[ Index ] |
PHP Cross Reference of Unnamed Project |
[Summary view] [Print] [Text view]
1 <?php 2 /*************************************************************************** 3 * admin_users.php 4 * ------------------- 5 * begin : Saturday, Feb 13, 2001 6 * copyright : (C) 2001 The phpBB Group 7 * email : support@phpbb.com 8 * 9 * $Id: admin_users.php 6981 2007-02-10 12:14:24Z acydburn $ 10 * 11 * 12 ***************************************************************************/ 13 14 /*************************************************************************** 15 * 16 * This program is free software; you can redistribute it and/or modify 17 * it under the terms of the GNU General Public License as published by 18 * the Free Software Foundation; either version 2 of the License, or 19 * (at your option) any later version. 20 * 21 ***************************************************************************/ 22 23 define('IN_PHPBB', 1); 24 25 if( !empty($setmodules) ) 26 { 27 $filename = basename(__FILE__); 28 $module['Users']['Manage'] = $filename; 29 30 return; 31 } 32 33 $phpbb_root_path = './../'; 34 require ($phpbb_root_path . 'extension.inc'); 35 require('./pagestart.' . $phpEx); 36 require($phpbb_root_path . 'includes/bbcode.'.$phpEx); 37 require($phpbb_root_path . 'includes/functions_post.'.$phpEx); 38 require($phpbb_root_path . 'includes/functions_selects.'.$phpEx); 39 require($phpbb_root_path . 'includes/functions_validate.'.$phpEx); 40 41 $html_entities_match = array('#<#', '#>#'); 42 $html_entities_replace = array('<', '>'); 43 44 // 45 // Set mode 46 // 47 if( isset( $HTTP_POST_VARS['mode'] ) || isset( $HTTP_GET_VARS['mode'] ) ) 48 { 49 $mode = ( isset( $HTTP_POST_VARS['mode']) ) ? $HTTP_POST_VARS['mode'] : $HTTP_GET_VARS['mode']; 50 $mode = htmlspecialchars($mode); 51 } 52 else 53 { 54 $mode = ''; 55 } 56 57 // 58 // Begin program 59 // 60 if ( $mode == 'edit' || $mode == 'save' && ( isset($HTTP_POST_VARS['username']) || isset($HTTP_GET_VARS[POST_USERS_URL]) || isset( $HTTP_POST_VARS[POST_USERS_URL]) ) ) 61 { 62 // 63 // Ok, the profile has been modified and submitted, let's update 64 // 65 if ( ( $mode == 'save' && isset( $HTTP_POST_VARS['submit'] ) ) || isset( $HTTP_POST_VARS['avatargallery'] ) || isset( $HTTP_POST_VARS['submitavatar'] ) || isset( $HTTP_POST_VARS['cancelavatar'] ) ) 66 { 67 $user_id = intval($HTTP_POST_VARS['id']); 68 69 if (!($this_userdata = get_userdata($user_id))) 70 { 71 message_die(GENERAL_MESSAGE, $lang['No_user_id_specified'] ); 72 } 73 74 if( $HTTP_POST_VARS['deleteuser'] && ( $userdata['user_id'] != $user_id ) ) 75 { 76 $sql = "SELECT g.group_id 77 FROM " . USER_GROUP_TABLE . " ug, " . GROUPS_TABLE . " g 78 WHERE ug.user_id = $user_id 79 AND g.group_id = ug.group_id 80 AND g.group_single_user = 1"; 81 if( !($result = $db->sql_query($sql)) ) 82 { 83 message_die(GENERAL_ERROR, 'Could not obtain group information for this user', '', __LINE__, __FILE__, $sql); 84 } 85 86 $row = $db->sql_fetchrow($result); 87 88 $sql = "UPDATE " . POSTS_TABLE . " 89 SET poster_id = " . DELETED . ", post_username = '" . str_replace("\\'", "''", addslashes($this_userdata['username'])) . "' 90 WHERE poster_id = $user_id"; 91 if( !$db->sql_query($sql) ) 92 { 93 message_die(GENERAL_ERROR, 'Could not update posts for this user', '', __LINE__, __FILE__, $sql); 94 } 95 96 $sql = "UPDATE " . TOPICS_TABLE . " 97 SET topic_poster = " . DELETED . " 98 WHERE topic_poster = $user_id"; 99 if( !$db->sql_query($sql) ) 100 { 101 message_die(GENERAL_ERROR, 'Could not update topics for this user', '', __LINE__, __FILE__, $sql); 102 } 103 104 $sql = "UPDATE " . VOTE_USERS_TABLE . " 105 SET vote_user_id = " . DELETED . " 106 WHERE vote_user_id = $user_id"; 107 if( !$db->sql_query($sql) ) 108 { 109 message_die(GENERAL_ERROR, 'Could not update votes for this user', '', __LINE__, __FILE__, $sql); 110 } 111 112 $sql = "UPDATE " . GROUPS_TABLE . " 113 SET group_moderator = " . $userdata['user_id'] . " 114 WHERE group_moderator = $user_id"; 115 if( !$db->sql_query($sql) ) 116 { 117 message_die(GENERAL_ERROR, 'Could not update group moderators', '', __LINE__, __FILE__, $sql); 118 } 119 120 $sql = "DELETE FROM " . USERS_TABLE . " 121 WHERE user_id = $user_id"; 122 if( !$db->sql_query($sql) ) 123 { 124 message_die(GENERAL_ERROR, 'Could not delete user', '', __LINE__, __FILE__, $sql); 125 } 126 127 $sql = "DELETE FROM " . USER_GROUP_TABLE . " 128 WHERE user_id = $user_id"; 129 if( !$db->sql_query($sql) ) 130 { 131 message_die(GENERAL_ERROR, 'Could not delete user from user_group table', '', __LINE__, __FILE__, $sql); 132 } 133 134 $sql = "DELETE FROM " . GROUPS_TABLE . " 135 WHERE group_id = " . $row['group_id']; 136 if( !$db->sql_query($sql) ) 137 { 138 message_die(GENERAL_ERROR, 'Could not delete group for this user', '', __LINE__, __FILE__, $sql); 139 } 140 141 $sql = "DELETE FROM " . AUTH_ACCESS_TABLE . " 142 WHERE group_id = " . $row['group_id']; 143 if( !$db->sql_query($sql) ) 144 { 145 message_die(GENERAL_ERROR, 'Could not delete group for this user', '', __LINE__, __FILE__, $sql); 146 } 147 148 $sql = "DELETE FROM " . TOPICS_WATCH_TABLE . " 149 WHERE user_id = $user_id"; 150 if ( !$db->sql_query($sql) ) 151 { 152 message_die(GENERAL_ERROR, 'Could not delete user from topic watch table', '', __LINE__, __FILE__, $sql); 153 } 154 155 $sql = "DELETE FROM " . BANLIST_TABLE . " 156 WHERE ban_userid = $user_id"; 157 if ( !$db->sql_query($sql) ) 158 { 159 message_die(GENERAL_ERROR, 'Could not delete user from banlist table', '', __LINE__, __FILE__, $sql); 160 } 161 162 $sql = "DELETE FROM " . SESSIONS_TABLE . " 163 WHERE session_user_id = $user_id"; 164 if ( !$db->sql_query($sql) ) 165 { 166 message_die(GENERAL_ERROR, 'Could not delete sessions for this user', '', __LINE__, __FILE__, $sql); 167 } 168 169 $sql = "DELETE FROM " . SESSIONS_KEYS_TABLE . " 170 WHERE user_id = $user_id"; 171 if ( !