PersonalMessage.php 136 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019
  1. <?php
  2. /**
  3. * This file is mainly meant for controlling the actions related to personal
  4. * messages. It allows viewing, sending, deleting, and marking personal
  5. * messages. For compatibility reasons, they are often called "instant messages".
  6. *
  7. * Simple Machines Forum (SMF)
  8. *
  9. * @package SMF
  10. * @author Simple Machines http://www.simplemachines.org
  11. * @copyright 2013 Simple Machines and individual contributors
  12. * @license http://www.simplemachines.org/about/smf/license.php BSD
  13. *
  14. * @version 2.1 Alpha 1
  15. */
  16. if (!defined('SMF'))
  17. die('No direct access...');
  18. /**
  19. * This helps organize things...
  20. * @todo this should be a simple dispatcher....
  21. */
  22. function MessageMain()
  23. {
  24. global $txt, $scripturl, $sourcedir, $context, $user_info, $user_settings, $smcFunc, $modSettings;
  25. // No guests!
  26. is_not_guest();
  27. // You're not supposed to be here at all, if you can't even read PMs.
  28. isAllowedTo('pm_read');
  29. // This file contains the basic functions for sending a PM.
  30. require_once($sourcedir . '/Subs-Post.php');
  31. loadLanguage('PersonalMessage+Drafts');
  32. if (WIRELESS && WIRELESS_PROTOCOL == 'wap')
  33. fatal_lang_error('wireless_error_notyet', false);
  34. elseif (WIRELESS)
  35. $context['sub_template'] = WIRELESS_PROTOCOL . '_pm';
  36. elseif (!isset($_REQUEST['xml']))
  37. loadTemplate('PersonalMessage');
  38. // Load up the members maximum message capacity.
  39. if ($user_info['is_admin'])
  40. $context['message_limit'] = 0;
  41. elseif (($context['message_limit'] = cache_get_data('msgLimit:' . $user_info['id'], 360)) === null)
  42. {
  43. // @todo Why do we do this? It seems like if they have any limit we should use it.
  44. $request = $smcFunc['db_query']('', '
  45. SELECT MAX(max_messages) AS top_limit, MIN(max_messages) AS bottom_limit
  46. FROM {db_prefix}membergroups
  47. WHERE id_group IN ({array_int:users_groups})',
  48. array(
  49. 'users_groups' => $user_info['groups'],
  50. )
  51. );
  52. list ($maxMessage, $minMessage) = $smcFunc['db_fetch_row']($request);
  53. $smcFunc['db_free_result']($request);
  54. $context['message_limit'] = $minMessage == 0 ? 0 : $maxMessage;
  55. // Save us doing it again!
  56. cache_put_data('msgLimit:' . $user_info['id'], $context['message_limit'], 360);
  57. }
  58. // Prepare the context for the capacity bar.
  59. if (!empty($context['message_limit']))
  60. {
  61. $bar = ($user_info['messages'] * 100) / $context['message_limit'];
  62. $context['limit_bar'] = array(
  63. 'messages' => $user_info['messages'],
  64. 'allowed' => $context['message_limit'],
  65. 'percent' => $bar,
  66. 'bar' => min(100, (int) $bar),
  67. 'text' => sprintf($txt['pm_currently_using'], $user_info['messages'], round($bar, 1)),
  68. );
  69. }
  70. // a previous message was sent successfully? show a small indication.
  71. if (isset($_GET['done']) && ($_GET['done'] == 'sent'))
  72. $context['pm_sent'] = true;
  73. $context['labels'] = array();
  74. // Load the label data.
  75. if ($user_settings['new_pm'] || ($context['labels'] = cache_get_data('labelCounts:' . $user_info['id'], 720)) === null)
  76. {
  77. // Looks like we need to reseek!
  78. // Inbox "label"
  79. $context['labels'][-1] = array(
  80. 'id' => -1,
  81. 'name' => $txt['pm_msg_label_inbox'],
  82. 'messages' => 0,
  83. 'unread_messages' => 0,
  84. );
  85. // First get the inbox counts
  86. $result = $smcFunc['db_query']('', '
  87. SELECT COUNT(*) AS total, SUM(is_read) AS num_read
  88. FROM {db_prefix}pm_recipients
  89. WHERE id_member = {int:current_member}
  90. AND in_inbox = {int:in_inbox}',
  91. array(
  92. 'current_member' => $user_info['id'],
  93. 'in_inbox' => 1,
  94. )
  95. );
  96. while ($row = $smcFunc['db_fetch_assoc']($result))
  97. {
  98. $context['labels'][-1]['messages'] = $row['total'];
  99. $context['labels'][-1]['unread_messages'] = $row['total'] - $row['num_read'];
  100. }
  101. $smcFunc['db_free_result']($result);
  102. // Now load info about all the other labels
  103. $result = $smcFunc['db_query']('', '
  104. SELECT l.id_label, l.name, IFNULL(SUM(pr.is_read), 0) AS num_read, IFNULL(COUNT(pr.id_pm), 0) AS total
  105. FROM {db_prefix}pm_labels AS l
  106. LEFT JOIN {db_prefix}pm_labeled_messages AS pl ON (pl.id_label = l.id_label)
  107. LEFT JOIN {db_prefix}pm_recipients AS pr ON (pr.id_pm = pl.id_pm)
  108. WHERE l.id_member = {int:current_member}
  109. GROUP BY l.id_label',
  110. array(
  111. 'current_member' => $user_info['id'],
  112. )
  113. );
  114. while ($row = $smcFunc['db_fetch_assoc']($result))
  115. {
  116. $context['labels'][$row['id_label']] = array(
  117. 'id' => $row['id_label'],
  118. 'name' => $row['name'],
  119. 'messages' => $row['total'],
  120. 'unread_messages' => $row['total'] - $row['num_read']
  121. );
  122. }
  123. $smcFunc['db_free_result']($result);
  124. // Store it please!
  125. cache_put_data('labelCounts:' . $user_info['id'], $context['labels'], 720);
  126. }
  127. // Now we have the labels, and assuming we have unsorted mail, apply our rules!
  128. if ($user_settings['new_pm'])
  129. {
  130. ApplyRules();
  131. updateMemberData($user_info['id'], array('new_pm' => 0));
  132. $smcFunc['db_query']('', '
  133. UPDATE {db_prefix}pm_recipients
  134. SET is_new = {int:not_new}
  135. WHERE id_member = {int:current_member}',
  136. array(
  137. 'current_member' => $user_info['id'],
  138. 'not_new' => 0,
  139. )
  140. );
  141. }
  142. // This determines if we have more labels than just the standard inbox.
  143. $context['currently_using_labels'] = count($context['labels']) > 1 ? 1 : 0;
  144. // Some stuff for the labels...
  145. $context['current_label_id'] = isset($_REQUEST['l']) && isset($context['labels'][(int) $_REQUEST['l']]) ? (int) $_REQUEST['l'] : -1;
  146. $context['current_label'] = &$context['labels'][(int) $context['current_label_id']]['name'];
  147. $context['folder'] = !isset($_REQUEST['f']) || $_REQUEST['f'] != 'sent' ? 'inbox' : 'sent';
  148. // This is convenient. Do you know how annoying it is to do this every time?!
  149. $context['current_label_redirect'] = 'action=pm;f=' . $context['folder'] . (isset($_GET['start']) ? ';start=' . $_GET['start'] : '') . (isset($_REQUEST['l']) ? ';l=' . $_REQUEST['l'] : '');
  150. $context['can_issue_warning'] = allowedTo('issue_warning') && $modSettings['warning_settings'][0] == 1;
  151. // Are PM drafts enabled?
  152. $context['drafts_pm_save'] = !empty($modSettings['drafts_pm_enabled']) && allowedTo('pm_draft');
  153. $context['drafts_autosave'] = !empty($context['drafts_pm_save']) && !empty($modSettings['drafts_autosave_enabled']) && allowedTo('pm_autosave_draft');
  154. // Build the linktree for all the actions...
  155. $context['linktree'][] = array(
  156. 'url' => $scripturl . '?action=pm',
  157. 'name' => $txt['personal_messages']
  158. );
  159. // Preferences...
  160. $context['display_mode'] = WIRELESS ? 0 : $user_settings['pm_prefs'] & 3;
  161. $subActions = array(
  162. 'addbuddy' => 'WirelessAddBuddy',
  163. 'manlabels' => 'ManageLabels',
  164. 'manrules' => 'ManageRules',
  165. 'pmactions' => 'MessageActionsApply',
  166. 'prune' => 'MessagePrune',
  167. 'removeall' => 'MessageKillAllQuery',
  168. 'removeall2' => 'MessageKillAll',
  169. 'report' => 'ReportMessage',
  170. 'search' => 'MessageSearch',
  171. 'search2' => 'MessageSearch2',
  172. 'send' => 'MessagePost',
  173. 'send2' => 'MessagePost2',
  174. 'settings' => 'MessageSettings',
  175. 'showpmdrafts' => 'MessageDrafts',
  176. );
  177. if (!isset($_REQUEST['sa']) || !isset($subActions[$_REQUEST['sa']]))
  178. {
  179. $_REQUEST['sa'] = '';
  180. MessageFolder();
  181. }
  182. else
  183. {
  184. if (!isset($_REQUEST['xml']))
  185. messageIndexBar($_REQUEST['sa']);
  186. $subActions[$_REQUEST['sa']]();
  187. }
  188. }
  189. /**
  190. * A menu to easily access different areas of the PM section
  191. *
  192. * @param string $area
  193. */
  194. function messageIndexBar($area)
  195. {
  196. global $txt, $context, $scripturl, $sourcedir, $sc, $modSettings, $settings, $user_info, $options;
  197. $pm_areas = array(
  198. 'folders' => array(
  199. 'title' => $txt['pm_messages'],
  200. 'areas' => array(
  201. 'send' => array(
  202. 'label' => $txt['new_message'],
  203. 'custom_url' => $scripturl . '?action=pm;sa=send',
  204. 'permission' => allowedTo('pm_send'),
  205. ),
  206. 'inbox' => array(
  207. 'label' => $txt['inbox'],
  208. 'custom_url' => $scripturl . '?action=pm',
  209. ),
  210. 'sent' => array(
  211. 'label' => $txt['sent_items'],
  212. 'custom_url' => $scripturl . '?action=pm;f=sent',
  213. ),
  214. 'drafts' => array(
  215. 'label' => $txt['drafts_show'],
  216. 'custom_url' => $scripturl . '?action=pm;sa=showpmdrafts',
  217. 'permission' => allowedTo('pm_draft'),
  218. 'enabled' => !empty($modSettings['drafts_pm_enabled']),
  219. ),
  220. ),
  221. ),
  222. 'labels' => array(
  223. 'title' => $txt['pm_labels'],
  224. 'areas' => array(),
  225. ),
  226. 'actions' => array(
  227. 'title' => $txt['pm_actions'],
  228. 'areas' => array(
  229. 'search' => array(
  230. 'label' => $txt['pm_search_bar_title'],
  231. 'custom_url' => $scripturl . '?action=pm;sa=search',
  232. ),
  233. 'prune' => array(
  234. 'label' => $txt['pm_prune'],
  235. 'custom_url' => $scripturl . '?action=pm;sa=prune'
  236. ),
  237. ),
  238. ),
  239. 'pref' => array(
  240. 'title' => $txt['pm_preferences'],
  241. 'areas' => array(
  242. 'manlabels' => array(
  243. 'label' => $txt['pm_manage_labels'],
  244. 'custom_url' => $scripturl . '?action=pm;sa=manlabels',
  245. ),
  246. 'manrules' => array(
  247. 'label' => $txt['pm_manage_rules'],
  248. 'custom_url' => $scripturl . '?action=pm;sa=manrules',
  249. ),
  250. 'settings' => array(
  251. 'label' => $txt['pm_settings'],
  252. 'custom_url' => $scripturl . '?action=pm;sa=settings',
  253. ),
  254. ),
  255. ),
  256. );
  257. // Handle labels.
  258. if (empty($context['currently_using_labels']))
  259. unset($pm_areas['labels']);
  260. else
  261. {
  262. // Note we send labels by id as it will have less problems in the querystring.
  263. $unread_in_labels = 0;
  264. foreach ($context['labels'] as $label)
  265. {
  266. if ($label['id'] == -1)
  267. continue;
  268. // Count the amount of unread items in labels.
  269. $unread_in_labels += $label['unread_messages'];
  270. // Add the label to the menu.
  271. $pm_areas['labels']['areas']['label' . $label['id']] = array(
  272. 'label' => $label['name'] . (!empty($label['unread_messages']) ? ' (<strong>' . $label['unread_messages'] . '</strong>)' : ''),
  273. 'custom_url' => $scripturl . '?action=pm;l=' . $label['id'],
  274. 'unread_messages' => $label['unread_messages'],
  275. 'messages' => $label['messages'],
  276. );
  277. }
  278. if (!empty($unread_in_labels))
  279. $pm_areas['labels']['title'] .= ' (' . $unread_in_labels . ')';
  280. }
  281. $pm_areas['folders']['areas']['inbox']['unread_messages'] = &$context['labels'][-1]['unread_messages'];
  282. $pm_areas['folders']['areas']['inbox']['messages'] = &$context['labels'][-1]['messages'];
  283. if (!empty($context['labels'][-1]['unread_messages']))
  284. {
  285. $pm_areas['folders']['areas']['inbox']['label'] .= ' (<strong>' . $context['labels'][-1]['unread_messages'] . '</strong>)';
  286. $pm_areas['folders']['title'] .= ' (' . $context['labels'][-1]['unread_messages'] . ')';
  287. }
  288. // Do we have a limit on the amount of messages we can keep?
  289. if (!empty($context['message_limit']))
  290. {
  291. $bar = round(($user_info['messages'] * 100) / $context['message_limit'], 1);
  292. $context['limit_bar'] = array(
  293. 'messages' => $user_info['messages'],
  294. 'allowed' => $context['message_limit'],
  295. 'percent' => $bar,
  296. 'bar' => $bar > 100 ? 100 : (int) $bar,
  297. 'text' => sprintf($txt['pm_currently_using'], $user_info['messages'], $bar)
  298. );
  299. }
  300. require_once($sourcedir . '/Subs-Menu.php');
  301. // What page is this, again?
  302. $current_page = $scripturl . '?action=pm' . (!empty($_REQUEST['sa']) ? ';sa=' . $_REQUEST['sa'] : '') . (!empty($context['folder']) ? ';f=' . $context['folder'] : '') . (!empty($context['current_label_id']) ? ';l=' . $context['current_label_id'] : '');
  303. // Set a few options for the menu.
  304. $menuOptions = array(
  305. 'current_area' => $area,
  306. 'disable_url_session_check' => true,
  307. );
  308. // Actually create the menu!
  309. $pm_include_data = createMenu($pm_areas, $menuOptions);
  310. unset($pm_areas);
  311. // No menu means no access.
  312. if (!$pm_include_data && (!$user_info['is_guest'] || validateSession()))
  313. fatal_lang_error('no_access', false);
  314. // Make a note of the Unique ID for this menu.
  315. $context['pm_menu_id'] = $context['max_menu_id'];
  316. $context['pm_menu_name'] = 'menu_data_' . $context['pm_menu_id'];
  317. // Set the selected item.
  318. $current_area = $pm_include_data['current_area'];
  319. $context['menu_item_selected'] = $current_area;
  320. // Set the template for this area and add the profile layer.
  321. if (!WIRELESS && !isset($_REQUEST['xml']))
  322. $context['template_layers'][] = 'pm';
  323. }
  324. /**
  325. * A folder, ie. inbox/sent etc.
  326. */
  327. function MessageFolder()
  328. {
  329. global $txt, $scripturl, $modSettings, $context, $subjects_request;
  330. global $messages_request, $user_info, $recipients, $options, $smcFunc, $memberContext, $user_settings;
  331. // Changing view?
  332. if (isset($_GET['view']))
  333. {
  334. $context['display_mode'] = $context['display_mode'] > 1 ? 0 : $context['display_mode'] + 1;
  335. updateMemberData($user_info['id'], array('pm_prefs' => ($user_settings['pm_prefs'] & 252) | $context['display_mode']));
  336. }
  337. // Make sure the starting location is valid.
  338. if (isset($_GET['start']) && $_GET['start'] != 'new')
  339. $_GET['start'] = (int) $_GET['start'];
  340. elseif (!isset($_GET['start']) && !empty($options['view_newest_pm_first']))
  341. $_GET['start'] = 0;
  342. else
  343. $_GET['start'] = 'new';
  344. // Set up some basic theme stuff.
  345. $context['from_or_to'] = $context['folder'] != 'sent' ? 'from' : 'to';
  346. $context['get_pmessage'] = 'prepareMessageContext';
  347. $context['signature_enabled'] = substr($modSettings['signature_settings'], 0, 1) == 1;
  348. $context['disabled_fields'] = isset($modSettings['disabled_profile_fields']) ? array_flip(explode(',', $modSettings['disabled_profile_fields'])) : array();
  349. $labelJoin = '';
  350. $labelQuery = '';
  351. $labelQuery2 = '';
  352. // SMF logic: If you're viewing a label, it's still the inbox
  353. if ($context['folder'] == 'inbox' && $context['current_label_id'] == -1)
  354. {
  355. $labelQuery = '
  356. AND pmr.in_inbox = 1';
  357. }
  358. elseif ($context['folder'] != 'sent')
  359. {
  360. $labelJoin = '
  361. INNER JOIN {db_prefix}pm_labeled_messages AS pl';
  362. $labelQuery2 = '
  363. AND pl.id_label = ' . $context['current_label_id'];
  364. }
  365. // Set the index bar correct!
  366. messageIndexBar($context['current_label_id'] == -1 ? $context['folder'] : 'label' . $context['current_label_id']);
  367. // Sorting the folder.
  368. $sort_methods = array(
  369. 'date' => 'pm.id_pm',
  370. 'name' => 'IFNULL(mem.real_name, \'\')',
  371. 'subject' => 'pm.subject',
  372. );
  373. // They didn't pick one, use the forum default.
  374. if (!isset($_GET['sort']) || !isset($sort_methods[$_GET['sort']]))
  375. {
  376. $context['sort_by'] = 'date';
  377. $_GET['sort'] = 'pm.id_pm';
  378. // An overriding setting?
  379. $descending = !empty($options['view_newest_pm_first']);
  380. }
  381. // Otherwise use the defaults: ascending, by date.
  382. else
  383. {
  384. $context['sort_by'] = $_GET['sort'];
  385. $_GET['sort'] = $sort_methods[$_GET['sort']];
  386. $descending = isset($_GET['desc']);
  387. }
  388. $context['sort_direction'] = $descending ? 'down' : 'up';
  389. // Set the text to resemble the current folder.
  390. $pmbox = $context['folder'] != 'sent' ? $txt['inbox'] : $txt['sent_items'];
  391. $txt['delete_all'] = str_replace('PMBOX', $pmbox, $txt['delete_all']);
  392. // Now, build the link tree!
  393. if ($context['current_label_id'] == -1)
  394. $context['linktree'][] = array(
  395. 'url' => $scripturl . '?action=pm;f=' . $context['folder'],
  396. 'name' => $pmbox
  397. );
  398. // Build it further for a label.
  399. if ($context['current_label_id'] != -1)
  400. $context['linktree'][] = array(
  401. 'url' => $scripturl . '?action=pm;f=' . $context['folder'] . ';l=' . $context['current_label_id'],
  402. 'name' => $txt['pm_current_label'] . ': ' . $context['current_label']
  403. );
  404. // Figure out how many messages there are.
  405. if ($context['folder'] == 'sent')
  406. $request = $smcFunc['db_query']('', '
  407. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  408. FROM {db_prefix}personal_messages AS pm
  409. WHERE pm.id_member_from = {int:current_member}
  410. AND pm.deleted_by_sender = {int:not_deleted}',
  411. array(
  412. 'current_member' => $user_info['id'],
  413. 'not_deleted' => 0,
  414. )
  415. );
  416. else
  417. $request = $smcFunc['db_query']('', '
  418. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  419. FROM {db_prefix}pm_recipients AS pmr' . ($context['display_mode'] == 2 ? '
  420. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)' : '') . $labelJoin . '
  421. WHERE pmr.id_member = {int:current_member}
  422. AND pmr.deleted = {int:not_deleted}' . $labelQuery . $labelQuery2,
  423. array(
  424. 'current_member' => $user_info['id'],
  425. 'not_deleted' => 0,
  426. )
  427. );
  428. list ($max_messages) = $smcFunc['db_fetch_row']($request);
  429. $smcFunc['db_free_result']($request);
  430. // Only show the button if there are messages to delete.
  431. $context['show_delete'] = $max_messages > 0;
  432. // Start on the last page.
  433. if (!is_numeric($_GET['start']) || $_GET['start'] >= $max_messages)
  434. $_GET['start'] = ($max_messages - 1) - (($max_messages - 1) % $modSettings['defaultMaxMessages']);
  435. elseif ($_GET['start'] < 0)
  436. $_GET['start'] = 0;
  437. // ... but wait - what if we want to start from a specific message?
  438. if (isset($_GET['pmid']))
  439. {
  440. $pmID = (int) $_GET['pmid'];
  441. // Make sure you have access to this PM.
  442. if (!isAccessiblePM($pmID, $context['folder'] == 'sent' ? 'outbox' : 'inbox'))
  443. fatal_lang_error('no_access', false);
  444. $context['current_pm'] = $pmID;
  445. // With only one page of PM's we're gonna want page 1.
  446. if ($max_messages <= $modSettings['defaultMaxMessages'])
  447. $_GET['start'] = 0;
  448. // If we pass kstart we assume we're in the right place.
