assign('includeheader', $tpl_includeheader);
}
/* Show the footer of the manage page */
function Footer() {
global $dwoo_data, $dwoo, $tpl_page;
$dwoo_data->assign('page', $tpl_page);
$board_class = new Board('');
$dwoo->output(KU_TEMPLATEDIR . '/manage.tpl', $dwoo_data);
}
// Creates a salt to be used for passwords
function CreateSalt() {
$chars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789';
$salt = '';
for ($i = 0; $i < 3; ++$i) {
$salt .= $chars[mt_rand(0, strlen($chars) - 1)];
}
return $salt;
}
/* Validate the current session */
function ValidateSession($is_menu = false) {
global $tc_db, $tpl_page;
if (isset($_SESSION['manageusername']) && isset($_SESSION['managepassword'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `username` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = " . $tc_db->qstr($_SESSION['manageusername']) . " AND `password` = " . $tc_db->qstr($_SESSION['managepassword']) . " LIMIT 1");
if (count($results) == 0) {
session_destroy();
exitWithErrorPage(_gettext('Invalid session.'), ''. _gettext('Log in again.') . ' ');
}
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "staff` SET `lastactive` = " . time() . " WHERE `username` = " . $tc_db->qstr($_SESSION['manageusername']));
return true;
} else {
if (!$is_menu) {
$this->LoginForm();
die($tpl_page);
} else {
return false;
}
}
}
/* Show the login form and halt execution */
function LoginForm() {
global $tc_db, $tpl_page;
if (file_exists(KU_ROOTDIR . 'inc/pages/manage_login.html')) {
$tpl_page .= file_get_contents(KU_ROOTDIR . 'inc/pages/manage_login.html');
}
}
/* Check login names and create session if user/pass is correct */
function CheckLogin() {
global $tc_db, $action;
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "loginattempts` WHERE `timestamp` < '" . (time() - 1200) . "'");
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `ip` FROM `" . KU_DBPREFIX . "loginattempts` WHERE `ip` = '" . $_SERVER['REMOTE_ADDR'] . "' LIMIT 6");
if (count($results) > 5) {
exitWithErrorPage(_gettext('System lockout'), _gettext('Sorry, because of your numerous failed logins, you have been locked out from logging in for 20 minutes. Please wait and then try again.'));
} else {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `username`, `password`, `salt` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = " . $tc_db->qstr($_POST['username']) . " AND `type` != 3 LIMIT 1");
if (count($results) > 0) {
if (empty($results[0]['salt'])) {
if (md5($_POST['password']) == $results[0]['password']) {
$salt = $this->CreateSalt();
$tc_db->Execute("UPDATE `" .KU_DBPREFIX. "staff` SET salt = '" .$salt. "' WHERE username = " .$tc_db->qstr($_POST['username']));
$newpass = md5($_POST['password'] . $salt);
$tc_db->Execute("UPDATE `" .KU_DBPREFIX. "staff` SET password = '" .$newpass. "' WHERE username = " .$tc_db->qstr($_POST['username']));
$_SESSION['manageusername'] = $_POST['username'];
$_SESSION['managepassword'] = $newpass;
$_SESSION['token'] = md5($_SESSION['manageusername'] . $_SESSION['managepassword'] . rand(0,100));
$this->SetModerationCookies();
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "loginattempts` WHERE `ip` < '" . $_SERVER['REMOTE_ADDR'] . "'");
$action = 'posting_rates';
management_addlogentry(_gettext('Logged in'), 1);
die('');
} else {
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "loginattempts` ( `username` , `ip` , `timestamp` ) VALUES ( " . $tc_db->qstr($_POST['username']) . " , '" . $_SERVER['REMOTE_ADDR'] . "' , '" . time() . "' )");
exitWithErrorPage(_gettext('Incorrect username/password.'));
}
} else {
if (md5($_POST['password'] . $results[0]['salt']) == $results[0]['password']) {
$_SESSION['manageusername'] = $_POST['username'];
$_SESSION['managepassword'] = md5($_POST['password'] . $results[0]['salt']);
$_SESSION['token'] = md5($_SESSION['manageusername'] . $_SESSION['managepassword'] . rand(0,100));
$this->SetModerationCookies();
$action = 'posting_rates';
management_addlogentry(_gettext('Logged in'), 1);
die('');
} else {
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "loginattempts` ( `username` , `ip` , `timestamp` ) VALUES ( " . $tc_db->qstr($_POST['username']) . " , '" . $_SERVER['REMOTE_ADDR'] . "' , '" . time() . "' )");
exitWithErrorPage(_gettext('Incorrect username/password.'));
}
}
} else {
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "loginattempts` ( `username` , `ip` , `timestamp` ) VALUES ( " . $tc_db->qstr($_POST['username']) . " , '" . $_SERVER['REMOTE_ADDR'] . "' , '" . time() . "' )");
exitWithErrorPage(_gettext('Incorrect username/password.'));
}
}
}
/* Set mod cookies for boards */
function SetModerationCookies() {
global $tc_db, $tpl_page;
if (isset($_SESSION['manageusername'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `boards` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = " . $tc_db->qstr($_SESSION['manageusername']) . " LIMIT 1");
if ($this->CurrentUserIsAdministrator() || $results[0][0] == 'allboards') {
setcookie("kumod", "allboards", time() + 3600, KU_BOARDSFOLDER, KU_DOMAIN);
} else {
if ($results[0][0] != '') {
setcookie("kumod", $results[0][0], time() + 3600, KU_BOARDSFOLDER, KU_DOMAIN);
}
}
}
}
function CheckToken($posttoken) {
if ($posttoken != $_SESSION['token']) {
// Something is strange
session_destroy();
exitWithErrorPage(_gettext('Invalid Token'));
}
}
/* Log current user out */
function Logout() {
global $tc_db, $tpl_page;
setcookie('kumod', '', time() - 3600, KU_BOARDSFOLDER, KU_DOMAIN);
session_destroy();
unset($_SESSION['manageusername']);
unset($_SESSION['managepassword']);
unset($_SESSION['token']);
die('');
}
/* If the user logged in isn't an admin, kill the script */
function AdministratorsOnly() {
global $tc_db, $tpl_page;
if (!$this->CurrentUserIsAdministrator()) {
exitWithErrorPage('That page is for admins only.');
}
}
/* If the user logged in isn't an moderator or higher, kill the script */
function ModeratorsOnly() {
global $tc_db, $tpl_page;
if ($this->CurrentUserIsAdministrator()) {
return true;
} else {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `type` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = '" . $_SESSION['manageusername'] . "' AND `password` = '" . $_SESSION['managepassword'] . "' LIMIT 1");
foreach ($results as $line) {
if ($line['type'] != 2) {
exitWithErrorPage(_gettext('That page is for moderators and administrators only.'));
}
}
}
}
/* See if the user logged in is an admin */
function CurrentUserIsAdministrator() {
global $tc_db, $tpl_page;
if ($_SESSION['manageusername'] == '' || $_SESSION['managepassword'] == '' || $_SESSION['token'] == '') {
$_SESSION['manageusername'] = '';
$_SESSION['managepassword'] = '';
$_SESSION['token'] = '';
return false;
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `type` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = '" . $_SESSION['manageusername'] . "' AND `password` = '" . $_SESSION['managepassword'] . "' LIMIT 1");
foreach ($results as $line) {
if ($line['type'] == 1) {
return true;
} else {
return false;
}
}
/* If the function reaches this point, something is fishy. Kill their session */
session_destroy();
exitWithErrorPage(_gettext('Invalid session, please log in again.'));
}
/* See if the user logged in is a moderator */
function CurrentUserIsModerator() {
global $tc_db, $tpl_page;
if ($_SESSION['manageusername'] == '' || $_SESSION['managepassword'] == '' || $_SESSION['token'] == '') {
$_SESSION['manageusername'] = '';
$_SESSION['managepassword'] = '';
$_SESSION['token'] = '';
return false;
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `type` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = '" . $_SESSION['manageusername'] . "' AND `password` = '" . $_SESSION['managepassword'] . "' LIMIT 1");
foreach ($results as $line) {
if ($line['type'] == 2) {
return true;
} else {
return false;
}
}
/* If the function reaches this point, something is fishy. Kill their session */
session_destroy();
exitWithErrorPage(_gettext('Invalid session, please log in again.'));
}
/* See if the user logged in is a moderator of a specified board */
function CurrentUserIsModeratorOfBoard($board, $username) {
global $tc_db, $tpl_page;
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `type`, `boards` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = '" . $username . "' LIMIT 1");
if (count($results) > 0) {
foreach ($results as $line) {
if ($line['boards'] == 'allboards') {
return true;
} else {
if ($line['type'] == '1') {
return true;
} else {
$array_boards = explode('|', $line['boards']);
if (in_array($board, $array_boards)) {
return true;
} else {
return false;
}
}
}
}
} else {
return false;
}
}
/*
* +------------------------------------------------------------------------------+
* Manage pages
* +------------------------------------------------------------------------------+
*/
/*
* +------------------------------------------------------------------------------+
* Home Pages
* +------------------------------------------------------------------------------+
*/
/* View Announcements */
function announcements() {
global $tc_db, $tpl_page;
$this->ModeratorsOnly();
$tpl_page .= '
'. _gettext('Announcements') .' '. "\n";
$entries = 0;
/* Get all of the announcements, ordered with the newest one placed on top */
$results = $tc_db->GetAll("SELECT * FROM `".KU_DBPREFIX."announcements` ORDER BY `postedat` DESC");
foreach($results AS $line) {
$entries++;
$tpl_page .= ''.stripslashes($line['subject']).' '. _gettext('by') .' ';
$tpl_page .= stripslashes($line['postedby']);
$tpl_page .= ' - '.date("n/j/y @ g:iA T", $line['postedat']);
$tpl_page .= ' ' .
''. stripslashes($line['message']) . '
';
}
}
function posting_rates() {
global $tc_db, $tpl_page;
$tpl_page .= ''. _gettext('Posting rates (past hour)') . ' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards` ORDER BY `name` ASC");
if (count($results) > 0) {
$tpl_page .= ''. _gettext('Board') . ' '. _gettext('Threads') . ' '. _gettext('Replies') . ' '. _gettext('Posts') . ' ';
foreach ($results as $line) {
$rows_threads = $tc_db->GetOne("SELECT HIGH_PRIORITY count(id) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $line['id'] . " AND `parentid` = 0 AND `timestamp` >= " . (time() - 3600));
$rows_replies = $tc_db->GetOne("SELECT HIGH_PRIORITY count(id) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $line['id'] . " AND `parentid` != 0 AND `timestamp` >= " . (time() - 3600));
$rows_posts = $rows_threads + $rows_replies;
$threads_perminute = $rows_threads;
$replies_perminute = $rows_replies;
$posts_perminute = $rows_posts;
$tpl_page .= ''. $line['name'] . ' '. $threads_perminute . ' '. $replies_perminute . ' '. $posts_perminute . ' ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('No boards');
}
}
function statistics() {
global $tc_db, $tpl_page;
$tpl_page .= ''. _gettext('Statistics') .' ';
$tpl_page .= '
';
}
function changepwd() {
global $tc_db, $tpl_page;
$tpl_page .= ''. _gettext('Change account password') . ' ';
if (isset($_POST['oldpwd']) && isset($_POST['newpwd']) && isset($_POST['newpwd2'])) {
$this->CheckToken($_POST['token']);
if ($_POST['oldpwd'] != '' && $_POST['newpwd'] != '' && $_POST['newpwd2'] != '') {
if ($_POST['newpwd'] == $_POST['newpwd2']) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "staff` WHERE `username` = " . $tc_db->qstr($_SESSION['manageusername']) . "");
foreach ($results as $line) {
$staff_passwordenc = $line['password'];
$staff_salt = $line['salt'];
}
if (md5($_POST['oldpwd'].$staff_salt) == $staff_passwordenc) {
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "staff` SET `password` = '" . md5($_POST['newpwd'].$staff_salt) . "' WHERE `username` = " . $tc_db->qstr($_SESSION['manageusername']) . "");
$_SESSION['managepassword'] = md5($_POST['newpwd'].$staff_salt);
$tpl_page .= _gettext('Password successfully changed.');
} else {
$tpl_page .= _gettext('The old password you provided did not match the current one.');
}
} else {
$tpl_page .= _gettext('The second password did not match the first.');
}
} else {
$tpl_page .= _gettext('Please fill in all required fields.');
}
$tpl_page .= ' ';
}
$tpl_page .= '';
}
/*
* +------------------------------------------------------------------------------+
* Site Administration Pages
* +------------------------------------------------------------------------------+
*/
function addannouncement() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$disptable = true; $formval = 'add'; $title = _gettext('Announcement Management');
if(isset($_GET['act'])) {
if ($_GET['act'] == 'edit') {
if (isset($_POST['announcement'])) {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "announcements` SET `subject` = " . $tc_db->qstr($_POST['subject']) . ", `message` = " . $tc_db->qstr($_POST['announcement']) . " WHERE `id` = " . $tc_db->qstr($_GET['id']));
$tpl_page .= ''. _gettext('Announcement edited') .' ';
management_addlogentry(_gettext('Edited an announcement'));
}
$formval = 'edit&id='. $_GET['id']; $title .= ' - Edit';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "announcements` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$values = $results[0]; $disptable = false;
} elseif ($_GET['act'] == 'del') {
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "announcements` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('Announcement successfully deleted') .' ';
management_addlogentry(_gettext('Deleted an announcement'), 9);
} elseif ($_GET['act'] == 'add' && isset($_POST['announcement']) && isset($_POST['subject'])) {
if (!empty($_POST['announcement']) && !empty($_POST['subject'])) {
$tpl_page .= ' ';
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "announcements` ( `subject` , `message` , `postedat` , `postedby` ) VALUES ( " . $tc_db->qstr($_POST['subject']) . " , " . $tc_db->qstr($_POST['announcement']) . " , '" . time() . "' , " . $tc_db->qstr($_SESSION['manageusername']) . " )");
$tpl_page .= ''. _gettext('Announcement successfully added.') . ' ';
management_addlogentry(_gettext('Added an announcement'), 9);
$tpl_page .= ' ';
} else {
$tpl_page .= ' '. _gettext('You must enter a subject as well as a post.') .' ';
}
}
}
$tpl_page .= ''. $title . '
';
if ($disptable) {
$tpl_page .= ''. _gettext('Edit/Delete announcement') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "announcements` ORDER BY `id` DESC");
if (count($results) > 0) {
$tpl_page .= ''. _gettext('Date Added') .' '. _gettext('Subject') .' '. _gettext('Message') .' '. _gettext('Edit/Delete') .' ';
foreach ($results as $line) {
$tpl_page .= ''. date('F j, Y, g:i a', $line['postedat']) . ' '. $line['subject'] . ' '. $line['message'] . ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('No announcements yet.');
}
}
}
/* Edit Dwoo templates */
function templates() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$files = array();
$tpl_page .= ''. _gettext('Template editor') .' ';
if ($dh = opendir(KU_TEMPLATEDIR)) {
while (($file = readdir($dh)) !== false) {
if($file != '.' && $file != '..')
$files[] = $file;
}
closedir($dh);
}
sort($files);
if(isset($_POST['templatedata']) && isset($_POST['template'])) {
$this->CheckToken($_POST['token']);
$file = basename($_POST['template']);
if (in_array($file, $files)) {
if(file_exists(KU_TEMPLATEDIR . '/'. $file)) {
file_put_contents(KU_TEMPLATEDIR . '/'. $file, $_POST['templatedata']);
$tpl_page .= ''. _gettext('Template edited') .' ';
if (isset($_POST['rebuild'])) {
$this->rebuildall();
}
unset($_POST['template']);
unset($_POST['templatedata']);
}
}
}
if(!isset($_POST['templatedata']) && !isset($_POST['template'])) {
$tpl_page .= '
' ._gettext('Template'). ':
';
foreach($files as $template) {
$tpl_page .=''. $template . ' ';
}
$tpl_page .= ' ';
}
if(!isset($_POST['templatedata']) && isset($_POST['template'])) {
$file = basename($_POST['template']);
if (in_array($file, $files)) {
if(file_exists(KU_TEMPLATEDIR . '/'. $file)) {
$tpl_page .= '
'. htmlspecialchars(file_get_contents(KU_TEMPLATEDIR . '/'. $file)) . '
'. _gettext('Rebuild HTML after edit?') .'
