#', '#"#'); $html_entities_replace = array('&', '<', '>', '"'); // // Parameters // $submit = (isset($HTTP_POST_VARS['post'])) ? TRUE : 0; $submit_search = (isset($HTTP_POST_VARS['usersubmit'])) ? TRUE : 0; $submit_msgdays = (isset($HTTP_POST_VARS['submit_msgdays'])) ? TRUE : 0; $cancel = (isset($HTTP_POST_VARS['cancel'])) ? TRUE : 0; $preview = (isset($HTTP_POST_VARS['preview'])) ? TRUE : 0; $confirm = (isset($HTTP_POST_VARS['confirm'])) ? TRUE : 0; $delete = (isset($HTTP_POST_VARS['delete'])) ? TRUE : 0; $delete_all = (isset($HTTP_POST_VARS['deleteall'])) ? TRUE : 0; $save = (isset($HTTP_POST_VARS['save'])) ? TRUE : 0; $refresh = $preview || $submit_search; $mark_list = (!empty($HTTP_POST_VARS['mark'])) ? $HTTP_POST_VARS['mark'] : 0; if ( isset($HTTP_POST_VARS['folder']) || isset($HTTP_GET_VARS['folder']) ) { $folder = (isset($HTTP_POST_VARS['folder'])) ? $HTTP_POST_VARS['folder'] : $HTTP_GET_VARS['folder']; $folder = htmlspecialchars($folder); if ( $folder != 'inbox' && $folder != 'outbox' && $folder != 'sentbox' && $folder != 'savebox' ) { $folder = 'inbox'; } } else { $folder = 'inbox'; } // // Start session management // $userdata = session_pagestart($user_ip, PAGE_PRIVMSGS); init_userprefs($userdata); // // End session management // $user_topics_per_page = ($userdata['user_topics_per_page'] > $board_config['topics_per_page']) ? $board_config['topics_per_page'] : $userdata['user_topics_per_page']; if ( $board_config['login_require'] && !$userdata['session_logged_in'] ) { $message = $lang['login_require'] . '

' . sprintf($lang['login_require_register'], '', ''); message_die(GENERAL_MESSAGE, $message); } // // Cancel // if ( $cancel ) { redirect(append_sid("privmsg.$phpEx?folder=$folder", true)); } // // Var definitions // if ( !empty($HTTP_POST_VARS['mode']) || !empty($HTTP_GET_VARS['mode']) ) { $mode = ( !empty($HTTP_POST_VARS['mode']) ) ? $HTTP_POST_VARS['mode'] : $HTTP_GET_VARS['mode']; $mode = htmlspecialchars($mode); } else { $mode = ''; } $sql = $pm_sql_user = $privmsgs_id = $sql_priority = ''; // session id check if (!empty($HTTP_POST_VARS['sid']) || !empty($HTTP_GET_VARS['sid'])) { $sid = (!empty($HTTP_POST_VARS['sid'])) ? $HTTP_POST_VARS['sid'] : $HTTP_GET_VARS['sid']; } else { $sid = ''; } $start = (!empty($HTTP_GET_VARS['start'])) ? intval($HTTP_GET_VARS['start']) : 0; if ( isset($HTTP_POST_VARS['start']) ) { $start = intval($HTTP_POST_VARS['start']); } if ( isset($HTTP_POST_VARS[POST_POST_URL]) || isset($HTTP_GET_VARS[POST_POST_URL]) ) { $privmsg_id = ( isset($HTTP_POST_VARS[POST_POST_URL]) ) ? intval($HTTP_POST_VARS[POST_POST_URL]) : intval($HTTP_GET_VARS[POST_POST_URL]); } else { $privmsg_id = ''; } function check_enable_pm($user_id) { global $db, $lang, $userdata, $phpEx; $sql = "SELECT allowpm FROM " . USERS_TABLE . " WHERE user_id = $user_id"; if ( !$result = $db->sql_query($sql) ) { message_die(GENERAL_MESSAGE, $lang['No_user_id_specified']); } $allowpm = $db->sql_fetchrow($result); if ( !$allowpm['allowpm'] && $userdata['user_level'] != ADMIN && $userdata['user_level'] != MOD ) { message_die(GENERAL_MESSAGE, $lang['user_not_allowpm'] . '

' . sprintf($lang['Click_return_inbox'], '', ' ') . '

' . sprintf($lang['Click_return_index'], '', '')); } return; } $error = FALSE; // Define the box image links $inbox_img = ($folder != 'inbox' || $mode != '') ? '' . $lang['Inbox'] . '' : '' . $lang['Inbox'] . ''; $inbox_url = ($folder != 'inbox' || $mode != '') ? '' . $lang['Inbox'] . '' : $lang['Inbox']; $outbox_img = ($folder != 'outbox' || $mode != '') ? '' . $lang['Outbox'] . '' : '' . $lang['Outbox'] . ''; $outbox_url = ($folder != 'outbox' || $mode != '') ? '' . $lang['Outbox'] . '' : $lang['Outbox']; $sentbox_img = ($folder != 'sentbox' || $mode != '') ? '' . $lang['Sentbox'] . '' : '' . $lang['Sentbox'] . ''; $sentbox_url = ($folder != 'sentbox' || $mode != '') ? '' . $lang['Sentbox'] . '' : $lang['Sentbox']; $savebox_img = ($folder != 'savebox' || $mode != '') ? '' . $lang['Savebox'] . '' : '' . $lang['Savebox'] . ''; $savebox_url = ($folder != 'savebox' || $mode != '') ? '' . $lang['Savebox'] . '' : $lang['Savebox']; if ( defined('ATTACHMENTS_ON') ) { execute_privmsgs_attachment_handling($mode); } $user_can_use_bbcode = false; if ( $board_config['allow_bbcode'] && $userdata['user_allowbbcode'] ) { $user_can_use_bbcode = true; } if ( !$user_can_use_bbcode ) { $bbcode_on = 0; } else { $bbcode_on = (!empty($HTTP_POST_VARS['disable_bbcode'])) ? 0 : true; } // Start main if ( $mode == 'birthday' ) { $gen_simple_header = true; $page_title = $lang['Greeting_Messaging']; include($phpbb_root_path . 'includes/page_header.'.$phpEx); $l_greeting = (date('dm') == realdate('dm', $userdata['user_birthday'])) ? sprintf($lang['Birthday_greeting_today'], date('Y')-realdate('Y',$userdata['user_birthday'])) : sprintf ( $lang['Birthday_greeting_prev'], date('Y')-realdate('Y',$userdata['user_birthday']), realdate(str_replace('Y','',$lang['DATE_FORMAT']),$userdata['user_birthday']) ); $template->set_filenames(array( 'body' => 'greeting_popup.tpl') ); $template->assign_vars(array( 'L_CLOSE_WINDOW' => $lang['Close_window'], 'L_MESSAGE' => $l_greeting ) ); $template->pparse('body'); include($phpbb_root_path . 'includes/page_tail.'.$phpEx); } else if ( $mode == 'newpm' ) { $gen_simple_header = TRUE; $page_title = $lang['Private_Messaging']; include($phpbb_root_path . 'includes/page_header.'.$phpEx); $template->set_filenames(array( 'body' => 'privmsgs_popup.tpl') ); if ( $userdata['session_logged_in'] ) { if ( $userdata['user_new_privmsg'] ) { $l_new_message = ($userdata['user_new_privmsg'] == 1) ? $lang['You_new_pm'] : $lang['You_new_pms']; } else { $l_new_message = $lang['You_no_new_pm']; } $l_new_message .= '

