UTF-8"?>
<permissions>
<group>
<grouptitle>Управление группами</grouptitle>
<items>
<item>
<key>groups_add</key>
<string>Может добавлять группы?</string>
</item>
<item>
<key>groups_add_admin</key>
<string>Может добавлять АДМИНИСТРАТОРСКИЕ группы?</string>
</item>
<item>
<key>groups_edit</key>
<string>Может редактировать группы?</string>
</item>
<item>
<key>groups_edit_admin</key>
<string>Может редактировать АДМИНИСТРАТОРСКИЕ группы?</string>
</item>
<item>
<key>groups_delete</key>
<string>Может удалять группы?</string>
</item>
<item>
<key>groups_delete_admin</key>
<string>Может удалять АДМИНИСТРАТОРСКИЕ группы?</string>
</item>
</items>
</group>
<group>
<grouptitle>Управление правами</grouptitle>
<items>
<item>
<key>perms_manage</key>
<string>Может добавлять и редактировать маски доступа?</string>
</item>
<item>
<key>perms_delete</key>
<string>Может удалять маски доступа?</string>
</item>
</items>
</group>
</permissions>
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,278 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Ban Filters
* Last Updated: $Date: 2009-10-01 10:02:08 -0400 (Thu, 01 Oct 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Rev: 5190 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_members_banfilters extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
//-----------------------------------------
// Load skin
//-----------------------------------------
$this->html = $this->registry->output->loadTemplate( 'cp_skin_banfilters' );
//-----------------------------------------
// Set up stuff
//-----------------------------------------
$this->form_code = $this->html->form_code = 'module=members&amp;section=banfilters';
$this->form_code_js = $this->html->form_code_js = 'module=members&section=banfilters';
//-----------------------------------------
// Load lang
//-----------------------------------------
$this->registry->class_localization->loadLanguageFile( array( 'admin_member' ) );
//-----------------------------------------
// What to do...
//-----------------------------------------
switch( $this->request['do'] )
{
case 'ban_add':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ban_manage' );
$this->banAdd();
break;
case 'ban_delete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ban_remove' );
$this->banDelete();
break;
default:
case 'ban':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ban_manage' );
$this->banOverview();
break;
}
//-----------------------------------------
// Pass to CP output hander
//-----------------------------------------
$this->registry->output->html_main .= $this->registry->output->global_template->global_frame_wrapper();
$this->registry->output->sendOutput();
}
/**
* Add a new ban filter
*
* @access public
* @return void
*/
public function banAdd()
{
/* Error checking */
if( ! $this->request['bantext'] )
{
$this->registry->output->global_message = $this->lang->words['ban_entersomething'];
$this->banOverview();
return;
}
/* Check for duplicate */
$result = $this->DB->buildAndFetch( array(
'select' => '*',
'from' => 'banfilters',
'where' => "ban_content='{$this->request['bantext']}' and ban_type='{$this->request['bantype']}'"
) );
if ( $result['ban_id'] )
{
$this->registry->output->global_message = $this->lang->words['ban_dupe'];
$this->banOverview();
return;
}
/* Insert the new ban filter */
$this->DB->insert( 'banfilters', array( 'ban_type' => $this->request['bantype'], 'ban_content' => trim( $this->request['bantext'] ), 'ban_date' => time() ) );
/* Rebuild cacne and bounce */
$this->rebuildBanCache();
$this->registry->output->global_message = $this->lang->words['ban_added'];
$this->banOverview();
}
/**
* Delete a ban filter
*
* @access public
* @return void
*/
public function banDelete()
{
/* INI */
$ids = array();
/* Loop through the request fields and find checked ban filters */
foreach( $this->request as $key => $value )
{
if( preg_match( "/^id_(\d+)$/", $key, $match ) )
{
if( $this->request[ $match[0] ] )
{
$ids[] = $match[1];
}
}
}
/* Clean the array */
$ids = IPSLib::cleanIntArray( $ids );
/* Delete any checked ban filters */
if ( count( $ids ) )
{
$this->DB->delete( 'banfilters', 'ban_id IN(' . implode( ",", $ids ) . ')' );
$this->DB->execute();
}
/* Rebuild the cache */
$this->rebuildBanCache();
/* Bounce */
$this->registry->output->global_message = $this->lang->words['ban_removed'];
$this->banOverview();
}
/**
* Displays the ban overview screen
*
* @access public
* @return void
*/
public function banOverview()
{
/* INI */
$ban = array();
/* Get ban filters */
$this->DB->build( array( 'select' => '*', 'from' => 'banfilters', 'order' => 'ban_date desc' ) );
$this->DB->execute();
while ( $r = $this->DB->fetch() )
{
$ban[ $r['ban_type'] ][ $r['ban_id'] ] = $r;
}
/* IPs */
$ips = array();
if( isset( $ban['ip'] ) AND is_array( $ban['ip'] ) AND count( $ban['ip'] ) )
{
foreach( $ban['ip'] as $entry )
{
$entry['_checkbox'] = "<input type='checkbox' name='id_{$entry['ban_id']}' value='1' />";
$entry['_date'] = $this->registry->class_localization->getDate( $entry['ban_date'], 'SHORT' );
$ips[] = $entry;
}
}
/* Emails */
$emails = array();
if( isset( $ban['email'] ) AND is_array( $ban['email'] ) AND count( $ban['email'] ) )
{
foreach( $ban['email'] as $entry )
{
$entry['_checkbox'] = "<input type='checkbox' name='id_{$entry['ban_id']}' value='1' />";
$entry['_date'] = $this->registry->class_localization->getDate( $entry['ban_date'], 'SHORT' );
$emails[] = $entry;
}
}
/* Banned Names */
$names = array();
if( isset( $ban['name'] ) AND is_array( $ban['name'] ) AND count( $ban['name'] ) )
{
foreach( $ban['name'] as $entry )
{
$entry['_checkbox'] = "<input type='checkbox' name='id_{$entry['ban_id']}' value='1' />";
$entry['_date'] = $this->registry->class_localization->getDate( $entry['ban_date'], 'SHORT' );
$names[] = $entry;
}
}
/* Output */
$this->registry->output->html .= $this->html->banOverview( $ips, $emails, $names );
}
/**
* Rebuilds the ban cache
*
* @access public
* @return void
*/
public function rebuildBanCache()
{
/* INI */
$cache = array();
/* Get the ban filters */
$this->DB->build( array( 'select' => 'ban_content', 'from' => 'banfilters', 'where' => "ban_type='ip' AND ban_nocache=0" ) );
$this->DB->execute();
while ( $r = $this->DB->fetch() )
{
$cache[] = $r['ban_content'];
}
/* Update the cache */
$this->cache->setCache( 'banfilters', $cache, array( 'array' => 1 ) );
}
}
@@ -0,0 +1,687 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Custom field management
* Last Updated: $Date: 2009-10-01 10:02:08 -0400 (Thu, 01 Oct 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5190 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_members_customfields extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
//-----------------------------------------
// Load skin & lang
//-----------------------------------------
$this->html = $this->registry->output->loadTemplate( 'cp_skin_profilefields' );
$this->registry->class_localization->loadLanguageFile( array( 'admin_member' ) );
$this->form_code = $this->html->form_code = '&module=members&amp;section=customfields&amp;';
$this->js_form_code = $this->html->form_code_js = '&module=members&section=customfields&';
//-----------------------------------------
// switch-a-magoo
//-----------------------------------------
switch( $this->request['do'] )
{
case 'add':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'profilefields_add' );
$this->mainForm( 'add' );
break;
case 'doadd':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'profilefields_add' );
$this->mainSave( 'add' );
break;
case 'edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'profilefields_edit' );
$this->mainForm( 'edit' );
break;