'. sprintf(_gettext('To access Kusaba variables, use {%%KU_VARNAME}, for example {%%KU_BOARDSPATH} would be replaced with %s'), KU_BOARDSPATH) . '
'. _gettext('Enclose text in {t}{/t} blocks to allow them to be translated for different languages.') . '
';
}
}
}
$tpl_page .= ' ';
}
/* Add, edit, delete, and view news entries */
function news() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$disptable = true; $formval = 'add'; $title = _gettext('News Management');
if(isset($_GET['act'])) {
if ($_GET['act'] == 'edit') {
if (isset($_POST['news'])) {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "front` SET `subject` = " . $tc_db->qstr($_POST['subject']) . ", `message` = " . $tc_db->qstr($_POST['news']) . ", `email` = " . $tc_db->qstr($_POST['email']) . " WHERE `id` = " . $tc_db->qstr($_GET['id']) . " AND `page` = 0");
$tpl_page .= ''. _gettext('News post edited') .' ';
management_addlogentry(_gettext('Edited a news entry'), 9);
}
$formval = 'edit&id='. $_GET['id']; $title .= ' - Edit';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "front` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$values = $results[0];
$disptable = false;
} elseif ($_GET['act'] == 'del') {
$results = $tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "front` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('News post deleted') .' ';
management_addlogentry(_gettext('Deleted a news entry'), 9);
} elseif ($_GET['act'] == 'add') {
if (isset($_POST['news']) && isset($_POST['subject']) && isset($_POST['email'])) {
if (!empty($_POST['news']) || !empty($_POST['subject'])) {
$this->CheckToken($_POST['token']);
$tpl_page .= ' ';
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "front` ( `page`, `subject` , `message` , `timestamp` , `poster` , `email` ) VALUES ( '0', " . $tc_db->qstr($_POST['subject']) . " , " . $tc_db->qstr($_POST['news']) . " , '" . time() . "' , " . $tc_db->qstr($_SESSION['manageusername']) . " , " . $tc_db->qstr($_POST['email']) . " )");
$tpl_page .= ''. _gettext('News entry successfully added.') . ' ';
management_addlogentry(_gettext('Added a news entry'), 9);
$tpl_page .= ' ';
} else {
$tpl_page .= ' '. _gettext('You must enter a subject as well as a post.') .' ';
}
}
}
}
$tpl_page .= ''. $title . '
'. _gettext('Subject') . ':
'. _gettext('Can not be left blank.') . '
'. _gettext('Post') . ':
' . (isset($values['message']) ? htmlspecialchars($values['message']) : '') . '
'. _gettext('E-mail') . ':
'. _gettext('Can be left blank.') . '
';
if ($disptable) {
$tpl_page .= ''. _gettext('Edit/Delete News') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "front` WHERE `page` = 0 ORDER BY `timestamp` DESC");
if (count($results) > 0) {
$tpl_page .= ''. _gettext('Date Added') .' '. _gettext('Subject') .' '. _gettext('Message') .' '. _gettext('Edit/Delete') .' ';
foreach ($results as $line) {
$tpl_page .= ''. date('F j, Y, g:i a', $line['timestamp']) . ' '. $line['subject'] . ' '. $line['message'] . ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('No news posts yet.');
}
}
}
/* Add, edit, or delete FAQ entries */
function faq() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$disptable = true; $formval = 'add'; $title = _gettext('FAQ Management');
if(isset($_GET['act'])) {
if ($_GET['act'] == 'edit') {
if (isset($_POST['faq'])) {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "front` SET `subject` = " . $tc_db->qstr($_POST['heading']) . ", `message` = " . $tc_db->qstr($_POST['faq']) . ", `order` = " . intval($_POST['order']) . " WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('FAQ entry edited') .' ';
management_addlogentry(_gettext('Edited a FAQ entry'), 9);
}
$formval = 'edit&id='. $_GET['id']; $title .= ' - Edit';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "front` WHERE `id` = " . $tc_db->qstr($_GET['id']));
$values = $results[0];
$disptable = false;
} elseif ($_GET['act'] == 'del') {
$results = $tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "front` WHERE `id` = " . $tc_db->qstr($_GET['id']));
$tpl_page .= ''. _gettext('FAQ entry deleted') .' ';
management_addlogentry(_gettext('Deleted a FAQ entry'), 9);
} elseif ($_GET['act'] == 'add') {
if (isset($_POST['faq']) && isset($_POST['heading']) && isset($_POST['order'])) {
if (!empty($_POST['faq']) || !empty($_POST['heading'])) {
$this->CheckToken($_POST['token']);
$tpl_page .= ' ';
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "front` ( `page`, `subject` , `message` , `order` ) VALUES ( '1', " . $tc_db->qstr($_POST['heading']) . " , " . intval($_POST['faq']) . " , " . intval($_POST['order']) . " )");
$tpl_page .= ''. _gettext('FAQ entry successfully added.') . ' ';
management_addlogentry(_gettext('Added a FAQ entry'), 9);
$tpl_page .= ' ';
} else {
$tpl_page .= ' '. _gettext('You must enter a heading as well as a post.') .' ';
}
}
}
}
$tpl_page .= ''. $title . '
'. _gettext('Heading') . ':
'. _gettext('Can not be left blank.') . '
'. _gettext('Post') . ':
' . (isset($values['message']) ? htmlspecialchars($values['message']) : '') . '
'. _gettext('Order') . ':
'. _gettext('This can be left blank, however it will appear at the very top of the list') . '
';
if ($disptable) {
$tpl_page .= ''. _gettext('Edit/Delete FAQ Entries') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "front` WHERE `page` = 1 ORDER BY `order` ASC");
if (count($results) > 0) {
$tpl_page .= ''. _gettext('Order') .' '. _gettext('Heading') .' '. _gettext('Message') .' '. _gettext('Edit/Delete') .' ';
foreach ($results as $line) {
$tpl_page .= ''. $line['order'] . ' '. $line['subject'] . ' '. $line['message'] . ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('No FAQ entries yet.');
}
}
}
/* Add, edit, or delete Rules Entries */
function rules() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$disptable = true; $formval = 'add'; $title = _gettext('Rules Management');
if(isset($_GET['act'])) {
if ($_GET['act'] == 'edit') {
if (isset($_POST['rules'])) {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "front` SET `subject` = " . $tc_db->qstr($_POST['heading']) . ", `message` = " . $tc_db->qstr($_POST['rules']) . ", `order` = " . intval($_POST['order']) . " WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('Rules entry edited') .' ';
management_addlogentry(_gettext('Edited a Rule entry'), 9);
}
$formval = 'edit&id='. $_GET['id']; $title .= ' - Edit';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "front` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$values = $results[0];
$disptable = false;
} elseif ($_GET['act'] == 'del') {
$results = $tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "front` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('Rule entry deleted') .' ';
management_addlogentry(_gettext('Deleted a Rules entry'), 9);
} elseif ($_GET['act'] == 'add') {
if (isset($_POST['rules']) && isset($_POST['heading']) && isset($_POST['order'])) {
if (!empty($_POST['rules']) || !empty($_POST['heading'])) {
$this->CheckToken($_POST['token']);
$tpl_page .= ' ';
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "front` ( `page`, `subject` , `message` , `order` ) VALUES ( '2', " . $tc_db->qstr($_POST['heading']) . " , " . $tc_db->qstr($_POST['rules']) . " , " . intval($_POST['order']) . " )");
$tpl_page .= ''. _gettext('Rules entry successfully added.') . ' ';
management_addlogentry(_gettext('Added a Rule entry'), 9);
$tpl_page .= ' ';
} else {
$tpl_page .= ' '. _gettext('You must enter a heading as well as a post.') .' ';
}
}
}
}
$tpl_page .= ''. $title . '
'. _gettext('Heading') . ':
'. _gettext('Can not be left blank.') . '
'. _gettext('Post') . ':
' . (isset($values['message']) ? htmlspecialchars($values['message']) : '') . '
'. _gettext('Order') . ':
'. _gettext('This can be left blank, however it will appear at the very top of the list') . '
';
if ($disptable) {
$tpl_page .= ''. _gettext('Edit/Delete Rule Entries') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "front` WHERE `page` = 2 ORDER BY `order` ASC");
if (count($results) > 0) {
$tpl_page .= ''. _gettext('Order') .' '. _gettext('Heading') .' '. _gettext('Message') .' '. _gettext('Edit/Delete') .' ';
foreach ($results as $line) {
$tpl_page .= ''. $line['order'] . ' '. $line['subject'] . ' '. $line['message'] . ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('No Rule entries yet.');
}
}
}
function blotter() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
if (!KU_BLOTTER) exitWithErrorPage(_gettext('Blotter is disabled'));
$tpl_page .= '' ._gettext('Blotter'). ' ';
$act = 'add'; $values = array();
if (isset($_GET['act'])) {
switch($_GET['act']) {
case 'add':
if (isset($_POST['message'])) {
$this->CheckToken($_POST['token']);
$important = (isset($_POST['important'])) ? 1 : 0;
$tc_db->Execute("INSERT INTO `" . KU_DBPREFIX . "blotter` (`at`, `message`, `important`) VALUES ('" . time() . "', " . $tc_db->qstr($_POST['message']) . ", '" . $important . "')");
$tpl_page .= ''. _gettext('Blotter entry added.') . ' ';
clearBlotterCache();
}
break;
case 'del':
if (is_numeric($_GET['id'])) {
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "blotter` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('Blotter entry deleted.') . ' ';
clearBlotterCache();
} else {
exitWithErrorPage(_gettext('Invalid ID'));
}
break;
case 'edit':
if (is_numeric($_GET['id'])) {
$act = 'edit&id=' .$_GET['id'];
if (isset($_POST['message'])) {
$this->CheckToken($_POST['token']);
$important = (isset($_POST['important'])) ? 1 : 0;
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "blotter` SET `message` = " . $tc_db->qstr($_POST['message']) . ", `important` = '" . $important . "' WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('Blotter entry updated.') . ' ';
clearBlotterCache();
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "blotter` WHERE `id` = " . $tc_db->qstr($_GET['id']) . " LIMIT 1");
$values = $results[0];
} else {
exitWithErrorPage(_gettext('Invalid ID'));
}
break;
default:
exitWithErrorPage(_gettext('Invalid value for \'act\''));
break;
}
}
$tpl_page .= '
' ._gettext('Message'). ':
' ._gettext('Important'). ':
';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "blotter` ORDER BY `id` DESC");
if (count($results) > 0) {
$tpl_page .= ''. _gettext('At') . ' '. _gettext('Message') . ' '. _gettext('Important') . ' ';
foreach ($results as $line) {
$tpl_page .= ''. date('m/d/y', $line['at']) . ' '. $line['message'] . ' ';
$tpl_page .= ($line['important'] == 1) ? _gettext('Yes') : _gettext('No');
$tpl_page .= ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('No blotter entries');
}
}
/* Display disk space used per board, and finally total in a large table */
function spaceused() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Disk space used') . ' ';
$spaceused_res = 0;
$spaceused_src = 0;
$spaceused_thumb = 0;
$spaceused_total = 0;
$files_res = 0;
$files_src = 0;
$files_thumb = 0;
$files_total = 0;
$tpl_page .= ''. _gettext('Board') .' '. _gettext('Area') .' '. _gettext('Files') .' '. _gettext('Space Used') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `name` FROM `" . KU_DBPREFIX . "boards` ORDER BY `name` ASC");
foreach ($results as $line) {
list($spaceused_board_res, $files_board_res) = recursive_directory_size(KU_BOARDSDIR . $line['name'] . '/res');
list($spaceused_board_src, $files_board_src) = recursive_directory_size(KU_BOARDSDIR . $line['name'] . '/src');
list($spaceused_board_thumb, $files_board_thumb) = recursive_directory_size(KU_BOARDSDIR . $line['name'] . '/thumb');
$spaceused_board_total = $spaceused_board_res + $spaceused_board_src + $spaceused_board_thumb;
$files_board_total = $files_board_res + $files_board_src + $files_board_thumb;
$spaceused_res += $spaceused_board_res;
$files_res += $files_board_res;
$spaceused_src += $spaceused_board_src;
$files_src += $files_board_src;
$spaceused_thumb += $spaceused_board_thumb;
$files_thumb += $files_board_thumb;
$spaceused_total += $spaceused_board_total;
$files_total += $files_board_total;
$tpl_page .= '/'.$line['name'].'/ res/ '. number_format($files_board_res) . ' '. ConvertBytes($spaceused_board_res) . ' ';
$tpl_page .= 'src/ '. number_format($files_board_src) . ' '. ConvertBytes($spaceused_board_src) . ' ';
$tpl_page .= 'thumb/ '. number_format($files_board_thumb) . ' '. ConvertBytes($spaceused_board_thumb) . ' ';
$tpl_page .= ''. _gettext('Total') .' '. number_format($files_board_total) . ' '. ConvertBytes($spaceused_board_total) . ' ';
}
$tpl_page .= ''. _gettext('All boards') .' res/ '. number_format($files_res) . ' '. ConvertBytes($spaceused_res) . ' ';
$tpl_page .= 'src/ '. number_format($files_src) . ' '. ConvertBytes($spaceused_src) . ' ';
$tpl_page .= 'thumb/ '. number_format($files_thumb) . ' '. ConvertBytes($spaceused_thumb) . ' ';
$tpl_page .= ''. _gettext('Total') .' '. number_format($files_total) . ' '. ConvertBytes($spaceused_total) . ' ';
$tpl_page .= '
';
management_addlogentry(_gettext('Viewed disk space used'), 0);
}
function staff() { //183 lines
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= '' ._gettext('Staff'). ' ';
if (isset($_GET['add']) && !empty($_POST['username']) && !empty($_POST['password'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" .KU_DBPREFIX. "staff` WHERE `username` = " .$tc_db->qstr($_POST['username']));
if (count($results) == 0) {
if ($_POST['type'] < 3 && $_POST['type'] >= 0) {
$this->CheckToken($_POST['token']);
$salt = $this->CreateSalt();
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" .KU_DBPREFIX. "staff` ( `username` , `password` , `salt` , `type` , `addedon` ) VALUES (" .$tc_db->qstr($_POST['username']). " , '" .md5($_POST['password'] . $salt). "' , '" .$salt. "' , '" .$_POST['type']. "' , '" .time(). "' )");
$log = _gettext('Added'). ' ';
switch ($_POST['type']) {
case 0:
$log .= _gettext('Janitor');
break;
case 1:
$log .= _gettext('Administrator');
break;
case 2:
$log .= _gettext('Moderator');
break;
}
$log .= ' '. $_POST['username'];
management_addlogentry($log, 6);
$tpl_page .= _gettext('Staff member successfully added.');
} else {
exitWithErrorPage('Invalid type');
}
} else {
$tpl_page .= _gettext('A staff member with that ID already exists.');
}
} elseif (isset($_GET['del']) && $_GET['del'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "staff` WHERE `id` = " . $tc_db->qstr($_GET['del']) . "");
if (count($results) > 0) {
$username = $results[0]['username'];
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "staff` WHERE `id` = " . $tc_db->qstr($_GET['del']) . "");
$tpl_page .= _gettext('Staff successfully deleted') . ' ';
management_addlogentry(_gettext('Deleted staff member') . ': '. $username, 6);
} else {
$tpl_page .= _gettext('Invalid staff ID.');
}
} elseif (isset($_GET['edit']) && $_GET['edit'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "staff` WHERE `id` = " . $tc_db->qstr($_GET['edit']) . "");
if (count($results) > 0) {
if (isset($_POST['submitting'])) {
$this->CheckToken($_POST['token']);
$username = $results[0]['username'];
$type = $results[0]['type'];
$boards = array();
if (isset($_POST['modsallboards'])) {
$newboards = array('allboards');
} else {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY name FROM `" . KU_DBPREFIX . "boards`");
foreach ($results as $line) {
$boards = array_merge($boards, array($line['name']));
}
$changed_boards = array();
$newboards = array();
while (list($postkey, $postvalue) = each($_POST)) {
if (substr($postkey, 0, 8) == "moderate") {
$changed_boards = array_merge($changed_boards, array(substr($postkey, 8)));
}
}
while (list(, $thisboard_name) = each($boards)) {
if (in_array($thisboard_name, $changed_boards)) {
$newboards = array_merge($newboards, array($thisboard_name));
}
}
}
$logentry = _gettext('Updated staff member') . ' - ';
if ($_POST['type'] == '1') {
$logentry .= _gettext('Administrator');
} elseif ($_POST['type'] == '2') {
$logentry .= _gettext('Moderator');
} elseif ($_POST['type'] == '0') {
$logentry .= _gettext('Janitor');
} else {
exitWithErrorPage('Something went wrong.');
}
$logentry .= ': '. $username;
if ($_POST['type'] != '1') {
$logentry .= ' - '. _gettext('Moderates') . ': ';
if (isset($_POST['modsallboards'])) {
$logentry .= strtolower(_gettext('All boards'));
} else {
$logentry .= '/'. implode('/, /', $newboards) . '/';
}
}
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "staff` SET `boards` = " . $tc_db->qstr(implode('|', $newboards)) . " , `type` = " .$tc_db->qstr($_POST['type']). " WHERE `id` = " . $tc_db->qstr($_GET['edit']) . "");
management_addlogentry($logentry, 6);
$tpl_page .= _gettext('Staff successfully updated') . ' ';
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "staff` WHERE `id` = '" . $_GET['edit'] . "'");
$username = $results[0]['username'];
$type = $results[0]['type'];
$boards = explode('|', $results[0]['boards']);
$tpl_page .= '
' ._gettext('Username'). ':
' ._gettext('Type'). ':
';
$tpl_page .= ($type==1) ? '' ._gettext('Administrator'). ' ' : '' ._gettext('Administrator'). ' ';
$tpl_page .= ($type==2) ? '' ._gettext('Moderator'). ' ' : '' ._gettext('Moderator'). ' ';
$tpl_page .= ($type==0) ? '' ._gettext('Janitor'). ' ' : '' ._gettext('Janitor'). ' ';
$tpl_page .= ' ';
$tpl_page .= _gettext('Moderates') . '
' ._gettext('All boards'). ' '. "\n";
$tpl_page .= ($boards==array('allboards')) ? ' ' : ' ';
$tpl_page .= ' ' ._gettext('or'). ' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards`");
foreach ($results as $line) {
$tpl_page .= ''. $line['name'] . '
';
}
}
$tpl_page .= '
' ._gettext('Username'). ':
' ._gettext('Password'). ':
' ._gettext('Type'). ':
' ._gettext('Administrator'). '
' ._gettext('Moderator'). '
' ._gettext('Janitor'). '
';
$tpl_page .= ''. _gettext('Username') . ' '. _gettext('Added on') . ' '. _gettext('Last active') . ' '. _gettext('Moderating boards') . ' '. "\n";
$i = 1;
while($i <= 3) {
if ($i == 1) {
$stafftype = 'Administrator';
$numtype = 1;
} elseif ($i == 2) {
$stafftype = 'Moderator';
$numtype = 2;
} elseif ($i == 3) {
$stafftype = 'Janitor';
$numtype = 0;
}
$tpl_page .= ''. _gettext($stafftype) . ' '. "\n";
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "staff` WHERE `type` = '" .$numtype. "' ORDER BY `username` ASC");
if (count($results) > 0) {
foreach ($results as $line) {
$tpl_page .= '' .$line['username']. ' ' .date("y/m/d(D)H:i", $line['addedon']). ' ';
if ($line['lastactive'] == 0) {
$tpl_page .= _gettext('Never');
} elseif ((time() - $line['lastactive']) > 300) {
$tpl_page .= timeDiff($line['lastactive'], false);
} else {
$tpl_page .= _gettext('Online now');
}
$tpl_page .= ' ';
if ($line['boards'] != '' || $line['type'] == 1) {
if ($line['boards'] == 'allboards' || $line['type'] == 1) {
$tpl_page .= _gettext('All boards') ;
} else {
$tpl_page .= '/'. implode('/ , /', explode('|', $line['boards'])) . '/ ';
}
} else {
$tpl_page .= _gettext('No boards');
}
$tpl_page .= ' ['. _gettext('Edit') . ' ] ['. _gettext('Delete') .' ] '. "\n";
}
} else {
$tpl_page .= ''. _gettext('None') . ' '. "\n";
}
$i++;
}
$tpl_page .= '
';
}
/* Display moderators and administrators actions which were logged */
function modlog() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "modlog` WHERE `timestamp` < '" . (time() - KU_MODLOGDAYS * 86400) . "'");
$tpl_page .= ''. ('ModLog') . '
'. _gettext('Time') .' '. _gettext('User') .' '. _gettext('Action') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "modlog` ORDER BY `timestamp` DESC");
foreach ($results as $line) {
$tpl_page .= "" . date("y/m/d(D)H:i", $line['timestamp']) . " " . $line['user'] . " " . $line['entry'] . " ";
}
$tpl_page .= '
';
}
function proxyban() {
global $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Ban proxy list') . ' ';
if (isset($_FILES['imagefile'])) {
$bans_class = new Bans;
$ips = 0;
$successful = 0;
$proxies = file($_FILES['imagefile']['tmp_name']);
foreach($proxies as $proxy) {
if (preg_match('/.[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+.*/', $proxy)) {
$proxy = trim($proxy);
$ips++;
if ($bans_class->BanUser(preg_replace('/:.*/', '', $proxy), 'SERVER', 1, 0, '', 'IP from proxylist automatically banned', '', 0, 0, 1, true)) {
$successful++;
}
}
}
management_addlogentry(sprintf(_gettext('Banned %d IP addresses using an IP address list.'), $successful), 8);
$tpl_page .= $successful . ' of '. $ips . ' IP addresses banned.';
} else {
$tpl_page .= ' '. _gettext('Proxy list') .'
