Profile-Actions.php 26 KB

  1. <?php
  2. /**
  3. * This file handles actions made on a user's profile.
  4. *
  5. * Simple Machines Forum (SMF)
  6. *
  7. * @package SMF
  8. * @author Simple Machines http://www.simplemachines.org
  9. * @copyright 2011 Simple Machines
  10. * @license http://www.simplemachines.org/about/smf/license.php BSD
  11. *
  12. * @version 2.1 Alpha 1
  13. */
  14. if (!defined('SMF'))
  15. die('Hacking attempt...');
  16. /**
  17. * Activate an account.
  18. *
  19. * @param int $memID the member ID
  20. */
  21. function activateAccount($memID)
  22. {
  23. global $sourcedir, $context, $user_profile, $modSettings, $user_info;
  24. isAllowedTo('moderate_forum');
  25. if (isset($_REQUEST['save']) && isset($user_profile[$memID]['is_activated']) && $user_profile[$memID]['is_activated'] != 1)
  26. {
  27. // If we are approving the deletion of an account, we do something special ;)
  28. if ($user_profile[$memID]['is_activated'] == 4)
  29. {
  30. require_once($sourcedir . '/Subs-Members.php');
  31. deleteMembers($context['id_member']);
  32. redirectexit();
  33. }
  34. // Let the integrations know of the activation.
  35. call_integration_hook('integrate_activate', array($user_profile[$memID]['member_name']));
  36. // Actually update this member now, as it guarantees the unapproved count can't get corrupted.
  37. updateMemberData($context['id_member'], array('is_activated' => $user_profile[$memID]['is_activated'] >= 10 ? 11 : 1, 'validation_code' => ''));
  38. // Log what we did?
  39. require_once($sourcedir . '/Logging.php');
  40. logAction('approve_member', array('member' => $memID), 'admin');
  41. // If we are doing approval, update the stats for the member just in case.
  42. if (in_array($user_profile[$memID]['is_activated'], array(3, 4, 13, 14)))
  43. updateSettings(array('unapprovedMembers' => ($modSettings['unapprovedMembers'] > 1 ? $modSettings['unapprovedMembers'] - 1 : 0)));
  44. // Make sure we update the stats too.
  45. updateStats('member', false);
  46. }
  47. // Leave it be...
  48. redirectexit('action=profile;u=' . $memID . ';area=summary');
  49. }
  50. /**
  51. * Issue/manage an user's warning status.
  52. *
  53. * @param int $memID
  54. */
  55. function issueWarning($memID)
  56. {
  57. global $txt, $scripturl, $modSettings, $user_info, $mbname;
  58. global $context, $cur_profile, $memberContext, $smcFunc, $sourcedir;
  59. // Get all the actual settings.
  60. list ($modSettings['warning_enable'], $modSettings['user_limit']) = explode(',', $modSettings['warning_settings']);
  61. // This stores any legitimate errors.
  62. $issueErrors = array();
  63. // Doesn't hurt to be overly cautious.
  64. if (empty($modSettings['warning_enable']) || ($context['user']['is_owner'] && !$cur_profile['warning']) || !allowedTo('issue_warning'))
  65. fatal_lang_error('no_access', false);
  66. // Make sure things which are disabled stay disabled.
  67. $modSettings['warning_watch'] = !empty($modSettings['warning_watch']) ? $modSettings['warning_watch'] : 110;
  68. $modSettings['warning_moderate'] = !empty($modSettings['warning_moderate']) && !empty($modSettings['postmod_active']) ? $modSettings['warning_moderate'] : 110;
  69. $modSettings['warning_mute'] = !empty($modSettings['warning_mute']) ? $modSettings['warning_mute'] : 110;
  70. $context['warning_limit'] = allowedTo('admin_forum') ? 0 : $modSettings['user_limit'];
  71. $context['member']['warning'] = $cur_profile['warning'];
  72. $context['member']['name'] = $cur_profile['real_name'];
  73. // What are the limits we can apply?
  74. $context['min_allowed'] = 0;
  75. $context['max_allowed'] = 100;
  76. if ($context['warning_limit'] > 0)
  77. {
  78. // Make sure we cannot go outside of our limit for the day.
