999) $modSettings['defaultMaxTopics'] = 20; if (empty($modSettings['defaultMaxMessages']) || $modSettings['defaultMaxMessages'] <= 0 || $modSettings['defaultMaxMessages'] > 999) $modSettings['defaultMaxMessages'] = 15; if (empty($modSettings['defaultMaxMembers']) || $modSettings['defaultMaxMembers'] <= 0 || $modSettings['defaultMaxMembers'] > 999) $modSettings['defaultMaxMembers'] = 30; if (!empty($modSettings['cache_enable'])) cache_put_data('modSettings', $modSettings, 90); } // UTF-8 ? $utf8 = (empty($modSettings['global_character_set']) ? $txt['lang_character_set'] : $modSettings['global_character_set']) === 'UTF-8'; // Set a list of common functions. $ent_list = empty($modSettings['disableEntityCheck']) ? '&(#\d{1,7}|quot|amp|lt|gt|nbsp);' : '&(#021|quot|amp|lt|gt|nbsp);'; $ent_check = empty($modSettings['disableEntityCheck']) ? array('preg_replace_callback(\'~(&#(\d{1,7}|x[0-9a-fA-F]{1,6});)~\', \'entity_fix__callback\', ', ')') : array('', ''); // Preg_replace space characters depend on the character set in use $space_chars = $utf8 ? '\x{A0}\x{AD}\x{2000}-\x{200F}\x{201F}\x{202F}\x{3000}\x{FEFF}' : '\x00-\x08\x0B\x0C\x0E-\x19\xA0'; // global array of anonymous helper functions, used mosly to properly handle multi byte strings $smcFunc += array( 'entity_fix' => create_function('$string', ' $num = $string[0] === \'x\' ? hexdec(substr($string, 1)) : (int) $string; return $num < 0x20 || $num > 0x10FFFF || ($num >= 0xD800 && $num <= 0xDFFF) || $num === 0x202E || $num === 0x202D ? \'\' : \'&#\' . $num . \';\';'), 'htmlspecialchars' => create_function('$string, $quote_style = ENT_COMPAT, $charset = \'ISO-8859-1\'', ' global $smcFunc; return ' . strtr($ent_check[0], array('&' => '&')) . 'htmlspecialchars($string, $quote_style, ' . ($utf8 ? '\'UTF-8\'' : '$charset') . ')' . $ent_check[1] . ';'), 'htmltrim' => create_function('$string', ' global $smcFunc; return preg_replace(\'~^(?:[ \t\n\r\x0B\x00' . $space_chars . ']| )+|(?:[ \t\n\r\x0B\x00' . $space_chars . ']| )+$~' . ($utf8 ? 'u' : '') . '\', \'\', ' . implode('$string', $ent_check) . ');'), 'strlen' => create_function('$string', ' global $smcFunc; return strlen(preg_replace(\'~' . $ent_list . ($utf8 ? '|.~u' : '~') . '\', \'_\', ' . implode('$string', $ent_check) . '));'), 'strpos' => create_function('$haystack, $needle, $offset = 0', ' global $smcFunc; $haystack_arr = preg_split(\'~(&#' . (empty($modSettings['disableEntityCheck']) ? '\d{1,7}' : '021') . ';|"|&|<|>| |.)~' . ($utf8 ? 'u' : '') . '\', ' . implode('$haystack', $ent_check) . ', -1, PREG_SPLIT_DELIM_CAPTURE | PREG_SPLIT_NO_EMPTY); $haystack_size = count($haystack_arr); if (strlen($needle) === 1) { $result = array_search($needle, array_slice($haystack_arr, $offset)); return is_int($result) ? $result + $offset : false; } else { $needle_arr = preg_split(\'~(&#' . (empty($modSettings['disableEntityCheck']) ? '\d{1,7}' : '021') . ';|"|&|<|>| |.)~' . ($utf8 ? 'u' : '') . '\', ' . implode('$needle', $ent_check) . ', -1, PREG_SPLIT_DELIM_CAPTURE | PREG_SPLIT_NO_EMPTY); $needle_size = count($needle_arr); $result = array_search($needle_arr[0], array_slice($haystack_arr, $offset)); while ((int) $result === $result) { $offset += $result; if (array_slice($haystack_arr, $offset, $needle_size) === $needle_arr) return $offset; $result = array_search($needle_arr[0], array_slice($haystack_arr, ++$offset)); } return false; }'), 'substr' => create_function('$string, $start, $length = null', ' global $smcFunc; $ent_arr = preg_split(\'~(&#' . (empty($modSettings['disableEntityCheck']) ? '\d{1,7}' : '021') . ';|"|&|<|>| |.)~' . ($utf8 ? 'u' : '') . '\', ' . implode('$string', $ent_check) . ', -1, PREG_SPLIT_DELIM_CAPTURE | PREG_SPLIT_NO_EMPTY); return $length === null ? implode(\'\', array_slice($ent_arr, $start)) : implode(\'\', array_slice($ent_arr, $start, $length));'), 'strtolower' => $utf8 ? (function_exists('mb_strtolower') ? create_function('$string', ' return mb_strtolower($string, \'UTF-8\');') : create_function('$string', ' global $sourcedir; require_once($sourcedir . \'/Subs-Charset.php\'); return utf8_strtolower($string);')) : 'strtolower', 'strtoupper' => $utf8 ? (function_exists('mb_strtoupper') ? create_function('$string', ' return mb_strtoupper($string, \'UTF-8\');') : create_function('$string', ' global $sourcedir; require_once($sourcedir . \'/Subs-Charset.php\'); return utf8_strtoupper($string);')) : 'strtoupper', 'truncate' => create_function('$string, $length', (empty($modSettings['disableEntityCheck']) ? ' global $smcFunc; $string = ' . implode('$string', $ent_check) . ';' : '') . ' preg_match(\'~^(' . $ent_list . '|.){\' . $smcFunc[\'strlen\'](substr($string, 0, $length)) . \'}~'. ($utf8 ? 'u' : '') . '\', $string, $matches); $string = $matches[0]; while (strlen($string) > $length) $string = preg_replace(\'~(?:' . $ent_list . '|.)$~'. ($utf8 ? 'u' : '') . '\', \'\', $string); return $string;'), 'ucfirst' => $utf8 ? create_function('$string', ' global $smcFunc; return $smcFunc[\'strtoupper\']($smcFunc[\'substr\']($string, 0, 1)) . $smcFunc[\'substr\']($string, 1);') : 'ucfirst', 'ucwords' => $utf8 ? create_function('$string', ' global $smcFunc; $words = preg_split(\'~([\s\r\n\t]+)~\', $string, -1, PREG_SPLIT_DELIM_CAPTURE); for ($i = 0, $n = count($words); $i < $n; $i += 2) $words[$i] = $smcFunc[\'ucfirst\']($words[$i]); return implode(\'\', $words);') : 'ucwords', ); // Setting the timezone is a requirement for some functions in PHP >= 5.1. if (isset($modSettings['default_timezone']) && function_exists('date_default_timezone_set')) date_default_timezone_set($modSettings['default_timezone']); // Check the load averages? if (!empty($modSettings['loadavg_enable'])) { if (($modSettings['load_average'] = cache_get_data('loadavg', 90)) == null) { $modSettings['load_average'] = @file_get_contents('/proc/loadavg'); if (!empty($modSettings['load_average']) && preg_match('~^([^ ]+?) ([^ ]+?) ([^ ]+)~', $modSettings['load_average'], $matches) != 0) $modSettings['load_average'] = (float) $matches[1]; elseif (($modSettings['load_average'] = @`uptime`) != null && preg_match('~load average[s]?: (\d+\.\d+), (\d+\.\d+), (\d+\.\d+)~i', $modSettings['load_average'], $matches) != 0) $modSettings['load_average'] = (float) $matches[1]; else unset($modSettings['load_average']); if (!empty($modSettings['load_average'])) cache_put_data('loadavg', $modSettings['load_average'], 90); } if (!empty($modSettings['load_average'])) call_integration_hook('integrate_load_average', array($modSettings['load_average'])); if (!empty($modSettings['loadavg_forum']) && !empty($modSettings['load_average']) && $modSettings['load_average'] >= $modSettings['loadavg_forum']) display_loadavg_error(); } // Is post moderation alive and well? Everywhere else assumes this has been defined, so let's make sure it is. $modSettings['postmod_active'] = !empty($modSettings['postmod_active']); // Here to justify the name of this function. :P // It should be added to the install and upgrade scripts. // But since the convertors need to be updated also. This is easier. if (empty($modSettings['currentAttachmentUploadDir'])) { updateSettings(array( 'attachmentUploadDir' => serialize(array(1 => $modSettings['attachmentUploadDir'])), 'currentAttachmentUploadDir' => 1, )); } // Integration is cool. if (defined('SMF_INTEGRATION_SETTINGS')) { $integration_settings = unserialize(SMF_INTEGRATION_SETTINGS); foreach ($integration_settings as $hook => $function) add_integration_function($hook, $function, '', false); } // Any files to pre include? if (!empty($modSettings['integrate_pre_include'])) { $pre_includes = explode(',', $modSettings['integrate_pre_include']); foreach ($pre_includes as $include) { $include = strtr(trim($include), array('$boarddir' => $boarddir, '$sourcedir' => $sourcedir)); if (file_exists($include)) require_once($include); } } // Call pre load integration functions. call_integration_hook('integrate_pre_load'); // This determines the server... not used in many places, except for login fixing. $context['server'] = array( 'is_iis' => isset($_SERVER['SERVER_SOFTWARE']) && strpos($_SERVER['SERVER_SOFTWARE'], 'Microsoft-IIS') !== false, 'is_apache' => isset($_SERVER['SERVER_SOFTWARE']) && strpos($_SERVER['SERVER_SOFTWARE'], 'Apache') !== false, 'is_litespeed' => isset($_SERVER['SERVER_SOFTWARE']) && strpos($_SERVER['SERVER_SOFTWARE'], 'LiteSpeed') !== false, 'is_lighttpd' => isset($_SERVER['SERVER_SOFTWARE']) && strpos($_SERVER['SERVER_SOFTWARE'], 'lighttpd') !== false, 'is_nginx' => isset($_SERVER['SERVER_SOFTWARE']) && strpos($_SERVER['SERVER_SOFTWARE'], 'nginx') !== false, 'is_cgi' => isset($_SERVER['SERVER_SOFTWARE']) && strpos(php_sapi_name(), 'cgi') !== false, 'is_windows' => strpos(PHP_OS, 'WIN') === 0, 'iso_case_folding' => ord(strtolower(chr(138))) === 154, ); // A bug in some versions of IIS under CGI (older ones) makes cookie setting not work with Location: headers. $context['server']['needs_login_fix'] = $context['server']['is_cgi'] && $context['server']['is_iis']; } /** * Load all the important user information. * What it does: * - sets up the $user_info array * - assigns $user_info['query_wanna_see_board'] for what boards the user can see. * - first checks for cookie or integration validation. * - uses the current session if no integration function or cookie is found. * - checks password length, if member is activated and the login span isn't over. * - if validation fails for the user, $id_member is set to 0. * - updates the last visit time when needed. */ function loadUserSettings() { global $modSettings, $user_settings, $sourcedir, $smcFunc; global $cookiename, $user_info, $language, $context; // Check first the integration, then the cookie, and last the session. if (count($integration_ids = call_integration_hook('integrate_verify_user')) > 0) { $id_member = 0; foreach ($integration_ids as $integration_id) { $integration_id = (int) $integration_id; if ($integration_id > 0) { $id_member = $integration_id; $already_verified = true; break; } } } else $id_member = 0; if (empty($id_member) && isset($_COOKIE[$cookiename])) { // Fix a security hole in PHP 4.3.9 and below... if (preg_match('~^a:[34]:\{i:0;i:\d{1,7};i:1;s:(0|40):"([a-fA-F0-9]{40})?";i:2;[id]:\d{1,14};(i:3;i:\d;)?