X-Git-Url: http://git.polytechnique.org/?a=blobdiff_plain;f=modules%2Fxnetgrp.php;h=37c93d29ac1cf4c2c7d6b42c84b3e16bb84d33cb;hb=5d42c993d85a2f1fa3595eb1591a921c0f89d8cd;hp=794fdc7e60b1828d0d46bec6f6e221b2ad12468e;hpb=91288d86e195bc79e894c39ccf4d6560f707a0e7;p=platal.git diff --git a/modules/xnetgrp.php b/modules/xnetgrp.php index 794fdc7..37c93d2 100644 --- a/modules/xnetgrp.php +++ b/modules/xnetgrp.php @@ -34,7 +34,7 @@ function get_infos($email) } $res = XDB::query( - "SELECT uid, nom, prenom, email, email AS email2, perms='admin', origine, sexe + "SELECT uid, nom, prenom, email, email AS email2, perms='admin', origine, comm, sexe FROM groupex.membres WHERE $field = {?} AND asso_id = {?}", $email, $globals->asso('id')); @@ -54,7 +54,7 @@ function get_infos($email) u.prenom, b.alias, CONCAT(b.alias, '@m4x.org') AS email, CONCAT(b.alias, '@polytechnique.org') AS email2, - m.perms = 'admin' AS perms, m.origine, + m.perms = 'admin' AS perms, m.origine, m.comm, FIND_IN_SET('femme', u.flags) AS sexe FROM auth_user_md5 AS u INNER JOIN aliases AS a ON ( u.user_id = a.id AND a.type != 'homonyme' ) @@ -82,9 +82,11 @@ class XnetGrpModule extends PLModule '%grp/forum' => $this->make_hook('forum', AUTH_MDP, 'groupmember'), '%grp/annuaire' => $this->make_hook('annuaire', AUTH_MDP, 'groupannu'), '%grp/annuaire/vcard' => $this->make_hook('vcard', AUTH_MDP, 'groupmember:groupannu'), + '%grp/annuaire/csv' => $this->make_hook('csv', AUTH_MDP, 'groupmember:groupannu'), '%grp/trombi' => $this->make_hook('trombi', AUTH_MDP, 'groupannu'), '%grp/geoloc' => $this->make_hook('geoloc', AUTH_MDP, 'groupannu'), '%grp/subscribe' => $this->make_hook('subscribe', AUTH_MDP), + '%grp/subscribe/valid' => $this->make_hook('subscribe_valid', AUTH_MDP, 'groupadmin'), '%grp/unsubscribe' => $this->make_hook('unsubscribe', AUTH_MDP, 'groupmember'), '%grp/change_rights' => $this->make_hook('change_rights', AUTH_MDP), @@ -120,7 +122,7 @@ class XnetGrpModule extends PLModule if (S::logged()) { if (Env::has('read')) { - XDB::query('DELETE r.* + XDB::query('DELETE groupex.r.* FROM groupex.announces_read AS r INNER JOIN groupex.announces AS a ON a.id = r.announce_id WHERE peremption < CURRENT_DATE()'); @@ -164,6 +166,13 @@ class XnetGrpModule extends PLModule AND FIND_IN_SET('public', u.flags)", $globals->asso('id')); } + if (may_update()) { + $subs_valid = XDB::query("SELECT uid + FROM groupex.membres_sub_requests + WHERE asso_id = {?}", + $globals->asso('id')); + $page->assign('requests', $subs_valid->numRows()); + } if (!S::has('core_rss_hash')) { $page->setRssLink("Polytechnique.net :: {$globals->asso("nom")} :: News publiques", @@ -209,7 +218,7 @@ class XnetGrpModule extends PLModule global $globals; $site = $globals->asso('site'); if (!$site) { - $page->trig('Le groupe n\'a pas de site web'); + $page->trigError('Le groupe n\'a pas de site web.'); return $this->handler_index($page); } http_redirect($site); @@ -222,9 +231,15 @@ class XnetGrpModule extends PLModule $page->changeTpl('xnetgrp/edit.tpl'); if (Post::has('submit')) { + S::assert_xsrf_token(); + + $flags = new PlFlagSet('wiki_desc'); + if (Post::has('notif_unsub') && Post::i('notif_unsub') == 1) { + $flags->addFlag('notif_unsub'); + } if (S::has_perms()) { if (Post::v('mail_domain') && (strstr(Post::v('mail_domain'), '.') === false)) { - $page->trig("le domaine doit être un FQDN (aucune modif effectuée) !!!"); + $page->trigError("le domaine doit être un FQDN (aucune modif effectuée) !!!"); return; } XDB::execute( @@ -233,7 +248,7 @@ class XnetGrpModule extends PLModule descr={?}, site={?}, mail={?}, resp={?}, forum={?}, mail_domain={?}, ax={?}, pub={?}, sub_url={?}, inscriptible={?}, unsub_url={?}, - flags='wiki_desc' + flags={?} WHERE id={?