PageRenderTime 40ms CodeModel.GetById 11ms RepoModel.GetById 1ms app.codeStats 0ms

/phpBB3/includes/acp/acp_groups.php

http://pbb-png1.googlecode.com/
PHP | 776 lines | 601 code | 129 blank | 46 comment | 140 complexity | e09d131670bc438901ec311505219b7f MD5 | raw file
  1. <?php
  2. /**
  3. *
  4. * @package acp
  5. * @version $Id: acp_groups.php 9053 2008-11-09 15:10:40Z acydburn $
  6. * @copyright (c) 2005 phpBB Group
  7. * @license http://opensource.org/licenses/gpl-license.php GNU Public License
  8. *
  9. */
  10. /**
  11. * @ignore
  12. */
  13. if (!defined('IN_PHPBB'))
  14. {
  15. exit;
  16. }
  17. /**
  18. * @package acp
  19. */
  20. class acp_groups
  21. {
  22. var $u_action;
  23. function main($id, $mode)
  24. {
  25. global $config, $db, $user, $auth, $template, $cache;
  26. global $phpbb_root_path, $phpbb_admin_path, $phpEx, $table_prefix, $file_uploads;
  27. $user->add_lang('acp/groups');
  28. $this->tpl_name = 'acp_groups';
  29. $this->page_title = 'ACP_GROUPS_MANAGE';
  30. $form_key = 'acp_groups';
  31. add_form_key($form_key);
  32. include($phpbb_root_path . 'includes/functions_user.' . $phpEx);
  33. // Check and set some common vars
  34. $action = (isset($_POST['add'])) ? 'add' : ((isset($_POST['addusers'])) ? 'addusers' : request_var('action', ''));
  35. $group_id = request_var('g', 0);
  36. $mark_ary = request_var('mark', array(0));
  37. $name_ary = request_var('usernames', '', true);
  38. $leader = request_var('leader', 0);
  39. $default = request_var('default', 0);
  40. $start = request_var('start', 0);
  41. $update = (isset($_POST['update'])) ? true : false;
  42. // Clear some vars
  43. $can_upload = (file_exists($phpbb_root_path . $config['avatar_path']) && @is_writable($phpbb_root_path . $config['avatar_path']) && $file_uploads) ? true : false;
  44. $group_row = array();
  45. // Grab basic data for group, if group_id is set and exists
  46. if ($group_id)
  47. {
  48. $sql = 'SELECT *
  49. FROM ' . GROUPS_TABLE . "
  50. WHERE group_id = $group_id";
  51. $result = $db->sql_query($sql);
  52. $group_row = $db->sql_fetchrow($result);
  53. $db->sql_freeresult($result);
  54. if (!$group_row)
  55. {
  56. trigger_error($user->lang['NO_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  57. }
  58. // Check if the user is allowed to manage this group if set to founder only.
  59. if ($user->data['user_type'] != USER_FOUNDER && $group_row['group_founder_manage'])
  60. {
  61. trigger_error($user->lang['NOT_ALLOWED_MANAGE_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  62. }
  63. }
  64. // Which page?