\}$~i', $_COOKIE[$cookiename]) == 1) { list ($id_member, $password) = @unserialize($_COOKIE[$cookiename]); $id_member = !empty($id_member) && strlen($password) > 0 ? (int) $id_member : 0; } else $id_member = 0; } elseif (empty($id_member) && isset($_SESSION['login_' . $cookiename]) && ($_SESSION['USER_AGENT'] == $_SERVER['HTTP_USER_AGENT'] || !empty($modSettings['disableCheckUA']))) { // @todo Perhaps we can do some more checking on this, such as on the first octet of the IP? list ($id_member, $password, $login_span) = @unserialize($_SESSION['login_' . $cookiename]); $id_member = !empty($id_member) && strlen($password) == 40 && $login_span > time() ? (int) $id_member : 0; } // Only load this stuff if the user isn't a guest. if ($id_member != 0) { // Is the member data cached? if (empty($modSettings['cache_enable']) || $modSettings['cache_enable'] < 2 || ($user_settings = cache_get_data('user_settings-' . $id_member, 60)) == null) { $request = $smcFunc['db_query']('', ' SELECT mem.*, IFNULL(a.id_attach, 0) AS id_attach, a.filename, a.attachment_type FROM {db_prefix}members AS mem LEFT JOIN {db_prefix}attachments AS a ON (a.id_member = {int:id_member}) WHERE mem.id_member = {int:id_member} LIMIT 1', array( 'id_member' => $id_member, ) ); $user_settings = $smcFunc['db_fetch_assoc']($request); $smcFunc['db_free_result']($request); if (!empty($modSettings['cache_enable']) && $modSettings['cache_enable'] >= 2) cache_put_data('user_settings-' . $id_member, $user_settings, 60); } // Did we find 'im? If not, junk it. if (!empty($user_settings)) { // As much as the password should be right, we can assume the integration set things up. if (!empty($already_verified) && $already_verified === true) $check = true; // SHA-1 passwords should be 40 characters long. elseif (strlen($password) == 40) $check = sha1($user_settings['passwd'] . $user_settings['password_salt']) == $password; else $check = false; // Wrong password or not activated - either way, you're going nowhere. $id_member = $check && ($user_settings['is_activated'] == 1 || $user_settings['is_activated'] == 11) ? (int) $user_settings['id_member'] : 0; } else $id_member = 0; // If we no longer have the member maybe they're being all hackey, stop brute force! if (!$id_member) { require_once($sourcedir . '/LogInOut.php'); validatePasswordFlood(!empty($user_settings['id_member']) ? $user_settings['id_member'] : $id_member, !empty($user_settings['passwd_flood']) ? $user_settings['passwd_flood'] : false, $id_member != 0); } } // Found 'im, let's set up the variables. if ($id_member != 0) { // Let's not update the last visit time in these cases... // 1. SSI doesn't count as visiting the forum. // 2. RSS feeds and XMLHTTP requests don't count either. // 3. If it was set within this session, no need to set it again. // 4. New session, yet updated < five hours ago? Maybe cache can help. if (SMF != 'SSI' && !isset($_REQUEST['xml']) && (!isset($_REQUEST['action']) || $_REQUEST['action'] != '.xml') && empty($_SESSION['id_msg_last_visit']) && (empty($modSettings['cache_enable']) || ($_SESSION['id_msg_last_visit'] = cache_get_data('user_last_visit-' . $id_member, 5 * 3600)) === null)) { // @todo can this be cached? // Do a quick query to make sure this isn't a mistake. $result = $smcFunc['db_query']('', ' SELECT poster_time FROM {db_prefix}messages WHERE id_msg = {int:id_msg} LIMIT 1', array( 'id_msg' => $user_settings['id_msg_last_visit'], ) ); list ($visitTime) = $smcFunc['db_fetch_row']($result); $smcFunc['db_free_result']($result); $_SESSION['id_msg_last_visit'] = $user_settings['id_msg_last_visit']; // If it was *at least* five hours ago... if ($visitTime < time() - 5 * 3600) { updateMemberData($id_member, array('id_msg_last_visit' => (int) $modSettings['maxMsgID'], 'last_login' => time(), 'member_ip' => $_SERVER['REMOTE_ADDR'], 'member_ip2' => $_SERVER['BAN_CHECK_IP'])); $user_settings['last_login'] = time(); if (!empty($modSettings['cache_enable']) && $modSettings['cache_enable'] >= 2) cache_put_data('user_settings-' . $id_member, $user_settings, 60); if (!empty($modSettings['cache_enable'])) cache_put_data('user_last_visit-' . $id_member, $_SESSION['id_msg_last_visit'], 5 * 3600); } } elseif (empty($_SESSION['id_msg_last_visit'])) $_SESSION['id_msg_last_visit'] = $user_settings['id_msg_last_visit']; $username = $user_settings['member_name']; if (empty($user_settings['additional_groups'])) $user_info = array( 'groups' => array($user_settings['id_group'], $user_settings['id_post_group']) ); else $user_info = array( 'groups' => array_merge( array($user_settings['id_group'], $user_settings['id_post_group']), explode(',', $user_settings['additional_groups']) ) ); // Because history has proven that it is possible for groups to go bad - clean up in case. foreach ($user_info['groups'] as $k => $v) $user_info['groups'][$k] = (int) $v; // This is a logged in user, so definitely not a spider. $user_info['possibly_robot'] = false; } // If the user is a guest, initialize all the critical user settings. else { // This is what a guest's variables should be. $username = ''; $user_info = array('groups' => array(-1)); $user_settings = array(); if (isset($_COOKIE[$cookiename])) $_COOKIE[$cookiename] = ''; // Create a login token if it doesn't exist yet. if (!isset($_SESSION['token']['post-login'])) createToken('login'); else list ($context['login_token_var'],,, $context['login_token']) = $_SESSION['token']['post-login']; // Do we perhaps think this is a search robot? Check every five minutes just in case... if ((!empty($modSettings['spider_mode']) || !empty($modSettings['spider_group'])) && (!isset($_SESSION['robot_check']) || $_SESSION['robot_check'] < time() - 300)) { require_once($sourcedir . '/ManageSearchEngines.php'); $user_info['possibly_robot'] = SpiderCheck(); } elseif (!empty($modSettings['spider_mode'])) $user_info['possibly_robot'] = isset($_SESSION['id_robot']) ? $_SESSION['id_robot'] : 0; // If we haven't turned on proper spider hunts then have a guess! else { $ci_user_agent = strtolower($_SERVER['HTTP_USER_AGENT']); $user_info['possibly_robot'] = (strpos($_SERVER['HTTP_USER_AGENT'], 'Mozilla') === false && strpos($_SERVER['HTTP_USER_AGENT'], 'Opera') === false) || strpos($ci_user_agent, 'googlebot') !== false || strpos($ci_user_agent, 'slurp') !== false || strpos($ci_user_agent, 'crawl') !== false || strpos($ci_user_agent, 'msnbot') !== false; } } // Set up the $user_info array. $user_info += array( 'id' => $id_member, 'username' => $username, 'name' => isset($user_settings['real_name']) ? $user_settings['real_name'] : '', 'email' => isset($user_settings['email_address']) ? $user_settings['email_address'] : '', 'passwd' => isset($user_settings['passwd']) ? $user_settings['passwd'] : '', 'language' => empty($user_settings['lngfile']) || empty($modSettings['userLanguage']) ? $language : $user_settings['lngfile'], 'is_guest' => $id_member == 0, 'is_admin' => in_array(1, $user_info['groups']), 'theme' => empty($user_settings['id_theme']) ? 0 : $user_settings['id_theme'], 'last_login' => empty($user_settings['last_login']) ? 0 : $user_settings['last_login'], 'ip' => $_SERVER['REMOTE_ADDR'], 'ip2' => $_SERVER['BAN_CHECK_IP'], 'posts' => empty($user_settings['posts']) ? 0 : $user_settings['posts'], 'time_format' => empty($user_settings['time_format']) ? $modSettings['time_format'] : $user_settings['time_format'], 'time_offset' => empty($user_settings['time_offset']) ? 0 : $user_settings['time_offset'], 'avatar' => array( 'url' => isset($user_settings['avatar']) ? $user_settings['avatar'] : '', 'filename' => empty($user_settings['filename']) ? '' : $user_settings['filename'], 'custom_dir' => !empty($user_settings['attachment_type']) && $user_settings['attachment_type'] == 1, 'id_attach' => isset($user_settings['id_attach']) ? $user_settings['id_attach'] : 0 ), 'smiley_set' => isset($user_settings['smiley_set']) ? $user_settings['smiley_set'] : '', 'messages' => empty($user_settings['instant_messages']) ? 0 : $user_settings['instant_messages'], 'unread_messages' => empty($user_settings['unread_messages']) ? 0 : $user_settings['unread_messages'], 'alerts' => empty($user_settings['alerts']) ? 0 : $user_settings['alerts'], 'total_time_logged_in' => empty($user_settings['total_time_logged_in']) ? 0 : $user_settings['total_time_logged_in'], 'buddies' => !empty($modSettings['enable_buddylist']) && !empty($user_settings['buddy_list']) ? explode(',', $user_settings['buddy_list']) : array(), 'ignoreboards' => !empty($user_settings['ignore_boards']) && !empty($modSettings['allow_ignore_boards']) ? explode(',', $user_settings['ignore_boards']) : array(), 'ignoreusers' => !empty($user_settings['pm_ignore_list']) ? explode(',', $user_settings['pm_ignore_list']) : array(), 'warning' => isset($user_settings['warning']) ? $user_settings['warning'] : 0, 'permissions' => array(), ); $user_info['groups'] = array_unique($user_info['groups']); // Make sure that the last item in the ignore boards array is valid. If the list was too long it could have an ending comma that could cause problems. if (!empty($user_info['ignoreboards']) && empty($user_info['ignoreboards'][$tmp = count($user_info['ignoreboards']) - 1])) unset($user_info['ignoreboards'][$tmp]); // Do we have any languages to validate this? if (!empty($modSettings['userLanguage']) && (!empty($_GET['language']) || !empty($_SESSION['language']))) $languages = getLanguages(); // Allow the user to change their language if its valid. if (!empty($modSettings['userLanguage']) && !empty($_GET['language']) && isset($languages[strtr($_GET['language'], './\\:', '____')])) { $user_info['language'] = strtr($_GET['language'], './\\:', '____'); $_SESSION['language'] = $user_info['language']; } elseif (!empty($modSettings['userLanguage']) && !empty($_SESSION['language']) && isset($languages[strtr($_SESSION['language'], './\\:', '____')])) $user_info['language'] = strtr($_SESSION['language'], './\\:', '____'); // Just build this here, it makes it easier to change/use - administrators can see all boards. if ($user_info['is_admin']) $user_info['query_see_board'] = '1=1'; // Otherwise just the groups in $user_info['groups']. else $user_info['query_see_board'] = '((FIND_IN_SET(' . implode(', b.member_groups) != 0 OR FIND_IN_SET(', $user_info['groups']) . ', b.member_groups) != 0)' . (!empty($modSettings['deny_boards_access']) ? ' AND (FIND_IN_SET(' . implode(', b.deny_member_groups) = 0 AND FIND_IN_SET(', $user_info['groups']) . ', b.deny_member_groups) = 0)' : '') . (isset($user_info['mod_cache']) ? ' OR ' . $user_info['mod_cache']['mq'] : '') . ')'; // Build the list of boards they WANT to see. // This will take the place of query_see_boards in certain spots, so it better include the boards they can see also // If they aren't ignoring any boards then they want to see all