PageRenderTime 51ms CodeModel.GetById 19ms RepoModel.GetById 0ms app.codeStats 1ms

/forum/includes/ucp/ucp_groups.php

https://github.com/GreyTeardrop/socionicasys-forum
PHP | 1117 lines | 870 code | 212 blank | 35 comment | 181 complexity | d06de40f6cffe1a22027a40a8713b0c4 MD5 | raw file
Possible License(s): AGPL-1.0, LGPL-3.0, MPL-2.0-no-copyleft-exception
  1. <?php
  2. /**
  3. *
  4. * @package ucp
  5. * @version $Id$
  6. * @copyright (c) 2005 phpBB Group
  7. * @license http://opensource.org/licenses/gpl-license.php GNU Public License
  8. *
  9. */
  10. /**
  11. * @ignore
  12. */
  13. if (!defined('IN_PHPBB'))
  14. {
  15. exit;
  16. }
  17. /**
  18. * ucp_groups
  19. * @package ucp
  20. */
  21. class ucp_groups
  22. {
  23. var $u_action;
  24. function main($id, $mode)
  25. {
  26. global $config, $phpbb_root_path, $phpEx;
  27. global $db, $user, $auth, $cache, $template;
  28. $user->add_lang('groups');
  29. $return_page = '<br /><br />' . sprintf($user->lang['RETURN_PAGE'], '<a href="' . $this->u_action . '">', '</a>');
  30. $mark_ary = request_var('mark', array(0));
  31. $submit = (!empty($_POST['submit'])) ? true : false;
  32. $delete = (!empty($_POST['delete'])) ? true : false;
  33. $error = $data = array();
  34. switch ($mode)
  35. {
  36. case 'membership':
  37. $this->page_title = 'UCP_USERGROUPS_MEMBER';
  38. if ($submit || isset($_POST['change_default']))
  39. {
  40. $action = (isset($_POST['change_default'])) ? 'change_default' : request_var('action', '');
  41. $group_id = ($action == 'change_default') ? request_var('default', 0) : request_var('selected', 0);
  42. if (!$group_id)
  43. {
  44. trigger_error('NO_GROUP_SELECTED');
  45. }
  46. $sql = 'SELECT group_id, group_name, group_type
  47. FROM ' . GROUPS_TABLE . "
  48. WHERE group_id IN ($group_id, {$user->data['group_id']})";
  49. $result = $db->sql_query($sql);
  50. $group_row = array();
  51. while ($row = $db->sql_fetchrow($result))
  52. {
  53. $row['group_name'] = ($row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $row['group_name']] : $row['group_name'];
  54. $group_row[$row['group_id']] = $row;
  55. }
  56. $db->sql_freeresult($result);
  57. if (!sizeof($group_row))
  58. {
  59. trigger_error('GROUP_NOT_EXIST');
  60. }
  61. switch ($action)
  62. {
  63. case 'change_default':
  64. // User already having this group set as default?
  65. if ($group_id == $user->data['group_id'])
  66. {
  67. trigger_error($user->lang['ALREADY_DEFAULT_GROUP'] . $return_page);
  68. }
  69. if (!$auth->acl_get('u_chggrp'))
  70. {
  71. trigger_error($user->lang['NOT_AUTHORISED'] . $return_page);
  72. }
  73. // User needs to be member of the group in order to make it default
  74. if (!group_memberships($group_id, $user->data['user_id'], true))
  75. {
  76. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  77. }
  78. if (confirm_box(true))
  79. {
  80. group_user_attributes('default', $group_id, $user->data['user_id']);
  81. add_log('user', $user->data['user_id'], 'LOG_USER_GROUP_CHANGE', sprintf($user->lang['USER_GROUP_CHANGE'], $group_row[$user->data['group_id']]['group_name'], $group_row[$group_id]['group_name']));
  82. meta_refresh(3, $this->u_action);
  83. trigger_error($user->lang['CHANGED_DEFAULT_GROUP'] . $return_page);
  84. }
  85. else
  86. {
  87. $s_hidden_fields = array(
  88. 'default' => $group_id,
  89. 'change_default'=> true
  90. );
  91. confirm_box(false, sprintf($user->lang['GROUP_CHANGE_DEFAULT'], $group_row[$group_id]['group_name']), build_hidden_fields($s_hidden_fields));
  92. }
  93. break;
  94. case 'resign':
  95. // User tries to resign from default group but is not allowed to change it?
