2
0

PersonalMessage.php 141 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177
  1. <?php
  2. /**
  3. * This file is mainly meant for controlling the actions related to personal
  4. * messages. It allows viewing, sending, deleting, and marking personal
  5. * messages. For compatibility reasons, they are often called "instant messages".
  6. *
  7. * Simple Machines Forum (SMF)
  8. *
  9. * @package SMF
  10. * @author Simple Machines http://www.simplemachines.org
  11. * @copyright 2014 Simple Machines and individual contributors
  12. * @license http://www.simplemachines.org/about/smf/license.php BSD
  13. *
  14. * @version 2.1 Alpha 1
  15. */
  16. if (!defined('SMF'))
  17. die('No direct access...');
  18. /**
  19. * This helps organize things...
  20. * @todo this should be a simple dispatcher....
  21. */
  22. function MessageMain()
  23. {
  24. global $txt, $scripturl, $sourcedir, $context, $user_info, $user_settings, $smcFunc, $modSettings;
  25. // No guests!
  26. is_not_guest();
  27. // You're not supposed to be here at all, if you can't even read PMs.
  28. isAllowedTo('pm_read');
  29. // This file contains the basic functions for sending a PM.
  30. require_once($sourcedir . '/Subs-Post.php');
  31. loadLanguage('PersonalMessage+Drafts');
  32. if (WIRELESS && WIRELESS_PROTOCOL == 'wap')
  33. fatal_lang_error('wireless_error_notyet', false);
  34. elseif (WIRELESS)
  35. $context['sub_template'] = WIRELESS_PROTOCOL . '_pm';
  36. elseif (!isset($_REQUEST['xml']))
  37. loadTemplate('PersonalMessage');
  38. // Load up the members maximum message capacity.
  39. if ($user_info['is_admin'])
  40. $context['message_limit'] = 0;
  41. elseif (($context['message_limit'] = cache_get_data('msgLimit:' . $user_info['id'], 360)) === null)
  42. {
  43. // @todo Why do we do this? It seems like if they have any limit we should use it.
  44. $request = $smcFunc['db_query']('', '
  45. SELECT MAX(max_messages) AS top_limit, MIN(max_messages) AS bottom_limit
  46. FROM {db_prefix}membergroups
  47. WHERE id_group IN ({array_int:users_groups})',
  48. array(
  49. 'users_groups' => $user_info['groups'],
  50. )
  51. );
  52. list ($maxMessage, $minMessage) = $smcFunc['db_fetch_row']($request);
  53. $smcFunc['db_free_result']($request);
  54. $context['message_limit'] = $minMessage == 0 ? 0 : $maxMessage;
  55. // Save us doing it again!
  56. cache_put_data('msgLimit:' . $user_info['id'], $context['message_limit'], 360);
  57. }
  58. // Prepare the context for the capacity bar.
  59. if (!empty($context['message_limit']))
  60. {
  61. $bar = ($user_info['messages'] * 100) / $context['message_limit'];
  62. $context['limit_bar'] = array(
  63. 'messages' => $user_info['messages'],
  64. 'allowed' => $context['message_limit'],
  65. 'percent' => $bar,
  66. 'bar' => min(100, (int) $bar),
  67. 'text' => sprintf($txt['pm_currently_using'], $user_info['messages'], round($bar, 1)),
  68. );
  69. }
  70. // a previous message was sent successfully? show a small indication.
  71. if (isset($_GET['done']) && ($_GET['done'] == 'sent'))
  72. $context['pm_sent'] = true;
  73. $context['labels'] = array();
  74. // Load the label data.
  75. if ($user_settings['new_pm'] || ($context['labels'] = cache_get_data('labelCounts:' . $user_info['id'], 720)) === null)
  76. {
  77. // Looks like we need to reseek!
  78. // Inbox "label"
  79. $context['labels'][-1] = array(
  80. 'id' => -1,
  81. 'name' => $txt['pm_msg_label_inbox'],
  82. 'messages' => 0,
  83. 'unread_messages' => 0,
  84. );
  85. // First get the inbox counts
  86. // The CASE WHEN here is because is_read is set to 3 when you reply to a message
  87. $result = $smcFunc['db_query']('', '
  88. SELECT COUNT(*) AS total, SUM(is_read & 1) AS num_read
  89. FROM {db_prefix}pm_recipients
  90. WHERE id_member = {int:current_member}
  91. AND in_inbox = {int:in_inbox}
  92. AND deleted = {int:not_deleted}',
  93. array(
  94. 'current_member' => $user_info['id'],
  95. 'in_inbox' => 1,
  96. 'not_deleted' => 0,
  97. )
  98. );
  99. while ($row = $smcFunc['db_fetch_assoc']($result))
  100. {
  101. $context['labels'][-1]['messages'] = $row['total'];
  102. $context['labels'][-1]['unread_messages'] = $row['total'] - $row['num_read'];
  103. }
  104. $smcFunc['db_free_result']($result);
  105. // Now load info about all the other labels
  106. $result = $smcFunc['db_query']('', '
  107. SELECT l.id_label, l.name, IFNULL(SUM(pr.is_read & 1), 0) AS num_read, IFNULL(COUNT(pr.id_pm), 0) AS total
  108. FROM {db_prefix}pm_labels AS l
  109. LEFT JOIN {db_prefix}pm_labeled_messages AS pl ON (pl.id_label = l.id_label)
  110. LEFT JOIN {db_prefix}pm_recipients AS pr ON (pr.id_pm = pl.id_pm)
  111. WHERE l.id_member = {int:current_member}
  112. GROUP BY l.id_label, l.name',
  113. array(
  114. 'current_member' => $user_info['id'],
  115. )
  116. );
  117. while ($row = $smcFunc['db_fetch_assoc']($result))
  118. {
  119. $context['labels'][$row['id_label']] = array(
  120. 'id' => $row['id_label'],
  121. 'name' => $row['name'],
  122. 'messages' => $row['total'],
  123. 'unread_messages' => $row['total'] - $row['num_read']
  124. );
  125. }
  126. $smcFunc['db_free_result']($result);
  127. // Store it please!
  128. cache_put_data('labelCounts:' . $user_info['id'], $context['labels'], 720);
  129. }
  130. // Now we have the labels, and assuming we have unsorted mail, apply our rules!
  131. if ($user_settings['new_pm'])
  132. {
  133. ApplyRules();
  134. updateMemberData($user_info['id'], array('new_pm' => 0));
  135. $smcFunc['db_query']('', '
  136. UPDATE {db_prefix}pm_recipients
  137. SET is_new = {int:not_new}
  138. WHERE id_member = {int:current_member}',
  139. array(
  140. 'current_member' => $user_info['id'],
  141. 'not_new' => 0,
  142. )
  143. );
  144. }
  145. // This determines if we have more labels than just the standard inbox.
  146. $context['currently_using_labels'] = count($context['labels']) > 1 ? 1 : 0;
  147. // Some stuff for the labels...
  148. $context['current_label_id'] = isset($_REQUEST['l']) && isset($context['labels'][$_REQUEST['l']]) ? (int) $_REQUEST['l'] : -1;
  149. $context['current_label'] = &$context['labels'][$context['current_label_id']]['name'];
  150. $context['folder'] = !isset($_REQUEST['f']) || $_REQUEST['f'] != 'sent' ? 'inbox' : 'sent';
  151. // This is convenient. Do you know how annoying it is to do this every time?!
  152. $context['current_label_redirect'] = 'action=pm;f=' . $context['folder'] . (isset($_GET['start']) ? ';start=' . $_GET['start'] : '') . (isset($_REQUEST['l']) ? ';l=' . $_REQUEST['l'] : '');
  153. $context['can_issue_warning'] = allowedTo('issue_warning') && $modSettings['warning_settings'][0] == 1;
  154. // Are PM drafts enabled?
  155. $context['drafts_pm_save'] = !empty($modSettings['drafts_pm_enabled']) && allowedTo('pm_draft');
  156. $context['drafts_autosave'] = !empty($context['drafts_pm_save']) && !empty($modSettings['drafts_autosave_enabled']) && allowedTo('pm_autosave_draft');
  157. // Build the linktree for all the actions...
  158. $context['linktree'][] = array(
  159. 'url' => $scripturl . '?action=pm',
  160. 'name' => $txt['personal_messages']
  161. );
  162. // Preferences...
  163. $context['display_mode'] = WIRELESS ? 0 : $user_settings['pm_prefs'] & 3;
  164. $subActions = array(
  165. 'popup' => 'MessagePopup',
  166. 'addbuddy' => 'WirelessAddBuddy',
  167. 'manlabels' => 'ManageLabels',
  168. 'manrules' => 'ManageRules',
  169. 'pmactions' => 'MessageActionsApply',
  170. 'prune' => 'MessagePrune',
  171. 'removeall' => 'MessageKillAllQuery',
  172. 'removeall2' => 'MessageKillAll',
  173. 'report' => 'ReportMessage',
  174. 'search' => 'MessageSearch',
  175. 'search2' => 'MessageSearch2',
  176. 'send' => 'MessagePost',
  177. 'send2' => 'MessagePost2',
  178. 'settings' => 'MessageSettings',
  179. 'showpmdrafts' => 'MessageDrafts',
  180. );
  181. if (!isset($_REQUEST['sa']) || !isset($subActions[$_REQUEST['sa']]))
  182. {
  183. $_REQUEST['sa'] = '';
  184. MessageFolder();
  185. }
  186. else
  187. {
  188. if (!isset($_REQUEST['xml']) && $_REQUEST['sa'] != 'popup')
  189. messageIndexBar($_REQUEST['sa']);
  190. $subActions[$_REQUEST['sa']]();
  191. }
  192. }
  193. /**
  194. * A menu to easily access different areas of the PM section
  195. *
  196. * @param string $area
  197. */
  198. function messageIndexBar($area)
  199. {
  200. global $txt, $context, $scripturl, $sourcedir, $sc, $modSettings, $user_info;
  201. $pm_areas = array(
  202. 'folders' => array(
  203. 'title' => $txt['pm_messages'],
  204. 'areas' => array(
  205. 'send' => array(
  206. 'label' => $txt['new_message'],
  207. 'custom_url' => $scripturl . '?action=pm;sa=send',
  208. 'permission' => allowedTo('pm_send'),
  209. ),
  210. 'inbox' => array(
  211. 'label' => $txt['inbox'],
  212. 'custom_url' => $scripturl . '?action=pm',
  213. ),
  214. 'sent' => array(
  215. 'label' => $txt['sent_items'],
  216. 'custom_url' => $scripturl . '?action=pm;f=sent',
  217. ),
  218. 'drafts' => array(
  219. 'label' => $txt['drafts_show'],
  220. 'custom_url' => $scripturl . '?action=pm;sa=showpmdrafts',
  221. 'permission' => allowedTo('pm_draft'),
  222. 'enabled' => !empty($modSettings['drafts_pm_enabled']),
  223. ),
  224. ),
  225. ),
  226. 'labels' => array(
  227. 'title' => $txt['pm_labels'],
  228. 'areas' => array(),
  229. ),
  230. 'actions' => array(
  231. 'title' => $txt['pm_actions'],
  232. 'areas' => array(
  233. 'search' => array(
  234. 'label' => $txt['pm_search_bar_title'],
  235. 'custom_url' => $scripturl . '?action=pm;sa=search',
  236. ),
  237. 'prune' => array(
  238. 'label' => $txt['pm_prune'],
  239. 'custom_url' => $scripturl . '?action=pm;sa=prune'
  240. ),
  241. ),
  242. ),
  243. 'pref' => array(
  244. 'title' => $txt['pm_preferences'],
  245. 'areas' => array(
  246. 'manlabels' => array(
  247. 'label' => $txt['pm_manage_labels'],
  248. 'custom_url' => $scripturl . '?action=pm;sa=manlabels',
  249. ),
  250. 'manrules' => array(
  251. 'label' => $txt['pm_manage_rules'],
  252. 'custom_url' => $scripturl . '?action=pm;sa=manrules',
  253. ),
  254. 'settings' => array(
  255. 'label' => $txt['pm_settings'],
  256. 'custom_url' => $scripturl . '?action=pm;sa=settings',
  257. ),
  258. ),
  259. ),
  260. );
  261. // Handle labels.
  262. if (empty($context['currently_using_labels']))
  263. unset($pm_areas['labels']);
  264. else
  265. {
  266. // Note we send labels by id as it will have less problems in the querystring.
  267. $unread_in_labels = 0;
  268. foreach ($context['labels'] as $label)
  269. {
  270. if ($label['id'] == -1)
  271. continue;
  272. // Count the amount of unread items in labels.
  273. $unread_in_labels += $label['unread_messages'];
  274. // Add the label to the menu.
  275. $pm_areas['labels']['areas']['label' . $label['id']] = array(
  276. 'label' => $label['name'] . (!empty($label['unread_messages']) ? ' <span class="amt">' . $label['unread_messages'] . '</span>' : ''),
  277. 'custom_url' => $scripturl . '?action=pm;l=' . $label['id'],
  278. 'unread_messages' => $label['unread_messages'],
  279. 'messages' => $label['messages'],
  280. );
  281. }
  282. if (!empty($unread_in_labels))
  283. $pm_areas['labels']['title'] .= ' <span class="amt">' . $unread_in_labels . '</span>';
  284. }
  285. $pm_areas['folders']['areas']['inbox']['unread_messages'] = &$context['labels'][-1]['unread_messages'];
  286. $pm_areas['folders']['areas']['inbox']['messages'] = &$context['labels'][-1]['messages'];
  287. if (!empty($context['labels'][-1]['unread_messages']))
  288. {
  289. $pm_areas['folders']['areas']['inbox']['label'] .= ' <span class="amt">' . $context['labels'][-1]['unread_messages'] . '</span>';
  290. $pm_areas['folders']['title'] .= ' <span class="amt">' . $context['labels'][-1]['unread_messages'] . '</span>';
  291. }
  292. // Do we have a limit on the amount of messages we can keep?
  293. if (!empty($context['message_limit']))
  294. {
  295. $bar = round(($user_info['messages'] * 100) / $context['message_limit'], 1);
  296. $context['limit_bar'] = array(
  297. 'messages' => $user_info['messages'],
  298. 'allowed' => $context['message_limit'],
  299. 'percent' => $bar,
  300. 'bar' => $bar > 100 ? 100 : (int) $bar,
  301. 'text' => sprintf($txt['pm_currently_using'], $user_info['messages'], $bar)
  302. );
  303. }
  304. require_once($sourcedir . '/Subs-Menu.php');
  305. // What page is this, again?
  306. $current_page = $scripturl . '?action=pm' . (!empty($_REQUEST['sa']) ? ';sa=' . $_REQUEST['sa'] : '') . (!empty($context['folder']) ? ';f=' . $context['folder'] : '') . (!empty($context['current_label_id']) ? ';l=' . $context['current_label_id'] : '');
  307. // Set a few options for the menu.
  308. $menuOptions = array(
  309. 'current_area' => $area,
  310. 'disable_url_session_check' => true,
  311. );
  312. // Actually create the menu!
  313. $pm_include_data = createMenu($pm_areas, $menuOptions);
  314. unset($pm_areas);
  315. // No menu means no access.
  316. if (!$pm_include_data && (!$user_info['is_guest'] || validateSession()))
  317. fatal_lang_error('no_access', false);
  318. // Make a note of the Unique ID for this menu.
  319. $context['pm_menu_id'] = $context['max_menu_id'];
  320. $context['pm_menu_name'] = 'menu_data_' . $context['pm_menu_id'];
  321. // Set the selected item.
  322. $current_area = $pm_include_data['current_area'];
  323. $context['menu_item_selected'] = $current_area;
  324. // Set the template for this area and add the profile layer.
  325. if (!WIRELESS && !isset($_REQUEST['xml']))
  326. $context['template_layers'][] = 'pm';
  327. }
  328. /**
  329. * The popup for when we ask for the popup from the user.
  330. */
  331. function MessagePopup()
  332. {
  333. global $context, $modSettings, $smcFunc, $memberContext, $scripturl, $user_settings, $db_show_debug;
  334. // We do not want to output debug information here.
  335. $db_show_debug = false;
  336. // We only want to output our little layer here.
  337. $context['template_layers'] = array();
  338. $context['sub_template'] = 'pm_popup';
  339. $context['can_send_pm'] = allowedTo('pm_send');
  340. $context['can_draft'] = allowedTo('pm_draft') && !empty($modSettings['drafts_pm_enabled']);
  341. // So are we loading stuff?
  342. $request = $smcFunc['db_query']('', '
  343. SELECT id_pm
  344. FROM {db_prefix}pm_recipients AS pmr
  345. WHERE pmr.id_member = {int:current_member}
  346. AND is_read = {int:not_read}
  347. ORDER BY id_pm',
  348. array(
  349. 'current_member' => $context['user']['id'],
  350. 'not_read' => 0,
  351. )
  352. );
  353. $pms = array();
  354. while ($row = $smcFunc['db_fetch_row']($request))
  355. $pms[] = $row[0];
  356. $smcFunc['db_free_result']($request);
  357. if (!empty($pms))
  358. {
  359. // Just quickly, it's possible that the number of PMs can get out of sync.
  360. $count_unread = count($pms);
  361. if ($count_unread != $user_settings['unread_messages'])
  362. {
  363. updateMemberData($context['user']['id'], array('unread_messages' => $count_unread));
  364. $context['user']['unread_messages'] = count($pms);
  365. }
  366. // Now, actually fetch me some PMs. Make sure we track the senders, got some work to do for them.
  367. $senders = array();
  368. $request = $smcFunc['db_query']('', '
  369. SELECT pm.id_pm, pm.id_pm_head, IFNULL(mem.id_member, pm.id_member_from) AS id_member_from,
  370. IFNULL(mem.real_name, pm.from_name) AS member_from, pm.msgtime AS timestamp, pm.subject
  371. FROM {db_prefix}personal_messages AS pm
  372. LEFT JOIN {db_prefix}members AS mem ON (pm.id_member_from = mem.id_member)
  373. WHERE pm.id_pm IN ({array_int:id_pms})',
  374. array(
  375. 'id_pms' => $pms,
  376. )
  377. );
  378. while ($row = $smcFunc['db_fetch_assoc']($request))
  379. {
  380. if (!empty($row['id_member_from']))
  381. $senders[] = $row['id_member_from'];
  382. $row['replied_to_you'] = $row['id_pm'] != $row['id_pm_head'];
  383. $row['time'] = timeformat($row['timestamp']);
  384. $row['pm_link'] = '<a href="' . $scripturl . '?action=pm;f=inbox;pmsg=' . $row['id_pm'] . '">' . $row['subject'] . '</a>';
  385. $context['unread_pms'][$row['id_pm']] = $row;
  386. }
  387. $smcFunc['db_free_result']($request);
  388. if (!empty($senders))
  389. {
  390. $senders = loadMemberData($senders);
  391. foreach ($senders as $member)
  392. loadMemberContext($member);
  393. }
  394. // Having loaded everyone, attach them to the PMs.
  395. foreach ($context['unread_pms'] as $id_pm => $details)
  396. if (!empty($memberContext[$details['id_member_from']]))
  397. $context['unread_pms'][$id_pm]['member'] = &$memberContext[$details['id_member_from']];
  398. }
  399. }
  400. /**
  401. * A folder, ie. inbox/sent etc.
  402. */
  403. function MessageFolder()
  404. {
  405. global $txt, $scripturl, $modSettings, $context, $subjects_request;
  406. global $messages_request, $user_info, $recipients, $options, $smcFunc, $memberContext, $user_settings;
  407. // Changing view?
  408. if (isset($_GET['view']))
  409. {
  410. $context['display_mode'] = $context['display_mode'] > 1 ? 0 : $context['display_mode'] + 1;
  411. updateMemberData($user_info['id'], array('pm_prefs' => ($user_settings['pm_prefs'] & 252) | $context['display_mode']));
  412. }
  413. // Make sure the starting location is valid.
  414. if (isset($_GET['start']) && $_GET['start'] != 'new')
  415. $_GET['start'] = (int) $_GET['start'];
  416. elseif (!isset($_GET['start']) && !empty($options['view_newest_pm_first']))
  417. $_GET['start'] = 0;
  418. else
  419. $_GET['start'] = 'new';
  420. // Set up some basic theme stuff.
  421. $context['from_or_to'] = $context['folder'] != 'sent' ? 'from' : 'to';
  422. $context['get_pmessage'] = 'prepareMessageContext';
  423. $context['signature_enabled'] = substr($modSettings['signature_settings'], 0, 1) == 1;
  424. $context['disabled_fields'] = isset($modSettings['disabled_profile_fields']) ? array_flip(explode(',', $modSettings['disabled_profile_fields'])) : array();
  425. $labelJoin = '';
  426. $labelQuery = '';
  427. $labelQuery2 = '';
  428. // SMF logic: If you're viewing a label, it's still the inbox
  429. if ($context['folder'] == 'inbox' && $context['current_label_id'] == -1)
  430. {
  431. $labelQuery = '
  432. AND pmr.in_inbox = 1';
  433. }
  434. elseif ($context['folder'] != 'sent')
  435. {
  436. $labelJoin = '
  437. INNER JOIN {db_prefix}pm_labeled_messages AS pl ON (pl.id_pm = pmr.id_pm)';
  438. $labelQuery2 = '
  439. AND pl.id_label = ' . $context['current_label_id'];
  440. }
  441. // Set the index bar correct!
  442. messageIndexBar($context['current_label_id'] == -1 ? $context['folder'] : 'label' . $context['current_label_id']);
  443. // Sorting the folder.
  444. $sort_methods = array(
  445. 'date' => 'pm.id_pm',
  446. 'name' => 'IFNULL(mem.real_name, \'\')',
  447. 'subject' => 'pm.subject',
  448. );
  449. // They didn't pick one, use the forum default.
  450. if (!isset($_GET['sort']) || !isset($sort_methods[$_GET['sort']]))
  451. {
  452. $context['sort_by'] = 'date';
  453. $_GET['sort'] = 'pm.id_pm';
  454. // An overriding setting?
  455. $descending = !empty($options['view_newest_pm_first']);
  456. }
  457. // Otherwise use the defaults: ascending, by date.
  458. else
  459. {
  460. $context['sort_by'] = $_GET['sort'];
  461. $_GET['sort'] = $sort_methods[$_GET['sort']];
  462. $descending = isset($_GET['desc']);
  463. }
  464. $context['sort_direction'] = $descending ? 'down' : 'up';
  465. // Set the text to resemble the current folder.
