Add new directory structure. Tags will contain current and past releases, and stable will contain any bug fixes to the current stable release so users won't have to get the potentially broken trunk build to fix a screwup in stable.
Trunk updated to 0.9 git-svn-id: http://kusabax.cultnet.net/svn/repo/stable@176 73d99b7e-4f53-4972-b7b7-2ecd3c4d89ee
This commit is contained in:
commit
88bacfad9c
316 files changed
+79806
No files matched your search
@@ -0,0 +1,326 @@
|
||||
<?php
|
||||
/*
|
||||
* This file is part of kusaba.
|
||||
*
|
||||
* kusaba is free software; you can redistribute it and/or modify it under the
|
||||
* terms of the GNU General Public License as published by the Free Software
|
||||
* Foundation; either version 2 of the License, or (at your option) any later
|
||||
* version.
|
||||
*
|
||||
* kusaba is distributed in the hope that it will be useful, but WITHOUT ANY
|
||||
* WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
|
||||
* A PARTICULAR PURPOSE. See the GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License along with
|
||||
* kusaba; if not, write to the Free Software Foundation, Inc.,
|
||||
* 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
||||
* +------------------------------------------------------------------------------+
|
||||
* Posting class
|
||||
* +------------------------------------------------------------------------------+
|
||||
*/
|
||||
class Posting {
|
||||
|
||||
function CheckOekaki() {
|
||||
global $board_class;
|
||||
|
||||
/* If oekaki seems to be in the url... */
|
||||
if (isset($_POST['oekaki'])) {
|
||||
/* See if it checks out and is a valid oekaki id */
|
||||
if ($_POST['oekaki'] != '' && is_file(KU_CGIDIR . 'kusabaoek/' . $_POST['oekaki'] . '.png') && $board_class->board['type'] == '2') {
|
||||
/* Set the variable to tell the script it is handling an oekaki posting, and the oekaki file which will be posted */
|
||||
return KU_CGIDIR . 'kusabaoek/' . $_POST['oekaki'] . '.png';
|
||||
}
|
||||
}
|
||||
|
||||
return '';
|
||||
}
|
||||
|
||||
function CheckReplyTime() {
|
||||
global $tc_db, $board_class;
|
||||
|
||||
/* Get the timestamp of the last time a reply was made by this IP address */
|
||||
$results = $tc_db->GetAll("SELECT MAX(timestamp) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_class->board['id'] . " AND `parentid` != 0 AND `ipmd5` = '" . md5($_SERVER['REMOTE_ADDR']) . "' AND `timestamp` > " . (time() - KU_REPLYDELAY));
|
||||
/* If they have posted before and it was recorded... */
|
||||
if (isset($result)) {
|
||||
/* If the time was shorter than the minimum time distance */
|
||||
if (time() - $line['timestamp'] <= KU_REPLYDELAY) {
|
||||
exitWithErrorPage(_gettext('Please wait a moment before posting again.'), _gettext('You are currently posting faster than the configured minimum post delay allows.'));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function CheckNewThreadTime() {
|
||||
global $tc_db, $board_class;
|
||||
|
||||
/* Get the timestamp of the last time a new thread was made by this IP address */
|
||||
$result = $tc_db->GetOne("SELECT MAX(timestamp) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_class->board['id'] . " AND `parentid` = 0 AND `ipmd5` = '" . md5($_SERVER['REMOTE_ADDR']) . "' AND `timestamp` > " . (time() - KU_NEWTHREADDELAY));
|
||||
/* If they have posted before and it was recorded... */
|
||||
if (isset($result)) {
|
||||
/* If the time was shorter than the minimum time distance */
|
||||
if (time() - $result <= KU_NEWTHREADDELAY) {
|
||||
exitWithErrorPage(_gettext('Please wait a moment before posting again.'), _gettext('You are currently posting faster than the configured minimum post delay allows.'));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function UTF8Strings() {