  79. $request = $smcFunc['db_query']('', '
  80. SELECT SUM(counter)
  81. FROM {db_prefix}log_comments
  82. WHERE id_recipient = {int:selected_member}
  83. AND id_member = {int:current_member}
  84. AND comment_type = {string:warning}
  85. AND log_time > {int:day_time_period}',
  86. array(
  87. 'current_member' => $user_info['id'],
  88. 'selected_member' => $memID,
  89. 'day_time_period' => time() - 86400,
  90. 'warning' => 'warning',
  91. )
  92. );
  93. list ($current_applied) = $smcFunc['db_fetch_row']($request);
  94. $smcFunc['db_free_result']($request);
  95. $context['min_allowed'] = max(0, $cur_profile['warning'] - $current_applied - $context['warning_limit']);
  96. $context['max_allowed'] = min(100, $cur_profile['warning'] - $current_applied + $context['warning_limit']);
  97. }
  98. // Defaults.
  99. $context['warning_data'] = array(
  100. 'reason' => '',
  101. 'notify' => '',
  102. 'notify_subject' => '',
  103. 'notify_body' => '',
  104. );
  105. // Are we saving?
  106. if (isset($_POST['save']))
  107. {
  108. // Security is good here.
  109. checkSession('post');
  110. // This cannot be empty!
  111. $_POST['warn_reason'] = isset($_POST['warn_reason']) ? trim($_POST['warn_reason']) : '';
  112. if ($_POST['warn_reason'] == '' && !$context['user']['is_owner'])
  113. $issueErrors[] = 'warning_no_reason';
  114. $_POST['warn_reason'] = $smcFunc['htmlspecialchars']($_POST['warn_reason']);
  115. // If the value hasn't changed it's either no JS or a real no change (Which this will pass)
  116. if ($_POST['warning_level'] == 'SAME')
  117. $_POST['warning_level'] = $_POST['warning_level_nojs'];
  118. $_POST['warning_level'] = (int) $_POST['warning_level'];
  119. $_POST['warning_level'] = max(0, min(100, $_POST['warning_level']));
  120. if ($_POST['warning_level'] < $context['min_allowed'])
  121. $_POST['warning_level'] = $context['min_allowed'];
  122. elseif ($_POST['warning_level'] > $context['max_allowed'])
  123. $_POST['warning_level'] = $context['max_allowed'];
  124. // Do we actually have to issue them with a PM?
  125. $id_notice = 0;
  126. if (!empty($_POST['warn_notify']) && empty($issueErrors))
  127. {
  128. $_POST['warn_sub'] = trim($_POST['warn_sub']);
  129. $_POST['warn_body'] = trim($_POST['warn_body']);
  130. if (empty($_POST['warn_sub']) || empty($_POST['warn_body']))
  131. $issueErrors[] = 'warning_notify_blank';
  132. // Send the PM?
  133. else
  134. {
  135. require_once($sourcedir . '/Subs-Post.php');
  136. $from = array(
  137. 'id' => 0,
  138. 'name' => $context['forum_name'],
  139. 'username' => $context['forum_name'],
  140. );
  141. sendpm(array('to' => array($memID), 'bcc' => array()), $_POST['warn_sub'], $_POST['warn_body'], false, $from);
  142. // Log the notice!
  143. $smcFunc['db_insert']('',
  144. '{db_prefix}log_member_notices',
  145. array(
  146. 'subject' => 'string-255', 'body' => 'string-65534',
  147. ),
  148. array(
  149. $smcFunc['htmlspecialchars']($_POST['warn_sub']), $smcFunc['htmlspecialchars']($_POST['warn_body']),
  150. ),
  151. array('id_notice')
  152. );
  153. $id_notice = $smcFunc['db_insert_id']('{db_prefix}log_member_notices', 'id_notice');
  154. }
  155. }
  156. // Just in case - make sure notice is valid!
  157. $id_notice = (int) $id_notice;
  158. // What have we changed?
  159. $level_change = $_POST['warning_level'] - $cur_profile['warning'];
  160. // No errors? Proceed! Only log if you're not the owner.
  161. if (empty($issueErrors))
  162. {
  163. // Log what we've done!
