Chris@76: 2) Chris@76: foreach ($_GET as $k => $v) Chris@76: { Chris@76: if (!in_array($k, array('topic', 'board', 'start', session_name()))) Chris@76: $context['robot_no_index'] = true; Chris@76: } Chris@76: Chris@76: if (!empty($_REQUEST['start']) && (!is_numeric($_REQUEST['start']) || $_REQUEST['start'] % $context['messages_per_page'] != 0)) Chris@76: $context['robot_no_index'] = true; Chris@76: Chris@76: // Find the previous or next topic. Make a fuss if there are no more. Chris@76: if (isset($_REQUEST['prev_next']) && ($_REQUEST['prev_next'] == 'prev' || $_REQUEST['prev_next'] == 'next')) Chris@76: { Chris@76: // No use in calculating the next topic if there's only one. Chris@76: if ($board_info['num_topics'] > 1) Chris@76: { Chris@76: // Just prepare some variables that are used in the query. Chris@76: $gt_lt = $_REQUEST['prev_next'] == 'prev' ? '>' : '<'; Chris@76: $order = $_REQUEST['prev_next'] == 'prev' ? '' : ' DESC'; Chris@76: Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT t2.id_topic Chris@76: FROM {db_prefix}topics AS t Chris@76: INNER JOIN {db_prefix}topics AS t2 ON (' . (empty($modSettings['enableStickyTopics']) ? ' Chris@76: t2.id_last_msg ' . $gt_lt . ' t.id_last_msg' : ' Chris@76: (t2.id_last_msg ' . $gt_lt . ' t.id_last_msg AND t2.is_sticky ' . $gt_lt . '= t.is_sticky) OR t2.is_sticky ' . $gt_lt . ' t.is_sticky') . ') Chris@76: WHERE t.id_topic = {int:current_topic} Chris@76: AND t2.id_board = {int:current_board}' . (!$modSettings['postmod_active'] || allowedTo('approve_posts') ? '' : ' Chris@76: AND (t2.approved = {int:is_approved} OR (t2.id_member_started != {int:id_member_started} AND t2.id_member_started = {int:current_member}))') . ' Chris@76: ORDER BY' . (empty($modSettings['enableStickyTopics']) ? '' : ' t2.is_sticky' . $order . ',') . ' t2.id_last_msg' . $order . ' Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'current_board' => $board, Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: 'is_approved' => 1, Chris@76: 'id_member_started' => 0, Chris@76: ) Chris@76: ); Chris@76: Chris@76: // No more left. Chris@76: if ($smcFunc['db_num_rows']($request) == 0) Chris@76: { Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // Roll over - if we're going prev, get the last - otherwise the first. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT id_topic Chris@76: FROM {db_prefix}topics Chris@76: WHERE id_board = {int:current_board}' . (!$modSettings['postmod_active'] || allowedTo('approve_posts') ? '' : ' Chris@76: AND (approved = {int:is_approved} OR (id_member_started != {int:id_member_started} AND id_member_started = {int:current_member}))') . ' Chris@76: ORDER BY' . (empty($modSettings['enableStickyTopics']) ? '' : ' is_sticky' . $order . ',') . ' id_last_msg' . $order . ' Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'current_board' => $board, Chris@76: 'current_member' => $user_info['id'], Chris@76: 'is_approved' => 1, Chris@76: 'id_member_started' => 0, Chris@76: ) Chris@76: ); Chris@76: } Chris@76: Chris@76: // Now you can be sure $topic is the id_topic to view. Chris@76: list ($topic) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: $context['current_topic'] = $topic; Chris@76: } Chris@76: Chris@76: // Go to the newest message on this topic. Chris@76: $_REQUEST['start'] = 'new'; Chris@76: } Chris@76: Chris@76: // Add 1 to the number of views of this topic. Chris@76: if (empty($_SESSION['last_read_topic']) || $_SESSION['last_read_topic'] != $topic) Chris@76: { Chris@76: $smcFunc['db_query']('', ' Chris@76: UPDATE {db_prefix}topics Chris@76: SET num_views = num_views + 1 Chris@76: WHERE id_topic = {int:current_topic}', Chris@76: array( Chris@76: 'current_topic' => $topic, Chris@76: ) Chris@76: ); Chris@76: Chris@76: $_SESSION['last_read_topic'] = $topic; Chris@76: } Chris@76: Chris@76: // Get all the important topic info. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT Chris@76: t.num_replies, t.num_views, t.locked, ms.subject, t.is_sticky, t.id_poll, Chris@76: t.id_member_started, t.id_first_msg, t.id_last_msg, t.approved, t.unapproved_posts, Chris@76: ' . ($user_info['is_guest'] ? 't.id_last_msg + 1' : 'IFNULL(lt.id_msg, IFNULL(lmr.id_msg, -1)) + 1') . ' AS new_from Chris@76: ' . (!empty($modSettings['recycle_board']) && $modSettings['recycle_board'] == $board ? ', id_previous_board, id_previous_topic' : '') . ' Chris@76: FROM {db_prefix}topics AS t Chris@76: INNER JOIN {db_prefix}messages AS ms ON (ms.id_msg = t.id_first_msg)' . ($user_info['is_guest'] ? '' : ' Chris@76: LEFT JOIN {db_prefix}log_topics AS lt ON (lt.id_topic = {int:current_topic} AND lt.id_member = {int:current_member}) Chris@76: LEFT JOIN {db_prefix}log_mark_read AS lmr ON (lmr.id_board = {int:current_board} AND lmr.id_member = {int:current_member})') . ' Chris@76: WHERE t.id_topic = {int:current_topic} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: 'current_board' => $board, Chris@76: ) Chris@76: ); Chris@76: if ($smcFunc['db_num_rows']($request) == 0) Chris@76: fatal_lang_error('not_a_topic', false); Chris@76: $topicinfo = $smcFunc['db_fetch_assoc']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: $context['real_num_replies'] = $context['num_replies'] = $topicinfo['num_replies']; Chris@76: $context['topic_first_message'] = $topicinfo['id_first_msg']; Chris@76: $context['topic_last_message'] = $topicinfo['id_last_msg']; Chris@76: Chris@76: // Add up unapproved replies to get real number of replies... Chris@76: if ($modSettings['postmod_active'] && allowedTo('approve_posts')) Chris@76: $context['real_num_replies'] += $topicinfo['unapproved_posts'] - ($topicinfo['approved'] ? 0 : 1); Chris@76: Chris@76: // If this topic has unapproved posts, we need to work out how many posts the user can see, for page indexing. Chris@76: if ($modSettings['postmod_active'] && $topicinfo['unapproved_posts'] && !$user_info['is_guest'] && !allowedTo('approve_posts')) Chris@76: { Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT COUNT(id_member) AS my_unapproved_posts Chris@76: FROM {db_prefix}messages Chris@76: WHERE id_topic = {int:current_topic} Chris@76: AND id_member = {int:current_member} Chris@76: AND approved = 0', Chris@76: array( Chris@76: 'current_topic' => $topic, Chris@76: 'current_member' => $user_info['id'], Chris@76: ) Chris@76: ); Chris@76: list ($myUnapprovedPosts) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: $context['total_visible_posts'] = $context['num_replies'] + $myUnapprovedPosts + ($topicinfo['approved'] ? 1 : 0); Chris@76: } Chris@76: else Chris@76: $context['total_visible_posts'] = $context['num_replies'] + $topicinfo['unapproved_posts'] + ($topicinfo['approved'] ? 1 : 0); Chris@76: Chris@76: // When was the last time this topic was replied to? Should we warn them about it? Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT poster_time Chris@76: FROM {db_prefix}messages Chris@76: WHERE id_msg = {int:id_last_msg} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'id_last_msg' => $topicinfo['id_last_msg'], Chris@76: ) Chris@76: ); Chris@76: Chris@76: list ($lastPostTime) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: $context['oldTopicError'] = !empty($modSettings['oldTopicDays']) && $lastPostTime + $modSettings['oldTopicDays'] * 86400 < time() && empty($sticky); Chris@76: Chris@76: // The start isn't a number; it's information about what to do, where to go. Chris@76: if (!is_numeric($_REQUEST['start'])) Chris@76: { Chris@76: // Redirect to the page and post with new messages, originally by Omar Bazavilvazo. Chris@76: if ($_REQUEST['start'] == 'new') Chris@76: { Chris@76: // Guests automatically go to the last post. Chris@76: if ($user_info['is_guest']) Chris@76: { Chris@76: $context['start_from'] = $context['total_visible_posts'] - 1; Chris@76: $_REQUEST['start'] = empty($options['view_newest_first']) ? $context['start_from'] : 0; Chris@76: } Chris@76: else Chris@76: { Chris@76: // Find the earliest unread message in the topic. (the use of topics here is just for both tables.) Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT IFNULL(lt.id_msg, IFNULL(lmr.id_msg, -1)) + 1 AS new_from Chris@76: FROM {db_prefix}topics AS t Chris@76: LEFT JOIN {db_prefix}log_topics AS lt ON (lt.id_topic = {int:current_topic} AND lt.id_member = {int:current_member}) Chris@76: LEFT JOIN {db_prefix}log_mark_read AS lmr ON (lmr.id_board = {int:current_board} AND lmr.id_member = {int:current_member}) Chris@76: WHERE t.id_topic = {int:current_topic} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'current_board' => $board, Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: ) Chris@76: ); Chris@76: list ($new_from) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // Fall through to the next if statement. Chris@76: $_REQUEST['start'] = 'msg' . $new_from; Chris@76: } Chris@76: } Chris@76: Chris@76: // Start from a certain time index, not a message. Chris@76: if (substr($_REQUEST['start'], 0, 4) == 'from') Chris@76: { Chris@76: $timestamp = (int) substr($_REQUEST['start'], 4); Chris@76: if ($timestamp === 0) Chris@76: $_REQUEST['start'] = 0; Chris@76: else Chris@76: { Chris@76: // Find the number of messages posted before said time... Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT COUNT(*) Chris@76: FROM {db_prefix}messages Chris@76: WHERE poster_time < {int:timestamp} Chris@76: AND id_topic = {int:current_topic}' . ($modSettings['postmod_active'] && $topicinfo['unapproved_posts'] && !allowedTo('approve_posts') ? ' Chris@76: AND (approved = {int:is_approved}' . ($user_info['is_guest'] ? '' : ' OR id_member = {int:current_member}') . ')' : ''), Chris@76: array( Chris@76: 'current_topic' => $topic, Chris@76: 'current_member' => $user_info['id'], Chris@76: 'is_approved' => 1, Chris@76: 'timestamp' => $timestamp, Chris@76: ) Chris@76: ); Chris@76: list ($context['start_from']) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // Handle view_newest_first options, and get the correct start value. Chris@76: $_REQUEST['start'] = empty($options['view_newest_first']) ? $context['start_from'] : $context['total_visible_posts'] - $context['start_from'] - 1; Chris@76: } Chris@76: } Chris@76: Chris@76: // Link to a message... Chris@76: elseif (substr($_REQUEST['start'], 0, 3) == 'msg') Chris@76: { Chris@76: $virtual_msg = (int) substr($_REQUEST['start'], 3); Chris@76: if (!