' . sprintf($lang['Click_view_privmsg'], '', ''); } else { $l_new_message = $lang['Login_check_pm']; } $template->assign_vars(array( 'L_CLOSE_WINDOW' => $lang['Close_window'], 'L_MESSAGE' => $l_new_message) ); $template->pparse('body'); include($phpbb_root_path . 'includes/page_tail.'.$phpEx); } else if ( $mode == 'read' ) { if ( !empty($HTTP_GET_VARS[POST_POST_URL]) ) { $privmsgs_id = intval($HTTP_GET_VARS[POST_POST_URL]); } else { message_die(GENERAL_ERROR, $lang['No_post_id']); } if ( !$userdata['session_logged_in'] ) { redirect(append_sid("login.$phpEx?redirect=privmsg.$phpEx&folder=$folder&mode=$mode&" . POST_POST_URL . "=$privmsgs_id", true)); } // SQL to pull appropriate message, prevents nosey people // reading other peoples messages ... hopefully! switch( $folder ) { case 'inbox': $l_box_name = $lang['Inbox']; $pm_sql_user = "AND pm.privmsgs_to_userid = " . $userdata['user_id'] . " AND ( pm.privmsgs_type = " . PRIVMSGS_READ_MAIL . " OR pm.privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR pm.privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " )"; break; case 'outbox': $l_box_name = $lang['Outbox']; $pm_sql_user = "AND pm.privmsgs_from_userid = " . $userdata['user_id'] . " AND ( pm.privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR pm.privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " ) "; break; case 'sentbox': $l_box_name = $lang['Sentbox']; $pm_sql_user = "AND pm.privmsgs_from_userid = " . $userdata['user_id'] . " AND pm.privmsgs_type = " . PRIVMSGS_SENT_MAIL; break; case 'savebox': $l_box_name = $lang['Savebox']; $pm_sql_user = "AND ( ( pm.privmsgs_to_userid = " . $userdata['user_id'] . " AND pm.privmsgs_type = " . PRIVMSGS_SAVED_IN_MAIL . " ) OR ( pm.privmsgs_from_userid = " . $userdata['user_id'] . " AND pm.privmsgs_type = " . PRIVMSGS_SAVED_OUT_MAIL . " ) )"; break; default: message_die(GENERAL_ERROR, $lang['No_such_folder']); break; } // Major query obtains the message ... $sql = "SELECT u.username AS username_1, u.user_id AS user_id_1, u2.username AS username_2, u2.user_id AS user_id_2, u.user_sig_bbcode_uid, u.user_posts, u.user_from, u.user_website, u.user_email, u.user_icq, u.user_aim, u.user_viewaim, u.user_yim, u.user_regdate, u.user_msnm, u.user_viewemail, u.user_rank, u.user_sig, u.user_sig_image, u.user_allowsig, u.user_avatar, pm.*, pmt.privmsgs_bbcode_uid, pmt.privmsgs_text FROM (" . PRIVMSGS_TABLE . " pm, " . PRIVMSGS_TEXT_TABLE . " pmt, " . USERS_TABLE . " u, " . USERS_TABLE . " u2) WHERE pm.privmsgs_id = $privmsgs_id AND pmt.privmsgs_text_id = pm.privmsgs_id $pm_sql_user AND u.user_id = pm.privmsgs_from_userid AND u2.user_id = pm.privmsgs_to_userid"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not query private message post information', '', __LINE__, __FILE__, $sql); } // Did the query return any data? if ( !($privmsg = $db->sql_fetchrow($result)) ) { redirect(append_sid("privmsg.$phpEx?folder=$folder", true)); } $privmsg_id = $privmsg['privmsgs_id']; // Is this a new message in the inbox? If it is then save // a copy in the posters sent box if ( ($privmsg['privmsgs_type'] == PRIVMSGS_NEW_MAIL || $privmsg['privmsgs_type'] == PRIVMSGS_UNREAD_MAIL) && $folder == 'inbox' ) { // Update appropriate counter switch ($privmsg['privmsgs_type']) { case PRIVMSGS_NEW_MAIL: $sql = "user_new_privmsg = user_new_privmsg - 1"; break; case PRIVMSGS_UNREAD_MAIL: $sql = "user_unread_privmsg = user_unread_privmsg - 1"; break; } $sql = "UPDATE " . USERS_TABLE . " SET $sql WHERE user_id = " . $userdata['user_id']; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not update private message read status for user', '', __LINE__, __FILE__, $sql); } $sql = "UPDATE " . PRIVMSGS_TABLE . " SET privmsgs_type = " . PRIVMSGS_READ_MAIL . " WHERE privmsgs_id = " . $privmsg['privmsgs_id']; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not update private message read status', '', __LINE__, __FILE__, $sql); } // Check to see if the poster has a 'full' sent box $sql = "SELECT COUNT(privmsgs_id) AS sent_items, MIN(privmsgs_date) AS oldest_post_time FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_type = " . PRIVMSGS_SENT_MAIL . " AND privmsgs_from_userid = " . $privmsg['privmsgs_from_userid']; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain sent message info for sendee', '', __LINE__, __FILE__, $sql); } $sql_priority = ( SQL_LAYER == 'mysql' ) ? 'LOW_PRIORITY' : ''; if ( $sent_info = $db->sql_fetchrow($result) ) { if ( $userdata['user_level'] == ADMIN ) { $max_sentbox_privmsgs = $board_config['max_sentbox_privmsgs'] * 6; } else if ( $userdata['user_level'] == MOD ) { $max_sentbox_privmsgs = $board_config['max_sentbox_privmsgs'] * 3; } else { $max_sentbox_privmsgs = $board_config['max_sentbox_privmsgs']; } if ( $board_config['max_sentbox_privmsgs'] && $sent_info['sent_items'] >= $max_sentbox_privmsgs ) { $sql = "SELECT privmsgs_id FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_type = " . PRIVMSGS_SENT_MAIL . " AND privmsgs_date = " . $sent_info['oldest_post_time'] . " AND privmsgs_from_userid = " . $privmsg['privmsgs_from_userid']; if ( !$result = $db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not find oldest privmsgs', '', __LINE__, __FILE__, $sql); } $old_privmsgs_id = $db->sql_fetchrow($result); $old_privmsgs_id = $old_privmsgs_id['privmsgs_id']; $sql = "DELETE $sql_priority FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_id = $old_privmsgs_id"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not delete oldest privmsgs (sent)', '', __LINE__, __FILE__, $sql); } $sql = "DELETE $sql_priority FROM " . PRIVMSGS_TEXT_TABLE . " WHERE privmsgs_text_id = $old_privmsgs_id"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not delete oldest privmsgs text (sent)', '', __LINE__, __FILE__, $sql); } } } if ( $privmsg['privmsgs_from_userid'] != ANONYMOUS ) { $sql = "INSERT $sql_priority INTO " . PRIVMSGS_TABLE . " (privmsgs_type, privmsgs_subject, privmsgs_from_userid, privmsgs_to_userid, privmsgs_date, privmsgs_ip, privmsgs_enable_html, privmsgs_enable_bbcode, privmsgs_enable_smilies, privmsgs_attach_sig) VALUES (" . PRIVMSGS_SENT_MAIL . ", '" . str_replace("'", "''", addslashes($privmsg['privmsgs_subject'])) . "', " . $privmsg['privmsgs_from_userid'] . ", " . $privmsg['privmsgs_to_userid'] . ", " . $privmsg['privmsgs_date'] . ", '" . $privmsg['privmsgs_ip'] . "', " . $privmsg['privmsgs_enable_html'] . ", " . $privmsg['privmsgs_enable_bbcode'] . ", " . $privmsg['privmsgs_enable_smilies'] . ", " . $privmsg['privmsgs_attach_sig'] . ")"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not