$db->sql_query($sql) ) 172 { 173 message_die(GENERAL_ERROR, 'Could not delete auto-login keys for this user', '', __LINE__, __FILE__, $sql); 174 } 175 176 $sql = "SELECT privmsgs_id 177 FROM " . PRIVMSGS_TABLE . " 178 WHERE privmsgs_from_userid = $user_id 179 OR privmsgs_to_userid = $user_id"; 180 if ( !($result = $db->sql_query($sql)) ) 181 { 182 message_die(GENERAL_ERROR, 'Could not select all users private messages', '', __LINE__, __FILE__, $sql); 183 } 184 185 // This little bit of code directly from the private messaging section. 186 while ( $row_privmsgs = $db->sql_fetchrow($result) ) 187 { 188 $mark_list[] = $row_privmsgs['privmsgs_id']; 189 } 190 191 if ( count($mark_list) ) 192 { 193 $delete_sql_id = implode(', ', $mark_list); 194 195 $delete_text_sql = "DELETE FROM " . PRIVMSGS_TEXT_TABLE . " 196 WHERE privmsgs_text_id IN ($delete_sql_id)"; 197 $delete_sql = "DELETE FROM " . PRIVMSGS_TABLE . " 198 WHERE privmsgs_id IN ($delete_sql_id)"; 199 200 if ( !$db->sql_query($delete_sql) ) 201 { 202 message_die(GENERAL_ERROR, 'Could not delete private message info', '', __LINE__, __FILE__, $delete_sql); 203 } 204 205 if ( !$db->sql_query($delete_text_sql) ) 206 { 207 message_die(GENERAL_ERROR, 'Could not delete private message text', '', __LINE__, __FILE__, $delete_text_sql); 208 } 209 } 210 211 $message = $lang['User_deleted'] . '<br /><br />' . sprintf($lang['Click_return_useradmin'], '<a href="' . append_sid("admin_users.$phpEx") . '">', '</a>') . '<br /><br />' . sprintf($lang['Click_return_admin_index'], '<a href="' . append_sid("index.$phpEx?pane=right") . '">', '</a>'); 212 213 message_die(GENERAL_MESSAGE, $message); 214 } 215 216 $username = ( !empty($HTTP_POST_VARS['username']) ) ? phpbb_clean_username($HTTP_POST_VARS['username']) : ''; 217 $email = ( !empty($HTTP_POST_VARS['email']) ) ? trim(strip_tags(htmlspecialchars( $HTTP_POST_VARS['email'] ) )) : ''; 218 219 $password = ( !empty($HTTP_POST_VARS['password']) ) ? trim(strip_tags(htmlspecialchars( $HTTP_POST_VARS['password'] ) )) : ''; 220 $password_confirm = ( !empty($HTTP_POST_VARS['password_confirm']) ) ? trim(strip_tags(htmlspecialchars( $HTTP_POST_VARS['password_confirm'] ) )) : ''; 221 222 $icq = ( !empty($HTTP_POST_VARS['icq']) ) ? trim(strip_tags( $HTTP_POST_VARS['icq'] ) ) : ''; 223 $aim = ( !empty($HTTP_POST_VARS['aim']) ) ? trim(strip_tags( $HTTP_POST_VARS['aim'] ) ) : ''; 224 $msn = ( !empty($HTTP_POST_VARS['msn']) ) ? trim(strip_tags( $HTTP_POST_VARS['msn'] ) ) : ''; 225 $yim = ( !empty($HTTP_POST_VARS['yim']) ) ? trim(strip_tags( $HTTP_POST_VARS['yim'] ) ) : ''; 226 227 $website = ( !empty($HTTP_POST_VARS['website']) ) ? trim(strip_tags( $HTTP_POST_VARS['website'] ) ) : ''; 228 $location = ( !empty($HTTP_POST_VARS['location']) ) ? trim(strip_tags( $HTTP_POST_VARS['location'] ) ) : ''; 229 $occupation = ( !empty($HTTP_POST_VARS['occupation']) ) ? trim(strip_tags( $HTTP_POST_VARS['occupation'] ) ) : ''; 230 $interests = ( !empty($HTTP_POST_VARS['interests']) ) ? trim(strip_tags( $HTTP_POST_VARS['interests'] ) ) : ''; 231 $signature = ( !empty($HTTP_POST_VARS['signature']) ) ? trim(str_replace('<br />', "\n", $HTTP_POST_VARS['signature'] ) ) : ''; 232 233 validate_optional_fields($icq, $aim, $msn, $yim, $website, $location, $occupation, $interests, $signature); 234 235 $viewemail = ( isset( $HTTP_POST_VARS['viewemail']) ) ? ( ( $HTTP_POST_VARS['viewemail'] ) ? TRUE : 0 ) : 0; 236 $allowviewonline = ( isset( $HTTP_POST_VARS['hideonline']) ) ? ( ( $HTTP_POST_VARS['hideonline'] ) ? 0 : TRUE ) : TRUE; 237 $notifyreply = ( isset( $HTTP_POST_VARS['notifyreply']) ) ? ( ( $HTTP_POST_VARS['notifyreply'] ) ? TRUE : 0 ) : 0; 238 $notifypm = ( isset( $HTTP_POST_VARS['notifypm']) ) ? ( ( $HTTP_POST_VARS['notifypm'] ) ? TRUE : 0 ) : TRUE; 239 $popuppm = ( isset( $HTTP_POST_VARS['popup_pm']) ) ? ( ( $HTTP_POST_VARS['popup_pm'] ) ? TRUE : 0 ) : TRUE; 240 $attachsig = ( isset( $HTTP_POST_VARS['attachsig']) ) ? ( ( $HTTP_POST_VARS['attachsig'] ) ? TRUE : 0 ) : 0; 241 242 $allowhtml = ( isset( $HTTP_POST_VARS['allowhtml']) ) ? intval( $HTTP_POST_VARS['allowhtml'] ) : $board_config['allow_html']; 243 $allowbbcode = ( isset( $HTTP_POST_VARS['allowbbcode']) ) ? intval( $HTTP_POST_VARS['allowbbcode'] ) : $board_config['allow_bbcode']; 244 $allowsmilies = ( isset( $HTTP_POST_VARS['allowsmilies']) ) ? intval( $HTTP_POST_VARS['allowsmilies'] ) : $board_config['allow_smilies']; 245 246 $user_style = ( isset( $HTTP_POST_VARS['style'] ) ) ? intval( $HTTP_POST_VARS['style'] ) : $board_config['default_style']; 247 $user_lang = ( $HTTP_POST_VARS['language'] ) ? $HTTP_POST_VARS['language'] : $board_config['default_lang']; 248 $user_timezone = ( isset( $HTTP_POST_VARS['timezone']) ) ? doubleval( $HTTP_POST_VARS['timezone'] ) : $board_config['board_timezone']; 249 $user_dateformat = ( $HTTP_POST_VARS['dateformat'] ) ? trim( $HTTP_POST_VARS['dateformat'] ) : $board_config['default_dateformat']; 250 251 $user_avatar_local = ( isset( $HTTP_POST_VARS['avatarselect'] ) && !empty($HTTP_POST_VARS['submitavatar'] ) && $board_config['allow_avatar_local'] ) ? $HTTP_POST_VARS['avatarselect'] : ( ( isset( $HTTP_POST_VARS['avatarlocal'] ) ) ? $HTTP_POST_VARS['avatarlocal'] : '' ); 252 $user_avatar_category = ( isset($HTTP_POST_VARS['avatarcatname']) && $board_config['allow_avatar_local'] ) ? htmlspecialchars($HTTP_POST_VARS['avatarcatname']) : '' ; 253 254 $user_avatar_remoteurl = ( !empty($HTTP_POST_VARS['avatarremoteurl']) ) ? trim( $HTTP_POST_VARS['avatarremoteurl'] ) : ''; 255 $user_avatar_url = ( !empty($HTTP_POST_VARS['avatarurl']) ) ? trim( $HTTP_POST_VARS['avatarurl'] ) : ''; 256 $user_avatar_loc = ( $HTTP_POST_FILES['avatar']['tmp_name'] != "none") ? $HTTP_POST_FILES['avatar']['tmp_name'] : ''; 257 $user_avatar_name = ( !empty($HTTP_POST_FILES['avatar']['name']) ) ? $HTTP_POST_FILES['avatar']['name'] : ''; 258 $user_avatar_size = ( !empty($HTTP_POST_FILES['avatar']['size']) ) ? $HTTP_POST_FILES['avatar']['size'] : 0; 259 $user_avatar_filetype = ( !empty($HTTP_POST_FILES['avatar']['type']) ) ? $HTTP_POST_FILES['avatar']['type'] : ''; 260 261 $user_avatar = ( empty($user_avatar_loc) ) ? $this_userdata['user_avatar'] : ''; 262 $user_avatar_type = ( empty($user_avatar_loc) ) ? $this_userdata['user_avatar_type'] : ''; 263 264 $user_status = ( !empty($HTTP_POST_VARS['user_status']) ) ? intval( $HTTP_POST_VARS['user_status'] ) : 0; 265 $user_allowpm = ( !empty($HTTP_POST_VARS['user_allowpm']) ) ? intval( $HTTP_POST_VARS['user_allowpm'] ) : 0; 266 $user_rank = ( !empty($HTTP_POST_VARS['user_rank']) ) ? intval( $HTTP_POST_VARS['user_rank'] ) : 0; 267 $user_allowavatar = ( !empty($HTTP_POST_VARS['user_allowavatar']) ) ? intval( $HTTP_POST_VARS['user_allowavatar'] ) : 0; 268 269 if( isset( $HTTP_POST_VARS['avatargallery'] ) || isset( $HTTP_POST_VARS['submitavatar'] ) || isset( $HTTP_POST_VARS['cancelavatar'] ) ) 270 { 271 $username = stripslashes($username); 272 $email = stripslashes($email); 273 $password = ''; 274 $password_confirm = ''; 275 276 $icq = stripslashes($icq); 277 $aim = htmlspecialchars(stripslashes($aim)); 278 $msn = htmlspecialchars(stripslashes($msn)); 279 $yim = htmlspecialchars(stripslashes($yim)); 280 281 $website = htmlspecialchars(stripslashes($website)); 282 $location = htmlspecialchars(stripslashes($location)); 283 $occupation = htmlspecialchars(stripslashes($occupation)); 284 $interests = htmlspecialchars(stripslashes($interests)); 285 $signature = htmlspecialchars(stripslashes($signature)); 286 287 $user_lang = stripslashes($user_lang); 288 $user_dateformat = htmlspecialchars(stripslashes($user_dateformat)); 289 290 if ( !isset($HTTP_POST_VARS['cancelavatar'])) 291 { 292 $user_avatar = $user_avatar_category . '/' . $user_avatar_local; 293 $user_avatar_type = USER_AVATAR_GALLERY; 294 } 295 } 296 } 297 298 if( isset( $HTTP_POST_VARS['submit'] ) ) 299 { 300 include($phpbb_root_path . 'includes/usercp_avatar.'.$phpEx); 301 302 $error = FALSE; 303 304 if (stripslashes($username) != $this_userdata['username']) 305 { 306 unset($rename_user); 307 308 if ( stripslashes(strtolower($username)) != strtolower($this_userdata['username']) ) 309 { 310 $result = validate_username($username); 311 if ( $result['error'] ) 312 { 313 $error = TRUE; 314 $error_msg .= ( ( isset($error_msg) ) ? '<br />' : '' ) . $result['error_msg']; 315 } 316 else if ( strtolower(str_replace("\\'", "''", $username)) == strtolower($userdata['username']) ) 317 { 318 $error = TRUE; 319 $error_msg .= ( ( isset($error_msg) ) ? '<br />' : '' ) . $lang['Username_taken']; 320 } 321 } 322 323 if (!$error) 324 { 325 $username_sql = "username = '" . str_replace("\\'", "''", $username) . "', "; 326 $rename_user = $username; // Used for renaming usergroup 327 } 328 } 329 330 $passwd_sql = ''; 331 if( !empty($password) && !empty($password_confirm) ) 332 { 333 // 334 // Awww, the user wants to change their password, isn't that cute.. 335 // 336 if($password != $password_confirm) 337 { 338 $error = TRUE; 339 $error_msg .= ( ( isset($error_msg) ) ? '<br />' : '' ) . $lang['Password_mismatch']; 340 } 341 else 342 { 343 $password = md5($password); 344 $passwd_sql = "user_password = '$password', "; 345 } 346 } 347 else if( $password && !$password_confirm ) 348 { 349 $error = TRUE; 350 $error_msg .= ( ( isset($error_msg) ) ? '<br />' : '' ) . $lang['Password_mismatch']; 351 } 352 else if( !$password && $password_confirm ) 353 { 354 $error = TRUE; 355 $error_msg .= ( ( isset($error_msg) ) ? '<br />' : '' ) . $lang['Password_mismatch']; 356 } 357 358 if ($signature != '') 359 { 360 $sig_length_check = preg_replace('/(\[.*?)(=.*?)\]/is', '\\1]', stripslashes($signature)); 361 if ( $allowhtml ) 362 { 363 $sig_length_check = preg_replace('/(\<.*?)(=.*?)( .*?=.*?)?([ \/]?\>)/is', '\\1\\3\\4', $sig_length_check); 364 } 365 366 // Only create a new bbcode_uid when there was no uid yet. 367 if ( $signature_bbcode_uid == '' ) 368 { 369 $signature_bbcode_uid = ( $allowbbcode ) ? make_bbcode_uid() : ''; 370 } 371 $signature = prepare_message($signature, $allowhtml, $allowbbcode, $allowsmilies, $signature_bbcode_uid); 372 373 if ( strlen($sig_length_check) > $board_config['max_sig_chars'] ) 374 { 375 $error = TRUE; 376 $error_msg .= ( ( isset($error_msg) ) ? '<br />' : '' ) . $lang['Signature_too_long']; 377 } 378 } 379 380 // 381 // Avatar stuff 382 // 383 $avatar_sql = ""; 384 if( isset($HTTP_POST_VARS['avatardel']) ) 385 { 386 if( $this_userdata['user_avatar_type'] == USER_AVATAR_UPLOAD && $this_userdata['user_avatar'] != "" ) 387 { 388 if( @file_exists(@phpbb_realpath('./../' . $board_config['avatar_path'] . "/" . $this_userdata['user_avatar'])) ) 389 { 390 @unlink('./../' . $board_config['avatar_path'] . "/" . $this_userdata['user_avatar']); 391 } 392 } 393 $avatar_sql = ", user_avatar = '', user_avatar_type = " . USER_AVATAR_NONE; 394 } 395 else if( ( $user_avatar_loc != "" || !empty($user_avatar_url) ) && !$error ) 396 { 397 // 398 // Only allow one type of upload, either a 399 // filename or a URL 400 // 401 if( !empty($user_avatar_loc) && !empty($user_avatar_url) ) 402 { 403 $error = TRUE; 404 if( isset($error_msg) ) 405 { 406 $error_msg .= "<br />"; 407 } 408 $error_msg .= $lang['Only_one_avatar']; 409 } 410 411 if( $user_avatar_loc != "" ) 412 { 413 if( file_exists(@phpbb_realpath($user_avatar_loc)) && ereg(".jpg$|.gif$|.png$", $user_avatar_name) ) 414 { 415 if( $user_avatar_size <= $board_config['avatar_filesize'] && $user_avatar_size > 0) 416 { 417 $error_type = false; 418 419 // 420 // Opera appends the image name after the type, not big, not clever! 421 // 422 preg_match("'image\/[x\-]*([a-z]+)'", $user_avatar_filetype, $user_avatar_filetype); 423 $user_avatar_filetype = $user_avatar_filetype[1]; 424 425 switch( $user_avatar_filetype ) 426 { 427 case "jpeg": 428 case "pjpeg": 429 case "jpg": 430 $imgtype = '.jpg'; 431 break; 432 case "gif": 433 $imgtype = '.gif'; 434 break; 435 case "png": 436 $imgtype = '.png'; 437 break; 438 default: 439 $error = true; 440 $error_msg = (!empty($error_msg)) ? $error_msg . "<br />" . $lang['Avatar_filetype'] : $lang['Avatar_filetype']; 441 break; 442 } 443 444 if( !