}", Post::v('nom'), Post::v('diminutif'), Post::v('cat'), Post::i('dom'), @@ -242,9 +257,9 @@ class XnetGrpModule extends PLModule Post::v('forum'), Post::v('mail_domain'), Post::has('ax'), Post::v('pub'), Post::v('sub_url'), Post::v('inscriptible'), - Post::v('unsub_url'),$globals->asso('id')); + Post::v('unsub_url'), $flags, $globals->asso('id')); if (Post::v('mail_domain')) { - XDB::execute('INSERT INTO virtual_domains (domain) VALUES({?})', + XDB::execute('INSERT IGNORE INTO virtual_domains (domain) VALUES({?})', Post::v('mail_domain')); } } else { @@ -252,14 +267,14 @@ class XnetGrpModule extends PLModule "UPDATE groupex.asso SET descr={?}, site={?}, mail={?}, resp={?}, forum={?}, ax={?}, pub= {?}, sub_url={?}, - unsub_url={?},flags='wiki_desc' + unsub_url={?},flags={?} WHERE id={?}", Post::v('descr'), Post::v('site'), Post::v('mail'), Post::v('resp'), Post::v('forum'), Post::has('ax'), - Post::has('pub'), + Post::v('pub'), Post::v('sub_url'), Post::v('unsub_url'), - $globals->asso('id')); + $flags, $globals->asso('id')); } if ($_FILES['logo']['name']) { @@ -280,7 +295,7 @@ class XnetGrpModule extends PLModule $page->assign('super', true); } if (!$globals->asso('wiki_desc') && $globals->asso('descr')) { - $page->trig("Attention, le format de la description a changé et utilise désormais la syntaxe wiki " + $page->trigWarning("Attention, le format de la description a changé et utilise désormais la syntaxe wiki " . "intégrée au site. Il te faudra probablement adapter le formatage du texte actuel pour " . "qu'il s'affiche correctement avec cette nouvelle syntaxe."); } @@ -297,6 +312,7 @@ class XnetGrpModule extends PLModule $page->addJsLink('ajax.js'); if (Post::has('send')) { + S::assert_xsrf_token(); $from = Post::v('from'); $sujet = Post::v('sujet'); $body = Post::v('body'); @@ -304,7 +320,7 @@ class XnetGrpModule extends PLModule $mls = array_keys(Env::v('ml', array())); $mbr = array_keys(Env::v('membres', array())); - require_once dirname(__FILE__) . '/xnetgrp/mail.inc.php'; + $this->load('mail.inc.php'); set_time_limit(120); $tos = get_all_redirects($mbr, $mls, $mmlist); $upload = PlUpload::get($_FILES['uploaded'], S::v('forlife'), 'xnet.emails', true); @@ -312,7 +328,7 @@ class XnetGrpModule extends PLModule if ($upload) { $upload->rm(); } - $page->kill("Mail envoyé !"); + $page->kill("Email envoyé !"); $page->assign('sent', true); } } @@ -432,7 +448,8 @@ class XnetGrpModule extends PLModule m.perms='admin' AS admin, m.origine='X' AS x, u.perms!='pending' AS inscrit, - m.uid, IF(e.email IS NULL,NULL,1) AS actif + m.comm as comm, + m.uid, IF(e.email IS NULL AND FIND_IN_SET('googleapps', u.mail_storage) = 0, NULL, 1) AS actif FROM groupex.membres AS m LEFT JOIN auth_user_md5 AS u ON ( u.user_id = m.uid ) LEFT JOIN aliases AS a ON ( a.id = m.uid AND a.type='a_vie' ) @@ -462,8 +479,69 @@ class XnetGrpModule extends PLModule $res = XDB::query('SELECT uid FROM groupex.membres WHERE asso_id = {?}', $globals->asso('id')); - $vcard = new VCard($res->fetchColumn(), $photos == 'photos', 'Membre du groupe ' . $globals->asso('nom')); - $vcard->do_page($page); + $vcard = new VCard($photos == 'photos', 'Membre du groupe ' . $globals->asso('nom')); + $vcard->addUsers($res->fetchColumn()); + $vcard->show(); + } + + function handler_csv(&$page, $filename = null) + { + global $globals; + if (is_null($filename)) { + $filename = $globals->asso('diminutif') . '.csv'; + } + $ann = XDB::iterator( + "SELECT IF(m.origine='X',IF(u.nom_usage<>'', u.nom_usage, u.nom) ,m.nom) AS nom, + IF(m.origine='X',u.prenom,m.prenom) AS prenom, + IF(m.origine='X', u.promo, IF(m.origine='ext', 'extérieur', 'personne morale')) AS promo, + IF(m.origine='X' AND u.perms != 'pending',CONCAT(a.alias, '@', {?