insert private message sent info', '', __LINE__, __FILE__, $sql); } $privmsg_sent_id = $db->sql_nextid(); $sql = "INSERT $sql_priority INTO " . PRIVMSGS_TEXT_TABLE . " (privmsgs_text_id, privmsgs_bbcode_uid, privmsgs_text) VALUES ($privmsg_sent_id, '" . $privmsg['privmsgs_bbcode_uid'] . "', '" . str_replace("'", "''", addslashes($privmsg['privmsgs_text'])) . "')"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not insert private message sent text', '', __LINE__, __FILE__, $sql); } } } if ( defined('ATTACHMENTS_ON') ) { $attachment_mod['pm'] -> duplicate_attachment_pm($privmsg['privmsgs_attachment'], $privmsg['privmsgs_id'], $privmsg_sent_id); } $service = ($privmsg['user_id_1'] == ANONYMOUS) ? true : false; // Pick a folder, any folder, so long as it's one below ... $post_urls = array( 'post' => append_sid("privmsg.$phpEx?mode=post"), 'reply' => append_sid("privmsg.$phpEx?mode=reply&" . POST_POST_URL . "=$privmsg_id"), 'quote' => append_sid("privmsg.$phpEx?mode=quote&" . POST_POST_URL . "=$privmsg_id"), 'edit' => append_sid("privmsg.$phpEx?mode=edit&" . POST_POST_URL . "=$privmsg_id") ); $post_icons = array( 'post_img' => '' . $lang['Post_new_pm'] . '', 'post' => '' . $lang['Post_new_pm'] . '', 'reply_img' => (!$service) ? '' . $lang['Post_reply_pm'] . '' : '', 'reply' => '' . $lang['Post_reply_pm'] . '', 'quote_img' => (!$service) ? '' . $lang['Post_quote_pm'] . '' : '', 'quote' => '' . $lang['Post_quote_pm'] . '', 'edit_img' => '' . $lang['Edit_pm'] . '', 'edit' => '' . $lang['Edit_pm'] . '' ); if ( $folder == 'inbox' ) { $post_img = $post_icons['post_img']; $reply_img = $post_icons['reply_img']; $edit_img = $edit = ''; $post = $post_icons['post']; $reply = $post_icons['reply']; $l_box_name = $lang['Inbox']; if ( $user_can_use_bbcode ) { $quote_img = $post_icons['quote_img']; $quote = $post_icons['quote']; } } else if ( $folder == 'outbox' ) { $post_img = $post_icons['post_img']; $reply_img = ''; $quote_img = ''; $edit_img = $post_icons['edit_img']; $post = $post_icons['post']; $reply = ''; $quote = ''; $edit = $post_icons['edit']; $l_box_name = $lang['Outbox']; } else if ( $folder == 'savebox' ) { if ( $privmsg['privmsgs_type'] == PRIVMSGS_SAVED_IN_MAIL ) { $post_img = $post_icons['post_img']; $reply_img = $post_icons['reply_img']; if ( $user_can_use_bbcode ) { $quote_img = $post_icons['quote_img']; } $edit_img = ''; $post = $post_icons['post']; $reply = $post_icons['reply']; $quote = $post_icons['quote']; $edit = ''; } else { $post_img = $post_icons['post_img']; $reply_img = ''; $quote_img = ''; $edit_img = ''; $post = $post_icons['post']; $reply = ''; $quote = ''; $edit = ''; } $l_box_name = $lang['Saved']; } else if ( $folder == 'sentbox' ) { $post_img = $post_icons['post_img']; $reply_img = ''; $quote_img = ''; $edit_img = ''; $post = $post_icons['post']; $reply = ''; $quote = ''; $edit = ''; $l_box_name = $lang['Sent']; } $s_hidden_fields = ''; $page_title = $lang['Read_pm']; include($phpbb_root_path . 'includes/page_header.'.$phpEx); // Load templates $template->set_filenames(array( 'body' => 'privmsgs_read_body.tpl') ); make_jumpbox('viewforum.'.$phpEx); $template->assign_vars(array( 'INBOX_IMG' => $inbox_img, 'SENTBOX_IMG' => $sentbox_img, 'OUTBOX_IMG' => $outbox_img, 'SAVEBOX_IMG' => $savebox_img, 'INBOX' => $inbox_url, 'POST_PM_IMG' => $post_img, 'REPLY_PM_IMG' => $reply_img, 'EDIT_PM_IMG' => $edit_img, 'QUOTE_PM_IMG' => $quote_img, 'POST_PM' => $post, 'REPLY_PM' => $reply, 'EDIT_PM' => $edit, 'QUOTE_PM' => $quote, 'SENTBOX' => $sentbox_url, 'OUTBOX' => $outbox_url, 'SAVEBOX' => $savebox_url, 'BOX_NAME' => $l_box_name, 'L_MESSAGE' => $lang['Message'], 'L_SZYBKA' => $lang['Quick_Reply'], 'L_INBOX' => $lang['Inbox'], 'L_OUTBOX' => $lang['Outbox'], 'L_SENTBOX' => $lang['Sent'], 'L_SAVEBOX' => $lang['Saved'], 'L_FLAG' => $lang['Flag'], 'L_SUBJECT' => $lang['Subject'], 'L_POSTED' => $lang['Posted'], 'L_DATE' => $lang['Date'], 'L_FROM' => $lang['From'], 'L_TO' => $lang['To'], 'L_SAVE_MSG' => $lang['Save_message'], 'L_DELETE_MSG' => $lang['Delete_message'], 'L_REPLY'=> $lang['Reply'], 'L_PREVIEW' => $lang['Preview'], 'L_SUBMIT' => $lang['Submit'], 'S_PRIVMSGS_ACTION' => append_sid("privmsg.$phpEx?folder=$folder"), 'S_HIDDEN_FIELDS' => $s_hidden_fields) ); $username_from = ($service) ? '' . $lang['forum_service'] . '' : $privmsg['username_1']; $user_id_from = $privmsg['user_id_1']; $username_to = $privmsg['username_2']; $user_id_to = $privmsg['user_id_2']; if ( defined('ATTACHMENTS_ON') ) { init_display_pm_attachments($privmsg['privmsgs_attachment']); } $post_date = create_date($board_config['default_dateformat'], $privmsg['privmsgs_date'], $board_config['board_timezone']); $temp_url = append_sid("profile.$phpEx?mode=viewprofile&" . POST_USERS_URL . '=' . $user_id_from); $profile_img = ($service) ? '' : '' . $lang['Read_profile'] . ''; $profile = ($service) ? '' : '' . $lang['Read_profile'] . ''; $temp_url = append_sid("privmsg.$phpEx?mode=post&" . POST_USERS_URL . "=$user_id_from"); $pm_img = ($service) ? '' : '' . $lang['Send_private_message'] . ''; $pm = ($service) ? '' : '' . $lang['Send_private_message'] . ''; if ( (!empty($privmsg['user_viewemail']) || $userdata['user_level'] == ADMIN) && !$service ) { $email_uri = ( $board_config['board_email_form'] ) ? append_sid("profile.$phpEx?mode=email&" . POST_USERS_URL .'=' . $user_id_from) : 'mailto:' . $privmsg['user_email']; $email_img = '' . $lang['Send_email'] . ''; $email = '' . $lang['Send_email'] . ''; } else { $email_img = ''; $email = ''; } $www_img = ($privmsg['user_website'] && !$service) ? '' . $lang['Visit_website'] . '' : ''; $www = ($privmsg['user_website'] && !$service) ? '' . $lang['Visit_website'] . '' : ''; if ( !empty($privmsg['user_icq']) && !$service) { $icq_status_img = ''; $icq_img = '' . $lang['ICQ'] . ''; $icq = '' . $lang['ICQ'] . ''; } else { $icq_status_img = ''; $icq_img = ''; $icq = ''; } if ( !empty($privmsg['user_aim']) && !