$topicinfo['unapproved_posts'] && $virtual_msg >= $topicinfo['id_last_msg']) Chris@76: $context['start_from'] = $context['total_visible_posts'] - 1; Chris@76: elseif (!$topicinfo['unapproved_posts'] && $virtual_msg <= $topicinfo['id_first_msg']) Chris@76: $context['start_from'] = 0; Chris@76: else Chris@76: { Chris@76: // Find the start value for that message...... Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT COUNT(*) Chris@76: FROM {db_prefix}messages Chris@76: WHERE id_msg < {int:virtual_msg} Chris@76: AND id_topic = {int:current_topic}' . ($modSettings['postmod_active'] && $topicinfo['unapproved_posts'] && !allowedTo('approve_posts') ? ' Chris@76: AND (approved = {int:is_approved}' . ($user_info['is_guest'] ? '' : ' OR id_member = {int:current_member}') . ')' : ''), Chris@76: array( Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: 'virtual_msg' => $virtual_msg, Chris@76: 'is_approved' => 1, Chris@76: 'no_member' => 0, Chris@76: ) Chris@76: ); Chris@76: list ($context['start_from']) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: } Chris@76: Chris@76: // We need to reverse the start as well in this case. Chris@76: $_REQUEST['start'] = empty($options['view_newest_first']) ? $context['start_from'] : $context['total_visible_posts'] - $context['start_from'] - 1; Chris@76: } Chris@76: } Chris@76: Chris@76: // Create a previous next string if the selected theme has it as a selected option. Chris@76: $context['previous_next'] = $modSettings['enablePreviousNext'] ? '' . $txt['previous_next_back'] . ' ' . $txt['previous_next_forward'] . '' : ''; Chris@76: Chris@76: // Check if spellchecking is both enabled and actually working. (for quick reply.) Chris@76: $context['show_spellchecking'] = !empty($modSettings['enableSpellChecking']) && function_exists('pspell_new'); Chris@76: Chris@76: // Do we need to show the visual verification image? Chris@76: $context['require_verification'] = !$user_info['is_mod'] && !$user_info['is_admin'] && !empty($modSettings['posts_require_captcha']) && ($user_info['posts'] < $modSettings['posts_require_captcha'] || ($user_info['is_guest'] && $modSettings['posts_require_captcha'] == -1)); Chris@76: if ($context['require_verification']) Chris@76: { Chris@76: require_once($sourcedir . '/Subs-Editor.php'); Chris@76: $verificationOptions = array( Chris@76: 'id' => 'post', Chris@76: ); Chris@76: $context['require_verification'] = create_control_verification($verificationOptions); Chris@76: $context['visual_verification_id'] = $verificationOptions['id']; Chris@76: } Chris@76: Chris@76: // Are we showing signatures - or disabled fields? Chris@76: $context['signature_enabled'] = substr($modSettings['signature_settings'], 0, 1) == 1; Chris@76: $context['disabled_fields'] = isset($modSettings['disabled_profile_fields']) ? array_flip(explode(',', $modSettings['disabled_profile_fields'])) : array(); Chris@76: Chris@76: // Censor the title... Chris@76: censorText($topicinfo['subject']); Chris@76: $context['page_title'] = $topicinfo['subject']; Chris@76: Chris@76: // Is this topic sticky, or can it even be? Chris@76: $topicinfo['is_sticky'] = empty($modSettings['enableStickyTopics']) ? '0' : $topicinfo['is_sticky']; Chris@76: Chris@76: // Default this topic to not marked for notifications... of course... Chris@76: $context['is_marked_notify'] = false; Chris@76: Chris@76: // Did we report a post to a moderator just now? Chris@76: $context['report_sent'] = isset($_GET['reportsent']); Chris@76: Chris@76: // Let's get nosey, who is viewing this topic? Chris@76: if (!empty($settings['display_who_viewing'])) Chris@76: { Chris@76: // Start out with no one at all viewing it. Chris@76: $context['view_members'] = array(); Chris@76: $context['view_members_list'] = array(); Chris@76: $context['view_num_hidden'] = 0; Chris@76: Chris@76: // Search for members who have this topic set in their GET data. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT Chris@76: lo.id_member, lo.log_time, mem.real_name, mem.member_name, mem.show_online, Chris@76: mg.online_color, mg.id_group, mg.group_name Chris@76: FROM {db_prefix}log_online AS lo Chris@76: LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = lo.id_member) Chris@76: LEFT JOIN {db_prefix}membergroups AS mg ON (mg.id_group = CASE WHEN mem.id_group = {int:reg_id_group} THEN mem.id_post_group ELSE mem.id_group END) Chris@76: WHERE INSTR(lo.url, {string:in_url_string}) > 0 OR lo.session = {string:session}', Chris@76: array( Chris@76: 'reg_id_group' => 0, Chris@76: 'in_url_string' => 's:5:"topic";i:' . $topic . ';', Chris@76: 'session' => $user_info['is_guest'] ? 'ip' . $user_info['ip'] : session_id(), Chris@76: ) Chris@76: ); Chris@76: while ($row = $smcFunc['db_fetch_assoc']($request)) Chris@76: { Chris@76: if (empty($row['id_member'])) Chris@76: continue; Chris@76: Chris@76: if (!empty($row['online_color'])) Chris@76: $link = '' . $row['real_name'] . ''; Chris@76: else Chris@76: $link = '' . $row['real_name'] . ''; Chris@76: Chris@76: $is_buddy = in_array($row['id_member'], $user_info['buddies']); Chris@76: if ($is_buddy) Chris@76: $link = '' . $link . ''; Chris@76: Chris@76: // Add them both to the list and to the more detailed list. Chris@76: if (!empty($row['show_online']) || allowedTo('moderate_forum')) Chris@76: $context['view_members_list'][$row['log_time'] . $row['member_name']] = empty($row['show_online']) ? '' . $link . '' : $link; Chris@76: $context['view_members'][$row['log_time'] . $row['member_name']] = array( Chris@76: 'id' => $row['id_member'], Chris@76: 'username' => $row['member_name'], Chris@76: 'name' => $row['real_name'], Chris@76: 'group' => $row['id_group'], Chris@76: 'href' => $scripturl . '?action=profile;u=' . $row['id_member'], Chris@76: 'link' => $link, Chris@76: 'is_buddy' => $is_buddy, Chris@76: 'hidden' => empty($row['show_online']), Chris@76: ); Chris@76: Chris@76: if (empty($row['show_online'])) Chris@76: $context['view_num_hidden']++; Chris@76: } Chris@76: Chris@76: // The number of guests is equal to the rows minus the ones we actually used ;). Chris@76: $context['view_num_guests'] = $smcFunc['db_num_rows']($request) - count($context['view_members']); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // Sort the list. Chris@76: krsort($context['view_members']); Chris@76: krsort($context['view_members_list']); Chris@76: } Chris@76: Chris@76: // If all is set, but not allowed... just unset it. Chris@76: $can_show_all = !empty($modSettings['enableAllMessages']) && $context['total_visible_posts'] > $context['messages_per_page'] && $context['total_visible_posts'] < $modSettings['enableAllMessages']; Chris@76: if (isset($_REQUEST['all']) && !$can_show_all) Chris@76: unset($_REQUEST['all']); Chris@76: // Otherwise, it must be allowed... so pretend start was -1. Chris@76: elseif (isset($_REQUEST['all'])) Chris@76: $_REQUEST['start'] = -1; Chris@76: Chris@76: // Construct the page index, allowing for the .START method... Chris@76: $context['page_index'] = constructPageIndex($scripturl . '?topic=' . $topic . '.%1$d', $_REQUEST['start'], $context['total_visible_posts'], $context['messages_per_page'], true); Chris@76: $context['start'] = $_REQUEST['start']; Chris@76: Chris@76: // This is information about which page is current, and which page we're on - in case you don't like the constructed page index. (again, wireles..) Chris@76: $context['page_info'] = array( Chris@76: 'current_page' => $_REQUEST['start'] / $context['messages_per_page'] + 1, Chris@76: 'num_pages' => floor(($context['total_visible_posts'] - 1) / $context['messages_per_page']) + 1, Chris@76: ); Chris@76: Chris@76: // Figure out all the link to the next/prev/first/last/etc. for wireless mainly. Chris@76: $context['links'] = array( Chris@76: 'first' => $_REQUEST['start'] >= $context['messages_per_page'] ? $scripturl . '?topic=' . $topic . '.0' : '', Chris@76: 'prev' => $_REQUEST['start'] >= $context['messages_per_page'] ? $scripturl . '?topic=' . $topic . '.' . ($_REQUEST['start'] - $context['messages_per_page']) : '', Chris@76: 'next' => $_REQUEST['start'] + $context['messages_per_page'] < $context['total_visible_posts'] ? $scripturl . '?topic=' . $topic. '.' . ($_REQUEST['start'] + $context['messages_per_page']) : '', Chris@76: 'last' => $_REQUEST['start'] + $context['messages_per_page'] < $context['total_visible_posts'] ? $scripturl . '?topic=' . $topic. '.' . (floor($context['total_visible_posts'] / $context['messages_per_page']) * $context['messages_per_page']) : '', Chris@76: 'up' => $scripturl . '?board=' . $board . '.0' Chris@76: ); Chris@76: Chris@76: // If they are viewing all the posts, show all the posts, otherwise limit the number. Chris@76: if ($can_show_all) Chris@76: { Chris@76: if (isset($_REQUEST['all'])) Chris@76: { Chris@76: // No limit! (actually, there is a limit, but...) Chris@76: $context['messages_per_page'] = -1; Chris@76: $context['page_index'] .= empty($modSettings['compactTopicPagesEnable']) ? '' . $txt['all'] . ' ' : '[' . $txt['all'] . '] '; Chris@76: Chris@76: // Set start back to 0... Chris@76: $_REQUEST['start'] = 0; Chris@76: } Chris@76: // They aren't using it, but the *option* is there, at least. Chris@76: else Chris@76: $context['page_index'] .