  65. switch ($action)
  66. {
  67. case 'approve':
  68. case 'demote':
  69. case 'promote':
  70. if (!$group_id)
  71. {
  72. trigger_error($user->lang['NO_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  73. }
  74. // Approve, demote or promote
  75. $group_name = ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'];
  76. $error = group_user_attributes($action, $group_id, $mark_ary, false, $group_name);
  77. if (!$error)
  78. {
  79. switch ($action)
  80. {
  81. case 'demote':
  82. $message = 'GROUP_MODS_DEMOTED';
  83. break;
  84. case 'promote':
  85. $message = 'GROUP_MODS_PROMOTED';
  86. break;
  87. case 'approve':
  88. $message = 'USERS_APPROVED';
  89. break;
  90. }
  91. trigger_error($user->lang[$message] . adm_back_link($this->u_action . '&amp;action=list&amp;g=' . $group_id));
  92. }
  93. else
  94. {
  95. trigger_error($user->lang[$error] . adm_back_link($this->u_action . '&amp;action=list&amp;g=' . $group_id), E_USER_WARNING);
  96. }
  97. break;
  98. case 'default':
  99. if (!$group_id)
  100. {
  101. trigger_error($user->lang['NO_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  102. }
  103. if (confirm_box(true))
  104. {
  105. $group_name = ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'];
  106. if (!sizeof($mark_ary))
  107. {
  108. $start = 0;
  109. do
  110. {
  111. $sql = 'SELECT user_id
  112. FROM ' . USER_GROUP_TABLE . "
  113. WHERE group_id = $group_id
  114. ORDER BY user_id";
  115. $result = $db->sql_query_limit($sql, 200, $start);
  116. $mark_ary = array();
  117. if ($row = $db->sql_fetchrow($result))
  118. {
  119. do
  120. {
  121. $mark_ary[] = $row['user_id'];
  122. }
  123. while ($row = $db->sql_fetchrow($result));
  124. group_user_attributes('default', $group_id, $mark_ary, false, $group_name, $group_row);
  125. $start = (sizeof($mark_ary) < 200) ? 0 : $start + 200;
  126. }
  127. else
  128. {
  129. $start = 0;
  130. }
  131. $db->sql_freeresult($result);
  132. }
  133. while ($start);
  134. }
  135. else
  136. {
  137. group_user_attributes('default', $group_id, $mark_ary, false, $group_name, $group_row);
  138. }
  139. trigger_error($user->lang['GROUP_DEFS_UPDATED'] . adm_back_link($this->u_action . '&amp;action=list&amp;g=' . $group_id));
  140. }
  141. else
  142. {
  143. confirm_box(false, $user->lang['CONFIRM_OPERATION'], build_hidden_fields(array(
  144. 'mark' => $mark_ary,
  145. 'g' => $group_id,
  146. 'i' => $id,
  147. 'mode' => $mode,
  148. 'action' => $action))
  149. );
  150. }
  151. break;
  152. case 'deleteusers':
  153. case 'delete':
  154. if (!$group_id)
  155. {
  156. trigger_error($user->lang['NO_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  157. }
  158. else if ($action === 'delete' && $group_row['group_type'] == GROUP_SPECIAL)
  159. {
  160. trigger_error($user->lang['NO_AUTH_OPERATION'] . adm_back_link($this->u_action), E_USER_WARNING);
  161. }
  162. if (confirm_box(true))
  163. {
  164. $error = '';
  165. switch ($action)
  166. {
  167. case 'delete':
  168. if (!$auth->acl_get('a_groupdel'))
  169. {
  170. trigger_error($user->lang['NO_AUTH_OPERATION'] . adm_back_link($this->u_action), E_USER_WARNING);
  171. }
  172. $error = group_delete($group_id, $group_row['group_name']);
  173. break;
  174. case 'deleteusers':
  175. $group_name = ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'];
  176. $error = group_user_del($group_id, $mark_ary, false, $group_name);
  177. break;
  178. }
  179. $back_link = ($action == 'delete') ? $this->u_action : $this->u_action . '&amp;action=list&amp;g=' . $group_id;
  180. if ($error)
  181. {
  182. trigger_error($user->lang[$error] . adm_back_link($back_link), E_USER_WARNING);
  183. }
  184. $message = ($action == 'delete') ? 'GROUP_DELETED' : 'GROUP_USERS_REMOVE';
  185. trigger_error($user->lang[$message] . adm_back_link($back_link));
  186. }
  187. else
  188. {
  189. confirm_box(false, $user->lang['CONFIRM_OPERATION'], build_hidden_fields(array(
  190. 'mark' => $mark_ary,
  191. 'g' => $group_id,
  192. 'i' => $id,
  193. 'mode' => $mode,
  194. 'action' => $action))
  195. );
  196. }
  197. break;
  198. case 'addusers':
  199. if (!$group_id)
  200. {
  201. trigger_error($user->lang['NO_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  202. }
  203. if (!$name_ary)
  204. {
  205. trigger_error($user->lang['NO_USERS'] . adm_back_link($this->u_action . '&amp;action=list&amp;g=' . $group_id), E_USER_WARNING);
  206. }
  207. $name_ary = array_unique(explode("\n", $name_ary));
  208. $group_name = ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'];
  209. // Add user/s to group
  210. if ($error = group_user_add($group_id, false, $name_ary, $group_name, $default, $leader, 0, $group_row))
  211. {
  212. trigger_error($user->lang[$error] . adm_back_link($this->u_action . '&amp;action=list&amp;g=' . $group_id), E_USER_WARNING);
  213. }
  214. $message = ($leader) ? 'GROUP_MODS_ADDED' : 'GROUP_USERS_ADDED';
  215. trigger_error($user->lang[$message] . adm_back_link($this->u_action . '&amp;action=list&amp;g=' . $group_id));
  216. break;
  217. case 'edit':
  218. case 'add':
  219. include($phpbb_root_path . 'includes/functions_display.' . $phpEx);
  220. $data = $submit_ary = array();
  221. if ($action == 'edit' && !$group_id)
  222. {
  223. trigger_error($user->lang['NO_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  224. }
  225. if ($action == 'add' && !$auth->acl_get('a_groupadd'))
  226. {
  227. trigger_error($user->lang['NO_AUTH_OPERATION'] . adm_back_link($this->u_action), E_USER_WARNING);
  228. }
  229. $error = array();
  230. $user->add_lang('ucp');
  231. $avatar_select = basename(request_var('avatar_select', ''));
  232. $category = basename(request_var('category', ''));
  233. // Did we submit?