the boards they can see if (empty($user_info['ignoreboards'])) $user_info['query_wanna_see_board'] = $user_info['query_see_board']; // Ok I guess they don't want to see all the boards else $user_info['query_wanna_see_board'] = '(' . $user_info['query_see_board'] . ' AND b.id_board NOT IN (' . implode(',', $user_info['ignoreboards']) . '))'; call_integration_hook('integrate_user_info'); } /** * Check for moderators and see if they have access to the board. * What it does: * - sets up the $board_info array for current board information. * - if cache is enabled, the $board_info array is stored in cache. * - redirects to appropriate post if only message id is requested. * - is only used when inside a topic or board. * - determines the local moderators for the board. * - adds group id 3 if the user is a local moderator for the board they are in. * - prevents access if user is not in proper group nor a local moderator of the board. */ function loadBoard() { global $txt, $scripturl, $context, $modSettings; global $board_info, $board, $topic, $user_info, $smcFunc; // Assume they are not a moderator. $user_info['is_mod'] = false; $context['user']['is_mod'] = &$user_info['is_mod']; // Start the linktree off empty.. $context['linktree'] = array(); // Have they by chance specified a message id but nothing else? if (empty($_REQUEST['action']) && empty($topic) && empty($board) && !empty($_REQUEST['msg'])) { // Make sure the message id is really an int. $_REQUEST['msg'] = (int) $_REQUEST['msg']; // Looking through the message table can be slow, so try using the cache first. if (($topic = cache_get_data('msg_topic-' . $_REQUEST['msg'], 120)) === null) { $request = $smcFunc['db_query']('', ' SELECT id_topic FROM {db_prefix}messages WHERE id_msg = {int:id_msg} LIMIT 1', array( 'id_msg' => $_REQUEST['msg'], ) ); // So did it find anything? if ($smcFunc['db_num_rows']($request)) { list ($topic) = $smcFunc['db_fetch_row']($request); $smcFunc['db_free_result']($request); // Save save save. cache_put_data('msg_topic-' . $_REQUEST['msg'], $topic, 120); } } // Remember redirection is the key to avoiding fallout from your bosses. if (!empty($topic)) redirectexit('topic=' . $topic . '.msg' . $_REQUEST['msg'] . '#msg' . $_REQUEST['msg']); else { loadPermissions(); loadTheme(); fatal_lang_error('topic_gone', false); } } // Load this board only if it is specified. if (empty($board) && empty($topic)) { $board_info = array('moderators' => array(), 'moderator_groups' => array()); return; } if (!empty($modSettings['cache_enable']) && (empty($topic) || $modSettings['cache_enable'] >= 3)) { // @todo SLOW? if (!empty($topic)) $temp = cache_get_data('topic_board-' . $topic, 120); else $temp = cache_get_data('board-' . $board, 120); if (!empty($temp)) { $board_info = $temp; $board = $board_info['id']; } } if (empty($temp)) { $request = $smcFunc['db_query']('', ' SELECT c.id_cat, b.name AS bname, b.description, b.num_topics, b.member_groups, b.deny_member_groups, b.id_parent, c.name AS cname, IFNULL(mg.id_group, 0) AS id_moderator_group, mg.group_name, IFNULL(mem.id_member, 0) AS id_moderator, mem.real_name' . (!empty($topic) ? ', b.id_board' : '') . ', b.child_level, b.id_theme, b.override_theme, b.count_posts, b.id_profile, b.redirect, b.unapproved_topics, b.unapproved_posts' . (!empty($topic) ? ', t.approved, t.id_member_started' : '') . ' FROM {db_prefix}boards AS b' . (!empty($topic) ? ' INNER JOIN {db_prefix}topics AS t ON (t.id_topic = {int:current_topic})' : '') . ' LEFT JOIN {db_prefix}categories AS c ON (c.id_cat = b.id_cat) LEFT JOIN {db_prefix}moderator_groups AS modgs ON (modgs.id_board = {raw:board_link}) LEFT JOIN {db_prefix}membergroups AS mg ON (mg.id_group = modgs.id_group) LEFT JOIN {db_prefix}moderators AS mods ON (mods.id_board = {raw:board_link}) LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = mods.id_member) WHERE b.id_board = {raw:board_link}', array( 'current_topic' => $topic, 'board_link' => empty($topic) ? $smcFunc['db_quote']('{int:current_board}', array('current_board' => $board)) : 't.id_board', ) ); // If there aren't any, skip. if ($smcFunc['db_num_rows']($request) > 0) { $row = $smcFunc['db_fetch_assoc']($request); // Set the current board. if (!empty($row['id_board'])) $board = $row['id_board']; // Basic operating information. (globals... :/) $board_info = array( 'id' => $board, 'moderators' => array(), 'moderator_groups' => array(), 'cat' => array( 'id' => $row['id_cat'], 'name' => $row['cname'] ), 'name' => $row['bname'], 'description' => $row['description'], 'num_topics' => $row['num_topics'], 'unapproved_topics' => $row['unapproved_topics'], 'unapproved_posts' => $row['unapproved_posts'], 'unapproved_user_topics' => 0, 'parent_boards' => getBoardParents($row['id_parent']), 'parent' => $row['id_parent'], 'child_level' => $row['child_level'], 'theme' => $row['id_theme'], 'override_theme' => !empty($row['override_theme']), 'profile' => $row['id_profile'], 'redirect' => $row['redirect'], 'posts_count' => empty($row['count_posts']), 'cur_topic_approved' => empty($topic) || $row['approved'], 'cur_topic_starter' => empty($topic) ? 0 : $row['id_member_started'], ); // Load the membergroups allowed, and check permissions. $board_info['groups'] = $row['member_groups'] == '' ? array() : explode(',', $row['member_groups']); $board_info['deny_groups'] = $row['deny_member_groups'] == '' ? array() : explode(',', $row['deny_member_groups']); do { if (!empty($row['id_moderator'])) $board_info['moderators'][$row['id_moderator']] = array( 'id' => $row['id_moderator'], 'name' => $row['real_name'], 'href' => $scripturl . '?action=profile;u=' . $row['id_moderator'], 'link' => '' . $row['real_name'] . '' ); if (!empty($row['id_moderator_group'])) $board_info['moderator_groups'][$row['id_moderator_group']] = array( 'id' => $row['id_moderator_group'], 'name' => $row['group_name'], 'href' => $scripturl . '?action=groups;sa=members;group=' . $row['id_moderator_group'], 'link' => '' . $row['group_name'] . '' ); } while ($row = $smcFunc['db_fetch_assoc']($request)); // If the board only contains unapproved posts and the user isn't an approver then they can't see any topics. // If that is the case do an additional check to see if they have any topics waiting to be approved. if ($board_info['num_topics'] == 0 && $modSettings['postmod_active'] && !allowedTo('approve_posts')) { // Free the previous result $smcFunc['db_free_result']($request); // @todo why is this using id_topic? // @todo Can this get cached? $request = $smcFunc['db_query']('', ' SELECT COUNT(id_topic) FROM {db_prefix}topics WHERE id_member_started={int:id_member} AND approved = {int:unapproved} AND id_board = {int:board}', array( 'id_member' => $user_info['id'], 'unapproved' => 0, 'board' => $board, ) ); list ($board_info['unapproved_user_topics']) = $smcFunc['db_fetch_row']($request); } if (!empty($modSettings['cache_enable']) && (empty($topic) || $modSettings['cache_enable'] >= 3)) { // @todo SLOW? if (!empty($topic)) cache_put_data('topic_board-' . $topic, $board_info, 120); cache_put_data('board-' . $board, $board_info, 120); } } else { // Otherwise the topic is invalid, there are no moderators, etc. $board_info = array( 'moderators' => array(), 'moderator_groups' => array(), 'error' => 'exist' ); $topic = null; $board = 0; } $smcFunc['db_free_result']($request); } if (!empty($topic)) $_GET['board'] = (int) $board; if (!empty($board)) { // Get this into an array of keys for array_intersect $moderator_groups = array_keys($board_info['moderator_groups']); // Now check if the user is a moderator. $user_info['is_mod'] = isset($board_info['moderators'][$user_info['id']]) || count(array_intersect($user_info['groups'], $moderator_groups)) != 0; if (count(array_intersect($user_info['groups'], $board_info['groups'])) == 0 && !$user_info['is_admin']) $board_info['error'] = 'access'; if (!empty($modSettings['deny_boards_access']) && count(array_intersect($user_info['groups'], $board_info['deny_groups'])) != 0 && !$user_info['is_admin']) $board_info['error'] = 'access'; // Build up the linktree. $context['linktree'] = array_merge( $context['linktree'], array(array( 'url' => $scripturl . '#c' . $board_info['cat']['id'], 'name' => $board_info['cat']['name'] )), array_reverse($board_info['parent_boards']), array(array( 'url' => $scripturl . '?board=' . $board . '.0', 'name' => $board_info['name'] )) ); } // Set the template contextual information. $context['user']['is_mod'] = &$user_info['is_mod']; $context['current_topic'] = $topic; $context['current_board'] = $board; // Hacker... you can't see this topic, I'll tell you that. (but moderators can!) if (!empty($board_info['error']) && (!empty($modSettings['deny_boards_access']) || $board_info['error'] != 'access' || !$user_info['is_mod'])) { // The permissions and theme need loading, just to make sure everything goes smoothly. loadPermissions(); loadTheme(); $_GET['board'] = ''; $_GET['topic'] = ''; // The linktree should not give the game away mate! $context['linktree'] = array( array( 'url' => $scripturl, 'name' => $context['forum_name_html_safe'] ) ); // If it's a prefetching agent or we're requesting an attachment. if ((isset($_SERVER['HTTP_X_MOZ']) && $_SERVER['HTTP_X_MOZ'] == 'prefetch') || (!empty($_REQUEST['action']) && $_REQUEST['action'] === 'dlattach')) { ob_end_clean(); header('HTTP/1.1 403 Forbidden'); die; } elseif ($user_info['is_guest']) { loadLanguage('Errors'); is_not_guest($txt['topic_gone']); } else fatal_lang_error('topic_gone', false); } if ($user_info['is_mod']) $user_info['groups'][] = 3; } /** * Load this user's permissions. * */ function loadPermissions() { global $user_info, $board, $board_info, $modSettings, $smcFunc, $sourcedir; if ($user_info['is_admin']) { banPermissions(); return; } if (!empty($modSettings['cache_enable'])) { $cache_groups = $user_info['groups']; asort($cache_groups); $cache_groups = implode(',', $cache_groups); // If it's a spider then cache it different. if ($user_info['possibly_robot']) $cache_groups .