$service ) { $gg_url = append_sid("gg.$phpEx?mode=gadu&" . POST_USERS_URL . '=' . $user_id_from); if ( $privmsg['user_viewaim'] ) { $gg_url = append_sid("gg.$phpEx?mode=gadu&" . POST_USERS_URL . '=' . $user_id_from); $aim_status_img = '' .$postrow[$i]['user_aim'] . ''; $aim_img = '' . $lang['AIM'] . ''; } else { $aim_status_img = ''; $aim_img = ''; } } else { $aim_status_img = ''; $aim_img = ''; } $temp_url = append_sid("profile.$phpEx?mode=viewprofile&" . POST_USERS_URL . "=$user_id_from"); $msn_img = ($privmsg['user_msnm'] && !$service) ? '' . $lang['MSNM'] . '' : ''; $msn = ($privmsg['user_msnm'] && !$service) ? '' . $lang['MSNM'] . '' : ''; $yim_img = ($privmsg['user_yim'] && !$service) ? '' . $lang['YIM'] . '' : ''; $yim = ($privmsg['user_yim'] && !$service) ? '' . $lang['YIM'] . '' : ''; $temp_url = append_sid("search.$phpEx?search_author=" . urlencode($username_from) . "&showresults=posts"); $search_img = ($service) ? '' : '' . sprintf($lang['Search_user_posts'], $username_from) . ''; $search = ($service) ? '' : '' . sprintf($lang['Search_user_posts'], $username_from) . ''; // Processing of post $post_subject = $privmsg['privmsgs_subject']; $private_message = $privmsg['privmsgs_text']; $bbcode_uid = $privmsg['privmsgs_bbcode_uid']; if ( $board_config['allow_sig'] && $privmsg['user_allowsig'] ) { $user_sig = ( $privmsg['privmsgs_from_userid'] == $userdata['user_id'] ) ? $userdata['user_sig'] : $privmsg['user_sig']; if ( $board_config['allow_sig_image'] ) { $user_sig_image = ($privmsg['privmsgs_from_userid'] == $userdata['user_id']) ? $userdata['user_sig_image'] : $privmsg['user_sig_image']; } } else { $user_sig = ''; $user_sig_image = ''; } $user_sig_bbcode_uid = ($privmsg['privmsgs_from_userid'] == $userdata['user_id']) ? $userdata['user_sig_bbcode_uid'] : $privmsg['user_sig_bbcode_uid']; $user_sig = ($userdata['user_allow_signature']) ? $user_sig : ''; $user_sig_image = ( $userdata['user_allow_sig_image'] ) ? $user_sig_image : ''; // If the board has HTML off but the post has HTML // on then we process it, else leave it alone if ( !$board_config['allow_html'] || !$userdata['user_allowhtml']) { if ( $user_sig != '') { $user_sig = preg_replace('#(<)([/]?.*?)(>)#is', "<\2>", $user_sig); } if ( $privmsg['privmsgs_enable_html'] ) { $private_message = preg_replace('#(<)([/]?.*?)(>)#is', "<\2>", $private_message); } } if ( $user_sig != '' && $privmsg['privmsgs_attach_sig'] && $user_sig_bbcode_uid != '' ) { $user_sig = ($board_config['allow_bbcode']) ? bbencode_second_pass($user_sig, $user_sig_bbcode_uid, $userdata['username']) : preg_replace('/:[0-9a-z:]+]/si', ']', $user_sig); } if ( $bbcode_uid != '' ) { $private_message = ($board_config['allow_bbcode']) ? bbencode_second_pass($private_message, $bbcode_uid, $userdata['username']) : preg_replace('/:[0-9a-z:]+]/si', ']', $private_message); } $private_message = make_clickable($private_message); if ( $privmsg['privmsgs_attach_sig'] && $user_sig != '' ) { $private_message .= '

_________________
' . make_clickable($user_sig); } if ( $privmsg['privmsgs_attach_sig'] && $user_sig_image != '' ) { $private_message .= ( ($user_sig != '' ) ? '
' : '

_________________
' ) . ''; } $orig_word = array(); $replacement_word = array(); $replacement_word_html = array(); obtain_word_list($orig_word, $replacement_word, $replacement_word_html); if ( count($orig_word) ) { $post_subject = preg_replace($orig_word, $replacement_word, $post_subject); $private_message = preg_replace($orig_word, $replacement_word, $private_message); } if ( $board_config['allow_smilies'] && $privmsg['privmsgs_enable_smilies'] && $userdata['show_smiles'] ) { $private_message = smilies_pass($private_message); } $private_message = str_replace(array("n", "r"), array("
", ''), $private_message); // Dump it to the templating engine $template->assign_vars(array( 'MESSAGE_TO' => $username_to, 'MESSAGE_REPLY'=> $username, 'MESSAGE_FROM' => $username_from, 'RANK_IMAGE' => $rank_image, 'POSTER_JOINED' => $poster_joined, 'POSTER_POSTS' => $poster_posts, 'POSTER_FROM' => $poster_from, 'POSTER_AVATAR' => $poster_avatar, 'POST_SUBJECT' => $post_subject, 'POST_DATE' => $post_date, 'MESSAGE' => $private_message, 'PROFILE_IMG' => $profile_img, 'PROFILE' => $profile, 'SEARCH_IMG' => $search_img, 'SEARCH' => $search, 'EMAIL_IMG' => $email_img, 'EMAIL' => $email, 'WWW_IMG' => $www_img, 'WWW' => $www, 'ICQ_STATUS_IMG' => $icq_status_img, 'ICQ_IMG' => $icq_img, 'ICQ' => $icq, 'AIM_IMG' => $aim_img, 'AIM_STATUS_IMG' => $aim_status_img, 'MSN_IMG' => $msn_img, 'MSN' => $msn, 'YIM_IMG' => $yim_img, 'YIM' => $yim) ); $template->pparse('body'); include($phpbb_root_path . 'includes/page_tail.'.$phpEx); } else if ( ( $delete && $mark_list ) || $delete_all ) { if ( !$userdata['session_logged_in'] ) { redirect(append_sid("login.$phpEx?redirect=privmsg.$phpEx&folder=inbox", true)); } if ( isset($mark_list) && !is_array($mark_list) ) { // Set to empty array instead of '0' if nothing is selected. $mark_list = array(); } if ( !$confirm ) { $s_hidden_fields = ''; $s_hidden_fields .= ( isset($HTTP_POST_VARS['delete']) ) ? '' : ''; for($i = 0; $i < count($mark_list); $i++) { $s_hidden_fields .= ''; } // Output confirmation page include($phpbb_root_path . 'includes/page_header.'.$phpEx); $template->set_filenames(array( 'confirm_body' => 'confirm_body.tpl') ); $template->assign_vars(array( 'MESSAGE_TITLE' => $lang['Information'], 'MESSAGE_TEXT' => (count($mark_list) == 1) ? $lang['Confirm_delete_pm'] : $lang['Confirm_delete_pms'], 'L_YES' => $lang['Yes'], 'L_NO' => $lang['No'], 'S_CONFIRM_ACTION' => append_sid("privmsg.$phpEx?folder=$folder"), 'S_HIDDEN_FIELDS' => $s_hidden_fields) ); $template->pparse('confirm_body'); include($phpbb_root_path . 'includes/page_tail.'.$phpEx); } else if ( $confirm ) { $delete_sql_id = $delete_type = ''; if (!$delete_all) { for ($i = 0; $i < count($mark_list); $i++) { $delete_sql_id .