  234. if ($update)
  235. {
  236. if (!check_form_key($form_key))
  237. {
  238. trigger_error($user->lang['FORM_INVALID'] . adm_back_link($this->u_action), E_USER_WARNING);
  239. }
  240. $group_name = utf8_normalize_nfc(request_var('group_name', '', true));
  241. $group_desc = utf8_normalize_nfc(request_var('group_desc', '', true));
  242. $group_type = request_var('group_type', GROUP_FREE);
  243. $allow_desc_bbcode = request_var('desc_parse_bbcode', false);
  244. $allow_desc_urls = request_var('desc_parse_urls', false);
  245. $allow_desc_smilies = request_var('desc_parse_smilies', false);
  246. $data['uploadurl'] = request_var('uploadurl', '');
  247. $data['remotelink'] = request_var('remotelink', '');
  248. $data['width'] = request_var('width', '');
  249. $data['height'] = request_var('height', '');
  250. $delete = request_var('delete', '');
  251. $submit_ary = array(
  252. 'colour' => request_var('group_colour', ''),
  253. 'rank' => request_var('group_rank', 0),
  254. 'receive_pm' => isset($_REQUEST['group_receive_pm']) ? 1 : 0,
  255. 'legend' => isset($_REQUEST['group_legend']) ? 1 : 0,
  256. 'message_limit' => request_var('group_message_limit', 0),
  257. 'max_recipients' => request_var('group_max_recipients', 0),
  258. 'founder_manage' => 0,
  259. );
  260. if ($user->data['user_type'] == USER_FOUNDER)
  261. {
  262. $submit_ary['founder_manage'] = isset($_REQUEST['group_founder_manage']) ? 1 : 0;
  263. }
  264. if (!empty($_FILES['uploadfile']['tmp_name']) || $data['uploadurl'] || $data['remotelink'])
  265. {
  266. // Avatar stuff
  267. $var_ary = array(
  268. 'uploadurl' => array('string', true, 5, 255),
  269. 'remotelink' => array('string', true, 5, 255),
  270. 'width' => array('string', true, 1, 3),
  271. 'height' => array('string', true, 1, 3),
  272. );
  273. if (!($error = validate_data($data, $var_ary)))
  274. {
  275. $data['user_id'] = "g$group_id";
  276. if ((!empty($_FILES['uploadfile']['tmp_name']) || $data['uploadurl']) && $can_upload)
  277. {
  278. list($submit_ary['avatar_type'], $submit_ary['avatar'], $submit_ary['avatar_width'], $submit_ary['avatar_height']) = avatar_upload($data, $error);
  279. }
  280. else if ($data['remotelink'])
  281. {
  282. list($submit_ary['avatar_type'], $submit_ary['avatar'], $submit_ary['avatar_width'], $submit_ary['avatar_height']) = avatar_remote($data, $error);
  283. }
  284. }
  285. }
  286. else if ($avatar_select && $config['allow_avatar_local'])
  287. {
  288. // check avatar gallery
  289. if (is_dir($phpbb_root_path . $config['avatar_gallery_path'] . '/' . $category))
  290. {
  291. $submit_ary['avatar_type'] = AVATAR_GALLERY;
  292. list($submit_ary['avatar_width'], $submit_ary['avatar_height']) = getimagesize($phpbb_root_path . $config['avatar_gallery_path'] . '/' . $category . '/' . $avatar_select);
  293. $submit_ary['avatar'] = $category . '/' . $avatar_select;
  294. }
  295. }
  296. else if ($delete)
  297. {
  298. $submit_ary['avatar'] = '';
  299. $submit_ary['avatar_type'] = $submit_ary['avatar_width'] = $submit_ary['avatar_height'] = 0;
  300. }
  301. else if ($data['width'] && $data['height'])
  302. {
  303. // Only update the dimensions?