= '-spider'; if ($modSettings['cache_enable'] >= 2 && !empty($board) && ($temp = cache_get_data('permissions:' . $cache_groups . ':' . $board, 240)) != null && time() - 240 > $modSettings['settings_updated']) { list ($user_info['permissions']) = $temp; banPermissions(); return; } elseif (($temp = cache_get_data('permissions:' . $cache_groups, 240)) != null && time() - 240 > $modSettings['settings_updated']) list ($user_info['permissions'], $removals) = $temp; } // If it is detected as a robot, and we are restricting permissions as a special group - then implement this. $spider_restrict = $user_info['possibly_robot'] && !empty($modSettings['spider_group']) ? ' OR (id_group = {int:spider_group} AND add_deny = 0)' : ''; if (empty($user_info['permissions'])) { // Get the general permissions. $request = $smcFunc['db_query']('', ' SELECT permission, add_deny FROM {db_prefix}permissions WHERE id_group IN ({array_int:member_groups}) ' . $spider_restrict, array( 'member_groups' => $user_info['groups'], 'spider_group' => !empty($modSettings['spider_group']) ? $modSettings['spider_group'] : 0, ) ); $removals = array(); while ($row = $smcFunc['db_fetch_assoc']($request)) { if (empty($row['add_deny'])) $removals[] = $row['permission']; else $user_info['permissions'][] = $row['permission']; } $smcFunc['db_free_result']($request); if (isset($cache_groups)) cache_put_data('permissions:' . $cache_groups, array($user_info['permissions'], $removals), 240); } // Get the board permissions. if (!empty($board)) { // Make sure the board (if any) has been loaded by loadBoard(). if (!isset($board_info['profile'])) fatal_lang_error('no_board'); $request = $smcFunc['db_query']('', ' SELECT permission, add_deny FROM {db_prefix}board_permissions WHERE (id_group IN ({array_int:member_groups}) ' . $spider_restrict . ') AND id_profile = {int:id_profile}', array( 'member_groups' => $user_info['groups'], 'id_profile' => $board_info['profile'], 'spider_group' => !empty($modSettings['spider_group']) ? $modSettings['spider_group'] : 0, ) ); while ($row = $smcFunc['db_fetch_assoc']($request)) { if (empty($row['add_deny'])) $removals[] = $row['permission']; else $user_info['permissions'][] = $row['permission']; } $smcFunc['db_free_result']($request); } // Remove all the permissions they shouldn't have ;). if (!empty($modSettings['permission_enable_deny'])) $user_info['permissions'] = array_diff($user_info['permissions'], $removals); if (isset($cache_groups) && !empty($board) && $modSettings['cache_enable'] >= 2) cache_put_data('permissions:' . $cache_groups . ':' . $board, array($user_info['permissions'], null), 240); // Banned? Watch, don't touch.. banPermissions(); // Load the mod cache so we can know what additional boards they should see, but no sense in doing it for guests if (!$user_info['is_guest']) { if (!isset($_SESSION['mc']) || $_SESSION['mc']['time'] <= $modSettings['settings_updated']) { require_once($sourcedir . '/Subs-Auth.php'); rebuildModCache(); } else $user_info['mod_cache'] = $_SESSION['mc']; // This is a useful phantom permission added to the current user, and only the current user while they are logged in. // For example this drastically simplifies certain changes to the profile area. $user_info['permissions'][] = 'is_not_guest'; // And now some backwards compatibility stuff for mods and whatnot that aren't expecting the new permissions. $user_info['permissions'][] = 'profile_view_own'; if (in_array('profile_view', $user_info['permissions'])) $user_info['permissions'][] = 'profile_view_any'; } } /** * Loads an array of users' data by ID or member_name. * * @param array|string $users An array of users by id or name or a single username/id * @param bool $is_name Whether $users contains names * @param string $set What kind of data to load (normal, profile, minimal) * @return array|bool The ids of the members loaded or false if no data was loaded */ function loadMemberData($users, $is_name = false, $set = 'normal') { global $user_profile, $modSettings, $board_info, $smcFunc, $context; // Can't just look for no users :P. if (empty($users)) return false; // Pass the set value $context['loadMemberContext_set'] = $set; // Make sure it's an array. $users = !is_array($users) ? array($users) : array_unique($users); $loaded_ids = array(); if (!$is_name && !empty($modSettings['cache_enable']) && $modSettings['cache_enable'] >= 3) { $users = array_values($users); for ($i = 0, $n = count($users); $i < $n; $i++) { $data = cache_get_data('member_data-' . $set . '-' . $users[$i], 240); if ($data == null) continue; $loaded_ids[] = $data['id_member']; $user_profile[$data['id_member']] = $data; unset($users[$i]); } } // Used by default $select_columns = ' IFNULL(lo.log_time, 0) AS is_online, IFNULL(a.id_attach, 0) AS id_attach, a.filename, a.attachment_type, mem.signature, mem.personal_text, mem.location, mem.gender, mem.avatar, mem.id_member, mem.member_name, mem.real_name, mem.email_address, mem.hide_email, mem.date_registered, mem.website_title, mem.website_url, mem.birthdate, mem.member_ip, mem.member_ip2, mem.icq, mem.aim, mem.yim, mem.skype, mem.posts, mem.last_login, mem.karma_good, mem.id_post_group, mem.karma_bad, mem.lngfile, mem.id_group, mem.time_offset, mem.show_online, mg.online_color AS member_group_color, IFNULL(mg.group_name, {string:blank_string}) AS member_group, pg.online_color AS post_group_color, IFNULL(pg.group_name, {string:blank_string}) AS post_group, mem.is_activated, mem.warning, ' . (!empty($modSettings['titlesEnable']) ? 'mem.usertitle, ' : '') . ' CASE WHEN mem.id_group = 0 OR mg.icons = {string:blank_string} THEN pg.icons ELSE mg.icons END AS icons'; $select_tables = ' LEFT JOIN {db_prefix}log_online AS lo ON (lo.id_member = mem.id_member) LEFT JOIN {db_prefix}attachments AS a ON (a.id_member = mem.id_member) LEFT JOIN {db_prefix}membergroups AS pg ON (pg.id_group = mem.id_post_group) LEFT JOIN {db_prefix}membergroups AS mg ON (mg.id_group = mem.id_group)'; // We add or replace according the the set switch ($set) { case 'normal': $select_columns .= ', mem.buddy_list, mem.additional_groups'; break; case 'profile': $select_columns .= ', mem.additional_groups, mem.openid_uri, mem.id_theme, mem.pm_ignore_list, mem.pm_email_notify, mem.pm_receive_from, mem.time_format, mem.secret_question, mem.smiley_set, mem.total_time_logged_in, mem.notify_announcements, mem.notify_regularity, mem.notify_send_body, mem.notify_types, lo.url, mem.ignore_boards, mem.password_salt, mem.pm_prefs, mem.buddy_list'; break; case 'minimal': $select_columns = ' mem.id_member, mem.member_name, mem.real_name, mem.email_address, mem.hide_email, mem.date_registered, mem.posts, mem.last_login, mem.member_ip, mem.member_ip2, mem.lngfile, mem.id_group'; $select_tables = ''; break; default: trigger_error('loadMemberData(): Invalid member data set \'' . $set . '\'', E_USER_WARNING); } // Allow mods to easily add to the selected member data call_integration_hook('integrate_load_member_data', array(&$select_columns, &$select_tables, &$set)); if (!empty($users)) { // Load the member's data. $request = $smcFunc['db_query']('', ' SELECT' . $select_columns . ' FROM {db_prefix}members AS mem' . $select_tables . ' WHERE mem.' . ($is_name ? 'member_name' : 'id_member') . ' IN ({' . ($is_name ? 'array_string' : 'array_int') . ':users})', array( 'blank_string' => '', 'users' => $users, ) ); $new_loaded_ids = array(); while ($row = $smcFunc['db_fetch_assoc']($request)) { $new_loaded_ids[] = $row['id_member']; $loaded_ids[] = $row['id_member']; $row['options'] = array(); $user_profile[$row['id_member']] = $row; } $smcFunc['db_free_result']($request); } if (!empty($new_loaded_ids) && $set !== 'minimal') { $request = $smcFunc['db_query']('', ' SELECT * FROM {db_prefix}themes WHERE id_member IN ({array_int:loaded_ids})', array( 'loaded_ids' => $new_loaded_ids, ) ); while ($row = $smcFunc['db_fetch_assoc']($request)) $user_profile[$row['id_member']]['options'][$row['variable']] = $row['value']; $smcFunc['db_free_result']($request); } $additional_mods = array(); // Are any of these users in groups assigned to moderate this board? if (!empty($loaded_ids) && !empty($board_info['moderator_groups']) && $set === 'normal') { foreach ($loaded_ids as $a_member) { if (!empty($user_profile[$a_member]['additional_groups'])) $groups = array_merge(array($user_profile[$a_member]['id_group']), explode(',', $user_profile[$a_member]['additional_groups'])); else $groups = array($user_profile[$a_member]['id_group']); $temp = array_intersect($groups, array_keys($board_info['moderator_groups'])); if (!empty($temp)) { $additional_mods[] = $a_member; } } } if (!empty($new_loaded_ids) && !empty($modSettings['cache_enable']) && $modSettings['cache_enable'] >= 3) { for ($i = 0, $n = count($new_loaded_ids); $i < $n; $i++) cache_put_data('member_data-' . $set . '-' . $new_loaded_ids[$i], $user_profile[$new_loaded_ids[$i]], 240); } // Are we loading any moderators? If so, fix their group data... if (!empty($loaded_ids) && (!empty($board_info['moderators']) || !empty($board_info['moderator_groups'])) && $set === 'normal' && count($temp_mods = array_merge(array_intersect($loaded_ids, array_keys($board_info['moderators'])), $additional_mods)) !== 0) { if (($row = cache_get_data('moderator_group_info', 480)) == null) { $request = $smcFunc['db_query']('', ' SELECT group_name AS member_group, online_color AS member_group_color, icons FROM {db_prefix}membergroups WHERE id_group = {int:moderator_group} LIMIT 1', array( 'moderator_group' => 3, ) ); $row = $smcFunc['db_fetch_assoc']($request); $smcFunc['db_free_result']($request); cache_put_data('moderator_group_info', $row, 480); } foreach ($temp_mods as $id) { // By popular demand, don't show admins or global moderators as moderators. if ($user_profile[$id]['id_group'] != 1 && $user_profile[$id]['id_group'] != 2) $user_profile[$id]['member_group'] = $row['member_group']; // If the Moderator group has no color or icons, but their group does... don't overwrite. if (!empty($row['icons'])) $user_profile[$id]['icons'] = $row['icons']; if (!empty($row['member_group_color'])) $user_profile[$id]['member_group_color'] = $row['member_group_color']; } } return empty($loaded_ids) ? false : $loaded_ids; } /** * Loads the user's basic values... meant for template/theme usage. * * @param int $user The ID of a user previously loaded by {@link loadMemberData()} * @param bool $display_custom_fields Whether or not to display custom profile fields * @return boolean Whether or not the data was loaded successfully */ function loadMemberContext($user, $display_custom_fields = false) { global $memberContext, $user_profile, $txt, $scripturl, $user_info; global $context, $modSettings, $settings; global $smcFunc; static $dataLoaded = array(); // If this person's data is already loaded, skip it. if (isset($dataLoaded[$user])) return true; // We can't load guests or members not loaded by loadMemberData()! if ($user == 0) return false; if (!isset($user_profile[$user])) { trigger_error('loadMemberContext(): member id ' . $user . ' not previously loaded by loadMemberData()', E_USER_WARNING); return false; } // Well, it's loaded now anyhow. $dataLoaded[$user] = true; $profile = $user_profile[$user]; // Censor everything. censorText($profile['signature']); censorText($profile['personal_text']); censorText($profile['location']); // Set things up to be used before hand. $gendertxt = $profile['gender'] == 2 ? $txt['female'] : ($profile['gender'] == 1 ? $txt['male'] : ''); $profile['signature'] = str_replace(array("\n", "\r"), array('
