'emails/antispam/submit' => $this->make_hook('submit', AUTH_COOKIE),
'emails/test' => $this->make_hook('test', AUTH_COOKIE, 'user', NO_AUTH),
+ 'emails/imap/in' => $this->make_hook('imap_in', AUTH_PUBLIC),
+
'admin/emails/duplicated' => $this->make_hook('duplicated', AUTH_MDP, 'admin'),
'admin/emails/watch' => $this->make_hook('duplicated', AUTH_MDP, 'admin'),
'admin/emails/lost' => $this->make_hook('lost', AUTH_MDP, 'admin'),
function handler_emails(&$page, $action = null, $email = null)
{
global $globals;
+ require_once 'emails.inc.php';
$page->changeTpl('emails/index.tpl');
$page->assign('xorg_title','Polytechnique.org - Mes emails');
$uid = S::v('uid');
if ($action == 'best' && $email) {
+ if (!S::has_xsrf_token()) {
+ return PL_FORBIDDEN;
+ }
+
// bestalias is the first bit : 1
// there will be maximum 8 bits in flags : 255
XDB::execute("UPDATE aliases SET flags=flags & (255 - 1) WHERE id={?}", $uid);
ORDER BY LENGTH(alias)";
$page->assign('aliases', XDB::iterator($sql, $uid));
- $homonyme = XDB::query("SELECT alias FROM aliases INNER JOIN homonymes ON (id = homonyme_id) WHERE user_id = {?} AND type = 'homonyme'", $uid);
- $page->assign('homonyme', $homonyme->fetchOneCell());
+ $homonyme = XDB::query("SELECT alias FROM aliases INNER JOIN homonymes ON (id = homonyme_id) WHERE user_id = {?} AND type = 'homonyme'", $uid);
+ $page->assign('homonyme', $homonyme->fetchOneCell());
// Affichage des redirections de l'utilisateur.
- $sql = "SELECT email
- FROM emails
- WHERE uid = {?} AND FIND_IN_SET('active', flags)";
- $page->assign('mails', XDB::iterator($sql, $uid));
-
- // Affichage des backends actifs de stockage des emails.
- $sql = "SELECT mail_storage
- FROM auth_user_md5
- WHERE user_id = {?}";
- $storages = XDB::query($sql, $uid)->fetchOneCell();
- $page->assign('storage', explode(',', $storages));
+ $redirect = new Redirect($uid);
+ $page->assign('mails', $redirect->active_emails());
// on regarde si l'utilisateur a un alias et si oui on l'affiche !
$forlife = S::v('forlife');
$page->assign('demande', AliasReq::get_request($uid));
if ($action == 'delete' && $value) {
+ S::assert_xsrf_token();
+
//Suppression d'un alias
XDB::execute(
'DELETE virtual, virtual_redirect
list($alias, $visibility) = $res->fetchOneRow();
$page->assign('actuel', $alias);
- if ($action == 'ask' && Env::has('alias') and Env::has('raison')) {
- //Si l'utilisateur vient de faire une damande
+ if ($action == 'ask' && Env::has('alias') && Env::has('raison')) {
+ S::assert_xsrf_token();
+ //Si l'utilisateur vient de faire une damande
$alias = Env::v('alias');
$raison = Env::v('raison');
$public = (Env::v('public', 'off') == 'on')?"public":"private";
$page->assign('success',$alias);
return;
}
- }
- elseif ($action == 'set'
- && ($value == 'public' || $value == 'private'))
- {
+ } elseif ($action == 'set' && ($value == 'public' || $value == 'private')) {
+ if (!S::has_xsrf_token()) {
+ return PL_FORBIDDEN;
+ }
+
if ($value == 'public') {
XDB::execute("UPDATE auth_user_quick SET emails_alias_pub = 'public'
WHERE user_id = {?}", S::v('uid'));
$redirect->modify_one_email_redirect($email, $rewrite);
}
- if ($action == 'storage') {
- if ($email == 'imap') {
- $storage = new MailStorageIMAP(S::v('uid'));
- } else if ($email == 'googleapps') {
- $storage = new MailStorageGoogleApps(S::v('uid'));
- } else {
- $storage = NULL;
- }
-
- if ($storage) {
- $subaction = @func_get_arg(3);
- if ($subaction == 'active') {
- $storage->enable();
- }
- if ($subaction == 'inactive') {
- $storage->disable();
- }
- }
- }
-
if (Env::has('emailop')) {
+ S::assert_xsrf_token();
+
$actifs = Env::v('emails_actifs', Array());
print_r(Env::v('emails_rewrite'));
if (Env::v('emailop') == "ajouter" && Env::has('email')) {
$page->assign('alias', $res->fetchAllAssoc());