  304. if ($config['avatar_max_width'] || $config['avatar_max_height'])
  305. {
  306. if ($data['width'] > $config['avatar_max_width'] || $data['height'] > $config['avatar_max_height'])
  307. {
  308. $error[] = sprintf($user->lang['AVATAR_WRONG_SIZE'], $config['avatar_min_width'], $config['avatar_min_height'], $config['avatar_max_width'], $config['avatar_max_height'], $data['width'], $data['height']);
  309. }
  310. }
  311. if (!sizeof($error))
  312. {
  313. if ($config['avatar_min_width'] || $config['avatar_min_height'])
  314. {
  315. if ($data['width'] < $config['avatar_min_width'] || $data['height'] < $config['avatar_min_height'])
  316. {
  317. $error[] = sprintf($user->lang['AVATAR_WRONG_SIZE'], $config['avatar_min_width'], $config['avatar_min_height'], $config['avatar_max_width'], $config['avatar_max_height'], $data['width'], $data['height']);
  318. }
  319. }
  320. }
  321. if (!sizeof($error))
  322. {
  323. $submit_ary['avatar_width'] = $data['width'];
  324. $submit_ary['avatar_height'] = $data['height'];
  325. }
  326. }
  327. if ((isset($submit_ary['avatar']) && $submit_ary['avatar'] && (!isset($group_row['group_avatar']))) || $delete)
  328. {
  329. if (isset($group_row['group_avatar']) && $group_row['group_avatar'])
  330. {
  331. avatar_delete('group', $group_row, true);
  332. }
  333. }
  334. if (!sizeof($error))
  335. {
  336. // Only set the rank, colour, etc. if it's changed or if we're adding a new
  337. // group. This prevents existing group members being updated if no changes
  338. // were made.
  339. $group_attributes = array();
  340. $test_variables = array('rank', 'colour', 'avatar', 'avatar_type', 'avatar_width', 'avatar_height', 'receive_pm', 'legend', 'message_limit', 'max_recipients', 'founder_manage');
  341. foreach ($test_variables as $test)
  342. {
  343. if (isset($submit_ary[$test]) && ($action == 'add' || $group_row['group_' . $test] != $submit_ary[$test]))
  344. {
  345. $group_attributes['group_' . $test] = $group_row['group_' . $test] = $submit_ary[$test];
  346. }
  347. }
  348. if (!($error = group_create($group_id, $group_type, $group_name, $group_desc, $group_attributes, $allow_desc_bbcode, $allow_desc_urls, $allow_desc_smilies)))
  349. {
  350. $group_perm_from = request_var('group_perm_from', 0);
  351. // Copy permissions?
  352. // If the user has the a_authgroups permission and at least one additional permission ability set the permissions are fully transferred.
  353. // We do not limit on one auth category because this can lead to incomplete permissions being tricky to fix for the admin, roles being assigned or added non-default permissions.
  354. // Since the user only has the option to copy permissions from non leader managed groups this seems to be a good compromise.
  355. if ($group_perm_from && $action == 'add' && $auth->acl_get('a_authgroups') && $auth->acl_gets('a_aauth', 'a_fauth', 'a_mauth', 'a_uauth'))
  356. {
  357. $sql = 'SELECT group_founder_manage
  358. FROM ' . GROUPS_TABLE . '
  359. WHERE group_id = ' . $group_perm_from;
  360. $result = $db->sql_query($sql);
  361. $check_row = $db->sql_fetchrow($result);
  362. $db->sql_freeresult($result);
  363. // Check the group if non-founder
  364. if ($check_row && ($user->data['user_type'] == USER_FOUNDER || $check_row['group_founder_manage'] == 0))
  365. {
  366. // From the mysql documentation:
  367. // Prior to MySQL 4.0.14, the target table of the INSERT statement cannot appear in the FROM clause of the SELECT part of the query. This limitation is lifted in 4.0.14.