case 'doedit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'profilefields_edit' );
$this->mainSave( 'edit' );
break;
case 'delete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'profilefields_delete' );
$this->deleteForm();
break;
case 'dodelete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'profilefields_delete' );
$this->doDelete();
break;
case 'group_overview':
$this->groupOverview();
break;
case 'group_form_add':
$this->groupForm( 'add' );
break;
case 'group_form_edit':
$this->groupForm( 'edit' );
break;
case 'do_add_group':
$this->groupSave( 'add' );
break;
case 'do_edit_group':
$this->groupSave( 'edit' );
break;
case 'group_form_delete':
$this->groupDelete();
break;
case 'reorder':
$this->reorder();
break;
default:
$this->mainScreen();
break;
}
/* Output */
$this->registry->output->html_main .= $this->registry->output->global_template->global_frame_wrapper();
$this->registry->output->sendOutput();
}
/**
* Remove a profile field group
*
* @access public
* @return void
*/
public function groupDelete()
{
/* ID */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['cf_gid'], 11211 );
}
/* Do the delete */
$this->DB->delete( 'pfields_groups', "pf_group_id={$id}" );
/* Done */
$this->registry->output->main_msg = $this->lang->words['cf_gremoved'];
$this->rebuildCache();
$this->groupOverview();
}
/**
* Handles the form for adding/editing profile field groups
*
* @access public
* @param string $mode Either add or edit
* @return void
*/
public function groupSave( $mode='add' )
{
/* Error Checking */
if( ! $this->request['pf_group_name'] || ! $this->request['pf_group_key'] )
{
$this->registry->output->showError( $this->lang->words['cf_completeform'], 11212 );
}
/* DB Array */
$db_array = array(
'pf_group_name' => $this->request['pf_group_name'],
'pf_group_key' => str_replace( ' ', '_', $this->request['pf_group_key'] ),
);
/* Create the field */
if( $mode == 'add' )
{
/* Make sure the key is unique */
$chk = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'pfields_groups', 'where' => "pf_group_key='{$db_array['pf_group_key']}'" ) );
if( $chk )
{
$this->registry->output->showError( $this->lang->words['cf_gkey'], 11213 );
}
/* Insert the group */
$this->DB->insert( 'pfields_groups', $db_array );
/* Done */
$this->registry->output->main_msg = $this->lang->words['cf_gadded'];
}
/* Edit the field */
else
{
/* ID */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['cf_gid'], 11214 );
}
/* Make sure the key is unique */
$chk = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'pfields_groups', 'where' => "pf_group_key='{$db_array['pf_group_key']}' AND pf_group_id <> {$id}" ) );
if( $chk )
{
$this->registry->output->showError( $this->lang->words['cf_gkey'], 11215 );
}
/* Update the group */
$this->DB->update( 'pfields_groups', $db_array, "pf_group_id={$id}" );
/* Done */
$this->registry->output->main_msg = $this->lang->words['cf_gmodified'];
}
/* Done */
$this->rebuildCache();
$this->groupOverview();
}
/**
* Builds the form for adding/editing profile field groups
*
* @access public
* @param string $mode Either add or edit
* @return void
*/
public function groupForm( $mode='add' )
{
/* Add Form */
if( $mode == 'add' )
{
/* ID */
$id = 0;
/* Data */
$data = array();
/* Text Bits */
$title = $this->lang->words['cf_gcreate'];
$do = 'do_add_group';
}
/* Edit Form */
else
{
/* ID */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['cf_gid'], 11216 );
}
/* Data */
$data = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'pfields_groups', 'where' => "pf_group_id={$id}" ) );
/* Text Bits */
$title = $this->lang->words['cf_gedit'];
$do = 'do_edit_group';
}
/* Default Values */
$data = array(
'pf_group_name' => $this->request['pf_group_name'] ? $this->request['pf_group_name'] : $data['pf_group_name'],
'pf_group_key' => $this->request['pf_group_key'] ? $this->request['pf_group_key'] : $data['pf_group_key'],
);
/* Output */
$this->registry->output->html .= $this->html->groupForm( $id, $data, $title, $do );
}
/**
* Builds the group listing screen
*
* @access public
* @return void
*/
public function groupOverview()
{
/* Query Groups */
$this->DB->build( array( 'select' => '*', 'from' => 'pfields_groups' ) );
$this->DB->execute();
$fields = array();
while( $r = $this->DB->fetch() )
{
$fields[] = $r;
}
/* Output */
$this->registry->output->html .= $this->html->groupList( $fields );
}
/**
* Rebuilds the custom profile field cache
*
* @access public
* @return void
*/
public function rebuildCache()
{
/* INIT */
$profile_fields = array();
/* Query the fields */
$this->DB->build( array(
'select' => 'p.*',
'from' => array( 'pfields_data' => 'p' ),
'order' => 'p.pf_group_id, p.pf_position',
'add_join' => array(
array(
'select' => 'g.*',
'from' => array( 'pfields_groups' => 'g' ),
'where' => 'p.pf_group_id=g.pf_group_id',
'type' => 'left',
)
)
) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$r['pf_group_key'] = $r['pf_group_key'] ? $r['pf_group_key'] : '_other';
$profile_fields[ $r['pf_id'] ] = $r;
}
/* Update the cache */
$this->cache->setCache( 'profilefields', $profile_fields, array( 'array' => 1 ) );
}
/**
* Confirm field deletion form
*
* @access public
* @return void
*/
public function deleteForm()
{
/* INI */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['cf_gid'], 11217 );
}
/* Query the field */
$this->DB->build( array( 'select' => 'pf_title', 'from' => 'pfields_data', 'where' => "pf_id={$id}" ) );
$this->DB->execute();
if ( ! $field = $this->DB->fetch() )
{
$this->registry->output->showError( $this->lang->words['cf_norow'], 11218 );
}
/* Output */
$this->registry->output->html .= $this->html->customProfileFieldDelete( $id, $field['pf_title'] );
}
/**
* Removes a field from the database
*
* @access public
* @return void
*/
public function doDelete()
{
/* INI */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['cf_gid'], 11219 );
}
/* Query the field */
$this->DB->build( array( 'select' => '*', 'from' => 'pfields_data', 'where' => "pf_id={$id}" ) );
$this->DB->execute();
if ( ! $row = $this->DB->fetch() )
{
$this->registry->output->showError( $this->lang->words['cf_norow'], 11220 );
}
/* Remove the filed */
$this->DB->dropField( 'pfields_content', "field_{$row['pf_id']}" );
$this->DB->buildAndFetch( array( 'delete' => 'pfields_data', 'where' => "pf_id={$id}" ) );
/* Rebuild the cache and redirect */
$this->rebuildCache();
$this->registry->output->doneScreen( $this->lang->words['cf_removed'], $this->lang->words['cf_control'], $this->form_code, 'redirect' );
}
/**
* Saves a custom field form
*
* @access public
* @param string Type (add|edit)
* @return void
*/
public function mainSave( $type='edit' )
{
/* ID */
$id = intval( $this->request['id'] );
/* Custom Fields Class */
require_once( IPS_KERNEL_PATH . 'classCustomFields.php' );
$cfields_class = new classCustomFields( array() );
if( ! $this->request['pf_title'] )
{
$this->registry->output->showError( $this->lang->words['cf_entertitle'], 11221 );
}
//-----------------------------------------
// check-da-motcha
//-----------------------------------------
if( $type == 'edit' )
{
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['cf_norow'], 11222 );
}
}
$content = "";
if( $_POST['pf_content'] != "" )
{
$content = $cfields_class->formatContentForSave( $_POST['pf_content'] );
}
$db_string = array( 'pf_title' => $this->request['pf_title'],
'pf_desc' => $this->request['pf_desc'],
'pf_content' => IPSText::stripslashes( $content ),
'pf_type' => $this->request['pf_type'],
'pf_not_null' => intval( $this->request['pf_not_null'] ),
'pf_member_hide' => intval( $this->request['pf_member_hide'] ),
'pf_max_input' => intval( $this->request['pf_max_input'] ),
'pf_member_edit' => intval( $this->request['pf_member_edit'] ),