  96. if ($group_id == $user->data['group_id'] && !$auth->acl_get('u_chggrp'))
  97. {
  98. trigger_error($user->lang['NOT_RESIGN_FROM_DEFAULT_GROUP'] . $return_page);
  99. }
  100. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  101. {
  102. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  103. }
  104. list(, $row) = each($row);
  105. $sql = 'SELECT group_type
  106. FROM ' . GROUPS_TABLE . '
  107. WHERE group_id = ' . $group_id;
  108. $result = $db->sql_query($sql);
  109. $group_type = (int) $db->sql_fetchfield('group_type');
  110. $db->sql_freeresult($result);
  111. if ($group_type != GROUP_OPEN && $group_type != GROUP_FREE)
  112. {
  113. trigger_error($user->lang['CANNOT_RESIGN_GROUP'] . $return_page);
  114. }
  115. if (confirm_box(true))
  116. {
  117. group_user_del($group_id, $user->data['user_id']);
  118. add_log('user', $user->data['user_id'], 'LOG_USER_GROUP_RESIGN', $group_row[$group_id]['group_name']);
  119. meta_refresh(3, $this->u_action);
  120. trigger_error($user->lang[($row['user_pending']) ? 'GROUP_RESIGNED_PENDING' : 'GROUP_RESIGNED_MEMBERSHIP'] . $return_page);
  121. }
  122. else
  123. {
  124. $s_hidden_fields = array(
  125. 'selected' => $group_id,
  126. 'action' => 'resign',
  127. 'submit' => true
  128. );
  129. confirm_box(false, ($row['user_pending']) ? 'GROUP_RESIGN_PENDING' : 'GROUP_RESIGN_MEMBERSHIP', build_hidden_fields($s_hidden_fields));
  130. }
  131. break;
  132. case 'join':
  133. $sql = 'SELECT ug.*, u.username, u.username_clean, u.user_email
  134. FROM ' . USER_GROUP_TABLE . ' ug, ' . USERS_TABLE . ' u
  135. WHERE ug.user_id = u.user_id
  136. AND ug.group_id = ' . $group_id . '
  137. AND ug.user_id = ' . $user->data['user_id'];
  138. $result = $db->sql_query($sql);
  139. $row = $db->sql_fetchrow($result);
  140. $db->sql_freeresult($result);
  141. if ($row)
  142. {
  143. if ($row['user_pending'])
  144. {
  145. trigger_error($user->lang['ALREADY_IN_GROUP_PENDING'] . $return_page);
  146. }
  147. trigger_error($user->lang['ALREADY_IN_GROUP'] . $return_page);
  148. }
  149. // Check permission to join (open group or request)
  150. if ($group_row[$group_id]['group_type'] != GROUP_OPEN && $group_row[$group_id]['group_type'] != GROUP_FREE)
  151. {
  152. trigger_error($user->lang['CANNOT_JOIN_GROUP'] . $return_page);
  153. }
  154. if (confirm_box(true))
  155. {
  156. if ($group_row[$group_id]['group_type'] == GROUP_FREE)
  157. {
  158. group_user_add($group_id, $user->data['user_id']);
  159. $email_template = 'group_added';
  160. }
  161. else
  162. {
  163. group_user_add($group_id, $user->data['user_id'], false, false, false, 0, 1);
  164. $email_template = 'group_request';
  165. }
  166. include_once($phpbb_root_path . 'includes/functions_messenger.' . $phpEx);
  167. $messenger = new messenger();
  168. $sql = 'SELECT u.username, u.username_clean, u.user_email, u.user_notify_type, u.user_jabber, u.user_lang
  169. FROM ' . USER_GROUP_TABLE . ' ug, ' . USERS_TABLE . ' u
  170. WHERE ug.user_id = u.user_id
  171. AND ' . (($group_row[$group_id]['group_type'] == GROUP_FREE) ? "ug.user_id = {$user->data['user_id']}" : 'ug.group_leader = 1') . "
  172. AND ug.group_id = $group_id";
  173. $result = $db->sql_query($sql);
  174. while ($row = $db->sql_fetchrow($result))
  175. {
  176. $messenger->template($email_template, $row['user_lang']);
  177. $messenger->to($row['user_email'], $row['username']);
  178. $messenger->im($row['user_jabber'], $row['username']);
  179. $messenger->assign_vars(array(
  180. 'USERNAME' => htmlspecialchars_decode($row['username']),
  181. 'GROUP_NAME' => htmlspecialchars_decode($group_row[$group_id]['group_name']),
  182. 'REQUEST_USERNAME' => $user->data['username'],
  183. 'U_PENDING' => generate_board_url() . "/ucp.$phpEx?i=groups&mode=manage&action=list&g=$group_id",
  184. 'U_GROUP' => generate_board_url() . "/memberlist.$phpEx?mode=group&g=$group_id")
  185. );
  186. $messenger->send($row['user_notify_type']);
  187. }
  188. $db->sql_freeresult($result);
  189. $messenger->save_queue();
  190. add_log('user', $user->data['user_id'], 'LOG_USER_GROUP_JOIN' . (($group_row[$group_id]['group_type'] == GROUP_FREE) ? '' : '_PENDING'), $group_row[$group_id]['group_name']);
  191. meta_refresh(3, $this->u_action);
  192. trigger_error($user->lang[($group_row[$group_id]['group_type'] == GROUP_FREE) ? 'GROUP_JOINED' : 'GROUP_JOINED_PENDING'] . $return_page);
  193. }
  194. else
  195. {
  196. $s_hidden_fields = array(
  197. 'selected' => $group_id,
  198. 'action' => 'join',
  199. 'submit' => true
  200. );
  201. confirm_box(false, ($group_row[$group_id]['group_type'] == GROUP_FREE) ? 'GROUP_JOIN' : 'GROUP_JOIN_PENDING', build_hidden_fields($s_hidden_fields));
  202. }
  203. break;
  204. case 'demote':
  205. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  206. {
  207. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  208. }
  209. list(, $row) = each($row);
  210. if (!$row['group_leader'])
  211. {
  212. trigger_error($user->lang['NOT_LEADER_OF_GROUP'] . $return_page);
  213. }
  214. if (confirm_box(true))
  215. {
  216. group_user_attributes('demote', $group_id, $user->data['user_id']);
  217. add_log('user', $user->data['user_id'], 'LOG_USER_GROUP_DEMOTE', $group_row[$group_id]['group_name']);
  218. meta_refresh(3, $this->u_action);
  219. trigger_error($user->lang['USER_GROUP_DEMOTED'] . $return_page);
  220. }
  221. else
  222. {
  223. $s_hidden_fields = array(