  449. elseif (!isset($_GET['kstart']))
  450. {
  451. if ($context['folder'] == 'sent')
  452. $request = $smcFunc['db_query']('', '
  453. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  454. FROM {db_prefix}personal_messages
  455. WHERE id_member_from = {int:current_member}
  456. AND deleted_by_sender = {int:not_deleted}
  457. AND id_pm ' . ($descending ? '>' : '<') . ' {int:id_pm}',
  458. array(
  459. 'current_member' => $user_info['id'],
  460. 'not_deleted' => 0,
  461. 'id_pm' => $pmID,
  462. )
  463. );
  464. else
  465. $request = $smcFunc['db_query']('', '
  466. SELECT COUNT(' . ($context['display_mode'] == 2 ? 'DISTINCT pm.id_pm_head' : '*') . ')
  467. FROM {db_prefix}pm_recipients AS pmr' . ($context['display_mode'] == 2 ? '
  468. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)' : '') . $labelJoin . '
  469. WHERE pmr.id_member = {int:current_member}
  470. AND pmr.deleted = {int:not_deleted}' . $labelQuery . $labelQuery2 . '
  471. AND pmr.id_pm ' . ($descending ? '>' : '<') . ' {int:id_pm}',
  472. array(
  473. 'current_member' => $user_info['id'],
  474. 'not_deleted' => 0,
  475. 'id_pm' => $pmID,
  476. )
  477. );
  478. list ($_GET['start']) = $smcFunc['db_fetch_row']($request);
  479. $smcFunc['db_free_result']($request);
  480. // To stop the page index's being abnormal, start the page on the page the message would normally be located on...
  481. $_GET['start'] = $modSettings['defaultMaxMessages'] * (int) ($_GET['start'] / $modSettings['defaultMaxMessages']);
  482. }
  483. }
  484. // Sanitize and validate pmsg variable if set.
  485. if (isset($_GET['pmsg']))
  486. {
  487. $pmsg = (int) $_GET['pmsg'];
  488. if (!isAccessiblePM($pmsg, $context['folder'] == 'sent' ? 'outbox' : 'inbox'))
  489. fatal_lang_error('no_access', false);
  490. }
  491. // Set up the page index.
  492. $context['page_index'] = constructPageIndex($scripturl . '?action=pm;f=' . $context['folder'] . (isset($_REQUEST['l']) ? ';l=' . (int) $_REQUEST['l'] : '') . ';sort=' . $context['sort_by'] . ($descending ? ';desc' : ''), $_GET['start'], $max_messages, $modSettings['defaultMaxMessages']);
  493. $context['start'] = $_GET['start'];
  494. // Determine the navigation context (especially useful for the wireless template).
  495. $context['links'] = array(
  496. 'first' => $_GET['start'] >= $modSettings['defaultMaxMessages'] ? $scripturl . '?action=pm;start=0' : '',
  497. 'prev' => $_GET['start'] >= $modSettings['defaultMaxMessages'] ? $scripturl . '?action=pm;start=' . ($_GET['start'] - $modSettings['defaultMaxMessages']) : '',
  498. 'next' => $_GET['start'] + $modSettings['defaultMaxMessages'] < $max_messages ? $scripturl . '?action=pm;start=' . ($_GET['start'] + $modSettings['defaultMaxMessages']) : '',
  499. 'last' => $_GET['start'] + $modSettings['defaultMaxMessages'] < $max_messages ? $scripturl . '?action=pm;start=' . (floor(($max_messages - 1) / $modSettings['defaultMaxMessages']) * $modSettings['defaultMaxMessages']) : '',
  500. 'up' => $scripturl,
  501. );
  502. $context['page_info'] = array(
  503. 'current_page' => $_GET['start'] / $modSettings['defaultMaxMessages'] + 1,
  504. 'num_pages' => floor(($max_messages - 1) / $modSettings['defaultMaxMessages']) + 1
  505. );
  506. // First work out what messages we need to see - if grouped is a little trickier...
  507. if ($context['display_mode'] == 2)
  508. {
  509. if ($context['folder'] != 'sent' && $context['folder'] != 'inbox')
  510. {
  511. $labelJoin = '
  512. INNER JOIN {db_prefix}pm_labeled_messages AS pl ON (pl.id_pm = pm.id_pm)';
  513. $labelQuery = '';
  514. $labelQuery2 = '
  515. AND pl.id_label = ' . $context['current_label_id'];
  516. }
  517. // On a non-default sort due to PostgreSQL we have to do a harder sort.
  518. if ($smcFunc['db_title'] == 'PostgreSQL' && $_GET['sort'] != 'pm.id_pm')
  519. {
  520. $sub_request = $smcFunc['db_query']('', '
  521. SELECT MAX({raw:sort}) AS sort_param, pm.id_pm_head
  522. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? ($context['sort_by'] == 'name' ? '
  523. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  524. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  525. AND pmr.id_member = {int:current_member}
  526. AND pmr.deleted = {int:not_deleted}
  527. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  528. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:id_member})') : '') . '
  529. WHERE ' . ($context['folder'] == 'sent' ? 'pm.id_member_from = {int:current_member}
  530. AND pm.deleted_by_sender = {int:not_deleted}' : '1=1') . (empty($pmsg) ? '' : '
  531. AND pm.id_pm = {int:id_pm}') . $labelQuery2 . '
  532. GROUP BY pm.id_pm_head
  533. ORDER BY sort_param' . ($descending ? ' DESC' : ' ASC') . (empty($pmsg) ? '
  534. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  535. array(
  536. 'current_member' => $user_info['id'],
  537. 'not_deleted' => 0,
  538. 'id_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  539. 'id_pm' => isset($pmsg) ? $pmsg : '0',
  540. 'sort' => $_GET['sort'],
  541. )
  542. );
  543. $sub_pms = array();
  544. while ($row = $smcFunc['db_fetch_assoc']($sub_request))
  545. $sub_pms[$row['id_pm_head']] = $row['sort_param'];
  546. $smcFunc['db_free_result']($sub_request);
  547. $request = $smcFunc['db_query']('', '
  548. SELECT pm.id_pm AS id_pm, pm.id_pm_head
  549. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? ($context['sort_by'] == 'name' ? '
  550. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  551. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  552. AND pmr.id_member = {int:current_member}
  553. AND pmr.deleted = {int:not_deleted}
  554. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  555. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:id_member})') : '') . '
  556. WHERE ' . (empty($sub_pms) ? '0=1' : 'pm.id_pm IN ({array_int:pm_list})') . $labelQuery2 . '
  557. ORDER BY ' . ($_GET['sort'] == 'pm.id_pm' && $context['folder'] != 'sent' ? 'id_pm' : '{raw:sort}') . ($descending ? ' DESC' : ' ASC') . (empty($pmsg) ? '
  558. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  559. array(
  560. 'current_member' => $user_info['id'],
  561. 'pm_list' => array_keys($sub_pms),
  562. 'not_deleted' => 0,
  563. 'sort' => $_GET['sort'],
  564. 'id_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  565. )
  566. );
  567. }
  568. else
  569. {
  570. $request = $smcFunc['db_query']('pm_conversation_list', '
  571. SELECT MAX(pm.id_pm) AS id_pm, pm.id_pm_head
  572. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? ($context['sort_by'] == 'name' ? '
  573. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  574. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  575. AND pmr.id_member = {int:current_member}
  576. AND pmr.deleted = {int:deleted_by}
  577. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  578. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:pm_member})') : '') . '
  579. WHERE ' . ($context['folder'] == 'sent' ? 'pm.id_member_from = {int:current_member}
  580. AND pm.deleted_by_sender = {int:deleted_by}' : '1=1') . (empty($pmsg) ? '' : '
  581. AND pm.id_pm = {int:pmsg}') . $labelQuery2 . '
  582. GROUP BY pm.id_pm_head
  583. ORDER BY ' . ($_GET['sort'] == 'pm.id_pm' && $context['folder'] != 'sent' ? 'id_pm' : '{raw:sort}') . ($descending ? ' DESC' : ' ASC') . (empty($_GET['pmsg']) ? '
  584. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  585. array(
  586. 'current_member' => $user_info['id'],
  587. 'deleted_by' => 0,
  588. 'sort' => $_GET['sort'],
  589. 'pm_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  590. 'pmsg' => isset($pmsg) ? (int) $pmsg : 0,
  591. )
  592. );
  593. }
  594. }
  595. // This is kinda simple!
  596. else
  597. {
  598. // @todo SLOW This query uses a filesort. (inbox only.)
  599. $request = $smcFunc['db_query']('', '
  600. SELECT pm.id_pm, pm.id_pm_head, pm.id_member_from
  601. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? '' . ($context['sort_by'] == 'name' ? '
  602. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') : '
  603. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm
  604. AND pmr.id_member = {int:current_member}
  605. AND pmr.deleted = {int:is_deleted}
  606. ' . $labelQuery . ')') . $labelJoin . ($context['sort_by'] == 'name' ? ( '
  607. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:pm_member})') : '') . '
  608. WHERE ' . ($context['folder'] == 'sent' ? 'pm.id_member_from = {raw:current_member}
  609. AND pm.deleted_by_sender = {int:is_deleted}' : '1=1') . (empty($pmsg) ? '' : '
  610. AND pm.id_pm = {int:pmsg}') . $labelQuery2 . '
  611. ORDER BY ' . ($_GET['sort'] == 'pm.id_pm' && $context['folder'] != 'sent' ? 'pmr.id_pm' : '{raw:sort}') . ($descending ? ' DESC' : ' ASC') . (empty($pmsg) ? '
  612. LIMIT ' . $_GET['start'] . ', ' . $modSettings['defaultMaxMessages'] : ''),
  613. array(
  614. 'current_member' => $user_info['id'],
  615. 'is_deleted' => 0,
  616. 'sort' => $_GET['sort'],
  617. 'pm_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  618. 'pmsg' => isset($pmsg) ? (int) $pmsg : 0,
  619. )
  620. );
  621. }
  622. // Load the id_pms and initialize recipients.
  623. $pms = array();
  624. $lastData = array();
  625. $posters = $context['folder'] == 'sent' ? array($user_info['id']) : array();
  626. $recipients = array();
  627. while ($row = $smcFunc['db_fetch_assoc']($request))
  628. {
  629. if (!isset($recipients[$row['id_pm']]))
  630. {
  631. if (isset($row['id_member_from']))
  632. $posters[$row['id_pm']] = $row['id_member_from'];
  633. $pms[$row['id_pm']] = $row['id_pm'];
  634. $recipients[$row['id_pm']] = array(
  635. 'to' => array(),
  636. 'bcc' => array()
  637. );
  638. }
  639. // Keep track of the last message so we know what the head is without another query!
  640. if ((empty($pmID) && (empty($options['view_newest_pm_first']) || !isset($lastData))) || empty($lastData) || (!empty($pmID) && $pmID == $row['id_pm']))
  641. $lastData = array(
  642. 'id' => $row['id_pm'],
  643. 'head' => $row['id_pm_head'],
  644. );
  645. }
  646. $smcFunc['db_free_result']($request);
  647. // Make sure that we have been given a correct head pm id!
  648. if ($context['display_mode'] == 2 && !empty($pmID) && $pmID != $lastData['id'])
  649. fatal_lang_error('no_access', false);
  650. if (!empty($pms))
  651. {
  652. // Select the correct current message.
  653. if (empty($pmID))
  654. $context['current_pm'] = $lastData['id'];
  655. // This is a list of the pm's that are used for "full" display.
  656. if ($context['display_mode'] == 0)
  657. $display_pms = $pms;
  658. else
  659. $display_pms = array($context['current_pm']);
  660. // At this point we know the main id_pm's. But - if we are looking at conversations we need the others!
  661. if ($context['display_mode'] == 2)
  662. {
  663. $request = $smcFunc['db_query']('', '
  664. SELECT pm.id_pm, pm.id_member_from, pm.deleted_by_sender, pmr.id_member, pmr.deleted
  665. FROM {db_prefix}personal_messages AS pm
  666. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)
  667. WHERE pm.id_pm_head = {int:id_pm_head}
  668. AND ((pm.id_member_from = {int:current_member} AND pm.deleted_by_sender = {int:not_deleted})
  669. OR (pmr.id_member = {int:current_member} AND pmr.deleted = {int:not_deleted}))
  670. ORDER BY pm.id_pm',
  671. array(
  672. 'current_member' => $user_info['id'],
  673. 'id_pm_head' => $lastData['head'],
  674. 'not_deleted' => 0,
  675. )
  676. );
  677. while ($row = $smcFunc['db_fetch_assoc']($request))
  678. {
  679. // This is, frankly, a joke. We will put in a workaround for people sending to themselves - yawn!
  680. if ($context['folder'] == 'sent' && $row['id_member_from'] == $user_info['id'] && $row['deleted_by_sender'] == 1)
  681. continue;
  682. elseif ($row['id_member'] == $user_info['id'] & $row['deleted'] == 1)
  683. continue;
  684. if (!isset($recipients[$row['id_pm']]))
  685. $recipients[$row['id_pm']] = array(
  686. 'to' => array(),
  687. 'bcc' => array()
  688. );
  689. $display_pms[] = $row['id_pm'];
  690. $posters[$row['id_pm']] = $row['id_member_from'];
  691. }
  692. $smcFunc['db_free_result']($request);
  693. }
  694. // This is pretty much EVERY pm!
  695. $all_pms = array_merge($pms, $display_pms);
  696. $all_pms = array_unique($all_pms);
  697. // Get recipients (don't include bcc-recipients for your inbox, you're not supposed to know :P).
  698. $request = $smcFunc['db_query']('', '
  699. SELECT pmr.id_pm, mem_to.id_member AS id_member_to, mem_to.real_name AS to_name, pmr.bcc, pmr.in_inbox, pmr.is_read
  700. FROM {db_prefix}pm_recipients AS pmr
  701. LEFT JOIN {db_prefix}members AS mem_to ON (mem_to.id_member = pmr.id_member)
  702. WHERE pmr.id_pm IN ({array_int:pm_list})',
  703. array(
  704. 'pm_list' => $all_pms,
  705. )
  706. );
  707. $context['message_labels'] = array();
  708. $context['message_replied'] = array();
  709. $context['message_unread'] = array();
  710. while ($row = $smcFunc['db_fetch_assoc']($request))
  711. {
  712. if ($context['folder'] == 'sent' || empty($row['bcc']))
  713. $recipients[$row['id_pm']][empty($row['bcc']) ? 'to' : 'bcc'][] = empty($row['id_member_to']) ? $txt['guest_title'] : '<a href="' . $scripturl . '?action=profile;u=' . $row['id_member_to'] . '">' . $row['to_name'] . '</a>';
  714. if ($row['id_member_to'] == $user_info['id'] && $context['folder'] != 'sent')
  715. {
  716. $context['message_replied'][$row['id_pm']] = $row['is_read'] & 2;
  717. $context['message_unread'][$row['id_pm']] = $row['is_read'] == 0;
  718. // Get the labels for this PM
  719. $request2 = $smcFunc['db_query']('', '
  720. SELECT id_label
  721. FROM {db_prefix}pm_labeled_messages
  722. WHERE id_pm = {int:current_pm}',
  723. array(
  724. 'current_pm' => $row['id_pm'],
  725. )
  726. );
  727. while($row2 = $smcFunc['db_fetch_assoc']($request2))
  728. {
  729. $l_id = $row2['id_label'];
  730. if (isset($context['labels'][$id_label]))
  731. $context['message_labels'][$row['id_pm']][$l_id] = array('id' => $l_id, 'name' => $context['labels'][$l_id]['name']);
  732. }
  733. $smcFunc['db_free_result']($request2);
  734. // Is this in the inbox as well?
  735. if ($row['in_inbox'] == 1)
  736. {
  737. $context['message_labels'][$row['id_pm']][-1] = array('id' => -1, 'name' => $context['labels'][-1]['name']);
  738. }
  739. }
  740. }
  741. $smcFunc['db_free_result']($request);
  742. // Make sure we don't load unnecessary data.
  743. if ($context['display_mode'] == 1)
  744. {
  745. foreach ($posters as $k => $v)
  746. if (!in_array($k, $display_pms))
  747. unset($posters[$k]);
  748. }
  749. // Load any users....
  750. $posters = array_unique($posters);
  751. if (!empty($posters))
  752. loadMemberData($posters);
  753. // If we're on grouped/restricted view get a restricted list of messages.
  754. if ($context['display_mode'] != 0)
  755. {
  756. // Get the order right.
  757. $orderBy = array();
  758. foreach (array_reverse($pms) as $pm)
  759. $orderBy[] = 'pm.id_pm = ' . $pm;
  760. // Seperate query for these bits!
  761. $subjects_request = $smcFunc['db_query']('', '
  762. SELECT pm.id_pm, pm.subject, IFNULL(pm.id_member_from, 0) AS not_guest, pm.msgtime, IFNULL(mem.real_name, pm.from_name) AS from_name,
  763. mem.id_member
  764. FROM {db_prefix}personal_messages AS pm
  765. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  766. WHERE pm.id_pm IN ({array_int:pm_list})
  767. ORDER BY ' . implode(', ', $orderBy) . '
  768. LIMIT ' . count($pms),
  769. array(
  770. 'pm_list' => $pms,
  771. )
  772. );
  773. }
  774. // Execute the query!
  775. $messages_request = $smcFunc['db_query']('', '
  776. SELECT pm.id_pm, pm.subject, pm.id_member_from, pm.body, pm.msgtime, pm.from_name
  777. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? '
  778. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)' : '') . ($context['sort_by'] == 'name' ? '
  779. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = {raw:id_member})' : '') . '
  780. WHERE pm.id_pm IN ({array_int:display_pms})' . ($context['folder'] == 'sent' ? '
  781. GROUP BY pm.id_pm, pm.subject, pm.id_member_from, pm.body, pm.msgtime, pm.from_name' : '') . '
  782. ORDER BY ' . ($context['display_mode'] == 2 ? 'pm.id_pm' : $_GET['sort']) . ($descending ? ' DESC' : ' ASC') . '
  783. LIMIT ' . count($display_pms),
  784. array(
  785. 'display_pms' => $display_pms,
  786. 'id_member' => $context['folder'] == 'sent' ? 'pmr.id_member' : 'pm.id_member_from',
  787. )
  788. );
  789. // Build the conversation button array.
  790. if ($context['display_mode'] == 2)
  791. {
  792. $context['conversation_buttons'] = array(
  793. 'delete' => array('text' => 'delete_conversation', 'image' => 'delete.png', 'lang' => true, 'url' => $scripturl . '?action=pm;sa=pmactions;pm_actions[' . $context['current_pm'] . ']=delete;conversation;f=' . $context['folder'] . ';start=' . $context['start'] . ($context['current_label_id'] != -1 ? ';l=' . $context['current_label_id'] : '') . ';' . $context['session_var'] . '=' . $context['session_id'], 'custom' => 'onclick="return confirm(\'' . addslashes($txt['remove_message']) . '?\');"'),
  794. );
  795. // Allow mods to add additional buttons here
  796. call_integration_hook('integrate_conversation_buttons');
  797. }
  798. }
  799. else
  800. $messages_request = false;
  801. $context['can_send_pm'] = allowedTo('pm_send');
  802. $context['can_send_email'] = allowedTo('send_email_to_members');
  803. if (!WIRELESS)
  804. $context['sub_template'] = 'folder';
  805. $context['page_title'] = $txt['pm_inbox'];
  806. // Finally mark the relevant messages as read.
  807. if ($context['folder'] != 'sent' && !empty($context['labels'][(int) $context['current_label_id']]['unread_messages']))
  808. {
  809. // If the display mode is "old sk00l" do them all...
  810. if ($context['display_mode'] == 0)
  811. markMessages(null, $context['current_label_id']);
  812. // Otherwise do just the current one!
  813. elseif (!empty($context['current_pm']))
  814. markMessages($display_pms, $context['current_label_id']);
  815. }
  816. }
  817. /**
  818. * Get a personal message for the theme. (used to save memory.)
  819. *
  820. * @param $type
  821. * @param $reset
  822. */
  823. function prepareMessageContext($type = 'subject', $reset = false)
  824. {
  825. global $txt, $scripturl, $modSettings, $settings, $context, $messages_request, $memberContext, $recipients, $smcFunc;
  826. global $user_info, $subjects_request;
  827. // Count the current message number....
  828. static $counter = null;
  829. if ($counter === null || $reset)
  830. $counter = $context['start'];
  831. static $temp_pm_selected = null;
  832. if ($temp_pm_selected === null)
  833. {
  834. $temp_pm_selected = isset($_SESSION['pm_selected']) ? $_SESSION['pm_selected'] : array();
  835. $_SESSION['pm_selected'] = array();
  836. }
  837. // If we're in non-boring view do something exciting!
  838. if ($context['display_mode'] != 0 && $subjects_request && $type == 'subject')
  839. {
  840. $subject = $smcFunc['db_fetch_assoc']($subjects_request);
  841. if (!$subject)
  842. {
  843. $smcFunc['db_free_result']($subjects_request);
  844. return false;
  845. }
  846. $subject['subject'] = $subject['subject'] == '' ? $txt['no_subject'] : $subject['subject'];
  847. censorText($subject['subject']);
  848. $output = array(
  849. 'id' => $subject['id_pm'],
  850. 'member' => array(
  851. 'id' => $subject['id_member_from'],
  852. 'name' => $subject['from_name'],
  853. 'link' => $subject['not_guest'] ? '<a href="' . $scripturl . '?action=profile;u=' . $subject['id_member_from'] . '">' . $subject['from_name'] . '</a>' : $subject['from_name'],
  854. ),
  855. 'recipients' => &$recipients[$subject['id_pm']],
  856. 'subject' => $subject['subject'],
  857. 'time' => timeformat($subject['msgtime']),
  858. 'timestamp' => forum_time(true, $subject['msgtime']),
  859. 'number_recipients' => count($recipients[$subject['id_pm']]['to']),
  860. 'labels' => &$context['message_labels'][$subject['id_pm']],
  861. 'fully_labeled' => count($context['message_labels'][$subject['id_pm']]) == count($context['labels']),
  862. 'is_replied_to' => &$context['message_replied'][$subject['id_pm']],
  863. 'is_unread' => &$context['message_unread'][$subject['id_pm']],
  864. 'is_selected' => !empty($temp_pm_selected) && in_array($subject['id_pm'], $temp_pm_selected),
  865. );
  866. return $output;
  867. }
  868. // Bail if it's false, ie. no messages.