'. _gettext('The proxy list is assumed to be in plaintext *.*.*.*:port or *.*.*.* format, one IP per line.') .' ';
}
}
function sql() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('SQL query') . ' ';
if (isset($_POST['query'])) {
$this->CheckToken($_POST['token']);
$tpl_page .= ' ';
$result = $tc_db->Execute($_POST['query']);
if ($result) {
$tpl_page .= _gettext('Query executed successfully');
} else {
$tpl_page .= 'Error: '. $tc_db->ErrorMsg();
}
$tpl_page .= ' ';
management_addlogentry(_gettext('Inserted SQL'), 0);
}
$tpl_page .= '
';
}
function cleanup() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Cleanup') . ' ';
if (isset($_POST['run'])) {
$tpl_page .= ' '. _gettext('Deleting non-deleted replies which belong to deleted threads.') .' ';
$this->delorphanreplies(true);
$tpl_page .= ' '. _gettext('Deleting unused images.') .' ';
$this->delunusedimages(true);
$tpl_page .= ' '. _gettext('Removing posts deleted more than one week ago from the database.') .' ';
$results = $tc_db->GetAll("SELECT `name`, `type`, `id` FROM `" . KU_DBPREFIX . "boards`");
foreach ($results AS $line) {
if ($line['type'] != 1) {
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $line['id'] . " AND `IS_DELETED` = 1 AND `deleted_timestamp` < " . (time() - 604800) . "");
}
}
$tpl_page .= _gettext('Optimizing all tables in database.') .' ';
if (KU_DBTYPE == 'mysql' || KU_DBTYPE == 'mysqli') {
$results = $tc_db->GetAll("SHOW TABLES");
foreach ($results AS $line) {
$tc_db->Execute("OPTIMIZE TABLE `" . $line[0] . "`");
}
}
if (KU_DBTYPE == 'postgres7' || KU_DBTYPE == 'postgres8' || KU_DBTYPE == 'postgres') {
$results = $tc_db->GetAll("SELECT table_name FROM information_schema.tables WHERE table_schema='public' AND table_type='BASE TABLE'");
foreach ($results AS $line) {
$tc_db->Execute("VACUUM ANALYZE `" . $line[0] . "`");
}
}
$tpl_page .= _gettext('Cleanup finished.');
management_addlogentry(_gettext('Ran cleanup'), 2);
} else {
$tpl_page .= ''. "\n" .
' '. "\n" .
' ';
}
}
/*
* +------------------------------------------------------------------------------+
* Boards Administration Pages
* +------------------------------------------------------------------------------+
*/
function adddelboard() {
global $tc_db, $tpl_page, $board_class;
$this->AdministratorsOnly();
if (isset($_POST['directory'])) {
$this->CheckToken($_POST['token']);
if (isset($_POST['add'])) {
$tpl_page .= $this->addBoard($_POST['directory'], $_POST['desc']);
} elseif (isset($_POST['del'])) {
if (isset($_POST['confirmation'])) {
$tpl_page .= $this->delBoard($_POST['directory'], $_POST['confirmation']);
} else {
$tpl_page .= $this->delBoard($_POST['directory']);
}
}
}
$tpl_page .= ''. _gettext('Add board') . '
'. _gettext('Directory') . ':
'. _gettext('The directory of the board.') . ' '. _gettext('Only put in the letter(s) of the board directory, no slashes!') . '
'. _gettext('Description') . ':
'. _gettext('The name of the board.') . '
'. _gettext('First Post ID') . ':
'. _gettext('The first post of this board will recieve this ID.') . '
'. _gettext('Delete board') .'
'. _gettext('Directory') .': ' .
$this->MakeBoardListDropdown('directory', $this->BoardList($_SESSION['manageusername'])) .
'
';
}
function addBoard($dir, $desc) {
global $tc_db;
$this->AdministratorsOnly();
$output = '';
$output .= ''. _gettext('Add Results') .' ';
$dir = cleanBoardName($dir);
if ($dir != '' && $desc != '') {
if (strtolower($dir) != 'allboards') {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($dir) . "");
if (count($results) == 0) {
if (mkdir(KU_BOARDSDIR . $dir, 0777) && mkdir(KU_BOARDSDIR . $dir . '/res', 0777) && mkdir(KU_BOARDSDIR . $dir . '/src', 0777) && mkdir(KU_BOARDSDIR . $dir . '/thumb', 0777)) {
file_put_contents(KU_BOARDSDIR . $dir . '/.htaccess', 'DirectoryIndex '. KU_FIRSTPAGE . '');
file_put_contents(KU_BOARDSDIR . $dir . '/src/.htaccess', 'AddType text/plain .ASM .C .CPP .CSS .JAVA .JS .LSP .PHP .PL .PY .RAR .SCM .TXT'. "\n" . 'SetHandler default-handler');
if ($_POST['firstpostid'] < 1) {
$_POST['firstpostid'] = 1;
}
$tc_db->Execute("INSERT INTO `" . KU_DBPREFIX . "boards` ( `name` , `desc` , `createdon`, `start`, `image`, `includeheader` ) VALUES ( " . $tc_db->qstr($dir) . " , " . $tc_db->qstr($desc) . " , '" . time() . "', " . $_POST['firstpostid'] . ", '', '' )");
$boardid = $tc_db->Insert_Id();
$filetypes = $tc_db->GetAll("SELECT " . KU_DBPREFIX . "filetypes.id FROM " . KU_DBPREFIX . "filetypes WHERE " . KU_DBPREFIX . "filetypes.filetype = 'JPG' OR " . KU_DBPREFIX . "filetypes.filetype = 'GIF' OR " . KU_DBPREFIX . "filetypes.filetype = 'PNG';");
foreach ($filetypes AS $filetype) {
$tc_db->Execute("INSERT INTO `" . KU_DBPREFIX . "board_filetypes` ( `boardid` , `typeid` ) VALUES ( " . $boardid . " , " . $filetype['id'] . " );");
}
$board_class = new Board($dir);
$board_class->RegenerateAll();
unset($board_class);
$output .= _gettext('Board successfully added.') . '/'. $dir . '/ ! ';
$output .= ' ';
management_addlogentry(_gettext('Added board') . ': /'. $dir . '/', 3);
} else {
$output .= ' '. _gettext('Unable to create directories.');
}
} else {
$output .= _gettext('A board with that name already exists.');
}
} else {
$output .= _gettext('That name is for internal use. Please pick another.');
}
} else {
$output .= _gettext('Please fill in all required fields.');
}
return $output;
}
function delboard($dir, $confirm = '') {
global $tc_db;
$this->AdministratorsOnly();
$output = '';
$output .= ''. _gettext('Delete Results') .' ';
if (!empty($dir)) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($dir) . "");
foreach ($results as $line) {
$board_id = $line['id'];
$board_dir = $line['name'];
}
if (count($results) > 0) {
if (!empty($confirm)) {
if (removeBoard($board_dir)) {
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = '" . $board_id . "'");
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "boards` WHERE `id` = '" . $board_id . "'");
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "board_filetypes` WHERE `boardid` = '" . $board_id . "'");
require_once KU_ROOTDIR . 'inc/classes/menu.class.php';
$menu_class = new Menu();
$menu_class->Generate();
$output .= _gettext('Board successfully deleted.');
management_addlogentry(_gettext('Deleted board') .': /'. $dir . '/', 3);
} else {
// Error
$output .= _gettext('Unable to delete board.');
}
} else {
$output .= sprintf(_gettext('Are you absolutely sure you want to delete %s?'),'/'. $board_dir . '/') .
'
';
}
} else {
$output .= _gettext('A board with that name does not exist.');
}
}
$output .= ' ';
return $output;
}
/* Replace words in posts with something else */
function wordfilter() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Wordfilter') . ' ';
if (isset($_POST['word'])) {
$this->CheckToken($_POST['token']);
if ($_POST['word'] != '' && $_POST['replacedby'] != '') {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "wordfilter` WHERE `word` = " . $tc_db->qstr($_POST['word']) . "");
if (count($results) == 0) {
$wordfilter_boards = array();
foreach ($results as $line) {
$wordfilter_word = $line['word'];
}
$wordfilter_boards = array();
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards`");
foreach ($_POST['wordfilter'] as $board) {
$check = $tc_db->GetOne("SELECT `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($board));
if (!empty($check)) {
$wordfilter_boards[] = $board;
}
}
$is_regex = (isset($_POST['regex'])) ? '1' : '0';
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "wordfilter` ( `word` , `replacedby` , `boards` , `time` , `regex` ) VALUES ( " . $tc_db->qstr($_POST['word']) . " , " . $tc_db->qstr($_POST['replacedby']) . " , " . $tc_db->qstr(implode('|', $wordfilter_boards)) . " , '" . time() . "' , '" . $is_regex . "' )");
$tpl_page .= _gettext('Word successfully added.');
management_addlogentry(sprintf(_gettext("Added word to wordfilter: %s - Changes to: %s - Boards: /%s/"),$_POST['word'], $_POST['replacedby'], implode('/, /', $wordfilter_boards)), 11);
} else {
$tpl_page .= _gettext('That word already exists.');
}
} else {
$tpl_page .= _gettext('Please fill in all required fields.');
}
$tpl_page .= ' ';
} elseif (isset($_GET['delword'])) {
if ($_GET['delword'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "wordfilter` WHERE `id` = " . $tc_db->qstr($_GET['delword']) . "");
if (count($results) > 0) {
foreach ($results as $line) {
$del_word = $line['word'];
}
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "wordfilter` WHERE `id` = " . $tc_db->qstr($_GET['delword']) . "");
$tpl_page .= _gettext('Word successfully removed.');
management_addlogentry(_gettext('Removed word from wordfilter') . ': '. $del_word, 11);
} else {
$tpl_page .= _gettext('That ID does not exist.');
}
$tpl_page .= ' ';
}
} elseif (isset($_GET['editword'])) {
if ($_GET['editword'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "wordfilter` WHERE `id` = " . $tc_db->qstr($_GET['editword']) . "");
if (count($results) > 0) {
if (!isset($_POST['replacedby'])) {
foreach ($results as $line) {
$tpl_page .= '
'. _gettext('Word') .':
'. _gettext('Is replaced by') .':
'. _gettext('Regular expression') .':
';
$array_boards = array();
$resultsboard = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards`");
foreach ($resultsboard as $lineboard) {
$array_boards = array_merge($array_boards, array($lineboard['name']));
}
foreach ($array_boards as $this_board_name) {
$tpl_page .= ''. $this_board_name . '
';
}
} else {
$this->CheckToken($_POST['token']);
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "wordfilter` WHERE `id` = " . $tc_db->qstr($_GET['editword']) . "");
if (count($results) > 0) {
foreach ($results as $line) {
$wordfilter_word = $line['word'];
}
$wordfilter_boards = array();
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards`");
if (isset($_POST['wordfilter'])){
foreach ($_POST['wordfilter'] as $board) {
$check = $tc_db->GetOne("SELECT `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($board));
if (!empty($check)) {
$wordfilter_boards[] = $board;
}
}
}
$is_regex = (isset($_POST['regex'])) ? '1' : '0';
$tc_db->Execute("UPDATE `". KU_DBPREFIX ."wordfilter` SET `replacedby` = " . $tc_db->qstr($_POST['replacedby']) . " , `boards` = " . $tc_db->qstr(implode('|', $wordfilter_boards)) . " , `regex` = '" . $is_regex . "' WHERE `id` = " . $tc_db->qstr($_GET['editword']) . "");
$tpl_page .= _gettext('Word successfully updated.');
management_addlogentry(_gettext('Updated word on wordfilter') . ': '. $wordfilter_word, 11);
} else {
$tpl_page .= _gettext('Unable to locate that word.');
}
}
} else {
$tpl_page .= _gettext('That ID does not exist.');
}
$tpl_page .= ' ';
}
} else {
$tpl_page .= '
'. _gettext('Word') .':
'. _gettext('Is replaced by') .':
'. _gettext('Regular expression') .':
'. _gettext('Boards') .': ';
$array_boards = array();
$resultsboard = $tc_db->GetAll("SELECT HIGH_PRIORITY name FROM `" . KU_DBPREFIX . "boards`");
$array_boards = array_merge($array_boards, $resultsboard);
$tpl_page .= $this->MakeBoardListCheckboxes('wordfilter', $array_boards) .
'
';
}
$tpl_page .= ' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "wordfilter`");
if ($results > 0) {
$tpl_page .= ''. _gettext('Word') . ' '. _gettext('Replacement') . ' '. _gettext('Boards') . ' '. "\n";
foreach ($results as $line) {
$tpl_page .= ''. $line['word'] . ' '. $line['replacedby'] . ' ';
if (explode('|', $line['boards']) != '') {
$tpl_page .= '/'. implode('/ , /', explode('|', $line['boards'])) . '/ ';
} else {
$tpl_page .= _gettext('No boards');
}
$tpl_page .= ' ['. _gettext('Edit') . ' ] ['. _gettext('Delete') .' ] '. "\n";
}
$tpl_page .= '
';
}
}
/* Ad Management */
function ads() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Ad Management') .' '. _gettext('Anything can go here, such as banners, links, etc. It doesn\'t have to be just ads.') .' '. "\n";
if (isset($_GET['edit']) && ($_GET['edit'] == 1 || $_GET['edit'] == 2)) {
if (isset($_POST['code']) and !empty($_POST['code'])) {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "ads` SET `disp` = " . $tc_db->qstr($_POST['disp']) . ", `code` = " . $tc_db->qstr($_POST['code']) . " WHERE `id` = " . $tc_db->qstr($_GET['edit']) . "");
$tpl_page .= ''. _gettext('Ad Edited.') .' '.sprintf(_gettext('Click %shere%s to return to Ad Management.'),'',' ') .'
'. "\n";
management_addlogentry(_gettext('Edited an ad'));
}
$results = $tc_db->GetAll("SELECT * FROM `" . KU_DBPREFIX . "ads` WHERE `id` = '" . $_GET['edit'] . "'");
foreach ($results as $ad) {
$tpl_page .= ''. "\n" .
' ' . "\n" .
''. _gettext('Position') .': '. "\n" .
' '. "\n" .
''. _gettext('Code') .': '. "\n" .
'' . htmlspecialchars($ad['code']) . ' ' . "\n" .
''. _gettext('Display') .': '. "\n" .
''. _gettext('Put 0 for no display, 1 to display.') .'
'. "\n" .
' '. "\n";
}
} else {
$results = $tc_db->GetAll("SELECT * FROM `" . KU_DBPREFIX . "ads`");
if (count($results) > 0) {
$tpl_page .= ''. "\n";
$tpl_page .= ''. _gettext('Position') .' '. _gettext('Display') .' '. _gettext('Code') .' '. "\n";
foreach ($results as $line) {
$find = array('<', '>');
$replace = array ('<', '>');
if ($line['disp'] == 0) {
$disp = 'Not Displayed';
} elseif ($line['disp'] == 1) {
$disp = _gettext('Displayed');
}
$tpl_page .= ''. $line['position'] . ' '. $disp . ' '. str_replace($find, $replace, $line['code']) . ' '. _gettext('Edit') .' '. "\n";
}
$tpl_page .= '
'. "\n";
} else {
$tpl_page .= _gettext('There was an error during install, and the ads table didn\'t get populated.');
}
}
}
/* Add or delete Embed Entries */
function embeds() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$disptable = true; $formval = 'add'; $title = _gettext('Embed Management');
if(isset($_GET['act'])) {
if ($_GET['act'] == 'edit') {
if (isset($_POST['embeds'])) {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "embeds` SET `filetype` = " . $tc_db->qstr(trim($_POST['filetype'])) . ", `videourl` = " . $tc_db->qstr(trim($_POST['videourl'])) . ", `name` = " . $tc_db->qstr(trim($_POST['name'])) . ", `width` = " . $tc_db->qstr(trim($_POST['width'])) . ", `height` = " . $tc_db->qstr(trim($_POST['height'])) . ", `code` = " . $tc_db->qstr(trim($_POST['embeds'])) . " WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('Embed Edited') .' ';
management_addlogentry(_gettext('Edited an embed'), 9);
}
$formval = 'edit&id='. $_GET['id']; $title .= ' - Edit';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "embeds` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$values = $results[0];
$disptable = false;
} elseif ($_GET['act'] == 'del') {
$results = $tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "embeds` WHERE `id` = " . $tc_db->qstr($_GET['id']) . "");
$tpl_page .= ''. _gettext('Embed deleted') .' ';
management_addlogentry(_gettext('Deleted an Embed'), 9);
} elseif ($_GET['act'] == 'add') {
if (isset($_POST['embeds']) && isset($_POST['name']) && isset($_POST['filetype']) && isset($_POST['videourl'])) {
if ($_POST['embeds'] != '') {
$this->CheckToken($_POST['token']);
$width = ($_POST['width'] != '') ? $_POST['width'] : KU_YOUTUBEWIDTH;
$height = ($_POST['height'] != '') ? $_POST['height'] : KU_YOUTUBEHEIGHT;
$tpl_page .= ' ';
if ($_POST['embeds'] != '') {
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "embeds` ( `name` , `filetype` , `videourl` , `width` , `height` , `code` ) VALUES ( " . $tc_db->qstr(trim($_POST['name'])) . " , " . $tc_db->qstr(trim($_POST['filetype'])) . " , " . $tc_db->qstr(trim($_POST['videourl'])) . " , " . $tc_db->qstr(trim($width)) . " , " . $tc_db->qstr(trim($height)) . " , " . $tc_db->qstr(trim($_POST['embeds'])) . " )");
$tpl_page .= ''. _gettext('Embed successfully added.') . ' ';
management_addlogentry(_gettext('Added an Embed'), 9);
} else {
$tpl_page .= _gettext('You must enter code.');
}
$tpl_page .= ' ';
}
}
}
}
$tpl_page .= ''. $title . '
'. _gettext('Site Name') . ':
'. _gettext('Can not be left blank.') . '
'. _gettext('Filetype') . ':
'. _gettext('Can not be left blank, or longer than 3 characters') . '
'. _gettext('Video URL Start') . ':
'. _gettext('Can not be left blank. This is what comes before the embed ID. Example: \'http://www.youtube.com/watch?v=\'') . '
'. _gettext('Code') . ':
' . (isset($values['code']) ? htmlspecialchars($values['code']) : '') . '
'. _gettext('Width') . ':
'. _gettext('This can be left blank. It will be reset with the default width set in config.php') . '
'. _gettext('Height') . ':
'. _gettext('This can be left blank. It will be reset with the default height set in config.php') . '
'. _gettext('When adding an embed, please check
http://www.kusabax.org/wiki/embedding and check if there is a tutorial image for the site you are adding. Put this image in the /inc/embedhelp/ folder, or create your own in this folder if one does not exist. The image must be the same as the site name in all lowercase.') . '
';
if ($disptable) {
$tpl_page .= ''. _gettext('Edit/Delete Embeds') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "embeds` ORDER BY `id` ASC");
if (count($results) > 0) {
$find = array('<', '>');
$replace = array ('<', '>');
$tpl_page .= ''. _gettext('Site Name') .' '. _gettext('Filetype') .' '. _gettext('Video URL Start') .' '. _gettext('Width') .' '. _gettext('Height') .' '. _gettext('Code') .' ';
foreach ($results as $line) {
$tpl_page .= ''. $line['name'] . ' '. $line['filetype'] . ' '. $line['videourl'] . ' '. $line['width'] . ' '. $line['height'] . ' '. str_replace($find, $replace, $line['code']) . ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('No Embeds yet.');
}
}
}
function movethread() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Move thread') . ' ';
if (isset($_POST['id']) && isset($_POST['board_from']) && isset($_POST['board_to'])) {
$this->CheckToken($_POST['token']);
// Get the IDs for the from and to boards
$board_from_id = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_POST['board_from']) . "");
$board_to_id = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_POST['board_to']) . "");
$board_from = $_POST['board_from'];
$board_to = $_POST['board_to'];
$id = $tc_db->qstr($_POST['id']);
if (isset($_POST['mf'])) {
$image = $tc_db->GetOne("SELECT `file` FROM " .KU_DBPREFIX. "posts WHERE `boardid` = " .$board_from_id. " AND `id` = " .$id);
$filetype = $tc_db->GetOne("SELECT `file_type` FROM " .KU_DBPREFIX. "posts WHERE `boardid` = " .$board_from_id. " AND `id` = " .$id);
$from_pic = KU_BOARDSDIR . $board_from . '/src/'. $image . '.'. $filetype;
$from_thumb = KU_BOARDSDIR . $board_from . '/thumb/'. $image . 's'. '.'. $filetype;
$from_cat = KU_BOARDSDIR . $board_from . '/thumb/'. $image . 'c'. '.'. $filetype;
$to_pic = KU_BOARDSDIR . $board_to . '/src/'. $image . '.'. $filetype;
$to_thumb = KU_BOARDSDIR . $board_to . '/thumb/'. $image . 's'. '.'. $filetype;
$to_cat = KU_BOARDSDIR . $board_to . '/thumb/'. $image . 'c'. '.'. $filetype;
@rename($from_pic, $to_pic);
@rename($from_thumb, $to_thumb);
@rename($from_cat, $to_cat);
@unlink($from_pic);
@unlink($from_thumb);
@unlink($from_cat);
}
$from_html = KU_BOARDSDIR . $board_from . '/res/'. $_POST['id'] . '.html';
$from_html_50 = KU_BOARDSDIR . $board_from . '/res/'. $_POST['id'] . '+50.html';
$from_html_100 = KU_BOARDSDIR . $board_from . '/res/'. $_POST['id'] . '-100.html';
@unlink($from_html);
@unlink($from_html_50);
@unlink($from_html_100);
$tc_db->Execute("START TRANSACTION");
$new_id = $tc_db->GetOne("SELECT COALESCE(MAX(id),0) + 1 FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_to_id);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "posts` SET `id` = " . $new_id . ", `boardid` = " .$board_to_id. " WHERE `boardid` = " .$board_from_id. " AND `id` = " . $id);
processPost($new_id, $new_id, $id, $board_from, $board_to, $board_to_id);
$results = $tc_db->GetAll("SELECT `id` FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " .$board_from_id. " AND `parentid` = " . $id . " ORDER BY `id` ASC");
foreach ($results as $line) {
if (isset($_POST['mf'])) {
$image = $tc_db->GetOne("SELECT `file` FROM `" .KU_DBPREFIX. "posts` WHERE `boardid` = " .$board_from_id. " AND `id` = " .$line['id']);
$filetype = $tc_db->GetOne("SELECT `file_type` FROM `" .KU_DBPREFIX. "posts` WHERE `boardid` = " .$board_from_id. " AND `id` = " .$line['id']);
$from_pic = KU_BOARDSDIR . $board_from . '/src/'. $image . '.'. $filetype;
$from_thumb = KU_BOARDSDIR . $board_from . '/thumb/'. $image . 's'. '.'. $filetype;
$from_cat = KU_BOARDSDIR . $board_from . '/thumb/'. $image . 'c'. '.'. $filetype;
$to_pic = KU_BOARDSDIR . $board_to . '/src/'. $image . '.'. $filetype;
$to_thumb = KU_BOARDSDIR . $board_to . '/thumb/'. $image . 's'. '.'. $filetype;
$to_cat = KU_BOARDSDIR . $board_to . '/thumb/'. $image . 'c'. '.'. $filetype;
@rename($from_pic, $to_pic);
@rename($from_thumb, $to_thumb);
@rename($from_cat, $to_cat);
@unlink($from_pic);
@unlink($from_thumb);
@unlink($from_cat);
}
$insert_id = $tc_db->GetOne("SELECT COALESCE(MAX(id),0) + 1 FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_to_id);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "posts` SET `id` = " . $insert_id . ", `boardid` = " .$board_to_id. " WHERE `boardid` = " .$board_from_id. " AND `id` = " . $line['id']);
processPost($insert_id, $new_id, $id, $board_from, $board_to, $board_to_id);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "posts` SET `parentid` = " . $new_id . " WHERE `boardid` = " . $board_to_id . " AND `id` = " . $insert_id);
}
$tc_db->Execute("COMMIT");
$board_class = new Board($board_from);
$board_class->RegenerateThreads();
$board_class->RegeneratePages();
unset($board_class);
$board_class = new Board($board_to);
$board_class->RegenerateThreads();
$board_class->RegeneratePages();
unset($board_class);
$tpl_page .= _gettext('Move complete.') . ' ';
}
$tpl_page .= '
'. _gettext('ID') . ':
'. _gettext('From') . ': ' .