  224. 'selected' => $group_id,
  225. 'action' => 'demote',
  226. 'submit' => true
  227. );
  228. confirm_box(false, 'USER_GROUP_DEMOTE', build_hidden_fields($s_hidden_fields));
  229. }
  230. break;
  231. }
  232. }
  233. $sql = 'SELECT g.*, ug.group_leader, ug.user_pending
  234. FROM ' . GROUPS_TABLE . ' g, ' . USER_GROUP_TABLE . ' ug
  235. WHERE ug.user_id = ' . $user->data['user_id'] . '
  236. AND g.group_id = ug.group_id
  237. ORDER BY g.group_type DESC, g.group_name';
  238. $result = $db->sql_query($sql);
  239. $group_id_ary = array();
  240. $leader_count = $member_count = $pending_count = 0;
  241. while ($row = $db->sql_fetchrow($result))
  242. {
  243. $block = ($row['group_leader']) ? 'leader' : (($row['user_pending']) ? 'pending' : 'member');
  244. switch ($row['group_type'])
  245. {
  246. case GROUP_OPEN:
  247. $group_status = 'OPEN';
  248. break;
  249. case GROUP_CLOSED:
  250. $group_status = 'CLOSED';
  251. break;
  252. case GROUP_HIDDEN:
  253. $group_status = 'HIDDEN';
  254. break;
  255. case GROUP_SPECIAL:
  256. $group_status = 'SPECIAL';
  257. break;
  258. case GROUP_FREE:
  259. $group_status = 'FREE';
  260. break;
  261. }
  262. $template->assign_block_vars($block, array(
  263. 'GROUP_ID' => $row['group_id'],
  264. 'GROUP_NAME' => ($row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $row['group_name']] : $row['group_name'],
  265. 'GROUP_DESC' => ($row['group_type'] <> GROUP_SPECIAL) ? generate_text_for_display($row['group_desc'], $row['group_desc_uid'], $row['group_desc_bitfield'], $row['group_desc_options']) : $user->lang['GROUP_IS_SPECIAL'],
  266. 'GROUP_SPECIAL' => ($row['group_type'] <> GROUP_SPECIAL) ? false : true,
  267. 'GROUP_STATUS' => $user->lang['GROUP_IS_' . $group_status],
  268. 'GROUP_COLOUR' => $row['group_colour'],
  269. 'U_VIEW_GROUP' => append_sid("{$phpbb_root_path}memberlist.$phpEx", 'mode=group&amp;g=' . $row['group_id']),
  270. 'S_GROUP_DEFAULT' => ($row['group_id'] == $user->data['group_id']) ? true : false,
  271. 'S_ROW_COUNT' => ${$block . '_count'}++)
  272. );
  273. $group_id_ary[] = (int) $row['group_id'];
  274. }
  275. $db->sql_freeresult($result);
  276. // Hide hidden groups unless user is an admin with group privileges
  277. $sql_and = ($auth->acl_gets('a_group', 'a_groupadd', 'a_groupdel')) ? '<> ' . GROUP_SPECIAL : 'NOT IN (' . GROUP_SPECIAL . ', ' . GROUP_HIDDEN . ')';
  278. $sql = 'SELECT group_id, group_name, group_colour, group_desc, group_desc_uid, group_desc_bitfield, group_desc_options, group_type, group_founder_manage
  279. FROM ' . GROUPS_TABLE . '
  280. WHERE ' . ((sizeof($group_id_ary)) ? $db->sql_in_set('group_id', $group_id_ary, true) . ' AND ' : '') . "
  281. group_type $sql_and
  282. ORDER BY group_type DESC, group_name";
  283. $result = $db->sql_query($sql);
  284. $nonmember_count = 0;
  285. while ($row = $db->sql_fetchrow($result))
  286. {
  287. switch ($row['group_type'])
  288. {
  289. case GROUP_OPEN:
  290. $group_status = 'OPEN';
  291. break;
  292. case GROUP_CLOSED:
  293. $group_status = 'CLOSED';
  294. break;
  295. case GROUP_HIDDEN:
  296. $group_status = 'HIDDEN';
  297. break;
  298. case GROUP_SPECIAL:
  299. $group_status = 'SPECIAL';
  300. break;
  301. case GROUP_FREE:
  302. $group_status = 'FREE';
  303. break;
  304. }
  305. $template->assign_block_vars('nonmember', array(
  306. 'GROUP_ID' => $row['group_id'],
  307. 'GROUP_NAME' => ($row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $row['group_name']] : $row['group_name'],
  308. 'GROUP_DESC' => ($row['group_type'] <> GROUP_SPECIAL) ? generate_text_for_display($row['group_desc'], $row['group_desc_uid'], $row['group_desc_bitfield'], $row['group_desc_options']) : $user->lang['GROUP_IS_SPECIAL'],
  309. 'GROUP_SPECIAL' => ($row['group_type'] <> GROUP_SPECIAL) ? false : true,
  310. 'GROUP_CLOSED' => ($row['group_type'] <> GROUP_CLOSED || $auth->acl_gets('a_group', 'a_groupadd', 'a_groupdel')) ? false : true,
  311. 'GROUP_STATUS' => $user->lang['GROUP_IS_' . $group_status],
  312. 'S_CAN_JOIN' => ($row['group_type'] == GROUP_OPEN || $row['group_type'] == GROUP_FREE) ? true : false,
  313. 'GROUP_COLOUR' => $row['group_colour'],
  314. 'U_VIEW_GROUP' => append_sid("{$phpbb_root_path}memberlist.$phpEx", 'mode=group&amp;g=' . $row['group_id']),
  315. 'S_ROW_COUNT' => $nonmember_count++)
  316. );
  317. }
  318. $db->sql_freeresult($result);
  319. $template->assign_vars(array(
  320. 'S_CHANGE_DEFAULT' => ($auth->acl_get('u_chggrp')) ? true : false,
  321. 'S_LEADER_COUNT' => $leader_count,
  322. 'S_MEMBER_COUNT' => $member_count,
  323. 'S_PENDING_COUNT' => $pending_count,
  324. 'S_NONMEMBER_COUNT' => $nonmember_count,
  325. 'S_UCP_ACTION' => $this->u_action)
  326. );
  327. break;
  328. case 'manage':
  329. $this->page_title = 'UCP_USERGROUPS_MANAGE';
  330. $action = (isset($_POST['addusers'])) ? 'addusers' : request_var('action', '');
  331. $group_id = request_var('g', 0);
  332. include($phpbb_root_path . 'includes/functions_display.' . $phpEx);
  333. add_form_key('ucp_groups');
  334. if ($group_id)
  335. {
  336. $sql = 'SELECT *
  337. FROM ' . GROUPS_TABLE . "
  338. WHERE group_id = $group_id";
  339. $result = $db->sql_query($sql);
  340. $group_row = $db->sql_fetchrow($result);
  341. $db->sql_freeresult($result);
  342. if (!$group_row)
  343. {
  344. trigger_error($user->lang['NO_GROUP'] . $return_page);
  345. }
  346. // Check if the user is allowed to manage this group if set to founder only.