  466. $pmbox = $context['folder'] != 'sent' ? $txt['inbox'] : $txt['sent_items'];
  467. $txt['delete_all'] = str_replace('PMBOX', $pmbox, $txt['delete_all']);
  468. // Now, build the link tree!
  469. if ($context['current_label_id'] == -1)
  470. $context['linktree'][] = array(
  471. 'url' => $scripturl . '?action=pm;f=' . $context['folder'],
  472. 'name' => $pmbox
  473. );
  474. // Build it further for a label.
  475. if ($context['current_label_id'] != -1)
  476. $context['linktree'][] = array(
  477. 'url' => $scripturl . '?action=pm;f=' . $context['folder'] . ';l=' . $context['current_label_id'],
  478. 'name' => $txt['pm_current_label'] . ': ' . $context['current_label']
  479. );
  480. // Figure out how many messages there are.
  481. if ($context['folder'] == 'sent')
  482. $request = $smcFunc['db_query']('', '
  483. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  484. FROM {db_prefix}personal_messages AS pm
  485. WHERE pm.id_member_from = {int:current_member}
  486. AND pm.deleted_by_sender = {int:not_deleted}',
  487. array(
  488. 'current_member' => $user_info['id'],
  489. 'not_deleted' => 0,
  490. )
  491. );
  492. else
  493. $request = $smcFunc['db_query']('', '
  494. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  495. FROM {db_prefix}pm_recipients AS pmr' . ($context['display_mode'] == 2 ? '
  496. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)' : '') . $labelJoin . '
  497. WHERE pmr.id_member = {int:current_member}
  498. AND pmr.deleted = {int:not_deleted}' . $labelQuery . $labelQuery2,
  499. array(
  500. 'current_member' => $user_info['id'],
  501. 'not_deleted' => 0,
  502. )
  503. );
  504. list ($max_messages) = $smcFunc['db_fetch_row']($request);
  505. $smcFunc['db_free_result']($request);
  506. // Only show the button if there are messages to delete.
  507. $context['show_delete'] = $max_messages > 0;
  508. // Start on the last page.
  509. if (!is_numeric($_GET['start']) || $_GET['start'] >= $max_messages)
  510. $_GET['start'] = ($max_messages - 1) - (($max_messages - 1) % $modSettings['defaultMaxMessages']);
  511. elseif ($_GET['start'] < 0)
  512. $_GET['start'] = 0;
  513. // ... but wait - what if we want to start from a specific message?
  514. if (isset($_GET['pmid']))
  515. {
  516. $pmID = (int) $_GET['pmid'];
  517. // Make sure you have access to this PM.
  518. if (!isAccessiblePM($pmID, $context['folder'] == 'sent' ? 'outbox' : 'inbox'))
  519. fatal_lang_error('no_access', false);
  520. $context['current_pm'] = $pmID;
  521. // With only one page of PM's we're gonna want page 1.
  522. if ($max_messages <= $modSettings['defaultMaxMessages'])
  523. $_GET['start'] = 0;
  524. // If we pass kstart we assume we're in the right place.
  525. elseif (!isset($_GET['kstart']))
  526. {
  527. if ($context['folder'] == 'sent')
  528. $request = $smcFunc['db_query']('', '
  529. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  530. FROM {db_prefix}personal_messages
  531. WHERE id_member_from = {int:current_member}
  532. AND deleted_by_sender = {int:not_deleted}
  533. AND id_pm ' . ($descending ? '>' : '<') . ' {int:id_pm}',
  534. array(
  535. 'current_member' => $user_info['id'],
  536. 'not_deleted' => 0,
  537. 'id_pm' => $pmID,
  538. )
  539. );
  540. else
  541. $request = $smcFunc['db_query']('', '
  542. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  543. FROM {db_prefix}pm_recipients AS pmr' . ($context['display_mode'] == 2 ? '
  544. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)' : '') . $labelJoin . '
  545. WHERE pmr.id_member = {int:current_member}
  546. AND pmr.deleted = {int:not_deleted}' . $labelQuery . $labelQuery2 . '
  547. AND pmr.id_pm ' . ($descending ? '>' : '<') . ' {int:id_pm}',
  548. array(
  549. 'current_member' => $user_info['id'],
  550. 'not_deleted' => 0,
  551. 'id_pm' => $pmID,
  552. )
  553. );
  554. list ($_GET['start']) = $smcFunc['db_fetch_row']($request);
  555. $smcFunc['db_free_result']($request);
  556. // To stop the page index's being abnormal, start the page on the page the message would normally be located on...
  557. $_GET['start'] = $modSettings['defaultMaxMessages'] * (int) ($_GET['start'] / $modSettings['defaultMaxMessages']);
  558. }
  559. }
  560. // Sanitize and validate pmsg variable if set.
  561. if (isset($_GET['pmsg']))
  562. {
  563. $pmsg = (int) $_GET['pmsg'];
  564. if (!isAccessiblePM($pmsg, $context['folder'] == 'sent' ? 'outbox' : 'inbox'))
  565. fatal_lang_error('no_access', false);
  566. }
  567. // Set up the page index.
  568. $context['page_index'] = constructPageIndex($scripturl . '?action=pm;f=' . $context['folder'] . (isset($_REQUEST['l']) ? ';l=' . (int) $_REQUEST['l'] : '') . ';sort=' . $context['sort_by'] . ($descending ? ';desc' : ''), $_GET['start'], $max_messages, $modSettings['defaultMaxMessages']);
  569. $context['start'] = $_GET['start'];
  570. // Determine the navigation context (especially useful for the wireless template).
  571. $context['links'] = array(
  572. 'first' => $_GET['start'] >= $modSettings['defaultMaxMessages'] ? $scripturl . '?action=pm;start=0' : '',
  573. 'prev' => $_GET['start'] >= $modSettings['defaultMaxMessages'] ? $scripturl . '?action=pm;start=' . ($_GET['start'] - $modSettings['defaultMaxMessages']) : '',
  574. 'next' => $_GET['start'] + $modSettings['defaultMaxMessages'] < $max_messages ? $scripturl . '?action=pm;start=' . ($_GET['start'] + $modSettings['defaultMaxMessages']) : '',
  575. 'last' => $_GET['start'] + $modSettings['defaultMaxMessages'] < $max_messages ? $scripturl . '?action=pm;start=' . (floor(($max_messages - 1) / $modSettings['defaultMaxMessages']) * $modSettings['defaultMaxMessages']) : '',
  576. 'up' => $scripturl,
  577. );
  578. $context['page_info'] = array(
  579. 'current_page' => $_GET['start'] / $modSettings['defaultMaxMessages'] + 1,
  580. 'num_pages' => floor(($max_messages - 1) / $modSettings['defaultMaxMessages']) + 1
  581. );
  582. // First work out what messages we need to see - if grouped is a little trickier...
  583. if ($context['display_mode'] == 2)
  584. {
  585. if ($context['folder'] != 'sent' && $context['folder'] != 'inbox')
  586. {
  587. $labelJoin = '
  588. INNER JOIN {db_prefix}pm_labeled_messages AS pl ON (pl.id_pm = pm.id_pm)';
  589. $labelQuery = '';
  590. $labelQuery2 = '
  591. AND pl.id_label = ' . $context['current_label_id'];
  592. }
  593. // On a non-default sort due to PostgreSQL we have to do a harder sort.
  594. if ($smcFunc['db_title'] == 'PostgreSQL' && $_GET['sort'] != 'pm.id_pm')
  595. {
  596. $sub_request = $smcFunc['db_query']('', '
  597. SELECT MAX({raw:sort}) AS sort_param, pm.id_pm_head
  598. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? ($context['sort_by'] == 'name' ? '
  599. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  600. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  601. AND pmr.id_member = {int:current_member}
  602. AND pmr.deleted = {int:not_deleted}
  603. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  604. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:id_member})') : '') . '
  605. WHERE ' . ($context['folder'] == 'sent' ? 'pm.id_member_from = {int:current_member}
  606. AND pm.deleted_by_sender = {int:not_deleted}' : '1=1') . (empty($pmsg) ? '' : '
  607. AND pm.id_pm = {int:id_pm}') . $labelQuery2 . '
  608. GROUP BY pm.id_pm_head
  609. ORDER BY sort_param' . ($descending ? ' DESC' : ' ASC') . (empty($pmsg) ? '
  610. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  611. array(
  612. 'current_member' => $user_info['id'],
  613. 'not_deleted' => 0,
  614. 'id_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  615. 'id_pm' => isset($pmsg) ? $pmsg : '0',
  616. 'sort' => $_GET['sort'],
  617. )
  618. );
  619. $sub_pms = array();
  620. while ($row = $smcFunc['db_fetch_assoc']($sub_request))
  621. $sub_pms[$row['id_pm_head']] = $row['sort_param'];
  622. $smcFunc['db_free_result']($sub_request);
  623. $request = $smcFunc['db_query']('', '
  624. SELECT pm.id_pm AS id_pm, pm.id_pm_head
  625. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? ($context['sort_by'] == 'name' ? '
  626. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  627. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  628. AND pmr.id_member = {int:current_member}
  629. AND pmr.deleted = {int:not_deleted}
  630. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  631. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:id_member})') : '') . '
  632. WHERE ' . (empty($sub_pms) ? '0=1' : 'pm.id_pm IN ({array_int:pm_list})') . $labelQuery2 . '
  633. ORDER BY ' . ($_GET['sort'] == 'pm.id_pm' && $context['folder'] != 'sent' ? 'id_pm' : '{raw:sort}') . ($descending ? ' DESC' : ' ASC') . (empty($pmsg) ? '
  634. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  635. array(
  636. 'current_member' => $user_info['id'],
  637. 'pm_list' => array_keys($sub_pms),
  638. 'not_deleted' => 0,
  639. 'sort' => $_GET['sort'],
  640. 'id_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  641. )
  642. );
  643. }
  644. else
  645. {
  646. $request = $smcFunc['db_query']('pm_conversation_list', '
  647. SELECT MAX(pm.id_pm) AS id_pm, pm.id_pm_head
  648. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? ($context['sort_by'] == 'name' ? '
  649. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  650. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  651. AND pmr.id_member = {int:current_member}
  652. AND pmr.deleted = {int:deleted_by}
  653. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  654. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:pm_member})') : '') . '
  655. WHERE ' . ($context['folder'] == 'sent' ? 'pm.id_member_from = {int:current_member}
  656. AND pm.deleted_by_sender = {int:deleted_by}' : '1=1') . (empty($pmsg) ? '' : '
  657. AND pm.id_pm = {int:pmsg}') . $labelQuery2 . '
  658. GROUP BY pm.id_pm_head
  659. ORDER BY ' . ($_GET['sort'] == 'pm.id_pm' && $context['folder'] != 'sent' ? 'id_pm' : '{raw:sort}') . ($descending ? ' DESC' : ' ASC') . (empty($_GET['pmsg']) ? '
  660. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  661. array(
  662. 'current_member' => $user_info['id'],
  663. 'deleted_by' => 0,
  664. 'sort' => $_GET['sort'],
  665. 'pm_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  666. 'pmsg' => isset($pmsg) ? (int) $pmsg : 0,
  667. )
  668. );
  669. }
  670. }
  671. // This is kinda simple!
  672. else
  673. {
  674. // @todo SLOW This query uses a filesort. (inbox only.)
  675. $request = $smcFunc['db_query']('', '
  676. SELECT pm.id_pm, pm.id_pm_head, pm.id_member_from
  677. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? '' . ($context['sort_by'] == 'name' ? '
  678. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  679. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  680. AND pmr.id_member = {int:current_member}
  681. AND pmr.deleted = {int:is_deleted}
  682. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  683. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:pm_member})') : '') . '
  684. WHERE ' . ($context['folder'] == 'sent' ? 'pm.id_member_from = {raw:current_member}
  685. AND pm.deleted_by_sender = {int:is_deleted}' : '1=1') . (empty($pmsg) ? '' : '
  686. AND pm.id_pm = {int:pmsg}') . $labelQuery2 . '
  687. ORDER BY ' . ($_GET['sort'] == 'pm.id_pm' && $context['folder'] != 'sent' ? 'pmr.id_pm' : '{raw:sort}') . ($descending ? ' DESC' : ' ASC') . (empty($pmsg) ? '
  688. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  689. array(
  690. 'current_member' => $user_info['id'],
  691. 'is_deleted' => 0,
  692. 'sort' => $_GET['sort'],
  693. 'pm_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  694. 'pmsg' => isset($pmsg) ? (int) $pmsg : 0,
  695. )
  696. );
  697. }
  698. // Load the id_pms and initialize recipients.
  699. $pms = array();
  700. $lastData = array();
  701. $posters = $context['folder'] == 'sent' ? array($user_info['id']) : array();
  702. $recipients = array();
  703. while ($row = $smcFunc['db_fetch_assoc']($request))
  704. {
  705. if (!isset($recipients[$row['id_pm']]))
  706. {
  707. if (isset($row['id_member_from']))
  708. $posters[$row['id_pm']] = $row['id_member_from'];
  709. $pms[$row['id_pm']] = $row['id_pm'];
  710. $recipients[$row['id_pm']] = array(
  711. 'to' => array(),
  712. 'bcc' => array()
  713. );
  714. }
  715. // Keep track of the last message so we know what the head is without another query!
  716. if ((empty($pmID) && (empty($options['view_newest_pm_first']) || !isset($lastData))) || empty($lastData) || (!empty($pmID) && $pmID == $row['id_pm']))
  717. $lastData = array(
  718. 'id' => $row['id_pm'],
  719. 'head' => $row['id_pm_head'],
  720. );
  721. }
  722. $smcFunc['db_free_result']($request);
  723. // Make sure that we have been given a correct head pm id!
  724. if ($context['display_mode'] == 2 && !empty($pmID) && $pmID != $lastData['id'])
  725. fatal_lang_error('no_access', false);
  726. if (!empty($pms))
  727. {
  728. // Select the correct current message.
  729. if (empty($pmID))
  730. $context['current_pm'] = $lastData['id'];
  731. // This is a list of the pm's that are used for "full" display.
  732. if ($context['display_mode'] == 0)
  733. $display_pms = $pms;
  734. else
  735. $display_pms = array($context['current_pm']);
  736. // At this point we know the main id_pm's. But - if we are looking at conversations we need the others!
  737. if ($context['display_mode'] == 2)
  738. {
  739. $request = $smcFunc['db_query']('', '
  740. SELECT pm.id_pm, pm.id_member_from, pm.deleted_by_sender, pmr.id_member, pmr.deleted
  741. FROM {db_prefix}personal_messages AS pm
  742. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)
  743. WHERE pm.id_pm_head = {int:id_pm_head}
  744. AND ((pm.id_member_from = {int:current_member} AND pm.deleted_by_sender = {int:not_deleted})
  745. OR (pmr.id_member = {int:current_member} AND pmr.deleted = {int:not_deleted}))
  746. ORDER BY pm.id_pm',
  747. array(
  748. 'current_member' => $user_info['id'],
  749. 'id_pm_head' => $lastData['head'],
  750. 'not_deleted' => 0,
  751. )
  752. );
  753. while ($row = $smcFunc['db_fetch_assoc']($request))
  754. {
  755. // This is, frankly, a joke. We will put in a workaround for people sending to themselves - yawn!
  756. if ($context['folder'] == 'sent' && $row['id_member_from'] == $user_info['id'] && $row['deleted_by_sender'] == 1)
  757. continue;
  758. elseif ($row['id_member'] == $user_info['id'] & $row['deleted'] == 1)
  759. continue;
  760. if (!isset($recipients[$row['id_pm']]))
  761. $recipients[$row['id_pm']] = array(
  762. 'to' => array(),
  763. 'bcc' => array()
  764. );
  765. $display_pms[] = $row['id_pm'];
  766. $posters[$row['id_pm']] = $row['id_member_from'];
  767. }
  768. $smcFunc['db_free_result']($request);
  769. }
  770. // This is pretty much EVERY pm!
  771. $all_pms = array_merge($pms, $display_pms);
  772. $all_pms = array_unique($all_pms);
  773. // Get recipients (don't include bcc-recipients for your inbox, you're not supposed to know :P).
  774. $request = $smcFunc['db_query']('', '
  775. SELECT pmr.id_pm, mem_to.id_member AS id_member_to, mem_to.real_name AS to_name, pmr.bcc, pmr.in_inbox, pmr.is_read
  776. FROM {db_prefix}pm_recipients AS pmr
  777. LEFT JOIN {db_prefix}members AS mem_to ON (mem_to.id_member = pmr.id_member)
  778. WHERE pmr.id_pm IN ({array_int:pm_list})',
  779. array(
  780. 'pm_list' => $all_pms,
  781. )
  782. );
  783. $context['message_labels'] = array();
  784. $context['message_replied'] = array();
  785. $context['message_unread'] = array();
  786. while ($row = $smcFunc['db_fetch_assoc']($request))
  787. {
  788. if ($context['folder'] == 'sent' || empty($row['bcc']))
  789. $recipients[$row['id_pm']][empty($row['bcc']) ? 'to' : 'bcc'][] = empty($row['id_member_to']) ? $txt['guest_title'] : '<a href="' . $scripturl . '?action=profile;u=' . $row['id_member_to'] . '">' . $row['to_name'] . '</a>';
  790. if ($row['id_member_to'] == $user_info['id'] && $context['folder'] != 'sent')
  791. {
  792. $context['message_replied'][$row['id_pm']] = $row['is_read'] & 2;
  793. $context['message_unread'][$row['id_pm']] = $row['is_read'] == 0;
  794. // Get the labels for this PM
  795. $request2 = $smcFunc['db_query']('', '
  796. SELECT id_label
  797. FROM {db_prefix}pm_labeled_messages
  798. WHERE id_pm = {int:current_pm}',
  799. array(
  800. 'current_pm' => $row['id_pm'],
  801. )
  802. );
  803. while($row2 = $smcFunc['db_fetch_assoc']($request2))
  804. {
  805. $l_id = $row2['id_label'];
  806. if (isset($context['labels'][$l_id]))
  807. $context['message_labels'][$row['id_pm']][$l_id] = array('id' => $l_id, 'name' => $context['labels'][$l_id]['name']);
  808. }
  809. $smcFunc['db_free_result']($request2);
  810. // Is this in the inbox as well?
  811. if ($row['in_inbox'] == 1)
  812. {
  813. $context['message_labels'][$row['id_pm']][-1] = array('id' => -1, 'name' => $context['labels'][-1]['name']);
  814. }
  815. }
  816. }
  817. $smcFunc['db_free_result']($request);
  818. // Make sure we don't load unnecessary data.
  819. if ($context['display_mode'] == 1)
  820. {
  821. foreach ($posters as $k => $v)
  822. if (!in_array($k, $display_pms))
  823. unset($posters[$k]);
  824. }
  825. // Load any users....
  826. $posters = array_unique($posters);
  827. if (!empty($posters))
  828. loadMemberData($posters);
  829. // If we're on grouped/restricted view get a restricted list of messages.
  830. if ($context['display_mode'] != 0)
  831. {
  832. // Get the order right.
  833. $orderBy = array();
  834. foreach (array_reverse($pms) as $pm)
  835. $orderBy[] = 'pm.id_pm = ' . $pm;
  836. // Seperate query for these bits!
  837. $subjects_request = $smcFunc['db_query']('', '
  838. SELECT pm.id_pm, pm.subject, IFNULL(pm.id_member_from, 0) AS id_member_from, pm.msgtime, IFNULL(mem.real_name, pm.from_name) AS from_name,
  839. mem.id_member
  840. FROM {db_prefix}personal_messages AS pm
  841. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  842. WHERE pm.id_pm IN ({array_int:pm_list})
  843. ORDER BY ' . implode(', ', $orderBy) . '
  844. LIMIT ' . count($pms),
  845. array(
  846. 'pm_list' => $pms,
  847. )
  848. );
  849. }
  850. // Execute the query!
  851. $messages_request = $smcFunc['db_query']('', '
  852. SELECT pm.id_pm, pm.subject, pm.id_member_from, pm.body, pm.msgtime, pm.from_name
  853. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? '
  854. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') . ($context['sort_by'] == 'name' ? '
  855. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:id_member})' : '') . '
  856. WHERE pm.id_pm IN ({array_int:display_pms})' . ($context['folder'] == 'sent' ? '
  857. GROUP BY pm.id_pm, pm.subject, pm.id_member_from, pm.body, pm.msgtime, pm.from_name' : '') . '
  858. ORDER BY ' . ($context['display_mode'] == 2 ? 'pm.id_pm' : $_GET['sort']) . ($descending ? ' DESC' : ' ASC') . '
  859. LIMIT ' . count($display_pms),
  860. array(
  861. 'display_pms' => $display_pms,
  862. 'id_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  863. )
  864. );
  865. // Build the conversation button array.
  866. if ($context['display_mode'] == 2)
  867. {
  868. $context['conversation_buttons'] = array(
  869. 'delete' => array('text' => 'delete_conversation', 'image' => 'delete.png', 'lang' => true, 'url' => $scripturl . '?action=pm;sa=pmactions;pm_actions[' . $context['current_pm'] . ']=delete;conversation;f=' . $context['folder'] . ';start=' . $context['start'] . ($context['current_label_id'] != -1 ? ';l=' . $context['current_label_id'] : '') . ';' . $context['session_var'] . '=' . $context['session_id'], 'custom' => 'onclick="return confirm(\'' . addslashes($txt['remove_conversation']) . '?\');"'),
  870. );
  871. // Allow mods to add additional buttons here
  872. call_integration_hook('integrate_conversation_buttons');
  873. }
  874. }
  875. else
  876. $messages_request = false;
  877. $context['can_send_pm'] = allowedTo('pm_send');
  878. $context['can_send_email'] = allowedTo('send_email_to_members');
  879. if (!WIRELESS)
  880. $context['sub_template'] = 'folder';
  881. $context['page_title'] = $txt['pm_inbox'];
  882. // Finally mark the relevant messages as read.
  883. if ($context['folder'] != 'sent' && !empty($context['labels'][(int) $context['current_label_id']]['unread_messages']))
  884. {
  885. // If the display mode is "old sk00l" do them all...
  886. if ($context['display_mode'] == 0)
  887. markMessages(null, $context['current_label_id']);
  888. // Otherwise do just the current one!
  889. elseif (!empty($context['current_pm']))
  890. markMessages($display_pms, $context['current_label_id']);
  891. }
  892. }
  893. /**
  894. * Get a personal message for the theme. (used to save memory.)
  895. *
  896. * @param $type
  897. * @param $reset
  898. */
  899. function prepareMessageContext($type = 'subject', $reset = false)
  900. {
  901. global $txt, $scripturl, $modSettings, $settings, $context, $messages_request, $memberContext, $recipients, $smcFunc;
  902. global $user_info, $subjects_request;
  903. // Count the current message number....