'pf_position' => intval( $this->request['pf_position'] ),
'pf_show_on_reg' => intval( $this->request['pf_show_on_reg'] ),
'pf_input_format' => $this->request['pf_input_format'],
'pf_admin_only' => intval( $this->request['pf_admin_only'] ),
'pf_topic_format' => IPSText::stripslashes( $_POST['pf_topic_format'] ),
'pf_group_id' => intval( $this->request['pf_group_id'] ),
'pf_icon' => trim($this->request['pf_icon']),
'pf_key' => trim($this->request['pf_key']),
);
if ($type == 'edit')
{
$this->DB->update( 'pfields_data', $db_string, 'pf_id=' . $id );
$this->registry->output->main_msg = $this->lang->words['cf_edited'];
}
else
{
$this->DB->insert( 'pfields_data', $db_string );
$new_id = $this->DB->getInsertId();
$this->DB->addField( 'pfields_content', "field_$new_id", 'text' );
$this->DB->optimize( 'pfields_content' );
$this->registry->output->main_msg = $this->lang->words['cf_added'];
}
$this->rebuildCache();
$this->mainScreen();
}
/**
* Shows a custom field form
*
* @access public
* @param string Type (add|edit)
* @return void
*/
public function mainForm( $type='edit' )
{
/* INI */
$id = intval( $this->request['id'] );
/* Custom Fields Class */
require_once( IPS_KERNEL_PATH . 'classCustomFields.php' );
$cfields_class = new classCustomFields( array() );
/* Type of form */
if( $type == 'edit' )
{
/* Check for id */
if ( ! $id )
{
$this->registry->output->showError( $this->lang->words['cf_gid'], 11223 );
}
/* Query data */
$this->DB->build( array( 'select' => '*', 'from' => 'pfields_data', 'where' => "pf_id=" . $id ) );
$this->DB->execute();
$fields = $this->DB->fetch();
/* Form Setup */
$form_code = 'doedit';
$button = $this->lang->words['cf_editbutton'];
$title = $this->lang->words['cf_pagetitle_edit'];
}
else
{
/* Form Setup */
$form_code = 'doadd';
$button = $this->lang->words['cf_addbutton'];
/* Data */
$fields = array( 'pf_topic_format' => '<span class="ft">{title}:</span><span class="fc">{content}</span>' );
$title = $this->lang->words['cf_pagetitle_add'];
}
/* Format Content */
$fields['pf_content'] = $cfields_class->formatContentForEdit($fields['pf_content'] );
/* Form Fields */
$fields['pf_show_on_reg'] = $this->registry->output->formYesNo( 'pf_show_on_reg', $fields['pf_show_on_reg'] );
$fields['pf_not_null'] = $this->registry->output->formYesNo( 'pf_not_null', $fields['pf_not_null'] );
$fields['pf_member_edit'] = $this->registry->output->formYesNo( 'pf_member_edit', $fields['pf_member_edit'] );
$fields['pf_member_hide'] = $this->registry->output->formYesNo( 'pf_member_hide', $fields['pf_member_hide'] );
$fields['pf_admin_only'] = $this->registry->output->formYesNo( 'pf_admin_only', $fields['pf_admin_only'] );
$fields['pf_type'] = $this->registry->output->formDropdown( 'pf_type', $cfields_class->getFieldTypes(), $fields['pf_type'] );
$fields['pf_icon'] = $this->registry->output->formInput( 'pf_icon', $fields['pf_icon'] );
$fields['pf_key'] = $this->registry->output->formInput( 'pf_key', $fields['pf_key'] );
/* Grab the groups */
$this->DB->build( array( 'select' => '*', 'from' => 'pfields_groups' ) );
$this->DB->execute();
$_groups = array();
while( $r = $this->DB->fetch() )
{
$_groups[] = array( $r['pf_group_id'], $r['pf_group_name'] );
}
$fields['pf_group_id'] = $this->registry->output->formDropdown( 'pf_group_id', $_groups, $fields['pf_group_id'] );
/* Output */
$this->registry->output->html .= $this->html->customProfileFieldForm( $id, $form_code, $button, $fields, $title );
}
/**
* Lists the current custom profile fields
*
* @access public
* @return void
*/
public function mainScreen()
{
/* Get the fields */
$this->DB->build( array(
'select' => 'p.*',
'from' => array( 'pfields_data' => 'p' ),
'order' => 'p.pf_position',
'add_join' => array(
array(
'select' => 'g.*',
'from' => array( 'pfields_groups' => 'g' ),
'where' => 'p.pf_group_id=g.pf_group_id',
'type' => 'left'
)
)
) );
$this->DB->execute();
/* Loop through and build list */
$fields = array();
if ( $this->DB->getTotalRows() )
{
while ( $r = $this->DB->fetch() )
{
/* INI */
$hide = '&nbsp;';
$req = '&nbsp;';
$regi = '&nbsp;';
$admin = '&nbsp;';
/* Hidden */
$r['_hide'] = ( $r['pf_member_hide'] ) ? 'tick.png' : 'cross.png';
$r['_req'] = ( $r['pf_not_null'] ) ? 'tick.png' : 'cross.png';
$r['_regi'] = ( $r['pf_show_on_reg'] ) ? 'tick.png' : 'cross.png';
$r['_admin'] = ( $r['pf_admin_only'] ) ? 'tick.png' : 'cross.png';
/*if( $r['pf_member_hide'] == 1 )
{
$r['_hide'] = ;
}
if( $r['pf_not_null'] == 1 )
{
$r['_req'] = '<center><span style="color:red">Y</span></center>';
}
if( $r['pf_show_on_reg'] == 1 )
{
$r['_regi'] = '<center><span style="color:red">Y</span></center>';
}
if( $r['pf_admin_only'] == 1 )
{
$r['_admin'] = '<center><span style="color:red">Y</span></center>';
}*/
/* Add to fields */
$key = $r['pf_group_name'] ? $r['pf_group_name'] : 'Other';
$fields[$key][] = $r;
}
}
/* Output */
$this->registry->output->html .= $this->html->customProfileFieldsList( $fields );
}
/**
* Reorder fields
*
* @access private
* @return void [Outputs to screen]
*/
private function reorder()
{
//-----------------------------------------
// INIT
//-----------------------------------------
require_once( IPS_KERNEL_PATH . 'classAjax.php' );
$ajax = new classAjax();
//-----------------------------------------
// Checks...
//-----------------------------------------
if( $this->registry->adminFunctions->checkSecurityKey( $this->request['md5check'], true ) === false )
{
$ajax->returnString( $this->lang->words['postform_badmd5'] );
exit();
}
//-----------------------------------------
// Save new position
//-----------------------------------------
$position = 1;
if( is_array($this->request['fields']) AND count($this->request['fields']) )
{
foreach( $this->request['fields'] as $this_id )
{
$this->DB->update( 'pfields_data', array( 'pf_position' => $position ), 'pf_id=' . $this_id );
$position++;
}
}
$this->rebuildCache();
$ajax->returnString( 'OK' );
exit();
}
}
@@ -0,0 +1,30 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Define the default members section
* Last Updated: $Date: 2009-07-28 20:26:37 -0400 (Tue, 28 Jul 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @since 20th February 2002
* @version $Rev: 4948 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
/**
* Very simply returns the default section if one is not
* passed in the URL
*/
$DEFAULT_SECTION = 'members';
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
File diff suppressed because it is too large. Load diff
@@ -0,0 +1,334 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Member management
* Last Updated: $Date: 2009-10-01 10:02:08 -0400 (Thu, 01 Oct 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Revision: 5190 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_members_ranks extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Editor object
*
* @access private
* @var object Editor library
*/
private $han_editor;
/**
* Trash can forum id
*
* @access private
* @var integer Trash can forum
*/
private $trash_forum = 0;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
//-----------------------------------------
// Load skin
//-----------------------------------------
$this->html = $this->registry->output->loadTemplate('cp_skin_ranks');
//-----------------------------------------
// Set up stuff
//-----------------------------------------
$this->form_code = $this->html->form_code = 'module=members&amp;section=ranks';
$this->form_code_js = $this->html->form_code_js = 'module=members&section=ranks';
//-----------------------------------------
// Load lang
//-----------------------------------------
ipsRegistry::getClass('class_localization')->loadLanguageFile( array( 'admin_member' ) );
///-----------------------------------------
// What to do...