  869. if ($messages_request == false)
  870. return false;
  871. // Reset the data?
  872. if ($reset == true)
  873. return @$smcFunc['db_data_seek']($messages_request, 0);
  874. // Get the next one... bail if anything goes wrong.
  875. $message = $smcFunc['db_fetch_assoc']($messages_request);
  876. if (!$message)
  877. {
  878. if ($type != 'subject')
  879. $smcFunc['db_free_result']($messages_request);
  880. return false;
  881. }
  882. // Use '(no subject)' if none was specified.
  883. $message['subject'] = $message['subject'] == '' ? $txt['no_subject'] : $message['subject'];
  884. // Load the message's information - if it's not there, load the guest information.
  885. if (!loadMemberContext($message['id_member_from'], true))
  886. {
  887. $memberContext[$message['id_member_from']]['name'] = $message['from_name'];
  888. $memberContext[$message['id_member_from']]['id'] = 0;
  889. // Sometimes the forum sends messages itself (Warnings are an example) - in this case don't label it from a guest.
  890. $memberContext[$message['id_member_from']]['group'] = $message['from_name'] == $context['forum_name'] ? '' : $txt['guest_title'];
  891. $memberContext[$message['id_member_from']]['link'] = $message['from_name'];
  892. $memberContext[$message['id_member_from']]['email'] = '';
  893. $memberContext[$message['id_member_from']]['show_email'] = showEmailAddress(true, 0);
  894. $memberContext[$message['id_member_from']]['is_guest'] = true;
  895. }
  896. else
  897. {
  898. $memberContext[$message['id_member_from']]['can_view_profile'] = allowedTo('profile_view_any') || ($message['id_member_from'] == $user_info['id'] && allowedTo('profile_view_own'));
  899. $memberContext[$message['id_member_from']]['can_see_warning'] = !isset($context['disabled_fields']['warning_status']) && $memberContext[$message['id_member_from']]['warning_status'] && ($context['user']['can_mod'] || (!empty($modSettings['warning_show']) && ($modSettings['warning_show'] > 1 || $message['id_member_from'] == $user_info['id'])));
  900. }
  901. $memberContext[$message['id_member_from']]['show_profile_buttons'] = $settings['show_profile_buttons'] && (!empty($memberContext[$message['id_member_from']]['can_view_profile']) || (!empty($memberContext[$message['id_member_from']]['website']['url']) && !isset($context['disabled_fields']['website'])) || (in_array($memberContext[$message['id_member_from']]['show_email'], array('yes', 'yes_permission_override', 'no_through_forum'))) || $context['can_send_pm']);
  902. // Censor all the important text...
  903. censorText($message['body']);
  904. censorText($message['subject']);
  905. // Run UBBC interpreter on the message.
  906. $message['body'] = parse_bbc($message['body'], true, 'pm' . $message['id_pm']);
  907. // Send the array.
  908. $output = array(
  909. 'alternate' => $counter % 2,
  910. 'id' => $message['id_pm'],
  911. 'member' => &$memberContext[$message['id_member_from']],
  912. 'subject' => $message['subject'],
  913. 'time' => timeformat($message['msgtime']),
  914. 'timestamp' => forum_time(true, $message['msgtime']),
  915. 'counter' => $counter,
  916. 'body' => $message['body'],
  917. 'recipients' => &$recipients[$message['id_pm']],
  918. 'number_recipients' => count($recipients[$message['id_pm']]['to']),
  919. 'labels' => &$context['message_labels'][$message['id_pm']],
  920. 'fully_labeled' => count($context['message_labels'][$message['id_pm']]) == count($context['labels']),
  921. 'is_replied_to' => &$context['message_replied'][$message['id_pm']],
  922. 'is_unread' => &$context['message_unread'][$message['id_pm']],
  923. 'is_selected' => !empty($temp_pm_selected) && in_array($message['id_pm'], $temp_pm_selected),
  924. 'is_message_author' => $message['id_member_from'] == $user_info['id'],
  925. 'can_report' => !empty($modSettings['enableReportPM']),
  926. 'can_see_ip' => allowedTo('moderate_forum') || ($message['id_member_from'] == $user_info['id'] && !empty($user_info['id'])),
  927. );
  928. $counter++;
  929. return $output;
  930. }
  931. /**
  932. * Allows to search through personal messages.
  933. */
  934. function MessageSearch()
  935. {
  936. global $context, $txt, $scripturl, $modSettings, $smcFunc;
  937. if (isset($_REQUEST['params']))
  938. {
  939. $temp_params = explode('|"|', base64_decode(strtr($_REQUEST['params'], array(' ' => '+'))));
  940. $context['search_params'] = array();
  941. foreach ($temp_params as $i => $data)
  942. {
  943. @list ($k, $v) = explode('|\'|', $data);
  944. $context['search_params'][$k] = $v;
  945. }
  946. }
  947. if (isset($_REQUEST['search']))
  948. $context['search_params']['search'] = un_htmlspecialchars($_REQUEST['search']);
  949. if (isset($context['search_params']['search']))
  950. $context['search_params']['search'] = $smcFunc['htmlspecialchars']($context['search_params']['search']);
  951. if (isset($context['search_params']['userspec']))
  952. $context['search_params']['userspec'] = $smcFunc['htmlspecialchars']($context['search_params']['userspec']);
  953. if (!empty($context['search_params']['searchtype']))
  954. $context['search_params']['searchtype'] = 2;
  955. if (!empty($context['search_params']['minage']))
  956. $context['search_params']['minage'] = (int) $context['search_params']['minage'];
  957. if (!empty($context['search_params']['maxage']))
  958. $context['search_params']['maxage'] = (int) $context['search_params']['maxage'];
  959. $context['search_params']['subject_only'] = !empty($context['search_params']['subject_only']);
  960. $context['search_params']['show_complete'] = !empty($context['search_params']['show_complete']);
  961. // Create the array of labels to be searched.
  962. $context['search_labels'] = array();
  963. $searchedLabels = isset($context['search_params']['labels']) && $context['search_params']['labels'] != '' ? explode(',', $context['search_params']['labels']) : array();
  964. foreach ($context['labels'] as $label)
  965. {
  966. $context['search_labels'][] = array(
  967. 'id' => $label['id'],
  968. 'name' => $label['name'],
  969. 'checked' => !empty($searchedLabels) ? in_array($label['id'], $searchedLabels) : true,
  970. );
  971. }
  972. // Are all the labels checked?
  973. $context['check_all'] = empty($searchedLabels) || count($context['search_labels']) == count($searchedLabels);
  974. // Load the error text strings if there were errors in the search.
  975. if (!empty($context['search_errors']))
  976. {
  977. loadLanguage('Errors');
  978. $context['search_errors']['messages'] = array();
  979. foreach ($context['search_errors'] as $search_error => $dummy)
  980. {
  981. if ($search_error == 'messages')
  982. continue;
  983. $context['search_errors']['messages'][] = $txt['error_' . $search_error];
  984. }
  985. }
  986. $context['simple_search'] = isset($context['search_params']['advanced']) ? empty($context['search_params']['advanced']) : !empty($modSettings['simpleSearch']) && !isset($_REQUEST['advanced']);
  987. $context['page_title'] = $txt['pm_search_title'];
  988. $context['sub_template'] = 'search';
  989. $context['linktree'][] = array(
  990. 'url' => $scripturl . '?action=pm;sa=search',
  991. 'name' => $txt['pm_search_bar_title'],
  992. );
  993. }
  994. /**
  995. * Actually do the search of personal messages.
  996. */
  997. function MessageSearch2()
  998. {
  999. global $scripturl, $modSettings, $user_info, $context, $txt;
  1000. global $memberContext, $smcFunc;
  1001. if (!empty($context['load_average']) && !empty($modSettings['loadavg_search']) && $context['load_average'] >= $modSettings['loadavg_search'])
  1002. fatal_lang_error('loadavg_search_disabled', false);
  1003. /**
  1004. * @todo For the moment force the folder to the inbox.
  1005. * @todo Maybe set the inbox based on a cookie or theme setting?
  1006. */
  1007. $context['folder'] = 'inbox';
  1008. // Some useful general permissions.
  1009. $context['can_send_pm'] = allowedTo('pm_send');
  1010. // Some hardcoded veriables that can be tweaked if required.
  1011. $maxMembersToSearch = 500;
  1012. // Extract all the search parameters.
  1013. $search_params = array();
  1014. if (isset($_REQUEST['params']))
  1015. {
  1016. $temp_params = explode('|"|', base64_decode(strtr($_REQUEST['params'], array(' ' => '+'))));
  1017. foreach ($temp_params as $i => $data)
  1018. {
  1019. @list ($k, $v) = explode('|\'|', $data);
  1020. $search_params[$k] = $v;
  1021. }
  1022. }
  1023. $context['start'] = isset($_GET['start']) ? (int) $_GET['start'] : 0;
  1024. // Store whether simple search was used (needed if the user wants to do another query).
  1025. if (!isset($search_params['advanced']))
  1026. $search_params['advanced'] = empty($_REQUEST['advanced']) ? 0 : 1;
  1027. // 1 => 'allwords' (default, don't set as param) / 2 => 'anywords'.
  1028. if (!empty($search_params['searchtype']) || (!empty($_REQUEST['searchtype']) && $_REQUEST['searchtype'] == 2))
  1029. $search_params['searchtype'] = 2;
  1030. // Minimum age of messages. Default to zero (don't set param in that case).
  1031. if (!empty($search_params['minage']) || (!empty($_REQUEST['minage']) && $_REQUEST['minage'] > 0))
  1032. $search_params['minage'] = !empty($search_params['minage']) ? (int) $search_params['minage'] : (int) $_REQUEST['minage'];
  1033. // Maximum age of messages. Default to infinite (9999 days: param not set).
  1034. if (!empty($search_params['maxage']) || (!empty($_REQUEST['maxage']) && $_REQUEST['maxage'] != 9999))
  1035. $search_params['maxage'] = !empty($search_params['maxage']) ? (int) $search_params['maxage'] : (int) $_REQUEST['maxage'];
  1036. $search_params['subject_only'] = !empty($search_params['subject_only']) || !empty($_REQUEST['subject_only']);
  1037. $search_params['show_complete'] = !empty($search_params['show_complete']) || !empty($_REQUEST['show_complete']);
  1038. // Default the user name to a wildcard matching every user (*).
  1039. if (!empty($search_params['user_spec']) || (!empty($_REQUEST['userspec']) && $_REQUEST['userspec'] != '*'))
  1040. $search_params['userspec'] = isset($search_params['userspec']) ? $search_params['userspec'] : $_REQUEST['userspec'];
  1041. // This will be full of all kinds of parameters!
  1042. $searchq_parameters = array();
  1043. // If there's no specific user, then don't mention it in the main query.
  1044. if (empty($search_params['userspec']))
  1045. $userQuery = '';
  1046. else
  1047. {
  1048. $userString = strtr($smcFunc['htmlspecialchars']($search_params['userspec'], ENT_QUOTES), array('&quot;' => '"'));
  1049. $userString = strtr($userString, array('%' => '\%', '_' => '\_', '*' => '%', '?' => '_'));
  1050. preg_match_all('~"([^"]+)"~', $userString, $matches);
  1051. $possible_users = array_merge($matches[1], explode(',', preg_replace('~"[^"]+"~', '', $userString)));
  1052. for ($k = 0, $n = count($possible_users); $k < $n; $k++)
  1053. {
  1054. $possible_users[$k] = trim($possible_users[$k]);
  1055. if (strlen($possible_users[$k]) == 0)
  1056. unset($possible_users[$k]);
  1057. }
  1058. if (!empty($possible_users))
  1059. {
  1060. // We need to bring this into the query and do it nice and cleanly.
  1061. $where_params = array();
  1062. $where_clause = array();
  1063. foreach ($possible_users as $k => $v)
  1064. {
  1065. $where_params['name_' . $k] = $v;
  1066. $where_clause[] = '{raw:real_name} LIKE {string:name_' . $k . '}';
  1067. if (!isset($where_params['real_name']))
  1068. $where_params['real_name'] = $smcFunc['db_case_sensitive'] ? 'LOWER(real_name)' : 'real_name';
  1069. }
  1070. // Who matches those criteria?
  1071. // @todo This doesn't support sent item searching.
  1072. $request = $smcFunc['db_query']('', '
  1073. SELECT id_member
  1074. FROM {db_prefix}members
  1075. WHERE ' . implode(' OR ', $where_clause),
  1076. $where_params
  1077. );
  1078. // Simply do nothing if there're too many members matching the criteria.
  1079. if ($smcFunc['db_num_rows']($request) > $maxMembersToSearch)
  1080. $userQuery = '';
  1081. elseif ($smcFunc['db_num_rows']($request) == 0)
  1082. {
  1083. $userQuery = 'AND pm.id_member_from = 0 AND ({raw:pm_from_name} LIKE {raw:guest_user_name_implode})';
  1084. $searchq_parameters['guest_user_name_implode'] = '\'' . implode('\' OR ' . ($smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name') . ' LIKE \'', $possible_users) . '\'';
  1085. $searchq_parameters['pm_from_name'] = $smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name';
  1086. }
  1087. else
  1088. {
  1089. $memberlist = array();
  1090. while ($row = $smcFunc['db_fetch_assoc']($request))
  1091. $memberlist[] = $row['id_member'];
  1092. $userQuery = 'AND (pm.id_member_from IN ({array_int:member_list}) OR (pm.id_member_from = 0 AND ({raw:pm_from_name} LIKE {raw:guest_user_name_implode})))';
  1093. $searchq_parameters['guest_user_name_implode'] = '\'' . implode('\' OR ' . ($smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name') . ' LIKE \'', $possible_users) . '\'';
  1094. $searchq_parameters['member_list'] = $memberlist;
  1095. $searchq_parameters['pm_from_name'] = $smcFunc['db_case_sensitive'] ? 'LOWER(pm.from_name)' : 'pm.from_name';
  1096. }
  1097. $smcFunc['db_free_result']($request);
  1098. }
  1099. else
  1100. $userQuery = '';
  1101. }
  1102. // Setup the sorting variables...
  1103. // @todo Add more in here!
  1104. $sort_columns = array(
  1105. 'pm.id_pm',
  1106. );
  1107. if (empty($search_params['sort']) && !empty($_REQUEST['sort']))
  1108. list ($search_params['sort'], $search_params['sort_dir']) = array_pad(explode('|', $_REQUEST['sort']), 2, '');
  1109. $search_params['sort'] = !empty($search_params['sort']) && in_array($search_params['sort'], $sort_columns) ? $search_params['sort'] : 'pm.id_pm';
  1110. $search_params['sort_dir'] = !empty($search_params['sort_dir']) && $search_params['sort_dir'] == 'asc' ? 'asc' : 'desc';
  1111. // Sort out any labels we may be searching by.
  1112. $labelQuery = '';
  1113. $labelJoin = '';
  1114. if ($context['folder'] == 'inbox' && !empty($search_params['advanced']) && $context['currently_using_labels'])
  1115. {
  1116. // Came here from pagination? Put them back into $_REQUEST for sanitization.
  1117. if (isset($search_params['labels']))
  1118. $_REQUEST['searchlabel'] = explode(',', $search_params['labels']);
  1119. // Assuming we have some labels - make them all integers.
  1120. if (!empty($_REQUEST['searchlabel']) && is_array($_REQUEST['searchlabel']))
  1121. {
  1122. foreach ($_REQUEST['searchlabel'] as $key => $id)
  1123. $_REQUEST['searchlabel'][$key] = (int) $id;
  1124. }
  1125. else
  1126. $_REQUEST['searchlabel'] = array();
  1127. // Now that everything is cleaned up a bit, make the labels a param.
  1128. $search_params['labels'] = implode(',', $_REQUEST['searchlabel']);
  1129. // No labels selected? That must be an error!
  1130. if (empty($_REQUEST['searchlabel']))
  1131. $context['search_errors']['no_labels_selected'] = true;
  1132. // Otherwise prepare the query!
  1133. elseif (count($_REQUEST['searchlabel']) != count($context['labels']))
  1134. {
  1135. // Special case here... "inbox" isn't a real label anymore...
  1136. if (in_array(-1, $_REQUEST['searchlabel']))
  1137. {
  1138. $labelQuery = ' AND pmr.in_inbox = {int:in_inbox}';
  1139. $searchq_parameters['in_inbox'] = 1;
  1140. // Now we get rid of that...
  1141. $temp = array_diff($_REQUEST['searchlabel'], array(-1));
  1142. $_REQUEST['searchlabel'] = $temp;
  1143. }
  1144. // Still have something?
  1145. if (!empty($_REQUEST['searchlabel']))
  1146. {
  1147. if ($labelQuery == '')
  1148. {
  1149. // Not searching the inbox - PM must be labeled
  1150. $labelQuery = ' AND pml.id_label IN ({array_int:labels})';
  1151. $labelJoin = ' INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_pm = pmr.id_pm)';
  1152. }
  1153. else
  1154. {
  1155. // Searching the inbox - PM doesn't have to be labeled
  1156. $labelQuery = ' AND (' . substr($labelQuery, 5) . ' OR pml.id_label IN ({array_int:labels}))';
  1157. $labelJoin = ' LEFT JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_pm = pmr.id_pm)';
  1158. }
  1159. $searchq_parameters['labels'] = $_REQUEST['searchlabel'];
  1160. }
  1161. }
  1162. }
  1163. // What are we actually searching for?
  1164. $search_params['search'] = !empty($search_params['search']) ? $search_params['search'] : (isset($_REQUEST['search']) ? $_REQUEST['search'] : '');
  1165. // If we ain't got nothing - we should error!
  1166. if (!isset($search_params['search']) || $search_params['search'] == '')
  1167. $context['search_errors']['invalid_search_string'] = true;
  1168. // Extract phrase parts first (e.g. some words "this is a phrase" some more words.)
  1169. preg_match_all('~(?:^|\s)([-]?)"([^"]+)"(?:$|\s)~' . ($context['utf8'] ? 'u' : ''), $search_params['search'], $matches, PREG_PATTERN_ORDER);
  1170. $searchArray = $matches[2];
  1171. // Remove the phrase parts and extract the words.
  1172. $tempSearch = explode(' ', preg_replace('~(?:^|\s)(?:[-]?)"(?:[^"]+)"(?:$|\s)~' . ($context['utf8'] ? 'u' : ''), ' ', $search_params['search']));
  1173. // A minus sign in front of a word excludes the word.... so...
  1174. $excludedWords = array();
  1175. // .. first, we check for things like -"some words", but not "-some words".
  1176. foreach ($matches[1] as $index => $word)
  1177. if ($word == '-')
  1178. {
  1179. $word = $smcFunc['strtolower'](trim($searchArray[$index]));
  1180. if (strlen($word) > 0)
  1181. $excludedWords[] = $word;
  1182. unset($searchArray[$index]);
  1183. }
  1184. // Now we look for -test, etc.... normaller.
  1185. foreach ($tempSearch as $index => $word)
  1186. {
  1187. if (strpos(trim($word), '-') === 0)
  1188. {
  1189. $word = substr($smcFunc['strtolower']($word), 1);
  1190. if (strlen($word) > 0)
  1191. $excludedWords[] = $word;
  1192. unset($tempSearch[$index]);
  1193. }
  1194. }
  1195. $searchArray = array_merge($searchArray, $tempSearch);
  1196. // Trim everything and make sure there are no words that are the same.
  1197. foreach ($searchArray as $index => $value)
  1198. {
  1199. $searchArray[$index] = $smcFunc['strtolower'](trim($value));
  1200. if ($searchArray[$index] == '')
  1201. unset($searchArray[$index]);
  1202. else
  1203. {
  1204. // Sort out entities first.
  1205. $searchArray[$index] = $smcFunc['htmlspecialchars']($searchArray[$index]);
  1206. }
  1207. }
  1208. $searchArray = array_unique($searchArray);
  1209. // Create an array of replacements for highlighting.
  1210. $context['mark'] = array();
  1211. foreach ($searchArray as $word)
  1212. $context['mark'][$word] = '<strong class="highlight">' . $word . '</strong>';
  1213. // This contains *everything*
  1214. $searchWords = array_merge($searchArray, $excludedWords);
  1215. // Make sure at least one word is being searched for.
  1216. if (empty($searchArray))
  1217. $context['search_errors']['invalid_search_string'] = true;
  1218. // Sort out the search query so the user can edit it - if they want.
  1219. $context['search_params'] = $search_params;
  1220. if (isset($context['search_params']['search']))
  1221. $context['search_params']['search'] = $smcFunc['htmlspecialchars']($context['search_params']['search']);
  1222. if (isset($context['search_params']['userspec']))
  1223. $context['search_params']['userspec'] = $smcFunc['htmlspecialchars']($context['search_params']['userspec']);
  1224. // Now we have all the parameters, combine them together for pagination and the like...
  1225. $context['params'] = array();
  1226. foreach ($search_params as $k => $v)
  1227. $context['params'][] = $k . '|\'|' . $v;
  1228. $context['params'] = base64_encode(implode('|"|', $context['params']));
  1229. // Compile the subject query part.