  904. static $counter = null;
  905. if ($counter === null || $reset)
  906. $counter = $context['start'];
  907. static $temp_pm_selected = null;
  908. if ($temp_pm_selected === null)
  909. {
  910. $temp_pm_selected = isset($_SESSION['pm_selected']) ? $_SESSION['pm_selected'] : array();
  911. $_SESSION['pm_selected'] = array();
  912. }
  913. // If we're in non-boring view do something exciting!
  914. if ($context['display_mode'] != 0 && $subjects_request && $type == 'subject')
  915. {
  916. $subject = $smcFunc['db_fetch_assoc']($subjects_request);
  917. if (!$subject)
  918. {
  919. $smcFunc['db_free_result']($subjects_request);
  920. return false;
  921. }
  922. $subject['subject'] = $subject['subject'] == '' ? $txt['no_subject'] : $subject['subject'];
  923. censorText($subject['subject']);
  924. $output = array(
  925. 'id' => $subject['id_pm'],
  926. 'member' => array(
  927. 'id' => $subject['id_member_from'],
  928. 'name' => $subject['from_name'],
  929. 'link' => ($subject['id_member_from'] != 0) ? '<a href="' . $scripturl . '?action=profile;u=' . $subject['id_member_from'] . '">' . $subject['from_name'] . '</a>' : $subject['from_name'],
  930. ),
  931. 'recipients' => &$recipients[$subject['id_pm']],
  932. 'subject' => $subject['subject'],
  933. 'time' => timeformat($subject['msgtime']),
  934. 'timestamp' => forum_time(true, $subject['msgtime']),
  935. 'number_recipients' => count($recipients[$subject['id_pm']]['to']),
  936. 'labels' => &$context['message_labels'][$subject['id_pm']],
  937. 'fully_labeled' => count($context['message_labels'][$subject['id_pm']]) == count($context['labels']),
  938. 'is_replied_to' => &$context['message_replied'][$subject['id_pm']],
  939. 'is_unread' => &$context['message_unread'][$subject['id_pm']],
  940. 'is_selected' => !empty($temp_pm_selected) && in_array($subject['id_pm'], $temp_pm_selected),
  941. );
  942. return $output;
  943. }
  944. // Bail if it's false, ie. no messages.
  945. if ($messages_request == false)
  946. return false;
  947. // Reset the data?
  948. if ($reset == true)
  949. return @$smcFunc['db_data_seek']($messages_request, 0);
  950. // Get the next one... bail if anything goes wrong.
  951. $message = $smcFunc['db_fetch_assoc']($messages_request);
  952. if (!$message)
  953. {
  954. if ($type != 'subject')
  955. $smcFunc['db_free_result']($messages_request);
  956. return false;
  957. }
  958. // Use '(no subject)' if none was specified.
  959. $message['subject'] = $message['subject'] == '' ? $txt['no_subject'] : $message['subject'];
  960. // Load the message's information - if it's not there, load the guest information.
  961. if (!loadMemberContext($message['id_member_from'], true))
  962. {
  963. $memberContext[$message['id_member_from']]['name'] = $message['from_name'];
  964. $memberContext[$message['id_member_from']]['id'] = 0;
  965. // Sometimes the forum sends messages itself (Warnings are an example) - in this case don't label it from a guest.
  966. $memberContext[$message['id_member_from']]['group'] = $message['from_name'] == $context['forum_name'] ? '' : $txt['guest_title'];
  967. $memberContext[$message['id_member_from']]['link'] = $message['from_name'];
  968. $memberContext[$message['id_member_from']]['email'] = '';
  969. $memberContext[$message['id_member_from']]['show_email'] = showEmailAddress(true, 0);
  970. $memberContext[$message['id_member_from']]['is_guest'] = true;
  971. }
  972. else
  973. {
  974. $memberContext[$message['id_member_from']]['can_view_profile'] = allowedTo('profile_view') || ($message['id_member_from'] == $user_info['id'] && !$user_info['is_guest']);
  975. $memberContext[$message['id_member_from']]['can_see_warning'] = !isset($context['disabled_fields']['warning_status']) && $memberContext[$message['id_member_from']]['warning_status'] && ($context['user']['can_mod'] || (!empty($modSettings['warning_show']) && ($modSettings['warning_show'] > 1 || $message['id_member_from'] == $user_info['id'])));
  976. }
  977. $memberContext[$message['id_member_from']]['show_profile_buttons'] = $settings['show_profile_buttons'] && (!empty($memberContext[$message['id_member_from']]['can_view_profile']) || (!empty($memberContext[$message['id_member_from']]['website']['url']) && !isset($context['disabled_fields']['website'])) || (in_array($memberContext[$message['id_member_from']]['show_email'], array('yes', 'yes_permission_override', 'no_through_forum'))) || $context['can_send_pm']);
  978. // Censor all the important text...
  979. censorText($message['body']);
  980. censorText($message['subject']);
  981. // Run UBBC interpreter on the message.
  982. $message['body'] = parse_bbc($message['body'], true, 'pm' . $message['id_pm']);
  983. // Send the array.
  984. $output = array(
  985. 'alternate' => $counter % 2,
  986. 'id' => $message['id_pm'],
  987. 'member' => &$memberContext[$message['id_member_from']],
  988. 'subject' => $message['subject'],
  989. 'time' => timeformat($message['msgtime']),
  990. 'timestamp' => forum_time(true, $message['msgtime']),
  991. 'counter' => $counter,
  992. 'body' => $message['body'],
  993. 'recipients' => &$recipients[$message['id_pm']],
  994. 'number_recipients' => count($recipients[$message['id_pm']]['to']),
  995. 'labels' => &$context['message_labels'][$message['id_pm']],
  996. 'fully_labeled' => count($context['message_labels'][$message['id_pm']]) == count($context['labels']),
  997. 'is_replied_to' => &$context['message_replied'][$message['id_pm']],
  998. 'is_unread' => &$context['message_unread'][$message['id_pm']],
  999. 'is_selected' => !empty($temp_pm_selected) && in_array($message['id_pm'], $temp_pm_selected),
  1000. 'is_message_author' => $message['id_member_from'] == $user_info['id'],
  1001. 'can_report' => !empty($modSettings['enableReportPM']),
  1002. 'can_see_ip' => allowedTo('moderate_forum') || ($message['id_member_from'] == $user_info['id'] && !empty($user_info['id'])),
  1003. );
  1004. $counter++;
  1005. return $output;
  1006. }
  1007. /**
  1008. * Allows to search through personal messages.
  1009. */
  1010. function MessageSearch()
  1011. {
  1012. global $context, $txt, $scripturl, $modSettings, $smcFunc;
  1013. if (isset($_REQUEST['params']))
  1014. {
  1015. $temp_params = explode('|"|', base64_decode(strtr($_REQUEST['params'], array(' ' => '+'))));
  1016. $context['search_params'] = array();
  1017. foreach ($temp_params as $i => $data)
  1018. {
  1019. @list ($k, $v) = explode('|\'|', $data);
  1020. $context['search_params'][$k] = $v;
  1021. }
  1022. }
  1023. if (isset($_REQUEST['search']))
  1024. $context['search_params']['search'] = un_htmlspecialchars($_REQUEST['search']);
  1025. if (isset($context['search_params']['search']))
  1026. $context['search_params']['search'] = $smcFunc['htmlspecialchars']($context['search_params']['search']);
  1027. if (isset($context['search_params']['userspec']))
  1028. $context['search_params']['userspec'] = $smcFunc['htmlspecialchars']($context['search_params']['userspec']);
  1029. if (!empty($context['search_params']['searchtype']))
  1030. $context['search_params']['searchtype'] = 2;
  1031. if (!empty($context['search_params']['minage']))
  1032. $context['search_params']['minage'] = (int) $context['search_params']['minage'];
  1033. if (!empty($context['search_params']['maxage']))
  1034. $context['search_params']['maxage'] = (int) $context['search_params']['maxage'];
  1035. $context['search_params']['subject_only'] = !empty($context['search_params']['subject_only']);
  1036. $context['search_params']['show_complete'] = !empty($context['search_params']['show_complete']);
  1037. // Create the array of labels to be searched.
  1038. $context['search_labels'] = array();
  1039. $searchedLabels = isset($context['search_params']['labels']) && $context['search_params']['labels'] != '' ? explode(',', $context['search_params']['labels']) : array();
  1040. foreach ($context['labels'] as $label)
  1041. {
  1042. $context['search_labels'][] = array(
  1043. 'id' => $label['id'],
  1044. 'name' => $label['name'],
  1045. 'checked' => !empty($searchedLabels) ? in_array($label['id'], $searchedLabels) : true,
  1046. );
  1047. }
  1048. // Are all the labels checked?
  1049. $context['check_all'] = empty($searchedLabels) || count($context['search_labels']) == count($searchedLabels);
  1050. // Load the error text strings if there were errors in the search.
  1051. if (!empty($context['search_errors']))
  1052. {
  1053. loadLanguage('Errors');
  1054. $context['search_errors']['messages'] = array();
  1055. foreach ($context['search_errors'] as $search_error => $dummy)
  1056. {
  1057. if ($search_error == 'messages')
  1058. continue;
  1059. $context['search_errors']['messages'][] = $txt['error_' . $search_error];
  1060. }
  1061. }
  1062. $context['page_title'] = $txt['pm_search_title'];
  1063. $context['sub_template'] = 'search';
  1064. $context['linktree'][] = array(
  1065. 'url' => $scripturl . '?action=pm;sa=search',
  1066. 'name' => $txt['pm_search_bar_title'],
  1067. );
  1068. }
  1069. /**
  1070. * Actually do the search of personal messages.
  1071. */
  1072. function MessageSearch2()
  1073. {
  1074. global $scripturl, $modSettings, $user_info, $context, $txt;
  1075. global $memberContext, $smcFunc;
  1076. if (!empty($context['load_average']) && !empty($modSettings['loadavg_search']) && $context['load_average'] >= $modSettings['loadavg_search'])
  1077. fatal_lang_error('loadavg_search_disabled', false);
  1078. /**
  1079. * @todo For the moment force the folder to the inbox.
  1080. * @todo Maybe set the inbox based on a cookie or theme setting?
  1081. */
  1082. $context['folder'] = 'inbox';
  1083. // Some useful general permissions.
  1084. $context['can_send_pm'] = allowedTo('pm_send');
  1085. // Some hardcoded veriables that can be tweaked if required.
  1086. $maxMembersToSearch = 500;
  1087. // Extract all the search parameters.
  1088. $search_params = array();
  1089. if (isset($_REQUEST['params']))
  1090. {
  1091. $temp_params = explode('|"|', base64_decode(strtr($_REQUEST['params'], array(' ' => '+'))));
  1092. foreach ($temp_params as $i => $data)
  1093. {
  1094. @list ($k, $v) = explode('|\'|', $data);
  1095. $search_params[$k] = $v;
  1096. }
  1097. }
  1098. $context['start'] = isset($_GET['start']) ? (int) $_GET['start'] : 0;
  1099. // Store whether simple search was used (needed if the user wants to do another query).
  1100. if (!isset($search_params['advanced']))
  1101. $search_params['advanced'] = empty($_REQUEST['advanced']) ? 0 : 1;
  1102. // 1 => 'allwords' (default, don't set as param) / 2 => 'anywords'.
  1103. if (!empty($search_params['searchtype']) || (!empty($_REQUEST['searchtype']) && $_REQUEST['searchtype'] == 2))
  1104. $search_params['searchtype'] = 2;
  1105. // Minimum age of messages. Default to zero (don't set param in that case).
  1106. if (!empty($search_params['minage']) || (!empty($_REQUEST['minage']) && $_REQUEST['minage'] > 0))
  1107. $search_params['minage'] = !empty($search_params['minage']) ? (int) $search_params['minage'] : (int) $_REQUEST['minage'];
  1108. // Maximum age of messages. Default to infinite (9999 days: param not set).
  1109. if (!empty($search_params['maxage']) || (!empty($_REQUEST['maxage']) && $_REQUEST['maxage'] != 9999))
  1110. $search_params['maxage'] = !empty($search_params['maxage']) ? (int) $search_params['maxage'] : (int) $_REQUEST['maxage'];
  1111. $search_params['subject_only'] = !empty($search_params['subject_only']) || !empty($_REQUEST['subject_only']);
  1112. $search_params['show_complete'] = !empty($search_params['show_complete']) || !empty($_REQUEST['show_complete']);
  1113. // Default the user name to a wildcard matching every user (*).
  1114. if (!empty($search_params['user_spec']) || (!empty($_REQUEST['userspec']) && $_REQUEST['userspec'] != '*'))
  1115. $search_params['userspec'] = isset($search_params['userspec']) ? $search_params['userspec'] : $_REQUEST['userspec'];
  1116. // This will be full of all kinds of parameters!
  1117. $searchq_parameters = array();
  1118. // If there's no specific user, then don't mention it in the main query.
  1119. if (empty($search_params['userspec']))
  1120. $userQuery = '';
  1121. else
  1122. {
  1123. $userString = strtr($smcFunc['htmlspecialchars']($search_params['userspec'], ENT_QUOTES), array('&quot;' => '"'));
  1124. $userString = strtr($userString, array('%' => '\%', '_' => '\_', '*' => '%', '?' => '_'));
  1125. preg_match_all('~"([^"]+)"~', $userString, $matches);
  1126. $possible_users = array_merge($matches[1], explode(',', preg_replace('~"[^"]+"~', '', $userString)));
  1127. for ($k = 0, $n = count($possible_users); $k < $n; $k++)
  1128. {
  1129. $possible_users[$k] = trim($possible_users[$k]);
  1130. if (strlen($possible_users[$k]) == 0)
  1131. unset($possible_users[$k]);
  1132. }
  1133. if (!empty($possible_users))
  1134. {
  1135. // We need to bring this into the query and do it nice and cleanly.
  1136. $where_params = array();
  1137. $where_clause = array();
  1138. foreach ($possible_users as $k => $v)
  1139. {
  1140. $where_params['name_' . $k] = $v;
  1141. $where_clause[] = '{raw:real_name} LIKE {string:name_' . $k . '}';
  1142. if (!isset($where_params['real_name']))
  1143. $where_params['real_name'] = $smcFunc['db_case_sensitive'] ? 'LOWER(real_name)' : 'real_name';
  1144. }
  1145. // Who matches those criteria?
  1146. // @todo This doesn't support sent item searching.
  1147. $request = $smcFunc['db_query']('', '
  1148. SELECT id_member
  1149. FROM {db_prefix}members
  1150. WHERE ' . implode(' OR ', $where_clause),
  1151. $where_params
  1152. );
  1153. // Simply do nothing if there're too many members matching the criteria.
  1154. if ($smcFunc['db_num_rows']($request) > $maxMembersToSearch)
  1155. $userQuery = '';
  1156. elseif ($smcFunc['db_num_rows']($request) == 0)
  1157. {
  1158. $userQuery = 'AND pm.id_member_from = 0 AND ({raw:pm_from_name} LIKE {raw:guest_user_name_implode})';
  1159. $searchq_parameters['guest_user_name_implode'] = '\'' . implode('\' OR ' . ($smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name') . ' LIKE \'', $possible_users) . '\'';
  1160. $searchq_parameters['pm_from_name'] = $smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name';
  1161. }
  1162. else
  1163. {
  1164. $memberlist = array();
  1165. while ($row = $smcFunc['db_fetch_assoc']($request))
  1166. $memberlist[] = $row['id_member'];
  1167. $userQuery = 'AND (pm.id_member_from IN ({array_int:member_list}) OR (pm.id_member_from = 0 AND ({raw:pm_from_name} LIKE {raw:guest_user_name_implode})))';
  1168. $searchq_parameters['guest_user_name_implode'] = '\'' . implode('\' OR ' . ($smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name') . ' LIKE \'', $possible_users) . '\'';
  1169. $searchq_parameters['member_list'] = $memberlist;
  1170. $searchq_parameters['pm_from_name'] = $smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name';
  1171. }
  1172. $smcFunc['db_free_result']($request);
  1173. }
  1174. else
  1175. $userQuery = '';
  1176. }
  1177. // Setup the sorting variables...
  1178. // @todo Add more in here!
  1179. $sort_columns = array(
  1180. 'pm.id_pm',
  1181. );
  1182. if (empty($search_params['sort']) && !empty($_REQUEST['sort']))
  1183. list ($search_params['sort'], $search_params['sort_dir']) = array_pad(explode('|', $_REQUEST['sort']), 2, '');
  1184. $search_params['sort'] = !empty($search_params['sort']) && in_array($search_params['sort'], $sort_columns) ? $search_params['sort'] : 'pm.id_pm';
  1185. $search_params['sort_dir'] = !empty($search_params['sort_dir']) && $search_params['sort_dir'] == 'asc' ? 'asc' : 'desc';
  1186. // Sort out any labels we may be searching by.
  1187. $labelQuery = '';
  1188. $labelJoin = '';
  1189. if ($context['folder'] == 'inbox' && !empty($search_params['advanced']) && $context['currently_using_labels'])
  1190. {
  1191. // Came here from pagination? Put them back into $_REQUEST for sanitization.
  1192. if (isset($search_params['labels']))
  1193. $_REQUEST['searchlabel'] = explode(',', $search_params['labels']);
  1194. // Assuming we have some labels - make them all integers.
  1195. if (!empty($_REQUEST['searchlabel']) && is_array($_REQUEST['searchlabel']))
  1196. {
  1197. foreach ($_REQUEST['searchlabel'] as $key => $id)
  1198. $_REQUEST['searchlabel'][$key] = (int) $id;
  1199. }
  1200. else
  1201. $_REQUEST['searchlabel'] = array();
  1202. // Now that everything is cleaned up a bit, make the labels a param.
  1203. $search_params['labels'] = implode(',', $_REQUEST['searchlabel']);
  1204. // No labels selected? That must be an error!
  1205. if (empty($_REQUEST['searchlabel']))
  1206. $context['search_errors']['no_labels_selected'] = true;
  1207. // Otherwise prepare the query!
  1208. elseif (count($_REQUEST['searchlabel']) != count($context['labels']))
  1209. {
  1210. // Special case here... "inbox" isn't a real label anymore...
  1211. if (in_array(-1, $_REQUEST['searchlabel']))
  1212. {
  1213. $labelQuery = ' AND pmr.in_inbox = {int:in_inbox}';
  1214. $searchq_parameters['in_inbox'] = 1;
  1215. // Now we get rid of that...
  1216. $temp = array_diff($_REQUEST['searchlabel'], array(-1));
  1217. $_REQUEST['searchlabel'] = $temp;
  1218. }
  1219. // Still have something?
  1220. if (!empty($_REQUEST['searchlabel']))
  1221. {
  1222. if ($labelQuery == '')
  1223. {
  1224. // Not searching the inbox - PM must be labeled
  1225. $labelQuery = ' AND pml.id_label IN ({array_int:labels})';
  1226. $labelJoin = ' INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_pm = pmr.id_pm)';
  1227. }
  1228. else
  1229. {
  1230. // Searching the inbox - PM doesn't have to be labeled
  1231. $labelQuery = ' AND (' . substr($labelQuery, 5) . ' OR pml.id_label IN ({array_int:labels}))';
  1232. $labelJoin = ' LEFT JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_pm = pmr.id_pm)';
  1233. }
  1234. $searchq_parameters['labels'] = $_REQUEST['searchlabel'];
  1235. }
  1236. }
  1237. }
  1238. // What are we actually searching for?
  1239. $search_params['search'] = !empty($search_params['search']) ? $search_params['search'] : (isset($_REQUEST['search']) ? $_REQUEST['search'] : '');
  1240. // If we ain't got nothing - we should error!
  1241. if (!isset($search_params['search']) || $search_params['search'] == '')
  1242. $context['search_errors']['invalid_search_string'] = true;
  1243. // Extract phrase parts first (e.g. some words "this is a phrase" some more words.)
  1244. preg_match_all('~(?:^|\s)([-]?)"([^"]+)"(?:$|\s)~' . ($context['utf8'] ? 'u' : ''), $search_params['search'], $matches, PREG_PATTERN_ORDER);
  1245. $searchArray = $matches[2];
  1246. // Remove the phrase parts and extract the words.
  1247. $tempSearch = explode(' ', preg_replace('~(?:^|\s)(?:[-]?)"(?:[^"]+)"(?:$|\s)~' . ($context['utf8'] ? 'u' : ''), ' ', $search_params['search']));
  1248. // A minus sign in front of a word excludes the word.... so...
  1249. $excludedWords = array();
  1250. // .. first, we check for things like -"some words", but not "-some words".
  1251. foreach ($matches[1] as $index => $word)
  1252. if ($word == '-')
  1253. {
  1254. $word = $smcFunc['strtolower'](trim($searchArray[$index]));
  1255. if (strlen($word) > 0)
  1256. $excludedWords[] = $word;
  1257. unset($searchArray[$index]);
  1258. }
  1259. // Now we look for -test, etc.... normaller.
  1260. foreach ($tempSearch as $index => $word)
  1261. {
  1262. if (strpos(trim($word), '-') === 0)
  1263. {
  1264. $word = substr($smcFunc['strtolower']($word), 1);
  1265. if (strlen($word) > 0)
  1266. $excludedWords[] = $word;
  1267. unset($tempSearch[$index]);
  1268. }
  1269. }
  1270. $searchArray = array_merge($searchArray, $tempSearch);
  1271. // Trim everything and make sure there are no words that are the same.
  1272. foreach ($searchArray as $index => $value)
  1273. {
  1274. $searchArray[$index] = $smcFunc['strtolower'](trim($value));
  1275. if ($searchArray[$index] == '')
  1276. unset($searchArray[$index]);
  1277. else
  1278. {
  1279. // Sort out entities first.
  1280. $searchArray[$index] = $smcFunc['htmlspecialchars']($searchArray[$index]);
  1281. }
  1282. }
  1283. $searchArray = array_unique($searchArray);
  1284. // Create an array of replacements for highlighting.
  1285. $context['mark'] = array();
  1286. foreach ($searchArray as $word)
  1287. $context['mark'][$word] = '<strong class="highlight">' . $word . '</strong>';
  1288. // This contains *everything*
  1289. $searchWords = array_merge($searchArray, $excludedWords);
  1290. // Make sure at least one word is being searched for.
  1291. if (empty($searchArray))
  1292. $context['search_errors']['invalid_search_string'] = true;
  1293. // Sort out the search query so the user can edit it - if they want.