= ' ' . $txt['all'] . ' '; Chris@76: } Chris@76: Chris@76: // Build the link tree. Chris@76: $context['linktree'][] = array( Chris@76: 'url' => $scripturl . '?topic=' . $topic . '.0', Chris@76: 'name' => $topicinfo['subject'], Chris@76: 'extra_before' => $settings['linktree_inline'] ? $txt['topic'] . ': ' : '' Chris@76: ); Chris@76: Chris@76: // Build a list of this board's moderators. Chris@76: $context['moderators'] = &$board_info['moderators']; Chris@76: $context['link_moderators'] = array(); Chris@76: if (!empty($board_info['moderators'])) Chris@76: { Chris@76: // Add a link for each moderator... Chris@76: foreach ($board_info['moderators'] as $mod) Chris@76: $context['link_moderators'][] = '' . $mod['name'] . ''; Chris@76: Chris@76: // And show it after the board's name. Chris@76: $context['linktree'][count($context['linktree']) - 2]['extra_after'] = ' (' . (count($context['link_moderators']) == 1 ? $txt['moderator'] : $txt['moderators']) . ': ' . implode(', ', $context['link_moderators']) . ')'; Chris@76: } Chris@76: Chris@76: // Information about the current topic... Chris@76: $context['is_locked'] = $topicinfo['locked']; Chris@76: $context['is_sticky'] = $topicinfo['is_sticky']; Chris@76: $context['is_very_hot'] = $topicinfo['num_replies'] >= $modSettings['hotTopicVeryPosts']; Chris@76: $context['is_hot'] = $topicinfo['num_replies'] >= $modSettings['hotTopicPosts']; Chris@76: $context['is_approved'] = $topicinfo['approved']; Chris@76: Chris@76: // We don't want to show the poll icon in the topic class here, so pretend it's not one. Chris@76: $context['is_poll'] = false; Chris@76: determineTopicClass($context); Chris@76: Chris@76: $context['is_poll'] = $topicinfo['id_poll'] > 0 && $modSettings['pollMode'] == '1' && allowedTo('poll_view'); Chris@76: Chris@76: // Did this user start the topic or not? Chris@76: $context['user']['started'] = $user_info['id'] == $topicinfo['id_member_started'] && !$user_info['is_guest']; Chris@76: $context['topic_starter_id'] = $topicinfo['id_member_started']; Chris@76: Chris@76: // Set the topic's information for the template. Chris@76: $context['subject'] = $topicinfo['subject']; Chris@76: $context['num_views'] = $topicinfo['num_views']; Chris@76: $context['mark_unread_time'] = $topicinfo['new_from']; Chris@76: Chris@76: // Set a canonical URL for this page. Chris@76: $context['canonical_url'] = $scripturl . '?topic=' . $topic . '.' . $context['start']; Chris@76: Chris@76: // For quick reply we need a response prefix in the default forum language. Chris@76: if (!isset($context['response_prefix']) && !($context['response_prefix'] = cache_get_data('response_prefix', 600))) Chris@76: { Chris@76: if ($language === $user_info['language']) Chris@76: $context['response_prefix'] = $txt['response_prefix']; Chris@76: else Chris@76: { Chris@76: loadLanguage('index', $language, false); Chris@76: $context['response_prefix'] = $txt['response_prefix']; Chris@76: loadLanguage('index'); Chris@76: } Chris@76: cache_put_data('response_prefix', $context['response_prefix'], 600); Chris@76: } Chris@76: Chris@76: // If we want to show event information in the topic, prepare the data. Chris@76: if (allowedTo('calendar_view') && !empty($modSettings['cal_showInTopic']) && !empty($modSettings['cal_enabled'])) Chris@76: { Chris@76: // First, try create a better time format, ignoring the "time" elements. Chris@76: if (preg_match('~%[AaBbCcDdeGghjmuYy](?:[^%]*%[AaBbCcDdeGghjmuYy])*~', $user_info['time_format'], $matches) == 0 || empty($matches[0])) Chris@76: $date_string = $user_info['time_format']; Chris@76: else Chris@76: $date_string = $matches[0]; Chris@76: Chris@76: // Any calendar information for this topic? Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT cal.id_event, cal.start_date, cal.end_date, cal.title, cal.id_member, mem.real_name Chris@76: FROM {db_prefix}calendar AS cal Chris@76: LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = cal.id_member) Chris@76: WHERE cal.id_topic = {int:current_topic} Chris@76: ORDER BY start_date', Chris@76: array( Chris@76: 'current_topic' => $topic, Chris@76: ) Chris@76: ); Chris@76: $context['linked_calendar_events'] = array(); Chris@76: while ($row = $smcFunc['db_fetch_assoc']($request)) Chris@76: { Chris@76: // Prepare the dates for being formatted. Chris@76: $start_date = sscanf($row['start_date'], '%04d-%02d-%02d'); Chris@76: $start_date = mktime(12, 0, 0, $start_date[1], $start_date[2], $start_date[0]); Chris@76: $end_date = sscanf($row['end_date'], '%04d-%02d-%02d'); Chris@76: $end_date = mktime(12, 0, 0, $end_date[1], $end_date[2], $end_date[0]); Chris@76: Chris@76: $context['linked_calendar_events'][] = array( Chris@76: 'id' => $row['id_event'], Chris@76: 'title' => $row['title'], Chris@76: 'can_edit' => allowedTo('calendar_edit_any') || ($row['id_member'] == $user_info['id'] && allowedTo('calendar_edit_own')), Chris@76: 'modify_href' => $scripturl . '?action=post;msg=' . $topicinfo['id_first_msg'] . ';topic=' . $topic . '.0;calendar;eventid=' . $row['id_event'] . ';' . $context['session_var'] . '=' . $context['session_id'], Chris@76: 'start_date' => timeformat($start_date, $date_string, 'none'), Chris@76: 'start_timestamp' => $start_date, Chris@76: 'end_date' => timeformat($end_date, $date_string, 'none'), Chris@76: 'end_timestamp' => $end_date, Chris@76: 'is_last' => false Chris@76: ); Chris@76: } Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: if (!empty($context['linked_calendar_events'])) Chris@76: $context['linked_calendar_events'][count($context['linked_calendar_events']) - 1]['is_last'] = true; Chris@76: } Chris@76: Chris@76: // Create the poll info if it exists. Chris@76: if ($context['is_poll']) Chris@76: { Chris@76: // Get the question and if it's locked. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT Chris@76: p.question, p.voting_locked, p.hide_results, p.expire_time, p.max_votes, p.change_vote, Chris@76: p.guest_vote, p.id_member, IFNULL(mem.real_name, p.poster_name) AS poster_name, p.num_guest_voters, p.reset_poll Chris@76: FROM {db_prefix}polls AS p Chris@76: LEFT JOIN {db_prefix}members AS mem ON (mem.id_member = p.id_member) Chris@76: WHERE p.id_poll = {int:id_poll} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'id_poll' => $topicinfo['id_poll'], Chris@76: ) Chris@76: ); Chris@76: $pollinfo = $smcFunc['db_fetch_assoc']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT COUNT(DISTINCT id_member) AS total Chris@76: FROM {db_prefix}log_polls Chris@76: WHERE id_poll = {int:id_poll} Chris@76: AND id_member != {int:not_guest}', Chris@76: array( Chris@76: 'id_poll' => $topicinfo['id_poll'], Chris@76: 'not_guest' => 0, Chris@76: ) Chris@76: ); Chris@76: list ($pollinfo['total']) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // Total voters needs to include guest voters Chris@76: $pollinfo['total'] += $pollinfo['num_guest_voters']; Chris@76: Chris@76: // Get all the options, and calculate the total votes. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT pc.id_choice, pc.label, pc.votes, IFNULL(lp.id_choice, -1) AS voted_this Chris@76: FROM {db_prefix}poll_choices AS pc Chris@76: LEFT JOIN {db_prefix}log_polls AS lp ON (lp.id_choice = pc.id_choice AND lp.id_poll = {int:id_poll} AND lp.id_member = {int:current_member} AND lp.id_member != {int:not_guest}) Chris@76: WHERE pc.id_poll = {int:id_poll}', Chris@76: array( Chris@76: 'current_member' => $user_info['id'], Chris@76: 'id_poll' => $topicinfo['id_poll'], Chris@76: 'not_guest' => 0, Chris@76: ) Chris@76: ); Chris@76: $pollOptions = array(); Chris@76: $realtotal = 0; Chris@76: $pollinfo['has_voted'] = false; Chris@76: while ($row = $smcFunc['db_fetch_assoc']($request)) Chris@76: { Chris@76: censorText($row['label']); Chris@76: $pollOptions[$row['id_choice']] = $row; Chris@76: $realtotal += $row['votes']; Chris@76: $pollinfo['has_voted'] |= $row['voted_this'] != -1; Chris@76: } Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // If this is a guest we need to do our best to work out if they have voted, and what they voted for. Chris@76: if ($user_info['is_guest'] && $pollinfo['guest_vote'] && allowedTo('poll_vote')) Chris@76: { Chris@76: if (!empty($_COOKIE['guest_poll_vote']) && preg_match('~^[0-9,;]+$~', $_COOKIE['guest_poll_vote']) && strpos($_COOKIE['guest_poll_vote'], ';' . $topicinfo['id_poll'] . ',') !== false) Chris@76: { Chris@76: // ;id,timestamp,[vote,vote...]; etc Chris@76: $guestinfo = explode(';', $_COOKIE['guest_poll_vote']); Chris@76: // Find the poll we're after. Chris@76: foreach ($guestinfo as $i => $guestvoted) Chris@76: { Chris@76: $guestvoted = explode(',', $guestvoted); Chris@76: if ($guestvoted[0] == $topicinfo['id_poll']) Chris@76: break; Chris@76: } Chris@76: // Has the poll been reset since guest voted? Chris@76: if ($pollinfo['reset_poll'] > $guestvoted[1]) Chris@76: { Chris@76: // Remove the poll info from the cookie to allow guest to vote again Chris@76: unset($guestinfo[$i]); Chris@76: if (!empty($guestinfo)) Chris@76: $_COOKIE['guest_poll_vote'] = ';' . implode(';', $guestinfo); Chris@76: else Chris@76: unset($_COOKIE['guest_poll_vote']); Chris@76: } Chris@76: else Chris@76: { Chris@76: // What did they vote for? Chris@76: unset($guestvoted[0], $guestvoted[1]); Chris@76: foreach ($pollOptions as $choice => $details) Chris@76: { Chris@76: $pollOptions[$choice]['voted_this'] = in_array($choice, $guestvoted) ? 1 : -1; Chris@76: $pollinfo['has_voted'] |= $pollOptions[$choice]['voted_this'] != -1; Chris@76: } Chris@76: unset($choice, $details, $guestvoted); Chris@76: } Chris@76: unset($guestinfo, $guestvoted, $i); Chris@76: } Chris@76: } Chris@76: Chris@76: // Set up the basic poll information. Chris@76: $context['poll'] = array( Chris@76: 'id' => $topicinfo['id_poll'], Chris@76: 'image' => 'normal_' . (empty($pollinfo['voting_locked']) ? 'poll' : 'locked_poll'), Chris@76: 'question' => parse_bbc($pollinfo['question']), Chris@76: 'total_votes' => $pollinfo['total'], Chris@76: 'change_vote' => !empty($pollinfo['change_vote']), Chris@76: 'is_locked' => !empty($pollinfo['voting_locked']), Chris@76: 'options' => array(), Chris@76: 'lock' => allowedTo('poll_lock_any') || ($context['user']['started'] && allowedTo('poll_lock_own')), Chris@76: 'edit' => allowedTo('poll_edit_any') || ($context['user']['started'] && allowedTo('poll_edit_own')), Chris@76: 'allowed_warning' => $pollinfo['max_votes'] > 1 ? sprintf($txt['poll_options6'], min(count($pollOptions), $pollinfo['max_votes'])) : '', Chris@76: 'is_expired' => !empty($pollinfo['expire_time']) && $pollinfo['expire_time'] < time(), Chris@76: 'expire_time' => !empty($pollinfo['expire_time']) ? timeformat($pollinfo['expire_time']) : 0, Chris@76: 'has_voted' => !empty($pollinfo['has_voted']), Chris@76: 'starter' => array( Chris@76: 'id' => $pollinfo['id_member'], Chris@76: 'name' => $row['poster_name'], Chris@76: 'href' => $pollinfo['id_member'] == 0 ? '' : $scripturl . '?action=profile;u=' . $pollinfo['id_member'], Chris@76: 'link' => $pollinfo['id_member'] == 0 ? $row['poster_name'] : '' . $row['poster_name'] . '' Chris@76: ) Chris@76: ); Chris@76: Chris@76: // Make the lock and edit permissions defined above more directly accessible. Chris@76: $context['allow_lock_poll'] = $context['poll']['lock']; Chris@76: $context['allow_edit_poll'] = $context['poll']['edit']; Chris@76: Chris@76: // You're allowed to vote if: Chris@76: // 1. the poll did not expire, and Chris@76: // 2. you're either not a guest OR guest voting is enabled... and Chris@76: // 3. you're not trying to view the results, and Chris@76: // 4. the poll is not locked, and Chris@76: // 5. you have the proper permissions, and Chris@76: // 6. you haven't already voted before. Chris@76: $context['allow_vote'] = !