  347. if ($user->data['user_type'] != USER_FOUNDER && $group_row['group_founder_manage'])
  348. {
  349. trigger_error($user->lang['NOT_ALLOWED_MANAGE_GROUP'] . $return_page, E_USER_WARNING);
  350. }
  351. $group_name = $group_row['group_name'];
  352. $group_type = $group_row['group_type'];
  353. $avatar_img = (!empty($group_row['group_avatar'])) ? get_user_avatar($group_row['group_avatar'], $group_row['group_avatar_type'], $group_row['group_avatar_width'], $group_row['group_avatar_height'], 'GROUP_AVATAR') : '<img src="' . $phpbb_root_path . 'adm/images/no_avatar.gif" alt="" />';
  354. $template->assign_vars(array(
  355. 'GROUP_NAME' => ($group_type == GROUP_SPECIAL) ? $user->lang['G_' . $group_name] : $group_name,
  356. 'GROUP_INTERNAL_NAME' => $group_name,
  357. 'GROUP_COLOUR' => (isset($group_row['group_colour'])) ? $group_row['group_colour'] : '',
  358. 'GROUP_DESC_DISP' => generate_text_for_display($group_row['group_desc'], $group_row['group_desc_uid'], $group_row['group_desc_bitfield'], $group_row['group_desc_options']),
  359. 'GROUP_TYPE' => $group_row['group_type'],
  360. 'AVATAR' => $avatar_img,
  361. 'AVATAR_IMAGE' => $avatar_img,
  362. 'AVATAR_WIDTH' => (isset($group_row['group_avatar_width'])) ? $group_row['group_avatar_width'] : '',
  363. 'AVATAR_HEIGHT' => (isset($group_row['group_avatar_height'])) ? $group_row['group_avatar_height'] : '',
  364. ));
  365. }
  366. switch ($action)
  367. {
  368. case 'edit':
  369. if (!$group_id)
  370. {
  371. trigger_error($user->lang['NO_GROUP'] . $return_page);
  372. }
  373. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  374. {
  375. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  376. }
  377. list(, $row) = each($row);
  378. if (!$row['group_leader'])
  379. {
  380. trigger_error($user->lang['NOT_LEADER_OF_GROUP'] . $return_page);
  381. }
  382. $file_uploads = (@ini_get('file_uploads') || strtolower(@ini_get('file_uploads')) == 'on') ? true : false;
  383. $user->add_lang(array('acp/groups', 'acp/common'));
  384. $data = $submit_ary = array();
  385. $update = (isset($_POST['update'])) ? true : false;
  386. $error = array();
  387. $avatar_select = basename(request_var('avatar_select', ''));
  388. $category = basename(request_var('category', ''));
  389. $can_upload = (file_exists($phpbb_root_path . $config['avatar_path']) && phpbb_is_writable($phpbb_root_path . $config['avatar_path']) && $file_uploads) ? true : false;
  390. // Did we submit?
  391. if ($update)
  392. {
  393. $group_name = utf8_normalize_nfc(request_var('group_name', '', true));
  394. $group_desc = utf8_normalize_nfc(request_var('group_desc', '', true));
  395. $group_type = request_var('group_type', GROUP_FREE);
  396. $allow_desc_bbcode = request_var('desc_parse_bbcode', false);
  397. $allow_desc_urls = request_var('desc_parse_urls', false);
  398. $allow_desc_smilies = request_var('desc_parse_smilies', false);
  399. $submit_ary = array(
  400. 'colour' => request_var('group_colour', ''),
  401. 'rank' => request_var('group_rank', 0),
  402. 'receive_pm' => isset($_REQUEST['group_receive_pm']) ? 1 : 0,
  403. 'message_limit' => request_var('group_message_limit', 0),
  404. 'max_recipients'=> request_var('group_max_recipients', 0),
  405. );
  406. $data['uploadurl'] = request_var('uploadurl', '');
  407. $data['remotelink'] = request_var('remotelink', '');
  408. $data['width'] = request_var('width', '');
  409. $data['height'] = request_var('height', '');
  410. $delete = request_var('delete', '');
  411. if (!empty($_FILES['uploadfile']['tmp_name']) || $data['uploadurl'] || $data['remotelink'])
  412. {
  413. // Avatar stuff
  414. $var_ary = array(
  415. 'uploadurl' => array('string', true, 5, 255),
  416. 'remotelink' => array('string', true, 5, 255),
  417. 'width' => array('string', true, 1, 3),
  418. 'height' => array('string', true, 1, 3),
  419. );
  420. if (!($error = validate_data($data, $var_ary)))
  421. {
  422. $data['user_id'] = "g$group_id";
  423. if ((!empty($_FILES['uploadfile']['tmp_name']) || $data['uploadurl']) && $can_upload)
  424. {
  425. list($submit_ary['avatar_type'], $submit_ary['avatar'], $submit_ary['avatar_width'], $submit_ary['avatar_height']) = avatar_upload($data, $error);
  426. }
  427. else if ($data['remotelink'])
  428. {
  429. list($submit_ary['avatar_type'], $submit_ary['avatar'], $submit_ary['avatar_width'], $submit_ary['avatar_height']) = avatar_remote($data, $error);
  430. }
  431. }
  432. }
  433. else if ($avatar_select && $config['allow_avatar_local'])
  434. {
  435. // check avatar gallery
  436. if (is_dir($phpbb_root_path . $config['avatar_gallery_path'] . '/' . $category))
  437. {
  438. $submit_ary['avatar_type'] = AVATAR_GALLERY;
  439. list($submit_ary['avatar_width'], $submit_ary['avatar_height']) = getimagesize($phpbb_root_path . $config['avatar_gallery_path'] . '/' . $category . '/' . $avatar_select);
  440. $submit_ary['avatar'] = $category . '/' . $avatar_select;
  441. }
  442. }
  443. else if ($delete)
  444. {
  445. $submit_ary['avatar'] = '';
  446. $submit_ary['avatar_type'] = $submit_ary['avatar_width'] = $submit_ary['avatar_height'] = 0;
  447. }
  448. else if ($data['width'] && $data['height'])
  449. {
  450. // Only update the dimensions?