= (($delete_sql_id != '') ? ', ' : '') . intval($mark_list[$i]); } $delete_sql_id = "AND privmsgs_id IN ($delete_sql_id)"; } switch($folder) { case 'inbox': $delete_type = "privmsgs_to_userid = " . $userdata['user_id'] . " AND ( privmsgs_type = " . PRIVMSGS_READ_MAIL . " OR privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " )"; break; case 'outbox': $delete_type = "privmsgs_from_userid = " . $userdata['user_id'] . " AND ( privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " )"; break; case 'sentbox': $delete_type = "privmsgs_from_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SENT_MAIL; break; case 'savebox': $delete_type = "( ( privmsgs_from_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_OUT_MAIL . " ) OR ( privmsgs_to_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_IN_MAIL . " ) )"; break; } $sql = "SELECT privmsgs_id FROM " . PRIVMSGS_TABLE . " WHERE $delete_type $delete_sql_id"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain id list to delete messages', '', __LINE__, __FILE__, $sql); } $mark_list = array(); while ( $row = $db->sql_fetchrow($result) ) { $mark_list[] = $row['privmsgs_id']; } unset($delete_type); if ( defined('ATTACHMENTS_ON') ) { $attachment_mod['pm']->delete_all_pm_attachments($mark_list); } if ( count($mark_list) ) { $delete_sql_id = ''; for ($i = 0; $i < sizeof($mark_list); $i++) { $delete_sql_id .= (($delete_sql_id != '') ? ', ' : '') . intval($mark_list[$i]); } if ( $folder == 'inbox' || $folder == 'outbox') { switch ($folder) { case 'inbox': $sql = "privmsgs_to_userid = " . $userdata['user_id']; break; case 'outbox': $sql = "privmsgs_from_userid = " . $userdata['user_id']; break; } // Get information relevant to new or unread mail // so we can adjust users counters appropriately $sql = "SELECT privmsgs_to_userid, privmsgs_type FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_id IN ($delete_sql_id) AND $sql AND privmsgs_type IN (" . PRIVMSGS_NEW_MAIL . ", " . PRIVMSGS_UNREAD_MAIL . ")"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain user id list for outbox messages', '', __LINE__, __FILE__, $sql); } if ( $row = $db->sql_fetchrow($result)) { $type = $dec = ''; $update_users = $update_list = array(); do { switch ($row['privmsgs_type']) { case PRIVMSGS_NEW_MAIL: $update_users['new'][$row['privmsgs_to_userid']]++; break; case PRIVMSGS_UNREAD_MAIL: $update_users['unread'][$row['privmsgs_to_userid']]++; break; } } while ($row = $db->sql_fetchrow($result)); if ( sizeof($update_users) ) { while (list($type, $users) = each($update_users)) { while (list($user_id, $dec) = each($users)) { $update_list[$type][$dec][] = $user_id; } } unset($update_users); while (list($type, $dec_ary) = each($update_list)) { switch ($type) { case 'new': $type = 'user_new_privmsg'; break; case 'unread': $type = 'user_unread_privmsg'; break; } while (list($dec, $user_ary) = each($dec_ary)) { $user_ids = implode(', ', $user_ary); $sql = "UPDATE " . USERS_TABLE . " SET $type = $type - $dec WHERE user_id IN ($user_ids)"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not update user pm counters', '', __LINE__, __FILE__, $sql); } } } unset($update_list); } } $db->sql_freeresult($result); } // Delete the messages $delete_text_sql = "DELETE FROM " . PRIVMSGS_TEXT_TABLE . " WHERE privmsgs_text_id IN ($delete_sql_id)"; $delete_sql = "DELETE FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_id IN ($delete_sql_id) AND "; switch( $folder ) { case 'inbox': $delete_sql .= "privmsgs_to_userid = " . $userdata['user_id'] . " AND ( privmsgs_type = " . PRIVMSGS_READ_MAIL . " OR privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " )"; break; case 'outbox': $delete_sql .= "privmsgs_from_userid = " . $userdata['user_id'] . " AND ( privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " )"; break; case 'sentbox': $delete_sql .= "privmsgs_from_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SENT_MAIL; break; case 'savebox': $delete_sql .= "( ( privmsgs_from_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_OUT_MAIL . " ) OR ( privmsgs_to_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_IN_MAIL . " ) )"; break; } if ( !$db->sql_query($delete_sql, BEGIN_TRANSACTION) ) { message_die(GENERAL_ERROR, 'Could not delete private message info', '', __LINE__, __FILE__, $delete_sql); } if ( !$db->sql_query($delete_text_sql, END_TRANSACTION) ) { message_die(GENERAL_ERROR, 'Could not delete private message text', '', __LINE__, __FILE__, $delete_text_sql); } } } } else if ( $save && $mark_list && $folder != 'savebox' && $folder != 'outbox' ) { if ( !$userdata['session_logged_in'] ) { redirect(append_sid("login.$phpEx?redirect=privmsg.$phpEx&folder=inbox", true)); } if ( sizeof($mark_list) ) { // See if recipient is at their savebox limit $sql = "SELECT COUNT(privmsgs_id) AS savebox_items, MIN(privmsgs_date) AS oldest_post_time FROM " . PRIVMSGS_TABLE . " WHERE ( ( privmsgs_to_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_IN_MAIL . " ) OR ( privmsgs_from_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_OUT_MAIL . ") )"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain sent message info for sendee', '', __LINE__, __FILE__, $sql); } $sql_priority = ( SQL_LAYER == 'mysql' ) ? 'LOW_PRIORITY' : ''; if ( $saved_info = $db->sql_fetchrow($result) ) { if ( $userdata['user_level'] == ADMIN ) { $max_savebox_privmsgs = $board_config['max_savebox_privmsgs'] * 6; } else if ( $userdata['user_level'] == MOD ) { $max_savebox_privmsgs = $board_config['max_savebox_privmsgs'] * 3; } else { $max_savebox_privmsgs = $board_config['max_savebox_privmsgs']; } if ( $board_config['max_savebox_privmsgs'] && $saved_info['savebox_items'] >= $max_savebox_privmsgs ) { $sql = "SELECT privmsgs_id FROM " . PRIVMSGS_TABLE . " WHERE ( ( privmsgs_to_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_IN_MAIL . " ) OR ( privmsgs_from_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SAVED_OUT_MAIL . ") ) AND privmsgs_date = " . $saved_info['oldest_post_time']; if ( !