  1230. $andQueryParts = array();
  1231. foreach ($searchWords as $index => $word)
  1232. {
  1233. if ($word == '')
  1234. continue;
  1235. if ($search_params['subject_only'])
  1236. $andQueryParts[] = 'pm.subject' . (in_array($word, $excludedWords) ? ' NOT' : '') . ' LIKE {string:search_' . $index . '}';
  1237. else
  1238. $andQueryParts[] = '(pm.subject' . (in_array($word, $excludedWords) ? ' NOT' : '') . ' LIKE {string:search_' . $index . '} ' . (in_array($word, $excludedWords) ? 'AND pm.body NOT' : 'OR pm.body') . ' LIKE {string:search_' . $index . '})';
  1239. $searchq_parameters['search_' . $index] = '%' . strtr($word, array('_' => '\\_', '%' => '\\%')) . '%';
  1240. }
  1241. $searchQuery = ' 1=1';
  1242. if (!empty($andQueryParts))
  1243. $searchQuery = implode(!empty($search_params['searchtype']) && $search_params['searchtype'] == 2 ? ' OR ' : ' AND ', $andQueryParts);
  1244. // Age limits?
  1245. $timeQuery = '';
  1246. if (!empty($search_params['minage']))
  1247. $timeQuery .= ' AND pm.msgtime < ' . (time() - $search_params['minage'] * 86400);
  1248. if (!empty($search_params['maxage']))
  1249. $timeQuery .= ' AND pm.msgtime > ' . (time() - $search_params['maxage'] * 86400);
  1250. // If we have errors - return back to the first screen...
  1251. if (!empty($context['search_errors']))
  1252. {
  1253. $_REQUEST['params'] = $context['params'];
  1254. return MessageSearch();
  1255. }
  1256. // Get the amount of results.
  1257. $request = $smcFunc['db_query']('', '
  1258. SELECT COUNT(*)
  1259. FROM {db_prefix}pm_recipients AS pmr
  1260. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  1261. ' . $labelJoin . '
  1262. WHERE ' . ($context['folder'] == 'inbox' ? '
  1263. pmr.id_member = {int:current_member}
  1264. AND pmr.deleted = {int:not_deleted}' : '
  1265. pm.id_member_from = {int:current_member}
  1266. AND pm.deleted_by_sender = {int:not_deleted}') . '
  1267. ' . $userQuery . $labelQuery . $timeQuery . '
  1268. AND (' . $searchQuery . ')',
  1269. array_merge($searchq_parameters, array(
  1270. 'current_member' => $user_info['id'],
  1271. 'not_deleted' => 0,
  1272. ))
  1273. );
  1274. list ($numResults) = $smcFunc['db_fetch_row']($request);
  1275. $smcFunc['db_free_result']($request);
  1276. // Get all the matching messages... using standard search only (No caching and the like!)
  1277. // @todo This doesn't support sent item searching yet.
  1278. $request = $smcFunc['db_query']('', '
  1279. SELECT pm.id_pm, pm.id_pm_head, pm.id_member_from
  1280. FROM {db_prefix}pm_recipients AS pmr
  1281. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  1282. ' . $labelJoin . '
  1283. WHERE ' . ($context['folder'] == 'inbox' ? '
  1284. pmr.id_member = {int:current_member}
  1285. AND pmr.deleted = {int:not_deleted}' : '
  1286. pm.id_member_from = {int:current_member}
  1287. AND pm.deleted_by_sender = {int:not_deleted}') . '
  1288. ' . $userQuery . $labelQuery . $timeQuery . '
  1289. AND (' . $searchQuery . ')
  1290. ORDER BY ' . $search_params['sort'] . ' ' . $search_params['sort_dir'] . '
  1291. LIMIT ' . $context['start'] . ', ' . $modSettings['search_results_per_page'],
  1292. array_merge($searchq_parameters, array(
  1293. 'current_member' => $user_info['id'],
  1294. 'not_deleted' => 0,
  1295. ))
  1296. );
  1297. $foundMessages = array();
  1298. $posters = array();
  1299. $head_pms = array();
  1300. while ($row = $smcFunc['db_fetch_assoc']($request))
  1301. {
  1302. $foundMessages[] = $row['id_pm'];
  1303. $posters[] = $row['id_member_from'];
  1304. $head_pms[$row['id_pm']] = $row['id_pm_head'];
  1305. }
  1306. $smcFunc['db_free_result']($request);
  1307. // Find the real head pms!
  1308. if ($context['display_mode'] == 2 && !empty($head_pms))
  1309. {
  1310. $request = $smcFunc['db_query']('', '
  1311. SELECT MAX(pm.id_pm) AS id_pm, pm.id_pm_head
  1312. FROM {db_prefix}personal_messages AS pm
  1313. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)
  1314. WHERE pm.id_pm_head IN ({array_int:head_pms})
  1315. AND pmr.id_member = {int:current_member}
  1316. AND pmr.deleted = {int:not_deleted}
  1317. GROUP BY pm.id_pm_head
  1318. LIMIT {int:limit}',
  1319. array(
  1320. 'head_pms' => array_unique($head_pms),
  1321. 'current_member' => $user_info['id'],
  1322. 'not_deleted' => 0,
  1323. 'limit' => count($head_pms),
  1324. )
  1325. );
  1326. $real_pm_ids = array();
  1327. while ($row = $smcFunc['db_fetch_assoc']($request))
  1328. $real_pm_ids[$row['id_pm_head']] = $row['id_pm'];
  1329. $smcFunc['db_free_result']($request);
  1330. }
  1331. // Load the users...
  1332. $posters = array_unique($posters);
  1333. if (!empty($posters))
  1334. loadMemberData($posters);
  1335. // Sort out the page index.
  1336. $context['page_index'] = constructPageIndex($scripturl . '?action=pm;sa=search2;params=' . $context['params'], $_GET['start'], $numResults, $modSettings['search_results_per_page'], false);
  1337. $context['message_labels'] = array();
  1338. $context['message_replied'] = array();
  1339. $context['personal_messages'] = array();
  1340. if (!empty($foundMessages))
  1341. {
  1342. // Now get recipients (but don't include bcc-recipients for your inbox, you're not supposed to know :P!)
  1343. $request = $smcFunc['db_query']('', '
  1344. SELECT
  1345. pmr.id_pm, mem_to.id_member AS id_member_to, mem_to.real_name AS to_name,
  1346. pmr.bcc, pmr.in_inbox, pmr.is_read
  1347. FROM {db_prefix}pm_recipients AS pmr
  1348. LEFT JOIN {db_prefix}members AS mem_to ON (mem_to.id_member = pmr.id_member)
  1349. WHERE pmr.id_pm IN ({array_int:message_list})',
  1350. array(
  1351. 'message_list' => $foundMessages,
  1352. )
  1353. );
  1354. while ($row = $smcFunc['db_fetch_assoc']($request))
  1355. {
  1356. if ($context['folder'] == 'sent' || empty($row['bcc']))
  1357. $recipients[$row['id_pm']][empty($row['bcc']) ? 'to' : 'bcc'][] = empty($row['id_member_to']) ? $txt['guest_title'] : '<a href="' . $scripturl . '?action=profile;u=' . $row['id_member_to'] . '">' . $row['to_name'] . '</a>';
  1358. if ($row['id_member_to'] == $user_info['id'] && $context['folder'] != 'sent')
  1359. {
  1360. $context['message_replied'][$row['id_pm']] = $row['is_read'] & 2;
  1361. $row['labels'] = '';
  1362. // Get the labels for this PM
  1363. $request2 = $smcFunc['db_query']('', '
  1364. SELECT id_label
  1365. FROM {db_prefix}pm_labeled_messages
  1366. WHERE id_pm = {int:current_pm}',
  1367. array(
  1368. 'current_pm' => $row['id_pm'],
  1369. )
  1370. );
  1371. while($row2 = $smcFunc['db_fetch_assoc']($request2))
  1372. {
  1373. $l_id = $row2['id_label'];
  1374. if (isset($context['labels'][$id_label]))
  1375. $context['message_labels'][$row['id_pm']][$l_id] = array('id' => $l_id, 'name' => $context['labels'][$l_id]['name']);
  1376. // Here we find the first label on a message - for linking to posts in results
  1377. if (!isset($context['first_label'][$row['id_pm']]) && $row['in_inbox'] != 1)
  1378. $context['first_label'][$row['id_pm']] = $l_id;
  1379. }
  1380. $smcFunc['db_free_result']($request2);
  1381. // Is this in the inbox as well?
  1382. if ($row['in_inbox'] == 1)
  1383. {
  1384. $context['message_labels'][$row['id_pm']][-1] = array('id' => -1, 'name' => $context['labels'][-1]['name']);
  1385. }
  1386. $row['labels'] = $row['labels'] == '' ? array() : explode(',', $row['labels']);
  1387. }
  1388. }
  1389. // Prepare the query for the callback!
  1390. $request = $smcFunc['db_query']('', '
  1391. SELECT pm.id_pm, pm.subject, pm.id_member_from, pm.body, pm.msgtime, pm.from_name
  1392. FROM {db_prefix}personal_messages AS pm
  1393. WHERE pm.id_pm IN ({array_int:message_list})
  1394. ORDER BY ' . $search_params['sort'] . ' ' . $search_params['sort_dir'] . '
  1395. LIMIT ' . count($foundMessages),
  1396. array(
  1397. 'message_list' => $foundMessages,
  1398. )
  1399. );
  1400. $counter = 0;
  1401. while ($row = $smcFunc['db_fetch_assoc']($request))
  1402. {
  1403. // If there's no message subject, use the default.
  1404. $row['subject'] = $row['subject'] == '' ? $txt['no_subject'] : $row['subject'];
  1405. // Load this posters context info, if it ain't there then fill in the essentials...
  1406. if (!loadMemberContext($row['id_member_from'], true))
  1407. {
  1408. $memberContext[$row['id_member_from']]['name'] = $row['from_name'];
  1409. $memberContext[$row['id_member_from']]['id'] = 0;
  1410. $memberContext[$row['id_member_from']]['group'] = $txt['guest_title'];
  1411. $memberContext[$row['id_member_from']]['link'] = $row['from_name'];
  1412. $memberContext[$row['id_member_from']]['email'] = '';
  1413. $memberContext[$row['id_member_from']]['show_email'] = showEmailAddress(true, 0);
  1414. $memberContext[$row['id_member_from']]['is_guest'] = true;
  1415. }
  1416. // Censor anything we don't want to see...
  1417. censorText($row['body']);
  1418. censorText($row['subject']);
  1419. // Parse out any BBC...
  1420. $row['body'] = parse_bbc($row['body'], true, 'pm' . $row['id_pm']);
  1421. $href = $scripturl . '?action=pm;f=' . $context['folder'] . (isset($context['first_label'][$row['id_pm']]) ? ';l=' . $context['first_label'][$row['id_pm']] : '') . ';pmid=' . ($context['display_mode'] == 2 && isset($real_pm_ids[$head_pms[$row['id_pm']]]) ? $real_pm_ids[$head_pms[$row['id_pm']]] : $row['id_pm']) . '#msg' . $row['id_pm'];
  1422. $context['personal_messages'][] = array(
  1423. 'id' => $row['id_pm'],
  1424. 'member' => &$memberContext[$row['id_member_from']],
  1425. 'subject' => $row['subject'],
  1426. 'body' => $row['body'],
  1427. 'time' => timeformat($row['msgtime']),
  1428. 'recipients' => &$recipients[$row['id_pm']],
  1429. 'labels' => &$context['message_labels'][$row['id_pm']],
  1430. 'fully_labeled' => count($context['message_labels'][$row['id_pm']]) == count($context['labels']),
  1431. 'is_replied_to' => &$context['message_replied'][$row['id_pm']],
  1432. 'href' => $href,
  1433. 'link' => '<a href="' . $href . '">' . $row['subject'] . '</a>',
  1434. 'counter' => ++$counter,
  1435. );
  1436. }
  1437. $smcFunc['db_free_result']($request);
  1438. }
  1439. // Finish off the context.
  1440. $context['page_title'] = $txt['pm_search_title'];
  1441. $context['sub_template'] = 'search_results';
  1442. $context['menu_data_' . $context['pm_menu_id']]['current_area'] = 'search';
  1443. $context['linktree'][] = array(
  1444. 'url' => $scripturl . '?action=pm;sa=search',
  1445. 'name' => $txt['pm_search_bar_title'],
  1446. );
  1447. }
  1448. /**
  1449. * Send a new message?
  1450. */
  1451. function MessagePost()
  1452. {
  1453. global $txt, $sourcedir, $scripturl, $modSettings;
  1454. global $context, $options, $smcFunc, $language, $user_info;
  1455. isAllowedTo('pm_send');
  1456. loadLanguage('PersonalMessage');
  1457. // Just in case it was loaded from somewhere else.
  1458. if (!WIRELESS)
  1459. {
  1460. loadTemplate('PersonalMessage');
  1461. $context['sub_template'] = 'send';
  1462. }
  1463. // Extract out the spam settings - cause it's neat.
  1464. list ($modSettings['max_pm_recipients'], $modSettings['pm_posts_verification'], $modSettings['pm_posts_per_hour']) = explode(',', $modSettings['pm_spam_settings']);
  1465. // Set the title...
  1466. $context['page_title'] = $txt['send_message'];
  1467. $context['reply'] = isset($_REQUEST['pmsg']) || isset($_REQUEST['quote']);
  1468. // Check whether we've gone over the limit of messages we can send per hour.
  1469. if (!empty($modSettings['pm_posts_per_hour']) && !allowedTo(array('admin_forum', 'moderate_forum', 'send_mail')) && $user_info['mod_cache']['bq'] == '0=1' && $user_info['mod_cache']['gq'] == '0=1')
  1470. {
  1471. // How many messages have they sent this last hour?
  1472. $request = $smcFunc['db_query']('', '
  1473. SELECT COUNT(pr.id_pm) AS post_count
  1474. FROM {db_prefix}personal_messages AS pm
  1475. INNER JOIN {db_prefix}pm_recipients AS pr ON (pr.id_pm = pm.id_pm)
  1476. WHERE pm.id_member_from = {int:current_member}
  1477. AND pm.msgtime > {int:msgtime}',
  1478. array(
  1479. 'current_member' => $user_info['id'],
  1480. 'msgtime' => time() - 3600,
  1481. )
  1482. );
  1483. list ($postCount) = $smcFunc['db_fetch_row']($request);
  1484. $smcFunc['db_free_result']($request);
  1485. if (!empty($postCount) && $postCount >= $modSettings['pm_posts_per_hour'])
  1486. fatal_lang_error('pm_too_many_per_hour', true, array($modSettings['pm_posts_per_hour']));
  1487. }
  1488. // Quoting/Replying to a message?
  1489. if (!empty($_REQUEST['pmsg']))
  1490. {
  1491. $pmsg = (int) $_REQUEST['pmsg'];
  1492. // Make sure this is yours.
  1493. if (!isAccessiblePM($pmsg))
  1494. fatal_lang_error('no_access', false);
  1495. // Work out whether this is one you've received?
  1496. $request = $smcFunc['db_query']('', '
  1497. SELECT
  1498. id_pm
  1499. FROM {db_prefix}pm_recipients
  1500. WHERE id_pm = {int:id_pm}
  1501. AND id_member = {int:current_member}
  1502. LIMIT 1',
  1503. array(
  1504. 'current_member' => $user_info['id'],
  1505. 'id_pm' => $pmsg,
  1506. )
  1507. );
  1508. $isReceived = $smcFunc['db_num_rows']($request) != 0;
  1509. $smcFunc['db_free_result']($request);
  1510. // Get the quoted message (and make sure you're allowed to see this quote!).
  1511. $request = $smcFunc['db_query']('', '
  1512. SELECT
  1513. pm.id_pm, CASE WHEN pm.id_pm_head = {int:id_pm_head_empty} THEN pm.id_pm ELSE pm.id_pm_head END AS pm_head,
  1514. pm.body, pm.subject, pm.msgtime, mem.member_name, IFNULL(mem.id_member, 0) AS id_member,
  1515. IFNULL(mem.real_name, pm.from_name) AS real_name
  1516. FROM {db_prefix}personal_messages AS pm' . (!$isReceived ? '' : '
  1517. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = {int:id_pm})') . '
  1518. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  1519. WHERE pm.id_pm = {int:id_pm}' . (!$isReceived ? '
  1520. AND pm.id_member_from = {int:current_member}' : '
  1521. AND pmr.id_member = {int:current_member}') . '
  1522. LIMIT 1',
  1523. array(
  1524. 'current_member' => $user_info['id'],
  1525. 'id_pm_head_empty' => 0,
  1526. 'id_pm' => $pmsg,
  1527. )
  1528. );
  1529. if ($smcFunc['db_num_rows']($request) == 0)
  1530. fatal_lang_error('pm_not_yours', false);
  1531. $row_quoted = $smcFunc['db_fetch_assoc']($request);
  1532. $smcFunc['db_free_result']($request);
  1533. // Censor the message.
  1534. censorText($row_quoted['subject']);
  1535. censorText($row_quoted['body']);
  1536. // Add 'Re: ' to it....
  1537. if (!isset($context['response_prefix']) && !($context['response_prefix'] = cache_get_data('response_prefix')))
  1538. {
  1539. if ($language === $user_info['language'])
  1540. $context['response_prefix'] = $txt['response_prefix'];
  1541. else
  1542. {
  1543. loadLanguage('index', $language, false);
  1544. $context['response_prefix'] = $txt['response_prefix'];
  1545. loadLanguage('index');
  1546. }
  1547. cache_put_data('response_prefix', $context['response_prefix'], 600);
  1548. }
  1549. $form_subject = $row_quoted['subject'];
  1550. if ($context['reply'] && trim($context['response_prefix']) != '' && $smcFunc['strpos']($form_subject, trim($context['response_prefix'])) !== 0)
  1551. $form_subject = $context['response_prefix'] . $form_subject;
  1552. if (isset($_REQUEST['quote']))
  1553. {
  1554. // Remove any nested quotes and <br />...
  1555. $form_message = preg_replace('~<br ?/?' . '>~i', "\n", $row_quoted['body']);
  1556. if (!empty($modSettings['removeNestedQuotes']))
  1557. $form_message = preg_replace(array('~\n?\[quote.*?\].+?\[/quote\]\n?~is', '~^\n~', '~\[/quote\]~'), '', $form_message);
  1558. if (empty($row_quoted['id_member']))
  1559. $form_message = '[quote author=&quot;' . $row_quoted['real_name'] . '&quot;]' . "\n" . $form_message . "\n" . '[/quote]';
  1560. else
  1561. $form_message = '[quote author=' . $row_quoted['real_name'] . ' link=action=profile;u=' . $row_quoted['id_member'] . ' date=' . $row_quoted['msgtime'] . ']' . "\n" . $form_message . "\n" . '[/quote]';
  1562. }
  1563. else
  1564. $form_message = '';
  1565. // Do the BBC thang on the message.
  1566. $row_quoted['body'] = parse_bbc($row_quoted['body'], true, 'pm' . $row_quoted['id_pm']);
  1567. // Set up the quoted message array.
  1568. $context['quoted_message'] = array(
  1569. 'id' => $row_quoted['id_pm'],
  1570. 'pm_head' => $row_quoted['pm_head'],
  1571. 'member' => array(
  1572. 'name' => $row_quoted['real_name'],
  1573. 'username' => $row_quoted['member_name'],
  1574. 'id' => $row_quoted['id_member'],
  1575. 'href' => !empty($row_quoted['id_member']) ? $scripturl . '?action=profile;u=' . $row_quoted['id_member'] : '',
  1576. 'link' => !empty($row_quoted['id_member']) ? '<a href="' . $scripturl . '?action=profile;u=' . $row_quoted['id_member'] . '">' . $row_quoted['real_name'] . '</a>' : $row_quoted['real_name'],
  1577. ),
  1578. 'subject' => $row_quoted['subject'],
  1579. 'time' => timeformat($row_quoted['msgtime']),
  1580. 'timestamp' => forum_time(true, $row_quoted['msgtime']),
  1581. 'body' => $row_quoted['body']
  1582. );
  1583. }
  1584. else
  1585. {
  1586. $context['quoted_message'] = false;
  1587. $form_subject = '';
  1588. $form_message = '';
  1589. }
  1590. $context['recipients'] = array(
  1591. 'to' => array(),
  1592. 'bcc' => array(),
  1593. );
  1594. // Sending by ID? Replying to all? Fetch the real_name(s).
  1595. if (isset($_REQUEST['u']))
  1596. {
  1597. // If the user is replying to all, get all the other members this was sent to..
  1598. if ($_REQUEST['u'] == 'all' && isset($row_quoted))
  1599. {
  1600. // Firstly, to reply to all we clearly already have $row_quoted - so have the original member from.
  1601. if ($row_quoted['id_member'] != $user_info['id'])
  1602. $context['recipients']['to'][] = array(
  1603. 'id' => $row_quoted['id_member'],
  1604. 'name' => $smcFunc['htmlspecialchars']($row_quoted['real_name']),
  1605. );
  1606. // Now to get the others.
  1607. $request = $smcFunc['db_query']('', '
  1608. SELECT mem.id_member, mem.real_name
  1609. FROM {db_prefix}pm_recipients AS pmr
  1610. INNER JOIN {db_prefix}members AS mem ON (mem.id_member = pmr.id_member)
  1611. WHERE pmr.id_pm = {int:id_pm}
  1612. AND pmr.id_member != {int:current_member}
  1613. AND pmr.bcc = {int:not_bcc}',
  1614. array(
  1615. 'current_member' => $user_info['id'],
  1616. 'id_pm' => $pmsg,
  1617. 'not_bcc' => 0,
  1618. )
  1619. );
  1620. while ($row = $smcFunc['db_fetch_assoc']($request))
  1621. $context['recipients']['to'][] = array(
  1622. 'id' => $row['id_member'],
  1623. 'name' => $row['real_name'],
  1624. );
  1625. $smcFunc['db_free_result']($request);
  1626. }
  1627. else
  1628. {
  1629. $_REQUEST['u'] = explode(',', $_REQUEST['u']);
  1630. foreach ($_REQUEST['u'] as $key => $uID)
  1631. $_REQUEST['u'][$key] = (int) $uID;
  1632. $_REQUEST['u'] = array_unique($_REQUEST['u']);
  1633. $request = $smcFunc['db_query']('', '
  1634. SELECT id_member, real_name
  1635. FROM {db_prefix}members
  1636. WHERE id_member IN ({array_int:member_list})
  1637. LIMIT ' . count($_REQUEST['u']),
  1638. array(
  1639. 'member_list' => $_REQUEST['u'],
  1640. )
  1641. );
  1642. while ($row = $smcFunc['db_fetch_assoc']($request))
  1643. $context['recipients']['to'][] = array(
  1644. 'id' => $row['id_member'],
  1645. 'name' => $row['real_name'],
  1646. );
  1647. $smcFunc['db_free_result']($request);
  1648. }
  1649. // Get a literal name list in case the user has JavaScript disabled.