  451. if ($config['avatar_max_width'] || $config['avatar_max_height'])
  452. {
  453. if ($data['width'] > $config['avatar_max_width'] || $data['height'] > $config['avatar_max_height'])
  454. {
  455. $error[] = sprintf($user->lang['AVATAR_WRONG_SIZE'], $config['avatar_min_width'], $config['avatar_min_height'], $config['avatar_max_width'], $config['avatar_max_height'], $data['width'], $data['height']);
  456. }
  457. }
  458. if (!sizeof($error))
  459. {
  460. if ($config['avatar_min_width'] || $config['avatar_min_height'])
  461. {
  462. if ($data['width'] < $config['avatar_min_width'] || $data['height'] < $config['avatar_min_height'])
  463. {
  464. $error[] = sprintf($user->lang['AVATAR_WRONG_SIZE'], $config['avatar_min_width'], $config['avatar_min_height'], $config['avatar_max_width'], $config['avatar_max_height'], $data['width'], $data['height']);
  465. }
  466. }
  467. }
  468. if (!sizeof($error))
  469. {
  470. $submit_ary['avatar_width'] = $data['width'];
  471. $submit_ary['avatar_height'] = $data['height'];
  472. }
  473. }
  474. if ((isset($submit_ary['avatar']) && $submit_ary['avatar'] && (!isset($group_row['group_avatar']))) || $delete)
  475. {
  476. if (isset($group_row['group_avatar']) && $group_row['group_avatar'])
  477. {
  478. avatar_delete('group', $group_row, true);
  479. }
  480. }
  481. if (!check_form_key('ucp_groups'))
  482. {
  483. $error[] = $user->lang['FORM_INVALID'];
  484. }
  485. if (!sizeof($error))
  486. {
  487. // Only set the rank, colour, etc. if it's changed or if we're adding a new
  488. // group. This prevents existing group members being updated if no changes
  489. // were made.
  490. $group_attributes = array();
  491. $test_variables = array(
  492. 'rank' => 'int',
  493. 'colour' => 'string',
  494. 'avatar' => 'string',
  495. 'avatar_type' => 'int',
  496. 'avatar_width' => 'int',
  497. 'avatar_height' => 'int',
  498. 'receive_pm' => 'int',
  499. 'legend' => 'int',
  500. 'message_limit' => 'int',
  501. 'max_recipients'=> 'int',
  502. );
  503. foreach ($test_variables as $test => $type)
  504. {
  505. if (isset($submit_ary[$test]) && ($action == 'add' || $group_row['group_' . $test] != $submit_ary[$test]))
  506. {
  507. settype($submit_ary[$test], $type);
  508. $group_attributes['group_' . $test] = $group_row['group_' . $test] = $submit_ary[$test];
  509. }
  510. }
  511. if (!($error = group_create($group_id, $group_type, $group_name, $group_desc, $group_attributes, $allow_desc_bbcode, $allow_desc_urls, $allow_desc_smilies)))
  512. {
  513. $cache->destroy('sql', GROUPS_TABLE);
  514. $message = ($action == 'edit') ? 'GROUP_UPDATED' : 'GROUP_CREATED';
  515. trigger_error($user->lang[$message] . $return_page);
  516. }
  517. }
  518. if (sizeof($error))
  519. {
  520. $group_rank = $submit_ary['rank'];
  521. $group_desc_data = array(
  522. 'text' => $group_desc,
  523. 'allow_bbcode' => $allow_desc_bbcode,
  524. 'allow_smilies' => $allow_desc_smilies,
  525. 'allow_urls' => $allow_desc_urls
  526. );
  527. }
  528. }
  529. else if (!$group_id)
  530. {
  531. $group_name = utf8_normalize_nfc(request_var('group_name', '', true));
  532. $group_desc_data = array(
  533. 'text' => '',
  534. 'allow_bbcode' => true,
  535. 'allow_smilies' => true,
  536. 'allow_urls' => true
  537. );
  538. $group_rank = 0;
  539. $group_type = GROUP_OPEN;
  540. }
  541. else
  542. {
  543. $group_desc_data = generate_text_for_edit($group_row['group_desc'], $group_row['group_desc_uid'], $group_row['group_desc_options']);
  544. $group_rank = $group_row['group_rank'];
  545. }
  546. $sql = 'SELECT *
  547. FROM ' . RANKS_TABLE . '
  548. WHERE rank_special = 1
  549. ORDER BY rank_title';
  550. $result = $db->sql_query($sql);
  551. $rank_options = '<option value="0"' . ((!$group_rank) ? ' selected="selected"' : '') . '>' . $user->lang['USER_DEFAULT'] . '</option>';
  552. while ($row = $db->sql_fetchrow($result))
  553. {
  554. $selected = ($group_rank && $row['rank_id'] == $group_rank) ? ' selected="selected"' : '';
  555. $rank_options .= '<option value="' . $row['rank_id'] . '"' . $selected . '>' . $row['rank_title'] . '</option>';
  556. }
  557. $db->sql_freeresult($result);
  558. $type_free = ($group_type == GROUP_FREE) ? ' checked="checked"' : '';
  559. $type_open = ($group_type == GROUP_OPEN) ? ' checked="checked"' : '';
  560. $type_closed = ($group_type == GROUP_CLOSED) ? ' checked="checked"' : '';
  561. $type_hidden = ($group_type == GROUP_HIDDEN) ? ' checked="checked"' : '';
  562. $display_gallery = (isset($_POST['display_gallery'])) ? true : false;
  563. if ($config['allow_avatar'] && $config['allow_avatar_local'] && $display_gallery)
  564. {
  565. avatar_gallery($category, $avatar_select, 4);
  566. }
  567. $avatars_enabled = ($config['allow_avatar'] && (($can_upload && ($config['allow_avatar_upload'] || $config['allow_avatar_remote_upload'])) || ($config['allow_avatar_local'] || $config['allow_avatar_remote']))) ? true : false;