  1294. $context['search_params'] = $search_params;
  1295. if (isset($context['search_params']['search']))
  1296. $context['search_params']['search'] = $smcFunc['htmlspecialchars']($context['search_params']['search']);
  1297. if (isset($context['search_params']['userspec']))
  1298. $context['search_params']['userspec'] = $smcFunc['htmlspecialchars']($context['search_params']['userspec']);
  1299. // Now we have all the parameters, combine them together for pagination and the like...
  1300. $context['params'] = array();
  1301. foreach ($search_params as $k => $v)
  1302. $context['params'][] = $k . '|\'|' . $v;
  1303. $context['params'] = base64_encode(implode('|"|', $context['params']));
  1304. // Compile the subject query part.
  1305. $andQueryParts = array();
  1306. foreach ($searchWords as $index => $word)
  1307. {
  1308. if ($word == '')
  1309. continue;
  1310. if ($search_params['subject_only'])
  1311. $andQueryParts[] = 'pm.subject' . (in_array($word, $excludedWords) ? ' NOT' : '') . ' LIKE {string:search_' . $index . '}';
  1312. else
  1313. $andQueryParts[] = '(pm.subject' . (in_array($word, $excludedWords) ? ' NOT' : '') . ' LIKE {string:search_' . $index . '} ' . (in_array($word, $excludedWords) ? 'AND pm.body NOT' : 'OR pm.body') . ' LIKE {string:search_' . $index . '})';
  1314. $searchq_parameters['search_' . $index] = '%' . strtr($word, array('_' => '\\_', '%' => '\\%')) . '%';
  1315. }
  1316. $searchQuery = ' 1=1';
  1317. if (!empty($andQueryParts))
  1318. $searchQuery = implode(!empty($search_params['searchtype']) && $search_params['searchtype'] == 2 ? ' OR ' : ' AND ', $andQueryParts);
  1319. // Age limits?
  1320. $timeQuery = '';
  1321. if (!empty($search_params['minage']))
  1322. $timeQuery .= ' AND pm.msgtime < ' . (time() - $search_params['minage'] * 86400);
  1323. if (!empty($search_params['maxage']))
  1324. $timeQuery .= ' AND pm.msgtime > ' . (time() - $search_params['maxage'] * 86400);
  1325. // If we have errors - return back to the first screen...
  1326. if (!empty($context['search_errors']))
  1327. {
  1328. $_REQUEST['params'] = $context['params'];
  1329. return MessageSearch();
  1330. }
  1331. // Get the amount of results.
  1332. $request = $smcFunc['db_query']('', '
  1333. SELECT COUNT(*)
  1334. FROM {db_prefix}pm_recipients AS pmr
  1335. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  1336. ' . $labelJoin . '
  1337. WHERE ' . ($context['folder'] == 'inbox' ? '
  1338. pmr.id_member = {int:current_member}
  1339. AND pmr.deleted = {int:not_deleted}' : '
  1340. pm.id_member_from = {int:current_member}
  1341. AND pm.deleted_by_sender = {int:not_deleted}') . '
  1342. ' . $userQuery . $labelQuery . $timeQuery . '
  1343. AND (' . $searchQuery . ')',
  1344. array_merge($searchq_parameters, array(
  1345. 'current_member' => $user_info['id'],
  1346. 'not_deleted' => 0,
  1347. ))
  1348. );
  1349. list ($numResults) = $smcFunc['db_fetch_row']($request);
  1350. $smcFunc['db_free_result']($request);
  1351. // Get all the matching messages... using standard search only (No caching and the like!)
  1352. // @todo This doesn't support sent item searching yet.
  1353. $request = $smcFunc['db_query']('', '
  1354. SELECT pm.id_pm, pm.id_pm_head, pm.id_member_from
  1355. FROM {db_prefix}pm_recipients AS pmr
  1356. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  1357. ' . $labelJoin . '
  1358. WHERE ' . ($context['folder'] == 'inbox' ? '
  1359. pmr.id_member = {int:current_member}
  1360. AND pmr.deleted = {int:not_deleted}' : '
  1361. pm.id_member_from = {int:current_member}
  1362. AND pm.deleted_by_sender = {int:not_deleted}') . '
  1363. ' . $userQuery . $labelQuery . $timeQuery . '
  1364. AND (' . $searchQuery . ')
  1365. ORDER BY ' . $search_params['sort'] . ' ' . $search_params['sort_dir'] . '
  1366. LIMIT ' . $context['start'] . ', ' . $modSettings['search_results_per_page'],
  1367. array_merge($searchq_parameters, array(
  1368. 'current_member' => $user_info['id'],
  1369. 'not_deleted' => 0,
  1370. ))
  1371. );
  1372. $foundMessages = array();
  1373. $posters = array();
  1374. $head_pms = array();
  1375. while ($row = $smcFunc['db_fetch_assoc']($request))
  1376. {
  1377. $foundMessages[] = $row['id_pm'];
  1378. $posters[] = $row['id_member_from'];
  1379. $head_pms[$row['id_pm']] = $row['id_pm_head'];
  1380. }
  1381. $smcFunc['db_free_result']($request);
  1382. // Find the real head pms!
  1383. if ($context['display_mode'] == 2 && !empty($head_pms))
  1384. {
  1385. $request = $smcFunc['db_query']('', '
  1386. SELECT MAX(pm.id_pm) AS id_pm, pm.id_pm_head
  1387. FROM {db_prefix}personal_messages AS pm
  1388. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)
  1389. WHERE pm.id_pm_head IN ({array_int:head_pms})
  1390. AND pmr.id_member = {int:current_member}
  1391. AND pmr.deleted = {int:not_deleted}
  1392. GROUP BY pm.id_pm_head
  1393. LIMIT {int:limit}',
  1394. array(
  1395. 'head_pms' => array_unique($head_pms),
  1396. 'current_member' => $user_info['id'],
  1397. 'not_deleted' => 0,
  1398. 'limit' => count($head_pms),
  1399. )
  1400. );
  1401. $real_pm_ids = array();
  1402. while ($row = $smcFunc['db_fetch_assoc']($request))
  1403. $real_pm_ids[$row['id_pm_head']] = $row['id_pm'];
  1404. $smcFunc['db_free_result']($request);
  1405. }
  1406. // Load the users...
  1407. $posters = array_unique($posters);
  1408. if (!empty($posters))
  1409. loadMemberData($posters);
  1410. // Sort out the page index.
  1411. $context['page_index'] = constructPageIndex($scripturl . '?action=pm;sa=search2;params=' . $context['params'], $_GET['start'], $numResults, $modSettings['search_results_per_page'], false);
  1412. $context['message_labels'] = array();
  1413. $context['message_replied'] = array();
  1414. $context['personal_messages'] = array();
  1415. if (!empty($foundMessages))
  1416. {
  1417. // Now get recipients (but don't include bcc-recipients for your inbox, you're not supposed to know :P!)
  1418. $request = $smcFunc['db_query']('', '
  1419. SELECT
  1420. pmr.id_pm, mem_to.id_member AS id_member_to, mem_to.real_name AS to_name,
  1421. pmr.bcc, pmr.in_inbox, pmr.is_read
  1422. FROM {db_prefix}pm_recipients AS pmr
  1423. LEFT JOIN {db_prefix}members AS mem_to ON (mem_to.id_member = pmr.id_member)
  1424. WHERE pmr.id_pm IN ({array_int:message_list})',
  1425. array(
  1426. 'message_list' => $foundMessages,
  1427. )
  1428. );
  1429. while ($row = $smcFunc['db_fetch_assoc']($request))
  1430. {
  1431. if ($context['folder'] == 'sent' || empty($row['bcc']))
  1432. $recipients[$row['id_pm']][empty($row['bcc']) ? 'to' : 'bcc'][] = empty($row['id_member_to']) ? $txt['guest_title'] : '<a href="' . $scripturl . '?action=profile;u=' . $row['id_member_to'] . '">' . $row['to_name'] . '</a>';
  1433. if ($row['id_member_to'] == $user_info['id'] && $context['folder'] != 'sent')
  1434. {
  1435. $context['message_replied'][$row['id_pm']] = $row['is_read'] & 2;
  1436. $row['labels'] = '';
  1437. // Get the labels for this PM
  1438. $request2 = $smcFunc['db_query']('', '
  1439. SELECT id_label
  1440. FROM {db_prefix}pm_labeled_messages
  1441. WHERE id_pm = {int:current_pm}',
  1442. array(
  1443. 'current_pm' => $row['id_pm'],
  1444. )
  1445. );
  1446. while($row2 = $smcFunc['db_fetch_assoc']($request2))
  1447. {
  1448. $l_id = $row2['id_label'];
  1449. if (isset($context['labels'][$id_label]))
  1450. $context['message_labels'][$row['id_pm']][$l_id] = array('id' => $l_id, 'name' => $context['labels'][$l_id]['name']);
  1451. // Here we find the first label on a message - for linking to posts in results
  1452. if (!isset($context['first_label'][$row['id_pm']]) && $row['in_inbox'] != 1)
  1453. $context['first_label'][$row['id_pm']] = $l_id;
  1454. }
  1455. $smcFunc['db_free_result']($request2);
  1456. // Is this in the inbox as well?
  1457. if ($row['in_inbox'] == 1)
  1458. {
  1459. $context['message_labels'][$row['id_pm']][-1] = array('id' => -1, 'name' => $context['labels'][-1]['name']);
  1460. }
  1461. $row['labels'] = $row['labels'] == '' ? array() : explode(',', $row['labels']);
  1462. }
  1463. }
  1464. // Prepare the query for the callback!
  1465. $request = $smcFunc['db_query']('', '
  1466. SELECT pm.id_pm, pm.subject, pm.id_member_from, pm.body, pm.msgtime, pm.from_name
  1467. FROM {db_prefix}personal_messages AS pm
  1468. WHERE pm.id_pm IN ({array_int:message_list})
  1469. ORDER BY ' . $search_params['sort'] . ' ' . $search_params['sort_dir'] . '
  1470. LIMIT ' . count($foundMessages),
  1471. array(
  1472. 'message_list' => $foundMessages,
  1473. )
  1474. );
  1475. $counter = 0;
  1476. while ($row = $smcFunc['db_fetch_assoc']($request))
  1477. {
  1478. // If there's no message subject, use the default.
  1479. $row['subject'] = $row['subject'] == '' ? $txt['no_subject'] : $row['subject'];
  1480. // Load this posters context info, if it ain't there then fill in the essentials...
  1481. if (!loadMemberContext($row['id_member_from'], true))
  1482. {
  1483. $memberContext[$row['id_member_from']]['name'] = $row['from_name'];
  1484. $memberContext[$row['id_member_from']]['id'] = 0;
  1485. $memberContext[$row['id_member_from']]['group'] = $txt['guest_title'];
  1486. $memberContext[$row['id_member_from']]['link'] = $row['from_name'];
  1487. $memberContext[$row['id_member_from']]['email'] = '';
  1488. $memberContext[$row['id_member_from']]['show_email'] = showEmailAddress(true, 0);
  1489. $memberContext[$row['id_member_from']]['is_guest'] = true;
  1490. }
  1491. // Censor anything we don't want to see...
  1492. censorText($row['body']);
  1493. censorText($row['subject']);
  1494. // Parse out any BBC...
  1495. $row['body'] = parse_bbc($row['body'], true, 'pm' . $row['id_pm']);
  1496. $href = $scripturl . '?action=pm;f=' . $context['folder'] . (isset($context['first_label'][$row['id_pm']]) ? ';l=' . $context['first_label'][$row['id_pm']] : '') . ';pmid=' . ($context['display_mode'] == 2 && isset($real_pm_ids[$head_pms[$row['id_pm']]]) ? $real_pm_ids[$head_pms[$row['id_pm']]] : $row['id_pm']) . '#msg' . $row['id_pm'];
  1497. $context['personal_messages'][] = array(
  1498. 'id' => $row['id_pm'],
  1499. 'member' => &$memberContext[$row['id_member_from']],
  1500. 'subject' => $row['subject'],
  1501. 'body' => $row['body'],
  1502. 'time' => timeformat($row['msgtime']),
  1503. 'recipients' => &$recipients[$row['id_pm']],
  1504. 'labels' => &$context['message_labels'][$row['id_pm']],
  1505. 'fully_labeled' => count($context['message_labels'][$row['id_pm']]) == count($context['labels']),
  1506. 'is_replied_to' => &$context['message_replied'][$row['id_pm']],
  1507. 'href' => $href,
  1508. 'link' => '<a href="' . $href . '">' . $row['subject'] . '</a>',
  1509. 'counter' => ++$counter,
  1510. );
  1511. }
  1512. $smcFunc['db_free_result']($request);
  1513. }
  1514. // Finish off the context.
  1515. $context['page_title'] = $txt['pm_search_title'];
  1516. $context['sub_template'] = 'search_results';
  1517. $context['menu_data_' . $context['pm_menu_id']]['current_area'] = 'search';
  1518. $context['linktree'][] = array(
  1519. 'url' => $scripturl . '?action=pm;sa=search',
  1520. 'name' => $txt['pm_search_bar_title'],
  1521. );
  1522. }
  1523. /**
  1524. * Send a new message?
  1525. */
  1526. function MessagePost()
  1527. {
  1528. global $txt, $sourcedir, $scripturl, $modSettings;
  1529. global $context, $smcFunc, $language, $user_info;
  1530. isAllowedTo('pm_send');
  1531. loadLanguage('PersonalMessage');
  1532. // Just in case it was loaded from somewhere else.
  1533. if (!WIRELESS)
  1534. {
  1535. loadTemplate('PersonalMessage');
  1536. $context['sub_template'] = 'send';
  1537. }
  1538. // Extract out the spam settings - cause it's neat.
  1539. list ($modSettings['max_pm_recipients'], $modSettings['pm_posts_verification'], $modSettings['pm_posts_per_hour']) = explode(',', $modSettings['pm_spam_settings']);
  1540. // Set the title...
  1541. $context['page_title'] = $txt['send_message'];
  1542. $context['reply'] = isset($_REQUEST['pmsg']) || isset($_REQUEST['quote']);
  1543. // Check whether we've gone over the limit of messages we can send per hour.
  1544. if (!empty($modSettings['pm_posts_per_hour']) && !allowedTo(array('admin_forum', 'moderate_forum', 'send_mail')) && $user_info['mod_cache']['bq'] == '0=1' && $user_info['mod_cache']['gq'] == '0=1')
  1545. {
  1546. // How many messages have they sent this last hour?
  1547. $request = $smcFunc['db_query']('', '
  1548. SELECT COUNT(pr.id_pm) AS post_count
  1549. FROM {db_prefix}personal_messages AS pm
  1550. INNER JOIN {db_prefix}pm_recipients AS pr ON (pr.id_pm = pm.id_pm)
  1551. WHERE pm.id_member_from = {int:current_member}
  1552. AND pm.msgtime > {int:msgtime}',
  1553. array(
  1554. 'current_member' => $user_info['id'],
  1555. 'msgtime' => time() - 3600,
  1556. )
  1557. );
  1558. list ($postCount) = $smcFunc['db_fetch_row']($request);
  1559. $smcFunc['db_free_result']($request);
  1560. if (!empty($postCount) && $postCount >= $modSettings['pm_posts_per_hour'])
  1561. fatal_lang_error('pm_too_many_per_hour', true, array($modSettings['pm_posts_per_hour']));
  1562. }
  1563. // Quoting/Replying to a message?
  1564. if (!empty($_REQUEST['pmsg']))
  1565. {
  1566. $pmsg = (int) $_REQUEST['pmsg'];
  1567. // Make sure this is yours.
  1568. if (!isAccessiblePM($pmsg))
  1569. fatal_lang_error('no_access', false);
  1570. // Work out whether this is one you've received?
  1571. $request = $smcFunc['db_query']('', '
  1572. SELECT
  1573. id_pm
  1574. FROM {db_prefix}pm_recipients
  1575. WHERE id_pm = {int:id_pm}
  1576. AND id_member = {int:current_member}
  1577. LIMIT 1',
  1578. array(
  1579. 'current_member' => $user_info['id'],
  1580. 'id_pm' => $pmsg,
  1581. )
  1582. );
  1583. $isReceived = $smcFunc['db_num_rows']($request) != 0;
  1584. $smcFunc['db_free_result']($request);
  1585. // Get the quoted message (and make sure you're allowed to see this quote!).
  1586. $request = $smcFunc['db_query']('', '
  1587. SELECT
  1588. pm.id_pm, CASE WHEN pm.id_pm_head = {int:id_pm_head_empty} THEN pm.id_pm ELSE pm.id_pm_head END AS pm_head,
  1589. pm.body, pm.subject, pm.msgtime, mem.member_name, IFNULL(mem.id_member, 0) AS id_member,
  1590. IFNULL(mem.real_name, pm.from_name) AS real_name
  1591. FROM {db_prefix}personal_messages AS pm' . (!$isReceived ? '' : '
  1592. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = {int:id_pm})') . '
  1593. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  1594. WHERE pm.id_pm = {int:id_pm}' . (!$isReceived ? '
  1595. AND pm.id_member_from = {int:current_member}' : '
  1596. AND pmr.id_member = {int:current_member}') . '
  1597. LIMIT 1',
  1598. array(
  1599. 'current_member' => $user_info['id'],
  1600. 'id_pm_head_empty' => 0,
  1601. 'id_pm' => $pmsg,
  1602. )
  1603. );
  1604. if ($smcFunc['db_num_rows']($request) == 0)
  1605. fatal_lang_error('pm_not_yours', false);
  1606. $row_quoted = $smcFunc['db_fetch_assoc']($request);
  1607. $smcFunc['db_free_result']($request);
  1608. // Censor the message.
  1609. censorText($row_quoted['subject']);
  1610. censorText($row_quoted['body']);
  1611. // Add 'Re: ' to it....
  1612. if (!isset($context['response_prefix']) && !($context['response_prefix'] = cache_get_data('response_prefix')))
  1613. {
  1614. if ($language === $user_info['language'])
  1615. $context['response_prefix'] = $txt['response_prefix'];
  1616. else
  1617. {
  1618. loadLanguage('index', $language, false);
  1619. $context['response_prefix'] = $txt['response_prefix'];
  1620. loadLanguage('index');
  1621. }
  1622. cache_put_data('response_prefix', $context['response_prefix'], 600);
  1623. }
  1624. $form_subject = $row_quoted['subject'];
  1625. if ($context['reply'] && trim($context['response_prefix']) != '' && $smcFunc['strpos']($form_subject, trim($context['response_prefix'])) !== 0)
  1626. $form_subject = $context['response_prefix'] . $form_subject;
  1627. if (isset($_REQUEST['quote']))
  1628. {
  1629. // Remove any nested quotes and <br>...
  1630. $form_message = preg_replace('~<br ?/?' . '>~i', "\n", $row_quoted['body']);
  1631. if (!empty($modSettings['removeNestedQuotes']))
  1632. $form_message = preg_replace(array('~\n?\[quote.*?\].+?\[/quote\]\n?~is', '~^\n~', '~\[/quote\]~'), '', $form_message);
  1633. if (empty($row_quoted['id_member']))
  1634. $form_message = '[quote author=&quot;' . $row_quoted['real_name'] . '&quot;]' . "\n" . $form_message . "\n" . '[/quote]';
  1635. else
  1636. $form_message = '[quote author=' . $row_quoted['real_name'] . ' link=action=profile;u=' . $row_quoted['id_member'] . ' date=' . $row_quoted['msgtime'] . ']' . "\n" . $form_message . "\n" . '[/quote]';
  1637. }
  1638. else
  1639. $form_message = '';
  1640. // Do the BBC thang on the message.
  1641. $row_quoted['body'] = parse_bbc($row_quoted['body'], true, 'pm' . $row_quoted['id_pm']);
  1642. // Set up the quoted message array.
  1643. $context['quoted_message'] = array(
  1644. 'id' => $row_quoted['id_pm'],
  1645. 'pm_head' => $row_quoted['pm_head'],
  1646. 'member' => array(
  1647. 'name' => $row_quoted['real_name'],
  1648. 'username' => $row_quoted['member_name'],
  1649. 'id' => $row_quoted['id_member'],
  1650. 'href' => !empty($row_quoted['id_member']) ? $scripturl . '?action=profile;u=' . $row_quoted['id_member'] : '',
  1651. 'link' => !empty($row_quoted['id_member']) ? '<a href="' . $scripturl . '?action=profile;u=' . $row_quoted['id_member'] . '">' . $row_quoted['real_name'] . '</a>' : $row_quoted['real_name'],
  1652. ),
  1653. 'subject' => $row_quoted['subject'],
  1654. 'time' => timeformat($row_quoted['msgtime']),
  1655. 'timestamp' => forum_time(true, $row_quoted['msgtime']),
  1656. 'body' => $row_quoted['body']
  1657. );
  1658. }
  1659. else
  1660. {
  1661. $context['quoted_message'] = false;
  1662. $form_subject = '';
  1663. $form_message = '';
  1664. }
  1665. $context['recipients'] = array(
  1666. 'to' => array(),
  1667. 'bcc' => array(),
  1668. );
  1669. // Sending by ID? Replying to all? Fetch the real_name(s).
  1670. if (isset($_REQUEST['u']))
  1671. {
  1672. // If the user is replying to all, get all the other members this was sent to..
  1673. if ($_REQUEST['u'] == 'all' && isset($row_quoted))
  1674. {
  1675. // Firstly, to reply to all we clearly already have $row_quoted - so have the original member from.
  1676. if ($row_quoted['id_member'] != $user_info['id'])
  1677. $context['recipients']['to'][] = array(
  1678. 'id' => $row_quoted['id_member'],
  1679. 'name' => $smcFunc['htmlspecialchars']($row_quoted['real_name']),
  1680. );
  1681. // Now to get the others.