$context['poll']['is_expired'] && (!$user_info['is_guest'] || ($pollinfo['guest_vote'] && allowedTo('poll_vote'))) && empty($pollinfo['voting_locked']) && allowedTo('poll_vote') && !$context['poll']['has_voted']; Chris@76: Chris@76: // You're allowed to view the results if: Chris@76: // 1. you're just a super-nice-guy, or Chris@76: // 2. anyone can see them (hide_results == 0), or Chris@76: // 3. you can see them after you voted (hide_results == 1), or Chris@76: // 4. you've waited long enough for the poll to expire. (whether hide_results is 1 or 2.) Chris@76: $context['allow_poll_view'] = allowedTo('moderate_board') || $pollinfo['hide_results'] == 0 || ($pollinfo['hide_results'] == 1 && $context['poll']['has_voted']) || $context['poll']['is_expired']; Chris@76: $context['poll']['show_results'] = $context['allow_poll_view'] && (isset($_REQUEST['viewresults']) || isset($_REQUEST['viewResults'])); Chris@76: $context['show_view_results_button'] = $context['allow_vote'] && (!$context['allow_poll_view'] || !$context['poll']['show_results'] || !$context['poll']['has_voted']); Chris@76: Chris@76: // You're allowed to change your vote if: Chris@76: // 1. the poll did not expire, and Chris@76: // 2. you're not a guest... and Chris@76: // 3. the poll is not locked, and Chris@76: // 4. you have the proper permissions, and Chris@76: // 5. you have already voted, and Chris@76: // 6. the poll creator has said you can! Chris@76: $context['allow_change_vote'] = !$context['poll']['is_expired'] && !$user_info['is_guest'] && empty($pollinfo['voting_locked']) && allowedTo('poll_vote') && $context['poll']['has_voted'] && $context['poll']['change_vote']; Chris@76: Chris@76: // You're allowed to return to voting options if: Chris@76: // 1. you are (still) allowed to vote. Chris@76: // 2. you are currently seeing the results. Chris@76: $context['allow_return_vote'] = $context['allow_vote'] && $context['poll']['show_results']; Chris@76: Chris@76: // Calculate the percentages and bar lengths... Chris@76: $divisor = $realtotal == 0 ? 1 : $realtotal; Chris@76: Chris@76: // Determine if a decimal point is needed in order for the options to add to 100%. Chris@76: $precision = $realtotal == 100 ? 0 : 1; Chris@76: Chris@76: // Now look through each option, and... Chris@76: foreach ($pollOptions as $i => $option) Chris@76: { Chris@76: // First calculate the percentage, and then the width of the bar... Chris@76: $bar = round(($option['votes'] * 100) / $divisor, $precision); Chris@76: $barWide = $bar == 0 ? 1 : floor(($bar * 8) / 3); Chris@76: Chris@76: // Now add it to the poll's contextual theme data. Chris@76: $context['poll']['options'][$i] = array( Chris@76: 'id' => 'options-' . $i, Chris@76: 'percent' => $bar, Chris@76: 'votes' => $option['votes'], Chris@76: 'voted_this' => $option['voted_this'] != -1, Chris@76: 'bar' => '-', Chris@76: // Note: IE < 8 requires us to set a width on the container, too. Chris@76: 'bar_ndt' => $bar > 0 ? '
' : '', Chris@76: 'bar_width' => $barWide, Chris@76: 'option' => parse_bbc($option['label']), Chris@76: 'vote_button' => '' Chris@76: ); Chris@76: } Chris@76: } Chris@76: Chris@76: // Calculate the fastest way to get the messages! Chris@76: $ascending = empty($options['view_newest_first']); Chris@76: $start = $_REQUEST['start']; Chris@76: $limit = $context['messages_per_page']; Chris@76: $firstIndex = 0; Chris@76: if ($start >= $context['total_visible_posts'] / 2 && $context['messages_per_page'] != -1) Chris@76: { Chris@76: $ascending = !$ascending; Chris@76: $limit = $context['total_visible_posts'] <= $start + $limit ? $context['total_visible_posts'] - $start : $limit; Chris@76: $start = $context['total_visible_posts'] <= $start + $limit ? 0 : $context['total_visible_posts'] - $start - $limit; Chris@76: $firstIndex = $limit - 1; Chris@76: } Chris@76: Chris@76: // Get each post and poster in this topic. Chris@76: $request = $smcFunc['db_query']('display_get_post_poster', ' Chris@76: SELECT id_msg, id_member, approved Chris@76: FROM {db_prefix}messages Chris@76: WHERE id_topic = {int:current_topic}' . (!$modSettings['postmod_active'] || allowedTo('approve_posts') ? '' : (!empty($modSettings['db_mysql_group_by_fix']) ? '' : ' Chris@76: GROUP BY id_msg') . ' Chris@76: HAVING (approved = {int:is_approved}' . ($user_info['is_guest'] ? '' : ' OR id_member = {int:current_member}') . ')') . ' Chris@76: ORDER BY id_msg ' . ($ascending ? '' : 'DESC') . ($context['messages_per_page'] == -1 ? '' : ' Chris@76: LIMIT ' . $start . ', ' . $limit), Chris@76: array( Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: 'is_approved' => 1, Chris@76: 'blank_id_member' => 0, Chris@76: ) Chris@76: ); Chris@76: Chris@76: $messages = array(); Chris@76: $all_posters = array(); Chris@76: while ($row = $smcFunc['db_fetch_assoc']($request)) Chris@76: { Chris@76: if (!empty($row['id_member'])) Chris@76: $all_posters[$row['id_msg']] = $row['id_member']; Chris@76: $messages[] = $row['id_msg']; Chris@76: } Chris@76: $smcFunc['db_free_result']($request); Chris@76: $posters = array_unique($all_posters); Chris@76: Chris@76: // Guests can't mark topics read or for notifications, just can't sorry. Chris@76: if (!$user_info['is_guest']) Chris@76: { Chris@76: $mark_at_msg = max($messages); Chris@76: if ($mark_at_msg >= $topicinfo['id_last_msg']) Chris@76: $mark_at_msg = $modSettings['maxMsgID']; Chris@76: if ($mark_at_msg >= $topicinfo['new_from']) Chris@76: { Chris@76: $smcFunc['db_insert']($topicinfo['new_from'] == 0 ? 'ignore' : 'replace', Chris@76: '{db_prefix}log_topics', Chris@76: array( Chris@76: 'id_member' => 'int', 'id_topic' => 'int', 'id_msg' => 'int', Chris@76: ), Chris@76: array( Chris@76: $user_info['id'], $topic, $mark_at_msg, Chris@76: ), Chris@76: array('id_member', 'id_topic') Chris@76: ); Chris@76: } Chris@76: Chris@76: // Check for notifications on this topic OR board. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT sent, id_topic Chris@76: FROM {db_prefix}log_notify Chris@76: WHERE (id_topic = {int:current_topic} OR id_board = {int:current_board}) Chris@76: AND id_member = {int:current_member} Chris@76: LIMIT 2', Chris@76: array( Chris@76: 'current_board' => $board, Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: ) Chris@76: ); Chris@76: $do_once = true; Chris@76: while ($row = $smcFunc['db_fetch_assoc']($request)) Chris@76: { Chris@76: // Find if this topic is marked for notification... Chris@76: if (!empty($row['id_topic'])) Chris@76: $context['is_marked_notify'] = true; Chris@76: Chris@76: // Only do this once, but mark the notifications as "not sent yet" for next time. Chris@76: if (!empty($row['sent']) && $do_once) Chris@76: { Chris@76: $smcFunc['db_query']('', ' Chris@76: UPDATE {db_prefix}log_notify Chris@76: SET sent = {int:is_not_sent} Chris@76: WHERE (id_topic = {int:current_topic} OR id_board = {int:current_board}) Chris@76: AND id_member = {int:current_member}', Chris@76: array( Chris@76: 'current_board' => $board, Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: 'is_not_sent' => 0, Chris@76: ) Chris@76: ); Chris@76: $do_once = false; Chris@76: } Chris@76: } Chris@76: Chris@76: // Have we recently cached the number of new topics in this board, and it's still a lot? Chris@76: if (isset($_REQUEST['topicseen']) && isset($_SESSION['topicseen_cache'][$board]) && $_SESSION['topicseen_cache'][$board] > 5) Chris@76: $_SESSION['topicseen_cache'][$board]--; Chris@76: // Mark board as seen if this is the only new topic. Chris@76: elseif (isset($_REQUEST['topicseen'])) Chris@76: { Chris@76: // Use the mark read tables... and the last visit to figure out if this should be read or not. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT COUNT(*) Chris@76: FROM {db_prefix}topics AS t Chris@76: LEFT JOIN {db_prefix}log_boards AS lb ON (lb.id_board = {int:current_board} AND lb.id_member = {int:current_member}) Chris@76: LEFT JOIN {db_prefix}log_topics AS lt ON (lt.id_topic = t.id_topic AND lt.id_member = {int:current_member}) Chris@76: WHERE t.id_board = {int:current_board} Chris@76: AND t.id_last_msg > IFNULL(lb.id_msg, 0) Chris@76: AND t.id_last_msg > IFNULL(lt.id_msg, 0)' . (empty($_SESSION['id_msg_last_visit']) ? '' : ' Chris@76: AND t.id_last_msg > {int:id_msg_last_visit}'), Chris@76: array( Chris@76: 'current_board' => $board, Chris@76: 'current_member' => $user_info['id'], Chris@76: 'id_msg_last_visit' => (int) $_SESSION['id_msg_last_visit'], Chris@76: ) Chris@76: ); Chris@76: list ($numNewTopics) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // If there're no real new topics in this board, mark the board as seen. Chris@76: if (empty($numNewTopics)) Chris@76: $_REQUEST['boardseen'] = true; Chris@76: else Chris@76: $_SESSION['topicseen_cache'][$board] = $numNewTopics; Chris@76: } Chris@76: // Probably one less topic - maybe not, but even if we decrease this too fast it will only make us look more often. Chris@76: elseif (isset($_SESSION['topicseen_cache'][$board])) Chris@76: $_SESSION['topicseen_cache'][$board]--; Chris@76: Chris@76: // Mark board as seen if we came using last post link from BoardIndex. (or other places...) Chris@76: if (isset($_REQUEST['boardseen'])) Chris@76: { Chris@76: $smcFunc['db_insert']('replace', Chris@76: '{db_prefix}log_boards', Chris@76: array('id_msg' => 'int', 'id_member' => 'int', 'id_board' => 'int'), Chris@76: array($modSettings['maxMsgID'], $user_info['id'], $board), Chris@76: array('id_member', 'id_board') Chris@76: ); Chris@76: } Chris@76: } Chris@76: Chris@76: $attachments = array(); Chris@76: Chris@76: // If there _are_ messages here... (probably an error otherwise :!) Chris@76: if (!empty($messages)) Chris@76: { Chris@76: // Fetch attachments. Chris@76: if (!empty($modSettings['attachmentEnable']) && allowedTo('view_attachments')) Chris@76: { Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT Chris@76: a.id_attach, a.id_folder, a.id_msg, a.filename, a.file_hash, IFNULL(a.size, 0) AS filesize, a.downloads, a.approved, Chris@76: a.width, a.height' . (empty($modSettings['attachmentShowImages']) || empty($modSettings['attachmentThumbnails']) ? '' : ', Chris@76: IFNULL(thumb.id_attach, 0) AS id_thumb, thumb.width AS thumb_width, thumb.height AS thumb_height') . ' Chris@76: FROM {db_prefix}attachments AS a' . (empty($modSettings['attachmentShowImages']) || empty($modSettings['attachmentThumbnails']) ? '' : ' Chris@76: LEFT JOIN {db_prefix}attachments AS thumb ON (thumb.id_attach = a.id_thumb)') . ' Chris@76: WHERE a.id_msg IN ({array_int:message_list}) Chris@76: AND a.attachment_type = {int:attachment_type}', Chris@76: array( Chris@76: 'message_list' => $messages, Chris@76: 'attachment_type' => 0, Chris@76: 'is_approved' => 1, Chris@76: ) Chris@76: ); Chris@76: $temp = array(); Chris@76: while ($row = $smcFunc['db_fetch_assoc']($request)) Chris@76: { Chris@76: if (!