//-----------------------------------------
switch( $this->request['do'] )
{
default:
case 'title':
$this->_titlesStart();
break;
case 'rank_edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ranks_edit' );
$this->_titlesForm( 'edit' );
break;
case 'rank_add':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ranks_add' );
$this->_titlesForm( 'add' );
break;
case 'do_add_rank':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ranks_add' );
$this->_titlesSave( 'add' );
break;
case 'do_rank_edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ranks_edit' );
$this->_titlesSave( 'edit' );
break;
case 'rank_delete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'ranks_delete' );
$this->_titlesDelete();
break;
}
//-----------------------------------------
// Pass to CP output hander
//-----------------------------------------
$this->registry->getClass('output')->html_main .= $this->registry->getClass('output')->global_template->global_frame_wrapper();
$this->registry->getClass('output')->sendOutput();
}
/**
* Recache ranks
*
* @access public
* @return void
*/
public function titlesRecache()
{
$ranks = array();
$this->DB->build( array( 'select' => 'id, title, pips, posts',
'from' => 'titles',
'order' => 'posts DESC',
) );
$this->DB->execute();
while ( $i = $this->DB->fetch() )
{
$ranks[ $i['id'] ] = array(
'TITLE' => $i['title'],
'PIPS' => $i['pips'],
'POSTS' => $i['posts'],
);
}
$this->cache->setCache( 'ranks', $ranks, array( 'array' => 1 ) );
}
/**
* Overview page
*
* @access protected
* @return void [Outputs to screen]
*/
protected function _titlesStart()
{
$this->registry->output->extra_nav[] = array( '', $this->lang->words['member_rank_nav'] );
$titles = array();
//-----------------------------------------
// Parse macro
//-----------------------------------------
$row = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'skin_replacements', 'where' => "replacement_set_id=0 AND replacement_key='pip_pip'" ) );
$row['A_STAR'] = str_replace( "{style_image_url}", $this->settings['img_url'], $row['replacement_content'] );
//-----------------------------------------
// Lets get on with it...
//-----------------------------------------
$this->DB->build( array( 'select' => '*', 'from' => 'titles', 'order' => "posts" ) );
$this->DB->execute();
while ( $r = $this->DB->fetch() )
{
$r['A_STAR'] = $row['A_STAR'];
$titles[] = $r;
}
$this->registry->output->html .= $this->html->titlesOverview( $titles );
}
/**
* Save rank [add/edit]
*
* @access protected
* @param string 'add' or 'edit'
* @return void [Outputs to screen]
*/
protected function _titlesSave( $type = 'add' )
{
//-----------------------------------------
// check for input
//-----------------------------------------
foreach( array( 'title', 'pips' ) as $field )
{
if ( ! isset( $this->request[ $field ] ) )
{
$this->registry->output->showError( $this->lang->words['rnk_completeform'], 11239 );
}
}
if ( $this->request['pips'] > 100 )
{
$this->registry->output->showError( $this->lang->words['rnk_max100'], 11240 );
}
if( $type == 'add' )
{
$this->DB->insert( 'titles', array(
'posts' => intval( trim( $this->request['posts'] ) ),
'title' => trim($this->request['title']),
'pips' => trim($this->request['pips']),
) );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( $this->lang->words['rnk_added'] );
}
else
{
if ( !$this->request['id'] )
{
$this->registry->output->showError( $this->lang->words['rnk_notfound'], 11241 );
}
$this->DB->update( 'titles', array ( 'posts' => trim($this->request['posts']),
'title' => trim($this->request['title']),
'pips' => trim($this->request['pips']),
) , "id=" . intval( $this->request['id'] ) );
ipsRegistry::getClass('adminFunctions')->saveAdminLog( $this->lang->words['rnk_edit'] );
}
$this->titlesRecache();
if( $type == 'add' )
{
$this->registry->output->doneScreen($this->lang->words['rnk_added2'], $this->lang->words['rnk_rankcontrol'], "{$this->form_code}&do=title", 'redirect' );
}
else
{
$this->registry->output->doneScreen($this->lang->words['rnk_edited'], $this->lang->words['rnk_rankcontrol'], "{$this->form_code}&do=title", 'redirect' );
}
}
/**
* Delete a rank
*
* @access protected
* @return void [Outputs to screen]
*/
protected function _titlesDelete()
{
//-----------------------------------------
// check for input
//-----------------------------------------
if ( !$this->request['id'] )
{
$this->registry->output->showError( $this->lang->words['rnk_notfounddel'], 11242 );
}
$this->DB->delete( 'titles', "id=" . intval($this->request['id']) );
$this->titlesRecache();
ipsRegistry::getClass('adminFunctions')->saveAdminLog( $this->lang->words['rnk_removed'] );
$this->registry->output->doneScreen($this->lang->words['rnk_removed2'], $this->lang->words['rnk_rankcontrol'], "{$this->form_code}&do=title", 'redirect' );
}
/**
* Show the form to add/edit a rank
*
* @access protected
* @param string Type of form (add|edit)
* @return void [Outputs to screen]
*/
protected function _titlesForm( $mode='edit' )
{
$this->registry->output->extra_nav[] = array( '', $this->lang->words['rnk_setup'] );
if ( $mode == 'edit' )
{
$form_code = 'do_rank_edit';
if ( !$this->request['id'] )
{
$this->registry->output->showError( $this->lang->words['rnk_notfound'], 11243 );
}
$rank = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'titles', 'where' => "id=" . intval($this->request['id']) ) );
$button = $this->lang->words['rnk_editrank'];
}
else
{
$form_code = 'do_add_rank';
$rank = array( 'posts' => '', 'title' => "", 'pips' => "");
$button = $this->lang->words['rnk_addrank'];
}
//-----------------------------------------
$this->registry->output->html .= $this->html->titlesForm( $rank, $form_code, $button );
}
}
@@ -0,0 +1,299 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Reputation System
* Last Updated: $Date: 2009-10-01 10:02:08 -0400 (Thu, 01 Oct 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @version $Rev: 5190 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_members_reputation extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
/* Load Skin & Lang */
$this->html = $this->registry->output->loadTemplate( 'cp_skin_reputation' );
$this->registry->class_localization->loadLanguageFile( array( 'admin_member' ) );
/* URL Bits */
$this->form_code = $this->html->form_code = 'module=members&amp;section=reputation';
$this->form_code_js = $this->html->form_code_js = 'module=members&section=reputation';
/* What to do */
switch( $this->request['do'] )
{
case 'add_level_form':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'reps_manage' );
$this->levelForm( 'add' );
break;
case 'do_add_level':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'reps_manage' );
$this->doLevelForm( 'add' );
break;
case 'edit_level_form':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'reps_manage' );
$this->levelForm( 'edit' );
break;
case 'do_edit_level':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'reps_manage' );
$this->doLevelForm( 'edit' );
break;
case 'delete_level':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'reps_delete' );
$this->deleteLevel();
break;
default:
case 'overview':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'reps_manage' );
$this->reputationOverview();
break;
}
/* Output */
$this->registry->output->html_main .= $this->registry->output->global_template->global_frame_wrapper();
$this->registry->output->sendOutput();