  164. if (!$context['user']['is_owner'])
  165. $smcFunc['db_insert']('',
  166. '{db_prefix}log_comments',
  167. array(
  168. 'id_member' => 'int', 'member_name' => 'string', 'comment_type' => 'string', 'id_recipient' => 'int', 'recipient_name' => 'string-255',
  169. 'log_time' => 'int', 'id_notice' => 'int', 'counter' => 'int', 'body' => 'string-65534',
  170. ),
  171. array(
  172. $user_info['id'], $user_info['name'], 'warning', $memID, $cur_profile['real_name'],
  173. time(), $id_notice, $level_change, $_POST['warn_reason'],
  174. ),
  175. array('id_comment')
  176. );
  177. // Make the change.
  178. updateMemberData($memID, array('warning' => $_POST['warning_level']));
  179. // Leave a lovely message.
  180. $context['profile_updated'] = $context['user']['is_owner'] ? $txt['profile_updated_own'] : $txt['profile_warning_success'];
  181. }
  182. else
  183. {
  184. // Get the base stuff done.
  185. loadLanguage('Errors');
  186. $context['custom_error_title'] = $txt['profile_warning_errors_occured'];
  187. // Fill in the suite of errors.
  188. $context['post_errors'] = array();
  189. foreach ($issueErrors as $error)
  190. $context['post_errors'][] = $txt[$error];
  191. // Try to remember some bits.
  192. $context['warning_data'] = array(
  193. 'reason' => $_POST['warn_reason'],
  194. 'notify' => !empty($_POST['warn_notify']),
  195. 'notify_subject' => isset($_POST['warn_sub']) ? $_POST['warn_sub'] : '',
  196. 'notify_body' => isset($_POST['warn_body']) ? $_POST['warn_body'] : '',
  197. );
  198. }
  199. // Show the new improved warning level.
  200. $context['member']['warning'] = $_POST['warning_level'];
  201. }
  202. $context['page_title'] = $txt['profile_issue_warning'];
  203. // Work our the various levels.
  204. $context['level_effects'] = array(
  205. 0 => $txt['profile_warning_effect_none'],
  206. $modSettings['warning_watch'] => $txt['profile_warning_effect_watch'],
  207. $modSettings['warning_moderate'] => $txt['profile_warning_effect_moderation'],
  208. $modSettings['warning_mute'] => $txt['profile_warning_effect_mute'],
  209. );
  210. $context['current_level'] = 0;
  211. foreach ($context['level_effects'] as $limit => $dummy)
  212. if ($context['member']['warning'] >= $limit)
  213. $context['current_level'] = $limit;
  214. // Load up all the old warnings - count first!
  215. $context['total_warnings'] = list_getUserWarningCount($memID);
  216. // Make the page index.
  217. $context['start'] = (int) $_REQUEST['start'];
  218. $perPage = (int) $modSettings['defaultMaxMessages'];
  219. $context['page_index'] = constructPageIndex($scripturl . '?action=profile;u=' . $memID . ';area=issuewarning', $context['start'], $context['total_warnings'], $perPage);
  220. // Now do the data itself.
  221. $context['previous_warnings'] = list_getUserWarnings($context['start'], $perPage, 'log_time DESC', $memID);
  222. // Are they warning because of a message?
  223. if (isset($_REQUEST['msg']) && 0 < (int) $_REQUEST['msg'])
  224. {
  225. $request = $smcFunc['db_query']('', '
  226. SELECT subject
  227. FROM {db_prefix}messages AS m
  228. INNER JOIN {db_prefix}boards AS b ON (b.id_board = m.id_board)
  229. WHERE id_msg = {int:message}
  230. AND {query_see_board}
  231. LIMIT 1',
  232. array(
  233. 'message' => (int) $_REQUEST['msg'],
  234. )
  235. );
  236. if ($smcFunc['db_num_rows']($request) != 0)
  237. {
  238. $context['warning_for_message'] = (int) $_REQUEST['msg'];
  239. list ($context['warned_message_subject']) = $smcFunc['db_fetch_row']($request);
  240. }
  241. $smcFunc['db_free_result']($request);
  242. }
  243. // Didn't find the message?
  244. if (empty($context['warning_for_message']))
  245. {
  246. $context['warning_for_message'] = 0;
  247. $context['warned_message_subject'] = '';
  248. }
  249. // Any custom templates?