}), m.email) AS email, + IF(m.origine='X',FIND_IN_SET('femme', u.flags), m.sexe) AS femme, + m.comm as comm + FROM groupex.membres AS m + LEFT JOIN auth_user_md5 AS u ON ( u.user_id = m.uid ) + LEFT JOIN aliases AS a ON ( a.id = m.uid AND a.type = 'a_vie' ) + WHERE m.asso_id = {?} + AND (m.origine != 'X' OR u.perms != 'pending' OR m.email IS NOT NULL) + GROUP BY m.uid + ORDER BY nom, prenom", + $globals->mail->domain, $globals->asso('id')); + header('Content-Type: text/x-csv; charset=utf-8;'); + header('Pragma: '); + header('Cache-Control: '); + $page->changeTpl('xnetgrp/annuaire-csv.tpl', NO_SKIN); + $page->assign('ann', $ann); + } + + private function removeSubscriptionRequest($uid) + { + global $globals; + XDB::execute("DELETE FROM groupex.membres_sub_requests + WHERE asso_id = {?} AND uid = {?}", + $globals->asso('id'), $uid); + } + + private function validSubscription($nom, $prenom, $sexe, $uid, $forlife) + { + global $globals; + $this->removeSubscriptionRequest($uid); + XDB::execute("INSERT INTO groupex.membres (asso_id, uid) + VALUES ({?}, {?})", + $globals->asso('id'), $uid); + $mailer = new PlMailer(); + $mailer->addTo("$forlife@polytechnique.org"); + $mailer->setFrom('"' . S::v('prenom') . ' ' . S::v('nom') + . '" <' . S::v('forlife') . '@polytechnique.org>'); + $mailer->setSubject('[' . $globals->asso('nom') . '] Demande d\'inscription'); + $message = ($sexe ? 'Chère' : 'Cher') . " Camarade,\n" + . "\n" + . " Suite à ta demande d'adhésion à " . $globals->asso('nom') . ",\n" + . "j'ai le plaisir de t'annoncer que ton inscription a été validée !\n" + . "\n" + . "Bien cordialement,\n" + . "-- \n" + . S::s('prenom') . ' ' . S::s('nom') . '.'; + $mailer->setTxtBody($message); + $mailer->send(); } function handler_subscribe(&$page, $u = null) @@ -478,12 +556,13 @@ class XnetGrpModule extends PLModule if (!is_null($u) && may_update()) { $page->assign('u', $u); - $res = XDB::query("SELECT u.nom, u.prenom, u.promo, u.user_id, FIND_IN_SET('femme', u.flags) + $res = XDB::query("SELECT u.nom, u.prenom, u.promo, u.user_id, FIND_IN_SET('femme', u.flags), s.reason FROM auth_user_md5 AS u INNER JOIN aliases AS al ON (al.id = u.user_id AND al.type != 'liste') - WHERE al.alias = {?}", $u); + LEFT JOIN groupex.membres_sub_requests AS s ON (u.user_id = s.uid AND s.asso_id = {?}) + WHERE al.alias = {?}", $globals->asso('id'), $u); - if (list($nom, $prenom, $promo, $uid, $sexe) = $res->fetchOneRow()) { + if (list($nom, $prenom, $promo, $uid, $sexe, $reason) = $res->fetchOneRow()) { $res = XDB::query("SELECT COUNT(*) FROM groupex.membres AS m INNER JOIN aliases AS a ON (m.uid = a.id AND a.type != 'homonyme') @@ -491,32 +570,18 @@ class XnetGrpModule extends PLModule $u, $globals->asso('id')); $n = $res->fetchOneCell(); if ($n) { + $this->removeSubscriptionRequest($uid); $page->kill("$prenom $nom est déjà membre du groupe !"); return; - } - elseif (Env::has('accept')) - { - XDB::execute("INSERT INTO groupex.membres (asso_id, uid) - VALUES ({?}, {?})", - $globals->asso('id'), $uid); - $mailer = new PlMailer(); - $mailer->addTo("$u@polytechnique.org"); - $mailer->setFrom('"'.S::v('prenom').' '.S::v('nom') - .'" <'.S::v('forlife').'@polytechnique.org>'); - $mailer->setSubject('['.$globals->asso('nom').'] Demande d\'inscription'); - $message = ($sexe ? 'Chère' : 'Cher') . " Camarade,\n" - . "\n" - . " Suite à ta demande d'adhésion à ".$globals->asso('nom').",\n" - . "j'ai le plaisir de t'annoncer que ton inscription a été validée !\n" - . "\n" - . "Bien cordialement,\n" - . "{$_SESSION["prenom"]} {$_SESSION["nom"]}."; - $mailer->setTxtBody($message); - $mailer->send(); - $page->kill("$prenom $nom a bien été inscrit" . ($sexe ? 