$this->MakeBoardListDropdown('board_from', $this->BoardList($_SESSION['manageusername'])) .
'
' ._gettext('To') . ': ' .
$this->MakeBoardListDropdown('board_to', $this->BoardList($_SESSION['manageusername'])) .
'
'. _gettext('Move Files') .':
';
}
/* Search for posts by IP */
function ipsearch() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('IP Address Search') .' '. "\n";
if (isset($_GET['ip']) && !empty($_GET['board'])) {
if ($_GET['board'] == 'all') {
$queryextra = "";
} else {
$queryextra = "`boardid` IN (" . $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['board']) . "") . ") AND";
}
$results = $tc_db->GetAll("SELECT `" . KU_DBPREFIX . "posts`.`id` AS id, `" . KU_DBPREFIX . "posts`.`parentid` AS parentid, `" . KU_DBPREFIX . "posts`.`ip` AS ip, `" . KU_DBPREFIX . "posts`.`message` AS message, `" . KU_DBPREFIX . "posts`.`file` AS file, `" . KU_DBPREFIX . "posts`.`file_type` AS file_type, `" . KU_DBPREFIX . "boards`.`name` AS boardname FROM `" . KU_DBPREFIX . "posts`, `" . KU_DBPREFIX . "boards` WHERE ".$queryextra." `ipmd5` = '" . md5($_GET['ip']) . "' AND `IS_DELETED` = 0 AND `" . KU_DBPREFIX . "boards`.`id` = `" . KU_DBPREFIX . "posts`.`boardid` ORDER BY `boardid`");
if (count($results) > 0) {
foreach ($results as $line) {
$tpl_page .= ''. "\n" .
''. _gettext('Post Number') .' '. _gettext('File') .' '. _gettext('Message') .' '. _gettext('IP Address') .' '. "\n";
$real_parentid = ($line['parentid'] == 0) ? $line['id'] : $line['parentid'];
$tpl_page .= '/'. $line['boardname'] . '/'. $line['id'] . ' '. (($line['file_type'] == 'jpg' || $line['file_type'] == 'gif' || $line['file_type'] == 'png') ? (' ') : ('')) . ' '. $line['message'] . ' '. md5_decrypt($line['ip'], KU_RANDOMSEED) . ' ';
}
$tpl_page .= '
'. "\n";
} else {
$tpl_page .= _gettext('No results found for') .' '. $_GET['ip'] . ' '. "\n";
}
} else {
$tpl_page .= ' '. "\n" .
' '. "\n" .
''. _gettext('Board') . ': '. "\n" .
$this->MakeBoardListDropdown('board', $this->BoardList($_SESSION['manageusername']), true) . ' '. "\n" .
''. _gettext('IP') . ': '. "\n" .
' '. "\n" .
' '. "\n";
}
}
/* Search for text in posts */
function search() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
if (isset($_GET['query'])) {
$search_query = $_GET['query'];
if (isset($_GET['s'])) {
$s = $_GET['s'];
} else {
$s = 0;
}
$search_query_array = explode('KUSABA_AND', $search_query);
$trimmed = trim($search_query);
$limit = 10;
if ($trimmed == '') {
$tpl_page .= _gettext('Please enter a search query.');
exit;
}
$boardlist = $this->BoardList($_SESSION['manageusername']);
$likequery = '';
foreach ($search_query_array as $search_split) {
$likequery .= "`message` LIKE " . $tc_db->qstr(str_replace('_', '\_', $search_split)) . " AND ";
}
$likequery = substr($likequery, 0, -4);
$query = '';
$query .= "SELECT `" . KU_DBPREFIX . "posts`.`id` AS id, `" . KU_DBPREFIX . "posts`.`parentid` AS parentid, `" . KU_DBPREFIX . "posts`.`message` AS message, `" . KU_DBPREFIX . "boards`.`name` AS boardname FROM `" . KU_DBPREFIX . "posts`, `" . KU_DBPREFIX . "boards` WHERE `IS_DELETED` = 0 AND " . $likequery . " AND `" . KU_DBPREFIX . "boards`.`id` = `" . KU_DBPREFIX . "posts`.`boardid` ORDER BY `timestamp` DESC";
$numresults = $tc_db->GetAll($query);
$numrows = count($numresults);
if ($numrows == 0) {
$tpl_page .= ''. _gettext('Results') . ' ';
$tpl_page .= ''. _gettext('Sorry, your search returned zero results.') . '
';
} else {
$query .= " LIMIT $limit OFFSET $s";
$results = $tc_db->GetAll($query);
$tpl_page .= ''. _gettext('Results for') .': '. $search_query . '
';
$count = 1 + $s;
foreach ($results as $line) {
$tpl_page .= ''. $count . '. '. _gettext('Board') .': /'. $line['boardname'] . '/, ';
} else {
$tpl_page .= $line['parentid'] . '.html#'. $line['id'] . '">';
}
if ($line['parentid'] == 0) {
$tpl_page .= _gettext('Thread') .' #'. $line['id'];
} else {
$tpl_page .= _gettext('Thread') .' #'. $line['parentid'] . ', Post #'. $line['id'];
}
$tpl_page .= ' ';
$regexp = '/(';
foreach ($search_query_array as $search_word) {
$regexp .= preg_quote($search_word) . '|';
}
$regexp = substr($regexp, 0, -1) . ')/';
//$line['message'] = preg_replace_callback($regexp, array(&$this, 'search_callback'), stripslashes($line['message']));
$line['message'] = stripslashes($line['message']);
$tpl_page .= ''. $line['message'] . ' ';
$count++;
}
$currPage = (($s / $limit) + 1);
$tpl_page .= ' ';
if ($s >= 1) {
$prevs = ($s - $limit);
$tpl_page .= " << "._gettext('Prev')." 10   ";
}
$pages = intval($numrows / $limit);
if ($numrows % $limit) {
$pages++;
}
if (!((($s + $limit) / $limit) == $pages) && $pages != 1) {
$news = $s + $limit;
$tpl_page .= " "._gettext('Next')." 10 >> ";
}
$a = $s + ($limit);
if ($a > $numrows) {
$a = $numrows;
}
$b = $s + 1;
$tpl_page .= $this->search_results_display($a, $b, $numrows);
}
}
$tpl_page .= '
'. _gettext('Query') .' :
'. _gettext('Search Help') .'
'. _gettext('Separate search terms with the word KUSABA_AND ') .'
'. _gettext('To find a single phrase anywhere in a post\'s message, use:') .'
%'. _gettext('some phrase here') .'%
'. _gettext('To find a phrase at the beginning of a post\'s message:') .'
'. _gettext('some phrase here') .'%
'. _gettext('To find a phrase at the end of a post\'s message:') .'
%'. _gettext('some phrase here') .'
'. _gettext('To find two phrases anywhere in a post\'s message, use:') .'
%'. _gettext('first phrase here') .'%KUSABA_AND%'. _gettext('second phrase here') .'%
';
}
function search_callback($matches) {
print_r($matches);
return ''. $matches[0] . ' ';
}
function search_results_display($a, $b, $numrows) {
return ''. _gettext('Results') . ' '. $b . ' to '. $a . ' of '. $numrows . '
'. "\n" .
' ';
}
// Credits to Eman for this code
function viewthread() {
global $tc_db, $tpl_page;
$tpl_page .= ''. _gettext('View Threads (including deleted)') .' ';
$board = isset($_GET['board']) ? $_GET['board'] : '';
$thread = isset($_GET['thread']) ? $_GET['thread'] : '';
if (!$thread ) {
$thread = "0";
}
if (!$board) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `name`, `id` FROM `". KU_DBPREFIX . "boards` ORDER BY `name` ASC");
$tpl_page .= "
";
$tpl_page .= ' '. _gettext('Select Board') .': ';
foreach ($results as $line) {
$name = $line['name'];
$id = $line['id'];
$tpl_page .= "/$name/ ";
}
$tpl_page .= ' ';
} else {
$board_id = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `". KU_DBPREFIX . "boards` WHERE `name` = ".$tc_db->qstr($board));
$tpl_page .= "
";
if ($thread == "0" ) {
$tpl_page .= "". sprintf(_gettext('All threads on /%s/'), $board) ." ";
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = $board_id AND (`id` = ".$tc_db->qstr($thread)." OR `parentid` = ".$tc_db->qstr($thread).") ORDER BY `id` DESC LIMIT 500");
} else {
$tpl_page .= "". sprintf(_gettext('Thread %s on /%s/'), $thread, $board) ." ";
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = $board_id AND (`id` = ".$tc_db->qstr($thread)." OR `parentid` = ".$tc_db->qstr($thread).") ORDER BY `id` ASC");
}
$time = round(microtime(), 5);
$first = "1";
foreach ($results as $line) {
$bans = "";
$id = $line['id'];
$ip = md5_decrypt($line['ip'], KU_RANDOMSEED);
$filename = $line['file'];
$file_original = $line['file_original'];
$filetype = $line['file_type'];
$filesize_formatted = $line['file_size_formatted'];
$image_w = $line['image_w'];
$image_h = $line['image_h'];
$message = $line['message'];
$name = $line['name'];
$tripcode = $line['tripcode'];
$timestamp = date(r, $line['timestamp']);
$subject = $line['subject'];
$posterauthority = $line['posterauthority'];
$deleted = isset($line['IS_DELETED']) ? $line['IS_DELETED'] : $line['is_deleted'] ;
if ($thread == "0") {
$view = "[". _gettext('View') ."] ";
} else {
$view = "";
}
if ($name == "") {
$name = _gettext('Anonymous');
} else {
$name = "$name ";
}
if ($tripcode != "") {
$tripcode = "!$tripcode ";
}
if ($subject != "") {
$subject = "$subject - ";
}
if ($posterauthority == "1") {
$posterauthority = "##Admin## ";
} elseif ($posterauthority == "2") {
$posterauthority = "##Mod## ";
} else {
$posterauthority = "";
}
if ($deleted == "1") {
$deleted = "". _gettext('DELETED') ." - ";
} else {
$deleted = "";
if ($first == "1") {
$bans = "[D & B ]";
} else {
$bans = " [D & B ]";
}
}
if ($bans == "") {
$bans = " ";
}
$tpl_page .= "
$deleted$subject$name$tripcode $posterauthority $timestamp ". _gettext('No.') ." $id ". _gettext('IP') .": $ip $view $bans
";
if ($filename != "") {
$tpl_page .= "
". _gettext('File') .": $filename.$filetype -( $filesize_formatted, {$image_w}x{$image_h}, $file_original.$filetype )
";
}
$tpl_page .= "
";
if ($filename != "") {
$tpl_page .= "
";
}
if ($message == "") {
$message = " ";
}
$tpl_page .= "$message
";
$first = "0";
}
$time2 = round(microtime(), 5);
$generation = $time2 - $time;
$generation = abs($generation);
$tpl_page .= '
'. _gettext('Render Time') .':'. $generation .' '._gettext('Seconds').'
';
}
}
/* View a thread marked as deleted */
function viewdeletedthread() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('View deleted thread') . ' '. "\n";
if (isset($_GET['board']) && isset($_GET['threadid']) && $_GET['threadid'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['board']) . "");
foreach ($results as $line) {
$board_id = $line['id'];
$board_dir = $line['name'];
}
if (count($results) > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts_" . $board_dir . "` WHERE `id` = " . $tc_db->qstr($_GET['threadid']) . "");
foreach ($results as $line) {
$thread_isdeleted = $line['IS_DELETED'];
$thread_parentid = $line['parentid'];
}
if ($thread_isdeleted == 1 && $thread_parentid == 0) {
foreach ($results as $line) {
if ($line['name'] != '') {
$name = $line['name'];
} else {
$name = _gettext('Anonymous') .' ';
}
$tpl_page .= ''. "\n";
$tpl_page .= $name . $line['tripcode'] . formatDate($line['postedat']) . ' | '. _gettext('No.') .' '. $line['id'] . ' | '. _gettext('IP') .': '. md5_decrypt($line['ip'], KU_RANDOMSEED) . '
'. "\n";
if (isset($line['filename'])) {
$tpl_page .= '
'. $line['filename'] . '.'. $line['filetype'] . ' '. "\n" .
'
'. "\n";
}
$tpl_page .= $line['message'];
$tpl_page .= '
';
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts_" . $board_dir . "` WHERE `parentid` = " . $tc_db->qstr($_GET['threadid']) . "");
foreach ($results as $line) {
if ($line['name'] != '') {
$name = $line['name'] . ' ';
} else {
$name = _gettext('Anonymous') .' ';
}
$tpl_page .= ''. "\n";
$tpl_page .= $name . $line['tripcode'] . formatDate($line['postedat']) . ' | No. '. $line['id'] . ' | IP: '. md5_decrypt($line['ip'], KU_RANDOMSEED) . '
'. "\n";
if ($line['filename'] != '') {
$tpl_page .= '
'. $line['filename'] . '.'. $line['filetype'] . ' '. "\n" .
'
'. "\n";
}
$tpl_page .= $line['message'];
$tpl_page .= '
';
}
} else {
$tpl_page .= _gettext('That\'s either not a thread, or it\'s not deleted.') ;
}
}
} else {
$tpl_page .= ''. "\n" .
' '. "\n" .
''. _gettext('Board') . ': '. "\n" .
$this->MakeBoardListDropdown('board', $this->BoardList($_SESSION['manageusername'])) . "\n" .
' '. "\n" .
''. _gettext('Thread') . ': '. "\n" .
' '. "\n" .
' '. "\n" .
' ';
}
}
/* Add, view, and delete filetypes */
function editfiletypes() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Edit filetypes') . ' ';
if (isset($_GET['do'])) {
if ($_GET['do'] == 'addfiletype') {
if (isset($_POST['filetype']) || isset($_POST['image'])) {
$this->CheckToken($_POST['token']);
if ($_POST['filetype'] != '' && $_POST['image'] != '') {
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "filetypes` ( `filetype` , `mime` , `image` , `image_w` , `image_h` ) VALUES ( " . $tc_db->qstr($_POST['filetype']) . " , " . $tc_db->qstr($_POST['mime']) . " , " . $tc_db->qstr($_POST['image']) . " , " . $tc_db->qstr($_POST['image_w']) . " , " . $tc_db->qstr($_POST['image_h']) . " )");
$tpl_page .= _gettext('Filetype added.');
}
} else {
$tpl_page .= '
'. _gettext('Filetype') .':
'. _gettext('The extension this will be applied to. Must be lowercase ') .'