  1650. $names = array();
  1651. foreach ($context['recipients']['to'] as $to)
  1652. $names[] = $to['name'];
  1653. $context['to_value'] = empty($names) ? '' : '&quot;' . implode('&quot;, &quot;', $names) . '&quot;';
  1654. }
  1655. else
  1656. $context['to_value'] = '';
  1657. // Set the defaults...
  1658. $context['subject'] = $form_subject;
  1659. $context['message'] = str_replace(array('"', '<', '>', '&nbsp;'), array('&quot;', '&lt;', '&gt;', ' '), $form_message);
  1660. $context['post_error'] = array();
  1661. // And build the link tree.
  1662. $context['linktree'][] = array(
  1663. 'url' => $scripturl . '?action=pm;sa=send',
  1664. 'name' => $txt['new_message']
  1665. );
  1666. $modSettings['disable_wysiwyg'] = !empty($modSettings['disable_wysiwyg']) || empty($modSettings['enableBBC']);
  1667. // Generate a list of drafts that they can load in to the editor
  1668. if (!empty($context['drafts_pm_save']))
  1669. {
  1670. require_once($sourcedir . '/Drafts.php');
  1671. $pm_seed = isset($_REQUEST['pmsg']) ? $_REQUEST['pmsg'] : (isset($_REQUEST['quote']) ? $_REQUEST['quote'] : 0);
  1672. ShowDrafts($user_info['id'], $pm_seed, 1);
  1673. }
  1674. // Needed for the WYSIWYG editor.
  1675. require_once($sourcedir . '/Subs-Editor.php');
  1676. // Now create the editor.
  1677. $editorOptions = array(
  1678. 'id' => 'message',
  1679. 'value' => $context['message'],
  1680. 'height' => '250px',
  1681. 'width' => '100%',
  1682. 'labels' => array(
  1683. 'post_button' => $txt['send_message'],
  1684. ),
  1685. 'preview_type' => 2,
  1686. );
  1687. create_control_richedit($editorOptions);
  1688. // Store the ID for old compatibility.
  1689. $context['post_box_name'] = $editorOptions['id'];
  1690. $context['bcc_value'] = '';
  1691. $context['require_verification'] = !$user_info['is_admin'] && !empty($modSettings['pm_posts_verification']) && $user_info['posts'] < $modSettings['pm_posts_verification'];
  1692. if ($context['require_verification'])
  1693. {
  1694. $verificationOptions = array(
  1695. 'id' => 'pm',
  1696. );
  1697. $context['require_verification'] = create_control_verification($verificationOptions);
  1698. $context['visual_verification_id'] = $verificationOptions['id'];
  1699. }
  1700. // Register this form and get a sequence number in $context.
  1701. checkSubmitOnce('register');
  1702. }
  1703. /**
  1704. * This function allows the user to view their PM drafts
  1705. */
  1706. function MessageDrafts()
  1707. {
  1708. global $sourcedir, $user_info;
  1709. // validate with loadMemberData()
  1710. $memberResult = loadMemberData($user_info['id'], false);
  1711. if (!is_array($memberResult))
  1712. fatal_lang_error('not_a_user', false);
  1713. list ($memID) = $memberResult;
  1714. // drafts is where the functions reside
  1715. require_once($sourcedir . '/Drafts.php');
  1716. showPMDrafts($memID);
  1717. }
  1718. /**
  1719. * An error in the message...
  1720. *
  1721. * @param $error_types
  1722. * @param $named_recipients
  1723. * @param $recipient_ids
  1724. */
  1725. function messagePostError($error_types, $named_recipients, $recipient_ids = array())
  1726. {
  1727. global $txt, $context, $scripturl, $modSettings;
  1728. global $smcFunc, $user_info, $sourcedir;
  1729. if (!isset($_REQUEST['xml']))
  1730. $context['menu_data_' . $context['pm_menu_id']]['current_area'] = 'send';
  1731. if (!WIRELESS && !isset($_REQUEST['xml']))
  1732. $context['sub_template'] = 'send';
  1733. elseif (isset($_REQUEST['xml']))
  1734. $context['sub_template'] = 'pm';
  1735. $context['page_title'] = $txt['send_message'];
  1736. // Got some known members?
  1737. $context['recipients'] = array(
  1738. 'to' => array(),
  1739. 'bcc' => array(),
  1740. );
  1741. if (!empty($recipient_ids['to']) || !empty($recipient_ids['bcc']))
  1742. {
  1743. $allRecipients = array_merge($recipient_ids['to'], $recipient_ids['bcc']);
  1744. $request = $smcFunc['db_query']('', '
  1745. SELECT id_member, real_name
  1746. FROM {db_prefix}members
  1747. WHERE id_member IN ({array_int:member_list})',
  1748. array(
  1749. 'member_list' => $allRecipients,
  1750. )
  1751. );
  1752. while ($row = $smcFunc['db_fetch_assoc']($request))
  1753. {
  1754. $recipientType = in_array($row['id_member'], $recipient_ids['bcc']) ? 'bcc' : 'to';
  1755. $context['recipients'][$recipientType][] = array(
  1756. 'id' => $row['id_member'],
  1757. 'name' => $row['real_name'],
  1758. );
  1759. }
  1760. $smcFunc['db_free_result']($request);
  1761. }
  1762. // Set everything up like before....
  1763. $context['subject'] = isset($_REQUEST['subject']) ? $smcFunc['htmlspecialchars']($_REQUEST['subject']) : '';
  1764. $context['message'] = isset($_REQUEST['message']) ? str_replace(array(' '), array('&nbsp; '), $smcFunc['htmlspecialchars']($_REQUEST['message'])) : '';
  1765. $context['reply'] = !empty($_REQUEST['replied_to']);
  1766. if ($context['reply'])
  1767. {
  1768. $_REQUEST['replied_to'] = (int) $_REQUEST['replied_to'];
  1769. $request = $smcFunc['db_query']('', '
  1770. SELECT
  1771. pm.id_pm, CASE WHEN pm.id_pm_head = {int:no_id_pm_head} THEN pm.id_pm ELSE pm.id_pm_head END AS pm_head,
  1772. pm.body, pm.subject, pm.msgtime, mem.member_name, IFNULL(mem.id_member, 0) AS id_member,
  1773. IFNULL(mem.real_name, pm.from_name) AS real_name
  1774. FROM {db_prefix}personal_messages AS pm' . ($context['folder'] == 'sent' ? '' : '
  1775. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = {int:replied_to})') . '
  1776. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  1777. WHERE pm.id_pm = {int:replied_to}' . ($context['folder'] == 'sent' ? '
  1778. AND pm.id_member_from = {int:current_member}' : '
  1779. AND pmr.id_member = {int:current_member}') . '
  1780. LIMIT 1',
  1781. array(
  1782. 'current_member' => $user_info['id'],
  1783. 'no_id_pm_head' => 0,
  1784. 'replied_to' => $_REQUEST['replied_to'],
  1785. )
  1786. );
  1787. if ($smcFunc['db_num_rows']($request) == 0)
  1788. {
  1789. if (!isset($_REQUEST['xml']))
  1790. fatal_lang_error('pm_not_yours', false);
  1791. else
  1792. $error_types[] = 'pm_not_yours';
  1793. }
  1794. $row_quoted = $smcFunc['db_fetch_assoc']($request);
  1795. $smcFunc['db_free_result']($request);
  1796. censorText($row_quoted['subject']);
  1797. censorText($row_quoted['body']);
  1798. $context['quoted_message'] = array(
  1799. 'id' => $row_quoted['id_pm'],
  1800. 'pm_head' => $row_quoted['pm_head'],
  1801. 'member' => array(
  1802. 'name' => $row_quoted['real_name'],
  1803. 'username' => $row_quoted['member_name'],
  1804. 'id' => $row_quoted['id_member'],
  1805. 'href' => !empty($row_quoted['id_member']) ? $scripturl . '?action=profile;u=' . $row_quoted['id_member'] : '',
  1806. 'link' => !empty($row_quoted['id_member']) ? '<a href="' . $scripturl . '?action=profile;u=' . $row_quoted['id_member'] . '">' . $row_quoted['real_name'] . '</a>' : $row_quoted['real_name'],
  1807. ),
  1808. 'subject' => $row_quoted['subject'],
  1809. 'time' => timeformat($row_quoted['msgtime']),
  1810. 'timestamp' => forum_time(true, $row_quoted['msgtime']),
  1811. 'body' => parse_bbc($row_quoted['body'], true, 'pm' . $row_quoted['id_pm']),
  1812. );
  1813. }
  1814. // Build the link tree....
  1815. $context['linktree'][] = array(
  1816. 'url' => $scripturl . '?action=pm;sa=send',
  1817. 'name' => $txt['new_message']
  1818. );
  1819. // Set each of the errors for the template.
  1820. loadLanguage('Errors');
  1821. $context['error_type'] = 'minor';
  1822. $context['post_error'] = array(
  1823. 'messages' => array(),
  1824. // @todo error handling: maybe fatal errors can be error_type => serious
  1825. 'error_type' => '',
  1826. );
  1827. foreach ($error_types as $error_type)
  1828. {
  1829. $context['post_error'][$error_type] = true;
  1830. if (isset($txt['error_' . $error_type]))
  1831. {
  1832. if ($error_type == 'long_message')
  1833. $txt['error_' . $error_type] = sprintf($txt['error_' . $error_type], $modSettings['max_messageLength']);
  1834. $context['post_error']['messages'][] = $txt['error_' . $error_type];
  1835. }
  1836. // If it's not a minor error flag it as such.
  1837. if (!in_array($error_type, array('new_reply', 'not_approved', 'new_replies', 'old_topic', 'need_qr_verification', 'no_subject')))
  1838. $context['error_type'] = 'serious';
  1839. }
  1840. // We need to load the editor once more.
  1841. require_once($sourcedir . '/Subs-Editor.php');
  1842. // Create it...
  1843. $editorOptions = array(
  1844. 'id' => 'message',
  1845. 'value' => $context['message'],
  1846. 'width' => '90%',
  1847. 'height' => '250px',
  1848. 'labels' => array(
  1849. 'post_button' => $txt['send_message'],
  1850. ),
  1851. 'preview_type' => 2,
  1852. );
  1853. create_control_richedit($editorOptions);
  1854. // ... and store the ID again...
  1855. $context['post_box_name'] = $editorOptions['id'];
  1856. // Check whether we need to show the code again.
  1857. $context['require_verification'] = !$user_info['is_admin'] && !empty($modSettings['pm_posts_verification']) && $user_info['posts'] < $modSettings['pm_posts_verification'];
  1858. if ($context['require_verification'] && !isset($_REQUEST['xml']))
  1859. {
  1860. require_once($sourcedir . '/Subs-Editor.php');
  1861. $verificationOptions = array(
  1862. 'id' => 'pm',
  1863. );
  1864. $context['require_verification'] = create_control_verification($verificationOptions);
  1865. $context['visual_verification_id'] = $verificationOptions['id'];
  1866. }
  1867. $context['to_value'] = empty($named_recipients['to']) ? '' : '&quot;' . implode('&quot;, &quot;', $named_recipients['to']) . '&quot;';
  1868. $context['bcc_value'] = empty($named_recipients['bcc']) ? '' : '&quot;' . implode('&quot;, &quot;', $named_recipients['bcc']) . '&quot;';
  1869. // No check for the previous submission is needed.
  1870. checkSubmitOnce('free');
  1871. // Acquire a new form sequence number.
  1872. checkSubmitOnce('register');
  1873. }
  1874. /**
  1875. * Send it!
  1876. */
  1877. function MessagePost2()
  1878. {
  1879. global $txt, $context, $sourcedir;
  1880. global $user_info, $modSettings, $scripturl, $smcFunc;
  1881. isAllowedTo('pm_send');
  1882. require_once($sourcedir . '/Subs-Auth.php');
  1883. // PM Drafts enabled and needed?
  1884. if ($context['drafts_pm_save'] && (isset($_POST['save_draft']) || isset($_POST['id_pm_draft'])))
  1885. require_once($sourcedir . '/Drafts.php');
  1886. loadLanguage('PersonalMessage', '', false);
  1887. // Extract out the spam settings - it saves database space!
  1888. list ($modSettings['max_pm_recipients'], $modSettings['pm_posts_verification'], $modSettings['pm_posts_per_hour']) = explode(',', $modSettings['pm_spam_settings']);
  1889. // Initialize the errors we're about to make.
  1890. $post_errors = array();
  1891. // Check whether we've gone over the limit of messages we can send per hour - fatal error if fails!
  1892. if (!empty($modSettings['pm_posts_per_hour']) && !allowedTo(array('admin_forum', 'moderate_forum', 'send_mail')) && $user_info['mod_cache']['bq'] == '0=1' && $user_info['mod_cache']['gq'] == '0=1')
  1893. {
  1894. // How many have they sent this last hour?
  1895. $request = $smcFunc['db_query']('', '
  1896. SELECT COUNT(pr.id_pm) AS post_count
  1897. FROM {db_prefix}personal_messages AS pm
  1898. INNER JOIN {db_prefix}pm_recipients AS pr ON (pr.id_pm = pm.id_pm)
  1899. WHERE pm.id_member_from = {int:current_member}
  1900. AND pm.msgtime > {int:msgtime}',
  1901. array(
  1902. 'current_member' => $user_info['id'],
  1903. 'msgtime' => time() - 3600,
  1904. )
  1905. );
  1906. list ($postCount) = $smcFunc['db_fetch_row']($request);
  1907. $smcFunc['db_free_result']($request);
  1908. if (!empty($postCount) && $postCount >= $modSettings['pm_posts_per_hour'])
  1909. {
  1910. if (!isset($_REQUEST['xml']))
  1911. fatal_lang_error('pm_too_many_per_hour', true, array($modSettings['pm_posts_per_hour']));
  1912. else
  1913. $post_errors[] = 'pm_too_many_per_hour';
  1914. }
  1915. }
  1916. // If your session timed out, show an error, but do allow to re-submit.
  1917. if (!isset($_REQUEST['xml']) && checkSession('post', '', false) != '')
  1918. $post_errors[] = 'session_timeout';
  1919. $_REQUEST['subject'] = isset($_REQUEST['subject']) ? trim($_REQUEST['subject']) : '';
  1920. $_REQUEST['to'] = empty($_POST['to']) ? (empty($_GET['to']) ? '' : $_GET['to']) : $_POST['to'];
  1921. $_REQUEST['bcc'] = empty($_POST['bcc']) ? (empty($_GET['bcc']) ? '' : $_GET['bcc']) : $_POST['bcc'];
  1922. // Route the input from the 'u' parameter to the 'to'-list.
  1923. if (!empty($_POST['u']))
  1924. $_POST['recipient_to'] = explode(',', $_POST['u']);
  1925. // Construct the list of recipients.
  1926. $recipientList = array();
  1927. $namedRecipientList = array();
  1928. $namesNotFound = array();
  1929. foreach (array('to', 'bcc') as $recipientType)
  1930. {
  1931. // First, let's see if there's user ID's given.
  1932. $recipientList[$recipientType] = array();
  1933. if (!empty($_POST['recipient_' . $recipientType]) && is_array($_POST['recipient_' . $recipientType]))
  1934. {
  1935. foreach ($_POST['recipient_' . $recipientType] as $recipient)
  1936. $recipientList[$recipientType][] = (int) $recipient;
  1937. }
  1938. // Are there also literal names set?
  1939. if (!empty($_REQUEST[$recipientType]))
  1940. {
  1941. // We're going to take out the "s anyway ;).
  1942. $recipientString = strtr($_REQUEST[$recipientType], array('\\"' => '"'));
  1943. preg_match_all('~"([^"]+)"~', $recipientString, $matches);
  1944. $namedRecipientList[$recipientType] = array_unique(array_merge($matches[1], explode(',', preg_replace('~"[^"]+"~', '', $recipientString))));
  1945. foreach ($namedRecipientList[$recipientType] as $index => $recipient)
  1946. {
  1947. if (strlen(trim($recipient)) > 0)
  1948. $namedRecipientList[$recipientType][$index] = $smcFunc['htmlspecialchars']($smcFunc['strtolower'](trim($recipient)));
  1949. else
  1950. unset($namedRecipientList[$recipientType][$index]);
  1951. }
  1952. if (!empty($namedRecipientList[$recipientType]))
  1953. {
  1954. $foundMembers = findMembers($namedRecipientList[$recipientType]);
  1955. // Assume all are not found, until proven otherwise.
  1956. $namesNotFound[$recipientType] = $namedRecipientList[$recipientType];
  1957. foreach ($foundMembers as $member)
  1958. {
  1959. $testNames = array(
  1960. $smcFunc['strtolower']($member['username']),
  1961. $smcFunc['strtolower']($member['name']),
  1962. $smcFunc['strtolower']($member['email']),
  1963. );
  1964. if (count(array_intersect($testNames, $namedRecipientList[$recipientType])) !== 0)
  1965. {
  1966. $recipientList[$recipientType][] = $member['id'];
  1967. // Get rid of this username, since we found it.
  1968. $namesNotFound[$recipientType] = array_diff($namesNotFound[$recipientType], $testNames);
  1969. }
  1970. }
  1971. }
  1972. }
  1973. // Selected a recipient to be deleted? Remove them now.
  1974. if (!empty($_POST['delete_recipient']))
  1975. $recipientList[$recipientType] = array_diff($recipientList[$recipientType], array((int) $_POST['delete_recipient']));
  1976. // Make sure we don't include the same name twice
  1977. $recipientList[$recipientType] = array_unique($recipientList[$recipientType]);
  1978. }
  1979. // Are we changing the recipients some how?
  1980. $is_recipient_change = !empty($_POST['delete_recipient']) || !empty($_POST['to_submit']) || !empty($_POST['bcc_submit']);
  1981. // Check if there's at least one recipient.
  1982. if (empty($recipientList['to']) && empty($recipientList['bcc']))
  1983. $post_errors[] = 'no_to';
  1984. // Make sure that we remove the members who did get it from the screen.
  1985. if (!$is_recipient_change)
  1986. {
  1987. foreach ($recipientList as $recipientType => $dummy)
  1988. {
  1989. if (!empty($namesNotFound[$recipientType]))
  1990. {
  1991. $post_errors[] = 'bad_' . $recipientType;
  1992. // Since we already have a post error, remove the previous one.
  1993. $post_errors = array_diff($post_errors, array('no_to'));
  1994. foreach ($namesNotFound[$recipientType] as $name)
  1995. $context['send_log']['failed'][] = sprintf($txt['pm_error_user_not_found'], $name);
  1996. }
  1997. }
  1998. }
  1999. // Did they make any mistakes?
  2000. if ($_REQUEST['subject'] == '')
  2001. $post_errors[] = 'no_subject';
  2002. if (!isset($_REQUEST['message']) || $_REQUEST['message'] == '')
  2003. $post_errors[] = 'no_message';
  2004. elseif (!empty($modSettings['max_messageLength']) && $smcFunc['strlen']($_REQUEST['message']) > $modSettings['max_messageLength'])
  2005. $post_errors[] = 'long_message';
  2006. else
  2007. {
  2008. // Preparse the message.
  2009. $message = $_REQUEST['message'];
  2010. preparsecode($message);
  2011. // Make sure there's still some content left without the tags.
  2012. if ($smcFunc['htmltrim'](strip_tags(parse_bbc($smcFunc['htmlspecialchars']($message, ENT_QUOTES), false), '<img>')) === '' && (!allowedTo('admin_forum') || strpos($message, '[html]') === false))
  2013. $post_errors[] = 'no_message';
  2014. }
  2015. // Wrong verification code?
  2016. if (!$user_info['is_admin'] && !isset($_REQUEST['xml']) && !empty($modSettings['pm_posts_verification']) && $user_info['posts'] < $modSettings['pm_posts_verification'])
  2017. {
  2018. require_once($sourcedir . '/Subs-Editor.php');
  2019. $verificationOptions = array(
  2020. 'id' => 'pm',
  2021. );
  2022. $context['require_verification'] = create_control_verification($verificationOptions, true);
  2023. if (is_array($context['require_verification']))
  2024. $post_errors = array_merge($post_errors, $context['require_verification']);
  2025. }
  2026. // If they did, give a chance to make ammends.
  2027. if (!empty($post_errors) && !$is_recipient_change && !isset($_REQUEST['preview']) && !isset($_REQUEST['xml']))
  2028. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2029. // Want to take a second glance before you send?
  2030. if (isset($_REQUEST['preview']))
  2031. {
  2032. // Set everything up to be displayed.
  2033. $context['preview_subject'] = $smcFunc['htmlspecialchars']($_REQUEST['subject']);
  2034. $context['preview_message'] = $smcFunc['htmlspecialchars']($_REQUEST['message'], ENT_QUOTES);
  2035. preparsecode($context['preview_message'], true);
  2036. // Parse out the BBC if it is enabled.
  2037. $context['preview_message'] = parse_bbc($context['preview_message']);
  2038. // Censor, as always.
  2039. censorText($context['preview_subject']);
  2040. censorText($context['preview_message']);
  2041. // Set a descriptive title.
  2042. $context['page_title'] = $txt['preview'] . ' - ' . $context['preview_subject'];
  2043. // Pretend they messed up but don't ignore if they really did :P.