  250. $context['notification_templates'] = array();
  251. $request = $smcFunc['db_query']('', '
  252. SELECT recipient_name AS template_title, body
  253. FROM {db_prefix}log_comments
  254. WHERE comment_type = {string:warntpl}
  255. AND (id_recipient = {int:generic} OR id_recipient = {int:current_member})',
  256. array(
  257. 'warntpl' => 'warntpl',
  258. 'generic' => 0,
  259. 'current_member' => $user_info['id'],
  260. )
  261. );
  262. while ($row = $smcFunc['db_fetch_assoc']($request))
  263. {
  264. // If we're not warning for a message skip any that are.
  265. if (!$context['warning_for_message'] && strpos($row['body'], '{MESSAGE}') !== false)
  266. continue;
  267. $context['notification_templates'][] = array(
  268. 'title' => $row['template_title'],
  269. 'body' => $row['body'],
  270. );
  271. }
  272. $smcFunc['db_free_result']($request);
  273. // Setup the "default" templates.
  274. foreach (array('spamming', 'offence', 'insulting') as $type)
  275. $context['notification_templates'][] = array(
  276. 'title' => $txt['profile_warning_notify_title_' . $type],
  277. 'body' => sprintf($txt['profile_warning_notify_template_outline' . (!empty($context['warning_for_message']) ? '_post' : '')], $txt['profile_warning_notify_for_' . $type]),
  278. );
  279. // Replace all the common variables in the templates.
  280. foreach ($context['notification_templates'] as $k => $name)
  281. $context['notification_templates'][$k]['body'] = strtr($name['body'], array('{MEMBER}' => un_htmlspecialchars($context['member']['name']), '{MESSAGE}' => '[url=' . $scripturl . '?msg=' . $context['warning_for_message'] . ']' . un_htmlspecialchars($context['warned_message_subject']) . '[/url]', '{SCRIPTURL}' => $scripturl, '{FORUMNAME}' => $mbname, '{REGARDS}' => $txt['regards_team']));
  282. }
  283. /**
  284. * Get the number of warnings a user has.
  285. *
  286. * @param int $memID
  287. * @return int Total number of warnings for the user
  288. */
  289. function list_getUserWarningCount($memID)
  290. {
  291. global $smcFunc;
  292. $request = $smcFunc['db_query']('', '
  293. SELECT COUNT(*)
  294. FROM {db_prefix}log_comments
  295. WHERE id_recipient = {int:selected_member}
  296. AND comment_type = {string:warning}',
  297. array(
  298. 'selected_member' => $memID,
  299. 'warning' => 'warning',
  300. )
  301. );
  302. list ($total_warnings) = $smcFunc['db_fetch_row']($request);
  303. $smcFunc['db_free_result']($request);
  304. return $total_warnings;
  305. }
  306. /**
  307. * Get the data about a users warnings.
  308. *
  309. * @param int $start
  310. * @param int $items_per_page
  311. * @param string $sort
  312. * @param int $memID, the member ID
  313. * @return array the preview warnings
  314. */
  315. function list_getUserWarnings($start, $items_per_page, $sort, $memID)
  316. {
  317. global $smcFunc, $scripturl;
  318. $request = $smcFunc['db_query']('', '
  319. SELECT IFNULL(mem.id_member, 0) AS id_member, IFNULL(mem.real_name, lc.member_name) AS member_name,
  320. lc.log_time, lc.body, lc.counter, lc.id_notice
  321. FROM {db_prefix}log_comments AS lc
  322. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = lc.id_member)
  323. WHERE lc.id_recipient = {int:selected_member}
  324. AND lc.comment_type = {string:warning}
  325. ORDER BY ' . $sort . '
  326. LIMIT ' . $start . ', ' . $items_per_page,
  327. array(
  328. 'selected_member' => $memID,
  329. 'warning' => 'warning',
  330. )
  331. );
  332. $previous_warnings = array();
  333. while ($row = $smcFunc['db_fetch_assoc']($request))
  334. {
  335. $previous_warnings[] = array(
  336. 'issuer' => array(
  337. 'id' => $row['id_member'],
  338. 'link' => $row['id_member'] ? ('<a href="' . $scripturl . '?action=profile;u=' . $row['id_member'] . '">' . $row['member_name'] . '</a>') : $row['member_name'],
  339. ),
  340. 'time' => timeformat($row['log_time']),
  341. 'reason' => $row['body'],
  342. 'counter' => $row['counter'] > 0 ? '+' . $row['counter'] : $row['counter'],
  343. 'id_notice' => $row['id_notice'],
  344. );
  345. }
  346. $smcFunc['db_free_result']($request);
  347. return $previous_warnings;
  348. }
  349. /**
  350. * Present a screen to make sure the user wants to be deleted
  351. *
  352. * @param int $memID, the member ID
  353. */
  354. function deleteAccount($memID)
  355. {
  356. global $txt, $context, $user_info, $modSettings, $cur_profile, $smcFunc;
  357. if (!$context['user']['is_owner'])
  358. isAllowedTo('profile_remove_any');
  359. elseif (!allowedTo('profile_remove_any'))
  360. isAllowedTo('profile_remove_own');
  361. // Permissions for removing stuff...