  568. $template->assign_vars(array(
  569. 'S_EDIT' => true,
  570. 'S_INCLUDE_SWATCH' => true,
  571. 'S_FORM_ENCTYPE' => ($config['allow_avatar'] && $can_upload && ($config['allow_avatar_upload'] || $config['allow_avatar_remote_upload'])) ? ' enctype="multipart/form-data"' : '',
  572. 'S_ERROR' => (sizeof($error)) ? true : false,
  573. 'S_SPECIAL_GROUP' => ($group_type == GROUP_SPECIAL) ? true : false,
  574. 'S_AVATARS_ENABLED' => $avatars_enabled,
  575. 'S_DISPLAY_GALLERY' => ($config['allow_avatar'] && $config['allow_avatar_local'] && !$display_gallery) ? true : false,
  576. 'S_IN_GALLERY' => ($config['allow_avatar_local'] && $display_gallery) ? true : false,
  577. 'S_UPLOAD_AVATAR_FILE' => ($config['allow_avatar'] && $config['allow_avatar_upload'] && $can_upload) ? true : false,
  578. 'S_UPLOAD_AVATAR_URL' => ($config['allow_avatar'] && $config['allow_avatar_remote_upload'] && $can_upload) ? true : false,
  579. 'S_LINK_AVATAR' => ($config['allow_avatar'] && $config['allow_avatar_remote']) ? true : false,
  580. 'ERROR_MSG' => (sizeof($error)) ? implode('<br />', $error) : '',
  581. 'GROUP_RECEIVE_PM' => (isset($group_row['group_receive_pm']) && $group_row['group_receive_pm']) ? ' checked="checked"' : '',
  582. 'GROUP_MESSAGE_LIMIT' => (isset($group_row['group_message_limit'])) ? $group_row['group_message_limit'] : 0,
  583. 'GROUP_MAX_RECIPIENTS' => (isset($group_row['group_max_recipients'])) ? $group_row['group_max_recipients'] : 0,
  584. 'GROUP_DESC' => $group_desc_data['text'],
  585. 'S_DESC_BBCODE_CHECKED' => $group_desc_data['allow_bbcode'],
  586. 'S_DESC_URLS_CHECKED' => $group_desc_data['allow_urls'],
  587. 'S_DESC_SMILIES_CHECKED'=> $group_desc_data['allow_smilies'],
  588. 'S_RANK_OPTIONS' => $rank_options,
  589. 'AVATAR_MAX_FILESIZE' => $config['avatar_filesize'],
  590. 'GROUP_TYPE_FREE' => GROUP_FREE,
  591. 'GROUP_TYPE_OPEN' => GROUP_OPEN,
  592. 'GROUP_TYPE_CLOSED' => GROUP_CLOSED,
  593. 'GROUP_TYPE_HIDDEN' => GROUP_HIDDEN,
  594. 'GROUP_TYPE_SPECIAL' => GROUP_SPECIAL,
  595. 'GROUP_FREE' => $type_free,
  596. 'GROUP_OPEN' => $type_open,
  597. 'GROUP_CLOSED' => $type_closed,
  598. 'GROUP_HIDDEN' => $type_hidden,
  599. 'U_SWATCH' => append_sid("{$phpbb_root_path}adm/swatch.$phpEx", 'form=ucp&amp;name=group_colour'),
  600. 'S_UCP_ACTION' => $this->u_action . "&amp;action=$action&amp;g=$group_id",
  601. 'L_AVATAR_EXPLAIN' => sprintf($user->lang['AVATAR_EXPLAIN'], $config['avatar_max_width'], $config['avatar_max_height'], $config['avatar_filesize'] / 1024),
  602. ));
  603. break;
  604. case 'list':
  605. if (!$group_id)
  606. {
  607. trigger_error($user->lang['NO_GROUP'] . $return_page);
  608. }
  609. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  610. {
  611. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  612. }
  613. list(, $row) = each($row);
  614. if (!$row['group_leader'])
  615. {
  616. trigger_error($user->lang['NOT_LEADER_OF_GROUP'] . $return_page);
  617. }
  618. $user->add_lang(array('acp/groups', 'acp/common'));
  619. $start = request_var('start', 0);
  620. // Grab the leaders - always, on every page...
  621. $sql = 'SELECT u.user_id, u.username, u.username_clean, u.user_colour, u.user_regdate, u.user_posts, u.group_id, ug.group_leader, ug.user_pending
  622. FROM ' . USERS_TABLE . ' u, ' . USER_GROUP_TABLE . " ug
  623. WHERE ug.group_id = $group_id
  624. AND u.user_id = ug.user_id
  625. AND ug.group_leader = 1
  626. ORDER BY ug.user_pending DESC, u.username_clean";
  627. $result = $db->sql_query($sql);
  628. while ($row = $db->sql_fetchrow($result))
  629. {
  630. $template->assign_block_vars('leader', array(
  631. 'USERNAME' => $row['username'],
  632. 'USERNAME_COLOUR' => $row['user_colour'],
  633. 'USERNAME_FULL' => get_username_string('full', $row['user_id'], $row['username'], $row['user_colour']),
  634. 'U_USER_VIEW' => get_username_string('profile', $row['user_id'], $row['username']),
  635. 'S_GROUP_DEFAULT' => ($row['group_id'] == $group_id) ? true : false,
  636. 'JOINED' => ($row['user_regdate']) ? $user->format_date($row['user_regdate']) : ' - ',
  637. 'USER_POSTS' => $row['user_posts'],
  638. 'USER_ID' => $row['user_id'])
  639. );
  640. }
  641. $db->sql_freeresult($result);
  642. // Total number of group members (non-leaders)
  643. $sql = 'SELECT COUNT(user_id) AS total_members
  644. FROM ' . USER_GROUP_TABLE . "
  645. WHERE group_id = $group_id
  646. AND group_leader = 0";
  647. $result = $db->sql_query($sql);
  648. $total_members = (int) $db->sql_fetchfield('total_members');
  649. $db->sql_freeresult($result);
  650. // Grab the members
  651. $sql = 'SELECT u.user_id, u.username, u.username_clean, u.user_colour, u.user_regdate, u.user_posts, u.group_id, ug.group_leader, ug.user_pending
  652. FROM ' . USERS_TABLE . ' u, ' . USER_GROUP_TABLE . " ug
  653. WHERE ug.group_id = $group_id
  654. AND u.user_id = ug.user_id
  655. AND ug.group_leader = 0