  368. // Due to this we stay on the safe side if we do the insertion "the manual way"
  369. // Copy permisisons from/to the acl groups table (only group_id gets changed)
  370. $sql = 'SELECT forum_id, auth_option_id, auth_role_id, auth_setting
  371. FROM ' . ACL_GROUPS_TABLE . '
  372. WHERE group_id = ' . $group_perm_from;
  373. $result = $db->sql_query($sql);
  374. $groups_sql_ary = array();
  375. while ($row = $db->sql_fetchrow($result))
  376. {
  377. $groups_sql_ary[] = array(
  378. 'group_id' => (int) $group_id,
  379. 'forum_id' => (int) $row['forum_id'],
  380. 'auth_option_id' => (int) $row['auth_option_id'],
  381. 'auth_role_id' => (int) $row['auth_role_id'],
  382. 'auth_setting' => (int) $row['auth_setting']
  383. );
  384. }
  385. $db->sql_freeresult($result);
  386. // Now insert the data
  387. $db->sql_multi_insert(ACL_GROUPS_TABLE, $groups_sql_ary);
  388. $auth->acl_clear_prefetch();
  389. }
  390. }
  391. $cache->destroy('sql', GROUPS_TABLE);
  392. $message = ($action == 'edit') ? 'GROUP_UPDATED' : 'GROUP_CREATED';
  393. trigger_error($user->lang[$message] . adm_back_link($this->u_action));
  394. }
  395. }
  396. if (sizeof($error))
  397. {
  398. $group_rank = $submit_ary['rank'];
  399. $group_desc_data = array(
  400. 'text' => $group_desc,
  401. 'allow_bbcode' => $allow_desc_bbcode,
  402. 'allow_smilies' => $allow_desc_smilies,
  403. 'allow_urls' => $allow_desc_urls
  404. );
  405. }
  406. }
  407. else if (!$group_id)
  408. {
  409. $group_name = utf8_normalize_nfc(request_var('group_name', '', true));
  410. $group_desc_data = array(
  411. 'text' => '',
  412. 'allow_bbcode' => true,
  413. 'allow_smilies' => true,
  414. 'allow_urls' => true
  415. );
  416. $group_rank = 0;
  417. $group_type = GROUP_OPEN;
  418. }
  419. else
  420. {
  421. $group_name = $group_row['group_name'];
  422. $group_desc_data = generate_text_for_edit($group_row['group_desc'], $group_row['group_desc_uid'], $group_row['group_desc_options']);
  423. $group_type = $group_row['group_type'];
  424. $group_rank = $group_row['group_rank'];
  425. }
  426. $sql = 'SELECT *
  427. FROM ' . RANKS_TABLE . '
  428. WHERE rank_special = 1
  429. ORDER BY rank_title';
  430. $result = $db->sql_query($sql);
  431. $rank_options = '<option value="0"' . ((!$group_rank) ? ' selected="selected"' : '') . '>' . $user->lang['USER_DEFAULT'] . '</option>';
  432. while ($row = $db->sql_fetchrow($result))
  433. {
  434. $selected = ($group_rank && $row['rank_id'] == $group_rank) ? ' selected="selected"' : '';
  435. $rank_options .= '<option value="' . $row['rank_id'] . '"' . $selected . '>' . $row['rank_title'] . '</option>';
  436. }
  437. $db->sql_freeresult($result);
  438. $type_free = ($group_type == GROUP_FREE) ? ' checked="checked"' : '';
  439. $type_open = ($group_type == GROUP_OPEN) ? ' checked="checked"' : '';
  440. $type_closed = ($group_type == GROUP_CLOSED) ? ' checked="checked"' : '';
  441. $type_hidden = ($group_type == GROUP_HIDDEN) ? ' checked="checked"' : '';
  442. $avatar_img = (!empty($group_row['group_avatar'])) ? get_user_avatar($group_row['group_avatar'], $group_row['group_avatar_type'], $group_row['group_avatar_width'], $group_row['group_avatar_height'], 'GROUP_AVATAR') : '<img src="' . $phpbb_admin_path . 'images/no_avatar.gif" alt="" />';
  443. $display_gallery = (isset($_POST['display_gallery'])) ? true : false;
  444. if ($config['allow_avatar_local'] && $display_gallery)
  445. {
  446. avatar_gallery($category, $avatar_select, 4);
  447. }
  448. $back_link = request_var('back_link', '');
  449. switch ($back_link)
  450. {
  451. case 'acp_users_groups':