', ''), $profile['signature']); $profile['signature'] = parse_bbc($profile['signature'], true, 'sig' . $profile['id_member']); $profile['is_online'] = (!empty($profile['show_online']) || allowedTo('moderate_forum')) && $profile['is_online'] > 0; $profile['icons'] = empty($profile['icons']) ? array('', '') : explode('#', $profile['icons']); // Setup the buddy status here (One whole in_array call saved :P) $profile['buddy'] = in_array($profile['id_member'], $user_info['buddies']); $buddy_list = !empty($profile['buddy_list']) ? explode(',', $profile['buddy_list']) : array(); // If we're always html resizing, assume it's too large. if ($modSettings['avatar_action_too_large'] == 'option_html_resize' || $modSettings['avatar_action_too_large'] == 'option_js_resize') { $avatar_width = !empty($modSettings['avatar_max_width_external']) ? ' width="' . $modSettings['avatar_max_width_external'] . '"' : ''; $avatar_height = !empty($modSettings['avatar_max_height_external']) ? ' height="' . $modSettings['avatar_max_height_external'] . '"' : ''; } else { $avatar_width = ''; $avatar_height = ''; } // These minimal values are always loaded $memberContext[$user] = array( 'username' => $profile['member_name'], 'name' => $profile['real_name'], 'id' => $profile['id_member'], 'href' => $scripturl . '?action=profile;u=' . $profile['id_member'], 'link' => '' . $profile['real_name'] . '', 'email' => $profile['email_address'], 'show_email' => showEmailAddress(!empty($profile['hide_email']), $profile['id_member']), 'registered' => empty($profile['date_registered']) ? $txt['not_applicable'] : timeformat($profile['date_registered']), 'registered_timestamp' => empty($profile['date_registered']) ? 0 : forum_time(true, $profile['date_registered']), ); // If the set isn't minimal then load the monstrous array. if ($context['loadMemberContext_set'] != 'minimal') $memberContext[$user] += array( 'username_color' => ''. $profile['member_name'] .'', 'name_color' => ''. $profile['real_name'] .'', 'link_color' => '' . $profile['real_name'] . '', 'is_buddy' => $profile['buddy'], 'is_reverse_buddy' => in_array($user_info['id'], $buddy_list), 'buddies' => $buddy_list, 'title' => !empty($modSettings['titlesEnable']) ? $profile['usertitle'] : '', 'blurb' => $profile['personal_text'], 'gender' => array( 'name' => $gendertxt, 'image' => !empty($profile['gender']) ? '' : '' ), 'website' => array( 'title' => $profile['website_title'], 'url' => $profile['website_url'], ), 'birth_date' => empty($profile['birthdate']) || $profile['birthdate'] === '0001-01-01' ? '0000-00-00' : (substr($profile['birthdate'], 0, 4) === '0004' ? '0000' . substr($profile['birthdate'], 4) : $profile['birthdate']), 'signature' => $profile['signature'], 'location' => $profile['location'], 'icq' => $profile['icq'] != '' && !$user_info['is_guest'] ? array( 'name' => $profile['icq'], 'href' => 'http://www.icq.com/whitepages/about_me.php?uin=' . $profile['icq'], 'link' => '' . $txt['icq'] . ' - ' . $profile['icq'] . '', 'link_text' => '' . $profile['icq'] . '', ) : array('name' => '', 'add' => '', 'href' => '', 'link' => '', 'link_text' => ''), 'aim' => $profile['aim'] != '' && !$user_info['is_guest'] ? array( 'name' => $profile['aim'], 'href' => 'aim:goim?screenname=' . urlencode(strtr($profile['aim'], array(' ' => '%20'))) . '&message=' . $txt['aim_default_message'], 'link' => '' . $txt['aim_title'] . ' - ' . $profile['aim'] . '', 'link_text' => '' . $profile['aim'] . '' ) : array('name' => '', 'href' => '', 'link' => '', 'link_text' => ''), 'yim' => $profile['yim'] != '' && !$user_info['is_guest'] ? array( 'name' => $profile['yim'], 'href' => 'http://edit.yahoo.com/config/send_webmesg?.target=' . urlencode($profile['yim']), 'link' => '' . $txt['yim_title'] . ' - ' . $profile['yim'] . '', 'link_text' => '' . $profile['yim'] . '' ) : array('name' => '', 'href' => '', 'link' => '', 'link_text' => ''), 'skype' => !empty($profile['skype']) && !$user_info['is_guest'] ? array( 'name' => $profile['skype'], 'href' => 'skype:' . $profile['skype'] . '?chat', 'link' => '' . $txt['skype'] . ' - ' . $profile['skype'] . '', 'link_text' => '' . $profile['skype'] . '', ) : array('name' => '', 'href' => '', 'link' => '', 'link_text' => '',), 'real_posts' => $profile['posts'], 'posts' => $profile['posts'] > 500000 ? $txt['geek'] : comma_format($profile['posts']), 'avatar' => array( 'name' => $profile['avatar'], 'image' => $profile['avatar'] == '' ? ($profile['id_attach'] > 0 ? '' : '') : (stristr($profile['avatar'], 'http://') ? '' : ''), 'href' => $profile['avatar'] == '' ? ($profile['id_attach'] > 0 ? (empty($profile['attachment_type']) ? $scripturl . '?action=dlattach;attach=' . $profile['id_attach'] . ';type=avatar' : $modSettings['custom_avatar_url'] . '/' . $profile['filename']) : '') : (stristr($profile['avatar'], 'http://') ? $profile['avatar'] : $modSettings['avatar_url'] . '/' . $profile['avatar']), 'url' => $profile['avatar'] == '' ? '' : (stristr($profile['avatar'], 'http://') ? $profile['avatar'] : $modSettings['avatar_url'] . '/' . $profile['avatar']) ), 'last_login' => empty($profile['last_login']) ? $txt['never'] : timeformat($profile['last_login']), 'last_login_timestamp' => empty($profile['last_login']) ? 0 : forum_time(0, $profile['last_login']), 'karma' => array( 'good' => $profile['karma_good'], 'bad' => $profile['karma_bad'], 'allow' => !$user_info['is_guest'] && !empty($modSettings['karmaMode']) && $user_info['id'] != $user && allowedTo('karma_edit') && ($user_info['posts'] >= $modSettings['karmaMinPosts'] || $user_info['is_admin']), ), 'ip' => $smcFunc['htmlspecialchars']($profile['member_ip']), 'ip2' => $smcFunc['htmlspecialchars']($profile['member_ip2']), 'online' => array( 'is_online' => $profile['is_online'], 'text' => $smcFunc['htmlspecialchars']($txt[$profile['is_online'] ? 'online' : 'offline']), 'member_online_text' => sprintf($txt[$profile['is_online'] ? 'member_is_online' : 'member_is_offline'], $smcFunc['htmlspecialchars']($profile['real_name'])), 'href' => $scripturl . '?action=pm;sa=send;u=' . $profile['id_member'], 'link' => '' . $txt[$profile['is_online'] ? 'online' : 'offline'] . '', 'image_href' => $settings['images_url'] . '/' . ($profile['buddy'] ? 'buddy_' : '') . ($profile['is_online'] ? 'useron' : 'useroff') . '.png', 'label' => $txt[$profile['is_online'] ? 'online' : 'offline'] ), 'language' => $smcFunc['ucwords'](strtr($profile['lngfile'], array('_' => ' ', '-utf8' => ''))), 'is_activated' => isset($profile['is_activated']) ? $profile['is_activated'] : 1, 'is_banned' => isset($profile['is_activated']) ? $profile['is_activated'] >= 10 : 0, 'options' => $profile['options'], 'is_guest' => false, 'group' => $profile['member_group'], 'group_color' => $profile['member_group_color'], 'group_id' => $profile['id_group'], 'post_group' => $profile['post_group'], 'post_group_color' => $profile['post_group_color'], 'group_icons' => str_repeat('*', empty($profile['icons'][0]) || empty($profile['icons'][1]) ? 0 : $profile['icons'][0]), 'warning' => $profile['warning'], 'warning_status' => !empty($modSettings['warning_mute']) && $modSettings['warning_mute'] <= $profile['warning'] ? 'mute' : (!empty($modSettings['warning_moderate']) && $modSettings['warning_moderate'] <= $profile['warning'] ? 'moderate' : (!empty($modSettings['warning_watch']) && $modSettings['warning_watch'] <= $profile['warning'] ? 'watch' : (''))), 'local_time' => timeformat(time() + ($profile['time_offset'] - $user_info['time_offset']) * 3600, false), ); // First do a quick run through to make sure there is something to be shown. $memberContext[$user]['has_messenger'] = false; foreach (array('icq', 'skype', 'aim', 'yim') as $messenger) { if (!isset($context['disabled_fields'][$messenger]) && !empty($memberContext[$user][$messenger]['link'])) { $memberContext[$user]['has_messenger'] = true; break; } } // Are we also loading the members custom fields into context? if ($display_custom_fields && !empty($modSettings['displayFields'])) { $memberContext[$user]['custom_fields'] = array(); if (!isset($context['display_fields'])) $context['display_fields'] = unserialize($modSettings['displayFields']); foreach ($context['display_fields'] as $custom) { if (!isset($custom['title']) || trim($custom['title']) == '' || empty($profile['options'][$custom['colname']])) continue; $value = $profile['options'][$custom['colname']]; // BBC? if ($custom['bbc']) $value = parse_bbc($value); // ... or checkbox? elseif (isset($custom['type']) && $custom['type'] == 'check') $value = $value ? $txt['yes'] : $txt['no']; // Enclosing the user input within some other text? if (!empty($custom['enclose'])) $value = strtr($custom['enclose'], array( '{SCRIPTURL}' => $scripturl, '{IMAGES_URL}' => $settings['images_url'], '{DEFAULT_IMAGES_URL}' => $settings['default_images_url'], '{INPUT}' => $value, )); $memberContext[$user]['custom_fields'][] = array( 'title' => $custom['title'], 'colname' => $custom['colname'], 'value' => $value, 'placement' => !empty($custom['placement']) ? $custom['placement'] : 0, ); } } call_integration_hook('integrate_member_context', array(&$user, $display_custom_fields)); return true; } /** * Loads the user's custom profile fields * * @param integer|array $users A single user ID or an array of user IDs * @param string|array $param Either a string or an array of strings with profile field names * @return array|boolean An array of data about the fields and their values or false if nothing was loaded */ function loadMemberCustomFields($users, $params) { global $smcFunc, $txt, $scripturl, $settings; // Do not waste my time... if (empty($users) || empty($params)) return false; // Make sure it's an array. $users = !is_array($users) ? array($users) : array_unique($users); $params = !is_array($params) ? array($params) : array_unique($params); $return = array(); $request = $smcFunc['db_query']('', ' SELECT