  2044. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2045. }
  2046. // Adding a recipient cause javascript ain't working?
  2047. elseif ($is_recipient_change)
  2048. {
  2049. // Maybe we couldn't find one?
  2050. foreach ($namesNotFound as $recipientType => $names)
  2051. {
  2052. $post_errors[] = 'bad_' . $recipientType;
  2053. foreach ($names as $name)
  2054. $context['send_log']['failed'][] = sprintf($txt['pm_error_user_not_found'], $name);
  2055. }
  2056. return messagePostError(array(), $namedRecipientList, $recipientList);
  2057. }
  2058. // Want to save this as a draft and think about it some more?
  2059. if ($context['drafts_pm_save'] && isset($_POST['save_draft']))
  2060. {
  2061. SavePMDraft($post_errors, $recipientList);
  2062. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2063. }
  2064. // Before we send the PM, let's make sure we don't have an abuse of numbers.
  2065. elseif (!empty($modSettings['max_pm_recipients']) && count($recipientList['to']) + count($recipientList['bcc']) > $modSettings['max_pm_recipients'] && !allowedTo(array('moderate_forum', 'send_mail', 'admin_forum')))
  2066. {
  2067. $context['send_log'] = array(
  2068. 'sent' => array(),
  2069. 'failed' => array(sprintf($txt['pm_too_many_recipients'], $modSettings['max_pm_recipients'])),
  2070. );
  2071. return messagePostError($post_errors, $namedRecipientList, $recipientList);
  2072. }
  2073. // Protect from message spamming.
  2074. spamProtection('pm');
  2075. // Prevent double submission of this form.
  2076. checkSubmitOnce('check');
  2077. // Do the actual sending of the PM.
  2078. if (!empty($recipientList['to']) || !empty($recipientList['bcc']))
  2079. $context['send_log'] = sendpm($recipientList, $_REQUEST['subject'], $_REQUEST['message'], true, null, !empty($_REQUEST['pm_head']) ? (int) $_REQUEST['pm_head'] : 0);
  2080. else
  2081. $context['send_log'] = array(
  2082. 'sent' => array(),
  2083. 'failed' => array()
  2084. );
  2085. // Mark the message as "replied to".
  2086. if (!empty($context['send_log']['sent']) && !empty($_REQUEST['replied_to']) && isset($_REQUEST['f']) && $_REQUEST['f'] == 'inbox')
  2087. {
  2088. $smcFunc['db_query']('', '
  2089. UPDATE {db_prefix}pm_recipients
  2090. SET is_read = is_read | 2
  2091. WHERE id_pm = {int:replied_to}
  2092. AND id_member = {int:current_member}',
  2093. array(
  2094. 'current_member' => $user_info['id'],
  2095. 'replied_to' => (int) $_REQUEST['replied_to'],
  2096. )
  2097. );
  2098. }
  2099. // If one or more of the recipient were invalid, go back to the post screen with the failed usernames.
  2100. if (!empty($context['send_log']['failed']))
  2101. return messagePostError($post_errors, $namesNotFound, array(
  2102. 'to' => array_intersect($recipientList['to'], $context['send_log']['failed']),
  2103. 'bcc' => array_intersect($recipientList['bcc'], $context['send_log']['failed'])
  2104. ));
  2105. // Message sent successfully?
  2106. if (!empty($context['send_log']) && empty($context['send_log']['failed']))
  2107. {
  2108. $context['current_label_redirect'] = $context['current_label_redirect'] . ';done=sent';
  2109. // If we had a PM draft for this one, then its time to remove it since it was just sent
  2110. if ($context['drafts_pm_save'] && !empty($_POST['id_pm_draft']))
  2111. DeleteDraft($_POST['id_pm_draft']);
  2112. }
  2113. // Go back to the where they sent from, if possible...
  2114. redirectexit($context['current_label_redirect']);
  2115. }
  2116. /**
  2117. * This function lists all buddies for wireless protocols.
  2118. */
  2119. function WirelessAddBuddy()
  2120. {
  2121. global $scripturl, $txt, $user_info, $context, $smcFunc;
  2122. isAllowedTo('pm_send');
  2123. $context['page_title'] = $txt['wireless_pm_add_buddy'];
  2124. $current_buddies = empty($_REQUEST['u']) ? array() : explode(',', $_REQUEST['u']);
  2125. foreach ($current_buddies as $key => $buddy)
  2126. $current_buddies[$key] = (int) $buddy;
  2127. $base_url = $scripturl . '?action=pm;sa=send;u=' . (empty($current_buddies) ? '' : implode(',', $current_buddies) . ',');
  2128. $context['pm_href'] = $scripturl . '?action=pm;sa=send' . (empty($current_buddies) ? '' : ';u=' . implode(',', $current_buddies));
  2129. $context['buddies'] = array();
  2130. if (!empty($user_info['buddies']))
  2131. {
  2132. $request = $smcFunc['db_query']('', '
  2133. SELECT id_member, real_name
  2134. FROM {db_prefix}members
  2135. WHERE id_member IN ({array_int:buddy_list})
  2136. ORDER BY real_name
  2137. LIMIT ' . count($user_info['buddies']),
  2138. array(
  2139. 'buddy_list' => $user_info['buddies'],
  2140. )
  2141. );
  2142. while ($row = $smcFunc['db_fetch_assoc']($request))
  2143. $context['buddies'][] = array(
  2144. 'id' => $row['id_member'],
  2145. 'name' => $row['real_name'],
  2146. 'selected' => in_array($row['id_member'], $current_buddies),
  2147. 'add_href' => $base_url . $row['id_member'],
  2148. );
  2149. $smcFunc['db_free_result']($request);
  2150. }
  2151. }
  2152. /**
  2153. * This function performs all additional stuff...
  2154. */
  2155. function MessageActionsApply()
  2156. {
  2157. global $txt, $context, $user_info, $options, $smcFunc;
  2158. checkSession('request');
  2159. if (isset($_REQUEST['del_selected']))
  2160. $_REQUEST['pm_action'] = 'delete';
  2161. if (isset($_REQUEST['pm_action']) && $_REQUEST['pm_action'] != '' && !empty($_REQUEST['pms']) && is_array($_REQUEST['pms']))
  2162. {
  2163. foreach ($_REQUEST['pms'] as $pm)
  2164. $_REQUEST['pm_actions'][(int) $pm] = $_REQUEST['pm_action'];
  2165. }
  2166. if (empty($_REQUEST['pm_actions']))
  2167. redirectexit($context['current_label_redirect']);
  2168. // If we are in conversation, we may need to apply this to every message in the conversation.
  2169. if ($context['display_mode'] == 2 && isset($_REQUEST['conversation']))
  2170. {
  2171. $id_pms = array();
  2172. foreach ($_REQUEST['pm_actions'] as $pm => $dummy)
  2173. $id_pms[] = (int) $pm;
  2174. $request = $smcFunc['db_query']('', '
  2175. SELECT id_pm_head, id_pm
  2176. FROM {db_prefix}personal_messages
  2177. WHERE id_pm IN ({array_int:id_pms})',
  2178. array(
  2179. 'id_pms' => $id_pms,
  2180. )
  2181. );
  2182. $pm_heads = array();
  2183. while ($row = $smcFunc['db_fetch_assoc']($request))
  2184. $pm_heads[$row['id_pm_head']] = $row['id_pm'];
  2185. $smcFunc['db_free_result']($request);
  2186. $request = $smcFunc['db_query']('', '
  2187. SELECT id_pm, id_pm_head
  2188. FROM {db_prefix}personal_messages
  2189. WHERE id_pm_head IN ({array_int:pm_heads})',
  2190. array(
  2191. 'pm_heads' => array_keys($pm_heads),
  2192. )
  2193. );
  2194. // Copy the action from the single to PM to the others.
  2195. while ($row = $smcFunc['db_fetch_assoc']($request))
  2196. {
  2197. if (isset($pm_heads[$row['id_pm_head']]) && isset($_REQUEST['pm_actions'][$pm_heads[$row['id_pm_head']]]))
  2198. $_REQUEST['pm_actions'][$row['id_pm']] = $_REQUEST['pm_actions'][$pm_heads[$row['id_pm_head']]];
  2199. }
  2200. $smcFunc['db_free_result']($request);
  2201. }
  2202. $to_delete = array();
  2203. $to_label = array();
  2204. $to_unlabel = array();
  2205. $label_type = array();
  2206. $labels = array();
  2207. foreach ($_REQUEST['pm_actions'] as $pm => $action)
  2208. {
  2209. if ($action === 'delete')
  2210. $to_delete[] = (int) $pm;
  2211. else
  2212. {
  2213. if (substr($action, 0, 4) == 'add_')
  2214. {
  2215. $type = 'add';
  2216. $action = substr($action, 4);
  2217. }
  2218. elseif (substr($action, 0, 4) == 'rem_')
  2219. {
  2220. $type = 'rem';
  2221. $action = substr($action, 4);
  2222. }
  2223. else
  2224. $type = 'unk';
  2225. if ($action == '-1' || (int) $action > 0)
  2226. {
  2227. $to_label[(int) $pm] = (int) $action;
  2228. $label_type[(int) $pm] = $type;
  2229. }
  2230. }
  2231. }
  2232. // Deleting, it looks like?
  2233. if (!empty($to_delete))
  2234. deleteMessages($to_delete, $context['display_mode'] == 2 ? null : $context['folder']);
  2235. // Are we labeling anything?
  2236. if (!empty($to_label) && $context['folder'] == 'inbox')
  2237. {
  2238. $updateErrors = 0;
  2239. // Get information about each message...
  2240. $request = $smcFunc['db_query']('', '
  2241. SELECT id_pm, in_inbox
  2242. FROM {db_prefix}pm_recipients
  2243. WHERE id_member = {int:current_member}
  2244. AND id_pm IN ({array_int:to_label})
  2245. LIMIT ' . count($to_label),
  2246. array(
  2247. 'current_member' => $user_info['id'],
  2248. 'to_label' => array_keys($to_label),
  2249. )
  2250. );
  2251. while ($row = $smcFunc['db_fetch_assoc']($request))
  2252. {
  2253. // Get the labels as well, but only if we're not dealing with the inbox
  2254. if ($to_label[$row['id_pm']] != '-1')
  2255. {
  2256. // The JOIN here ensures we only get labels that this user has applied to this PM
  2257. $request2 = $smcFunc['db_query']('', '
  2258. SELECT l.id_label, pml.id_pm
  2259. FROM {db_prefix}pm_labels AS l
  2260. INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_label = l.id_label)
  2261. WHERE l.id_member = {int:current_member}
  2262. AND pml.id_pm = {int:current_pm}',
  2263. array(
  2264. 'current_member' => $user_info['id'],
  2265. 'current_pm' => $row['id_pm'],
  2266. )
  2267. );
  2268. while ($row2 = $smcFunc['db_fetch_assoc']($request2))
  2269. {
  2270. $labels[$row2['id_label']] = $row2['id_label'];
  2271. }
  2272. $smcFunc['db_free_result']($request2);
  2273. }
  2274. // Use this to determine what to do later on...
  2275. $original_labels = $labels;
  2276. // Ignore inbox for now - we'll deal with it later
  2277. if ($to_label[$row['id_pm']] != '-1')
  2278. {
  2279. // If this label is in the list and we're not adding it, remove it
  2280. if (array_key_exists($to_label[$row['id_pm']], $labels) && $type !== 'add')
  2281. unset($labels[$to_label[$row['id_pm']]]);
  2282. else if ($type !== 'remove')
  2283. $labels[$to_label[$row['id_pm']]] = $to_label[$row['id_pm']];
  2284. }
  2285. // Removing all labels, so make sure it's in the inbox
  2286. if ($type == 'rem' && empty($labels))
  2287. $in_inbox = 1;
  2288. // Adding new labels, but removing inbox and applying new ones
  2289. elseif($type == 'add' && !empty($options['pm_remove_inbox_label']) && !empty($labels))
  2290. $in_inbox = 0;
  2291. // Just adding it to the inbox
  2292. else
  2293. $in_inbox = 1;
  2294. // Are we adding it to or removing it from the inbox?
  2295. if ($in_inbox != $row['in_inbox'])
  2296. {
  2297. $smcFunc['db_query']('', '
  2298. UPDATE {db_prefix}pm_recipients
  2299. SET in_inbox = {int:in_inbox}
  2300. WHERE id_pm = {int:id_pm}
  2301. AND id_member = {int:current_member}',
  2302. array(
  2303. 'current_member' => $user_info['id'],
  2304. 'id_pm' => $row['id_pm'],
  2305. 'in_inbox' => $in_inbox,
  2306. )
  2307. );
  2308. }
  2309. // Which labels do we not want now?
  2310. $labels_to_remove = array_diff($original_labels, $labels);
  2311. // Don't apply it if it's already applied
  2312. $labels_to_apply = array_diff($labels, $original_labels);
  2313. // Remove labels
  2314. if (!empty($labels_to_remove))
  2315. {
  2316. $smcFunc['db_query']('', '
  2317. DELETE FROM {db_prefix}pm_labeled_messages
  2318. WHERE id_pm = {int:current_pm}
  2319. AND id_label IN ({array_int:labels_to_remove})',
  2320. array(
  2321. 'current_pm' => $row['id_pm'],
  2322. 'labels_to_remove' => $labels_to_remove,
  2323. )
  2324. );
  2325. }
  2326. // Add new ones
  2327. if (!empty($labels_to_apply))
  2328. {
  2329. $inserts = array();
  2330. foreach($labels_to_apply as $pm => $label)
  2331. {
  2332. $inserts[] = array($pm, $label);
  2333. }
  2334. $smcFunc['db_insert']('', '{db_prefix}pm_labeled_messages', array('id_pm' => 'int', 'id_label' => 'int'), $inserts, array());
  2335. }
  2336. }
  2337. $smcFunc['db_free_result']($request);
  2338. }
  2339. // Back to the folder.
  2340. $_SESSION['pm_selected'] = array_keys($to_label);
  2341. redirectexit($context['current_label_redirect'] . (count($to_label) == 1 ? '#msg' . $_SESSION['pm_selected'][0] : ''), count($to_label) == 1 && isBrowser('ie'));
  2342. }
  2343. /**
  2344. * Are you sure you want to PERMANENTLY (mostly) delete ALL your messages?
  2345. */
  2346. function MessageKillAllQuery()
  2347. {
  2348. global $txt, $context;
  2349. // Only have to set up the template....
  2350. $context['sub_template'] = 'ask_delete';
  2351. $context['page_title'] = $txt['delete_all'];
  2352. $context['delete_all'] = $_REQUEST['f'] == 'all';
  2353. // And set the folder name...
  2354. $txt['delete_all'] = str_replace('PMBOX', $context['folder'] != 'sent' ? $txt['inbox'] : $txt['sent_items'], $txt['delete_all']);
  2355. }
  2356. /**
  2357. * Delete ALL the messages!
  2358. */
  2359. function MessageKillAll()
  2360. {
  2361. global $context;
  2362. checkSession('get');
  2363. // If all then delete all messages the user has.
  2364. if ($_REQUEST['f'] == 'all')
  2365. deleteMessages(null, null);
  2366. // Otherwise just the selected folder.
  2367. else
  2368. deleteMessages(null, $_REQUEST['f'] != 'sent' ? 'inbox' : 'sent');
  2369. // Done... all gone.
  2370. redirectexit($context['current_label_redirect']);
  2371. }
  2372. /**
  2373. * This function allows the user to delete all messages older than so many days.
  2374. */
  2375. function MessagePrune()
  2376. {
  2377. global $txt, $context, $user_info, $scripturl, $smcFunc;
  2378. // Actually delete the messages.
  2379. if (isset($_REQUEST['age']))
  2380. {
  2381. checkSession();
  2382. // Calculate the time to delete before.
  2383. $deleteTime = max(0, time() - (86400 * (int) $_REQUEST['age']));
  2384. // Array to store the IDs in.
  2385. $toDelete = array();
  2386. // Select all the messages they have sent older than $deleteTime.
  2387. $request = $smcFunc['db_query']('', '
  2388. SELECT id_pm
  2389. FROM {db_prefix}personal_messages
  2390. WHERE deleted_by_sender = {int:not_deleted}
  2391. AND id_member_from = {int:current_member}
  2392. AND msgtime < {int:msgtime}',
  2393. array(
  2394. 'current_member' => $user_info['id'],
  2395. 'not_deleted' => 0,
  2396. 'msgtime' => $deleteTime,
  2397. )
  2398. );
  2399. while ($row = $smcFunc['db_fetch_row']($request))
  2400. $toDelete[] = $row[0];
  2401. $smcFunc['db_free_result']($request);
  2402. // Select all messages in their inbox older than $deleteTime.
  2403. $request = $smcFunc['db_query']('', '
  2404. SELECT pmr.id_pm
  2405. FROM {db_prefix}pm_recipients AS pmr
  2406. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  2407. WHERE pmr.deleted = {int:not_deleted}
  2408. AND pmr.id_member = {int:current_member}
  2409. AND pm.msgtime < {int:msgtime}',
  2410. array(
  2411. 'current_member' => $user_info['id'],
  2412. 'not_deleted' => 0,
  2413. 'msgtime' => $deleteTime,
  2414. )
  2415. );
  2416. while ($row = $smcFunc['db_fetch_assoc']($request))
  2417. $toDelete[] = $row['id_pm'];
  2418. $smcFunc['db_free_result']($request);
  2419. // Delete the actual messages.
  2420. deleteMessages($toDelete);
  2421. // Go back to their inbox.
  2422. redirectexit($context['current_label_redirect']);
  2423. }
  2424. // Build the link tree elements.
  2425. $context['linktree'][] = array(
  2426. 'url' => $scripturl . '?action=pm;sa=prune',
  2427. 'name' => $txt['pm_prune']
  2428. );
  2429. $context['sub_template'] = 'prune';
  2430. $context['page_title'] = $txt['pm_prune'];
  2431. }
  2432. /**
  2433. * Delete the specified personal messages.
  2434. *
  2435. * @param array $personal_messages array of pm ids
  2436. * @param string $folder = null
  2437. * @param int $owner = null
  2438. */
  2439. function deleteMessages($personal_messages, $folder = null, $owner = null)
  2440. {
  2441. global $user_info, $smcFunc;
  2442. if ($owner === null)
  2443. $owner = array($user_info['id']);
  2444. elseif (empty($owner))
  2445. return;
  2446. elseif (!is_array($owner))
  2447. $owner = array($owner);
  2448. if ($personal_messages !== null)
  2449. {
  2450. if (empty($personal_messages) || !is_array($personal_messages))
  2451. return;
  2452. foreach ($personal_messages as $index => $delete_id)
  2453. $personal_messages[$index] = (int) $delete_id;
  2454. $where = '
  2455. AND id_pm IN ({array_int:pm_list})';
  2456. }
  2457. else
  2458. $where = '';
  2459. if ($folder == 'sent' || $folder === null)
  2460. {
  2461. $smcFunc['db_query']('', '
  2462. UPDATE {db_prefix}personal_messages
  2463. SET deleted_by_sender = {int:is_deleted}
  2464. WHERE id_member_from IN ({array_int:member_list})
  2465. AND deleted_by_sender = {int:not_deleted}' . $where,
  2466. array(
  2467. 'member_list' => $owner,
  2468. 'is_deleted' => 1,
  2469. 'not_deleted' => 0,
  2470. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2471. )
  2472. );
  2473. }
  2474. if ($folder != 'sent' || $folder === null)
  2475. {
  2476. // Calculate the number of messages each member's gonna lose...
  2477. $request = $smcFunc['db_query']('', '
  2478. SELECT id_member, COUNT(*) AS num_deleted_messages, CASE WHEN is_read & 1 >= 1 THEN 1 ELSE 0 END AS is_read
  2479. FROM {db_prefix}pm_recipients
  2480. WHERE id_member IN ({array_int:member_list})
  2481. AND deleted = {int:not_deleted}' . $where . '
  2482. GROUP BY id_member, is_read',
  2483. array(
  2484. 'member_list' => $owner,
  2485. 'not_deleted' => 0,
  2486. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2487. )
  2488. );
  2489. // ...And update the statistics accordingly - now including unread messages!.
  2490. while ($row = $smcFunc['db_fetch_assoc']($request))
  2491. {
  2492. if ($row['is_read'])
  2493. updateMemberData($row['id_member'], array('instant_messages' => $where == '' ? 0 : 'instant_messages - ' . $row['num_deleted_messages']));
  2494. else
  2495. updateMemberData($row['id_member'], array('instant_messages' => $where == '' ? 0 : 'instant_messages - ' . $row['num_deleted_messages'], 'unread_messages' => $where == '' ? 0 : 'unread_messages - ' . $row['num_deleted_messages']));
  2496. // If this is the current member we need to make their message count correct.
  2497. if ($user_info['id'] == $row['id_member'])
  2498. {
  2499. $user_info['messages'] -= $row['num_deleted_messages'];
  2500. if (!($row['is_read']))
  2501. $user_info['unread_messages'] -= $row['num_deleted_messages'];
  2502. }
  2503. }
  2504. $smcFunc['db_free_result']($request);
  2505. // Do the actual deletion.