'e' : '') . "."); - } - elseif (Env::has('refuse')) - { + } elseif (Env::has('accept')) { + S::assert_xsrf_token(); + + $this->validSubscription($nom, $prenom, $sexe, $uid, $u); + pl_redirect("member/$u"); + } elseif (Env::has('refuse')) { + S::assert_xsrf_token(); + + $this->removeSubscriptionRequest($uid); $mailer = new PlMailer(); $mailer->addTo("$u@polytechnique.org"); $mailer->setFrom('"'.S::v('prenom').' '.S::v('nom') @@ -524,13 +589,14 @@ class XnetGrpModule extends PLModule $mailer->setSubject('['.$globals->asso('nom').'] Demande d\'inscription annulée'); $mailer->setTxtBody(Env::v('motif')); $mailer->send(); - $page->kill("la demande $prenom $nom a bien été refusée"); + $page->kill("La demande de $prenom $nom a bien été refusée."); } else { $page->assign('show_form', true); $page->assign('prenom', $prenom); $page->assign('nom', $nom); $page->assign('promo', $promo); $page->assign('uid', $uid); + $page->assign('reason', $reason); } return; } @@ -538,19 +604,33 @@ class XnetGrpModule extends PLModule } if (is_member()) { - $page->kill("tu es déjà membre !"); + $page->kill("Tu es déjà membre !"); + return; + } + + $res = XDB::query("SELECT uid + FROM groupex.membres_sub_requests + WHERE uid = {?} AND asso_id = {?}", + S::i('uid'), $globals->asso('id')); + if ($res->numRows() != 0) { + $page->kill("Tu as déjà demandé ton inscription à ce groupe. Cette demande est actuellement en attente de validation."); return; } if (Post::has('inscrire')) { + S::assert_xsrf_token(); + + XDB::execute("INSERT INTO groupex.membres_sub_requests (asso_id, uid, ts, reason) + VALUES ({?}, {?}, NOW(), {?})", + $globals->asso('id'), S::i('uid'), Post::v('message')); $res = XDB::query('SELECT IF(m.email IS NULL, - CONCAT(al.alias,"@polytechnique.org"), - m.email) - FROM groupex.membres AS m - INNER JOIN aliases AS al ON (al.type = "a_vie" - AND al.id = m.uid) - WHERE perms="admin" AND m.asso_id = {?}', - $globals->asso('id')); + CONCAT(al.alias,"@polytechnique.org"), + m.email) + FROM groupex.membres AS m + INNER JOIN aliases AS al ON (al.type = "a_vie" + AND al.id = m.uid) + WHERE perms="admin" AND m.asso_id = {?}', + $globals->asso('id')); $emails = $res->fetchColumn(); $to = implode(',', $emails); @@ -585,30 +665,70 @@ class XnetGrpModule extends PLModule } } + function handler_subscribe_valid(&$page) + { + global $globals; + + if (Post::has('valid')) { + S::assert_xsrf_token(); + $subs = Post::v('subs'); + if (is_array($subs)) { + $users = array(); + foreach ($subs as $forlife => $val) { + if ($val == '1') { + $res = XDB::query("SELECT IF(u.nom_usage != '', u.nom_usage, u.nom) AS u, + u.prenom, FIND_IN_SET('femme', u.flags) AS sexe, + u.user_id + FROM auth_user_md5 AS u + INNER JOIN aliases AS a ON (a.id = u.user_id) + WHERE a.alias = {?}", $forlife); + if ($res->numRows() == 1) { + list($nom, $prenom, $sexe, $uid) = $res->fetchOneRow(); + $this->validSubscription($nom, $prenom, $sexe, $uid, $forlife); + } + } + } + } + } + + $it = XDB::iterator("SELECT IF(u.nom_usage != '', u.nom_usage, u.nom) AS nom, + u.prenom, u.promo, a.alias AS forlife, s.ts AS date + FROM groupex.membres_sub_requests AS s + INNER JOIN auth_user_md5 AS u ON (s.uid = u.user_id) + INNER JOIN aliases AS a ON (a.id = s.uid AND a.type = 'a_vie') + WHERE asso_id = {?} + ORDER BY nom, prenom", + $globals->asso('id')); + + $page->changeTpl('xnetgrp/subscribe-valid.tpl'); + $page->assign('valid', $it); + } + function handler_change_rights(&$page) { if (Env::has('right') && (may_update() || S::has('suid'))) { switch (Env::v('right')) { case 'admin': - XnetSession::killSuid(); + Platal::session()->stopSUID(); break; case 'anim': - XnetSession::doSelfSuid(); + Platal::session()->doSelfSuid(); may_update(true); is_member(true); break; case 'member': - XnetSession::doSelfSuid(); + Platal::session()->doSelfSuid(); may_update(false, true); is_member(true); break; case 