$row['approved'] && $modSettings['postmod_active'] && !allowedTo('approve_posts') && (!isset($all_posters[$row['id_msg']]) || $all_posters[$row['id_msg']] != $user_info['id'])) Chris@76: continue; Chris@76: Chris@76: $temp[$row['id_attach']] = $row; Chris@76: Chris@76: if (!isset($attachments[$row['id_msg']])) Chris@76: $attachments[$row['id_msg']] = array(); Chris@76: } Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // This is better than sorting it with the query... Chris@76: ksort($temp); Chris@76: Chris@76: foreach ($temp as $row) Chris@76: $attachments[$row['id_msg']][] = $row; Chris@76: } Chris@76: Chris@76: // What? It's not like it *couldn't* be only guests in this topic... Chris@76: if (!empty($posters)) Chris@76: loadMemberData($posters); Chris@76: $messages_request = $smcFunc['db_query']('', ' Chris@76: SELECT Chris@76: id_msg, icon, subject, poster_time, poster_ip, id_member, modified_time, modified_name, body, Chris@76: smileys_enabled, poster_name, poster_email, approved, Chris@76: id_msg_modified < {int:new_from} AS is_read Chris@76: FROM {db_prefix}messages Chris@76: WHERE id_msg IN ({array_int:message_list}) Chris@76: ORDER BY id_msg' . (empty($options['view_newest_first']) ? '' : ' DESC'), Chris@76: array( Chris@76: 'message_list' => $messages, Chris@76: 'new_from' => $topicinfo['new_from'], Chris@76: ) Chris@76: ); Chris@76: Chris@76: // Go to the last message if the given time is beyond the time of the last message. Chris@76: if (isset($context['start_from']) && $context['start_from'] >= $topicinfo['num_replies']) Chris@76: $context['start_from'] = $topicinfo['num_replies']; Chris@76: Chris@76: // Since the anchor information is needed on the top of the page we load these variables beforehand. Chris@76: $context['first_message'] = isset($messages[$firstIndex]) ? $messages[$firstIndex] : $messages[0]; Chris@76: if (empty($options['view_newest_first'])) Chris@76: $context['first_new_message'] = isset($context['start_from']) && $_REQUEST['start'] == $context['start_from']; Chris@76: else Chris@76: $context['first_new_message'] = isset($context['start_from']) && $_REQUEST['start'] == $topicinfo['num_replies'] - $context['start_from']; Chris@76: } Chris@76: else Chris@76: { Chris@76: $messages_request = false; Chris@76: $context['first_message'] = 0; Chris@76: $context['first_new_message'] = false; Chris@76: } Chris@76: Chris@76: $context['jump_to'] = array( Chris@76: 'label' => addslashes(un_htmlspecialchars($txt['jump_to'])), Chris@76: 'board_name' => htmlspecialchars(strtr(strip_tags($board_info['name']), array('&' => '&'))), Chris@76: 'child_level' => $board_info['child_level'], Chris@76: ); Chris@76: Chris@76: // Set the callback. (do you REALIZE how much memory all the messages would take?!?) Chris@76: $context['get_message'] = 'prepareDisplayContext'; Chris@76: Chris@76: // Now set all the wonderful, wonderful permissions... like moderation ones... Chris@76: $common_permissions = array( Chris@76: 'can_approve' => 'approve_posts', Chris@76: 'can_ban' => 'manage_bans', Chris@76: 'can_sticky' => 'make_sticky', Chris@76: 'can_merge' => 'merge_any', Chris@76: 'can_split' => 'split_any', Chris@76: 'calendar_post' => 'calendar_post', Chris@76: 'can_mark_notify' => 'mark_any_notify', Chris@76: 'can_send_topic' => 'send_topic', Chris@76: 'can_send_pm' => 'pm_send', Chris@76: 'can_report_moderator' => 'report_any', Chris@76: 'can_moderate_forum' => 'moderate_forum', Chris@76: 'can_issue_warning' => 'issue_warning', Chris@76: 'can_restore_topic' => 'move_any', Chris@76: 'can_restore_msg' => 'move_any', Chris@76: ); Chris@76: foreach ($common_permissions as $contextual => $perm) Chris@76: $context[$contextual] = allowedTo($perm); Chris@76: Chris@76: // Permissions with _any/_own versions. $context[YYY] => ZZZ_any/_own. Chris@76: $anyown_permissions = array( Chris@76: 'can_move' => 'move', Chris@76: 'can_lock' => 'lock', Chris@76: 'can_delete' => 'remove', Chris@76: 'can_add_poll' => 'poll_add', Chris@76: 'can_remove_poll' => 'poll_remove', Chris@76: 'can_reply' => 'post_reply', Chris@76: 'can_reply_unapproved' => 'post_unapproved_replies', Chris@76: ); Chris@76: foreach ($anyown_permissions as $contextual => $perm) Chris@76: $context[$contextual] = allowedTo($perm . '_any') || ($context['user']['started'] && allowedTo($perm . '_own')); Chris@76: Chris@76: // Cleanup all the permissions with extra stuff... Chris@76: $context['can_mark_notify'] &= !$context['user']['is_guest']; Chris@76: $context['can_sticky'] &= !empty($modSettings['enableStickyTopics']); Chris@76: $context['calendar_post'] &= !empty($modSettings['cal_enabled']); Chris@76: $context['can_add_poll'] &= $modSettings['pollMode'] == '1' && $topicinfo['id_poll'] <= 0; Chris@76: $context['can_remove_poll'] &= $modSettings['pollMode'] == '1' && $topicinfo['id_poll'] > 0; Chris@76: $context['can_reply'] &= empty($topicinfo['locked']) || allowedTo('moderate_board'); Chris@76: $context['can_reply_unapproved'] &= $modSettings['postmod_active'] && (empty($topicinfo['locked']) || allowedTo('moderate_board')); Chris@76: $context['can_issue_warning'] &= in_array('w', $context['admin_features']) && $modSettings['warning_settings'][0] == 1; Chris@76: // Handle approval flags... Chris@76: $context['can_reply_approved'] = $context['can_reply']; Chris@76: $context['can_reply'] |= $context['can_reply_unapproved']; Chris@76: $context['can_quote'] = $context['can_reply'] && (empty($modSettings['disabledBBC']) || !in_array('quote', explode(',', $modSettings['disabledBBC']))); Chris@76: $context['can_mark_unread'] = !$user_info['is_guest'] && $settings['show_mark_read']; Chris@76: Chris@76: $context['can_send_topic'] = (!$modSettings['postmod_active'] || $topicinfo['approved']) && allowedTo('send_topic'); Chris@76: Chris@76: // Start this off for quick moderation - it will be or'd for each post. Chris@76: $context['can_remove_post'] = allowedTo('delete_any') || (allowedTo('delete_replies') && $context['user']['started']); Chris@76: Chris@76: // Can restore topic? That's if the topic is in the recycle board and has a previous restore state. Chris@76: $context['can_restore_topic'] &= !empty($modSettings['recycle_enable']) && $modSettings['recycle_board'] == $board && !empty($topicinfo['id_previous_board']); Chris@76: $context['can_restore_msg'] &= !empty($modSettings['recycle_enable']) && $modSettings['recycle_board'] == $board && !empty($topicinfo['id_previous_topic']); Chris@76: Chris@76: // Wireless shows a "more" if you can do anything special. Chris@76: if (WIRELESS && WIRELESS_PROTOCOL != 'wap') Chris@76: { Chris@76: $context['wireless_more'] = $context['can_sticky'] || $context['can_lock'] || allowedTo('modify_any'); Chris@76: $context['wireless_moderate'] = isset($_GET['moderate']) ? ';moderate' : ''; Chris@76: } Chris@76: Chris@76: // Load up the "double post" sequencing magic. Chris@76: if (!empty($options['display_quick_reply'])) Chris@76: { Chris@76: checkSubmitOnce('register'); Chris@76: $context['name'] = isset($_SESSION['guest_name']) ? $_SESSION['guest_name'] : ''; Chris@76: $context['email'] = isset($_SESSION['guest_email']) ? $_SESSION['guest_email'] : ''; Chris@76: } Chris@76: } Chris@76: Chris@76: // Callback for the message display. Chris@76: function prepareDisplayContext($reset = false) Chris@76: { Chris@76: global $settings, $txt, $modSettings, $scripturl, $options, $user_info, $smcFunc; Chris@76: global $memberContext, $context, $messages_request, $topic, $attachments, $topicinfo; Chris@76: Chris@76: static $counter = null; Chris@76: Chris@76: // If the query returned false, bail. Chris@76: if ($messages_request == false) Chris@76: return false; Chris@76: Chris@76: // Remember which message this is. (ie. reply #83) Chris@76: if ($counter === null || $reset) Chris@76: $counter = empty($options['view_newest_first']) ? $context['start'] : $context['total_visible_posts'] - $context['start']; Chris@76: Chris@76: // Start from the beginning... Chris@76: if ($reset) Chris@76: return @$smcFunc['db_data_seek']($messages_request, 0); Chris@76: Chris@76: // Attempt to get the next message. Chris@76: $message = $smcFunc['db_fetch_assoc']($messages_request); Chris@76: if (!$message) Chris@76: { Chris@76: $smcFunc['db_free_result']($messages_request); Chris@76: return false; Chris@76: } Chris@76: Chris@76: // $context['icon_sources'] says where each icon should come from - here we set up the ones which will always exist! Chris@76: if (empty($context['icon_sources'])) Chris@76: { Chris@76: $stable_icons = array('xx', 'thumbup', 'thumbdown', 'exclamation', 'question', 'lamp', 'smiley', 'angry', 'cheesy', 'grin', 'sad', 'wink', 'moved', 'recycled', 'wireless', 'clip'); Chris@76: $context['icon_sources'] = array(); Chris@76: foreach ($stable_icons as $icon) Chris@76: $context['icon_sources'][$icon] = 'images_url'; Chris@76: } Chris@76: Chris@76: // Message Icon Management... check the images exist. Chris@76: if (empty($modSettings['messageIconChecks_disable'])) Chris@76: { Chris@76: // If the current icon isn't known, then we need to do something... Chris@76: if (!isset($context['icon_sources'][$message['icon']])) Chris@76: $context['icon_sources'][$message['icon']] = file_exists($settings['theme_dir'] . '/images/post/' . $message['icon'] . '.gif') ? 