  1682. $request = $smcFunc['db_query']('', '
  1683. SELECT mem.id_member, mem.real_name
  1684. FROM {db_prefix}pm_recipients AS pmr
  1685. INNER JOIN {db_prefix}members AS mem ON (mem.id_member = pmr.id_member)
  1686. WHERE pmr.id_pm = {int:id_pm}
  1687. AND pmr.id_member != {int:current_member}
  1688. AND pmr.bcc = {int:not_bcc}',
  1689. array(
  1690. 'current_member' => $user_info['id'],
  1691. 'id_pm' => $pmsg,
  1692. 'not_bcc' => 0,
  1693. )
  1694. );
  1695. while ($row = $smcFunc['db_fetch_assoc']($request))
  1696. $context['recipients']['to'][] = array(
  1697. 'id' => $row['id_member'],
  1698. 'name' => $row['real_name'],
  1699. );
  1700. $smcFunc['db_free_result']($request);
  1701. }
  1702. else
  1703. {
  1704. $_REQUEST['u'] = explode(',', $_REQUEST['u']);
  1705. foreach ($_REQUEST['u'] as $key => $uID)
  1706. $_REQUEST['u'][$key] = (int) $uID;
  1707. $_REQUEST['u'] = array_unique($_REQUEST['u']);
  1708. $request = $smcFunc['db_query']('', '
  1709. SELECT id_member, real_name
  1710. FROM {db_prefix}members
  1711. WHERE id_member IN ({array_int:member_list})
  1712. LIMIT ' . count($_REQUEST['u']),
  1713. array(
  1714. 'member_list' => $_REQUEST['u'],
  1715. )
  1716. );
  1717. while ($row = $smcFunc['db_fetch_assoc']($request))
  1718. $context['recipients']['to'][] = array(
  1719. 'id' => $row['id_member'],
  1720. 'name' => $row['real_name'],
  1721. );
  1722. $smcFunc['db_free_result']($request);
  1723. }
  1724. // Get a literal name list in case the user has JavaScript disabled.
  1725. $names = array();
  1726. foreach ($context['recipients']['to'] as $to)
  1727. $names[] = $to['name'];
  1728. $context['to_value'] = empty($names) ? '' : '&quot;' . implode('&quot;, &quot;', $names) . '&quot;';
  1729. }
  1730. else
  1731. $context['to_value'] = '';
  1732. // Set the defaults...
  1733. $context['subject'] = $form_subject;
  1734. $context['message'] = str_replace(array('"', '<', '>', '&nbsp;'), array('&quot;', '&lt;', '&gt;', ' '), $form_message);
  1735. $context['post_error'] = array();
  1736. // And build the link tree.
  1737. $context['linktree'][] = array(
  1738. 'url' => $scripturl . '?action=pm;sa=send',
  1739. 'name' => $txt['new_message']
  1740. );
  1741. $modSettings['disable_wysiwyg'] = !empty($modSettings['disable_wysiwyg']) || empty($modSettings['enableBBC']);
  1742. // Generate a list of drafts that they can load in to the editor
  1743. if (!empty($context['drafts_pm_save']))
  1744. {
  1745. require_once($sourcedir . '/Drafts.php');
  1746. $pm_seed = isset($_REQUEST['pmsg']) ? $_REQUEST['pmsg'] : (isset($_REQUEST['quote']) ? $_REQUEST['quote'] : 0);
  1747. ShowDrafts($user_info['id'], $pm_seed, 1);
  1748. }
  1749. // Needed for the WYSIWYG editor.
  1750. require_once($sourcedir . '/Subs-Editor.php');
  1751. // Now create the editor.
  1752. $editorOptions = array(
  1753. 'id' => 'message',
  1754. 'value' => $context['message'],
  1755. 'height' => '250px',
  1756. 'width' => '100%',
  1757. 'labels' => array(
  1758. 'post_button' => $txt['send_message'],
  1759. ),
  1760. 'preview_type' => 2,
  1761. 'required' => true,
  1762. );
  1763. create_control_richedit($editorOptions);
  1764. // Store the ID for old compatibility.
  1765. $context['post_box_name'] = $editorOptions['id'];
  1766. $context['bcc_value'] = '';
  1767. $context['require_verification'] = !$user_info['is_admin'] && !empty($modSettings['pm_posts_verification']) && $user_info['posts'] < $modSettings['pm_posts_verification'];
  1768. if ($context['require_verification'])
  1769. {
  1770. $verificationOptions = array(
  1771. 'id' => 'pm',
  1772. );
  1773. $context['require_verification'] = create_control_verification($verificationOptions);
  1774. $context['visual_verification_id'] = $verificationOptions['id'];
  1775. }
  1776. // Register this form and get a sequence number in $context.
  1777. checkSubmitOnce('register');
  1778. }
  1779. /**
  1780. * This function allows the user to view their PM drafts
  1781. */
  1782. function MessageDrafts()
  1783. {
  1784. global $sourcedir, $user_info;
  1785. // validate with loadMemberData()
  1786. $memberResult = loadMemberData($user_info['id'], false);
  1787. if (!is_array($memberResult))
  1788. fatal_lang_error('not_a_user', false);
  1789. list ($memID) = $memberResult;
  1790. // drafts is where the functions reside
  1791. require_once($sourcedir . '/Drafts.php');
  1792. showPMDrafts($memID);
  1793. }
  1794. /**
  1795. * An error in the message...
  1796. *
  1797. * @param $error_types
  1798. * @param $named_recipients
  1799. * @param $recipient_ids
  1800. */
  1801. function messagePostError($error_types, $named_recipients, $recipient_ids = array())
  1802. {
  1803. global $txt, $context, $scripturl, $modSettings;
  1804. global $smcFunc, $user_info, $sourcedir;
  1805. if (!isset($_REQUEST['xml']))
  1806. $context['menu_data_' . $context['pm_menu_id']]['current_area'] = 'send';
  1807. if (!WIRELESS && !isset($_REQUEST['xml']))
  1808. $context['sub_template'] = 'send';
  1809. elseif (isset($_REQUEST['xml']))
  1810. $context['sub_template'] = 'pm';
  1811. $context['page_title'] = $txt['send_message'];
  1812. // Got some known members?
  1813. $context['recipients'] = array(
  1814. 'to' => array(),
  1815. 'bcc' => array(),
  1816. );
  1817. if (!empty($recipient_ids['to']) || !empty($recipient_ids['bcc']))
  1818. {
  1819. $allRecipients = array_merge($recipient_ids['to'], $recipient_ids['bcc']);
  1820. $request = $smcFunc['db_query']('', '
  1821. SELECT id_member, real_name
  1822. FROM {db_prefix}members
  1823. WHERE id_member IN ({array_int:member_list})',
  1824. array(
  1825. 'member_list' => $allRecipients,
  1826. )
  1827. );
  1828. while ($row = $smcFunc['db_fetch_assoc']($request))
  1829. {
  1830. $recipientType = in_array($row['id_member'], $recipient_ids['bcc']) ? 'bcc' : 'to';
  1831. $context['recipients'][$recipientType][] = array(
  1832. 'id' => $row['id_member'],
  1833. 'name' => $row['real_name'],
  1834. );
  1835. }
  1836. $smcFunc['db_free_result']($request);
  1837. }
  1838. // Set everything up like before....
  1839. $context['subject'] = isset($_REQUEST['subject']) ? $smcFunc['htmlspecialchars']($_REQUEST['subject']) : '';
  1840. $context['message'] = isset($_REQUEST['message']) ? str_replace(array(' '), array('&nbsp; '), $smcFunc['htmlspecialchars']($_REQUEST['message'])) : '';
  1841. $context['reply'] = !empty($_REQUEST['replied_to']);
  1842. if ($context['reply'])
  1843. {
  1844. $_REQUEST['replied_to'] = (int) $_REQUEST['replied_to'];
  1845. $request = $smcFunc['db_query']('', '
  1846. SELECT
  1847. pm.id_pm, CASE WHEN pm.id_pm_head = {int:no_id_pm_head} THEN pm.id_pm ELSE pm.id_pm_head END AS pm_head,
  1848. pm.body, pm.subject, pm.msgtime, mem.member_name, IFNULL(mem.id_member, 0) AS id_member,
  1849. IFNULL(mem.real_name, pm.from_name) AS real_name
  1850. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? '' : '
  1851. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = {int:replied_to})') . '
  1852. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  1853. WHERE pm.id_pm = {int:replied_to}' . ($context['folder'] == 'sent' ? '
  1854. AND pm.id_member_from = {int:current_member}' : '
  1855. AND pmr.id_member = {int:current_member}') . '
  1856. LIMIT 1',
  1857. array(
  1858. 'current_member' => $user_info['id'],
  1859. 'no_id_pm_head' => 0,
  1860. 'replied_to' => $_REQUEST['replied_to'],
  1861. )
  1862. );
  1863. if ($smcFunc['db_num_rows']($request) == 0)
  1864. {
  1865. if (!isset($_REQUEST['xml']))
  1866. fatal_lang_error('pm_not_yours', false);
  1867. else
  1868. $error_types[] = 'pm_not_yours';
  1869. }
  1870. $row_quoted = $smcFunc['db_fetch_assoc']($request);
  1871. $smcFunc['db_free_result']($request);
  1872. censorText($row_quoted['subject']);
  1873. censorText($row_quoted['body']);
  1874. $context['quoted_message'] = array(
  1875. 'id' => $row_quoted['id_pm'],
  1876. 'pm_head' => $row_quoted['pm_head'],
  1877. 'member' => array(
  1878. 'name' => $row_quoted['real_name'],
  1879. 'username' => $row_quoted['member_name'],
  1880. 'id' => $row_quoted['id_member'],
  1881. 'href' => !empty($row_quoted['id_member']) ? $scripturl . '?action=profile;u=' . $row_quoted['id_member'] : '',
  1882. 'link' => !empty($row_quoted['id_member']) ? '<a href="' . $scripturl . '?action=profile;u=' . $row_quoted['id_member'] . '">' . $row_quoted['real_name'] . '</a>' : $row_quoted['real_name'],
  1883. ),
  1884. 'subject' => $row_quoted['subject'],
  1885. 'time' => timeformat($row_quoted['msgtime']),
  1886. 'timestamp' => forum_time(true, $row_quoted['msgtime']),
  1887. 'body' => parse_bbc($row_quoted['body'], true, 'pm' . $row_quoted['id_pm']),
  1888. );
  1889. }
  1890. // Build the link tree....
  1891. $context['linktree'][] = array(
  1892. 'url' => $scripturl . '?action=pm;sa=send',
  1893. 'name' => $txt['new_message']
  1894. );
  1895. // Set each of the errors for the template.
  1896. loadLanguage('Errors');
  1897. $context['error_type'] = 'minor';
  1898. $context['post_error'] = array(
  1899. 'messages' => array(),
  1900. // @todo error handling: maybe fatal errors can be error_type => serious
  1901. 'error_type' => '',
  1902. );
  1903. foreach ($error_types as $error_type)
  1904. {
  1905. $context['post_error'][$error_type] = true;
  1906. if (isset($txt['error_' . $error_type]))
  1907. {
  1908. if ($error_type == 'long_message')
  1909. $txt['error_' . $error_type] = sprintf($txt['error_' . $error_type], $modSettings['max_messageLength']);
  1910. $context['post_error']['messages'][] = $txt['error_' . $error_type];
  1911. }
  1912. // If it's not a minor error flag it as such.
  1913. if (!in_array($error_type, array('new_reply', 'not_approved', 'new_replies', 'old_topic', 'need_qr_verification', 'no_subject')))
  1914. $context['error_type'] = 'serious';
  1915. }
  1916. // We need to load the editor once more.
  1917. require_once($sourcedir . '/Subs-Editor.php');
  1918. // Create it...
  1919. $editorOptions = array(
  1920. 'id' => 'message',
  1921. 'value' => $context['message'],
  1922. 'width' => '90%',
  1923. 'height' => '250px',
  1924. 'labels' => array(
  1925. 'post_button' => $txt['send_message'],
  1926. ),
  1927. 'preview_type' => 2,
  1928. );
  1929. create_control_richedit($editorOptions);
  1930. // ... and store the ID again...
  1931. $context['post_box_name'] = $editorOptions['id'];
  1932. // Check whether we need to show the code again.
  1933. $context['require_verification'] = !$user_info['is_admin'] && !empty($modSettings['pm_posts_verification']) && $user_info['posts'] < $modSettings['pm_posts_verification'];
  1934. if ($context['require_verification'] && !isset($_REQUEST['xml']))
  1935. {
  1936. require_once($sourcedir . '/Subs-Editor.php');
  1937. $verificationOptions = array(
  1938. 'id' => 'pm',
  1939. );
  1940. $context['require_verification'] = create_control_verification($verificationOptions);
  1941. $context['visual_verification_id'] = $verificationOptions['id'];
  1942. }
  1943. $context['to_value'] = empty($named_recipients['to']) ? '' : '&quot;' . implode('&quot;, &quot;', $named_recipients['to']) . '&quot;';
  1944. $context['bcc_value'] = empty($named_recipients['bcc']) ? '' : '&quot;' . implode('&quot;, &quot;', $named_recipients['bcc']) . '&quot;';
  1945. // No check for the previous submission is needed.
  1946. checkSubmitOnce('free');
  1947. // Acquire a new form sequence number.
  1948. checkSubmitOnce('register');
  1949. }
  1950. /**
  1951. * Send it!
  1952. */
  1953. function MessagePost2()
  1954. {
  1955. global $txt, $context, $sourcedir;
  1956. global $user_info, $modSettings, $scripturl, $smcFunc;
  1957. isAllowedTo('pm_send');
  1958. require_once($sourcedir . '/Subs-Auth.php');
  1959. // PM Drafts enabled and needed?
  1960. if ($context['drafts_pm_save'] && (isset($_POST['save_draft']) || isset($_POST['id_pm_draft'])))
  1961. require_once($sourcedir . '/Drafts.php');
  1962. loadLanguage('PersonalMessage', '', false);
  1963. // Extract out the spam settings - it saves database space!
  1964. list ($modSettings['max_pm_recipients'], $modSettings['pm_posts_verification'], $modSettings['pm_posts_per_hour']) = explode(',', $modSettings['pm_spam_settings']);
  1965. // Initialize the errors we're about to make.
  1966. $post_errors = array();
  1967. // Check whether we've gone over the limit of messages we can send per hour - fatal error if fails!
  1968. if (!empty($modSettings['pm_posts_per_hour']) && !allowedTo(array('admin_forum', 'moderate_forum', 'send_mail')) && $user_info['mod_cache']['bq'] == '0=1' && $user_info['mod_cache']['gq'] == '0=1')
  1969. {
  1970. // How many have they sent this last hour?
  1971. $request = $smcFunc['db_query']('', '
  1972. SELECT COUNT(pr.id_pm) AS post_count
  1973. FROM {db_prefix}personal_messages AS pm
  1974. INNER JOIN {db_prefix}pm_recipients AS pr ON (pr.id_pm = pm.id_pm)
  1975. WHERE pm.id_member_from = {int:current_member}
  1976. AND pm.msgtime > {int:msgtime}',
  1977. array(
  1978. 'current_member' => $user_info['id'],
  1979. 'msgtime' => time() - 3600,
  1980. )
  1981. );
  1982. list ($postCount) = $smcFunc['db_fetch_row']($request);
  1983. $smcFunc['db_free_result']($request);
  1984. if (!empty($postCount) && $postCount >= $modSettings['pm_posts_per_hour'])
  1985. {
  1986. if (!isset($_REQUEST['xml']))
  1987. fatal_lang_error('pm_too_many_per_hour', true, array($modSettings['pm_posts_per_hour']));
  1988. else
  1989. $post_errors[] = 'pm_too_many_per_hour';
  1990. }
  1991. }
  1992. // If your session timed out, show an error, but do allow to re-submit.
  1993. if (!isset($_REQUEST['xml']) && checkSession('post', '', false) != '')
  1994. $post_errors[] = 'session_timeout';
  1995. $_REQUEST['subject'] = isset($_REQUEST['subject']) ? trim($_REQUEST['subject']) : '';
  1996. $_REQUEST['to'] = empty($_POST['to']) ? (empty($_GET['to']) ? '' : $_GET['to']) : $_POST['to'];
  1997. $_REQUEST['bcc'] = empty($_POST['bcc']) ? (empty($_GET['bcc']) ? '' : $_GET['bcc']) : $_POST['bcc'];
  1998. // Route the input from the 'u' parameter to the 'to'-list.
  1999. if (!empty($_POST['u']))
  2000. $_POST['recipient_to'] = explode(',', $_POST['u']);
  2001. // Construct the list of recipients.
  2002. $recipientList = array();
  2003. $namedRecipientList = array();
  2004. $namesNotFound = array();
  2005. foreach (array('to', 'bcc') as $recipientType)
  2006. {
  2007. // First, let's see if there's user ID's given.
  2008. $recipientList[$recipientType] = array();
  2009. if (!empty($_POST['recipient_' . $recipientType]) && is_array($_POST['recipient_' . $recipientType]))
  2010. {
  2011. foreach ($_POST['recipient_' . $recipientType] as $recipient)
  2012. $recipientList[$recipientType][] = (int) $recipient;
  2013. }
  2014. // Are there also literal names set?
  2015. if (!empty($_REQUEST[$recipientType]))
  2016. {
  2017. // We're going to take out the "s anyway ;).
  2018. $recipientString = strtr($_REQUEST[$recipientType], array('\\"' => '"'));
  2019. preg_match_all('~"([^"]+)"~', $recipientString, $matches);
  2020. $namedRecipientList[$recipientType] = array_unique(array_merge($matches[1], explode(',', preg_replace('~"[^"]+"~', '', $recipientString))));
  2021. foreach ($namedRecipientList[$recipientType] as $index => $recipient)
  2022. {
  2023. if (strlen(trim($recipient)) > 0)
  2024. $namedRecipientList[$recipientType][$index] = $smcFunc['htmlspecialchars']($smcFunc['strtolower'](trim($recipient)));
  2025. else
  2026. unset($namedRecipientList[$recipientType][$index]);
  2027. }
  2028. if (!empty($namedRecipientList[$recipientType]))
  2029. {
  2030. $foundMembers = findMembers($namedRecipientList[$recipientType]);
  2031. // Assume all are not found, until proven otherwise.
  2032. $namesNotFound[$recipientType] = $namedRecipientList[$recipientType];
  2033. foreach ($foundMembers as $member)
  2034. {
  2035. $testNames = array(
  2036. $smcFunc['strtolower']($member['username']),
  2037. $smcFunc['strtolower']($member['name']),
  2038. $smcFunc['strtolower']($member['email']),
  2039. );
  2040. if (count(array_intersect($testNames, $namedRecipientList[$recipientType])) !== 0)
  2041. {
  2042. $recipientList[$recipientType][] = $member['id'];
  2043. // Get rid of this username, since we found it.
  2044. $namesNotFound[$recipientType] = array_diff($namesNotFound[$recipientType], $testNames);
  2045. }
  2046. }
  2047. }
  2048. }
  2049. // Selected a recipient to be deleted? Remove them now.
  2050. if (!empty($_POST['delete_recipient']))
  2051. $recipientList[$recipientType] = array_diff($recipientList[$recipientType], array((int) $_POST['delete_recipient']));
  2052. // Make sure we don't include the same name twice
  2053. $recipientList[$recipientType] = array_unique($recipientList[$recipientType]);
  2054. }
  2055. // Are we changing the recipients some how?
  2056. $is_recipient_change = !empty($_POST['delete_recipient']) || !empty($_POST['to_submit']) || !empty($_POST['bcc_submit']);
  2057. // Check if there's at least one recipient.
  2058. if (empty($recipientList['to']) && empty($recipientList['bcc']))
  2059. $post_errors[] = 'no_to';
  2060. // Make sure that we remove the members who did get it from the screen.
  2061. if (!$is_recipient_change)
  2062. {
  2063. foreach ($recipientList as $recipientType => $dummy)
  2064. {
  2065. if (!empty($namesNotFound[$recipientType]))
  2066. {
  2067. $post_errors[] = 'bad_' . $recipientType;
  2068. // Since we already have a post error, remove the previous one.
  2069. $post_errors = array_diff($post_errors, array('no_to'));
  2070. foreach ($namesNotFound[$recipientType] as $name)
  2071. $context['send_log']['failed'][] = sprintf($txt['pm_error_user_not_found'], $name);
  2072. }
  2073. }
  2074. }
  2075. // Did they make any mistakes?
  2076. if ($_REQUEST['subject'] == '')
  2077. $post_errors[] = 'no_subject';
  2078. if (!isset($_REQUEST['message']) || $_REQUEST['message'] == '')
  2079. $post_errors[] = 'no_message';
  2080. elseif (!empty($modSettings['max_messageLength']) && $smcFunc['strlen']($_REQUEST['message']) > $modSettings['max_messageLength'])
  2081. $post_errors[] = 'long_message';
  2082. else
  2083. {
  2084. // Preparse the message.
  2085. $message = $_REQUEST['message'];
  2086. preparsecode($message);
  2087. // Make sure there's still some content left without the tags.
  2088. if ($smcFunc['htmltrim'](strip_tags(parse_bbc($smcFunc['htmlspecialchars']($message, ENT_QUOTES), false), '<img>')) === '' && (!allowedTo('admin_forum') || strpos($message, '[html]') === false))
  2089. $post_errors[] = 'no_message';
  2090. }
  2091. // Wrong verification code?
  2092. if (!$user_info['is_admin'] && !isset($_REQUEST['xml']) && !empty($modSettings['pm_posts_verification']) && $user_info['posts'] < $modSettings['pm_posts_verification'])
  2093. {
  2094. require_once($sourcedir . '/Subs-Editor.php');
  2095. $verificationOptions = array(
  2096. 'id' => 'pm',
  2097. );
  2098. $context['require_verification'] = create_control_verification($verificationOptions, true);
  2099. if (is_array($context['require_verification']))
  2100. $post_errors = array_merge($post_errors, $context['require_verification']);
  2101. }
  2102. // If they did, give a chance to make ammends.
  2103. if (!empty($post_errors) && !$is_recipient_change && !isset($_REQUEST['preview']) && !isset($_REQUEST['xml']))
  2104. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2105. // Want to take a second glance before you send?
  2106. if (isset($_REQUEST['preview']))
  2107. {
  2108. // Set everything up to be displayed.
  2109. $context['preview_subject'] = $smcFunc['htmlspecialchars']($_REQUEST['subject']);
  2110. $context['preview_message'] = $smcFunc['htmlspecialchars']($_REQUEST['message'], ENT_QUOTES);
  2111. preparsecode($context['preview_message'], true);
  2112. // Parse out the BBC if it is enabled.
  2113. $context['preview_message'] = parse_bbc($context['preview_message']);
  2114. // Censor, as always.
  2115. censorText($context['preview_subject']);
  2116. censorText($context['preview_message']);
  2117. // Set a descriptive title.
  2118. $context['page_title'] = $txt['preview'] . ' - ' . $context['preview_subject'];
  2119. // Pretend they messed up but don't ignore if they really did :P.
  2120. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2121. }
  2122. // Adding a recipient cause javascript ain't working?
  2123. elseif ($is_recipient_change)
  2124. {
  2125. // Maybe we couldn't find one?