c.id_field, c.col_name, c.field_name, c.field_desc, c.field_type, c.field_length, c.field_options, c.mask, show_reg, c.show_display, c.show_profile, c.private, c.active, c.bbc, c.can_search, c.default_value, c.enclose, c.placement, t.variable, t.value, t.id_member FROM {db_prefix}themes AS t LEFT JOIN {db_prefix}custom_fields AS c ON (c.col_name = t.variable) WHERE id_member IN ({array_int:loaded_ids}) AND variable IN ({array_string:params})', array( 'loaded_ids' => $users, 'params' => $params, ) ); while ($row = $smcFunc['db_fetch_assoc']($request)) { // BBC? if (!empty($row['bbc'])) $row['value'] = parse_bbc($row['value']); // ... or checkbox? elseif (isset($row['type']) && $row['type'] == 'check') $row['value'] = !empty($row['value']) ? $txt['yes'] : $txt['no']; // Enclosing the user input within some other text? if (!empty($row['enclose'])) $row['value'] = strtr($row['enclose'], array( '{SCRIPTURL}' => $scripturl, '{IMAGES_URL}' => $settings['images_url'], '{DEFAULT_IMAGES_URL}' => $settings['default_images_url'], '{INPUT}' => $row['value'], )); // Send a simple array if there is just 1 param if (count($params) == 1) $return[$row['id_member']] = $row; // More than 1? knock yourself out... else $return[$row['id_member']][$row['id_field']] = $row; } $smcFunc['db_free_result']($request); return !empty($return) ? $return : false; } /** * Loads information about what browser the user is viewing with and places it in $context * - uses the class from Class-BrowerDetect.php * */ function detectBrowser() { // Load the current user's browser of choice $detector = new browser_detector; $detector->detectBrowser(); } /** * Are we using this browser? * * Wrapper function for detectBrowser * @param string $browser The browser we are checking for. */ function isBrowser($browser) { global $context; // @todo REMOVE THIS BEFORE BETA 1 RELEASE. if (in_array($browser, array('ie7', 'ie6', 'ie5.5', 'ie5', 'ie5', 'ie4', 'mac_ie', 'firefox1'))) { $line = $file = null; foreach (debug_backtrace() as $step) { // Found it? if (strpos($step['function'], 'query') === false && !in_array(substr($step['function'], 0, 7), array('smf_db_', 'preg_re', 'db_erro', 'call_us')) && strpos($step['function'], '__') !== 0) { $function = '
Function: ' . $step['function']; break; } if (isset($step['line'])) { $file = $step['file']; $line = $step['line']; } } log_error('Old browser support' . $function, 'debug', $file, $line); } // Don't know any browser! if (empty($context['browser'])) detectBrowser(); return !empty($context['browser'][$browser]) || !empty($context['browser']['is_' . $browser]) ? true : false; } /** * Load a theme, by ID. * * @param int $id_theme The ID of the theme to load * @param bool $initialize Whether or not to initialize a bunch of theme-related variables/settings */ function loadTheme($id_theme = 0, $initialize = true) { global $user_info, $user_settings, $board_info, $boarddir; global $txt, $boardurl, $scripturl, $mbname, $modSettings; global $context, $settings, $options, $sourcedir, $ssi_theme, $smcFunc; // The theme was specified by parameter. if (!empty($id_theme)) $id_theme = (int) $id_theme; // The theme was specified by REQUEST. elseif (!empty($_REQUEST['theme']) && (!empty($modSettings['theme_allow']) || allowedTo('admin_forum'))) { $id_theme = (int) $_REQUEST['theme']; $_SESSION['id_theme'] = $id_theme; } // The theme was specified by REQUEST... previously. elseif (!empty($_SESSION['id_theme']) && (!empty($modSettings['theme_allow']) || allowedTo('admin_forum'))) $id_theme = (int) $_SESSION['id_theme']; // The theme is just the user's choice. (might use ?board=1;theme=0 to force board theme.) elseif (!empty($user_info['theme']) && !isset($_REQUEST['theme']) && (!empty($modSettings['theme_allow']) || allowedTo('admin_forum'))) $id_theme = $user_info['theme']; // The theme was specified by the board. elseif (!empty($board_info['theme'])) $id_theme = $board_info['theme']; // The theme is the forum's default. else $id_theme = $modSettings['theme_guests']; // Verify the id_theme... no foul play. // Always allow the board specific theme, if they are overriding. if (!empty($board_info['theme']) && $board_info['override_theme']) $id_theme = $board_info['theme']; // If they have specified a particular theme to use with SSI allow it to be used. elseif (!empty($ssi_theme) && $id_theme == $ssi_theme) $id_theme = (int) $id_theme; elseif (!empty($modSettings['enableThemes']) && !allowedTo('admin_forum')) { $themes = explode(',', $modSettings['enableThemes']); if (!in_array($id_theme, $themes)) $id_theme = $modSettings['theme_guests']; else $id_theme = (int) $id_theme; } else $id_theme = (int) $id_theme; $member = empty($user_info['id']) ? -1 : $user_info['id']; if (!empty($modSettings['cache_enable']) && $modSettings['cache_enable'] >= 2 && ($temp = cache_get_data('theme_settings-' . $id_theme . ':' . $member, 60)) != null && time() - 60 > $modSettings['settings_updated']) { $themeData = $temp; $flag = true; } elseif (($temp = cache_get_data('theme_settings-' . $id_theme, 90)) != null && time() - 60 > $modSettings['settings_updated']) $themeData = $temp + array($member => array()); else $themeData = array(-1 => array(), 0 => array(), $member => array()); if (empty($flag)) { // Load variables from the current or default theme, global or this user's. $result = $smcFunc['db_query']('', ' SELECT variable, value, id_member, id_theme FROM {db_prefix}themes WHERE id_member' . (empty($themeData[0]) ? ' IN (-1, 0, {int:id_member})' : ' = {int:id_member}') . ' AND id_theme' . ($id_theme == 1 ? ' = {int:id_theme}' : ' IN ({int:id_theme}, 1)'), array( 'id_theme' => $id_theme, 'id_member' => $member, ) ); // Pick between $settings and $options depending on whose data it is. while ($row = $smcFunc['db_fetch_assoc']($result)) { // There are just things we shouldn't be able to change as members. if ($row['id_member'] != 0 && in_array($row['variable'], array('actual_theme_url', 'actual_images_url', 'base_theme_dir', 'base_theme_url', 'default_images_url', 'default_theme_dir', 'default_theme_url', 'default_template', 'images_url', 'number_recent_posts', 'smiley_sets_default', 'theme_dir', 'theme_id', 'theme_layers', 'theme_templates', 'theme_url'))) continue; // If this is the theme_dir of the default theme, store it. if (in_array($row['variable'], array('theme_dir', 'theme_url', 'images_url')) && $row['id_theme'] == '1' && empty($row['id_member'])) $themeData[0]['default_' . $row['variable']] = $row['value']; // If this isn't set yet, is a theme option, or is not the default theme.. if (!isset($themeData[$row['id_member']][$row['variable']]) || $row['id_theme'] != '1') $themeData[$row['id_member']][$row['variable']] = substr($row['variable'], 0, 5) == 'show_' ? $row['value'] == '1' : $row['value']; } $smcFunc['db_free_result']($result); if (!empty($themeData[-1])) foreach ($themeData[-1] as $k => $v) { if (!isset($themeData[$member][$k])) $themeData[$member][$k] = $v; } if (!empty($modSettings['cache_enable']) && $modSettings['cache_enable'] >= 2) cache_put_data('theme_settings-' . $id_theme . ':' . $member, $themeData, 60); // Only if we didn't already load that part of the cache... elseif (!isset($temp)) cache_put_data('theme_settings-' . $id_theme, array(-1 => $themeData[-1], 0 => $themeData[0]), 90); } $settings = $themeData[0]; $options = $themeData[$member]; $settings['theme_id'] = $id_theme; $settings['actual_theme_url'] = $settings['theme_url']; $settings['actual_images_url'] = $settings['images_url']; $settings['actual_theme_dir'] = $settings['theme_dir']; $settings['template_dirs'] = array(); // This theme first. $settings['template_dirs'][] = $settings['theme_dir']; // Based on theme (if there is one). if (!empty($settings['base_theme_dir'])) $settings['template_dirs'][] = $settings['base_theme_dir']; // Lastly the default theme. if ($settings['theme_dir'] != $settings['default_theme_dir']) $settings['template_dirs'][] = $settings['default_theme_dir']; if (!$initialize) return; // Check to see if they're accessing it from the wrong place. if (isset($_SERVER['HTTP_HOST']) || isset($_SERVER['SERVER_NAME'])) { $detected_url = isset($_SERVER['HTTPS']) && strtolower($_SERVER['HTTPS']) == 'on' ? 'https://' : 'http://'; $detected_url .= empty($_SERVER['HTTP_HOST']) ? $_SERVER['SERVER_NAME'] . (empty($_SERVER['SERVER_PORT']) || $_SERVER['SERVER_PORT'] == '80' ? '' : ':' . $_SERVER['SERVER_PORT']) : $_SERVER['HTTP_HOST']; $temp = preg_replace('~/' . basename($scripturl) . '(/.+)?$~', '', strtr(dirname($_SERVER['PHP_SELF']), '\\', '/')); if ($temp != '/') $detected_url .= $temp; } if (isset($detected_url) && $detected_url != $boardurl) { // Try #1 - check if it's in a list of alias addresses. if (!empty($modSettings['forum_alias_urls'])) { $aliases = explode(',', $modSettings['forum_alias_urls']); foreach ($aliases as $alias) { // Rip off all the boring parts, spaces, etc. if ($detected_url == trim($alias) || strtr($detected_url, array('http://' => '', 'https://' => '')) == trim($alias)) $do_fix = true; } } // Hmm... check #2 - is it just different by a www? Send them to the correct place!! if (empty($do_fix) && strtr($detected_url, array('://' => '://www.')) == $boardurl && (empty($_GET) || count($_GET) == 1) && SMF != 'SSI') { // Okay, this seems weird, but we don't want an endless loop - this will make $_GET not empty ;). if (empty($_GET)) redirectexit('wwwRedirect'); else { list ($k, $v) = each($_GET); if ($k != 'wwwRedirect') redirectexit('wwwRedirect;' . $k . '=' . $v); } } // #3 is just a check for SSL... if (strtr($detected_url, array('https://' => 'http://')) == $boardurl) $do_fix = true; // Okay, #4 - perhaps it's an IP address? We're gonna want to use that one, then. (assuming it's the IP or something...) if (!empty($do_fix) || preg_match('~^http[s]?://(?:[\d\.:]+|\[[\d:]+\](?::\d+)?)