'logged': - XnetSession::doSelfSuid(); + Platal::session()->doSelfSuid(); may_update(false, true); is_member(false, true); break; } } +// var_dump($_SESSION); http_redirect($_SERVER['HTTP_REFERER']); } @@ -616,7 +736,7 @@ class XnetGrpModule extends PLModule { global $globals; - require_once dirname(__FILE__) . '/xnetgrp/mail.inc.php'; + $this->load('mail.inc.php'); $page->changeTpl('xnetgrp/annuaire-admin.tpl'); $mmlist = new MMList(S::v('uid'), S::v('password'), $globals->asso('mail_domain')); @@ -667,6 +787,8 @@ class XnetGrpModule extends PLModule if (is_null($email)) { return; + } else { + S::assert_xsrf_token(); } if (strpos($email, '@') === false) { @@ -688,10 +810,9 @@ class XnetGrpModule extends PLModule WHERE a.alias={?}', $globals->asso('id'), $forlife); pl_redirect("member/$forlife"); } else { - $page->trig($email." n'est pas un alias polytechnique.org valide."); + $page->trigError($email." n'est pas un alias polytechnique.org valide."); } } else { - require_once 'xorg.misc.inc.php'; if (isvalid_email($email)) { if (Env::v('x') && Env::has('userid') && Env::i('userid')) { $uid = Env::i('userid'); @@ -710,9 +831,10 @@ class XnetGrpModule extends PLModule XDB::execute('INSERT INTO groupex.membres (uid, asso_id, origine, email) VALUES ({?}, {?}, "X", {?})', $uid, $globals->asso('id'), $email); + $this->removeSubscriptionRequest($uid); pl_redirect("member/$email"); } - $page->trig("Utilisateur invalide"); + $page->trigError("Utilisateur invalide"); } else { $res = XDB::query('SELECT MAX(uid)+1 FROM groupex.membres'); $uid = max(intval($res->fetchOneCell()), 50001); @@ -722,7 +844,7 @@ class XnetGrpModule extends PLModule pl_redirect("member/$email"); } } else { - $page->trig("« $email » n'est pas une adresse mail valide"); + $page->trigError("« $email » n'est pas une adresse email valide."); } } } @@ -763,15 +885,34 @@ class XnetGrpModule extends PLModule function unsubscribe(&$user) { - global $globals, $page; + global $globals; XDB::execute( "DELETE FROM groupex.membres WHERE uid={?} AND asso_id={?}", $user['uid'], $globals->asso('id')); + if ($globals->asso('notif_unsub')) { + $mailer = new PlMailer('xnetgrp/unsubscription-notif.mail.tpl'); + $res = XDB::iterRow("SELECT a.alias, u.prenom, IF(u.nom_usage != '', u.nom_usage, u.nom) AS nom + FROM groupex.membres AS m + INNER JOIN aliases AS a ON (m.uid = a.id AND FIND_IN_SET('bestalias', a.flags)) + INNER JOIn auth_user_md5 AS u ON (u.user_id = a.id) + WHERE m.asso_id = {?} AND m.perms = 'admin'", + $globals->asso('id')); + while (list($alias, $prenom, $nom) = $res->next()) { + $mailer->addTo("\"$prenom $nom\" <$alias@{$globals->mail->domain}>"); + } + $mailer->assign('group', $globals->asso('nom')); + $mailer->assign('prenom', $user['prenom']); + $mailer->assign('nom', $user['nom']); + $mailer->assign('mail', $user['email2']); + $mailer->assign('selfdone', $user['uid'] == S::i('uid')); + $mailer->send(); + } + $user_same_email = get_infos($user['email']); $domain = $globals->asso('mail_domain'); - if (!$domain || !empty($user_same_email)) { + if (!$domain || (!empty($user_same_email) && $user_same_email['uid'] != $user['uid'])) { return true; } @@ -788,9 +929,9 @@ class XnetGrpModule extends PLModule $mmlist->unsubscribe($liste['list']); } } elseif ($liste['sub']) { - $page->trig("{$user['prenom']} {$user['nom']} a une" - ." demande d'inscription en cours sur la" - ." liste {$liste['list']}@ !"); + Platal::page()->trigWarning("{$user['prenom']} {$user['nom']} a une" + ." demande d'inscription en cours sur la" + ." liste {$liste['list']}@ !"); $warning = true; } } @@ -815,12 +956,14 @@ class XnetGrpModule extends PLModule if (!Post::has('confirm')) { return; + } else { + S::assert_xsrf_token(); } if ($this->unsubscribe($user)) { - $page->trig('Vous avez été désinscrit du groupe avec succès.'); + $page->trigSuccess('Vous avez été désinscrit