  2126. foreach ($namesNotFound as $recipientType => $names)
  2127. {
  2128. $post_errors[] = 'bad_' . $recipientType;
  2129. foreach ($names as $name)
  2130. $context['send_log']['failed'][] = sprintf($txt['pm_error_user_not_found'], $name);
  2131. }
  2132. return messagePostError(array(), $namedRecipientList, $recipientList);
  2133. }
  2134. // Want to save this as a draft and think about it some more?
  2135. if ($context['drafts_pm_save'] && isset($_POST['save_draft']))
  2136. {
  2137. SavePMDraft($post_errors, $recipientList);
  2138. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2139. }
  2140. // Before we send the PM, let's make sure we don't have an abuse of numbers.
  2141. elseif (!empty($modSettings['max_pm_recipients']) && count($recipientList['to']) + count($recipientList['bcc']) > $modSettings['max_pm_recipients'] && !allowedTo(array('moderate_forum', 'send_mail', 'admin_forum')))
  2142. {
  2143. $context['send_log'] = array(
  2144. 'sent' => array(),
  2145. 'failed' => array(sprintf($txt['pm_too_many_recipients'], $modSettings['max_pm_recipients'])),
  2146. );
  2147. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2148. }
  2149. // Protect from message spamming.
  2150. spamProtection('pm');
  2151. // Prevent double submission of this form.
  2152. checkSubmitOnce('check');
  2153. // Do the actual sending of the PM.
  2154. if (!empty($recipientList['to']) || !empty($recipientList['bcc']))
  2155. $context['send_log'] = sendpm($recipientList, $_REQUEST['subject'], $_REQUEST['message'], true, null, !empty($_REQUEST['pm_head']) ? (int) $_REQUEST['pm_head'] : 0);
  2156. else
  2157. $context['send_log'] = array(
  2158. 'sent' => array(),
  2159. 'failed' => array()
  2160. );
  2161. // Mark the message as "replied to".
  2162. if (!empty($context['send_log']['sent']) && !empty($_REQUEST['replied_to']) && isset($_REQUEST['f']) && $_REQUEST['f'] == 'inbox')
  2163. {
  2164. $smcFunc['db_query']('', '
  2165. UPDATE {db_prefix}pm_recipients
  2166. SET is_read = is_read | 2
  2167. WHERE id_pm = {int:replied_to}
  2168. AND id_member = {int:current_member}',
  2169. array(
  2170. 'current_member' => $user_info['id'],
  2171. 'replied_to' => (int) $_REQUEST['replied_to'],
  2172. )
  2173. );
  2174. }
  2175. // If one or more of the recipient were invalid, go back to the post screen with the failed usernames.
  2176. if (!empty($context['send_log']['failed']))
  2177. return messagePostError($post_errors, $namesNotFound, array(
  2178. 'to' => array_intersect($recipientList['to'], $context['send_log']['failed']),
  2179. 'bcc' => array_intersect($recipientList['bcc'], $context['send_log']['failed'])
  2180. ));
  2181. // Message sent successfully?
  2182. if (!empty($context['send_log']) && empty($context['send_log']['failed']))
  2183. {
  2184. $context['current_label_redirect'] = $context['current_label_redirect'] . ';done=sent';
  2185. // If we had a PM draft for this one, then its time to remove it since it was just sent
  2186. if ($context['drafts_pm_save'] && !empty($_POST['id_pm_draft']))
  2187. DeleteDraft($_POST['id_pm_draft']);
  2188. }
  2189. // Go back to the where they sent from, if possible...
  2190. redirectexit($context['current_label_redirect']);
  2191. }
  2192. /**
  2193. * This function lists all buddies for wireless protocols.
  2194. */
  2195. function WirelessAddBuddy()
  2196. {
  2197. global $scripturl, $txt, $user_info, $context, $smcFunc;
  2198. isAllowedTo('pm_send');
  2199. $context['page_title'] = $txt['wireless_pm_add_buddy'];
  2200. $current_buddies = empty($_REQUEST['u']) ? array() : explode(',', $_REQUEST['u']);
  2201. foreach ($current_buddies as $key => $buddy)
  2202. $current_buddies[$key] = (int) $buddy;
  2203. $base_url = $scripturl . '?action=pm;sa=send;u=' . (empty($current_buddies) ? '' : implode(',', $current_buddies) . ',');
  2204. $context['pm_href'] = $scripturl . '?action=pm;sa=send' . (empty($current_buddies) ? '' : ';u=' . implode(',', $current_buddies));
  2205. $context['buddies'] = array();
  2206. if (!empty($user_info['buddies']))
  2207. {
  2208. $request = $smcFunc['db_query']('', '
  2209. SELECT id_member, real_name
  2210. FROM {db_prefix}members
  2211. WHERE id_member IN ({array_int:buddy_list})
  2212. ORDER BY real_name
  2213. LIMIT ' . count($user_info['buddies']),
  2214. array(
  2215. 'buddy_list' => $user_info['buddies'],
  2216. )
  2217. );
  2218. while ($row = $smcFunc['db_fetch_assoc']($request))
  2219. $context['buddies'][] = array(
  2220. 'id' => $row['id_member'],
  2221. 'name' => $row['real_name'],
  2222. 'selected' => in_array($row['id_member'], $current_buddies),
  2223. 'add_href' => $base_url . $row['id_member'],
  2224. );
  2225. $smcFunc['db_free_result']($request);
  2226. }
  2227. }
  2228. /**
  2229. * This function performs all additional stuff...
  2230. */
  2231. function MessageActionsApply()
  2232. {
  2233. global $txt, $context, $user_info, $options, $smcFunc;
  2234. checkSession('request');
  2235. if (isset($_REQUEST['del_selected']))
  2236. $_REQUEST['pm_action'] = 'delete';
  2237. if (isset($_REQUEST['pm_action']) && $_REQUEST['pm_action'] != '' && !empty($_REQUEST['pms']) && is_array($_REQUEST['pms']))
  2238. {
  2239. foreach ($_REQUEST['pms'] as $pm)
  2240. $_REQUEST['pm_actions'][(int) $pm] = $_REQUEST['pm_action'];
  2241. }
  2242. if (empty($_REQUEST['pm_actions']))
  2243. redirectexit($context['current_label_redirect']);
  2244. // If we are in conversation, we may need to apply this to every message in the conversation.
  2245. if ($context['display_mode'] == 2 && isset($_REQUEST['conversation']))
  2246. {
  2247. $id_pms = array();
  2248. foreach ($_REQUEST['pm_actions'] as $pm => $dummy)
  2249. $id_pms[] = (int) $pm;
  2250. $request = $smcFunc['db_query']('', '
  2251. SELECT id_pm_head, id_pm
  2252. FROM {db_prefix}personal_messages
  2253. WHERE id_pm IN ({array_int:id_pms})',
  2254. array(
  2255. 'id_pms' => $id_pms,
  2256. )
  2257. );
  2258. $pm_heads = array();
  2259. while ($row = $smcFunc['db_fetch_assoc']($request))
  2260. $pm_heads[$row['id_pm_head']] = $row['id_pm'];
  2261. $smcFunc['db_free_result']($request);
  2262. $request = $smcFunc['db_query']('', '
  2263. SELECT id_pm, id_pm_head
  2264. FROM {db_prefix}personal_messages
  2265. WHERE id_pm_head IN ({array_int:pm_heads})',
  2266. array(
  2267. 'pm_heads' => array_keys($pm_heads),
  2268. )
  2269. );
  2270. // Copy the action from the single to PM to the others.
  2271. while ($row = $smcFunc['db_fetch_assoc']($request))
  2272. {
  2273. if (isset($pm_heads[$row['id_pm_head']]) && isset($_REQUEST['pm_actions'][$pm_heads[$row['id_pm_head']]]))
  2274. $_REQUEST['pm_actions'][$row['id_pm']] = $_REQUEST['pm_actions'][$pm_heads[$row['id_pm_head']]];
  2275. }
  2276. $smcFunc['db_free_result']($request);
  2277. }
  2278. $to_delete = array();
  2279. $to_label = array();
  2280. $to_unlabel = array();
  2281. $label_type = array();
  2282. $labels = array();
  2283. foreach ($_REQUEST['pm_actions'] as $pm => $action)
  2284. {
  2285. if ($action === 'delete')
  2286. $to_delete[] = (int) $pm;
  2287. else
  2288. {
  2289. if (substr($action, 0, 4) == 'add_')
  2290. {
  2291. $type = 'add';
  2292. $action = substr($action, 4);
  2293. }
  2294. elseif (substr($action, 0, 4) == 'rem_')
  2295. {
  2296. $type = 'rem';
  2297. $action = substr($action, 4);
  2298. }
  2299. else
  2300. $type = 'unk';
  2301. if ($action == '-1' || (int) $action > 0)
  2302. {
  2303. $to_label[(int) $pm] = (int) $action;
  2304. $label_type[(int) $pm] = $type;
  2305. }
  2306. }
  2307. }
  2308. // Deleting, it looks like?
  2309. if (!empty($to_delete))
  2310. deleteMessages($to_delete, $context['display_mode'] == 2 ? null : $context['folder']);
  2311. // Are we labeling anything?
  2312. if (!empty($to_label) && $context['folder'] == 'inbox')
  2313. {
  2314. $updateErrors = 0;
  2315. // Are we dealing with conversation view? If so, get all the messages in each conversation
  2316. if ($context['display_mode'] == 2)
  2317. {
  2318. $get_pms = $smcFunc['db_query']('', '
  2319. SELECT pm.id_pm_head, pm.id_pm
  2320. FROM {db_prefix}personal_messages AS pm
  2321. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)
  2322. WHERE pm.id_pm_head IN ({array_int:head_pms})
  2323. AND pm.id_pm NOT IN ({array_int:head_pms})
  2324. AND pmr.id_recipient = {int:current_member}',
  2325. array(
  2326. 'head_pms' => array_keys($to_label),
  2327. 'current_member' => $user_info['id'],
  2328. )
  2329. );
  2330. while ($other_pms = $smcFunc['db_query']($get_pms))
  2331. {
  2332. $to_label[$other_pms['id_pm']] = $to_label[$other_pms['id_pm_head']];
  2333. }
  2334. $smcFunc['db_free_result']($get_pms);
  2335. }
  2336. // Get information about each message...
  2337. $request = $smcFunc['db_query']('', '
  2338. SELECT id_pm, in_inbox
  2339. FROM {db_prefix}pm_recipients
  2340. WHERE id_member = {int:current_member}
  2341. AND id_pm IN ({array_int:to_label})
  2342. LIMIT ' . count($to_label),
  2343. array(
  2344. 'current_member' => $user_info['id'],
  2345. 'to_label' => array_keys($to_label),
  2346. )
  2347. );
  2348. while ($row = $smcFunc['db_fetch_assoc']($request))
  2349. {
  2350. // Get the labels as well, but only if we're not dealing with the inbox
  2351. if ($to_label[$row['id_pm']] != '-1')
  2352. {
  2353. // The JOIN here ensures we only get labels that this user has applied to this PM
  2354. $request2 = $smcFunc['db_query']('', '
  2355. SELECT l.id_label, pml.id_pm
  2356. FROM {db_prefix}pm_labels AS l
  2357. INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_label = l.id_label)
  2358. WHERE l.id_member = {int:current_member}
  2359. AND pml.id_pm = {int:current_pm}',
  2360. array(
  2361. 'current_member' => $user_info['id'],
  2362. 'current_pm' => $row['id_pm'],
  2363. )
  2364. );
  2365. while ($row2 = $smcFunc['db_fetch_assoc']($request2))
  2366. {
  2367. $labels[$row2['id_label']] = $row2['id_label'];
  2368. }
  2369. $smcFunc['db_free_result']($request2);
  2370. }
  2371. elseif ($type == 'rem')
  2372. {
  2373. // If we're removing from the inbox, see if we have at least one other label.
  2374. // This query is faster than the one above
  2375. $request2 = $smcFunc['db_query']('', '
  2376. SELECT COUNT(l.id_label)
  2377. FROM {db_prefix}pm_labels AS l
  2378. INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_label = l.id_label)
  2379. WHERE l.id_member = {int:current_member}
  2380. AND pml.id_pm = {int:current_pm}',
  2381. array(
  2382. 'current_member' => $user_info['id'],
  2383. 'current_pm' => $row['id_pm'],
  2384. )
  2385. );
  2386. // How many labels do you have?
  2387. list ($num_labels) = $smcFunc['db_fetch_assoc']($request2);
  2388. if ($num_labels > 0);
  2389. $context['can_remove_inbox'] = true;
  2390. $smcFunc['db_free_result']($request2);
  2391. }
  2392. // Use this to determine what to do later on...
  2393. $original_labels = $labels;
  2394. // Ignore inbox for now - we'll deal with it later
  2395. if ($to_label[$row['id_pm']] != '-1')
  2396. {
  2397. // If this label is in the list and we're not adding it, remove it
  2398. if (array_key_exists($to_label[$row['id_pm']], $labels) && $type !== 'add')
  2399. unset($labels[$to_label[$row['id_pm']]]);
  2400. else if ($type !== 'rem')
  2401. $labels[$to_label[$row['id_pm']]] = $to_label[$row['id_pm']];
  2402. }
  2403. // Removing all labels or just removing the inbox label
  2404. if ($type == 'rem' && empty($labels))
  2405. $in_inbox = (empty($context['can_remove_inbox']) ? 1 : 0);
  2406. // Adding new labels, but removing inbox and applying new ones
  2407. elseif ($type == 'add' && !empty($options['pm_remove_inbox_label']) && !empty($labels))
  2408. $in_inbox = 0;
  2409. // Just adding it to the inbox
  2410. else
  2411. $in_inbox = 1;
  2412. // Are we adding it to or removing it from the inbox?
  2413. if ($in_inbox != $row['in_inbox'])
  2414. {
  2415. $smcFunc['db_query']('', '
  2416. UPDATE {db_prefix}pm_recipients
  2417. SET in_inbox = {int:in_inbox}
  2418. WHERE id_pm = {int:id_pm}
  2419. AND id_member = {int:current_member}',
  2420. array(
  2421. 'current_member' => $user_info['id'],
  2422. 'id_pm' => $row['id_pm'],
  2423. 'in_inbox' => $in_inbox,
  2424. )
  2425. );
  2426. }
  2427. // Which labels do we not want now?
  2428. $labels_to_remove = array_diff($original_labels, $labels);
  2429. // Don't apply it if it's already applied
  2430. $labels_to_apply = array_diff($labels, $original_labels);
  2431. // Remove labels
  2432. if (!empty($labels_to_remove))
  2433. {
  2434. $smcFunc['db_query']('', '
  2435. DELETE FROM {db_prefix}pm_labeled_messages
  2436. WHERE id_pm = {int:current_pm}
  2437. AND id_label IN ({array_int:labels_to_remove})',
  2438. array(
  2439. 'current_pm' => $row['id_pm'],
  2440. 'labels_to_remove' => $labels_to_remove,
  2441. )
  2442. );
  2443. }
  2444. // Add new ones
  2445. if (!empty($labels_to_apply))
  2446. {
  2447. $inserts = array();
  2448. foreach ($labels_to_apply as $label)
  2449. $inserts[] = array($row['id_pm'], $label);
  2450. $smcFunc['db_insert']('',
  2451. '{db_prefix}pm_labeled_messages',
  2452. array('id_pm' => 'int', 'id_label' => 'int'),
  2453. $inserts,
  2454. array()
  2455. );
  2456. }
  2457. }
  2458. $smcFunc['db_free_result']($request);
  2459. }
  2460. // Back to the folder.
  2461. $_SESSION['pm_selected'] = array_keys($to_label);
  2462. redirectexit($context['current_label_redirect'] . (count($to_label) == 1 ? '#msg' . $_SESSION['pm_selected'][0] : ''), count($to_label) == 1 && isBrowser('ie'));
  2463. }
  2464. /**
  2465. * Are you sure you want to PERMANENTLY (mostly) delete ALL your messages?
  2466. */
  2467. function MessageKillAllQuery()
  2468. {
  2469. global $txt, $context;
  2470. // Only have to set up the template....
  2471. $context['sub_template'] = 'ask_delete';
  2472. $context['page_title'] = $txt['delete_all'];
  2473. $context['delete_all'] = $_REQUEST['f'] == 'all';
  2474. // And set the folder name...
  2475. $txt['delete_all'] = str_replace('PMBOX', $context['folder'] != 'sent' ? $txt['inbox'] : $txt['sent_items'], $txt['delete_all']);
  2476. }
  2477. /**
  2478. * Delete ALL the messages!
  2479. */
  2480. function MessageKillAll()
  2481. {
  2482. global $context;
  2483. checkSession('get');
  2484. // If all then delete all messages the user has.
  2485. if ($_REQUEST['f'] == 'all')
  2486. deleteMessages(null, null);
  2487. // Otherwise just the selected folder.
  2488. else
  2489. deleteMessages(null, $_REQUEST['f'] != 'sent' ? 'inbox' : 'sent');
  2490. // Done... all gone.
  2491. redirectexit($context['current_label_redirect']);
  2492. }
  2493. /**
  2494. * This function allows the user to delete all messages older than so many days.
  2495. */
  2496. function MessagePrune()
  2497. {
  2498. global $txt, $context, $user_info, $scripturl, $smcFunc;
  2499. // Actually delete the messages.
  2500. if (isset($_REQUEST['age']))
  2501. {
  2502. checkSession();
  2503. // Calculate the time to delete before.
  2504. $deleteTime = max(0, time() - (86400 * (int) $_REQUEST['age']));
  2505. // Array to store the IDs in.
  2506. $toDelete = array();
  2507. // Select all the messages they have sent older than $deleteTime.
  2508. $request = $smcFunc['db_query']('', '
  2509. SELECT id_pm
  2510. FROM {db_prefix}personal_messages
  2511. WHERE deleted_by_sender = {int:not_deleted}
  2512. AND id_member_from = {int:current_member}
  2513. AND msgtime < {int:msgtime}',
  2514. array(
  2515. 'current_member' => $user_info['id'],
  2516. 'not_deleted' => 0,
  2517. 'msgtime' => $deleteTime,
  2518. )
  2519. );
  2520. while ($row = $smcFunc['db_fetch_row']($request))
  2521. $toDelete[] = $row[0];
  2522. $smcFunc['db_free_result']($request);
  2523. // Select all messages in their inbox older than $deleteTime.
  2524. $request = $smcFunc['db_query']('', '
  2525. SELECT pmr.id_pm
  2526. FROM {db_prefix}pm_recipients AS pmr
  2527. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  2528. WHERE pmr.deleted = {int:not_deleted}
  2529. AND pmr.id_member = {int:current_member}
  2530. AND pm.msgtime < {int:msgtime}',
  2531. array(
  2532. 'current_member' => $user_info['id'],
  2533. 'not_deleted' => 0,
  2534. 'msgtime' => $deleteTime,
  2535. )
  2536. );
  2537. while ($row = $smcFunc['db_fetch_assoc']($request))
  2538. $toDelete[] = $row['id_pm'];
  2539. $smcFunc['db_free_result']($request);
  2540. // Delete the actual messages.
  2541. deleteMessages($toDelete);
  2542. // Go back to their inbox.
  2543. redirectexit($context['current_label_redirect']);
  2544. }
  2545. // Build the link tree elements.
  2546. $context['linktree'][] = array(
  2547. 'url' => $scripturl . '?action=pm;sa=prune',
  2548. 'name' => $txt['pm_prune']
  2549. );
  2550. $context['sub_template'] = 'prune';
  2551. $context['page_title'] = $txt['pm_prune'];
  2552. }
  2553. /**
  2554. * Delete the specified personal messages.
  2555. *
  2556. * @param array $personal_messages array of pm ids
  2557. * @param string $folder = null
  2558. * @param int $owner = null
  2559. */
  2560. function deleteMessages($personal_messages, $folder = null, $owner = null)
  2561. {
  2562. global $user_info, $smcFunc;
  2563. if ($owner === null)
  2564. $owner = array($user_info['id']);
  2565. elseif (empty($owner))
  2566. return;
  2567. elseif (!is_array($owner))
  2568. $owner = array($owner);
  2569. if ($personal_messages !== null)
  2570. {
  2571. if (empty($personal_messages) || !is_array($personal_messages))
  2572. return;
  2573. foreach ($personal_messages as $index => $delete_id)
  2574. $personal_messages[$index] = (int) $delete_id;
  2575. $where = '
  2576. AND id_pm IN ({array_int:pm_list})';
  2577. }
  2578. else
  2579. $where = '';
  2580. if ($folder == 'sent' || $folder === null)
  2581. {
  2582. $smcFunc['db_query']('', '
  2583. UPDATE {db_prefix}personal_messages
  2584. SET deleted_by_sender = {int:is_deleted}
  2585. WHERE id_member_from IN ({array_int:member_list})
  2586. AND deleted_by_sender = {int:not_deleted}' . $where,
  2587. array(
  2588. 'member_list' => $owner,
  2589. 'is_deleted' => 1,
  2590. 'not_deleted' => 0,
  2591. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2592. )
  2593. );
  2594. }
  2595. if ($folder != 'sent' || $folder === null)
  2596. {
  2597. // Calculate the number of messages each member's gonna lose...
  2598. $request = $smcFunc['db_query']('', '
  2599. SELECT id_member, COUNT(*) AS num_deleted_messages, CASE WHEN is_read & 1 >= 1 THEN 1 ELSE 0 END AS is_read
  2600. FROM {db_prefix}pm_recipients
  2601. WHERE id_member IN ({array_int:member_list})
  2602. AND deleted = {int:not_deleted}' . $where . '
  2603. GROUP BY id_member, is_read',
  2604. array(
  2605. 'member_list' => $owner,
  2606. 'not_deleted' => 0,
  2607. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2608. )
  2609. );
  2610. // ...And update the statistics accordingly - now including unread messages!.
  2611. while ($row = $smcFunc['db_fetch_assoc']($request))
  2612. {
  2613. if ($row['is_read'])
  2614. updateMemberData($row['id_member'], array('instant_messages' => $where == '' ? 0 : 'instant_messages - ' . $row['num_deleted_messages']));
  2615. else
  2616. updateMemberData($row['id_member'], array('instant_messages' => $where == '' ? 0 : 'instant_messages - ' . $row['num_deleted_messages'], 'unread_messages' => $where == '' ? 0 : 'unread_messages - ' . $row['num_deleted_messages']));
  2617. // If this is the current member we need to make their message count correct.