  452. $u_back = append_sid("{$phpbb_admin_path}index.$phpEx", 'i=users&amp;mode=groups&amp;u=' . request_var('u', 0));
  453. break;
  454. default:
  455. $u_back = $this->u_action;
  456. break;
  457. }
  458. $template->assign_vars(array(
  459. 'S_EDIT' => true,
  460. 'S_ADD_GROUP' => ($action == 'add') ? true : false,
  461. 'S_GROUP_PERM' => ($action == 'add' && $auth->acl_get('a_authgroups') && $auth->acl_gets('a_aauth', 'a_fauth', 'a_mauth', 'a_uauth')) ? true : false,
  462. 'S_INCLUDE_SWATCH' => true,
  463. 'S_CAN_UPLOAD' => $can_upload,
  464. 'S_ERROR' => (sizeof($error)) ? true : false,
  465. 'S_SPECIAL_GROUP' => ($group_type == GROUP_SPECIAL) ? true : false,
  466. 'S_DISPLAY_GALLERY' => ($config['allow_avatar_local'] && !$display_gallery) ? true : false,
  467. 'S_IN_GALLERY' => ($config['allow_avatar_local'] && $display_gallery) ? true : false,
  468. 'S_USER_FOUNDER' => ($user->data['user_type'] == USER_FOUNDER) ? true : false,
  469. 'ERROR_MSG' => (sizeof($error)) ? implode('<br />', $error) : '',
  470. 'GROUP_NAME' => ($group_type == GROUP_SPECIAL) ? $user->lang['G_' . $group_name] : $group_name,
  471. 'GROUP_INTERNAL_NAME' => $group_name,
  472. 'GROUP_DESC' => $group_desc_data['text'],
  473. 'GROUP_RECEIVE_PM' => (isset($group_row['group_receive_pm']) && $group_row['group_receive_pm']) ? ' checked="checked"' : '',
  474. 'GROUP_FOUNDER_MANAGE' => (isset($group_row['group_founder_manage']) && $group_row['group_founder_manage']) ? ' checked="checked"' : '',
  475. 'GROUP_LEGEND' => (isset($group_row['group_legend']) && $group_row['group_legend']) ? ' checked="checked"' : '',
  476. 'GROUP_MESSAGE_LIMIT' => (isset($group_row['group_message_limit'])) ? $group_row['group_message_limit'] : 0,
  477. 'GROUP_MAX_RECIPIENTS' => (isset($group_row['group_max_recipients'])) ? $group_row['group_max_recipients'] : 0,
  478. 'GROUP_COLOUR' => (isset($group_row['group_colour'])) ? $group_row['group_colour'] : '',
  479. 'S_DESC_BBCODE_CHECKED' => $group_desc_data['allow_bbcode'],
  480. 'S_DESC_URLS_CHECKED' => $group_desc_data['allow_urls'],
  481. 'S_DESC_SMILIES_CHECKED'=> $group_desc_data['allow_smilies'],
  482. 'S_RANK_OPTIONS' => $rank_options,
  483. 'S_GROUP_OPTIONS' => group_select_options(false, false, (($user->data['user_type'] == USER_FOUNDER) ? false : 0)),
  484. 'AVATAR' => $avatar_img,
  485. 'AVATAR_IMAGE' => $avatar_img,
  486. 'AVATAR_MAX_FILESIZE' => $config['avatar_filesize'],
  487. 'AVATAR_WIDTH' => (isset($group_row['group_avatar_width'])) ? $group_row['group_avatar_width'] : '',
  488. 'AVATAR_HEIGHT' => (isset($group_row['group_avatar_height'])) ? $group_row['group_avatar_height'] : '',
  489. 'GROUP_TYPE_FREE' => GROUP_FREE,
  490. 'GROUP_TYPE_OPEN' => GROUP_OPEN,
  491. 'GROUP_TYPE_CLOSED' => GROUP_CLOSED,
  492. 'GROUP_TYPE_HIDDEN' => GROUP_HIDDEN,
  493. 'GROUP_TYPE_SPECIAL' => GROUP_SPECIAL,
  494. 'GROUP_FREE' => $type_free,
  495. 'GROUP_OPEN' => $type_open,
  496. 'GROUP_CLOSED' => $type_closed,
  497. 'GROUP_HIDDEN' => $type_hidden,
  498. 'U_BACK' => $u_back,
  499. 'U_SWATCH' => append_sid("{$phpbb_admin_path}swatch.$phpEx", 'form=settings&amp;name=group_colour'),
  500. 'U_ACTION' => "{$this->u_action}&amp;action=$action&amp;g=$group_id",
  501. 'L_AVATAR_EXPLAIN' => sprintf($user->lang['AVATAR_EXPLAIN'], $config['avatar_max_width'], $config['avatar_max_height'], round($config['avatar_filesize'] / 1024)),
  502. )
  503. );
  504. return;
  505. break;
  506. case 'list':
  507. if (!$group_id)
  508. {
  509. trigger_error($user->lang['NO_GROUP'] . adm_back_link($this->u_action), E_USER_WARNING);
  510. }
  511. $this->page_title = 'GROUP_MEMBERS';
  512. // Grab the leaders - always, on every page...