  362. $context['can_delete_posts'] = !$context['user']['is_owner'] && allowedTo('moderate_forum');
  363. // Can they do this, or will they need approval?
  364. $context['needs_approval'] = $context['user']['is_owner'] && !empty($modSettings['approveAccountDeletion']) && !allowedTo('moderate_forum');
  365. $context['page_title'] = $txt['deleteAccount'] . ': ' . $cur_profile['real_name'];
  366. }
  367. /**
  368. * Actually delete an account.
  369. *
  370. * @param $profile_vars
  371. * @param $post_errors
  372. * @param int $memID, the member ID
  373. */
  374. function deleteAccount2($profile_vars, $post_errors, $memID)
  375. {
  376. global $user_info, $sourcedir, $context, $cur_profile, $modSettings, $smcFunc;
  377. // Try get more time...
  378. @set_time_limit(600);
  379. // @todo Add a way to delete pms as well?
  380. if (!$context['user']['is_owner'])
  381. isAllowedTo('profile_remove_any');
  382. elseif (!allowedTo('profile_remove_any'))
  383. isAllowedTo('profile_remove_own');
  384. checkSession();
  385. $old_profile = &$cur_profile;
  386. // Too often, people remove/delete their own only account.
  387. if (in_array(1, explode(',', $old_profile['additional_groups'])) || $old_profile['id_group'] == 1)
  388. {
  389. // Are you allowed to administrate the forum, as they are?
  390. isAllowedTo('admin_forum');
  391. $request = $smcFunc['db_query']('', '
  392. SELECT id_member
  393. FROM {db_prefix}members
  394. WHERE (id_group = {int:admin_group} OR FIND_IN_SET({int:admin_group}, additional_groups) != 0)
  395. AND id_member != {int:selected_member}
  396. LIMIT 1',
  397. array(
  398. 'admin_group' => 1,
  399. 'selected_member' => $memID,
  400. )
  401. );
  402. list ($another) = $smcFunc['db_fetch_row']($request);
  403. $smcFunc['db_free_result']($request);
  404. if (empty($another))
  405. fatal_lang_error('at_least_one_admin', 'critical');
  406. }
  407. // This file is needed for the deleteMembers function.
  408. require_once($sourcedir . '/Subs-Members.php');
  409. // Do you have permission to delete others profiles, or is that your profile you wanna delete?
  410. if ($memID != $user_info['id'])
  411. {
  412. isAllowedTo('profile_remove_any');
  413. // Now, have you been naughty and need your posts deleting?
  414. // @todo Should this check board permissions?
  415. if ($_POST['remove_type'] != 'none' && allowedTo('moderate_forum'))
  416. {
  417. // Include RemoveTopics - essential for this type of work!
  418. require_once($sourcedir . '/RemoveTopic.php');
  419. // First off we delete any topics the member has started - if they wanted topics being done.
  420. if ($_POST['remove_type'] == 'topics')
  421. {
  422. // Fetch all topics started by this user within the time period.