$error ) 445 { 446 list($width, $height) = @getimagesize($user_avatar_loc); 447 448 if( $width <= $board_config['avatar_max_width'] && $height <= $board_config['avatar_max_height'] ) 449 { 450 $user_id = $this_userdata['user_id']; 451 452 $avatar_filename = $user_id . $imgtype; 453 454 if( $this_userdata['user_avatar_type'] == USER_AVATAR_UPLOAD && $this_userdata['user_avatar'] != "" ) 455 { 456 if( @file_exists(@phpbb_realpath("./../" . $board_config['avatar_path'] . "/" . $this_userdata['user_avatar'])) ) 457 { 458 @unlink("./../" . $board_config['avatar_path'] . "/". $this_userdata['user_avatar']); 459 } 460 } 461 @copy($user_avatar_loc, "./../" . $board_config['avatar_path'] . "/$avatar_filename"); 462 463 $avatar_sql = ", user_avatar = '$avatar_filename', user_avatar_type = " . USER_AVATAR_UPLOAD; 464 } 465 else 466 { 467 $l_avatar_size = sprintf($lang['Avatar_imagesize'], $board_config['avatar_max_width'], $board_config['avatar_max_height']); 468 469 $error = true; 470 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $l_avatar_size : $l_avatar_size; 471 } 472 } 473 } 474 else 475 { 476 $l_avatar_size = sprintf($lang['Avatar_filesize'], round($board_config['avatar_filesize'] / 1024)); 477 478 $error = true; 479 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $l_avatar_size : $l_avatar_size; 480 } 481 } 482 else 483 { 484 $error = true; 485 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $lang['Avatar_filetype'] : $lang['Avatar_filetype']; 486 } 487 } 488 else if( !empty($user_avatar_url) ) 489 { 490 // 491 // First check what port we should connect 492 // to, look for a :[xxxx]/ or, if that doesn't 493 // exist assume port 80 (http) 494 // 495 preg_match("/^(http:\/\/)?([\w\-\.]+)\:?([0-9]*)\/(.*)$/", $user_avatar_url, $url_ary); 496 497 if( !empty($url_ary[4]) ) 498 { 499 $port = (!empty($url_ary[3])) ? $url_ary[3] : 80; 500 501 $fsock = @fsockopen($url_ary[2], $port, $errno, $errstr); 502 if( $fsock ) 503 { 504 $base_get = "/" . $url_ary[4]; 505 506 // 507 // Uses HTTP 1.1, could use HTTP 1.0 ... 508 // 509 @fputs($fsock, "GET $base_get HTTP/1.1\r\n"); 510 @fputs($fsock, "HOST: " . $url_ary[2] . "\r\n"); 511 @fputs($fsock, "Connection: close\r\n\r\n"); 512 513 unset($avatar_data); 514 while( !@feof($fsock) ) 515 { 516 $avatar_data .= @fread($fsock, $board_config['avatar_filesize']); 517 } 518 @fclose($fsock); 519 520 if( preg_match("/Content-Length\: ([0-9]+)[^\/ ][\s]+/i", $avatar_data, $file_data1) && preg_match("/Content-Type\: image\/[x\-]*([a-z]+)[\s]+/i", $avatar_data, $file_data2) ) 521 { 522 $file_size = $file_data1[1]; 523 $file_type = $file_data2[1]; 524 525 switch( $file_type ) 526 { 527 case "jpeg": 528 case "pjpeg": 529 case "jpg": 530 $imgtype = '.jpg'; 531 break; 532 case "gif": 533 $imgtype = '.gif'; 534 break; 535 case "png": 536 $imgtype = '.png'; 537 break; 538 default: 539 $error = true; 540 $error_msg = (!empty($error_msg)) ? $error_msg . "<br />" . $lang['Avatar_filetype'] : $lang['Avatar_filetype']; 541 break; 542 } 543 544 if( !$error && $file_size > 0 && $file_size < $board_config['avatar_filesize'] ) 545 { 546 $avatar_data = substr($avatar_data, strlen($avatar_data) - $file_size, $file_size); 547 548 $tmp_filename = tempnam ("/tmp", $this_userdata['user_id'] . "-"); 549 $fptr = @fopen($tmp_filename, "wb"); 550 $bytes_written = @fwrite($fptr, $avatar_data, $file_size); 551 @fclose($fptr); 552 553 if( $bytes_written == $file_size ) 554 { 555 list($width, $height) = @getimagesize($tmp_filename); 556 557 if( $width <= $board_config['avatar_max_width'] && $height <= $board_config['avatar_max_height'] ) 558 { 559 $user_id = $this_userdata['user_id']; 560 561 $avatar_filename = $user_id . $imgtype; 562 563 if( $this_userdata['user_avatar_type'] == USER_AVATAR_UPLOAD && $this_userdata['user_avatar'] != "") 564 { 565 if( file_exists(@phpbb_realpath("./../" . $board_config['avatar_path'] . "/" . $this_userdata['user_avatar'])) ) 566 { 567 @unlink("./../" . $board_config['avatar_path'] . "/" . $this_userdata['user_avatar']); 568 } 569 } 570 @copy($tmp_filename, "./../" . $board_config['avatar_path'] . "/$avatar_filename"); 571 @unlink($tmp_filename); 572 573 $avatar_sql = ", user_avatar = '$avatar_filename', user_avatar_type = " . USER_AVATAR_UPLOAD; 574 } 575 else 576 { 577 $l_avatar_size = sprintf($lang['Avatar_imagesize'], $board_config['avatar_max_width'], $board_config['avatar_max_height']); 578 579 $error = true; 580 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $l_avatar_size : $l_avatar_size; 581 } 582 } 583 else 584 { 585 // 586 // Error writing file 587 // 588 @unlink($tmp_filename); 589 message_die(GENERAL_ERROR, "Could not write avatar file to local storage. Please contact the board administrator with this message", "", __LINE__, __FILE__); 590 } 591 } 592 } 593 else 594 { 595 // 596 // No data 597 // 598 $error = true; 599 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $lang['File_no_data'] : $lang['File_no_data']; 600 } 601 } 602 else 603 { 604 // 605 // No connection 606 // 607 $error = true; 608 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $lang['No_connection_URL'] : $lang['No_connection_URL']; 609 } 610 } 611 else 612 { 613 $error = true; 614 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $lang['Incomplete_URL'] : $lang['Incomplete_URL']; 615 } 616 } 617 else if( !empty($user_avatar_name) ) 618 { 619 $l_avatar_size = sprintf($lang['Avatar_filesize'], round($board_config['avatar_filesize'] / 1024)); 620 621 $error = true; 622 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $l_avatar_size : $l_avatar_size; 623 } 624 } 625 else if( $user_avatar_remoteurl != "" && $avatar_sql == "" && !