(?:$|/)~', $detected_url) == 1) { // Caching is good ;). $oldurl = $boardurl; // Fix $boardurl and $scripturl. $boardurl = $detected_url; $scripturl = strtr($scripturl, array($oldurl => $boardurl)); $_SERVER['REQUEST_URL'] = strtr($_SERVER['REQUEST_URL'], array($oldurl => $boardurl)); // Fix the theme urls... $settings['theme_url'] = strtr($settings['theme_url'], array($oldurl => $boardurl)); $settings['default_theme_url'] = strtr($settings['default_theme_url'], array($oldurl => $boardurl)); $settings['actual_theme_url'] = strtr($settings['actual_theme_url'], array($oldurl => $boardurl)); $settings['images_url'] = strtr($settings['images_url'], array($oldurl => $boardurl)); $settings['default_images_url'] = strtr($settings['default_images_url'], array($oldurl => $boardurl)); $settings['actual_images_url'] = strtr($settings['actual_images_url'], array($oldurl => $boardurl)); // And just a few mod settings :). $modSettings['smileys_url'] = strtr($modSettings['smileys_url'], array($oldurl => $boardurl)); $modSettings['avatar_url'] = strtr($modSettings['avatar_url'], array($oldurl => $boardurl)); // Clean up after loadBoard(). if (isset($board_info['moderators'])) { foreach ($board_info['moderators'] as $k => $dummy) { $board_info['moderators'][$k]['href'] = strtr($dummy['href'], array($oldurl => $boardurl)); $board_info['moderators'][$k]['link'] = strtr($dummy['link'], array('"' . $oldurl => '"' . $boardurl)); } } foreach ($context['linktree'] as $k => $dummy) $context['linktree'][$k]['url'] = strtr($dummy['url'], array($oldurl => $boardurl)); } } // Set up the contextual user array. $context['user'] = array( 'id' => $user_info['id'], 'is_logged' => !$user_info['is_guest'], 'is_guest' => &$user_info['is_guest'], 'is_admin' => &$user_info['is_admin'], 'is_mod' => &$user_info['is_mod'], // A user can mod if they have permission to see the mod center, or they are a board/group/approval moderator. 'can_mod' => allowedTo('access_mod_center') || (!$user_info['is_guest'] && ($user_info['mod_cache']['gq'] != '0=1' || $user_info['mod_cache']['bq'] != '0=1' || ($modSettings['postmod_active'] && !empty($user_info['mod_cache']['ap'])))), 'username' => $user_info['username'], 'language' => $user_info['language'], 'email' => $user_info['email'], 'ignoreusers' => $user_info['ignoreusers'], ); if (!$context['user']['is_guest']) $context['user']['name'] = $user_info['name']; elseif ($context['user']['is_guest'] && !empty($txt['guest_title'])) $context['user']['name'] = $txt['guest_title']; // Determine the current smiley set. $user_info['smiley_set'] = (!in_array($user_info['smiley_set'], explode(',', $modSettings['smiley_sets_known'])) && $user_info['smiley_set'] != 'none') || empty($modSettings['smiley_sets_enable']) ? (!empty($settings['smiley_sets_default']) ? $settings['smiley_sets_default'] : $modSettings['smiley_sets_default']) : $user_info['smiley_set']; $context['user']['smiley_set'] = $user_info['smiley_set']; // Some basic information... if (!isset($context['html_headers'])) $context['html_headers'] = ''; if (!isset($context['javascript_files'])) $context['javascript_files'] = array(); if (!isset($context['css_files'])) $context['css_files'] = array(); if (!isset($context['javascript_inline'])) $context['javascript_inline'] = array('standard' => array(), 'defer' => array()); if (!isset($context['javascript_vars'])) $context['javascript_vars'] = array(); $context['menu_separator'] = !empty($settings['use_image_buttons']) ? ' ' : ' | '; $context['session_var'] = $_SESSION['session_var']; $context['session_id'] = $_SESSION['session_value']; $context['forum_name'] = $mbname; $context['forum_name_html_safe'] = $smcFunc['htmlspecialchars']($context['forum_name']); $context['header_logo_url_html_safe'] = empty($settings['header_logo_url']) ? '' : $smcFunc['htmlspecialchars']($settings['header_logo_url']); $context['current_action'] = isset($_REQUEST['action']) ? $smcFunc['htmlspecialchars']($_REQUEST['action']) : null; $context['current_subaction'] = isset($_REQUEST['sa']) ? $_REQUEST['sa'] : null; $context['can_register'] = empty($modSettings['registration_method']) || $modSettings['registration_method'] != 3; if (isset($modSettings['load_average'])) $context['load_average'] = $modSettings['load_average']; // Set some permission related settings. $context['show_login_bar'] = $user_info['is_guest'] && !empty($modSettings['enableVBStyleLogin']); // Detect the browser. This is separated out because it's also used in attachment downloads detectBrowser(); // Set the top level linktree up. array_unshift($context['linktree'], array( 'url' => $scripturl, 'name' => $context['forum_name_html_safe'] )); // This allows sticking some HTML on the page output - useful for controls. $context['insert_after_template'] = ''; if (!isset($txt)) $txt = array(); $simpleActions = array( 'findmember', 'helpadmin', 'printpage', 'quotefast', 'spellcheck', ); // Wireless mode? Load up the wireless stuff. if (WIRELESS) { $context['template_layers'] = array(WIRELESS_PROTOCOL); loadTemplate('Wireless'); loadLanguage('Wireless+index+Modifications'); } // Output is fully XML, so no need for the index template. elseif (isset($_REQUEST['xml'])) { loadLanguage('index+Modifications'); loadTemplate('Xml'); $context['template_layers'] = array(); } // These actions don't require the index template at all. elseif (!empty($_REQUEST['action']) && in_array($_REQUEST['action'], $simpleActions)) { loadLanguage('index+Modifications'); $context['template_layers'] = array(); } else { // Custom templates to load, or just default? if (isset($settings['theme_templates'])) $templates = explode(',', $settings['theme_templates']); else $templates = array('index'); // Load each template... foreach ($templates as $template) loadTemplate($template); // ...and attempt to load their associated language files. $required_files = implode('+', array_merge($templates, array('Modifications'))); loadLanguage($required_files, '', false); // Custom template layers? if (isset($settings['theme_layers'])) $context['template_layers'] = explode(',', $settings['theme_layers']); else $context['template_layers'] = array('html', 'body'); } // Initialize the theme. loadSubTemplate('init', 'ignore'); // Guests may still need a name. if ($context['user']['is_guest'] && empty($context['user']['name'])) $context['user']['name'] = $txt['guest_title']; // Any theme-related strings that need to be loaded? if (!empty($settings['require_theme_strings'])) loadLanguage('ThemeStrings', '', false); // We allow theme variants, because we're cool. $context['theme_variant'] = ''; $context['theme_variant_url'] = ''; if (!empty($settings['theme_variants'])) { // Overriding - for previews and that ilk. if (!empty($_REQUEST['variant'])) $_SESSION['id_variant'] = $_REQUEST['variant']; // User selection? if (empty($settings['disable_user_variant']) || allowedTo('admin_forum')) $context['theme_variant'] = !empty($_SESSION['id_variant']) ? $_SESSION['id_variant'] : (!empty($options['theme_variant']) ? $options['theme_variant'] : ''); // If not a user variant, select the default. if ($context['theme_variant'] == '' || !in_array($context['theme_variant'], $settings['theme_variants'])) $context['theme_variant'] = !empty($settings['default_variant']) && in_array($settings['default_variant'], $settings['theme_variants']) ? $settings['default_variant'] : $settings['theme_variants'][0]; // Do this to keep things easier in the templates. $context['theme_variant'] = '_' . $context['theme_variant']; $context['theme_variant_url'] = $context['theme_variant'] . '/'; } // Let's be compatible with old themes! if (!function_exists('template_html_above') && in_array('html', $context['template_layers'])) $context['template_layers'] = array('main'); // Allow overriding the board wide time/number formats. if (empty($user_settings['time_format']) && !empty($txt['time_format'])) $user_info['time_format'] = $txt['time_format']; if (isset($settings['use_default_images']) && $settings['use_default_images'] == 'always') { $settings['theme_url'] = $settings['default_theme_url']; $settings['images_url'] = $settings['default_images_url']; $settings['theme_dir'] = $settings['default_theme_dir']; } // Make a special URL for the language. $settings['lang_images_url'] = $settings['images_url'] . '/' . (!empty($txt['image_lang']) ? $txt['image_lang'] : $user_info['language']); // Set the character set from the template. $context['character_set'] = empty($modSettings['global_character_set']) ? $txt['lang_character_set'] : $modSettings['global_character_set']; $context['utf8'] = $context['character_set'] === 'UTF-8'; $context['right_to_left'] = !empty($txt['lang_rtl']); $context['tabindex'] = 1; // Compatibility. if (!isset($settings['theme_version'])) $modSettings['memberCount'] = $modSettings['totalMembers']; // Default JS variables for use in every theme $context['javascript_vars'] = array( 'smf_theme_url' => '"' . $settings['theme_url'] . '"', 'smf_default_theme_url' => '"' . $settings['default_theme_url'] . '"', 'smf_images_url' => '"' . $settings['images_url'] . '"', 'smf_scripturl' => '"' . $scripturl . '"', 'smf_iso_case_folding' => $context['server']['iso_case_folding'] ? 'true' : 'false', 'smf_charset' => '"' . $context['character_set'] . '"', 'smf_session_id' => '"' . $context['session_id'] . '"', 'smf_session_var' => '"' . $context['session_var'] . '"', 'smf_member_id' => $context['user']['id'], 'ajax_notification_text' => JavaScriptEscape($txt['ajax_in_progress']), 'help_popup_heading_text' => JavaScriptEscape($txt['help_popup']), ); // Add the JQuery library to the list of files to load. if (isset($modSettings['jquery_source']) && $modSettings['jquery_source'] == 'cdn') loadJavascriptFile('https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js', array(), 'jquery'); elseif (isset($modSettings['jquery_source']) && $modSettings['jquery_source'] == 'local') loadJavascriptFile('jquery-1.7.1.min.js', array('default_theme' => true, 'seed' => false), 'jquery'); elseif (isset($modSettings['jquery_source'], $modSettings['jquery_custom']) && $modSettings['jquery_source'] == 'custom') loadJavascriptFile($modSettings['jquery_custom'], array(), 'jquery'); // Auto loading? template_javascript() will take care of the local half of this. else loadJavascriptFile('https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js', array(), 'jquery'); // Queue our JQuery plugins! loadJavascriptFile('smf_jquery_plugins.js', array('default_theme' => true)); // script.js and theme.js, always required, so always add them! Makes index.template.php cleaner and all. loadJavascriptFile('script.js', array('default_theme' => true), 'smf_scripts'); loadJavascriptFile('theme.js', array(), 'theme_scripts'); // If we think we have mail to send, let's offer up some possibilities... robots get pain (Now with scheduled task support!) if ((!empty($modSettings['mail_next_send']) && $modSettings['mail_next_send'] < time() && empty($modSettings['mail_queue_use_cron'])) || empty($modSettings['next_task_time']) || $modSettings['next_task_time'] < time()) { if (isBrowser('possibly_robot')) { // @todo Maybe move this somewhere better?! require_once($sourcedir . '/ScheduledTasks.php'); // What to do, what to do?! if (empty($modSettings['next_task_time']) || $modSettings['next_task_time'] < time()) AutoTask(); else ReduceMailQueue(); } else { $type = empty($modSettings['next_task_time']) || $modSettings['next_task_time'] < time() ? 