  423. $request = $smcFunc['db_query']('', '
  424. SELECT t.id_topic
  425. FROM {db_prefix}topics AS t
  426. WHERE t.id_member_started = {int:selected_member}',
  427. array(
  428. 'selected_member' => $memID,
  429. )
  430. );
  431. $topicIDs = array();
  432. while ($row = $smcFunc['db_fetch_assoc']($request))
  433. $topicIDs[] = $row['id_topic'];
  434. $smcFunc['db_free_result']($request);
  435. // Actually remove the topics.
  436. // @todo This needs to check permissions, but we'll let it slide for now because of moderate_forum already being had.
  437. removeTopics($topicIDs);
  438. }
  439. // Now delete the remaining messages.
  440. $request = $smcFunc['db_query']('', '
  441. SELECT m.id_msg
  442. FROM {db_prefix}messages AS m
  443. INNER JOIN {db_prefix}topics AS t ON (t.id_topic = m.id_topic
  444. AND t.id_first_msg != m.id_msg)
  445. WHERE m.id_member = {int:selected_member}',
  446. array(
  447. 'selected_member' => $memID,
  448. )
  449. );
  450. // This could take a while... but ya know it's gonna be worth it in the end.
  451. while ($row = $smcFunc['db_fetch_assoc']($request))
  452. {
  453. if (function_exists('apache_reset_timeout'))
  454. @apache_reset_timeout();
  455. removeMessage($row['id_msg']);
  456. }
  457. $smcFunc['db_free_result']($request);
  458. }
  459. // Only delete this poor members account if they are actually being booted out of camp.
  460. if (isset($_POST['deleteAccount']))
  461. deleteMembers($memID);
  462. }
  463. // Do they need approval to delete?
  464. elseif (empty($post_errors) && !empty($modSettings['approveAccountDeletion']) && !allowedTo('moderate_forum'))
  465. {
  466. // Setup their account for deletion ;)
  467. updateMemberData($memID, array('is_activated' => 4));
  468. // Another account needs approval...
  469. updateSettings(array('unapprovedMembers' => true), true);
  470. }
  471. // Also check if you typed your password correctly.
  472. elseif (empty($post_errors))
  473. {
  474. deleteMembers($memID);
  475. require_once($sourcedir . '/LogInOut.php');
  476. LogOut(true);
  477. redirectexit();
  478. }
  479. }
  480. /**
  481. * Function for doing all the paid subscription stuff - kinda.
  482. *
  483. * @param int $memID
  484. */
  485. function subscriptions($memID)
  486. {
  487. global $context, $txt, $sourcedir, $modSettings, $smcFunc, $scripturl;
  488. // Load the paid template anyway.
  489. loadTemplate('ManagePaid');
  490. loadLanguage('ManagePaid');
  491. // Load all of the subscriptions.
  492. require_once($sourcedir . '/ManagePaid.php');
  493. loadSubscriptions();
  494. $context['member']['id'] = $memID;
  495. // Remove any invalid ones.
  496. foreach ($context['subscriptions'] as $id => $sub)
  497. {
  498. // Work out the costs.
  499. $costs = @unserialize($sub['real_cost']);
  500. $cost_array = array();
  501. if ($sub['real_length'] == 'F')
  502. {
  503. foreach ($costs as $duration => $cost)
  504. {
  505. if ($cost != 0)
  506. $cost_array[$duration] = $cost;
  507. }
  508. }
  509. else
  510. {
  511. $cost_array['fixed'] = $costs['fixed'];
  512. }
  513. if (empty($cost_array))
  514. unset($context['subscriptions'][$id]);
  515. else
  516. {
  517. $context['subscriptions'][$id]['member'] = 0;
  518. $context['subscriptions'][$id]['subscribed'] = false;
  519. $context['subscriptions'][$id]['costs'] = $cost_array;
  520. }
  521. }
  522. // Work out what gateways are enabled.
  523. $gateways = loadPaymentGateways();
  524. foreach ($gateways as $id => $gateway)
  525. {
  526. $gateways[$id] = new $gateway['display_class']();
  527. if (!$gateways[$id]->gatewayEnabled())
  528. unset($gateways[$id]);
  529. }
  530. // No gateways yet?
  531. if (empty($gateways))
  532. fatal_error($txt['paid_admin_not_setup_gateway']);
  533. // Get the current subscriptions.