$result = $db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not find oldest privmsgs (save)', '', __LINE__, __FILE__, $sql); } $old_privmsgs_id = $db->sql_fetchrow($result); $old_privmsgs_id = $old_privmsgs_id['privmsgs_id']; $sql = "DELETE $sql_priority FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_id = $old_privmsgs_id"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not delete oldest privmsgs (save)', '', __LINE__, __FILE__, $sql); } $sql = "DELETE $sql_priority FROM " . PRIVMSGS_TEXT_TABLE . " WHERE privmsgs_text_id = $old_privmsgs_id"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not delete oldest privmsgs text (save)', '', __LINE__, __FILE__, $sql); } } } $saved_sql_id = ''; for ($i = 0; $i < sizeof($mark_list); $i++) { $saved_sql_id .= (($saved_sql_id != '') ? ', ' : '') . intval($mark_list[$i]); } // Process request $saved_sql = "UPDATE " . PRIVMSGS_TABLE; // Decrement read/new counters if appropriate if ( $folder == 'inbox' || $folder == 'outbox' ) { switch ($folder) { case 'inbox': $sql = "privmsgs_to_userid = " . $userdata['user_id']; break; case 'outbox': $sql = "privmsgs_from_userid = " . $userdata['user_id']; break; } // Get information relevant to new or unread mail // so we can adjust users counters appropriately $sql = "SELECT privmsgs_to_userid, privmsgs_type FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_id IN ($saved_sql_id) AND $sql AND privmsgs_type IN (" . PRIVMSGS_NEW_MAIL . ", " . PRIVMSGS_UNREAD_MAIL . ")"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain user id list for outbox messages', '', __LINE__, __FILE__, $sql); } if ( $row = $db->sql_fetchrow($result) ) { $type = $dec = ''; $update_users = $update_list = array(); do { switch ($row['privmsgs_type']) { case PRIVMSGS_NEW_MAIL: $update_users['new'][$row['privmsgs_to_userid']]++; break; case PRIVMSGS_UNREAD_MAIL: $update_users['unread'][$row['privmsgs_to_userid']]++; break; } } while ($row = $db->sql_fetchrow($result)); if ( sizeof($update_users) ) { while (list($type, $users) = each($update_users)) { while (list($user_id, $dec) = each($users)) { $update_list[$type][$dec][] = $user_id; } } unset($update_users); while (list($type, $dec_ary) = each($update_list)) { switch ($type) { case 'new': $type = "user_new_privmsg"; break; case 'unread': $type = "user_unread_privmsg"; break; } while (list($dec, $user_ary) = each($dec_ary)) { $user_ids = implode(', ', $user_ary); $sql = "UPDATE " . USERS_TABLE . " SET $type = $type - $dec WHERE user_id IN ($user_ids)"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not update user pm counters', '', __LINE__, __FILE__, $sql); } } } unset($update_list); } } $db->sql_freeresult($result); } switch ($folder) { case 'inbox': $saved_sql .= " SET privmsgs_type = " . PRIVMSGS_SAVED_IN_MAIL . " WHERE privmsgs_to_userid = " . $userdata['user_id'] . " AND ( privmsgs_type = " . PRIVMSGS_READ_MAIL . " OR privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . ")"; break; case 'outbox': $saved_sql .= " SET privmsgs_type = " . PRIVMSGS_SAVED_OUT_MAIL . " WHERE privmsgs_from_userid = " . $userdata['user_id'] . " AND ( privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " ) "; break; case 'sentbox': $saved_sql .= " SET privmsgs_type = " . PRIVMSGS_SAVED_OUT_MAIL . " WHERE privmsgs_from_userid = " . $userdata['user_id'] . " AND privmsgs_type = " . PRIVMSGS_SENT_MAIL; break; } $saved_sql .= " AND privmsgs_id IN ($saved_sql_id)"; if ( !$db->sql_query($saved_sql) ) { message_die(GENERAL_ERROR, 'Could not save private messages', '', __LINE__, __FILE__, $saved_sql); } redirect(append_sid("privmsg.$phpEx?folder=savebox", true)); } } else if ( $submit || $refresh || $mode != '' ) { if ( !$userdata['session_logged_in'] ) { $user_id = ( isset($HTTP_GET_VARS[POST_USERS_URL]) ) ? '&' . POST_USERS_URL . '=' . intval($HTTP_GET_VARS[POST_USERS_URL]) : ''; redirect(append_sid("login.$phpEx?redirect=privmsg.$phpEx&folder=$folder&mode=$mode" . $user_id, true)); } // Toggles if ( !$board_config['allow_html'] ) { $html_on = 0; } else { $html_on = ( $submit || $refresh ) ? ( ( !empty($HTTP_POST_VARS['disable_html']) ) ? 0 : TRUE ) : $userdata['user_allowhtml']; } if ( !$user_can_use_bbcode ) { $bbcode_on = 0; } else { $bbcode_on = ( $submit || $refresh ) ? ( ( !empty($HTTP_POST_VARS['disable_bbcode']) ) ? 0 : TRUE ) : $userdata['user_allowbbcode']; } if ( !$board_config['allow_smilies'] ) { $smilies_on = 0; } else { $smilies_on = ( $submit || $refresh ) ? ( ( !empty($HTTP_POST_VARS['disable_smilies']) ) ? 0 : TRUE ) : $userdata['user_allowsmile']; } $attach_sig = ($submit || $refresh) ? ( ( !empty($HTTP_POST_VARS['attach_sig']) ) ? TRUE : 0 ) : $userdata['user_attachsig']; $user_sig = ($userdata['user_sig'] != '' && $board_config['allow_sig']) ? $userdata['user_sig'] : ''; if ( $submit && $mode != 'edit' ) { // Flood control $sql = "SELECT MAX(privmsgs_date) AS last_post_time FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_from_userid = " . $userdata['user_id']; if ( $result = $db->sql_query($sql) ) { $db_row = $db->sql_fetchrow($result); $last_post_time = $db_row['last_post_time']; if ( (( CR_TIME - $last_post_time ) < $board_config['flood_interval']) && $userdata['user_level'] == USER && !$userdata['user_jr'] ) { message_die(GENERAL_MESSAGE, $lang['Flood_Error']); } } // End Flood control } if ($submit && $mode == 'edit') { $sql = 'SELECT privmsgs_from_userid FROM ' . PRIVMSGS_TABLE . ' WHERE privmsgs_id = ' . (int) $privmsg_id . ' AND privmsgs_from_userid = ' . $userdata['user_id']; if (!($result = $db->sql_query($sql))) { message_die(GENERAL_ERROR, "Could not obtain message details", "", __LINE__, __FILE__, $sql); } if (!($row = $db->sql_fetchrow($result))) { message_die(GENERAL_MESSAGE, $lang['No_such_post']); } $db->sql_freeresult($result); unset($row); } if ( $submit ) { if ( !empty($HTTP_POST_VARS['username']) ) { $to_username = phpbb_clean_username($HTTP_POST_VARS['username']); $sql = "SELECT user_id, user_level, user_notify_pm, user_email, user_lang, user_active, user_aim, user_notify_gg FROM " . USERS_TABLE . " WHERE username = '" . str_replace("'", "''", $to_username) . "' AND user_id <> " . ANONYMOUS; if ( !($result = $db->sql_query($sql)) ) { $error = TRUE; $error_msg = $lang['No_user_id_specified']; } if (!($to_userdata = $db->sql_fetchrow($result))) { $error = TRUE; $error_msg = $lang['No_user_id_specified']; } } else { $error = TRUE; $error_msg .= ( ( !empty($error_msg) ) ? '