  2506. $smcFunc['db_query']('', '
  2507. UPDATE {db_prefix}pm_recipients
  2508. SET deleted = {int:is_deleted}
  2509. WHERE id_member IN ({array_int:member_list})
  2510. AND deleted = {int:not_deleted}' . $where,
  2511. array(
  2512. 'member_list' => $owner,
  2513. 'is_deleted' => 1,
  2514. 'not_deleted' => 0,
  2515. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2516. )
  2517. );
  2518. $labels = array();
  2519. // Get any labels that the owner may have applied to this PM
  2520. // The join is here to ensure we only get labels applied by the specified member(s)
  2521. $get_labels = $smcFunc['db_query']('', '
  2522. SELECT pml.id_label
  2523. FROM {db_prefix}pm_labels AS l
  2524. INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_label = l.id_label)
  2525. WHERE l.id_member IN ({array_int:member_list})' . $where,
  2526. array(
  2527. 'member_list' => $owner,
  2528. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2529. )
  2530. );
  2531. while ($row = $smcFunc['db_fetch_assoc']($get_labels))
  2532. {
  2533. $labels[] = $row['id_label'];
  2534. }
  2535. $smcFunc['db_free_result']($get_labels);
  2536. if (!empty($labels))
  2537. {
  2538. $smcFunc['db_query']('', '
  2539. DELETE FROM {db_prefix}pm_labeled_messages
  2540. WHERE label_id IN ({array_int:labels})' . $where,
  2541. array(
  2542. 'labels' => $labels,
  2543. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2544. )
  2545. );
  2546. }
  2547. }
  2548. // If sender and recipients all have deleted their message, it can be removed.
  2549. $request = $smcFunc['db_query']('', '
  2550. SELECT pm.id_pm AS sender, pmr.id_pm
  2551. FROM {db_prefix}personal_messages AS pm
  2552. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm AND pmr.deleted = {int:not_deleted})
  2553. WHERE pm.deleted_by_sender = {int:is_deleted}
  2554. ' . str_replace('id_pm', 'pm.id_pm', $where) . '
  2555. GROUP BY sender, pmr.id_pm
  2556. HAVING pmr.id_pm IS null',
  2557. array(
  2558. 'not_deleted' => 0,
  2559. 'is_deleted' => 1,
  2560. 'pm_list' => $personal_messages !== null ? array_unique($personal_messages) : array(),
  2561. )
  2562. );
  2563. $remove_pms = array();
  2564. while ($row = $smcFunc['db_fetch_assoc']($request))
  2565. $remove_pms[] = $row['sender'];
  2566. $smcFunc['db_free_result']($request);
  2567. if (!empty($remove_pms))
  2568. {
  2569. $smcFunc['db_query']('', '
  2570. DELETE FROM {db_prefix}personal_messages
  2571. WHERE id_pm IN ({array_int:pm_list})',
  2572. array(
  2573. 'pm_list' => $remove_pms,
  2574. )
  2575. );
  2576. $smcFunc['db_query']('', '
  2577. DELETE FROM {db_prefix}pm_recipients
  2578. WHERE id_pm IN ({array_int:pm_list})',
  2579. array(
  2580. 'pm_list' => $remove_pms,
  2581. )
  2582. );
  2583. $smcFunc['db_query']('', '
  2584. DELETE FROM {db_prefix}pm_labeled_messages
  2585. WHERE id_pm IN ({array_int:pm_list})',
  2586. array(
  2587. 'pm_list' => $remove_pms,
  2588. )
  2589. );
  2590. }
  2591. // Any cached numbers may be wrong now.
  2592. cache_put_data('labelCounts:' . $user_info['id'], null, 720);
  2593. }
  2594. /**
  2595. * Mark the specified personal messages read.
  2596. *
  2597. * @param array $personal_messages = null, array of pm ids
  2598. * @param string $label = null, if label is set, only marks messages with that label
  2599. * @param int $owner = null, if owner is set, marks messages owned by that member id
  2600. */
  2601. function markMessages($personal_messages = null, $label = null, $owner = null)
  2602. {
  2603. global $user_info, $context, $smcFunc;
  2604. if ($owner === null)
  2605. $owner = $user_info['id'];
  2606. $in_inbox = '';
  2607. // Marking all messages with a specific label as read?
  2608. // If we know which PMs we're marking read, then we don't need label info
  2609. if ($personal_messages === null && $label !== null && $label != '-1')
  2610. {
  2611. $personal_messages = array();
  2612. $get_messages = $smcFunc['db_query']('', '
  2613. SELECT id_pm
  2614. FROM {db_prefix}pm_labeled_messages
  2615. WHERE id_label = {int:current_label}',
  2616. array(
  2617. 'current_label' => $label,
  2618. )
  2619. );
  2620. while ($row = $smcFunc['db_fetch_assoc']($get_messages))
  2621. {
  2622. $personal_messages[] = $row['id_pm'];
  2623. }
  2624. $smcFunc['db_free_result']($get_messages);
  2625. }
  2626. elseif ($label = '-1')
  2627. {
  2628. // Marking all PMs in your inbox read
  2629. $in_inbox = '
  2630. AND in_inbox = {int:in_inbox}';
  2631. }
  2632. $smcFunc['db_query']('', '
  2633. UPDATE {db_prefix}pm_recipients
  2634. SET is_read = is_read | 1
  2635. WHERE id_member = {int:id_member}
  2636. AND NOT (is_read & 1 >= 1)' . ($personal_messages !== null ? '
  2637. AND id_pm IN ({array_int:personal_messages})' : '') . $in_inbox,
  2638. array(
  2639. 'personal_messages' => $personal_messages,
  2640. 'id_member' => $owner,
  2641. 'in_inbox' => 1,
  2642. )
  2643. );
  2644. // If something wasn't marked as read, get the number of unread messages remaining.
  2645. if ($smcFunc['db_affected_rows']() > 0)
  2646. {
  2647. if ($owner == $user_info['id'])
  2648. {
  2649. foreach ($context['labels'] as $label)
  2650. $context['labels'][(int) $label['id']]['unread_messages'] = 0;
  2651. }
  2652. $result = $smcFunc['db_query']('', '
  2653. SELECT id_pm, in_inbox, COUNT(*) AS num
  2654. FROM {db_prefix}pm_recipients
  2655. WHERE id_member = {int:id_member}
  2656. AND NOT (is_read & 1 >= 1)
  2657. AND deleted = {int:is_not_deleted}',
  2658. array(
  2659. 'id_member' => $owner,
  2660. 'is_not_deleted' => 0,
  2661. )
  2662. );
  2663. $total_unread = 0;
  2664. while ($row = $smcFunc['db_fetch_assoc']($result))
  2665. {
  2666. $total_unread += $row['num'];
  2667. if ($owner != $user_info['id'])
  2668. continue;
  2669. $this_labels = array();
  2670. // Get all the labels
  2671. $result2 = $smcFunc['db_query']('', '
  2672. SELECT pml.id_label
  2673. FROM {db_prefix}pm_labels AS l
  2674. INNER JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_label = l.id_label)
  2675. WHERE l.id_member = {int:id_member}
  2676. AND pml.id_pm = {int:current_pm}',
  2677. array(
  2678. 'id_member' => $owner,
  2679. 'current_pm' => $row['id_pm'],
  2680. )
  2681. );
  2682. while ($row2 = $smcFunc['db_fetch_assoc']($result2))
  2683. {
  2684. $this_labels[] = $row2['id_label'];
  2685. }
  2686. $smcFunc['db_free_result']($result2);
  2687. foreach ($this_labels as $this_label)
  2688. $context['labels'][$this_label]['unread_messages'] += $row['num'];
  2689. if ($row['in_inbox'] == 1)
  2690. $context['labels'][-1]['unread_messages'] += $row['num'];
  2691. }
  2692. $smcFunc['db_free_result']($result);
  2693. // Need to store all this.
  2694. cache_put_data('labelCounts:' . $owner, $context['labels'], 720);
  2695. updateMemberData($owner, array('unread_messages' => $total_unread));
  2696. // If it was for the current member, reflect this in the $user_info array too.
  2697. if ($owner == $user_info['id'])
  2698. $user_info['unread_messages'] = $total_unread;
  2699. }
  2700. }
  2701. /**
  2702. * This function handles adding, deleting and editing labels on messages.
  2703. */
  2704. function ManageLabels()
  2705. {
  2706. global $txt, $context, $user_info, $scripturl, $smcFunc;
  2707. // Build the link tree elements...
  2708. $context['linktree'][] = array(
  2709. 'url' => $scripturl . '?action=pm;sa=manlabels',
  2710. 'name' => $txt['pm_manage_labels']
  2711. );
  2712. $context['page_title'] = $txt['pm_manage_labels'];
  2713. $context['sub_template'] = 'labels';
  2714. $the_labels = array();
  2715. $labels_to_add = array();
  2716. $labels_to_remove = array();
  2717. $label_updates = array();
  2718. // Add all existing labels to the array to save, slashing them as necessary...
  2719. foreach ($context['labels'] as $label)
  2720. {
  2721. if ($label['id'] != -1)
  2722. $the_labels[$label['id']] = $label['name'];
  2723. }
  2724. if (isset($_POST[$context['session_var']]))
  2725. {
  2726. checkSession('post');
  2727. // This will be for updating messages.
  2728. $message_changes = array();
  2729. $rule_changes = array();
  2730. // Will most likely need this.
  2731. LoadRules();
  2732. // Adding a new label?
  2733. if (isset($_POST['add']))
  2734. {
  2735. $_POST['label'] = strtr($smcFunc['htmlspecialchars'](trim($_POST['label'])), array(',' => '&#044;'));
  2736. if ($smcFunc['strlen']($_POST['label']) > 30)
  2737. $_POST['label'] = $smcFunc['substr']($_POST['label'], 0, 30);
  2738. if ($_POST['label'] != '')
  2739. {
  2740. $the_labels[] = $_POST['label'];
  2741. $labels_to_add[] = $_POST['label'];
  2742. }
  2743. }
  2744. // Deleting an existing label?
  2745. elseif (isset($_POST['delete'], $_POST['delete_label']))
  2746. {
  2747. foreach ($_POST['delete_label'] AS $label)
  2748. {
  2749. unset($the_labels[$label]);
  2750. $labels_to_remove[] = $label;
  2751. }
  2752. }
  2753. // The hardest one to deal with... changes.
  2754. elseif (isset($_POST['save']) && !empty($_POST['label_name']))
  2755. {
  2756. foreach ($the_labels as $id => $name)
  2757. {
  2758. if ($id == -1)
  2759. continue;
  2760. elseif (isset($_POST['label_name'][$id]))
  2761. {
  2762. $_POST['label_name'][$id] = trim(strtr($smcFunc['htmlspecialchars']($_POST['label_name'][$id]), array(',' => '&#044;')));
  2763. if ($smcFunc['strlen']($_POST['label_name'][$id]) > 30)
  2764. $_POST['label_name'][$id] = $smcFunc['substr']($_POST['label_name'][$id], 0, 30);
  2765. if ($_POST['label_name'][$id] != '')
  2766. {
  2767. // Changing the name of this label?
  2768. if ($the_labels[$id] != $_POST['label_name'][$id])
  2769. $label_updates[$id] = $_POST['label_name'][$id];
  2770. $the_labels[(int) $id] = $_POST['label_name'][$id];
  2771. }
  2772. else
  2773. {
  2774. unset($the_labels[(int) $id]);
  2775. $labels_to_remove[] = $id;
  2776. $message_changes[(int) $id] = true;
  2777. }
  2778. }
  2779. }
  2780. }
  2781. // Save any new labels
  2782. if (!empty($labels_to_add))
  2783. {
  2784. $inserts = array();
  2785. foreach($labels_to_add AS $label)
  2786. {
  2787. $inserts[] = array($user_info['id'], $label);
  2788. }
  2789. $smcFunc['db_insert']('', '{db_prefix}pm_labels', array('id_member' => 'int', 'name' => 'string-30'), $inserts, array());
  2790. }
  2791. // Update existing labels as needed
  2792. if (!empty($label_upates))
  2793. {
  2794. foreach($label_updates AS $id => $name)
  2795. {
  2796. $smcFunc['db_query']('', '
  2797. UPDATE {db_prefix}labels
  2798. SET name = {string:name}
  2799. WHERE id_label = {int:id_label}',
  2800. array(
  2801. 'name' => $name,
  2802. 'id' => $id
  2803. )
  2804. );
  2805. }
  2806. }
  2807. // Now the fun part... Deleting labels.
  2808. if (!empty($labels_to_remove))
  2809. {
  2810. // First delete the labels
  2811. $smcFunc['db_query']('', '
  2812. DELETE FROM {db_prefix}pm_labels
  2813. WHERE id_label IN ({array_int:labels_to_delete})',
  2814. array(
  2815. 'labels_to_delete' => $labels_to_delete,
  2816. )
  2817. );
  2818. // Get any PMs with no labels which aren't in the inbox
  2819. $get_stranded_pms = $smcFunc['db_query']('', '
  2820. SELECT pmr.id_pm
  2821. FROM {db_prefix}pm_recipients
  2822. LEFT JOIN {db_prefix}pm_labeled_messages AS pml ON (pml.id_pm = pmr.id_pm)
  2823. WHERE pml.id_label IS NULL
  2824. AND pmr.in_inbox = {int:not_in_inbox}
  2825. AND pmr.deleted = {int:not_deleted}
  2826. AND pmr.id_member = {int:current_member}',
  2827. array(
  2828. 'not_in_inbox' => 0,
  2829. 'not_deleted' => 0,
  2830. 'current_member' => $user_info['id'],
  2831. )
  2832. );
  2833. $stranded_messages = array();
  2834. while ($row = $smcFunc['db_fetch_assoc']($get_stranded_pms))
  2835. {
  2836. $stranded_messages[] = $row['id_pm'];
  2837. }
  2838. $smcFunc['db_free_result']($get_stranded_pms);
  2839. // Move these back to the inbox if necessary
  2840. if (!empty($stranded_messages))
  2841. {
  2842. // We now have more messages in the inbox
  2843. $context['labels'][-1]['messages'] += count($stranded_messages);
  2844. $smcFunc['db_query']('', '
  2845. UPDATE {db_prefix}pm_recipients
  2846. SET in_inbox = {int:in_inbox}
  2847. WHERE id_pm IN ({array_int:stranded_messages})
  2848. AND id_member = {int:current_member}',
  2849. array(
  2850. 'stranded_messages' => $stranded_messages,
  2851. 'in_inbox' => 1,
  2852. )
  2853. );
  2854. }
  2855. // Now do the same the rules - check through each rule.
  2856. foreach ($context['rules'] as $k => $rule)
  2857. {
  2858. // Each action...
  2859. foreach ($rule['actions'] as $k2 => $action)
  2860. {
  2861. if ($action['t'] != 'lab' || !in_array($action['v'], $labels_to_remove))
  2862. continue;
  2863. $rule_changes[] = $rule['id'];
  2864. // Can't apply this label anymore if it doesn't exist
  2865. unset($context['rules'][$k]['actions'][$k2]);
  2866. }
  2867. }
  2868. }
  2869. // If we have rules to change do so now.
  2870. if (!empty($rule_changes))
  2871. {
  2872. $rule_changes = array_unique($rule_changes);
  2873. // Update/delete as appropriate.
  2874. foreach ($rule_changes as $k => $id)
  2875. if (!empty($context['rules'][$id]['actions']))
  2876. {
  2877. $smcFunc['db_query']('', '
  2878. UPDATE {db_prefix}pm_rules
  2879. SET actions = {string:actions}
  2880. WHERE id_rule = {int:id_rule}
  2881. AND id_member = {int:current_member}',
  2882. array(
  2883. 'current_member' => $user_info['id'],
  2884. 'id_rule' => $id,
  2885. 'actions' => serialize($context['rules'][$id]['actions']),
  2886. )
  2887. );
  2888. unset($rule_changes[$k]);
  2889. }
  2890. // Anything left here means it's lost all actions...
  2891. if (!empty($rule_changes))
  2892. $smcFunc['db_query']('', '
  2893. DELETE FROM {db_prefix}pm_rules
  2894. WHERE id_rule IN ({array_int:rule_list})
  2895. AND id_member = {int:current_member}',
  2896. array(
  2897. 'current_member' => $user_info['id'],
  2898. 'rule_list' => $rule_changes,
  2899. )
  2900. );
  2901. }
  2902. // Make sure we're not caching this!
  2903. cache_put_data('labelCounts:' . $user_info['id'], null, 720);
  2904. // To make the changes appear right away, redirect.
  2905. redirectexit('action=pm;sa=manlabels');
  2906. }
  2907. }
  2908. /**
  2909. * Allows to edit Personal Message Settings.
  2910. *
  2911. * @uses Profile.php
  2912. * @uses Profile-Modify.php
  2913. * @uses Profile template.
  2914. * @uses Profile language file.
  2915. */
  2916. function MessageSettings()
  2917. {
  2918. global $txt, $user_settings, $user_info, $context, $sourcedir, $smcFunc;
  2919. global $scripturl, $profile_vars, $cur_profile, $user_profile;
  2920. // Need this for the display.
  2921. require_once($sourcedir . '/Profile.php');
  2922. require_once($sourcedir . '/Profile-Modify.php');
  2923. // We want them to submit back to here.
  2924. $context['profile_custom_submit_url'] = $scripturl . '?action=pm;sa=settings;save';
  2925. loadMemberData($user_info['id'], false, 'profile');
  2926. $cur_profile = $user_profile[$user_info['id']];
  2927. loadLanguage('Profile');
  2928. loadTemplate('Profile');
  2929. $context['page_title'] = $txt['pm_settings'];
  2930. $context['user']['is_owner'] = true;
  2931. $context['id_member'] = $user_info['id'];
  2932. $context['require_password'] = false;
  2933. $context['menu_item_selected'] = 'settings';
  2934. $context['submit_button_text'] = $txt['pm_settings'];
  2935. $context['profile_header_text'] = $txt['personal_messages'];
  2936. // Add our position to the linktree.
  2937. $context['linktree'][] = array(
  2938. 'url' => $scripturl . '?action=pm;sa=settings',
  2939. 'name' => $txt['pm_settings']
  2940. );
  2941. // Are they saving?
  2942. if (isset($_REQUEST['save']))
  2943. {
  2944. checkSession('post');
  2945. // Mimic what profile would do.
  2946. $_POST = htmltrim__recursive($_POST);
  2947. $_POST = htmlspecialchars__recursive($_POST);
  2948. // Save the fields.
  2949. saveProfileFields();
  2950. if (!empty($profile_vars))
  2951. updateMemberData($user_info['id'], $profile_vars);
  2952. }
  2953. // Load up the fields.
  2954. pmprefs($user_info['id']);
  2955. }
  2956. /**
  2957. * Allows the user to report a personal message to an administrator.
  2958. *
  2959. * - In the first instance requires that the ID of the message to report is passed through $_GET.
  2960. * - It allows the user to report to either a particular administrator - or the whole admin team.
  2961. * - It will forward on a copy of the original message without allowing the reporter to make changes.
  2962. *
  2963. * @uses report_message sub-template.
  2964. */
  2965. function ReportMessage()
  2966. {
  2967. global $txt, $context, $scripturl, $sourcedir;
  2968. global $user_info, $language, $modSettings, $smcFunc;
  2969. // Check that this feature is even enabled!
  2970. if (empty($modSettings['enableReportPM']) || empty($_REQUEST['pmsg']))
  2971. fatal_lang_error('no_access', false);
  2972. $pmsg = (int) $_REQUEST['pmsg'];
  2973. if (!isAccessiblePM($pmsg, 'inbox'))
  2974. fatal_lang_error('no_access', false);
  2975. $context['pm_id'] = $pmsg;
  2976. $context['page_title'] = $txt['pm_report_title'];
  2977. // If we're here, just send the user to the template, with a few useful context bits.
  2978. if (!isset($_POST['report']))
  2979. {
  2980. $context['sub_template'] = 'report_message';
  2981. // @todo I don't like being able to pick who to send it to. Favoritism, etc. sucks.
  2982. // Now, get all the administrators.
  2983. $request = $smcFunc['db_query']('', '
  2984. SELECT id_member, real_name
  2985. FROM {db_prefix}members
  2986. WHERE id_group = {int:admin_group} OR FIND_IN_SET({int:admin_group}, additional_groups) != 0
  2987. ORDER BY real_name',
  2988. array(
  2989. 'admin_group' => 1,
  2990. )
  2991. );
  2992. $context['admins'] = array();
  2993. while ($row = $smcFunc['db_fetch_assoc']($request))
  2994. $context['admins'][$row['id_member']] = $row['real_name'];
  2995. $smcFunc['db_free_result']($request);
  2996. // How many admins in total?
  2997. $context['admin_count'] = count($context['admins']);
  2998. }
  2999. // Otherwise, let's get down to the sending stuff.
  3000. else
  3001. {
  3002. // Check the session before proceeding any further!
  3003. checkSession('post');
  3004. // First, pull out the message contents, and verify it actually went to them!
  3005. $request = $smcFunc['db_query']('', '
  3006. SELECT pm.subject, pm.body, pm.msgtime, pm.id_member_from, IFNULL(m.real_name, pm.from_name) AS sender_name
  3007. FROM {db_prefix}personal_messages AS pm
  3008. INNER JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm)
  3009. LEFT JOIN {db_prefix}members AS m ON (m.id_member = pm.id_member_from)
  3010. WHERE pm.id_pm = {int:id_pm}
  3011. AND pmr.id_member = {int:current_member}
  3012. AND pmr.deleted = {int:not_deleted}
  3013. LIMIT 1',
  3014. array(
  3015. 'current_member' => $user_info['id'],
  3016. 'id_pm' => $context['pm_id'],
  3017. 'not_deleted' => 0,
  3018. )
  3019. );
  3020. // Can only be a hacker here!
  3021. if ($smcFunc['db_num_rows']($request) == 0)
  3022. fatal_lang_error('no_access', false);
  3023. list ($subject, $body, $time, $memberFromID, $memberFromName) = $smcFunc['db_fetch_row']($request);
  3024. $smcFunc['db_free_result']($request);
  3025. // Remove the line breaks...
  3026. $body = preg_replace('~<br ?/?' . '>~i', "\n", $body);
  3027. // Get any other recipients of the email.