  534. $request = $smcFunc['db_query']('', '
  535. SELECT id_sublog, id_subscribe, start_time, end_time, status, payments_pending, pending_details
  536. FROM {db_prefix}log_subscribed
  537. WHERE id_member = {int:selected_member}',
  538. array(
  539. 'selected_member' => $memID,
  540. )
  541. );
  542. $context['current'] = array();
  543. while ($row = $smcFunc['db_fetch_assoc']($request))
  544. {
  545. // The subscription must exist!
  546. if (!isset($context['subscriptions'][$row['id_subscribe']]))
  547. continue;
  548. $context['current'][$row['id_subscribe']] = array(
  549. 'id' => $row['id_sublog'],
  550. 'sub_id' => $row['id_subscribe'],
  551. 'hide' => $row['status'] == 0 && $row['end_time'] == 0 && $row['payments_pending'] == 0,
  552. 'name' => $context['subscriptions'][$row['id_subscribe']]['name'],
  553. 'start' => timeformat($row['start_time'], false),
  554. 'end' => $row['end_time'] == 0 ? $txt['not_applicable'] : timeformat($row['end_time'], false),
  555. 'pending_details' => $row['pending_details'],
  556. 'status' => $row['status'],
  557. 'status_text' => $row['status'] == 0 ? ($row['payments_pending'] ? $txt['paid_pending'] : $txt['paid_finished']) : $txt['paid_active'],
  558. );
  559. if ($row['status'] == 1)
  560. $context['subscriptions'][$row['id_subscribe']]['subscribed'] = true;
  561. }
  562. $smcFunc['db_free_result']($request);
  563. // Simple "done"?
  564. if (isset($_GET['done']))
  565. {
  566. $_GET['sub_id'] = (int) $_GET['sub_id'];
  567. // Must exist but let's be sure...
  568. if (isset($context['current'][$_GET['sub_id']]))
  569. {
  570. // What are the details like?
  571. $current_pending = @unserialize($context['current'][$_GET['sub_id']]['pending_details']);
  572. if (!empty($current_pending))
  573. {
  574. $current_pending = array_reverse($current_pending);
  575. foreach ($current_pending as $id => $sub)
  576. {
  577. // Just find one and change it.
  578. if ($sub[0] == $_GET['sub_id'] && $sub[3] == 'prepay')
  579. {
  580. $current_pending[$id][3] = 'payback';
  581. break;
  582. }
  583. }
  584. // Save the details back.
  585. $pending_details = serialize($current_pending);
  586. $smcFunc['db_query']('', '
  587. UPDATE {db_prefix}log_subscribed
  588. SET payments_pending = payments_pending + 1, pending_details = {string:pending_details}
  589. WHERE id_sublog = {int:current_subscription_id}
  590. AND id_member = {int:selected_member}',
  591. array(
  592. 'current_subscription_id' => $context['current'][$_GET['sub_id']]['id'],
  593. 'selected_member' => $memID,
  594. 'pending_details' => $pending_details,
  595. )
  596. );
  597. }
  598. }
  599. $context['sub_template'] = 'paid_done';
  600. return;
  601. }
  602. // If this is confirmation then it's simpler...
  603. if (isset($_GET['confirm']) && isset($_POST['sub_id']) && is_array($_POST['sub_id']))
  604. {
  605. // Hopefully just one.
  606. foreach ($_POST['sub_id'] as $k => $v)
  607. $ID_SUB = (int) $k;
  608. if (!isset($context['subscriptions'][$ID_SUB]) || $context['subscriptions'][$ID_SUB]['active'] == 0)
  609. fatal_lang_error('paid_sub_not_active');
  610. // Simplify...
  611. $context['sub'] = $context['subscriptions'][$ID_SUB];
  612. $period = 'xx';
  613. if ($context['sub']['flexible'])
  614. $period = isset($_POST['cur'][$ID_SUB]) && isset($context['sub']['costs'][$_POST['cur'][$ID_SUB]]) ? $_POST['cur'][$ID_SUB] : 'xx';
  615. // Check we have a valid cost.
  616. if ($context['sub']['flexible'] && $period == 'xx')
  617. fatal_lang_error('paid_sub_not_active');
  618. // Sort out the cost/currency.