  656. ORDER BY ug.user_pending DESC, u.username_clean";
  657. $result = $db->sql_query_limit($sql, $config['topics_per_page'], $start);
  658. $pending = false;
  659. $approved = false;
  660. while ($row = $db->sql_fetchrow($result))
  661. {
  662. if ($row['user_pending'] && !$pending)
  663. {
  664. $template->assign_block_vars('member', array(
  665. 'S_PENDING' => true)
  666. );
  667. $template->assign_var('S_PENDING_SET', true);
  668. $pending = true;
  669. }
  670. else if (!$row['user_pending'] && !$approved)
  671. {
  672. $template->assign_block_vars('member', array(
  673. 'S_APPROVED' => true)
  674. );
  675. $template->assign_var('S_APPROVED_SET', true);
  676. $approved = true;
  677. }
  678. $template->assign_block_vars('member', array(
  679. 'USERNAME' => $row['username'],
  680. 'USERNAME_COLOUR' => $row['user_colour'],
  681. 'USERNAME_FULL' => get_username_string('full', $row['user_id'], $row['username'], $row['user_colour']),
  682. 'U_USER_VIEW' => get_username_string('profile', $row['user_id'], $row['username']),
  683. 'S_GROUP_DEFAULT' => ($row['group_id'] == $group_id) ? true : false,
  684. 'JOINED' => ($row['user_regdate']) ? $user->format_date($row['user_regdate']) : ' - ',
  685. 'USER_POSTS' => $row['user_posts'],
  686. 'USER_ID' => $row['user_id'])
  687. );
  688. }
  689. $db->sql_freeresult($result);
  690. $s_action_options = '';
  691. $options = array('default' => 'DEFAULT', 'approve' => 'APPROVE', 'deleteusers' => 'DELETE');
  692. foreach ($options as $option => $lang)
  693. {
  694. $s_action_options .= '<option value="' . $option . '">' . $user->lang['GROUP_' . $lang] . '</option>';
  695. }
  696. $template->assign_vars(array(
  697. 'S_LIST' => true,
  698. 'S_ACTION_OPTIONS' => $s_action_options,
  699. 'S_ON_PAGE' => on_page($total_members, $config['topics_per_page'], $start),
  700. 'PAGINATION' => generate_pagination($this->u_action . "&amp;action=$action&amp;g=$group_id", $total_members, $config['topics_per_page'], $start),
  701. 'U_ACTION' => $this->u_action . "&amp;g=$group_id",
  702. 'S_UCP_ACTION' => $this->u_action . "&amp;g=$group_id",
  703. 'U_FIND_USERNAME' => append_sid("{$phpbb_root_path}memberlist.$phpEx", 'mode=searchuser&amp;form=ucp&amp;field=usernames'),
  704. ));
  705. break;
  706. case 'approve':
  707. if (!$group_id)
  708. {
  709. trigger_error($user->lang['NO_GROUP'] . $return_page);
  710. }
  711. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  712. {
  713. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  714. }
  715. list(, $row) = each($row);
  716. if (!$row['group_leader'])
  717. {
  718. trigger_error($user->lang['NOT_LEADER_OF_GROUP'] . $return_page);
  719. }
  720. $user->add_lang('acp/groups');
  721. // Approve, demote or promote
  722. group_user_attributes('approve', $group_id, $mark_ary, false, false);
  723. trigger_error($user->lang['USERS_APPROVED'] . '<br /><br />' . sprintf($user->lang['RETURN_PAGE'], '<a href="' . $this->u_action . '&amp;action=list&amp;g=' . $group_id . '">', '</a>'));
  724. break;
  725. case 'default':
  726. if (!$group_id)
  727. {
  728. trigger_error($user->lang['NO_GROUP'] . $return_page);
  729. }
  730. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  731. {
  732. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  733. }
  734. list(, $row) = each($row);
  735. if (!$row['group_leader'])
  736. {
  737. trigger_error($user->lang['NOT_LEADER_OF_GROUP'] . $return_page);
  738. }
  739. $group_row['group_name'] = ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'];
  740. if (confirm_box(true))
  741. {
  742. if (!sizeof($mark_ary))
  743. {
  744. $start = 0;
  745. do
  746. {
  747. $sql = 'SELECT user_id
  748. FROM ' . USER_GROUP_TABLE . "
  749. WHERE group_id = $group_id
  750. ORDER BY user_id";
  751. $result = $db->sql_query_limit($sql, 200, $start);
  752. $mark_ary = array();
  753. if ($row = $db->sql_fetchrow($result))
  754. {
  755. do
  756. {
  757. $mark_ary[] = $row['user_id'];
  758. }
  759. while ($row = $db->sql_fetchrow($result));
  760. group_user_attributes('default', $group_id, $mark_ary, false, $group_row['group_name'], $group_row);
  761. $start = (sizeof($mark_ary) < 200) ? 0 : $start + 200;
  762. }
  763. else
  764. {
  765. $start = 0;
  766. }
  767. $db->sql_freeresult($result);
  768. }
  769. while ($start);
  770. }
  771. else
  772. {
  773. group_user_attributes('default', $group_id, $mark_ary, false, $group_row['group_name'], $group_row);
  774. }
  775. $user->add_lang('acp/groups');
  776. trigger_error($user->lang['GROUP_DEFS_UPDATED'] . '<br /><br />' . sprintf($user->lang['RETURN_PAGE'], '<a href="' . $this->u_action . '&amp;action=list&amp;g=' . $group_id . '">', '</a>'));
  777. }
  778. else
  779. {
  780. $user->add_lang('acp/common');
  781. confirm_box(false, $user->lang['CONFIRM_OPERATION'], build_hidden_fields(array(
  782. 'mark' => $mark_ary,
  783. 'g' => $group_id,
  784. 'i' => $id,
  785. 'mode' => $mode,