  513. $sql = 'SELECT u.user_id, u.username, u.username_clean, u.user_regdate, u.user_posts, u.group_id, ug.group_leader, ug.user_pending
  514. FROM ' . USERS_TABLE . ' u, ' . USER_GROUP_TABLE . " ug
  515. WHERE ug.group_id = $group_id
  516. AND u.user_id = ug.user_id
  517. AND ug.group_leader = 1
  518. ORDER BY ug.group_leader DESC, ug.user_pending ASC, u.username_clean";
  519. $result = $db->sql_query($sql);
  520. while ($row = $db->sql_fetchrow($result))
  521. {
  522. $template->assign_block_vars('leader', array(
  523. 'U_USER_EDIT' => append_sid("{$phpbb_admin_path}index.$phpEx", "i=users&amp;action=edit&amp;u={$row['user_id']}"),
  524. 'USERNAME' => $row['username'],
  525. 'S_GROUP_DEFAULT' => ($row['group_id'] == $group_id) ? true : false,
  526. 'JOINED' => ($row['user_regdate']) ? $user->format_date($row['user_regdate']) : ' - ',
  527. 'USER_POSTS' => $row['user_posts'],
  528. 'USER_ID' => $row['user_id'])
  529. );
  530. }
  531. $db->sql_freeresult($result);
  532. // Total number of group members (non-leaders)
  533. $sql = 'SELECT COUNT(user_id) AS total_members
  534. FROM ' . USER_GROUP_TABLE . "
  535. WHERE group_id = $group_id
  536. AND group_leader = 0";
  537. $result = $db->sql_query($sql);
  538. $total_members = (int) $db->sql_fetchfield('total_members');
  539. $db->sql_freeresult($result);
  540. $s_action_options = '';
  541. $options = array('default' => 'DEFAULT', 'approve' => 'APPROVE', 'demote' => 'DEMOTE', 'promote' => 'PROMOTE', 'deleteusers' => 'DELETE');
  542. foreach ($options as $option => $lang)
  543. {
  544. $s_action_options .= '<option value="' . $option . '">' . $user->lang['GROUP_' . $lang] . '</option>';
  545. }
  546. $template->assign_vars(array(
  547. 'S_LIST' => true,
  548. 'S_GROUP_SPECIAL' => ($group_row['group_type'] == GROUP_SPECIAL) ? true : false,
  549. 'S_ACTION_OPTIONS' => $s_action_options,
  550. 'S_ON_PAGE' => on_page($total_members, $config['topics_per_page'], $start),
  551. 'PAGINATION' => generate_pagination($this->u_action . "&amp;action=$action&amp;g=$group_id", $total_members, $config['topics_per_page'], $start, true),
  552. 'GROUP_NAME' => ($group_row['group_type'] == GROUP_SPECIAL) ? $user->lang['G_' . $group_row['group_name']] : $group_row['group_name'],
  553. 'U_ACTION' => $this->u_action . "&amp;g=$group_id",
  554. 'U_BACK' => $this->u_action,
  555. 'U_FIND_USERNAME' => append_sid("{$phpbb_root_path}memberlist.$phpEx", 'mode=searchuser&amp;form=list&amp;field=usernames'),
  556. 'U_DEFAULT_ALL' => "{$this->u_action}&amp;action=default&amp;g=$group_id",
  557. ));
  558. // Grab the members
  559. $sql = 'SELECT u.user_id, u.username, u.username_clean, u.user_regdate, u.user_posts, u.group_id, ug.group_leader, ug.user_pending
  560. FROM ' . USERS_TABLE . ' u, ' . USER_GROUP_TABLE . " ug
  561. WHERE ug.group_id = $group_id
  562. AND u.user_id = ug.user_id
  563. AND ug.group_leader = 0
  564. ORDER BY ug.group_leader DESC, ug.user_pending ASC, u.username_clean";
  565. $result = $db->sql_query_limit($sql, $config['topics_per_page'], $start);
  566. $pending = false;
  567. while ($row = $db->sql_fetchrow($result))
  568. {