  619. $context['currency'] = $modSettings['paid_currency_code'];
  620. $context['recur'] = $context['sub']['repeatable'];
  621. if ($context['sub']['flexible'])
  622. {
  623. // Real cost...
  624. $context['value'] = $context['sub']['costs'][$_POST['cur'][$ID_SUB]];
  625. $context['cost'] = sprintf($modSettings['paid_currency_symbol'], $context['value']) . '/' . $txt[$_POST['cur'][$ID_SUB]];
  626. // The period value for paypal.
  627. $context['paypal_period'] = strtoupper(substr($_POST['cur'][$ID_SUB], 0, 1));
  628. }
  629. else
  630. {
  631. // Real cost...
  632. $context['value'] = $context['sub']['costs']['fixed'];
  633. $context['cost'] = sprintf($modSettings['paid_currency_symbol'], $context['value']);
  634. // Recur?
  635. preg_match('~(\d*)(\w)~', $context['sub']['real_length'], $match);
  636. $context['paypal_unit'] = $match[1];
  637. $context['paypal_period'] = $match[2];
  638. }
  639. // Setup the gateway context.
  640. $context['gateways'] = array();
  641. foreach ($gateways as $id => $gateway)
  642. {
  643. $fields = $gateways[$id]->fetchGatewayFields($context['sub']['id'] . '+' . $memID, $context['sub'], $context['value'], $period, $scripturl . '?action=profile;u=' . $memID . ';area=subscriptions;sub_id=' . $context['sub']['id'] . ';done');
  644. if (!empty($fields['form']))
  645. $context['gateways'][] = $fields;
  646. }
  647. // Bugger?!
  648. if (empty($context['gateways']))
  649. fatal_error($txt['paid_admin_not_setup_gateway']);
  650. // Now we are going to assume they want to take this out ;)
  651. $new_data = array($context['sub']['id'], $context['value'], $period, 'prepay');
  652. if (isset($context['current'][$context['sub']['id']]))
  653. {
  654. // What are the details like?
  655. $current_pending = array();
  656. if ($context['current'][$context['sub']['id']]['pending_details'] != '')
  657. $current_pending = @unserialize($context['current'][$context['sub']['id']]['pending_details']);
  658. // Don't get silly.
  659. if (count($current_pending) > 9)
  660. $current_pending = array();
  661. $pending_count = 0;
  662. // Only record real pending payments as will otherwise confuse the admin!
  663. foreach ($current_pending as $pending)
  664. if ($pending[3] == 'payback')
  665. $pending_count++;
  666. if (!in_array($new_data, $current_pending))
  667. {
  668. $current_pending[] = $new_data;
  669. $pending_details = serialize($current_pending);
  670. $smcFunc['db_query']('', '
  671. UPDATE {db_prefix}log_subscribed
  672. SET payments_pending = {int:pending_count}, pending_details = {string:pending_details}
  673. WHERE id_sublog = {int:current_subscription_item}
  674. AND id_member = {int:selected_member}',
  675. array(
  676. 'pending_count' => $pending_count,
  677. 'current_subscription_item' => $context['current'][$context['sub']['id']]['id'],
  678. 'selected_member' => $memID,
  679. 'pending_details' => $pending_details,
  680. )
  681. );
  682. }
  683. }
  684. // Never had this before, lovely.
  685. else
  686. {
  687. $pending_details = serialize(array($new_data));
  688. $smcFunc['db_insert']('',
  689. '{db_prefix}log_subscribed',
  690. array(
  691. 'id_subscribe' => 'int', 'id_member' => 'int', 'status' => 'int', 'payments_pending' => 'int', 'pending_details' => 'string-65534',
  692. 'start_time' => 'int', 'vendor_ref' => 'string-255',
  693. ),
  694. array(
  695. $context['sub']['id'], $memID, 0, 0, $pending_details,
  696. time(), '',
  697. ),
  698. array('id_sublog')
  699. );
  700. }
  701. // Change the template.
  702. $context['sub_template'] = 'choose_payment';
  703. // Quit.
  704. return;
  705. }
  706. else
  707. $context['sub_template'] = 'user_subscription';
  708. }
  709. ?>