'. _gettext('MIME type') .':
'. _gettext('The MIME type which must be present with an image uploaded in this type. Leave blank to disable.') .'
Image:
'. _gettext('The image which will be used, found in inc/filetypes.') .'
'. _gettext('Image width') .':
'. _gettext('The width of the image. Needs to be set to prevent the page from jumping around while images load.') .'
'. _gettext('Image height') .':
'. _gettext('The height of the image. Needs to be set to prevent the page from jumping around while images load.') .'.
';
}
$tpl_page .= ' ';
}
if ($_GET['do'] == 'editfiletype' && $_GET['filetypeid'] > 0) {
if (isset($_POST['filetype'])) {
if ($_POST['filetype'] != '' && $_POST['image'] != '') {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "filetypes` SET `filetype` = " . $tc_db->qstr($_POST['filetype']) . " , `mime` = " . $tc_db->qstr($_POST['mime']) . " , `image` = " . $tc_db->qstr($_POST['image']) . " , `image_w` = " . $tc_db->qstr($_POST['image_w']) . " , `image_h` = " . $tc_db->qstr($_POST['image_h']) . " WHERE `id` = " . $tc_db->qstr($_GET['filetypeid']) . "");
if (KU_APC) {
apc_delete('filetype|'. $_POST['filetype']);
}
$tpl_page .= _gettext('Filetype updated.');
}
} else {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "filetypes` WHERE `id` = " . $tc_db->qstr($_GET['filetypeid']) . "");
if (count($results) > 0) {
foreach ($results as $line) {
$tpl_page .= '
'. _gettext('Filetype') .':
'. _gettext('The extension this will be applied to. Must be lowercase ') .'
'. _gettext('MIME type') .':
'. _gettext('The MIME type which must be present with an image uploaded in this type. Leave blank to disable.') .'
'. _gettext('Image') .':
'. _gettext('The image which will be used, found in inc/filetypes.') .'
'. _gettext('Image width') .':
'. _gettext('The width of the image. Needs to be set to prevent the page from jumping around while images load.') .'
'. _gettext('Image height') .':
'. _gettext('The height of the image. Needs to be set to prevent the page from jumping around while images load.') .'.
';
}
} else {
$tpl_page .= _gettext('Unable to locate a filetype with that ID.');
}
}
$tpl_page .= ' ';
}
if ($_GET['do'] == 'deletefiletype' && $_GET['filetypeid'] > 0) {
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "filetypes` WHERE `id` = " . $tc_db->qstr($_GET['filetypeid']) . "");
$tpl_page .= _gettext('Filetype deleted.');
$tpl_page .= ' ';
}
}
$tpl_page .= ''. _gettext('Add filetype') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "filetypes` ORDER BY `filetype` ASC");
if (count($results) > 0) {
$tpl_page .= ''. _gettext('ID') .' '. _gettext('Filetype') .' '. _gettext('Image') .' '. _gettext('Edit/Delete') .' ';
foreach ($results as $line) {
$tpl_page .= ''. $line['id'] . ' '. $line['filetype'] . ' '. $line['image'] . ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('There are currently no filetypes.');
}
}
/* Add, view, and delete sections */
function editsections() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Edit sections') . ' ';
if (isset($_GET['do'])) {
if ($_GET['do'] == 'addsection') {
if (isset($_POST['name'])) {
if ($_POST['name'] != '' && $_POST['abbreviation'] != '') {
$this->CheckToken($_POST['token']);
$tc_db->Execute("INSERT HIGH_PRIORITY INTO `" . KU_DBPREFIX . "sections` ( `name` , `abbreviation` , `order` , `hidden` ) VALUES ( " . $tc_db->qstr($_POST['name']) . " , " . $tc_db->qstr($_POST['abbreviation']) . " , " . $tc_db->qstr($_POST['order']) . " , '" . (isset($_POST['hidden']) ? '1' : '0') . "' )");
require_once KU_ROOTDIR . 'inc/classes/menu.class.php';
$menu_class = new Menu();
$menu_class->Generate();
$tpl_page .= _gettext('Section added.');
}
} else {
$tpl_page .= '
'. _gettext('Name') .': '. _gettext('The name of the section') .'
'. _gettext('Abbreviation') .': '. _gettext('Abbreviation (less then 10 characters)') .'
'. _gettext('Order') .': '. _gettext('Order to show this section with others, in ascending order') .'
'. _gettext('Hidden') .': '. _gettext('If checked, this section will be collapsed by default when a user visits the site.') .'
';
}
$tpl_page .= ' ';
}
if ($_GET['do'] == 'editsection' && $_GET['sectionid'] > 0) {
if (isset($_POST['name'])) {
if ($_POST['name'] != '' && $_POST['abbreviation'] != '') {
$this->CheckToken($_POST['token']);
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "sections` SET `name` = " . $tc_db->qstr($_POST['name']) . " , `abbreviation` = " . $tc_db->qstr($_POST['abbreviation']) . " , `order` = " . $tc_db->qstr($_POST['order']) . " , `hidden` = '" . (isset($_POST['hidden']) ? '1' : '0') . "' WHERE `id` = '" . $_GET['sectionid'] . "'");
require_once KU_ROOTDIR . 'inc/classes/menu.class.php';
$menu_class = new Menu();
$menu_class->Generate();
$tpl_page .= _gettext('Section updated.');
}
} else {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "sections` WHERE `id` = " . $tc_db->qstr($_GET['sectionid']) . "");
if (count($results) > 0) {
foreach ($results as $line) {
$tpl_page .= '
'. _gettext('Name') .':
'. _gettext('The name of the section') .'
'. _gettext('Abbreviation') .':
'. _gettext('Abbreviation (less then 10 characters)') .'
'. _gettext('Order') .':
'. _gettext('Order to show this section with others, in ascending order') .'
'. _gettext('Hidden') .':
'. _gettext('If checked, this section will be collapsed by default when a user visits the site.') .'
';
}
} else {
$tpl_page .= _gettext('Unable to locate a section with that ID.');
}
}
$tpl_page .= ' ';
}
if ($_GET['do'] == 'deletesection' && isset($_GET['sectionid'])) {
if ($_GET['sectionid'] > 0) {
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "sections` WHERE `id` = " . $tc_db->qstr($_GET['sectionid']) . "");
require_once KU_ROOTDIR . 'inc/classes/menu.class.php';
$menu_class = new Menu();
$menu_class->Generate();
$tpl_page .= _gettext('Section deleted.') . ' ';
}
}
}
$tpl_page .= ''. _gettext('Add section') .' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "sections` ORDER BY `order` ASC");
if (count($results) > 0) {
$tpl_page .= ''.('ID') .' '.('Order') .' '. _gettext('Abbreviation') .' '. _gettext('Name') .' '. _gettext('Edit/Delete') .' ';
foreach ($results as $line) {
$tpl_page .= ''. $line['id'] . ' '. $line['order'] . ' '. $line['abbreviation'] . ' '. $line['name'] . ' ['. _gettext('Edit') .' ] ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
} else {
$tpl_page .= _gettext('There are currently no sections.');
}
}
/* Rebuild all boards */
function rebuildall() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Rebuild all HTML files') . ' ';
$time_start = time();
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards`");
foreach ($results as $line) {
$board_class = new Board($line['name']);
$board_class->RegenerateAll();
$tpl_page .= sprintf(_gettext('Regenerated %s'), '/'. $line['name'] . '/') . ' ';
unset($board_class);
flush();
}
require_once KU_ROOTDIR . 'inc/classes/menu.class.php';
$menu_class = new Menu();
$menu_class->Generate();
$tpl_page .= _gettext('Regenerated menu pages') .' ';
$tpl_page .= sprintf(_gettext('Rebuild complete. Took %d seconds.'), time() - $time_start);
management_addlogentry(_gettext('Rebuilt all boards and threads'), 2);
unset($board_class);
}
/*
* +------------------------------------------------------------------------------+
* Boards Pages
* +------------------------------------------------------------------------------+
*/
function boardopts() {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$tpl_page .= ''. _gettext('Board options') . ' ';
if (isset($_GET['updateboard']) && isset($_POST['order']) && isset($_POST['maxpages']) && isset($_POST['maxage']) && isset($_POST['messagelength'])) {
$this->CheckToken($_POST['token']);
if (!$this->CurrentUserIsModeratorOfBoard($_GET['updateboard'], $_SESSION['manageusername'])) {
exitWithErrorPage(_gettext('You are not a moderator of this board.'));
}
$boardid = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['updateboard']) . " LIMIT 1");
if ($boardid != '') {
if ($_POST['order'] >= 0 && $_POST['maxpages'] >= 0 && $_POST['markpage'] >= 0 && $_POST['maxage'] >= 0 && $_POST['messagelength'] >= 0 && ($_POST['defaultstyle'] == '' || in_array($_POST['defaultstyle'], explode(':', KU_STYLES)) || in_array($_POST['defaultstyle'], explode(':', KU_TXTSTYLES)))) {
$filetypes = array();
while (list($postkey, $postvalue) = each($_POST)) {
if (substr($postkey, 0, 9) == 'filetype_') {
$filetypes[] = substr($postkey, 9);
}
}
$updateboard_enablecatalog = isset($_POST['enablecatalog']) ? '1' : '0';
$updateboard_enablenofile = isset($_POST['enablenofile']) ? '1' : '0';
$updateboard_redirecttothread = isset($_POST['redirecttothread']) ? '1' : '0';
$updateboard_enablereporting = isset($_POST['enablereporting']) ? '1' : '0';
$updateboard_enablecaptcha = isset($_POST['enablecaptcha']) ? '1' : '0';
$updateboard_forcedanon = isset($_POST['forcedanon']) ? '1' : '0';
$updateboard_trial = isset($_POST['trial']) ? '1' : '0';
$updateboard_popular = isset($_POST['popular']) ? '1' : '0';
$updateboard_enablearchiving = isset($_POST['enablearchiving']) ? '1' : '0';
$updateboard_showid = isset($_POST['showid']) ? '1' : '0';
$updateboard_compactlist = isset($_POST['compactlist']) ? '1' : '0';
$updateboard_locked = isset($_POST['locked']) ? '1' : '0';
if (($_POST['type'] == '0' || $_POST['type'] == '1' || $_POST['type'] == '2' || $_POST['type'] == '3') && ($_POST['uploadtype'] == '0' || $_POST['uploadtype'] == '1' || $_POST['uploadtype'] == '2')) {
if (!($_POST['uploadtype'] != '0' && $_POST['type'] == '3')) {
if(count($_POST['allowedembeds']) > 0) {
$updateboard_allowedembeds = '';
$results = $tc_db->GetAll("SELECT `filetype` FROM `" . KU_DBPREFIX . "embeds`");
foreach ($results as $line) {
if(in_array($line['filetype'], $_POST['allowedembeds'])) {
$updateboard_allowedembeds .= $line['filetype'].',';
}
}
if ($updateboard_allowedembeds != '') {
$updateboard_allowedembeds = substr($updateboard_allowedembeds, 0, -1);
}
}
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "boards` SET `type` = " . $tc_db->qstr($_POST['type']) . " , `uploadtype` = " . $tc_db->qstr($_POST['uploadtype']) . " , `order` = " . $tc_db->qstr(intval($_POST['order'])) . " , `section` = " . $tc_db->qstr(intval($_POST['section'])) . " , `desc` = " . $tc_db->qstr($_POST['desc']) . " , `locale` = " . $tc_db->qstr($_POST['locale']) . " , `showid` = '" . $updateboard_showid . "' , `compactlist` = '" . $updateboard_compactlist . "' , `locked` = '" . $updateboard_locked . "' , `maximagesize` = " . $tc_db->qstr($_POST['maximagesize']) . " , `messagelength` = " . $tc_db->qstr($_POST['messagelength']) . " , `maxpages` = " . $tc_db->qstr($_POST['maxpages']) . " , `maxage` = " . $tc_db->qstr($_POST['maxage']) . " , `markpage` = " . $tc_db->qstr($_POST['markpage']) . " , `maxreplies` = " . $tc_db->qstr($_POST['maxreplies']) . " , `image` = " . $tc_db->qstr($_POST['image']) . " , `includeheader` = " . $tc_db->qstr($_POST['includeheader']) . " , `redirecttothread` = '" . $updateboard_redirecttothread . "' , `anonymous` = " . $tc_db->qstr($_POST['anonymous']) . " , `forcedanon` = '" . $updateboard_forcedanon . "' , `embeds_allowed` = " . $tc_db->qstr($updateboard_allowedembeds) . " , `trial` = '" . $updateboard_trial . "' , `popular` = '" . $updateboard_popular . "' , `defaultstyle` = " . $tc_db->qstr($_POST['defaultstyle']) . " , `enablereporting` = '" . $updateboard_enablereporting . "', `enablecaptcha` = '" . $updateboard_enablecaptcha . "' , `enablenofile` = '" . $updateboard_enablenofile . "' , `enablearchiving` = '" . $updateboard_enablearchiving . "', `enablecatalog` = '" . $updateboard_enablecatalog . "' , `loadbalanceurl` = " . $tc_db->qstr($_POST['loadbalanceurl']) . " , `loadbalancepassword` = " . $tc_db->qstr($_POST['loadbalancepassword']) . " WHERE `name` = " . $tc_db->qstr($_GET['updateboard']) . "");
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "board_filetypes` WHERE `boardid` = '" . $boardid . "'");
foreach ($filetypes as $filetype) {
$tc_db->Execute("INSERT INTO `" . KU_DBPREFIX . "board_filetypes` ( `boardid`, `typeid` ) VALUES ( '" . $boardid . "', " . $tc_db->qstr($filetype) . " )");
}
require_once KU_ROOTDIR . 'inc/classes/menu.class.php';
$menu_class = new Menu();
$menu_class->Generate();
if (isset($_POST['submit_regenerate'])) {
$board_class = new Board($_GET['updateboard']);
$board_class->RegenerateAll();
}
$tpl_page .= _gettext('Update successful.');
management_addlogentry(_gettext('Updated board configuration') . " - /" . $_GET['updateboard'] . "/", 4);
} else {
$tpl_page .= _gettext('Sorry, embed may only be enabled on normal imageboards.');
}
} else {
$tpl_page .= _gettext('Sorry, a generic error has occurred.');
}
} else {
$tpl_page .= _gettext('Integer values must be entered correctly.');
}
} else {
$tpl_page .= _gettext('Unable to locate a board named') . ' '. $_GET['updateboard'] . ' .';
}
} elseif (isset($_POST['board'])) {
if (!$this->CurrentUserIsModeratorOfBoard($_POST['board'], $_SESSION['manageusername'])) {
exitWithErrorPage(_gettext('You are not a moderator of this board.'));
}
$resultsboard = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_POST['board']) . "");
if (count($resultsboard) > 0) {
foreach ($resultsboard as $lineboard) {
$tpl_page .= '
';
/* Directory */
$tpl_page .= ''. _gettext('Directory') .':
'. _gettext('The directory of the board.') .'
';
/* Description */
$tpl_page .= ''. _gettext('Description') .':
'. _gettext('The name of the board.') .'
';
/* Locale */
$tpl_page .= ''. _gettext('Locale') .':
'. _gettext('Locale to use on this board. Leave blank to use the locale defined in config.php') .'
';
/* Board type */
$tpl_page .= ''. _gettext('Board type') .':
'. _gettext('The type of posts which will be accepted on this board. A normal imageboard will feature image and extended format posts, a text board will have no images, an Oekaki board will allow users to draw images and use them in their posts, and an Upload imageboard will be styled more towards file uploads.') .' '. _gettext('Default') .': Normal Imageboard
';
/* Upload type */
$tpl_page .= ''. _gettext('Upload type') .':
'. _gettext('Whether or not to allow embedding of videos.') .' '. _gettext('Default') .'.: '. _gettext('No Embedding') .'
';
/* Order */
$tpl_page .= ''. _gettext('Order') .':
'. _gettext('Order to show board in menu list, in ascending order.') .' '. _gettext('Default') .': 0
';
/* Section */
$tpl_page .= ''. _gettext('Section') .': ' .
$this->MakeSectionListDropdown('section', $lineboard['section']) .
''. _gettext('The section the board is in. This is used for displaying the list of boards on the top and bottom of pages.') .' '. _gettext('If this is set to Select a Board , it will not be shown in the menu .') .'
';
/* Load balancer URL */
$tpl_page .= ''. _gettext('Load balance URL') .':
'. _gettext('The full http:// URL to the load balance script for this board. The script will handle file uploads, and creation of thumbnails. Only one script per board can be used, and there must be a src and thumb dir in the same folder as the script. Set to nothing to disable.') .'
';
/* Load balancer password */
$tpl_page .= ''. _gettext('Load balance password') .':
'. _gettext('The password which will be passed to the script above. The script must have this same password entered at the top, in the configuration area.') .'
';
/* Allowed filetypes */
$tpl_page .= ''. _gettext('Allowed filetypes') .':
'. _gettext('What filetypes users are allowed to upload.') .'
';
$filetypes = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `filetype` FROM `" . KU_DBPREFIX . "filetypes` ORDER BY `filetype` ASC");
foreach ($filetypes as $filetype) {
$tpl_page .= ''. strtoupper($filetype['filetype']) . ' GetOne("SELECT HIGH_PRIORITY COUNT(*) FROM `" . KU_DBPREFIX . "board_filetypes` WHERE `boardid` = '" . $lineboard['id'] . "' AND `typeid` = '" . $filetype['id'] . "' LIMIT 1");
if ($filetype_isenabled == 1) {
$tpl_page .= ' checked';
}
$tpl_page .= ' /> ';
}
/* Allowed embeds */
$tpl_page .= ''. _gettext('Allowed embeds') .':
'. _gettext('What embed sites are allowed on this board. Only useful on board with embedding enabled.') .'
';
$embeds = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `filetype`, `name` FROM `" . KU_DBPREFIX . "embeds` ORDER BY `filetype` ASC");
foreach ($embeds as $embed) {
$tpl_page .= ''. $embed['name'] . '
'. _gettext('Maxmimum size of uploaded images, in bytes .') . ' '. _gettext('Default') .': 1024000
';
/* Maximum message length */
$tpl_page .= ''. _gettext('Maximum message length') .':
'. _gettext('Default') .': 8192
';
/* Maximum board pages */
$tpl_page .= ''. _gettext('Maximum board pages') .':
'. _gettext('Default') .': 11
';
/* Maximum thread age */
$tpl_page .= ''. _gettext('Maximum thread age (Hours)') .':
'. _gettext('Default') .': 0
';
/* Mark page */
$tpl_page .= ''. _gettext('Mark page') .':
'. _gettext('Threads which reach this page or further will be marked to be deleted in two hours.') .' '. _gettext('Default') .': 9
';
/* Maximum thread replies */
$tpl_page .= ''. _gettext('Maximum thread replies') .':
'. _gettext('The number of replies a thread can have before autosaging to the back of the board.') . ' '. _gettext('Default') .': 200
';
/* Header image */
$tpl_page .= ''. _gettext('Header image') .':
'. _gettext('Overrides the header set in the config file. Leave blank to use configured global header image. Needs to be a full url including http://. Set to none to show no header image.') .'
';
/* Include header */
$tpl_page .= ''. _gettext('Include header') .':
'.htmlspecialchars($lineboard['includeheader']).'
'. _gettext('Raw HTML which will be inserted at the top of each page of the board.') .'