'images_url' : 'default_images_url'; Chris@76: } Chris@76: elseif (!isset($context['icon_sources'][$message['icon']])) Chris@76: $context['icon_sources'][$message['icon']] = 'images_url'; Chris@76: Chris@76: // If you're a lazy bum, you probably didn't give a subject... Chris@76: $message['subject'] = $message['subject'] != '' ? $message['subject'] : $txt['no_subject']; Chris@76: Chris@76: // Are you allowed to remove at least a single reply? Chris@76: $context['can_remove_post'] |= allowedTo('delete_own') && (empty($modSettings['edit_disable_time']) || $message['poster_time'] + $modSettings['edit_disable_time'] * 60 >= time()) && $message['id_member'] == $user_info['id']; Chris@76: Chris@76: // If it couldn't load, or the user was a guest.... someday may be done with a guest table. Chris@76: if (!loadMemberContext($message['id_member'], true)) Chris@76: { Chris@76: // Notice this information isn't used anywhere else.... Chris@76: $memberContext[$message['id_member']]['name'] = $message['poster_name']; Chris@76: $memberContext[$message['id_member']]['id'] = 0; Chris@76: $memberContext[$message['id_member']]['group'] = $txt['guest_title']; Chris@76: $memberContext[$message['id_member']]['link'] = $message['poster_name']; Chris@76: $memberContext[$message['id_member']]['email'] = $message['poster_email']; Chris@76: $memberContext[$message['id_member']]['show_email'] = showEmailAddress(true, 0); Chris@76: $memberContext[$message['id_member']]['is_guest'] = true; Chris@76: } Chris@76: else Chris@76: { Chris@76: $memberContext[$message['id_member']]['can_view_profile'] = allowedTo('profile_view_any') || ($message['id_member'] == $user_info['id'] && allowedTo('profile_view_own')); Chris@76: $memberContext[$message['id_member']]['is_topic_starter'] = $message['id_member'] == $context['topic_starter_id']; Chris@76: $memberContext[$message['id_member']]['can_see_warning'] = !isset($context['disabled_fields']['warning_status']) && $memberContext[$message['id_member']]['warning_status'] && ($context['user']['can_mod'] || (!$user_info['is_guest'] && !empty($modSettings['warning_show']) && ($modSettings['warning_show'] > 1 || $message['id_member'] == $user_info['id']))); Chris@76: } Chris@76: Chris@76: $memberContext[$message['id_member']]['ip'] = $message['poster_ip']; Chris@76: Chris@76: // Do the censor thang. Chris@76: censorText($message['body']); Chris@76: censorText($message['subject']); Chris@76: Chris@76: // Run BBC interpreter on the message. Chris@76: $message['body'] = parse_bbc($message['body'], $message['smileys_enabled'], $message['id_msg']); Chris@76: Chris@76: // Compose the memory eat- I mean message array. Chris@76: $output = array( Chris@76: 'attachment' => loadAttachmentContext($message['id_msg']), Chris@76: 'alternate' => $counter % 2, Chris@76: 'id' => $message['id_msg'], Chris@76: 'href' => $scripturl . '?topic=' . $topic . '.msg' . $message['id_msg'] . '#msg' . $message['id_msg'], Chris@76: 'link' => '' . $message['subject'] . '', Chris@76: 'member' => &$memberContext[$message['id_member']], Chris@76: 'icon' => $message['icon'], Chris@76: 'icon_url' => $settings[$context['icon_sources'][$message['icon']]] . '/post/' . $message['icon'] . '.gif', Chris@76: 'subject' => $message['subject'], Chris@76: 'time' => timeformat($message['poster_time']), Chris@76: 'timestamp' => forum_time(true, $message['poster_time']), Chris@76: 'counter' => $counter, Chris@76: 'modified' => array( Chris@76: 'time' => timeformat($message['modified_time']), Chris@76: 'timestamp' => forum_time(true, $message['modified_time']), Chris@76: 'name' => $message['modified_name'] Chris@76: ), Chris@76: 'body' => $message['body'], Chris@76: 'new' => empty($message['is_read']), Chris@76: 'approved' => $message['approved'], Chris@76: 'first_new' => isset($context['start_from']) && $context['start_from'] == $counter, Chris@76: 'is_ignored' => !empty($modSettings['enable_buddylist']) && !empty($options['posts_apply_ignore_list']) && in_array($message['id_member'], $context['user']['ignoreusers']), Chris@76: 'can_approve' => !$message['approved'] && $context['can_approve'], Chris@76: 'can_unapprove' => $message['approved'] && $context['can_approve'], Chris@76: 'can_modify' => (!$context['is_locked'] || allowedTo('moderate_board')) && (allowedTo('modify_any') || (allowedTo('modify_replies') && $context['user']['started']) || (allowedTo('modify_own') && $message['id_member'] == $user_info['id'] && (empty($modSettings['edit_disable_time']) || !$message['approved'] || $message['poster_time'] + $modSettings['edit_disable_time'] * 60 > time()))), Chris@76: 'can_remove' => allowedTo('delete_any') || (allowedTo('delete_replies') && $context['user']['started']) || (allowedTo('delete_own') && $message['id_member'] == $user_info['id'] && (empty($modSettings['edit_disable_time']) || $message['poster_time'] + $modSettings['edit_disable_time'] * 60 > time())), Chris@76: 'can_see_ip' => allowedTo('moderate_forum') || ($message['id_member'] == $user_info['id'] && !empty($user_info['id'])), Chris@76: ); Chris@76: Chris@76: // Is this user the message author? Chris@76: $output['is_message_author'] = $message['id_member'] == $user_info['id']; Chris@76: Chris@76: if (empty($options['view_newest_first'])) Chris@76: $counter++; Chris@76: else Chris@76: $counter--; Chris@76: Chris@76: return $output; Chris@76: } Chris@76: Chris@76: // Download an attachment. Chris@76: function Download() Chris@76: { Chris@76: global $txt, $modSettings, $user_info, $scripturl, $context, $sourcedir, $topic, $smcFunc; Chris@76: Chris@76: // Some defaults that we need. Chris@76: $context['character_set'] = empty($modSettings['global_character_set']) ? (empty($txt['lang_character_set']) ? 'ISO-8859-1' : $txt['lang_character_set']) : $modSettings['global_character_set']; Chris@76: $context['utf8'] = $context['character_set'] === 'UTF-8' && (strpos(strtolower(PHP_OS), 'win') === false || @version_compare(PHP_VERSION, '4.2.3') != -1); Chris@76: $context['no_last_modified'] = true; Chris@76: Chris@76: // Make sure some attachment was requested! Chris@76: if (!isset($_REQUEST['attach']) && !isset($_REQUEST['id'])) Chris@76: fatal_lang_error('no_access', false); Chris@76: Chris@76: $_REQUEST['attach'] = isset($_REQUEST['attach']) ? (int) $_REQUEST['attach'] : (int) $_REQUEST['id']; Chris@76: Chris@76: if (isset($_REQUEST['type']) && $_REQUEST['type'] == 'avatar') Chris@76: { Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT id_folder, filename, file_hash, fileext, id_attach, attachment_type, mime_type, approved, id_member Chris@76: FROM {db_prefix}attachments Chris@76: WHERE id_attach = {int:id_attach} Chris@76: AND id_member > {int:blank_id_member} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'id_attach' => $_REQUEST['attach'], Chris@76: 'blank_id_member' => 0, Chris@76: ) Chris@76: ); Chris@76: $_REQUEST['image'] = true; Chris@76: } Chris@76: // This is just a regular attachment... Chris@76: else Chris@76: { Chris@76: // This checks only the current board for $board/$topic's permissions. Chris@76: isAllowedTo('view_attachments'); Chris@76: Chris@76: // Make sure this attachment is on this board. Chris@76: // NOTE: We must verify that $topic is the attachment's topic, or else the permission check above is broken. Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT a.id_folder, a.filename, a.file_hash, a.fileext, a.id_attach, a.attachment_type, a.mime_type, a.approved, m.id_member Chris@76: FROM {db_prefix}attachments AS a Chris@76: INNER JOIN {db_prefix}messages AS m ON (m.id_msg = a.id_msg AND m.id_topic = {int:current_topic}) Chris@76: INNER JOIN {db_prefix}boards AS b ON (b.id_board = m.id_board AND {query_see_board}) Chris@76: WHERE a.id_attach = {int:attach} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'attach' => $_REQUEST['attach'], Chris@76: 'current_topic' => $topic, Chris@76: ) Chris@76: ); Chris@76: } Chris@76: if ($smcFunc['db_num_rows']($request) == 0) Chris@76: fatal_lang_error('no_access', false); Chris@76: list ($id_folder, $real_filename, $file_hash, $file_ext, $id_attach, $attachment_type, $mime_type, $is_approved, $id_member) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // If it isn't yet approved, do they have permission to view it? Chris@76: if (!$is_approved && ($id_member == 0 || $user_info['id'] != $id_member) && ($attachment_type == 0 || $attachment_type == 3)) Chris@76: isAllowedTo('approve_posts'); Chris@76: Chris@76: // Update the download counter (unless it's a thumbnail). Chris@76: if ($attachment_type != 3) Chris@76: $smcFunc['db_query']('attach_download_increase', ' Chris@76: UPDATE LOW_PRIORITY {db_prefix}attachments Chris@76: SET downloads = downloads + 1 Chris@76: WHERE id_attach = {int:id_attach}', Chris@76: array( Chris@76: 'id_attach' => $id_attach, Chris@76: ) Chris@76: ); Chris@76: Chris@76: $filename = getAttachmentFilename($real_filename, $_REQUEST['attach'], $id_folder, false, $file_hash); Chris@76: Chris@76: // This is done to clear any output that was made before now. (would use ob_clean(), but that's PHP 4.2.0+...) Chris@76: ob_end_clean(); Chris@76: if (!empty($modSettings['enableCompressedOutput']) && @version_compare(PHP_VERSION, '4.2.0') >= 0 && @filesize($filename) <= 4194304 && in_array($file_ext, array('txt', 'html', 'htm', 'js', 'doc', 'pdf', 'docx', 'rtf', 'css', 'php', 'log', 'xml', 'sql', 'c', 'java'))) Chris@76: @ob_start('ob_gzhandler'); Chris@76: else Chris@76: { Chris@76: ob_start(); Chris@76: header('Content-Encoding: none'); Chris@76: } Chris@76: Chris@76: // No point in a nicer message, because this is supposed to be an attachment anyway... Chris@76: if (!file_exists($filename)) Chris@76: { Chris@76: loadLanguage('Errors'); Chris@76: Chris@76: header('HTTP/1.0 404 ' . $txt['attachment_not_found']); Chris@76: header('Content-Type: text/plain; charset=' . (empty($context['character_set']) ? 