  569. if ($row['user_pending'] && !$pending)
  570. {
  571. $template->assign_block_vars('member', array(
  572. 'S_PENDING' => true)
  573. );
  574. $pending = true;
  575. }
  576. $template->assign_block_vars('member', array(
  577. 'U_USER_EDIT' => append_sid("{$phpbb_admin_path}index.$phpEx", "i=users&amp;action=edit&amp;u={$row['user_id']}"),
  578. 'USERNAME' => $row['username'],
  579. 'S_GROUP_DEFAULT' => ($row['group_id'] == $group_id) ? true : false,
  580. 'JOINED' => ($row['user_regdate']) ? $user->format_date($row['user_regdate']) : ' - ',
  581. 'USER_POSTS' => $row['user_posts'],
  582. 'USER_ID' => $row['user_id'])
  583. );
  584. }
  585. $db->sql_freeresult($result);
  586. return;
  587. break;
  588. }
  589. $template->assign_vars(array(
  590. 'U_ACTION' => $this->u_action,
  591. 'S_GROUP_ADD' => ($auth->acl_get('a_groupadd')) ? true : false)
  592. );
  593. // Get us all the groups
  594. $sql = 'SELECT g.group_id, g.group_name, g.group_type
  595. FROM ' . GROUPS_TABLE . ' g
  596. ORDER BY g.group_type ASC, g.group_name';
  597. $result = $db->sql_query($sql);
  598. $lookup = $cached_group_data = array();
  599. while ($row = $db->sql_fetchrow($result))
  600. {
  601. $type = ($row['group_type'] == GROUP_SPECIAL) ? 'special' : 'normal';
  602. // used to determine what type a group is
  603. $lookup[$row['group_id']] = $type;
  604. // used for easy access to the data within a group
  605. $cached_group_data[$type][$row['group_id']] = $row;
  606. $cached_group_data[$type][$row['group_id']]['total_members'] = 0;
  607. }
  608. $db->sql_freeresult($result);
  609. // How many people are in which group?
  610. $sql = 'SELECT COUNT(ug.user_id) AS total_members, ug.group_id
  611. FROM ' . USER_GROUP_TABLE . ' ug
  612. WHERE ' . $db->sql_in_set('ug.group_id', array_keys($lookup)) . '
  613. GROUP BY ug.group_id';
  614. $result = $db->sql_query($sql);
  615. while ($row = $db->sql_fetchrow($result))
  616. {
  617. $type = $lookup[$row['group_id']];
  618. $cached_group_data[$type][$row['group_id']]['total_members'] = $row['total_members'];
  619. }
  620. $db->sql_freeresult($result);
  621. // The order is... normal, then special
  622. ksort($cached_group_data);
  623. foreach ($cached_group_data as $type => $row_ary)
  624. {
  625. if ($type == 'special')
  626. {
  627. $template->assign_block_vars('groups', array(
  628. 'S_SPECIAL' => true)
  629. );
  630. }
  631. foreach ($row_ary as $group_id => $row)
  632. {
  633. $group_name = (!empty($user->lang['G_' . $row['group_name']]))? $user->lang['G_' . $row['group_name']] : $row['group_name'];
  634. $template->assign_block_vars('groups', array(
  635. 'U_LIST' => "{$this->u_action}&amp;action=list&amp;g=$group_id",
  636. 'U_EDIT' => "{$this->u_action}&amp;action=edit&amp;g=$group_id",
  637. 'U_DELETE' => ($auth->acl_get('a_groupdel')) ? "{$this->u_action}&amp;action=delete&amp;g=$group_id" : '',
  638. 'S_GROUP_SPECIAL' => ($row['group_type'] == GROUP_SPECIAL) ? true : false,
  639. 'GROUP_NAME' => $group_name,
  640. 'TOTAL_MEMBERS' => $row['total_members'],
  641. )
  642. );
  643. }
  644. }
  645. }
  646. }
  647. ?>