|
||||
if (function_exists('mb_convert_encoding') && function_exists('mb_check_encoding')) {
|
||||
if (isset($_POST['name']) && !mb_check_encoding($_POST['name'], 'UTF-8')) {
|
||||
$_POST['name'] = mb_convert_encoding($_POST['name'], 'UTF-8');
|
||||
}
|
||||
if (isset($_POST['em']) && !mb_check_encoding($_POST['em'], 'UTF-8')) {
|
||||
$_POST['em'] = mb_convert_encoding($_POST['em'], 'UTF-8');
|
||||
}
|
||||
if (isset($_POST['subject']) && !mb_check_encoding($_POST['subject'], 'UTF-8')) {
|
||||
$_POST['subject'] = mb_convert_encoding($_POST['subject'], 'UTF-8');
|
||||
}
|
||||
if (isset($_POST['message']) && !mb_check_encoding($_POST['message'], 'UTF-8')) {
|
||||
$_POST['message'] = mb_convert_encoding($_POST['message'], 'UTF-8');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function CheckValidPost($is_oekaki) {
|
||||
global $tc_db, $board_class;
|
||||
|
||||
if (
|
||||
( /* A message is set, or an image was provided */
|
||||
isset($_POST['message']) ||
|
||||
isset($_FILES['imagefile'])
|
||||
) || /* It is a validated oekaki posting */
|
||||
$is_oekaki ||
|
||||
( /* It is a text board, meaning only a message is required */
|
||||
$board_class->board['type'] == '1' &&
|
||||
isset($_POST['message'])
|
||||
) || (
|
||||
( /* It has embedding allowed */
|
||||
$board_class->board['uploadtype'] == '1' ||
|
||||
$board_class->board['uploadtype'] == '2'
|
||||
) && ( /* An embed ID was provided, or no file was checked and no ID was supplied */
|
||||
isset($_POST['embed']) ||
|
||||
(
|
||||
$board_class->board['uploadtype'] == '2' &&
|
||||
!isset($_FILES['imagefile']) &&
|
||||
isset($_POST['nofile']) &&
|
||||
$board_class->board['enablenofile'] == true
|
||||
)
|
||||
)
|
||||
)
|
||||
) {
|
||||
return true;
|
||||
} else {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
function CheckMessageLength() {
|
||||
global $board_class;
|
||||
|
||||
/* If the length of the message is greater than the board's maximum message length... */
|
||||
if (strlen($_POST['message']) > $board_class->board['messagelength']) {
|
||||
/* Kill the script, stopping the posting process */
|
||||
exitWithErrorPage(sprintf(_gettext('Sorry, your message is too long. Message length: %d, maximum allowed length: %d'), strlen($_POST['message']), $board_class->board['messagelength']));
|
||||
}
|
||||
}
|
||||
|
||||
function CheckCaptcha() {
|
||||
global $board_class;
|
||||
|
||||
/* If the board has captcha's enabled... */
|
||||
if ($board_class->board['enablecaptcha'] == 1) {
|
||||
/* Check if they entered the correct code. If not... */
|
||||
if ($_SESSION['security_code'] != strtolower($_POST['captcha']) || empty($_SESSION['security_code'])) {
|
||||
/* Kill the script, stopping the posting process */
|
||||
exitWithErrorPage(_gettext('Incorrect captcha entered.'));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function CheckBannedHash() {
|
||||
global $tc_db, $board_class, $bans_class;
|
||||
|
||||
/* Banned file hash check */
|
||||
if (isset($_FILES['imagefile'])) {
|
||||
if ($_FILES['imagefile']['name'] != '') {
|
||||
$results = $tc_db->GetAll("SELECT `bantime` , `description` FROM `" . KU_DBPREFIX . "bannedhashes` WHERE `md5` = " . $tc_db->qstr(md5_file($_FILES['imagefile']['tmp_name'])) . " LIMIT 1");
|
||||
if (count($results) > 0) {
|
||||
$bans_class->BanUser($_SERVER['REMOTE_ADDR'], 'SERVER', '1', $results[0]['bantime'], '', 'Posting a banned file.<br />' . $results[0]['description'], 0, 0, 1);
|
||||
$bans_class->BanCheck($_SERVER['REMOTE_ADDR'], $board_class->board['name']);
|
||||
die();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function CheckIsReply() {