'ISO-8859-1' : $context['character_set'])); Chris@76: Chris@76: // We need to die like this *before* we send any anti-caching headers as below. Chris@76: die('404 - ' . $txt['attachment_not_found']); Chris@76: } Chris@76: Chris@76: // If it hasn't been modified since the last time this attachement was retrieved, there's no need to display it again. Chris@76: if (!empty($_SERVER['HTTP_IF_MODIFIED_SINCE'])) Chris@76: { Chris@76: list($modified_since) = explode(';', $_SERVER['HTTP_IF_MODIFIED_SINCE']); Chris@76: if (strtotime($modified_since) >= filemtime($filename)) Chris@76: { Chris@76: ob_end_clean(); Chris@76: Chris@76: // Answer the question - no, it hasn't been modified ;). Chris@76: header('HTTP/1.1 304 Not Modified'); Chris@76: exit; Chris@76: } Chris@76: } Chris@76: Chris@76: // Check whether the ETag was sent back, and cache based on that... Chris@76: $eTag = '"' . substr($_REQUEST['attach'] . $real_filename . filemtime($filename), 0, 64) . '"'; Chris@76: if (!empty($_SERVER['HTTP_IF_NONE_MATCH']) && strpos($_SERVER['HTTP_IF_NONE_MATCH'], $eTag) !== false) Chris@76: { Chris@76: ob_end_clean(); Chris@76: Chris@76: header('HTTP/1.1 304 Not Modified'); Chris@76: exit; Chris@76: } Chris@76: Chris@76: // Send the attachment headers. Chris@76: header('Pragma: '); Chris@76: if (!$context['browser']['is_gecko']) Chris@76: header('Content-Transfer-Encoding: binary'); Chris@76: header('Expires: ' . gmdate('D, d M Y H:i:s', time() + 525600 * 60) . ' GMT'); Chris@76: header('Last-Modified: ' . gmdate('D, d M Y H:i:s', filemtime($filename)) . ' GMT'); Chris@76: header('Accept-Ranges: bytes'); Chris@76: header('Connection: close'); Chris@76: header('ETag: ' . $eTag); Chris@76: Chris@76: // IE 6 just doesn't play nice. As dirty as this seems, it works. Chris@76: if ($context['browser']['is_ie6'] && isset($_REQUEST['image'])) Chris@76: unset($_REQUEST['image']); Chris@76: Chris@76: // Make sure the mime type warrants an inline display. Chris@76: elseif (isset($_REQUEST['image']) && !empty($mime_type) && strpos($mime_type, 'image/') !== 0) Chris@76: unset($_REQUEST['image']); Chris@76: Chris@76: // Does this have a mime type? Chris@76: elseif (!empty($mime_type) && (isset($_REQUEST['image']) || !in_array($file_ext, array('jpg', 'gif', 'jpeg', 'x-ms-bmp', 'png', 'psd', 'tiff', 'iff')))) Chris@76: header('Content-Type: ' . strtr($mime_type, array('image/bmp' => 'image/x-ms-bmp'))); Chris@76: Chris@76: else Chris@76: { Chris@76: header('Content-Type: ' . ($context['browser']['is_ie'] || $context['browser']['is_opera'] ? 'application/octetstream' : 'application/octet-stream')); Chris@76: if (isset($_REQUEST['image'])) Chris@76: unset($_REQUEST['image']); Chris@76: } Chris@76: Chris@76: // Convert the file to UTF-8, cuz most browsers dig that. Chris@76: $utf8name = !$context['utf8'] && function_exists('iconv') ? iconv($context['character_set'], 'UTF-8', $real_filename) : (!$context['utf8'] && function_exists('mb_convert_encoding') ? mb_convert_encoding($real_filename, 'UTF-8', $context['character_set']) : $real_filename); Chris@76: $fixchar = create_function('$n', ' Chris@76: if ($n < 32) Chris@76: return \'\'; Chris@76: elseif ($n < 128) Chris@76: return chr($n); Chris@76: elseif ($n < 2048) Chris@76: return chr(192 | $n >> 6) . chr(128 | $n & 63); Chris@76: elseif ($n < 65536) Chris@76: return chr(224 | $n >> 12) . chr(128 | $n >> 6 & 63) . chr(128 | $n & 63); Chris@76: else Chris@76: return chr(240 | $n >> 18) . chr(128 | $n >> 12 & 63) . chr(128 | $n >> 6 & 63) . chr(128 | $n & 63);'); Chris@76: Chris@76: $disposition = !isset($_REQUEST['image']) ? 'attachment' : 'inline'; Chris@76: Chris@76: // Different browsers like different standards... Chris@76: if ($context['browser']['is_firefox']) Chris@76: header('Content-Disposition: ' . $disposition . '; filename*="UTF-8\'\'' . preg_replace('~&#(\d{3,8});~e', '$fixchar(\'$1\')', $utf8name) . '"'); Chris@76: Chris@76: elseif ($context['browser']['is_opera']) Chris@76: header('Content-Disposition: ' . $disposition . '; filename="' . preg_replace('~&#(\d{3,8});~e', '$fixchar(\'$1\')', $utf8name) . '"'); Chris@76: Chris@76: elseif ($context['browser']['is_ie']) Chris@76: header('Content-Disposition: ' . $disposition . '; filename="' . urlencode(preg_replace('~&#(\d{3,8});~e', '$fixchar(\'$1\')', $utf8name)) . '"'); Chris@76: Chris@76: else Chris@76: header('Content-Disposition: ' . $disposition . '; filename="' . $utf8name . '"'); Chris@76: Chris@76: // If this has an "image extension" - but isn't actually an image - then ensure it isn't cached cause of silly IE. Chris@76: if (!isset($_REQUEST['image']) && in_array($file_ext, array('gif', 'jpg', 'bmp', 'png', 'jpeg', 'tiff'))) Chris@76: header('Cache-Control: no-cache'); Chris@76: else Chris@76: header('Cache-Control: max-age=' . (525600 * 60) . ', private'); Chris@76: Chris@76: if (empty($modSettings['enableCompressedOutput']) || filesize($filename) > 4194304) Chris@76: header('Content-Length: ' . filesize($filename)); Chris@76: Chris@76: // Try to buy some time... Chris@76: @set_time_limit(600); Chris@76: Chris@76: // Recode line endings for text files, if enabled. Chris@76: if (!empty($modSettings['attachmentRecodeLineEndings']) && !isset($_REQUEST['image']) && in_array($file_ext, array('txt', 'css', 'htm', 'html', 'php', 'xml'))) Chris@76: { Chris@76: if (strpos($_SERVER['HTTP_USER_AGENT'], 'Windows') !== false) Chris@76: $callback = create_function('$buffer', 'return preg_replace(\'~[\r]?\n~\', "\r\n", $buffer);'); Chris@76: elseif (strpos($_SERVER['HTTP_USER_AGENT'], 'Mac') !== false) Chris@76: $callback = create_function('$buffer', 'return preg_replace(\'~[\r]?\n~\', "\r", $buffer);'); Chris@76: else Chris@76: $callback = create_function('$buffer', 'return preg_replace(\'~[\r]?\n~\', "\n", $buffer);'); Chris@76: } Chris@76: Chris@76: // Since we don't do output compression for files this large... Chris@76: if (filesize($filename) > 4194304) Chris@76: { Chris@76: // Forcibly end any output buffering going on. Chris@76: if (function_exists('ob_get_level')) Chris@76: { Chris@76: while (@ob_get_level() > 0) Chris@76: @ob_end_clean(); Chris@76: } Chris@76: else Chris@76: { Chris@76: @ob_end_clean(); Chris@76: @ob_end_clean(); Chris@76: @ob_end_clean(); Chris@76: } Chris@76: Chris@76: $fp = fopen($filename, 'rb'); Chris@76: while (!feof($fp)) Chris@76: { Chris@76: if (isset($callback)) Chris@76: echo $callback(fread($fp, 8192)); Chris@76: else Chris@76: echo fread($fp, 8192); Chris@76: flush(); Chris@76: } Chris@76: fclose($fp); Chris@76: } Chris@76: // On some of the less-bright hosts, readfile() is disabled. It's just a faster, more byte safe, version of what's in the if. Chris@76: elseif (isset($callback) || @readfile($filename) == null) Chris@76: echo isset($callback) ? $callback(file_get_contents($filename)) : file_get_contents($filename); Chris@76: Chris@76: obExit(false); Chris@76: } Chris@76: Chris@76: function loadAttachmentContext($id_msg) Chris@76: { Chris@76: global $attachments, $modSettings, $txt, $scripturl, $topic, $sourcedir, $smcFunc; Chris@76: Chris@76: // Set up the attachment info - based on code by Meriadoc. Chris@76: $attachmentData = array(); Chris@76: $have_unapproved = false; Chris@76: if (isset($attachments[$id_msg]) && !empty($modSettings['attachmentEnable'])) Chris@76: { Chris@76: foreach ($attachments[$id_msg] as $i => $attachment) Chris@76: { Chris@76: $attachmentData[$i] = array( Chris@76: 'id' => $attachment['id_attach'], Chris@76: 'name' => preg_replace('~&#(\\d{1,7}|x[0-9a-fA-F]{1,6});~', '&#\\1;', htmlspecialchars($attachment['filename'])), Chris@76: 'downloads' => $attachment['downloads'], Chris@76: 'size' => round($attachment['filesize'] / 1024, 2) . ' ' . $txt['kilobyte'], Chris@76: 'byte_size' => $attachment['filesize'], Chris@76: 'href' => $scripturl . '?action=dlattach;topic=' . $topic . '.0;attach=' . $attachment['id_attach'], Chris@76: 'link' => '' . htmlspecialchars($attachment['filename']) . '', Chris@76: 'is_image' => !empty($attachment['width']) && !empty($attachment['height']) && !empty($modSettings['attachmentShowImages']), Chris@76: 'is_approved' => $attachment['approved'], Chris@76: ); Chris@76: Chris@76: // If something is unapproved we'll note it so we can sort them. Chris@76: if (!$attachment['approved']) Chris@76: $have_unapproved = true; Chris@76: Chris@76: if (!$attachmentData[$i]['is_image']) Chris@76: continue; Chris@76: Chris@76: $attachmentData[$i]['real_width'] = $attachment['width']; Chris@76: $attachmentData[$i]['width'] = $attachment['width']; Chris@76: $attachmentData[$i]['real_height'] = $attachment['height']; Chris@76: $attachmentData[$i]['height'] = $attachment['height']; Chris@76: Chris@76: // Let's see, do we want thumbs? Chris@76: if (!empty($modSettings['attachmentThumbnails']) && !empty($modSettings['attachmentThumbWidth']) && !empty($modSettings['attachmentThumbHeight']) && ($attachment['width'] > $modSettings['attachmentThumbWidth'] || $attachment['height'] > $modSettings['attachmentThumbHeight']) && strlen($attachment['filename']) < 249) Chris@76: { Chris@76: // A proper thumb doesn't exist yet? Create one! Chris@76: if (empty($attachment['id_thumb']) || $attachment['thumb_width'] > $modSettings['attachmentThumbWidth'] || $attachment['thumb_height'] > $modSettings['attachmentThumbHeight'] || ($attachment['thumb_width'] < $modSettings['attachmentThumbWidth'] && $attachment['thumb_height'] < $modSettings['attachmentThumbHeight'])) Chris@76: { Chris@76: $filename = getAttachmentFilename($attachment['filename'], $attachment['id_attach'], $attachment['id_folder']); Chris@76: Chris@76: require_once($sourcedir . '/Subs-Graphics.php'); Chris@76: if (createThumbnail($filename, $modSettings['attachmentThumbWidth'], $modSettings['attachmentThumbHeight'])) Chris@76: { Chris@76: // So what folder are we putting this image in? Chris@76: if (!empty($modSettings['currentAttachmentUploadDir'])) Chris@76: { Chris@76: if (!is_array($modSettings['attachmentUploadDir'])) Chris@76: $modSettings['attachmentUploadDir'] = @unserialize($modSettings['attachmentUploadDir']); Chris@76: $path = $modSettings['attachmentUploadDir'][$modSettings['currentAttachmentUploadDir']]; Chris@76: $id_folder_thumb = $modSettings['currentAttachmentUploadDir']; Chris@76: } Chris@76: else Chris@76: { Chris@76: $path = $modSettings['attachmentUploadDir']; Chris@76: $id_folder_thumb = 1; Chris@76: } Chris@76: Chris@76: // Calculate the size of the created thumbnail. Chris@76: $size = @getimagesize($filename . '_thumb'); Chris@76: list ($attachment['thumb_width'], $attachment['thumb_height']) = $size; Chris@76: $thumb_size = filesize($filename . '_thumb'); Chris@76: Chris@76: // These are the only valid image types for SMF. Chris@76: $validImageTypes = array(1 => 'gif', 2 => 'jpeg', 3 => 'png', 5 => 'psd', 6 => 'bmp', 7 => 'tiff', 8 => 'tiff', 9 => 'jpeg', 14 => 'iff'); Chris@76: Chris@76: // What about the extension? Chris@76: $thumb_ext = isset($validImageTypes[$size[2]]) ? $validImageTypes[$size[2]] : ''; Chris@76: Chris@76: // Figure out the mime type. Chris@76: if (!empty($size['mime'])) Chris@76: $thumb_mime = $size['mime']; Chris@76: else Chris@76: $thumb_mime = 'image/' . $thumb_ext; Chris@76: Chris@76: $thumb_filename = $attachment['filename'] . '_thumb'; Chris@76: $thumb_hash = getAttachmentFilename($thumb_filename, false, null, true); Chris@76: Chris@76: // Add this beauty to the database. Chris@76: $smcFunc['db_insert']('', Chris@76: '{db_prefix}attachments', Chris@76: array('id_folder' => 'int', 'id_msg' => 'int', 'attachment_type' => 'int', 'filename' => 'string', 'file_hash' => 'string', 'size' => 'int', 'width' => 'int', 'height' => 'int', 'fileext' => 'string', 'mime_type' => 'string'), Chris@76: array($id_folder_thumb, $id_msg, 3, $thumb_filename, $thumb_hash, (int) $thumb_size, (int) $attachment['thumb_width'], (int) $attachment['thumb_height'], $thumb_ext, $thumb_mime), Chris@76: array('id_attach') Chris@76: ); Chris@76: $old_id_thumb = $attachment['id_thumb']; Chris@76: $attachment['id_thumb'] = $smcFunc['db_insert_id']('{db_prefix}attachments', 'id_attach'); Chris@76: if (!empty($attachment['id_thumb'])) Chris@76: { Chris@76: $smcFunc['db_query']('', ' Chris@76: UPDATE {db_prefix}attachments Chris@76: SET id_thumb = {int:id_thumb} Chris@76: WHERE id_attach = {int:id_attach}', Chris@76: array( Chris@76: 'id_thumb' => $attachment['id_thumb'], Chris@76: 'id_attach' => $attachment['id_attach'], Chris@76: ) Chris@76: ); Chris@76: Chris@76: $thumb_realname = getAttachmentFilename($thumb_filename, $attachment['id_thumb'], $id_folder_thumb, false, $thumb_hash); Chris@76: rename($filename . '_thumb', $thumb_realname); Chris@76: Chris@76: // Do we need to remove an old thumbnail? Chris@76: if (!empty($old_id_thumb)) Chris@76: { Chris@76: require_once($sourcedir . '/ManageAttachments.php'); Chris@76: removeAttachments(array('id_attach' => $old_id_thumb), '', false, false); Chris@76: } Chris@76: } Chris@76: } Chris@76: } Chris@76: Chris@76: // Only adjust dimensions on successful thumbnail creation. Chris@76: if (!empty($attachment['thumb_width']) && !empty($attachment['thumb_height'])) Chris@76: { Chris@76: $attachmentData[$i]['width'] = $attachment['thumb_width']; Chris@76: $attachmentData[$i]['height'] = $attachment['thumb_height']; Chris@76: } Chris@76: } Chris@76: Chris@76: if (!empty($attachment['id_thumb'])) Chris@76: $attachmentData[$i]['thumbnail'] = array( Chris@76: 'id' => $attachment['id_thumb'], Chris@76: 'href' => $scripturl . '?action=dlattach;topic=' . $topic . '.0;attach=' . $attachment['id_thumb'] . ';image', Chris@76: ); Chris@76: $attachmentData[$i]['thumbnail']['has_thumb'] = !empty($attachment['id_thumb']); Chris@76: Chris@76: // If thumbnails are disabled, check the maximum size of the image. Chris@76: if (!$attachmentData[$i]['thumbnail']['has_thumb'] && ((!empty($modSettings['max_image_width']) && $attachment['width'] > $modSettings['max_image_width']) || (!empty($modSettings['max_image_height']) && $attachment['height'] > $modSettings['max_image_height']))) Chris@76: { Chris@76: if (!empty($modSettings['max_image_width']) && (empty($modSettings['max_image_height']) || $attachment['height'] * $modSettings['max_image_width'] / $attachment['width'] <= $modSettings['max_image_height'])) Chris@76: { Chris@76: $attachmentData[$i]['width'] = $modSettings['max_image_width']; Chris@76: $attachmentData[$i]['height'] = floor($attachment['height'] * $modSettings['max_image_width'] / $attachment['width']); Chris@76: } Chris@76: elseif (!empty($modSettings['max_image_width'])) Chris@76: { Chris@76: $attachmentData[$i]['width'] = floor($attachment['width'] * $modSettings['max_image_height'] / $attachment['height']); Chris@76: $attachmentData[$i]['height'] = $modSettings['max_image_height']; Chris@76: } Chris@76: } Chris@76: elseif ($attachmentData[$i]['thumbnail']['has_thumb']) Chris@76: { Chris@76: // If the image is too large to show inline, make it a popup. Chris@76: if (((!empty($modSettings['max_image_width']) && $attachmentData[$i]['real_width'] > $modSettings['max_image_width']) || (!empty($modSettings['max_image_height']) && $attachmentData[$i]['real_height'] > $modSettings['max_image_height']))) Chris@76: $attachmentData[$i]['thumbnail']['javascript'] = 'return reqWin(\'' . $attachmentData[$i]['href'] . ';image\', ' . ($attachment['width'] + 20) . ', ' . ($attachment['height'] + 20) . ', true);'; Chris@76: else Chris@76: $attachmentData[$i]['thumbnail']['javascript'] = 'return expandThumb(' . $attachment['id_attach'] . ');'; Chris@76: } Chris@76: Chris@76: if (!$attachmentData[$i]['thumbnail']['has_thumb']) Chris@76: $attachmentData[$i]['downloads']++; Chris@76: } Chris@76: } Chris@76: Chris@76: // Do we need to instigate a sort? Chris@76: if ($have_unapproved) Chris@76: usort($attachmentData, 'approved_attach_sort'); Chris@76: Chris@76: return $attachmentData; Chris@76: } Chris@76: Chris@76: // A sort function for putting unapproved attachments first. Chris@76: function approved_attach_sort($a, $b) Chris@76: { Chris@76: if ($a['is_approved'] == $b['is_approved']) Chris@76: return 0; Chris@76: Chris@76: return $a['is_approved'] > $b['is_approved'] ? -1 : 1; Chris@76: } Chris@76: Chris@76: // In-topic quick moderation. Chris@76: function QuickInTopicModeration() Chris@76: { Chris@76: global $sourcedir, $topic, $board, $user_info, $smcFunc, $modSettings, $context; Chris@76: Chris@76: // Check the session = get or post. Chris@76: checkSession('request'); Chris@76: Chris@76: require_once($sourcedir . '/RemoveTopic.php'); Chris@76: Chris@76: if (empty($_REQUEST['msgs'])) Chris@76: redirectexit('topic=' . $topic . '.' . $_REQUEST['start']); Chris@76: Chris@76: $messages = array(); Chris@76: foreach ($_REQUEST['msgs'] as $dummy) Chris@76: $messages[] = (int) $dummy; Chris@76: Chris@76: // We are restoring messages. We handle this in another place. Chris@76: if (isset($_REQUEST['restore_selected'])) Chris@76: redirectexit('action=restoretopic;msgs=' . implode(',', $messages) . ';' . $context['session_var'] . '=' . $context['session_id']); Chris@76: Chris@76: // Allowed to delete any message? Chris@76: if (allowedTo('delete_any')) Chris@76: $allowed_all = true; Chris@76: // Allowed to delete replies to their messages? Chris@76: elseif (allowedTo('delete_replies')) Chris@76: { Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT id_member_started Chris@76: FROM {db_prefix}topics Chris@76: WHERE id_topic = {int:current_topic} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'current_topic' => $topic, Chris@76: ) Chris@76: ); Chris@76: list ($starter) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: $allowed_all = $starter == $user_info['id']; Chris@76: } Chris@76: else Chris@76: $allowed_all = false; Chris@76: Chris@76: // Make sure they're allowed to delete their own messages, if not any. Chris@76: if (!$allowed_all) Chris@76: isAllowedTo('delete_own'); Chris@76: Chris@76: // Allowed to remove which messages? Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT id_msg, subject, id_member, poster_time Chris@76: FROM {db_prefix}messages Chris@76: WHERE id_msg IN ({array_int:message_list}) Chris@76: AND id_topic = {int:current_topic}' . (!$allowed_all ? ' Chris@76: AND id_member = {int:current_member}' : '') . ' Chris@76: LIMIT ' . count($messages), Chris@76: array( Chris@76: 'current_member' => $user_info['id'], Chris@76: 'current_topic' => $topic, Chris@76: 'message_list' => $messages, Chris@76: ) Chris@76: ); Chris@76: $messages = array(); Chris@76: while ($row = $smcFunc['db_fetch_assoc']($request)) Chris@76: { Chris@76: if (!$allowed_all && !empty($modSettings['edit_disable_time']) && $row['poster_time'] + $modSettings['edit_disable_time'] * 60 < time()) Chris@76: continue; Chris@76: Chris@76: $messages[$row['id_msg']] = array($row['subject'], $row['id_member']); Chris@76: } Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // Get the first message in the topic - because you can't delete that! Chris@76: $request = $smcFunc['db_query']('', ' Chris@76: SELECT id_first_msg, id_last_msg Chris@76: FROM {db_prefix}topics Chris@76: WHERE id_topic = {int:current_topic} Chris@76: LIMIT 1', Chris@76: array( Chris@76: 'current_topic' => $topic, Chris@76: ) Chris@76: ); Chris@76: list ($first_message, $last_message) = $smcFunc['db_fetch_row']($request); Chris@76: $smcFunc['db_free_result']($request); Chris@76: Chris@76: // Delete all the messages we know they can delete. ($messages) Chris@76: foreach ($messages as $message => $info) Chris@76: { Chris@76: // Just skip the first message - if it's not the last. Chris@76: if ($message == $first_message && $message != $last_message) Chris@76: continue; Chris@76: // If the first message is going then don't bother going back to the topic as we're effectively deleting it. Chris@76: elseif ($message == $first_message) Chris@76: $topicGone = true; Chris@76: Chris@76: removeMessage($message); Chris@76: Chris@76: // Log this moderation action ;). Chris@76: if (allowedTo('delete_any') && (!allowedTo('delete_own') || $info[1] != $user_info['id'])) Chris@76: logAction('delete', array('topic' => $topic, 'subject' => $info[0], 'member' => $info[1], 'board' => $board)); Chris@76: } Chris@76: Chris@76: redirectexit(!empty($topicGone) ? 'board=' . $board : 'topic=' . $topic . '.' . $_REQUEST['start']); Chris@76: } Chris@76: Chris@76: ?>