';
/* Anonymous */
$tpl_page .= ''. _gettext('Anonymous') .':
'. _gettext('Name to display when a name is not attached to a post.') . ' '. _gettext('Default') .': '. _gettext('Anonymous') .'
';
/* Locked */
$tpl_page .= ''. _gettext('Locked') .':
';
/* Show ID */
$tpl_page .= ''. _gettext('Show ID') .':
';
/* Show ID */
$tpl_page .= ''. _gettext('Compact list') .':
';
/* Enable reporting */
$tpl_page .= ''. _gettext('Enable reporting') .':
'. _gettext('Reporting allows users to report posts, adding the post to the report list.') .' '. _gettext('Default') .': '. _gettext('Yes') .' ';
/* Enable captcha */
$tpl_page .= ''. _gettext('Enable captcha') .':
'. _gettext('No') .' ';
/* Enable archiving */
$tpl_page .= ''. _gettext('Enable archiving') .':
'. _gettext('No') .' ';
/* Enable catalog */
$tpl_page .= ''. _gettext('Enable catalog') .':
'. _gettext('Yes') .' ';
/* Enable "no file" posting */
$tpl_page .= ''. _gettext('Enable \'no file\' posting') .':
'. _gettext('No') .' ';
/* Redirect to thread */
$tpl_page .= ''. _gettext('Redirect to thread') .':
'.('No') .' ';
/* Forced anonymous */
$tpl_page .= ''. _gettext('Forced anonymous') .':
'. _gettext('No') .' ';
/* Trial */
$tpl_page .= ''. _gettext('Trial') .':
'. _gettext('No') .' ';
/* Popular */
$tpl_page .= ''. _gettext('Popular') .':
'. _gettext('No') .' ';
/* Default style */
$tpl_page .= ''. _gettext('Default style') .':
';
$styles = explode(':', KU_STYLES);
foreach ($styles as $stylesheet) {
$tpl_page .= ' ';
}
$stylestxt = explode(':', KU_TXTSTYLES);
foreach ($stylestxt as $stylesheet) {
$tpl_page .= ' ';
}
$tpl_page .= '
'. _gettext('The style which will be set when the user first visits the board.') .' '. _gettext('Default') .': '. _gettext('Use Default') .'
';
/* Submit form */
$tpl_page .= '
';
}
} else {
$tpl_page .= _gettext('Unable to locate a board named') . ' '. $_POST['board'] . ' .';
}
} else {
$tpl_page .= '
'. _gettext('Board') .': ' .
$this->MakeBoardListDropdown('board', $this->BoardList($_SESSION['manageusername'])) .
'
';
}
}
function unstickypost() {
global $tc_db, $tpl_page, $board_class;
$this->ModeratorsOnly();
$tpl_page .= ''. _gettext('Manage stickies') . ' ';
if (isset($_GET['postid']) && isset($_GET['board'])) {
if ($_GET['postid'] > 0 && $_GET['board'] != '') {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['board']) . "");
if (count($results) > 0) {
if (!$this->CurrentUserIsModeratorOfBoard($_GET['board'], $_SESSION['manageusername'])) {
exitWithErrorPage(_gettext('You are not a moderator of this board.'));
}
foreach ($results as $line) {
$sticky_board_name = $line['name'];
$sticky_board_id = $line['id'];
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $sticky_board_id ." AND `IS_DELETED` = '0' AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
if (count($results) > 0) {
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "posts` SET `stickied` = '0' WHERE `boardid` = " . $sticky_board_id ." AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
$board_class = new Board($sticky_board_name);
$board_class->RegenerateAll();
unset($board_class);
$tpl_page .= _gettext('Thread successfully un-stickied');
management_addlogentry(_gettext('Unstickied thread') . ' #' . intval($_GET['postid']) . ' - /' . $sticky_board_name . '/', 5);
} else {
$tpl_page .= _gettext('Invalid thread ID. This may have been caused by the thread recently being deleted.');
}
} else {
$tpl_page .= _gettext('Invalid board directory.');
}
$tpl_page .= ' ';
}
}
$tpl_page .= $this->stickyforms();
}
function stickypost() {
global $tc_db, $tpl_page, $board_class;
$this->ModeratorsOnly();
$tpl_page .= ''. _gettext('Manage stickies') . ' ';
if (isset($_GET['postid']) && isset($_GET['board'])) {
if ($_GET['postid'] > 0 && $_GET['board'] != '') {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['board']) . "");
if (count($results) > 0) {
if (!$this->CurrentUserIsModeratorOfBoard($_GET['board'], $_SESSION['manageusername'])) {
exitWithErrorPage(_gettext('You are not a moderator of this board.'));
}
foreach ($results as $line) {
$sticky_board_name = $line['name'];
$sticky_board_id = $line['id'];
}
$result = $tc_db->GetOne("SELECT HIGH_PRIORITY COUNT(*) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $sticky_board_id . " AND `IS_DELETED` = '0' AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
if ($result > 0) {
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "posts` SET `stickied` = '1' WHERE `boardid` = " . $sticky_board_id . " AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
$board_class = new Board($sticky_board_name);
$board_class->RegenerateAll();
unset($board_class);
$tpl_page .= _gettext('Thread successfully stickied.');
management_addlogentry(_gettext('Stickied thread') . ' #' . intval($_GET['postid']) . ' - /' . $sticky_board_name . '/', 5);
} else {
$tpl_page .= _gettext('Invalid thread ID. This may have been caused by the thread recently being deleted.');
}
} else {
$tpl_page .= _gettext('Invalid board directory.');
}
$tpl_page .= ' ';
}
}
$tpl_page .= $this->stickyforms();
}
/* Create forms for stickying a post */
function stickyforms() {
global $tc_db;
$output = '';
return $output;
}
function lockpost() {
global $tc_db, $tpl_page, $board_class;
$this->ModeratorsOnly();
$tpl_page .= ''. _gettext('Manage locked threads') . ' ';
if (isset($_GET['postid']) && isset($_GET['board'])) {
if ($_GET['postid'] > 0 && $_GET['board'] != '') {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['board']) . "");
if (count($results) > 0) {
if (!$this->CurrentUserIsModeratorOfBoard($_GET['board'], $_SESSION['manageusername'])) {
exitWithErrorPage(_gettext('You are not a moderator of this board.'));
}
foreach ($results as $line) {
$lock_board_name = $line['name'];
$lock_board_id = $line['id'];
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $lock_board_id . " AND `IS_DELETED` = '0' AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
if (count($results) > 0) {
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "posts` SET `locked` = '1' WHERE `boardid` = " . $lock_board_id . " AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
$board_class = new Board($lock_board_name);
$board_class->RegenerateAll();
unset($board_class);
$tpl_page .= _gettext('Thread successfully locked.');
management_addlogentry(_gettext('Locked thread') . ' #'. intval($_GET['postid']) . ' - /'. intval($_GET['board']) . '/', 5);
} else {
$tpl_page .= _gettext('Invalid thread ID. This may have been caused by the thread recently being deleted.');
}
} else {
$tpl_page .= _gettext('Invalid board directory.');
}
$tpl_page .= ' ';
}
}
$tpl_page .= $this->lockforms();
}
function unlockpost() {
global $tc_db, $tpl_page, $board_class;
$tpl_page .= ''. _gettext('Manage locked threads') . ' ';
if ($_GET['postid'] > 0 && $_GET['board'] != '') {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['board']) . "");
if (count($results) > 0) {
if (!$this->CurrentUserIsModeratorOfBoard($_GET['board'], $_SESSION['manageusername'])) {
exitWithErrorPage(_gettext('You are not a moderator of this board.'));
}
foreach ($results as $line) {
$lock_board_name = $line['name'];
$lock_board_id = $line['id'];
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $lock_board_id . " AND `IS_DELETED` = '0' AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
if (count($results) > 0) {
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "posts` SET `locked` = '0' WHERE `boardid` = " . $lock_board_id . " AND `parentid` = '0' AND `id` = " . $tc_db->qstr($_GET['postid']) . "");
$board_class = new Board($lock_board_name);
$board_class->RegenerateAll();
unset($board_class);
$tpl_page .= _gettext('Thread successfully unlocked.');
management_addlogentry(_gettext('Unlocked thread') . ' #'. intval($_GET['postid']) . ' - /'. intval($_GET['board']) . '/', 5);
} else {
$tpl_page .= _gettext('Invalid thread ID. This may have been caused by the thread recently being deleted.');
}
} else {
$tpl_page .= _gettext('Invalid board directory.');
}
$tpl_page .= ' ';
}
$tpl_page .= $this->lockforms();
}
function lockforms() {
global $tc_db;
$output = '';
return $output;
}
/* Delete a post, or multiple posts */
function delposts($multidel=false) {
global $tc_db, $tpl_page, $board_class;
$isquickdel = false;
if (isset($_POST['boarddir']) || isset($_GET['boarddir'])) {
if (!isset($_GET['boarddir']) && isset($_POST['boarddir'])) {
$this->CheckToken($_POST['token']);
}
if (isset($_GET['boarddir'])) {
$isquickdel = true;
$_POST['boarddir'] = $_GET['boarddir'];
if (isset($_GET['delthreadid'])) {
$_POST['delthreadid'] = $_GET['delthreadid'];
}
if (isset($_GET['delpostid'])) {
$_POST['delpostid'] = $_GET['delpostid'];
}
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_POST['boarddir']) . "");
if (count($results) > 0) {
if (!$this->CurrentUserIsModeratorOfBoard($_POST['boarddir'], $_SESSION['manageusername'])) {
exitWithErrorPage(_gettext('You are not a moderator of this board.'));
}
foreach ($results as $line) {
$board_id = $line['id'];
$board_dir = $line['name'];
}
if (isset($_GET['cp'])) {
$cp = '&cp=y&instant=y';
}
if (isset($_POST['delthreadid'])) {
if ($_POST['delthreadid'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_id . " AND `IS_DELETED` = '0' AND `id` = " . $tc_db->qstr($_POST['delthreadid']) . " AND `parentid` = '0'");
if (count($results) > 0) {
if (isset($_POST['fileonly'])) {
foreach ($results as $line) {
if (!empty($line['file'])) {
$del = unlink(KU_ROOTDIR . $_POST['boarddir'] . '/src/'. $line['file'] . '.'. $line['file_type']);
if ($del) {
@unlink(KU_ROOTDIR . $_POST['boarddir'] . '/thumb/'. $line['file'] . 's.'. $line['file_type']);
@unlink(KU_ROOTDIR . $_POST['boarddir'] . '/thumb/'. $line['file'] . 'c.'. $line['file_type']);
$tc_db->Execute("UPDATE `".KU_DBPREFIX."posts` SET `file` = 'removed', `file_md5` = '' WHERE `boardid` = " . $board_id . " AND `id` = ".$_POST['delthreadid']." LIMIT 1");
$tpl_page .= ' File successfully deleted ';
} else {
$tpl_page .= ' That file has already been deleted. ';
}
} else {
$tpl_page .= ' Error: That thread doesn\'t have a file associated with it. ';
}
}
} else {
foreach ($results as $line) {
$delthread_id = $line['id'];
}
$post_class = new Post($delthread_id, $board_dir, $board_id);
if (isset($_POST['archive'])) {
$numposts_deleted = $post_class->Delete(true);
} else {
$numposts_deleted = $post_class->Delete();
}
$board_class = new Board($board_dir);
$board_class->RegenerateAll();
unset($board_class);
unset($post_class);
$tpl_page .= _gettext('Thread '.$delthread_id.' successfully deleted.');
management_addlogentry(_gettext('Deleted thread') . ' #'. $delthread_id . ' ('. $numposts_deleted . ' replies) - /'. $board_dir . '/', 7);
if (!empty($_GET['postid'])) {
$tpl_page .= ''. _gettext('Redirecting') . ' to ban page...';
} elseif ($isquickdel) {
$tpl_page .= ''. _gettext('Redirecting') . ' back to board...';
}
}
} else {
$tpl_page .= _gettext('Invalid thread ID '.$delpost_id.'. This may have been caused by the thread recently being deleted.');
}
}
} elseif (isset($_POST['delpostid'])) {
if ($_POST['delpostid'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $board_id . " AND `IS_DELETED` = '0' AND `id` = " . $tc_db->qstr($_POST['delpostid']) . "");
if (count($results) > 0) {
if (isset($_POST['fileonly'])) {
foreach ($results as $line) {
if (!empty($line['file'])) {
$del = @unlink(KU_ROOTDIR . $_POST['boarddir'] . '/src/'. $line['file'] . '.'. $line['file_type']);
if ($del) {
@unlink(KU_ROOTDIR . $_POST['boarddir'] . '/thumb/'. $line['file'] . 's.'. $line['file_type']);
@unlink(KU_ROOTDIR . $_POST['boarddir'] . '/thumb/'. $line['file'] . 'c.'. $line['file_type']);
$tc_db->Execute("UPDATE `".KU_DBPREFIX."posts` SET `file` = 'removed', `file_md5` = '' WHERE `boardid` = " . $board_id . " AND `id` = ".$_POST['delpostid']." LIMIT 1");
$tpl_page .= ' File successfully deleted ';
} else {
$tpl_page .= ' That file has already been deleted. ';
}
} else {
$tpl_page .= ' Error: That thread doesn\'t have a file associated with it. ';
}
}
} else {
foreach ($results as $line) {
$delpost_id = $line['id'];
$delpost_parentid = $line['parentid'];
}
$post_class = new Post($delpost_id, $board_dir, $board_id);
$post_class->Delete();
$board_class = new Board($board_dir);
$board_class->RegenerateThreads($delpost_parentid);
$board_class->RegeneratePages();
unset($board_class);
unset($post_class);
$tpl_page .= _gettext('Post '.$delpost_id.' successfully deleted.');
management_addlogentry(_gettext('Deleted post') . ' #'. $delpost_id . ' - /'. $board_dir . '/', 7);
if ($_GET['postid'] != '') {
$tpl_page .= ''. _gettext('Redirecting') . ' to ban page...';
} elseif ($isquickdel) {
$tpl_page .= ''. _gettext('Redirecting') . ' back to thread...';
}
}
} else {
$tpl_page .= _gettext('Invalid thread ID '.$delpost_id.'. This may have been caused by the thread recently being deleted.');
}
}
}
} else {
$tpl_page .= _gettext('Invalid board directory.');
}
}
$tpl_page .= ''. _gettext('Delete thread/post') . ' ';
if (!$multidel) {
$tpl_page .= '
'. _gettext('Board') .': ' .
$this->MakeBoardListDropdown('boarddir', $this->BoardList($_SESSION['manageusername'])) .
'
'. _gettext('Thread') .':
'. _gettext('File Only') .':
'. _gettext('Board') .': ' .
$this->MakeBoardListDropdown('boarddir', $this->BoardList($_SESSION['manageusername'])) .