|
||||
global $tc_db, $board_class;
|
||||
|
||||
/* If it appears this is a reply to a thread, and not a new thread... */
|
||||
if (isset($_POST['replythread'])) {
|
||||
if ($_POST['replythread'] != '0') {
|
||||
/* Check if the thread id supplied really exists */
|
||||
$results = $tc_db->GetOne("SELECT COUNT(*) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_class->board['id'] . " AND `IS_DELETED` = '0' AND `id` = " . $tc_db->qstr($_POST['replythread']) . " AND `parentid` = '0' LIMIT 1");
|
||||
/* If it does... */
|
||||
if ($results > 0) {
|
||||
return true;
|
||||
/* If it doesn't... */
|
||||
} else {
|
||||
/* Kill the script, stopping the posting process */
|
||||
exitWithErrorPage(_gettext('Invalid thread ID.'), _gettext('That thread may have been recently deleted.'));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
function CheckNotDuplicateSubject($subject) {
|
||||
global $tc_db, $board_class;
|
||||
|
||||
$result = $tc_db->GetOne("SELECT COUNT(*) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_class->board['id'] . " AND `IS_DELETED` = '0' AND `subject` = " . $tc_db->qstr($subject) . " AND `parentid` = '0'");
|
||||
if ($result > 0) {
|
||||
exitWithErrorPage(_gettext('Duplicate thread subject'), _gettext('Text boards may have only one thread with a unique subject. Please pick another.'));
|
||||
}
|
||||
}
|
||||
|
||||
function GetThreadInfo($id) {
|
||||
global $tc_db, $board_class;
|
||||
|
||||
/* Check if the thread id supplied really exists and if it is locked */
|
||||
$results = $tc_db->GetAll("SELECT `id`,`locked` FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_class->board['id'] . " AND `IS_DELETED` = '0' AND `id` = " . $tc_db->qstr($id) . " AND `parentid` = '0'");
|
||||
/* If it does... */
|
||||
if (count($results) > 0) {
|
||||
/* Get the thread's info */
|
||||
$thread_locked = $results[0]['locked'];
|
||||
$thread_replyto = $results[0]['id'];
|
||||
/* Get the number of replies */
|
||||
$result = $tc_db->GetOne("SELECT COUNT(id) FROM `" . KU_DBPREFIX ."posts` WHERE `boardid` = " . $board_class->board['id'] . " AND `IS_DELETED` = '0' AND `parentid` = " . $tc_db->qstr($id) . "");
|
||||
$thread_replies = $result;
|
||||
|
||||
return array($thread_replies, $thread_locked, $thread_replyto);
|
||||
} else {
|
||||
/* If it doesn't, kill the script, stopping the posting process */
|
||||
exitWithErrorPage(_gettext('Invalid thread ID.'), _gettext('That thread may have been recently deleted.'));
|
||||
}
|
||||
}
|
||||
|
||||
function GetFields() {
|
||||
/* Fetch and process the name, email, and subject fields from the post data */
|
||||
$post_name = isset($_POST['name']) ? htmlspecialchars($_POST['name'], ENT_QUOTES) : '';
|
||||
$post_email = isset($_POST['em']) ? str_replace('"', '', strip_tags($_POST['em'])) : '';
|
||||
/* If the user used a software function, don't store it in the database */
|
||||
if ($post_email == 'return' || $post_email == 'noko') $post_email = '';
|
||||
$post_subject = isset($_POST['subject']) ? htmlspecialchars($_POST['subject'], ENT_QUOTES) : '';
|
||||
|
||||
return array($post_name, $post_email, $post_subject);
|
||||
}
|
||||
|
||||
function GetUserAuthority() {
|
||||
global $tc_db, $board_class;
|
||||
|
||||
$user_authority = 0;
|
||||
$flags = '';
|
||||
|
||||
if (isset($_POST['modpassword'])) {
|
||||
|
||||
$results = $tc_db->GetAll("SELECT `type`, `boards` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = '" . md5_decrypt($_POST['modpassword'], KU_RANDOMSEED) . "' LIMIT 1");
|
||||
|
||||
if (count($results) > 0) {
|
||||
if ($results[0][0] == 1) {
|
||||
$user_authority = 1; // admin
|
||||