  3028. $request = $smcFunc['db_query']('', '
  3029. SELECT mem_to.id_member AS id_member_to, mem_to.real_name AS to_name, pmr.bcc
  3030. FROM {db_prefix}pm_recipients AS pmr
  3031. LEFT JOIN {db_prefix}members AS mem_to ON (mem_to.id_member = pmr.id_member)
  3032. WHERE pmr.id_pm = {int:id_pm}
  3033. AND pmr.id_member != {int:current_member}',
  3034. array(
  3035. 'current_member' => $user_info['id'],
  3036. 'id_pm' => $context['pm_id'],
  3037. )
  3038. );
  3039. $recipients = array();
  3040. $hidden_recipients = 0;
  3041. while ($row = $smcFunc['db_fetch_assoc']($request))
  3042. {
  3043. // If it's hidden still don't reveal their names - privacy after all ;)
  3044. if ($row['bcc'])
  3045. $hidden_recipients++;
  3046. else
  3047. $recipients[] = '[url=' . $scripturl . '?action=profile;u=' . $row['id_member_to'] . ']' . $row['to_name'] . '[/url]';
  3048. }
  3049. $smcFunc['db_free_result']($request);
  3050. if ($hidden_recipients)
  3051. $recipients[] = sprintf($txt['pm_report_pm_hidden'], $hidden_recipients);
  3052. // Now let's get out and loop through the admins.
  3053. $request = $smcFunc['db_query']('', '
  3054. SELECT id_member, real_name, lngfile
  3055. FROM {db_prefix}members
  3056. WHERE (id_group = {int:admin_id} OR FIND_IN_SET({int:admin_id}, additional_groups) != 0)
  3057. ' . (empty($_POST['id_admin']) ? '' : 'AND id_member = {int:specific_admin}') . '
  3058. ORDER BY lngfile',
  3059. array(
  3060. 'admin_id' => 1,
  3061. 'specific_admin' => isset($_POST['id_admin']) ? (int) $_POST['id_admin'] : 0,
  3062. )
  3063. );
  3064. // Maybe we shouldn't advertise this?
  3065. if ($smcFunc['db_num_rows']($request) == 0)
  3066. fatal_lang_error('no_access', false);
  3067. $memberFromName = un_htmlspecialchars($memberFromName);
  3068. // Prepare the message storage array.
  3069. $messagesToSend = array();
  3070. // Loop through each admin, and add them to the right language pile...
  3071. while ($row = $smcFunc['db_fetch_assoc']($request))
  3072. {
  3073. // Need to send in the correct language!
  3074. $cur_language = empty($row['lngfile']) || empty($modSettings['userLanguage']) ? $language : $row['lngfile'];
  3075. if (!isset($messagesToSend[$cur_language]))
  3076. {
  3077. loadLanguage('PersonalMessage', $cur_language, false);
  3078. // Make the body.
  3079. $report_body = str_replace(array('{REPORTER}', '{SENDER}'), array(un_htmlspecialchars($user_info['name']), $memberFromName), $txt['pm_report_pm_user_sent']);
  3080. $report_body .= "\n" . '[b]' . $_POST['reason'] . '[/b]' . "\n\n";
  3081. if (!empty($recipients))
  3082. $report_body .= $txt['pm_report_pm_other_recipients'] . ' ' . implode(', ', $recipients) . "\n\n";
  3083. $report_body .= $txt['pm_report_pm_unedited_below'] . "\n" . '[quote author=' . (empty($memberFromID) ? '&quot;' . $memberFromName . '&quot;' : $memberFromName . ' link=action=profile;u=' . $memberFromID . ' date=' . $time) . ']' . "\n" . un_htmlspecialchars($body) . '[/quote]';
  3084. // Plonk it in the array ;)
  3085. $messagesToSend[$cur_language] = array(
  3086. 'subject' => ($smcFunc['strpos']($subject, $txt['pm_report_pm_subject']) === false ? $txt['pm_report_pm_subject'] : '') . un_htmlspecialchars($subject),
  3087. 'body' => $report_body,
  3088. 'recipients' => array(
  3089. 'to' => array(),
  3090. 'bcc' => array()
  3091. ),
  3092. );
  3093. }
  3094. // Add them to the list.
  3095. $messagesToSend[$cur_language]['recipients']['to'][$row['id_member']] = $row['id_member'];
  3096. }
  3097. $smcFunc['db_free_result']($request);
  3098. // Send a different email for each language.
  3099. foreach ($messagesToSend as $lang => $message)
  3100. sendpm($message['recipients'], $message['subject'], $message['body']);
  3101. // Give the user their own language back!
  3102. if (!empty($modSettings['userLanguage']))
  3103. loadLanguage('PersonalMessage', '', false);
  3104. // Leave them with a template.
  3105. $context['sub_template'] = 'report_message_complete';
  3106. }
  3107. }
  3108. /**
  3109. * List all rules, and allow adding/entering etc...
  3110. */
  3111. function ManageRules()
  3112. {
  3113. global $txt, $context, $user_info, $scripturl, $smcFunc;
  3114. // The link tree - gotta have this :o
  3115. $context['linktree'][] = array(
  3116. 'url' => $scripturl . '?action=pm;sa=manrules',
  3117. 'name' => $txt['pm_manage_rules']
  3118. );
  3119. $context['page_title'] = $txt['pm_manage_rules'];
  3120. $context['sub_template'] = 'rules';
  3121. // Load them... load them!!
  3122. LoadRules();
  3123. // Likely to need all the groups!
  3124. $request = $smcFunc['db_query']('', '
  3125. SELECT mg.id_group, mg.group_name, IFNULL(gm.id_member, 0) AS can_moderate, mg.hidden
  3126. FROM {db_prefix}membergroups AS mg
  3127. LEFT JOIN {db_prefix}group_moderators AS gm ON (gm.id_group = mg.id_group AND gm.id_member = {int:current_member})
  3128. WHERE mg.min_posts = {int:min_posts}
  3129. AND mg.id_group != {int:moderator_group}
  3130. AND mg.hidden = {int:not_hidden}
  3131. ORDER BY mg.group_name',
  3132. array(
  3133. 'current_member' => $user_info['id'],
  3134. 'min_posts' => -1,
  3135. 'moderator_group' => 3,
  3136. 'not_hidden' => 0,
  3137. )
  3138. );
  3139. $context['groups'] = array();
  3140. while ($row = $smcFunc['db_fetch_assoc']($request))
  3141. {
  3142. // Hide hidden groups!
  3143. if ($row['hidden'] && !$row['can_moderate'] && !allowedTo('manage_membergroups'))
  3144. continue;
  3145. $context['groups'][$row['id_group']] = $row['group_name'];
  3146. }
  3147. $smcFunc['db_free_result']($request);
  3148. // Applying all rules?
  3149. if (isset($_GET['apply']))
  3150. {
  3151. checkSession('get');
  3152. ApplyRules(true);
  3153. redirectexit('action=pm;sa=manrules');
  3154. }
  3155. // Editing a specific one?
  3156. if (isset($_GET['add']))
  3157. {
  3158. $context['rid'] = isset($_GET['rid']) && isset($context['rules'][$_GET['rid']])? (int) $_GET['rid'] : 0;
  3159. $context['sub_template'] = 'add_rule';
  3160. // Current rule information...
  3161. if ($context['rid'])
  3162. {
  3163. $context['rule'] = $context['rules'][$context['rid']];
  3164. $members = array();
  3165. // Need to get member names!
  3166. foreach ($context['rule']['criteria'] as $k => $criteria)
  3167. if ($criteria['t'] == 'mid' && !empty($criteria['v']))
  3168. $members[(int) $criteria['v']] = $k;
  3169. if (!empty($members))
  3170. {
  3171. $request = $smcFunc['db_query']('', '
  3172. SELECT id_member, member_name
  3173. FROM {db_prefix}members
  3174. WHERE id_member IN ({array_int:member_list})',
  3175. array(
  3176. 'member_list' => array_keys($members),
  3177. )
  3178. );
  3179. while ($row = $smcFunc['db_fetch_assoc']($request))
  3180. $context['rule']['criteria'][$members[$row['id_member']]]['v'] = $row['member_name'];
  3181. $smcFunc['db_free_result']($request);
  3182. }
  3183. }
  3184. else
  3185. $context['rule'] = array(
  3186. 'id' => '',
  3187. 'name' => '',
  3188. 'criteria' => array(),
  3189. 'actions' => array(),
  3190. 'logic' => 'and',
  3191. );
  3192. }
  3193. // Saving?
  3194. elseif (isset($_GET['save']))
  3195. {
  3196. checkSession('post');
  3197. $context['rid'] = isset($_GET['rid']) && isset($context['rules'][$_GET['rid']])? (int) $_GET['rid'] : 0;
  3198. // Name is easy!
  3199. $ruleName = $smcFunc['htmlspecialchars'](trim($_POST['rule_name']));
  3200. if (empty($ruleName))
  3201. fatal_lang_error('pm_rule_no_name', false);
  3202. // Sanity check...
  3203. if (empty($_POST['ruletype']) || empty($_POST['acttype']))
  3204. fatal_lang_error('pm_rule_no_criteria', false);
  3205. // Let's do the criteria first - it's also hardest!
  3206. $criteria = array();
  3207. foreach ($_POST['ruletype'] as $ind => $type)
  3208. {
  3209. // Check everything is here...
  3210. if ($type == 'gid' && (!isset($_POST['ruledefgroup'][$ind]) || !isset($context['groups'][$_POST['ruledefgroup'][$ind]])))
  3211. continue;
  3212. elseif ($type != 'bud' && !isset($_POST['ruledef'][$ind]))
  3213. continue;
  3214. // Members need to be found.
  3215. if ($type == 'mid')
  3216. {
  3217. $name = trim($_POST['ruledef'][$ind]);
  3218. $request = $smcFunc['db_query']('', '
  3219. SELECT id_member
  3220. FROM {db_prefix}members
  3221. WHERE real_name = {string:member_name}
  3222. OR member_name = {string:member_name}',
  3223. array(
  3224. 'member_name' => $name,
  3225. )
  3226. );
  3227. if ($smcFunc['db_num_rows']($request) == 0)
  3228. continue;
  3229. list ($memID) = $smcFunc['db_fetch_row']($request);
  3230. $smcFunc['db_free_result']($request);
  3231. $criteria[] = array('t' => 'mid', 'v' => $memID);
  3232. }
  3233. elseif ($type == 'bud')
  3234. $criteria[] = array('t' => 'bud', 'v' => 1);
  3235. elseif ($type == 'gid')
  3236. $criteria[] = array('t' => 'gid', 'v' => (int) $_POST['ruledefgroup'][$ind]);
  3237. elseif (in_array($type, array('sub', 'msg')) && trim($_POST['ruledef'][$ind]) != '')
  3238. $criteria[] = array('t' => $type, 'v' => $smcFunc['htmlspecialchars'](trim($_POST['ruledef'][$ind])));
  3239. }
  3240. // Also do the actions!
  3241. $actions = array();
  3242. $doDelete = 0;
  3243. $isOr = $_POST['rule_logic'] == 'or' ? 1 : 0;
  3244. foreach ($_POST['acttype'] as $ind => $type)
  3245. {
  3246. // Picking a valid label?
  3247. if ($type == 'lab' && (!isset($_POST['labdef'][$ind]) || !isset($context['labels'][$_POST['labdef'][$ind]])))
  3248. continue;
  3249. // Record what we're doing.
  3250. if ($type == 'del')
  3251. $doDelete = 1;
  3252. elseif ($type == 'lab')
  3253. $actions[] = array('t' => 'lab', 'v' => (int) $_POST['labdef'][$ind]);
  3254. }
  3255. if (empty($criteria) || (empty($actions) && !$doDelete))
  3256. fatal_lang_error('pm_rule_no_criteria', false);
  3257. // What are we storing?
  3258. $criteria = serialize($criteria);
  3259. $actions = serialize($actions);
  3260. // Create the rule?
  3261. if (empty($context['rid']))
  3262. $smcFunc['db_insert']('',
  3263. '{db_prefix}pm_rules',
  3264. array(
  3265. 'id_member' => 'int', 'rule_name' => 'string', 'criteria' => 'string', 'actions' => 'string',
  3266. 'delete_pm' => 'int', 'is_or' => 'int',
  3267. ),
  3268. array(
  3269. $user_info['id'], $ruleName, $criteria, $actions, $doDelete, $isOr,
  3270. ),
  3271. array('id_rule')
  3272. );
  3273. else
  3274. $smcFunc['db_query']('', '
  3275. UPDATE {db_prefix}pm_rules
  3276. SET rule_name = {string:rule_name}, criteria = {string:criteria}, actions = {string:actions},
  3277. delete_pm = {int:delete_pm}, is_or = {int:is_or}
  3278. WHERE id_rule = {int:id_rule}
  3279. AND id_member = {int:current_member}',
  3280. array(
  3281. 'current_member' => $user_info['id'],
  3282. 'delete_pm' => $doDelete,
  3283. 'is_or' => $isOr,
  3284. 'id_rule' => $context['rid'],
  3285. 'rule_name' => $ruleName,
  3286. 'criteria' => $criteria,
  3287. 'actions' => $actions,
  3288. )
  3289. );
  3290. redirectexit('action=pm;sa=manrules');
  3291. }
  3292. // Deleting?
  3293. elseif (isset($_POST['delselected']) && !empty($_POST['delrule']))
  3294. {
  3295. checkSession('post');
  3296. $toDelete = array();
  3297. foreach ($_POST['delrule'] as $k => $v)
  3298. $toDelete[] = (int) $k;
  3299. if (!empty($toDelete))
  3300. $smcFunc['db_query']('', '
  3301. DELETE FROM {db_prefix}pm_rules
  3302. WHERE id_rule IN ({array_int:delete_list})
  3303. AND id_member = {int:current_member}',
  3304. array(
  3305. 'current_member' => $user_info['id'],
  3306. 'delete_list' => $toDelete,
  3307. )
  3308. );
  3309. redirectexit('action=pm;sa=manrules');
  3310. }
  3311. }
  3312. /**
  3313. * This will apply rules to all unread messages. If all_messages is set will, clearly, do it to all!
  3314. *
  3315. * @param bool $all_messages = false
  3316. */
  3317. function ApplyRules($all_messages = false)
  3318. {
  3319. global $user_info, $smcFunc, $context, $options;
  3320. // Want this - duh!
  3321. loadRules();
  3322. // No rules?
  3323. if (empty($context['rules']))
  3324. return;
  3325. // Just unread ones?
  3326. $ruleQuery = $all_messages ? '' : ' AND pmr.is_new = 1';
  3327. // @todo Apply all should have timeout protection!
  3328. // Get all the messages that match this.
  3329. $request = $smcFunc['db_query']('', '
  3330. SELECT
  3331. pmr.id_pm, pm.id_member_from, pm.subject, pm.body, mem.id_group
  3332. FROM {db_prefix}pm_recipients AS pmr
  3333. INNER JOIN {db_prefix}personal_messages AS pm ON (pm.id_pm = pmr.id_pm)
  3334. LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = pm.id_member_from)
  3335. WHERE pmr.id_member = {int:current_member}
  3336. AND pmr.deleted = {int:not_deleted}
  3337. ' . $ruleQuery,
  3338. array(
  3339. 'current_member' => $user_info['id'],
  3340. 'not_deleted' => 0,
  3341. )
  3342. );
  3343. $actions = array();
  3344. while ($row = $smcFunc['db_fetch_assoc']($request))
  3345. {
  3346. foreach ($context['rules'] as $rule)
  3347. {
  3348. $match = false;
  3349. // Loop through all the criteria hoping to make a match.
  3350. foreach ($rule['criteria'] as $criterium)
  3351. {
  3352. if (($criterium['t'] == 'mid' && $criterium['v'] == $row['id_member_from']) || ($criterium['t'] == 'gid' && $criterium['v'] == $row['id_group']) || ($criterium['t'] == 'sub' && strpos($row['subject'], $criterium['v']) !== false) || ($criterium['t'] == 'msg' && strpos($row['body'], $criterium['v']) !== false))
  3353. $match = true;
  3354. // If we're adding and one criteria don't match then we stop!
  3355. elseif ($rule['logic'] == 'and')
  3356. {
  3357. $match = false;
  3358. break;
  3359. }
  3360. }
  3361. // If we have a match the rule must be true - act!
  3362. if ($match)
  3363. {
  3364. if ($rule['delete'])
  3365. $actions['deletes'][] = $row['id_pm'];
  3366. else
  3367. {
  3368. foreach ($rule['actions'] as $ruleAction)
  3369. {
  3370. if ($ruleAction['t'] == 'lab')
  3371. {
  3372. // Get a basic pot started!
  3373. if (!isset($actions['labels'][$row['id_pm']]))
  3374. $actions['labels'][$row['id_pm']] = array();
  3375. $actions['labels'][$row['id_pm']][] = $ruleAction['v'];
  3376. }
  3377. }
  3378. }
  3379. }
  3380. }
  3381. }
  3382. $smcFunc['db_free_result']($request);
  3383. // Deletes are easy!
  3384. if (!empty($actions['deletes']))
  3385. deleteMessages($actions['deletes']);
  3386. // Relabel?
  3387. if (!empty($actions['labels']))
  3388. {
  3389. foreach ($actions['labels'] as $pm => $labels)
  3390. {
  3391. // Quickly check each label is valid!
  3392. $realLabels = array();
  3393. foreach ($context['labels'] as $label)
  3394. {
  3395. if (in_array($label['id'], $labels) && $label['id'] != -1 || empty($options['pm_remove_inbox_label']))
  3396. {
  3397. // Make sure this stays in the inbox
  3398. if ($label['id'] == '-1')
  3399. {
  3400. $smcFunc['db_query']('', '
  3401. UPDATE {db_prefix}pm_recipients
  3402. SET in_inbox = {int:in_inbox}
  3403. WHERE id_pm = {int:pm}
  3404. AND id_member = {int:current_member}',
  3405. array(
  3406. 'in_inbox' => 1,
  3407. 'id_pm' => $pm,
  3408. 'current_member' => $user_info['id'],
  3409. )
  3410. );
  3411. }
  3412. else
  3413. {
  3414. $realLabels[] = $label['id'];
  3415. }
  3416. }
  3417. }
  3418. $inserts = array();
  3419. // Now we insert the label info
  3420. foreach($realLabels as $a_label)
  3421. {
  3422. $inserts[] = array($user_info['id'], $pm, $label);
  3423. }
  3424. $smcFunc['db_insert']('', '{db_prefix}pm_labeled_messages', array('id_pm' => 'int', 'id_label' => 'int'), $inserts, array());
  3425. }
  3426. }
  3427. }
  3428. /**
  3429. * Load up all the rules for the current user.
  3430. *
  3431. * @param bool $reload = false
  3432. */
  3433. function LoadRules($reload = false)
  3434. {
  3435. global $user_info, $context, $smcFunc;
  3436. if (isset($context['rules']) && !$reload)
  3437. return;
  3438. $request = $smcFunc['db_query']('', '
  3439. SELECT
  3440. id_rule, rule_name, criteria, actions, delete_pm, is_or
  3441. FROM {db_prefix}pm_rules
  3442. WHERE id_member = {int:current_member}',
  3443. array(
  3444. 'current_member' => $user_info['id'],
  3445. )
  3446. );
  3447. $context['rules'] = array();
  3448. // Simply fill in the data!
  3449. while ($row = $smcFunc['db_fetch_assoc']($request))
  3450. {
  3451. $context['rules'][$row['id_rule']] = array(
  3452. 'id' => $row['id_rule'],
  3453. 'name' => $row['rule_name'],
  3454. 'criteria' => unserialize($row['criteria']),
  3455. 'actions' => unserialize($row['actions']),
  3456. 'delete' => $row['delete_pm'],
  3457. 'logic' => $row['is_or'] ? 'or' : 'and',
  3458. );
  3459. if ($row['delete_pm'])
  3460. $context['rules'][$row['id_rule']]['actions'][] = array('t' => 'del', 'v' => 1);
  3461. }
  3462. $smcFunc['db_free_result']($request);
  3463. }
  3464. /**
  3465. * Check if the PM is available to the current user.
  3466. *
  3467. * @param int $pmID
  3468. * @param $validFor
  3469. * @return boolean
  3470. */
  3471. function isAccessiblePM($pmID, $validFor = 'in_or_outbox')
  3472. {
  3473. global $user_info, $smcFunc;
  3474. $request = $smcFunc['db_query']('', '
  3475. SELECT
  3476. pm.id_member_from = {int:id_current_member} AND pm.deleted_by_sender = {int:not_deleted} AS valid_for_outbox,
  3477. pmr.id_pm IS NOT NULL AS valid_for_inbox
  3478. FROM {db_prefix}personal_messages AS pm
  3479. LEFT JOIN {db_prefix}pm_recipients AS pmr ON (pmr.id_pm = pm.id_pm AND pmr.id_member = {int:id_current_member} AND pmr.deleted = {int:not_deleted})
  3480. WHERE pm.id_pm = {int:id_pm}
  3481. AND ((pm.id_member_from = {int:id_current_member} AND pm.deleted_by_sender = {int:not_deleted}) OR pmr.id_pm IS NOT NULL)',
  3482. array(
  3483. 'id_pm' => $pmID,
  3484. 'id_current_member' => $user_info['id'],
  3485. 'not_deleted' => 0,
  3486. )
  3487. );
  3488. if ($smcFunc['db_num_rows']($request) === 0)
  3489. {
  3490. $smcFunc['db_free_result']($request);
  3491. return false;
  3492. }
  3493. $validationResult = $smcFunc['db_fetch_assoc']($request);
  3494. $smcFunc['db_free_result']($request);
  3495. switch ($validFor)
  3496. {
  3497. case 'inbox':
  3498. return !empty($validationResult['valid_for_inbox']);
  3499. break;
  3500. case 'outbox':
  3501. return !empty($validationResult['valid_for_outbox']);
  3502. break;
  3503. case 'in_or_outbox':
  3504. return !empty($validationResult['valid_for_inbox']) || !empty($validationResult['valid_for_outbox']);
  3505. break;
  3506. default:
  3507. trigger_error('Undefined validation type given', E_USER_ERROR);
  3508. break;
  3509. }
  3510. }
  3511. ?>