$page->assign('emails',$redirect->emails);
- $res = XDB::query(
- "SELECT mail_storage
- FROM auth_user_md5
- WHERE user_id = {?}", $uid);
- $page->assign('storage', explode(',', $res->fetchOneCell()));
-
require_once 'googleapps.inc.php';
$page->assign('googleapps', GoogleAppsAccount::account_status($uid));
}
$page->changeTpl('emails/submit_spam.tpl');
if (Post::has('send_email')) {
+ S::assert_xsrf_token();
+
$upload = PlUpload::get($_FILES['mail'], S::v('forlife'), 'spam.submit', true);
if (!$upload) {
$page->trig('Une erreur a été rencontrée lors du transfert du fichier');
// action si on recoit un formulaire
if (Post::has('save')) {
+ if (!S::has_xsrf_token()) {
+ return PL_FORBIDDEN;
+ }
+
unset($_POST['save']);
if (trim(preg_replace('/-- .*/', '', Post::v('contenu'))) != "") {
$_POST['to_contacts'] = explode(';', @$_POST['to_contacts']);
}
exit;
} else if (Env::v('submit') == 'Envoyer') {
+ S::assert_xsrf_token();
+
function getEmails($aliases)
{
if (!is_array($aliases)) {
function handler_test(&$page, $forlife = null)
{
global $globals;
+ require_once 'emails.inc.php';
+
+ if (!S::has_xsrf_token()) {
+ return PL_FORBIDDEN;
+ }
if (!S::has_perms() || !$forlife) {
$forlife = S::v('bestalias');
}
- $mailer = new PlMailer('emails/test.mail.tpl');
- $mailer->assign('email', $forlife . '@' . $globals->mail->domain);
- $iterator = XDB::iterator("SELECT email
- FROM emails AS e
- INNER JOIN aliases AS a ON (e.uid = a.id)
- WHERE FIND_IN_SET('active', e.flags) AND a.alias = {?}",
- $forlife);
- $mailer->assign('redirects', $iterator);
- $res = XDB::query("SELECT FIND_IN_SET('femme', u.flags), prenom
+
+ $res = XDB::query("SELECT FIND_IN_SET('femme', u.flags), prenom, user_id
FROM auth_user_md5 AS u
INNER JOIN aliases AS a ON (a.id = u.user_id)
WHERE a.alias = {?}", $forlife);
- list($sexe, $prenom) = $res->fetchOneRow();
+ list($sexe, $prenom, $uid) = $res->fetchOneRow();
+ $redirect = new Redirect($uid);
+
+ $mailer = new PlMailer('emails/test.mail.tpl');
+ $mailer->assign('email', $forlife . '@' . $globals->mail->domain);
+ $mailer->assign('redirects', $redirect->active_emails());
$mailer->assign('sexe', $sexe);
$mailer->assign('prenom', $prenom);
$mailer->send();
exit;
}
+ function handler_imap_in(&$page, $hash = null, $login = null)
+ {
+ $page->changeTpl('emails/imap_register.tpl');
+ $id = null;
+ if (!empty($hash) || !empty($login)) {
+ $req = XDB::query("SELECT u.prenom, FIND_IN_SET('femme', u.flags) AS sexe, a.id
+ FROM aliases AS a
+ INNER JOIN newsletter_ins AS ni ON (a.id = ni.user_id)
+ INNER JOIN auth_user_md5 AS u ON (u.user_id = a.id)
+ WHERE a.alias = {?} AND ni.hash = {?}", $login, $hash);
+ list($prenom, $sexe, $id) = $req->fetchOneRow();
+ }
+
+ require_once('emails.inc.php');
+ $page->assign('ok', false);
+ if (S::logged() && (is_null($id) || $id == S::i('uid'))) {
+ $storage = new EmailStorage(S::i('uid'), 'imap');
+ $storage->activate();
+ $page->assign('ok', true);
+ $page->assign('prenom', S::v('prenom'));
+ $page->assign('sexe', S::v('femme'));
+ } else if (!S::logged() && $id) {
+ $storage = new EmailStorage($id, 'imap');
+ $storage->activate();
+ $page->assign('ok', true);
+ $page->assign('prenom', $prenom);
+ $page->assign('sexe', $sexe);
+ }
+ }
+
function handler_broken(&$page, $warn = null, $email = null)
{
require_once 'emails.inc.php';
$page->changeTpl('emails/broken.tpl');
if ($warn == 'warn' && $email) {
+ S::assert_xsrf_token();
+
$email = valide_email($email);
// vérifications d'usage
$sel = XDB::query(
"SELECT e.uid, a.alias
FROM emails AS e
- INNER JOIN auth_user_md5 AS u ON e.uid = u.user_id
INNER JOIN aliases AS a ON (e.uid = a.id AND type!='homonyme'
AND FIND_IN_SET('bestalias',a.flags))
WHERE e.email={?}", $email);
à jour sur le site <{$globals->baseurl}/emails> tes adresses
de redirection...