}
/**
* Rebuilds the reputation level cache
*
* @access public
* @return void
*/
public function rebuildReputationLevelCache()
{
/* Cache */
$cache = array();
/* Query the levels */
$this->DB->build( array( 'select' => '*', 'from' => 'reputation_levels', 'order' => 'level_points DESC' ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$cache[] = $r;
}
/* Update the cache */
$this->cache->setCache( 'reputation_levels', $cache, array( 'array' => 1 ) );
}
/**
* Removes the selected reputation level
*
* @access public
* @return void
*/
public function deleteLevel()
{
/* ID */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['invalid_id'], 11244 );
}
/* Delete */
$this->DB->delete( 'reputation_levels', "level_id={$id}" );
$this->rebuildReputationLevelCache();
/* Redirect */
$this->registry->output->doneScreen( $this->lang->words['rep_level_removed'], $this->lang->words['rep_management'], $this->form_code, 'redirect' );
}
/**
* Handles the add/edit reputation level form
*
* @access public
* @param string $mode Either add or edit
* @return void
*/
public function doLevelForm( $mode='add' )
{
/* Error Checking */
$errors = array();
if( ! $this->request['level_title'] && ! $this->request['level_image'] )
{
$errors[] = $this->lang->words['rep_no_title_img'];
}
if( count( $errors ) )
{
$this->levelForm( $mode, $errors );
return;
}
/* Build the data array */
$data = array(
'level_title' => $this->request['level_title'],
'level_image' => $this->request['level_image'],
'level_points' => intval( $this->request['level_points'] )
);
/* Add the level */
if( $mode == 'add' )
{
/* Insert */
$this->DB->insert( 'reputation_levels', $data );
$this->rebuildReputationLevelCache();
/* Redirect */
$this->registry->output->doneScreen( $this->lang->words['rep_level_added'], $this->lang->words['rep_management'], $this->form_code, 'redirect' );
}
else
{
/* ID Check */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['invalid_id'], 11245 );
}
/* Update */
$this->DB->update( 'reputation_levels', $data, "level_id={$id}" );
$this->rebuildReputationLevelCache();
/* Redirect */
$this->registry->output->doneScreen( $this->lang->words['rep_level_edited'], $this->lang->words['rep_management'], $this->form_code, 'redirect' );
}
}
/**
* Form for adding/exiting reputation levels
*
* @access public
* @param string $mode Either add or edit
* @param array $errors Array of error messages to display
* @return void
*/
public function levelForm( $mode='add', $errors=array() )
{
/* Add Level Form */
if( $mode == 'add' )
{
/* ID */
$id = 0;
/* Data */
$data = array();
/* Text Bits */
$title = $this->lang->words['rep_form_add_title'];
$do = 'do_add_level';
}
/* Edit Level Form */
else
{
/* ID */
$id = intval( $this->request['id'] );
if( ! $id )
{
$this->registry->output->showError( $this->lang->words['invalid_id'], 11246 );
}
/* Data */
$data = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'reputation_levels', 'where' => 'level_id=' . $id ) );
/* Text Bits */
$title = $this->lang->words['rep_form_edit_title'];
$do = 'do_edit_level';
}
/* Default Values */
$data['level_title'] = isset( $this->request['level_title'] ) ? $this->request['level_title'] : $data['level_title'];
$data['level_image'] = isset( $this->request['level_image'] ) ? $this->request['level_image'] : $data['level_image'];
$data['level_points'] = isset( $this->request['level_points'] ) ? $this->request['level_points'] : $data['level_points'];
/* Form Elements */
$form = array();
$form['level_title'] = $this->registry->output->formInput( 'level_title' , $data['level_title'] );
$form['level_image'] = $this->registry->output->formInput( 'level_image' , $data['level_image'] );
$form['level_points'] = $this->registry->output->formInput( 'level_points', $data['level_points'] );
/* Output */
$this->registry->output->html .= $this->html->reputationForm( $id, $do, $title, $form, $errors );
}
/**
* Reputation overview
*
* @access public
* @return void
*/
public function reputationOverview()
{
/* INIT */
$levels = array();
/* Query Levels */
$this->DB->build( array( 'select' => '*', 'from' => 'reputation_levels', 'order' => 'level_points ASC' ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$r['level_image'] = $r['level_image'] ? "<img src='{$this->settings['public_dir']}style_extra/reputation_icons/{$r['level_image']}'>" : '';
$levels[] = $r;
}
/* Output */
$this->registry->output->html .= $this->html->reputationOverview( $levels );
}
}
File diff suppressed because it is too large. Load diff
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,136 @@
<?xml version="1.0" encoding="UTF-8"?>
<menu>
<tabitems>
<item>
<title>Управление пользователями</title>
<subitems>
<subitem>
<subitemtitle>Управление пользователями</subitemtitle>
<subsection>members</subsection>
<subitemurl>do=members_overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
<subitem>
<subitemtitle>Список неактивированных</subitemtitle>
<subsection>tools</subsection>
<subitemurl>do=validating</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
<subitem>
<subitemtitle>Список заблокированных</subitemtitle>
<subsection>tools</subsection>
<subitemurl>do=locked</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
<subitem>
<subitemtitle>Список забаненных</subitemtitle>
<subsection>tools</subsection>
<subitemurl>do=banned</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
<subitem>
<subitemtitle>Список спамеров</subitemtitle>
<subsection>tools</subsection>
<subitemurl>do=spam</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Звания</title>
<subitems>
<subitem>
<subitemtitle>Управление званиями пользователей</subitemtitle>
<subsection>ranks</subsection>
<subitemurl>do=ranks_overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Репутация</title>
<subitems>
<subitem>
<subitemtitle>Управление репутацией пользователей</subitemtitle>
<subsection>reputation</subsection>
<subitemurl>do=overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Дополнительные поля</title>
<subitems>
<subitem>
<subitemtitle>Управление дополнительными полями профиля</subitemtitle>
<subsection>customfields</subsection>
<subitemurl></subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Группы дополнительных полей</title>
<subitems>
<subitem>
<subitemtitle>Управление группами дополнительных полей профиля</subitemtitle>
<subsection>customfields</subsection>
<subitemurl>do=group_overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Определение IP</title>
<subitems>
<subitem>
<subitemtitle>Инструменты</subitemtitle>
<subsection>tools</subsection>
<subitemurl></subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Добавление пользователя</title>
<subitems>
<subitem>
<subitemtitle>Добавление пользователя</subitemtitle>
<subsection>members</subsection>
<subitemurl>do=add</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
<item>
<title>Бан фильтры</title>
<subitems>
<subitem>
<subitemtitle>Управление бан фильтрами</subitemtitle>
<subsection>banfilters</subsection>
<subitemurl>do=add</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
</tabitems>
</menu>
@@ -0,0 +1,161 @@
<?xml version="1.0" encoding="UTF-8"?>
<permissions>
<group>
<grouptitle>Управление пользователями</grouptitle>
<items>
<item>
<key>member_add</key>
<string>Может добавлять пользователей?</string>
</item>
<item>
<key>member_add_admin</key>