du groupe avec succès.'); } else { - $page->trig('Vous avez été désinscrit du groupe, mais des erreurs se sont produites lors des désinscriptions des alias et des mailing-lists.'); + $page->trigWarning('Vous avez été désinscrit du groupe, mais des erreurs se sont produites lors des désinscriptions des alias et des listes de diffusion.'); } $page->assign('is_member', is_member(true)); } @@ -836,16 +979,18 @@ class XnetGrpModule extends PLModule if (!Post::has('confirm')) { return; + } else { + S::assert_xsrf_token(); } if ($this->unsubscribe($user)) { - $page->trig("{$user['prenom']} {$user['nom']} a été désabonné du groupe !"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été désabonné du groupe !"); } else { - $page->trig("{$user['prenom']} {$user['nom']} a été désabonné du groupe, mais des erreurs subsistent !"); + $page->trigWarning("{$user['prenom']} {$user['nom']} a été désabonné du groupe, mais des erreurs subsistent !"); } } - private function changeLogin(PlatalPage &$page, array &$user, MMList &$mmlist, $login) + private function changeLogin(PlPage &$page, array &$user, MMList &$mmlist, $login) { require_once 'user.func.inc.php'; // Search the uid of the user... @@ -857,10 +1002,10 @@ class XnetGrpModule extends PLModule if ($res->numRows() == 0) { $x = get_not_registered_user($login); if (!$x) { - $page->trig("Le login $login ne correspond à aucun X"); + $page->trigError("Le login $login ne correspond à aucun X."); return false; } else if (count($x) > 1) { - $page->trig("Le login $login correspond a plusieurs camarades"); + $page->trigError("Le login $login correspond a plusieurs camarades."); return false; } $uid = $x[0]['user_id']; @@ -895,20 +1040,23 @@ class XnetGrpModule extends PLModule // Update subscription to aliases if ($email != $user['email']) { XDB::execute("UPDATE IGNORE virtual_redirect AS vr - INNER JOIN virtual AS v ON(vr.vid = v.vid AND SUBSTRING_INDEX(alias, '@', 2) = {?}) + INNER JOIN virtual AS v ON(vr.vid = v.vid AND SUBSTRING_INDEX(alias, '@', -1) = {?}) SET vr.redirect = {?} WHERE vr.redirect = {?}", $globals->asso('mail_domain'), $email, $user['email']); XDB::execute("DELETE vr.* FROM virtual_redirect AS vr - INNER JOIN virtual AS v ON(vr.vid = v.vid AND SUBSTRING_INDEX(alias, '@', 2) = {?}) + INNER JOIN virtual AS v ON(vr.vid = v.vid AND SUBSTRING_INDEX(alias, '@', -1) = {?}) WHERE vr.redirect = {?}", $globals->asso('mail_domain'), $user['email']); foreach (Env::v('ml1', array()) as $ml => $state) { $mmlist->replace_email($ml, $user['email'], $email); } } - return $login; + if ($sub) { + return $login; + } + return $user['email']; } function handler_admin_member(&$page, $user) @@ -926,6 +1074,8 @@ class XnetGrpModule extends PLModule $globals->asso('mail_domain')); if (Post::has('change')) { + S::assert_xsrf_token(); + // Convert user status to X if ($user['origine'] == 'ext' && trim(Post::v('login_X'))) { $forlife = $this->changeLogin($page, $user, $mmlist, trim(Post::v('login_X'))); @@ -946,20 +1096,29 @@ class XnetGrpModule extends PLModule SET prenom={?}, nom={?}, email={?}, sexe={?}, origine={?} WHERE uid={?} AND asso_id={?}', $user['prenom'], $user['nom'], Post::v('email'), - $user['sexe'], $user['origine'], $user['uid'], - $globals->asso('id')); + $user['sexe'], $user['origine'], + $user['uid'], $globals->asso('id')); $user['email'] = Post::v('email'); $user['email2'] = Post::v('email'); + $page->trigSuccess('Données de l\'utilisateur mise à jour.'); } $perms = Post::i('is_admin'); - if ($user['perms'] != $perms) { - XDB::query('UPDATE groupex.membres SET perms={?} + $comm = trim(Post::s('comm')); + if ($user['perms'] != $perms || $user['comm'] != $comm) { + XDB::query('UPDATE groupex.membres + SET perms={?}, comm={?} WHERE uid={?} AND asso_id={?}', - $perms ? 