} elseif ($results[0][0] == 2 && in_array($board_class->board['name'], explode('|', $results[0][1]))) {
|
||||
$user_authority = 2; // mod
|
||||
} elseif ($results[0][0] == 2 && $results[0][1] == 'allboards') {
|
||||
$user_authority = 2;
|
||||
}/* elseif ($results[0][0] == 3) {
|
||||
$user_authority = 3; // VIP
|
||||
}*/
|
||||
if ($user_authority < 3) { /* set posting flags for mods and admins */
|
||||
if (isset($_POST['displaystaffstatus'])) $flags .= 'D';
|
||||
if (isset($_POST['lockonpost'])) $flags .= 'L';
|
||||
if (isset($_POST['stickyonpost'])) $flags .= 'S';
|
||||
if (isset($_POST['rawhtml'])) $flags .= 'RH';
|
||||
if (isset($_POST['usestaffname'])) $flags .= 'N';
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return array($user_authority, $flags);
|
||||
}
|
||||
|
||||
function CheckBadUnicode($post_name, $post_email, $post_subject, $post_message) {
|
||||
/* Check for bad characters which can cause the page to deform (right-to-left markers, etc) */
|
||||
$bad_ords = array(8235, 8238);
|
||||
|
||||
$ords_name = unistr_to_ords($post_name);
|
||||
$ords_email = unistr_to_ords($post_email);
|
||||
$ords_subject = unistr_to_ords($post_subject);
|
||||
$ords_message = unistr_to_ords($post_message);
|
||||
$ords_filename = isset($_FILES['imagefile']) ? unistr_to_ords($_FILES['imagefile']['name']) : '';
|
||||
foreach ($bad_ords as $bad_ord) {
|
||||
if ($ords_name != '') {
|
||||
if (in_array($bad_ord, $ords_name)) {
|
||||
exitWithErrorPage(_gettext('Your post contains one or more illegal characters.'));
|
||||
}
|
||||
}
|
||||
if ($ords_email != '') {
|
||||
if (in_array($bad_ord, $ords_email)) {
|
||||
exitWithErrorPage(_gettext('Your post contains one or more illegal characters.'));
|
||||
}
|
||||
}
|
||||
if ($ords_subject != '') {
|
||||
if (in_array($bad_ord, $ords_subject)) {
|
||||
exitWithErrorPage(_gettext('Your post contains one or more illegal characters.'));
|
||||
}
|
||||
}
|
||||
if ($ords_message != '') {
|
||||
if (in_array($bad_ord, $ords_message)) {
|
||||
exitWithErrorPage(_gettext('Your post contains one or more illegal characters.'));
|
||||
}
|
||||
}
|
||||
if ($ords_filename != '') {
|
||||
if (in_array($bad_ord, $ords_filename)) {
|
||||
exitWithErrorPage(_gettext('Your post contains one or more illegal characters.'));
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function GetPostTag() {
|
||||
global $board_class;
|
||||
|
||||
/* Check for and parse tags if one was provided, and they are enabled */
|
||||
$post_tag = '';
|
||||
$tags = unserialize(KU_TAGS);
|
||||
if ($board_class->board['type'] == 3 && $tags != '' && isset($_POST['tag'])) {
|
||||
if ($_POST['tag'] != '') {
|
||||
$validtag = false;
|
||||
while (list($tag, $tag_abbr) = each($tags)) {
|
||||
if ($tag_abbr == $_POST['tag']) {
|
||||
$validtag = true;
|
||||
}
|
||||
}
|
||||
if ($validtag) {
|
||||
$post_tag = $_POST['tag'];
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return $post_tag;
|
||||
}
|
||||
|
||||
function CheckBlacklistedText() {
|
||||
global $bans_class, $tc_db;
|
||||
$badlinks = array_map('rtrim', file(KU_ROOTDIR . 'spam.txt', FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES));
|
||||
|
||||
foreach ($badlinks as $badlink) {
|
||||
if (stripos($_POST['message'], $badlink) !== false) {
|
||||
/* They included a blacklisted link in their post. Ban them for an hour */
|
||||
$bans_class->BanUser($_SERVER['REMOTE_ADDR'], 'board.php', 1, 3600, '', $tc_db->qstr(_gettext('Posting a blacklisted link.') . ' (' . $badlink . ')'), $tc_db->qstr($_POST['message']));
|
||||
exitWithErrorPage(sprintf(_gettext('Blacklisted link ( %s ) detected.'), $badlink));
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
?>
|
||||
Reference in new issue
Block a user