<string>Может добавлять АДМИНОВ?</string>
</item>
<item>
<key>member_edit</key>
<string>Может редактировать пользователей?</string>
</item>
<item>
<key>member_edit_admin</key>
<string>Может редактировать АДМИНОВ?</string>
</item>
<item>
<key>member_delete</key>
<string>Может удалять пользователей?</string>
</item>
<item>
<key>member_delete_admin</key>
<string>Может удалять АДМИНОВ?</string>
</item>
<item>
<key>members_merge</key>
<string>Может соединять пользовательские учетки?</string>
</item>
<item>
<key>member_suspend</key>
<string>Может блокировать и разблокировать пользователей?</string>
</item>
<item>
<key>member_suspend_admin</key>
<string>Может блокировать и разблокировать АДМИНОВ?</string>
</item>
<item>
<key>member_prune</key>
<string>Может массово удалять пользователей?</string>
</item>
<item>
<key>member_prune_admin</key>
<string>Может массово удалять АДМИНОВ?</string>
</item>
<item>
<key>member_move</key>
<string>Может перемещать пользователей в другие группы?</string>
</item>
<item>
<key>member_move_admin1</key>
<string>Может перемещать АДМИНОВ в другие группы?</string>
</item>
<item>
<key>member_move_admin2</key>
<string>Может настроить продвижение группы в АДМИНА?</string>
</item>
<item>
<key>member_ban</key>
<string>Может банить пользователей?</string>
</item>
<item>
<key>member_ban_admin</key>
<string>Может банить АДМИНОВ?</string>
</item>
<item>
<key>member_photo</key>
<string>Может изменять пользователские фотографии и аватары?</string>
</item>
<item>
<key>member_photo_admin</key>
<string>Может изменять фотографии и аватары у АДМИНОВ?</string>
</item>
</items>
</group>
<group>
<grouptitle>Инструменты по работе с пользователями</grouptitle>
<items>
<item>
<key>membertools_validating</key>
<string>Может управлять неактивированными пользователями?</string>
</item>
<item>
<key>membertools_locked</key>
<string>Может управлять заблокированными пользователями?</string>
</item>
<item>
<key>membertools_banned</key>
<string>Может управлять забаненными пользователями?</string>
</item>
<item>
<key>membertools_ip</key>
<string>Может использовать инструмент для работы с IP адресами?</string>
</item>
</items>
</group>
<group>
<grouptitle>Звания пользователей</grouptitle>
<items>
<item>
<key>ranks_add</key>
<string>Может добавлять новые?</string>
</item>
<item>
<key>ranks_edit</key>
<string>Может изменять существующие?</string>
</item>
<item>
<key>ranks_delete</key>
<string>Может удалять?</string>
</item>
</items>
</group>
<group>
<grouptitle>Дополнительные поля</grouptitle>
<items>
<item>
<key>profilefields_add</key>
<string>Может добавлять новые?</string>
</item>
<item>
<key>profilefields_edit</key>
<string>Может изменять существующие?</string>
</item>
<item>
<key>profilefields_delete</key>
<string>Может удалять?</string>
</item>
</items>
</group>
<group>
<grouptitle>Бан фильтры</grouptitle>
<items>
<item>
<key>ban_manage</key>
<string>Может добавлять/изменять?</string>
</item>
<item>
<key>ban_remove</key>
<string>Может удалять?</string>
</item>
</items>
</group>
<group>
<grouptitle>Репутация пользователей</grouptitle>
<items>
<item>
<key>reps_manage</key>
<string>Может добавлять/изменять уровни репутации?</string>
</item>
<item>
<key>reps_delete</key>
<string>Может удалять уровни?</string>
</item>
</items>
</group>
</permissions>
@@ -0,0 +1,30 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* Define the default restrictions section
* Last Updated: $Date: 2009-07-28 20:26:37 -0400 (Tue, 28 Jul 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @since 20th February 2002
* @version $Rev: 4948 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
/**
* Very simply returns the default section if one is not
* passed in the URL
*/
$DEFAULT_SECTION = 'restrictions';
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,774 @@
<?php
/**
* Invision Power Services
* IP.Board v3.0.5
* ACP Restrictions
* Last Updated: $Date: 2009-06-10 16:15:40 -0400 (Wed, 10 Jun 2009) $
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.iinvisionpower.com/community/board/license.html
* @package Invision Power Board
* @subpackage Members
* @link http://www.iinvisionpower.com
* @since 1st march 2002
* @version $Revision: 4755 $
*
*/
if ( ! defined( 'IN_ACP' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
exit();
}
class admin_members_restrictions_restrictions extends ipsCommand
{
/**
* Skin object
*
* @access private
* @var object Skin templates
*/
private $html;
/**
* Shortcut for url
*
* @access private
* @var string URL shortcut
*/
private $form_code;
/**
* Shortcut for url (javascript)
*
* @access private
* @var string JS URL shortcut
*/
private $form_code_js;
/**
* Member information
*
* @access private
* @var array Member information
*/
private $member_info = array();
/**
* Main class entry point
*
* @access public
* @param object ipsRegistry reference
* @return void [Outputs to screen]
*/
public function doExecute( ipsRegistry $registry )
{
//-----------------------------------------
// Load skin
//-----------------------------------------
$this->html = $this->registry->output->loadTemplate('cp_skin_restrictions');
//-----------------------------------------
// Set up stuff
//-----------------------------------------
$this->form_code = $this->html->form_code = 'module=restrictions&amp;section=restrictions';
$this->form_code_js = $this->html->form_code_js = 'module=restrictions&section=restrictions';
//-----------------------------------------
// Load lang
//-----------------------------------------
ipsRegistry::getClass('class_localization')->loadLanguageFile( array( 'admin_restrictions' ) );
///-----------------------------------------
// What to do...
//-----------------------------------------
switch( $this->request['do'] )
{
///-----------------------------------------
// Remove restrictions
//-----------------------------------------
case 'accperms-member-remove':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_delete_member' );
$this->_removePermissions( 'member' );
break;
case 'accperms-group-remove':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_delete_group' );
$this->_removePermissions( 'group' );
break;
///-----------------------------------------
// Add restrictions to member
//-----------------------------------------
case 'acpperms-member-add':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_add_member' );
$this->_addRole( 'member' );
break;
case 'acpperms-member-add-complete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_add_member' );
$this->_addMemberDo();
break;
///-----------------------------------------
// Add restrictions to group
//-----------------------------------------
case 'acpperms-group-add':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_add_group' );
$this->_addRole( 'group' );
break;
case 'acpperms-group-add-complete':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_add_group' );
$this->_addGroupDo();
break;
///-----------------------------------------
// Management form..
//-----------------------------------------
case 'accperms-member-edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_edit_member' );
$this->_restrictionsForm( 'member' );
break;
case 'accperms-group-edit':
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_edit_group' );
$this->_restrictionsForm( 'group' );
break;
///-----------------------------------------
// And saving the restrictions..