$error ) 626 { 627 if( !preg_match("#^http:\/\/#i", $user_avatar_remoteurl) ) 628 { 629 $user_avatar_remoteurl = "http://" . $user_avatar_remoteurl; 630 } 631 632 if( preg_match("#^(http:\/\/[a-z0-9\-]+?\.([a-z0-9\-]+\.)*[a-z]+\/.*?\.(gif|jpg|png)$)#is", $user_avatar_remoteurl) ) 633 { 634 $avatar_sql = ", user_avatar = '" . str_replace("\'", "''", $user_avatar_remoteurl) . "', user_avatar_type = " . USER_AVATAR_REMOTE; 635 } 636 else 637 { 638 $error = true; 639 $error_msg = ( !empty($error_msg) ) ? $error_msg . "<br />" . $lang['Wrong_remote_avatar_format'] : $lang['Wrong_remote_avatar_format']; 640 } 641 } 642 else if( $user_avatar_local != "" && $avatar_sql == "" && !$error ) 643 { 644 $avatar_sql = ", user_avatar = '" . str_replace("\'", "''", phpbb_ltrim(basename($user_avatar_category), "'") . '/' . phpbb_ltrim(basename($user_avatar_local), "'")) . "', user_avatar_type = " . USER_AVATAR_GALLERY; 645 } 646 647 // 648 // Update entry in DB 649 // 650 if( !$error ) 651 { 652 $sql = "UPDATE " . USERS_TABLE . " 653 SET " . $username_sql . $passwd_sql . "user_email = '" . str_replace("\'", "''", $email) . "', user_icq = '" . str_replace("\'", "''", $icq) . "', user_website = '" . str_replace("\'", "''", $website) . "', user_occ = '" . str_replace("\'", "''", $occupation) . "', user_from = '" . str_replace("\'", "''", $location) . "', user_interests = '" . str_replace("\'", "''", $interests) . "', user_sig = '" . str_replace("\'", "''", $signature) . "', user_viewemail = $viewemail, user_aim = '" . str_replace("\'", "''", $aim) . "', user_yim = '" . str_replace("\'", "''", $yim) . "', user_msnm = '" . str_replace("\'", "''", $msn) . "', user_attachsig = $attachsig, user_sig_bbcode_uid = '$signature_bbcode_uid', user_allowsmile = $allowsmilies, user_allowhtml = $allowhtml, user_allowavatar = $user_allowavatar, user_allowbbcode = $allowbbcode, user_allow_viewonline = $allowviewonline, user_notify = $notifyreply, user_allow_pm = $user_allowpm, user_notify_pm = $notifypm, user_popup_pm = $popuppm, user_lang = '" . str_replace("\'", "''", $user_lang) . "', user_style = $user_style, user_timezone = $user_timezone, user_dateformat = '" . str_replace("\'", "''", $user_dateformat) . "', user_active = $user_status, user_rank = $user_rank" . $avatar_sql . " 654 WHERE user_id = $user_id"; 655 656 if( $result = $db->sql_query($sql) ) 657 { 658 if( isset($rename_user) ) 659 { 660 $sql = "UPDATE " . GROUPS_TABLE . " 661 SET group_name = '".str_replace("\'", "''", $rename_user)."' 662 WHERE group_name = '".str_replace("'", "''", $this_userdata['username'] )."'"; 663 if( !$result = $db->sql_query($sql) ) 664 { 665 message_die(GENERAL_ERROR, 'Could not rename users group', '', __LINE__, __FILE__, $sql); 666 } 667 } 668 669 // Delete user session, to prevent the user navigating the forum (if logged in) when disabled 670 if (!$user_status) 671 { 672 $sql = "DELETE FROM " . SESSIONS_TABLE . " 673 WHERE session_user_id = " . $user_id; 674 675 if ( !$db->sql_query($sql) ) 676 { 677 message_die(GENERAL_ERROR, 'Error removing user session', '', __LINE__, __FILE__, $sql); 678 } 679 } 680 681 // We remove all stored login keys since the password has been updated 682 // and change the current one (if applicable) 683 if ( !empty($passwd_sql) ) 684 { 685 session_reset_keys($user_id, $user_ip); 686 } 687 688 $message .= $lang['Admin_user_updated']; 689 } 690 else 691 { 692 message_die(GENERAL_ERROR, 'Admin_user_fail', '', __LINE__, __FILE__, $sql); 693 } 694 695 $message .= '<br /><br />' . sprintf($lang['Click_return_useradmin'], '<a href="' . append_sid("admin_users.$phpEx") . '">', '</a>') . '<br /><br />' . sprintf($lang['Click_return_admin_index'], '<a href="' . append_sid("index.$phpEx?pane=right") . '">', '</a>'); 696 697 message_die(GENERAL_MESSAGE, $message); 698 } 699 else 700 { 701 $template->set_filenames(array( 702 'reg_header' => 'error_body.tpl') 703 ); 704 705 $template->assign_vars(array( 706 'ERROR_MESSAGE' => $error_msg) 707 ); 708 709 $template->assign_var_from_handle('ERROR_BOX', 'reg_header'); 710 711 $username = htmlspecialchars(stripslashes($username)); 712 $email = stripslashes($email); 713 $password = ''; 714 $password_confirm = ''; 715 716 $icq = stripslashes($icq); 717 $aim = htmlspecialchars(str_replace('+', ' ', stripslashes($aim))); 718 $msn = htmlspecialchars(stripslashes($msn)); 719 $yim = htmlspecialchars(stripslashes($yim)); 720 721 $website = htmlspecialchars(stripslashes($website)); 722 $location = htmlspecialchars(stripslashes($location)); 723 $occupation = htmlspecialchars(stripslashes($occupation)); 724 $interests = htmlspecialchars(stripslashes($interests)); 725 $signature = htmlspecialchars(stripslashes($signature)); 726 727 $user_lang = stripslashes($user_lang); 728 $user_dateformat = htmlspecialchars(stripslashes($user_dateformat)); 729 } 730 } 731 else if( !isset( $HTTP_POST_VARS['submit'] ) && $mode != 'save' && !isset( $HTTP_POST_VARS['avatargallery'] ) && !isset( $HTTP_POST_VARS['submitavatar'] ) && !isset( $HTTP_POST_VARS['cancelavatar'] ) ) 732 { 733 if( isset( $HTTP_GET_VARS[POST_USERS_URL]) || isset( $HTTP_POST_VARS[POST_USERS_URL]) ) 734 { 735 $user_id = ( isset( $HTTP_POST_VARS[POST_USERS_URL]) ) ? intval( $HTTP_POST_VARS[POST_USERS_URL]) : intval( $HTTP_GET_VARS[POST_USERS_URL]); 736 $this_userdata = get_userdata($user_id); 737 if( !$this_userdata ) 738 { 739 message_die(GENERAL_MESSAGE, $lang['No_user_id_specified'] ); 740 } 741 } 742 else 743 { 744 $this_userdata = get_userdata($HTTP_POST_VARS['username'], true); 745 if( !