'
'. _gettext('Post') .':
'. _gettext('Archive') .':
'. _gettext('File Only') .':
';
}
}
/*
* +------------------------------------------------------------------------------+
* Moderation Pages
* +------------------------------------------------------------------------------+
*/
/* View and delete reports */
function reports() {
global $tc_db, $tpl_page;
$this->ModeratorsOnly();
$tpl_page .= ''. _gettext('Reports') . ' ';
if (isset($_GET['clear'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "reports` WHERE `id` = " . $tc_db->qstr($_GET['clear']) . " LIMIT 1");
if (count($results) > 0) {
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "reports` SET `cleared` = '1' WHERE `id` = " . $tc_db->qstr($_GET['clear']));
$tpl_page .= 'Report successfully cleared. ';
}
}
$query = "SELECT * FROM `" . KU_DBPREFIX . "reports` WHERE `cleared` = 0";
if (!$this->CurrentUserIsAdministrator()) {
$boardlist = $this->BoardList($_SESSION['manageusername']);
if (!empty($boardlist)) {
$query .= ' AND (';
foreach ($boardlist as $board) {
$query .= ' `board` = \''. $board['name'] .'\' OR';
}
$query = substr($query, 0, -3) . ')';
} else {
$tpl_page .= _gettext('You do not moderate any boards.');
}
}
$resultsreport = $tc_db->GetAll($query);
if (count($resultsreport) > 0) {
$tpl_page .= 'Board Post File Message Reason Reporter IP Action ';
foreach ($resultsreport as $linereport) {
$reportboardid = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($linereport['board']) . "");
$results = $tc_db->GetAll("SELECT * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $reportboardid . " AND `id` = " . $tc_db->qstr($linereport['postid']) . "");
foreach ($results as $line) {
if ($line['IS_DELETED'] == 0) {
$tpl_page .= '/'. $linereport['board'] . '/ '. $line['id'] . ' ';
if ($line['file'] == 'removed') {
$tpl_page .= 'removed';
} elseif ($line['file'] == '') {
$tpl_page .= 'none';
} elseif ($line['file_type'] == 'jpg' || $line['file_type'] == 'gif' || $line['file_type'] == 'png') {
$tpl_page .= ' ';
} else {
$tpl_page .= 'File ';
}
$tpl_page .= ' ';
if ($line['message'] != '') {
$tpl_page .= stripslashes($line['message']);
} else {
$tpl_page .= ' ';
}
$tpl_page .= ' ';
if ($linereport['reason'] != '') {
$tpl_page .= htmlspecialchars(stripslashes($linereport['reason']));
} else {
$tpl_page .= ' ';
}
$tpl_page .= ' '. md5_decrypt($linereport['ip'], KU_RANDOMSEED) . ' Clear [D & B ] ';
} else {
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "reports` SET `cleared` = 1 WHERE id = " . $linereport['id'] . "");
}
}
}
$tpl_page .= '
';
} else {
$tpl_page .= 'No reports to show.';
}
}
/* Addition, modification, deletion, and viewing of bans */
function bans() {
global $tc_db, $tpl_page, $bans_class;
$this->ModeratorsOnly();
$reason = KU_BANREASON;
$ban_ip = ''; $ban_hash = ''; $ban_parentid = 0; $multiban = Array();
if (isset($_POST['modban']) && is_array($_POST['post']) && $_POST['board']) {
$ban_board_id = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_POST['board']) . "");
if (!empty($ban_board_id)) {
foreach ( $_POST['post'] as $post ) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = '" . $ban_board_id . "' AND `id` = " . intval($post) . "");
if (count($results) > 0) {
$multiban[] = md5_decrypt($results[0]['ip'], KU_RANDOMSEED);
$multiban_hash[] = $results[0]['file_md5'];
$multiban_parentid[] = $results[0]['parentid'];
}
}
}
}
if (isset($_GET['banboard']) && isset($_GET['banpost'])) {
$ban_board_id = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['banboard']) . "");
$ban_board = $_GET['banboard'];
$ban_post_id = $_GET['banpost'];
if (!empty($ban_board_id)) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = '" . $ban_board_id . "' AND `id` = " . $tc_db->qstr($_GET['banpost']) . "");
if (count($results) > 0) {
$ban_ip = md5_decrypt($results[0]['ip'], KU_RANDOMSEED);
$ban_hash = $results[0]['file_md5'];
$ban_parentid = $results[0]['parentid'];
} else {
$tpl_page.= _gettext('A post with that ID does not exist.') . ' ';
}
}
}
$instantban = false;
if ((isset($_GET['instant']) || isset($_GET['cp'])) && $ban_ip) {
if (isset($_GET['cp'])) {
$ban_reason = "You have been banned for posting Child Pornography. Your IP has been logged, and the proper authorities will be notified.";
} else {
if($_GET['reason']) {
$ban_reason = urldecode($_GET['reason']);
} else {
$ban_Reason = KU_BANREASON;
}
}
$instantban = true;
}
$tpl_page .= ''. _gettext('Bans') . ' ';
if (((isset($_POST['ip']) || isset($_POST['multiban'])) && isset($_POST['seconds']) && (!empty($_POST['ip']) || (empty($_POST['ip']) && !empty($_POST['multiban'])))) || $instantban) {
if ($_POST['seconds'] >= 0 || $instantban) {
$banning_boards = array();
$ban_boards = '';
if (isset($_POST['banfromall']) || $instantban) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `name` FROM `" . KU_DBPREFIX . "boards`");
foreach ($results as $line) {
if (!$this->CurrentUserIsModeratorOfBoard($line['name'], $_SESSION['manageusername'])) {
exitWithErrorPage('/'. $line['name'] . '/: '. _gettext('You can only make bans applying to boards you moderate.'));
}
}
} else {
if (empty($_POST['bannedfrom'])) {
exitWithErrorPage(_gettext('Please select a board.'));
}
if(isset($_POST['deleteposts'])) {
$_POST['deletefrom'] = $_POST['bannedfrom'];
}
foreach($_POST['bannedfrom'] as $board) {
if (!$this->CurrentUserIsModeratorOfBoard($board, $_SESSION['manageusername'])) {
exitWithErrorPage('/'. $board . '/: '. _gettext('You can only make bans applying to boards you moderate.'));
}
}
$ban_boards = implode('|', $_POST['bannedfrom']);
}
$ban_globalban = (isset($_POST['banfromall']) || $instantban) ? 1 : 0;
$ban_allowread = ($_POST['allowread'] == 0 || $instantban) ? 0 : 1;
if (isset($_POST['quickbanboardid'])) {
$ban_board_id = $_POST['quickbanboardid'];
}
if(isset($_POST['quickbanboard'])) {
$ban_board = $_POST['quickbanboard'];
}
if(isset($_POST['quickbanpostid'])) {
$ban_post_id = $_POST['quickbanpostid'];
}
$ban_ip = ($instantban) ? $ban_ip : $_POST['ip'];
$ban_duration = ($_POST['seconds'] == 0 || $instantban) ? 0 : $_POST['seconds'];
$ban_type = ($_POST['type'] <= 2 && $_POST['type'] >= 0) ? $_POST['type'] : 0;
$ban_reason = ($instantban) ? $ban_reason : $_POST['reason'];
$ban_note = ($instantban) ? '' : $_POST['staffnote'];
$ban_appealat = 0;
if (KU_APPEAL != '' && !$instantban) {
$ban_appealat = intval($_POST['appealdays'] * 86400);
if ($ban_appealat > 0) $ban_appealat += time();
}
if (isset($_POST['multiban']))
$ban_ips = unserialize($_POST['multiban']);
else
$ban_ips = Array($ban_ip);
$i = 0;
foreach ($ban_ips as $ban_ip) {
$ban_msg = '';
$whitelist = $tc_db->GetAll("SELECT `ipmd5` FROM `" . KU_DBPREFIX . "banlist` WHERE `type` = 2");
if (in_array(md5($ban_ip), $whitelist)) {
exitWithErrorPage(_gettext('That IP is on the whitelist'));
}
if ($bans_class->BanUser($ban_ip, $_SESSION['manageusername'], $ban_globalban, $ban_duration, $ban_boards, $ban_reason, $ban_note, $ban_appealat, $ban_type, $ban_allowread)) {
$regenerated = array();
if (((KU_BANMSG != '' || $_POST['banmsg'] != '') && isset($_POST['addbanmsg']) && (isset($_POST['quickbanpostid']) || isset($_POST['quickmultibanpostid']))) || $instantban ) {
$ban_msg = ((KU_BANMSG == $_POST['banmsg']) || empty($_POST['banmsg'])) ? KU_BANMSG : $_POST['banmsg'];
if (isset($ban_post_id))
$postids = Array($ban_post_id);
else
$postids = unserialize($_POST['quickmultibanpostid']);
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `parentid`, `message` FROM `".KU_DBPREFIX."posts` WHERE `boardid` = " . $tc_db->qstr($ban_board_id) . " AND `id` = ".$tc_db->qstr($postids[$i])." LIMIT 1");
foreach($results AS $line) {
$tc_db->Execute("UPDATE `".KU_DBPREFIX."posts` SET `message` = ".$tc_db->qstr($line['message'] . $ban_msg)." WHERE `boardid` = " . $tc_db->qstr($ban_board_id) . " AND `id` = ".$tc_db->qstr($postids[$i]));
clearPostCache($postids[$i], $ban_board_id);
if ($line['parentid']==0) {
if (!in_array($postids, $regenerated)) {
$regenerated[] = $postids[$i];
}
} else {
if (!in_array($line['parentid'], $regenerated)) {
$regenerated[] = $line['parentid'];
}
}
}
}
$tpl_page .= _gettext('Ban successfully placed.')." ";
} else {
exitWithErrorPage(_gettext('Sorry, a generic error has occurred.'));
}
$logentry = _gettext('Banned') . ' '. $ban_ip;
$logentry .= ($ban_duration == 0) ? ' '. _gettext('without expiration') : ' '. _gettext('until') . ' '. date('F j, Y, g:i a', time() + $ban_duration);
$logentry .= ' - '. _gettext('Reason') . ': '. $ban_reason . (($ban_note) ? (" (".$ban_note.")") : ("")). ' - '. _gettext('Banned from') . ': ';
$logentry .= ($ban_globalban == 1) ? _gettext('All boards') . ' ' : '/'. implode('/, /', explode('|', $ban_boards)) . '/ ';
management_addlogentry($logentry, 8);
$ban_ip = '';
$i++;
}
if (count($regenerated) > 0) {
$board_class = new Board($ban_board);
foreach($regenerated as $thread) {
$board_class->RegenerateThreads($thread);
}
$board_class->RegeneratePages();
unset($board_class);
}
if(isset($_POST['deleteposts'])) {
$tpl_page .= ' ';
$this->deletepostsbyip(true);
}
if ((isset($_GET['instant']) && !isset($_GET['cp']))) {
die("success");
}
if (isset($_POST['banhashtime']) && $_POST['banhashtime'] !== '' && ($_POST['hash'] !== '' || isset($_POST['multibanhashes'])) && $_POST['banhashtime'] >= 0) {
if (isset($_POST['multibanhashes']))
$banhashes = unserialize($_POST['multibanhashes']);
else
$banhashes = Array($_POST['hash']);
foreach ($banhashes as $banhash){
$results = $tc_db->GetOne("SELECT HIGH_PRIORITY COUNT(*) FROM `".KU_DBPREFIX."bannedhashes` WHERE `md5` = ".$tc_db->qstr($banhash)." LIMIT 1");
if ($results == 0) {
$tc_db->Execute("INSERT INTO `".KU_DBPREFIX."bannedhashes` ( `md5` , `bantime` , `description` ) VALUES ( ".$tc_db->qstr($banhash)." , ".$tc_db->qstr($_POST['banhashtime'])." , ".$tc_db->qstr($_POST['banhashdesc'])." )");
management_addlogentry('Banned md5 hash '. $banhash . ' with a description of '. $_POST['banhashdesc'], 8);
}
}
}
if (!empty($_POST['quickbanboard']) && !empty($_POST['quickbanthreadid'])) {
$tpl_page .= ''. _gettext('Redirecting') . ' ...';
}
} else {
$tpl_page .= _gettext('Please enter a positive amount of seconds, or zero for a permanent ban.');
}
$tpl_page .= ' ';
} elseif (isset($_GET['delban']) && $_GET['delban'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `id` = " . $tc_db->qstr($_GET['delban']) . "");
if (count($results) > 0) {
$unban_ip = md5_decrypt($results[0]['ip'], KU_RANDOMSEED);
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "banlist` WHERE `id` = " . $tc_db->qstr($_GET['delban']) . "");
$bans_class->UpdateHtaccess();
$tpl_page .= _gettext('Ban successfully removed.');
management_addlogentry(_gettext('Unbanned') . ' '. $unban_ip, 8);
} else {
$tpl_page .= _gettext('Invalid ban ID');
}
$tpl_page .= ' ';
} elseif (isset($_GET['delhashid'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "bannedhashes` WHERE `id` = " . $tc_db->qstr($_GET['delhashid']) . "");
if (count($results) > 0) {
$tc_db->Execute("DELETE FROM `" . KU_DBPREFIX . "bannedhashes` WHERE `id` = " . $tc_db->qstr($_GET['delhashid']) . "");
$tpl_page .= _gettext('Hash removed from ban list.') . ' ';
}
}
flush();
$isquickban = false;
$tpl_page .= '';
if ((!empty($ban_ip) && isset($_GET['banboard']) && isset($_GET['banpost'])) || (!empty($multiban) && isset($_POST['board']) && isset($_POST['post']))) {
$isquickban = true;
$tpl_page .= ' ';
if(!empty($multiban)) {
$tpl_page .= ' ';
} else {
$tpl_page .= ' ';
}
} elseif (isset($_GET['ip'])) {
$ban_ip = $_GET['ip'];
}
$tpl_page .= '
'. _gettext('IP address and ban type') . '
'. _gettext('IP') . ': ';
if (!$multiban) {
$tpl_page .= '
'. _gettext('Delete all posts by this IP') . ':
';
}
else {
$tpl_page .= '
Multiple IPs
'. _gettext('Delete all posts by these IPs') . ':
';
}
$tpl_page .= '
'. _gettext('Allow read') . ':
'._gettext('Yes').' '._gettext('No').'
'. _gettext('Whether or not the user(s) affected by this ban will be allowed to read the boards.') . ''. _gettext('Warning') . ': '. _gettext('Selecting "No" will prevent any reading of any page on the level of the boards on the server. It will also act as a global ban.') . '
'. _gettext('Type') . ':
'. _gettext('Single IP') . ' '. _gettext('IP Range') . ' '. _gettext('Whitelist') . '
'. _gettext('The type of ban. A single IP can be banned by providing the full address. A whitelist ban prevents that IP from being banned. An IP range can be banned by providing the IP range you would like to ban, in this format: 123.123.12') . '
';
if ($isquickban && KU_BANMSG != '') {
$tpl_page .= ''. _gettext('Add ban message') . ':
'. _gettext('If checked, the configured ban message will be added to the end of the post.') . '
'. _gettext('Ban message') . ':
';
}
$tpl_page .='
'. _gettext('Ban from') . '
'. _gettext('All boards') . '
' .
$this->MakeBoardListCheckboxes('bannedfrom', $this->BoardList($_SESSION['manageusername'])) .
' ';
if (isset($ban_hash)) {
$tpl_page .= '
'. _gettext('Ban file') . '
'. _gettext('Ban file hash for') . ':
'. _gettext('The amount of time to ban the hash of the image which was posted under this ID. Leave blank to not ban the image, 0 for an infinite global ban, or any number of seconds for that duration of a global ban.') . '
'. _gettext('Ban file hash description') . ':
'. _gettext('The description of the image being banned. Not applicable if the above box is blank.') . '
';
}
$tpl_page .= '
'. _gettext('Ban duration, reason, and appeal information') . '
'. _gettext('Seconds') . ':
'. _gettext('Reason') . ':
'. _gettext('Staff Note') . '
'. _gettext('Presets') . ':
CP || '. _gettext('This message will be shown only on this page and only to staff, not to the user.') .'
';
if (KU_APPEAL != '') {
$tpl_page .= ''. _gettext('Appeal (days)') . ':
';
}
$tpl_page .= '
';
for ($i = 2; $i >= 0; $i--) {
switch ($i) {
case 2:
$tpl_page .= ''. _gettext('Whitelisted IPs') . ': ';
break;
case 1:
$tpl_page .= ''. _gettext('IP Range Bans') . ': ';
break;
case 0:
if (!empty($ban_ip))
$tpl_page .= ''. _gettext('Previous bans on this IP') . ': ';
else
$tpl_page .= ''. _gettext('Single IP Bans') . ': ';
break;
}
if (isset($_GET['allbans'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `type` = '" . $i . "' AND `by` != 'SERVER' ORDER BY `id` DESC");
$hiddenbans = 0;
} elseif (isset($_GET['limit'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `type` = '" . $i . "' ORDER BY `id` DESC LIMIT ".intval($_GET['limit']));
$hiddenbans = 0;
} else {
if (!empty($ban_ip) && $i == 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `ipmd5` = '" . md5($ban_ip) . "' AND `type` = '" . $i . "' AND `by` != 'SERVER' ORDER BY `id` DESC");
} else {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `type` = '" . $i . "' AND `by` != 'SERVER' ORDER BY `id` DESC LIMIT 15");
// Get the number of bans in the database of this type
$hiddenbans = $tc_db->GetAll("SELECT HIGH_PRIORITY COUNT(*) FROM `" . KU_DBPREFIX . "banlist` WHERE `type` = '" . $i . "'");
// Subtract 15 from the count, since we only want the number not shown
$hiddenbans = $hiddenbans[0][0] - 15;
}
}
if (count($results) > 0) {
$tpl_page .= '';
$tpl_page .= ($i == 1) ? _gettext('IP Range') : _gettext('IP Address');
$tpl_page .= ' '. _gettext('Boards') . ' '. _gettext('Reason') . ' '. _gettext('Staff Note') . ' '. _gettext('Date added') . ' '. _gettext('Expires/Expired') . ' '. _gettext('Added By') . ' ';
foreach ($results as $line) {
$tpl_page .= ''. md5_decrypt($line['ip'], KU_RANDOMSEED) . ' ';
if ($line['globalban'] == 1) {
$tpl_page .= ''. _gettext('All boards') . ' ';
} elseif (!empty($line['boards'])) {
$tpl_page .= '/'. implode('/ , /', explode('|', $line['boards'])) . '/ ';
}
$tpl_page .= ' ';
$tpl_page .= (!empty($line['reason'])) ? htmlentities(stripslashes($line['reason'])) : ' ';
$tpl_page .= ' ';
$tpl_page .= (!empty($line['staffnote'])) ? htmlentities(stripslashes($line['staffnote'])) : ' ';
$tpl_page .= ' '. date("F j, Y, g:i a", $line['at']) . ' ';
$tpl_page .= ($line['until'] == 0) ? ''. _gettext('Does not expire') . ' ' : date("F j, Y, g:i a", $line['until']);
$tpl_page .= ' '. $line['by'] . ' ['. _gettext('Delete') .' ] ';
}
$tpl_page .= '
';
if ($hiddenbans > 0) {
$tpl_page .= sprintf(_gettext('%s bans not shown.'), $hiddenbans) .
' '. _gettext('View all bans') . ' '.' View last 100 bans ';
}
} else {
$tpl_page .= _gettext('There are currently no bans');
}
}
$tpl_page .= ''. _gettext('File hash bans') . ': '. _gettext('Hash') . ' '. _gettext('Description') . ' '. _gettext('Ban time') . ' ';
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `".KU_DBPREFIX."bannedhashes` ". ((!isset($_GET['allbans'])) ? ("LIMIT 5") : ("")));
if (count($results) == 0) {
$tpl_page .= ''. _gettext('None') . ' ';
} else {
foreach ($results as $line) {
$tpl_page .= ''. $line['md5'] . ' '. $line['description'] . ' ';
$tpl_page .= ($line['bantime'] == 0) ? ''. _gettext('Does not expire') . ' ' : $line['bantime'] . ' seconds';
$tpl_page .= ' [x ] ';
}
}
$tpl_page .= '
';
}
function appeals() {
global $tc_db, $tpl_page, $bans_class;
$this->ModeratorsOnly();
$tpl_page .= ''. _gettext('Appeals') . ' ';
$ban_ip = '';
if (isset($_GET['accept'])) {
if ($_GET['accept'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `id` = " . $tc_db->qstr($_GET['accept']) . "");
if (count($results) > 0) {
foreach ($results as $line) {
$unban_ip = md5_decrypt($line['ip'], KU_RANDOMSEED);
}
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "banlist` SET `expired` = 1, `appealat` = -4 WHERE `id` = " . $tc_db->qstr($_GET['accept']) . "");
$bans_class->UpdateHtaccess();
$tpl_page .= _gettext('Ban successfully removed.');
management_addlogentry('Accepted appeal #'.$_GET['accept'].' from: '. $unban_ip, 8);
} else {
$tpl_page .= _gettext('Invalid ID');
}
$tpl_page .= ' ';
}
} elseif (isset($_GET['deny'])) {
if ($_GET['deny'] > 0) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `id` = " . $tc_db->qstr($_GET['deny']) . "");
if (count($results) > 0) {
foreach ($results as $line) {
$unban_ip = md5_decrypt($line['ip'], KU_RANDOMSEED);
}
$tc_db->Execute("UPDATE `" . KU_DBPREFIX . "banlist` SET `appealat` = -2 WHERE `id` = " . $tc_db->qstr($_GET['deny']) . "");
$bans_class->UpdateHtaccess();
$tpl_page .= _gettext('Appeal successfully denied.');
management_addlogentry(_gettext('Denied the ban appeal for') . ' '. $unban_ip, 8);
} else {
$tpl_page .= _gettext('Invalid ID');
}
$tpl_page .= ' ';
}
}
flush();
for ($i = 1; $i >= 0; $i--) {
if ($i == 1) {
$tpl_page .= ''. _gettext('IP Range bans') . ': ';
} else {
$tpl_page .= ''. _gettext('Single IP Bans') . ': ';
}
if ($ban_ip != '') {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `ipmd5` = '" . md5($ban_ip) . "' AND `type` = '" . $i . "' AND `expired` = 0 ORDER BY `id` DESC");
} else {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "banlist` WHERE `type` = '" . $i . "' AND `appealat` = -1 AND `expired` = 0 ORDER BY `id` DESC");
}
if (count($results) > 0) {
$tpl_page .= '';
if ($i == 1) {
$tpl_page .= 'IP Range';
} else {
$tpl_page .= 'IP Address';
}
$tpl_page .= ' Boards Reason Staff Note Date Added Expires Added By Appeal Message Deny Accept ';
foreach ($results as $line) {
$tpl_page .= '';
$tpl_page .= ''. md5_decrypt($line['ip'], KU_RANDOMSEED) . ' ';
if ($line['globalban'] == '1') {
$tpl_page .= ''. _gettext('All boards') . ' ';
} else {
if ($line['boards'] != '') {
$tpl_page .= '/'. implode('/ , /', explode('|', $line['boards'])) . '/ ';
}
}
$tpl_page .= ' ';
if ($line['reason'] != '') {
$tpl_page .= htmlentities(stripslashes($line['reason']));
} else {
$tpl_page .= ' ';
}
$tpl_page .= ' ';
if ($line['staffnote'] != '') {
$tpl_page .= htmlentities(stripslashes($line['staffnote']));
} else {
$tpl_page .= ' ';
}
$tpl_page .= ' '. date("F j, Y, g:i a", $line['at']) . ' ';
if ($line['until'] == '0') {
$tpl_page .= ''. _gettext('Does not expire') . ' ';
} else {
$tpl_page .= date("F j, Y, g:i a", $line['until']);
}
$tpl_page .= ' '. $line['by'] . '
'.$line['appeal'].'