'admin' : 'membre', + $perms ? 'admin' : 'membre', $comm, $user['uid'], $globals->asso('id')); + if ($perms != $user['perms']) { + $page->trigSuccess('Permissions modifiées !'); + } + if ($comm != $user['comm']) { + $page->trigSuccess('Commentaire mis à jour.'); + } $user['perms'] = $perms; - $page->trig('permissions modifiées'); + $user['comm'] = $comm; } // Update ML subscriptions @@ -968,24 +1127,24 @@ class XnetGrpModule extends PLModule if ($ask == $state) { if ($state && $email_changed) { $mmlist->replace_email($ml, $from_email, $user['email2']); - $page->trig("L'abonnement de {$user['prenom']} {$user['nom']} à $ml@ a été mis à jour"); + $page->trigSuccess("L'abonnement de {$user['prenom']} {$user['nom']} à $ml@ a été mis à jour."); } continue; } if ($state == '1') { - $page->trig("{$user['prenom']} {$user['nom']} a " + $page->trigWarning("{$user['prenom']} {$user['nom']} a " ."actuellement une demande d'inscription en " ."cours sur $ml@ !!!"); } elseif ($ask) { $mmlist->mass_subscribe($ml, Array($user['email2'])); - $page->trig("{$user['prenom']} {$user['nom']} a été abonné à $ml@"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été abonné à $ml@."); } else { if ($email_changed) { $mmlist->mass_unsubscribe($ml, Array($from_email)); } else { $mmlist->mass_unsubscribe($ml, Array($user['email2'])); } - $page->trig("{$user['prenom']} {$user['nom']} a été désabonné de $ml@"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été désabonné de $ml@."); } } @@ -997,14 +1156,14 @@ class XnetGrpModule extends PLModule XDB::query("INSERT INTO virtual_redirect (vid,redirect) SELECT vid,{?} FROM virtual WHERE alias={?}", $user['email'], $ml); - $page->trig("{$user['prenom']} {$user['nom']} a été abonné à $ml"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été abonné à $ml."); } else { XDB::query("DELETE FROM virtual_redirect USING virtual_redirect INNER JOIN virtual USING(vid) WHERE redirect={?} AND alias={?}", $user['email'], $ml); - $page->trig("{$user['prenom']} {$user['nom']} a été désabonné de $ml"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été désabonné de $ml."); } } } @@ -1016,54 +1175,36 @@ class XnetGrpModule extends PLModule $res = XDB::query( 'SELECT alias, redirect IS NOT NULL as sub FROM virtual AS v - LEFT JOIN virtual_redirect AS vr ON(v.vid=vr.vid AND redirect={?}) + LEFT JOIN virtual_redirect AS vr ON(v.vid=vr.vid AND (redirect = {?} OR redirect = {?})) WHERE alias LIKE {?} AND type="user"', - $user['email'], '%@'.$globals->asso('mail_domain')); + $user['email'], $user['email2'], '%@'.$globals->asso('mail_domain')); $page->assign('alias', $res->fetchAllAssoc()); } function handler_rss(&$page, $user = null, $hash = null) { global $globals; - require_once('rss.inc.php'); - $uid = init_rss('xnetgrp/announce-rss.tpl', $user, $hash, false); - - if ($uid) { - $rss = XDB::iterator("SELECT a.id, a.titre, a.texte, a.contacts, a.create_date, - IF(u2.nom_usage != '', u2.nom_usage, u2.nom) AS nom, u2.prenom, u2.promo, - FIND_IN_SET('photo', a.flags) AS photo - FROM auth_user_md5 AS u - INNER JOIN groupex.announces AS a ON ( (a.promo_min = 0 OR a.promo_min <= u.promo) - AND (a.promo_max = 0 OR a.promo_max <= u.promo)) - INNER JOIN auth_user_md5 AS u2 ON (u2.user_id = a.user_id) - WHERE u.user_id = {?} AND peremption >= NOW() AND a.asso_id = {?}", - $uid, $globals->asso('id')); - } else { - $rss = XDB::iterator("SELECT a.id, a.titre, a.texte, a.create_date, - IF(u.nom_usage != '', u.nom_usage, u.nom) AS nom, u.prenom, u.promo - FROM groupex.announces AS a - INNER JOIN auth_user_md5 AS u USING(user_id) - WHERE FIND_IN_SET('public', a.flags) AND peremption >= NOW() AND a.asso_id = {?