$this_userdata ) 746 { 747 message_die(GENERAL_MESSAGE, $lang['No_user_id_specified'] ); 748 } 749 } 750 751 // 752 // Now parse and display it as a template 753 // 754 $user_id = $this_userdata['user_id']; 755 $username = $this_userdata['username']; 756 $email = $this_userdata['user_email']; 757 $password = ''; 758 $password_confirm = ''; 759 760 $icq = $this_userdata['user_icq']; 761 $aim = htmlspecialchars(str_replace('+', ' ', $this_userdata['user_aim'] )); 762 $msn = htmlspecialchars($this_userdata['user_msnm']); 763 $yim = htmlspecialchars($this_userdata['user_yim']); 764 765 $website = htmlspecialchars($this_userdata['user_website']); 766 $location = htmlspecialchars($this_userdata['user_from']); 767 $occupation = htmlspecialchars($this_userdata['user_occ']); 768 $interests = htmlspecialchars($this_userdata['user_interests']); 769 770 $signature = ($this_userdata['user_sig_bbcode_uid'] != '') ? preg_replace('#:' . $this_userdata['user_sig_bbcode_uid'] . '#si', '', $this_userdata['user_sig']) : $this_userdata['user_sig']; 771 $signature = preg_replace($html_entities_match, $html_entities_replace, $signature); 772 773 $viewemail = $this_userdata['user_viewemail']; 774 $notifypm = $this_userdata['user_notify_pm']; 775 $popuppm = $this_userdata['user_popup_pm']; 776 $notifyreply = $this_userdata['user_notify']; 777 $attachsig = $this_userdata['user_attachsig']; 778 $allowhtml = $this_userdata['user_allowhtml']; 779 $allowbbcode = $this_userdata['user_allowbbcode']; 780 $allowsmilies = $this_userdata['user_allowsmile']; 781 $allowviewonline = $this_userdata['user_allow_viewonline']; 782 783 $user_avatar = $this_userdata['user_avatar']; 784 $user_avatar_type = $this_userdata['user_avatar_type']; 785 $user_style = $this_userdata['user_style']; 786 $user_lang = $this_userdata['user_lang']; 787 $user_timezone = $this_userdata['user_timezone']; 788 $user_dateformat = htmlspecialchars($this_userdata['user_dateformat']); 789 790 $user_status = $this_userdata['user_active']; 791 $user_allowavatar = $this_userdata['user_allowavatar']; 792 $user_allowpm = $this_userdata['user_allow_pm']; 793 794 $COPPA = false; 795 796 $html_status = ($this_userdata['user_allowhtml'] ) ? $lang['HTML_is_ON'] : $lang['HTML_is_OFF']; 797 $bbcode_status = ($this_userdata['user_allowbbcode'] ) ? $lang['BBCode_is_ON'] : $lang['BBCode_is_OFF']; 798 $smilies_status = ($this_userdata['user_allowsmile'] ) ? $lang['Smilies_are_ON'] : $lang['Smilies_are_OFF']; 799 } 800 801 if( isset($HTTP_POST_VARS['avatargallery']) && !$error ) 802 { 803 if( !$error ) 804 { 805 $user_id = intval($HTTP_POST_VARS['id']); 806 807 $template->set_filenames(array( 808 "body" => "admin/user_avatar_gallery.tpl") 809 ); 810 811 $dir = @opendir("../" . $board_config['avatar_gallery_path']); 812 813 $avatar_images = array(); 814 while( $file = @readdir($dir) ) 815 { 816 if( $file != "." && $file != ".." && !is_file(phpbb_realpath("./../" . $board_config['avatar_gallery_path'] . "/" . $file)) && !is_link(phpbb_realpath("./../" . $board_config['avatar_gallery_path'] . "/" . $file)) ) 817 { 818 $sub_dir = @opendir("../" . $board_config['avatar_gallery_path'] . "/" . $file); 819 820 $avatar_row_count = 0; 821 $avatar_col_count = 0; 822 823 while( $sub_file = @readdir($sub_dir) ) 824 { 825 if( preg_match("/(\.gif$|\.png$|\.jpg)$/is", $sub_file) ) 826 { 827 $avatar_images[$file][$avatar_row_count][$avatar_col_count] = $sub_file; 828 829 $avatar_col_count++; 830 if( $avatar_col_count == 5 ) 831 { 832 $avatar_row_count++; 833 $avatar_col_count = 0; 834 } 835 } 836 } 837 } 838 } 839 840 @closedir($dir); 841 842 if( isset($HTTP_POST_VARS['avatarcategory']) ) 843 { 844 $category = htmlspecialchars($HTTP_POST_VARS['avatarcategory']); 845 } 846 else 847 { 848 list($category, ) = each($avatar_images); 849 } 850 @reset($avatar_images); 851 852 $s_categories = ""; 853 while( list($key) = each($avatar_images) ) 854 { 855 $selected = ( $key == $category ) ? "selected=\"selected\"" : ""; 856 if( count($avatar_images[$key]) ) 857 { 858 $s_categories .= '<option value="' . $key . '"' . $selected . '>' . ucfirst($key) . '</option>'; 859 } 860 } 861 862 $s_colspan = 0; 863 for($i = 0; $i < count($avatar_images[$category]); $i++) 864 { 865 $template->assign_block_vars("avatar_row", array()); 866 867 $s_colspan = max($s_colspan, count($avatar_images[$category][$i])); 868 869 for($j = 0; $j < count($avatar_images[$category][$i]); $j++) 870 { 871 $template->assign_block_vars("avatar_row.avatar_column", array( 872 "AVATAR_IMAGE" => "../" . $board_config['avatar_gallery_path'] . '/' . $category . '/' . $avatar_images[$category][$i][$j]) 873 ); 874 875 $template->assign_block_vars("avatar_row.avatar_option_column", array( 876 "S_OPTIONS_AVATAR" => $avatar_images[$category][$i][$j]) 877 ); 878 } 879 } 880 881 $coppa = ( ( !$HTTP_POST_VARS['coppa'] && !$HTTP_GET_VARS['coppa'] ) || $mode == "register") ? 0 : TRUE; 882 883 $s_hidden_fields = '<input type="hidden" name="mode" value="edit" /><input type="hidden" name="agreed" value="true" /><input type="hidden" name="coppa" value="' . $coppa . '" /><input type="hidden" name="avatarcatname" value="' . $category . '" />'; 884 $s_hidden_fields .= '<input type="hidden" name="id" value="' . $user_id . '" />'; 885 886 $s_hidden_fields .= '<input type="hidden" name="username" value="' . str_replace("\"", """, $username) . '" />'; 887 $s_hidden_fields .= '<input type="hidden" name="email" value="' . str_replace("\"", """, $email) . '" />'; 888 $s_hidden_fields .= '<input type="hidden" name="icq" value="' . str_replace("\"", """, $icq) . '" />'; 889 $s_hidden_fields .= '<input type="hidden" name="aim" value="' . str_replace("\"", """, $aim) . '" />'; 890 $s_hidden_fields .= '<input type="hidden" name="msn" value="' . str_replace("\"", """, $msn) . '" />'; 891 $s_hidden_fields .= '<input type="hidden" name="yim" value="' . str_replace("\"", """, $yim) . '" />'; 892 $s_hidden_fields .= '<input type="hidden" name="website" value="' . str_replace("\"", """, $website) . '" />'; 893 $s_hidden_fields .= '<input type="hidden" name="location" value="' . str_replace("\"", """, $location) . '" />'; 894 $s_hidden_fields .= '<input type="hidden" name="occupation" value="' . str_replace("\"", """, $occupation) . '" />'; 895 $s_hidden_fields .= '<input type="hidden" name="interests" value="' . str_replace("\"", """, $interests) . '" />'; 896 $s_hidden_fields .