' : '' ) . $lang['No_to_user']; } $privmsg_subject = trim(strip_tags($HTTP_POST_VARS['subject'])); if ( empty($privmsg_subject) ) { $error = TRUE; $error_msg .= ( ( !empty($error_msg) ) ? '
' : '' ) . $lang['Empty_subject']; } if ( !empty($HTTP_POST_VARS['message']) ) { if ( !$error ) { if ( $bbcode_on ) { $bbcode_uid = make_bbcode_uid(); } $privmsg_message = prepare_message($HTTP_POST_VARS['message'], $html_on, $bbcode_on, $smilies_on, $bbcode_uid); } } else { $error = TRUE; $error_msg .= ( ( !empty($error_msg) ) ? '
' : '' ) . $lang['Empty_message']; } } if ( $submit && !$error ) { // Has admin prevented user from sending PM's? if ( !$userdata['user_allow_pm'] ) { message_die(GENERAL_MESSAGE, $lang['Cannot_send_privmsg']); } $msg_time = CR_TIME; if ( $sid == '' || $sid != $userdata['session_id'] ) { message_die(GENERAL_ERROR, 'Invalid_session'); } if ( $mode != 'edit' ) { check_enable_pm($to_userdata['user_id']); // See if recipient is at their inbox limit $sql = "SELECT COUNT(privmsgs_id) AS inbox_items, MIN(privmsgs_date) AS oldest_post_time FROM " . PRIVMSGS_TABLE . " WHERE ( privmsgs_type = " . PRIVMSGS_NEW_MAIL . " OR privmsgs_type = " . PRIVMSGS_READ_MAIL . " OR privmsgs_type = " . PRIVMSGS_UNREAD_MAIL . " ) AND privmsgs_to_userid = " . $to_userdata['user_id']; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_MESSAGE, $lang['No_user_id_specified']); } $sql_priority = ( SQL_LAYER == 'mysql' ) ? 'LOW_PRIORITY' : ''; if ( $inbox_info = $db->sql_fetchrow($result) ) { if ( $to_userdata['user_level'] == ADMIN ) { $max_inbox_privmsgs = $board_config['max_inbox_privmsgs'] * 6; } else if ( $to_userdata['user_level'] == MOD ) { $max_inbox_privmsgs = $board_config['max_inbox_privmsgs'] * 3; } else { $max_inbox_privmsgs = $board_config['max_inbox_privmsgs']; } if ( $board_config['max_inbox_privmsgs'] && $inbox_info['inbox_items'] >= $max_inbox_privmsgs ) { $sql = "SELECT privmsgs_id FROM " . PRIVMSGS_TABLE . " WHERE ( privmsgs_type = '" . PRIVMSGS_NEW_MAIL . "' OR privmsgs_type = '" . PRIVMSGS_READ_MAIL . "' OR privmsgs_type = '" . PRIVMSGS_UNREAD_MAIL . "' ) AND privmsgs_date = '" . $inbox_info['oldest_post_time'] . "' AND privmsgs_to_userid = " . $to_userdata['user_id']; if ( !$result = $db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not find oldest privmsgs (inbox)', '', __LINE__, __FILE__, $sql); } $old_privmsgs_id = $db->sql_fetchrow($result); $old_privmsgs_id = $old_privmsgs_id['privmsgs_id']; $sql = "DELETE $sql_priority FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_id = '$old_privmsgs_id'"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not delete oldest privmsgs (inbox)'.$sql, '', __LINE__, __FILE__, $sql); } $sql = "DELETE $sql_priority FROM " . PRIVMSGS_TEXT_TABLE . " WHERE privmsgs_text_id = '$old_privmsgs_id'"; if ( !$db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not delete oldest privmsgs text (inbox)', '', __LINE__, __FILE__, $sql); } } } $sql_info = "INSERT INTO " . PRIVMSGS_TABLE . " (privmsgs_type, privmsgs_subject, privmsgs_from_userid, privmsgs_to_userid, privmsgs_date, privmsgs_ip, privmsgs_enable_html, privmsgs_enable_bbcode, privmsgs_enable_smilies, privmsgs_attach_sig) VALUES (" . PRIVMSGS_NEW_MAIL . ", '" . str_replace("'", "''", $privmsg_subject) . "', " . $userdata['user_id'] . ", " . $to_userdata['user_id'] . ", $msg_time, '$user_ip', $html_on, $bbcode_on, $smilies_on, $attach_sig)"; } else { $sql_info = "UPDATE " . PRIVMSGS_TABLE . " SET privmsgs_type = " . PRIVMSGS_NEW_MAIL . ", privmsgs_subject = '" . str_replace("'", "''", $privmsg_subject) . "', privmsgs_from_userid = " . $userdata['user_id'] . ", privmsgs_to_userid = " . $to_userdata['user_id'] . ", privmsgs_date = $msg_time, privmsgs_ip = '$user_ip', privmsgs_enable_html = $html_on, privmsgs_enable_bbcode = $bbcode_on, privmsgs_enable_smilies = $smilies_on, privmsgs_attach_sig = $attach_sig WHERE privmsgs_id = $privmsg_id"; } if ( !($result = $db->sql_query($sql_info, BEGIN_TRANSACTION)) ) { message_die(GENERAL_ERROR, "Could not insert/update private message sent info.", "", __LINE__, __FILE__, $sql_info); } if ( $mode != 'edit' ) { $privmsg_sent_id = $db->sql_nextid(); $sql = "INSERT INTO " . PRIVMSGS_TEXT_TABLE . " (privmsgs_text_id, privmsgs_bbcode_uid, privmsgs_text) VALUES ($privmsg_sent_id, '" . $bbcode_uid . "', '" . str_replace("'", "''", $privmsg_message) . "')"; } else { $sql = "UPDATE " . PRIVMSGS_TEXT_TABLE . " SET privmsgs_text = '" . str_replace("'", "''", $privmsg_message) . "', privmsgs_bbcode_uid = '$bbcode_uid' WHERE privmsgs_text_id = $privmsg_id"; } if ( !$db->sql_query($sql, END_TRANSACTION) ) { message_die(GENERAL_ERROR, "Could not insert/update private message sent text.", "", __LINE__, __FILE__, $sql); } if ( defined('ATTACHMENTS_ON') ) { $attachment_mod['pm']->insert_attachment_pm($privmsg_id); } if ( $mode != 'edit' ) { // Add to the users new pm counter $sql = "UPDATE " . USERS_TABLE . " SET user_new_privmsg = user_new_privmsg + 1, user_last_privmsg = " . CR_TIME . " WHERE user_id = " . $to_userdata['user_id']; if ( !$status = $db->sql_query($sql) ) { message_die(GENERAL_ERROR, 'Could not update private message new/read status for user', '', __LINE__, __FILE__, $sql); } $script_name = preg_replace('/^/?(.*?)/?$/', "\1", trim($board_config['script_path'])); $script_name = ( $script_name != '' ) ? $script_name . '/privmsg.'.$phpEx : 'privmsg.'.$phpEx; $server_name = trim($board_config['server_name']); $server_protocol = ( $board_config['cookie_secure'] ) ? 'https://' : 'http://'; $server_port = ( $board_config['server_port'] <> 80 ) ? ':' . trim($board_config['server_port']) . '/' : '/'; if ( $to_userdata['user_notify_gg'] && !empty($to_userdata['user_aim']) && !empty($board_config['numer_gg']) && !empty($board_config['haslo_gg'])) { $tresc = """ . $board_config['sitename'] . ""rn" . sprintf($lang['gg_header_info_pm'], $userdata['username']) . "rnrn"; $tresc2 = sprintf($lang['l_notify_gg_privmsg'], $server_protocol . $server_name . $server_port . $script_name . '?folder=inbox'); $tresc = $tresc.