'task' : 'mailq'; $ts = $type == 'mailq' ? $modSettings['mail_next_send'] : $modSettings['next_task_time']; addInlineJavascript(' function smfAutoTask() { var tempImage = new Image(); tempImage.src = smf_scripturl + "?scheduled=' . $type . ';ts=' . $ts . '"; } window.setTimeout("smfAutoTask();", 1);'); } } // Any files to include at this point? if (!empty($modSettings['integrate_theme_include'])) { $theme_includes = explode(',', $modSettings['integrate_theme_include']); foreach ($theme_includes as $include) { $include = strtr(trim($include), array('$boarddir' => $boarddir, '$sourcedir' => $sourcedir, '$themedir' => $settings['theme_dir'])); if (file_exists($include)) require_once($include); } } // Call load theme integration functions. call_integration_hook('integrate_load_theme'); // We are ready to go. $context['theme_loaded'] = true; } /** * Load a template - if the theme doesn't include it, use the default. * What this function does: * - loads a template file with the name template_name from the current, default, or base theme. * - detects a wrong default theme directory and tries to work around it. * * @uses the template_include() function to include the file. * @param string $template_name The name of the template to load * @param array|string $style_sheets The name of a single stylesheet or an array of names of stylesheets to load * @param bool $fatal If true, dies with an error message if the template cannot be found * @return boolean True if the template was loaded, false otherwise */ function loadTemplate($template_name, $style_sheets = array(), $fatal = true) { global $context, $settings, $txt, $scripturl, $boarddir, $db_show_debug; // Do any style sheets first, cause we're easy with those. if (!empty($style_sheets)) { if (!is_array($style_sheets)) $style_sheets = array($style_sheets); foreach ($style_sheets as $sheet) loadCSSFile($sheet . '.css', array(), $sheet); } // No template to load? if ($template_name === false) return true; $loaded = false; foreach ($settings['template_dirs'] as $template_dir) { if (file_exists($template_dir . '/' . $template_name . '.template.php')) { $loaded = true; template_include($template_dir . '/' . $template_name . '.template.php', true); break; } } if ($loaded) { // For compatibility reasons, if this is the index template without new functions, include compatible stuff. if (substr($template_name, 0, 5) == 'index' && !function_exists('template_button_strip')) loadTemplate('Compat'); if ($db_show_debug === true) $context['debug']['templates'][] = $template_name . ' (' . basename($template_dir) . ')'; // If they have specified an initialization function for this template, go ahead and call it now. if (function_exists('template_' . $template_name . '_init')) call_user_func('template_' . $template_name . '_init'); } // Hmmm... doesn't exist?! I don't suppose the directory is wrong, is it? elseif (!file_exists($settings['default_theme_dir']) && file_exists($boarddir . '/Themes/default')) { $settings['default_theme_dir'] = $boarddir . '/Themes/default'; $settings['template_dirs'][] = $settings['default_theme_dir']; if (!empty($context['user']['is_admin']) && !isset($_GET['th'])) { loadLanguage('Errors'); echo '
', $txt['theme_dir_wrong'], '
'; } loadTemplate($template_name); } // Cause an error otherwise. elseif ($template_name != 'Errors' && $template_name != 'index' && $fatal) fatal_lang_error('theme_template_error', 'template', array((string) $template_name)); elseif ($fatal) die(log_error(sprintf(isset($txt['theme_template_error']) ? $txt['theme_template_error'] : 'Unable to load Themes/default/%s.template.php!', (string) $template_name), 'template')); else return false; } /** * Load a sub-template. * What it does: * - loads the sub template specified by sub_template_name, which must be in an already-loaded template. * - if ?debug is in the query string, shows administrators a marker after every sub template * for debugging purposes. * * @todo get rid of reading $_REQUEST directly * * @param string $sub_template_name The name of the sub-template to load * @param bool Whether to die with an error if the sub-template can't be loaded */ function loadSubTemplate($sub_template_name, $fatal = false) { global $context, $txt, $db_show_debug; if ($db_show_debug === true) $context['debug']['sub_templates'][] = $sub_template_name; // Figure out what the template function is named. $theme_function = 'template_' . $sub_template_name; if (function_exists($theme_function)) $theme_function(); elseif ($fatal === false) fatal_lang_error('theme_template_error', 'template', array((string) $sub_template_name)); elseif ($fatal !== 'ignore') die(log_error(sprintf(isset($txt['theme_template_error']) ? $txt['theme_template_error'] : 'Unable to load the %s sub template!', (string) $sub_template_name), 'template')); // Are we showing debugging for templates? Just make sure not to do it before the doctype... if (allowedTo('admin_forum') && isset($_REQUEST['debug']) && !in_array($sub_template_name, array('init', 'main_below')) && ob_get_length() > 0 && !isset($_REQUEST['xml'])) { echo '
---- ', $sub_template_name, ' ends ----
'; } } /** * Add a CSS file for output later * * @param string $filename THe name of the file to load * @param array $params An array of parameters * Keys are the following: * - ['local'] (true/false): define if the file is local * - ['default_theme'] (true/false): force use of default theme url * - ['force_current'] (true/false): if this is false, we will attempt to load the file from the default theme if not found in the current theme * - ['validate'] (true/false): if true script will validate the local file exists * - ['seed'] (true/false/string): if true or null, use cache stale, false do not, or used a supplied string * @param string $id An ID to stick on the end of the filename for caching purposes */ function loadCSSFile($filename, $params = array(), $id = '') { global $settings, $context; $params['seed'] = (!isset($params['seed']) || $params['seed'] === true) ? '?alph21' : (is_string($params['seed']) ? ($params['seed'] = $params['seed'][0] === '?' ? $params['seed'] : '?' . $params['seed']) : ''); $params['force_current'] = !empty($params['force_current']) ? $params['force_current'] : false; $theme = !empty($params['default_theme']) ? 'default_theme' : 'theme'; // account for shorthand like admin.css?alp21 filenames $has_seed = strpos($filename, '.css?'); $id = empty($id) ? strtr(basename($filename), '?', '_') : $id; // Is this a local file? if (strpos($filename, 'http') === false || !empty($params['local'])) { // Are we validating the the file exists? if (!empty($params['validate']) && !file_exists($settings[$theme . '_dir'] . '/css/' . $filename)) { // Maybe the default theme has it? if ($theme === 'theme' && !$params['force_current'] && file_exists($settings['default_theme_dir'] . '/css/' . $filename)) $filename = $settings['default_theme_url'] . '/css/' . $filename . ($has_seed ? '' : $params['seed']); else $filename = false; } else $filename = $settings[$theme . '_url'] . '/css/' . $filename . ($has_seed ? '' : $params['seed']); } // Add it to the array for use in the template if (!empty($filename)) $context['css_files'][$id] = array('filename' => $filename, 'options' => $params); } /** * Add a Javascript file for output later * @param string $filename The name of the file to load * @param array $params An array of parameter info * Keys are the following: * - ['local'] (true/false): define if the file is local * - ['default_theme'] (true/false): force use of default theme url * - ['defer'] (true/false): define if the file should load in or before the closing tag * - ['force_current'] (true/false): if this is false, we will attempt to load the file from the * default theme if not found in the current theme * - ['async'] (true/false): if the script should be loaded asynchronously (HTML5) * - ['validate'] (true/false): if true script will validate the local file exists * - ['seed'] (true/false/string): if true or null, use cache stale, false do not, or used a supplied string * * @param string $id An ID to stik on the end of the filename */ function loadJavascriptFile($filename, $params = array(), $id = '') { global $settings, $context; $params['seed'] = (!isset($params['seed']) || $params['seed'] === true) ? '?alph21' : (is_string($params['seed']) ? ($params['seed'] = $params['seed'][0] === '?' ? $params['seed'] : '?' . $params['seed']) : ''); $params['force_current'] = !empty($params['force_current']) ? $params['force_current'] : false; $theme = !empty($params['default_theme']) ? 'default_theme' : 'theme'; // account for shorthand like admin.js?alp21 filenames $has_seed = strpos($filename, '.js?'); $id = empty($id) ? strtr(basename($filename), '?', '_') : $id; // Is this a local file? if (strpos($filename, 'http') === false || !empty($params['local'])) { // Are we validating it exists on disk? if (!empty($params['validate']) && !file_exists($settings[$theme . '_dir'] . '/scripts/' . $filename)) { // can't find it in this theme, how about the default? if ($theme === 'theme' && !$params['force_current'] && file_exists($settings['default_theme_dir'] . '/' . $filename)) $filename = $settings['default_theme_url'] . '/scripts/' . $filename . ($has_seed ? '' : $params['seed']); else $filename = false; } else $filename = $settings[$theme . '_url'] . '/scripts/' . $filename . ($has_seed ? '' : $params['seed']); } // Add it to the array for use in the template if (!empty($filename)) $context['javascript_files'][$id] = array('filename' => $filename, 'options' => $params); } /** * Add a Javascript variable for output later (for feeding text strings and similar to JS) * Cleaner and easier (for modders) than to use the function below. * * @param string $key The key for this variable * @param string $value The value * @param bool $escape Whether or not to escape the value */ function addJavascriptVar($key, $value, $escape = false) { global $context; if (!empty($key) && !empty($value)) $context['javascript_vars'][$key] = !empty($escape) ? JavaScriptEscape($value) : $value; } /** * Add a block of inline Javascript code to be executed later * * - only use this if you have to, generally external JS files are better, but for very small scripts * or for scripts that require help from PHP/whatever, this can be useful. * - all code added with this function is added to the same