//-----------------------------------------
case 'acpperms-save':
$this->_restrictionsSave();
break;
default:
case 'overview':
$this->_acppermsList();
break;
}
//-----------------------------------------
// Pass to CP output hander
//-----------------------------------------
$this->registry->getClass('output')->html_main .= $this->registry->getClass('output')->global_template->global_frame_wrapper();
$this->registry->getClass('output')->sendOutput();
}
/**
* Saving the ACP restrictions - here's where it gets really dirty
*
* @access private
* @return void
* @since 2.1.0.2005-7-11
*/
private function _restrictionsSave()
{
$role_id = intval($this->request['id']);
$role_type = $this->request['type'];
if( $role_type == 'member' )
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_edit_member' );
}
else
{
$this->registry->getClass('class_permissions')->checkPermissionAutoMsg( 'restrictions_edit_group' );
}
if( !$role_id OR !$role_type )
{
$this->registry->output->global_message = $this->lang->words['r_whichmodify'];
$this->_acppermsList();
return;
}
if( !in_array( $role_type, array( 'member', 'group' ) ) )
{
$this->registry->output->global_message = $this->lang->words['r_whichmodify'];
$this->_acppermsList();
return;
}
$role_entry = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'admin_permission_rows', 'where' => "row_id_type='{$role_type}' AND row_id=" . $role_id ) );
if( !$role_entry['row_id'] )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_whichrole'], $role_type );
$this->_acppermsList();
return;
}
$updated_permissions = array(
'applications' => array(),
'modules' => array(),
'items' => array(),
);
foreach( $_POST as $key => $value )
{
if( preg_match( "/^app_(\d+)$/", $key, $matches ) )
{
if( $value )
{
$updated_permissions['applications'][] = $matches[1];
}
}
else if( preg_match( "/^module_(\d+)$/", $key, $matches ) )
{
if( $value )
{
$updated_permissions['modules'][] = $matches[1];
}
}
else if( preg_match( "/^item_(\d+)_(\S+)$/", $key, $matches ) )
{
if( $value )
{
$updated_permissions['items'][ $matches[1] ][] = $matches[2];
}
}
}
$this->DB->update( 'admin_permission_rows', array( 'row_perm_cache' => serialize($updated_permissions), 'row_updated' => time() ), "row_id_type='{$role_type}' AND row_id=" . $role_id );
$this->registry->output->global_message = sprintf( $this->lang->words['r_roleupdate'], $role_type );
$this->_acppermsList();
}
/**
* Manage ACP restrictions - The meat and potatoes, so to speak
*
* @access private
* @param string [member|group]
* @return void
* @since 2.1.0.2005-7-11
* @todo One of the only areas that still uses the old XML parser
*/
private function _restrictionsForm( $type='member' )
{
//-------------------------------
// INIT
//-------------------------------
$row_id = $type == 'member' ? intval( $this->request['mid'] ) : intval( $this->request['gid'] );
$perms = array();
//-------------------------------
// Check...
//-------------------------------
if ( ! $row_id )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_notypeid'], $type );
$this->_acppermsList();
return;
}
//-------------------------------
// Grab member's row
//-------------------------------
$row = $this->DB->buildAndFetch( array( 'select' => '*', 'from' => 'admin_permission_rows', 'where' => "row_id_type='{$type}' AND row_id=" . $row_id ) );
$row['current'] = unserialize( $row['row_perm_cache'] );
if( !is_array($row['current']) OR !count($row['current']) )
{
$row['current'] = array(
'applications' => array(),
'modules' => array(),
'items' => array(),
);
}
//-------------------------------
// Grab XML library
//-------------------------------
require_once( IPS_KERNEL_PATH . 'class_xml.php' );
$xml = new class_xml();
//-------------------------------
// Start the madness...err parsing
//-------------------------------
foreach( ipsRegistry::$applications as $app_dir => $app_data )
{
if( !is_array(ipsRegistry::$modules[ $app_dir ]) OR !count(ipsRegistry::$modules[ $app_dir ]) )
{
continue;
}
foreach( ipsRegistry::$modules[ $app_dir ] as $module )
{
$_file = IPSLib::getAppDir( $app_dir ) . '/modules_admin/' . $module['sys_module_key'] . '/xml/permissions.xml';
if( ! $module['sys_module_admin'] )
{
continue;
}
if( ! file_exists( $_file ) )
{
continue;
}
$content = file_get_contents( $_file );
$xml->xml_parse_document( $content );
if ( ! is_array( $xml->xml_array['permissions']['group'][0] ) )
{
//-----------------------------------------
// Ensure [0] is populated
//-----------------------------------------
$xml->xml_array['permissions']['group'] = array( 0 => $xml->xml_array['permissions']['group'] );
}
//-----------------------------------------
// Loop through and sort out permissions and groups...
//-----------------------------------------
$group = 0;
foreach( $xml->xml_array['permissions']['group'] as $entry )
{
//-----------------------------------------
// Do we have a row matching this already?
//-----------------------------------------
$_title = $entry['grouptitle']['VALUE'];
$items = array();
$group++;
if( is_array($entry['items']) AND count($entry['items']) )
{
foreach( $entry['items'] as $item )
{
if( is_array($item) AND count($item) )
{
if( isset($item['key']) )
{
$items[ $item['key']['VALUE'] ] = $item['string']['VALUE'];
}
else
{
foreach( $item as $sub_item )
{
$items[ $sub_item['key']['VALUE'] ] = $sub_item['string']['VALUE'];
}
}
}
}
$perms[ $app_data['app_id'] ][ $module['sys_module_id'] ][ $group ]['title'] = $_title;
$perms[ $app_data['app_id'] ][ $module['sys_module_id'] ][ $group ]['items'] = $items;
}
}
}
}
//-------------------------------
// Print
//-------------------------------
$this->registry->output->html .= $this->html->restrictionsForm( $row_id, $type, $perms, $row['current'] );
}
/**
* List members and groups with restrictions
*
* @access private
* @return void Outputs to screen
* @since 2.1.0.2005-7-7
*/
private function _acppermsList()
{
//-------------------------------
// INIT
//-------------------------------
$members = '';
$groups = '';
//-------------------------------
// Get current ACP listed members
//-------------------------------
$this->DB->build( array( 'select' => 'p.*',
'from' => array( 'admin_permission_rows' => 'p' ),
'add_join' => array(
array(
'select' => 'm.members_display_name, m.member_id, m.member_group_id, m.mgroup_others',
'from' => array( 'members' => 'm' ),
'where' => "p.row_id_type='member' AND m.member_id=p.row_id",
'type' => 'left'
)
),
'order' => 'm.members_display_name DESC'
) );
$outer = $this->DB->execute();
while( $r = $this->DB->fetch($outer) )
{
//-------------------------------
// (Alex) Cross
//-------------------------------
$r['_date'] = ipsRegistry::getClass('class_localization')->getDate( $r['row_updated'], 'SHORT' );
if( $r['row_id_type'] == 'member' )
{
$r['_group_name'] = $this->caches['group_cache'][ $r['member_group_id'] ]['g_title'];
$r['_other_groups'] = '<em>Нет</em>';
if( $r['mgroup_others'] )
{
$other_mgroups = explode( ',', IPSText::cleanPermString( $r['mgroup_others'] ) );
$formatted = array();
if( is_array($other_mgroups) AND count($other_mgroups) )
{
foreach( $other_mgroups as $omg )
{
$formatted[] = $this->caches['group_cache'][ $omg ]['g_title'];
}
$r['_other_groups'] = implode( ', ', $formatted );
}
}
$members .= $this->html->acpMemberRow($r);
}
else
{
$count = $this->DB->buildAndFetch(
array(
'select' => 'count(*) as total',
'from' => 'members',
'where' => "member_group_id = {$r['row_id']} OR mgroup_others LIKE '%,{$r['row_id']},%'",
)
);
$r['_group_name'] = $this->caches['group_cache'][ $r['row_id'] ]['g_title'];
$r['_total'] = $count['total'];
$groups .= $this->html->acpGroupRow($r);
}
}
$this->registry->output->html .= $this->html->acpPermsOverview( $members, $groups );
}
/**
* Remove ACP restrictions - this will make a restricted member or group have full permissions
*
* @access private
* @param string [member|group]
* @return void
* @since 2.1.0.2005-7-11
*/
private function _removePermissions( $type='member' )
{
//-------------------------------
// INIT
//-------------------------------
$row_id = $type == 'member' ? intval( $this->request['mid'] ) : intval( $this->request['gid'] );
//-------------------------------
// Check...