$tresc2; require_once('includes/functions_gg_notice.'.$phpEx); wiadomosc_gg( intval(trim($to_userdata['user_aim'])), $tresc, intval(trim($board_config['numer_gg'])), $board_config['haslo_gg']); $gg_send = true; } if ( $to_userdata['user_notify_pm'] && !empty($to_userdata['user_email']) && $to_userdata['user_active'] && !$gg_send ) { include($phpbb_root_path . 'includes/emailer.'.$phpEx); $emailer = new emailer($board_config['smtp_delivery']); $emailer->from($board_config['email_from']); $emailer->replyto($board_config['email_return_path']); $emailer->use_template('privmsg_notify', $to_userdata['user_lang']); $emailer->email_address($to_userdata['user_email']); $emailer->set_subject($lang['Notification_subject']); $emailer->assign_vars(array( 'USERNAME' => stripslashes($to_username), 'POSTER_USERNAME' => stripslashes($userdata['username']), 'SITENAME' => $board_config['sitename'], 'EMAIL_SIG' => (!empty($board_config['board_email_sig'])) ? str_replace('
', "n", "-- n" . $board_config['board_email_sig']) : '', 'U_INBOX' => $server_protocol . $server_name . $server_port . $script_name . '?folder=inbox') ); $emailer->send(); $emailer->reset(); } } $template->assign_vars(array( 'META' => '') ); $msg = $lang['Message_sent'] . '

' . sprintf($lang['Click_return_inbox'], '', ' ') . '

' . sprintf($lang['Click_return_index'], '', ''); message_die(GENERAL_MESSAGE, $msg); } else if ( $preview || $refresh || $error ) { // If we're previewing or refreshing then obtain the data // passed to the script, process it a little, do some checks // where neccessary, etc. $to_username = (isset($HTTP_POST_VARS['username'])) ? trim(strip_tags(stripslashes($HTTP_POST_VARS['username']))) : ''; $privmsg_subject = (isset($HTTP_POST_VARS['subject'])) ? trim(strip_tags(stripslashes($HTTP_POST_VARS['subject']))) : ''; $privmsg_message = (isset($HTTP_POST_VARS['message'])) ? trim($HTTP_POST_VARS['message']) : ''; $privmsg_message = preg_replace('##si', '</textarea>', $privmsg_message); $user_sig = ( $board_config['allow_sig'] ) ? (($privmsg['privmsgs_type'] == PRIVMSGS_NEW_MAIL) ? $user_sig : $privmsg['user_sig']) : ''; $user_sig_image = ($board_config['allow_sig'] && $board_config['allow_sig_image']) ? $privmsg['user_sig_image'] : ''; $to_username = $privmsg['username']; $to_userid = $privmsg['user_id']; } else if ( $mode == 'reply' || $mode == 'quote' ) { $sql = "SELECT privmsgs_from_userid FROM " . PRIVMSGS_TABLE . " WHERE privmsgs_id = " . $privmsg_id; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain private message data', '', __LINE__, __FILE__, $sql); } $row = $db->sql_fetchrow($result); check_enable_pm($row['privmsgs_from_userid']); $sql = "SELECT pm.privmsgs_subject, pm.privmsgs_date, pmt.privmsgs_bbcode_uid, pmt.privmsgs_text, u.username, u.user_id FROM (" . PRIVMSGS_TABLE . " pm, " . PRIVMSGS_TEXT_TABLE . " pmt, " . USERS_TABLE . " u) WHERE pm.privmsgs_id = $privmsg_id AND pmt.privmsgs_text_id = pm.privmsgs_id AND pm.privmsgs_to_userid = " . $userdata['user_id'] . " AND u.user_id = pm.privmsgs_from_userid"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain private message for editing', '', __LINE__, __FILE__, $sql); } if ( !($privmsg = $db->sql_fetchrow($result)) ) { redirect(append_sid("privmsg.$phpEx?folder=$folder", true)); } $privmsg_subject = ( ( !preg_match('/^Re:/', $privmsg['privmsgs_subject']) ) ? 'Re: ' : '' ) . $privmsg['privmsgs_subject']; $to_username = $privmsg['username']; $to_userid = $privmsg['user_id']; if ( $mode == 'quote' ) { $privmsg_message = $privmsg['privmsgs_text']; $privmsg_bbcode_uid = $privmsg['privmsgs_bbcode_uid']; $privmsg_message = preg_replace("/:(([a-z0-9]:)?)$privmsg_bbcode_uid/si", '', $privmsg_message); $privmsg_message = str_replace('
', "n", $privmsg_message); $privmsg_message = preg_replace('##si', '</textarea>', $privmsg_message); $msg_date = create_date($board_config['default_dateformat'], $privmsg['privmsgs_date'], $board_config['board_timezone']); $privmsg_message = '[quote="' . $to_username . '"]' . $privmsg_message . '[/quote]'; $mode = 'reply'; } } else { $privmsg_subject = $privmsg_message = $to_username = ''; } } // Has admin prevented user from sending PM's? if ( !$userdata['user_allow_pm'] && $mode != 'edit' ) { $message = $lang['Cannot_send_privmsg']; message_die(GENERAL_MESSAGE, $message); } // Start output, first preview, then errors then post form $page_title = $lang['Send_private_message']; include($phpbb_root_path . 'includes/page_header.'.$phpEx); if ( $preview && !$error ) { $orig_word = array(); $replacement_word = array(); $replacement_word_html = array(); obtain_word_list($orig_word, $replacement_word, $replacement_word_html); if ( $bbcode_on ) { $bbcode_uid = make_bbcode_uid(); } $preview_message = stripslashes(prepare_message($privmsg_message, $html_on, $bbcode_on, $smilies_on, $bbcode_uid)); $privmsg_message = stripslashes(preg_replace($html_entities_match, $html_entities_replace, $privmsg_message)); $user_sig = ($userdata['user_allow_signature']) ? $user_sig : ''; $user_sig_image = ($userdata['user_allow_sig_image']) ? $user_sig_image : ''; // Finalise processing as per viewtopic if ( !$html_on || !$board_config['allow_html'] || !$userdata['user_allowhtml'] ) { if ( $user_sig != '' ) { $user_sig = preg_replace('#(<)([/]?.*?)(>)#is', "<\2>", $user_sig); } } if ( $attach_sig && $user_sig != '' && $userdata['user_sig_bbcode_uid'] ) { $user_sig = bbencode_second_pass($user_sig, $userdata['user_sig_bbcode_uid'], $userdata['username']); } if ( $bbcode_on ) { $preview_message = bbencode_second_pass($preview_message, $bbcode_uid, $userdata['username']); } if ( $attach_sig && $user_sig != '' ) { $preview_message = $preview_message . '

_________________
' . $user_sig; } if ( $attach_sig && $user_sig_image != '' ) { $preview_message .= ( ($user_sig != '') ? '
' : '

_________________
' ) . ''; } if ( count($orig_word) ) { $preview_subject = preg_replace($orig_word, $replacement_word, $privmsg_subject); $preview_message = preg_replace($orig_word, $re