  2618. if ($user_info['id'] == $row['id_member'])
  2619. {
  2620. $user_info['messages'] -= $row['num_deleted_messages'];
  2621. if (!($row['is_read']))
  2622. $user_info['unread_messages'] -= $row['num_deleted_messages'];
  2623. }
  2624. }
  2625. $smcFunc['db_free_result']($request);
  2626. // Do the actual deletion.
  2627. $smcFunc['db_query']('', '
  2628. UPDATE {db_prefix}pm_recipients
  2629. SET deleted = {int:is_deleted}
  2630. WHERE id_member IN ({array_int:member_list})
  2631. AND deleted = {int:not_deleted}' . $where,
  2632. array(
  2633. 'member_list' => $owner,
  2634. 'is_deleted' => 1,
  2635. 'not_deleted' => 0,
  2636. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2637. )
  2638. );
  2639. $labels = array();
  2640. // Get any labels that the owner may have applied to this PM
  2641. // The join is here to ensure we only get labels applied by the specified member(s)
  2642. $get_labels = $smcFunc['db_query']('', '
  2643. SELECT pml.id_label
  2644. FROM {db_prefix}pm_labels AS l
  2645. INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_label = l.id_label)
  2646. WHERE l.id_member IN ({array_int:member_list})' . $where,
  2647. array(
  2648. 'member_list' => $owner,
  2649. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2650. )
  2651. );
  2652. while ($row = $smcFunc['db_fetch_assoc']($get_labels))
  2653. {
  2654. $labels[] = $row['id_label'];
  2655. }
  2656. $smcFunc['db_free_result']($get_labels);
  2657. if (!empty($labels))
  2658. {
  2659. $smcFunc['db_query']('', '
  2660. DELETE FROM {db_prefix}pm_labeled_messages
  2661. WHERE label_id IN ({array_int:labels})' . $where,
  2662. array(
  2663. 'labels' => $labels,
  2664. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2665. )
  2666. );
  2667. }
  2668. }
  2669. // If sender and recipients all have deleted their message, it can be removed.
  2670. $request = $smcFunc['db_query']('', '
  2671. SELECT pm.id_pm AS sender, pmr.id_pm
  2672. FROM {db_prefix}personal_messages AS pm
  2673. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm AND pmr.deleted = {int:not_deleted})
  2674. WHERE pm.deleted_by_sender = {int:is_deleted}
  2675. ' . str_replace('id_pm', 'pm.id_pm', $where) . '
  2676. GROUP BY sender, pmr.id_pm
  2677. HAVING pmr.id_pm IS null',
  2678. array(
  2679. 'not_deleted' => 0,
  2680. 'is_deleted' => 1,
  2681. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2682. )
  2683. );
  2684. $remove_pms = array();
  2685. while ($row = $smcFunc['db_fetch_assoc']($request))
  2686. $remove_pms[] = $row['sender'];
  2687. $smcFunc['db_free_result']($request);
  2688. if (!empty($remove_pms))
  2689. {
  2690. $smcFunc['db_query']('', '
  2691. DELETE FROM {db_prefix}personal_messages
  2692. WHERE id_pm IN ({array_int:pm_list})',
  2693. array(
  2694. 'pm_list' => $remove_pms,
  2695. )
  2696. );
  2697. $smcFunc['db_query']('', '
  2698. DELETE FROM {db_prefix}pm_recipients
  2699. WHERE id_pm IN ({array_int:pm_list})',
  2700. array(
  2701. 'pm_list' => $remove_pms,
  2702. )
  2703. );
  2704. $smcFunc['db_query']('', '
  2705. DELETE FROM {db_prefix}pm_labeled_messages
  2706. WHERE id_pm IN ({array_int:pm_list})',
  2707. array(
  2708. 'pm_list' => $remove_pms,
  2709. )
  2710. );
  2711. }
  2712. // Any cached numbers may be wrong now.
  2713. cache_put_data('labelCounts:' . $user_info['id'], null, 720);
  2714. }
  2715. /**
  2716. * Mark the specified personal messages read.
  2717. *
  2718. * @param array $personal_messages = null, array of pm ids
  2719. * @param string $label = null, if label is set, only marks messages with that label
  2720. * @param int $owner = null, if owner is set, marks messages owned by that member id
  2721. */
  2722. function markMessages($personal_messages = null, $label = null, $owner = null)
  2723. {
  2724. global $user_info, $context, $smcFunc;
  2725. if ($owner === null)
  2726. $owner = $user_info['id'];
  2727. $in_inbox = '';
  2728. // Marking all messages with a specific label as read?
  2729. // If we know which PMs we're marking read, then we don't need label info
  2730. if ($personal_messages === null && $label !== null && $label != '-1')
  2731. {
  2732. $personal_messages = array();
  2733. $get_messages = $smcFunc['db_query']('', '
  2734. SELECT id_pm
  2735. FROM {db_prefix}pm_labeled_messages
  2736. WHERE id_label = {int:current_label}',
  2737. array(
  2738. 'current_label' => $label,
  2739. )
  2740. );
  2741. while ($row = $smcFunc['db_fetch_assoc']($get_messages))
  2742. {
  2743. $personal_messages[] = $row['id_pm'];
  2744. }
  2745. $smcFunc['db_free_result']($get_messages);
  2746. }
  2747. elseif ($label = '-1')
  2748. {
  2749. // Marking all PMs in your inbox read
  2750. $in_inbox = '
  2751. AND in_inbox = {int:in_inbox}';
  2752. }
  2753. $smcFunc['db_query']('', '
  2754. UPDATE {db_prefix}pm_recipients
  2755. SET is_read = is_read | 1
  2756. WHERE id_member = {int:id_member}
  2757. AND NOT (is_read & 1 >= 1)' . ($personal_messages !== null ? '
  2758. AND id_pm IN ({array_int:personal_messages})' : '') . $in_inbox,
  2759. array(
  2760. 'personal_messages' => $personal_messages,
  2761. 'id_member' => $owner,
  2762. 'in_inbox' => 1,
  2763. )
  2764. );
  2765. // If something wasn't marked as read, get the number of unread messages remaining.
  2766. if ($smcFunc['db_affected_rows']() > 0)
  2767. {
  2768. if ($owner == $user_info['id'])
  2769. {
  2770. foreach ($context['labels'] as $label)
  2771. $context['labels'][(int) $label['id']]['unread_messages'] = 0;
  2772. }
  2773. $result = $smcFunc['db_query']('', '
  2774. SELECT id_pm, in_inbox, COUNT(*) AS num
  2775. FROM {db_prefix}pm_recipients
  2776. WHERE id_member = {int:id_member}
  2777. AND NOT (is_read & 1 >= 1)
  2778. AND deleted = {int:is_not_deleted}',
  2779. array(
  2780. 'id_member' => $owner,
  2781. 'is_not_deleted' => 0,
  2782. )
  2783. );
  2784. $total_unread = 0;
  2785. while ($row = $smcFunc['db_fetch_assoc']($result))
  2786. {
  2787. $total_unread += $row['num'];
  2788. if ($owner != $user_info['id'] || empty($row['id_pm']))
  2789. continue;
  2790. $this_labels = array();
  2791. // Get all the labels
  2792. $result2 = $smcFunc['db_query']('', '
  2793. SELECT pml.id_label
  2794. FROM {db_prefix}pm_labels AS l
  2795. INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_label = l.id_label)
  2796. WHERE l.id_member = {int:id_member}
  2797. AND pml.id_pm = {int:current_pm}',
  2798. array(
  2799. 'id_member' => $owner,
  2800. 'current_pm' => $row['id_pm'],
  2801. )
  2802. );
  2803. while ($row2 = $smcFunc['db_fetch_assoc']($result2))
  2804. {
  2805. $this_labels[] = $row2['id_label'];
  2806. }
  2807. $smcFunc['db_free_result']($result2);
  2808. foreach ($this_labels as $this_label)
  2809. $context['labels'][$this_label]['unread_messages'] += $row['num'];
  2810. if ($row['in_inbox'] == 1)
  2811. $context['labels'][-1]['unread_messages'] += $row['num'];
  2812. }
  2813. $smcFunc['db_free_result']($result);
  2814. // Need to store all this.
  2815. cache_put_data('labelCounts:' . $owner, $context['labels'], 720);
  2816. updateMemberData($owner, array('unread_messages' => $total_unread));
  2817. // If it was for the current member, reflect this in the $user_info array too.
  2818. if ($owner == $user_info['id'])
  2819. $user_info['unread_messages'] = $total_unread;
  2820. }
  2821. }
  2822. /**
  2823. * This function handles adding, deleting and editing labels on messages.
  2824. */
  2825. function ManageLabels()
  2826. {
  2827. global $txt, $context, $user_info, $scripturl, $smcFunc;
  2828. // Build the link tree elements...
  2829. $context['linktree'][] = array(
  2830. 'url' => $scripturl . '?action=pm;sa=manlabels',
  2831. 'name' => $txt['pm_manage_labels']
  2832. );
  2833. $context['page_title'] = $txt['pm_manage_labels'];
  2834. $context['sub_template'] = 'labels';
  2835. $the_labels = array();
  2836. $labels_to_add = array();
  2837. $labels_to_remove = array();
  2838. $label_updates = array();
  2839. // Add all existing labels to the array to save, slashing them as necessary...
  2840. foreach ($context['labels'] as $label)
  2841. {
  2842. if ($label['id'] != -1)
  2843. $the_labels[$label['id']] = $label['name'];
  2844. }
  2845. if (isset($_POST[$context['session_var']]))
  2846. {
  2847. checkSession();
  2848. // This will be for updating messages.
  2849. $message_changes = array();
  2850. $rule_changes = array();
  2851. // Will most likely need this.
  2852. LoadRules();
  2853. // Adding a new label?
  2854. if (isset($_POST['add']))
  2855. {
  2856. $_POST['label'] = strtr($smcFunc['htmlspecialchars'](trim($_POST['label'])), array(',' => '&#044;'));
  2857. if ($smcFunc['strlen']($_POST['label']) > 30)
  2858. $_POST['label'] = $smcFunc['substr']($_POST['label'], 0, 30);
  2859. if ($_POST['label'] != '')
  2860. {
  2861. $the_labels[] = $_POST['label'];
  2862. $labels_to_add[] = $_POST['label'];
  2863. }
  2864. }
  2865. // Deleting an existing label?
  2866. elseif (isset($_POST['delete'], $_POST['delete_label']))
  2867. {
  2868. foreach ($_POST['delete_label'] AS $label => $dummy)
  2869. {
  2870. unset($the_labels[$label]);
  2871. $labels_to_remove[] = $label;
  2872. }
  2873. }
  2874. // The hardest one to deal with... changes.
  2875. elseif (isset($_POST['save']) && !empty($_POST['label_name']))
  2876. {
  2877. foreach ($the_labels as $id => $name)
  2878. {
  2879. if ($id == -1)
  2880. continue;
  2881. elseif (isset($_POST['label_name'][$id]))
  2882. {
  2883. $_POST['label_name'][$id] = trim(strtr($smcFunc['htmlspecialchars']($_POST['label_name'][$id]), array(',' => '&#044;')));
  2884. if ($smcFunc['strlen']($_POST['label_name'][$id]) > 30)
  2885. $_POST['label_name'][$id] = $smcFunc['substr']($_POST['label_name'][$id], 0, 30);
  2886. if ($_POST['label_name'][$id] != '')
  2887. {
  2888. // Changing the name of this label?
  2889. if ($the_labels[$id] != $_POST['label_name'][$id])
  2890. $label_updates[$id] = $_POST['label_name'][$id];
  2891. $the_labels[(int) $id] = $_POST['label_name'][$id];
  2892. }
  2893. else
  2894. {
  2895. unset($the_labels[(int) $id]);
  2896. $labels_to_remove[] = $id;
  2897. $message_changes[(int) $id] = true;
  2898. }
  2899. }
  2900. }
  2901. }
  2902. // Save any new labels
  2903. if (!empty($labels_to_add))
  2904. {
  2905. $inserts = array();
  2906. foreach ($labels_to_add AS $label)
  2907. $inserts[] = array($user_info['id'], $label);
  2908. $smcFunc['db_insert']('', '{db_prefix}pm_labels', array('id_member' => 'int', 'name' => 'string-30'), $inserts, array());
  2909. }
  2910. // Update existing labels as needed
  2911. if (!empty($label_upates))
  2912. {
  2913. foreach ($label_updates AS $id => $name)
  2914. {
  2915. $smcFunc['db_query']('', '
  2916. UPDATE {db_prefix}labels
  2917. SET name = {string:name}
  2918. WHERE id_label = {int:id_label}',
  2919. array(
  2920. 'name' => $name,
  2921. 'id' => $id
  2922. )
  2923. );
  2924. }
  2925. }
  2926. // Now the fun part... Deleting labels.
  2927. if (!empty($labels_to_remove))
  2928. {
  2929. // First delete the labels
  2930. $smcFunc['db_query']('', '
  2931. DELETE FROM {db_prefix}pm_labels
  2932. WHERE id_label IN ({array_int:labels_to_delete})',
  2933. array(
  2934. 'labels_to_delete' => $labels_to_remove,
  2935. )
  2936. );
  2937. // Now remove the now-deleted labels from any PMs...
  2938. $smcFunc['db_query']('', '
  2939. DELETE FROM {db_prefix}pm_labeled_messages
  2940. WHERE id_label IN ({array_int:labels_to_delete})',
  2941. array(
  2942. 'labels_to_delete' => $labels_to_remove,
  2943. )
  2944. );
  2945. // Get any PMs with no labels which aren't in the inbox
  2946. $get_stranded_pms = $smcFunc['db_query']('', '
  2947. SELECT pmr.id_pm
  2948. FROM {db_prefix}pm_recipients AS pmr
  2949. LEFT JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_pm = pmr.id_pm)
  2950. WHERE pml.id_label IS NULL
  2951. AND pmr.in_inbox = {int:not_in_inbox}
  2952. AND pmr.deleted = {int:not_deleted}
  2953. AND pmr.id_member = {int:current_member}',
  2954. array(
  2955. 'not_in_inbox' => 0,
  2956. 'not_deleted' => 0,
  2957. 'current_member' => $user_info['id'],
  2958. )
  2959. );
  2960. $stranded_messages = array();
  2961. while ($row = $smcFunc['db_fetch_assoc']($get_stranded_pms))
  2962. {
  2963. $stranded_messages[] = $row['id_pm'];
  2964. }
  2965. $smcFunc['db_free_result']($get_stranded_pms);
  2966. // Move these back to the inbox if necessary
  2967. if (!empty($stranded_messages))
  2968. {
  2969. // We now have more messages in the inbox
  2970. $context['labels'][-1]['messages'] += count($stranded_messages);
  2971. $smcFunc['db_query']('', '
  2972. UPDATE {db_prefix}pm_recipients
  2973. SET in_inbox = {int:in_inbox}
  2974. WHERE id_pm IN ({array_int:stranded_messages})
  2975. AND id_member = {int:current_member}',
  2976. array(
  2977. 'stranded_messages' => $stranded_messages,
  2978. 'in_inbox' => 1,
  2979. )
  2980. );
  2981. }
  2982. // Now do the same the rules - check through each rule.
  2983. foreach ($context['rules'] as $k => $rule)
  2984. {
  2985. // Each action...
  2986. foreach ($rule['actions'] as $k2 => $action)
  2987. {
  2988. if ($action['t'] != 'lab' || !in_array($action['v'], $labels_to_remove))
  2989. continue;
  2990. $rule_changes[] = $rule['id'];
  2991. // Can't apply this label anymore if it doesn't exist
  2992. unset($context['rules'][$k]['actions'][$k2]);
  2993. }
  2994. }
  2995. }
  2996. // If we have rules to change do so now.
  2997. if (!empty($rule_changes))
  2998. {
  2999. $rule_changes = array_unique($rule_changes);
  3000. // Update/delete as appropriate.
  3001. foreach ($rule_changes as $k => $id)
  3002. if (!empty($context['rules'][$id]['actions']))
  3003. {
  3004. $smcFunc['db_query']('', '
  3005. UPDATE {db_prefix}pm_rules
  3006. SET actions = {string:actions}
  3007. WHERE id_rule = {int:id_rule}
  3008. AND id_member = {int:current_member}',
  3009. array(
  3010. 'current_member' => $user_info['id'],
  3011. 'id_rule' => $id,
  3012. 'actions' => serialize($context['rules'][$id]['actions']),
  3013. )
  3014. );
  3015. unset($rule_changes[$k]);
  3016. }
  3017. // Anything left here means it's lost all actions...
  3018. if (!empty($rule_changes))
  3019. $smcFunc['db_query']('', '
  3020. DELETE FROM {db_prefix}pm_rules
  3021. WHERE id_rule IN ({array_int:rule_list})
  3022. AND id_member = {int:current_member}',
  3023. array(
  3024. 'current_member' => $user_info['id'],
  3025. 'rule_list' => $rule_changes,
  3026. )
  3027. );
  3028. }
  3029. // Make sure we're not caching this!
  3030. cache_put_data('labelCounts:' . $user_info['id'], null, 720);
  3031. // To make the changes appear right away, redirect.
  3032. redirectexit('action=pm;sa=manlabels');
  3033. }
  3034. }
  3035. /**
  3036. * Allows to edit Personal Message Settings.
  3037. *
  3038. * @uses Profile.php
  3039. * @uses Profile-Modify.php
  3040. * @uses Profile template.
  3041. * @uses Profile language file.
  3042. */
  3043. function MessageSettings()
  3044. {
  3045. global $txt, $user_settings, $user_info, $context, $sourcedir, $smcFunc;
  3046. global $scripturl, $profile_vars, $cur_profile, $user_profile;
  3047. // Need this for the display.
  3048. require_once($sourcedir . '/Profile.php');
  3049. require_once($sourcedir . '/Profile-Modify.php');
  3050. // We want them to submit back to here.
  3051. $context['profile_custom_submit_url'] = $scripturl . '?action=pm;sa=settings;save';
  3052. loadMemberData($user_info['id'], false, 'profile');
  3053. $cur_profile = $user_profile[$user_info['id']];
  3054. loadLanguage('Profile');
  3055. loadTemplate('Profile');
  3056. // Since this is internally handled with the profile code because that's how it was done ages ago
  3057. // we have to set everything up for handling this...
  3058. $context['page_title'] = $txt['pm_settings'];
  3059. $context['user']['is_owner'] = true;
  3060. $context['id_member'] = $user_info['id'];
  3061. $context['require_password'] = false;
  3062. $context['menu_item_selected'] = 'settings';
  3063. $context['submit_button_text'] = $txt['pm_settings'];
  3064. $context['profile_header_text'] = $txt['personal_messages'];
  3065. $context['sub_template'] = 'edit_options';
  3066. $context['page_desc'] = $txt['pm_settings_desc'];
  3067. loadThemeOptions($user_info['id']);
  3068. loadCustomFields($user_info['id'], 'pmprefs');
  3069. // Add our position to the linktree.
  3070. $context['linktree'][] = array(
  3071. 'url' => $scripturl . '?action=pm;sa=settings',
  3072. 'name' => $txt['pm_settings']
  3073. );
  3074. // Are they saving?
  3075. if (isset($_REQUEST['save']))
  3076. {
  3077. checkSession();
  3078. // Mimic what profile would do.
  3079. $_POST = htmltrim__recursive($_POST);
  3080. $_POST = htmlspecialchars__recursive($_POST);
  3081. // Save the fields.
  3082. saveProfileFields();
  3083. if (!empty($profile_vars))
  3084. updateMemberData($user_info['id'], $profile_vars);
  3085. }
  3086. setupProfileContext(
  3087. array(
  3088. 'pm_prefs',
  3089. )
  3090. );
  3091. }
  3092. /**
  3093. * Allows the user to report a personal message to an administrator.
  3094. *
  3095. * - In the first instance requires that the ID of the message to report is passed through $_GET.
  3096. * - It allows the user to report to either a particular administrator - or the whole admin team.
  3097. * - It will forward on a copy of the original message without allowing the reporter to make changes.
  3098. *
  3099. * @uses report_message sub-template.
  3100. */
  3101. function ReportMessage()
  3102. {
  3103. global $txt, $context, $scripturl, $sourcedir;
  3104. global $user_info, $language, $modSettings, $smcFunc;
  3105. // Check that this feature is even enabled!
  3106. if (empty($modSettings['enableReportPM']) || empty($_REQUEST['pmsg']))
  3107. fatal_lang_error('no_access', false);
  3108. $pmsg = (int) $_REQUEST['pmsg'];
  3109. if (!isAccessiblePM($pmsg, 'inbox'))
  3110. fatal_lang_error('no_access', false);
  3111. $context['pm_id'] = $pmsg;
  3112. $context['page_title'] = $txt['pm_report_title'];
  3113. // If we're here, just send the user to the template, with a few useful context bits.
  3114. if (!isset($_POST['report']))
  3115. {
  3116. $context['sub_template'] = 'report_message';
  3117. // @todo I don't like being able to pick who to send it to. Favoritism, etc. sucks.
  3118. // Now, get all the administrators.
  3119. $request = $smcFunc['db_query']('', '
  3120. SELECT id_member, real_name
  3121. FROM {db_prefix}members
  3122. WHERE id_group = {int:admin_group} OR FIND_IN_SET({int:admin_group}, additional_groups) != 0
  3123. ORDER BY real_name',
  3124. array(
  3125. 'admin_group' => 1,
  3126. )
  3127. );
  3128. $context['admins'] = array();
  3129. while ($row = $smcFunc['db_fetch_assoc']($request))
  3130. $context['admins'][$row['id_member']] = $row['real_name'];
  3131. $smcFunc['db_free_result']($request);
  3132. // How many admins in total?
  3133. $context['admin_count'] = count($context['admins']);
  3134. }
  3135. // Otherwise, let's get down to the sending stuff.
  3136. else
  3137. {
  3138. // Check the session before proceeding any further!
  3139. checkSession();
  3140. // First, pull out the message contents, and verify it actually went to them!
  3141. $request = $smcFunc['db_query']('', '
  3142. SELECT pm.subject, pm.body, pm.msgtime, pm.id_member_from, IFNULL(m.real_name, pm.from_name) AS sender_name
  3143. FROM {db_prefix}personal_messages AS pm
  3144. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)
  3145. LEFT JOIN {db_prefix}members AS m ON (m.id_member = pm.id_member_from)
  3146. WHERE pm.id_pm = {int:id_pm}
  3147. AND pmr.id_member = {int:current_member}
  3148. AND pmr.deleted = {int:not_deleted}
  3149. LIMIT 1',
  3150. array(
  3151. 'current_member' => $user_info['id'],
  3152. 'id_pm' => $context['pm_id'],
  3153. 'not_deleted' => 0,
  3154. )
  3155. );
  3156. // Can only be a hacker here!