//-------------------------------
if ( ! $row_id )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_notypeid'], $type );
$this->_acppermsList();
return;
}
//-------------------------------
// Remove member's row
//-------------------------------
$this->DB->delete( 'admin_permission_rows', 'row_id=' . $row_id );
//-------------------------------
// Print
//-------------------------------
$this->registry->output->global_message = $this->lang->words['r_lifted'];
$this->_acppermsList();
}
/**
* ACP Perms: Add member form
*
* @access private
* @param string [member|group]
* @return void
* @since 2.1.0.2005-7-7
*/
private function _addRole( $type='member' )
{
$this->registry->output->extra_nav[] = array( '', $this->lang->words['r_nav'] );
//-------------------------------
// Show the form
//-------------------------------
$method = $type == 'member' ? 'restrictionsMemberForm' : 'restrictionsGroupForm';
$this->registry->output->html .= $this->html->$method();
}
/**
* ACP Perms: Finish adding the member
*
* Checks input, adds row to DB if OK
* This bud's for you
*
* @access private
* @return void
* @since 2.1.0.2005-7-8
*/
private function _addMemberDo()
{
//-------------------------------
// INIT
//-------------------------------
$name = trim( $this->request['entered_name'] );
$isok = 0;
//-------------------------------
// Check...
//-------------------------------
if ( ! $name )
{
$this->registry->output->global_message = $this->lang->words['r_entername'];
$this->_addRole( 'member' );
return;
}
//-------------------------------
// Get member...
//-------------------------------
$member = IPSMember::load( $name, 'groups' , 'displayname' );
//-------------------------------
// Check...
//-------------------------------
if ( ! $member['member_id'] )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_noname'], $name );
$this->_addRole( 'member' );
return;
}
//-------------------------------
// Already got 'em
//-------------------------------
$test = $this->DB->buildAndFetch( array( 'select' => 'row_id', 'from' => 'admin_permission_rows', 'where' => "row_id_type='member' AND row_id=" . $member['member_id'] ) );
if ( $test['row_id'] )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_namealready'], $name );
$this->_addRole( 'member' );
return;
}
//-------------------------------
// Don't restrict ourselves
//-------------------------------
if( $member['member_id'] == $this->memberData['member_id'] )
{
$this->registry->output->global_message = $this->lang->words['r_ownaccount'];
$this->_addRole( 'member' );
return;
}
//-------------------------------
// Primary ACP group?
//-------------------------------
if ( $member['g_access_cp'] )
{
$isok = 1;
}
//-------------------------------
// Secondary ACP group?
//-------------------------------
else if ( $member['mgroup_others'] )
{
foreach( explode( ',', IPSText::cleanPermString( $member['mgroup_others'] ) ) as $gid )
{
if ( $this->caches['group_cache'][ $gid ]['g_access_cp'] )
{
$isok = 1;
break;
}
}
}
//-------------------------------
// Not oK?
//-------------------------------
if ( ! $isok )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_noaccess'], $member['members_display_name'] );
$this->_addRole( 'member' );
return;
}
//-------------------------------
// Does we haz groop perms?
// Too many LOLCATZ >.<
//-------------------------------
$groups[] = $member['member_group_id'];
$restrict = array();
if( $member['mgroup_others'] )
{
$groups = array_merge( $groups, explode( ',', IPSText::cleanPermString( $member['mgroup_others'] ) ) );
}
$this->DB->build( array( 'select' => '*', 'from' => 'admin_permission_rows', 'where' => "row_id_type='group' AND row_id IN(" . implode( ',', $groups ) . ")" ) );
$this->DB->execute();
while( $r = $this->DB->fetch() )
{
$restrict = array_merge( $restrict, unserialize($r['row_perm_cache']) );
}
//-------------------------------
// A-OK
//-------------------------------
$this->DB->insert( 'admin_permission_rows', array( 'row_id' => $member['member_id'],
'row_id_type' => 'member',
'row_perm_cache' => serialize( $restrict ),
'row_updated' => time() ) );
$message = count($restrict) ? $this->lang->words['r_restrictbase'] : $this->lang->words['r_noacpaccessuntil'];
$this->registry->output->global_message = sprintf( $this->lang->words['r_addedmember'], $member['members_display_name'], $message );
$this->request[ 'mid'] = $member['member_id'] ;
$this->_restrictionsForm( 'member' );
}
/**
* ACP Perms: Finish adding the group
*
* @access private
* @return void
* @since 2.1.0.2005-7-8
*/
private function _addGroupDo()
{
//-------------------------------
// INIT
//-------------------------------
$g_id = intval( $this->request['entered_group'] );
$isok = 0;
//-------------------------------
// Check...
//-------------------------------
if ( !$g_id )
{
$this->registry->output->global_message = $this->lang->words['r_nogroup'];
$this->_addRole( 'group' );
return;
}
//-------------------------------
// Get member...
//-------------------------------
$group = $this->caches['group_cache'][ $g_id ];
//-------------------------------
// Check...
//-------------------------------
if ( ! $group['g_id'] )
{
$this->registry->output->global_message = $this->lang->words['r_nofindgroup'];
$this->_addRole( 'group' );
return;
}
//-------------------------------
// Already got 'em
//-------------------------------
$test = $this->DB->buildAndFetch( array( 'select' => 'row_id', 'from' => 'admin_permission_rows', 'where' => "row_id_type='group' AND row_id=" . $g_id ) );
if ( $test['row_id'] )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_groupalready'], $group['g_title'] );
$this->_addRole( 'group' );
return;
}
//-------------------------------
// Don't restrict ourselves
//-------------------------------
if( $g_id == $this->memberData['member_group_id'] )
{
$this->registry->output->global_message = $this->lang->words['r_ownaccount'];
$this->_addRole( 'group' );
return;
}
if( in_array( $g_id, explode( ',', IPSText::cleanPermString( $this->memberData['mgroup_others'] ) ) ) )
{
$this->registry->output->global_message = $this->lang->words['r_ownaccount'];
$this->_addRole( 'group' );
return;
}
//-------------------------------
// Primary ACP group?
//-------------------------------
if ( !$group['g_access_cp'] )
{
$this->registry->output->global_message = sprintf( $this->lang->words['r_groupnoacp'], $group['g_title'] );
$this->_addRole( 'group' );
return;
}
//-------------------------------
// A-OK
//-------------------------------
$this->DB->insert( 'admin_permission_rows', array( 'row_id' => $g_id,
'row_id_type' => 'group',
'row_perm_cache' => serialize( array() ),
'row_updated' => time() ) );
$this->registry->output->global_message = sprintf( $this->lang->words['r_addedgroup'], $group['g_title'] );
$this->_acppermsList();
}
}
@@ -0,0 +1 @@
<html>␍<head><title>IP.Board - Bulletin Board System</title></head>␍<body>␍<h1>403: IP.Board -> Forbidden</h1>␍<hr>␍You have reached this page in error, please use your back button to return to the forum.␍<hr>␍<a href="http://www.invisionboard.com/">IP.Board</a>␍</body>␍</html>␍
@@ -0,0 +1,17 @@
<?xml version="1.0" encoding="UTF-8"?>
<menu>
<tabitems>
<item>
<title>Управление администраторскими ограничениями</title>
<subitems>
<subitem>
<subitemtitle>Администраторские ограничения</subitemtitle>
<subsection>restrictions</subsection>
<subitemurl>do=overview</subitemurl>
<subitemrolekey></subitemrolekey>
<subisredirect>0</subisredirect>
</subitem>
</subitems>
</item>
</tabitems>
</menu>
@@ -0,0 +1,32 @@
<?xml version="1.0" encoding="UTF-8"?>
<permissions>
<group>
<grouptitle>Управление ограничениями доступа</grouptitle>
<items>
<item>
<key>restrictions_add_member</key>
<string>Может добавлять ограничения?</string>
</item>
<item>
<key>restrictions_edit_member</key>
<string>Может изменять ограничения?</string>
</item>
<item>
<key>restrictions_delete_member</key>
<string>Может удалять ограничения?</string>
</item>
<item>
<key>restrictions_add_group</key>
<string>Может добавлять ограничения для групп?</string>
</item>
<item>
<key>restrictions_edit_group</key>
<string>Может изменять ограничения для групп?</string>
</item>
<item>
<key>restrictions_delete_group</key>
<string>Может удалять ограничения для групп?</string>
</item>
</items>
</group>
</permissions>