-Pour plus de rensignements sur le service de patte cassée, n'hésites pas à
+Pour plus de renseignements sur le service de patte cassée, n'hésite pas à
consulter la page <{$globals->baseurl}/emails/broken>.
-A bientôt sur Polytechnique.org !
+À bientôt sur Polytechnique.org !
L'équipe d'administration <support@" . $globals->mail->domain . '>';
$mail = new PlMailer();
$page->trig("Mail envoyé ! :o)");
}
} elseif (Post::has('email')) {
+ S::assert_xsrf_token();
+
$email = valide_email(Post::v('email'));
list(,$fqdn) = explode('@', $email);
$fqdn = strtolower($fqdn);
- if ($fqdn == 'polytechnique.org' || $fqdn == 'melix.org'
- || $fqdn == 'm4x.org' || $fqdn == 'melix.net')
- {
+ if ($fqdn == 'polytechnique.org' || $fqdn == 'melix.org' || $fqdn == 'm4x.org' || $fqdn == 'melix.net') {
$page->assign('neuneu', true);
} else {
$page->assign('email',$email);
$sel = XDB::query(
- "SELECT e1.uid, e1.panne != 0 AS panne, count(e2.uid) AS nb_mails,
+ "SELECT e1.uid, e1.panne != 0 AS panne,
+ (count(e2.uid) + IF(FIND_IN_SET('googleapps', u.mail_storage), 1, 0)) AS nb_mails,
u.nom, u.prenom, u.promo, a.alias AS forlife
FROM emails as e1
LEFT JOIN emails as e2 ON(e1.uid = e2.uid
'dangerous' => 'Usurpations par cette adresse');
$page->assign('states', $states);
+ if (Post::has('action')) {
+ S::assert_xsrf_token();
+ }
switch (Post::v('action')) {
- case 'create':
+ case 'create':
if (trim(Post::v('emailN')) != '') {
Xdb::execute('INSERT IGNORE INTO emails_watch (email, state, detection, last, uid, description)
VALUES ({?}, {?}, CURDATE(), NOW(), {?}, {?})',
};
break;
- case 'edit':
+ case 'edit':
Xdb::execute('UPDATE emails_watch
SET state = {?}, last = NOW(), uid = {?}, description = {?}
WHERE email = {?}', Post::v('stateN'), S::i('uid'), Post::v('descriptionN'), Post::v('emailN'));
break;
- default:
+ default:
if ($action == 'delete' && !is_null($email)) {
Xdb::execute('DELETE FROM emails_watch WHERE email = {?}', $email);
}
$page->changeTpl('emails/lost.tpl');
$page->assign('lost_emails', XDB::iterator('
- SELECT u.user_id, a.alias
- FROM auth_user_md5 AS u
- INNER JOIN aliases AS a ON (a.id = u.user_id AND a.type = "a_vie")
- LEFT JOIN emails AS e ON (u.user_id=e.uid AND FIND_IN_SET("active",e.flags))
- WHERE e.uid IS NULL AND u.deces = 0
- ORDER BY u.promo DESC, u.nom, u.prenom'));
+ SELECT u.user_id, a.alias
+ FROM auth_user_md5 AS u
+ INNER JOIN aliases AS a ON (a.id = u.user_id AND a.type = "a_vie")
+ LEFT JOIN emails AS e ON (u.user_id=e.uid AND FIND_IN_SET("active",e.flags))
+ WHERE e.uid IS NULL AND
+ FIND_IN_SET("googleapps", u.mail_storage) = 0 AND
+ u.deces = 0
+ ORDER BY u.promo DESC, u.nom, u.prenom'));
}
}