:(
:) ';
$tpl_page .= ' ';
}
$tpl_page .= '
';
if ($hiddenbans>0) {
$tpl_page .= sprintf(_gettext('%s bans not shown.'), $hiddenbans) .
' '. _gettext('View all bans') . ' '.' View last 100 bans ';
}
} else {
$tpl_page .= _gettext('There are currently no bans.');
}
}
}
/* Search for all posts by a selected IP address and delete them */
function deletepostsbyip($from_ban = false) {
global $tc_db, $tpl_page, $board_class;
$this->ModeratorsOnly();
if (!$from_ban) {
$tpl_page .= ''. _gettext('Delete all posts by IP') . ' ';
}
if (isset($_POST['ip']) || isset($_POST['multiban'])) {
if ($_POST['ip'] != '' || !empty($_POST['multiban'])) {
if (!$from_ban) {
$this->CheckToken($_POST['token']);
}
$deletion_boards = array();
$deletion_new_boards = array();
$board_ids = '';
if (isset($_POST['banfromall'])) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards`");
foreach ($results as $line) {
if (!$this->CurrentUserIsModeratorOfBoard($line['name'], $_SESSION['manageusername'])) {
exitWithErrorPage('/'. $line['name'] . '/: '. _gettext('You can only delete posts from boards you moderate.'));
}
$delete_boards[$line['id']] = $line['name'];
$board_ids .= $line['id'] . ',';
}
} else {
if (empty($_POST['deletefrom'])) {
exitWithErrorPage(_gettext('Please select a board.'));
}
foreach($_POST['deletefrom'] as $board) {
if (!$this->CurrentUserIsModeratorOfBoard($board, $_SESSION['manageusername'])) {
exitWithErrorPage('/'. $board . '/: '. _gettext('You can only delete posts from boards you moderate.'));
}
$id = $tc_db->GetOne("SELECT `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($board));
$board_ids .= $tc_db->qstr($id) . ',';
$delete_boards[$id] = $board;
}
}
$board_ids = substr($board_ids, 0, -1);
$i = 0;
if (isset($_POST['multiban']))
$ips = unserialize($_POST['multiban']);
else
$ips = Array($_POST['ip']);
foreach ($ips as $ip) {
$i = 0;
$post_list = $tc_db->GetAll("SELECT `id`, `boardid` FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` IN (" . $board_ids . ") AND `IS_DELETED` = '0' AND `ipmd5` = '" . md5($ip) . "'");
if (count($post_list) > 0) {
foreach ($post_list as $post) {
$i++;
$post_class = new Post($post['id'], $delete_boards[$post['boardid']], $post['boardid']);
$post_class->Delete();
$boards_deleted[$post['boardid']] = $delete_boards[$post['boardid']];
unset($post_class);
}
$tpl_page .= _gettext('All threads/posts by that IP in selected boards successfully deleted.') . ''. $i . ' posts were removed. ';
management_addlogentry(_gettext('Deleted posts by ip') . ' '. $ip, 7);
}
else {
$tpl_page .= _gettext('No posts for that IP found');
}
if (isset($boards_deleted)) {
foreach ($boards_deleted as $board) {
$board_class = new Board($board);
$board_class->RegenerateAll();
unset($board_class);
}
}
}
$tpl_page .= ' ';
}
}
if (!$from_ban) {
$tpl_page .= '
IP
'. _gettext('IP') .':
'. _gettext('All boards') .'
' .
$this->MakeBoardListCheckboxes('deletefrom', $this->BoardList($_SESSION['manageusername'])) .
'
';
}
}
/* View recently uploaded images */
function recentimages() {
global $tc_db, $tpl_page;
$this->ModeratorsOnly();
if (!isset($_SESSION['imagesperpage'])) {
$_SESSION['imagesperpage'] = 50;
}
if (isset($_GET['show'])) {
if ($_GET['show'] == '25' || $_GET['show'] == '50' || $_GET['show'] == '75' || $_GET['show'] == '100') {
$_SESSION['imagesperpage'] = $_GET['show'];
}
}
$tpl_page .= ''. _gettext('Recently uploaded images') . '
'._gettext('Number of images to show per page').': 25 , 50 , 75 , 100 '._gettext('(note that this is a rough limit, more may be shown)').' ';
if (isset($_POST['clear'])) {
if ($_POST['clear'] != '') {
$clear_decrypted = md5_decrypt($_POST['clear'], KU_RANDOMSEED);
if ($clear_decrypted != '') {
$clear_unserialized = unserialize($clear_decrypted);
foreach ($clear_unserialized as $clear_sql) {
$tc_db->Execute($clear_sql);
}
$tpl_page .= _gettext('Successfully marked previous images as reviewed.').' ';
}
}
}
$dayago = (time() - 86400);
$imagesshown = 0;
$reviewsql_array = array();
if ($imagesshown <= $_SESSION['imagesperpage']) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `" . KU_DBPREFIX . "boards`.`name` AS `boardname`, `" . KU_DBPREFIX . "posts`.`boardid` AS boardid, `" . KU_DBPREFIX . "posts`.`id` AS id, `" . KU_DBPREFIX . "posts`.`parentid` AS parentid, `" . KU_DBPREFIX . "posts`.`file` AS file, `" . KU_DBPREFIX . "posts`.`file_type` AS file_type, `" . KU_DBPREFIX . "posts`.`thumb_w` AS thumb_w, `" . KU_DBPREFIX . "posts`.`thumb_h` AS thumb_h FROM `" . KU_DBPREFIX . "posts`, `" . KU_DBPREFIX ."boards` WHERE (`file_type` = 'jpg' OR `file_type` = 'gif' OR `file_type` = 'png') AND `reviewed` = 0 AND `IS_DELETED` = 0 AND `" . KU_DBPREFIX . "boards`.`id` = `" . KU_DBPREFIX . "posts`.`boardid` ORDER BY `timestamp` DESC LIMIT " . intval($_SESSION['imagesperpage']));
if (count($results) > 0) {
$reviewsql = "UPDATE `" . KU_DBPREFIX . "posts` SET `reviewed` = 1 WHERE ";
$tpl_page .= ''. "\n";
foreach ($results as $line) {
$reviewsql .= '(`boardid` = '.$line['boardid'] .' AND `id` = '. $line['id'] . ') OR ';
$real_parentid = ($line['parentid'] == 0) ? $line['id'] : $line['parentid'];
$tpl_page .= '/'. $line['boardname'] . '/'. $line['id'] . ' ';
}
$tpl_page .= '
';
$reviewsql = substr($reviewsql, 0, -3);
$reviewsql_array[] = $reviewsql;
$imagesshown += count($results);
}
}
if ($imagesshown > 0) {
$tpl_page .= ' '. sprintf(_gettext('%s images shown.'), $imagesshown). ' ';
$tpl_page .= '
';
} else {
$tpl_page .= ' '. _gettext('No recent images currently need review.') ;
}
}
/* View recently posted posts */
function recentposts() {
global $tc_db, $tpl_page;
$this->ModeratorsOnly();
if (!isset($_SESSION['postsperpage'])) {
$_SESSION['postsperpage'] = 50;
}
if (isset($_GET['show'])) {
if ($_GET['show'] == '25' || $_GET['show'] == '50' || $_GET['show'] == '75' || $_GET['show'] == '100') {
$_SESSION['postsperpage'] = $_GET['show'];
}
}
$tpl_page .= ''. _gettext('Recent posts') . '
'._gettext('Number of posts to show per page').': 25 , 50 , 75 , 100 '._gettext('(note that this is a rough limit, more may be shown)').' ';
if (isset($_POST['clear'])) {
if ($_POST['clear'] != '') {
$clear_decrypted = md5_decrypt($_POST['clear'], KU_RANDOMSEED);
if ($clear_decrypted != '') {
$clear_unserialized = unserialize($clear_decrypted);
foreach ($clear_unserialized as $clear_sql) {
$tc_db->Execute($clear_sql);
}
$tpl_page .= _gettext('Successfully marked previous posts as reviewed.').' ';
}
}
}
$dayago = (time() - 86400);
$postsshown = 0;
$reviewsql_array = array();
$boardlist = $this->BoardList($_SESSION['manageusername']);
if ($postsshown <= $_SESSION['postsperpage']) {
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `" . KU_DBPREFIX . "boards`.`name` AS `boardname`, `" . KU_DBPREFIX . "posts`.`boardid` AS boardid, `" . KU_DBPREFIX . "posts`.`id` AS id, `" . KU_DBPREFIX . "posts`.`parentid` AS parentid, `" . KU_DBPREFIX . "posts`.`message` AS message, `" . KU_DBPREFIX . "posts`.`ip` AS ip FROM `" . KU_DBPREFIX . "posts`, `" . KU_DBPREFIX ."boards` WHERE `" . KU_DBPREFIX . "posts`.`timestamp` > " . $dayago . " AND `reviewed` = 0 AND `IS_DELETED` = 0 AND `" . KU_DBPREFIX . "boards`.`id` = `" . KU_DBPREFIX . "posts`.`boardid` ORDER BY `timestamp` DESC LIMIT " . intval($_SESSION['postsperpage']));
if (count($results) > 0) {
$reviewsql = "UPDATE `" . KU_DBPREFIX . "posts` SET `reviewed` = 1 WHERE ";
$tpl_page .= ''. "\n";
$tpl_page .= ''._gettext('Post Number').' '._gettext('Post Message').' '._gettext('Poster IP').' '. "\n";
foreach ($results as $line) {
$reviewsql .= '(`boardid` = '.$line['boardid'] .' AND `id` = '. $line['id'] . ') OR ';
$real_parentid = ($line['parentid'] == 0) ? $line['id'] : $line['parentid'];
$tpl_page .= '/'. $line['boardname'] . '/'. $line['id'] . ' '. stripslashes($line['message']) . ' '. md5_decrypt($line['ip'], KU_RANDOMSEED) . ' ';
}
$tpl_page .= '
';
$reviewsql = substr($reviewsql, 0, -3) . ' LIMIT '. count($results);
$reviewsql_array[] = $reviewsql;
$postsshown += count($results);
}
}
if ($postsshown > 0) {
$tpl_page .= ' '. sprintf(_gettext('%s posts shown.'), $postsshown) .'
';
} else {
$tpl_page .= ' '. _gettext('No recent posts currently need review.') ;
}
}
/*
* +------------------------------------------------------------------------------+
* Misc Functions
* +------------------------------------------------------------------------------+
*/
/* Show APC info */
function apc() {
global $tpl_page;
if (KU_APC) {
$apc_info_system = apc_cache_info();
$apc_info_user = apc_cache_info('user');
//print_r($apc_info_user);
$tpl_page .= 'APC '. _gettext('System (File cache)') .' ';
$tpl_page .= 'Start time: '. date("y/m/d(D)H:i", $apc_info_system['start_time']) . ' ';
$tpl_page .= 'Hits: '. $apc_info_system['num_hits'] . ' ';
$tpl_page .= 'Misses: '. $apc_info_system['num_misses'] . ' ';
$tpl_page .= 'Entries: '. $apc_info_system['num_entries'] . ' ';
$tpl_page .= ' User (kusaba) ';
$tpl_page .= 'Start time: '. date("y/m/d(D)H:i", $apc_info_user['start_time']) . ' ';
$tpl_page .= 'Hits: '. $apc_info_user['num_hits'] . ' ';
$tpl_page .= 'Misses: '. $apc_info_user['num_misses'] . ' ';
$tpl_page .= 'Entries: '. $apc_info_user['num_entries'] . ' ';
$tpl_page .= ' Clear APC cache ';
} else {
$tpl_page .= 'APC isn\'t enabled!';
}
}
/* Clear the APC cache */
function clearcache() {
global $tpl_page;
if (KU_APC) {
apc_clear_cache();
apc_clear_cache('user');
$tpl_page .= 'APC cache cleared.';
management_addlogentry(_gettext('Cleared APC cache'), 0);
} else {
$tpl_page .= 'APC isn\'t enabled!';
}
}
/* Generate a list of boards a moderator controls */
function BoardList($username) {
global $tc_db, $tpl_page;
$staff_boardsmoderated = array();
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `boards` FROM `" . KU_DBPREFIX . "staff` WHERE `username` = '" . $username . "' LIMIT 1");
if ($this->CurrentUserIsAdministrator() || $results[0][0] == 'allboards') {
$resultsboard = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards` ORDER BY `name` ASC");
foreach ($resultsboard as $lineboard) {
$staff_boardsmoderated = array_merge($staff_boardsmoderated, array(array( 'name' => $lineboard['name'], 'id' => $lineboard['id'])));
}
} else {
if ($results[0][0] != '') {
foreach ($results as $line) {
$array_boards = explode('|', $line['boards']);
}
foreach ($array_boards as $this_board_name) {
$this_board_id = $tc_db->GetOne("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($this_board_name) . "");
$staff_boardsmoderated = array_merge($staff_boardsmoderated, array(array('name' => $this_board_name, 'id' => $this_board_id)));
}
}
}
return $staff_boardsmoderated;
}
/* Generate a list of boards in query format */
function sqlboardlist() {
global $tc_db, $tpl_page;
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id` FROM `" . KU_DBPREFIX . "boards` ORDER BY `name` ASC");
$sqlboards = '';
foreach ($results as $line) {
$sqlboards .= 'posts_'. $line['name'] . ', ';
}
return substr($sqlboards, 0, -2);
}
/* Generate a dropdown box from a supplied array of boards */
function MakeBoardListDropdown($name, $boards, $all = false) {
$output = ''. _gettext('Select a Board') .' ';
if (!empty($boards)) {
if ($all) {
$output .= ''. _gettext('All Boards') .' ';
}
foreach ($boards as $board) {
$output .= '/'. $board['name'] . '/ ';
}
}
$output .= ' ';
return $output;
}
/* Generate a series of checkboxes from a supplied array of boards */
function MakeBoardListCheckboxes($boxname, $boards) {
$output = '';
if (!empty($boards)) {
foreach ($boards as $board) {
$output .= ''. $board['name'] . ' '."\n";
}
}
return $output;
}
/* Generate a dropdown box for all sections */
function MakeSectionListDropDown($name, $selected) {
global $tc_db;
$output = ''. _gettext('Select a Section') .' '. "\n";
$results = $tc_db->GetAll("SELECT `id`, `name` FROM `" . KU_DBPREFIX . "sections` ORDER BY `order` ASC");
if(count($results) > 0) {
foreach ($results as $section) {
if ($section['id'] == $selected) {
$select = ' selected="selected"';
} else {
$select = '';
}
$output .= ''. $section['name'] . ' '. "\n";
}
}
$output .= ' '. "\n";
return $output;
}
/* Delete files without their md5 stored in the database */
function delunusedimages($verbose = false) {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$resultsboard = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards`");
foreach ($resultsboard as $lineboard) {
if ($verbose) {
$tpl_page .= ''. _gettext('Looking for unused images in') .' /'. $lineboard['name'] . '/ ';
}
$file_md5list = array();
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `file_md5` FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $lineboard['id'] . " AND `IS_DELETED` = 0 AND `file` != '' AND `file` != 'removed' AND `file_md5` != ''");
foreach ($results as $line) {
$file_md5list[] = $line['file_md5'];
}
$dir = './'. $lineboard['name'] . '/src';
$files = glob("$dir/{*.jpg, *.png, *.gif, *.swf}", GLOB_BRACE);
if (is_array($files)) {
foreach ($files as $file) {
if (in_array(md5_file(KU_BOARDSDIR . $lineboard['name'] . '/src/'. basename($file)), $file_md5list) == false) {
if (time() - filemtime(KU_BOARDSDIR . $lineboard['name'] . '/src/'. basename($file)) > 120) {
if ($verbose == true) {
$tpl_page .= sprintf(_gettext('A live record for %s was not found; the file has been removed.'), $file).' ';
}
unlink(KU_BOARDSDIR . $lineboard['name'] . '/src/'. basename($file));
@unlink(KU_BOARDSDIR . $lineboard['name'] . '/thumb/'. substr(basename($file), 0, -4) . 's'. substr(basename($file), strlen(basename($file)) - 4));
@unlink(KU_BOARDSDIR . $lineboard['name'] . '/thumb/'. substr(basename($file), 0, -4) . 'c'. substr(basename($file), strlen(basename($file)) - 4));
}
}
}
}
}
return true;
}
/* Delete replies currently not marked as deleted who belong to a thread which is marked as deleted */
function delorphanreplies($verbose = false) {
global $tc_db, $tpl_page;
$this->AdministratorsOnly();
$resultsboard = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `name` FROM `" . KU_DBPREFIX . "boards`");
foreach ($resultsboard as $lineboard) {
if ($verbose) {
$tpl_page .= ''. _gettext('Looking for orphans in') .' /'. $lineboard['name'] . '/ ';
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY `id`, `parentid` FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $lineboard['id'] . " AND `parentid` != '0' AND `IS_DELETED` = 0");
foreach ($results as $line) {
$exists_rows = $tc_db->GetAll("SELECT HIGH_PRIORITY COUNT(*) FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $lineboard['id'] . " AND `id` = '" . $line['parentid'] . "' AND `IS_DELETED` = 0", 1);
if ($exists_rows[0] == 0) {
$post_class = new Post($line['id'], $lineboard['name'], $lineboard['id']);
$post_class->Delete;
unset($post_class);
if ($verbose) {
$tpl_page .= sprintf(_gettext('Reply #%1$s\'s thread (#%2$s) does not exist! It has been deleted.'),$line['id'],$line['parentid']).' ';
}
}
}
}
return true;
}
function spam() {
global $tpl_page;
$spam = KU_ROOTDIR . 'spam.txt';
if (!empty($_POST['spam'])) {
$this->CheckToken($_POST['token']);
file_put_contents($spam, $_POST['spam']);
$tpl_page .= ' '. _gettext('Spam.txt successfully edited.') .' ';
}
$content = htmlspecialchars(file_get_contents(KU_ROOTDIR . 'spam.txt'));
$tpl_page .= ''. _gettext('Spam.txt Management') .' '. "\n" .
''. "\n" .
' ' . "\n" .
'' . htmlspecialchars($content) . ' ' . "\n" .
' '. "\n" .
' '. "\n";
}
/* Gets the IP address of a post */
function getip() {
global $tc_db, $smarty, $tpl_page;
if(!$this->CurrentUserIsModerator() && !$this->CurrentUserIsAdministrator()) {
die();
}
$results = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "boards` WHERE `name` = " . $tc_db->qstr($_GET['boarddir']));
if (count($results) > 0) {
if (!$this->CurrentUserIsModeratorOfBoard($_GET['boarddir'], $_SESSION['manageusername'])) {
die();
}
$ip = $tc_db->GetAll("SELECT HIGH_PRIORITY * FROM `" . KU_DBPREFIX . "posts` WHERE `boardid` = " . $tc_db->qstr($results[0]['id']) . " AND `id` = " . $tc_db->qstr($_GET['id']));
die("dnb-".$_GET['boarddir']."-".$_GET['id']."-".(($ip[0]['parentid'] == 0) ? ("y") : ("n"))."=".md5_decrypt($ip[0]['ip'], KU_RANDOMSEED));
}
die();
}
}
?>