= '<input type="hidden" name="signature" value="' . str_replace("\"", """, $signature) . '" />'; 897 $s_hidden_fields .= '<input type="hidden" name="viewemail" value="' . $viewemail . '" />'; 898 $s_hidden_fields .= '<input type="hidden" name="notifypm" value="' . $notifypm . '" />'; 899 $s_hidden_fields .= '<input type="hidden" name="popup_pm" value="' . $popuppm . '" />'; 900 $s_hidden_fields .= '<input type="hidden" name="notifyreply" value="' . $notifyreply . '" />'; 901 $s_hidden_fields .= '<input type="hidden" name="attachsig" value="' . $attachsig . '" />'; 902 $s_hidden_fields .= '<input type="hidden" name="allowhtml" value="' . $allowhtml . '" />'; 903 $s_hidden_fields .= '<input type="hidden" name="allowbbcode" value="' . $allowbbcode . '" />'; 904 $s_hidden_fields .= '<input type="hidden" name="allowsmilies" value="' . $allowsmilies . '" />'; 905 $s_hidden_fields .= '<input type="hidden" name="hideonline" value="' . !$allowviewonline . '" />'; 906 $s_hidden_fields .= '<input type="hidden" name="style" value="' . $user_style . '" />'; 907 $s_hidden_fields .= '<input type="hidden" name="language" value="' . $user_lang . '" />'; 908 $s_hidden_fields .= '<input type="hidden" name="timezone" value="' . $user_timezone . '" />'; 909 $s_hidden_fields .= '<input type="hidden" name="dateformat" value="' . str_replace("\"", """, $user_dateformat) . '" />'; 910 911 $s_hidden_fields .= '<input type="hidden" name="user_status" value="' . $user_status . '" />'; 912 $s_hidden_fields .= '<input type="hidden" name="user_allowpm" value="' . $user_allowpm . '" />'; 913 $s_hidden_fields .= '<input type="hidden" name="user_allowavatar" value="' . $user_allowavatar . '" />'; 914 $s_hidden_fields .= '<input type="hidden" name="user_rank" value="' . $user_rank . '" />'; 915 916 $template->assign_vars(array( 917 "L_USER_TITLE" => $lang['User_admin'], 918 "L_USER_EXPLAIN" => $lang['User_admin_explain'], 919 "L_AVATAR_GALLERY" => $lang['Avatar_gallery'], 920 "L_SELECT_AVATAR" => $lang['Select_avatar'], 921 "L_RETURN_PROFILE" => $lang['Return_profile'], 922 "L_CATEGORY" => $lang['Select_category'], 923 "L_GO" => $lang['Go'], 924 925 "S_OPTIONS_CATEGORIES" => $s_categories, 926 "S_COLSPAN" => $s_colspan, 927 "S_PROFILE_ACTION" => append_sid("admin_users.$phpEx?mode=$mode"), 928 "S_HIDDEN_FIELDS" => $s_hidden_fields) 929 ); 930 } 931 } 932 else 933 { 934 $s_hidden_fields = '<input type="hidden" name="mode" value="save" /><input type="hidden" name="agreed" value="true" /><input type="hidden" name="coppa" value="' . $coppa . '" />'; 935 $s_hidden_fields .= '<input type="hidden" name="id" value="' . $this_userdata['user_id'] . '" />'; 936 937 if( !empty($user_avatar_local) ) 938 { 939 $s_hidden_fields .= '<input type="hidden" name="avatarlocal" value="' . $user_avatar_local . '" /><input type="hidden" name="avatarcatname" value="' . $user_avatar_category . '" />'; 940 } 941 942 if( $user_avatar_type ) 943 { 944 switch( $user_avatar_type ) 945 { 946 case USER_AVATAR_UPLOAD: 947 $avatar = '<img src="../' . $board_config['avatar_path'] . '/' . $user_avatar . '" alt="" />'; 948 break; 949 case USER_AVATAR_REMOTE: 950 $avatar = '<img src="' . $user_avatar . '" alt="" />'; 951 break; 952 case USER_AVATAR_GALLERY: 953 $avatar = '<img src="../' . $board_config['avatar_gallery_path'] . '/' . $user_avatar . '" alt="" />'; 954 break; 955 } 956 } 957 else 958 { 959 $avatar = ""; 960 } 961 962 $sql = "SELECT * FROM " . RANKS_TABLE . " 963 WHERE rank_special = 1 964 ORDER BY rank_title"; 965 if ( !($result = $db->sql_query($sql)) ) 966 { 967 message_die(GENERAL_ERROR, 'Could not obtain ranks data', '', __LINE__, __FILE__, $sql); 968 } 969 970 $rank_select_box = '<option value="0">' . $lang['No_assigned_rank'] . '</option>'; 971 while( $row = $db->sql_fetchrow($result) ) 972 { 973 $rank = $row['rank_title']; 974 $rank_id = $row['rank_id']; 975 976 $selected = ( $this_userdata['user_rank'] == $rank_id ) ? ' selected="selected"' : ''; 977 $rank_select_box .= '<option value="' . $rank_id . '"' . $selected . '>' . $rank . '</option>'; 978 } 979 980 $template->set_filenames(array( 981 "body" => "admin/user_edit_body.tpl") 982 ); 983 984 // 985 // Let's do an overall check for settings/versions which would prevent 986 // us from doing file uploads.... 987 // 988 $ini_val = ( phpversion() >= '4.0.0' ) ? 'ini_get' : 'get_cfg_var'; 989 $form_enctype = ( !@$ini_val('file_uploads') || phpversion() == '4.0.4pl1' || !$board_config['allow_avatar_upload'] || ( phpversion() < '4.0.3' && @$ini_val('open_basedir') != '' ) ) ? '' : 'enctype="multipart/form-data"'; 990 991 $template->assign_vars(array( 992 'USERNAME' => $username, 993 'EMAIL' => $email, 994 'YIM' => $yim, 995 'ICQ' => $icq, 996 'MSN' => $msn, 997 'AIM' => $aim, 998 'OCCUPATION' => $occupation, 999 'INTERESTS' => $interests, 1000 'LOCATION' => $location, 1001 'WEBSITE' => $website, 1002 'SIGNATURE' => str_replace('<br />', "\n", $signature), 1003 'VIEW_EMAIL_YES' => ($viewemail) ? 'checked="checked"' : '', 1004 'VIEW_EMAIL_NO' => (!$viewemail) ? 'checked="checked"' : '', 1005 'HIDE_USER_YES' => (!$allowviewonline) ? 'checked="checked"' : '', 1006 'HIDE_USER_NO' => ($allowviewonline) ? 'checked="checked"' : '', 1007 'NOTIFY_PM_YES' => ($notifypm) ? 'checked="checked"' : '', 1008 'NOTIFY_PM_NO' => (!$notifypm) ? 'checked="checked"' : '', 1009 'POPUP_PM_YES' => ($popuppm) ? 'checked="checked"' : '', 1010 'POPUP_PM_NO' => (!$popuppm) ? 'checked="checked"' : '', 1011 'ALWAYS_ADD_SIGNATURE_YES' => ($attachsig) ? 'checked="checked"' : '', 1012 'ALWAYS_ADD_SIGNATURE_NO' => (!$attachsig) ? 'checked="checked"' : '', 1013 'NOTIFY_REPLY_YES' => ( $notifyreply ) ? 'checked="checked"' : '', 1014 'NOTIFY_REPLY_NO' => ( !$notifyreply ) ? 'checked="checked"' : '', 1015 'ALWAYS_ALLOW_BBCODE_YES' => ($allowbbcode) ? 'checked="checked"' : '', 1016 'ALWAYS_ALLOW_BBCODE_NO' => (!$allowbbcode) ? 