  3157. if ($smcFunc['db_num_rows']($request) == 0)
  3158. fatal_lang_error('no_access', false);
  3159. list ($subject, $body, $time, $memberFromID, $memberFromName) = $smcFunc['db_fetch_row']($request);
  3160. $smcFunc['db_free_result']($request);
  3161. // Remove the line breaks...
  3162. $body = preg_replace('~<br ?/?' . '>~i', "\n", $body);
  3163. // Get any other recipients of the email.
  3164. $request = $smcFunc['db_query']('', '
  3165. SELECT mem_to.id_member AS id_member_to, mem_to.real_name AS to_name, pmr.bcc
  3166. FROM {db_prefix}pm_recipients AS pmr
  3167. LEFT JOIN {db_prefix}members AS mem_to ON (mem_to.id_member = pmr.id_member)
  3168. WHERE pmr.id_pm = {int:id_pm}
  3169. AND pmr.id_member != {int:current_member}',
  3170. array(
  3171. 'current_member' => $user_info['id'],
  3172. 'id_pm' => $context['pm_id'],
  3173. )
  3174. );
  3175. $recipients = array();
  3176. $hidden_recipients = 0;
  3177. while ($row = $smcFunc['db_fetch_assoc']($request))
  3178. {
  3179. // If it's hidden still don't reveal their names - privacy after all ;)
  3180. if ($row['bcc'])
  3181. $hidden_recipients++;
  3182. else
  3183. $recipients[] = '[url=' . $scripturl . '?action=profile;u=' . $row['id_member_to'] . ']' . $row['to_name'] . '[/url]';
  3184. }
  3185. $smcFunc['db_free_result']($request);
  3186. if ($hidden_recipients)
  3187. $recipients[] = sprintf($txt['pm_report_pm_hidden'], $hidden_recipients);
  3188. // Now let's get out and loop through the admins.
  3189. $request = $smcFunc['db_query']('', '
  3190. SELECT id_member, real_name, lngfile
  3191. FROM {db_prefix}members
  3192. WHERE (id_group = {int:admin_id} OR FIND_IN_SET({int:admin_id}, additional_groups) != 0)
  3193. ' . (empty($_POST['id_admin']) ? '' : 'AND id_member = {int:specific_admin}') . '
  3194. ORDER BY lngfile',
  3195. array(
  3196. 'admin_id' => 1,
  3197. 'specific_admin' => isset($_POST['id_admin']) ? (int) $_POST['id_admin'] : 0,
  3198. )
  3199. );
  3200. // Maybe we shouldn't advertise this?
  3201. if ($smcFunc['db_num_rows']($request) == 0)
  3202. fatal_lang_error('no_access', false);
  3203. $memberFromName = un_htmlspecialchars($memberFromName);
  3204. // Prepare the message storage array.
  3205. $messagesToSend = array();
  3206. // Loop through each admin, and add them to the right language pile...
  3207. while ($row = $smcFunc['db_fetch_assoc']($request))
  3208. {
  3209. // Need to send in the correct language!
  3210. $cur_language = empty($row['lngfile']) || empty($modSettings['userLanguage']) ? $language : $row['lngfile'];
  3211. if (!isset($messagesToSend[$cur_language]))
  3212. {
  3213. loadLanguage('PersonalMessage', $cur_language, false);
  3214. // Make the body.
  3215. $report_body = str_replace(array('{REPORTER}', '{SENDER}'), array(un_htmlspecialchars($user_info['name']), $memberFromName), $txt['pm_report_pm_user_sent']);
  3216. $report_body .= "\n" . '[b]' . $_POST['reason'] . '[/b]' . "\n\n";
  3217. if (!empty($recipients))
  3218. $report_body .= $txt['pm_report_pm_other_recipients'] . ' ' . implode(', ', $recipients) . "\n\n";
  3219. $report_body .= $txt['pm_report_pm_unedited_below'] . "\n" . '[quote author=' . (empty($memberFromID) ? '&quot;' . $memberFromName . '&quot;' : $memberFromName . ' link=action=profile;u=' . $memberFromID . ' date=' . $time) . ']' . "\n" . un_htmlspecialchars($body) . '[/quote]';
  3220. // Plonk it in the array ;)
  3221. $messagesToSend[$cur_language] = array(
  3222. 'subject' => ($smcFunc['strpos']($subject, $txt['pm_report_pm_subject']) === false ? $txt['pm_report_pm_subject'] : '') . un_htmlspecialchars($subject),
  3223. 'body' => $report_body,
  3224. 'recipients' => array(
  3225. 'to' => array(),
  3226. 'bcc' => array()
  3227. ),
  3228. );
  3229. }
  3230. // Add them to the list.
  3231. $messagesToSend[$cur_language]['recipients']['to'][$row['id_member']] = $row['id_member'];
  3232. }
  3233. $smcFunc['db_free_result']($request);
  3234. // Send a different email for each language.
  3235. foreach ($messagesToSend as $lang => $message)
  3236. sendpm($message['recipients'], $message['subject'], $message['body']);
  3237. // Give the user their own language back!
  3238. if (!empty($modSettings['userLanguage']))
  3239. loadLanguage('PersonalMessage', '', false);
  3240. // Leave them with a template.
  3241. $context['sub_template'] = 'report_message_complete';
  3242. }
  3243. }
  3244. /**
  3245. * List all rules, and allow adding/entering etc...
  3246. */
  3247. function ManageRules()
  3248. {
  3249. global $txt, $context, $user_info, $scripturl, $smcFunc;
  3250. // The link tree - gotta have this :o
  3251. $context['linktree'][] = array(
  3252. 'url' => $scripturl . '?action=pm;sa=manrules',
  3253. 'name' => $txt['pm_manage_rules']
  3254. );
  3255. $context['page_title'] = $txt['pm_manage_rules'];
  3256. $context['sub_template'] = 'rules';
  3257. // Load them... load them!!
  3258. LoadRules();
  3259. // Likely to need all the groups!
  3260. $request = $smcFunc['db_query']('', '
  3261. SELECT mg.id_group, mg.group_name, IFNULL(gm.id_member, 0) AS can_moderate, mg.hidden
  3262. FROM {db_prefix}membergroups AS mg
  3263. LEFT JOIN {db_prefix}group_moderators AS gm ON (gm.id_group = mg.id_group AND gm.id_member = {int:current_member})
  3264. WHERE mg.min_posts = {int:min_posts}
  3265. AND mg.id_group != {int:moderator_group}
  3266. AND mg.hidden = {int:not_hidden}
  3267. ORDER BY mg.group_name',
  3268. array(
  3269. 'current_member' => $user_info['id'],
  3270. 'min_posts' => -1,
  3271. 'moderator_group' => 3,
  3272. 'not_hidden' => 0,
  3273. )
  3274. );
  3275. $context['groups'] = array();
  3276. while ($row = $smcFunc['db_fetch_assoc']($request))
  3277. {
  3278. // Hide hidden groups!
  3279. if ($row['hidden'] && !$row['can_moderate'] && !allowedTo('manage_membergroups'))
  3280. continue;
  3281. $context['groups'][$row['id_group']] = $row['group_name'];
  3282. }
  3283. $smcFunc['db_free_result']($request);
  3284. // Applying all rules?
  3285. if (isset($_GET['apply']))
  3286. {
  3287. checkSession('get');
  3288. ApplyRules(true);
  3289. redirectexit('action=pm;sa=manrules');
  3290. }
  3291. // Editing a specific one?
  3292. if (isset($_GET['add']))
  3293. {
  3294. $context['rid'] = isset($_GET['rid']) && isset($context['rules'][$_GET['rid']])? (int) $_GET['rid'] : 0;
  3295. $context['sub_template'] = 'add_rule';
  3296. // Current rule information...
  3297. if ($context['rid'])
  3298. {
  3299. $context['rule'] = $context['rules'][$context['rid']];
  3300. $members = array();
  3301. // Need to get member names!
  3302. foreach ($context['rule']['criteria'] as $k => $criteria)
  3303. if ($criteria['t'] == 'mid' && !empty($criteria['v']))
  3304. $members[(int) $criteria['v']] = $k;
  3305. if (!empty($members))
  3306. {
  3307. $request = $smcFunc['db_query']('', '
  3308. SELECT id_member, member_name
  3309. FROM {db_prefix}members
  3310. WHERE id_member IN ({array_int:member_list})',
  3311. array(
  3312. 'member_list' => array_keys($members),
  3313. )
  3314. );
  3315. while ($row = $smcFunc['db_fetch_assoc']($request))
  3316. $context['rule']['criteria'][$members[$row['id_member']]]['v'] = $row['member_name'];
  3317. $smcFunc['db_free_result']($request);
  3318. }
  3319. }
  3320. else
  3321. $context['rule'] = array(
  3322. 'id' => '',
  3323. 'name' => '',
  3324. 'criteria' => array(),
  3325. 'actions' => array(),
  3326. 'logic' => 'and',
  3327. );
  3328. }
  3329. // Saving?
  3330. elseif (isset($_GET['save']))
  3331. {
  3332. checkSession();
  3333. $context['rid'] = isset($_GET['rid']) && isset($context['rules'][$_GET['rid']])? (int) $_GET['rid'] : 0;
  3334. // Name is easy!
  3335. $ruleName = $smcFunc['htmlspecialchars'](trim($_POST['rule_name']));
  3336. if (empty($ruleName))
  3337. fatal_lang_error('pm_rule_no_name', false);
  3338. // Sanity check...
  3339. if (empty($_POST['ruletype']) || empty($_POST['acttype']))
  3340. fatal_lang_error('pm_rule_no_criteria', false);
  3341. // Let's do the criteria first - it's also hardest!
  3342. $criteria = array();
  3343. foreach ($_POST['ruletype'] as $ind => $type)
  3344. {
  3345. // Check everything is here...
  3346. if ($type == 'gid' && (!isset($_POST['ruledefgroup'][$ind]) || !isset($context['groups'][$_POST['ruledefgroup'][$ind]])))
  3347. continue;
  3348. elseif ($type != 'bud' && !isset($_POST['ruledef'][$ind]))
  3349. continue;
  3350. // Members need to be found.
  3351. if ($type == 'mid')
  3352. {
  3353. $name = trim($_POST['ruledef'][$ind]);
  3354. $request = $smcFunc['db_query']('', '
  3355. SELECT id_member
  3356. FROM {db_prefix}members
  3357. WHERE real_name = {string:member_name}
  3358. OR member_name = {string:member_name}',
  3359. array(
  3360. 'member_name' => $name,
  3361. )
  3362. );
  3363. if ($smcFunc['db_num_rows']($request) == 0)
  3364. continue;
  3365. list ($memID) = $smcFunc['db_fetch_row']($request);
  3366. $smcFunc['db_free_result']($request);
  3367. $criteria[] = array('t' => 'mid', 'v' => $memID);
  3368. }
  3369. elseif ($type == 'bud')
  3370. $criteria[] = array('t' => 'bud', 'v' => 1);
  3371. elseif ($type == 'gid')
  3372. $criteria[] = array('t' => 'gid', 'v' => (int) $_POST['ruledefgroup'][$ind]);
  3373. elseif (in_array($type, array('sub', 'msg')) && trim($_POST['ruledef'][$ind]) != '')
  3374. $criteria[] = array('t' => $type, 'v' => $smcFunc['htmlspecialchars'](trim($_POST['ruledef'][$ind])));
  3375. }
  3376. // Also do the actions!
  3377. $actions = array();
  3378. $doDelete = 0;
  3379. $isOr = $_POST['rule_logic'] == 'or' ? 1 : 0;
  3380. foreach ($_POST['acttype'] as $ind => $type)
  3381. {
  3382. // Picking a valid label?
  3383. if ($type == 'lab' && (!isset($_POST['labdef'][$ind]) || !isset($context['labels'][$_POST['labdef'][$ind]])))
  3384. continue;
  3385. // Record what we're doing.
  3386. if ($type == 'del')
  3387. $doDelete = 1;
  3388. elseif ($type == 'lab')
  3389. $actions[] = array('t' => 'lab', 'v' => (int) $_POST['labdef'][$ind]);
  3390. }
  3391. if (empty($criteria) || (empty($actions) && !$doDelete))
  3392. fatal_lang_error('pm_rule_no_criteria', false);
  3393. // What are we storing?
  3394. $criteria = serialize($criteria);
  3395. $actions = serialize($actions);
  3396. // Create the rule?
  3397. if (empty($context['rid']))
  3398. $smcFunc['db_insert']('',
  3399. '{db_prefix}pm_rules',
  3400. array(
  3401. 'id_member' => 'int', 'rule_name' => 'string', 'criteria' => 'string', 'actions' => 'string',
  3402. 'delete_pm' => 'int', 'is_or' => 'int',
  3403. ),
  3404. array(
  3405. $user_info['id'], $ruleName, $criteria, $actions, $doDelete, $isOr,
  3406. ),
  3407. array('id_rule')
  3408. );
  3409. else
  3410. $smcFunc['db_query']('', '
  3411. UPDATE {db_prefix}pm_rules
  3412. SET rule_name = {string:rule_name}, criteria = {string:criteria}, actions = {string:actions},
  3413. delete_pm = {int:delete_pm}, is_or = {int:is_or}
  3414. WHERE id_rule = {int:id_rule}
  3415. AND id_member = {int:current_member}',
  3416. array(
  3417. 'current_member' => $user_info['id'],
  3418. 'delete_pm' => $doDelete,
  3419. 'is_or' => $isOr,
  3420. 'id_rule' => $context['rid'],
  3421. 'rule_name' => $ruleName,
  3422. 'criteria' => $criteria,
  3423. 'actions' => $actions,
  3424. )
  3425. );
  3426. redirectexit('action=pm;sa=manrules');
  3427. }
  3428. // Deleting?
  3429. elseif (isset($_POST['delselected']) && !empty($_POST['delrule']))
  3430. {
  3431. checkSession();
  3432. $toDelete = array();
  3433. foreach ($_POST['delrule'] as $k => $v)
  3434. $toDelete[] = (int) $k;
  3435. if (!empty($toDelete))
  3436. $smcFunc['db_query']('', '
  3437. DELETE FROM {db_prefix}pm_rules
  3438. WHERE id_rule IN ({array_int:delete_list})
  3439. AND id_member = {int:current_member}',
  3440. array(
  3441. 'current_member' => $user_info['id'],
  3442. 'delete_list' => $toDelete,
  3443. )
  3444. );
  3445. redirectexit('action=pm;sa=manrules');
  3446. }
  3447. }
  3448. /**
  3449. * This will apply rules to all unread messages. If all_messages is set will, clearly, do it to all!
  3450. *
  3451. * @param bool $all_messages = false
  3452. */
  3453. function ApplyRules($all_messages = false)
  3454. {
  3455. global $user_info, $smcFunc, $context, $options;
  3456. // Want this - duh!
  3457. loadRules();
  3458. // No rules?
  3459. if (empty($context['rules']))
  3460. return;
  3461. // Just unread ones?
  3462. $ruleQuery = $all_messages ? '' : ' AND pmr.is_new = 1';
  3463. // @todo Apply all should have timeout protection!
  3464. // Get all the messages that match this.
  3465. $request = $smcFunc['db_query']('', '
  3466. SELECT
  3467. pmr.id_pm, pm.id_member_from, pm.subject, pm.body, mem.id_group
  3468. FROM {db_prefix}pm_recipients AS pmr
  3469. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  3470. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  3471. WHERE pmr.id_member = {int:current_member}
  3472. AND pmr.deleted = {int:not_deleted}
  3473. ' . $ruleQuery,
  3474. array(
  3475. 'current_member' => $user_info['id'],
  3476. 'not_deleted' => 0,
  3477. )
  3478. );
  3479. $actions = array();
  3480. while ($row = $smcFunc['db_fetch_assoc']($request))
  3481. {
  3482. foreach ($context['rules'] as $rule)
  3483. {
  3484. $match = false;
  3485. // Loop through all the criteria hoping to make a match.
  3486. foreach ($rule['criteria'] as $criterium)
  3487. {
  3488. if (($criterium['t'] == 'mid' && $criterium['v'] == $row['id_member_from']) || ($criterium['t'] == 'gid' && $criterium['v'] == $row['id_group']) || ($criterium['t'] == 'sub' && strpos($row['subject'], $criterium['v']) !== false) || ($criterium['t'] == 'msg' && strpos($row['body'], $criterium['v']) !== false))
  3489. $match = true;
  3490. // If we're adding and one criteria don't match then we stop!
  3491. elseif ($rule['logic'] == 'and')
  3492. {
  3493. $match = false;
  3494. break;
  3495. }
  3496. }
  3497. // If we have a match the rule must be true - act!
  3498. if ($match)
  3499. {
  3500. if ($rule['delete'])
  3501. $actions['deletes'][] = $row['id_pm'];
  3502. else
  3503. {
  3504. foreach ($rule['actions'] as $ruleAction)
  3505. {
  3506. if ($ruleAction['t'] == 'lab')
  3507. {
  3508. // Get a basic pot started!
  3509. if (!isset($actions['labels'][$row['id_pm']]))
  3510. $actions['labels'][$row['id_pm']] = array();
  3511. $actions['labels'][$row['id_pm']][] = $ruleAction['v'];
  3512. }
  3513. }
  3514. }
  3515. }
  3516. }
  3517. }
  3518. $smcFunc['db_free_result']($request);
  3519. // Deletes are easy!
  3520. if (!empty($actions['deletes']))
  3521. deleteMessages($actions['deletes']);
  3522. // Relabel?
  3523. if (!empty($actions['labels']))
  3524. {
  3525. foreach ($actions['labels'] as $pm => $labels)
  3526. {
  3527. // Quickly check each label is valid!
  3528. $realLabels = array();
  3529. foreach ($context['labels'] as $label)
  3530. {
  3531. if (in_array($label['id'], $labels) && $label['id'] != -1 || empty($options['pm_remove_inbox_label']))
  3532. {
  3533. // Make sure this stays in the inbox
  3534. if ($label['id'] == '-1')
  3535. {
  3536. $smcFunc['db_query']('', '
  3537. UPDATE {db_prefix}pm_recipients
  3538. SET in_inbox = {int:in_inbox}
  3539. WHERE id_pm = {int:id_pm}
  3540. AND id_member = {int:current_member}',
  3541. array(
  3542. 'in_inbox' => 1,
  3543. 'id_pm' => $pm,
  3544. 'current_member' => $user_info['id'],
  3545. )
  3546. );
  3547. }
  3548. else
  3549. {
  3550. $realLabels[] = $label['id'];
  3551. }
  3552. }
  3553. }
  3554. $inserts = array();
  3555. // Now we insert the label info
  3556. foreach ($realLabels as $a_label)
  3557. $inserts[] = array($pm, $a_label);
  3558. $smcFunc['db_insert']('',
  3559. '{db_prefix}pm_labeled_messages',
  3560. array('id_pm' => 'int', 'id_label' => 'int'),
  3561. $inserts,
  3562. array()
  3563. );
  3564. }
  3565. }
  3566. }
  3567. /**
  3568. * Load up all the rules for the current user.
  3569. *
  3570. * @param bool $reload = false
  3571. */
  3572. function LoadRules($reload = false)
  3573. {
  3574. global $user_info, $context, $smcFunc;
  3575. if (isset($context['rules']) && !$reload)
  3576. return;
  3577. $request = $smcFunc['db_query']('', '
  3578. SELECT
  3579. id_rule, rule_name, criteria, actions, delete_pm, is_or
  3580. FROM {db_prefix}pm_rules
  3581. WHERE id_member = {int:current_member}',
  3582. array(
  3583. 'current_member' => $user_info['id'],
  3584. )
  3585. );
  3586. $context['rules'] = array();
  3587. // Simply fill in the data!
  3588. while ($row = $smcFunc['db_fetch_assoc']($request))
  3589. {
  3590. $context['rules'][$row['id_rule']] = array(
  3591. 'id' => $row['id_rule'],
  3592. 'name' => $row['rule_name'],
  3593. 'criteria' => unserialize($row['criteria']),
  3594. 'actions' => unserialize($row['actions']),
  3595. 'delete' => $row['delete_pm'],
  3596. 'logic' => $row['is_or'] ? 'or' : 'and',
  3597. );
  3598. if ($row['delete_pm'])
  3599. $context['rules'][$row['id_rule']]['actions'][] = array('t' => 'del', 'v' => 1);
  3600. }
  3601. $smcFunc['db_free_result']($request);
  3602. }
  3603. /**
  3604. * Check if the PM is available to the current user.
  3605. *
  3606. * @param int $pmID
  3607. * @param $validFor
  3608. * @return boolean
  3609. */
  3610. function isAccessiblePM($pmID, $validFor = 'in_or_outbox')
  3611. {
  3612. global $user_info, $smcFunc;
  3613. $request = $smcFunc['db_query']('', '
  3614. SELECT
  3615. pm.id_member_from = {int:id_current_member} AND pm.deleted_by_sender = {int:not_deleted} AS valid_for_outbox,
  3616. pmr.id_pm IS NOT NULL AS valid_for_inbox
  3617. FROM {db_prefix}personal_messages AS pm
  3618. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm AND pmr.id_member = {int:id_current_member} AND pmr.deleted = {int:not_deleted})
  3619. WHERE pm.id_pm = {int:id_pm}
  3620. AND ((pm.id_member_from = {int:id_current_member} AND pm.deleted_by_sender = {int:not_deleted}) OR pmr.id_pm IS NOT NULL)',
  3621. array(
  3622. 'id_pm' => $pmID,
  3623. 'id_current_member' => $user_info['id'],
  3624. 'not_deleted' => 0,
  3625. )
  3626. );
  3627. if ($smcFunc['db_num_rows']($request) === 0)
  3628. {
  3629. $smcFunc['db_free_result']($request);
  3630. return false;
  3631. }
  3632. $validationResult = $smcFunc['db_fetch_assoc']($request);
  3633. $smcFunc['db_free_result']($request);
  3634. switch ($validFor)
  3635. {
  3636. case 'inbox':
  3637. return !empty($validationResult['valid_for_inbox']);
  3638. break;
  3639. case 'outbox':
  3640. return !empty($validationResult['valid_for_outbox']);
  3641. break;
  3642. case 'in_or_outbox':
  3643. return !empty($validationResult['valid_for_inbox']) || !empty($validationResult['valid_for_outbox']);
  3644. break;
  3645. default:
  3646. trigger_error('Undefined validation type given', E_USER_ERROR);
  3647. break;
  3648. }
  3649. }
  3650. ?>