}", - $globals->asso('id')); - } $page->assign('asso', $globals->asso()); - $page->assign('rss', $rss); + + $this->load('feed.inc.php'); + $feed = new XnetGrpEventFeed(); + return $feed->run($page, $user, $hash, false); } - private function upload_image(PlatalPage &$page, PlUpload &$upload) + private function upload_image(PlPage &$page, PlUpload &$upload) { if (@!$_FILES['image']['tmp_name'] && !Env::v('image_url')) { return true; } if (!$upload->upload($_FILES['image']) && !$upload->download(Env::v('image_url'))) { - $page->trig('Impossible de télécharger l\'image'); + $page->trigError('Impossible de télécharger l\'image'); return false; } elseif (!$upload->isType('image')) { - $page->trig('Le fichier n\'est pas une image valide au format JPEG, GIF ou PNG.'); + $page->trigError('Le fichier n\'est pas une image valide au format JPEG, GIF ou PNG.'); $upload->rm(); return false; } elseif (!$upload->resizeImage(200, 300, 100, 100, 32284)) { - $page->trig('Impossible de retraiter l\'image'); + $page->trigError('Impossible de retraiter l\'image'); return false; } return true; @@ -1101,6 +1242,8 @@ class XnetGrpModule extends PLModule if (Post::v('valid') == 'Visualiser' || Post::v('valid') == 'Enregistrer' || Post::v('valid') == 'Supprimer l\'image' || Post::v('valid') == 'Pas d\'image') { + S::assert_xsrf_token(); + if (!is_null($aid)) { $art['id'] = $aid; } @@ -1131,12 +1274,12 @@ class XnetGrpModule extends PLModule ($art['promo_min'] != 0 && ($art['promo_min'] <= 1900 || $art['promo_min'] >= 2020)) || ($art['promo_max'] != 0 && ($art['promo_max'] <= 1900 || $art['promo_max'] >= 2020)))) { - $page->trig("L'intervalle de promotions est invalide"); + $page->trigError("L'intervalle de promotions est invalide."); Post::kill('valid'); } if (!trim($art['titre']) || !trim($art['texte'])) { - $page->trig("L'article doit avoir un titre et un contenu"); + $page->trigError("L'article doit avoir un titre et un contenu."); Post::kill('valid'); } @@ -1156,14 +1299,13 @@ class XnetGrpModule extends PLModule if (Post::v('valid') == 'Enregistrer') { $promo_min = ($art['public'] ? 0 : $art['promo_min']); $promo_max = ($art['public'] ? 0 : $art['promo_max']); - $flags = array(); + $flags = new PlFlagSet(); if ($art['public']) { - $flags[] = 'public'; + $flags->addFlag('public'); } if ($art['photo']) { - $flags[] = 'photo'; + $flags->addFlag('photo'); } - $flags = implode(',', $flags); if (is_null($aid)) { $fulltext = $art['texte']; if (!empty($art['contact_html'])) { @@ -1195,7 +1337,7 @@ class XnetGrpModule extends PLModule $art['promo_min'], $art['promo_max'], $art['peremption'], "", S::v('uid'), $upload); $article->submit(); - $page->trig("L'affichage sur la page d'accueil de Polytechnique.org est en attente de validation"); + $page->trigWarning("L'affichage sur la page d'accueil de Polytechnique.org est en attente de validation."); } else if ($upload && $upload->exists()) { $upload->rm(); } @@ -1204,7 +1346,7 @@ class XnetGrpModule extends PLModule $article = new NLReq(S::v('uid'), $globals->asso('nom') . " : " .$art['titre'], $art['texte'], $art['contact_html']); $article->submit(); - $page->trig("La parution dans la Lettre Mensuelle est en attente de validation"); + $page->trigWarning("La parution dans la Lettre Mensuelle est en attente de validation."); } } else { XDB::query("UPDATE groupex.announces @@ -1240,7 +1382,7 @@ class XnetGrpModule extends PLModule $art = $res->fetchOneAssoc(); $art['contact_html'] = $art['contacts']; } else { - $page->kill("Aucun article correspond à l'identifiant indiqué"); + $page->kill("Aucun article correspond à l'identifiant indiqué."); } } @@ -1265,6 +1407,7 @@ class XnetGrpModule extends PLModule $page->changeTpl('xnetgrp/announce-admin.tpl'); if (Env::has('del')) { + S::assert_xsrf_token(); XDB::execute("DELETE FROM groupex.announces WHERE id = {?} AND asso_id = {?}", Env::i('del'), $globals->asso('id'));