'checked="checked"' : '', 1017 'ALWAYS_ALLOW_HTML_YES' => ($allowhtml) ? 'checked="checked"' : '', 1018 'ALWAYS_ALLOW_HTML_NO' => (!$allowhtml) ? 'checked="checked"' : '', 1019 'ALWAYS_ALLOW_SMILIES_YES' => ($allowsmilies) ? 'checked="checked"' : '', 1020 'ALWAYS_ALLOW_SMILIES_NO' => (!$allowsmilies) ? 'checked="checked"' : '', 1021 'AVATAR' => $avatar, 1022 'LANGUAGE_SELECT' => language_select($user_lang), 1023 'TIMEZONE_SELECT' => tz_select($user_timezone), 1024 'STYLE_SELECT' => style_select($user_style, 'style'), 1025 'DATE_FORMAT' => $user_dateformat, 1026 'ALLOW_PM_YES' => ($user_allowpm) ? 'checked="checked"' : '', 1027 'ALLOW_PM_NO' => (!$user_allowpm) ? 'checked="checked"' : '', 1028 'ALLOW_AVATAR_YES' => ($user_allowavatar) ? 'checked="checked"' : '', 1029 'ALLOW_AVATAR_NO' => (!$user_allowavatar) ? 'checked="checked"' : '', 1030 'USER_ACTIVE_YES' => ($user_status) ? 'checked="checked"' : '', 1031 'USER_ACTIVE_NO' => (!$user_status) ? 'checked="checked"' : '', 1032 'RANK_SELECT_BOX' => $rank_select_box, 1033 1034 'L_USERNAME' => $lang['Username'], 1035 'L_USER_TITLE' => $lang['User_admin'], 1036 'L_USER_EXPLAIN' => $lang['User_admin_explain'], 1037 'L_NEW_PASSWORD' => $lang['New_password'], 1038 'L_PASSWORD_IF_CHANGED' => $lang['password_if_changed'], 1039 'L_CONFIRM_PASSWORD' => $lang['Confirm_password'], 1040 'L_PASSWORD_CONFIRM_IF_CHANGED' => $lang['password_confirm_if_changed'], 1041 'L_SUBMIT' => $lang['Submit'], 1042 'L_RESET' => $lang['Reset'], 1043 'L_ICQ_NUMBER' => $lang['ICQ'], 1044 'L_MESSENGER' => $lang['MSNM'], 1045 'L_YAHOO' => $lang['YIM'], 1046 'L_WEBSITE' => $lang['Website'], 1047 'L_AIM' => $lang['AIM'], 1048 'L_LOCATION' => $lang['Location'], 1049 'L_OCCUPATION' => $lang['Occupation'], 1050 'L_BOARD_LANGUAGE' => $lang['Board_lang'], 1051 'L_BOARD_STYLE' => $lang['Board_style'], 1052 'L_TIMEZONE' => $lang['Timezone'], 1053 'L_DATE_FORMAT' => $lang['Date_format'], 1054 'L_DATE_FORMAT_EXPLAIN' => $lang['Date_format_explain'], 1055 'L_YES' => $lang['Yes'], 1056 'L_NO' => $lang['No'], 1057 'L_INTERESTS' => $lang['Interests'], 1058 'L_ALWAYS_ALLOW_SMILIES' => $lang['Always_smile'], 1059 'L_ALWAYS_ALLOW_BBCODE' => $lang['Always_bbcode'], 1060 'L_ALWAYS_ALLOW_HTML' => $lang['Always_html'], 1061 'L_HIDE_USER' => $lang['Hide_user'], 1062 'L_ALWAYS_ADD_SIGNATURE' => $lang['Always_add_sig'], 1063 1064 'L_SPECIAL' => $lang['User_special'], 1065 'L_SPECIAL_EXPLAIN' => $lang['User_special_explain'], 1066 'L_USER_ACTIVE' => $lang['User_status'], 1067 'L_ALLOW_PM' => $lang['User_allowpm'], 1068 'L_ALLOW_AVATAR' => $lang['User_allowavatar'], 1069 1070 'L_AVATAR_PANEL' => $lang['Avatar_panel'], 1071 'L_AVATAR_EXPLAIN' => $lang['Admin_avatar_explain'], 1072 'L_DELETE_AVATAR' => $lang['Delete_Image'], 1073 'L_CURRENT_IMAGE' => $lang['Current_Image'], 1074 'L_UPLOAD_AVATAR_FILE' => $lang['Upload_Avatar_file'], 1075 'L_UPLOAD_AVATAR_URL' => $lang['Upload_Avatar_URL'], 1076 'L_AVATAR_GALLERY' => $lang['Select_from_gallery'], 1077 'L_SHOW_GALLERY' => $lang['View_avatar_gallery'], 1078 'L_LINK_REMOTE_AVATAR' => $lang['Link_remote_Avatar'], 1079 1080 'L_SIGNATURE' => $lang['Signature'], 1081 'L_SIGNATURE_EXPLAIN' => sprintf($lang['Signature_explain'], $board_config['max_sig_chars'] ), 1082 'L_NOTIFY_ON_PRIVMSG' => $lang['Notify_on_privmsg'], 1083 'L_NOTIFY_ON_REPLY' => $lang['Always_notify'], 1084 'L_POPUP_ON_PRIVMSG' => $lang['Popup_on_privmsg'], 1085 'L_PREFERENCES' => $lang['Preferences'], 1086 'L_PUBLIC_VIEW_EMAIL' => $lang['Public_view_email'], 1087 'L_ITEMS_REQUIRED' => $lang['Items_required'], 1088 'L_REGISTRATION_INFO' => $lang['Registration_info'], 1089 'L_PROFILE_INFO' => $lang['Profile_info'], 1090 'L_PROFILE_INFO_NOTICE' => $lang['Profile_info_warn'], 1091 'L_EMAIL_ADDRESS' => $lang['Email_address'], 1092 'S_FORM_ENCTYPE' => $form_enctype, 1093 1094 'HTML_STATUS' => $html_status, 1095 'BBCODE_STATUS' => sprintf($bbcode_status, '<a href="../' . append_sid("faq.$phpEx?mode=bbcode") . '" target="_phpbbcode">', '</a>'), 1096 'SMILIES_STATUS' => $smilies_status, 1097 1098 'L_DELETE_USER' => $lang['User_delete'], 1099 'L_DELETE_USER_EXPLAIN' => $lang['User_delete_explain'], 1100 'L_SELECT_RANK' => $lang['Rank_title'], 1101 1102 'S_HIDDEN_FIELDS' => $s_hidden_fields, 1103 'S_PROFILE_ACTION' => append_sid("admin_users.$phpEx")) 1104 ); 1105 1106 if( file_exists(@phpbb_realpath('./../' . $board_config['avatar_path'])) && ($board_config['allow_avatar_upload'] == TRUE) ) 1107 { 1108 if ( $form_enctype != '' ) 1109 { 1110 $template->assign_block_vars('avatar_local_upload', array() ); 1111 } 1112 $template->assign_block_vars('avatar_remote_upload', array() ); 1113 } 1114 1115 if( file_exists(@phpbb_realpath('./../' . $board_config['avatar_gallery_path'])) && ($board_config['allow_avatar_local'] == TRUE) ) 1116 { 1117 $template->assign_block_vars('avatar_local_gallery', array() ); 1118 } 1119 1120 if( $board_config['allow_avatar_remote'] == TRUE ) 1121 { 1122 $template->assign_block_vars('avatar_remote_link', array() ); 1123 } 1124 } 1125 1126 $template->pparse('body'); 1127 } 1128 else 1129 { 1130 // 1131 // Default user selection box 1132 // 1133 $template->set_filenames(array( 1134 'body' => 'admin/user_select_body.tpl') 1135 ); 1136 1137 $template->assign_vars(array( 1138 'L_USER_TITLE' => $lang['User_admin'], 1139 'L_USER_EXPLAIN' => $lang['User_admin_explain'], 1140 'L_USER_SELECT' => $lang['Select_a_User'], 1141 'L_LOOK_UP' => $lang['Look_up_user'], 1142 'L_FIND_USERNAME' => $lang['Find_username'], 1143 1144 'U_SEARCH_USER' => append_sid("./../search.$phpEx?mode=searchuser"), 1145 1146 'S_USER_ACTION' => append_sid("admin_users.$phpEx"), 1147 'S_USER_SELECT' => $select_list) 1148 ); 1149 $template->pparse('body'); 1150 1151 } 1152 1153 include('./page_footer_admin.'.$phpEx); 1154 1155 ?>
title
Description
Body
title
Description
Body
title
Description
Body
title
Body
Generated: Mon Jan 14 19:21:40 2013 | Cross-referenced by PHPXref 0.7.1 |