  786. 'action' => $action))
  787. );
  788. }
  789. // redirect to last screen
  790. redirect($this->u_action . '&amp;action=list&amp;g=' . $group_id);
  791. break;
  792. case 'deleteusers':
  793. $user->add_lang(array('acp/groups', 'acp/common'));
  794. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  795. {
  796. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  797. }
  798. list(, $row) = each($row);
  799. if (!$row['group_leader'])
  800. {
  801. trigger_error($user->lang['NOT_LEADER_OF_GROUP'] . $return_page);
  802. }
  803. $group_row['group_name'] = ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'];
  804. if (confirm_box(true))
  805. {
  806. if (!$group_id)
  807. {
  808. trigger_error($user->lang['NO_GROUP'] . $return_page);
  809. }
  810. $error = group_user_del($group_id, $mark_ary, false, $group_row['group_name']);
  811. if ($error)
  812. {
  813. trigger_error($user->lang[$error] . '<br /><br />' . sprintf($user->lang['RETURN_PAGE'], '<a href="' . $this->u_action . '&amp;action=list&amp;g=' . $group_id . '">', '</a>'));
  814. }
  815. trigger_error($user->lang['GROUP_USERS_REMOVE'] . '<br /><br />' . sprintf($user->lang['RETURN_PAGE'], '<a href="' . $this->u_action . '&amp;action=list&amp;g=' . $group_id . '">', '</a>'));
  816. }
  817. else
  818. {
  819. confirm_box(false, $user->lang['CONFIRM_OPERATION'], build_hidden_fields(array(
  820. 'mark' => $mark_ary,
  821. 'g' => $group_id,
  822. 'i' => $id,
  823. 'mode' => $mode,
  824. 'action' => $action))
  825. );
  826. }
  827. // redirect to last screen
  828. redirect($this->u_action . '&amp;action=list&amp;g=' . $group_id);
  829. break;
  830. case 'addusers':
  831. $user->add_lang(array('acp/groups', 'acp/common'));
  832. $names = utf8_normalize_nfc(request_var('usernames', '', true));
  833. if (!$group_id)
  834. {
  835. trigger_error($user->lang['NO_GROUP'] . $return_page);
  836. }
  837. if (!$names)
  838. {
  839. trigger_error($user->lang['NO_USERS'] . $return_page);
  840. }
  841. if (!($row = group_memberships($group_id, $user->data['user_id'])))
  842. {
  843. trigger_error($user->lang['NOT_MEMBER_OF_GROUP'] . $return_page);
  844. }
  845. list(, $row) = each($row);
  846. if (!$row['group_leader'])
  847. {
  848. trigger_error($user->lang['NOT_LEADER_OF_GROUP'] . $return_page);
  849. }
  850. $name_ary = array_unique(explode("\n", $names));
  851. $group_name = ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'];
  852. $default = request_var('default', 0);
  853. if (confirm_box(true))
  854. {
  855. // Add user/s to group
  856. if ($error = group_user_add($group_id, false, $name_ary, $group_name, $default, 0, 0, $group_row))
  857. {
  858. trigger_error($user->lang[$error] . $return_page);
  859. }
  860. trigger_error($user->lang['GROUP_USERS_ADDED'] . '<br /><br />' . sprintf($user->lang['RETURN_PAGE'], '<a href="' . $this->u_action . '&amp;action=list&amp;g=' . $group_id . '">', '</a>'));
  861. }
  862. else
  863. {
  864. $s_hidden_fields = array(
  865. 'default' => $default,
  866. 'usernames' => $names,
  867. 'g' => $group_id,
  868. 'i' => $id,
  869. 'mode' => $mode,
  870. 'action' => $action
  871. );
  872. confirm_box(false, sprintf($user->lang['GROUP_CONFIRM_ADD_USER' . ((sizeof($name_ary) == 1) ? '' : 'S')], implode(', ', $name_ary)), build_hidden_fields($s_hidden_fields));
  873. }
  874. trigger_error($user->lang['NO_USERS_ADDED'] . '<br /><br />' . sprintf($user->lang['RETURN_PAGE'], '<a href="' . $this->u_action . '&amp;action=list&amp;g=' . $group_id . '">', '</a>'));
  875. break;
  876. default:
  877. $user->add_lang('acp/common');
  878. $sql = 'SELECT g.group_id, g.group_name, g.group_colour, g.group_desc, g.group_desc_uid, g.group_desc_bitfield, g.group_desc_options, g.group_type, ug.group_leader
  879. FROM ' . GROUPS_TABLE . ' g, ' . USER_GROUP_TABLE . ' ug
  880. WHERE ug.user_id = ' . $user->data['user_id'] . '
  881. AND g.group_id = ug.group_id
  882. AND ug.group_leader = 1
  883. ORDER BY g.group_type DESC, g.group_name';
  884. $result = $db->sql_query($sql);
  885. while ($value = $db->sql_fetchrow($result))
  886. {
  887. $template->assign_block_vars('leader', array(
  888. 'GROUP_NAME' => ($value['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $value['group_name']] : $value['group_name'],
  889. 'GROUP_DESC' => generate_text_for_display($value['group_desc'], $value['group_desc_uid'], $value['group_desc_bitfield'], $value['group_desc_options']),
  890. 'GROUP_TYPE' => $value['group_type'],
  891. 'GROUP_ID' => $value['group_id'],
  892. 'GROUP_COLOUR' => $value['group_colour'],
  893. 'U_LIST' => $this->u_action . "&amp;action=list&amp;g={$value['group_id']}",
  894. 'U_EDIT' => $this->u_action . "&amp;action=edit&amp;g={$value['group_id']}")
  895. );
  896. }
  897. $db->sql_freeresult($result);
  898. break;
  899. }
  900. break;
  901. }
  902. $this->tpl_name = 'ucp_groups_' . $mode;
  903. }
  904. }
  905. ?>